Yes, I was wondering about the AdwCleaner - I click Clean and Repair when the scan is done, then restart, then click Delete, but each time the log states "Not Deleted" and the same items come up on the next scan - am I doing something wrong with that?
And I did reboot after removing those extensions.
[removed]
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\AVGSvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Digital Wave Ltd.) C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Garmin Ltd or its subsidiaries) C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Microsoft Corporation) C:\Program Files\Microsoft LifeCam\MSCamS64.exe
(Garmin Ltd or its subsidiaries) C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\AVGUI.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Smilebox, Inc.) C:\Users\Barley\AppData\Roaming\Smilebox\SmileboxTray.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\NortonSecurity.exe
(PDF Complete Inc) C:\Program Files (x86)\PDF Complete\pdfsvc.exe
(Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaRegistry.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaRegistry64.exe
() C:\Users\Barley\AppData\Roaming\HP SimpleSave Application\StartHelper.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\Brother\Brother Help\BrotherHelp.exe
(the sz development) C:\Users\Barley\AppData\Local\RimhillEx\RimhillEx.exe
(Wondershare) C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\NortonSecurity.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\psia.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\sua.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(Microsoft Corporation) C:\Windows\System32\WirelessKB850NotificationService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\Browny02\BrYNSvc.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\x64\aswidsagenta.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Calendar\Service\GCalService.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Calendar\Service\HPTouchSmartSyncCalReminderApp.exe
(HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(HP Inc.) C:\Program Files\HP\HP Touchpoint Analytics Client\TouchpointAnalyticsClientService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\…\Run: [HPSYSDRV] => C:\Program Files (x86)\Hewlett-Packard\HP Odometer\HPSYSDRV.EXE [62768 2008-11-20] (Hewlett-Packard)
HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176440 2016-11-01] (Apple Inc.)
HKLM\…\Run: [AVGUI.exe] => C:\Program Files (x86)\AVG\Antivirus\AvLaunch.exe [290064 2018-11-15] (AVG Technologies CZ, s.r.o.)
HKLM-x32\…\Run: [ControlCenter4] => C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe [139776 2014-11-12] (Brother Industries, Ltd.)
HKLM-x32\…\Run: [BrStsMon00] => C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [4517376 2014-11-11] (Brother Industries, Ltd.)
HKLM-x32\…\Run: [BrHelp] => C:\Program Files (x86)\Brother\Brother Help\BrotherHelp.exe [1939968 2014-10-22] (Brother Industries, Ltd.)
HKLM-x32\…\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2137744 2016-10-08] (Wondershare)
HKLM-x32\…\Run: [DelaypluginInstall] => C:\ProgramData\Wondershare\Video Converter Ultimate\DelayPluginI.exe [1971856 2017-02-16] ()
HKLM-x32\…\Run: [PDF Complete] => C:\Program Files (x86)\PDF Complete\pdfsty.exe [1194048 2018-02-01] (PDF Complete Inc)
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [601424 2018-10-06] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\windows\System32\igfxdev.dll (Intel Corporation)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-632860548-1775735820-415820443-1000\…\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1095000 2013-12-13] (Garmin Ltd or its subsidiaries)
HKU\S-1-5-21-632860548-1775735820-415820443-1000\…\Run: [Google Update] => C:\Users\Barley\AppData\Local\Google\Update\1.3.33.23\GoogleUpdateCore.exe [605992 2018-12-18] (Google Inc.)
HKU\S-1-5-21-632860548-1775735820-415820443-1000\…\Run: [60439BD48E4DF21A7F8F35AA69AA655C496AD691._service_run] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1587680 2018-12-12] (Google Inc.)
HKU\S-1-5-21-632860548-1775735820-415820443-1000\…\Run: [SmileboxTray] => C:\Users\Barley\AppData\Roaming\Smilebox\SmileboxTray.exe [366552 2017-09-27] (Smilebox, Inc.)
HKU\S-1-5-21-632860548-1775735820-415820443-1000\…\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [19589208 2018-12-10] (Piriform Software Ltd)
HKU\S-1-5-21-632860548-1775735820-415820443-1000\…\Run: [GoogleChromeAutoLaunch_457733C4A2F5F6E1F2B25B1F77F935C9] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1587680 2018-12-12] (Google Inc.)
HKU\S-1-5-21-632860548-1775735820-415820443-1000\…\MountPoints2: {cf036f94-4e8d-11e2-b318-24be05218274} - G:\HPLauncher.exe
HKU\S-1-5-21-632860548-1775735820-415820443-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\windows\system32\Ribbons.scr [241664 2010-11-20] (Microsoft Corporation)
HKLM\…\Drivers32: [MSVideo8] => C:\windows\System32\VfWWDM32.dll [68096 2010-11-20] (Microsoft Corporation)
HKLM\…\Drivers32-x32: [msacm.siren] => C:\Windows\SysWOW64\sirenacm.dll [49016 2011-05-13] (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk [2014-03-18]
ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia)
Startup: C:\Users\Barley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\HP SimpleSave Monitor.lnk [2014-03-01]
ShortcutTarget: HP SimpleSave Monitor.lnk -> C:\Users\Barley\AppData\Roaming\HP SimpleSave Application\StartHelper.exe ()
Startup: C:\Users\Barley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RimhillEx.lnk [2017-01-15]
ShortcutTarget: RimhillEx.lnk -> C:\Users\Barley\AppData\Local\RimhillEx\RimhillEx.exe (the sz development)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{06AE0B1F-FB3C-4241-9145-DF12EC7CB857}: [DhcpNameServer] 172.20.10.1
Tcpip\..\Interfaces\{D3EED012-4886-4C2D-8491-DD153D715076}: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{D3EED012-4886-4C2D-8491-DD153D715076}: [DhcpNameServer] 75.75.75.75 75.75.76.76
Internet Explorer:
==================
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Norton Password Manager -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\coIEPlg.dll [2018-11-03] (Symantec Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_191\bin\jp2ssv.dll [2018-12-01] (Oracle Corporation)
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2016-07-21] (HP Inc.)
BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-09-20] (Hewlett-Packard Co.)
BHO-x32: Wondershare Video Converter Ultimate 7.1.0 -> {451C804F-C205-4F03-B48E-537EC94937BF} -> C:\ProgramData\Wondershare\Video Converter Ultimate\WSBrowserAppMgr.dll [2017-02-16] (Wondershare)
BHO-x32: Norton Password Manager -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton Internet Security\Engine32\22.16.2.22\coIEPlg.dll [2018-11-03] (Symantec Corporation)
BHO-x32: No Name -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> No File
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2016-07-21] (HP Inc.)
BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-09-20] (Hewlett-Packard Co.)
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\coIEPlg.dll [2018-11-03] (Symantec Corporation)
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine32\22.16.2.22\coIEPlg.dll [2018-11-03] (Symantec Corporation)
Toolbar: HKU\S-1-5-21-632860548-1775735820-415820443-1000 -> Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\coIEPlg.dll [2018-11-03] (Symantec Corporation)
FireFox:
========
FF ProfilePath: C:\Users\Barley\AppData\Roaming\Mozilla\Firefox\Profiles\z9dx3jxz.default [2018-12-23]
FF Extension: (Wondershare Video Converter Ultimate) - C:\ProgramData\Wondershare\Video Converter Ultimate\WSVCU@Wondershare.com_xpi\ [] [Legacy]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: (HP Smart Web Printing) - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2013-02-03] [Legacy] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\ProgramData\Wondershare\Video Converter Ultimate\WSVCU@Wondershare.com_xpi
FF Extension: (Wondershare Video Converter Ultimate) - C:\ProgramData\Wondershare\Video Converter Ultimate\WSVCU@Wondershare.com_xpi [2017-03-03] [Legacy]
FF HKU\S-1-5-21-632860548-1775735820-415820443-1000\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_32_0_0_101.dll [2018-12-05] ()
FF Plugin: @java.com/DTPlugin,version=11.191.2 -> C:\Program Files\Java\jre1.8.0_191\bin\dtplugin\npDeployJava1.dll [2018-12-01] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.191.2 -> C:\Program Files\Java\jre1.8.0_191\bin\plugin2\npjp2.dll [2018-12-01] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_101.dll [2018-12-05] ()
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @Sibelius.com/Scorch Plugin,version=6.2.0.88 -> C:\Program Files (x86)\Sibelius Software\Scorch\npsibelius.dll [2013-03-11] ()
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.23\npGoogleUpdate3.dll [2018-12-18] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.23\npGoogleUpdate3.dll [2018-12-18] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2011-09-28] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-12-04] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-632860548-1775735820-415820443-1000: @tools.google.com/Google Update;version=3 -> C:\Users\Barley\AppData\Local\Google\Update\1.3.33.23\npGoogleUpdate3.dll [2018-12-18] (Google Inc.)
FF Plugin HKU\S-1-5-21-632860548-1775735820-415820443-1000: @tools.google.com/Google Update;version=9 -> C:\Users\Barley\AppData\Local\Google\Update\1.3.33.23\npGoogleUpdate3.dll [2018-12-18] (Google Inc.)
FF Plugin HKU\S-1-5-21-632860548-1775735820-415820443-1000: CouponNetwork.com/CMDUniversalCouponPrintActivator -> C:\Users\Barley\AppData\Roaming\CATALI~1\NPBCSK~1.DLL [No File]
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\browser\plugins\npMozCouponPrinter.dll [2015-09-18] (Coupons, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Barley\AppData\Roaming\mozilla\plugins\npatgpc.dll [2015-11-18] (Cisco WebEx LLC)
Chrome:
=======
CHR DefaultProfile: Profile 1
CHR HomePage: Profile 1 -> hxxp://www.google.com/
CHR StartupUrls: Profile 1 -> "hxxp://www.google.com/"
CHR NewTab: Profile 1 -> Not-active:"chrome-extension://bkpkokkapfiigghcbhkblnngjlcccckf/index.html", Not-active:"chrome-extension://lpdcomiegbcchfdacgnkemnicebaodne/newtab/newtab.html", Not-active:"chrome-extension://gbioooacocedmkdadhinnkjonienkfbe/stubby.html", Not-active:"chrome-extension://dpgfhhkchdfegbdmjginkcffgjncmboh/stubby.html"
CHR Profile: C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Guest Profile [2018-12-23]
CHR Profile: C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1 [2018-12-24]
CHR Extension: (Share to Classroom) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\adokjfanaflbkibffcbhihgihpgijcei [2018-12-24]
CHR Extension: (Bejeweled) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\adpkifcfcacgmnggcbpbjbkdijciiigm [2015-04-15]
CHR Extension: (Asus Download Master) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\akidbpofokakpmmabjlpcgplfmbmcemj [2015-04-15]
CHR Extension: (Docs) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-12]
CHR Extension: (Google Drive) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21]
CHR Extension: (Destiny Discover) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bbhkckkafippkgeicobhgafkioeblebh [2018-12-24]
CHR Extension: (Quizlet) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bgofflgeghkhocbociocnckocbjmomjh [2018-12-24]
CHR Extension: (Desmos Graphing Calculator) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bhdheahnajobgndecdbggfmcojekgdko [2018-12-24]
CHR Extension: (YouTube) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-25]
CHR Extension: (GeoGebra Classic) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bnbaboaihhkjoaolfnfoablhllahjnee [2018-12-24]
CHR Extension: (Norton Security Toolbar) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\cjabmdjcfcfdmffimndhafhblfmpjdpe [2018-11-19]
CHR Extension: (Google Search) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27]
CHR Extension: (Fancy Pants 3) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ddmbgnlndmdpfggbojljojamjkkikeka [2015-04-15]
CHR Extension: (Vernier Graphical Analysis) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\dncgedbnidfkppmdgfgidcepclnokpkb [2018-12-24]
CHR Extension: (Pear Deck) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\dnloadmamaeibnaadmfdfelflmmnbajd [2018-12-24]
CHR Extension: (FromDocToPDF) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\dpgfhhkchdfegbdmjginkcffgjncmboh [2018-12-10]
CHR Extension: (App for Instagram) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ebmdoffeooapnmjcnidddmhancpfpjab [2018-12-12]
CHR Extension: (Destiny Discover) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eebnbmbhdfnfhfhigoklhaklkodghbla [2018-12-24]
CHR Extension: (Adobe Acrobat) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-03-15]
CHR Extension: (PicMonkey) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fgdgokchhicmaiacmgegjnppjkgogdhm [2018-12-24]
CHR Extension: (OnlineMapFinder) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gbioooacocedmkdadhinnkjonienkfbe [2018-12-10]
CHR Extension: (Google Docs Offline) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-08-14]
CHR Extension: (goo.gl URL Shortener (Unofficial)) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iblijlcdoidgdpfknkckljiocdbnlagk [2018-12-24]
CHR Extension: (Norton Identity Safe) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iikflkcanblccfahdhdonehdalibjnif [2015-02-07]
CHR Extension: (Voice Recorder) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\jehegmanppiacmmpiifhjalpkigpcida [2018-12-24]
CHR Extension: (Cisco Webex Extension) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\jlhmfgmfgeifomenelglieieghnjghma [2018-07-05]
CHR Extension: (mydlink services plugin) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ldibdoepbjbkkcbgndfljnphngpglhbb [2016-01-01]
CHR Extension: (Lightspeed User Agent) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lnidfclfgppmpldkkchcpoegjlcbaekc [2018-12-24] [UpdateUrl: hxxps://lsrelay-extensions-staging.s3.amazonaws.com/chrome_ua/1bf15dff521aff9f15e160f73e7a18ab5206eb1bfa7eb5b71b5d983899285034/UserAgent.xml] <==== ATTENTION
CHR Extension: (FromDocToPDF) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mallpejgeafdahhflmliiahjdpgbegpk [2018-12-10]
CHR Extension: (Google Classroom) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mfhehppjhmmnlfbbopchdfldgimhfhfk [2018-12-24]
CHR Extension: (Socrative Student) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nblhpecglllndfihipmpdoikimcmgkha [2018-12-24]
CHR Extension: (ScanQR) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nihhbejdflkeingkkpakffdlmepaeaah [2018-12-24]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-04]
CHR Extension: (Gmail) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-28]
CHR Extension: (Padlet) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ppckapbnfhikdajgehibjapcohbaomhd [2018-12-24]
CHR Profile: C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 2 [2018-12-23]
CHR Extension: (Slides) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-12-06]
CHR Extension: (Docs) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aohghmighlieiainnegkcijnfilokake [2018-12-06]
CHR Extension: (Google Drive) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-08-18]
CHR Extension: (YouTube) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-12-06]
CHR Extension: (Norton Security Toolbar) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\cjabmdjcfcfdmffimndhafhblfmpjdpe [2015-08-18]
CHR Extension: (Google Search) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-08-18]
CHR Extension: (Adobe Acrobat) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2018-12-06]
CHR Extension: (Sheets) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-12-06]
CHR Extension: (Google Docs Offline) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-12-06]
CHR Extension: (Norton Identity Safe) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\iikflkcanblccfahdhdonehdalibjnif [2015-08-18]
CHR Extension: (AVG SafePrice | Comparison, deals, coupons) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\mbckjcfnjmoiinpgddefodcighgikkgn [2018-12-06]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-12-06]
CHR Extension: (Amazon.com Search Settings) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ooebgdicanjhnamfmdlmlbcnkgehkkmf [2018-12-06]
CHR Extension: (Gmail) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-08-18]
CHR Extension: (Chrome Media Router) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-12-06]
CHR Profile: C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3 [2018-12-23]
CHR Extension: (Slides) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-12-06]
CHR Extension: (Entanglement Web App) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\aciahcmjmecflokailenpkdchphgkefd [2018-12-06]
CHR Extension: (Docs) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\aohghmighlieiainnegkcijnfilokake [2018-12-06]
CHR Extension: (Google Drive) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-12-06]
CHR Extension: (YouTube) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-12-06]
CHR Extension: (Adblock Plus) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2018-12-06]
CHR Extension: (Pushbullet) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\chlffgpmiacpedhhbkiomidkjlcfhogd [2018-12-06]
CHR Extension: (Norton Security Toolbar) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\cjabmdjcfcfdmffimndhafhblfmpjdpe [2018-12-06]
CHR Extension: (Spotify - Music for every moment) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\cnkjkdjlofllcpbemipjbcpfnglbgieh [2018-12-06]
CHR Extension: (Adobe Acrobat) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2018-12-06]
CHR Extension: (Photo Zoom for Facebook) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\elioihkkcdgakfbahdoddophfngopipi [2018-12-06]
CHR Extension: (Sheets) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-12-06]
CHR Extension: (Google Docs Offline) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-12-08]
CHR Extension: (AVG SafePrice | Comparison, deals, coupons) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\mbckjcfnjmoiinpgddefodcighgikkgn [2018-12-06]
CHR Extension: (Poppit!) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\mcbkbpnkkkipelfledbfocopglifcfmi [2018-12-06]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-12-06]
CHR Extension: (Amazon.com Search Settings) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\ooebgdicanjhnamfmdlmlbcnkgehkkmf [2018-12-06]
CHR Extension: (Gmail) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-12-06]
CHR Extension: (Chrome Media Router) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-12-07]
CHR Profile: C:\Users\Barley\AppData\Local\Google\Chrome\User Data\System Profile [2018-12-23]
CHR Extension: (Google Slides) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-05-30]
CHR Extension: (Google Docs) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\aohghmighlieiainnegkcijnfilokake [2015-05-30]
CHR Extension: (Google Drive) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-05-30]
CHR Extension: (YouTube) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-05-30]
CHR Extension: (Google Search) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-05-30]
CHR Extension: (Google Sheets) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-05-30]
CHR Extension: (Gmail) - C:\Users\Barley\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-05-30]
CHR HKLM\…\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\Exts\Chrome.crx
CHR HKLM\…\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\Exts\Chrome.crx
CHR HKLM-x32\…\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [mbckjcfnjmoiinpgddefodcighgikkgn] - hxxps://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-09-22] (Apple Inc.)
R2 AVG Antivirus; C:\Program Files (x86)\AVG\Antivirus\AVGSvc.exe [324048 2018-11-15] (AVG Technologies CZ, s.r.o.)
R3 avgbIDSAgent; C:\Program Files (x86)\AVG\Antivirus\x64\aswidsagenta.exe [8237160 2018-11-15] (AVG Technologies CZ, s.r.o.)
R3 BrYNSvc; C:\Program Files (x86)\Browny02\BrYNSvc.exe [289792 2014-10-23] (Brother Industries, Ltd.) [File not signed]
R2 CalendarSynchService; C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Calendar\Service\GCalService.exe [16384 2011-08-16] (Hewlett-Packard) [File not signed]
R2 DigitalWave.Update.Service; C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe [440808 2017-01-20] (Digital Wave Ltd.)
R2 Garmin Core Update Service; C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [250712 2013-12-13] (Garmin Ltd or its subsidiaries)
S3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [249344 2009-09-20] (Hewlett-Packard Co.) [File not signed]
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [347512 2018-12-06] (HP Inc.)
R2 HPTouchpointAnalyticsService; C:\Program Files\HP\HP Touchpoint Analytics Client\TouchpointAnalyticsClientService.exe [332216 2017-11-22] (HP Inc.)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6347056 2018-09-19] (Malwarebytes)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2008-12-03] (Hewlett-Packard) [File not signed]
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-01] (Symantec Corporation)
R2 NortonSecurity; C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\NortonSecurity.exe [328648 2018-11-03] (Symantec Corporation)
R2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [1795136 2018-02-01] (PDF Complete Inc)
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2008-12-03] (Hewlett-Packard) [File not signed]
R2 RalinkRegistryWriter; C:\Program Files (x86)\Ralink\Common\RaRegistry.exe [372736 2012-01-13] (Ralink Technology, Corp.) [File not signed]
R2 RalinkRegistryWriter64; C:\Program Files (x86)\Ralink\Common\RaRegistry64.exe [447488 2012-01-13] (Ralink Technology, Corp.) [File not signed]
S2 RaMediaServer; C:\Program Files (x86)\Ralink\Common\RaMediaServer.exe [625728 2011-08-18] ()
R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1229528 2013-12-06] (Secunia)
R2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [662232 2013-12-06] (Secunia)
R2 STacSV; C:\Program Files\IDT\WDM\STacSV64.exe [311296 2012-03-30] (IDT, Inc.) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
R2 WirelessKB850NotificationService; C:\windows\system32\WirelessKB850NotificationService.exe [174256 2018-05-14] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 avgArPot; C:\windows\System32\drivers\avgArPot.sys [201504 2018-11-15] (AVG Technologies CZ, s.r.o.)
R1 avgbidsdriver; C:\windows\System32\drivers\avgbidsdrivera.sys [231104 2018-11-15] (AVG Technologies CZ, s.r.o.)
R0 avgbidsh; C:\windows\System32\drivers\avgbidsha.sys [202528 2018-11-15] (AVG Technologies CZ, s.r.o.)
R0 avgblog; C:\windows\System32\drivers\avgbloga.sys [346840 2018-11-15] (AVG Technologies CZ, s.r.o.)
R0 avgbuniv; C:\windows\System32\drivers\avgbuniva.sys [59744 2018-11-15] (AVG Technologies CZ, s.r.o.)
S3 avgHwid; C:\windows\System32\drivers\avgHwid.sys [46648 2018-11-15] (AVG Technologies CZ, s.r.o.)
R1 avgKbd; C:\windows\System32\drivers\avgKbd.sys [42552 2018-11-15] (AVG Technologies CZ, s.r.o.)
R2 avgMonFlt; C:\windows\System32\drivers\avgMonFlt.sys [163496 2018-11-15] (AVG Technologies CZ, s.r.o.)
R1 avgRdr; C:\windows\System32\drivers\avgRdr2.sys [112040 2018-11-15] (AVG Technologies CZ, s.r.o.)
R0 avgRvrt; C:\windows\System32\drivers\avgRvrt.sys [87680 2018-11-15] (AVG Technologies CZ, s.r.o.)
R1 avgSnx; C:\windows\System32\drivers\avgSnx.sys [1028920 2018-11-15] (AVG Technologies CZ, s.r.o.)
R1 avgSP; C:\windows\System32\drivers\avgSP.sys [469520 2018-11-15] (AVG Technologies CZ, s.r.o.)
R2 avgStm; C:\windows\System32\drivers\avgStm.sys [208712 2018-11-15] (AVG Technologies CZ, s.r.o.)
R0 avgVmm; C:\windows\System32\drivers\avgVmm.sys [380704 2018-11-15] (AVG Technologies CZ, s.r.o.)
R1 BHDrvx64; C:\Program Files (x86)\Norton Internet Security\NortonData\22.5.2.15\Definitions\BASHDefs\20181016.001\BHDrvx64.sys [1925104 2018-10-16] (Symantec Corporation)
R1 ccSet_NGC; C:\windows\System32\drivers\NGCx64\1610020.016\ccSetx64.sys [189120 2018-11-03] (Symantec Corporation)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [515776 2018-10-20] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [153280 2018-10-22] (Symantec Corporation)
R1 IDSVia64; C:\Program Files (x86)\Norton Internet Security\NortonData\22.5.2.15\Definitions\IPSDefs\20181019.061\IDSvia64.sys [1305072 2018-10-19] (Symantec Corporation)
R3 MBAMSwissArmy; C:\windows\System32\Drivers\mbamswissarmy.sys [260384 2018-12-24] (Malwarebytes)
S3 PSI; C:\windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2013-12-06] (Secunia)
R3 SRTSP; C:\windows\System32\drivers\NGCx64\1610020.016\SRTSP64.SYS [847344 2018-11-03] (Symantec Corporation)
R1 SRTSPX; C:\windows\System32\drivers\NGCx64\1610020.016\SRTSPX64.SYS [49648 2018-11-03] (Symantec Corporation)
R0 SymEFASI; C:\windows\System32\drivers\NGCx64\1610020.016\SYMEFASI64.SYS [1969328 2018-11-03] (Symantec Corporation)
R3 SymEvent; C:\windows\system32\Drivers\SYMEVENT64x86.SYS [99920 2018-06-17] (Symantec Corporation)
S4 SymEvnt; C:\Program Files (x86)\Norton Internet Security\NortonData\22.5.2.15\SymPlatform\SymEvnt.sys [114256 2018-09-27] (Symantec Corporation)
R1 SymIRON; C:\windows\System32\drivers\NGCx64\1610020.016\Ironx64.SYS [308416 2018-11-03] (Symantec Corporation)
R1 SymNetS; C:\windows\System32\drivers\NGCx64\1610020.016\symnets.sys [567024 2018-11-03] (Symantec Corporation)
S3 wpCtrlDrv_NGC; C:\windows\System32\drivers\NGCx64\1610020.016\wpCtrlDrv.sys [1011056 2018-11-03] (Symantec Corporation)
S1 AntiLog32; \??\C:\windows\system32\drivers\AntiLog64.sys [X]
S3 NAVENG; \??\C:\Program Files (x86)\Norton Internet Security\NortonData\22.5.2.15\Definitions\SDSDefs\20160823.022\ENG64.SYS [X]
S3 NAVEX15; \??\C:\Program Files (x86)\Norton Internet Security\NortonData\22.5.2.15\Definitions\SDSDefs\20160823.022\EX64.SYS [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-12-24 15:14 - 2018-12-24 15:14 - 000260384 _____ (Malwarebytes) C:\windows\system32\Drivers\mbamswissarmy.sys
2018-12-24 13:20 - 2018-12-24 13:20 - 007320272 _____ (Malwarebytes) C:\Users\Barley\Desktop\adwcleaner_7.2.6.0(3).exe
2018-12-24 13:09 - 2018-12-24 13:09 - 000000000 ____D C:\windows\System32\Tasks\Remediation
2018-12-24 12:01 - 2018-12-24 12:01 - 007320272 _____ (Malwarebytes) C:\Users\Barley\Desktop\adwcleaner_7.2.6.0(2).exe
2018-12-23 22:34 - 2018-12-24 00:13 - 000000239 _____ C:\Users\Barley\Desktop\Search.txt
2018-12-23 22:32 - 2018-12-24 15:17 - 000000000 ____D C:\Users\Barley\Desktop\FRST-OlderVersion
2018-12-23 12:22 - 2018-12-23 12:22 - 000002422 _____ C:\Users\Barley\Desktop\Forensics_181223-122219.txt
2018-12-23 12:11 - 2018-12-23 12:11 - 000000000 ____D C:\ProgramData\Emsisoft
2018-12-23 12:07 - 2018-12-23 12:22 - 000000000 ____D C:\EEK
2018-12-23 12:04 - 2018-12-23 12:06 - 355354792 _____ C:\Users\Barley\Downloads\EmsisoftEmergencyKit.exe
2018-12-23 12:00 - 2018-12-23 12:00 - 000001489 _____ C:\Users\Barley\Desktop\Malwarebytestxt1.txt
2018-12-23 11:43 - 2018-12-23 11:43 - 000001869 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2018-12-23 11:43 - 2018-12-23 11:43 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2018-12-23 11:43 - 2018-09-11 13:18 - 000152688 _____ (Malwarebytes) C:\windows\system32\Drivers\mbae64.sys
2018-12-23 11:42 - 2018-12-23 11:42 - 080022264 _____ (Malwarebytes ) C:\Users\Barley\Downloads\mb3-setup-1878.1878-3.6.1.2711.exe
2018-12-23 01:02 - 2018-12-23 01:02 - 000000256 _____ C:\Users\Barley\Documents\cc_20181223_010208.reg
2018-12-23 00:58 - 2018-12-23 00:59 - 000525076 _____ C:\Users\Barley\Documents\cc_20181223_005852.reg
2018-12-23 00:54 - 2018-12-23 00:54 - 019299120 _____ (Piriform Software Ltd) C:\Users\Barley\Downloads\ccsetup551.exe
2018-12-23 00:54 - 2018-12-23 00:54 - 000003870 _____ C:\windows\System32\Tasks\CCleaner Update
2018-12-23 00:54 - 2018-12-23 00:54 - 000002812 _____ C:\windows\System32\Tasks\CCleanerSkipUAC
2018-12-23 00:54 - 2018-12-23 00:54 - 000000824 _____ C:\Users\Public\Desktop\CCleaner.lnk
2018-12-23 00:54 - 2018-12-23 00:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2018-12-23 00:54 - 2018-12-23 00:54 - 000000000 ____D C:\Program Files\CCleaner
2018-12-23 00:45 - 2018-12-23 00:46 - 004707504 _____ (hxxp://www.specialuninstaller.com/ ) C:\Users\Barley\Downloads\SpecialUninstaller_setup.exe
2018-12-23 00:03 - 2018-12-23 00:03 - 000000000 ____D C:\ProgramData\Reason
2018-12-22 23:10 - 2018-12-22 23:10 - 000000000 ____D C:\Program Files\Reason
2018-12-22 12:08 - 2018-12-23 10:38 - 000000860 _____ C:\Users\Public\Desktop\RogueKiller.lnk
2018-12-22 12:08 - 2018-12-23 10:38 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
2018-12-22 12:08 - 2018-12-22 13:07 - 000000000 ____D C:\ProgramData\RogueKiller
2018-12-22 12:07 - 2018-12-23 10:38 - 000000000 ____D C:\Program Files\RogueKiller
2018-12-22 12:06 - 2018-12-22 12:06 - 029155072 _____ (Adlice Software ) C:\Users\Barley\Desktop\RogueKiller_setup.exe
2018-12-22 12:05 - 2018-12-22 12:06 - 029155072 _____ (Adlice Software ) C:\Users\Barley\Downloads\RogueKiller_setup.exe
2018-12-22 11:59 - 2018-12-22 11:59 - 007320272 _____ (Malwarebytes) C:\Users\Barley\Desktop\adwcleaner_7.2.6.0(1).exe
2018-12-22 11:32 - 2018-12-22 11:32 - 007320272 _____ (Malwarebytes) C:\Users\Barley\Desktop\adwcleaner_7.2.6.0.exe
2018-12-22 11:30 - 2018-12-22 11:30 - 007320272 _____ (Malwarebytes) C:\Users\Barley\Downloads\adwcleaner_7.2.6.0.exe
2018-12-22 11:29 - 2018-12-22 11:35 - 000000000 ____D C:\AdwCleaner
2018-12-22 11:29 - 2018-12-22 11:29 - 007592144 _____ (Malwarebytes) C:\Users\Barley\Desktop\AdwCleaner.exe
2018-12-22 11:13 - 2018-12-22 11:16 - 000022243 _____ C:\Users\Barley\Desktop\Fixlog.txt
2018-12-21 22:55 - 2018-12-22 11:12 - 000068782 _____ C:\Users\Barley\Desktop\Addition.txt
2018-12-21 22:51 - 2018-12-24 15:18 - 000038953 _____ C:\Users\Barley\Desktop\FRST.txt
2018-12-21 22:50 - 2018-12-24 15:17 - 002421760 _____ (Farbar) C:\Users\Barley\Desktop\FRST64.exe
2018-12-21 22:50 - 2018-12-23 22:32 - 000000000 ____D C:\FRST
2018-12-21 22:48 - 2018-12-21 22:48 - 002420224 _____ (Farbar) C:\Users\Barley\Downloads\FRST64.exe
2018-12-21 22:42 - 2018-12-21 22:42 - 000001845 _____ C:\Users\Barley\Desktop\aswMBR.txt
2018-12-21 22:42 - 2018-12-21 22:42 - 000000512 _____ C:\Users\Barley\Desktop\MBR.dat
2018-12-21 22:31 - 2018-12-21 22:31 - 005198336 _____ (AVAST Software) C:\Users\Barley\Downloads\aswMBR (2).exe
2018-12-21 22:31 - 2018-12-21 22:22 - 005198336 _____ (AVAST Software) C:\Users\Barley\Desktop\aswMBR.exe
2018-12-21 22:25 - 2018-12-21 22:25 - 005198336 _____ (AVAST Software) C:\Users\Barley\Downloads\aswMBR (1).exe
2018-12-21 22:22 - 2018-12-21 22:22 - 005198336 _____ (AVAST Software) C:\Users\Barley\Downloads\aswMBR.exe
2018-12-21 16:19 - 2018-12-21 16:20 - 081227760 _____ (Malwarebytes ) C:\Users\Barley\Downloads\mb3-setup-consumer-3.6.1.2711-1.0.508-1.0.8211.exe
2018-12-20 23:07 - 2018-12-14 19:06 - 000397088 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2018-12-20 23:07 - 2018-12-14 18:14 - 000348760 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2018-12-20 23:07 - 2018-12-14 03:09 - 025736704 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2018-12-20 23:07 - 2018-12-14 03:01 - 002724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2018-12-20 23:07 - 2018-12-14 03:01 - 000004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2018-12-20 23:07 - 2018-12-14 02:51 - 002902016 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2018-12-20 23:07 - 2018-12-14 02:49 - 000417280 _____ (Microsoft Corporation) C:\windows\system32\html.iec
2018-12-20 23:07 - 2018-12-14 02:49 - 000066560 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2018-12-20 23:07 - 2018-12-14 02:49 - 000048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2018-12-20 23:07 - 2018-12-14 02:48 - 000576512 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2018-12-20 23:07 - 2018-12-14 02:48 - 000088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2018-12-20 23:07 - 2018-12-14 02:42 - 000054784 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2018-12-20 23:07 - 2018-12-14 02:41 - 000034304 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2018-12-20 23:07 - 2018-12-14 02:39 - 000615936 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2018-12-20 23:07 - 2018-12-14 02:38 - 000814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2018-12-20 23:07 - 2018-12-14 02:38 - 000790016 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2018-12-20 23:07 - 2018-12-14 02:38 - 000144384 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2018-12-20 23:07 - 2018-12-14 02:38 - 000116224 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2018-12-20 23:07 - 2018-12-14 02:36 - 005779456 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2018-12-20 23:07 - 2018-12-14 02:33 - 000969216 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2018-12-20 23:07 - 2018-12-14 02:30 - 000489984 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2018-12-20 23:07 - 2018-12-14 02:24 - 000087552 _____ (Microsoft Corporation) C:\windows\system32\tdc.ocx
2018-12-20 23:07 - 2018-12-14 02:24 - 000077824 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2018-12-20 23:07 - 2018-12-14 02:23 - 000107520 _____ (Microsoft Corporation) C:\windows\system32\inseng.dll
2018-12-20 23:07 - 2018-12-14 02:21 - 000199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2018-12-20 23:07 - 2018-12-14 02:20 - 000092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2018-12-20 23:07 - 2018-12-14 02:18 - 000315392 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2018-12-20 23:07 - 2018-12-14 02:17 - 000152064 _____ (Microsoft Corporation) C:\windows\system32\occache.dll
2018-12-20 23:07 - 2018-12-14 02:09 - 000262144 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll
2018-12-20 23:07 - 2018-12-14 02:06 - 000809472 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2018-12-20 23:07 - 2018-12-14 02:06 - 000728064 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2018-12-20 23:07 - 2018-12-14 02:05 - 001359360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2018-12-20 23:07 - 2018-12-14 02:04 - 002136064 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2018-12-20 23:07 - 2018-12-14 02:02 - 015284736 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2018-12-20 23:07 - 2018-12-14 01:58 - 020280832 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2018-12-20 23:07 - 2018-12-14 01:57 - 004859904 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2018-12-20 23:07 - 2018-12-14 01:51 - 002724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2018-12-20 23:07 - 2018-12-14 01:45 - 001555968 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2018-12-20 23:07 - 2018-12-14 01:41 - 000498176 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2018-12-20 23:07 - 2018-12-14 01:41 - 000062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2018-12-20 23:07 - 2018-12-14 01:40 - 000341504 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec
2018-12-20 23:07 - 2018-12-14 01:40 - 000047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2018-12-20 23:07 - 2018-12-14 01:39 - 000064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2018-12-20 23:07 - 2018-12-14 01:38 - 002295808 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2018-12-20 23:07 - 2018-12-14 01:35 - 000047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2018-12-20 23:07 - 2018-12-14 01:35 - 000030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2018-12-20 23:07 - 2018-12-14 01:34 - 000800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2018-12-20 23:07 - 2018-12-14 01:34 - 000476160 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2018-12-20 23:07 - 2018-12-14 01:33 - 000663040 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2018-12-20 23:07 - 2018-12-14 01:33 - 000115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2018-12-20 23:07 - 2018-12-14 01:32 - 000620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2018-12-20 23:07 - 2018-12-14 01:26 - 000416256 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2018-12-20 23:07 - 2018-12-14 01:23 - 000060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2018-12-20 23:07 - 2018-12-14 01:22 - 000091136 _____ (Microsoft Corporation) C:\windows\SysWOW64\inseng.dll
2018-12-20 23:07 - 2018-12-14 01:22 - 000073216 _____ (Microsoft Corporation) C:\windows\SysWOW64\tdc.ocx
2018-12-20 23:07 - 2018-12-14 01:20 - 000168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2018-12-20 23:07 - 2018-12-14 01:19 - 000279040 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2018-12-20 23:07 - 2018-12-14 01:19 - 000076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2018-12-20 23:07 - 2018-12-14 01:18 - 004494848 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2018-12-20 23:07 - 2018-12-14 01:18 - 000130048 _____ (Microsoft Corporation) C:\windows\SysWOW64\occache.dll
2018-12-20 23:07 - 2018-12-14 01:14 - 013681152 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2018-12-20 23:07 - 2018-12-14 01:13 - 000230400 _____ (Microsoft Corporation) C:\windows\SysWOW64\webcheck.dll
2018-12-20 23:07 - 2018-12-14 01:11 - 002059776 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2018-12-20 23:07 - 2018-12-14 01:11 - 000696320 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2018-12-20 23:07 - 2018-12-14 01:10 - 001155072 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2018-12-20 23:07 - 2018-12-14 00:58 - 004386816 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2018-12-20 23:07 - 2018-12-14 00:54 - 001330176 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2018-12-20 23:07 - 2018-12-14 00:52 - 000710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2018-12-11 14:16 - 2018-12-05 21:39 - 003227648 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2018-12-11 14:16 - 2018-11-28 17:02 - 014635520 _____ (Microsoft Corporation) C:\windows\system32\wmp.dll
2018-12-11 14:16 - 2018-11-28 17:02 - 012574720 _____ (Microsoft Corporation) C:\windows\system32\wmploc.DLL
2018-12-11 14:16 - 2018-11-28 17:02 - 000009728 _____ (Microsoft Corporation) C:\windows\system32\spwmp.dll
2018-12-11 14:16 - 2018-11-28 17:02 - 000005632 _____ (Microsoft Corporation) C:\windows\system32\msdxm.ocx
2018-12-11 14:16 - 2018-11-28 17:02 - 000005632 _____ (Microsoft Corporation) C:\windows\system32\dxmasf.dll
2018-12-11 14:16 - 2018-11-28 16:50 - 012574208 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmploc.DLL
2018-12-11 14:16 - 2018-11-28 16:50 - 011411968 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmp.dll
2018-12-11 14:16 - 2018-11-28 16:38 - 000008192 _____ (Microsoft Corporation) C:\windows\SysWOW64\spwmp.dll
2018-12-11 14:16 - 2018-11-28 16:38 - 000004608 _____ (Microsoft Corporation) C:\windows\SysWOW64\msdxm.ocx
2018-12-11 14:16 - 2018-11-28 16:38 - 000004608 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxmasf.dll
2018-12-11 14:16 - 2018-11-11 12:19 - 000631680 _____ (Microsoft Corporation) C:\windows\system32\winresume.efi
2018-12-11 14:16 - 2018-11-11 12:02 - 000262376 _____ (Microsoft Corporation) C:\windows\system32\hal.dll
2018-12-11 14:16 - 2018-11-11 12:01 - 005551848 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2018-12-11 14:16 - 2018-11-11 12:01 - 000708328 _____ (Microsoft Corporation) C:\windows\system32\winload.efi
2018-12-11 14:16 - 2018-11-11 12:01 - 000366824 _____ (Microsoft Corporation) C:\windows\system32\Drivers\msrpc.sys
2018-12-11 14:16 - 2018-11-11 12:01 - 000154856 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2018-12-11 14:16 - 2018-11-11 12:01 - 000095464 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2018-12-11 14:16 - 2018-11-11 12:00 - 001664360 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 001461760 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 001211904 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 001163264 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000731648 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000503808 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000419840 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000405504 _____ (Microsoft Corporation) C:\windows\system32\gdi32.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000361984 _____ (Microsoft Corporation) C:\windows\system32\wow64win.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000345600 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000316928 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000312320 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000215552 _____ (Microsoft Corporation) C:\windows\system32\winsrv.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000210432 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000190464 _____ (Microsoft Corporation) C:\windows\system32\rpchttp.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000135680 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000094208 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000063488 _____ (Microsoft Corporation) C:\windows\system32\setbcdlocale.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000050176 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000028672 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000016384 _____ (Microsoft Corporation) C:\windows\system32\ntvdm64.dll
2018-12-11 14:16 - 2018-11-11 11:58 - 000013312 _____ (Microsoft Corporation) C:\windows\system32\wow64cpu.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000880640 _____ (Microsoft Corporation) C:\windows\system32\advapi32.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000690688 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000463872 _____ (Microsoft Corporation) C:\windows\system32\certcli.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000123904 _____ (Microsoft Corporation) C:\windows\system32\bcrypt.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000059904 _____ (Microsoft Corporation) C:\windows\system32\appidapi.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000044032 _____ (Microsoft Corporation) C:\windows\system32\csrsrv.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000043520 _____ (Microsoft Corporation) C:\windows\system32\cryptbase.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000034816 _____ (Microsoft Corporation) C:\windows\system32\appidsvc.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000006656 _____ (Microsoft Corporation) C:\windows\system32\apisetschema.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000006144 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000005120 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:57 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:49 - 004054760 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
2018-12-11 14:16 - 2018-11-11 11:49 - 003960040 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
2018-12-11 14:16 - 2018-11-11 11:47 - 001314104 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
2018-12-11 14:16 - 2018-11-11 11:45 - 001114112 _____ (Microsoft Corporation) C:\windows\SysWOW64\kernel32.dll
2018-12-11 14:16 - 2018-11-11 11:45 - 000666112 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpcrt4.dll
2018-12-11 14:16 - 2018-11-11 11:45 - 000554496 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2018-12-11 14:16 - 2018-11-11 11:45 - 000313344 _____ (Microsoft Corporation) C:\windows\SysWOW64\gdi32.dll
2018-12-11 14:16 - 2018-11-11 11:45 - 000275968 _____ (Microsoft Corporation) C:\windows\SysWOW64\KernelBase.dll
2018-12-11 14:16 - 2018-11-11 11:45 - 000261120 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2018-12-11 14:16 - 2018-11-11 11:45 - 000254464 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2018-12-11 14:16 - 2018-11-11 11:45 - 000223232 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
2018-12-11 14:16 - 2018-11-11 11:45 - 000172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
2018-12-11 14:16 - 2018-11-11 11:45 - 000146432 _____ (Microsoft Corporation) C:\windows\SysWOW64\msaudite.dll
2018-12-11 14:16 - 2018-11-11 11:45 - 000141312 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpchttp.dll
2018-12-11 14:16 - 2018-11-11 11:45 - 000096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
2018-12-11 14:16 - 2018-11-11 11:45 - 000082944 _____ (Microsoft Corporation) C:\windows\SysWOW64\bcrypt.dll
2018-12-11 14:16 - 2018-11-11 11:45 - 000070144 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2018-12-11 14:16 - 2018-11-11 11:45 - 000060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\msobjs.dll
2018-12-11 14:16 - 2018-11-11 11:45 - 000043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\srclient.dll
2018-12-11 14:16 - 2018-11-11 11:45 - 000022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
2018-12-11 14:16 - 2018-11-11 11:45 - 000005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000690688 _____ (Microsoft Corporation) C:\windows\SysWOW64\adtschema.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000644096 _____ (Microsoft Corporation) C:\windows\SysWOW64\advapi32.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000342528 _____ (Microsoft Corporation) C:\windows\SysWOW64\certcli.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000050688 _____ (Microsoft Corporation) C:\windows\SysWOW64\appidapi.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\apisetschema.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000005120 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:44 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:25 - 000148480 _____ (Microsoft Corporation) C:\windows\system32\appidpolicyconverter.exe
2018-12-11 14:16 - 2018-11-11 11:25 - 000062464 _____ (Microsoft Corporation) C:\windows\system32\Drivers\appid.sys
2018-12-11 14:16 - 2018-11-11 11:25 - 000017920 _____ (Microsoft Corporation) C:\windows\system32\appidcertstorecheck.exe
2018-12-11 14:16 - 2018-11-11 11:24 - 000064000 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe
2018-12-11 14:16 - 2018-11-11 11:20 - 000338432 _____ (Microsoft Corporation) C:\windows\system32\conhost.exe
2018-12-11 14:16 - 2018-11-11 11:20 - 000129024 _____ (Microsoft Corporation) C:\windows\system32\Drivers\videoprt.sys
2018-12-11 14:16 - 2018-11-11 11:19 - 000296960 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe
2018-12-11 14:16 - 2018-11-11 11:19 - 000050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\auditpol.exe
2018-12-11 14:16 - 2018-11-11 11:16 - 000291328 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb10.sys
2018-12-11 14:16 - 2018-11-11 11:16 - 000160768 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb.sys
2018-12-11 14:16 - 2018-11-11 11:16 - 000129536 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb20.sys
2018-12-11 14:16 - 2018-11-11 11:15 - 000112640 _____ (Microsoft Corporation) C:\windows\system32\smss.exe
2018-12-11 14:16 - 2018-11-11 11:15 - 000064512 _____ (Microsoft Corporation) C:\windows\system32\Drivers\amdk8.sys
2018-12-11 14:16 - 2018-11-11 11:15 - 000062464 _____ (Microsoft Corporation) C:\windows\system32\Drivers\intelppm.sys
2018-12-11 14:16 - 2018-11-11 11:15 - 000060928 _____ (Microsoft Corporation) C:\windows\system32\Drivers\processr.sys
2018-12-11 14:16 - 2018-11-11 11:15 - 000060928 _____ (Microsoft Corporation) C:\windows\system32\Drivers\amdppm.sys
2018-12-11 14:16 - 2018-11-11 11:15 - 000030720 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2018-12-11 14:16 - 2018-11-11 11:15 - 000025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe
2018-12-11 14:16 - 2018-11-11 11:15 - 000014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll
2018-12-11 14:16 - 2018-11-11 11:15 - 000007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe
2018-12-11 14:16 - 2018-11-11 11:15 - 000002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe
2018-12-11 14:16 - 2018-11-11 11:14 - 000036352 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptbase.dll
2018-12-11 14:16 - 2018-11-11 11:13 - 000006144 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:13 - 000004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:13 - 000003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2018-12-11 14:16 - 2018-11-11 11:13 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2018-12-11 14:16 - 2018-11-08 11:58 - 002009600 _____ (Microsoft Corporation) C:\windows\system32\msxml6.dll
2018-12-11 14:16 - 2018-11-08 11:58 - 001889280 _____ (Microsoft Corporation) C:\windows\system32\msxml3.dll
2018-12-11 14:16 - 2018-11-08 11:58 - 000002048 _____ (Microsoft Corporation) C:\windows\system32\msxml6r.dll
2018-12-11 14:16 - 2018-11-08 11:58 - 000002048 _____ (Microsoft Corporation) C:\windows\system32\msxml3r.dll
2018-12-11 14:16 - 2018-11-08 11:43 - 001391104 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml6.dll
2018-12-11 14:16 - 2018-11-08 11:43 - 001241088 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3.dll
2018-12-11 14:16 - 2018-11-08 11:43 - 000002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml6r.dll
2018-12-11 14:16 - 2018-11-08 11:43 - 000002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3r.dll
2018-12-11 14:16 - 2018-11-05 23:36 - 000002048 _____ (Microsoft Corporation) C:\windows\system32\tzres.dll
2018-12-11 14:16 - 2018-11-05 23:20 - 000002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\tzres.dll
2018-12-11 14:16 - 2018-10-06 11:03 - 000383720 _____ (Adobe Systems Incorporated) C:\windows\system32\atmfd.dll
2018-12-11 14:16 - 2018-10-06 10:59 - 000151552 _____ (Microsoft Corporation) C:\windows\system32\t2embed.dll
2018-12-11 14:16 - 2018-10-06 10:59 - 000041472 _____ (Microsoft Corporation) C:\windows\system32\lpk.dll
2018-12-11 14:16 - 2018-10-06 10:58 - 000100864 _____ (Microsoft Corporation) C:\windows\system32\fontsub.dll
2018-12-11 14:16 - 2018-10-06 10:58 - 000046080 _____ (Adobe Systems) C:\windows\system32\atmlib.dll
2018-12-11 14:16 - 2018-10-06 10:58 - 000014336 _____ (Microsoft Corporation) C:\windows\system32\dciman32.dll
2018-12-11 14:16 - 2018-10-06 10:50 - 000309480 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\atmfd.dll
2018-12-11 14:16 - 2018-10-06 10:44 - 000111616 _____ (Microsoft Corporation) C:\windows\SysWOW64\t2embed.dll
2018-12-11 14:16 - 2018-10-06 10:44 - 000025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\lpk.dll
2018-12-11 14:16 - 2018-10-06 10:43 - 000071680 _____ (Microsoft Corporation) C:\windows\SysWOW64\fontsub.dll
2018-12-11 14:16 - 2018-10-06 10:43 - 000010240 _____ (Microsoft Corporation) C:\windows\SysWOW64\dciman32.dll
2018-12-11 14:16 - 2018-10-06 10:16 - 000034304 _____ (Adobe Systems) C:\windows\SysWOW64\atmlib.dll
2018-12-10 02:38 - 2018-12-10 02:38 - 000000000 ____D C:\Users\Barley\AppData\Local\mbam
2018-12-10 02:37 - 2018-12-10 02:37 - 000000000 ____D C:\Users\Barley\AppData\Local\mbamtray
2018-12-10 02:37 - 2018-12-10 02:37 - 000000000 ____D C:\Program Files\Malwarebytes
2018-12-06 20:38 - 2018-12-22 11:14 - 000002242 _____ C:\Users\Barley\Desktop\Chris - Chrome.lnk
2018-12-01 08:58 - 2018-12-01 08:58 - 000110968 _____ (Oracle Corporation) C:\windows\system32\WindowsAccessBridge-64.dll
2018-12-01 08:58 - 2018-12-01 08:58 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2018-12-01 08:57 - 2018-12-01 08:57 - 000000000 ____D C:\Program Files\Java
2018-12-01 08:56 - 2018-12-01 08:57 - 074618232 _____ (Oracle Corporation) C:\Users\Barley\Downloads\jre-8u191-windows-x64.exe
2018-12-01 08:52 - 2018-12-01 08:52 - 000000954 _____ C:\Users\Barley\Downloads\Coupon_Package_CommonKindness (5).jnlp
2018-11-30 10:40 - 2018-11-30 10:41 - 002204152 _____ (Valassis) C:\Users\Barley\Downloads\P@H_prod308-piPSZUcb.exe
2018-11-25 12:07 - 2018-11-25 12:07 - 000000000 ____D C:\Users\Barley\AppData\Local\Nuance
2018-11-25 12:07 - 2018-11-25 12:07 - 000000000 ____D C:\Users\Barley\AppData\Local\Brother
2018-11-25 12:07 - 2018-11-25 12:07 - 000000000 ____D C:\ProgramData\Nuance
2018-11-25 11:02 - 2018-11-25 11:02 - 006796563 _____ C:\Users\Barley\Downloads\HUSB_CampFlyer_2019_v4_FINAL.pdf
2018-11-24 13:40 - 2018-11-24 13:40 - 004110943 _____ C:\Users\Barley\Downloads\all-11750417.zip
2018-11-24 13:40 - 2018-11-24 13:40 - 001219747 _____ C:\Users\Barley\Downloads\histograms.pdf
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-12-24 15:17 - 2012-10-07 17:22 - 000003934 _____ C:\windows\System32\Tasks\User_Feed_Synchronization-{DDA5C770-AE6C-4A93-AC90-AB64C59BEC72}
2018-12-24 15:14 - 2012-10-02 13:47 - 000000000 ____D C:\ProgramData\PDFC
2018-12-24 15:13 - 2009-07-14 00:08 - 000000006 ____H C:\windows\Tasks\SA.DAT
2018-12-24 15:12 - 2009-07-13 23:45 - 000024608 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-12-24 15:12 - 2009-07-13 23:45 - 000024608 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-12-24 12:16 - 2012-10-02 13:36 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
2018-12-24 12:15 - 2012-10-02 13:36 - 000000000 ____D C:\Program Files (x86)\Hp
2018-12-24 12:10 - 2009-07-14 00:13 - 000782470 _____ C:\windows\system32\PerfStringBackup.INI
2018-12-24 12:10 - 2009-07-13 22:20 - 000000000 ____D C:\windows\inf
2018-12-24 00:16 - 2016-01-01 11:32 - 000000000 ____D C:\Users\Barley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
2018-12-23 11:43 - 2013-11-17 01:01 - 000000000 ____D C:\ProgramData\Malwarebytes
2018-12-23 04:46 - 2018-05-18 09:05 - 000217088 ___SH C:\Users\Barley\Desktop\Thumbs.db
2018-12-23 04:45 - 2009-07-13 23:45 - 000332232 _____ C:\windows\system32\FNTCACHE.DAT
2018-12-23 01:06 - 2012-10-07 17:25 - 000083472 _____ C:\Users\Barley\AppData\Local\GDIPFONTCACHEV1.DAT
2018-12-23 00:56 - 2014-06-26 21:30 - 000000000 ____D C:\windows\Minidump
2018-12-23 00:56 - 2012-11-11 21:07 - 000000000 ____D C:\Users\Barley\AppData\Local\CrashDumps
2018-12-23 00:00 - 2009-07-14 00:08 - 000032586 _____ C:\windows\Tasks\SCHEDLGU.TXT
2018-12-22 23:53 - 2016-08-27 09:19 - 000000000 ____D C:\Users\Barley\Downloads\Comets 2016_files
2018-12-22 15:16 - 2012-10-07 17:17 - 000000000 ____D C:\Users\Barley
2018-12-22 15:13 - 2017-03-23 06:44 - 000482304 ___SH C:\Users\Barley\Downloads\Thumbs.db
2018-12-22 14:46 - 2009-07-13 22:20 - 000000000 ____D C:\windows\rescache
2018-12-22 12:48 - 2015-12-25 14:06 - 000001596 _____ C:\Users\Barley\Desktop\DCS-5020L(26467279).lnk
2018-12-22 12:48 - 2014-03-02 13:24 - 000000000 ____D C:\Users\Barley\Downloads\FRST-OlderVersion
2018-12-22 11:35 - 2013-02-03 16:45 - 000000000 ____D C:\Users\Barley\AppData\Roaming\Yahoo!
2018-12-22 11:35 - 2013-02-03 16:45 - 000000000 ____D C:\Program Files (x86)\Yahoo!
2018-12-22 11:15 - 2014-03-16 15:16 - 000000000 ____D C:\Users\Barley\AppData\LocalLow\Temp
2018-12-22 11:14 - 2013-11-23 01:51 - 000002748 _____ C:\Users\Barley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ie11 RWW (Remote Web Workplace) Connect to Computer - Spiceworks.lnk
2018-12-22 11:14 - 2013-11-23 01:51 - 000002718 _____ C:\Users\Barley\Desktop\ie11 RWW (Remote Web Workplace) Connect to Computer - Spiceworks.lnk
2018-12-22 11:14 - 2012-10-07 17:28 - 000002242 _____ C:\Users\Barley\Desktop\Erica - Chrome.lnk
2018-12-22 10:51 - 2017-11-20 21:50 - 000003192 _____ C:\windows\System32\Tasks\HPCeeScheduleForBarley
2018-12-22 10:51 - 2017-11-20 21:50 - 000000336 _____ C:\windows\Tasks\HPCeeScheduleForBarley.job
2018-12-21 16:11 - 2017-04-05 11:22 - 000000000 ___RD C:\Users\Barley\Dropbox
2018-12-21 16:10 - 2012-10-07 17:37 - 014843556 ____H C:\Users\Barley\AppData\Local\IconCache.db.backup
2018-12-21 00:18 - 2016-12-25 11:57 - 000008051 _____ C:\windows\BRRBCOM.INI
2018-12-19 21:15 - 2018-03-14 23:51 - 000000000 _____ C:\windows\SysWOW64\last.dump
2018-12-18 21:09 - 2012-10-07 17:26 - 000003332 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2018-12-18 21:09 - 2012-10-07 17:25 - 000003204 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
2018-12-18 20:59 - 2013-12-25 10:30 - 000003508 _____ C:\windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-632860548-1775735820-415820443-1000UA
2018-12-18 20:59 - 2013-12-25 10:30 - 000003236 _____ C:\windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-632860548-1775735820-415820443-1000Core
2018-12-16 10:49 - 2018-11-13 09:30 - 000003236 _____ C:\windows\System32\Tasks\Norton WSC Integration
2018-12-16 10:49 - 2018-09-13 20:51 - 000000000 ____D C:\windows\System32\Tasks\AVAST Software
2018-12-16 10:49 - 2018-03-13 16:07 - 000004466 _____ C:\windows\System32\Tasks\Adobe Flash Player NPAPI Notifier
2018-12-16 10:49 - 2018-01-09 01:01 - 000003916 _____ C:\windows\System32\Tasks\Antivirus Emergency Update
2018-12-16 10:49 - 2017-08-31 23:12 - 000004478 _____ C:\windows\System32\Tasks\Adobe Flash Player PPAPI Notifier
2018-12-16 10:49 - 2017-04-15 06:34 - 000003118 _____ C:\windows\System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe
2018-12-16 10:49 - 2017-04-15 06:34 - 000003092 _____ C:\windows\System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe
2018-12-16 10:49 - 2017-04-15 06:34 - 000003090 _____ C:\windows\System32\Tasks\Microsoft_Hardware_Launch_itype_exe
2018-12-16 10:49 - 2017-04-15 06:34 - 000003062 _____ C:\windows\System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe
2018-12-16 10:49 - 2017-04-15 06:34 - 000003060 _____ C:\windows\System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe
2018-12-16 10:49 - 2015-04-23 23:38 - 000004476 _____ C:\windows\System32\Tasks\Adobe Acrobat Update Task
2018-12-16 10:49 - 2015-02-03 21:08 - 000003164 _____ C:\windows\System32\Tasks\{D95529CE-E95E-447C-8D8C-4C1A622E5294}
2018-12-16 10:49 - 2012-10-02 13:44 - 000004312 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater
2018-12-12 14:10 - 2012-10-07 17:28 - 000002226 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-12-12 07:56 - 2015-04-23 23:38 - 000002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2018-12-12 01:28 - 2011-02-11 12:15 - 000774592 _____ C:\windows\SysWOW64\PerfStringBackup.INI
2018-12-12 01:27 - 2014-09-06 18:49 - 000000000 ____D C:\windows\system32\MRT
2018-12-12 01:23 - 2014-09-06 18:49 - 137260640 ____C (Microsoft Corporation) C:\windows\system32\MRT.exe
2018-12-10 02:37 - 2014-09-06 19:22 - 000000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2018-12-06 00:07 - 2012-10-02 13:44 - 000842240 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2018-12-06 00:07 - 2012-10-02 13:44 - 000175104 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2018-12-06 00:07 - 2012-10-02 13:44 - 000000000 ____D C:\windows\SysWOW64\Macromed
2018-12-06 00:07 - 2012-10-02 13:44 - 000000000 ____D C:\windows\system32\Macromed
2018-11-30 10:41 - 2015-04-21 08:51 - 000000000 ____D C:\Program Files (x86)\Valassis
==================== Files in the root of some directories =======
2014-09-06 20:02 - 2014-09-06 20:02 - 000000055 _____ () C:\Users\Barley\AppData\Roaming\mbam.context.scan
2013-08-09 23:33 - 2013-08-09 23:34 - 000595302 _____ () C:\Users\Barley\AppData\Roaming\Scorch_Install.log
2012-10-08 14:16 - 2015-09-09 18:32 - 000011264 _____ () C:\Users\Barley\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\windows\system32\winlogon.exe => File is digitally signed
C:\windows\system32\wininit.exe => File is digitally signed
C:\windows\SysWOW64\wininit.exe => File is digitally signed
C:\windows\explorer.exe => File is digitally signed
C:\windows\SysWOW64\explorer.exe => File is digitally signed
C:\windows\system32\svchost.exe => File is digitally signed
C:\windows\SysWOW64\svchost.exe => File is digitally signed
C:\windows\system32\services.exe => File is digitally signed
C:\windows\system32\User32.dll => File is digitally signed
C:\windows\SysWOW64\User32.dll => File is digitally signed
C:\windows\system32\userinit.exe => File is digitally signed
C:\windows\SysWOW64\userinit.exe => File is digitally signed
C:\windows\system32\rpcss.dll => File is digitally signed
C:\windows\system32\dnsapi.dll => File is digitally signed
C:\windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2018-12-24 02:43
==================== End of FRST.txt ============================
Addition.txt
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 24.12.2018
Ran by [removed] (24-12-2018 15:21:08)
Running from C:\Users\[removed]\Desktop
Windows 7 Home Premium Service Pack 1 (X64) (2012-10-07 22:17:47)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-632860548-1775735820-415820443-500 - Administrator - Disabled)
Barley (S-1-5-21-632860548-1775735820-415820443-1000 - Administrator - Enabled) => C:\Users\Barley
Guest (S-1-5-21-632860548-1775735820-415820443-501 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: AVG Antivirus (Enabled - Up to date) {4FC75CA5-1654-5411-7CFB-1893D506BCF4}
AV: Norton Internet Security (Disabled - Out of date) {E3FDBD9F-8140-1400-F32B-8B58923F7C4D}
AS: Norton Internet Security (Disabled - Out of date) {589C5C7B-A77A-1B8E-C99B-B02AE9B836F0}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG Antivirus (Enabled - Up to date) {F4A6BD41-306E-5B9F-464B-23E1AE81F649}
FW: Norton Internet Security (Disabled) {DBC63CBA-CB2F-1558-D874-226D6CEC3B36}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
4 Elements II (HKLM-x32\…\WTA-b59b7394-ad89-4e36-9b0e-246773f6f556) (Version: 2.2.0.98 - WildTangent) Hidden
64 Bit HP CIO Components Installer (HKLM\…\{55D55008-E5F6-47D6-B16F-B2A40D4D145F}) (Version: 6.2.1 - Hewlett-Packard) Hidden
Able RAWer 1.10.3.20 (HKLM-x32\…\Able RAWer_is1) (Version: 1.10.3.20 - GraphicRegion.com)
Adobe Acrobat Reader DC (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 19.010.20064 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 18.0.0.180 - Adobe Systems Incorporated)
Adobe Flash Player 32 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 32.0.0.101 - Adobe Systems Incorporated)
Adobe Flash Player 32 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 32.0.0.101 - Adobe Systems Incorporated)
Adobe Flash Player 32 PPAPI (HKLM-x32\…\Adobe Flash Player PPAPI) (Version: 32.0.0.101 - Adobe Systems Incorporated)
AIO_CDA_ProductContext (HKLM-x32\…\{2A7EF808-14F3-4E93-BE3A-1675EE5332A4}) (Version: 130.0.365.000 - Hewlett-Packard) Hidden
AIO_CDA_Software (HKLM-x32\…\{A7AEE29F-839E-46B5-B347-6D430618129F}) (Version: 130.0.365.000 - Hewlett-Packard) Hidden
AIO_Scan (HKLM-x32\…\{D86B0E2E-DF9A-441C-AF77-8D1A0FF00FA6}) (Version: 130.0.365.000 - Hewlett-Packard) Hidden
Apple Application Support (32-bit) (HKLM-x32\…\{F2871C89-C8A5-42EE-8D45-0F02506385A6}) (Version: 5.1 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\…\{9BC93467-75D1-4AA4-BD58-D9C51D88DFAB}) (Version: 5.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{55BB2110-FB43-49B3-93F4-945A0CFB0A6C}) (Version: 10.0.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.)
AVG AntiVirus FREE (HKLM-x32\…\AVG Antivirus) (Version: 18.8.3071 - AVG Technologies)
Bejeweled 3 (HKLM-x32\…\WTA-ac717e9e-48e0-49d5-b5a2-824923e38ed4) (Version: 2.2.0.98 - WildTangent) Hidden
Blackhawk Striker 2 (HKLM-x32\…\WTA-73c3dc74-4cd1-419d-b230-d78796a73007) (Version: 2.2.0.95 - WildTangent) Hidden
Blio (HKLM-x32\…\{FCD6D60F-AF2B-49E3-ABC4-A4C96B56225D}) (Version: 3.0.9482 - K-NFB Reading Technology, Inc.)
Bonjour (HKLM\…\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
BrLauncher (HKLM-x32\…\{C661197A-6B93-4E37-9E3F-2A1DFCD64234}) (Version: 1.1.15.0 - Brother Industries Ltd.) Hidden
BrLogRx (HKLM-x32\…\{B556F816-FF4D-4BB6-9339-ED28639E2EF3}) (Version: 1.0.2.1 - Brother Industries Ltd.) Hidden
Brother PCFax Driver (HKLM-x32\…\{56BA05BD-7A67-4EF8-85A7-8C6528AEE2AC}) (Version: 1.4.0.0 - Brother Industries Ltd.) Hidden
Brother Printer Driver (HKLM-x32\…\{4A30C4EE-52AC-4A6B-A898-D484E9FAED63}) (Version: 1.5.0.0 - Brother Industries Ltd.) Hidden
Brother Scanner Driver (HKLM-x32\…\{B843B8F3-1815-4335-99F2-039AE06CAD86}) (Version: 1.0.15.10 - Brother Industries Ltd.) Hidden
BrotherHelpInstaller (HKLM-x32\…\{4E461C2A-EC1C-46D1-AF5B-7FEFD0054AF8}) (Version: 1.0.0.0 - Brother) Hidden
BrSupportTools (HKLM-x32\…\{F8F9EB58-33BA-4FF8-80E7-66D87D2E0C3C}) (Version: 1.0.9.0 - Brother Industries Ltd.) Hidden
Bubble Wrap (HKLM-x32\…\{5BFFDDEB-AFD7-499F-BB13-7A6EAD927CDA}_is1) (Version: 1.0.0.0 - XM Asia Pacific Pte Ltd)
BufferChm (HKLM-x32\…\{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}) (Version: 130.0.331.000 - Hewlett-Packard) Hidden
C6100 (HKLM-x32\…\{0DEF8C02-2EAB-4BFE-A7E0-7990665DF1A9}) (Version: 130.0.365.000 - Hewlett-Packard) Hidden
c6100_Help (HKLM-x32\…\{4BD5B5D2-406D-4bc5-BB10-2F0D1D367C95}) (Version: 82.0.256.000 - Hewlett-Packard) Hidden
Catalina Savings Printer (HKLM-x32\…\{4956ACE3-F537-4418-BB45-FD52395275A7}) (Version: 1.0.0 - Catalina Marketing Corp) <==== ATTENTION
CCleaner (HKLM\…\CCleaner) (Version: 5.51 - Piriform)
ChromecastApp (HKU\S-1-5-21-632860548-1775735820-415820443-1000\…\{079ede36-133d-44b0-8053-c7c1fa8d2e0d}_is1) (Version: 1.5.1693.0 - Google Inc.)
Chuzzle Deluxe (HKLM-x32\…\WTA-350df33b-9fdb-4c58-80af-3f5a302269c2) (Version: 2.2.0.95 - WildTangent) Hidden
Cisco WebEx Meetings (HKU\S-1-5-21-632860548-1775735820-415820443-1000\…\ActiveTouchMeetingClient) (Version: - Cisco WebEx LLC)
ControlCenter4 (HKLM-x32\…\{C5744F42-FDC4-4CC2-B4A8-47C9AA9553B4}) (Version: 4.2.435.1 - Brother Insutries Ltd.) Hidden
ControlCenter4 CSDK (HKLM-x32\…\{1BAE50D4-5F2A-4E34-BD81-B4555109F7C2}) (Version: 4.2.3.1 - Brother Insutries Ltd.) Hidden
Cradle of Rome 2 (HKLM-x32\…\WTA-1c1f6121-da0f-4e8c-9c68-5081de00e04b) (Version: 2.2.0.98 - WildTangent) Hidden
D3DX10 (HKLM-x32\…\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden
DeviceDetect (HKLM-x32\…\{CEF07BDC-47F1-4477-8F3C-0E7132AF88C5}) (Version: 1.0.4.5 - Brother Industries Ltd.) Hidden
Dietz & Watson 2015 (HKLM-x32\…\{CD6EEFE2-17F9-AC22-9223-48776E476221}) (Version: 2.5 - Koupon Media) Hidden
Dietz & Watson 2015 (HKLM-x32\…\com.kouponmedia.dietzandwatson2015) (Version: 2.5 - Koupon Media)
DirectX for Managed Code Update (Summer 2004) (HKLM-x32\…\{E9E34215-82EF-4909-BE2F-F581F0DC9062}) (Version: 9.02.2904 - Microsoft) Hidden
DocProc (HKLM-x32\…\{9B362566-EC1B-4700-BB9C-EC661BDE2175}) (Version: 13.0.0.0 - Hewlett-Packard) Hidden
Dora's World Adventure (HKLM-x32\…\WTA-220769bc-a6cc-4095-8049-d7448f650a3e) (Version: 2.2.0.95 - WildTangent) Hidden
Dragon NaturallySpeaking 7.0 (HKLM-x32\…\{6675E71B-9843-4971-BC15-18AB52801134}) (Version: 7.00.200.409 - ScanSoft)
Elevated Installer (HKLM-x32\…\{352B1136-BF8D-4F5A-924B-43B26D05B3B5}) (Version: 2.3.17.0 - Garmin Ltd or its subsidiaries) Hidden
Escape the Emerald Star (HKLM-x32\…\WTA-424f1b8b-d37a-42ea-b226-3030d1996772) (Version: 2.2.0.98 - WildTangent) Hidden
Exact Audio Copy 1.2 (HKLM-x32\…\Exact Audio Copy) (Version: 1.2 - Andre Wiethoff)
Facebook (HKLM-x32\…\{8AE50893-3A87-4439-9A57-942ED43F7189}) (Version: 1.1.0004 - Hewlett-Packard)
Farm Frenzy (HKLM-x32\…\WTA-c81077f9-55f3-4d11-b4fe-585ad41d8209) (Version: 2.2.0.98 - WildTangent) Hidden
Farmscapes (HKLM-x32\…\WTA-ba2cfe9d-b15a-44af-87b3-25c19f580002) (Version: 2.2.0.97 - WildTangent) Hidden
FATE (HKLM-x32\…\WTA-0e36d320-14f2-4de0-88cd-beb4083d639d) (Version: 2.2.0.97 - WildTangent) Hidden
Final Drive Fury (HKLM-x32\…\WTA-844866d1-e9d3-40b2-a85e-666243def709) (Version: 2.2.0.95 - WildTangent) Hidden
Free YouTube To MP3 Converter (HKLM-x32\…\Free YouTube To MP3 Converter_is1) (Version: 4.1.33.119 - Digital Wave Ltd)
Garmin Express (HKLM-x32\…\{874B12CE-2C6A-4E12-AEB5-4D35CCA5270B}) (Version: 2.3.17.0 - Garmin Ltd or its subsidiaries) Hidden
Garmin Express (HKLM-x32\…\{d6f59919-3fd4-48c5-8404-def6f92d8422}) (Version: 2.3.17.0 - Garmin Ltd or its subsidiaries)
Garmin Express Tray (HKLM-x32\…\{BE770575-1FB0-47EB-A2EE-52107A023F12}) (Version: 2.3.17.0 - Garmin Ltd or its subsidiaries) Hidden
Golden Trails 2: The Lost Legacy Collector's Edition (HKLM-x32\…\WTA-a751c50d-1758-4426-8ac0-a7be901bb1c2) (Version: 2.2.0.98 - WildTangent) Hidden
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 71.0.3578.98 - Google Inc.)
Google Update Helper (HKLM-x32\…\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.23 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\…\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden
GPBaseService2 (HKLM-x32\…\{63FF21C9-A810-464F-B60A-3111747B1A6D}) (Version: 130.0.371.000 - Hewlett-Packard) Hidden
Hewlett-Packard ACLM.NET v1.2.2.3 (HKLM-x32\…\{6F340107-F9AA-47C6-B54C-C3A19F11553F}) (Version: 1.00.0000 - Hewlett-Packard Company) Hidden
HowToGuide (HKLM-x32\…\{36580EEB-4EDF-4880-BBD4-097E2C645ECD}) (Version: 1.0.1.0 - Brother Industries Ltd.) Hidden
Hoyle Card Games (HKLM-x32\…\WTA-818c6384-6cd9-4f15-8a4f-14a502345e34) (Version: 2.2.0.95 - WildTangent) Hidden
HP Application Assistant (HKLM\…\{0CE7EBAF-157D-4111-9146-057CB2A4023E}) (Version: 1.1.466.3970 - Hewlett-Packard)
HP Calendar (HKLM-x32\…\{2B38E0FA-D8A5-4EBF-A018-E3C1C8E7A2E2}) (Version: 5.1.4245.23508 - Hewlett-Packard)
HP Clock (HKLM-x32\…\{750E9D0F-B188-4A7E-ADD2-84B7ED7D32F6}) (Version: 5.1.4281.27332 - Hewlett-Packard)
HP Customer Participation Program 13.0 (HKLM\…\HPExtendedCapabilities) (Version: 13.0 - HP)
HP Easy Print (HKLM-x32\…\{37C4570C-2F39-4756-AF26-A204CEF202D6}) (Version: 1.00.0000 - HP)
HP Games (HKLM-x32\…\WildTangent hp Master Uninstall) (Version: 1.0.2.5 - WildTangent)
HP LinkUp (HKLM-x32\…\{7E750542-55BC-4300-8B7B-AC2A762FB435}) (Version: 2.01.029 - Hewlett-Packard)
HP Magic Canvas (HKLM-x32\…\{DDFDC9D6-4220-41F8-BF9A-8E7512C4EF52}) (Version: 5.1.15.0 - Hewlett-Packard)
HP Magic Canvas Tutorials (HKLM-x32\…\{858FCB65-7C6D-4BA4-AD80-A3CB3744CE09}_is1) (Version: 6.0.0.0 - Hewlett-Packard)
HP Notes (HKLM-x32\…\{86BAB08A-5E66-4C53-82E3-C1E91673C7CA}) (Version: 5.1.4274.30382 - Hewlett-Packard)
HP Odometer (HKLM-x32\…\{B8AC1A89-FFD1-4F97-8051-E505A160F562}) (Version: 2.10.0000 - Hewlett-Packard)
HP Photosmart All-In-One Driver Software 13.0 Rel. A (HKLM\…\{17016DA1-F040-4032-BD36-34DD317BC9D5}) (Version: 13.0 - HP)
HP RSS (HKLM-x32\…\{452479C5-0118-48E9-AA69-0A7339F95FC8}) (Version: 5.1.4289.23799 - Hewlett-Packard)
HP Setup (HKLM-x32\…\{438363A8-F486-4C37-834C-4955773CB3D3}) (Version: 9.1.15430.4033 - Hewlett-Packard Company)
HP Smart Web Printing 4.51 (HKLM\…\HP Smart Web Printing) (Version: 4.51 - HP)
HP Solution Center 13.0 (HKLM\…\HP Solution Center & Imaging Support Tools) (Version: 13.0 - HP)
HP Support Assistant (HKLM-x32\…\{61EB474B-67A6-47F4-B1B7-386851BAB3D0}) (Version: 8.7.50.3 - Hewlett-Packard Company)
HP Support Information (HKLM-x32\…\{B2B7B1C8-7C8B-476C-BE2C-049731C55992}) (Version: 11.00.0001 - Hewlett-Packard)
HP Support Solutions Framework (HKLM-x32\…\{F6A11738-3EE4-4573-AEA5-6CD5D491C167}) (Version: 12.10.49.21 - Hewlett-Packard Company)
HP Touchpoint Analytics Client (HKLM\…\{E5FB98E0-0784-44F0-8CEC-95CD4690C43F}) (Version: 4.0.2.1439 - HP Inc.)
HP TouchSmart Background - Beats (HKLM-x32\…\{6A6F8D36-04BA-41E9-9004-1789BD545874}) (Version: 1.0.1.0 - Hewlett-Packard)
HP TouchSmart RecipeBox (HKLM-x32\…\{20714B53-FC73-4F9C-9687-49EB237D6FD7}) (Version: 3.0.3830.27730 - Hewlett-Packard)
HP Update (HKLM-x32\…\{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}) (Version: 5.003.001.001 - Hewlett-Packard)
HP Weather (HKLM-x32\…\{776CC95E-8160-401B-AC79-164822AA8306}) (Version: 5.1.4245.22595 - Hewlett-Packard)
HPPhotoGadget (HKLM-x32\…\{CAE4213F-F797-439D-BD9E-79B71D115BE3}) (Version: 130.0.282.000 - Hewlett-Packard) Hidden
HPProductAssistant (HKLM-x32\…\{C43326F5-F135-4551-8270-7F7ABA0462E1}) (Version: 130.0.371.000 - Hewlett-Packard) Hidden
iCloud (HKLM\…\{309768A4-A2BB-4930-A5A2-8169678C9B4C}) (Version: 4.0.6.28 - Apple Inc.)
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.0.0.1351 - Intel Corporation)
Intel(R) OpenCL CPU Runtime (HKLM-x32\…\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2696 - Intel Corporation)
iTunes (HKLM\…\{554C62C7-E6BB-40F1-892B-F0AE02D3C135}) (Version: 12.5.3.17 - Apple Inc.)
Java 8 Update 191 (64-bit) (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F64180191F0}) (Version: 8.0.1910.12 - Oracle Corporation)
Jewel Match 3 (HKLM-x32\…\WTA-4660ad21-bbd2-4056-9274-17cdbb6e8a8c) (Version: 2.2.0.98 - WildTangent) Hidden
Jewel Quest Mysteries: The Seventh Gate Collector's Edition (HKLM-x32\…\WTA-6bd8460b-7dda-4a26-9e12-707c452d9b21) (Version: 2.2.0.98 - WildTangent) Hidden
John Deere Drive Green (HKLM-x32\…\WTA-5333fae1-48ca-41d7-8382-7c65262bc50c) (Version: 2.2.0.95 - WildTangent) Hidden
Junk Mail filter update (HKLM-x32\…\{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}) (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
LabelPrint (HKLM-x32\…\{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.4507 - CyberLink Corp.) Hidden
LabelPrint (HKLM-x32\…\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.4507 - CyberLink Corp.)
Luxor HD (HKLM-x32\…\WTA-7d011431-914e-437f-b7a1-ef23ab9154a0) (Version: 2.2.0.98 - WildTangent) Hidden
Mah Jong Medley (HKLM-x32\…\WTA-0fd9482b-7878-4605-8c28-19efd6521c0a) (Version: 2.2.0.95 - WildTangent) Hidden
Malwarebytes version 3.6.1.2711 (HKLM\…\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.6.1.2711 - Malwarebytes)
MarketResearch (HKLM-x32\…\{175F0111-2968-4935-8F70-33108C6A4DE3}) (Version: 130.0.374.000 - Hewlett-Packard) Hidden
Mesh Runtime (HKLM-x32\…\{8C6D6116-B724-4810-8F2D-D047E6B7D68E}) (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Metric Converter (HKLM-x32\…\{D0661463-50F7-4A1E-83CB-37CC590589AE}_is1) (Version: 1.0.0.0 - XM Asia Pacific Pte Ltd)
Microsoft .NET Framework 4.7.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.03062 - Microsoft Corporation)
Microsoft LifeCam (HKLM\…\{5CE7E3F5-9803-4F32-AA89-2D8848A80109}) (Version: 3.60.253.0 - Microsoft Corporation)
Microsoft Mathematics (HKLM-x32\…\{4D090F70-6F08-4B60-9357-A1DFD4458F09}) (Version: 4.0 - Microsoft Corporation)
Microsoft Mouse and Keyboard Center (HKLM\…\Microsoft Mouse and Keyboard Center) (Version: 2.3.188.0 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\…\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
Microsoft Office 2010 (HKLM-x32\…\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM-x32\…\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Home and Student 2007 (HKLM-x32\…\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Zoo Tycoon (HKLM-x32\…\Zoo Tycoon 1.0) (Version: - )
Mortimer Beckett and the Crimson Thief Premium Edition (HKLM-x32\…\WTA-7fc1033b-c678-45d5-a485-905aaf4a04e4) (Version: 2.2.0.98 - WildTangent) Hidden
Mozilla Firefox 26.0 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 26.0 (x86 en-US)) (Version: 26.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 26.0 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
My Farm Life 2 (HKLM-x32\…\WTA-3daa2b41-1b22-4cc2-838a-7a7c844442d1) (Version: 2.2.0.98 - WildTangent) Hidden
Network64 (HKLM\…\{05EFBF37-0E52-4579-875C-7EEF0DFB4FCB}) (Version: 130.0.572.000 - Hewlett-Packard) Hidden
NetworkRepairTool (HKLM-x32\…\{4694AD3E-D4A2-4D98-9848-662A0475E872}) (Version: 1.2.11.0 - Brother Insutries Ltd.) Hidden
Norton Internet Security (HKLM-x32\…\NGC) (Version: 22.16.2.22 - Symantec Corporation)
Norton Online Backup (HKLM-x32\…\{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}) (Version: 2.1.17869 - Symantec Corporation)
OCR Software by I.R.I.S. 13.0 (HKLM\…\HPOCR) (Version: 13.0 - HP)
opensource (HKLM-x32\…\{3677D4D8-E5E0-49FC-B86E-06541CF00BBE}) (Version: 1.0.14960.3876 - Your Company Name) Hidden
P@H-Protocol (HKLM-x32\…\{14F936AB-5D31-410E-A4E2-70AE504712F2}) (Version: 3.0.8.6 - Valassis)
P@H-Protocol (HKLM-x32\…\{4CFAC858-CB6F-4F5B-9BD9-4DAE8747F0E3}) (Version: 3.0.8.11 - Valassis)
P@H-Protocol (HKLM-x32\…\{A2CB3AFC-E449-408A-BF4F-FE64EB1899D8}) (Version: 3.0.8.7 - Valassis)
PC-FAXReceive (HKLM-x32\…\{DD40894F-7575-4905-90AB-695FD827E358}) (Version: 1.4.24.0 - Brother Insutries Ltd.) Hidden
PCFaxTx (HKLM-x32\…\{63530B2D-3A34-4D79-A52D-F3EB5D99A7C1}) (Version: 1.1.1.1 - Brother Industries Ltd.) Hidden
PDF Complete Corporate Edition (HKLM-x32\…\PDF Complete) (Version: 4.2.33 - PDF Complete, Inc)
Penguins! (HKLM-x32\…\WTA-c6d3fe1b-0537-4004-87f7-b2843d0833ac) (Version: 2.2.0.98 - WildTangent) Hidden
Plants vs. Zombies - Game of the Year (HKLM-x32\…\WTA-c43bee99-1714-4c3c-82e7-267367a21983) (Version: 2.2.0.98 - WildTangent) Hidden
PlayReady PC Runtime amd64 (HKLM\…\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation)
PlayReady PC Runtime x86 (HKLM-x32\…\{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}) (Version: 1.3.0 - Microsoft Corporation)
Poker Superstars III (HKLM-x32\…\WTA-ceced49d-d9ad-49da-ac4a-adcacf6cd937) (Version: 2.2.0.95 - WildTangent) Hidden
Polar Bowler (HKLM-x32\…\WTA-ad6b48d4-4aa6-49b1-b668-6005090a3c83) (Version: 2.2.0.97 - WildTangent) Hidden
Polar Golfer (HKLM-x32\…\WTA-417cc89d-18f1-44b3-90c8-0f4968fb00c2) (Version: 2.2.0.98 - WildTangent) Hidden
Power2Go (HKLM-x32\…\{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.6207 - CyberLink Corp.) Hidden
Power2Go (HKLM-x32\…\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.6207 - CyberLink Corp.)
PowerISO (HKLM-x32\…\PowerISO) (Version: 5.4 - Power Software Ltd)
Print@Home (HKLM-x32\…\{123D4082-3194-4191-9139-067E9157C2B2}) (Version: 2.0.0 - Valassis Interactive Inc.)
Ralink 802.11n Wireless LAN Card (HKLM-x32\…\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}) (Version: 3.2.12.0 - Ralink)
Recovery Manager (HKLM-x32\…\{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}) (Version: 5.5.0.5119 - CyberLink Corp.) Hidden
Remote Graphics Receiver (HKLM-x32\…\{16FC3056-90C0-4757-8A68-64D8DA846ADA}) (Version: 5.4.5 - Hewlett-Packard)
RemoteSetup (HKLM-x32\…\{B6CE4633-EA3F-4856-9BCC-9B8702E076FE}) (Version: 3.8.0.2 - Brother Industries Ltd.) Hidden
RimhillEx 1.08 (HKU\S-1-5-21-632860548-1775735820-415820443-1000\…\RimhillEx_is1) (Version: - the sz development)
RMNEveryday Coupon Printer (HKLM-x32\…\{08586830-7F6E-41F5-9A1C-51F7D2873631}) (Version: 3.1.0.0 - Valassis)
Roads of Rome 3 (HKLM-x32\…\WTA-0939384a-c84d-4e93-be59-7ae8b6d3e2dc) (Version: 2.2.0.98 - WildTangent) Hidden
RogueKiller version 13.0.17.0 (HKLM\…\8B3D7924-ED89-486B-8322-E8594065D5CB_is1) (Version: 13.0.17.0 - Adlice Software)
Scan (HKLM-x32\…\{0F367CA3-3B2F-43F9-A44A-25A8EE69E45D}) (Version: 13.0.0.0 - Hewlett-Packard) Hidden
ScannerUtilityInstaller (HKLM-x32\…\{5B645FE2-19E9-4B15-B5B2-3D8766F6FA27}) (Version: 1.0.0.0 - Brother) Hidden
Secunia PSI (3.0.0.9016) (HKLM-x32\…\Secunia PSI) (Version: 3.0.0.9016 - Secunia)
Sibelius Scorch (Firefox, Opera, Netscape, Chrome only) (HKLM-x32\…\{41626CC0-A854-4402-AD06-D7939515C282}) (Version: 6.2.0 - Sibelius Software, a division of Avid Technology, Inc.)
Skype™ 7.0 (HKLM-x32\…\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
SmartWebPrinting (HKLM-x32\…\{DC635845-46D3-404B-BCB1-FC4A91091AFA}) (Version: 130.0.457.000 - Hewlett-Packard) Hidden
Smilebox (HKU\S-1-5-21-632860548-1775735820-415820443-1000\…\Smilebox) (Version: 1.0.0.31741 - Smilebox, Inc.)
SolutionCenter (HKLM-x32\…\{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}) (Version: 130.0.373.000 - Hewlett-Packard) Hidden
Spot (HKLM-x32\…\{3D171340-B528-42E0-92E4-BDA7AEEF6F32}_is1) (Version: 1.0.0.0 - XM Asia Pacific Pte Ltd)
StatusMonitor (HKLM-x32\…\{86D16055-3C14-44C6-BCD7-5514B83BAD34}) (Version: 1.12.4.0 - Brother Insutries Ltd.) Hidden
Tales of Lagoona (HKLM-x32\…\WTA-75f90731-d0ef-4ead-85f3-edbfba5c6ced) (Version: 2.2.0.98 - WildTangent) Hidden
Tap Tap Bear (HKLM-x32\…\{A393CDFF-BEB8-48EA-990D-2EB35B311D23}_is1) (Version: 1.0.0.0 - XM Asia Pacific Pte Ltd)
TeamViewer 9 (HKLM-x32\…\TeamViewer 9) (Version: 9.0.32494 - TeamViewer)
TI USB 3.0 Host Controller Driver (HKLM-x32\…\InstallShield_{355FBD67-5A4F-44DA-86A1-56EEC4C20EC0}) (Version: 1.12.18.0 - Texas Instruments Inc.)
TI USB3 Host Driver (HKLM-x32\…\{355FBD67-5A4F-44DA-86A1-56EEC4C20EC0}) (Version: 1.12.18.0 - Texas Instruments Inc.) Hidden
Toolbox (HKLM-x32\…\{6BBA26E9-AB03-4FE7-831A-3535584CA002}) (Version: 130.0.648.000 - Hewlett-Packard) Hidden
Torchlight (HKLM-x32\…\WTA-3c9ded15-538a-4040-b422-610d26c7de9d) (Version: 2.2.0.98 - WildTangent) Hidden
TSHostedAppLauncher (HKLM-x32\…\{F89BADB0-D319-470E-8024-443EE3A3402B}) (Version: 5.1.15.0 - Hewlett-Packard) Hidden
UnloadSupport (HKLM-x32\…\{4E7C28C7-D5DA-4E9F-A1CA-60490B54AE35}) (Version: 11.0.0 - Hewlett-Packard) Hidden
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\…\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
Update Installer for WildTangent Games App (HKLM-x32\…\{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App) (Version: - WildTangent) Hidden
UsbRepairTool (HKLM-x32\…\{523276A4-5779-4105-9163-CA1CF94EC533}) (Version: 1.4.0.0 - Brother Insutries Ltd.) Hidden
Virtual Villagers 4 - The Tree of Life (HKLM-x32\…\WTA-a76813b1-d318-4c70-b481-009dabe4cb9b) (Version: 2.2.0.98 - WildTangent) Hidden
WebReg (HKLM-x32\…\{43CDF946-F5D9-4292-B006-BA0D92013021}) (Version: 130.0.132.017 - Hewlett-Packard) Hidden
WildTangent Games App (HP Games) (HKLM-x32\…\{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-hp) (Version: 4.0.5.36 - WildTangent) Hidden
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\…\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
WinZip 16.0 (HKLM\…\{CD95F661-A5C4-44F5-A6AA-ECDD91C240CD}) (Version: 16.0.9715 - WinZip Computing, S.L. )
Wondershare Helper Compact 2.5.2 (HKLM-x32\…\{5363CE84-5F09-48A1-8B6C-6BB590FFEDF2}_is1) (Version: 2.5.2 - Wondershare)
Wondershare Video Converter Ultimate(Build 9.0.1.4) (HKLM-x32\…\Wondershare Video Converter Ultimate_is1) (Version: 9.0.1.4 - Wondershare Software)
Youda Fisherman (HKLM-x32\…\WTA-cb0bd757-b714-4ced-8e65-6cdcd47c3ad9) (Version: 2.2.0.98 - WildTangent) Hidden
Zuma's Revenge (HKLM-x32\…\WTA-6a3fb242-dbd2-46cf-bf50-6031b10d212b) (Version: 2.2.0.98 - WildTangent) Hidden
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
ShellIconOverlayIdentifiers: [ OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\buShell.dll [2018-11-03] (Symantec Corporation)
ShellIconOverlayIdentifiers: [ OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\buShell.dll [2018-11-03] (Symantec Corporation)
ShellIconOverlayIdentifiers: [ OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\buShell.dll [2018-11-03] (Symantec Corporation)
ShellIconOverlayIdentifiers-x32: [ OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\buShell.dll [2018-11-03] (Symantec Corporation)
ShellIconOverlayIdentifiers-x32: [ OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\buShell.dll [2018-11-03] (Symantec Corporation)
ShellIconOverlayIdentifiers-x32: [ OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\buShell.dll [2018-11-03] (Symantec Corporation)
ContextMenuHandlers1: [AVG] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files (x86)\AVG\Antivirus\ashShA64.dll [2018-11-15] (AVG Technologies CZ, s.r.o.)
ContextMenuHandlers1: [BUContextMenu] -> {F7CAA2A1-67A2-44BB-B20F-202FD8EB1DAB} => C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\buShell.dll [2018-11-03] (Symantec Corporation)
ContextMenuHandlers1: [PhotoStreamsExt] -> {89D984B3-813B-406A-8298-118AFA3A22AE} => C:\Program Files\Common Files\Apple\Internet Services\ShellStreams64.dll [2014-11-21] (Apple Inc.)
ContextMenuHandlers1: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => C:\Program Files (x86)\PowerISO\PWRISOSH.DLL [2012-08-24] (Power Software Ltd)
ContextMenuHandlers1: [Symantec.Norton.Antivirus.IEContextMenu] -> {FAD61B3D-699D-49B2-BE16-7F82CB4C59CA} => C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\NavShExt.dll [2018-11-03] (Symantec Corporation)
ContextMenuHandlers1: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\wzshls64.dll [2012-02-16] (WinZip Computing, S.L.)
ContextMenuHandlers1: [WondershareVideoConverterFileOpreation] -> {FEB746CA-95C2-485F-B386-C30D4E56D22E} => C:\windows\SysWOW64\WSCM64.dll [2015-02-27] ()
ContextMenuHandlers2: [Symantec.Norton.Antivirus.IEContextMenu] -> {FAD61B3D-699D-49B2-BE16-7F82CB4C59CA} => C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\NavShExt.dll [2018-11-03] (Symantec Corporation)
ContextMenuHandlers3: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ContextMenuHandlers3: [LinkUpMenuExt] -> {B793E5EA-5344-488E-B98D-A18E2E5938AB} => C:\Program Files (x86)\Hewlett-Packard\HP LinkUp\LinkUpExt64.dll [2011-05-06] (Hewlett-Packard)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-09-19] (Malwarebytes)
ContextMenuHandlers4: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => C:\Program Files (x86)\PowerISO\PWRISOSH.DLL [2012-08-24] (Power Software Ltd)
ContextMenuHandlers4: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\wzshls64.dll [2012-02-16] (WinZip Computing, S.L.)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\windows\system32\igfxpph.dll [2012-04-04] (Intel Corporation)
ContextMenuHandlers6: [AVG] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files (x86)\AVG\Antivirus\ashShA64.dll [2018-11-15] (AVG Technologies CZ, s.r.o.)
ContextMenuHandlers6: [BUContextMenu] -> {F7CAA2A1-67A2-44BB-B20F-202FD8EB1DAB} => C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\buShell.dll [2018-11-03] (Symantec Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-09-19] (Malwarebytes)
ContextMenuHandlers6: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => C:\Program Files (x86)\PowerISO\PWRISOSH.DLL [2012-08-24] (Power Software Ltd)
ContextMenuHandlers6: [Symantec.Norton.Antivirus.IEContextMenu] -> {FAD61B3D-699D-49B2-BE16-7F82CB4C59CA} => C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\NavShExt.dll [2018-11-03] (Symantec Corporation)
ContextMenuHandlers6: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\wzshls64.dll [2012-02-16] (WinZip Computing, S.L.)
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {03256141-1BAE-4C9E-8D28-AED4BC1B37DE} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [2018-08-30] (HP Inc.)
Task: {0583328E-0A8D-40B9-88C1-6CBF18EF2064} - System32\Tasks\HPCeeScheduleForBarley => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2015-06-16] (Hewlett-Packard)
Task: {13CA88A1-CDA4-4585-9F11-8BC5130BC8D0} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation)
Task: {1ABD908E-44DD-46E5-93D6-F85795AE81E1} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\windows\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_101_pepper.exe [2018-12-06] (Adobe Systems Incorporated)
Task: {2AA6B539-4673-4A05-8597-E9C84EE0899E} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2014-03-19] (Microsoft)
Task: {2C5DC53C-3BB7-43CC-AA49-116AAEF51CF5} - System32\Tasks\{D95529CE-E95E-447C-8D8C-4C1A622E5294} => C:\windows\system32\pcalua.exe -a "C:\Users\Barley\Downloads\chromeinstall-8u31 (1).exe" -d C:\Users\Barley\Downloads
Task: {40CB04A3-5E27-4FFF-8F98-2069CF54D5AB} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-632860548-1775735820-415820443-1000Core => C:\Users\Barley\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {45416CB6-710F-4224-82AA-01FE4BC3D47B} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Product Configurator => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\ProductConfig.exe [2018-11-08] (HP Inc.)
Task: {4DEF5C25-BA5D-4828-98AF-FC4FBA2C55C2} - System32\Tasks\AVG\Overseer => C:\Program Files\Common Files\AVG\Overseer\overseer.exe [2018-10-28] (AVG Technologies CZ, s.r.o.)
Task: {4F04A113-09B2-4923-A098-4F9DCBB11ADA} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation)
Task: {6D07362E-868E-43E5-9482-326BF8228EB4} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\windows\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_101_Plugin.exe [2018-12-05] (Adobe Systems Incorporated)
Task: {6D49B0C9-CEF2-467A-AD36-7DB6C8FE2F99} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation)
Task: {7A479DAC-A6ED-4050-961C-372019C23B7B} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2018-12-10] (HP Inc.)
Task: {7F66690E-782F-4E81-A623-244E817342E9} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2018-12-10] (Piriform Software Ltd)
Task: {8D5865E3-B262-4FEE-BD7A-1A397D69B4EE} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {93BAAB6E-33D2-47CD-B0F4-D7C3357882E7} - System32\Tasks\Norton Internet Security\Norton Internet Security Error Analyzer => C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\SymErr.exe [2018-11-03] (Symantec Corporation)
Task: {9F9B883E-CB9B-48C3-BBF8-9C2C0E0750AC} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation)
Task: {A4DFCC1B-B3C7-4572-A960-FB8DA59855C5} - System32\Tasks\Antivirus Emergency Update => C:\Program Files (x86)\AVG\Antivirus\AvEmUpdate.exe [2018-11-15] (AVG Technologies CZ, s.r.o.)
Task: {AFF25087-364C-4FB3-AAC9-50F6F6E0A392} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater - Resources => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2017-09-20] (HP Inc.)
Task: {B458637F-D899-4538-BA11-2A14B1ED6A8C} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.)
Task: {BEF7C1BC-3725-43AE-B6C5-660106D31E7E} - System32\Tasks\Hewlett-Packard\HP Active Health\HP Active Health Scan (HPSA) => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.exe [2017-11-20] ()
Task: {BF9223F9-D1BF-46CB-BBC9-3C2CBBC5638F} - System32\Tasks\Remediation\AntimalwareMigrationTask => C:\Program Files\Common Files\AV\Norton Internet Security\Upgrade.exe [2018-11-03] (Symantec Corporation)
Task: {C56A0862-A80E-4AF3-A838-7EE9E32EC86D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2018-11-09] (HP Inc.)
Task: {C7EB1FD5-AF07-496F-A6FA-1D64ED3C7ACF} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2018-08-13] (Adobe Systems Incorporated)
Task: {CCEC197E-48A7-4647-AD8D-6D177DE3402A} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-632860548-1775735820-415820443-1000UA => C:\Users\Barley\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {CF50CD1D-1E6D-4BCE-BEF5-42BAA1D3D88B} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2018-11-09] (HP Inc.)
Task: {DA1CEAA8-060C-4D55-81D2-C45E1899F543} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {E0AB2A07-7DD0-4B65-BDAA-603EA27394D6} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [2018-12-10] (Piriform Ltd)
Task: {E25995B7-68C9-4394-B1CE-2988A5345F45} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2017-09-20] (HP Inc.)
Task: {EF88B9A7-8B01-496D-BFED-719F2A3A7981} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2018-12-10] (HP Inc.)
Task: {F2946359-CBD4-45CF-A8B0-F43C86BAACF4} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\WSCStub.exe [2018-11-03] (Symantec Corporation)
Task: {F8605A12-4EF9-4498-9431-35EDC2893E69} - System32\Tasks\Norton Internet Security\Norton Internet Security Error Processor => C:\Program Files (x86)\Norton Internet Security\Engine\22.16.2.22\SymErr.exe [2018-11-03] (Symantec Corporation)
Task: {FB40547D-7545-4F51-84A4-F02B26327EC3} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-12-06] (Adobe Systems Incorporated)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\windows\Tasks\HPCeeScheduleForBarley.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
==================== Shortcuts & WMI ========================
(The entries could be listed to be restored or removed.)
ShortcutWithArgument: C:\Users\Barley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Destiny Discover.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> –profile-directory="Profile 1" –app-id=bbhkckkafippkgeicobhgafkioeblebh
ShortcutWithArgument: C:\Users\Barley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\ScanQR.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> –profile-directory="Profile 1" –app-id=nihhbejdflkeingkkpakffdlmepaeaah
ShortcutWithArgument: C:\Users\Barley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Vernier Graphical Analysis.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> –profile-directory="Profile 1" –app-id=dncgedbnidfkppmdgfgidcepclnokpkb
ShortcutWithArgument: C:\Users\Barley\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\69639df789022856\Erica - Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> –profile-directory="Profile 1"
==================== Loaded Modules (Whitelisted) ==============
2017-03-03 17:38 - 2015-02-27 14:38 - 000721263 _____ () C:\windows\SysWOW64\WSCM64.dll
2016-10-05 18:17 - 2016-10-05 18:17 - 000092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2016-10-05 18:17 - 2016-10-05 18:17 - 001353528 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2012-04-04 21:46 - 2012-04-04 21:46 - 000094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2012-12-25 15:57 - 2011-05-26 14:14 - 000477080 _____ () C:\Users\Barley\AppData\Roaming\HP SimpleSave Application\StartHelper.exe
2018-12-12 14:09 - 2018-12-12 00:11 - 005237216 _____ () C:\Program Files (x86)\Google\Chrome\Application\71.0.3578.98\libglesv2.dll
2018-12-12 14:09 - 2018-12-12 00:11 - 000117216 _____ () C:\Program Files (x86)\Google\Chrome\Application\71.0.3578.98\libegl.dll
2016-12-25 11:57 - 2005-04-22 13:36 - 000143360 _____ () C:\windows\system32\BrSNMP64.dll
2018-12-23 11:43 - 2018-09-12 11:35 - 002701064 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\SelfProtectionSdk.dll
2018-11-15 20:11 - 2018-11-15 20:11 - 000724752 _____ () c:\Program Files (x86)\AVG\Antivirus\x64\StreamBack.dll
2018-11-15 20:10 - 2018-11-15 20:10 - 000919312 _____ () C:\Program Files (x86)\AVG\Antivirus\anen.dll
2018-11-15 20:11 - 2018-11-15 20:11 - 000594192 _____ () C:\Program Files (x86)\AVG\Antivirus\streamback.dll
2018-12-24 12:46 - 2018-12-24 12:46 - 005734600 _____ () C:\Program Files (x86)\AVG\Antivirus\defs\18122404\algo.dll
2018-11-15 20:10 - 2018-11-15 20:10 - 000496400 _____ () C:\Program Files (x86)\AVG\Antivirus\gui_cache.dll
2018-11-15 20:10 - 2018-11-15 20:10 - 001112336 _____ () C:\Program Files (x86)\AVG\Antivirus\shepherdsync.dll
2016-10-29 23:32 - 2016-10-27 11:13 - 000114664 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\zlib1.dll
2016-10-29 23:32 - 2017-01-20 07:51 - 000108008 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\boost_filesystem-vc120-mt-1_56.dll
2016-10-29 23:32 - 2017-01-20 07:51 - 000024040 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\boost_system-vc120-mt-1_56.dll
2016-10-29 23:32 - 2017-01-20 07:51 - 000048104 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\boost_date_time-vc120-mt-1_56.dll
2018-03-13 10:22 - 2018-03-13 10:22 - 067127976 _____ () C:\Program Files (x86)\AVG\Antivirus\libcef.dll
2009-02-27 16:38 - 2009-02-27 16:38 - 000139264 _____ () C:\Program Files (x86)\Brother\BrUtilities\BrLogAPI.dll
2017-03-03 17:39 - 2016-10-08 16:48 - 001506304 _____ () C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\DAQExp.dll
2017-03-03 17:39 - 2016-07-21 10:54 - 000137728 _____ () C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\CBSCreateVC.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
IE trusted site: HKU\S-1-5-21-632860548-1775735820-415820443-1000\…\sjhnh.org -> hxxps://gateway1.sjhnh.org
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-13 21:34 - 2018-12-23 00:27 - 000000824 _____ C:\windows\system32\Drivers\etc\hosts
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-632860548-1775735820-415820443-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Barley\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 8.8.8.8 - 8.8.4.4
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
If an entry is included in the fixlist, it will be removed.
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk => C:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: BeatsOSDApp => C:\Program Files\IDT\WDM\beats64.exe
MSCONFIG\startupreg: DNS7reminder => "C:\Program Files (x86)\ScanSoft\NaturallySpeaking\Program\Ereg.exe" -r "C:\Program Files (x86)\ScanSoft\NaturallySpeaking\Program\ereg.ini"
MSCONFIG\startupreg: HP Software Update => c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: LifeCam => "C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe"
MSCONFIG\startupreg: Norton Online Backup => C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
MSCONFIG\startupreg: PWRISOVM.EXE => C:\Program Files (x86)\PowerISO\PWRISOVM.EXE -startup
MSCONFIG\startupreg: SysTrayApp => C:\Program Files\IDT\WDM\sttray64.exe
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{C40D9B13-61A2-4285-A4E7-E26BB14A390D}] => (Allow) C:\Program Files (x86)\Ralink\Common\RaMediaServer.exe ()
FirewallRules: [{8E66A095-795E-494F-8F39-F583A6C355AE}] => (Allow) C:\Program Files (x86)\Ralink\Common\RaMediaServer.exe ()
FirewallRules: [{64D8B223-4FDB-4856-984E-D6A313D081AC}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Remote Graphics Receiver\rgreceiver.exe (Hewlett-Packard)
FirewallRules: [{46D3AD7D-F0D3-4B5B-A87A-8A74DD670C45}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Remote Graphics Receiver\rgreceiver.exe (Hewlett-Packard)
FirewallRules: [{096CA7E4-26E4-4D3F-BCE6-8B421C198BB6}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\HP LinkUp\HP LinkUp Viewer.exe (Hewlett-Packard Company)
FirewallRules: [{62DA04C4-6D00-4D4D-83D7-0C35250D69CD}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\HP LinkUp\HP LinkUp Viewer.exe (Hewlett-Packard Company)
FirewallRules: [{77D34678-43F1-4822-B594-6E09D82214B1}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe (Skype Technologies S.A.)
FirewallRules: [{368B141D-50B1-4EE3-9F97-6978FEC3BCA7}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe (Microsoft Corporation)
FirewallRules: [{748AC05F-6DAF-4DDA-B7F8-49F3BAC6092C}] => (Allow) LPort=2869
FirewallRules: [{1A056468-B541-45F9-9F3B-9DE4103860F9}] => (Allow) LPort=1900
FirewallRules: [{47F869E4-237F-428A-87B2-B24C77087D97}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
FirewallRules: [{083D86A3-2137-4A0F-A1FD-6C5139F7A6D9}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe (Microsoft Corporation)
FirewallRules: [{3C757619-EA6B-4395-B7C1-7FD9D82913A0}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeCam.exe (Microsoft Corporation)
FirewallRules: [{337898BF-4E6C-4F28-B6FF-F4E0103C7088}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeCam.exe (Microsoft Corporation)
FirewallRules: [{72660C52-6CAD-426B-8480-9A4CCDA25FDE}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeEnC2.exe (Microsoft Corporation)
FirewallRules: [{A7ED8D1C-7DC5-4254-9A3C-7210F65BCA23}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeEnC2.exe (Microsoft Corporation)
FirewallRules: [{FC12E3B7-37DB-40F2-8007-7CDBA8F98DA1}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe (Microsoft Corporation)
FirewallRules: [{F8F68A5A-37F7-458F-A223-6EDFBEB178CF}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe (Microsoft Corporation)
FirewallRules: [{29DFB764-4E0E-4C7F-8E63-04BEEB9E85E5}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeTray.exe (Microsoft Corporation)
FirewallRules: [{6DFF213C-2E9D-40B4-93A0-96C6D06DBDBF}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeTray.exe (Microsoft Corporation)
FirewallRules: [{16F9FFA7-DE34-4195-8889-99836EA872DE}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
FirewallRules: [{188D6962-81EE-44A5-8C30-3730334E748F}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
FirewallRules: [{9DF14B61-33D7-4600-A2DC-8B67E3D34687}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc.)
FirewallRules: [{C02B03BE-C660-42B9-AF20-FE8402B12E27}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc.)
FirewallRules: [{1E46AAC8-F6F9-4A9E-80D6-C952FCBA08A4}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe No File
FirewallRules: [{C803B594-7DEF-49DD-B2B1-190FC1E5BDF0}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe No File
FirewallRules: [{E2A974B2-9D33-4747-A3E5-A6E3DB73D7A1}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpofxm08.exe No File
FirewallRules: [{B847FD57-37DB-41C1-B8EE-F834959F0586}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposfx08.exe No File
FirewallRules: [{2BC6FC16-2643-4675-8DA0-D440DAAB07D3}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposid01.exe (Hewlett-Packard Co.)
FirewallRules: [{2E5B1FB9-CD88-4C24-BCCA-1B1C98E43CF1}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqkygrp.exe (Hewlett-Packard)
FirewallRules: [{971D0E46-D0B7-4B59-A6F8-5474F692BAFC}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcopy2.exe No File
FirewallRules: [{BED31218-45AD-43F9-9FC9-381AE7CBE610}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpfccopy.exe ()
FirewallRules: [{2FC88A0B-5EB8-45B5-AEBA-CDA2C66C54B6}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpzwiz01.exe No File
FirewallRules: [{371C863F-1809-44C4-8001-AC3E16BC8CC9}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpoews01.exe (Hewlett-Packard Co.)
FirewallRules: [{AA1AED5A-88F8-45FE-BEBC-F85163E1DB67}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqnrs08.exe (Hewlett-Packard Co.)
FirewallRules: [{C9A77EEA-40C1-4D8F-8DA8-4E74A52A3F2A}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpiscnapp.exe (Hewlett-Packard)
FirewallRules: [{766360E0-0271-47DC-9292-260B4AF19224}] => (Allow) C:\Program Files (x86)\common files\hp\digital imaging\bin\hpqphotocrm.exe No File
FirewallRules: [{FBECA0C4-4012-4779-9914-18054013DF61}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqsudi.exe No File
FirewallRules: [{B51D41D8-9002-424B-96AE-995272DF678E}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqpsapp.exe No File
FirewallRules: [{FD780D56-F9B3-4CAA-9DFE-753F355A2B42}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpofxs08.exe No File
FirewallRules: [{EF53A754-678A-4A38-A8F1-2CA43185FD29}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqfxt08.exe No File
FirewallRules: [{37A40D7C-152E-4165-9107-66247F5ECEE8}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqpse.exe No File
FirewallRules: [{3A9268B3-2F0B-4490-8182-A74DFB16F9A1}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgplgtupl.exe (Hewlett-Packard Co.)
FirewallRules: [{62364A33-C195-4DAB-87F8-D01F2F09A8B4}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe (Hewlett-Packard)
FirewallRules: [{A33F9CEA-E81D-4C74-87BF-B40CE8544101}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgm.exe (Hewlett-Packard Co.)
FirewallRules: [{57303010-2E61-4E65-8DE8-0FD8771F2010}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgh.exe (Hewlett-Packard Co.)
FirewallRules: [{B5492CC8-06DF-47E8-8D6D-082A6BD1DF53}] => (Allow) C:\Program Files (x86)\HP\hp software update\hpwucli.exe (Hewlett-Packard)
FirewallRules: [{6D422CBB-1201-4676-A036-95969E82F3FE}] => (Allow) C:\Program Files (x86)\HP\digital imaging\smart web printing\smartwebprintexe.exe (Hewlett-Packard Co.)
FirewallRules: [{3ED30955-EFF3-4107-8BE4-689FCE621E0B}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe (TeamViewer GmbH)
FirewallRules: [{E0E4ABAD-93C0-4E6E-A0A0-A4A561496784}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe (TeamViewer GmbH)
FirewallRules: [{BD69C17B-9FC9-4912-A2C1-3AE23478EB2E}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe (TeamViewer GmbH)
FirewallRules: [{44605B2D-69D2-45FD-968A-081B858ACCBF}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe (TeamViewer GmbH)
FirewallRules: [{4243050D-CF14-483C-945D-B517D4B8E297}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
FirewallRules: [{6807B6A1-AAC1-4555-8EA4-D9633E4A34B6}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
FirewallRules: [{402DF736-0E3F-482F-813A-1E0EFF713B0E}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc.)
FirewallRules: [{F613D847-4755-4F67-9E83-CA8D9D16A333}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc.)
FirewallRules: [{524FBD36-AFE4-4D69-ACC6-FBAFA6255D9C}] => (Allow) C:\Program Files\iTunes\iTunes.exe (Apple Inc.)
FirewallRules: [{B497A808-16EF-4A4D-9A0B-B40E7343890A}] => (Allow) E:\Install\wlan_wiz\.\wlan_assistant\waw.exe No File
FirewallRules: [{316051F7-DEE7-47A6-B06C-7130CBFECE25}] => (Allow) LPort=54925
FirewallRules: [{3355062F-82C4-416B-BD10-2077C5EE5B54}] => (Allow) c:\program files (x86)\pc-faxreceive\brengineprocess.exe (Brother Industries, Ltd.)
FirewallRules: [{42C4E2DF-128F-46EF-80AB-44DB8071AB7F}] => (Allow) c:\program files (x86)\pc-faxreceive\brengineprocess.exe (Brother Industries, Ltd.)
FirewallRules: [{AE566146-EE91-4B46-A6C3-741877219C69}] => (Allow) C:\Program Files (x86)\AVG\Antivirus\AvEmUpdate.exe (AVG Technologies CZ, s.r.o.)
FirewallRules: [{AB4720B2-A03A-4E60-B06D-CE71795B241E}] => (Allow) C:\Program Files (x86)\AVG\Antivirus\AvEmUpdate.exe (AVG Technologies CZ, s.r.o.)
FirewallRules: [{5D6943E6-0633-4C12-8E44-B632FFD15340}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
FirewallRules: [{B8DA1F71-AC18-4883-88F2-B48A644C0CD2}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe (Piriform Ltd)
FirewallRules: [{9431D078-F9CC-4406-84BC-AD1A801972F0}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe (Piriform Ltd)
==================== Restore Points =========================
21-12-2018 01:12:55 Windows Update
22-12-2018 10:50:38 Removed CouponPrinterPlugin
22-12-2018 11:13:46 Restore Point Created by FRST
24-12-2018 12:08:53 Removed Digital Coupon Printer
24-12-2018 12:25:42 Removed RevTraxPrintMyCoupon
24-12-2018 12:26:51 Removed PrintMyCouponAnywhere
==================== Faulty Device Manager Devices =============
Name: Photosmart C6100 series
Description: Photosmart C6100 series
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name: Photosmart C6100 series
Description: Photosmart C6100 series
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name: Photosmart C6100 series
Description: Photosmart C6100 series
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name: Photosmart C6100 series
Description: Photosmart C6100 series
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name: Photosmart C6100 series
Description: Photosmart C6100 series
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name: Photosmart C6100 series
Description: Photosmart C6100 series
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name: AntiLog32
Description: AntiLog32
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: AntiLog32
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
Name: Photosmart C6100 series
Description: Photosmart C6100 series
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name: Photosmart C6100 series
Description: Photosmart C6100 series
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name: Photosmart C6100 series
Description: Photosmart C6100 series
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name: Photosmart C6100 series
Description: Photosmart C6100 series
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (12/24/2018 03:22:01 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: mbamservice.exe, version: 3.2.0.704, time stamp: 0x5b9acf90
Faulting module name: ntdll.dll, version: 6.1.7601.24308, time stamp: 0x5be8601e
Exception code: 0xc0000005
Fault offset: 0x0000000000032b04
Faulting process id: 0x714
Faulting application start time: 0x01d49ae700d914a0
Faulting application path: C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe
Faulting module path: C:\windows\SYSTEM32\ntdll.dll
Report Id: fc353145-0754-11e9-99d0-24be05218274
Error: (12/23/2018 12:40:40 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: mbamservice.exe, version: 3.2.0.704, time stamp: 0x5b9acf90
Faulting module name: SelfProtectionSdk.dll, version: 3.0.0.360, time stamp: 0x5b995ba2
Exception code: 0xc0000005
Fault offset: 0x000000000001f177
Faulting process id: 0x1c8c
Faulting application start time: 0x01d49adea763ca09
Faulting application path: C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe
Faulting module path: C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\SelfProtectionSdk.dll
Report Id: dce7af3b-06d9-11e9-b4a2-24be05218274
Error: (12/23/2018 12:25:38 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program Un_A.exe version 3.2.0.4 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
Process ID: a80
Start Time: 01d49a7d383060d0
Termination Time: 0
Application Path: C:\Users\Barley\AppData\Local\Temp\~nsuA.tmp\Un_A.exe
Report Id:
Error: (12/22/2018 11:14:43 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: svchost.exe, version: 6.1.7600.16385, time stamp: 0x4a5bc3c1
Faulting module name: ole32.dll, version: 6.1.7601.24291, time stamp: 0x5be78530
Exception code: 0xc0000005
Fault offset: 0x0000000000040cc2
Faulting process id: 0x15e0
Faulting application start time: 0x01d49a08c8a1e844
Faulting application path: C:\windows\system32\svchost.exe
Faulting module path: C:\windows\system32\ole32.dll
Report Id: b068b25d-0604-11e9-bd26-24be05218274
Error: (12/21/2018 10:33:08 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program aswMBR.exe version 1.0.1.2252 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
Process ID: 1c34
Start Time: 01d499a6ffb3ae09
Termination Time: 2
Application Path: C:\Users\Barley\Desktop\aswMBR.exe
Report Id: 49dfc6dd-059a-11e9-962c-24be05218274
Error: (12/20/2018 11:39:43 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: mbamservice.exe, version: 3.2.0.704, time stamp: 0x5b9acf90
Faulting module name: ntdll.dll, version: 6.1.7601.24308, time stamp: 0x5be8601e
Exception code: 0xc0000005
Fault offset: 0x0000000000032b04
Faulting process id: 0x1468
Faulting application start time: 0x01d498e473a5f40f
Faulting application path: C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe
Faulting module path: C:\windows\SYSTEM32\ntdll.dll
Report Id: 6f60daa2-04da-11e9-b7b1-24be05218274
Error: (12/18/2018 08:10:01 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 80746
Error: (12/18/2018 08:10:01 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 80746
System errors:
=============
Error: (12/24/2018 03:14:28 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Ralink UPnP Media Server service to connect.
Error: (12/24/2018 03:12:22 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has stopped unexpectedly.
Module Path: C:\windows\system32\RAIHV.dll
Error: (12/24/2018 03:12:22 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has stopped unexpectedly.
Module Path: C:\windows\system32\RAIHV.dll
Error: (12/24/2018 03:12:17 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has stopped unexpectedly.
Module Path: C:\windows\system32\RAIHV.dll
Error: (12/24/2018 03:12:07 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The HP Touchpoint Analytics service terminated unexpectedly. It has done this 1 time(s).
Error: (12/24/2018 03:12:07 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The PDF Document Manager service terminated unexpectedly. It has done this 1 time(s).
Error: (12/24/2018 03:12:07 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Software Protection service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
Error: (12/24/2018 03:12:07 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Media Player Network Sharing Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.
CodeIntegrity:
===================================
Date: 2013-01-24 07:41:06.474
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2013-01-24 07:41:06.456
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i3-2120 CPU @ 3.30GHz
Percentage of memory in use: 49%
Total physical RAM: 6030.01 MB
Available physical RAM: 3029.55 MB
Total Virtual: 12058.17 MB
Available Virtual: 8778.67 MB
==================== Drives ================================
Drive c: (OS) (Fixed) (Total:914.75 GB) (Free:754.9 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive d: (HP_RECOVERY) (Fixed) (Total:16.54 GB) (Free:2.06 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: C88C1F6D)
Partition: GPT.
==================== End of Addition.txt ============================