Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

I've been getting a lot of NSFW pop ups and my computer has been r


  • Please log in to reply

#1
crayolaplaydoh

crayolaplaydoh

    Member

  • Member
  • PipPip
  • 33 posts

Hi!

I've been getting a LOT of NSFW pop ups. I've disabled them in my Chrome. When I think I've mostly deleted them, they always return so I've left them disabled for now.

 

Also, I have Chrome as my default browser, but whenever I restart, it goes to Yahoo or Bing? I have no idea why. Again, I always remove from my search engine list and they always come back.

 

My computer has been running a little slower and I used to have McAfee but that expired years ago.

 

Please help? Is my computer infected?

 

Logs below:

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 30-08-2022
Ran by nicz8 (administrator) on DESKTOP-T35MG81 (LENOVO 80X6) (11-09-2022 19:09:17)
Running from C:\Users\nicz8\Desktop
Loaded Profiles: nicz8
Platform: Microsoft Windows 10 Home Version 21H1 19043.1889 (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\cmd.exe
(C:\Program Files\Common Files\mcafee\SystemCore\mfemms.exe ->) (McAfee, Inc. -> McAfee LLC) C:\Program Files\Common Files\mcafee\SystemCore\mfefire.exe
(C:\Program Files\Common Files\mcafee\SystemCore\mfemms.exe ->) (McAfee, Inc. -> McAfee LLC) C:\Windows\System32\mfevtps.exe <2>
(C:\Program Files\Common Files\mcafee\SystemCore\mfemms.exe ->) (McAfee, Inc. -> McAfee LLC.) C:\Program Files\Common Files\mcafee\amcore\mcshield.exe
(C:\Program Files\Common Files\mcafee\SystemCore\mfemms.exe ->) (McAfee, Inc. -> McAfee, Inc.) C:\Program Files\Common Files\mcafee\MMSSHost\MMSSHOST.exe
(C:\Program Files\Common Files\mcafee\SystemCore\mfemms.exe ->) (McAfee, Inc. -> McAfee, Inc.) C:\Program Files\mcafee\MfeAV\MfeAVSvc.exe
(C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe
(C:\Program Files\mcafee\WebAdvisor\servicehost.exe ->) (McAfee, LLC -> McAfee, LLC) C:\Program Files\mcafee\WebAdvisor\uihost.exe
(C:\Program Files\mcafee\WebAdvisor\uihost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\104.0.1293.70\msedgewebview2.exe <6>
(C:\Program Files\Tablet\ISD\WacomHost.exe ->) (Wacom Technology Corporation -> Wacom Technology, Corp.) C:\Program Files\Tablet\ISD\ISD_Tablet.exe
(C:\Program Files\Tablet\ISD\WTabletServiceISD.exe ->) (Wacom Technology Corp. -> Wacom Technology) C:\Program Files\Tablet\ISD\WacomHost.exe
(C:\Program Files\Tablet\ISD\WTabletServiceISD.exe ->) (Wacom Technology Corporation -> Wacom Technology, Corp.) C:\Program Files\Tablet\ISD\ISD_TabletUser.exe
(C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2207.7-0\MsMpEng.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2207.7-0\MpCopyAccelerator.exe
(C:\Users\nicz8\AppData\Roaming\Microsoft\Skype for Desktop\Skype-Setup.exe ->) (Skype Software Sarl -> ) C:\Users\nicz8\AppData\Local\Temp\is-LUME7.tmp\Skype-Setup.tmp
(C:\Windows\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe ->) (Lenovo -> Lenovo Group Ltd.) C:\Windows\Lenovo\ImController\PluginHost\Lenovo.Modern.ImController.PluginHost.SettingsApp.exe <3>
(C:\Windows\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe ->) (Lenovo -> Lenovo Group Ltd.) C:\Windows\Lenovo\ImController\PluginHost86\Lenovo.Modern.ImController.PluginHost.Device.exe <2>
(Canon Inc. -> CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE
(cmd.exe ->) (McAfee, LLC -> McAfee, LLC) C:\Program Files\mcafee\WebAdvisor\browserhost.exe
(explorer.exe ->) (Apple Inc.) C:\Program Files\WindowsApps\AppleInc.iTunes_12124.1.57017.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe
(explorer.exe ->) (Dolby Laboratories, Inc. -> ) C:\Program Files\Dolby\Dolby DAX3\APP\DAX3TrayIcon.exe
(explorer.exe ->) (LENOVO -> Lenovo(beijing) Limited) C:\ProgramData\Lenovo\ImController\Plugins\IdeaOSDPackage\x64\utility.exe
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
(explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe <2>
(explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <101>
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.152\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.152\GoogleCrashHandler64.exe
(Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_09afa4e14ee4fad2\igfxEM.exe
(Intel\DPTF\esif_uf.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\Temp\DPTF\esif_assist_64.exe
(McAfee, Inc. -> McAfee, Inc.) C:\Program Files\Common Files\mcafee\platform\McUICnt.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (Canon Inc. -> ) C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(services.exe ->) (Dolby Laboratories, Inc. -> ) C:\Program Files\Dolby\Dolby DAX3\API\DAX3API.exe
(services.exe ->) (Intel Corporation - pGFX -> Intel Corporation) C:\Windows\System32\Intel\DPTF\esif_uf.exe
(services.exe ->) (Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_09afa4e14ee4fad2\igfxCUIService.exe
(services.exe ->) (Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_09afa4e14ee4fad2\IntelCpHDCPSvc.exe
(services.exe ->) (Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_09afa4e14ee4fad2\IntelCpHeciSvc.exe
(services.exe ->) (Intuit, Inc. -> Intuit Inc.) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
(services.exe ->) (Lenovo -> Lenovo Group Ltd.) C:\Windows\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe
(services.exe ->) (LENOVO -> Lenovo) C:\Program Files\Lenovo\YMC\ymc.exe
(services.exe ->) (McAfee, Inc. -> McAfee LLC) C:\Program Files\Common Files\mcafee\SystemCore\mfemms.exe
(services.exe ->) (McAfee, Inc. -> McAfee, Inc.) C:\Program Files\Common Files\mcafee\csp\2.7.371.0\McCSPServiceHost.exe
(services.exe ->) (McAfee, Inc. -> McAfee, Inc.) C:\Program Files\Common Files\mcafee\modulecore\ModuleCoreService.exe <2>
(services.exe ->) (McAfee, Inc. -> McAfee, Inc.) C:\Program Files\Common Files\mcafee\PEF\CORE\PEFService.exe
(services.exe ->) (McAfee, Inc. -> McAfee, Inc.) C:\Program Files\Common Files\mcafee\VSCore_15_8\mcapexe.exe
(services.exe ->) (McAfee, LLC -> McAfee, LLC) C:\Program Files\mcafee\WebAdvisor\servicehost.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2207.7-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2207.7-0\NisSrv.exe
(services.exe ->) (Wacom Technology Corporation -> Wacom Technology, Corp.) C:\Program Files\Tablet\ISD\WTabletServiceISD.exe
(Skype Software Sarl -> Skype Technologies S.A.) C:\Users\nicz8\AppData\Roaming\Microsoft\Skype for Desktop\Skype-Setup.exe
(svchost.exe ->) (McAfee, Inc. -> McAfee, Inc.) C:\Program Files\mcafee\vul\McVulCtr.exe
(svchost.exe ->) (McAfee, LLC -> ) C:\Program Files (x86)\McAfee Security Scan\4.1.262\McUpdaterModule.exe
(svchost.exe ->) (McAfee, LLC -> McAfee, LLC) C:\Program Files (x86)\McAfee Security Scan\4.1.262\SSScheduler.exe
(svchost.exe ->) (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.YourPhone_1.22062.536.0_x64__8wekyb3d8bbwe\PhoneExperienceHost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\consent.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\InputMethod\CHS\ChsIME.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(svchost.exe ->) (SweetLabs Inc -> SweetLabs, Inc) C:\Users\nicz8\AppData\Local\Host App Service\Engine\HostAppServiceUpdater.exe
 
==================== Registry (Whitelisted) ===================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16781312 2017-02-07] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_LENOVO_DOLBYDRAGON] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1483264 2017-02-07] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_LENOVO_MICPKEY] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1483264 2017-02-07] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [LenovoUtility] => C:\ProgramData\Lenovo\ImController\Plugins\IdeaOSDPackage\x64\utility.exe [911272 2017-07-27] (LENOVO -> Lenovo(beijing) Limited)
HKLM\...\Run: [APP] => C:\Program Files\Dolby\Dolby DAX3\APP\DAX3TrayIcon.exe [963376 2016-10-27] (Dolby Laboratories, Inc. -> )
HKLM-x32\...\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1313408 2017-07-05] (Canon Inc. -> CANON INC.)
HKLM\...\RunOnce: [msedge_cleanup_{F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}] => C:\Program Files (x86)\Microsoft\EdgeWebView\Application\105.0.1343.33\Installer\setup.exe [3324344 2022-09-11] (Microsoft Corporation -> Microsoft Corporation)
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION
HKU\S-1-5-21-2126566057-4181855661-943989508-1001\...\Run: [Skype for Desktop] => C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe [91585088 2020-03-31] (Skype Software Sarl -> Skype Technologies S.A.)
HKU\S-1-5-21-2126566057-4181855661-943989508-1001\...\RunOnce: [Delete Cached Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\nicz8\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe" (No File)
HKU\S-1-5-21-2126566057-4181855661-943989508-1001\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\nicz8\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe" (No File)
HKU\S-1-5-21-2126566057-4181855661-943989508-1001\...\RunOnce: [Uninstall 22.151.0717.0001] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\nicz8\AppData\Local\Microsoft\OneDrive\22.151.0717.0001" (No File)
HKLM\...\Windows x64\Print Processors\Canon TS300 series Print Processor: C:\Windows\System32\spool\prtprocs\x64\CNMPDDV.DLL [482816 2017-06-06] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\Canon BJ Language Monitor TS300 series: C:\WINDOWS\system32\CNMLMDV.DLL [1302016 2017-06-06] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\105.0.5195.102\Installer\chrmstp.exe [2022-09-11] (Google LLC -> Google LLC)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2022-08-13]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files (x86)\McAfee Security Scan\4.1.262\SSScheduler.exe (McAfee, LLC -> McAfee, LLC)
 
==================== Scheduled Tasks (Whitelisted) ============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {09F8ECF5-6292-4067-AEF5-88BEE5B0A7DC} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [6570472 2022-08-13] (Microsoft Corporation -> Microsoft Corporation)
Task: {1B977145-C117-42D2-BA89-0206CCE0E5C3} - System32\Tasks\McUpdaterModuleTask => C:\Program Files (x86)\McAfee Security Scan\4.1.262\McUpdaterModule.exe [3512600 2022-06-23] (McAfee, LLC -> )
Task: {1D6FA44E-65B7-4121-B01C-2A7224353DDE} - System32\Tasks\Microsoft\Office\OfficeOsfInstaller => C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\osfinstaller.exe (No File)
Task: {234DBE84-DDF3-41C0-A8F4-010E33F33516} - System32\Tasks\Lenovo\ImController\Lenovo iM Controller Scheduled Maintenance => "%windir%\system32\sc.exe" START ImControllerService
Task: {254353FB-348E-43EF-B4CF-B19F952F5D95} - System32\Tasks\McAfeeLogon => C:\Program Files\Common Files\mcafee\platform\McUICnt.exe [745296 2017-10-04] (McAfee, Inc. -> McAfee, Inc.)
Task: {26438B70-2F15-4291-8AA9-EDF9799AEFDF} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23713200 2022-08-13] (Microsoft Corporation -> Microsoft Corporation)
Task: {4A98DF94-BF7C-4533-B7CA-F40D5B084514} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2207.7-0\MpCmdRun.exe [1335960 2022-09-11] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {4CC4FDF7-25A0-41C7-8FB6-12DF875EB57F} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23713200 2022-08-13] (Microsoft Corporation -> Microsoft Corporation)
Task: {5A97C3E8-72E6-458C-833C-5214AD70ED19} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\028e192b-a1f1-4375-96be-23f18df75679 => C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [84240 2022-01-28] (Lenovo -> Lenovo Group Ltd.)
Task: {6077E522-7BDA-480B-ADB8-92D25E066A99} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\855aa72c-dfc5-47c6-b481-90d18cdaa6f8 => C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [84240 2022-01-28] (Lenovo -> Lenovo Group Ltd.)
Task: {66D183F5-99B4-4211-BE7E-FB37780D1855} - System32\Tasks\McAfee\McAfee Auto Maintenance Task Agent => {ABCECA3B-EA5A-496B-A021-5C6BAB365E5C} C:\Program Files\Common Files\McAfee\TaskScheduler\McAMTaskAgent.exe [1015416 2017-07-24] (McAfee, Inc. -> McAfee, Inc.)
Task: {794BA88A-EF09-4A49-B749-2A646AAF0D9F} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\eb1f11d4-4ad8-4ec9-b91d-4bca5eaea8da => C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [84240 2022-01-28] (Lenovo -> Lenovo Group Ltd.)
Task: {7B94BF6D-187D-48C7-AA8E-849A7152ACBA} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2017-08-20] (Google Inc -> Google Inc.)
Task: {8B30D4AC-0967-4C93-8112-A6D4424DB57C} - System32\Tasks\McAfee Remediation (Prepare) => C:\Program Files\Common Files\AV\McAfee VirusScan\upgrade.exe [4560960 2022-06-27] (McAfee, LLC -> McAfee, LLC)
Task: {9F484312-0659-4703-94FE-3BB356A21464} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\0f8b63f6-8596-4c9f-8616-39a976081da5 => C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [84240 2022-01-28] (Lenovo -> Lenovo Group Ltd.)
Task: {A375F4C5-31E2-412B-8259-D1F224191056} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2207.7-0\MpCmdRun.exe [1335960 2022-09-11] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {A3813C09-7FE9-4A0B-A09F-69357D25BF22} - System32\Tasks\Lenovo\ImController\Lenovo iM Controller Monitor => C:\WINDOWS\system32\ImController.InfInstaller.exe [64256 2022-01-28] (Lenovo -> Lenovo Group Ltd.)
Task: {A6330C81-A5E8-4B39-8B6B-C688C24F82AD} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [6570472 2022-08-13] (Microsoft Corporation -> Microsoft Corporation)
Task: {A941E3D8-086F-4592-A522-CB13D593B3C8} - System32\Tasks\Lenovo\BatteryGauge\BatteryGaugeMaintenance => C:\ProgramData\Lenovo\ImController\Plugins\LenovoBatteryGaugePackage\x64\BGHelper.exe [147864 2022-05-12] (Lenovo -> Lenovo Group Ltd.)
Task: {AB9D833F-8449-4F12-BDD8-1D6AB6D88BAB} - System32\Tasks\SecurityScannerScheduler => C:\Program Files (x86)\McAfee Security Scan\4.1.262\SSScheduler.exe [814872 2022-06-23] (McAfee, LLC -> McAfee, LLC)
"C:\Windows\System32\Tasks\McAfee\McAfee Idle Detection Task" was unlocked. <==== ATTENTION
Task: {AC4D8C0B-8AF9-4C7E-B768-72651E067634} - System32\Tasks\McAfee\McAfee Idle Detection Task => {ABCDCA3B-DE6B-5A7C-B132-6D7CBA63E5C5} C:\Program Files\Common Files\McAfee\TaskScheduler\McAMTaskAgent.exe [1015416 2017-07-24] (McAfee, Inc. -> McAfee, Inc.)
Task: {B674EDBE-FE1C-4273-89E3-E26561249C06} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [116632 2022-08-13] (Microsoft Corporation -> Microsoft Corporation)
Task: {C45B3F37-DA14-41F3-AC15-C317AA326E9B} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1555696 2022-08-03] (Adobe Inc. -> Adobe Inc.)
Task: {D36FFA16-1B54-40B6-AC6D-88F5CF30D5BC} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2207.7-0\MpCmdRun.exe [1335960 2022-09-11] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {D90CAE8F-15A5-423D-BC27-889D9FC5BAD8} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [116632 2022-08-13] (Microsoft Corporation -> Microsoft Corporation)
Task: {DED4DAFA-6CE4-4D22-9EBB-382412B6116C} - System32\Tasks\McAfee\DAD.Execute.Updates => C:\Program Files\Common Files\McAfee\DynamicAppDownloader\1.7.104\DADUpdater.exe [4089168 2022-02-08] (McAfee, LLC -> McAfee, LLC)
Task: {E35849B1-741E-439E-9936-DC3891AAEAB1} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2207.7-0\MpCmdRun.exe [1335960 2022-09-11] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {EA8E2548-A120-48D9-B56F-275CB8CA5E4C} - System32\Tasks\App Explorer => C:\Users\nicz8\AppData\Local\Host App Service\Engine\HostAppServiceUpdater.exe [7890976 2022-05-23] (SweetLabs Inc -> SweetLabs, Inc) <==== ATTENTION
Task: {F16E7B30-6F5E-4F07-8414-31B18ADD90F6} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2017-08-20] (Google Inc -> Google Inc.)
Task: {F87F90F6-62A5-422A-B935-E8129F0A511C} - System32\Tasks\Lenovo\ImController\Plugins\LenovoSystemUpdatePlugin_WeeklyTask => %windir%\System32\reg.exe add hklm\SOFTWARE\Lenovo\SystemUpdatePlugin\scheduler /v start /t reg_dword /d 1 /f /reg:32
Task: {F8AA1377-15DA-4E2F-BCD5-FC97EBBF19F8} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\53770f90-b57c-43ef-b586-d389ee35bcde => C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [84240 2022-01-28] (Lenovo -> Lenovo Group Ltd.)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Hosts: 0.0.0.1 mssplus.mcafee.com
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 205.171.2.26
Tcpip\..\Interfaces\{d8bb469e-622d-452c-bc58-8ced83f41aba}: [DhcpNameServer] 192.168.0.1 205.171.2.26
 
Edge: 
=======
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
Edge DefaultProfile: Default
Edge Profile: C:\Users\nicz8\AppData\Local\Microsoft\Edge\User Data\Default [2022-04-03]
 
FireFox:
========
FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files\McAfee\WebAdvisor\e10ssaffplg.xpi
FF Extension: (McAfee® WebAdvisor) - C:\Program Files\McAfee\WebAdvisor\e10ssaffplg.xpi [2022-09-01] [UpdateUrl:hxxps://sadownload.mcafee.com/products/SA/Win/xpi/webadvisor/update.json]
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files\McAfee\WebAdvisor\e10ssaffplg.xpi
FF HKLM-x32\...\Thunderbird\Extensions: [[email protected]] - C:\Program Files\McAfee\MSK
FF Extension: (McAfee Anti-Spam Thunderbird Extension) - C:\Program Files\McAfee\MSK [2018-03-26] [Legacy] [not signed]
FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL [2018-01-25] (McAfee, Inc. -> )
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2019-07-02] (CANON INC.) [File not signed]
FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL [2018-01-25] (McAfee, Inc. -> )
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2022-03-07] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2022-07-20] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2022-09-07] (Adobe Inc. -> Adobe Systems Inc.)
 
Chrome: 
=======
CHR DefaultProfile: Profile 1
CHR Profile: C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Default [2022-08-13]
CHR Notifications: Default -> hxxps://www.bostonmarket.com; hxxps://www.mirta.com; hxxps://www.sephora.com; hxxps://www.yesstyle.com; hxxps://www.youtube.com
CHR HomePage: Default -> hxxp://intra.bmwgroup.net/China/NSC_Intranet/
CHR StartupUrls: Default -> "hxxps://www.bing.com/?PC=PV02"
CHR DefaultSearchURL: Default -> hxxps://search.yahoo.com/search?fr=mcafee&type=E211US714G0&p={searchTerms}
CHR DefaultSearchKeyword: Default -> mcafee
CHR DefaultSuggestURL: Default -> hxxps://us.search.yahoo.com/sugg/gossip/gossip-us-partner?output=fxjson&appid=mca&source=yahoo_mcafee_searchassist&command={searchTerms}
CHR Extension: (Slides) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-17]
CHR Extension: (Docs) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-17]
CHR Extension: (Google Drive) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-10-29]
CHR Extension: (YouTube) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-08-20]
CHR Extension: (DownAlbum) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgjnhhjpfcdhbhlcmmjppicjmgfkppok [2020-10-29]
CHR Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2022-02-17]
CHR Extension: (Sheets) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-17]
CHR Extension: (McAfee® WebAdvisor) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2022-02-17]
CHR Extension: (Google Docs Offline) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2022-02-17]
CHR Extension: (Helium Backup) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpglbgbpeobllokpmeagpoagjbfknanl [2018-07-23]
CHR Extension: (Chrome Web Store Payments) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-30]
CHR Extension: (Gmail) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-10-29]
CHR Profile: C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Guest Profile [2022-04-02]
CHR Profile: C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 1 [2022-09-11]
CHR Notifications: Profile 1 -> hxxps://1.dating-roo2.site; hxxps://idea-shopping.xyz
CHR Extension: (LightSurf) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eeelmcphjdlldmbaamlckoifefbncbaf [2022-08-21]
CHR Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2022-08-28]
CHR Extension: (McAfee® WebAdvisor) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2022-09-01]
CHR Extension: (Google Docs Offline) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2022-09-01]
CHR Extension: (Chrome Web Store Payments) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-07-26]
CHR Profile: C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 2 [2022-04-10]
CHR Extension: (Slides) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2021-08-29]
CHR Extension: (Docs) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aohghmighlieiainnegkcijnfilokake [2021-08-29]
CHR Extension: (Google Drive) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\apdfllckaahabafndbhieahigkjlhalf [2021-08-29]
CHR Extension: (YouTube) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2021-08-29]
CHR Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2022-04-10]
CHR Extension: (Sheets) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2021-08-29]
CHR Extension: (McAfee® WebAdvisor) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2022-04-10]
CHR Extension: (Google Docs Offline) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2022-04-10]
CHR Extension: (Chrome Web Store Payments) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-08-29]
CHR Extension: (Gmail) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2021-08-29]
CHR Profile: C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 3 [2022-08-13]
CHR Extension: (Slides) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2021-11-08]
CHR Extension: (Docs) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\aohghmighlieiainnegkcijnfilokake [2021-11-08]
CHR Extension: (Google Drive) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\apdfllckaahabafndbhieahigkjlhalf [2021-11-08]
CHR Extension: (YouTube) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2021-11-08]
CHR Extension: (Adobe Acrobat) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2021-11-19]
CHR Extension: (Sheets) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2021-11-08]
CHR Extension: (McAfee® WebAdvisor) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2021-12-16]
CHR Extension: (Google Docs Offline) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2021-12-16]
CHR Extension: (Chrome Web Store Payments) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-11-08]
CHR Extension: (Gmail) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2021-11-08]
CHR Profile: C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 4 [2022-04-10]
CHR Extension: (Slides) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2022-03-26]
CHR Extension: (Docs) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\aohghmighlieiainnegkcijnfilokake [2022-03-26]
CHR Extension: (Google Drive) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\apdfllckaahabafndbhieahigkjlhalf [2022-03-26]
CHR Extension: (YouTube) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2022-03-26]
CHR Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2022-03-26]
CHR Extension: (Sheets) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2022-03-26]
CHR Extension: (McAfee® WebAdvisor) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2022-03-26]
CHR Extension: (Google Docs Offline) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2022-03-26]
CHR Extension: (Chrome Web Store Payments) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2022-03-26]
CHR Extension: (Gmail) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2022-03-26]
CHR Profile: C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\System Profile [2022-04-02]
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho]
 
Opera: 
=======
OPR Profile: C:\Users\nicz8\AppData\Roaming\Opera Software\Opera Stable [2019-11-23]
 
==================== Services (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [172264 2022-08-03] (Adobe Inc. -> Adobe Inc.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [12102608 2022-08-13] (Microsoft Corporation -> Microsoft Corporation)
S3 ClientAnalyticsService; C:\Program Files\Common Files\McAfee\ClientAnalytics\Legacy\McClientAnalytics.exe [1511728 2017-09-21] (McAfee, Inc. -> McAfee, Inc.)
R2 DAXAPI; C:\Program Files\Dolby\Dolby DAX3\API\DAX3API.exe [147760 2017-01-16] (Dolby Laboratories, Inc. -> )
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [443344 2020-05-25] (Canon Inc. -> )
R2 ImControllerService; C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [84240 2022-01-28] (Lenovo -> Lenovo Group Ltd.)
R2 McAfee WebAdvisor; C:\Program Files\McAfee\WebAdvisor\ServiceHost.exe [819040 2022-09-01] (McAfee, LLC -> McAfee, LLC)
R2 McAPExe; C:\Program Files\Common Files\McAfee\VSCore_15_8\McApExe.exe [728296 2018-01-31] (McAfee, Inc. -> McAfee, Inc.)
S3 McAWFwk; C:\Program Files\Common Files\mcafee\actwiz\McAWFwk.exe [454560 2016-11-15] (McAfee, Inc. -> McAfee, Inc.)
S3 McComponentHostService; C:\Program Files (x86)\McAfee Security Scan\4.1.262\McCHSvc.exe [330288 2022-06-23] (McAfee, LLC -> McAfee, LLC)
R2 mccspsvc; C:\Program Files\Common Files\McAfee\CSP\2.7.371.0\\McCSPServiceHost.exe [2140888 2017-12-14] (McAfee, Inc. -> McAfee, Inc.)
S3 McSecDashboardService; C:\Program Files\McAfeeDashboard\McSecDashboardService.exe [1257520 2021-05-03] (McAfee, LLC -> McAfee, LLC)
S3 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe [359888 2018-01-26] (McAfee, Inc. -> McAfee LLC)
R2 mfemms; C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe [512976 2018-01-26] (McAfee, Inc. -> McAfee LLC)
R3 mfevtp; C:\Windows\system32\mfevtps.exe [475600 2018-01-26] (McAfee, Inc. -> McAfee LLC)
R2 ModuleCoreService; C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe [1666224 2017-12-19] (McAfee, Inc. -> McAfee, Inc.)
R2 PEFService; C:\Program Files\Common Files\McAfee\PEF\CORE\PEFService.exe [1045360 2018-01-30] (McAfee, Inc. -> McAfee, Inc.)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2207.7-0\NisSrv.exe [3125112 2022-09-11] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2207.7-0\MsMpEng.exe [133560 2022-09-11] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 ymc; C:\Program Files\Lenovo\YMC\ymc.exe [49032 2016-12-23] (LENOVO -> Lenovo)
 
===================== Drivers (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 AppleKmdfFilter; C:\WINDOWS\System32\drivers\AppleKmdfFilter.sys [20032 2020-10-09] (WDKTestCert build,132303256403278908 -> Apple Inc.)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [File not signed]
R3 cfwids; C:\WINDOWS\System32\drivers\cfwids.sys [77216 2018-01-31] (McAfee, Inc. -> McAfee LLC)
S3 HipShieldK; C:\WINDOWS\System32\drivers\HipShieldK.sys [218336 2017-10-10] (McAfee, Inc. -> McAfee, Inc.)
R3 mfeaack; C:\WINDOWS\System32\drivers\mfeaack.sys [496544 2018-01-31] (McAfee, Inc. -> McAfee LLC)
R3 mfeavfk; C:\WINDOWS\System32\drivers\mfeavfk.sys [357792 2018-01-31] (McAfee, Inc. -> McAfee LLC)
U3 mfeavfk01; no ImagePath
S0 mfeelamk; C:\WINDOWS\System32\drivers\mfeelamk.sys [83952 2018-01-31] (Microsoft Windows Early Launch Anti-malware Publisher -> McAfee LLC)
R3 mfefirek; C:\WINDOWS\System32\drivers\mfefirek.sys [528288 2018-01-31] (McAfee, Inc. -> McAfee LLC)
R0 mfehidk; C:\WINDOWS\System32\drivers\mfehidk.sys [948128 2018-01-31] (McAfee, Inc. -> McAfee LLC)
R3 mfencbdc; C:\WINDOWS\System32\DRIVERS\mfencbdc.sys [521128 2017-11-21] (McAfee, Inc. -> McAfee LLC.)
S3 mfencrk; C:\WINDOWS\System32\DRIVERS\mfencrk.sys [108464 2017-11-21] (McAfee, Inc. -> McAfee LLC.)
R3 mfeplk; C:\WINDOWS\System32\drivers\mfeplk.sys [115104 2018-01-31] (McAfee, Inc. -> McAfee LLC)
R0 mfewfpk; C:\WINDOWS\System32\drivers\mfewfpk.sys [252832 2018-01-31] (McAfee, Inc. -> McAfee LLC)
R3 MpKsl946daeec; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{06C9E4FA-6C80-42D7-ADB0-61CA4451C613}\MpKslDrv.sys [228600 2022-09-11] (Microsoft Windows -> Microsoft Corporation)
R2 speedfan; C:\WINDOWS\SysWOW64\speedfan.sys [28664 2012-12-29] (SOKNO S.R.L. -> Almico Software)
R3 WacHidRouterISD; C:\WINDOWS\system32\DRIVERS\wachidrouter_isd.sys [132248 2016-12-07] (Wacom Technology Corporation -> Wacom Technology, Corp.)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [49576 2022-09-11] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [453904 2022-09-11] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [94480 2022-09-11] (Microsoft Windows -> Microsoft Corporation)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One month (created) (Whitelisted) =========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2022-09-11 19:06 - 2022-09-11 19:06 - 002371072 _____ (Farbar) C:\Users\nicz8\Desktop\FRST64 (1).exe
2022-09-11 19:06 - 2022-09-11 19:06 - 000000000 ____D C:\Users\nicz8\Downloads\FRST-OlderVersion
2022-09-02 15:59 - 2022-09-02 15:59 - 000167949 _____ C:\Users\nicz8\OneDrive\Documents\canon receipt.pdf
2022-08-13 18:02 - 2022-08-13 18:02 - 000581120 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhotoScreensaver.scr
2022-08-13 18:02 - 2022-08-13 18:02 - 000499200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhotoScreensaver.scr
2022-08-13 18:02 - 2022-08-13 18:02 - 000288768 _____ C:\WINDOWS\system32\Windows.Management.InprocObjects.dll
2022-08-13 18:02 - 2022-08-13 18:02 - 000162304 _____ C:\WINDOWS\system32\DataStoreCacheDumpTool.exe
2022-08-13 18:02 - 2022-08-13 18:02 - 000089088 _____ C:\WINDOWS\system32\windows.applicationmodel.conversationalagent.proxystub.dll
2022-08-13 18:02 - 2022-08-13 18:02 - 000073216 _____ C:\WINDOWS\system32\windows.applicationmodel.conversationalagent.internal.proxystub.dll
2022-08-13 18:02 - 2022-08-13 18:02 - 000060928 _____ C:\WINDOWS\system32\runexehelper.exe
2022-08-13 18:02 - 2022-08-13 18:02 - 000011803 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim
2022-08-13 17:49 - 2022-08-13 17:49 - 000000000 ___HD C:\$WinREAgent
2022-08-13 17:15 - 2022-08-13 17:15 - 000003206 _____ C:\WINDOWS\system32\Tasks\SecurityScannerScheduler
2022-08-13 17:15 - 2022-08-13 17:15 - 000003204 _____ C:\WINDOWS\system32\Tasks\McUpdaterModuleTask
2022-08-13 17:14 - 2022-08-13 17:14 - 000002174 _____ C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
2022-08-13 17:14 - 2022-08-13 17:14 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
2022-08-13 17:13 - 2022-08-13 17:13 - 000000000 ____D C:\ProgramData\McAfee Security Scan
 
==================== One month (modified) ==================
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2022-09-11 19:10 - 2019-11-20 20:32 - 000037309 _____ C:\Users\nicz8\Desktop\FRST.txt
2022-09-11 19:09 - 2019-11-20 20:29 - 000000000 ____D C:\FRST
2022-09-11 18:55 - 2019-12-07 04:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2022-09-11 18:51 - 2017-08-20 02:04 - 000000000 ____D C:\Program Files (x86)\Google
2022-09-11 18:33 - 2020-09-30 00:00 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2022-09-11 12:14 - 2017-08-20 01:54 - 000000000 ____D C:\Users\nicz8\AppData\Local\Host App Service
2022-09-11 08:57 - 2019-12-07 04:14 - 000000000 ___HD C:\Program Files\WindowsApps
2022-09-11 08:57 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2022-09-11 08:56 - 2020-09-30 00:09 - 000004562 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2022-09-11 08:56 - 2017-08-20 02:06 - 000002308 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2022-09-11 08:56 - 2017-08-20 02:06 - 000002267 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2022-09-11 08:55 - 2018-04-19 20:18 - 000000000 ____D C:\Users\nicz8\AppData\Local\Packages
2022-09-11 08:55 - 2017-08-23 01:52 - 000002143 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2022-09-11 08:54 - 2018-04-19 19:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
2022-09-11 08:50 - 2020-05-24 00:26 - 000002445 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2022-09-11 08:50 - 2020-05-24 00:26 - 000002283 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2022-09-11 08:50 - 2018-01-20 10:27 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2022-09-01 20:09 - 2021-12-16 22:42 - 000003588 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2126566057-4181855661-943989508-1001
2022-09-01 20:09 - 2020-09-30 00:09 - 000003378 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2126566057-4181855661-943989508-1001
2022-09-01 20:09 - 2020-09-30 00:01 - 000002386 _____ C:\Users\nicz8\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2022-09-01 20:07 - 2020-09-30 00:09 - 000003420 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2022-09-01 20:07 - 2020-09-30 00:09 - 000003296 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2022-08-28 13:46 - 2021-11-08 20:44 - 000000000 ____D C:\Users\nicz8\AppData\Local\D3DSCache
2022-08-28 08:39 - 2021-05-03 11:26 - 000000000 ____D C:\ProgramData\CanonIJPLM
2022-08-28 08:36 - 2020-09-30 00:09 - 000003536 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2022-08-28 08:36 - 2020-09-30 00:09 - 000003412 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2022-08-13 19:46 - 2020-09-30 02:46 - 000428838 _____ C:\WINDOWS\system32\prfh0804.dat
2022-08-13 19:46 - 2020-09-30 02:46 - 000133344 _____ C:\WINDOWS\system32\prfc0804.dat
2022-08-13 19:46 - 2020-09-30 00:03 - 001390218 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2022-08-13 19:46 - 2019-12-07 04:13 - 000000000 ____D C:\WINDOWS\INF
2022-08-13 19:41 - 2020-09-30 00:09 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2022-08-13 19:41 - 2020-09-30 00:00 - 000473928 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2022-08-13 19:41 - 2020-09-30 00:00 - 000008192 ___SH C:\DumpStack.log.tmp
2022-08-13 19:41 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\ServiceState
2022-08-13 19:41 - 2019-12-07 04:03 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2022-08-13 19:41 - 2017-08-20 01:57 - 000000000 __SHD C:\Users\nicz8\IntelGraphicsProfiles
2022-08-13 19:41 - 2017-07-29 23:58 - 000000000 ____D C:\Program Files (x86)\McAfee
2022-08-13 19:41 - 2017-07-29 23:50 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2022-08-13 19:40 - 2019-12-07 04:52 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2022-08-13 19:40 - 2019-12-07 04:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2022-08-13 19:40 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2022-08-13 19:40 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2022-08-13 19:40 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\SystemResources
2022-08-13 19:40 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2022-08-13 19:40 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2022-08-13 19:40 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2022-08-13 19:40 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\Dism
2022-08-13 19:40 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\ShellExperiences
2022-08-13 19:40 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2022-08-13 18:09 - 2020-09-30 00:09 - 000003710 _____ C:\WINDOWS\system32\Tasks\McAfee Remediation (Prepare)
2022-08-13 18:06 - 2019-12-07 04:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2022-08-13 18:02 - 2020-09-30 00:04 - 003011072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2022-08-13 17:48 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2022-08-13 17:47 - 2017-08-21 06:48 - 000000000 ____D C:\WINDOWS\system32\MRT
2022-08-13 17:42 - 2017-08-21 06:48 - 144534560 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2022-08-13 17:15 - 2017-07-29 23:58 - 000000000 ____D C:\ProgramData\McAfee
2022-08-13 17:14 - 2022-05-22 10:20 - 000000000 ____D C:\Program Files (x86)\McAfee Security Scan
2022-08-13 17:09 - 2019-12-07 04:03 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
 
==================== SigCheck ============================
 
(There is no automatic fix for files that do not pass verification.)
 
==================== End of FRST.txt ========================
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 30-08-2022
Ran by nicz8 (11-09-2022 19:11:27)
Running from C:\Users\nicz8\Desktop
Microsoft Windows 10 Home Version 21H1 19043.1889 (X64) (2020-09-30 05:10:12)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
 
(If an entry is included in the fixlist, it will be removed.)
 
Administrator (S-1-5-21-2126566057-4181855661-943989508-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-2126566057-4181855661-943989508-503 - Limited - Disabled)
Guest (S-1-5-21-2126566057-4181855661-943989508-501 - Limited - Disabled)
nicz8 (S-1-5-21-2126566057-4181855661-943989508-1001 - Administrator - Enabled) => C:\Users\nicz8
WDAGUtilityAccount (S-1-5-21-2126566057-4181855661-943989508-504 - Limited - Disabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: McAfee VirusScan (Disabled - Up to date) {8BCDACFA-D264-3528-5EF8-E94FD0BC1FBC}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: McAfee VirusScan (Disabled - Up to date) {30AC4D1E-F45E-3AA6-6448-D23DAB3B5501}
FW: McAfee Firewall (Disabled) {B3F62DDF-980B-3470-75A7-407A2E6F58C7}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 22.002.20212 - Adobe Systems Incorporated)
Adobe Refresh Manager (HKLM-x32\...\{AC76BA86-0804-1033-1959-018244601013}) (Version: 1.8.0 - Adobe Systems Incorporated) Hidden
Canon Easy-WebPrint EX (HKLM-x32\...\Easy-WebPrint EX) (Version: 1.7.0.0 - Canon Inc.)
Canon IJ Printer Assistant Tool (HKLM-x32\...\Canon IJ Printer Assistant Tool) (Version: 1.00.4.51 - Canon Inc.)
Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM-x32\...\CANONIJPLM100) (Version: 6.3.0 - Canon Inc.)
Canon My Image Garden (HKLM-x32\...\Canon My Image Garden) (Version: 3.6.4 - Canon Inc.)
Canon My Image Garden Design Files (HKLM-x32\...\Canon My Image Garden Design Files) (Version: 3.6.0 - Canon Inc.)
Canon Quick Menu (HKLM-x32\...\CanonQuickMenu) (Version: 2.8.5 - Canon Inc.)
Canon TS300 series On-screen Manual (HKLM-x32\...\Canon TS300 series On-screen Manual) (Version: 1.1.0 - Canon Inc.)
Canon TS300 series Printer Driver (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_TS300_series) (Version:  - Canon Inc.)
darktable (HKLM\...\darktable) (Version: 3.4.1.1 - the darktable project)
Dolby Atmos Windows API SDK (HKLM\...\{4A2D8823-7CFF-4B1D-9A8A-1807645FFB4E}) (Version: 1.0.1.12 - Dolby Laboratories, Inc.)
Dolby Atmos Windows APP (HKLM\...\{3FC92273-FEF4-4C0B-9AF4-F38D747EB765}) (Version: 1.0.0.10 - Dolby Laboratories, Inc.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 105.0.5195.102 - Google LLC)
Intel® Chipset Device Software (HKLM\...\{81520FC5-3518-40E9-9803-70CE8A801D07}) (Version: 10.1.1.38 - Intel Corporation) Hidden
Intel® Chipset Device Software (HKLM-x32\...\{bb0592a7-5772-4736-9d55-2402740085db}) (Version: 10.1.1.38 - Intel® Corporation) Hidden
Intel® Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.6.0.1039 - Intel Corporation)
Intel® Management Engine Components (HKLM\...\{A6B270EC-19A3-4B33-B78A-297EC57E5B2F}) (Version: 11.6.0.1039 - Intel Corporation) Hidden
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 22.20.16.4836 - Intel Corporation) Hidden
Lenovo App Explorer (HKU\S-1-5-21-2126566057-4181855661-943989508-1001\...\Host App Service) (Version: 0.273.4.468 - SweetLabs for Lenovo) <==== ATTENTION
Lenovo Yoga Mode Control (HKLM\...\{3F2E25D6-49D3-45D5-A7BD-13F5D6F64171}_is1) (Version: 2.0.0.9 - Lenovo)
LINE (HKU\S-1-5-21-2126566057-4181855661-943989508-1001\...\LINE) (Version: 5.11.4.1836 - LINE Corporation)
McAfee LiveSafe (HKLM-x32\...\MSC) (Version: 16.0 R8 - McAfee, Inc.)
McAfee Security Scan Plus (HKLM-x32\...\McAfee Security Scan) (Version: 4.1.262.1 - McAfee, LLC)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 105.0.1343.33 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 105.0.1343.33 - Microsoft Corporation)
Microsoft HEVC Media Extension Installation for Microsoft.HEVCVideoExtension_1.0.2512.0_x64__8wekyb3d8bbwe (x64) (HKLM\...\{B0169E83-757B-EF66-E2F0-391944D785BC}) (Version: 1.0.0.0 - Microsoft Corporation) Hidden
Microsoft Office Professional Plus 2016 - en-us (HKLM\...\ProPlusRetail - en-us) (Version: 16.0.15427.20210 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-2126566057-4181855661-943989508-1001\...\OneDriveSetup.exe) (Version: 22.166.0807.0002 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{7B1FCD52-8F6B-4F12-A143-361EA39F5E7C}) (Version: 3.67.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005 (HKLM\...\{929FBD26-9020-399B-9A7A-751D61F0B942}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005 (HKLM\...\{A749D8E6-B613-3BE3-8F5F-045C84EBA29B}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (HKLM-x32\...\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (HKLM-x32\...\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Mylio (HKLM\...\{005E1001-1B62-491C-8B92-661E112A6546}) (Version: 3.12.7092.0 - Mylio, LLC) Hidden
Mylio (HKLM-x32\...\{333af088-8b57-48b7-a31d-9eecfe31638d}) (Version: 3.12.7092.0 - Mylio, LLC)
Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.15427.20178 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.15427.20178 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.15427.20148 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0409-0000-0000000FF1CE}) (Version: 16.0.14131.20278 - Microsoft Corporation) Hidden
Skype version 8.58 (HKLM-x32\...\Skype_is1) (Version: 8.58 - Skype Technologies S.A.)
Sparkol VideoScribe (HKLM-x32\...\{DD0825FB-0B47-48B8-BAC2-B27F1D63FEAB}) (Version: 3.0.9003 - Sparkol) Hidden
Sparkol VideoScribe (HKLM-x32\...\Sparkol VideoScribe 3.0.9003) (Version: 3.0.9003 - Sparkol)
Speccy (HKLM\...\Speccy) (Version: 1.32 - Piriform)
SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version:  - )
Stagelight (HKLM\...\Stagelight) (Version: 3.0.3.6229 - Open Labs, LLC.)
TurboTax 2017 wiapbpm (HKLM-x32\...\{1EEA0422-07ED-41AC-8084-B901A5B2770F}) (Version: 017.000.0312 - Intuit Inc.) Hidden
TurboTax 2017 WinBizFedFormset (HKLM-x32\...\{DC6E9B3E-41FA-46D7-8F83-4BA1E2A76D95}) (Version: 017.000.1323 - Intuit Inc.) Hidden
TurboTax 2017 WinBizReleaseEngine (HKLM-x32\...\{14B2DB5A-45A2-45D5-AEF4-83A1046D847E}) (Version: 017.000.0485 - Intuit Inc.) Hidden
TurboTax 2017 WinBizTaxSupport (HKLM-x32\...\{B626F5E1-668F-4298-9352-400746786DED}) (Version: 017.000.0890 - Intuit Inc.) Hidden
TurboTax 2017 wrapper (HKLM-x32\...\{C00030AF-035D-4D5A-909C-A860A155C420}) (Version: 017.000.0126 - Intuit Inc.) Hidden
TurboTax Business 2017 (HKLM-x32\...\TurboTax Business 2017) (Version: 2017.0 - Intuit, Inc)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{32DC821E-4A7D-4878-BEE8-337FA153D7F2}) (Version: 2.63.0.0 - Microsoft Corporation) Hidden
UpdateAssistant (HKLM\...\{52C1DD03-104E-4AC6-9DC6-21D585721ED1}) (Version: 1.19.0.0 - Microsoft Corporation) Hidden
Vulkan Run Time Libraries 1.0.54.1 (HKLM\...\VulkanRT1.0.54.1) (Version: 1.0.54.1 - Intel Corporation Inc.) Hidden
Vulkan Run Time Libraries 1.0.54.1 (HKLM\...\VulkanRT1.0.54.1-2) (Version: 1.0.54.1 - Intel Corporation Inc.) Hidden
Vulkan Run Time Libraries 1.0.54.1 (HKLM\...\VulkanRT1.0.54.1-3) (Version: 1.0.54.1 - Intel Corporation Inc.) Hidden
Vulkan Run Time Libraries 1.0.54.1 (HKLM\...\VulkanRT1.0.54.1-4) (Version: 1.0.54.1 - Intel Corporation Inc.) Hidden
Vulkan Run Time Libraries 1.0.54.1 (HKLM\...\VulkanRT1.0.54.1-5) (Version: 1.0.54.1 - Intel Corporation Inc.)
Wacom Pen (HKLM\...\ISD Tablet Driver) (Version: 7.3.4-23 - Wacom Technology Corp.)
WebAdvisor by McAfee (HKLM-x32\...\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}) (Version: 4.1.1.756 - McAfee, LLC)
WhoCrashed 6.65 (HKLM\...\WhoCrashed_is1) (Version:  - Resplendence Software Projects Sp.)
Windows 10 Update Assistant (HKLM-x32\...\{D5C69738-B486-402E-85AC-2456D98A64E4}) (Version: 1.4.9200.22395 - Microsoft Corporation)
Windows PC Health Check (HKLM\...\{6798C408-2636-448C-8AC6-F4E341102D27}) (Version: 3.6.2204.08001 - Microsoft Corporation)
Windows Setup Remediations (x64) (KB4023057) (HKLM\...\{5534e02f-0f5d-40dd-ba92-bea38d22384d}.sdb) (Version:  - )
 
Packages:
=========
Autodesk SketchBook -> C:\Program Files\WindowsApps\89006A2E.AutodeskSketchBook_5.1.0.0_x64__tf1gferkr813w [2019-11-10] (Autodesk Inc.)
Bubble Witch 3 Saga -> C:\Program Files\WindowsApps\king.com.BubbleWitch3Saga_7.21.71.0_x64__kgqvnymyfvs32 [2022-07-24] (king.com)
iTunes -> C:\Program Files\WindowsApps\AppleInc.iTunes_12124.1.57017.0_x64__nzyj5cx40ttqa [2022-05-23] (Apple Inc.) [Startup Task]
Keeper - Password Manager & Secure File Storage -> C:\Program Files\WindowsApps\KeeperSecurityInc.Keeper_14.0.33.0_x64__kejf07qmg0jnm [2019-07-29] (Keeper Security Inc)
Lenovo Account Portal -> C:\Program Files\WindowsApps\LenovoCorporation.LenovoID_2.0.37.0_x86__4642shxvsv8s2 [2017-08-20] (LENOVO INCORPORATED.)
Lenovo Settings -> C:\Program Files\WindowsApps\LenovoCorporation.LenovoSettings_3.177.0.0_x86__4642shxvsv8s2 [2018-03-26] (LENOVO INCORPORATED.)
Lenovo Vantage -> C:\Program Files\WindowsApps\E046963F.LenovoCompanion_10.2208.7.0_x64__k1h2ywk1493x8 [2022-08-20] (LENOVO INC.)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-02-17] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-02-17] (Microsoft Corporation) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.14.9020.0_x64__8wekyb3d8bbwe [2022-09-11] (Microsoft Studios) [MS Ad]
Minecraft for Windows 10 -> C:\Program Files\WindowsApps\Microsoft.MinecraftUWP_1.19.2201.0_x64__8wekyb3d8bbwe [2022-09-01] (Microsoft Studios)
Netflix -> C:\Program Files\WindowsApps\4DF9E0F8.Netflix_6.98.1805.0_x64__mcm4njqhnhss8 [2022-02-16] (Netflix, Inc.)
Plex -> C:\Program Files\WindowsApps\CAF9E577.Plex_3.2.20.0_x64__aam28m9va5cke [2017-08-20] (Plex)
 
==================== Custom CLSID (Whitelisted): ==============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
ContextMenuHandlers1: [McCtxMenuFrmWrk] -> {CCA9EFD3-29ED-430A-BA6D-E6BBFF0A60C2} => c:\Program Files\mcafee\msc\McCtxMenuFrmWrk.dll [2018-01-25] (McAfee, Inc. -> McAfee, Inc.)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} =>  -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_09afa4e14ee4fad2\igfxDTCM.dll [2017-11-24] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers6: [McCtxMenuFrmWrk] -> {CCA9EFD3-29ED-430A-BA6D-E6BBFF0A60C2} => c:\Program Files\mcafee\msc\McCtxMenuFrmWrk.dll [2018-01-25] (McAfee, Inc. -> McAfee, Inc.)
 
==================== Codecs (Whitelisted) ====================
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
ShortcutWithArgument: C:\Users\nicz8\Desktop\Nicole - Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory="Default"
ShortcutWithArgument: C:\Users\nicz8\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Helium Backup.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) ->  --profile-directory=Default --app-id=gpglbgbpeobllokpmeagpoagjbfknanl
 
==================== Loaded Modules (Whitelisted) =============
 
2021-05-03 18:41 - 2017-07-05 13:49 - 000593920 _____ (CANON INC.) [File not signed] [File is in use] C:\Program Files (x86)\Canon\Quick Menu\CNQMMWRP.dll
2021-05-03 18:41 - 2017-07-05 13:43 - 000561152 _____ (CANON INC.) [File not signed] C:\Program Files (x86)\Canon\Quick Menu\CCL.dll
2020-04-20 17:53 - 2020-04-20 17:53 - 000000000 ____L (Microsoft Corporation) [simlink -> C:\Program Files\Common Files\Microsoft Shared\ClickToRun\AppvIsvSubsystems32.dll] C:\Program Files (x86)\Microsoft Office\root\Office16\AppVIsvSubsystems32.dll
2020-04-20 17:53 - 2020-04-20 17:53 - 000000000 ____L (Microsoft Corporation) [simlink -> C:\Program Files\Common Files\Microsoft Shared\ClickToRun\C2R32.dll] C:\Program Files (x86)\Microsoft Office\root\Office16\c2r32.dll
 
==================== Alternate Data Streams (Whitelisted) ========
 
==================== Safe Mode (Whitelisted) ==================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""="Service"
 
==================== Association (Whitelisted) =================
 
==================== Internet Explorer (Whitelisted) ==========
 
HKU\S-1-5-21-2126566057-4181855661-943989508-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://lenovo17win10.msn.com/?pc=LCTE
HKU\S-1-5-21-2126566057-4181855661-943989508-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo17win10.msn.com/?pc=LCTE
HKU\S-1-5-21-2126566057-4181855661-943989508-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://mystart.lenovo.com
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2022-08-13] (Microsoft Corporation -> Microsoft Corporation)
BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2016-02-23] (Canon Inc. -> CANON INC.)
BHO: McAfee WebAdvisor -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> C:\Program Files\McAfee\WebAdvisor\x64\IEPlugin.dll [2022-07-20] (McAfee, LLC -> McAfee, LLC)
BHO: No Name -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> No File
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2022-08-13] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2016-02-23] (Canon Inc. -> CANON INC.)
BHO-x32: McAfee WebAdvisor -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> C:\Program Files\McAfee\WebAdvisor\win32\IEPlugin.dll [2022-07-20] (McAfee, LLC -> McAfee, LLC)
Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2016-02-23] (Canon Inc. -> CANON INC.)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2016-02-23] (Canon Inc. -> CANON INC.)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2022-08-13] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2022-08-13] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2022-08-13] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2022-08-13] (Microsoft Corporation -> Microsoft Corporation)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll No File
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\mcafee\msc\McSnIePl64.dll [2018-01-25] (McAfee, Inc. -> McAfee, Inc.)
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\msc\McSnIePl.dll [2018-01-25] (McAfee, Inc. -> McAfee, Inc.)
 
==================== Hosts content: =========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2017-03-18 16:03 - 2022-08-13 17:15 - 000000865 _____ C:\WINDOWS\system32\drivers\etc\hosts
0.0.0.1 mssplus.mcafee.com
 
==================== Other Areas ===========================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-2126566057-4181855661-943989508-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Lenovo\LenovoWallPaper.jpg
DNS Servers: 192.168.0.1 - 205.171.2.26
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
==================== FirewallRules (Whitelisted) ================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{37B3A384-E450-404C-BEA3-9450E7DA18C1}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{E7D70699-C9CA-4053-B021-59C8399B9D4F}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{985C433C-047D-4602-97E1-0ED887339089}] => (Allow) C:\Users\nicz8\AppData\Local\LINE\bin\5.10.0.1789\LineUpdater.exe (LINE Corporation -> LINE Corporation)
FirewallRules: [{5E47C5B4-6BF5-498F-83BE-A639A48521E4}] => (Allow) C:\Users\nicz8\AppData\Local\LINE\bin\5.10.0.1789\LineUpdater.exe (LINE Corporation -> LINE Corporation)
FirewallRules: [{2F923BAD-A768-4736-B430-EC55D5F7BA60}] => (Allow) C:\Users\nicz8\AppData\Local\LINE\bin\5.10.0.1789\LINE.exe (LINE Corporation -> LINE Corporation)
FirewallRules: [{C3F1FE33-25B1-4678-B08B-4FB738626F9C}] => (Allow) C:\Users\nicz8\AppData\Local\LINE\bin\5.10.0.1789\LINE.exe (LINE Corporation -> LINE Corporation)
FirewallRules: [{BC30834D-13FE-4617-89C9-D23B3F9DE2B6}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe (McAfee, Inc. -> McAfee, Inc.)
FirewallRules: [{99D4DF19-76F3-4F1B-BB1C-4FF49029C914}] => (Allow) C:\Program Files (x86)\Common Files\Mcafee\MMSSHost\MMSSHost.exe (McAfee, Inc. -> McAfee, Inc.)
FirewallRules: [{8F5B8066-4388-4586-98DF-A4993BDAF0AD}] => (Allow) C:\Program Files\Common Files\McAfee\MMSSHost\MMSSHost.exe (McAfee, Inc. -> McAfee, Inc.)
FirewallRules: [{D7D21A45-BD6D-4360-80DF-7C31046B76A0}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdater.exe (Intuit, Inc. -> Intuit Inc.)
FirewallRules: [{F8D8559A-1435-470C-AC86-27CC10B2571E}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe (Intuit, Inc. -> Intuit Inc.)
FirewallRules: [{753327F0-9644-4966-822D-31080D36E3B8}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe (Intuit, Inc. -> Intuit Inc.)
FirewallRules: [{DCB5FC85-43C8-498A-9E82-B4DB7E409DAA}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe (Intuit, Inc. -> Intuit Inc.)
FirewallRules: [{B278BA47-688C-4BE0-AFBB-E84944891CBC}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe (Intuit, Inc. -> Intuit Inc.)
FirewallRules: [{358C1194-1C30-4061-B8AC-13BEA2DF7FA5}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe (Intuit, Inc. -> Intuit Inc.)
FirewallRules: [{3ACF6AEB-1F49-4A7B-AF4D-9A70E2725DE6}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{67599174-D798-4DCB-A7AD-4682C2C104B8}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{4C7495B4-A205-43FF-BA8F-05AA55A35B08}] => (Allow) C:\Program Files\Mylio\Mylio.exe (MYLIO, LLC -> Mylio LLC)
FirewallRules: [{1DDFB1C9-D4D9-4D7E-9E59-B3C49019B788}] => (Allow) C:\Program Files\Mylio\Mylio.exe (MYLIO, LLC -> Mylio LLC)
FirewallRules: [{BA748F57-778C-44B8-89B0-3C8E71F1ADAE}] => (Allow) C:\Users\nicz8\AppData\Local\Temp\win-ts300-1_2-n_mcd\win\MSetup64.exe => No File
FirewallRules: [{0B466E53-82D9-4E8C-930D-C14247FC997C}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{DD17EA51-F596-4377-98F5-1CB3C751AB9F}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{AA4ADB30-32E9-471E-B50A-D7397AF75CDC}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{366A9B4F-B151-436F-B697-F902AD158230}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12124.1.57017.0_x64__nzyj5cx40ttqa\iTunes.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{C7425F0E-BB39-4151-B7C4-3815406160CB}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12124.1.57017.0_x64__nzyj5cx40ttqa\iTunes.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{7B271025-BC00-4685-887C-A267C2C72B61}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12124.1.57017.0_x64__nzyj5cx40ttqa\iTunes.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{89329FEB-6125-4E1F-A6C8-32402A0207FD}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12124.1.57017.0_x64__nzyj5cx40ttqa\iTunes.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{3A369B41-6D28-467B-95E2-BA8656A1E030}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12124.1.57017.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{13508D2F-D0FC-4522-BC64-5D5C26F387A4}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12124.1.57017.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{BB70D2E3-837B-4BCA-A7BE-95C2083A8999}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12124.1.57017.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{6B517CDF-C3AB-4FCC-9249-20A2668AD622}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12124.1.57017.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{D4FDB47B-8724-4732-864E-9E44F9D3D434}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\104.0.1293.70\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{1A3FDB38-7E73-44B1-907D-9F38603C4296}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\105.0.1343.33\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{C7F7EB77-1123-4EB3-831A-90E18B12C2BE}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{7DDD999B-6240-42D0-99D7-EE027D27C1B9}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.88.3401.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{1C6A57F1-D3BD-494F-B2B3-DB768A6E323E}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.88.3401.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{AAE29C16-0C04-47B2-88C3-C4263C9E0FBF}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.88.3401.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{8FA3F7EC-4C48-4336-892C-6C6705467D29}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.88.3401.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
 
==================== Restore Points =========================
 
21-08-2022 14:22:06 Scheduled Checkpoint
01-09-2022 21:17:31 Scheduled Checkpoint
11-09-2022 09:10:35 Scheduled Checkpoint
 
==================== Faulty Device Manager Devices ============
 
 
==================== Event log errors: ========================
 
Application errors:
==================
Error: (08/14/2022 05:35:20 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program SearchApp.exe version 10.0.19041.1889 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.
 
Process ID: 3378
 
Start Time: 01d8af78166246d3
 
Termination Time: 4294967295
 
Application Path: C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe
 
Report Id: a4ab6bd8-adde-4645-915c-602041aad39a
 
Faulting package full name: Microsoft.Windows.Search_1.14.6.19041_neutral_neutral_cw5n1h2txyewy
 
Faulting package-relative application ID: ShellFeedsUI
 
Hang type: Navigation
 
Error: (08/13/2022 07:44:39 PM) (Source: SecurityCenter) (EventID: 17) (User: )
Description: Security Center failed to validate caller with error %1.
 
Error: (08/13/2022 07:43:26 PM) (Source: SecurityCenter) (EventID: 17) (User: )
Description: Security Center failed to validate caller with error %1.
 
Error: (08/13/2022 05:10:54 PM) (Source: SecurityCenter) (EventID: 17) (User: )
Description: Security Center failed to validate caller with error %1.
 
Error: (08/04/2022 07:03:57 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: svchost.exe_FrameServer, version: 10.0.19041.1806, time stamp: 0x7dcad237
Faulting module name: ntdll.dll, version: 10.0.19041.1806, time stamp: 0x1000a5b9
Exception code: 0xc0000005
Fault offset: 0x0000000000030ee8
Faulting process id: 0x3e80
Faulting application start time: 0x01d8a85ea48ab3f1
Faulting application path: C:\WINDOWS\System32\svchost.exe
Faulting module path: C:\WINDOWS\SYSTEM32\ntdll.dll
Report Id: 86262ed3-342e-48ad-be1a-1c3eb4bceb9c
Faulting package full name: 
Faulting package-relative application ID:
 
Error: (07/29/2022 09:51:54 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program svchost.exe version 10.0.19041.1806 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.
 
Process ID: b80
 
Start Time: 01d89c9bd6752602
 
Termination Time: 4294967295
 
Application Path: C:\Windows\System32\svchost.exe
 
Report Id: ea60f326-ce65-4c85-923e-6160028cf0fe
 
Faulting package full name: 
 
Faulting package-relative application ID: 
 
Hang type: Cross-process
 
Error: (07/20/2022 07:53:27 PM) (Source: SecurityCenter) (EventID: 17) (User: )
Description: Security Center failed to validate caller with error %1.
 
Error: (07/20/2022 07:52:43 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: svchost.exe_FrameServer, version: 10.0.19041.1806, time stamp: 0x7dcad237
Faulting module name: combase.dll, version: 10.0.19041.1741, time stamp: 0xafbf9ef6
Exception code: 0xc0000005
Fault offset: 0x0000000000042b28
Faulting process id: 0x2dd4
Faulting application start time: 0x01d89c9c1d650f6e
Faulting application path: C:\WINDOWS\System32\svchost.exe
Faulting module path: C:\WINDOWS\System32\combase.dll
Report Id: 5e92c5ef-d104-453c-b8d1-42df7b78813c
Faulting package full name: 
Faulting package-relative application ID:
 
 
System errors:
=============
Error: (09/11/2022 04:30:17 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-T35MG81)
Description: The server microsoft.windowscommunicationsapps_16005.14326.20970.0_x64__8wekyb3d8bbwe!microsoft.windowslive.calendar.AppXwkn9j84yh1kvnt49k5r8h6y1ecsv09hs.mca did not register with DCOM within the required timeout.
 
Error: (09/11/2022 08:55:42 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80073d02: 9NMPJ99VJBWV-Microsoft.YourPhone.
 
Error: (09/01/2022 08:11:59 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80073d02: 9NMPJ99VJBWV-Microsoft.YourPhone.
 
Error: (08/28/2022 08:48:23 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80073d02: 9NMPJ99VJBWV-Microsoft.YourPhone.
 
Error: (08/20/2022 01:49:54 PM) (Source: disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
 
Error: (08/20/2022 01:49:54 PM) (Source: disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
 
Error: (08/20/2022 01:49:54 PM) (Source: disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
 
Error: (08/20/2022 01:49:54 PM) (Source: disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
 
 
Windows Defender:
================
Date: 2022-09-11 09:00:37
Description: 
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
 
Date: 2022-09-03 01:41:19
Description: 
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
 
Date: 2022-09-02 16:11:52
Description: 
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
 
Date: 2022-09-01 20:17:08
Description: 
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
 
Date: 2022-08-28 09:05:03
Description: 
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
Event[0]:
 
Date: 2022-02-15 20:26:05
Description: 
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version: 
Previous security intelligence Version: 1.355.2132.0
Update Source: Microsoft Update Server
Security intelligence Type: AntiVirus
Update Type: Full
Current Engine Version: 
Previous Engine Version: 1.1.18800.4
Error code: 0x8024402f
Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support. 
 
Date: 2021-11-19 19:48:20
Description: 
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version: 
Previous security intelligence Version: 1.353.669.0
Update Source: Microsoft Update Server
Security intelligence Type: AntiVirus
Update Type: Full
Current Engine Version: 
Previous Engine Version: 1.1.18700.4
Error code: 0x80240022
Error description: The program can't check for definition updates. 
 
Date: 2021-11-19 19:48:20
Description: 
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version: 
Previous security intelligence Version: 1.353.669.0
Update Source: Microsoft Update Server
Security intelligence Type: AntiVirus
Update Type: Full
Current Engine Version: 
Previous Engine Version: 1.1.18700.4
Error code: 0x80240022
Error description: The program can't check for definition updates. 
 
Date: 2021-06-30 13:44:26
Description: 
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version: 1.343.119.0
Previous security intelligence Version: 1.341.1614.0
Update Source: User
Security intelligence Type: AntiSpyware
Update Type: Delta
Current Engine Version: 1.1.18300.4
Previous Engine Version: 1.1.18200.4
Error code: 0x80070666
Error description: Another version of this product is already installed. Installation of this version cannot continue. To configure or remove the existing version of this product, use Add/Remove Programs on the Control Panel. 
 
Date: 2021-06-30 13:44:26
Description: 
Microsoft Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version: 1.343.119.0
Previous security intelligence Version: 1.341.1614.0
Update Source: User
Security intelligence Type: AntiVirus
Update Type: Delta
Current Engine Version: 1.1.18300.4
Previous Engine Version: 1.1.18200.4
Error code: 0x80070666
Error description: Another version of this product is already installed. Installation of this version cannot continue. To configure or remove the existing version of this product, use Add/Remove Programs on the Control Panel. 
 
CodeIntegrity:
===============
Date: 2022-09-11 18:33:59
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.2207.7-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_09afa4e14ee4fad2\igd10iumd64.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
Date: 2022-09-11 08:59:25
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.2207.7-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
 
Date: 2022-09-11 08:48:35
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.2205.7-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_09afa4e14ee4fad2\igd10iumd64.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
 
==================== Memory info =========================== 
 
BIOS: LENOVO 1YCN30WW(V1.07) 06/14/2017
Motherboard: LENOVO Lenovo YOGA 720-13IKB
Processor: Intel® Core™ i5-7200U CPU @ 2.50GHz
Percentage of memory in use: 94%
Total physical RAM: 8034.39 MB
Available physical RAM: 454.33 MB
Total Virtual: 16621.88 MB
Available Virtual: 2475.97 MB
 
==================== Drives ================================
 
Drive c: (Windows) (Fixed) (Total:212.23 GB) (Free:100.62 GB) (Model: NVMe INTEL SSDPEKKW25) NTFS
Drive d: (LENOVO) (Fixed) (Total:25 GB) (Free:23.43 GB) (Model: NVMe INTEL SSDPEKKW25) NTFS
 
\\?\Volume{518f5e61-ba9f-4b70-852c-9437ce5de1a4}\ (WINRE_DRV) (Fixed) (Total:0.98 GB) (Free:0.48 GB) NTFS
\\?\Volume{e17cf99c-0739-4dd5-8122-ae65e303b6d9}\ (SYSTEM_DRV) (Fixed) (Total:0.25 GB) (Free:0.22 GB) FAT32
 
==================== MBR & Partition Table ====================
 
==========================================================
Disk: 0 (Size: 238.5 GB) (Disk ID: B9DA0316)
 
Partition: GPT.
 
==================== End of Addition.txt =======================

 


  • 0

Advertisements


#2
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,331 posts
  • MVP

Can't see anything obvious but you do have a file system error so let's fix that first

 

Search for:

cmd

It will find Command Prompt.  Right click on Command Prompt and Run As Admin.

 

Then type: 

chkdsk  /r  C:

Hit Enter.

 

It will say it can't do it now and ask you if you want to schedule it for your next reboot.

 

Tell it:

y

then Restart.  The disk check should start and usually takes a few hours.

 

After it reboots, then uninstall:

 

McAfee LiveSafe (HKLM-x32\...\MSC) (Version: 16.0 R8 - McAfee, Inc.)
McAfee Security Scan Plus (HKLM-x32\...\McAfee Security Scan) (Version: 4.1.262.1 - McAfee, LLC)
 
(Search for Control Panel and hit Enter. Then select Programs and Features.  Scroll down to and click on the first McAfee and then Uninstall.  It will probably want to reboot.  Repeat for the second McAfee)
 
Then because McAfee is such a poorly written program you need to download and run the MCPR uninstall program:
 
 
Download, Save, Go to the download folder and right click and Run As Admin.
 
Reboot when done.
 
Then let's remove some deadwood, check your system files and clear your alarms:
 

Download the attached fixlist.txt to the same location as FRST

Attached File  fixlist.txt   3.76KB   15 downloads

Run FRST and press Fix.  This usually takes about 30 minutes so be patient.  Will reboot when done.
A fix log will be generated please post that

Reboot if the fix doesn't reboot it for you

Run FRST again but this time make sure Addition.txt is checked and hit Scan.  Post both logs.

Then let's see if it is running as fast as it should:
 
Multiple replies are OK.  Best to post a log as you get it.

Get Process Explorer

https://live.sysinte...com/procexp.exe

Save it to your desktop then run it (Vista or Win7+ - right click and Run As Administrator).  
View and check Show Processes From All Users

View, Select Column, check Verified Signer, OK
Options, Verify Image Signatures


Click twice on the CPU column header  to sort things by CPU usage with the big hitters at the top.  

Wait a full minute then:

File, Save As, Save.  Note the file name.   Open the file  on your desktop and copy and paste the text to a reply.


Copy the next 2 lines:

TASKLIST /SVC  > \junk.txt
notepad \junk.txt

Open an Elevated Command Prompt:
Win 7: Start, All Programs, Accessories then right click on Command Prompt and Run as Administrator
Win 8: http://www.eightforu...indows-8-a.html
win 10: http://www.howtogeek...-in-windows-10/

Right click and Paste (or Edit then Paste) and the copied lines should appear.
Hit Enter if notepad does not open.  Copy and paste the text from notepad into a reply.


Get the free version of Speccy:

http://www.filehippo...ownload_speccy/ 

(Look in the upper right for the Download
Latest Version button  - Do NOT press the large Start Download button on the upper left!)  
Download, Save and Install it.  Tell it you do not need CCLEANER.    Run Speccy.  When it finishes (the little icon in the bottom left will stop moving),
File, Save as Text File,  (to your desktop) note the name it gives. OK.  Open the file in notepad and delete the line that gives the serial number of your Operating System.  
(It will be near the top,  10-20  lines down.) Save the file.  Attach the file to your next post.  Attaching the log is the best option as it is too big for the forum.  Attaching is a multi step process.

First click on More Reply Options
Then scroll down to where you see
Choose File and click on it.  Point it at the file and hit Open.
Now click on Attach this file.


Latency Monitor:

Go to

http://www.resplendence.com/downloads

Scroll down to

System Monitoring Tools

and then find

LatencyMon 7.0 (or it may be a higher number if they update)

Click on Download free home edition

Save it then right click and Run As Admin.  It will install and then start the program.  
It will tell you to click on the Start button but there isn't one.  
Instead click on the green arrowhead (looks like a Play button).   Let it run for at least 20 seconds.  Then hit the red box to stop it.

Edit, Copy Report text to Clipboard then move to a REPLY and Ctrl + v to paste the text into a reply.  


Click on the Drivers Tab.  Click on the column header for "Total execution (ms)" once or twice until the biggest numbers are at the top of the column then take a screen shot (save as type jpg) and attach it.  
Click on the Processes tab then click on the  "Hard Pagefaults" column header once or twice until the big numbers are at the top of the column.  Take a screen shot (save as type jpg) and attach it.
 


 

  • 0

#3
crayolaplaydoh

crayolaplaydoh

    Member

  • Topic Starter
  • Member
  • PipPip
  • 33 posts

Oh man. I can't even get past the first step!

 

I'm getting some kind of error message on the command prompt. 

 

"'dskchk' is not recognized as an internal or external command,

operable program or batch file."

  • 0

#4
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,331 posts
  • MVP

Curses I did it again.  Should be:

 

chkdsk /r C:


  • 0

#5
crayolaplaydoh

crayolaplaydoh

    Member

  • Topic Starter
  • Member
  • PipPip
  • 33 posts

 Okay! Thank you for your time!

 

First set of logs.

FRST log:

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 30-08-2022
Ran by nicz8 (administrator) on DESKTOP-T35MG81 (LENOVO 80X6) (14-09-2022 20:13:07)
Running from C:\Users\nicz8\Desktop
Loaded Profiles: nicz8
Platform: Microsoft Windows 10 Home Version 21H1 19043.1889 (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(C:\Program Files\Tablet\ISD\WacomHost.exe ->) (Wacom Technology Corporation -> Wacom Technology, Corp.) C:\Program Files\Tablet\ISD\ISD_Tablet.exe
(C:\Program Files\Tablet\ISD\WTabletServiceISD.exe ->) (Wacom Technology Corp. -> Wacom Technology) C:\Program Files\Tablet\ISD\WacomHost.exe
(C:\Program Files\Tablet\ISD\WTabletServiceISD.exe ->) (Wacom Technology Corporation -> Wacom Technology, Corp.) C:\Program Files\Tablet\ISD\ISD_TabletUser.exe
(C:\Windows\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe ->) (Lenovo -> Lenovo Group Ltd.) C:\Windows\Lenovo\ImController\PluginHost\Lenovo.Modern.ImController.PluginHost.SettingsApp.exe <3>
(Canon Inc. -> CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE
(explorer.exe ->) (Apple Inc.) C:\Program Files\WindowsApps\AppleInc.iTunes_12125.8.57037.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe
(explorer.exe ->) (Dolby Laboratories, Inc. -> ) C:\Program Files\Dolby\Dolby DAX3\APP\DAX3TrayIcon.exe
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <11>
(explorer.exe ->) (LENOVO -> Lenovo(beijing) Limited) C:\ProgramData\Lenovo\ImController\Plugins\IdeaOSDPackage\x64\utility.exe
(explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe <2>
(explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.152\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.152\GoogleCrashHandler64.exe
(Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_09afa4e14ee4fad2\igfxEM.exe
(Intel\DPTF\esif_uf.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\Temp\DPTF\esif_assist_64.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (Canon Inc. -> ) C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(services.exe ->) (Dolby Laboratories, Inc. -> ) C:\Program Files\Dolby\Dolby DAX3\API\DAX3API.exe
(services.exe ->) (Intel Corporation - pGFX -> Intel Corporation) C:\Windows\System32\Intel\DPTF\esif_uf.exe
(services.exe ->) (Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_09afa4e14ee4fad2\igfxCUIService.exe
(services.exe ->) (Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_09afa4e14ee4fad2\IntelCpHDCPSvc.exe
(services.exe ->) (Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_09afa4e14ee4fad2\IntelCpHeciSvc.exe
(services.exe ->) (Lenovo -> Lenovo Group Ltd.) C:\Windows\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe
(services.exe ->) (LENOVO -> Lenovo) C:\Program Files\Lenovo\YMC\ymc.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2207.7-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2207.7-0\NisSrv.exe
(services.exe ->) (Wacom Technology Corporation -> Wacom Technology, Corp.) C:\Program Files\Tablet\ISD\WTabletServiceISD.exe
(svchost.exe ->) (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.YourPhone_1.22062.543.0_x64__8wekyb3d8bbwe\PhoneExperienceHost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\InputMethod\CHS\ChsIME.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.1852_none_7de3b01c7cacf858\TiWorker.exe
 
==================== Registry (Whitelisted) ===================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16781312 2017-02-07] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_LENOVO_DOLBYDRAGON] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1483264 2017-02-07] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_LENOVO_MICPKEY] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1483264 2017-02-07] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [LenovoUtility] => C:\ProgramData\Lenovo\ImController\Plugins\IdeaOSDPackage\x64\utility.exe [911272 2017-07-27] (LENOVO -> Lenovo(beijing) Limited)
HKLM\...\Run: [APP] => C:\Program Files\Dolby\Dolby DAX3\APP\DAX3TrayIcon.exe [963376 2016-10-27] (Dolby Laboratories, Inc. -> )
HKLM-x32\...\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1313408 2017-07-05] (Canon Inc. -> CANON INC.)
HKU\S-1-5-21-2126566057-4181855661-943989508-1001\...\Run: [Skype for Desktop] => C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe [91667312 2020-05-12] (Skype Software Sarl -> Skype Technologies S.A.)
HKLM\...\Windows x64\Print Processors\Canon TS300 series Print Processor: C:\Windows\System32\spool\prtprocs\x64\CNMPDDV.DLL [482816 2017-06-06] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\Canon BJ Language Monitor TS300 series: C:\WINDOWS\system32\CNMLMDV.DLL [1302016 2017-06-06] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\105.0.5195.102\Installer\chrmstp.exe [2022-09-11] (Google LLC -> Google LLC)
 
==================== Scheduled Tasks (Whitelisted) ============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {09F8ECF5-6292-4067-AEF5-88BEE5B0A7DC} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [6570472 2022-08-13] (Microsoft Corporation -> Microsoft Corporation)
Task: {234DBE84-DDF3-41C0-A8F4-010E33F33516} - System32\Tasks\Lenovo\ImController\Lenovo iM Controller Scheduled Maintenance => "%windir%\system32\sc.exe" START ImControllerService
Task: {26438B70-2F15-4291-8AA9-EDF9799AEFDF} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23709120 2022-09-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {2C25B451-638B-462C-BCB7-ECDC3A68416F} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\5b6dbee2-4d63-4c2c-bc30-09d4747a22a1 => C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [84240 2022-01-28] (Lenovo -> Lenovo Group Ltd.)
Task: {301694BB-3078-4E27-A0EA-C3B03612FF78} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\b041a6fd-0381-4244-93e6-b51a7ddd7f63 => C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [84240 2022-01-28] (Lenovo -> Lenovo Group Ltd.)
Task: {4A98DF94-BF7C-4533-B7CA-F40D5B084514} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2207.7-0\MpCmdRun.exe [1335960 2022-09-11] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {4CC4FDF7-25A0-41C7-8FB6-12DF875EB57F} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23709120 2022-09-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {57A57598-83E6-49D3-A815-95E86417BFC4} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\8e4452dc-f169-4ebf-b73c-76fcdf1c7e37 => C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [84240 2022-01-28] (Lenovo -> Lenovo Group Ltd.)
Task: {73E3EEE5-583A-4D8E-ABF8-301FD02C3F4D} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\de82a515-fff0-4035-a245-901dc9ee4885 => C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [84240 2022-01-28] (Lenovo -> Lenovo Group Ltd.)
Task: {7B94BF6D-187D-48C7-AA8E-849A7152ACBA} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2017-08-20] (Google Inc -> Google Inc.)
Task: {A375F4C5-31E2-412B-8259-D1F224191056} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2207.7-0\MpCmdRun.exe [1335960 2022-09-11] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {A3813C09-7FE9-4A0B-A09F-69357D25BF22} - System32\Tasks\Lenovo\ImController\Lenovo iM Controller Monitor => C:\WINDOWS\system32\ImController.InfInstaller.exe [64256 2022-01-28] (Lenovo -> Lenovo Group Ltd.)
Task: {A6330C81-A5E8-4B39-8B6B-C688C24F82AD} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [6570472 2022-08-13] (Microsoft Corporation -> Microsoft Corporation)
Task: {A941E3D8-086F-4592-A522-CB13D593B3C8} - System32\Tasks\Lenovo\BatteryGauge\BatteryGaugeMaintenance => C:\ProgramData\Lenovo\ImController\Plugins\LenovoBatteryGaugePackage\x64\BGHelper.exe [147864 2022-05-12] (Lenovo -> Lenovo Group Ltd.)
Task: {B674EDBE-FE1C-4273-89E3-E26561249C06} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [116632 2022-08-13] (Microsoft Corporation -> Microsoft Corporation)
Task: {C45B3F37-DA14-41F3-AC15-C317AA326E9B} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1555696 2022-08-03] (Adobe Inc. -> Adobe Inc.)
Task: {D36FFA16-1B54-40B6-AC6D-88F5CF30D5BC} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2207.7-0\MpCmdRun.exe [1335960 2022-09-11] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {D8689F9C-52AC-4DFA-A009-129FCE884A6E} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\a4ec54be-cabe-49ef-bf06-4e02fa3928c3 => C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [84240 2022-01-28] (Lenovo -> Lenovo Group Ltd.)
Task: {D90CAE8F-15A5-423D-BC27-889D9FC5BAD8} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [116632 2022-08-13] (Microsoft Corporation -> Microsoft Corporation)
Task: {E35849B1-741E-439E-9936-DC3891AAEAB1} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2207.7-0\MpCmdRun.exe [1335960 2022-09-11] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {EA8E2548-A120-48D9-B56F-275CB8CA5E4C} - System32\Tasks\App Explorer => C:\Users\nicz8\AppData\Local\Host App Service\Engine\HostAppServiceUpdater.exe [7890976 2022-05-23] (SweetLabs Inc -> SweetLabs, Inc) <==== ATTENTION
Task: {F16E7B30-6F5E-4F07-8414-31B18ADD90F6} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2017-08-20] (Google Inc -> Google Inc.)
Task: {F87F90F6-62A5-422A-B935-E8129F0A511C} - System32\Tasks\Lenovo\ImController\Plugins\LenovoSystemUpdatePlugin_WeeklyTask => %windir%\System32\reg.exe add hklm\SOFTWARE\Lenovo\SystemUpdatePlugin\scheduler /v start /t reg_dword /d 1 /f /reg:32
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 205.171.2.26
Tcpip\..\Interfaces\{d8bb469e-622d-452c-bc58-8ced83f41aba}: [DhcpNameServer] 192.168.0.1 205.171.2.26
 
Edge: 
=======
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
Edge DefaultProfile: Default
Edge Profile: C:\Users\nicz8\AppData\Local\Microsoft\Edge\User Data\Default [2022-04-03]
 
FireFox:
========
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2019-07-02] (CANON INC.) [File not signed]
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2022-03-07] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2022-07-20] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2022-09-07] (Adobe Inc. -> Adobe Systems Inc.)
 
Chrome: 
=======
CHR DefaultProfile: Profile 1
CHR Profile: C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Default [2022-09-14]
CHR Notifications: Default -> hxxps://www.bostonmarket.com; hxxps://www.mirta.com; hxxps://www.sephora.com; hxxps://www.yesstyle.com; hxxps://www.youtube.com
CHR HomePage: Default -> hxxp://intra.bmwgroup.net/China/NSC_Intranet/
CHR DefaultSuggestURL: Default -> hxxps://us.search.yahoo.com/sugg/gossip/gossip-us-partner?output=fxjson&appid=mca&source=yahoo_mcafee_searchassist&command={searchTerms}
CHR Extension: (Slides) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-17]
CHR Extension: (Docs) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-17]
CHR Extension: (Google Drive) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-10-29]
CHR Extension: (YouTube) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-08-20]
CHR Extension: (DownAlbum) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgjnhhjpfcdhbhlcmmjppicjmgfkppok [2020-10-29]
CHR Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2022-02-17]
CHR Extension: (Sheets) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-17]
CHR Extension: (McAfee® WebAdvisor) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2022-02-17]
CHR Extension: (Google Docs Offline) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2022-02-17]
CHR Extension: (Helium Backup) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpglbgbpeobllokpmeagpoagjbfknanl [2018-07-23]
CHR Extension: (Chrome Web Store Payments) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-30]
CHR Extension: (Gmail) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-10-29]
CHR Profile: C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Guest Profile [2022-04-02]
CHR Profile: C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 1 [2022-09-14]
CHR Extension: (LightSurf) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eeelmcphjdlldmbaamlckoifefbncbaf [2022-08-21]
CHR Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2022-09-14]
CHR Extension: (Google Docs Offline) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2022-09-14]
CHR Extension: (Chrome Web Store Payments) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-07-26]
CHR Profile: C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 2 [2022-04-10]
CHR Extension: (Slides) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2021-08-29]
CHR Extension: (Docs) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aohghmighlieiainnegkcijnfilokake [2021-08-29]
CHR Extension: (Google Drive) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\apdfllckaahabafndbhieahigkjlhalf [2021-08-29]
CHR Extension: (YouTube) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2021-08-29]
CHR Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2022-04-10]
CHR Extension: (Sheets) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2021-08-29]
CHR Extension: (McAfee® WebAdvisor) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2022-04-10]
CHR Extension: (Google Docs Offline) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2022-04-10]
CHR Extension: (Chrome Web Store Payments) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-08-29]
CHR Extension: (Gmail) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2021-08-29]
CHR Profile: C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 3 [2022-09-14]
CHR Extension: (Slides) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2021-11-08]
CHR Extension: (Docs) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\aohghmighlieiainnegkcijnfilokake [2021-11-08]
CHR Extension: (Google Drive) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\apdfllckaahabafndbhieahigkjlhalf [2021-11-08]
CHR Extension: (YouTube) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2021-11-08]
CHR Extension: (Adobe Acrobat) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2021-11-19]
CHR Extension: (Sheets) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2021-11-08]
CHR Extension: (McAfee® WebAdvisor) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2021-12-16]
CHR Extension: (Google Docs Offline) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2021-12-16]
CHR Extension: (Chrome Web Store Payments) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-11-08]
CHR Extension: (Gmail) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2021-11-08]
CHR Profile: C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 4 [2022-04-10]
CHR Extension: (Slides) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2022-03-26]
CHR Extension: (Docs) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\aohghmighlieiainnegkcijnfilokake [2022-03-26]
CHR Extension: (Google Drive) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\apdfllckaahabafndbhieahigkjlhalf [2022-03-26]
CHR Extension: (YouTube) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2022-03-26]
CHR Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2022-03-26]
CHR Extension: (Sheets) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2022-03-26]
CHR Extension: (McAfee® WebAdvisor) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2022-03-26]
CHR Extension: (Google Docs Offline) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2022-03-26]
CHR Extension: (Chrome Web Store Payments) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2022-03-26]
CHR Extension: (Gmail) - C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2022-03-26]
CHR Profile: C:\Users\nicz8\AppData\Local\Google\Chrome\User Data\System Profile [2022-04-02]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
 
Opera: 
=======
OPR Profile: C:\Users\nicz8\AppData\Roaming\Opera Software\Opera Stable [2019-11-23]
 
==================== Services (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [172264 2022-08-03] (Adobe Inc. -> Adobe Inc.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [12131256 2022-09-14] (Microsoft Corporation -> Microsoft Corporation)
R2 DAXAPI; C:\Program Files\Dolby\Dolby DAX3\API\DAX3API.exe [147760 2017-01-16] (Dolby Laboratories, Inc. -> )
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [443344 2020-05-25] (Canon Inc. -> )
R2 ImControllerService; C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [84240 2022-01-28] (Lenovo -> Lenovo Group Ltd.)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2207.7-0\NisSrv.exe [3125112 2022-09-11] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2207.7-0\MsMpEng.exe [133560 2022-09-11] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 ymc; C:\Program Files\Lenovo\YMC\ymc.exe [49032 2016-12-23] (LENOVO -> Lenovo)
 
===================== Drivers (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 AppleKmdfFilter; C:\WINDOWS\System32\drivers\AppleKmdfFilter.sys [20032 2020-10-09] (WDKTestCert build,132303256403278908 -> Apple Inc.)
R3 MpKslf3c92a07; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{A54D847D-CA11-4954-A92A-FCEEAB5418A5}\MpKslDrv.sys [228600 2022-09-14] (Microsoft Windows -> Microsoft Corporation)
R2 speedfan; C:\WINDOWS\SysWOW64\speedfan.sys [28664 2012-12-29] (SOKNO S.R.L. -> Almico Software)
R3 WacHidRouterISD; C:\WINDOWS\system32\DRIVERS\wachidrouter_isd.sys [132248 2016-12-07] (Wacom Technology Corporation -> Wacom Technology, Corp.)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [49576 2022-09-11] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [453904 2022-09-11] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [94480 2022-09-11] (Microsoft Windows -> Microsoft Corporation)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One month (created) (Whitelisted) =========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2022-09-14 20:02 - 2022-09-14 20:10 - 000172430 _____ C:\Users\nicz8\Desktop\Fixlog.txt
2022-09-14 19:53 - 2022-09-14 19:53 - 011609272 _____ (McAfee, LLC) C:\Users\nicz8\Downloads\MCPR.exe
2022-09-14 19:23 - 2022-09-14 19:23 - 000000000 ___HD C:\$WinREAgent
2022-09-11 19:06 - 2022-09-11 19:06 - 002371072 _____ (Farbar) C:\Users\nicz8\Desktop\FRST64 (1).exe
2022-09-11 19:06 - 2022-09-11 19:06 - 000000000 ____D C:\Users\nicz8\Downloads\FRST-OlderVersion
2022-09-02 15:59 - 2022-09-02 15:59 - 000167949 _____ C:\Users\nicz8\OneDrive\Documents\canon receipt.pdf
 
==================== One month (modified) ==================
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2022-09-14 20:13 - 2019-11-20 20:32 - 000026181 _____ C:\Users\nicz8\Desktop\FRST.txt
2022-09-14 20:13 - 2019-11-20 20:29 - 000000000 ____D C:\FRST
2022-09-14 20:13 - 2017-08-20 02:04 - 000000000 ____D C:\Program Files (x86)\Google
2022-09-14 20:12 - 2019-12-07 04:14 - 000000000 ___HD C:\Program Files\WindowsApps
2022-09-14 20:12 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2022-09-14 20:11 - 2020-09-30 00:09 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2022-09-14 20:11 - 2020-09-30 00:00 - 000008192 ___SH C:\DumpStack.log.tmp
2022-09-14 20:11 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\ServiceState
2022-09-14 20:11 - 2019-12-07 04:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2022-09-14 20:11 - 2019-12-07 04:03 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2022-09-14 20:11 - 2017-08-20 01:57 - 000000000 __SHD C:\Users\nicz8\IntelGraphicsProfiles
2022-09-14 20:09 - 2021-12-16 22:42 - 000003588 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2126566057-4181855661-943989508-1001
2022-09-14 20:09 - 2020-09-30 00:09 - 000003378 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2126566057-4181855661-943989508-1001
2022-09-14 20:09 - 2020-09-30 00:01 - 000002386 _____ C:\Users\nicz8\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2022-09-14 20:09 - 2017-08-21 06:48 - 000000000 ____D C:\WINDOWS\system32\MRT
2022-09-14 20:08 - 2020-09-30 02:46 - 000428838 _____ C:\WINDOWS\system32\prfh0804.dat
2022-09-14 20:08 - 2020-09-30 02:46 - 000133344 _____ C:\WINDOWS\system32\prfc0804.dat
2022-09-14 20:08 - 2020-09-30 00:03 - 001390218 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2022-09-14 20:08 - 2019-12-07 04:13 - 000000000 ____D C:\WINDOWS\INF
2022-09-14 20:06 - 2019-12-07 04:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2022-09-14 20:06 - 2017-08-21 06:48 - 141646296 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2022-09-14 19:59 - 2020-09-30 00:09 - 000000000 ____D C:\WINDOWS\system32\Tasks\McAfee
2022-09-14 19:44 - 2019-12-07 04:03 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2022-09-14 19:44 - 2019-03-25 20:37 - 000000000 ____D C:\Program Files\McAfeeDashboard
2022-09-14 19:44 - 2017-07-29 23:50 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2022-09-14 19:43 - 2018-04-19 19:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
2022-09-14 19:42 - 2017-08-20 01:54 - 000000000 ____D C:\Users\nicz8\AppData\Local\Host App Service
2022-09-14 19:24 - 2021-05-03 11:26 - 000000000 ____D C:\ProgramData\CanonIJPLM
2022-09-14 19:21 - 2020-09-30 00:00 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2022-09-13 06:51 - 2020-03-28 11:46 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2022-09-13 06:51 - 2017-08-20 02:01 - 000000000 ____D C:\Users\nicz8\AppData\Roaming\Skype
2022-09-11 19:13 - 2019-11-20 20:34 - 000037586 _____ C:\Users\nicz8\Desktop\Addition.txt
2022-09-11 08:56 - 2020-09-30 00:09 - 000004562 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2022-09-11 08:56 - 2017-08-20 02:06 - 000002308 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2022-09-11 08:56 - 2017-08-20 02:06 - 000002267 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2022-09-11 08:55 - 2018-04-19 20:18 - 000000000 ____D C:\Users\nicz8\AppData\Local\Packages
2022-09-11 08:55 - 2017-08-23 01:52 - 000002143 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2022-09-11 08:50 - 2020-05-24 00:26 - 000002445 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2022-09-11 08:50 - 2020-05-24 00:26 - 000002283 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2022-09-11 08:50 - 2018-01-20 10:27 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2022-09-01 20:07 - 2020-09-30 00:09 - 000003420 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2022-09-01 20:07 - 2020-09-30 00:09 - 000003296 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2022-08-28 13:46 - 2021-11-08 20:44 - 000000000 ____D C:\Users\nicz8\AppData\Local\D3DSCache
2022-08-28 08:36 - 2020-09-30 00:09 - 000003536 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2022-08-28 08:36 - 2020-09-30 00:09 - 000003412 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
 
==================== SigCheck ============================
 
(There is no automatic fix for files that do not pass verification.)
 
==================== End of FRST.txt ========================
 

Addition log:

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 30-08-2022
Ran by nicz8 (14-09-2022 20:14:26)
Running from C:\Users\nicz8\Desktop
Microsoft Windows 10 Home Version 21H1 19043.1889 (X64) (2020-09-30 05:10:12)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
 
(If an entry is included in the fixlist, it will be removed.)
 
Administrator (S-1-5-21-2126566057-4181855661-943989508-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-2126566057-4181855661-943989508-503 - Limited - Disabled)
Guest (S-1-5-21-2126566057-4181855661-943989508-501 - Limited - Disabled)
nicz8 (S-1-5-21-2126566057-4181855661-943989508-1001 - Administrator - Enabled) => C:\Users\nicz8
WDAGUtilityAccount (S-1-5-21-2126566057-4181855661-943989508-504 - Limited - Disabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: McAfee VirusScan (Disabled - Up to date) {30AC4D1E-F45E-3AA6-6448-D23DAB3B5501}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 22.002.20212 - Adobe Systems Incorporated)
Adobe Refresh Manager (HKLM-x32\...\{AC76BA86-0804-1033-1959-018244601013}) (Version: 1.8.0 - Adobe Systems Incorporated) Hidden
Canon Easy-WebPrint EX (HKLM-x32\...\Easy-WebPrint EX) (Version: 1.7.0.0 - Canon Inc.)
Canon IJ Printer Assistant Tool (HKLM-x32\...\Canon IJ Printer Assistant Tool) (Version: 1.00.4.51 - Canon Inc.)
Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM-x32\...\CANONIJPLM100) (Version: 6.3.0 - Canon Inc.)
Canon My Image Garden (HKLM-x32\...\Canon My Image Garden) (Version: 3.6.4 - Canon Inc.)
Canon My Image Garden Design Files (HKLM-x32\...\Canon My Image Garden Design Files) (Version: 3.6.0 - Canon Inc.)
Canon Quick Menu (HKLM-x32\...\CanonQuickMenu) (Version: 2.8.5 - Canon Inc.)
Canon TS300 series On-screen Manual (HKLM-x32\...\Canon TS300 series On-screen Manual) (Version: 1.1.0 - Canon Inc.)
Canon TS300 series Printer Driver (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_TS300_series) (Version:  - Canon Inc.)
darktable (HKLM\...\darktable) (Version: 3.4.1.1 - the darktable project)
Dolby Atmos Windows API SDK (HKLM\...\{4A2D8823-7CFF-4B1D-9A8A-1807645FFB4E}) (Version: 1.0.1.12 - Dolby Laboratories, Inc.)
Dolby Atmos Windows APP (HKLM\...\{3FC92273-FEF4-4C0B-9AF4-F38D747EB765}) (Version: 1.0.0.10 - Dolby Laboratories, Inc.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 105.0.5195.102 - Google LLC)
Intel® Chipset Device Software (HKLM\...\{81520FC5-3518-40E9-9803-70CE8A801D07}) (Version: 10.1.1.38 - Intel Corporation) Hidden
Intel® Chipset Device Software (HKLM-x32\...\{bb0592a7-5772-4736-9d55-2402740085db}) (Version: 10.1.1.38 - Intel® Corporation) Hidden
Intel® Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.6.0.1039 - Intel Corporation)
Intel® Management Engine Components (HKLM\...\{A6B270EC-19A3-4B33-B78A-297EC57E5B2F}) (Version: 11.6.0.1039 - Intel Corporation) Hidden
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 22.20.16.4836 - Intel Corporation) Hidden
Lenovo App Explorer (HKU\S-1-5-21-2126566057-4181855661-943989508-1001\...\Host App Service) (Version: 0.273.4.468 - SweetLabs for Lenovo) <==== ATTENTION
Lenovo Yoga Mode Control (HKLM\...\{3F2E25D6-49D3-45D5-A7BD-13F5D6F64171}_is1) (Version: 2.0.0.9 - Lenovo)
LINE (HKU\S-1-5-21-2126566057-4181855661-943989508-1001\...\LINE) (Version: 5.11.4.1836 - LINE Corporation)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 105.0.1343.33 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 105.0.1343.33 - Microsoft Corporation)
Microsoft HEVC Media Extension Installation for Microsoft.HEVCVideoExtension_1.0.2512.0_x64__8wekyb3d8bbwe (x64) (HKLM\...\{B0169E83-757B-EF66-E2F0-391944D785BC}) (Version: 1.0.0.0 - Microsoft Corporation) Hidden
Microsoft Office Professional Plus 2016 - en-us (HKLM\...\ProPlusRetail - en-us) (Version: 16.0.15427.20210 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-2126566057-4181855661-943989508-1001\...\OneDriveSetup.exe) (Version: 22.176.0821.0003 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{7B1FCD52-8F6B-4F12-A143-361EA39F5E7C}) (Version: 3.67.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005 (HKLM\...\{929FBD26-9020-399B-9A7A-751D61F0B942}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005 (HKLM\...\{A749D8E6-B613-3BE3-8F5F-045C84EBA29B}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (HKLM-x32\...\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (HKLM-x32\...\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Mylio (HKLM\...\{005E1001-1B62-491C-8B92-661E112A6546}) (Version: 3.12.7092.0 - Mylio, LLC) Hidden
Mylio (HKLM-x32\...\{333af088-8b57-48b7-a31d-9eecfe31638d}) (Version: 3.12.7092.0 - Mylio, LLC)
Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.15427.20178 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.15427.20178 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.15427.20148 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0409-0000-0000000FF1CE}) (Version: 16.0.14131.20278 - Microsoft Corporation) Hidden
Skype version 8.60 (HKLM-x32\...\Skype_is1) (Version: 8.60 - Skype Technologies S.A.)
Sparkol VideoScribe (HKLM-x32\...\{DD0825FB-0B47-48B8-BAC2-B27F1D63FEAB}) (Version: 3.0.9003 - Sparkol) Hidden
Sparkol VideoScribe (HKLM-x32\...\Sparkol VideoScribe 3.0.9003) (Version: 3.0.9003 - Sparkol)
Speccy (HKLM\...\Speccy) (Version: 1.32 - Piriform)
SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version:  - )
Stagelight (HKLM\...\Stagelight) (Version: 3.0.3.6229 - Open Labs, LLC.)
TurboTax 2017 wiapbpm (HKLM-x32\...\{1EEA0422-07ED-41AC-8084-B901A5B2770F}) (Version: 017.000.0312 - Intuit Inc.) Hidden
TurboTax 2017 WinBizFedFormset (HKLM-x32\...\{DC6E9B3E-41FA-46D7-8F83-4BA1E2A76D95}) (Version: 017.000.1323 - Intuit Inc.) Hidden
TurboTax 2017 WinBizReleaseEngine (HKLM-x32\...\{14B2DB5A-45A2-45D5-AEF4-83A1046D847E}) (Version: 017.000.0485 - Intuit Inc.) Hidden
TurboTax 2017 WinBizTaxSupport (HKLM-x32\...\{B626F5E1-668F-4298-9352-400746786DED}) (Version: 017.000.0890 - Intuit Inc.) Hidden
TurboTax 2017 wrapper (HKLM-x32\...\{C00030AF-035D-4D5A-909C-A860A155C420}) (Version: 017.000.0126 - Intuit Inc.) Hidden
TurboTax Business 2017 (HKLM-x32\...\TurboTax Business 2017) (Version: 2017.0 - Intuit, Inc)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{32DC821E-4A7D-4878-BEE8-337FA153D7F2}) (Version: 2.63.0.0 - Microsoft Corporation) Hidden
UpdateAssistant (HKLM\...\{52C1DD03-104E-4AC6-9DC6-21D585721ED1}) (Version: 1.19.0.0 - Microsoft Corporation) Hidden
Vulkan Run Time Libraries 1.0.54.1 (HKLM\...\VulkanRT1.0.54.1) (Version: 1.0.54.1 - Intel Corporation Inc.) Hidden
Vulkan Run Time Libraries 1.0.54.1 (HKLM\...\VulkanRT1.0.54.1-2) (Version: 1.0.54.1 - Intel Corporation Inc.) Hidden
Vulkan Run Time Libraries 1.0.54.1 (HKLM\...\VulkanRT1.0.54.1-3) (Version: 1.0.54.1 - Intel Corporation Inc.) Hidden
Vulkan Run Time Libraries 1.0.54.1 (HKLM\...\VulkanRT1.0.54.1-4) (Version: 1.0.54.1 - Intel Corporation Inc.) Hidden
Vulkan Run Time Libraries 1.0.54.1 (HKLM\...\VulkanRT1.0.54.1-5) (Version: 1.0.54.1 - Intel Corporation Inc.)
Wacom Pen (HKLM\...\ISD Tablet Driver) (Version: 7.3.4-23 - Wacom Technology Corp.)
WhoCrashed 6.65 (HKLM\...\WhoCrashed_is1) (Version:  - Resplendence Software Projects Sp.)
Windows 10 Update Assistant (HKLM-x32\...\{D5C69738-B486-402E-85AC-2456D98A64E4}) (Version: 1.4.9200.22395 - Microsoft Corporation)
Windows PC Health Check (HKLM\...\{6798C408-2636-448C-8AC6-F4E341102D27}) (Version: 3.6.2204.08001 - Microsoft Corporation)
Windows Setup Remediations (x64) (KB4023057) (HKLM\...\{5534e02f-0f5d-40dd-ba92-bea38d22384d}.sdb) (Version:  - )
 
Packages:
=========
Autodesk SketchBook -> C:\Program Files\WindowsApps\89006A2E.AutodeskSketchBook_5.1.0.0_x64__tf1gferkr813w [2019-11-10] (Autodesk Inc.)
Bubble Witch 3 Saga -> C:\Program Files\WindowsApps\king.com.BubbleWitch3Saga_7.21.71.0_x64__kgqvnymyfvs32 [2022-07-24] (king.com)
iTunes -> C:\Program Files\WindowsApps\AppleInc.iTunes_12125.8.57037.0_x64__nzyj5cx40ttqa [2022-09-14] (Apple Inc.) [Startup Task]
Keeper - Password Manager & Secure File Storage -> C:\Program Files\WindowsApps\KeeperSecurityInc.Keeper_14.0.33.0_x64__kejf07qmg0jnm [2019-07-29] (Keeper Security Inc)
Lenovo Account Portal -> C:\Program Files\WindowsApps\LenovoCorporation.LenovoID_2.0.37.0_x86__4642shxvsv8s2 [2017-08-20] (LENOVO INCORPORATED.)
Lenovo Settings -> C:\Program Files\WindowsApps\LenovoCorporation.LenovoSettings_3.177.0.0_x86__4642shxvsv8s2 [2018-03-26] (LENOVO INCORPORATED.)
Lenovo Vantage -> C:\Program Files\WindowsApps\E046963F.LenovoCompanion_10.2208.7.0_x64__k1h2ywk1493x8 [2022-08-20] (LENOVO INC.)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-02-17] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-02-17] (Microsoft Corporation) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.14.9020.0_x64__8wekyb3d8bbwe [2022-09-11] (Microsoft Studios) [MS Ad]
Minecraft for Windows 10 -> C:\Program Files\WindowsApps\Microsoft.MinecraftUWP_1.19.2201.0_x64__8wekyb3d8bbwe [2022-09-01] (Microsoft Studios)
Netflix -> C:\Program Files\WindowsApps\4DF9E0F8.Netflix_6.98.1805.0_x64__mcm4njqhnhss8 [2022-02-16] (Netflix, Inc.)
Plex -> C:\Program Files\WindowsApps\CAF9E577.Plex_3.2.20.0_x64__aam28m9va5cke [2017-08-20] (Plex)
 
==================== Custom CLSID (Whitelisted): ==============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_09afa4e14ee4fad2\igfxDTCM.dll [2017-11-24] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
 
==================== Codecs (Whitelisted) ====================
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
ShortcutWithArgument: C:\Users\nicz8\Desktop\Nicole - Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory="Default"
ShortcutWithArgument: C:\Users\nicz8\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Helium Backup.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) ->  --profile-directory=Default --app-id=gpglbgbpeobllokpmeagpoagjbfknanl
 
==================== Loaded Modules (Whitelisted) =============
 
2021-05-03 18:41 - 2017-07-05 13:49 - 000593920 _____ (CANON INC.) [File not signed] [File is in use] C:\Program Files (x86)\Canon\Quick Menu\CNQMMWRP.dll
2021-05-03 18:41 - 2017-07-05 13:43 - 000561152 _____ (CANON INC.) [File not signed] C:\Program Files (x86)\Canon\Quick Menu\CCL.dll
 
==================== Alternate Data Streams (Whitelisted) ========
 
==================== Safe Mode (Whitelisted) ==================
 
==================== Association (Whitelisted) =================
 
==================== Internet Explorer (Whitelisted) ==========
 
HKU\S-1-5-21-2126566057-4181855661-943989508-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://lenovo17win10.msn.com/?pc=LCTE
HKU\S-1-5-21-2126566057-4181855661-943989508-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo17win10.msn.com/?pc=LCTE
HKU\S-1-5-21-2126566057-4181855661-943989508-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://mystart.lenovo.com
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2022-08-13] (Microsoft Corporation -> Microsoft Corporation)
BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2016-02-23] (Canon Inc. -> CANON INC.)
BHO: No Name -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> No File
BHO: No Name -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> No File
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2022-08-13] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2016-02-23] (Canon Inc. -> CANON INC.)
BHO-x32: No Name -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> No File
Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2016-02-23] (Canon Inc. -> CANON INC.)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2016-02-23] (Canon Inc. -> CANON INC.)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2022-08-13] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2022-08-13] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2022-08-13] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2022-08-13] (Microsoft Corporation -> Microsoft Corporation)
 
==================== Hosts content: =========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2017-03-18 16:03 - 2022-09-14 19:51 - 000000838 _____ C:\WINDOWS\system32\drivers\etc\hosts
 
==================== Other Areas ===========================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-2126566057-4181855661-943989508-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Lenovo\LenovoWallPaper.jpg
DNS Servers: 192.168.0.1 - 205.171.2.26
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
==================== FirewallRules (Whitelisted) ================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{985C433C-047D-4602-97E1-0ED887339089}] => (Allow) C:\Users\nicz8\AppData\Local\LINE\bin\5.10.0.1789\LineUpdater.exe (LINE Corporation -> LINE Corporation)
FirewallRules: [{5E47C5B4-6BF5-498F-83BE-A639A48521E4}] => (Allow) C:\Users\nicz8\AppData\Local\LINE\bin\5.10.0.1789\LineUpdater.exe (LINE Corporation -> LINE Corporation)
FirewallRules: [{2F923BAD-A768-4736-B430-EC55D5F7BA60}] => (Allow) C:\Users\nicz8\AppData\Local\LINE\bin\5.10.0.1789\LINE.exe (LINE Corporation -> LINE Corporation)
FirewallRules: [{C3F1FE33-25B1-4678-B08B-4FB738626F9C}] => (Allow) C:\Users\nicz8\AppData\Local\LINE\bin\5.10.0.1789\LINE.exe (LINE Corporation -> LINE Corporation)
FirewallRules: [{99D4DF19-76F3-4F1B-BB1C-4FF49029C914}] => (Allow) C:\Program Files (x86)\Common Files\Mcafee\MMSSHost\MMSSHost.exe => No File
FirewallRules: [{8F5B8066-4388-4586-98DF-A4993BDAF0AD}] => (Allow) C:\Program Files\Common Files\McAfee\MMSSHost\MMSSHost.exe => No File
FirewallRules: [{D7D21A45-BD6D-4360-80DF-7C31046B76A0}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdater.exe (Intuit, Inc. -> Intuit Inc.)
FirewallRules: [{F8D8559A-1435-470C-AC86-27CC10B2571E}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe (Intuit, Inc. -> Intuit Inc.)
FirewallRules: [{753327F0-9644-4966-822D-31080D36E3B8}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe (Intuit, Inc. -> Intuit Inc.)
FirewallRules: [{DCB5FC85-43C8-498A-9E82-B4DB7E409DAA}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe (Intuit, Inc. -> Intuit Inc.)
FirewallRules: [{B278BA47-688C-4BE0-AFBB-E84944891CBC}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe (Intuit, Inc. -> Intuit Inc.)
FirewallRules: [{358C1194-1C30-4061-B8AC-13BEA2DF7FA5}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe (Intuit, Inc. -> Intuit Inc.)
FirewallRules: [{3ACF6AEB-1F49-4A7B-AF4D-9A70E2725DE6}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{67599174-D798-4DCB-A7AD-4682C2C104B8}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{4C7495B4-A205-43FF-BA8F-05AA55A35B08}] => (Allow) C:\Program Files\Mylio\Mylio.exe (MYLIO, LLC -> Mylio LLC)
FirewallRules: [{1DDFB1C9-D4D9-4D7E-9E59-B3C49019B788}] => (Allow) C:\Program Files\Mylio\Mylio.exe (MYLIO, LLC -> Mylio LLC)
FirewallRules: [{0B466E53-82D9-4E8C-930D-C14247FC997C}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{DD17EA51-F596-4377-98F5-1CB3C751AB9F}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{AA4ADB30-32E9-471E-B50A-D7397AF75CDC}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{1A3FDB38-7E73-44B1-907D-9F38603C4296}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\105.0.1343.33\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{C7F7EB77-1123-4EB3-831A-90E18B12C2BE}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{7DDD999B-6240-42D0-99D7-EE027D27C1B9}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.88.3401.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{1C6A57F1-D3BD-494F-B2B3-DB768A6E323E}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.88.3401.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{AAE29C16-0C04-47B2-88C3-C4263C9E0FBF}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.88.3401.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{8FA3F7EC-4C48-4336-892C-6C6705467D29}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.88.3401.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{EB42B062-F3AE-4C87-AFBE-1BE36F83885B}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{3A000F57-32D9-45D0-B062-F16205C2346D}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{18BA925E-42AE-4E27-8513-4B480543EE82}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12125.8.57037.0_x64__nzyj5cx40ttqa\iTunes.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{5E7E8C5F-7067-47B9-B73B-B44930423030}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12125.8.57037.0_x64__nzyj5cx40ttqa\iTunes.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{F98A90EA-053E-4941-8C32-805E286B21A3}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12125.8.57037.0_x64__nzyj5cx40ttqa\iTunes.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{C6C4BBB0-A15B-47B1-8503-BE7EF0879573}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12125.8.57037.0_x64__nzyj5cx40ttqa\iTunes.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{95582CA7-E4D1-4574-BEE1-1C99C8AF5D39}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12125.8.57037.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{3365A9D5-91F6-414B-AE82-C1D33B629EEA}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12125.8.57037.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{777C72B1-26D2-4012-9420-1872AFDC603D}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12125.8.57037.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{A2BF635D-37DB-4B9B-9549-85E7171F99AF}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12125.8.57037.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (Apple Inc. -> Apple Inc.)
 
==================== Restore Points =========================
 
 
==================== Faulty Device Manager Devices ============
 
 
==================== Event log errors: ========================
 
Application errors:
==================
 
System errors:
=============
Error: (09/14/2022 08:11:08 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-T35MG81)
Description: The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register with DCOM within the required timeout.
 
 
CodeIntegrity:
===============
Date: 2022-09-14 20:11:36
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.2207.7-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_09afa4e14ee4fad2\igd10iumd64.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
 
==================== Memory info =========================== 
 
BIOS: LENOVO 1YCN30WW(V1.07) 06/14/2017
Motherboard: LENOVO Lenovo YOGA 720-13IKB
Processor: Intel® Core™ i5-7200U CPU @ 2.50GHz
Percentage of memory in use: 48%
Total physical RAM: 8034.39 MB
Available physical RAM: 4141.99 MB
Total Virtual: 14178.39 MB
Available Virtual: 10391.55 MB
 
==================== Drives ================================
 
Drive c: (Windows) (Fixed) (Total:212.23 GB) (Free:108.38 GB) (Model: NVMe INTEL SSDPEKKW25) NTFS
Drive d: (LENOVO) (Fixed) (Total:25 GB) (Free:23.43 GB) (Model: NVMe INTEL SSDPEKKW25) NTFS
 
\\?\Volume{518f5e61-ba9f-4b70-852c-9437ce5de1a4}\ (WINRE_DRV) (Fixed) (Total:0.98 GB) (Free:0.48 GB) NTFS
\\?\Volume{e17cf99c-0739-4dd5-8122-ae65e303b6d9}\ (SYSTEM_DRV) (Fixed) (Total:0.25 GB) (Free:0.22 GB) FAT32
 
==================== MBR & Partition Table ====================
 
==========================================================
Disk: 0 (Size: 238.5 GB) (Disk ID: B9DA0316)
 
Partition: GPT.
 
==================== End of Addition.txt =======================

  • 0

#6
crayolaplaydoh

crayolaplaydoh

    Member

  • Topic Starter
  • Member
  • PipPip
  • 33 posts

Next set of logs:

Process Log:

Process CPU Private Bytes Working Set PID Verified Signer
System Idle Process 90.86 60 K 8 K 0
ymc.exe 4.05 28,996 K 36,492 K 4440 (Verified) LENOVO
procexp64.exe 2.58 40,568 K 77,056 K 5232 (Verified) Microsoft Corporation
Interrupts 1.47 0 K 0 K n/a
MsMpEng.exe 0.74 265,596 K 257,792 K 4424 (Verified) Microsoft Windows Publisher
csrss.exe 0.37 2,604 K 6,088 K 684 (Verified) Microsoft Windows Publisher
dwm.exe < 0.01 62,824 K 101,216 K 1240 (Verified) Microsoft Windows
System < 0.01 196 K 140 K 4
WUDFHost.exe < 0.01 3,672 K 13,568 K 1052 (Verified) Microsoft Windows
svchost.exe < 0.01 4,368 K 16,088 K 8480 (Verified) Microsoft Windows Publisher
Skype.exe < 0.01 35,296 K 88,020 K 9532 (Verified) Skype Software Sarl
chrome.exe < 0.01 83,776 K 178,096 K 6124 (Verified) Google LLC
explorer.exe < 0.01 70,984 K 280,652 K 7060 (Verified) Microsoft Windows
Lenovo.Modern.ImController.PluginHost.Device.exe < 0.01 36,648 K 58,584 K 6880 (Verified) Lenovo
svchost.exe < 0.01 2,252 K 8,576 K 2528 (Verified) Microsoft Windows Publisher
svchost.exe < 0.01 3,340 K 9,724 K 1704 (Verified) Microsoft Windows Publisher
TabTip.exe < 0.01 3,844 K 16,512 K 10016 (Verified) Microsoft Windows
Lenovo.Modern.ImController.PluginHost.SettingsApp.exe < 0.01 43,472 K 63,828 K 11048 (Verified) Lenovo
Lenovo.Modern.ImController.PluginHost.Device.exe < 0.01 25,608 K 43,408 K 6088 (Verified) Lenovo
ISD_Tablet.exe < 0.01 11,208 K 18,800 K 7384 (Verified) Wacom Technology Corporation
Lenovo.Modern.ImController.PluginHost.SettingsApp.exe < 0.01 30,200 K 43,916 K 11240 (Verified) Lenovo
Lenovo.Modern.ImController.PluginHost.SettingsApp.exe < 0.01 35,960 K 54,840 K 10812 (Verified) Lenovo
chrome.exe < 0.01 15,508 K 40,088 K 9012 (Verified) Google LLC
OfficeClickToRun.exe < 0.01 16,504 K 39,232 K 4156 (Verified) Microsoft Corporation
NisSrv.exe < 0.01 4,796 K 11,908 K 6332 (Verified) Microsoft Windows Publisher
services.exe < 0.01 5,940 K 11,036 K 752 (Verified) Microsoft Windows Publisher
AppleMobileDeviceProcess.exe < 0.01 3,260 K 13,764 K 10884 (Verified) Apple Inc.
chrome.exe < 0.01 119,180 K 152,628 K 10796 (Verified) Google LLC
svchost.exe < 0.01 3,864 K 22,208 K 7264 (Verified) Microsoft Windows Publisher
esif_assist_64.exe < 0.01 1,240 K 4,424 K 6768 (Verified) Intel Corporation
Skype.exe < 0.01 38,124 K 64,116 K 9836 (Verified) Skype Software Sarl
svchost.exe < 0.01 1,552 K 6,288 K 1540 (Verified) Microsoft Windows Publisher
svchost.exe < 0.01 4,268 K 16,268 K 7232 (Verified) Microsoft Windows Publisher
svchost.exe < 0.01 11,792 K 21,520 K 4240 (Verified) Microsoft Windows Publisher
svchost.exe < 0.01 24,536 K 44,796 K 7952 (Verified) Microsoft Windows Publisher
svchost.exe < 0.01 3,588 K 13,144 K 4892 (Verified) Microsoft Windows Publisher
lsass.exe < 0.01 7,936 K 22,492 K 820 (Verified) Microsoft Windows Publisher
TrustedInstaller.exe < 0.01 1,976 K 7,740 K 12008 (Verified) Microsoft Windows
WUDFHost.exe 24,824 K 15,036 K 1016 (Verified) Microsoft Windows
WUDFHost.exe 1,664 K 6,244 K 2588 (Verified) Microsoft Windows
WTabletServiceISD.exe 1,580 K 7,380 K 3084 (Verified) Wacom Technology Corporation
WmiPrvSE.exe 4,392 K 12,496 K 4088 (Verified) Microsoft Windows
WmiPrvSE.exe 3,176 K 10,500 K 5492 (Verified) Microsoft Windows
wlanext.exe 1,284 K 5,948 K 3888 (Verified) Microsoft Windows
winlogon.exe 2,980 K 12,776 K 780 (Verified) Microsoft Windows
wininit.exe 1,704 K 7,156 K 676 (Verified) Microsoft Windows Publisher
WacomHost.exe 2,248 K 11,252 K 5964 (Verified) Wacom Technology Corp.
utility.exe 2,456 K 12,048 K 10848 (Verified) LENOVO
UserOOBEBroker.exe 2,224 K 9,920 K 4024 (Verified) Microsoft Windows
TextInputHost.exe 10,896 K 46,268 K 9924 (Verified) Microsoft Windows
taskhostw.exe 6,768 K 16,204 K 7080 (Verified) Microsoft Windows
SystemSettings.exe Suspended 23,348 K 2,892 K 3564 (Verified) Microsoft Windows
svchost.exe 3,164 K 8,460 K 3168 (Verified) Microsoft Windows Publisher
svchost.exe 20,836 K 21,768 K 1912 (Verified) Microsoft Windows Publisher
svchost.exe 7,792 K 15,692 K 1040 (Verified) Microsoft Windows Publisher
svchost.exe 5,648 K 21,032 K 7040 (Verified) Microsoft Windows Publisher
svchost.exe 13,080 K 34,236 K 956 (Verified) Microsoft Windows Publisher
svchost.exe 2,956 K 10,792 K 9612 (Verified) Microsoft Windows Publisher
svchost.exe 4,900 K 12,872 K 2580 (Verified) Microsoft Windows Publisher
svchost.exe 21,716 K 38,956 K 4132 (Verified) Microsoft Windows Publisher
svchost.exe 9,896 K 15,944 K 4164 (Verified) Microsoft Windows Publisher
svchost.exe 9,288 K 32,484 K 6776 (Verified) Microsoft Windows Publisher
svchost.exe 2,620 K 8,616 K 1124 (Verified) Microsoft Windows Publisher
svchost.exe 6,540 K 19,772 K 3444 (Verified) Microsoft Windows Publisher
svchost.exe 3,044 K 15,440 K 1920 (Verified) Microsoft Windows Publisher
svchost.exe 3,252 K 12,752 K 1368 (Verified) Microsoft Windows Publisher
svchost.exe 4,096 K 8,364 K 2076 (Verified) Microsoft Windows Publisher
svchost.exe 9,144 K 18,260 K 2280 (Verified) Microsoft Windows Publisher
svchost.exe 3,752 K 14,716 K 1728 (Verified) Microsoft Windows Publisher
svchost.exe 2,336 K 7,844 K 2196 (Verified) Microsoft Windows Publisher
svchost.exe 6,684 K 22,632 K 10164 (Verified) Microsoft Windows Publisher
svchost.exe 7,392 K 16,624 K 1580 (Verified) Microsoft Windows Publisher
svchost.exe 2,308 K 8,200 K 2348 (Verified) Microsoft Windows Publisher
svchost.exe 2,748 K 14,028 K 2372 (Verified) Microsoft Windows Publisher
svchost.exe 11,244 K 20,436 K 3944 (Verified) Microsoft Windows Publisher
svchost.exe 8,136 K 33,656 K 6848 (Verified) Microsoft Windows Publisher
svchost.exe 3,588 K 10,128 K 2820 (Verified) Microsoft Windows Publisher
svchost.exe 3,808 K 17,316 K 6684 (Verified) Microsoft Windows Publisher
svchost.exe 2,356 K 7,740 K 3352 (Verified) Microsoft Windows Publisher
svchost.exe 3,164 K 11,992 K 8584 (Verified) Microsoft Windows Publisher
svchost.exe 2,512 K 9,212 K 5784 (Verified) Microsoft Windows Publisher
svchost.exe 3,140 K 13,172 K 9428 (Verified) Microsoft Windows Publisher
svchost.exe 2,352 K 10,764 K 2184 (Verified) Microsoft Windows Publisher
svchost.exe 17,376 K 35,700 K 5644 (Verified) Microsoft Windows Publisher
svchost.exe 2,992 K 10,732 K 4112 (Verified) Microsoft Windows Publisher
svchost.exe 5,048 K 16,580 K 3704 (Verified) Microsoft Windows Publisher
svchost.exe 3,376 K 13,612 K 2180 (Verified) Microsoft Windows Publisher
svchost.exe 1,416 K 5,724 K 4972 (Verified) Microsoft Windows Publisher
svchost.exe 1,996 K 8,068 K 9648 (Verified) Microsoft Windows Publisher
svchost.exe 2,456 K 9,564 K 4348 (Verified) Microsoft Windows Publisher
svchost.exe 1,828 K 6,976 K 3176 (Verified) Microsoft Windows Publisher
svchost.exe 1,916 K 8,212 K 3692 (Verified) Microsoft Windows Publisher
svchost.exe 1,916 K 7,596 K 5396 (Verified) Microsoft Windows Publisher
svchost.exe 2,352 K 10,396 K 3936 (Verified) Microsoft Windows Publisher
svchost.exe 2,092 K 7,912 K 2848 (Verified) Microsoft Windows Publisher
svchost.exe 1,344 K 6,036 K 2396 (Verified) Microsoft Windows Publisher
svchost.exe 2,532 K 10,872 K 7152 (Verified) Microsoft Windows Publisher
svchost.exe 4,844 K 21,528 K 4412 (Verified) Microsoft Windows Publisher
svchost.exe 1,784 K 7,220 K 1348 (Verified) Microsoft Windows Publisher
svchost.exe 2,400 K 9,052 K 3520 (Verified) Microsoft Windows Publisher
svchost.exe 2,848 K 10,880 K 1456 (Verified) Microsoft Windows Publisher
svchost.exe 4,300 K 14,912 K 9780 (Verified) Microsoft Windows Publisher
svchost.exe 1,856 K 8,604 K 6784 (Verified) Microsoft Windows Publisher
svchost.exe 3,328 K 10,720 K 3180 (Verified) Microsoft Windows Publisher
svchost.exe 2,156 K 8,484 K 4000 (Verified) Microsoft Windows Publisher
svchost.exe 3,404 K 11,252 K 4564 (Verified) Microsoft Windows Publisher
svchost.exe 1,724 K 7,460 K 5864 (Verified) Microsoft Windows Publisher
svchost.exe 1,428 K 5,704 K 6108 (Verified) Microsoft Windows Publisher
svchost.exe 2,164 K 10,388 K 5728 (Verified) Microsoft Windows Publisher
svchost.exe 4,612 K 11,208 K 1484 (Verified) Microsoft Windows Publisher
svchost.exe 2,168 K 9,424 K 4360 (Verified) Microsoft Windows Publisher
svchost.exe 1,684 K 7,004 K 4324 (Verified) Microsoft Windows Publisher
svchost.exe 1,332 K 5,892 K 4376 (Verified) Microsoft Windows Publisher
svchost.exe 1,588 K 5,952 K 4708 (Verified) Microsoft Windows Publisher
svchost.exe 2,480 K 13,044 K 3596 (Verified) Microsoft Windows Publisher
svchost.exe 2,140 K 8,436 K 2832 (Verified) Microsoft Windows Publisher
svchost.exe 2,132 K 8,744 K 2632 (Verified) Microsoft Windows Publisher
svchost.exe 2,072 K 8,536 K 2652 (Verified) Microsoft Windows Publisher
svchost.exe 1,760 K 6,836 K 2052 (Verified) Microsoft Windows Publisher
svchost.exe 1,776 K 6,692 K 1760 (Verified) Microsoft Windows Publisher
svchost.exe 1,640 K 7,548 K 2044 (Verified) Microsoft Windows Publisher
svchost.exe 2,132 K 8,144 K 1340 (Verified) Microsoft Windows Publisher
svchost.exe 1,916 K 8,284 K 1928 (Verified) Microsoft Windows Publisher
svchost.exe 2,072 K 8,608 K 1476 (Verified) Microsoft Windows Publisher
svchost.exe 2,076 K 8,036 K 1152 (Verified) Microsoft Windows Publisher
StartMenuExperienceHost.exe 23,024 K 69,820 K 7228 (Verified) Microsoft Windows
sppsvc.exe 4,172 K 13,164 K 7284 (Verified) Microsoft Windows
spoolsv.exe 6,336 K 17,596 K 3816 (Verified) Microsoft Windows
smss.exe 1,172 K 1,252 K 500 (Verified) Microsoft Windows Publisher
smartscreen.exe 9,696 K 27,196 K 10616 (Verified) Microsoft Windows
Skype.exe 14,048 K 39,292 K 11704 (Verified) Skype Software Sarl
Skype.exe 88,024 K 101,444 K 11188 (Verified) Skype Software Sarl
Skype.exe 12,776 K 26,736 K 4356 (Verified) Skype Software Sarl
sihost.exe 6,612 K 29,036 K 6744 (Verified) Microsoft Windows
ShellExperienceHost.exe Suspended 20,428 K 66,236 K 9096 (Verified) Microsoft Windows
SgrmBroker.exe 5,080 K 7,860 K 9680 (Verified) Microsoft Windows Publisher
SettingSyncHost.exe 3,264 K 6,524 K 9976 (Verified) Microsoft Windows
SecurityHealthSystray.exe 1,976 K 9,788 K 11028 (Verified) Microsoft Windows
SecurityHealthService.exe 4,200 K 14,940 K 11072 (Verified) Microsoft Windows Publisher
SearchIndexer.exe 23,368 K 30,228 K 8224 (Verified) Microsoft Windows
SearchApp.exe Suspended 93,888 K 161,768 K 6944 (Verified) Microsoft Windows
RuntimeBroker.exe 6,248 K 24,420 K 7852 (Verified) Microsoft Windows
RuntimeBroker.exe 8,068 K 28,272 K 8788 (Verified) Microsoft Windows
RuntimeBroker.exe 2,084 K 12,588 K 900 (Verified) Microsoft Windows
RuntimeBroker.exe 4,144 K 19,020 K 3580 (Verified) Microsoft Windows
RuntimeBroker.exe 3,056 K 15,676 K 6024 (Verified) Microsoft Windows
Registry 11,240 K 95,968 K 100
RAVCpl64.exe 6,724 K 17,512 K 11216 (Verified) Realtek Semiconductor Corp.
RAVBg64.exe 6,272 K 15,804 K 10416 (Verified) Realtek Semiconductor Corp.
RAVBg64.exe 6,288 K 15,868 K 10716 (Verified) Realtek Semiconductor Corp.
procexp.exe 7,332 K 12,852 K 6812 (Verified) Microsoft Corporation
PresentationFontCache.exe 29,204 K 25,888 K 6972 (Verified) Microsoft Corporation
PhoneExperienceHost.exe 79,628 K 158,964 K 10156 (Verified) Microsoft Corporation
MoUsoCoreWorker.exe 4,912 K 15,476 K 1620 (Verified) Microsoft Windows
Memory Compression 160 K 42,192 K 2536
Lenovo.Modern.ImController.PluginHost.SettingsApp.exe 29,364 K 42,784 K 12128 (Verified) Lenovo
Lenovo.Modern.ImController.PluginHost.Device.exe 50,560 K 65,756 K 8160 (Verified) Lenovo
Lenovo.Modern.ImController.PluginHost.Device.exe 33,988 K 55,988 K 10404 (Verified) Lenovo
Lenovo.Modern.ImController.exe 49,352 K 67,072 K 4192 (Verified) Lenovo
ISD_TabletUser.exe 1,788 K 8,472 K 5128 (Verified) Wacom Technology Corporation
IntuitUpdateService.exe 22,348 K 12,524 K 2100 (Verified) Intuit, Inc.
IntelCpHeciSvc.exe 1,948 K 8,692 K 4840 (Verified) Intel® pGFX
IntelCpHDCPSvc.exe 1,508 K 7,448 K 4120 (Verified) Intel® pGFX
ijplmsvc.exe 1,396 K 6,692 K 4180 (Verified) Canon Inc.
igfxEM.exe 3,752 K 14,944 K 3508 (Verified) Intel® pGFX
igfxCUIService.exe 1,968 K 9,236 K 2744 (Verified) Intel® pGFX
HostAppServiceUpdater.exe 4,840 K 5,672 K 8888 (Verified) SweetLabs Inc
GoogleCrashHandler64.exe 1,740 K 876 K 8116 (Verified) Google LLC
GoogleCrashHandler.exe 1,752 K 876 K 8108 (Verified) Google LLC
fontdrvhost.exe 3,620 K 7,804 K 992 (Verified) Microsoft Windows
fontdrvhost.exe 1,508 K 3,616 K 996 (Verified) Microsoft Windows
esif_uf.exe 1,768 K 7,156 K 4212 (Verified) Intel Corporation - pGFX
dllhost.exe 1,996 K 13,120 K 10748 (Verified) Microsoft Windows
dllhost.exe 4,232 K 12,008 K 6456 (Verified) Microsoft Windows
DAX3TrayIcon.exe 3,984 K 12,572 K 4920 (Verified) Dolby Laboratories, Inc.
DAX3API.exe 28,852 K 42,832 K 11884 (Verified) Dolby Laboratories, Inc.
ctfmon.exe 4,316 K 21,352 K 2304 (Verified) Microsoft Windows
csrss.exe 2,364 K 5,812 K 592 (Verified) Microsoft Windows Publisher
conhost.exe 6,256 K 10,144 K 3912 (Verified) Microsoft Windows
CNQMMAIN.EXE 70,752 K 23,560 K 10596 (Verified) Canon Inc.
ChsIME.exe 1,560 K 8,160 K 3784 (Verified) Microsoft Windows
chrome.exe 18,548 K 51,884 K 11532 (Verified) Google LLC
chrome.exe 14,600 K 30,932 K 5904 (Verified) Google LLC
chrome.exe 101,532 K 123,528 K 5608 (Verified) Google LLC
chrome.exe 8,884 K 20,200 K 5664 (Verified) Google LLC
chrome.exe 18,508 K 50,344 K 11512 (Verified) Google LLC
chrome.exe 18,216 K 50,832 K 9172 (Verified) Google LLC
chrome.exe 1,992 K 7,516 K 6132 (Verified) Google LLC
audiodg.exe 11,112 K 16,960 K 4540 (Verified) Microsoft Windows
armsvc.exe 1,756 K 5,988 K 4104 (Verified) Adobe Inc.
ApplicationFrameHost.exe 8,448 K 28,732 K 4432 (Verified) Microsoft Windows
 

 

Notepad from the elevated command prompt:

 

 
Image Name                     PID Services                                    
========================= ======== ============================================
System Idle Process              0 N/A                                         
System                           4 N/A                                         
Registry                       100 N/A                                         
smss.exe                       500 N/A                                         
csrss.exe                      592 N/A                                         
wininit.exe                    676 N/A                                         
csrss.exe                      684 N/A                                         
services.exe                   752 N/A                                         
winlogon.exe                   780 N/A                                         
lsass.exe                      820 KeyIso, SamSs, VaultSvc                     
svchost.exe                    956 BrokerInfrastructure, DcomLaunch, PlugPlay, 
                                   Power, SystemEventsBroker                   
fontdrvhost.exe                992 N/A                                         
fontdrvhost.exe                996 N/A                                         
WUDFHost.exe                  1016 N/A                                         
svchost.exe                   1040 RpcEptMapper, RpcSs                         
WUDFHost.exe                  1052 N/A                                         
svchost.exe                   1124 LSM                                         
dwm.exe                       1240 N/A                                         
svchost.exe                   1340 BTAGService                                 
svchost.exe                   1348 BthAvctpSvc                                 
svchost.exe                   1368 bthserv                                     
svchost.exe                   1456 NcbService                                  
svchost.exe                   1476 TimeBrokerSvc                               
svchost.exe                   1540 CoreMessagingRegistrar                      
svchost.exe                   1580 Schedule                                    
svchost.exe                   1704 DisplayEnhancementService                   
svchost.exe                   1728 ProfSvc                                     
svchost.exe                   1760 hidserv                                     
svchost.exe                   1912 EventLog                                    
svchost.exe                   1920 UserManager                                 
svchost.exe                   1928 TabletInputService                          
svchost.exe                   2044 DispBrokerDesktopSvc                        
svchost.exe                   2052 DeviceAssociationService                    
svchost.exe                   2076 nsi                                         
svchost.exe                   2184 camsvc                                      
svchost.exe                   2196 Dhcp                                        
svchost.exe                   2280 StateRepository                             
svchost.exe                   2348 EventSystem                                 
svchost.exe                   2372 SysMain                                     
svchost.exe                   2396 Themes                                      
svchost.exe                   2528 SensrSvc                                    
Memory Compression            2536 N/A                                         
svchost.exe                   2580 NlaSvc                                      
WUDFHost.exe                  2588 N/A                                         
svchost.exe                   2632 SENS                                        
svchost.exe                   2652 SensorService                               
igfxCUIService.exe            2744 igfxCUIService2.0.0.0                       
svchost.exe                   2820 netprofm                                    
svchost.exe                   2832 AudioEndpointBuilder                        
svchost.exe                   2848 FontCache                                   
svchost.exe                   2180 Audiosrv                                    
WTabletServiceISD.exe         3084 WTabletServiceISD                           
svchost.exe                   3168 Dnscache                                    
svchost.exe                   3180 Wcmsvc                                      
svchost.exe                   3176 DusmSvc                                     
svchost.exe                   3352 WinHttpAutoProxySvc                         
svchost.exe                   3444 WlanSvc                                     
svchost.exe                   3520 RmSvc                                       
svchost.exe                   3596 ShellHWDetection                            
svchost.exe                   3692 NgcSvc                                      
svchost.exe                   3704 WbioSrvc                                    
spoolsv.exe                   3816 Spooler                                     
wlanext.exe                   3888 N/A                                         
conhost.exe                   3912 N/A                                         
svchost.exe                   3936 NgcCtnrSvc                                  
svchost.exe                   3944 BFE, mpssvc                                 
svchost.exe                   4000 LanmanWorkstation                           
armsvc.exe                    4104 AdobeARMservice                             
svchost.exe                   4112 CryptSvc                                    
IntelCpHDCPSvc.exe            4120 cplspcon                                    
svchost.exe                   4132 DiagTrack                                   
OfficeClickToRun.exe          4156 ClickToRunSvc                               
svchost.exe                   4164 DPS                                         
ijplmsvc.exe                  4180 IJPLMSVC                                    
Lenovo.Modern.ImControlle     4192 ImControllerService                         
esif_uf.exe                   4212 esifsvc                                     
svchost.exe                   4240 Winmgmt                                     
svchost.exe                   4324 SstpSvc                                     
svchost.exe                   4348 LanmanServer                                
svchost.exe                   4360 stisvc                                      
svchost.exe                   4376 TrkWks                                      
svchost.exe                   4412 WpnService                                  
MsMpEng.exe                   4424 WinDefend                                   
ymc.exe                       4440 ymc                                         
svchost.exe                   4564 iphlpsvc                                    
svchost.exe                   4708 WdiSystemHost                               
IntelCpHeciSvc.exe            4840 cphs                                        
svchost.exe                   4892 RasMan                                      
svchost.exe                   4972 WdiServiceHost                              
svchost.exe                   1484 PcaSvc                                      
WmiPrvSE.exe                  5492 N/A                                         
svchost.exe                   5644 AppXSvc                                     
svchost.exe                   5728 Appinfo                                     
svchost.exe                   6108 lmhosts                                     
svchost.exe                   5864 Browser                                     
NisSrv.exe                    6332 WdNisSvc                                    
dllhost.exe                   6456 N/A                                         
svchost.exe                   6684 TokenBroker                                 
sihost.exe                    6744 N/A                                         
esif_assist_64.exe            6768 N/A                                         
svchost.exe                   6776 CDPUserSvc_6eac4                            
svchost.exe                   6784 BluetoothUserService_6eac4                  
svchost.exe                   6848 WpnUserService_6eac4                        
PresentationFontCache.exe     6972 FontCache3.0.0.0                            
taskhostw.exe                 7080 N/A                                         
ISD_TabletUser.exe            5128 N/A                                         
WacomHost.exe                 5964 N/A                                         
svchost.exe                   7040 CDPSvc                                      
explorer.exe                  7060 N/A                                         
igfxEM.exe                    3508 N/A                                         
svchost.exe                   7264 cbdhsvc_6eac4                               
ISD_Tablet.exe                7384 N/A                                         
GoogleCrashHandler.exe        8108 N/A                                         
GoogleCrashHandler64.exe      8116 N/A                                         
StartMenuExperienceHost.e     7228 N/A                                         
RuntimeBroker.exe             7852 N/A                                         
svchost.exe                   5784 UsoSvc                                      
svchost.exe                   7952 wuauserv                                    
SearchApp.exe                 6944 N/A                                         
SearchIndexer.exe             8224 WSearch                                     
svchost.exe                   8480 DoSvc                                       
svchost.exe                   8584 StorSvc                                     
RuntimeBroker.exe             8788 N/A                                         
svchost.exe                   7152 LicenseManager                              
svchost.exe                   9428 lfsvc                                       
TextInputHost.exe             9924 N/A                                         
PhoneExperienceHost.exe      10156 N/A                                         
svchost.exe                  10164 OneSyncSvc_6eac4,                           
                                   PimIndexMaintenanceSvc_6eac4,               
                                   UnistoreSvc_6eac4, UserDataSvc_6eac4        
SettingSyncHost.exe           9976 N/A                                         
ctfmon.exe                    2304 N/A                                         
TabTip.exe                   10016 N/A                                         
ChsIME.exe                    3784 N/A                                         
RuntimeBroker.exe             6024 N/A                                         
RuntimeBroker.exe             3580 N/A                                         
chrome.exe                    6124 N/A                                         
chrome.exe                    6132 N/A                                         
chrome.exe                    5608 N/A                                         
chrome.exe                    9012 N/A                                         
chrome.exe                    5664 N/A                                         
SecurityHealthSystray.exe    11028 N/A                                         
Lenovo.Modern.ImControlle    11048 N/A                                         
SecurityHealthService.exe    11072 SecurityHealthService                       
RAVCpl64.exe                 11216 N/A                                         
Lenovo.Modern.ImControlle    11240 N/A                                         
RAVBg64.exe                  10416 N/A                                         
RAVBg64.exe                  10716 N/A                                         
utility.exe                  10848 N/A                                         
chrome.exe                   10796 N/A                                         
DAX3TrayIcon.exe              4920 N/A                                         
chrome.exe                    9172 N/A                                         
chrome.exe                   11512 N/A                                         
chrome.exe                   11532 N/A                                         
DAX3API.exe                  11884 DAXAPI                                      
Lenovo.Modern.ImControlle    12128 N/A                                         
AppleMobileDeviceProcess.    10884 N/A                                         
CNQMMAIN.EXE                 10596 N/A                                         
SystemSettings.exe            3564 N/A                                         
ApplicationFrameHost.exe      4432 N/A                                         
UserOOBEBroker.exe            4024 N/A                                         
svchost.exe                   1152 SSDPSRV                                     
IntuitUpdateService.exe       2100 IntuitUpdateServiceV4                       
SgrmBroker.exe                9680 SgrmBroker                                  
svchost.exe                   9612 wscsvc                                      
HostAppServiceUpdater.exe     8888 N/A                                         
svchost.exe                   9780 smphost                                     
Lenovo.Modern.ImControlle    10404 N/A                                         
Lenovo.Modern.ImControlle    10812 N/A                                         
Lenovo.Modern.ImControlle     6088 N/A                                         
Lenovo.Modern.ImControlle     8160 N/A                                         
Lenovo.Modern.ImControlle     6880 N/A                                         
chrome.exe                    5904 N/A                                         
Skype.exe                     9532 N/A                                         
Skype.exe                     4356 N/A                                         
Skype.exe                     9836 N/A                                         
Skype.exe                    11704 N/A                                         
Skype.exe                    11188 N/A                                         
dllhost.exe                  10748 N/A                                         
smartscreen.exe              10616 N/A                                         
audiodg.exe                   4540 N/A                                         
procexp.exe                   6812 N/A                                         
procexp64.exe                 5232 N/A                                         
WmiPrvSE.exe                  4088 N/A                                         
ShellExperienceHost.exe       9096 N/A                                         
RuntimeBroker.exe              900 N/A                                         
svchost.exe                   5396 gpsvc                                       
svchost.exe                   7232 wlidsvc                                     
TrustedInstaller.exe         12008 TrustedInstaller                            
MoUsoCoreWorker.exe           1620 N/A                                         
SearchProtocolHost.exe        2664 N/A                                         
SearchFilterHost.exe         11760 N/A                                         
dllhost.exe                  12104 N/A                                         
cmd.exe                       6652 N/A                                         
conhost.exe                   9236 N/A                                         
tasklist.exe                  1272 N/A                                         

  • 0

#7
crayolaplaydoh

crayolaplaydoh

    Member

  • Topic Starter
  • Member
  • PipPip
  • 33 posts

Okay! Attaching the Desktop log. 

 

Latency report below:

_________________________________________________________________________________________________________
CONCLUSION
_________________________________________________________________________________________________________
Your system appears to be suitable for handling real-time audio and other tasks without dropouts. 
LatencyMon has been analyzing your system for  0:00:36  (h:mm:ss) on all processors.
 
 
_________________________________________________________________________________________________________
SYSTEM INFORMATION
_________________________________________________________________________________________________________
Computer name:                                        DESKTOP-T35MG81
OS version:                                           Windows 10, 10.0, version 2009, build: 19043 (x64)
Hardware:                                             80X6, LENOVO
BIOS:                                                 1YCN30WW(V1.07)
CPU:                                                  GenuineIntel Intel® Core™ i5-7200U CPU @ 2.50GHz
Logical processors:                                   4
Processor groups:                                     1
Processor group size:                                 4
RAM:                                                  8034 MB total
 
 
_________________________________________________________________________________________________________
CPU SPEED
_________________________________________________________________________________________________________
Reported CPU speed (WMI):                             260 MHz
Reported CPU speed (registry):                        2712 MHz
 
Note: reported execution times may be calculated based on a fixed reported CPU speed. Disable variable speed settings like Intel Speed Step and AMD Cool N Quiet in the BIOS setup for more accurate results.
 
 
_________________________________________________________________________________________________________
MEASURED INTERRUPT TO USER PROCESS LATENCIES
_________________________________________________________________________________________________________
The interrupt to process latency reflects the measured interval that a usermode process needed to respond to a hardware request from the moment the interrupt service routine started execution. This includes the scheduling and execution of a DPC routine, the signaling of an event and the waking up of a usermode thread from an idle wait state in response to that event.
 
Highest measured interrupt to process latency (µs):   219.0
Average measured interrupt to process latency (µs):   13.531479
 
Highest measured interrupt to DPC latency (µs):       183.90
Average measured interrupt to DPC latency (µs):       3.130735
 
 
_________________________________________________________________________________________________________
 REPORTED ISRs
_________________________________________________________________________________________________________
Interrupt service routines are routines installed by the OS and device drivers that execute in response to a hardware interrupt signal.
 
Highest ISR routine execution time (µs):              104.50
Driver with highest ISR routine execution time:       Wdf01000.sys - Kernel Mode Driver Framework Runtime, Microsoft Corporation
 
Highest reported total ISR routine time (%):          0.044437
Driver with highest ISR total time:                   Wdf01000.sys - Kernel Mode Driver Framework Runtime, Microsoft Corporation
 
Total time spent in ISRs (%)                          0.048146
 
ISR count (execution time <250 µs):                   8502
ISR count (execution time 250-500 µs):                0
ISR count (execution time 500-1000 µs):               0
ISR count (execution time 1000-2000 µs):              0
ISR count (execution time 2000-4000 µs):              0
ISR count (execution time >=4000 µs):                 0
 
 
_________________________________________________________________________________________________________
REPORTED DPCs
_________________________________________________________________________________________________________
DPC routines are part of the interrupt servicing dispatch mechanism and disable the possibility for a process to utilize the CPU while it is interrupted until the DPC has finished execution.
 
Highest DPC routine execution time (µs):              506.409292
Driver with highest DPC routine execution time:       ACPI.sys - ACPI Driver for NT, Microsoft Corporation
 
Highest reported total DPC routine time (%):          0.093562
Driver with highest DPC total execution time:         Wdf01000.sys - Kernel Mode Driver Framework Runtime, Microsoft Corporation
 
Total time spent in DPCs (%)                          0.271728
 
DPC count (execution time <250 µs):                   43754
DPC count (execution time 250-500 µs):                0
DPC count (execution time 500-10000 µs):              6
DPC count (execution time 1000-2000 µs):              0
DPC count (execution time 2000-4000 µs):              0
DPC count (execution time >=4000 µs):                 0
 
 
_________________________________________________________________________________________________________
 REPORTED HARD PAGEFAULTS
_________________________________________________________________________________________________________
Hard pagefaults are events that get triggered by making use of virtual memory that is not resident in RAM but backed by a memory mapped file on disk. The process of resolving the hard pagefault requires reading in the memory from disk while the process is interrupted and blocked from execution.
 
NOTE: some processes were hit by hard pagefaults. If these were programs producing audio, they are likely to interrupt the audio stream resulting in dropouts, clicks and pops. Check the Processes tab to see which programs were hit.
 
Process with highest pagefault count:                 compattelrunner.exe
 
Total number of hard pagefaults                       870
Hard pagefault count of hardest hit process:          790
Number of processes hit:                              13
 
 
_________________________________________________________________________________________________________
 PER CPU DATA
_________________________________________________________________________________________________________
CPU 0 Interrupt cycle time (s):                       0.937222
CPU 0 ISR highest execution time (µs):                104.50
CPU 0 ISR total execution time (s):                   0.069721
CPU 0 ISR count:                                      8502
CPU 0 DPC highest execution time (µs):                506.409292
CPU 0 DPC total execution time (s):                   0.324367
CPU 0 DPC count:                                      31106
_________________________________________________________________________________________________________
CPU 1 Interrupt cycle time (s):                       0.298419
CPU 1 ISR highest execution time (µs):                0.0
CPU 1 ISR total execution time (s):                   0.0
CPU 1 ISR count:                                      0
CPU 1 DPC highest execution time (µs):                273.851032
CPU 1 DPC total execution time (s):                   0.015936
CPU 1 DPC count:                                      2400
_________________________________________________________________________________________________________
CPU 2 Interrupt cycle time (s):                       0.189576
CPU 2 ISR highest execution time (µs):                0.0
CPU 2 ISR total execution time (s):                   0.0
CPU 2 ISR count:                                      0
CPU 2 DPC highest execution time (µs):                353.188791
CPU 2 DPC total execution time (s):                   0.034316
CPU 2 DPC count:                                      6740
_________________________________________________________________________________________________________
CPU 3 Interrupt cycle time (s):                       0.152534
CPU 3 ISR highest execution time (µs):                0.0
CPU 3 ISR total execution time (s):                   0.0
CPU 3 ISR count:                                      0
CPU 3 DPC highest execution time (µs):                254.932891
CPU 3 DPC total execution time (s):                   0.018875
CPU 3 DPC count:                                      3514
_________________________________________________________________________________________________________
 

Attached Files


  • 0

#8
crayolaplaydoh

crayolaplaydoh

    Member

  • Topic Starter
  • Member
  • PipPip
  • 33 posts

Screenshots attached. I think this is the last step for me.

 

Attached Thumbnails

  • 9.14 Processes.JPG
  • 9.14 Drivers.JPG

  • 0

#9
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,331 posts
  • MVP
You have a problem with your WiFi.  You are using channel 6 and the signal strength is 91.  There is a second signal on channel 6 with a signal strength of 93 and several others with a strength of 80.  This will cause a lot of interference.  If you have access to your router you can log on to it and change the WiFi channel assignment from Automatic to Manual then tell it to use  a different channel such as 9.  For best results you may want to download Inssider
Double click to install it. Then run it by right click and Run As Admin.
 
It will show you a graph in the bottom that has your signal in blue and competing signals in orange and yellow.  (If you don't see a graph then try a different tab)  It may also recommend a different channel which might have less interference.  You will probably need to reconnect your wifi after changing the channel.
 
Moving to a different channel (by logging on to your router) can drastically improve performance.  Test your connectivity before and after changing the channel assignment by going to speedtest.net then hit Go and wait.
 
We can speed up your PC a bit by removing some Microsoft spyware:
 
 
Search for
 
task scheduler
 
When it finds it, right click and Run As Administrator
 
Click on the arrow in front of Task Scheduler Library then
 
Click on the arrow in front of Microsoft
 
Click on the arrow in front of Windows
 
Click on Application Experience.  In the next pane to the right, right click on each Task and Delete.  Should be three or four (later versions) tasks.
 
Click on Customer Experience Improvement Program.  In the next pane to the right, right click on each Task and Delete.  Should be two tasks.
 
Close Task Scheduler.
 
Search for
services.msc
hit Enter
 
Find SysMain
Right click on it and select Properties.  Change the Startup Type from Automatic to Disabled.  OK
 
 
 
Download OOSU10.exe:
 
 
Download and Save it (You will get a popup while it's downloading.  You can X out of it)
then go to the Download folder and Right click on the downloaded file and Run As Admin.
Allow it to make a System Restore Point.
Click on Actions then on Apply Recommended Settings.
 
Close the program and reboot.
Rerun Latency Monitor and post the summary and a screenshot of the Processes tab.
 
 
The only thing I can see which might cause a popup is that you have several notifications allowed in Chrome. 
CHR Notifications: Default -> hxxps://www.bostonmarket.com; hxxps://www.mirta.com; hxxps://www.sephora.com; hxxps://www.yesstyle.com; hxxps://www.youtube.com
 

 

I suppose it's possible that one of these is sending you NSFW popups.

 
In Chrome go to 
chrome://settings/content
 
Click on the arrow to the right of Notifications
 
Scroll down to Allowed to send notifications.
Look for the list.  If you see a site that you think might be at fault you can click on the three dots and Block or Remove.

  • 0

#10
crayolaplaydoh

crayolaplaydoh

    Member

  • Topic Starter
  • Member
  • PipPip
  • 33 posts

Hi! Thanks -

 

Sorry - I'm a little stuck at this step. How do I allow it to make a System Restore Point? I don't see a pop up / option for this?

 

Download and Save it (You will get a popup while it's downloading.  You can X out of it)
then go to the Download folder and Right click on the downloaded file and Run As Admin.
Allow it to make a System Restore Point.
Click on Actions then on Apply Recommended Settings.

  • 0

Advertisements


#11
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,331 posts
  • MVP

Normally it just asks you if you want to make a System Restore point.  If it doesn't ask you may have turned off system restore or perhaps you didn't start the program by right clicking and Run As Admin.  The program is pretty safe and I've never needed the System Restore point so I'd just go ahead and continue.


  • 0

#12
crayolaplaydoh

crayolaplaydoh

    Member

  • Topic Starter
  • Member
  • PipPip
  • 33 posts

Okay.

 

Latency Monitor:

_________________________________________________________________________________________________________
CONCLUSION
_________________________________________________________________________________________________________
Your system appears to be suitable for handling real-time audio and other tasks without dropouts. 
LatencyMon has been analyzing your system for  0:01:12  (h:mm:ss) on all processors.
 
 
_________________________________________________________________________________________________________
SYSTEM INFORMATION
_________________________________________________________________________________________________________
Computer name:                                        DESKTOP-T35MG81
OS version:                                           Windows 10, 10.0, version 2009, build: 19043 (x64)
Hardware:                                             80X6, LENOVO
BIOS:                                                 1YCN30WW(V1.07)
CPU:                                                  GenuineIntel Intel® Core™ i5-7200U CPU @ 2.50GHz
Logical processors:                                   4
Processor groups:                                     1
Processor group size:                                 4
RAM:                                                  8034 MB total
 
 
_________________________________________________________________________________________________________
CPU SPEED
_________________________________________________________________________________________________________
Reported CPU speed (WMI):                             260 MHz
Reported CPU speed (registry):                        2712 MHz
 
Note: reported execution times may be calculated based on a fixed reported CPU speed. Disable variable speed settings like Intel Speed Step and AMD Cool N Quiet in the BIOS setup for more accurate results.
 
 
_________________________________________________________________________________________________________
MEASURED INTERRUPT TO USER PROCESS LATENCIES
_________________________________________________________________________________________________________
The interrupt to process latency reflects the measured interval that a usermode process needed to respond to a hardware request from the moment the interrupt service routine started execution. This includes the scheduling and execution of a DPC routine, the signaling of an event and the waking up of a usermode thread from an idle wait state in response to that event.
 
Highest measured interrupt to process latency (µs):   560.70
Average measured interrupt to process latency (µs):   11.027357
 
Highest measured interrupt to DPC latency (µs):       545.10
Average measured interrupt to DPC latency (µs):       2.554087
 
 
_________________________________________________________________________________________________________
 REPORTED ISRs
_________________________________________________________________________________________________________
Interrupt service routines are routines installed by the OS and device drivers that execute in response to a hardware interrupt signal.
 
Highest ISR routine execution time (µs):              413.119838
Driver with highest ISR routine execution time:       ACPI.sys - ACPI Driver for NT, Microsoft Corporation
 
Highest reported total ISR routine time (%):          0.050426
Driver with highest ISR total time:                   Wdf01000.sys - Kernel Mode Driver Framework Runtime, Microsoft Corporation
 
Total time spent in ISRs (%)                          0.056142
 
ISR count (execution time <250 µs):                   22028
ISR count (execution time 250-500 µs):                0
ISR count (execution time 500-1000 µs):               1
ISR count (execution time 1000-2000 µs):              0
ISR count (execution time 2000-4000 µs):              0
ISR count (execution time >=4000 µs):                 0
 
 
_________________________________________________________________________________________________________
REPORTED DPCs
_________________________________________________________________________________________________________
DPC routines are part of the interrupt servicing dispatch mechanism and disable the possibility for a process to utilize the CPU while it is interrupted until the DPC has finished execution.
 
Highest DPC routine execution time (µs):              844.334808
Driver with highest DPC routine execution time:       ACPI.sys - ACPI Driver for NT, Microsoft Corporation
 
Highest reported total DPC routine time (%):          0.120980
Driver with highest DPC total execution time:         Wdf01000.sys - Kernel Mode Driver Framework Runtime, Microsoft Corporation
 
Total time spent in DPCs (%)                          0.316661
 
DPC count (execution time <250 µs):                   106722
DPC count (execution time 250-500 µs):                0
DPC count (execution time 500-10000 µs):              7
DPC count (execution time 1000-2000 µs):              0
DPC count (execution time 2000-4000 µs):              0
DPC count (execution time >=4000 µs):                 0
 
 
_________________________________________________________________________________________________________
 REPORTED HARD PAGEFAULTS
_________________________________________________________________________________________________________
Hard pagefaults are events that get triggered by making use of virtual memory that is not resident in RAM but backed by a memory mapped file on disk. The process of resolving the hard pagefault requires reading in the memory from disk while the process is interrupted and blocked from execution.
 
NOTE: some processes were hit by hard pagefaults. If these were programs producing audio, they are likely to interrupt the audio stream resulting in dropouts, clicks and pops. Check the Processes tab to see which programs were hit.
 
Process with highest pagefault count:                 runtimebroker.exe
 
Total number of hard pagefaults                       7916
Hard pagefault count of hardest hit process:          1036
Number of processes hit:                              44
 
 
_________________________________________________________________________________________________________
 PER CPU DATA
_________________________________________________________________________________________________________
CPU 0 Interrupt cycle time (s):                       1.914960
CPU 0 ISR highest execution time (µs):                413.119838
CPU 0 ISR total execution time (s):                   0.161995
CPU 0 ISR count:                                      21966
CPU 0 DPC highest execution time (µs):                844.334808
CPU 0 DPC total execution time (s):                   0.738935
CPU 0 DPC count:                                      77006
_________________________________________________________________________________________________________
CPU 1 Interrupt cycle time (s):                       0.546901
CPU 1 ISR highest execution time (µs):                38.88090
CPU 1 ISR total execution time (s):                   0.000501
CPU 1 ISR count:                                      63
CPU 1 DPC highest execution time (µs):                101.112832
CPU 1 DPC total execution time (s):                   0.044749
CPU 1 DPC count:                                      7923
_________________________________________________________________________________________________________
CPU 2 Interrupt cycle time (s):                       0.420977
CPU 2 ISR highest execution time (µs):                0.0
CPU 2 ISR total execution time (s):                   0.0
CPU 2 ISR count:                                      0
CPU 2 DPC highest execution time (µs):                160.026917
CPU 2 DPC total execution time (s):                   0.088590
CPU 2 DPC count:                                      13869
_________________________________________________________________________________________________________
CPU 3 Interrupt cycle time (s):                       0.308142
CPU 3 ISR highest execution time (µs):                0.0
CPU 3 ISR total execution time (s):                   0.0
CPU 3 ISR count:                                      0
CPU 3 DPC highest execution time (µs):                142.463496
CPU 3 DPC total execution time (s):                   0.044257
CPU 3 DPC count:                                      7931
_________________________________________________________________________________________________________
 

  • 0

#13
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,331 posts
  • MVP

Looks much better.  Suspect it may be trying to install a Windows update.  Go into Settings, Update & Security and it should tell you if it has an update in progress.  Click on Check Now.

 

 

 

How is it running now?  Any more popups?

 

We can look for a rootkit.  Run MBAR:

 

https://www.malwareb...com/antirootkit

 

Click on Download, Save the file then go to the download folder and right click and Run as Admin. then follow the instructions.


  • 0

#14
crayolaplaydoh

crayolaplaydoh

    Member

  • Topic Starter
  • Member
  • PipPip
  • 33 posts

Hi:

So I think it was trying to install an update. I paused it? Should I have done that?

 

It's running so much faster right now. No lag and no popups so far.

 

Here's the scan:

 

Malwarebytes
www.malwarebytes.com
 
-Log Details-
Scan Date: 9/17/22
Scan Time: 2:15 PM
Log File: 17062f76-36bd-11ed-9069-aced5cf6893d.json
 
-Software Information-
Version: 4.5.14.210
Components Version: 1.0.1767
Update Package Version: 1.0.60189
License: Trial
 
-System Information-
OS: Windows 10 (Build 19043.1889)
CPU: x64
File System: NTFS
User: DESKTOP-T35MG81\nicz8
 
-Scan Summary-
Scan Type: Threat Scan
Scan Initiated By: Manual
Result: Completed
Objects Scanned: 276977
Threats Detected: 0
Threats Quarantined: 0
Time Elapsed: 3 min, 0 sec
 
-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Detect
PUM: Detect
 
-Scan Details-
Process: 0
(No malicious items detected)
 
Module: 0
(No malicious items detected)
 
Registry Key: 0
(No malicious items detected)
 
Registry Value: 0
(No malicious items detected)
 
Registry Data: 0
(No malicious items detected)
 
Data Stream: 0
(No malicious items detected)
 
Folder: 0
(No malicious items detected)
 
File: 0
(No malicious items detected)
 
Physical Sector: 0
(No malicious items detected)
 
WMI: 0
(No malicious items detected)
 
 
(end)

  • 0

#15
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,331 posts
  • MVP

Best to let Windows do its updates as soon as possible.  Let's watch it for a while and make sure the popups don't come back.


  • 0






Similar Topics

1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP