First off title is Sam
Sorry for the delay rolling blackouts resulting from climate.
Second the one entry I’ve to the affected laptop is thru the restore laptop / superior choices / command immediate.. Different clever laptop computer display goes black after I enter my password.
working frst as you requested with the above exception
Scan results of Farbar Restoration Scan Device (FRST) (x64) Model: 13-02-2021
Ran by SYSTEM on MININT-31IN7FR (05-02-2021 00:18:13)
Working from F:
Platform: Home windows 10 House Model 1903 18362.900 (X64) Language: English (United States)
Boot Mode: Restoration
Default: ControlSet001
ATTENTION!:=====> If the system is bootable FRST have to be run from regular or Protected mode to create a whole log.
==================== Registry (Whitelisted) ===================
(If an entry is included within the fixlist, the registry merchandise can be restored to default or eliminated. The file won’t be moved.)
HKLM…Run: [ForteConfig] => C:Program FilesConexantForteConfigfmapp.exe [49056 2010-10-26] (Fortemedia Inc -> )
HKLM…Run: [cAudioFilterAgent] => C:Program FilesConexantcAudioFilterAgentcAudioFilterAgent64.exe [919768 2014-11-20] (Conexant Techniques, Inc. -> Conexant Techniques, Inc.)
HKLM…Run: [MFNetworkScanUtility] => C:Program FilesCanonCanon MF Community Scan UtilityCNMFSUT6.EXE [486552 2012-09-27] (CANON INC. -> CANON INC.)
HKLM…Run: [LenovoUtility] => C:ProgramDataLenovoImControllerPluginsIdeaOSDPackagex64utility.exe [911272 2017-07-27] (LENOVO -> Lenovo(beijing) Restricted)
HKLM…Run: [AdobeAAMUpdater-1.0] => C:Program Information (x86)Frequent FilesAdobeOOBEPDAppUWAUpdaterStartupUtility.exe [509936 2018-04-10] (Adobe Techniques Included -> Adobe Techniques Included)
HKLM…Run: [AdobeGCInvoker-1.0] => C:Program Information (x86)Frequent FilesAdobeAdobeGCClientAGCInvokerUtility.exe [3402832 2020-09-23] (Adobe Inc. -> Adobe Techniques, Included)
HKLM…Run: [SmartAudio] => C:Program FilesCONEXANTSAIISACpl.exe [1830616 2014-04-10] (Conexant Techniques, Inc. -> Conexant Techniques, Inc.)
HKLM…Run: [StartCN] => C:Program FilesAMDCNextCNextRadeonSettings.exe [8029064 2016-12-16] (Superior Micro Gadgets, Inc. -> Superior Micro Gadgets, Inc.)
HKLM…Run: [Logitech Download Assistant] => C:WindowsSystem32LogiLDA.dll [3942864 2016-10-13] (Logitech -> Logitech, Inc.)
HKLM-x32…Run: [CLMLServer_For_P2G8] => C:Program Information (x86)LenovoPower2GoCLMLSvc_P2G8.exe [110344 2014-09-09] (CyberLink Corp. -> CyberLink)
HKLM-x32…Run: [CLVirtualDrive] => C:Program Information (x86)LenovoPower2GoVirtualDrive.exe [492808 2014-09-09] (CyberLink Corp. -> CyberLink Corp.)
HKLM-x32…Run: [Adobe Creative Cloud] => C:Program FilesAdobeAdobe Artistic CloudACCCreative Cloud.exe [2042424 2020-03-15] (Adobe Inc. -> Adobe Inc.)
HKLM-x32…Run: [Acrobat Assistant 8.0] => C:Program Information (x86)AdobeAcrobat DCAcrobatAcrotray.exe [5641776 2020-05-03] (Adobe Inc. -> Adobe Techniques Inc.)
HKLM-x32…Run: [] => [X]
HKUsstub…Run: [Steam] => C:Program Information (x86)Steamsteam.exe [3375904 2020-06-01] (Valve -> Valve Company)
HKUsstub…Run: [PhotoMasterImportAgent] => C:Program Information (x86)LenovoLenovo Photograph MasterPhotoMasterImportAgent.exe [675608 2016-09-21] (CyberLink Corp. -> CyberLink Corp.)
HKUsstub…Run: [Adobe Acrobat Synchronizer] => C:Program Information (x86)AdobeAcrobat DCAcrobatAdobeCollabSync.exe [5417008 2020-05-03] (Adobe Inc. -> Adobe Techniques Included)
HKUsstub…Run: [CCXProcess] => C:Program FilesAdobeAdobe Artistic Cloud ExperienceCCXProcess.exe [648328 2020-04-13] (Adobe Inc. -> Adobe Techniques Included)
HKUsstub…RunOnce: [Application Restart #0] => C:Program Information (x86)Frequent FilesAdobeAdobe Desktop CommonADSAdobe Desktop Service.exe [2598968 2020-03-15] (Adobe Inc. -> Adobe Inc.)
HKUsstub…RunOnce: [Delete Cached Update Binary] => C:WINDOWSsystem32cmd.exe /q /c del /q “C:UserssstubAppDataLocalMicrosoftOneDriveUpdateOneDriveSetup.exe”
HKUsstub…RunOnce: [Delete Cached Standalone Update Binary] => C:WINDOWSsystem32cmd.exe /q /c del /q “C:UserssstubAppDataLocalMicrosoftOneDriveStandaloneUpdaterOneDriveSetup.exe”
HKUsstub…RunOnce: [Uninstall 20.052.0311.0011amd64] => C:WINDOWSsystem32cmd.exe /q /c rmdir /s /q “C:UserssstubAppDataLocalMicrosoftOneDrive20.052.0311.0011amd64”
HKUsstub…RunOnce: [Uninstall 20.052.0311.0011] => C:WINDOWSsystem32cmd.exe /q /c rmdir /s /q “C:UserssstubAppDataLocalMicrosoftOneDrive20.052.0311.0011”
HKUtrail…Run: [CCXProcess] => C:Program FilesAdobeAdobe Artistic Cloud ExperienceCCXProcess.exe [648328 2020-04-13] (Adobe Inc. -> Adobe Techniques Included)
HKUtrail…Run: [Discord] => C:UserstrailAppDataLocalDiscordapp-0.0.306Discord.exe [90950968 2020-02-24] (Discord Inc. -> Discord Inc.)
HKUtrail…RunOnce: [Application Restart #2] => C:Program Information (x86)GoogleChromeApplicationchrome.exe –flag-switches-begin –flag-switches-end –enable-audio-service-sandbox –flag-switches-begin –flag-switches-end –enable-audio-service-s (the info entry has 102 extra characters).
HKUtrail…RunOnce: [Application Restart #1] => C:Program Information (x86)GoogleChromeApplicationchrome.exe –flag-switches-begin –flag-switches-end –enable-audio-service-sandbox –flag-switches-begin –flag-switches-end –enable-audio-service-s (the info entry has 102 extra characters).
HKUtrail…RunOnce: [Application Restart #0] => C:Program Information (x86)Frequent FilesAdobeAdobe Desktop CommonADSAdobe Desktop Service.exe [2598968 2020-03-15] (Adobe Inc. -> Adobe Inc.)
HKUtrail…RunOnce: [Delete Cached Update Binary] => C:WINDOWSsystem32cmd.exe /q /c del /q “C:UserstrailAppDataLocalMicrosoftOneDriveUpdateOneDriveSetup.exe”
HKUtrail…RunOnce: [Delete Cached Standalone Update Binary] => C:WINDOWSsystem32cmd.exe /q /c del /q “C:UserstrailAppDataLocalMicrosoftOneDriveStandaloneUpdaterOneDriveSetup.exe”
HKLM…PrintMonitorsAdobe PDF Port Monitor: C:Windowssystem32AdobePDF.dll [65488 2019-12-02] (Adobe Inc. -> Adobe Techniques Inc)
HKLM…PrintMonitorsCanon MFNP Port: C:Windowssystem32CNCENPM6.dll [153088 2016-02-10] (CANON INC.)
HKLM…PrintMonitorsCanon WSD Language Monitor: C:Windowssystem32cnnx0_flm.dll [1420800 2013-02-25] (CANON INC.)
HKLM…PrintMonitorsCPCA Language Monitor3b: C:Windowssystem32CNAS0MOK.DLL [1006080 2012-08-09] (CANON INC.)
HKLM…PrintMonitorsTif Port: C:Windowssystem32v_localmon_rc.dll [23552 2016-09-30] (Copyright© RingCentral, inc.)
==================== Scheduled Duties (Whitelisted) ============
(If an entry is included within the fixlist, will probably be faraway from the registry. The file won’t be moved until listed individually.)
Activity: {0D14106E-14EC-4A44-B98F-813FC627E1D4} – System32TasksMicrosoftOfficeOffice Automated Updates 2.0 => C:Program FilesCommon FilesMicrosoft SharedClickToRunOfficeC2RClient.exe [23054216 2020-12-07] (Microsoft Company -> Microsoft Company)
Activity: {0DDEB7F0-39CD-47B2-8A5C-BBB136688D60} – System32TasksLenovoLSCLSCHardwareScanPostpone => C:Program FilesLenovoLenovo Answer CenterLSC.exe [9476544 2015-08-07] (LENOVO -> )
Activity: {115F2555-53E6-4071-BDFF-B98641B756AD} – System32TasksMicrosoftOfficeOffice Characteristic Updates => C:Program Information (x86)Microsoft OfficerootOffice16sdxhelper.exe [116584 2020-12-17] (Microsoft Company -> Microsoft Company)
Activity: {1167647D-E157-4DD8-9E89-5EBE3196A43F} – System32TasksLenovoLSCLSCHardwareScan => C:Program FilesLenovoLenovo Answer CenterLSC.exe [9476544 2015-08-07] (LENOVO -> )
Activity: {12228450-524C-48AA-ADD1-E4F2D37C5B89} – System32TasksLenovoImControllerPluginsLenovoSystemUpdatePlugin_WeeklyTask => %windirpercentSystem32reg.exe add hklmSOFTWARELenovoSystemUpdatePluginscheduler /v begin /t reg_dword /d 1 /f /reg:32
Activity: {15F991ED-79F0-4A46-967C-A38E2E8F3EB9} – System32TasksMicrosoftOfficeOffice ClickToRun Service Monitor => C:Program FilesCommon FilesMicrosoft SharedClickToRunOfficeC2RClient.exe [23054216 2020-12-07] (Microsoft Company -> Microsoft Company)
Activity: {1B590AFD-CBC9-4CDE-97A0-56C58B5BA20F} – MicrosoftWindowsUNPRunCampaignManager -> No File <==== ATTENTION
Activity: {1BDDAB3C-B1F0-4062-8D82-F98D132CBDDE} – System32TasksG2MUploadTask-S-1-5-21-1080762102-1500660939-3740112618-1002 => C:UserssstubAppDataLocalGoToMeeting17956g2mupload.exe [32424 2020-06-08] (LogMeIn, Inc. -> LogMeIn, Inc.)
Activity: {1C7E9CDE-29C5-4783-9FAA-16B12BC2099B} – System32TasksLenovoImControllerLenovo iM Controller Scheduled Upkeep => “%windirpercentsystem32sc.exe” START ImControllerService
Activity: {1D55D1D7-37DB-4A60-B0CB-DDD074E9CE72} – System32TasksPDVDServ12 Activity => C:Program Information (x86)LenovoPowerDVD12PDVD12Serv.exe [85432 2015-05-28] (CyberLink Corp. -> CyberLink Corp.)
Activity: {206C9449-1C46-4C85-9C88-71992EE3A9D7} – System32TasksMicrosoftWindowsPLALSC Reminiscence => C:Windowssystem32rundll32.exe C:Windowssystem32pla.dll,PlaHost “LSC Reminiscence” “$(Arg0)”
Activity: {35D54AE6-5884-4CCF-88A0-2D0D3587B384} – System32TasksAdobe Acrobat Replace Activity => C:Program Information (x86)Frequent FilesAdobeARM1.0AdobeARM.exe [1242704 2020-02-25] (Adobe Inc. -> Adobe Techniques)
Activity: {361B69E8-DF03-4A17-9071-F9E87431F5F4} – System32TasksCyberLinkPhoto Grasp Gadget startup => C:Program Information (x86)LenovoLenovo Photograph MasterPhotoMasterWorker.exe [745240 2016-09-21] (CyberLink Corp. -> CyberLink Corp.)
Activity: {42775632-DE48-409C-B42B-E379E294D463} – System32TasksLenovoExperience Enchancment => C:Program FilesLenovoExperienceImprovementLenovoExperienceImprovement.exe [287688 2016-11-25] (LENOVO -> Lenovo)
Activity: {446CC90E-2DF3-4ADC-82B7-EEC228E994F4} – System32TasksLenovoLenovo Buyer Suggestions Program 64 35 => C:Program Information (x86)LenovoCustomer Suggestions Program 35Lenovo.TVT.CustomerFeedback.Agent35.exe [16832 2015-07-06] (LENOVO -> Lenovo)
Activity: {502973DE-4041-4FED-A040-3CA208A1D392} – System32TasksLenovoImControllerTimeBasedEventsb19642f6-1761-4742-81e2-68447a588085 => C:WINDOWSLenovoImControllerServiceLenovo.Trendy.ImController.exe [81240 2020-07-15] (Lenovo -> Lenovo Group Ltd.)
Activity: {5DAB852D-FF1F-4920-852F-FD0D8125EB78} – System32TasksLenovoSHPrompt => C:Program Information (x86)LenovoSHAREitShareitPrompt.exe [829344 2015-07-12] (LENOVO -> )
Activity: {63C5794D-05E9-40F0-B851-25F26BC12027} – System32TasksLenovoImControllerTimeBasedEvents826b7c73-37ec-4874-9ecd-400e88a87598 => C:WINDOWSLenovoImControllerServiceLenovo.Trendy.ImController.exe [81240 2020-07-15] (Lenovo -> Lenovo Group Ltd.)
Activity: {6926B56F-F11C-44E2-9942-2D0D6D8C793A} – System32TasksLenovoImControllerTimeBasedEvents1b6b7331-d1ed-45b0-b534-b4ce7abd492a => C:WINDOWSLenovoImControllerServiceLenovo.Trendy.ImController.exe [81240 2020-07-15] (Lenovo -> Lenovo Group Ltd.)
Activity: {6ECD3852-94CA-4A97-8002-95FB145CCD68} – System32TasksLenovoLSCLenovo Answer Heart Notifications => C:Program FilesLenovoLenovo Answer CenterLSCNotify.exe [1320384 2015-08-07] (LENOVO -> Lenovo)
Activity: {817408F7-509E-42A8-88B1-B795D99584C8} – System32TasksLenovoImControllerLenovo iM Controller Monitor => C:Windowssystem32ImController.InfInstaller.exe [56136 2020-07-15] (Lenovo -> Lenovo Group Ltd.)
Activity: {9088B1D1-E635-473C-ACEC-BB7CE871B40F} – System32TasksLenovoBatteryGaugeBatteryGaugeMaintenance => C:ProgramDataLenovoImControllerPluginsLenovoBatteryGaugePackagex64BGHelper.exe [141752 2020-05-27] (Lenovo -> Lenovo Group Ltd.)
Activity: {9A2D2E20-ABF9-4610-8228-889DA647BB4B} – System32TasksMicrosoftWindowsWindows DefenderWindows Defender Verification => C:ProgramDataMicrosoftWindows Defenderplatform4.18.2011.6-0MpCmdRun.exe [545704 2020-12-03] (Microsoft Home windows Writer -> Microsoft Company)
Activity: {9F209517-CDF0-4873-A553-5460F7B7D9C6} – System32TasksG2MUpdateTask-S-1-5-21-1080762102-1500660939-3740112618-1002 => C:UserssstubAppDataLocalGoToMeeting17956g2mupdate.exe [32424 2020-06-08] (LogMeIn, Inc. -> LogMeIn, Inc.)
Activity: {9F6D8D22-B483-488A-A695-5F469B34D883} – System32TasksLenovoREACHit Agent Replace => C:Program Information (x86)LenovoREACHitwebAgent.exe [552912 2015-02-09] (LENOVO -> Lenovo)
Activity: {A2DC1018-2EC0-48FE-B87D-385900E5A295} – System32TasksMicrosoftWindowsWindows DefenderWindows Defender Cache Upkeep => C:ProgramDataMicrosoftWindows Defenderplatform4.18.2011.6-0MpCmdRun.exe [545704 2020-12-03] (Microsoft Home windows Writer -> Microsoft Company)
Activity: {A90125DA-34B2-473C-B20F-168A0054E13F} – System32TasksLenovoREACHit Agent Startup => C:Program Information (x86)LenovoREACHitwebAgent.exe [552912 2015-02-09] (LENOVO -> Lenovo)
Activity: {AB300F35-4DDA-45D0-80B8-F5331536D7AC} – System32TasksLenovoImControllerTimeBasedEvents 87483ee-9f9b-404e-b75e-789c24627d69 => C:WINDOWSLenovoImControllerServiceLenovo.Trendy.ImController.exe [81240 2020-07-15] (Lenovo -> Lenovo Group Ltd.)
Activity: {AE6C24CB-03AA-4852-BB54-E8BB52A42B62} – System32TasksGoogleUpdateTaskMachineCore => C:Program Information (x86)GoogleUpdateGoogleUpdate.exe [153752 2016-11-26] (Google Inc -> Google Inc.)
Activity: {AE6F0C15-A43A-4590-A4C5-61B45AC6551A} – System32TasksLenovoVantageLenovo.Vantage.ServiceMaintainance => %systemrootpercentsystem32sc.exe begin LenovoVantageService
Activity: {B0472E5B-323E-448E-8AD9-3793CE14BEB9} – System32TasksMicrosoftWindowsWindows DefenderWindows Defender Cleanup => C:ProgramDataMicrosoftWindows Defenderplatform4.18.2011.6-0MpCmdRun.exe [545704 2020-12-03] (Microsoft Home windows Writer -> Microsoft Company)
Activity: {B2C8C49B-6C9D-41F8-AB36-E490BAD5747E} – System32TasksGoogleUpdateTaskMachineUA => C:Program Information (x86)GoogleUpdateGoogleUpdate.exe [153752 2016-11-26] (Google Inc -> Google Inc.)
