This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Infected PC acting weird

35 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi and thanks in advance. Been a few years since I needed your help, but I think my PC is badly infected. Lots of strange activity going on. Have run AVG virus scanner and Malwarebytes a couple of time but still with issues.

Thanks again.

 

   Here's the log files you recommended:

 

aswMBR.txt

 

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2018-12-21 22:33:12
—————————–
22:33:12.119    OS Version: Windows x64 6.1.7601 Service Pack 1
22:33:12.120    Number of processors: 4 586 0x2A07
22:33:12.121    ComputerName: BARLEY-HP  UserName: Barley
22:33:13.081    Initialize success
22:33:13.099    VM: initialized successfully
22:33:13.100    VM: Intel CPU BiosDisabled 
22:35:46.152    AVAST engine defs: 17030301
22:36:27.345    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
22:36:27.347    Disk 0 Vendor: WDC_WD10EZEX-60ZF5A0 80.00A80 Size: 953869MB BusType: 11
22:36:27.457    Disk 0 MBR read successfully
22:36:27.459    Disk 0 MBR scan
22:36:27.463    Disk 0 unknown MBR code
22:36:27.470    Disk 0 Partition 1 00     EE          GPT           2097151 MB offset 1
22:36:27.507    Disk 0 scanning C:\windows\system32\drivers
22:36:57.000    Service scanning
22:37:23.997    Modules scanning
22:37:24.003    Disk 0 trace - called modules:
22:37:24.018    ntoskrnl.exe CLASSPNP.SYS disk.sys ataport.SYS PCIIDEX.SYS hal.dll msahci.sys 
22:37:24.345    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8005ffa060]
22:37:24.349    3 CLASSPNP.SYS[fffff88000c0143f] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa8005b21060]
22:37:26.001    AVAST engine scan C:\windows
22:37:28.481    AVAST engine scan C:\windows\system32
22:40:26.634    AVAST engine scan C:\windows\system32\drivers
22:40:54.687    AVAST engine scan C:\Users\Barley
22:41:20.258    File: C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Local State  **SUSPICIOUS**
22:42:46.638    Disk 0 MBR has been saved successfully to "C:\Users\Barley\Desktop\MBR.dat"
22:42:46.643    The log file has been saved successfully to "C:\Users\Barley\Desktop\aswMBR.txt"
 
FRST.txt
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 20.12.2018
Ran by [removed] (administrator) on BARLEY-HP (21-12-2018 22:51:29)
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\AVGSvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(ArcSoft, Inc.) C:\Users\Barley\AppData\Roaming\HP SimpleSave Application\uUACTokenSvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Digital Wave Ltd.) C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Garmin Ltd or its subsidiaries) C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Microsoft Corporation) C:\Program Files\Microsoft LifeCam\MSCamS64.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\NortonSecurity.exe
(PDF Complete Inc) C:\Program Files (x86)\PDF Complete\pdfsvc.exe
(Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaRegistry.exe
(Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaRegistry64.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\NortonSecurity.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\psia.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\sua.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(Microsoft Corporation) C:\Windows\System32\WirelessKB850NotificationService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\x64\aswidsagenta.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Garmin Ltd or its subsidiaries) C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\AVGUI.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Smilebox, Inc.) C:\Users\Barley\AppData\Roaming\Smilebox\SmileboxTray.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
(Hewlett-Packard) C:\Program Files (x86)\Hp\Digital Imaging\bin\HpqSRmon.exe
() C:\Users\Barley\AppData\Roaming\HP SimpleSave Application\StartHelper.exe
(the sz development) C:\Users\Barley\AppData\Local\RimhillEx\RimhillEx.exe
() C:\Program Files (x86)\PrintMyCouponAnywhere\PrintMyCouponAnywhere.exe
(Inmar, Inc.) C:\Program Files (x86)\Digital Coupon Printer\DigitalCouponPrinter.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\Brother\Brother Help\BrotherHelp.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe
(Wondershare) C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\Browny02\BrYNSvc.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(ShopAtHome.com) C:\Users\Barley\AppData\Roaming\ShopAtHome.com BrowserAppCore Service\ShopAtHome_BAC_Service.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Calendar\Service\GCalService.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Calendar\Service\HPTouchSmartSyncCalReminderApp.exe
(HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(HP Inc.) C:\Program Files\HP\HP Touchpoint Analytics Client\TouchpointAnalyticsClientService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\SeaPort.EXE
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
"Path" (C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x64;C:\Program Files (x86)\Windows Live\Shared -> %SystemRoot%\System32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x64;C:\Program Files (x86)\Windows Live\Shared) <==== Repaired successfully
HKLM\…\Run: [HPSYSDRV] => C:\Program Files (x86)\Hewlett-Packard\HP Odometer\HPSYSDRV.EXE [62768 2008-11-20] (Hewlett-Packard)
HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176440 2016-11-01] (Apple Inc.)
HKLM\…\Run: [AVGUI.exe] => C:\Program Files (x86)\AVG\Antivirus\AvLaunch.exe [290064 2018-11-15] (AVG Technologies CZ, s.r.o.)
HKLM-x32\…\Run: [hpqSRMon] => C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe [150528 2008-07-22] (Hewlett-Packard)
HKLM-x32\…\Run: [Http Listener] => C:\Program Files (x86)\PrintMyCouponAnywhere\PrintMyCouponAnywhere.exe [90760 2015-04-30] ()
HKLM-x32\…\Run: [Digital Coupon Print Driver] => C:\Program Files (x86)\Digital Coupon Printer\DigitalCouponPrinter.exe [90048 2015-09-22] (Inmar, Inc.)
HKLM-x32\…\Run: [ControlCenter4] => C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe [139776 2014-11-12] (Brother Industries, Ltd.)
HKLM-x32\…\Run: [BrStsMon00] => C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [4517376 2014-11-11] (Brother Industries, Ltd.)
HKLM-x32\…\Run: [BrHelp] => C:\Program Files (x86)\Brother\Brother Help\BrotherHelp.exe [1939968 2014-10-22] (Brother Industries, Ltd.)
HKLM-x32\…\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2137744 2016-10-08] (Wondershare)
HKLM-x32\…\Run: [DelaypluginInstall] => C:\ProgramData\Wondershare\Video Converter Ultimate\DelayPluginI.exe [1971856 2017-02-16] ()
HKLM-x32\…\Run: [PDF Complete] => C:\Program Files (x86)\PDF Complete\pdfsty.exe [1194048 2018-02-01] (PDF Complete Inc)
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [601424 2018-10-06] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\Windows\System32\igfxdev.dll (Intel Corporation)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-632860548-1775735820-415820443-1000\…\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1095000 2013-12-13] (Garmin Ltd or its subsidiaries)
HKU\S-1-5-21-632860548-1775735820-415820443-1000\…\Run: [Google Update] => C:\Users\Barley\AppData\Local\Google\Update\1.3.33.23\GoogleUpdateCore.exe [605992 2018-12-18] (Google Inc.)
HKU\S-1-5-21-632860548-1775735820-415820443-1000\…\Run: [60439BD48E4DF21A7F8F35AA69AA655C496AD691._service_run] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1587680 2018-12-12] (Google Inc.)
HKU\S-1-5-21-632860548-1775735820-415820443-1000\…\Run: [SmileboxTray] => C:\Users\Barley\AppData\Roaming\Smilebox\SmileboxTray.exe [366552 2017-09-27] (Smilebox, Inc.)
HKU\S-1-5-21-632860548-1775735820-415820443-1000\…\MountPoints2: {cf036f94-4e8d-11e2-b318-24be05218274} - G:\HPLauncher.exe
HKU\S-1-5-21-632860548-1775735820-415820443-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\windows\system32\Ribbons.scr [241664 2010-11-20] (Microsoft Corporation)
HKLM\…\Drivers32: [MSVideo8] => C:\Windows\System32\VfWWDM32.dll [68096 2010-11-20] (Microsoft Corporation)
HKLM\…\Drivers32-x32: [msacm.siren] => C:\Windows\SysWOW64\sirenacm.dll [49016 2011-05-13] (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk [2014-03-18]
ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia)
Startup: C:\Users\Barley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\HP SimpleSave Monitor.lnk [2014-03-01]
ShortcutTarget: HP SimpleSave Monitor.lnk -> C:\Users\Barley\AppData\Roaming\HP SimpleSave Application\StartHelper.exe ()
Startup: C:\Users\Barley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RimhillEx.lnk [2017-01-15]
ShortcutTarget: RimhillEx.lnk -> C:\Users\Barley\AppData\Local\RimhillEx\RimhillEx.exe (the sz development)
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{06AE0B1F-FB3C-4241-9145-DF12EC7CB857}: [DhcpNameServer] 172.20.10.1
Tcpip\..\Interfaces\{D3EED012-4886-4C2D-8491-DD153D715076}: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{D3EED012-4886-4C2D-8491-DD153D715076}: [DhcpNameServer] 75.75.75.75 75.75.76.76
 
Internet Explorer:
==================
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.coupons.com/
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=HPDTDF&pc;=HPDTDF&src;=IE-SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=HPDTDF&pc;=HPDTDF&src;=IE-SearchBox
SearchScopes: HKLM -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/711-30572-11896-1/4?mpre=hxxp://www.ebay.com/sch/i.html?_nkw={searchTerms}
SearchScopes: HKLM -> {F8E29CD1-3CFA-4356-AB1F-1E4764BF30F5} URL = hxxp://www.amazon.com/s/ref=azs_osd_iea?ie=UTF-8&tag;=hp-us1-vsb-20&link;%5Fcode=qs&index;=aps&field-keywords;={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope value is missing
SearchScopes: HKLM-x32 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/711-30572-11896-1/4?mpre=hxxp://www.ebay.com/sch/i.html?_nkw={searchTerms}
SearchScopes: HKU\S-1-5-21-632860548-1775735820-415820443-1000 -> {B3B3A6AC-74EC-BD56-BCDB-EFA4799FB9DF} URL = hxxps://www.amazon.com/gp/bit/amazonserp/ref=bit_bds-p10_serp_ie_us_display?ie=UTF8&tagbase;=bds-p10&tbrId;=v1_abb-channel-10_d088afc8_1201_1401_20160524_US_ie_ds_&tag;=bds-p10-serp-us-ie-20&query;={searchTerms}
SearchScopes: HKU\S-1-5-21-632860548-1775735820-415820443-1000 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = 
BHO: Bing Bar Helper -> {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} -> C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll [2014-03-11] (Microsoft Corporation.)
BHO: Norton Password Manager -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\coIEPlg.dll [2018-11-03] (Symantec Corporation)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_191\bin\ssv.dll [2018-12-01] (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_191\bin\jp2ssv.dll [2018-12-01] (Oracle Corporation)
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2016-07-21] (HP Inc.)
BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-09-20] (Hewlett-Packard Co.)
BHO-x32: Bing Bar Helper -> {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} -> C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll [2014-03-11] (Microsoft Corporation.)
BHO-x32: Wondershare Video Converter Ultimate 7.1.0 -> {451C804F-C205-4F03-B48E-537EC94937BF} -> C:\ProgramData\Wondershare\Video Converter Ultimate\WSBrowserAppMgr.dll [2017-02-16] (Wondershare)
BHO-x32: Norton Password Manager -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton Internet Security\Engine32\22.16.2.22\coIEPlg.dll [2018-11-03] (Symantec Corporation)
BHO-x32: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files (x86)\Norton Internet Security\Engine\21.7.0.11\IPS\IPSBHO.DLL => No File
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2016-07-21] (HP Inc.)
BHO-x32: SingleInstance Class -> {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} -> C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll [2008-07-28] (Yahoo! Inc)
BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-09-20] (Hewlett-Packard Co.)
Toolbar: HKLM - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll [2014-03-11] (Microsoft Corporation.)
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\coIEPlg.dll [2018-11-03] (Symantec Corporation)
Toolbar: HKLM-x32 - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll [2014-03-11] (Microsoft Corporation.)
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine32\22.16.2.22\coIEPlg.dll [2018-11-03] (Symantec Corporation)
Toolbar: HKU\S-1-5-21-632860548-1775735820-415820443-1000 -> Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\coIEPlg.dll [2018-11-03] (Symantec Corporation)
Handler: WSWSVCUchrome - {1CA93FF0-A218-44F1 -  No File
 
FireFox:
========
FF ProfilePath: C:\Users\Barley\AppData\Roaming\Mozilla\Firefox\Profiles\z9dx3jxz.default [2018-12-10]
FF Extension: (Wondershare Video Converter Ultimate) - C:\ProgramData\Wondershare\Video Converter Ultimate\WSVCU@Wondershare.com_xpi\ [] [Legacy]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: (HP Smart Web Printing) - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2013-02-03] [Legacy] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\ProgramData\Wondershare\Video Converter Ultimate\WSVCU@Wondershare.com_xpi
FF Extension: (Wondershare Video Converter Ultimate) - C:\ProgramData\Wondershare\Video Converter Ultimate\WSVCU@Wondershare.com_xpi [2017-03-03] [Legacy]
FF HKU\S-1-5-21-632860548-1775735820-415820443-1000\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_32_0_0_101.dll [2018-12-05] ()
FF Plugin: @java.com/DTPlugin,version=11.191.2 -> C:\Program Files\Java\jre1.8.0_191\bin\dtplugin\npDeployJava1.dll [2018-12-01] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.191.2 -> C:\Program Files\Java\jre1.8.0_191\bin\plugin2\npjp2.dll [2018-12-01] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_101.dll [2018-12-05] ()
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @Sibelius.com/Scorch Plugin,version=6.2.0.88 -> C:\Program Files (x86)\Sibelius Software\Scorch\npsibelius.dll [2013-03-11] ()
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.23\npGoogleUpdate3.dll [2018-12-18] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.23\npGoogleUpdate3.dll [2018-12-18] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2011-09-28] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-12-04] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-632860548-1775735820-415820443-1000: @tools.google.com/Google Update;version=3 -> C:\Users\Barley\AppData\Local\Google\Update\1.3.33.23\npGoogleUpdate3.dll [2018-12-18] (Google Inc.)
FF Plugin HKU\S-1-5-21-632860548-1775735820-415820443-1000: @tools.google.com/Google Update;version=9 -> C:\Users\Barley\AppData\Local\Google\Update\1.3.33.23\npGoogleUpdate3.dll [2018-12-18] (Google Inc.)
FF Plugin HKU\S-1-5-21-632860548-1775735820-415820443-1000: CouponNetwork.com/CMDUniversalCouponPrintActivator -> C:\Users\Barley\AppData\Roaming\CATALI~1\NPBCSK~1.DLL [2013-06-07] (Catalina Marketing Corporation)
FF Plugin HKU\S-1-5-21-632860548-1775735820-415820443-1000: hopster.com/CouponPrinterPlugin -> C:\Users\Barley\AppData\Roaming\Hopster\CouponPrinterPlugin\2.0.2.0\npCouponPrinterPlugin.dll [2013-02-21] (Hopster)
FF Plugin HKU\S-1-5-21-632860548-1775735820-415820443-1000: revtrax.com/RevTraxPrintMyCoupon -> C:\Users\Barley\AppData\Roaming\RevTrax\RevTraxPrintMyCoupon\1.0.0.0\npRevTraxPrintMyCoupon.dll [2014-10-15] (RevTrax)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\browser\plugins\npMozCouponPrinter.dll [2015-09-18] (Coupons, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Barley\AppData\Roaming\mozilla\plugins\npatgpc.dll [2015-11-18] (Cisco WebEx LLC)
 
Chrome: 
=======
CHR DefaultProfile: Profile 1
CHR HomePage: Profile 1 -> hxxp://www.search.ask.com/?gct=hp
CHR StartupUrls: Profile 1 -> "hxxp://www.google.com/"
CHR NewTab: Profile 1 ->  Not-active:"chrome-extension://bkpkokkapfiigghcbhkblnngjlcccckf/index.html", Not-active:"chrome-extension://lpdcomiegbcchfdacgnkemnicebaodne/newtab/newtab.html", Not-active:"chrome-extension://gbioooacocedmkdadhinnkjonienkfbe/stubby.html", Not-active:"chrome-extension://dpgfhhkchdfegbdmjginkcffgjncmboh/stubby.html"
CHR Profile: C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Guest Profile [2018-12-10]
CHR Profile: C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1 [2018-12-21]
CHR Extension: (Bejeweled) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\adpkifcfcacgmnggcbpbjbkdijciiigm [2015-04-15]
CHR Extension: (Asus Download Master) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\akidbpofokakpmmabjlpcgplfmbmcemj [2015-04-15]
CHR Extension: (Docs) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-12]
CHR Extension: (Google Drive) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21]
CHR Extension: (YouTube) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-25]
CHR Extension: (Honey) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bmnlcjabgnpnenekpadlanbbkooimhnj [2018-11-12]
CHR Extension: (Norton Security Toolbar) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\cjabmdjcfcfdmffimndhafhblfmpjdpe [2018-11-19]
CHR Extension: (Google Search) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27]
CHR Extension: (Fancy Pants 3) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ddmbgnlndmdpfggbojljojamjkkikeka [2015-04-15]
CHR Extension: (FromDocToPDF) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\dpgfhhkchdfegbdmjginkcffgjncmboh [2018-12-10]
CHR Extension: (App for Instagram) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ebmdoffeooapnmjcnidddmhancpfpjab [2018-12-12]
CHR Extension: (Adobe Acrobat) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-03-15]
CHR Extension: (OnlineMapFinder) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gbioooacocedmkdadhinnkjonienkfbe [2018-12-10]
CHR Extension: (Google Docs Offline) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-08-14]
CHR Extension: (Savings Button: Deals + Cash Back) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\hmhdchlgkaelnphlklcdddpigfiblbhb [2018-10-29]
CHR Extension: (Norton Identity Safe) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iikflkcanblccfahdhdonehdalibjnif [2015-02-07]
CHR Extension: (Cisco Webex Extension) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\jlhmfgmfgeifomenelglieieghnjghma [2018-07-05]
CHR Extension: (mydlink services plugin) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ldibdoepbjbkkcbgndfljnphngpglhbb [2016-01-01]
CHR Extension: (FromDocToPDF) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mallpejgeafdahhflmliiahjdpgbegpk [2018-12-10]
CHR Extension: (AVG SafePrice | Comparison, deals, coupons) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mbckjcfnjmoiinpgddefodcighgikkgn [2018-12-18]
CHR Extension: (CouponXplorer) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mgdcgnnjenhecpdnhpnhpmgndjenmnnk [2018-12-10]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-04]
CHR Extension: (Amazon Smart Search) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ooebgdicanjhnamfmdlmlbcnkgehkkmf [2016-05-24]
CHR Extension: (Gmail) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-28]
CHR Extension: (Chrome Media Router) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-12-07]
CHR Profile: C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 2 [2018-12-06]
CHR Extension: (Slides) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-12-06]
CHR Extension: (Docs) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aohghmighlieiainnegkcijnfilokake [2018-12-06]
CHR Extension: (Google Drive) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-08-18]
CHR Extension: (YouTube) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-12-06]
CHR Extension: (Norton Security Toolbar) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\cjabmdjcfcfdmffimndhafhblfmpjdpe [2015-08-18]
CHR Extension: (Google Search) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-08-18]
CHR Extension: (Adobe Acrobat) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2018-12-06]
CHR Extension: (Sheets) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-12-06]
CHR Extension: (Google Docs Offline) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-12-06]
CHR Extension: (Norton Identity Safe) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\iikflkcanblccfahdhdonehdalibjnif [2015-08-18]
CHR Extension: (AVG SafePrice | Comparison, deals, coupons) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\mbckjcfnjmoiinpgddefodcighgikkgn [2018-12-06]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-12-06]
CHR Extension: (Amazon Smart Search) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ooebgdicanjhnamfmdlmlbcnkgehkkmf [2018-12-06]
CHR Extension: (Amazon Assistant for Chrome) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pbjikboenpfhbbejgkoklgkhjpfogcam [2018-12-06]
CHR Extension: (Gmail) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-08-18]
CHR Extension: (Chrome Media Router) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-12-06]
CHR Profile: C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3 [2018-12-09]
CHR Extension: (Slides) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-12-06]
CHR Extension: (Entanglement Web App) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\aciahcmjmecflokailenpkdchphgkefd [2018-12-06]
CHR Extension: (Docs) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\aohghmighlieiainnegkcijnfilokake [2018-12-06]
CHR Extension: (Google Drive) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-12-06]
CHR Extension: (YouTube) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-12-06]
CHR Extension: (Adblock Plus) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2018-12-06]
CHR Extension: (Pushbullet) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\chlffgpmiacpedhhbkiomidkjlcfhogd [2018-12-06]
CHR Extension: (Norton Security Toolbar) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\cjabmdjcfcfdmffimndhafhblfmpjdpe [2018-12-06]
CHR Extension: (Spotify - Music for every moment) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\cnkjkdjlofllcpbemipjbcpfnglbgieh [2018-12-06]
CHR Extension: (Adobe Acrobat) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2018-12-06]
CHR Extension: (Photo Zoom for Facebook) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\elioihkkcdgakfbahdoddophfngopipi [2018-12-06]
CHR Extension: (Sheets) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-12-06]
CHR Extension: (Google Docs Offline) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-12-08]
CHR Extension: (Bitly | Unleash the power of the link) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\iabeihobmhlgpkcgjiloemdbofjbdcic [2018-12-06]
CHR Extension: (AVG SafePrice | Comparison, deals, coupons) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\mbckjcfnjmoiinpgddefodcighgikkgn [2018-12-06]
CHR Extension: (Poppit!) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\mcbkbpnkkkipelfledbfocopglifcfmi [2018-12-06]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-12-06]
CHR Extension: (Hover Zoom) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\nonjdcjchghhkdoolnlbekcfllmednbl [2018-12-06]
CHR Extension: (Amazon Smart Search) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\ooebgdicanjhnamfmdlmlbcnkgehkkmf [2018-12-06]
CHR Extension: (Amazon Assistant for Chrome) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\pbjikboenpfhbbejgkoklgkhjpfogcam [2018-12-06]
CHR Extension: (Gmail) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-12-06]
CHR Extension: (Chrome Media Router) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-12-07]
CHR Profile: C:\Users\Barley\AppData\Local\Google\Chrome\User Data\System Profile [2018-12-06]
CHR Extension: (Google Slides) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-05-30]
CHR Extension: (Google Docs) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\aohghmighlieiainnegkcijnfilokake [2015-05-30]
CHR Extension: (Google Drive) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-05-30]
CHR Extension: (YouTube) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-05-30]
CHR Extension: (Google Search) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-05-30]
CHR Extension: (Google Sheets) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-05-30]
CHR Extension: (Gmail) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-05-30]
CHR HKLM\…\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\Exts\Chrome.crx
CHR HKLM\…\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-632860548-1775735820-415820443-1000\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [ooebgdicanjhnamfmdlmlbcnkgehkkmf] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-632860548-1775735820-415820443-1000\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [pbjikboenpfhbbejgkoklgkhjpfogcam] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\Exts\Chrome.crx
CHR HKLM-x32\…\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [mbckjcfnjmoiinpgddefodcighgikkgn] - hxxps://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-09-22] (Apple Inc.)
R2 AVG Antivirus; C:\Program Files (x86)\AVG\Antivirus\AVGSvc.exe [324048 2018-11-15] (AVG Technologies CZ, s.r.o.)
R3 avgbIDSAgent; C:\Program Files (x86)\AVG\Antivirus\x64\aswidsagenta.exe [8237160 2018-11-15] (AVG Technologies CZ, s.r.o.)
R2 BackupService; C:\Users\Barley\AppData\Roaming\HP SimpleSave Application\uUACTokenSvc.exe [83512 2010-07-01] (ArcSoft, Inc.)
R3 BrYNSvc; C:\Program Files (x86)\Browny02\BrYNSvc.exe [289792 2014-10-23] (Brother Industries, Ltd.) [File not signed]
R2 CalendarSynchService; C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Calendar\Service\GCalService.exe [16384 2011-08-16] (Hewlett-Packard) [File not signed]
R2 DigitalWave.Update.Service; C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe [440808 2017-01-20] (Digital Wave Ltd.)
R2 Garmin Core Update Service; C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [250712 2013-12-13] (Garmin Ltd or its subsidiaries)
S3 GoogleChromeElevationService; C:\Program Files (x86)\Google\Chrome\Application\71.0.3578.98\elevation_service.exe [443872 2018-12-12] (Google Inc.)
R3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [249344 2009-09-20] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-09-20] (Hewlett-Packard Co.) [File not signed]
R2 HPSLPSVC; C:\Users\Barley\AppData\Local\Temp\7zS0674\hpslpsvc64.dll [1039360 2012-08-27] (Hewlett-Packard Co.) [File not signed] <==== ATTENTION
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [347512 2018-12-06] (HP Inc.)
R2 HPTouchpointAnalyticsService; C:\Program Files\HP\HP Touchpoint Analytics Client\TouchpointAnalyticsClientService.exe [332216 2017-11-22] (HP Inc.)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6347056 2018-09-19] (Malwarebytes)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2008-12-03] (Hewlett-Packard) [File not signed]
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-01] (Symantec Corporation)
R2 NortonSecurity; C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\NortonSecurity.exe [328648 2018-11-03] (Symantec Corporation)
R2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [1795136 2018-02-01] (PDF Complete Inc)
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2008-12-03] (Hewlett-Packard) [File not signed]
R2 RalinkRegistryWriter; C:\Program Files (x86)\Ralink\Common\RaRegistry.exe [372736 2012-01-13] (Ralink Technology, Corp.) [File not signed]
R2 RalinkRegistryWriter64; C:\Program Files (x86)\Ralink\Common\RaRegistry64.exe [447488 2012-01-13] (Ralink Technology, Corp.) [File not signed]
S2 RaMediaServer; C:\Program Files (x86)\Ralink\Common\RaMediaServer.exe [625728 2011-08-18] ()
R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1229528 2013-12-06] (Secunia)
R2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [662232 2013-12-06] (Secunia)
R2 STacSV; C:\Program Files\IDT\WDM\STacSV64.exe [311296 2012-03-30] (IDT, Inc.) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
R2 WirelessKB850NotificationService; C:\windows\system32\WirelessKB850NotificationService.exe [174256 2018-05-14] (Microsoft Corporation)
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R1 avgArPot; C:\windows\System32\drivers\avgArPot.sys [201504 2018-11-15] (AVG Technologies CZ, s.r.o.)
R1 avgbidsdriver; C:\windows\System32\drivers\avgbidsdrivera.sys [231104 2018-11-15] (AVG Technologies CZ, s.r.o.)
R0 avgbidsh; C:\windows\System32\drivers\avgbidsha.sys [202528 2018-11-15] (AVG Technologies CZ, s.r.o.)
R0 avgblog; C:\windows\System32\drivers\avgbloga.sys [346840 2018-11-15] (AVG Technologies CZ, s.r.o.)
R0 avgbuniv; C:\windows\System32\drivers\avgbuniva.sys [59744 2018-11-15] (AVG Technologies CZ, s.r.o.)
S3 avgHwid; C:\windows\System32\drivers\avgHwid.sys [46648 2018-11-15] (AVG Technologies CZ, s.r.o.)
R1 avgKbd; C:\windows\System32\drivers\avgKbd.sys [42552 2018-11-15] (AVG Technologies CZ, s.r.o.)
R2 avgMonFlt; C:\windows\System32\drivers\avgMonFlt.sys [163496 2018-11-15] (AVG Technologies CZ, s.r.o.)
R1 avgRdr; C:\windows\System32\drivers\avgRdr2.sys [112040 2018-11-15] (AVG Technologies CZ, s.r.o.)
R0 avgRvrt; C:\windows\System32\drivers\avgRvrt.sys [87680 2018-11-15] (AVG Technologies CZ, s.r.o.)
R1 avgSnx; C:\windows\System32\drivers\avgSnx.sys [1028920 2018-11-15] (AVG Technologies CZ, s.r.o.)
R1 avgSP; C:\windows\System32\drivers\avgSP.sys [469520 2018-11-15] (AVG Technologies CZ, s.r.o.)
R2 avgStm; C:\windows\System32\drivers\avgStm.sys [208712 2018-11-15] (AVG Technologies CZ, s.r.o.)
R0 avgVmm; C:\windows\System32\drivers\avgVmm.sys [380704 2018-11-15] (AVG Technologies CZ, s.r.o.)
R1 BHDrvx64; C:\Program Files (x86)\Norton Internet Security\NortonData\22.5.2.15\Definitions\BASHDefs\20181016.001\BHDrvx64.sys [1925104 2018-10-16] (Symantec Corporation)
R1 ccSet_NGC; C:\windows\System32\drivers\NGCx64\1610020.016\ccSetx64.sys [189120 2018-11-03] (Symantec Corporation)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [515776 2018-10-20] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [153280 2018-10-22] (Symantec Corporation)
R1 ESProtectionDriver; C:\windows\system32\drivers\mbae64.sys [152688 2018-12-04] (Malwarebytes)
R1 IDSVia64; C:\Program Files (x86)\Norton Internet Security\NortonData\22.5.2.15\Definitions\IPSDefs\20181019.061\IDSvia64.sys [1305072 2018-10-19] (Symantec Corporation)
R2 MBAMChameleon; C:\windows\System32\Drivers\MbamChameleon.sys [198512 2018-12-21] (Malwarebytes)
R3 MBAMFarflt; C:\windows\System32\DRIVERS\farflt.sys [126624 2018-12-21] (Malwarebytes)
R3 MBAMProtection; C:\windows\System32\DRIVERS\mbam.sys [72536 2018-12-21] (Malwarebytes)
R0 MBAMSwissArmy; C:\windows\System32\Drivers\mbamswissarmy.sys [261032 2018-12-21] (Malwarebytes)
R3 MBAMWebProtection; C:\windows\System32\DRIVERS\mwac.sys [103760 2018-12-21] (Malwarebytes)
S3 PSI; C:\windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2013-12-06] (Secunia)
R3 SRTSP; C:\windows\System32\drivers\NGCx64\1610020.016\SRTSP64.SYS [847344 2018-11-03] (Symantec Corporation)
R1 SRTSPX; C:\windows\System32\drivers\NGCx64\1610020.016\SRTSPX64.SYS [49648 2018-11-03] (Symantec Corporation)
R0 SymEFASI; C:\windows\System32\drivers\NGCx64\1610020.016\SYMEFASI64.SYS [1969328 2018-11-03] (Symantec Corporation)
R3 SymEvent; C:\windows\system32\Drivers\SYMEVENT64x86.SYS [99920 2018-06-17] (Symantec Corporation)
S4 SymEvnt; C:\Program Files (x86)\Norton Internet Security\NortonData\22.5.2.15\SymPlatform\SymEvnt.sys [114256 2018-09-27] (Symantec Corporation)
R1 SymIRON; C:\windows\System32\drivers\NGCx64\1610020.016\Ironx64.SYS [308416 2018-11-03] (Symantec Corporation)
R1 SymNetS; C:\windows\System32\drivers\NGCx64\1610020.016\symnets.sys [567024 2018-11-03] (Symantec Corporation)
S3 wpCtrlDrv_NGC; C:\windows\System32\drivers\NGCx64\1610020.016\wpCtrlDrv.sys [1011056 2018-11-03] (Symantec Corporation)
S1 AntiLog32; \??\C:\windows\system32\drivers\AntiLog64.sys [X]
S3 NAVENG; \??\C:\Program Files (x86)\Norton Internet Security\NortonData\22.5.2.15\Definitions\SDSDefs\20160823.022\ENG64.SYS [X]
S3 NAVEX15; \??\C:\Program Files (x86)\Norton Internet Security\NortonData\22.5.2.15\Definitions\SDSDefs\20160823.022\EX64.SYS [X]
U3 aswMBR; \??\C:\Users\Barley\AppData\Local\Temp\aswMBR.sys [X] <==== ATTENTION
U3 aswVmm; \??\C:\Users\Barley\AppData\Local\Temp\aswVmm.sys [X] <==== ATTENTION
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2018-12-21 22:51 - 2018-12-21 22:53 - 000045413 _____ C:\Users\Barley\Desktop\FRST.txt
2018-12-21 22:50 - 2018-12-21 22:51 - 000000000 ____D C:\FRST
2018-12-21 22:50 - 2018-12-21 22:48 - 002420224 _____ (Farbar) C:\Users\Barley\Desktop\FRST64.exe
2018-12-21 22:48 - 2018-12-21 22:48 - 002420224 _____ (Farbar) C:\Users\Barley\Downloads\FRST64.exe
2018-12-21 22:42 - 2018-12-21 22:42 - 000001845 _____ C:\Users\Barley\Desktop\aswMBR.txt
2018-12-21 22:42 - 2018-12-21 22:42 - 000000512 _____ C:\Users\Barley\Desktop\MBR.dat
2018-12-21 22:31 - 2018-12-21 22:31 - 005198336 _____ (AVAST Software) C:\Users\Barley\Downloads\aswMBR (2).exe
2018-12-21 22:31 - 2018-12-21 22:22 - 005198336 _____ (AVAST Software) C:\Users\Barley\Desktop\aswMBR.exe
2018-12-21 22:25 - 2018-12-21 22:25 - 005198336 _____ (AVAST Software) C:\Users\Barley\Downloads\aswMBR (1).exe
2018-12-21 22:22 - 2018-12-21 22:22 - 005198336 _____ (AVAST Software) C:\Users\Barley\Downloads\aswMBR.exe
2018-12-21 20:55 - 2018-12-21 20:55 - 000126624 _____ (Malwarebytes) C:\windows\system32\Drivers\farflt.sys
2018-12-21 20:55 - 2018-12-21 20:55 - 000103760 _____ (Malwarebytes) C:\windows\system32\Drivers\mwac.sys
2018-12-21 20:55 - 2018-12-21 20:55 - 000072536 _____ (Malwarebytes) C:\windows\system32\Drivers\mbam.sys
2018-12-21 16:31 - 2018-12-21 16:31 - 000000000 ____D C:\windows\System32\Tasks\Remediation
2018-12-21 16:21 - 2018-12-21 16:21 - 000261032 _____ (Malwarebytes) C:\windows\system32\Drivers\mbamswissarmy.sys
2018-12-21 16:21 - 2018-12-21 16:21 - 000198512 _____ (Malwarebytes) C:\windows\system32\Drivers\MbamChameleon.sys
2018-12-21 16:21 - 2018-12-21 16:21 - 000001869 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2018-12-21 16:21 - 2018-12-21 16:21 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2018-12-21 16:21 - 2018-12-04 08:09 - 000152688 _____ (Malwarebytes) C:\windows\system32\Drivers\mbae64.sys
2018-12-21 16:19 - 2018-12-21 16:20 - 081227760 _____ (Malwarebytes ) C:\Users\Barley\Downloads\mb3-setup-consumer-3.6.1.2711-1.0.508-1.0.8211.exe
2018-12-20 23:07 - 2018-12-14 19:06 - 000397088 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2018-12-20 23:07 - 2018-12-14 18:14 - 000348760 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2018-12-20 23:07 - 2018-12-14 03:09 - 025736704 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2018-12-20 23:07 - 2018-12-14 03:01 - 002724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2018-12-20 23:07 - 2018-12-14 03:01 - 000004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2018-12-20 23:07 - 2018-12-14 02:51 - 002902016 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2018-12-20 23:07 - 2018-12-14 02:49 - 000417280 _____ (Microsoft Corporation) C:\windows\system32\html.iec
2018-12-20 23:07 - 2018-12-14 02:49 - 000066560 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2018-12-20 23:07 - 2018-12-14 02:49 - 000048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2018-12-20 23:07 - 2018-12-14 02:48 - 000576512 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2018-12-20 23:07 - 2018-12-14 02:48 - 000088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2018-12-20 23:07 - 2018-12-14 02:42 - 000054784 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2018-12-20 23:07 - 2018-12-14 02:41 - 000034304 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2018-12-20 23:07 - 2018-12-14 02:39 - 000615936 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2018-12-20 23:07 - 2018-12-14 02:38 - 000814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2018-12-20 23:07 - 2018-12-14 02:38 - 000790016 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2018-12-20 23:07 - 2018-12-14 02:38 - 000144384 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2018-12-20 23:07 - 2018-12-14 02:38 - 000116224 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2018-12-20 23:07 - 2018-12-14 02:36 - 005779456 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2018-12-20 23:07 - 2018-12-14 02:33 - 000969216 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2018-12-20 23:07 - 2018-12-14 02:30 - 000489984 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2018-12-20 23:07 - 2018-12-14 02:24 - 000087552 _____ (Microsoft Corporation) C:\windows\system32\tdc.ocx
2018-12-20 23:07 - 2018-12-14 02:24 - 000077824 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2018-12-20 23:07 - 2018-12-14 02:23 - 000107520 _____ (Microsoft Corporation) C:\windows\system32\inseng.dll
2018-12-20 23:07 - 2018-12-14 02:21 - 000199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2018-12-20 23:07 - 2018-12-14 02:20 - 000092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2018-12-20 23:07 - 2018-12-14 02:18 - 000315392 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2018-12-20 23:07 - 2018-12-14 02:17 - 000152064 _____ (Microsoft Corporation) C:\windows\system32\occache.dll
2018-12-20 23:07 - 2018-12-14 02:09 - 000262144 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll
2018-12-20 23:07 - 2018-12-14 02:06 - 000809472 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2018-12-20 23:07 - 2018-12-14 02:06 - 000728064 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2018-12-20 23:07 - 2018-12-14 02:05 - 001359360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2018-12-20 23:07 - 2018-12-14 02:04 - 002136064 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2018-12-20 23:07 - 2018-12-14 02:02 - 015284736 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2018-12-20 23:07 - 2018-12-14 01:58 - 020280832 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2018-12-20 23:07 - 2018-12-14 01:57 - 004859904 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2018-12-20 23:07 - 2018-12-14 01:51 - 002724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2018-12-20 23:07 - 2018-12-14 01:45 - 001555968 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2018-12-20 23:07 - 2018-12-14 01:41 - 000498176 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2018-12-20 23:07 - 2018-12-14 01:41 - 000062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2018-12-20 23:07 - 2018-12-14 01:40 - 000341504 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec
2018-12-20 23:07 - 2018-12-14 01:40 - 000047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2018-12-20 23:07 - 2018-12-14 01:39 - 000064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2018-12-20 23:07 - 2018-12-14 01:38 - 002295808 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2018-12-20 23:07 - 2018-12-14 01:35 - 000047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2018-12-20 23:07 - 2018-12-14 01:35 - 000030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2018-12-20 23:07 - 2018-12-14 01:34 - 000800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2018-12-20 23:07 - 2018-12-14 01:34 - 000476160 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2018-12-20 23:07 - 2018-12-14 01:33 - 000663040 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2018-12-20 23:07 - 2018-12-14 01:33 - 000115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2018-12-20 23:07 - 2018-12-14 01:32 - 000620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2018-12-20 23:07 - 2018-12-14 01:26 - 000416256 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2018-12-20 23:07 - 2018-12-14 01:23 - 000060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2018-12-20 23:07 - 2018-12-14 01:22 - 000091136 _____ (Microsoft Corporation) C:\windows\SysWOW64\inseng.dll
2018-12-20 23:07 - 2018-12-14 01:22 - 000073216 _____ (Microsoft Corporation) C:\windows\SysWOW64\tdc.ocx
2018-12-20 23:07 - 2018-12-14 01:20 - 000168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2018-12-20 23:07 - 2018-12-14 01:19 - 000279040 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2018-12-20 23:07 - 2018-12-14 01:19 - 000076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2018-12-20 23:07 - 2018-12-14 01:18 - 004494848 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2018-12-20 23:07 - 2018-12-14 01:18 - 000130048 _____ (Microsoft Corporation) C:\windows\SysWOW64\occache.dll
2018-12-20 23:07 - 2018-12-14 01:14 - 013681152 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2018-12-20 23:07 - 2018-12-14 01:13 - 000230400 _____ (Microsoft Corporation) C:\windows\SysWOW64\webcheck.dll
2018-12-20 23:07 - 2018-12-14 01:11 - 002059776 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2018-12-20 23:07 - 2018-12-14 01:11 - 000696320 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2018-12-20 23:07 - 2018-12-14 01:10 - 001155072 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2018-12-20 23:07 - 2018-12-14 00:58 - 004386816 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2018-12-20 23:07 - 2018-12-14 00:54 - 001330176 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2018-12-20 23:07 - 2018-12-14 00:52 - 000710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2018-12-11 14:16 - 2018-12-05 21:39 - 003227648 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2018-12-11 14:16 - 2018-11-28 17:02 - 014635520 _____ (Microsoft Corporation) C:\windows\system32\wmp.dll
2018-12-11 14:16 - 2018-11-28 17:02 - 012574720 _____ (Microsoft Corporation) C:\windows\system32\wmploc.DLL
2018-12-11 14:16 - 2018-11-28 17:02 - 000009728 _____ (Microsoft Corporation) C:\windows\system32\spwmp.dll
2018-12-11 14:16 - 2018-11-28 17:02 - 000005632 _____ (Microsoft Corporation) C:\windows\system32\msdxm.ocx
2018-12-11 14:16 - 2018-11-28 17:02 - 000005632 _____ (Microsoft Corporation) C:\windows\system32\dxmasf.dll
2018-12-11 14:16 - 2018-11-28 16:50 - 012574208 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmploc.DLL
2018-12-11 14:16 - 2018-11-28 16:50 - 011411968 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmp.dll
2018-12-11 14:16 - 2018-11-28 16:38 - 000008192 _____ (Microsoft Corporation) C:\windows\SysWOW64\spwmp.dll
2018-12-11 14:16 - 2018-11-28 16:38 - 000004608 _____ (Microsoft Corporation) C:\windows\SysWOW64\msdxm.ocx
2018-12-11 14:16 - 2018-11-28 16:38 - 000004608 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxmasf.dll
2018-12-11 14:16 - 2018-11-11 12:19 - 000631680 _____ (Microsoft Corporation) C:\windows\system32\winresume.efi
2018-12-11 14:16 - 2018-11-11 12:02 - 000262376 _____ (Microsoft Corporation) C:\windows\system32\hal.dll
2018-12-11 14:16 - 2018-11-11 12:01 - 005551848 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2018-12-11 14:16 - 2018-11-11 12:01 - 000708328 _____ (Microsoft Corporation) C:\windows\system32\winload.efi
2018-12-11 14:16 - 2018-11-11 12:01 - 000366824 _____ (Microsoft Corporation) C:\windows\system32\Drivers\msrpc.sys
2018-12-11 14:16 - 2018-11-11 12:01 - 000154856 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2018-12-11 14:16 - 2018-11-11 12:01 - 000095464 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2018-12-11 14:16 - 2018-11-11 12:00 - 001664360 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 001461760 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 001211904 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 001163264 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000731648 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000503808 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000419840 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000405504 _____ (Microsoft Corporation) C:\windows\system32\gdi32.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000361984 _____ (Microsoft Corporation) C:\windows\system32\wow64win.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000345600 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000316928 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000312320 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000215552 _____ (Microsoft Corporation) C:\windows\system32\winsrv.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000210432 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000190464 _____ (Microsoft Corporation) C:\windows\system32\rpchttp.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000135680 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000094208 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000063488 _____ (Microsoft Corporation) C:\windows\system32\setbcdlocale.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000050176 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000028672 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000016384 _____ (Microsoft Corporation) C:\windows\system32\ntvdm64.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000013312 _____ (Microsoft Corporation) C:\windows\system32\wow64cpu.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000880640 _____ (Microsoft Corporation) C:\windows\system32\advapi32.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000690688 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000463872 _____ (Microsoft Corporation) C:\windows\system32\certcli.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000123904 _____ (Microsoft Corporation) C:\windows\system32\bcrypt.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000059904 _____ (Microsoft Corporation) C:\windows\system32\appidapi.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000044032 _____ (Microsoft Corporation) C:\windows\system32\csrsrv.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000043520 _____ (Microsoft Corporation) C:\windows\system32\cryptbase.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000034816 _____ (Microsoft Corporation) C:\windows\system32\appidsvc.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000006656 _____ (Microsoft Corporation) C:\windows\system32\apisetschema.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000006144 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000005120 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:49 - 004054760 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
2018-12-11 14:16 - 2018-11-11 11:49 - 003960040 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
2018-12-11 14:16 - 2018-11-11 11:47 - 001314104 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
2018-12-11 14:16 - 2018-11-11 11:45 - 001114112 _____ (Microsoft Corporation) C:\windows\SysWOW64\kernel32.dll
2018-12-11 14:16 - 2018-11-11 11:45 - 000666112 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpcrt4.dll
2018-12-11 14:16 - 2018-11-11 11:45 - 000554496 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2018-12-11 14:16 - 2018-11-11 11:45 - 000313344 _____ (Microsoft Corporation) C:\windows\SysWOW64\gdi32.dll
2018-12-11 14:16 - 2018-11-11 11:45 - 000275968 _____ (Microsoft Corporation) C:\windows\SysWOW64\KernelBase.dll
2018-12-11 14:16 - 2018-11-11 11:45 - 000261120 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2018-12-11 14:16 - 2018-11-11 11:45 - 000254464 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2018-12-11 14:16 - 2018-11-11 11:45 - 000223232 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
2018-12-11 14:16 - 2018-11-11 11:45 - 000172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
2018-12-11 14:16 - 2018-11-11 11:45 - 000146432 _____ (Microsoft Corporation) C:\windows\SysWOW64\msaudite.dll
2018-12-11 14:16 - 2018-11-11 11:45 - 000141312 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpchttp.dll
2018-12-11 14:16 - 2018-11-11 11:45 - 000096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
2018-12-11 14:16 - 2018-11-11 11:45 - 000082944 _____ (Microsoft Corporation) C:\windows\SysWOW64\bcrypt.dll
2018-12-11 14:16 - 2018-11-11 11:45 - 000070144 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2018-12-11 14:16 - 2018-11-11 11:45 - 000060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\msobjs.dll
2018-12-11 14:16 - 2018-11-11 11:45 - 000043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\srclient.dll
2018-12-11 14:16 - 2018-11-11 11:45 - 000022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
2018-12-11 14:16 - 2018-11-11 11:45 - 000005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000690688 _____ (Microsoft Corporation) C:\windows\SysWOW64\adtschema.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000644096 _____ (Microsoft Corporation) C:\windows\SysWOW64\advapi32.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000342528 _____ (Microsoft Corporation) C:\windows\SysWOW64\certcli.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000050688 _____ (Microsoft Corporation) C:\windows\SysWOW64\appidapi.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\apisetschema.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000005120 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:25 - 000148480 _____ (Microsoft Corporation) C:\windows\system32\appidpolicyconverter.exe
2018-12-11 14:16 - 2018-11-11 11:25 - 000062464 _____ (Microsoft Corporation) C:\windows\system32\Drivers\appid.sys
2018-12-11 14:16 - 2018-11-11 11:25 - 000017920 _____ (Microsoft Corporation) C:\windows\system32\appidcertstorecheck.exe
2018-12-11 14:16 - 2018-11-11 11:24 - 000064000 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe
2018-12-11 14:16 - 2018-11-11 11:20 - 000338432 _____ (Microsoft Corporation) C:\windows\system32\conhost.exe
2018-12-11 14:16 - 2018-11-11 11:20 - 000129024 _____ (Microsoft Corporation) C:\windows\system32\Drivers\videoprt.sys
2018-12-11 14:16 - 2018-11-11 11:19 - 000296960 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe
2018-12-11 14:16 - 2018-11-11 11:19 - 000050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\auditpol.exe
2018-12-11 14:16 - 2018-11-11 11:16 - 000291328 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb10.sys
2018-12-11 14:16 - 2018-11-11 11:16 - 000160768 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb.sys
2018-12-11 14:16 - 2018-11-11 11:16 - 000129536 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb20.sys
2018-12-11 14:16 - 2018-11-11 11:15 - 000112640 _____ (Microsoft Corporation) C:\windows\system32\smss.exe
2018-12-11 14:16 - 2018-11-11 11:15 - 000064512 _____ (Microsoft Corporation) C:\windows\system32\Drivers\amdk8.sys
2018-12-11 14:16 - 2018-11-11 11:15 - 000062464 _____ (Microsoft Corporation) C:\windows\system32\Drivers\intelppm.sys
2018-12-11 14:16 - 2018-11-11 11:15 - 000060928 _____ (Microsoft Corporation) C:\windows\system32\Drivers\processr.sys
2018-12-11 14:16 - 2018-11-11 11:15 - 000060928 _____ (Microsoft Corporation) C:\windows\system32\Drivers\amdppm.sys
2018-12-11 14:16 - 2018-11-11 11:15 - 000030720 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2018-12-11 14:16 - 2018-11-11 11:15 - 000025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe
2018-12-11 14:16 - 2018-11-11 11:15 - 000014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll
2018-12-11 14:16 - 2018-11-11 11:15 - 000007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe
2018-12-11 14:16 - 2018-11-11 11:15 - 000002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe
2018-12-11 14:16 - 2018-11-11 11:14 - 000036352 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptbase.dll
2018-12-11 14:16 - 2018-11-11 11:13 - 000006144 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:13 - 000004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:13 - 000003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:13 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2018-12-11 14:16 - 2018-11-08 11:58 - 002009600 _____ (Microsoft Corporation) C:\windows\system32\msxml6.dll
2018-12-11 14:16 - 2018-11-08 11:58 - 001889280 _____ (Microsoft Corporation) C:\windows\system32\msxml3.dll
2018-12-11 14:16 - 2018-11-08 11:58 - 000002048 _____ (Microsoft Corporation) C:\windows\system32\msxml6r.dll
2018-12-11 14:16 - 2018-11-08 11:58 - 000002048 _____ (Microsoft Corporation) C:\windows\system32\msxml3r.dll
2018-12-11 14:16 - 2018-11-08 11:43 - 001391104 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml6.dll
2018-12-11 14:16 - 2018-11-08 11:43 - 001241088 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3.dll
2018-12-11 14:16 - 2018-11-08 11:43 - 000002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml6r.dll
2018-12-11 14:16 - 2018-11-08 11:43 - 000002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3r.dll
2018-12-11 14:16 - 2018-11-05 23:36 - 000002048 _____ (Microsoft Corporation) C:\windows\system32\tzres.dll
2018-12-11 14:16 - 2018-11-05 23:20 - 000002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\tzres.dll
2018-12-11 14:16 - 2018-10-06 11:03 - 000383720 _____ (Adobe Systems Incorporated) C:\windows\system32\atmfd.dll
2018-12-11 14:16 - 2018-10-06 10:59 - 000151552 _____ (Microsoft Corporation) C:\windows\system32\t2embed.dll
2018-12-11 14:16 - 2018-10-06 10:59 - 000041472 _____ (Microsoft Corporation) C:\windows\system32\lpk.dll
2018-12-11 14:16 - 2018-10-06 10:58 - 000100864 _____ (Microsoft Corporation) C:\windows\system32\fontsub.dll
2018-12-11 14:16 - 2018-10-06 10:58 - 000046080 _____ (Adobe Systems) C:\windows\system32\atmlib.dll
2018-12-11 14:16 - 2018-10-06 10:58 - 000014336 _____ (Microsoft Corporation) C:\windows\system32\dciman32.dll
2018-12-11 14:16 - 2018-10-06 10:50 - 000309480 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\atmfd.dll
2018-12-11 14:16 - 2018-10-06 10:44 - 000111616 _____ (Microsoft Corporation) C:\windows\SysWOW64\t2embed.dll
2018-12-11 14:16 - 2018-10-06 10:44 - 000025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\lpk.dll
2018-12-11 14:16 - 2018-10-06 10:43 - 000071680 _____ (Microsoft Corporation) C:\windows\SysWOW64\fontsub.dll
2018-12-11 14:16 - 2018-10-06 10:43 - 000010240 _____ (Microsoft Corporation) C:\windows\SysWOW64\dciman32.dll
2018-12-11 14:16 - 2018-10-06 10:16 - 000034304 _____ (Adobe Systems) C:\windows\SysWOW64\atmlib.dll
2018-12-10 02:38 - 2018-12-10 02:38 - 000000000 ____D C:\Users\Barley\AppData\Local\mbam
2018-12-10 02:37 - 2018-12-10 02:37 - 000000000 ____D C:\Users\Barley\AppData\Local\mbamtray
2018-12-10 02:37 - 2018-12-10 02:37 - 000000000 ____D C:\Program Files\Malwarebytes
2018-12-06 20:38 - 2018-12-06 20:39 - 000002403 _____ C:\Users\Barley\Desktop\Chris - Chrome.lnk
2018-12-01 08:58 - 2018-12-01 08:58 - 000110968 _____ (Oracle Corporation) C:\windows\system32\WindowsAccessBridge-64.dll
2018-12-01 08:58 - 2018-12-01 08:58 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2018-12-01 08:57 - 2018-12-01 08:57 - 000000000 ____D C:\Program Files\Java
2018-12-01 08:56 - 2018-12-01 08:57 - 074618232 _____ (Oracle Corporation) C:\Users\Barley\Downloads\jre-8u191-windows-x64.exe
2018-12-01 08:52 - 2018-12-01 08:52 - 000000954 _____ C:\Users\Barley\Downloads\Coupon_Package_CommonKindness (5).jnlp
2018-11-30 10:53 - 2018-11-30 10:53 - 000025103 _____ C:\Users\Barley\Downloads\This computer is BLOCKED.htm
2018-11-30 10:40 - 2018-11-30 10:41 - 002204152 _____ (Valassis) C:\Users\Barley\Downloads\P@H_prod308-piPSZUcb.exe
2018-11-25 12:07 - 2018-11-25 12:07 - 000000000 ____D C:\Users\Barley\AppData\Local\Nuance
2018-11-25 12:07 - 2018-11-25 12:07 - 000000000 ____D C:\Users\Barley\AppData\Local\Brother
2018-11-25 12:07 - 2018-11-25 12:07 - 000000000 ____D C:\ProgramData\Nuance
2018-11-25 11:02 - 2018-11-25 11:02 - 006796563 _____ C:\Users\Barley\Downloads\HUSB_CampFlyer_2019_v4_FINAL.pdf
2018-11-24 13:40 - 2018-11-24 13:40 - 004110943 _____ C:\Users\Barley\Downloads\all-11750417.zip
2018-11-24 13:40 - 2018-11-24 13:40 - 001219747 _____ C:\Users\Barley\Downloads\histograms.pdf
2018-11-21 01:25 - 2018-11-21 01:25 - 000000064 _____ C:\Users\Barley\Downloads\listen (10).pls
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2018-12-21 22:50 - 2012-10-07 17:22 - 000003934 _____ C:\windows\System32\Tasks\User_Feed_Synchronization-{DDA5C770-AE6C-4A93-AC90-AB64C59BEC72}
2018-12-21 22:44 - 2009-07-13 23:45 - 000024608 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-12-21 22:44 - 2009-07-13 23:45 - 000024608 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-12-21 20:55 - 2012-10-02 13:47 - 000000000 ____D C:\ProgramData\PDFC
2018-12-21 20:54 - 2009-07-14 00:08 - 000000006 ____H C:\windows\Tasks\SA.DAT
2018-12-21 16:21 - 2013-11-17 01:01 - 000000000 ____D C:\ProgramData\Malwarebytes
2018-12-21 16:11 - 2017-04-05 11:22 - 000000000 ___RD C:\Users\Barley\Dropbox
2018-12-21 16:10 - 2012-10-07 17:37 - 014843556 ____H C:\Users\Barley\AppData\Local\IconCache.db.backup
2018-12-21 16:03 - 2013-11-15 20:31 - 000000000 ____D C:\Users\Barley\AppData\Roaming\ShopAtHome.com BrowserAppCore Service
2018-12-21 00:18 - 2016-12-25 11:57 - 000008051 _____ C:\windows\BRRBCOM.INI
2018-12-19 21:15 - 2018-03-14 23:51 - 000000000 _____ C:\windows\SysWOW64\last.dump
2018-12-19 07:23 - 2017-11-20 21:50 - 000000336 _____ C:\windows\Tasks\HPCeeScheduleForBarley.job
2018-12-18 21:09 - 2012-10-07 17:26 - 000003332 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2018-12-18 21:09 - 2012-10-07 17:25 - 000003204 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
2018-12-18 20:59 - 2013-12-25 10:30 - 000003508 _____ C:\windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-632860548-1775735820-415820443-1000UA
2018-12-18 20:59 - 2013-12-25 10:30 - 000003236 _____ C:\windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-632860548-1775735820-415820443-1000Core
2018-12-18 10:51 - 2017-11-20 21:50 - 000003192 _____ C:\windows\System32\Tasks\HPCeeScheduleForBarley
2018-12-16 10:49 - 2018-11-13 09:30 - 000003236 _____ C:\windows\System32\Tasks\Norton WSC Integration
2018-12-16 10:49 - 2018-09-13 20:51 - 000000000 ____D C:\windows\System32\Tasks\AVAST Software
2018-12-16 10:49 - 2018-03-13 16:07 - 000004466 _____ C:\windows\System32\Tasks\Adobe Flash Player NPAPI Notifier
2018-12-16 10:49 - 2018-01-09 01:01 - 000003916 _____ C:\windows\System32\Tasks\Antivirus Emergency Update
2018-12-16 10:49 - 2017-08-31 23:12 - 000004478 _____ C:\windows\System32\Tasks\Adobe Flash Player PPAPI Notifier
2018-12-16 10:49 - 2017-04-15 06:34 - 000003118 _____ C:\windows\System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe
2018-12-16 10:49 - 2017-04-15 06:34 - 000003092 _____ C:\windows\System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe
2018-12-16 10:49 - 2017-04-15 06:34 - 000003090 _____ C:\windows\System32\Tasks\Microsoft_Hardware_Launch_itype_exe
2018-12-16 10:49 - 2017-04-15 06:34 - 000003062 _____ C:\windows\System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe
2018-12-16 10:49 - 2017-04-15 06:34 - 000003060 _____ C:\windows\System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe
2018-12-16 10:49 - 2016-05-24 17:44 - 000003286 _____ C:\windows\System32\Tasks\{AC99B250-78CB-4E6E-B667-70C074C519ED}
2018-12-16 10:49 - 2015-04-23 23:38 - 000004476 _____ C:\windows\System32\Tasks\Adobe Acrobat Update Task
2018-12-16 10:49 - 2015-02-03 21:08 - 000003164 _____ C:\windows\System32\Tasks\{D95529CE-E95E-447C-8D8C-4C1A622E5294}
2018-12-16 10:49 - 2013-11-15 20:31 - 000003852 _____ C:\windows\System32\Tasks\Reset ShopAtHome BAC
2018-12-16 10:49 - 2012-10-02 13:44 - 000004312 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater
2018-12-12 14:10 - 2012-10-07 17:28 - 000002226 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-12-12 08:29 - 2009-07-13 22:20 - 000000000 ____D C:\windows\rescache
2018-12-12 07:56 - 2015-04-23 23:38 - 000002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2018-12-12 07:48 - 2009-07-14 00:13 - 000782470 _____ C:\windows\system32\PerfStringBackup.INI
2018-12-12 07:48 - 2009-07-13 22:20 - 000000000 ____D C:\windows\inf
2018-12-12 07:40 - 2009-07-13 23:45 - 000332936 _____ C:\windows\system32\FNTCACHE.DAT
2018-12-12 01:28 - 2011-02-11 12:15 - 000774592 _____ C:\windows\SysWOW64\PerfStringBackup.INI
2018-12-12 01:27 - 2014-09-06 18:49 - 000000000 ____D C:\windows\system32\MRT
2018-12-12 01:23 - 2014-09-06 18:49 - 137260640 ____C (Microsoft Corporation) C:\windows\system32\MRT.exe
2018-12-10 02:37 - 2014-09-06 19:22 - 000000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2018-12-06 00:07 - 2012-10-02 13:44 - 000842240 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2018-12-06 00:07 - 2012-10-02 13:44 - 000175104 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2018-12-06 00:07 - 2012-10-02 13:44 - 000000000 ____D C:\windows\SysWOW64\Macromed
2018-12-06 00:07 - 2012-10-02 13:44 - 000000000 ____D C:\windows\system32\Macromed
2018-11-30 10:41 - 2015-04-21 08:51 - 000000000 ____D C:\Program Files (x86)\Valassis
2018-11-25 11:42 - 2017-03-23 06:44 - 000482304 ___SH C:\Users\Barley\Downloads\Thumbs.db
 
==================== Files in the root of some directories =======
 
2014-09-06 20:02 - 2014-09-06 20:02 - 000000055 _____ () C:\Users\Barley\AppData\Roaming\mbam.context.scan
2013-08-09 23:33 - 2013-08-09 23:34 - 000595302 _____ () C:\Users\Barley\AppData\Roaming\Scorch_Install.log
2015-03-31 14:37 - 2015-03-31 14:37 - 000893239 _____ () C:\Users\Barley\AppData\Local\a.zip
2015-03-31 14:37 - 2015-03-31 14:37 - 002162416 _____ (Catalina Marketing Corp) C:\Users\Barley\AppData\Local\BcsKtYcHW.dll
2012-10-08 14:16 - 2015-09-09 18:32 - 000011264 _____ () C:\Users\Barley\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
 
Some files in TEMP:
====================
2006-10-28 00:28 - 2006-10-28 00:28 - 000145184 ____R (Microsoft Corporation) C:\Users\Barley\AppData\Local\Temp\ose00000.exe
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\windows\system32\winlogon.exe => File is digitally signed
C:\windows\system32\wininit.exe => File is digitally signed
C:\windows\SysWOW64\wininit.exe => File is digitally signed
C:\windows\explorer.exe => File is digitally signed
C:\windows\SysWOW64\explorer.exe => File is digitally signed
C:\windows\system32\svchost.exe => File is digitally signed
C:\windows\SysWOW64\svchost.exe => File is digitally signed
C:\windows\system32\services.exe => File is digitally signed
C:\windows\system32\User32.dll => File is digitally signed
C:\windows\SysWOW64\User32.dll => File is digitally signed
C:\windows\system32\userinit.exe => File is digitally signed
C:\windows\SysWOW64\userinit.exe => File is digitally signed
C:\windows\system32\rpcss.dll => File is digitally signed
C:\windows\system32\dnsapi.dll => File is digitally signed
C:\windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\windows\system32\Drivers\volsnap.sys => File is digitally signed
 
