In Chrome on a Win10 PC, some address bar searches redirect to Yahoo instead of the defined default (Google). Edge also acts funny: when you open it, it opens, minimizes, then maximizes again. Don't know if the issues are related.
My wife found some info in a search and we downloaded SpyHunter, which found browserassistant.lnk and browserassistant.exe but wouldn't fix them unless we paid. Don't know if these are involved.
I downloaded aswMBR. I ran it twice and it caused a blue screen both times. I wasn't able to get pen/paper and write down the code fast enough.
Thanks in advance for your help.
FRST64 log:
Ran by [removed] (administrator) on DESKTOP-TTM2T1H (HP HP Pavilion Desktop PC 570-p0xx) (13-04-2020 21:12:15)
Running from C:\Users\[removed]\Desktop
[removed] Platform: Windows 10 Home Version 1909 18363.720 (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
(Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.452\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.452\GoogleCrashHandler64.exe
(HP Inc. -> HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(HP Inc. -> HP Inc.) C:\Program Files (x86)\HP\HP JumpStart Bridge\HPJumpStartBridge.exe
(HP Inc. -> HP Inc.) C:\Program Files (x86)\HP\HP JumpStart Launch\HPJumpStartLaunch.exe
(HP Inc. -> HP Inc.) C:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe
(HP Inc. -> HP Inc.) C:\Program Files (x86)\HP\HPAudioSwitch\HPAudioSwitch.exe
(HP Inc. -> HP Inc.) C:\Program Files\HPCommRecovery\HPCommRecovery.exe
(Intel Corporation -> Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Intel Corporation -> Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel Corporation -> Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_31a8dbbf39dcdc3b\jhi_service.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki131064.inf_amd64_5d13f27a9a9843fa\igfxCUIService.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki131064.inf_amd64_5d13f27a9a9843fa\igfxEM.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki131064.inf_amd64_5d13f27a9a9843fa\IntelCpHDCPSvc.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki131064.inf_amd64_5d13f27a9a9843fa\IntelCpHeciSvc.exe
(Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel(R) Wireless Connectivity Solutions -> Intel Corporation) C:\Windows\System32\ibtsiva.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <3>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe <5>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeSH.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2003.8-0\MsMpEng.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2003.8-0\NisSrv.exe
(Realistic Media Inc. -> ) C:\Users\Chad\AppData\Roaming\Browser Assistant\BrowserAssistant.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe
(SEIKO EPSON CORPORATION -> Seiko Epson Corporation) C:\Program Files (x86)\EPSON Software\PMA_A\PMAService.exe
(SEIKO EPSON Corporation -> Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe
(SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_YATIKEE.EXE
(WildTangent Inc -> ) C:\Program Files (x86)\WildTangent Games\Integration\WildTangentHelperService.exe
HKLM-x32\…\Run: [EEventManager] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [1092304 2016-03-14] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
HKLM-x32\…\Run: [FUFAXRCV] => C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe [653352 2017-02-16] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
HKLM-x32\…\Run: [FUFAXSTM] => C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe [862248 2017-02-16] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
HKLM-x32\…\Run: [TeamsMachineInstaller] => C:\Program Files (x86)\Teams Installer\Teams.exe [84008696 2019-12-08] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-739738517-1214496134-3013126539-1001\…\Run: [EPLTarget\P0000000000000000] => C:\windows\system32\spool\DRIVERS\x64\3\E_YATIKEE.EXE [298560 2013-09-12] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
HKU\S-1-5-21-739738517-1214496134-3013126539-1001\…\Run: [com.squirrel.Teams.Teams] => C:\Users\Chad\AppData\Local\Microsoft\Teams\Update.exe [2337544 2020-03-14] (Microsoft 3rd Party Application Component -> Microsoft Corporation)
HKU\S-1-5-21-739738517-1214496134-3013126539-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\PhotoScreensaver.scr [567296 2019-03-19] (Microsoft Windows -> Microsoft Corporation)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\80.0.3987.163\Installer\chrmstp.exe [2020-04-03] (Google LLC -> Google LLC)
Startup: C:\Users\Chad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\BrowserAssistant.lnk [2020-03-06]
ShortcutTarget: BrowserAssistant.lnk -> C:\Users\Chad\AppData\Roaming\Browser Assistant\BrowserAssistant.exe (Realistic Media Inc. -> )
Startup: C:\Users\Chad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\updater.lnk [2020-03-06]
ShortcutAndArgument: updater.lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe => -noninteractive -ExecutionPolicy bypass -c "try{$w="$env:APPDATA"+'\Browser Assistant\';[Reflection.Assembly]::Load([System.IO.File]::ReadAllBytes($w+'Updater.dll'));$i=new-object u.U;$i.R()}catch{}"
Task: {049A88AF-9172-4734-9C26-6B3ACB1CA904} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\MpCmdRun.exe [480272 2020-03-25] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {085D2A27-A43F-414A-874C-A1881515A75D} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\MpCmdRun.exe [480272 2020-03-25] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {0E2273D5-1090-42C1-9E17-6E84297F4041} - System32\Tasks\EPSON WF-3620 Series Invitation {406C84BF-E4F0-4835-83EF-9BEEC53EE65B} => C:\windows\system32\spool\DRIVERS\x64\3\E_YTSKEE.EXE [679488 2013-02-28] (SEIKO EPSON Corporation -> SEIKO EPSON CORPORATION)
Task: {12CC6395-F37E-477A-88A8-CB46AD038573} - System32\Tasks\HPJumpStartLaunch => C:\Program Files (x86)\HP\HP JumpStart Launch\HPJumpStartLaunch.exe [461824 2017-10-06] (HP Inc. -> HP Inc.)
Task: {14325B4B-B34D-40D0-8FFB-249E98397B08} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [1571208 2020-03-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {352F7434-A485-4C53-8189-1CA08F03B277} - System32\Tasks\Hewlett-Packard\HP Active Health\HP Active Health Scan (HPSA) => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.exe [198696 2017-09-27] (HP Inc. -> HP Inc.)
Task: {3E906362-F03C-44D0-9A90-C1C8530058C1} - System32\Tasks\HPCeeScheduleForChad => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [97656 2018-09-11] (HP Inc. -> HP Inc.)
Task: {496EF8CF-1F13-49E5-9B69-8DC87EC94FF5} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9279544 2018-09-13] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
Task: {4A5494F4-411A-42DE-A4D6-0019C8227A32} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [134008 2020-03-25] (HP Inc. -> HP Inc.)
Task: {4A6DD08F-2D7C-4645-A2FA-F1EE10611E56} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [1421704 2020-03-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {53D9042B-0EC3-43FF-BD0A-427F79FFC144} - System32\Tasks\HPAudioSwitch => C:\Program Files (x86)\HP\HPAudioSwitch\HPAudioSwitch.exe [1644472 2019-06-21] (HP Inc. -> HP Inc.)
Task: {655FEC79-1778-4380-BEE9-5BD0DD8C4F54} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [1117048 2020-03-26] (HP Inc. -> HP Inc.)
Task: {69EA899C-4D00-4435-A883-646AA5C3516A} - System32\Tasks\HPEA3JOBS => C:\Program [Argument = Files\HP\HP ePrint\hpeprint.exe /CheckJobs]
Task: {6BE9E83E-F8C8-41F8-9B58-5ADE266C4CA2} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156104 2019-12-26] (Google LLC -> Google LLC)
Task: {73D987CE-7565-412C-A88E-B4467BDBF4C3} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [1421704 2020-03-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {79AC2131-5AE8-4F61-A946-BD56E00F08C6} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [27369752 2020-03-03] (Microsoft Corporation -> Microsoft Corporation)
Task: {7DF8998E-EF69-4E8A-A57D-C074848BCEA9} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [1506680 2019-06-14] (HP Inc. -> HP Inc.)
Task: {8F70775B-7E2E-43E1-B075-EC084AA81ADE} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156104 2019-12-26] (Google LLC -> Google LLC)
Task: {9F884CF8-8269-4463-A1D6-11AB807DCA27} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1242704 2020-02-25] (Adobe Inc. -> Adobe Systems)
Task: {A53D7517-E078-4D39-A60E-A210BE9F0CE7} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [1506680 2019-06-14] (HP Inc. -> HP Inc.)
Task: {AE2F4F11-BCE0-4760-ACF8-FEC2B5861552} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Product Configurator => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\ProductConfig.exe [308088 2020-02-12] (HP Inc. -> HP Inc.)
Task: {B6A2891E-A851-4F22-B957-4366F443CC46} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [27369752 2020-03-03] (Microsoft Corporation -> Microsoft Corporation)
Task: {B8313863-D6B7-4868-9FF2-3ABC4B4D5FF4} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [4461160 2020-01-23] (Microsoft Corporation -> Microsoft Corporation)
Task: {C2DF782A-4DA4-495B-9842-E4AE71E646AD} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\MpCmdRun.exe [480272 2020-03-25] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {C8E5E442-158B-4665-B9C8-DEF57855541B} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\sdxhelper.exe [110632 2020-03-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {CF20AEAF-4C4D-4281-81FD-0CB6CC082D33} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [4461160 2020-01-23] (Microsoft Corporation -> Microsoft Corporation)
Task: {D366AFF7-BEB0-416D-874D-D71401CBC55D} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\MpCmdRun.exe [480272 2020-03-25] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {D7D4CDE4-4254-4388-99EA-A8108955BB7E} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\sdxhelper.exe [110632 2020-03-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {E0A504AA-C700-420C-B764-FC1064A4C19C} - System32\Tasks\BA Scheduler => powershell.exe -WindowStyle Hidden -ExecutionPolicy bypass -c "$env:COMPLUS_version='v4.0.30319';&powershell;{$w="$env:APPDATA"+'\Browser Assistant\';[Reflection.Assembly]::Load([System.IO.File]::ReadAllBytes($w+'Updater.dll'));$i=new-object u.U;$i.ST()}" <==== ATTENTION
Task: {E388E96F-392C-4725-8353-E12D9D628803} - System32\Tasks\EPSON WF-3620 Series Update {406C84BF-E4F0-4835-83EF-9BEEC53EE65B} => C:\windows\system32\spool\DRIVERS\x64\3\E_YTSKEE.EXE [679488 2013-02-28] (SEIKO EPSON Corporation -> SEIKO EPSON CORPORATION)
Task: {FE146D3B-AD56-485E-9EE5-95FAF8E823CF} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [655736 2019-07-31] (HP Inc. -> HP Inc.)
Task: C:\WINDOWS\Tasks\EPSON WF-3620 Series Update {406C84BF-E4F0-4835-83EF-9BEEC53EE65B}.job => C:\windows\system32\spool\DRIVERS\x64\3\E_YTSKEE.EXE:/EXE:{406C84BF-E4F0-4835-83EF-9BEEC53EE65B} /F:UpdateWORKGROUP\RE5BBOV0NVGFP$ĊSearches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi
Task: C:\WINDOWS\Tasks\HPCeeScheduleForChad.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
Tcpip\..\Interfaces\{55abad87-d4c4-4d05-b8d5-d633cc63cc75}: [DhcpNameServer] 192.168.1.1
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://hp17win10.msn.com/?pc=HCTE
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp17win10.msn.com/?pc=HCTE
HKU\S-1-5-21-739738517-1214496134-3013126539-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://hp17win10.msn.com/?pc=HCTE
HKU\S-1-5-21-739738517-1214496134-3013126539-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp17win10.msn.com/?pc=HCTE
SearchScopes: HKLM -> {CD3A9B6B-ADC3-4116-8B3F-FB3EAACA6672} URL = hxxp://www.amazon.com/s/ref=azs_osd_iea?ie=UTF-8&tag;=hp-us1-vsb-20&link;%5Fcode=qs&index;=aps&field-keywords;={searchTerms}
SearchScopes: HKLM-x32 -> {CD3A9B6B-ADC3-4116-8B3F-FB3EAACA6672} URL = hxxp://www.amazon.com/s/ref=azs_osd_iea?ie=UTF-8&tag;=hp-us1-vsb-20&link;%5Fcode=qs&index;=aps&field-keywords;={searchTerms}
SearchScopes: HKU\S-1-5-21-739738517-1214496134-3013126539-1001 -> {CD3A9B6B-ADC3-4116-8B3F-FB3EAACA6672} URL = hxxp://www.amazon.com/s/ref=azs_osd_iea?ie=UTF-8&tag;=hp-us1-vsb-20&link;%5Fcode=qs&index;=aps&field-keywords;={searchTerms}
BHO: IEBrowserAssistant -> {2421CBA2-89B7-4734-8438-49E0D7EB8A75} -> C:\Users\Chad\AppData\Roaming\IEBrowserAssistant\adxloader64.dll [2018-11-13] (Default Company) [File not signed]
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2020-01-23] (Microsoft Corporation -> Microsoft Corporation)
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2017-10-27] (HP Inc. -> HP Inc.)
BHO-x32: IEBrowserAssistant -> {2421CBA2-89B7-4734-8438-49E0D7EB8A75} -> C:\Users\Chad\AppData\Roaming\IEBrowserAssistant\adxloader.dll [2018-11-13] (Default Company) [File not signed]
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2020-01-23] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2017-10-27] (HP Inc. -> HP Inc.)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2020-01-23] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2020-01-23] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2020-01-23] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2020-01-23] (Microsoft Corporation -> Microsoft Corporation)
======
DownloadDir: C:\Users\Chad\Downloads
Edge Notifications: HKU\S-1-5-21-739738517-1214496134-3013126539-1001 -> hxxps://trampolineparkmiamisburg.notification-0.com; hxxps://jcpenney.notification-0.com
========
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2020-01-23] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2020-01-23] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2020-03-05] (Adobe Inc. -> Adobe Systems Inc.)
=======
CHR DefaultProfile: Profile 2
CHR Profile: C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Default [2020-04-13]
CHR Notifications: Default -> hxxps://www.smarter.com
CHR Extension: (Chrome Web Store Payments) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-12-26]
CHR Extension: (Chrome Media Router) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-04-06]
CHR Profile: C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Guest Profile [2020-03-16]
CHR Profile: C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1 [2020-04-13]
CHR Notifications: Profile 1 -> hxxps://kizi.com; hxxps://www.youtube.com
CHR Extension: (Slides) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2020-03-16]
CHR Extension: (DocHub - Edit and Sign PDF Documents) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\adgncicbhbjfpijkdmbijninnhnmiblj [2020-04-06]
CHR Extension: (Share to Classroom) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\adokjfanaflbkibffcbhihgihpgijcei [2020-04-06]
CHR Extension: (BIODIGITAL HUMAN) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\agoenciogemlojlhccbcpcfflicgnaak [2020-04-06]
CHR Extension: (Docs) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2020-03-16]
CHR Extension: (Google Drive) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-03-16]
CHR Extension: (Desmos Graphing Calculator) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bhdheahnajobgndecdbggfmcojekgdko [2020-04-06]
CHR Extension: (YouTube) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2020-03-16]
CHR Extension: (GeoGebra Classic) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bnbaboaihhkjoaolfnfoablhllahjnee [2020-04-06]
CHR Extension: (Useful Periodic Table (lite)) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\chachkegffmilnmdlonllkhkfkakghie [2020-04-06]
CHR Extension: (Sheets) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2020-03-16]
CHR Extension: (Google Docs Offline) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-03-16]
CHR Extension: (Camera) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\hfhhnacclhffhdffklopdkcgdhifgngh [2020-04-06]
CHR Extension: (Zoom) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\hmbjbjdpkobdjplfobhljndfdfdipjhg [2020-04-06]
CHR Extension: (Pixlr Editor) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\icmaknaampgiegkcjlimdiidlhopknpk [2020-04-06]
CHR Extension: (Smoothwall) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\jbldkhfglmgeihlcaeliadhipokhocnm [2020-04-08]
CHR Extension: (TestNav) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mdmkkicfmmkgmpkmkdikhlbggogpicma [2020-04-06]
CHR Extension: (Google Classroom) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mfhehppjhmmnlfbbopchdfldgimhfhfk [2020-04-06]
CHR Extension: (Screencastify - Screen Video Recorder) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mmeijimgabbpbgpdklnllpncmdofkcpn [2020-04-13]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2020-03-16]
CHR Extension: (Kids A-Z) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pifccnhncmnilgbnnkjkgicpkeclodpd [2020-04-06]
CHR Extension: (Gmail) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-03-16]
CHR Extension: (Chrome Media Router) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-04-03]
CHR Profile: C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 2 [2020-04-13]
CHR Extension: (Slides) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2020-04-13]
CHR Extension: (Docs) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aohghmighlieiainnegkcijnfilokake [2020-04-13]
CHR Extension: (Google Drive) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-04-13]
CHR Extension: (YouTube) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2020-04-13]
CHR Extension: (Sheets) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2020-04-13]
CHR Extension: (Google Docs Offline) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-04-13]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2020-04-13]
CHR Extension: (Gmail) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-04-13]
CHR Extension: (Chrome Media Router) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-04-13]
CHR Profile: C:\Users\Chad\AppData\Local\Google\Chrome\User Data\System Profile [2020-04-13]
R2 Epson PMAService A; C:\Program Files (x86)\Epson Software\PMA_A\PMAService.exe [113144 2017-03-28] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
R2 EpsonScanSvc; C:\windows\system32\EscSvc64.exe [144560 2012-05-17] (SEIKO EPSON Corporation -> Seiko Epson Corporation)
R2 HP Comm Recover; C:\Program Files\HPCommRecovery\HPCommRecovery.exe [1321096 2018-09-28] (HP Inc. -> HP Inc.)
R2 HPJumpStartBridge; c:\Program Files (x86)\HP\HP JumpStart Bridge\HPJumpStartBridge.exe [477184 2017-10-06] (HP Inc. -> HP Inc.)
S3 hpqcaslwmiex; C:\Program Files (x86)\HP\Shared\hpqwmiex.exe [1031704 2016-06-04] (Hewlett-Packard Company -> HP)
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [378744 2020-03-31] (HP Inc. -> HP Inc.)
R2 HPWMISVC; c:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe [628768 2017-07-13] (HP Inc. -> HP Inc.)
R2 ibtsiva; C:\WINDOWS\System32\ibtsiva.exe [529912 2018-12-21] (Intel(R) Wireless Connectivity Solutions -> Intel Corporation)
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\WINDOWS\System32\DriverStore\FileRepository\iclsclient.inf_amd64_7e148e9c120d86df\lib\SocketHeciServer.exe [872416 2019-04-23] (Intel(R) Trust Services -> Intel(R) Corporation)
S2 Intel(R) TPM Provisioning Service; C:\WINDOWS\System32\DriverStore\FileRepository\iclsclient.inf_amd64_7e148e9c120d86df\lib\TPMProvisioningService.exe [800224 2019-04-23] (Intel(R) Trust Services -> Intel(R) Corporation)
R2 jhi_service; C:\WINDOWS\System32\DriverStore\FileRepository\dal.inf_amd64_31a8dbbf39dcdc3b\jhi_service.exe [647568 2019-04-30] (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [310880 2018-09-05] (Intel Corporation -> )
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\NisSrv.exe [3294680 2020-03-25] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WildTangentHelper; C:\Program Files (x86)\WildTangent Games\Integration\WildTangentHelperService.exe [1582384 2019-12-09] (WildTangent Inc -> )
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\MsMpEng.exe [103168 2020-03-25] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [4059744 2018-09-05] (Intel Corporation -> Intel® Corporation)
R3 Netwtw04; C:\WINDOWS\System32\drivers\Netwtw04.sys [8720384 2019-08-27] (Intel(R) Wireless Connectivity Solutions -> Intel Corporation)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [984032 2017-09-15] (Realtek Semiconductor Corp. -> Realtek )
R3 RTSUER; C:\WINDOWS\system32\Drivers\RtsUer.sys [421312 2017-09-14] (Realtek Semiconductor Corp. -> Realsil Semiconductor Corporation)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [45960 2020-03-25] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [391392 2020-03-25] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [59104 2020-03-25] (Microsoft Windows -> Microsoft Corporation)
==================== One month (created) ===================
2020-04-13 21:11 - 2020-04-13 21:12 - 000000000 ____D C:\FRST
2020-04-13 21:10 - 2020-04-13 21:10 - 002281984 _____ (Farbar) C:\Users\Chad\Desktop\FRST64.exe
2020-04-13 21:09 - 2020-04-13 21:09 - 001157812 _____ C:\WINDOWS\Minidump\041320-21796-01.dmp
2020-04-13 21:08 - 2020-04-13 21:08 - 688590482 ____N C:\WINDOWS\MEMORY.DMP
2020-04-13 21:04 - 2020-04-13 21:09 - 000000000 ____D C:\WINDOWS\Minidump
2020-04-13 21:02 - 2020-04-13 21:02 - 005198336 _____ (AVAST Software) C:\Users\Chad\Desktop\aswMBR.exe
2020-04-13 20:42 - 2020-04-13 20:42 - 006946736 _____ (EnigmaSoft Limited) C:\Users\Chad\Downloads\sh-remover.exe
2020-04-13 13:33 - 2020-04-13 13:33 - 000002481 _____ C:\Users\Chad\Desktop\Mom - Chrome.lnk
2020-04-06 09:36 - 2020-04-06 09:36 - 000000000 ____D C:\Users\Chad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
2020-03-26 13:20 - 2020-03-26 13:20 - 000078168 _____ (Zoom Video Communications, Inc.) C:\Users\Chad\Downloads\Zoom_42034cce248d8e41.exe
2020-03-16 09:57 - 2020-04-06 09:35 - 000002481 _____ C:\Users\Chad\Desktop\Grace - Chrome.lnk
2020-04-13 21:09 - 2019-03-02 15:44 - 000000000 ____D C:\Users\Chad\AppData\Roaming\Browser Assistant
2020-04-13 21:08 - 2019-12-26 11:39 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2020-04-13 21:08 - 2019-12-26 11:35 - 000000000 ____D C:\Users\Chad
2020-04-13 21:08 - 2019-12-26 11:32 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2020-04-13 21:08 - 2019-03-19 00:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2020-04-13 21:08 - 2018-06-26 20:11 - 000000000 __SHD C:\Users\Chad\IntelGraphicsProfiles
2020-04-13 21:06 - 2019-03-19 00:37 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2020-04-13 21:04 - 2019-12-26 11:32 - 001810805 ____N C:\WINDOWS\Minidump\041320-6703-01.dmp
2020-04-13 21:04 - 2018-07-08 09:46 - 000000360 _____ C:\WINDOWS\Tasks\HPCeeScheduleForChad.job
2020-04-13 20:53 - 2019-12-26 11:39 - 000004164 _____ C:\WINDOWS\system32\Tasks\User_Feed_Synchronization-{1F435414-D5C0-4BCD-8953-1C1EE5157FC8}
2020-04-13 20:42 - 2018-06-26 20:44 - 000000000 ____D C:\Users\Chad\Documents\Outlook Files
2020-04-13 20:28 - 2019-12-26 11:39 - 000003248 _____ C:\WINDOWS\system32\Tasks\HPCeeScheduleForChad
2020-04-13 17:49 - 2019-03-19 00:52 - 000000000 ___HD C:\Program Files\WindowsApps
2020-04-13 17:49 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\AppReadiness
2020-04-11 17:09 - 2018-06-26 20:43 - 000044402 _____ C:\Users\Chad\Desktop\Food Inventory.xlsx
2020-04-11 16:20 - 2018-06-26 20:11 - 000000000 ____D C:\Users\Chad\AppData\Local\Packages
2020-04-09 19:47 - 2020-01-08 20:42 - 000000000 ____D C:\Users\Chad\Desktop\Nate's Camera
2020-04-09 06:35 - 2018-06-26 20:43 - 000000000 ____D C:\Users\Chad\Desktop\8876 Wildfire
2020-04-03 14:01 - 2019-12-26 11:56 - 000002308 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-04-03 14:01 - 2019-12-26 11:56 - 000002267 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2020-04-03 14:01 - 2019-12-26 11:56 - 000002267 _____ C:\ProgramData\Desktop\Google Chrome.lnk
2020-04-02 10:15 - 2018-08-27 09:21 - 000744808 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2020-03-25 09:24 - 2018-06-27 08:13 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2020-03-23 07:55 - 2019-12-26 11:39 - 000003376 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-739738517-1214496134-3013126539-1001
2020-03-23 07:55 - 2019-12-26 11:35 - 000002367 _____ C:\Users\Chad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2020-03-23 07:55 - 2019-09-10 16:25 - 000000000 ___RD C:\Users\Chad\OneDrive - Dayton Regional STEM School
2020-03-20 18:45 - 2019-12-26 11:56 - 000003420 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2020-03-20 18:45 - 2019-12-26 11:56 - 000003296 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2020-03-19 15:28 - 2019-12-26 11:39 - 000004562 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2020-03-19 15:28 - 2019-12-26 09:58 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2020-03-18 09:23 - 2018-06-26 21:10 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2020-03-16 12:06 - 2020-01-31 10:09 - 000013247 _____ C:\Users\Chad\Desktop\Nate Jan Progress Book.xlsx
2020-03-14 10:25 - 2020-01-26 07:55 - 000002366 _____ C:\Users\Chad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Teams.lnk
2020-03-14 10:25 - 2020-01-26 07:55 - 000002358 _____ C:\Users\Chad\Desktop\Microsoft Teams.lnk
FRST64 Addition:
Ran by [removed] (13-04-2020 21:13:03)
Running from C:\Users\[removed]\Desktop
Windows 10 Home Version 1909 18363.720 (X64) (2019-12-26 15:39:51)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Chad (S-1-5-21-739738517-1214496134-3013126539-1001 - Administrator - Enabled) => C:\Users\Chad
DefaultAccount (S-1-5-21-739738517-1214496134-3013126539-503 - Limited - Disabled)
Guest (S-1-5-21-739738517-1214496134-3013126539-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-739738517-1214496134-3013126539-504 - Limited - Disabled)
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
Bonjour (HKLM\…\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Browser Assistant (HKLM-x32\…\{8AD59EE9-679B-466D-8423-57F15B149794}) (Version: 1.37.7345.30189 - Realistic Media Inc.)
Direct Game UNI Installer (HKLM-x32\…\{C77717A7-09BF-49AF-92F2-9F3ED9AF5BFD}) (Version: 1.0.17 - GamesLOL)
Epson Event Manager (HKLM-x32\…\{006C8256-3855-43BF-8BA5-4B4C40F41F71}) (Version: 3.10.0065 - Seiko Epson Corporation)
Epson FAX Utility (HKLM-x32\…\{0CBE6C93-CB2E-4378-91EE-12BE6D4E2E4A}) (Version: 2.02.00 - Seiko Epson Corporation)
Epson PC-FAX Driver (HKLM-x32\…\EPSON PC-FAX Driver 2) (Version: - Seiko Epson Corporation)
Epson ReadyInk Agent (A) (HKLM-x32\…\{A9B4584F-A29E-4880-97E6-1744B4AF2AF8}) (Version: 1.0.1.0 - Seiko Epson Corporation)
EPSON Scan (HKLM-x32\…\EPSON Scanner) (Version: - Seiko Epson Corporation)
Epson Software Updater (HKLM-x32\…\{B55DB65D-EF6E-4E04-89D5-B03603BF681B}) (Version: 4.4.5 - SEIKO EPSON CORPORATION)
EPSON WF-3620 Series Printer Uninstall (HKLM\…\EPSON WF-3620 Series) (Version: - SEIKO EPSON Corporation)
Epson WF-3620 User’s Guide version 1.0 (HKLM-x32\…\UsersGuideEpson WF-3620 User’s Guide_is1) (Version: 1.0 - )
EpsonNet Print (HKLM\…\{96ED1D58-440C-4345-8FEE-C4781366C67F}) (Version: 3.1.4.0 - SEIKO EPSON Corporation)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 80.0.3987.163 - Google LLC)
Google Update Helper (HKLM-x32\…\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.451 - Google LLC) Hidden
HP Audio Switch (HKLM-x32\…\{3A5141D4-47DB-4302-9B1C-272BE585BC8A}) (Version: 1.0.179.0 - HP Inc.)
HP Connection Optimizer (HKLM-x32\…\{6468C4A5-E47E-405F-B675-A70A70983EA6}) (Version: 2.0.15.0 - HP Inc.)
HP Documentation (HKLM\…\HP_Documentation) (Version: 1.0.0.1 - HP Inc.)
HP ePrint SW (HKLM-x32\…\{cdb5f70f-5107-4613-bf69-15de903b5b5d}) (Version: 5.5.22560 - HP Inc.)
HP JumpStart Apps (HKLM-x32\…\HP JumpStart Apps) (Version: 7.0.32 - HP Inc.)
HP JumpStart Bridge (HKLM-x32\…\{3FC961DB-BD36-4D8D-B276-0C456A2BB638}) (Version: 1.4.0.441 - HP Inc.)
HP JumpStart Launch (HKLM-x32\…\{F213102E-FD30-4E22-AF73-4C682D65FFEE}) (Version: 1.4.441.0 - HP Inc.)
HP Support Assistant (HKLM-x32\…\{4AAC4B07-77EF-4BCF-88DC-D24E4DE683E8}) (Version: 8.8.24.33 - HP Inc.)
HP Support Solutions Framework (HKLM-x32\…\{63F82052-C045-4F97-A3CA-C41D2CCA1FFA}) (Version: 12.15.14.3 - HP Inc.)
HP System Event Utility (HKLM-x32\…\{4B0A7A8A-ECE5-4639-9A0D-C535F354313D}) (Version: 1.4.26 - HP Inc.)
IEBrowserAssistant (HKLM-x32\…\{BC63C727-3079-49AA-876A-8E459D35CB72}) (Version: 1.0.0 - Realistic Media Inc.)
Intel(R) Chipset Device Software (HKLM-x32\…\{17408817-d415-4768-a160-ae6d46d6bdb0}) (Version: 10.1.1.44 - Intel(R) Corporation) Hidden
Intel(R) Management Engine Components (HKLM\…\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.7.0.1043 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 25.20.100.6446 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\…\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 15.8.1.1007 - Intel Corporation)
Intel(R) Serial IO (HKLM\…\{9FD91C5C-44AE-4D9D-85BE-AE52816B0294}) (Version: 30.100.1725.1 - Intel Corporation)
Intel(R) Wireless Bluetooth(R) (HKLM-x32\…\{00000080-0190-1033-84C8-B8D95FA3C8C3}) (Version: 19.80.0 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\…\{f8c930bd-0a68-425f-8c11-87723d1e2c97}) (Version: 20.90.0 - Intel Corporation)
Microsoft Office 365 - en-us (HKLM\…\o365homepremretail - en-us) (Version: 16.0.11929.20648 - Microsoft Corporation)
Microsoft Office 365 ProPlus - en-us (HKLM\…\O365ProPlusRetail - en-us) (Version: 16.0.11929.20648 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-739738517-1214496134-3013126539-1001\…\OneDriveSetup.exe) (Version: 19.232.1124.0010 - Microsoft Corporation)
Microsoft Teams (HKU\S-1-5-21-739738517-1214496134-3013126539-1001\…\Teams) (Version: 1.3.00.3564 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\…\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\…\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\…\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\…\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24123 (HKLM-x32\…\{2cbcedbb-f38c-48a3-a3e1-6c6fd821a7f4}) (Version: 14.0.24123.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24123 (HKLM-x32\…\{206898cc-4b41-4d98-ac28-9f9ae57f91fe}) (Version: 14.0.24123.0 - Microsoft Corporation)
Office 16 Click-to-Run Extensibility Component (HKLM-x32\…\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.11929.20648 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\…\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.11929.20648 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\…\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.11929.20648 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM-x32\…\{90160000-008C-0409-0000-0000000FF1CE}) (Version: 16.0.11929.20648 - Microsoft Corporation) Hidden
Realtek Card Reader (HKLM-x32\…\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.15063.31237 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.19.627.2017 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8536 - Realtek Semiconductor Corp.)
Teams Machine-Wide Installer (HKLM-x32\…\{39AF0813-FA7B-4860-ADBE-93B9B214B914}) (Version: 1.2.0.34161 - Microsoft Corporation)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\…\{F14FB68A-9188-4036-AD0D-D054BC9C9291}) (Version: 2.59.0.0 - Microsoft Corporation)
Vulkan Run Time Libraries 1.1.70.1 (HKLM\…\VulkanRT1.1.70.1) (Version: 1.1.70.1 - LunarG, Inc.) Hidden
Windows 10 Update Assistant (HKLM-x32\…\{D5C69738-B486-402E-85AC-2456D98A64E4}) (Version: 1.4.9200.22391 - Microsoft Corporation)
=========
Any Player -> C:\Program Files\WindowsApps\15191PeakPlayer.50533F9B98293_3.1.4.0_x64__y5c4dfz5b21fm [2020-04-11] (Any DVD & Office App)
Connect -> C:\Windows\SystemApps\Microsoft.Windows.DevicesFlowHost_cw5n1h2txyewy [2019-12-26] (Microsoft Corporation)
Dolby Access -> C:\Program Files\WindowsApps\DolbyLaboratories.DolbyAccess_3.1.4081.0_x64__rz1tebttyb220 [2020-01-28] (Dolby Laboratories)
Floor Adjustment -> C:\Windows\SystemApps\RoomAdjustment_cw5n1h2txyewy [2019-12-26] (Microsoft Corporation)
HP JumpStart -> C:\Program Files\WindowsApps\AD2F1837.HPJumpStart_1.4.443.0_x86__v10z8vjag6ke6 [2018-03-06] (HP Inc.)
Learn Mixed Reality -> C:\Windows\SystemApps\MixedRealityLearning_cw5n1h2txyewy [2019-12-26] (Microsoft Corporation)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-01-19] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-01-19] (Microsoft Corporation) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.6.1224.0_x64__8wekyb3d8bbwe [2020-02-28] (Microsoft Studios) [MS Ad]
MSN Weather -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.36.20714.0_x64__8wekyb3d8bbwe [2020-03-24] (Microsoft Corporation) [MS Ad]
New for You -> C:\Windows\SystemApps\WhatsNew_cw5n1h2txyewy [2019-12-26] (Microsoft Corporation)
Passthrough -> C:\Windows\SystemApps\passthrough_cw5n1h2txyewy [2019-12-26] (Microsoft Corporation)
Photos Add-on -> C:\Program Files\WindowsApps\Microsoft.Windows.Photos.DLC.Main_2017.39121.36610.0_x64__8wekyb3d8bbwe [2019-06-18] (Microsoft Corporation)
Photos Media Engine Add-on -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2019-09-27] (Microsoft Corporation)
Power Media Player 14 for HP Consumer PCs with DVD -> C:\Program Files\WindowsApps\CyberLinkCorp.hs.PowerMediaPlayer14forHPConsumerPC_14.2.9528.0_x86__06qsbagp91rvg [2019-01-26] (CYBERLINKCOM CORP)
Sign In -> C:\Windows\SystemApps\WebAuthBridgeInternet_cw5n1h2txyewy [2019-12-26] (ms-resource:PublisherDisplayName)
Sign In -> C:\Windows\SystemApps\WebAuthBridgeInternetSso_cw5n1h2txyewy [2019-12-26] (ms-resource:PublisherDisplayName)
Sign In -> C:\Windows\SystemApps\WebAuthBridgeIntranetSso_cw5n1h2txyewy [2019-12-26] (ms-resource:PublisherDisplayName)
Simple Solitaire -> C:\Program Files\WindowsApps\26720RandomSaladGamesLLC.SimpleSolitaire_6.18.78.0_x64__kx24dqmazqk8j [2020-02-29] (Random Salad Games LLC) [MS Ad]
Sling TV -> C:\Program Files\WindowsApps\SlingTVLLC.SlingTV_7.0.8.0_x86__vgszm6stshdqy [2019-01-09] (Sling TV LLC)
Smartfriend by HP Care -> C:\Program Files\WindowsApps\AD2F1837.SmartfriendbyHPCare_1.1.13.0_x64__v10z8vjag6ke6 [2018-03-06] (HP Inc.)
CustomCLSID: HKU\S-1-5-21-739738517-1214496134-3013126539-1001_Classes\CLSID\{19A6E644-14E6-4A60-B8D7-DD20610A871D}\InprocServer32 -> C:\Users\Chad\AppData\Local\Microsoft\TeamsMeetingAddin\1.0.19350.3\x64\Microsoft.Teams.AddinLoader.dll (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-739738517-1214496134-3013126539-1001_Classes\CLSID\{CB965DF1-B8EA-49C7-BDAD-5457FDC1BF92}\InprocServer32 -> C:\Users\Chad\AppData\Local\Microsoft\TeamsMeetingAddin\1.0.19350.3\x64\Microsoft.Teams.AddinLoader.dll (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\System32\DriverStore\FileRepository\ki131064.inf_amd64_5d13f27a9a9843fa\igfxDTCM.dll [2019-02-17] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ShortcutWithArgument: C:\Users\Chad\Desktop\Mom - Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> –profile-directory="Profile 2"
ShortcutWithArgument: C:\Users\Chad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Camera.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> –profile-directory="Profile 1" –app-id=hfhhnacclhffhdffklopdkcgdhifgngh
ShortcutWithArgument: C:\Users\Chad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\GeoGebra Classic.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> –profile-directory="Profile 1" –app-id=bnbaboaihhkjoaolfnfoablhllahjnee
ShortcutWithArgument: C:\Users\Chad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\TestNav.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> –profile-directory="Profile 1" –app-id=mdmkkicfmmkgmpkmkdikhlbggogpicma
ShortcutWithArgument: C:\Users\Chad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Zoom.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> –profile-directory="Profile 1" –app-id=hmbjbjdpkobdjplfobhljndfdfdipjhg
ShortcutWithArgument: C:\Users\Chad\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\ff13ca23fee04978\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> –profile-directory="Profile 5"
ShortcutWithArgument: C:\Users\Chad\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\9501e18d7c2ab92e\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> –profile-directory="Profile 2"
ShortcutWithArgument: C:\Users\Chad\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\69639df789022856\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> –profile-directory="Profile 1"
ShortcutWithArgument: C:\Users\Chad\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\48499db33039e897\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> –profile-directory="Profile 4"
ShortcutWithArgument: C:\Users\Chad\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\225bb61db2f318c1\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> –profile-directory="Profile 3"
2020-02-13 20:38 - 2020-02-13 20:38 - 000160768 _____ () [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\BRIDGECommon\106852b62f2dce48f68f823bb25b51bb\BRIDGECommon.ni.dll
2020-02-13 20:39 - 2020-02-13 20:39 - 000125440 _____ () [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\BridgeExtension\512361b13bdadec3c76781ced2b9ba25\BridgeExtension.ni.dll
2020-02-13 20:39 - 2020-02-13 20:39 - 000395264 _____ () [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\CleanStartController\8a1af52831b2ac51f3246da60333b1d9\CleanStartController.ni.dll
2020-02-13 20:39 - 2020-02-13 20:39 - 000145920 _____ () [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Registratio4eabc192#\0c4e7d4693b00c0677da9c65c0889302\RegistrationUtilities.ni.dll
2020-02-13 20:40 - 2020-02-13 20:40 - 000134656 _____ (hardcodet.net) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Hardcodet.W6cab32f3#\4faa7a04101a97b05eff64101eb5eb70\Hardcodet.Wpf.TaskbarNotification.ni.dll
2020-02-13 20:39 - 2020-02-13 20:39 - 000136192 _____ (HP Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\CommonPortable\661da84cbe3eb8c9142d35b54c52a1d9\CommonPortable.ni.dll
2020-02-13 20:40 - 2020-02-13 20:40 - 001701888 _____ (Mark Heath & Contributors) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\NAudio\9e86bf19bde10a6d24242ac28ecf3ad6\NAudio.ni.dll
2020-02-13 20:38 - 2020-02-13 20:38 - 002306560 _____ (Newtonsoft) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Newtonsoft.Json\cbac7b8be40869c5395f0ef28ddabd0b\Newtonsoft.Json.ni.dll
2020-02-13 20:40 - 2020-02-13 20:40 - 003060736 _____ (Newtonsoft) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Newtonsoft.Json\f49f899040cee6804ea2c4a4d309f9a9\Newtonsoft.Json.ni.dll
2016-05-09 09:20 - 2016-05-09 09:20 - 000132096 _____ (Seiko Epson Corporation) [File not signed] C:\Program Files (x86)\EPSON Software\Event Manager\epnsm.dll
2009-10-21 17:39 - 2009-10-21 17:39 - 000291328 _____ (SEIKO EPSON CORPORATION) [File not signed] C:\Program Files (x86)\EPSON Software\Event Manager\LcMgr.dll
2016-09-14 14:31 - 2016-09-14 14:31 - 000500736 _____ (SEIKO EPSON CORPORATION) [File not signed] C:\WINDOWS\System32\enppmon.dll
2020-02-13 20:40 - 2020-02-13 20:40 - 000793088 _____ (The Apache Software Foundation) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\log4net\4e37f9f72190581f516ebaf75e4fb60a\log4net.ni.dll
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Windows Firewall is enabled.
HKLM\…\StartupApproved\Run32: => "FUFAXRCV"
HKLM\…\StartupApproved\Run32: => "FUFAXSTM"
HKU\S-1-5-21-739738517-1214496134-3013126539-1001\…\StartupApproved\Run: => "OneDrive"
FirewallRules: [{1100765F-5717-49C7-804E-A0E76CF930E1}] => (Allow) C:\Users\Chad\AppData\Local\Temp\WF-3620\Common\EpsonNet Setup\ENEasyApp.exe No File
FirewallRules: [{A615BE46-8F40-44D2-8C07-8D1837C9A155}] => (Allow) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
FirewallRules: [{E701CCE1-991D-4E32-BE22-6B8CA0133AC8}] => (Allow) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
FirewallRules: [{CADF8CDF-AFAC-4BD2-9CDB-7BE1992B7137}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{87132A74-3F41-45FF-AAD5-E9DC2C4BC058}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{33CA5CE1-C253-4D11-AB9E-0C6387E9A4D5}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{335234DF-FD72-42B1-B714-47D5CF448F45}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{3EE1FDF2-12E1-47B6-A319-4940FB0F3F15}] => (Allow) C:\Program Files (x86)\Common Files\Mcafee\MMSSHost\MMSSHost.exe No File
FirewallRules: [{C74A739F-68DA-408D-B3F7-57165959BA47}] => (Allow) C:\Program Files\Common Files\McAfee\MMSSHost\MMSSHost.exe No File
FirewallRules: [{1D23678D-91C3-4FFE-8DCD-9F814D770BC4}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{01DCF1BB-01F6-402D-860B-5A5625BF40AD}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{CA76B6D7-C405-4660-AD8A-35235D9565F5}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe (Intel Corporation -> )
FirewallRules: [{3854827A-6F82-43F1-8DEA-90A13A569D63}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{5244D7F8-C295-4E2C-A94A-E37300DF7191}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{34788936-5E00-483F-B55C-35120CC9C0ED}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{4F4D9931-5619-4133-BE4D-BF7A8F97BB5F}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
==================== Event log errors: ========================
==================
Error: (04/13/2020 08:59:42 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: MicrosoftEdgeCP.exe, version: 11.0.18362.1, time stamp: 0xceb8cbe1
Faulting module name: EdgeContent.dll, version: 11.0.18362.657, time stamp: 0xe6b5ea8d
Exception code: 0xc0000409
Fault offset: 0x0000000000095f82
Faulting process id: 0x1e6c
Faulting application start time: 0x01d611f7fad3ceb7
Faulting application path: C:\Windows\System32\MicrosoftEdgeCP.exe
Faulting module path: C:\Windows\System32\EdgeContent.dll
Report Id: 8a0261d9-7a72-492f-85b6-d659692b74a9
Faulting package full name: Microsoft.MicrosoftEdge_44.18362.449.0_neutral__8wekyb3d8bbwe
Faulting package-relative application ID: MicrosoftEdge
Description: svchost (31128,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.
Description: Unable to open the Server service performance object. The first four bytes (DWORD) of the Data section contains the status code.
Description: svchost (29828,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.
Description: svchost (26504,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.
Description: svchost (30732,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.
Description: svchost (30732,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.
Description: The required buffer size is greater than the buffer size passed to the Collect function of the "C:\Windows\System32\perfts.dll" Extensible Counter DLL for the "LSM" service. The given buffer size was 4344 and the required size was 33408.
System errors:
=============
Error: (04/13/2020 09:09:01 PM) (Source: BugCheck) (EventID: 1001) (User: )
Description: The computer has rebooted from a bugcheck. The bugcheck was: 0x000000d1 (0xffffc80191cf2010, 0x00000000000000ff, 0x0000000000000000, 0xfffff8023b4295ae). A dump was saved in: C:\WINDOWS\MEMORY.DMP. Report Id: 3d1c5510-3ccf-44b4-ac47-c45624ec63a3.
Description: The previous system shutdown at 9:06:15 PM on 4/13/2020 was unexpected.
Description: The computer has rebooted from a bugcheck. The bugcheck was: 0x000000d1 (0xffffb40014093010, 0x00000000000000ff, 0x0000000000000000, 0xfffff80246c795ae). A dump was saved in: C:\WINDOWS\Minidump\041320-6703-01.dmp. Report Id: bf205ae9-e7c0-45c0-ab9b-226ff3a1aea2.
Description: The previous system shutdown at 8:35:37 PM on 4/13/2020 was unexpected.
Description: Installation Failure: Windows failed to install the following update with error 0x80073d02: 9NMPJ99VJBWV-Microsoft.YourPhone.
Description: Installation Failure: Windows failed to install the following update with error 0x80073d02: 9NMPJ99VJBWV-Microsoft.YourPhone.
Description: Installation Failure: Windows failed to install the following update with error 0x80073d02: 9NMPJ99VJBWV-Microsoft.YourPhone.
Description: Installation Failure: Windows failed to install the following update with error 0x80073d02: 9NMPJ99VJBWV-Microsoft.YourPhone.
Windows Defender:
===================================
Date: 2020-04-02 09:20:56.934
Description:
Windows Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?linkid=37020&name;=Program:Win32/Unwaders&threatid;=250668&enterprise;=0
Name: Program:Win32/Unwaders
ID: 250668
Severity: Severe
Category: Potentially Unwanted Software
Path: file:_C:\Users\Chad\AppData\Roaming\Browser Assistant\BrowserAssistant.Driver.dll
Detection Origin: Local machine
Detection Type: FastPath
Detection Source: Real-Time Protection
Process Name: C:\Users\Chad\AppData\Roaming\Browser Assistant\BrowserAssistant.exe
Security intelligence Version: AV: 1.313.558.0, AS: 1.313.558.0, NIS: 1.313.558.0
Engine Version: AM: 1.1.16900.4, NIS: 1.1.16900.4
Motherboard: HP 82F2
Processor: Intel(R) Core(TM) i3-7100 CPU @ 3.90GHz
Percentage of memory in use: 41%
Total physical RAM: 8080.34 MB
Available physical RAM: 4732.28 MB
Total Virtual: 16272.34 MB
Available Virtual: 13039 MB
Drive d: (DATA) (Fixed) (Total:917.14 GB) (Free:908.95 GB) NTFS
Drive e: (RECOVERY) (Fixed) (Total:14.37 GB) (Free:1.73 GB) NTFS ==>[system with boot components (obtained from drive)]
\\?\Volume{f7bdef1d-c0ab-4af5-9c2a-062f10ba0fb6}\ () (Fixed) (Total:0.25 GB) (Free:0.18 GB) FAT32
Disk: 0 (Size: 119.2 GB) (Disk ID: 6136ABCD)
Disk: 1 (Size: 931.5 GB) (Disk ID: B119E5B4)