Greetings folks,
Hoping for some assistance on an issue facing one of my clients that has me stumped.
2 people at a company have reported occasionally having web searches redirect to strange addresses. It's been happening for 2-3 weeks. I've checked, and it looks like there is a secondary DNS server added that's likely malicious. This was seen on both.
Other than that, no other behavior is reported. The installed EDR has been silent, and a MBAM full scan on the first user's computer has come up clean.
DNS should be coming from the firewall which afiak is fine and secure, nothing strange. I'm hoping someone can check the attached frst logs and advise if there is any evidence of local infection that I've missed.
Thanks!
(I've censored the logs a touch, if a fixlist is provided I'll edit the user and company name back in, if required.)
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 10.04.2024
Ran by admin (administrator) on ADL-PF4EQNV1 (LENOVO 21JR001RUS) (15-04-2024 10:04:33)
Running from C:\Temp\farbar\FRST64.exe
Loaded Profiles: admin & USERNAME
Platform: Microsoft Windows 11 Pro Version 23H2 22631.3447 (X64) Language: English (United States)
Default browser: Edge
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(0A0B0503-04C2-4CCF-9BC2-4F164DC80FEE -> Advanced Micro Devices, Inc.) C:\Program Files\WindowsApps\AdvancedMicroDevicesInc-2.AMDRadeonSoftware_10.23.10022.0_x64__0a9344xs7nr4m\radeonsoftware\AMDRSServ.exe
(0A0B0503-04C2-4CCF-9BC2-4F164DC80FEE -> Advanced Micro Devices, Inc.) C:\Program Files\WindowsApps\AdvancedMicroDevicesInc-2.AMDRadeonSoftware_10.23.10022.0_x64__0a9344xs7nr4m\radeonsoftware\RadeonSoftware.exe
(0F0AD9E1-5E20-4F73-9864-163EC6D96846 -> Senary Technology Limited) C:\Program Files\WindowsApps\SenaryTechnologyLimited.SenarySmartAudio_2.42.0.0_x64__dqz7eftfn33jw\SenaryAudioApp.exe
(C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe ->) (Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\acrocef_1\RdrCEF.exe <8>
(C:\Program Files (x86)\BeAnywhere Support Express\GetSupportService_N-Central\BASupSrvc.exe ->) (N-ABLE TECHNOLOGIES LTD -> N-able Take Control) C:\Program Files (x86)\BeAnywhere Support Express\GetSupportService_N-Central\BASupTSHelper.exe
(C:\Program Files (x86)\BeAnywhere Support Express\GetSupportService_N-Central\BASupTSHelper.exe ->) (N-ABLE TECHNOLOGIES LTD -> N-able Take Control) C:\Program Files (x86)\BeAnywhere Support Express\GetSupportService_N-Central\BASupClpHlp.exe
(C:\Program Files (x86)\Microsoft\EdgeWebView\Application\123.0.2420.97\msedgewebview2.exe ->) (N-ABLE TECHNOLOGIES LTD -> N-able Take Control) C:\Program Files (x86)\BeAnywhere Support Express\GetSupportService_N-Central\BASupSrvcCnfg.exe
(C:\Program Files (x86)\N-able Technologies\Windows Agent\bin\agent.exe ->) (N-ABLE TECHNOLOGIES LTD -> N-able Technologies Inc.) C:\Program Files (x86)\N-able Technologies\Reactive\bin\NableReactiveManagement.exe
(C:\Program Files (x86)\N-able Technologies\Windows Agent\bin\agent.exe ->) (N-ABLE TECHNOLOGIES LTD -> N-able Technologies Inc.) C:\Program Files (x86)\N-able Technologies\Windows Agent\bin\NableSixtyFourBitManager.exe
(C:\Program Files\Lenovo\Lenovo Smart Appearance Components\Components\IntelligentSensingAwareService\LsaRpcServer.exe ->) (Lenovo -> Lenovo) C:\Program Files\Lenovo\Lenovo Smart Appearance Components\Components\IntelligentSensingAwareService\LsaToast.exe
(C:\Program Files\Lenovo\Lenovo Smart Appearance Components\Components\SmartAppearanceAIService\SmartAppearanceSVC.exe ->) (Lenovo -> Lenovo) C:\Program Files\Lenovo\Lenovo Smart Appearance Components\Components\SmartAppearanceAIService\FaceBeautify.exe
(C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\splwow64.exe
(C:\Program Files\Microsoft Office\root\Office16\OUTLOOK.EXE ->) (Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe <2>
(C:\Program Files\Microsoft Office\root\Office16\OUTLOOK.EXE ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\ai.exe
(C:\Program Files\SentinelOne\Sentinel Agent 23.3.3.264\SentinelAgent.exe ->) (SentinelOne Inc. -> Sentinel Labs, Inc.) C:\Program Files\SentinelOne\Sentinel Agent 23.3.3.264\SentinelAgentWorker.exe
(C:\Program Files\SentinelOne\Sentinel Agent 23.3.3.264\SentinelStaticEngine.exe ->) (SentinelOne Inc. -> Sentinel Labs, Inc.) C:\Program Files\SentinelOne\Sentinel Agent 23.3.3.264\SentinelStaticEngineScanner.exe <2>
(C:\Program Files\WindowsApps\AdvancedMicroDevicesInc-2.AMDRadeonSoftware_10.23.10022.0_x64__0a9344xs7nr4m\radeonsoftware\AMDRSServ.exe ->) (0A0B0503-04C2-4CCF-9BC2-4F164DC80FEE -> Advanced Micro Devices, Inc.) C:\Program Files\WindowsApps\AdvancedMicroDevicesInc-2.AMDRadeonSoftware_10.23.10022.0_x64__0a9344xs7nr4m\radeonsoftware\AMDRSSrcExt.exe
(C:\Program Files\WindowsApps\AdvancedMicroDevicesInc-2.AMDRadeonSoftware_10.23.10022.0_x64__0a9344xs7nr4m\radeonsoftware\RadeonSoftware.exe ->) (0A0B0503-04C2-4CCF-9BC2-4F164DC80FEE -> Advanced Micro Devices, Inc.) C:\Program Files\WindowsApps\AdvancedMicroDevicesInc-2.AMDRadeonSoftware_10.23.10022.0_x64__0a9344xs7nr4m\radeonsoftware\cncmd.exe
(C:\Program Files\WindowsApps\MSTeams_24060.2623.2790.8046_x64__8wekyb3d8bbwe\ms-teams.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\123.0.2420.97\msedgewebview2.exe <22>
(DriverStore\FileRepository\dax3_swc_aposvc.inf_amd64_cfeb891cbda10dc3\DAX3API.exe ->) (Dolby Laboratories, Inc. -> Dolby Laboratories) C:\Windows\System32\DriverStore\FileRepository\DAX3_S~1.INF\DAX3API.exe
(DriverStore\FileRepository\fn.inf_amd64_28255300d21d060b\driver\tphkload.exe ->) (Lenovo -> ) C:\Windows\System32\DriverStore\FileRepository\FNAD1C~1.INF\driver\shtctky.exe
(DriverStore\FileRepository\fn.inf_amd64_28255300d21d060b\driver\tphkload.exe ->) (Lenovo -> ) C:\Windows\System32\DriverStore\FileRepository\FNAD1C~1.INF\driver\tposd.exe
(DriverStore\FileRepository\u0395871.inf_amd64_73c8ac0273e02088\B395725\atiesrxx.exe ->) (Advanced Micro Devices Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0395871.inf_amd64_73c8ac0273e02088\B395725\atieclxx.exe
(EPDService.exe ->) (ELAN MICROELECTRONICS CORPORATION -> ELAN Microelectronics Corp.) C:\Windows\System32\EPDCtrl.exe
(explorer.exe ->) (Bluebeam, Inc. -> Bluebeam, Inc.) C:\Program Files\Bluebeam Software\Bluebeam Revu\2017\Revu\BBPrint.exe
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <15>
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE <2>
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Office\root\Office16\OUTLOOK.EXE
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\OneDrive.exe
(explorer.exe ->) (SentinelOne Inc. -> Sentinel Labs, Inc.) C:\Program Files\SentinelOne\Sentinel Agent 23.3.3.264\SentinelUI.exe
(explorer.exe ->) (SonicWall Inc. -> ) C:\Program Files (x86)\SonicWall\SSL-VPN\NetExtender\NEIdle.exe
(explorer.exe ->) (SonicWall Inc. -> SonicWall) C:\Program Files (x86)\SonicWall\SSL-VPN\NetExtender\NEGui.exe
(Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe <13>
(Immense Networks LLC -> Immense Networks) C:\ProgramData\ImmyBot\Scripts\0383aa1d443645e69e76b06dd8887db7\Immybot.Agent.Ephemeral.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\MSTeams_24060.2623.2790.8046_x64__8wekyb3d8bbwe\ms-teams.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (Advanced Micro Devices Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0395871.inf_amd64_73c8ac0273e02088\B395725\atiesrxx.exe
(services.exe ->) (CyberQP (QuickPass Software Inc) -> ) C:\Program Files\Quickpass Software\Quickpass Server Agent\QuickpassService.exe
(services.exe ->) (CyberQP (QuickPass Software Inc) -> ) C:\Program Files\Quickpass Software\Quickpass Server Agent\ValidationService.exe
(services.exe ->) (Dolby Laboratories, Inc. -> Dolby Laboratories) C:\Windows\System32\DriverStore\FileRepository\dax3_swc_aposvc.inf_amd64_cfeb891cbda10dc3\DAX3API.exe
(services.exe ->) (ELAN MICROELECTRONICS CORPORATION -> ELAN Microelectronics Corp.) C:\Windows\System32\EPDService.exe
(services.exe ->) (Immense Networks LLC -> Immense Networks) C:\Program Files (x86)\ImmyBot\Immybot.Agent.exe
(services.exe ->) (Lenovo -> Lenovo Group Limited) C:\Windows\System32\DriverStore\FileRepository\fn.inf_amd64_28255300d21d060b\driver\tphkload.exe
(services.exe ->) (Lenovo -> Lenovo Group Ltd.) C:\Windows\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe
(services.exe ->) (Lenovo -> Lenovo Group Ltd.) C:\Windows\System32\drivers\lenovo\UDC\Service\UDClientService.exe
(services.exe ->) (Lenovo -> Lenovo) C:\Program Files\Lenovo\Lenovo Smart Appearance Components\Components\IntelligentSensingAwareService\LsaRpcServer.exe
(services.exe ->) (Lenovo -> Lenovo) C:\Program Files\Lenovo\Lenovo Smart Appearance Components\Components\SmartAppearanceAIService\SmartAppearanceSVC.exe
(services.exe ->) (Lenovo -> Lenovo) C:\Windows\System32\DriverStore\FileRepository\ibmpmdrv.inf_amd64_02d728b29c6492d3\x64\ibmpmsvc.exe
(services.exe ->) (Lenovo -> Lenovo) C:\Windows\System32\DriverStore\FileRepository\smartstandbycomponent.inf_amd64_1a7a38fb4d407c19\SmartStandby.exe
(services.exe ->) (Lenovo -> Lenovo.) C:\Windows\System32\LITSSvc.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Program Files\Microsoft Update Health Tools\uhssvc.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.) C:\Windows\System32\amdfendrsr.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Fortemedia) C:\Windows\System32\FMService64.exe
(services.exe ->) (N-ABLE TECHNOLOGIES LTD -> N-able Take Control) C:\Program Files (x86)\BeAnywhere Support Express\GetSupportService_N-Central\BASupSrvc.exe
(services.exe ->) (N-ABLE TECHNOLOGIES LTD -> N-able Take Control) C:\Program Files (x86)\BeAnywhere Support Express\GetSupportService_N-Central\BASupSrvcUpdater.exe
(services.exe ->) (N-ABLE TECHNOLOGIES LTD -> N-able Technologies Inc.) C:\Program Files (x86)\N-able Technologies\Windows Agent\bin\agent.exe
(services.exe ->) (N-ABLE TECHNOLOGIES LTD -> N-able Technologies Inc.) C:\Program Files (x86)\N-able Technologies\Windows Agent\bin\AgentMaint.exe
(services.exe ->) (N-ABLE TECHNOLOGIES LTD -> N-able) C:\Program Files (x86)\MspPlatform\FileCacheServiceAgent\FileCacheServiceAgent.exe
(services.exe ->) (N-ABLE TECHNOLOGIES LTD -> N-able) C:\Program Files (x86)\MspPlatform\PME\PME.Agent.exe
(services.exe ->) (N-ABLE TECHNOLOGIES LTD -> N-able) C:\Program Files (x86)\MspPlatform\RequestHandlerAgent\RequestHandlerAgent.exe
(services.exe ->) (N-ABLE TECHNOLOGIES LTD -> N-able) C:\Program Files (x86)\N-able Technologies\AutomationManagerAgent\AutomationManager.AgentService.exe
(services.exe ->) (N-ABLE TECHNOLOGIES LTD -> N-able) C:\Program Files (x86)\N-able Technologies\Ecosystem Agent\Nable.Ecosystem.WindowsAgent.exe
(services.exe ->) (N-ABLE TECHNOLOGIES LTD -> N-able) C:\Program Files (x86)\N-able Technologies\Ecosystem Agent\Nable.Ecosystem.WindowsAgentMaint.exe
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor Corp.) C:\Windows\RtkBtManServ.exe
(services.exe ->) (Senary Technology Limited -> Senary Technology Limited) C:\Windows\System32\DriverStore\FileRepository\audioservice.inf_amd64_f1eeaf43bdc43415\SenaryAudioApp.Svc.exe
(services.exe ->) (SentinelOne Inc. -> Sentinel Labs, Inc.) C:\Program Files\SentinelOne\Sentinel Agent 23.3.3.264\SentinelHelperService.exe
(services.exe ->) (SentinelOne Inc. -> Sentinel Labs, Inc.) C:\Program Files\SentinelOne\Sentinel Agent 23.3.3.264\SentinelServiceHost.exe
(services.exe ->) (SentinelOne Inc. -> Sentinel Labs, Inc.) C:\Program Files\SentinelOne\Sentinel Agent 23.3.3.264\SentinelStaticEngine.exe
(services.exe ->) (Sentinelone, Inc. -> Sentinel Labs, Inc.) C:\Program Files\SentinelOne\Sentinel Agent 23.3.3.264\SentinelAgent.exe
(services.exe ->) (Shenzhen Goodix Technology Co., Ltd. -> Goodix) C:\Windows\System32\drivers\SessionService.exe
(services.exe ->) (SonicWall Inc. -> SonicWall Inc.) C:\Program Files (x86)\SonicWall\SSL-VPN\NetExtender\NEService.exe
(services.exe ->) (SonicWall Inc. -> SonicWall) C:\Program Files\SonicWall\Client Protection Service\SonicWallClientProtectionService.exe
(services.exe ->) (Xerox Corporation -> Xerox Corporation) C:\Program Files\Xerox\XeroxPrintExperience\CommonFiles\XeroxPrintJobEventManagerService.exe
(sihost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.GamingApp_2403.1001.3.0_x64__8wekyb3d8bbwe\XboxPcAppFT.exe
(svchost.exe ->) (Lenovo -> Lenovo) C:\Windows\SysWOW64\Lenovo\PowerMgr\PowerMgr.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\24.062.0326.0002\FileCoAuth.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_11.2401.0.0_x64__8wekyb3d8bbwe\CalculatorApp.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_424.1301.450.0_x64__cw5n1h2txyewy\Dashboard\WidgetService.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <3>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\Windows.Media.BackgroundPlayback.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [BbInstallUser] => C:\Program Files\Bluebeam Software\Bluebeam Revu\2017\Pushbutton PDF\Bluebeam Admin User.exe [50736 2017-12-12] (Bluebeam, Inc. -> Bluebeam, Inc.)
HKLM\...\Run: [BbPrintMonitor] => C:\Program Files\Bluebeam Software\Bluebeam Revu\2017\Revu\BBPrint.exe [868912 2017-12-12] (Bluebeam, Inc. -> Bluebeam, Inc.)
HKLM\...\Run: [SonicWallNetExtender] => C:\Program Files (x86)\SonicWall\SSL-VPN\NetExtender\NEGui.exe [3766176 2023-09-22] (SonicWall Inc. -> SonicWall)
HKLM\...\Run: [SonicWallNEIdle] => C:\Program Files (x86)\SonicWall\SSL-VPN\NetExtender\NEIdle.exe [120744 2023-09-22] (SonicWall Inc. -> )
HKLM\...\Run: [Sentinel Agent] => C:\Program Files\SentinelOne\Sentinel Agent 23.3.3.264\SentinelUI.exe [3349792 2023-12-22] (SentinelOne Inc. -> Sentinel Labs, Inc.)
HKLM-x32\...\Run: [BASupSrvcCnfg_N-Central] => C:\Program Files (x86)\BeAnywhere Support Express\GetSupportService_N-Central\BASupSrvcCnfg.exe [8306616 2024-03-05] (N-ABLE TECHNOLOGIES LTD -> N-able Take Control)
HKLM-x32\...\Run: [TeamsMachineInstaller] => C:\Program Files (x86)\Teams Installer\Teams.exe [143380856 2023-10-26] (Microsoft Corporation -> Microsoft Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [750680 2023-12-19] (Oracle America, Inc. -> Oracle Corporation)
HKLM\...\RunOnce: [Delete Cached Update Binary] => C:\Windows\system32\cmd.exe /q /c del /q "C:\Program Files\Microsoft OneDrive\Update\OneDriveSetup.exe" (No File)
HKLM\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\Windows\system32\cmd.exe /q /c del /q "C:\Program Files\Microsoft OneDrive\StandaloneUpdater\OneDriveSetup.exe" (No File)
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall: Restriction <==== ATTENTION
HKU\S-1-5-21-1102328504-126867679-1360648775-1001\...\Run: [MicrosoftEdgeAutoLaunch_29EBC4579851B72EE312C449CF839B1A] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5 [4063800 2024-04-12] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-1102328504-126867679-1360648775-1001\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [3306400 2024-04-13] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-1102328504-126867679-1360648775-1001\...\Run: [com.squirrel.Teams.Teams] => C:\Users\admin\AppData\Local\Microsoft\Teams\Update.exe [2589872 2023-11-23] (Microsoft 3rd Party Application Component -> Microsoft Corporation)
HKU\S-1-5-21-1102328504-126867679-1360648775-500\...\Run: [MicrosoftEdgeAutoLaunch_98769996E24836F99EC8617644423B4C] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5 [4063800 2024-04-12] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-1102328504-126867679-1360648775-500\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [3306400 2024-04-13] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-1102328504-126867679-1360648775-500\...\Run: [com.squirrel.Teams.Teams] => C:\Users\Administrator\AppData\Local\Microsoft\Teams\Update.exe [2589872 2023-11-21] (Microsoft 3rd Party Application Component -> Microsoft Corporation)
HKU\S-1-5-21-2814321435-3934866655-2077815162-4663\...\Run: [MicrosoftEdgeAutoLaunch_F6428EB7911EFEC2BA6068B62A8B7176] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4063800 2024-04-12] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2814321435-3934866655-2077815162-4663\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [3306400 2024-04-13] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2814321435-3934866655-2077815162-4663\...\Run: [com.squirrel.Teams.Teams] => C:\Users\USERNAME\AppData\Local\Microsoft\Teams\Update.exe [2589872 2023-11-23] (Microsoft 3rd Party Application Component -> Microsoft Corporation)
HKU\S-1-5-21-2814321435-3934866655-2077815162-4663\Control Panel\Desktop\\SCRNSAVE.EXE ->
HKLM\...\Print\Monitors\Bluebeam PDF Monitor: C:\Windows\system32\BBPdfPortMon.DLL [491056 2017-12-12] (Bluebeam, Inc. -> Bluebeam, Inc.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\123.0.6312.123\Installer\chrmstp.exe [2024-04-11] (Google LLC -> Google LLC)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{A6EADE66-0000-0000-484E-7E8A45000000}] -> "C:\Windows\SysWOW64\Rundll32.exe" "C:\Program Files (x86)\Adobe\Acrobat Reader DC\Esl\AiodLite.dll",CreateReaderUserSettings
HKLM\Software\...\Authentication\Credential Providers: [{003554A0-2314-4E7D-9745-89C0A681166E}] -> C:\Windows\system32\MSPACredentialProvider_7.50.06.202403051641_N-Central.dll [2024-03-05] (N-ABLE TECHNOLOGIES LTD -> N-able Take Control)
HKLM\Software\...\Authentication\PLAP Providers: [{9F4A2197-23EF-4815-8C4C-6C75A208823B}] -> C:\Program Files (x86)\SonicWall\SSL-VPN\NetExtender\NxCredentialProvider.dll [2023-09-22] (SonicWall Inc. -> )
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
"C:\Windows\System32\Tasks\Microsoft\Windows\GroupPolicy\{A7719E0F-10DB-4640-AD8C-490CC6AD5202}" was unlocked. <==== ATTENTION
"C:\Windows\System32\Tasks\Microsoft\Windows\GroupPolicy\{3E0A038B-D834-4930-9981-E89C9BFF83AA}" was unlocked. <==== ATTENTION
Task: {27176220-E325-4D0B-9354-718291FAC6AB} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1547208 2024-01-31] (Adobe Inc. -> Adobe Inc.)
Task: {2D60CF26-FC98-4385-A35C-F5BBD07BA008} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem125.0.6407.0{58501246-18E4-4872-9EDD-86FDF8DA2EBC} => C:\Program Files (x86)\Google\GoogleUpdater\125.0.6407.0\updater.exe [4782880 2024-04-08] (Google LLC -> Google LLC)
Task: {41F441F6-9E7E-41C1-9779-631974FDC3B6} - System32\Tasks\Lenovo\ImController\Lenovo iM Controller Monitor => C:\Windows\system32\ImController.InfInstaller.exe [74952 2022-11-20] (Lenovo -> Lenovo Group Ltd.)
Task: {DAD5630A-21D3-4539-AE17-24C241BE52A1} - System32\Tasks\Lenovo\ImController\Lenovo iM Controller Scheduled Maintenance => C:\Windows\system32\sc.exe [98304 2022-05-06] (Microsoft Windows -> Microsoft Corporation) -> START ImControllerService
Task: {16780F59-8503-4229-82BE-80DD75D3380A} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\b1c2dfc3-d1f5-477b-a8f1-ead4925ae9bc => C:\Windows\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [93896 2022-11-20] (Lenovo -> Lenovo Group Ltd.)
Task: {8A94D09C-D726-4695-8BD5-4E070B184EE8} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\c6de7f25-b259-4802-8faf-3fc65cafed0d => C:\Windows\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [93896 2022-11-20] (Lenovo -> Lenovo Group Ltd.)
Task: {107E5BE7-BDB3-4364-A23C-F7CC975914FE} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\e20ebcaa-fe0d-4f8d-8b39-55cd06ea834c => C:\Windows\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [93896 2022-11-20] (Lenovo -> Lenovo Group Ltd.)
Task: {EA394E62-779A-4ABD-8A70-E621A89E3476} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\ec00c61f-bf16-48b9-9a52-20ec81fc89d9 => C:\Windows\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [93896 2022-11-20] (Lenovo -> Lenovo Group Ltd.)
Task: {DF7A3066-C9F2-4267-B796-44F8D041EE6F} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\ed2fc224-d262-4300-989c-f9094d5caa88 => C:\Windows\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [93896 2022-11-20] (Lenovo -> Lenovo Group Ltd.)
Task: {A394DDFF-970B-4D42-BA10-100360CC9A20} - System32\Tasks\Lenovo\LenovoNowLauncher => C:\Program Files (x86)\Lenovo\LenovoNow\x86\LenovoNow.exe [1616808 2023-09-19] (Lenovo -> Lenovo) -> C:\Program Files (x86)\Lenovo\LenovoNow\x86\/task
Task: {9F7E6515-A2BF-4096-B1ED-641A19D3A020} - System32\Tasks\Lenovo\LenovoNowQuarterlyLaunch => C:\Program Files (x86)\Lenovo\LenovoNow\x86\LenovoNow.Task.exe [1548200 2023-09-19] (Lenovo -> Lenovo) -> C:\Program Files (x86)\Lenovo\LenovoNow\x86\/QuarterlyLaunch
Task: {2554E49B-6BEC-483B-95F8-E294049FA06F} - System32\Tasks\Lenovo\LenovoNowTask => C:\Program Files (x86)\Lenovo\LenovoNow\x86\LenovoNow.Task.exe [1548200 2023-09-19] (Lenovo -> Lenovo) -> C:\Program Files (x86)\Lenovo\LenovoNow\x86\$(EventData)
Task: {D6F04303-D467-46B5-BC53-983F754A8D21} - System32\Tasks\Lenovo\Power Manager\Background monitor => C:\Windows\SysWOW64\Lenovo\PowerMgr\PowerMgr.exe [129016 2022-12-04] (Lenovo -> Lenovo)
Task: {C33A096D-A76F-4F36-85B1-09714BEA3626} - System32\Tasks\Lenovo\Power Manager\Uninstall task => C:\Windows\SysWOW64\PowerMgrInst.exe [65016 2022-12-04] (Lenovo -> )
Task: {E2290B1B-BFEF-4D1D-BC5C-78025B6CAFEA} - System32\Tasks\Lenovo\SmartStandby\Daily analysis => C:\Windows\System32\DriverStore\FileRepository\smartstandbycomponent.inf_amd64_1a7a38fb4d407c19\AutonomicMgr.exe [74232 2023-02-02] (Lenovo -> )
Task: {45B19B38-B34C-4226-B232-8DCB0B70BA08} - System32\Tasks\Lenovo\SmartStandby\Uninstall Monitor => C:\Windows\system32\SmartStandbyInst.exe [43512 2023-02-02] (Lenovo -> )
Task: {A594CE64-83CE-4E0E-A5A4-9E1C8D6D2F04} - System32\Tasks\Lenovo\UDC\Lenovo UDC Diagnostic Scan => C:\Windows\system32\sc.exe [98304 2022-05-06] (Microsoft Windows -> Microsoft Corporation) -> control udcservice 210
Task: {BB6BAA63-1172-4AB8-AC8F-23C14318D01B} - System32\Tasks\Lenovo\UDC\Lenovo UDC Monitor => C:\Windows\system32\drivers\lenovo\udc\data\InfBackup\UdcInfInstaller.exe [185312 2023-11-02] (Lenovo -> Lenovo Group Ltd.)
Task: {475CB33D-919E-486A-BE9A-A528842F26E3} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28452944 2024-04-06] (Microsoft Corporation -> Microsoft Corporation)
Task: {01E57CE4-265F-4D61-9444-C126CC6C7E76} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28452944 2024-04-06] (Microsoft Corporation -> Microsoft Corporation)
Task: {72ED3523-3591-4CD7-B87D-B26CC4629166} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [309944 2024-04-09] (Microsoft Corporation -> Microsoft Corporation)
Task: {161E547C-8A27-4865-A17E-851F25E67D91} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [309944 2024-04-09] (Microsoft Corporation -> Microsoft Corporation)
Task: {C11EA7FF-28A0-47B2-B4B4-AF2F3170F05C} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\operfmon.exe [168488 2024-04-09] (Microsoft Corporation -> Microsoft Corporation)
Task: {D36AC155-4BB5-4CC0-9088-144C142B0869} - System32\Tasks\Microsoft\Windows\GroupPolicy\{3E0A038B-D834-4930-9981-E89C9BFF83AA} => C:\Windows\system32\gpupdate.exe [53248 2024-03-19] (Microsoft Windows -> Microsoft Corporation)
Task: {C04ACB94-5EC5-4C06-9CCE-29A1CED58D59} - System32\Tasks\Microsoft\Windows\GroupPolicy\{A7719E0F-10DB-4640-AD8C-490CC6AD5202} => C:\Windows\system32\gpupdate.exe [53248 2024-03-19] (Microsoft Windows -> Microsoft Corporation)
Task: {E0F10DCF-44AD-40E8-9370-FB5DA59F93FB} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
Task: {75D6CF42-A68B-4684-A012-7045A2E81CC0} - System32\Tasks\OneDrive Per-Machine Standalone Update Task => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4206512 2024-04-13] (Microsoft Corporation -> Microsoft Corporation)
Task: {C0C38CC4-8362-467F-B519-ADD49DD62230} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-1102328504-126867679-1360648775-1000 => C:\Program Files (x86)\Microsoft OneDrive\OneDriveStandaloneUpdater.exe /reporting (No File)
Task: {338C0904-0195-4765-914E-5588BE906FFB} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-1102328504-126867679-1360648775-1001 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4206512 2024-04-13] (Microsoft Corporation -> Microsoft Corporation)
Task: {9D6CFFF6-5341-401B-B93F-27398EDF01AF} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-1102328504-126867679-1360648775-500 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4206512 2024-04-13] (Microsoft Corporation -> Microsoft Corporation)
Task: {E54B08A7-03F9-4C5A-90B5-620F03A615AC} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-2814321435-3934866655-2077815162-4206 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4206512 2024-04-13] (Microsoft Corporation -> Microsoft Corporation)
Task: {160DB8E1-F9DF-4A99-9345-FC218933F613} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-2814321435-3934866655-2077815162-4663 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4206512 2024-04-13] (Microsoft Corporation -> Microsoft Corporation)
Task: {4BEC9F1A-00BF-4F82-BC6A-63FC15768099} - System32\Tasks\Quickpass Updater => C:\Program Files\Quickpass Software\Quickpass Server Agent\AgentUpdater.exe [27352 2024-04-02] (CyberQP (QuickPass Software Inc) -> )
Task: {B9411A8E-30DE-49DC-871A-3D35E4A8B53A} - System32\Tasks\Sentinel\AutoRepair_23.3.3.264 => C:\Program Files\SentinelOne\Sentinel Agent 23.3.3.264\uninstall.exe [2011976 2023-12-22] (SentinelOne Inc. -> Sentinel Labs, Inc.)
Task: {5C4C3D21-884C-468A-8C4E-535716EFCD72} - System32\Tasks\Xerox XeroxPrintExperience Printer Configuration - New or Changed => c:\program files\Xerox\xeroxprintexperience\xeroxprintexperience\XeroxPrinterConfiguration.exe [414152 2023-04-06] (Xerox Corporation -> Xerox Corporation)
Task: {25D3DB68-9CD1-4AE1-9597-B8B16AA8F0A2} - System32\Tasks\Xerox XeroxPrintExperience Printer Configuration - Periodic Refresh => c:\program files\Xerox\xeroxprintexperience\xeroxprintexperience\XeroxPrinterConfiguration.exe [414152 2023-04-06] (Xerox Corporation -> Xerox Corporation)
Task: {F9B9A6BF-7932-474B-8D32-338AF1CCEDEB} - System32\Tasks\Xerox XeroxPrintExperience Printer Configuration - User Logon => c:\program files\Xerox\xeroxprintexperience\xeroxprintexperience\XeroxPrinterConfiguration.exe [414152 2023-04-06] (Xerox Corporation -> Xerox Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.11.1 89.208.105.113
Tcpip\..\Interfaces\{1218d491-6105-4ff1-9d87-be43fe333829}: [DhcpNameServer] 192.168.11.1 10.10.10.1
Tcpip\..\Interfaces\{39907580-d9bb-48d5-87fe-6937512fb7b6}: [DhcpNameServer] 192.168.11.1 89.208.105.113
Tcpip\..\Interfaces\{3f8bf92b-1229-4ac6-9c96-1eb8fa3b9644}: [DhcpNameServer] 192.168.11.1 10.10.10.1
Tcpip\..\Interfaces\{3f8bf92b-1229-4ac6-9c96-1eb8fa3b9644}\458454024455E47454F4E40224554502249474745425: [DhcpNameServer] 64.59.184.13 64.59.190.242
Tcpip\..\Interfaces\{3f8bf92b-1229-4ac6-9c96-1eb8fa3b9644}\458454024455E47454F4E40224554502249474745425: [DhcpDomain] ed.shawcable.net
Edge:
=======
Edge Profile: C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default [2023-11-23]
Edge Extension: (Google Docs Offline) - C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-11-23]
Edge Extension: (Edge relevant text changes) - C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2023-11-23]
FireFox:
========
FF Plugin: @java.com/DTPlugin,version=11.401.2 -> C:\Program Files\Java\jre-1.8\bin\dtplugin\npDeployJava1.dll [2023-12-19] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.401.2 -> C:\Program Files\Java\jre-1.8\bin\plugin2\npjp2.dll [2023-12-19] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2024-04-09] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2024-04-09] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2024-03-30] (Adobe Inc. -> Adobe Systems Inc.)
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [172992 2024-01-31] (Adobe Inc. -> Adobe Inc.)
R2 AutomationManagerAgent; C:\Program Files (x86)\N-able Technologies\AutomationManagerAgent\AutomationManager.AgentService.exe [30488 2024-01-26] (N-ABLE TECHNOLOGIES LTD -> N-able)
R2 BASupportExpressSrvcUpdater_N_Central; C:\Program Files (x86)\BeAnywhere Support Express\GetSupportService_N-Central\BASupSrvcUpdater.exe [1252280 2024-03-05] (N-ABLE TECHNOLOGIES LTD -> N-able Take Control)
R2 BASupportExpressStandaloneService_N_Central; C:\Program Files (x86)\BeAnywhere Support Express\GetSupportService_N-Central\BASupSrvc.exe [5653944 2024-03-05] (N-ABLE TECHNOLOGIES LTD -> N-able Take Control)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [14221280 2024-04-06] (Microsoft Corporation -> Microsoft Corporation)
R2 DolbyDAXAPI; C:\Windows\System32\DriverStore\FileRepository\dax3_swc_aposvc.inf_amd64_cfeb891cbda10dc3\DAX3API.exe [2360336 2023-01-17] (Dolby Laboratories, Inc. -> Dolby Laboratories)
R2 EcosystemAgent; C:\Program Files (x86)\N-able Technologies\Ecosystem Agent\Nable.Ecosystem.WindowsAgent.exe [127504 2024-03-04] (N-ABLE TECHNOLOGIES LTD -> N-able)
R2 EcosystemAgentMaintenance; C:\Program Files (x86)\N-able Technologies\Ecosystem Agent\Nable.Ecosystem.WindowsAgentMaint.exe [124432 2024-03-04] (N-ABLE TECHNOLOGIES LTD -> N-able)
R2 EPDService; C:\Windows\System32\EPDService.exe [211568 2023-01-31] (ELAN MICROELECTRONICS CORPORATION -> ELAN Microelectronics Corp.)
S3 FileSyncHelper; C:\Program Files\Microsoft OneDrive\24.062.0326.0002\FileSyncHelper.exe [3512232 2024-04-13] (Microsoft Corporation -> Microsoft Corporation)
R2 FMAPOService; C:\Windows\System32\FMService64.exe [943032 2023-07-14] (Microsoft Windows Hardware Compatibility Publisher -> Fortemedia)
S2 GoogleUpdaterInternalService125.0.6407.0; C:\Program Files (x86)\Google\GoogleUpdater\125.0.6407.0\updater.exe [4782880 2024-04-08] (Google LLC -> Google LLC)
S2 GoogleUpdaterService125.0.6407.0; C:\Program Files (x86)\Google\GoogleUpdater\125.0.6407.0\updater.exe [4782880 2024-04-08] (Google LLC -> Google LLC)
R2 IBMPMSVC; C:\Windows\System32\DriverStore\FileRepository\ibmpmdrv.inf_amd64_02d728b29c6492d3\x64\ibmpmsvc.exe [850936 2022-11-23] (Lenovo -> Lenovo)
R2 ImControllerService; C:\Windows\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [93896 2022-11-20] (Lenovo -> Lenovo Group Ltd.)
R2 ImmyBot Agent; C:\Program Files (x86)\ImmyBot\Immybot.Agent.exe [53234856 2024-04-02] (Immense Networks LLC -> Immense Networks)
R2 Lenovo Smart Appearance Intelligent Sensing Aware Service; C:\Program Files\Lenovo\Lenovo Smart Appearance Components\Components\IntelligentSensingAwareService\LsaRpcServer.exe [160032 2023-02-09] (Lenovo -> Lenovo)
R2 LenovoSmartStandby; C:\Windows\System32\DriverStore\FileRepository\smartstandbycomponent.inf_amd64_1a7a38fb4d407c19\SmartStandby.exe [332792 2023-02-02] (Lenovo -> Lenovo)
R2 LITSSVC; C:\Windows\System32\LITSSvc.exe [1260488 2023-01-16] (Lenovo -> Lenovo.)
R2 LogProcessorService; C:\Program Files\SentinelOne\Sentinel Agent 23.3.3.264\SentinelServiceHost.exe [265784 2023-12-22] (SentinelOne Inc. -> Sentinel Labs, Inc.)
S2 LPlatSvc; C:\Windows\System32\DriverStore\FileRepository\ibmpmdrv.inf_amd64_02d728b29c6492d3\x64\LPlatSvc.exe [906232 2022-11-23] (Lenovo -> Lenovo)
S3 OneDrive Updater Service; C:\Program Files\Microsoft OneDrive\24.062.0326.0002\OneDriveUpdaterService.exe [3852200 2024-04-13] (Microsoft Corporation -> Microsoft Corporation)
R2 PME.Agent.PmeService; C:\Program Files (x86)\MspPlatform\PME\PME.Agent.exe [126816 2024-02-16] (N-ABLE TECHNOLOGIES LTD -> N-able)
R2 QuickpassServerAgent; C:\Program Files\Quickpass Software\Quickpass Server Agent\QuickpassService.exe [49368 2024-04-02] (CyberQP (QuickPass Software Inc) -> )
R2 QuickpassValidationService; C:\Program Files\Quickpass Software\Quickpass Server Agent\ValidationService.exe [21208 2024-04-02] (CyberQP (QuickPass Software Inc) -> )
R2 SenaryAudioApp.Svc; C:\Windows\System32\DriverStore\FileRepository\audioservice.inf_amd64_f1eeaf43bdc43415\SenaryAudioApp.Svc.exe [88024 2023-07-23] (Senary Technology Limited -> Senary Technology Limited)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [522080 2024-04-13] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 SentinelAgent; C:\Program Files\SentinelOne\Sentinel Agent 23.3.3.264\SentinelAgent.exe [290832 2023-12-22] (Sentinelone, Inc. -> Sentinel Labs, Inc.)
R3 SentinelHelperService; C:\Program Files\SentinelOne\Sentinel Agent 23.3.3.264\SentinelHelperService.exe [358192 2023-12-22] (SentinelOne Inc. -> Sentinel Labs, Inc.)
R2 SentinelStaticEngine; C:\Program Files\SentinelOne\Sentinel Agent 23.3.3.264\SentinelStaticEngine.exe [267320 2023-12-22] (SentinelOne Inc. -> Sentinel Labs, Inc.)
R2 SmartAppearanceAISVC; C:\Program Files\Lenovo\Lenovo Smart Appearance Components\Components\SmartAppearanceAIService\SmartAppearanceSVC.exe [83744 2023-02-09] (Lenovo -> Lenovo)
R2 SolarWinds.MSP.CacheService; C:\Program Files (x86)\MspPlatform\FileCacheServiceAgent\FileCacheServiceAgent.exe [270176 2024-02-16] (N-ABLE TECHNOLOGIES LTD -> N-able)
R2 SolarWinds.MSP.RpcServerService; C:\Program Files (x86)\MspPlatform\RequestHandlerAgent\RequestHandlerAgent.exe [125280 2024-02-16] (N-ABLE TECHNOLOGIES LTD -> N-able)
R2 SonicWallClientProtectionService; C:\Program Files\SonicWall\Client Protection Service\SonicWallClientProtectionService.exe [1030936 2023-11-23] (SonicWall Inc. -> SonicWall)
R2 SONICWALL_NetExtender; C:\Program Files (x86)\SonicWall\SSL-VPN\NetExtender\NEService.exe [965032 2023-09-22] (SonicWall Inc. -> SonicWall Inc.)
R2 TPHKLOAD; C:\Windows\System32\DriverStore\FileRepository\fn.inf_amd64_28255300d21d060b\driver\TPHKLOAD.exe [507760 2023-08-23] (Lenovo -> Lenovo Group Limited)
R2 UDCService; C:\Windows\System32\drivers\Lenovo\udc\Service\UDClientService.exe [72160 2023-11-02] (Lenovo -> Lenovo Group Ltd.)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23100.2009-0\NisSrv.exe [3121120 2023-11-20] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23100.2009-0\MsMpEng.exe [133704 2023-11-20] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 Windows Agent Maintenance Service; C:\Program Files (x86)\N-able Technologies\Windows Agent\bin\AgentMaint.exe [176408 2024-03-09] (N-ABLE TECHNOLOGIES LTD -> N-able Technologies Inc.)
R2 Windows Agent Service; C:\Program Files (x86)\N-able Technologies\Windows Agent\bin\agent.exe [333592 2024-03-09] (N-ABLE TECHNOLOGIES LTD -> N-able Technologies Inc.)
R2 XeroxPrintJobEventManagerService; C:\Program Files\Xerox\XeroxPrintExperience\CommonFiles\XeroxPrintJobEventManagerService.exe [522696 2023-04-06] (Xerox Corporation -> Xerox Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 AMDAfdAudioService; C:\Windows\System32\DriverStore\FileRepository\amdacpafd.inf_amd64_93221359f0901248\amdacpafd.sys [435608 2023-10-11] (Advanced Micro Devices Inc. -> Advanced Micro Devices)
R3 amdfendrmgr; C:\Windows\System32\drivers\amdfendrmgr.sys [25584 2023-10-11] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.)
R3 amdwddmg; C:\Windows\System32\DriverStore\FileRepository\u0395871.inf_amd64_73c8ac0273e02088\B395725\amdkmdag.sys [99747448 2023-10-11] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
S3 BTHMODEM; C:\Windows\System32\drivers\bthmodem.sys [106496 2023-06-25] (Microsoft Corporation) [File not signed]
R3 CnxtHdAudService; C:\Windows\System32\DriverStore\FileRepository\cisstrtu-base.inf_amd64_67966f096e60b8c4\CHDRT64ISST.sys [2673584 2023-07-23] (Senary Technology Limited -> Senary Technology Limited.)
R3 dlcdcncm; C:\Windows\System32\drivers\dlcdcncm660.sys [143560 2022-06-29] (DISPLAYLINK (UK) LIMITED -> DisplayLink Corp.)
R3 EPD; C:\Windows\System32\drivers\EPD.sys [162416 2023-01-31] (ELAN MICROELECTRONICS CORPORATION -> ELAN Microelectronics Corp.)
R0 fse; C:\Windows\System32\drivers\fse.sys [218592 2023-11-20] (Microsoft Windows -> Microsoft Corporation)
R3 IBMPMDRV; C:\Windows\System32\DriverStore\FileRepository\ibmpmdrv.inf_amd64_02d728b29c6492d3\x64\ibmpmdrv.sys [53240 2022-11-23] (Lenovo -> Lenovo)
R1 PMDRVS; C:\Windows\System32\DriverStore\FileRepository\ibmpmdrv.inf_amd64_02d728b29c6492d3\x64\pmdrvs.sys [38904 2022-11-23] (Lenovo -> Lenovo)
S0 SentinelDeviceControl; C:\Windows\System32\DRIVERS\SentinelOne\23.3.3.264\SentinelDeviceControl.sys [528552 2023-12-22] (Microsoft Windows Hardware Compatibility Publisher -> Sentinel Labs, Inc.)
S0 SentinelELAM; C:\Windows\System32\DRIVERS\SentinelOne\ELAM\SentinelELAM.sys [16880 2023-12-22] (Microsoft Windows Early Launch Anti-malware Publisher -> SentinelOne, Inc.)
R1 SentinelMonitor; C:\Windows\System32\DRIVERS\SentinelOne\23.3.3.264\SentinelMonitor.sys [1566272 2023-12-22] (Microsoft Windows Hardware Compatibility Publisher -> Sentinel Labs, Inc.)
R1 SFPMonitor; C:\Windows\System32\DRIVERS\sfpmonitor.sys [57040 2023-11-23] (SonicWall Inc. -> SonicWall Inc.)
S3 vmbusproxy; C:\Windows\system32\drivers\vmbusproxy.sys [94208 2023-11-20] (Microsoft Windows -> )
S3 WdBoot; C:\Windows\system32\drivers\wd\WdBoot.sys [55744 2023-11-20] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\wd\WdFilter.sys [578856 2023-11-20] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [105768 2023-11-20] (Microsoft Windows -> Microsoft Corporation)
S3 wintun; C:\Windows\system32\DRIVERS\wintun.sys [38704 2023-11-23] (WireGuard LLC -> WireGuard LLC)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2024-04-15 10:04 - 2024-04-15 10:04 - 000000000 ____D C:\FRST
2024-04-14 02:04 - 2024-04-14 02:04 - 000001229 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SentinelOne Agent.lnk
2024-04-14 02:04 - 2024-04-14 02:04 - 000000000 ____D C:\Program Files\Common Files\DESIGNER
2024-04-14 02:01 - 2024-04-14 02:01 - 000000000 ____D C:\Windows\SysWOW64\DDFs
2024-04-13 15:51 - 2024-04-13 15:51 - 000024320 _____ C:\Windows\SysWOW64\IntegratedServicesRegionPolicySet.json
2024-04-13 15:50 - 2024-04-13 15:50 - 000024320 _____ C:\Windows\system32\IntegratedServicesRegionPolicySet.json
2024-04-13 14:51 - 2024-04-13 14:51 - 000000000 ___HD C:\OneDriveTemp
2024-04-10 13:54 - 2024-04-10 13:54 - 006834150 _____ C:\Users\USERNAME\Downloads\SSPC-PA-Guide-13 - 2006.pdf
2024-04-04 09:45 - 2024-04-04 09:45 - 000130444 _____ C:\Users\USERNAME\Downloads\CRA Business Number-new1.pdf
2024-04-02 17:25 - 2024-04-02 17:25 - 000313560 _____ (CyberQP) C:\Windows\system32\CyberQPCredentialProvider.dll
2024-03-22 11:13 - 2024-03-22 11:13 - 000286635 _____ C:\Users\USERNAME\Downloads\Reactamine_760_PDS.pdf
2024-03-21 09:00 - 2024-03-21 09:00 - 000036479 _____ C:\Users\USERNAME\Downloads\eBay-ListingsSalesReport-Mar-21-2024-08_00_42-0700-11151543999.csv
2024-03-19 11:26 - 2024-03-19 11:26 - 000091085 _____ C:\Users\USERNAME\Downloads\Secure Space Information Sheet.pdf
2024-03-19 11:22 - 2024-03-19 11:22 - 000157368 _____ C:\Users\USERNAME\Downloads\Personal Care Preferences, F145 (Dec 21, 2023).pdf
2024-03-19 11:16 - 2024-03-19 11:16 - 000265357 _____ C:\Users\USERNAME\Downloads\Resident Trust Account, F288 (Dec 21, 2023).pdf
2024-03-19 10:54 - 2024-03-19 10:54 - 000197297 _____ C:\Users\USERNAME\Downloads\Post-Acute Admission Agreement (ALC), F434 (Dec 21, 2023) (1).pdf
2024-03-19 08:32 - 2024-03-19 08:32 - 000435125 _____ C:\Users\USERNAME\Downloads\235 PDS.pdf
2024-03-19 08:32 - 2024-03-19 08:32 - 000196361 _____ C:\Users\USERNAME\Downloads\235 SDS.pdf
2024-03-19 08:30 - 2024-03-19 08:30 - 000131302 _____ C:\Users\USERNAME\Downloads\SSPC-PA1 - 2004-11-01.pdf
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2024-04-15 10:04 - 2023-11-23 14:02 - 000000000 ____D C:\ProgramData\Sentinel
2024-04-15 10:04 - 2022-05-06 23:24 - 000000000 ____D C:\Windows\SystemTemp
2024-04-15 10:04 - 2022-05-06 23:24 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2024-04-15 10:02 - 2023-11-20 14:41 - 000000000 ____D C:\Temp
2024-04-15 10:00 - 2023-11-23 12:38 - 000000000 ____D C:\Users\USERNAME\AppData\Local\Packages
2024-04-15 09:10 - 2022-05-06 23:24 - 000000000 ____D C:\Windows\AppReadiness
2024-04-15 09:09 - 2023-11-23 12:37 - 000000000 ____D C:\Users\USERNAME\AppData\Local\D3DSCache
2024-04-15 09:09 - 2022-05-06 23:24 - 000000000 ___HD C:\Program Files\WindowsApps
2024-04-15 09:07 - 2023-11-20 14:41 - 000000000 ____D C:\ProgramData\GetSupportService_N-Central
2024-04-15 08:00 - 2023-11-23 14:00 - 000020064 _____ C:\Windows\system32\batteryreport.xml
2024-04-15 07:54 - 2023-11-23 13:32 - 000000000 ____D C:\Users\USERNAME\AppData\Roaming\Microsoft\Excel
2024-04-15 07:24 - 2023-11-23 12:55 - 000000000 ____D C:\Users\USERNAME\AppData\Roaming\Microsoft\Word
2024-04-15 07:17 - 2023-11-23 13:08 - 000000000 ___RD C:\Users\USERNAME\OneDrive - Adler Insulation
2024-04-15 07:16 - 2023-11-23 12:40 - 000000000 ____D C:\Users\USERNAME\AppData\Roaming\Microsoft\Teams
2024-04-14 04:08 - 2022-05-25 13:06 - 000002445 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2024-04-14 04:08 - 2022-05-25 13:06 - 000002283 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2024-04-14 02:19 - 2022-05-06 23:24 - 000000000 ____D C:\ProgramData\USOPrivate
2024-04-14 02:11 - 2023-06-25 14:32 - 000806514 _____ C:\Windows\system32\PerfStringBackup.INI
2024-04-14 02:11 - 2022-05-06 23:22 - 000000000 ____D C:\Windows\INF
2024-04-14 02:06 - 2022-05-06 23:24 - 000000000 ____D C:\Windows\security
2024-04-14 02:04 - 2023-11-20 14:14 - 000000000 ____D C:\ProgramData\ImmyBotAgentService
2024-04-14 02:04 - 2023-06-25 14:31 - 000000000 ____D C:\ProgramData\Goodix
2024-04-14 02:04 - 2023-06-25 14:25 - 000000000 ____D C:\Program Files\Microsoft Office
2024-04-14 02:04 - 2023-06-25 14:21 - 000001623 _____ C:\Windows\system32\config\VSMIDK
2024-04-14 02:04 - 2022-05-25 13:05 - 000012288 ___SH C:\DumpStack.log.tmp
2024-04-14 02:04 - 2022-05-25 13:05 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2024-04-14 02:04 - 2022-05-06 23:24 - 000000000 ____D C:\Windows\ServiceState
2024-04-14 02:04 - 2022-05-06 23:24 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2024-04-14 02:03 - 2022-05-06 23:17 - 001048576 _____ C:\Windows\system32\config\BBI
2024-04-14 02:02 - 2023-11-20 15:14 - 000000000 ____D C:\Program Files\Microsoft OneDrive
2024-04-14 02:02 - 2022-05-25 13:05 - 001728488 _____ C:\Windows\system32\FNTCACHE.DAT
2024-04-14 02:01 - 2023-11-20 15:24 - 000000000 ____D C:\Windows\system32\Microsoft-Edge-WebView
2024-04-14 02:01 - 2023-06-25 15:12 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2024-04-14 02:01 - 2022-05-06 23:24 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2024-04-14 02:01 - 2022-05-06 23:24 - 000000000 ____D C:\Windows\SysWOW64\WinMetadata
2024-04-14 02:01 - 2022-05-06 23:24 - 000000000 ____D C:\Windows\SystemResources
2024-04-14 02:01 - 2022-05-06 23:24 - 000000000 ____D C:\Windows\system32\WinMetadata
2024-04-14 02:01 - 2022-05-06 23:24 - 000000000 ____D C:\Windows\system32\ShellExperiences
2024-04-14 02:01 - 2022-05-06 23:24 - 000000000 ____D C:\Windows\system32\Sgrm
2024-04-14 02:01 - 2022-05-06 23:24 - 000000000 ____D C:\Windows\system32\SecureBootUpdates
2024-04-14 02:01 - 2022-05-06 23:24 - 000000000 ____D C:\Windows\system32\oobe
2024-04-14 02:01 - 2022-05-06 23:24 - 000000000 ____D C:\Windows\system32\HealthAttestationClient
2024-04-14 02:01 - 2022-05-06 23:24 - 000000000 ____D C:\Windows\system32\DDFs
2024-04-14 02:01 - 2022-05-06 23:24 - 000000000 ____D C:\Windows\ShellComponents
2024-04-14 02:01 - 2022-05-06 23:24 - 000000000 ____D C:\Windows\Provisioning
2024-04-14 02:01 - 2022-05-06 23:24 - 000000000 ____D C:\Windows\PolicyDefinitions
2024-04-14 02:01 - 2022-05-06 23:24 - 000000000 ____D C:\Windows\bcastdvr
2024-04-14 00:31 - 2023-11-20 14:20 - 000000120 _____ C:\Windows\system32\config\netlogon.ftl
2024-04-13 15:53 - 2022-05-06 23:17 - 000000000 ____D C:\Windows\CbsTemp
2024-04-13 15:51 - 2022-05-25 13:08 - 003213824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2024-04-13 15:39 - 2023-11-20 15:12 - 000000000 ____D C:\Windows\system32\MRT
2024-04-13 15:38 - 2023-11-20 15:12 - 192651728 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2024-04-13 14:51 - 2023-12-12 08:49 - 000003588 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-1102328504-126867679-1360648775-500
2024-04-13 14:51 - 2023-11-23 12:40 - 000003596 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2814321435-3934866655-2077815162-4663
2024-04-13 14:51 - 2023-11-23 12:21 - 000003596 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2814321435-3934866655-2077815162-4206
2024-04-13 14:51 - 2023-11-23 12:04 - 000003592 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-1102328504-126867679-1360648775-1001
2024-04-13 14:51 - 2023-11-20 14:47 - 000003194 _____ C:\Windows\system32\Tasks\OneDrive Per-Machine Standalone Update Task
2024-04-13 14:51 - 2023-11-20 14:47 - 000002139 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2024-04-11 15:34 - 2023-11-30 16:33 - 000000000 ____D C:\Program Files (x86)\Google
2024-04-11 15:34 - 2023-11-20 14:40 - 000002254 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2024-04-11 15:34 - 2023-11-20 14:40 - 000002213 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2024-04-04 01:52 - 2023-11-20 14:51 - 000004470 _____ C:\Windows\system32\Tasks\Quickpass Updater
2024-04-04 01:52 - 2023-11-20 14:51 - 000000000 ____D C:\ProgramData\Package Cache
2024-04-03 15:35 - 2023-11-20 14:54 - 000004562 _____ C:\Windows\system32\Tasks\Adobe Acrobat Update Task
2024-04-03 15:35 - 2023-11-20 14:54 - 000002143 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader.lnk
2024-04-03 15:35 - 2023-11-20 14:54 - 000002131 _____ C:\Users\Public\Desktop\Acrobat Reader.lnk
2024-04-03 15:03 - 2022-05-25 13:06 - 000003536 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2024-04-03 15:03 - 2022-05-25 13:06 - 000003412 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2024-04-02 18:01 - 2023-12-17 22:02 - 000000000 ____D C:\Program Files (x86)\ImmyBot
2024-04-02 14:42 - 2023-11-23 17:07 - 000000000 ____D C:\Users\USERNAME\AppData\Local\CrashDumps
2024-03-28 10:35 - 2022-05-06 23:24 - 000000000 ____D C:\Windows\system32\SecurityHealth
2024-03-21 07:08 - 2022-05-25 13:06 - 000000000 ____D C:\ProgramData\Packages
2024-03-21 02:02 - 2022-05-06 23:24 - 000000000 ____D C:\Windows\SysWOW64\Dism
2024-03-21 02:02 - 2022-05-06 23:24 - 000000000 ____D C:\Windows\system32\appraiser
2024-03-21 02:02 - 2022-05-06 23:24 - 000000000 ____D C:\Windows\ShellExperiences
2024-03-21 02:02 - 2022-05-06 23:17 - 000000000 ____D C:\Windows\servicing
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 10.04.2024
Ran by admin (15-04-2024 10:05:27)
Running from C:\Temp\farbar
Microsoft Windows 11 Pro Version 23H2 22631.3447 (X64) (2023-11-21 11:14:53)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
(If an entry is included in the fixlist, it will be removed.)
admin (S-1-5-21-1102328504-126867679-1360648775-1001 - Administrator - Enabled) => C:\Users\admin
Administrator (S-1-5-21-1102328504-126867679-1360648775-500 - Administrator - Disabled) => C:\Users\Administrator
DefaultAccount (S-1-5-21-1102328504-126867679-1360648775-503 - Limited - Disabled)
Guest (S-1-5-21-1102328504-126867679-1360648775-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-1102328504-126867679-1360648775-504 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Sentinel Agent (Enabled - Up to date) {B81B202D-B515-3D48-B28C-10C266DF0ED7}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
7-Zip 23.01 (x64 edition) (HKLM\...\{23170F69-40C1-2702-2301-000001000000}) (Version: 23.01.00.0 - Igor Pavlov)
Adobe Acrobat Reader (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 24.001.20643 - Adobe Systems Incorporated)
Adobe Refresh Manager (HKLM-x32\...\{AC76BA86-0804-1033-1959-018244601067}) (Version: 1.8.0 - Adobe Systems Incorporated) Hidden
Bluebeam Revu x64 2017.0.40 (HKLM\...\{A9FF6312-66C3-4D99-AA3F-40611C2360FD}) (Version: 17.0.40 - Bluebeam, Inc.)
Ecosystem Agent (HKLM-x32\...\{00000000-2ABA-488A-A12C-F9626142D029}}) (Version: - SolarWinds MSP) Hidden
Ecosystem Agent (HKLM-x32\...\{3A399BFE-2ABA-488A-A12C-F9626142D029}_is1) (Version: 5.1.4.2473 - N-able Technologies)
File Cache Service Agent (HKLM-x32\...\{E28A41A6-5ED1-47C2-B151-548DABC4CD88}_is1) (Version: 2.10.4.5025 - N-able)
FileZilla 3.64.0 (HKLM-x32\...\FileZilla Client) (Version: 3.64.0 - Tim Kosse)
Google Chrome (HKLM\...\{B8C6D6E8-71ED-3FD7-95F9-0661330AA1EC}) (Version: 123.0.6312.123 - Google LLC)
ImmyBot Agent (HKLM-x32\...\{D5FC2BEF-37DA-48AE-80D8-42B02A429C34}) (Version: 0.62.8.30356 - Immense Networks)
Java 8 Update 401 (64-bit) (HKLM\...\{71024AE4-039E-4CA4-87B4-2F64180401F0}) (Version: 8.0.4010.10 - Oracle Corporation)
Lenovo Now (HKLM-x32\...\Lenovo Now) (Version: 3.11.0.15 - Lenovo Group Ltd.)
Lenovo Smart Appearance Components (HKLM-x32\...\{13E9CBF6-6E32-40D0-874A-018DFEFB0851}_is1) (Version: 2.3.22.0 - Lenovo)
Microsoft 365 Apps for business - en-us (HKLM\...\O365BusinessRetail - en-us) (Version: 16.0.17425.20176 - Microsoft Corporation)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 123.0.2420.97 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 123.0.2420.97 - Microsoft Corporation)
Microsoft OneDrive (HKLM\...\OneDriveSetup.exe) (Version: 24.062.0326.0002 - Microsoft Corporation)
Microsoft OneNote - en-us (HKLM\...\OneNoteFreeRetail - en-us) (Version: 16.0.17425.20176 - Microsoft Corporation)
Microsoft Teams classic (HKU\S-1-5-21-1102328504-126867679-1360648775-1001\...\Teams) (Version: 1.6.00.29964 - Microsoft Corporation)
Microsoft Teams classic (HKU\S-1-5-21-1102328504-126867679-1360648775-500\...\Teams) (Version: 1.6.00.29964 - Microsoft Corporation)
Microsoft Teams classic (HKU\S-1-5-21-2814321435-3934866655-2077815162-4663\...\Teams) (Version: 1.6.00.29964 - Microsoft Corporation)
Microsoft Teams Meeting Add-in for Microsoft Office (HKLM\...\{A7AB73A3-CB10-4AA5-9D38-6AEFFBDE4C91}) (Version: 1.24.05401 - Microsoft)
Microsoft Update Health Tools (HKLM\...\{C6FD611E-7EFE-488C-A0E0-974C09EF6473}) (Version: 5.72.0.0 - Microsoft Corporation)
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.17425.20146 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.17425.20176 - Microsoft Corporation) Hidden
Patch Management Service Controller (HKLM-x32\...\{1DE39C5D-B9EF-4412-BC4F-6BEF694E4DD5}_is1) (Version: 2.10.4.5454 - N-able)
PosiSoft Desktop (HKLM-x32\...\PosiSoft) (Version: 4.11 - DeFelsko)
Quickpass Agent (64-bit) (HKLM\...\{A3FCB12F-395B-411F-8111-D35D55E47380}) (Version: 4.0.2.3 - Quickpass Software)
Quickpass Agent (HKLM-x32\...\{62d8ac49-7969-488c-a59e-dfeb02e3ced1}) (Version: 4.0.2.3 - Quickpass Software)
Request Handler Agent (HKLM-x32\...\{08FD2DB0-B170-4CC4-B4B2-11F1102345CA}_is1) (Version: 2.10.4.5025 - N-able)
Sentinel Agent (HKLM\...\{4CE2629F-7EBF-4084-A629-571BC2FF21DF}) (Version: 23.3.264 - Sentinel Labs, Inc.)
SonicWall NetExtender (HKLM-x32\...\{4CE4DE1C-38CF-4313-9DF2-8B1E6B46E221}) (Version: 10.2.337 - SonicWall Inc.)
Teams Machine-Wide Installer (HKLM-x32\...\{731F6BAA-A986-45A4-8936-7C3AAAAA760B}) (Version: 1.6.0.29964 - Microsoft Corporation)
VLC media player (HKLM\...\{9675011C-2395-4AD7-B1CC-92910F991F58}) (Version: 3.0.20.0 - VideoLAN)
Windows Agent (HKLM-x32\...\{249B4EE3-C59F-4D2E-BB35-7285D3C50166}) (Version: 2024.1.1017 - N-able Technologies)
Xerox Desktop Print Experience 7.0 (HKLM\...\{DC38B6F0-DBA4-D3AB-BF0C-A7479ADD524D}) (Version: 8.73.10.0 - Xerox Corporation)
Packages:
=========
Microsoft.WindowsAppRuntime.CBS -> C:\Windows\SystemApps\Microsoft.WindowsAppRuntime.CBS_8wekyb3d8bbwe [2024-03-21] (Microsoft Corporation)
SenarySmartAudio -> C:\Program Files\WindowsApps\SenaryTechnologyLimited.SenarySmartAudio_2.42.0.0_x64__dqz7eftfn33jw [2023-11-23] (Senary Technology Limited)
Windows Feature Experience Pack -> C:\Windows\SystemApps\MicrosoftWindows.Client.FileExp_cw5n1h2txyewy [2024-03-21] (Microsoft Corporation)
==================== Custom CLSID (Whitelisted): ==============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-1102328504-126867679-1360648775-1001_Classes\CLSID\{19A6E644-14E6-4A60-B8D7-DD20610A871D}\InprocServer32 -> C:\Users\admin\AppData\Local\Microsoft\TeamsMeetingAddin\1.0.23270.2\x64\Microsoft.Teams.AddinLoader.dll (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1102328504-126867679-1360648775-1001_Classes\CLSID\{efd4e8f5-6e0e-9405-4ec4-9c673447cfee}\localserver32 -> C:\Program Files\Lenovo\Lenovo Smart Appearance Components\Components\IntelligentSensingAwareService\LsaToast.exe (Lenovo -> Lenovo)
CustomCLSID: HKU\S-1-5-21-2814321435-3934866655-2077815162-4663_Classes\CLSID\{04271989-C4D2-27B8-B510-A4FE88B74654} -> [OneDrive - COMPANY NAME] => C:\Users\USERNAME\OneDrive - COMPANY NAME [2023-11-23 13:08]
CustomCLSID: HKU\S-1-5-21-2814321435-3934866655-2077815162-4663_Classes\CLSID\{19A6E644-14E6-4A60-B8D7-DD20610A871D}\InprocServer32 -> C:\Users\USERNAME\AppData\Local\Microsoft\TeamsMeetingAdd-in\1.24.05401\x64\Microsoft.Teams.AddinLoader.dll (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2814321435-3934866655-2077815162-4663_Classes\CLSID\{d1b22d3d-8585-53a6-acb3-0e803c7e8d2a}\localserver32 -> C:\Users\USERNAME\AppData\Local\Microsoft\Teams\current\Teams.exe (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2814321435-3934866655-2077815162-4663_Classes\CLSID\{efd4e8f5-6e0e-9405-4ec4-9c673447cfee}\localserver32 -> C:\Program Files\Lenovo\Lenovo Smart Appearance Components\Components\IntelligentSensingAwareService\LsaToast.exe (Lenovo -> Lenovo)
ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files\Microsoft OneDrive\24.062.0326.0002\FileSyncShell64.dll [2024-04-13] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files\Microsoft OneDrive\24.062.0326.0002\FileSyncShell64.dll [2024-04-13] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files\Microsoft OneDrive\24.062.0326.0002\FileSyncShell64.dll [2024-04-13] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files\Microsoft OneDrive\24.062.0326.0002\FileSyncShell64.dll [2024-04-13] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files\Microsoft OneDrive\24.062.0326.0002\FileSyncShell64.dll [2024-04-13] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files\Microsoft OneDrive\24.062.0326.0002\FileSyncShell64.dll [2024-04-13] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files\Microsoft OneDrive\24.062.0326.0002\FileSyncShell64.dll [2024-04-13] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files\Microsoft OneDrive\24.062.0326.0002\FileSyncShell64.dll [2024-04-13] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files\Microsoft OneDrive\24.062.0326.0002\FileSyncShell64.dll [2024-04-13] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files\Microsoft OneDrive\24.062.0326.0002\FileSyncShell64.dll [2024-04-13] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files\Microsoft OneDrive\24.062.0326.0002\FileSyncShell64.dll [2024-04-13] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files\Microsoft OneDrive\24.062.0326.0002\FileSyncShell64.dll [2024-04-13] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files\Microsoft OneDrive\24.062.0326.0002\FileSyncShell64.dll [2024-04-13] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files\Microsoft OneDrive\24.062.0326.0002\FileSyncShell64.dll [2024-04-13] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers1: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\24.062.0326.0002\FileSyncShell64.dll [2024-04-13] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2023-06-20] (Igor Pavlov) [File not signed]
ContextMenuHandlers4: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\24.062.0326.0002\FileSyncShell64.dll [2024-04-13] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2023-06-20] (Igor Pavlov) [File not signed]
ContextMenuHandlers5: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\24.062.0326.0002\FileSyncShell64.dll [2024-04-13] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => -> No File
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2023-06-20] (Igor Pavlov) [File not signed]
==================== Codecs (Whitelisted) ====================
==================== Shortcuts & WMI ========================
==================== Loaded Modules (Whitelisted) =============
2023-10-05 13:08 - 2023-10-05 13:08 - 000491520 _____ () [File not signed] [File is in use] C:\Program Files (x86)\N-able Technologies\Windows Agent\bin\SnmpComp.dll
2024-04-14 14:04 - 2024-04-14 14:04 - 000208384 _____ () [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_64\Interop.Shell32\4fdcdbfcd1f6b18586100a86c16d506a\Interop.Shell32.ni.dll
2024-04-14 14:04 - 2024-04-14 14:04 - 000093184 _____ (Bluebeam, Inc.) [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_64\Bluebeam.Co6829f9db#\8890e847205e77db3fcee5aea1e96b82\Bluebeam.Common.Utilities.ni.dll
2024-04-14 14:04 - 2024-04-14 14:04 - 000848384 _____ (Bluebeam, Inc.) [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_64\Bluebeam.Co6fd05c8d#\d5629e0a7cd8bc8b1174a59400adb51d\Bluebeam.Core.Utilities.ni.dll
2024-04-14 14:05 - 2024-04-14 14:05 - 000733184 _____ (Bluebeam, Inc.) [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_64\Bluebeam.Co9519d13a#\e30a272ee4cb71bcd8f39a3abda04f44\Bluebeam.Core.Registration.ni.dll
2024-04-14 14:04 - 2024-04-14 14:04 - 002244096 _____ (Bluebeam, Inc.) [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_64\Bluebeam.Fonts\09995926cb677524f83cbeaef221537a\Bluebeam.Fonts.ni.dll
2024-04-14 14:05 - 2024-04-14 14:05 - 000355328 _____ (Bluebeam, Inc.) [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_64\Bluebeam.Li65e005b7#\cce6b36740e13555a67f7dce108228f5\Bluebeam.Licensing.Client.ni.dll
2024-04-14 14:05 - 2024-04-14 14:05 - 000334336 _____ (Bluebeam, Inc.) [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_64\Bluebeam.Wi36fb82de#\8d994f8d513fba2d10ebc719078d5756\Bluebeam.Windows.Registration.ni.dll
2024-04-14 14:04 - 2024-04-14 14:04 - 000617472 _____ (ICSharpCode.net) [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_64\ICSharpCoded64bfd68#\642ca350558636bb0a84ffb27725c3a4\ICSharpCode.SharpZipLib.ni.dll
2023-06-20 14:00 - 2023-06-20 14:00 - 000101376 _____ (Igor Pavlov) [File not signed] C:\Program Files\7-Zip\7-zip.dll
2023-06-25 14:26 - 2023-06-25 14:26 - 000000000 ____L (Microsoft Corporation) [symlink -> C:\Program Files\Common Files\Microsoft Shared\ClickToRun\AppvIsvSubsystems64.dll] C:\Program Files\Microsoft Office\root\Client\AppVIsvSubsystems64.dll
2023-06-25 14:26 - 2023-06-25 14:26 - 000000000 ____L (Microsoft Corporation) [symlink -> C:\Program Files\Common Files\Microsoft Shared\ClickToRun\AppvIsvSubsystems64.dll] C:\Program Files\Microsoft Office\root\Office16\AppVIsvSubsystems64.dll
2023-06-25 14:26 - 2023-06-25 14:26 - 000000000 ____L (Microsoft Corporation) [symlink -> C:\Program Files\Common Files\Microsoft Shared\ClickToRun\C2R64.dll] C:\Program Files\Microsoft Office\root\Client\C2R64.dll
2023-06-25 14:26 - 2023-06-25 14:26 - 000000000 ____L (Microsoft Corporation) [symlink -> C:\Program Files\Common Files\Microsoft Shared\ClickToRun\C2R64.dll] C:\Program Files\Microsoft Office\root\Office16\c2r64.dll
2024-04-14 14:05 - 2024-04-14 14:05 - 002889728 _____ (Newtonsoft) [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_64\Newtonsoft.Json\7f09a4a7d2f45052090306eb2d5a86d7\Newtonsoft.Json.ni.dll
2023-06-26 17:42 - 2023-06-26 17:42 - 010861568 _____ (Sentinel Labs, Inc.) [File not signed] C:\Program Files\SentinelOne\Sentinel Agent 23.3.3.264\SentinelOneAgentUI.dll
2023-11-09 18:10 - 2023-11-09 18:10 - 011571200 _____ (SentinelOne, Inc.) [File not signed] C:\Program Files\SentinelOne\Sentinel Agent 23.3.3.264\StaticEngineLibrary\StaticEngineMain\SentinelStaticAI.dll
2024-04-14 14:05 - 2024-04-14 14:05 - 006985216 _____ (The Legion of the Bouncy Castle Inc.) [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_64\crypto\94eef861f568e604b8d61e44c2469bb9\crypto.ni.dll
==================== Alternate Data Streams (Whitelisted) ========
==================== Safe Mode (Whitelisted) ==================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AutomationManagerAgent => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Windows Agent Maintenance Service => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Windows Agent Service => ""="Service"
==================== Association (Whitelisted) =================
==================== Internet Explorer (Whitelisted) ==========
BHO: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre-1.8\bin\ssv.dll [2023-12-19] (Oracle America, Inc. -> Oracle Corporation)
BHO: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre-1.8\bin\jp2ssv.dll [2023-12-19] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2024-04-09] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2024-04-09] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2024-04-09] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2024-04-09] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2024-04-09] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2024-04-09] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2024-04-09] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2024-04-09] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2024-04-09] (Microsoft Corporation -> Microsoft Corporation)
(If an entry is included in the fixlist, it will be removed from the registry.)
IE trusted site: HKU\S-1-5-21-2814321435-3934866655-2077815162-4663\...\sharepoint.com -> hxxps://COMPANYinsulationinc-files.sharepoint.com
==================== Hosts content: =========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2022-05-06 23:24 - 2022-05-06 23:22 - 000000824 _____ C:\Windows\system32\drivers\etc\hosts
==================== Other Areas ===========================
(Currently there is no automatic fix for this section.)
HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Common Files\Oracle\Java\javapath;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\
HKU\S-1-5-21-1102328504-126867679-1360648775-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Lenovo\ThinkPad-ThinkCentre_wallpaper.png
HKU\S-1-5-21-1102328504-126867679-1360648775-500\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Lenovo\ThinkPad-ThinkCentre_wallpaper.png
HKU\S-1-5-21-2814321435-3934866655-2077815162-4663\Control Panel\Desktop\\Wallpaper -> C:\Users\USERNAME\Pictures\WallPaper\img13.jpg
DNS Servers: 192.168.11.1 - 89.208.105.113
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 1) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
==================== FirewallRules (Whitelisted) ================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{A47BDD10-83EF-46F5-BB06-A254119C9AEC}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [TCP Query User{D31C3FDE-6261-48C2-ABAB-A781712B3E4A}C:\users\USERNAME\appdata\local\microsoft\teams\current\teams.exe] => (Block) C:\users\USERNAME\appdata\local\microsoft\teams\current\teams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [UDP Query User{6859AAEB-275D-4A52-A6F5-5BDF23C32798}C:\users\USERNAME\appdata\local\microsoft\teams\current\teams.exe] => (Block) C:\users\USERNAME\appdata\local\microsoft\teams\current\teams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{FAE78889-42B1-4F35-84BD-9FC880C3A847}] => (Allow) C:\Program Files\SentinelOne\Sentinel Agent 23.3.3.264\Ranger\SentinelRanger.exe (SentinelOne Inc. -> SentinelRanger)
FirewallRules: [{0BCE11FF-E3AD-4608-9016-891EBF419E6D}] => (Allow) C:\Program Files\SentinelOne\Sentinel Agent 23.3.3.264\SentinelAgent.exe (Sentinelone, Inc. -> Sentinel Labs, Inc.)
FirewallRules: [{83B4634E-741D-449D-8860-0BB6DB4F6CA1}] => (Allow) C:\Program Files\SentinelOne\Sentinel Agent 23.3.3.264\SentinelCtl.exe (SentinelOne Inc. -> Sentinel Labs, Inc.)
FirewallRules: [{5850C03F-C743-4D12-9092-5BECB9B51CB7}] => (Allow) C:\Program Files (x86)\BeAnywhere Support Express\GetSupportService_N-Central\BASupSrvc.exe (N-ABLE TECHNOLOGIES LTD -> N-able Take Control)
FirewallRules: [{FC261753-91F5-4615-8407-1F0BF47D3D98}] => (Allow) C:\Program Files (x86)\BeAnywhere Support Express\GetSupportService_N-Central\BASupSrvc.exe (N-ABLE TECHNOLOGIES LTD -> N-able Take Control)
FirewallRules: [{BA869518-FE90-4A05-B8AC-BB93CC7A4ACC}] => (Allow) C:\Program Files\WindowsApps\MSTeams_24060.2623.2790.8046_x64__8wekyb3d8bbwe\ms-teams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{1E8A2019-CA56-44E0-AD6F-004EF0C31AD0}] => (Allow) C:\Program Files\WindowsApps\MSTeams_24060.2623.2790.8046_x64__8wekyb3d8bbwe\ms-teams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{AE27BF8C-C987-4D81-93EF-E82D72B68FEB}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{17234F82-696B-4228-8308-E314D71213D7}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\123.0.2420.97\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)
==================== Restore Points =========================
==================== Faulty Device Manager Devices ============
==================== Event log errors: ========================
Application errors:
==================
Error: (04/14/2024 02:25:34 PM) (Source: .NET Runtime) (EventID: 1000) (User: )
Description: Category: Immybot.Agent.Common.Ephemeral.PowerShellExecutionHost
EventId: 0
Start
System.Collections.Generic.Dictionary`2[System.String,System.Guid]
PSPipeHost(10584) logged error: ReadByte failed, pipe likely closed. Exiting.
Error: (04/14/2024 02:25:34 PM) (Source: .NET Runtime) (EventID: 1000) (User: )
Description: Category: Immybot.Agent.Common.Ephemeral.PowerShellExecutionHost
EventId: 0
Start
System.Collections.Generic.Dictionary`2[System.String,System.Guid]
PSPipeHost(7884) logged error: ReadByte failed, pipe likely closed. Exiting.
Error: (04/14/2024 02:25:34 PM) (Source: .NET Runtime) (EventID: 1000) (User: )
Description: Category: Immybot.Agent.Common.Ephemeral.PowerShellExecutionHost
EventId: 0
Start
System.Collections.Generic.Dictionary`2[System.String,System.Guid]
PSPipeHost(10356) logged error: ReadByte failed, pipe likely closed. Exiting.
Error: (04/14/2024 02:25:24 PM) (Source: .NET Runtime) (EventID: 1000) (User: )
Description: Category: Immybot.Agent.Common.Ephemeral.PowerShellExecutionHost
EventId: 0
Start
System.Collections.Generic.Dictionary`2[System.String,System.Guid]
PSPipeHost(7672) logged error: ReadByte failed, pipe likely closed. Exiting.
Error: (04/14/2024 02:23:23 PM) (Source: .NET Runtime) (EventID: 1000) (User: )
Description: Category: Immybot.Agent.MinimalShared.PSExecutionEngine
EventId: 0
Start
System.Collections.Generic.Dictionary`2[System.String,System.Guid]
Failed to spawn process via Win32API
Exception:
Immybot.Agent.MinimalShared.NoLoggedOnUserException: Could not start the process as the current user because no user is logged in.
at Immybot.Agent.MinimalShared.ProcessRunner.DoStartUser(String commandLine)
at Immybot.Agent.MinimalShared.ProcessRunner.StartCommandLine(String commandLine, Boolean asUser)
at Immybot.Agent.MinimalShared.PSExecutionEngine.EnsureScriptExistsAndValidatedThenExecute(PowershellContext desiredContext, String script, String scriptName, String expectedScriptHash, String scriptDir, String additionalArgs)
Error: (04/14/2024 02:23:23 PM) (Source: .NET Runtime) (EventID: 1000) (User: )
Description: Category: Immybot.Agent.MinimalShared.PSExecutionEngine
EventId: 0
Start
System.Collections.Generic.Dictionary`2[System.String,System.Guid]
Failed to spawn process via Win32API
Exception:
Immybot.Agent.MinimalShared.NoLoggedOnUserException: Could not start the process as the current user because no user is logged in.
at Immybot.Agent.MinimalShared.ProcessRunner.DoStartUser(String commandLine)
at Immybot.Agent.MinimalShared.ProcessRunner.StartCommandLine(String commandLine, Boolean asUser)
at Immybot.Agent.MinimalShared.PSExecutionEngine.EnsureScriptExistsAndValidatedThenExecute(PowershellContext desiredContext, String script, String scriptName, String expectedScriptHash, String scriptDir, String additionalArgs)
Error: (04/14/2024 01:45:13 PM) (Source: Microsoft-Windows-Perflib) (EventID: 1023) (User: NT AUTHORITY)
Description: Windows cannot load the extensible counter DLL "C:\Windows\system32\sysmain.dll" (Win32 error code 126).
Error: (04/14/2024 02:02:12 AM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance. hr = 0x8007045b, A system shutdown is in progress..
System errors:
=============
Error: (04/15/2024 08:46:31 AM) (Source: Microsoft-Windows-GroupPolicy) (EventID: 1129) (User: COMPANY)
Description: The processing of Group Policy failed because of lack of network connectivity to a domain controller. This may be a transient condition. A success message would be generated once the machine gets connected to the domain controller and Group Policy has successfully processed. If you do not see a success message for several hours, then contact your administrator.
Error: (04/15/2024 08:13:13 AM) (Source: Microsoft-Windows-GroupPolicy) (EventID: 1129) (User: NT AUTHORITY)
Description: The processing of Group Policy failed because of lack of network connectivity to a domain controller. This may be a transient condition. A success message would be generated once the machine gets connected to the domain controller and Group Policy has successfully processed. If you do not see a success message for several hours, then contact your administrator.
Error: (04/15/2024 07:16:31 AM) (Source: Microsoft-Windows-GroupPolicy) (EventID: 1129) (User: COMPANY)
Description: The processing of Group Policy failed because of lack of network connectivity to a domain controller. This may be a transient condition. A success message would be generated once the machine gets connected to the domain controller and Group Policy has successfully processed. If you do not see a success message for several hours, then contact your administrator.
Error: (04/15/2024 06:20:13 AM) (Source: Microsoft-Windows-GroupPolicy) (EventID: 1129) (User: NT AUTHORITY)
Description: The processing of Group Policy failed because of lack of network connectivity to a domain controller. This may be a transient condition. A success message would be generated once the machine gets connected to the domain controller and Group Policy has successfully processed. If you do not see a success message for several hours, then contact your administrator.
Error: (04/15/2024 06:06:19 AM) (Source: NETLOGON) (EventID: 5719) (User: )
Description: This computer was not able to set up a secure session with a domain
controller in domain COMPANY due to the following:
We can't sign you in with this credential because your domain isn't available. Make sure your device is connected to your organization's network and try again. If you previously signed in on this device with another credential, you can sign in with that credential.
This may lead to authentication problems. Make sure that this
computer is connected to the network. If the problem persists,
please contact your domain administrator.
ADDITIONAL INFO
If this computer is a domain controller for the specified domain, it
sets up the secure session to the primary domain controller emulator in the specified
domain. Otherwise, this computer sets up the secure session to any domain controller
in the specified domain.
Error: (04/15/2024 04:27:13 AM) (Source: Microsoft-Windows-GroupPolicy) (EventID: 1129) (User: NT AUTHORITY)
Description: The processing of Group Policy failed because of lack of network connectivity to a domain controller. This may be a transient condition. A success message would be generated once the machine gets connected to the domain controller and Group Policy has successfully processed. If you do not see a success message for several hours, then contact your administrator.
Error: (04/15/2024 02:34:13 AM) (Source: Microsoft-Windows-GroupPolicy) (EventID: 1129) (User: NT AUTHORITY)
Description: The processing of Group Policy failed because of lack of network connectivity to a domain controller. This may be a transient condition. A success message would be generated once the machine gets connected to the domain controller and Group Policy has successfully processed. If you do not see a success message for several hours, then contact your administrator.
Error: (04/15/2024 02:06:05 AM) (Source: NETLOGON) (EventID: 5719) (User: )
Description: This computer was not able to set up a secure session with a domain
controller in domain COMPANY due to the following:
We can't sign you in with this credential because your domain isn't available. Make sure your device is connected to your organization's network and try again. If you previously signed in on this device with another credential, you can sign in with that credential.
This may lead to authentication problems. Make sure that this
computer is connected to the network. If the problem persists,
please contact your domain administrator.
ADDITIONAL INFO
If this computer is a domain controller for the specified domain, it
sets up the secure session to the primary domain controller emulator in the specified
domain. Otherwise, this computer sets up the secure session to any domain controller
in the specified domain.
Windows Defender:
================
Date: 2023-11-20 14:01:55
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan
CodeIntegrity:
===============
Date: 2024-04-15 09:11:00
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Program Files\SentinelOne\Sentinel Agent 23.3.3.264\SentinelAmsi64.dll that did not meet the Windows signing level requirements.
==================== Memory info ===========================
BIOS: LENOVO R2CET31W (1.13) 09/26/2023
Motherboard: LENOVO 21JR001RUS
Processor: AMD Ryzen 5 7530U with Radeon Graphics
Percentage of memory in use: 63%
Total physical RAM: 15182.37 MB
Available physical RAM: 5518.61 MB
Total Virtual: 28494.37 MB
Available Virtual: 12409.38 MB
==================== Drives ================================
Drive c: (Windows) (Fixed) (Total:236.25 GB) (Free:73.67 GB) (Model: Micron MTFDKCD256TFK) NTFS
\\?\Volume{6055c4f8-3309-48ae-b481-c3ddf65d4f13}\ (WinRE_DRV) (Fixed) (Total:1.95 GB) (Free:1.2 GB) NTFS
\\?\Volume{44cc2561-0714-4362-98b7-55235c8a4cf0}\ (SYSTEM) (Fixed) (Total:0.25 GB) (Free:0.22 GB) FAT32
==================== MBR & Partition Table ====================
==========================================================
Disk: 0 (Size: 238.5 GB) (Disk ID: E2C77DFD)
Partition: GPT.
==================== End of Addition.txt =======================