Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

LummaC2 Stealer? hijacked??


  • Please log in to reply
3 replies to this topic

#1 fergcoreyg59

fergcoreyg59

  •  Avatar image
  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:10:58 PM

Posted 29 February 2024 - 03:45 AM

been having alot of issues with with laptop an phone lately. please help an go threw this an see if theres anything strange!

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 26.02.2024 01
Ran by ferg_ (administrator) on COREY (LENOVO 82BH) (29-02-2024 03:24:06)
Running from C:\Users\ferg_\Downloads\FRST64.exe
Loaded Profiles: ferg_
Platform: Microsoft Windows 11 Pro Version 23H2 22631.3155 (X64) Language: English (United States)
Default browser: Edge
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(C:\Program Files (x86)\Lenovo\VantageService\4.0.52.0\LenovoVantageService.exe ->) (Lenovo -> Lenovo) C:\Program Files (x86)\Lenovo\VantageService\4.0.52.0\LenovoVantage-(DeviceSettingsSystemAddin).exe
(C:\Program Files (x86)\Lenovo\VantageService\4.0.52.0\LenovoVantageService.exe ->) (Lenovo -> Lenovo) C:\Program Files (x86)\Lenovo\VantageService\4.0.52.0\LenovoVantage-(GenericMessagingAddin).exe
(C:\Program Files (x86)\Lenovo\VantageService\4.0.52.0\LenovoVantageService.exe ->) (Lenovo -> Lenovo) C:\Program Files (x86)\Lenovo\VantageService\4.0.52.0\LenovoVantage-(VantageCoreAddin).exe
(C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe ->) (McAfee, LLC -> McAfee, LLC) C:\Program Files\Common Files\McAfee\MMSSHost\MMSSHOST.exe
(C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe ->) (McAfee, LLC -> McAfee, LLC) C:\Program Files\Common Files\McAfee\ModuleCore\ProtectedModuleHost.exe
(C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe ->) (McAfee, LLC -> McAfee, LLC) C:\Program Files\McAfee\MfeAV\MfeAVSvc.exe
(C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe ->) (MUSARUBRA US LLC -> McAfee LLC.) C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe
(C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe ->) (MUSARUBRA US LLC -> McAfee, LLC) C:\Windows\System32\mfevtps.exe
(C:\Program Files\WindowsApps\microsoftwindows.client.webexperience_424.1301.170.0_x64__cw5n1h2txyewy\Dashboard\Widgets.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\122.0.2365.52\msedgewebview2.exe <6>
(DriverStore\FileRepository\cui_dch.inf_amd64_b18a4e283f67c0b5\igfxCUIServiceN.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_b18a4e283f67c0b5\igfxEMN.exe
(DriverStore\FileRepository\lenovofnandfunctionkeys.inf_amd64_fdde6ecd49c3a98b\LenovoUtilityService.exe ->) (Lenovo -> Lenovo) C:\Windows\System32\DriverStore\FileRepository\lenovofnandfunctionkeys.inf_amd64_fdde6ecd49c3a98b\FnHotkeyCapsLKNumLK.exe
(DriverStore\FileRepository\lenovofnandfunctionkeys.inf_amd64_fdde6ecd49c3a98b\LenovoUtilityService.exe ->) (Lenovo -> Lenovo) C:\Windows\System32\DriverStore\FileRepository\lenovofnandfunctionkeys.inf_amd64_fdde6ecd49c3a98b\FnHotkeyUtility.exe
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <19>
(explorer.exe ->) (Microsoft Corporation -> Sysinternals - www.sysinternals.com) C:\Users\ferg_\Downloads\Autoruns\Autoruns.exe
(explorer.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\Taskmgr.exe
(LNBITSSvc.exe ->) (Lenovo -> Lenovo(beijing) Limited) C:\Windows\System32\AutoModeDetect.exe
(McAfee, LLC -> McAfee, LLC) C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe
(services.exe ->) (Dolby Laboratories, Inc. -> Dolby Laboratories) C:\Windows\System32\DriverStore\FileRepository\dax3_swc_aposvc.inf_amd64_771d64c55bc6db71\DAX3API.exe <2>
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_b18a4e283f67c0b5\igfxCUIServiceN.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dptf_cpu.inf_amd64_897ea327b3fe52f7\esif_uf.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iastorvd.inf_amd64_a5ea1b1d8db1527e\RstMwService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_5fe2e31c542e0065\OneApp.IGCC.WinService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_a4c5029a9cea195e\IntelCpHDCPSvc.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_21e0cf0737fd48af\WMIRegistrationService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\TbtP2pShortcutService.exe
(services.exe ->) (Intel Corporation -> Intel) C:\Windows\System32\DriverStore\FileRepository\intcoed.inf_amd64_dd6a7ef14d856351\AS\IAS\IntelAudioService.exe
(services.exe ->) (Intel® Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_b5484efd38adbe8d\jhi_service.exe
(services.exe ->) (Lenovo -> Lenovo Group Ltd.) C:\Windows\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe
(services.exe ->) (Lenovo -> Lenovo Group Ltd.) C:\Windows\System32\drivers\Lenovo\udc\Service\UDClientService.exe
(services.exe ->) (Lenovo -> Lenovo Group Ltd.) C:\Windows\System32\YMC.exe
(services.exe ->) (Lenovo -> Lenovo(beijing) Limited) C:\Windows\System32\LNBITSSvc.exe
(services.exe ->) (Lenovo -> Lenovo) C:\Program Files (x86)\Lenovo\VantageService\4.0.52.0\LenovoVantageService.exe
(services.exe ->) (Lenovo -> Lenovo) C:\Windows\System32\DriverStore\FileRepository\lenovofnandfunctionkeys.inf_amd64_fdde6ecd49c3a98b\LenovoUtilityService.exe
(services.exe ->) (McAfee, LLC -> McAfee, LLC) C:\Program Files\Common Files\McAfee\CSP\5.5.107.0\McCSPServiceHost.exe
(services.exe ->) (McAfee, LLC -> McAfee, LLC) C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe <3>
(services.exe ->) (McAfee, LLC -> McAfee, LLC) C:\Program Files\Common Files\McAfee\PEF\CORE\PEFService.exe
(services.exe ->) (McAfee, LLC -> McAfee, LLC) C:\Program Files\Common Files\McAfee\VSCore_22_12\mcapexe.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\Locator.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Fortemedia) C:\Windows\System32\FMService64.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24010.12-0\MsMpEng.exe
(services.exe ->) (MUSARUBRA US LLC -> McAfee, LLC) C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_a1020546271138b9\RtkAudUService64.exe <2>
(services.exe ->) (Texas Instruments Inc. -> Texas Instuments) C:\Windows\System32\TISmartAmpService.exe <2>
(services.exe ->) (Wacom Co., Ltd. -> Wacom Technology, Corp.) C:\Windows\System32\DriverStore\FileRepository\wtabletserviceisd.inf_amd64_e6fcc557ac12c616\WTabletServiceISD.exe <2>
(svchost.exe ->) (McAfee, LLC -> McAfee, LLC) C:\Program Files\Common Files\McAfee\TaskScheduler\SETA46D.tmp
(svchost.exe ->) (McAfee, LLC -> McAfee, LLC) C:\Program Files\McAfee\MQS\QcShm.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
(svchost.exe ->) (Microsoft Windows -> ) C:\Program Files\WindowsApps\microsoftwindows.client.webexperience_424.1301.170.0_x64__cw5n1h2txyewy\Dashboard\WidgetService.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <3>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\LocationNotificationWindows.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\UUS\Packages\Preview\amd64\MoUsoCoreWorker.exe
 
==================== Registry (Whitelisted) ===================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\DriverStore\FileRepository\realtekservice.inf_amd64_a1020546271138b9\RtkAudUService64.exe [1343072 2021-08-26] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKU\S-1-5-21-3652864268-2719191564-4212199372-1001\...\Run: [MicrosoftEdgeAutoLaunch_86E305C0A48CB3C5F0394A2FDA89967F] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4067896 2024-02-23] (Microsoft Corporation -> Microsoft Corporation)
HKLM\Software\...\Authentication\Credential Providers: [{C885AA15-1764-4293-B82A-0586ADD46B35}] -> 
GroupPolicy: Restriction ? <==== ATTENTION
ProgramData\NTUSER.pol: RestrPolicies: C:\iction <==== ATTENTION
 
==================== Scheduled Tasks (Whitelisted) =================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
"C:\Windows\System32\Tasks\McAfee\McAfee Idle Detection Task" was unlocked. <==== ATTENTION
Task: {DC7200C0-0BA3-4B18-B45E-DFD1EB9FD9A5} - System32\Tasks\Lenovo\ImController\Lenovo iM Controller Monitor => C:\WINDOWS\system32\ImController.InfInstaller.exe [74952 2022-11-20] (Lenovo -> Lenovo Group Ltd.)
Task: {601E7F0F-C0C4-4185-A013-860FF5F9BDEC} - System32\Tasks\Lenovo\ImController\Lenovo iM Controller Scheduled Maintenance => C:\WINDOWS\system32\sc.exe [98304 2022-05-07] (Microsoft Windows -> Microsoft Corporation) -> START ImControllerService
Task: {8DF0C638-7469-4BC9-9F55-A2FD7FB0BBDD} - System32\Tasks\Lenovo\ImController\Plugins\LenovoSystemUpdatePlugin_WeeklyTask => C:\WINDOWS\System32\reg.exe [102400 2022-05-07] (Microsoft Windows -> Microsoft Corporation) -> add hklm\SOFTWARE\Lenovo\SystemUpdatePlugin\scheduler /v start /t reg_dword /d 1 /f /reg:32
Task: {DD0561EF-852B-4FFA-A21F-9EE2A98BA4EC} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\16bc0f9f-198f-4999-9d45-de4b56e415dd => C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [93896 2022-11-20] (Lenovo -> Lenovo Group Ltd.)
Task: {9F0ABED1-0CD0-4E85-90E6-26B929D9D058} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\9c97e0b2-9a17-4c55-98da-096667cab0c9 => C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [93896 2022-11-20] (Lenovo -> Lenovo Group Ltd.)
Task: {093C40E0-CA6B-481C-815D-F6E27A2ABB1A} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\9d2efcf9-7730-4f19-b4cf-8141682812cd => C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [93896 2022-11-20] (Lenovo -> Lenovo Group Ltd.)
Task: {DC3C396D-51B8-475B-AD14-AF2348CB2098} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\b6ae5d26-28ed-44a2-9278-bf5e06c058f4 => C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [93896 2022-11-20] (Lenovo -> Lenovo Group Ltd.)
Task: {5C487C07-62D5-4520-ACC2-7ABC4FC77BC8} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\c4b39a40-ff98-446d-845a-53f682711595 => C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [93896 2022-11-20] (Lenovo -> Lenovo Group Ltd.)
Task: {F6DDA756-F7F2-4ECD-8406-E44C9A0CB779} - System32\Tasks\Lenovo\LenovoWelcomeLauncher => C:\ProgramData\Lenovo\ImController\Plugins\LenovoFirstRunExperiencePackage\x86\LenovoWelcome.exe [983480 2020-10-13] (Lenovo -> Lenovo Group Ltd.)
Task: {FB84BE0E-2CBD-4A2F-A003-EF61FCFB0D29} - System32\Tasks\Lenovo\LenovoWelcomeTask => C:\ProgramData\Lenovo\ImController\Plugins\LenovoFirstRunExperiencePackage\x86\LenovoWelcomeTask.exe [37816 2020-10-13] (Lenovo -> Lenovo Group Ltd.)
Task: {D6E2DB6C-960C-4493-BE87-435B053E537B} - System32\Tasks\Lenovo\UDC\Lenovo UDC Monitor => C:\WINDOWS\system32\drivers\lenovo\udc\data\InfBackup\UdcInfInstaller.exe [185312 2023-11-02] (Lenovo -> Lenovo Group Ltd.)
Task: {D971584E-A6E2-4C81-9BB7-3EFB594EC222} - System32\Tasks\Lenovo\Vantage\Lenovo.Vantage.ServiceMaintainance => C:\WINDOWS\system32\sc.exe [98304 2022-05-07] (Microsoft Windows -> Microsoft Corporation) -> start LenovoVantageService
Task: {D584142F-CAAB-4E5A-AD04-0D9197735E4C} - System32\Tasks\Lenovo\Vantage\Schedule\BatteryGaugeAddinDailyScheduleTask => C:\Program Files (x86)\Lenovo\VantageService\4.0.52.0\ScheduleEventAction.exe [30176 2023-12-15] (Lenovo -> Lenovo)
Task: {A8BBB021-2DDE-49F6-8329-658FA9F60005} - System32\Tasks\Lenovo\Vantage\Schedule\DailyTelemetryTransmission => C:\Program Files (x86)\Lenovo\VantageService\4.0.52.0\ScheduleEventAction.exe [30176 2023-12-15] (Lenovo -> Lenovo)
Task: {85E40900-2241-43A0-849D-E22F8BE443D1} - System32\Tasks\Lenovo\Vantage\Schedule\GenericMessagingAddin => C:\Program Files (x86)\Lenovo\VantageService\4.0.52.0\ScheduleEventAction.exe [30176 2023-12-15] (Lenovo -> Lenovo)
Task: {AA505FF7-0270-44F5-A577-261A01BE11E7} - System32\Tasks\Lenovo\Vantage\Schedule\HeartbeatAddinDailyScheduleTask => C:\Program Files (x86)\Lenovo\VantageService\4.0.52.0\ScheduleEventAction.exe [30176 2023-12-15] (Lenovo -> Lenovo)
Task: {94814D2F-041D-4DB8-941D-DB1CD25C8261} - System32\Tasks\Lenovo\Vantage\Schedule\IdeaNotebookAddinDailyEvent => C:\Program Files (x86)\Lenovo\VantageService\4.0.52.0\ScheduleEventAction.exe [30176 2023-12-15] (Lenovo -> Lenovo)
Task: {B28C4BFD-519D-4ADD-B5E5-E451E0CB0059} - System32\Tasks\Lenovo\Vantage\Schedule\Lenovo.Vantage.SmartPerformance.MonthlyReport => C:\Program Files (x86)\Lenovo\VantageService\4.0.52.0\ScheduleEventAction.exe [30176 2023-12-15] (Lenovo -> Lenovo)
Task: {FE3573FA-9C53-4DE6-9DC0-844B4D27121B} - System32\Tasks\Lenovo\Vantage\Schedule\LenovoCompanionAppAddinDailyScheduleTask => C:\Program Files (x86)\Lenovo\VantageService\4.0.52.0\ScheduleEventAction.exe [30176 2023-12-15] (Lenovo -> Lenovo)
Task: {FDB8F6BC-3E3E-4C9D-822E-01701AF8D76D} - System32\Tasks\Lenovo\Vantage\Schedule\LenovoSystemUpdateAddin_WeeklyTask => C:\Program Files (x86)\Lenovo\VantageService\4.0.52.0\ScheduleEventAction.exe [30176 2023-12-15] (Lenovo -> Lenovo)
Task: {BB7B2CCD-31F7-4582-BD44-1591B9ED0E83} - System32\Tasks\Lenovo\Vantage\Schedule\SettingsWidgetAddinDailyScheduleTask => C:\Program Files (x86)\Lenovo\VantageService\4.0.52.0\ScheduleEventAction.exe [30176 2023-12-15] (Lenovo -> Lenovo)
Task: {87604331-390D-4E78-9224-19F4B3476FA2} - System32\Tasks\Lenovo\Vantage\Schedule\SmartPerformance.ExpireReminder => C:\Program Files (x86)\Lenovo\VantageService\4.0.52.0\ScheduleEventAction.exe [30176 2023-12-15] (Lenovo -> Lenovo)
Task: {0FB7415A-EE32-4F14-8321-D638ADE0AEA8} - System32\Tasks\Lenovo\Vantage\Schedule\VantageCoreAddinWeekScheduleTask => C:\Program Files (x86)\Lenovo\VantageService\4.0.52.0\ScheduleEventAction.exe [30176 2023-12-15] (Lenovo -> Lenovo)
Task: {EA66D900-E7BD-4EB0-8A4F-857E8C653B78} - System32\Tasks\Lenovo\Vantage\StartupFixPlan => C:\Program Files (x86)\Lenovo\VantageService\4.0.52.0\uninstall.exe [311776 2023-12-15] (Lenovo -> Lenovo)
Task: {F3986661-44CD-47FC-85DE-68D3FF55E0CB} - System32\Tasks\McAfee Remediation (Prepare) => C:\Program Files\Common Files\AV\McAfee VirusScan\upgrade.exe [4565040 2023-07-17] (McAfee, LLC -> McAfee, LLC)
Task: {D0F44B6B-790F-4EF2-BBB0-8004F30FEB08} - System32\Tasks\McAfee\DAD.Execute.Updates => C:\Program Files\Common Files\McAfee\DynamicAppDownloader\DADUpdater.exe [4094568 2023-02-17] (McAfee, LLC -> McAfee, LLC)
Task: {6E179C92-CD74-4A19-BB9A-F9B62DFC7DAE} - System32\Tasks\McAfee\McAfee Auto Maintenance Task Agent => {ABCECA3B-EA5A-496B-A021-5C6BAB365E5C} C:\Program Files\Common Files\McAfee\TaskScheduler\McAMTaskAgent.exe [931056 2023-02-20] (McAfee, LLC -> McAfee, LLC)
Task: {DA6C8094-816A-4BA8-B55C-D75905E76309} - System32\Tasks\McAfee\McAfee Idle Detection Task => {ABCDCA3B-DE6B-5A7C-B132-6D7CBA63E5C5} C:\Program Files\Common Files\McAfee\TaskScheduler\McAMTaskAgent.exe [931056 2023-02-20] (McAfee, LLC -> McAfee, LLC)
Task: {F5910351-966C-429C-8D39-B24CF0C3CDC1} - System32\Tasks\McAfeeLogon => C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe [768288 2022-03-24] (McAfee, LLC -> McAfee, LLC)
Task: {BC727098-6EAA-49A3-8148-82DF97F5D588} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [22764936 2020-10-06] (Microsoft Corporation -> Microsoft Corporation)
Task: {2B35FB16-1AE2-41DD-9433-0AA235747672} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [22764936 2020-10-06] (Microsoft Corporation -> Microsoft Corporation)
Task: {D2554FAC-3616-4D20-8966-0E273BF44B5C} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [145752 2023-12-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {1E83706C-2AE5-4DE3-81A8-243CFA8E0FCF} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [145752 2023-12-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {CCDFC0B8-01A3-4E74-A820-4F13F51D269E} - System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => %SystemRoot%\System32\MbaeParserTask.exe  (No File)
Task: {241C61E4-9A15-4732-9216-D9AAF5EB8321} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe  (No File)
Task: {C6AB035E-FDD3-420D-BD5A-29AAB13F9B6F} - System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1946765252-2041723333-188045582-500 => %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe  (No File)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{45503a29-caa3-4e37-853d-7dc7223bc5d8}: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{45503a29-caa3-4e37-853d-7dc7223bc5d8}\8416C6: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{45503a29-caa3-4e37-853d-7dc7223bc5d8}\8416C6: [DhcpDomain] attlocal.net
Tcpip\..\Interfaces\{45503a29-caa3-4e37-853d-7dc7223bc5d8}\84F6D656F66635861646F677: [DhcpNameServer] 206.225.75.225 206.225.75.226
 
Edge: 
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\ferg_\AppData\Local\Microsoft\Edge\User Data\Default [2024-02-29]
Edge Extension: (Google Docs Offline) - C:\Users\ferg_\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-02-23]
Edge Extension: (Edge relevant text changes) - C:\Users\ferg_\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-02-23]
Edge Extension: (Crystal Ad block) - C:\Users\ferg_\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\nebmdgjnibegbogmdlpojcgjklkbgmpl [2024-02-24]
 
FireFox:
========
FF Plugin: @mcafee.com/MSC,version=10 -> C:\Program Files\McAfee\MSC\npMcSnFFPl64.dll [2023-10-05] (McAfee, LLC -> )
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2023-12-14] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @mcafee.com/MSC,version=10 -> C:\Program Files (x86)\McAfee\MSC\npMcSnFFPl.dll [2023-10-05] (McAfee, LLC -> )
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2023-12-14] (Microsoft Corporation -> Microsoft Corporation)
 
==================== Services (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S2 0319031709192528mcinstcleanup; C:\ProgramData\McInstTemp0319031709192528\McInst.exe [927896 2023-11-06] (McAfee, LLC -> McAfee, LLC)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [8853384 2020-10-05] (Microsoft Corporation -> Microsoft Corporation)
R2 DolbyDAXAPI; C:\WINDOWS\System32\DriverStore\FileRepository\dax3_swc_aposvc.inf_amd64_771d64c55bc6db71\DAX3API.exe [2141832 2021-07-23] (Dolby Laboratories, Inc. -> Dolby Laboratories)
R2 FMAPOService; C:\WINDOWS\System32\FMService64.exe [437680 2022-01-24] (Microsoft Windows Hardware Compatibility Publisher -> Fortemedia)
R2 ImControllerService; C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [93896 2022-11-20] (Lenovo -> Lenovo Group Ltd.)
R2 IntelAudioService; C:\WINDOWS\System32\DriverStore\FileRepository\intcoed.inf_amd64_dd6a7ef14d856351\AS\IAS\IntelAudioService.exe [539816 2021-09-01] (Intel Corporation -> Intel)
R2 LenovoFnAndFunctionKeys; C:\WINDOWS\System32\DriverStore\FileRepository\lenovofnandfunctionkeys.inf_amd64_fdde6ecd49c3a98b\LenovoUtilityService.exe [161760 2024-01-15] (Lenovo -> Lenovo)
R2 LenovoVantageService; C:\Program Files (x86)\Lenovo\VantageService\4.0.52.0\LenovoVantageService.exe [34272 2023-12-15] (Lenovo -> Lenovo)
R2 LITSSVC; C:\WINDOWS\System32\LNBITSSvc.exe [1831672 2022-08-17] (Lenovo -> Lenovo(beijing) Limited)
R2 McAPExe; C:\Program Files\Common Files\McAfee\VSCore_22_12\McApExe.exe [815376 2023-11-06] (McAfee, LLC -> McAfee, LLC)
S3 McAWFwk; C:\Program Files\Common Files\McAfee\ActWiz\McAWFwk.exe [604720 2022-01-19] (McAfee, LLC -> McAfee, LLC)
R2 mccspsvc; C:\Program Files\Common Files\McAfee\CSP\5.5.107.0\McCSPServiceHost.exe [3384472 2023-02-28] (McAfee, LLC -> McAfee, LLC)
S3 McSecDashboardService; C:\Program Files\McAfeeDashboard\McSecDashboardService.exe [1161032 2022-07-14] (McAfee, LLC -> McAfee, LLC)
S3 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe [1226192 2023-04-05] (MUSARUBRA US LLC -> McAfee, LLC)
R2 mfemms; C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe [1226192 2023-04-05] (MUSARUBRA US LLC -> McAfee, LLC)
R3 mfevtp; C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe [1226192 2023-04-05] (MUSARUBRA US LLC -> McAfee, LLC)
R2 ModuleCoreService; C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe [1570496 2023-10-10] (McAfee, LLC -> McAfee, LLC)
R2 PEFService; C:\Program Files\Common Files\McAfee\PEF\CORE\PEFService.exe [4248712 2022-10-14] (McAfee, LLC -> McAfee, LLC)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [534592 2023-12-27] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 TbtP2pShortcutService; C:\WINDOWS\TbtP2pShortcutService.exe [254112 2021-07-14] (Intel Corporation -> Intel Corporation)
R2 TISmartAmpService; C:\WINDOWS\System32\TISmartAmpService.exe [542464 2022-02-10] (Texas Instruments Inc. -> Texas Instuments)
R2 UDCService; C:\WINDOWS\System32\drivers\Lenovo\udc\Service\UDClientService.exe [72160 2023-11-02] (Lenovo -> Lenovo Group Ltd.)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24010.12-0\NisSrv.exe [3191256 2024-02-27] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24010.12-0\MsMpEng.exe [133576 2024-02-27] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 YMC; C:\WINDOWS\System32\YMC.exe [856920 2020-06-16] (Lenovo -> Lenovo Group Ltd.)
 
===================== Drivers (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 bqusbser; C:\WINDOWS\System32\drivers\Mousbser.sys [118016 2013-07-23] (Microsoft Windows Hardware Compatibility Publisher -> Motorola Incorporated)
R3 cfwids; C:\WINDOWS\System32\drivers\cfwids.sys [70880 2023-04-05] (Microsoft Windows Hardware Compatibility Publisher -> Trellix US LLC.)
S3 dg_ssudbus; C:\WINDOWS\System32\drivers\ssudbus2.sys [167440 2022-10-04] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 FlashUSB; C:\WINDOWS\System32\drivers\FlashUSB.sys [19968 2022-05-13] (Microsoft Windows Hardware Compatibility Publisher -> Intel Mobile Communications)
R3 iaLPSS2_GPIO2_TGL; C:\WINDOWS\System32\DriverStore\FileRepository\ialpss2_gpio2_tgl.inf_amd64_2546dafe2183e972\iaLPSS2_GPIO2_TGL.sys [131224 2021-07-20] (Intel Corporation -> Intel Corporation)
R3 iaLPSS2_I2C_TGL; C:\WINDOWS\System32\DriverStore\FileRepository\ialpss2_i2c_tgl.inf_amd64_1308f85f1b0adf27\iaLPSS2_I2C_TGL.sys [204440 2021-07-20] (Intel Corporation -> Intel Corporation)
R3 iaLPSS2_SPI_TGL; C:\WINDOWS\System32\DriverStore\FileRepository\ialpss2_spi_tgl.inf_amd64_fc1ed3a5a1d514f2\iaLPSS2_SPI_TGL.sys [158352 2021-07-20] (Intel Corporation -> Intel Corporation)
R3 iaLPSS2_UART2_TGL; C:\WINDOWS\System32\DriverStore\FileRepository\ialpss2_uart2_tgl.inf_amd64_cd8c3a141c1b1284\iaLPSS2_UART2_TGL.sys [313504 2021-07-20] (Intel Corporation -> Intel Corporation)
R0 iaStorVD; C:\WINDOWS\System32\drivers\iaStorVD.sys [1544912 2021-08-26] (Intel Corporation -> Intel Corporation)
R3 IntcUSB; C:\WINDOWS\System32\DriverStore\FileRepository\intcusb.inf_amd64_8dd4e6dd6061449d\IntcUSB.sys [1684544 2021-09-01] (Intel Corporation -> Intel® Corporation)
S3 IntelGNA; C:\WINDOWS\System32\DriverStore\FileRepository\gna.inf_amd64_689d3d5fefeef458\gna.sys [84880 2020-11-05] (Gaussian Mixture Models and Neural Networks Accelerator -> Intel Corporation)
S3 leusbser; C:\WINDOWS\System32\drivers\leusbser.sys [238080 2023-04-05] (Microsoft Windows Hardware Compatibility Publisher -> QUALCOMM Incorporated)
R3 mfeaack; C:\WINDOWS\System32\drivers\mfeaack.sys [491232 2023-04-05] (Microsoft Windows Hardware Compatibility Publisher -> Trellix US LLC.)
U3 mfeaack01; no ImagePath
R3 mfeavfk; C:\WINDOWS\System32\drivers\mfeavfk.sys [354016 2023-04-05] (Microsoft Windows Hardware Compatibility Publisher -> Trellix US LLC.)
U3 mfeavfk01; no ImagePath
U3 mfeavfk02; no ImagePath
S0 mfeelamk; C:\WINDOWS\System32\drivers\mfeelamk.sys [85456 2023-04-05] (Microsoft Windows Early Launch Anti-malware Publisher -> Trellix US LLC.)
R3 mfefirek; C:\WINDOWS\System32\drivers\mfefirek.sys [464080 2023-04-05] (Microsoft Windows Hardware Compatibility Publisher -> Trellix US LLC.)
R0 mfehidk; C:\WINDOWS\System32\drivers\mfehidk.sys [949472 2023-04-05] (Microsoft Windows Hardware Compatibility Publisher -> Trellix US LLC.)
U3 mfehidk01; no ImagePath
U3 mfehidk02; no ImagePath
R3 mfencbdc; C:\WINDOWS\System32\DRIVERS\mfencbdc.sys [714600 2022-11-15] (Musarubra US LLC -> Trellix US LLC.)
U3 mfencbdc01; no ImagePath
U3 mfencbdc02; no ImagePath
S3 mfencrk; C:\WINDOWS\System32\DRIVERS\mfencrk.sys [135024 2022-11-15] (Musarubra US LLC -> Trellix US LLC.)
R3 mfeplk; C:\WINDOWS\System32\drivers\mfeplk.sys [106720 2023-04-05] (Microsoft Windows Hardware Compatibility Publisher -> Trellix US LLC.)
R0 mfewfpk; C:\WINDOWS\System32\drivers\mfewfpk.sys [233176 2023-04-05] (Microsoft Windows Hardware Compatibility Publisher -> Trellix US LLC.)
S3 motccgp; C:\WINDOWS\System32\drivers\motccgp.sys [23552 2013-07-23] (Microsoft Windows Hardware Compatibility Publisher -> Motorola Mobility Inc)
S3 MotoSwitchService; C:\WINDOWS\System32\drivers\motswch.sys [8832 2013-07-23] (Microsoft Windows Hardware Compatibility Publisher -> Motorola)
S3 motport; C:\WINDOWS\System32\drivers\motport.sys [31744 2013-07-23] (Microsoft Windows Hardware Compatibility Publisher -> Motorola Mobility Inc)
S3 motusbdevice; C:\WINDOWS\System32\drivers\motusbdevice.sys [12288 2013-07-23] (Microsoft Windows Hardware Compatibility Publisher -> Motorola Inc)
S3 rdavcom; C:\WINDOWS\System32\drivers\rdavcom.sys [46024 2023-04-05] (Beijing Unisoc Technologies Co., Ltd. -> SPRD Device)
S3 secubus; C:\WINDOWS\System32\drivers\secubus.sys [118784 2022-05-13] (MCCI Corporation -> MCCI Corporation)
S3 shspusb; C:\WINDOWS\System32\drivers\HSPUSB.sys [24064 2022-05-13] (Microsoft Windows Hardware Compatibility Publisher -> MobileTop)
S3 sprdvcom; C:\WINDOWS\System32\drivers\sprdvcom.sys [46024 2023-04-05] (Beijing Unisoc Technologies Co., Ltd. -> SPRD Device)
S3 ssaebus; C:\WINDOWS\System32\drivers\ssaebus.sys [136264 2022-05-13] (MCCI Corporation -> MCCI Corporation)
S3 ssaeunic; C:\WINDOWS\System32\drivers\ssaeunic.sys [178760 2022-05-13] (MCCI Corporation -> MCCI Corporation)
S3 ssbcbus; C:\WINDOWS\System32\drivers\ssbcbus.sys [108032 2022-05-13] (MCCI Corporation -> MCCI)
S3 sscdserd; C:\WINDOWS\System32\drivers\sscdserd.sys [158024 2022-05-13] (MCCI Corporation -> MCCI Corporation)
S3 ssceserd; C:\WINDOWS\System32\drivers\ssceserd.sys [158024 2022-05-13] (MCCI Corporation -> MCCI Corporation)
S3 ssdudfu; C:\WINDOWS\System32\drivers\ssdudfu.sys [101960 2022-05-13] (MCCI Corporation -> MCCI)
S3 ssecbus; C:\WINDOWS\System32\drivers\ssecbus.sys [113664 2022-05-13] (MCCI Corporation -> MCCI Corporation)
S3 ssecmgmt; C:\WINDOWS\System32\drivers\ssecmgmt.sys [132096 2022-05-13] (MCCI Corporation -> MCCI Corporation)
S3 ssecobex; C:\WINDOWS\System32\drivers\ssecobex.sys [127488 2022-05-13] (MCCI Corporation -> MCCI Corporation)
S3 ssecunic; C:\WINDOWS\System32\drivers\ssecunic.sys [145408 2022-05-13] (MCCI Corporation -> MCCI Corporation)
S3 ssm_bus; C:\WINDOWS\System32\drivers\ssm_bus.sys [136192 2022-05-13] (MCCI Corporation -> MCCI Corporation)
S3 ssm_mdm; C:\WINDOWS\System32\drivers\ssm_mdm.sys [172032 2022-05-13] (MCCI Corporation -> MCCI Corporation)
S3 sssdbus; C:\WINDOWS\System32\drivers\sssdbus.sys [129352 2022-05-13] (MCCI Corporation -> MCCI Corporation)
S3 sssdmgmt; C:\WINDOWS\System32\drivers\sssdmgmt.sys [142664 2022-05-13] (MCCI Corporation -> MCCI Corporation)
S3 sssdobex; C:\WINDOWS\System32\drivers\sssdobex.sys [138056 2022-05-13] (MCCI Corporation -> MCCI Corporation)
S3 ssudqcfilter; C:\WINDOWS\System32\drivers\ssudqcfilter.sys [76832 2022-10-04] (Samsung Electronics CO., LTD. -> QUALCOMM Incorporated)
S3 SSUSBDownload; C:\WINDOWS\System32\drivers\SSUSBDownload.sys [23040 2022-05-13] (Microsoft Windows Hardware Compatibility Publisher -> SAMSUNG Electronics Co.,Ltd.)
S3 ss_bserd; C:\WINDOWS\System32\drivers\ss_bserd.sys [128000 2022-05-13] (MCCI Corporation -> MCCI Corporation)
S3 ss_conn_usb_driver; C:\WINDOWS\System32\Drivers\ss_conn_usb_driver.sys [50720 2022-10-04] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 ss_conn_usb_driver2; C:\WINDOWS\System32\Drivers\ss_conn_usb_driver2.sys [50720 2022-10-04] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 tusbd; C:\WINDOWS\System32\drivers\tusbd.sys [49656 2024-02-16] (Microsoft Windows Hardware Compatibility Publisher -> SimplyCore LLC)
S3 tusbdbus; C:\WINDOWS\System32\drivers\tusbdbus.sys [80376 2024-02-16] (Microsoft Windows Hardware Compatibility Publisher -> SimplyCore LLC)
S3 UsbserFilt; C:\WINDOWS\System32\drivers\usbser_lowerfltsax64j.sys [9216 2022-05-13] (Microsoft Windows Hardware Compatibility Publisher -> Nokia)
S3 VIA_USB_ETS; C:\WINDOWS\System32\drivers\VIA_USB_ETS.sys [21760 2022-05-13] (Microsoft Windows Hardware Compatibility Publisher -> Via Telecom, Inc.)
S3 WacHIDFilterISD; C:\WINDOWS\System32\drivers\WacHIDRouterISDU.sys [181872 2020-09-17] (Wacom Co., Ltd. -> Wacom Technology, Corp.)
R3 WacHIDRouterISDF; C:\WINDOWS\System32\drivers\WacHIDRouterISDF.sys [127280 2022-04-21] (Wacom Co., Ltd. -> Wacom Technology, Corp.)
S3 WacHIDRouterISDFV; C:\WINDOWS\System32\drivers\WacHIDRouterISDF.sys [127280 2022-04-21] (Wacom Co., Ltd. -> Wacom Technology, Corp.)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [21040 2024-02-27] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [608648 2024-02-27] (Microsoft Windows -> Microsoft Corporation)
S3 wdm_usb; C:\WINDOWS\System32\drivers\usb2ser.sys [163048 2022-07-24] (MEDIATEK INC. -> MBB)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [105752 2024-02-27] (Microsoft Windows -> Microsoft Corporation)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One month (created) (Whitelisted) =========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2024-02-29 03:24 - 2024-02-29 03:24 - 000032893 _____ C:\Users\ferg_\Downloads\FRST.txt
2024-02-29 03:23 - 2024-02-29 03:24 - 000000000 ____D C:\FRST
2024-02-29 03:23 - 2024-02-29 03:23 - 002386944 _____ (Farbar) C:\Users\ferg_\Downloads\FRST64.exe
2024-02-29 02:58 - 2024-02-29 02:58 - 002932380 _____ C:\Users\ferg_\Downloads\Autoruns.zip
2024-02-29 02:58 - 2024-02-29 02:58 - 000000000 ____D C:\Users\ferg_\Downloads\Autoruns
2024-02-29 02:55 - 2024-02-29 02:55 - 000000000 ____D C:\Users\ferg_\AppData\Roaming\McAfee
2024-02-29 02:50 - 2024-02-29 02:50 - 000000000 ____D C:\Users\ferg_\AppData\Local\McAfee
2024-02-29 02:50 - 2024-02-29 02:50 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
2024-02-29 02:42 - 2024-02-29 02:42 - 000000000 ____D C:\ProgramData\McInstTemp0319031709192528
2024-02-27 22:56 - 2024-02-27 22:56 - 000000660 _____ C:\Users\ferg_\advanced_ip_scanner_MAC.bin
2024-02-27 22:56 - 2024-02-27 22:56 - 000000036 _____ C:\Users\ferg_\advanced_ip_scanner_Aliases.bin
2024-02-27 22:56 - 2024-02-27 22:56 - 000000015 _____ C:\Users\ferg_\advanced_ip_scanner_Comments.bin
2024-02-27 06:05 - 2024-02-27 06:10 - 000000000 ___HD C:\$MfeDeepRem
2024-02-27 06:05 - 2024-02-27 06:05 - 021050672 _____ (Famatech Corp. ) C:\Users\ferg_\Downloads\Advanced_IP_Scanner_2.5.4594.1.exe
2024-02-27 06:05 - 2024-02-27 06:05 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced IP Scanner v2
2024-02-27 06:05 - 2024-02-27 06:05 - 000000000 ____D C:\Program Files (x86)\Advanced IP Scanner
2024-02-27 05:45 - 2024-02-27 05:45 - 000000000 ____D C:\Program Files\McAfeeDashboard
2024-02-27 05:25 - 2024-02-27 05:25 - 000000000 ____D C:\Users\ferg_\AppData\Local\Backup
2024-02-27 04:13 - 2024-02-27 04:13 - 000031559 _____ C:\Users\ferg_\Downloads\Cash_App_January_2024_Account_Statement_015eca0bd37c25340d2153cfe2931b764fbbc1c321093d77825d62f8f00819980b01374aa74fc749c5a7f1c361484d701af0a96ba97bf245beecbc9454de595727b9.pdf
2024-02-27 03:59 - 2024-02-27 03:59 - 000068055 _____ C:\Users\ferg_\Downloads\direct-deposit-authorization-form-2c8f865ebe3523f42d7c534281a0ceea4164c0adf14400a1c93c40b1a8c9eb84.pdf
2024-02-27 03:51 - 2024-02-27 03:51 - 000000000 ____D C:\Users\ferg_\AppData\Local\CEF
2024-02-27 03:49 - 2024-02-29 02:41 - 000000000 ____D C:\ProgramData\McInstTemp0050921709023768
2024-02-27 03:48 - 2024-02-29 02:43 - 000003316 _____ C:\WINDOWS\system32\Tasks\McAfeeLogon
2024-02-27 03:46 - 2024-02-27 03:47 - 000000000 ____D C:\ProgramData\McInstTemp0044911709023584
2024-02-27 03:43 - 2024-02-27 03:43 - 000000000 ____D C:\ProgramData\DynamicAppDownloader
2024-02-26 00:22 - 2024-02-26 00:22 - 000000400 __RSH C:\ProgramData\ntuser.pol
2024-02-26 00:22 - 2024-02-26 00:22 - 000000000 ____D C:\Users\ferg_\AppData\Local\Rufus
2024-02-25 23:52 - 2024-02-26 00:03 - 3130513408 _____ C:\Users\ferg_\Downloads\HBCD_PE_x64.iso
2024-02-25 23:52 - 2024-02-25 23:52 - 001432648 _____ (Akeo Consulting) C:\Users\ferg_\Downloads\rufus-4.4.exe
2024-02-25 06:55 - 2024-02-27 03:44 - 000000000 ____D C:\WINDOWS\TempInst
2024-02-25 02:59 - 2024-02-25 02:59 - 000000000 ____D C:\Users\ferg_\AppData\Roaming\BetterHash
2024-02-25 02:55 - 2024-02-25 02:56 - 007009776 _____ (Innovative Solutions ) C:\Users\ferg_\Downloads\BetterHash_Setup.exe
2024-02-25 02:37 - 2024-02-25 02:58 - 000000000 ____D C:\Users\ferg_\AppData\Roaming\Dogecoin
2024-02-25 02:37 - 2024-02-25 02:37 - 015407720 _____ (Dogecoin Core project) C:\Users\ferg_\Downloads\dogecoin-1.14.6-win64-setup-unsigned.exe
2024-02-24 21:08 - 2024-02-24 21:08 - 000005463 _____ C:\Users\ferg_\Downloads\Nascar Heat 4 Setup Compilation - Atlanta.csv
2024-02-24 20:39 - 2024-02-24 20:39 - 000000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2024-02-23 13:06 - 2024-02-29 02:52 - 000000000 ____D C:\WINDOWS\system32\Tasks\McAfee
2024-02-23 13:06 - 2024-02-28 19:45 - 000003706 _____ C:\WINDOWS\system32\Tasks\McAfee Remediation (Prepare)
2024-02-23 13:06 - 2024-02-25 07:27 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2024-02-23 13:06 - 2024-02-23 13:06 - 000003408 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2024-02-23 13:06 - 2024-02-23 13:06 - 000003184 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2024-02-23 13:06 - 2024-02-23 13:06 - 000002854 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1946765252-2041723333-188045582-500
2024-02-23 13:06 - 2024-02-23 13:06 - 000000000 _SHDL C:\Users\Default User
2024-02-23 13:06 - 2024-02-23 13:06 - 000000000 _SHDL C:\Users\All Users
2024-02-23 13:06 - 2024-02-23 13:06 - 000000000 _SHDL C:\Documents and Settings
2024-02-23 13:06 - 2024-02-23 13:06 - 000000000 ____D C:\WINDOWS\system32\Tasks\Lenovo
2024-02-23 13:06 - 2024-02-23 13:06 - 000000000 ____D C:\WINDOWS\system32\Tasks\Intel
2024-02-23 13:06 - 2024-02-23 13:06 - 000000000 ____D C:\Users\Default\AppData\Roaming\Microsoft\Network
2024-02-23 13:06 - 2023-12-14 21:45 - 000002854 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1428055543-359601596-3697867768-500
2024-02-23 13:06 - 2020-11-26 20:06 - 000003390 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2623500204-34688127-2264388554-500
2024-02-23 13:06 - 2020-11-19 02:38 - 000003394 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3538912014-3826891016-3662973680-500
2024-02-23 13:02 - 2024-02-23 13:06 - 000000239 _____ C:\WINDOWS\system32\k9001_type_0_restore.txt
2024-02-23 13:02 - 2024-02-23 13:06 - 000000238 _____ C:\WINDOWS\system32\k900_type_0_restore.txt
2024-02-23 13:02 - 2024-02-23 13:02 - 000000591 _____ C:\WINDOWS\system32\regtest.txt
2024-02-23 13:02 - 2024-02-23 13:02 - 000000000 ____D C:\ProgramData\Intel
2024-02-23 13:02 - 2024-02-23 13:02 - 000000000 ____D C:\ProgramData\Dolby
2024-02-23 13:01 - 2024-02-29 02:29 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2024-02-23 13:01 - 2024-02-25 23:51 - 000002449 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2024-02-23 13:01 - 2024-02-25 07:27 - 000012288 ___SH C:\DumpStack.log.tmp
2024-02-23 13:01 - 2024-02-25 07:27 - 000000000 ____D C:\Intel
2024-02-23 13:01 - 2024-02-25 07:26 - 000001623 _____ C:\WINDOWS\system32\config\VSMIDK
2024-02-23 13:01 - 2024-02-24 15:33 - 000000000 ____D C:\ProgramData\Lenovo
2024-02-23 13:01 - 2024-02-23 13:01 - 000295552 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2024-02-23 13:01 - 2024-02-23 13:01 - 000000000 ____D C:\WINDOWS\system32\config\BFS
2024-02-23 13:01 - 2024-02-23 13:01 - 000000000 ____D C:\WINDOWS\ServiceProfiles
2024-02-23 13:00 - 2015-04-28 13:06 - 000043256 _____ C:\WINDOWS\system32\oemlogo.bmp
2024-02-23 12:59 - 2024-02-23 13:06 - 000000000 ____D C:\WINDOWS\Panther
2024-02-23 12:59 - 2024-02-23 12:59 - 000000000 ____D C:\WINDOWS\Lenovo
2024-02-23 12:58 - 2024-02-23 12:58 - 000000000 ____D C:\WINDOWS\system32\Drivers\Lenovo
2024-02-23 12:57 - 2024-02-23 13:08 - 000000000 ____D C:\WINDOWS\system32\FxsTmp
2024-02-23 12:57 - 2024-02-23 12:57 - 000008192 _____ C:\WINDOWS\system32\config\userdiff
2024-02-23 12:57 - 2024-02-23 12:57 - 000000000 ____D C:\WINDOWS\SysWOW64\MailContactsCalendarSync
2024-02-23 12:57 - 2024-02-23 12:57 - 000000000 ____D C:\WINDOWS\SysWOW64\FxsTmp
2024-02-23 12:57 - 2024-02-23 12:57 - 000000000 ____D C:\WINDOWS\system32\OpenSSH
2024-02-23 12:57 - 2024-02-23 12:57 - 000000000 ____D C:\WINDOWS\system32\MailContactsCalendarSync
2024-02-23 12:57 - 2024-02-23 12:57 - 000000000 ____D C:\WINDOWS\Setup
2024-02-23 12:57 - 2024-02-23 12:57 - 000000000 ____D C:\WINDOWS\addins
2024-02-23 12:57 - 2024-02-23 12:57 - 000000000 ____D C:\ProgramData\ssh
2024-02-23 12:56 - 2024-02-23 12:56 - 000000000 ____D C:\WINDOWS\SysWOW64\winrm
2024-02-23 12:56 - 2024-02-23 12:56 - 000000000 ____D C:\WINDOWS\SysWOW64\WCN
2024-02-23 12:56 - 2024-02-23 12:56 - 000000000 ____D C:\WINDOWS\SysWOW64\sysprep
2024-02-23 12:56 - 2024-02-23 12:56 - 000000000 ____D C:\WINDOWS\SysWOW64\slmgr
2024-02-23 12:56 - 2024-02-23 12:56 - 000000000 ____D C:\WINDOWS\SysWOW64\Printing_Admin_Scripts
2024-02-23 12:56 - 2024-02-23 12:56 - 000000000 ____D C:\WINDOWS\SysWOW64\0409
2024-02-23 12:56 - 2024-02-23 12:56 - 000000000 ____D C:\WINDOWS\system32\winrm
2024-02-23 12:56 - 2024-02-23 12:56 - 000000000 ____D C:\WINDOWS\system32\WCN
2024-02-23 12:56 - 2024-02-23 12:56 - 000000000 ____D C:\WINDOWS\system32\slmgr
2024-02-23 12:56 - 2024-02-23 12:56 - 000000000 ____D C:\WINDOWS\system32\Printing_Admin_Scripts
2024-02-23 12:56 - 2024-02-23 12:56 - 000000000 ____D C:\WINDOWS\system32\0409
2024-02-23 12:56 - 2024-02-23 12:56 - 000000000 ____D C:\WINDOWS\DigitalLocker
2024-02-23 12:55 - 2024-02-29 02:59 - 000000000 ____D C:\WINDOWS\SystemTemp
2024-02-23 12:55 - 2024-02-29 02:41 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2024-02-23 12:55 - 2024-02-29 02:29 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2024-02-23 12:55 - 2024-02-28 19:50 - 000000000 ____D C:\WINDOWS\AppReadiness
2024-02-23 12:55 - 2024-02-27 06:05 - 000000000 ___RD C:\Program Files (x86)
2024-02-23 12:55 - 2024-02-27 05:22 - 000000000 ____D C:\WINDOWS\appcompat
2024-02-23 12:55 - 2024-02-26 00:22 - 000000000 ___HD C:\Program Files\WindowsApps
2024-02-23 12:55 - 2024-02-25 07:27 - 000000000 ____D C:\WINDOWS\ServiceState
2024-02-23 12:55 - 2024-02-24 15:36 - 000000000 ____D C:\WINDOWS\system32\WebThreatDefSvc
2024-02-23 12:55 - 2024-02-23 13:08 - 000000000 ____D C:\WINDOWS\system32\AppLocker
2024-02-23 12:55 - 2024-02-23 13:06 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
2024-02-23 12:55 - 2024-02-23 13:06 - 000000000 ____D C:\WINDOWS\CSC
2024-02-23 12:55 - 2024-02-23 13:05 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2024-02-23 12:55 - 2024-02-23 13:04 - 000000000 ____D C:\WINDOWS\WaaS
2024-02-23 12:55 - 2024-02-23 13:04 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2024-02-23 12:55 - 2024-02-23 13:04 - 000000000 ____D C:\WINDOWS\system32\spool
2024-02-23 12:55 - 2024-02-23 13:03 - 000000000 ____D C:\Users\Default\AppData\Roaming\Microsoft\Windows
2024-02-23 12:55 - 2024-02-23 13:01 - 000000000 ____D C:\WINDOWS\system32\Drivers\DriverData
2024-02-23 12:55 - 2024-02-23 13:00 - 000000000 ____D C:\WINDOWS\system32\oobe
2024-02-23 12:55 - 2024-02-23 12:59 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template
2024-02-23 12:55 - 2024-02-23 12:57 - 000000000 ____D C:\WINDOWS\SysWOW64\vi-VN
2024-02-23 12:55 - 2024-02-23 12:57 - 000000000 ____D C:\WINDOWS\SysWOW64\id-ID
2024-02-23 12:55 - 2024-02-23 12:57 - 000000000 ____D C:\WINDOWS\SysWOW64\gl-ES
2024-02-23 12:55 - 2024-02-23 12:57 - 000000000 ____D C:\WINDOWS\SysWOW64\eu-ES
2024-02-23 12:55 - 2024-02-23 12:57 - 000000000 ____D C:\WINDOWS\SysWOW64\ca-ES
2024-02-23 12:55 - 2024-02-23 12:57 - 000000000 ____D C:\WINDOWS\SystemResources
2024-02-23 12:55 - 2024-02-23 12:57 - 000000000 ____D C:\WINDOWS\system32\vi-VN
2024-02-23 12:55 - 2024-02-23 12:57 - 000000000 ____D C:\WINDOWS\system32\setup
2024-02-23 12:55 - 2024-02-23 12:57 - 000000000 ____D C:\WINDOWS\system32\id-ID
2024-02-23 12:55 - 2024-02-23 12:57 - 000000000 ____D C:\WINDOWS\system32\gl-ES
2024-02-23 12:55 - 2024-02-23 12:57 - 000000000 ____D C:\WINDOWS\system32\eu-ES
2024-02-23 12:55 - 2024-02-23 12:57 - 000000000 ____D C:\WINDOWS\system32\ca-ES
2024-02-23 12:55 - 2024-02-23 12:57 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2024-02-23 12:55 - 2024-02-23 12:57 - 000000000 ____D C:\WINDOWS\OCR
2024-02-23 12:55 - 2024-02-23 12:57 - 000000000 ____D C:\WINDOWS\Globalization
2024-02-23 12:55 - 2024-02-23 12:56 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2024-02-23 12:55 - 2024-02-23 12:56 - 000000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs
2024-02-23 12:55 - 2024-02-23 12:56 - 000000000 ___SD C:\WINDOWS\system32\F12
2024-02-23 12:55 - 2024-02-23 12:56 - 000000000 ___SD C:\WINDOWS\system32\dsc
2024-02-23 12:55 - 2024-02-23 12:56 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2024-02-23 12:55 - 2024-02-23 12:56 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2024-02-23 12:55 - 2024-02-23 12:56 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2024-02-23 12:55 - 2024-02-23 12:56 - 000000000 ____D C:\WINDOWS\SysWOW64\MUI
2024-02-23 12:55 - 2024-02-23 12:56 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2024-02-23 12:55 - 2024-02-23 12:56 - 000000000 ____D C:\WINDOWS\SysWOW64\Com
2024-02-23 12:55 - 2024-02-23 12:56 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2024-02-23 12:55 - 2024-02-23 12:56 - 000000000 ____D C:\WINDOWS\system32\Sysprep
2024-02-23 12:55 - 2024-02-23 12:56 - 000000000 ____D C:\WINDOWS\system32\Sgrm
2024-02-23 12:55 - 2024-02-23 12:56 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
2024-02-23 12:55 - 2024-02-23 12:56 - 000000000 ____D C:\WINDOWS\system32\MUI
2024-02-23 12:55 - 2024-02-23 12:56 - 000000000 ____D C:\WINDOWS\system32\migwiz
2024-02-23 12:55 - 2024-02-23 12:56 - 000000000 ____D C:\WINDOWS\system32\Dism
2024-02-23 12:55 - 2024-02-23 12:56 - 000000000 ____D C:\WINDOWS\system32\Com
2024-02-23 12:55 - 2024-02-23 12:56 - 000000000 ____D C:\WINDOWS\IME
2024-02-23 12:55 - 2024-02-23 12:56 - 000000000 ____D C:\WINDOWS\Help
2024-02-23 12:55 - 2024-02-23 12:56 - 000000000 ____D C:\WINDOWS\BrowserCore
2024-02-23 12:55 - 2024-02-23 12:56 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2024-02-23 12:55 - 2024-02-23 12:56 - 000000000 ____D C:\Program Files\Windows NT
2024-02-23 12:55 - 2024-02-23 12:56 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2024-02-23 12:55 - 2024-02-23 12:56 - 000000000 ____D C:\Program Files\Common Files\System
2024-02-23 12:55 - 2024-02-23 12:56 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2024-02-23 12:55 - 2024-02-23 12:56 - 000000000 ____D C:\Program Files (x86)\Windows NT
2024-02-23 12:55 - 2024-02-23 12:56 - 000000000 ____D C:\Program Files (x86)\Windows Defender
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 __SHD C:\WINDOWS\BitLockerDiscoveryVolumeContents
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 __SHD C:\Program Files\Windows Sidebar
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 __SHD C:\Program Files (x86)\Windows Sidebar
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 __RHD C:\Users\Public\Libraries
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ___SD C:\WINDOWS\SysWOW64\Nui
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ___SD C:\WINDOWS\SysWOW64\lxss
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ___SD C:\WINDOWS\SysWOW64\Configuration
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ___SD C:\WINDOWS\system32\UNP
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ___SD C:\WINDOWS\system32\Nui
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ___SD C:\WINDOWS\system32\lxss
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ___SD C:\WINDOWS\system32\Configuration
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ___SD C:\WINDOWS\system32\AppV
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ___SD C:\WINDOWS\Downloaded Program Files
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ___RD C:\WINDOWS\Offline Web Pages
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ___HD C:\WINDOWS\LanguageOverlayCache
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\WUModels
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\Web
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\Vss
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\UUS
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\tracing
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\TAPI
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\SysWOW64\SMI
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\SysWOW64\ras
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\SysWOW64\PerceptionSimulation
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\SysWOW64\NDF
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\SysWOW64\Msdtc
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\SysWOW64\migwiz
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\SysWOW64\Keywords
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\SysWOW64\Ipmi
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\SysWOW64\InputMethod
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\SysWOW64\inetsrv
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\SysWOW64\IME
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\SysWOW64\icsxml
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\SysWOW64\GroupPolicyUsers
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\SysWOW64\downlevel
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\SysWOW64\Bthprops
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\SysWOW64\AppLocker
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\SystemApps
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\system32\winevt
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\system32\ras
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\system32\ProximityToast
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\system32\PointOfService
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\system32\Pbr
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\system32\NDF
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\system32\Microsoft-Edge-WebView
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\system32\Keywords
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\system32\Ipmi
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\system32\InputMethod
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\system32\inetsrv
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\system32\IME
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\system32\icsxml
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\system32\ias
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\system32\Hydrogen
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\system32\HealthAttestationClient
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\system32\DriverState
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\system32\Drivers\mde
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\system32\downlevel
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\system32\DDFs
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\system32\config\TxR
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\system32\config\systemprofile
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\system32\config\RegBack
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\system32\config\Journal
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\system32\Bthprops
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\system32\appraiser
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\system32\AdvancedInstallers
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\System
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\SKB
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\ShellExperiences
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\ShellComponents
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\security
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\schemas
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\SchCache
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\Resources
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\rescache
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\RemotePackages
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\Registration
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\Provisioning
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\PLA
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\Performance
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\ModemLogs
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\Media
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\L2Schemas
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\InputMethod
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\InboxApps
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\IdentityCRL
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\GameBarPresenceWriter
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\DiagTrack
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\Cursors
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\Containers
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\Branding
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\bcastdvr
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\Users\Default\AppData\Roaming\Microsoft\Spelling
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\ProgramData\WindowsHolographicDevices
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\ProgramData\USOShared
2024-02-23 12:55 - 2024-02-23 12:55 - 000000000 ____D C:\Program Files\ModifiableWindowsApps
2024-02-23 12:55 - 2024-02-23 12:54 - 000003103 _____ C:\WINDOWS\SysWOW64\mmc.exe.config
2024-02-23 12:55 - 2024-02-23 12:54 - 000003103 _____ C:\WINDOWS\system32\mmc.exe.config
2024-02-23 12:55 - 2024-02-23 12:54 - 000000858 _____ C:\WINDOWS\system32\DefaultQuestions.json
2024-02-23 12:55 - 2024-02-23 10:33 - 000000000 ___RD C:\WINDOWS\PrintDialog
2024-02-23 12:55 - 2024-02-23 10:32 - 000000000 ____D C:\ProgramData\USOPrivate
2024-02-23 12:55 - 2024-02-23 10:30 - 000000000 ____D C:\Program Files\Windows Defender
2024-02-23 12:55 - 2024-02-23 10:20 - 000000000 ____D C:\WINDOWS\system32\SecurityHealth
2024-02-23 12:55 - 2024-02-23 10:17 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2024-02-23 12:54 - 2024-02-29 03:23 - 000000000 ____D C:\WINDOWS\INF
2024-02-23 12:53 - 2024-02-29 02:40 - 000008192 _____ C:\WINDOWS\system32\config\ELAM
2024-02-23 12:53 - 2024-02-25 07:26 - 092012544 _____ C:\WINDOWS\system32\config\SOFTWARE
2024-02-23 12:53 - 2024-02-25 07:26 - 020185088 _____ C:\WINDOWS\system32\config\SYSTEM
2024-02-23 12:53 - 2024-02-25 07:26 - 000786432 _____ C:\WINDOWS\system32\config\DEFAULT
2024-02-23 12:53 - 2024-02-25 07:26 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2024-02-23 12:53 - 2024-02-25 07:26 - 000131072 _____ C:\WINDOWS\system32\config\SAM
2024-02-23 12:53 - 2024-02-25 07:26 - 000065536 _____ C:\WINDOWS\system32\config\SECURITY
2024-02-23 12:53 - 2024-02-23 12:55 - 000000000 ____D C:\WINDOWS\system32\SMI
2024-02-23 12:53 - 2024-02-23 10:31 - 000000000 ____D C:\WINDOWS\servicing
2024-02-23 12:53 - 2024-02-23 10:31 - 000000000 ____D C:\WINDOWS\CbsTemp
2024-02-23 12:31 - 2024-02-23 12:58 - 000000503 _____ C:\WINDOWS\system32\Drivers\etc\hosts.ics
2024-02-23 10:33 - 2024-02-23 10:33 - 000000000 ____D C:\Users\ferg_\AppData\Local\VirtualStore
2024-02-23 10:33 - 2024-02-23 10:33 - 000000000 ____D C:\Users\ferg_\AppData\Local\Comms
2024-02-23 10:32 - 2024-02-23 10:34 - 000000000 ____D C:\Users\ferg_\AppData\Local\Publishers
2024-02-23 10:21 - 2024-02-29 02:38 - 000000000 ____D C:\Users\ferg_\AppData\Local\D3DSCache
2024-02-23 10:21 - 2024-02-23 10:22 - 000000000 ____D C:\WINDOWS\system32\MRT
2024-02-23 10:20 - 2024-02-23 10:20 - 000000238 _____ C:\WINDOWS\system32\k202_type_0_restore.txt
2024-02-23 10:20 - 2024-02-23 10:20 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
2024-02-23 10:19 - 2024-02-23 10:20 - 000000000 ___RD C:\Users\ferg_\OneDrive
2024-02-23 10:19 - 2024-02-23 10:19 - 000000000 ____D C:\Users\ferg_\AppData\Local\PeerDistRepub
2024-02-23 10:18 - 2024-02-25 07:27 - 000000000 ____D C:\Users\ferg_\AppData\Local\PlaceholderTileLogoFolder
2024-02-23 10:18 - 2024-02-23 10:19 - 000000000 ____D C:\Users\ferg_\AppData\Local\Lenovo
2024-02-23 10:18 - 2024-02-23 10:18 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2024-02-23 10:17 - 2024-02-23 10:17 - 000000000 ____D C:\Users\ferg_\AppData\LocalLow\Intel
2024-02-23 10:16 - 2024-02-23 10:16 - 000001084 _____ C:\WINDOWS\system32\InstallUtil.InstallLog
2024-02-23 10:15 - 2024-02-28 19:43 - 000000000 __SHD C:\Users\ferg_\IntelGraphicsProfiles
2024-02-23 10:15 - 2024-02-25 07:27 - 000000000 ____D C:\Users\ferg_\AppData\Local\Packages
2024-02-23 10:15 - 2024-02-23 11:58 - 000000000 ____D C:\Users\ferg_\AppData\Local\ConnectedDevicesPlatform
2024-02-23 10:15 - 2024-02-23 10:15 - 000000000 ___SD C:\Users\ferg_\AppData\Roaming\Microsoft\Crypto
2024-02-23 10:15 - 2024-02-23 10:15 - 000000000 ____D C:\Users\ferg_\AppData\Roaming\Microsoft\Vault
2024-02-23 10:15 - 2024-02-23 10:15 - 000000000 ____D C:\Users\ferg_\AppData\Roaming\Adobe
2024-02-23 10:13 - 2024-02-23 10:13 - 000000000 ___SD C:\Users\ferg_\AppData\Roaming\Microsoft\SystemCertificates
2024-02-23 10:12 - 2024-02-27 22:56 - 000000000 ____D C:\Users\ferg_
2024-02-23 10:12 - 2024-02-23 13:06 - 000000000 ____D C:\Users\ferg_\AppData\Roaming\Microsoft\Network
2024-02-23 10:12 - 2024-02-23 10:21 - 000000000 ____D C:\Users\ferg_\AppData\Roaming\Microsoft\Spelling
2024-02-23 10:12 - 2024-02-23 10:17 - 000000000 ____D C:\Users\ferg_\AppData\Roaming\Microsoft\Windows
2024-02-23 10:12 - 2024-02-23 10:12 - 000000020 ___SH C:\Users\ferg_\ntuser.ini
2024-02-23 10:12 - 2024-02-23 10:12 - 000000000 ___SD C:\Users\ferg_\AppData\Roaming\Microsoft\Protect
2024-02-23 10:12 - 2024-02-23 10:12 - 000000000 ___SD C:\Users\ferg_\AppData\Roaming\Microsoft\Credentials
2024-02-23 10:10 - 2024-02-25 07:32 - 000805616 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2024-02-23 09:50 - 2024-02-23 13:00 - 000000000 ___HD C:\$SysReset
 
==================== One month (modified) ==================
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2024-02-29 02:50 - 2023-12-14 21:59 - 000000000 ____D C:\ProgramData\McAfee
2024-02-29 02:44 - 2023-12-14 21:59 - 000000000 ____D C:\Program Files\Common Files\McAfee
2024-02-29 02:43 - 2023-12-14 21:59 - 000000000 ____D C:\Program Files\McAfee
2024-02-27 22:57 - 2020-11-19 02:30 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2024-02-27 05:45 - 2023-12-14 21:59 - 000000000 ____D C:\Program Files (x86)\McAfee
2024-02-27 03:50 - 2019-12-07 04:14 - 000000124 _____ C:\WINDOWS\win.ini
2024-02-25 23:52 - 2019-12-07 04:14 - 000000000 ___HD C:\WINDOWS\system32\GroupPolicy
2024-02-25 07:27 - 2020-11-19 02:33 - 000000000 ____D C:\ProgramData\Packages
2024-02-23 13:06 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\Tasks_Migrated
2024-02-23 13:04 - 2023-12-14 21:59 - 000000000 ____D C:\ProgramData\McInstTemp0293021702609191
2024-02-23 13:04 - 2023-12-14 21:59 - 000000000 ____D C:\Program Files\McAfee.com
2024-02-23 13:04 - 2023-12-14 21:59 - 000000000 ____D C:\Program Files\Common Files\AV
2024-02-23 13:04 - 2023-12-14 21:59 - 000000000 ____D C:\Program Files (x86)\Lenovo
2024-02-23 13:04 - 2023-12-14 21:55 - 000000000 ____D C:\Program Files\Intel
2024-02-23 13:04 - 2023-12-14 21:55 - 000000000 ____D C:\DRIVER
2024-02-23 13:04 - 2023-12-14 21:52 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools
2024-02-23 13:04 - 2023-12-14 21:50 - 000000000 ____D C:\Program Files\Microsoft Office 15
2024-02-23 13:04 - 2023-12-14 21:50 - 000000000 ____D C:\Program Files\Microsoft Office
2024-02-23 13:04 - 2023-12-14 21:50 - 000000000 ____D C:\Program Files\Lenovo
2024-02-23 13:04 - 2023-12-14 21:50 - 000000000 ____D C:\Program Files\Common Files\DESIGNER
2024-02-23 13:04 - 2023-12-14 21:49 - 000000000 ____D C:\ProgramData\Package Cache
2024-02-23 13:04 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2024-02-23 13:04 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\Macromed
2024-02-23 13:04 - 2019-12-07 04:14 - 000000000 ____D C:\Program Files\Windows Security
2024-02-23 13:03 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\MsDtc
2024-02-23 10:18 - 2020-11-19 02:33 - 000000000 __RHD C:\Users\Public\AccountPictures
 
==================== SigCheck ============================
 
(There is no automatic fix for files that do not pass verification.)
 
==================== End of FRST.txt ========================
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 26.02.2024 01
Ran by ferg_ (29-02-2024 03:24:56)
Running from C:\Users\ferg_\Downloads
Microsoft Windows 11 Pro Version 23H2 22631.3155 (X64) (2024-02-23 18:06:39)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
 
(If an entry is included in the fixlist, it will be removed.)
 
Administrator (S-1-5-21-3652864268-2719191564-4212199372-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-3652864268-2719191564-4212199372-503 - Limited - Disabled)
ferg_ (S-1-5-21-3652864268-2719191564-4212199372-1001 - Administrator - Enabled) => C:\Users\ferg_
Guest (S-1-5-21-3652864268-2719191564-4212199372-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-3652864268-2719191564-4212199372-504 - Limited - Disabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: McAfee VirusScan (Enabled - Up to date) {FE987762-0FB6-6BB6-1BF1-73F8ED8566FA}
FW: McAfee Firewall (Enabled) {C6A3F647-45D9-6AEE-30AE-DACD13562181}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Advanced IP Scanner 2.5.1 (HKLM-x32\...\{C8511AEB-814C-4D6F-AA45-44035EAD563B}) (Version: 2.5.4594.1 - Famatech)
Intel® Chipset Device Software (HKLM\...\{368C1112-09E1-4EE3-A274-9118DF101CA9}) (Version: 10.1.18460.8229 - Intel Corporation) Hidden
Intel® Chipset Device Software (HKLM-x32\...\{a2c684b7-4a4b-425f-a805-1e88940804b0}) (Version: 10.1.18460.8229 - Intel® Corporation)
Lenovo Vantage Service (HKLM-x32\...\VantageSRV_is1) (Version: 4.0.52.0 - Lenovo Group Ltd.)
McAfee® (HKLM-x32\...\MSC) (Version: 16.0 R53 - McAfee, LLC)
Microsoft 365 - en-us (HKLM\...\O365HomePremRetail - en-us) (Version: 16.0.13127.20616 - Microsoft Corporation)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 122.0.2365.52 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 122.0.2365.52 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{C6FD611E-7EFE-488C-A0E0-974C09EF6473}) (Version: 5.72.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.26.28720 (HKLM-x32\...\{7d607fb4-7e28-4c7a-a92f-3fcdaf555faf}) (Version: 14.26.28720.3 - Microsoft Corporation)
Microsoft Visual C++ 2019 X64 Additional Runtime - 14.26.28720 (HKLM\...\{CB4A0FDE-1126-4AE2-97C6-A243692C3D95}) (Version: 14.26.28720 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2019 X64 Minimum Runtime - 14.26.28720 (HKLM\...\{DD1EC0FD-3F0A-4740-A05E-1DCD14A6B0D1}) (Version: 14.26.28720 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.13127.20616 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.13127.20616 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0409-1000-0000000FF1CE}) (Version: 16.0.13127.20616 - Microsoft Corporation) Hidden
 
Packages:
=========
 
8 Ball Billiards - Super Challenge -> C:\Program Files\WindowsApps\7817LissyWooInc.8BallBilliards-SuperChallenge_1.0.9.0_x64__dpfj2md5wt7vw [2024-02-24] (Lissy Woo Inc)
Amazon Alexa -> C:\Program Files\WindowsApps\57540AMZNMobileLLC.AmazonAlexa_3.25.1156.0_x64__22t9g3sebte08 [2024-02-23] (AMZN Mobile LLC.) [Startup Task]
AppUp.IntelGraphicsExperience -> C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.5336.0_x64__8j3eq9eme6ctt [2024-02-23] (INTEL CORP) [Startup Task]
AppUp.ThunderboltControlCenter -> C:\Program Files\WindowsApps\appup.thunderboltcontrolcenter_1.0.37.0_x64__8j3eq9eme6ctt [2024-02-23] (INTEL CORP)
Dev Home -> C:\Program Files\WindowsApps\Microsoft.Windows.DevHome_0.1100.416.0_x64__8wekyb3d8bbwe [2024-02-24] (Microsoft Corporation)
Dolby Atmos Speaker System -> C:\Program Files\WindowsApps\dolbylaboratories.dolbyatmosspeakersystem_3.30100.101.0_x64__rz1tebttyb220 [2024-02-23] (Dolby Laboratories)
Facebook -> C:\Program Files\WindowsApps\FACEBOOK.FACEBOOK_2023.531.1.0_x64__8xx8rvfyw5nnt [2024-02-27] (Meta)
Glance by Mirametrix® -> C:\Program Files\WindowsApps\mirametrixinc.glancebymirametrix_10.24.1787.0_x64__17mer8kcn3j54 [2024-02-23] (Mirametrix Inc.) [Startup Task]
Ink.Handwriting.en-US.1.0 -> C:\Program Files\WindowsApps\microsoft.ink.handwriting.en-us.1.0_0.237.110.0_x64__8wekyb3d8bbwe [2024-02-25] (Microsoft Corporation)
Ink.Handwriting.en-US.1.0 -> C:\Program Files\WindowsApps\microsoft.ink.handwriting.en-us.1.0_0.237.110.0_x86__8wekyb3d8bbwe [2024-02-25] (Microsoft Corporation)
Ink.Handwriting.Main.en-US.1.0 -> C:\Program Files\WindowsApps\Microsoft.Ink.Handwriting.Main.en-US.1.0.1_0.237.110.0_x64__8wekyb3d8bbwe [2024-02-25] (Microsoft Corporation)
Lenovo Companion -> C:\Program Files\WindowsApps\E046963F.LenovoCompanion_10.2401.24.0_x64__k1h2ywk1493x8 [2024-02-23] (LENOVO INC.)
Lenovo Hotkeys -> C:\Program Files\WindowsApps\E0469640.LenovoUtility_4.5.109.0_x64__5grkq8ppsgwt4 [2024-02-23] (LENOVO INC) [Startup Task]
Lenovo Pen Settings -> C:\Program Files\WindowsApps\WacomTechnologyCorp.157535B83C264_8.2.2.0_neutral__ss941bf8mfs8a [2024-02-25] (Wacom Technology Corp.)
Microsoft Defender -> C:\Program Files\WindowsApps\Microsoft.6365217CE6EB4_102.2402.13002.0_x64__8wekyb3d8bbwe [2024-02-25] (Microsoft Corporation) [Startup Task]
Microsoft.WindowsAppRuntime.CBS -> C:\Windows\SystemApps\Microsoft.WindowsAppRuntime.CBS_8wekyb3d8bbwe [2024-02-23] (Microsoft Corporation)
OneDrive -> C:\Program Files\WindowsApps\microsoft.microsoftskydrive_19.23.19.0_x64__8wekyb3d8bbwe [2024-02-23] (Microsoft Corporation)
Power Automate -> C:\Program Files\WindowsApps\Microsoft.PowerAutomateDesktop_11.2402.223.0_x64__8wekyb3d8bbwe [2024-02-23] (Microsoft Corporation) [Startup Task]
Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.16.228.0_x64__dt26b99r8h8gj [2024-02-23] (Realtek Semiconductor Corp)
Smart Microphone Setting -> C:\Program Files\WindowsApps\4505Fortemedia.FMAPOControl_1.0.38.0_x64__4pejv7q2gmsnr [2024-02-23] (Fortemedia)
Solitaire & Casual Games -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.19.1262.0_x64__8wekyb3d8bbwe [2024-02-23] (Microsoft Studios) [MS Ad]
Spotify Music -> C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.231.1205.0_x64__zpdnekdrzrea0 [2024-02-23] (Spotify AB) [Startup Task]
WinAppRuntime.Main.1.4 -> C:\Program Files\WindowsApps\microsoftcorporationii.winappruntime.main.1.4_4000.1136.2333.0_x64__8wekyb3d8bbwe [2024-02-23] (Microsoft Corp.)
WinAppRuntime.Singleton -> C:\Program Files\WindowsApps\microsoftcorporationii.winappruntime.singleton_4000.1136.2333.0_x64__8wekyb3d8bbwe [2024-02-23] (Microsoft Corp.)
Windows App Runtime DDLM 4000.964.11.0-x6 -> C:\Program Files\WindowsApps\microsoft.winappruntime.ddlm.4000.964.11.0-x6_4000.964.11.0_x64__8wekyb3d8bbwe [2024-02-23] (Microsoft Corporation)
Windows App Runtime DDLM 4000.964.11.0-x8 -> C:\Program Files\WindowsApps\microsoft.winappruntime.ddlm.4000.964.11.0-x8_4000.964.11.0_x86__8wekyb3d8bbwe [2024-02-23] (Microsoft Corporation)
Windows Feature Experience Pack -> C:\Windows\SystemApps\MicrosoftWindows.Client.FileExp_cw5n1h2txyewy [2024-02-23] (Microsoft Corporation)
 
==================== Custom CLSID (Whitelisted): ==============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  -> No File
ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} =>  -> No File
ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} =>  -> No File
ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  -> No File
ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  -> No File
ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} =>  -> No File
ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} =>  -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} =>  -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} =>  -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} =>  -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} =>  -> No File
ContextMenuHandlers1: [McCtxMenuFrmWrk] -> {CCA9EFD3-29ED-430A-BA6D-E6BBFF0A60C2} => C:\Program Files\McAfee\MSC\McCtxMenuFrmWrk.dll [2023-10-05] (McAfee, LLC -> McAfee, LLC)
ContextMenuHandlers6: [McCtxMenuFrmWrk] -> {CCA9EFD3-29ED-430A-BA6D-E6BBFF0A60C2} => C:\Program Files\McAfee\MSC\McCtxMenuFrmWrk.dll [2023-10-05] (McAfee, LLC -> McAfee, LLC)
 
==================== Codecs (Whitelisted) ====================
 
==================== Shortcuts & WMI ========================
 
==================== Loaded Modules (Whitelisted) =============
 
==================== Alternate Data Streams (Whitelisted) ========
 
==================== Safe Mode (Whitelisted) ==================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ModuleCoreService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcapexe => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfemms => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeplk => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeplk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ModuleCoreService => ""="Service"
 
==================== Association (Whitelisted) =================
 
==================== Internet Explorer (Whitelisted) ==========
 
HKU\S-1-5-21-3652864268-2719191564-4212199372-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://mystart.lenovo.com/
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2023-12-14] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2023-12-14] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2023-12-14] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2023-12-14] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2023-12-14] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2023-12-14] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2023-12-14] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2023-12-14] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2023-12-14] (Microsoft Corporation -> Microsoft Corporation)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - C:\Program Files\McAfee\MSC\McSnIePl64.dll [2023-10-05] (McAfee, LLC -> McAfee, LLC)
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - C:\Program Files (x86)\McAfee\MSC\McSnIePl.dll [2023-10-05] (McAfee, LLC -> McAfee, LLC)
 
==================== Hosts content: =========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2019-12-07 04:14 - 2019-12-07 04:12 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts
 
2024-02-23 12:31 - 2024-02-23 12:58 - 000000503 _____ C:\WINDOWS\system32\drivers\etc\hosts.ics
 
==================== Other Areas ===========================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-3652864268-2719191564-4212199372-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\ferg_\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
DNS Servers: 75.75.75.75 - 75.75.76.76
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
==================== FirewallRules (Whitelisted) ================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{D1A4BBCF-58C1-4F4F-84FE-B71345AA8B0A}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe => No File
FirewallRules: [{C45CB2C3-E3C6-4C47-B37A-F480AA5DBB5A}] => (Allow) C:\Program Files (x86)\Common Files\McAfee\MMSSHost\MMSSHost.exe (McAfee, LLC -> McAfee, LLC)
FirewallRules: [{9521853A-109F-4741-8EE3-E5BFEA106C84}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{98D779BD-513E-4BA4-936D-D723CE3214F5}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.231.1205.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{0C16F744-CA7E-4BE7-A615-FD572B527D0A}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.231.1205.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{8EE922AB-E3F9-4B44-8C66-15B485860CD5}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.231.1205.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{35E047CF-8762-4DD3-89F3-F1E930CB1512}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.231.1205.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{AF3AD4B0-7379-436D-8572-32C2190618DC}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.231.1205.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{CF4CF489-1703-4F74-B4CC-CDEAB679BA51}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.231.1205.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{44C5C1D4-4F40-4CFA-B450-1ACB21763E58}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.231.1205.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{6BAA8E8D-5888-4B9A-B4F5-A8A5C0DE0BFB}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.231.1205.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{FA75869F-6AF1-48AF-9D20-EF9FA271636F}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.231.1205.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{B6271B79-E53E-442D-B0B1-5AB7D403954B}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.231.1205.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [TCP Query User{C3DFB11C-247E-4EC4-AAD2-5727BB451339}C:\program files\dogecoin\dogecoin-qt.exe] => (Allow) C:\program files\dogecoin\dogecoin-qt.exe => No File
FirewallRules: [UDP Query User{CE380620-BA9F-479B-969A-FD5BA79EDF48}C:\program files\dogecoin\dogecoin-qt.exe] => (Allow) C:\program files\dogecoin\dogecoin-qt.exe => No File
FirewallRules: [{7631544A-805D-4334-9246-85F797C7412E}] => (Allow) C:\Program Files (x86)\BetterHash\Cores\xmrig-cpu\xmrig.exe => No File
FirewallRules: [{9D64B502-4963-4BF8-8A2B-B379F33D05C8}] => (Allow) C:\Program Files (x86)\BetterHash\Cores\xmrig-cpu\xmrig.exe => No File
FirewallRules: [{9DC04A61-75F1-449A-AB09-36E1F78005CB}] => (Allow) C:\Program Files (x86)\BetterHash\Cores\equihash\powercore-main-g.exe => No File
FirewallRules: [{8C056905-55B6-4727-9F88-6CC0C75B82B7}] => (Allow) C:\Program Files (x86)\BetterHash\Cores\equihash\powercore-main-g.exe => No File
FirewallRules: [{66706FA5-60D8-491D-B1D9-8D2B26F5340F}] => (Allow) C:\Program Files (x86)\BetterHash\Cores\ewbf\miner.exe => No File
FirewallRules: [{1082D0BA-B688-4504-ABFB-4FBC8C89E0AE}] => (Allow) C:\Program Files (x86)\BetterHash\Cores\ewbf\miner.exe => No File
FirewallRules: [{E14F4486-26C0-473C-B5C5-72DA497E135B}] => (Allow) C:\Program Files (x86)\BetterHash\Cores\xmrig-amd\xmrig-amd.exe => No File
FirewallRules: [{5C0E4A9E-6974-4BBF-8D7E-B5D4F3920F06}] => (Allow) C:\Program Files (x86)\BetterHash\Cores\xmrig-amd\xmrig-amd.exe => No File
FirewallRules: [{3ABE60CA-AC06-42C9-8132-F3456D6DB864}] => (Allow) C:\Program Files (x86)\BetterHash\Cores\ccminer-cryptonight-x64\ccminer-cryptonight.exe => No File
FirewallRules: [{961AFFFD-2EC3-4CF5-9714-B82A3CE79DF2}] => (Allow) C:\Program Files (x86)\BetterHash\Cores\ccminer-cryptonight-x64\ccminer-cryptonight.exe => No File
FirewallRules: [{DD9D86D2-A41E-4113-A62F-218D661C3A7B}] => (Allow) C:\Program Files (x86)\BetterHash\Cores\gminer-etchash\gminer-etc.exe => No File
FirewallRules: [{0FD17FEB-1124-449F-BD68-CD24B5772E00}] => (Allow) C:\Program Files (x86)\BetterHash\Cores\gminer-etchash\gminer-etc.exe => No File
FirewallRules: [{B8CFCFBE-D8B8-42F6-93AF-15A6DAA7381E}] => (Allow) C:\Program Files (x86)\BetterHash\Cores\d3-dash\scpd3.exe => No File
FirewallRules: [{2280B595-21A9-4C41-8280-DA68A325AA5E}] => (Allow) C:\Program Files (x86)\BetterHash\Cores\d3-dash\scpd3.exe => No File
FirewallRules: [{D1DBEAF3-298A-4FF7-A55C-2DB9145C8217}] => (Allow) C:\Program Files (x86)\BetterHash\Cores\z9-zcash\scpz9.exe => No File
FirewallRules: [{91B9D6C5-0305-400D-889E-D72E011D3393}] => (Allow) C:\Program Files (x86)\BetterHash\Cores\z9-zcash\scpz9.exe => No File
FirewallRules: [{CEED6DCA-B7FE-418F-A296-DD83A240DB6B}] => (Allow) C:\Program Files (x86)\BetterHash\Cores\gminer-zhash\gminer-zh.exe => No File
FirewallRules: [{7B151DAE-0655-4F51-8A63-E5AD0E1A1DEE}] => (Allow) C:\Program Files (x86)\BetterHash\Cores\gminer-zhash\gminer-zh.exe => No File
FirewallRules: [{22D79A27-FF9A-4833-BB8D-B9847B377C74}] => (Allow) C:\Program Files (x86)\BetterHash\Cores\gminer-zhash-amd\gminer-zh-amd.exe => No File
FirewallRules: [{5FD4C2E4-91EA-4900-804E-F0FC10179031}] => (Allow) C:\Program Files (x86)\BetterHash\Cores\gminer-zhash-amd\gminer-zh-amd.exe => No File
FirewallRules: [{730CAC8D-0A4D-4BCA-B832-09BCFA992338}] => (Allow) C:\Program Files (x86)\BetterHash\Cores\gminer-rvn\gminer-rvn.exe => No File
FirewallRules: [{FF7486B6-27E7-44D0-AC86-9758CB9A0E4D}] => (Allow) C:\Program Files (x86)\BetterHash\Cores\gminer-rvn\gminer-rvn.exe => No File
FirewallRules: [{17AA6899-5CDF-436E-9B99-93405D760CCD}] => (Allow) C:\Program Files (x86)\BetterHash\Cores\teamredminer-cryptonight\teamredminer.exe => No File
FirewallRules: [{295C2360-B2A9-4A29-900A-F04563233B63}] => (Allow) C:\Program Files (x86)\BetterHash\Cores\teamredminer-cryptonight\teamredminer.exe => No File
FirewallRules: [{A3A9CE93-EAD1-4AED-AC33-D33DA3BFB92B}] => (Allow) C:\Program Files (x86)\BetterHash\Cores\nbminer-grin\nbminer-grin.exe => No File
FirewallRules: [{3368BBEF-78E4-4F07-98CC-E033D6809858}] => (Allow) C:\Program Files (x86)\BetterHash\Cores\nbminer-grin\nbminer-grin.exe => No File
FirewallRules: [{9BCD1D94-C9D0-4487-BE64-0815C805802B}] => (Allow) C:\Program Files (x86)\BetterHash\Cores\nbminer-grin29\nbminer-grin29.exe => No File
FirewallRules: [{BCD7B353-6A0B-44E8-9DB7-790E1D3444DB}] => (Allow) C:\Program Files (x86)\BetterHash\Cores\nbminer-grin29\nbminer-grin29.exe => No File
FirewallRules: [{6B36340A-6861-42BA-A02A-7766DBB7EB4A}] => (Allow) C:\Program Files (x86)\BetterHash\Cores\t-rex-firo\t-rex-firo.exe => No File
FirewallRules: [{27F0519C-48CC-4C32-AA6B-71F95E481607}] => (Allow) C:\Program Files (x86)\BetterHash\Cores\t-rex-firo\t-rex-firo.exe => No File
FirewallRules: [{8DDA501A-70CA-401D-AB8C-A40505EA1532}] => (Allow) C:\Program Files (x86)\BetterHash\Cores\lol-beam\lolMiner-beam.exe => No File
FirewallRules: [{E3498960-F677-4A9E-9793-9BABFA98AC4D}] => (Allow) C:\Program Files (x86)\BetterHash\Cores\lol-beam\lolMiner-beam.exe => No File
FirewallRules: [{F366698B-F28C-410C-91AE-45DA3BBA07ED}] => (Allow) C:\Program Files (x86)\BetterHash\Cores\lol-flux\lolMiner-flux.exe => No File
FirewallRules: [{1A84D62C-0C25-466D-9617-EF4387C39FB8}] => (Allow) C:\Program Files (x86)\BetterHash\Cores\lol-flux\lolMiner-flux.exe => No File
FirewallRules: [{C9BF0835-88C4-4D2E-A3A2-F3D837716C1D}] => (Allow) C:\Program Files (x86)\BetterHash\Cores\lol-ergo\lolMiner-ergo.exe => No File
FirewallRules: [{E516DE1D-12CD-4ED7-AF83-242786222378}] => (Allow) C:\Program Files (x86)\BetterHash\Cores\lol-ergo\lolMiner-ergo.exe => No File
FirewallRules: [{A2052A20-9388-4901-AB91-873A92C5C8D8}] => (Allow) C:\Program Files (x86)\BetterHash\Cores\phoenixminer-eth\phoenixminer-eth.exe => No File
FirewallRules: [{196A0534-8FA7-4E43-9531-486D044F798B}] => (Allow) C:\Program Files (x86)\BetterHash\Cores\phoenixminer-eth\phoenixminer-eth.exe => No File
FirewallRules: [{C3E87C73-4F28-4C82-AFFF-1E12809EC93D}] => (Allow) C:\Program Files (x86)\BetterHash\Cores\gminer-cfx\gminer-cfx.exe => No File
FirewallRules: [{FB990B34-80E5-4D2D-BD05-5840503A439D}] => (Allow) C:\Program Files (x86)\BetterHash\Cores\gminer-cfx\gminer-cfx.exe => No File
FirewallRules: [{A394F54B-85FD-453E-BF52-0879C4E6511F}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.113.3210.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{829E92AA-D2B7-4128-8253-1A768B087A5E}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.113.3210.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{C47EB858-5E07-419D-99CD-D339EF97AE71}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.113.3210.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{1041AB15-E7FA-4274-9F86-205DD189EB93}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.113.3210.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{9399C6DE-3DB3-4347-BB5A-BAA8A9C86111}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\122.0.2365.52\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{A83F5E5A-2C67-48AF-9940-545697526650}] => (Allow) C:\Program Files\Common Files\McAfee\MMSSHost\MMSSHost.exe (McAfee, LLC -> McAfee, LLC)
 
==================== Restore Points =========================
 
ATTENTION: System Restore is disabled (Total:216.33 GB) (Free:164.56 GB) (76%)
 
==================== Faulty Device Manager Devices ============
 
 
==================== Event log errors: ========================
 
Application errors:
==================
Error: (02/29/2024 03:12:02 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: Activation context generation failed for "C:\Users\ferg_\Downloads\Autoruns\Autoruns.exe".Error in manifest or policy file "" on line .
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.22621.2506_none_6eb991c088050a06.manifest.
Component 2: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.22621.2506_none_270c5ae97388e100.manifest.
 
Error: (02/29/2024 02:58:40 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: Activation context generation failed for "C:\Users\ferg_\Downloads\Autoruns\Autoruns.exe".Error in manifest or policy file "" on line .
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.22621.2506_none_6eb991c088050a06.manifest.
Component 2: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.22621.2506_none_270c5ae97388e100.manifest.
 
Error: (02/29/2024 02:58:36 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: Activation context generation failed for "C:\Users\ferg_\Downloads\Autoruns\Autoruns.exe".Error in manifest or policy file "" on line .
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.22621.2506_none_6eb991c088050a06.manifest.
Component 2: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.22621.2506_none_270c5ae97388e100.manifest.
 
Error: (02/29/2024 02:41:18 AM) (Source: Application Error) (EventID: 1000) (User: NT AUTHORITY)
Description: Faulting application name: mfevtps.exe, version: 21.9.0.184, time stamp: 0x6144db15
Faulting module name: CRYPT32.dll, version: 10.0.22621.2506, time stamp: 0x9caf0168
Exception code: 0xc0000005
Fault offset: 0x000000000001ff72
Faulting process id: 0x0x1290
Faulting application start time: 0x0x1da6959a5f650ca
Faulting application path: C:\Windows\system32\mfevtps.exe
Faulting module path: C:\WINDOWS\SYSTEM32\CRYPT32.dll
Report Id: 186398ae-e868-4f9a-a26e-4afeaaf79307
Faulting package full name: 
Faulting package-relative application ID:
 
Error: (02/25/2024 04:40:53 PM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1552) (User: NT AUTHORITY)
Description: User hive is loaded by another process (Registry Lock) Process name: C:\Program Files (x86)\Lenovo\VantageService\4.0.52.0\LenovoVantageService.exe, PID: 4892, ProfSvc PID: 2132.
 
Error: (02/25/2024 04:40:53 PM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1552) (User: NT AUTHORITY)
Description: User hive is loaded by another process (Registry Lock) Process name: C:\Windows\System32\svchost.exe, PID: 13196, ProfSvc PID: 2132.
 
Error: (02/25/2024 04:40:53 PM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1552) (User: NT AUTHORITY)
Description: User hive is loaded by another process (Registry Lock) Process name: C:\Windows\System32\svchost.exe, PID: 13196, ProfSvc PID: 2132.
 
Error: (02/25/2024 04:40:53 PM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1552) (User: NT AUTHORITY)
Description: User hive is loaded by another process (Registry Lock) Process name: C:\Windows\System32\svchost.exe, PID: 13196, ProfSvc PID: 2132.
 
 
System errors:
=============
Error: (02/29/2024 02:44:16 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Print Spooler service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 5000 milliseconds: Restart the service.
 
Error: (02/27/2024 10:56:24 PM) (Source: Microsoft-Windows-NDIS) (EventID: 10317) (User: )
Description: Miniport Microsoft Wi-Fi Direct Virtual Adapter #2, {58582eb9-47d7-4bc6-bc07-2de6b8c453f0}, had event 74
 
Error: (02/27/2024 05:39:23 PM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
Description: The server {A463FCB9-6B1C-4E0D-A80B-A2CA7999E25D} did not register with DCOM within the required timeout.
 
Error: (02/27/2024 06:52:05 AM) (Source: DCOM) (EventID: 10028) (User: COREY)
Description: DCOM was unable to communicate with the computer 192.168.4.22 using any of the configured protocols; requested by PID     4e30 (C:\Program Files (x86)\Advanced IP Scanner\advanced_ip_scanner.exe), while activating CLSID {8BC3F05E-D86B-11D0-A075-00C04FB68820}.
 
Error: (02/27/2024 06:51:48 AM) (Source: DCOM) (EventID: 10028) (User: COREY)
Description: DCOM was unable to communicate with the computer 192.168.4.69 using any of the configured protocols; requested by PID     4e30 (C:\Program Files (x86)\Advanced IP Scanner\advanced_ip_scanner.exe), while activating CLSID {8BC3F05E-D86B-11D0-A075-00C04FB68820}.
 
Error: (02/27/2024 06:51:48 AM) (Source: DCOM) (EventID: 10028) (User: COREY)
Description: DCOM was unable to communicate with the computer 192.168.4.31 using any of the configured protocols; requested by PID     4e30 (C:\Program Files (x86)\Advanced IP Scanner\advanced_ip_scanner.exe), while activating CLSID {8BC3F05E-D86B-11D0-A075-00C04FB68820}.
 
Error: (02/27/2024 06:51:45 AM) (Source: DCOM) (EventID: 10028) (User: COREY)
Description: DCOM was unable to communicate with the computer 192.168.4.27 using any of the configured protocols; requested by PID     4e30 (C:\Program Files (x86)\Advanced IP Scanner\advanced_ip_scanner.exe), while activating CLSID {8BC3F05E-D86B-11D0-A075-00C04FB68820}.
 
Error: (02/27/2024 06:51:45 AM) (Source: DCOM) (EventID: 10028) (User: COREY)
Description: DCOM was unable to communicate with the computer 192.168.4.43 using any of the configured protocols; requested by PID     4e30 (C:\Program Files (x86)\Advanced IP Scanner\advanced_ip_scanner.exe), while activating CLSID {8BC3F05E-D86B-11D0-A075-00C04FB68820}.
 
 
Windows Defender:
================
Date: 2024-02-26 00:07:30
Description: 
Microsoft Defender Antivirus has detected a suspicious behavior.
Name: Behavior:Win32/ModifiedBootRecord
Severity: Low
Category: Suspicious Behavior
Path Found: file:_C:\Users\ferg_\Downloads\rufus-4.4.exe; process:_8988
Detection Origin: Local machine
Detection Type: Suspicious
Detection Source: Real-Time Protection
Status: Executing
Process Name: C:\Users\ferg_\Downloads\rufus-4.4.exe
Security intelligence ID: 23858570787236
Security intelligence Version: AV: 1.405.575.0, AS: 1.405.575.0
Engine Version: 1.1.24010.10
Fidelity Label:  Medium
Target File Name:  
 
 
Date: 2024-02-25 23:52:53
Description: 
Microsoft Defender Antivirus has detected potentially unwanted application(PUA).
For more information please see the following:
Name: PUABundler:Win32/ICBundler
Severity: Low
Category: Potentially Unwanted Software
Path: file:_C:\Users\ferg_\Downloads\BetterHash_Setup.exe
Detection Origin: Local machine
Detection Type: FastPath
Detection Source: Real-Time Protection
Process Name: C:\Windows\explorer.exe
Security intelligence Version: AV: 1.405.575.0, AS: 1.405.575.0, NIS: 1.405.575.0
Engine Version: AM: 1.1.24010.10, NIS: 1.1.24010.10 
 
Date: 2024-02-25 02:56:07
Description: 
Microsoft Defender Antivirus has detected potentially unwanted application(PUA).
For more information please see the following:
Name: PUABundler:Win32/ICBundler
Severity: Low
Category: Potentially Unwanted Software
Path: file:_C:\Users\ferg_\Downloads\BetterHash_Setup.exe
Detection Origin: Local machine
Detection Type: FastPath
Detection Source: Real-Time Protection
Process Name: C:\Windows\explorer.exe
Security intelligence Version: AV: 1.405.486.0, AS: 1.405.486.0, NIS: 1.405.486.0
Engine Version: AM: 1.1.24010.10, NIS: 1.1.24010.10 
 
Date: 2024-02-25 02:56:07
Description: 
Microsoft Defender Antivirus has detected potentially unwanted application(PUA).
For more information please see the following:
Name: PUABundler:Win32/ICBundler
Severity: Low
Category: Potentially Unwanted Software
Path: file:_C:\Users\ferg_\Downloads\BetterHash_Setup.exe
Detection Origin: Local machine
Detection Type: FastPath
Detection Source: Real-Time Protection
Process Name: C:\Windows\explorer.exe
Security intelligence Version: AV: 1.405.486.0, AS: 1.405.486.0, NIS: 1.405.486.0
Engine Version: AM: 1.1.24010.10, NIS: 1.1.24010.10 
 
Date: 2024-02-25 02:56:05
Description: 
Microsoft Defender Antivirus has detected potentially unwanted application(PUA).
For more information please see the following:
Name: PUABundler:Win32/ICBundler
Severity: Low
Category: Potentially Unwanted Software
Path: file:_C:\Users\ferg_\Downloads\BetterHash_Setup.exe; webfile:_C:\Users\ferg_\Downloads\BetterHash_Setup.exe|https://www.betterhash.net/bh/download/|pid:14752,ProcessStart:133533213633169204
Detection Origin: Internet
Detection Type: FastPath
Detection Source: Downloads and attachments
Process Name: Unknown
Security intelligence Version: AV: 1.405.486.0, AS: 1.405.486.0, NIS: 1.405.486.0
Engine Version: AM: 1.1.24010.10, NIS: 1.1.24010.10 

CodeIntegrity:
===============
Date: 2024-02-29 03:10:46
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Program Files\McAfee\MfeAV\AMSIExt.dll that did not meet the Windows signing level requirements. 
 
 
==================== Memory info =========================== 
 
BIOS: LENOVO F5CN62WW 09/05/2023
Motherboard: LENOVO LNVNB161216
Processor: 11th Gen Intel® Core™ i5-1135G7 @ 2.40GHz
Percentage of memory in use: 58%
Total physical RAM: 12087.3 MB
Available physical RAM: 5071.96 MB
Total Virtual: 14519.3 MB
Available Virtual: 6769.33 MB
 
==================== Drives ================================
 
Drive c: (Windows-SSD) (Fixed) (Total:216.33 GB) (Free:164.56 GB) (Model: NVMe WD_BLACK SN770 500GB) (Protected) NTFS
 
\\?\Volume{9621ab45-7207-4ccb-b48d-31fd557bba18}\ (WINRE_DRV) (Fixed) (Total:0.98 GB) (Free:0.06 GB) NTFS
\\?\Volume{4a29bfbb-20ea-44d6-992a-d05235f1f403}\ (SYSTEM_DRV) (Fixed) (Total:0.25 GB) (Free:0.19 GB) FAT32
 
==================== MBR & Partition Table ====================
 
==========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: 8AF0EC67)
 
Partition: GPT.
 
==================== End of Addition.txt =======================

 

 



BC AdBot (Login to Remove)

 


#2 dennis_l

dennis_l

  •  Avatar image
  • Malware Response Team
  • 3,141 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:03:58 AM

Posted 29 February 2024 - 05:51 AM

Hi fergcoreyg59,
My name is Dennis and I will assist you with your computer problems.
Please read through these guidelines before we start.

  • Back up any important data, as a precaution, before starting this process.
  • If you are unsure about anything then please ask. This makes the task much easier in the long run.
  • Do not run any other tools or make changes to your system during the removal process.
  • Please do not start a new topic and keep all replies in this thread.
  • Follow the instructions in the sequence advised.
  • Copy and paste the logs into the reply. I will advise if anything needs to be added as an attachment.
  • Here at Bleeping Computer we are mostly volunteers, so please be patient with us. I’ll try to respond within 24 hours. You will be advised if it is expected to be longer than 48 hours.
  • Please let me know if you are going to be delayed in responding. If you do not reply after 5 days, I’ll assume you do not want to continue and will close the topic.
  • Sometimes things might seem to be resolved, but there may still need to be more checks necessary, so please wait until I give the all clear.

Please give me some time to examine your logs and I will get back to you as soon as possible.

Dennis
 

 



#3 dennis_l

dennis_l

  •  Avatar image
  • Malware Response Team
  • 3,141 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:03:58 AM

Posted 29 February 2024 - 08:34 AM

Could you please provide some more details of the issues you have been experiencing.
Please also do the following.

  • Highlight all of the information in the text box below then hit the Ctrl + C keys together to copy the text.
  • It is not necessary to paste the information anywhere as FRST will do this for you.
Start::
SystemRestore: On
CreateRestorePoint:
End::
  • Click on the Fix button just once and wait.
  • When it's finished FRST will generate a log in the location you ran the tool from. (Fixlog.txt).

Please copy the contents from this text file and paste into your next reply.
------------------------------------------------------------------------------------------------------
If FRST says Restore point was successfully created, please proceed and run AdwCleaner, as follows.
Please download AdwCleaner.

  • Close all open programs and browsers
  • Right click on the icon and select Run as administrator
  • Click Scan Now
  • When the scan has finished AdwCleaner shows you all detected PUPs and adware.
  • If any are found, select them and click Quarantine. (I would suggest that you do not select Pre-installed applications for now, or any other items you wish to keep.)
  • AdwCleaner prompts you to save and close your work before continuing. Click Continue.
  • After cleaning, you are prompted to restart your device. Click Restart now to complete the cleanup process.

Once your computer has restarted ...

  •     If it doesn't open automatically, please start AdwCleaner.
  •     Click on View Log File button (This log can also be found in the Log Files tab).
  •     A Notepad file will open containing the results.
  •     Click Skip Basic Repair (if the option appears)
  •     Please post the contents of the file in your next reply.


#4 dennis_l

dennis_l

  •  Avatar image
  • Malware Response Team
  • 3,141 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:03:58 AM

Posted 03 March 2024 - 01:51 PM

Please advise if you still need help?
It has been 3 days since my last post.
If you have not replied within the next 48 hours, I will assume that you no longer need help and this topic will be closed.






1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users