Activity: {B49C4D6F-05DF-471E-B235-059BA5719AFA} – System32TasksOneDrive Standalone Replace Activity-S-1-5-21-1080762102-1500660939-3740112618-1002 => %localappdatapercentMicrosoftOneDriveOneDriveStandaloneUpdater.exe
Activity: {B8F0DEC7-8392-4F57-9990-74FCB934033F} – System32TasksMicrosoftWindowsHelloFaceFODCleanupTask => C:WindowsSystem32WinBioPlugInsFaceFodUninstaller.exe [502272 2020-02-13] ()
Activity: {BA64C7A0-2E5D-43E4-A14E-685451A794FD} – System32TasksMicrosoftOfficeOffice Characteristic Updates Logon => C:Program Information (x86)Microsoft OfficerootOffice16sdxhelper.exe [116584 2020-12-17] (Microsoft Company -> Microsoft Company)
Activity: {C6936CFE-FF79-4D1A-B017-84B7C1F4F440} – System32TasksLenovoLenovo Answer Heart Launcher => C:Program Fileslenovolenovo answer centerAppLSCService.exe [270272 2015-08-07] (LENOVO -> Lenovo)
Activity: {CE5A8064-1B44-449B-94A8-3A84E91098B6} – System32TasksOneDrive Standalone Replace Activity-S-1-5-21-1080762102-1500660939-3740112618-1004 => %localappdatapercentMicrosoftOneDriveOneDriveStandaloneUpdater.exe
Activity: {D7DA32BB-0626-499F-B397-630F2EAB74D3} – System32TasksMicrosoftOfficeOffice Subscription Upkeep => C:Program Information (x86)Microsoft OfficerootvfsProgramFilesCommonx86Microsoft SharedOffice16OLicenseHeartbeat.exe [1149336 2020-12-17] (Microsoft Company -> Microsoft Company)
Activity: {DD8C4E87-7248-4279-A07E-B3BF2909DBFA} – System32TasksAdobeGCInvoker-1.0 => C:Program Information (x86)Frequent FilesAdobeAdobeGCClientAGCInvokerUtility.exe [3402832 2020-09-23] (Adobe Inc. -> Adobe Techniques, Included)
Activity: {E36875BE-0782-4996-AE53-3A76FEC0E06E} – System32TasksMicrosoftWindowsWindows DefenderWindows Defender Scheduled Scan => C:ProgramDataMicrosoftWindows Defenderplatform4.18.2011.6-0MpCmdRun.exe [545704 2020-12-03] (Microsoft Home windows Writer -> Microsoft Company)
Activity: {FCB77F5B-9389-445E-8163-4F34A83BA28E} – System32TasksLenovoSHUpdate => C:Program Information (x86)LenovoSHAREitShareitUpdater.exe [808352 2015-07-12] (LENOVO -> )
Activity: {FF866563-EC99-4617-A506-3BEEC871DE0F} – System32TasksOneDrive Standalone Replace Activity-S-1-5-21-1080762102-1500660939-3740112618-1005 => %localappdatapercentMicrosoftOneDriveOneDriveStandaloneUpdater.exe
(If an entry is included within the fixlist, the duty (.job) file can be moved. The file which is working by the duty won’t be moved.)
Activity: C:WindowsTasksG2MUpdateTask-S-1-5-21-1080762102-1500660939-3740112618-1002.job => C:UserssstubAppDataLocalGoToMeeting17956g2mupdate.exe
Activity: C:WindowsTasksG2MUploadTask-S-1-5-21-1080762102-1500660939-3740112618-1002.job => C:UserssstubAppDataLocalGoToMeeting17956g2mupload.exe
==================== Providers (Whitelisted) ===================
(If an entry is included within the fixlist, will probably be faraway from the registry. The file won’t be moved until listed individually.)
S2 AdobeARMservice; C:Program Information (x86)Frequent FilesAdobeARM1.0armsvc.exe [88648 2020-02-25] (Adobe Inc. -> Adobe Techniques)
S2 AdobeUpdateService; C:Program Information (x86)Frequent FilesAdobeAdobe Desktop CommonElevationManagerAdobeUpdateService.exe [820280 2020-03-15] (Adobe Inc. -> Adobe Inc.)
S2 AGMService; C:Program Information (x86)Frequent FilesAdobeAdobeGCClientAGMService.exe [3739728 2020-09-23] (Adobe Inc. -> Adobe Techniques, Included)
S2 AGSService; C:Program Information (x86)Frequent FilesAdobeAdobeGCClientAGSService.exe [3511376 2020-09-23] (Adobe Inc. -> Adobe Techniques, Included)
S2 AMD FUEL Service; C:Program FilesATI TechnologiesATI.ACEFuelFuel.Service.exe [344064 2015-08-06] (Superior Micro Gadgets, Inc.)
S2 CCSDK; C:Program Information (x86)LenovoCCSDKCCSDK.exe [688992 2017-02-27] (LENOVO -> Lenovo)
S2 ClickToRunSvc; C:Program FilesCommon FilesMicrosoft SharedClickToRunOfficeClickToRun.exe [9105800 2020-12-01] (Microsoft Company -> Microsoft Company)
S2 GDCAgent; C:Program Information (x86)LenovoGDCAgentSetupRedGDCAgent.exe [1155512 2015-07-29] (LENOVO -> Lenovo)
S2 ImControllerService; C:WindowsLenovoImControllerServiceLenovo.Trendy.ImController.exe [81240 2020-07-15] (Lenovo -> Lenovo Group Ltd.)
S3 LSCWinService; C:Program FilesLenovoLenovo Answer CenterAppLSCWinService.exe [271296 2015-08-07] (LENOVO -> Lenovo)
S4 ssh-agent; C:WindowsSystem32OpenSSHssh-agent.exe [384512 2019-03-18] ()
S3 WdNisSvc; C:ProgramDataMicrosoftWindows Defenderplatform4.18.2011.6-0NisSrv.exe [2491880 2020-12-03] (Microsoft Home windows Writer -> Microsoft Company)
S2 WinDefend; C:ProgramDataMicrosoftWindows Defenderplatform4.18.2011.6-0MsMpEng.exe [128376 2020-12-03] (Microsoft Home windows Writer -> Microsoft Company)
S2 LenovoVantageService; “C:Program Information (x86)LenovoVantageService3.2.114.0LenovoVantageService.exe” [X]
===================== Drivers (Whitelisted) ===================
(If an entry is included within the fixlist, will probably be faraway from the registry. The file won’t be moved until listed individually.)
S3 1394ohci; C:WindowsSystem32drivers1394ohci.sys [264704 2019-03-18] (Microsoft Company)
S3 AcpiDev; C:WindowsSystem32driversAcpiDev.sys [20992 2019-03-18] (Microsoft Company)
S3 acpipagr; C:WindowsSystem32driversacpipagr.sys [12800 2019-03-18] (Microsoft Company)
S3 AcpiPmi; C:WindowsSystem32driversacpipmi.sys [16896 2019-03-18] (Microsoft Company)
S3 acpitime; C:WindowsSystem32driversacpitime.sys [13824 2019-03-18] (Microsoft Company)
S3 Acx01000; C:WindowsSystem32driversAcx01000.sys [337920 2020-03-22] (Microsoft Company)
S1 afunix; C:Windowssystem32driversafunix.sys [40960 2020-03-22] (Microsoft Company)
S1 afunix; C:WindowsSysWOW64driversafunix.sys [29696 2020-03-22] (Microsoft Company)
S1 ahcache; C:WindowsSystem32DRIVERSahcache.sys [291840 2020-03-22] (Microsoft Company)
S3 amdi2c; C:WindowsSystem32driversamdi2c.sys [37888 2019-03-18] (Superior Micro Gadgets, Inc)
S3 applockerfltr; C:WindowsSystem32driversapplockerfltr.sys [18432 2019-11-14] (Microsoft Company)
S3 AsyncMac; C:WindowsSystem32driversasyncmac.sys [31232 2019-03-18] (Microsoft Company)
S3 bcmfn2; C:WindowsSystem32driversbcmfn2.sys [9728 2019-03-18] (Home windows ® Win 7 DDK supplier)
S1 Beep; C:WindowsSystem32DriversBeep.sys [10240 2019-03-18] (Microsoft Company)
S3 bowser; C:WindowsSystem32DRIVERSbowser.sys [117248 2019-03-18] (Microsoft Company)
S3 BthA2dp; C:WindowsSystem32driversBthA2dp.sys [231936 2019-09-14] (Microsoft Company)
S3 BthEnum; C:WindowsSystem32driversBthEnum.sys [114688 2020-03-22] (Microsoft Company)
S3 BthHFEnum; C:WindowsSystem32driversbthhfenum.sys [131072 2019-03-18] (Microsoft Company)
S3 BthLEEnum; C:WindowsSystem32driversMicrosoft.Bluetooth.Legacy.LEEnumerator.sys [97280 2019-03-18] (Microsoft Company)
S3 BthMini; C:WindowsSystem32driversBTHMINI.sys [36864 2020-03-22] (Microsoft Company)
S3 BTHMODEM; C:WindowsSystem32driversbthmodem.sys [76288 2019-03-18] (Microsoft Company)
S3 BthPan; C:WindowsSystem32driversbthpan.sys [133120 2019-03-18] (Microsoft Company)
S3 BTHPORT; C:WindowsSystem32driversBTHport.sys [1428992 2020-03-22] (Microsoft Company)
S3 BTHUSB; C:WindowsSystem32driversBTHUSB.sys [99328 2020-03-22] (Microsoft Company)
S3 buttonconverter; C:WindowsSystem32driversbuttonconverter.sys [43008 2019-03-18] (Microsoft Company)
S4 cdfs; C:WindowsSystem32DRIVERScdfs.sys [100352 2019-12-12] (Microsoft Company)
S1 cdrom; C:WindowsSystem32driverscdrom.sys [173056 2019-03-18] (Microsoft Company)
S3 circlass; C:WindowsSystem32driverscirclass.sys [51200 2019-03-18] (Microsoft Company)
S2 CldFlt; C:WindowsSystem32driverscldflt.sys [457216 2020-05-13] (Microsoft Company)
S3 CmBatt; C:WindowsSystem32driversCmBatt.sys [36864 2019-03-18] (Microsoft Company)
S1 Dfsc; C:WindowsSystem32Driversdfsc.sys [151040 2019-03-18] (Microsoft Company)
S3 ErrDev; C:WindowsSystem32driverserrdev.sys [14336 2019-03-18] (Microsoft Company)
S3 exfat; C:WindowsSystem32Driversexfat.sys [404480 2019-12-12] (Microsoft Company)
S3 fdc; C:WindowsSystem32driversfdc.sys [35328 2019-03-18] (Microsoft Company)
S1 FileCrypt; C:WindowsSystem32driversfilecrypt.sys [59392 2019-03-18] (Microsoft Company)
S3 Filetrace; C:WindowsSystem32driversfiletrace.sys [40960 2019-03-18] (Microsoft Company)
S3 flpydisk; C:WindowsSystem32driversflpydisk.sys [28160 2020-04-18] (Microsoft Company)
S3 genericusbfn; C:WindowsSystem32DriverStoreFileRepositorygenericusbfn.inf_amd64_b9c53b80e63af230genericusbfn.sys [20992 2019-09-14] (Microsoft Company)
S1 GpuEnergyDrv; C:WindowsSystem32driversgpuenergydrv.sys [8704 2019-03-18] (Microsoft Company)
S3 HdAudAddService; C:WindowsSystem32driversHdAudio.sys [425472 2019-09-14] (Microsoft Company)
S3 HDAudBus; C:WindowsSystem32driversHDAudBus.sys [114688 2020-03-22] (Microsoft Company)
S3 HidBth; C:WindowsSystem32drivershidbth.sys [121344 2020-05-13] (Microsoft Company)
S3 hidi2c; C:WindowsSystem32drivershidi2c.sys [54784 2019-03-18] (Microsoft Company)
S3 HidIr; C:WindowsSystem32drivershidir.sys [48640 2019-03-18] (Microsoft Company)
S3 hidspi; C:WindowsSystem32drivershidspi.sys [64000 2019-10-03] (Microsoft Company)
S3 HidUsb; C:WindowsSystem32drivershidusb.sys [45568 2019-08-31] (Microsoft Company)
S1 HWiNFO32; C:WINDOWSSysWoW64driversHWiNFO64A.SYS [27552 2016-11-26] (Martin Malik – REALiX -> REALiX)
S3 HwNClx0101; C:WindowsSystem32Driversmshwnclx.sys [28672 2019-03-18] (Microsoft Company)
S3 i8042prt; C:WindowsSystem32driversi8042prt.sys [119296 2019-03-18] (Microsoft Company)
S3 iaLPSS2i_I2C_CNL; C:WindowsSystem32driversiaLPSS2i_I2C_CNL.sys [180736 2019-03-18] (Intel Company)
S3 IndirectKmd; C:WindowsSystem32driversIndirectKmd.sys [46592 2019-03-18] (Microsoft Company)
S3 intelpmax; C:WindowsSystem32driversintelpmax.sys [28672 2019-03-18] (Microsoft Company)
S3 IpFilterDriver; C:WindowsSystem32DRIVERSipfltdrv.sys [90624 2019-03-18] (Microsoft Company)
S3 IPNAT; C:WindowsSystem32driversipnat.sys [224768 2019-03-18] (Microsoft Company)
S3 kbdhid; C:WindowsSystem32driverskbdhid.sys [46592 2019-03-18] (Microsoft Company)
S3 ksthunk; C:Windowssystem32driversksthunk.sys [29184 2019-03-18] (Microsoft Company)
S2 lltdio; C:WindowsSystem32driverslltdio.sys [72192 2019-03-18] (Microsoft Company)
S2 luafv; C:Windowssystem32driversluafv.sys [141312 2019-08-31] (Microsoft Company)
S3 MbbCx; C:WindowsSystem32driversMbbCx.sys [359424 2019-11-14] (Microsoft Company)
S3 Microsoft_Bluetooth_AvrcpTransport; C:WindowsSystem32driversMicrosoft.Bluetooth.AvrcpTransport.sys [64512 2019-03-18] (Microsoft Company)
S2 MMCSS; C:Windowssystem32driversmmcss.sys [53760 2019-03-18] (Microsoft Company)
S3 Modem; C:WindowsSystem32driversmodem.sys [46592 2019-03-18] (Microsoft Company)
S3 monitor; C:WindowsSystem32driversmonitor.sys [69632 2020-03-22] (Microsoft Company)
S3 mouhid; C:WindowsSystem32driversmouhid.sys [35840 2019-03-18] (Microsoft Company)
S3 MpKsl19d2fa85; C:ProgramDataMicrosoftWindows DefenderDefinition Updates{CB1C0AA4-EEA7-48C2-AA35-85625213B099}MpKslDrv.sys [91376 2020-12-24] (Microsoft Home windows -> Microsoft Company)
S3 MpKsl9974a543; C:ProgramDataMicrosoftWindows DefenderDefinition Updates{CB1C0AA4-EEA7-48C2-AA35-85625213B099}MpKslDrv.sys [91376 2020-12-24] (Microsoft Home windows -> Microsoft Company)
S3 mpsdrv; C:WindowsSystem32driversmpsdrv.sys [80384 2019-03-18] (Microsoft Company)
S3 MRxDAV; C:Windowssystem32driversmrxdav.sys [158208 2019-10-03] (Microsoft Company)
S3 MsBridge; C:WindowsSystem32driversbridge.sys [127488 2019-03-18] (Microsoft Company)
S3 mshidkmdf; C:WindowsSystem32driversmshidkmdf.sys [8704 2019-03-18] (Microsoft Company)
S3 mshidumdf; C:WindowsSystem32driversmshidumdf.sys [12288 2019-03-18] (Microsoft Company)
S3 MSKSSRV; C:WindowsSystem32driversMSKSSRV.sys [34816 2019-08-31] (Microsoft Company)
S2 MsLldp; C:WindowsSystem32driversmslldp.sys [78848 2019-03-18] (Microsoft Company)
S3 MSPCLOCK; C:WindowsSystem32driversMSPCLOCK.sys [11264 2019-03-18] (Microsoft Company)
S3 MSPQM; C:WindowsSystem32driversMSPQM.sys [11264 2019-03-18] (Microsoft Company)
S3 MSTEE; C:WindowsSystem32driversMSTEE.sys [12800 2019-03-18] (Microsoft Company)
S3 MTConfig; C:WindowsSystem32driversMTConfig.sys [16384 2019-03-18] (Microsoft Company)
S3 NativeWifiP; C:WindowsSystem32DRIVERSnwifi.sys [702464 2019-10-03] (Microsoft Company)
S3 NdisCap; C:WindowsSystem32driversndiscap.sys [56320 2019-03-18] (Microsoft Company)
S3 NdisImPlatform; C:WindowsSystem32driversNdisImPlatform.sys [135168 2020-03-22] (Microsoft Company)
S3 NdisTapi; C:WindowsSystem32DRIVERSndistapi.sys [28672 2019-10-03] (Microsoft Company)
S3 Ndisuio; C:WindowsSystem32driversndisuio.sys [70656 2019-03-18] (Microsoft Company)
S3 NdisVirtualBus; C:WindowsSystem32driversNdisVirtualBus.sys [22016 2019-03-18] (Microsoft Company)
S3 NdisWan; C:WindowsSystem32driversndiswan.sys [206336 2020-03-22] (Microsoft Company)
S3 ndiswanlegacy; C:WindowsSystem32DRIVERSndiswan.sys [206336 2020-03-22] (Microsoft Company)
S3 NDKPing; C:WindowsSystem32driversNDKPing.sys [63488 2019-03-18] (Microsoft Company)
S3 ndproxy; C:WindowsSystem32DRIVERSNDProxy.sys [244736 2019-10-03] (Microsoft Company)
S2 Ndu; C:WindowsSystem32driversNdu.sys [132096 2019-03-18] (Microsoft Company)
S3 NetAdapterCx; C:WindowsSystem32driversNetAdapterCx.sys [187904 2019-03-18] (Microsoft Company)
S1 NetBT; C:WindowsSystem32DRIVERSnetbt.sys [337408 2019-08-31] (Microsoft Company)
S1 npsvctrig; C:WindowsSystem32driversnpsvctrig.sys [27136 2019-03-18] (Microsoft Company)
S1 nsiproxy; C:WindowsSystem32driversnsiproxy.sys [48128 2019-11-14] (Microsoft Company)
S1 Null; C:WindowsSystem32DriversNull.sys [7680 2019-03-18] (Microsoft Company)
S3 Parport; C:WindowsSystem32driversparport.sys [108032 2019-03-18] (Microsoft Company)
S2 PEAUTH; C:WindowsSystem32driverspeauth.sys [817152 2019-08-31] (Microsoft Company)
S3 PNPMEM; C:WindowsSystem32driverspnpmem.sys [17408 2019-03-18] (Microsoft Company)
S3 portcfg; C:WindowsSystem32driversportcfg.sys [25600 2019-03-18] (Microsoft Company)
S3 PptpMiniport; C:WindowsSystem32driversraspptp.sys [103424 2019-03-18] (Microsoft Company)
S3 Qcamain; C:WindowsSystem32driversQcamainx64.sys [2276352 2015-07-10] (Qualcomm Atheros, Inc.)
S3 QWAVEdrv; C:Windowssystem32driversqwavedrv.sys [53760 2019-03-18] (Microsoft Company)
S3 RasAcd; C:WindowsSystem32DRIVERSrasacd.sys [19968 2019-03-18] (Microsoft Company)
S3 RasAgileVpn; C:WindowsSystem32driversAgileVpn.sys [114176 2020-03-22] (Microsoft Company)
S3 Rasl2tp; C:WindowsSystem32driversrasl2tp.sys [112128 2019-03-18] (Microsoft Company)
S3 RasPppoe; C:WindowsSystem32DRIVERSraspppoe.sys [87552 2019-03-18] (Microsoft Company)
S3 RasSstp; C:WindowsSystem32driversrassstp.sys [85504 2019-03-18] (Microsoft Company)
S3 rdpbus; C:WindowsSystem32driversrdpbus.sys [28672 2019-03-18] (Microsoft Company)
S3 RDPDR; C:WindowsSystem32driversrdpdr.sys [167936 2019-08-31] (Microsoft Company)
S3 RFCOMM; C:WindowsSystem32driversrfcomm.sys [211456 2019-03-18] (Microsoft Company)
S3 rhproxy; C:WindowsSystem32driversrhproxy.sys [113152 2019-03-18] (Microsoft Company)
S2 rspndr; C:WindowsSystem32driversrspndr.sys [89088 2019-03-18] (Microsoft Company)
S3 scfilter; C:WindowsSystem32DRIVERSscfilter.sys [45056 2019-03-18] (Microsoft Company)
S3 Serenum; C:WindowsSystem32driversserenum.sys [27648 2019-03-18] (Microsoft Company)
S3 Serial; C:WindowsSystem32driversserial.sys [89600 2019-03-18] (Microsoft Company)
S3 sermouse; C:WindowsSystem32driverssermouse.sys [29696 2019-03-18] (Microsoft Company)
S3 sfloppy; C:WindowsSystem32driverssfloppy.sys [18944 2020-04-18] (Microsoft Company)
S3 srv2; C:WindowsSystem32DRIVERSsrv2.sys [772096 2020-04-18] (Microsoft Company)
S3 srvnet; C:WindowsSystem32DRIVERSsrvnet.sys [309248 2020-06-12] (Microsoft Company)
S3 ssudmdm; C:Windowssystem32DRIVERSssudmdm.sys [166288 2017-05-18] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
S3 StillCam; C:WindowsSystem32driversserscan.sys [13312 2020-01-14] (Microsoft Company)
S3 Synth3dVsc; C:WindowsSystem32driversSynth3dVsc.sys [66560 2019-03-18] (Microsoft Company)
S2 tcpipreg; C:WindowsSystem32driverstcpipreg.sys [54784 2019-03-18] (Microsoft Company)
S3 TsUsbFlt; C:WindowsSystem32driverstsusbflt.sys [65024 2019-03-18] (Microsoft Company)
S3 TsUsbGD; C:WindowsSystem32driversTsUsbGD.sys [35328 2020-05-13] (Microsoft Company)
S3 tunnel; C:WindowsSystem32driverstunnel.sys [128512 2019-11-14] (Microsoft Company)
S3 UcmCx0101; C:WindowsSystem32DriversUcmCx.sys [160256 2019-03-18] (Microsoft Company)
S3 UcmTcpciCx0101; C:WindowsSystem32DriversUcmTcpciCx.sys [186368 2019-03-18] (Microsoft Company)
S3 UcmUcsiAcpiClient; C:WindowsSystem32driversUcmUcsiAcpiClient.sys [34816 2019-03-18] (Microsoft Company)
S3 UcmUcsiCx0101; C:WindowsSystem32DriversUcmUcsiCx.sys [111104 2019-03-18] (Microsoft Company)
S3 UdeCx; C:WindowsSystem32driversudecx.sys [51200 2019-03-18] (Microsoft Company)
S4 udfs; C:WindowsSystem32DRIVERSudfs.sys [342528 2019-12-12] (Microsoft Company)
S3 umbus; C:WindowsSystem32DriverStoreFileRepositoryumbus.inf_amd64_e566af5dd9858a0eumbus.sys [57856 2019-09-14] (Microsoft Company)
S3 UmPass; C:WindowsSystem32driversumpass.sys [13312 2019-03-18] (Microsoft Company)
S3 usbaudio; C:Windowssystem32driversusbaudio.sys [198656 2019-03-18] (Microsoft Company)
S3 usbaudio2; C:WindowsSystem32driversusbaudio2.sys [257536 2019-08-31] (Microsoft Company)
S3 usbcir; C:WindowsSystem32driversusbcir.sys [107008 2019-03-18] (Microsoft Company)
S3 usbohci; C:WindowsSystem32driversusbohci.sys [30208 2019-03-18] (Microsoft Company)
S3 usbprint; C:WindowsSystem32driversusbprint.sys [34304 2019-03-18] (Microsoft Company)
S3 usbser; C:WindowsSystem32driversusbser.sys [79360 2019-03-18] (Microsoft Company)
S3 usbuhci; C:WindowsSystem32driversusbuhci.sys [39936 2019-03-18] (Microsoft Company)
S3 vhf; C:WindowsSystem32driversvhf.sys [39936 2019-03-18] (Microsoft Company)
S3 vwifibus; C:WindowsSystem32driversvwifibus.sys [27648 2019-03-18] (Microsoft Company)
S1 vwififlt; C:WindowsSystem32driversvwififlt.sys [77312 2019-03-18] (Microsoft Company)
S3 vwifimp; C:WindowsSystem32driversvwifimp.sys [50176 2019-03-18] (Microsoft Company)
S3 WacomPen; C:WindowsSystem32driverswacompen.sys [31744 2019-03-18] (Microsoft Company)
S2 wanarp; C:WindowsSystem32DRIVERSwanarp.sys [92672 2019-10-03] (Microsoft Company)
S3 wanarpv6; C:WindowsSystem32DRIVERSwanarp.sys [92672 2019-10-03] (Microsoft Company)
S3 wcnfs; C:Windowssystem32driverswcnfs.sys [92672 2019-03-18] (Microsoft Company)
S0 WdBoot; C:WindowsSystem32driverswdWdBoot.sys [48536 2020-12-03] (Microsoft Home windows Early Launch Anti-malware Writer -> Microsoft Company)
S0 WdFilter; C:WindowsSystem32driverswdWdFilter.sys [429296 2020-12-03] (Microsoft Home windows -> Microsoft Company)
S3 wdiwifi; C:WindowsSystem32DRIVERSwdiwifi.sys [931840 2019-10-03] (Microsoft Company)
S3 WdNisDrv; C:WindowsSystem32driverswdWdNisDrv.sys [70896 2020-12-03] (Microsoft Home windows -> Microsoft Company)
S3 WinNat; C:WindowsSystem32driverswinnat.sys [251392 2020-05-13] (Microsoft Company)
S3 WINUSB; C:WindowsSystem32driversWinUsb.sys [105472 2019-03-18] (Microsoft Company)
S3 WmiAcpi; C:WindowsSystem32driverswmiacpi.sys [19456 2019-03-18] (Microsoft Company)
S4 ws2ifsl; C:Windowssystem32driversws2ifsl.sys [25088 2019-09-14] (Microsoft Company)
S3 WSDPrintDevice; C:WindowsSystem32driversWSDPrint.sys [24576 2019-03-18] (Microsoft Company)
S3 wsvd; C:Windowssystem32DRIVERSwsvd.sys [102376 2012-06-13] (CyberLink -> “CyberLink)
S3 WudfPf; C:WindowsSystem32driversWudfPf.sys [134656 2019-03-18] (Microsoft Company)
S3 WUDFRd; C:WindowsSystem32driversWUDFRd.sys [297984 2019-03-18] (Microsoft Company)
S3 WUDFWpdFs; C:Windowssystem32DRIVERSWUDFRd.sys [297984 2019-03-18] (Microsoft Company)
S3 WUDFWpdMtp; C:WindowsSystem32driversWUDFRd.sys [297984 2019-03-18] (Microsoft Company)
S3 xboxgip; C:WindowsSystem32driversxboxgip.sys [324608 2019-08-31] (Microsoft Company)
S3 xinputhid; C:WindowsSystem32driversxinputhid.sys [48128 2019-03-18] (Microsoft Company)
UpperFilters: [{4D36E96B-E325-11CE-BFC1-08002BE10318}] -> [SynTP kbdclass]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included within the fixlist, will probably be faraway from the registry. The file won’t be moved until listed individually.)
==================== One month (created) (All) =========
(If an entry is included within the fixlist, the file/folder can be moved.)
2021-02-02 14:42 – 2021-02-02 14:42 – 000000000 ____D C:Usersdefaultuser1AppDataLocalCyberLink
2021-02-02 14:42 – 2021-02-02 14:42 – 000000000 ____D C:Usersdefaultuser1AppDataLocalAdobe
2021-02-02 06:33 – 2021-02-02 06:36 – 000000000 ____D C:FRST
2021-02-02 06:18 – 2021-02-02 06:18 – 000000000 ____D C:Usersdefaultuser1AppDataRoamingLenovo
2021-02-02 06:16 – 2021-02-02 06:16 – 000000020 ___SH C:Usersdefaultuser1ntuser.ini
2021-02-02 06:16 – 2021-02-02 06:16 – 000000000 ____D C:Usersdefaultuser1AppDataLocalVirtualStore
2021-02-02 06:16 – 2021-02-02 06:16 – 000000000 ____D C:Usersdefaultuser1AppDataLocalPackages
2021-02-02 06:16 – 2021-02-02 06:16 – 000000000 ____D C:Usersdefaultuser1AppDataLocalConnectedDevicesPlatform
2021-02-02 06:15 – 2021-02-02 06:16 – 000000000 ____D C:usersdefaultuser1
2021-02-02 06:15 – 2017-01-30 11:43 – 000000000 ____D C:Usersdefaultuser1AppDataRoamingATI
2021-02-02 06:15 – 2017-01-30 11:43 – 000000000 ____D C:Usersdefaultuser1AppDataLocalATI
2021-02-02 04:15 – 2021-02-02 04:15 – 000000080 ___SH C:bootTel.dat
2021-02-02 04:15 – 2021-02-02 04:15 – 000000000 __SHD C:discovered.000
2021-02-02 00:54 – 2021-02-05 00:04 – 000000000 _____ C:Restoration.txt
==================== One month (modified) ==================
(If an entry is included within the fixlist, the file/folder can be moved.)
2021-02-02 14:45 – 2019-08-31 10:13 – 000000006 ____H C:WindowsTasksSA.DAT
2021-02-02 14:45 – 2019-08-31 09:31 – 000000000 ____D C:WindowsSystem32SleepStudy
2021-02-02 06:19 – 2019-10-12 14:35 – 000784648 _____ C:WindowsSystem32perfh00A.dat
2021-02-02 06:19 – 2019-10-12 14:35 – 000153130 _____ C:WindowsSystem32perfc00A.dat
2021-02-02 06:19 – 2019-08-31 10:00 – 001767634 _____ C:WindowsSystem32PerfStringBackup.INI
2021-02-02 06:19 – 2019-03-18 20:50 – 000000000 ____D C:WindowsINF
2021-02-02 03:45 – 2020-01-22 15:51 – 000000000 ____D C:userstrail
2021-02-02 03:45 – 2019-08-31 10:13 – 000000000 ____D C:WindowsSystem32TasksLenovo
2021-02-02 03:45 – 2019-08-31 09:46 – 000000000 ____D C:userssstub
2021-02-02 03:45 – 2019-08-31 09:46 – 000000000 ____D C:usersorkan
2021-02-02 03:45 – 2019-03-18 20:52 – 000000000 ____D C:WindowsServiceState
2021-02-02 03:38 – 2019-03-18 20:52 – 000000000 ___HD C:Program FilesWindowsApps
2021-02-02 03:11 – 2019-03-18 20:52 – 000000000 ____D C:Windowsregistration
2021-02-02 03:10 – 2015-10-18 13:51 – 000000000 ____D C:ProgramDataLenovo
==================== KnownDLLs (Whitelisted) =========================
==================== SigCheck ============================
(There is no such thing as a computerized repair for information that don’t cross verification.)
C:WindowsSystem32winlogon.exe => MD5 is legit
C:WindowsSystem32wininit.exe => MD5 is legit
C:Windowsexplorer.exe => MD5 is legit
C:WindowsSysWOW64explorer.exe => MD5 is legit
C:WindowsSystem32svchost.exe => MD5 is legit
C:WindowsSysWOW64svchost.exe => MD5 is legit
C:WindowsSystem32services.exe => MD5 is legit
C:WindowsSystem32User32.dll => MD5 is legit
C:WindowsSysWOW64User32.dll => MD5 is legit
C:WindowsSystem32userinit.exe => MD5 is legit
C:WindowsSysWOW64userinit.exe => MD5 is legit
C:WindowsSystem32rpcss.dll => MD5 is legit
C:WindowsSystem32dnsapi.dll => MD5 is legit
C:WindowsSysWOW64dnsapi.dll => MD5 is legit
C:WindowsSystem32dllhost.exe => MD5 is legit
C:WindowsSysWOW64dllhost.exe => MD5 is legit
C:WindowsSystem32Driversvolsnap.sys => MD5 is legit
==================== Affiliation (Whitelisted) =============
==================== Restore Factors =========================
Restore level date: 2021-01-10 20:31
Restore level date: 2021-01-20 02:28
Restore level date: 2021-02-02 07:10
==================== Reminiscence data ===========================
Proportion of reminiscence in use: 14%
Complete bodily RAM: 7128.26 MB
Accessible bodily RAM: 6099.98 MB
Complete Digital: 7128.26 MB
Accessible Digital: 6172.11 MB
==================== Drives ================================
Drive c: (Home windows) (Fastened) (Complete:885.66 GB) (Free:717.52 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive d: (LENOVO) (Fastened) (Complete:25 GB) (Free:20.29 GB) NTFS
Drive e: (LENOVO_PART) (Fastened) (Complete:18.62 GB) (Free:5.51 GB) NTFS
Drive f: (ESD-USB) (Detachable) (Complete:31.99 GB) (Free:27.41 GB) FAT32
Drive x: (Boot) (Fastened) (Complete:0.5 GB) (Free:0.49 GB) NTFS
?Quantity{9babf813-f595-434a-a043-444ed328023c} (WINRE_DRV) (Fastened) (Complete:0.98 GB) (Free:0.45 GB) NTFS
?Quantity{ec4e8f77-d08e-4056-97d3-3f7ea68e987d} (SYSTEM_DRV) (Fastened) (Complete:0.25 GB) (Free:0.22 GB) FAT32
==================== MBR & Partition Desk ====================
==========================================================
Disk: 0 (Measurement: 931.5 GB) (Disk ID: 68D88A68)
Partition: GPT.
==========================================================
Disk: 1 (MBR Code: Home windows 7/8/10) (Measurement: 230.9 GB) (Disk ID: 17008F10)
Partition 1: (Energetic) – (Measurement=32 GB) – (Kind=0C)
==================== Finish of FRST.txt ========================
I didn’t obtain a Addition window. If there may be one other manner you need me to run it simply let me know.