This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Laptop restarts in airplane mode when i try to ShutDown. Will not shu

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

First, hello and thank you.

 

When i try to shut down my computer it restarts every time.  Usually it restarts in airplane mode.  i reset the laptop, using the tool provided Recovery menu but the issue continued. I've had a lot of success with you all in the past so I'm turning to you once again.  As directed, I downloaded aswMBR and FRST.  I tried to run aswMBR twice but got a blue screen and restart both times.  I provided the FRST log below.

 

Thank you again.

 

UPDATED 2017-12-03:

Got aswMBR to run, i think.

kl

 

ASWMBR:

 

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2017-12-03 13:58:39
—————————–
13:58:39.517    OS Version: Windows x64 6.2.9200
13:58:39.517    Number of processors: 4 586 0x4E03
13:58:39.517    ComputerName: THUNDERBOLT2  UserName: Kevin
13:58:41.267    Initialize success
13:58:41.298    VM: initialized successfully
13:58:41.298    VM: Intel CPU supported
13:58:47.469    VM: not used
14:00:27.156    AVAST engine defs: 17030301
14:00:42.668    The log file has been saved successfully to "C:\Users\Kevin Lenertz\Desktop\What the Tech 12-2017\aswMBR.txt"

 

FRST.txt

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 30-11-2017
Ran by [removed] (administrator) on THUNDERBOLT2 (01-12-2017 21:11:34)
Running from C:\Users\[removed]\Desktop
[removed] Platform: Windows 10 Home Version 1709 16299.64 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Windows\System32\WerFault.exe
(Microsoft Corporation) C:\Windows\System32\provtool.exe
(Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\k120836.inf_amd64_ccaf7e7e1e972b78\igfxCUIService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\AVGSvc.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel Corporation) C:\Windows\System32\ibtsiva.exe
() C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
() C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
(Waves Audio Ltd.) C:\Program Files\Waves\MaxxAudio\WavesSysSvc64.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\k120836.inf_amd64_ccaf7e7e1e972b78\igfxEM.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\x64\aswidsagenta.exe
(Dell Inc.) C:\Program Files\Dell\QuickSet\quickset.exe
(Waves Audio Ltd.) C:\Program Files\Waves\MaxxAudio\WavesSvc64.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avguix.exe
Failed to access process -> quickset.exe
(Microsoft Corporation) C:\Windows\System32\WerFault.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\AVGUI.exe
(CyberLink) C:\Program Files (x86)\CyberLink\CyberLink Media Suite\Power2Go8\CLMLSvc_P2G8.exe
() C:\Program Files (x86)\Dropbox\DropboxOEM\DropboxOEM.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Dell Inc.) C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe
(Dell Inc.) C:\Program Files (x86)\Dell Customer Connect\DCCService.exe
(Dell) C:\Program Files\Dell\Dell Foundation Services\DFSSvc.exe
(Dell Inc.) C:\Program Files\Dell\Dell Help & Support\MDLCSvc.exe
(Dell) C:\Program Files\Dell\Product Registration\PRSvc.exe
(Dell Products, LP.) C:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe
(Dell) C:\Program Files\Dell\Dell Foundation Services\DFS.Common.Agent.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\…\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [630168 2017-09-29] (Microsoft Corporation)
HKLM\…\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9226752 2017-05-04] (Realtek Semiconductor)
HKLM\…\Run: [RtHDVBg_MAXX6] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1485312 2017-05-04] (Realtek Semiconductor)
HKLM\…\Run: [RtHDVBg_PushButton] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1485312 2017-05-04] (Realtek Semiconductor)
HKLM\…\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [322472 2015-06-23] (Intel Corporation)
HKLM\…\Run: [QuickSet] => c:\Program Files\Dell\QuickSet\QuickSet.exe [5786576 2015-06-24] (Dell Inc.)
HKLM\…\Run: [WavesSvc] => C:\Program Files\Waves\MaxxAudio\WavesSvc64.exe [611248 2015-05-26] (Waves Audio Ltd.)
HKLM\…\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe [239592 2017-10-31] (AVG Technologies CZ, s.r.o.)
HKLM\…\Run: [AVGUI.exe] => C:\Program Files (x86)\AVG\Antivirus\AvLaunch.exe [302744 2017-11-29] (AVG Technologies CZ, s.r.o.)
Startup: C:\Users\Kevin Lenertz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Monitor Ink Alerts - HP Officejet 6500 E710a-f.lnk [2017-11-19]
ShortcutTarget: Monitor Ink Alerts - HP Officejet 6500 E710a-f.lnk -> C:\Program Files\HP\HP Officejet 6500 E710a-f\bin\HPStatusBL.dll (No File)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{7cd8c78c-fcb3-4106-8b76-e4f2041c875f}: [DhcpNameServer] 192.168.1.254

Internet Explorer:
==================
HKU\S-1-5-21-914164008-461376372-368114211-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://mysearch.avg.com/?cid=%7BEC3E0E9B-0CCC-4DC9-8FEE-A49F2D7D2241%7D∣=30dc798aba5047ccb877a945fecc4f1d-755cdf6c1f988ce36c8cd1b6bc64b36ab09dd6bd⟨=en&ds;=AVG&coid;=avgtbavg&cmpid;=0516tb≺=fr&d;=2015-11-05%2022:59:35&v;=4.3.1.831&pid;=wtu&sg;=&sap;=hp
HKU\S-1-5-21-914164008-461376372-368114211-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://dell15.msn.com/?pc=DCTE
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2017-12-01] (Microsoft Corporation)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2017-12-01] (Microsoft Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2017-12-01] (Microsoft Corporation)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2017-12-01] (Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-12-01] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-12-01] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-12-01] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-12-01] (Microsoft Corporation)

FireFox:
========
FF DefaultProfile: 04zcreyr.default
FF ProfilePath: C:\Users\Kevin Lenertz\AppData\Roaming\Mozilla\Firefox\Profiles\04zcreyr.default [2017-12-01]
FF Homepage: Mozilla\Firefox\Profiles\04zcreyr.default -> hxxps://www.wwdb.com
FF Extension: (Disable Media WMF NV12 format) - C:\Users\Kevin Lenertz\AppData\Roaming\Mozilla\Firefox\Profiles\04zcreyr.default\features\{1aacadad-9231-4574-99e0-162262ec50ee}\[removed] [2017-11-29] [Lagacy]
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.68 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2015-04-21] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2015-04-21] (Intel Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2017-12-01] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2017-12-01] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-29] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-29] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-11-04] (Adobe Systems Inc.)

Chrome:
=======
CHR HKLM-x32\…\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [mbckjcfnjmoiinpgddefodcighgikkgn] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AVG Antivirus; C:\Program Files (x86)\AVG\Antivirus\AVGSvc.exe [282536 2017-11-29] (AVG Technologies CZ, s.r.o.)
R3 avgbIDSAgent; C:\Program Files (x86)\AVG\Antivirus\x64\aswidsagenta.exe [7600584 2017-11-29] (AVG Technologies CZ, s.r.o.)
R2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [1428656 2017-10-31] (AVG Technologies CZ, s.r.o.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [8063664 2017-11-22] (Microsoft Corporation)
S2 DDVCollectorSvcApi; C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe [208760 2017-07-27] (Dell Inc.)
S2 DDVDataCollector; C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe [3294584 2017-07-27] (Dell Inc.)
R2 DDVRulesProcessor; C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe [217464 2017-07-27] (Dell Inc.)
R2 Dell Customer Connect; C:\Program Files (x86)\Dell Customer Connect\DCCService.exe [130936 2017-09-19] (Dell Inc.)
R2 Dell Foundation Services; C:\Program Files\Dell\Dell Foundation Services\DFSSvc.exe [119656 2016-01-15] (Dell)
R2 Dell Help & Support; C:\Program Files\Dell\Dell Help & Support\MDLCSvc.exe [40976 2017-09-18] (Dell Inc.)
R2 Dell Product Registration; C:\Program Files\Dell\Product Registration\PRSvc.exe [32104 2016-01-25] (Dell)
R2 DellUpdate; C:\Program Files (x86)\Dell Update\DellUpService.exe [230248 2017-05-01] (Dell Inc.)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [18856 2015-06-23] (Intel Corporation)
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [881152 2015-05-22] (Intel(R) Corporation)
S3 Intel(R) Security Assist; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe [335872 2015-05-19] (Intel Corporation) [File not signed]
R2 isaHelperSvc; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe [7680 2015-05-19] () [File not signed]
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [223520 2015-07-10] (Intel Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [268704 2017-03-21] ()
R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [253776 2014-04-14] ()
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [324608 2017-05-04] (Realtek Semiconductor)
R2 SupportAssistAgent; C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [53208 2017-09-22] (Dell Inc.)
R2 WavesSysSvc; C:\Program Files\Waves\MaxxAudio\WavesSysSvc64.exe [564144 2015-05-26] (Waves Audio Ltd.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [355304 2017-09-29] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [105944 2017-09-29] (Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3750304 2017-03-21] (Intel® Corporation)
R2 ibtsiva; %SystemRoot%\system32\ibtsiva [X]

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 avgArPot; C:\WINDOWS\System32\drivers\avgArPot.sys [176000 2017-11-29] (AVG Technologies CZ, s.r.o.)
R1 avgbdisk; C:\WINDOWS\System32\drivers\avgbdiska.sys [166624 2017-11-29] (AVG Technologies CZ, s.r.o.)
R1 avgbidsdriver; C:\WINDOWS\System32\drivers\avgbidsdrivera.sys [314640 2017-11-29] (AVG Technologies CZ, s.r.o.)
R0 avgbidsh; C:\WINDOWS\System32\drivers\avgbidsha.sys [192584 2017-11-29] (AVG Technologies CZ, s.r.o.)
R0 avgblog; C:\WINDOWS\System32\drivers\avgbloga.sys [336896 2017-11-29] (AVG Technologies CZ, s.r.o.)
R0 avgbuniv; C:\WINDOWS\System32\drivers\avgbuniva.sys [51336 2017-11-29] (AVG Technologies CZ, s.r.o.)
S3 avgHwid; C:\WINDOWS\System32\drivers\avgHwid.sys [39424 2017-11-29] (AVG Technologies CZ, s.r.o.)
R2 avgMonFlt; C:\WINDOWS\System32\drivers\avgMonFlt.sys [140704 2017-11-29] (AVG Technologies CZ, s.r.o.)
R1 avgRdr; C:\WINDOWS\System32\drivers\avgRdr2.sys [102792 2017-11-29] (AVG Technologies CZ, s.r.o.)
R0 avgRvrt; C:\WINDOWS\System32\drivers\avgRvrt.sys [76832 2017-11-29] (AVG Technologies CZ, s.r.o.)
R1 avgSnx; C:\WINDOWS\System32\drivers\avgSnx.sys [1018648 2017-11-29] (AVG Technologies CZ, s.r.o.)
R1 avgSP; C:\WINDOWS\System32\drivers\avgSP.sys [447800 2017-11-29] (AVG Technologies CZ, s.r.o.)
R2 avgStm; C:\WINDOWS\System32\drivers\avgStm.sys [196392 2017-11-29] (AVG Technologies CZ, s.r.o.)
R0 avgVmm; C:\WINDOWS\System32\drivers\avgVmm.sys [356880 2017-11-29] (AVG Technologies CZ, s.r.o.)
R1 CLVirtualDrive; C:\WINDOWS\system32\DRIVERS\CLVirtualDrive.sys [91912 2013-11-12] (CyberLink)
R3 DDDriver; C:\WINDOWS\system32\drivers\DDDriver64Dcsa.sys [32960 2017-07-27] (Dell Inc.)
R3 DellProf; C:\WINDOWS\system32\drivers\DellProf.sys [32568 2017-07-27] (Dell Computer Corporation)
R3 DellRbtn; C:\WINDOWS\System32\drivers\DellRbtn.sys [19440 2015-05-08] (OSR Open Systems Resources, Inc.)
S3 iaLPSS2_GPIO2; C:\WINDOWS\System32\drivers\iaLPSS2_GPIO2.sys [84264 2015-06-16] (Intel Corporation)
R3 ibtusb; C:\WINDOWS\system32\DRIVERS\ibtusb.sys [230144 2016-11-11] (Intel Corporation)
R3 NETwNb64; C:\WINDOWS\System32\drivers\Netwbw02.sys [3517696 2017-04-13] (Intel Corporation)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [886528 2015-05-29] (Realtek )
R3 RTSUER; C:\WINDOWS\system32\Drivers\RtsUer.sys [402136 2015-05-27] (Realsil Semiconductor Corporation)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44608 2017-09-29] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [309144 2017-09-29] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [119192 2017-09-29] (Microsoft Corporation)
R3 WirelessKeyboardFilter; C:\WINDOWS\System32\drivers\WirelessKeyboardFilter.sys [49896 2016-07-22] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-12-01 21:11 - 2017-12-01 21:12 - 000016550 _____ C:\Users\Kevin Lenertz\Desktop\FRST.txt
2017-12-01 21:11 - 2017-12-01 21:11 - 000000000 ____D C:\FRST
2017-12-01 21:10 - 2017-12-01 21:10 - 002391552 _____ (Farbar) C:\Users\Kevin Lenertz\Desktop\FRST64.exe
2017-12-01 21:07 - 2017-12-01 21:07 - 000000000 _____ C:\WINDOWS\Minidump\120117-29531-01.dmp
2017-12-01 21:02 - 2017-12-01 21:07 - 732877811 _____ C:\WINDOWS\MEMORY.DMP
2017-12-01 21:02 - 2017-12-01 21:07 - 000000000 ____D C:\WINDOWS\Minidump
2017-12-01 21:02 - 2017-12-01 21:02 - 000000000 _____ C:\WINDOWS\Minidump\120117-32515-01.dmp
2017-12-01 20:59 - 2017-12-01 21:00 - 005198336 _____ (AVAST Software) C:\Users\Kevin Lenertz\Desktop\aswMBR.exe
2017-12-01 20:54 - 2017-12-01 20:54 - 000000000 ___HD C:\OneDriveTemp
2017-12-01 20:51 - 2017-12-01 20:51 - 000000000 ____D C:\Users\Kevin Lenertz\AppData\Roaming\Skype
2017-12-01 20:49 - 2017-12-01 20:49 - 000002536 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive for Business.lnk
2017-12-01 20:49 - 2017-12-01 20:49 - 000002500 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype for Business 2016.lnk
2017-12-01 20:49 - 2017-12-01 20:49 - 000002495 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word 2016.lnk
2017-12-01 20:49 - 2017-12-01 20:49 - 000002494 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint 2016.lnk
2017-12-01 20:49 - 2017-12-01 20:49 - 000002458 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access 2016.lnk
2017-12-01 20:49 - 2017-12-01 20:49 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel 2016.lnk
2017-12-01 20:49 - 2017-12-01 20:49 - 000002451 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook 2016.lnk
2017-12-01 20:49 - 2017-12-01 20:49 - 000002445 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher 2016.lnk
2017-12-01 20:49 - 2017-12-01 20:49 - 000002437 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk
2017-12-01 20:40 - 2017-12-01 20:40 - 000000000 ____D C:\Program Files\Microsoft Office 15
2017-12-01 20:15 - 2017-12-01 20:15 - 000000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2017-11-29 00:42 - 2017-11-29 00:42 - 000000000 ____D C:\Users\Kevin Lenertz\AppData\Local\Google
2017-11-29 00:32 - 2017-11-29 00:42 - 000002274 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-11-29 00:32 - 2017-11-29 00:42 - 000002262 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-11-29 00:31 - 2017-11-29 00:36 - 000003416 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2017-11-29 00:31 - 2017-11-29 00:36 - 000003292 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2017-11-29 00:30 - 2017-11-29 00:32 - 000000000 ____D C:\Program Files (x86)\Google
2017-11-29 00:30 - 2017-11-29 00:30 - 000004562 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2017-11-29 00:29 - 2017-11-29 00:29 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2017-11-29 00:29 - 2017-11-29 00:29 - 000000000 ____D C:\Program Files (x86)\Adobe
2017-11-29 00:28 - 2017-11-29 01:13 - 000000000 ____D C:\ProgramData\Adobe
2017-11-29 00:27 - 2017-12-01 20:36 - 000000000 ____D C:\Users\Kevin Lenertz\AppData\Local\Adobe
2017-11-29 00:27 - 2017-11-29 00:27 - 000447800 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgSP.sys
2017-11-29 00:27 - 2017-11-29 00:27 - 000004008 _____ C:\WINDOWS\System32\Tasks\Antivirus Emergency Update
2017-11-29 00:27 - 2017-11-29 00:27 - 000002123 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG AntiVirus FREE.lnk
2017-11-29 00:27 - 2017-11-29 00:27 - 000000000 ____D C:\Users\Kevin Lenertz\AppData\Roaming\AVG
2017-11-29 00:27 - 2017-11-29 00:26 - 001018648 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgSnx.sys
2017-11-29 00:27 - 2017-11-29 00:26 - 000356880 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgVmm.sys
2017-11-29 00:27 - 2017-11-29 00:26 - 000336896 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgbloga.sys
2017-11-29 00:27 - 2017-11-29 00:26 - 000314640 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgbidsdrivera.sys
2017-11-29 00:27 - 2017-11-29 00:26 - 000196392 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgStm.sys
2017-11-29 00:27 - 2017-11-29 00:26 - 000192584 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgbidsha.sys
2017-11-29 00:27 - 2017-11-29 00:26 - 000176000 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgArPot.sys
2017-11-29 00:27 - 2017-11-29 00:26 - 000166624 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgbdiska.sys
2017-11-29 00:27 - 2017-11-29 00:26 - 000140704 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgMonFlt.sys
2017-11-29 00:27 - 2017-11-29 00:26 - 000102792 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgRdr2.sys
2017-11-29 00:27 - 2017-11-29 00:26 - 000076832 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgRvrt.sys
2017-11-29 00:27 - 2017-11-29 00:26 - 000051336 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgbuniva.sys
2017-11-29 00:27 - 2017-11-29 00:26 - 000039424 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgHwid.sys
2017-11-29 00:26 - 2017-11-29 00:26 - 000366288 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\avgBoot.exe
2017-11-29 00:23 - 2017-12-01 04:39 - 000003668 _____ C:\WINDOWS\System32\Tasks\AVG EUpdate Task
2017-11-29 00:23 - 2017-11-29 00:25 - 000000000 ____D C:\Program Files (x86)\AVG
2017-11-29 00:22 - 2017-11-29 02:01 - 000000000 ____D C:\ProgramData\Avg
2017-11-29 00:22 - 2017-11-29 00:27 - 000000000 ____D C:\Users\Kevin Lenertz\AppData\Local\Mozilla
2017-11-29 00:22 - 2017-11-29 00:27 - 000000000 ____D C:\Users\Kevin Lenertz\AppData\Local\Avg
2017-11-29 00:22 - 2017-11-29 00:24 - 000000000 ____D C:\Users\Kevin Lenertz\AppData\Local\AvgSetupLog
2017-11-29 00:22 - 2017-11-29 00:23 - 000000000 ____D C:\Users\Kevin Lenertz\AppData\Roaming\Mozilla
2017-11-29 00:22 - 2017-11-29 00:22 - 000001007 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2017-11-29 00:22 - 2017-11-29 00:22 - 000000995 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2017-11-29 00:22 - 2017-11-29 00:22 - 000000000 ____D C:\Users\Kevin Lenertz\AppData\Local\CEF
2017-11-29 00:22 - 2017-11-29 00:22 - 000000000 ____D C:\Program Files\Mozilla Firefox
2017-11-29 00:22 - 2017-11-29 00:22 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-11-28 13:17 - 2017-11-28 13:17 - 000003896 _____ C:\WINDOWS\System32\Tasks\Dell SupportAssistAgent AutoUpdate
2017-11-28 13:17 - 2017-11-28 13:17 - 000000000 ____D C:\ProgramData\PC-Doctor, Inc
2017-11-28 13:16 - 2017-11-28 13:16 - 000000000 ____D C:\ProgramData\SupportAssist
2017-11-28 13:00 - 2017-11-28 13:00 - 000004124 _____ C:\WINDOWS\System32\Tasks\PCDoctorBackgroundMonitorTask
2017-11-28 13:00 - 2017-11-28 13:00 - 000003560 _____ C:\WINDOWS\System32\Tasks\PCDEventLauncherTask
2017-11-28 13:00 - 2017-11-28 13:00 - 000003412 _____ C:\WINDOWS\System32\Tasks\PCDDataUploadTask
2017-11-28 13:00 - 2017-11-28 13:00 - 000003294 _____ C:\WINDOWS\System32\Tasks\SystemToolsDailyTest
2017-11-28 13:00 - 2017-11-28 13:00 - 000000000 ____D C:\ProgramData\PC-Doctor for Windows
2017-11-28 13:00 - 2017-11-28 13:00 - 000000000 ____D C:\Program Files\Dell Support Center
2017-11-28 12:56 - 2017-11-28 13:16 - 000000000 ____D C:\Users\Kevin Lenertz\AppData\Roaming\PCDr
2017-11-28 12:53 - 2017-11-28 12:53 - 000000000 ____D C:\Users\Kevin Lenertz\AppData\Roaming\Dell
2017-11-28 07:18 - 2017-11-28 07:18 - 000003616 _____ C:\WINDOWS\System32\Tasks\UninstallDDS-C960901F-CE14-4DE1-9729-1305F719A337
2017-11-28 06:42 - 2017-11-28 06:42 - 000000000 ____D C:\WINDOWS\SysWOW64\Dell
2017-11-28 06:42 - 2017-11-28 06:42 - 000000000 ____D C:\Program Files (x86)\Dell Customer Connect
2017-11-28 06:41 - 2017-11-28 06:45 - 000000000 ____D C:\WINDOWS\system32\MRT
2017-11-28 06:41 - 2017-11-28 06:41 - 000000000 ____D C:\Program Files\Common Files\Intel
2017-11-28 06:41 - 2017-11-28 06:41 - 000000000 ____D C:\Program Files (x86)\Cisco
2017-11-28 06:40 - 2017-11-28 06:40 - 127017032 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT-KB890830.exe
2017-11-28 06:40 - 2017-11-28 06:40 - 127017032 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-11-27 23:27 - 2017-11-27 23:27 - 000000139 _____ C:\WINDOWS\SysWOW64\DLC_Debug_log.txt
2017-11-27 22:45 - 2017-11-27 22:45 - 000000000 ____D C:\Users\Kevin Lenertz\AppData\Local\Comms
2017-11-27 22:28 - 2017-11-27 22:28 - 000003366 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-914164008-461376372-368114211-1001
2017-11-27 22:27 - 2017-11-27 22:28 - 000002385 _____ C:\Users\Kevin Lenertz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2017-11-27 22:27 - 2017-11-27 22:27 - 000000000 ____D C:\Users\Kevin Lenertz\AppData\Roaming\Intel Corporation
2017-11-27 22:26 - 2017-11-27 22:26 - 000000000 ____D C:\Users\Kevin Lenertz\AppData\Roaming\Macromedia
2017-11-27 22:26 - 2017-11-27 22:26 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2017-11-27 22:25 - 2017-11-27 22:25 - 000000000 ____D C:\Users\Kevin Lenertz\AppData\Local\MicrosoftEdge
2017-11-27 22:25 - 2017-11-27 22:25 - 000000000 ____D C:\Program Files (x86)\Dell Update
2017-11-27 22:24 - 2017-12-01 20:35 - 000000000 ____D C:\Users\Kevin Lenertz\AppData\Roaming\Adobe
2017-11-27 22:24 - 2017-11-28 17:56 - 000000000 ____D C:\Users\Kevin Lenertz\AppData\Local\Packages
2017-11-27 22:24 - 2017-11-27 22:25 - 000000000 ____D C:\Users\Kevin Lenertz\AppData\Roaming\DropboxOEM
2017-11-27 22:24 - 2017-11-27 22:24 - 000000000 ____D C:\Users\Kevin Lenertz\AppData\Local\VirtualStore
2017-11-27 22:24 - 2017-11-27 22:24 - 000000000 ____D C:\Users\Kevin Lenertz\AppData\Local\Publishers
2017-11-27 22:24 - 2017-11-27 22:24 - 000000000 ____D C:\Users\Kevin Lenertz\AppData\Local\Power2Go8
2017-11-27 22:24 - 2017-11-27 22:24 - 000000000 ____D C:\Users\Kevin Lenertz\AppData\Local\DropboxOEM
2017-11-27 22:24 - 2017-11-27 22:24 - 000000000 ____D C:\Users\Kevin Lenertz\AppData\Local\DBG
2017-11-27 22:24 - 2017-11-27 22:24 - 000000000 ____D C:\Users\Kevin Lenertz\AppData\Local\Apps\2.0
2017-11-27 22:23 - 2017-11-28 07:11 - 000000000 ____D C:\Users\Kevin Lenertz\AppData\Local\ConnectedDevicesPlatform
2017-11-27 22:23 - 2017-11-27 22:23 - 000000020 ___SH C:\Users\Kevin Lenertz\ntuser.ini
2017-11-27 22:23 - 2017-11-27 22:23 - 000000000 ____D C:\Users\Kevin Lenertz\AppData\Roaming\Intel
2017-11-27 21:59 - 2017-11-27 21:59 - 000000000 _SHDL C:\Users\Default User
2017-11-27 21:59 - 2017-11-27 21:59 - 000000000 _SHDL C:\Users\All Users
2017-11-27 21:55 - 2017-12-01 21:07 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-11-27 21:55 - 2017-11-27 21:55 - 000022744 _____ C:\WINDOWS\system32\emptyregdb.dat
2017-11-27 21:55 - 2017-11-27 21:55 - 000002528 _____ C:\WINDOWS\System32\Tasks\CLVDLauncher
2017-11-27 21:55 - 2017-11-27 21:55 - 000002528 _____ C:\WINDOWS\System32\Tasks\CLMLSvc_P2G8
2017-11-27 21:55 - 2017-11-27 21:55 - 000002304 _____ C:\WINDOWS\System32\Tasks\RtHDVBg_PushButton
2017-11-27 21:55 - 2017-11-27 21:55 - 000002172 _____ C:\WINDOWS\System32\Tasks\DropboxOEM
2017-11-27 21:50 - 2017-12-01 21:03 - 000000000 ____D C:\Users\piama
2017-11-27 21:50 - 2017-12-01 21:03 - 000000000 ____D C:\Users\Kevin Lenertz
2017-11-27 21:49 - 2017-11-27 21:49 - 000001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2017-11-27 21:43 - 2017-11-27 21:43 - 000000000 ____D C:\WINDOWS\system32\config\bbimigrate
2017-11-27 21:42 - 2017-11-27 21:42 - 000000000 ____D C:\ProgramData\USOShared
2017-11-27 21:36 - 2017-11-28 06:41 - 000000000 ____D C:\Program Files (x86)\Intel
2017-11-27 21:36 - 2017-11-28 06:39 - 000000000 ____D C:\Program Files\Intel
2017-11-27 21:36 - 2017-11-27 21:36 - 000000000 ____D C:\Program Files (x86)\VulkanRT
2017-11-27 21:36 - 2017-11-27 21:36 - 000000000 _____ C:\WINDOWS\system32\GfxValDisplayLog.bin
2017-11-27 21:36 - 2017-02-20 03:37 - 000113664 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.DLL
2017-11-27 21:36 - 2017-02-20 03:37 - 000104456 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.DLL
2017-11-27 21:36 - 2016-11-22 16:23 - 000271648 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2017-11-27 21:36 - 2016-11-22 16:23 - 000110880 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2017-11-27 21:36 - 2016-11-22 16:22 - 000265504 _____ C:\WINDOWS\system32\vulkan-1.dll
2017-11-27 21:36 - 2016-11-22 16:22 - 000125216 _____ C:\WINDOWS\system32\vulkaninfo.exe
2017-11-27 21:35 - 2017-11-27 21:48 - 000000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2017-11-27 21:35 - 2017-11-27 21:35 - 000000000 ____H C:\ProgramData\DP45977C.lfl
2017-11-27 21:35 - 2017-11-27 21:35 - 000000000 ____D C:\WINDOWS\system32\SRSLabs
2017-11-27 21:35 - 2017-11-27 21:35 - 000000000 ____D C:\Program Files\Realtek
2017-11-27 21:35 - 2017-09-29 05:41 - 002241024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2017-11-27 21:32 - 2017-12-01 21:07 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2017-11-27 21:31 - 2017-12-01 21:03 - 000412416 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2017-11-27 21:30 - 2017-11-27 22:37 - 000000000 ____D C:\Windows.old
2017-11-27 21:30 - 2017-11-27 21:30 - 000000000 ____D C:\WINDOWS\InfusedApps
2017-11-27 21:29 - 2017-11-27 21:32 - 000000000 ____D C:\WINDOWS\ServiceProfiles
2017-11-27 21:28 - 2017-11-27 21:28 - 000008192 _____ C:\WINDOWS\system32\config\userdiff
2017-11-27 21:27 - 2017-11-27 21:27 - 000000000 ____D C:\WINDOWS\SysWOW64\sda
2017-11-27 21:25 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\Setup
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\zu-ZA
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\yo-NG
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\xh-ZA
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\wo-SN
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\vi-VN
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\uz-Latn-UZ
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\ur-PK
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\ug-CN
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\tt-RU
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\tn-ZA
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\tk-TM
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\ti-ET
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\tg-Cyrl-TJ
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\te-IN
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\ta-IN
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\sw-KE
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\sr-Cyrl-RS
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\sr-Cyrl-BA
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\sq-AL
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\si-LK
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\sd-Arab-PK
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\rw-RW
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\quz-PE
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\quc-Latn-GT
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\prs-AF
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\pa-IN
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\pa-Arab-PK
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\or-IN
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\nso-ZA
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\nn-NO
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\ne-NP
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\mt-MT
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\mr-IN
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\mn-MN
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\ml-IN
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\mk-MK
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\mi-NZ
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\lo-LA
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\lb-LU
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\ky-KG
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\ku-Arab-IQ
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\kok-IN
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\kn-IN
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\km-KH
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\kk-KZ
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\ka-GE
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\is-IS
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\ig-NG
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\id-ID
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\hy-AM
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\ha-Latn-NG
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\gu-IN
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\gd-GB
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\ga-IE
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\fil-PH
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\fa-IR
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\cy-GB
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\chr-CHER-US
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\ca-ES-valencia
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\bs-Latn-BA
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\bn-IN
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\bn-BD
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\be-BY
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\az-Latn-AZ
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\as-IN
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\am-ET
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\af-ZA
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\zu-ZA
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\yo-NG
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\xh-ZA
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\wo-SN
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\vi-VN
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\uz-Latn-UZ
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\ur-PK
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\ug-CN
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\tt-RU
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\tn-ZA
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\tk-TM
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\ti-ET
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\tg-Cyrl-TJ
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\te-IN
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\ta-IN
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\sw-KE
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\sr-Cyrl-RS
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\sr-Cyrl-BA
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\sq-AL
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\si-LK
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\sd-Arab-PK
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\rw-RW
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\quz-PE
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\quc-Latn-GT
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\prs-AF
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\pa-IN
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\pa-Arab-PK
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\or-IN
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\nso-ZA
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\nn-NO
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\ne-NP
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\mt-MT
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\mr-IN
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\mn-MN
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\ml-IN
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\mk-MK
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\mi-NZ
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\lo-LA
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\lb-LU
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\ky-KG
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\ku-Arab-IQ
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\kok-IN
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\kn-IN
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\km-KH
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\kk-KZ
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\ka-GE
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\is-IS
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\ig-NG
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\id-ID
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\hy-AM
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\ha-Latn-NG
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\gu-IN
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\gd-GB
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\ga-IE
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\fil-PH
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\fa-IR
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\cy-GB
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\chr-CHER-US
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\ca-ES-valencia
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\bs-Latn-BA
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\bn-IN
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\bn-BD
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\be-BY
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\az-Latn-AZ
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\as-IN
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\am-ET
2017-11-27 21:24 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\af-ZA
2017-11-27 21:24 - 2017-11-27 21:24 - 000000000 ____D C:\WINDOWS\SysWOW64\MailContactsCalendarSync
2017-11-27 21:24 - 2017-11-27 21:24 - 000000000 ____D C:\WINDOWS\SysWOW64\hi-IN
2017-11-27 21:24 - 2017-11-27 21:24 - 000000000 ____D C:\WINDOWS\SysWOW64\gl-ES
2017-11-27 21:24 - 2017-11-27 21:24 - 000000000 ____D C:\WINDOWS\SysWOW64\eu-ES
2017-11-27 21:24 - 2017-11-27 21:24 - 000000000 ____D C:\WINDOWS\SysWOW64\ca-ES
2017-11-27 21:24 - 2017-11-27 21:24 - 000000000 ____D C:\WINDOWS\system32\MailContactsCalendarSync
2017-11-27 21:24 - 2017-11-27 21:24 - 000000000 ____D C:\WINDOWS\system32\hi-IN
2017-11-27 21:24 - 2017-11-27 21:24 - 000000000 ____D C:\WINDOWS\system32\gl-ES
2017-11-27 21:24 - 2017-11-27 21:24 - 000000000 ____D C:\WINDOWS\system32\eu-ES
2017-11-27 21:24 - 2017-11-27 21:24 - 000000000 ____D C:\WINDOWS\system32\ca-ES
2017-11-27 21:24 - 2017-11-27 21:24 - 000000000 ____D C:\WINDOWS\OCR
2017-11-27 21:24 - 2017-11-27 21:24 - 000000000 ____D C:\Program Files\Reference Assemblies
2017-11-27 21:24 - 2017-11-27 21:24 - 000000000 ____D C:\Program Files\MSBuild
2017-11-27 21:24 - 2017-11-27 21:24 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies
2017-11-27 21:24 - 2017-11-27 21:24 - 000000000 ____D C:\Program Files (x86)\MSBuild
2017-11-27 21:22 - 2017-11-27 21:22 - 000000000 ____D C:\WINDOWS\SysWOW64\winrm
2017-11-27 21:22 - 2017-11-27 21:22 - 000000000 ____D C:\WINDOWS\SysWOW64\WCN
2017-11-27 21:22 - 2017-11-27 21:22 - 000000000 ____D C:\WINDOWS\SysWOW64\sysprep
2017-11-27 21:22 - 2017-11-27 21:22 - 000000000 ____D C:\WINDOWS\SysWOW64\slmgr
2017-11-27 21:22 - 2017-11-27 21:22 - 000000000 ____D C:\WINDOWS\SysWOW64\Printing_Admin_Scripts
2017-11-27 21:22 - 2017-11-27 21:22 - 000000000 ____D C:\WINDOWS\SysWOW64\0409
2017-11-27 21:22 - 2017-11-27 21:22 - 000000000 ____D C:\WINDOWS\system32\winrm
2017-11-27 21:22 - 2017-11-27 21:22 - 000000000 ____D C:\WINDOWS\system32\WCN
2017-11-27 21:22 - 2017-11-27 21:22 - 000000000 ____D C:\WINDOWS\system32\slmgr
2017-11-27 21:22 - 2017-11-27 21:22 - 000000000 ____D C:\WINDOWS\system32\Printing_Admin_Scripts
2017-11-27 21:22 - 2017-11-27 21:22 - 000000000 ____D C:\WINDOWS\system32\0409
2017-11-27 21:22 - 2017-11-27 21:22 - 000000000 ____D C:\WINDOWS\DigitalLocker
2017-11-27 21:20 - 2017-11-03 17:25 - 000835568 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2017-11-27 21:20 - 2017-11-03 17:25 - 000177648 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2017-11-27 21:18 - 2017-12-01 20:51 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2017-11-27 21:18 - 2017-12-01 20:40 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2017-11-27 21:18 - 2017-12-01 18:43 - 000000000 ____D C:\WINDOWS\DeliveryOptimization
2017-11-27 21:18 - 2017-12-01 03:42 - 000000000 ___HD C:\Program Files\WindowsApps
2017-11-27 21:18 - 2017-12-01 03:42 - 000000000 ____D C:\WINDOWS\AppReadiness
2017-11-27 21:18 - 2017-11-30 23:35 - 000000000 ____D C:\WINDOWS\rescache
2017-11-27 21:18 - 2017-11-29 01:33 - 000000000 ___RD C:\Program Files (x86)
2017-11-27 21:18 - 2017-11-29 01:23 - 000000000 ____D C:\WINDOWS\system32\NDF
2017-11-27 21:18 - 2017-11-29 01:04 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2017-11-27 21:18 - 2017-11-29 00:33 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2017-11-27 21:18 - 2017-11-28 03:14 - 000000000 ____D C:\WINDOWS\appcompat
2017-11-27 21:18 - 2017-11-27 21:56 - 000000000 ____D C:\WINDOWS\Registration
2017-11-27 21:18 - 2017-11-27 21:54 - 000000000 __RHD C:\Users\Public\Libraries
2017-11-27 21:18 - 2017-11-27 21:51 - 000000000 ____D C:\WINDOWS\system32\FxsTmp
2017-11-27 21:18 - 2017-11-27 21:48 - 000000000 ____D C:\WINDOWS\system32\spool
2017-11-27 21:18 - 2017-11-27 21:48 - 000000000 ____D C:\WINDOWS\system32\oobe
2017-11-27 21:18 - 2017-11-27 21:43 - 000000000 ____D C:\ProgramData\USOPrivate
2017-11-27 21:18 - 2017-11-27 21:42 - 000000000 ____D C:\WINDOWS\system32\Sysprep
2017-11-27 21:18 - 2017-11-27 21:38 - 000000000 ___RD C:\WINDOWS\PrintDialog
2017-11-27 21:18 - 2017-11-27 21:38 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2017-11-27 21:18 - 2017-11-27 21:31 - 000000000 ____D C:\WINDOWS\system32\config\RegBack
2017-11-27 21:18 - 2017-11-27 21:30 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template
2017-11-27 21:18 - 2017-11-27 21:30 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
2017-11-27 21:18 - 2017-11-27 21:25 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2017-11-27 21:18 - 2017-11-27 21:25 - 000000000 ___SD C:\WINDOWS\system32\F12
2017-11-27 21:18 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\TextInput
2017-11-27 21:18 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2017-11-27 21:18 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2017-11-27 21:18 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\Dism
2017-11-27 21:18 - 2017-11-27 21:25 - 000000000 ____D C:\WINDOWS\system32\appraiser
2017-11-27 21:18 - 2017-11-27 21:24 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2017-11-27 21:18 - 2017-11-27 21:22 - 000000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs
2017-11-27 21:18 - 2017-11-27 21:22 - 000000000 ___SD C:\WINDOWS\system32\dsc
2017-11-27 21:18 - 2017-11-27 21:22 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2017-11-27 21:18 - 2017-11-27 21:22 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2017-11-27 21:18 - 2017-11-27 21:22 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2017-11-27 21:18 - 2017-11-27 21:22 - 000000000 ____D C:\WINDOWS\SysWOW64\MUI
2017-11-27 21:18 - 2017-11-27 21:22 - 000000000 ____D C:\WINDOWS\SysWOW64\com
2017-11-27 21:18 - 2017-11-27 21:22 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2017-11-27 21:18 - 2017-11-27 21:22 - 000000000 ____D C:\WINDOWS\system32\setup
2017-11-27 21:18 - 2017-11-27 21:22 - 000000000 ____D C:\WINDOWS\system32\MUI
2017-11-27 21:18 - 2017-11-27 21:22 - 000000000 ____D C:\WINDOWS\system32\migwiz
2017-11-27 21:18 - 2017-11-27 21:22 - 000000000 ____D C:\WINDOWS\system32\com
2017-11-27 21:18 - 2017-11-27 21:22 - 000000000 ____D C:\WINDOWS\IME
2017-11-27 21:18 - 2017-11-27 21:22 - 000000000 ____D C:\WINDOWS\Help
2017-11-27 21:18 - 2017-11-27 21:22 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2017-11-27 21:18 - 2017-11-27 21:22 - 000000000 ____D C:\Program Files\Windows Defender
2017-11-27 21:18 - 2017-11-27 21:22 - 000000000 ____D C:\Program Files\Common Files\system
2017-11-27 21:18 - 2017-11-27 21:22 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2017-11-27 21:18 - 2017-11-27 21:22 - 000000000 ____D C:\Program Files (x86)\Windows Defender
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 __SHD C:\Program Files\Windows Sidebar
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 __SHD C:\Program Files (x86)\Windows Sidebar
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 __RSD C:\WINDOWS\media
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ___SD C:\WINDOWS\SysWOW64\Nui
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ___SD C:\WINDOWS\SysWOW64\Configuration
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ___SD C:\WINDOWS\system32\UNP
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ___SD C:\WINDOWS\system32\Nui
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ___SD C:\WINDOWS\system32\Configuration
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ___SD C:\WINDOWS\Downloaded Program Files
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ___RD C:\WINDOWS\Offline Web Pages
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\Web
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\Vss
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\tracing
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\TAPI
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\SysWOW64\SMI
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\SysWOW64\ras
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\SysWOW64\NDF
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\SysWOW64\Msdtc
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\SysWOW64\migwiz
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\SysWOW64\Ipmi
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\SysWOW64\InputMethod
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\SysWOW64\inetsrv
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\SysWOW64\IME
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\SysWOW64\icsxml
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\SysWOW64\GroupPolicyUsers
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\SysWOW64\FxsTmp
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\SysWOW64\downlevel
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\SysWOW64\Bthprops
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\SysWOW64\AppLocker
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\SystemResources
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\SystemApps
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\system32\winevt
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\system32\ras
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\system32\ProximityToast
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\system32\PointOfService
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\system32\MsDtc
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\system32\Macromed
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\system32\Ipmi
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\system32\InputMethod
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\system32\inetsrv
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\system32\IME
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\system32\icsxml
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\system32\ias
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\system32\hydrogen
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\system32\GroupPolicyUsers
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\system32\GroupPolicy
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\system32\downlevel
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\system32\DDFs
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\system32\config\TxR
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\system32\config\systemprofile
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\system32\config\Journal
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\system32\Bthprops
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\system32\AppLocker
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\system32\AdvancedInstallers
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\System
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\SKB
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\ShellExperiences
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\security
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\schemas
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\SchCache
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\Resources
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\Provisioning
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\PLA
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\Performance
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\ModemLogs
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\L2Schemas
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\InputMethod
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\Globalization
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\GameBarPresenceWriter
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\Cursors
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\Branding
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\bcastdvr
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\addins
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\ProgramData\WindowsHolographicDevices
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\Program Files\Windows Security
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\Program Files\Windows Portable Devices
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\Program Files\windows nt
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\Program Files\Windows Multimedia Platform
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\Program Files\Common Files\Services
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\Program Files (x86)\Windows Portable Devices
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\Program Files (x86)\windows nt
2017-11-27 21:18 - 2017-11-27 21:18 - 000000000 ____D C:\Program Files (x86)\Windows Multimedia Platform
2017-11-27 21:18 - 2017-11-27 21:16 - 000229376 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll
2017-11-27 21:18 - 2017-11-27 21:16 - 000215943 _____ C:\WINDOWS\SysWOW64\dssec.dat
2017-11-27 21:18 - 2017-11-27 21:16 - 000215943 _____ C:\WINDOWS\system32\dssec.dat
2017-11-27 21:18 - 2017-11-27 21:16 - 000208384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msclmd.dll
2017-11-27 21:18 - 2017-11-27 21:16 - 000017572 _____ C:\WINDOWS\system32\OEMDefaultAssociations.xml
2017-11-27 21:18 - 2017-11-27 21:16 - 000004096 _____ C:\WINDOWS\system32\config\VSMIDK
2017-11-27 21:18 - 2017-11-27 21:16 - 000003683 _____ C:\WINDOWS\system32\Drivers\etc\lmhosts.sam
2017-11-27 21:18 - 2017-11-27 21:16 - 000000858 _____ C:\WINDOWS\system32\DefaultQuestions.json
2017-11-27 21:18 - 2017-11-27 21:16 - 000000741 _____ C:\WINDOWS\SysWOW64\NOISE.DAT
2017-11-27 21:18 - 2017-11-27 21:16 - 000000741 _____ C:\WINDOWS\system32\NOISE.DAT
2017-11-27 21:16 - 2017-12-01 20:15 - 000000000 ____D C:\WINDOWS\INF
2017-11-27 21:11 - 2017-11-27 22:38 - 000000000 ____D C:\WINDOWS\CbsTemp
2017-11-27 21:07 - 2017-12-01 20:28 - 097517568 _____ C:\WINDOWS\system32\config\SOFTWARE
2017-11-27 21:07 - 2017-12-01 20:28 - 017825792 _____ C:\WINDOWS\system32\config\SYSTEM
2017-11-27 21:07 - 2017-12-01 20:28 - 000786432 _____ C:\WINDOWS\system32\config\DEFAULT
2017-11-27 21:07 - 2017-12-01 20:28 - 000057344 _____ C:\WINDOWS\system32\config\SECURITY
2017-11-27 21:07 - 2017-11-29 01:29 - 000028672 _____ C:\WINDOWS\system32\config\SAM
2017-11-27 21:07 - 2017-11-29 00:33 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2017-11-27 21:07 - 2017-11-27 22:00 - 000000000 ____D C:\WINDOWS\Panther
2017-11-27 21:07 - 2017-11-27 21:22 - 000000000 ____D C:\WINDOWS\servicing
2017-11-27 21:07 - 2017-11-27 21:18 - 000000000 ____D C:\WINDOWS\system32\SMI
2017-11-27 21:07 - 2017-11-19 01:28 - 001310720 _____ C:\WINDOWS\system32\config\BBI
2017-11-20 11:57 - 2017-11-20 11:57 - 000627368 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcp140.dll
2017-11-20 11:57 - 2017-11-20 11:57 - 000391344 _____ (Microsoft Corporation) C:\WINDOWS\system32\vccorlib140.dll
2017-11-20 11:57 - 2017-11-20 11:57 - 000087224 _____ (Microsoft Corporation) C:\WINDOWS\system32\vcruntime140.dll
2017-11-20 11:56 - 2017-11-20 11:56 - 000332456 _____ (Microsoft Corporation) C:\WINDOWS\system32\concrt140.dll
2017-11-20 11:43 - 2017-11-20 11:43 - 000438080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcp140.dll
2017-11-20 11:43 - 2017-11-20 11:43 - 000264368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vccorlib140.dll
2017-11-20 11:43 - 2017-11-20 11:43 - 000243016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\concrt140.dll
2017-11-20 11:43 - 2017-11-20 11:43 - 000083792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vcruntime140.dll
2017-11-19 12:57 - 2017-11-19 12:57 - 003449304 _____ (AVG Technologies CZ, s.r.o.) C:\Users\Kevin Lenertz\Downloads\AVG_Protection_Free_1606.exe
2017-11-19 03:32 - 2017-11-27 21:56 - 000006410 _____ C:\Users\Kevin Lenertz\Desktop\Removed Apps.html
2017-11-19 03:32 - 2017-11-27 21:56 - 000006008 _____ C:\Users\piama\Desktop\Removed Apps.html
2017-11-19 03:03 - 2017-11-23 09:00 - 000000000 ____D C:\Windows.old(1)
2017-11-16 19:34 - 2017-10-25 01:11 - 017083904 ____N (Microsoft Corporation) C:\WINDOWS\system32\HologramCompositor.dll
2017-11-16 19:34 - 2017-10-25 01:11 - 000336896 ____N (Microsoft Corporation) C:\WINDOWS\system32\HolographicRuntimes.dll
2017-11-16 19:34 - 2017-10-25 01:09 - 021753344 ____N (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll
2017-11-16 19:34 - 2017-10-25 00:57 - 000956416 ____N (Microsoft Corporation) C:\WINDOWS\system32\Spectrum.exe
2017-11-16 19:34 - 2017-10-25 00:57 - 000882688 ____N (Microsoft Corporation) C:\WINDOWS\system32\Windows.Mirage.Internal.dll
2017-11-16 19:34 - 2017-10-25 00:56 - 000665600 ____N (Microsoft Corporation) C:\WINDOWS\system32\DHolographicDisplay.dll
2017-11-16 19:34 - 2017-10-24 22:36 - 000618496 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.Internal.dll
2017-11-16 19:34 - 2017-10-24 20:41 - 000362176 ____N (Microsoft Corporation) C:\WINDOWS\system32\BioIso.exe
2017-11-16 19:34 - 2017-10-24 20:40 - 001634288 ____N (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2017-11-16 19:34 - 2017-10-24 20:40 - 000612760 ____N (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2017-11-16 19:34 - 2017-10-24 20:40 - 000269696 ____N C:\WINDOWS\system32\FaceProcessorCore.dll
2017-11-16 19:34 - 2017-10-24 20:39 - 007831248 ____N (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll
2017-11-16 19:34 - 2017-10-24 20:39 - 000479912 ____N (Microsoft Corporation) C:\WINDOWS\system32\wow64win.dll
2017-11-16 19:34 - 2017-10-24 20:39 - 000285080 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2017-11-16 19:34 - 2017-10-24 20:37 - 001954048 ____N (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2017-11-16 19:34 - 2017-10-24 20:37 - 000610712 ____N (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2017-11-16 19:34 - 2017-10-24 20:36 - 008590744 ____N (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2017-11-16 19:34 - 2017-10-24 20:36 - 002400664 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2017-11-16 19:34 - 2017-10-24 20:36 - 000187288 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2017-11-16 19:34 - 2017-10-24 20:34 - 002573208 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2017-11-16 19:34 - 2017-10-24 20:34 - 000839928 ____N (Microsoft Corporation) C:\WINDOWS\system32\Windows.Perception.Stub.dll
2017-11-16 19:34 - 2017-10-24 20:34 - 000710920 ____N (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2017-11-16 19:34 - 2017-10-24 20:32 - 000559512 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2017-11-16 19:34 - 2017-10-24 20:32 - 000147864 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wcifs.sys
2017-11-16 19:34 - 2017-10-24 20:31 - 000436120 ____N (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostCommon.dll
2017-11-16 19:34 - 2017-10-24 20:31 - 000045464 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storufs.sys
2017-11-16 19:34 - 2017-10-24 20:30 - 004487968 ____N (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2017-11-16 19:34 - 2017-10-24 20:30 - 000555416 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS
2017-11-16 19:34 - 2017-10-24 20:29 - 002269080 ____N (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll
2017-11-16 19:34 - 2017-10-24 20:29 - 001507736 ____N (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2017-11-16 19:34 - 2017-10-24 20:29 - 000603920 ____N (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2017-11-16 19:34 - 2017-10-24 20:28 - 001170008 ____N (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2017-11-16 19:34 - 2017-10-24 20:27 - 006791472 ____N (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2017-11-16 19:34 - 2017-10-24 20:27 - 001970520 ____N (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
2017-11-16 19:34 - 2017-10-24 20:27 - 001426152 ____N (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2017-11-16 19:34 - 2017-10-24 20:27 - 000374032 ____N (Microsoft Corporation) C:\WINDOWS\system32\vac.exe
2017-11-16 19:34 - 2017-10-24 20:24 - 000428952 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
2017-11-16 19:34 - 2017-10-24 20:20 - 002717392 ____N (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2017-11-16 19:34 - 2017-10-24 19:52 - 001615720 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2017-11-16 19:34 - 2017-10-24 19:50 - 001528904 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2017-11-16 19:34 - 2017-10-24 19:36 - 025246208 ____N (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2017-11-16 19:34 - 2017-10-24 19:30 - 005615968 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll
2017-11-16 19:34 - 2017-10-24 19:30 - 000354200 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudExperienceHostCommon.dll
2017-11-16 19:34 - 2017-10-24 19:28 - 004648528 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2017-11-16 19:34 - 2017-10-24 19:28 - 001246432 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2017-11-16 19:34 - 2017-10-24 19:28 - 000982016 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2017-11-16 19:34 - 2017-10-24 19:27 - 001454568 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll
2017-11-16 19:34 - 2017-10-24 19:27 - 001377080 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
2017-11-16 19:34 - 2017-10-24 19:27 - 001015008 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2017-11-16 19:34 - 2017-10-24 19:24 - 000506256 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Perception.Stub.dll
2017-11-16 19:34 - 2017-10-24 19:22 - 006015200 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2017-11-16 19:34 - 2017-10-24 19:22 - 002465848 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2017-11-16 19:34 - 2017-10-24 19:19 - 003670016 ____N (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2017-11-16 19:34 - 2017-10-24 19:19 - 000097792 ____N C:\WINDOWS\system32\runexehelper.exe
2017-11-16 19:34 - 2017-10-24 19:18 - 000975872 ____N C:\WINDOWS\system32\FaceProcessor.dll
2017-11-16 19:34 - 2017-10-24 19:18 - 000328192 ____N (Microsoft Corporation) C:\WINDOWS\system32\AcGenral.dll
2017-11-16 19:34 - 2017-10-24 19:18 - 000301056 ____N (Microsoft Corporation) C:\WINDOWS\system32\AcLayers.dll
2017-11-16 19:34 - 2017-10-24 19:18 - 000135168 ____N (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_CapabilityAccess.dll
2017-11-16 19:34 - 2017-10-24 19:18 - 000095744 ____N (Microsoft Corporation) C:\WINDOWS\system32\CapabilityAccessManagerClient.dll
2017-11-16 19:34 - 2017-10-24 19:18 - 000056320 ____N (Microsoft Corporation) C:\WINDOWS\system32\AcSpecfc.dll
2017-11-16 19:34 - 2017-10-24 19:16 - 023658496 ____N (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2017-11-16 19:34 - 2017-10-24 19:16 - 000227328 ____N (Microsoft Corporation) C:\WINDOWS\system32\CapabilityAccessManager.dll
2017-11-16 19:34 - 2017-10-24 19:16 - 000114688 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\UcmCx.sys
2017-11-16 19:34 - 2017-10-24 19:16 - 000002560 ____N (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll
2017-11-16 19:34 - 2017-10-24 19:15 - 000140800 ____N (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2017-11-16 19:34 - 2017-10-24 19:14 - 000541184 ____N (Microsoft Corporation) C:\WINDOWS\system32\HolographicExtensions.dll
2017-11-16 19:34 - 2017-10-24 19:14 - 000046080 ____N (Microsoft Corporation) C:\WINDOWS\system32\rdrleakdiag.exe
2017-11-16 19:34 - 2017-10-24 19:13 - 013655552 ____N (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2017-11-16 19:34 - 2017-10-24 19:13 - 002972672 ____N (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2017-11-16 19:34 - 2017-10-24 19:12 - 001015296 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
2017-11-16 19:34 - 2017-10-24 19:12 - 000708096 ____N (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2017-11-16 19:34 - 2017-10-24 19:12 - 000599040 ____N (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2017-11-16 19:34 - 2017-10-24 19:12 - 000568832 ____N (Microsoft Corporation) C:\WINDOWS\system32\TileDataRepository.dll
2017-11-16 19:34 - 2017-10-24 19:11 - 000768512 ____N (Microsoft Corporation) C:\WINDOWS\system32\PCPKsp.dll
2017-11-16 19:34 - 2017-10-24 19:10 - 008099328 ____N (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2017-11-16 19:34 - 2017-10-24 19:10 - 004742144 ____N (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2017-11-16 19:34 - 2017-10-24 19:10 - 001167360 ____N (Microsoft Corporation) C:\WINDOWS\system32\ISM.dll
2017-11-16 19:34 - 2017-10-24 19:09 - 002862080 ____N (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2017-11-16 19:34 - 2017-10-24 19:09 - 002106368 ____N (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2017-11-16 19:34 - 2017-10-24 19:09 - 001806336 ____N (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
2017-11-16 19:34 - 2017-10-24 19:09 - 000812032 ____N (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2017-11-16 19:34 - 2017-10-24 19:08 - 002905600 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2017-11-16 19:34 - 2017-10-24 19:08 - 002781696 ____N (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2017-11-16 19:34 - 2017-10-24 19:08 - 002633216 ____N (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2017-11-16 19:34 - 2017-10-24 19:08 - 002392576 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcGenral.dll
2017-11-16 19:34 - 2017-10-24 19:08 - 001667584 ____N (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2017-11-16 19:34 - 2017-10-24 19:08 - 000654848 ____N (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2017-11-16 19:34 - 2017-10-24 19:08 - 000487424 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcSpecfc.dll
2017-11-16 19:34 - 2017-10-24 19:08 - 000465408 ____N (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2017-11-16 19:34 - 2017-10-24 19:07 - 018914304 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2017-11-16 19:34 - 2017-10-24 19:07 - 003478016 ____N (Microsoft Corporation) C:\WINDOWS\system32\mispace.dll
2017-11-16 19:34 - 2017-10-24 19:07 - 001485824 ____N (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2017-11-16 19:34 - 2017-10-24 19:07 - 000685056 ____N (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2017-11-16 19:34 - 2017-10-24 19:07 - 000372224 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcLayers.dll
2017-11-16 19:34 - 2017-10-24 19:07 - 000064512 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\CapabilityAccessManagerClient.dll
2017-11-16 19:34 - 2017-10-24 19:06 - 000002560 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll
2017-11-16 19:34 - 2017-10-24 19:05 - 019339776 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2017-11-16 19:34 - 2017-10-24 19:05 - 000106496 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2017-11-16 19:34 - 2017-10-24 19:05 - 000022528 ____N (Microsoft Corporation) C:\WINDOWS\system32\msdtcVSp1res.dll
2017-11-16 19:34 - 2017-10-24 19:04 - 000124928 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\luafv.sys
2017-11-16 19:34 - 2017-10-24 19:04 - 000041984 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdrleakdiag.exe
2017-11-16 19:34 - 2017-10-24 19:03 - 000450048 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\TileDataRepository.dll
2017-11-16 19:34 - 2017-10-24 19:02 - 000591872 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\PCPKsp.dll
2017-11-16 19:34 - 2017-10-24 19:01 - 012687360 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2017-11-16 19:34 - 2017-10-24 19:01 - 000462848 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2017-11-16 19:34 - 2017-10-24 18:59 - 003679232 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2017-11-16 19:34 - 2017-10-24 18:59 - 000664576 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2017-11-16 19:34 - 2017-10-24 18:58 - 002467840 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2017-11-16 19:34 - 2017-10-24 18:58 - 001322496 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll
2017-11-16 19:34 - 2017-10-24 18:58 - 001280000 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll
2017-11-16 19:34 - 2017-10-24 18:57 - 006035968 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2017-11-16 19:34 - 2017-10-24 18:55 - 002864640 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\mispace.dll
2017-11-16 19:34 - 2017-10-24 18:54 - 000022528 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdtcVSp1res.dll
2017-11-16 19:34 - 2017-10-21 04:25 - 003313968 ____N C:\WINDOWS\system32\Windows.Mirage.dll
2017-11-16 19:34 - 2017-10-20 06:17 - 002474584 ____N C:\WINDOWS\SysWOW64\Windows.Mirage.dll
2017-11-16 19:34 - 2017-10-19 21:08 - 000339968 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\msexcl40.dll
2017-11-05 12:06 - 2017-11-05 12:06 - 007470520 _____ (Bose Corporation) C:\Users\Kevin Lenertz\Downloads\BoseUpdaterInstaller_2.1.0.1551.6380.exe
2017-11-04 18:27 - 2017-11-04 18:27 - 000000000 ___HD C:\Users\Kevin Lenertz\MicrosoftEdgeBackups
2017-11-04 13:56 - 2017-11-04 13:56 - 000285696 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys
2017-11-04 13:55 - 2017-11-04 13:55 - 005906264 ____N (Microsoft Corporation) C:\WINDOWS\system32\StartTileData.dll
2017-11-04 13:55 - 2017-11-04 13:55 - 003334144 ____N (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2017-11-04 13:55 - 2017-11-04 13:55 - 002869248 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2017-11-04 13:55 - 2017-11-04 13:55 - 001856000 ____N (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2017-11-04 13:55 - 2017-11-04 13:55 - 001822208 ____N (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2017-11-04 13:55 - 2017-11-04 13:55 - 001664000 ____N (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2017-11-04 13:55 - 2017-11-04 13:55 - 001641536 ____N (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2017-11-04 13:55 - 2017-11-04 13:55 - 001587200 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2017-11-04 13:55 - 2017-11-04 13:55 - 001559552 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2017-11-04 13:55 - 2017-11-04 13:55 - 001554216 ____N (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2017-11-04 13:55 - 2017-11-04 13:55 - 001547264 ____N (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2017-11-04 13:55 - 2017-11-04 13:55 - 001470976 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2017-11-04 13:55 - 2017-11-04 13:55 - 001463856 ____N (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2017-11-04 13:55 - 2017-11-04 13:55 - 001436432 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2017-11-04 13:55 - 2017-11-04 13:55 - 001323840 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2017-11-04 13:55 - 2017-11-04 13:55 - 001261864 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
2017-11-04 13:55 - 2017-11-04 13:55 - 001200024 ____N (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2017-11-04 13:55 - 2017-11-04 13:55 - 001053592 ____N (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2017-11-04 13:55 - 2017-11-04 13:55 - 000925184 ____N (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
2017-11-04 13:55 - 2017-11-04 13:55 - 000778936 ____N (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2017-11-04 13:55 - 2017-11-04 13:55 - 000739696 ____N (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2017-11-04 13:55 - 2017-11-04 13:55 - 000726016 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2017-11-04 13:55 - 2017-11-04 13:55 - 000677280 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2017-11-04 13:55 - 2017-11-04 13:55 - 000665088 ____N (Microsoft Corporation) C:\WINDOWS\system32\TpmCoreProvisioning.dll
2017-11-04 13:55 - 2017-11-04 13:55 - 000649304 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2017-11-04 13:55 - 2017-11-04 13:55 - 000640512 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\mswstr10.dll
2017-11-04 13:55 - 2017-11-04 13:55 - 000597160 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
2017-11-04 13:55 - 2017-11-04 13:55 - 000566272 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\TpmCoreProvisioning.dll
2017-11-04 13:55 - 2017-11-04 13:55 - 000542208 ____N (Microsoft Corporation) C:\WINDOWS\system32\FirewallAPI.dll
2017-11-04 13:55 - 2017-11-04 13:55 - 000529408 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nwifi.sys
2017-11-04 13:55 - 2017-11-04 13:55 - 000478208 ____N (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnr.dll
2017-11-04 13:55 - 2017-11-04 13:55 - 000464416 ____N (Microsoft Corporation) C:\WINDOWS\system32\bcryptprimitives.dll
2017-11-04 13:55 - 2017-11-04 13:55 - 000461312 ____N (Microsoft Corporation) C:\WINDOWS\system32\wlansec.dll
2017-11-04 13:55 - 2017-11-04 13:55 - 000442880 ____N (Microsoft Corporation) C:\WINDOWS\system32\cryptngc.dll
2017-11-04 13:55 - 2017-11-04 13:55 - 000418712 ____N (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2017-11-04 13:55 - 2017-11-04 13:55 - 000374784 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\FirewallAPI.dll
2017-11-04 13:55 - 2017-11-04 13:55 - 000373656 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys
2017-11-04 13:55 - 2017-11-04 13:55 - 000353688 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2017-11-04 13:55 - 2017-11-04 13:55 - 000326144 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptngc.dll
2017-11-04 13:55 - 2017-11-04 13:55 - 000246168 ____N (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2017-11-04 13:55 - 2017-11-04 13:55 - 000232344 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
2017-11-04 13:55 - 2017-11-04 13:55 - 000184984 ____N (Microsoft Corporation) C:\WINDOWS\system32\sspicli.dll
2017-11-04 13:55 - 2017-11-04 13:55 - 000177664 ____N (Microsoft Corporation) C:\WINDOWS\system32\t2embed.dll
2017-11-04 13:55 - 2017-11-04 13:55 - 000139672 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecdd.sys
2017-11-04 13:55 - 2017-11-04 13:55 - 000136192 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\t2embed.dll
2017-11-04 13:55 - 2017-11-04 13:55 - 000123520 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\sspicli.dll
2017-11-04 13:55 - 2017-11-04 13:55 - 000086016 ____N (Microsoft Corporation) C:\WINDOWS\system32\XblAuthTokenBrokerExt.dll
2017-11-04 13:55 - 2017-11-04 13:55 - 000070656 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\XblAuthTokenBrokerExt.dll
2017-11-04 13:55 - 2017-11-04 13:55 - 000060824 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\urscx01000.sys
2017-11-04 13:55 - 2017-11-04 13:55 - 000058880 ____N (Microsoft Corporation) C:\WINDOWS\system32\TpmTasks.dll
2017-11-04 13:55 - 2017-11-04 13:55 - 000057344 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\UcmUcsi.sys
2017-11-04 13:55 - 2017-11-04 13:55 - 000034816 ____N (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BasicRender.sys
2017-11-04 13:55 - 2017-11-04 13:55 - 000028672 ____N (Microsoft Corporation) C:\WINDOWS\system32\sspisrv.dll
2017-11-04 13:55 - 2017-11-04 13:55 - 000008704 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\msjint40.dll
2017-11-04 13:42 - 2017-11-04 13:42 - 001166520 ____N (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2017-11-04 13:42 - 2017-11-04 13:42 - 000778936 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
2017-11-04 13:42 - 2017-11-04 13:42 - 000124624 ____N (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2017-11-04 13:42 - 2017-11-04 13:42 - 000103120 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2017-11-04 13:42 - 2017-11-04 13:42 - 000035456 ____N (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
2017-11-04 13:42 - 2017-11-04 13:42 - 000035456 ____N (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-12-01 21:09 - 2016-11-20 03:27 - 000000000 ____D C:\Users\Kevin Lenertz\AppData\LocalLow\Mozilla
2017-12-01 21:09 - 2015-11-05 21:23 - 000000000 __RDL C:\Users\Kevin Lenertz\OneDrive
2017-12-01 20:51 - 2015-10-01 11:55 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2017-12-01 20:49 - 2015-11-05 21:42 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016 Tools
2017-12-01 20:36 - 2015-10-01 12:06 - 000000000 ____D C:\ProgramData\Dell
2017-12-01 20:36 - 2015-10-01 11:48 - 000000000 ____D C:\Program Files\Dell
2017-12-01 20:34 - 2015-10-01 11:49 - 001002998 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-12-01 20:19 - 2012-04-12 10:06 - 000000000 ____D C:\Users\Kevin Lenertz\Desktop\_Past Classes
2017-12-01 20:17 - 2011-11-29 12:53 - 000000000 ____D C:\Users\Kevin Lenertz\Desktop\School stuff
2017-11-29 01:33 - 2015-10-01 11:56 - 000000000 ____D C:\ProgramData\McAfee
2017-11-29 01:01 - 2015-10-01 11:53 - 000000000 ____D C:\ProgramData\PCDr
2017-11-29 00:24 - 2017-04-05 19:33 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2017-11-28 13:00 - 2015-10-01 11:48 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell
2017-11-28 06:51 - 2015-10-01 11:39 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2017-11-28 06:42 - 2015-10-01 11:43 - 000000000 ____D C:\ProgramData\Package Cache
2017-11-28 06:41 - 2015-10-01 11:49 - 000000000 ____D C:\ProgramData\Intel
2017-11-27 22:24 - 2015-11-06 18:18 - 000000000 ___RD C:\Users\Kevin Lenertz\3D Objects
2017-11-27 22:24 - 2015-10-01 12:35 - 000000000 __RHD C:\Users\Public\AccountPictures
2017-11-27 21:56 - 2017-06-05 20:10 - 000000000 ____D C:\Users\Kevin Lenertz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Corporation
2017-11-27 21:56 - 2017-01-11 00:14 - 000000000 ____D C:\Users\Kevin Lenertz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dell
2017-11-27 21:56 - 2016-08-06 21:08 - 000000000 ____D C:\Users\Kevin Lenertz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\World of Warships
2017-11-27 21:54 - 2015-07-10 03:04 - 000000000 ____D C:\WINDOWS\system32\Tasks_Migrated
2017-11-27 21:48 - 2017-10-08 12:47 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
2017-11-27 21:48 - 2015-10-01 11:53 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox 20 GB
2017-11-27 21:48 - 2015-10-01 11:52 - 000000000 ___HD C:\WINDOWS\system32\WLANProfiles
2017-11-27 21:48 - 2015-10-01 11:51 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell Audio
2017-11-27 21:48 - 2015-10-01 11:46 - 000000000 ____D C:\WINDOWS\LastGood.Tmp
2017-11-27 21:48 - 2015-10-01 11:43 - 000000000 ____D C:\Users\Public\CyberLink
2017-11-27 21:48 - 2015-10-01 11:39 - 000000000 ____D C:\ProgramData\Temp
2017-11-27 21:48 - 2015-07-10 03:04 - 000000000 ___RD C:\WINDOWS\PurchaseDialog
2017-11-27 21:48 - 2015-07-10 03:04 - 000000000 ___RD C:\WINDOWS\DesktopTileResources
2017-11-27 21:47 - 2015-10-01 11:52 - 000000000 ____D C:\ProgramData\Intel.sav
2017-11-27 21:47 - 2015-10-01 11:39 - 000000000 ____D C:\ProgramData\install_clap
2017-11-27 21:46 - 2015-10-01 11:53 - 000000000 ____D C:\Program Files (x86)\Dropbox
2017-11-27 21:46 - 2015-10-01 11:53 - 000000000 ____D C:\Program Files (x86)\Dell Digital Delivery
2017-11-27 21:46 - 2015-10-01 11:49 - 000000000 ____D C:\Program Files (x86)\Realtek
2017-11-27 21:46 - 2015-10-01 11:40 - 000000000 ____D C:\Program Files (x86)\CyberLink
2017-11-27 21:46 - 2015-10-01 11:39 - 000000000 ____D C:\ProgramData\CyberLink
2017-11-27 21:46 - 2015-10-01 11:39 - 000000000 ____D C:\ProgramData\CLSK
2017-11-27 21:44 - 2015-10-01 11:50 - 000000000 ____D C:\Program Files\Waves
2017-11-27 21:44 - 2015-07-10 05:16 - 000000000 ____D C:\Program Files\Windows Journal
2017-11-27 21:30 - 2016-05-08 09:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Buddy
2017-11-27 21:30 - 2015-12-13 11:56 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2017-11-27 21:30 - 2015-11-09 23:48 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XnView
2017-11-27 21:30 - 2015-11-09 22:44 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Image Eye
2017-11-27 21:30 - 2015-11-08 12:23 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FreeVideo Downloader
2017-11-27 21:29 - 2017-03-22 21:01 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Western Digital
2017-11-27 21:29 - 2016-10-20 23:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FlashIntegro
2017-11-27 21:29 - 2016-07-14 00:10 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
2017-11-27 21:29 - 2016-05-08 09:25 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
2017-11-27 21:29 - 2016-05-08 09:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SoundTaxi Media Suite
2017-11-27 21:29 - 2015-11-08 12:29 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2017-11-27 21:29 - 2015-11-05 22:41 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2017-11-27 21:14 - 2017-09-29 05:40 - 000067584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthmodem.sys
2017-11-19 03:18 - 2015-10-01 12:27 - 000000000 ____D C:\backup
2017-11-04 17:38 - 2017-10-09 15:59 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2017-11-04 17:38 - 2017-01-01 19:45 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HWiNFO64
2017-11-04 17:38 - 2016-07-13 23:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Help and Support
2017-11-04 17:38 - 2016-01-24 21:13 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2017-11-04 17:38 - 2016-01-01 20:20 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin
2017-11-04 17:38 - 2015-12-03 01:35 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel Driver Update Utility
2017-11-04 17:38 - 2015-11-17 23:33 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2017-11-04 17:38 - 2015-11-16 17:25 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BackupManager
2017-11-04 17:38 - 2015-11-05 22:47 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG Zen
2017-11-04 08:21 - 2017-05-29 19:33 - 000000000 ____D C:\Users\Kevin Lenertz\Desktop\Sophea Phone 5-29-17