LastRegBack: 2018-12-14 08:05
 
==================== End of FRST.txt ============================
 
Addition.txt
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 20.12.2018
Ran by [removed] (21-12-2018 22:55:37)
Running from C:\Users\[removed]\Desktop
Windows 7 Home Premium Service Pack 1 (X64) (2012-10-07 22:17:47)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-632860548-1775735820-415820443-500 - Administrator - Disabled)
Barley (S-1-5-21-632860548-1775735820-415820443-1000 - Administrator - Enabled) => C:\Users\Barley
Guest (S-1-5-21-632860548-1775735820-415820443-501 - Limited - Disabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: AVG Antivirus (Enabled - Up to date) {4FC75CA5-1654-5411-7CFB-1893D506BCF4}
AV: Norton Internet Security (Disabled - Out of date) {E3FDBD9F-8140-1400-F32B-8B58923F7C4D}
AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
AS: Norton Internet Security (Disabled - Out of date) {589C5C7B-A77A-1B8E-C99B-B02AE9B836F0}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG Antivirus (Enabled - Up to date) {F4A6BD41-306E-5B9F-464B-23E1AE81F649}
FW: Norton Internet Security (Disabled) {DBC63CBA-CB2F-1558-D874-226D6CEC3B36}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
4 Elements II (HKLM-x32\…\WTA-b59b7394-ad89-4e36-9b0e-246773f6f556) (Version: 2.2.0.98 - WildTangent) Hidden
64 Bit HP CIO Components Installer (HKLM\…\{55D55008-E5F6-47D6-B16F-B2A40D4D145F}) (Version: 6.2.1 - Hewlett-Packard) Hidden
Able RAWer 1.10.3.20 (HKLM-x32\…\Able RAWer_is1) (Version: 1.10.3.20 - GraphicRegion.com)
Adobe Acrobat Reader DC (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 19.010.20064 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 18.0.0.180 - Adobe Systems Incorporated)
Adobe Flash Player 32 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 32.0.0.101 - Adobe Systems Incorporated)
Adobe Flash Player 32 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 32.0.0.101 - Adobe Systems Incorporated)
Adobe Flash Player 32 PPAPI (HKLM-x32\…\Adobe Flash Player PPAPI) (Version: 32.0.0.101 - Adobe Systems Incorporated)
AIO_CDA_ProductContext (HKLM-x32\…\{2A7EF808-14F3-4E93-BE3A-1675EE5332A4}) (Version: 130.0.365.000 - Hewlett-Packard) Hidden
AIO_CDA_Software (HKLM-x32\…\{A7AEE29F-839E-46B5-B347-6D430618129F}) (Version: 130.0.365.000 - Hewlett-Packard) Hidden
AIO_Scan (HKLM-x32\…\{D86B0E2E-DF9A-441C-AF77-8D1A0FF00FA6}) (Version: 130.0.365.000 - Hewlett-Packard) Hidden
Apple Application Support (32-bit) (HKLM-x32\…\{F2871C89-C8A5-42EE-8D45-0F02506385A6}) (Version: 5.1 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\…\{9BC93467-75D1-4AA4-BD58-D9C51D88DFAB}) (Version: 5.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{55BB2110-FB43-49B3-93F4-945A0CFB0A6C}) (Version: 10.0.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.)
AVG AntiVirus FREE (HKLM-x32\…\AVG Antivirus) (Version: 18.8.3071 - AVG Technologies)
Bejeweled 3 (HKLM-x32\…\WTA-ac717e9e-48e0-49d5-b5a2-824923e38ed4) (Version: 2.2.0.98 - WildTangent) Hidden
Bing Bar (HKLM-x32\…\{3365E735-48A6-4194-9988-CE59AC5AE503}) (Version: 7.3.132.0 - Microsoft Corporation)
Blackhawk Striker 2 (HKLM-x32\…\WTA-73c3dc74-4cd1-419d-b230-d78796a73007) (Version: 2.2.0.95 - WildTangent) Hidden
Blio (HKLM-x32\…\{FCD6D60F-AF2B-49E3-ABC4-A4C96B56225D}) (Version: 3.0.9482 - K-NFB Reading Technology, Inc.)
Bonjour (HKLM\…\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
BrLauncher (HKLM-x32\…\{C661197A-6B93-4E37-9E3F-2A1DFCD64234}) (Version: 1.1.15.0 - Brother Industries Ltd.) Hidden
BrLogRx (HKLM-x32\…\{B556F816-FF4D-4BB6-9339-ED28639E2EF3}) (Version: 1.0.2.1 - Brother Industries Ltd.) Hidden
Brother PCFax Driver (HKLM-x32\…\{56BA05BD-7A67-4EF8-85A7-8C6528AEE2AC}) (Version: 1.4.0.0 - Brother Industries Ltd.) Hidden
Brother Printer Driver (HKLM-x32\…\{4A30C4EE-52AC-4A6B-A898-D484E9FAED63}) (Version: 1.5.0.0 - Brother Industries Ltd.) Hidden
Brother Scanner Driver (HKLM-x32\…\{B843B8F3-1815-4335-99F2-039AE06CAD86}) (Version: 1.0.15.10 - Brother Industries Ltd.) Hidden
BrotherHelpInstaller (HKLM-x32\…\{4E461C2A-EC1C-46D1-AF5B-7FEFD0054AF8}) (Version: 1.0.0.0 - Brother) Hidden
BrSupportTools (HKLM-x32\…\{F8F9EB58-33BA-4FF8-80E7-66D87D2E0C3C}) (Version: 1.0.9.0 - Brother Industries Ltd.) Hidden
Bubble Wrap (HKLM-x32\…\{5BFFDDEB-AFD7-499F-BB13-7A6EAD927CDA}_is1) (Version: 1.0.0.0 - XM Asia Pacific Pte Ltd)
BufferChm (HKLM-x32\…\{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}) (Version: 130.0.331.000 - Hewlett-Packard) Hidden
C6100 (HKLM-x32\…\{0DEF8C02-2EAB-4BFE-A7E0-7990665DF1A9}) (Version: 130.0.365.000 - Hewlett-Packard) Hidden
c6100_Help (HKLM-x32\…\{4BD5B5D2-406D-4bc5-BB10-2F0D1D367C95}) (Version: 82.0.256.000 - Hewlett-Packard) Hidden
Catalina Savings Printer (HKLM-x32\…\{37331C16-3E97-4A20-80D8-BFB43AB0E2FB}) (Version: 1.0.0 - Catalina Marketing Corp) <==== ATTENTION
Catalina Savings Printer (HKLM-x32\…\{4956ACE3-F537-4418-BB45-FD52395275A7}) (Version: 1.0.0 - Catalina Marketing Corp) <==== ATTENTION
ChromecastApp (HKU\S-1-5-21-632860548-1775735820-415820443-1000\…\{079ede36-133d-44b0-8053-c7c1fa8d2e0d}_is1) (Version: 1.5.1693.0 - Google Inc.)
Chuzzle Deluxe (HKLM-x32\…\WTA-350df33b-9fdb-4c58-80af-3f5a302269c2) (Version: 2.2.0.95 - WildTangent) Hidden
Cisco WebEx Meetings (HKU\S-1-5-21-632860548-1775735820-415820443-1000\…\ActiveTouchMeetingClient) (Version:  - Cisco WebEx LLC)
ControlCenter4 (HKLM-x32\…\{C5744F42-FDC4-4CC2-B4A8-47C9AA9553B4}) (Version: 4.2.435.1 - Brother Insutries Ltd.) Hidden
ControlCenter4 CSDK (HKLM-x32\…\{1BAE50D4-5F2A-4E34-BD81-B4555109F7C2}) (Version: 4.2.3.1 - Brother Insutries Ltd.) Hidden
Copy (HKLM-x32\…\{3C92B2E6-380D-4fef-B4DF-4A3B4B669771}) (Version: 130.0.428.000 - Hewlett-Packard) Hidden
Coupon Printer for Windows (HKLM-x32\…\Coupon Printer for Windows5.0.2.1) (Version: 5.0.2.1 - Coupons.com Incorporated)
CouponPrinterPlugin (HKLM-x32\…\{8AC6566B-131F-4987-82DF-932CED9FCA23}) (Version: 2.0.2.0 - Hopster) <==== ATTENTION
Cradle of Rome 2 (HKLM-x32\…\WTA-1c1f6121-da0f-4e8c-9c68-5081de00e04b) (Version: 2.2.0.98 - WildTangent) Hidden
D3DX10 (HKLM-x32\…\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden
Destinations (HKLM-x32\…\{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}) (Version: 130.0.0.0 - Hewlett-Packard) Hidden
DeviceDetect (HKLM-x32\…\{CEF07BDC-47F1-4477-8F3C-0E7132AF88C5}) (Version: 1.0.4.5 - Brother Industries Ltd.) Hidden
DeviceDiscovery (HKLM-x32\…\{2FF8C687-DB7D-4adc-A5DC-57983EC25046}) (Version: 130.0.465.000 - Hewlett-Packard) Hidden
Dietz & Watson 2015 (HKLM-x32\…\{CD6EEFE2-17F9-AC22-9223-48776E476221}) (Version: 2.5 - Koupon Media) Hidden
Dietz & Watson 2015 (HKLM-x32\…\com.kouponmedia.dietzandwatson2015) (Version: 2.5 - Koupon Media)
Digital Coupon Printer (HKLM-x32\…\{2CDD20A5-DFDE-4AC0-97DD-F60B1196BF98}) (Version: 3.50.0.0 - Hopster, Inc. an Inmar company)
DirectX for Managed Code Update (Summer 2004) (HKLM-x32\…\{E9E34215-82EF-4909-BE2F-F581F0DC9062}) (Version: 9.02.2904 - Microsoft) Hidden
DocProc (HKLM-x32\…\{9B362566-EC1B-4700-BB9C-EC661BDE2175}) (Version: 13.0.0.0 - Hewlett-Packard) Hidden
Dora's World Adventure (HKLM-x32\…\WTA-220769bc-a6cc-4095-8049-d7448f650a3e) (Version: 2.2.0.95 - WildTangent) Hidden
Dragon NaturallySpeaking 7.0 (HKLM-x32\…\{6675E71B-9843-4971-BC15-18AB52801134}) (Version: 7.00.200.409 - ScanSoft)
Elevated Installer (HKLM-x32\…\{352B1136-BF8D-4F5A-924B-43B26D05B3B5}) (Version: 2.3.17.0 - Garmin Ltd or its subsidiaries) Hidden
Escape the Emerald Star (HKLM-x32\…\WTA-424f1b8b-d37a-42ea-b226-3030d1996772) (Version: 2.2.0.98 - WildTangent) Hidden
Exact Audio Copy 1.2 (HKLM-x32\…\Exact Audio Copy) (Version: 1.2 - Andre Wiethoff)
Facebook (HKLM-x32\…\{8AE50893-3A87-4439-9A57-942ED43F7189}) (Version: 1.1.0004 - Hewlett-Packard)
Farm Frenzy (HKLM-x32\…\WTA-c81077f9-55f3-4d11-b4fe-585ad41d8209) (Version: 2.2.0.98 - WildTangent) Hidden
Farmscapes (HKLM-x32\…\WTA-ba2cfe9d-b15a-44af-87b3-25c19f580002) (Version: 2.2.0.97 - WildTangent) Hidden
FATE (HKLM-x32\…\WTA-0e36d320-14f2-4de0-88cd-beb4083d639d) (Version: 2.2.0.97 - WildTangent) Hidden
Fax (HKLM-x32\…\{440B915A-0C85-45DB-92AE-75AE14704A64}) (Version: 130.0.418.000 - Hewlett-Packard) Hidden
Final Drive Fury (HKLM-x32\…\WTA-844866d1-e9d3-40b2-a85e-666243def709) (Version: 2.2.0.95 - WildTangent) Hidden
Free YouTube To MP3 Converter (HKLM-x32\…\Free YouTube To MP3 Converter_is1) (Version: 4.1.33.119 - Digital Wave Ltd)
Garmin Express (HKLM-x32\…\{874B12CE-2C6A-4E12-AEB5-4D35CCA5270B}) (Version: 2.3.17.0 - Garmin Ltd or its subsidiaries) Hidden
Garmin Express (HKLM-x32\…\{d6f59919-3fd4-48c5-8404-def6f92d8422}) (Version: 2.3.17.0 - Garmin Ltd or its subsidiaries)
Garmin Express Tray (HKLM-x32\…\{BE770575-1FB0-47EB-A2EE-52107A023F12}) (Version: 2.3.17.0 - Garmin Ltd or its subsidiaries) Hidden
Golden Trails 2: The Lost Legacy Collector's Edition (HKLM-x32\…\WTA-a751c50d-1758-4426-8ac0-a7be901bb1c2) (Version: 2.2.0.98 - WildTangent) Hidden
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 71.0.3578.98 - Google Inc.)
Google Update Helper (HKLM-x32\…\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.23 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\…\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden
GPBaseService2 (HKLM-x32\…\{63FF21C9-A810-464F-B60A-3111747B1A6D}) (Version: 130.0.371.000 - Hewlett-Packard) Hidden
Hewlett-Packard ACLM.NET v1.2.2.3 (HKLM-x32\…\{6F340107-F9AA-47C6-B54C-C3A19F11553F}) (Version: 1.00.0000 - Hewlett-Packard Company) Hidden
HowToGuide (HKLM-x32\…\{36580EEB-4EDF-4880-BBD4-097E2C645ECD}) (Version: 1.0.1.0 - Brother Industries Ltd.) Hidden
Hoyle Card Games (HKLM-x32\…\WTA-818c6384-6cd9-4f15-8a4f-14a502345e34) (Version: 2.2.0.95 - WildTangent) Hidden
HP Application Assistant (HKLM\…\{0CE7EBAF-157D-4111-9146-057CB2A4023E}) (Version: 1.1.466.3970 - Hewlett-Packard)
HP Calendar (HKLM-x32\…\{2B38E0FA-D8A5-4EBF-A018-E3C1C8E7A2E2}) (Version: 5.1.4245.23508 - Hewlett-Packard)
HP Clock (HKLM-x32\…\{750E9D0F-B188-4A7E-ADD2-84B7ED7D32F6}) (Version: 5.1.4281.27332 - Hewlett-Packard)
HP Customer Participation Program 13.0 (HKLM\…\HPExtendedCapabilities) (Version: 13.0 - HP)
HP Easy Print (HKLM-x32\…\{37C4570C-2F39-4756-AF26-A204CEF202D6}) (Version: 1.00.0000 - HP)
HP Games (HKLM-x32\…\WildTangent hp Master Uninstall) (Version: 1.0.2.5 - WildTangent)
HP Imaging Device Functions 13.0 (HKLM\…\HP Imaging Device Functions) (Version: 13.0 - HP)
HP LinkUp (HKLM-x32\…\{7E750542-55BC-4300-8B7B-AC2A762FB435}) (Version: 2.01.029 - Hewlett-Packard)
HP Magic Canvas (HKLM-x32\…\{DDFDC9D6-4220-41F8-BF9A-8E7512C4EF52}) (Version: 5.1.15.0 - Hewlett-Packard)
HP Magic Canvas Tutorials (HKLM-x32\…\{858FCB65-7C6D-4BA4-AD80-A3CB3744CE09}_is1) (Version: 6.0.0.0 - Hewlett-Packard)
HP Notes (HKLM-x32\…\{86BAB08A-5E66-4C53-82E3-C1E91673C7CA}) (Version: 5.1.4274.30382 - Hewlett-Packard)
HP Odometer (HKLM-x32\…\{B8AC1A89-FFD1-4F97-8051-E505A160F562}) (Version: 2.10.0000 - Hewlett-Packard)
HP Photosmart All-In-One Driver Software 13.0 Rel. A (HKLM\…\{17016DA1-F040-4032-BD36-34DD317BC9D5}) (Version: 13.0 - HP)
HP Photosmart Essential 3.5 (HKLM\…\HP Photosmart Essential) (Version: 3.5 - HP)
HP RSS (HKLM-x32\…\{452479C5-0118-48E9-AA69-0A7339F95FC8}) (Version: 5.1.4289.23799 - Hewlett-Packard)
HP Setup (HKLM-x32\…\{438363A8-F486-4C37-834C-4955773CB3D3}) (Version: 9.1.15430.4033 - Hewlett-Packard Company)
HP Smart Web Printing 4.51 (HKLM\…\HP Smart Web Printing) (Version: 4.51 - HP)
HP Solution Center 13.0 (HKLM\…\HP Solution Center & Imaging Support Tools) (Version: 13.0 - HP)
HP Support Assistant (HKLM-x32\…\{61EB474B-67A6-47F4-B1B7-386851BAB3D0}) (Version: 8.7.50.3 - Hewlett-Packard Company)
HP Support Information (HKLM-x32\…\{B2B7B1C8-7C8B-476C-BE2C-049731C55992}) (Version: 11.00.0001 - Hewlett-Packard)
HP Support Solutions Framework (HKLM-x32\…\{F6A11738-3EE4-4573-AEA5-6CD5D491C167}) (Version: 12.10.49.21 - Hewlett-Packard Company)
HP Touchpoint Analytics Client (HKLM\…\{E5FB98E0-0784-44F0-8CEC-95CD4690C43F}) (Version: 4.0.2.1439 - HP Inc.)
HP TouchSmart Background - Beats (HKLM-x32\…\{6A6F8D36-04BA-41E9-9004-1789BD545874}) (Version: 1.0.1.0 - Hewlett-Packard)
HP TouchSmart RecipeBox (HKLM-x32\…\{20714B53-FC73-4F9C-9687-49EB237D6FD7}) (Version: 3.0.3830.27730 - Hewlett-Packard)
HP Update (HKLM-x32\…\{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}) (Version: 5.003.001.001 - Hewlett-Packard)
HP Weather (HKLM-x32\…\{776CC95E-8160-401B-AC79-164822AA8306}) (Version: 5.1.4245.22595 - Hewlett-Packard)
HPPhotoGadget (HKLM-x32\…\{CAE4213F-F797-439D-BD9E-79B71D115BE3}) (Version: 130.0.282.000 - Hewlett-Packard) Hidden
HPPhotoSmartDiscLabelContent1 (HKLM-x32\…\{681B698F-C997-42C3-B184-B489C6CA24C9}) (Version: 2.04.0000 - Hewlett-Packard) Hidden
HPPhotosmartEssential (HKLM-x32\…\{D79113E7-274C-470B-BD46-01B10219DF6A}) (Version: 2.04.0000 - Hewlett-Packard) Hidden
HPProductAssistant (HKLM-x32\…\{C43326F5-F135-4551-8270-7F7ABA0462E1}) (Version: 130.0.371.000 - Hewlett-Packard) Hidden
HPSSupply (HKLM-x32\…\{6B2FFB21-AC88-45C3-9A7D-4BB3E744EC91}) (Version: 130.0.371.000 - Hewlett-Packard) Hidden
iCloud (HKLM\…\{309768A4-A2BB-4930-A5A2-8169678C9B4C}) (Version: 4.0.6.28 - Apple Inc.)
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.0.0.1351 - Intel Corporation)
Intel(R) OpenCL CPU Runtime (HKLM-x32\…\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version:  - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2696 - Intel Corporation)
iTunes (HKLM\…\{554C62C7-E6BB-40F1-892B-F0AE02D3C135}) (Version: 12.5.3.17 - Apple Inc.)
Java 8 Update 191 (64-bit) (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F64180191F0}) (Version: 8.0.1910.12 - Oracle Corporation)
Jewel Match 3 (HKLM-x32\…\WTA-4660ad21-bbd2-4056-9274-17cdbb6e8a8c) (Version: 2.2.0.98 - WildTangent) Hidden
Jewel Quest Mysteries: The Seventh Gate Collector's Edition (HKLM-x32\…\WTA-6bd8460b-7dda-4a26-9e12-707c452d9b21) (Version: 2.2.0.98 - WildTangent) Hidden
John Deere Drive Green (HKLM-x32\…\WTA-5333fae1-48ca-41d7-8382-7c65262bc50c) (Version: 2.2.0.95 - WildTangent) Hidden
Junk Mail filter update (HKLM-x32\…\{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}) (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
LabelPrint (HKLM-x32\…\{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.4507 - CyberLink Corp.) Hidden
LabelPrint (HKLM-x32\…\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.4507 - CyberLink Corp.)
Luxor HD (HKLM-x32\…\WTA-7d011431-914e-437f-b7a1-ef23ab9154a0) (Version: 2.2.0.98 - WildTangent) Hidden
Mah Jong Medley (HKLM-x32\…\WTA-0fd9482b-7878-4605-8c28-19efd6521c0a) (Version: 2.2.0.95 - WildTangent) Hidden
Malwarebytes version 3.6.1.2711 (HKLM\…\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.6.1.2711 - Malwarebytes)
MarketResearch (HKLM-x32\…\{175F0111-2968-4935-8F70-33108C6A4DE3}) (Version: 130.0.374.000 - Hewlett-Packard) Hidden
Mesh Runtime (HKLM-x32\…\{8C6D6116-B724-4810-8F2D-D047E6B7D68E}) (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Metric Converter (HKLM-x32\…\{D0661463-50F7-4A1E-83CB-37CC590589AE}_is1) (Version: 1.0.0.0 - XM Asia Pacific Pte Ltd)
Microsoft .NET Framework 4.7.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.03062 - Microsoft Corporation)
Microsoft LifeCam (HKLM\…\{5CE7E3F5-9803-4F32-AA89-2D8848A80109}) (Version: 3.60.253.0 - Microsoft Corporation)
Microsoft Mathematics (HKLM-x32\…\{4D090F70-6F08-4B60-9357-A1DFD4458F09}) (Version: 4.0 - Microsoft Corporation)
Microsoft Mouse and Keyboard Center (HKLM\…\Microsoft Mouse and Keyboard Center) (Version: 2.3.188.0 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\…\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office 2010 (HKLM-x32\…\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM-x32\…\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Home and Student 2007 (HKLM-x32\…\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Zoo Tycoon (HKLM-x32\…\Zoo Tycoon 1.0) (Version:  - )
Mortimer Beckett and the Crimson Thief Premium Edition (HKLM-x32\…\WTA-7fc1033b-c678-45d5-a485-905aaf4a04e4) (Version: 2.2.0.98 - WildTangent) Hidden
Mozilla Firefox 26.0 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 26.0 (x86 en-US)) (Version: 26.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 26.0 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
My Farm Life 2 (HKLM-x32\…\WTA-3daa2b41-1b22-4cc2-838a-7a7c844442d1) (Version: 2.2.0.98 - WildTangent) Hidden
Network64 (HKLM\…\{05EFBF37-0E52-4579-875C-7EEF0DFB4FCB}) (Version: 130.0.572.000 - Hewlett-Packard) Hidden
NetworkRepairTool (HKLM-x32\…\{4694AD3E-D4A2-4D98-9848-662A0475E872}) (Version: 1.2.11.0 - Brother Insutries Ltd.) Hidden
Norton Internet Security (HKLM-x32\…\NGC) (Version: 22.16.2.22 - Symantec Corporation)
Norton Online Backup (HKLM-x32\…\{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}) (Version: 2.1.17869 - Symantec Corporation)
OCR Software by I.R.I.S. 13.0 (HKLM\…\HPOCR) (Version: 13.0 - HP)
opensource (HKLM-x32\…\{3677D4D8-E5E0-49FC-B86E-06541CF00BBE}) (Version: 1.0.14960.3876 - Your Company Name) Hidden
P@H-Protocol (HKLM-x32\…\{14F936AB-5D31-410E-A4E2-70AE504712F2}) (Version: 3.0.8.6 - Valassis)
P@H-Protocol (HKLM-x32\…\{4CFAC858-CB6F-4F5B-9BD9-4DAE8747F0E3}) (Version: 3.0.8.11 - Valassis)
P@H-Protocol (HKLM-x32\…\{A2CB3AFC-E449-408A-BF4F-FE64EB1899D8}) (Version: 3.0.8.7 - Valassis)
PC-FAXReceive (HKLM-x32\…\{DD40894F-7575-4905-90AB-695FD827E358}) (Version: 1.4.24.0 - Brother Insutries Ltd.) Hidden
PCFaxTx (HKLM-x32\…\{63530B2D-3A34-4D79-A52D-F3EB5D99A7C1}) (Version: 1.1.1.1 - Brother Industries Ltd.) Hidden
PDF Complete Corporate Edition (HKLM-x32\…\PDF Complete) (Version: 4.2.33 - PDF Complete, Inc)
Penguins! (HKLM-x32\…\WTA-c6d3fe1b-0537-4004-87f7-b2843d0833ac) (Version: 2.2.0.98 - WildTangent) Hidden
Plants vs. Zombies - Game of the Year (HKLM-x32\…\WTA-c43bee99-1714-4c3c-82e7-267367a21983) (Version: 2.2.0.98 - WildTangent) Hidden
PlayReady PC Runtime amd64 (HKLM\…\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation)
PlayReady PC Runtime x86 (HKLM-x32\…\{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}) (Version: 1.3.0 - Microsoft Corporation)
Poker Superstars III (HKLM-x32\…\WTA-ceced49d-d9ad-49da-ac4a-adcacf6cd937) (Version: 2.2.0.95 - WildTangent) Hidden
Polar Bowler (HKLM-x32\…\WTA-ad6b48d4-4aa6-49b1-b668-6005090a3c83) (Version: 2.2.0.97 - WildTangent) Hidden
Polar Golfer (HKLM-x32\…\WTA-417cc89d-18f1-44b3-90c8-0f4968fb00c2) (Version: 2.2.0.98 - WildTangent) Hidden
Power2Go (HKLM-x32\…\{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.6207 - CyberLink Corp.) Hidden
Power2Go (HKLM-x32\…\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.6207 - CyberLink Corp.)
PowerISO (HKLM-x32\…\PowerISO) (Version: 5.4 - Power Software Ltd)
Print@Home (HKLM-x32\…\{123D4082-3194-4191-9139-067E9157C2B2}) (Version: 2.0.0 - Valassis Interactive Inc.)
PrintMyCouponAnywhere (HKLM-x32\…\{9E5A9316-541D-4F22-BE19-AFE969C00B06}) (Version: 1.0.0.0 - RevTrax)
QponPrinter 1.0.1 (HKLM-x32\…\Qpon-Printer) (Version: 1.0.1 - Qples Inc)
QponPrinterV2 1.0.3 (HKLM-x32\…\Qpon-Printer-v2) (Version: 1.0.3 - Qples Inc)
Ralink 802.11n Wireless LAN Card (HKLM-x32\…\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}) (Version: 3.2.12.0 - Ralink)
Recovery Manager (HKLM-x32\…\{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}) (Version: 5.5.0.5119 - CyberLink Corp.) Hidden
Remote Graphics Receiver (HKLM-x32\…\{16FC3056-90C0-4757-8A68-64D8DA846ADA}) (Version: 5.4.5 - Hewlett-Packard)
RemoteSetup (HKLM-x32\…\{B6CE4633-EA3F-4856-9BCC-9B8702E076FE}) (Version: 3.8.0.2 - Brother Industries Ltd.) Hidden
RevTraxPrintMyCoupon (HKLM-x32\…\{19E8EBBF-55F3-41FB-AC8E-373BA0436939}) (Version: 1.0.0.0 - RevTrax)
RimhillEx 1.08 (HKU\S-1-5-21-632860548-1775735820-415820443-1000\…\RimhillEx_is1) (Version:  - the sz development)
RMNEveryday Coupon Printer (HKLM-x32\…\{08586830-7F6E-41F5-9A1C-51F7D2873631}) (Version: 3.1.0.0 - Valassis)
Roads of Rome 3 (HKLM-x32\…\WTA-0939384a-c84d-4e93-be59-7ae8b6d3e2dc) (Version: 2.2.0.98 - WildTangent) Hidden
Scan (HKLM-x32\…\{0F367CA3-3B2F-43F9-A44A-25A8EE69E45D}) (Version: 13.0.0.0 - Hewlett-Packard) Hidden
ScannerUtilityInstaller (HKLM-x32\…\{5B645FE2-19E9-4B15-B5B2-3D8766F6FA27}) (Version: 1.0.0.0 - Brother) Hidden
Secunia PSI (3.0.0.9016) (HKLM-x32\…\Secunia PSI) (Version: 3.0.0.9016 - Secunia)
Shop for HP Supplies (HKLM\…\Shop for HP Supplies) (Version: 13.0 - HP)
Sibelius Scorch (Firefox, Opera, Netscape, Chrome only) (HKLM-x32\…\{41626CC0-A854-4402-AD06-D7939515C282}) (Version: 6.2.0 - Sibelius Software, a division of Avid Technology, Inc.)
Skype™ 7.0 (HKLM-x32\…\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
SmartWebPrinting (HKLM-x32\…\{DC635845-46D3-404B-BCB1-FC4A91091AFA}) (Version: 130.0.457.000 - Hewlett-Packard) Hidden
Smilebox (HKU\S-1-5-21-632860548-1775735820-415820443-1000\…\Smilebox) (Version: 1.0.0.31741 - Smilebox, Inc.)
SolutionCenter (HKLM-x32\…\{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}) (Version: 130.0.373.000 - Hewlett-Packard) Hidden
Spot (HKLM-x32\…\{3D171340-B528-42E0-92E4-BDA7AEEF6F32}_is1) (Version: 1.0.0.0 - XM Asia Pacific Pte Ltd)
Status (HKLM-x32\…\{0EF5BEA9-B9D3-46d7-8958-FB69A0BAEACC}) (Version: 130.0.469.000 - Hewlett-Packard) Hidden
StatusMonitor (HKLM-x32\…\{86D16055-3C14-44C6-BCD7-5514B83BAD34}) (Version: 1.12.4.0 - Brother Insutries Ltd.) Hidden
Tales of Lagoona (HKLM-x32\…\WTA-75f90731-d0ef-4ead-85f3-edbfba5c6ced) (Version: 2.2.0.98 - WildTangent) Hidden
Tap Tap Bear (HKLM-x32\…\{A393CDFF-BEB8-48EA-990D-2EB35B311D23}_is1) (Version: 1.0.0.0 - XM Asia Pacific Pte Ltd)
TeamViewer 9 (HKLM-x32\…\TeamViewer 9) (Version: 9.0.32494 - TeamViewer)
TI USB 3.0 Host Controller Driver (HKLM-x32\…\InstallShield_{355FBD67-5A4F-44DA-86A1-56EEC4C20EC0}) (Version: 1.12.18.0 - Texas Instruments Inc.)
TI USB3 Host Driver (HKLM-x32\…\{355FBD67-5A4F-44DA-86A1-56EEC4C20EC0}) (Version: 1.12.18.0 - Texas Instruments Inc.) Hidden
Toolbox (HKLM-x32\…\{6BBA26E9-AB03-4FE7-831A-3535584CA002}) (Version: 130.0.648.000 - Hewlett-Packard) Hidden
Torchlight (HKLM-x32\…\WTA-3c9ded15-538a-4040-b422-610d26c7de9d) (Version: 2.2.0.98 - WildTangent) Hidden
TrayApp (HKLM-x32\…\{1EC71BFB-01A3-4239-B6AF-B1AE656B15C0}) (Version: 130.0.422.000 - Hewlett-Packard) Hidden
TSHostedAppLauncher (HKLM-x32\…\{F89BADB0-D319-470E-8024-443EE3A3402B}) (Version: 5.1.15.0 - Hewlett-Packard) Hidden
UnloadSupport (HKLM-x32\…\{4E7C28C7-D5DA-4E9F-A1CA-60490B54AE35}) (Version: 11.0.0 - Hewlett-Packard) Hidden
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\…\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
Update Installer for WildTangent Games App (HKLM-x32\…\{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App) (Version:  - WildTangent) Hidden
UsbRepairTool (HKLM-x32\…\{523276A4-5779-4105-9163-CA1CF94EC533}) (Version: 1.4.0.0 - Brother Insutries Ltd.) Hidden
Virtual Villagers 4 - The Tree of Life (HKLM-x32\…\WTA-a76813b1-d318-4c70-b481-009dabe4cb9b) (Version: 2.2.0.98 - WildTangent) Hidden
WebReg (HKLM-x32\…\{43CDF946-F5D9-4292-B006-BA0D92013021}) (Version: 130.0.132.017 - Hewlett-Packard) Hidden
WildTangent Games App (HP Games) (HKLM-x32\…\{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-hp) (Version: 4.0.5.36 - WildTangent) Hidden
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\…\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
WinZip 16.0 (HKLM\…\{CD95F661-A5C4-44F5-A6AA-ECDD91C240CD}) (Version: 16.0.9715 - WinZip Computing, S.L. )
Wondershare Helper Compact 2.5.2 (HKLM-x32\…\{5363CE84-5F09-48A1-8B6C-6BB590FFEDF2}_is1) (Version: 2.5.2 - Wondershare)
Wondershare Video Converter Ultimate(Build 9.0.1.4) (HKLM-x32\…\Wondershare Video Converter Ultimate_is1) (Version: 9.0.1.4 - Wondershare Software)
Yahoo! Toolbar (HKLM-x32\…\Yahoo! Companion) (Version:  - )
Youda Fisherman (HKLM-x32\…\WTA-cb0bd757-b714-4ced-8e65-6cdcd47c3ad9) (Version: 2.2.0.98 - WildTangent) Hidden
Zuma's Revenge (HKLM-x32\…\WTA-6a3fb242-dbd2-46cf-bf50-6031b10d212b) (Version: 2.2.0.98 - WildTangent) Hidden
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-632860548-1775735820-415820443-1000_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\Barley\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-632860548-1775735820-415820443-1000_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\Barley\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-632860548-1775735820-415820443-1000_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\Barley\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-632860548-1775735820-415820443-1000_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Barley\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-632860548-1775735820-415820443-1000_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\Barley\AppData\Local\Google\Update\1.3.24.7\psuser_64.dll => No File
ShellIconOverlayIdentifiers: [  OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\buShell.dll [2018-11-03] (Symantec Corporation)
ShellIconOverlayIdentifiers: [  OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\buShell.dll [2018-11-03] (Symantec Corporation)
ShellIconOverlayIdentifiers: [  OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\buShell.dll [2018-11-03] (Symantec Corporation)
ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ShellIconOverlayIdentifiers-x32: [  OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\buShell.dll [2018-11-03] (Symantec Corporation)
ShellIconOverlayIdentifiers-x32: [  OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\buShell.dll [2018-11-03] (Symantec Corporation)
ShellIconOverlayIdentifiers-x32: [  OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\buShell.dll [2018-11-03] (Symantec Corporation)
ContextMenuHandlers1: [AVG] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files (x86)\AVG\Antivirus\ashShA64.dll [2018-11-15] (AVG Technologies CZ, s.r.o.)
ContextMenuHandlers1: [BUContextMenu] -> {F7CAA2A1-67A2-44BB-B20F-202FD8EB1DAB} => C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\buShell.dll [2018-11-03] (Symantec Corporation)
ContextMenuHandlers1: [PhotoStreamsExt] -> {89D984B3-813B-406A-8298-118AFA3A22AE} => C:\Program Files\Common Files\Apple\Internet Services\ShellStreams64.dll [2014-11-21] (Apple Inc.)
ContextMenuHandlers1: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => C:\Program Files (x86)\PowerISO\PWRISOSH.DLL [2012-08-24] (Power Software Ltd)
ContextMenuHandlers1: [Symantec.Norton.Antivirus.IEContextMenu] -> {FAD61B3D-699D-49B2-BE16-7F82CB4C59CA} => C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\NavShExt.dll [2018-11-03] (Symantec Corporation)
ContextMenuHandlers1: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\wzshls64.dll [2012-02-16] (WinZip Computing, S.L.)
ContextMenuHandlers1: [WondershareVideoConverterFileOpreation] -> {FEB746CA-95C2-485F-B386-C30D4E56D22E} => C:\windows\SysWOW64\WSCM64.dll [2015-02-27] ()
ContextMenuHandlers2: [Symantec.Norton.Antivirus.IEContextMenu] -> {FAD61B3D-699D-49B2-BE16-7F82CB4C59CA} => C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\NavShExt.dll [2018-11-03] (Symantec Corporation)
ContextMenuHandlers3: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ContextMenuHandlers3: [LinkUpMenuExt] -> {B793E5EA-5344-488E-B98D-A18E2E5938AB} => C:\Program Files (x86)\Hewlett-Packard\HP LinkUp\LinkUpExt64.dll [2011-05-06] (Hewlett-Packard)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-09-19] (Malwarebytes)
ContextMenuHandlers4: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => C:\Program Files (x86)\PowerISO\PWRISOSH.DLL [2012-08-24] (Power Software Ltd)
ContextMenuHandlers4: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\wzshls64.dll [2012-02-16] (WinZip Computing, S.L.)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\windows\system32\igfxpph.dll [2012-04-04] (Intel Corporation)
ContextMenuHandlers6: [AVG] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files (x86)\AVG\Antivirus\ashShA64.dll [2018-11-15] (AVG Technologies CZ, s.r.o.)
ContextMenuHandlers6: [BUContextMenu] -> {F7CAA2A1-67A2-44BB-B20F-202FD8EB1DAB} => C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\buShell.dll [2018-11-03] (Symantec Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-09-19] (Malwarebytes)
ContextMenuHandlers6: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => C:\Program Files (x86)\PowerISO\PWRISOSH.DLL [2012-08-24] (Power Software Ltd)
ContextMenuHandlers6: [Symantec.Norton.Antivirus.IEContextMenu] -> {FAD61B3D-699D-49B2-BE16-7F82CB4C59CA} => C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\NavShExt.dll [2018-11-03] (Symantec Corporation)
ContextMenuHandlers6: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\wzshls64.dll [2012-02-16] (WinZip Computing, S.L.)
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {03256141-1BAE-4C9E-8D28-AED4BC1B37DE} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [2018-08-30] (HP Inc.)
Task: {0583328E-0A8D-40B9-88C1-6CBF18EF2064} - System32\Tasks\HPCeeScheduleForBarley => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2015-06-16] (Hewlett-Packard)
Task: {13CA88A1-CDA4-4585-9F11-8BC5130BC8D0} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation)
Task: {1820F1F2-07DE-4C3F-996F-0B89A5A39544} - System32\Tasks\Reset ShopAtHome BAC => C:\Users\Barley\AppData\Roaming\ShopAtHome.com BrowserAppCore Service\SahProcessManager.exe [2013-08-26] (ShopAtHome.com)
Task: {1ABD908E-44DD-46E5-93D6-F85795AE81E1} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\windows\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_101_pepper.exe [2018-12-06] (Adobe Systems Incorporated)
Task: {2AA6B539-4673-4A05-8597-E9C84EE0899E} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2014-03-19] (Microsoft)
Task: {2C5DC53C-3BB7-43CC-AA49-116AAEF51CF5} - System32\Tasks\{D95529CE-E95E-447C-8D8C-4C1A622E5294} => C:\windows\system32\pcalua.exe -a "C:\Users\Barley\Downloads\chromeinstall-8u31 (1).exe" -d C:\Users\Barley\Downloads
Task: {40CB04A3-5E27-4FFF-8F98-2069CF54D5AB} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-632860548-1775735820-415820443-1000Core => C:\Users\Barley\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {45416CB6-710F-4224-82AA-01FE4BC3D47B} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Product Configurator => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\ProductConfig.exe [2018-11-08] (HP Inc.)
Task: {4DEF5C25-BA5D-4828-98AF-FC4FBA2C55C2} - System32\Tasks\AVG\Overseer => C:\Program Files\Common Files\AVG\Overseer\overseer.exe [2018-10-28] (AVG Technologies CZ, s.r.o.)
Task: {4F04A113-09B2-4923-A098-4F9DCBB11ADA} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation)
Task: {6D07362E-868E-43E5-9482-326BF8228EB4} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\windows\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_101_Plugin.exe [2018-12-05] (Adobe Systems Incorporated)
Task: {6D49B0C9-CEF2-467A-AD36-7DB6C8FE2F99} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation)
Task: {7A479DAC-A6ED-4050-961C-372019C23B7B} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2018-12-10] (HP Inc.)
Task: {8D5865E3-B262-4FEE-BD7A-1A397D69B4EE} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {93BAAB6E-33D2-47CD-B0F4-D7C3357882E7} - System32\Tasks\Norton Internet Security\Norton Internet Security Error Analyzer => C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\SymErr.exe [2018-11-03] (Symantec Corporation)
Task: {9F9B883E-CB9B-48C3-BBF8-9C2C0E0750AC} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation)
Task: {A097D96E-83DE-42F6-BC21-28703FD90BA4} - System32\Tasks\Remediation\AntimalwareMigrationTask => C:\Program Files\Common Files\AV\Norton Internet Security\Upgrade.exe [2018-11-03] (Symantec Corporation)
Task: {A4DFCC1B-B3C7-4572-A960-FB8DA59855C5} - System32\Tasks\Antivirus Emergency Update => C:\Program Files (x86)\AVG\Antivirus\AvEmUpdate.exe [2018-11-15] (AVG Technologies CZ, s.r.o.)
Task: {AFF25087-364C-4FB3-AAC9-50F6F6E0A392} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater - Resources => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2017-09-20] (HP Inc.)
Task: {B458637F-D899-4538-BA11-2A14B1ED6A8C} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.)
Task: {BEF7C1BC-3725-43AE-B6C5-660106D31E7E} - System32\Tasks\Hewlett-Packard\HP Active Health\HP Active Health Scan (HPSA) => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.exe [2017-11-20] ()
Task: {C56A0862-A80E-4AF3-A838-7EE9E32EC86D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2018-11-09] (HP Inc.)
Task: {C7EB1FD5-AF07-496F-A6FA-1D64ED3C7ACF} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2018-08-13] (Adobe Systems Incorporated)
Task: {CCEC197E-48A7-4647-AD8D-6D177DE3402A} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-632860548-1775735820-415820443-1000UA => C:\Users\Barley\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {CF50CD1D-1E6D-4BCE-BEF5-42BAA1D3D88B} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2018-11-09] (HP Inc.)
Task: {D71AB59B-68FD-484B-A9A0-22955D183C18} - System32\Tasks\{AC99B250-78CB-4E6E-B667-70C074C519ED} => C:\windows\system32\pcalua.exe -a "C:\Users\Barley\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QC9P1FVT\JavaSetup8u91 (1).exe" -d C:\Users\Barley\Desktop
Task: {DA1CEAA8-060C-4D55-81D2-C45E1899F543} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {E25995B7-68C9-4394-B1CE-2988A5345F45} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2017-09-20] (HP Inc.)
Task: {EF88B9A7-8B01-496D-BFED-719F2A3A7981} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2018-12-10] (HP Inc.)
Task: {F2946359-CBD4-45CF-A8B0-F43C86BAACF4} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\WSCStub.exe [2018-11-03] (Symantec Corporation)
Task: {F8605A12-4EF9-4498-9431-35EDC2893E69} - System32\Tasks\Norton Internet Security\Norton Internet Security Error Processor => C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\SymErr.exe [2018-11-03] (Symantec Corporation)
Task: {FB40547D-7545-4F51-84A4-F02B26327EC3} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-12-06] (Adobe Systems Incorporated)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\windows\Tasks\HPCeeScheduleForBarley.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
 
ShortcutWithArgument: C:\Users\Barley\Desktop\Chris - Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> –profile-directory="Profile 3"
ShortcutWithArgument: C:\Users\Barley\Desktop\Erica - Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> –profile-directory="Profile 1"
ShortcutWithArgument: C:\Users\Barley\Desktop\ie11 RWW (Remote Web Workplace) Connect to Computer - Spiceworks.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  –app=hxxp://community.spiceworks.com/topic/358500-ie11-rww-remote-web-workplace-connect-to-computer
ShortcutWithArgument: C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Default\Web Applications\community.spiceworks.com\http_80\ie11 RWW (Remote Web Workplace) Connect to Computer - Spiceworks.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  –app=hxxp://community.spiceworks.com/topic/358500-ie11-rww-remote-web-workplace-connect-to-computer
ShortcutWithArgument: C:\Users\Barley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ie11 RWW (Remote Web Workplace) Connect to Computer - Spiceworks.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  –app=hxxp://community.spiceworks.com/topic/358500-ie11-rww-remote-web-workplace-connect-to-computer
ShortcutWithArgument: C:\Users\Barley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\mydlink services plugin.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  –profile-directory="Profile 1" –app-id=ldibdoepbjbkkcbgndfljnphngpglhbb
ShortcutWithArgument: C:\Users\Barley\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Erica - Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> –profile-directory="Profile 1"
ShortcutWithArgument: C:\Users\Barley\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\69639df789022856\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> –profile-directory="Profile 1"
 
==================== Loaded Modules (Whitelisted) ==============
 
2016-10-05 18:17 - 2016-10-05 18:17 - 000092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2016-10-05 18:17 - 2016-10-05 18:17 - 001353528 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2017-03-03 17:38 - 2015-02-27 14:38 - 000721263 _____ () C:\windows\SysWOW64\WSCM64.dll
2016-12-25 11:57 - 2005-04-22 13:36 - 000143360 _____ () C:\windows\system32\BrSNMP64.dll
2018-12-21 16:21 - 2018-11-21 11:07 - 002842608 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll
2018-12-21 16:21 - 2018-11-15 11:01 - 002712432 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\SelfProtectionSdk.dll
2018-11-15 20:11 - 2018-11-15 20:11 - 000724752 _____ () c:\Program Files (x86)\AVG\Antivirus\x64\StreamBack.dll
2012-04-04 21:46 - 2012-04-04 21:46 - 000094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2012-12-25 15:57 - 2011-05-26 14:14 - 000477080 _____ () C:\Users\Barley\AppData\Roaming\HP SimpleSave Application\StartHelper.exe
2015-04-30 13:43 - 2015-04-30 13:43 - 000090760 _____ () C:\Program Files (x86)\PrintMyCouponAnywhere\PrintMyCouponAnywhere.exe
2018-12-12 14:09 - 2018-12-12 00:11 - 005237216 _____ () C:\Program Files (x86)\Google\Chrome\Application\71.0.3578.98\libglesv2.dll
2018-12-12 14:09 - 2018-12-12 00:11 - 000117216 _____ () C:\Program Files (x86)\Google\Chrome\Application\71.0.3578.98\libegl.dll
2018-11-15 20:10 - 2018-11-15 20:10 - 000919312 _____ () C:\Program Files (x86)\AVG\Antivirus\anen.dll
2018-11-15 20:11 - 2018-11-15 20:11 - 000594192 _____ () C:\Program Files (x86)\AVG\Antivirus\streamback.dll
2018-12-21 15:58 - 2018-12-21 15:58 - 005734600 _____ () C:\Program Files (x86)\AVG\Antivirus\defs\18122106\algo.dll
2018-11-15 20:10 - 2018-11-15 20:10 - 000496400 _____ () C:\Program Files (x86)\AVG\Antivirus\gui_cache.dll
2018-11-15 20:10 - 2018-11-15 20:10 - 001112336 _____ () C:\Program Files (x86)\AVG\Antivirus\shepherdsync.dll
2016-10-29 23:32 - 2016-10-27 11:13 - 000114664 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\zlib1.dll
2016-10-29 23:32 - 2017-01-20 07:51 - 000108008 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\boost_filesystem-vc120-mt-1_56.dll
2016-10-29 23:32 - 2017-01-20 07:51 - 000024040 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\boost_system-vc120-mt-1_56.dll
2016-10-29 23:32 - 2017-01-20 07:51 - 000048104 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\boost_date_time-vc120-mt-1_56.dll
2018-03-13 10:22 - 2018-03-13 10:22 - 067127976 _____ () C:\Program Files (x86)\AVG\Antivirus\libcef.dll
2009-02-27 16:38 - 2009-02-27 16:38 - 000139264 _____ () C:\Program Files (x86)\Brother\BrUtilities\BrLogAPI.dll
2017-03-03 17:39 - 2016-10-08 16:48 - 001506304 _____ () C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\DAQExp.dll
2017-03-03 17:39 - 2016-07-21 10:54 - 000137728 _____ () C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\CBSCreateVC.dll
2016-10-05 18:18 - 2016-10-05 18:18 - 001041720 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2016-10-05 18:18 - 2016-10-05 18:18 - 000080184 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE trusted site: HKU\S-1-5-21-632860548-1775735820-415820443-1000\…\sjhnh.org -> hxxps://gateway1.sjhnh.org
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-13 21:34 - 2018-12-21 16:19 - 000000884 _____ C:\windows\system32\Drivers\etc\hosts
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-632860548-1775735820-415820443-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Barley\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 8.8.8.8 - 8.8.4.4
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
If an entry is included in the fixlist, it will be removed.
 
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk => C:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
MSCONFIG\startupreg: ApnTBMon => "C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe"
MSCONFIG\startupreg: ApnUpdater => "C:\Program Files (x86)\Ask.com\Updater\Updater.exe"
MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: BeatsOSDApp => C:\Program Files\IDT\WDM\beats64.exe
MSCONFIG\startupreg: BrowserAppCoreService => C:\Users\Barley\AppData\Roaming\ShopAtHome.com BrowserAppCore Service\SahProcessManager.exe "C:\Users\Barley\AppData\Roaming\ShopAtHome.com BrowserAppCore Service\ShopAtHome_BAC_Service.exe" "restart"
MSCONFIG\startupreg: DNS7reminder => "C:\Program Files (x86)\ScanSoft\NaturallySpeaking\Program\Ereg.exe" -r "C:\Program Files (x86)\ScanSoft\NaturallySpeaking\Program\ereg.ini"
MSCONFIG\startupreg: HP Software Update => c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: LifeCam => "C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe"
MSCONFIG\startupreg: Norton Online Backup => C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
MSCONFIG\startupreg: PWRISOVM.EXE => C:\Program Files (x86)\PowerISO\PWRISOVM.EXE -startup
MSCONFIG\startupreg: SearchSettings => "C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe"
MSCONFIG\startupreg: SysTrayApp => C:\Program Files\IDT\WDM\sttray64.exe
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{C40D9B13-61A2-4285-A4E7-E26BB14A390D}] => (Allow) C:\Program Files (x86)\Ralink\Common\RaMediaServer.exe
FirewallRules: [{8E66A095-795E-494F-8F39-F583A6C355AE}] => (Allow) C:\Program Files (x86)\Ralink\Common\RaMediaServer.exe
FirewallRules: [{64D8B223-4FDB-4856-984E-D6A313D081AC}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Remote Graphics Receiver\rgreceiver.exe
FirewallRules: [{46D3AD7D-F0D3-4B5B-A87A-8A74DD670C45}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Remote Graphics Receiver\rgreceiver.exe
FirewallRules: [{096CA7E4-26E4-4D3F-BCE6-8B421C198BB6}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\HP LinkUp\HP LinkUp Viewer.exe
FirewallRules: [{62DA04C4-6D00-4D4D-83D7-0C35250D69CD}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\HP LinkUp\HP LinkUp Viewer.exe
FirewallRules: [{77D34678-43F1-4822-B594-6E09D82214B1}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{368B141D-50B1-4EE3-9F97-6978FEC3BCA7}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{748AC05F-6DAF-4DDA-B7F8-49F3BAC6092C}] => (Allow) LPort=2869
FirewallRules: [{1A056468-B541-45F9-9F3B-9DE4103860F9}] => (Allow) LPort=1900
FirewallRules: [{47F869E4-237F-428A-87B2-B24C77087D97}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{083D86A3-2137-4A0F-A1FD-6C5139F7A6D9}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
FirewallRules: [{3C757619-EA6B-4395-B7C1-7FD9D82913A0}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeCam.exe
FirewallRules: [{337898BF-4E6C-4F28-B6FF-F4E0103C7088}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeCam.exe
FirewallRules: [{72660C52-6CAD-426B-8480-9A4CCDA25FDE}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeEnC2.exe
FirewallRules: [{A7ED8D1C-7DC5-4254-9A3C-7210F65BCA23}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeEnC2.exe
FirewallRules: [{FC12E3B7-37DB-40F2-8007-7CDBA8F98DA1}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe
FirewallRules: [{F8F68A5A-37F7-458F-A223-6EDFBEB178CF}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe
FirewallRules: [{29DFB764-4E0E-4C7F-8E63-04BEEB9E85E5}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeTray.exe
FirewallRules: [{6DFF213C-2E9D-40B4-93A0-96C6D06DBDBF}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeTray.exe
FirewallRules: [{16F9FFA7-DE34-4195-8889-99836EA872DE}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{188D6962-81EE-44A5-8C30-3730334E748F}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{9DF14B61-33D7-4600-A2DC-8B67E3D34687}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{C02B03BE-C660-42B9-AF20-FE8402B12E27}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{5A8A4694-318C-49DA-8D92-1AA400543BFA}] => (Allow) C:\Users\Barley\AppData\Local\Temp\7zS0550\HPDiagnosticCoreUI.exe
FirewallRules: [{760435D3-CC33-43A2-9A1D-FBDBB5B55989}] => (Allow) C:\Users\Barley\AppData\Local\Temp\7zS0550\HPDiagnosticCoreUI.exe
FirewallRules: [{21507A6E-B592-4771-9515-41CD4F76BE31}] => (Allow) C:\Users\Barley\AppData\Local\Temp\7zS0674\hppiw.exe
FirewallRules: [{EC201312-D027-458B-ACC9-84594303EBF1}] => (Allow) C:\Users\Barley\AppData\Local\Temp\7zS0674\hppiw.exe
FirewallRules: [{47BD5BDD-CD2C-4B46-8AF5-342D9FE7C3AE}] => (Allow) C:\Users\Barley\AppData\Local\Temp\7zS7B67\setup\hpznui40.exe
FirewallRules: [{1E46AAC8-F6F9-4A9E-80D6-C952FCBA08A4}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
FirewallRules: [{C803B594-7DEF-49DD-B2B1-190FC1E5BDF0}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe
FirewallRules: [{E2A974B2-9D33-4747-A3E5-A6E3DB73D7A1}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpofxm08.exe
FirewallRules: [{B847FD57-37DB-41C1-B8EE-F834959F0586}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposfx08.exe
FirewallRules: [{2BC6FC16-2643-4675-8DA0-D440DAAB07D3}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposid01.exe
FirewallRules: [{2E5B1FB9-CD88-4C24-BCCA-1B1C98E43CF1}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqkygrp.exe
FirewallRules: [{971D0E46-D0B7-4B59-A6F8-5474F692BAFC}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcopy2.exe
FirewallRules: [{BED31218-45AD-43F9-9FC9-381AE7CBE610}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpfccopy.exe
FirewallRules: [{2FC88A0B-5EB8-45B5-AEBA-CDA2C66C54B6}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpzwiz01.exe
FirewallRules: [{371C863F-1809-44C4-8001-AC3E16BC8CC9}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpoews01.exe
FirewallRules: [{AA1AED5A-88F8-45FE-BEBC-F85163E1DB67}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqnrs08.exe
FirewallRules: [{C9A77EEA-40C1-4D8F-8DA8-4E74A52A3F2A}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpiscnapp.exe
FirewallRules: [{766360E0-0271-47DC-9292-260B4AF19224}] => (Allow) C:\Program Files (x86)\common files\hp\digital imaging\bin\hpqphotocrm.exe
FirewallRules: [{FBECA0C4-4012-4779-9914-18054013DF61}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqsudi.exe
FirewallRules: [{B51D41D8-9002-424B-96AE-995272DF678E}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqpsapp.exe
FirewallRules: [{FD780D56-F9B3-4CAA-9DFE-753F355A2B42}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpofxs08.exe
FirewallRules: [{EF53A754-678A-4A38-A8F1-2CA43185FD29}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqfxt08.exe
FirewallRules: [{37A40D7C-152E-4165-9107-66247F5ECEE8}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqpse.exe
FirewallRules: [{3A9268B3-2F0B-4490-8182-A74DFB16F9A1}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgplgtupl.exe
FirewallRules: [{62364A33-C195-4DAB-87F8-D01F2F09A8B4}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
FirewallRules: [{A33F9CEA-E81D-4C74-87BF-B40CE8544101}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgm.exe
FirewallRules: [{57303010-2E61-4E65-8DE8-0FD8771F2010}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgh.exe
FirewallRules: [{B5492CC8-06DF-47E8-8D6D-082A6BD1DF53}] => (Allow) C:\Program Files (x86)\HP\hp software update\hpwucli.exe
FirewallRules: [{6D422CBB-1201-4676-A036-95969E82F3FE}] => (Allow) C:\Program Files (x86)\HP\digital imaging\smart web printing\smartwebprintexe.exe
FirewallRules: [{95B36E8C-2368-4802-8747-86A3CFCD50AA}] => (Allow) C:\Program Files (x86)\Constant Guard Protection Suite\IDVault.exe
FirewallRules: [{3ED30955-EFF3-4107-8BE4-689FCE621E0B}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
FirewallRules: [{E0E4ABAD-93C0-4E6E-A0A0-A4A561496784}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
FirewallRules: [{BD69C17B-9FC9-4912-A2C1-3AE23478EB2E}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
FirewallRules: [{44605B2D-69D2-45FD-968A-081B858ACCBF}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
FirewallRules: [{C2C9770A-7C1C-476C-8FC5-311F31302F7E}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPDeviceDetection3.exe
FirewallRules: [{3B192164-7E8C-45B2-BD99-7D5DD3E627DF}] => (Allow) C:\Users\Barley\AppData\Local\Temp\7zS6C7F.tmp\autorun.exe
FirewallRules: [{10CC073E-D975-4DCF-AC50-BE23ADDABD17}] => (Allow) LPort=15600
FirewallRules: [{4243050D-CF14-483C-945D-B517D4B8E297}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{6807B6A1-AAC1-4555-8EA4-D9633E4A34B6}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{402DF736-0E3F-482F-813A-1E0EFF713B0E}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{F613D847-4755-4F67-9E83-CA8D9D16A333}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{524FBD36-AFE4-4D69-ACC6-FBAFA6255D9C}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{B497A808-16EF-4A4D-9A0B-B40E7343890A}] => (Allow) E:\Install\wlan_wiz\.\wlan_assistant\waw.exe
FirewallRules: [{316051F7-DEE7-47A6-B06C-7130CBFECE25}] => (Allow) LPort=54925
FirewallRules: [{3355062F-82C4-416B-BD10-2077C5EE5B54}] => (Allow) c:\program files (x86)\pc-faxreceive\brengineprocess.exe
FirewallRules: [{42C4E2DF-128F-46EF-80AB-44DB8071AB7F}] => (Allow) c:\program files (x86)\pc-faxreceive\brengineprocess.exe
FirewallRules: [{AE566146-EE91-4B46-A6C3-741877219C69}] => (Allow) C:\Program Files (x86)\AVG\Antivirus\AvEmUpdate.exe
FirewallRules: [{AB4720B2-A03A-4E60-B06D-CE71795B241E}] => (Allow) C:\Program Files (x86)\AVG\Antivirus\AvEmUpdate.exe
FirewallRules: [{5D6943E6-0633-4C12-8E44-B632FFD15340}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
==================== Restore Points =========================
 
12-12-2018 01:19:01 Windows Update
21-12-2018 01:12:55 Windows Update
 
==================== Faulty Device Manager Devices =============
 
Name: Photosmart C6100 series
Description: Photosmart C6100 series
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
 
Name: Photosmart C6100 series
Description: Photosmart C6100 series
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
 
Name: Photosmart C6100 series
Description: Photosmart C6100 series
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
 
Name: Photosmart C6100 series
Description: Photosmart C6100 series
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
 
Name: Photosmart C6100 series
Description: Photosmart C6100 series
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
 
Name: Photosmart C6100 series
Description: Photosmart C6100 series
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
 
Name: AntiLog32
Description: AntiLog32
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer: 
Service: AntiLog32
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
 
Name: Photosmart C6100 series
Description: Photosmart C6100 series
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
 
Name: Photosmart C6100 series
Description: Photosmart C6100 series
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
 
Name: Photosmart C6100 series
Description: Photosmart C6100 series
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
 
Name: Photosmart C6100 series
Description: Photosmart C6100 series
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (12/21/2018 10:33:08 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program aswMBR.exe version 1.0.1.2252 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
 
Process ID: 1c34
 
Start Time: 01d499a6ffb3ae09
 
Termination Time: 2
 
Application Path: C:\Users\Barley\Desktop\aswMBR.exe
 
Report Id: 49dfc6dd-059a-11e9-962c-24be05218274
 
Error: (12/20/2018 11:39:43 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: mbamservice.exe, version: 3.2.0.704, time stamp: 0x5b9acf90
Faulting module name: ntdll.dll, version: 6.1.7601.24308, time stamp: 0x5be8601e
Exception code: 0xc0000005
Fault offset: 0x0000000000032b04
Faulting process id: 0x1468
Faulting application start time: 0x01d498e473a5f40f
Faulting application path: C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe
Faulting module path: C:\windows\SYSTEM32\ntdll.dll
Report Id: 6f60daa2-04da-11e9-b7b1-24be05218274
 
Error: (12/18/2018 08:10:01 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 80746
 
Error: (12/18/2018 08:10:01 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 80746
 
Error: (12/18/2018 08:10:01 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
 
Error: (12/18/2018 08:09:43 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 62385
 
Error: (12/18/2018 08:09:43 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 62385
 
Error: (12/18/2018 08:09:43 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
 
 
System errors:
=============
Error: (12/21/2018 09:12:39 PM) (Source: BROWSER) (EventID: 8032) (User: )
Description: The browser service has failed to retrieve the backup list too many times on transport \Device\NetBT_Tcpip_{D3EED012-4886-4C2D-8491-DD153D715076}.
The backup browser is stopping.
 
Error: (12/21/2018 08:54:55 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Ralink UPnP Media Server service to connect.
 
Error: (12/21/2018 04:03:00 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: The server {E60687F7-01A1-40AA-86AC-DB1CBF673334} did not register with DCOM within the required timeout.
 
Error: (12/21/2018 04:02:52 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: The Windows Update service hung on starting.
 
Error: (12/21/2018 03:57:24 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Ralink UPnP Media Server service to connect.
 
Error: (12/20/2018 11:47:34 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: The Windows Update service hung on starting.
 
Error: (12/20/2018 11:42:08 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Ralink UPnP Media Server service to connect.
 
Error: (12/20/2018 11:25:26 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: The Windows Update service hung on starting.
 
 
CodeIntegrity:
===================================
 
Date: 2013-01-24 07:41:06.474
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
Date: 2013-01-24 07:41:06.456
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
==================== Memory info =========================== 
 
Processor: Intel(R) Core(TM) i3-2120 CPU @ 3.30GHz
Percentage of memory in use: 66%
Total physical RAM: 6030.01 MB
Available physical RAM: 2007.07 MB
Total Virtual: 12058.17 MB
Available Virtual: 7447.55 MB
 
==================== Drives ================================
 
Drive c: (OS) (Fixed) (Total:914.75 GB) (Free:753.23 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive d: (HP_RECOVERY) (Fixed) (Total:16.54 GB) (Free:2.06 GB) NTFS
 
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: C88C1F6D)
 
Partition: GPT.
 
==================== End of Addition.txt ============================
I found both AVG\Antivirus and Norton Internet Security on the computer.
Both appear to be running at the same time which is kinda bad news. Norton itself at times can be a resources hog with AVG having it's own issues over system slow downs.
Using 2 antivirus Causes conflicts, negatively impacting the effectiveness of each Anti-Virus installed.
Trigger false-positives.
Trigger false-negatives, where neither programme detects malware.
Cause system instability/performance issues. Your system may lock up or slow down due to both software attempting to access the same file at the same time.

With some of the items I found in your logs I'm surprised to see you were able to download them and they remain workable.

Make a decision which to keep and which one to uninstall,

****

Located in your Add/Remove programs list, the below needs to be deleted/uninstalled.

Catalina Savings Printer (HKLM-x32\…\{37331C16-3E97-4A20-80D8-BFB43AB0E2FB}) (Version: 1.0.0 - Catalina Marketing Corp) <==== ATTENTION
Catalina Savings Printer (HKLM-x32\…\{4956ACE3-F537-4418-BB45-FD52395275A7}) (Version: 1.0.0 - Catalina Marketing Corp) <==== ATTENTION
CouponPrinterPlugin (HKLM-x32\…\{8AC6566B-131F-4987-82DF-932CED9FCA23}) (Version: 2.0.2.0 - Hopster) <==== ATTENTION



**

Start Farbar Recovery Scan Tool with Administrator privileges
(Right click on the FRST icon and select Run as administrator)

highlight on the text below and select Copy.
beginning with Start:: and finishing with End::
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Highlight the entire content of the quote box below and select Copy.

 

Start::
CloseProcesses:
CreateRestorePoint:
C:\Program Files (x86)\Digital Coupon Printer\DigitalCouponPrinter.exe
C:\Program Files (x86)\Digital Coupon Printer
C:\Users\Barley\AppData\Roaming\ShopAtHome.com BrowserAppCore Service\ShopAtHome_BAC_Service.exe
C:\Users\Barley\AppData\Roaming\ShopAtHome.com BrowserAppCore Service
HKLM-x32\…\Run: [Digital Coupon Print Driver] => C:\Program Files (x86)\Digital Coupon Printer\DigitalCouponPrinter.exe [90048 2015-09-22] (Inmar, Inc.)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.coupons.com/
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPDTDF&pc=HPDTDF&src=IE-SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPDTDF&pc=HPDTDF&src=IE-SearchBox
SearchScopes: HKLM -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/711-30572-11896-1/4?mpre=hxxp://www.ebay.com/sch/i.html?_nkw={searchTerms}
SearchScopes: HKLM -> {F8E29CD1-3CFA-4356-AB1F-1E4764BF30F5} URL = hxxp://www.amazon.com/s/ref=azs_osd_iea?ie=UTF-8&tag=hp-us1-vsb-20&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope value is missing
SearchScopes: HKLM-x32 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/711-30572-11896-1/4?mpre=hxxp://www.ebay.com/sch/i.html?_nkw={searchTerms}
SearchScopes: HKU\S-1-5-21-632860548-1775735820-415820443-1000 -> {B3B3A6AC-74EC-BD56-BCDB-EFA4799FB9DF} URL = hxxps://www.amazon.com/gp/bit/amazonserp/ref=bit_bds-p10_serp_ie_us_display?ie=UTF8&tagbase=bds-p10&tbrId=v1_abb-channel-10_d088afc8_1201_1401_20160524_US_ie_ds_&tag=bds-p10-serp-us-ie-20&query={searchTerms}
SearchScopes: HKU\S-1-5-21-632860548-1775735820-415820443-1000 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL =
BHO: Bing Bar Helper -> {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} -> C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll [2014-03-11] (Microsoft Corporation.)
BHO: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_191\bin\ssv.dll [2018-12-01] (Oracle Corporation)
BHO-x32: Bing Bar Helper -> {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} -> C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll [2014-03-11] (Microsoft Corporation.)
BHO-x32: SingleInstance Class -> {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} -> C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll [2008-07-28] (Yahoo! Inc)
Toolbar: HKLM-x32 - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll [2014-03-11] (Microsoft Corporation.)
Handler: WSWSVCUchrome - {1CA93FF0-A218-44F1 - No File
CHR HomePage: Profile 1 -> hxxp://www.search.ask.com/?gct=hp
R2 HPSLPSVC; C:\Users\Barley\AppData\Local\Temp\7zS0674\hpslpsvc64.dll [1039360 2012-08-27] (Hewlett-Packard Co.) [File not signed] <==== ATTENTION
U3 aswMBR; \??\C:\Users\Barley\AppData\Local\Temp\aswMBR.sys [X] <==== ATTENTION
U3 aswVmm; \??\C:\Users\Barley\AppData\Local\Temp\aswVmm.sys [X] <==== ATTENTION
2006-10-28 00:28 - 2006-10-28 00:28 - 000145184 ____R (Microsoft Corporation) C:\Users\Barley\AppData\Local\Temp\ose00000.exe
CustomCLSID: HKU\S-1-5-21-632860548-1775735820-415820443-1000_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\Barley\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-632860548-1775735820-415820443-1000_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\Barley\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-632860548-1775735820-415820443-1000_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\Barley\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-632860548-1775735820-415820443-1000_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Barley\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-632860548-1775735820-415820443-1000_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\Barley\AppData\Local\Google\Update\1.3.24.7\psuser_64.dll => No File
ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
Task: {1820F1F2-07DE-4C3F-996F-0B89A5A39544} - System32\Tasks\Reset ShopAtHome BAC => C:\Users\Barley\AppData\Roaming\ShopAtHome.com BrowserAppCore Service\SahProcessManager.exe [2013-08-26] (ShopAtHome.com)
Task: {D71AB59B-68FD-484B-A9A0-22955D183C18} - System32\Tasks\{AC99B250-78CB-4E6E-B667-70C074C519ED} => C:\windows\system32\pcalua.exe -a "C:\Users\Barley\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QC9P1FVT\JavaSetup8u91 (1).exe" -d C:\Users\Barley\Desktop
ShortcutWithArgument: C:\Users\Barley\Desktop\Chris - Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> –profile-directory="Profile 3"
ShortcutWithArgument: C:\Users\Barley\Desktop\Erica - Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> –profile-directory="Profile 1"
ShortcutWithArgument: C:\Users\Barley\Desktop\ie11 RWW (Remote Web Workplace) Connect to Computer - Spiceworks.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> –app=hxxp://community.spiceworks.com/topic/358500-ie11-rww-remote-web-workplace-connect-to-computer
ShortcutWithArgument: C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Default\Web Applications\community.spiceworks.com\http_80\ie11 RWW (Remote Web Workplace) Connect to Computer - Spiceworks.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> –app=hxxp://community.spiceworks.com/topic/358500-ie11-rww-remote-web-workplace-connect-to-computer
ShortcutWithArgument: C:\Users\Barley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ie11 RWW (Remote Web Workplace) Connect to Computer - Spiceworks.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> –app=hxxp://community.spiceworks.com/topic/358500-ie11-rww-remote-web-workplace-connect-to-computer
ShortcutWithArgument: C:\Users\Barley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\mydlink services plugin.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> –profile-directory="Profile 1" –app-id=ldibdoepbjbkkcbgndfljnphngpglhbb
ShortcutWithArgument: C:\Users\Barley\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Erica - Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> –profile-directory="Profile 1"
ShortcutWithArgument: C:\Users\Barley\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\69639df789022856\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> –profile-directory="Profile 1"
C:\Windows\Temp\*.*
Emptytemp:
End::



Start FRST (FRST64) with Administrator privileges
Press the Fix button. FRST will process the lines copied above from the clipboard.
When finished, a log file Fixlog.txt will pop up and saved in the same location the tool was ran from.

Please copy and paste its contents in your next reply.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

[external image: zcMPezJ.png]AdwCleaner - Fix Mode
  • Download AdwCleaner and move it to your Desktop
  • Right-click on AdwCleaner.exe and select [external image: Spcusrh.png]Run as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users)
  • Accept the EULA (I accept), then click on Scan
  • Let the scan complete. Once it's done, make sure that every item listed in the different tabs is checked and click on the Clean & Repair button. This will kill all the active processes
  • Once the cleaning process is complete, AdwCleaner will ask to restart your computer, do it
  • After the restart, a log will open when logging in. Please copy/paste the content of that log in your next reply
*******
[external image: RQKuhw1.png]RogueKiller
  • Download the right version of RogueKiller for your Windows version (32 or 64-bit)
  • Once done, move the executable file to your Desktop, right-click on it and select [external image: Spcusrh.png]Run as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users)
  • Click on the Start Scan button in the right panel, which will bring you to another tab, and click on it again (this time it'll be in the bottom right corner)
  • Wait for the scan to complete
  • On completion, the results will be displayed
  • Check every single entry (threat found), and click on the Remove Selected button
  • On completion, the results will be displayed. Click on the Open Report button in the bottom left corner, followed by the Open TXT button (also in the bottom left corner)
  • This will open the report in Notepad. Copy/paste its content in your next reply
*****
created by Aura


Please post these 3 logs when finished.

Thanks for the fast reply.

     I deleted 2 out of 3 of the Coupon printing things, but it wouldn't let me delete the 2nd Catalina Savings Printer one.

 I'll delete the Norton package for now and leave AVG running, but was thinking of deleting that as well, and splurging for the BitDefender Security package as I think I've had some issues with hackers, etc - not sure if you can comment on that but is that a reasonable thing to do once we get the computer cleaned up, or if you have other programs you prefer I'd be open to suggestions.

   Also, one other thing I didn't mention about the computer, is that when I start it up with the power button, instead of going to the Windows logo thing like it should, it goes to a black screen w/ white letters where I have to press enter to "Start Windows normally" or some similar screen - not sure if that means anything, but it didn't do that until a few days ago.

  

   I hope I did the scans correctly, the 3 you asked for are pasted below.

 

  Thanks so much again.

 

Fixlog.txt

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 20.12.2018
Ran by [removed] (22-12-2018 11:13:14) Run:1
Running from C:\Users\[removed]\Desktop
[removed]
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
CloseProcesses:
CreateRestorePoint:
C:\Program Files (x86)\Digital Coupon Printer\DigitalCouponPrinter.exe
C:\Program Files (x86)\Digital Coupon Printer
C:\Users\Barley\AppData\Roaming\ShopAtHome.com BrowserAppCore Service\ShopAtHome_BAC_Service.exe
C:\Users\Barley\AppData\Roaming\ShopAtHome.com BrowserAppCore Service
HKLM-x32\…\Run: [Digital Coupon Print Driver] => C:\Program Files (x86)\Digital Coupon Printer\DigitalCouponPrinter.exe [90048 2015-09-22] (Inmar, Inc.)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.coupons.com/
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPDTDF&pc=HPDTDF&src=IE-SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPDTDF&pc=HPDTDF&src=IE-SearchBox
SearchScopes: HKLM -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/711-30572-11896-1/4?mpre=hxxp://www.ebay.com/sch/i.html?_nkw={searchTerms}
SearchScopes: HKLM -> {F8E29CD1-3CFA-4356-AB1F-1E4764BF30F5} URL = hxxp://www.amazon.com/s/ref=azs_osd_iea?ie=UTF-8&tag=hp-us1-vsb-20&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope value is missing
SearchScopes: HKLM-x32 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/711-30572-11896-1/4?mpre=hxxp://www.ebay.com/sch/i.html?_nkw={searchTerms}
SearchScopes: HKU\S-1-5-21-632860548-1775735820-415820443-1000 -> {B3B3A6AC-74EC-BD56-BCDB-EFA4799FB9DF} URL = hxxps://www.amazon.com/gp/bit/amazonserp/ref=bit_bds-p10_serp_ie_us_display?ie=UTF8&tagbase=bds-p10&tbrId=v1_abb-channel-10_d088afc8_1201_1401_20160524_US_ie_ds_&tag=bds-p10-serp-us-ie-20&query={searchTerms}
SearchScopes: HKU\S-1-5-21-632860548-1775735820-415820443-1000 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL =
BHO: Bing Bar Helper -> {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} -> C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll [2014-03-11] (Microsoft Corporation.)
BHO: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_191\bin\ssv.dll [2018-12-01] (Oracle Corporation)
BHO-x32: Bing Bar Helper -> {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} -> C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll [2014-03-11] (Microsoft Corporation.)
BHO-x32: SingleInstance Class -> {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} -> C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll [2008-07-28] (Yahoo! Inc)
Toolbar: HKLM-x32 - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll [2014-03-11] (Microsoft Corporation.)
Handler: WSWSVCUchrome - {1CA93FF0-A218-44F1 - No File
CHR HomePage: Profile 1 -> hxxp://www.search.ask.com/?gct=hp
R2 HPSLPSVC; C:\Users\Barley\AppData\Local\Temp\7zS0674\hpslpsvc64.dll [1039360 2012-08-27] (Hewlett-Packard Co.) [File not signed] <==== ATTENTION
U3 aswMBR; \??\C:\Users\Barley\AppData\Local\Temp\aswMBR.sys [X] <==== ATTENTION
U3 aswVmm; \??\C:\Users\Barley\AppData\Local\Temp\aswVmm.sys [X] <==== ATTENTION
2006-10-28 00:28 - 2006-10-28 00:28 - 000145184 ____R (Microsoft Corporation) C:\Users\Barley\AppData\Local\Temp\ose00000.exe
CustomCLSID: HKU\S-1-5-21-632860548-1775735820-415820443-1000_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\Barley\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-632860548-1775735820-415820443-1000_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\Barley\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-632860548-1775735820-415820443-1000_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\Barley\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-632860548-1775735820-415820443-1000_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Barley\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-632860548-1775735820-415820443-1000_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\Barley\AppData\Local\Google\Update\1.3.24.7\psuser_64.dll => No File
ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
Task: {1820F1F2-07DE-4C3F-996F-0B89A5A39544} - System32\Tasks\Reset ShopAtHome BAC => C:\Users\Barley\AppData\Roaming\ShopAtHome.com BrowserAppCore Service\SahProcessManager.exe [2013-08-26] (ShopAtHome.com)
Task: {D71AB59B-68FD-484B-A9A0-22955D183C18} - System32\Tasks\{AC99B250-78CB-4E6E-B667-70C074C519ED} => C:\windows\system32\pcalua.exe -a "C:\Users\Barley\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QC9P1FVT\JavaSetup8u91 (1).exe" -d C:\Users\Barley\Desktop
ShortcutWithArgument: C:\Users\Barley\Desktop\Chris - Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> –profile-directory="Profile 3"
ShortcutWithArgument: C:\Users\Barley\Desktop\Erica - Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> –profile-directory="Profile 1"
ShortcutWithArgument: C:\Users\Barley\Desktop\ie11 RWW (Remote Web Workplace) Connect to Computer - Spiceworks.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> –app=hxxp://community.spiceworks.com/topic/358500-ie11-rww-remote-web-workplace-connect-to-computer
ShortcutWithArgument: C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Default\Web Applications\community.spiceworks.com\http_80\ie11 RWW (Remote Web Workplace) Connect to Computer - Spiceworks.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> –app=hxxp://community.spiceworks.com/topic/358500-ie11-rww-remote-web-workplace-connect-to-computer
ShortcutWithArgument: C:\Users\Barley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ie11 RWW (Remote Web Workplace) Connect to Computer - Spiceworks.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> –app=hxxp://community.spiceworks.com/topic/358500-ie11-rww-remote-web-workplace-connect-to-computer
ShortcutWithArgument: C:\Users\Barley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\mydlink services plugin.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> –profile-directory="Profile 1" –app-id=ldibdoepbjbkkcbgndfljnphngpglhbb
ShortcutWithArgument: C:\Users\Barley\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Erica - Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> –profile-directory="Profile 1"
ShortcutWithArgument: C:\Users\Barley\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\69639df789022856\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> –profile-directory="Profile 1"
C:\Windows\Temp\*.*
Emptytemp:
 
*****************
 
Processes closed successfully.
Restore point was successfully created.
C:\Program Files (x86)\Digital Coupon Printer\DigitalCouponPrinter.exe => moved successfully
C:\Program Files (x86)\Digital Coupon Printer => moved successfully
C:\Users\Barley\AppData\Roaming\ShopAtHome.com BrowserAppCore Service\ShopAtHome_BAC_Service.exe => moved successfully
C:\Users\Barley\AppData\Roaming\ShopAtHome.com BrowserAppCore Service => moved successfully
"HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Digital Coupon Print Driver" => removed successfully
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender => removed successfully
HKLM\SOFTWARE\Policies\Google => removed successfully
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => removed successfully
HKLM\Software\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => not found
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC} => removed successfully
HKLM\Software\Classes\CLSID\{D944BB61-2E34-4DBF-A683-47E505C587DC} => not found
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{F8E29CD1-3CFA-4356-AB1F-1E4764BF30F5} => removed successfully
HKLM\Software\Classes\CLSID\{F8E29CD1-3CFA-4356-AB1F-1E4764BF30F5} => not found
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC} => removed successfully
HKLM\Software\Wow6432Node\Classes\CLSID\{D944BB61-2E34-4DBF-A683-47E505C587DC} => not found
HKU\S-1-5-21-632860548-1775735820-415820443-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B3B3A6AC-74EC-BD56-BCDB-EFA4799FB9DF} => removed successfully
HKLM\Software\Classes\CLSID\{B3B3A6AC-74EC-BD56-BCDB-EFA4799FB9DF} => not found
HKU\S-1-5-21-632860548-1775735820-415820443-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC} => removed successfully
HKLM\Software\Classes\CLSID\{D944BB61-2E34-4DBF-A683-47E505C587DC} => not found
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1dad3af3-ef2f-4f64-ac4b-11789189fcb6} => removed successfully
HKLM\Software\Classes\CLSID\{1dad3af3-ef2f-4f64-ac4b-11789189fcb6} => removed successfully
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} => removed successfully
HKLM\Software\Classes\CLSID\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} => removed successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1dad3af3-ef2f-4f64-ac4b-11789189fcb6} => removed successfully
HKLM\Software\Wow6432Node\Classes\CLSID\{1dad3af3-ef2f-4f64-ac4b-11789189fcb6} => removed successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} => removed successfully
HKLM\Software\Wow6432Node\Classes\CLSID\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} => removed successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{eec0f710-38b5-4aba-99bf-ec87564a4e13}" => removed successfully
HKLM\Software\Wow6432Node\Classes\CLSID\{eec0f710-38b5-4aba-99bf-ec87564a4e13} => removed successfully
HKLM\Software\Classes\PROTOCOLS\Handler\WSWSVCUchrome => removed successfully
"Chrome HomePage" => removed successfully
HPSLPSVC => Service stopped successfully.
HKLM\System\CurrentControlSet\Services\HPSLPSVC => removed successfully
HPSLPSVC => service removed successfully
aswMBR => service not found.
aswVmm => service not found.
C:\Users\Barley\AppData\Local\Temp\ose00000.exe => moved successfully
HKU\S-1-5-21-632860548-1775735820-415820443-1000_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208} => removed successfully
HKU\S-1-5-21-632860548-1775735820-415820443-1000_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1} => removed successfully
HKU\S-1-5-21-632860548-1775735820-415820443-1000_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8} => removed successfully
HKU\S-1-5-21-632860548-1775735820-415820443-1000_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F} => removed successfully
HKU\S-1-5-21-632860548-1775735820-415820443-1000_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E} => removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avg => removed successfully
HKLM\Software\Classes\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => not found
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1820F1F2-07DE-4C3F-996F-0B89A5A39544}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1820F1F2-07DE-4C3F-996F-0B89A5A39544}" => removed successfully
C:\windows\System32\Tasks\Reset ShopAtHome BAC => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Reset ShopAtHome BAC" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D71AB59B-68FD-484B-A9A0-22955D183C18}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D71AB59B-68FD-484B-A9A0-22955D183C18}" => removed successfully
C:\windows\System32\Tasks\{AC99B250-78CB-4E6E-B667-70C074C519ED} => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{AC99B250-78CB-4E6E-B667-70C074C519ED}" => removed successfully
C:\Users\Barley\Desktop\Chris - Chrome.lnk => Shortcut argument removed successfully
C:\Users\Barley\Desktop\Erica - Chrome.lnk => Shortcut argument removed successfully
C:\Users\Barley\Desktop\ie11 RWW (Remote Web Workplace) Connect to Computer - Spiceworks.lnk => Shortcut argument removed successfully
C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Default\Web Applications\community.spiceworks.com\http_80\ie11 RWW (Remote Web Workplace) Connect to Computer - Spiceworks.lnk => Shortcut argument removed successfully
C:\Users\Barley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ie11 RWW (Remote Web Workplace) Connect to Computer - Spiceworks.lnk => Shortcut argument removed successfully
C:\Users\Barley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\mydlink services plugin.lnk => Shortcut argument removed successfully
C:\Users\Barley\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Erica - Chrome.lnk => Shortcut argument removed successfully
C:\Users\Barley\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\69639df789022856\Google Chrome.lnk => Shortcut argument removed successfully
 
=========== "C:\Windows\Temp\*.*" ==========
 
C:\Windows\Temp\AdobeARM.log => moved successfully
C:\Windows\Temp\AdobeARM_NotLocked.log => moved successfully
C:\Windows\Temp\ArmUI.ini => moved successfully
C:\Windows\Temp\ASPNETSetup_00000.log => moved successfully
C:\Windows\Temp\ASPNETSetup_00001.log => moved successfully
C:\Windows\Temp\ASPNETSetup_00002.log => moved successfully
C:\Windows\Temp\ASPNETSetup_00003.log => moved successfully
C:\Windows\Temp\BROMJ885DW.INI => moved successfully
C:\Windows\Temp\chrome_installer.log => moved successfully
C:\Windows\Temp\contentDATs.exe => moved successfully
C:\Windows\Temp\dd_NDP46-KB4459942-x64_decompression_log.txt => moved successfully
C:\Windows\Temp\dd_ndp46-kb4470640-x64_decompression_log.txt => moved successfully
C:\Windows\Temp\dd_wcf_CA_smci_20181115_060542_453.txt => moved successfully
C:\Windows\Temp\dd_wcf_CA_smci_20181115_060546_275.txt => moved successfully
C:\Windows\Temp\dd_wcf_CA_smci_20181212_062746_046.txt => moved successfully
C:\Windows\Temp\dd_wcf_CA_smci_20181212_062749_447.txt => moved successfully
C:\Windows\Temp\FXSAPIDebugLogFile.txt => moved successfully
C:\Windows\Temp\FXSTIFFDebugLogFile.txt => moved successfully
C:\Windows\Temp\hpqddsvc.log => moved successfully
C:\Windows\Temp\HPSLPSVC0000.log => moved successfully
C:\Windows\Temp\HPSLPSVC0001.log => moved successfully
C:\Windows\Temp\HPSLPSVC0002.log => moved successfully
C:\Windows\Temp\HPSLPSVC0003.log => moved successfully
C:\Windows\Temp\HPSLPSVC0004.log => moved successfully
C:\Windows\Temp\HPSLPSVC0005.log => moved successfully
C:\Windows\Temp\HPSLPSVC0006.log => moved successfully
C:\Windows\Temp\HPSLPSVC0007.log => moved successfully
C:\Windows\Temp\HPSLPSVC0008.log => moved successfully
C:\Windows\Temp\HPSLPSVC0009.log => moved successfully
C:\Windows\Temp\HPSLPSVC0010.log => moved successfully
C:\Windows\Temp\HPSLPSVC0011.log => moved successfully
C:\Windows\Temp\HPSLPSVC0012.log => moved successfully
C:\Windows\Temp\HPSLPSVC0013.log => moved successfully
C:\Windows\Temp\HPSLPSVC0014.log => moved successfully
C:\Windows\Temp\HPSLPSVC0015.log => moved successfully
C:\Windows\Temp\HPSLPSVC0016.log => moved successfully
C:\Windows\Temp\HPSLPSVC0017.log => moved successfully
C:\Windows\Temp\HPSLPSVC0018.log => moved successfully
C:\Windows\Temp\HPSLPSVC0019.log => moved successfully
C:\Windows\Temp\HPSLPSVC0020.log => moved successfully
C:\Windows\Temp\HPSLPSVC0021.log => moved successfully
C:\Windows\Temp\HPSLPSVC0022.log => moved successfully
C:\Windows\Temp\HPSLPSVC0023.log => moved successfully
C:\Windows\Temp\HPSLPSVC0024.log => moved successfully
C:\Windows\Temp\HPSLPSVC0025.log => moved successfully
C:\Windows\Temp\HPSLPSVC0026.log => moved successfully
C:\Windows\Temp\HPSLPSVC0027.log => moved successfully
C:\Windows\Temp\HPSLPSVC0028.log => moved successfully
C:\Windows\Temp\HPSLPSVC0029.log => moved successfully
C:\Windows\Temp\HPSLPSVC0030.log => moved successfully
C:\Windows\Temp\HPSLPSVC0031.log => moved successfully
C:\Windows\Temp\HPSLPSVC0032.log => moved successfully
C:\Windows\Temp\HPSLPSVC0033.log => moved successfully
C:\Windows\Temp\HPSLPSVC0034.log => moved successfully
C:\Windows\Temp\HPSLPSVC0035.log => moved successfully
C:\Windows\Temp\HPSLPSVC0036.log => moved successfully
C:\Windows\Temp\HPSLPSVC0037.log => moved successfully
C:\Windows\Temp\HPSLPSVC0038.log => moved successfully
C:\Windows\Temp\HPSLPSVC0039.log => moved successfully
C:\Windows\Temp\HPSLPSVC0040.log => moved successfully
C:\Windows\Temp\HPSLPSVC0041.log => moved successfully
C:\Windows\Temp\HPSLPSVC0042.log => moved successfully
C:\Windows\Temp\HPSLPSVC0043.log => moved successfully
C:\Windows\Temp\HPSLPSVC0044.log => moved successfully
C:\Windows\Temp\HPSLPSVC0045.log => moved successfully
C:\Windows\Temp\HPSLPSVC0046.log => moved successfully
C:\Windows\Temp\HPSLPSVC0047.log => moved successfully
C:\Windows\Temp\HPSLPSVC0048.log => moved successfully
C:\Windows\Temp\HPSLPSVC0049.log => moved successfully
C:\Windows\Temp\HPSLPSVC0050.log => moved successfully
C:\Windows\Temp\HPSLPSVC0051.log => moved successfully
C:\Windows\Temp\HPSLPSVC0052.log => moved successfully
C:\Windows\Temp\HPSLPSVC0053.log => moved successfully
C:\Windows\Temp\HPSLPSVC0054.log => moved successfully
C:\Windows\Temp\HPSLPSVC0055.log => moved successfully
C:\Windows\Temp\HPSLPSVC0056.log => moved successfully
C:\Windows\Temp\HPSLPSVC0057.log => moved successfully
C:\Windows\Temp\HPSLPSVC0058.log => moved successfully
C:\Windows\Temp\HPSLPSVC0059.log => moved successfully
C:\Windows\Temp\HPSLPSVC0060.log => moved successfully
C:\Windows\Temp\HPSLPSVC0061.log => moved successfully
C:\Windows\Temp\HPSLPSVC0062.log => moved successfully
C:\Windows\Temp\HPSLPSVC0063.log => moved successfully
C:\Windows\Temp\HPSLPSVC0064.log => moved successfully
C:\Windows\Temp\HPSLPSVC0065.log => moved successfully
C:\Windows\Temp\HPSLPSVC0066.log => moved successfully
C:\Windows\Temp\HPSLPSVC0067.log => moved successfully
C:\Windows\Temp\HPSLPSVC0068.log => moved successfully
C:\Windows\Temp\HPSLPSVC0069.log => moved successfully
C:\Windows\Temp\HPSLPSVC0070.log => moved successfully
C:\Windows\Temp\HPSLPSVC0071.log => moved successfully
C:\Windows\Temp\HPSLPSVC0072.log => moved successfully
C:\Windows\Temp\HPSLPSVC0073.log => moved successfully
C:\Windows\Temp\KB4459942_20181115_010516635-Microsoft .NET Framework 4.7.2-MSP0.txt => moved successfully
C:\Windows\Temp\KB4459942_20181115_010516635.html => moved successfully
C:\Windows\Temp\KB4470640_20181212_012719978-Microsoft .NET Framework 4.7.2-MSP0.txt => moved successfully
C:\Windows\Temp\KB4470640_20181212_012719978.html => moved successfully
C:\Windows\Temp\Log.IntelligentUpdater.txt => moved successfully
C:\Windows\Temp\OutofProcReport36947032.txt => moved successfully
C:\Windows\Temp\patch.js => moved successfully
C:\Windows\Temp\RGI1B6A.tmp => moved successfully
C:\Windows\Temp\RGI1B6A.tmp-tmp => moved successfully
C:\Windows\Temp\RGI70FF.tmp => moved successfully
C:\Windows\Temp\RGI70FF.tmp-tmp => moved successfully
C:\Windows\Temp\SecurityScan_Release.exe => moved successfully
C:\Windows\Temp\SYMEVENT.LOG => moved successfully
C:\Windows\Temp\TFR7104.tmp => moved successfully
C:\Windows\Temp\TFRC007.tmp => moved successfully
C:\Windows\Temp\tmp13DD.tmp => moved successfully
C:\Windows\Temp\tmp2BB1.tmp => moved successfully
C:\Windows\Temp\tmp36A.tmp => moved successfully
C:\Windows\Temp\tmp450A.tmp => moved successfully
C:\Windows\Temp\tmp4604.tmp => moved successfully
C:\Windows\Temp\tmp6325.tmp => moved successfully
C:\Windows\Temp\tmp7280.tmp => moved successfully
C:\Windows\Temp\tmpB66.tmp => moved successfully
 
========= End -> "C:\Windows\Temp\*.*" ========
 
 
=========== EmptyTemp: ==========
 
BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 23764205 B
Java, Flash, Steam htmlcache => 2418 B
Windows/system/drivers => 91905026 B
Edge => 0 B
Chrome => 1194315806 B
Firefox => 19070001 B
Opera => 0 B
 
Temp, IE cache, history, cookies, recent:
Users => 0 B
Default => 0 B
Public => 0 B
ProgramData => 0 B
systemprofile => 65718486 B
systemprofile32 => 198412 B
LocalService => 16512 B
NetworkService => 26708 B
Barley => 497487657 B
 
RecycleBin => 2582 B
EmptyTemp: => 1.8 GB temporary data Removed.
 
================================
 
 
The system needed a reboot.
 

 

==== End of Fixlog 11:16:25 ====

 

 

AdwCleaner

 

# ——————————-
# Malwarebytes AdwCleaner 7.2.6.0
# ——————————-
# Build:    12-18-2018
# Database: 2018-12-21.2 (Cloud)
# Support:  https://www.malwarebytes.com/support
#
# ——————————-
# Mode: Clean
# ——————————-
# Start:    12-22-2018
# Duration: 00:00:12
# OS:       Windows 7 Home Premium
# Cleaned:  274
# Failed:   12
 
 
***** [ Services ] *****
 
No malicious services cleaned.
 
***** [ Folders ] *****
 
Deleted       C:\Program Files (x86)\PrintMyCouponAnywhere
Deleted       C:\Program Files (x86)\Yahoo!\Companion
Deleted       C:\Users\Barley\AppData\Roaming\Yahoo!\Companion
Deleted       C:\ProgramData\Yahoo! Companion
Deleted       C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Application Updater
Deleted       C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Coupons
Deleted       C:\Program Files (x86)\Coupons
Deleted       C:\ProgramData\apn
 
***** [ Files ] *****
 
Deleted       C:\Program Files (x86)\Yahoo!\Common\unyt.exe
 
***** [ DLL ] *****
 
No malicious DLLs cleaned.
 
***** [ WMI ] *****
 
No malicious WMI cleaned.
 
***** [ Shortcuts ] *****
 
No malicious shortcuts cleaned.
 
***** [ Tasks ] *****
 
No malicious tasks cleaned.
 
***** [ Registry ] *****
 
Deleted       HKCU\Software\Classes\Software\APPDATALOW\SOFTWARE\AMAZON\Amazon1ButtonApp
Deleted       HKLM\Software\Wow6432Node\AppDataLow\Software\Amazon\AmazonAssistant
Deleted       HKLM\Software\Wow6432Node\Classes\AppID\AmazonAppIE.dll
Deleted       HKLM\SOFTWARE\Classes\AppID\AmazonAppIE.dll
Deleted       HKLM\Software\Wow6432Node\Classes\Interface\{571139B2-8D93-4B29-9AA9-496EF27D6AF8}
Deleted       HKLM\Software\Classes\Interface\{571139B2-8D93-4B29-9AA9-496EF27D6AF8}
Deleted       HKLM\Software\Wow6432Node\Classes\Interface\{BFF94CF8-2D3B-4B2F-BB83-3600280AFEBA}
Deleted       HKLM\Software\Wow6432Node\Classes\Interface\{6B7479D5-C493-40F0-99B6-BFC901980034}
Deleted       HKLM\Software\Wow6432Node\Classes\Interface\{3268A00F-D329-42E1-ABF0-E78D5656BA2A}
Deleted       HKLM\Software\Classes\Interface\{3268A00F-D329-42E1-ABF0-E78D5656BA2A}
Deleted       HKLM\Software\Wow6432Node\Classes\TypeLib\{55B621F9-BAE8-4CF7-9D76-1DB25CD95850}
Deleted       HKLM\Software\Classes\TypeLib\{55B621F9-BAE8-4CF7-9D76-1DB25CD95850}
Deleted       HKLM\Software\Wow6432Node\Classes\AppID\{F18AE3C4-D2AD-42AC-9282-509DCF035D06}
Deleted       HKLM\Software\Classes\AppID\{F18AE3C4-D2AD-42AC-9282-509DCF035D06}
Deleted       HKLM\System\CurrentControlSet\Services\EventLog\Application\Amazon Assistant Service
Deleted       HKLM\Software\Microsoft\Shared Tools\MSConfig\startupreg\SearchSettings
Deleted       HKLM\Software\Microsoft\Shared Tools\MSConfig\startupreg\BrowserAppCoreService
Deleted       HKLM\Software\Microsoft\Shared Tools\MSConfig\startupreg\ApnTBMon
Deleted       HKLM\Software\Microsoft\Shared Tools\MSConfig\startupreg\ApnUpdater
Deleted       HKCU\Software\Yahoo\YFriendsBar
Deleted       HKCU\Software\AppDataLow\Software\Yahoo\Companion
Deleted       HKCU\Software\Yahoo\Companion
Deleted       HKLM\Software\Wow6432Node\Yahoo\Companion
Deleted       HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! Toolbar
Deleted       HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! Companion
Deleted       HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8DF9A1AC557F56c49B56F6B83E293C15
Deleted       HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3DCCCD6BD02558446B24CF1C63EC213C
Deleted       HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\68E4BF4B11615E03C97732FD581AB607
Deleted       HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3CDF313E9B28c944FBC7579CF4949414
Deleted       HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\158D6D9E3FE81fa428925F22ACB3A965
Deleted       HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\00E944CB89111313EAF35A0553F547F9
Deleted       HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7AB5857A57A0687786597A857BFFFFFF
Deleted       HKLM\Software\Classes\Installer\UpgradeCodes\7AB5857A57A0687786597A857BFFFFFF
Deleted       HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BCDA179D619B91648538E3394CAC94CC
Deleted       HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8CBC85D72B148084ABE8C2F072F781F4
Deleted       HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2251BF05A2F606d43BB064BD63CBD87E
Deleted       HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8CC5A38A64D6098468BC8395BA0EFF03
Deleted       HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B08932C78B697C244BE7BA3E6FF09B62
Deleted       HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\754590DD06DE8d249B526503432F99D4
Deleted       HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D14A7F65792054F418578C78367D13F7
Deleted       HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F0390A76D28822743A68D7F1AB22E6D0
Deleted       HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\22468B0D6050b2e46B9C4B67A8F59577
Deleted       HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D2A425F4453535D205547A857BC0C110
Deleted       HKLM\Software\Classes\Installer\Products\D2A425F4453535D205547A857BC0C110
Deleted       HKLM\Software\Classes\Installer\Features\D2A425F4453535D205547A857BC0C110
Deleted       HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\53F55AF3F4049ED3FA6EA6F88E414E24
Deleted       HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FB1E44269B58F433A8C8E671E37CFDCF
Deleted       HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B4E78E12704AFCE408C7FBE501F1AA0A
Deleted       HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\97ECFF59EE08D4F47BB1464DEC37DA87
Deleted       HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\71E54748EDD3dc1468548785DC856EDA
Deleted       HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F739A19A8327dc64C9A8B641A9E89646
Deleted       HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\89BB7852687BDC34B9A81E01C7FF9173
Deleted       HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\15E6C514FEFC09f45BAFAAE1D7546ED4
Deleted       HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AF6CE16AFEA5C9A39B766468A8B35C21
Deleted       HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0A5AC497E6BBC8D45BE8AD6619DA8217
Deleted       HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DFE9F0BD163D827438CB6AD6B100EC48
Deleted       HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1DB42320A8525634AA089F0BEC86473B
Deleted       HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\49D4375FE41653242AEA4C969E4E65E0
Deleted       HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3255D95681398614190EDF0A4F3F77DB
Deleted       HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CFA51B44D54927c4E9B7BC1D3FD1E49F
Deleted       HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\89EA4F1B8FBCDEF47AE328E455E28AA0
Deleted       HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C6A54B56C58C82a4688AFB93F42EA17B
Deleted       HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A97C590397DCC454AA8923563BAB10E4
Deleted       HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A8CB937199A57E748B6AC433DA453EE2
Deleted       HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8036C72171EF4ba46856BF57969F6A36
Deleted       HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E12F736682067FDE4D1158D5940A82E
Deleted       HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1A24B5BB8521B03E0C8D908F5ABC0AE6
Deleted       HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\922525DCC5199162F8935747CA3D8E59
Deleted       HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E36E114A0EAD2AD46B381D23AD69CDDF
Deleted       HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D677B1A9671D4D4004F6F2A4469E86EA
Deleted       HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EF8E618DB3AEDFBB384561B5C548F65E
Deleted       HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8CE3DDAB2D152683FBCEB4866BCD2B0F
Deleted       HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2B0D56C4F4C46D844A57FFED6F0D2852
Deleted       HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6AA0923513360135B272E8289C5F13FA
Deleted       HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DD1402A9DD4215A43ABDE169A41AFA0E
Deleted       HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\98FD652EB4839214E97B69DD8EEA1D29
Deleted       HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6F7467AF8F29C134CBBAB394ECCFDE96
Deleted       HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components\{981b174d-7733-4e7f-b89d-6545a7c21838}
Deleted       HKLM\Software\Wow6432Node\Classes\AppID\YTSingleInstance.DLL
Deleted       HKLM\SOFTWARE\Classes\AppID\YTSingleInstance.DLL
Deleted       HKLM\Software\Wow6432Node\Classes\AppID\YTNavAssist.DLL
Deleted       HKLM\SOFTWARE\Classes\AppID\YTNavAssist.DLL
Deleted       HKLM\Software\Wow6432Node\Classes\AppID\YTMsgr.DLL
Deleted       HKLM\SOFTWARE\Classes\AppID\YTMsgr.DLL
Deleted       HKLM\Software\Wow6432Node\Classes\AppID\YTBM.DLL
Deleted       HKLM\SOFTWARE\Classes\AppID\YTBM.DLL
Deleted       HKLM\Software\Wow6432Node\Classes\AppID\ytbbroker.EXE
Deleted       HKLM\SOFTWARE\Classes\AppID\ytbbroker.EXE
Deleted       HKLM\Software\Wow6432Node\Classes\AppID\YTabBar.DLL
Deleted       HKLM\SOFTWARE\Classes\AppID\YTabBar.DLL
Deleted       HKLM\Software\Wow6432Node\Classes\AppID\yt.DLL
Deleted       HKLM\SOFTWARE\Classes\AppID\yt.DLL
Deleted       HKLM\Software\Wow6432Node\Classes\AppID\YPUBC.DLL
Deleted       HKLM\SOFTWARE\Classes\AppID\YPUBC.DLL
Deleted       HKLM\Software\Wow6432Node\Classes\AppID\YCAPlugin.DLL
Deleted       HKLM\SOFTWARE\Classes\AppID\YCAPlugin.DLL
Deleted       HKLM\Software\Wow6432Node\Google\Chrome\NativeMessagingHosts\com.apn.native_messaging_host_aaaaaiabcopkplhgaedhbloeejhhankf
Deleted       HKLM\SOFTWARE\Google\Chrome\NativeMessagingHosts\com.apn.native_messaging_host_aaaaaiabcopkplhgaedhbloeejhhankf
Deleted       HKLM\Software\Wow6432Node\Google\Chrome\NativeMessagingHosts\com.apn.native_messaging_host_aaaaahaeginbdcckocjkhbciadcafnep
Deleted       HKLM\SOFTWARE\Google\Chrome\NativeMessagingHosts\com.apn.native_messaging_host_aaaaahaeginbdcckocjkhbciadcafnep
Deleted       HKLM\Software\Wow6432Node\Google\Chrome\NativeMessagingHosts\com.apn.native_messaging_host_aaaaahlfahldnilidgnlikdckbfehhca
Deleted       HKLM\SOFTWARE\Google\Chrome\NativeMessagingHosts\com.apn.native_messaging_host_aaaaahlfahldnilidgnlikdckbfehhca
Deleted       HKLM\Software\Wow6432Node\Classes\AppID\YMERemote.DLL
Deleted       HKLM\SOFTWARE\Classes\AppID\YMERemote.DLL
Deleted       HKLM\Software\Wow6432Node\Classes\AppID\TbHelper.EXE
Deleted       HKLM\SOFTWARE\Classes\AppID\TbHelper.EXE
Deleted       HKLM\Software\Wow6432Node\Classes\AppID\TbCommonUtils.DLL
Deleted       HKLM\SOFTWARE\Classes\AppID\TbCommonUtils.DLL
Deleted       HKLM\Software\Wow6432Node\Classes\TypeLib\{EB2BEAEF-150C-4DE4-9D09-F16403C22769}
Deleted       HKLM\Software\Classes\TypeLib\{EB2BEAEF-150C-4DE4-9D09-F16403C22769}
Deleted       HKLM\Software\Wow6432Node\Classes\CLSID\{E4ADC61E-D06A-4E0E-8582-78C809CC8450}
Deleted       HKLM\Software\Classes\CLSID\{E4ADC61E-D06A-4E0E-8582-78C809CC8450}
Deleted       HKLM\Software\Wow6432Node\Classes\CLSID\{6EB4349D-4333-442F-ACA4-4C72AF28B6ED}
Deleted       HKLM\Software\Wow6432Node\Classes\CLSID\{6557DB6C-EFE1-45AC-92A6-FBB1554B7502}
Deleted       HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BD6ECB00-7C4A-4F97-B425-44117F2A7AAE}
Deleted       HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BD6ECB00-7C4A-4F97-B425-44117F2A7AAE}
Deleted       HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BD6ECB00-7C4A-4F97-B425-44117F2A7AAE}
Deleted       HKLM\Software\Wow6432Node\Classes\CLSID\{BD6ECB00-7C4A-4F97-B425-44117F2A7AAE}
Deleted       HKLM\Software\Classes\CLSID\{BD6ECB00-7C4A-4F97-B425-44117F2A7AAE}
Deleted       HKLM\Software\Wow6432Node\Classes\CLSID\{BAC72C85-CEC6-4B86-AF06-FA20C259FAB8}
Deleted       HKLM\Software\Classes\CLSID\{BAC72C85-CEC6-4B86-AF06-FA20C259FAB8}
Deleted       HKLM\Software\Wow6432Node\Classes\AppID\{7F46C358-270D-4791-A579-AD1DDA1A3F7B}
Deleted       HKLM\Software\Classes\AppID\{7F46C358-270D-4791-A579-AD1DDA1A3F7B}
Deleted       HKLM\Software\Wow6432Node\Classes\Interface\{F56ACA29-1C99-40F1-AC64-2E44C4F6BC71}
Deleted       HKLM\Software\Classes\Interface\{F56ACA29-1C99-40F1-AC64-2E44C4F6BC71}
Deleted       HKLM\Software\Wow6432Node\Classes\Interface\{DF522774-8CA0-4B15-A93A-5F61AB95DA1C}
Deleted       HKLM\Software\Classes\Interface\{DF522774-8CA0-4B15-A93A-5F61AB95DA1C}
Deleted       HKLM\Software\Wow6432Node\Classes\Interface\{D13DC65C-C77B-4986-9078-DEA3D34C71BB}
Deleted       HKLM\Software\Classes\Interface\{D13DC65C-C77B-4986-9078-DEA3D34C71BB}
Deleted       HKLM\Software\Wow6432Node\Classes\Interface\{B1E712C4-03AA-495F-B0F5-0F057E126E2A}
Deleted       HKLM\Software\Classes\Interface\{B1E712C4-03AA-495F-B0F5-0F057E126E2A}
Deleted       HKLM\Software\Wow6432Node\Classes\Interface\{B09E015A-4D4E-4F8D-A436-95E19140947D}
Deleted       HKLM\Software\Classes\Interface\{B09E015A-4D4E-4F8D-A436-95E19140947D}
Deleted       HKLM\Software\Wow6432Node\Classes\Interface\{A310B105-FB7D-4497-A7E8-E046462B012F}
Deleted       HKLM\Software\Classes\Interface\{A310B105-FB7D-4497-A7E8-E046462B012F}
Deleted       HKLM\Software\Wow6432Node\Classes\Interface\{863FCF5D-DC39-4DA9-AF32-CB0025990EEE}
Deleted       HKLM\Software\Classes\Interface\{863FCF5D-DC39-4DA9-AF32-CB0025990EEE}
Deleted       HKLM\Software\Wow6432Node\Classes\Interface\{7207E52B-821E-4C05-A8D6-2965B2BE77CF}
Deleted       HKLM\Software\Classes\Interface\{7207E52B-821E-4C05-A8D6-2965B2BE77CF}
Deleted       HKLM\Software\Wow6432Node\Classes\Interface\{686D40BC-FA43-4317-8474-E634E6B487F2}
Deleted       HKLM\Software\Classes\Interface\{686D40BC-FA43-4317-8474-E634E6B487F2}
Deleted       HKLM\Software\Wow6432Node\Classes\Interface\{67E5E37C-E6B8-4782-877D-E9437C4CD982}
Deleted       HKLM\Software\Classes\Interface\{67E5E37C-E6B8-4782-877D-E9437C4CD982}
Deleted       HKLM\Software\Wow6432Node\Classes\Interface\{63B73044-FC1A-4FE1-991B-FDBD4CDAA868}
Deleted       HKLM\Software\Classes\Interface\{63B73044-FC1A-4FE1-991B-FDBD4CDAA868}
Deleted       HKLM\Software\Wow6432Node\Classes\Interface\{49F018EE-F362-4B5B-8EC8-BCF9246ABF21}
Deleted       HKLM\Software\Classes\Interface\{49F018EE-F362-4B5B-8EC8-BCF9246ABF21}
Deleted       HKLM\Software\Wow6432Node\Classes\Interface\{3D592FCB-FEFD-43A6-9A4F-BDE2D4607D07}
Deleted       HKLM\Software\Classes\Interface\{3D592FCB-FEFD-43A6-9A4F-BDE2D4607D07}
Deleted       HKLM\Software\Wow6432Node\Classes\Interface\{38552F25-8DED-4206-BB21-041EF53328F9}
Deleted       HKLM\Software\Classes\Interface\{38552F25-8DED-4206-BB21-041EF53328F9}
Deleted       HKLM\Software\Wow6432Node\Classes\Interface\{367BD1CD-74A3-451F-B1A4-6A2DE4129A2D}
Deleted       HKLM\Software\Classes\Interface\{367BD1CD-74A3-451F-B1A4-6A2DE4129A2D}
Deleted       HKLM\Software\Wow6432Node\Classes\Interface\{2FCB4E7E-E5C7-4D07-BB2C-78DF2DA867AD}
Deleted       HKLM\Software\Classes\Interface\{2FCB4E7E-E5C7-4D07-BB2C-78DF2DA867AD}
Deleted       HKLM\Software\Wow6432Node\Classes\Interface\{29E3319C-4B3C-479F-8692-BDD2CA30BEDD}
Deleted       HKLM\Software\Classes\Interface\{29E3319C-4B3C-479F-8692-BDD2CA30BEDD}
Deleted       HKLM\Software\Wow6432Node\Classes\Interface\{2723E96B-905F-4C64-8999-D868A08E6370}
Deleted       HKLM\Software\Classes\Interface\{2723E96B-905F-4C64-8999-D868A08E6370}
Deleted       HKLM\Software\Wow6432Node\Classes\Interface\{26A3152F-CF87-4C5B-8093-4D4B9EC084EB}
Deleted       HKLM\Software\Classes\Interface\{26A3152F-CF87-4C5B-8093-4D4B9EC084EB}
Deleted       HKLM\Software\Wow6432Node\Classes\Interface\{23E3CEB3-D63A-433E-A5D0-4DB1C501B915}
Deleted       HKLM\Software\Classes\Interface\{23E3CEB3-D63A-433E-A5D0-4DB1C501B915}
Deleted       HKLM\Software\Wow6432Node\Classes\Interface\{22389F39-2CF4-47C4-B8B2-273BB16BF70C}
Deleted       HKLM\Software\Classes\Interface\{22389F39-2CF4-47C4-B8B2-273BB16BF70C}
Deleted       HKLM\Software\Wow6432Node\Classes\Interface\{12D3E096-0FDF-42CC-8F44-04944F9C1648}
Deleted       HKLM\Software\Classes\Interface\{12D3E096-0FDF-42CC-8F44-04944F9C1648}
Deleted       HKLM\Software\Wow6432Node\Classes\Interface\{11D5E9EA-3117-4389-8E58-742F0975C980}
Deleted       HKLM\Software\Classes\Interface\{11D5E9EA-3117-4389-8E58-742F0975C980}
Deleted       HKLM\Software\Wow6432Node\Classes\AppID\{FFFFE1D1-E40D-49a1-9622-BC59BD1879C3}
Deleted       HKLM\Software\Classes\AppID\{FFFFE1D1-E40D-49a1-9622-BC59BD1879C3}
Deleted       HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EFC0651C-B6D7-49CD-A6E0-B1CE9AB5FE46}
Deleted       HKLM\Software\Wow6432Node\Classes\AppID\{EFC0651C-B6D7-49CD-A6E0-B1CE9AB5FE46}
Deleted       HKLM\Software\Classes\AppID\{EFC0651C-B6D7-49CD-A6E0-B1CE9AB5FE46}
Deleted       HKLM\Software\Wow6432Node\Classes\AppID\{EB2BA65E-41F6-4F64-92A6-216CDFFDF577}
Deleted       HKLM\Software\Classes\AppID\{EB2BA65E-41F6-4F64-92A6-216CDFFDF577}
Deleted       HKLM\Software\Wow6432Node\Classes\AppID\{9EDCCD11-960D-49AE-B523-C6B5AB7E1345}
Deleted       HKLM\Software\Classes\AppID\{9EDCCD11-960D-49AE-B523-C6B5AB7E1345}
Deleted       HKLM\Software\Wow6432Node\Classes\AppID\{7D831388-D405-4272-9511-A07440AD2927}
Deleted       HKLM\Software\Classes\AppID\{7D831388-D405-4272-9511-A07440AD2927}
Deleted       HKLM\Software\Wow6432Node\Classes\AppID\{41D7CEE0-D91F-498C-BC88-4A6BEE46C2BC}
Deleted       HKLM\Software\Classes\AppID\{41D7CEE0-D91F-498C-BC88-4A6BEE46C2BC}
Deleted       HKLM\Software\Wow6432Node\Classes\AppID\{39DCCEAF-C749-4390-9953-527CF916935C}
Deleted       HKLM\Software\Classes\AppID\{39DCCEAF-C749-4390-9953-527CF916935C}
Deleted       HKLM\Software\Wow6432Node\Classes\AppID\{35860EFB-1589-4F32-A618-99E847A502B2}
Deleted       HKLM\Software\Classes\AppID\{35860EFB-1589-4F32-A618-99E847A502B2}
Deleted       HKLM\Software\Wow6432Node\Classes\AppID\{1CAE874F-F5C7-4BCC-BA46-9AD26DF35B93}
Deleted       HKLM\Software\Classes\AppID\{1CAE874F-F5C7-4BCC-BA46-9AD26DF35B93}
Deleted       HKLM\Software\Wow6432Node\Classes\AppID\{07CDAAD9-1226-4C6D-B774-C00E7B323484}
Deleted       HKLM\Software\Classes\AppID\{07CDAAD9-1226-4C6D-B774-C00E7B323484}
Deleted       HKLM\Software\Wow6432Node\Classes\CLSID\{FBE30D66-39A2-4b72-8B43-6D4C335A6F34}
Deleted       HKLM\Software\Wow6432Node\Classes\Interface\{F9A10D86-182A-4946-869B-70C3D109D14D}
Deleted       HKLM\Software\Classes\Interface\{F9A10D86-182A-4946-869B-70C3D109D14D}
Deleted       HKLM\Software\Wow6432Node\Classes\CLSID\{F9A10D86-182A-4946-869B-70C3D109D14D}
Deleted       HKLM\Software\Wow6432Node\Classes\CLSID\{F51C15D4-3D0A-4DBA-A095-EBCC09F24DA2}
Deleted       HKLM\Software\Wow6432Node\Classes\CLSID\{E1A2D448-6334-45ec-8800-6D7F71DC87FC}
Deleted       HKLM\Software\Wow6432Node\Classes\CLSID\{DDCED22E-D018-471D-9A5C-A4EA2F21133D}
Deleted       HKLM\Software\Wow6432Node\Classes\CLSID\{D40A62D1-8FC0-4F03-90C4-0DE03BE73A41}
Deleted       HKLM\Software\Wow6432Node\Classes\CLSID\{C60CCE95-6AF9-4E74-B66B-3212D19F1D2F}
Deleted       HKLM\Software\Wow6432Node\Classes\CLSID\{B7A0E898-93E5-43f4-B99A-6C70B303699C}
Deleted       HKLM\Software\Wow6432Node\Classes\CLSID\{9F9C4C5C-2BA8-4E00-A697-9F710BB1026B}
Deleted       HKLM\Software\Wow6432Node\Classes\CLSID\{6E40017D-FB6A-4804-BDE4-3BB09F1719C1}
Deleted       HKLM\Software\Wow6432Node\Classes\CLSID\{46140CE4-76FE-440E-AE88-4C2272BC05C7}
Deleted       HKLM\Software\Wow6432Node\Classes\CLSID\{3A06AA27-D94B-48C2-BB55-9FD0FF2120E3}
Deleted       HKLM\Software\Wow6432Node\Classes\CLSID\{37B8167C-B9A4-4316-94B2-67B64BB2BA7C}
Deleted       HKLM\Software\Wow6432Node\Classes\CLSID\{31371420-098D-4C0E-A11E-EBEC2305DD01}
Deleted       HKLM\Software\Wow6432Node\Classes\CLSID\{1E57256D-9F39-4267-AB39-D7813D644C5A}
Deleted       HKLM\Software\Wow6432Node\Classes\CLSID\{11CB4723-D5A1-4a55-8D1D-5C2679D54CF5}
Deleted       HKLM\Software\Wow6432Node\Classes\CLSID\{1147DC83-6208-4dca-8E88-DD45BAAB3043}
Deleted       HKLM\Software\Wow6432Node\Classes\TypeLib\{D2EA97F6-6235-4B2D-B5AA-A4472B9CE557}
Deleted       HKLM\Software\Classes\TypeLib\{D2EA97F6-6235-4B2D-B5AA-A4472B9CE557}
Deleted       HKLM\Software\Wow6432Node\Classes\TypeLib\{B82D18E0-1649-48DE-92D7-AA89BBB5F0AD}
Deleted       HKLM\Software\Classes\TypeLib\{B82D18E0-1649-48DE-92D7-AA89BBB5F0AD}
Deleted       HKLM\Software\Wow6432Node\Classes\TypeLib\{AD34BE7D-2603-43DD-8D1F-E4431D42C44E}
Deleted       HKLM\Software\Classes\TypeLib\{AD34BE7D-2603-43DD-8D1F-E4431D42C44E}
Deleted       HKLM\Software\Wow6432Node\Classes\TypeLib\{A31F34A1-EBD2-45A2-BF6D-231C1B987CC8}
Deleted       HKLM\Software\Classes\TypeLib\{A31F34A1-EBD2-45A2-BF6D-231C1B987CC8}
Deleted       HKLM\Software\Wow6432Node\Classes\TypeLib\{A2C55651-A23E-43CA-B63D-C10B99EFF7E0}
Deleted       HKLM\Software\Classes\TypeLib\{A2C55651-A23E-43CA-B63D-C10B99EFF7E0}
Deleted       HKLM\Software\Wow6432Node\Classes\TypeLib\{8A1AB044-787D-4309-8410-709768E484AB}
Deleted       HKLM\Software\Classes\TypeLib\{8A1AB044-787D-4309-8410-709768E484AB}
Deleted       HKLM\Software\Wow6432Node\Classes\TypeLib\{78DB07DF-483E-4829-AB44-ED7952083584}
Deleted       HKLM\Software\Classes\TypeLib\{78DB07DF-483E-4829-AB44-ED7952083584}
Deleted       HKLM\Software\Wow6432Node\Classes\TypeLib\{61A2027D-B837-4080-A925-6E30E10DEF32}
Deleted       HKLM\Software\Classes\TypeLib\{61A2027D-B837-4080-A925-6E30E10DEF32}
Deleted       HKLM\Software\Wow6432Node\Classes\TypeLib\{4A1E52AC-64F2-49E9-BFD7-0806D9494DBB}
Deleted       HKLM\Software\Classes\TypeLib\{4A1E52AC-64F2-49E9-BFD7-0806D9494DBB}
Deleted       HKLM\Software\Wow6432Node\Classes\TypeLib\{0548C79F-7B8C-455D-B228-97D35371BB62}
Deleted       HKLM\Software\Classes\TypeLib\{0548C79F-7B8C-455D-B228-97D35371BB62}
Deleted       HKLM\Software\Wow6432Node\Classes\TypeLib\{003028C2-EA1C-4676-A316-B5CB50917002}
Deleted       HKLM\Software\Classes\TypeLib\{003028C2-EA1C-4676-A316-B5CB50917002}
Deleted       HKLM\Software\Wow6432Node\Classes\Interface\{BD125908-5F10-409F-9C01-F2207CA18887}
Deleted       HKLM\Software\Wow6432Node\Classes\TypeLib\{B722ED8B-0B38-408E-BB89-260C73BCF3D4}
Deleted       HKLM\Software\Classes\TypeLib\{B722ED8B-0B38-408E-BB89-260C73BCF3D4}
Deleted       HKLM\Software\Wow6432Node\Classes\Interface\{8233093C-178B-484B-979E-3C6B5B147DBC}
Deleted       HKLM\Software\Classes\Interface\{8233093C-178B-484B-979E-3C6B5B147DBC}
Deleted       HKLM\Software\Wow6432Node\Classes\CLSID\{D89031C2-10DA-4C90-9A62-FCED012BC46B}
Deleted       HKLM\Software\Wow6432Node\Classes\CLSID\{C339D489-FABC-41DD-B39D-276101667C70}
Deleted       HKLM\Software\Wow6432Node\Classes\CLSID\{AE338F6D-5A7C-4D1D-86E3-C618532079B5}
Deleted       HKLM\Software\Wow6432Node\Classes\CLSID\{A9A56B8E-2DEB-4ED3-BC92-1FA450BCE1A5}
Deleted       HKLM\Software\Wow6432Node\Classes\AppID\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
Deleted       HKLM\Software\Classes\AppID\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
Deleted       HKLM\Software\Wow6432Node\Classes\CLSID\{1C950DE5-D31E-42FB-AFB9-91B0161633D8}
Deleted       HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}
Deleted       HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}
Deleted       HKLM\Software\Wow6432Node\Classes\CLSID\{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}
Deleted       HKLM\Software\Wow6432Node\Classes\TypeLib\{EEA63863-87BC-4DCA-A5B5-EB97E3B04806}
Deleted       HKLM\Software\Classes\TypeLib\{EEA63863-87BC-4DCA-A5B5-EB97E3B04806}
Deleted       HKLM\Software\Classes\yt.YToolbarBand
Deleted       HKLM\Software\Classes\yt.YTHelper
Deleted       HKLM\Software\Classes\yt.Clickstream
Deleted       HKLM\Software\Classes\yt.CacheLoader
Deleted       HKLM\Software\Classes\Yahoo.PopupBlockerPlugin
Deleted       HKLM\Software\Classes\Yahoo.AntiSpyPlugin
Deleted       HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\analytics.app.amazonbrowserapp.com
Deleted       HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\amazonbrowserapp.com
Deleted       HKCU\Software\Microsoft\Internet Explorer\DOMStorage\analytics.app.amazonbrowserapp.com
Deleted       HKCU\Software\Microsoft\Internet Explorer\DOMStorage\amazonbrowserapp.com
 
***** [ Chromium (and derivatives) ] *****
 
Not Deleted   Amazon Assistant for Chrome
Not Deleted   Amazon Assistant for Chrome
Not Deleted   Amazon Assistant for Chrome
Not Deleted   CouponXplorer
Not Deleted   Hover Zoom
Not Deleted   Bitly | Unleash the power of the link
Not Deleted   FromDocToPDF
Not Deleted   Shopping App by Ask
 
***** [ Chromium URLs ] *****
 
Deleted       Mysearchdial
Deleted       AVG Secure Search
Deleted       Mysearchdial
Deleted       AVG Secure Search
Deleted       Softonic EN
Deleted       Softonic EN
Deleted       Softonic EN
 
***** [ Firefox (and derivatives) ] *****
 
No malicious Firefox entries cleaned.
 
***** [ Firefox URLs ] *****
 
No malicious Firefox URLs cleaned.
 
 
*************************
 
[+] Delete Tracing Keys
[+] Reset Winsock
 
*************************
 
AdwCleaner[S00].txt - [33512 octets] - [22/12/2018 11:33:37]
 
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########
 

 

 

RogueKiller

 

RogueKiller Anti-Malware V13.0.17.0 (x64) [Dec 17 2018] (Free) by Adlice Software
mail : https://adlice.com/contact/
Website : https://adlice.com/download/roguekiller/
Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits
Started in : Normal mode
User : Barley [Administrator]
Started from : C:\Program Files\RogueKiller\RogueKiller64.exe
Mode : Standard Scan, Scan – Date : 2018/12/22 12:09:35 (Duration : 00:35:47)
 
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
 
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Process Modules ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
 
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Services ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
 
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Tasks ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
 
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Registry ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
>>>>>> O101 - Clsid
  [PUP.Coupons (Potentially Malicious)] (X64) HKEY_CLASSES_ROOT\CLSID\{1A53AD8B-D0B9-4E7F-88E4-50C07A65F2DC} – (Coupons, Inc.) C:\windows\COUPON~2.OCX -> Found
  [PUP.Coupons (Potentially Malicious)] (X64) HKEY_CLASSES_ROOT\CLSID\{A85A5E6A-DE2C-4F4E-99DC-F469DF5A0EEC} – (Coupons, Inc.) C:\windows\COUPON~2.OCX -> Found
>>>>>> O4 - Run
  [PUP.Gen1 (Potentially Malicious)] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|Http Listener – C:\Program Files (x86)\PrintMyCouponAnywhere\PrintMyCouponAnywhere.exe (missing) -> Found
>>>>>> O23 - Services
  [Suspicious.Path (Potentially Malicious)] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\BackupService – "C:\Users\Barley\AppData\Roaming\HP SimpleSave Application\uUACTokenSvc.exe" -> Found
  [Suspicious.Path (Potentially Malicious)] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\BackupService – "C:\Users\Barley\AppData\Roaming\HP SimpleSave Application\uUACTokenSvc.exe" -> Found
>>>>>> R5 - Proxy
  [PUM.Proxy (Potentially Malicious)] (X64) HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings|ProxyServer – N/A -> Found
  [PUM.Proxy (Potentially Malicious)] (X86) HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings|ProxyServer – N/A -> Found
  [PUM.Proxy (Potentially Malicious)] (X64) HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings|ProxyServer – N/A -> Found
  [PUM.Proxy (Potentially Malicious)] (X86) HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings|ProxyServer – N/A -> Found
>>>>>> O87 - Firewall
  [Suspicious.Path (Potentially Malicious)] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{47BD5BDD-CD2C-4B46-8AF5-342D9FE7C3AE} – v2.10|Action=Allow|Active=TRUE|Dir=In|App=C:\Users\Barley\AppData\Local\Temp\7zS7B67\setup\hpznui40.exe|Name=hpznui40.exe|Desc=C:\Users\Barley\AppData\Local\Temp\7zS7B67\setup\hpznui40.exe| (C:\Users\Barley\AppData\Local\Temp\7zS7B67\setup\hpznui40.exe) (missing) -> Found
  [Suspicious.Path (Potentially Malicious)] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{3B192164-7E8C-45B2-BD99-7D5DD3E627DF} – v2.10|Action=Allow|Active=TRUE|Dir=In|App=C:\Users\Barley\AppData\Local\Temp\7zS6C7F.tmp\autorun.exe|Name=MyDlink Wizard| (C:\Users\Barley\AppData\Local\Temp\7zS6C7F.tmp\autorun.exe) (missing) -> Found
  [Suspicious.Path (Potentially Malicious)] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{47BD5BDD-CD2C-4B46-8AF5-342D9FE7C3AE} – v2.10|Action=Allow|Active=TRUE|Dir=In|App=C:\Users\Barley\AppData\Local\Temp\7zS7B67\setup\hpznui40.exe|Name=hpznui40.exe|Desc=C:\Users\Barley\AppData\Local\Temp\7zS7B67\setup\hpznui40.exe| (C:\Users\Barley\AppData\Local\Temp\7zS7B67\setup\hpznui40.exe) (missing) -> Found
  [Suspicious.Path (Potentially Malicious)] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{3B192164-7E8C-45B2-BD99-7D5DD3E627DF} – v2.10|Action=Allow|Active=TRUE|Dir=In|App=C:\Users\Barley\AppData\Local\Temp\7zS6C7F.tmp\autorun.exe|Name=MyDlink Wizard| (C:\Users\Barley\AppData\Local\Temp\7zS6C7F.tmp\autorun.exe) (missing) -> Found
 
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ WMI ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
 
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Hosts File ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
 
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Files ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
[Hj.Shortcut (Malicious)] (shortcut) DCS-5020L(26467279).lnk – C:\Users\Barley\Desktop\DCS-5020L(26467279).lnk => C:\Windows\explorer.exe ["https://mp-us-portal.auto.mydlink.com/device#26467279?lang=en_US"]-> Found
[PUP.Coupons (Potentially Malicious)] (file) couponprinter_x64.ocx – (Coupons, Inc.) C:\Windows\couponprinter_x64.ocx -> Found
[PUP.Coupons (Potentially Malicious)] (file) CouponPrinter.ocx – (Coupons, Inc.) C:\Windows\CouponPrinter.ocx -> Found
[Hj.Shortcut (Malicious)] (shortcut) DCS-5020L(26467279).lnk – C:\Users\Barley\Desktop\DCS-5020L(26467279).lnk => C:\Windows\explorer.exe ["https://mp-us-portal.auto.mydlink.com/device#26467279?lang=en_US"]-> Found
[PUP.AutoIt.Gen (Potentially Malicious)] (file) FRST64.exe – C:\Users\Barley\Downloads\FRST-OlderVersion\FRST64.exe -> Found
 
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Web browsers ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
>>>>>> Firefox Config
  [PUM.SearchEngine (Potentially Malicious)] browser.search.selectedEngine (C:\Users\Barley\AppData\Roaming\Mozilla\Firefox\Profiles\z9dx3jxz.default\prefs.js) – Yahoo! -> Found
  [PUM.SearchEngine (Potentially Malicious)] browser.search.defaultenginename (C:\Users\Barley\AppData\Roaming\Mozilla\Firefox\Profiles\z9dx3jxz.default\prefs.js) – Yahoo! -> Found
>>>>>> Chrome Addon
  [PUP.Gen0 (Potentially Malicious)] Honey (C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\BMNLCJ~1) – bmnlcjabgnpnenekpadlanbbkooimhnj -> Found
  [PUP.Gen0 (Potentially Malicious)] Amazon Assistant for Chrome (C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\PBJIKB~1) – pbjikboenpfhbbejgkoklgkhjpfogcam -> Found
  [PUP.Gen0 (Potentially Malicious)] Bitly | Unleash the power of the link (C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\IABEIH~1) – iabeihobmhlgpkcgjiloemdbofjbdcic -> Found
  [PUP.Gen0 (Potentially Malicious)] Hover Zoom (C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\NONJDC~1) – nonjdcjchghhkdoolnlbekcfllmednbl -> Found
  [PUP.Gen0 (Potentially Malicious)] Amazon Assistant for Chrome (C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\PBJIKB~1) – pbjikboenpfhbbejgkoklgkhjpfogcam -> Found
 

 

  

My goodness, look what those tools found.

First, let me give you some info for antivirus and anti-malware programs.

Note: The programs listed below are all free to use or they have some sort of trial. Some of them have a paid version that provides more features, while a lot of other good programs only have a paid version but aren't listed there (such as Kaspersky and ESET Antivirus products).

Anti-VirusAnti-Malware~~~
created by Aura


~~~~~
Why the computer booted to a different screen then usually, I don't know. Could be setting were altered with something that was removed but we can try to deal with that latter.


In the RogueKiller log I can see 'Found', did you let it delete and quarantine?

~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Let's check for remnants

If you're already running Malwarebytes 3 then open Malwarebytes and check for updates.
Then click on the Scan tab and select Threat Scan and click on Start Scan button.
If you don't have Malwarebytes 3 installed yet please download it from here Here and install it.
Once installed then open Malwarebytes and check for updates. Then click on the Scan tab and select Threat Scan and click on Start Scan button.
Once the scan is completed click on the Export Summary button and save the file as a Text file to your desktop or other location you can find, and attach that log on your next reply.
You can access the logs by going in the "Reports" tab, clicking on the latest "Scan" entry (the one with detections), then clicking on the "Export" button in the bottom-left corner and select "Copy to clipboard". After that, all you have to do is paste it here
  • Then click on POST
  • Exit Malwarebytes
~~~~~~~~~~~~

[external image: G0tu5D9.png]Emsisoft Emergency Kit - Fix Mode
Follow the instructions below to run a scan using the Emsisoft Emergency Kit.
  • Download the Emsisoft Emergency Kit and execute it. From there, click on the Install button to extract the program in the EEK folder;
  • Once the extraction is complete, the EEK folder will open. Right-click on [external image: G0tu5D9.png]start emergency kit scanner.exe and select [external image: Spcusrh.png]Run as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users);
  • EEK will suggest that you run an online update before using the program. Click on Yes to launch it.
  • After the update, click on Malware Scan under 2. Scan and accept to let EEK detect PUPs (click on Yes).
  • Once the scan is complete, make sure that every item in the list is checked, and click on the Quarantine selected button;
  • If it asks you for a reboot to delete some items, click on Ok to reboot automatically;
  • After the restart, open EEK again (in the C:\EEK folder);
  • This time, click on Logs;
  • From there, go under the Quarantine Log tab, and click on the Export button;
  • Save the log on your desktop, then open it, and copy/paste its content in your next reply;
Please post these 2 logs when finished.

Also, tell me how the computer is now.

Hi again:

 

  A few quick things first . . .

 

   Yes I did let the RogueKIller delete the Found items - just to be sure, I just ran it again and it came up clean.

   (also, another quick question - most of these scans quarantine everything when done, but I've gone the next step and deleted them as well - is that what I'm supposed to do, or is just quarantining them adequate?)

 

   (And I think that leftover Catalina Printer thing is just a remnant of the program, I've tried a couple of Uninstallers and even did regedit, but still can't get rid of it - I'd like to see it completely gone - saw something about going into Safe Mode to try something, but not sure if that will work either.)

 

   Last, the computer did boot up normally this AM, so hopefully whatever caused that is fixed - and that had happened just before I posted here, so it probably wasn't anything that was removed, but will watch that to see if it happens again.

 

    I uninstalled my Malwarebytes, and re-installed the version 3 you sent (which was the same one I had), and the Report is pasted below, along with the EEK report (it didn't ask me to re-boot when done) and I quarantined and deleted the ?Trojan that it found.

   Finally, the computer seems to be running quite cleanly now.

 

Thanks again.

 

Malwarebytes

 

Malwarebytes
www.malwarebytes.com
 
-Log Details-
Scan Date: 12/23/18
Scan Time: 11:46 AM
Log File: 48abe3b4-06d2-11e9-8936-24be05218274.json
 
-Software Information-
Version: 3.6.1.2711
Components Version: 1.0.463
Update Package Version: 1.0.8455
License: Trial
 
-System Information-
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Barley-HP\Barley
 
-Scan Summary-
Scan Type: Threat Scan
Scan Initiated By: Manual
Result: Completed
Objects Scanned: 285121
Threats Detected: 2
Threats Quarantined: 0
Time Elapsed: 6 min, 54 sec
 
-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Detect
PUM: Detect
 
-Scan Details-
Process: 0
(No malicious items detected)
 
Module: 0
(No malicious items detected)
 
Registry Key: 0
(No malicious items detected)
 
Registry Value: 0
(No malicious items detected)
 
Registry Data: 0
(No malicious items detected)
 
Data Stream: 0
(No malicious items detected)
 
Folder: 0
(No malicious items detected)
 
File: 2
PUP.Optional.Iminent, C:\USERS\BARLEY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Profile 3\Secure Preferences, Removal Failed, [98], [455248],1.0.8455
PUP.Optional.Speedial, C:\USERS\BARLEY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Profile 3\Secure Preferences, Removal Failed, [359], [455287],1.0.8455
 
Physical Sector: 0
(No malicious items detected)
 
WMI: 0
(No malicious items detected)
 
 

 

(end)

 

  EEK

 

Emsisoft Emergency Kit 2018.6.0.8742 stable [en-us]

OS: Windows 7 Service Pack 1 (Version 6.1, Build 7601, 64-bit Edition)
 
Forensics log
 
Date Component Action Details
12/23/2018 12:21:09 PM User BARLEY-HP\BARLEY Infection deleted High risk Malware "JS:Trojan.Cryxos.1726 (B)" in "This computer is BLOCKED.htm".
12/23/2018 12:19:09 PM User BARLEY-HP\BARLEY Infection quarantined High risk Malware "JS:Trojan.Cryxos.1726 (B)" in "This computer is BLOCKED.htm".
12/23/2018 12:17:50 PM Scanner Scan finished Found 1 object , user to decide on further actions.
12/23/2018 12:15:37 PM Scanner Detection High risk Malware "JS:Trojan.Cryxos.1726 (B)" in "This computer is BLOCKED.htm -> (INFECTED_JS)"
12/23/2018 12:12:54 PM User BARLEY-HP\Barley Scan started Malware Scan
12/23/2018 12:12:54 PM User BARLEY-HP\Barley Setting modified "Detect PUPs" has been changed to "Enabled".
12/23/2018 12:12:11 PM User Update Downloaded and installed 49 files (4764 kb) (25 sec.).
12/23/2018 12:11:47 PM Core Notification "Recommended Reading:5 Privacy tools to keep your data safe and secure during the holidays".
12/23/2018 12:11:42 PM User Update Failed with error "Server returned error" (0 sec.).
 

Quote
 
most of these scans quarantine everything when done, but I've gone the next step and deleted them as well - is that what I'm supposed to do, or is just quarantining them adequate?)

Quarantine is fine,  we'll use a tool at the end to remove tools and quarantine folders. So dont worry over that.
 

Quote
 
And I think that leftover Catalina Printer thing is just a remnant of the program, I've tried a couple of Uninstallers and even did regedit, but still can't get rid of it - I'd like to see it completely gone

We can use FRST to do a search for this.
 

Quote
 
Last, the computer did boot up normally this AM, so hopefully whatever caused that is fixed - and that had happened just before I posted here, so it probably wasn't anything that was removed, but will watch that to see if it happens again.

 I got my fingers crossed it doesn't happen again.
 

Quote
 
Finally, the computer seems to be running quite cleanly now.

 
Your my favorite person today! Music to my ears.
 
~~~~~~~~~~~~~~~~~~~~~~~~~
you have Chrome Sync enabled?
Follow the below link to reset this.
https://forums.malwarebytes.com/topic/214325-chrome-secure-preferences-detection-always-comes-back/

~~~~~~~~~~~~~~~~~~~~~~~~

Start Farbar Recovery Scan Tool with Administrator privileges
(Right click on the FRST icon and select Run as administrator)
type the following text in the Search box
Catalina

Click the Search Files button.

When finished, a log file (Search.txt) will open and is saved where FRST was run from, on the Desktop.

Please post that log in your next reply.

Hi Juliet:

 

     I think I jinxed the good roll we were out - doesn't look like anything came up with the FRST Search for Catalina.

    I did the Chrome Synch thing the way the Belgium lady said (I think), and nothing came up on Malwarebytes (except the 2 items that keep coming up - can't get rid of those either) or the FRST Search, unless I did something wrong.

 

    Otherwise everything is still going fine.

 

I've posted both the Malwarebytes and FRST Search logs below.

 

Thanks for your time again.

 

 

Malwarebytes

 

Malwarebytes
www.malwarebytes.com
 
-Log Details-
Scan Date: 12/23/18
Scan Time: 10:17 PM
Log File: 761021ab-072a-11e9-bd81-24be05218274.json
 
-Software Information-
Version: 3.6.1.2711
Components Version: 1.0.463
Update Package Version: 1.0.8459
License: Trial
 
-System Information-
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Barley-HP\Barley
 
-Scan Summary-
Scan Type: Threat Scan
Scan Initiated By: Manual
Result: Completed
Objects Scanned: 285209
Threats Detected: 2
Threats Quarantined: 0
Time Elapsed: 6 min, 48 sec
 
-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Detect
PUM: Detect
 
-Scan Details-
Process: 0
(No malicious items detected)
 
Module: 0
(No malicious items detected)
 
Registry Key: 0
(No malicious items detected)
 
Registry Value: 0
(No malicious items detected)
 
Registry Data: 0
(No malicious items detected)
 
Data Stream: 0
(No malicious items detected)
 
Folder: 0
(No malicious items detected)
 
File: 2
PUP.Optional.Speedial, C:\USERS\BARLEY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Profile 3\Secure Preferences, Removal Failed, [359], [455287],1.0.8459
PUP.Optional.Iminent, C:\USERS\BARLEY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Profile 3\Secure Preferences, Removal Failed, [98], [455248],1.0.8459
 
Physical Sector: 0
(No malicious items detected)
 
WMI: 0
(No malicious items detected)
 
 
(end)

 

FRST

 

Farbar Recovery Scan Tool (x64) Version: 23.12.2018
Ran by [removed] (23-12-2018 23:03:27)
Running from C:\Users\[removed]\Desktop
Boot Mode: Normal
 
================== Search Files: "Catalina" =============
 
 
====== End of Search ======

 

On that page did you try option 2 by Aura?
Please check for me.
~~~~~~~~~~~~~~~~

Im listing a few Google extensions I'd like you to look for then try to uninstall/delete
The link below should show you how to do this
https://support.google.com/chrome_webstore/answer/2664769?hl=en

CHR Extension: (AVG SafePrice |
CHR Extension: (Savings Button: Deals + Cash Back) -
CHR Extension: (AVG SafePrice | Comparison, deals, coupons)
CHR Extension: (CouponXplorer) -

Next, look in your add/remove programs list for a few things to uninstall

Please uninstall the following programs:

Digital Coupon Printer
ShopAtHome.com Helper
Bing Bar
Catalina Savings Printer
Catalina Savings Printer
Coupon Printer for Windows
CouponPrinterPlugin
PrintMyCouponAnywhere
QponPrinter 1.0.1
QponPrinterV2 1.0.3
RevTraxPrintMyCoupon


Might not find them all, but what you do find please uninstall, then, reboot your computer.

Next
run another scan using Malwarebytes Anti-Malware and post this log for me to see.

Good morning:

 

    I'm sorry, I didn't initially try Aura's option 2, but did just try it this AM. 

   I don't think much changed with it, and I've also posted the AdwareCleaner report that I did after trying it.

 

   I deleted those Google Chrome extensions that you mentioned, and unistalled those programs you asked to be removed (except still can't remove the one Catalina thing).

   The Malwarebytes scan comes up the same - that's posted below as well.

 

   (and just to check, while deleting those Chrome Extensions, I saw one called "ViewMyPDF ads" which had a red exclamation point and said it might be corrupted - wasn't sure if I should delete/repair it or just leave it alone - wasn't sure if it's related to anything.)

 

Thanks again.

 

AdwCleaner

 

# ——————————-
# Malwarebytes AdwCleaner 7.2.6.0
# ——————————-
# Build:    12-18-2018
# Database: 2018-12-21.2 (Cloud)
# Support:  https://www.malwarebytes.com/support
#
# ——————————-
# Mode: Clean
# ——————————-
# Start:    12-24-2018
# Duration: 00:00:02
# OS:       Windows 7 Home Premium
# Cleaned:  0
# Failed:   13
 
 
***** [ Services ] *****
 
No malicious services cleaned.
 
***** [ Folders ] *****
 
No malicious folders cleaned.
 
***** [ Files ] *****
 
No malicious files cleaned.
 
***** [ DLL ] *****
 
No malicious DLLs cleaned.
 
***** [ WMI ] *****
 
No malicious WMI cleaned.
 
***** [ Shortcuts ] *****
 
No malicious shortcuts cleaned.
 
***** [ Tasks ] *****
 
No malicious tasks cleaned.
 
***** [ Registry ] *****
 
No malicious registry entries cleaned.
 
***** [ Chromium (and derivatives) ] *****
 
Not Deleted   Amazon Assistant for Chrome
Not Deleted   Amazon Assistant for Chrome
Not Deleted   Amazon Assistant for Chrome
Not Deleted   CouponXplorer
Not Deleted   Hover Zoom
Not Deleted   Share to Classroom
Not Deleted   Bitly | Unleash the power of the link
Not Deleted   FromDocToPDF
Not Deleted   Shopping App by Ask
 
***** [ Chromium URLs ] *****
 
Not Deleted   http://start.mysearchdial.com/?f=1&a=ir_14_19_ch&cd=2XzuyEtN2Y1L1QzutDtDtBtBtCzytCyCyCyCzyzz0B0F0EtBtN0D0Tzu0SzzyDzztN1L2XzutBtFtBtDtFyCtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyB0CtCtD0BtD0EtAtGyD0DyDtCtG0A0EyBzytGyC0EyD0CtGyEyByE0ByEzz0FtCtC0ByE0A2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyC0DtA0EtAtC0AyEtG0DtC0E0FtGyEtC0EtAtG0E0D0A0AtGtBtB0CtDyBtDtBtBtDtCyDzz2Q&cr=1966473572&ir=
Not Deleted   http://start.iminent.com/?appId=d0e1b9eb-c65b-4260-826d-e4745cbdde8d
Not Deleted   http://speedial.com/?f=7&a=defoffer_spd_irspd_14_37_ch&cd=2XzuyEtN2Y1L1Qzu0BzztB0AyBtB0BtDyE0Ezy0ByE0EtCyBtN0D0Tzu0SzyzztAtN1L2XzutBtFtBtCtFtCtCtFtDtN1L1Czu0C0I0S0V0E0R1V1StN1L1G1B1V1N2Y1L1Qzu2SyB0DyC0C0CyByByDtG0FtAyDzytGtB0DtC0DtGyBzyzzyDtGyE0FtDyB0E0Czy0B0DyEtCyB2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyC0CzztCyDtCyE0AtGyCyDzy0AtG0DyEyEyEtG0CyD0DyDtGtAtA0F0EyB0D0AtCyC0BzyyB2Q&cr=615555417&ir=
Not Deleted   http://start.mysearchdial.com/?f=1&a=ir_14_19_ch&cd=2XzuyEtN2Y1L1QzutDtDtBtBtCzytCyCyCyCzyzz0B0F0EtBtN0D0Tzu0SzzyDzztN1L2XzutBtFtBtDtFyCtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyB0CtCtD0BtD0EtAtGyD0DyDtCtG0A0EyBzytGyC0EyD0CtGyEyByE0ByEzz0FtCtC0ByE0A2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyC0DtA0EtAtC0AyEtG0DtC0E0FtGyEtC0EtAtG0E0D0A0AtGtBtB0CtDyBtDtBtBtDtCyDzz2Q&cr=1966473572&ir=
 
***** [ Firefox (and derivatives) ] *****
 
No malicious Firefox entries cleaned.
 
***** [ Firefox URLs ] *****
 
No malicious Firefox URLs cleaned.
 
 
*************************
 
[+] Delete Tracing Keys
[+] Reset Winsock
 
*************************
 
AdwCleaner[S00].txt - [33512 octets] - [22/12/2018 11:33:37]
AdwCleaner[C00].txt - [28542 octets] - [22/12/2018 11:36:01]
AdwCleaner[S01].txt - [3144 octets] - [24/12/2018 12:02:43]
 
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C01].txt ##########

 

 

Malwarebytes

 

Malwarebytes

www.malwarebytes.com
 
-Log Details-
Scan Date: 12/24/18
Scan Time: 12:48 PM
Log File: 240f4f6e-07a4-11e9-9219-24be05218274.json
 
-Software Information-
Version: 3.6.1.2711
Components Version: 1.0.463
Update Package Version: 1.0.8473
License: Free
 
-System Information-
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Barley-HP\Barley
 
-Scan Summary-
Scan Type: Threat Scan
Scan Initiated By: Manual
Result: Completed
Objects Scanned: 282588
Threats Detected: 2
Threats Quarantined: 0
Time Elapsed: 9 min, 32 sec
 
-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Detect
PUM: Detect
 
-Scan Details-
Process: 0
(No malicious items detected)
 
Module: 0
(No malicious items detected)
 
Registry Key: 0
(No malicious items detected)
 
Registry Value: 0
(No malicious items detected)
 
Registry Data: 0
(No malicious items detected)
 
Data Stream: 0
(No malicious items detected)
 
Folder: 0
(No malicious items detected)
 
File: 2
PUP.Optional.Speedial, C:\USERS\BARLEY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Profile 3\Secure Preferences, Removal Failed, [359], [455287],1.0.8473
PUP.Optional.Iminent, C:\USERS\BARLEY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Profile 3\Secure Preferences, Removal Failed, [98], [455248],1.0.8473
 
Physical Sector: 0
(No malicious items detected)
 
WMI: 0
(No malicious items detected)
 
 
(end)

 

I saw one called "ViewMyPDF ads" which had a red exclamation point and said it might be corrupted - wasn't sure if I should delete/repair it or just leave it alone - wasn't sure if it's related to anything

I'd remove that as well.

 

After removing those extensions did you reboot the computer?

Run a new scan with FRST
  • Right-Click FRST.exe / FRST64.exe and select [external image: AVOiBNU.jpg]Run as administrator to run the programme.
  • Click Yes to the disclaimer.
  • Ensure the Addition.txt box is checked.
  • Click the Scan button and let the programme run.
  • Upon completion, click OK, then OK on the Addition.txt pop up screen.
  • Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy the contents of both logs and paste in your next reply.

Yes, I was wondering about the AdwCleaner - I click Clean and Repair when the scan is done, then restart, then click Delete, but each time the log states "Not Deleted" and the same items come up on the next scan - am I doing something wrong with that?

 

And I did reboot after removing those extensions.

 

Thanks again!

 

Here's the last FRST scans:

 

 

 

 

FRST.txt

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 24.12.2018
Ran by [removed] (administrator) on BARLEY-HP (24-12-2018 15:17:54)
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\AVGSvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Digital Wave Ltd.) C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Garmin Ltd or its subsidiaries) C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Microsoft Corporation) C:\Program Files\Microsoft LifeCam\MSCamS64.exe
(Garmin Ltd or its subsidiaries) C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\AVGUI.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Smilebox, Inc.) C:\Users\Barley\AppData\Roaming\Smilebox\SmileboxTray.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\NortonSecurity.exe
(PDF Complete Inc) C:\Program Files (x86)\PDF Complete\pdfsvc.exe
(Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaRegistry.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaRegistry64.exe
() C:\Users\Barley\AppData\Roaming\HP SimpleSave Application\StartHelper.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\Brother\Brother Help\BrotherHelp.exe
(the sz development) C:\Users\Barley\AppData\Local\RimhillEx\RimhillEx.exe
(Wondershare) C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\NortonSecurity.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\psia.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\sua.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(Microsoft Corporation) C:\Windows\System32\WirelessKB850NotificationService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\Browny02\BrYNSvc.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\x64\aswidsagenta.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Calendar\Service\GCalService.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Calendar\Service\HPTouchSmartSyncCalReminderApp.exe
(HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(HP Inc.) C:\Program Files\HP\HP Touchpoint Analytics Client\TouchpointAnalyticsClientService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [HPSYSDRV] => C:\Program Files (x86)\Hewlett-Packard\HP Odometer\HPSYSDRV.EXE [62768 2008-11-20] (Hewlett-Packard)
HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176440 2016-11-01] (Apple Inc.)
HKLM\…\Run: [AVGUI.exe] => C:\Program Files (x86)\AVG\Antivirus\AvLaunch.exe [290064 2018-11-15] (AVG Technologies CZ, s.r.o.)
HKLM-x32\…\Run: [ControlCenter4] => C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe [139776 2014-11-12] (Brother Industries, Ltd.)
HKLM-x32\…\Run: [BrStsMon00] => C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [4517376 2014-11-11] (Brother Industries, Ltd.)
HKLM-x32\…\Run: [BrHelp] => C:\Program Files (x86)\Brother\Brother Help\BrotherHelp.exe [1939968 2014-10-22] (Brother Industries, Ltd.)
HKLM-x32\…\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2137744 2016-10-08] (Wondershare)
HKLM-x32\…\Run: [DelaypluginInstall] => C:\ProgramData\Wondershare\Video Converter Ultimate\DelayPluginI.exe [1971856 2017-02-16] ()
HKLM-x32\…\Run: [PDF Complete] => C:\Program Files (x86)\PDF Complete\pdfsty.exe [1194048 2018-02-01] (PDF Complete Inc)
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [601424 2018-10-06] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\windows\System32\igfxdev.dll (Intel Corporation)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-632860548-1775735820-415820443-1000\…\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1095000 2013-12-13] (Garmin Ltd or its subsidiaries)
HKU\S-1-5-21-632860548-1775735820-415820443-1000\…\Run: [Google Update] => C:\Users\Barley\AppData\Local\Google\Update\1.3.33.23\GoogleUpdateCore.exe [605992 2018-12-18] (Google Inc.)
HKU\S-1-5-21-632860548-1775735820-415820443-1000\…\Run: [60439BD48E4DF21A7F8F35AA69AA655C496AD691._service_run] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1587680 2018-12-12] (Google Inc.)
HKU\S-1-5-21-632860548-1775735820-415820443-1000\…\Run: [SmileboxTray] => C:\Users\Barley\AppData\Roaming\Smilebox\SmileboxTray.exe [366552 2017-09-27] (Smilebox, Inc.)
HKU\S-1-5-21-632860548-1775735820-415820443-1000\…\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [19589208 2018-12-10] (Piriform Software Ltd)
HKU\S-1-5-21-632860548-1775735820-415820443-1000\…\Run: [GoogleChromeAutoLaunch_457733C4A2F5F6E1F2B25B1F77F935C9] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1587680 2018-12-12] (Google Inc.)
HKU\S-1-5-21-632860548-1775735820-415820443-1000\…\MountPoints2: {cf036f94-4e8d-11e2-b318-24be05218274} - G:\HPLauncher.exe
HKU\S-1-5-21-632860548-1775735820-415820443-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\windows\system32\Ribbons.scr [241664 2010-11-20] (Microsoft Corporation)
HKLM\…\Drivers32: [MSVideo8] => C:\windows\System32\VfWWDM32.dll [68096 2010-11-20] (Microsoft Corporation)
HKLM\…\Drivers32-x32: [msacm.siren] => C:\Windows\SysWOW64\sirenacm.dll [49016 2011-05-13] (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk [2014-03-18]
ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia)
Startup: C:\Users\Barley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\HP SimpleSave Monitor.lnk [2014-03-01]
ShortcutTarget: HP SimpleSave Monitor.lnk -> C:\Users\Barley\AppData\Roaming\HP SimpleSave Application\StartHelper.exe ()
Startup: C:\Users\Barley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RimhillEx.lnk [2017-01-15]
ShortcutTarget: RimhillEx.lnk -> C:\Users\Barley\AppData\Local\RimhillEx\RimhillEx.exe (the sz development)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{06AE0B1F-FB3C-4241-9145-DF12EC7CB857}: [DhcpNameServer] 172.20.10.1
Tcpip\..\Interfaces\{D3EED012-4886-4C2D-8491-DD153D715076}: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{D3EED012-4886-4C2D-8491-DD153D715076}: [DhcpNameServer] 75.75.75.75 75.75.76.76
 
Internet Explorer:
==================
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: Norton Password Manager -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\coIEPlg.dll [2018-11-03] (Symantec Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_191\bin\jp2ssv.dll [2018-12-01] (Oracle Corporation)
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2016-07-21] (HP Inc.)
BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-09-20] (Hewlett-Packard Co.)
BHO-x32: Wondershare Video Converter Ultimate 7.1.0 -> {451C804F-C205-4F03-B48E-537EC94937BF} -> C:\ProgramData\Wondershare\Video Converter Ultimate\WSBrowserAppMgr.dll [2017-02-16] (Wondershare)
BHO-x32: Norton Password Manager -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton Internet Security\Engine32\22.16.2.22\coIEPlg.dll [2018-11-03] (Symantec Corporation)
BHO-x32: No Name -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> No File
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2016-07-21] (HP Inc.)
BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-09-20] (Hewlett-Packard Co.)
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\coIEPlg.dll [2018-11-03] (Symantec Corporation)
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine32\22.16.2.22\coIEPlg.dll [2018-11-03] (Symantec Corporation)
Toolbar: HKU\S-1-5-21-632860548-1775735820-415820443-1000 -> Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\coIEPlg.dll [2018-11-03] (Symantec Corporation)
 
FireFox:
========
FF ProfilePath: C:\Users\Barley\AppData\Roaming\Mozilla\Firefox\Profiles\z9dx3jxz.default [2018-12-23]
FF Extension: (Wondershare Video Converter Ultimate) - C:\ProgramData\Wondershare\Video Converter Ultimate\WSVCU@Wondershare.com_xpi\ [] [Legacy]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: (HP Smart Web Printing) - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2013-02-03] [Legacy] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\ProgramData\Wondershare\Video Converter Ultimate\WSVCU@Wondershare.com_xpi
FF Extension: (Wondershare Video Converter Ultimate) - C:\ProgramData\Wondershare\Video Converter Ultimate\WSVCU@Wondershare.com_xpi [2017-03-03] [Legacy]
FF HKU\S-1-5-21-632860548-1775735820-415820443-1000\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_32_0_0_101.dll [2018-12-05] ()
FF Plugin: @java.com/DTPlugin,version=11.191.2 -> C:\Program Files\Java\jre1.8.0_191\bin\dtplugin\npDeployJava1.dll [2018-12-01] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.191.2 -> C:\Program Files\Java\jre1.8.0_191\bin\plugin2\npjp2.dll [2018-12-01] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_101.dll [2018-12-05] ()
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @Sibelius.com/Scorch Plugin,version=6.2.0.88 -> C:\Program Files (x86)\Sibelius Software\Scorch\npsibelius.dll [2013-03-11] ()
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.23\npGoogleUpdate3.dll [2018-12-18] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.23\npGoogleUpdate3.dll [2018-12-18] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2011-09-28] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-12-04] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-632860548-1775735820-415820443-1000: @tools.google.com/Google Update;version=3 -> C:\Users\Barley\AppData\Local\Google\Update\1.3.33.23\npGoogleUpdate3.dll [2018-12-18] (Google Inc.)
FF Plugin HKU\S-1-5-21-632860548-1775735820-415820443-1000: @tools.google.com/Google Update;version=9 -> C:\Users\Barley\AppData\Local\Google\Update\1.3.33.23\npGoogleUpdate3.dll [2018-12-18] (Google Inc.)
FF Plugin HKU\S-1-5-21-632860548-1775735820-415820443-1000: CouponNetwork.com/CMDUniversalCouponPrintActivator -> C:\Users\Barley\AppData\Roaming\CATALI~1\NPBCSK~1.DLL [No File]
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\browser\plugins\npMozCouponPrinter.dll [2015-09-18] (Coupons, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Barley\AppData\Roaming\mozilla\plugins\npatgpc.dll [2015-11-18] (Cisco WebEx LLC)
 
Chrome: 
=======
CHR DefaultProfile: Profile 1
CHR HomePage: Profile 1 -> hxxp://www.google.com/
CHR StartupUrls: Profile 1 -> "hxxp://www.google.com/"
CHR NewTab: Profile 1 ->  Not-active:"chrome-extension://bkpkokkapfiigghcbhkblnngjlcccckf/index.html", Not-active:"chrome-extension://lpdcomiegbcchfdacgnkemnicebaodne/newtab/newtab.html", Not-active:"chrome-extension://gbioooacocedmkdadhinnkjonienkfbe/stubby.html", Not-active:"chrome-extension://dpgfhhkchdfegbdmjginkcffgjncmboh/stubby.html"
CHR Profile: C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Guest Profile [2018-12-23]
CHR Profile: C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1 [2018-12-24]
CHR Extension: (Share to Classroom) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\adokjfanaflbkibffcbhihgihpgijcei [2018-12-24]
CHR Extension: (Bejeweled) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\adpkifcfcacgmnggcbpbjbkdijciiigm [2015-04-15]
CHR Extension: (Asus Download Master) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\akidbpofokakpmmabjlpcgplfmbmcemj [2015-04-15]
CHR Extension: (Docs) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-12]
CHR Extension: (Google Drive) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21]
CHR Extension: (Destiny Discover) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bbhkckkafippkgeicobhgafkioeblebh [2018-12-24]
CHR Extension: (Quizlet) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bgofflgeghkhocbociocnckocbjmomjh [2018-12-24]
CHR Extension: (Desmos Graphing Calculator) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bhdheahnajobgndecdbggfmcojekgdko [2018-12-24]
CHR Extension: (YouTube) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-25]
CHR Extension: (GeoGebra Classic) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bnbaboaihhkjoaolfnfoablhllahjnee [2018-12-24]
CHR Extension: (Norton Security Toolbar) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\cjabmdjcfcfdmffimndhafhblfmpjdpe [2018-11-19]
CHR Extension: (Google Search) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27]
CHR Extension: (Fancy Pants 3) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ddmbgnlndmdpfggbojljojamjkkikeka [2015-04-15]
CHR Extension: (Vernier Graphical Analysis) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\dncgedbnidfkppmdgfgidcepclnokpkb [2018-12-24]
CHR Extension: (Pear Deck) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\dnloadmamaeibnaadmfdfelflmmnbajd [2018-12-24]
CHR Extension: (FromDocToPDF) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\dpgfhhkchdfegbdmjginkcffgjncmboh [2018-12-10]
CHR Extension: (App for Instagram) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ebmdoffeooapnmjcnidddmhancpfpjab [2018-12-12]
CHR Extension: (Destiny Discover) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eebnbmbhdfnfhfhigoklhaklkodghbla [2018-12-24]
CHR Extension: (Adobe Acrobat) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-03-15]
CHR Extension: (PicMonkey) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fgdgokchhicmaiacmgegjnppjkgogdhm [2018-12-24]
CHR Extension: (OnlineMapFinder) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gbioooacocedmkdadhinnkjonienkfbe [2018-12-10]
CHR Extension: (Google Docs Offline) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-08-14]
CHR Extension: (goo.gl URL Shortener (Unofficial)) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iblijlcdoidgdpfknkckljiocdbnlagk [2018-12-24]
CHR Extension: (Norton Identity Safe) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iikflkcanblccfahdhdonehdalibjnif [2015-02-07]
CHR Extension: (Voice Recorder) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\jehegmanppiacmmpiifhjalpkigpcida [2018-12-24]
CHR Extension: (Cisco Webex Extension) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\jlhmfgmfgeifomenelglieieghnjghma [2018-07-05]
CHR Extension: (mydlink services plugin) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ldibdoepbjbkkcbgndfljnphngpglhbb [2016-01-01]
CHR Extension: (Lightspeed User Agent) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lnidfclfgppmpldkkchcpoegjlcbaekc [2018-12-24] [UpdateUrl: hxxps://lsrelay-extensions-staging.s3.amazonaws.com/chrome_ua/1bf15dff521aff9f15e160f73e7a18ab5206eb1bfa7eb5b71b5d983899285034/UserAgent.xml] <==== ATTENTION
CHR Extension: (FromDocToPDF) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mallpejgeafdahhflmliiahjdpgbegpk [2018-12-10]
CHR Extension: (Google Classroom) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mfhehppjhmmnlfbbopchdfldgimhfhfk [2018-12-24]
CHR Extension: (Socrative Student) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nblhpecglllndfihipmpdoikimcmgkha [2018-12-24]
CHR Extension: (ScanQR) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nihhbejdflkeingkkpakffdlmepaeaah [2018-12-24]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-04]
CHR Extension: (Gmail) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-28]
CHR Extension: (Padlet) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ppckapbnfhikdajgehibjapcohbaomhd [2018-12-24]
CHR Profile: C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 2 [2018-12-23]
CHR Extension: (Slides) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-12-06]
CHR Extension: (Docs) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aohghmighlieiainnegkcijnfilokake [2018-12-06]
CHR Extension: (Google Drive) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-08-18]
CHR Extension: (YouTube) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-12-06]
CHR Extension: (Norton Security Toolbar) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\cjabmdjcfcfdmffimndhafhblfmpjdpe [2015-08-18]
CHR Extension: (Google Search) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-08-18]
CHR Extension: (Adobe Acrobat) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2018-12-06]
CHR Extension: (Sheets) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-12-06]
CHR Extension: (Google Docs Offline) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-12-06]
CHR Extension: (Norton Identity Safe) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\iikflkcanblccfahdhdonehdalibjnif [2015-08-18]
CHR Extension: (AVG SafePrice | Comparison, deals, coupons) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\mbckjcfnjmoiinpgddefodcighgikkgn [2018-12-06]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-12-06]
CHR Extension: (Amazon.com Search Settings) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ooebgdicanjhnamfmdlmlbcnkgehkkmf [2018-12-06]
CHR Extension: (Gmail) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-08-18]
CHR Extension: (Chrome Media Router) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-12-06]
CHR Profile: C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3 [2018-12-23]
CHR Extension: (Slides) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-12-06]
CHR Extension: (Entanglement Web App) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\aciahcmjmecflokailenpkdchphgkefd [2018-12-06]
CHR Extension: (Docs) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\aohghmighlieiainnegkcijnfilokake [2018-12-06]
CHR Extension: (Google Drive) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-12-06]
CHR Extension: (YouTube) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-12-06]
CHR Extension: (Adblock Plus) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2018-12-06]
CHR Extension: (Pushbullet) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\chlffgpmiacpedhhbkiomidkjlcfhogd [2018-12-06]
CHR Extension: (Norton Security Toolbar) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\cjabmdjcfcfdmffimndhafhblfmpjdpe [2018-12-06]
CHR Extension: (Spotify - Music for every moment) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\cnkjkdjlofllcpbemipjbcpfnglbgieh [2018-12-06]
CHR Extension: (Adobe Acrobat) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2018-12-06]
CHR Extension: (Photo Zoom for Facebook) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\elioihkkcdgakfbahdoddophfngopipi [2018-12-06]
CHR Extension: (Sheets) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-12-06]
CHR Extension: (Google Docs Offline) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-12-08]
CHR Extension: (AVG SafePrice | Comparison, deals, coupons) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\mbckjcfnjmoiinpgddefodcighgikkgn [2018-12-06]
CHR Extension: (Poppit!) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\mcbkbpnkkkipelfledbfocopglifcfmi [2018-12-06]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-12-06]
CHR Extension: (Amazon.com Search Settings) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\ooebgdicanjhnamfmdlmlbcnkgehkkmf [2018-12-06]
CHR Extension: (Gmail) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-12-06]
CHR Extension: (Chrome Media Router) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-12-07]
CHR Profile: C:\Users\Barley\AppData\Local\Google\Chrome\User Data\System Profile [2018-12-23]
CHR Extension: (Google Slides) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-05-30]
CHR Extension: (Google Docs) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\aohghmighlieiainnegkcijnfilokake [2015-05-30]
CHR Extension: (Google Drive) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-05-30]
CHR Extension: (YouTube) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-05-30]
CHR Extension: (Google Search) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-05-30]
CHR Extension: (Google Sheets) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-05-30]
CHR Extension: (Gmail) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-05-30]
CHR HKLM\…\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\Exts\Chrome.crx
CHR HKLM\…\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\Exts\Chrome.crx
CHR HKLM-x32\…\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [mbckjcfnjmoiinpgddefodcighgikkgn] - hxxps://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-09-22] (Apple Inc.)
R2 AVG Antivirus; C:\Program Files (x86)\AVG\Antivirus\AVGSvc.exe [324048 2018-11-15] (AVG Technologies CZ, s.r.o.)
R3 avgbIDSAgent; C:\Program Files (x86)\AVG\Antivirus\x64\aswidsagenta.exe [8237160 2018-11-15] (AVG Technologies CZ, s.r.o.)
R3 BrYNSvc; C:\Program Files (x86)\Browny02\BrYNSvc.exe [289792 2014-10-23] (Brother Industries, Ltd.) [File not signed]
R2 CalendarSynchService; C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Calendar\Service\GCalService.exe [16384 2011-08-16] (Hewlett-Packard) [File not signed]
R2 DigitalWave.Update.Service; C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe [440808 2017-01-20] (Digital Wave Ltd.)
R2 Garmin Core Update Service; C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [250712 2013-12-13] (Garmin Ltd or its subsidiaries)
S3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [249344 2009-09-20] (Hewlett-Packard Co.) [File not signed]
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [347512 2018-12-06] (HP Inc.)
R2 HPTouchpointAnalyticsService; C:\Program Files\HP\HP Touchpoint Analytics Client\TouchpointAnalyticsClientService.exe [332216 2017-11-22] (HP Inc.)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6347056 2018-09-19] (Malwarebytes)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2008-12-03] (Hewlett-Packard) [File not signed]
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-01] (Symantec Corporation)
R2 NortonSecurity; C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\NortonSecurity.exe [328648 2018-11-03] (Symantec Corporation)
R2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [1795136 2018-02-01] (PDF Complete Inc)
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2008-12-03] (Hewlett-Packard) [File not signed]
R2 RalinkRegistryWriter; C:\Program Files (x86)\Ralink\Common\RaRegistry.exe [372736 2012-01-13] (Ralink Technology, Corp.) [File not signed]
R2 RalinkRegistryWriter64; C:\Program Files (x86)\Ralink\Common\RaRegistry64.exe [447488 2012-01-13] (Ralink Technology, Corp.) [File not signed]
S2 RaMediaServer; C:\Program Files (x86)\Ralink\Common\RaMediaServer.exe [625728 2011-08-18] ()
R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1229528 2013-12-06] (Secunia)
R2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [662232 2013-12-06] (Secunia)
R2 STacSV; C:\Program Files\IDT\WDM\STacSV64.exe [311296 2012-03-30] (IDT, Inc.) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
R2 WirelessKB850NotificationService; C:\windows\system32\WirelessKB850NotificationService.exe [174256 2018-05-14] (Microsoft Corporation)
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R1 avgArPot; C:\windows\System32\drivers\avgArPot.sys [201504 2018-11-15] (AVG Technologies CZ, s.r.o.)
R1 avgbidsdriver; C:\windows\System32\drivers\avgbidsdrivera.sys [231104 2018-11-15] (AVG Technologies CZ, s.r.o.)
R0 avgbidsh; C:\windows\System32\drivers\avgbidsha.sys [202528 2018-11-15] (AVG Technologies CZ, s.r.o.)
R0 avgblog; C:\windows\System32\drivers\avgbloga.sys [346840 2018-11-15] (AVG Technologies CZ, s.r.o.)
R0 avgbuniv; C:\windows\System32\drivers\avgbuniva.sys [59744 2018-11-15] (AVG Technologies CZ, s.r.o.)
S3 avgHwid; C:\windows\System32\drivers\avgHwid.sys [46648 2018-11-15] (AVG Technologies CZ, s.r.o.)
R1 avgKbd; C:\windows\System32\drivers\avgKbd.sys [42552 2018-11-15] (AVG Technologies CZ, s.r.o.)
R2 avgMonFlt; C:\windows\System32\drivers\avgMonFlt.sys [163496 2018-11-15] (AVG Technologies CZ, s.r.o.)
R1 avgRdr; C:\windows\System32\drivers\avgRdr2.sys [112040 2018-11-15] (AVG Technologies CZ, s.r.o.)
R0 avgRvrt; C:\windows\System32\drivers\avgRvrt.sys [87680 2018-11-15] (AVG Technologies CZ, s.r.o.)
R1 avgSnx; C:\windows\System32\drivers\avgSnx.sys [1028920 2018-11-15] (AVG Technologies CZ, s.r.o.)
R1 avgSP; C:\windows\System32\drivers\avgSP.sys [469520 2018-11-15] (AVG Technologies CZ, s.r.o.)
R2 avgStm; C:\windows\System32\drivers\avgStm.sys [208712 2018-11-15] (AVG Technologies CZ, s.r.o.)
R0 avgVmm; C:\windows\System32\drivers\avgVmm.sys [380704 2018-11-15] (AVG Technologies CZ, s.r.o.)
R1 BHDrvx64; C:\Program Files (x86)\Norton Internet Security\NortonData\22.5.2.15\Definitions\BASHDefs\20181016.001\BHDrvx64.sys [1925104 2018-10-16] (Symantec Corporation)
R1 ccSet_NGC; C:\windows\System32\drivers\NGCx64\1610020.016\ccSetx64.sys [189120 2018-11-03] (Symantec Corporation)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [515776 2018-10-20] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [153280 2018-10-22] (Symantec Corporation)
R1 IDSVia64; C:\Program Files (x86)\Norton Internet Security\NortonData\22.5.2.15\Definitions\IPSDefs\20181019.061\IDSvia64.sys [1305072 2018-10-19] (Symantec Corporation)
R3 MBAMSwissArmy; C:\windows\System32\Drivers\mbamswissarmy.sys [260384 2018-12-24] (Malwarebytes)
S3 PSI; C:\windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2013-12-06] (Secunia)
R3 SRTSP; C:\windows\System32\drivers\NGCx64\1610020.016\SRTSP64.SYS [847344 2018-11-03] (Symantec Corporation)
R1 SRTSPX; C:\windows\System32\drivers\NGCx64\1610020.016\SRTSPX64.SYS [49648 2018-11-03] (Symantec Corporation)
R0 SymEFASI; C:\windows\System32\drivers\NGCx64\1610020.016\SYMEFASI64.SYS [1969328 2018-11-03] (Symantec Corporation)
R3 SymEvent; C:\windows\system32\Drivers\SYMEVENT64x86.SYS [99920 2018-06-17] (Symantec Corporation)
S4 SymEvnt; C:\Program Files (x86)\Norton Internet Security\NortonData\22.5.2.15\SymPlatform\SymEvnt.sys [114256 2018-09-27] (Symantec Corporation)
R1 SymIRON; C:\windows\System32\drivers\NGCx64\1610020.016\Ironx64.SYS [308416 2018-11-03] (Symantec Corporation)
R1 SymNetS; C:\windows\System32\drivers\NGCx64\1610020.016\symnets.sys [567024 2018-11-03] (Symantec Corporation)
S3 wpCtrlDrv_NGC; C:\windows\System32\drivers\NGCx64\1610020.016\wpCtrlDrv.sys [1011056 2018-11-03] (Symantec Corporation)
S1 AntiLog32; \??\C:\windows\system32\drivers\AntiLog64.sys [X]
S3 NAVENG; \??\C:\Program Files (x86)\Norton Internet Security\NortonData\22.5.2.15\Definitions\SDSDefs\20160823.022\ENG64.SYS [X]
S3 NAVEX15; \??\C:\Program Files (x86)\Norton Internet Security\NortonData\22.5.2.15\Definitions\SDSDefs\20160823.022\EX64.SYS [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2018-12-24 15:14 - 2018-12-24 15:14 - 000260384 _____ (Malwarebytes) C:\windows\system32\Drivers\mbamswissarmy.sys
2018-12-24 13:20 - 2018-12-24 13:20 - 007320272 _____ (Malwarebytes) C:\Users\Barley\Desktop\adwcleaner_7.2.6.0(3).exe
2018-12-24 13:09 - 2018-12-24 13:09 - 000000000 ____D C:\windows\System32\Tasks\Remediation
2018-12-24 12:01 - 2018-12-24 12:01 - 007320272 _____ (Malwarebytes) C:\Users\Barley\Desktop\adwcleaner_7.2.6.0(2).exe
2018-12-23 22:34 - 2018-12-24 00:13 - 000000239 _____ C:\Users\Barley\Desktop\Search.txt
2018-12-23 22:32 - 2018-12-24 15:17 - 000000000 ____D C:\Users\Barley\Desktop\FRST-OlderVersion
2018-12-23 12:22 - 2018-12-23 12:22 - 000002422 _____ C:\Users\Barley\Desktop\Forensics_181223-122219.txt
2018-12-23 12:11 - 2018-12-23 12:11 - 000000000 ____D C:\ProgramData\Emsisoft
2018-12-23 12:07 - 2018-12-23 12:22 - 000000000 ____D C:\EEK
2018-12-23 12:04 - 2018-12-23 12:06 - 355354792 _____ C:\Users\Barley\Downloads\EmsisoftEmergencyKit.exe
2018-12-23 12:00 - 2018-12-23 12:00 - 000001489 _____ C:\Users\Barley\Desktop\Malwarebytestxt1.txt
2018-12-23 11:43 - 2018-12-23 11:43 - 000001869 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2018-12-23 11:43 - 2018-12-23 11:43 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2018-12-23 11:43 - 2018-09-11 13:18 - 000152688 _____ (Malwarebytes) C:\windows\system32\Drivers\mbae64.sys
2018-12-23 11:42 - 2018-12-23 11:42 - 080022264 _____ (Malwarebytes ) C:\Users\Barley\Downloads\mb3-setup-1878.1878-3.6.1.2711.exe
2018-12-23 01:02 - 2018-12-23 01:02 - 000000256 _____ C:\Users\Barley\Documents\cc_20181223_010208.reg
2018-12-23 00:58 - 2018-12-23 00:59 - 000525076 _____ C:\Users\Barley\Documents\cc_20181223_005852.reg
2018-12-23 00:54 - 2018-12-23 00:54 - 019299120 _____ (Piriform Software Ltd) C:\Users\Barley\Downloads\ccsetup551.exe
2018-12-23 00:54 - 2018-12-23 00:54 - 000003870 _____ C:\windows\System32\Tasks\CCleaner Update
2018-12-23 00:54 - 2018-12-23 00:54 - 000002812 _____ C:\windows\System32\Tasks\CCleanerSkipUAC
2018-12-23 00:54 - 2018-12-23 00:54 - 000000824 _____ C:\Users\Public\Desktop\CCleaner.lnk
2018-12-23 00:54 - 2018-12-23 00:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2018-12-23 00:54 - 2018-12-23 00:54 - 000000000 ____D C:\Program Files\CCleaner
2018-12-23 00:45 - 2018-12-23 00:46 - 004707504 _____ (hxxp://www.specialuninstaller.com/ ) C:\Users\Barley\Downloads\SpecialUninstaller_setup.exe
2018-12-23 00:03 - 2018-12-23 00:03 - 000000000 ____D C:\ProgramData\Reason
2018-12-22 23:10 - 2018-12-22 23:10 - 000000000 ____D C:\Program Files\Reason
2018-12-22 12:08 - 2018-12-23 10:38 - 000000860 _____ C:\Users\Public\Desktop\RogueKiller.lnk
2018-12-22 12:08 - 2018-12-23 10:38 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
2018-12-22 12:08 - 2018-12-22 13:07 - 000000000 ____D C:\ProgramData\RogueKiller
2018-12-22 12:07 - 2018-12-23 10:38 - 000000000 ____D C:\Program Files\RogueKiller
2018-12-22 12:06 - 2018-12-22 12:06 - 029155072 _____ (Adlice Software ) C:\Users\Barley\Desktop\RogueKiller_setup.exe
2018-12-22 12:05 - 2018-12-22 12:06 - 029155072 _____ (Adlice Software ) C:\Users\Barley\Downloads\RogueKiller_setup.exe
2018-12-22 11:59 - 2018-12-22 11:59 - 007320272 _____ (Malwarebytes) C:\Users\Barley\Desktop\adwcleaner_7.2.6.0(1).exe
2018-12-22 11:32 - 2018-12-22 11:32 - 007320272 _____ (Malwarebytes) C:\Users\Barley\Desktop\adwcleaner_7.2.6.0.exe
2018-12-22 11:30 - 2018-12-22 11:30 - 007320272 _____ (Malwarebytes) C:\Users\Barley\Downloads\adwcleaner_7.2.6.0.exe
2018-12-22 11:29 - 2018-12-22 11:35 - 000000000 ____D C:\AdwCleaner
2018-12-22 11:29 - 2018-12-22 11:29 - 007592144 _____ (Malwarebytes) C:\Users\Barley\Desktop\AdwCleaner.exe
2018-12-22 11:13 - 2018-12-22 11:16 - 000022243 _____ C:\Users\Barley\Desktop\Fixlog.txt
2018-12-21 22:55 - 2018-12-22 11:12 - 000068782 _____ C:\Users\Barley\Desktop\Addition.txt
2018-12-21 22:51 - 2018-12-24 15:18 - 000038953 _____ C:\Users\Barley\Desktop\FRST.txt
2018-12-21 22:50 - 2018-12-24 15:17 - 002421760 _____ (Farbar) C:\Users\Barley\Desktop\FRST64.exe
2018-12-21 22:50 - 2018-12-23 22:32 - 000000000 ____D C:\FRST
2018-12-21 22:48 - 2018-12-21 22:48 - 002420224 _____ (Farbar) C:\Users\Barley\Downloads\FRST64.exe
2018-12-21 22:42 - 2018-12-21 22:42 - 000001845 _____ C:\Users\Barley\Desktop\aswMBR.txt
2018-12-21 22:42 - 2018-12-21 22:42 - 000000512 _____ C:\Users\Barley\Desktop\MBR.dat
2018-12-21 22:31 - 2018-12-21 22:31 - 005198336 _____ (AVAST Software) C:\Users\Barley\Downloads\aswMBR (2).exe
2018-12-21 22:31 - 2018-12-21 22:22 - 005198336 _____ (AVAST Software) C:\Users\Barley\Desktop\aswMBR.exe
2018-12-21 22:25 - 2018-12-21 22:25 - 005198336 _____ (AVAST Software) C:\Users\Barley\Downloads\aswMBR (1).exe
2018-12-21 22:22 - 2018-12-21 22:22 - 005198336 _____ (AVAST Software) C:\Users\Barley\Downloads\aswMBR.exe
2018-12-21 16:19 - 2018-12-21 16:20 - 081227760 _____ (Malwarebytes ) C:\Users\Barley\Downloads\mb3-setup-consumer-3.6.1.2711-1.0.508-1.0.8211.exe
2018-12-20 23:07 - 2018-12-14 19:06 - 000397088 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2018-12-20 23:07 - 2018-12-14 18:14 - 000348760 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2018-12-20 23:07 - 2018-12-14 03:09 - 025736704 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2018-12-20 23:07 - 2018-12-14 03:01 - 002724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2018-12-20 23:07 - 2018-12-14 03:01 - 000004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2018-12-20 23:07 - 2018-12-14 02:51 - 002902016 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2018-12-20 23:07 - 2018-12-14 02:49 - 000417280 _____ (Microsoft Corporation) C:\windows\system32\html.iec
2018-12-20 23:07 - 2018-12-14 02:49 - 000066560 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2018-12-20 23:07 - 2018-12-14 02:49 - 000048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2018-12-20 23:07 - 2018-12-14 02:48 - 000576512 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2018-12-20 23:07 - 2018-12-14 02:48 - 000088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2018-12-20 23:07 - 2018-12-14 02:42 - 000054784 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2018-12-20 23:07 - 2018-12-14 02:41 - 000034304 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2018-12-20 23:07 - 2018-12-14 02:39 - 000615936 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2018-12-20 23:07 - 2018-12-14 02:38 - 000814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2018-12-20 23:07 - 2018-12-14 02:38 - 000790016 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2018-12-20 23:07 - 2018-12-14 02:38 - 000144384 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2018-12-20 23:07 - 2018-12-14 02:38 - 000116224 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2018-12-20 23:07 - 2018-12-14 02:36 - 005779456 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2018-12-20 23:07 - 2018-12-14 02:33 - 000969216 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2018-12-20 23:07 - 2018-12-14 02:30 - 000489984 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2018-12-20 23:07 - 2018-12-14 02:24 - 000087552 _____ (Microsoft Corporation) C:\windows\system32\tdc.ocx
2018-12-20 23:07 - 2018-12-14 02:24 - 000077824 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2018-12-20 23:07 - 2018-12-14 02:23 - 000107520 _____ (Microsoft Corporation) C:\windows\system32\inseng.dll
2018-12-20 23:07 - 2018-12-14 02:21 - 000199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2018-12-20 23:07 - 2018-12-14 02:20 - 000092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2018-12-20 23:07 - 2018-12-14 02:18 - 000315392 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2018-12-20 23:07 - 2018-12-14 02:17 - 000152064 _____ (Microsoft Corporation) C:\windows\system32\occache.dll
2018-12-20 23:07 - 2018-12-14 02:09 - 000262144 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll
2018-12-20 23:07 - 2018-12-14 02:06 - 000809472 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2018-12-20 23:07 - 2018-12-14 02:06 - 000728064 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2018-12-20 23:07 - 2018-12-14 02:05 - 001359360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2018-12-20 23:07 - 2018-12-14 02:04 - 002136064 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2018-12-20 23:07 - 2018-12-14 02:02 - 015284736 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2018-12-20 23:07 - 2018-12-14 01:58 - 020280832 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2018-12-20 23:07 - 2018-12-14 01:57 - 004859904 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2018-12-20 23:07 - 2018-12-14 01:51 - 002724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2018-12-20 23:07 - 2018-12-14 01:45 - 001555968 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2018-12-20 23:07 - 2018-12-14 01:41 - 000498176 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2018-12-20 23:07 - 2018-12-14 01:41 - 000062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2018-12-20 23:07 - 2018-12-14 01:40 - 000341504 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec
2018-12-20 23:07 - 2018-12-14 01:40 - 000047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2018-12-20 23:07 - 2018-12-14 01:39 - 000064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2018-12-20 23:07 - 2018-12-14 01:38 - 002295808 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2018-12-20 23:07 - 2018-12-14 01:35 - 000047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2018-12-20 23:07 - 2018-12-14 01:35 - 000030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2018-12-20 23:07 - 2018-12-14 01:34 - 000800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2018-12-20 23:07 - 2018-12-14 01:34 - 000476160 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2018-12-20 23:07 - 2018-12-14 01:33 - 000663040 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2018-12-20 23:07 - 2018-12-14 01:33 - 000115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2018-12-20 23:07 - 2018-12-14 01:32 - 000620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2018-12-20 23:07 - 2018-12-14 01:26 - 000416256 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2018-12-20 23:07 - 2018-12-14 01:23 - 000060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2018-12-20 23:07 - 2018-12-14 01:22 - 000091136 _____ (Microsoft Corporation) C:\windows\SysWOW64\inseng.dll
2018-12-20 23:07 - 2018-12-14 01:22 - 000073216 _____ (Microsoft Corporation) C:\windows\SysWOW64\tdc.ocx
2018-12-20 23:07 - 2018-12-14 01:20 - 000168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2018-12-20 23:07 - 2018-12-14 01:19 - 000279040 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2018-12-20 23:07 - 2018-12-14 01:19 - 000076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2018-12-20 23:07 - 2018-12-14 01:18 - 004494848 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2018-12-20 23:07 - 2018-12-14 01:18 - 000130048 _____ (Microsoft Corporation) C:\windows\SysWOW64\occache.dll
2018-12-20 23:07 - 2018-12-14 01:14 - 013681152 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2018-12-20 23:07 - 2018-12-14 01:13 - 000230400 _____ (Microsoft Corporation) C:\windows\SysWOW64\webcheck.dll
2018-12-20 23:07 - 2018-12-14 01:11 - 002059776 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2018-12-20 23:07 - 2018-12-14 01:11 - 000696320 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2018-12-20 23:07 - 2018-12-14 01:10 - 001155072 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2018-12-20 23:07 - 2018-12-14 00:58 - 004386816 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2018-12-20 23:07 - 2018-12-14 00:54 - 001330176 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2018-12-20 23:07 - 2018-12-14 00:52 - 000710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2018-12-11 14:16 - 2018-12-05 21:39 - 003227648 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2018-12-11 14:16 - 2018-11-28 17:02 - 014635520 _____ (Microsoft Corporation) C:\windows\system32\wmp.dll
2018-12-11 14:16 - 2018-11-28 17:02 - 012574720 _____ (Microsoft Corporation) C:\windows\system32\wmploc.DLL
2018-12-11 14:16 - 2018-11-28 17:02 - 000009728 _____ (Microsoft Corporation) C:\windows\system32\spwmp.dll
2018-12-11 14:16 - 2018-11-28 17:02 - 000005632 _____ (Microsoft Corporation) C:\windows\system32\msdxm.ocx
2018-12-11 14:16 - 2018-11-28 17:02 - 000005632 _____ (Microsoft Corporation) C:\windows\system32\dxmasf.dll
2018-12-11 14:16 - 2018-11-28 16:50 - 012574208 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmploc.DLL
2018-12-11 14:16 - 2018-11-28 16:50 - 011411968 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmp.dll
2018-12-11 14:16 - 2018-11-28 16:38 - 000008192 _____ (Microsoft Corporation) C:\windows\SysWOW64\spwmp.dll
2018-12-11 14:16 - 2018-11-28 16:38 - 000004608 _____ (Microsoft Corporation) C:\windows\SysWOW64\msdxm.ocx
2018-12-11 14:16 - 2018-11-28 16:38 - 000004608 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxmasf.dll
2018-12-11 14:16 - 2018-11-11 12:19 - 000631680 _____ (Microsoft Corporation) C:\windows\system32\winresume.efi
2018-12-11 14:16 - 2018-11-11 12:02 - 000262376 _____ (Microsoft Corporation) C:\windows\system32\hal.dll
2018-12-11 14:16 - 2018-11-11 12:01 - 005551848 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2018-12-11 14:16 - 2018-11-11 12:01 - 000708328 _____ (Microsoft Corporation) C:\windows\system32\winload.efi
2018-12-11 14:16 - 2018-11-11 12:01 - 000366824 _____ (Microsoft Corporation) C:\windows\system32\Drivers\msrpc.sys
2018-12-11 14:16 - 2018-11-11 12:01 - 000154856 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2018-12-11 14:16 - 2018-11-11 12:01 - 000095464 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2018-12-11 14:16 - 2018-11-11 12:00 - 001664360 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 001461760 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 001211904 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 001163264 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000731648 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000503808 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000419840 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000405504 _____ (Microsoft Corporation) C:\windows\system32\gdi32.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000361984 _____ (Microsoft Corporation) C:\windows\system32\wow64win.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000345600 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000316928 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000312320 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000215552 _____ (Microsoft Corporation) C:\windows\system32\winsrv.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000210432 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000190464 _____ (Microsoft Corporation) C:\windows\system32\rpchttp.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000135680 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000094208 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000063488 _____ (Microsoft Corporation) C:\windows\system32\setbcdlocale.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000050176 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000028672 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000016384 _____ (Microsoft Corporation) C:\windows\system32\ntvdm64.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000013312 _____ (Microsoft Corporation) C:\windows\system32\wow64cpu.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000880640 _____ (Microsoft Corporation) C:\windows\system32\advapi32.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000690688 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000463872 _____ (Microsoft Corporation) C:\windows\system32\certcli.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000123904 _____ (Microsoft Corporation) C:\windows\system32\bcrypt.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000059904 _____ (Microsoft Corporation) C:\windows\system32\appidapi.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000044032 _____ (Microsoft Corporation) C:\windows\system32\csrsrv.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000043520 _____ (Microsoft Corporation) C:\windows\system32\cryptbase.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000034816 _____ (Microsoft Corporation) C:\windows\system32\appidsvc.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000006656 _____ (Microsoft Corporation) C:\windows\system32\apisetschema.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000006144 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000005120 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:49 - 004054760 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
2018-12-11 14:16 - 2018-11-11 11:49 - 003960040 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
2018-12-11 14:16 - 2018-11-11 11:47 - 001314104 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
2018-12-11 14:16 - 2018-11-11 11:45 - 001114112 _____ (Microsoft Corporation) C:\windows\SysWOW64\kernel32.dll
2018-12-11 14:16 - 2018-11-11 11:45 - 000666112 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpcrt4.dll
2018-12-11 14:16 - 2018-11-11 11:45 - 000554496 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2018-12-11 14:16 - 2018-11-11 11:45 - 000313344 _____ (Microsoft Corporation) C:\windows\SysWOW64\gdi32.dll
2018-12-11 14:16 - 2018-11-11 11:45 - 000275968 _____ (Microsoft Corporation) C:\windows\SysWOW64\KernelBase.dll
2018-12-11 14:16 - 2018-11-11 11:45 - 000261120 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2018-12-11 14:16 - 2018-11-11 11:45 - 000254464 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2018-12-11 14:16 - 2018-11-11 11:45 - 000223232 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
2018-12-11 14:16 - 2018-11-11 11:45 - 000172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
2018-12-11 14:16 - 2018-11-11 11:45 - 000146432 _____ (Microsoft Corporation) C:\windows\SysWOW64\msaudite.dll
2018-12-11 14:16 - 2018-11-11 11:45 - 000141312 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpchttp.dll
2018-12-11 14:16 - 2018-11-11 11:45 - 000096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
2018-12-11 14:16 - 2018-11-11 11:45 - 000082944 _____ (Microsoft Corporation) C:\windows\SysWOW64\bcrypt.dll
2018-12-11 14:16 - 2018-11-11 11:45 - 000070144 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2018-12-11 14:16 - 2018-11-11 11:45 - 000060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\msobjs.dll
2018-12-11 14:16 - 2018-11-11 11:45 - 000043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\srclient.dll
2018-12-11 14:16 - 2018-11-11 11:45 - 000022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
2018-12-11 14:16 - 2018-11-11 11:45 - 000005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000690688 _____ (Microsoft Corporation) C:\windows\SysWOW64\adtschema.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000644096 _____ (Microsoft Corporation) C:\windows\SysWOW64\advapi32.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000342528 _____ (Microsoft Corporation) C:\windows\SysWOW64\certcli.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000050688 _____ (Microsoft Corporation) C:\windows\SysWOW64\appidapi.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\apisetschema.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000005120 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:25 - 000148480 _____ (Microsoft Corporation) C:\windows\system32\appidpolicyconverter.exe
2018-12-11 14:16 - 2018-11-11 11:25 - 000062464 _____ (Microsoft Corporation) C:\windows\system32\Drivers\appid.sys
2018-12-11 14:16 - 2018-11-11 11:25 - 000017920 _____ (Microsoft Corporation) C:\windows\system32\appidcertstorecheck.exe
2018-12-11 14:16 - 2018-11-11 11:24 - 000064000 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe
2018-12-11 14:16 - 2018-11-11 11:20 - 000338432 _____ (Microsoft Corporation) C:\windows\system32\conhost.exe
2018-12-11 14:16 - 2018-11-11 11:20 - 000129024 _____ (Microsoft Corporation) C:\windows\system32\Drivers\videoprt.sys
2018-12-11 14:16 - 2018-11-11 11:19 - 000296960 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe
2018-12-11 14:16 - 2018-11-11 11:19 - 000050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\auditpol.exe
2018-12-11 14:16 - 2018-11-11 11:16 - 000291328 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb10.sys
2018-12-11 14:16 - 2018-11-11 11:16 - 000160768 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb.sys
2018-12-11 14:16 - 2018-11-11 11:16 - 000129536 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb20.sys
2018-12-11 14:16 - 2018-11-11 11:15 - 000112640 _____ (Microsoft Corporation) C:\windows\system32\smss.exe
2018-12-11 14:16 - 2018-11-11 11:15 - 000064512 _____ (Microsoft Corporation) C:\windows\system32\Drivers\amdk8.sys
2018-12-11 14:16 - 2018-11-11 11:15 - 000062464 _____ (Microsoft Corporation) C:\windows\system32\Drivers\intelppm.sys
2018-12-11 14:16 - 2018-11-11 11:15 - 000060928 _____ (Microsoft Corporation) C:\windows\system32\Drivers\processr.sys
2018-12-11 14:16 - 2018-11-11 11:15 - 000060928 _____ (Microsoft Corporation) C:\windows\system32\Drivers\amdppm.sys
2018-12-11 14:16 - 2018-11-11 11:15 - 000030720 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2018-12-11 14:16 - 2018-11-11 11:15 - 000025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe
2018-12-11 14:16 - 2018-11-11 11:15 - 000014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll
2018-12-11 14:16 - 2018-11-11 11:15 - 000007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe
2018-12-11 14:16 - 2018-11-11 11:15 - 000002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe
2018-12-11 14:16 - 2018-11-11 11:14 - 000036352 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptbase.dll
2018-12-11 14:16 - 2018-11-11 11:13 - 000006144 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:13 - 000004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:13 - 000003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:13 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2018-12-11 14:16 - 2018-11-08 11:58 - 002009600 _____ (Microsoft Corporation) C:\windows\system32\msxml6.dll
2018-12-11 14:16 - 2018-11-08 11:58 - 001889280 _____ (Microsoft Corporation) C:\windows\system32\msxml3.dll
2018-12-11 14:16 - 2018-11-08 11:58 - 000002048 _____ (Microsoft Corporation) C:\windows\system32\msxml6r.dll
2018-12-11 14:16 - 2018-11-08 11:58 - 000002048 _____ (Microsoft Corporation) C:\windows\system32\msxml3r.dll
2018-12-11 14:16 - 2018-11-08 11:43 - 001391104 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml6.dll
2018-12-11 14:16 - 2018-11-08 11:43 - 001241088 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3.dll
2018-12-11 14:16 - 2018-11-08 11:43 - 000002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml6r.dll
2018-12-11 14:16 - 2018-11-08 11:43 - 000002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3r.dll
2018-12-11 14:16 - 2018-11-05 23:36 - 000002048 _____ (Microsoft Corporation) C:\windows\system32\tzres.dll
2018-12-11 14:16 - 2018-11-05 23:20 - 000002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\tzres.dll
2018-12-11 14:16 - 2018-10-06 11:03 - 000383720 _____ (Adobe Systems Incorporated) C:\windows\system32\atmfd.dll
2018-12-11 14:16 - 2018-10-06 10:59 - 000151552 _____ (Microsoft Corporation) C:\windows\system32\t2embed.dll
2018-12-11 14:16 - 2018-10-06 10:59 - 000041472 _____ (Microsoft Corporation) C:\windows\system32\lpk.dll
2018-12-11 14:16 - 2018-10-06 10:58 - 000100864 _____ (Microsoft Corporation) C:\windows\system32\fontsub.dll
2018-12-11 14:16 - 2018-10-06 10:58 - 000046080 _____ (Adobe Systems) C:\windows\system32\atmlib.dll
2018-12-11 14:16 - 2018-10-06 10:58 - 000014336 _____ (Microsoft Corporation) C:\windows\system32\dciman32.dll
2018-12-11 14:16 - 2018-10-06 10:50 - 000309480 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\atmfd.dll
2018-12-11 14:16 - 2018-10-06 10:44 - 000111616 _____ (Microsoft Corporation) C:\windows\SysWOW64\t2embed.dll
2018-12-11 14:16 - 2018-10-06 10:44 - 000025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\lpk.dll
2018-12-11 14:16 - 2018-10-06 10:43 - 000071680 _____ (Microsoft Corporation) C:\windows\SysWOW64\fontsub.dll
2018-12-11 14:16 - 2018-10-06 10:43 - 000010240 _____ (Microsoft Corporation) C:\windows\SysWOW64\dciman32.dll
2018-12-11 14:16 - 2018-10-06 10:16 - 000034304 _____ (Adobe Systems) C:\windows\SysWOW64\atmlib.dll
2018-12-10 02:38 - 2018-12-10 02:38 - 000000000 ____D C:\Users\Barley\AppData\Local\mbam
2018-12-10 02:37 - 2018-12-10 02:37 - 000000000 ____D C:\Users\Barley\AppData\Local\mbamtray
2018-12-10 02:37 - 2018-12-10 02:37 - 000000000 ____D C:\Program Files\Malwarebytes
2018-12-06 20:38 - 2018-12-22 11:14 - 000002242 _____ C:\Users\Barley\Desktop\Chris - Chrome.lnk
2018-12-01 08:58 - 2018-12-01 08:58 - 000110968 _____ (Oracle Corporation) C:\windows\system32\WindowsAccessBridge-64.dll
2018-12-01 08:58 - 2018-12-01 08:58 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2018-12-01 08:57 - 2018-12-01 08:57 - 000000000 ____D C:\Program Files\Java
2018-12-01 08:56 - 2018-12-01 08:57 - 074618232 _____ (Oracle Corporation) C:\Users\Barley\Downloads\jre-8u191-windows-x64.exe
2018-12-01 08:52 - 2018-12-01 08:52 - 000000954 _____ C:\Users\Barley\Downloads\Coupon_Package_CommonKindness (5).jnlp
2018-11-30 10:40 - 2018-11-30 10:41 - 002204152 _____ (Valassis) C:\Users\Barley\Downloads\P@H_prod308-piPSZUcb.exe
2018-11-25 12:07 - 2018-11-25 12:07 - 000000000 ____D C:\Users\Barley\AppData\Local\Nuance
2018-11-25 12:07 - 2018-11-25 12:07 - 000000000 ____D C:\Users\Barley\AppData\Local\Brother
2018-11-25 12:07 - 2018-11-25 12:07 - 000000000 ____D C:\ProgramData\Nuance
2018-11-25 11:02 - 2018-11-25 11:02 - 006796563 _____ C:\Users\Barley\Downloads\HUSB_CampFlyer_2019_v4_FINAL.pdf
2018-11-24 13:40 - 2018-11-24 13:40 - 004110943 _____ C:\Users\Barley\Downloads\all-11750417.zip
2018-11-24 13:40 - 2018-11-24 13:40 - 001219747 _____ C:\Users\Barley\Downloads\histograms.pdf
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2018-12-24 15:17 - 2012-10-07 17:22 - 000003934 _____ C:\windows\System32\Tasks\User_Feed_Synchronization-{DDA5C770-AE6C-4A93-AC90-AB64C59BEC72}
2018-12-24 15:14 - 2012-10-02 13:47 - 000000000 ____D C:\ProgramData\PDFC
2018-12-24 15:13 - 2009-07-14 00:08 - 000000006 ____H C:\windows\Tasks\SA.DAT
2018-12-24 15:12 - 2009-07-13 23:45 - 000024608 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-12-24 15:12 - 2009-07-13 23:45 - 000024608 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-12-24 12:16 - 2012-10-02 13:36 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
2018-12-24 12:15 - 2012-10-02 13:36 - 000000000 ____D C:\Program Files (x86)\Hp
2018-12-24 12:10 - 2009-07-14 00:13 - 000782470 _____ C:\windows\system32\PerfStringBackup.INI
2018-12-24 12:10 - 2009-07-13 22:20 - 000000000 ____D C:\windows\inf
2018-12-24 00:16 - 2016-01-01 11:32 - 000000000 ____D C:\Users\Barley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
2018-12-23 11:43 - 2013-11-17 01:01 - 000000000 ____D C:\ProgramData\Malwarebytes
2018-12-23 04:46 - 2018-05-18 09:05 - 000217088 ___SH C:\Users\Barley\Desktop\Thumbs.db
2018-12-23 04:45 - 2009-07-13 23:45 - 000332232 _____ C:\windows\system32\FNTCACHE.DAT
2018-12-23 01:06 - 2012-10-07 17:25 - 000083472 _____ C:\Users\Barley\AppData\Local\GDIPFONTCACHEV1.DAT
2018-12-23 00:56 - 2014-06-26 21:30 - 000000000 ____D C:\windows\Minidump
2018-12-23 00:56 - 2012-11-11 21:07 - 000000000 ____D C:\Users\Barley\AppData\Local\CrashDumps
2018-12-23 00:00 - 2009-07-14 00:08 - 000032586 _____ C:\windows\Tasks\SCHEDLGU.TXT
2018-12-22 23:53 - 2016-08-27 09:19 - 000000000 ____D C:\Users\Barley\Downloads\Comets 2016_files
2018-12-22 15:16 - 2012-10-07 17:17 - 000000000 ____D C:\Users\Barley
2018-12-22 15:13 - 2017-03-23 06:44 - 000482304 ___SH C:\Users\Barley\Downloads\Thumbs.db
2018-12-22 14:46 - 2009-07-13 22:20 - 000000000 ____D C:\windows\rescache
2018-12-22 12:48 - 2015-12-25 14:06 - 000001596 _____ C:\Users\Barley\Desktop\DCS-5020L(26467279).lnk
2018-12-22 12:48 - 2014-03-02 13:24 - 000000000 ____D C:\Users\Barley\Downloads\FRST-OlderVersion
2018-12-22 11:35 - 2013-02-03 16:45 - 000000000 ____D C:\Users\Barley\AppData\Roaming\Yahoo!
2018-12-22 11:35 - 2013-02-03 16:45 - 000000000 ____D C:\Program Files (x86)\Yahoo!
2018-12-22 11:15 - 2014-03-16 15:16 - 000000000 ____D C:\Users\Barley\AppData\LocalLow\Temp
2018-12-22 11:14 - 2013-11-23 01:51 - 000002748 _____ C:\Users\Barley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ie11 RWW (Remote Web Workplace) Connect to Computer - Spiceworks.lnk
2018-12-22 11:14 - 2013-11-23 01:51 - 000002718 _____ C:\Users\Barley\Desktop\ie11 RWW (Remote Web Workplace) Connect to Computer - Spiceworks.lnk
2018-12-22 11:14 - 2012-10-07 17:28 - 000002242 _____ C:\Users\Barley\Desktop\Erica - Chrome.lnk
2018-12-22 10:51 - 2017-11-20 21:50 - 000003192 _____ C:\windows\System32\Tasks\HPCeeScheduleForBarley
2018-12-22 10:51 - 2017-11-20 21:50 - 000000336 _____ C:\windows\Tasks\HPCeeScheduleForBarley.job
2018-12-21 16:11 - 2017-04-05 11:22 - 000000000 ___RD C:\Users\Barley\Dropbox
2018-12-21 16:10 - 2012-10-07 17:37 - 014843556 ____H C:\Users\Barley\AppData\Local\IconCache.db.backup
2018-12-21 00:18 - 2016-12-25 11:57 - 000008051 _____ C:\windows\BRRBCOM.INI
2018-12-19 21:15 - 2018-03-14 23:51 - 000000000 _____ C:\windows\SysWOW64\last.dump
2018-12-18 21:09 - 2012-10-07 17:26 - 000003332 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2018-12-18 21:09 - 2012-10-07 17:25 - 000003204 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
2018-12-18 20:59 - 2013-12-25 10:30 - 000003508 _____ C:\windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-632860548-1775735820-415820443-1000UA
2018-12-18 20:59 - 2013-12-25 10:30 - 000003236 _____ C:\windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-632860548-1775735820-415820443-1000Core
2018-12-16 10:49 - 2018-11-13 09:30 - 000003236 _____ C:\windows\System32\Tasks\Norton WSC Integration
2018-12-16 10:49 - 2018-09-13 20:51 - 000000000 ____D C:\windows\System32\Tasks\AVAST Software
2018-12-16 10:49 - 2018-03-13 16:07 - 000004466 _____ C:\windows\System32\Tasks\Adobe Flash Player NPAPI Notifier
2018-12-16 10:49 - 2018-01-09 01:01 - 000003916 _____ C:\windows\System32\Tasks\Antivirus Emergency Update
2018-12-16 10:49 - 2017-08-31 23:12 - 000004478 _____ C:\windows\System32\Tasks\Adobe Flash Player PPAPI Notifier
2018-12-16 10:49 - 2017-04-15 06:34 - 000003118 _____ C:\windows\System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe
2018-12-16 10:49 - 2017-04-15 06:34 - 000003092 _____ C:\windows\System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe
2018-12-16 10:49 - 2017-04-15 06:34 - 000003090 _____ C:\windows\System32\Tasks\Microsoft_Hardware_Launch_itype_exe
2018-12-16 10:49 - 2017-04-15 06:34 - 000003062 _____ C:\windows\System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe
2018-12-16 10:49 - 2017-04-15 06:34 - 000003060 _____ C:\windows\System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe
2018-12-16 10:49 - 2015-04-23 23:38 - 000004476 _____ C:\windows\System32\Tasks\Adobe Acrobat Update Task
2018-12-16 10:49 - 2015-02-03 21:08 - 000003164 _____ C:\windows\System32\Tasks\{D95529CE-E95E-447C-8D8C-4C1A622E5294}
2018-12-16 10:49 - 2012-10-02 13:44 - 000004312 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater
2018-12-12 14:10 - 2012-10-07 17:28 - 000002226 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-12-12 07:56 - 2015-04-23 23:38 - 000002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2018-12-12 01:28 - 2011-02-11 12:15 - 000774592 _____ C:\windows\SysWOW64\PerfStringBackup.INI
2018-12-12 01:27 - 2014-09-06 18:49 - 000000000 ____D C:\windows\system32\MRT
2018-12-12 01:23 - 2014-09-06 18:49 - 137260640 ____C (Microsoft Corporation) C:\windows\system32\MRT.exe
2018-12-10 02:37 - 2014-09-06 19:22 - 000000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2018-12-06 00:07 - 2012-10-02 13:44 - 000842240 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2018-12-06 00:07 - 2012-10-02 13:44 - 000175104 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2018-12-06 00:07 - 2012-10-02 13:44 - 000000000 ____D C:\windows\SysWOW64\Macromed
2018-12-06 00:07 - 2012-10-02 13:44 - 000000000 ____D C:\windows\system32\Macromed
2018-11-30 10:41 - 2015-04-21 08:51 - 000000000 ____D C:\Program Files (x86)\Valassis
 
==================== Files in the root of some directories =======
 
2014-09-06 20:02 - 2014-09-06 20:02 - 000000055 _____ () C:\Users\Barley\AppData\Roaming\mbam.context.scan
2013-08-09 23:33 - 2013-08-09 23:34 - 000595302 _____ () C:\Users\Barley\AppData\Roaming\Scorch_Install.log
2012-10-08 14:16 - 2015-09-09 18:32 - 000011264 _____ () C:\Users\Barley\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\windows\system32\winlogon.exe => File is digitally signed
C:\windows\system32\wininit.exe => File is digitally signed
C:\windows\SysWOW64\wininit.exe => File is digitally signed
C:\windows\explorer.exe => File is digitally signed
C:\windows\SysWOW64\explorer.exe => File is digitally signed
C:\windows\system32\svchost.exe => File is digitally signed
C:\windows\SysWOW64\svchost.exe => File is digitally signed
C:\windows\system32\services.exe => File is digitally signed
C:\windows\system32\User32.dll => File is digitally signed
C:\windows\SysWOW64\User32.dll => File is digitally signed
C:\windows\system32\userinit.exe => File is digitally signed
C:\windows\SysWOW64\userinit.exe => File is digitally signed
C:\windows\system32\rpcss.dll => File is digitally signed
C:\windows\system32\dnsapi.dll => File is digitally signed
C:\windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\windows\system32\Drivers\volsnap.sys => File is digitally signed
 
LastRegBack: 2018-12-24 02:43
 
==================== End of FRST.txt ============================

 

Addition.txt

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 24.12.2018
Ran by [removed] (24-12-2018 15:21:08)
Running from C:\Users\[removed]\Desktop
Windows 7 Home Premium Service Pack 1 (X64) (2012-10-07 22:17:47)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-632860548-1775735820-415820443-500 - Administrator - Disabled)
Barley (S-1-5-21-632860548-1775735820-415820443-1000 - Administrator - Enabled) => C:\Users\Barley
Guest (S-1-5-21-632860548-1775735820-415820443-501 - Limited - Disabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: AVG Antivirus (Enabled - Up to date) {4FC75CA5-1654-5411-7CFB-1893D506BCF4}
AV: Norton Internet Security (Disabled - Out of date) {E3FDBD9F-8140-1400-F32B-8B58923F7C4D}
AS: Norton Internet Security (Disabled - Out of date) {589C5C7B-A77A-1B8E-C99B-B02AE9B836F0}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG Antivirus (Enabled - Up to date) {F4A6BD41-306E-5B9F-464B-23E1AE81F649}
FW: Norton Internet Security (Disabled) {DBC63CBA-CB2F-1558-D874-226D6CEC3B36}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
4 Elements II (HKLM-x32\…\WTA-b59b7394-ad89-4e36-9b0e-246773f6f556) (Version: 2.2.0.98 - WildTangent) Hidden
64 Bit HP CIO Components Installer (HKLM\…\{55D55008-E5F6-47D6-B16F-B2A40D4D145F}) (Version: 6.2.1 - Hewlett-Packard) Hidden
Able RAWer 1.10.3.20 (HKLM-x32\…\Able RAWer_is1) (Version: 1.10.3.20 - GraphicRegion.com)
Adobe Acrobat Reader DC (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 19.010.20064 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 18.0.0.180 - Adobe Systems Incorporated)
Adobe Flash Player 32 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 32.0.0.101 - Adobe Systems Incorporated)
Adobe Flash Player 32 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 32.0.0.101 - Adobe Systems Incorporated)
Adobe Flash Player 32 PPAPI (HKLM-x32\…\Adobe Flash Player PPAPI) (Version: 32.0.0.101 - Adobe Systems Incorporated)
AIO_CDA_ProductContext (HKLM-x32\…\{2A7EF808-14F3-4E93-BE3A-1675EE5332A4}) (Version: 130.0.365.000 - Hewlett-Packard) Hidden
AIO_CDA_Software (HKLM-x32\…\{A7AEE29F-839E-46B5-B347-6D430618129F}) (Version: 130.0.365.000 - Hewlett-Packard) Hidden
AIO_Scan (HKLM-x32\…\{D86B0E2E-DF9A-441C-AF77-8D1A0FF00FA6}) (Version: 130.0.365.000 - Hewlett-Packard) Hidden
Apple Application Support (32-bit) (HKLM-x32\…\{F2871C89-C8A5-42EE-8D45-0F02506385A6}) (Version: 5.1 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\…\{9BC93467-75D1-4AA4-BD58-D9C51D88DFAB}) (Version: 5.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{55BB2110-FB43-49B3-93F4-945A0CFB0A6C}) (Version: 10.0.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.)
AVG AntiVirus FREE (HKLM-x32\…\AVG Antivirus) (Version: 18.8.3071 - AVG Technologies)
Bejeweled 3 (HKLM-x32\…\WTA-ac717e9e-48e0-49d5-b5a2-824923e38ed4) (Version: 2.2.0.98 - WildTangent) Hidden
Blackhawk Striker 2 (HKLM-x32\…\WTA-73c3dc74-4cd1-419d-b230-d78796a73007) (Version: 2.2.0.95 - WildTangent) Hidden
Blio (HKLM-x32\…\{FCD6D60F-AF2B-49E3-ABC4-A4C96B56225D}) (Version: 3.0.9482 - K-NFB Reading Technology, Inc.)
Bonjour (HKLM\…\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
BrLauncher (HKLM-x32\…\{C661197A-6B93-4E37-9E3F-2A1DFCD64234}) (Version: 1.1.15.0 - Brother Industries Ltd.) Hidden
BrLogRx (HKLM-x32\…\{B556F816-FF4D-4BB6-9339-ED28639E2EF3}) (Version: 1.0.2.1 - Brother Industries Ltd.) Hidden
Brother PCFax Driver (HKLM-x32\…\{56BA05BD-7A67-4EF8-85A7-8C6528AEE2AC}) (Version: 1.4.0.0 - Brother Industries Ltd.) Hidden
Brother Printer Driver (HKLM-x32\…\{4A30C4EE-52AC-4A6B-A898-D484E9FAED63}) (Version: 1.5.0.0 - Brother Industries Ltd.) Hidden
Brother Scanner Driver (HKLM-x32\…\{B843B8F3-1815-4335-99F2-039AE06CAD86}) (Version: 1.0.15.10 - Brother Industries Ltd.) Hidden
BrotherHelpInstaller (HKLM-x32\…\{4E461C2A-EC1C-46D1-AF5B-7FEFD0054AF8}) (Version: 1.0.0.0 - Brother) Hidden
BrSupportTools (HKLM-x32\…\{F8F9EB58-33BA-4FF8-80E7-66D87D2E0C3C}) (Version: 1.0.9.0 - Brother Industries Ltd.) Hidden
Bubble Wrap (HKLM-x32\…\{5BFFDDEB-AFD7-499F-BB13-7A6EAD927CDA}_is1) (Version: 1.0.0.0 - XM Asia Pacific Pte Ltd)
BufferChm (HKLM-x32\…\{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}) (Version: 130.0.331.000 - Hewlett-Packard) Hidden
C6100 (HKLM-x32\…\{0DEF8C02-2EAB-4BFE-A7E0-7990665DF1A9}) (Version: 130.0.365.000 - Hewlett-Packard) Hidden
c6100_Help (HKLM-x32\…\{4BD5B5D2-406D-4bc5-BB10-2F0D1D367C95}) (Version: 82.0.256.000 - Hewlett-Packard) Hidden
Catalina Savings Printer (HKLM-x32\…\{4956ACE3-F537-4418-BB45-FD52395275A7}) (Version: 1.0.0 - Catalina Marketing Corp) <==== ATTENTION
CCleaner (HKLM\…\CCleaner) (Version: 5.51 - Piriform)
ChromecastApp (HKU\S-1-5-21-632860548-1775735820-415820443-1000\…\{079ede36-133d-44b0-8053-c7c1fa8d2e0d}_is1) (Version: 1.5.1693.0 - Google Inc.)
Chuzzle Deluxe (HKLM-x32\…\WTA-350df33b-9fdb-4c58-80af-3f5a302269c2) (Version: 2.2.0.95 - WildTangent) Hidden
Cisco WebEx Meetings (HKU\S-1-5-21-632860548-1775735820-415820443-1000\…\ActiveTouchMeetingClient) (Version:  - Cisco WebEx LLC)
ControlCenter4 (HKLM-x32\…\{C5744F42-FDC4-4CC2-B4A8-47C9AA9553B4}) (Version: 4.2.435.1 - Brother Insutries Ltd.) Hidden
ControlCenter4 CSDK (HKLM-x32\…\{1BAE50D4-5F2A-4E34-BD81-B4555109F7C2}) (Version: 4.2.3.1 - Brother Insutries Ltd.) Hidden
Cradle of Rome 2 (HKLM-x32\…\WTA-1c1f6121-da0f-4e8c-9c68-5081de00e04b) (Version: 2.2.0.98 - WildTangent) Hidden
D3DX10 (HKLM-x32\…\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden
DeviceDetect (HKLM-x32\…\{CEF07BDC-47F1-4477-8F3C-0E7132AF88C5}) (Version: 1.0.4.5 - Brother Industries Ltd.) Hidden
Dietz & Watson 2015 (HKLM-x32\…\{CD6EEFE2-17F9-AC22-9223-48776E476221}) (Version: 2.5 - Koupon Media) Hidden
Dietz & Watson 2015 (HKLM-x32\…\com.kouponmedia.dietzandwatson2015) (Version: 2.5 - Koupon Media)
DirectX for Managed Code Update (Summer 2004) (HKLM-x32\…\{E9E34215-82EF-4909-BE2F-F581F0DC9062}) (Version: 9.02.2904 - Microsoft) Hidden
DocProc (HKLM-x32\…\{9B362566-EC1B-4700-BB9C-EC661BDE2175}) (Version: 13.0.0.0 - Hewlett-Packard) Hidden
Dora's World Adventure (HKLM-x32\…\WTA-220769bc-a6cc-4095-8049-d7448f650a3e) (Version: 2.2.0.95 - WildTangent) Hidden
Dragon NaturallySpeaking 7.0 (HKLM-x32\…\{6675E71B-9843-4971-BC15-18AB52801134}) (Version: 7.00.200.409 - ScanSoft)
Elevated Installer (HKLM-x32\…\{352B1136-BF8D-4F5A-924B-43B26D05B3B5}) (Version: 2.3.17.0 - Garmin Ltd or its subsidiaries) Hidden
Escape the Emerald Star (HKLM-x32\…\WTA-424f1b8b-d37a-42ea-b226-3030d1996772) (Version: 2.2.0.98 - WildTangent) Hidden
Exact Audio Copy 1.2 (HKLM-x32\…\Exact Audio Copy) (Version: 1.2 - Andre Wiethoff)
Facebook (HKLM-x32\…\{8AE50893-3A87-4439-9A57-942ED43F7189}) (Version: 1.1.0004 - Hewlett-Packard)
Farm Frenzy (HKLM-x32\…\WTA-c81077f9-55f3-4d11-b4fe-585ad41d8209) (Version: 2.2.0.98 - WildTangent) Hidden
Farmscapes (HKLM-x32\…\WTA-ba2cfe9d-b15a-44af-87b3-25c19f580002) (Version: 2.2.0.97 - WildTangent) Hidden
FATE (HKLM-x32\…\WTA-0e36d320-14f2-4de0-88cd-beb4083d639d) (Version: 2.2.0.97 - WildTangent) Hidden
Final Drive Fury (HKLM-x32\…\WTA-844866d1-e9d3-40b2-a85e-666243def709) (Version: 2.2.0.95 - WildTangent) Hidden
Free YouTube To MP3 Converter (HKLM-x32\…\Free YouTube To MP3 Converter_is1) (Version: 4.1.33.119 - Digital Wave Ltd)
Garmin Express (HKLM-x32\…\{874B12CE-2C6A-4E12-AEB5-4D35CCA5270B}) (Version: 2.3.17.0 - Garmin Ltd or its subsidiaries) Hidden
Garmin Express (HKLM-x32\…\{d6f59919-3fd4-48c5-8404-def6f92d8422}) (Version: 2.3.17.0 - Garmin Ltd or its subsidiaries)
Garmin Express Tray (HKLM-x32\…\{BE770575-1FB0-47EB-A2EE-52107A023F12}) (Version: 2.3.17.0 - Garmin Ltd or its subsidiaries) Hidden
Golden Trails 2: The Lost Legacy Collector's Edition (HKLM-x32\…\WTA-a751c50d-1758-4426-8ac0-a7be901bb1c2) (Version: 2.2.0.98 - WildTangent) Hidden
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 71.0.3578.98 - Google Inc.)
Google Update Helper (HKLM-x32\…\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.23 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\…\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden
GPBaseService2 (HKLM-x32\…\{63FF21C9-A810-464F-B60A-3111747B1A6D}) (Version: 130.0.371.000 - Hewlett-Packard) Hidden
Hewlett-Packard ACLM.NET v1.2.2.3 (HKLM-x32\…\{6F340107-F9AA-47C6-B54C-C3A19F11553F}) (Version: 1.00.0000 - Hewlett-Packard Company) Hidden
HowToGuide (HKLM-x32\…\{36580EEB-4EDF-4880-BBD4-097E2C645ECD}) (Version: 1.0.1.0 - Brother Industries Ltd.) Hidden
Hoyle Card Games (HKLM-x32\…\WTA-818c6384-6cd9-4f15-8a4f-14a502345e34) (Version: 2.2.0.95 - WildTangent) Hidden
HP Application Assistant (HKLM\…\{0CE7EBAF-157D-4111-9146-057CB2A4023E}) (Version: 1.1.466.3970 - Hewlett-Packard)
HP Calendar (HKLM-x32\…\{2B38E0FA-D8A5-4EBF-A018-E3C1C8E7A2E2}) (Version: 5.1.4245.23508 - Hewlett-Packard)
HP Clock (HKLM-x32\…\{750E9D0F-B188-4A7E-ADD2-84B7ED7D32F6}) (Version: 5.1.4281.27332 - Hewlett-Packard)
HP Customer Participation Program 13.0 (HKLM\…\HPExtendedCapabilities) (Version: 13.0 - HP)
HP Easy Print (HKLM-x32\…\{37C4570C-2F39-4756-AF26-A204CEF202D6}) (Version: 1.00.0000 - HP)
HP Games (HKLM-x32\…\WildTangent hp Master Uninstall) (Version: 1.0.2.5 - WildTangent)
HP LinkUp (HKLM-x32\…\{7E750542-55BC-4300-8B7B-AC2A762FB435}) (Version: 2.01.029 - Hewlett-Packard)
HP Magic Canvas (HKLM-x32\…\{DDFDC9D6-4220-41F8-BF9A-8E7512C4EF52}) (Version: 5.1.15.0 - Hewlett-Packard)
HP Magic Canvas Tutorials (HKLM-x32\…\{858FCB65-7C6D-4BA4-AD80-A3CB3744CE09}_is1) (Version: 6.0.0.0 - Hewlett-Packard)
HP Notes (HKLM-x32\…\{86BAB08A-5E66-4C53-82E3-C1E91673C7CA}) (Version: 5.1.4274.30382 - Hewlett-Packard)
HP Odometer (HKLM-x32\…\{B8AC1A89-FFD1-4F97-8051-E505A160F562}) (Version: 2.10.0000 - Hewlett-Packard)
HP Photosmart All-In-One Driver Software 13.0 Rel. A (HKLM\…\{17016DA1-F040-4032-BD36-34DD317BC9D5}) (Version: 13.0 - HP)
HP RSS (HKLM-x32\…\{452479C5-0118-48E9-AA69-0A7339F95FC8}) (Version: 5.1.4289.23799 - Hewlett-Packard)
HP Setup (HKLM-x32\…\{438363A8-F486-4C37-834C-4955773CB3D3}) (Version: 9.1.15430.4033 - Hewlett-Packard Company)
HP Smart Web Printing 4.51 (HKLM\…\HP Smart Web Printing) (Version: 4.51 - HP)
HP Solution Center 13.0 (HKLM\…\HP Solution Center & Imaging Support Tools) (Version: 13.0 - HP)
HP Support Assistant (HKLM-x32\…\{61EB474B-67A6-47F4-B1B7-386851BAB3D0}) (Version: 8.7.50.3 - Hewlett-Packard Company)
HP Support Information (HKLM-x32\…\{B2B7B1C8-7C8B-476C-BE2C-049731C55992}) (Version: 11.00.0001 - Hewlett-Packard)
HP Support Solutions Framework (HKLM-x32\…\{F6A11738-3EE4-4573-AEA5-6CD5D491C167}) (Version: 12.10.49.21 - Hewlett-Packard Company)
HP Touchpoint Analytics Client (HKLM\…\{E5FB98E0-0784-44F0-8CEC-95CD4690C43F}) (Version: 4.0.2.1439 - HP Inc.)
HP TouchSmart Background - Beats (HKLM-x32\…\{6A6F8D36-04BA-41E9-9004-1789BD545874}) (Version: 1.0.1.0 - Hewlett-Packard)
HP TouchSmart RecipeBox (HKLM-x32\…\{20714B53-FC73-4F9C-9687-49EB237D6FD7}) (Version: 3.0.3830.27730 - Hewlett-Packard)
HP Update (HKLM-x32\…\{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}) (Version: 5.003.001.001 - Hewlett-Packard)
HP Weather (HKLM-x32\…\{776CC95E-8160-401B-AC79-164822AA8306}) (Version: 5.1.4245.22595 - Hewlett-Packard)
HPPhotoGadget (HKLM-x32\…\{CAE4213F-F797-439D-BD9E-79B71D115BE3}) (Version: 130.0.282.000 - Hewlett-Packard) Hidden
HPProductAssistant (HKLM-x32\…\{C43326F5-F135-4551-8270-7F7ABA0462E1}) (Version: 130.0.371.000 - Hewlett-Packard) Hidden
iCloud (HKLM\…\{309768A4-A2BB-4930-A5A2-8169678C9B4C}) (Version: 4.0.6.28 - Apple Inc.)
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.0.0.1351 - Intel Corporation)
Intel(R) OpenCL CPU Runtime (HKLM-x32\…\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version:  - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2696 - Intel Corporation)
iTunes (HKLM\…\{554C62C7-E6BB-40F1-892B-F0AE02D3C135}) (Version: 12.5.3.17 - Apple Inc.)
Java 8 Update 191 (64-bit) (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F64180191F0}) (Version: 8.0.1910.12 - Oracle Corporation)
Jewel Match 3 (HKLM-x32\…\WTA-4660ad21-bbd2-4056-9274-17cdbb6e8a8c) (Version: 2.2.0.98 - WildTangent) Hidden
Jewel Quest Mysteries: The Seventh Gate Collector's Edition (HKLM-x32\…\WTA-6bd8460b-7dda-4a26-9e12-707c452d9b21) (Version: 2.2.0.98 - WildTangent) Hidden
John Deere Drive Green (HKLM-x32\…\WTA-5333fae1-48ca-41d7-8382-7c65262bc50c) (Version: 2.2.0.95 - WildTangent) Hidden
Junk Mail filter update (HKLM-x32\…\{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}) (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
LabelPrint (HKLM-x32\…\{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.4507 - CyberLink Corp.) Hidden
LabelPrint (HKLM-x32\…\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.4507 - CyberLink Corp.)
Luxor HD (HKLM-x32\…\WTA-7d011431-914e-437f-b7a1-ef23ab9154a0) (Version: 2.2.0.98 - WildTangent) Hidden
Mah Jong Medley (HKLM-x32\…\WTA-0fd9482b-7878-4605-8c28-19efd6521c0a) (Version: 2.2.0.95 - WildTangent) Hidden
Malwarebytes version 3.6.1.2711 (HKLM\…\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.6.1.2711 - Malwarebytes)
MarketResearch (HKLM-x32\…\{175F0111-2968-4935-8F70-33108C6A4DE3}) (Version: 130.0.374.000 - Hewlett-Packard) Hidden
Mesh Runtime (HKLM-x32\…\{8C6D6116-B724-4810-8F2D-D047E6B7D68E}) (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Metric Converter (HKLM-x32\…\{D0661463-50F7-4A1E-83CB-37CC590589AE}_is1) (Version: 1.0.0.0 - XM Asia Pacific Pte Ltd)
Microsoft .NET Framework 4.7.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.03062 - Microsoft Corporation)
Microsoft LifeCam (HKLM\…\{5CE7E3F5-9803-4F32-AA89-2D8848A80109}) (Version: 3.60.253.0 - Microsoft Corporation)
Microsoft Mathematics (HKLM-x32\…\{4D090F70-6F08-4B60-9357-A1DFD4458F09}) (Version: 4.0 - Microsoft Corporation)
Microsoft Mouse and Keyboard Center (HKLM\…\Microsoft Mouse and Keyboard Center) (Version: 2.3.188.0 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\…\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office 2010 (HKLM-x32\…\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM-x32\…\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Home and Student 2007 (HKLM-x32\…\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Zoo Tycoon (HKLM-x32\…\Zoo Tycoon 1.0) (Version:  - )
Mortimer Beckett and the Crimson Thief Premium Edition (HKLM-x32\…\WTA-7fc1033b-c678-45d5-a485-905aaf4a04e4) (Version: 2.2.0.98 - WildTangent) Hidden
Mozilla Firefox 26.0 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 26.0 (x86 en-US)) (Version: 26.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 26.0 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
My Farm Life 2 (HKLM-x32\…\WTA-3daa2b41-1b22-4cc2-838a-7a7c844442d1) (Version: 2.2.0.98 - WildTangent) Hidden
Network64 (HKLM\…\{05EFBF37-0E52-4579-875C-7EEF0DFB4FCB}) (Version: 130.0.572.000 - Hewlett-Packard) Hidden
NetworkRepairTool (HKLM-x32\…\{4694AD3E-D4A2-4D98-9848-662A0475E872}) (Version: 1.2.11.0 - Brother Insutries Ltd.) Hidden
Norton Internet Security (HKLM-x32\…\NGC) (Version: 22.16.2.22 - Symantec Corporation)
Norton Online Backup (HKLM-x32\…\{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}) (Version: 2.1.17869 - Symantec Corporation)
OCR Software by I.R.I.S. 13.0 (HKLM\…\HPOCR) (Version: 13.0 - HP)
opensource (HKLM-x32\…\{3677D4D8-E5E0-49FC-B86E-06541CF00BBE}) (Version: 1.0.14960.3876 - Your Company Name) Hidden
P@H-Protocol (HKLM-x32\…\{14F936AB-5D31-410E-A4E2-70AE504712F2}) (Version: 3.0.8.6 - Valassis)
P@H-Protocol (HKLM-x32\…\{4CFAC858-CB6F-4F5B-9BD9-4DAE8747F0E3}) (Version: 3.0.8.11 - Valassis)
P@H-Protocol (HKLM-x32\…\{A2CB3AFC-E449-408A-BF4F-FE64EB1899D8}) (Version: 3.0.8.7 - Valassis)
PC-FAXReceive (HKLM-x32\…\{DD40894F-7575-4905-90AB-695FD827E358}) (Version: 1.4.24.0 - Brother Insutries Ltd.) Hidden
PCFaxTx (HKLM-x32\…\{63530B2D-3A34-4D79-A52D-F3EB5D99A7C1}) (Version: 1.1.1.1 - Brother Industries Ltd.) Hidden
PDF Complete Corporate Edition (HKLM-x32\…\PDF Complete) (Version: 4.2.33 - PDF Complete, Inc)
Penguins! (HKLM-x32\…\WTA-c6d3fe1b-0537-4004-87f7-b2843d0833ac) (Version: 2.2.0.98 - WildTangent) Hidden
Plants vs. Zombies - Game of the Year (HKLM-x32\…\WTA-c43bee99-1714-4c3c-82e7-267367a21983) (Version: 2.2.0.98 - WildTangent) Hidden
PlayReady PC Runtime amd64 (HKLM\…\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation)
PlayReady PC Runtime x86 (HKLM-x32\…\{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}) (Version: 1.3.0 - Microsoft Corporation)
Poker Superstars III (HKLM-x32\…\WTA-ceced49d-d9ad-49da-ac4a-adcacf6cd937) (Version: 2.2.0.95 - WildTangent) Hidden
Polar Bowler (HKLM-x32\…\WTA-ad6b48d4-4aa6-49b1-b668-6005090a3c83) (Version: 2.2.0.97 - WildTangent) Hidden
Polar Golfer (HKLM-x32\…\WTA-417cc89d-18f1-44b3-90c8-0f4968fb00c2) (Version: 2.2.0.98 - WildTangent) Hidden
Power2Go (HKLM-x32\…\{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.6207 - CyberLink Corp.) Hidden
Power2Go (HKLM-x32\…\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.6207 - CyberLink Corp.)
PowerISO (HKLM-x32\…\PowerISO) (Version: 5.4 - Power Software Ltd)
Print@Home (HKLM-x32\…\{123D4082-3194-4191-9139-067E9157C2B2}) (Version: 2.0.0 - Valassis Interactive Inc.)
Ralink 802.11n Wireless LAN Card (HKLM-x32\…\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}) (Version: 3.2.12.0 - Ralink)
Recovery Manager (HKLM-x32\…\{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}) (Version: 5.5.0.5119 - CyberLink Corp.) Hidden
Remote Graphics Receiver (HKLM-x32\…\{16FC3056-90C0-4757-8A68-64D8DA846ADA}) (Version: 5.4.5 - Hewlett-Packard)
RemoteSetup (HKLM-x32\…\{B6CE4633-EA3F-4856-9BCC-9B8702E076FE}) (Version: 3.8.0.2 - Brother Industries Ltd.) Hidden
RimhillEx 1.08 (HKU\S-1-5-21-632860548-1775735820-415820443-1000\…\RimhillEx_is1) (Version:  - the sz development)
RMNEveryday Coupon Printer (HKLM-x32\…\{08586830-7F6E-41F5-9A1C-51F7D2873631}) (Version: 3.1.0.0 - Valassis)
Roads of Rome 3 (HKLM-x32\…\WTA-0939384a-c84d-4e93-be59-7ae8b6d3e2dc) (Version: 2.2.0.98 - WildTangent) Hidden
RogueKiller version 13.0.17.0 (HKLM\…\8B3D7924-ED89-486B-8322-E8594065D5CB_is1) (Version: 13.0.17.0 - Adlice Software)
Scan (HKLM-x32\…\{0F367CA3-3B2F-43F9-A44A-25A8EE69E45D}) (Version: 13.0.0.0 - Hewlett-Packard) Hidden
ScannerUtilityInstaller (HKLM-x32\…\{5B645FE2-19E9-4B15-B5B2-3D8766F6FA27}) (Version: 1.0.0.0 - Brother) Hidden
Secunia PSI (3.0.0.9016) (HKLM-x32\…\Secunia PSI) (Version: 3.0.0.9016 - Secunia)
Sibelius Scorch (Firefox, Opera, Netscape, Chrome only) (HKLM-x32\…\{41626CC0-A854-4402-AD06-D7939515C282}) (Version: 6.2.0 - Sibelius Software, a division of Avid Technology, Inc.)
Skype™ 7.0 (HKLM-x32\…\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
SmartWebPrinting (HKLM-x32\…\{DC635845-46D3-404B-BCB1-FC4A91091AFA}) (Version: 130.0.457.000 - Hewlett-Packard) Hidden
Smilebox (HKU\S-1-5-21-632860548-1775735820-415820443-1000\…\Smilebox) (Version: 1.0.0.31741 - Smilebox, Inc.)
SolutionCenter (HKLM-x32\…\{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}) (Version: 130.0.373.000 - Hewlett-Packard) Hidden
Spot (HKLM-x32\…\{3D171340-B528-42E0-92E4-BDA7AEEF6F32}_is1) (Version: 1.0.0.0 - XM Asia Pacific Pte Ltd)
StatusMonitor (HKLM-x32\…\{86D16055-3C14-44C6-BCD7-5514B83BAD34}) (Version: 1.12.4.0 - Brother Insutries Ltd.) Hidden
Tales of Lagoona (HKLM-x32\…\WTA-75f90731-d0ef-4ead-85f3-edbfba5c6ced) (Version: 2.2.0.98 - WildTangent) Hidden
Tap Tap Bear (HKLM-x32\…\{A393CDFF-BEB8-48EA-990D-2EB35B311D23}_is1) (Version: 1.0.0.0 - XM Asia Pacific Pte Ltd)
TeamViewer 9 (HKLM-x32\…\TeamViewer 9) (Version: 9.0.32494 - TeamViewer)
TI USB 3.0 Host Controller Driver (HKLM-x32\…\InstallShield_{355FBD67-5A4F-44DA-86A1-56EEC4C20EC0}) (Version: 1.12.18.0 - Texas Instruments Inc.)
TI USB3 Host Driver (HKLM-x32\…\{355FBD67-5A4F-44DA-86A1-56EEC4C20EC0}) (Version: 1.12.18.0 - Texas Instruments Inc.) Hidden
Toolbox (HKLM-x32\…\{6BBA26E9-AB03-4FE7-831A-3535584CA002}) (Version: 130.0.648.000 - Hewlett-Packard) Hidden
Torchlight (HKLM-x32\…\WTA-3c9ded15-538a-4040-b422-610d26c7de9d) (Version: 2.2.0.98 - WildTangent) Hidden
TSHostedAppLauncher (HKLM-x32\…\{F89BADB0-D319-470E-8024-443EE3A3402B}) (Version: 5.1.15.0 - Hewlett-Packard) Hidden
UnloadSupport (HKLM-x32\…\{4E7C28C7-D5DA-4E9F-A1CA-60490B54AE35}) (Version: 11.0.0 - Hewlett-Packard) Hidden
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\…\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
Update Installer for WildTangent Games App (HKLM-x32\…\{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App) (Version:  - WildTangent) Hidden
UsbRepairTool (HKLM-x32\…\{523276A4-5779-4105-9163-CA1CF94EC533}) (Version: 1.4.0.0 - Brother Insutries Ltd.) Hidden
Virtual Villagers 4 - The Tree of Life (HKLM-x32\…\WTA-a76813b1-d318-4c70-b481-009dabe4cb9b) (Version: 2.2.0.98 - WildTangent) Hidden
WebReg (HKLM-x32\…\{43CDF946-F5D9-4292-B006-BA0D92013021}) (Version: 130.0.132.017 - Hewlett-Packard) Hidden
WildTangent Games App (HP Games) (HKLM-x32\…\{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-hp) (Version: 4.0.5.36 - WildTangent) Hidden
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\…\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
WinZip 16.0 (HKLM\…\{CD95F661-A5C4-44F5-A6AA-ECDD91C240CD}) (Version: 16.0.9715 - WinZip Computing, S.L. )
Wondershare Helper Compact 2.5.2 (HKLM-x32\…\{5363CE84-5F09-48A1-8B6C-6BB590FFEDF2}_is1) (Version: 2.5.2 - Wondershare)
Wondershare Video Converter Ultimate(Build 9.0.1.4) (HKLM-x32\…\Wondershare Video Converter Ultimate_is1) (Version: 9.0.1.4 - Wondershare Software)
Youda Fisherman (HKLM-x32\…\WTA-cb0bd757-b714-4ced-8e65-6cdcd47c3ad9) (Version: 2.2.0.98 - WildTangent) Hidden
Zuma's Revenge (HKLM-x32\…\WTA-6a3fb242-dbd2-46cf-bf50-6031b10d212b) (Version: 2.2.0.98 - WildTangent) Hidden
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
ShellIconOverlayIdentifiers: [  OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\buShell.dll [2018-11-03] (Symantec Corporation)
ShellIconOverlayIdentifiers: [  OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\buShell.dll [2018-11-03] (Symantec Corporation)
ShellIconOverlayIdentifiers: [  OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\buShell.dll [2018-11-03] (Symantec Corporation)
ShellIconOverlayIdentifiers-x32: [  OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\buShell.dll [2018-11-03] (Symantec Corporation)
ShellIconOverlayIdentifiers-x32: [  OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\buShell.dll [2018-11-03] (Symantec Corporation)
ShellIconOverlayIdentifiers-x32: [  OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\buShell.dll [2018-11-03] (Symantec Corporation)
ContextMenuHandlers1: [AVG] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files (x86)\AVG\Antivirus\ashShA64.dll [2018-11-15] (AVG Technologies CZ, s.r.o.)
ContextMenuHandlers1: [BUContextMenu] -> {F7CAA2A1-67A2-44BB-B20F-202FD8EB1DAB} => C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\buShell.dll [2018-11-03] (Symantec Corporation)
ContextMenuHandlers1: [PhotoStreamsExt] -> {89D984B3-813B-406A-8298-118AFA3A22AE} => C:\Program Files\Common Files\Apple\Internet Services\ShellStreams64.dll [2014-11-21] (Apple Inc.)
ContextMenuHandlers1: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => C:\Program Files (x86)\PowerISO\PWRISOSH.DLL [2012-08-24] (Power Software Ltd)
ContextMenuHandlers1: [Symantec.Norton.Antivirus.IEContextMenu] -> {FAD61B3D-699D-49B2-BE16-7F82CB4C59CA} => C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\NavShExt.dll [2018-11-03] (Symantec Corporation)
ContextMenuHandlers1: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\wzshls64.dll [2012-02-16] (WinZip Computing, S.L.)
ContextMenuHandlers1: [WondershareVideoConverterFileOpreation] -> {FEB746CA-95C2-485F-B386-C30D4E56D22E} => C:\windows\SysWOW64\WSCM64.dll [2015-02-27] ()
ContextMenuHandlers2: [Symantec.Norton.Antivirus.IEContextMenu] -> {FAD61B3D-699D-49B2-BE16-7F82CB4C59CA} => C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\NavShExt.dll [2018-11-03] (Symantec Corporation)
ContextMenuHandlers3: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ContextMenuHandlers3: [LinkUpMenuExt] -> {B793E5EA-5344-488E-B98D-A18E2E5938AB} => C:\Program Files (x86)\Hewlett-Packard\HP LinkUp\LinkUpExt64.dll [2011-05-06] (Hewlett-Packard)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-09-19] (Malwarebytes)
ContextMenuHandlers4: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => C:\Program Files (x86)\PowerISO\PWRISOSH.DLL [2012-08-24] (Power Software Ltd)
ContextMenuHandlers4: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\wzshls64.dll [2012-02-16] (WinZip Computing, S.L.)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\windows\system32\igfxpph.dll [2012-04-04] (Intel Corporation)
ContextMenuHandlers6: [AVG] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files (x86)\AVG\Antivirus\ashShA64.dll [2018-11-15] (AVG Technologies CZ, s.r.o.)
ContextMenuHandlers6: [BUContextMenu] -> {F7CAA2A1-67A2-44BB-B20F-202FD8EB1DAB} => C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\buShell.dll [2018-11-03] (Symantec Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-09-19] (Malwarebytes)
ContextMenuHandlers6: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => C:\Program Files (x86)\PowerISO\PWRISOSH.DLL [2012-08-24] (Power Software Ltd)
ContextMenuHandlers6: [Symantec.Norton.Antivirus.IEContextMenu] -> {FAD61B3D-699D-49B2-BE16-7F82CB4C59CA} => C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\NavShExt.dll [2018-11-03] (Symantec Corporation)
ContextMenuHandlers6: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\wzshls64.dll [2012-02-16] (WinZip Computing, S.L.)
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {03256141-1BAE-4C9E-8D28-AED4BC1B37DE} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [2018-08-30] (HP Inc.)
Task: {0583328E-0A8D-40B9-88C1-6CBF18EF2064} - System32\Tasks\HPCeeScheduleForBarley => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2015-06-16] (Hewlett-Packard)
Task: {13CA88A1-CDA4-4585-9F11-8BC5130BC8D0} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation)
Task: {1ABD908E-44DD-46E5-93D6-F85795AE81E1} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\windows\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_101_pepper.exe [2018-12-06] (Adobe Systems Incorporated)
Task: {2AA6B539-4673-4A05-8597-E9C84EE0899E} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2014-03-19] (Microsoft)
Task: {2C5DC53C-3BB7-43CC-AA49-116AAEF51CF5} - System32\Tasks\{D95529CE-E95E-447C-8D8C-4C1A622E5294} => C:\windows\system32\pcalua.exe -a "C:\Users\Barley\Downloads\chromeinstall-8u31 (1).exe" -d C:\Users\Barley\Downloads
Task: {40CB04A3-5E27-4FFF-8F98-2069CF54D5AB} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-632860548-1775735820-415820443-1000Core => C:\Users\Barley\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {45416CB6-710F-4224-82AA-01FE4BC3D47B} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Product Configurator => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\ProductConfig.exe [2018-11-08] (HP Inc.)
Task: {4DEF5C25-BA5D-4828-98AF-FC4FBA2C55C2} - System32\Tasks\AVG\Overseer => C:\Program Files\Common Files\AVG\Overseer\overseer.exe [2018-10-28] (AVG Technologies CZ, s.r.o.)
Task: {4F04A113-09B2-4923-A098-4F9DCBB11ADA} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation)
Task: {6D07362E-868E-43E5-9482-326BF8228EB4} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\windows\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_101_Plugin.exe [2018-12-05] (Adobe Systems Incorporated)
Task: {6D49B0C9-CEF2-467A-AD36-7DB6C8FE2F99} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation)
Task: {7A479DAC-A6ED-4050-961C-372019C23B7B} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2018-12-10] (HP Inc.)
Task: {7F66690E-782F-4E81-A623-244E817342E9} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2018-12-10] (Piriform Software Ltd)
Task: {8D5865E3-B262-4FEE-BD7A-1A397D69B4EE} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {93BAAB6E-33D2-47CD-B0F4-D7C3357882E7} - System32\Tasks\Norton Internet Security\Norton Internet Security Error Analyzer => C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\SymErr.exe [2018-11-03] (Symantec Corporation)
Task: {9F9B883E-CB9B-48C3-BBF8-9C2C0E0750AC} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation)
Task: {A4DFCC1B-B3C7-4572-A960-FB8DA59855C5} - System32\Tasks\Antivirus Emergency Update => C:\Program Files (x86)\AVG\Antivirus\AvEmUpdate.exe [2018-11-15] (AVG Technologies CZ, s.r.o.)
Task: {AFF25087-364C-4FB3-AAC9-50F6F6E0A392} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater - Resources => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2017-09-20] (HP Inc.)
Task: {B458637F-D899-4538-BA11-2A14B1ED6A8C} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.)
Task: {BEF7C1BC-3725-43AE-B6C5-660106D31E7E} - System32\Tasks\Hewlett-Packard\HP Active Health\HP Active Health Scan (HPSA) => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.exe [2017-11-20] ()
Task: {BF9223F9-D1BF-46CB-BBC9-3C2CBBC5638F} - System32\Tasks\Remediation\AntimalwareMigrationTask => C:\Program Files\Common Files\AV\Norton Internet Security\Upgrade.exe [2018-11-03] (Symantec Corporation)
Task: {C56A0862-A80E-4AF3-A838-7EE9E32EC86D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2018-11-09] (HP Inc.)
Task: {C7EB1FD5-AF07-496F-A6FA-1D64ED3C7ACF} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2018-08-13] (Adobe Systems Incorporated)
Task: {CCEC197E-48A7-4647-AD8D-6D177DE3402A} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-632860548-1775735820-415820443-1000UA => C:\Users\Barley\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {CF50CD1D-1E6D-4BCE-BEF5-42BAA1D3D88B} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2018-11-09] (HP Inc.)
Task: {DA1CEAA8-060C-4D55-81D2-C45E1899F543} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {E0AB2A07-7DD0-4B65-BDAA-603EA27394D6} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [2018-12-10] (Piriform Ltd)
Task: {E25995B7-68C9-4394-B1CE-2988A5345F45} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2017-09-20] (HP Inc.)
Task: {EF88B9A7-8B01-496D-BFED-719F2A3A7981} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2018-12-10] (HP Inc.)
Task: {F2946359-CBD4-45CF-A8B0-F43C86BAACF4} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\WSCStub.exe [2018-11-03] (Symantec Corporation)
Task: {F8605A12-4EF9-4498-9431-35EDC2893E69} - System32\Tasks\Norton Internet Security\Norton Internet Security Error Processor => C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\SymErr.exe [2018-11-03] (Symantec Corporation)
Task: {FB40547D-7545-4F51-84A4-F02B26327EC3} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-12-06] (Adobe Systems Incorporated)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\windows\Tasks\HPCeeScheduleForBarley.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
 
ShortcutWithArgument: C:\Users\Barley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Destiny Discover.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  –profile-directory="Profile 1" –app-id=bbhkckkafippkgeicobhgafkioeblebh
ShortcutWithArgument: C:\Users\Barley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\ScanQR.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  –profile-directory="Profile 1" –app-id=nihhbejdflkeingkkpakffdlmepaeaah
ShortcutWithArgument: C:\Users\Barley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Vernier Graphical Analysis.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  –profile-directory="Profile 1" –app-id=dncgedbnidfkppmdgfgidcepclnokpkb
ShortcutWithArgument: C:\Users\Barley\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\69639df789022856\Erica - Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> –profile-directory="Profile 1"
 
==================== Loaded Modules (Whitelisted) ==============
 
2017-03-03 17:38 - 2015-02-27 14:38 - 000721263 _____ () C:\windows\SysWOW64\WSCM64.dll
2016-10-05 18:17 - 2016-10-05 18:17 - 000092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2016-10-05 18:17 - 2016-10-05 18:17 - 001353528 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2012-04-04 21:46 - 2012-04-04 21:46 - 000094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2012-12-25 15:57 - 2011-05-26 14:14 - 000477080 _____ () C:\Users\Barley\AppData\Roaming\HP SimpleSave Application\StartHelper.exe
2018-12-12 14:09 - 2018-12-12 00:11 - 005237216 _____ () C:\Program Files (x86)\Google\Chrome\Application\71.0.3578.98\libglesv2.dll
2018-12-12 14:09 - 2018-12-12 00:11 - 000117216 _____ () C:\Program Files (x86)\Google\Chrome\Application\71.0.3578.98\libegl.dll
2016-12-25 11:57 - 2005-04-22 13:36 - 000143360 _____ () C:\windows\system32\BrSNMP64.dll
2018-12-23 11:43 - 2018-09-12 11:35 - 002701064 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\SelfProtectionSdk.dll
2018-11-15 20:11 - 2018-11-15 20:11 - 000724752 _____ () c:\Program Files (x86)\AVG\Antivirus\x64\StreamBack.dll
2018-11-15 20:10 - 2018-11-15 20:10 - 000919312 _____ () C:\Program Files (x86)\AVG\Antivirus\anen.dll
2018-11-15 20:11 - 2018-11-15 20:11 - 000594192 _____ () C:\Program Files (x86)\AVG\Antivirus\streamback.dll
2018-12-24 12:46 - 2018-12-24 12:46 - 005734600 _____ () C:\Program Files (x86)\AVG\Antivirus\defs\18122404\algo.dll
2018-11-15 20:10 - 2018-11-15 20:10 - 000496400 _____ () C:\Program Files (x86)\AVG\Antivirus\gui_cache.dll
2018-11-15 20:10 - 2018-11-15 20:10 - 001112336 _____ () C:\Program Files (x86)\AVG\Antivirus\shepherdsync.dll
2016-10-29 23:32 - 2016-10-27 11:13 - 000114664 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\zlib1.dll
2016-10-29 23:32 - 2017-01-20 07:51 - 000108008 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\boost_filesystem-vc120-mt-1_56.dll
2016-10-29 23:32 - 2017-01-20 07:51 - 000024040 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\boost_system-vc120-mt-1_56.dll
2016-10-29 23:32 - 2017-01-20 07:51 - 000048104 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\boost_date_time-vc120-mt-1_56.dll
2018-03-13 10:22 - 2018-03-13 10:22 - 067127976 _____ () C:\Program Files (x86)\AVG\Antivirus\libcef.dll
2009-02-27 16:38 - 2009-02-27 16:38 - 000139264 _____ () C:\Program Files (x86)\Brother\BrUtilities\BrLogAPI.dll
2017-03-03 17:39 - 2016-10-08 16:48 - 001506304 _____ () C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\DAQExp.dll
2017-03-03 17:39 - 2016-07-21 10:54 - 000137728 _____ () C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\CBSCreateVC.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE trusted site: HKU\S-1-5-21-632860548-1775735820-415820443-1000\…\sjhnh.org -> hxxps://gateway1.sjhnh.org
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-13 21:34 - 2018-12-23 00:27 - 000000824 _____ C:\windows\system32\Drivers\etc\hosts
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-632860548-1775735820-415820443-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Barley\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 8.8.8.8 - 8.8.4.4
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
If an entry is included in the fixlist, it will be removed.
 
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk => C:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: BeatsOSDApp => C:\Program Files\IDT\WDM\beats64.exe
MSCONFIG\startupreg: DNS7reminder => "C:\Program Files (x86)\ScanSoft\NaturallySpeaking\Program\Ereg.exe" -r "C:\Program Files (x86)\ScanSoft\NaturallySpeaking\Program\ereg.ini"
MSCONFIG\startupreg: HP Software Update => c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: LifeCam => "C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe"
MSCONFIG\startupreg: Norton Online Backup => C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
MSCONFIG\startupreg: PWRISOVM.EXE => C:\Program Files (x86)\PowerISO\PWRISOVM.EXE -startup
MSCONFIG\startupreg: SysTrayApp => C:\Program Files\IDT\WDM\sttray64.exe
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{C40D9B13-61A2-4285-A4E7-E26BB14A390D}] => (Allow) C:\Program Files (x86)\Ralink\Common\RaMediaServer.exe ()
FirewallRules: [{8E66A095-795E-494F-8F39-F583A6C355AE}] => (Allow) C:\Program Files (x86)\Ralink\Common\RaMediaServer.exe ()
FirewallRules: [{64D8B223-4FDB-4856-984E-D6A313D081AC}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Remote Graphics Receiver\rgreceiver.exe (Hewlett-Packard)
FirewallRules: [{46D3AD7D-F0D3-4B5B-A87A-8A74DD670C45}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Remote Graphics Receiver\rgreceiver.exe (Hewlett-Packard)
FirewallRules: [{096CA7E4-26E4-4D3F-BCE6-8B421C198BB6}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\HP LinkUp\HP LinkUp Viewer.exe (Hewlett-Packard Company)
FirewallRules: [{62DA04C4-6D00-4D4D-83D7-0C35250D69CD}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\HP LinkUp\HP LinkUp Viewer.exe (Hewlett-Packard Company)
FirewallRules: [{77D34678-43F1-4822-B594-6E09D82214B1}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe (Skype Technologies S.A.)
FirewallRules: [{368B141D-50B1-4EE3-9F97-6978FEC3BCA7}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe (Microsoft Corporation)
FirewallRules: [{748AC05F-6DAF-4DDA-B7F8-49F3BAC6092C}] => (Allow) LPort=2869
FirewallRules: [{1A056468-B541-45F9-9F3B-9DE4103860F9}] => (Allow) LPort=1900
FirewallRules: [{47F869E4-237F-428A-87B2-B24C77087D97}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
FirewallRules: [{083D86A3-2137-4A0F-A1FD-6C5139F7A6D9}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe (Microsoft Corporation)
FirewallRules: [{3C757619-EA6B-4395-B7C1-7FD9D82913A0}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeCam.exe (Microsoft Corporation)
FirewallRules: [{337898BF-4E6C-4F28-B6FF-F4E0103C7088}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeCam.exe (Microsoft Corporation)
FirewallRules: [{72660C52-6CAD-426B-8480-9A4CCDA25FDE}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeEnC2.exe (Microsoft Corporation)
FirewallRules: [{A7ED8D1C-7DC5-4254-9A3C-7210F65BCA23}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeEnC2.exe (Microsoft Corporation)
FirewallRules: [{FC12E3B7-37DB-40F2-8007-7CDBA8F98DA1}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe (Microsoft Corporation)
FirewallRules: [{F8F68A5A-37F7-458F-A223-6EDFBEB178CF}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe (Microsoft Corporation)
FirewallRules: [{29DFB764-4E0E-4C7F-8E63-04BEEB9E85E5}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeTray.exe (Microsoft Corporation)
FirewallRules: [{6DFF213C-2E9D-40B4-93A0-96C6D06DBDBF}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeTray.exe (Microsoft Corporation)
FirewallRules: [{16F9FFA7-DE34-4195-8889-99836EA872DE}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
FirewallRules: [{188D6962-81EE-44A5-8C30-3730334E748F}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
FirewallRules: [{9DF14B61-33D7-4600-A2DC-8B67E3D34687}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc.)
FirewallRules: [{C02B03BE-C660-42B9-AF20-FE8402B12E27}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc.)
FirewallRules: [{1E46AAC8-F6F9-4A9E-80D6-C952FCBA08A4}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe No File
FirewallRules: [{C803B594-7DEF-49DD-B2B1-190FC1E5BDF0}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe No File
FirewallRules: [{E2A974B2-9D33-4747-A3E5-A6E3DB73D7A1}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpofxm08.exe No File
FirewallRules: [{B847FD57-37DB-41C1-B8EE-F834959F0586}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposfx08.exe No File
FirewallRules: [{2BC6FC16-2643-4675-8DA0-D440DAAB07D3}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposid01.exe (Hewlett-Packard Co.)
FirewallRules: [{2E5B1FB9-CD88-4C24-BCCA-1B1C98E43CF1}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqkygrp.exe (Hewlett-Packard)
FirewallRules: [{971D0E46-D0B7-4B59-A6F8-5474F692BAFC}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcopy2.exe No File
FirewallRules: [{BED31218-45AD-43F9-9FC9-381AE7CBE610}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpfccopy.exe ()
FirewallRules: [{2FC88A0B-5EB8-45B5-AEBA-CDA2C66C54B6}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpzwiz01.exe No File
FirewallRules: [{371C863F-1809-44C4-8001-AC3E16BC8CC9}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpoews01.exe (Hewlett-Packard Co.)
FirewallRules: [{AA1AED5A-88F8-45FE-BEBC-F85163E1DB67}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqnrs08.exe (Hewlett-Packard Co.)
FirewallRules: [{C9A77EEA-40C1-4D8F-8DA8-4E74A52A3F2A}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpiscnapp.exe (Hewlett-Packard)
FirewallRules: [{766360E0-0271-47DC-9292-260B4AF19224}] => (Allow) C:\Program Files (x86)\common files\hp\digital imaging\bin\hpqphotocrm.exe No File
FirewallRules: [{FBECA0C4-4012-4779-9914-18054013DF61}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqsudi.exe No File
FirewallRules: [{B51D41D8-9002-424B-96AE-995272DF678E}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqpsapp.exe No File
FirewallRules: [{FD780D56-F9B3-4CAA-9DFE-753F355A2B42}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpofxs08.exe No File
FirewallRules: [{EF53A754-678A-4A38-A8F1-2CA43185FD29}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqfxt08.exe No File
FirewallRules: [{37A40D7C-152E-4165-9107-66247F5ECEE8}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqpse.exe No File
FirewallRules: [{3A9268B3-2F0B-4490-8182-A74DFB16F9A1}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgplgtupl.exe (Hewlett-Packard Co.)
FirewallRules: [{62364A33-C195-4DAB-87F8-D01F2F09A8B4}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe (Hewlett-Packard)
FirewallRules: [{A33F9CEA-E81D-4C74-87BF-B40CE8544101}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgm.exe (Hewlett-Packard Co.)
FirewallRules: [{57303010-2E61-4E65-8DE8-0FD8771F2010}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgh.exe (Hewlett-Packard Co.)
FirewallRules: [{B5492CC8-06DF-47E8-8D6D-082A6BD1DF53}] => (Allow) C:\Program Files (x86)\HP\hp software update\hpwucli.exe (Hewlett-Packard)
FirewallRules: [{6D422CBB-1201-4676-A036-95969E82F3FE}] => (Allow) C:\Program Files (x86)\HP\digital imaging\smart web printing\smartwebprintexe.exe (Hewlett-Packard Co.)
FirewallRules: [{3ED30955-EFF3-4107-8BE4-689FCE621E0B}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe (TeamViewer GmbH)
FirewallRules: [{E0E4ABAD-93C0-4E6E-A0A0-A4A561496784}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe (TeamViewer GmbH)
FirewallRules: [{BD69C17B-9FC9-4912-A2C1-3AE23478EB2E}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe (TeamViewer GmbH)
FirewallRules: [{44605B2D-69D2-45FD-968A-081B858ACCBF}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe (TeamViewer GmbH)
FirewallRules: [{4243050D-CF14-483C-945D-B517D4B8E297}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
FirewallRules: [{6807B6A1-AAC1-4555-8EA4-D9633E4A34B6}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
FirewallRules: [{402DF736-0E3F-482F-813A-1E0EFF713B0E}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc.)
FirewallRules: [{F613D847-4755-4F67-9E83-CA8D9D16A333}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc.)
FirewallRules: [{524FBD36-AFE4-4D69-ACC6-FBAFA6255D9C}] => (Allow) C:\Program Files\iTunes\iTunes.exe (Apple Inc.)
FirewallRules: [{B497A808-16EF-4A4D-9A0B-B40E7343890A}] => (Allow) E:\Install\wlan_wiz\.\wlan_assistant\waw.exe No File
FirewallRules: [{316051F7-DEE7-47A6-B06C-7130CBFECE25}] => (Allow) LPort=54925
FirewallRules: [{3355062F-82C4-416B-BD10-2077C5EE5B54}] => (Allow) c:\program files (x86)\pc-faxreceive\brengineprocess.exe (Brother Industries, Ltd.)
FirewallRules: [{42C4E2DF-128F-46EF-80AB-44DB8071AB7F}] => (Allow) c:\program files (x86)\pc-faxreceive\brengineprocess.exe (Brother Industries, Ltd.)
FirewallRules: [{AE566146-EE91-4B46-A6C3-741877219C69}] => (Allow) C:\Program Files (x86)\AVG\Antivirus\AvEmUpdate.exe (AVG Technologies CZ, s.r.o.)
FirewallRules: [{AB4720B2-A03A-4E60-B06D-CE71795B241E}] => (Allow) C:\Program Files (x86)\AVG\Antivirus\AvEmUpdate.exe (AVG Technologies CZ, s.r.o.)
FirewallRules: [{5D6943E6-0633-4C12-8E44-B632FFD15340}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
FirewallRules: [{B8DA1F71-AC18-4883-88F2-B48A644C0CD2}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe (Piriform Ltd)
FirewallRules: [{9431D078-F9CC-4406-84BC-AD1A801972F0}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe (Piriform Ltd)
 
==================== Restore Points =========================
 
21-12-2018 01:12:55 Windows Update
22-12-2018 10:50:38 Removed CouponPrinterPlugin
22-12-2018 11:13:46 Restore Point Created by FRST
24-12-2018 12:08:53 Removed Digital Coupon Printer
24-12-2018 12:25:42 Removed RevTraxPrintMyCoupon
24-12-2018 12:26:51 Removed PrintMyCouponAnywhere
 
==================== Faulty Device Manager Devices =============
 
Name: Photosmart C6100 series
Description: Photosmart C6100 series
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
 
Name: Photosmart C6100 series
Description: Photosmart C6100 series
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
 
Name: Photosmart C6100 series
Description: Photosmart C6100 series
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
 
Name: Photosmart C6100 series
Description: Photosmart C6100 series
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
 
Name: Photosmart C6100 series
Description: Photosmart C6100 series
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
 
Name: Photosmart C6100 series
Description: Photosmart C6100 series
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
 
Name: AntiLog32
Description: AntiLog32
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer: 
Service: AntiLog32
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
 
Name: Photosmart C6100 series
Description: Photosmart C6100 series
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
 
Name: Photosmart C6100 series
Description: Photosmart C6100 series
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
 
Name: Photosmart C6100 series
Description: Photosmart C6100 series
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
 
Name: Photosmart C6100 series
Description: Photosmart C6100 series
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (12/24/2018 03:22:01 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: mbamservice.exe, version: 3.2.0.704, time stamp: 0x5b9acf90
Faulting module name: ntdll.dll, version: 6.1.7601.24308, time stamp: 0x5be8601e
Exception code: 0xc0000005
Fault offset: 0x0000000000032b04
Faulting process id: 0x714
Faulting application start time: 0x01d49ae700d914a0
Faulting application path: C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe
Faulting module path: C:\windows\SYSTEM32\ntdll.dll
Report Id: fc353145-0754-11e9-99d0-24be05218274
 
Error: (12/23/2018 12:40:40 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: mbamservice.exe, version: 3.2.0.704, time stamp: 0x5b9acf90
Faulting module name: SelfProtectionSdk.dll, version: 3.0.0.360, time stamp: 0x5b995ba2
Exception code: 0xc0000005
Fault offset: 0x000000000001f177
Faulting process id: 0x1c8c
Faulting application start time: 0x01d49adea763ca09
Faulting application path: C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe
Faulting module path: C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\SelfProtectionSdk.dll
Report Id: dce7af3b-06d9-11e9-b4a2-24be05218274
 
Error: (12/23/2018 12:25:38 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program Un_A.exe version 3.2.0.4 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
 
Process ID: a80
 
Start Time: 01d49a7d383060d0
 
Termination Time: 0
 
Application Path: C:\Users\Barley\AppData\Local\Temp\~nsuA.tmp\Un_A.exe
 
Report Id:
 
Error: (12/22/2018 11:14:43 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: svchost.exe, version: 6.1.7600.16385, time stamp: 0x4a5bc3c1
Faulting module name: ole32.dll, version: 6.1.7601.24291, time stamp: 0x5be78530
Exception code: 0xc0000005
Fault offset: 0x0000000000040cc2
Faulting process id: 0x15e0
Faulting application start time: 0x01d49a08c8a1e844
Faulting application path: C:\windows\system32\svchost.exe
Faulting module path: C:\windows\system32\ole32.dll
Report Id: b068b25d-0604-11e9-bd26-24be05218274
 
Error: (12/21/2018 10:33:08 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program aswMBR.exe version 1.0.1.2252 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
 
Process ID: 1c34
 
Start Time: 01d499a6ffb3ae09
 
Termination Time: 2
 
Application Path: C:\Users\Barley\Desktop\aswMBR.exe
 
Report Id: 49dfc6dd-059a-11e9-962c-24be05218274
 
Error: (12/20/2018 11:39:43 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: mbamservice.exe, version: 3.2.0.704, time stamp: 0x5b9acf90
Faulting module name: ntdll.dll, version: 6.1.7601.24308, time stamp: 0x5be8601e
Exception code: 0xc0000005
Fault offset: 0x0000000000032b04
Faulting process id: 0x1468
Faulting application start time: 0x01d498e473a5f40f
Faulting application path: C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe
Faulting module path: C:\windows\SYSTEM32\ntdll.dll
Report Id: 6f60daa2-04da-11e9-b7b1-24be05218274
 
Error: (12/18/2018 08:10:01 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 80746
 
Error: (12/18/2018 08:10:01 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 80746
 
 
System errors:
=============
Error: (12/24/2018 03:14:28 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Ralink UPnP Media Server service to connect.
 
Error: (12/24/2018 03:12:22 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has stopped unexpectedly.
 
Module Path: C:\windows\system32\RAIHV.dll
 
Error: (12/24/2018 03:12:22 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has stopped unexpectedly.
 
Module Path: C:\windows\system32\RAIHV.dll
 
Error: (12/24/2018 03:12:17 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has stopped unexpectedly.
 
Module Path: C:\windows\system32\RAIHV.dll
 
Error: (12/24/2018 03:12:07 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The HP Touchpoint Analytics service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (12/24/2018 03:12:07 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The PDF Document Manager service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (12/24/2018 03:12:07 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Software Protection service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 120000 milliseconds: Restart the service.
 
Error: (12/24/2018 03:12:07 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Media Player Network Sharing Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 30000 milliseconds: Restart the service.
 
 
CodeIntegrity:
===================================
 
Date: 2013-01-24 07:41:06.474
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
Date: 2013-01-24 07:41:06.456
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
==================== Memory info =========================== 
 
Processor: Intel(R) Core(TM) i3-2120 CPU @ 3.30GHz
Percentage of memory in use: 49%
Total physical RAM: 6030.01 MB
Available physical RAM: 3029.55 MB
Total Virtual: 12058.17 MB
Available Virtual: 8778.67 MB
 
==================== Drives ================================
 
Drive c: (OS) (Fixed) (Total:914.75 GB) (Free:754.9 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive d: (HP_RECOVERY) (Fixed) (Total:16.54 GB) (Free:2.06 GB) NTFS
 
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: C88C1F6D)
 
Partition: GPT.
 
==================== End of Addition.txt ============================

am I doing something wrong with that?

Might be

Let the scan complete. Once it's done, make sure that every item listed has a checked mark next to it and click on the Clean & Repair button. This will kill all the active processes
Once the cleaning process is complete, AdwCleaner will ask to restart your computer, do it

Is that what you followed?

I'm pushed for time at the moment might be quite a while before I can get back, I'll wish you a Merry Christmas now

Yes, I've been checking the boxes - but nothing gets deleted for some reason.

I just tried stopping the AVG to see if that made a difference but it didn't.

Also reinstalled the AdwCleaner.

 

But the computer is running fine, so I'm okay for now.

Have a nice Holiday and let me know if you have any other tricks up your sleeve when you get back - but no hurry!

 

Thanks again for your time.

 

 

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI