I have been getting some strange system behavior on my personal PC, along with odd activity via SMB and Terminal server& RDP, and immediately after I finished looking at all this in the logs, I literally watched my machine do an lsass dump, via process hacker and Wireshark, at which point I disconnected it from the network with a machete... Anyways, I opened autoruns to help with my search for any persistence, and it showed these timestamps ([1]: /answers/storage/attachments/81788-auto.png). I loaded a clean copy from another machine after this occurred, same thing happened. I couldn't find but one other instance on the web of this, and the person was referred here by the mod. So, any ideas?
20H2 19042.867, 4770k, Kaspersky