Summary Operating System Windows 10 Home 64-bit CPU Intel Core i5 650 @ 3.20GHz 49 °C Clarkdale 32nm Technology RAM 4.00GB Dual-Channel DDR3 @ 531MHz (7-7-7-20) Motherboard Dell Inc. 0T568R (CPU 1) 22 °C Graphics IPS236 (1920x1080@60Hz) 1792MB NVIDIA GeForce GTX 260 (NVIDIA) 61 °C Storage 596GB Intel Raid 0 Volume (RAID ) 931GB Seagate Desktop USB Device (USB (SATA) ) 40 °C Optical Drives HL-DT-ST DVD+-RW GH50N HL-DT-ST DVD+-RW GH50N Audio Realtek High Definition Audio Operating System Windows 10 Home 64-bit Computer type: Desktop Installation Date: 8/10/2019 2:03:37 AM Windows Security Center User Account Control (UAC) Enabled Notify level 2 - Default Windows Update AutoUpdate Download Automatically and Install at Set Scheduled time Schedule Frequency Every Day Schedule Time Windows Defender Windows Defender Disabled Firewall Firewall Enabled Display Name McAfee Firewall Antivirus Windows Defender Antivirus Disabled Virus Signature Database Up to date McAfee VirusScan Antivirus Enabled Virus Signature Database Up to date McAfee VirusScan Antivirus Enabled Virus Signature Database Up to date Malwarebytes Antivirus Enabled Virus Signature Database Up to date .NET Frameworks installed v4.8 Full v4.8 Client v3.5 SP1 v3.0 SP2 v2.0 SP2 Internet Explorer Version 11.778.18362.0 PowerShell Version 5.1.18362.1 Environment Variables USERPROFILE C:\Users\Steve SystemRoot C:\WINDOWS User Variables OneDrive C:\Users\Steve\OneDrive OneDriveConsumer C:\Users\Steve\OneDrive Path C:\Users\Steve\AppData\Local\Microsoft\WindowsApps TEMP C:\Users\Steve\AppData\Local\Temp TMP C:\Users\Steve\AppData\Local\Temp Machine Variables ComSpec C:\WINDOWS\system32\cmd.exe DriverData C:\Windows\System32\Drivers\DriverData EMC_AUTOPLAY c:\Program Files (x86)\Common Files\Roxio Shared\ FP_NO_HOST_CHECK NO NUMBER_OF_PROCESSORS 4 OS Windows_NT Path C:\ProgramData\Oracle\Java\javapath C:\WINDOWS\system32 C:\WINDOWS C:\WINDOWS\System32\Wbem C:\WINDOWS\System32\WindowsPowerShell\v1.0\ c:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\ c:\Program Files (x86)\Common Files\Roxio Shared\DLLShared\ c:\Program Files (x86)\Microsoft SQL Server\90\Tools\binn\ C:\WINDOWS\System32\OpenSSH\ PATHEXT .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC PROCESSOR_ARCHITECTURE AMD64 PROCESSOR_IDENTIFIER Intel64 Family 6 Model 37 Stepping 2, GenuineIntel PROCESSOR_LEVEL 6 PROCESSOR_REVISION 2502 PSModulePath C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\ RGSC C:\Program Files (x86)\Rockstar Games\Rockstar Games Social Club\1_0_0_0 RGSCLauncher C:\Program Files (x86)\Rockstar Games\Rockstar Games Social Club RoxioCentral c:\Program Files (x86)\Common Files\Roxio Shared\10.0\Roxio Central36\ TEMP C:\WINDOWS\TEMP TMP C:\WINDOWS\TEMP USERNAME SYSTEM windir C:\WINDOWS Power Profile Active power scheme Dell Hibernation Enabled Turn Off Monitor after: (On AC Power) 60 min Turn Off Hard Disk after: (On AC Power) 20 min Suspend after: (On AC Power) 120 min Screen saver Disabled Uptime Current Session Current Time 5/14/2020 5:47:55 PM Current Uptime 29,949 sec (0 d, 08 h, 19 m, 09 s) Last Boot Time 5/14/2020 9:28:46 AM Services Running Adobe Acrobat Update Service Running Application Host Helper Service Running Application Information Running AppX Deployment Service (AppXSVC) Running AVCTP service Running Background Intelligent Transfer Service Running Background Tasks Infrastructure Service Running Base Filtering Engine Running Business Contact Manager SQL Server Startup Service Running Capability Access Manager Service Running Client License Service (ClipSVC) Running Clipboard User Service_c6faa Running CNG Key Isolation Running COM+ Event System Running Connected Devices Platform Service Running Connected Devices Platform User Service_c6faa Running Connected User Experiences and Telemetry Running Contact Data_c6faa Running CoreMessaging Running Credential Manager Running Cryptographic Services Running Data Sharing Service Running Data Usage Running DCOM Server Process Launcher Running Delivery Optimization Running Device Association Service Running DHCP Client Running Diagnostic Policy Service Running Diagnostic Service Host Running Diagnostic System Host Running Display Enhancement Service Running Display Policy Service Running Distributed Link Tracking Client Running DNS Client Running Encrypting File System (EFS) Running Function Discovery Provider Host Running Function Discovery Resource Publication Running Geolocation Service Running HP Support Solutions Framework Service Running Human Interface Device Service Running IKE and AuthIP IPsec Keying Modules Running IP Helper Running IPsec Policy Agent Running Local Session Manager Running Malwarebytes Service Running McAfee AP Service Running McAfee CSP Service Running McAfee Module Core Service Running McAfee PEF Service Running McAfee Service Controller Running McAfee Validation Trust Protection Service Running McAfee WebAdvisor Running Message Queuing Running Microsoft Office ClickToRun Service Running Microsoft Passport Running Microsoft Passport Container Running Microsoft Store Install Service Running Net.Msmq Listener Adapter Running Net.Pipe Listener Adapter Running Net.Tcp Listener Adapter Running Net.Tcp Port Sharing Service Running Network Connected Devices Auto-Setup Running Network Connection Broker Running Network Connections Running Network List Service Running Network Location Awareness Running Network Store Interface Service Running nordvpn-service Running NVIDIA Display Driver Service Running Peer Name Resolution Protocol Running Peer Networking Identity Manager Running Plug and Play Running Power Running Print Spooler Running Program Compatibility Assistant Service Running Realtek8723AU Running Remote Access Connection Manager Running Remote Procedure Call (RPC) Running RPC Endpoint Mapper Running Secure Socket Tunneling Protocol Service Running Security Accounts Manager Running Security Center Running Server Running Shell Hardware Detection Running SQL Server Browser Running SQL Server VSS Writer Running SSDP Discovery Running State Repository Service Running Steam Client Service Running Storage Service Running Sync Host_c6faa Running SysMain Running System Event Notification Service Running System Events Broker Running System Guard Runtime Monitor Broker Running Task Scheduler Running TCP/IP NetBIOS Helper Running Telephony Running Themes Running Time Broker Running Touch Keyboard and Handwriting Panel Service Running Update Orchestrator Service Running User Data Access_c6faa Running User Data Storage_c6faa Running User Manager Running User Profile Service Running Web Account Manager Running Windows Audio Running Windows Audio Endpoint Builder Running Windows Backup Running Windows Biometric Service Running Windows Connection Manager Running Windows Defender Firewall Running Windows Event Log Running Windows Font Cache Service Running Windows Image Acquisition (WIA) Running Windows License Manager Service Running Windows Management Instrumentation Running Windows Process Activation Service Running Windows Push Notifications System Service Running Windows Push Notifications User Service_c6faa Running Windows Search Running Windows Security Service Running Windows Update Running WinHTTP Web Proxy Auto-Discovery Service Running WLAN AutoConfig Running Workstation Running World Wide Web Publishing Service Stopped ActiveX Installer (AxInstSV) Stopped Adobe Flash Player Update Service Stopped Agent Activation Runtime_c6faa Stopped AllJoyn Router Service Stopped Amazon Assistant Service Stopped App Readiness Stopped Application Identity Stopped Application Layer Gateway Service Stopped ASP.NET State Service Stopped Auto Time Zone Updater Stopped BitLocker Drive Encryption Service Stopped Block Level Backup Engine Service Stopped Bluetooth Audio Gateway Service Stopped Bluetooth Support Service Stopped Bluetooth User Support Service_c6faa Stopped CaptureService_c6faa Stopped Cellular Time Stopped Certificate Propagation Stopped ClientAnalyticsService Stopped COM+ System Application Stopped ConsentUX_c6faa Stopped CredentialEnrollmentManagerUserSvc_c6faa Stopped Device Install Service Stopped Device Management Enrollment Service Stopped Device Management Wireless Application Protocol (WAP) Push message Routing Service Stopped Device Setup Manager Stopped DeviceAssociationBroker_c6faa Stopped DevicePicker_c6faa Stopped DevicesFlow_c6faa Stopped DevQuery Background Discovery Broker Stopped Diagnostic Execution Service Stopped Distributed Transaction Coordinator Stopped Dock Login Service Stopped Downloaded Maps Manager Stopped Embedded Mode Stopped Enterprise App Management Service Stopped Extensible Authentication Protocol Stopped Fax Stopped File History Service Stopped FLEXnet Licensing Service Stopped GameDVR and Broadcast User Service_c6faa Stopped Google Chrome Elevation Service Stopped Google Update Service (gupdate) Stopped Google Update Service (gupdatem) Stopped GoToAssist Stopped GraphicsPerfSvc Stopped Group Policy Client Stopped HV Host Service Stopped Hyper-V Data Exchange Service Stopped Hyper-V Guest Service Interface Stopped Hyper-V Guest Shutdown Service Stopped Hyper-V Heartbeat Service Stopped Hyper-V PowerShell Direct Service Stopped Hyper-V Remote Desktop Virtualization Service Stopped Hyper-V Time Synchronization Service Stopped Hyper-V Volume Shadow Copy Requestor Stopped Internet Connection Sharing (ICS) Stopped IP Translation Configuration Service Stopped KtmRm for Distributed Transaction Coordinator Stopped Language Experience Service Stopped Link-Layer Topology Discovery Mapper Stopped Local Profile Assistant Service Stopped McAfee Application Installer Cleanup (0111151589486273) Stopped McAfee Firewall Core Service Stopped McAfee Security Scan Component Host Service Stopped MessagingService_c6faa Stopped Microsoft Diagnostics Hub Standard Collector Service Stopped Microsoft Account Sign-in Assistant Stopped Microsoft iSCSI Initiator Service Stopped Microsoft Office Diagnostics Service Stopped Microsoft Software Shadow Copy Provider Stopped Microsoft Storage Spaces SMP Stopped Microsoft Windows SMS Router Service. Stopped Natural Authentication Stopped Netlogon Stopped Network Connectivity Assistant Stopped Network Setup Service Stopped Office Source Engine Stopped Office Software Protection Platform Stopped OpenSSH Authentication Agent Stopped Optimize drives Stopped Parental Controls Stopped Payments and NFC/SE Manager Stopped Peer Networking Grouping Stopped Performance Counter DLL Host Stopped Performance Logs & Alerts Stopped Phone Service Stopped PNRP Machine Name Publication Service Stopped Portable Device Enumerator Service Stopped Printer Extensions and Notifications Stopped PrintWorkflow_c6faa Stopped Problem Reports and Solutions Control Panel Support Stopped Quality Windows Audio Video Experience Stopped Radio Management Service Stopped Recommended Troubleshooting Service Stopped Remote Access Auto Connection Manager Stopped Remote Desktop Configuration Stopped Remote Desktop Services Stopped Remote Desktop Services UserMode Port Redirector Stopped Remote Procedure Call (RPC) Locator Stopped Remote Registry Stopped Retail Demo Service Stopped Routing and Remote Access Stopped RoxMediaDB10 Stopped Secondary Logon Stopped Sensor Data Service Stopped Sensor Monitoring Service Stopped Sensor Service Stopped Shared PC Account Manager Stopped Skype Updater Stopped Smart Card Stopped Smart Card Device Enumeration Service Stopped Smart Card Removal Policy Stopped SNMP Trap Stopped SoftThinks Agent Service Stopped Software Protection Stopped Spatial Data Service Stopped Spot Verifier Stopped SQL Server (MSSMLBIZ) Stopped SQL Server Active Directory Helper Stopped Still Image Acquisition Events Stopped stllssvr Stopped Storage Tiers Management Stopped SupportSoft Sprocket Service (DellSupportCenter) Stopped UPnP Device Host Stopped Virtual Disk Stopped Volume Shadow Copy Stopped Volumetric Audio Compositor Service Stopped W3C Logging Service Stopped WalletService Stopped WarpJITSvc Stopped WebClient Stopped Wi-Fi Direct Services Connection Manager Service Stopped Windows Camera Frame Server Stopped Windows Connect Now - Config Registrar Stopped Windows Defender Antivirus Network Inspection Service Stopped Windows Defender Antivirus Service Stopped Windows Encryption Provider Host Service Stopped Windows Error Reporting Service Stopped Windows Event Collector Stopped Windows Insider Service Stopped Windows Installer Stopped Windows Management Service Stopped Windows Media Player Network Sharing Service Stopped Windows Mobile Hotspot Service Stopped Windows Modules Installer Stopped Windows Perception Service Stopped Windows Perception Simulation Service Stopped Windows Presentation Foundation Font Cache 3.0.0.0 Stopped Windows PushToInstall Service Stopped Windows Remote Management (WS-Management) Stopped Windows Time Stopped Windows Update Medic Service Stopped Wired AutoConfig Stopped WMI Performance Adapter Stopped Work Folders Stopped WWAN AutoConfig Stopped Xbox Accessory Management Service Stopped Xbox Live Auth Manager Stopped Xbox Live Game Save Stopped Xbox Live Networking Service TimeZone TimeZone GMT -7:00 Hours Language English (United States) Location United States Format English (United States) Currency $ Date Format M/d/yyyy Time Format h:mm:ss tt Scheduler 5/14/2020 5:57 PM; Adobe Flash Player Updater 5/14/2020 6:08 PM; GoogleUpdateTaskMachineCore 5/14/2020 6:08 PM; GoogleUpdateTaskMachineUA 5/14/2020 6:39 PM; HPCustParticipation HP ENVY Photo 7100 series 5/15/2020 7:00 AM; Adobe Acrobat Update Task 5/15/2020 8:39 AM; HPCeeScheduleForSteve 5/15/2020 10:38 AM; OneDrive Standalone Update Task-S-1-5-21-2126779717-1312616141-414031349-1003 5/15/2020 6:44 PM; Adobe Flash Player PPAPI Notifier McAfee Remediation (Prepare) McAfeeLogon Hotfixes Installed 5/14/2020 Windows Malicious Software Removal Tool x64 - v5.82 (KB890830) After the download, this tool runs one time to check your computer for infection by specific, prevalent malicious software (including Blaster, Sasser, and Mydoom) and helps remove any infection that is found. If an infection is found, the tool will display a status report the next time that you start your computer. A new version of the tool will be offered every month. If you want to manually run the tool on your computer, you can download a copy from the Microsoft Download Center, or you can run an online version from microsoft.com. This tool is not a replacement for an antivirus product. To help protect your computer, you should use an antivirus product. 4/17/2020 2020-04 Cumulative Update for Windows 10 Version 1909 for x64-based Systems (KB4549951) Install this update to resolve issues in Windows. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article for more information. After you install this item, you may have to restart your computer. 3/31/2020 2020-03 Cumulative Update for Windows 10 Version 1909 for x64-based Systems (KB4541335) Install this update to resolve issues in Windows. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article for more information. After you install this item, you may have to restart your computer. 3/13/2020 2020-03 Cumulative Update for Windows 10 Version 1909 for x64-based Systems (KB4551762) Install this update to resolve issues in Windows. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article for more information. After you install this item, you may have to restart your computer. 3/12/2020 2020-03 Cumulative Update for Windows 10 Version 1909 for x64-based Systems (KB4540673) Install this update to resolve issues in Windows. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article for more information. After you install this item, you may have to restart your computer. 3/7/2020 2020-02 Cumulative Update for .NET Framework 3.5 and 4.8 for Windows 10 Version 1909 for x64 (KB4537572) Install this update to resolve issues in Windows. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article for more information. After you install this item, you may have to restart your computer. 2/14/2020 Security Update for Windows 10 Version 1909 for x64-based Systems (KB4524244) A security issue has been identified in a Microsoft software product that could affect your system. You can help protect your system by installing this update from Microsoft. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article. After you install this update, you may have to restart your system. 2/13/2020 2020-02 Cumulative Update for .NET Framework 3.5 and 4.8 for Windows 10 Version 1909 for x64 (KB4534132) Install this update to resolve issues in Windows. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article for more information. After you install this item, you may have to restart your computer. 2/13/2020 Windows Malicious Software Removal Tool x64 - February 2020 (KB890830) After the download, this tool runs one time to check your computer for infection by specific, prevalent malicious software (including Blaster, Sasser, and Mydoom) and helps remove any infection that is found. If an infection is found, the tool will display a status report the next time that you start your computer. A new version of the tool will be offered every month. If you want to manually run the tool on your computer, you can download a copy from the Microsoft Download Center, or you can run an online version from microsoft.com. This tool is not a replacement for an antivirus product. To help protect your computer, you should use an antivirus product. 2/13/2020 2020-02 Security Update for Adobe Flash Player for Windows 10 Version 1909 for x64-based Systems (KB4537759) A security issue has been identified in a Microsoft software product that could affect your system. You can help protect your system by installing this update from Microsoft. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article. After you install this update, you may have to restart your system. 2/13/2020 2020-02 Cumulative Update for Windows 10 Version 1909 for x64-based Systems (KB4532693) Install this update to resolve issues in Windows. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article for more information. After you install this item, you may have to restart your computer. 1/16/2020 Windows Malicious Software Removal Tool x64 - January 2020 (KB890830) After the download, this tool runs one time to check your computer for infection by specific, prevalent malicious software (including Blaster, Sasser, and Mydoom) and helps remove any infection that is found. If an infection is found, the tool will display a status report the next time that you start your computer. A new version of the tool will be offered every month. If you want to manually run the tool on your computer, you can download a copy from the Microsoft Download Center, or you can run an online version from microsoft.com. This tool is not a replacement for an antivirus product. To help protect your computer, you should use an antivirus product. 1/16/2020 2020-01 Cumulative Update for .NET Framework 3.5 and 4.8 for Windows 10 Version 1909 for x64 (KB4532938) A security issue has been identified in a Microsoft software product that could affect your system. You can help protect your system by installing this update from Microsoft. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article. After you install this update, you may have to restart your system. 1/16/2020 2020-01 Cumulative Update for Windows 10 Version 1909 for x64-based Systems (KB4528760) Install this update to resolve issues in Windows. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article for more information. After you install this item, you may have to restart your computer. 12/30/2019 Feature update to Windows 10, version 1909 Install the latest update for Windows 10: Windows 10, version 1909. 12/30/2019 Feature update to Windows 10, version 1909 Install the latest update for Windows 10: Windows 10, version 1909. 12/11/2019 Windows Malicious Software Removal Tool x64 - December 2019 (KB890830) After the download, this tool runs one time to check your computer for infection by specific, prevalent malicious software (including Blaster, Sasser, and Mydoom) and helps remove any infection that is found. If an infection is found, the tool will display a status report the next time that you start your computer. A new version of the tool will be offered every month. If you want to manually run the tool on your computer, you can download a copy from the Microsoft Download Center, or you can run an online version from microsoft.com. This tool is not a replacement for an antivirus product. To help protect your computer, you should use an antivirus product. 12/11/2019 2019-12 Cumulative Update for .NET Framework 3.5 and 4.8 for Windows 10 Version 1903 for x64 (KB4533002) Install this update to resolve issues in Windows. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article for more information. After you install this item, you may have to restart your computer. 12/11/2019 2019-12 Cumulative Update for Windows 10 Version 1903 for x64-based Systems (KB4530684) Install this update to resolve issues in Windows. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article for more information. After you install this item, you may have to restart your computer. 11/14/2019 Windows Malicious Software Removal Tool x64 - November 2019 (KB890830) After the download, this tool runs one time to check your computer for infection by specific, prevalent malicious software (including Blaster, Sasser, and Mydoom) and helps remove any infection that is found. If an infection is found, the tool will display a status report the next time that you start your computer. A new version of the tool will be offered every month. If you want to manually run the tool on your computer, you can download a copy from the Microsoft Download Center, or you can run an online version from microsoft.com. This tool is not a replacement for an antivirus product. To help protect your computer, you should use an antivirus product. 11/14/2019 2019-11 Cumulative Update for Windows 10 Version 1903 for x64-based Systems (KB4524570) Install this update to resolve issues in Windows. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article for more information. After you install this item, you may have to restart your computer. 10/9/2019 2019-10 Cumulative Update for .NET Framework 3.5 and 4.8 for Windows 10 Version 1903 for x64 (KB4524100) Install this update to resolve issues in Windows. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article for more information. After you install this item, you may have to restart your computer. 10/9/2019 Windows Malicious Software Removal Tool x64 - October 2019 (KB890830) After the download, this tool runs one time to check your computer for infection by specific, prevalent malicious software (including Blaster, Sasser, and Mydoom) and helps remove any infection that is found. If an infection is found, the tool will display a status report the next time that you start your computer. A new version of the tool will be offered every month. If you want to manually run the tool on your computer, you can download a copy from the Microsoft Download Center, or you can run an online version from microsoft.com. This tool is not a replacement for an antivirus product. To help protect your computer, you should use an antivirus product. 10/9/2019 2019-10 Cumulative Update for Windows 10 Version 1903 for x64-based Systems (KB4517389) Install this update to resolve issues in Windows. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article for more information. After you install this item, you may have to restart your computer. 10/3/2019 2019-09 Cumulative Update for Windows 10 Version 1903 for x64-based Systems (KB4524147) Install this update to resolve issues in Windows. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article for more information. After you install this item, you may have to restart your computer. 9/12/2019 2019-09 Security Update for Adobe Flash Player for Windows 10 Version 1903 for x64-based Systems (KB4516115) A security issue has been identified in a Microsoft software product that could affect your system. You can help protect your system by installing this update from Microsoft. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article. After you install this update, you may have to restart your system. 9/12/2019 2019-09 Cumulative Update for .NET Framework 3.5 and 4.8 for Windows 10 Version 1903 for x64 (KB4514359) A security issue has been identified in a Microsoft software product that could affect your system. You can help protect your system by installing this update from Microsoft. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article. After you install this update, you may have to restart your system. 9/12/2019 2019-09 Cumulative Update for Windows 10 Version 1903 for x64-based Systems (KB4515384) Install this update to resolve issues in Windows. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article for more information. After you install this item, you may have to restart your computer. 9/5/2019 2019-08 Cumulative Update for .NET Framework 3.5 and 4.8 for Windows 10 Version 1903 for x64 (KB4511555) Install this update to resolve issues in Windows. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article for more information. After you install this item, you may have to restart your computer. 8/15/2019 Windows Malicious Software Removal Tool x64 - August 2019 (KB890830) After the download, this tool runs one time to check your computer for infection by specific, prevalent malicious software (including Blaster, Sasser, and Mydoom) and helps remove any infection that is found. If an infection is found, the tool will display a status report the next time that you start your computer. A new version of the tool will be offered every month. If you want to manually run the tool on your computer, you can download a copy from the Microsoft Download Center, or you can run an online version from microsoft.com. This tool is not a replacement for an antivirus product. To help protect your computer, you should use an antivirus product. 8/15/2019 2019-08 Cumulative Update for Windows 10 Version 1903 for x64-based Systems (KB4512508) Install this update to resolve issues in Windows. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article for more information. After you install this item, you may have to restart your computer. 8/10/2019 2019-07 Cumulative Update for .NET Framework 3.5, 4.8 for Windows 10 Version 1903 for x64 (KB4506991) A security issue has been identified in a Microsoft software product that could affect your system. You can help protect your system by installing this update from Microsoft. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article. After you install this update, you may have to restart your system. 8/10/2019 2019-06 Security Update for Adobe Flash Player for Windows 10 Version 1903 for x64-based Systems (KB4503308) A security issue has been identified in a Microsoft software product that could affect your system. You can help protect your system by installing this update from Microsoft. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article. After you install this update, you may have to restart your system. 8/10/2019 Feature update to Windows 10, version 1903 Install the latest update for Windows 10: Windows 10, version 1903. Not Installed 5/14/2020 2020-05 Cumulative Update for .NET Framework 3.5 and 4.8 for Windows 10 Version 1909 for x64 (KB4552931) Installation Status In Progress A security issue has been identified in a Microsoft software product that could affect your system. You can help protect your system by installing this update from Microsoft. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article. After you install this update, you may have to restart your system. 3/12/2020 Windows Malicious Software Removal Tool x64 - March 2020 (KB890830) Installation Status Failed After the download, this tool runs one time to check your computer for infection by specific, prevalent malicious software (including Blaster, Sasser, and Mydoom) and helps remove any infection that is found. If an infection is found, the tool will display a status report the next time that you start your computer. A new version of the tool will be offered every month. If you want to manually run the tool on your computer, you can download a copy from the Microsoft Download Center, or you can run an online version from microsoft.com. This tool is not a replacement for an antivirus product. To help protect your computer, you should use an antivirus product. System Folders Application Data C:\ProgramData Cookies C:\Users\Steve\AppData\Local\Microsoft\Windows\INetCookies Desktop C:\Users\Steve\Desktop Documents C:\Users\Public\Documents Fonts C:\WINDOWS\Fonts Global Favorites C:\Users\Steve\Favorites Internet History C:\Users\Steve\AppData\Local\Microsoft\Windows\History Local Application Data C:\Users\Steve\AppData\Local Music C:\Users\Public\Music Path for burning CD C:\Users\Steve\AppData\Local\Microsoft\Windows\Burn\Burn Physical Desktop C:\Users\Steve\Desktop Pictures C:\Users\Public\Pictures Program Files C:\Program Files Public Desktop C:\Users\Public\Desktop Start Menu C:\ProgramData\Microsoft\Windows\Start Menu Start Menu Programs C:\ProgramData\Microsoft\Windows\Start Menu\Programs Startup C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup Templates C:\ProgramData\Microsoft\Windows\Templates Temporary Internet Files C:\Users\Steve\AppData\Local\Microsoft\Windows\INetCache User Favorites C:\Users\Steve\Favorites Videos C:\Users\Public\Videos Windows Directory C:\WINDOWS Windows/System C:\WINDOWS\system32 Process List A6100.EXE Process ID 8020 User SYSTEM Domain NT AUTHORITY Path C:\Program Files (x86)\NETGEAR\A6100\A6100.EXE Memory Usage 7.36 MB Peak Memory Usage 21 MB ApplicationFrameHost.exe Process ID 10476 User Steve Domain STEVE-PC Path C:\Windows\System32\ApplicationFrameHost.exe Memory Usage 29 MB Peak Memory Usage 35 MB armsvc.exe Process ID 3868 User SYSTEM Domain NT AUTHORITY Path C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe Memory Usage 1.67 MB Peak Memory Usage 6.51 MB audiodg.exe Process ID 19024 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\audiodg.exe Memory Usage 12 MB Peak Memory Usage 13 MB BcmSqlStartupSvc.exe Process ID 3856 User SYSTEM Domain NT AUTHORITY Path C:\Program Files (x86)\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe Memory Usage 1.71 MB Peak Memory Usage 6.40 MB browser_broker.exe Process ID 2256 User Steve Domain STEVE-PC Path C:\Windows\System32\browser_broker.exe Memory Usage 19 MB Peak Memory Usage 20 MB conhost.exe Process ID 1880 User Steve Domain STEVE-PC Path C:\Windows\System32\conhost.exe Memory Usage 1.00 MB Peak Memory Usage 6.04 MB csrss.exe Process ID 688 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\csrss.exe Memory Usage 2.04 MB Peak Memory Usage 5.33 MB csrss.exe Process ID 788 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\csrss.exe Memory Usage 3.20 MB Peak Memory Usage 15 MB ctfmon.exe Process ID 1044 User Steve Domain STEVE-PC Path C:\Windows\System32\ctfmon.exe Memory Usage 8.17 MB Peak Memory Usage 14 MB dasHost.exe Process ID 3476 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\dasHost.exe Memory Usage 9.01 MB Peak Memory Usage 19 MB dwm.exe Process ID 1116 User DWM-1 Domain Window Manager Path C:\Windows\System32\dwm.exe Memory Usage 50 MB Peak Memory Usage 361 MB explorer.exe Process ID 9092 User Steve Domain STEVE-PC Path C:\Windows\explorer.exe Memory Usage 95 MB Peak Memory Usage 165 MB Facebook Gameroom Browser.exe Process ID 14580 User Steve Domain STEVE-PC Path C:\Users\Steve\AppData\Local\Facebook\Games\Facebook Gameroom Browser.exe Memory Usage 14 MB Peak Memory Usage 155 MB FacebookGameroom.exe Process ID 13776 User Steve Domain STEVE-PC Path C:\Users\Steve\AppData\Local\Facebook\Games\FacebookGameroom.exe Memory Usage 40 MB Peak Memory Usage 96 MB fontdrvhost.exe Process ID 572 User UMFD-1 Domain Font Driver Host Path C:\Windows\System32\fontdrvhost.exe Memory Usage 3.08 MB Peak Memory Usage 6.00 MB fontdrvhost.exe Process ID 568 User UMFD-0 Domain Font Driver Host Path C:\Windows\System32\fontdrvhost.exe Memory Usage 672 KB Peak Memory Usage 3.58 MB GoogleCrashHandler.exe Process ID 10152 User SYSTEM Domain NT AUTHORITY Path C:\Program Files (x86)\Google\Update\1.3.35.452\GoogleCrashHandler.exe Memory Usage 180 KB Peak Memory Usage 7.09 MB GoogleCrashHandler64.exe Process ID 9516 User SYSTEM Domain NT AUTHORITY Path C:\Program Files (x86)\Google\Update\1.3.35.452\GoogleCrashHandler64.exe Memory Usage 296 KB Peak Memory Usage 6.65 MB HPNETW~1.EXE Process ID 14156 User Steve Domain STEVE-PC Path C:\PROGRA~1\HP\HPENVY~1\Bin\HPNETW~1.EXE Memory Usage 6.32 MB Peak Memory Usage 13 MB HPSupportSolutionsFrameworkService.exe Process ID 10108 User SYSTEM Domain NT AUTHORITY Path C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe Memory Usage 4.51 MB Peak Memory Usage 53 MB HxOutlook.exe Process ID 3108 User Steve Domain STEVE-PC Path C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.12624.20368.0_x64__8wekyb3d8bbwe\HxOutlook.exe Memory Usage 780 KB Peak Memory Usage 103 MB HxTsr.exe Process ID 13504 User Steve Domain STEVE-PC Path C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.12624.20368.0_x64__8wekyb3d8bbwe\HxTsr.exe Memory Usage 532 KB Peak Memory Usage 38 MB lsass.exe Process ID 944 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\lsass.exe Memory Usage 18 MB Peak Memory Usage 20 MB MBAMService.exe Process ID 3924 User SYSTEM Domain NT AUTHORITY Path C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe Memory Usage 151 MB Peak Memory Usage 415 MB mbamtray.exe Process ID 8828 User Steve Domain STEVE-PC Path C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe Memory Usage 14 MB Peak Memory Usage 40 MB mcapexe.exe Process ID 6852 User SYSTEM Domain NT AUTHORITY Path C:\Program Files\Common Files\McAfee\VSCore_20_1\mcapexe.exe Memory Usage 2.30 MB Peak Memory Usage 11 MB McCSPServiceHost.exe Process ID 7124 User SYSTEM Domain NT AUTHORITY Path C:\Program Files\Common Files\McAfee\CSP\3.4.105.0\McCSPServiceHost.exe Memory Usage 13 MB Peak Memory Usage 19 MB McPvTray.exe Process ID 9632 User Steve Domain STEVE-PC Path C:\Program Files\McAfee\MAT\McPvTray.exe Memory Usage 620 KB Peak Memory Usage 15 MB mcshield.exe Process ID 7532 User SYSTEM Domain NT AUTHORITY Path C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe Memory Usage 32 MB Peak Memory Usage 280 MB McUICnt.exe Process ID 4740 User Steve Domain STEVE-PC Path C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe Memory Usage 19 MB Peak Memory Usage 42 MB Memory Compression Process ID 2004 User SYSTEM Domain NT AUTHORITY Memory Usage 38 MB Peak Memory Usage 244 MB MfeAVSvc.exe Process ID 16452 User SYSTEM Domain NT AUTHORITY Path C:\Program Files\McAfee\MfeAV\MfeAVSvc.exe Memory Usage 32 MB Peak Memory Usage 44 MB mfemms.exe Process ID 3804 User SYSTEM Domain NT AUTHORITY Path C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe Memory Usage 6.84 MB Peak Memory Usage 14 MB mfevtps.exe Process ID 5400 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\mfevtps.exe Memory Usage 10 MB Peak Memory Usage 59 MB MicrosoftEdge.exe Process ID 2844 User Steve Domain STEVE-PC Path C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe Memory Usage 100 MB Peak Memory Usage 104 MB MicrosoftEdgeCP.exe Process ID 3024 User Steve Domain STEVE-PC Path C:\Windows\System32\MicrosoftEdgeCP.exe Memory Usage 149 MB Peak Memory Usage 269 MB MicrosoftEdgeCP.exe Process ID 18344 User Steve Domain STEVE-PC Path C:\Windows\System32\MicrosoftEdgeCP.exe Memory Usage 26 MB Peak Memory Usage 26 MB MicrosoftEdgeCP.exe Process ID 404 User Steve Domain STEVE-PC Path C:\Windows\System32\MicrosoftEdgeCP.exe Memory Usage 187 MB Peak Memory Usage 195 MB MicrosoftEdgeCP.exe Process ID 12920 User Steve Domain STEVE-PC Path C:\Windows\System32\MicrosoftEdgeCP.exe Memory Usage 621 MB Peak Memory Usage 765 MB MicrosoftEdgeCP.exe Process ID 15712 User Steve Domain STEVE-PC Path C:\Windows\System32\MicrosoftEdgeCP.exe Memory Usage 24 MB Peak Memory Usage 26 MB MicrosoftEdgeCP.exe Process ID 9968 User Steve Domain STEVE-PC Path C:\Windows\System32\MicrosoftEdgeCP.exe Memory Usage 51 MB Peak Memory Usage 154 MB MicrosoftEdgeSH.exe Process ID 14992 User Steve Domain STEVE-PC Path C:\Windows\System32\MicrosoftEdgeSH.exe Memory Usage 17 MB Peak Memory Usage 26 MB MMSSHOST.exe Process ID 11072 User SYSTEM Domain NT AUTHORITY Path C:\Program Files\Common Files\McAfee\MMSSHost\MMSSHOST.exe Memory Usage 42 MB Peak Memory Usage 79 MB ModuleCoreService.exe Process ID 3844 User SYSTEM Domain NT AUTHORITY Path C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe Memory Usage 42 MB Peak Memory Usage 77 MB ModuleCoreService.exe Process ID 7452 User Steve Domain STEVE-PC Path C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe Memory Usage 14 MB Peak Memory Usage 38 MB mqsvc.exe Process ID 3152 User NETWORK SERVICE Domain NT AUTHORITY Path C:\Windows\System32\mqsvc.exe Memory Usage 2.66 MB Peak Memory Usage 13 MB MusNotifyIcon.exe Process ID 8452 User Steve Domain STEVE-PC Path C:\Windows\System32\MusNotifyIcon.exe Memory Usage 2.75 MB Peak Memory Usage 14 MB nordvpn-service.exe Process ID 3264 User SYSTEM Domain NT AUTHORITY Path C:\Program Files (x86)\NordVPN\nordvpn-service.exe Memory Usage 9.46 MB Peak Memory Usage 71 MB NordVPN.exe Process ID 13520 User Steve Domain STEVE-PC Path C:\Program Files (x86)\NordVPN\NordVPN.exe Memory Usage 104 MB Peak Memory Usage 241 MB notepad.exe Process ID 2956 User Steve Domain STEVE-PC Path C:\Windows\System32\notepad.exe Memory Usage 43 MB Peak Memory Usage 45 MB NvBackend.exe Process ID 10512 User Steve Domain STEVE-PC Path C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe Memory Usage 2.79 MB Peak Memory Usage 20 MB nvtray.exe Process ID 14008 User Steve Domain STEVE-PC Path C:\Program Files\NVIDIA Corporation\Display\nvtray.exe Memory Usage 6.62 MB Peak Memory Usage 12 MB nvvsvc.exe Process ID 1968 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\nvvsvc.exe Memory Usage 5.31 MB Peak Memory Usage 15 MB nvvsvc.exe Process ID 1660 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\nvvsvc.exe Memory Usage 4.29 MB Peak Memory Usage 10 MB nvxdsync.exe Process ID 1956 User SYSTEM Domain NT AUTHORITY Path C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe Memory Usage 12 MB Peak Memory Usage 21 MB officeclicktorun.exe Process ID 3732 User SYSTEM Domain NT AUTHORITY Path C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe Memory Usage 10 MB Peak Memory Usage 38 MB OneDrive.exe Process ID 13332 User Steve Domain STEVE-PC Path C:\Users\Steve\AppData\Local\Microsoft\OneDrive\OneDrive.exe Memory Usage 18 MB Peak Memory Usage 63 MB PDVDDXSrv.exe Process ID 13896 User Steve Domain STEVE-PC Path C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe Memory Usage 3.03 MB Peak Memory Usage 12 MB PEFService.exe Process ID 3936 User SYSTEM Domain NT AUTHORITY Path C:\Program Files\Common Files\McAfee\PEF\CORE\PEFService.exe Memory Usage 1.45 MB Peak Memory Usage 8.21 MB ProtectedModuleHost.exe Process ID 5496 User SYSTEM Domain NT AUTHORITY Path C:\Program Files\Common Files\McAfee\ModuleCore\ProtectedModuleHost.exe Memory Usage 3.22 MB Peak Memory Usage 16 MB QcShm.exe Process ID 17420 User SYSTEM Domain NT AUTHORITY Path C:\Program Files\McAfee\MQS\QcShm.exe Memory Usage 10 MB Peak Memory Usage 12 MB RAVCpl64.exe Process ID 11028 User Steve Domain STEVE-PC Path C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe Memory Usage 3.69 MB Peak Memory Usage 14 MB Registry Process ID 96 User SYSTEM Domain NT AUTHORITY Memory Usage 48 MB Peak Memory Usage 234 MB RemindersServer.exe Process ID 10160 User Steve Domain STEVE-PC Path C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe Memory Usage 9.33 MB Peak Memory Usage 21 MB RtlService.exe Process ID 3960 User SYSTEM Domain NT AUTHORITY Path C:\Program Files (x86)\NETGEAR\A6100\RtlService.exe Memory Usage 2.06 MB Peak Memory Usage 12 MB rundll32.exe Process ID 10508 User Steve Domain STEVE-PC Path C:\Windows\System32\rundll32.exe Memory Usage 2.29 MB Peak Memory Usage 10 MB rundll32.exe Process ID 1984 User Steve Domain STEVE-PC Path C:\Windows\System32\rundll32.exe Memory Usage 2.11 MB Peak Memory Usage 8.79 MB RuntimeBroker.exe Process ID 13140 User Steve Domain STEVE-PC Path C:\Windows\System32\RuntimeBroker.exe Memory Usage 9.43 MB Peak Memory Usage 26 MB RuntimeBroker.exe Process ID 11148 User Steve Domain STEVE-PC Path C:\Windows\System32\RuntimeBroker.exe Memory Usage 33 MB Peak Memory Usage 36 MB RuntimeBroker.exe Process ID 2996 User Steve Domain STEVE-PC Path C:\Windows\System32\RuntimeBroker.exe Memory Usage 6.23 MB Peak Memory Usage 22 MB RuntimeBroker.exe Process ID 8456 User Steve Domain STEVE-PC Path C:\Windows\System32\RuntimeBroker.exe Memory Usage 2.51 MB Peak Memory Usage 18 MB RuntimeBroker.exe Process ID 10636 User Steve Domain STEVE-PC Path C:\Windows\System32\RuntimeBroker.exe Memory Usage 17 MB Peak Memory Usage 31 MB RuntimeBroker.exe Process ID 14108 User Steve Domain STEVE-PC Path C:\Windows\System32\RuntimeBroker.exe Memory Usage 15 MB Peak Memory Usage 20 MB RuntimeBroker.exe Process ID 12312 User Steve Domain STEVE-PC Path C:\Windows\System32\RuntimeBroker.exe Memory Usage 33 MB Peak Memory Usage 35 MB RuntimeBroker.exe Process ID 12624 User Steve Domain STEVE-PC Path C:\Windows\System32\RuntimeBroker.exe Memory Usage 6.07 MB Peak Memory Usage 21 MB ScanToPCActivationApp.exe Process ID 13368 User Steve Domain STEVE-PC Path C:\Program Files\HP\HP ENVY Photo 7100 series\Bin\ScanToPCActivationApp.exe Memory Usage 7.63 MB Peak Memory Usage 16 MB SearchFilterHost.exe Process ID 1264 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\SearchFilterHost.exe Memory Usage 6.28 MB Peak Memory Usage 6.30 MB SearchIndexer.exe Process ID 10728 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\SearchIndexer.exe Memory Usage 27 MB Peak Memory Usage 48 MB SearchProtocolHost.exe Process ID 9220 User Steve Domain STEVE-PC Path C:\Windows\System32\SearchProtocolHost.exe Memory Usage 7.30 MB Peak Memory Usage 7.82 MB SearchProtocolHost.exe Process ID 1500 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\SearchProtocolHost.exe Memory Usage 19 MB Peak Memory Usage 20 MB SearchUI.exe Process ID 12216 User Steve Domain STEVE-PC Path C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe Memory Usage 124 MB Peak Memory Usage 159 MB SecurityHealthService.exe Process ID 10676 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\SecurityHealthService.exe Memory Usage 4.61 MB Peak Memory Usage 15 MB SecurityHealthSystray.exe Process ID 2152 User Steve Domain STEVE-PC Path C:\Windows\System32\SecurityHealthSystray.exe Memory Usage 2.20 MB Peak Memory Usage 8.99 MB servicehost.exe Process ID 3812 User SYSTEM Domain NT AUTHORITY Path C:\Program Files\McAfee\WebAdvisor\servicehost.exe Memory Usage 16 MB Peak Memory Usage 24 MB services.exe Process ID 928 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\services.exe Memory Usage 6.14 MB Peak Memory Usage 14 MB SettingSyncHost.exe Process ID 13264 User Steve Domain STEVE-PC Path C:\Windows\System32\SettingSyncHost.exe Memory Usage 6.76 MB Peak Memory Usage 75 MB SgrmBroker.exe Process ID 10344 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\SgrmBroker.exe Memory Usage 3.18 MB Peak Memory Usage 6.79 MB ShellExperienceHost.exe Process ID 1176 User Steve Domain STEVE-PC Path C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe Memory Usage 1.70 MB Peak Memory Usage 51 MB ShwiconXP9106.exe Process ID 13880 User Steve Domain STEVE-PC Path C:\Program Files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe Memory Usage 2.43 MB Peak Memory Usage 8.50 MB sihost.exe Process ID 2816 User Steve Domain STEVE-PC Path C:\Windows\System32\sihost.exe Memory Usage 20 MB Peak Memory Usage 26 MB SkypeApp.exe Process ID 11636 User Steve Domain STEVE-PC Path C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.56.102.0_x64__kzf8qxf38zg5c\SkypeApp.exe Memory Usage 26 MB Peak Memory Usage 170 MB SkypeBackgroundHost.exe Process ID 8184 User Steve Domain STEVE-PC Path C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.56.102.0_x64__kzf8qxf38zg5c\SkypeBackgroundHost.exe Memory Usage 2.16 MB Peak Memory Usage 12 MB SkypeBridge.exe Process ID 13976 User Steve Domain STEVE-PC Path C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.56.102.0_x64__kzf8qxf38zg5c\SkypeBridge\SkypeBridge.exe Memory Usage 24 MB Peak Memory Usage 55 MB smartscreen.exe Process ID 4576 User Steve Domain STEVE-PC Path C:\Windows\System32\smartscreen.exe Memory Usage 29 MB Peak Memory Usage 34 MB smss.exe Process ID 592 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\smss.exe Memory Usage 324 KB Peak Memory Usage 1.24 MB SMSvcHost.exe Process ID 6024 User NETWORK SERVICE Domain NT AUTHORITY Path C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe Memory Usage 2.07 MB Peak Memory Usage 16 MB SMSvcHost.exe Process ID 3944 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe Memory Usage 2.19 MB Peak Memory Usage 24 MB Speccy64.exe Process ID 8068 User Steve Domain STEVE-PC Path C:\Program Files\Speccy\Speccy64.exe Memory Usage 34 MB Peak Memory Usage 34 MB spoolsv.exe Process ID 3196 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\spoolsv.exe Memory Usage 9.69 MB Peak Memory Usage 30 MB sprtcmd.exe Process ID 13996 User Steve Domain STEVE-PC Path C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe Memory Usage 1.38 MB Peak Memory Usage 17 MB sqlbrowser.exe Process ID 3992 User NETWORK SERVICE Domain NT AUTHORITY Path C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe Memory Usage 1.13 MB Peak Memory Usage 4.60 MB sqlwriter.exe Process ID 4044 User SYSTEM Domain NT AUTHORITY Path C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe Memory Usage 1.94 MB Peak Memory Usage 7.96 MB SSScheduler.exe Process ID 13708 User Steve Domain STEVE-PC Path C:\Program Files\McAfee Security Scan\3.11.1719\SSScheduler.exe Memory Usage 2.06 MB Peak Memory Usage 7.27 MB StartMenuExperienceHost.exe Process ID 10548 User Steve Domain STEVE-PC Path C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe Memory Usage 73 MB Peak Memory Usage 87 MB steam.exe Process ID 13432 User Steve Domain STEVE-PC Path C:\Program Files (x86)\Steam\steam.exe Memory Usage 21 MB Peak Memory Usage 71 MB SteamService.exe Process ID 11588 User SYSTEM Domain NT AUTHORITY Path C:\Program Files (x86)\Common Files\Steam\SteamService.exe Memory Usage 2.11 MB Peak Memory Usage 14 MB steamwebhelper.exe Process ID 14904 User Steve Domain STEVE-PC Path C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe Memory Usage 16 MB Peak Memory Usage 103 MB steamwebhelper.exe Process ID 13640 User Steve Domain STEVE-PC Path C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe Memory Usage 14 MB Peak Memory Usage 56 MB steamwebhelper.exe Process ID 9572 User Steve Domain STEVE-PC Path C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe Memory Usage 2.66 MB Peak Memory Usage 14 MB steamwebhelper.exe Process ID 13908 User Steve Domain STEVE-PC Path C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe Memory Usage 5.49 MB Peak Memory Usage 119 MB steamwebhelper.exe Process ID 12180 User Steve Domain STEVE-PC Path C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe Memory Usage 12 MB Peak Memory Usage 26 MB steamwebhelper.exe Process ID 14704 User Steve Domain STEVE-PC Path C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe Memory Usage 15 MB Peak Memory Usage 93 MB steamwebhelper.exe Process ID 14720 User Steve Domain STEVE-PC Path C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe Memory Usage 4.78 MB Peak Memory Usage 43 MB svchost.exe Process ID 1756 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 5.90 MB Peak Memory Usage 12 MB svchost.exe Process ID 8984 User Steve Domain STEVE-PC Path C:\Windows\System32\svchost.exe Memory Usage 23 MB Peak Memory Usage 39 MB svchost.exe Process ID 9728 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 5.23 MB Peak Memory Usage 12 MB svchost.exe Process ID 9924 User Steve Domain STEVE-PC Path C:\Windows\System32\svchost.exe Memory Usage 13 MB Peak Memory Usage 17 MB svchost.exe Process ID 8900 User Steve Domain STEVE-PC Path C:\Windows\System32\svchost.exe Memory Usage 16 MB Peak Memory Usage 67 MB svchost.exe Process ID 532 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 18 MB Peak Memory Usage 42 MB svchost.exe Process ID 7060 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 3.38 MB Peak Memory Usage 10 MB svchost.exe Process ID 4136 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 1.22 MB Peak Memory Usage 7.61 MB svchost.exe Process ID 1620 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 1.04 MB Peak Memory Usage 9.28 MB svchost.exe Process ID 4608 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 8.30 MB Peak Memory Usage 28 MB svchost.exe Process ID 6768 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 3.98 MB Peak Memory Usage 9.26 MB svchost.exe Process ID 10488 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 2.64 MB Peak Memory Usage 36 MB svchost.exe Process ID 6760 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 1.33 MB Peak Memory Usage 7.12 MB svchost.exe Process ID 504 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 936 KB Peak Memory Usage 3.94 MB svchost.exe Process ID 6324 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 3.01 MB Peak Memory Usage 6.13 MB svchost.exe Process ID 5272 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 2.63 MB Peak Memory Usage 8.01 MB svchost.exe Process ID 8316 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 7.03 MB Peak Memory Usage 15 MB svchost.exe Process ID 5068 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 4.63 MB Peak Memory Usage 13 MB svchost.exe Process ID 4316 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 920 KB Peak Memory Usage 6.58 MB svchost.exe Process ID 4228 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 1.07 MB Peak Memory Usage 5.34 MB svchost.exe Process ID 5412 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 6.48 MB Peak Memory Usage 6.62 MB svchost.exe Process ID 2392 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 1.34 MB Peak Memory Usage 8.05 MB svchost.exe Process ID 4108 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 800 KB Peak Memory Usage 5.56 MB svchost.exe Process ID 3348 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 12 MB Peak Memory Usage 22 MB svchost.exe Process ID 4092 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 8.26 MB Peak Memory Usage 17 MB svchost.exe Process ID 13180 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 3.58 MB Peak Memory Usage 12 MB svchost.exe Process ID 3972 User NETWORK SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage KB Peak Memory Usage 7.15 MB svchost.exe Process ID 3916 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 7.50 MB Peak Memory Usage 14 MB svchost.exe Process ID 3880 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 2.61 MB Peak Memory Usage 11 MB svchost.exe Process ID 3784 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 4.15 MB Peak Memory Usage 9.00 MB svchost.exe Process ID 3712 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 15 MB Peak Memory Usage 42 MB svchost.exe Process ID 3692 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 26 MB Peak Memory Usage 149 MB svchost.exe Process ID 3672 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 28 MB Peak Memory Usage 57 MB svchost.exe Process ID 10652 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 8.04 MB Peak Memory Usage 15 MB svchost.exe Process ID 3652 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 2.31 MB Peak Memory Usage 6.62 MB svchost.exe Process ID 3636 User NETWORK SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 12 MB Peak Memory Usage 21 MB svchost.exe Process ID 3628 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 2.54 MB Peak Memory Usage 11 MB svchost.exe Process ID 3508 User NETWORK SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 3.33 MB Peak Memory Usage 9.70 MB svchost.exe Process ID 16804 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 5.82 MB Peak Memory Usage 5.83 MB svchost.exe Process ID 3424 User NETWORK SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 2.49 MB Peak Memory Usage 8.12 MB svchost.exe Process ID 3272 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 11 MB Peak Memory Usage 25 MB svchost.exe Process ID 3076 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 4.10 MB Peak Memory Usage 14 MB svchost.exe Process ID 2384 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 8.44 MB Peak Memory Usage 19 MB svchost.exe Process ID 3060 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 3.81 MB Peak Memory Usage 9.38 MB svchost.exe Process ID 2900 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 4.36 MB Peak Memory Usage 10 MB svchost.exe Process ID 2892 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 2.79 MB Peak Memory Usage 6.44 MB svchost.exe Process ID 14308 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 10 MB Peak Memory Usage 22 MB svchost.exe Process ID 10832 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 2.95 MB Peak Memory Usage 13 MB svchost.exe Process ID 2808 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 13 MB Peak Memory Usage 22 MB svchost.exe Process ID 6292 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 10 MB Peak Memory Usage 22 MB svchost.exe Process ID 2692 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 7.61 MB Peak Memory Usage 14 MB svchost.exe Process ID 2148 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 9.05 MB Peak Memory Usage 18 MB svchost.exe Process ID 5792 User NETWORK SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 8.36 MB Peak Memory Usage 15 MB svchost.exe Process ID 2604 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 6.71 MB Peak Memory Usage 11 MB svchost.exe Process ID 9580 User Steve Domain STEVE-PC Path C:\Windows\System32\svchost.exe Memory Usage 20 MB Peak Memory Usage 31 MB svchost.exe Process ID 2616 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 264 KB Peak Memory Usage 6.74 MB svchost.exe Process ID 2460 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 12 MB Peak Memory Usage 20 MB svchost.exe Process ID 10900 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 1.30 MB Peak Memory Usage 11 MB svchost.exe Process ID 2376 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 5.59 MB Peak Memory Usage 9.29 MB svchost.exe Process ID 16176 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 4.94 MB Peak Memory Usage 12 MB svchost.exe Process ID 2276 User NETWORK SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 5.31 MB Peak Memory Usage 8.22 MB svchost.exe Process ID 2128 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 3.59 MB Peak Memory Usage 16 MB svchost.exe Process ID 2080 User NETWORK SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 7.33 MB Peak Memory Usage 13 MB svchost.exe Process ID 6480 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 1.86 MB Peak Memory Usage 13 MB svchost.exe Process ID 16144 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 1.68 MB Peak Memory Usage 10 MB svchost.exe Process ID 2072 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 2.21 MB Peak Memory Usage 8.05 MB svchost.exe Process ID 1632 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 8.86 MB Peak Memory Usage 22 MB svchost.exe Process ID 2036 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 2.16 MB Peak Memory Usage 8.48 MB svchost.exe Process ID 1820 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 1.37 MB Peak Memory Usage 5.75 MB svchost.exe Process ID 1788 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 33 MB Peak Memory Usage 84 MB svchost.exe Process ID 3500 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 2.80 MB Peak Memory Usage 8.02 MB svchost.exe Process ID 1764 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 1.26 MB Peak Memory Usage 7.90 MB svchost.exe Process ID 8880 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 4.85 MB Peak Memory Usage 5.41 MB svchost.exe Process ID 1732 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 3.30 MB Peak Memory Usage 7.64 MB svchost.exe Process ID 5188 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 8.69 MB Peak Memory Usage 9.17 MB svchost.exe Process ID 1652 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 3.71 MB Peak Memory Usage 9.66 MB svchost.exe Process ID 1604 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 1.23 MB Peak Memory Usage 7.34 MB svchost.exe Process ID 1452 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 4.25 MB Peak Memory Usage 12 MB svchost.exe Process ID 1444 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 9.59 MB Peak Memory Usage 22 MB svchost.exe Process ID 1436 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 1.65 MB Peak Memory Usage 5.79 MB svchost.exe Process ID 18752 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 11 MB Peak Memory Usage 12 MB svchost.exe Process ID 1328 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 1.45 MB Peak Memory Usage 5.96 MB svchost.exe Process ID 1268 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 4.21 MB Peak Memory Usage 11 MB svchost.exe Process ID 6960 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 8.54 MB Peak Memory Usage 8.55 MB svchost.exe Process ID 2416 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 8.14 MB Peak Memory Usage 8.16 MB svchost.exe Process ID 2472 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 20 MB Peak Memory Usage 22 MB svchost.exe Process ID 1036 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 2.64 MB Peak Memory Usage 8.79 MB svchost.exe Process ID 772 User NETWORK SERVICE Domain NT AUTHORITY Path C:\Windows\System32\svchost.exe Memory Usage 12 MB Peak Memory Usage 18 MB System Process ID 4 Memory Usage 1.64 MB Peak Memory Usage 7.68 MB System Idle Process Process ID 0 SystemSettings.exe Process ID 11716 User Steve Domain STEVE-PC Path C:\Windows\ImmersiveControlPanel\SystemSettings.exe Memory Usage 208 KB Peak Memory Usage 94 MB taskhostw.exe Process ID 9076 User Steve Domain STEVE-PC Path C:\Windows\System32\taskhostw.exe Memory Usage 17 MB Peak Memory Usage 30 MB Taskmgr.exe Process ID 18848 User Steve Domain STEVE-PC Path C:\Windows\System32\Taskmgr.exe Memory Usage 51 MB Peak Memory Usage 52 MB uihost.exe Process ID 8840 User Steve Domain STEVE-PC Path C:\Program Files\McAfee\WebAdvisor\uihost.exe Memory Usage 7.24 MB Peak Memory Usage 17 MB unsecapp.exe Process ID 8604 User Steve Domain STEVE-PC Path C:\Windows\System32\wbem\unsecapp.exe Memory Usage 1.96 MB Peak Memory Usage 7.00 MB Video.UI.exe Process ID 13812 User Steve Domain STEVE-PC Path C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.20022.11011.0_x64__8wekyb3d8bbwe\Video.UI.exe Memory Usage 460 KB Peak Memory Usage 43 MB WindowsInternal.ComposableShell.Experiences.TextInput.InputApp.exe Process ID 12204 User Steve Domain STEVE-PC Path C:\Windows\SystemApps\InputApp_cw5n1h2txyewy\WindowsInternal.ComposableShell.Experiences.TextInput.InputApp.exe Memory Usage 10 MB Peak Memory Usage 42 MB wininit.exe Process ID 780 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\wininit.exe Memory Usage 1.13 MB Peak Memory Usage 6.81 MB winlogon.exe Process ID 840 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\winlogon.exe Memory Usage 3.95 MB Peak Memory Usage 17 MB WmiPrvSE.exe Process ID 6360 User NETWORK SERVICE Domain NT AUTHORITY Path C:\Windows\System32\wbem\WmiPrvSE.exe Memory Usage 19 MB Peak Memory Usage 19 MB WmiPrvSE.exe Process ID 16604 User SYSTEM Domain NT AUTHORITY Path C:\Windows\System32\wbem\WmiPrvSE.exe Memory Usage 8.52 MB Peak Memory Usage 8.52 MB WUDFHost.exe Process ID 1592 User LOCAL SERVICE Domain NT AUTHORITY Path C:\Windows\System32\WUDFHost.exe Memory Usage 1.60 MB Peak Memory Usage 8.39 MB YourPhone.exe Process ID 11376 User Steve Domain STEVE-PC Path C:\Program Files\WindowsApps\Microsoft.YourPhone_1.20041.88.0_x64__8wekyb3d8bbwe\YourPhone.exe Memory Usage 5.75 MB Peak Memory Usage 38 MB Security Options Accounts: Administrator account status Disabled Accounts: Block Microsoft accounts Not Defined Accounts: Guest account status Disabled Accounts: Limit local account use of blank passwords to console logon only Enabled Accounts: Rename administrator account Administrator Accounts: Rename guest account Guest Audit: Audit the access of global system objects Disabled Audit: Audit the use of Backup and Restore privilege Disabled Audit: Force audit policy subcategory settings (Windows Vista or later) to override audit policy category settings Not Defined Audit: Shut down system immediately if unable to log security audits Disabled DCOM: Machine Access Restrictions in Security Descriptor Definition Language (SDDL) syntax Not Defined DCOM: Machine Launch Restrictions in Security Descriptor Definition Language (SDDL) syntax Not Defined Devices: Allow undock without having to log on Enabled Devices: Allowed to format and eject removable media Not Defined Devices: Prevent users from installing printer drivers Disabled Devices: Restrict CD-ROM access to locally logged-on user only Not Defined Devices: Restrict floppy access to locally logged-on user only Not Defined Domain controller: Allow server operators to schedule tasks Not Defined Domain controller: LDAP server channel binding token requirements Not Defined Domain controller: LDAP server signing requirements Not Defined Domain controller: Refuse machine account password changes Not Defined Domain member: Digitally encrypt or sign secure channel data (always) Enabled Domain member: Digitally encrypt secure channel data (when possible) Enabled Domain member: Digitally sign secure channel data (when possible) Enabled Domain member: Disable machine account password changes Disabled Domain member: Maximum machine account password age 30 days Domain member: Require strong (Windows 2000 or later) session key Enabled Interactive logon: Display user information when the session is locked Not Defined Interactive logon: Do not require CTRL+ALT+DEL Not Defined Interactive logon: Don't display last signed-in Disabled Interactive logon: Don't display username at sign-in Not Defined Interactive logon: Machine account lockout threshold Not Defined Interactive logon: Machine inactivity limit Not Defined Interactive logon: Message text for users attempting to log on Interactive logon: Message title for users attempting to log on Interactive logon: Number of previous logons to cache (in case domain controller is not available) 10 logons Interactive logon: Prompt user to change password before expiration 5 days Interactive logon: Require Domain Controller authentication to unlock workstation Disabled Interactive logon: Require Windows Hello for Business or smart card Disabled Interactive logon: Smart card removal behavior No Action Microsoft network client: Digitally sign communications (always) Disabled Microsoft network client: Digitally sign communications (if server agrees) Enabled Microsoft network client: Send unencrypted password to third-party SMB servers Disabled Microsoft network server: Amount of idle time required before suspending session Not Defined Microsoft network server: Attempt S4U2Self to obtain claim information Not Defined Microsoft network server: Digitally sign communications (always) Disabled Microsoft network server: Digitally sign communications (if client agrees) Disabled Microsoft network server: Disconnect clients when logon hours expire Enabled Microsoft network server: Server SPN target name validation level Not Defined Network access: Allow anonymous SID/Name translation Disabled Network access: Do not allow anonymous enumeration of SAM accounts Enabled Network access: Do not allow anonymous enumeration of SAM accounts and shares Disabled Network access: Do not allow storage of passwords and credentials for network authentication Disabled Network access: Let Everyone permissions apply to anonymous users Disabled Network access: Named Pipes that can be accessed anonymously Network access: Remotely accessible registry paths System\CurrentControlSet\Control\ProductOptions,System\CurrentControlSet\Control\Server Applications,Software\Microsoft\Windows NT\CurrentVersion Network access: Remotely accessible registry paths and sub-paths System\CurrentControlSet\Control\Print\Printers,System\CurrentControlSet\Services\Eventlog,Software\Microsoft\OLAP Server,Software\Microsoft\Windows NT\CurrentVersion\Print,Software\Microsoft\Windows NT\CurrentVersion\Windows,System\CurrentControlSet\Control\ContentIndex,System\CurrentControlSet\Control\Terminal Server,System\CurrentControlSet\Control\Terminal Server\UserConfig,System\CurrentControlSet\Control\Terminal Server\DefaultUserConfiguration,Software\Microsoft\Windows NT\CurrentVersion\Perflib,System\CurrentControlSet\Services\SysmonLog Network access: Restrict anonymous access to Named Pipes and Shares Enabled Network access: Restrict clients allowed to make remote calls to SAM Network access: Shares that can be accessed anonymously Not Defined Network access: Sharing and security model for local accounts Classic - local users authenticate as themselves Network security: Allow Local System to use computer identity for NTLM Not Defined Network security: Allow LocalSystem NULL session fallback Not Defined Network security: Allow PKU2U authentication requests to this computer to use online identities. Not Defined Network security: Configure encryption types allowed for Kerberos Not Defined Network security: Do not store LAN Manager hash value on next password change Enabled Network security: Force logoff when logon hours expire Disabled Network security: LAN Manager authentication level Not Defined Network security: LDAP client signing requirements Negotiate signing Network security: Minimum session security for NTLM SSP based (including secure RPC) clients Require 128-bit encryption Network security: Minimum session security for NTLM SSP based (including secure RPC) servers Require 128-bit encryption Network security: Restrict NTLM: Add remote server exceptions for NTLM authentication Not Defined Network security: Restrict NTLM: Add server exceptions in this domain Not Defined Network security: Restrict NTLM: Audit Incoming NTLM Traffic Not Defined Network security: Restrict NTLM: Audit NTLM authentication in this domain Not Defined Network security: Restrict NTLM: Incoming NTLM traffic Not Defined Network security: Restrict NTLM: NTLM authentication in this domain Not Defined Network security: Restrict NTLM: Outgoing NTLM traffic to remote servers Not Defined Recovery console: Allow automatic administrative logon Not Defined Recovery console: Allow floppy copy and access to all drives and all folders Not Defined Shutdown: Allow system to be shut down without having to log on Enabled Shutdown: Clear virtual memory pagefile Disabled System cryptography: Force strong key protection for user keys stored on the computer Not Defined System cryptography: Use FIPS compliant algorithms for encryption, hashing, and signing Disabled System objects: Require case insensitivity for non-Windows subsystems Enabled System objects: Strengthen default permissions of internal system objects (e.g. Symbolic Links) Enabled System settings: Optional subsystems Posix System settings: Use Certificate Rules on Windows Executables for Software Restriction Policies Disabled User Account Control: Admin Approval Mode for the Built-in Administrator account Not Defined User Account Control: Allow UIAccess applications to prompt for elevation without using the secure desktop Disabled User Account Control: Behavior of the elevation prompt for administrators in Admin Approval Mode Prompt for consent for non-Windows binaries User Account Control: Behavior of the elevation prompt for standard users Prompt for credentials User Account Control: Detect application installations and prompt for elevation Enabled User Account Control: Only elevate executables that are signed and validated Disabled User Account Control: Only elevate UIAccess applications that are installed in secure locations Enabled User Account Control: Run all administrators in Admin Approval Mode Enabled User Account Control: Switch to the secure desktop when prompting for elevation Enabled User Account Control: Virtualize file and registry write failures to per-user locations Enabled Device Tree ACPI x64-based PC Microsoft ACPI-Compliant System ACPI Fixed Feature Button ACPI Power Button Intel Core i5 CPU 650 @ 3.20GHz Intel Core i5 CPU 650 @ 3.20GHz Intel Core i5 CPU 650 @ 3.20GHz Intel Core i5 CPU 650 @ 3.20GHz System board PCI Express Root Complex Intel 5 Series/3400 Series Chipset Family PCI Express Root Port 1 - 3B42 Intel 5 Series/3400 Series Chipset Family SMBus Controller - 3B30 Intel Management Engine Interface Intel processor DRAM Controller - 0040 Motherboard resources PCI-to-PCI Bridge System board Intel(R) processor PCI Express Root Port - 0041 NVIDIA GeForce GTX 260 Generic PnP Monitor Intel(R) 5 Series/3400 Series Chipset Family USB Enhanced Host Controller - 3B3C USB Root Hub Generic USB Hub USB Mass Storage Device Seagate Desktop USB Device USB Input Device HID Keyboard Device High Definition Audio Controller Intel Display Audio Realtek High Definition Audio Realtek Digital Output (Realtek High Definition Audio) Realtek HDMI Output (Realtek High Definition Audio) Speakers (Realtek High Definition Audio) Intel(R) 5 Series/3400 Series Chipset Family PCI Express Root Port 2 - 3B44 VIA 1394 OHCI Compliant Host Controller Intel(R) 5 Series/3400 Series Chipset Family PCI Express Root Port 6 - 3B4C Broadcom NetLink Gigabit Ethernet Intel(R) 5 Series/3400 Series Chipset Family USB Enhanced Host Controller - 3B34 USB Root Hub Generic USB Hub Unknown USB Device (Device Descriptor Request Failed) USB Composite Device USB Input Device HID-compliant mouse USB Input Device HID-compliant consumer control device HID-compliant vendor-defined device HID-compliant vendor-defined device NETGEAR A6100 WiFi Adapter Microsoft Wi-Fi Direct Virtual Adapter Microsoft Wi-Fi Direct Virtual Adapter #3 Intel(R) H57 Express Chipset LPC Interface Controller - 3B08 Direct memory access controller High precision event timer Legacy device Motherboard resources Motherboard resources Motherboard resources Motherboard resources Numeric data processor Programmable interrupt controller System CMOS/real time clock System speaker System timer Intel Chipset SATA RAID Controller HL-DT-ST DVD+-RW GH50N HL-DT-ST DVD+-RW GH50N Intel Raid 0 Volume CPU Intel Core i5 650 Cores 2 Threads 4 Name Intel Core i5 650 Code Name Clarkdale Package Socket 1156 LGA Technology 32nm Specification Intel Core i5 CPU 650 @ 3.20GHz Family 6 Extended Family 6 Model 5 Extended Model 25 Stepping 2 Revision C2 Instructions MMX, SSE, SSE2, SSE3, SSSE3, SSE4.1, SSE4.2, Intel 64, NX, VMX, AES Virtualization Supported, Enabled Hyperthreading Supported, Enabled Fan Speed 900 RPM Rated Bus Speed 3192.4 MHz Stock Core Speed 3200 MHz Stock Bus Speed 133 MHz Average Temperature 49 °C Caches L1 Data Cache Size 2 x 32 KBytes L1 Instructions Cache Size 2 x 32 KBytes L2 Unified Cache Size 2 x 256 KBytes L3 Unified Cache Size 4096 KBytes Cores Core 0 Core Speed 1197.1 MHz Multiplier x 9.0 Bus Speed 133.0 MHz Rated Bus Speed 3192.4 MHz Temperature 48 °C Threads APIC ID: 0, 1 Core 1 Core Speed 1463.2 MHz Multiplier x 11.0 Bus Speed 133.0 MHz Rated Bus Speed 3192.4 MHz Temperature 50 °C Threads APIC ID: 4, 5 RAM Memory slots Total memory slots 4 Used memory slots 2 Free memory slots 2 Memory Type DDR3 Size 4096 MBytes Channels # Dual DRAM Frequency 532.1 MHz CAS# Latency (CL) 7 clocks RAS# to CAS# Delay (tRCD) 7 clocks RAS# Precharge (tRP) 7 clocks Cycle Time (tRAS) 20 clocks Command Rate (CR) 1T Physical Memory Memory Usage 79 % Total Physical 3.87 GB Available Physical 808 MB Total Virtual 9.12 GB Available Virtual 3.67 GB SPD Number Of SPD Modules 2 Slot #1 Type DDR3 Size 2048 MBytes Manufacturer Samsung Max Bandwidth PC3-8500F (533 MHz) Part Number M378B5673FH0-CF8 Serial Number 1667607120 Week/year 15 / 10 Timing table JEDEC #1 Frequency 457.1 MHz CAS# Latency 6.0 RAS# To CAS# 6 RAS# Precharge 6 tRAS 18 tRC 24 Voltage 1.500 V JEDEC #2 Frequency 533.3 MHz CAS# Latency 7.0 RAS# To CAS# 7 RAS# Precharge 7 tRAS 20 tRC 27 Voltage 1.500 V JEDEC #3 Frequency 533.3 MHz CAS# Latency 8.0 RAS# To CAS# 7 RAS# Precharge 7 tRAS 20 tRC 27 Voltage 1.500 V Slot #2 Type DDR3 Size 2048 MBytes Manufacturer Samsung Max Bandwidth PC3-8500F (533 MHz) Part Number M378B5673FH0-CF8 Serial Number 1667607017 Week/year 15 / 10 Timing table JEDEC #1 Frequency 457.1 MHz CAS# Latency 6.0 RAS# To CAS# 6 RAS# Precharge 6 tRAS 18 tRC 24 Voltage 1.500 V JEDEC #2 Frequency 533.3 MHz CAS# Latency 7.0 RAS# To CAS# 7 RAS# Precharge 7 tRAS 20 tRC 27 Voltage 1.500 V JEDEC #3 Frequency 533.3 MHz CAS# Latency 8.0 RAS# To CAS# 7 RAS# Precharge 7 tRAS 20 tRC 27 Voltage 1.500 V Motherboard Manufacturer Dell Inc. Model 0T568R (CPU 1) Version A00 Chipset Vendor Intel Chipset Model Havendale/Clarkdale Host Bridge Chipset Revision 12 Southbridge Vendor Intel Southbridge Model H57 Southbridge Revision 06 System Temperature 22 °C BIOS Brand Dell Inc. Version A03 Date 12/9/2009 Voltage CPU CORE 0.928 V MEMORY CONTROLLER 3.056 V +3.3V 3.328 V +5V 5.080 V +12V 11.968 V -12V -8.640 V -5V -8.640 V +5V HIGH THRESHOLD 4.919 V PCI Data Slot PCI Slot Type PCI Slot Usage Available Bus Width 32 bit Slot Designation PCI1 Characteristics 3.3V, Shared, PME Slot Number 0 Slot PCI-E Slot Type PCI-E Slot Usage Available Data lanes x1 Slot Designation PCIE1 Characteristics 3.3V, Shared, PME Slot Number 1 Slot PCI-E Slot Type PCI-E Slot Usage Available Data lanes x1 Slot Designation PCIE2 Characteristics 3.3V, Shared, PME Slot Number 2 Slot PCI-E Slot Type PCI-E Slot Usage In Use Data lanes x16 Slot Designation PCIE3 Characteristics 3.3V, Shared, PME Slot Number 3 Graphics Monitor Name IPS236 on NVIDIA GeForce GTX 260 Current Resolution 1920x1080 pixels Work Resolution 1858x1080 pixels State Enabled, Primary Monitor Width 1920 Monitor Height 1080 Monitor BPP 32 bits per pixel Monitor Frequency 60 Hz Device \\.\DISPLAY1\Monitor0 NVIDIA GeForce GTX 260 Manufacturer NVIDIA Model GeForce GTX 260 GPU GT200 Device ID 10DE-05EA Revision A2 Subvendor NVIDIA (10DE) Current Performance Level Level 0 Technology 55 nm Die Size 576 mm˛ DirectX Support 10.0 OpenGL Support 4.0 Bus Interface PCI Express x16 Temperature 61 °C Driver version 21.21.13.4201 BIOS Version 62.00.67.00.04 ROPs 28 Shaders 192 unified Memory Type GDDR3 Memory 1792 MB Bus Width 64x7 (448 bit) Anti Aliasing Modes -?- Filtering Modes Bilinear, Trilinear, 2x Anisotropic, 4x Anisotropic, 8x Anisotropic, 16x Anisotropic Noise Level Moderate Max Power Draw 182 Watts Count of performance levels : 1 Level 1 - "Perf Level 0" Storage Hard drives Intel Raid 0 Volume Manufacturer Intel Serial Number Volume Firmware Version Number 1.0.00 Interface RAID Capacity 596 GB Real size 640,140,967,936 bytes RAID Type Software RAID S.M.A.R.T S.M.A.R.T not supported Partition 0 Partition ID Disk #0, Partition #0 Size 39.1 MB Partition 1 Partition ID Disk #0, Partition #1 File System NTFS Volume Serial Number FC0DE348 Size 10.1 GB Used Space 6.36 GB (62%) Free Space 3.76 GB (38%) Partition 2 Partition ID Disk #0, Partition #2 Disk Letter C: File System NTFS Volume Serial Number 8E103884 Size 586 GB Used Space 102 GB (17%) Free Space 483 GB (83%) Seagate Desktop USB Device Heads 16 Cylinders 121,601 Tracks 31,008,255 Sectors 1,953,520,065 SATA type SATA-II 3.0Gb/s Device type Fixed ATA Standard ATA8-ACS Serial Number 9VP0MS0K Firmware Version Number CC35 LBA Size 48-bit LBA Power On Count 102 times Power On Time 24.5 days Speed 7200 RPM Features S.M.A.R.T., AAM, NCQ Max. Transfer Mode SATA II 3.0Gb/s Used Transfer Mode SATA II 3.0Gb/s Interface USB (SATA) Capacity 931 GB Real size 1,000,204,886,016 bytes RAID Type None S.M.A.R.T Status Warning Temperature 40 °C Temperature Range OK (less than 50 °C) S.M.A.R.T attributes 01 Attribute name Read Error Rate Real value 0 Current 115 Worst 99 Threshold 6 Raw Value 00051A1BF5 Status Good 03 Attribute name Spin-Up Time Real value 0 ms Current 96 Worst 95 Threshold 0 Raw Value 0000000000 Status Good 04 Attribute name Start/Stop Count Real value 26,302 Current 75 Worst 75 Threshold 20 Raw Value 00000066BE Status Good 05 Attribute name Reallocated Sectors Count Real value 821 Current 80 Worst 80 Threshold 36 Raw Value 0000000335 Status Good 07 Attribute name Seek Error Rate Real value 0 Current 61 Worst 55 Threshold 30 Raw Value 00030BF8F5 Status Good 09 Attribute name Power-On Hours (POH) Real value 24d 11h Current 100 Worst 11 Threshold 0 Raw Value 000000024B Status Good 0A Attribute name Spin Retry Count Real value 0 Current 100 Worst 100 Threshold 97 Raw Value 0000000000 Status Good 0C Attribute name Device Power Cycle Count Real value 102 Current 100 Worst 100 Threshold 20 Raw Value 0000000066 Status Good B7 Attribute name SATA Downshift Error Count Real value 0 Current 100 Worst 100 Threshold 0 Raw Value 0000000000 Status Good B8 Attribute name End-to-End error / IOEDC Real value 0 Current 100 Worst 100 Threshold 99 Raw Value 0000000000 Status Good BB Attribute name Reported Uncorrectable Errors Real value 1 Current 99 Worst 99 Threshold 0 Raw Value 0000000001 Status Good BC Attribute name Command Timeout Real value 571,239,432,334 Current 100 Worst 87 Threshold 0 Raw Value 000086008E Status Good BD Attribute name High Fly Writes (WDC) Real value 2 Current 98 Worst 98 Threshold 0 Raw Value 0000000002 Status Good BE Attribute name Airflow Temperature Real value 39 °C Current 61 Worst 45 Threshold 45 Raw Value 00361B0027 Status Good C2 Attribute name Temperature Real value 39 °C Current 39 Worst 55 Threshold 0 Raw Value 0000000027 Status Good C3 Attribute name Hardware ECC Recovered Real value 0 Current 33 Worst 18 Threshold 0 Raw Value 00051A1BF5 Status Good C5 Attribute name Current Pending Sector Count Real value 0 Current 100 Worst 100 Threshold 0 Raw Value 0000000000 Status Good C6 Attribute name Uncorrectable Sector Count Real value 0 Current 100 Worst 100 Threshold 0 Raw Value 0000000000 Status Good C7 Attribute name UltraDMA CRC Error Count Real value 0 Current 200 Worst 200 Threshold 0 Raw Value 0000000000 Status Good F0 Attribute name Head Flying Hours Real value 1346d 9h Current 100 Worst 253 Threshold 0 Raw Value 0000007E39 Status Good F1 Attribute name Total LBAs Written Real value 407,547,562 Current 100 Worst 253 Threshold 0 Raw Value 00184AAEAA Status Good F2 Attribute name Total LBAs Read Real value 2,690,226,143 Current 100 Worst 253 Threshold 0 Raw Value 00A05997DF Status Good Partition 0 Partition ID Disk #1, Partition #0 Disk Letter K: File System NTFS Volume Serial Number 30B588A4 Size 931 GB Used Space 730 GB (78%) Free Space 201 GB (22%) Optical Drives HL-DT-ST DVD+-RW GH50N Media Type DVD Writer Name HL-DT-ST DVD+-RW GH50N Availability Running/Full Power Capabilities Random Access, Supports Writing, Supports Removable Media Read capabilities CD-R, CD-RW, CD-ROM, DVD-RAM, DVD-ROM, DVD-R, DVD-RW, DVD+R, DVD+RW, DVD-R DL, DVD+R DL Write capabilities CD-R, CD-RW, DVD-RAM, DVD-R, DVD-RW, DVD+R, DVD+RW, DVD-R DL, DVD+R DL Config Manager Error Code Device is working properly Config Manager User Config FALSE Drive D: Media Loaded FALSE SCSI Bus 0 SCSI Logical Unit 0 SCSI Port 0 SCSI Target Id 2 Status OK HL-DT-ST DVD+-RW GH50N Media Type DVD Writer Name HL-DT-ST DVD+-RW GH50N Availability Running/Full Power Capabilities Random Access, Supports Writing, Supports Removable Media Read capabilities CD-R, CD-RW, CD-ROM, DVD-RAM, DVD-ROM, DVD-R, DVD-RW, DVD+R, DVD+RW, DVD-R DL, DVD+R DL Write capabilities CD-R, CD-RW, DVD-RAM, DVD-R, DVD-RW, DVD+R, DVD+RW, DVD-R DL, DVD+R DL Config Manager Error Code Device is working properly Config Manager User Config FALSE Drive E: Media Loaded FALSE SCSI Bus 0 SCSI Logical Unit 0 SCSI Port 0 SCSI Target Id 3 Status OK Audio Sound Cards Intel Display Audio Realtek High Definition Audio Playback Devices Realtek Digital Output (Realtek High Definition Audio) Speakers (Realtek High Definition Audio) (default) Realtek HDMI Output (Realtek High Definition Audio) Peripherals HID Keyboard Device Device Kind Keyboard Device Name HID Keyboard Device Vendor Unknown Location USB Input Device Driver Date 6-21-2006 Version 10.0.18362.1 File C:\WINDOWS\system32\DRIVERS\kbdhid.sys File C:\WINDOWS\system32\DRIVERS\kbdclass.sys HID-compliant mouse Device Kind Mouse Device Name HID-compliant mouse Vendor Logitech Location USB Input Device Driver Date 6-21-2006 Version 10.0.18362.1 File C:\WINDOWS\system32\DRIVERS\mouhid.sys File C:\WINDOWS\system32\DRIVERS\mouclass.sys HP ENVY Photo 7100 series PCL-3 Device Kind Printer Device Name HP ENVY Photo 7100 series PCL-3 Vendor HP Location http://[fe80::9657:a5ff:fe0c:cb09%3]:3911/ Driver Date 12-5-2017 Version 24.94.1.7079 WSD Scan Device Device Kind Camera/scanner Device Name WSD Scan Device Vendor Hewlett-Packard Comment HP0CCB09 (HP ENVY Photo 7100 series) Location http://[fe80::9657:a5ff:fe0c:cb09%4]:3911/ Driver Date 6-21-2006 Version 10.0.18362.1 File C:\WINDOWS\System32\drivers\WSDScan.sys HP ENVY Photo 7100 (NET) Device Kind Camera/scanner Device Name HP ENVY Photo 7100 (NET) Vendor HP Driver Date 2-10-2017 Version 44.1.2402.1741 File C:\WINDOWS\system32\HPWia2_EN7100.dll File C:\WINDOWS\system32\HPScanTEDrv_EN7100_x64.dll File C:\WINDOWS\system32\HPScanTEDrv_EN7100_x64_DiscoveryLibDyn.dll File C:\WINDOWS\SysWOW64\HPScanTEDrv_EN7100.dll File C:\WINDOWS\SysWOW64\HPScanTEDrv_EN7100_DiscoveryLibDyn.dll File C:\WINDOWS\system32\drivers\serscan.sys Desktop Device Kind Portable Device Device Name Desktop Vendor Seagate Comment Expansion Drive Location Volume Driver Date 6-21-2006 Version 10.0.18362.1 File C:\WINDOWS\system32\DRIVERS\WUDFRd.sys Printers Fax Printer Port SHRFAX: Print Processor winprint Availability Always Priority 1 Duplex None Print Quality 200 * 200 dpi Monochrome Status Unknown Driver Driver Name Microsoft Shared Fax Driver (v4.00) Driver Path C:\WINDOWS\system32\spool\DRIVERS\x64\3\FXSDRV.DLL HP ENVY Photo 7100 series PCL-3 (Network) (Default Printer) Printer Port WSD-b226f51a-cff2-475e-9e93-da2062619bcf.0034 Print Processor winprint Availability Always Priority 1 Duplex None Print Quality 600 * 600 dpi Color Status Unknown Driver Driver Name HP ENVY Photo 7100 series PCL-3 (v6.03) Driver Path C:\WINDOWS\System32\DriverStore\FileRepository\ntprint.inf_amd64_829b03839496f36b\Amd64\mxdwdrv.dll Microsoft Print to PDF Printer Port PORTPROMPT: Print Processor winprint Availability Always Priority 1 Duplex None Print Quality 600 * 600 dpi Color Status Unknown Driver Driver Name Microsoft Print To PDF (v6.03) Driver Path C:\WINDOWS\System32\DriverStore\FileRepository\ntprint.inf_amd64_829b03839496f36b\Amd64\mxdwdrv.dll Microsoft XPS Document Writer Printer Port PORTPROMPT: Print Processor winprint Availability Always Priority 1 Duplex None Print Quality 600 * 600 dpi Color Status Unknown Driver Driver Name Microsoft XPS Document Writer v4 (v6.03) Driver Path C:\WINDOWS\System32\DriverStore\FileRepository\ntprint.inf_amd64_829b03839496f36b\Amd64\mxdwdrv.dll OneNote for Windows 10 Printer Port Microsoft.Office.OneNote_16001.12730.20190.0_x64__8wekyb3d8bbwe_microsoft.onenoteim_S-1-5-21-2126779717-1312616141-414031349-1003 Print Processor winprint Availability Always Priority 1 Duplex None Print Quality 300 * 300 dpi Color Status Unknown Driver Driver Name Microsoft Software Printer Driver (v6.03) Driver Path C:\WINDOWS\System32\DriverStore\FileRepository\ntprint.inf_amd64_829b03839496f36b\Amd64\mxdwdrv.dll Send To OneNote 2013 Printer Port nul: Print Processor winprint Availability Always Priority 1 Duplex None Print Quality 600 * 600 dpi Color Status Unknown Driver Driver Name Send to Microsoft OneNote 15 Driver (v6.03) Driver Path C:\WINDOWS\System32\DriverStore\FileRepository\ntprint.inf_amd64_829b03839496f36b\Amd64\mxdwdrv.dll Network You are connected to the internet Connected through NETGEAR A6100 WiFi Adapter IP Address 10.0.0.171 Subnet mask 255.255.255.0 Gateway server 10.0.0.1 Preferred DNS server 75.75.75.75 Alternate DNS server 75.75.76.76 DHCP Enabled DHCP server 10.0.0.1 External IP Address 73.3.237.135 Adapter Type IEEE 802.11 wireless NetBIOS over TCP/IP Enabled via DHCP NETBIOS Node Type Hybrid node Link Speed 0 Bps Computer Name NetBIOS Name STEVE-PC DNS Name Steve-PC Membership Part of workgroup Workgroup WORKGROUP Remote Desktop Disabled Console State Active Domain STEVE-PC WinInet Info LAN Connection Local system uses a local area network to connect to the Internet Local system has RAS to connect to the Internet Wi-Fi Info Using native Wi-Fi API version 2 Available access points count 13 Wi-Fi () SSID Frequency 5785000 kHz Channel Number 157 Name No name Signal Strength/Quality 100 Security Enabled State The interface is connected to a network Dot11 Type Infrastructure BSS network Network Connectible Network Flags There is a profile for this network Cipher Algorithm to be used when joining this network AES-CCMP algorithm Default Auth used to join this network for the first time 802.11i Robust Security Network Association (RSNA) algorithm (WPA2 is one such algorithm) Wi-Fi (CenturyLink7170) SSID CenturyLink7170 Frequency 2412000 kHz Channel Number 1 Name CenturyLink7170 Signal Strength/Quality 100 Security Enabled State The interface is connected to a network Dot11 Type Infrastructure BSS network Network Connectible Network Flags There is a profile for this network Cipher Algorithm to be used when joining this network AES-CCMP algorithm Default Auth used to join this network for the first time 802.11i RSNA algorithm that uses PSK Wi-Fi (DIRECT-09-HP ENVY Photo 7100) SSID DIRECT-09-HP ENVY Photo 7100 Frequency 5180000 kHz Channel Number 36 Name DIRECT-09-HP ENVY Photo 7100 Signal Strength/Quality 100 Security Enabled State The interface is connected to a network Dot11 Type Infrastructure BSS network Network Connectible Network Flags There is a profile for this network Cipher Algorithm to be used when joining this network AES-CCMP algorithm Default Auth used to join this network for the first time 802.11i RSNA algorithm that uses PSK Wi-Fi (Jesus) SSID Jesus Frequency 5220000 kHz Channel Number 44 Name Jesus Signal Strength/Quality 100 Security Enabled State The interface is connected to a network Dot11 Type Infrastructure BSS network Network Connectible Network Flags There is a profile for this network Cipher Algorithm to be used when joining this network AES-CCMP algorithm Default Auth used to join this network for the first time 802.11i RSNA algorithm that uses PSK Wi-Fi (ODOEV) SSID ODOEV Frequency 2457000 kHz Channel Number 10 Name ODOEV Signal Strength/Quality 64 Security Enabled State The interface is connected to a network Dot11 Type Infrastructure BSS network Network Connectible Network Flags There is a profile for this network Cipher Algorithm to be used when joining this network AES-CCMP algorithm Default Auth used to join this network for the first time 802.11i RSNA algorithm that uses PSK Wi-Fi (ODOEVA_5G) SSID ODOEVA_5G Frequency 5745000 kHz Channel Number 149 Name ODOEVA_5G Signal Strength/Quality 43 Security Enabled State The interface is connected to a network Dot11 Type Infrastructure BSS network Network Connectible Network Flags There is a profile for this network Cipher Algorithm to be used when joining this network AES-CCMP algorithm Default Auth used to join this network for the first time 802.11i RSNA algorithm that uses PSK Wi-Fi (RT-AC66U_B1_F8_5G) SSID RT-AC66U_B1_F8_5G Frequency 5785000 kHz Channel Number 157 Name RT-AC66U_B1_F8_5G Signal Strength/Quality 72 Security Enabled State The interface is connected to a network Dot11 Type Infrastructure BSS network Network Connectible Network Flags There is a profile for this network Cipher Algorithm to be used when joining this network AES-CCMP algorithm Default Auth used to join this network for the first time 802.11i RSNA algorithm that uses PSK Wi-Fi (Steve) SSID Steve Frequency 2412000 kHz Channel Number 1 Name Steve Signal Strength/Quality 100 Security Enabled State The interface is connected to a network Dot11 Type Infrastructure BSS network Network Connectible Network Flags Currently Connected to this network Cipher Algorithm to be used when joining this network AES-CCMP algorithm Default Auth used to join this network for the first time 802.11i RSNA algorithm that uses PSK Wi-Fi (Steve-5) SSID Steve-5 Frequency 5180000 kHz Channel Number 36 Name Steve-5 Signal Strength/Quality 100 Security Enabled State The interface is connected to a network Dot11 Type Infrastructure BSS network Network Connectible Network Flags There is a profile for this network Cipher Algorithm to be used when joining this network AES-CCMP algorithm Default Auth used to join this network for the first time 802.11i RSNA algorithm that uses PSK Wi-Fi (XFINITY) SSID XFINITY Frequency 5785000 kHz Channel Number 157 Name XFINITY Signal Strength/Quality 100 Security Enabled State The interface is connected to a network Dot11 Type Infrastructure BSS network Network Connectible Network Flags There is a profile for this network Cipher Algorithm to be used when joining this network AES-CCMP algorithm Default Auth used to join this network for the first time 802.11i Robust Security Network Association (RSNA) algorithm (WPA2 is one such algorithm) Wi-Fi (XFSETUP-FBDA) SSID XFSETUP-FBDA Frequency 5785000 kHz Channel Number 157 Name XFSETUP-FBDA Signal Strength/Quality 47 Security Enabled State The interface is connected to a network Dot11 Type Infrastructure BSS network Network Connectible Network Flags There is a profile for this network Cipher Algorithm to be used when joining this network AES-CCMP algorithm Default Auth used to join this network for the first time 802.11i RSNA algorithm that uses PSK Wi-Fi (mercury28) SSID mercury28 Frequency 2452000 kHz Channel Number 9 Name mercury28 Signal Strength/Quality 100 Security Enabled State The interface is connected to a network Dot11 Type Infrastructure BSS network Network Connectible Network Flags There is a profile for this network Cipher Algorithm to be used when joining this network AES-CCMP algorithm Default Auth used to join this network for the first time 802.11i RSNA algorithm that uses PSK Wi-Fi (xfinitywifi) SSID xfinitywifi Frequency 5220000 kHz Channel Number 44 Name xfinitywifi Signal Strength/Quality 100 Security Disabled State The interface is connected to a network Dot11 Type Infrastructure BSS network Network Connectible Network Flags There is a profile for this network Cipher Algorithm to be used when joining this network No Cipher algorithm is enabled/supported Default Auth used to join this network for the first time IEEE 802.11 Open System authentication algorithm WinHTTPInfo WinHTTPSessionProxyType No proxy Session Proxy Session Proxy Bypass Connect Retries 5 Connect Timeout (ms) 60,000 HTTP Version HTTP 1.1 Max Connects Per 1.0 Servers INFINITE Max Connects Per Servers INFINITE Max HTTP automatic redirects 10 Max HTTP status continue 10 Send Timeout (ms) 30,000 IEProxy Auto Detect Yes IEProxy Auto Config IEProxy IEProxy Bypass Default Proxy Config Access Type No proxy Default Config Proxy Default Config Proxy Bypass Sharing and Discovery File and printer sharing service Enabled Simple File Sharing Enabled Administrative Shares Enabled Network access: Sharing and security model for local accounts Classic - local users authenticate as themselves Private profile Network Discovery Enabled File and Printer Sharing Enabled Public profile Network Discovery Enabled File and Printer Sharing Enabled Adapters List Enabled Broadcom NetLink (TM) Gigabit Ethernet Connection Name Local Area Connection DHCP enabled Yes MAC Address A4-BA-DB-F5-7C-3D NETGEAR A6100 WiFi Adapter Connection-specific DNS Suffix hsd1.co.comcast.net Connection Name Wi-Fi NetBIOS over TCPIP Yes DHCP enabled Yes MAC Address B0-39-56-8B-4E-F9 IP Address 10.0.0.171 Subnet mask 255.255.255.0 Gateway server 10.0.0.1 DHCP 10.0.0.1 DNS Server 75.75.75.75 75.75.76.76 NordLynx Tunnel Connection Name NordLynx NetBIOS over TCPIP Yes DHCP enabled No IP Address 169.254.57.70 Subnet mask 255.255.0.0 TAP-NordVPN Windows Adapter V9 Connection Name Ethernet 2 DHCP enabled Yes MAC Address 00-FF-D1-60-99-86 TAP-Windows Adapter V9 Connection Name Ethernet DHCP enabled Yes MAC Address 00-FF-5A-F0-B6-C1 Network Shares Users C:\Users Current TCP Connections C:\Program Files (x86)\NordVPN\NordVPN.exe (13520) Local 10.0.0.171:52505 ESTABLISHED Remote 3.212.150.249:8884 (Querying... ) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (10512) Local 127.0.0.1:23401 LISTEN C:\Program Files (x86)\Steam\steam.exe (13432) Local 0.0.0.0:27036 LISTEN Local 127.0.0.1:27060 LISTEN C:\PROGRA~1\HP\HPENVY~1\Bin\HPNETW~1.EXE (14156) Local 10.0.0.171:51018 CLOSE-WAIT Remote 10.0.0.174:80 (Querying... ) (HTTP) Local 10.0.0.171:52490 ESTABLISHED Remote 10.0.0.174:80 (Querying... ) (HTTP) C:\Users\Steve\AppData\Local\Microsoft\OneDrive\OneDrive.exe (13332) Local 10.0.0.171:51040 ESTABLISHED Remote 52.230.222.68:443 (Querying... ) (HTTPS) C:\Windows\System32\MicrosoftEdgeCP.exe (12920) Local 10.0.0.171:55977 CLOSE-WAIT Remote 104.254.148.166:443 (Querying... ) (HTTPS) Local 10.0.0.171:55099 ESTABLISHED Remote 104.112.249.46:443 (Querying... ) (HTTPS) Local 10.0.0.171:55115 ESTABLISHED Remote 23.4.14.113:443 (Querying... ) (HTTPS) Local 10.0.0.171:55129 ESTABLISHED Remote 23.211.23.115:443 (Querying... ) (HTTPS) Local 10.0.0.171:55561 ESTABLISHED Remote 146.20.132.38:443 (Querying... ) (HTTPS) Local 10.0.0.171:55563 CLOSE-WAIT Remote 54.84.169.173:443 (Querying... ) (HTTPS) Local 10.0.0.171:55564 ESTABLISHED Remote 23.4.14.113:443 (Querying... ) (HTTPS) Local 10.0.0.171:55570 ESTABLISHED Remote 34.197.92.111:443 (Querying... ) (HTTPS) Local 10.0.0.171:55573 ESTABLISHED Remote 23.211.23.115:443 (Querying... ) (HTTPS) Local 10.0.0.171:55574 ESTABLISHED Remote 23.211.23.115:443 (Querying... ) (HTTPS) Local 10.0.0.171:55575 ESTABLISHED Remote 34.197.92.111:443 (Querying... ) (HTTPS) Local 10.0.0.171:55576 ESTABLISHED Remote 13.57.87.105:443 (Querying... ) (HTTPS) Local 10.0.0.171:55587 ESTABLISHED Remote 3.219.214.100:443 (Querying... ) (HTTPS) Local 10.0.0.171:55697 ESTABLISHED Remote 184.87.218.39:443 (Querying... ) (HTTPS) Local 10.0.0.171:55749 ESTABLISHED Remote 35.244.159.8:443 (Querying... ) (HTTPS) Local 10.0.0.171:55786 ESTABLISHED Remote 8.39.36.180:443 (Querying... ) (HTTPS) Local 10.0.0.171:55978 CLOSE-WAIT Remote 104.254.148.166:443 (Querying... ) (HTTPS) Local 10.0.0.171:55979 CLOSE-WAIT Remote 104.254.148.166:443 (Querying... ) (HTTPS) Local 10.0.0.171:55980 CLOSE-WAIT Remote 104.254.148.166:443 (Querying... ) (HTTPS) Local 10.0.0.171:55981 CLOSE-WAIT Remote 104.254.148.166:443 (Querying... ) (HTTPS) Local 10.0.0.171:55982 ESTABLISHED Remote 35.186.236.204:443 (Querying... ) (HTTPS) Local 10.0.0.171:55983 ESTABLISHED Remote 35.186.236.204:443 (Querying... ) (HTTPS) Local 10.0.0.171:55984 ESTABLISHED Remote 184.87.217.134:443 (Querying... ) (HTTPS) Local 10.0.0.171:55985 ESTABLISHED Remote 184.87.217.134:443 (Querying... ) (HTTPS) Local 10.0.0.171:55986 ESTABLISHED Remote 23.50.129.102:443 (Querying... ) (HTTPS) Local 10.0.0.171:55987 ESTABLISHED Remote 23.50.129.102:443 (Querying... ) (HTTPS) Local 10.0.0.171:55989 CLOSE-WAIT Remote 50.31.142.95:443 (Querying... ) (HTTPS) Local 10.0.0.171:55914 ESTABLISHED Remote 52.204.68.29:443 (Querying... ) (HTTPS) Local 10.0.0.171:55946 ESTABLISHED Remote 151.101.70.2:443 (Querying... ) (HTTPS) Local 10.0.0.171:55910 ESTABLISHED Remote 52.53.54.100:443 (Querying... ) (HTTPS) Local 10.0.0.171:55947 ESTABLISHED Remote 151.101.70.2:443 (Querying... ) (HTTPS) Local 10.0.0.171:55950 CLOSE-WAIT Remote 69.16.175.10:443 (Querying... ) (HTTPS) Local 10.0.0.171:55951 CLOSE-WAIT Remote 69.16.175.10:443 (Querying... ) (HTTPS) Local 10.0.0.171:55958 CLOSE-WAIT Remote 69.16.175.42:443 (Querying... ) (HTTPS) Local 10.0.0.171:55959 CLOSE-WAIT Remote 69.16.175.42:443 (Querying... ) (HTTPS) Local 10.0.0.171:55960 CLOSE-WAIT Remote 23.4.14.113:443 (Querying... ) (HTTPS) Local 10.0.0.171:55971 CLOSE-WAIT Remote 38.106.34.115:443 (Querying... ) (HTTPS) Local 10.0.0.171:55972 CLOSE-WAIT Remote 38.106.34.115:443 (Querying... ) (HTTPS) Local 10.0.0.171:55976 CLOSE-WAIT Remote 104.254.148.166:443 (Querying... ) (HTTPS) Local 10.0.0.171:55841 ESTABLISHED Remote 8.39.36.164:443 (Querying... ) (HTTPS) Local 10.0.0.171:55815 ESTABLISHED Remote 23.66.48.57:443 (Querying... ) (HTTPS) Local 10.0.0.171:55812 CLOSE-WAIT Remote 44.229.98.14:443 (Querying... ) (HTTPS) Local 10.0.0.171:55811 CLOSE-WAIT Remote 34.228.98.110:443 (Querying... ) (HTTPS) Local 10.0.0.171:55809 CLOSE-WAIT Remote 52.45.66.108:443 (Querying... ) (HTTPS) Local 10.0.0.171:55805 ESTABLISHED Remote 208.185.50.56:443 (Querying... ) (HTTPS) Local 10.0.0.171:55800 ESTABLISHED Remote 74.121.138.91:443 (Querying... ) (HTTPS) Local 10.0.0.171:55787 ESTABLISHED Remote 8.39.36.180:443 (Querying... ) (HTTPS) C:\Windows\System32\MicrosoftEdgeCP.exe (404) Local 10.0.0.171:56040 ESTABLISHED Remote 184.84.231.31:443 (Querying... ) (HTTPS) Local 10.0.0.171:56043 ESTABLISHED Remote 23.216.81.235:443 (Querying... ) (HTTPS) Local 10.0.0.171:56044 ESTABLISHED Remote 23.216.81.235:443 (Querying... ) (HTTPS) Local 10.0.0.171:56045 ESTABLISHED Remote 23.216.81.235:443 (Querying... ) (HTTPS) Local 10.0.0.171:56046 ESTABLISHED Remote 23.216.81.235:443 (Querying... ) (HTTPS) Local 10.0.0.171:56055 ESTABLISHED Remote 139.178.90.123:443 (Querying... ) (HTTPS) Local 10.0.0.171:56056 ESTABLISHED Remote 139.178.90.123:443 (Querying... ) (HTTPS) Local 10.0.0.171:56059 ESTABLISHED Remote 147.75.68.35:443 (Querying... ) (HTTPS) Local 10.0.0.171:56060 ESTABLISHED Remote 147.75.68.35:443 (Querying... ) (HTTPS) Local 10.0.0.171:56061 ESTABLISHED Remote 184.85.193.125:443 (Querying... ) (HTTPS) Local 10.0.0.171:56062 ESTABLISHED Remote 184.85.193.125:443 (Querying... ) (HTTPS) Local 10.0.0.171:56063 ESTABLISHED Remote 52.24.71.252:443 (Querying... ) (HTTPS) Local 10.0.0.171:56064 ESTABLISHED Remote 52.24.71.252:443 (Querying... ) (HTTPS) Local 10.0.0.171:56065 ESTABLISHED Remote 172.217.12.2:443 (Querying... ) (HTTPS) Local 10.0.0.171:56066 ESTABLISHED Remote 172.217.12.2:443 (Querying... ) (HTTPS) Local 10.0.0.171:56067 ESTABLISHED Remote 74.121.138.90:443 (Querying... ) (HTTPS) Local 10.0.0.171:56068 ESTABLISHED Remote 74.121.138.90:443 (Querying... ) (HTTPS) Local 10.0.0.171:56069 ESTABLISHED Remote 69.194.244.13:443 (Querying... ) (HTTPS) Local 10.0.0.171:56070 ESTABLISHED Remote 69.194.244.13:443 (Querying... ) (HTTPS) Local 10.0.0.171:56071 ESTABLISHED Remote 52.34.132.185:443 (Querying... ) (HTTPS) Local 10.0.0.171:56072 ESTABLISHED Remote 52.34.132.185:443 (Querying... ) (HTTPS) Local 10.0.0.171:56073 ESTABLISHED Remote 104.254.148.196:443 (Querying... ) (HTTPS) Local 10.0.0.171:56039 ESTABLISHED Remote 184.84.231.31:443 (Querying... ) (HTTPS) Local 10.0.0.171:56075 ESTABLISHED Remote 100.24.196.187:443 (Querying... ) (HTTPS) Local 10.0.0.171:56076 ESTABLISHED Remote 100.24.196.187:443 (Querying... ) (HTTPS) Local 10.0.0.171:56077 ESTABLISHED Remote 52.26.73.125:443 (Querying... ) (HTTPS) Local 10.0.0.171:56078 ESTABLISHED Remote 52.26.73.125:443 (Querying... ) (HTTPS) Local 10.0.0.171:56079 ESTABLISHED Remote 205.210.187.128:443 (Querying... ) (HTTPS) Local 10.0.0.171:56080 ESTABLISHED Remote 205.210.187.128:443 (Querying... ) (HTTPS) Local 10.0.0.171:56081 ESTABLISHED Remote 23.216.81.235:443 (Querying... ) (HTTPS) Local 10.0.0.171:56082 ESTABLISHED Remote 23.216.81.235:443 (Querying... ) (HTTPS) Local 10.0.0.171:56083 ESTABLISHED Remote 23.216.81.235:443 (Querying... ) (HTTPS) Local 10.0.0.171:56084 ESTABLISHED Remote 35.161.145.47:443 (Querying... ) (HTTPS) Local 10.0.0.171:56085 ESTABLISHED Remote 35.161.145.47:443 (Querying... ) (HTTPS) Local 10.0.0.171:56086 ESTABLISHED Remote 184.85.193.125:443 (Querying... ) (HTTPS) Local 10.0.0.171:56087 ESTABLISHED Remote 184.85.193.125:443 (Querying... ) (HTTPS) Local 10.0.0.171:56074 ESTABLISHED Remote 104.254.148.196:443 (Querying... ) (HTTPS) Local 10.0.0.171:55993 ESTABLISHED Remote 151.101.70.202:80 (Querying... ) (HTTP) Local 10.0.0.171:55992 ESTABLISHED Remote 151.101.70.202:80 (Querying... ) (HTTP) Local 10.0.0.171:55998 ESTABLISHED Remote 35.190.25.25:443 (Querying... ) (HTTPS) Local 10.0.0.171:55999 ESTABLISHED Remote 35.190.25.25:443 (Querying... ) (HTTPS) Local 10.0.0.171:56000 ESTABLISHED Remote 35.190.25.25:443 (Querying... ) (HTTPS) Local 10.0.0.171:56001 ESTABLISHED Remote 72.21.91.29:80 (Querying... ) (HTTP) Local 10.0.0.171:56002 ESTABLISHED Remote 208.118.62.69:443 (Querying... ) (HTTPS) Local 10.0.0.171:56003 ESTABLISHED Remote 208.118.62.69:443 (Querying... ) (HTTPS) Local 10.0.0.171:56004 ESTABLISHED Remote 139.178.90.229:443 (Querying... ) (HTTPS) Local 10.0.0.171:56005 ESTABLISHED Remote 139.178.90.229:443 (Querying... ) (HTTPS) Local 10.0.0.171:56006 ESTABLISHED Remote 13.107.21.200:443 (Querying... ) (HTTPS) Local 10.0.0.171:56007 ESTABLISHED Remote 13.107.21.200:443 (Querying... ) (HTTPS) Local 10.0.0.171:56014 ESTABLISHED Remote 72.21.91.29:80 (Querying... ) (HTTP) Local 10.0.0.171:56017 ESTABLISHED Remote 139.178.90.123:443 (Querying... ) (HTTPS) Local 10.0.0.171:56018 ESTABLISHED Remote 139.178.90.123:443 (Querying... ) (HTTPS) Local 10.0.0.171:56019 CLOSE-WAIT Remote 151.139.237.73:80 (Querying... ) (HTTP) Local 10.0.0.171:56020 CLOSE-WAIT Remote 151.139.237.73:80 (Querying... ) (HTTP) Local 10.0.0.171:56021 CLOSE-WAIT Remote 151.139.237.73:80 (Querying... ) (HTTP) Local 10.0.0.171:56022 CLOSE-WAIT Remote 151.139.237.73:80 (Querying... ) (HTTP) Local 10.0.0.171:56023 ESTABLISHED Remote 151.101.70.202:80 (Querying... ) (HTTP) Local 10.0.0.171:56024 ESTABLISHED Remote 151.101.70.202:80 (Querying... ) (HTTP) Local 10.0.0.171:56025 ESTABLISHED Remote 23.216.81.235:443 (Querying... ) (HTTPS) Local 10.0.0.171:56026 ESTABLISHED Remote 23.216.81.235:443 (Querying... ) (HTTPS) Local 10.0.0.171:56032 ESTABLISHED Remote 34.96.102.137:80 (Querying... ) (HTTP) Local 10.0.0.171:56033 ESTABLISHED Remote 34.96.102.137:80 (Querying... ) (HTTP) Local 10.0.0.171:56034 ESTABLISHED Remote 34.96.102.137:443 (Querying... ) (HTTPS) Local 10.0.0.171:56038 ESTABLISHED Remote 192.124.249.23:80 (Querying... ) (HTTP) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe (2844) Local 10.0.0.171:56042 CLOSE-WAIT Remote 151.139.237.73:80 (Querying... ) (HTTP) Local 10.0.0.171:56041 ESTABLISHED Remote 151.139.237.73:80 (Querying... ) (HTTP) lsass.exe (944) Local 0.0.0.0:49664 LISTEN MBAMService.exe (3924) Local 127.0.0.1:43227 LISTEN mcshield.exe (7532) Local 10.0.0.171:54443 ESTABLISHED Remote 161.69.92.27:443 (Querying... ) (HTTPS) MfeAVSvc.exe (16452) Local 10.0.0.171:55943 ESTABLISHED Remote 8.21.161.73:443 (Querying... ) (HTTPS) MMSSHOST.exe (11072) Local 0.0.0.0:6646 LISTEN mqsvc.exe (3152) Local 0.0.0.0:1801 LISTEN Local 0.0.0.0:2103 LISTEN Local 0.0.0.0:2105 LISTEN Local 0.0.0.0:2107 LISTEN Local 0.0.0.0:49669 LISTEN services.exe (928) Local 0.0.0.0:49673 LISTEN spoolsv.exe (3196) Local 0.0.0.0:49668 LISTEN svchost.exe (1444) Local 0.0.0.0:49666 LISTEN svchost.exe (1632) Local 0.0.0.0:49667 LISTEN svchost.exe (2148) Local 0.0.0.0:5040 LISTEN svchost.exe (3348) Local 10.0.0.171:52457 ESTABLISHED Remote 52.230.222.68:443 (Querying... ) (HTTPS) svchost.exe (5792) Local 0.0.0.0:7680 LISTEN svchost.exe (772) Local 0.0.0.0:135 (DCE) LISTEN System Process Local 10.0.0.171:55175 TIME-WAIT Remote 35.227.202.209:443 (Querying... ) (HTTPS) Local 10.0.0.171:55595 TIME-WAIT Remote 35.244.159.8:443 (Querying... ) (HTTPS) Local 10.0.0.171:55895 TIME-WAIT Remote 35.244.159.8:443 (Querying... ) (HTTPS) Local 10.0.0.171:55596 TIME-WAIT Remote 35.244.159.8:443 (Querying... ) (HTTPS) Local 10.0.0.171:55603 TIME-WAIT Remote 35.244.159.8:443 (Querying... ) (HTTPS) Local 10.0.0.171:55604 TIME-WAIT Remote 35.244.159.8:443 (Querying... ) (HTTPS) Local 10.0.0.171:55615 TIME-WAIT Remote 40.79.66.194:443 (Querying... ) (HTTPS) Local 10.0.0.171:55629 TIME-WAIT Remote 35.241.8.149:443 (Querying... ) (HTTPS) Local 10.0.0.171:55721 TIME-WAIT Remote 104.36.113.19:443 (Querying... ) (HTTPS) Local 10.0.0.171:55630 TIME-WAIT Remote 35.241.8.149:443 (Querying... ) (HTTPS) Local 10.0.0.171:55645 TIME-WAIT Remote 172.217.11.226:443 (Querying... ) (HTTPS) Local 10.0.0.171:55646 TIME-WAIT Remote 172.217.11.226:443 (Querying... ) (HTTPS) Local 10.0.0.171:55656 TIME-WAIT Remote 8.39.36.144:443 (Querying... ) (HTTPS) Local 10.0.0.171:55945 TIME-WAIT Remote 161.69.13.35:443 (Querying... ) (HTTPS) Local 10.0.0.171:55719 TIME-WAIT Remote 34.98.64.218:443 (Querying... ) (HTTPS) Local 10.0.0.171:55720 TIME-WAIT Remote 34.98.64.218:443 (Querying... ) (HTTPS) Local 10.0.0.171:55901 TIME-WAIT Remote 35.244.159.8:443 (Querying... ) (HTTPS) Local 10.0.0.171:55733 TIME-WAIT Remote 74.125.201.155:443 (Querying... ) (HTTPS) Local 10.0.0.171:55734 TIME-WAIT Remote 74.125.201.155:443 (Querying... ) (HTTPS) Local 10.0.0.171:55584 TIME-WAIT Remote 146.20.132.40:443 (Querying... ) (HTTPS) Local 10.0.0.171:55940 TIME-WAIT Remote 172.217.11.226:443 (Querying... ) (HTTPS) Local 10.0.0.171:55750 TIME-WAIT Remote 35.244.159.8:443 (Querying... ) (HTTPS) Local 10.0.0.171:55762 TIME-WAIT Remote 23.111.8.18:443 (Querying... ) (HTTPS) Local 10.0.0.171:55763 TIME-WAIT Remote 23.111.8.18:443 (Querying... ) (HTTPS) Local 10.0.0.171:55941 TIME-WAIT Remote 172.217.11.226:443 (Querying... ) (HTTPS) Local 10.0.0.171:55585 TIME-WAIT Remote 146.20.132.40:443 (Querying... ) (HTTPS) Local 10.0.0.171:55012 TIME-WAIT Remote 35.186.241.3:443 (Querying... ) (HTTPS) Local 10.0.0.171:55013 TIME-WAIT Remote 35.186.241.3:443 (Querying... ) (HTTPS) Local 10.0.0.171:55016 TIME-WAIT Remote 35.186.241.3:443 (Querying... ) (HTTPS) Local 10.0.0.171:55017 TIME-WAIT Remote 35.186.241.3:443 (Querying... ) (HTTPS) Local 10.0.0.171:55032 TIME-WAIT Remote 143.204.33.79:443 (Querying... ) (HTTPS) Local 10.0.0.171:55033 TIME-WAIT Remote 143.204.33.79:443 (Querying... ) (HTTPS) Local 10.0.0.171:55078 TIME-WAIT Remote 172.217.12.6:443 (Querying... ) (HTTPS) Local 10.0.0.171:55079 TIME-WAIT Remote 172.217.12.6:443 (Querying... ) (HTTPS) Local 10.0.0.171:55082 TIME-WAIT Remote 172.217.12.2:443 (Querying... ) (HTTPS) Local 10.0.0.171:55083 TIME-WAIT Remote 172.217.12.2:443 (Querying... ) (HTTPS) Local 127.0.0.1:23401 TIME-WAIT Remote 127.0.0.1:55923 (Querying... ) Local 10.0.0.171:55110 TIME-WAIT Remote 84.17.63.177:443 (Querying... ) (HTTPS) Local 10.0.0.171:55112 TIME-WAIT Remote 84.17.63.177:443 (Querying... ) (HTTPS) Local 127.0.0.1:23401 TIME-WAIT Remote 127.0.0.1:55922 (Querying... ) Local 127.0.0.1:23401 TIME-WAIT Remote 127.0.0.1:55921 (Querying... ) Local 10.0.0.171:55134 TIME-WAIT Remote 172.217.12.2:443 (Querying... ) (HTTPS) Local 10.0.0.171:55135 TIME-WAIT Remote 172.217.12.2:443 (Querying... ) (HTTPS) Local 10.0.0.171:55147 TIME-WAIT Remote 172.217.1.194:443 (Querying... ) (HTTPS) Local 10.0.0.171:55148 TIME-WAIT Remote 172.217.1.194:443 (Querying... ) (HTTPS) Local 10.0.0.171:55153 TIME-WAIT Remote 35.227.202.209:443 (Querying... ) (HTTPS) Local 10.0.0.171:55154 TIME-WAIT Remote 35.227.202.209:443 (Querying... ) (HTTPS) Local 10.0.0.171:55157 TIME-WAIT Remote 172.217.11.226:443 (Querying... ) (HTTPS) Local 10.0.0.171:55158 TIME-WAIT Remote 172.217.11.226:443 (Querying... ) (HTTPS) Local 10.0.0.171:55159 TIME-WAIT Remote 13.33.255.28:443 (Querying... ) (HTTPS) Local 127.0.0.1:23401 TIME-WAIT Remote 127.0.0.1:55920 (Querying... ) Local 10.0.0.171:55176 TIME-WAIT Remote 35.227.202.209:443 (Querying... ) (HTTPS) Local 127.0.0.1:23401 TIME-WAIT Remote 127.0.0.1:55905 (Querying... ) Local 10.0.0.171:55562 TIME-WAIT Remote 146.20.132.38:443 (Querying... ) (HTTPS) Local 127.0.0.1:23401 TIME-WAIT Remote 127.0.0.1:55904 (Querying... ) Local 127.0.0.1:23401 TIME-WAIT Remote 127.0.0.1:55903 (Querying... ) Local 10.0.0.171:55827 TIME-WAIT Remote 104.17.187.107:443 (Querying... ) (HTTPS) Local 127.0.0.1:23401 TIME-WAIT Remote 127.0.0.1:55902 (Querying... ) Local 10.0.0.171:55887 TIME-WAIT Remote 146.20.132.40:443 (Querying... ) (HTTPS) System Process Local 0.0.0.0:445 (Windows shares) LISTEN Local 0.0.0.0:5357 LISTEN Local 10.0.0.171:139 (NetBIOS session service) LISTEN Local 0.0.0.0:80 (HTTP) LISTEN Local 169.254.57.70:139 (NetBIOS session service) LISTEN wininit.exe (780) Local 0.0.0.0:49665 LISTEN Generated with Speccy v1.32.740