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2017-11-27 21:31

==================== End of FRST.txt ============================

 

ADDITION.txt

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 30-11-2017
Ran by [removed] (01-12-2017 21:14:20)
Running from C:\Users\[removed]\Desktop
Windows 10 Home Version 1709 16299.64 (X64) (2017-11-28 06:00:29)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-914164008-461376372-368114211-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-914164008-461376372-368114211-503 - Limited - Disabled)
Guest (S-1-5-21-914164008-461376372-368114211-501 - Limited - Disabled)
Kevin (S-1-5-21-914164008-461376372-368114211-1001 - Administrator - Enabled) => C:\Users\Kevin Lenertz
piama (S-1-5-21-914164008-461376372-368114211-1002 - Limited - Enabled) => C:\Users\piama
WDAGUtilityAccount (S-1-5-21-914164008-461376372-368114211-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: AVG Antivirus (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG Antivirus (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Acrobat Reader DC (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 18.009.20044 - Adobe Systems Incorporated)
AVG (HKLM\…\{E61E6143-4937-43FC-8C12-06B8A987484D}) (Version: 1.211.3 - AVG Technologies) Hidden
AVG AntiVirus FREE (HKLM-x32\…\AVG Antivirus) (Version: 17.8.3036 - AVG Technologies)
CyberLink Media Suite Essentials (HKLM-x32\…\InstallShield_{8F14AA37-5193-4A14-BD5B-BDF9B361AEF7}) (Version: 12 - CyberLink Corp.)
Dell Customer Connect (HKLM-x32\…\{04A41EBC-AB30-4574-A14D-E0CDFE31AB70}) (Version: 1.5.1.0 - Dell Inc.)
Dell Digital Delivery (HKLM-x32\…\{AB7F2792-2ED1-4C5C-9F28-680E5110BF72}) (Version: 3.1.1018.0 - Dell Products, LP)
Dell Foundation Services (HKLM\…\{AE5E3C86-2633-4DAF-A7F4-C43D1E738BAE}) (Version: 3.1.3300.0 - Dell Inc.)
Dell Help & Support (HKLM\…\{457EFE69-8F49-43E0-80F9-1DEF4F7690C2}) (Version: 2.5.23.0 - Dell Inc.) Hidden
Dell Help & Support (HKLM-x32\…\InstallShield_{457EFE69-8F49-43E0-80F9-1DEF4F7690C2}) (Version: 2.5.23.0 - Dell Inc.)
Dell SupportAssist (HKLM\…\PC-Doctor for Windows) (Version: 2.0.6875.668 - Dell)
Dell SupportAssistAgent (HKLM\…\{18EF001B-B005-46CB-917B-112BA69ED85E}) (Version: 2.0.3.10 - Dell)
Dell Update (HKLM-x32\…\{F91263FA-BE4D-439D-9C0A-2E7204E0E9E3}) (Version: 1.9.20.0 - Dell Inc.)
Dropbox 20 GB (HKLM-x32\…\{597A58EC-42D6-4940-8739-FB94491B013C}) (Version: 1.0.8.0 - Dropbox, Inc.)
FMW 1 (HKLM\…\{36133E9F-B129-4206-9FB4-13F707787542}) (Version: 1.226.3 - AVG Technologies) Hidden
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 62.0.3202.94 - Google Inc.)
Google Update Helper (HKLM-x32\…\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.7 - Google Inc.) Hidden
Intel(R) Chipset Device Software (HKLM-x32\…\{60c073df-e736-4210-9c3a-5fc2b651cef3}) (Version: 10.1.1.7 - Intel(R) Corporation) Hidden
Intel(R) Management Engine Components (HKLM\…\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.0.0.1158 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.15.4281 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\…\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 14.5.0.1081 - Intel Corporation)
Intel(R) Serial IO (HKLM\…\{9FD91C5C-44AE-4D9D-85BE-AE52816B0294}) (Version: 30.100.1519.7 - Intel Corporation)
Intel(R) Wireless Bluetooth(R) (HKLM-x32\…\{DC5673D2-228D-45BC-B9BB-9610CE67DFC0}) (Version: 17.1.1524.1353 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\…\{8431b7d7-59d1-4f45-8212-a2eac049528f}) (Version: 19.60.0 - Intel Corporation)
Intel® Security Assist (HKLM-x32\…\{4B230374-6475-4A73-BA6E-41015E9C5013}) (Version: 1.0.0.532 - Intel Corporation)
Maxx Audio Installer (x64) (HKLM\…\{307032B2-6AF2-46D7-B933-62438DEB2B9A}) (Version: 2.6.6168.10 - Waves Audio Ltd.) Hidden
Microsoft Office Professional Plus 2016 - en-us (HKLM\…\ProPlusRetail - en-us) (Version: 16.0.8625.2139 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-914164008-461376372-368114211-1001\…\OneDriveSetup.exe) (Version: 17.3.7076.1026 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\…\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Mozilla Firefox 57.0 (x64 en-US) (HKLM\…\Mozilla Firefox 57.0 (x64 en-US)) (Version: 57.0 - Mozilla)
Mozilla Maintenance Service (HKLM\…\MozillaMaintenanceService) (Version: 57.0 - Mozilla)
Office 16 Click-to-Run Extensibility Component (HKLM-x32\…\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.8625.2139 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\…\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.8625.2139 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\…\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.8625.2139 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM-x32\…\{90160000-008C-0409-0000-0000000FF1CE}) (Version: 16.0.8326.2076 - Microsoft Corporation) Hidden
Product Registration (HKLM\…\{C1600AC7-74E3-4BB5-8B42-B13653792252}) (Version: 2.2.38.0 - Dell Inc.) Hidden
Product Registration (HKLM-x32\…\InstallShield_{C1600AC7-74E3-4BB5-8B42-B13653792252}) (Version: 2.2.38.0 - Dell Inc.)
Quickset64 (HKLM\…\{87CF757E-C1F1-4D22-865C-00C6950B5258}) (Version: 10.17.007 - Dell Inc.)
Realtek Card Reader (HKLM-x32\…\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.10125.31214 - Realtek Semiconductor Corp.)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8142 - Realtek Semiconductor Corp.)
Vulkan Run Time Libraries 1.0.33.0 (HKLM\…\VulkanRT1.0.33.0) (Version: 1.0.33.0 - LunarG, Inc.)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ContextMenuHandlers1: [AVG] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files (x86)\AVG\Antivirus\ashShA64.dll [2017-11-29] (AVG Technologies CZ, s.r.o.)
ContextMenuHandlers1: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} => C:\Program Files (x86)\Common Files\CyberLink\ShellExtComponent\CLVDShellExt.dll [2015-08-19] (Cyberlink)
ContextMenuHandlers2: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} => C:\Program Files (x86)\Common Files\CyberLink\ShellExtComponent\CLVDShellExt.dll [2015-08-19] (Cyberlink)
ContextMenuHandlers3: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} =>  -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\System32\DriverStore\FileRepository\k120836.inf_amd64_ccaf7e7e1e972b78\igfxDTCM.dll [2017-02-20] (Intel Corporation)
ContextMenuHandlers6: [AVG] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files (x86)\AVG\Antivirus\ashShA64.dll [2017-11-29] (AVG Technologies CZ, s.r.o.)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {02A84F56-5B9F-42F8-A3F2-5A87EF4CB164} - System32\Tasks\RtHDVBg_PushButton => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2017-05-04] (Realtek Semiconductor)
Task: {0659ACD4-40E7-4C82-B949-8B956B9AD8F7} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2017-12-01] ()
Task: {135AD230-354F-44B6-8449-5462D1009EE5} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-11-29] (Google Inc.)
Task: {16123C84-B934-47F7-AAF2-7DB1DC4B2789} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2017-12-01] (Microsoft Corporation)
Task: {186B99C9-E05D-44F0-93DF-EDAD3D7D50AB} - System32\Tasks\Antivirus Emergency Update => C:\Program Files (x86)\AVG\Antivirus\AvEmUpdate.exe [2017-11-29] (AVG Technologies CZ, s.r.o.)
Task: {252B8C39-D96E-41CE-A07D-1681FC3D011D} - System32\Tasks\AVG EUpdate Task => avgsetupx.exe
Task: {2751713A-AF0E-4C8A-8423-2D46ABCEDA5E} - System32\Tasks\PCDoctorBackgroundMonitorTask => C:\Program Files\Dell\SupportAssist\uaclauncher.exe [2017-09-14] (PC-Doctor, Inc.)
Task: {3A734DD5-AEDD-4539-8406-66B86C524B80} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-11-22] (Microsoft Corporation)
Task: {496B5C3E-8461-4D62-AA4C-659FED9B34A3} - System32\Tasks\PCDDataUploadTask => uaclauncher.exe
Task: {7A16DC76-D0F0-473E-95A8-0ADC55C0F21A} - System32\Tasks\CLVDLauncher => C:\Program Files (x86)\CyberLink\CyberLink Media Suite\Power2Go8\CLVDLauncher.exe [2015-01-28] (CyberLink Corp.)
Task: {7C7FB473-318B-4B24-87EF-B97E945C2C54} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2017-12-01] (Microsoft Corporation)
Task: {81279E7B-1EF4-4219-8627-041D2895397E} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-11-29] (Google Inc.)
Task: {A81CCB0D-61DB-487B-9FC6-107236FAB119} - System32\Tasks\DropboxOEM => C:\Program Files (x86)\Dropbox\DropboxOEM\DropboxOEM.exe [2015-05-29] ()
Task: {AB56FFF7-8486-404A-8EF4-C9D597A9FF13} - System32\Tasks\UninstallDDS-C960901F-CE14-4DE1-9729-1305F719A337 => C:\WINDOWS\TEMP\DeleteFolderTask.exe [2017-11-28] () <==== ATTENTION
Task: {B5FE7616-C578-4B0F-ADF6-C2EA047CB9B2} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2017-12-01] ()
Task: {BAB42E23-8D27-4710-8D7B-6825F62600A1} - System32\Tasks\PCDEventLauncherTask => C:\Program Files\Dell\SupportAssist\sessionchecker.exe [2017-09-14] (PC-Doctor, Inc.)
Task: {BEB9724A-11A0-42EE-942F-FC434F0D6A64} - System32\Tasks\SystemToolsDailyTest => uaclauncher.exe
Task: {C9A1FBED-7D67-4971-8896-404DCF1216FD} - System32\Tasks\CLMLSvc_P2G8 => C:\Program Files (x86)\CyberLink\CyberLink Media Suite\Power2Go8\CLMLSvc_P2G8.exe [2015-08-18] (CyberLink)
Task: {D3803C01-559B-44A2-B519-BF96CE9BACEE} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-11-22] (Microsoft Corporation)
Task: {E2D0DF52-9A35-4A9A-93B7-0D47F945507D} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-09-27] (Adobe Systems Incorporated)
Task: {ED49CDD2-E348-485D-A11E-EF1B13785AE9} - System32\Tasks\Dell SupportAssistAgent AutoUpdate => C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssist.exe [2017-09-22] (Dell Inc.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


==================== Loaded Modules (Whitelisted) ==============

2017-09-29 05:41 - 2017-09-29 05:41 - 000184432 ____N () C:\WINDOWS\SYSTEM32\inputhost.dll
2015-05-19 08:11 - 2015-05-19 08:11 - 000007680 _____ () C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe
2015-10-01 11:42 - 2014-04-14 17:59 - 000253776 _____ () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
2017-11-16 19:34 - 2017-10-24 19:18 - 000975872 ____N () c:\windows\system32\FaceProcessor.dll
2017-11-16 19:34 - 2017-10-24 20:40 - 000269696 ____N () c:\windows\system32\FaceProcessorCore.dll
2017-09-29 05:41 - 2017-09-29 05:41 - 001357464 ____N () c:\windows\system32\FaceTrackerInternal.dll
2017-12-01 20:43 - 2017-12-01 20:43 - 008931496 _____ () C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\1033\GrooveIntlResource.dll
2017-09-29 05:42 - 2017-09-29 06:43 - 011044864 ____N () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2017-09-29 05:42 - 2017-09-29 06:43 - 001804288 ____N () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2015-05-29 15:12 - 2015-05-29 15:12 - 000505200 _____ () C:\Program Files (x86)\Dropbox\DropboxOEM\DropboxOEM.exe
2017-11-29 00:23 - 2017-11-29 00:22 - 048920064 _____ () C:\Program Files (x86)\AVG\UiDll\2623\libcef.dll
2017-11-29 00:26 - 2017-11-29 00:26 - 000168216 _____ () C:\Program Files (x86)\AVG\Antivirus\JsonRpcServer.dll
2017-11-29 00:26 - 2017-11-29 00:26 - 000060160 _____ () C:\Program Files (x86)\AVG\Antivirus\module_lifetime.dll
2017-11-29 00:26 - 2017-11-29 00:26 - 067109376 _____ () C:\Program Files (x86)\AVG\Antivirus\libcef.dll
2017-11-29 00:26 - 2017-11-29 00:26 - 000238928 _____ () C:\Program Files (x86)\AVG\Antivirus\event_routing_rpc.dll
2017-11-29 00:26 - 2017-11-29 00:26 - 000245704 _____ () C:\Program Files (x86)\AVG\Antivirus\tasks_core.dll
2015-10-01 11:40 - 2014-12-07 23:28 - 000627672 _____ () C:\Program Files (x86)\CyberLink\CyberLink Media Suite\Power2Go8\CLMediaLibrary.dll
2014-12-08 14:28 - 2014-12-08 14:28 - 000016856 _____ () C:\Program Files (x86)\CyberLink\CyberLink Media Suite\Power2Go8\CLMLSvcPS.dll
2017-09-19 10:35 - 2017-09-19 10:35 - 000134008 _____ () C:\Program Files (x86)\Dell Customer Connect\ServiceTagPlusPlus.dll
2015-06-23 15:26 - 2015-06-23 15:26 - 000155888 _____ () c:\Program Files (x86)\Dell Digital Delivery\ServiceTagPlusPlus.dll
2017-05-01 15:27 - 2017-05-01 15:27 - 000133992 _____ () C:\Program Files (x86)\Dell Update\ServiceTagPlusPlus.dll
2015-07-10 22:37 - 2015-07-10 22:37 - 001243936 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2015-07-10 03:04 - 2015-07-10 03:02 - 000000824 _____ C:\WINDOWS\system32\Drivers\etc\hosts


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-914164008-461376372-368114211-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Kevin Lenertz\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
HKU\S-1-5-21-914164008-461376372-368114211-1002\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\web\wallpaper\Windows\img0.jpg
DNS Servers: 192.168.1.254
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==


==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{3792AC3B-8AE6-452E-AA1E-1B542CB8D973}] => (Allow) C:\Program Files (x86)\CyberLink\CyberLink Media Suite\PowerDVD12\Movie\PowerDVD Cinema\PowerDVDCinema12.exe
FirewallRules: [{045A3A6A-5B4D-431C-AAC2-61CCAFBF84A6}] => (Allow) C:\Program Files (x86)\CyberLink\CyberLink Media Suite\PowerDirector12\PDR10.EXE
FirewallRules: [{DB4490CB-3C32-401E-9E05-43DB3A2D0740}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
FirewallRules: [{643420FF-197D-4AEA-9767-3F482382D802}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{5EC2A110-0BA1-492B-858A-E510518D7C76}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{5D27D243-CD5C-4ABD-9A73-6881988ED741}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{8ABD412D-F59E-4D65-B3A9-BB1D944FFB52}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe
FirewallRules: [{8DEE81E7-9065-4D06-AF4C-6DFBB85F4048}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{674CA0FE-8AEF-4901-BCBD-2A8823A05184}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{086DA54B-ACE4-4CEC-93DC-ED892B2922D0}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [{A49FAE02-64FA-4180-8E52-46EFBB08F5BE}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe

==================== Restore Points =========================

28-11-2017 06:39:40 Windows Update
28-11-2017 06:39:58 Windows Update

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (12/01/2017 09:08:54 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: quickset.exe, version: 10.17.7.3, time stamp: 0x558a13bc
Faulting module name: quickset.exe, version: 10.17.7.3, time stamp: 0x558a13bc
Exception code: 0xc0000005
Fault offset: 0x00000000000041d0
Faulting process id: 0x22b8
Faulting application start time: 0x01d36b2ba386aedd
Faulting application path: C:\Program Files\Dell\QuickSet\quickset.exe
Faulting module path: C:\Program Files\Dell\QuickSet\quickset.exe
Report Id: 5d0e46b7-b64f-4695-9d79-8e4d82cd4183
Faulting package full name:
Faulting package-relative application ID:

Error: (12/01/2017 09:03:45 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: quickset.exe, version: 10.17.7.3, time stamp: 0x558a13bc
Faulting module name: quickset.exe, version: 10.17.7.3, time stamp: 0x558a13bc
Exception code: 0xc0000005
Fault offset: 0x00000000000041d0
Faulting process id: 0x90c
Faulting application start time: 0x01d36b2aec9e634b
Faulting application path: C:\Program Files\Dell\QuickSet\quickset.exe
Faulting module path: C:\Program Files\Dell\QuickSet\quickset.exe
Report Id: f67fb7a5-2441-4a4b-bc55-73b1f505629c
Faulting package full name:
Faulting package-relative application ID:

Error: (12/01/2017 08:54:42 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: quickset.exe, version: 10.17.7.3, time stamp: 0x558a13bc
Faulting module name: quickset.exe, version: 10.17.7.3, time stamp: 0x558a13bc
Exception code: 0xc000041d
Fault offset: 0x00000000000041d0
Faulting process id: 0x1ecc
Faulting application start time: 0x01d36b29a40a0de0
Faulting application path: C:\Program Files\Dell\QuickSet\quickset.exe
Faulting module path: C:\Program Files\Dell\QuickSet\quickset.exe
Report Id: 92888313-8a14-4d66-8de2-b4058a7c133d
Faulting package full name:
Faulting package-relative application ID:

Error: (12/01/2017 08:54:31 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: quickset.exe, version: 10.17.7.3, time stamp: 0x558a13bc
Faulting module name: quickset.exe, version: 10.17.7.3, time stamp: 0x558a13bc
Exception code: 0xc0000005
Fault offset: 0x00000000000041d0
Faulting process id: 0x1ecc
Faulting application start time: 0x01d36b29a40a0de0
Faulting application path: C:\Program Files\Dell\QuickSet\quickset.exe
Faulting module path: C:\Program Files\Dell\QuickSet\quickset.exe
Report Id: 0de3336d-9720-46bf-bac0-aed3703de22e
Faulting package full name:
Faulting package-relative application ID:

Error: (12/01/2017 08:33:33 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: quickset.exe, version: 10.17.7.3, time stamp: 0x558a13bc
Faulting module name: quickset.exe, version: 10.17.7.3, time stamp: 0x558a13bc
Exception code: 0xc000041d
Fault offset: 0x00000000000041d0
Faulting process id: 0x2040
Faulting application start time: 0x01d36b2646bf46ec
Faulting application path: C:\Program Files\Dell\QuickSet\quickset.exe
Faulting module path: C:\Program Files\Dell\QuickSet\quickset.exe
Report Id: caaf8c92-49fa-4320-b2b9-20e1ad176dab
Faulting package full name:
Faulting package-relative application ID:

Error: (12/01/2017 08:30:34 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: quickset.exe, version: 10.17.7.3, time stamp: 0x558a13bc
Faulting module name: quickset.exe, version: 10.17.7.3, time stamp: 0x558a13bc
Exception code: 0xc0000005
Fault offset: 0x00000000000041d0
Faulting process id: 0x2040
Faulting application start time: 0x01d36b2646bf46ec
Faulting application path: C:\Program Files\Dell\QuickSet\quickset.exe
Faulting module path: C:\Program Files\Dell\QuickSet\quickset.exe
Report Id: 15fefee5-0809-4493-b68f-0de5c8feb315
Faulting package full name:
Faulting package-relative application ID:

Error: (12/01/2017 08:28:46 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: ZeroConfigService.exe, version: 19.60.0.0, time stamp: 0x58d16fa6
Faulting module name: ZeroConfigService.exe, version: 19.60.0.0, time stamp: 0x58d16fa6
Exception code: 0xc0000409
Fault offset: 0x000000000022af80
Faulting process id: 0xe4c
Faulting application start time: 0x01d368f4fd404f93
Faulting application path: C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
Faulting module path: C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
Report Id: 76cbf46b-d7f1-4871-a0ac-674f5db821d4
Faulting package full name:
Faulting package-relative application ID:

Error: (12/01/2017 08:28:27 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program explorer.exe version 10.0.16299.15 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.

Process ID: 2da4

Start Time: 01d36b259fdb071b

Termination Time: 0

Application Path: C:\Windows\explorer.exe

Report Id: 02be570d-ed5a-4784-ad2d-9b89320c6411

Faulting package full name:

Faulting package-relative application ID:

Error: (12/01/2017 08:25:47 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program explorer.exe version 10.0.16299.15 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.

Process ID: 1790

Start Time: 01d368f59695d724

Termination Time: 60000

Application Path: C:\Windows\explorer.exe

Report Id: d05a54e4-cd00-465d-9bea-17394b5629f5

Faulting package full name:

Faulting package-relative application ID:

Error: (12/01/2017 08:25:45 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: explorer.exe, version: 10.0.16299.15, time stamp: 0x66e02565
Faulting module name: windows.immersiveshell.serviceprovider.dll, version: 10.0.16299.15, time stamp: 0xdabe3df6
Exception code: 0x80270233
Fault offset: 0x000000000004ec39
Faulting process id: 0xb28
Faulting application start time: 0x01d36b256e612328
Faulting application path: C:\Windows\explorer.exe
Faulting module path: C:\Windows\System32\windows.immersiveshell.serviceprovider.dll
Report Id: 6fe3af9f-4859-4f3a-86cd-60546f4a2e50
Faulting package full name:
Faulting package-relative application ID:


System errors:
=============
Error: (12/01/2017 09:08:24 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (12/01/2017 09:08:24 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (12/01/2017 09:07:40 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 9:02:35 PM on ‎12/‎1/‎2017 was unexpected.

Error: (12/01/2017 09:03:18 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (12/01/2017 09:03:18 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (12/01/2017 09:02:35 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 8:54:45 PM on ‎12/‎1/‎2017 was unexpected.

Error: (12/01/2017 08:55:24 PM) (Source: DCOM) (EventID: 10010) (User: THUNDERBOLT2)
Description: The server {14286318-B6CF-49A1-81FC-D74AD94902F9} did not register with DCOM within the required timeout.

Error: (12/01/2017 08:55:03 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (12/01/2017 08:54:16 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (12/01/2017 08:54:16 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.


==================== Memory info ===========================

Processor: Intel(R) Core(TM) i5-6200U CPU @ 2.30GHz
Percentage of memory in use: 40%
Total physical RAM: 8083.71 MB
Available physical RAM: 4774.38 MB
Total Virtual: 9363.71 MB
Available Virtual: 5924.98 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:918.31 GB) (Free:766.87 GB) NTFS
Drive d: () (CDROM) (Total:0.03 GB) (Free:0 GB) CDFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: 658A1F1F)

Partition: GPT.

==================== End of Addition.txt ============================


 

Hi
I can see errors thrown out in the logs that relate to your wireless devices.
 
Faulting application path: scan for available WiFi networks and troubleshoot wireless connection problems.
C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe Faulting module path: C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe The WiFi Connection Utility lets users view the current connection details (signal quality, speed and current network name),
 
I've collected a few web sites with discussions to this 
http://en.community.dell.com/support-forums/laptop/f/3518/t/20017387https://answers.microsoft.com/en-us/windows/forum/windows_10-networking/windows-10-airplane-mode-wont-turn-off/c2739cb9-8b97-4e94-8b08-0709e30709f0
https://h30434.www3.hp.com/t5/Notebook-Wireless-and-Networking/Aeroplane-mode-getting-ON-and-OFF-automatically/td-p/5572607https://communities.intel.com/thread/115242


~~~~~~~~~~~~`

Start Farbar Recovery Scan Tool with Administrator privileges
or Right click on the FRST icon and select Run as administrator

Right click/highlight on the text below and select Copy.
beginning with Start:: and finishing with End::


Start::
CloseProcesses:
CreateRestorePoint:
HKU\S-1-5-21-914164008-461376372-368114211-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://mysearch.avg.com/?cid=%7BEC3E0E9B-0CCC-4DC9-8FEE-A49F2D7D2241%7D&mid=30dc798aba5047ccb877a945fecc4f1d-755cdf6c1f988ce36c8cd1b6bc64b36ab09dd6bd&lang=en&ds=AVG&coid=avgtbavg&cmpid=0516tb&pr=fr&d=2015-11-05%2022:59:35&v=4.3.1.831&pid=wtu&sg=&sap=hp
HKU\S-1-5-21-914164008-461376372-368114211-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://dell15.msn.com/?pc=DCTE
ContextMenuHandlers3: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
Task: {AB56FFF7-8486-404A-8EF4-C9D597A9FF13} - System32\Tasks\UninstallDDS-C960901F-CE14-4DE1-9729-1305F719A337 => C:\WINDOWS\TEMP\DeleteFolderTask.exe [2017-11-28] () <==== ATTENTION
Emptytemp:
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: ipconfig /flushdns
CMD: netsh winsock reset catalog
CMD: Bitsadmin /Reset /Allusers
End::


Press the Fix button.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.

******

Thank you Juliet.  I'm not having an issue turning off the airplane mode.  I took one of those links and disabled airplane mode, which seems to have worked.  However, i still can't turn off the laptop.  When i shut down it restarts every time.

KL

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 30-11-2017
Ran by [removed] (05-12-2017 00:07:55) Run:1
Running from C:\Users\[removed]\Desktop\What the Tech 12-2017
[removed] Boot Mode: Normal
==============================================

fixlist content:
*****************
CloseProcesses:
CreateRestorePoint:
HKU\S-1-5-21-914164008-461376372-368114211-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://mysearch.avg.com/?cid=%7BEC3E0E9B-0CCC-4DC9-8FEE-A49F2D7D2241%7D&mid=30dc798aba5047ccb877a945fecc4f1d-755cdf6c1f988ce36c8cd1b6bc64b36ab09dd6bd&lang=en&ds=AVG&coid=avgtbavg&cmpid=0516tb&pr=fr&d=2015-11-05%2022:59:35&v=4.3.1.831&pid=wtu&sg=&sap=hp
HKU\S-1-5-21-914164008-461376372-368114211-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://dell15.msn.com/?pc=DCTE
ContextMenuHandlers3: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
Task: {AB56FFF7-8486-404A-8EF4-C9D597A9FF13} - System32\Tasks\UninstallDDS-C960901F-CE14-4DE1-9729-1305F719A337 => C:\WINDOWS\TEMP\DeleteFolderTask.exe [2017-11-28] () <==== ATTENTION
Emptytemp:
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: ipconfig /flushdns
CMD: netsh winsock reset catalog
CMD: Bitsadmin /Reset /Allusers

*****************

Processes closed successfully.
Restore point was successfully created.
HKU\S-1-5-21-914164008-461376372-368114211-1001\Software\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
HKU\S-1-5-21-914164008-461376372-368114211-1001\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully
HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers\00avg => key removed successfully
HKLM\Software\Classes\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => key not found
HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxcui => key removed successfully
HKLM\Software\Classes\CLSID\{3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => key not found
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{AB56FFF7-8486-404A-8EF4-C9D597A9FF13} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AB56FFF7-8486-404A-8EF4-C9D597A9FF13} => key removed successfully
C:\WINDOWS\System32\Tasks\UninstallDDS-C960901F-CE14-4DE1-9729-1305F719A337 => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\UninstallDDS-C960901F-CE14-4DE1-9729-1305F719A337 => key removed successfully

========= netsh advfirewall reset =========

Ok.


========= End of CMD: =========


========= netsh advfirewall set allprofiles state ON =========

Ok.


========= End of CMD: =========


========= ipconfig /flushdns =========


Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

========= End of CMD: =========


========= netsh winsock reset catalog =========


Sucessfully reset the Winsock Catalog.
You must restart the computer in order to complete the reset.


========= End of CMD: =========


========= Bitsadmin /Reset /Allusers =========


BITSADMIN version 3.0
BITS administration utility.
(C) Copyright 2000-2006 Microsoft Corp.

BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.

0 out of 0 jobs canceled.

========= End of CMD: =========


=========== EmptyTemp: ==========

BITS transfer queue => 7888896 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 11742700 B
Java, Flash, Steam htmlcache => 1199 B
Windows/system/drivers => 67972685 B
Edge => 1058503 B
Chrome => 0 B
Firefox => 364182451 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 6656 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 19738 B
NetworkService => 27672556 B
Kevin Lenertz => 1584431580 B
piama => 88331 B

RecycleBin => 0 B
EmptyTemp: => 1.9 GB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 00:12:56 ====

Sounds like a system setting or driver not working correct.

Let's run another malware scan then a repair scan.

[external image: RQKuhw1.png]RogueKiller
  • Download the right version of RogueKiller for your Windows version (32 or 64-bit)
  • Once done, move the executable file to your Desktop, right-click on it and select [external image: Spcusrh.png]Run as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users)
  • Click on the Start Scan button in the right panel, which will bring you to another tab, and click on it again (this time it'll be in the bottom right corner)
  • Wait for the scan to complete
  • On completion, the results will be displayed
  • Check every single entry (threat found), and click on the Remove Selected button
  • On completion, the results will be displayed. Click on the Open Report button in the bottom left corner, followed by the Open TXT button (also in the bottom left corner)
  • This will open the report in Notepad. Copy/paste its content in your next reply
  • created by Aura
~~~~~~~~~~~~~~~~~~~~~~~

Please Download Tweaking.com - Windows Repair from Here
OR
Windows Repair (all in one) from here.
  • Install and then run the program
  • Execute the instructions on Step 1 Important
  • Click Next on Step 2 Optional, do the Pre Scan skip Step 3 and 4 Optional for now.
  • On Step 5 Backup System Restore Do a Registry backup. When you have completed this click Next
  • Click Repairs - Open Repairs in the bottom right corner
  • Uncheck the All repair button then select just the item(s) listed below

    01 - Repair Registry Permissions
    03 - Reset Service permissions
    04 - Register System Files
    05 - Repair WMI
    06 - Repair Windows Firewall
    07 - Repair Internet Explorer
    10 - Remove Policies Set By Infections
    17 - Repair Windows Updates
    19 - Repair Volume Shadow Copy Service
    21 - Repair MSI (Windows Installer)
    26 - Restore Important Windows Services
    27 - Set Windows Service to Default Startup
  • Click the Start button and let the process run to completion. Copy any error messages into Notepad, Save it on your Desktop. ( Reboot if asked to do so)
  • Please copy and paste the Contents of this file on your next reply.
  • Restart the computer normally.

I stand corrected, when the laptop restarted last night, it restarted in airplane mode so that was still an issue.  Also, i provided two Tweaking reports because I failed to read your directions in full and didn't deselect the options you told me to.  So, report #1 is with all the options selected, report #2 is with the options you told me to select.  Also, the numbers you have with your selections are inaccurate; i.e.: #27 Set Windows Service to Default Startup is actually selection #26.

KL

 

SCAN REPORT

RogueKiller V12.11.27.0 (x64) [Dec  4 2017] (Free) by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : https://forum.adlice.com
Website : http://www.adlice.com/download/roguekiller/
Blog : http://www.adlice.com

Operating System : Windows 10 (10.0.16299) 64 bits version
Started in : Normal mode
User : Kevin [Administrator]
Started from : C:\Users\Kevin Lenertz\Desktop\What the Tech 12-2017\RogueKiller_portable64.exe
Mode : Scan – Date : 12/06/2017 19:12:54 (Duration : 00:40:02)

¤¤¤ Processes : 0 ¤¤¤

¤¤¤ Registry : 0 ¤¤¤

¤¤¤ Tasks : 0 ¤¤¤

¤¤¤ Files : 0 ¤¤¤

¤¤¤ WMI : 0 ¤¤¤

¤¤¤ Hosts File : 0 ¤¤¤

¤¤¤ Antirootkit : 0 (Driver: Loaded) ¤¤¤

¤¤¤ Web browsers : 1 ¤¤¤
[PUM.HomePage][Firefox:Config] 04zcreyr.default : user_pref("browser.startup.homepage", "https://www.wwdb.com");-> Found

¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: WDC WD10JPVX-75JC3T0 +++++
— User —
[MBR] ce6f763e66903a6da61db10afbdc18b3
[BSP] a4c039eeaee7e427d8e85158a427a2a6 : Empty MBR Code
Partition table:
0 - [MAN-MOUNT] EFI system partition | Offset (sectors): 2048 | Size: 500 MB
1 - [MAN-MOUNT] Microsoft reserved partition | Offset (sectors): 1026048 | Size: 128 MB
2 - Basic data partition | Offset (sectors): 1288192 | Size: 940349 MB
3 - [SYSTEM][MAN-MOUNT]  | Offset (sectors): 1927122944 | Size: 851 MB
4 - [SYSTEM][MAN-MOUNT]  | Offset (sectors): 1928865792 | Size: 12040 MB
User = LL1 … OK
User = LL2 … OK


DELETE REPORT

RogueKiller V12.11.27.0 (x64) [Dec  4 2017] (Free) by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : https://forum.adlice.com
Website : http://www.adlice.com/download/roguekiller/
Blog : http://www.adlice.com

Operating System : Windows 10 (10.0.16299) 64 bits version
Started in : Normal mode
User : Kevin [Administrator]
Started from : C:\Users\Kevin Lenertz\Desktop\What the Tech 12-2017\RogueKiller_portable64.exe
Mode : Delete – Date : 12/06/2017 19:12:54 (Duration : 00:40:02)

¤¤¤ Processes : 0 ¤¤¤

¤¤¤ Registry : 0 ¤¤¤

¤¤¤ Tasks : 0 ¤¤¤

¤¤¤ Files : 0 ¤¤¤

¤¤¤ WMI : 0 ¤¤¤

¤¤¤ Hosts File : 0 ¤¤¤

¤¤¤ Antirootkit : 0 (Driver: Loaded) ¤¤¤

¤¤¤ Web browsers : 1 ¤¤¤
[PUM.HomePage][Firefox:Config] 04zcreyr.default : user_pref("browser.startup.homepage", "https://www.wwdb.com");-> Replaced (about:home)

¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: WDC WD10JPVX-75JC3T0 +++++
— User —
[MBR] ce6f763e66903a6da61db10afbdc18b3
[BSP] a4c039eeaee7e427d8e85158a427a2a6 : Empty MBR Code
Partition table:
0 - [MAN-MOUNT] EFI system partition | Offset (sectors): 2048 | Size: 500 MB
1 - [MAN-MOUNT] Microsoft reserved partition | Offset (sectors): 1026048 | Size: 128 MB
2 - Basic data partition | Offset (sectors): 1288192 | Size: 940349 MB
3 - [SYSTEM][MAN-MOUNT]  | Offset (sectors): 1927122944 | Size: 851 MB
4 - [SYSTEM][MAN-MOUNT]  | Offset (sectors): 1928865792 | Size: 12040 MB
User = LL1 … OK
User = LL2 … OK

Tweaking Report #1

 

Tweaking.com - Windows Repair 2018 (v4.0.10)
——————————————————————————–

System Variables
——————————————————————————–
OS: Windows 10 Home
OS Architecture: 64-bit
OS Version: 10.0.16299.64
OS Service Pack:
Computer Name: THUNDERBOLT2
Windows Drive: C:\
Windows Path: C:\WINDOWS
Program Files: C:\Program Files
Program Files (x86): C:\Program Files (x86)
Current Profile: C:\Users\Kevin Lenertz
Current Profile SID: S-1-5-21-914164008-461376372-368114211-1001
Current Profile Classes: S-1-5-21-914164008-461376372-368114211-1001_Classes
Profiles Location: C:\Users
Profiles Location 2: C:\WINDOWS\ServiceProfiles
Local Settings AppData: C:\Users\Kevin Lenertz\AppData\Local
——————————————————————————–

System Information
——————————————————————————–
System Up Time: 0 Days 00:48:12

Process Count: 154
Commit Total: 3.34 GB
Commit Limit: 9.14 GB
Commit Peak: 3.79 GB
Handle Count: 60460
Kernel Total: 925.41 MB
Kernel Paged: 682.00 MB
Kernel Non Paged: 243.41 MB
System Cache: 4.76 GB
Thread Count: 1794
——————————————————————————–

Memory Before Cleaning with CleanMem
——————————————————————————–
Memory Total: 7.89 GB
Memory Used: 2.78 GB(35.1906%)
Memory Avail.: 5.12 GB
——————————————————————————–

Cleaning Memory Before Starting Repairs…

Memory After Cleaning with CleanMem
——————————————————————————–
Memory Total: 7.89 GB
Memory Used: 2.44 GB(30.9173%)
Memory Avail.: 5.45 GB
——————————————————————————–

Starting Repairs…
   Started at (12/6/2017 22:11:48)

Setting Any Missing 'InstallDate' From Uninstall Sections Before Running Repair…
Total Missing 'InstallDate' Fixed: 0
 
01 - Reset Registry Permissions
   Restore Windows 7/8/10 Default Registry Permissions
   Start (12/6/2017 22:11:51)


Decompressing & Updating Windows Permission File C:\Users\Kevin Lenertz\Desktop\What the Tech 12-2017\tweaking.com_windows_repair_aio\Tweaking.com - Windows Repair\files\permissions\10\hku.7z
Done,  0.26 seconds.


Decompressing & Updating Windows Permission File C:\Users\Kevin Lenertz\Desktop\What the Tech 12-2017\tweaking.com_windows_repair_aio\Tweaking.com - Windows Repair\files\permissions\10\hklm.7z
Done,  3.71 seconds.

   Running Repair Under System Account
   Done (12/6/2017 22:12:55)

02 - Reset File Permissions
   Restore Windows 7/8/10 Default File Permissions
   Start (12/6/2017 22:12:55)


Decompressing & Updating Windows Permission File C:\Users\Kevin Lenertz\Desktop\What the Tech 12-2017\tweaking.com_windows_repair_aio\Tweaking.com - Windows Repair\files\permissions\10\default.7z
Done,  0.16 seconds.


Decompressing & Updating Windows Permission File C:\Users\Kevin Lenertz\Desktop\What the Tech 12-2017\tweaking.com_windows_repair_aio\Tweaking.com - Windows Repair\files\permissions\10\profile.7z
Done,  0.22 seconds.


Decompressing & Updating Windows Permission File C:\Users\Kevin Lenertz\Desktop\What the Tech 12-2017\tweaking.com_windows_repair_aio\Tweaking.com - Windows Repair\files\permissions\10\program_files.7z
Done,  0.31 seconds.


Decompressing & Updating Windows Permission File C:\Users\Kevin Lenertz\Desktop\What the Tech 12-2017\tweaking.com_windows_repair_aio\Tweaking.com - Windows Repair\files\permissions\10\program_files_x86.7z
Done,  0.17 seconds.


Decompressing & Updating Windows Permission File C:\Users\Kevin Lenertz\Desktop\What the Tech 12-2017\tweaking.com_windows_repair_aio\Tweaking.com - Windows Repair\files\permissions\10\programdata.7z
Done,  0.19 seconds.


Decompressing & Updating Windows Permission File C:\Users\Kevin Lenertz\Desktop\What the Tech 12-2017\tweaking.com_windows_repair_aio\Tweaking.com - Windows Repair\files\permissions\10\windows.7z
Done,  1.38 seconds.

   Running Repair Under System Account
   Done (12/6/2017 22:17:58)

03 - Reset Service Permissions
   Start (12/6/2017 22:17:58)

   Running Repair Under Current User Account
   Running Repair Under System Account
   Done (12/6/2017 22:18:27)

04 - Register System Files
   Start (12/6/2017 22:18:27)
   Running Repair Under Current User Account
   Running Repair Under System Account
   Done (12/6/2017 22:19:26)

05 - Repair WMI
   Start (12/6/2017 22:19:26)

   Starting Security Center So We Can Export The Security Info.

   Exporting Antivirus Info…
   Windows Defender Exported.
   AVG Antivirus Exported.

   Exporting AntiSpyware Info…
   Windows Defender Exported.
   AVG Antivirus Exported.

   Exporting 3rd Party Firewall Info…
   No Firewall Products Reported.

   Running Repair Under Current User Account
   Done (12/6/2017 22:24:47)

06 - Repair Windows Firewall
   Start (12/6/2017 22:24:47)

Decompressing & Updating Windows Permission File C:\Users\Kevin Lenertz\Desktop\What the Tech 12-2017\tweaking.com_windows_repair_aio\Tweaking.com - Windows Repair\files\permissions\10\services.7z
Done,  0.2 seconds.

   Running Repair Under Current User Account
   Running Repair Under System Account
   Done (12/6/2017 22:25:06)

07 - Repair Internet Explorer
   Start (12/6/2017 22:25:06)
   Running Repair Under Current User Account
   Running Repair Under System Account
   Done (12/6/2017 22:25:34)

08 - Repair MDAC/MS Jet
   Start (12/6/2017 22:25:34)
   Running Repair Under Current User Account
   Running Repair Under System Account
   Done (12/6/2017 22:25:45)

09 - Repair Hosts File
   Start (12/6/2017 22:25:45)
   Running Repair Under System Account
   Done (12/6/2017 22:25:46)

10 - Remove Policies Set By Infections
   Start (12/6/2017 22:25:46)
   Running Repair Under Current User Account
   Running Repair Under System Account
   Done (12/6/2017 22:26:11)

11 - Repair Start Menu Icons Removed By Infections
   Start (12/6/2017 22:26:11)
   Running Repair Under System Account
   Done (12/6/2017 22:26:12)

12 - Repair Icons
   Start (12/6/2017 22:26:12)
   Running Repair Under Current User Account
   Done (12/6/2017 22:26:22)

13 - Repair Network
   Start (12/6/2017 22:26:22)

Decompressing & Updating Windows Permission File C:\Users\Kevin Lenertz\Desktop\What the Tech 12-2017\tweaking.com_windows_repair_aio\Tweaking.com - Windows Repair\files\permissions\10\services.7z
Done,  0.28 seconds.

   Running Repair Under Current User Account
   Running Repair Under System Account
   Done (12/6/2017 22:26:43)

14 - Remove Temp Files
   Start (12/6/2017 22:26:43)
   Running Repair Under System Account
   Done (12/6/2017 22:26:45)

15 - Repair Proxy Settings
   Start (12/6/2017 22:26:45)
   Running Repair Under Current User Account
   Running Repair Under System Account
   Done (12/6/2017 22:26:47)

16 - Repair Windows Updates
   Start (12/6/2017 22:26:47)

Decompressing & Updating Windows Permission File C:\Users\Kevin Lenertz\Desktop\What the Tech 12-2017\tweaking.com_windows_repair_aio\Tweaking.com - Windows Repair\files\permissions\10\services.7z
Done,  0.22 seconds.

   Running Repair Under Current User Account
   Running Repair Under System Account
   Setting Windows Updates Files That Are In Use To Be Removed At Next Boot.
   Done (12/6/2017 22:27:40)

17 - Repair CD/DVD Missing/Not Working
   Start (12/6/2017 22:27:40)
   iTunes or GEARAspiWDM.sys not found, not applying UpperFilters iTunes Reg Key
   Done (12/6/2017 22:27:40)

18 - Repair Volume Shadow Copy Service
   Start (12/6/2017 22:27:40)

Decompressing & Updating Windows Permission File C:\Users\Kevin Lenertz\Desktop\What the Tech 12-2017\tweaking.com_windows_repair_aio\Tweaking.com - Windows Repair\files\permissions\10\services.7z
Done,  0.2 seconds.

   Running Repair Under Current User Account
   Running Repair Under System Account
   Done (12/6/2017 22:28:28)

19 - Repair Windows Sidebar/Gadgets
   Start (12/6/2017 22:28:28)
   Running Repair Under Current User Account
   Running Repair Under System Account
   Done (12/6/2017 22:28:31)

20 - Repair MSI (Windows Installer)
   Start (12/6/2017 22:28:31)

Decompressing & Updating Windows Permission File C:\Users\Kevin Lenertz\Desktop\What the Tech 12-2017\tweaking.com_windows_repair_aio\Tweaking.com - Windows Repair\files\permissions\10\services.7z
Done,  0.19 seconds.

   Running Repair Under Current User Account
   Running Repair Under System Account
   Done (12/6/2017 22:28:46)

21 - Repair Windows Snipping Tool
   Start (12/6/2017 22:28:46)
   Running Repair Under Current User Account
   Running Repair Under System Account
   Done (12/6/2017 22:28:48)

22.01 - Repair bat Association
   Start (12/6/2017 22:28:48)
   Running Repair Under Current User Account
   Running Repair Under System Account
   Done (12/6/2017 22:28:50)

22.02 - Repair cmd Association
   Start (12/6/2017 22:28:50)
   Running Repair Under Current User Account
   Running Repair Under System Account
   Done (12/6/2017 22:28:53)

22.03 - Repair com Association
   Start (12/6/2017 22:28:53)
   Running Repair Under Current User Account
   Running Repair Under System Account
   Done (12/6/2017 22:28:55)

22.04 - Repair Directory Association
   Start (12/6/2017 22:28:55)
   Running Repair Under Current User Account
   Running Repair Under System Account
   Done (12/6/2017 22:28:57)

22.05 - Repair Drive Association
   Start (12/6/2017 22:28:57)
   Running Repair Under Current User Account
   Running Repair Under System Account
   Done (12/6/2017 22:28:59)

22.06 - Repair exe Association
   Start (12/6/2017 22:28:59)
   Running Repair Under Current User Account
   Running Repair Under System Account
   Done (12/6/2017 22:29:01)

22.07 - Repair Folder Association
   Start (12/6/2017 22:29:02)
   Running Repair Under Current User Account
   Running Repair Under System Account
   Done (12/6/2017 22:29:04)

22.08 - Repair inf Association
   Start (12/6/2017 22:29:04)
   Running Repair Under Current User Account
   Running Repair Under System Account
   Done (12/6/2017 22:29:06)

22.09 - Repair lnk (Shortcuts) Association
   Start (12/6/2017 22:29:06)
   Running Repair Under Current User Account
   Running Repair Under System Account
   Done (12/6/2017 22:29:08)

22.10 - Repair msc Association
   Start (12/6/2017 22:29:08)
   Running Repair Under Current User Account
   Running Repair Under System Account
   Done (12/6/2017 22:29:11)

22.11 - Repair reg Association
   Start (12/6/2017 22:29:11)
   Running Repair Under Current User Account
   Running Repair Under System Account
   Done (12/6/2017 22:29:13)

22.12 - Repair scr Association
   Start (12/6/2017 22:29:13)
   Running Repair Under Current User Account
   Running Repair Under System Account
   Done (12/6/2017 22:29:15)

23 - Repair Windows Safe Mode
   Start (12/6/2017 22:29:15)
   Running Repair Under Current User Account
   Running Repair Under System Account
   Done (12/6/2017 22:29:17)

24 - Repair Print Spooler
   Start (12/6/2017 22:29:17)

Decompressing & Updating Windows Permission File C:\Users\Kevin Lenertz\Desktop\What the Tech 12-2017\tweaking.com_windows_repair_aio\Tweaking.com - Windows Repair\files\permissions\10\services.7z
Done,  0.2 seconds.

   Running Repair Under Current User Account
   Running Repair Under System Account
   Done (12/6/2017 22:29:33)

25 - Restore Important Windows Services
   Skipping Repair.
   This repair is currently being updated to support the Windows 10 Fall Update

26 - Set Windows Services To Default Startup
   Skipping Repair.
   This repair is currently being updated to support the Windows 10 Fall Update

27.01 - Repair Windows 8/10 App Store
   Start (12/6/2017 22:29:33)

Decompressing & Updating Windows Permission File C:\Users\Kevin Lenertz\Desktop\What the Tech 12-2017\tweaking.com_windows_repair_aio\Tweaking.com - Windows Repair\files\permissions\10\hku.7z
Done,  0.28 seconds.

   Running Repair Under Current User Account
   Done (12/6/2017 22:33:15)

28 - Repair Windows 8/10 Component Store
   Start (12/6/2017 22:33:15)
   Running Repair Under Current User Account
   Done (12/6/2017 22:48:09)

29 - Restore Windows 8/10 COM+ Unmarshalers
   Start (12/6/2017 22:48:09)
   Running Repair Under System Account
[X] —–Job Complete—–         Items Done: 1      
   Done (12/6/2017 22:48:13)

30 - Repair Windows 'New' Submenu
   Start (12/6/2017 22:48:13)
   Running Repair Under Current User Account
   Running Repair Under System Account
   Done (12/6/2017 22:48:16)

31 - Restore UAC (User Account Control) Settings
   Start (12/6/2017 22:48:16)
   Running Repair Under Current User Account
   Running Repair Under System Account
   Done (12/6/2017 22:48:18)

32 - Repair Performance Counters
   Start (12/6/2017 22:48:18)
   Running Repair Under Current User Account
   Done (12/6/2017 22:48:21)

Cleaning up empty logs…

All Selected Repairs Done.
   Done at (12/6/2017 22:48:21)
   Total Repair Time: 00:36:34


…YOU MUST RESTART YOUR SYSTEM…

 

Tweaking Report #2

 

Tweaking.com - Windows Repair 2018 (v4.0.10)
——————————————————————————–

System Variables
——————————————————————————–
OS: Windows 10 Home
OS Architecture: 64-bit
OS Version: 10.0.16299.64
OS Service Pack:
Computer Name: THUNDERBOLT2
Windows Drive: C:\
Windows Path: C:\WINDOWS
Program Files: C:\Program Files
Program Files (x86): C:\Program Files (x86)
Current Profile: C:\Users\Kevin Lenertz
Current Profile SID: S-1-5-21-914164008-461376372-368114211-1001
Current Profile Classes: S-1-5-21-914164008-461376372-368114211-1001_Classes
Profiles Location: C:\Users
Profiles Location 2: C:\WINDOWS\ServiceProfiles
Local Settings AppData: C:\Users\Kevin Lenertz\AppData\Local
——————————————————————————–

System Information
——————————————————————————–
System Up Time: 0 Days 01:30:20

Process Count: 158
Commit Total: 3.35 GB
Commit Limit: 9.14 GB
Commit Peak: 4.12 GB
Handle Count: 61708
Kernel Total: 903.05 MB
Kernel Paged: 634.27 MB
Kernel Non Paged: 268.77 MB
System Cache: 5.16 GB
Thread Count: 1729
——————————————————————————–

Memory Before Cleaning with CleanMem
——————————————————————————–
Memory Total: 7.89 GB
Memory Used: 2.86 GB(36.2002%)
Memory Avail.: 5.04 GB
——————————————————————————–

Cleaning Memory Before Starting Repairs…

Memory After Cleaning with CleanMem
——————————————————————————–
Memory Total: 7.89 GB
Memory Used: 2.41 GB(30.479%)
Memory Avail.: 5.49 GB
——————————————————————————–

Starting Repairs…
   Started at (12/6/2017 22:53:56)

Setting Any Missing 'InstallDate' From Uninstall Sections Before Running Repair…
Total Missing 'InstallDate' Fixed: 0
 
01 - Reset Registry Permissions
   Restore Windows 7/8/10 Default Registry Permissions
   Start (12/6/2017 22:54:00)


Decompressing & Updating Windows Permission File C:\Users\Kevin Lenertz\Desktop\What the Tech 12-2017\tweaking.com_windows_repair_aio\Tweaking.com - Windows Repair\files\permissions\10\hku.7z
Done,  0.47 seconds.


Decompressing & Updating Windows Permission File C:\Users\Kevin Lenertz\Desktop\What the Tech 12-2017\tweaking.com_windows_repair_aio\Tweaking.com - Windows Repair\files\permissions\10\hklm.7z
Done,  3.87 seconds.

   Running Repair Under System Account
   Done (12/6/2017 22:55:03)

03 - Reset Service Permissions
   Start (12/6/2017 22:55:03)

   Running Repair Under Current User Account
   Running Repair Under System Account
   Done (12/6/2017 22:55:29)

04 - Register System Files
   Start (12/6/2017 22:55:29)
   Running Repair Under Current User Account
   Running Repair Under System Account
   Done (12/6/2017 23:00:04)

05 - Repair WMI
   Start (12/6/2017 23:00:04)

   Starting Security Center So We Can Export The Security Info.

   Exporting Antivirus Info…
   Windows Defender Exported.
   AVG Antivirus Exported.

   Exporting AntiSpyware Info…
   Windows Defender Exported.
   AVG Antivirus Exported.

   Exporting 3rd Party Firewall Info…
   No Firewall Products Reported.

   Running Repair Under Current User Account
   Done (12/6/2017 23:07:02)

06 - Repair Windows Firewall
   Start (12/6/2017 23:07:02)

Decompressing & Updating Windows Permission File C:\Users\Kevin Lenertz\Desktop\What the Tech 12-2017\tweaking.com_windows_repair_aio\Tweaking.com - Windows Repair\files\permissions\10\services.7z
Done,  0.25 seconds.

   Running Repair Under Current User Account
   Running Repair Under System Account
   Done (12/6/2017 23:07:18)

07 - Repair Internet Explorer
   Start (12/6/2017 23:07:18)
   Running Repair Under Current User Account
   Running Repair Under System Account
   Done (12/6/2017 23:08:08)

10 - Remove Policies Set By Infections
   Start (12/6/2017 23:08:08)
   Running Repair Under Current User Account
   Running Repair Under System Account
   Done (12/6/2017 23:08:36)

16 - Repair Windows Updates
   Start (12/6/2017 23:08:36)

Decompressing & Updating Windows Permission File C:\Users\Kevin Lenertz\Desktop\What the Tech 12-2017\tweaking.com_windows_repair_aio\Tweaking.com - Windows Repair\files\permissions\10\services.7z
Done,  0.19 seconds.

   Running Repair Under Current User Account
   Running Repair Under System Account
   Setting Windows Updates Files That Are In Use To Be Removed At Next Boot.
   Done (12/6/2017 23:09:21)

18 - Repair Volume Shadow Copy Service
   Start (12/6/2017 23:09:21)

Decompressing & Updating Windows Permission File C:\Users\Kevin Lenertz\Desktop\What the Tech 12-2017\tweaking.com_windows_repair_aio\Tweaking.com - Windows Repair\files\permissions\10\services.7z
Done,  0.22 seconds.

   Running Repair Under Current User Account
   Running Repair Under System Account
   Done (12/6/2017 23:10:15)

20 - Repair MSI (Windows Installer)
   Start (12/6/2017 23:10:15)

Decompressing & Updating Windows Permission File C:\Users\Kevin Lenertz\Desktop\What the Tech 12-2017\tweaking.com_windows_repair_aio\Tweaking.com - Windows Repair\files\permissions\10\services.7z
Done,  0.17 seconds.

   Running Repair Under Current User Account
   Running Repair Under System Account
   Done (12/6/2017 23:10:33)

25 - Restore Important Windows Services
   Skipping Repair.
   This repair is currently being updated to support the Windows 10 Fall Update

26 - Set Windows Services To Default Startup
   Skipping Repair.
   This repair is currently being updated to support the Windows 10 Fall Update

Cleaning up empty logs…

All Selected Repairs Done.
   Done at (12/6/2017 23:10:33)
   Total Repair Time: 00:16:38


…YOU MUST RESTART YOUR SYSTEM…
 

We have removed any instances I can see of malware/adware and the system problems remain.

What I can do from here is to refer you over to the tech forum and allow them to try and find the issue.
Start a new topic here
https://forums.whatthetech.com/index.php?showforum=119

explain that you can't turn off the laptop and you can post info from this thread to see if that will assist.

We need to remove tools and quarantine folders.

DelFix
  • Please download DelFix or from Here and save the file to your Desktop.
  • Double-click DelFix.exe to run the programme.
  • Place a checkmark next to the following items:
  • Activate UAC
  • Remove disinfection tools
  • Click the Run button.
  • – This will remove the specialized tools we used to disinfect your system.
    Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually (right-click the file + delete
    ).
*************

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI