Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 14-11-2021 Ran by jmccastle (administrator) on DESKTOP-M0NPDML (LENOVO 20AMS24V00) (22-11-2021 03:08:59) Running from C:\Users\jmcca\Downloads Loaded Profiles: jmccastle Platform: Microsoft Windows 10 Pro Version 1909 18363.1556 (X64) Language: English (United States) Default browser: Chrome Boot Mode: Normal ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Corel Corporation -> WinZip Computing) C:\Program Files\WinZip\WzPreloader.exe (Corel Corporation -> WinZip Computing, S.L.) C:\Program Files\WinZip\FAHWindow64.exe (F-Secure Corporation -> F-Secure Corporation) C:\Program Files (x86)\Charter Security Suite\fs_ui_32.exe (F-Secure Corporation -> F-Secure Corporation) C:\Program Files (x86)\Charter Security Suite\fshoster32.exe <3> (F-Secure Corporation -> F-Secure Corporation) C:\Program Files (x86)\Charter Security Suite\ui\fsmainui.exe (F-Secure Corporation -> F-Secure Corporation) C:\Program Files (x86)\Charter Security Suite\Ultralight\http\1637061456\nif2_ols_ca.exe (F-Secure Corporation -> F-Secure Corporation) C:\Program Files (x86)\Charter Security Suite\Ultralight\ulcore\1636551986\fshoster64.exe <2> (F-Secure Corporation -> F-Secure Corporation) C:\Program Files (x86)\Charter Security Suite\Ultralight\ulcore\1636551986\fsorsp64.exe (F-Secure Corporation -> F-Secure Corporation) C:\Program Files (x86)\Charter Security Suite\Ultralight\ulcore\1636551986\FsPisces.exe (F-Secure Corporation -> F-Secure Corporation) C:\Program Files (x86)\Charter Security Suite\Ultralight\ulcore\1636551986\fsulprothoster.exe (Google Inc -> Google Inc.) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <40> (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.112\GoogleCrashHandler.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.112\GoogleCrashHandler64.exe (Intel Corporation -> Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\igfxCUIService.exe (Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\igfxHK.exe (Intel(R) Wireless Connectivity Solutions -> Intel Corporation) C:\Windows\System32\ibtsiva.exe (Juniper Networks, Inc. -> Pulse Secure, LLC) C:\Program Files (x86)\Common Files\Juniper Networks\JUNS\dsAccessService.exe (Lavasoft Limited -> Lavasoft Limited) [File not signed] C:\Program Files (x86)\Lavasoft\Web Companion\TcpService\2.3.4.7\LavasoftTcpService.exe (Lavasoft Software Canada -> ) C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe (LENOVO (UNITED STATES) INC. -> Lenovo) C:\Users\jmcca\AppData\Local\Apps\2.0\R2AW7NXE.TZE\5ALG24VY.KOT\lsb...tion_2d7b41b05b24775e_0001.0006_6e55c1acac1ba44a\LSB.exe (Lenovo -> ) C:\Program Files (x86)\Lenovo\System Update\tvsuShim.exe (Lenovo -> Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\micmute.exe (Lenovo -> Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\shtctky.exe (Lenovo -> Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tphkload.exe (Lenovo -> Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tpnumlkd.exe (Lenovo -> Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tposd.exe (Lenovo -> Lenovo Group Ltd.) C:\Windows\Lenovo\ImController\PluginHost86\Lenovo.Modern.ImController.PluginHost.Device.exe (Lenovo -> Lenovo Group Ltd.) C:\Windows\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe (LENOVO -> Lenovo) C:\Program Files\Lenovo\Lenovo Solution Center\LSCNotify.exe (Lenovo -> Lenovo) C:\Windows\SysWOW64\Lenovo\PowerMgr\PowerMgr.exe (Lenovo -> Lenovo.) C:\Windows\System32\ibmpmsvc.exe (McAfee, Inc. -> McAfee, LLC.) C:\Program Files\McAfee\TrueKey\McAfee.TrueKey.Service.exe (McAfee, Inc. -> McAfee, LLC.) C:\Program Files\McAfee\TrueKey\McAfee.TrueKey.ServiceHelper.exe (McAfee, Inc. -> McAfee, LLC.) C:\Program Files\McAfee\TrueKey\McTkSchedulerService.exe (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Microsoft Windows -> Microsoft Corporation) C:\Program Files\ruxim\RUXIMICS.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\cmd.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\LocationNotificationWindows.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\SecurityHealthHost.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\Taskmgr.exe <2> (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\WerFault.exe (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe <2> (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe (Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe (Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics Incorporated -> Synaptics) C:\Program Files\Synaptics\SynTP\SynLenovoHelper.exe (VMware, Inc. -> VMware, Inc.) C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe (VMware, Inc. -> VMware, Inc.) C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe (VMware, Inc. -> VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe (VMware, Inc. -> VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe Failed to access process -> fsscanwizard.exe ==================== Registry (Whitelisted) =================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [WinZip UN] => C:\Program Files\WinZip\WZUpdateNotifier.exe [2859928 2020-08-19] (Corel Corporation -> Corel Corporation) HKLM\...\Run: [WinZip FAH] => C:\Program Files\WinZip\FAHConsole.exe [436704 2020-08-19] (Corel Corporation -> WinZip Computing, S.L.) HKLM-x32\...\Run: [Integrated Camera_Monitor] => C:\Program Files (x86)\Integrated Camera\monitor.exe [1723040 2014-09-01] (Sunplus Innovation Technology Inc. -> SunplusIT, Inc.) [File not signed] HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2016-12-12] (Oracle America, Inc. -> Oracle Corporation) HKLM-x32\...\Run: [TeamsMachineUninstallerLocalAppData] => C:\Users\jmcca\AppData\Local\Microsoft\Teams\Update.exe [2350752 2020-06-11] (Microsoft 3rd Party Application Component -> Microsoft Corporation) HKLM-x32\...\Run: [TeamsMachineUninstallerProgramData] => %ProgramData%\Microsoft\Teams\Update.exe --uninstall --msiUninstall --source=default (No File) HKLM-x32\...\Run: [PulseSecure] => C:\Program Files (x86)\Common Files\Juniper Networks\JamUI\Pulse.exe [2831192 2014-12-09] (Juniper Networks, Inc. -> Pulse Secure, LLC) HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION HKU\S-1-5-21-2892202112-2661542964-2761913289-1001\...\Run: [Web Companion] => C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe [1795736 2017-01-22] (Lavasoft Software Canada -> Lavasoft) HKU\S-1-5-21-2892202112-2661542964-2761913289-1001\...\Run: [com.squirrel.Teams.Teams] => C:\Users\jmcca\AppData\Local\Microsoft\Teams\Update.exe [2350752 2020-06-11] (Microsoft 3rd Party Application Component -> Microsoft Corporation) HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\96.0.4664.45\Installer\chrmstp.exe [2021-11-20] (Google LLC -> Google LLC) HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{30C521FB-255B-46C8-9F0D-EE5AE371C9AA}] -> "C:\Program Files (x86)\AVAST Software\Browser\Application\87.0.7478.88\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level HKLM\Software\...\Authentication\Credential Providers: [{B7724AE5-1135-4889-8A5F-CA98BE6CA1ED}] -> C:\Program Files\McAfee\TrueKey\McAfee.TrueKey.CredentialProvider.dll [2018-11-27] (McAfee, Inc. -> McAfee, LLC.) Lsa: [Notification Packages] scecli "C:\Program Files\TrueKey\McAfeeTrueKeyPasswordFilter" "C:\Program Files\McAfee\TrueKey\McAfeeTrueKeyPasswordFilter" Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Preloader.lnk [2021-11-22] ShortcutTarget: WinZip Preloader.lnk -> C:\Program Files\WinZip\WzPreloader.exe (Corel Corporation -> WinZip Computing) Startup: C:\Users\jmcca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneDrive for Business.lnk [2016-09-19] ShortcutTarget: OneDrive for Business.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVE.EXE (No File) Startup: C:\Users\jmcca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk [2017-01-24] ShortcutTarget: Send to OneNote.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE (No File) HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION ==================== Scheduled Tasks (Whitelisted) ============ (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {0AB330A2-C8C6-4F9C-81E7-93997F0DD865} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program 64 => C:\Program Files (x86)\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe [16832 2015-07-01] (LENOVO -> Lenovo) Task: {0E0151CA-1499-4DB0-A1ED-24A459261D5F} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\45153c97-3f7c-48cb-a62b-0180f74fffd5 => C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [83200 2021-11-07] (Lenovo -> Lenovo Group Ltd.) Task: {1E8D95F4-2E99-466E-BEBD-997AB67037E5} - System32\Tasks\Microsoft\VisualStudio\VSIX Auto Update 14 => C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\VSIXAutoUpdate.exe (No File) Task: {22F06389-CFE2-49AF-9769-CE1DBCEC543A} - System32\Tasks\Microsoft\Windows\WindowsUpdate\RUXIM\RUXIMDisplay => C:\Program Files\ruxim\ruximics.exe [477512 2021-06-30] (Microsoft Windows -> Microsoft Corporation) Task: {2BA17B67-1999-4EE5-ADBD-EDC5545970A6} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\7032d745-7eff-4be6-9cac-5d067be4ef5f => C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [83200 2021-11-07] (Lenovo -> Lenovo Group Ltd.) Task: {3667BF97-9C0E-42F9-AA84-5C8F5C27AD30} - System32\Tasks\Lenovo\ImController\Plugins\LenovoSystemUpdatePlugin_WeeklyTask => %windir%\System32\reg.exe add hklm\SOFTWARE\Lenovo\SystemUpdatePlugin\scheduler /v start /t reg_dword /d 1 /f /reg:32 Task: {378D0E1C-F50C-42C4-9874-DFFF0CD6354E} - System32\Tasks\Lenovo\LSC\Lenovo Solution Center Notifications => C:\Program Files\Lenovo\Lenovo Solution Center\LSCNotify.exe [1321296 2016-06-02] (LENOVO -> Lenovo) Task: {3AC3F644-8E7F-431B-9A39-6FC2E45A3241} - System32\Tasks\TVT\TVSUUpdateTask => C:\Program Files (x86)\Lenovo\System Update\tvsuShim.exe [1758792 2021-07-13] (Lenovo -> ) Task: {3AFCAFB2-5533-4246-8293-339F4FD21DDA} - System32\Tasks\Lenovo\ImController\Lenovo iM Controller Scheduled Maintenance => %windir%\system32\sc.exe START ImControllerService Task: {3DCF7919-0A59-47ED-B7E3-96BC0F3AFB16} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2016-10-30] (Google Inc -> Google Inc.) Task: {404FA85C-0BC7-400A-A9FE-6B13B796A93A} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [682936 2021-11-03] (Mozilla Corporation -> Mozilla Foundation) Task: {44236035-22A9-4DF3-8E2C-D7BC4EA88E56} - System32\Tasks\Microsoft\Windows\WaaSMedic\MaintenanceWork => {72566E27-1ABB-4EB3-B4F0-EB431CB1CB32} Task: {49F3C2FF-84BC-46EB-8D80-9DB01D059BA6} - System32\Tasks\Lenovo\Lenovo Service Bridge\S-1-5-21-2892202112-2661542964-2761913289-1001 => "C:\WINDOWS\system32\rundll32.exe" dfshim.dll,ShOpenVerbShortcut C:\Users\jmcca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo\Lenovo Service Bridge.appref-ms Task: {52A9DD59-20AB-4D29-8056-B983A670890F} - System32\Tasks\TVT\TVSUUpdateTask_UserLogOn => C:\Program Files (x86)\Lenovo\System Update\tvsuShim.exe [1758792 2021-07-13] (Lenovo -> ) Task: {53ADD377-2BD7-4657-89A3-1CBFDDB21991} - System32\Tasks\Lenovo\Power Manager\Background monitor => C:\WINDOWS\SysWOW64\Lenovo\PowerMgr\PowerMgr.exe [113024 2019-11-12] (Lenovo -> Lenovo) Task: {612FCB1E-9057-44D4-9644-321E5AAB9B8F} - System32\Tasks\Lenovo\ImController\Lenovo iM Controller Monitor => C:\WINDOWS\system32\ImController.InfInstaller.exe [63728 2021-11-07] (Lenovo -> Lenovo Group Ltd.) Task: {738E307F-1222-4ED9-A9C1-0B0E80566A56} - System32\Tasks\Lenovo\LSC\LSCHardwareScan => C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe [9944400 2016-06-02] (LENOVO -> Lenovo) Task: {7B810A70-5151-46C4-8ECB-CFE71993A1B6} - System32\Tasks\Lenovo Power Management Driver PnP Task => C:\WINDOWS\System32\ibmpmsvc.exe [851800 2018-12-25] (Lenovo -> Lenovo.) Task: {7D2C1525-B597-4781-BD8E-73AE4D74EA53} - System32\Tasks\McAfee Remediation (Prepare) => C:\Program Files\Common Files\AV\McAfee VirusScan\upgrade.exe [4665296 2018-09-11] (McAfee, Inc. -> McAfee, Inc.) Task: {7DC31F2B-7346-47F0-B4F5-DDF4BE889DC9} - System32\Tasks\DolbySelectorTask => C:\Program Files\Dolby Digital Plus\ddp.exe -autostart (No File) Task: {7E44CAD5-F7EA-4BD8-8BC6-B34A1F2291F5} - System32\Tasks\Lenovo\Lenovo Solution Center Launcher => C:\Program Files\lenovo\lenovo solution center\App\LSC.Services.UpdateStatusService.exe [263504 2016-06-02] (LENOVO -> ) Task: {91A95D73-4CD5-4540-91DE-58D569FCA871} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask backgroundupdate Task: {94B39297-50E2-4976-A4BC-1A7C89D86533} - System32\Tasks\Microsoft\Windows\WindowsUpdate\RUXIM\RUXIMSync => C:\Program Files\ruxim\ruximics.exe [477512 2021-06-30] (Microsoft Windows -> Microsoft Corporation) Task: {A2D33204-D8DB-4DA9-BC46-4DB7DD2693B3} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe /backup /iavs (No File) Task: {AA40C92C-AB21-4328-B0B8-D060341E3A1D} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION Task: {B238EF4D-E3CD-4C19-9713-674C6B63EFE3} - System32\Tasks\WinZip Update Notifier 3 => C:\Program Files\WinZip\WZUpdateNotifier.exe [2859928 2020-08-19] (Corel Corporation -> Corel Corporation) Task: {CF777170-440F-4AB2-BF29-56D4B2700833} - System32\Tasks\RtHDVBg_Dolby => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [3617568 2020-03-06] (Realtek Semiconductor Corp. -> Realtek Semiconductor) Task: {D267DD57-13D0-4D3D-B3F5-C16CF4B950D8} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752 2016-10-30] (Google Inc -> Google Inc.) Task: {E1DE0ADA-98D2-4977-9E52-7DA8BE4BC127} - System32\Tasks\Lenovo\Power Manager\Uninstall task => C:\WINDOWS\SysWOW64\Lenovo\PowerMgr\PowerMgrInst.exe [59776 2019-11-12] (Lenovo -> ) Task: {E78978D1-98B2-4D50-B76B-67DAAE216CF9} - System32\Tasks\MySQL\Installer\ManifestUpdate => C:\Program Files (x86)\MySQL\MySQL Installer for Windows\MySQLInstallerConsole.exe [56272 2018-03-17] (Oracle America, Inc. -> Oracle Corporation) Task: {E7D79063-1733-44CF-A18B-059562A5ABEE} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\439cf995-4873-4a9c-ba54-63298d7d19b8 => C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [83200 2021-11-07] (Lenovo -> Lenovo Group Ltd.) Task: {EB80F889-D264-4C21-9CB3-919AB1A21FE3} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [3617568 2020-03-06] (Realtek Semiconductor Corp. -> Realtek Semiconductor) Task: {EE5D1DA7-DE3D-4A05-8D26-328BE8E12EF2} - System32\Tasks\F-Secure\F-Secure Hotfix => C:\Program Files (x86)\Charter Security Suite\fs_hotfix.exe [338264 2021-05-19] (F-Secure Corporation -> F-Secure Corporation) Task: {EE9CBDDD-BFB7-4337-80D5-37FBC249212F} - System32\Tasks\WinZip Update Notifier 2 => C:\Program Files\WinZip\WZUpdateNotifier.exe [2859928 2020-08-19] (Corel Corporation -> Corel Corporation) Task: {FD886EE9-2725-4C14-A5DA-B545C149A2E6} - System32\Tasks\WinZip Update Notifier 1 => C:\Program Files\WinZip\WZUpdateNotifier.exe [2859928 2020-08-19] (Corel Corporation -> Corel Corporation) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\..\Interfaces\{722fea56-df00-4f20-b5fb-db6178865da2}: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{b0c1890a-7af1-4dcd-a33e-fbc876f11881}: [DhcpNameServer] 192.168.1.1 Edge: ======= Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found] Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found] Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found] Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found] Edge Profile: C:\Users\jmcca\AppData\Local\Microsoft\Edge\User Data\Default [2021-11-22] Edge HKLM\...\Edge\Extension: [cpikpibllpjmpnchjajlibnmmomnnhnm] Edge HKLM-x32\...\Edge\Extension: [cpikpibllpjmpnchjajlibnmmomnnhnm] FireFox: ======== FF DefaultProfile: 7ejylcr7.default-1612849177010 FF ProfilePath: C:\Users\jmcca\AppData\Roaming\Mozilla\Firefox\Profiles\3pkl1gny.default-release [2021-11-22] FF Extension: (Browsing Protection by F-Secure) - C:\Users\jmcca\AppData\Roaming\Mozilla\Firefox\Profiles\3pkl1gny.default-release\Extensions\ols@f-secure.com.xpi [2021-11-22] [UpdateUrl:hxxps://download.sp.f-secure.com/online-safety/updates.json] FF ProfilePath: C:\Users\jmcca\AppData\Roaming\Mozilla\Firefox\Profiles\7ejylcr7.default-1612849177010 [2021-06-17] FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_25_0_0_171.dll [2017-06-10] (Adobe Systems Incorporated -> ) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_171.dll [2017-06-10] (Adobe Systems Incorporated -> ) FF Plugin-x32: @java.com/DTPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll [2017-03-21] (Oracle America, Inc. -> Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\plugin2\npjp2.dll [2017-03-21] (Oracle America, Inc. -> Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation) FF Plugin HKU\S-1-5-21-2892202112-2661542964-2761913289-1001: @citrixonline.com/appdetectorplugin -> C:\Users\jmcca\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2017-01-24] (Citrix Online -> Citrix Online) Chrome: ======= CHR Profile: C:\Users\jmcca\AppData\Local\Google\Chrome\User Data\Default [2021-11-22] CHR HomePage: Default -> hxxp://nsite/Pages/Nsite%20Home.aspx CHR Extension: (Slides) - C:\Users\jmcca\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-14] CHR Extension: (Docs) - C:\Users\jmcca\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-14] CHR Extension: (Google Drive) - C:\Users\jmcca\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2021-03-09] CHR Extension: (PDF Editor for Docs:Edit, Fill, Sign, Print) - C:\Users\jmcca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjboohgkgchdnfnjiaggdbkdmpieoagi [2018-09-23] CHR Extension: (Avast SafePrice | Comparison, deals, coupons) - C:\Users\jmcca\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2021-11-21] CHR Extension: (Sheets) - C:\Users\jmcca\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-14] CHR Extension: (Chrome Remote Desktop) - C:\Users\jmcca\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbchcmhmhahfdphkhkmpfmihenigjmpp [2019-08-03] CHR Extension: (Google Docs Offline) - C:\Users\jmcca\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2021-11-21] CHR Extension: (Avast Online Security & Privacy) - C:\Users\jmcca\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2021-11-21] CHR Extension: (Auto Refresh Plus | Page Monitor) - C:\Users\jmcca\AppData\Local\Google\Chrome\User Data\Default\Extensions\hgeljhfekpckiiplhkigfehkdpldcggm [2021-11-21] CHR Extension: (Chrome Remote Desktop) - C:\Users\jmcca\AppData\Local\Google\Chrome\User Data\Default\Extensions\inomeogfingihgjfjlpeplalcfajhgai [2020-03-24] CHR Extension: (Browsing Protection by F-Secure) - C:\Users\jmcca\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmjjnhpacphpjmnnlnccpfmhkcloaade [2021-11-21] CHR Extension: (Google Keep Chrome Extension) - C:\Users\jmcca\AppData\Local\Google\Chrome\User Data\Default\Extensions\lpcaedmchfhocbbapmcbpinfpgnhiddi [2021-11-21] CHR Extension: (Chrome Web Store Payments) - C:\Users\jmcca\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-02-06] CHR Extension: (Gmail) - C:\Users\jmcca\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2021-03-09] CHR Profile: C:\Users\jmcca\AppData\Local\Google\Chrome\User Data\Guest Profile [2017-02-15] CHR Profile: C:\Users\jmcca\AppData\Local\Google\Chrome\User Data\Profile 1 [2021-11-22] CHR Extension: (Slides) - C:\Users\jmcca\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2021-11-22] CHR Extension: (Docs) - C:\Users\jmcca\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2021-11-22] CHR Extension: (Google Drive) - C:\Users\jmcca\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2021-11-22] CHR Extension: (YouTube) - C:\Users\jmcca\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2021-11-22] CHR Extension: (Avast SafePrice | Comparison, deals, coupons) - C:\Users\jmcca\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2021-11-22] CHR Extension: (Sheets) - C:\Users\jmcca\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2021-11-22] CHR Extension: (Avast Online Security & Privacy) - C:\Users\jmcca\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gomekmidlodglbbmalcneegieacbdmki [2021-11-22] CHR Extension: (Browsing Protection by F-Secure) - C:\Users\jmcca\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\jmjjnhpacphpjmnnlnccpfmhkcloaade [2021-11-22] CHR Extension: (Gmail) - C:\Users\jmcca\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2021-11-22] CHR Profile: C:\Users\jmcca\AppData\Local\Google\Chrome\User Data\System Profile [2021-11-22] CHR HKLM\...\Chrome\Extension: [jmjjnhpacphpjmnnlnccpfmhkcloaade] CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] CHR HKLM-x32\...\Chrome\Extension: [jmjjnhpacphpjmnnlnccpfmhkcloaade] ==================== Services (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [99104 2021-03-16] (Apple Inc. -> Apple Inc.) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [8901968 2021-03-01] (BattlEye Innovations e.K. -> ) S3 chromoting; C:\Program Files (x86)\Google\Chrome Remote Desktop\96.0.4664.39\remoting_host.exe [72536 2021-11-04] (Google LLC -> Google LLC) S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [818304 2021-03-01] (EasyAntiCheat Oy -> Epic Games, Inc) R2 fshoster; C:\Program Files (x86)\Charter Security Suite\fshoster32.exe [238936 2021-05-19] (F-Secure Corporation -> F-Secure Corporation) R2 fsnethoster; C:\Program Files (x86)\Charter Security Suite\fshoster32.exe [238936 2021-05-19] (F-Secure Corporation -> F-Secure Corporation) R2 fsulhoster; C:\Program Files (x86)\Charter Security Suite\Ultralight\ulcore\1636551986\fshoster64.exe [605008 2021-11-11] (F-Secure Corporation -> F-Secure Corporation) R2 fsulnethoster; C:\Program Files (x86)\Charter Security Suite\Ultralight\ulcore\1636551986\fshoster64.exe [605008 2021-11-11] (F-Secure Corporation -> F-Secure Corporation) R2 fsulorsp; C:\Program Files (x86)\Charter Security Suite\Ultralight\ulcore\1636551986\fsorsp64.exe [99480 2021-11-11] (F-Secure Corporation -> F-Secure Corporation) R2 fsulprothoster; C:\Program Files (x86)\Charter Security Suite\Ultralight\ulcore\1636551986\fsulprothoster.exe [605008 2021-11-11] (F-Secure Corporation -> F-Secure Corporation) R2 ImControllerService; C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [83200 2021-11-07] (Lenovo -> Lenovo Group Ltd.) R2 IpOverUsbSvc; C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe [21184 2016-07-28] (Microsoft Corporation -> Microsoft Corporation) R2 LavasoftTcpService; C:\Program Files (x86)\Lavasoft\Web Companion\TcpService\2.3.4.7\LavasoftTcpService.exe [2751760 2017-01-22] (Lavasoft Limited -> Lavasoft Limited) [File not signed] S2 LPlatSvc; C:\WINDOWS\System32\LPlatSvc.exe [892760 2018-12-25] (Lenovo -> Lenovo.) S3 LSC.Services.SystemService; C:\Program Files\Lenovo\Lenovo Solution Center\App\LSC.Services.SystemService.exe [273232 2016-06-02] (LENOVO -> Lenovo) S2 MySQL80; C:\Program Files\MySQL\MySQL Server 8.0\bin\mysqld.exe [44932096 2018-04-08] () [File not signed] S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [6517736 2021-06-01] (Microsoft Windows Publisher -> Microsoft Corporation) S3 ShareItSvc; C:\Program Files (x86)\SHAREit\SHAREit\Shareit.Service.exe [35272 2016-05-04] (LENOVO -> SHAREit Technologies Co.Ltd) R2 TrueKey; C:\Program Files\McAfee\TrueKey\McAfee.TrueKey.Service.exe [352688 2018-11-27] (McAfee, Inc. -> McAfee, LLC.) R2 TrueKeyScheduler; C:\Program Files\McAfee\TrueKey\McTkSchedulerService.exe [352688 2018-11-27] (McAfee, Inc. -> McAfee, LLC.) R2 TrueKeyServiceHelper; C:\Program Files\McAfee\TrueKey\McAfee.TrueKey.ServiceHelper.exe [194168 2018-11-27] (McAfee, Inc. -> McAfee, LLC.) S3 VSStandardCollectorService150; C:\Program Files (x86)\Microsoft Visual Studio\Shared\Common\DiagnosticsHub.Collection.Service\StandardCollector.Service.exe [157480 2018-06-22] (Microsoft Corporation -> Microsoft Corporation) R2 WCAssistantService; C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe [25232 2017-01-22] (Lavasoft Software Canada -> ) S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\NisSrv.exe [3206472 2020-02-15] (Microsoft Windows Publisher -> Microsoft Corporation) S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\MsMpEng.exe [103376 2020-02-15] (Microsoft Windows Publisher -> Microsoft Corporation) ===================== Drivers (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S3 AppleKmdfFilter; C:\WINDOWS\System32\drivers\AppleKmdfFilter.sys [20640 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.) S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35560 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.) S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [231936 2020-02-13] (Microsoft Corporation) [File not signed] S3 EasyAntiCheatSys; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys [2201040 2021-03-12] (EasyAntiCheat Oy -> EasyAntiCheat Oy) R3 F-Secure Gatekeeper; C:\Program Files (x86)\Charter Security Suite\Ultralight\ulcore\1636551986\fsulgk.sys [367544 2021-11-11] (Microsoft Windows Hardware Compatibility Publisher -> F-Secure Corporation) R0 fsbts; C:\WINDOWS\System32\drivers\fsbts.sys [58752 2021-11-20] (F-Secure Corporation -> F-Secure Corporation) S0 fselms; C:\WINDOWS\System32\drivers\fselms.sys [15816 2021-06-02] (Microsoft Windows Early Launch Anti-malware Publisher -> F-Secure Corporation) R2 fsnif2; C:\Program Files (x86)\Charter Security Suite\Ultralight\nif2\1635159743\nif2s64.sys [159184 2021-11-11] (Microsoft Windows Hardware Compatibility Publisher -> F-Secure Corporation) R1 jnprns; C:\WINDOWS\system32\DRIVERS\jnprns.sys [507192 2014-11-25] (Juniper Networks, Inc. -> Juniper Networks) S3 jnprva; C:\WINDOWS\System32\drivers\jnprva.sys [30072 2014-11-25] (Juniper Networks, Inc. -> Juniper Networks, Inc.) R3 JnprVaMgr; C:\WINDOWS\System32\drivers\jnprvamgr.sys [45352 2014-11-25] (Juniper Networks, Inc. -> Juniper Networks, Inc.) S3 Netaapl; C:\WINDOWS\System32\drivers\netaapl64.sys [32352 2017-11-28] (Microsoft Windows Hardware Compatibility Publisher -> Apple Inc.) R0 PMDRVS; C:\WINDOWS\System32\drivers\pmdrvs.sys [44160 2018-12-25] (Lenovo -> Lenovo.) R3 rspWhySoSlow; C:\WINDOWS\System32\DRIVERS\rspWhy64.sys [28928 2016-12-17] (Daniel Terhell -> Resplendence Software Projects Sp.) S3 SPUVCbv; C:\WINDOWS\System32\Drivers\SPUVCbv64.sys [735744 2016-03-11] (Sunplus Innovation Technology Inc. -> Sunplus) S3 tap0901; C:\WINDOWS\System32\drivers\tap0901.sys [27136 2017-10-10] (OpenVPN Technologies, Inc. -> The OpenVPN Project) S3 tapprotonvpn; C:\WINDOWS\System32\drivers\tapprotonvpn.sys [49024 2020-12-30] (Microsoft Windows Hardware Compatibility Publisher -> The OpenVPN Project) S3 USBAAPL64; C:\WINDOWS\System32\Drivers\usbaapl64.sys [54784 2016-12-21] (Microsoft Windows Hardware Compatibility Publisher -> Apple, Inc.) S3 VBoxNetAdp; C:\WINDOWS\system32\DRIVERS\VBoxNetAdp6.sys [203328 2018-02-26] (Oracle Corporation -> Oracle Corporation) R0 vsock; C:\WINDOWS\system32\DRIVERS\vsock.sys [91712 2016-09-30] (VMware, Inc. -> VMware, Inc.) S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [45664 2020-02-15] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [355760 2020-02-15] (Microsoft Windows -> Microsoft Corporation) S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [54192 2020-02-15] (Microsoft Windows -> Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One month (created) (Whitelisted) ========= (If an entry is included in the fixlist, the file/folder will be moved.) 2021-11-22 03:30 - 2021-11-22 03:30 - 000000797 _____ C:\Users\Public\Desktop\Speccy.lnk 2021-11-22 03:30 - 2021-11-22 03:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Speccy 2021-11-22 03:17 - 2021-11-22 03:17 - 000000000 ____D C:\Users\jmcca\AppData\Local\Resplendence 2021-11-22 03:16 - 2021-11-22 03:17 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WhySoSlow 2021-11-22 03:16 - 2021-11-22 03:16 - 000000000 ____D C:\Program Files\WhySoSlow 2021-11-22 03:16 - 2016-12-17 20:59 - 000028928 _____ (Resplendence Software Projects Sp.) C:\WINDOWS\system32\Drivers\rspWhy64.sys 2021-11-22 03:13 - 2021-11-22 03:14 - 003622480 _____ (Resplendence Software Projects Sp. ) C:\Users\jmcca\Downloads\LatencyMon.exe 2021-11-22 03:13 - 2021-11-22 03:13 - 010692312 _____ (Resplendence Software Projects Sp. ) C:\Users\jmcca\Downloads\whocrashedSetup.exe 2021-11-22 03:13 - 2021-11-22 03:13 - 003124592 _____ (Resplendence Software Projects Sp. ) C:\Users\jmcca\Downloads\sanitySetup.exe 2021-11-22 03:13 - 2021-11-22 03:13 - 003040528 _____ (Resplendence Software Projects Sp. ) C:\Users\jmcca\Downloads\whySoSlowSetup.exe 2021-11-22 03:13 - 2021-11-22 03:13 - 003040528 _____ (Resplendence Software Projects Sp. ) C:\Users\jmcca\Downloads\WhySoSlowSetup (1).exe 2021-11-22 03:12 - 2021-11-22 03:13 - 008234296 _____ (Piriform Software Ltd) C:\Users\jmcca\Downloads\spsetup132.exe 2021-11-22 03:08 - 2021-11-22 03:24 - 000033172 _____ C:\Users\jmcca\Downloads\FRST.txt 2021-11-22 03:08 - 2021-11-22 03:08 - 000000000 ____D C:\Users\jmcca\Downloads\FRST-OlderVersion 2021-11-22 03:07 - 2021-11-22 03:07 - 002839416 _____ (Sysinternals - www.sysinternals.com) C:\Users\jmcca\Downloads\procexp.exe 2021-11-22 03:02 - 2021-11-22 03:18 - 000000000 ____D C:\FRST 2021-11-22 03:00 - 2021-11-22 03:08 - 002311680 _____ (Farbar) C:\Users\jmcca\Downloads\FRST64.exe 2021-11-22 02:43 - 2021-11-22 02:43 - 000002436 _____ C:\Users\jmcca\Desktop\JERIME - Chrome.lnk 2021-11-22 02:38 - 2021-11-22 02:39 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla 2021-11-22 02:29 - 2021-11-22 02:33 - 000000000 ____D C:\Users\jmcca\Desktop\RunTIme 2021-11-22 02:22 - 2021-11-22 02:33 - 000000000 ____D C:\Users\jmcca\AppData\Local\WinZip 2021-11-22 02:22 - 2021-11-22 02:22 - 000003678 _____ C:\WINDOWS\system32\Tasks\WinZip Update Notifier 2 2021-11-22 02:22 - 2021-11-22 02:22 - 000003676 _____ C:\WINDOWS\system32\Tasks\WinZip Update Notifier 3 2021-11-22 02:22 - 2021-11-22 02:22 - 000003676 _____ C:\WINDOWS\system32\Tasks\WinZip Update Notifier 1 2021-11-22 02:21 - 2021-11-22 02:21 - 000002047 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip.lnk 2021-11-22 02:21 - 2021-11-22 02:21 - 000001947 _____ C:\Users\Public\Desktop\WinZip.lnk 2021-11-22 02:21 - 2021-11-22 02:21 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip 2021-11-22 02:19 - 2021-11-22 02:20 - 000000000 ____D C:\Program Files\WinZip 2021-11-22 02:13 - 2021-11-22 02:13 - 000949680 _____ (WinZip Computing) C:\Users\jmcca\Downloads\winzip25-cnet.exe 2021-11-22 02:08 - 2021-11-22 02:38 - 000000965 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk 2021-11-22 02:08 - 2021-11-22 02:38 - 000000953 _____ C:\Users\Public\Desktop\Firefox.lnk 2021-11-22 02:08 - 2021-11-22 02:38 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2021-11-22 02:06 - 2021-11-22 02:06 - 000333872 _____ (Mozilla) C:\Users\jmcca\Downloads\Firefox Installer.exe 2021-11-22 02:04 - 2021-11-22 02:38 - 000000000 ____D C:\Program Files\Mozilla Firefox 2021-11-22 01:35 - 2021-11-22 01:35 - 000000000 ____D C:\WINDOWS\Panther 2021-11-21 09:56 - 2021-11-21 09:56 - 010141853 _____ C:\Users\jmcca\Downloads\IMG_1801.mp4 2021-11-21 09:52 - 2021-11-22 01:28 - 000000000 ___RD C:\Users\jmcca\iCloudDrive 2021-11-21 09:49 - 2021-11-21 09:49 - 000000000 ____D C:\ProgramData\Apple Inc 2021-11-11 14:17 - 2021-11-11 14:20 - 4028575744 _____ C:\Users\jmcca\Downloads\kali-linux-2021.3a-live-amd64.iso ==================== One month (modified) ================== (If an entry is included in the fixlist, the file/folder will be moved.) 2021-11-22 02:43 - 2016-11-24 08:38 - 000000000 ____D C:\Users\jmcca\AppData\LocalLow\Mozilla 2021-11-22 02:40 - 2021-02-09 00:39 - 000000000 ____D C:\ProgramData\Mozilla 2021-11-22 02:25 - 2016-10-21 19:22 - 000000000 ____D C:\ProgramData\WinZip 2021-11-22 02:08 - 2016-10-23 19:54 - 000000000 ____D C:\Users\jmcca\AppData\Local\CrashDumps 2021-11-22 01:42 - 2020-02-13 04:46 - 000939940 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2021-11-22 01:42 - 2019-03-18 23:50 - 000000000 ____D C:\WINDOWS\INF 2021-11-22 01:40 - 2019-03-18 23:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2021-11-22 01:38 - 2016-09-10 10:53 - 000000000 ____D C:\Program Files (x86)\Google 2021-11-22 01:35 - 2020-02-13 05:00 - 000003700 _____ C:\WINDOWS\system32\Tasks\Lenovo Power Management Driver PnP Task 2021-11-22 01:35 - 2020-02-13 05:00 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2021-11-22 01:35 - 2016-09-16 23:36 - 000000000 ____D C:\ProgramData\VMware 2021-11-22 01:35 - 2016-09-10 09:48 - 000000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat 2021-11-22 01:34 - 2019-03-18 23:37 - 000524288 _____ C:\WINDOWS\system32\config\BBI 2021-11-22 01:28 - 2018-07-27 10:06 - 000000000 ____D C:\Users\jmcca\AppData\Local\D3DSCache 2021-11-22 00:59 - 2020-02-13 04:26 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2021-11-21 18:15 - 2021-01-03 21:32 - 000002438 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk 2021-11-21 10:17 - 2019-03-18 23:52 - 000000000 ___HD C:\Program Files\WindowsApps 2021-11-21 10:17 - 2019-03-18 23:52 - 000000000 ____D C:\WINDOWS\AppReadiness 2021-11-21 09:52 - 2020-02-13 04:35 - 000000000 ____D C:\Users\jmcca 2021-11-21 09:52 - 2017-04-29 14:30 - 000000000 ____D C:\Users\jmcca\AppData\Local\Apple Computer 2021-11-21 09:49 - 2021-06-01 18:33 - 000000000 ____D C:\Users\jmcca\AppData\Local\Apple Inc 2021-11-21 09:49 - 2017-04-29 14:30 - 000000000 ____D C:\Users\jmcca\AppData\Roaming\Apple Computer 2021-11-21 09:46 - 2020-02-13 05:07 - 000000000 ____D C:\Users\jmcca\AppData\Local\PlaceholderTileLogoFolder 2021-11-21 09:46 - 2018-07-20 01:51 - 000000000 ____D C:\ProgramData\Packages 2021-11-21 09:46 - 2018-02-02 01:45 - 000000000 ____D C:\Users\jmcca\AppData\Local\Packages 2021-11-20 07:38 - 2016-10-30 17:51 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2021-11-20 07:38 - 2016-10-30 17:51 - 000002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2021-11-20 07:36 - 2021-01-03 21:31 - 000003480 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA 2021-11-20 07:36 - 2021-01-03 21:31 - 000003356 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore 2021-11-20 07:30 - 2021-01-09 03:48 - 000058752 _____ (F-Secure Corporation) C:\WINDOWS\system32\Drivers\fsbts.sys 2021-11-12 17:56 - 2019-03-18 23:37 - 000000000 ____D C:\WINDOWS\CbsTemp 2021-11-12 17:51 - 2020-12-30 21:28 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools 2021-11-12 17:50 - 2016-09-10 12:24 - 000000000 ____D C:\WINDOWS\system32\MRT 2021-11-12 17:42 - 2016-09-10 12:24 - 141529560 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2021-11-12 17:31 - 2020-03-25 02:13 - 000002383 _____ C:\Users\jmcca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2021-11-12 17:31 - 2020-02-13 05:00 - 000003388 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2892202112-2661542964-2761913289-1001 2021-11-11 14:14 - 2020-02-13 05:00 - 000003420 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA 2021-11-11 14:14 - 2020-02-13 05:00 - 000003296 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore 2021-11-11 14:12 - 2016-09-16 23:37 - 000000000 ____D C:\Users\jmcca\AppData\Roaming\VMware 2021-11-11 14:12 - 2016-09-16 23:37 - 000000000 ____D C:\Users\jmcca\AppData\Local\VMware 2021-11-07 22:36 - 2019-12-02 00:39 - 000429952 _____ (Lenovo Group Limited) C:\WINDOWS\system32\iMDriverHelper.dll 2021-11-07 22:36 - 2019-12-02 00:39 - 000109296 _____ (Lenovo Group Ltd.) C:\WINDOWS\system32\WudfUpdate_02000.dll 2021-11-07 22:36 - 2019-12-02 00:39 - 000063728 _____ (Lenovo Group Ltd.) C:\WINDOWS\system32\ImController.InfInstaller.exe 2021-11-07 22:36 - 2017-12-21 11:18 - 000109296 _____ (Lenovo Group Ltd.) C:\WINDOWS\system32\ImController.CoInstaller.dll ==================== Files in the root of some directories ======== 2018-10-23 03:02 - 2018-10-23 03:02 - 000000000 _____ () C:\Users\jmcca\.mongorc.js 2020-06-05 22:33 - 2020-06-05 22:33 - 024166400 _____ () C:\Program Files (x86)\GUT22DC.tmp 2020-06-08 05:37 - 2020-06-08 05:37 - 024166400 _____ () C:\Program Files (x86)\GUT2F66.tmp 2020-06-07 07:02 - 2020-06-07 07:02 - 024166400 _____ () C:\Program Files (x86)\GUT4E5C.tmp 2020-06-05 15:52 - 2020-06-05 15:52 - 024166400 _____ () C:\Program Files (x86)\GUT5CD1.tmp 2020-06-08 10:37 - 2020-06-08 10:37 - 024166400 _____ () C:\Program Files (x86)\GUT6C5B.tmp 2020-06-08 00:35 - 2020-06-08 00:35 - 024166400 _____ () C:\Program Files (x86)\GUT729C.tmp 2020-06-04 23:57 - 2020-06-04 23:57 - 024166400 _____ () C:\Program Files (x86)\GUT92F5.tmp 2020-06-06 22:24 - 2020-06-06 22:24 - 024166400 _____ () C:\Program Files (x86)\GUTC69B.tmp 2016-10-21 20:35 - 2017-06-10 21:27 - 000000096 _____ () C:\Users\jmcca\AppData\Roaming\Camdata.ini 2016-10-21 20:35 - 2017-06-10 21:27 - 000000408 _____ () C:\Users\jmcca\AppData\Roaming\CamLayout.ini 2016-10-21 20:35 - 2017-06-10 21:27 - 000000408 _____ () C:\Users\jmcca\AppData\Roaming\CamShapes.ini 2016-10-21 19:07 - 2017-06-10 21:27 - 000004536 _____ () C:\Users\jmcca\AppData\Roaming\CamStudio.cfg 2016-10-21 19:07 - 2017-06-10 21:27 - 000000096 _____ () C:\Users\jmcca\AppData\Roaming\version2.xml 2016-11-26 16:30 - 2016-12-20 20:24 - 000000600 _____ () C:\Users\jmcca\AppData\Local\PUTTY.RND ==================== SigCheck ============================ (There is no automatic fix for files that do not pass verification.) ==================== End of FRST.txt ========================