This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Yahoo browser redirects [Solved]

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

In Chrome on a Win10 PC, some address bar searches redirect to Yahoo instead of the defined default (Google).  Edge also acts funny:  when you open it, it opens, minimizes, then maximizes again.  Don't know if the issues are related.

 

My wife found some info in a search and we downloaded SpyHunter, which found browserassistant.lnk and browserassistant.exe but wouldn't fix them unless we paid.  Don't know if these are involved.

 

I downloaded aswMBR.  I ran it twice and it caused a blue screen both times.  I wasn't able to get pen/paper and write down the code fast enough.

 

Thanks in advance for your help.

 

FRST64 log:

 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 13-04-2020
Ran by [removed] (administrator) on DESKTOP-TTM2T1H (HP HP Pavilion Desktop PC 570-p0xx) (13-04-2020 21:12:15)
Running from C:\Users\[removed]\Desktop
[removed] Platform: Windows 10 Home Version 1909 18363.720 (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Adobe Inc. -> Adobe Systems) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.452\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.452\GoogleCrashHandler64.exe
(HP Inc. -> HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(HP Inc. -> HP Inc.) C:\Program Files (x86)\HP\HP JumpStart Bridge\HPJumpStartBridge.exe
(HP Inc. -> HP Inc.) C:\Program Files (x86)\HP\HP JumpStart Launch\HPJumpStartLaunch.exe
(HP Inc. -> HP Inc.) C:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe
(HP Inc. -> HP Inc.) C:\Program Files (x86)\HP\HPAudioSwitch\HPAudioSwitch.exe
(HP Inc. -> HP Inc.) C:\Program Files\HPCommRecovery\HPCommRecovery.exe
(Intel Corporation -> Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Intel Corporation -> Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel Corporation -> Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_31a8dbbf39dcdc3b\jhi_service.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki131064.inf_amd64_5d13f27a9a9843fa\igfxCUIService.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki131064.inf_amd64_5d13f27a9a9843fa\igfxEM.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki131064.inf_amd64_5d13f27a9a9843fa\IntelCpHDCPSvc.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki131064.inf_amd64_5d13f27a9a9843fa\IntelCpHeciSvc.exe
(Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel(R) Wireless Connectivity Solutions -> Intel Corporation) C:\Windows\System32\ibtsiva.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <3>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe <5>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeSH.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2003.8-0\MsMpEng.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2003.8-0\NisSrv.exe
(Realistic Media Inc. -> ) C:\Users\Chad\AppData\Roaming\Browser Assistant\BrowserAssistant.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe
(SEIKO EPSON CORPORATION -> Seiko Epson Corporation) C:\Program Files (x86)\EPSON Software\PMA_A\PMAService.exe
(SEIKO EPSON Corporation -> Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe
(SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_YATIKEE.EXE
(WildTangent Inc -> ) C:\Program Files (x86)\WildTangent Games\Integration\WildTangentHelperService.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM-x32\…\Run: [HPMessageService] => C:\Program Files (x86)\HP\HP System Event\HPMSGSVC.exe [703312 2017-07-21] (HP Inc. -> HP Inc.)
HKLM-x32\…\Run: [EEventManager] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [1092304 2016-03-14] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
HKLM-x32\…\Run: [FUFAXRCV] => C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe [653352 2017-02-16] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
HKLM-x32\…\Run: [FUFAXSTM] => C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe [862248 2017-02-16] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
HKLM-x32\…\Run: [TeamsMachineInstaller] => C:\Program Files (x86)\Teams Installer\Teams.exe [84008696 2019-12-08] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-739738517-1214496134-3013126539-1001\…\Run: [EPLTarget\P0000000000000000] => C:\windows\system32\spool\DRIVERS\x64\3\E_YATIKEE.EXE [298560 2013-09-12] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
HKU\S-1-5-21-739738517-1214496134-3013126539-1001\…\Run: [com.squirrel.Teams.Teams] => C:\Users\Chad\AppData\Local\Microsoft\Teams\Update.exe [2337544 2020-03-14] (Microsoft 3rd Party Application Component -> Microsoft Corporation)
HKU\S-1-5-21-739738517-1214496134-3013126539-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\PhotoScreensaver.scr [567296 2019-03-19] (Microsoft Windows -> Microsoft Corporation)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\80.0.3987.163\Installer\chrmstp.exe [2020-04-03] (Google LLC -> Google LLC)
Startup: C:\Users\Chad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\BrowserAssistant.lnk [2020-03-06]
ShortcutTarget: BrowserAssistant.lnk -> C:\Users\Chad\AppData\Roaming\Browser Assistant\BrowserAssistant.exe (Realistic Media Inc. -> )
Startup: C:\Users\Chad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\updater.lnk [2020-03-06]
ShortcutAndArgument: updater.lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe => -noninteractive -ExecutionPolicy bypass -c "try{$w="$env:APPDATA"+'\Browser Assistant\';[Reflection.Assembly]::Load([System.IO.File]::ReadAllBytes($w+'Updater.dll'));$i=new-object u.U;$i.R()}catch{}"
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {02A43A00-5DB2-48C5-8487-EC76D7BF6E63} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [1117048 2020-03-26] (HP Inc. -> HP Inc.)
Task: {049A88AF-9172-4734-9C26-6B3ACB1CA904} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\MpCmdRun.exe [480272 2020-03-25] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {085D2A27-A43F-414A-874C-A1881515A75D} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\MpCmdRun.exe [480272 2020-03-25] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {0E2273D5-1090-42C1-9E17-6E84297F4041} - System32\Tasks\EPSON WF-3620 Series Invitation {406C84BF-E4F0-4835-83EF-9BEEC53EE65B} => C:\windows\system32\spool\DRIVERS\x64\3\E_YTSKEE.EXE [679488 2013-02-28] (SEIKO EPSON Corporation -> SEIKO EPSON CORPORATION)
Task: {12CC6395-F37E-477A-88A8-CB46AD038573} - System32\Tasks\HPJumpStartLaunch => C:\Program Files (x86)\HP\HP JumpStart Launch\HPJumpStartLaunch.exe [461824 2017-10-06] (HP Inc. -> HP Inc.)
Task: {14325B4B-B34D-40D0-8FFB-249E98397B08} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [1571208 2020-03-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {352F7434-A485-4C53-8189-1CA08F03B277} - System32\Tasks\Hewlett-Packard\HP Active Health\HP Active Health Scan (HPSA) => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.exe [198696 2017-09-27] (HP Inc. -> HP Inc.)
Task: {3E906362-F03C-44D0-9A90-C1C8530058C1} - System32\Tasks\HPCeeScheduleForChad => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [97656 2018-09-11] (HP Inc. -> HP Inc.)
Task: {496EF8CF-1F13-49E5-9B69-8DC87EC94FF5} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9279544 2018-09-13] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
Task: {4A5494F4-411A-42DE-A4D6-0019C8227A32} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [134008 2020-03-25] (HP Inc. -> HP Inc.)
Task: {4A6DD08F-2D7C-4645-A2FA-F1EE10611E56} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [1421704 2020-03-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {53D9042B-0EC3-43FF-BD0A-427F79FFC144} - System32\Tasks\HPAudioSwitch => C:\Program Files (x86)\HP\HPAudioSwitch\HPAudioSwitch.exe [1644472 2019-06-21] (HP Inc. -> HP Inc.)
Task: {655FEC79-1778-4380-BEE9-5BD0DD8C4F54} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [1117048 2020-03-26] (HP Inc. -> HP Inc.)
Task: {69EA899C-4D00-4435-A883-646AA5C3516A} - System32\Tasks\HPEA3JOBS => C:\Program [Argument = Files\HP\HP ePrint\hpeprint.exe /CheckJobs]
Task: {6BE9E83E-F8C8-41F8-9B58-5ADE266C4CA2} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156104 2019-12-26] (Google LLC -> Google LLC)
Task: {73D987CE-7565-412C-A88E-B4467BDBF4C3} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [1421704 2020-03-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {79AC2131-5AE8-4F61-A946-BD56E00F08C6} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [27369752 2020-03-03] (Microsoft Corporation -> Microsoft Corporation)
Task: {7DF8998E-EF69-4E8A-A57D-C074848BCEA9} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [1506680 2019-06-14] (HP Inc. -> HP Inc.)
Task: {8F70775B-7E2E-43E1-B075-EC084AA81ADE} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156104 2019-12-26] (Google LLC -> Google LLC)
Task: {9F884CF8-8269-4463-A1D6-11AB807DCA27} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1242704 2020-02-25] (Adobe Inc. -> Adobe Systems)
Task: {A53D7517-E078-4D39-A60E-A210BE9F0CE7} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [1506680 2019-06-14] (HP Inc. -> HP Inc.)
Task: {AE2F4F11-BCE0-4760-ACF8-FEC2B5861552} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Product Configurator => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\ProductConfig.exe [308088 2020-02-12] (HP Inc. -> HP Inc.)
Task: {B6A2891E-A851-4F22-B957-4366F443CC46} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [27369752 2020-03-03] (Microsoft Corporation -> Microsoft Corporation)
Task: {B8313863-D6B7-4868-9FF2-3ABC4B4D5FF4} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [4461160 2020-01-23] (Microsoft Corporation -> Microsoft Corporation)
Task: {C2DF782A-4DA4-495B-9842-E4AE71E646AD} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\MpCmdRun.exe [480272 2020-03-25] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {C8E5E442-158B-4665-B9C8-DEF57855541B} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\sdxhelper.exe [110632 2020-03-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {CF20AEAF-4C4D-4281-81FD-0CB6CC082D33} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [4461160 2020-01-23] (Microsoft Corporation -> Microsoft Corporation)
Task: {D366AFF7-BEB0-416D-874D-D71401CBC55D} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\MpCmdRun.exe [480272 2020-03-25] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {D7D4CDE4-4254-4388-99EA-A8108955BB7E} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\sdxhelper.exe [110632 2020-03-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {E0A504AA-C700-420C-B764-FC1064A4C19C} - System32\Tasks\BA Scheduler => powershell.exe -WindowStyle Hidden -ExecutionPolicy bypass -c "$env:COMPLUS_version='v4.0.30319';&powershell;{$w="$env:APPDATA"+'\Browser Assistant\';[Reflection.Assembly]::Load([System.IO.File]::ReadAllBytes($w+'Updater.dll'));$i=new-object u.U;$i.ST()}" <==== ATTENTION
Task: {E388E96F-392C-4725-8353-E12D9D628803} - System32\Tasks\EPSON WF-3620 Series Update {406C84BF-E4F0-4835-83EF-9BEEC53EE65B} => C:\windows\system32\spool\DRIVERS\x64\3\E_YTSKEE.EXE [679488 2013-02-28] (SEIKO EPSON Corporation -> SEIKO EPSON CORPORATION)
Task: {FE146D3B-AD56-485E-9EE5-95FAF8E823CF} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [655736 2019-07-31] (HP Inc. -> HP Inc.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\EPSON WF-3620 Series Invitation {406C84BF-E4F0-4835-83EF-9BEEC53EE65B}.job => C:\windows\system32\spool\DRIVERS\x64\3\E_YTSKEE.EXE
Task: C:\WINDOWS\Tasks\EPSON WF-3620 Series Update {406C84BF-E4F0-4835-83EF-9BEEC53EE65B}.job => C:\windows\system32\spool\DRIVERS\x64\3\E_YTSKEE.EXE:/EXE:{406C84BF-E4F0-4835-83EF-9BEEC53EE65B} /F:UpdateWORKGROUP\RE5BBOV0NVGFP$ĊSearches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi
Task: C:\WINDOWS\Tasks\HPCeeScheduleForChad.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{55abad87-d4c4-4d05-b8d5-d633cc63cc75}: [DhcpNameServer] 192.168.1.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://hp17win10.msn.com/?pc=HCTE
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp17win10.msn.com/?pc=HCTE
HKU\S-1-5-21-739738517-1214496134-3013126539-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://hp17win10.msn.com/?pc=HCTE
HKU\S-1-5-21-739738517-1214496134-3013126539-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp17win10.msn.com/?pc=HCTE
SearchScopes: HKLM -> {CD3A9B6B-ADC3-4116-8B3F-FB3EAACA6672} URL = hxxp://www.amazon.com/s/ref=azs_osd_iea?ie=UTF-8&tag;=hp-us1-vsb-20&link;%5Fcode=qs&index;=aps&field-keywords;={searchTerms}
SearchScopes: HKLM-x32 -> {CD3A9B6B-ADC3-4116-8B3F-FB3EAACA6672} URL = hxxp://www.amazon.com/s/ref=azs_osd_iea?ie=UTF-8&tag;=hp-us1-vsb-20&link;%5Fcode=qs&index;=aps&field-keywords;={searchTerms}
SearchScopes: HKU\S-1-5-21-739738517-1214496134-3013126539-1001 -> {CD3A9B6B-ADC3-4116-8B3F-FB3EAACA6672} URL = hxxp://www.amazon.com/s/ref=azs_osd_iea?ie=UTF-8&tag;=hp-us1-vsb-20&link;%5Fcode=qs&index;=aps&field-keywords;={searchTerms}
BHO: IEBrowserAssistant -> {2421CBA2-89B7-4734-8438-49E0D7EB8A75} -> C:\Users\Chad\AppData\Roaming\IEBrowserAssistant\adxloader64.dll [2018-11-13] (Default Company) [File not signed]
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2020-01-23] (Microsoft Corporation -> Microsoft Corporation)
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2017-10-27] (HP Inc. -> HP Inc.)
BHO-x32: IEBrowserAssistant -> {2421CBA2-89B7-4734-8438-49E0D7EB8A75} -> C:\Users\Chad\AppData\Roaming\IEBrowserAssistant\adxloader.dll [2018-11-13] (Default Company) [File not signed]
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2020-01-23] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2017-10-27] (HP Inc. -> HP Inc.)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2020-01-23] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2020-01-23] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2020-01-23] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2020-01-23] (Microsoft Corporation -> Microsoft Corporation)
Edge:
======
DownloadDir: C:\Users\Chad\Downloads
Edge Notifications: HKU\S-1-5-21-739738517-1214496134-3013126539-1001 -> hxxps://trampolineparkmiamisburg.notification-0.com; hxxps://jcpenney.notification-0.com
FireFox:
========
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2020-01-23] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2020-01-23] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2020-03-05] (Adobe Inc. -> Adobe Systems Inc.)
Chrome:
=======
CHR DefaultProfile: Profile 2
CHR Profile: C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Default [2020-04-13]
CHR Notifications: Default -> hxxps://www.smarter.com
CHR Extension: (Chrome Web Store Payments) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-12-26]
CHR Extension: (Chrome Media Router) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-04-06]
CHR Profile: C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Guest Profile [2020-03-16]
CHR Profile: C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1 [2020-04-13]
CHR Notifications: Profile 1 -> hxxps://kizi.com; hxxps://www.youtube.com
CHR Extension: (Slides) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2020-03-16]
CHR Extension: (DocHub - Edit and Sign PDF Documents) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\adgncicbhbjfpijkdmbijninnhnmiblj [2020-04-06]
CHR Extension: (Share to Classroom) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\adokjfanaflbkibffcbhihgihpgijcei [2020-04-06]
CHR Extension: (BIODIGITAL HUMAN) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\agoenciogemlojlhccbcpcfflicgnaak [2020-04-06]
CHR Extension: (Docs) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2020-03-16]
CHR Extension: (Google Drive) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-03-16]
CHR Extension: (Desmos Graphing Calculator) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bhdheahnajobgndecdbggfmcojekgdko [2020-04-06]
CHR Extension: (YouTube) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2020-03-16]
CHR Extension: (GeoGebra Classic) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bnbaboaihhkjoaolfnfoablhllahjnee [2020-04-06]
CHR Extension: (Useful Periodic Table (lite)) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\chachkegffmilnmdlonllkhkfkakghie [2020-04-06]
CHR Extension: (Sheets) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2020-03-16]
CHR Extension: (Google Docs Offline) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-03-16]
CHR Extension: (Camera) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\hfhhnacclhffhdffklopdkcgdhifgngh [2020-04-06]
CHR Extension: (Zoom) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\hmbjbjdpkobdjplfobhljndfdfdipjhg [2020-04-06]
CHR Extension: (Pixlr Editor) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\icmaknaampgiegkcjlimdiidlhopknpk [2020-04-06]
CHR Extension: (Smoothwall) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\jbldkhfglmgeihlcaeliadhipokhocnm [2020-04-08]
CHR Extension: (TestNav) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mdmkkicfmmkgmpkmkdikhlbggogpicma [2020-04-06]
CHR Extension: (Google Classroom) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mfhehppjhmmnlfbbopchdfldgimhfhfk [2020-04-06]
CHR Extension: (Screencastify - Screen Video Recorder) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mmeijimgabbpbgpdklnllpncmdofkcpn [2020-04-13]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2020-03-16]
CHR Extension: (Kids A-Z) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pifccnhncmnilgbnnkjkgicpkeclodpd [2020-04-06]
CHR Extension: (Gmail) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-03-16]
CHR Extension: (Chrome Media Router) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-04-03]
CHR Profile: C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 2 [2020-04-13]
CHR Extension: (Slides) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2020-04-13]
CHR Extension: (Docs) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aohghmighlieiainnegkcijnfilokake [2020-04-13]
CHR Extension: (Google Drive) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-04-13]
CHR Extension: (YouTube) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2020-04-13]
CHR Extension: (Sheets) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2020-04-13]
CHR Extension: (Google Docs Offline) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-04-13]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2020-04-13]
CHR Extension: (Gmail) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-04-13]
CHR Extension: (Chrome Media Router) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-04-13]
CHR Profile: C:\Users\Chad\AppData\Local\Google\Chrome\User Data\System Profile [2020-04-13]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [11600672 2020-03-03] (Microsoft Corporation -> Microsoft Corporation)
R2 Epson PMAService A; C:\Program Files (x86)\Epson Software\PMA_A\PMAService.exe [113144 2017-03-28] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
R2 EpsonScanSvc; C:\windows\system32\EscSvc64.exe [144560 2012-05-17] (SEIKO EPSON Corporation -> Seiko Epson Corporation)
R2 HP Comm Recover; C:\Program Files\HPCommRecovery\HPCommRecovery.exe [1321096 2018-09-28] (HP Inc. -> HP Inc.)
R2 HPJumpStartBridge; c:\Program Files (x86)\HP\HP JumpStart Bridge\HPJumpStartBridge.exe [477184 2017-10-06] (HP Inc. -> HP Inc.)
S3 hpqcaslwmiex; C:\Program Files (x86)\HP\Shared\hpqwmiex.exe [1031704 2016-06-04] (Hewlett-Packard Company -> HP)
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [378744 2020-03-31] (HP Inc. -> HP Inc.)
R2 HPWMISVC; c:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe [628768 2017-07-13] (HP Inc. -> HP Inc.)
R2 ibtsiva; C:\WINDOWS\System32\ibtsiva.exe [529912 2018-12-21] (Intel(R) Wireless Connectivity Solutions -> Intel Corporation)
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\WINDOWS\System32\DriverStore\FileRepository\iclsclient.inf_amd64_7e148e9c120d86df\lib\SocketHeciServer.exe [872416 2019-04-23] (Intel(R) Trust Services -> Intel(R) Corporation)
S2 Intel(R) TPM Provisioning Service; C:\WINDOWS\System32\DriverStore\FileRepository\iclsclient.inf_amd64_7e148e9c120d86df\lib\TPMProvisioningService.exe [800224 2019-04-23] (Intel(R) Trust Services -> Intel(R) Corporation)
R2 jhi_service; C:\WINDOWS\System32\DriverStore\FileRepository\dal.inf_amd64_31a8dbbf39dcdc3b\jhi_service.exe [647568 2019-04-30] (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [310880 2018-09-05] (Intel Corporation -> )
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\NisSrv.exe [3294680 2020-03-25] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WildTangentHelper; C:\Program Files (x86)\WildTangent Games\Integration\WildTangentHelperService.exe [1582384 2019-12-09] (WildTangent Inc -> )
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\MsMpEng.exe [103168 2020-03-25] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [4059744 2018-09-05] (Intel Corporation -> Intel® Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 ibtusb; C:\WINDOWS\System32\drivers\ibtusb.sys [199192 2018-05-11] (Intel(R) Wireless Connectivity Solutions -> Intel Corporation)
R3 Netwtw04; C:\WINDOWS\System32\drivers\Netwtw04.sys [8720384 2019-08-27] (Intel(R) Wireless Connectivity Solutions -> Intel Corporation)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [984032 2017-09-15] (Realtek Semiconductor Corp. -> Realtek )
R3 RTSUER; C:\WINDOWS\system32\Drivers\RtsUer.sys [421312 2017-09-14] (Realtek Semiconductor Corp. -> Realsil Semiconductor Corporation)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [45960 2020-03-25] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [391392 2020-03-25] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [59104 2020-03-25] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

==================== One month (created) ===================
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-04-13 21:12 - 2020-04-13 21:12 - 000030972 _____ C:\Users\Chad\Desktop\FRST.txt
2020-04-13 21:11 - 2020-04-13 21:12 - 000000000 ____D C:\FRST
2020-04-13 21:10 - 2020-04-13 21:10 - 002281984 _____ (Farbar) C:\Users\Chad\Desktop\FRST64.exe
2020-04-13 21:09 - 2020-04-13 21:09 - 001157812 _____ C:\WINDOWS\Minidump\041320-21796-01.dmp
2020-04-13 21:08 - 2020-04-13 21:08 - 688590482 ____N C:\WINDOWS\MEMORY.DMP
2020-04-13 21:04 - 2020-04-13 21:09 - 000000000 ____D C:\WINDOWS\Minidump
2020-04-13 21:02 - 2020-04-13 21:02 - 005198336 _____ (AVAST Software) C:\Users\Chad\Desktop\aswMBR.exe
2020-04-13 20:42 - 2020-04-13 20:42 - 006946736 _____ (EnigmaSoft Limited) C:\Users\Chad\Downloads\sh-remover.exe
2020-04-13 13:33 - 2020-04-13 13:33 - 000002481 _____ C:\Users\Chad\Desktop\Mom - Chrome.lnk
2020-04-06 09:36 - 2020-04-06 09:36 - 000000000 ____D C:\Users\Chad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
2020-03-26 13:20 - 2020-03-26 13:20 - 000078168 _____ (Zoom Video Communications, Inc.) C:\Users\Chad\Downloads\Zoom_42034cce248d8e41.exe
2020-03-16 09:57 - 2020-04-06 09:35 - 000002481 _____ C:\Users\Chad\Desktop\Grace - Chrome.lnk
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-04-13 21:11 - 2019-03-19 00:50 - 000000000 ____D C:\WINDOWS\INF
2020-04-13 21:09 - 2019-03-02 15:44 - 000000000 ____D C:\Users\Chad\AppData\Roaming\Browser Assistant
2020-04-13 21:08 - 2019-12-26 11:39 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2020-04-13 21:08 - 2019-12-26 11:35 - 000000000 ____D C:\Users\Chad
2020-04-13 21:08 - 2019-12-26 11:32 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2020-04-13 21:08 - 2019-03-19 00:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2020-04-13 21:08 - 2018-06-26 20:11 - 000000000 __SHD C:\Users\Chad\IntelGraphicsProfiles
2020-04-13 21:06 - 2019-03-19 00:37 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2020-04-13 21:04 - 2019-12-26 11:32 - 001810805 ____N C:\WINDOWS\Minidump\041320-6703-01.dmp
2020-04-13 21:04 - 2018-07-08 09:46 - 000000360 _____ C:\WINDOWS\Tasks\HPCeeScheduleForChad.job
2020-04-13 20:53 - 2019-12-26 11:39 - 000004164 _____ C:\WINDOWS\system32\Tasks\User_Feed_Synchronization-{1F435414-D5C0-4BCD-8953-1C1EE5157FC8}
2020-04-13 20:42 - 2018-06-26 20:44 - 000000000 ____D C:\Users\Chad\Documents\Outlook Files
2020-04-13 20:28 - 2019-12-26 11:39 - 000003248 _____ C:\WINDOWS\system32\Tasks\HPCeeScheduleForChad
2020-04-13 17:49 - 2019-03-19 00:52 - 000000000 ___HD C:\Program Files\WindowsApps
2020-04-13 17:49 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\AppReadiness
2020-04-11 17:09 - 2018-06-26 20:43 - 000044402 _____ C:\Users\Chad\Desktop\Food Inventory.xlsx
2020-04-11 16:20 - 2018-06-26 20:11 - 000000000 ____D C:\Users\Chad\AppData\Local\Packages
2020-04-09 19:47 - 2020-01-08 20:42 - 000000000 ____D C:\Users\Chad\Desktop\Nate's Camera
2020-04-09 06:35 - 2018-06-26 20:43 - 000000000 ____D C:\Users\Chad\Desktop\8876 Wildfire
2020-04-03 14:01 - 2019-12-26 11:56 - 000002308 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-04-03 14:01 - 2019-12-26 11:56 - 000002267 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2020-04-03 14:01 - 2019-12-26 11:56 - 000002267 _____ C:\ProgramData\Desktop\Google Chrome.lnk
2020-04-02 10:15 - 2018-08-27 09:21 - 000744808 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2020-03-25 09:24 - 2018-06-27 08:13 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2020-03-23 07:55 - 2019-12-26 11:39 - 000003376 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-739738517-1214496134-3013126539-1001
2020-03-23 07:55 - 2019-12-26 11:35 - 000002367 _____ C:\Users\Chad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2020-03-23 07:55 - 2019-09-10 16:25 - 000000000 ___RD C:\Users\Chad\OneDrive - Dayton Regional STEM School
2020-03-20 18:45 - 2019-12-26 11:56 - 000003420 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2020-03-20 18:45 - 2019-12-26 11:56 - 000003296 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2020-03-19 15:28 - 2019-12-26 11:39 - 000004562 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2020-03-19 15:28 - 2019-12-26 09:58 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2020-03-18 09:23 - 2018-06-26 21:10 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2020-03-16 12:06 - 2020-01-31 10:09 - 000013247 _____ C:\Users\Chad\Desktop\Nate Jan Progress Book.xlsx
2020-03-14 10:25 - 2020-01-26 07:55 - 000002366 _____ C:\Users\Chad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Teams.lnk
2020-03-14 10:25 - 2020-01-26 07:55 - 000002358 _____ C:\Users\Chad\Desktop\Microsoft Teams.lnk
==================== Files in the root of some directories ========
2019-05-04 18:55 - 2019-05-04 18:55 - 000024359 _____ () C:\Users\Chad\AppData\Local\recently-used.xbel
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================

 

 

FRST64 Addition:

 

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-04-2020
Ran by [removed] (13-04-2020 21:13:03)
Running from C:\Users\[removed]\Desktop
Windows 10 Home Version 1909 18363.720 (X64) (2019-12-26 15:39:51)
Boot Mode: Normal
==========================================================

==================== Accounts: =============================
Administrator (S-1-5-21-739738517-1214496134-3013126539-500 - Administrator - Disabled)
Chad (S-1-5-21-739738517-1214496134-3013126539-1001 - Administrator - Enabled) => C:\Users\Chad
DefaultAccount (S-1-5-21-739738517-1214496134-3013126539-503 - Limited - Disabled)
Guest (S-1-5-21-739738517-1214496134-3013126539-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-739738517-1214496134-3013126539-504 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe Acrobat Reader DC (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 20.006.20042 - Adobe Systems Incorporated)
Bonjour (HKLM\…\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Browser Assistant (HKLM-x32\…\{8AD59EE9-679B-466D-8423-57F15B149794}) (Version: 1.37.7345.30189 - Realistic Media Inc.)
Direct Game UNI Installer (HKLM-x32\…\{C77717A7-09BF-49AF-92F2-9F3ED9AF5BFD}) (Version: 1.0.17 - GamesLOL)
Epson Event Manager (HKLM-x32\…\{006C8256-3855-43BF-8BA5-4B4C40F41F71}) (Version: 3.10.0065 - Seiko Epson Corporation)
Epson FAX Utility (HKLM-x32\…\{0CBE6C93-CB2E-4378-91EE-12BE6D4E2E4A}) (Version: 2.02.00 - Seiko Epson Corporation)
Epson PC-FAX Driver (HKLM-x32\…\EPSON PC-FAX Driver 2) (Version:  - Seiko Epson Corporation)
Epson ReadyInk Agent (A) (HKLM-x32\…\{A9B4584F-A29E-4880-97E6-1744B4AF2AF8}) (Version: 1.0.1.0 - Seiko Epson Corporation)
EPSON Scan (HKLM-x32\…\EPSON Scanner) (Version:  - Seiko Epson Corporation)
Epson Software Updater (HKLM-x32\…\{B55DB65D-EF6E-4E04-89D5-B03603BF681B}) (Version: 4.4.5 - SEIKO EPSON CORPORATION)
EPSON WF-3620 Series Printer Uninstall (HKLM\…\EPSON WF-3620 Series) (Version:  - SEIKO EPSON Corporation)
Epson WF-3620 User’s Guide version 1.0 (HKLM-x32\…\UsersGuideEpson WF-3620 User’s Guide_is1) (Version: 1.0 - )
EpsonNet Print (HKLM\…\{96ED1D58-440C-4345-8FEE-C4781366C67F}) (Version: 3.1.4.0 - SEIKO EPSON Corporation)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 80.0.3987.163 - Google LLC)
Google Update Helper (HKLM-x32\…\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.451 - Google LLC) Hidden
HP Audio Switch (HKLM-x32\…\{3A5141D4-47DB-4302-9B1C-272BE585BC8A}) (Version: 1.0.179.0 - HP Inc.)
HP Connection Optimizer (HKLM-x32\…\{6468C4A5-E47E-405F-B675-A70A70983EA6}) (Version: 2.0.15.0 - HP Inc.)
HP Documentation (HKLM\…\HP_Documentation) (Version: 1.0.0.1 - HP Inc.)
HP ePrint SW (HKLM-x32\…\{cdb5f70f-5107-4613-bf69-15de903b5b5d}) (Version: 5.5.22560 - HP Inc.)
HP JumpStart Apps (HKLM-x32\…\HP JumpStart Apps) (Version: 7.0.32 - HP Inc.)
HP JumpStart Bridge (HKLM-x32\…\{3FC961DB-BD36-4D8D-B276-0C456A2BB638}) (Version: 1.4.0.441 - HP Inc.)
HP JumpStart Launch (HKLM-x32\…\{F213102E-FD30-4E22-AF73-4C682D65FFEE}) (Version: 1.4.441.0 - HP Inc.)
HP Support Assistant (HKLM-x32\…\{4AAC4B07-77EF-4BCF-88DC-D24E4DE683E8}) (Version: 8.8.24.33 - HP Inc.)
HP Support Solutions Framework (HKLM-x32\…\{63F82052-C045-4F97-A3CA-C41D2CCA1FFA}) (Version: 12.15.14.3 - HP Inc.)
HP System Event Utility (HKLM-x32\…\{4B0A7A8A-ECE5-4639-9A0D-C535F354313D}) (Version: 1.4.26 - HP Inc.)
IEBrowserAssistant (HKLM-x32\…\{BC63C727-3079-49AA-876A-8E459D35CB72}) (Version: 1.0.0 - Realistic Media Inc.)
Intel(R) Chipset Device Software (HKLM-x32\…\{17408817-d415-4768-a160-ae6d46d6bdb0}) (Version: 10.1.1.44 - Intel(R) Corporation) Hidden
Intel(R) Management Engine Components (HKLM\…\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.7.0.1043 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 25.20.100.6446 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\…\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 15.8.1.1007 - Intel Corporation)
Intel(R) Serial IO (HKLM\…\{9FD91C5C-44AE-4D9D-85BE-AE52816B0294}) (Version: 30.100.1725.1 - Intel Corporation)
Intel(R) Wireless Bluetooth(R) (HKLM-x32\…\{00000080-0190-1033-84C8-B8D95FA3C8C3}) (Version: 19.80.0 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\…\{f8c930bd-0a68-425f-8c11-87723d1e2c97}) (Version: 20.90.0 - Intel Corporation)
Microsoft Office 365 - en-us (HKLM\…\o365homepremretail - en-us) (Version: 16.0.11929.20648 - Microsoft Corporation)
Microsoft Office 365 ProPlus - en-us (HKLM\…\O365ProPlusRetail - en-us) (Version: 16.0.11929.20648 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-739738517-1214496134-3013126539-1001\…\OneDriveSetup.exe) (Version: 19.232.1124.0010 - Microsoft Corporation)
Microsoft Teams (HKU\S-1-5-21-739738517-1214496134-3013126539-1001\…\Teams) (Version: 1.3.00.3564 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\…\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\…\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\…\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\…\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24123 (HKLM-x32\…\{2cbcedbb-f38c-48a3-a3e1-6c6fd821a7f4}) (Version: 14.0.24123.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24123 (HKLM-x32\…\{206898cc-4b41-4d98-ac28-9f9ae57f91fe}) (Version: 14.0.24123.0 - Microsoft Corporation)
Office 16 Click-to-Run Extensibility Component (HKLM-x32\…\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.11929.20648 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\…\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.11929.20648 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\…\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.11929.20648 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM-x32\…\{90160000-008C-0409-0000-0000000FF1CE}) (Version: 16.0.11929.20648 - Microsoft Corporation) Hidden
Realtek Card Reader (HKLM-x32\…\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.15063.31237 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.19.627.2017 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8536 - Realtek Semiconductor Corp.)
Teams Machine-Wide Installer (HKLM-x32\…\{39AF0813-FA7B-4860-ADBE-93B9B214B914}) (Version: 1.2.0.34161 - Microsoft Corporation)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\…\{F14FB68A-9188-4036-AD0D-D054BC9C9291}) (Version: 2.59.0.0 - Microsoft Corporation)
Vulkan Run Time Libraries 1.1.70.1 (HKLM\…\VulkanRT1.1.70.1) (Version: 1.1.70.1 - LunarG, Inc.) Hidden
Windows 10 Update Assistant (HKLM-x32\…\{D5C69738-B486-402E-85AC-2456D98A64E4}) (Version: 1.4.9200.22391 - Microsoft Corporation)
Packages:
=========
Any Player -> C:\Program Files\WindowsApps\15191PeakPlayer.50533F9B98293_3.1.4.0_x64__y5c4dfz5b21fm [2020-04-11] (Any DVD & Office App)
Connect -> C:\Windows\SystemApps\Microsoft.Windows.DevicesFlowHost_cw5n1h2txyewy [2019-12-26] (Microsoft Corporation)
Dolby Access -> C:\Program Files\WindowsApps\DolbyLaboratories.DolbyAccess_3.1.4081.0_x64__rz1tebttyb220 [2020-01-28] (Dolby Laboratories)
Floor Adjustment -> C:\Windows\SystemApps\RoomAdjustment_cw5n1h2txyewy [2019-12-26] (Microsoft Corporation)
HP JumpStart -> C:\Program Files\WindowsApps\AD2F1837.HPJumpStart_1.4.443.0_x86__v10z8vjag6ke6 [2018-03-06] (HP Inc.)
Learn Mixed Reality -> C:\Windows\SystemApps\MixedRealityLearning_cw5n1h2txyewy [2019-12-26] (Microsoft Corporation)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-01-19] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-01-19] (Microsoft Corporation) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.6.1224.0_x64__8wekyb3d8bbwe [2020-02-28] (Microsoft Studios) [MS Ad]
MSN Weather -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.36.20714.0_x64__8wekyb3d8bbwe [2020-03-24] (Microsoft Corporation) [MS Ad]
New for You -> C:\Windows\SystemApps\WhatsNew_cw5n1h2txyewy [2019-12-26] (Microsoft Corporation)
Passthrough -> C:\Windows\SystemApps\passthrough_cw5n1h2txyewy [2019-12-26] (Microsoft Corporation)
Photos Add-on -> C:\Program Files\WindowsApps\Microsoft.Windows.Photos.DLC.Main_2017.39121.36610.0_x64__8wekyb3d8bbwe [2019-06-18] (Microsoft Corporation)
Photos Media Engine Add-on -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2019-09-27] (Microsoft Corporation)
Power Media Player 14 for HP Consumer PCs with DVD -> C:\Program Files\WindowsApps\CyberLinkCorp.hs.PowerMediaPlayer14forHPConsumerPC_14.2.9528.0_x86__06qsbagp91rvg [2019-01-26] (CYBERLINKCOM CORP)
Sign In -> C:\Windows\SystemApps\WebAuthBridgeInternet_cw5n1h2txyewy [2019-12-26] (ms-resource:PublisherDisplayName)
Sign In -> C:\Windows\SystemApps\WebAuthBridgeInternetSso_cw5n1h2txyewy [2019-12-26] (ms-resource:PublisherDisplayName)
Sign In -> C:\Windows\SystemApps\WebAuthBridgeIntranetSso_cw5n1h2txyewy [2019-12-26] (ms-resource:PublisherDisplayName)
Simple Solitaire -> C:\Program Files\WindowsApps\26720RandomSaladGamesLLC.SimpleSolitaire_6.18.78.0_x64__kx24dqmazqk8j [2020-02-29] (Random Salad Games LLC) [MS Ad]
Sling TV -> C:\Program Files\WindowsApps\SlingTVLLC.SlingTV_7.0.8.0_x86__vgszm6stshdqy [2019-01-09] (Sling TV LLC)
Smartfriend by HP Care -> C:\Program Files\WindowsApps\AD2F1837.SmartfriendbyHPCare_1.1.13.0_x64__v10z8vjag6ke6 [2018-03-06] (HP Inc.)
==================== Custom CLSID (Whitelisted): ==============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-739738517-1214496134-3013126539-1001_Classes\CLSID\{04271989-C4D2-D497-85E3-A60B7ED435AC} -> [OneDrive - Dayton Regional STEM School] => C:\Users\Chad\OneDrive - Dayton Regional STEM School [2019-09-10 16:25]
CustomCLSID: HKU\S-1-5-21-739738517-1214496134-3013126539-1001_Classes\CLSID\{19A6E644-14E6-4A60-B8D7-DD20610A871D}\InprocServer32 -> C:\Users\Chad\AppData\Local\Microsoft\TeamsMeetingAddin\1.0.19350.3\x64\Microsoft.Teams.AddinLoader.dll (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-739738517-1214496134-3013126539-1001_Classes\CLSID\{CB965DF1-B8EA-49C7-BDAD-5457FDC1BF92}\InprocServer32 -> C:\Users\Chad\AppData\Local\Microsoft\TeamsMeetingAddin\1.0.19350.3\x64\Microsoft.Teams.AddinLoader.dll (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} =>  -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\System32\DriverStore\FileRepository\ki131064.inf_amd64_5d13f27a9a9843fa\igfxDTCM.dll [2019-02-17] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
==================== Codecs (Whitelisted) ====================
==================== Shortcuts & WMI ========================
(The entries could be listed to be restored or removed.)
ShortcutWithArgument: C:\Users\Chad\Desktop\Grace - Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> –profile-directory="Profile 1"
ShortcutWithArgument: C:\Users\Chad\Desktop\Mom - Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> –profile-directory="Profile 2"
ShortcutWithArgument: C:\Users\Chad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Camera.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) ->  –profile-directory="Profile 1" –app-id=hfhhnacclhffhdffklopdkcgdhifgngh
ShortcutWithArgument: C:\Users\Chad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\GeoGebra Classic.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) ->  –profile-directory="Profile 1" –app-id=bnbaboaihhkjoaolfnfoablhllahjnee
ShortcutWithArgument: C:\Users\Chad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\TestNav.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) ->  –profile-directory="Profile 1" –app-id=mdmkkicfmmkgmpkmkdikhlbggogpicma
ShortcutWithArgument: C:\Users\Chad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Zoom.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) ->  –profile-directory="Profile 1" –app-id=hmbjbjdpkobdjplfobhljndfdfdipjhg
ShortcutWithArgument: C:\Users\Chad\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\ff13ca23fee04978\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> –profile-directory="Profile 5"
ShortcutWithArgument: C:\Users\Chad\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\9501e18d7c2ab92e\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> –profile-directory="Profile 2"
ShortcutWithArgument: C:\Users\Chad\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\69639df789022856\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> –profile-directory="Profile 1"
ShortcutWithArgument: C:\Users\Chad\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\48499db33039e897\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> –profile-directory="Profile 4"
ShortcutWithArgument: C:\Users\Chad\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\225bb61db2f318c1\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> –profile-directory="Profile 3"
==================== Loaded Modules (Whitelisted) =============
2020-02-13 20:40 - 2020-02-13 20:40 - 000138240 _____ ( ) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Interop.IWs06dcaa36#\803ddc517fb122da5941404364d527d7\Interop.IWshRuntimeLibrary.ni.dll
2020-02-13 20:38 - 2020-02-13 20:38 - 000160768 _____ () [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\BRIDGECommon\106852b62f2dce48f68f823bb25b51bb\BRIDGECommon.ni.dll
2020-02-13 20:39 - 2020-02-13 20:39 - 000125440 _____ () [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\BridgeExtension\512361b13bdadec3c76781ced2b9ba25\BridgeExtension.ni.dll
2020-02-13 20:39 - 2020-02-13 20:39 - 000395264 _____ () [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\CleanStartController\8a1af52831b2ac51f3246da60333b1d9\CleanStartController.ni.dll
2020-02-13 20:39 - 2020-02-13 20:39 - 000145920 _____ () [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Registratio4eabc192#\0c4e7d4693b00c0677da9c65c0889302\RegistrationUtilities.ni.dll
2020-02-13 20:40 - 2020-02-13 20:40 - 000134656 _____ (hardcodet.net) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Hardcodet.W6cab32f3#\4faa7a04101a97b05eff64101eb5eb70\Hardcodet.Wpf.TaskbarNotification.ni.dll
2020-02-13 20:39 - 2020-02-13 20:39 - 000136192 _____ (HP Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\CommonPortable\661da84cbe3eb8c9142d35b54c52a1d9\CommonPortable.ni.dll
2020-02-13 20:40 - 2020-02-13 20:40 - 001701888 _____ (Mark Heath & Contributors) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\NAudio\9e86bf19bde10a6d24242ac28ecf3ad6\NAudio.ni.dll
2020-02-13 20:38 - 2020-02-13 20:38 - 002306560 _____ (Newtonsoft) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Newtonsoft.Json\cbac7b8be40869c5395f0ef28ddabd0b\Newtonsoft.Json.ni.dll
2020-02-13 20:40 - 2020-02-13 20:40 - 003060736 _____ (Newtonsoft) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Newtonsoft.Json\f49f899040cee6804ea2c4a4d309f9a9\Newtonsoft.Json.ni.dll
2016-05-09 09:20 - 2016-05-09 09:20 - 000132096 _____ (Seiko Epson Corporation) [File not signed] C:\Program Files (x86)\EPSON Software\Event Manager\epnsm.dll
2009-10-21 17:39 - 2009-10-21 17:39 - 000291328 _____ (SEIKO EPSON CORPORATION) [File not signed] C:\Program Files (x86)\EPSON Software\Event Manager\LcMgr.dll
2016-09-14 14:31 - 2016-09-14 14:31 - 000500736 _____ (SEIKO EPSON CORPORATION) [File not signed] C:\WINDOWS\System32\enppmon.dll
2020-02-13 20:40 - 2020-02-13 20:40 - 000793088 _____ (The Apache Software Foundation) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\log4net\4e37f9f72190581f516ebaf75e4fb60a\log4net.ni.dll
==================== Alternate Data Streams (Whitelisted) ========
==================== Safe Mode (Whitelisted) ==================
==================== Association (Whitelisted) =================
==================== Internet Explorer trusted/restricted ==========
(If an entry is included in the fixlist, it will be removed from the registry.)
IE trusted site: HKU\S-1-5-21-739738517-1214496134-3013126539-1001\…\sharepoint.com -> hxxps://daytonstemschoolorg-files.sharepoint.com
==================== Hosts content: =========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2017-09-29 09:46 - 2017-09-29 09:44 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts
==================== Other Areas ===========================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-739738517-1214496134-3013126539-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Chad\Pictures\Easter 2020 4.JPG
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
(If an entry is included in the fixlist, it will be removed.)
HKLM\…\StartupApproved\Run32: => "HPMessageService"
HKLM\…\StartupApproved\Run32: => "FUFAXRCV"
HKLM\…\StartupApproved\Run32: => "FUFAXSTM"
HKU\S-1-5-21-739738517-1214496134-3013126539-1001\…\StartupApproved\Run: => "OneDrive"
==================== FirewallRules (Whitelisted) ================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{00CB71B4-D99C-4C0C-93DB-E17E4281AB9F}] => (Allow) C:\Users\Chad\AppData\Local\Temp\WF-3620\Common\EpsonNet Setup\ENEasyApp.exe No File
FirewallRules: [{1100765F-5717-49C7-804E-A0E76CF930E1}] => (Allow) C:\Users\Chad\AppData\Local\Temp\WF-3620\Common\EpsonNet Setup\ENEasyApp.exe No File
FirewallRules: [{A615BE46-8F40-44D2-8C07-8D1837C9A155}] => (Allow) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
FirewallRules: [{E701CCE1-991D-4E32-BE22-6B8CA0133AC8}] => (Allow) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
FirewallRules: [{CADF8CDF-AFAC-4BD2-9CDB-7BE1992B7137}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{87132A74-3F41-45FF-AAD5-E9DC2C4BC058}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{33CA5CE1-C253-4D11-AB9E-0C6387E9A4D5}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{335234DF-FD72-42B1-B714-47D5CF448F45}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{3EE1FDF2-12E1-47B6-A319-4940FB0F3F15}] => (Allow) C:\Program Files (x86)\Common Files\Mcafee\MMSSHost\MMSSHost.exe No File
FirewallRules: [{C74A739F-68DA-408D-B3F7-57165959BA47}] => (Allow) C:\Program Files\Common Files\McAfee\MMSSHost\MMSSHost.exe No File
FirewallRules: [{1D23678D-91C3-4FFE-8DCD-9F814D770BC4}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{01DCF1BB-01F6-402D-860B-5A5625BF40AD}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{CA76B6D7-C405-4660-AD8A-35235D9565F5}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe (Intel Corporation -> )
FirewallRules: [{3854827A-6F82-43F1-8DEA-90A13A569D63}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{5244D7F8-C295-4E2C-A94A-E37300DF7191}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{34788936-5E00-483F-B55C-35120CC9C0ED}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{4F4D9931-5619-4133-BE4D-BF7A8F97BB5F}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
==================== Restore Points =========================
ATTENTION: System Restore is disabled (Total:118.01 GB) (Free:27.9 GB) (24%)
==================== Faulty Device Manager Devices ============

==================== Event log errors: ========================
Application errors:
==================
Error: (04/13/2020 08:59:42 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: MicrosoftEdgeCP.exe, version: 11.0.18362.1, time stamp: 0xceb8cbe1
Faulting module name: EdgeContent.dll, version: 11.0.18362.657, time stamp: 0xe6b5ea8d
Exception code: 0xc0000409
Fault offset: 0x0000000000095f82
Faulting process id: 0x1e6c
Faulting application start time: 0x01d611f7fad3ceb7
Faulting application path: C:\Windows\System32\MicrosoftEdgeCP.exe
Faulting module path: C:\Windows\System32\EdgeContent.dll
Report Id: 8a0261d9-7a72-492f-85b6-d659692b74a9
Faulting package full name: Microsoft.MicrosoftEdge_44.18362.449.0_neutral__8wekyb3d8bbwe
Faulting package-relative application ID: MicrosoftEdge
Error: (04/13/2020 08:41:21 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (31128,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.
Error: (04/13/2020 08:00:37 PM) (Source: Microsoft-Windows-PerfNet) (EventID: 2004) (User: DESKTOP-TTM2T1H)
Description: Unable to open the Server service performance object. The first four bytes (DWORD) of the Data section contains the status code.
Error: (04/13/2020 07:43:31 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (29828,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.
Error: (04/13/2020 05:54:14 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (26504,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.
Error: (04/13/2020 04:28:25 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (30732,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.
Error: (04/13/2020 02:27:21 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (30732,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.
Error: (04/13/2020 02:21:17 PM) (Source: Microsoft-Windows-Perflib) (EventID: 1020) (User: NT AUTHORITY)
Description: The required buffer size is greater than the buffer size passed to the Collect function of the "C:\Windows\System32\perfts.dll" Extensible Counter DLL for the "LSM" service. The given buffer size was 4344 and the required size was 33408.

System errors:
=============
Error: (04/13/2020 09:09:01 PM) (Source: BugCheck) (EventID: 1001) (User: )
Description: The computer has rebooted from a bugcheck.  The bugcheck was: 0x000000d1 (0xffffc80191cf2010, 0x00000000000000ff, 0x0000000000000000, 0xfffff8023b4295ae). A dump was saved in: C:\WINDOWS\MEMORY.DMP. Report Id: 3d1c5510-3ccf-44b4-ac47-c45624ec63a3.
Error: (04/13/2020 09:08:44 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 9:06:15 PM on ‎4/‎13/‎2020 was unexpected.
Error: (04/13/2020 09:04:59 PM) (Source: BugCheck) (EventID: 1001) (User: )
Description: The computer has rebooted from a bugcheck.  The bugcheck was: 0x000000d1 (0xffffb40014093010, 0x00000000000000ff, 0x0000000000000000, 0xfffff80246c795ae). A dump was saved in: C:\WINDOWS\Minidump\041320-6703-01.dmp. Report Id: bf205ae9-e7c0-45c0-ab9b-226ff3a1aea2.
Error: (04/13/2020 09:04:58 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 8:35:37 PM on ‎4/‎13/‎2020 was unexpected.
Error: (04/11/2020 08:33:52 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80073d02: 9NMPJ99VJBWV-Microsoft.YourPhone.
Error: (03/26/2020 09:28:14 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80073d02: 9NMPJ99VJBWV-Microsoft.YourPhone.
Error: (03/24/2020 02:20:09 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80073d02: 9NMPJ99VJBWV-Microsoft.YourPhone.
Error: (03/06/2020 08:48:01 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80073d02: 9NMPJ99VJBWV-Microsoft.YourPhone.

Windows Defender:
===================================
Date: 2020-04-02 09:20:56.934
Description:
Windows Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?linkid=37020&name;=Program:Win32/Unwaders&threatid;=250668&enterprise;=0
Name: Program:Win32/Unwaders
ID: 250668
Severity: Severe
Category: Potentially Unwanted Software
Path: file:_C:\Users\Chad\AppData\Roaming\Browser Assistant\BrowserAssistant.Driver.dll
Detection Origin: Local machine
Detection Type: FastPath
Detection Source: Real-Time Protection
Process Name: C:\Users\Chad\AppData\Roaming\Browser Assistant\BrowserAssistant.exe
Security intelligence Version: AV: 1.313.558.0, AS: 1.313.558.0, NIS: 1.313.558.0
Engine Version: AM: 1.1.16900.4, NIS: 1.1.16900.4
==================== Memory info ===========================
BIOS: AMI F.24 01/23/2018
Motherboard: HP 82F2
Processor: Intel(R) Core(TM) i3-7100 CPU @ 3.90GHz
Percentage of memory in use: 41%
Total physical RAM: 8080.34 MB
Available physical RAM: 4732.28 MB
Total Virtual: 16272.34 MB
Available Virtual: 13039 MB
==================== Drives ================================
Drive c: (Windows) (Fixed) (Total:118.01 GB) (Free:27.9 GB) NTFS
Drive d: (DATA) (Fixed) (Total:917.14 GB) (Free:908.95 GB) NTFS
Drive e: (RECOVERY) (Fixed) (Total:14.37 GB) (Free:1.73 GB) NTFS ==>[system with boot components (obtained from drive)]
\\?\Volume{c6de160f-ea7b-4d4f-9c1d-8a0c8ab91ab9}\ (Windows RE tools) (Fixed) (Total:0.96 GB) (Free:0.5 GB) NTFS
\\?\Volume{f7bdef1d-c0ab-4af5-9c2a-062f10ba0fb6}\ () (Fixed) (Total:0.25 GB) (Free:0.18 GB) FAT32
==================== MBR & Partition Table ====================
==========================================================
Disk: 0 (Size: 119.2 GB) (Disk ID: 6136ABCD)
Partition: GPT.
==========================================================
Disk: 1 (Size: 931.5 GB) (Disk ID: B119E5B4)
Partition: GPT.
==================== End of Addition.txt =======================

 

Hello ChadA and welcome to Bleeping Computer.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:

  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!

IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

===================================================

Note: Please complete these tasks in the order given in the instructions.

===================================================

Uninstall programmes

Uninstall the following programmes:


Browser Assistant

IEBrowser Assistant
 

To do this:

  • right-click the Start button and click Control Panel
  • go to Programs and Features - (if your Control Panel is in ‘Category’ view, go to Uninstall a Program)
  • locate Browser Assistant, click it to select it, and then click Uninstall.

===================================================

Download and run AdwCleaner

Download AdwCleaner from here and save it to your desktop.

  • run AdwCleaner by clicking on Scan Now
  • when it has finished, leave everything that was found checked, (ticked), then click on Clean and Repair
  • if it asks to reboot, allow the reboot
  • on reboot, click on View Log File; please attach the content of the log to your next reply.

===================================================

Run Malwarebytes Anti-Malware

Download it from here:

  • run the program
  • click on the ‘Dashboard’ to make sure everything is up to date, (it is not necessary to upgrade to the premium version of MBAM)
  • click on the ‘Scan’ tab, (directly below the Dashboard tab)
  • select the Threat Scan option
  • slick the Scan Now button
  • Threat Scan will begin
  • when the scan has completed and if malware was found, click the Quarantine Selected button to allow MBAM to quarantine what was found
  • if prompted to restart the computer, close all other programs and click Yes to restart your computer
  • once you are back at your desktop, open MBAM once more
  • click on the ‘Reports’ tab
  • double-click on the most recent Scan Report
  • click on Export, then Copy to Clipboard

===================================================

Please run FRST again and make sure there is a checkmark next to ‘Addition.txt’ before you hit Scan.

Logs to include with next post:

AdwCleaner log
Mbam.txt
New Frst.txt
New Addition.txt


Thanks

Satchfan

Satchfan,

Thanks!  I did the instructions as best I could.  Some of the programs have newer versions and the screens/options are different.

 

ADW Cleaner Log:

 

 

# ——————————-
# Malwarebytes AdwCleaner 8.0.4.0
# ——————————-
# Build:    04-03-2020
# Database: 2020-04-08.2 (Cloud)
# Support:  https://www.malwarebytes.com/support
#
# ——————————-
# Mode: Clean
# ——————————-
# Start:    04-14-2020
# Duration: 00:00:05
# OS:       Windows 10 Home
# Cleaned:  41
# Failed:   1

***** [ Services ] *****
No malicious services cleaned.
***** [ Folders ] *****
Deleted       C:\ProgramData\TSR7Settings
***** [ Files ] *****
No malicious files cleaned.
***** [ DLL ] *****
No malicious DLLs cleaned.
***** [ WMI ] *****
No malicious WMI cleaned.
***** [ Shortcuts ] *****
No malicious shortcuts cleaned.
***** [ Tasks ] *****
No malicious tasks cleaned.
***** [ Registry ] *****
Deleted       HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\dotomi.com
Deleted       HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\s.thebrighttag.com
Deleted       HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\search-findit.com
Deleted       HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\thebrighttag.com
Deleted       HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\dotomi.com
Deleted       HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\s.thebrighttag.com
Deleted       HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\search-findit.com
Deleted       HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\thebrighttag.com
***** [ Chromium (and derivatives) ] *****
Deleted       Share to Classroom - adokjfanaflbkibffcbhihgihpgijcei
***** [ Chromium URLs ] *****
No malicious Chromium URLs cleaned.
***** [ Firefox (and derivatives) ] *****
No malicious Firefox entries cleaned.
***** [ Firefox URLs ] *****
No malicious Firefox URLs cleaned.
***** [ Hosts File Entries ] *****
No malicious hosts file entries cleaned.
***** [ Preinstalled Software ] *****
Deleted       Preinstalled.HPAudioSwitch   Folder   C:\Program Files (x86)\HP\HPAUDIOSWITCH
Deleted       Preinstalled.HPAudioSwitch   Registry   HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{53D9042B-0EC3-43FF-BD0A-427F79FFC144}
Deleted       Preinstalled.HPAudioSwitch   Registry   HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\HPAudioSwitch
Deleted       Preinstalled.HPAudioSwitch   Task   C:\Windows\System32\Tasks\HPAUDIOSWITCH
Deleted       Preinstalled.HPJumpStartApps   Folder   C:\Program Files (x86)\HP\HP JUMPSTART APPS
Deleted       Preinstalled.HPJumpStartApps   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\HP JumpStart Apps
Deleted       Preinstalled.HPJumpStartBridge   Folder   C:\Program Files (x86)\HP\HP JUMPSTART BRIDGE
Deleted       Preinstalled.HPJumpStartLaunch   Folder   C:\Program Files (x86)\HP\HP JUMPSTART LAUNCH
Deleted       Preinstalled.HPJumpStartLaunch   Registry   HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{12CC6395-F37E-477A-88A8-CB46AD038573}
Deleted       Preinstalled.HPJumpStartLaunch   Registry   HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\HPJumpStartLaunch
Deleted       Preinstalled.HPJumpStartLaunch   Task   C:\Windows\System32\Tasks\HPJUMPSTARTLAUNCH
Deleted       Preinstalled.HPRegistrationService   Folder   C:\Program Files (x86)\HP\HP REGISTRATION SERVICE
Deleted       Preinstalled.HPRegistrationService   Folder   C:\ProgramData\HP\HP REGISTRATION SERVICE
Deleted       Preinstalled.HPSupportAssistant   Folder   C:\HP\SUPPORT
Deleted       Preinstalled.HPSupportAssistant   Folder   C:\Program Files (x86)\HEWLETT-PACKARD\HP CUSTOMER FEEDBACK
Deleted       Preinstalled.HPSupportAssistant   Folder   C:\Program Files (x86)\HEWLETT-PACKARD\HP SUPPORT FRAMEWORK
Deleted       Preinstalled.HPSupportAssistant   Folder   C:\ProgramData\HEWLETT-PACKARD\HP SUPPORT FRAMEWORK
Deleted       Preinstalled.HPSupportAssistant   Folder   C:\Users\Chad\AppData\Local\HEWLETT-PACKARD\HP SUPPORT FRAMEWORK
Deleted       Preinstalled.HPSupportAssistant   Folder   C:\Users\Chad\AppData\Roaming\HEWLETT-PACKARD\HP SUPPORT FRAMEWORK
Deleted       Preinstalled.HPSupportAssistant   Folder   C:\Windows\System32\config\systemprofile\AppData\Local\HEWLETT-PACKARD\HP SUPPORT FRAMEWORK
Deleted       Preinstalled.HPSupportAssistant   Registry   HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}
Deleted       Preinstalled.HPSupportAssistant   Registry   HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}
Deleted       Preinstalled.HPSupportAssistant   Registry   HKLM\Software\Classes\CLSID\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}
Deleted       Preinstalled.HPSupportAssistant   Registry   HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}
Deleted       Preinstalled.HPSupportAssistant   Registry   HKLM\Software\Wow6432Node\\Classes\CLSID\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}
Deleted       Preinstalled.HPSupportAssistant   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}
Deleted       Preinstalled.HPSupportAssistant   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{4AAC4B07-77EF-4BCF-88DC-D24E4DE683E8}
Deleted       Preinstalled.HPSupportAssistant   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{63F82052-C045-4F97-A3CA-C41D2CCA1FFA}
Deleted       Preinstalled.HPSureConnect   Folder   C:\Program Files\HPCOMMRECOVERY
Deleted       Preinstalled.HPSureConnect   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{6468C4A5-E47E-405F-B675-A70A70983EA6}
Deleted       Preinstalled.WildTangentGamesBundle   Folder   C:\Program Files (x86)\WILDTANGENT GAMES
Not Deleted   Preinstalled.HPSupportAssistant   Folder   C:\Program Files (x86)\HEWLETT-PACKARD\HP SUPPORT SOLUTIONS

*************************
[+] Delete Tracing Keys
[+] Reset Winsock
*************************
AdwCleaner[S00].txt - [7012 octets] - [14/04/2020 08:28:17]
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########

 

 

MBAM.txt:

 

 

Malwarebytes
www.malwarebytes.com
-Log Details-
Scan Date: 4/14/20
Scan Time: 8:34 AM
Log File: 5078bb2e-7e4c-11ea-8d96-80ce62ef4bfb.json
-Software Information-
Version: 4.1.0.56
Components Version: 1.0.867
Update Package Version: 1.0.22452
License: Trial
-System Information-
OS: Windows 10 (Build 18362.720)
CPU: x64
File System: NTFS
User: DESKTOP-TTM2T1H\Chad
-Scan Summary-
Scan Type: Threat Scan
Scan Initiated By: Manual
Result: Completed
Objects Scanned: 279370
Threats Detected: 8
Threats Quarantined: 8
Time Elapsed: 1 min, 8 sec
-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Detect
PUM: Detect
-Scan Details-
Process: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registry Key: 2
Trojan.BrowserAssistant.PS, HKU\S-1-5-21-739738517-1214496134-3013126539-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{2421CBA2-89B7-4734-8438-49E0D7EB8A75}, Quarantined, 1243, 775632, , , ,
Trojan.BrowserAssistant.PS, HKU\S-1-5-21-739738517-1214496134-3013126539-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{2421CBA2-89B7-4734-8438-49E0D7EB8A75}, Quarantined, 1243, 775632, 1.0.22452, , ame,
Registry Value: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Data Stream: 0
(No malicious items detected)
Folder: 1
Trojan.BrowserAssistant.Powershell, C:\USERS\CHAD\APPDATA\ROAMING\BROWSER ASSISTANT, Quarantined, 3844, 787388, 1.0.22452, , ame,
File: 5
Trojan.BrowserAssistant.Powershell, C:\USERS\CHAD\APPDATA\ROAMING\BROWSER ASSISTANT\PSHELLPID.DAT, Quarantined, 3844, 787388, 1.0.22452, , ame,
Trojan.BrowserAssistant, C:\USERS\CHAD\APPDATA\ROAMING\BROWSER ASSISTANT\.UPDATES\UPDATE\BAV1377345.MSI, Quarantined, 15532, 806558, 1.0.22452, , ame,
Trojan.BrowserAssistant, C:\USERS\CHAD\APPDATA\ROAMING\BROWSER ASSISTANT\.UPDATES\PRODUCTION\BAV1276992.MSI, Quarantined, 15532, 806558, 1.0.22452, , ame,
Trojan.BrowserAssistant, C:\USERS\CHAD\APPDATA\ROAMING\BROWSER ASSISTANT\.UPDATES\PRODUCTION\BAV1327106.MSI, Quarantined, 15532, 806558, 1.0.22452, , ame,
Trojan.BrowserAssistant, C:\USERS\CHAD\APPDATA\ROAMING\BROWSER ASSISTANT\.UPDATES\PRODUCTION\BAV1287010.MSI, Quarantined, 15532, 806558, 1.0.22452, , ame,
Physical Sector: 0
(No malicious items detected)
WMI: 0
(No malicious items detected)

(end)

 

Frst.txt

 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 14-04-2020
Ran by [removed] (administrator) on DESKTOP-TTM2T1H (HP HP Pavilion Desktop PC 570-p0xx) (14-04-2020 08:37:24)
Running from C:\Users\[removed]\Desktop
[removed] Platform: Windows 10 Home Version 1909 18363.720 (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Adobe Inc. -> Adobe Systems) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.452\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.452\GoogleCrashHandler64.exe
(HP Inc. -> HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(HP Inc. -> HP Inc.) C:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe
(Intel Corporation -> Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Intel Corporation -> Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel Corporation -> Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_31a8dbbf39dcdc3b\jhi_service.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki131064.inf_amd64_5d13f27a9a9843fa\igfxCUIService.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki131064.inf_amd64_5d13f27a9a9843fa\igfxEM.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki131064.inf_amd64_5d13f27a9a9843fa\IntelCpHDCPSvc.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki131064.inf_amd64_5d13f27a9a9843fa\IntelCpHeciSvc.exe
(Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel(R) Wireless Connectivity Solutions -> Intel Corporation) C:\Windows\System32\ibtsiva.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <4>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe <5>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeSH.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe
(SEIKO EPSON CORPORATION -> Seiko Epson Corporation) C:\Program Files (x86)\EPSON Software\PMA_A\PMA.exe
(SEIKO EPSON CORPORATION -> Seiko Epson Corporation) C:\Program Files (x86)\EPSON Software\PMA_A\PMAService.exe
(SEIKO EPSON Corporation -> Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe
(SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_YATIKEE.EXE
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM-x32\…\Run: [HPMessageService] => C:\Program Files (x86)\HP\HP System Event\HPMSGSVC.exe [703312 2017-07-21] (HP Inc. -> HP Inc.)
HKLM-x32\…\Run: [EEventManager] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [1092304 2016-03-14] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
HKLM-x32\…\Run: [FUFAXRCV] => C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe [653352 2017-02-16] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
HKLM-x32\…\Run: [FUFAXSTM] => C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe [862248 2017-02-16] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
HKLM-x32\…\Run: [TeamsMachineInstaller] => C:\Program Files (x86)\Teams Installer\Teams.exe [84008696 2019-12-08] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-739738517-1214496134-3013126539-1001\…\Run: [EPLTarget\P0000000000000000] => C:\windows\system32\spool\DRIVERS\x64\3\E_YATIKEE.EXE [298560 2013-09-12] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
HKU\S-1-5-21-739738517-1214496134-3013126539-1001\…\Run: [com.squirrel.Teams.Teams] => C:\Users\Chad\AppData\Local\Microsoft\Teams\Update.exe [2337544 2020-03-14] (Microsoft 3rd Party Application Component -> Microsoft Corporation)
HKU\S-1-5-21-739738517-1214496134-3013126539-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\PhotoScreensaver.scr [567296 2019-03-19] (Microsoft Windows -> Microsoft Corporation)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\80.0.3987.163\Installer\chrmstp.exe [2020-04-03] (Google LLC -> Google LLC)
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {02A43A00-5DB2-48C5-8487-EC76D7BF6E63} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe
Task: {0E2273D5-1090-42C1-9E17-6E84297F4041} - System32\Tasks\EPSON WF-3620 Series Invitation {406C84BF-E4F0-4835-83EF-9BEEC53EE65B} => C:\windows\system32\spool\DRIVERS\x64\3\E_YTSKEE.EXE [679488 2013-02-28] (SEIKO EPSON Corporation -> SEIKO EPSON CORPORATION)
Task: {14325B4B-B34D-40D0-8FFB-249E98397B08} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [1571208 2020-03-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {352F7434-A485-4C53-8189-1CA08F03B277} - System32\Tasks\Hewlett-Packard\HP Active Health\HP Active Health Scan (HPSA) => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.exe
Task: {3E906362-F03C-44D0-9A90-C1C8530058C1} - System32\Tasks\HPCeeScheduleForChad => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [97656 2018-09-11] (HP Inc. -> HP Inc.)
Task: {496EF8CF-1F13-49E5-9B69-8DC87EC94FF5} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9279544 2018-09-13] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
Task: {4A5494F4-411A-42DE-A4D6-0019C8227A32} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [134008 2020-03-25] (HP Inc. -> HP Inc.)
Task: {4A6DD08F-2D7C-4645-A2FA-F1EE10611E56} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [1421704 2020-03-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {624D5F62-7C51-48E4-8873-C9E26D9F8BD1} - System32\Tasks\AdwCleaner_onReboot => C:\Users\Chad\Desktop\adwcleaner_8.0.4.exe [8196784 2020-04-14] (Malwarebytes Inc -> Malwarebytes)
Task: {655FEC79-1778-4380-BEE9-5BD0DD8C4F54} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe
Task: {69EA899C-4D00-4435-A883-646AA5C3516A} - System32\Tasks\HPEA3JOBS => C:\Program [Argument = Files\HP\HP ePrint\hpeprint.exe /CheckJobs]
Task: {6BE9E83E-F8C8-41F8-9B58-5ADE266C4CA2} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156104 2019-12-26] (Google LLC -> Google LLC)
Task: {73D987CE-7565-412C-A88E-B4467BDBF4C3} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [1421704 2020-03-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {79AC2131-5AE8-4F61-A946-BD56E00F08C6} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [27369752 2020-03-03] (Microsoft Corporation -> Microsoft Corporation)
Task: {7DF8998E-EF69-4E8A-A57D-C074848BCEA9} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe
Task: {8F70775B-7E2E-43E1-B075-EC084AA81ADE} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156104 2019-12-26] (Google LLC -> Google LLC)
Task: {9F884CF8-8269-4463-A1D6-11AB807DCA27} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1242704 2020-02-25] (Adobe Inc. -> Adobe Systems)
Task: {A53D7517-E078-4D39-A60E-A210BE9F0CE7} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe
Task: {AE2F4F11-BCE0-4760-ACF8-FEC2B5861552} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Product Configurator => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\ProductConfig.exe
Task: {B6A2891E-A851-4F22-B957-4366F443CC46} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [27369752 2020-03-03] (Microsoft Corporation -> Microsoft Corporation)
Task: {B8313863-D6B7-4868-9FF2-3ABC4B4D5FF4} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [4461160 2020-01-23] (Microsoft Corporation -> Microsoft Corporation)
Task: {C8E5E442-158B-4665-B9C8-DEF57855541B} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\sdxhelper.exe [110632 2020-03-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {CF20AEAF-4C4D-4281-81FD-0CB6CC082D33} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [4461160 2020-01-23] (Microsoft Corporation -> Microsoft Corporation)
Task: {D7D4CDE4-4254-4388-99EA-A8108955BB7E} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\sdxhelper.exe [110632 2020-03-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {E388E96F-392C-4725-8353-E12D9D628803} - System32\Tasks\EPSON WF-3620 Series Update {406C84BF-E4F0-4835-83EF-9BEEC53EE65B} => C:\windows\system32\spool\DRIVERS\x64\3\E_YTSKEE.EXE [679488 2013-02-28] (SEIKO EPSON Corporation -> SEIKO EPSON CORPORATION)
Task: {FE146D3B-AD56-485E-9EE5-95FAF8E823CF} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [655736 2019-07-31] (HP Inc. -> HP Inc.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\EPSON WF-3620 Series Invitation {406C84BF-E4F0-4835-83EF-9BEEC53EE65B}.job => C:\windows\system32\spool\DRIVERS\x64\3\E_YTSKEE.EXE
Task: C:\WINDOWS\Tasks\EPSON WF-3620 Series Update {406C84BF-E4F0-4835-83EF-9BEEC53EE65B}.job => C:\windows\system32\spool\DRIVERS\x64\3\E_YTSKEE.EXE:/EXE:{406C84BF-E4F0-4835-83EF-9BEEC53EE65B} /F:UpdateWORKGROUP\RE5BBOV0NVGFP$ĊSearches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi
Task: C:\WINDOWS\Tasks\HPCeeScheduleForChad.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{55abad87-d4c4-4d05-b8d5-d633cc63cc75}: [DhcpNameServer] 192.168.1.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://hp17win10.msn.com/?pc=HCTE
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp17win10.msn.com/?pc=HCTE
HKU\S-1-5-21-739738517-1214496134-3013126539-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://hp17win10.msn.com/?pc=HCTE
HKU\S-1-5-21-739738517-1214496134-3013126539-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp17win10.msn.com/?pc=HCTE
SearchScopes: HKLM -> {CD3A9B6B-ADC3-4116-8B3F-FB3EAACA6672} URL = hxxp://www.amazon.com/s/ref=azs_osd_iea?ie=UTF-8&tag;=hp-us1-vsb-20&link;%5Fcode=qs&index;=aps&field-keywords;={searchTerms}
SearchScopes: HKLM-x32 -> {CD3A9B6B-ADC3-4116-8B3F-FB3EAACA6672} URL = hxxp://www.amazon.com/s/ref=azs_osd_iea?ie=UTF-8&tag;=hp-us1-vsb-20&link;%5Fcode=qs&index;=aps&field-keywords;={searchTerms}
SearchScopes: HKU\S-1-5-21-739738517-1214496134-3013126539-1001 -> {CD3A9B6B-ADC3-4116-8B3F-FB3EAACA6672} URL = hxxp://www.amazon.com/s/ref=azs_osd_iea?ie=UTF-8&tag;=hp-us1-vsb-20&link;%5Fcode=qs&index;=aps&field-keywords;={searchTerms}
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2020-01-23] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2020-01-23] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2020-01-23] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2020-01-23] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2020-01-23] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2020-01-23] (Microsoft Corporation -> Microsoft Corporation)
Edge:
======
DownloadDir: C:\Users\Chad\Downloads
Edge Notifications: HKU\S-1-5-21-739738517-1214496134-3013126539-1001 -> hxxps://trampolineparkmiamisburg.notification-0.com; hxxps://jcpenney.notification-0.com
FireFox:
========
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2020-01-23] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2020-01-23] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2020-03-05] (Adobe Inc. -> Adobe Systems Inc.)
Chrome:
=======
CHR DefaultProfile: Profile 2
CHR Profile: C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Default [2020-04-13]
CHR Notifications: Default -> hxxps://www.smarter.com
CHR Extension: (Chrome Web Store Payments) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-12-26]
CHR Extension: (Chrome Media Router) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-04-06]
CHR Profile: C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Guest Profile [2020-03-16]
CHR Profile: C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1 [2020-04-13]
CHR Notifications: Profile 1 -> hxxps://kizi.com; hxxps://www.youtube.com
CHR Extension: (Slides) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2020-03-16]
CHR Extension: (DocHub - Edit and Sign PDF Documents) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\adgncicbhbjfpijkdmbijninnhnmiblj [2020-04-06]
CHR Extension: (Share to Classroom) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\adokjfanaflbkibffcbhihgihpgijcei [2020-04-06]
CHR Extension: (BIODIGITAL HUMAN) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\agoenciogemlojlhccbcpcfflicgnaak [2020-04-06]
CHR Extension: (Docs) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2020-03-16]
CHR Extension: (Google Drive) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-03-16]
CHR Extension: (Desmos Graphing Calculator) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bhdheahnajobgndecdbggfmcojekgdko [2020-04-06]
CHR Extension: (YouTube) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2020-03-16]
CHR Extension: (GeoGebra Classic) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bnbaboaihhkjoaolfnfoablhllahjnee [2020-04-06]
CHR Extension: (Useful Periodic Table (lite)) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\chachkegffmilnmdlonllkhkfkakghie [2020-04-06]
CHR Extension: (Sheets) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2020-03-16]
CHR Extension: (Google Docs Offline) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-03-16]
CHR Extension: (Camera) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\hfhhnacclhffhdffklopdkcgdhifgngh [2020-04-06]
CHR Extension: (Zoom) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\hmbjbjdpkobdjplfobhljndfdfdipjhg [2020-04-06]
CHR Extension: (Pixlr Editor) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\icmaknaampgiegkcjlimdiidlhopknpk [2020-04-06]
CHR Extension: (Smoothwall) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\jbldkhfglmgeihlcaeliadhipokhocnm [2020-04-08]
CHR Extension: (TestNav) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mdmkkicfmmkgmpkmkdikhlbggogpicma [2020-04-06]
CHR Extension: (Google Classroom) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mfhehppjhmmnlfbbopchdfldgimhfhfk [2020-04-06]
CHR Extension: (Screencastify - Screen Video Recorder) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mmeijimgabbpbgpdklnllpncmdofkcpn [2020-04-13]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2020-03-16]
CHR Extension: (Kids A-Z) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pifccnhncmnilgbnnkjkgicpkeclodpd [2020-04-06]
CHR Extension: (Gmail) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-03-16]
CHR Extension: (Chrome Media Router) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-04-03]
CHR Profile: C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 2 [2020-04-13]
CHR Extension: (Slides) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2020-04-13]
CHR Extension: (Docs) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aohghmighlieiainnegkcijnfilokake [2020-04-13]
CHR Extension: (Google Drive) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-04-13]
CHR Extension: (YouTube) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2020-04-13]
CHR Extension: (Sheets) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2020-04-13]
CHR Extension: (Google Docs Offline) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-04-13]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2020-04-13]
CHR Extension: (Gmail) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-04-13]
CHR Extension: (Chrome Media Router) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-04-13]
CHR Profile: C:\Users\Chad\AppData\Local\Google\Chrome\User Data\System Profile [2020-04-13]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [11600672 2020-03-03] (Microsoft Corporation -> Microsoft Corporation)
R2 Epson PMAService A; C:\Program Files (x86)\Epson Software\PMA_A\PMAService.exe [113144 2017-03-28] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
R2 EpsonScanSvc; C:\windows\system32\EscSvc64.exe [144560 2012-05-17] (SEIKO EPSON Corporation -> Seiko Epson Corporation)
S3 hpqcaslwmiex; C:\Program Files (x86)\HP\Shared\hpqwmiex.exe [1031704 2016-06-04] (Hewlett-Packard Company -> HP)
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [378744 2020-03-31] (HP Inc. -> HP Inc.)
R2 HPWMISVC; c:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe [628768 2017-07-13] (HP Inc. -> HP Inc.)
R2 ibtsiva; C:\WINDOWS\System32\ibtsiva.exe [529912 2018-12-21] (Intel(R) Wireless Connectivity Solutions -> Intel Corporation)
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\WINDOWS\System32\DriverStore\FileRepository\iclsclient.inf_amd64_7e148e9c120d86df\lib\SocketHeciServer.exe [872416 2019-04-23] (Intel(R) Trust Services -> Intel(R) Corporation)
S2 Intel(R) TPM Provisioning Service; C:\WINDOWS\System32\DriverStore\FileRepository\iclsclient.inf_amd64_7e148e9c120d86df\lib\TPMProvisioningService.exe [800224 2019-04-23] (Intel(R) Trust Services -> Intel(R) Corporation)
R2 jhi_service; C:\WINDOWS\System32\DriverStore\FileRepository\dal.inf_amd64_31a8dbbf39dcdc3b\jhi_service.exe [647568 2019-04-30] (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [6933272 2020-04-14] (Malwarebytes Inc -> Malwarebytes)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [310880 2018-09-05] (Intel Corporation -> )
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\NisSrv.exe [3294680 2020-03-25] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\MsMpEng.exe [103168 2020-03-25] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [4059744 2018-09-05] (Intel Corporation -> Intel® Corporation)
S2 HP Comm Recover; "C:\Program Files\HPCommRecovery\HPCommRecovery.exe" [X]
S2 HPJumpStartBridge; "c:\Program Files (x86)\HP\HP JumpStart Bridge\HPJumpStartBridge.exe" [X]
S2 WildTangentHelper; "C:\Program Files (x86)\WildTangent Games\Integration\WildTangentHelperService.exe" [X]
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [153312 2020-04-14] (Malwarebytes Corporation -> Malwarebytes)
R3 ibtusb; C:\WINDOWS\System32\drivers\ibtusb.sys [199192 2018-05-11] (Intel(R) Wireless Connectivity Solutions -> Intel Corporation)
R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [214496 2020-04-14] (Malwarebytes Inc -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [20936 2020-04-14] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\System32\DRIVERS\farflt.sys [195432 2020-04-14] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\system32\DRIVERS\mbam.sys [73584 2020-04-14] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [248968 2020-04-14] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [119960 2020-04-14] (Malwarebytes Inc -> Malwarebytes)
R3 Netwtw04; C:\WINDOWS\System32\drivers\Netwtw04.sys [8720384 2019-08-27] (Intel(R) Wireless Connectivity Solutions -> Intel Corporation)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [984032 2017-09-15] (Realtek Semiconductor Corp. -> Realtek )
R3 RTSUER; C:\WINDOWS\system32\Drivers\RtsUer.sys [421312 2017-09-14] (Realtek Semiconductor Corp. -> Realsil Semiconductor Corporation)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [45960 2020-03-25] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [391392 2020-03-25] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [59104 2020-03-25] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

==================== One month (created) ===================
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-04-14 08:37 - 2020-04-14 08:37 - 000000000 ____D C:\Users\Chad\Desktop\FRST-OlderVersion
2020-04-14 08:33 - 2020-04-14 08:33 - 000248968 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2020-04-14 08:33 - 2020-04-14 08:33 - 000214496 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamChameleon.sys
2020-04-14 08:33 - 2020-04-14 08:33 - 000195432 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
2020-04-14 08:33 - 2020-04-14 08:33 - 000153312 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys
2020-04-14 08:33 - 2020-04-14 08:33 - 000119960 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2020-04-14 08:33 - 2020-04-14 08:33 - 000073584 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2020-04-14 08:33 - 2020-04-14 08:33 - 000020936 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamElam.sys
2020-04-14 08:33 - 2020-04-14 08:33 - 000002028 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2020-04-14 08:33 - 2020-04-14 08:33 - 000002028 _____ C:\ProgramData\Desktop\Malwarebytes.lnk
2020-04-14 08:33 - 2020-04-14 08:33 - 000000000 ____D C:\Users\Chad\AppData\LocalLow\IGDump
2020-04-14 08:33 - 2020-04-14 08:33 - 000000000 ____D C:\Users\Chad\AppData\Local\mbamtray
2020-04-14 08:33 - 2020-04-14 08:33 - 000000000 ____D C:\Users\Chad\AppData\Local\mbam
2020-04-14 08:33 - 2020-04-14 08:33 - 000000000 ____D C:\Users\Chad\AppData\Local\cache
2020-04-14 08:33 - 2020-04-14 08:33 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2020-04-14 08:33 - 2020-04-14 08:33 - 000000000 ____D C:\ProgramData\Malwarebytes
2020-04-14 08:32 - 2020-04-14 08:32 - 001928352 _____ (Malwarebytes) C:\Users\Chad\Desktop\MBSetup-076981.076981-Consumer.exe
2020-04-14 08:32 - 2020-04-14 08:32 - 000000000 ____D C:\Program Files\Malwarebytes
2020-04-14 08:29 - 2020-04-14 08:29 - 000003168 _____ C:\WINDOWS\system32\Tasks\AdwCleaner_onReboot
2020-04-14 08:26 - 2020-04-14 08:29 - 000000000 ____D C:\AdwCleaner
2020-04-14 08:25 - 2020-04-14 08:25 - 008196784 _____ (Malwarebytes) C:\Users\Chad\Desktop\adwcleaner_8.0.4.exe
2020-04-13 21:13 - 2020-04-13 21:13 - 000031437 _____ C:\Users\Chad\Desktop\Addition.txt
2020-04-13 21:12 - 2020-04-14 08:37 - 000027834 _____ C:\Users\Chad\Desktop\FRST.txt
2020-04-13 21:11 - 2020-04-14 08:37 - 000000000 ____D C:\FRST
2020-04-13 21:10 - 2020-04-14 08:37 - 002281472 _____ (Farbar) C:\Users\Chad\Desktop\FRST64.exe
2020-04-13 21:09 - 2020-04-13 21:09 - 001157812 _____ C:\WINDOWS\Minidump\041320-21796-01.dmp
2020-04-13 21:08 - 2020-04-13 21:08 - 688590482 ____N C:\WINDOWS\MEMORY.DMP
2020-04-13 21:04 - 2020-04-13 21:09 - 000000000 ____D C:\WINDOWS\Minidump
2020-04-13 21:02 - 2020-04-13 21:02 - 005198336 _____ (AVAST Software) C:\Users\Chad\Desktop\aswMBR.exe
2020-04-13 20:42 - 2020-04-13 20:42 - 006946736 _____ (EnigmaSoft Limited) C:\Users\Chad\Downloads\sh-remover.exe
2020-04-13 13:33 - 2020-04-13 13:33 - 000002481 _____ C:\Users\Chad\Desktop\Mom - Chrome.lnk
2020-04-06 09:36 - 2020-04-06 09:36 - 000000000 ____D C:\Users\Chad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
2020-03-26 13:20 - 2020-03-26 13:20 - 000078168 _____ (Zoom Video Communications, Inc.) C:\Users\Chad\Downloads\Zoom_42034cce248d8e41.exe
2020-03-16 09:57 - 2020-04-06 09:35 - 000002481 _____ C:\Users\Chad\Desktop\Grace - Chrome.lnk
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-04-14 08:33 - 2019-12-26 11:41 - 000936976 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2020-04-14 08:33 - 2019-03-19 00:52 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2020-04-14 08:33 - 2019-03-19 00:50 - 000000000 ____D C:\WINDOWS\INF
2020-04-14 08:29 - 2019-12-26 11:39 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2020-04-14 08:29 - 2019-03-19 00:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2020-04-14 08:29 - 2019-03-19 00:37 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2020-04-14 08:29 - 2018-06-26 20:14 - 000000000 ____D C:\Users\Chad\AppData\Roaming\Hewlett-Packard
2020-04-14 08:29 - 2018-06-26 20:11 - 000000000 __SHD C:\Users\Chad\IntelGraphicsProfiles
2020-04-14 08:29 - 2018-06-26 20:11 - 000000000 ____D C:\Users\Chad\AppData\Local\Hewlett-Packard
2020-04-14 08:29 - 2018-03-06 11:15 - 000000000 ____D C:\ProgramData\HP
2020-04-14 08:29 - 2018-03-06 11:15 - 000000000 ____D C:\ProgramData\Hewlett-Packard
2020-04-14 08:29 - 2018-03-06 11:15 - 000000000 ____D C:\Program Files (x86)\Hewlett-Packard
2020-04-14 08:29 - 2018-03-06 11:14 - 000000000 ____D C:\Program Files (x86)\HP
2020-04-14 08:29 - 2017-10-31 19:51 - 000000000 ___HD C:\hp
2020-04-14 08:25 - 2019-12-26 11:39 - 000004164 _____ C:\WINDOWS\system32\Tasks\User_Feed_Synchronization-{1F435414-D5C0-4BCD-8953-1C1EE5157FC8}
2020-04-13 22:31 - 2019-12-26 11:35 - 000000000 ____D C:\Users\Chad
2020-04-13 22:31 - 2019-12-26 11:32 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2020-04-13 21:04 - 2019-12-26 11:32 - 001810805 ____N C:\WINDOWS\Minidump\041320-6703-01.dmp
2020-04-13 21:04 - 2018-07-08 09:46 - 000000360 _____ C:\WINDOWS\Tasks\HPCeeScheduleForChad.job
2020-04-13 20:42 - 2018-06-26 20:44 - 000000000 ____D C:\Users\Chad\Documents\Outlook Files
2020-04-13 20:28 - 2019-12-26 11:39 - 000003248 _____ C:\WINDOWS\system32\Tasks\HPCeeScheduleForChad
2020-04-13 17:49 - 2019-03-19 00:52 - 000000000 ___HD C:\Program Files\WindowsApps
2020-04-13 17:49 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\AppReadiness
2020-04-11 17:09 - 2018-06-26 20:43 - 000044402 _____ C:\Users\Chad\Desktop\Food Inventory.xlsx
2020-04-11 16:20 - 2018-06-26 20:11 - 000000000 ____D C:\Users\Chad\AppData\Local\Packages
2020-04-09 19:47 - 2020-01-08 20:42 - 000000000 ____D C:\Users\Chad\Desktop\Nate's Camera
2020-04-09 06:35 - 2018-06-26 20:43 - 000000000 ____D C:\Users\Chad\Desktop\8876 Wildfire
2020-04-03 14:01 - 2019-12-26 11:56 - 000002308 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-04-03 14:01 - 2019-12-26 11:56 - 000002267 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2020-04-03 14:01 - 2019-12-26 11:56 - 000002267 _____ C:\ProgramData\Desktop\Google Chrome.lnk
2020-04-02 10:15 - 2018-08-27 09:21 - 000744808 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2020-03-25 09:24 - 2018-06-27 08:13 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2020-03-23 07:55 - 2019-12-26 11:39 - 000003376 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-739738517-1214496134-3013126539-1001
2020-03-23 07:55 - 2019-12-26 11:35 - 000002367 _____ C:\Users\Chad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2020-03-23 07:55 - 2019-09-10 16:25 - 000000000 ___RD C:\Users\Chad\OneDrive - Dayton Regional STEM School
2020-03-20 18:45 - 2019-12-26 11:56 - 000003420 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2020-03-20 18:45 - 2019-12-26 11:56 - 000003296 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2020-03-19 15:28 - 2019-12-26 11:39 - 000004562 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2020-03-19 15:28 - 2019-12-26 09:58 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2020-03-18 09:23 - 2018-06-26 21:10 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2020-03-16 12:06 - 2020-01-31 10:09 - 000013247 _____ C:\Users\Chad\Desktop\Nate Jan Progress Book.xlsx
==================== Files in the root of some directories ========
2019-05-04 18:55 - 2019-05-04 18:55 - 000024359 _____ () C:\Users\Chad\AppData\Local\recently-used.xbel
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================

 

Addition.txt:

 

 

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 14-04-2020
Ran by [removed] (14-04-2020 08:38:08)
Running from C:\Users\[removed]\Desktop
Windows 10 Home Version 1909 18363.720 (X64) (2019-12-26 15:39:51)
Boot Mode: Normal
==========================================================

==================== Accounts: =============================
Administrator (S-1-5-21-739738517-1214496134-3013126539-500 - Administrator - Disabled)
Chad (S-1-5-21-739738517-1214496134-3013126539-1001 - Administrator - Enabled) => C:\Users\Chad
DefaultAccount (S-1-5-21-739738517-1214496134-3013126539-503 - Limited - Disabled)
Guest (S-1-5-21-739738517-1214496134-3013126539-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-739738517-1214496134-3013126539-504 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe Acrobat Reader DC (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 20.006.20042 - Adobe Systems Incorporated)
Bonjour (HKLM\…\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Direct Game UNI Installer (HKLM-x32\…\{C77717A7-09BF-49AF-92F2-9F3ED9AF5BFD}) (Version: 1.0.17 - GamesLOL)
Epson Event Manager (HKLM-x32\…\{006C8256-3855-43BF-8BA5-4B4C40F41F71}) (Version: 3.10.0065 - Seiko Epson Corporation)
Epson FAX Utility (HKLM-x32\…\{0CBE6C93-CB2E-4378-91EE-12BE6D4E2E4A}) (Version: 2.02.00 - Seiko Epson Corporation)
Epson PC-FAX Driver (HKLM-x32\…\EPSON PC-FAX Driver 2) (Version:  - Seiko Epson Corporation)
Epson ReadyInk Agent (A) (HKLM-x32\…\{A9B4584F-A29E-4880-97E6-1744B4AF2AF8}) (Version: 1.0.1.0 - Seiko Epson Corporation)
EPSON Scan (HKLM-x32\…\EPSON Scanner) (Version:  - Seiko Epson Corporation)
Epson Software Updater (HKLM-x32\…\{B55DB65D-EF6E-4E04-89D5-B03603BF681B}) (Version: 4.4.5 - SEIKO EPSON CORPORATION)
EPSON WF-3620 Series Printer Uninstall (HKLM\…\EPSON WF-3620 Series) (Version:  - SEIKO EPSON Corporation)
Epson WF-3620 User’s Guide version 1.0 (HKLM-x32\…\UsersGuideEpson WF-3620 User’s Guide_is1) (Version: 1.0 - )
EpsonNet Print (HKLM\…\{96ED1D58-440C-4345-8FEE-C4781366C67F}) (Version: 3.1.4.0 - SEIKO EPSON Corporation)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 80.0.3987.163 - Google LLC)
Google Update Helper (HKLM-x32\…\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.451 - Google LLC) Hidden
HP Audio Switch (HKLM-x32\…\{3A5141D4-47DB-4302-9B1C-272BE585BC8A}) (Version: 1.0.179.0 - HP Inc.)
HP Documentation (HKLM\…\HP_Documentation) (Version: 1.0.0.1 - HP Inc.)
HP ePrint SW (HKLM-x32\…\{cdb5f70f-5107-4613-bf69-15de903b5b5d}) (Version: 5.5.22560 - HP Inc.)
HP JumpStart Bridge (HKLM-x32\…\{3FC961DB-BD36-4D8D-B276-0C456A2BB638}) (Version: 1.4.0.441 - HP Inc.)
HP JumpStart Launch (HKLM-x32\…\{F213102E-FD30-4E22-AF73-4C682D65FFEE}) (Version: 1.4.441.0 - HP Inc.)
HP System Event Utility (HKLM-x32\…\{4B0A7A8A-ECE5-4639-9A0D-C535F354313D}) (Version: 1.4.26 - HP Inc.)
Intel(R) Chipset Device Software (HKLM-x32\…\{17408817-d415-4768-a160-ae6d46d6bdb0}) (Version: 10.1.1.44 - Intel(R) Corporation) Hidden
Intel(R) Management Engine Components (HKLM\…\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.7.0.1043 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 25.20.100.6446 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\…\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 15.8.1.1007 - Intel Corporation)
Intel(R) Serial IO (HKLM\…\{9FD91C5C-44AE-4D9D-85BE-AE52816B0294}) (Version: 30.100.1725.1 - Intel Corporation)
Intel(R) Wireless Bluetooth(R) (HKLM-x32\…\{00000080-0190-1033-84C8-B8D95FA3C8C3}) (Version: 19.80.0 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\…\{f8c930bd-0a68-425f-8c11-87723d1e2c97}) (Version: 20.90.0 - Intel Corporation)
Malwarebytes version 4.1.0.56 (HKLM\…\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.1.0.56 - Malwarebytes)
Microsoft Office 365 - en-us (HKLM\…\o365homepremretail - en-us) (Version: 16.0.11929.20648 - Microsoft Corporation)
Microsoft Office 365 ProPlus - en-us (HKLM\…\O365ProPlusRetail - en-us) (Version: 16.0.11929.20648 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-739738517-1214496134-3013126539-1001\…\OneDriveSetup.exe) (Version: 19.232.1124.0010 - Microsoft Corporation)
Microsoft Teams (HKU\S-1-5-21-739738517-1214496134-3013126539-1001\…\Teams) (Version: 1.3.00.3564 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\…\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\…\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\…\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\…\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24123 (HKLM-x32\…\{2cbcedbb-f38c-48a3-a3e1-6c6fd821a7f4}) (Version: 14.0.24123.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24123 (HKLM-x32\…\{206898cc-4b41-4d98-ac28-9f9ae57f91fe}) (Version: 14.0.24123.0 - Microsoft Corporation)
Office 16 Click-to-Run Extensibility Component (HKLM-x32\…\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.11929.20648 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\…\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.11929.20648 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\…\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.11929.20648 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM-x32\…\{90160000-008C-0409-0000-0000000FF1CE}) (Version: 16.0.11929.20648 - Microsoft Corporation) Hidden
Realtek Card Reader (HKLM-x32\…\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.15063.31237 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.19.627.2017 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8536 - Realtek Semiconductor Corp.)
Teams Machine-Wide Installer (HKLM-x32\…\{39AF0813-FA7B-4860-ADBE-93B9B214B914}) (Version: 1.2.0.34161 - Microsoft Corporation)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\…\{F14FB68A-9188-4036-AD0D-D054BC9C9291}) (Version: 2.59.0.0 - Microsoft Corporation)
Vulkan Run Time Libraries 1.1.70.1 (HKLM\…\VulkanRT1.1.70.1) (Version: 1.1.70.1 - LunarG, Inc.) Hidden
Windows 10 Update Assistant (HKLM-x32\…\{D5C69738-B486-402E-85AC-2456D98A64E4}) (Version: 1.4.9200.22391 - Microsoft Corporation)
Packages:
=========
Any Player -> C:\Program Files\WindowsApps\15191PeakPlayer.50533F9B98293_3.1.4.0_x64__y5c4dfz5b21fm [2020-04-11] (Any DVD & Office App)
Connect -> C:\Windows\SystemApps\Microsoft.Windows.DevicesFlowHost_cw5n1h2txyewy [2019-12-26] (Microsoft Corporation)
Dolby Access -> C:\Program Files\WindowsApps\DolbyLaboratories.DolbyAccess_3.1.4081.0_x64__rz1tebttyb220 [2020-01-28] (Dolby Laboratories)
Floor Adjustment -> C:\Windows\SystemApps\RoomAdjustment_cw5n1h2txyewy [2019-12-26] (Microsoft Corporation)
HP JumpStart -> C:\Program Files\WindowsApps\AD2F1837.HPJumpStart_1.4.443.0_x86__v10z8vjag6ke6 [2018-03-06] (HP Inc.)
Learn Mixed Reality -> C:\Windows\SystemApps\MixedRealityLearning_cw5n1h2txyewy [2019-12-26] (Microsoft Corporation)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-01-19] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-01-19] (Microsoft Corporation) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.6.1224.0_x64__8wekyb3d8bbwe [2020-02-28] (Microsoft Studios) [MS Ad]
MSN Weather -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.36.20714.0_x64__8wekyb3d8bbwe [2020-03-24] (Microsoft Corporation) [MS Ad]
New for You -> C:\Windows\SystemApps\WhatsNew_cw5n1h2txyewy [2019-12-26] (Microsoft Corporation)
Passthrough -> C:\Windows\SystemApps\passthrough_cw5n1h2txyewy [2019-12-26] (Microsoft Corporation)
Photos Add-on -> C:\Program Files\WindowsApps\Microsoft.Windows.Photos.DLC.Main_2017.39121.36610.0_x64__8wekyb3d8bbwe [2019-06-18] (Microsoft Corporation)
Photos Media Engine Add-on -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2019-09-27] (Microsoft Corporation)
Power Media Player 14 for HP Consumer PCs with DVD -> C:\Program Files\WindowsApps\CyberLinkCorp.hs.PowerMediaPlayer14forHPConsumerPC_14.2.9528.0_x86__06qsbagp91rvg [2019-01-26] (CYBERLINKCOM CORP)
Sign In -> C:\Windows\SystemApps\WebAuthBridgeInternet_cw5n1h2txyewy [2019-12-26] (ms-resource:PublisherDisplayName)
Sign In -> C:\Windows\SystemApps\WebAuthBridgeInternetSso_cw5n1h2txyewy [2019-12-26] (ms-resource:PublisherDisplayName)
Sign In -> C:\Windows\SystemApps\WebAuthBridgeIntranetSso_cw5n1h2txyewy [2019-12-26] (ms-resource:PublisherDisplayName)
Simple Solitaire -> C:\Program Files\WindowsApps\26720RandomSaladGamesLLC.SimpleSolitaire_6.18.78.0_x64__kx24dqmazqk8j [2020-02-29] (Random Salad Games LLC) [MS Ad]
Sling TV -> C:\Program Files\WindowsApps\SlingTVLLC.SlingTV_7.0.8.0_x86__vgszm6stshdqy [2019-01-09] (Sling TV LLC)
Smartfriend by HP Care -> C:\Program Files\WindowsApps\AD2F1837.SmartfriendbyHPCare_1.1.13.0_x64__v10z8vjag6ke6 [2018-03-06] (HP Inc.)
==================== Custom CLSID (Whitelisted): ==============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-739738517-1214496134-3013126539-1001_Classes\CLSID\{04271989-C4D2-D497-85E3-A60B7ED435AC} -> [OneDrive - Dayton Regional STEM School] => C:\Users\Chad\OneDrive - Dayton Regional STEM School [2019-09-10 16:25]
CustomCLSID: HKU\S-1-5-21-739738517-1214496134-3013126539-1001_Classes\CLSID\{19A6E644-14E6-4A60-B8D7-DD20610A871D}\InprocServer32 -> C:\Users\Chad\AppData\Local\Microsoft\TeamsMeetingAddin\1.0.19350.3\x64\Microsoft.Teams.AddinLoader.dll (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-739738517-1214496134-3013126539-1001_Classes\CLSID\{CB965DF1-B8EA-49C7-BDAD-5457FDC1BF92}\InprocServer32 -> C:\Users\Chad\AppData\Local\Microsoft\TeamsMeetingAddin\1.0.19350.3\x64\Microsoft.Teams.AddinLoader.dll (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2020-04-14] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} =>  -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\System32\DriverStore\FileRepository\ki131064.inf_amd64_5d13f27a9a9843fa\igfxDTCM.dll [2019-02-17] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2020-04-14] (Malwarebytes Corporation -> Malwarebytes)
==================== Codecs (Whitelisted) ====================
==================== Shortcuts & WMI ========================
(The entries could be listed to be restored or removed.)
ShortcutWithArgument: C:\Users\Chad\Desktop\Grace - Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> –profile-directory="Profile 1"
ShortcutWithArgument: C:\Users\Chad\Desktop\Mom - Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> –profile-directory="Profile 2"
ShortcutWithArgument: C:\Users\Chad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Camera.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) ->  –profile-directory="Profile 1" –app-id=hfhhnacclhffhdffklopdkcgdhifgngh
ShortcutWithArgument: C:\Users\Chad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\GeoGebra Classic.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) ->  –profile-directory="Profile 1" –app-id=bnbaboaihhkjoaolfnfoablhllahjnee
ShortcutWithArgument: C:\Users\Chad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\TestNav.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) ->  –profile-directory="Profile 1" –app-id=mdmkkicfmmkgmpkmkdikhlbggogpicma
ShortcutWithArgument: C:\Users\Chad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Zoom.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) ->  –profile-directory="Profile 1" –app-id=hmbjbjdpkobdjplfobhljndfdfdipjhg
ShortcutWithArgument: C:\Users\Chad\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\ff13ca23fee04978\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> –profile-directory="Profile 5"
ShortcutWithArgument: C:\Users\Chad\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\9501e18d7c2ab92e\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> –profile-directory="Profile 2"
ShortcutWithArgument: C:\Users\Chad\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\69639df789022856\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> –profile-directory="Profile 1"
ShortcutWithArgument: C:\Users\Chad\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\48499db33039e897\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> –profile-directory="Profile 4"
ShortcutWithArgument: C:\Users\Chad\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\225bb61db2f318c1\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> –profile-directory="Profile 3"
==================== Loaded Modules (Whitelisted) =============
2016-05-09 09:20 - 2016-05-09 09:20 - 000132096 _____ (Seiko Epson Corporation) [File not signed] C:\Program Files (x86)\EPSON Software\Event Manager\epnsm.dll
2009-10-21 17:39 - 2009-10-21 17:39 - 000291328 _____ (SEIKO EPSON CORPORATION) [File not signed] C:\Program Files (x86)\EPSON Software\Event Manager\LcMgr.dll
2016-09-14 14:31 - 2016-09-14 14:31 - 000500736 _____ (SEIKO EPSON CORPORATION) [File not signed] C:\WINDOWS\System32\enppmon.dll
==================== Alternate Data Streams (Whitelisted) ========
==================== Safe Mode (Whitelisted) ==================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
==================== Association (Whitelisted) =================
==================== Internet Explorer trusted/restricted ==========
(If an entry is included in the fixlist, it will be removed from the registry.)
IE trusted site: HKU\S-1-5-21-739738517-1214496134-3013126539-1001\…\sharepoint.com -> hxxps://daytonstemschoolorg-files.sharepoint.com
==================== Hosts content: =========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2017-09-29 09:46 - 2017-09-29 09:44 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts
==================== Other Areas ===========================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-739738517-1214496134-3013126539-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Chad\Pictures\Easter 2020 4.JPG
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
(If an entry is included in the fixlist, it will be removed.)
HKLM\…\StartupApproved\Run32: => "HPMessageService"
HKLM\…\StartupApproved\Run32: => "FUFAXRCV"
HKLM\…\StartupApproved\Run32: => "FUFAXSTM"
HKU\S-1-5-21-739738517-1214496134-3013126539-1001\…\StartupApproved\Run: => "OneDrive"
==================== FirewallRules (Whitelisted) ================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{00CB71B4-D99C-4C0C-93DB-E17E4281AB9F}] => (Allow) C:\Users\Chad\AppData\Local\Temp\WF-3620\Common\EpsonNet Setup\ENEasyApp.exe No File
FirewallRules: [{1100765F-5717-49C7-804E-A0E76CF930E1}] => (Allow) C:\Users\Chad\AppData\Local\Temp\WF-3620\Common\EpsonNet Setup\ENEasyApp.exe No File
FirewallRules: [{A615BE46-8F40-44D2-8C07-8D1837C9A155}] => (Allow) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
FirewallRules: [{E701CCE1-991D-4E32-BE22-6B8CA0133AC8}] => (Allow) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
FirewallRules: [{CADF8CDF-AFAC-4BD2-9CDB-7BE1992B7137}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{87132A74-3F41-45FF-AAD5-E9DC2C4BC058}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{33CA5CE1-C253-4D11-AB9E-0C6387E9A4D5}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{335234DF-FD72-42B1-B714-47D5CF448F45}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{3EE1FDF2-12E1-47B6-A319-4940FB0F3F15}] => (Allow) C:\Program Files (x86)\Common Files\Mcafee\MMSSHost\MMSSHost.exe No File
FirewallRules: [{C74A739F-68DA-408D-B3F7-57165959BA47}] => (Allow) C:\Program Files\Common Files\McAfee\MMSSHost\MMSSHost.exe No File
FirewallRules: [{1D23678D-91C3-4FFE-8DCD-9F814D770BC4}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{01DCF1BB-01F6-402D-860B-5A5625BF40AD}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{CA76B6D7-C405-4660-AD8A-35235D9565F5}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe (Intel Corporation -> )
FirewallRules: [{3854827A-6F82-43F1-8DEA-90A13A569D63}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{5244D7F8-C295-4E2C-A94A-E37300DF7191}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{34788936-5E00-483F-B55C-35120CC9C0ED}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{4F4D9931-5619-4133-BE4D-BF7A8F97BB5F}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
==================== Restore Points =========================
ATTENTION: System Restore is disabled (Total:118.01 GB) (Free:27.78 GB) (24%)
==================== Faulty Device Manager Devices ============

==================== Event log errors: ========================
Application errors:
==================
Error: (04/13/2020 09:16:24 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (4992,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.
Error: (04/13/2020 08:59:42 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: MicrosoftEdgeCP.exe, version: 11.0.18362.1, time stamp: 0xceb8cbe1
Faulting module name: EdgeContent.dll, version: 11.0.18362.657, time stamp: 0xe6b5ea8d
Exception code: 0xc0000409
Fault offset: 0x0000000000095f82
Faulting process id: 0x1e6c
Faulting application start time: 0x01d611f7fad3ceb7
Faulting application path: C:\Windows\System32\MicrosoftEdgeCP.exe
Faulting module path: C:\Windows\System32\EdgeContent.dll
Report Id: 8a0261d9-7a72-492f-85b6-d659692b74a9
Faulting package full name: Microsoft.MicrosoftEdge_44.18362.449.0_neutral__8wekyb3d8bbwe
Faulting package-relative application ID: MicrosoftEdge
Error: (04/13/2020 08:41:21 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (31128,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.
Error: (04/13/2020 08:00:37 PM) (Source: Microsoft-Windows-PerfNet) (EventID: 2004) (User: DESKTOP-TTM2T1H)
Description: Unable to open the Server service performance object. The first four bytes (DWORD) of the Data section contains the status code.
Error: (04/13/2020 07:43:31 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (29828,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.
Error: (04/13/2020 05:54:14 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (26504,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.
Error: (04/13/2020 04:28:25 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (30732,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.
Error: (04/13/2020 02:27:21 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (30732,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.

System errors:
=============
Error: (04/14/2020 08:31:30 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The HP Comm Recovery service failed to start due to the following error:
The system cannot find the file specified.
Error: (04/14/2020 08:29:29 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The WildTangentHelper service failed to start due to the following error:
The system cannot find the file specified.
Error: (04/14/2020 08:29:16 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has stopped unexpectedly.
Module Path: C:\WINDOWS\system32\IntelWifiIhv04.dll
Error: (04/14/2020 08:29:16 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has stopped unexpectedly.
Module Path: C:\WINDOWS\system32\IntelWifiIhv04.dll
Error: (04/14/2020 08:29:14 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has stopped unexpectedly.
Module Path: C:\WINDOWS\system32\IntelWifiIhv04.dll
Error: (04/14/2020 08:29:10 AM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: The Service Control Manager tried to take a corrective action (Run the configured recovery program) after the unexpected termination of the WildTangentHelper service, but this action failed with the following error:
The system cannot find the file specified.
Error: (04/14/2020 08:29:05 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Intel(R) PROSet/Wireless Event Log service terminated unexpectedly.  It has done this 1 time(s).
Error: (04/14/2020 08:29:05 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Intel(R) Content Protection HECI Service service terminated unexpectedly.  It has done this 1 time(s).

Windows Defender:
===================================
Date: 2020-04-02 09:20:56.934
Description:
Windows Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?linkid=37020&name;=Program:Win32/Unwaders&threatid;=250668&enterprise;=0
Name: Program:Win32/Unwaders
ID: 250668
Severity: Severe
Category: Potentially Unwanted Software
Path: file:_C:\Users\Chad\AppData\Roaming\Browser Assistant\BrowserAssistant.Driver.dll
Detection Origin: Local machine
Detection Type: FastPath
Detection Source: Real-Time Protection
Process Name: C:\Users\Chad\AppData\Roaming\Browser Assistant\BrowserAssistant.exe
Security intelligence Version: AV: 1.313.558.0, AS: 1.313.558.0, NIS: 1.313.558.0
Engine Version: AM: 1.1.16900.4, NIS: 1.1.16900.4
==================== Memory info ===========================
BIOS: AMI F.24 01/23/2018
Motherboard: HP 82F2
Processor: Intel(R) Core(TM) i3-7100 CPU @ 3.90GHz
Percentage of memory in use: 39%
Total physical RAM: 8080.34 MB
Available physical RAM: 4855.64 MB
Total Virtual: 16272.34 MB
Available Virtual: 13219.19 MB
==================== Drives ================================
Drive c: (Windows) (Fixed) (Total:118.01 GB) (Free:27.78 GB) NTFS
Drive d: (DATA) (Fixed) (Total:917.14 GB) (Free:908.95 GB) NTFS
Drive e: (RECOVERY) (Fixed) (Total:14.37 GB) (Free:1.73 GB) NTFS ==>[system with boot components (obtained from drive)]
\\?\Volume{c6de160f-ea7b-4d4f-9c1d-8a0c8ab91ab9}\ (Windows RE tools) (Fixed) (Total:0.96 GB) (Free:0.5 GB) NTFS
\\?\Volume{f7bdef1d-c0ab-4af5-9c2a-062f10ba0fb6}\ () (Fixed) (Total:0.25 GB) (Free:0.18 GB) FAT32
==================== MBR & Partition Table ====================
==========================================================
Disk: 0 (Size: 119.2 GB) (Disk ID: 6136ABCD)
Partition: GPT.
==========================================================
Disk: 1 (Size: 931.5 GB) (Disk ID: B119E5B4)
Partition: GPT.
==================== End of Addition.txt =======================
Some of the programs have newer versions and the screens/options are different.

AdwCleaner and FRST always update themselves so those links were fine.

 

Did I send a link to the old, (version 3), of Malwarebytes? Also, which instructions were wrong? As I don't run these myself all the time I'm maybe a bit out of touch. :unsure:

Run Farbar Recovery Scan Tool

Open notepad. Please copy the contents of the code box below and paste it into Notepad.

CloseProcesses:
Task: C:\WINDOWS\Tasks\EPSON WF-3620 Series Invitation {406C84BF-E4F0-4835-83EF-9BEEC53EE65B}.job => C:\windows\system32\spool\DRIVERS\x64\3\E_YTSKEE.EXE
Task: C:\WINDOWS\Tasks\EPSON WF-3620 Series Update {406C84BF-E4F0-4835-83EF-9BEEC53EE65B}.job => C:\windows\system32\spool\DRIVERS\x64\3\E_YTSKEE.EXE:/EXE:{406C84BF-E4F0-4835-83EF-9BEEC53EE65B} /F:UpdateWORKGROUP\RE5BBOV0NVGFP$ĊSearches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi
Task: C:\WINDOWS\Tasks\HPCeeScheduleForChad.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
2019-05-04 18:55 - 2019-05-04 18:55 - 000024359 _____ () C:\Users\Chad\AppData\Local\recently-used.xbel
S2 HP Comm Recover; "C:\Program Files\HPCommRecovery\HPCommRecovery.exe" [X]
S2 HPJumpStartBridge; "c:\Program Files (x86)\HP\HP JumpStart Bridge\HPJumpStartBridge.exe" [X]
S2 WildTangentHelper; "C:\Program Files (x86)\WildTangent Games\Integration\WildTangentHelperService.exe" [X]
Google Update Helper (HKLM-x32\…\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.451 - Google LLC) Hidden
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} =>  -> No File
FirewallRules: [{3EE1FDF2-12E1-47B6-A319-4940FB0F3F15}] => (Allow) C:\Program Files (x86)\Common Files\Mcafee\MMSSHost\MMSSHost.exe No File
FirewallRules: [{C74A739F-68DA-408D-B3F7-57165959BA47}] => (Allow) C:\Program Files\Common Files\McAfee\MMSSHost\MMSSHost.exe No File
C:\Users\Chad\AppData\Roaming\Browser Assistant
CreateRestorePoint:
cmd: sc config WinDefend start= auto
cmd: sc start WinDefend
EmptyTemp:

NOTE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

  • save the files as fixlist.txt in the same folder as FRST – NOTE: It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work
  • run FRST64 then click Fix just once and wait
  • it will create a log on your desktop, (Fixlog.txt); please post it to your reply.

===================================================

Run Farbar Service Scanner

Please download Farbar Service Scanner and run it on the computer with the issue.

Make sure the following options are checked:


System Restore
Security Center/Action Center
Windows Update
Windows Defender

  • press Scan.
  • it will create a log (FSS.txt) in the same directory the tool is run
  • please copy and paste the log to your reply

Logs to include with next post:

Fixlog.txt
FSS.txt


Thanks

Satchfan

 

MBAM was version 4.1.0 and the instructions are a little different than what that version shows.  Not a big deal, though.

 

Fixlog.txt:

 

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 14-04-2020
Ran by [removed] (14-04-2020 12:18:49) Run:1
Running from C:\Users\[removed]\Desktop
[removed] Boot Mode: Normal
==============================================
fixlist content:
*****************
CloseProcesses:
Task: C:\WINDOWS\Tasks\EPSON WF-3620 Series Invitation {406C84BF-E4F0-4835-83EF-9BEEC53EE65B}.job => C:\windows\system32\spool\DRIVERS\x64\3\E_YTSKEE.EXE
Task: C:\WINDOWS\Tasks\EPSON WF-3620 Series Update {406C84BF-E4F0-4835-83EF-9BEEC53EE65B}.job => C:\windows\system32\spool\DRIVERS\x64\3\E_YTSKEE.EXE:/EXE:{406C84BF-E4F0-4835-83EF-9BEEC53EE65B} /F:UpdateWORKGROUP\RE5BBOV0NVGFP$ĊSearches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi
Task: C:\WINDOWS\Tasks\HPCeeScheduleForChad.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
2019-05-04 18:55 - 2019-05-04 18:55 - 000024359 _____ () C:\Users\Chad\AppData\Local\recently-used.xbel
S2 HP Comm Recover; "C:\Program Files\HPCommRecovery\HPCommRecovery.exe" [X]
S2 HPJumpStartBridge; "c:\Program Files (x86)\HP\HP JumpStart Bridge\HPJumpStartBridge.exe" [X]
S2 WildTangentHelper; "C:\Program Files (x86)\WildTangent Games\Integration\WildTangentHelperService.exe" [X]
Google Update Helper (HKLM-x32\…\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.451 - Google LLC) Hidden
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} =>  -> No File
FirewallRules: [{3EE1FDF2-12E1-47B6-A319-4940FB0F3F15}] => (Allow) C:\Program Files (x86)\Common Files\Mcafee\MMSSHost\MMSSHost.exe No File
FirewallRules: [{C74A739F-68DA-408D-B3F7-57165959BA47}] => (Allow) C:\Program Files\Common Files\McAfee\MMSSHost\MMSSHost.exe No File
C:\Users\Chad\AppData\Roaming\Browser Assistant
CreateRestorePoint:
cmd: sc config WinDefend start= auto
cmd: sc start WinDefend
EmptyTemp:
*****************
Processes closed successfully.
C:\WINDOWS\Tasks\EPSON WF-3620 Series Invitation {406C84BF-E4F0-4835-83EF-9BEEC53EE65B}.job => moved successfully
C:\WINDOWS\Tasks\EPSON WF-3620 Series Update {406C84BF-E4F0-4835-83EF-9BEEC53EE65B}.job => moved successfully
C:\WINDOWS\Tasks\HPCeeScheduleForChad.job => moved successfully
C:\Users\Chad\AppData\Local\recently-used.xbel => moved successfully
HKLM\System\CurrentControlSet\Services\HP Comm Recover => removed successfully
HP Comm Recover => service removed successfully
HKLM\System\CurrentControlSet\Services\HPJumpStartBridge => removed successfully
HPJumpStartBridge => service removed successfully
HKLM\System\CurrentControlSet\Services\WildTangentHelper => removed successfully
WildTangentHelper => service removed successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}\\SystemComponent" => removed successfully
HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxcui => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{3EE1FDF2-12E1-47B6-A319-4940FB0F3F15}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{C74A739F-68DA-408D-B3F7-57165959BA47}" => removed successfully
"C:\Users\Chad\AppData\Roaming\Browser Assistant" => not found
Error: (0) Failed to create a restore point.
========= sc config WinDefend start= auto =========
[SC] OpenService FAILED 5:
Access is denied.

========= End of CMD: =========

========= sc start WinDefend =========

SERVICE_NAME: WinDefend
        TYPE               : 10  WIN32_OWN_PROCESS 
        STATE              : 2  START_PENDING
                                (NOT_STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
        WIN32_EXIT_CODE    : 0  (0x0)
        SERVICE_EXIT_CODE  : 0  (0x0)
        CHECKPOINT         : 0x1
        WAIT_HINT          : 0x7530
        PID                : 668
        FLAGS              :
========= End of CMD: =========

=========== EmptyTemp: ==========
BITS transfer queue => 10248192 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 439183473 B
Java, Flash, Steam htmlcache => 1079 B
Windows/system/drivers => 7395575 B
Edge => 184129569 B
Chrome => 1929579761 B
Firefox => 0 B
Opera => 0 B
Temp, IE cache, history, cookies, recent:
Default => 6656 B
Users => 6656 B
ProgramData => 6656 B
Public => 6656 B
systemprofile => 6656 B
systemprofile32 => 6656 B
LocalService => 10416 B
NetworkService => 220548 B
Chad => 715101613 B
RecycleBin => 23015084 B
EmptyTemp: => 3.1 GB temporary data Removed.
================================

The system needed a reboot.
==== End of Fixlog 12:21:40 ====

 

FSS.txt:  

 

 

Farbar Service Scanner Version: 14-12-2019
Ran by [removed] (administrator) on 14-04-2020 at 12:24:21
Running from "C:\Users\Chad\Desktop"
Microsoft Windows 10 Home  (X64)
Boot Mode: Normal
****************************************************************
 
System Restore:
============
System Restore Policy:
========================

Security Center:
============

Windows Update:
============
Windows Autoupdate Disabled Policy:
============================

Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
The start type of WinDefend service is OK.
The ImagePath of WinDefend: ""C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\MsMpEng.exe"".

Windows Defender Disabled Policy:
==========================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware"=DWORD:1

Other Services:
==============

File Check:
========
C:\Windows\System32\SDRSVC.dll => File is digitally signed
C:\Windows\System32\vssvc.exe => File is digitally signed
C:\Windows\System32\wscsvc.dll => File is digitally signed
C:\Windows\System32\wbem\WMIsvc.dll => File is digitally signed
C:\Windows\System32\wuaueng.dll => File is digitally signed
C:\Windows\System32\qmgr.dll => File is digitally signed
C:\Windows\System32\es.dll => File is digitally signed
C:\Windows\System32\cryptsvc.dll => File is digitally signed
C:\Program Files\Windows Defender\MpSvc.dll => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed

**** End of log ****

Open Malwarebytes Anti-Malware

  • open Malwarebytes
  • when the programme opens, on the right, disable ‘Malware protection’
  • reboot

===================================================

System Restore

  • in the search box on the taskbar, type Create a restore point and select it from the list of results
  • on the ‘System Protection’ tab in ‘System Properties’, select Create
  • type a description for the restore point, and then select Create > OK.

===================================================

Please run FRST again and make sure there is a checkmark next to ‘Addition.txt’ before you hit Scan.

Logs to include with next post:

New Frst.txt
New Addition.txt


Thanks

 

A scan but don't run it until you've finished the first two instructions and the system rebooted.

 

The above instructions said "reboot" after the change to Malwarebytes but please leave rebooting until after you have created a restore point.

FRST.txt:

 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 14-04-2020
Ran by [removed] (administrator) on DESKTOP-TTM2T1H (HP HP Pavilion Desktop PC 570-p0xx) (14-04-2020 14:55:23)
Running from C:\Users\[removed]\Desktop
[removed] Platform: Windows 10 Home Version 1909 18363.720 (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Adobe Inc. -> Adobe Systems) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.452\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.452\GoogleCrashHandler64.exe
(HP Inc. -> HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(HP Inc. -> HP Inc.) C:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe
(Intel Corporation -> Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Intel Corporation -> Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel Corporation -> Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_31a8dbbf39dcdc3b\jhi_service.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki131064.inf_amd64_5d13f27a9a9843fa\igfxCUIService.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki131064.inf_amd64_5d13f27a9a9843fa\igfxEM.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki131064.inf_amd64_5d13f27a9a9843fa\IntelCpHDCPSvc.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki131064.inf_amd64_5d13f27a9a9843fa\IntelCpHeciSvc.exe
(Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel(R) Wireless Connectivity Solutions -> Intel Corporation) C:\Windows\System32\ibtsiva.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <3>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe <6>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeSH.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2003.8-0\MsMpEng.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2003.8-0\NisSrv.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe
(SEIKO EPSON CORPORATION -> Seiko Epson Corporation) C:\Program Files (x86)\EPSON Software\PMA_A\PMAService.exe
(SEIKO EPSON Corporation -> Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe
(SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_YATIKEE.EXE
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM-x32\…\Run: [HPMessageService] => C:\Program Files (x86)\HP\HP System Event\HPMSGSVC.exe [703312 2017-07-21] (HP Inc. -> HP Inc.)
HKLM-x32\…\Run: [EEventManager] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [1092304 2016-03-14] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
HKLM-x32\…\Run: [FUFAXRCV] => C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe [653352 2017-02-16] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
HKLM-x32\…\Run: [FUFAXSTM] => C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe [862248 2017-02-16] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
HKLM-x32\…\Run: [TeamsMachineInstaller] => C:\Program Files (x86)\Teams Installer\Teams.exe [84008696 2019-12-08] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-739738517-1214496134-3013126539-1001\…\Run: [EPLTarget\P0000000000000000] => C:\windows\system32\spool\DRIVERS\x64\3\E_YATIKEE.EXE [298560 2013-09-12] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
HKU\S-1-5-21-739738517-1214496134-3013126539-1001\…\Run: [com.squirrel.Teams.Teams] => C:\Users\Chad\AppData\Local\Microsoft\Teams\Update.exe [2337544 2020-03-14] (Microsoft 3rd Party Application Component -> Microsoft Corporation)
HKU\S-1-5-21-739738517-1214496134-3013126539-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\PhotoScreensaver.scr [567296 2019-03-19] (Microsoft Windows -> Microsoft Corporation)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\80.0.3987.163\Installer\chrmstp.exe [2020-04-03] (Google LLC -> Google LLC)
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {02A43A00-5DB2-48C5-8487-EC76D7BF6E63} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe
Task: {0E2273D5-1090-42C1-9E17-6E84297F4041} - System32\Tasks\EPSON WF-3620 Series Invitation {406C84BF-E4F0-4835-83EF-9BEEC53EE65B} => C:\windows\system32\spool\DRIVERS\x64\3\E_YTSKEE.EXE [679488 2013-02-28] (SEIKO EPSON Corporation -> SEIKO EPSON CORPORATION)
Task: {2C2B047A-C19C-4DA5-ABF1-A028A1438777} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\MpCmdRun.exe [480272 2020-03-25] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {352F7434-A485-4C53-8189-1CA08F03B277} - System32\Tasks\Hewlett-Packard\HP Active Health\HP Active Health Scan (HPSA) => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.exe
Task: {3E906362-F03C-44D0-9A90-C1C8530058C1} - System32\Tasks\HPCeeScheduleForChad => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [97656 2018-09-11] (HP Inc. -> HP Inc.)
Task: {496EF8CF-1F13-49E5-9B69-8DC87EC94FF5} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9279544 2018-09-13] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
Task: {4A5494F4-411A-42DE-A4D6-0019C8227A32} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [134008 2020-03-25] (HP Inc. -> HP Inc.)
Task: {4A6DD08F-2D7C-4645-A2FA-F1EE10611E56} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [1421704 2020-03-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {624D5F62-7C51-48E4-8873-C9E26D9F8BD1} - System32\Tasks\AdwCleaner_onReboot => C:\Users\Chad\Desktop\adwcleaner_8.0.4.exe [8196784 2020-04-14] (Malwarebytes Inc -> Malwarebytes)
Task: {655FEC79-1778-4380-BEE9-5BD0DD8C4F54} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe
Task: {6812ED31-859C-4A5E-8D85-C765B3CF8A2A} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\MpCmdRun.exe [480272 2020-03-25] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {69EA899C-4D00-4435-A883-646AA5C3516A} - System32\Tasks\HPEA3JOBS => C:\Program [Argument = Files\HP\HP ePrint\hpeprint.exe /CheckJobs]
Task: {6BE9E83E-F8C8-41F8-9B58-5ADE266C4CA2} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156104 2019-12-26] (Google LLC -> Google LLC)
Task: {73D987CE-7565-412C-A88E-B4467BDBF4C3} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [1421704 2020-03-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {79AC2131-5AE8-4F61-A946-BD56E00F08C6} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [27369752 2020-03-03] (Microsoft Corporation -> Microsoft Corporation)
Task: {7ABD3184-EA2D-4DC4-AB87-DC753DD7BDFB} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\MpCmdRun.exe [480272 2020-03-25] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {7DF8998E-EF69-4E8A-A57D-C074848BCEA9} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe
Task: {8F70775B-7E2E-43E1-B075-EC084AA81ADE} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156104 2019-12-26] (Google LLC -> Google LLC)
Task: {98CC0CD8-0B4F-4A66-A9F6-55002165E777} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [1571208 2020-03-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {9F884CF8-8269-4463-A1D6-11AB807DCA27} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1242704 2020-02-25] (Adobe Inc. -> Adobe Systems)
Task: {A53D7517-E078-4D39-A60E-A210BE9F0CE7} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe
Task: {A886F862-B87E-4F4D-AA6E-145758A83D57} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\MpCmdRun.exe [480272 2020-03-25] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {AE2F4F11-BCE0-4760-ACF8-FEC2B5861552} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Product Configurator => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\ProductConfig.exe
Task: {B6A2891E-A851-4F22-B957-4366F443CC46} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [27369752 2020-03-03] (Microsoft Corporation -> Microsoft Corporation)
Task: {B8313863-D6B7-4868-9FF2-3ABC4B4D5FF4} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [4461160 2020-01-23] (Microsoft Corporation -> Microsoft Corporation)
Task: {C8E5E442-158B-4665-B9C8-DEF57855541B} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\sdxhelper.exe [110632 2020-03-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {CF20AEAF-4C4D-4281-81FD-0CB6CC082D33} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [4461160 2020-01-23] (Microsoft Corporation -> Microsoft Corporation)
Task: {D7D4CDE4-4254-4388-99EA-A8108955BB7E} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\sdxhelper.exe [110632 2020-03-16] (Microsoft Corporation -> Microsoft Corporation)
Task: {E388E96F-392C-4725-8353-E12D9D628803} - System32\Tasks\EPSON WF-3620 Series Update {406C84BF-E4F0-4835-83EF-9BEEC53EE65B} => C:\windows\system32\spool\DRIVERS\x64\3\E_YTSKEE.EXE [679488 2013-02-28] (SEIKO EPSON Corporation -> SEIKO EPSON CORPORATION)
Task: {FE146D3B-AD56-485E-9EE5-95FAF8E823CF} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [655736 2019-07-31] (HP Inc. -> HP Inc.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{55abad87-d4c4-4d05-b8d5-d633cc63cc75}: [DhcpNameServer] 192.168.1.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://hp17win10.msn.com/?pc=HCTE
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp17win10.msn.com/?pc=HCTE
HKU\S-1-5-21-739738517-1214496134-3013126539-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://hp17win10.msn.com/?pc=HCTE
HKU\S-1-5-21-739738517-1214496134-3013126539-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp17win10.msn.com/?pc=HCTE
SearchScopes: HKLM -> {CD3A9B6B-ADC3-4116-8B3F-FB3EAACA6672} URL = hxxp://www.amazon.com/s/ref=azs_osd_iea?ie=UTF-8&tag;=hp-us1-vsb-20&link;%5Fcode=qs&index;=aps&field-keywords;={searchTerms}
SearchScopes: HKLM-x32 -> {CD3A9B6B-ADC3-4116-8B3F-FB3EAACA6672} URL = hxxp://www.amazon.com/s/ref=azs_osd_iea?ie=UTF-8&tag;=hp-us1-vsb-20&link;%5Fcode=qs&index;=aps&field-keywords;={searchTerms}
SearchScopes: HKU\S-1-5-21-739738517-1214496134-3013126539-1001 -> {CD3A9B6B-ADC3-4116-8B3F-FB3EAACA6672} URL = hxxp://www.amazon.com/s/ref=azs_osd_iea?ie=UTF-8&tag;=hp-us1-vsb-20&link;%5Fcode=qs&index;=aps&field-keywords;={searchTerms}
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2020-01-23] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2020-01-23] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2020-01-23] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2020-01-23] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2020-01-23] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2020-01-23] (Microsoft Corporation -> Microsoft Corporation)
Edge:
======
DownloadDir: C:\Users\Chad\Downloads
Edge Notifications: HKU\S-1-5-21-739738517-1214496134-3013126539-1001 -> hxxps://trampolineparkmiamisburg.notification-0.com; hxxps://jcpenney.notification-0.com
FireFox:
========
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2020-01-23] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2020-01-23] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2020-03-05] (Adobe Inc. -> Adobe Systems Inc.)
Chrome:
=======
CHR DefaultProfile: Profile 1
CHR Profile: C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Default [2020-04-14]
CHR Notifications: Default -> hxxps://www.smarter.com
CHR Extension: (Chrome Web Store Payments) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-12-26]
CHR Extension: (Chrome Media Router) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-04-06]
CHR Profile: C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Guest Profile [2020-04-14]
CHR Profile: C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1 [2020-04-14]
CHR Notifications: Profile 1 -> hxxps://kizi.com; hxxps://www.youtube.com
CHR Extension: (Slides) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2020-03-16]
CHR Extension: (DocHub - Edit and Sign PDF Documents) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\adgncicbhbjfpijkdmbijninnhnmiblj [2020-04-06]
CHR Extension: (Share to Classroom) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\adokjfanaflbkibffcbhihgihpgijcei [2020-04-14]
CHR Extension: (BIODIGITAL HUMAN) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\agoenciogemlojlhccbcpcfflicgnaak [2020-04-06]
CHR Extension: (Docs) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2020-03-16]
CHR Extension: (Google Drive) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-03-16]
CHR Extension: (Desmos Graphing Calculator) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bhdheahnajobgndecdbggfmcojekgdko [2020-04-06]
CHR Extension: (YouTube) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2020-03-16]
CHR Extension: (GeoGebra Classic) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bnbaboaihhkjoaolfnfoablhllahjnee [2020-04-06]
CHR Extension: (Useful Periodic Table (lite)) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\chachkegffmilnmdlonllkhkfkakghie [2020-04-06]
CHR Extension: (Sheets) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2020-03-16]
CHR Extension: (Google Docs Offline) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-03-16]
CHR Extension: (Camera) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\hfhhnacclhffhdffklopdkcgdhifgngh [2020-04-06]
CHR Extension: (Zoom) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\hmbjbjdpkobdjplfobhljndfdfdipjhg [2020-04-14]
CHR Extension: (Pixlr Editor) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\icmaknaampgiegkcjlimdiidlhopknpk [2020-04-06]
CHR Extension: (Smoothwall) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\jbldkhfglmgeihlcaeliadhipokhocnm [2020-04-08]
CHR Extension: (TestNav) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mdmkkicfmmkgmpkmkdikhlbggogpicma [2020-04-06]
CHR Extension: (Google Classroom) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mfhehppjhmmnlfbbopchdfldgimhfhfk [2020-04-06]
CHR Extension: (Screencastify - Screen Video Recorder) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mmeijimgabbpbgpdklnllpncmdofkcpn [2020-04-13]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2020-03-16]
CHR Extension: (Kids A-Z) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pifccnhncmnilgbnnkjkgicpkeclodpd [2020-04-06]
CHR Extension: (Gmail) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-03-16]
CHR Extension: (Chrome Media Router) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-04-03]
CHR Profile: C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 2 [2020-04-14]
CHR Extension: (Slides) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2020-04-13]
CHR Extension: (Docs) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aohghmighlieiainnegkcijnfilokake [2020-04-13]
CHR Extension: (Google Drive) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-04-13]
CHR Extension: (YouTube) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2020-04-13]
CHR Extension: (Sheets) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2020-04-13]
CHR Extension: (Google Docs Offline) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-04-13]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2020-04-13]
CHR Extension: (Gmail) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-04-13]
CHR Extension: (Chrome Media Router) - C:\Users\Chad\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-04-13]
CHR Profile: C:\Users\Chad\AppData\Local\Google\Chrome\User Data\System Profile [2020-04-14]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [11600672 2020-03-03] (Microsoft Corporation -> Microsoft Corporation)
R2 Epson PMAService A; C:\Program Files (x86)\Epson Software\PMA_A\PMAService.exe [113144 2017-03-28] (SEIKO EPSON CORPORATION -> Seiko Epson Corporation)
R2 EpsonScanSvc; C:\windows\system32\EscSvc64.exe [144560 2012-05-17] (SEIKO EPSON Corporation -> Seiko Epson Corporation)
S3 hpqcaslwmiex; C:\Program Files (x86)\HP\Shared\hpqwmiex.exe [1031704 2016-06-04] (Hewlett-Packard Company -> HP)
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [378744 2020-03-31] (HP Inc. -> HP Inc.)
R2 HPWMISVC; c:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe [628768 2017-07-13] (HP Inc. -> HP Inc.)
R2 ibtsiva; C:\WINDOWS\System32\ibtsiva.exe [529912 2018-12-21] (Intel(R) Wireless Connectivity Solutions -> Intel Corporation)
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\WINDOWS\System32\DriverStore\FileRepository\iclsclient.inf_amd64_7e148e9c120d86df\lib\SocketHeciServer.exe [872416 2019-04-23] (Intel(R) Trust Services -> Intel(R) Corporation)
S2 Intel(R) TPM Provisioning Service; C:\WINDOWS\System32\DriverStore\FileRepository\iclsclient.inf_amd64_7e148e9c120d86df\lib\TPMProvisioningService.exe [800224 2019-04-23] (Intel(R) Trust Services -> Intel(R) Corporation)
R2 jhi_service; C:\WINDOWS\System32\DriverStore\FileRepository\dal.inf_amd64_31a8dbbf39dcdc3b\jhi_service.exe [647568 2019-04-30] (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [6933272 2020-04-14] (Malwarebytes Inc -> Malwarebytes)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [310880 2018-09-05] (Intel Corporation -> )
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\NisSrv.exe [3294680 2020-03-25] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\MsMpEng.exe [103168 2020-03-25] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [4059744 2018-09-05] (Intel Corporation -> Intel® Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [153312 2020-04-14] (Malwarebytes Corporation -> Malwarebytes)
R3 ibtusb; C:\WINDOWS\System32\drivers\ibtusb.sys [199192 2018-05-11] (Intel(R) Wireless Connectivity Solutions -> Intel Corporation)
R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [214496 2020-04-14] (Malwarebytes Inc -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [20936 2020-04-14] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\System32\DRIVERS\farflt.sys [195432 2020-04-14] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [248968 2020-04-14] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [119960 2020-04-14] (Malwarebytes Inc -> Malwarebytes)
R3 Netwtw04; C:\WINDOWS\System32\drivers\Netwtw04.sys [8720384 2019-08-27] (Intel(R) Wireless Connectivity Solutions -> Intel Corporation)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [984032 2017-09-15] (Realtek Semiconductor Corp. -> Realtek )
R3 RTSUER; C:\WINDOWS\system32\Drivers\RtsUer.sys [421312 2017-09-14] (Realtek Semiconductor Corp. -> Realsil Semiconductor Corporation)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [45960 2020-03-25] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [391392 2020-03-25] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [59104 2020-03-25] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

==================== One month (created) ===================
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-04-14 14:27 - 2020-04-14 14:27 - 000248968 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2020-04-14 14:27 - 2020-04-14 14:27 - 000195432 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
2020-04-14 14:27 - 2020-04-14 14:27 - 000119960 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2020-04-14 12:24 - 2020-04-14 12:24 - 000001666 _____ C:\Users\Chad\Desktop\FSS.txt
2020-04-14 12:23 - 2020-04-14 12:23 - 000925696 _____ (Farbar) C:\Users\Chad\Desktop\FSS.exe
2020-04-14 12:18 - 2020-04-14 12:21 - 000004897 _____ C:\Users\Chad\Desktop\Fixlog.txt
2020-04-14 08:37 - 2020-04-14 08:37 - 000000000 ____D C:\Users\Chad\Desktop\FRST-OlderVersion
2020-04-14 08:33 - 2020-04-14 08:33 - 000214496 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamChameleon.sys
2020-04-14 08:33 - 2020-04-14 08:33 - 000153312 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys
2020-04-14 08:33 - 2020-04-14 08:33 - 000020936 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamElam.sys
2020-04-14 08:33 - 2020-04-14 08:33 - 000002028 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2020-04-14 08:33 - 2020-04-14 08:33 - 000002028 _____ C:\ProgramData\Desktop\Malwarebytes.lnk
2020-04-14 08:33 - 2020-04-14 08:33 - 000000000 ____D C:\Users\Chad\AppData\Local\mbamtray
2020-04-14 08:33 - 2020-04-14 08:33 - 000000000 ____D C:\Users\Chad\AppData\Local\mbam
2020-04-14 08:33 - 2020-04-14 08:33 - 000000000 ____D C:\Users\Chad\AppData\Local\cache
2020-04-14 08:33 - 2020-04-14 08:33 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2020-04-14 08:33 - 2020-04-14 08:33 - 000000000 ____D C:\ProgramData\Malwarebytes
2020-04-14 08:32 - 2020-04-14 08:32 - 001928352 _____ (Malwarebytes) C:\Users\Chad\Desktop\MBSetup-076981.076981-Consumer.exe
2020-04-14 08:32 - 2020-04-14 08:32 - 000000000 ____D C:\Program Files\Malwarebytes
2020-04-14 08:29 - 2020-04-14 08:29 - 000003168 _____ C:\WINDOWS\system32\Tasks\AdwCleaner_onReboot
2020-04-14 08:26 - 2020-04-14 08:29 - 000000000 ____D C:\AdwCleaner
2020-04-14 08:25 - 2020-04-14 08:25 - 008196784 _____ (Malwarebytes) C:\Users\Chad\Desktop\adwcleaner_8.0.4.exe
2020-04-13 21:13 - 2020-04-14 08:38 - 000029208 _____ C:\Users\Chad\Desktop\Addition.txt
2020-04-13 21:12 - 2020-04-14 14:55 - 000028123 _____ C:\Users\Chad\Desktop\FRST.txt
2020-04-13 21:11 - 2020-04-14 14:55 - 000000000 ____D C:\FRST
2020-04-13 21:10 - 2020-04-14 08:37 - 002281472 _____ (Farbar) C:\Users\Chad\Desktop\FRST64.exe
2020-04-13 21:09 - 2020-04-13 21:09 - 001157812 _____ C:\WINDOWS\Minidump\041320-21796-01.dmp
2020-04-13 21:08 - 2020-04-13 21:08 - 688590482 ____N C:\WINDOWS\MEMORY.DMP
2020-04-13 21:04 - 2020-04-13 21:09 - 000000000 ____D C:\WINDOWS\Minidump
2020-04-13 21:02 - 2020-04-13 21:02 - 005198336 _____ (AVAST Software) C:\Users\Chad\Desktop\aswMBR.exe
2020-04-13 20:42 - 2020-04-13 20:42 - 006946736 _____ (EnigmaSoft Limited) C:\Users\Chad\Downloads\sh-remover.exe
2020-04-13 13:33 - 2020-04-13 13:33 - 000002481 _____ C:\Users\Chad\Desktop\Mom - Chrome.lnk
2020-04-06 09:36 - 2020-04-06 09:36 - 000000000 ____D C:\Users\Chad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
2020-03-26 13:20 - 2020-03-26 13:20 - 000078168 _____ (Zoom Video Communications, Inc.) C:\Users\Chad\Downloads\Zoom_42034cce248d8e41.exe
2020-03-16 09:57 - 2020-04-06 09:35 - 000002481 _____ C:\Users\Chad\Desktop\Grace - Chrome.lnk
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-04-14 14:54 - 2018-06-26 20:11 - 000000000 __SHD C:\Users\Chad\IntelGraphicsProfiles
2020-04-14 14:53 - 2019-12-26 11:32 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2020-04-14 14:53 - 2019-03-19 00:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2020-04-14 14:41 - 2019-12-26 11:39 - 000004164 _____ C:\WINDOWS\system32\Tasks\User_Feed_Synchronization-{1F435414-D5C0-4BCD-8953-1C1EE5157FC8}
2020-04-14 14:37 - 2018-06-26 20:43 - 000044397 _____ C:\Users\Chad\Desktop\Food Inventory.xlsx
2020-04-14 14:31 - 2019-12-26 11:41 - 000936976 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2020-04-14 14:31 - 2019-03-19 00:50 - 000000000 ____D C:\WINDOWS\INF
2020-04-14 14:27 - 2019-12-26 11:39 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2020-04-14 14:26 - 2019-03-19 00:37 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2020-04-14 12:30 - 2018-06-26 20:44 - 000000000 ____D C:\Users\Chad\Documents\Outlook Files
2020-04-14 08:33 - 2019-03-19 00:52 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2020-04-14 08:29 - 2018-06-26 20:14 - 000000000 ____D C:\Users\Chad\AppData\Roaming\Hewlett-Packard
2020-04-14 08:29 - 2018-06-26 20:11 - 000000000 ____D C:\Users\Chad\AppData\Local\Hewlett-Packard
2020-04-14 08:29 - 2018-03-06 11:15 - 000000000 ____D C:\ProgramData\HP
2020-04-14 08:29 - 2018-03-06 11:15 - 000000000 ____D C:\ProgramData\Hewlett-Packard
2020-04-14 08:29 - 2018-03-06 11:15 - 000000000 ____D C:\Program Files (x86)\Hewlett-Packard
2020-04-14 08:29 - 2018-03-06 11:14 - 000000000 ____D C:\Program Files (x86)\HP
2020-04-14 08:29 - 2017-10-31 19:51 - 000000000 ___HD C:\hp
2020-04-13 22:31 - 2019-12-26 11:35 - 000000000 ____D C:\Users\Chad
2020-04-13 21:04 - 2019-12-26 11:32 - 001810805 ____N C:\WINDOWS\Minidump\041320-6703-01.dmp
2020-04-13 20:28 - 2019-12-26 11:39 - 000003248 _____ C:\WINDOWS\system32\Tasks\HPCeeScheduleForChad
2020-04-13 17:49 - 2019-03-19 00:52 - 000000000 ___HD C:\Program Files\WindowsApps
2020-04-13 17:49 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\AppReadiness
2020-04-11 16:20 - 2018-06-26 20:11 - 000000000 ____D C:\Users\Chad\AppData\Local\Packages
2020-04-09 19:47 - 2020-01-08 20:42 - 000000000 ____D C:\Users\Chad\Desktop\Nate's Camera
2020-04-09 06:35 - 2018-06-26 20:43 - 000000000 ____D C:\Users\Chad\Desktop\8876 Wildfire
2020-04-03 14:01 - 2019-12-26 11:56 - 000002308 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-04-03 14:01 - 2019-12-26 11:56 - 000002267 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2020-04-03 14:01 - 2019-12-26 11:56 - 000002267 _____ C:\ProgramData\Desktop\Google Chrome.lnk
2020-04-02 10:15 - 2018-08-27 09:21 - 000744808 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2020-03-25 09:24 - 2018-06-27 08:13 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2020-03-23 07:55 - 2019-12-26 11:39 - 000003376 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-739738517-1214496134-3013126539-1001
2020-03-23 07:55 - 2019-12-26 11:35 - 000002367 _____ C:\Users\Chad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2020-03-23 07:55 - 2019-09-10 16:25 - 000000000 ___RD C:\Users\Chad\OneDrive - Dayton Regional STEM School
2020-03-20 18:45 - 2019-12-26 11:56 - 000003420 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2020-03-20 18:45 - 2019-12-26 11:56 - 000003296 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2020-03-19 15:28 - 2019-12-26 11:39 - 000004562 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2020-03-19 15:28 - 2019-12-26 09:58 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2020-03-18 09:23 - 2018-06-26 21:10 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2020-03-16 12:06 - 2020-01-31 10:09 - 000013247 _____ C:\Users\Chad\Desktop\Nate Jan Progress Book.xlsx
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================

 

Addition.txt:

 

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 14-04-2020
Ran by [removed] (14-04-2020 14:56:18)
Running from C:\Users\[removed]\Desktop
Windows 10 Home Version 1909 18363.720 (X64) (2019-12-26 15:39:51)
Boot Mode: Normal
==========================================================

==================== Accounts: =============================
Administrator (S-1-5-21-739738517-1214496134-3013126539-500 - Administrator - Disabled)
Chad (S-1-5-21-739738517-1214496134-3013126539-1001 - Administrator - Enabled) => C:\Users\Chad
DefaultAccount (S-1-5-21-739738517-1214496134-3013126539-503 - Limited - Disabled)
Guest (S-1-5-21-739738517-1214496134-3013126539-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-739738517-1214496134-3013126539-504 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Malwarebytes (Disabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe Acrobat Reader DC (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 20.006.20042 - Adobe Systems Incorporated)
Bonjour (HKLM\…\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Direct Game UNI Installer (HKLM-x32\…\{C77717A7-09BF-49AF-92F2-9F3ED9AF5BFD}) (Version: 1.0.17 - GamesLOL)
Epson Event Manager (HKLM-x32\…\{006C8256-3855-43BF-8BA5-4B4C40F41F71}) (Version: 3.10.0065 - Seiko Epson Corporation)
Epson FAX Utility (HKLM-x32\…\{0CBE6C93-CB2E-4378-91EE-12BE6D4E2E4A}) (Version: 2.02.00 - Seiko Epson Corporation)
Epson PC-FAX Driver (HKLM-x32\…\EPSON PC-FAX Driver 2) (Version:  - Seiko Epson Corporation)
Epson ReadyInk Agent (A) (HKLM-x32\…\{A9B4584F-A29E-4880-97E6-1744B4AF2AF8}) (Version: 1.0.1.0 - Seiko Epson Corporation)
EPSON Scan (HKLM-x32\…\EPSON Scanner) (Version:  - Seiko Epson Corporation)
Epson Software Updater (HKLM-x32\…\{B55DB65D-EF6E-4E04-89D5-B03603BF681B}) (Version: 4.4.5 - SEIKO EPSON CORPORATION)
EPSON WF-3620 Series Printer Uninstall (HKLM\…\EPSON WF-3620 Series) (Version:  - SEIKO EPSON Corporation)
Epson WF-3620 User’s Guide version 1.0 (HKLM-x32\…\UsersGuideEpson WF-3620 User’s Guide_is1) (Version: 1.0 - )
EpsonNet Print (HKLM\…\{96ED1D58-440C-4345-8FEE-C4781366C67F}) (Version: 3.1.4.0 - SEIKO EPSON Corporation)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 80.0.3987.163 - Google LLC)
Google Update Helper (HKLM-x32\…\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.451 - Google LLC)
HP Audio Switch (HKLM-x32\…\{3A5141D4-47DB-4302-9B1C-272BE585BC8A}) (Version: 1.0.179.0 - HP Inc.)
HP Documentation (HKLM\…\HP_Documentation) (Version: 1.0.0.1 - HP Inc.)
HP ePrint SW (HKLM-x32\…\{cdb5f70f-5107-4613-bf69-15de903b5b5d}) (Version: 5.5.22560 - HP Inc.)
HP JumpStart Bridge (HKLM-x32\…\{3FC961DB-BD36-4D8D-B276-0C456A2BB638}) (Version: 1.4.0.441 - HP Inc.)
HP JumpStart Launch (HKLM-x32\…\{F213102E-FD30-4E22-AF73-4C682D65FFEE}) (Version: 1.4.441.0 - HP Inc.)
HP System Event Utility (HKLM-x32\…\{4B0A7A8A-ECE5-4639-9A0D-C535F354313D}) (Version: 1.4.26 - HP Inc.)
Intel(R) Chipset Device Software (HKLM-x32\…\{17408817-d415-4768-a160-ae6d46d6bdb0}) (Version: 10.1.1.44 - Intel(R) Corporation) Hidden
Intel(R) Management Engine Components (HKLM\…\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.7.0.1043 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 25.20.100.6446 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\…\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 15.8.1.1007 - Intel Corporation)
Intel(R) Serial IO (HKLM\…\{9FD91C5C-44AE-4D9D-85BE-AE52816B0294}) (Version: 30.100.1725.1 - Intel Corporation)
Intel(R) Wireless Bluetooth(R) (HKLM-x32\…\{00000080-0190-1033-84C8-B8D95FA3C8C3}) (Version: 19.80.0 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\…\{f8c930bd-0a68-425f-8c11-87723d1e2c97}) (Version: 20.90.0 - Intel Corporation)
Malwarebytes version 4.1.0.56 (HKLM\…\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.1.0.56 - Malwarebytes)
Microsoft Office 365 - en-us (HKLM\…\o365homepremretail - en-us) (Version: 16.0.11929.20648 - Microsoft Corporation)
Microsoft Office 365 ProPlus - en-us (HKLM\…\O365ProPlusRetail - en-us) (Version: 16.0.11929.20648 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-739738517-1214496134-3013126539-1001\…\OneDriveSetup.exe) (Version: 19.232.1124.0010 - Microsoft Corporation)
Microsoft Teams (HKU\S-1-5-21-739738517-1214496134-3013126539-1001\…\Teams) (Version: 1.3.00.3564 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\…\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\…\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\…\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\…\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24123 (HKLM-x32\…\{2cbcedbb-f38c-48a3-a3e1-6c6fd821a7f4}) (Version: 14.0.24123.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24123 (HKLM-x32\…\{206898cc-4b41-4d98-ac28-9f9ae57f91fe}) (Version: 14.0.24123.0 - Microsoft Corporation)
Office 16 Click-to-Run Extensibility Component (HKLM-x32\…\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.11929.20648 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\…\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.11929.20648 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\…\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.11929.20648 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM-x32\…\{90160000-008C-0409-0000-0000000FF1CE}) (Version: 16.0.11929.20648 - Microsoft Corporation) Hidden
Realtek Card Reader (HKLM-x32\…\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.15063.31237 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.19.627.2017 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8536 - Realtek Semiconductor Corp.)
Teams Machine-Wide Installer (HKLM-x32\…\{39AF0813-FA7B-4860-ADBE-93B9B214B914}) (Version: 1.2.0.34161 - Microsoft Corporation)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\…\{F14FB68A-9188-4036-AD0D-D054BC9C9291}) (Version: 2.59.0.0 - Microsoft Corporation)
Vulkan Run Time Libraries 1.1.70.1 (HKLM\…\VulkanRT1.1.70.1) (Version: 1.1.70.1 - LunarG, Inc.) Hidden
Windows 10 Update Assistant (HKLM-x32\…\{D5C69738-B486-402E-85AC-2456D98A64E4}) (Version: 1.4.9200.22391 - Microsoft Corporation)
Packages:
=========
Any Player -> C:\Program Files\WindowsApps\15191PeakPlayer.50533F9B98293_3.1.4.0_x64__y5c4dfz5b21fm [2020-04-11] (Any DVD & Office App)
Connect -> C:\Windows\SystemApps\Microsoft.Windows.DevicesFlowHost_cw5n1h2txyewy [2019-12-26] (Microsoft Corporation)
Dolby Access -> C:\Program Files\WindowsApps\DolbyLaboratories.DolbyAccess_3.1.4081.0_x64__rz1tebttyb220 [2020-01-28] (Dolby Laboratories)
Floor Adjustment -> C:\Windows\SystemApps\RoomAdjustment_cw5n1h2txyewy [2019-12-26] (Microsoft Corporation)
HP JumpStart -> C:\Program Files\WindowsApps\AD2F1837.HPJumpStart_1.4.443.0_x86__v10z8vjag6ke6 [2018-03-06] (HP Inc.)
Learn Mixed Reality -> C:\Windows\SystemApps\MixedRealityLearning_cw5n1h2txyewy [2019-12-26] (Microsoft Corporation)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-01-19] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-01-19] (Microsoft Corporation) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.6.1224.0_x64__8wekyb3d8bbwe [2020-02-28] (Microsoft Studios) [MS Ad]
MSN Weather -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.36.20714.0_x64__8wekyb3d8bbwe [2020-03-24] (Microsoft Corporation) [MS Ad]
New for You -> C:\Windows\SystemApps\WhatsNew_cw5n1h2txyewy [2019-12-26] (Microsoft Corporation)
Passthrough -> C:\Windows\SystemApps\passthrough_cw5n1h2txyewy [2019-12-26] (Microsoft Corporation)
Photos Add-on -> C:\Program Files\WindowsApps\Microsoft.Windows.Photos.DLC.Main_2017.39121.36610.0_x64__8wekyb3d8bbwe [2019-06-18] (Microsoft Corporation)
Photos Media Engine Add-on -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2019-09-27] (Microsoft Corporation)
Power Media Player 14 for HP Consumer PCs with DVD -> C:\Program Files\WindowsApps\CyberLinkCorp.hs.PowerMediaPlayer14forHPConsumerPC_14.2.9528.0_x86__06qsbagp91rvg [2019-01-26] (CYBERLINKCOM CORP)
Sign In -> C:\Windows\SystemApps\WebAuthBridgeInternet_cw5n1h2txyewy [2019-12-26] (ms-resource:PublisherDisplayName)
Sign In -> C:\Windows\SystemApps\WebAuthBridgeInternetSso_cw5n1h2txyewy [2019-12-26] (ms-resource:PublisherDisplayName)
Sign In -> C:\Windows\SystemApps\WebAuthBridgeIntranetSso_cw5n1h2txyewy [2019-12-26] (ms-resource:PublisherDisplayName)
Simple Solitaire -> C:\Program Files\WindowsApps\26720RandomSaladGamesLLC.SimpleSolitaire_6.18.78.0_x64__kx24dqmazqk8j [2020-02-29] (Random Salad Games LLC) [MS Ad]
Sling TV -> C:\Program Files\WindowsApps\SlingTVLLC.SlingTV_7.0.8.0_x86__vgszm6stshdqy [2019-01-09] (Sling TV LLC)
Smartfriend by HP Care -> C:\Program Files\WindowsApps\AD2F1837.SmartfriendbyHPCare_1.1.13.0_x64__v10z8vjag6ke6 [2018-03-06] (HP Inc.)
==================== Custom CLSID (Whitelisted): ==============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-739738517-1214496134-3013126539-1001_Classes\CLSID\{04271989-C4D2-D497-85E3-A60B7ED435AC} -> [OneDrive - Dayton Regional STEM School] => C:\Users\Chad\OneDrive - Dayton Regional STEM School [2019-09-10 16:25]
CustomCLSID: HKU\S-1-5-21-739738517-1214496134-3013126539-1001_Classes\CLSID\{19A6E644-14E6-4A60-B8D7-DD20610A871D}\InprocServer32 -> C:\Users\Chad\AppData\Local\Microsoft\TeamsMeetingAddin\1.0.19350.3\x64\Microsoft.Teams.AddinLoader.dll (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-739738517-1214496134-3013126539-1001_Classes\CLSID\{CB965DF1-B8EA-49C7-BDAD-5457FDC1BF92}\InprocServer32 -> C:\Users\Chad\AppData\Local\Microsoft\TeamsMeetingAddin\1.0.19350.3\x64\Microsoft.Teams.AddinLoader.dll (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2020-04-14] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\System32\DriverStore\FileRepository\ki131064.inf_amd64_5d13f27a9a9843fa\igfxDTCM.dll [2019-02-17] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2020-04-14] (Malwarebytes Corporation -> Malwarebytes)
==================== Codecs (Whitelisted) ====================
==================== Shortcuts & WMI ========================
(The entries could be listed to be restored or removed.)
ShortcutWithArgument: C:\Users\Chad\Desktop\Grace - Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> –profile-directory="Profile 1"
ShortcutWithArgument: C:\Users\Chad\Desktop\Mom - Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> –profile-directory="Profile 2"
ShortcutWithArgument: C:\Users\Chad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Camera.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) ->  –profile-directory="Profile 1" –app-id=hfhhnacclhffhdffklopdkcgdhifgngh
ShortcutWithArgument: C:\Users\Chad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\GeoGebra Classic.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) ->  –profile-directory="Profile 1" –app-id=bnbaboaihhkjoaolfnfoablhllahjnee
ShortcutWithArgument: C:\Users\Chad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\TestNav.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) ->  –profile-directory="Profile 1" –app-id=mdmkkicfmmkgmpkmkdikhlbggogpicma
ShortcutWithArgument: C:\Users\Chad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Zoom.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) ->  –profile-directory="Profile 1" –app-id=hmbjbjdpkobdjplfobhljndfdfdipjhg
ShortcutWithArgument: C:\Users\Chad\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\ff13ca23fee04978\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> –profile-directory="Profile 5"
ShortcutWithArgument: C:\Users\Chad\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\9501e18d7c2ab92e\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> –profile-directory="Profile 2"
ShortcutWithArgument: C:\Users\Chad\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\69639df789022856\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> –profile-directory="Profile 1"
ShortcutWithArgument: C:\Users\Chad\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\48499db33039e897\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> –profile-directory="Profile 4"
ShortcutWithArgument: C:\Users\Chad\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\225bb61db2f318c1\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> –profile-directory="Profile 3"
==================== Loaded Modules (Whitelisted) =============
2016-05-09 09:20 - 2016-05-09 09:20 - 000132096 _____ (Seiko Epson Corporation) [File not signed] C:\Program Files (x86)\EPSON Software\Event Manager\epnsm.dll
2009-10-21 17:39 - 2009-10-21 17:39 - 000291328 _____ (SEIKO EPSON CORPORATION) [File not signed] C:\Program Files (x86)\EPSON Software\Event Manager\LcMgr.dll
2016-09-14 14:31 - 2016-09-14 14:31 - 000500736 _____ (SEIKO EPSON CORPORATION) [File not signed] C:\WINDOWS\System32\enppmon.dll
==================== Alternate Data Streams (Whitelisted) ========
==================== Safe Mode (Whitelisted) ==================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
==================== Association (Whitelisted) =================
==================== Internet Explorer trusted/restricted ==========
(If an entry is included in the fixlist, it will be removed from the registry.)
IE trusted site: HKU\S-1-5-21-739738517-1214496134-3013126539-1001\…\sharepoint.com -> hxxps://daytonstemschoolorg-files.sharepoint.com
==================== Hosts content: =========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2017-09-29 09:46 - 2017-09-29 09:44 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts
==================== Other Areas ===========================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-739738517-1214496134-3013126539-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Chad\Pictures\Easter 2020 4.JPG
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
(If an entry is included in the fixlist, it will be removed.)
HKLM\…\StartupApproved\Run32: => "HPMessageService"
HKLM\…\StartupApproved\Run32: => "FUFAXRCV"
HKLM\…\StartupApproved\Run32: => "FUFAXSTM"
HKU\S-1-5-21-739738517-1214496134-3013126539-1001\…\StartupApproved\Run: => "OneDrive"
==================== FirewallRules (Whitelisted) ================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{00CB71B4-D99C-4C0C-93DB-E17E4281AB9F}] => (Allow) C:\Users\Chad\AppData\Local\Temp\WF-3620\Common\EpsonNet Setup\ENEasyApp.exe No File
FirewallRules: [{1100765F-5717-49C7-804E-A0E76CF930E1}] => (Allow) C:\Users\Chad\AppData\Local\Temp\WF-3620\Common\EpsonNet Setup\ENEasyApp.exe No File
FirewallRules: [{A615BE46-8F40-44D2-8C07-8D1837C9A155}] => (Allow) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
FirewallRules: [{E701CCE1-991D-4E32-BE22-6B8CA0133AC8}] => (Allow) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
FirewallRules: [{CADF8CDF-AFAC-4BD2-9CDB-7BE1992B7137}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{87132A74-3F41-45FF-AAD5-E9DC2C4BC058}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{33CA5CE1-C253-4D11-AB9E-0C6387E9A4D5}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{335234DF-FD72-42B1-B714-47D5CF448F45}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{1D23678D-91C3-4FFE-8DCD-9F814D770BC4}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{01DCF1BB-01F6-402D-860B-5A5625BF40AD}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{CA76B6D7-C405-4660-AD8A-35235D9565F5}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe (Intel Corporation -> )
FirewallRules: [{3854827A-6F82-43F1-8DEA-90A13A569D63}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{5244D7F8-C295-4E2C-A94A-E37300DF7191}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{34788936-5E00-483F-B55C-35120CC9C0ED}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{4F4D9931-5619-4133-BE4D-BF7A8F97BB5F}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
==================== Restore Points =========================
14-04-2020 14:29:23 Restore
==================== Faulty Device Manager Devices ============

==================== Event log errors: ========================
Application errors:
==================
Error: (04/14/2020 02:36:26 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (5428,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.
Error: (04/14/2020 12:33:47 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (5488,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.
Error: (04/14/2020 10:45:53 AM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (6712,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.
Error: (04/14/2020 10:37:53 AM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (2592,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.
Error: (04/14/2020 10:32:20 AM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (1344,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.
Error: (04/14/2020 08:49:07 AM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (10900,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.
Error: (04/14/2020 08:42:16 AM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (5368,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.
Error: (04/13/2020 09:16:24 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (4992,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.

System errors:
=============
Error: (04/14/2020 12:22:17 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has stopped unexpectedly.
Module Path: C:\WINDOWS\system32\IntelWifiIhv04.dll
Error: (04/14/2020 12:22:17 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has stopped unexpectedly.
Module Path: C:\WINDOWS\system32\IntelWifiIhv04.dll
Error: (04/14/2020 12:22:12 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has stopped unexpectedly.
Module Path: C:\WINDOWS\system32\IntelWifiIhv04.dll
Error: (04/14/2020 12:18:50 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The HP Support Solutions Framework Service service terminated unexpectedly.  It has done this 1 time(s).
Error: (04/14/2020 12:18:50 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Intel(R) Rapid Storage Technology service terminated unexpectedly.  It has done this 1 time(s).
Error: (04/14/2020 12:18:50 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Search service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 30000 milliseconds: Restart the service.
Error: (04/14/2020 12:18:50 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Intel(R) PROSet/Wireless Registry Service service terminated unexpectedly.  It has done this 1 time(s).
Error: (04/14/2020 12:18:50 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Intel(R) PROSet/Wireless Zero Configuration Service service terminated unexpectedly.  It has done this 1 time(s).

Windows Defender:
===================================
Date: 2020-04-02 09:20:56.934
Description:
Windows Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?linkid=37020&name;=Program:Win32/Unwaders&threatid;=250668&enterprise;=0
Name: Program:Win32/Unwaders
ID: 250668
Severity: Severe
Category: Potentially Unwanted Software
Path: file:_C:\Users\Chad\AppData\Roaming\Browser Assistant\BrowserAssistant.Driver.dll
Detection Origin: Local machine
Detection Type: FastPath
Detection Source: Real-Time Protection
Process Name: C:\Users\Chad\AppData\Roaming\Browser Assistant\BrowserAssistant.exe
Security intelligence Version: AV: 1.313.558.0, AS: 1.313.558.0, NIS: 1.313.558.0
Engine Version: AM: 1.1.16900.4, NIS: 1.1.16900.4
CodeIntegrity:
===================================
Date: 2020-04-14 14:29:07.577
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume5\Program Files\Malwarebytes\Anti-Malware\MBAMWsc.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2020-04-14 14:29:07.565
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume5\Program Files\Malwarebytes\Anti-Malware\MBAMWsc.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
==================== Memory info ===========================
BIOS: AMI F.24 01/23/2018
Motherboard: HP 82F2
Processor: Intel(R) Core(TM) i3-7100 CPU @ 3.90GHz
Percentage of memory in use: 40%
Total physical RAM: 8080.34 MB
Available physical RAM: 4811.75 MB
Total Virtual: 16272.34 MB
Available Virtual: 13201.68 MB
==================== Drives ================================
Drive c: (Windows) (Fixed) (Total:118.01 GB) (Free:30.05 GB) NTFS
Drive d: (DATA) (Fixed) (Total:917.14 GB) (Free:908.95 GB) NTFS
Drive e: (RECOVERY) (Fixed) (Total:14.37 GB) (Free:1.73 GB) NTFS ==>[system with boot components (obtained from drive)]
\\?\Volume{c6de160f-ea7b-4d4f-9c1d-8a0c8ab91ab9}\ (Windows RE tools) (Fixed) (Total:0.96 GB) (Free:0.5 GB) NTFS
\\?\Volume{f7bdef1d-c0ab-4af5-9c2a-062f10ba0fb6}\ () (Fixed) (Total:0.25 GB) (Free:0.18 GB) FAT32
==================== MBR & Partition Table ====================
==========================================================
Disk: 0 (Size: 119.2 GB) (Disk ID: 6136ABCD)
Partition: GPT.
==========================================================
Disk: 1 (Size: 931.5 GB) (Disk ID: B119E5B4)
Partition: GPT.
==================== End of Addition.txt =======================

That looks fine. Windows Defender is working again and you have a Restore point.

 

==============================

 

Please uninstall Google Update Helper.

 

==============================

 

Are there any outstanding problems?

Your computer appears to be clean. Now that it seems to be running well, please follow these steps to tidy up and decrease the likelihood of getting infected again:

Uninstall FRST

  • right-click on FRST64.exe and select Rename
  • rename the file to Uninstall.exe
  • double-click on Uninstall.exe – this will uninstall FRST

===================================================

Uninstall AdwCleaner

  • open adwcleaner.exe
  • click on Settings
  • click on the Application tab and scroll down to the bottom
  • click on Remove.

===================================================

Uninstall remaining programmes

To check for any leftover installed tools press the Windows Key + R at the same time, then type appwiz.cpl then Enter.

You can uninstall any programmes we used that still remain:

You can also delete all other logs and programmes we’ve used that are on your desktop. Just click on them and press Delete.

===================================================

Recommended

Update and run Malwarebytes. This really is an excellent program that you should update and run on a regular basis, probably weekly.

===================================================

I also recommend that you read the following:

Simple and easy ways to keep your computer safe and secure on the Internet by Lawrence Abrams

Answers to Common Security Questions - Best Practices by quietman7

How Malware Spreads - How Did I Get Infected by quietman7

I will keep this open for 24 hours in case you have any problems, after which I’ll close the topic.

Safe computing

Satchfan

 

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI