[removed]
Platform: Windows 8.1 (Update) (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
() C:\Program Files\Hewlett-Packard\SimplePass\cachesrvr.exe
(Softex Inc.) C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
() C:\Program Files\ATI Technologies\ATI.ACE\a4\AdaptiveSleepService.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(HP Inc.) C:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe
() C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
() C:\Program Files\Hewlett-Packard\SimplePass\opvapp.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\HPSmplPass.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBroker.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe
(CenturyLink Inc) C:\Program Files (x86)\CenturyLink\Desktop\CenturyLinkTouchPointAgent.exe
(HP Inc.) C:\Program Files (x86)\HP\HP System Event\HPMSGSVC.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler64.exe
(Intuit Inc.) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Farbar) C:\Users\Annette\Downloads\FRST64 (1).exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\…\Run: [SimplePass] => C:\Program Files\Hewlett-Packard\SimplePass\HPSmplPass.exe [2755640 2013-09-26] (Hewlett-Packard)
HKLM\…\Run: [OPBHOBroker] => C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBroker.exe [155704 2013-09-26] (Hewlett-Packard)
HKLM\…\Run: [OPBHOBrokerDesktop] => C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe [155704 2013-09-26] (Hewlett-Packard)
HKLM\…\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2771184 2013-07-26] (Synaptics Incorporated)
HKLM\…\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8843520 2016-02-19] (Realtek Semiconductor)
HKLM\…\Run: [WindowsDefender] => "%ProgramFiles%\Windows Defender\MSASCuiL.exe"
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [507776 2014-10-07] (Oracle Corporation)
HKLM-x32\…\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\…\Run: [CenturyLinkTouchPointAgent] => C:\Program Files (x86)\CenturyLink\Desktop\CenturyLinkTouchPointAgent.exe [48904 2014-11-04] (CenturyLink Inc)
HKLM-x32\…\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767200 2014-06-06] (Advanced Micro Devices, Inc.)
HKLM-x32\…\Run: [HPMessageService] => C:\Program Files (x86)\HP\HP System Event\HPMSGSVC.exe [709160 2018-05-22] (HP Inc.)
HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\Run: [GoogleChromeAutoLaunch_0C9337CDD31A557C75EB2CDF52C45A5A] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1471320 2018-07-23] (Google Inc.)
HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [479744 2014-10-28] (Microsoft Corporation)
HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\MountPoints2: {0971029e-8ae2-11e8-830f-3863bb8eae0e} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\MountPoints2: {097102d7-8ae2-11e8-830f-3863bb8eae0e} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\MountPoints2: {803e9b84-3b72-11e8-8302-3863bb8eae0e} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\MountPoints2: {ed76fc77-6b0a-11e5-8270-3863bb8eae0e} - "F:\AutoRun.exe"
Startup: C:\Users\Annette\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Facebook Gameroom.lnk [2018-01-13]
ShortcutTarget: Facebook Gameroom.lnk -> C:\Users\Annette\AppData\Local\Facebook\Games\FacebookGameroom.exe (Facebook)
Startup: C:\Users\Annette\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk [2018-01-08]
ShortcutTarget: Send to OneNote.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Users\Jacquelyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk [2016-05-14]
ShortcutTarget: Send to OneNote.lnk -> C:\Program Files (x86)\Microsoft Office\Office15\ONENOTEM.EXE (Microsoft Corporation)
BootExecute: autocheck autochk /r \??\Z:autocheck autochk *
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 208.67.222.222 8.8.8.8 [removed]
Tcpip\..\Interfaces\{2BE7FA48-E3A9-4398-8011-4CBB02E6ACC5}: [DhcpNameServer] 208.67.222.222 8.8.8.8 [removed]
Tcpip\..\Interfaces\{8E02059E-EC13-441B-AFD6-CD70C258610A}: [DhcpNameServer] 192.168.0.1 [removed]
Internet Explorer:
==================
HKU\S-1-5-21-1409944621-189731363-133459071-1005\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/
SearchScopes: HKU\S-1-5-21-1409944621-189731363-133459071-1005 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2018-07-18] (Microsoft Corporation)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2018-07-18] (Microsoft Corporation)
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2016-07-21] (HP Inc.)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2018-07-18] (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll [2014-12-01] (Oracle Corporation)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2018-07-18] (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll [2014-12-01] (Oracle Corporation)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2016-07-21] (HP Inc.)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-07-18] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-07-18] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-07-18] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-07-18] (Microsoft Corporation)
FireFox:
========
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\SysWOW64\Adobe\Director\np32dsw_1204144.dll [2013-09-05] (Adobe Systems, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll [2014-12-01] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll [2014-12-01] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2018-07-18] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2018-07-18] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2013-02-06] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-18] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-18] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\3\NP_wtapp.dll [2014-11-22] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-06-29] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1409944621-189731363-133459071-1005: @zoom.us/ZoomVideoPlugin -> C:\Users\Annette\AppData\Roaming\Zoom\bin\npzoomplugin.dll [2017-11-05] (Zoom Video Communications, Inc.)
Chrome:
=======
CHR DefaultProfile: Default
CHR NewTab: Default -> Not-active:"chrome-extension://odhkbaigkdgomaoipjcnnphjdlpnjjka/newtab/newtab.html", Not-active:"chrome-extension://fpdpdomdpmhpgncppolomeniknkgpbhm/newtab.html"
CHR DefaultSearchURL: Default -> hxxps://search.yahoo.com/search?p={searchTerms}&fr;=yset_chr_cnewtab&type;=default_v2
CHR DefaultSearchKeyword: Default -> Yahoo
CHR DefaultSuggestURL: Default -> hxxps://search.yahoo.com/sugg/ie?output=fxjson&command;={searchTerms}&nResults;=10
CHR Profile: C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default [2018-07-28]
CHR Extension: (Honey) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmnlcjabgnpnenekpadlanbbkooimhnj [2018-07-15]
CHR Extension: (Adobe Acrobat) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-03-26]
CHR Extension: (Yahoo Partner) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\fpdpdomdpmhpgncppolomeniknkgpbhm [2018-05-09]
CHR Extension: (Piggy - Automatic Coupons & Cash Back) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\hfapbcheiepjppjbnkphkmegjlipojba [2018-07-18]
CHR Extension: (HP Network Check Launcher) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\jkfpchpiljkaemlpmpebnglgkomamfeo [2017-03-26]
CHR Extension: (Grammarly for Chrome) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbfnbcaeplbcioakkpcpgfkobkghlhen [2018-07-27]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-07]
CHR Extension: (Coupon Simplified) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\odhkbaigkdgomaoipjcnnphjdlpnjjka [2018-04-01]
CHR Extension: (Amazon Assistant for Chrome) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbjikboenpfhbbejgkoklgkhjpfogcam [2018-06-24]
CHR Extension: (Chrome Media Router) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-07-27]
CHR Profile: C:\Users\Annette\AppData\Local\Google\Chrome\User Data\System Profile [2017-03-08]
CHR HKLM-x32\…\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [jkfpchpiljkaemlpmpebnglgkomamfeo] - hxxps://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdaptiveSleepService; C:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe [140288 2014-06-05] () [File not signed]
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2014-06-05] (Advanced Micro Devices, Inc.) [File not signed]
R2 Cachedrv server; C:\Program Files\Hewlett-Packard\SimplePass\cachesrvr.exe [109568 2013-09-26] () [File not signed]
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [8522928 2018-06-30] (Microsoft Corporation)
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [332656 2018-05-02] (HP Inc.)
R2 HPWMISVC; C:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe [628768 2017-07-13] (HP Inc.)
R2 HuaweiHiSuiteService64.exe; C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe [190784 2018-04-20] () [File not signed]
S2 KSDE1.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 1.0\ksde.exe [241544 2016-06-28] (AO Kaspersky Lab)
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [4278112 2013-08-02] (Symantec Corporation)
R2 omniserv; C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe [87552 2013-09-26] (Softex Inc.) [File not signed]
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [310016 2016-02-19] (Realtek Semiconductor)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [361824 2017-01-12] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [119872 2017-01-12] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 AmdAS4; C:\Windows\System32\drivers\AmdAS4.sys [17640 2017-07-21] (Advanced Micro Devices, INC.)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [222720 2017-07-21] (Advanced Micro Devices)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [100624 2015-06-08] (CyberLink)
S3 dg_ssudbus; C:\Windows\system32\DRIVERS\ssudbus.sys [131984 2017-05-18] (Samsung Electronics Co., Ltd.)
R1 epp; C:\Users\Annette\Desktop\bin64\epp.sys [115216 2017-01-03] (Emsisoft Ltd)
S3 ew_usbccgpfilter; C:\Windows\System32\drivers\ew_usbccgpfilter.sys [18944 2018-04-20] (Huawei Technologies Co., Ltd.)
U5 hw_usbdev; C:\Windows\System32\Drivers\hw_usbdev.sys [116864 2018-04-20] (Huawei Technologies Co., Ltd.)
R3 kltap; C:\Windows\system32\DRIVERS\kltap.sys [52152 2016-06-07] (The OpenVPN Project)
R3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [294104 2014-11-28] (Realtek Semiconductor Corp.)
R3 RTWlanE; C:\Windows\system32\DRIVERS\rtwlane.sys [3636440 2014-12-22] (Realtek Semiconductor Corporation )
R3 RTWlanE; C:\Windows\SysWOW64\DRIVERS\rtwlane.sys [2945240 2013-09-12] (Realtek Semiconductor Corporation )
S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [30448 2013-07-26] (Synaptics Incorporated)
S3 SmbDrvI; C:\Windows\System32\drivers\Smb_driver_Intel.sys [34544 2013-07-26] (Synaptics Incorporated)
S3 ssudmdm; C:\Windows\system32\DRIVERS\ssudmdm.sys [166288 2017-05-18] (Samsung Electronics Co., Ltd.)
S3 usbrndis6; C:\Windows\system32\DRIVERS\usb80236.sys [20992 2015-04-24] (Microsoft Corporation)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [46600 2017-02-10] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [274776 2017-01-12] (Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [117592 2017-01-12] (Microsoft Corporation)
R3 WirelessButtonDriver; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [30384 2015-06-23] (HP Inc.)
U3 aswMBR; \??\C:\Users\Annette\AppData\Local\Temp\aswMBR.sys [X] <==== ATTENTION
U3 aswVmm; \??\C:\Users\Annette\AppData\Local\Temp\aswVmm.sys [X] <==== ATTENTION
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-07-28 21:10 - 2018-07-28 21:10 - 002412544 _____ (Farbar) C:\Users\Annette\Downloads\FRST64 (1).exe
2018-07-28 21:06 - 2018-07-28 21:06 - 002412544 _____ (Farbar) C:\Users\Annette\Downloads\FRST64.exe
2018-07-28 20:49 - 2018-07-28 20:49 - 000000512 _____ C:\Users\Annette\Desktop\MBR.dat
2018-07-27 08:24 - 2018-07-27 08:24 - 000000000 ____D C:\Users\Annette\Documents\TECH
2018-07-27 08:24 - 2018-07-27 08:24 - 000000000 ____D C:\Users\Annette\Documents\New folder
2018-07-27 06:23 - 2018-07-27 06:23 - 005198336 _____ (AVAST Software) C:\Users\Annette\Downloads\aswMBR (1).exe
2018-07-18 21:29 - 2018-06-11 11:55 - 025744896 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2018-07-18 21:28 - 2018-06-20 15:01 - 007398232 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2018-07-18 21:28 - 2018-06-20 14:44 - 001676064 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2018-07-18 21:28 - 2018-06-20 14:44 - 001536120 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2018-07-18 21:28 - 2018-06-20 13:48 - 000095744 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\amdk8.sys
2018-07-18 21:28 - 2018-06-20 13:48 - 000027136 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\fxppm.sys
2018-07-18 21:28 - 2018-06-20 11:58 - 000098816 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\intelppm.sys
2018-07-18 21:28 - 2018-06-20 11:58 - 000098816 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\amdppm.sys
2018-07-18 21:28 - 2018-06-20 11:58 - 000092672 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\processr.sys
2018-07-18 21:28 - 2018-06-14 22:01 - 004169216 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2018-07-18 21:28 - 2018-06-12 03:00 - 022374248 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2018-07-18 21:28 - 2018-06-12 02:57 - 019790760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2018-07-18 21:28 - 2018-06-11 11:36 - 003119616 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll
2018-07-18 21:28 - 2018-06-11 11:14 - 000576512 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2018-07-18 21:28 - 2018-06-11 11:06 - 005779968 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2018-07-18 21:28 - 2018-06-11 11:04 - 000794624 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2018-07-18 21:28 - 2018-06-11 10:39 - 001033216 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2018-07-18 21:28 - 2018-06-11 10:36 - 015283200 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2018-07-18 21:28 - 2018-06-11 10:31 - 000809472 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2018-07-18 21:28 - 2018-06-11 10:22 - 003241472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2018-07-18 21:28 - 2018-06-11 10:11 - 001545216 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2018-07-18 21:28 - 2018-06-11 09:59 - 000800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2018-07-18 21:28 - 2018-06-09 11:40 - 020286976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2018-07-18 21:28 - 2018-06-09 11:26 - 002712064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll
2018-07-18 21:28 - 2018-06-09 11:09 - 000498176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2018-07-18 21:28 - 2018-06-09 10:59 - 000662016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2018-07-18 21:28 - 2018-06-09 10:37 - 004496384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2018-07-18 21:28 - 2018-06-09 10:37 - 000880640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2018-07-18 21:28 - 2018-06-09 10:36 - 013680128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2018-07-18 21:28 - 2018-06-09 10:32 - 000696320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2018-07-18 21:28 - 2018-06-09 10:11 - 002767872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2018-07-18 21:28 - 2018-06-09 10:08 - 001313792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2018-07-18 21:28 - 2018-06-09 10:06 - 000710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2018-07-18 21:28 - 2018-06-08 21:47 - 002176072 _____ (Microsoft Corporation) C:\Windows\system32\combase.dll
2018-07-18 21:28 - 2018-06-08 20:44 - 001565528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\combase.dll
2018-07-18 21:28 - 2018-06-08 13:26 - 000440832 _____ (Microsoft Corporation) C:\Windows\system32\zipfldr.dll
2018-07-18 21:28 - 2018-06-08 12:54 - 000656384 _____ (Microsoft Corporation) C:\Windows\system32\dnsapi.dll
2018-07-18 21:28 - 2018-06-08 12:53 - 000252416 _____ (Microsoft Corporation) C:\Windows\system32\dnsrslvr.dll
2018-07-18 21:28 - 2018-06-08 12:07 - 000404992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\zipfldr.dll
2018-07-18 21:28 - 2018-06-08 11:44 - 000499200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnsapi.dll
2018-07-18 21:28 - 2018-06-07 13:51 - 000074240 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mpsdrv.sys
2018-07-18 21:28 - 2018-05-24 16:29 - 002449752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2018-07-18 21:28 - 2018-05-24 16:29 - 000428888 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2018-07-18 21:28 - 2018-05-15 03:42 - 000590680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys
2018-07-18 21:28 - 2018-05-03 18:02 - 000439640 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2018-07-18 21:28 - 2018-05-03 18:02 - 000325456 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\USBXHCI.SYS
2018-07-18 21:28 - 2018-05-03 18:02 - 000187728 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\UCX01000.SYS
2018-07-18 21:28 - 2018-04-26 08:43 - 000918296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll
2018-07-18 21:28 - 2018-04-26 08:43 - 000065880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll
2018-07-18 21:28 - 2018-04-26 08:43 - 000021848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll
2018-07-18 21:28 - 2018-04-26 08:43 - 000018776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2018-07-18 21:28 - 2018-04-26 08:43 - 000017240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll
2018-07-18 21:28 - 2018-04-26 08:43 - 000017240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2018-07-18 21:28 - 2018-04-26 08:43 - 000015704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2018-07-18 21:28 - 2018-04-26 08:43 - 000015192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll
2018-07-18 21:28 - 2018-04-26 08:43 - 000013656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll
2018-07-18 21:28 - 2018-04-26 08:43 - 000013152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2018-07-18 21:28 - 2018-04-26 08:43 - 000012120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll
2018-07-18 21:28 - 2018-04-26 08:43 - 000012120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll
2018-07-18 21:28 - 2018-04-26 08:43 - 000011608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll
2018-07-18 21:28 - 2018-04-26 08:43 - 000011608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll
2018-07-18 21:28 - 2018-04-26 08:43 - 000011608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll
2018-07-18 21:28 - 2018-04-26 08:43 - 000011608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll
2018-07-18 21:28 - 2018-04-26 08:19 - 000998912 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll
2018-07-18 21:28 - 2018-04-26 08:19 - 000063832 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll
2018-07-18 21:28 - 2018-04-26 08:19 - 000020824 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll
2018-07-18 21:28 - 2018-04-26 08:19 - 000019288 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2018-07-18 21:28 - 2018-04-26 08:19 - 000017752 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll
2018-07-18 21:28 - 2018-04-26 08:19 - 000017752 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2018-07-18 21:28 - 2018-04-26 08:19 - 000016216 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2018-07-18 21:28 - 2018-04-26 08:19 - 000015704 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2018-07-18 21:28 - 2018-04-26 08:19 - 000014168 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll
2018-07-18 21:28 - 2018-04-26 08:19 - 000013656 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2018-07-18 21:28 - 2018-04-26 08:19 - 000012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2018-07-18 21:28 - 2018-04-26 08:19 - 000012632 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll
2018-07-18 21:28 - 2018-04-26 08:19 - 000012120 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2018-07-18 21:28 - 2018-04-26 08:19 - 000012120 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2018-07-18 21:28 - 2018-04-26 08:19 - 000012120 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2018-07-18 21:28 - 2018-04-26 08:19 - 000012120 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2018-07-18 21:28 - 2018-04-25 12:38 - 000243200 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2018-07-18 20:19 - 2018-07-18 20:19 - 000000000 ____D C:\Users\Annette\.android
2018-07-18 20:16 - 2018-07-18 20:27 - 000000000 ____D C:\Users\Annette\Documents\HiSuite
2018-07-18 20:16 - 2018-07-18 20:16 - 000001010 _____ C:\Users\Public\Desktop\HiSuite.lnk
2018-07-18 20:16 - 2018-07-18 20:16 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HiSuite
2018-07-18 20:15 - 2018-07-18 20:16 - 000000000 ____D C:\Program Files (x86)\HiSuite
2018-07-18 20:15 - 2018-07-18 20:15 - 000000000 ____D C:\Users\Annette\Documents\HUWEII PHOTOS
2018-07-18 20:15 - 2018-04-20 01:28 - 002152176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFUpdate_01009.dll
2018-07-18 20:15 - 2018-04-20 01:28 - 001721576 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01009.dll
2018-07-18 20:15 - 2018-04-20 01:28 - 001721576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfCoInstaller01009.dll
2018-07-18 20:15 - 2018-04-20 01:28 - 001002728 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\winusbcoinstaller2.dll
2018-07-18 20:15 - 2018-04-20 01:28 - 000287232 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\hw_quusbnet.sys
2018-07-18 20:15 - 2018-04-20 01:28 - 000226560 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\hw_quusbmdm.sys
2018-07-18 20:15 - 2018-04-20 01:28 - 000127360 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\hw_cdcacm.sys
2018-07-18 20:15 - 2018-04-20 01:28 - 000116864 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\hw_usbdev.sys
2018-07-18 20:15 - 2018-04-20 01:28 - 000033280 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbser.sys
2018-07-18 20:15 - 2018-04-20 01:28 - 000018944 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_usbccgpfilter.sys
2018-07-18 20:14 - 2018-07-18 20:17 - 000000000 ____D C:\Users\Annette\AppData\Local\HiSuite
2018-07-18 17:58 - 2018-06-12 14:01 - 000149632 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2018-07-18 17:58 - 2018-06-08 08:15 - 002860032 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2018-07-18 17:58 - 2018-06-08 08:15 - 001602048 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2018-07-18 17:58 - 2018-06-08 08:15 - 000783872 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2018-07-18 17:58 - 2018-06-08 08:15 - 000680960 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2018-07-18 17:58 - 2018-06-08 08:15 - 000612352 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2018-07-18 17:58 - 2018-06-08 08:15 - 000470016 _____ (Microsoft Corporation) C:\Windows\system32\centel.dll
2018-07-18 17:58 - 2018-06-08 08:15 - 000443392 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2018-07-18 17:58 - 2018-06-08 08:15 - 000301056 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2018-07-18 17:58 - 2018-06-08 08:15 - 000246272 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2018-07-18 16:31 - 2018-07-18 16:31 - 000417704 _____ C:\Users\Annette\Downloads\ICA_Sample-Membership-Agreement.pdf
2018-07-15 18:13 - 2018-07-18 18:03 - 000000000 ____D C:\Users\Annette\Documents\ED MN Organizing Fellowship 2018
2018-07-15 17:45 - 2018-07-15 17:45 - 000002163 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth Pro.lnk
2018-07-15 17:45 - 2018-07-15 17:45 - 000002151 _____ C:\Users\Public\Desktop\Google Earth Pro.lnk
2018-07-15 17:45 - 2018-07-15 17:45 - 000000000 ____D C:\Program Files\Google
2018-06-29 20:01 - 2018-07-27 23:22 - 000003180 _____ C:\Windows\System32\Tasks\HPCeeScheduleForAnnette
2018-06-29 20:01 - 2018-07-27 23:22 - 000000362 _____ C:\Windows\Tasks\HPCeeScheduleForAnnette.job
2018-06-29 19:51 - 2018-06-29 19:51 - 000000000 ____D C:\Program Files (x86)\HP
2018-06-28 15:52 - 2018-06-28 15:52 - 000641696 _____ (Microsoft Corporation) C:\Windows\system32\msvcp140.dll
2018-06-28 15:52 - 2018-06-28 15:52 - 000389296 _____ (Microsoft Corporation) C:\Windows\system32\vccorlib140.dll
2018-06-28 15:52 - 2018-06-28 15:52 - 000331432 _____ (Microsoft Corporation) C:\Windows\system32\concrt140.dll
2018-06-28 15:52 - 2018-06-28 15:52 - 000087728 _____ (Microsoft Corporation) C:\Windows\system32\vcruntime140.dll
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-07-28 21:15 - 2017-03-06 23:05 - 000021539 _____ C:\Users\Annette\Downloads\FRST.txt
2018-07-28 21:13 - 2017-03-06 23:03 - 000000000 ____D C:\FRST
2018-07-28 21:09 - 2015-11-17 17:45 - 000003942 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{3464BE36-788D-4EB3-890E-849F1DD7BE9F}
2018-07-28 20:54 - 2013-08-22 10:36 - 000000000 ____D C:\Windows\system32\NDF
2018-07-28 20:49 - 2017-03-06 23:00 - 000002706 _____ C:\Users\Annette\Desktop\aswMBR.txt
2018-07-28 20:45 - 2013-08-22 10:36 - 000000000 ____D C:\Windows\rescache
2018-07-28 08:35 - 2018-04-14 00:12 - 000000568 _____ C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-1409944621-189731363-133459071-1005.job
2018-07-28 08:33 - 2018-04-14 00:12 - 000000664 _____ C:\Windows\Tasks\G2MUploadTask-S-1-5-21-1409944621-189731363-133459071-1005.job
2018-07-28 05:09 - 2013-08-22 08:36 - 000000000 ____D C:\Windows\Inf
2018-07-27 06:37 - 2015-09-14 16:50 - 000003596 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1409944621-189731363-133459071-1005
2018-07-27 05:53 - 2015-09-14 16:49 - 000000000 ____D C:\Users\Annette\Documents\Youcam
2018-07-27 05:49 - 2014-03-18 04:53 - 000958060 _____ C:\Windows\system32\PerfStringBackup.INI
2018-07-27 05:48 - 2017-03-08 20:56 - 000000000 ____D C:\ProgramData\Kaspersky Lab
2018-07-27 05:48 - 2015-03-19 15:56 - 000000000 ____D C:\ProgramData\boost_interprocess
2018-07-27 05:46 - 2015-09-14 16:49 - 000000000 ___DO C:\Users\Annette\OneDrive
2018-07-27 05:43 - 2013-08-22 09:45 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2018-07-27 05:42 - 2013-08-22 09:44 - 000502304 _____ C:\Windows\system32\FNTCACHE.DAT
2018-07-27 05:39 - 2013-08-22 08:25 - 000524288 ___SH C:\Windows\system32\config\BBI
2018-07-27 05:34 - 2013-08-22 10:36 - 000000000 ___RD C:\Windows\ToastData
2018-07-24 21:06 - 2014-11-19 18:48 - 000002251 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-07-22 07:49 - 2013-08-22 10:20 - 000000000 ____D C:\Windows\CbsTemp
2018-07-22 06:35 - 2018-04-14 00:11 - 000000000 ____D C:\Users\Annette\AppData\Local\GoToMeeting
2018-07-21 10:44 - 2018-01-11 11:12 - 000002352 _____ C:\Users\Annette\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive for Business.lnk
2018-07-21 10:44 - 2017-07-26 22:13 - 000003180 _____ C:\Windows\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1409944621-189731363-133459071-1005
2018-07-21 10:15 - 2014-12-17 21:22 - 000000000 ____D C:\Windows\system32\appraiser
2018-07-18 21:38 - 2014-11-23 19:05 - 000000000 ____D C:\Windows\system32\MRT
2018-07-18 21:31 - 2014-11-23 19:05 - 134675576 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2018-07-18 21:16 - 2018-05-15 22:06 - 000685568 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2018-07-18 20:19 - 2015-04-07 21:03 - 000000000 ____D C:\Users\Annette
2018-07-18 19:59 - 2013-08-22 10:36 - 000000000 ____D C:\Windows\AppReadiness
2018-07-18 18:33 - 2013-08-22 10:36 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2018-07-18 18:29 - 2016-08-19 12:06 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016 Tools
2018-07-18 18:28 - 2014-04-22 12:28 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2018-07-18 18:05 - 2018-04-25 16:58 - 000000000 ____D C:\Users\Annette\Documents\Women Ventures
2018-07-18 16:39 - 2018-04-14 00:12 - 000003672 _____ C:\Windows\System32\Tasks\G2MUploadTask-S-1-5-21-1409944621-189731363-133459071-1005
2018-07-18 16:39 - 2018-04-14 00:12 - 000003576 _____ C:\Windows\System32\Tasks\G2MUpdateTask-S-1-5-21-1409944621-189731363-133459071-1005
2018-07-16 19:11 - 2016-03-24 09:59 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2018-07-16 19:09 - 2013-08-22 08:25 - 000000262 _____ C:\Windows\win.ini
2018-07-16 17:02 - 2014-12-01 11:44 - 000563832 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2018-07-15 18:37 - 2015-01-14 17:12 - 000004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2018-07-15 18:34 - 2015-12-12 14:20 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2018-07-15 18:21 - 2013-08-22 10:36 - 000000000 ___HD C:\Program Files\WindowsApps
2018-07-07 23:46 - 2014-09-09 21:21 - 000065536 _____ C:\Windows\system32\spu_storage.bin
2018-06-29 19:50 - 2014-03-31 20:07 - 000000000 ____D C:\SWSetup
2018-06-28 17:07 - 2018-01-12 10:17 - 000835064 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2018-06-28 17:07 - 2018-01-12 10:17 - 000179704 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2018-07-27 06:37
==================== End of FRST.txt ============================
Here is the Addition.txt.
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 21.07.2018
Ran by [removed] (28-07-2018 21:16:33)
Running from C:\Users\[removed]\Downloads
Windows 8.1 (Update) (X64) (2014-11-19 21:48:55)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-1409944621-189731363-133459071-500 - Administrator - Disabled)
Annette (S-1-5-21-1409944621-189731363-133459071-1005 - Administrator - Enabled) => C:\Users\Annette
Guest (S-1-5-21-1409944621-189731363-133459071-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1409944621-189731363-133459071-1004 - Limited - Enabled)
Jacquelyn (S-1-5-21-1409944621-189731363-133459071-1002 - Administrator - Enabled) => C:\Users\Jacquelyn
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
4 Elements II (HKLM-x32\…\WTA-f594756d-cea3-422d-a8fc-ced5205c861a) (Version: 2.2.0.98 - WildTangent) Hidden
7-Zip 9.20 (x64 edition) (HKLM\…\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Adobe Acrobat Reader DC (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 18.011.20055 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.0 (HKLM-x32\…\Adobe Shockwave Player) (Version: 12.0.4.144 - Adobe Systems, Inc.)
Airport Mania (HKLM-x32\…\WTA-67a03dfc-1d66-47d3-bc08-9a960e05c1bc) (Version: 2.2.0.95 - WildTangent) Hidden
AMD Catalyst Install Manager (HKLM\…\{89D9FBD5-7D44-509B-D17D-71FF2B2E7BDD}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.)
Azkend 2: The World Beneath (HKLM-x32\…\WTA-d289ec68-1f25-4f2b-ba18-86a20a21bc62) (Version: 2.2.0.98 - WildTangent) Hidden
Bejeweled 3 (HKLM-x32\…\WTA-8c1524c4-154e-48c1-9d0e-de089ad24105) (Version: 2.2.0.98 - WildTangent) Hidden
Bonjour (HKLM\…\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Bounce Symphony (HKLM-x32\…\WTA-73552c2f-075c-4734-8305-d61cc64f6bff) (Version: 2.2.0.97 - WildTangent) Hidden
Build-a-lot (HKLM-x32\…\WTA-51d1343d-3d81-4ede-9006-04b2be370e43) (Version: 2.2.0.98 - WildTangent) Hidden
CenturyLink Installer (HKLM-x32\…\{C96FF998-45BD-411E-9253-B7F2660FE280}) (Version: 1.0 - CenturyLink, Inc.)
Cisco EAP-FAST Module (HKLM-x32\…\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM-x32\…\{AF312B06-5C5C-468E-89B3-BE6DE2645722}) (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM-x32\…\{0A4EF0E6-A912-4CDE-A7F3-6E56E7C13A2F}) (Version: 1.1.6 - Cisco Systems, Inc.)
Cradle Of Egypt Collector's Edition (HKLM-x32\…\WTA-7a3200ac-a8c8-4a24-8f9d-1322c5984d44) (Version: 2.2.0.110 - WildTangent) Hidden
Cradle of Rome 2 (HKLM-x32\…\WTA-41e95925-8de8-4966-8b6f-39104fca2c0d) (Version: 2.2.0.98 - WildTangent) Hidden
Crescendo Music Notation Editor (HKLM-x32\…\Crescendo) (Version: 1.86 - NCH Software)
Curse at Twilight (HKLM-x32\…\WTA-bb4b4313-02fb-4516-b909-11928a5a3ef3) (Version: 3.0.2.32 - WildTangent) Hidden
CyberLink LabelPrint (HKLM-x32\…\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.5.6902 - CyberLink Corp.)
CyberLink Media Suite 10 (HKLM-x32\…\InstallShield_{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}) (Version: 10.0.9.4928 - CyberLink Corp.)
Cyberlink PhotoDirector (HKLM-x32\…\InstallShield_{39337565-330E-4ab6-A9AE-AC81E0720B10}) (Version: 3.0.4.4824 - CyberLink Corp.)
CyberLink Power Media Player 12 (HKLM-x32\…\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}) (Version: 12.0.6.5104 - CyberLink Corp.)
CyberLink Power2Go 8 (HKLM-x32\…\InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}) (Version: 8.0.10.5422 - CyberLink Corp.)
CyberLink PowerDirector 10 (HKLM-x32\…\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.6.3912 - CyberLink Corp.)
CyberLink YouCam (HKLM-x32\…\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 5.0.5.4628 - CyberLink Corp.)
D3DX10 (HKLM-x32\…\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden
Delicious: Emily's Childhood Memories Premium Edition (HKLM-x32\…\WTA-410ced0d-8414-4126-a7e5-3a4c77c6d5e8) (Version: 3.0.2.32 - WildTangent) Hidden
DisableMSDefender (HKLM\…\{74FE39A0-FB76-47CD-84BA-91E2BBB17EF2}) (Version: 1.0.0 - Hewlett-Packard Company) Hidden
Energy Star (HKLM-x32\…\{FC0ADA4D-8FA5-4452-8AFF-F0A0BAC97EF7}) (Version: 1.0.9 - Hewlett-Packard Company)
Facebook Gameroom 1.10.6515.35995 (HKLM-x32\…\{0B5F75BB-9192-4E2C-A0A6-D07DC31A2E84}) (Version: 1.10.6515.35995 - Facebook)
Farkle 3.0.13.10 (HKLM-x32\…\Farkle_is1) (Version: - )
Farm Frenzy (HKLM-x32\…\WTA-46580f9e-769c-43d3-9dea-256e9e1d09df) (Version: 2.2.0.98 - WildTangent) Hidden
Fishdom 3: Collector's Edition (HKLM-x32\…\WTA-0d9b177b-6105-4263-8018-fbf6cbf55172) (Version: 3.0.2.38 - WildTangent) Hidden
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 68.0.3440.75 - Google Inc.)
Google Earth Pro (HKLM\…\{B29B4ACE-362A-47D2-AB37-87C721D09803}) (Version: 7.3.2.5487 - Google)
Google Update Helper (HKLM-x32\…\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.17 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\…\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden
GoTo Opener (HKLM-x32\…\{1F803452-798F-49FB-A5DD-9F527F7017E4}) (Version: 1.0.473 - LogMeIn, Inc.)
GoToMeeting 8.30.1.9095 (HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\GoToMeeting) (Version: 8.30.1.9095 - LogMeIn, Inc.)
Governor of Poker 2 Premium Edition (HKLM-x32\…\WTA-68d441b2-c8f5-499f-96e1-6c93f7dab728) (Version: 2.2.0.110 - WildTangent) Hidden
Grammarly (HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\GrammarlyForWindows) (Version: 1.5.29 - Grammarly)
Grammarly for Microsoft® Office Suite (HKLM\…\{32A50269-D356-4E0E-8726-2D4CE92E5308}) (Version: 6.6.116 - Grammarly) Hidden
Grammarly for Microsoft® Office Suite (HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\{57565765-d384-47b2-bf69-37839b58e08e}) (Version: 6.6.116 - Grammarly)
Hewlett-Packard ACLM.NET v1.2.2.3 (HKLM-x32\…\{6F340107-F9AA-47C6-B54C-C3A19F11553F}) (Version: 1.00.0000 - Hewlett-Packard Company) Hidden
HiSuite (HKLM-x32\…\Hi Suite) (Version: 8.0.1.300 - )
House of 1000 Doors: Family Secrets (HKLM-x32\…\WTA-7f58df73-a448-48ba-b304-fc490ae02a7f) (Version: 2.2.0.98 - WildTangent) Hidden
HP Documentation (HKLM-x32\…\{2C0CCB21-5ED3-4417-93D2-CC6BEEB3C7CF}) (Version: 1.1.0.0 - Hewlett-Packard)
HP Registration Service (HKLM\…\{D1E8F2D7-7794-4245-B286-87ED86C1893C}) (Version: 1.2.7127.4628 - Hewlett-Packard)
HP SimplePass (HKLM-x32\…\InstallShield_{314FAD12-F785-4471-BCE8-AB506642B9A1}) (Version: 8.00.54 - Hewlett-Packard)
HP Support Assistant (HKLM-x32\…\{79C54A05-F146-4EA0-8A70-D4EFE6181E52}) (Version: 8.6.18.11 - Hewlett-Packard Company)
HP Support Solutions Framework (HKLM-x32\…\{55065080-504F-43BB-BE00-36B80D7D39A5}) (Version: 12.9.18.3 - Hewlett-Packard Company)
HP System Event Utility (HKLM-x32\…\{9DD60999-A4F0-4333-9D00-E45C718EA6C1}) (Version: 1.4.30 - HP Inc.)
HP Utility Center (HKLM\…\{7A75E042-0D30-43C2-BD2A-684F4BE38FF7}) (Version: 2.3.1 - Hewlett-Packard Company)
HP Wireless Button Driver (HKLM-x32\…\{EFA01423-3857-468C-B7B6-F30AA08E50BC}) (Version: 1.1.5.1 - Hewlett-Packard)
Inst5675 (HKLM\…\{2DE6247C-7077-451B-8BA7-FFD1A2ABBB47}) (Version: 8.00.54 - Softex Inc.) Hidden
Inst5676 (HKLM\…\{878F6913-7421-4713-97F7-0A736EE2A188}) (Version: 8.00.54 - Softex Inc.) Hidden
Java 8 Update 25 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83218025F0}) (Version: 8.0.250 - Oracle Corporation)
Jewel Match 3 (HKLM-x32\…\WTA-85145c7b-75a2-48d4-89bb-4168d89f47a0) (Version: 2.2.0.98 - WildTangent) Hidden
John Deere Drive Green (HKLM-x32\…\WTA-537118ba-a615-4d10-8bd5-6a461f5e5fa4) (Version: 2.2.0.95 - WildTangent) Hidden
Kaspersky Secure Connection (HKLM-x32\…\{1CF84962-50F8-48CA-9082-B70F3A02C686}) (Version: 17.0.0.611 - Kaspersky Lab) Hidden
Kaspersky Secure Connection (HKLM-x32\…\InstallWIX_{1CF84962-50F8-48CA-9082-B70F3A02C686}) (Version: 17.0.0.611 - Kaspersky Lab)
King Oddball (HKLM-x32\…\WTA-23746366-401a-4c3e-8074-4cd5e7772844) (Version: 3.0.2.48 - WildTangent) Hidden
Luxor Evolved (HKLM-x32\…\WTA-c636fc44-f491-4f3b-9e82-fed402533998) (Version: 2.2.0.98 - WildTangent) Hidden
Mahjongg Dimensions Deluxe (HKLM-x32\…\WTA-f60926f8-4f6a-4a38-9df5-e2927ec1f7fc) (Version: 2.2.0.95 - WildTangent) Hidden
Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Microsoft Office 365 ProPlus - en-us (HKLM\…\O365ProPlusRetail - en-us) (Version: 16.0.9126.2259 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-0081-0409-0000-0000000FF1CE}) (Version: 14.0.6123.5001 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM-x32\…\Office14.PROPLUSR) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Professional Plus 2013 (HKLM-x32\…\Office15.PROPLUSR) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\OneDriveSetup.exe) (Version: 18.111.0603.0006 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\…\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\…\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23026 (HKLM-x32\…\{e46eca4f-393b-40df-9f49-076faf788d83}) (Version: 14.0.23026.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Monopoly® (HKLM-x32\…\WTA-a2f0ba12-04c0-4194-af8a-79ed3a597c9d) (Version: 3.0.2.51 - WildTangent) Hidden
Movie Maker (HKLM-x32\…\{45898170-E68C-4F02-AA35-C2186BF347A3}) (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Movie Maker (HKLM-x32\…\{B39A6825-EA20-43EA-AB2D-A6BC0298D9A1}) (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Mystery P.I. - Curious Case of Counterfeit Cove (HKLM-x32\…\WTA-2b23e2e0-e38c-4d60-8e17-7ee68c32006b) (Version: 2.2.0.98 - WildTangent) Hidden
NCH Tone Generator (HKLM-x32\…\ToneGen) (Version: 3.26 - NCH Software)
Norton Online Backup (HKLM-x32\…\{1969BD50-331D-4B7A-8116-29A7DC6D45B4}) (Version: 2.8.0.44 - Symantec Corporation)
OEM Application Profile (HKLM-x32\…\{1D464EFF-EC8B-F225-2F74-F74143200DDF}) (Version: 1.00.0000 - Advanced Micro Devices, Inc.)
OEM Application Profile (HKLM-x32\…\{70D5F822-F4C4-33D9-7EEC-2A4AF4EA7BDC}) (Version: 1.00.0000 - Advanced Micro Devices, Inc.)
Office 16 Click-to-Run Extensibility Component (HKLM-x32\…\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.9126.2259 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\…\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.9126.2259 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\…\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.9126.2259 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM-x32\…\{90160000-008C-0409-0000-0000000FF1CE}) (Version: 16.0.9126.2259 - Microsoft Corporation) Hidden
Outils de vérification linguistique 2013 de Microsoft Office - Français (HKLM-x32\…\{90150000-001F-040C-0000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Peggle Nights (HKLM-x32\…\WTA-e36ab41b-84de-4891-b4ac-4c42415d828a) (Version: 2.2.0.98 - WildTangent) Hidden
Penguins! (HKLM-x32\…\WTA-9b6dc59b-5d81-4c6f-8733-82ae9078a7f8) (Version: 2.2.0.98 - WildTangent) Hidden
Pinger (HKLM-x32\…\{9B56B031-A6C0-4BB7-8F61-938548C1B759}) (Version: 1.4.0.1 - Pinger Inc.) Hidden
Pinger (HKLM-x32\…\Pinger 1.4.0.1) (Version: 1.4.0.1 - Pinger Inc.)
Plants vs. Zombies - Game of the Year (HKLM-x32\…\WTA-1624dfaa-74eb-4a04-b0d1-2816bc270b19) (Version: 2.2.0.98 - WildTangent) Hidden
Polar Bowler (HKLM-x32\…\WTA-bb0a5787-6371-4fdd-ac8a-5702d596c923) (Version: 2.2.0.97 - WildTangent) Hidden
Realtek Card Reader (HKLM-x32\…\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.3.9600.29080 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.32.508.2014 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7730 - Realtek Semiconductor Corp.)
REALTEK Wireless LAN Driver (HKLM-x32\…\{A5107464-AA9B-4177-8129-5FF2F42DD322}) (Version: 1.0.0.41 - REALTEK Semiconductor Corp.)
Roads of Rome 3 (HKLM-x32\…\WTA-24b516d7-0fa5-49af-b5f8-2b3dd95cd50d) (Version: 2.2.0.98 - WildTangent) Hidden
SecondLifeViewer (HKLM-x32\…\SecondLifeViewer) (Version: 5.0.3.324435 - Linden Research, Inc.)
Service Pack 1 for Microsoft Office 2013 (KB2850036) 32-Bit Edition (HKLM-x32\…\{91150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUSR_{7F6C4883-A18C-459A-82C1-A2F9403F2DA6}) (Version: - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\…\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft)
swMSM (HKLM-x32\…\{612C34C7-5E90-47D8-9B5C-0F717DD82726}) (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synaptics Pointing Device Driver (HKLM\…\SynTPDeinstKey) (Version: 17.0.6.2 - Synaptics Incorporated)
Tales of Lagoona (HKLM-x32\…\WTA-61166e11-25af-458a-bdb6-58e3bdab6835) (Version: 2.2.0.110 - WildTangent) Hidden
TurboTax 2014 (HKLM-x32\…\TurboTax 2014) (Version: 2014.0 - Intuit, Inc)
Update Installer for WildTangent Games App (HKLM-x32\…\{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App) (Version: - WildTangent) Hidden
Vacation Quest™ - Australia (HKLM-x32\…\WTA-05973e5c-9595-40e3-910a-ba1b6178d68c) (Version: 3.0.2.32 - WildTangent) Hidden
Visual Studio 2012 x64 Redistributables (HKLM\…\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\…\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
WavePad Sound Editor (HKLM-x32\…\WavePad) (Version: 7.00 - NCH Software)
WhatsApp (HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\WhatsApp) (Version: 0.2.1455 - WhatsApp)
WildTangent Games (HKLM-x32\…\WildTangent wildgames Master Uninstall) (Version: 1.0.4.0 - WildTangent)
WildTangent Games App (HP Games) (HKLM-x32\…\{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-hp) (Version: 4.0.10.15 - WildTangent) Hidden
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 16.4.3508.0205 - Microsoft Corporation)
Youda Jewel Shop (HKLM-x32\…\WTA-9173cba2-bfe3-462a-8bbc-6e837f324d64) (Version: 3.0.2.32 - WildTangent) Hidden
Zoom (HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\ZoomUMX) (Version: 4.1 - Zoom Video Communications, Inc.)
Zulu DJ Software (HKLM-x32\…\Zulu) (Version: 3.70 - NCH Software)
Zuma's Revenge (HKLM-x32\…\WTA-11f72db7-03ee-4570-8cc1-e63492ed09eb) (Version: 2.2.0.98 - WildTangent) Hidden
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-1409944621-189731363-133459071-1005_Classes\CLSID\{162C6FB5-44D3-435B-903D-E613FA093FB5}\InprocServer32 -> C:\Users\Annette\AppData\Local\Microsoft\OneDrive\17.3.6998.0830\amd64\FileCoAuthLib64.dll => No File
CustomCLSID: HKU\S-1-5-21-1409944621-189731363-133459071-1005_Classes\CLSID\{2AD206F1-152C-4F9D-A24E-6F93FE7A4AFC}\InprocServer32 -> C:\Users\Annette\AppData\Local\Grammarly\Grammarly for Microsoft Office Suite\6.6.116\07470D8E98\GrammarlyShim64.dll (CompanyName)
CustomCLSID: HKU\S-1-5-21-1409944621-189731363-133459071-1005_Classes\CLSID\{4BE56754-B616-4998-B825-D16983AEE1B2}\InprocServer32 -> C:\Windows\system32\mscoree.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1409944621-189731363-133459071-1005_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309}\InprocServer32 -> C:\Users\Annette\AppData\Local\GoToMeeting\8625\G2MOutlookAddin64.dll (LogMeIn, Inc.)
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2010-11-18] (Igor Pavlov)
ContextMenuHandlers1: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} => C:\Program Files (x86)\Common Files\CyberLink\ShellExtComponent\CLVDShellExt.dll [2015-12-05] (Cyberlink)
ContextMenuHandlers2: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} => C:\Program Files (x86)\Common Files\CyberLink\ShellExtComponent\CLVDShellExt.dll [2015-12-05] (Cyberlink)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamext.dll [2016-03-10] (Malwarebytes)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2010-11-18] (Igor Pavlov)
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\atiacm64.dll [2014-06-05] (Advanced Micro Devices, Inc.)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamext.dll [2016-03-10] (Malwarebytes)
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {10A0396E-4397-432D-A61A-B29936C98279} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-27] (Google Inc.)
Task: {13574B37-B008-40D6-9119-90B7E0B35F2D} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2018-07-18] (Microsoft Corporation)
Task: {2FE82A44-7615-47C1-88DD-E0D568E5D0F2} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe
Task: {3165798A-F44B-4387-8B96-BD947DFDF94F} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-22] (Microsoft Corporation)
Task: {3E898CDD-32F4-47D1-A2F4-BCF33E88AEBC} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2017-09-20] (HP Inc.)
Task: {422808BD-6F70-41BF-945D-E13AA06AE45A} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis Install => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2018-05-04] (HP Inc.)
Task: {468B13AD-B541-4A27-B004-9B018EEA3275} - System32\Tasks\Java Platform SE Auto Updater => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2014-10-07] (Oracle Corporation)
Task: {52011BB0-9609-4A94-8F8F-18EE0E3BA0E6} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2018-07-18] (Microsoft Corporation)
Task: {55DCE214-7F3F-463F-BECE-5A67E73B6324} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2018-05-04] (HP Inc.)
Task: {57DC314F-8673-4D52-A50F-5C96A0653F03} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2018-06-30] (Microsoft Corporation)
Task: {5B7B1C4A-9A07-4CAC-869E-5279651131BE} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-22] (Microsoft Corporation)
Task: {623F2F24-7088-4926-8C44-4BE258A2EB0F} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2018-07-18] (Microsoft Corporation)
Task: {69D3BA23-D578-4DE2-AFDE-D9EF27762CEC} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-27] (Google Inc.)
Task: {6E86A5AF-49A1-4B3C-84A1-CB279387142A} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2018-07-18] (Microsoft Corporation)
Task: {B73A7C7B-CF7F-4A7E-A613-BFBB8A73789D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater - Resources => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2017-09-20] (HP Inc.)
Task: {C45E956E-E070-4332-B57C-DF9D8B626B72} - System32\Tasks\Hewlett-Packard\HP Active Health\HP Active Health Scan (HPSA) => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.exe [2016-11-07] (HP Inc.)
Task: {CD39A3B5-0980-4947-BD6C-3D87425A7FCE} - System32\Tasks\Synaptics TouchPad Enhancements => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2013-07-26] (Synaptics Incorporated)
Task: {D04BBF70-03A8-413B-9CA3-5AC3314706E2} - System32\Tasks\G2MUpdateTask-S-1-5-21-1409944621-189731363-133459071-1005 => C:\Users\Annette\AppData\Local\GoToMeeting\9095\g2mupdate.exe [2018-07-18] (LogMeIn, Inc.)
Task: {D0F920D8-40AD-4B42-9F6C-ADA01607FCCD} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Product Configurator => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\ProductConfig.exe [2018-05-11] (HP Inc.)
Task: {D55B6A0A-527B-489A-AA62-762F86F1E055} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2018-06-30] (Microsoft Corporation)
Task: {D76D271F-29F7-4BE2-9407-EE2CF2665FAB} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2018-06-28] (HP Inc.)
Task: {DCEFA36E-E149-4C02-99DB-E3F29CC3066E} - System32\Tasks\YCMServiceAgent => C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe [2014-10-28] (CyberLink Corp.)
Task: {E6B7EE15-0DF8-473B-AA30-3C92EDE7356E} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2018-05-04] (HP Inc.)
Task: {EC860F0E-1C8E-4761-BA2C-9ACF03169D98} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [2017-06-22] (HP Inc.)
Task: {EFA0368A-E020-4987-ACB1-3EF2531B7D4E} - System32\Tasks\HPCeeScheduleForAnnette => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2015-06-16] (Hewlett-Packard)
Task: {EFE6E304-849C-4527-A6F6-903B564B9663} - System32\Tasks\G2MUploadTask-S-1-5-21-1409944621-189731363-133459071-1005 => C:\Users\Annette\AppData\Local\GoToMeeting\9095\g2mupload.exe [2018-07-18] (LogMeIn, Inc.)
Task: {F9C08FE8-A8B1-41A9-ADF0-5117990D5ED3} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2018-07-18] (Microsoft Corporation)
Task: {FF54D9DE-B40F-4062-A00B-865050811D0E} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2018-03-21] (Adobe Systems Incorporated)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-1409944621-189731363-133459071-1005.job => C:\Users\Annette\AppData\Local\GoToMeeting\9095\g2mupdate.exe
Task: C:\Windows\Tasks\G2MUploadTask-S-1-5-21-1409944621-189731363-133459071-1005.job => C:\Users\Annette\AppData\Local\GoToMeeting\9095\g2mupload.exe
Task: C:\Windows\Tasks\HPCeeScheduleForAnnette.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
==================== Shortcuts & WMI ========================
(The entries could be listed to be restored or removed.)
==================== Loaded Modules (Whitelisted) ==============
2013-09-26 13:26 - 2013-09-26 13:26 - 000109568 _____ () C:\Program Files\Hewlett-Packard\SimplePass\cachesrvr.exe
2013-09-26 13:32 - 2013-09-26 13:32 - 000627200 _____ () C:\Program Files\Hewlett-Packard\SimplePass\cachedrv.dll
2013-09-26 13:28 - 2013-09-26 13:28 - 002540544 _____ () C:\Program Files\Hewlett-Packard\SimplePass\autheng.dll
2013-09-26 13:25 - 2013-09-26 13:25 - 000035328 _____ () C:\Program Files\Hewlett-Packard\SimplePass\ssplogon.dll
2013-09-26 13:25 - 2013-09-26 13:25 - 000055296 _____ () C:\Program Files\Hewlett-Packard\SimplePass\RandomPass.dll
2013-09-26 13:25 - 2013-09-26 13:25 - 000021504 _____ () C:\Program Files\Hewlett-Packard\SimplePass\cryptodll.dll
2013-09-26 13:39 - 2013-09-26 13:39 - 000306064 _____ () C:\Program Files\Hewlett-Packard\SimplePass\mstrpwd.dll
2013-09-26 13:39 - 2013-09-26 13:39 - 001298832 _____ () C:\Program Files\Hewlett-Packard\SimplePass\GraphicalPwd.dll
2014-06-05 22:42 - 2014-06-05 22:42 - 000140288 _____ () C:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe
2014-06-05 22:40 - 2014-06-05 22:40 - 000127488 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.Wlan.dll
2018-04-20 01:28 - 2018-04-20 01:28 - 000190784 _____ () C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe
2016-08-19 12:07 - 2018-07-18 17:45 - 008936112 _____ () C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\1033\GrooveIntlResource.dll
2013-09-05 01:17 - 2013-09-05 01:17 - 004300456 _____ () C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2010-10-20 16:23 - 2010-10-20 16:23 - 008801632 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll
2013-09-26 13:34 - 2013-09-26 13:34 - 000064000 _____ () C:\Program Files\Hewlett-Packard\SimplePass\opvapp.exe
2018-07-24 21:06 - 2018-07-23 15:27 - 004076888 _____ () C:\Program Files (x86)\Google\Chrome\Application\68.0.3440.75\libglesv2.dll
2018-07-24 21:06 - 2018-07-23 15:27 - 000096088 _____ () C:\Program Files (x86)\Google\Chrome\Application\68.0.3440.75\libegl.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
IE trusted site: HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\sharepoint.com -> hxxps://liveedurdale-files.sharepoint.com
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2013-08-22 08:25 - 2017-03-26 07:31 - 000000035 _____ C:\Windows\system32\Drivers\etc\hosts
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-1409944621-189731363-133459071-1005\Control Panel\Desktop\\Wallpaper -> C:\Users\Annette\AppData\Roaming\Microsoft\Windows Photo Viewer\Windows Photo Viewer Wallpaper.jpg
DNS Servers: 208.67.222.222 - 8.8.8.8
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
HKLM\…\StartupApproved\Run: => "WindowsDefender"
HKLM\…\StartupApproved\Run32: => "YouCam Service"
HKLM\…\StartupApproved\Run32: => "SunJavaUpdateSched"
HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\StartupApproved\StartupFolder: => "Facebook Gameroom.lnk"
HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\StartupApproved\StartupFolder: => "Send to OneNote.lnk"
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{8D444952-FDB7-4FA5-901C-2462C1A37F99}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{AF3331A2-97B7-4313-AC3F-01DBA6B2C4FE}] => (Allow) LPort=2869
FirewallRules: [{150FBC6F-7AB5-4063-A0FB-EAC794994B93}] => (Allow) LPort=1900
FirewallRules: [{E39BD188-517F-4E06-97D0-5C42D5838F7E}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{F1948981-D69A-4ED2-8B17-9EFB0572B092}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{1402E48A-D816-4233-BC99-5439A3F6EDF5}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{8F1DB3E0-F2A7-42ED-91C7-FB0C90AC0852}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{BAB834BF-B807-4BB0-9914-BEB323488AC5}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{B4EC793D-9BBE-49AF-B2AF-C979A6135B15}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{711CA439-540E-400F-96B4-03755DDF5D83}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDirector10\PDR10.EXE
FirewallRules: [{A58108F8-825B-42DE-A8B0-03908ED19304}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{37B0BF0A-6A5B-4084-8C13-81F803B4FF7C}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{7281462C-F67B-4492-905D-4C4B321E723A}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\outlook.exe
FirewallRules: [{A5A52445-92E8-42E2-A32A-0836A405AB0F}] => (Allow) C:\Users\Jacquelyn\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
FirewallRules: [{3B61AE1B-6103-477A-8F0D-4BAE585A8645}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPSOCKSVC.exe
FirewallRules: [TCP Query User{ACBD9CE9-88F2-4D23-8571-2E3C7E52DE4E}C:\program files (x86)\symantec\norton online backup\nobuclient.exe] => (Allow) C:\program files (x86)\symantec\norton online backup\nobuclient.exe
FirewallRules: [UDP Query User{02717F8A-ABC2-4205-9C6C-6DD19E9FB7DF}C:\program files (x86)\symantec\norton online backup\nobuclient.exe] => (Allow) C:\program files (x86)\symantec\norton online backup\nobuclient.exe
FirewallRules: [{D7AA5C63-D072-4153-8525-465AED706750}] => (Block) C:\program files (x86)\symantec\norton online backup\nobuclient.exe
FirewallRules: [{ED315B61-5CAE-477B-92D2-6F17C887849E}] => (Block) C:\program files (x86)\symantec\norton online backup\nobuclient.exe
FirewallRules: [{A42A81CB-243D-424B-A1D2-E662EB7A79B5}] => (Allow) C:\Program Files (x86)\Tango\Tango.exe
FirewallRules: [{7878122C-021D-4A6D-A0EB-284AB08B8B7E}] => (Allow) C:\Program Files (x86)\Tango\Tango.exe
FirewallRules: [TCP Query User{07B278D4-21FF-4CD2-A965-9B4438E8948A}C:\windows\system32\settingsynchost.exe] => (Block) C:\windows\system32\settingsynchost.exe
FirewallRules: [UDP Query User{F79BB37B-92F4-474B-AD1B-CF9F1568C6B7}C:\windows\system32\settingsynchost.exe] => (Block) C:\windows\system32\settingsynchost.exe
FirewallRules: [TCP Query User{FEEB000C-3527-4656-972D-BD975F70038B}C:\program files (x86)\tango\tango.exe] => (Block) C:\program files (x86)\tango\tango.exe
FirewallRules: [UDP Query User{AA76E5A5-6069-49D6-B878-FDBD28329607}C:\program files (x86)\tango\tango.exe] => (Block) C:\program files (x86)\tango\tango.exe
FirewallRules: [{5407BD3E-4D9F-460E-A8AA-0B2BD11CE977}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe
FirewallRules: [{C767F0A0-DC9F-430D-81AC-BA6847226F1E}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPDeviceDetection3.exe
FirewallRules: [{6C0E44BE-0BDE-4BBC-A1D5-7E0B514B8E10}] => (Allow) C:\Users\Jacquelyn\AppData\Local\Maelstrom\Application\chrome.native.torrent.exe
FirewallRules: [{80803E9F-BC54-40E5-A2AC-C160843F37F5}] => (Allow) C:\Users\Jacquelyn\AppData\Local\Maelstrom\Application\chrome.native.torrent.exe
FirewallRules: [{91BE1D7A-7F5E-4888-8C7B-7A4FB2833155}] => (Allow) C:\Users\Jacquelyn\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{85591B93-2B77-4228-ACD3-3663078EA1C8}] => (Allow) C:\Users\Jacquelyn\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{D228A34F-3AF9-41F6-AA7B-3579CF041A48}] => (Allow) C:\Users\Jacquelyn\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{BD1FD5D4-E5B0-44EF-A5F2-0CC6D6F8A3E3}] => (Allow) C:\Users\Jacquelyn\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [TCP Query User{DF2CC86E-9A5F-4831-B378-C0A56490E11E}C:\program files (x86)\tams11\games\farkle\farkle.exe] => (Allow) C:\program files (x86)\tams11\games\farkle\farkle.exe
FirewallRules: [UDP Query User{BEB80554-9B9D-4AB0-90E7-0640D3A57881}C:\program files (x86)\tams11\games\farkle\farkle.exe] => (Allow) C:\program files (x86)\tams11\games\farkle\farkle.exe
FirewallRules: [TCP Query User{136FA891-6E6C-483B-8803-A3420AA28CD3}C:\program files (x86)\tams11\games\farkle\farkle.exe] => (Allow) C:\program files (x86)\tams11\games\farkle\farkle.exe
FirewallRules: [UDP Query User{11852EA3-54FD-4B1C-96D7-470540C49779}C:\program files (x86)\tams11\games\farkle\farkle.exe] => (Allow) C:\program files (x86)\tams11\games\farkle\farkle.exe
FirewallRules: [{9830404C-9584-4B5A-AAA7-37464D53161D}] => (Allow) C:\Users\Jacquelyn\AppData\Local\Maelstrom\Application\chrome.native.torrent.exe
FirewallRules: [{5BCD7EEB-5882-4C2B-8864-78E37C461F11}] => (Allow) C:\Users\Jacquelyn\AppData\Local\Maelstrom\Application\chrome.native.torrent.exe
FirewallRules: [{D1E14E70-55FD-433A-BA10-0FDA73C5FA47}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\lync.exe
FirewallRules: [{702D7745-DB5D-4710-8D92-015A472B9C96}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\lync.exe
FirewallRules: [{CB1CDFB6-8E46-4267-A529-C2D1099F4180}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{0CDC5D99-44C4-49B6-8130-528ED1F07E26}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{83F18E26-E83F-4F9C-A56D-8B5D7A93C367}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\lync.exe
FirewallRules: [{BD161ADE-0A7C-44D3-8915-BB5980B4305B}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\lync.exe
FirewallRules: [{A6A9097C-7008-48A2-AD29-13120F59BAAF}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{7F39D004-385E-48B2-9AC7-02CFC9CB9DF9}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{4767A3CC-2571-4160-8DAD-E9C5D341B5A2}] => (Allow) C:\Users\Jacquelyn\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{188AD522-CA2C-4096-B0C6-73A7377F1EDC}] => (Allow) C:\Users\Jacquelyn\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{3C9E1994-A54A-4741-9505-6142A9097317}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe
FirewallRules: [{B3EFC034-FD60-4DDF-B0F1-5837E7FA5375}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe
FirewallRules: [{F71E818A-A294-41B8-BD37-D13C81FA5F53}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe
FirewallRules: [{6B914922-3E76-4FEC-A515-4105D6FDC28F}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe
FirewallRules: [{F5E466D7-9CCD-4E00-B99F-B4B6D6F4D8D7}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{6C701C59-B17B-486B-9D50-93844C0B482F}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [{FD5590CC-017D-44AE-86A9-00E3FE28FB6D}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdater.exe
FirewallRules: [{C66BD5C9-1AB8-46C3-BC95-4795126CAECB}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [{071AC728-7D57-4B67-BAD1-F2BF4D1009DC}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [{75E91A46-1BBE-4E2D-A34A-3E22273BBB32}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [{B4F8DCE1-4FF7-4C1F-BC65-B49B02A489B3}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [{C3F65FC8-FCC0-4EDC-841B-E344B116F68B}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [{F92EFA33-3CBA-4D48-A37F-EAA5C3B85EAC}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12.exe
FirewallRules: [{7F0BE56E-50CB-4D65-BA66-69B59B4E5837}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMR\PowerDVD12DMREngine.exe
FirewallRules: [{5BDC7800-C619-4DAF-9158-04EC99DFB02E}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe
FirewallRules: [{BD129EA8-910D-4761-95EF-F4BD429148F1}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12Agent.exe
FirewallRules: [{1FA56378-6A82-4A35-99DE-8725DADA7EE5}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12ML.exe
FirewallRules: [{B5A22037-BC5A-4720-A169-8A51A0B6DD94}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Movie\PowerDVD.exe
FirewallRules: [TCP Query User{B628FD1B-686E-4D16-9BD7-3D9B41C5AF98}C:\program files (x86)\secondlifeviewer\slvoice.exe] => (Allow) C:\program files (x86)\secondlifeviewer\slvoice.exe
FirewallRules: [UDP Query User{FAB3A586-55FD-47A4-B4D2-14B68F8DBD70}C:\program files (x86)\secondlifeviewer\slvoice.exe] => (Allow) C:\program files (x86)\secondlifeviewer\slvoice.exe
FirewallRules: [{EC7061E5-5C74-40EC-904D-D4ECC603C62E}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{8768FC2F-3631-42FF-859D-F4F8C95917C3}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [{9B9E8249-AD2F-4AF4-B6BC-708AA2EBC171}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Restore Points =========================
29-06-2018 19:47:24 HPSF Applying updates
16-07-2018 18:45:16 Windows Update
18-07-2018 16:38:48 PROPLUSR
22-07-2018 07:40:32 Windows Update
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (07/28/2018 09:00:26 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program LiveComm.exe version 17.5.9600.22013 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
Process ID: 1a58
Start Time: 01d426df2390b6aa
Termination Time: 4294967295
Application Path: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.22013_x64__8wekyb3d8bbwe\LiveComm.exe
Report Id: 194c622b-92d3-11e8-8311-3863bb8eae0e
Faulting package full name: microsoft.windowscommunicationsapps_17.5.9600.22013_x64__8wekyb3d8bbwe
Faulting package-relative application ID: ppleae38af2e007f4358a809ac99a64a67c1
Error: (07/28/2018 08:55:26 PM) (Source: Office 2016 Licensing Service) (EventID: 0) (User: )
Description: Event-ID 0
Error: (07/28/2018 09:13:14 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1594
Error: (07/28/2018 09:13:14 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 1594
Error: (07/28/2018 09:13:14 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (07/27/2018 07:19:12 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1672
Error: (07/27/2018 07:19:12 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 1672
Error: (07/27/2018 07:19:12 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
System errors:
=============
Error: (07/28/2018 08:54:08 PM) (Source: Server) (EventID: 2505) (User: )
Description: The server could not bind to the transport \Device\NetBT_Tcpip_{2BE7FA48-E3A9-4398-8011-4CBB02E6ACC5} because another computer on the network has the same name. The server could not start.
Error: (07/27/2018 05:39:20 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ClickToRunSvc service.
Error: (07/27/2018 05:31:54 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ClickToRunSvc service.
Error: (07/21/2018 10:19:27 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ClickToRunSvc service.
Error: (07/21/2018 10:14:43 AM) (Source: DCOM) (EventID: 10010) (User: MRSJOHNSON)
Description: The server {4545DEA0-2DFC-4906-A728-6D986BA399A9} did not register with DCOM within the required timeout.
Error: (07/21/2018 10:14:43 AM) (Source: DCOM) (EventID: 10010) (User: MRSJOHNSON)
Description: The server {4545DEA0-2DFC-4906-A728-6D986BA399A9} did not register with DCOM within the required timeout.
Error: (07/21/2018 10:14:43 AM) (Source: DCOM) (EventID: 10010) (User: MRSJOHNSON)
Description: The server {4AA0A5C4-1B9B-4F2E-99D7-99C6AEC83474} did not register with DCOM within the required timeout.
Error: (07/21/2018 10:14:43 AM) (Source: DCOM) (EventID: 10010) (User: MRSJOHNSON)
Description: The server {4AA0A5C4-1B9B-4F2E-99D7-99C6AEC83474} did not register with DCOM within the required timeout.
Windows Defender:
===================================
Date: 2018-07-28 20:41:10.667
Description:
Windows Defender scan has been stopped before completion.
Scan ID: {01A37389-5ECC-4E95-9561-9F8B342B5E34}
Scan Type: Antimalware
Scan Parameters: Quick Scan
Date: 2018-07-27 07:00:04.142
Description:
Windows Defender scan has been stopped before completion.
Scan ID: {55CE8813-5AC4-469F-B0AB-5EBA06B96B56}
Scan Type: Antimalware
Scan Parameters: Quick Scan
Date: 2018-07-22 06:08:27.892
Description:
Windows Defender scan has been stopped before completion.
Scan ID: {C30C8114-C690-4311-A44F-91FBB0A060B4}
Scan Type: Antimalware
Scan Parameters: Quick Scan
Date: 2018-07-18 20:03:21.804
Description:
Windows Defender scan has been stopped before completion.
Scan ID: {AF21A81E-F369-4BDF-912C-BC5A1BD9A311}
Scan Type: Antimalware
Scan Parameters: Quick Scan
Date: 2018-06-27 19:49:02.651
Description:
Windows Defender scan has been stopped before completion.
Scan ID: {1419ABB6-CF41-41E1-8E65-F37475A45D0D}
Scan Type: Antimalware
Scan Parameters: Quick Scan
Date: 2018-07-27 05:26:53.014
Description:
Windows Defender has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.273.293.0
Update Source: Microsoft Malware Protection Center
Signature Type: AntiSpyware
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.15100.1
Error code: 0x80070652
Error description: Another installation is already in progress. Complete that installation before proceeding with this install.
Date: 2018-07-27 05:26:53.014
Description:
Windows Defender has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.273.293.0
Update Source: Microsoft Malware Protection Center
Signature Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.15100.1
Error code: 0x80070652
Error description: Another installation is already in progress. Complete that installation before proceeding with this install.
Date: 2018-07-27 05:26:46.836
Description:
Windows Defender has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version:
Update Source: User
Signature Type:
Update Type:
Current Engine Version:
Previous Engine Version:
Error code: 0x80070652
Error description: Another installation is already in progress. Complete that installation before proceeding with this install.
Date: 2018-07-27 05:26:46.835
Description:
Windows Defender has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version:
Update Source: User
Signature Type:
Update Type:
Current Engine Version:
Previous Engine Version:
Error code: 0x80070652
Error description: Another installation is already in progress. Complete that installation before proceeding with this install.
Date: 2018-07-27 05:26:19.709
Description:
Windows Defender has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.273.293.0
Update Source: Microsoft Update Server
Signature Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.15100.1
Error code: 0x80240016
Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
CodeIntegrity:
===================================
Date: 2018-07-27 07:40:25.759
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2018-07-27 07:40:23.829
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2018-07-27 06:47:45.328
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2018-07-22 06:08:15.191
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2018-07-18 18:59:38.562
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2018-06-23 20:30:19.044
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2018-06-21 18:48:31.684
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2018-06-14 14:17:22.258
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
==================== Memory info ===========================
Processor: AMD A6-5200 APU with Radeon(TM) HD Graphics
Percentage of memory in use: 71%
Total physical RAM: 3554.01 MB
Available physical RAM: 996.1 MB
Total Virtual: 6498.01 MB
Available Virtual: 3284.3 MB
==================== Drives ================================
Drive c: (Windows) (Fixed) (Total:677.63 GB) (Free:389.78 GB) NTFS
Drive d: (RECOVERY) (Fixed) (Total:19.99 GB) (Free:1.28 GB) NTFS ==>[system with boot components (obtained from drive)]
\\?\Volume{f0d011a2-f7dc-43a9-8b7c-0875843c6a46}\ (WINRE) (Fixed) (Total:0.63 GB) (Free:0.36 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 698.6 GB) (Disk ID: A9A16C4F)
Partition: GPT.
==================== End of Addition.txt ============================