This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

W32.ROGUE.GEN [Solved]

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Good Morning from Monroeville, PA!!

 

I woke up this morning to W32.rogue/gen being caught by Webroot.  Not real happy!  I can't find what Webroot has done with it, but I think I would of set it up to quarantine what it finds.  I can't find the quarantine in Webroot…

 

As of right now, it doesn't look like anything is going on that I can see.  Can't speak for what is going on behind the scenes tho.  I have not rebooted, as I feel that may activate it.

 

I would like help in removing it before it does it's evil work.  Thank you very much!

 

dar

:welcome:

 

Darlene, when you replied to your own topic it removed you from the zero reply topics that our helpers look for to help people, I found you by accident.

 

Go ahead and reboot and tell me if anything strange happens, then lets run FRST and see whats going on, make sure you download and run it from your desktop

 

 

Please download Farbar Recovery Scan Tool and save it to your DESKTOP
 
Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
 
How to determine whether a computer is running a 32-bit version or 64-bit version of the Windows operating system
A simple way to check your system: Start –> Computer (right click) –> Properties
 
[external image: FRST_zps5d956a1a.jpg]
 
 
  • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • Just keep the defaults as in the picture checkmarked
  • Press Scan button.
  • It will produce a log called FRST.txt in the same directory the tool is run from.
  • Please copy and paste log back here.
  • The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply.
  • Sorry…..didn't know! I just wanted to record what I've done…..

     

    I did reboot out of curiosity, and so far nothing…….

     

     

    Here is  addition.txt

     

    Additional scan result of Farbar Recovery Scan Tool (x64) Version:20-12-2015
    Ran by [removed] (2015-12-20 11:31:53)
    Running from C:\Users\[removed]\Desktop
    Windows 10 Home (X64) (2015-11-26 00:03:50)
    Boot Mode: Normal
    ==========================================================


    ==================== Accounts: =============================

    Administrator (S-1-5-21-3944082369-795306520-2734861758-500 - Administrator - Disabled)
    AGOF- (S-1-5-21-3944082369-795306520-2734861758-1006 - Limited - Disabled)
    Darlene (S-1-5-21-3944082369-795306520-2734861758-1001 - Administrator - Enabled) => C:\Users\Darlene
    DefaultAccount (S-1-5-21-3944082369-795306520-2734861758-503 - Limited - Disabled)
    Guest (S-1-5-21-3944082369-795306520-2734861758-501 - Limited - Disabled)
    HomeGroupUser$ (S-1-5-21-3944082369-795306520-2734861758-1005 - Limited - Enabled)

    ==================== Security Center ========================

    (If an entry is included in the fixlist, it will be removed.)

    AV: Webroot SecureAnywhere (Enabled - Up to date) {66A6FE14-08CB-F415-3742-517201416109}
    AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AS: Webroot SecureAnywhere (Enabled - Up to date) {DDC71FF0-2EF1-FB9B-0DF2-6A007AC62BB4}
    AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    ==================== Installed Programs ======================

    (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

    Adobe Acrobat Reader DC (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.009.20079 - Adobe Systems Incorporated)
    Adobe Flash Player 20 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 20.0.0.235 - Adobe Systems Incorporated)
    Advertising Center (x32 Version: 0.0.0.1 - Nero AG) Hidden
    Akamai NetSession Interface (HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Akamai) (Version:  - Akamai Technologies, Inc)
    ANT Drivers Installer x64 (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden
    Apple Application Support (HKLM-x32\…\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.)
    Apple Software Update (HKLM-x32\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
    ASUS Live Update (HKLM-x32\…\{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}) (Version: 3.3.4 - ASUS)
    ASUS Power4Gear Hybrid (HKLM\…\{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}) (Version: 3.0.6 - ASUS)
    ASUS Smart Gesture (HKLM-x32\…\{4D3286A6-F6AB-498A-82A4-E4F040529F3D}) (Version: 4.0.5 - ASUS)
    ASUS Splendid Video Enhancement Technology (HKLM-x32\…\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 2.01.0018 - ASUS)
    ASUS USB Charger Plus (HKLM-x32\…\{A859E3E5-C62F-4BFA-AF1D-2B95E03166AF}) (Version: 3.1.7 - ASUS)
    ATK Package (HKLM-x32\…\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0027 - ASUS)
    CyberLink LabelPrint 2.5 (HKLM-x32\…\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.5415 - CyberLink Corp.)
    CyberLink Power2Go (HKLM-x32\…\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 7.0.0.3625 - CyberLink Corp.)
    D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
    Dragon Assistant Application en-US version 1.5.7 (HKLM-x32\…\{1CCBE73F-4948-4711-8D12-22E2FD65D706}_is1) (Version: 1.5.7 - Nuance Communications, Inc.)
    Dragon Assistant Core Recognition Service version 1.1.10 (HKLM-x32\…\{E97BA7A6-46FC-4EBF-B24A-B8362948C696}_is1) (Version: 1.1.10 - Nuance Communications, Inc.)
    Dragon Assistant Language Data en-US version 1.1.3 (HKLM-x32\…\{4C0C1E4E-D3B1-4496-98EC-DA14D45EC855}_is1) (Version: 1.1.3 - Nuance Communications, Inc.)
    Dragon Assistant version 1.5.7 (HKLM-x32\…\{D57A8269-3BE5-4D10-B882-64D0F2D448BF}_is1) (Version: 1.5.7 - Nuance Communications, Inc.)
    Elevated Installer (x32 Version: 4.0.15.0 - Garmin Ltd or its subsidiaries) Hidden
    Epson USB Display (HKLM-x32\…\{7650F538-6274-44EA-8F50-843479073333}) (Version: 1.62.000 - SEIKO EPSON CORPORATION)
    FileZilla Client 3.11.0.2 (HKLM-x32\…\FileZilla Client) (Version: 3.11.0.2 - Tim Kosse)
    Garmin BaseCamp (HKLM-x32\…\{36A0D446-B8E9-4753-BDFE-335F6F4DE59C}) (Version: 4.5.2 - Garmin Ltd or its subsidiaries)
    Garmin City Navigator North America NT 2009 (HKLM-x32\…\{58B42F3F-EC8D-4A53-9813-5EA43C4E9350}) (Version: 10.0.0.0 - Garmin Ltd or its subsidiaries)
    Garmin City Navigator North America NT 2015.20 (HKLM-x32\…\{74699736-87EB-49E7-8B71-7527A45C35C6}) (Version: 2.0.0.0 - Garmin Ltd or its subsidiaries)
    Garmin City Navigator North America NT 2015.30 (HKLM-x32\…\{0F0E68E9-9463-4087-B211-E80FAC5F9BC6}) (Version: 2.0.0.0 - Garmin Ltd or its subsidiaries)
    Garmin Express (HKLM-x32\…\{50755d67-ae60-4e47-b3d6-ce44d01b5a95}) (Version: 4.0.15.0 - Garmin Ltd or its subsidiaries)
    Garmin Express (x32 Version: 4.0.15.0 - Garmin Ltd or its subsidiaries) Hidden
    Garmin Express Tray (x32 Version: 4.0.15.0 - Garmin Ltd or its subsidiaries) Hidden
    Garmin MapSource (HKLM-x32\…\{AFBAB9A0-DDE8-49AE-8C17-A01B61BEE64B}) (Version: 6.16.3 - Garmin Ltd or its subsidiaries)
    Garmin POI Loader (HKLM-x32\…\{3213ED5E-7BBE-4613-BE69-8B1E4FE520DD}) (Version: 2.7.3 - Garmin Ltd or its subsidiaries)
    Garmin USB Drivers (HKLM\…\{DC7720F2-98BE-41C1-B0A8-E391362E86B8}) (Version: 2.3.1.1 - Garmin Ltd or its subsidiaries)
    Generations (HKLM-x32\…\{CB9EA6BB-B653-11D4-B6F6-00105A27284D}) (Version:  - )
    GL_Audio (HKLM-x32\…\{12555116-3137-42EE-8958-869A7649D33B}) (Version: 1.0.0 - Bytheway Software Development Lab (BSDL))
    Google Chrome (HKLM-x32\…\Google Chrome) (Version: 47.0.2526.106 - Google Inc.)
    Google Earth (HKLM-x32\…\{817750FA-EC6A-485D-9901-0683AE6FFDF1}) (Version: 7.1.5.1557 - Google)
    Google Update Helper (x32 Version: 1.3.29.1 - Google Inc.) Hidden
    GPSBabel 1.5.2 (HKLM-x32\…\{1B8FE958-A304-4902-BF7A-4E2F0F5B7017}_is1) (Version:  - GPSBabel)
    ImagXpress (x32 Version: 7.0.74.0 - Nero AG) Hidden
    IncrediMail (x32 Version: 6.6.0.5288 - IncrediMail) Hidden
    IncrediMail 2.5 (HKLM-x32\…\IncrediMail) (Version: 6.6.0.5288 - IncrediMail Ltd.)
    Intel Experience Center - Configuration (x32 Version: 1.7.0.179 - Intel) Hidden
    Intel(R) Dynamic Platform and Thermal Framework (HKLM-x32\…\FFD10ECE-F715-4a86-9BD8-F6F47DA5DA1C) (Version: 7.1.0.2103 - Intel Corporation)
    Intel(R) Experience Center Desktop Software (HKLM-x32\…\{3608ec0a-56b4-4d9d-b038-9b3e51d72582}) (Version: 1.7.0.179 - Intel)
    Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.15.1730 - Intel Corporation)
    Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3308 - Intel Corporation)
    Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology(patch version 3.0.1337.1) (HKLM\…\{302600C1-6BDF-4FD1-1307-148929CC1385}) (Version: 3.1.1307.0362 - Intel Corporation)
    Intel(R) Smart Connect Technology (HKLM\…\{978B5476-EAF9-4EB0-AD34-92689249A016}) (Version: 4.2.41.2499 - Intel Corporation)
    Intel(R) Update Manager (HKLM-x32\…\{B991A1BC-DE0F-41B3-9037-B2F948F706EC}) (Version: 3.1.1228 - Intel Corporation)
    Intel® PROSet/Wireless Software (HKLM-x32\…\{e1172fd4-a6d9-4cfa-8256-268f728fec31}) (Version: 16.5.3 - Intel Corporation)
    JaVaWa Device Manager 3.8 (HKLM-x32\…\{4D700EE8-5A7D-43C1-B4E2-BC8A22B482DD}_is1) (Version: 3.8 - JaVaWa GPS-tools)
    Junk Mail filter update (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
    Legacy 8.0 (HKLM-x32\…\Legacy 8.0) (Version: 8.0  - Millennia Corporation)
    Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
    Microsoft ASP.NET MVC 2 (HKLM-x32\…\{DD8FF2F3-0D97-4CF3-AF78-FA0E1B242244}) (Version: 2.0.60926.0 - Microsoft Corporation)
    Microsoft Office 365 - en-us (HKLM\…\O365HomePremRetail - en-us) (Version: 16.0.6366.2036 - Microsoft Corporation)
    Microsoft Office Home and Student 2010 (HKLM-x32\…\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
    Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-007A-0409-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
    Microsoft Outlook Social Connector Provider for Windows Live Messenger 32-bit (HKLM-x32\…\{95140000-007D-0409-0000-0000000FF1CE}) (Version: 14.0.5120.5000 - Microsoft Corporation)
    Microsoft Power Query for Excel (HKLM-x32\…\{A6A2F2F7-9D47-4A3D-AD7D-A5ED323E0470}) (Version: 2.21.3974.242 - Microsoft Corporation)
    Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
    Microsoft SQL Server 2012 PowerPivot for Excel  32-bit (HKLM-x32\…\{4CFC749F-E178-42C7-8095-796C5814C9C3}) (Version: 11.1.3129.0 - Microsoft Corporation)
    Microsoft Streets and Trips 2005 (HKLM-x32\…\{67E4EE98-59F4-4210-89A6-A20AF5BEC689}) (Version: 12.00.07.1200 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\…\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
    Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
    Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
    Mozilla Firefox 43.0.1 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 43.0.1 (x86 en-US)) (Version: 43.0.1 - Mozilla)
    Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 43.0.1.5828 - Mozilla)
    Nero 9 Essentials (HKLM-x32\…\{6939c416-2a80-4d38-b431-32c81d6208ba}) (Version:  - Nero AG)
    Office 16 Click-to-Run Extensibility Component (x32 Version: 16.0.6326.1010 - Microsoft Corporation) Hidden
    Office 16 Click-to-Run Licensing Component (Version: 16.0.6326.1010 - Microsoft Corporation) Hidden
    Office 16 Click-to-Run Localization Component (x32 Version: 16.0.6326.1010 - Microsoft Corporation) Hidden
    Photo Notifier and Animation Creator (HKLM-x32\…\Photo Notifier and Animation Creator) (Version: 1.0.0.1009 - IncrediMail Ltd.)
    Picasa 3 (HKLM-x32\…\Picasa 3) (Version: 3.9.141.259 - Google, Inc.)
    QuickTime 7 (HKLM-x32\…\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.)
    Realtek Card Reader (HKLM-x32\…\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.2.9200.39048 - Realtek Semiconductor Corp.)
    Realtek Ethernet Controller Driver (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.20.815.2013 - Realtek)
    Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7023 - Realtek Semiconductor Corp.)
    Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\…\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
    VLC media player (HKLM-x32\…\VLC media player) (Version: 2.2.1 - VideoLAN)
    Webroot SecureAnywhere (HKLM-x32\…\WRUNINST) (Version: 9.0.7.42 - Webroot)
    WebStorage (HKLM-x32\…\WebStorage) (Version: 2.1.12.424 - ASUS Cloud Corporation)
    Windows Driver Package - ASUS (ATP) Mouse  (06/17/2015 1.0.0.262) (HKLM\…\14588A15B66655338DBCC021FFA81E31DC281859) (Version: 06/17/2015 1.0.0.262 - ASUS)
    Windows Driver Package - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\…\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.)
    Windows Driver Package - Silicon Labs Software (DSI_SiUSBXp_3_1) USB  (02/06/2007 3.1) (HKLM\…\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software)
    Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
    WinFlash (HKLM-x32\…\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 2.42.0 - ASUS)

    ==================== Custom CLSID (Whitelisted): ==========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    CustomCLSID: HKU\S-1-5-21-3944082369-795306520-2734861758-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Darlene\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\FileCoAuth.exe (Microsoft Corporation)

    ==================== Restore Points =========================

    02-12-2015 18:24:20 Windows Update
    08-12-2015 19:19:06 Windows Update
    17-12-2015 20:50:30 Windows Update

    ==================== Hosts content: ===============================

    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

    2013-08-22 08:25 - 2013-08-22 08:25 - 00000824 ____N C:\WINDOWS\system32\Drivers\etc\hosts


    ==================== Scheduled Tasks (Whitelisted) =============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    Task: {034B8AD5-9609-49FE-AFD9-99E66ADFBB86} - System32\Tasks\Update Checker => C:\Program Files (x86)\ASUS\ASUS Live Update\UpdateChecker.exe [2015-02-12] ()
    Task: {0AD5CCE8-31AD-4D05-8736-B31CD48CC136} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-12-08] (Adobe Systems Incorporated)
    Task: {0D5882F7-1EF1-4CBF-ADEB-28D9904DBE86} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
    Task: {1538967D-CCF9-4056-8547-F2613C1E483A} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
    Task: {22E03D7D-1FE9-4059-B845-ED5769BAB347} - System32\Tasks\ASUS Splendid ColorU => C:\Program Files (x86)\ASUS\Splendid\ColorUService.exe [2013-08-16] (ASUSTeK Computer Inc.)
    Task: {26204135-2996-4D85-A375-8FF6DDF34201} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
    Task: {26929322-93F8-46CF-ADB2-A6796FB75A95} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-12-08] (Microsoft Corporation)
    Task: {358E7683-7FDC-41A1-A9EB-90CE43AF643C} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
    Task: {41D30CA3-CB90-4558-8425-A5634ECC0522} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2015-12-04] (Microsoft Corporation)
    Task: {44ADDD6C-698F-469A-A952-DB8B46760F61} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2015-12-06] (Microsoft Corporation)
    Task: {453113FB-5786-4851-9D60-D23621D11112} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2015-09-25] (Intel Corporation)
    Task: {4F4AC660-429B-46E1-BC9B-4A42EC63F1D3} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
    Task: {508A49A3-574A-4D65-BEC7-3277B7647360} - System32\Tasks\ASUS Smart Gesture Launcher => C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLauncher.exe [2015-08-23] (AsusTek)
    Task: {51FB72CD-3971-4B9F-B885-0E2C5C95B7F0} - System32\Tasks\P4GIntlCtrl => C:\Program Files\ASUS\P4G\IntlDPST.exe [2013-08-29] ()
    Task: {5243A525-A228-41CB-9615-9FBC7975A752} - System32\Tasks\ASUS Live Update1 => C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe [2015-03-23] (ASUSTeK Computer Inc.)
    Task: {53204BF0-07B4-47ED-8FF0-3E9121DE7FA9} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
    Task: {60F17FC8-27FB-4793-AD14-447AFD2EE155} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
    Task: {61B1B66A-E4AC-475D-AE23-BD3083CD476C} - System32\Tasks\ASUS P4G => C:\Program Files\ASUS\P4G\BatteryLife.exe [2013-08-29] (ASUS)
    Task: {647D2B45-337A-4061-97FA-F5CBEF18F744} - System32\Tasks\GenericSettingsHandler\Windows-Credentials\RetrySyncTask_for_S-1-5-21-3944082369-795306520-2734861758-1001
    Task: {66D179DF-0663-45E7-B082-FFB02D0AC53E} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
    Task: {765866C0-C30C-453D-AE8A-7283FC8F0692} - System32\Tasks\ASUS Splendid ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2013-08-19] (ASUS)
    Task: {8A539946-19B5-407A-8FFF-096579F29B03} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
    Task: {8C5D9EA7-9A2E-4C57-948F-9A1229916F9E} - System32\Tasks\AUTOMATICALLY WAKE UP FROM SLEEP => C:\Users\Darlene\Documents\DAR\Desktop\1486804_778876578805644_1700898744_n.jpg [2014-03-16] ()
    Task: {96DAC478-F623-4712-AFE1-4B57E5ED2948} - System32\Tasks\ASUS Patch for Touch Panel => C:\ProgramData\AsTouchPanel\AsPatchTouchPanel64.exe [2013-01-09] (ASUSTek Computer INC.)
    Task: {9AD6002B-9A05-4FD1-A97D-15A7D76B88D2} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
    Task: {9CAB8A70-A7A9-43C4-8BF9-01840CEA628D} - System32\Tasks\ASUS USB Charger Plus => C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [2013-08-29] (ASUSTek Computer Inc.)
    Task: {9D525AE6-86DE-4260-9B8A-3D00DDC715FD} - System32\Tasks\{559BB109-F8DE-4779-87E0-26192DD4A81F} => pcalua.exe -a D:\autorun.exe -d D:\
    Task: {B5EAC601-7C64-4A53-B236-319F103660CE} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express Self Updater\ExpressSelfUpdater.exe
    Task: {C8547E51-7754-4DC6-88A6-C1CA81881CDF} - System32\Tasks\ASUS Live Update2 => C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe [2015-03-23] (ASUSTeK Computer Inc.)
    Task: {D8B13308-E64C-49B9-8D1C-77075EAD15D7} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2015-12-04] (Microsoft Corporation)
    Task: {D95AC4B2-686D-477B-81DC-6DBD78964CA7} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-10-28] (Adobe Systems Incorporated)
    Task: {E349320D-F171-4196-B1F5-786AA6E20D8F} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-04-25] (Google Inc.)
    Task: {EA6E612C-0F7A-40BB-8232-51E354692419} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
    Task: {ED500B6B-CF0A-46C1-A1BD-15A5B2742324} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
    Task: {F0940692-9ECE-4864-AF8D-94BAA3FF6966} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-04-25] (Google Inc.)
    Task: {F0B0277A-28FC-42F8-9ED6-0217CF8C1D0C} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2015-09-25] (Intel Corporation)

    (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

    Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

    ==================== Shortcuts =============================

    (The entries could be listed to be restored or removed.)

    ==================== Loaded Modules (Whitelisted) ==============

    2015-10-30 02:18 - 2015-10-30 02:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
    2013-09-06 20:06 - 2013-09-06 20:06 - 00198120 _____ () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe
    2013-09-06 20:06 - 2013-09-06 20:06 - 00054760 _____ () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\NetworkHeuristic.dll
    2013-09-06 20:05 - 2013-09-06 20:05 - 00034792 _____ () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\ISCTNetMon.dll
    2015-11-26 10:34 - 2015-12-04 03:52 - 00162472 _____ () C:\Program Files\Common Files\Microsoft Shared\ClickToRun\ApiClient.dll
    2015-12-02 17:57 - 2015-11-22 05:47 - 02653816 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
    2015-12-02 17:57 - 2015-11-22 05:47 - 02653816 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
    2015-06-02 10:18 - 2015-06-02 10:18 - 00043480 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll
    2015-12-17 17:51 - 2015-12-04 06:52 - 08903848 _____ () C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\1033\GrooveIntlResource.dll
    2015-12-17 20:33 - 2015-12-06 22:33 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
    2015-12-17 20:33 - 2015-12-06 23:14 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll
    2015-12-17 20:33 - 2015-12-06 23:00 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
    2015-12-17 20:33 - 2015-12-06 22:37 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
    2015-12-17 20:33 - 2015-12-06 22:34 - 00936448 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll
    2015-12-17 20:33 - 2015-12-06 22:34 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
    2015-12-17 20:33 - 2015-12-06 22:36 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
    2013-08-29 19:01 - 2013-08-29 19:01 - 00031360 _____ () C:\Program Files\ASUS\P4G\DevMng.dll
    2015-07-18 00:35 - 2015-07-18 00:35 - 00396688 _____ () C:\WINDOWS\system32\igfxTray.exe
    2015-12-17 05:42 - 2015-12-17 05:43 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.12.15004.0_x86__8wekyb3d8bbwe\SkypeHost.exe
    2015-12-10 05:36 - 2015-12-10 05:36 - 00012800 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.1208.10480.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
    2015-12-10 05:36 - 2015-12-10 05:36 - 11542016 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.1208.10480.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll
    2015-11-25 20:02 - 2015-11-25 20:02 - 00258560 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.1208.10480.0_x64__8wekyb3d8bbwe\StoreRatingPromotion.dll
    2013-12-18 15:04 - 2013-05-02 14:26 - 00387984 _____ () C:\Program Files (x86)\Nuance\Dragon Assistant\Core\fl_core.dll
    2013-12-18 15:04 - 2013-05-02 14:26 - 01165712 _____ () C:\Program Files (x86)\Nuance\Dragon Assistant\Core\vocon3200_asr.dll
    2013-12-18 15:04 - 2013-05-02 14:26 - 00199056 _____ () C:\Program Files (x86)\Nuance\Dragon Assistant\Core\vocon3200_base.dll
    2013-12-18 15:04 - 2013-05-02 14:26 - 01132944 _____ () C:\Program Files (x86)\Nuance\Dragon Assistant\Core\vocon3200_pron.dll
    2013-12-18 15:04 - 2013-05-02 14:26 - 00035216 _____ () C:\Program Files (x86)\Nuance\Dragon Assistant\Core\vocon3200_platform.dll
    2013-12-18 15:04 - 2013-05-02 14:26 - 00229264 _____ () C:\Program Files (x86)\Nuance\Dragon Assistant\Core\sdxg.dll
    2013-12-18 15:04 - 2013-05-02 14:25 - 00027648 _____ () C:\Program Files (x86)\Nuance\Dragon Assistant\Core\WASAPIResamplingStreamCOMServer.dll
    2013-08-16 13:03 - 2013-08-16 13:03 - 00023040 _____ () C:\Program Files (x86)\ASUS\Splendid\CCTAdjust.dll
    2013-08-19 20:16 - 2013-08-19 20:16 - 00015440 _____ () C:\Program Files (x86)\ASUS\Splendid\DetectDisplayDC.dll
    2014-08-13 19:30 - 2014-08-13 19:30 - 00033128 _____ () C:\Program Files (x86)\IncrediMail\Bin\IMHttpComm.dll
    2014-08-13 19:30 - 2014-08-13 19:30 - 00272808 _____ () C:\Program Files (x86)\IncrediMail\Bin\ImLookExU.dll
    2014-08-13 19:30 - 2014-08-13 19:30 - 00072104 _____ () C:\Program Files (x86)\IncrediMail\Bin\wlessfp1.dll
    2014-08-13 19:30 - 2014-08-13 19:30 - 00080296 _____ () C:\Program Files (x86)\IncrediMail\bin\ImAppRU.dll
    2014-08-13 19:30 - 2014-08-13 19:30 - 00133544 _____ () C:\Program Files (x86)\IncrediMail\Bin\ImComUtlU.dll
    2012-05-24 20:19 - 2012-05-24 20:19 - 00627216 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll
    2011-03-09 13:21 - 2011-03-09 13:21 - 00013096 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll
    2013-10-01 14:02 - 2013-10-01 14:02 - 00108888 _____ () C:\Program Files (x86)\IncrediMail\Bin\pmc.dll
    2013-12-18 14:45 - 2013-09-16 15:17 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
    2015-12-17 05:42 - 2015-12-17 05:43 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.12.15004.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll
    2015-12-17 05:42 - 2015-12-17 05:43 - 21845504 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.12.15004.0_x86__8wekyb3d8bbwe\SkyWrap.dll

    ==================== Alternate Data Streams (Whitelisted) =========

    (If an entry is included in the fixlist, only the ADS will be removed.)


    ==================== Safe Mode (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


    ==================== EXE Association (Whitelisted) ===============

    (If an entry is included in the fixlist, the registry item will be restored to default or removed.)

    HKU\.DEFAULT\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION
    HKU\.DEFAULT\Software\Classes\exefile: "%1" %* <===== ATTENTION
    HKU\S-1-5-19\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION
    HKU\S-1-5-19\Software\Classes\exefile: "%1" %* <===== ATTENTION
    HKU\S-1-5-20\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION
    HKU\S-1-5-20\Software\Classes\exefile: "%1" %* <===== ATTENTION
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\Software\Classes\exefile: "%1" %* <===== ATTENTION

    ==================== Internet Explorer trusted/restricted ===============

    (If an entry is included in the fixlist, it will be removed from the registry.)


    ==================== Other Areas ============================

    (Currently there is no automatic fix for this section.)

    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Darlene\AppData\Roaming\Mozilla\Firefox\Desktop Background.bmp
    DNS Servers: 192.168.1.1
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: ) (ConsentPromptBehaviorUser: ) (EnableLUA: 1)
    Windows Firewall is enabled.

    ==================== MSCONFIG/TASK MANAGER disabled items ==

    (Currently there is no automatic fix for this section.)

    HKLM\…\StartupApproved\StartupFolder: => "Install Webroot IE RunOnce.lnk"
    HKLM\…\StartupApproved\StartupFolder: => "Install Webroot FF RunOnce.lnk"
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\StartupApproved\Run: => "Speech Recognition"

    ==================== FirewallRules (Whitelisted) ===============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
    FirewallRules: [{E323874A-2511-4F16-A4AD-A90967A34A3B}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    FirewallRules: [{3054FDC8-CAAB-4B0C-A422-37DE86F95405}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    FirewallRules: [UDP Query User{BCE22DE0-D475-4908-A4EC-C53AAA26ADA3}C:\users\darlene\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\darlene\appdata\local\akamai\netsession_win.exe
    FirewallRules: [TCP Query User{45686273-F5EE-4887-877E-3696691DF1D4}C:\users\darlene\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\darlene\appdata\local\akamai\netsession_win.exe
    FirewallRules: [UDP Query User{57540340-3C15-4981-844B-8668BC40C74D}C:\users\darlene\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\darlene\appdata\local\akamai\netsession_win.exe
    FirewallRules: [TCP Query User{F656B0A2-0AD3-442A-B21B-FC1FB6C83125}C:\users\darlene\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\darlene\appdata\local\akamai\netsession_win.exe
    FirewallRules: [{1C713E57-BA0B-4A72-B915-B0A42C257254}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    FirewallRules: [{DAE1B52F-7472-426D-9190-79CFD530D06D}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    FirewallRules: [{7451C82A-5AA1-4690-8124-E5B8ADDCA098}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe
    FirewallRules: [{52B564D6-448D-4E06-8B16-D865AF6CE6FF}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe
    FirewallRules: [{4A7E00CF-0B9D-4DD2-8461-579C15E11613}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImApp.exe
    FirewallRules: [{D93618EC-F663-4ED6-A926-0751646F7FFE}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImApp.exe
    FirewallRules: [{C2D4A0A9-8452-4DB4-8858-9BCF0DE7A76F}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe
    FirewallRules: [TCP Query User{622A15BE-749D-44AC-A483-8B5EF5716881}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
    FirewallRules: [{EF30D24C-EA81-4E4F-BCDD-BEA2E2403FBD}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
    FirewallRules: [{16E6434F-E71D-44BA-9505-E8D5BA5AA080}] => (Allow) LPort=1900
    FirewallRules: [{65CA9CC1-436A-4515-983B-411D60B0D5F6}] => (Allow) LPort=2869
    FirewallRules: [{ECC3BDB6-0733-456E-B20D-1C4C6C8E5C9D}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
    FirewallRules: [{FFF74B1D-20DF-481C-8C89-A88F5FE34E1D}] => (Allow) C:\Users\Darlene\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
    FirewallRules: [{5843A7F0-30E5-4009-8067-EB6217405B98}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe
    FirewallRules: [{C97BA9BB-13E6-4B7C-B0A2-990BD95AC1D8}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe
    FirewallRules: [{A35A4593-20C8-4956-A8CE-228A07190185}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
    FirewallRules: [{4041F952-FF95-4B50-8C2F-9E6ED388292C}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe
    FirewallRules: [{123D1ADF-0098-43AA-A8F2-C0FB1D554607}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    ==================== Faulty Device Manager Devices =============


    ==================== Event log errors: =========================

    Application errors:
    ==================
    Error: (12/20/2015 10:39:41 AM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: IncMail.exe, version: 6.6.0.5288, time stamp: 0x524abb1e
    Faulting module name: ntdll.dll, version: 10.0.10586.20, time stamp: 0x5654262a
    Exception code: 0xc0000374
    Fault offset: 0x000dc089
    Faulting process id: 0x1d84
    Faulting application start time: 0xIncMail.exe0
    Faulting application path: IncMail.exe1
    Faulting module path: IncMail.exe2
    Report Id: IncMail.exe3
    Faulting package full name: IncMail.exe4
    Faulting package-relative application ID: IncMail.exe5

    Error: (12/20/2015 10:35:51 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: PEACHY)
    Description: Activation of app Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI failed with error: -2147023170 See the Microsoft-Windows-TWinUI/Operational log for additional information.

    Error: (12/20/2015 10:09:20 AM) (Source: Office 2016 Licensing Service) (EventID: 0) (User: )
    Description: Subscription licensing service failed: -1073418220

    Error: (12/19/2015 02:50:13 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: IncMail.exe, version: 6.6.0.5288, time stamp: 0x524abb1e
    Faulting module name: ntdll.dll, version: 10.0.10586.20, time stamp: 0x5654262a
    Exception code: 0xc0000374
    Fault offset: 0x000dc089
    Faulting process id: 0x22ec
    Faulting application start time: 0xIncMail.exe0
    Faulting application path: IncMail.exe1
    Faulting module path: IncMail.exe2
    Report Id: IncMail.exe3
    Faulting package full name: IncMail.exe4
    Faulting package-relative application ID: IncMail.exe5

    Error: (12/19/2015 10:09:02 AM) (Source: Office 2016 Licensing Service) (EventID: 0) (User: )
    Description: Subscription licensing service failed: -1073418220

    Error: (12/19/2015 07:00:12 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: PEACHY)
    Description: Activation of app Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI failed with error: -2147023170 See the Microsoft-Windows-TWinUI/Operational log for additional information.

    Error: (12/19/2015 07:00:10 AM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: SearchUI.exe, version: 10.0.10586.35, time stamp: 0x566503dc
    Faulting module name: Windows.UI.Xaml.dll, version: 10.0.10586.35, time stamp: 0x566505e8
    Exception code: 0xc000027b
    Fault offset: 0x00000000006fcc8b
    Faulting process id: 0x21dc
    Faulting application start time: 0xSearchUI.exe0
    Faulting application path: SearchUI.exe1
    Faulting module path: SearchUI.exe2
    Report Id: SearchUI.exe3
    Faulting package full name: SearchUI.exe4
    Faulting package-relative application ID: SearchUI.exe5

    Error: (12/18/2015 07:18:49 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: PEACHY)
    Description: Activation of app Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI failed with error: -2147023170 See the Microsoft-Windows-TWinUI/Operational log for additional information.

    Error: (12/18/2015 07:18:46 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: SearchUI.exe, version: 10.0.10586.35, time stamp: 0x566503dc
    Faulting module name: Windows.UI.Xaml.dll, version: 10.0.10586.35, time stamp: 0x566505e8
    Exception code: 0xc000027b
    Fault offset: 0x00000000006fcc8b
    Faulting process id: 0x1460
    Faulting application start time: 0xSearchUI.exe0
    Faulting application path: SearchUI.exe1
    Faulting module path: SearchUI.exe2
    Report Id: SearchUI.exe3
    Faulting package full name: SearchUI.exe4
    Faulting package-relative application ID: SearchUI.exe5

    Error: (12/18/2015 01:40:23 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: PEACHY)
    Description: Activation of app Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI failed with error: -2147023170 See the Microsoft-Windows-TWinUI/Operational log for additional information.


    System errors:
    =============
    Error: (12/20/2015 10:41:29 AM) (Source: DCOM) (EventID: 10016) (User: PEACHY)
    Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}PEACHYDarleneS-1-5-21-3944082369-795306520-2734861758-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

    Error: (12/20/2015 10:41:29 AM) (Source: DCOM) (EventID: 10016) (User: PEACHY)
    Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}PEACHYDarleneS-1-5-21-3944082369-795306520-2734861758-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

    Error: (12/20/2015 10:41:29 AM) (Source: DCOM) (EventID: 10016) (User: PEACHY)
    Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}PEACHYDarleneS-1-5-21-3944082369-795306520-2734861758-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

    Error: (12/20/2015 10:41:29 AM) (Source: DCOM) (EventID: 10016) (User: PEACHY)
    Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}PEACHYDarleneS-1-5-21-3944082369-795306520-2734861758-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

    Error: (12/20/2015 10:40:57 AM) (Source: DCOM) (EventID: 10016) (User: PEACHY)
    Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}PEACHYDarleneS-1-5-21-3944082369-795306520-2734861758-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

    Error: (12/20/2015 10:40:57 AM) (Source: DCOM) (EventID: 10016) (User: PEACHY)
    Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}PEACHYDarleneS-1-5-21-3944082369-795306520-2734861758-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

    Error: (12/20/2015 10:40:41 AM) (Source: DCOM) (EventID: 10016) (User: PEACHY)
    Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}PEACHYDarleneS-1-5-21-3944082369-795306520-2734861758-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

    Error: (12/20/2015 10:40:41 AM) (Source: DCOM) (EventID: 10016) (User: PEACHY)
    Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}PEACHYDarleneS-1-5-21-3944082369-795306520-2734861758-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

    Error: (12/20/2015 10:40:40 AM) (Source: DCOM) (EventID: 10016) (User: PEACHY)
    Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}PEACHYDarleneS-1-5-21-3944082369-795306520-2734861758-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

    Error: (12/20/2015 10:40:40 AM) (Source: DCOM) (EventID: 10016) (User: PEACHY)
    Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}PEACHYDarleneS-1-5-21-3944082369-795306520-2734861758-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742


    CodeIntegrity:
    ===================================
      Date: 2015-12-18 13:39:09.110
      Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

      Date: 2015-12-17 17:52:58.541
      Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

      Date: 2015-12-13 11:52:53.460
      Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

      Date: 2015-12-10 05:33:58.615
      Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

      Date: 2015-12-09 17:52:10.151
      Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

      Date: 2015-12-08 21:14:35.430
      Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

      Date: 2015-12-03 05:45:21.712
      Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

      Date: 2015-12-02 20:37:24.006
      Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

      Date: 2015-11-26 10:54:56.725
      Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

      Date: 2015-11-26 10:38:46.905
      Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.


    ==================== Memory info ===========================

    Processor: Intel(R) Core(TM) i5-4200U CPU @ 1.60GHz
    Percentage of memory in use: 32%
    Total physical RAM: 8075.62 MB
    Available physical RAM: 5488.93 MB
    Total Virtual: 9355.62 MB
    Available Virtual: 6662.02 MB

    ==================== Drives ================================

    Drive c: (OS) (Fixed) (Total:677.52 GB) (Free:470.66 GB) NTFS ==>[system with boot components (obtained from drive)]

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (Size: 698.6 GB) (Disk ID: D2664718)

    Partition: GPT.

    ==================== End of Addition.txt ============================

     

     

    Here is:  FRST.TXT

     

    Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:20-12-2015
    Ran by [removed] (administrator) on PEACHY (20-12-2015 11:30:52)
    Running from C:\Users\[removed]\Desktop
    [removed] Platform: Windows 10 Home Version 1511 (X64) Language: English (United States)
    Internet Explorer Version 11 (Default browser: FF)
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (Intel Corporation) C:\Windows\System32\igfxCUIService.exe
    (Intel Corporation) C:\Windows\SysWOW64\IntelCpHeciSvc.exe
    (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
    (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
    () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe
    (ASUS) C:\Program Files\ASUS\P4G\InsOnSrv.exe
    (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
    (ASUS Cloud Corporation) C:\Program Files (x86)\ASUS\WebStorage\2.0.3.226\AsusWSWinService.exe
    (SEIKO EPSON CORPORATION) C:\Program Files (x86)\EPSON Projector\Epson USB Display V1.6\EMP_UDSA.exe
    (Intel Corporation) C:\Windows\System32\DptfPolicyLpmService.exe
    (Intel Corporation) C:\Windows\System32\DptfParticipantProcessorService.exe
    (Intel Corporation) C:\Windows\System32\DptfPolicyCriticalService.exe
    (Intel Corporation) C:\Windows\System32\DptfPolicyConfigTDPService.exe
    (Nuance Communications, Inc.) C:\Program Files (x86)\Nuance\Dragon Assistant\Core\DACore.exe
    (Nero AG) C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
    (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
    (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
    (ASUS) C:\Program Files\ASUS\P4G\InsOnWMI.exe
    (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
    (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
    (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.1\GoogleCrashHandler.exe
    (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe
    (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
    (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
    (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.1\GoogleCrashHandler64.exe
    (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\Splendid\ColorUService.exe
    (ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
    (ASUSTek Computer INC.) C:\ProgramData\AsTouchPanel\AsPatchTouchPanel64.exe
    (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
    (ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe
    (Microsoft Corporation) C:\Windows\System32\dllhost.exe
    (Intel Corporation) C:\Windows\System32\igfxEM.exe
    (Intel Corporation) C:\Windows\System32\igfxHK.exe
    () C:\Windows\System32\igfxTray.exe
    (Webroot) C:\Program Files\Webroot\WRSA.exe
    (Webroot) C:\Program Files\Webroot\WRSA.exe
    (Microsoft Corporation) C:\Windows\System32\Speech_OneCore\Common\SpeechRuntime.exe
    (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
    (Intel Corporation) C:\Windows\System32\DptfPolicyLpmServiceHelper.exe
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
    (Akamai Technologies, Inc.) C:\Users\Darlene\AppData\Local\Akamai\netsession_win.exe
    (Akamai Technologies, Inc.) C:\Users\Darlene\AppData\Local\Akamai\netsession_win.exe
    (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE
    (IncrediMail, Ltd.) C:\Program Files (x86)\IncrediMail\Bin\ImApp.exe
    (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
    (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE16\CSISYNCCLIENT.EXE
    (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSYNC.EXE
    (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe
    (IncrediMail, Ltd.) C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
    (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe
    (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe
    (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    () C:\Program Files\WindowsApps\Microsoft.Messaging_2.12.15004.0_x86__8wekyb3d8bbwe\SkypeHost.exe
    (ASUS Cloud Corporation) C:\Program Files (x86)\ASUS\WebStorage\2.1.12.424\AsusWSPanel.exe
    () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.1208.10480.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
    (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.ZuneVideo_3.6.15731.0_x64__8wekyb3d8bbwe\Video.UI.exe


    ==================== Registry (Whitelisted) ===========================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\…\Run: [DptfPolicyLpmServiceHelper] => C:\WINDOWS\system32\DptfPolicyLpmServiceHelper.exe [111976 2013-09-11] (Intel Corporation)
    HKLM\…\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13650648 2013-08-20] (Realtek Semiconductor)
    HKLM\…\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1321688 2013-08-06] (Realtek Semiconductor)
    HKLM\…\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
    HKLM\…\Run: [IgfxTray] => C:\Windows\system32\igfxtray.exe [396688 2015-07-18] ()
    HKLM\…\Run: [HotKeysCmds] => "C:\Windows\system32\hkcmd.exe"
    HKLM\…\Run: [Persistence] => "C:\Windows\system32\igfxpers.exe"
    HKLM-x32\…\Run: [Adobe Reader Speed Launcher] => "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
    HKLM-x32\…\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [3216032 2013-09-06] (ASUSTek Computer Inc.)
    HKLM-x32\…\Run: [WebStorage] => C:\Program Files (x86)\ASUS\WebStorage\2.1.12.424\ASUSWSLoader.exe [63296 2014-10-23] ()
    HKLM-x32\…\Run: [WRSVC] => C:\Program Files\Webroot\WRSA.exe [842336 2015-12-16] (Webroot)
    HKLM-x32\…\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
    HKLM-x32\…\Run: [EPSON_UD_START] => C:\Program Files (x86)\EPSON Projector\Epson USB Display V1.6\EMP_UD.exe [536168 2013-05-31] (SEIKO EPSON CORPORATION)
    HKLM-x32\…\Run: [CLMLServer] => C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [111120 2012-05-24] (CyberLink)
    HKLM-x32\…\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
    HKLM\…\Policies\Explorer: [NoViewOnDrive] 0
    HKLM\…\Policies\Explorer: [DisableLocalMachineRun] 0
    HKLM\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
    HKLM\…\Policies\Explorer: [DisableCurrentUserRun] 0
    HKLM\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
    HKLM\…\Policies\Explorer: [NoViewContextMenu] 0
    HKLM\…\Policies\Explorer: [NoShellSearchButton] 0
    HKLM\…\Policies\Explorer: [NoFind] 0
    HKLM\…\Policies\Explorer: [NoFile] 0
    HKLM\…\Policies\Explorer: [HideClock] 0
    HKLM\…\Policies\Explorer: [NoTrayContextMenu] 0
    HKLM\…\Policies\Explorer: [NoTrayItemsDisplay] 0
    HKLM\…\Policies\Explorer: [NoSetFolders] 0
    HKLM\…\Policies\Explorer: [NoDevMgrUpdate] 0
    HKLM\…\Policies\Explorer: [NoSetTaskbar] 0
    HKLM\…\Policies\Explorer: [NoDeletePrinter] 0
    HKLM\…\Policies\Explorer: [NoDFSTab] 0
    HKLM\…\Policies\Explorer: [NoChangeStartMenu] 0
    HKLM\…\Policies\Explorer: [NoLogoff] 0
    HKLM\…\Policies\Explorer: [NoWindowsUpdate] 0
    HKLM\…\Policies\Explorer: [NoEncryptOnMove] 0
    HKLM\…\Policies\Explorer: [NoRunasInstallPrompt] 0
    HKLM\…\Policies\Explorer: [NoResolveSearch] 0
    HKLM\…\Policies\Explorer: [NoSaveSettings] 0
    HKLM\…\Policies\Explorer: [NoHardwareTab] 0
    HKLM\…\Policies\Explorer: [NoStartMenuSubFolders] 0
    HKLM\…\Policies\Explorer: [NoDesktop] 0
    HKU\S-1-5-19\…\Policies\system: [DisableCMD] 0
    HKU\S-1-5-19\…\Policies\system: [NoDispAppearancePage] 0
    HKU\S-1-5-19\…\Policies\system: [NoDispBackgroundPage] 0
    HKU\S-1-5-19\…\Policies\system: [NoDispSettingsPage] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoViewOnDrive] 0
    HKU\S-1-5-19\…\Policies\Explorer: [DisableLocalMachineRun] 0
    HKU\S-1-5-19\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
    HKU\S-1-5-19\…\Policies\Explorer: [DisableCurrentUserRun] 0
    HKU\S-1-5-19\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoViewContextMenu] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoShellSearchButton] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoFind] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoFile] 0
    HKU\S-1-5-19\…\Policies\Explorer: [HideClock] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoTrayContextMenu] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoTrayItemsDisplay] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoSetFolders] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoDevMgrUpdate] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoSetTaskbar] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoDeletePrinter] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoDFSTab] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoChangeStartMenu] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoLogoff] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoWindowsUpdate] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoEncryptOnMove] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoRunasInstallPrompt] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoResolveSearch] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoSaveSettings] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoHardwareTab] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoStartMenuSubFolders] 0
    HKU\S-1-5-20\…\Policies\system: [DisableCMD] 0
    HKU\S-1-5-20\…\Policies\system: [NoDispAppearancePage] 0
    HKU\S-1-5-20\…\Policies\system: [NoDispBackgroundPage] 0
    HKU\S-1-5-20\…\Policies\system: [NoDispSettingsPage] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoViewOnDrive] 0
    HKU\S-1-5-20\…\Policies\Explorer: [DisableLocalMachineRun] 0
    HKU\S-1-5-20\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
    HKU\S-1-5-20\…\Policies\Explorer: [DisableCurrentUserRun] 0
    HKU\S-1-5-20\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoViewContextMenu] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoShellSearchButton] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoFind] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoFile] 0
    HKU\S-1-5-20\…\Policies\Explorer: [HideClock] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoTrayContextMenu] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoTrayItemsDisplay] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoSetFolders] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoDevMgrUpdate] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoSetTaskbar] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoDeletePrinter] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoDFSTab] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoChangeStartMenu] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoLogoff] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoWindowsUpdate] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoEncryptOnMove] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoRunasInstallPrompt] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoResolveSearch] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoSaveSettings] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoHardwareTab] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoStartMenuSubFolders] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Run: [IncrediMail] => C:\Program Files (x86)\IncrediMail\bin\IncMail.exe [444840 2014-08-13] (IncrediMail, Ltd.)
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Run: [Power2GoExpress] => 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Run: [Akamai NetSession Interface] => C:\Users\Darlene\AppData\Local\Akamai\netsession_win.exe [4691384 2015-09-10] (Akamai Technologies, Inc.)
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\RunOnce: [Uninstall C:\Users\Darlene\AppData\Local\Microsoft\OneDrive\17.3.6201.1019_1\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Darlene\AppData\Local\Microsoft\OneDrive\17.3.6201.1019_1\amd64"
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\system: [DisableCMD] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\system: [NoDispAppearancePage] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\system: [NoDispBackgroundPage] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\system: [NoDispSettingsPage] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoViewOnDrive] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [DisableLocalMachineRun] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [DisableCurrentUserRun] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoViewContextMenu] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoShellSearchButton] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoFind] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoFile] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [HideClock] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoTrayContextMenu] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoTrayItemsDisplay] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoSetFolders] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoDevMgrUpdate] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoSetTaskbar] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoDeletePrinter] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoDFSTab] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoChangeStartMenu] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoLogoff] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoWindowsUpdate] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoEncryptOnMove] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoRunasInstallPrompt] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoResolveSearch] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoSaveSettings] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoHardwareTab] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoStartMenuSubFolders] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\ssText3d.scr [232960 2015-10-30] (Microsoft Corporation)
    HKU\S-1-5-18\…\Policies\system: [DisableCMD] 0
    HKU\S-1-5-18\…\Policies\system: [NoDispAppearancePage] 0
    HKU\S-1-5-18\…\Policies\system: [NoDispBackgroundPage] 0
    HKU\S-1-5-18\…\Policies\system: [NoDispSettingsPage] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoViewOnDrive] 0
    HKU\S-1-5-18\…\Policies\Explorer: [DisableLocalMachineRun] 0
    HKU\S-1-5-18\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
    HKU\S-1-5-18\…\Policies\Explorer: [DisableCurrentUserRun] 0
    HKU\S-1-5-18\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoViewContextMenu] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoShellSearchButton] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoFind] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoFile] 0
    HKU\S-1-5-18\…\Policies\Explorer: [HideClock] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoTrayContextMenu] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoTrayItemsDisplay] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoSetFolders] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoDevMgrUpdate] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoSetTaskbar] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoDeletePrinter] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoDFSTab] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoChangeStartMenu] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoLogoff] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoWindowsUpdate] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoEncryptOnMove] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoRunasInstallPrompt] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoResolveSearch] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoSaveSettings] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoHardwareTab] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoStartMenuSubFolders] 0
    ShellIconOverlayIdentifiers: [!AsusWSShellExt_B] -> {6D4133E5-0742-4ADC-8A8C-9303440F7191} => C:\Program Files (x86)\Common Files\AWS\2.1.12.424\ASUSWSShellExt64.dll [2014-09-03] (ASUS Cloud Corporation.)
    ShellIconOverlayIdentifiers: [!AsusWSShellExt_O] -> {64174815-8D98-4CE6-8646-4C039977D809} => C:\Program Files (x86)\Common Files\AWS\2.1.12.424\ASUSWSShellExt64.dll [2014-09-03] (ASUS Cloud Corporation.)
    ShellIconOverlayIdentifiers: [!AsusWSShellExt_U] -> {1C5AB7B1-0B38-4EC4-9093-7FD277E2AF4E} => C:\Program Files (x86)\Common Files\AWS\2.1.12.424\ASUSWSShellExt64.dll [2014-09-03] (ASUS Cloud Corporation.)
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Install LastPass FF RunOnce.lnk [2015-12-18]
    ShortcutTarget: Install LastPass FF RunOnce.lnk -> C:\Program Files (x86)\Common Files\wruninstall.exe (Webroot Software, Inc.)
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Install LastPass IE RunOnce.lnk [2015-12-18]
    ShortcutTarget: Install LastPass IE RunOnce.lnk -> C:\Program Files (x86)\Common Files\wruninstall.exe (Webroot Software, Inc.)
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Install Webroot FF RunOnce.lnk [2014-08-12]
    ShortcutTarget: Install Webroot FF RunOnce.lnk -> C:\Program Files (x86)\Common Files\wruninstall.exe (Webroot Software, Inc.)
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Install Webroot IE RunOnce.lnk [2014-08-12]
    ShortcutTarget: Install Webroot IE RunOnce.lnk -> C:\Program Files (x86)\Common Files\wruninstall.exe (Webroot Software, Inc.)
    Startup: C:\Users\Darlene\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk [2015-12-05]
    ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
    Startup: C:\Users\Darlene\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk [2015-12-13]
    ShortcutTarget: Send to OneNote.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE (Microsoft Corporation)
    CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION

    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
    Tcpip\..\Interfaces\{6cbe0644-5221-4535-a66c-76c2d1de27df}: [DhcpNameServer] 192.168.1.1

    Internet Explorer:
    ==================
    HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bing.com/
    BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2015-12-17] (Microsoft Corporation)
    BHO: No Name -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> No File
    BHO: Webroot Vault -> {c8d5d964-2be8-4c5b-8cf5-6e975aa88504} -> C:\ProgramData\WRData\pkg\LPBar64.dll [2015-12-18] (Webroot)
    BHO: Webroot Filtering Extension -> {C9C42510-9B41-42c1-9DCD-7282A2D07C61} -> C:\Program Files\Webroot\WRData\PKG\Vistax64\wrflt.dll [2015-12-18] (Webroot)
    BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2015-12-04] (Microsoft Corporation)
    BHO-x32: Webroot Vault -> {c8d5d964-2be8-4c5b-8cf5-6e975aa88504} -> C:\ProgramData\WRData\pkg\LPBar.dll [2015-12-18] (Webroot)
    BHO-x32: Webroot Filtering Extension -> {C9C42510-9B41-42c1-9DCD-7282A2D07C61} -> C:\Program Files\Webroot\WRData\PKG\Vistax86\wrflt.dll [2015-12-18] (Webroot)
    Toolbar: HKLM - Webroot Toolbar - {97ab88ef-346b-4179-a0b1-7445896547a5} - C:\ProgramData\WRData\pkg\LPBar64.dll [2015-12-18] (Webroot)
    Toolbar: HKLM-x32 - Webroot Toolbar - {97ab88ef-346b-4179-a0b1-7445896547a5} - C:\ProgramData\WRData\pkg\LPBar.dll [2015-12-18] (Webroot)
    Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll No File
    Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll No File
    Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2015-12-04] (Microsoft Corporation)
    Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2015-12-04] (Microsoft Corporation)
    Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2015-12-04] (Microsoft Corporation)
    Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2015-12-04] (Microsoft Corporation)
    Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2013-02-26] (Skype Technologies)

    Edge:
    ======
    Edge HomeButtonPage: HKU\S-1-5-21-3944082369-795306520-2734861758-1001 -> hxxp://bing.com/

    FireFox:
    ========
    FF ProfilePath: C:\Users\Darlene\AppData\Roaming\Mozilla\Firefox\Profiles\wz6u9pc8.default
    FF DefaultSearchEngine: Amazon.com
    FF DefaultSearchEngine.US: Bing
    FF SelectedSearchEngine: Amazon.com
    FF Homepage: hxxp://www.bing.com/
    FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_20_0_0_235.dll [2015-12-08] ()
    FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
    FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_235.dll [2015-12-08] ()
    FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-20] (Google)
    FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2015-10-13] (Google, Inc.)
    FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-16] (Intel Corporation)
    FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-16] (Intel Corporation)
    FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2015-12-04] (Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
    FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-03] (Google Inc.)
    FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-03] (Google Inc.)
    FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
    FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
    FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-09-30] (Adobe Systems Inc.)
    FF Extension: Themes Menu - C:\Users\Darlene\AppData\Roaming\Mozilla\Firefox\Profiles\wz6u9pc8.default\extensions\{84625510-7e5d-11e0-a411-0800200c9a66}.xpi [2015-10-14]
    FF Extension: NetVideoHunter - C:\Users\Darlene\AppData\Roaming\Mozilla\Firefox\Profiles\wz6u9pc8.default\extensions\[removed] [2015-11-11]
    FF Extension: Save as PDF - C:\Users\Darlene\AppData\Roaming\Mozilla\Firefox\Profiles\wz6u9pc8.default\extensions\[removed] [2015-11-14]
    FF Extension: Walnut2 for Firefox - C:\Users\Darlene\AppData\Roaming\Mozilla\Firefox\Profiles\wz6u9pc8.default\Extensions\{080955ad-b8bb-4500-806f-d2b9ad73d72e}.xpi [2015-11-10]
    FF Extension: Garmin Communicator - C:\Users\Darlene\AppData\Roaming\Mozilla\Firefox\Profiles\wz6u9pc8.default\Extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E} [2014-12-13] [not signed]
    FF Extension: YouTube High Definition - C:\Users\Darlene\AppData\Roaming\Mozilla\Firefox\Profiles\wz6u9pc8.default\Extensions\{7b1bf0b6-a1b9-42b0-b75d-252036438bdc}.xpi [2015-12-06]
    FF Extension: Webroot Password Manager - C:\Users\Darlene\AppData\Roaming\Mozilla\Firefox\Profiles\wz6u9pc8.default\Extensions\{8ac62a8b-8b3f-43ba-9b1a-90c299b9dfda} [2015-12-18]
    FF Extension: Webroot Password Manager - C:\Users\Darlene\AppData\Roaming\Mozilla\Firefox\Profiles\wz6u9pc8.default\Extensions\{8ac62a8b-8b3f-43ba-9b1a-90c299b9dfda}.xpi [2015-08-20]
    FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\ProgramData\WRData\PKG\FIREFOX\WebrootSecure_SocketServer
    FF Extension: Webroot Filtering Extension - C:\ProgramData\WRData\PKG\FIREFOX\WebrootSecure_SocketServer [2015-12-18]

    Chrome:
    =======
    CHR StartupUrls: Default -> "hxxp://www.bing.com/"
    CHR DefaultSearchURL: Default -> hxxps://www.bing.com/search?q={searchTerms}&PC;=U316&FORM;=CHROMN
    CHR DefaultSearchKeyword: Default -> bing.com
    CHR DefaultNewTabURL: Default -> hxxps://www.bing.com/chrome/newtab
    CHR DefaultSuggestURL: Default -> hxxps://www.bing.com/osjson.aspx?query={searchTerms}&language;={language}&PC;=U316
    CHR Profile: C:\Users\Darlene\AppData\Local\Google\Chrome\User Data\Default
    CHR Extension: (Google Slides) - C:\Users\Darlene\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-10-02]
    CHR Extension: (Google Docs) - C:\Users\Darlene\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-10-02]
    CHR Extension: (Google Drive) - C:\Users\Darlene\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-11-28]
    CHR Extension: (YouTube) - C:\Users\Darlene\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-10-02]
    CHR Extension: (Google Search) - C:\Users\Darlene\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-28]
    CHR Extension: (Google Sheets) - C:\Users\Darlene\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-10-02]
    CHR Extension: (Google Docs Offline) - C:\Users\Darlene\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-28]
    CHR Extension: (Webroot Filtering Extension) - C:\Users\Darlene\AppData\Local\Google\Chrome\User Data\Default\Extensions\kjeghcllfecehndceplomkocgfbklffd [2015-11-28]
    CHR Extension: (Chrome Web Store Payments) - C:\Users\Darlene\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-10-02]
    CHR Extension: (Webroot Password Manager) - C:\Users\Darlene\AppData\Local\Google\Chrome\User Data\Default\Extensions\okfhiodnpcnnnpgbjbhfebjnbagmfhab [2015-10-02]
    CHR Extension: (Gmail) - C:\Users\Darlene\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-10-02]
    CHR HKLM-x32\…\Chrome\Extension: [kjeghcllfecehndceplomkocgfbklffd] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM-x32\…\Chrome\Extension: [ngkhgikojglcgnckopipfdajaifmmnnc] - hxxp://clients2.google.com/service/update2/crx
    CHR HKLM-x32\…\Chrome\Extension: [okfhiodnpcnnnpgbjbhfebjnbagmfhab] - C:\ProgramData\WRData\pkg\lpchrome.crx [2014-08-12]

    ==================== Services (Whitelisted) ========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R2 ASUS InstantOn; C:\Program Files\ASUS\P4G\InsOnSrv.exe [277120 2013-08-29] (ASUS)
    R2 Asus WebStorage Windows Service; C:\Program Files (x86)\ASUS\WebStorage\2.0.3.226\AsusWSWinService.exe [71680 2013-08-16] (ASUS Cloud Corporation) [File not signed]
    R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [2748600 2015-12-04] (Microsoft Corporation)
    R2 DACoreService; C:\Program Files (x86)\Nuance\Dragon Assistant\Core\DACore.exe [432528 2013-05-02] (Nuance Communications, Inc.)
    R2 DptfParticipantProcessorService; C:\Windows\system32\DptfParticipantProcessorService.exe [115632 2013-09-11] (Intel Corporation)
    R2 DptfPolicyConfigTDPService; C:\Windows\system32\DptfPolicyConfigTDPService.exe [116656 2013-09-11] (Intel Corporation)
    R2 DptfPolicyCriticalService; C:\Windows\system32\DptfPolicyCriticalService.exe [148688 2013-09-11] (Intel Corporation)
    R2 DptfPolicyLpmService; C:\Windows\system32\DptfPolicyLpmService.exe [124880 2013-09-11] (Intel Corporation)
    R2 EMP_UDSA; C:\Program Files (x86)\EPSON Projector\Epson USB Display V1.6\EMP_UDSA.exe [157696 2013-05-31] (SEIKO EPSON CORPORATION) [File not signed]
    S2 Garmin Device Interaction Service; C:\Program Files (x86)\Garmin\Device Interaction Service\GarminService.exe [708616 2015-04-08] (Garmin Ltd. or its subsidiaries)
    R2 igfxCUIService2.0.0.0; C:\Windows\system32\igfxCUIService.exe [351120 2015-07-18] (Intel Corporation)
    R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed]
    S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation)
    R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-09-16] (Intel Corporation)
    R2 Intel(R) Wireless Bluetooth(R) 4.0 Radio Management; C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe [155448 2013-09-20] (Intel Corporation)
    R2 ISCTAgent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [198120 2013-09-06] ()
    S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [178312 2015-09-25] (Intel Corporation)
    R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-16] (Intel Corporation)
    S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
    S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
    S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)
    R2 WRSVC; C:\Program Files\Webroot\WRSA.exe [842336 2015-12-16] (Webroot)

    ===================== Drivers (Whitelisted) ==========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [100776 2015-08-23] (ASUS Corporation)
    R3 DptfDevDram; C:\Windows\system32\DRIVERS\DptfDevDram.sys [143568 2013-09-11] (Intel Corporation)
    R3 DptfDevPch; C:\Windows\system32\DRIVERS\DptfDevPch.sys [114680 2013-09-11] (Intel Corporation)
    R3 DptfDevProc; C:\Windows\system32\DRIVERS\DptfDevProc.sys [287160 2013-09-11] (Intel Corporation)
    R3 DptfManager; C:\Windows\system32\DRIVERS\DptfManager.sys [494272 2013-09-11] (Intel Corporation)
    R3 eppvad_simple; C:\Windows\system32\drivers\EMP_UDAU.sys [23040 2013-05-31] (SEIKO EPSON CORPORATION)
    S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [22704 2015-12-20] ()
    R3 ibtusb; C:\Windows\system32\DRIVERS\ibtusb.sys [263952 2015-07-14] (Intel Corporation)
    R3 ikbevent; C:\Windows\system32\DRIVERS\ikbevent.sys [21408 2013-08-08] ()
    R3 imsevent; C:\Windows\system32\DRIVERS\imsevent.sys [21920 2013-08-08] ()
    R3 INETMON; C:\Windows\System32\Drivers\INETMON.sys [29088 2013-08-07] ()
    R3 ISCT; C:\Windows\System32\drivers\ISCTD64.sys [46568 2013-08-07] ()
    R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [17280 2012-08-05] ( )
    R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
    S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-10-05] (Malwarebytes Corporation)
    R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-09-16] (Intel Corporation)
    R3 NETwNb64; C:\Windows\System32\drivers\Netwbw02.sys [3485696 2015-10-30] (Intel Corporation)
    R2 plctrl; C:\Program Files\ASUS\P4G\plctrl.sys [14136 2013-08-29] (Windows (R) Win 7 DDK provider)
    R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [895256 2015-07-07] (Realtek                                            )
    R3 RTSUER; C:\Windows\system32\Drivers\RtsUer.sys [402960 2015-05-14] (Realsil Semiconductor Corporation)
    S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
    S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
    S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
    R0 WRkrn; C:\Windows\System32\drivers\WRkrn.sys [117728 2015-10-15] (Webroot)
    S3 wrUrlFlt; C:\Windows\system32\DRIVERS\wrUrlFlt.sys [45104 2015-12-18] (Webroot)
    U0 SR; no ImagePath
    U2 srservice; no ImagePath

    ==================== NetSvcs (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


    ==================== One Month Created files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2015-12-20 11:30 - 2015-12-20 11:31 - 00035573 _____ C:\Users\Darlene\Desktop\FRST.txt
    2015-12-20 11:30 - 2015-12-20 11:31 - 00000000 ____D C:\Users\Darlene\Desktop\UNUSED GENEALOGY STUFF
    2015-12-20 11:30 - 2015-12-20 11:30 - 00000000 ____D C:\FRST
    2015-12-20 11:29 - 2015-12-20 11:30 - 02370560 _____ (Farbar) C:\Users\Darlene\Desktop\FRST64.exe
    2015-12-20 10:39 - 2015-12-20 10:39 - 00000000 ___HD C:\OneDriveTemp
    2015-12-20 08:51 - 2015-12-20 08:51 - 00022704 _____ C:\WINDOWS\system32\Drivers\EsgScanner.sys
    2015-12-20 08:51 - 2015-12-20 08:51 - 00000000 _____ C:\autoexec.bat
    2015-12-20 08:28 - 2015-12-20 08:28 - 00001133 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2015-12-18 20:26 - 2015-12-18 20:26 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
    2015-12-17 20:33 - 2015-12-06 23:57 - 00973664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
    2015-12-17 20:33 - 2015-12-06 23:55 - 01281376 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
    2015-12-17 20:33 - 2015-12-06 23:49 - 00412512 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifitask.exe
    2015-12-17 20:33 - 2015-12-06 23:48 - 02544256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
    2015-12-17 20:33 - 2015-12-06 23:48 - 02180136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
    2015-12-17 20:33 - 2015-12-06 23:48 - 01299504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetsrc.dll
    2015-12-17 20:33 - 2015-12-06 23:48 - 01155944 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
    2015-12-17 20:33 - 2015-12-06 23:48 - 01118208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetsrc.dll
    2015-12-17 20:33 - 2015-12-06 23:48 - 01092456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
    2015-12-17 20:33 - 2015-12-06 23:48 - 01065080 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
    2015-12-17 20:33 - 2015-12-06 23:48 - 01020096 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll
    2015-12-17 20:33 - 2015-12-06 23:48 - 00983464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
    2015-12-17 20:33 - 2015-12-06 23:48 - 00884256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
    2015-12-17 20:33 - 2015-12-06 23:48 - 00823264 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
    2015-12-17 20:33 - 2015-12-06 23:48 - 00794888 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll
    2015-12-17 20:33 - 2015-12-06 23:48 - 00696160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll
    2015-12-17 20:33 - 2015-12-06 23:48 - 00670928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll
    2015-12-17 20:33 - 2015-12-06 23:48 - 00526856 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfreadwrite.dll
    2015-12-17 20:33 - 2015-12-06 23:48 - 00502112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll
    2015-12-17 20:33 - 2015-12-06 23:48 - 00498448 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll
    2015-12-17 20:33 - 2015-12-06 23:48 - 00462760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfreadwrite.dll
    2015-12-17 20:33 - 2015-12-06 23:48 - 00450904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFCaptureEngine.dll
    2015-12-17 20:33 - 2015-12-06 23:48 - 00337840 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFPlay.dll
    2015-12-17 20:33 - 2015-12-06 23:48 - 00289248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFPlay.dll
    2015-12-17 20:33 - 2015-12-06 23:48 - 00245848 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
    2015-12-17 20:33 - 2015-12-06 23:48 - 00115040 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupApi.dll
    2015-12-17 20:33 - 2015-12-06 23:48 - 00084832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupApi.dll
    2015-12-17 20:33 - 2015-12-06 23:47 - 00925064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
    2015-12-17 20:33 - 2015-12-06 23:47 - 00898184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll
    2015-12-17 20:33 - 2015-12-06 23:47 - 00716928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
    2015-12-17 20:33 - 2015-12-06 23:47 - 00116720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfps.dll
    2015-12-17 20:33 - 2015-12-06 23:46 - 03671888 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
    2015-12-17 20:33 - 2015-12-06 23:46 - 02919320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
    2015-12-17 20:33 - 2015-12-06 23:45 - 00264544 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
    2015-12-17 20:33 - 2015-12-06 23:15 - 01035776 _____ (Microsoft Corporation) C:\WINDOWS\system32\XboxNetApiSvc.dll
    2015-12-17 20:33 - 2015-12-06 23:15 - 00075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.XboxLive.ProxyStub.dll
    2015-12-17 20:33 - 2015-12-06 23:10 - 00824320 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
    2015-12-17 20:33 - 2015-12-06 23:09 - 00133120 _____ (Microsoft Corporation) C:\WINDOWS\system32\flvprophandler.dll
    2015-12-17 20:33 - 2015-12-06 23:09 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanagerprecheck.dll
    2015-12-17 20:33 - 2015-12-06 23:09 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorageUsage.dll
    2015-12-17 20:33 - 2015-12-06 23:07 - 16984064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
    2015-12-17 20:33 - 2015-12-06 23:07 - 00134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\wificonnapi.dll
    2015-12-17 20:33 - 2015-12-06 23:07 - 00077312 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvPluginEng.dll
    2015-12-17 20:33 - 2015-12-06 23:06 - 00572928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
    2015-12-17 20:33 - 2015-12-06 23:06 - 00231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCore.dll
    2015-12-17 20:33 - 2015-12-06 23:06 - 00199168 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
    2015-12-17 20:33 - 2015-12-06 23:05 - 00192000 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
    2015-12-17 20:33 - 2015-12-06 23:05 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\BackgroundTransferHost.exe
    2015-12-17 20:33 - 2015-12-06 23:04 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll
    2015-12-17 20:33 - 2015-12-06 23:04 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\provtool.exe
    2015-12-17 20:33 - 2015-12-06 23:03 - 13017600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
    2015-12-17 20:33 - 2015-12-06 23:02 - 00269824 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll
    2015-12-17 20:33 - 2015-12-06 23:02 - 00161280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe
    2015-12-17 20:33 - 2015-12-06 23:01 - 00543232 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
    2015-12-17 20:33 - 2015-12-06 23:01 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BackgroundTransferHost.exe
    2015-12-17 20:33 - 2015-12-06 23:00 - 00618496 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
    2015-12-17 20:33 - 2015-12-06 23:00 - 00323072 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSFlacDecoder.dll
    2015-12-17 20:33 - 2015-12-06 23:00 - 00210432 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll
    2015-12-17 20:33 - 2015-12-06 23:00 - 00203776 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll
    2015-12-17 20:33 - 2015-12-06 22:59 - 00558080 _____ (Microsoft Corporation) C:\WINDOWS\system32\MBMediaManager.dll
    2015-12-17 20:33 - 2015-12-06 22:59 - 00292352 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
    2015-12-17 20:33 - 2015-12-06 22:59 - 00286208 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
    2015-12-17 20:33 - 2015-12-06 22:59 - 00165376 _____ (Microsoft Corporation) C:\WINDOWS\system32\provdatastore.dll
    2015-12-17 20:33 - 2015-12-06 22:58 - 24601600 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
    2015-12-17 20:33 - 2015-12-06 22:58 - 00459776 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
    2015-12-17 20:33 - 2015-12-06 22:57 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll
    2015-12-17 20:33 - 2015-12-06 22:57 - 00387072 _____ (Microsoft Corporation) C:\WINDOWS\system32\qdvd.dll
    2015-12-17 20:33 - 2015-12-06 22:57 - 00270848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSFlacDecoder.dll
    2015-12-17 20:33 - 2015-12-06 22:56 - 00607232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
    2015-12-17 20:33 - 2015-12-06 22:56 - 00497152 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll
    2015-12-17 20:33 - 2015-12-06 22:55 - 07979008 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
    2015-12-17 20:33 - 2015-12-06 22:55 - 00346112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
    2015-12-17 20:33 - 2015-12-06 22:54 - 00850432 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
    2015-12-17 20:33 - 2015-12-06 22:54 - 00569856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qdvd.dll
    2015-12-17 20:33 - 2015-12-06 22:53 - 19339264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
    2015-12-17 20:33 - 2015-12-06 22:53 - 00381952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll
    2015-12-17 20:33 - 2015-12-06 22:51 - 01318912 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
    2015-12-17 20:33 - 2015-12-06 22:51 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll
    2015-12-17 20:33 - 2015-12-06 22:50 - 01131520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Audio.dll
    2015-12-17 20:33 - 2015-12-06 22:49 - 01105920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Audio.dll
    2015-12-17 20:33 - 2015-12-06 22:48 - 06297088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
    2015-12-17 20:33 - 2015-12-06 22:47 - 03428864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
    2015-12-17 20:33 - 2015-12-06 22:45 - 02582016 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
    2015-12-17 20:33 - 2015-12-06 22:45 - 00900608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll
    2015-12-17 20:33 - 2015-12-06 22:45 - 00683008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.dll
    2015-12-17 20:33 - 2015-12-06 22:44 - 02796032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
    2015-12-17 20:33 - 2015-12-06 22:43 - 02598400 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
    2015-12-17 20:33 - 2015-12-06 22:43 - 00931328 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSMPEG2ENC.DLL
    2015-12-17 20:33 - 2015-12-06 22:41 - 02061824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
    2015-12-17 20:33 - 2015-12-06 22:40 - 03593216 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
    2015-12-17 20:33 - 2015-12-06 22:40 - 01995776 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll
    2015-12-17 20:33 - 2015-12-06 22:40 - 01706496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActiveSyncProvider.dll
    2015-12-17 20:33 - 2015-12-06 22:39 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
    2015-12-17 20:33 - 2015-12-06 22:38 - 00871936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSMPEG2ENC.DLL
    2015-12-17 20:33 - 2015-12-06 22:33 - 00375296 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDEServer.exe
    2015-12-17 20:33 - 2015-12-06 22:32 - 00126464 _____ (Microsoft Corporation) C:\WINDOWS\system32\dialserver.dll
    2015-12-13 09:06 - 2015-12-13 09:06 - 00000000 ___RD C:\Users\Darlene\3D Objects
    2015-12-13 08:07 - 2015-12-13 08:08 - 05321204 _____ C:\Users\Darlene\Desktop\COWS.mp4
    2015-12-10 05:31 - 2015-12-18 07:59 - 00000000 ____D C:\Users\Darlene\AppData\LocalLow\LastPass
    2015-12-10 05:31 - 2015-12-18 07:58 - 00000000 ____D C:\Users\Darlene\AppData\Local\lptmp
    2015-12-08 21:40 - 2015-12-09 06:08 - 00003792 _____ C:\WINDOWS\System32\Tasks\AUTOMATICALLY WAKE UP FROM SLEEP
    2015-12-08 21:37 - 2015-12-08 21:37 - 00000776 _____ C:\Users\Darlene\Desktop\Downloads - Shortcut.lnk
    2015-12-08 20:03 - 2015-12-08 20:03 - 00000000 ____D C:\Users\Darlene\AppData\Roaming\WildTangent
    2015-12-08 17:38 - 2015-12-01 02:12 - 02152800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
    2015-12-08 17:38 - 2015-11-24 07:07 - 01817160 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
    2015-12-08 17:38 - 2015-11-24 06:06 - 01540768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
    2015-12-08 17:38 - 2015-11-24 05:26 - 01399224 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
    2015-12-08 17:38 - 2015-11-24 05:01 - 02756096 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
    2015-12-08 17:38 - 2015-11-24 04:54 - 00007680 _____ (Microsoft Corporation) C:\WINDOWS\system32\readingviewresources.dll
    2015-12-08 17:38 - 2015-11-24 04:53 - 00115200 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
    2015-12-08 17:38 - 2015-11-24 04:45 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\wshrm.dll
    2015-12-08 17:38 - 2015-11-24 04:37 - 00147968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rmcast.sys
    2015-12-08 17:38 - 2015-11-24 04:26 - 01337240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
    2015-12-08 17:38 - 2015-11-24 04:19 - 00182784 _____ (Microsoft Corporation) C:\WINDOWS\system32\shutdownux.dll
    2015-12-08 17:38 - 2015-11-24 04:12 - 00523776 _____ (Microsoft Corporation) C:\WINDOWS\system32\catsrvut.dll
    2015-12-08 17:38 - 2015-11-24 03:58 - 00604672 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
    2015-12-08 17:38 - 2015-11-24 03:55 - 01393664 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
    2015-12-08 17:38 - 2015-11-24 03:54 - 02756096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
    2015-12-08 17:38 - 2015-11-24 03:52 - 01717248 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
    2015-12-08 17:38 - 2015-11-24 03:49 - 01648640 _____ (Microsoft Corporation) C:\WINDOWS\system32\comsvcs.dll
    2015-12-08 17:38 - 2015-11-24 03:14 - 00415744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\catsrvut.dll
    2015-12-08 17:38 - 2015-11-24 03:03 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
    2015-12-08 17:38 - 2015-11-24 02:59 - 01467392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
    2015-12-08 17:38 - 2015-11-24 02:57 - 01328128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comsvcs.dll
    2015-12-08 17:38 - 2015-11-24 02:35 - 22393856 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
    2015-12-08 17:38 - 2015-11-24 02:29 - 02352128 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
    2015-12-08 17:38 - 2015-11-24 02:23 - 13381120 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
    2015-12-08 17:38 - 2015-11-24 02:11 - 18678272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
    2015-12-08 17:38 - 2015-11-24 02:08 - 12125184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
    2015-12-08 17:38 - 2015-11-24 02:04 - 02155008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
    2015-12-06 16:56 - 2015-12-06 16:56 - 01572864 _____ C:\Users\Darlene\Desktop\2015_September_City_Newsletter_-_9th_Issue.pub
    2015-12-02 17:57 - 2015-11-22 05:47 - 07476576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
    2015-12-02 17:57 - 2015-11-22 05:47 - 02653816 _____ C:\WINDOWS\system32\CoreUIComponents.dll
    2015-12-02 17:57 - 2015-11-22 05:41 - 01859448 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
    2015-12-02 17:57 - 2015-11-22 05:41 - 00026408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
    2015-12-02 17:57 - 2015-11-22 05:35 - 00538632 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWanAPI.dll
    2015-12-02 17:57 - 2015-11-22 05:34 - 00080600 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwapi.dll
    2015-12-02 17:57 - 2015-11-22 05:33 - 00095072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdstor.sys
    2015-12-02 17:57 - 2015-11-22 05:33 - 00058408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.dll
    2015-12-02 17:57 - 2015-11-22 05:33 - 00051680 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsUtilsV2.dll
    2015-12-02 17:57 - 2015-11-22 05:30 - 00604928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
    2015-12-02 17:57 - 2015-11-22 05:30 - 00161632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
    2015-12-02 17:57 - 2015-11-22 05:26 - 00431232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWanAPI.dll
    2015-12-02 17:57 - 2015-11-22 05:25 - 00063528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wwapi.dll
    2015-12-02 17:57 - 2015-11-22 05:24 - 02772584 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
    2015-12-02 17:57 - 2015-11-22 05:20 - 00795840 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
    2015-12-02 17:57 - 2015-11-22 05:19 - 00440160 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe
    2015-12-02 17:57 - 2015-11-22 05:14 - 02185840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll
    2015-12-02 17:57 - 2015-11-22 05:00 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsCSP.dll
    2015-12-02 17:57 - 2015-11-22 04:56 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosHostClient.dll
    2015-12-02 17:57 - 2015-11-22 04:56 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ihvrilproxy.dll
    2015-12-02 17:57 - 2015-11-22 04:56 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\rilproxy.dll
    2015-12-02 17:57 - 2015-11-22 04:55 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManagerProxy.dll
    2015-12-02 17:57 - 2015-11-22 04:55 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvcProxy.dll
    2015-12-02 17:57 - 2015-11-22 04:54 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ETWCoreUIComponentsResources.dll
    2015-12-02 17:57 - 2015-11-22 04:54 - 00117248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\capimg.sys
    2015-12-02 17:57 - 2015-11-22 04:54 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.V2.dll
    2015-12-02 17:57 - 2015-11-22 04:54 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanprotdim.dll
    2015-12-02 17:57 - 2015-11-22 04:54 - 00044032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsplib.dll
    2015-12-02 17:57 - 2015-11-22 04:54 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
    2015-12-02 17:57 - 2015-11-22 04:54 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\WordBreakers.dll
    2015-12-02 17:57 - 2015-11-22 04:54 - 00028160 _____ (Microsoft Corporation) C:\WINDOWS\system32\nativemap.dll
    2015-12-02 17:57 - 2015-11-22 04:52 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininetlui.dll
    2015-12-02 17:57 - 2015-11-22 04:52 - 00060928 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthTokenBrokerExt.dll
    2015-12-02 17:57 - 2015-11-22 04:52 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
    2015-12-02 17:57 - 2015-11-22 04:52 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapsupdatetask.dll
    2015-12-02 17:57 - 2015-11-22 04:51 - 00157184 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcertinst.exe
    2015-12-02 17:57 - 2015-11-22 04:51 - 00119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll
    2015-12-02 17:57 - 2015-11-22 04:51 - 00072704 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll
    2015-12-02 17:57 - 2015-11-22 04:51 - 00042496 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapstoasttask.dll
    2015-12-02 17:57 - 2015-11-22 04:51 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll
    2015-12-02 17:57 - 2015-11-22 04:50 - 00074240 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssign32.dll
    2015-12-02 17:57 - 2015-11-22 04:49 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
    2015-12-02 17:57 - 2015-11-22 04:49 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll
    2015-12-02 17:57 - 2015-11-22 04:49 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wwanpref.dll
    2015-12-02 17:57 - 2015-11-22 04:46 - 00248832 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserMgrProxy.dll
    2015-12-02 17:57 - 2015-11-22 04:45 - 06572032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanmm.dll
    2015-12-02 17:57 - 2015-11-22 04:45 - 00638464 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
    2015-12-02 17:57 - 2015-11-22 04:45 - 00220672 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
    2015-12-02 17:57 - 2015-11-22 04:45 - 00073728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwancfg.dll
    2015-12-02 17:57 - 2015-11-22 04:44 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosHostClient.dll
    2015-12-02 17:57 - 2015-11-22 04:43 - 00704000 _____ (Microsoft Corporation) C:\WINDOWS\system32\CellularAPI.dll
    2015-12-02 17:57 - 2015-11-22 04:43 - 00382464 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
    2015-12-02 17:57 - 2015-11-22 04:43 - 00342016 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll
    2015-12-02 17:57 - 2015-11-22 04:43 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XblAuthManagerProxy.dll
    2015-12-02 17:57 - 2015-11-22 04:42 - 00589312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApi.dll
    2015-12-02 17:57 - 2015-11-22 04:42 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmmigrator.dll
    2015-12-02 17:57 - 2015-11-22 04:42 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ETWCoreUIComponentsResources.dll
    2015-12-02 17:57 - 2015-11-22 04:42 - 00024064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WordBreakers.dll
    2015-12-02 17:57 - 2015-11-22 04:41 - 01814528 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnidui.dll
    2015-12-02 17:57 - 2015-11-22 04:41 - 00948224 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManager.dll
    2015-12-02 17:57 - 2015-11-22 04:40 - 01056256 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
    2015-12-02 17:57 - 2015-11-22 04:40 - 00465920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanconn.dll
    2015-12-02 17:57 - 2015-11-22 04:40 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininetlui.dll
    2015-12-02 17:57 - 2015-11-22 04:40 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XblAuthTokenBrokerExt.dll
    2015-12-02 17:57 - 2015-11-22 04:39 - 02126848 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
    2015-12-02 17:57 - 2015-11-22 04:39 - 01713664 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRHInproc.dll
    2015-12-02 17:57 - 2015-11-22 04:39 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll
    2015-12-02 17:57 - 2015-11-22 04:39 - 00957440 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
    2015-12-02 17:57 - 2015-11-22 04:39 - 00938496 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
    2015-12-02 17:57 - 2015-11-22 04:39 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
    2015-12-02 17:57 - 2015-11-22 04:39 - 00783360 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
    2015-12-02 17:57 - 2015-11-22 04:39 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinelsa.dll
    2015-12-02 17:57 - 2015-11-22 04:39 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll
    2015-12-02 17:57 - 2015-11-22 04:39 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosStorage.dll
    2015-12-02 17:57 - 2015-11-22 04:39 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
    2015-12-02 17:57 - 2015-11-22 04:38 - 01223168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
    2015-12-02 17:57 - 2015-11-22 04:38 - 01212928 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
    2015-12-02 17:57 - 2015-11-22 04:38 - 00912384 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll
    2015-12-02 17:57 - 2015-11-22 04:38 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptngc.dll
    2015-12-02 17:57 - 2015-11-22 04:38 - 00060928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssign32.dll
    2015-12-02 17:57 - 2015-11-22 04:37 - 02624512 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
    2015-12-02 17:57 - 2015-11-22 04:37 - 01395200 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
    2015-12-02 17:57 - 2015-11-22 04:37 - 00515584 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
    2015-12-02 17:57 - 2015-11-22 04:36 - 01042432 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingOnlineServices.dll
    2015-12-02 17:57 - 2015-11-22 04:34 - 02843136 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll
    2015-12-02 17:57 - 2015-11-22 04:34 - 00345600 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
    2015-12-02 17:57 - 2015-11-22 04:34 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
    2015-12-02 17:57 - 2015-11-22 04:34 - 00166912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserMgrProxy.dll
    2015-12-02 17:57 - 2015-11-22 04:34 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll
    2015-12-02 17:57 - 2015-11-22 04:34 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditBufferTestHook.dll
    2015-12-02 17:57 - 2015-11-22 04:33 - 00205824 _____ (Nokia) C:\WINDOWS\SysWOW64\NmaDirect.dll
    2015-12-02 17:57 - 2015-11-22 04:32 - 00340480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToDevice.dll
    2015-12-02 17:57 - 2015-11-22 04:32 - 00334848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
    2015-12-02 17:57 - 2015-11-22 04:31 - 07199232 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
    2015-12-02 17:57 - 2015-11-22 04:31 - 00470528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApi.dll
    2015-12-02 17:57 - 2015-11-22 04:31 - 00416768 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
    2015-12-02 17:57 - 2015-11-22 04:29 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll
    2015-12-02 17:57 - 2015-11-22 04:28 - 01734656 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
    2015-12-02 17:57 - 2015-11-22 04:28 - 01443328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRHInproc.dll
    2015-12-02 17:57 - 2015-11-22 04:28 - 01387008 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
    2015-12-02 17:57 - 2015-11-22 04:28 - 00948224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll
    2015-12-02 17:57 - 2015-11-22 04:28 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
    2015-12-02 17:57 - 2015-11-22 04:28 - 00793600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll
    2015-12-02 17:57 - 2015-11-22 04:28 - 00784896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll
    2015-12-02 17:57 - 2015-11-22 04:28 - 00686592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
    2015-12-02 17:57 - 2015-11-22 04:28 - 00100864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offlinelsa.dll
    2015-12-02 17:57 - 2015-11-22 04:27 - 03993600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
    2015-12-02 17:57 - 2015-11-22 04:27 - 02049024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
    2015-12-02 17:57 - 2015-11-22 04:27 - 01944576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll
    2015-12-02 17:57 - 2015-11-22 04:27 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll
    2015-12-02 17:57 - 2015-11-22 04:27 - 00241664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptngc.dll
    2015-12-02 17:57 - 2015-11-22 04:27 - 00160768 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll
    2015-12-02 17:57 - 2015-11-22 04:26 - 03355136 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
    2015-12-02 17:57 - 2015-11-22 04:26 - 01139200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
    2015-12-02 17:57 - 2015-11-22 04:26 - 00709120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingOnlineServices.dll
    2015-12-02 17:57 - 2015-11-22 04:26 - 00421888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LogonController.dll
    2015-12-02 17:57 - 2015-11-22 04:25 - 02280448 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
    2015-12-02 17:57 - 2015-11-22 04:25 - 00133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
    2015-12-02 17:57 - 2015-11-22 04:24 - 02647552 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
    2015-12-02 17:57 - 2015-11-22 04:24 - 00245760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll
    2015-12-02 17:57 - 2015-11-22 04:24 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputLocaleManager.dll
    2015-12-02 17:57 - 2015-11-22 04:24 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EditBufferTestHook.dll
    2015-12-02 17:57 - 2015-11-22 04:23 - 05202944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
    2015-12-02 17:57 - 2015-11-22 04:20 - 01860096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll
    2015-12-02 17:57 - 2015-11-22 04:18 - 01505280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
    2015-12-02 17:57 - 2015-11-22 04:18 - 00697856 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToManager.dll
    2015-12-02 17:57 - 2015-11-22 04:18 - 00458752 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToDevice.dll
    2015-12-02 17:57 - 2015-11-22 04:17 - 02680320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
    2015-12-02 17:57 - 2015-11-22 04:17 - 02121216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
    2015-12-02 17:57 - 2015-11-22 04:11 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToManager.dll
    2015-12-02 17:56 - 2015-11-22 05:00 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosResource.dll
    2015-12-02 17:56 - 2015-11-22 04:57 - 00110592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MapControls.dll
    2015-12-02 17:56 - 2015-11-22 04:57 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCoreRes.dll
    2015-12-02 17:56 - 2015-11-22 04:57 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MosTrace.dll
    2015-12-02 17:56 - 2015-11-22 04:57 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MosHost.dll
    2015-12-02 17:56 - 2015-11-22 04:56 - 01268736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
    2015-12-02 17:56 - 2015-11-22 04:54 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlStringsRes.dll
    2015-12-02 17:56 - 2015-11-22 04:48 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosResource.dll
    2015-12-02 17:56 - 2015-11-22 04:45 - 00264192 _____ (Nokia) C:\WINDOWS\system32\NmaDirect.dll
    2015-12-02 17:56 - 2015-11-22 04:45 - 00110592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft-Windows-MapControls.dll
    2015-12-02 17:56 - 2015-11-22 04:45 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCoreRes.dll
    2015-12-02 17:56 - 2015-11-22 04:45 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft-Windows-MosTrace.dll
    2015-12-02 17:56 - 2015-11-22 04:45 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft-Windows-MosHost.dll
    2015-12-02 17:56 - 2015-11-22 04:44 - 01268736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Resources.dll
    2015-12-02 17:56 - 2015-11-22 04:42 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlStringsRes.dll
    2015-12-01 18:58 - 2015-12-01 18:58 - 00249462 _____ C:\Users\Darlene\Desktop\JOSEPH CARELLO.pdf
    2015-11-30 11:57 - 2015-11-30 11:57 - 00052651 _____ C:\Users\Darlene\Desktop\DVD LIBRARY LIST 2013.pdf
    2015-11-30 11:56 - 2015-11-30 11:56 - 00000000 ____D C:\Users\Darlene\Documents\Custom Office Templates
    2015-11-28 17:39 - 2015-12-02 19:44 - 00624087 _____ C:\Users\Darlene\Desktop\submission.pdf
    2015-11-28 14:45 - 2015-11-28 14:45 - 00000000 _____ C:\Users\Darlene\Desktop\TIMONEY_EQUITTED.pdf
    2015-11-28 13:39 - 2015-11-28 13:39 - 00002724 _____ C:\Users\Darlene\Documents\2016 OPENING FOR RIDE VIDEOS.wlmp
    2015-11-28 13:36 - 2015-11-28 13:36 - 02613962 _____ C:\Users\Darlene\Desktop\Paramount Opening Credit.mp4
    2015-11-28 13:34 - 2015-11-28 13:34 - 00652005 _____ C:\Users\Darlene\Desktop\Paramount gulf western company logo!avi - YouTube.mp4
    2015-11-27 11:07 - 2015-11-27 11:07 - 00000543 _____ C:\Users\Darlene\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Desktop.lnk
    2015-11-26 21:14 - 2015-11-26 21:14 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
    2015-11-26 10:46 - 2015-11-26 10:46 - 00000794 _____ C:\Users\Darlene\Documents\Downloads - Shortcut.lnk
    2015-11-26 10:39 - 2015-11-26 10:39 - 00002495 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word 2016.lnk
    2015-11-26 10:39 - 2015-11-26 10:39 - 00002494 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint 2016.lnk
    2015-11-26 10:39 - 2015-11-26 10:39 - 00002458 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access 2016.lnk
    2015-11-26 10:39 - 2015-11-26 10:39 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel 2016.lnk
    2015-11-26 10:39 - 2015-11-26 10:39 - 00002451 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook 2016.lnk
    2015-11-26 10:39 - 2015-11-26 10:39 - 00002445 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher 2016.lnk
    2015-11-26 10:39 - 2015-11-26 10:39 - 00002437 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk
    2015-11-26 10:39 - 2015-11-26 10:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016 Tools
    2015-11-26 10:34 - 2015-11-26 10:34 - 00000000 ____D C:\Program Files\Microsoft Office 15
    2015-11-26 07:19 - 2015-12-20 10:40 - 00000000 ____D C:\ProgramData\ASUS Smart Gesture
    2015-11-25 20:43 - 2015-11-25 19:01 - 00000000 ___DC C:\WINDOWS\Panther
    2015-11-25 20:40 - 2015-11-25 20:40 - 00000000 ____D C:\Windows.old
    2015-11-25 20:39 - 2015-11-25 20:39 - 22572632 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 21125408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 11545088 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 09918976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 02444288 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 02001408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 01063424 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 00969728 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 00911648 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 00809312 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
    2015-11-25 20:39 - 2015-11-25 20:39 - 00803840 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 00791552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 00704352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
    2015-11-25 20:39 - 2015-11-25 20:39 - 00698208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimgapi.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 00675064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 00674816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 00647168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 00630632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
    2015-11-25 20:39 - 2015-11-25 20:39 - 00623616 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneProviders.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 00586208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 00586080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wimgapi.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 00578912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys
    2015-11-25 20:39 - 2015-11-25 20:39 - 00540752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
    2015-11-25 20:39 - 2015-11-25 20:39 - 00536768 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 00523616 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimserv.exe
    2015-11-25 20:39 - 2015-11-25 20:39 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
    2015-11-25 20:39 - 2015-11-25 20:39 - 00516544 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 00511320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 00490496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 00454056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
    2015-11-25 20:39 - 2015-11-25 20:39 - 00408128 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 00405048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 00400896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
    2015-11-25 20:39 - 2015-11-25 20:39 - 00369912 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
    2015-11-25 20:39 - 2015-11-25 20:39 - 00366224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 00365568 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 00334736 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 00334336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.exe
    2015-11-25 20:39 - 2015-11-25 20:39 - 00315904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 00296488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 00286720 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceaccess.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 00275456 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 00227840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\deviceaccess.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 00204800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-AppModelExecEvents.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 00163328 _____ (Microsoft Corporation) C:\WINDOWS\system32\provops.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringservice.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 00122368 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCsp.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 00118624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tdx.sys
    2015-11-25 20:39 - 2015-11-25 20:39 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 00110032 _____ (Microsoft Corporation) C:\WINDOWS\system32\EncDump.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 00092352 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\system32\NFCProvisioningPlugin.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 00088392 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzautoupdate.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 00078336 _____ (Microsoft Corporation) C:\WINDOWS\system32\BarcodeProvisioningPlugin.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 00073360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\remoteaudioendpoint.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppCapture.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringclient.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemovableMediaProvisioningPlugin.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.proxy.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe
    2015-11-25 20:39 - 2015-11-25 20:39 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 00035680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wimmount.sys
    2015-11-25 20:39 - 2015-11-25 20:39 - 00035656 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfpmp.exe
    2015-11-25 20:39 - 2015-11-25 20:39 - 00032040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfpmp.exe
    2015-11-25 20:39 - 2015-11-25 20:39 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringconfigsp.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe
    2015-11-25 20:39 - 2015-11-25 20:39 - 00028160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Provisioning.ProxyStub.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.proxy.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\IcsEntitlementHost.exe
    2015-11-25 20:39 - 2015-11-25 20:39 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\dciman32.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dciman32.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\lpk.dll
    2015-11-25 20:39 - 2015-11-25 20:39 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpk.dll
    2015-11-25 20:37 - 2015-11-25 20:37 - 00008192 _____ C:\WINDOWS\system32\config\userdiff
    2015-11-25 20:35 - 2015-11-25 20:35 - 00000000 ____D C:\Program Files\Reference Assemblies
    2015-11-25 20:35 - 2015-11-25 20:35 - 00000000 ____D C:\Program Files\MSBuild
    2015-11-25 20:35 - 2015-11-25 20:35 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
    2015-11-25 20:35 - 2015-11-25 20:35 - 00000000 ____D C:\Program Files (x86)\MSBuild
    2015-11-25 20:35 - 2015-10-23 20:47 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
    2015-11-25 20:35 - 2015-10-23 20:47 - 00103120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
    2015-11-25 20:35 - 2015-10-23 20:47 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
    2015-11-25 20:35 - 2015-10-23 20:46 - 01166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
    2015-11-25 20:35 - 2015-10-23 20:46 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
    2015-11-25 20:35 - 2015-10-23 20:45 - 00124624 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
    2015-11-25 19:22 - 2015-11-25 19:22 - 00000000 ____D C:\Users\Darlene\AppData\Local\NetworkTiles
    2015-11-25 19:21 - 2015-11-27 08:01 - 00000000 ____D C:\Users\Darlene\AppData\Local\MicrosoftEdge
    2015-11-25 19:14 - 2015-12-13 20:55 - 00002409 _____ C:\Users\Darlene\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
    2015-11-25 19:10 - 2015-11-25 19:10 - 00003628 _____ C:\WINDOWS\System32\Tasks\ASUS Smart Gesture Launcher
    2015-11-25 19:09 - 2015-11-25 19:09 - 00000000 ____D C:\ProgramData\SetupTPDriver
    2015-11-25 19:08 - 2015-11-25 19:08 - 00000000 ____D C:\Users\Darlene\AppData\Local\Publishers
    2015-11-25 19:06 - 2015-11-25 19:06 - 00000000 ____D C:\Users\Darlene\AppData\Local\ActiveSync
    2015-11-25 19:05 - 2015-11-25 19:12 - 00000000 ____D C:\Users\Darlene\AppData\Local\Comms
    2015-11-25 19:04 - 2015-12-20 10:37 - 00000000 __SHD C:\Users\Darlene\IntelGraphicsProfiles
    2015-11-25 19:04 - 2015-11-25 19:04 - 00000020 ___SH C:\Users\Darlene\ntuser.ini
    2015-11-25 19:04 - 2015-11-25 19:04 - 00000000 ____D C:\Users\Darlene\AppData\Local\TileDataLayer
    2015-11-25 18:40 - 2015-11-25 18:40 - 00000000 ____D C:\ProgramData\USOShared
    2015-11-25 18:38 - 2015-11-25 18:38 - 00000000 _SHDL C:\Users\Default\My Documents
    2015-11-25 18:38 - 2015-11-25 18:38 - 00000000 _SHDL C:\Users\Default\Documents\My Videos
    2015-11-25 18:38 - 2015-11-25 18:38 - 00000000 _SHDL C:\Users\Default\Documents\My Pictures
    2015-11-25 18:38 - 2015-11-25 18:38 - 00000000 _SHDL C:\Users\Default\Documents\My Music
    2015-11-25 18:38 - 2015-11-25 18:38 - 00000000 _SHDL C:\Users\Default User\Documents\My Videos
    2015-11-25 18:38 - 2015-11-25 18:38 - 00000000 _SHDL C:\Users\Default User\Documents\My Pictures
    2015-11-25 18:38 - 2015-11-25 18:38 - 00000000 _SHDL C:\Users\Default User\Documents\My Music
    2015-11-25 18:27 - 2015-12-20 10:36 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
    2015-11-25 18:27 - 2015-11-25 18:27 - 00022744 _____ C:\WINDOWS\system32\emptyregdb.dat
    2015-11-25 18:18 - 2015-12-20 10:44 - 00908924 _____ C:\WINDOWS\system32\PerfStringBackup.INI
    2015-11-25 18:03 - 2015-11-25 18:03 - 00001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
    2015-11-25 18:03 - 2015-11-25 18:03 - 00000000 ____D C:\Users\Default\AppData\Roaming\Garmin
    2015-11-25 18:03 - 2015-11-25 18:03 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help
    2015-11-25 18:03 - 2015-11-25 18:03 - 00000000 ____D C:\Users\Default\AppData\Local\Garmin_Ltd._or_its_subsid
    2015-11-25 18:03 - 2015-11-25 18:03 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Garmin
    2015-11-25 18:03 - 2015-11-25 18:03 - 00000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help
    2015-11-25 18:03 - 2015-11-25 18:03 - 00000000 ____D C:\Users\Default User\AppData\Local\Garmin_Ltd._or_its_subsid
    2015-11-25 17:56 - 2015-11-25 17:56 - 00000000 ____D C:\WINDOWS\system32\config\bbimigrate
    2015-11-25 17:52 - 2015-12-13 18:43 - 00000000 ____D C:\Users\Darlene
    2015-11-25 17:52 - 2015-11-25 17:52 - 00000000 _SHDL C:\Users\Darlene\My Documents
    2015-11-25 17:52 - 2015-11-25 17:52 - 00000000 _SHDL C:\Users\Darlene\Documents\My Videos
    2015-11-25 17:52 - 2015-11-25 17:52 - 00000000 _SHDL C:\Users\Darlene\Documents\My Pictures
    2015-11-25 17:52 - 2015-11-25 17:52 - 00000000 _SHDL C:\Users\Darlene\Documents\My Music
    2015-11-25 17:49 - 2015-11-25 17:49 - 00171198 _____ C:\WINDOWS\system32\Drivers\RTWAVES40.dat
    2015-11-25 17:49 - 2015-11-25 17:49 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_DptfDevProc_01011.Wdf
    2015-11-25 17:49 - 2015-11-25 17:49 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_DptfDevPch_01011.Wdf
    2015-11-25 17:49 - 2015-11-25 17:49 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_DptfDevDram_01011.Wdf
    2015-11-25 17:49 - 2015-11-25 17:49 - 00000000 ____H C:\ProgramData\DP45977C.lfl
    2015-11-25 17:49 - 2015-11-25 17:49 - 00000000 ____D C:\WINDOWS\SysWOW64\sda
    2015-11-25 17:49 - 2015-11-25 17:49 - 00000000 ____D C:\WINDOWS\SysWOW64\RTCOM
    2015-11-25 17:49 - 2015-11-25 17:49 - 00000000 ____D C:\Program Files\Realtek
    2015-11-25 17:48 - 2015-12-20 10:37 - 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
    2015-11-25 17:48 - 2015-11-25 17:56 - 00000000 ____D C:\Program Files\Intel
    2015-11-25 17:48 - 2015-11-25 17:48 - 00000200 _____ C:\WINDOWS\system32\{EC94D02F-D200-4428-9531-05AF7F9799CB}.bat
    2015-11-25 17:48 - 2015-07-17 23:58 - 00086528 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.DLL
    2015-11-25 17:48 - 2015-07-17 23:58 - 00082432 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.DLL
    2015-11-25 17:47 - 2015-11-25 17:47 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_TeeDriverx64_01011.Wdf
    2015-11-25 17:47 - 2015-11-25 17:47 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_DptfManager_01011.Wdf
    2015-11-25 17:47 - 2015-10-30 02:17 - 02718208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
    2015-11-25 17:44 - 2015-12-09 17:50 - 00360728 _____ C:\WINDOWS\system32\FNTCACHE.DAT
    2015-11-25 17:18 - 2015-11-25 18:37 - 00009528 _____ C:\WINDOWS\diagwrn.xml
    2015-11-25 17:18 - 2015-11-25 18:37 - 00009528 _____ C:\WINDOWS\diagerr.xml
    2015-11-25 16:51 - 2015-11-25 18:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bluetooth Devices
    2015-11-21 15:16 - 2015-11-27 15:05 - 00000000 ____D C:\Users\Darlene\Desktop\CHRISTMAS TUNES

    ==================== One Month Modified files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2015-12-20 11:30 - 2015-10-30 01:28 - 00000000 ____D C:\Windows
    2015-12-20 11:30 - 2014-08-12 19:23 - 00000000 ____D C:\ProgramData\WRData
    2015-12-20 10:44 - 2015-10-30 02:21 - 00000000 ____D C:\WINDOWS\INF
    2015-12-20 10:44 - 2014-08-13 20:22 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
    2015-12-20 10:41 - 2014-08-12 17:23 - 00000074 _____ C:\Users\Darlene\AppData\Roaming\sp_data.sys
    2015-12-20 10:39 - 2014-08-12 17:24 - 00000000 __RDO C:\Users\Darlene\SkyDrive
    2015-12-20 10:37 - 2015-04-25 05:23 - 00000916 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
    2015-12-20 10:36 - 2015-10-30 01:28 - 00786432 ___SH C:\WINDOWS\system32\config\BBI
    2015-12-20 08:28 - 2014-11-08 10:49 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
    2015-12-20 08:28 - 2014-11-08 10:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
    2015-12-20 08:28 - 2014-11-08 10:48 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
    2015-12-20 07:38 - 2014-08-16 13:23 - 13746688 ___SH C:\Users\Darlene\Desktop\Thumbs.db
    2015-12-20 07:21 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\AppReadiness
    2015-12-20 07:21 - 2014-08-12 18:41 - 00004152 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{EB0981D3-B891-4340-97F0-E9F46E7F6117}
    2015-12-19 12:00 - 2015-05-23 12:57 - 00003544 _____ C:\WINDOWS\System32\Tasks\ASUS Live Update1
    2015-12-19 12:00 - 2015-05-23 12:57 - 00003534 _____ C:\WINDOWS\System32\Tasks\ASUS Live Update2
    2015-12-19 08:29 - 2014-09-13 16:21 - 00000000 ____D C:\Users\Darlene\AppData\Roaming\vlc
    2015-12-19 07:05 - 2015-10-30 02:24 - 00000000 ___HD C:\Program Files\WindowsApps
    2015-12-18 11:18 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\system32\appraiser
    2015-12-18 11:18 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\Provisioning
    2015-12-18 11:18 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\bcastdvr
    2015-12-18 07:57 - 2015-02-26 05:47 - 00045104 ____T (Webroot) C:\WINDOWS\system32\Drivers\wrUrlFlt.sys
    2015-12-17 20:51 - 2015-10-30 02:11 - 00000000 ____D C:\WINDOWS\CbsTemp
    2015-12-17 17:54 - 2015-10-30 02:24 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
    2015-12-17 17:54 - 2014-08-12 20:06 - 00000000 ____D C:\ProgramData\Microsoft Help
    2015-12-17 17:52 - 2013-09-06 15:44 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
    2015-12-17 05:47 - 2014-08-12 18:49 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
    2015-12-16 05:44 - 2014-08-12 19:54 - 00172328 _____ (Webroot) C:\WINDOWS\SysWOW64\WRusr.dll
    2015-12-16 05:44 - 2014-08-12 19:54 - 00107456 _____ (Webroot) C:\WINDOWS\system32\WRusr.dll
    2015-12-13 11:10 - 2015-06-19 18:31 - 00000000 ___RD C:\Users\Darlene\Desktop\BARNS
    2015-12-12 21:26 - 2014-08-20 16:41 - 00000000 ___RD C:\Users\Darlene\Desktop\DEATH CERT
    2015-12-12 16:51 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\system32\NDF
    2015-12-12 16:51 - 2014-09-01 15:25 - 00000000 ____D C:\Users\Darlene\AppData\Local\ElevatedDiagnostics
    2015-12-11 05:43 - 2014-08-12 17:22 - 00000000 ____D C:\Users\Darlene\AppData\Local\Packages
    2015-12-09 07:50 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\system32\oobe
    2015-12-08 20:03 - 2013-09-06 15:46 - 00000000 ____D C:\ProgramData\WildTangent
    2015-12-08 20:03 - 2013-09-06 15:46 - 00000000 ____D C:\Program Files (x86)\WildTangent Games
    2015-12-08 19:44 - 2014-08-13 20:22 - 00003816 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
    2015-12-08 19:40 - 2015-10-25 10:25 - 00000000 ____D C:\Users\Darlene\AppData\Local\TechSmith
    2015-12-08 19:40 - 2015-10-25 10:24 - 00000000 ____D C:\ProgramData\TechSmith
    2015-12-08 19:40 - 2013-12-18 14:55 - 00000000 ____D C:\ProgramData\Package Cache
    2015-12-08 19:27 - 2014-08-12 19:16 - 00000000 ____D C:\WINDOWS\system32\MRT
    2015-12-08 19:21 - 2014-08-12 19:16 - 140158008 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
    2015-12-03 19:48 - 2015-04-25 05:23 - 00003978 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
    2015-12-03 19:48 - 2015-04-25 05:23 - 00003746 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
    2015-12-03 19:48 - 2015-04-25 05:23 - 00000920 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
    2015-12-03 07:11 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\rescache
    2015-12-02 21:54 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform
    2015-11-30 19:33 - 2015-10-30 02:26 - 00826872 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
    2015-11-30 19:33 - 2015-10-30 02:26 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
    2015-11-30 15:49 - 2014-08-16 08:37 - 00000000 ___RD C:\Users\Darlene\Documents\DAR
    2015-11-30 14:35 - 2014-09-13 16:22 - 00000000 ____D C:\Users\Darlene\AppData\Roaming\dvdcss
    2015-11-28 08:06 - 2015-11-08 16:40 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
    2015-11-27 14:51 - 2015-11-01 08:09 - 00000000 ____D C:\Users\Darlene\Desktop\HISTORICAL STUFF
    2015-11-27 14:50 - 2015-11-07 17:04 - 00000000 ____D C:\Users\Darlene\Desktop\BAD PDF'S
    2015-11-27 14:50 - 2015-10-25 11:48 - 00000000 ____D C:\Users\Darlene\Desktop\Email Attachments
    2015-11-26 20:19 - 2014-08-12 20:06 - 00000000 ____D C:\Users\Darlene\AppData\Local\Microsoft Help
    2015-11-26 10:43 - 2014-08-13 20:02 - 00000000 ___RD C:\Users\Darlene\OneDrive
    2015-11-26 10:34 - 2015-10-30 02:24 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
    2015-11-26 07:23 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\appcompat
    2015-11-25 20:43 - 2015-10-30 02:24 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template
    2015-11-25 20:40 - 2015-10-30 01:28 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism
    2015-11-25 20:40 - 2015-10-30 01:28 - 00000000 ____D C:\WINDOWS\system32\Dism
    2015-11-25 20:40 - 2014-09-21 10:48 - 00000469 _____ C:\Users\Darlene\AppData\Roaming\Microsoft\Windows\Start Menu\MyUPMC A Free Online Patient Health Portal.website
    2015-11-25 19:24 - 2015-10-30 02:24 - 00000000 ___RD C:\WINDOWS\DevicesFlow
    2015-11-25 19:10 - 2013-12-18 14:49 - 00000000 ____D C:\Program Files\DIFX
    2015-11-25 19:09 - 2013-09-06 15:45 - 00000000 ____D C:\Program Files (x86)\ASUS
    2015-11-25 19:06 - 2015-10-30 02:24 - 00000000 ___RD C:\WINDOWS\PurchaseDialog
    2015-11-25 19:06 - 2015-10-30 02:24 - 00000000 ___RD C:\WINDOWS\PrintDialog
    2015-11-25 19:06 - 2015-10-30 02:24 - 00000000 ___RD C:\WINDOWS\MiracastView
    2015-11-25 19:05 - 2015-10-30 02:24 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
    2015-11-25 19:05 - 2014-08-12 21:10 - 00000000 __RHD C:\Users\Public\AccountPictures
    2015-11-25 19:04 - 2013-12-18 14:41 - 00000000 ___HD C:\Intel
    2015-11-25 18:40 - 2015-10-30 02:24 - 00000000 ____D C:\ProgramData\USOPrivate
    2015-11-25 18:39 - 2015-10-30 01:28 - 00032768 ___SH C:\WINDOWS\system32\config\ELAM
    2015-11-25 18:38 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase
    2015-11-25 18:31 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\Registration
    2015-11-25 18:27 - 2015-07-18 07:58 - 00002764 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
    2015-11-25 18:27 - 2015-05-23 12:57 - 00002428 _____ C:\WINDOWS\System32\Tasks\Update Checker
    2015-11-25 18:27 - 2014-09-24 04:54 - 00002872 _____ C:\WINDOWS\System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473
    2015-11-25 18:27 - 2014-09-24 04:54 - 00002494 _____ C:\WINDOWS\System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon
    2015-11-25 18:27 - 2014-08-14 19:25 - 00002576 _____ C:\WINDOWS\System32\Tasks\GarminUpdaterTask
    2015-11-25 18:27 - 2014-08-13 18:53 - 00001974 _____ C:\WINDOWS\System32\Tasks\{559BB109-F8DE-4779-87E0-26192DD4A81F}
    2015-11-25 18:27 - 2014-08-12 17:27 - 00002810 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3944082369-795306520-2734861758-1001
    2015-11-25 18:27 - 2013-12-18 15:09 - 00002480 _____ C:\WINDOWS\System32\Tasks\ASUS Patch for Touch Panel
    2015-11-25 18:27 - 2013-12-18 15:06 - 00002748 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3944082369-795306520-2734861758-500
    2015-11-25 18:27 - 2013-12-18 15:02 - 00002272 _____ C:\WINDOWS\System32\Tasks\ASUS P4G
    2015-11-25 18:27 - 2013-12-18 15:02 - 00002188 _____ C:\WINDOWS\System32\Tasks\ASUS USB Charger Plus
    2015-11-25 18:27 - 2013-12-18 15:02 - 00002172 _____ C:\WINDOWS\System32\Tasks\P4GIntlCtrl
    2015-11-25 18:27 - 2013-12-18 15:02 - 00002070 _____ C:\WINDOWS\System32\Tasks\ASUS Splendid ColorU
    2015-11-25 18:27 - 2013-12-18 15:02 - 00002054 _____ C:\WINDOWS\System32\Tasks\ASUS Splendid ACMON
    2015-11-25 18:18 - 2015-10-30 02:24 - 00000000 __RHD C:\Users\Public\Libraries
    2015-11-25 18:05 - 2015-10-30 04:07 - 00000000 ____D C:\WINDOWS\ShellNew
    2015-11-25 18:05 - 2015-10-02 20:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
    2015-11-25 18:05 - 2015-07-29 18:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero
    2015-11-25 18:05 - 2015-04-09 19:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Legacy 8.0
    2015-11-25 18:05 - 2014-10-31 04:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
    2015-11-25 18:05 - 2014-09-13 16:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
    2015-11-25 18:05 - 2014-08-24 12:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
    2015-11-25 18:05 - 2014-08-16 07:12 - 00000000 ____D C:\Users\Darlene\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Garmin
    2015-11-25 18:05 - 2014-08-14 17:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Garmin
    2015-11-25 18:05 - 2014-08-13 20:04 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live
    2015-11-25 18:05 - 2014-08-13 20:04 - 00000000 ____D C:\WINDOWS\en
    2015-11-25 18:05 - 2014-08-13 19:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Picasa 3
    2015-11-25 18:05 - 2014-08-13 19:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IncrediMail
    2015-11-25 18:05 - 2014-08-13 18:56 - 00000000 ____D C:\Users\Darlene\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Web Publishing
    2015-11-25 18:05 - 2014-08-13 18:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Generations
    2015-11-25 18:05 - 2014-08-12 20:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
    2015-11-25 18:05 - 2014-08-12 19:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Webroot SecureAnywhere
    2015-11-25 18:05 - 2013-12-18 14:47 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
    2015-11-25 18:05 - 2013-09-06 15:46 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
    2015-11-25 18:05 - 2013-09-06 15:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS
    2015-11-25 18:03 - 2013-08-22 08:36 - 00000000 ____D C:\Users\Default.migrated
    2015-11-25 18:00 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\system32\spool
    2015-11-25 18:00 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\system32\InputMethod
    2015-11-25 18:00 - 2013-12-18 14:56 - 00000000 ___HD C:\WINDOWS\system32\WLANProfiles
    2015-11-25 18:00 - 2013-08-22 10:36 - 00000000 ____D C:\WINDOWS\system32\WindowsInternal.Inbox.Shared
    2015-11-25 18:00 - 2013-08-22 10:36 - 00000000 ____D C:\WINDOWS\system32\WindowsInternal.Inbox.Media.Shared
    2015-11-25 17:57 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\LiveKernelReports
    2015-11-25 17:57 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\InputMethod
    2015-11-25 17:57 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\Help
    2015-11-25 17:57 - 2015-06-07 15:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JaVaWa
    2015-11-25 17:57 - 2015-05-31 15:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GPSBabel
    2015-11-25 17:57 - 2014-08-23 16:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink Media Suite
    2015-11-25 17:57 - 2014-08-23 14:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON Projector
    2015-11-25 17:57 - 2013-12-18 15:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nuance
    2015-11-25 17:57 - 2013-12-18 14:41 - 00000000 ____D C:\Program Files (x86)\Intel
    2015-11-25 17:57 - 2013-08-22 10:36 - 00000000 ____D C:\WINDOWS\MediaViewer
    2015-11-25 17:57 - 2013-08-22 10:36 - 00000000 ____D C:\WINDOWS\ADFS
    2015-11-25 17:52 - 2015-10-30 01:28 - 00000000 ____D C:\WINDOWS\system32\Sysprep
    2015-11-25 17:44 - 2015-10-30 04:13 - 00000000 ____D C:\WINDOWS\ServiceProfiles
    2015-11-25 17:18 - 2015-10-30 04:42 - 00000000 ___HD C:\$WINDOWS.~BT
    2015-11-23 21:27 - 2014-08-12 20:08 - 00000000 ____D C:\Users\Darlene\AppData\Local\CrashDumps
    2015-11-21 23:09 - 2015-02-25 21:31 - 785039678 _____ C:\WINDOWS\MEMORY.DMP

    ==================== Files in the root of some directories =======

    2014-08-12 19:55 - 2015-12-18 07:59 - 12964920 _____ (Webroot Software, Inc.) C:\Program Files (x86)\Common Files\wruninstall.exe
    2015-06-07 15:34 - 2015-10-25 09:05 - 0000044 _____ () C:\Users\Darlene\AppData\Roaming\jdm.conf
    2014-08-15 20:40 - 2014-08-15 20:40 - 0000021 _____ () C:\Users\Darlene\AppData\Roaming\my_intel.sys
    2014-08-12 17:23 - 2015-12-20 10:41 - 0000074 _____ () C:\Users\Darlene\AppData\Roaming\sp_data.sys
    2015-11-25 17:49 - 2015-11-25 17:49 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
    2013-09-06 15:45 - 2012-09-07 06:40 - 0000256 _____ () C:\ProgramData\SetStretch.cmd
    2013-09-06 15:45 - 2009-07-22 05:04 - 0024576 _____ () C:\ProgramData\SetStretch.exe
    2013-09-06 15:45 - 2012-09-07 06:37 - 0000103 _____ () C:\ProgramData\SetStretch.VBS
    2014-08-23 16:53 - 2014-08-23 16:55 - 0000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
    2014-08-23 16:53 - 2014-08-23 16:53 - 0000107 _____ () C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log

    Some files in TEMP:
    ====================
    C:\Users\Darlene\AppData\Local\Temp\vlc-2.2.1-win32.exe


    ==================== Bamital & volsnap =================

    (There is no automatic fix for files that do not pass verification.)

    C:\WINDOWS\system32\winlogon.exe => File is digitally signed
    C:\WINDOWS\system32\wininit.exe => File is digitally signed
    C:\WINDOWS\explorer.exe => File is digitally signed
    C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
    C:\WINDOWS\system32\svchost.exe => File is digitally signed
    C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
    C:\WINDOWS\system32\services.exe => File is digitally signed
    C:\WINDOWS\system32\User32.dll => File is digitally signed
    C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
    C:\WINDOWS\system32\userinit.exe => File is digitally signed
    C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
    C:\WINDOWS\system32\rpcss.dll => File is digitally signed
    C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
    C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
    C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed


    LastRegBack: 2015-12-20 09:49

    ==================== End of FRST.txt ============================

    Open notepad , Go to Start –> All Programs –> Accessories –> Notepad.
    Please copy the entire contents Inside of the code box below beginning with START and ending with END
    (To do this highlight the contents of the box, right click on it and select copy. Right-click in the open notepad and select Paste).
    Name the file Fixlist, Save it to your desktop where you have FRST/FRST64 or the fix wont work, . Then open up FRST/FRST64 and click on FIX (Not Scan) It won't take long, after your computer reboots you will find a FIXLOG.TXT on your desktop, post it please
     
    Start
    CloseProcesses:
    CreateRestorePoint: 
    HKU\.DEFAULT\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION
    HKU\.DEFAULT\Software\Classes\exefile: "%1" %* <===== ATTENTION
    HKU\S-1-5-19\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION
    HKU\S-1-5-19\Software\Classes\exefile: "%1" %* <===== ATTENTION
    HKU\S-1-5-20\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION
    HKU\S-1-5-20\Software\Classes\exefile: "%1" %* <===== ATTENTION
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\Software\Classes\exefile: "%1" %* <===== ATTENTION
    HKLM\…\Policies\Explorer: [NoViewOnDrive] 0
    HKLM\…\Policies\Explorer: [DisableLocalMachineRun] 0
    HKLM\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
    HKLM\…\Policies\Explorer: [DisableCurrentUserRun] 0
    HKLM\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
    HKLM\…\Policies\Explorer: [NoViewContextMenu] 0
    HKLM\…\Policies\Explorer: [NoShellSearchButton] 0
    HKLM\…\Policies\Explorer: [NoFind] 0
    HKLM\…\Policies\Explorer: [NoFile] 0
    HKLM\…\Policies\Explorer: [HideClock] 0
    HKLM\…\Policies\Explorer: [NoTrayContextMenu] 0
    HKLM\…\Policies\Explorer: [NoTrayItemsDisplay] 0
    HKLM\…\Policies\Explorer: [NoSetFolders] 0
    HKLM\…\Policies\Explorer: [NoDevMgrUpdate] 0
    HKLM\…\Policies\Explorer: [NoSetTaskbar] 0
    HKLM\…\Policies\Explorer: [NoDeletePrinter] 0
    HKLM\…\Policies\Explorer: [NoDFSTab] 0
    HKLM\…\Policies\Explorer: [NoChangeStartMenu] 0
    HKLM\…\Policies\Explorer: [NoLogoff] 0
    HKLM\…\Policies\Explorer: [NoWindowsUpdate] 0
    HKLM\…\Policies\Explorer: [NoEncryptOnMove] 0
    HKLM\…\Policies\Explorer: [NoRunasInstallPrompt] 0
    HKLM\…\Policies\Explorer: [NoResolveSearch] 0
    HKLM\…\Policies\Explorer: [NoSaveSettings] 0
    HKLM\…\Policies\Explorer: [NoHardwareTab] 0
    HKLM\…\Policies\Explorer: [NoStartMenuSubFolders] 0
    HKLM\…\Policies\Explorer: [NoDesktop] 0
    HKU\S-1-5-19\…\Policies\system: [DisableCMD] 0
    HKU\S-1-5-19\…\Policies\system: [NoDispAppearancePage] 0
    HKU\S-1-5-19\…\Policies\system: [NoDispBackgroundPage] 0
    HKU\S-1-5-19\…\Policies\system: [NoDispSettingsPage] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoViewOnDrive] 0
    HKU\S-1-5-19\…\Policies\Explorer: [DisableLocalMachineRun] 0
    HKU\S-1-5-19\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
    HKU\S-1-5-19\…\Policies\Explorer: [DisableCurrentUserRun] 0
    HKU\S-1-5-19\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoViewContextMenu] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoShellSearchButton] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoFind] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoFile] 0
    HKU\S-1-5-19\…\Policies\Explorer: [HideClock] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoTrayContextMenu] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoTrayItemsDisplay] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoSetFolders] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoDevMgrUpdate] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoSetTaskbar] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoDeletePrinter] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoDFSTab] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoChangeStartMenu] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoLogoff] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoWindowsUpdate] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoEncryptOnMove] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoRunasInstallPrompt] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoResolveSearch] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoSaveSettings] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoHardwareTab] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoStartMenuSubFolders] 0
    HKU\S-1-5-20\…\Policies\system: [DisableCMD] 0
    HKU\S-1-5-20\…\Policies\system: [NoDispAppearancePage] 0
    HKU\S-1-5-20\…\Policies\system: [NoDispBackgroundPage] 0
    HKU\S-1-5-20\…\Policies\system: [NoDispSettingsPage] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoViewOnDrive] 0
    HKU\S-1-5-20\…\Policies\Explorer: [DisableLocalMachineRun] 0
    HKU\S-1-5-20\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
    HKU\S-1-5-20\…\Policies\Explorer: [DisableCurrentUserRun] 0
    HKU\S-1-5-20\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoViewContextMenu] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoShellSearchButton] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoFind] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoFile] 0
    HKU\S-1-5-20\…\Policies\Explorer: [HideClock] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoTrayContextMenu] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoTrayItemsDisplay] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoSetFolders] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoDevMgrUpdate] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoSetTaskbar] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoDeletePrinter] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoDFSTab] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoChangeStartMenu] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoLogoff] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoWindowsUpdate] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoEncryptOnMove] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoRunasInstallPrompt] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoResolveSearch] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoSaveSettings] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoHardwareTab] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoStartMenuSubFolders] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\system: [DisableCMD] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\system: [NoDispAppearancePage] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\system: [NoDispBackgroundPage] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\system: [NoDispSettingsPage] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoViewOnDrive] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [DisableLocalMachineRun] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [DisableCurrentUserRun] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoViewContextMenu] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoShellSearchButton] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoFind] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoFile] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [HideClock] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoTrayContextMenu] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoTrayItemsDisplay] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoSetFolders] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoDevMgrUpdate] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoSetTaskbar] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoDeletePrinter] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoDFSTab] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoChangeStartMenu] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoLogoff] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoWindowsUpdate] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoEncryptOnMove] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoRunasInstallPrompt] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoResolveSearch] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoSaveSettings] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoHardwareTab] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoStartMenuSubFolders] 0
    HKU\S-1-5-18\…\Policies\system: [DisableCMD] 0
    HKU\S-1-5-18\…\Policies\system: [NoDispAppearancePage] 0
    HKU\S-1-5-18\…\Policies\system: [NoDispBackgroundPage] 0
    HKU\S-1-5-18\…\Policies\system: [NoDispSettingsPage] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoViewOnDrive] 0
    HKU\S-1-5-18\…\Policies\Explorer: [DisableLocalMachineRun] 0
    HKU\S-1-5-18\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
    HKU\S-1-5-18\…\Policies\Explorer: [DisableCurrentUserRun] 0
    HKU\S-1-5-18\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoViewContextMenu] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoShellSearchButton] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoFind] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoFile] 0
    HKU\S-1-5-18\…\Policies\Explorer: [HideClock] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoTrayContextMenu] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoTrayItemsDisplay] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoSetFolders] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoDevMgrUpdate] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoSetTaskbar] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoDeletePrinter] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoDFSTab] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoChangeStartMenu] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoLogoff] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoWindowsUpdate] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoEncryptOnMove] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoRunasInstallPrompt] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoResolveSearch] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoSaveSettings] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoHardwareTab] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoStartMenuSubFolders] 0
    HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
    EmptyTemp:
    End
    
     
    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    Done….

     

     

    Can you tell me what was going on?

     

     

    Fix result of Farbar Recovery Scan Tool (x64) Version:20-12-2015
    Ran by [removed] (2015-12-20 12:12:42) Run:1
    Running from C:\Users\[removed]\Desktop
    [removed] Boot Mode: Normal
    ==============================================

    fixlist content:
    *****************


    Start
    CloseProcesses:
    CreateRestorePoint:
    HKU\.DEFAULT\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION
    HKU\.DEFAULT\Software\Classes\exefile: "%1" %* <===== ATTENTION
    HKU\S-1-5-19\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION
    HKU\S-1-5-19\Software\Classes\exefile: "%1" %* <===== ATTENTION
    HKU\S-1-5-20\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION
    HKU\S-1-5-20\Software\Classes\exefile: "%1" %* <===== ATTENTION
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\Software\Classes\exefile: "%1" %* <===== ATTENTION
    HKLM\…\Policies\Explorer: [NoViewOnDrive] 0
    HKLM\…\Policies\Explorer: [DisableLocalMachineRun] 0
    HKLM\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
    HKLM\…\Policies\Explorer: [DisableCurrentUserRun] 0
    HKLM\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
    HKLM\…\Policies\Explorer: [NoViewContextMenu] 0
    HKLM\…\Policies\Explorer: [NoShellSearchButton] 0
    HKLM\…\Policies\Explorer: [NoFind] 0
    HKLM\…\Policies\Explorer: [NoFile] 0
    HKLM\…\Policies\Explorer: [HideClock] 0
    HKLM\…\Policies\Explorer: [NoTrayContextMenu] 0
    HKLM\…\Policies\Explorer: [NoTrayItemsDisplay] 0
    HKLM\…\Policies\Explorer: [NoSetFolders] 0
    HKLM\…\Policies\Explorer: [NoDevMgrUpdate] 0
    HKLM\…\Policies\Explorer: [NoSetTaskbar] 0
    HKLM\…\Policies\Explorer: [NoDeletePrinter] 0
    HKLM\…\Policies\Explorer: [NoDFSTab] 0
    HKLM\…\Policies\Explorer: [NoChangeStartMenu] 0
    HKLM\…\Policies\Explorer: [NoLogoff] 0
    HKLM\…\Policies\Explorer: [NoWindowsUpdate] 0
    HKLM\…\Policies\Explorer: [NoEncryptOnMove] 0
    HKLM\…\Policies\Explorer: [NoRunasInstallPrompt] 0
    HKLM\…\Policies\Explorer: [NoResolveSearch] 0
    HKLM\…\Policies\Explorer: [NoSaveSettings] 0
    HKLM\…\Policies\Explorer: [NoHardwareTab] 0
    HKLM\…\Policies\Explorer: [NoStartMenuSubFolders] 0
    HKLM\…\Policies\Explorer: [NoDesktop] 0
    HKU\S-1-5-19\…\Policies\system: [DisableCMD] 0
    HKU\S-1-5-19\…\Policies\system: [NoDispAppearancePage] 0
    HKU\S-1-5-19\…\Policies\system: [NoDispBackgroundPage] 0
    HKU\S-1-5-19\…\Policies\system: [NoDispSettingsPage] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoViewOnDrive] 0
    HKU\S-1-5-19\…\Policies\Explorer: [DisableLocalMachineRun] 0
    HKU\S-1-5-19\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
    HKU\S-1-5-19\…\Policies\Explorer: [DisableCurrentUserRun] 0
    HKU\S-1-5-19\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoViewContextMenu] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoShellSearchButton] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoFind] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoFile] 0
    HKU\S-1-5-19\…\Policies\Explorer: [HideClock] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoTrayContextMenu] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoTrayItemsDisplay] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoSetFolders] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoDevMgrUpdate] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoSetTaskbar] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoDeletePrinter] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoDFSTab] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoChangeStartMenu] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoLogoff] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoWindowsUpdate] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoEncryptOnMove] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoRunasInstallPrompt] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoResolveSearch] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoSaveSettings] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoHardwareTab] 0
    HKU\S-1-5-19\…\Policies\Explorer: [NoStartMenuSubFolders] 0
    HKU\S-1-5-20\…\Policies\system: [DisableCMD] 0
    HKU\S-1-5-20\…\Policies\system: [NoDispAppearancePage] 0
    HKU\S-1-5-20\…\Policies\system: [NoDispBackgroundPage] 0
    HKU\S-1-5-20\…\Policies\system: [NoDispSettingsPage] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoViewOnDrive] 0
    HKU\S-1-5-20\…\Policies\Explorer: [DisableLocalMachineRun] 0
    HKU\S-1-5-20\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
    HKU\S-1-5-20\…\Policies\Explorer: [DisableCurrentUserRun] 0
    HKU\S-1-5-20\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoViewContextMenu] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoShellSearchButton] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoFind] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoFile] 0
    HKU\S-1-5-20\…\Policies\Explorer: [HideClock] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoTrayContextMenu] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoTrayItemsDisplay] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoSetFolders] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoDevMgrUpdate] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoSetTaskbar] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoDeletePrinter] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoDFSTab] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoChangeStartMenu] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoLogoff] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoWindowsUpdate] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoEncryptOnMove] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoRunasInstallPrompt] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoResolveSearch] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoSaveSettings] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoHardwareTab] 0
    HKU\S-1-5-20\…\Policies\Explorer: [NoStartMenuSubFolders] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\system: [DisableCMD] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\system: [NoDispAppearancePage] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\system: [NoDispBackgroundPage] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\system: [NoDispSettingsPage] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoViewOnDrive] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [DisableLocalMachineRun] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [DisableCurrentUserRun] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoViewContextMenu] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoShellSearchButton] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoFind] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoFile] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [HideClock] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoTrayContextMenu] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoTrayItemsDisplay] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoSetFolders] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoDevMgrUpdate] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoSetTaskbar] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoDeletePrinter] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoDFSTab] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoChangeStartMenu] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoLogoff] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoWindowsUpdate] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoEncryptOnMove] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoRunasInstallPrompt] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoResolveSearch] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoSaveSettings] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoHardwareTab] 0
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\…\Policies\Explorer: [NoStartMenuSubFolders] 0
    HKU\S-1-5-18\…\Policies\system: [DisableCMD] 0
    HKU\S-1-5-18\…\Policies\system: [NoDispAppearancePage] 0
    HKU\S-1-5-18\…\Policies\system: [NoDispBackgroundPage] 0
    HKU\S-1-5-18\…\Policies\system: [NoDispSettingsPage] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoViewOnDrive] 0
    HKU\S-1-5-18\…\Policies\Explorer: [DisableLocalMachineRun] 0
    HKU\S-1-5-18\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
    HKU\S-1-5-18\…\Policies\Explorer: [DisableCurrentUserRun] 0
    HKU\S-1-5-18\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoViewContextMenu] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoShellSearchButton] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoFind] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoFile] 0
    HKU\S-1-5-18\…\Policies\Explorer: [HideClock] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoTrayContextMenu] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoTrayItemsDisplay] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoSetFolders] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoDevMgrUpdate] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoSetTaskbar] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoDeletePrinter] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoDFSTab] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoChangeStartMenu] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoLogoff] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoWindowsUpdate] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoEncryptOnMove] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoRunasInstallPrompt] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoResolveSearch] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoSaveSettings] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoHardwareTab] 0
    HKU\S-1-5-18\…\Policies\Explorer: [NoStartMenuSubFolders] 0
    HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
    EmptyTemp:
    End


    *****************

    Processes closed successfully.
    Restore point was successfully created.
    "HKU\.DEFAULT\Software\Classes\exefile" => key removed successfully
    "HKU\.DEFAULT\Software\Classes\.exe" => key removed successfully
    HKU\.DEFAULT\Software\Classes\exefile => key not found.
    "HKU\S-1-5-19\Software\Classes\exefile" => key removed successfully
    "HKU\S-1-5-19\Software\Classes\.exe" => key removed successfully
    HKU\S-1-5-19\Software\Classes\exefile => key not found.
    "HKU\S-1-5-20\Software\Classes\exefile" => key removed successfully
    "HKU\S-1-5-20\Software\Classes\.exe" => key removed successfully
    HKU\S-1-5-20\Software\Classes\exefile => key not found.
    "HKU\S-1-5-21-3944082369-795306520-2734861758-1001\Software\Classes\exefile" => key removed successfully
    "HKU\S-1-5-21-3944082369-795306520-2734861758-1001\Software\Classes\.exe" => key removed successfully
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\Software\Classes\exefile => key not found.
    HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoViewOnDrive => value removed successfully
    HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableLocalMachineRun => value removed successfully
    HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableLocalMachineRunOnce => value removed successfully
    HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableCurrentUserRun => value removed successfully
    HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableCurrentUserRunOnce => value removed successfully
    HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoViewContextMenu => value removed successfully
    HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoShellSearchButton => value removed successfully
    HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFind => value removed successfully
    HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFile => value removed successfully
    HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\HideClock => value removed successfully
    HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoTrayContextMenu => value removed successfully
    HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoTrayItemsDisplay => value removed successfully
    HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSetFolders => value removed successfully
    HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDevMgrUpdate => value removed successfully
    HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSetTaskbar => value removed successfully
    HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDeletePrinter => value removed successfully
    HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDFSTab => value removed successfully
    HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoChangeStartMenu => value removed successfully
    HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoLogoff => value removed successfully
    HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoWindowsUpdate => value removed successfully
    HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoEncryptOnMove => value removed successfully
    HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoRunasInstallPrompt => value removed successfully
    HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoResolveSearch => value removed successfully
    HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSaveSettings => value removed successfully
    HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoHardwareTab => value removed successfully
    HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoStartMenuSubFolders => value removed successfully
    HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDesktop => value removed successfully
    HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\system\\DisableCMD => value removed successfully
    HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispAppearancePage => value removed successfully
    HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispBackgroundPage => value removed successfully
    HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispSettingsPage => value removed successfully
    HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoViewOnDrive => value removed successfully
    HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableLocalMachineRun => value removed successfully
    HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableLocalMachineRunOnce => value removed successfully
    HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableCurrentUserRun => value removed successfully
    HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableCurrentUserRunOnce => value removed successfully
    HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoViewContextMenu => value removed successfully
    HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoShellSearchButton => value removed successfully
    HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFind => value removed successfully
    HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFile => value removed successfully
    HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\HideClock => value removed successfully
    HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoTrayContextMenu => value removed successfully
    HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoTrayItemsDisplay => value removed successfully
    HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSetFolders => value removed successfully
    HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDevMgrUpdate => value removed successfully
    HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSetTaskbar => value removed successfully
    HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDeletePrinter => value removed successfully
    HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDFSTab => value removed successfully
    HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoChangeStartMenu => value removed successfully
    HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoLogoff => value removed successfully
    HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoWindowsUpdate => value removed successfully
    HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoEncryptOnMove => value removed successfully
    HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoRunasInstallPrompt => value removed successfully
    HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoResolveSearch => value removed successfully
    HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSaveSettings => value removed successfully
    HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoHardwareTab => value removed successfully
    HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoStartMenuSubFolders => value removed successfully
    HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\system\\DisableCMD => value removed successfully
    HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispAppearancePage => value removed successfully
    HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispBackgroundPage => value removed successfully
    HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispSettingsPage => value removed successfully
    HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoViewOnDrive => value removed successfully
    HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableLocalMachineRun => value removed successfully
    HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableLocalMachineRunOnce => value removed successfully
    HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableCurrentUserRun => value removed successfully
    HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableCurrentUserRunOnce => value removed successfully
    HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoViewContextMenu => value removed successfully
    HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoShellSearchButton => value removed successfully
    HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFind => value removed successfully
    HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFile => value removed successfully
    HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\HideClock => value removed successfully
    HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoTrayContextMenu => value removed successfully
    HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoTrayItemsDisplay => value removed successfully
    HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSetFolders => value removed successfully
    HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDevMgrUpdate => value removed successfully
    HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSetTaskbar => value removed successfully
    HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDeletePrinter => value removed successfully
    HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDFSTab => value removed successfully
    HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoChangeStartMenu => value removed successfully
    HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoLogoff => value removed successfully
    HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoWindowsUpdate => value removed successfully
    HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoEncryptOnMove => value removed successfully
    HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoRunasInstallPrompt => value removed successfully
    HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoResolveSearch => value removed successfully
    HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSaveSettings => value removed successfully
    HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoHardwareTab => value removed successfully
    HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoStartMenuSubFolders => value removed successfully
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\Software\Microsoft\Windows\CurrentVersion\Policies\system\\DisableCMD => value removed successfully
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispAppearancePage => value removed successfully
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispBackgroundPage => value removed successfully
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispSettingsPage => value removed successfully
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoViewOnDrive => value removed successfully
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableLocalMachineRun => value removed successfully
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableLocalMachineRunOnce => value removed successfully
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableCurrentUserRun => value removed successfully
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableCurrentUserRunOnce => value removed successfully
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoViewContextMenu => value removed successfully
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoShellSearchButton => value removed successfully
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFind => value removed successfully
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFile => value removed successfully
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\HideClock => value removed successfully
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoTrayContextMenu => value removed successfully
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoTrayItemsDisplay => value removed successfully
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSetFolders => value removed successfully
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDevMgrUpdate => value removed successfully
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSetTaskbar => value removed successfully
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDeletePrinter => value removed successfully
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDFSTab => value removed successfully
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoChangeStartMenu => value removed successfully
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoLogoff => value removed successfully
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoWindowsUpdate => value removed successfully
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoEncryptOnMove => value removed successfully
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoRunasInstallPrompt => value removed successfully
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoResolveSearch => value removed successfully
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSaveSettings => value removed successfully
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoHardwareTab => value removed successfully
    HKU\S-1-5-21-3944082369-795306520-2734861758-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoStartMenuSubFolders => value removed successfully
    HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\system\\DisableCMD => value removed successfully
    HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispAppearancePage => value removed successfully
    HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispBackgroundPage => value removed successfully
    HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispSettingsPage => value removed successfully
    HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoViewOnDrive => value removed successfully
    HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableLocalMachineRun => value removed successfully
    HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableLocalMachineRunOnce => value removed successfully
    HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableCurrentUserRun => value removed successfully
    HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableCurrentUserRunOnce => value removed successfully
    HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoViewContextMenu => value removed successfully
    HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoShellSearchButton => value removed successfully
    HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFind => value removed successfully
    HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFile => value removed successfully
    HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\HideClock => value removed successfully
    HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoTrayContextMenu => value removed successfully
    HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoTrayItemsDisplay => value removed successfully
    HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSetFolders => value removed successfully
    HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDevMgrUpdate => value removed successfully
    HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSetTaskbar => value removed successfully
    HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDeletePrinter => value removed successfully
    HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDFSTab => value removed successfully
    HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoChangeStartMenu => value removed successfully
    HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoLogoff => value removed successfully
    HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoWindowsUpdate => value removed successfully
    HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoEncryptOnMove => value removed successfully
    HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoRunasInstallPrompt => value removed successfully
    HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoResolveSearch => value removed successfully
    HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSaveSettings => value removed successfully
    HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoHardwareTab => value removed successfully
    HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoStartMenuSubFolders => value removed successfully
    "HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully
    EmptyTemp: => 4.6 GB temporary data Removed.


    The system needed a reboot.

    ==== End of Fixlog 12:22:15 ====

    It looked like something changed all your permissions, not sure what did it but your fine now in that department

     

     

    ESET Online Scanner
    I'd like us to scan your machine with ESET OnlineScan
     
    *Note
    It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
    Please don't go surfing while your resident protection is disabled!
    Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.
     
     
    •  
    • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
    • Click the [external image: esetOnline.png] button.
    • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
      •  
    • Click on [external image: esetSmartInstall.png] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: esetSmartInstallDesktopIcon.png] icon on your desktop.
     
    • Check [external image: esetAcceptTerms.png]
    • Click the [external image: esetStart.png] button.
    • Accept any security warnings from your browser.
    • Check [external image: esetScanArchives.png]
    • Make sure that the option "Remove found threats" is Unchecked
    • Push the Start button.
    • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
    • When the scan completes, push [external image: esetListThreats.png]
    • Push [external image: esetExport.png], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
    • Push the [external image: esetBack.png] button.
    • Push [external image: esetFinish.png]
    Please make sure you include the following items in your next post:
    The log that was produced after running ESET Online Scanner.
     

    oops!  I think I forgot to uncheck "Remove found threats"…there were 4 threats, and it cleaned and removed them.

     

    Is there any way to get it after the fact?

     

    dar

    Morning Darlene,

     

    I think there gone and unless it created problems I wouldn't worry about them. Did you by chance save the log for me to see ?

     

     

    How is your system behaving now ?

    Morning!

     

    My system is working fine, nothing did show it's ugly face, so I guess I was lucky I acted so quickly!!

     

    It did not produce any log, as I did not see any List threats, as they were on the screen, but nothing to produce any log….weird!  I do not have any log.  Altho when I read them, I remember a win32 on the screen 4 times, and adware listed.  That is all I remember.

     

    I'm so glad this was eventless!!!

     

    Thank you for your help!

     

    dar

    Yep, looks like you squeaked by. You have the latest version of Malwarebytes, I would suggest upgrading to the Premium version, it will help stop threats like this , the cost is minimal and worth every dime, I believe somewhere around $25, but the upgrade is entirely up to you.

     

     

     I am going to leave this thread open for you for a few days so if any problems post back and let me know. A Merry Christmas to you and your family

     

    Please download DelFix and save the file to your Desktop.
     
    [external image: DelFix_zps139e2ea1.jpg]
     
    •  
    • Windows XP Double Click DelFix.exe to run the program. 
    • Windows Vista > Win 7 > Win 8 Right Click on DelFix.exe and select RUN AS ADMINISTRATOR 
    • Checkmark " Remove Disinfection Tools"
    • Click the Run button
     
     
    This will remove the specialised tools we used to clean your system. Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually
     
     
     
     
    So How did I get infected in the first place <– Some reading for you to keep yourself safe online
     
     
    Safe Surfn
    Ken

     

    Good Morning Darlene

     

    First go into your downloads folder and delete everything in that folder but not the downloads folder itself.

     

    As far as Delfix , some Antivirus programs will flag some of our tools and scanners as bad when in reality there not, the only way around it is to disable Webroot

    https://community.webroot.com/t5/Announcements-and-Release-Notes/quot-Temporary-quot-disable-Webroot/td-p/144653

     

    Or you can just  look for FRST, any fixlogs or Frst and additions logs and just drag them to the trash.

    Ask AI

    AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

    Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI