I did the next steps before I saw your message. I didn't receive an email that you'd replied so I decided to proceed. McAfee WebAdvisor wasn't listed in Chrome extensions, perhaps because I had already uninstalled it? Here is a screen shot of what I saw... https://www.dropbox....kstogo.png?dl=0
I was not aware of default user 100000.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 09-11-2021
Ran by 19192 (administrator) on LAPTOP-6BUIOIQ5 (LENOVO 81Y4) (14-11-2021 20:11:17)
Running from C:\Users\19192\Desktop
Loaded Profiles: 19192
Platform: Microsoft Windows 10 Home Version 20H2 19042.1110 (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Dolby Laboratories, Inc. -> Dolby Laboratories) C:\Windows\System32\DriverStore\FileRepository\DAX3_S~1.INF\DAX3API.exe
(Dolby Laboratories, Inc. -> Dolby Laboratories) C:\Windows\System32\DriverStore\FileRepository\dax3_swc_aposvc.inf_amd64_fe9531bca29258f3\DAX3API.exe
(Google LLC -> ) C:\Program Files\Google\Drive File Stream\52.0.6.0\crashpad_handler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.112\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.112\GoogleCrashHandler64.exe
(Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe <33>
(Google LLC -> Google, Inc.) C:\Program Files\Google\Drive File Stream\52.0.6.0\GoogleDriveFS.exe <7>
(Intel® Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_0b214be229a13e84\jhi_service.exe
(Intel® pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iaahcic.inf_amd64_c98d5e0dfc88ac2f\RstMwService.exe
(Intel® pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_0d8dab4470c5524b\igfxCUIService.exe
(Intel® pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_0d8dab4470c5524b\igfxEM.exe
(Intel® pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dptf_cpu.inf_amd64_82b77f8c4618e2d0\esif_uf.exe
(Intel® pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_a9a2dde7124f013f\OneApp.IGCC.WinService.exe
(Intel® pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_657d56a89b3d77d6\IntelCpHDCPSvc.exe
(Intel® pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_657d56a89b3d77d6\IntelCpHeciSvc.exe
(Lenovo -> Lenovo Group Ltd.) C:\Windows\Lenovo\ImController\PluginHost\Lenovo.Modern.ImController.PluginHost.Device.exe <3>
(Lenovo -> Lenovo Group Ltd.) C:\Windows\Lenovo\ImController\PluginHost\Lenovo.Modern.ImController.PluginHost.SettingsApp.exe <2>
(Lenovo -> Lenovo Group Ltd.) C:\Windows\Lenovo\ImController\PluginHost86\Lenovo.Modern.ImController.PluginHost.CompanionApp.exe
(Lenovo -> Lenovo Group Ltd.) C:\Windows\Lenovo\ImController\PluginHost86\Lenovo.Modern.ImController.PluginHost.Device.exe <3>
(Lenovo -> Lenovo Group Ltd.) C:\Windows\Lenovo\ImController\PluginHost86\Lenovo.Modern.ImController.PluginHost.SettingsApp.exe
(Lenovo -> Lenovo Group Ltd.) C:\Windows\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe
(Lenovo -> Lenovo Group Ltd.) C:\Windows\System32\drivers\Lenovo\udc\Service\UDClientService.exe
(Lenovo -> Lenovo(beijing) Limited) C:\Windows\System32\DriverStore\FileRepository\lenovofnandfunctionkeys.inf_amd64_b9fd1528982e300f\LenovoUtilityService.exe
(Logitech Inc -> Logitech) C:\ProgramData\Logishrd\LogiOptions\Software\Current\LogiOverlay.exe
(Logitech Inc -> Logitech, Inc.) C:\Program Files\Logitech\LogiOptions\LogiOptions.exe
(Logitech Inc -> Logitech, Inc.) C:\ProgramData\Logishrd\LogiOptions\Software\Current\laclient\laclient.exe
(Logitech Inc -> Logitech, Inc.) C:\ProgramData\Logishrd\LogiOptions\Software\Current\LogiOptionsMgr.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe <2>
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Office\root\Office16\SDXHelper.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_3.2109.6305.0_x64__8wekyb3d8bbwe\Cortana.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.14326.20544.0_x64__8wekyb3d8bbwe\HxOutlook.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.14326.20544.0_x64__8wekyb3d8bbwe\HxTsr.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_12107.1001.15.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\CredentialEnrollmentManager.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <3>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MusNotifyIcon.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.1220_none_7e21bc567c7ed16b\TiWorker.exe
(Microsoft Windows Hardware Compatibility Publisher -> Fortemedia) C:\Windows\System32\FMService64.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvlt.inf_amd64_5adc6075318430cf\Display.NvContainer\NVDisplay.Container.exe <2>
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\RtkAudUService64.exe <2>
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtkAudUService] => C:\Windows\System32\RtkAudUService64.exe [1085224 2020-06-03] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [3951024 2019-10-11] (Microsoft Windows Hardware Compatibility Publisher -> Logitech, Inc.)
HKLM\...\Run: [LogiOptions] => C:\Program Files\Logitech\LogiOptions\LogiOptions.exe [2109064 2019-11-27] (Logitech Inc -> Logitech, Inc.)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [339000 2021-10-26] (Apple Inc. -> Apple Inc.)
HKLM-x32\...\Run: [tvncontrol] => "C:\Program Files (x86)\ShowMyPCService\tvnserver.exe" -controlservice -slave (No File)
HKLM-x32\...\RunOnce: [GrpConv] => grpconv -o (No File)
HKU\S-1-5-19\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\52.0.6.0\GoogleDriveFS.exe [54107992 2021-10-18] (Google LLC -> Google, Inc.)
HKU\S-1-5-20\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\52.0.6.0\GoogleDriveFS.exe [54107992 2021-10-18] (Google LLC -> Google, Inc.)
HKU\S-1-5-21-4005300964-2302935580-1863167367-1001\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\52.0.6.0\GoogleDriveFS.exe [54107992 2021-10-18] (Google LLC -> Google, Inc.)
HKU\S-1-5-18\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\52.0.6.0\GoogleDriveFS.exe [54107992 2021-10-18] (Google LLC -> Google, Inc.)
HKLM\...\Windows x64\Print Processors\Canon MP830 Print Processor: C:\Windows\System32\spool\prtprocs\x64\CNMPD7Q.DLL [27136 2006-09-13] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\Canon BJ Language Monitor MP830: C:\Windows\system32\CNMLM7Q.DLL [234496 2006-09-13] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\Canon MP FAX Language Monitor MP830: C:\Windows\system32\CNCF2Lb.DLL [188928 2006-09-13] (Microsoft Windows Hardware Compatibility Publisher -> Canon Inc.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\95.0.4638.69\Installer\chrmstp.exe [2021-10-29] (Google LLC -> Google LLC)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\$McRebootA5E6DEAA56$.lnk [2021-11-13]
ShortcutTarget: $McRebootA5E6DEAA56$.lnk -> (No File)
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {01B10BEE-CEC8-4B67-9D40-0F1B616CB656} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [22654872 2021-11-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {045E4C8F-E096-4C5F-AA86-8441F3475142} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [138600 2021-11-12] (Microsoft Corporation -> Microsoft Corporation)
Task: {04D3FBF3-3CCD-4BB3-8A09-3F402FBAF841} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [907240 2020-06-23] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {0701D042-9791-4309-AC67-196ABEC83A9E} - System32\Tasks\Lenovo\ImController\Lenovo iM Controller Monitor => C:\Windows\system32\ImController.InfInstaller.exe [62440 2021-08-12] (Lenovo -> Lenovo Group Ltd.)
Task: {24F4E6C9-ACF2-48C9-969B-5A4D116A5E3D} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\fce8b35d-f625-4d1c-924d-c555a774b87c => C:\Windows\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [81896 2021-08-12] (Lenovo -> Lenovo Group Ltd.)
Task: {26F17EF2-56D4-4F1D-B730-834E8B375DC2} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1126888 2020-06-23] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {2F39C152-53BC-45FF-A1F7-088B7821CB81} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [874472 2020-05-07] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
Task: {368392EC-06F2-4824-99EF-186F5129F43F} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154440 2021-04-14] (Google LLC -> Google LLC)
Task: {54BFEC5B-779A-4060-88C1-F822AD15A989} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [647656 2020-06-23] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {73F46A70-9630-4059-B911-C5423206F6AD} - System32\Tasks\Lenovo\UDC\Lenovo UDC Monitor => C:\Windows\system32\drivers\lenovo\udc\data\InfBackup\UdcInfInstaller.exe [201584 2021-07-21] (Lenovo -> Lenovo Group Ltd.)
Task: {79185E2D-6052-4A95-9D94-E7BE95E4EE15} - System32\Tasks\Lenovo\BatteryGauge\BatteryGaugeMaintenance => C:\ProgramData\Lenovo\ImController\Plugins\LenovoBatteryGaugePackage\x64\BGHelper.exe [145480 2021-09-09] (Lenovo -> Lenovo Group Ltd.)
Task: {7B853215-31F4-482F-AD03-3F4AEB9487D3} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [138600 2021-11-12] (Microsoft Corporation -> Microsoft Corporation)
Task: {8478F36E-B1BA-4F6E-96E1-2C690989C3B0} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3292984 2020-06-25] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {8B0A2421-24B8-456A-9FF9-9B990F3C3E77} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [616832 2019-09-04] (Apple Inc. -> Apple Inc.)
Task: {8CCDCD9E-AE81-4FE0-8458-861B71078265} - System32\Tasks\Lenovo\ImController\Lenovo iM Controller Scheduled Maintenance => "%windir%\system32\sc.exe" START ImControllerService
Task: {9FD42CCE-79DC-4BD4-850F-D1327A7FC731} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\5162f36a-538c-448c-adde-aa0d542ef045 => C:\Windows\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [81896 2021-08-12] (Lenovo -> Lenovo Group Ltd.)
Task: {A6D33B72-85DF-45D9-9B95-CED37B7AF63F} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [874472 2020-05-07] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvBackend\NvBatteryBoostCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerBatteryBoostCheck.log
Task: {A9B1FB1E-2DE8-4794-B6A2-621E60ED6195} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1126888 2020-06-23] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {B2C9009F-58CB-4892-B36E-CA623FA3E35A} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\91917b8d-c346-4ebd-b347-373688af688b => C:\Windows\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [81896 2021-08-12] (Lenovo -> Lenovo Group Ltd.)
Task: {B66638EA-88E1-4C44-8194-313C7CD8EC7A} - System32\Tasks\KillHelpDeskService => C:\ProgramData\HelpDeskHost\RPCHDKillService.exe [14768 2021-08-27] (Pro Softnet Corporation -> )
Task: {D0FAFD93-351B-47CD-9DC5-09079FFB2273} - System32\Tasks\Lenovo\UDC\Lenovo UDC Idle Monitor => C:\windows\system32\drivers\Lenovo\udc\Service\UDCUserAgent.exe [443248 2021-07-21] (Lenovo -> Lenovo Group Ltd.)
Task: {DA622FAA-9F58-4D2A-BF99-030204ACD04C} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\4698dca5-e53b-4db6-a01f-2fcfe4af3754 => C:\Windows\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [81896 2021-08-12] (Lenovo -> Lenovo Group Ltd.)
Task: {E4A2CA68-F06D-4D06-94BA-574DF78F1F7D} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [907240 2020-06-23] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {E56B4006-2F6A-4E46-8852-CEA43C985289} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [22654872 2021-11-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {ED69C074-9E68-44E2-AD91-5DBD2515E764} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154440 2021-04-14] (Google LLC -> Google LLC)
Task: {F15C1A7A-F903-4445-90BE-34AC99FBA265} - System32\Tasks\Lenovo\ImController\Plugins\LenovoSystemUpdatePlugin_WeeklyTask => %windir%\System32\reg.exe add hklm\SOFTWARE\Lenovo\SystemUpdatePlugin\scheduler /v start /t reg_dword /d 1 /f /reg:32
Task: {F695EF1F-3E13-4EC5-95D7-21AA49D58E03} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1126888 2020-06-23] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {FD00D536-B53A-4FBC-852A-5E01E1347A32} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\8cca9d46-7384-4f46-8e72-8b54f6bbc9f4 => C:\Windows\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [81896 2021-08-12] (Lenovo -> Lenovo Group Ltd.)
Task: {FFF2C6B8-88BD-4DF4-9244-212E552EB500} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1126888 2020-06-23] (NVIDIA Corporation -> NVIDIA Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Winsock: Catalog5 08 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [122128 2015-08-12] (Apple Inc. -> Apple Inc.)
Winsock: Catalog5-x64 08 C:\Program Files\Bonjour\mdnsNSP.dll [133392 2015-08-12] (Apple Inc. -> Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{8e97fbc1-15cf-494a-82de-a590dbc646ae}: [DhcpNameServer] 152.206.1.3
Tcpip\..\Interfaces\{dde9b86d-16b9-4b9a-8585-74a0260b6f50}: [DhcpNameServer] 192.168.0.1
Edge:
=======
Edge Profile: C:\Users\19192\AppData\Local\Microsoft\Edge\User Data\Default [2021-11-10]
Edge HKLM-x32\...\Edge\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
FireFox:
========
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2021-10-29] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2021-10-29] (Microsoft Corporation -> Microsoft Corporation)
Chrome:
=======
CHR Profile: C:\Users\19192\AppData\Local\Google\Chrome\User Data\Default [2021-11-14]
CHR DownloadDir: C:\Users\19192\Desktop
CHR Notifications: Default -> hxxps://19216801.me
CHR DefaultSearchURL: Default -> hxxps://search.yahoo.com/search?fr=mcafee&type=E210US714G0&p={searchTerms}
CHR DefaultSearchKeyword: Default -> mcafee
CHR DefaultSuggestURL: Default -> hxxps://us.search.yahoo.com/sugg/gossip/gossip-us-partner?output=fxjson&appid=mca&source=yahoo_mcafee_searchassist&command={searchTerms}
CHR Session Restore: Default -> is enabled.
CHR Extension: (Slides) - C:\Users\19192\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2021-04-14]
CHR Extension: (Docs) - C:\Users\19192\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2021-04-14]
CHR Extension: (Google Drive) - C:\Users\19192\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2021-04-14]
CHR Extension: (Bitmoji) - C:\Users\19192\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfgdeiadkckfbkeigkoncpdieiiefpig [2021-11-09]
CHR Extension: (YouTube) - C:\Users\19192\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2021-04-14]
CHR Extension: (Sheets) - C:\Users\19192\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2021-04-14]
CHR Extension: (Google Docs Offline) - C:\Users\19192\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2021-11-09]
CHR Extension: (Application Launcher For Drive (by Google)) - C:\Users\19192\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2021-11-13]
CHR Extension: (Chrome Web Store Payments) - C:\Users\19192\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-04-14]
CHR Extension: (Gmail) - C:\Users\19192\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2021-04-14]
CHR HKU\S-1-5-21-4005300964-2302935580-1863167367-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh]
CHR HKLM-x32\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [99104 2021-08-20] (Apple Inc. -> Apple Inc.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [12034464 2021-11-04] (Microsoft Corporation -> Microsoft Corporation)
R2 DolbyDAXAPI; C:\Windows\System32\DriverStore\FileRepository\dax3_swc_aposvc.inf_amd64_fe9531bca29258f3\DAX3API.exe [1928648 2020-05-19] (Dolby Laboratories, Inc. -> Dolby Laboratories)
R2 FMAPOService; C:\Windows\System32\FMService64.exe [390400 2020-05-21] (Microsoft Windows Hardware Compatibility Publisher -> Fortemedia)
R2 ImControllerService; C:\Windows\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [81896 2021-08-12] (Lenovo -> Lenovo Group Ltd.)
R2 LenovoFnAndFunctionKeys; C:\Windows\System32\DriverStore\FileRepository\lenovofnandfunctionkeys.inf_amd64_b9fd1528982e300f\LenovoUtilityService.exe [539128 2021-08-26] (Lenovo -> Lenovo(beijing) Limited)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [7848632 2021-11-09] (Malwarebytes Inc -> Malwarebytes)
R2 UDCService; C:\Windows\System32\drivers\Lenovo\udc\Service\UDClientService.exe [116592 2021-07-21] (Lenovo -> Lenovo Group Ltd.)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2110.6-0\NisSrv.exe [2872024 2021-11-02] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2110.6-0\MsMpEng.exe [128376 2021-11-02] (Microsoft Windows Publisher -> Microsoft Corporation)
S2 GamingServices; C:\Program Files\WindowsApps\Microsoft.GamingServices_2.57.20005.0_x64__8wekyb3d8bbwe\GamingServices.exe [X]
S2 GamingServicesNet; C:\Program Files\WindowsApps\Microsoft.GamingServices_2.57.20005.0_x64__8wekyb3d8bbwe\GamingServicesNet.exe [X]
S2 HelpDeskService; C:\Users\19192\AppData\Local\Temp\HelpDesk\u8\HelpDesk\RPCHelpDeskServiceUAC.exe [X] <==== ATTENTION
R2 NVDisplay.ContainerLocalSystem; C:\Windows\System32\DriverStore\FileRepository\nvlt.inf_amd64_5adc6075318430cf\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\Windows\System32\DriverStore\FileRepository\nvlt.inf_amd64_5adc6075318430cf\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [160176 2021-09-05] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S3 FBNetFilter; C:\Windows\System32\drivers\FBNetFlt.sys [52688 2020-05-21] (LENOVO (UNITED STATES) INC. -> Lenovo Group Ltd.)
R1 googledrivefs3525; C:\Windows\System32\DRIVERS\googledrivefs3525.sys [389640 2021-10-18] (Google LLC -> Google, Inc.)
R2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [210352 2021-11-09] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S0 MbamElam; C:\Windows\System32\DRIVERS\MbamElam.sys [19912 2021-04-22] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMFarflt; C:\Windows\System32\DRIVERS\farflt.sys [193448 2021-11-09] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMProtection; C:\Windows\system32\DRIVERS\mbam.sys [69040 2021-11-09] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [248992 2021-10-03] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMWebProtection; C:\Windows\system32\DRIVERS\mwac.sys [149424 2021-11-09] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S3 WdBoot; C:\Windows\system32\drivers\wd\WdBoot.sys [48520 2021-11-02] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\wd\WdFilter.sys [435424 2021-11-02] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [86240 2021-11-02] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-11-14 20:11 - 2021-11-14 20:11 - 000024900 _____ C:\Users\19192\Desktop\FRST.txt
2021-11-14 19:53 - 2021-11-14 19:53 - 000000000 ___HD C:\$WinREAgent
2021-11-13 13:36 - 2021-11-13 13:36 - 000002068 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive.lnk
2021-11-13 13:36 - 2021-10-18 11:17 - 000389640 _____ (Google, Inc.) C:\Windows\system32\Drivers\googledrivefs3525.sys
2021-11-13 13:35 - 2021-11-13 13:36 - 261628248 _____ (Google, Inc.) C:\Users\19192\Desktop\GoogleDriveSetup.exe
2021-11-13 13:19 - 2021-11-13 13:19 - 000000000 ___HD C:\OneDriveTemp
2021-11-13 13:19 - 2021-04-03 14:53 - 000000172 ____R C:\Users\19192\OneDrive\Documents\Caroline's Notebook.url
2021-11-13 13:14 - 2021-11-13 13:14 - 000000000 ____D C:\Users\19192\AppData\Local\OneDrive
2021-11-10 15:07 - 2021-11-14 20:11 - 000000000 ____D C:\FRST
2021-11-10 12:14 - 2021-11-13 13:49 - 000000000 ____D C:\Users\19192\AppData\Local\CrashDumps
2021-11-09 22:49 - 2021-11-09 22:49 - 000210352 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys
2021-11-09 22:49 - 2021-11-09 22:49 - 000193448 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
2021-11-09 22:49 - 2021-11-09 22:49 - 000149424 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2021-11-09 22:49 - 2021-11-09 22:49 - 000069040 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2021-11-09 22:48 - 2021-11-09 22:48 - 002101944 _____ (Malwarebytes) C:\Users\19192\Downloads\MBSetup-119967.119967-consumer.exe
2021-11-09 17:52 - 2021-11-09 17:52 - 000000000 ____D C:\Users\19192\AppData\Local\AAR
2021-11-09 17:48 - 2021-11-09 17:48 - 000000000 ____D C:\Users\defaultuser100001.LAPTOP-6BUIOIQ5.001\AppData\Local\Lenovo
2021-11-09 17:46 - 2021-11-09 17:48 - 000000000 ____D C:\Users\defaultuser100001.LAPTOP-6BUIOIQ5.001\AppData\Local\Packages
2021-11-09 17:46 - 2021-11-09 17:47 - 000000000 ____D C:\Users\defaultuser100001.LAPTOP-6BUIOIQ5.001\AppData\Local\Intel
2021-11-09 17:46 - 2021-11-09 17:46 - 000000020 ___SH C:\Users\defaultuser100001.LAPTOP-6BUIOIQ5.001\ntuser.ini
2021-11-09 17:46 - 2021-11-09 17:46 - 000000000 ____D C:\Users\defaultuser100001.LAPTOP-6BUIOIQ5.001\AppData\LocalLow\Intel
2021-11-09 17:46 - 2021-11-09 17:46 - 000000000 ____D C:\Users\defaultuser100001.LAPTOP-6BUIOIQ5.001\AppData\Local\VirtualStore
2021-11-09 17:46 - 2021-11-09 17:46 - 000000000 ____D C:\Users\defaultuser100001.LAPTOP-6BUIOIQ5.001\AppData\Local\NVIDIA Corporation
2021-11-09 17:46 - 2021-11-09 17:46 - 000000000 ____D C:\Users\defaultuser100001.LAPTOP-6BUIOIQ5.001\AppData\Local\ConnectedDevicesPlatform
2021-11-09 17:46 - 2021-11-09 17:46 - 000000000 ____D C:\Users\defaultuser100001.LAPTOP-6BUIOIQ5.001
2021-11-09 17:46 - 2019-12-07 01:10 - 000001105 _____ C:\Users\defaultuser100001.LAPTOP-6BUIOIQ5.001\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2021-11-09 17:38 - 2021-11-09 17:38 - 000000000 ____D C:\Users\19192\AppData\Local\GoToAssist Remote Support Customer
2021-11-09 17:38 - 2021-11-09 17:38 - 000000000 ____D C:\Users\19192\AppData\Local\GoTo Opener
2021-11-09 17:21 - 2021-11-09 17:21 - 000000128 _____ C:\Users\19192\AppData\Local\PUTTY.RND
2021-11-09 17:17 - 2021-11-09 17:17 - 002745776 _____ C:\Users\19192\Downloads\ShowMyPC3606.exe
2021-11-09 16:48 - 2021-11-09 17:56 - 000000000 ____D C:\ProgramData\HelpDeskHost
2021-11-09 16:48 - 2021-11-09 16:48 - 000368560 _____ () C:\Users\19192\Downloads\HelpDesk_495711758.exe
2021-11-09 16:48 - 2021-11-09 16:48 - 000003124 _____ C:\Windows\system32\Tasks\KillHelpDeskService
2021-11-09 16:48 - 2021-11-09 16:48 - 000000000 ____D C:\ProgramData\RemotePC
2021-11-09 16:48 - 2021-11-09 16:48 - 000000000 ____D C:\Program Files (x86)\RemotePC
2021-11-08 14:21 - 2021-11-08 14:21 - 000000000 ___HD C:\Windows\system32\CanonIJ Uninstaller Information
2021-11-08 14:21 - 2021-11-08 14:21 - 000000000 ___HD C:\ProgramData\CanonBJ
2021-11-08 14:21 - 2021-11-08 14:21 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MP830
2021-11-08 14:21 - 2006-10-03 09:37 - 000003072 _____ C:\Windows\system32\CNCFLbNL.DLL
2021-11-08 14:21 - 2006-09-21 11:49 - 000003584 _____ (Canon Inc.) C:\Windows\system32\CNCFLbPT.DLL
2021-11-08 14:21 - 2006-09-21 11:49 - 000003584 _____ (Canon Inc.) C:\Windows\system32\CNCFLbES.DLL
2021-11-08 14:21 - 2006-09-21 11:49 - 000003584 _____ (Canon Inc.) C:\Windows\system32\CNCFLbDE.DLL
2021-11-08 14:21 - 2006-09-21 11:49 - 000003072 _____ (Canon Inc.) C:\Windows\system32\CNCFLbRU.DLL
2021-11-08 14:21 - 2006-09-21 11:49 - 000003072 _____ (Canon Inc.) C:\Windows\system32\CNCFLbPL.DLL
2021-11-08 14:21 - 2006-09-21 11:49 - 000003072 _____ (Canon Inc.) C:\Windows\system32\CNCFLbIT.DLL
2021-11-08 14:21 - 2006-09-21 11:49 - 000003072 _____ (Canon Inc.) C:\Windows\system32\CNCFLbFR.DLL
2021-11-08 14:21 - 2006-09-20 15:15 - 000003072 _____ (Canon Inc.) C:\Windows\system32\CNCFLbCN.DLL
2021-11-08 14:21 - 2006-09-20 11:37 - 000003072 _____ (Canon Inc.) C:\Windows\system32\CNCFLbKR.DLL
2021-11-08 14:21 - 2006-09-20 09:18 - 000003072 _____ (Canon Inc.) C:\Windows\system32\CNCFLbTW.DLL
2021-11-08 14:21 - 2006-09-13 11:32 - 000188928 _____ (Canon Inc.) C:\Windows\system32\CNCF2Lb.DLL
2021-11-08 14:21 - 2006-09-13 11:31 - 000093696 _____ (Canon Inc.) C:\Windows\system32\CNCFMSb.EXE
2021-11-08 14:21 - 2006-09-13 11:30 - 000003072 _____ (Canon Inc.) C:\Windows\system32\CNCFLbUS.DLL
2021-11-08 14:21 - 2006-09-13 11:28 - 000270336 _____ (CANON INC.) C:\Windows\system32\CNCC830.DLL
2021-11-08 14:21 - 2006-09-13 11:28 - 000049664 _____ (CANON INC.) C:\Windows\system32\CNCI830.DLL
2021-11-08 14:21 - 2006-09-13 05:00 - 000234496 _____ (CANON INC.) C:\Windows\system32\CNMLM7Q.DLL
2021-11-08 14:21 - 2006-06-29 14:30 - 000017408 _____ (Canon Inc.) C:\Windows\system32\cncisco.x64.dll
2021-11-08 14:21 - 2005-11-07 09:58 - 000122368 _____ (Canon Inc.) C:\Windows\system32\CNCL830.DLL
2021-11-08 14:20 - 2021-11-08 14:20 - 000000000 ___HD C:\Program Files\CanonBJ
2021-11-08 14:17 - 2021-11-08 14:17 - 016555152 _____ C:\Users\19192\Downloads\md64-win-mp830-1_12-ea12.exe
2021-11-08 14:09 - 2021-11-08 14:09 - 000266205 _____ C:\Users\19192\Downloads\Ming's lychee martini.pdf
2021-11-08 14:09 - 2021-11-08 14:09 - 000000000 ____D C:\Users\19192\AppData\LocalLow\Temp
2021-11-08 14:06 - 2021-11-08 14:06 - 000000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2021-11-08 13:22 - 2021-11-08 13:22 - 000138905 _____ C:\Users\19192\Downloads\2020_TaxReturn.pdf
2021-11-03 17:03 - 2021-11-03 17:03 - 000000000 ____D C:\Users\19192\AppData\Local\ElevatedDiagnostics
2021-11-03 16:47 - 2021-11-03 16:47 - 000001827 _____ C:\Users\Public\Desktop\iTunes.lnk
2021-11-03 16:47 - 2021-11-03 16:47 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2021-11-03 16:47 - 2021-11-03 16:47 - 000000000 ____D C:\Program Files\iTunes
2021-11-02 20:10 - 2021-11-02 20:10 - 000001157 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Health Check.lnk
2021-11-02 20:10 - 2021-11-02 20:10 - 000000000 ____D C:\Program Files\PCHealthCheck
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-11-14 19:54 - 2021-04-14 10:43 - 000004168 _____ C:\Windows\system32\Tasks\User_Feed_Synchronization-{008B1671-6ABD-46AE-ABF7-73DFDE00F4AA}
2021-11-14 19:54 - 2021-04-14 04:56 - 000000000 ____D C:\Program Files (x86)\Google
2021-11-14 19:54 - 2021-04-14 04:49 - 000000000 ____D C:\Users\19192\AppData\Local\Packages
2021-11-14 19:54 - 2021-03-10 07:02 - 000000000 ____D C:\ProgramData\NVIDIA
2021-11-14 19:54 - 2019-12-07 01:14 - 000000000 ____D C:\Windows\AppReadiness
2021-11-14 19:53 - 2019-12-07 01:14 - 000000000 ___HD C:\Program Files\WindowsApps
2021-11-14 19:52 - 2021-03-10 06:48 - 000002449 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2021-11-14 19:51 - 2020-05-06 10:33 - 000000000 ____D C:\Windows\system32\SleepStudy
2021-11-14 19:51 - 2019-12-07 01:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2021-11-13 13:49 - 2021-04-14 04:50 - 000000000 ___RD C:\Users\19192\OneDrive
2021-11-13 13:36 - 2021-04-14 04:56 - 000000000 ____D C:\Users\19192\AppData\Local\Google
2021-11-13 13:36 - 2021-04-14 04:56 - 000000000 ____D C:\Program Files\Google
2021-11-13 13:19 - 2021-04-14 04:26 - 000000000 ____D C:\Users\19192
2021-11-13 13:04 - 2021-04-14 04:50 - 000000000 ____D C:\Users\19192\AppData\Local\Lenovo
2021-11-13 13:04 - 2021-03-10 07:03 - 000000000 ____D C:\Program Files (x86)\Lenovo
2021-11-13 13:04 - 2021-03-10 06:51 - 000000000 ____D C:\Windows\system32\Tasks\Lenovo
2021-11-13 13:04 - 2021-03-10 06:51 - 000000000 ____D C:\ProgramData\Lenovo
2021-11-13 13:04 - 2019-12-07 01:14 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2021-11-12 17:31 - 2019-12-07 01:03 - 000000000 ____D C:\Windows\CbsTemp
2021-11-12 17:30 - 2021-04-19 07:35 - 000000000 ____D C:\Windows\system32\MRT
2021-11-12 17:28 - 2021-03-10 06:52 - 000000000 ____D C:\Program Files\Microsoft Office
2021-11-12 17:21 - 2021-04-19 07:35 - 141529560 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2021-11-10 15:10 - 2019-12-07 01:13 - 000000000 ____D C:\Windows\INF
2021-11-09 22:49 - 2021-04-22 13:36 - 000002044 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2021-11-09 22:49 - 2021-04-22 13:36 - 000002032 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2021-11-09 22:48 - 2021-04-22 13:36 - 000000000 ____D C:\ProgramData\Malwarebytes
2021-11-09 22:48 - 2021-04-22 13:35 - 000000000 ____D C:\Program Files\Malwarebytes
2021-11-09 22:46 - 2019-12-07 01:14 - 000000000 ____D C:\Windows\system32\NDF
2021-11-09 17:55 - 2021-04-22 13:29 - 000000000 ____D C:\Users\19192\AppData\Local\D3DSCache
2021-11-09 17:52 - 2021-07-25 12:34 - 000696106 _____ C:\Windows\system32\perfh00E.dat
2021-11-09 17:52 - 2021-07-25 12:34 - 000155082 _____ C:\Windows\system32\perfc00E.dat
2021-11-09 17:52 - 2020-05-06 10:41 - 001634274 _____ C:\Windows\system32\PerfStringBackup.INI
2021-11-09 17:48 - 2021-04-14 04:49 - 000000000 __SHD C:\Users\19192\IntelGraphicsProfiles
2021-11-09 17:46 - 2021-03-10 06:59 - 000000000 ___HD C:\Intel
2021-11-09 17:46 - 2020-05-06 10:33 - 000439016 _____ C:\Windows\system32\FNTCACHE.DAT
2021-11-09 17:46 - 2020-05-06 10:33 - 000008192 ___SH C:\DumpStack.log.tmp
2021-11-09 17:46 - 2020-05-06 10:33 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2021-11-09 17:46 - 2019-12-07 01:14 - 000000000 ____D C:\Windows\ServiceState
2021-11-09 17:45 - 2019-12-07 01:14 - 000000000 ____D C:\Windows\SysWOW64\setup
2021-11-09 17:45 - 2019-12-07 01:14 - 000000000 ____D C:\Windows\SysWOW64\oobe
2021-11-09 17:45 - 2019-12-07 01:14 - 000000000 ____D C:\Windows\SysWOW64\Dism
2021-11-09 17:45 - 2019-12-07 01:14 - 000000000 ____D C:\Windows\SystemResources
2021-11-09 17:45 - 2019-12-07 01:14 - 000000000 ____D C:\Windows\system32\WinBioPlugIns
2021-11-09 17:45 - 2019-12-07 01:14 - 000000000 ____D C:\Windows\system32\setup
2021-11-09 17:45 - 2019-12-07 01:14 - 000000000 ____D C:\Windows\system32\oobe
2021-11-09 17:45 - 2019-12-07 01:14 - 000000000 ____D C:\Windows\system32\Dism
2021-11-09 17:45 - 2019-12-07 01:14 - 000000000 ____D C:\Windows\Provisioning
2021-11-09 17:45 - 2019-12-07 01:14 - 000000000 ____D C:\Windows\bcastdvr
2021-11-09 17:45 - 2019-12-07 01:14 - 000000000 ____D C:\Program Files\Common Files\System
2021-11-09 17:45 - 2019-12-07 01:03 - 001572864 _____ C:\Windows\system32\config\BBI
2021-11-08 14:21 - 2019-12-07 01:14 - 000000000 __RSD C:\Windows\Media
2021-11-07 14:04 - 2021-04-14 04:50 - 000003380 _____ C:\Windows\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-4005300964-2302935580-1863167367-1001
2021-11-07 14:04 - 2021-04-14 04:26 - 000002394 _____ C:\Users\19192\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2021-11-02 21:03 - 2021-04-14 04:49 - 000004321 _____ C:\Windows\system32\InstallUtil.InstallLog
2021-11-02 20:10 - 2020-05-06 10:33 - 000000000 ____D C:\Windows\system32\Drivers\wd
2021-10-29 16:20 - 2021-04-14 04:56 - 000002258 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2021-10-29 16:20 - 2021-04-14 04:56 - 000002217 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2021-10-19 14:44 - 2021-03-10 06:48 - 000003480 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2021-10-19 14:44 - 2021-03-10 06:48 - 000003356 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
==================== Files in the root of some directories ========
2021-11-09 17:21 - 2021-11-09 17:21 - 000000128 _____ () C:\Users\19192\AppData\Local\PUTTY.RND
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 09-11-2021
Ran by 19192 (14-11-2021 20:11:55)
Running from C:\Users\19192\Desktop
Microsoft Windows 10 Home Version 20H2 19042.1110 (X64) (2021-04-14 12:23:10)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
(If an entry is included in the fixlist, it will be removed.)
19192 (S-1-5-21-4005300964-2302935580-1863167367-1001 - Administrator - Enabled) => C:\Users\19192
Administrator (S-1-5-21-4005300964-2302935580-1863167367-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-4005300964-2302935580-1863167367-503 - Limited - Disabled)
defaultuser100000 (S-1-5-21-4005300964-2302935580-1863167367-1018 - Limited - Enabled)
Guest (S-1-5-21-4005300964-2302935580-1863167367-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-4005300964-2302935580-1863167367-504 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Apple Mobile Device Support (HKLM\...\{527DD209-8A66-482F-8779-C7B3BACCA8F1}) (Version: 15.0.0.16 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{A3985C05-7386-411F-A4BF-32A73F37EB44}) (Version: 2.6.3.1 - Apple Inc.)
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
Canon MP830 MP Drivers (HKLM\...\{0D25F7CC-B99C-44ee-9945-B14532B2BB7B}) (Version: - Canon Inc.)
DriverUpdate (HKLM\...\{70A3DB76-E1F1-4D1C-B791-824F1C63238A}) (Version: 5.8.19 - Slimware Utilities Holdings, Inc.) Hidden <==== ATTENTION
DriverUpdate (HKLM\...\DriverUpdate) (Version: 5.8.19 - Slimware Utilities Holdings, Inc.) <==== ATTENTION
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 95.0.4638.69 - Google LLC)
Google Drive (HKLM\...\{6BBAE539-2232-434A-A4E5-9A33560C6283}) (Version: 52.0.6.0 - Google LLC)
GoTo Opener (HKLM-x32\...\{C0F33C38-345C-4C02-B161-11389350C2A5}) (Version: 1.0.533 - LogMeIn, Inc.)
Intel® Chipset Device Software (HKLM-x32\...\{afad3740-3061-4b48-a9ab-6f1435cb3dd6}) (Version: 10.1.18383.8213 - Intel® Corporation)
iTunes (HKLM\...\{0B3CC856-3A62-443A-B6CE-DED2D4495D56}) (Version: 12.12.2.2 - Apple Inc.)
Logitech Options (HKLM\...\LogiOptions) (Version: 8.10.84 - Logitech)
Malwarebytes version 4.4.10.144 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.4.10.144 - Malwarebytes)
Microsoft 365 - en-us (HKLM\...\O365HomePremRetail - en-us) (Version: 16.0.14527.20276 - Microsoft Corporation)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 95.0.1020.53 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 95.0.1020.53 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-4005300964-2302935580-1863167367-1001\...\OneDriveSetup.exe) (Version: 21.205.1003.0005 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{29B15818-E79F-4AB0-8938-9410C807AD76}) (Version: 2.84.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.26.28720 (HKLM-x32\...\{7d607fb4-7e28-4c7a-a92f-3fcdaf555faf}) (Version: 14.26.28720.3 - Microsoft Corporation)
NVIDIA GeForce Experience 3.20.4.14 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.20.4.14 - NVIDIA Corporation)
NVIDIA Graphics Driver 462.30 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 462.30 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.20.0221 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.20.0221 - NVIDIA Corporation)
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.14527.20276 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.14527.20276 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0409-1000-0000000FF1CE}) (Version: 16.0.14131.20278 - Microsoft Corporation) Hidden
Windows PC Health Check (HKLM\...\{B1E7D0FD-7CFE-4E0C-A5DA-0F676499DB91}) (Version: 3.2.2110.14001 - Microsoft Corporation)
Packages:
=========
AV1 Video Extension -> C:\Program Files\WindowsApps\Microsoft.AV1VideoExtension_1.1.41601.0_x64__8wekyb3d8bbwe [2021-07-24] (Microsoft Corporation)
Dolby Audio -> C:\Program Files\WindowsApps\DolbyLaboratories.DolbyAudio_3.20602.609.0_x64__rz1tebttyb220 [2021-03-10] (Dolby Laboratories)
Intel® Graphics Command Center -> C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.3370.0_x64__8j3eq9eme6ctt [2021-10-05] (INTEL CORP) [Startup Task]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.10.10270.0_x64__8wekyb3d8bbwe [2021-11-02] (Microsoft Studios) [MS Ad]
MPEG-2 Video Extension -> C:\Program Files\WindowsApps\Microsoft.MPEG2VideoExtension_1.0.42152.0_x64__8wekyb3d8bbwe [2021-09-10] (Microsoft Corporation)
NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.961.0_x64__56jybvy8sckqj [2021-06-11] (NVIDIA Corp.)
Photos Media Engine Add-on -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2021-07-25] (Microsoft Corporation)
Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.14.221.0_x64__dt26b99r8h8gj [2021-03-10] (Realtek Semiconductor Corp)
Spotify Music -> C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.172.439.0_x86__zpdnekdrzrea0 [2021-11-14] (Spotify AB) [Startup Task]
==================== Custom CLSID (Whitelisted): ==============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-4005300964-2302935580-1863167367-1001_Classes\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6} -> [OneDrive - Personal] => {a52bba46-e9e1-435f-b3d9-28daa648c0f6}
ShellIconOverlayIdentifiers: [ GoogleDriveCloudOverlayIconHandler] -> {A8E52322-8734-481D-A7E2-27B309EF8D56} => C:\Program Files\Google\Drive File Stream\52.0.6.0\drivefsext.dll [2021-10-18] (Google LLC -> Google, Inc.)
ShellIconOverlayIdentifiers: [ GoogleDriveMirrorBlacklistedOverlayIconHandler] -> {51EF1569-67EE-4AD6-9646-E726C3FFC8A2} => C:\Program Files\Google\Drive File Stream\52.0.6.0\drivefsext.dll [2021-10-18] (Google LLC -> Google, Inc.)
ShellIconOverlayIdentifiers: [ GoogleDrivePinnedOverlayIconHandler] -> {CFE8B367-77A7-41D7-9C90-75D16D7DC6B6} => C:\Program Files\Google\Drive File Stream\52.0.6.0\drivefsext.dll [2021-10-18] (Google LLC -> Google, Inc.)
ShellIconOverlayIdentifiers: [ GoogleDriveProgressOverlayIconHandler] -> {C973DA94-CBDF-4E77-81D1-E5B794FBD146} => C:\Program Files\Google\Drive File Stream\52.0.6.0\drivefsext.dll [2021-10-18] (Google LLC -> Google, Inc.)
ContextMenuHandlers1: [DriveFS 28 or later] -> {EE15C2BD-CECB-49F8-A113-CA1BFC528F5B} => C:\Program Files\Google\Drive File Stream\52.0.6.0\drivefsext.dll [2021-10-18] (Google LLC -> Google, Inc.)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2021-04-22] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers4: [DriveFS 28 or later] -> {EE15C2BD-CECB-49F8-A113-CA1BFC528F5B} => C:\Program Files\Google\Drive File Stream\52.0.6.0\drivefsext.dll [2021-10-18] (Google LLC -> Google, Inc.)
ContextMenuHandlers5: [DriveFS 28 or later] -> {EE15C2BD-CECB-49F8-A113-CA1BFC528F5B} => C:\Program Files\Google\Drive File Stream\52.0.6.0\drivefsext.dll [2021-10-18] (Google LLC -> Google, Inc.)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\System32\DriverStore\FileRepository\nvlt.inf_amd64_5adc6075318430cf\nvshext.dll [2021-08-31] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2021-04-22] (Malwarebytes Corporation -> Malwarebytes)
==================== Codecs (Whitelisted) ====================
==================== Shortcuts & WMI ========================
==================== Loaded Modules (Whitelisted) =============
2019-10-21 04:56 - 2019-10-21 04:56 - 000144896 _____ () [File not signed] C:\ProgramData\Logishrd\LogiOptions\Software\Current\laclient\libssh2.dll
2019-10-21 04:56 - 2019-10-21 04:56 - 000077824 _____ () [File not signed] C:\ProgramData\Logishrd\LogiOptions\Software\Current\laclient\zlib.dll
2021-03-10 06:53 - 2021-03-10 06:53 - 000000000 ____L (Microsoft Corporation) [simlink -> C:\Program Files\Common Files\Microsoft Shared\ClickToRun\AppvIsvSubsystems64.dll] C:\Program Files\Microsoft Office\Root\Office16\AppVIsvSubsystems64.dll
2021-03-10 06:53 - 2021-03-10 06:53 - 000000000 ____L (Microsoft Corporation) [simlink -> C:\Program Files\Common Files\Microsoft Shared\ClickToRun\C2R64.dll] C:\Program Files\Microsoft Office\Root\Office16\c2r64.dll
2021-06-11 06:57 - 2020-11-03 04:08 - 000954864 _____ (SQLite Development Team) [File not signed] C:\ProgramData\Lenovo\iMController\Plugins\LenovoWiFiSecurityPlugin\x86\x86\e_sqlite3.dll
2019-10-21 04:56 - 2019-10-21 04:56 - 000355840 _____ (The cURL library, hxxp://curl.haxx.se/) [File not signed] C:\ProgramData\Logishrd\LogiOptions\Software\Current\laclient\LIBCURL.dll
2019-10-21 04:56 - 2019-10-21 04:56 - 002286747 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\ProgramData\Logishrd\LogiOptions\Software\Current\laclient\LIBEAY32.dll
2019-10-21 04:56 - 2019-10-21 04:56 - 000416627 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\ProgramData\Logishrd\LogiOptions\Software\Current\laclient\SSLEAY32.dll
==================== Alternate Data Streams (Whitelisted) ========
==================== Safe Mode (Whitelisted) ==================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service"
==================== Association (Whitelisted) =================
==================== Internet Explorer (Whitelisted) ==========
HKU\S-1-5-21-4005300964-2302935580-1863167367-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://mystart.lenovo.com/
SearchScopes: HKU\S-1-5-21-4005300964-2302935580-1863167367-1001 -> DefaultScope {10ABE9E3-13DA-46DD-B4E9-AA1779861B5A} URL =
SearchScopes: HKU\S-1-5-21-4005300964-2302935580-1863167367-1001 -> {10ABE9E3-13DA-46DD-B4E9-AA1779861B5A} URL =
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2021-10-29] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2021-10-29] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2021-10-29] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2021-10-29] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2021-10-29] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2021-10-29] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2021-10-29] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2021-10-29] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2021-10-29] (Microsoft Corporation -> Microsoft Corporation)
==================== Hosts content: =========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2019-12-07 01:14 - 2019-12-07 01:12 - 000000824 _____ C:\Windows\system32\drivers\etc\hosts
==================== Other Areas ===========================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-4005300964-2302935580-1863167367-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\19192\Downloads\DaveGrohlnme.jpg
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
(If an entry is included in the fixlist, it will be removed.)
HKLM\...\StartupApproved\Run: => "SecurityHealth"
HKU\S-1-5-21-4005300964-2302935580-1863167367-1001\...\StartupApproved\Run: => "DriverUpdate"
==================== FirewallRules (Whitelisted) ================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{D5C3E1EA-BD09-48CB-A3DF-30592CE419BE}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{7D0B604C-038B-4FC1-8930-8B3126440FEE}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{64AE00D8-D5BF-4F49-915E-B3CD49991C10}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{9F51071C-07F0-4F8D-B0DD-911B5778B273}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{2E6FD9BC-4929-4D79-95F3-D2819EFD8469}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{8F5F7D55-AE49-4AA7-8ED5-1E5382FBB307}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{7B96223D-344F-49E8-BB86-B099582965B2}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{9383BB08-115F-46DC-B831-A85457068B9B}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{BFC9211C-A41A-4B30-8C01-FA8734904EBE}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{7518B9C5-4A36-4D2B-A28C-A99A57CAE376}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{6871DEBF-FBD1-4584-9C5E-1C209E52B0C8}] => (Allow) C:\ProgramData\Logishrd\LogiOptions\Software\Current\LogiOptionsMgr.EXE (Logitech Inc -> Logitech, Inc.)
FirewallRules: [{E616003B-1FCD-492F-904C-741D360C791D}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{BC52CFF5-BB26-4FDE-B744-4B82C17B32B7}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{6627577B-64FB-4315-97B9-C34E3C125B52}] => (Allow) C:\Program Files\iTunes\iTunes.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{BCEDF912-EBF8-4D18-9963-02964EFCA403}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.78.159.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{3E9EEA9D-7126-41F6-BB63-4B7392F2ABAB}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.78.159.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{F2139E85-C9BC-4E88-AB7E-C822C2957553}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.78.159.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{93B3FA20-4261-4EC3-9A8E-33FEFA400597}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.78.159.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{E281517D-A7B0-4B35-98C2-15EDAB153D75}] => (Allow) C:\Users\19192\AppData\Local\Temp\HelpDesk\u8\HelpDesk\RPCHelpDeskServiceUAC.exe => No File
FirewallRules: [{868BB4AB-5C17-4ED0-A373-2D0A60535557}] => (Allow) C:\Users\19192\AppData\Local\Temp\HelpDesk\u8\HelpDesk\RPCHelpDeskServiceUAC.exe => No File
FirewallRules: [{C7F4D455-330B-4ACC-BC29-DF1ACFF695FE}] => (Allow) C:\Users\19192\AppData\Local\Temp\ShowMyPC\-ShowMyPC3606\SMPCSetup.exe => No File
FirewallRules: [{5806E64E-1B06-4E0B-B9C2-B4EF9AFB8809}] => (Allow) C:\Users\19192\AppData\Local\Temp\ShowMyPC\-ShowMyPC3606\tvnserver.exe => No File
FirewallRules: [{45671AFA-8FBD-4F27-8BE0-35BDC1A7C406}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\95.0.1020.53\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{3EFDD2F4-2367-4881-9600-7F4CDCA30DCF}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.172.439.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{03646D20-6E5C-4CD5-A316-E57F5B2BF8D3}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.172.439.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{A188224B-E5AD-4802-BD1C-C73937185DD4}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.172.439.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{E6D8527E-99AD-4C2F-9BDD-B781EAE28F53}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.172.439.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{973868AC-5DF0-49FB-A3C6-7C40E1193B28}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.172.439.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{F090496E-3A0E-46C3-8ABA-076456BB1161}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.172.439.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{EC124086-E00B-41F1-BADB-F453C4459743}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.172.439.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{7CCF74D1-0C30-4D2E-903A-03C178B19976}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.172.439.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
==================== Restore Points =========================
10-09-2021 11:04:37 Scheduled Checkpoint
02-11-2021 21:56:09 Scheduled Checkpoint
08-11-2021 14:06:52 Windows Update
12-11-2021 17:30:52 Windows Modules Installer
==================== Faulty Device Manager Devices ============
==================== Event log errors: ========================
Application errors:
==================
Error: (11/14/2021 07:54:31 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program utility.exe version 4.1.32.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.
Process ID: 3d00
Start Time: 01d7d5d52c3da835
Termination Time: 4294967295
Application Path: C:\Program Files\WindowsApps\E0469640.LenovoUtility_4.1.32.0_x64__5grkq8ppsgwt4\LaunchUtility\utility.exe
Report Id: 1b7c558f-a633-487b-acbb-5797ea0e66ab
Faulting package full name: E0469640.LenovoUtility_4.1.32.0_x64__5grkq8ppsgwt4
Faulting package-relative application ID: LenovoUtility
Hang type: Quiesce
Error: (11/13/2021 01:49:18 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: OneDrive.exe, version: 21.205.1003.5, time stamp: 0x099752be
Faulting module name: KERNELBASE.dll, version: 10.0.19041.1110, time stamp: 0x4809adf2
Exception code: 0x80000003
Fault offset: 0x00000000000c9a92
Faulting process id: 0x5600
Faulting application start time: 0x01d7d8d84be90685
Faulting application path: C:\Users\19192\AppData\Local\Microsoft\OneDrive\OneDrive.exe
Faulting module path: C:\Windows\System32\KERNELBASE.dll
Report Id: e624b516-6054-4f86-8237-a60d22d4dc5d
Faulting package full name:
Faulting package-relative application ID:
Error: (11/13/2021 01:48:39 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: OneDrive.exe, version: 21.205.1003.5, time stamp: 0x099752be
Faulting module name: KERNELBASE.dll, version: 10.0.19041.1110, time stamp: 0x4809adf2
Exception code: 0x80000003
Fault offset: 0x00000000000c9a92
Faulting process id: 0x1734
Faulting application start time: 0x01d7d8d82fae0eaa
Faulting application path: C:\Users\19192\AppData\Local\Microsoft\OneDrive\OneDrive.exe
Faulting module path: C:\Windows\System32\KERNELBASE.dll
Report Id: 3bc65d4e-a157-4aeb-8dba-db1667e94b67
Faulting package full name:
Faulting package-relative application ID:
Error: (11/13/2021 01:48:18 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: OneDrive.exe, version: 21.205.1003.5, time stamp: 0x099752be
Faulting module name: KERNELBASE.dll, version: 10.0.19041.1110, time stamp: 0x4809adf2
Exception code: 0x80000003
Fault offset: 0x00000000000c9a92
Faulting process id: 0x25bc
Faulting application start time: 0x01d7d8d8264cf40f
Faulting application path: C:\Users\19192\AppData\Local\Microsoft\OneDrive\OneDrive.exe
Faulting module path: C:\Windows\System32\KERNELBASE.dll
Report Id: ec1b3075-c76a-4ba1-bf94-cdc8dfbf482d
Faulting package full name:
Faulting package-relative application ID:
Error: (11/13/2021 01:47:40 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: OneDrive.exe, version: 21.205.1003.5, time stamp: 0x099752be
Faulting module name: KERNELBASE.dll, version: 10.0.19041.1110, time stamp: 0x4809adf2
Exception code: 0x80000003
Fault offset: 0x00000000000c9a92
Faulting process id: 0x13b0
Faulting application start time: 0x01d7d8d80f0b81ee
Faulting application path: C:\Users\19192\AppData\Local\Microsoft\OneDrive\OneDrive.exe
Faulting module path: C:\Windows\System32\KERNELBASE.dll
Report Id: ece6b4a0-d10a-4ee2-98cc-57d115cdde00
Faulting package full name:
Faulting package-relative application ID:
Error: (11/13/2021 01:32:27 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: OneDrive.exe, version: 21.205.1003.5, time stamp: 0x099752be
Faulting module name: KERNELBASE.dll, version: 10.0.19041.1110, time stamp: 0x4809adf2
Exception code: 0x80000003
Fault offset: 0x00000000000c9a92
Faulting process id: 0x39bc
Faulting application start time: 0x01d7d8d5d54ffe86
Faulting application path: C:\Users\19192\AppData\Local\Microsoft\OneDrive\OneDrive.exe
Faulting module path: C:\Windows\System32\KERNELBASE.dll
Report Id: 446de0ff-0b82-4a3b-8e3d-99630554d491
Faulting package full name:
Faulting package-relative application ID:
Error: (11/13/2021 01:31:30 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: OneDrive.exe, version: 21.205.1003.5, time stamp: 0x099752be
Faulting module name: KERNELBASE.dll, version: 10.0.19041.1110, time stamp: 0x4809adf2
Exception code: 0x80000003
Fault offset: 0x00000000000c9a92
Faulting process id: 0x3c24
Faulting application start time: 0x01d7d8d5aa82d09d
Faulting application path: C:\Users\19192\AppData\Local\Microsoft\OneDrive\OneDrive.exe
Faulting module path: C:\Windows\System32\KERNELBASE.dll
Report Id: 519ef8b2-354e-48f3-9386-6f132a010d4e
Faulting package full name:
Faulting package-relative application ID:
Error: (11/13/2021 01:30:18 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: OneDrive.exe, version: 21.205.1003.5, time stamp: 0x099752be
Faulting module name: KERNELBASE.dll, version: 10.0.19041.1110, time stamp: 0x4809adf2
Exception code: 0x80000003
Fault offset: 0x00000000000c9a92
Faulting process id: 0x2880
Faulting application start time: 0x01d7d8d555c682f7
Faulting application path: C:\Users\19192\AppData\Local\Microsoft\OneDrive\OneDrive.exe
Faulting module path: C:\Windows\System32\KERNELBASE.dll
Report Id: a6677b19-0b7f-4673-953b-257763b8b155
Faulting package full name:
Faulting package-relative application ID:
System errors:
=============
Error: (11/14/2021 07:53:37 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x8007139f: 9MWPM2CQNLHN-Microsoft.GamingServices.
Error: (11/09/2021 05:57:36 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The HelpDeskService service failed to start due to the following error:
The system cannot find the file specified.
Error: (11/09/2021 05:56:36 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The HelpDeskService service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
Error: (11/09/2021 05:51:28 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The LenovoVantageService service terminated unexpectedly. It has done this 1 time(s).
Error: (11/09/2021 05:45:54 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The AppXSvc service depends on the StateRepository service which failed to start because of the following error:
The operation completed successfully.
Error: (11/09/2021 05:45:54 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Audiosrv service failed to start due to the following error:
The service did not start due to a logon failure.
Error: (11/09/2021 05:45:54 PM) (Source: Service Control Manager) (EventID: 7038) (User: )
Description: The Audiosrv service was unable to log on as NT AUTHORITY\LocalService with the currently configured password due to the following error:
The request is not supported.
To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
Error: (11/09/2021 05:45:47 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 5:18:45 PM on 11/9/2021 was unexpected.
Windows Defender:
================
Date: 2021-11-02 22:38:45
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
Date: 2021-07-24 15:58:10
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
Date: 2021-07-23 19:11:43
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
Date: 2021-06-11 17:24:39
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
Date: 2021-05-12 14:31:54
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
CodeIntegrity:
===============
Date: 2021-11-14 20:08:46
Description:
Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume5\Program Files\Bonjour\mdnsNSP.dll that did not meet the Windows signing level requirements.
Date: 2021-11-14 20:06:28
Description:
Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume5\Program Files\Bonjour\mdnsNSP.dll that did not meet the Microsoft signing level requirements.
==================== Memory info ===========================
BIOS: LENOVO EGCN33WW 12/24/2020
Motherboard: LENOVO LNVNB161216
Processor: Intel® Core i7-10750H CPU @ 2.60GHz
Percentage of memory in use: 78%
Total physical RAM: 8059.8 MB
Available physical RAM: 1708.93 MB
Total Virtual: 19323.8 MB
Available Virtual: 9814.08 MB
==================== Drives ================================
Drive c: (Windows-SSD) (Fixed) (Total:237.23 GB) (Free:160.15 GB) NTFS
Drive d: (Data) (Fixed) (Total:931.5 GB) (Free:928.08 GB) NTFS
Drive g: (Google Drive) (Fixed) (Total:15 GB) (Free:12.68 GB) FAT32
\\?\Volume{4c930333-03c7-4bda-89cb-1ab278503d60}\ (WINRE_DRV) (Fixed) (Total:0.98 GB) (Free:0.49 GB) NTFS
\\?\Volume{19bbc73d-d8a9-45aa-aa09-3899456ca382}\ (SYSTEM_DRV) (Fixed) (Total:0.25 GB) (Free:0.22 GB) FAT32
==================== MBR & Partition Table ====================
==========================================================
Disk: 0 (Size: 238.5 GB) (Disk ID: 17FC6791)
Partition: GPT.
==========================================================
Disk: 1 (Size: 931.5 GB) (Disk ID: 583D7DAE)
Partition: GPT.
==================== End of Addition.txt =======================