FRST_08-01-2025 17.49.06.txt 33.84KB
3 downloads
Addition_08-01-2025 17.50.18.txt 11KB
3 downloadsScan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 04-01-2025
Ran by judyz (administrator) on DESKTOP-FPEVD0P (HP HP ProBook 450 G7) (08-01-2025 17:44:24)
Running from C:\Users\judyz\Downloads\FRST64.exe
Loaded Profiles: judyz
Platform: Microsoft Windows 11 Pro Version 24H2 26100.2605 (X64) Language: English (United States)
Default browser: Edge
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(cmd.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\diskpart.exe
(DriverStore\FileRepository\cui_dch.inf_amd64_5207db0559876a61\igfxCUIService.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_5207db0559876a61\igfxEM.exe
(DriverStore\FileRepository\seapo64.inf_amd64_deaeb20891c6fa3a\SECOMN64.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Sonitude, Inc.) C:\Windows\System32\DriverStore\FileRepository\seapo64.inf_amd64_deaeb20891c6fa3a\SECOCL64.exe
(explorer.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\cmd.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <43>
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_5207db0559876a61\igfxCUIService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_af50fdb80983f7bc\jhi_service.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_401fde8782680631\OneApp.IGCC.WinService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_d132a4045a2a0202\IntelCpHDCPSvc.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_d132a4045a2a0202\IntelCpHeciSvc.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_d51901c26227fb29\WMIRegistrationService.exe
(services.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\vds.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Fortemedia) C:\Windows\System32\FMService64.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Sonitude, Inc.) C:\Windows\System32\DriverStore\FileRepository\seapo64.inf_amd64_deaeb20891c6fa3a\SECOMN64.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvbl.inf_amd64_bb28b4bb5c7c0290\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_a42d9de41f05fa49\RtkAudUService64.exe <3>
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.SecHealthUI_1000.26100.1.0_x64__8wekyb3d8bbwe\SecHealthUI.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Users\judyz\AppData\Local\Microsoft\OneDrive\24.226.1110.0004\FileCoAuth.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <4>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\fodhelper.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\NgcIso.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\SecurityHealthHost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\WWAHost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\UUS\amd64\MoUsoCoreWorker.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.26100.2592_none_a51f478d77516870\TiWorker.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtkAudUService] => C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_a42d9de41f05fa49\RtkAudUService64.exe [2119512 2024-07-29] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKU\S-1-5-21-1365236912-114835092-1529061894-1001\...\Run: [MicrosoftEdgeAutoLaunch_AC82F772BE81CB975221A975A9FEF1AD] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4060608 2024-03-21] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-1365236912-114835092-1529061894-1001\...\RunOnce: [Delete Cached Update Binary] => C:\Windows\system32\cmd.exe /q /c del /q "C:\Users\judyz\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe" [83426848 2025-01-08] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-1365236912-114835092-1529061894-1001\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\Windows\system32\cmd.exe /q /c del /q "C:\Users\judyz\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe" (No File)
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {5343DC93-5DCA-45D0-8FA3-C012CDAB0147} - System32\Tasks\Microsoft\Windows\Sense\InstallSenseClient => C:\ProgramData\Microsoft\Windows Defender Advanced Threat Protection\Task\SenseTask.exe [98304 2025-01-08] (Microsoft Windows -> )
Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 163.121.128.134 163.121.128.135 192.168.1.1
Tcpip\..\Interfaces\{3705c35b-d448-4324-a7d1-6835f8319c1a}: [DhcpNameServer] 163.121.128.134 163.121.128.135 192.168.1.1
Edge:
=======
Edge Profile: C:\Users\judyz\AppData\Local\Microsoft\Edge\User Data\Default [2025-01-08]
Edge Extension: (Honey: Automatic Coupons & Rewards) - C:\Users\judyz\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\bmnlcjabgnpnenekpadlanbbkooimhnj [2025-01-08]
Edge Extension: (McAfee® WebAdvisor) - C:\Users\judyz\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\fdhgeoginicibhagdmblfikbgbkahibd [2025-01-08]
Edge Extension: (Google Docs Offline) - C:\Users\judyz\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-01-08]
Edge Extension: (Edge relevant text changes) - C:\Users\judyz\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2025-01-08]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 FMAPOService; C:\Windows\System32\FMService64.exe [550320 2022-09-12] (Microsoft Windows Hardware Compatibility Publisher -> Fortemedia)
S2 IntelAudioService; C:\Windows\System32\DriverStore\FileRepository\intcoed.inf_amd64_581d7e91d349facc\AS\IAS\IntelAudioService.exe [402464 2022-10-20] (Intel Corporation -> Intel)
R2 NVDisplay.ContainerLocalSystem; C:\Windows\System32\DriverStore\FileRepository\nvbl.inf_amd64_bb28b4bb5c7c0290\Display.NvContainer\NVDisplay.Container.exe [1275000 2024-08-19] (NVIDIA Corporation -> NVIDIA Corporation)
R2 SECOMNService; C:\Windows\System32\DriverStore\FileRepository\seapo64.inf_amd64_deaeb20891c6fa3a\SECOMN64.exe [1087496 2024-07-08] (Microsoft Windows Hardware Compatibility Publisher -> Sonitude, Inc.)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [559304 2025-01-08] (Microsoft Windows Publisher -> Microsoft Corporation)
S2 WbfPolicyService110; C:\Windows\System32\WbfPolicyService110.exe [715704 2022-07-29] (Synaptics Incorporated -> Synaptics Incorporated.)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [3174840 2024-04-01] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [133592 2024-04-01] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 BHTPCRDR; C:\Windows\System32\drivers\bhtpcrdr.sys [201424 2019-09-23] (BayHub Technology Inc. -> BayHubTech/O2Micro)
R3 MpKsl647577b8; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D22FB5F2-1B2D-4169-9746-F884D6AA378B}\MpKslDrv.sys [263560 2025-01-08] (Microsoft Windows -> Microsoft Corporation)
R3 rtcx21; C:\Windows\System32\DriverStore\FileRepository\rtcx21x64.inf_amd64_feec7a9662e785f0\rtcx21x64.sys [539648 2024-03-28] (Microsoft Windows -> Realtek)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [55856 2024-04-01] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [594304 2024-04-01] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [105856 2024-04-01] (Microsoft Windows -> Microsoft Corporation)
R3 WiManH; C:\Windows\System32\DriverStore\FileRepository\wiman.inf_amd64_c1ac61211c357751\WiManH\WiManH.sys [182952 2024-03-22] (Intel Corporation -> Intel Corporation)
R3 WirelessButtonDriver64; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [40200 2023-11-17] (HP Inc. -> HP)
S3 MpKslb0e527fb; \??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Default\MpKslDrv.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2025-01-08 21:26 - 2025-01-08 17:09 - 000000438 _____ C:\Windows\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
2025-01-08 21:25 - 2025-01-08 21:25 - 000000000 _SHDL C:\Documents and Settings
2025-01-08 21:25 - 2025-01-08 17:28 - 000000000 ____D C:\Users\defaultuser0
2025-01-08 21:25 - 2025-01-08 17:28 - 000000000 ____D C:\ProgramData\Packages
2025-01-08 21:25 - 2025-01-08 17:08 - 000001623 _____ C:\Windows\system32\config\VSMIDK
2025-01-08 21:23 - 2025-01-08 21:23 - 000000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2025-01-08 21:23 - 2025-01-08 21:23 - 000000000 ____D C:\Windows\system32\Drivers\wd
2025-01-08 21:23 - 2025-01-08 21:23 - 000000000 ____D C:\Windows\system32\config\BFS
2025-01-08 21:23 - 2025-01-08 17:40 - 000002438 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2025-01-08 21:23 - 2025-01-08 17:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2025-01-08 21:23 - 2025-01-08 11:30 - 000003612 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA{CD7AA879-9B65-4940-86B8-0A5596561108}
2025-01-08 21:23 - 2025-01-08 11:30 - 000003488 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore{FBC05091-951E-43AB-B9C0-F469254B34F9}
2025-01-08 21:22 - 2025-01-08 21:24 - 000000000 ____D C:\Windows\Panther
2025-01-08 21:22 - 2025-01-08 21:23 - 000000000 ____D C:\Windows\system32\SleepStudy
2025-01-08 21:22 - 2025-01-08 21:22 - 000000000 ____D C:\Windows\ServiceProfiles
2025-01-08 21:22 - 2025-01-08 17:15 - 000012288 ___SH C:\DumpStack.log.tmp
2025-01-08 21:22 - 2025-01-08 17:08 - 000296880 _____ C:\Windows\system32\FNTCACHE.DAT
2025-01-08 17:45 - 2025-01-08 17:45 - 000000000 ____D C:\Users\judyz\AppData\Local\Comms
2025-01-08 17:44 - 2025-01-08 17:45 - 000011325 _____ C:\Users\judyz\Downloads\FRST.txt
2025-01-08 17:44 - 2025-01-08 17:45 - 000000000 ____D C:\FRST
2025-01-08 17:43 - 2025-01-08 17:43 - 002403840 _____ (Farbar) C:\Users\judyz\Downloads\FRST64.exe
2025-01-08 17:43 - 2025-01-08 17:43 - 000000000 ____D C:\Windows\Firmware
2025-01-08 17:43 - 2024-03-12 17:02 - 005208232 _____ (Intel Corporation) C:\Windows\system32\Drivers\Netwtw10.sys
2025-01-08 17:43 - 2024-03-12 17:02 - 001472168 _____ (Intel Corporation) C:\Windows\system32\IntelIHVRouter10.dll
2025-01-08 17:32 - 2025-01-08 17:32 - 000000000 ____D C:\Users\judyz\AppData\Local\OneDrive
2025-01-08 17:29 - 2025-01-08 17:29 - 000000000 ____D C:\Users\judyz\AppData\Roaming\Microsoft\MMC
2025-01-08 17:16 - 2025-01-08 17:16 - 000000000 ____D C:\Users\judyz\OneDrive\Documents\Zoom
2025-01-08 17:16 - 2025-01-08 17:16 - 000000000 ____D C:\Users\judyz\OneDrive\Documents\Summer 2024
2025-01-08 17:16 - 2025-01-08 17:16 - 000000000 ____D C:\Users\judyz\OneDrive\Documents\Sprints
2025-01-08 17:16 - 2025-01-08 17:16 - 000000000 ____D C:\Users\judyz\OneDrive\Documents\Obsidian Vault
2025-01-08 17:16 - 2025-01-08 17:16 - 000000000 ____D C:\Users\judyz\OneDrive\Documents\My Games
2025-01-08 17:16 - 2025-01-08 17:16 - 000000000 ____D C:\Users\judyz\OneDrive\Documents\CV
2025-01-08 17:16 - 2025-01-08 17:16 - 000000000 ____D C:\Users\judyz\OneDrive\Documents\Custom Office Templates
2025-01-08 17:16 - 2025-01-08 17:16 - 000000000 ____D C:\Users\judyz\OneDrive\Documents\Certifictaes
2025-01-08 17:16 - 2025-01-02 13:51 - 000019772 _____ C:\Users\judyz\OneDrive\Desktop\Removed Apps.html
2025-01-08 17:16 - 2025-01-01 20:56 - 000016707 _____ C:\Users\judyz\OneDrive\Documents\Brave Passwords.csv
2025-01-08 17:16 - 2024-10-04 20:52 - 000010277 _____ C:\Users\judyz\OneDrive\Documents\Judy Waleed 20225052 .xlsx
2025-01-08 17:16 - 2024-07-13 14:40 - 000000740 _____ C:\Users\judyz\OneDrive\Documents\Downloads - Shortcut.lnk
2025-01-08 17:16 - 2024-07-12 13:55 - 000055147 _____ C:\Users\judyz\OneDrive\Documents\Judy-Zeada.pdf
2025-01-08 17:16 - 2022-12-11 22:34 - 000000177 ____R C:\Users\judyz\OneDrive\Documents\CS.url
2025-01-08 17:16 - 2022-12-02 19:03 - 003810811 _____ C:\Users\judyz\OneDrive\Documents\TRW pres (1).pptx
2025-01-08 17:16 - 2022-11-26 19:36 - 003812274 _____ C:\Users\judyz\OneDrive\Documents\TRW pres.pptx
2025-01-08 17:16 - 2022-11-05 14:53 - 000000177 ____R C:\Users\judyz\OneDrive\Documents\Electronics.url
2025-01-08 17:16 - 2022-11-02 05:42 - 000000177 ____R C:\Users\judyz\OneDrive\Documents\Uni Google Drive Links.url
2025-01-08 17:16 - 2022-07-17 14:06 - 000011078 _____ C:\Users\judyz\OneDrive\Documents\Group 1 word guide 1.xlsx
2025-01-08 17:16 - 2022-03-10 15:05 - 000008129 _____ C:\Users\judyz\OneDrive\Documents\Book (1).xlsx
2025-01-08 17:16 - 2021-10-16 21:22 - 000000177 ____R C:\Users\judyz\OneDrive\Documents\University.url
2025-01-08 17:16 - 2021-07-07 04:17 - 000008047 _____ C:\Users\judyz\OneDrive\Documents\Book.xlsx
2025-01-08 17:16 - 2021-07-07 04:00 - 000005862 _____ C:\Users\judyz\OneDrive\Documents\Book 1.xlsx
2025-01-08 17:16 - 2021-07-04 13:38 - 000000177 ____R C:\Users\judyz\OneDrive\Documents\ict.url
2025-01-08 17:16 - 2021-01-26 23:25 - 000000177 ____R C:\Users\judyz\OneDrive\Documents\Mathematics.url
2025-01-08 17:16 - 2021-01-26 23:23 - 000000177 ____R C:\Users\judyz\OneDrive\Documents\Biology.url
2025-01-08 17:16 - 2021-01-26 23:23 - 000000177 ____R C:\Users\judyz\OneDrive\Documents\Accounting.url
2025-01-08 17:16 - 2021-01-26 23:19 - 000000177 ____R C:\Users\judyz\OneDrive\Documents\Judy's Notebook.url
2025-01-08 17:15 - 2025-01-08 17:15 - 000000000 ___HD C:\OneDriveTemp
2025-01-08 17:14 - 2025-01-08 17:16 - 000000000 ___RD C:\Users\judyz\OneDrive
2025-01-08 17:14 - 2025-01-08 17:15 - 000003588 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-1365236912-114835092-1529061894-1001
2025-01-08 17:14 - 2025-01-08 17:15 - 000003378 _____ C:\Windows\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1365236912-114835092-1529061894-1001
2025-01-08 17:14 - 2025-01-08 17:15 - 000002379 _____ C:\Users\judyz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2025-01-08 17:14 - 2025-01-08 17:14 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2025-01-08 17:13 - 2025-01-08 17:47 - 000000000 ____D C:\Users\judyz\AppData\Local\PlaceholderTileLogoFolder
2025-01-08 17:13 - 2025-01-08 17:13 - 000000000 ____D C:\Users\judyz\AppData\Local\Publishers
2025-01-08 17:12 - 2025-01-08 17:47 - 000000000 ____D C:\Users\judyz\AppData\Local\Packages
2025-01-08 17:12 - 2025-01-08 17:38 - 000000000 ____D C:\Users\judyz\AppData\Local\D3DSCache
2025-01-08 17:12 - 2025-01-08 17:13 - 000000000 __RHD C:\Users\Public\AccountPictures
2025-01-08 17:12 - 2025-01-08 17:12 - 000000000 __SHD C:\Users\judyz\IntelGraphicsProfiles
2025-01-08 17:12 - 2025-01-08 17:12 - 000000000 ___SD C:\Users\judyz\AppData\Roaming\Microsoft\Crypto
2025-01-08 17:12 - 2025-01-08 17:12 - 000000000 ____D C:\Users\judyz\AppData\Roaming\Microsoft\Vault
2025-01-08 17:12 - 2025-01-08 17:12 - 000000000 ____D C:\Users\judyz\AppData\Roaming\Microsoft\Network
2025-01-08 17:12 - 2025-01-08 17:12 - 000000000 ____D C:\Users\judyz\AppData\Roaming\Adobe
2025-01-08 17:12 - 2025-01-08 17:12 - 000000000 ____D C:\Users\judyz\AppData\LocalLow\NVIDIA
2025-01-08 17:12 - 2025-01-08 17:12 - 000000000 ____D C:\Users\judyz\AppData\LocalLow\Intel
2025-01-08 17:12 - 2025-01-08 17:12 - 000000000 ____D C:\Users\judyz\AppData\Local\VirtualStore
2025-01-08 17:12 - 2025-01-08 17:12 - 000000000 ____D C:\Users\judyz\AppData\Local\SoundResearch
2025-01-08 17:12 - 2025-01-08 17:12 - 000000000 ____D C:\Users\judyz\AppData\Local\ConnectedDevicesPlatform
2025-01-08 17:11 - 2025-01-08 17:33 - 000000000 ____D C:\Users\judyz\AppData\Roaming\Microsoft\Spelling
2025-01-08 17:11 - 2025-01-08 17:16 - 000000000 ____D C:\Users\judyz
2025-01-08 17:11 - 2025-01-08 17:12 - 000000000 ____D C:\Users\judyz\AppData\Roaming\Microsoft\Windows
2025-01-08 17:11 - 2025-01-08 17:11 - 000000020 ___SH C:\Users\judyz\ntuser.ini
2025-01-08 17:11 - 2025-01-08 17:11 - 000000000 ___SD C:\Users\judyz\AppData\Roaming\Microsoft\SystemCertificates
2025-01-08 17:11 - 2025-01-08 17:11 - 000000000 ___SD C:\Users\judyz\AppData\Roaming\Microsoft\Protect
2025-01-08 17:11 - 2025-01-08 17:11 - 000000000 ___SD C:\Users\judyz\AppData\Roaming\Microsoft\Credentials
2025-01-08 17:07 - 2025-01-08 17:09 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2025-01-08 17:01 - 2025-01-08 17:01 - 000000591 _____ C:\Windows\system32\regtest.txt
2025-01-08 17:00 - 2024-07-29 13:16 - 006228824 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHD64.sys
2025-01-08 16:56 - 2025-01-08 17:43 - 000000000 ____D C:\Windows\CbsTemp
2025-01-08 16:54 - 2025-01-08 16:54 - 000027132 _____ C:\Windows\SysWOW64\IntegratedServicesRegionPolicySet.json
2025-01-08 16:54 - 2025-01-08 16:54 - 000027132 _____ C:\Windows\system32\IntegratedServicesRegionPolicySet.json
2025-01-08 16:54 - 2025-01-08 16:54 - 000000998 _____ C:\Windows\system32\DeviceFeatureDDF.json
2025-01-08 16:51 - 2025-01-08 17:08 - 000000000 ____D C:\ProgramData\Intel
2025-01-08 16:51 - 2025-01-08 17:08 - 000000000 ____D C:\Intel
2025-01-08 16:51 - 2025-01-08 16:51 - 000000000 _____ C:\Windows\system32\GfxValDisplayLog.bin
2025-01-08 16:50 - 2022-06-16 04:01 - 000966376 _____ (Intel Corporation) C:\Windows\system32\libmfxhw64.dll
2025-01-08 16:50 - 2022-06-16 04:01 - 000725072 _____ (Intel Corporation) C:\Windows\SysWOW64\libmfxhw32.dll
2025-01-08 16:50 - 2022-06-16 04:01 - 000528768 _____ (Intel) C:\Windows\system32\libvpl.dll
2025-01-08 16:50 - 2022-06-16 04:01 - 000468880 _____ (Intel) C:\Windows\SysWOW64\libvpl.dll
2025-01-08 16:50 - 2022-06-16 04:00 - 000609016 _____ (Intel Corporation) C:\Windows\system32\intel_gfx_api-x64.dll
2025-01-08 16:50 - 2022-06-16 04:00 - 000468008 _____ (Intel Corporation) C:\Windows\SysWOW64\intel_gfx_api-x86.dll
2025-01-08 15:32 - 2025-01-08 17:12 - 000000000 ____D C:\ProgramData\NVIDIA
2025-01-08 15:32 - 2025-01-08 15:32 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2025-01-08 15:31 - 2025-01-08 15:31 - 000000000 ____D C:\Windows\system32\Drivers\NVIDIA Corporation
2025-01-08 15:31 - 2024-08-19 11:12 - 002031464 _____ C:\Windows\system32\vulkaninfo-1-999-0-0-0.exe
2025-01-08 15:31 - 2024-08-19 11:12 - 002031464 _____ C:\Windows\system32\vulkaninfo.exe
2025-01-08 15:31 - 2024-08-19 11:12 - 001578752 _____ C:\Windows\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2025-01-08 15:31 - 2024-08-19 11:12 - 001578752 _____ C:\Windows\SysWOW64\vulkaninfo.exe
2025-01-08 15:31 - 2024-08-19 11:12 - 001445120 _____ C:\Windows\system32\vulkan-1-999-0-0-0.dll
2025-01-08 15:31 - 2024-08-19 11:12 - 001295232 _____ C:\Windows\SysWOW64\vulkan-1-999-0-0-0.dll
2025-01-08 15:31 - 2024-08-19 11:12 - 000477840 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2025-01-08 15:31 - 2024-08-19 11:12 - 000374392 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2025-01-08 15:31 - 2024-08-19 11:09 - 001068688 _____ (NVIDIA Corporation) C:\Windows\system32\nvml.dll
2025-01-08 15:31 - 2024-08-19 11:09 - 000670344 _____ (NVIDIA Corporation) C:\Windows\system32\nvofapi64.dll
2025-01-08 15:31 - 2024-08-19 11:09 - 000506016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvofapi.dll
2025-01-08 15:31 - 2024-08-19 11:08 - 002180728 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2025-01-08 15:31 - 2024-08-19 11:08 - 001631368 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2025-01-08 15:31 - 2024-08-19 11:08 - 001549320 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2025-01-08 15:31 - 2024-08-19 11:08 - 001204856 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2025-01-08 15:31 - 2024-08-19 11:08 - 000847992 _____ (NVIDIA Corporation) C:\Windows\system32\nvidia-smi.exe
2025-01-08 15:31 - 2024-08-19 11:07 - 016119432 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2025-01-08 15:31 - 2024-08-19 11:07 - 013009064 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2025-01-08 15:31 - 2024-08-19 11:07 - 006914696 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2025-01-08 15:31 - 2024-08-19 11:07 - 005914248 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2025-01-08 15:31 - 2024-08-19 11:07 - 005867680 _____ (NVIDIA Corporation) C:\Windows\system32\nvcudadebugger.dll
2025-01-08 15:31 - 2024-08-19 11:07 - 003788936 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2025-01-08 15:31 - 2024-08-19 11:07 - 000460936 _____ (NVIDIA Corporation) C:\Windows\system32\nvdebugdump.exe
2025-01-08 15:31 - 2024-08-19 11:06 - 007061976 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2025-01-08 15:31 - 2024-08-19 11:06 - 006142728 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2025-01-08 15:31 - 2024-08-19 11:06 - 000853528 _____ (NVIDIA Corporation) C:\Windows\system32\MCU.exe
2025-01-08 15:31 - 2024-08-19 10:33 - 000123973 _____ C:\Windows\system32\nvinfo.pb
2025-01-08 11:40 - 2019-12-30 07:46 - 002626704 _____ (Sunplus Innovation Technology Inc.) C:\Windows\system32\SPITDevMft64.dll
2025-01-08 11:38 - 2025-01-08 17:16 - 000791266 _____ C:\Windows\system32\PerfStringBackup.INI
2025-01-08 11:29 - 2025-01-08 11:29 - 000000000 ____D C:\Windows\CSC
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2025-01-08 21:25 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\WinBioDatabase
2025-01-08 21:23 - 2024-04-01 09:21 - 000032768 _____ C:\Windows\system32\config\ELAM
2025-01-08 21:21 - 2024-04-01 09:26 - 000028672 _____ C:\Windows\system32\config\BCD-Template
2025-01-08 17:47 - 2024-04-01 09:24 - 000000000 ____D C:\Windows\INF
2025-01-08 17:45 - 2024-04-01 09:26 - 000000000 ___HD C:\Program Files\WindowsApps
2025-01-08 17:45 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\AppReadiness
2025-01-08 17:44 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\SecurityHealth
2025-01-08 17:43 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\appcompat
2025-01-08 17:42 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SystemTemp
2025-01-08 17:38 - 2024-04-01 09:26 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2025-01-08 17:27 - 2024-04-01 09:26 - 000000000 ____D C:\ProgramData\USOPrivate
2025-01-08 17:08 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\Drivers\DriverData
2025-01-08 17:08 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\ServiceState
2025-01-08 17:08 - 2024-04-01 09:21 - 000524288 _____ C:\Windows\system32\config\BBI
2025-01-08 17:07 - 2024-04-01 10:03 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2025-01-08 17:07 - 2024-04-01 09:26 - 000000000 ___SD C:\Windows\system32\UNP
2025-01-08 17:07 - 2024-04-01 09:26 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2025-01-08 17:07 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\UUS
2025-01-08 17:07 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\WinMetadata
2025-01-08 17:07 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\setup
2025-01-08 17:07 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SysWOW64\Dism
2025-01-08 17:07 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\SystemResources
2025-01-08 17:07 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\WinMetadata
2025-01-08 17:07 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\WinBioPlugIns
2025-01-08 17:07 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\ShellExperiences
2025-01-08 17:07 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\Sgrm
2025-01-08 17:07 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\setup
2025-01-08 17:07 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\SecureBootUpdates
2025-01-08 17:07 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\PerceptionSimulation
2025-01-08 17:07 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\oobe
2025-01-08 17:07 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\migwiz
2025-01-08 17:07 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\HealthAttestationClient
2025-01-08 17:07 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\Dism
2025-01-08 17:07 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\appraiser
2025-01-08 17:07 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\ShellExperiences
2025-01-08 17:07 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\ShellComponents
2025-01-08 17:07 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\Provisioning
2025-01-08 17:07 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\PolicyDefinitions
2025-01-08 17:07 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\bcastdvr
2025-01-08 17:07 - 2024-04-01 09:26 - 000000000 ____D C:\Program Files\Common Files\System
2025-01-08 11:29 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\spool
2025-01-08 11:29 - 2024-04-01 09:26 - 000000000 ____D C:\Windows\system32\AppLocker
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== BCD ================================
Firmware Boot Manager
---------------------
identifier {fwbootmgr}
displayorder {bootmgr}
{496b2c5e-cdf5-11ef-a4cd-f3c4e7e94054}
{496b2c5f-cdf5-11ef-a4cd-f3c4e7e94054}
{496b2c60-cdf5-11ef-a4cd-f3c4e7e94054}
{496b2c61-cdf5-11ef-a4cd-f3c4e7e94054}
{496b2c5c-cdf5-11ef-a4cd-f3c4e7e94054}
{496b2c5d-cdf5-11ef-a4cd-f3c4e7e94054}
{496b2c64-cdf5-11ef-a4cd-f3c4e7e94054}
timeout 0
Windows Boot Manager
--------------------
identifier {bootmgr}
device partition=\Device\HarddiskVolume1
path \EFI\Microsoft\Boot\bootmgfw.efi
description Windows Boot Manager
locale en-US
inherit {globalsettings}
default {current}
resumeobject {496b2c65-cdf5-11ef-a4cd-f3c4e7e94054}
displayorder {current}
toolsdisplayorder {memdiag}
timeout 30
Firmware Application (101fffff)
-------------------------------
identifier {496b2c5c-cdf5-11ef-a4cd-f3c4e7e94054}
description Wi-Fi IPV4 Network
Firmware Application (101fffff)
-------------------------------
identifier {496b2c5d-cdf5-11ef-a4cd-f3c4e7e94054}
description Wi-Fi IPV6 Network
Firmware Application (101fffff)
-------------------------------
identifier {496b2c5e-cdf5-11ef-a4cd-f3c4e7e94054}
description IPV4 Network - Realtek PCIe GBE Family Controller
Firmware Application (101fffff)
-------------------------------
identifier {496b2c5f-cdf5-11ef-a4cd-f3c4e7e94054}
description IPV6 Network - Realtek PCIe GBE Family Controller
Firmware Application (101fffff)
-------------------------------
identifier {496b2c60-cdf5-11ef-a4cd-f3c4e7e94054}
description USB NETWORK BOOT:
Firmware Application (101fffff)
-------------------------------
identifier {496b2c61-cdf5-11ef-a4cd-f3c4e7e94054}
description USB NETWORK BOOT:
Firmware Application (101fffff)
-------------------------------
identifier {496b2c62-cdf5-11ef-a4cd-f3c4e7e94054}
path EFI\Microsoft\Boot\bootmgfw.efi
description EFI\Microsoft\Boot\bootmgfw.efi
Firmware Application (101fffff)
-------------------------------
identifier {496b2c64-cdf5-11ef-a4cd-f3c4e7e94054}
description SanDisk Cruzer Blade 03025628051721142823
Windows Boot Loader
-------------------
identifier {current}
device partition=C:
path \Windows\system32\winload.efi
description Windows 11
locale en-US
inherit {bootloadersettings}
recoverysequence {496b2c67-cdf5-11ef-a4cd-f3c4e7e94054}
displaymessageoverride Recovery
recoveryenabled Yes
isolatedcontext Yes
allowedinmemorysettings 0x15000075
osdevice partition=C:
systemroot \Windows
resumeobject {496b2c65-cdf5-11ef-a4cd-f3c4e7e94054}
nx OptIn
bootmenupolicy Standard
Windows Boot Loader
-------------------
identifier {496b2c67-cdf5-11ef-a4cd-f3c4e7e94054}
device ramdisk=[unknown]\Recovery\WindowsRE\Winre.wim,{496b2c68-cdf5-11ef-a4cd-f3c4e7e94054}
path \windows\system32\winload.efi
description Windows Recovery Environment
locale en-us
inherit {bootloadersettings}
displaymessage Recovery
osdevice ramdisk=[unknown]\Recovery\WindowsRE\Winre.wim,{496b2c68-cdf5-11ef-a4cd-f3c4e7e94054}
systemroot \windows
nx OptIn
bootmenupolicy Standard
winpe Yes
Resume from Hibernate
---------------------
identifier {496b2c65-cdf5-11ef-a4cd-f3c4e7e94054}
device partition=C:
path \Windows\system32\winresume.efi
description Windows Resume Application
locale en-US
inherit {resumeloadersettings}
recoverysequence {496b2c67-cdf5-11ef-a4cd-f3c4e7e94054}
recoveryenabled Yes
isolatedcontext Yes
allowedinmemorysettings 0x15000075
filedevice partition=C:
custom:21000026 partition=C:
filepath \hiberfil.sys
bootmenupolicy Standard
debugoptionenabled No
Windows Memory Tester
---------------------
identifier {memdiag}
device partition=\Device\HarddiskVolume1
path \EFI\Microsoft\Boot\memtest.efi
description Windows Memory Diagnostic
locale en-US
inherit {globalsettings}
badmemoryaccess Yes
EMS Settings
------------
identifier {emssettings}
bootems No
Debugger Settings
-----------------
identifier {dbgsettings}
debugtype Local
RAM Defects
-----------
identifier {badmemory}
Global Settings
---------------
identifier {globalsettings}
inherit {dbgsettings}
{emssettings}
{badmemory}
Boot Loader Settings
--------------------
identifier {bootloadersettings}
inherit {globalsettings}
{hypervisorsettings}
Hypervisor Settings
-------------------
identifier {hypervisorsettings}
hypervisordebugtype Serial
hypervisordebugport 1
hypervisorbaudrate 115200
Resume Loader Settings
----------------------
identifier {resumeloadersettings}
inherit {globalsettings}
==================== End of FRST.txt ========================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 04-01-2025
Ran by judyz (08-01-2025 17:49:06)
Running from C:\Users\judyz\Downloads
Microsoft Windows 11 Pro Version 24H2 26100.2605 (X64) (2025-01-08 19:25:39)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
(If an entry is included in the fixlist, it will be removed.)
Administrator (S-1-5-21-1365236912-114835092-1529061894-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-1365236912-114835092-1529061894-503 - Limited - Disabled)
Guest (S-1-5-21-1365236912-114835092-1529061894-501 - Limited - Disabled)
judyz (S-1-5-21-1365236912-114835092-1529061894-1001 - Administrator - Enabled) => C:\Users\judyz
WDAGUtilityAccount (S-1-5-21-1365236912-114835092-1529061894-504 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 131.0.2903.112 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 131.0.2903.112 - Microsoft Corporation) Hidden
Microsoft OneDrive (HKU\S-1-5-21-1365236912-114835092-1529061894-1001\...\OneDriveSetup.exe) (Version: 24.226.1110.0004 - Microsoft Corporation)
NVIDIA Graphics Driver 556.12 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 556.12 - NVIDIA Corporation)
Packages:
=========
NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.967.0_x64__56jybvy8sckqj [2025-01-08] (NVIDIA Corp.)
Solitaire & Casual Games -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.19.3190.0_x64__8wekyb3d8bbwe [2025-01-08] (Microsoft Studios) [MS Ad]
==================== Custom CLSID (Whitelisted): ==============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\System32\DriverStore\FileRepository\nvbl.inf_amd64_bb28b4bb5c7c0290\nvshext.dll [2024-08-19] (NVIDIA Corporation -> NVIDIA Corporation)
==================== Codecs (Whitelisted) ====================
==================== Shortcuts & WMI ========================
==================== Loaded Modules (Whitelisted) =============
==================== Alternate Data Streams (Whitelisted) ========
==================== Safe Mode (Whitelisted) ==================
==================== Association (Whitelisted) =================
==================== Internet Explorer (Whitelisted) =============
==================== Hosts content: =========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2024-04-01 09:26 - 2024-04-01 09:24 - 000000824 _____ C:\Windows\system32\drivers\etc\hosts
==================== Other Areas ===========================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-1365236912-114835092-1529061894-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\DesktopSpotlight\Assets\Images\image_2.jpg
DNS Servers: 163.121.128.134 - 163.121.128.135
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
Network Binding:
=============
Ethernet: Realtek PCIe GbE Family Controller -> rtcx21x64.sys
Bluetooth Network Connection: Bluetooth Device (Personal Area Network) -> bthpan.sys
Wi-Fi: Intel® Wi-Fi 6 AX201 160MHz -> Netwtw10.sys
==================== MSCONFIG/TASK MANAGER disabled items ==
==================== FirewallRules (Whitelisted) ================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{515355E1-FAEE-439D-8B5B-6A7B7BC278E0}] => (Allow) C:\Program Files\WindowsApps\MSTeams_24295.605.3225.8804_x64__8wekyb3d8bbwe\ms-teams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{139E9CAB-6FD1-43CD-979A-E2A9A509E443}] => (Allow) C:\Program Files\WindowsApps\MSTeams_24295.605.3225.8804_x64__8wekyb3d8bbwe\ms-teams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{45CE6E2A-F025-4EB4-B771-55281F25264C}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\131.0.2903.112\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)
==================== Restore Points =========================
08-01-2025 11:30:16 Windows Modules Installer
==================== Faulty Device Manager Devices ============
==================== Event log errors: ========================
Application errors:
==================
Error: (01/08/2025 11:29:46 AM) (Source: SecurityCenter) (EventID: 16) (User: )
Description: Error while updating Windows Defender status to SECURITY_PRODUCT_STATE_ON.
Error: (01/08/2025 09:25:48 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: SCEP Certificate enrollment initialization for WORKGROUP\WIN-35VJ22MDFU8$ via https://NTC-KeyId-23f4e22ad3be374a449772954aa283aed752572e.microsoftaik.azure.net/templates/Aik/scep failed:
GetCACaps
Method: GET(16ms)
Stage: GetCACaps
The server name or address could not be resolved 0x80072ee7 (WinHttp: 12007 ERROR_WINHTTP_NAME_NOT_RESOLVED)
Error: (01/08/2025 09:25:47 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: SCEP Certificate enrollment initialization for Local system via https://NTC-KeyId-23f4e22ad3be374a449772954aa283aed752572e.microsoftaik.azure.net/templates/Aik/scep failed:
GetCACaps
Method: GET(0ms)
Stage: GetCACaps
The server name or address could not be resolved 0x80072ee7 (WinHttp: 12007 ERROR_WINHTTP_NAME_NOT_RESOLVED)
Error: (01/08/2025 09:25:47 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: SCEP Certificate enrollment initialization for WORKGROUP\WIN-35VJ22MDFU8$ via https://NTC-KeyId-23f4e22ad3be374a449772954aa283aed752572e.microsoftaik.azure.net/templates/Aik/scep failed:
GetCACaps
Method: GET(31ms)
Stage: GetCACaps
The server name or address could not be resolved 0x80072ee7 (WinHttp: 12007 ERROR_WINHTTP_NAME_NOT_RESOLVED)
Error: (01/08/2025 09:23:37 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: SCEP Certificate enrollment initialization for \MINWINPC$ via https://NTC-KeyId-23f4e22ad3be374a449772954aa283aed752572e.microsoftaik.azure.net/templates/Aik/scep failed:
GetCACaps
Method: GET(0ms)
Stage: GetCACaps
The server name or address could not be resolved 0x80072ee7 (WinHttp: 12007 ERROR_WINHTTP_NAME_NOT_RESOLVED)
Error: (01/08/2025 09:23:37 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: SCEP Certificate enrollment initialization for Local system via https://NTC-KeyId-23f4e22ad3be374a449772954aa283aed752572e.microsoftaik.azure.net/templates/Aik/scep failed:
GetCACaps
Method: GET(16ms)
Stage: GetCACaps
The server name or address could not be resolved 0x80072ee7 (WinHttp: 12007 ERROR_WINHTTP_NAME_NOT_RESOLVED)
System errors:
=============
Error: (01/08/2025 05:42:01 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x8024200b: Intel Corporation - System - 30.100.2020.7.
Error: (01/08/2025 05:39:22 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error (0x80073d02 = The package could not be installed because resources it modifies are currently in use.): 9MSSGKG348SP-MicrosoftWindows.Client.WebExperience.
Error: (01/08/2025 05:39:14 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80240016: 9NBLGGH4RV3K-Microsoft.VCLibs.140.00.UWPDesktop.
Error: (01/08/2025 05:39:13 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80240016: 9NBLGGH3FRZM-Microsoft.VCLibs.140.00.
Error: (01/08/2025 05:10:43 PM) (Source: Microsoft-Windows-TPM-WMI) (EventID: 1796) (User: NT AUTHORITY)
Description: The Secure Boot update failed to update a Secure Boot variable with error (-2147020471 = Secure Boot is not enabled on this machine.). For more information, please see https://go.microsoft.com/fwlink/?linkid=2169931
Error: (01/08/2025 05:07:18 PM) (Source: DCOM) (EventID: 10005) (User: NT AUTHORITY)
Description: DCOM got error "1115" attempting to start the service wuauserv with arguments "Unavailable" in order to run the server:
{E60687F7-01A1-40AA-86AC-DB1CBF673334}
Error: (01/08/2025 05:07:16 PM) (Source: DCOM) (EventID: 10005) (User: NT AUTHORITY)
Description: DCOM got error "1115" attempting to start the service wuauserv with arguments "Unavailable" in order to run the server:
{E60687F7-01A1-40AA-86AC-DB1CBF673334}
Error: (01/08/2025 05:07:16 PM) (Source: DCOM) (EventID: 10005) (User: NT AUTHORITY)
Description: DCOM got error "1115" attempting to start the service wuauserv with arguments "Unavailable" in order to run the server:
{E60687F7-01A1-40AA-86AC-DB1CBF673334}
CodeIntegrity:
===============
Date: 2025-01-08 17:19:52
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_d132a4045a2a0202\igd10iumd64.dll that did not meet the Custom 3 / Antimalware signing level requirements.
==================== Memory info ===========================
BIOS: HP S71 Ver. 01.22.01 08/23/2024
Motherboard: HP 86A0
Processor: Intel® Core i7-10510U CPU @ 1.80GHz
Percentage of memory in use: 80%
Total physical RAM: 8038.01 MB
Available physical RAM: 1591.34 MB
Total Virtual: 9958.01 MB
Available Virtual: 2558.22 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:953.13 GB) (Free:904.35 GB) (Model: NVMe PC SN730 NVMe WD) NTFS
\\?\Volume{b7f5c6a0-62ae-4b7b-9603-578a1d71fee9}\ () (Fixed) (Total:0.09 GB) (Free:0.06 GB) FAT32
==================== MBR & Partition Table ====================
==========================================================
Disk: 0 (Protective MBR) (Size: 953.9 GB) (Disk ID: 00000000)
Partition: GPT.
==================== End of Addition.txt =======================
Edited by Oh My!, 08 January 2025 - 11:12 AM.



This topic is locked
Back to top







