This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Slow loading laptop

27 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi

 

I need my computer cleaned. It seems to freeze up quite a bit as well. I have an HP laptop that has Windows 8.1 operating system.

 

 

Any help will be greatly appreciated.

Thanks

  • Please download Farbar Recovery Scan Tool (x32) or Farbar Recovery Scan Tool (x64) and save the file to your Desktop.
  • Note: Download and run the version compatible with your system (32 or 64-bit). Download both if you're unsure; only one will run.
  • Right-Click FRST.exe / FRST64.exe and select [external image: AVOiBNU.jpg]Run as administrator to run the programme.
  • Click Yes to the disclaimer.
  • Ensure the Addition.txt box is checked.
  • Click the Scan button and let the programme run.
  • Upon completion, click OK, then OK on the Addition.txt pop up screen.
  • Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy the contents of both logs and paste in your next reply.

Here is the FRST Notepad scan.

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 17.03.2019
Ran by [removed] (administrator) on MRSJOHNSON (02-04-2019 19:58:05)
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows 8.1 (Update) (X64) Language: English (United States)
Default browser: IE
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
() [File not signed] C:\Program Files\Hewlett-Packard\SimplePass\cachesrvr.exe
(Softex Inc.) [File not signed] C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe
(Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atiesrxx.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
() [File not signed] C:\Program Files\ATI Technologies\ATI.ACE\a4\AdaptiveSleepService.exe
(Advanced Micro Devices, Inc.) [File not signed] C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(PC DRIVERS HEADQUARTERS I, INC -> PC Drivers HeadQuarters LP) C:\Program Files (x86)\Driver Support\svc\DriverSupportAOsvc.exe
(HP Inc. -> HP Inc.) C:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe
(PC DRIVERS HEADQUARTERS I, INC -> PC Drivers HeadQuarters LP) C:\Program Files (x86)\Driver Support\svc\DriverSupportAO.exe
(Huawei Technologies Co., Ltd. -> ) [File not signed] C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
() [File not signed] C:\Program Files\Hewlett-Packard\SimplePass\opvapp.exe
(CyberLink Corp. -> CyberLink Corp.) C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe
(PC DRIVERS HEADQUARTERS I, INC -> PC Drivers Headquarters LP) C:\Program Files (x86)\Driver Support\DriverSupport.exe
(Softex Incorporated -> Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\HPSmplPass.exe
(Softex Incorporated -> Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBroker.exe
(Softex Incorporated -> Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\StikyNot.exe
(CenturyLink -> CenturyLink Inc) C:\Program Files (x86)\CenturyLink\Desktop\CenturyLinkTouchPointAgent.exe
(HP Inc. -> HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(Intuit, Inc. -> Intuit Inc.) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
(Adobe Systems, Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe
(Adobe Systems, Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe
(Symantec Corporation -> Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
(Symantec Corporation -> Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
(Google Inc -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Adobe Systems, Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Adobe Systems, Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\Updates\16.0.10730.20304\OfficeClickToRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Google Inc -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.34.7\GoogleCrashHandler.exe
(Google Inc -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.34.7\GoogleCrashHandler64.exe
(Google Inc -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Update\Install\{340C1C23-02B6-4C27-A6C4-DA4E488E412F}\73.0.3683.86_72.0.3626.109_chrome_updater.exe
(Google LLC -> Google Inc.) C:\Windows\Temp\CR_11088.tmp\setup.exe
(Google LLC -> Google Inc.) C:\Windows\Temp\CR_11088.tmp\setup.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\System32\MpSigStub.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\SoftwareDistribution\Download\Install\AM_Delta.exe
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [SimplePass] => C:\Program Files\Hewlett-Packard\SimplePass\HPSmplPass.exe [2755640 2013-09-26] (Softex Incorporated -> Hewlett-Packard)
HKLM\…\Run: [OPBHOBroker] => C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBroker.exe [155704 2013-09-26] (Softex Incorporated -> Hewlett-Packard)
HKLM\…\Run: [OPBHOBrokerDesktop] => C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe [155704 2013-09-26] (Softex Incorporated -> Hewlett-Packard)
HKLM\…\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2771184 2013-07-26] (Synaptics Incorporated -> Synaptics Incorporated)
HKLM\…\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8843520 2016-02-19] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\…\Run: [WindowsDefender] => "%ProgramFiles%\Windows Defender\MSASCuiL.exe"
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [507776 2014-10-07] (Oracle America, Inc. -> Oracle Corporation)
HKLM-x32\…\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation -> Microsoft Corporation)
HKLM-x32\…\Run: [CenturyLinkTouchPointAgent] => C:\Program Files (x86)\CenturyLink\Desktop\CenturyLinkTouchPointAgent.exe [48904 2014-11-04] (CenturyLink -> CenturyLink Inc)
HKLM-x32\…\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767200 2014-06-06] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
HKLM-x32\…\Run: [HPMessageService] => C:\Program Files (x86)\HP\HP System Event\HPMSGSVC.exe [707624 2018-08-08] (HP Inc. -> HP Inc.)
HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\Run: [GoogleChromeAutoLaunch_0C9337CDD31A557C75EB2CDF52C45A5A] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1426400 2018-12-11] (Google Inc -> Google Inc.)
HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [479744 2014-10-28] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\RunOnce: [Delete Cached Update Binary] => C:\Windows\system32\cmd.exe /q /c del /q "C:\Users\Annette\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe"
HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\RunOnce: [Delete Cached Standalone Update Binary] => C:\Windows\system32\cmd.exe /q /c del /q "C:\Users\Annette\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe"
HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\RunOnce: [Uninstall 18.240.1202.0004] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Annette\AppData\Local\Microsoft\OneDrive\18.240.1202.0004"
HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\MountPoints2: {0971029e-8ae2-11e8-830f-3863bb8eae0e} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\MountPoints2: {097102d7-8ae2-11e8-830f-3863bb8eae0e} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\MountPoints2: {803e9b84-3b72-11e8-8302-3863bb8eae0e} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\MountPoints2: {ed76fc77-6b0a-11e5-8270-3863bb8eae0e} - "F:\AutoRun.exe" 
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\72.0.3626.109\Installer\chrmstp.exe [2019-02-19] (Google LLC -> Google Inc.)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{A6EADE66-0000-0000-484E-7E8A45000000}] -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Esl\AiodLite.dll [2018-09-20] (Adobe Systems, Incorporated -> Adobe Systems, Inc.)
HKLM\Software\…\Authentication\Credential Providers: [{538C240D-3DEE-4032-AB4C-08A3A6EB0861}] -> C:\Program Files (x86)\CyberLink\YouCam\CLCredProv\x64\CLCredProv.dll [2014-10-28] (CyberLink Corp. -> CyberLink)
HKLM\Software\…\Authentication\Credential Providers: [{F3F1B0FA-4775-41d8-8578-436772D93FB4}] -> C:\Program Files\Hewlett-Packard\SimplePass\OmniPassCredProv.dll [2013-09-26] (Softex Inc..) [File not signed]
HKLM\Software\…\Authentication\Credential Provider Filters: [{F3F1B0FA-4775-41d8-8578-436772D93FB4}] -> C:\Program Files\Hewlett-Packard\SimplePass\OmniPassCredProv.dll [2013-09-26] (Softex Inc..) [File not signed]
Startup: C:\Users\Annette\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Facebook Gameroom.lnk [2018-08-03]
ShortcutTarget: Facebook Gameroom.lnk -> C:\Users\Annette\AppData\Local\Facebook\Games\FacebookGameroom.exe (Facebook, Inc. -> Facebook) [File not signed]
Startup: C:\Users\Annette\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk [2018-01-08]
ShortcutTarget: Send to OneNote.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE (Microsoft Corporation -> Microsoft Corporation)
Startup: C:\Users\Jacquelyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk [2016-05-14]
ShortcutTarget: Send to OneNote.lnk -> C:\Program Files (x86)\Microsoft Office\Office15\ONENOTEM.EXE (Microsoft Corporation -> Microsoft Corporation)
BootExecute: autocheck autochk /r \??\Z:autocheck autochk * 
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{2BE7FA48-E3A9-4398-8011-4CBB02E6ACC5}: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{8E02059E-EC13-441B-AFD6-CD70C258610A}: [DhcpNameServer] 192.168.0.1 [removed]
 
Internet Explorer:
==================
HKU\S-1-5-21-1409944621-189731363-133459071-1005\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/
SearchScopes: HKU\S-1-5-21-1409944621-189731363-133459071-1005 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2019-01-19] (Microsoft Corporation -> Microsoft Corporation)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation -> Microsoft Corporation)
BHO: No Name -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> No File
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2019-03-31] (Microsoft Corporation -> Microsoft Corporation)
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2016-07-21] (Hewlett-Packard Company -> HP Inc.)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2017-08-24] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll [2014-12-01] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2019-03-02] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll [2014-12-01] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2016-07-21] (Hewlett-Packard Company -> HP Inc.)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-03-31] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-03-31] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-03-31] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-03-31] (Microsoft Corporation -> Microsoft Corporation)
 
FireFox:
========
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation ->  Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\SysWOW64\Adobe\Director\np32dsw_1204144.dll [2013-09-05] (Adobe Systems, Inc.) [File not signed]
FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll [2014-12-01] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll [2014-12-01] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2016-07-19] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation ->  Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2019-03-31] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2013-02-06] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.34.7\npGoogleUpdate3.dll [2019-03-31] (Google Inc -> Google LLC)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.34.7\npGoogleUpdate3.dll [2019-03-31] (Google Inc -> Google LLC)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\3\NP_wtapp.dll [2014-11-22] (WildTangent Inc -> )
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-12-04] (Adobe Systems, Incorporated -> Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1409944621-189731363-133459071-1005: @zoom.us/ZoomVideoPlugin -> C:\Users\Annette\AppData\Roaming\Zoom\bin\npzoomplugin.dll [2017-11-05] (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
 
Chrome: 
=======
CHR DefaultProfile: Profile 1
CHR HomePage: Profile 1 -> mysearch.avg.com
CHR Profile: C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default [2018-08-03]
CHR Extension: (Slides) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-07-29]
CHR Extension: (Docs) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-07-29]
CHR Extension: (Google Drive) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-07-29]
CHR Extension: (YouTube) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-07-29]
CHR Extension: (Honey) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmnlcjabgnpnenekpadlanbbkooimhnj [2018-07-29]
CHR Extension: (Adobe Acrobat) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-03-26]
CHR Extension: (Sheets) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-07-29]
CHR Extension: (Yahoo Partner) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\fpdpdomdpmhpgncppolomeniknkgpbhm [2018-05-09]
CHR Extension: (Google Docs Offline) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-07-29]
CHR Extension: (Piggy - Automatic Coupons & Cash Back) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\hfapbcheiepjppjbnkphkmegjlipojba [2018-07-18]
CHR Extension: (HP Network Check Launcher) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\jkfpchpiljkaemlpmpebnglgkomamfeo [2017-03-26]
CHR Extension: (Grammarly for Chrome) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbfnbcaeplbcioakkpcpgfkobkghlhen [2018-08-03]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-07]
CHR Extension: (Coupon Simplified) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\odhkbaigkdgomaoipjcnnphjdlpnjjka [2018-04-01]
CHR Extension: (No Name) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbjikboenpfhbbejgkoklgkhjpfogcam [2018-07-29]
CHR Extension: (Gmail) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-07-29]
CHR Extension: (Chrome Media Router) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-07-27]
CHR Profile: C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1 [2019-04-02]
CHR Extension: (Slides) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-07-29]
CHR Extension: (Docs) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2018-07-29]
CHR Extension: (Google Drive) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-11-06]
CHR Extension: (YouTube) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-07-29]
CHR Extension: (AVG Secure Search) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\chfdnecihphmhljaaejmgoiahnihplgn [2018-08-07]
CHR Extension: (Adobe Acrobat) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2019-04-02]
CHR Extension: (My Inbox Helper) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eikdkoejhlpkgdeodpbpaigmbikhmbhn [2019-03-23]
CHR Extension: (Sheets) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-07-29]
CHR Extension: (Google Docs Offline) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-08-25]
CHR Extension: (Search Encrypt) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge [2019-03-31]
CHR Extension: (HP Network Check Launcher) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\jkfpchpiljkaemlpmpebnglgkomamfeo [2018-08-31]
CHR Extension: (webPass) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\jlkiooodjckigejdpbkbinlgooolgfhh [2018-10-10]
CHR Extension: (My Inbox Helper) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mpiffdmfpioemhakbaapeeopdppjloec [2019-03-23]
CHR Extension: (Yahoo Web) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\njajpefejmjnhcddhaleakkcehiilppa [2018-08-03]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-07-29]
CHR Extension: (Search Encrypt) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp [2019-03-31]
CHR Extension: (Gmail) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-07-29]
CHR Extension: (Chrome Media Router) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-03-02]
CHR Profile: C:\Users\Annette\AppData\Local\Google\Chrome\User Data\System Profile [2018-08-03]
CHR HKLM-x32\…\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [jkfpchpiljkaemlpmpebnglgkomamfeo] - hxxps://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AdaptiveSleepService; C:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe [140288 2014-06-05] () [File not signed]
R2 AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [239616 2013-09-25] (Microsoft Windows Hardware Compatibility Publisher -> AMD)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2014-06-05] (Advanced Micro Devices, Inc.) [File not signed]
R2 Cachedrv server; C:\Program Files\Hewlett-Packard\SimplePass\cachesrvr.exe [109568 2013-09-26] () [File not signed]
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [9677904 2018-12-28] (Microsoft Corporation -> Microsoft Corporation)
R2 DSAO; C:\Program Files (x86)\driver support\svc\DriverSupportAOsvc.exe [2033104 2016-10-22] (PC DRIVERS HEADQUARTERS I, INC -> PC Drivers HeadQuarters LP)
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [333688 2018-06-13] (HP Inc. -> HP Inc.)
R2 HPWMISVC; C:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe [628768 2017-07-13] (HP Inc. -> HP Inc.)
R2 HuaweiHiSuiteService64.exe; C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe [190784 2018-04-20] (Huawei Technologies Co., Ltd. -> ) [File not signed]
S2 KSDE1.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 1.0\ksde.exe [241544 2016-06-28] (Kaspersky Lab -> AO Kaspersky Lab)
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [4278112 2013-08-02] (Symantec Corporation -> Symantec Corporation)
R2 omniserv; C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe [87552 2013-09-26] (Softex Inc.) [File not signed]
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [310016 2016-02-19] (Realtek Semiconductor Corp -> Realtek Semiconductor)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [361824 2017-01-12] (Microsoft Corporation -> Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [119872 2017-01-12] (Microsoft Corporation -> Microsoft Corporation)
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 AmdAS4; C:\Windows\System32\drivers\AmdAS4.sys [17640 2017-07-21] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, INC.)
R3 amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [12533760 2013-09-25] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.)
R3 amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [619008 2013-09-25] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [222720 2017-07-21] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices)
S3 dg_ssudbus; C:\Windows\system32\DRIVERS\ssudbus.sys [131984 2017-05-18] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R1 epp; C:\Users\Annette\Desktop\bin64\epp.sys [115216 2017-01-03] (Emsisoft Ltd -> Emsisoft Ltd)
S3 ew_usbccgpfilter; C:\Windows\System32\drivers\ew_usbccgpfilter.sys [18944 2018-04-20] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
U5 hw_usbdev; C:\Windows\System32\Drivers\hw_usbdev.sys [116864 2018-04-20] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
R3 kltap; C:\Windows\system32\DRIVERS\kltap.sys [52152 2016-06-07] (AnchorFree Inc -> The OpenVPN Project)
R3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [294104 2014-11-28] (Realtek Semiconductor Corp -> Realtek Semiconductor Corp.)
R3 RTWlanE; C:\Windows\system32\DRIVERS\rtwlane.sys [3636440 2014-12-22] (Realtek Semiconductor Corp -> Realtek Semiconductor Corporation )
R3 RTWlanE; C:\Windows\SysWOW64\DRIVERS\rtwlane.sys [2945240 2013-09-12] (Realtek Semiconductor Corp -> Realtek Semiconductor Corporation )
S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [30448 2013-07-26] (Synaptics Incorporated -> Synaptics Incorporated)
S3 SmbDrvI; C:\Windows\System32\drivers\Smb_driver_Intel.sys [34544 2013-07-26] (Synaptics Incorporated -> Synaptics Incorporated)
S3 ssudmdm; C:\Windows\system32\DRIVERS\ssudmdm.sys [166288 2017-05-18] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
S3 usbrndis6; C:\Windows\system32\DRIVERS\usb80236.sys [20992 2015-04-24] (Microsoft Windows -> Microsoft Corporation)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [46600 2017-02-10] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WDC_SAM; C:\Windows\System32\drivers\wdcsam64.sys [26880 2015-11-12] (WDKTestCert wdclab,130885612892544312 -> Western Digital Technologies, Inc.)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [274776 2017-01-12] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [117592 2017-01-12] (Microsoft Windows -> Microsoft Corporation)
R3 WirelessButtonDriver; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [30384 2015-06-23] (Hewlett-Packard Company -> HP Inc.)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One month (created) ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2019-04-02 19:58 - 2019-04-02 20:02 - 000031179 _____ C:\Users\Annette\Desktop\FRST.txt
2019-04-02 19:50 - 2019-04-02 19:58 - 000000000 ____D C:\FRST
2019-04-02 18:25 - 2019-04-02 18:25 - 002434048 _____ (Farbar) C:\Users\Annette\Desktop\FRST64.exe
2019-04-01 21:31 - 2019-04-01 21:33 - 000000000 ____D C:\Users\Annette\Documents\NWSCLC
2019-03-31 23:19 - 2019-03-31 23:19 - 000002163 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth Pro.lnk
2019-03-31 23:19 - 2019-03-31 23:19 - 000002151 _____ C:\Users\Public\Desktop\Google Earth Pro.lnk
2019-03-31 23:19 - 2019-03-31 23:19 - 000000000 ____D C:\Program Files\Google
2019-03-31 22:43 - 2019-03-31 22:43 - 000002484 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive for Business.lnk
2019-03-31 22:43 - 2019-03-31 22:43 - 000002385 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk
2019-03-31 22:43 - 2019-03-31 22:43 - 000002177 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive for Business.lnk
2019-03-31 22:43 - 2019-03-31 22:43 - 000002177 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive for Business.lnk
2019-03-31 22:43 - 2019-03-31 22:43 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools
2019-03-31 22:43 - 2019-03-31 22:43 - 000000000 ____D C:\Program Files (x86)\Microsoft OneDrive
 
==================== One month (modified) ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2019-04-02 19:27 - 2018-04-14 00:12 - 000000572 _____ C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-1409944621-189731363-133459071-1005.job
2019-04-02 19:27 - 2018-04-14 00:11 - 000000000 ____D C:\Users\Annette\AppData\Local\GoToMeeting
2019-04-02 19:05 - 2013-08-22 10:20 - 000000000 ____D C:\Windows\CbsTemp
2019-04-02 18:43 - 2015-09-14 16:50 - 000003594 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1409944621-189731363-133459071-1005
2019-04-02 18:29 - 2018-12-22 12:09 - 000003182 _____ C:\Windows\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1409944621-189731363-133459071-1005
2019-04-02 18:29 - 2018-12-22 11:39 - 000002352 _____ C:\Users\Annette\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive for Business.lnk
2019-04-02 18:16 - 2015-11-17 17:45 - 000003942 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{3464BE36-788D-4EB3-890E-849F1DD7BE9F}
2019-04-02 18:12 - 2015-09-14 16:43 - 000000000 ____D C:\Users\Annette\AppData\Local\Packages
2019-04-01 21:10 - 2016-03-24 09:59 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2019-04-01 21:09 - 2018-04-14 00:12 - 000000668 _____ C:\Windows\Tasks\G2MUploadTask-S-1-5-21-1409944621-189731363-133459071-1005.job
2019-04-01 16:59 - 2015-01-23 04:11 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2019-04-01 16:57 - 2015-01-23 04:11 - 000000000 ____D C:\Program Files\Microsoft Silverlight
2019-04-01 16:57 - 2015-01-23 04:11 - 000000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2019-04-01 16:42 - 2015-09-14 16:49 - 000000000 __RDO C:\Users\Annette\OneDrive
2019-04-01 16:40 - 2014-11-19 18:48 - 000002251 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2019-04-01 16:33 - 2013-08-22 10:36 - 000000000 ____D C:\Windows\AppReadiness
2019-03-31 23:11 - 2014-11-19 18:47 - 000003330 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2019-03-31 23:11 - 2014-11-19 18:47 - 000003202 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2019-03-31 23:09 - 2018-04-14 00:12 - 000003676 _____ C:\Windows\System32\Tasks\G2MUploadTask-S-1-5-21-1409944621-189731363-133459071-1005
2019-03-31 23:09 - 2018-04-14 00:12 - 000003580 _____ C:\Windows\System32\Tasks\G2MUpdateTask-S-1-5-21-1409944621-189731363-133459071-1005
2019-03-31 22:46 - 2013-08-22 10:36 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2019-03-31 22:43 - 2017-04-01 17:27 - 000002399 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook.lnk
2019-03-31 22:43 - 2016-08-19 12:06 - 000002448 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype for Business.lnk
2019-03-31 22:43 - 2016-08-19 12:06 - 000002443 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk
2019-03-31 22:43 - 2016-08-19 12:06 - 000002442 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk
2019-03-31 22:43 - 2016-08-19 12:06 - 000002406 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access.lnk
2019-03-31 22:43 - 2016-08-19 12:06 - 000002405 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk
2019-03-31 22:43 - 2016-08-19 12:06 - 000002393 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher.lnk
2019-03-31 22:41 - 2016-08-19 12:06 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016 Tools
2019-03-31 22:40 - 2014-04-22 12:28 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2019-03-26 17:13 - 2013-08-22 08:36 - 000000000 ____D C:\Windows\Inf
2019-03-23 17:49 - 2014-09-09 21:21 - 000065536 _____ C:\Windows\system32\spu_storage.bin
 
Some files in TEMP:
====================
2018-10-15 19:07 - 2018-10-15 19:07 - 000006144 _____ () C:\Users\Annette\AppData\Local\Temp\73vkh5od.dll
2018-07-29 19:34 - 2018-03-09 16:20 - 001737592 _____ (Microsoft Corporation) C:\Users\Annette\AppData\Local\Temp\dllnt_dump.dll
2018-09-09 14:43 - 2018-09-09 14:43 - 000006144 _____ () C:\Users\Annette\AppData\Local\Temp\ejpo7arb.dll
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\dllhost.exe => File is digitally signed
C:\Windows\SysWOW64\dllhost.exe => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
LastRegBack: 2019-04-01 16:42
 
==================== End of FRST.txt ============================
 
 
 
 
 
Here is the Addition Notepad scan.
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 17.03.2019
Ran by [removed] (02-04-2019 20:16:09)
Running from C:\Users\[removed]\Desktop
Windows 8.1 (Update) (X64) (2014-11-19 21:48:55)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-1409944621-189731363-133459071-500 - Administrator - Disabled)
Annette (S-1-5-21-1409944621-189731363-133459071-1005 - Administrator - Enabled) => C:\Users\Annette
Guest (S-1-5-21-1409944621-189731363-133459071-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1409944621-189731363-133459071-1004 - Limited - Enabled)
Jacquelyn (S-1-5-21-1409944621-189731363-133459071-1002 - Administrator - Enabled) => C:\Users\Jacquelyn
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
4 Elements II (HKLM-x32\…\WTA-f594756d-cea3-422d-a8fc-ced5205c861a) (Version: 2.2.0.98 - WildTangent) Hidden
7-Zip 9.20 (x64 edition) (HKLM\…\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Adobe Acrobat Reader DC (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 19.010.20069 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.0 (HKLM-x32\…\Adobe Shockwave Player) (Version: 12.0.4.144 - Adobe Systems, Inc.)
Airport Mania (HKLM-x32\…\WTA-67a03dfc-1d66-47d3-bc08-9a960e05c1bc) (Version: 2.2.0.95 - WildTangent) Hidden
AMD Catalyst Install Manager (HKLM\…\{89D9FBD5-7D44-509B-D17D-71FF2B2E7BDD}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.)
Azkend 2: The World Beneath (HKLM-x32\…\WTA-d289ec68-1f25-4f2b-ba18-86a20a21bc62) (Version: 2.2.0.98 - WildTangent) Hidden
Bejeweled 3 (HKLM-x32\…\WTA-8c1524c4-154e-48c1-9d0e-de089ad24105) (Version: 2.2.0.98 - WildTangent) Hidden
Bonjour (HKLM\…\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Bounce Symphony (HKLM-x32\…\WTA-73552c2f-075c-4734-8305-d61cc64f6bff) (Version: 2.2.0.97 - WildTangent) Hidden
Build-a-lot (HKLM-x32\…\WTA-51d1343d-3d81-4ede-9006-04b2be370e43) (Version: 2.2.0.98 - WildTangent) Hidden
CenturyLink Installer (HKLM-x32\…\{C96FF998-45BD-411E-9253-B7F2660FE280}) (Version: 1.0 - CenturyLink, Inc.)
Cisco EAP-FAST Module (HKLM-x32\…\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM-x32\…\{AF312B06-5C5C-468E-89B3-BE6DE2645722}) (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM-x32\…\{0A4EF0E6-A912-4CDE-A7F3-6E56E7C13A2F}) (Version: 1.1.6 - Cisco Systems, Inc.)
Cradle Of Egypt Collector's Edition (HKLM-x32\…\WTA-7a3200ac-a8c8-4a24-8f9d-1322c5984d44) (Version: 2.2.0.110 - WildTangent) Hidden
Cradle of Rome 2 (HKLM-x32\…\WTA-41e95925-8de8-4966-8b6f-39104fca2c0d) (Version: 2.2.0.98 - WildTangent) Hidden
Crescendo Music Notation Editor (HKLM-x32\…\Crescendo) (Version: 1.86 - NCH Software)
Curse at Twilight (HKLM-x32\…\WTA-bb4b4313-02fb-4516-b909-11928a5a3ef3) (Version: 3.0.2.32 - WildTangent) Hidden
CyberLink LabelPrint (HKLM-x32\…\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.5.6902 - CyberLink Corp.)
CyberLink Media Suite 10 (HKLM-x32\…\InstallShield_{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}) (Version: 10.0.9.4928 - CyberLink Corp.)
Cyberlink PhotoDirector (HKLM-x32\…\InstallShield_{39337565-330E-4ab6-A9AE-AC81E0720B10}) (Version: 3.0.4.4824 - CyberLink Corp.)
CyberLink Power Media Player 12 (HKLM-x32\…\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}) (Version: 12.0.6.5104 - CyberLink Corp.)
CyberLink Power2Go 8 (HKLM-x32\…\InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}) (Version: 8.0.10.5422 - CyberLink Corp.)
CyberLink PowerDirector 10 (HKLM-x32\…\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.6.3912 - CyberLink Corp.)
CyberLink YouCam (HKLM-x32\…\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 5.0.5.4628 - CyberLink Corp.)
D3DX10 (HKLM-x32\…\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden
Delicious: Emily's Childhood Memories Premium Edition (HKLM-x32\…\WTA-410ced0d-8414-4126-a7e5-3a4c77c6d5e8) (Version: 3.0.2.32 - WildTangent) Hidden
DisableMSDefender (HKLM\…\{74FE39A0-FB76-47CD-84BA-91E2BBB17EF2}) (Version: 1.0.0 - Hewlett-Packard Company) Hidden
Driver Support (HKLM-x32\…\DriverSupport) (Version: 10.1.4.86 - PC Drivers HeadQuarters LP) <==== ATTENTION
Energy Star (HKLM-x32\…\{FC0ADA4D-8FA5-4452-8AFF-F0A0BAC97EF7}) (Version: 1.0.9 - Hewlett-Packard Company)
Facebook Gameroom 1.21.6697.19829 (HKLM-x32\…\{7BE2211B-F86C-40CA-A6CC-69564D9BD5E2}) (Version: 1.21.6697.19829 - Facebook)
Farkle 3.0.13.10 (HKLM-x32\…\Farkle_is1) (Version:  - )
Farm Frenzy (HKLM-x32\…\WTA-46580f9e-769c-43d3-9dea-256e9e1d09df) (Version: 2.2.0.98 - WildTangent) Hidden
Fishdom 3: Collector's Edition (HKLM-x32\…\WTA-0d9b177b-6105-4263-8018-fbf6cbf55172) (Version: 3.0.2.38 - WildTangent) Hidden
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 72.0.3626.109 - Google Inc.)
Google Earth Pro (HKLM\…\{70A0F34E-564B-4F93-ADD6-3BAEC6E44075}) (Version: 7.3.2.5776 - Google)
Google Update Helper (HKLM-x32\…\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.34.7 - Google LLC) Hidden
Google Update Helper (HKLM-x32\…\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden
GoTo Opener (HKLM-x32\…\{1F803452-798F-49FB-A5DD-9F527F7017E4}) (Version: 1.0.473 - LogMeIn, Inc.)
GoToMeeting 8.41.0.12127 (HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\GoToMeeting) (Version: 8.41.0.12127 - LogMeIn, Inc.)
Governor of Poker 2 Premium Edition (HKLM-x32\…\WTA-68d441b2-c8f5-499f-96e1-6c93f7dab728) (Version: 2.2.0.110 - WildTangent) Hidden
Grammarly (HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\GrammarlyForWindows) (Version: 1.5.29 - Grammarly)
Grammarly for Microsoft® Office Suite (HKLM\…\{32A50269-D356-4E0E-8726-2D4CE92E5308}) (Version: 6.6.116 - Grammarly) Hidden
Grammarly for Microsoft® Office Suite (HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\{57565765-d384-47b2-bf69-37839b58e08e}) (Version: 6.6.116 - Grammarly)
Hewlett-Packard ACLM.NET v1.2.2.3 (HKLM-x32\…\{6F340107-F9AA-47C6-B54C-C3A19F11553F}) (Version: 1.00.0000 - Hewlett-Packard Company) Hidden
HiSuite (HKLM-x32\…\Hi Suite) (Version: 8.0.1.300 - )
House of 1000 Doors: Family Secrets (HKLM-x32\…\WTA-7f58df73-a448-48ba-b304-fc490ae02a7f) (Version: 2.2.0.98 - WildTangent) Hidden
HP Documentation (HKLM-x32\…\{2C0CCB21-5ED3-4417-93D2-CC6BEEB3C7CF}) (Version: 1.1.0.0 - Hewlett-Packard)
HP Registration Service (HKLM\…\{D1E8F2D7-7794-4245-B286-87ED86C1893C}) (Version: 1.2.7127.4628 - Hewlett-Packard)
HP SimplePass (HKLM-x32\…\InstallShield_{314FAD12-F785-4471-BCE8-AB506642B9A1}) (Version: 8.00.54 - Hewlett-Packard)
HP Support Assistant (HKLM-x32\…\{79C54A05-F146-4EA0-8A70-D4EFE6181E52}) (Version: 8.6.18.11 - Hewlett-Packard Company)
HP Support Solutions Framework (HKLM-x32\…\{55065080-504F-43BB-BE00-36B80D7D39A5}) (Version: 12.9.24.3 - Hewlett-Packard Company)
HP System Event Utility (HKLM-x32\…\{57058272-92B0-4EFA-8FDD-ED3E5D689D37}) (Version: 1.4.32 - HP Inc.)
HP Utility Center (HKLM\…\{7A75E042-0D30-43C2-BD2A-684F4BE38FF7}) (Version: 2.3.1 - Hewlett-Packard Company)
HP Wireless Button Driver (HKLM-x32\…\{EFA01423-3857-468C-B7B6-F30AA08E50BC}) (Version: 1.1.5.1 - Hewlett-Packard)
Inst5675 (HKLM\…\{2DE6247C-7077-451B-8BA7-FFD1A2ABBB47}) (Version: 8.00.54 - Softex Inc.) Hidden
Inst5676 (HKLM\…\{878F6913-7421-4713-97F7-0A736EE2A188}) (Version: 8.00.54 - Softex Inc.) Hidden
Java 8 Update 25 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83218025F0}) (Version: 8.0.250 - Oracle Corporation)
Jewel Match 3 (HKLM-x32\…\WTA-85145c7b-75a2-48d4-89bb-4168d89f47a0) (Version: 2.2.0.98 - WildTangent) Hidden
John Deere Drive Green (HKLM-x32\…\WTA-537118ba-a615-4d10-8bd5-6a461f5e5fa4) (Version: 2.2.0.95 - WildTangent) Hidden
Kaspersky Secure Connection (HKLM-x32\…\{1CF84962-50F8-48CA-9082-B70F3A02C686}) (Version: 17.0.0.611 - Kaspersky Lab) Hidden
Kaspersky Secure Connection (HKLM-x32\…\InstallWIX_{1CF84962-50F8-48CA-9082-B70F3A02C686}) (Version: 17.0.0.611 - Kaspersky Lab)
King Oddball (HKLM-x32\…\WTA-23746366-401a-4c3e-8074-4cd5e7772844) (Version: 3.0.2.48 - WildTangent) Hidden
Luxor Evolved (HKLM-x32\…\WTA-c636fc44-f491-4f3b-9e82-fed402533998) (Version: 2.2.0.98 - WildTangent) Hidden
Mahjongg Dimensions Deluxe (HKLM-x32\…\WTA-f60926f8-4f6a-4a38-9df5-e2927ec1f7fc) (Version: 2.2.0.95 - WildTangent) Hidden
Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Microsoft Office 365 ProPlus - en-us (HKLM\…\O365ProPlusRetail - en-us) (Version: 16.0.10730.20264 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-0081-0409-0000-0000000FF1CE}) (Version: 14.0.6123.5001 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM-x32\…\Office14.PROPLUSR) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Professional Plus 2013 (HKLM-x32\…\Office15.PROPLUSR) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft OneDrive (HKU\.DEFAULT\…\OneDriveSetup.exe) (Version: 17.3.6743.1212 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\OneDriveSetup.exe) (Version: 19.033.0218.0011 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50918.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\…\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\…\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23026 (HKLM-x32\…\{e46eca4f-393b-40df-9f49-076faf788d83}) (Version: 14.0.23026.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Monopoly® (HKLM-x32\…\WTA-a2f0ba12-04c0-4194-af8a-79ed3a597c9d) (Version: 3.0.2.51 - WildTangent) Hidden
Movie Maker (HKLM-x32\…\{45898170-E68C-4F02-AA35-C2186BF347A3}) (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Movie Maker (HKLM-x32\…\{B39A6825-EA20-43EA-AB2D-A6BC0298D9A1}) (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Mystery P.I. - Curious Case of Counterfeit Cove (HKLM-x32\…\WTA-2b23e2e0-e38c-4d60-8e17-7ee68c32006b) (Version: 2.2.0.98 - WildTangent) Hidden
NCH Tone Generator (HKLM-x32\…\ToneGen) (Version: 3.26 - NCH Software)
Norton Online Backup (HKLM-x32\…\{1969BD50-331D-4B7A-8116-29A7DC6D45B4}) (Version: 2.8.0.44 - Symantec Corporation)
OEM Application Profile (HKLM-x32\…\{1D464EFF-EC8B-F225-2F74-F74143200DDF}) (Version: 1.00.0000 - Advanced Micro Devices, Inc.)
OEM Application Profile (HKLM-x32\…\{70D5F822-F4C4-33D9-7EEC-2A4AF4EA7BDC}) (Version: 1.00.0000 - Advanced Micro Devices, Inc.)
Office 16 Click-to-Run Extensibility Component (HKLM-x32\…\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.10730.20264 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\…\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.10730.20264 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\…\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.10730.20264 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM-x32\…\{90160000-008C-0409-0000-0000000FF1CE}) (Version: 16.0.10730.20264 - Microsoft Corporation) Hidden
Outils de vérification linguistique 2013 de Microsoft Office - Français (HKLM-x32\…\{90150000-001F-040C-0000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Peggle Nights (HKLM-x32\…\WTA-e36ab41b-84de-4891-b4ac-4c42415d828a) (Version: 2.2.0.98 - WildTangent) Hidden
Penguins! (HKLM-x32\…\WTA-9b6dc59b-5d81-4c6f-8733-82ae9078a7f8) (Version: 2.2.0.98 - WildTangent) Hidden
Pinger (HKLM-x32\…\{9B56B031-A6C0-4BB7-8F61-938548C1B759}) (Version: 1.4.0.1 - Pinger Inc.) Hidden
Pinger (HKLM-x32\…\Pinger 1.4.0.1) (Version: 1.4.0.1 - Pinger Inc.)
Plants vs. Zombies - Game of the Year (HKLM-x32\…\WTA-1624dfaa-74eb-4a04-b0d1-2816bc270b19) (Version: 2.2.0.98 - WildTangent) Hidden
Polar Bowler (HKLM-x32\…\WTA-bb0a5787-6371-4fdd-ac8a-5702d596c923) (Version: 2.2.0.97 - WildTangent) Hidden
Realtek Card Reader (HKLM-x32\…\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.3.9600.29080 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.32.508.2014 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7730 - Realtek Semiconductor Corp.)
REALTEK Wireless LAN Driver (HKLM-x32\…\{A5107464-AA9B-4177-8129-5FF2F42DD322}) (Version: 1.0.0.41 - REALTEK Semiconductor Corp.)
Roads of Rome 3 (HKLM-x32\…\WTA-24b516d7-0fa5-49af-b5f8-2b3dd95cd50d) (Version: 2.2.0.98 - WildTangent) Hidden
SecondLifeViewer (HKLM-x32\…\SecondLifeViewer) (Version: 5.0.3.324435 - Linden Research, Inc.)
Service Pack 1 for Microsoft Office 2013 (KB2850036) 32-Bit Edition (HKLM-x32\…\{91150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUSR_{7F6C4883-A18C-459A-82C1-A2F9403F2DA6}) (Version:  - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\…\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
swMSM (HKLM-x32\…\{612C34C7-5E90-47D8-9B5C-0F717DD82726}) (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synaptics Pointing Device Driver (HKLM\…\SynTPDeinstKey) (Version: 17.0.6.2 - Synaptics Incorporated)
Tales of Lagoona (HKLM-x32\…\WTA-61166e11-25af-458a-bdb6-58e3bdab6835) (Version: 2.2.0.110 - WildTangent) Hidden
TurboTax 2014 (HKLM-x32\…\TurboTax 2014) (Version: 2014.0 - Intuit, Inc)
Update for Skype for Business 2015 (KB4462135) 32-Bit Edition (HKLM-x32\…\{90150000-002A-0000-1000-0000000FF1CE}_Office15.PROPLUSR_{84A498A6-4C4D-4B31-8537-11E2ACA3C0A1}) (Version:  - Microsoft)
Update for Skype for Business 2015 (KB4462135) 32-Bit Edition (HKLM-x32\…\{90150000-012B-0409-0000-0000000FF1CE}_Office15.PROPLUSR_{84A498A6-4C4D-4B31-8537-11E2ACA3C0A1}) (Version:  - Microsoft)
Update for Skype for Business 2015 (KB4462135) 32-Bit Edition (HKLM-x32\…\{91150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUSR_{84A498A6-4C4D-4B31-8537-11E2ACA3C0A1}) (Version:  - Microsoft)
Update Installer for WildTangent Games App (HKLM-x32\…\{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App) (Version:  - WildTangent) Hidden
Vacation Quest™ - Australia (HKLM-x32\…\WTA-05973e5c-9595-40e3-910a-ba1b6178d68c) (Version: 3.0.2.32 - WildTangent) Hidden
Visual Studio 2012 x64 Redistributables (HKLM\…\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\…\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
WavePad Sound Editor (HKLM-x32\…\WavePad) (Version: 7.00 - NCH Software)
WhatsApp (HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\WhatsApp) (Version: 0.2.1455 - WhatsApp)
WildTangent Games (HKLM-x32\…\WildTangent wildgames Master Uninstall) (Version: 1.0.4.0 - WildTangent)
WildTangent Games App (HP Games) (HKLM-x32\…\{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-hp) (Version: 4.0.10.15 - WildTangent) Hidden
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 16.4.3508.0205 - Microsoft Corporation)
Youda Jewel Shop (HKLM-x32\…\WTA-9173cba2-bfe3-462a-8bbc-6e837f324d64) (Version: 3.0.2.32 - WildTangent) Hidden
Zoom (HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\ZoomUMX) (Version: 4.1 - Zoom Video Communications, Inc.)
Zulu DJ Software (HKLM-x32\…\Zulu) (Version: 3.70 - NCH Software)
Zuma's Revenge (HKLM-x32\…\WTA-11f72db7-03ee-4570-8cc1-e63492ed09eb) (Version: 2.2.0.98 - WildTangent) Hidden
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-1409944621-189731363-133459071-1005_Classes\CLSID\{162C6FB5-44D3-435B-903D-E613FA093FB5}\InprocServer32 -> C:\Users\Annette\AppData\Local\Microsoft\OneDrive\17.3.6998.0830\amd64\FileCoAuthLib64.dll => No File
CustomCLSID: HKU\S-1-5-21-1409944621-189731363-133459071-1005_Classes\CLSID\{2AD206F1-152C-4F9D-A24E-6F93FE7A4AFC}\InprocServer32 -> C:\Users\Annette\AppData\Local\Grammarly\Grammarly for Microsoft Office Suite\6.6.116\07470D8E98\GrammarlyShim64.dll (Grammarly, Inc. -> CompanyName)
CustomCLSID: HKU\S-1-5-21-1409944621-189731363-133459071-1005_Classes\CLSID\{4BE56754-B616-4998-B825-D16983AEE1B2}\InprocServer32 -> C:\Users\Annette\AppData\Local\Grammarly\Grammarly for Microsoft Office Suite\6.6.116\07470D8E98\Grammarly.AddIn.Connect.ActiveX.dll (Grammarly, Inc. -> Grammarly)
CustomCLSID: HKU\S-1-5-21-1409944621-189731363-133459071-1005_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309}\InprocServer32 -> C:\Users\Annette\AppData\Local\GoToMeeting\8625\G2MOutlookAddin64.dll => No File
CustomCLSID: HKU\S-1-5-21-1409944621-189731363-133459071-1005_Classes\CLSID\{D9AC5E73-BB10-467b-B884-AA1E475C51F5}\Shell\Open\Command -> C:\Program Files\Synaptics\SynTP\SynTPCpl.dll (Synaptics Incorporated -> Synaptics Incorporated)
ShellExecuteHooks: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [6671064 2013-12-19] (Microsoft Corporation -> Microsoft Corporation)
ShellExecuteHooks-x32: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [4171480 2013-12-19] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2010-11-18] (Igor Pavlov) [File not signed]
ContextMenuHandlers1: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} => C:\Program Files (x86)\Common Files\CyberLink\ShellExtComponent\CLVDShellExt.dll [2015-12-05] (CyberLink Corp. -> Cyberlink)
ContextMenuHandlers2: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} => C:\Program Files (x86)\Common Files\CyberLink\ShellExtComponent\CLVDShellExt.dll [2015-12-05] (CyberLink Corp. -> Cyberlink)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamext.dll [2016-03-10] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2010-11-18] (Igor Pavlov) [File not signed]
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\atiacm64.dll [2014-06-05] (Advanced Micro Devices, Inc.) [File not signed]
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamext.dll [2016-03-10] (Malwarebytes Corporation -> Malwarebytes)
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {10A0396E-4397-432D-A61A-B29936C98279} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe (Google Inc -> Google Inc.)
Task: {2FE82A44-7615-47C1-88DD-E0D568E5D0F2} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe
Task: {30B156EE-55FF-476A-A6A1-18BAEB408F18} - System32\Tasks\Microsoft\Office\OfficeOsfInstaller => C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\osfinstaller.exe (Microsoft Corporation -> Microsoft Corporation)
Task: {3165798A-F44B-4387-8B96-BD947DFDF94F} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe (Microsoft Corporation -> Microsoft Corporation)
Task: {3E898CDD-32F4-47D1-A2F4-BCF33E88AEBC} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe (Hewlett Packard -> HP Inc.)
Task: {422808BD-6F70-41BF-945D-E13AA06AE45A} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis Install => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe (HP Inc. -> HP Inc.)
Task: {468B13AD-B541-4A27-B004-9B018EEA3275} - System32\Tasks\Java Platform SE Auto Updater => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Oracle America, Inc. -> Oracle Corporation)
Task: {46BDC3CC-4E1E-4B04-A811-E3B1AC55C70F} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe (Microsoft Corporation -> Microsoft Corporation)
Task: {482C1111-09DA-40E1-9181-E344E242A1F2} - System32\Tasks\Driver Support-RTMRules => C:\Program Files (x86)\Driver Support\DriverSupport.exe (PC DRIVERS HEADQUARTERS I, INC -> PC Drivers Headquarters LP)
Task: {4BD0F4B2-4176-4FF7-9B67-38398F1F0A0D} - System32\Tasks\Driver Support => C:\Program Files (x86)\Driver Support\DriverSupport.exe (PC DRIVERS HEADQUARTERS I, INC -> PC Drivers Headquarters LP)
Task: {55DCE214-7F3F-463F-BECE-5A67E73B6324} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe (HP Inc. -> HP Inc.)
Task: {5B7B1C4A-9A07-4CAC-869E-5279651131BE} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe (Microsoft Corporation -> Microsoft Corporation)
Task: {61773716-6580-4DD8-8471-54CEE230A37C} - System32\Tasks\Driver Support-RTMScan => C:\Program Files (x86)\Driver Support\DriverSupport.exe (PC DRIVERS HEADQUARTERS I, INC -> PC Drivers Headquarters LP)
Task: {69088DFE-55C0-4D3D-9737-8FC62D63FF59} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe (Microsoft Corporation -> Microsoft Corporation)
Task: {69D3BA23-D578-4DE2-AFDE-D9EF27762CEC} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe (Google Inc -> Google Inc.)
Task: {6DF2025B-5532-4A83-A444-90131530C958} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe (Microsoft Corporation -> Microsoft Corporation)
Task: {73296B0F-F798-44FF-9230-D95559AAA3AF} - System32\Tasks\Driver Support-RTMUpdater => C:\Program Files (x86)\Driver Support\DriverSupport.exe (PC DRIVERS HEADQUARTERS I, INC -> PC Drivers Headquarters LP)
Task: {85D70D96-CB3D-4E56-AB0F-24B26C54D6BF} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe (HP Inc. -> HP Inc.)
Task: {8FF27663-5E4F-4513-97E8-6C1D0A5EDC7A} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe (Microsoft Corporation -> Microsoft Corporation)
Task: {ADD77FB5-6182-4E66-95C0-F40B0A9C225F} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe (Microsoft Corporation -> Microsoft Corporation)
Task: {B73A7C7B-CF7F-4A7E-A613-BFBB8A73789D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater - Resources => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe (Hewlett Packard -> HP Inc.)
Task: {BBE19C89-B07B-40EF-B2C4-D75E4FF38E60} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe (Microsoft Corporation -> Microsoft Corporation)
Task: {C2F915AC-97DE-4E69-9B7B-5443F08FFA8D} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
Task: {C45E956E-E070-4332-B57C-DF9D8B626B72} - System32\Tasks\Hewlett-Packard\HP Active Health\HP Active Health Scan (HPSA) => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.exe (HP Inc. -> HP Inc.)
Task: {CD39A3B5-0980-4947-BD6C-3D87425A7FCE} - System32\Tasks\Synaptics TouchPad Enhancements => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics Incorporated -> Synaptics Incorporated)
Task: {D04BBF70-03A8-413B-9CA3-5AC3314706E2} - System32\Tasks\G2MUpdateTask-S-1-5-21-1409944621-189731363-133459071-1005 => C:\Users\Annette\AppData\Local\GoToMeeting\12127\g2mupdate.exe (LogMeIn, Inc. -> LogMeIn, Inc.)
Task: {D0F920D8-40AD-4B42-9F6C-ADA01607FCCD} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Product Configurator => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\ProductConfig.exe (HP Inc. -> HP Inc.)
Task: {D5C531E1-84FD-4B99-81A6-F1B6E401FECD} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe (Microsoft Corporation -> Microsoft Corporation)
Task: {DCEFA36E-E149-4C02-99DB-E3F29CC3066E} - System32\Tasks\YCMServiceAgent => C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe (CyberLink Corp. -> CyberLink Corp.)
Task: {E6B7EE15-0DF8-473B-AA30-3C92EDE7356E} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe (HP Inc. -> HP Inc.)
Task: {EC860F0E-1C8E-4761-BA2C-9ACF03169D98} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe (HP Inc. -> HP Inc.)
Task: {EFE6E304-849C-4527-A6F6-903B564B9663} - System32\Tasks\G2MUploadTask-S-1-5-21-1409944621-189731363-133459071-1005 => C:\Users\Annette\AppData\Local\GoToMeeting\12127\g2mupload.exe (LogMeIn, Inc. -> LogMeIn, Inc.)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-1409944621-189731363-133459071-1005.job => C:\Users\Annette\AppData\Local\GoToMeeting\12127\g2mupdate.exe
Task: C:\Windows\Tasks\G2MUploadTask-S-1-5-21-1409944621-189731363-133459071-1005.job => C:\Users\Annette\AppData\Local\GoToMeeting\12127\g2mupload.exe
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
 
ShortcutWithArgument: C:\Users\Annette\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\69639df789022856\Person 1 - Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> –profile-directory="Profile 1"
 
==================== Loaded Modules (Whitelisted) ==============
 
2013-09-26 13:26 - 2013-09-26 13:26 - 000109568 _____ () [File not signed] C:\Program Files\Hewlett-Packard\SimplePass\cachesrvr.exe
2013-09-26 13:32 - 2013-09-26 13:32 - 000627200 _____ () [File not signed] C:\Program Files\Hewlett-Packard\SimplePass\cachedrv.dll
2013-09-26 13:39 - 2013-09-26 13:39 - 000208272 _____ (Softex Incorporated -> Hewlett-Packard) [File not signed] C:\Program Files\Hewlett-Packard\SimplePass\ldapdrv.dll
2013-09-26 13:28 - 2013-09-26 13:28 - 002540544 _____ () [File not signed] C:\Program Files\Hewlett-Packard\SimplePass\autheng.dll
2013-09-26 13:25 - 2013-09-26 13:25 - 000035328 _____ () [File not signed] C:\Program Files\Hewlett-Packard\SimplePass\ssplogon.dll
2013-09-26 13:27 - 2013-09-26 13:27 - 000690176 _____ (Hewlett-Packard) [File not signed] C:\Program Files\Hewlett-Packard\SimplePass\storeng.dll
2013-09-26 13:25 - 2013-09-26 13:25 - 000055296 _____ () [File not signed] C:\Program Files\Hewlett-Packard\SimplePass\RandomPass.dll
2013-09-26 13:32 - 2013-09-26 13:32 - 000087552 _____ (Softex Inc.) [File not signed] C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe
2013-09-26 13:28 - 2013-09-26 13:28 - 001097216 _____ (Hewlett-Packard) [File not signed] C:\Program Files\Hewlett-Packard\SimplePass\userdata.dll
2013-09-26 13:25 - 2013-09-26 13:25 - 000021504 _____ () [File not signed] C:\Program Files\Hewlett-Packard\SimplePass\cryptodll.dll
2013-09-26 13:39 - 2013-09-26 13:39 - 000599952 _____ (Softex Incorporated -> Hewlett-Packard) [File not signed] C:\Program Files\Hewlett-Packard\SimplePass\hdddrv.dll
2013-09-26 13:39 - 2013-09-26 13:39 - 000306064 _____ (Softex Incorporated -> ) [File not signed] C:\Program Files\Hewlett-Packard\SimplePass\mstrpwd.dll
2013-09-26 13:39 - 2013-09-26 13:39 - 001298832 _____ (Softex Incorporated -> ) [File not signed] C:\Program Files\Hewlett-Packard\SimplePass\GraphicalPwd.dll
2013-09-26 13:39 - 2013-09-26 13:39 - 002050960 _____ (Softex Incorporated -> Hewlett-Packard) [File not signed] C:\Program Files\Hewlett-Packard\SimplePass\Wbf.dll
2014-11-28 20:57 - 2013-04-02 00:19 - 000574464 _____ (Realtek Semiconductor Corp. ) [File not signed] C:\Windows\system32\Rtlihvs.dll
2014-06-05 22:42 - 2014-06-05 22:42 - 000140288 _____ () [File not signed] C:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe
2014-06-05 22:40 - 2014-06-05 22:40 - 000344064 _____ (Advanced Micro Devices, Inc.) [File not signed] C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
2014-06-05 22:40 - 2014-06-05 22:40 - 000127488 _____ () [File not signed] C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.Wlan.dll
2018-04-20 01:28 - 2018-04-20 01:28 - 000190784 _____ (Huawei Technologies Co., Ltd. -> ) [File not signed] C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe
2010-11-18 23:08 - 2010-11-18 23:08 - 000086016 _____ (Igor Pavlov) [File not signed] C:\Program Files\7-Zip\7-zip.dll
2013-09-26 13:34 - 2013-09-26 13:34 - 000064000 _____ () [File not signed] C:\Program Files\Hewlett-Packard\SimplePass\opvapp.exe
2013-09-26 13:38 - 2013-09-26 13:38 - 000764416 _____ (Hewlett-Packard) [File not signed] C:\Program Files\Hewlett-Packard\SimplePass\OpBHO64.dll
2014-09-09 21:32 - 2014-09-09 21:32 - 001093120 _____ (Microsoft Corporation) [File not signed] C:\Windows\WinSxS\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.6195_none_cbf5e994470a1a8f\MFC80U.DLL
2014-09-09 21:32 - 2014-09-09 21:32 - 000057344 _____ (Microsoft Corporation) [File not signed] C:\Windows\WinSxS\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.6195_none_03ce2c72205943d3\MFC80ENU.DLL
2015-03-19 14:48 - 2014-11-04 17:12 - 000200704 _____ (Microsoft) [File not signed] C:\Program Files (x86)\CenturyLink\Desktop\Qwest.Facilitator.Desktop.Agent.dll
2015-03-19 14:48 - 2014-11-04 17:11 - 000124416 _____ (CenturyLink Inc) [File not signed] C:\Program Files (x86)\CenturyLink\Desktop\CenturyLink.Desktop.Shared.dll
2015-03-19 14:48 - 2014-11-04 17:10 - 000180224 _____ ( ) [File not signed] C:\Program Files (x86)\CenturyLink\Desktop\ICSharpCode.SharpZipLib.dll
2018-12-04 14:50 - 2018-12-04 14:50 - 013651043 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\plug_ins\AcroForm.api
2018-12-04 14:50 - 2018-12-04 14:50 - 001347171 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\plug_ins\DigSig.api
2018-12-19 13:46 - 2018-12-19 13:46 - 007255651 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\plug_ins\PPKLite.api
2018-12-19 13:46 - 2018-12-19 13:46 - 002667619 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\plug_ins\EScript.api
2018-12-04 14:50 - 2018-12-04 14:50 - 007358563 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\plug_ins\Annots.api
2018-12-04 14:50 - 2018-12-04 14:50 - 000539747 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\plug_ins\Accessibility.api
2018-12-04 14:50 - 2018-12-04 14:50 - 000120931 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\plug_ins\IA32.api
2017-07-31 17:31 - 2017-07-31 17:31 - 000218624 _____ (RSA - The Security Division of EMC) [File not signed] C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\cryptocme.dll
2017-07-31 17:31 - 2017-07-31 17:31 - 000404480 _____ (RSA - The Security Division of EMC) [File not signed] C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\ccme_base.dll
2017-07-31 17:31 - 2017-07-31 17:31 - 000217600 _____ (RSA - The Security Division of EMC) [File not signed] C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\ccme_asym.dll
2017-07-31 17:31 - 2017-07-31 17:31 - 000504320 _____ (RSA - The Security Division of EMC) [File not signed] C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\ccme_ecc.dll
2017-07-31 17:31 - 2017-07-31 17:31 - 000379904 _____ (RSA - The Security Division of EMC) [File not signed] C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\ccme_base_non_fips.dll
2018-12-04 14:50 - 2018-12-04 14:50 - 000154211 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\plug_ins\Updater.api
2018-12-04 14:50 - 2018-12-04 14:50 - 000436835 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\plug_ins\PDDom.api
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE trusted site: HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\sharepoint.com -> hxxps://liveedurdale-files.sharepoint.com
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2013-08-22 08:25 - 2017-03-26 07:31 - 000000035 _____ C:\Windows\system32\drivers\etc\hosts
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path: C:\ProgramData\Oracle\Java\javapath;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files\Hewlett-Packard\SimplePass\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static
HKU\S-1-5-21-1409944621-189731363-133459071-1005\Control Panel\Desktop\\Wallpaper -> C:\Users\Annette\AppData\Roaming\Microsoft\Windows Photo Viewer\Windows Photo Viewer Wallpaper.jpg
DNS Servers: 75.75.75.75 - 75.75.76.76
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
If an entry is included in the fixlist, it will be removed.
 
HKLM\…\StartupApproved\Run: => "WindowsDefender"
HKLM\…\StartupApproved\Run32: => "YouCam Service"
HKLM\…\StartupApproved\Run32: => "SunJavaUpdateSched"
HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\StartupApproved\StartupFolder: => "Facebook Gameroom.lnk"
HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\StartupApproved\StartupFolder: => "Send to OneNote.lnk"
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{8D444952-FDB7-4FA5-901C-2462C1A37F99}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{AF3331A2-97B7-4313-AC3F-01DBA6B2C4FE}] => (Allow) LPort=2869
FirewallRules: [{150FBC6F-7AB5-4063-A0FB-EAC794994B93}] => (Allow) LPort=1900
FirewallRules: [{E39BD188-517F-4E06-97D0-5C42D5838F7E}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{F1948981-D69A-4ED2-8B17-9EFB0572B092}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{1402E48A-D816-4233-BC99-5439A3F6EDF5}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{8F1DB3E0-F2A7-42ED-91C7-FB0C90AC0852}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{BAB834BF-B807-4BB0-9914-BEB323488AC5}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe No File
FirewallRules: [{B4EC793D-9BBE-49AF-B2AF-C979A6135B15}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe No File
FirewallRules: [{711CA439-540E-400F-96B4-03755DDF5D83}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDirector10\PDR10.EXE (CyberLink Corp. -> CyberLink Corp.)
FirewallRules: [{A58108F8-825B-42DE-A8B0-03908ED19304}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe No File
FirewallRules: [{37B0BF0A-6A5B-4084-8C13-81F803B4FF7C}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe No File
FirewallRules: [{7281462C-F67B-4492-905D-4C4B321E723A}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\outlook.exe No File
FirewallRules: [{3B61AE1B-6103-477A-8F0D-4BAE585A8645}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPSOCKSVC.exe No File
FirewallRules: [TCP Query User{ACBD9CE9-88F2-4D23-8571-2E3C7E52DE4E}C:\program files (x86)\symantec\norton online backup\nobuclient.exe] => (Allow) C:\program files (x86)\symantec\norton online backup\nobuclient.exe (Symantec Corporation -> Symantec Corporation)
FirewallRules: [UDP Query User{02717F8A-ABC2-4205-9C6C-6DD19E9FB7DF}C:\program files (x86)\symantec\norton online backup\nobuclient.exe] => (Allow) C:\program files (x86)\symantec\norton online backup\nobuclient.exe (Symantec Corporation -> Symantec Corporation)
FirewallRules: [{D7AA5C63-D072-4153-8525-465AED706750}] => (Block) C:\program files (x86)\symantec\norton online backup\nobuclient.exe (Symantec Corporation -> Symantec Corporation)
FirewallRules: [{ED315B61-5CAE-477B-92D2-6F17C887849E}] => (Block) C:\program files (x86)\symantec\norton online backup\nobuclient.exe (Symantec Corporation -> Symantec Corporation)
FirewallRules: [{A42A81CB-243D-424B-A1D2-E662EB7A79B5}] => (Allow) C:\Program Files (x86)\Tango\Tango.exe No File
FirewallRules: [{7878122C-021D-4A6D-A0EB-284AB08B8B7E}] => (Allow) C:\Program Files (x86)\Tango\Tango.exe No File
FirewallRules: [TCP Query User{07B278D4-21FF-4CD2-A965-9B4438E8948A}C:\windows\system32\settingsynchost.exe] => (Block) C:\windows\system32\settingsynchost.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [UDP Query User{F79BB37B-92F4-474B-AD1B-CF9F1568C6B7}C:\windows\system32\settingsynchost.exe] => (Block) C:\windows\system32\settingsynchost.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [TCP Query User{FEEB000C-3527-4656-972D-BD975F70038B}C:\program files (x86)\tango\tango.exe] => (Block) C:\program files (x86)\tango\tango.exe No File
FirewallRules: [UDP Query User{AA76E5A5-6069-49D6-B878-FDBD28329607}C:\program files (x86)\tango\tango.exe] => (Block) C:\program files (x86)\tango\tango.exe No File
FirewallRules: [{5407BD3E-4D9F-460E-A8AA-0B2BD11CE977}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{C767F0A0-DC9F-430D-81AC-BA6847226F1E}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPDeviceDetection3.exe No File
FirewallRules: [{91BE1D7A-7F5E-4888-8C7B-7A4FB2833155}] => (Allow) C:\Users\Jacquelyn\AppData\Roaming\uTorrent\uTorrent.exe No File
FirewallRules: [{85591B93-2B77-4228-ACD3-3663078EA1C8}] => (Allow) C:\Users\Jacquelyn\AppData\Roaming\uTorrent\uTorrent.exe No File
FirewallRules: [{D228A34F-3AF9-41F6-AA7B-3579CF041A48}] => (Allow) C:\Users\Jacquelyn\AppData\Roaming\uTorrent\uTorrent.exe No File
FirewallRules: [{BD1FD5D4-E5B0-44EF-A5F2-0CC6D6F8A3E3}] => (Allow) C:\Users\Jacquelyn\AppData\Roaming\uTorrent\uTorrent.exe No File
FirewallRules: [TCP Query User{DF2CC86E-9A5F-4831-B378-C0A56490E11E}C:\program files (x86)\tams11\games\farkle\farkle.exe] => (Allow) C:\program files (x86)\tams11\games\farkle\farkle.exe (Tams11 Software) [File not signed]
FirewallRules: [UDP Query User{BEB80554-9B9D-4AB0-90E7-0640D3A57881}C:\program files (x86)\tams11\games\farkle\farkle.exe] => (Allow) C:\program files (x86)\tams11\games\farkle\farkle.exe (Tams11 Software) [File not signed]
FirewallRules: [TCP Query User{136FA891-6E6C-483B-8803-A3420AA28CD3}C:\program files (x86)\tams11\games\farkle\farkle.exe] => (Allow) C:\program files (x86)\tams11\games\farkle\farkle.exe (Tams11 Software) [File not signed]
FirewallRules: [UDP Query User{11852EA3-54FD-4B1C-96D7-470540C49779}C:\program files (x86)\tams11\games\farkle\farkle.exe] => (Allow) C:\program files (x86)\tams11\games\farkle\farkle.exe (Tams11 Software) [File not signed]
FirewallRules: [{9830404C-9584-4B5A-AAA7-37464D53161D}] => (Allow) C:\Users\Jacquelyn\AppData\Local\Maelstrom\Application\chrome.native.torrent.exe No File
FirewallRules: [{5BCD7EEB-5882-4C2B-8864-78E37C461F11}] => (Allow) C:\Users\Jacquelyn\AppData\Local\Maelstrom\Application\chrome.native.torrent.exe No File
FirewallRules: [{D1E14E70-55FD-433A-BA10-0FDA73C5FA47}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{702D7745-DB5D-4710-8D92-015A472B9C96}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{CB1CDFB6-8E46-4267-A529-C2D1099F4180}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{0CDC5D99-44C4-49B6-8130-528ED1F07E26}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{83F18E26-E83F-4F9C-A56D-8B5D7A93C367}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{BD161ADE-0A7C-44D3-8915-BB5980B4305B}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{A6A9097C-7008-48A2-AD29-13120F59BAAF}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{7F39D004-385E-48B2-9AC7-02CFC9CB9DF9}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{4767A3CC-2571-4160-8DAD-E9C5D341B5A2}] => (Allow) C:\Users\Jacquelyn\AppData\Roaming\uTorrent\uTorrent.exe No File
FirewallRules: [{188AD522-CA2C-4096-B0C6-73A7377F1EDC}] => (Allow) C:\Users\Jacquelyn\AppData\Roaming\uTorrent\uTorrent.exe No File
FirewallRules: [{3C9E1994-A54A-4741-9505-6142A9097317}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe No File
FirewallRules: [{B3EFC034-FD60-4DDF-B0F1-5837E7FA5375}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe No File
FirewallRules: [{F71E818A-A294-41B8-BD37-D13C81FA5F53}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe No File
FirewallRules: [{6B914922-3E76-4FEC-A515-4105D6FDC28F}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe No File
FirewallRules: [{F5E466D7-9CCD-4E00-B99F-B4B6D6F4D8D7}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{6C701C59-B17B-486B-9D50-93844C0B482F}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{FD5590CC-017D-44AE-86A9-00E3FE28FB6D}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdater.exe (Intuit, Inc. -> Intuit Inc.)
FirewallRules: [{C66BD5C9-1AB8-46C3-BC95-4795126CAECB}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe (Intuit, Inc. -> Intuit Inc.)
FirewallRules: [{071AC728-7D57-4B67-BAD1-F2BF4D1009DC}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe (Intuit, Inc. -> Intuit Inc.)
FirewallRules: [{75E91A46-1BBE-4E2D-A34A-3E22273BBB32}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe (Intuit, Inc. -> Intuit Inc.)
FirewallRules: [{B4F8DCE1-4FF7-4C1F-BC65-B49B02A489B3}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe (Intuit, Inc. -> Intuit Inc.)
FirewallRules: [{C3F65FC8-FCC0-4EDC-841B-E344B116F68B}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe (Intuit, Inc. -> Intuit Inc.)
FirewallRules: [{F92EFA33-3CBA-4D48-A37F-EAA5C3B85EAC}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12.exe (CyberLink Corp. -> CyberLink Corp.)
FirewallRules: [{7F0BE56E-50CB-4D65-BA66-69B59B4E5837}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMR\PowerDVD12DMREngine.exe No File
FirewallRules: [{5BDC7800-C619-4DAF-9158-04EC99DFB02E}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe (CyberLink Corp. -> CyberLink)
FirewallRules: [{BD129EA8-910D-4761-95EF-F4BD429148F1}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12Agent.exe No File
FirewallRules: [{1FA56378-6A82-4A35-99DE-8725DADA7EE5}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12ML.exe (CyberLink Corp. -> CyberLink Corp.)
FirewallRules: [{B5A22037-BC5A-4720-A169-8A51A0B6DD94}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Movie\PowerDVD.exe (CyberLink Corp. -> CyberLink Corp.)
FirewallRules: [TCP Query User{B628FD1B-686E-4D16-9BD7-3D9B41C5AF98}C:\program files (x86)\secondlifeviewer\slvoice.exe] => (Allow) C:\program files (x86)\secondlifeviewer\slvoice.exe (Mercer Road Corp -> Vivox Inc.)
FirewallRules: [UDP Query User{FAB3A586-55FD-47A4-B4D2-14B68F8DBD70}C:\program files (x86)\secondlifeviewer\slvoice.exe] => (Allow) C:\program files (x86)\secondlifeviewer\slvoice.exe (Mercer Road Corp -> Vivox Inc.)
FirewallRules: [TCP Query User{3C2FA513-AA5A-4427-AEAD-A957A609EA28}C:\windows\system32\settingsynchost.exe] => (Block) C:\windows\system32\settingsynchost.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [UDP Query User{EE6ADDC5-C232-4D80-A82B-0308C9010AD3}C:\windows\system32\settingsynchost.exe] => (Block) C:\windows\system32\settingsynchost.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{7555495A-4293-4DF5-B232-FE35A7213725}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{07950D66-E207-4F23-8ACA-522AF8E2B3F4}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{728D85F5-8702-4EE2-8B37-EEB1BAFE106B}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc -> Google Inc.)
 
==================== Restore Points =========================
 
Could not list restore points
Check "winmgmt" service or repair WMI.
 
 
==================== Faulty Device Manager Devices =============
 
Could not list Devices. Check "winmgmt" service or repair WMI.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (04/02/2019 07:45:20 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program LiveComm.exe version 17.5.9600.22013 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
 
Process ID: 1464
 
Start Time: 01d4e9b5c9dcc8b1
 
Termination Time: 4294967295
 
Application Path: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.22013_x64__8wekyb3d8bbwe\LiveComm.exe
 
Report Id: bdb04b64-55a9-11e9-8329-3863bb8eae0e
 
Faulting package full name: microsoft.windowscommunicationsapps_17.5.9600.22013_x64__8wekyb3d8bbwe
 
Faulting package-relative application ID: ppleae38af2e007f4358a809ac99a64a67c1
 
Error: (04/02/2019 07:06:00 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1578
 
Error: (04/02/2019 07:06:00 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 1578
 
Error: (04/02/2019 07:06:00 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
 
Error: (04/02/2019 06:54:47 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1609
 
Error: (04/02/2019 06:54:47 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 1609
 
Error: (04/02/2019 06:54:47 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
 
Error: (04/02/2019 06:33:19 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1734
 
 
System errors:
=============
Error: (04/01/2019 09:14:52 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80246013: Security Update for Microsoft Outlook 2010 (KB4461623) 32-Bit Edition.
 
Error: (04/01/2019 09:12:59 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80246013: Security Update for Microsoft Word 2013 (KB4461594) 32-Bit Edition.
 
Error: (04/01/2019 04:59:42 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80246013: Security Update for Microsoft Word 2010 (KB4461625) 32-Bit Edition.
 
Error: (03/31/2019 10:34:12 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80248007: Definition Update for Windows Defender Antivirus - KB2267602 (Definition 1.291.400.0).
 
Error: (03/26/2019 05:11:28 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the BITS service.
 
Error: (03/02/2019 08:59:31 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80070643: Definition Update for Windows Defender Antivirus - KB2267602 (Definition 1.289.277.0).
 
Error: (03/02/2019 08:39:02 AM) (Source: DCOM) (EventID: 10010) (User: MRSJOHNSON)
Description: The server Microsoft.WindowsLive.Mail.AppXj3e9v0xw9sf8t58nqr15tqqb2yq4zsfg.mca did not register with DCOM within the required timeout.
 
Error: (02/19/2019 06:02:23 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80070643: Definition Update for Windows Defender Antivirus - KB2267602 (Definition 1.287.351.0).
 
 
Windows Defender:
===================================
Date: 2019-01-12 17:15:14.286
Description: 
Windows Defender scan has been stopped before completion.
Scan ID: {32CA5F6A-04D5-4C10-8E41-B44B4D92DE05}
Scan Type: Antimalware
Scan Parameters: Quick Scan
 
Date: 2018-12-02 16:19:47.117
Description: 
Windows Defender scan has been stopped before completion.
Scan ID: {5C06E621-3921-4166-AF87-CD81142175A7}
Scan Type: Antimalware
Scan Parameters: Quick Scan
 
Date: 2018-12-02 16:14:43.640
Description: 
Windows Defender scan has been stopped before completion.
Scan ID: {A56B7156-00BE-46C0-A2D2-94CB0260FA3B}
Scan Type: Antimalware
Scan Parameters: Quick Scan
 
Date: 2018-12-02 16:09:39.714
Description: 
Windows Defender scan has been stopped before completion.
Scan ID: {746EE97B-90E1-4567-9CF3-8297A5700C48}
Scan Type: Antimalware
Scan Parameters: Quick Scan
 
Date: 2018-12-02 16:02:34.962
Description: 
Windows Defender scan has been stopped before completion.
Scan ID: {3CC0350D-9D68-40F4-8655-9599F4D9BB10}
Scan Type: Antimalware
Scan Parameters: Quick Scan
 
Date: 2019-04-02 19:42:00.230
Description: 
Windows Defender has encountered an error trying to update signatures.
New Signature Version: 
Previous Signature Version: 1.287.354.0
Update Source: Microsoft Malware Protection Center
Signature Type: AntiSpyware
Update Type: Full
Current Engine Version: 
Previous Engine Version: 1.1.15700.8
Error code: 0x80070652
Error description: Another installation is already in progress. Complete that installation before proceeding with this install. 
 
Date: 2019-04-02 19:42:00.230
Description: 
Windows Defender has encountered an error trying to update signatures.
New Signature Version: 
Previous Signature Version: 1.287.354.0
Update Source: Microsoft Malware Protection Center
Signature Type: AntiVirus
Update Type: Full
Current Engine Version: 
Previous Engine Version: 1.1.15700.8
Error code: 0x80070652
Error description: Another installation is already in progress. Complete that installation before proceeding with this install. 
 
Date: 2019-04-02 19:41:57.474
Description: 
Windows Defender has encountered an error trying to update signatures.
New Signature Version: 
Previous Signature Version: 
Update Source: User
Signature Type: 
Update Type: 
Current Engine Version: 
Previous Engine Version: 
Error code: 0x80070652
Error description: Another installation is already in progress. Complete that installation before proceeding with this install. 
 
Date: 2019-04-02 19:41:57.446
Description: 
Windows Defender has encountered an error trying to update signatures.
New Signature Version: 
Previous Signature Version: 
Update Source: User
Signature Type: 
Update Type: 
Current Engine Version: 
Previous Engine Version: 
Error code: 0x80070652
Error description: Another installation is already in progress. Complete that installation before proceeding with this install. 
 
Date: 2019-03-31 22:51:15.518
Description: 
Windows Defender has encountered an error trying to update signatures.
New Signature Version: 
Previous Signature Version: 1.283.3124.0
Update Source: Microsoft Malware Protection Center
Signature Type: AntiSpyware
Update Type: Full
Current Engine Version: 
Previous Engine Version: 1.1.15500.2
Error code: 0x800705b4
Error description: This operation returned because the timeout period expired. 
 
CodeIntegrity:
===================================
 
Date: 2019-01-12 14:59:46.564
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
 
Date: 2018-12-02 09:31:12.630
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
 
Date: 2018-11-13 18:04:54.318
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
 
Date: 2018-10-29 22:23:50.331
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
 
Date: 2018-10-11 19:40:37.723
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
 
Date: 2018-10-10 21:07:56.560
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
 
Date: 2018-10-07 11:02:00.759
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
 
Date: 2018-08-31 05:47:05.055
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
 
==================== Memory info =========================== 
 
Processor: AMD A6-5200 APU with Radeon(TM) HD Graphics 
Percentage of memory in use: 76%
Total physical RAM: 3554.01 MB
Available physical RAM: 838.23 MB
Total Virtual: 5986.01 MB
Available Virtual: 2556.68 MB
 
==================== Drives ================================
 
Drive c: (Windows) (Fixed) (Total:677.63 GB) (Free:378.53 GB) NTFS
Drive d: (RECOVERY) (Fixed) (Total:19.99 GB) (Free:1.28 GB) NTFS ==>[system with boot components (obtained from drive)]
 
\\?\Volume{f0d011a2-f7dc-43a9-8b7c-0875843c6a46}\ (WINRE) (Fixed) (Total:0.63 GB) (Free:0.36 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 698.6 GB) (Disk ID: A9A16C4F)
 
Partition: GPT.
 
==================== End of Addition.txt ============================
A couple of items to remove from your add/remove programs list

Driver Support (HKLM-x32\…\DriverSupport) (Version: 10.1.4.86 - PC Drivers HeadQuarters LP) <==== ATTENTION
Java 8 Update 25 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83218025F0}) (Version: 8.0.250 - Oracle Corporation

~~~~~~~~~~~~~~~~~`


Start Farbar Recovery Scan Tool with Administrator privileges
(Right click on the FRST icon and select Run as administrator)

highlight on the text below and select Copy.
beginning with Start:: and finishing with End::
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Highlight the entire content of the quote box below and select Copy.

 

Start::
CloseProcesses:
CreateRestorePoint:
C:\Program Files (x86)\Driver Support\svc\DriverSupportAOsvc.exe
C:\Program Files (x86)\Driver Support\svc\DriverSupportAO.exe
BootExecute: autocheck autochk /r \??\Z:autocheck autochk *
BHO: No Name -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> No File
BHO-x32: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll [2014-12-01] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll [2014-12-01] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll [2014-12-01] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll [2014-12-01] (Oracle America, Inc. -> Oracle Corporation)
CHR HomePage: Profile 1 -> mysearch.avg.com
2018-10-15 19:07 - 2018-10-15 19:07 - 000006144 _____ () C:\Users\Annette\AppData\Local\Temp\73vkh5od.dll
2018-07-29 19:34 - 2018-03-09 16:20 - 001737592 _____ (Microsoft Corporation) C:\Users\Annette\AppData\Local\Temp\dllnt_dump.dll
2018-09-09 14:43 - 2018-09-09 14:43 - 000006144 _____ () C:\Users\Annette\AppData\Local\Temp\ejpo7arb.dll
CustomCLSID: HKU\S-1-5-21-1409944621-189731363-133459071-1005_Classes\CLSID\{162C6FB5-44D3-435B-903D-E613FA093FB5}\InprocServer32 -> C:\Users\Annette\AppData\Local\Microsoft\OneDrive\17.3.6998.0830\amd64\FileCoAuthLib64.dll => No File
CustomCLSID: HKU\S-1-5-21-1409944621-189731363-133459071-1005_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309}\InprocServer32 -> C:\Users\Annette\AppData\Local\GoToMeeting\8625\G2MOutlookAddin64.dll => No File
Task: {482C1111-09DA-40E1-9181-E344E242A1F2} - System32\Tasks\Driver Support-RTMRules => C:\Program Files (x86)\Driver Support\DriverSupport.exe (PC DRIVERS HEADQUARTERS I, INC -> PC Drivers Headquarters LP)
Task: {4BD0F4B2-4176-4FF7-9B67-38398F1F0A0D} - System32\Tasks\Driver Support => C:\Program Files (x86)\Driver Support\DriverSupport.exe (PC DRIVERS HEADQUARTERS I, INC -> PC Drivers Headquarters LP)
Task: {61773716-6580-4DD8-8471-54CEE230A37C} - System32\Tasks\Driver Support-RTMScan => C:\Program Files (x86)\Driver Support\DriverSupport.exe (PC DRIVERS HEADQUARTERS I, INC -> PC Drivers Headquarters LP)
Task: {73296B0F-F798-44FF-9230-D95559AAA3AF} - System32\Tasks\Driver Support-RTMUpdater => C:\Program Files (x86)\Driver Support\DriverSupport.exe (PC DRIVERS HEADQUARTERS I, INC -> PC Drivers Headquarters LP)
ShortcutWithArgument: C:\Users\Annette\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\69639df789022856\Person 1 - Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> –profile-directory="Profile 1"
FirewallRules: [{A42A81CB-243D-424B-A1D2-E662EB7A79B5}] => (Allow) C:\Program Files (x86)\Tango\Tango.exe No File
FirewallRules: [{7878122C-021D-4A6D-A0EB-284AB08B8B7E}] => (Allow) C:\Program Files (x86)\Tango\Tango.exe No File
FirewallRules: [TCP Query User{FEEB000C-3527-4656-972D-BD975F70038B}C:\program files (x86)\tango\tango.exe] => (Block) C:\program files (x86)\tango\tango.exe No File
FirewallRules: [UDP Query User{AA76E5A5-6069-49D6-B878-FDBD28329607}C:\program files (x86)\tango\tango.exe] => (Block) C:\program files (x86)\tango\tango.exe No File
FirewallRules: [{91BE1D7A-7F5E-4888-8C7B-7A4FB2833155}] => (Allow) C:\Users\Jacquelyn\AppData\Roaming\uTorrent\uTorrent.exe No File
FirewallRules: [{85591B93-2B77-4228-ACD3-3663078EA1C8}] => (Allow) C:\Users\Jacquelyn\AppData\Roaming\uTorrent\uTorrent.exe No File
FirewallRules: [{D228A34F-3AF9-41F6-AA7B-3579CF041A48}] => (Allow) C:\Users\Jacquelyn\AppData\Roaming\uTorrent\uTorrent.exe No File
FirewallRules: [{BD1FD5D4-E5B0-44EF-A5F2-0CC6D6F8A3E3}] => (Allow) C:\Users\Jacquelyn\AppData\Roaming\uTorrent\uTorrent.exe No File
FirewallRules: [{9830404C-9584-4B5A-AAA7-37464D53161D}] => (Allow) C:\Users\Jacquelyn\AppData\Local\Maelstrom\Application\chrome.native.torrent.exe No File
FirewallRules: [{5BCD7EEB-5882-4C2B-8864-78E37C461F11}] => (Allow) C:\Users\Jacquelyn\AppData\Local\Maelstrom\Application\chrome.native.torrent.exe No File
FirewallRules: [{4767A3CC-2571-4160-8DAD-E9C5D341B5A2}] => (Allow) C:\Users\Jacquelyn\AppData\Roaming\uTorrent\uTorrent.exe No File
FirewallRules: [{188AD522-CA2C-4096-B0C6-73A7377F1EDC}] => (Allow) C:\Users\Jacquelyn\AppData\Roaming\uTorrent\uTorrent.exe No File
FirewallRules: [{3C9E1994-A54A-4741-9505-6142A9097317}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe No File
FirewallRules: [{B3EFC034-FD60-4DDF-B0F1-5837E7FA5375}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe No File
FirewallRules: [{F71E818A-A294-41B8-BD37-D13C81FA5F53}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe No File
FirewallRules: [{6B914922-3E76-4FEC-A515-4105D6FDC28F}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe No File
C:\Windows\Temp\*.*
Emptytemp:
End::



Start FRST (FRST64) with Administrator privileges
Press the Fix button. FRST will process the lines copied above from the clipboard.
When finished, a log file Fixlog.txt will pop up and saved in the same location the tool was ran from.

Please copy and paste its contents in your next reply.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

[external image: zcMPezJ.png]AdwCleaner - Fix Mode
  • Download AdwCleaner and move it to your Desktop
  • Right-click on AdwCleaner.exe and select [external image: Spcusrh.png]Run as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users)
  • Accept the EULA (I accept), then click on Scan
  • Let the scan complete. Once it's done, make sure that every item listed in the different tabs is checked and click on the Clean & Repair button. This will kill all the active processes
  • Once the cleaning process is complete, AdwCleaner will ask to restart your computer, do it
  • After the restart, a log will open when logging in. Please copy/paste the content of that log in your next reply
~~~~~~~~~~~~~~~~~`
[external image: RQKuhw1.png]RogueKiller
  • Download the right version of RogueKiller for your Windows version (32 or 64-bit)
  • Once done, move the executable file to your Desktop, right-click on it and select [external image: Spcusrh.png]Run as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users)
  • Click on the Start Scan button in the right panel, which will bring you to another tab, and click on it again (this time it'll be in the bottom right corner)
  • Wait for the scan to complete
  • On completion, the results will be displayed
  • Check every single entry (threat found), and click on the Remove Selected button
  • On completion, the results will be displayed. Click on the Open Report button in the bottom left corner, followed by the Open TXT button (also in the bottom left corner)
  • This will open the report in Notepad. Copy/paste its content in your next reply
Please post these logs when finished.
Fix result of Farbar Recovery Scan Tool (x64) Version: 17.03.2019
Ran by [removed] (04-04-2019 21:59:26) Run:1
Running from C:\Users\[removed]\Desktop
[removed]
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
CloseProcesses:
CreateRestorePoint:
C:\Program Files (x86)\Driver Support\svc\DriverSupportAOsvc.exe
C:\Program Files (x86)\Driver Support\svc\DriverSupportAO.exe
BootExecute: autocheck autochk /r \??\Z:autocheck autochk *
BHO: No Name -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> No File
BHO-x32: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll [2014-12-01] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll [2014-12-01] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll [2014-12-01] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll [2014-12-01] (Oracle America, Inc. -> Oracle Corporation)
CHR HomePage: Profile 1 -> mysearch.avg.com
2018-10-15 19:07 - 2018-10-15 19:07 - 000006144 _____ () C:\Users\Annette\AppData\Local\Temp\73vkh5od.dll
2018-07-29 19:34 - 2018-03-09 16:20 - 001737592 _____ (Microsoft Corporation) C:\Users\Annette\AppData\Local\Temp\dllnt_dump.dll
2018-09-09 14:43 - 2018-09-09 14:43 - 000006144 _____ () C:\Users\Annette\AppData\Local\Temp\ejpo7arb.dll
CustomCLSID: HKU\S-1-5-21-1409944621-189731363-133459071-1005_Classes\CLSID\{162C6FB5-44D3-435B-903D-E613FA093FB5}\InprocServer32 -> C:\Users\Annette\AppData\Local\Microsoft\OneDrive\17.3.6998.0830\amd64\FileCoAuthLib64.dll => No File
CustomCLSID: HKU\S-1-5-21-1409944621-189731363-133459071-1005_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309}\InprocServer32 -> C:\Users\Annette\AppData\Local\GoToMeeting\8625\G2MOutlookAddin64.dll => No File
Task: {482C1111-09DA-40E1-9181-E344E242A1F2} - System32\Tasks\Driver Support-RTMRules => C:\Program Files (x86)\Driver Support\DriverSupport.exe (PC DRIVERS HEADQUARTERS I, INC -> PC Drivers Headquarters LP)
Task: {4BD0F4B2-4176-4FF7-9B67-38398F1F0A0D} - System32\Tasks\Driver Support => C:\Program Files (x86)\Driver Support\DriverSupport.exe (PC DRIVERS HEADQUARTERS I, INC -> PC Drivers Headquarters LP)
Task: {61773716-6580-4DD8-8471-54CEE230A37C} - System32\Tasks\Driver Support-RTMScan => C:\Program Files (x86)\Driver Support\DriverSupport.exe (PC DRIVERS HEADQUARTERS I, INC -> PC Drivers Headquarters LP)
Task: {73296B0F-F798-44FF-9230-D95559AAA3AF} - System32\Tasks\Driver Support-RTMUpdater => C:\Program Files (x86)\Driver Support\DriverSupport.exe (PC DRIVERS HEADQUARTERS I, INC -> PC Drivers Headquarters LP)
ShortcutWithArgument: C:\Users\Annette\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\69639df789022856\Person 1 - Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> –profile-directory="Profile 1"
FirewallRules: [{A42A81CB-243D-424B-A1D2-E662EB7A79B5}] => (Allow) C:\Program Files (x86)\Tango\Tango.exe No File
FirewallRules: [{7878122C-021D-4A6D-A0EB-284AB08B8B7E}] => (Allow) C:\Program Files (x86)\Tango\Tango.exe No File
FirewallRules: [TCP Query User{FEEB000C-3527-4656-972D-BD975F70038B}C:\program files (x86)\tango\tango.exe] => (Block) C:\program files (x86)\tango\tango.exe No File
FirewallRules: [UDP Query User{AA76E5A5-6069-49D6-B878-FDBD28329607}C:\program files (x86)\tango\tango.exe] => (Block) C:\program files (x86)\tango\tango.exe No File
FirewallRules: [{91BE1D7A-7F5E-4888-8C7B-7A4FB2833155}] => (Allow) C:\Users\Jacquelyn\AppData\Roaming\uTorrent\uTorrent.exe No File
FirewallRules: [{85591B93-2B77-4228-ACD3-3663078EA1C8}] => (Allow) C:\Users\Jacquelyn\AppData\Roaming\uTorrent\uTorrent.exe No File
FirewallRules: [{D228A34F-3AF9-41F6-AA7B-3579CF041A48}] => (Allow) C:\Users\Jacquelyn\AppData\Roaming\uTorrent\uTorrent.exe No File
FirewallRules: [{BD1FD5D4-E5B0-44EF-A5F2-0CC6D6F8A3E3}] => (Allow) C:\Users\Jacquelyn\AppData\Roaming\uTorrent\uTorrent.exe No File
FirewallRules: [{9830404C-9584-4B5A-AAA7-37464D53161D}] => (Allow) C:\Users\Jacquelyn\AppData\Local\Maelstrom\Application\chrome.native.torrent.exe No File
FirewallRules: [{5BCD7EEB-5882-4C2B-8864-78E37C461F11}] => (Allow) C:\Users\Jacquelyn\AppData\Local\Maelstrom\Application\chrome.native.torrent.exe No File
FirewallRules: [{4767A3CC-2571-4160-8DAD-E9C5D341B5A2}] => (Allow) C:\Users\Jacquelyn\AppData\Roaming\uTorrent\uTorrent.exe No File
FirewallRules: [{188AD522-CA2C-4096-B0C6-73A7377F1EDC}] => (Allow) C:\Users\Jacquelyn\AppData\Roaming\uTorrent\uTorrent.exe No File
FirewallRules: [{3C9E1994-A54A-4741-9505-6142A9097317}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe No File
FirewallRules: [{B3EFC034-FD60-4DDF-B0F1-5837E7FA5375}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe No File
FirewallRules: [{F71E818A-A294-41B8-BD37-D13C81FA5F53}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe No File
FirewallRules: [{6B914922-3E76-4FEC-A515-4105D6FDC28F}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe No File
C:\Windows\Temp\*.*
Emptytemp:
 
*****************
 
Processes closed successfully.
Restore point was successfully created.
C:\Program Files (x86)\Driver Support\svc\DriverSupportAOsvc.exe => moved successfully
C:\Program Files (x86)\Driver Support\svc\DriverSupportAO.exe => moved successfully
HKLM\System\CurrentControlSet\Control\Session Manager\\BootExecute => value restored successfully
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF} => removed successfully
HKLM\Software\Classes\CLSID\{B4F3A835-0E21-4959-BA22-42B3008E02FF} => removed successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} => removed successfully
HKLM\Software\Wow6432Node\Classes\CLSID\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} => removed successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9} => removed successfully
HKLM\Software\Wow6432Node\Classes\CLSID\{DBC80044-A445-435b-BC74-9C25C1C588A9} => removed successfully
"HKLM\Software\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll [2014-12-01] (Oracle America, Inc." => not found
C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll => moved successfully
"HKLM\Software\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll [2014-12-01] (Oracle America, Inc." => not found
C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll => moved successfully
"Chrome HomePage" => removed successfully
C:\Users\Annette\AppData\Local\Temp\73vkh5od.dll => moved successfully
C:\Users\Annette\AppData\Local\Temp\dllnt_dump.dll => moved successfully
C:\Users\Annette\AppData\Local\Temp\ejpo7arb.dll => moved successfully
HKU\S-1-5-21-1409944621-189731363-133459071-1005_Classes\CLSID\{162C6FB5-44D3-435B-903D-E613FA093FB5} => removed successfully
HKU\S-1-5-21-1409944621-189731363-133459071-1005_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309} => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{482C1111-09DA-40E1-9181-E344E242A1F2}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{482C1111-09DA-40E1-9181-E344E242A1F2}" => removed successfully
C:\Windows\System32\Tasks\Driver Support-RTMRules => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Support-RTMRules" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{4BD0F4B2-4176-4FF7-9B67-38398F1F0A0D}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4BD0F4B2-4176-4FF7-9B67-38398F1F0A0D}" => removed successfully
C:\Windows\System32\Tasks\Driver Support => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Support" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{61773716-6580-4DD8-8471-54CEE230A37C}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{61773716-6580-4DD8-8471-54CEE230A37C}" => removed successfully
C:\Windows\System32\Tasks\Driver Support-RTMScan => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Support-RTMScan" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{73296B0F-F798-44FF-9230-D95559AAA3AF}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{73296B0F-F798-44FF-9230-D95559AAA3AF}" => removed successfully
C:\Windows\System32\Tasks\Driver Support-RTMUpdater => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Support-RTMUpdater" => removed successfully
C:\Users\Annette\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\69639df789022856\Person 1 - Chrome.lnk => Shortcut argument removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{A42A81CB-243D-424B-A1D2-E662EB7A79B5}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{7878122C-021D-4A6D-A0EB-284AB08B8B7E}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{FEEB000C-3527-4656-972D-BD975F70038B}C:\program files (x86)\tango\tango.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{AA76E5A5-6069-49D6-B878-FDBD28329607}C:\program files (x86)\tango\tango.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{91BE1D7A-7F5E-4888-8C7B-7A4FB2833155}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{85591B93-2B77-4228-ACD3-3663078EA1C8}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{D228A34F-3AF9-41F6-AA7B-3579CF041A48}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{BD1FD5D4-E5B0-44EF-A5F2-0CC6D6F8A3E3}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{9830404C-9584-4B5A-AAA7-37464D53161D}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{5BCD7EEB-5882-4C2B-8864-78E37C461F11}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{4767A3CC-2571-4160-8DAD-E9C5D341B5A2}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{188AD522-CA2C-4096-B0C6-73A7377F1EDC}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{3C9E1994-A54A-4741-9505-6142A9097317}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{B3EFC034-FD60-4DDF-B0F1-5837E7FA5375}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{F71E818A-A294-41B8-BD37-D13C81FA5F53}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{6B914922-3E76-4FEC-A515-4105D6FDC28F}" => removed successfully
 
=========== "C:\Windows\Temp\*.*" ==========
 
C:\Windows\Temp\66c5f96e-9e7d-44e3-ba1d-b9f1b919b773.tmp => moved successfully
C:\Windows\Temp\72.0.3626.109_71.0.3578.98_chrome_updater.exe3f68caca => moved successfully
C:\Windows\Temp\ACLM_GeneratedProxy.cs => moved successfully
C:\Windows\Temp\AdobeARM.log => moved successfully
C:\Windows\Temp\AdobeARM_NotLocked.log => moved successfully
C:\Windows\Temp\api-ms-win-crt-convert-l1-1-0.dll.bak => moved successfully
C:\Windows\Temp\api-ms-win-crt-environment-l1-1-0.dll.bak => moved successfully
C:\Windows\Temp\api-ms-win-crt-filesystem-l1-1-0.dll.bak => moved successfully
C:\Windows\Temp\api-ms-win-crt-heap-l1-1-0.dll.bak => moved successfully
C:\Windows\Temp\api-ms-win-crt-locale-l1-1-0.dll.bak => moved successfully
C:\Windows\Temp\api-ms-win-crt-math-l1-1-0.dll.bak => moved successfully
C:\Windows\Temp\api-ms-win-crt-multibyte-l1-1-0.dll.bak => moved successfully
C:\Windows\Temp\api-ms-win-crt-runtime-l1-1-0.dll.bak => moved successfully
C:\Windows\Temp\api-ms-win-crt-stdio-l1-1-0.dll.bak => moved successfully
C:\Windows\Temp\api-ms-win-crt-string-l1-1-0.dll.bak => moved successfully
C:\Windows\Temp\api-ms-win-crt-time-l1-1-0.dll.bak => moved successfully
C:\Windows\Temp\api-ms-win-crt-utility-l1-1-0.dll.bak => moved successfully
C:\Windows\Temp\CFG1A7A.tmp => moved successfully
C:\Windows\Temp\CFG29A.tmp => moved successfully
C:\Windows\Temp\CFG2C8.tmp => moved successfully
C:\Windows\Temp\CFG3366.tmp => moved successfully
C:\Windows\Temp\CFG511F.tmp => moved successfully
C:\Windows\Temp\CFG7421.tmp => moved successfully
C:\Windows\Temp\CFGF309.tmp => moved successfully
C:\Windows\Temp\CFGF321.tmp => moved successfully
C:\Windows\Temp\CFGFA40.tmp => moved successfully
C:\Windows\Temp\chrome_installer.log => moved successfully
C:\Windows\Temp\da768001-92b3-4ddb-b221-f8080fc7e5ce.tmp => moved successfully
C:\Windows\Temp\dd_vcredist_amd64_20170721195041.log => moved successfully
C:\Windows\Temp\dd_vcredist_amd64_20170826000804.log => moved successfully
C:\Windows\Temp\dd_vcredist_amd64_20170826000804_000_vcRuntimeMinimum_x64.log => moved successfully
C:\Windows\Temp\dd_vcredist_amd64_20170826000804_001_vcRuntimeAdditional_x64.log => moved successfully
C:\Windows\Temp\dd_vcredist_amd64_20180514191952.log => moved successfully
C:\Windows\Temp\dd_vcredist_amd64_20180629195109.log => moved successfully
C:\Windows\Temp\dd_vcredist_amd64_20181123104159.log => moved successfully
C:\Windows\Temp\dd_vcredist_x86_20170721195002.log => moved successfully
C:\Windows\Temp\DMIA415.tmp => moved successfully
C:\Windows\Temp\Extract.exe => moved successfully
C:\Windows\Temp\f7a77139-3d54-4a44-a6dd-a908c305e652.tmp => moved successfully
C:\Windows\Temp\fwtsqmfile00.sqm => moved successfully
C:\Windows\Temp\fwtsqmfile01.sqm => moved successfully
C:\Windows\Temp\fwtsqmfile02.sqm => moved successfully
C:\Windows\Temp\fwtsqmfile03.sqm => moved successfully
C:\Windows\Temp\fwtsqmfile04.sqm => moved successfully
C:\Windows\Temp\fwtsqmfile05.sqm => moved successfully
C:\Windows\Temp\fwtsqmfile06.sqm => moved successfully
C:\Windows\Temp\fwtsqmfile07.sqm => moved successfully
C:\Windows\Temp\fwtsqmfile08.sqm => moved successfully
C:\Windows\Temp\fwtsqmfile09.sqm => moved successfully
C:\Windows\Temp\fwtsqmfile10.sqm => moved successfully
C:\Windows\Temp\fwtsqmfile11.sqm => moved successfully
C:\Windows\Temp\fwtsqmfile12.sqm => moved successfully
C:\Windows\Temp\FXSAPIDebugLogFile.txt => moved successfully
C:\Windows\Temp\FXSTIFFDebugLogFile.txt => moved successfully
C:\Windows\Temp\HealthCheckAC.xml => moved successfully
C:\Windows\Temp\MpCmdRun-B2-421CFC91-A93E-42AB-A35C-F06F127FCC44.lock => moved successfully
C:\Windows\Temp\MpCmdRun.log => moved successfully
C:\Windows\Temp\MpSigStub.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170326-0734.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170326-0750.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170326-0940.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170327-0736.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170327-2151.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170327-2152.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170327-2156.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170327-2159.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170328-1812.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170328-1813.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170328-1820.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170328-2124.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170330-2135.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170331-0738.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170331-0742.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170401-1727.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170401-1746.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170402-1240.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170402-1249.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170404-1801.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170404-1820.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170404-1822.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170404-1822a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170416-1011.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170502-1545.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170502-1545a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170502-1547.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170505-1050.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170505-1327.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170606-2121.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170606-2128.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170606-2131.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170606-2159.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170606-2200.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170606-2201.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170607-0722.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170612-1019.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170612-1019a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170612-1123.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170613-1158.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170613-1707.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170614-1047.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170615-1204.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170617-1321.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170617-1321a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170617-1322.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170617-1402.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170617-1403.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170617-1404.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170627-0952.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170627-1020.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170627-1022.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170627-1036.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170627-1037.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170627-1050.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170627-1130.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170628-2207.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170629-1541.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170708-1126.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170708-1141.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170708-1145.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170708-1217.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170708-1245.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170709-1105.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170709-1105a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170710-1703.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170711-0722.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170711-0723.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170712-0725.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170713-1143.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170713-1757.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170713-2248.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170713-2250.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170713-2318.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170713-2320.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170714-1852.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170715-0846.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170716-1653.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170716-1654.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170717-1513.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170718-1255.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170718-1259.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170719-0759.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170719-1233.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170719-1436.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170719-1438.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170719-1450.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170719-1451.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170719-1452.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170720-1838.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170721-0557.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170721-0557a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170721-0557b.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170722-1319.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170722-1752.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170722-2031.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170722-2101.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170722-2131.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170723-1801.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170723-1805.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170724-1251.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170725-1728.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170725-1728a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170726-2211.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170727-1430.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170728-1139.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170728-1143.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170729-0631.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170730-0708.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170730-0713.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170731-0748.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170802-2102.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170802-2111.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170803-2017.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170804-0714.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170804-0715.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170804-0716.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170804-0724.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170804-0725.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170805-2117.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170806-0637.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170806-0637a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170806-0637b.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170807-0742.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170808-0729.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170808-0730.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170809-1217.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170810-0748.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170811-0819.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170811-0821.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170812-0716.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170812-2058.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170812-2114.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170812-2130.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170812-2200.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170812-2230.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170813-0923.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170813-0923a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170814-0729.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170815-0719.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170815-0720.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170815-1219.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170815-1338.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170815-1411.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170815-1441.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170815-1511.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170816-1900.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170817-1934.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170818-0659.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170818-0659a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170818-1545.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170818-1603.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170818-1633.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170818-1703.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170819-0812.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170820-0837.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170820-0837a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170821-0912.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170822-0712.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170822-0713.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170823-0733.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170824-1008.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170825-0749.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170825-0750.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170826-0022.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170829-1500.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170829-1519.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170829-1537.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170829-1537a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170829-1547.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170829-1801.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170830-1458.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170901-0932.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170901-0941.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170902-1244.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170903-0435.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170903-0924.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170904-0705.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170905-1850.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170905-1854.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170906-1452.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170907-1728.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170908-1733.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170908-1735.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170910-0651.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170910-0652.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170911-1649.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170912-1856.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170912-1901.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170913-2047.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170914-0451.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170915-0712.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170915-0712a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170916-0201.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170916-0222.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170916-0252.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170916-0741.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170916-0754.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170916-0757.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170916-0840.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170916-0857.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170917-0948.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170917-0951.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170918-1705.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170918-1719.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170918-1944.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170918-1949.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170918-2014.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170918-2044.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170918-2100.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170918-2101.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170918-2102.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170919-1509.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170919-1509a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170919-1510.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170919-1518.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170919-1519.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170922-1831.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170922-2000.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170922-2000a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170922-2003.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170922-2029.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170922-2059.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170923-1904.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170924-0456.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170924-0456a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170924-0532.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170924-0548.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170924-0618.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170924-0648.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170926-1913.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170926-1928.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170926-1931.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170926-1933.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170926-2003.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170926-2037.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170928-1708.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170928-1723.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170928-1723a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170928-1753.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170929-1505.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170929-1516.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170929-1519.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170929-1521.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170929-1551.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170929-1621.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170930-1818.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170930-1828.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170930-1833.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170930-1903.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20170930-1933.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171001-0853.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171001-0853a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171002-1849.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171003-0644.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171005-1512.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171005-1523.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171005-1755.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171005-1825.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171005-2110.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171007-0612.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171007-0626.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171007-0626a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171007-0629.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171007-0659.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171007-0732.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171008-0622.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171008-0622a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171009-1933.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171009-1950.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171009-1950a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171009-2019.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171009-2049.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171010-1455.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171010-1459.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171011-2056.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171012-2218.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171013-1923.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171013-1923a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171014-0815.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171014-1624.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171014-1640.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171014-1710.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171015-0631.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171015-0642.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171015-0650.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171016-2044.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171016-2058.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171016-2100.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171016-2130.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171016-2200.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171017-0703.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171017-0704.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171017-1928.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171017-1944.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171017-2014.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171017-2044.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171018-0605.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171019-1007.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171019-1021.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171019-1024.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171019-1054.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171019-1124.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171020-1426.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171020-1427.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171020-1427a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171020-1438.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171020-1439.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171020-1439a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171021-1133.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171022-0934.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171022-0935.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171022-0938.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171022-0943.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171022-0944.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171023-1543.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171023-2113.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171023-2129.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171024-2116.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171024-2127.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171024-2131.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171024-2147.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171025-1735.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171026-1530.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171027-1914.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171027-1917.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171027-2144.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171028-1620.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171028-1640.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171028-1648.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171028-1716.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171028-1746.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171029-0901.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171029-0902.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171030-1815.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171030-1825.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171030-1834.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171030-1905.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171030-1934.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171103-0721.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171103-0722.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171104-0747.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171104-0801.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171104-0805.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171104-0835.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171104-0925.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171105-1841.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171105-1841a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171106-1510.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171107-2041.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171107-2041a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171108-1653.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171109-0610.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171110-1851.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171110-1852.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171111-1107.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171111-1411.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171111-1421.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171111-1441.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171111-1511.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171112-0629.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171112-0629a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171113-1954.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171113-1956.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171113-2012.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171113-2019.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171113-2045.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171113-2222.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171115-1941.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171115-1952.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171115-1952a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171115-2002.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171115-2028.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171116-1727.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171116-1739.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171119-1543.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171119-1547.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171119-1549.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171119-1602.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171119-1602a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171119-1603.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171119-1609.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171119-1609a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171119-1610.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171119-1611.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171125-1836.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171125-1849.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171125-1849a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171125-1850.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171125-1901.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171125-1902.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171125-1908.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171125-1910.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171125-1910a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171126-0911.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171127-1821.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171128-0706.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171130-2024.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171130-2041.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171201-0727.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171201-0727a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171201-1549.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171201-1603.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171201-1604.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171201-1604a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171202-1413.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171203-1208.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171203-1208a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171203-1208b.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171205-1500.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171205-1510.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171205-1513.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171205-1529.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171205-1559.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171205-1629.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171207-2300.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171208-1608.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171209-0721.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171209-0734.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171209-0752.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171209-0848.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171211-2145.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171211-2225.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171211-2226.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171211-2355.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171212-0025.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171212-0055.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171212-2104.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171212-2118.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171212-2118a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171212-2121.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171213-1115.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171213-1121.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171213-1141.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171214-2315.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171214-2325.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171214-2331.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171215-0001.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171217-0645.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171217-0655.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171217-0658.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171217-0702.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171217-0732.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171217-0802.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171221-0653.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171221-2202.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171221-2232.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171221-2311.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171223-2123.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171223-2124.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171223-2125.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171224-1604.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171224-1604a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171224-1604b.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171229-0902.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171229-0906.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171229-0906a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171229-0908.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171229-0910.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171229-0911.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171231-1149.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171231-1152.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171231-1152a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171231-1202.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171231-1203.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171231-1228.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171231-1244.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171231-1314.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20171231-1344.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180101-1454.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180102-0405.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180102-1940.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180103-1646.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180104-0745.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180104-2223.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180104-2239.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180104-2309.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180104-2339.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180105-1353.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180105-1353a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180106-0852.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180107-0952.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180107-1003.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180108-0728.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180109-0942.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180109-0942a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180110-1701.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180111-1003.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180112-0915.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180112-0928.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180112-0937.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180112-1730.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180112-1800.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180112-1830.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180113-1915.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180113-1925.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180113-1931.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180113-2001.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180113-2031.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180114-0936.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180114-0937.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180116-1027.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180116-1042.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180116-1042a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180116-1338.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180116-1408.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180116-1438.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180117-1027.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180117-1041.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180117-1043.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180117-2248.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180117-2318.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180119-0818.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180119-0821.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180119-0822.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180119-0838.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180119-0839.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180119-0840.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180120-1842.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180121-0559.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180121-0603.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180122-1105.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180122-1119.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180122-1141.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180122-1210.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180122-1433.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180123-0615.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180123-0615a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180123-0615b.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180124-2013.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180126-0546.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180126-0552.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180202-1002.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180202-1020.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180202-1029.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180202-1031.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180202-1037.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180203-2053.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180203-2109.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180203-2109a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180204-0801.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180204-0816.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180204-0824.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180204-0831.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180205-1354.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180206-2017.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180206-2018.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180207-2021.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180209-0006.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180209-0915.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180209-0915a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180209-2030.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180209-2047.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180209-2117.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180209-2147.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180210-1808.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180210-1822.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180210-1824.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180210-1854.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180210-1924.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180211-0733.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180211-0736.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180212-2030.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180214-1750.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180214-1902.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180214-1902a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180214-1909.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180214-1929.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180218-0820.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180218-0822.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180218-0825.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180218-0836.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180218-1651.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180218-1717.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180218-1747.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180218-1817.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180220-1741.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180220-1748.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180220-1749.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180220-1755.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180220-1756.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180220-1756a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180221-1826.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180222-0432.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180224-0709.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180224-1124.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180224-1125.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180227-1843.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180227-1853.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180303-0853.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180303-0900.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180304-1313.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180304-1313a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180305-0827.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180306-0535.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180306-1028.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180306-1859.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180306-1929.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180306-2001.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180307-1600.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180309-1917.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180309-1932.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180309-1934.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180309-2004.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180310-0547.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180310-0854.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180311-2237.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180311-2237a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180312-2140.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180312-2154.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180312-2155.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180312-2235.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180313-0648.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180313-1948.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180313-2001.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180313-2004.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180313-2034.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180313-2140.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180314-1853.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180314-1907.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180314-1929.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180314-2214.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180316-0806.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180316-0811.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180316-1933.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180316-1948.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180316-2018.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180316-2050.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180318-2036.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180318-2037.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180326-0834.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180326-0834a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180326-0835.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180327-2031.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180327-2031a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180327-2032.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180327-2033.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180329-2007.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180330-1310.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180330-1310a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180330-1310b.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180330-1311.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180330-1313.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180401-1450.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180401-1454.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180401-1507.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180401-1508.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180401-1509.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180401-1517.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180402-2030.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180402-2040.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180402-2100.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180405-0335.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180405-0349.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180405-0349a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180405-0351.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180407-0652.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180407-0702.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180408-1319.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180408-1320.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180408-1320a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180408-1327.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180408-1620.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180408-1636.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180408-1706.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180408-1737.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180409-0519.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180412-0931.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180412-0931a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180414-0005.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180414-0006.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180414-0831.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180415-1322.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180415-1323.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180415-1342.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180415-1415.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180415-1446.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180415-1513.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180416-0839.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180417-1835.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180417-1836.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180417-1842.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180418-1936.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180419-2031.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180420-1743.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180420-1744.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180421-0900.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180422-0901.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180422-0902.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180422-0902a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180425-1557.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180425-1557a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180425-1559.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180428-1625.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180428-1626.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180428-1626a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180428-1626b.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180428-1627.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180428-1628.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180429-1102.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180429-1103.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180429-1106.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180501-2128.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180501-2128a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180502-2107.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180503-2041.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180503-2147.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180505-0902.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180505-0913.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180505-0913a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180505-0926.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180505-0954.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180505-1024.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180509-1824.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180509-1824a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180514-1907.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180514-1911.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180517-0713.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180518-2041.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180518-2041a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180518-2042.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180518-2056.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180518-2057.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180518-2058.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180519-1819.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180519-1833.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180519-2246.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180519-2247.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180519-2316.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180519-2346.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180520-1342.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180520-1351.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180521-1931.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180522-0749.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180522-0753.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180524-0643.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180527-0832.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180527-0833.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180527-0851.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180527-0909.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180527-0939.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180527-1009.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180529-2040.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180529-2040a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180531-1810.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180601-1957.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180601-2004.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180601-2107.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180601-2123.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180601-2153.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180601-2256.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180603-0652.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180603-0656.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180604-1948.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180609-1340.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180609-1357.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180609-1359.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180609-1359a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180614-1248.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180614-1251.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180614-1308.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180614-1341.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180614-1345.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180614-1345a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180614-1407.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180615-2158.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180615-2158a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180619-0819.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180619-0823.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180619-2003.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180619-2021.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180619-2051.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180620-2322.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180620-2338.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180621-1837.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180623-1143.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180623-1144.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180623-1735.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180623-1737.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180623-2010.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180623-2010a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180623-2012.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180623-2012a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180623-2014.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180623-2014a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180624-0937.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180624-0937a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180624-0938.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180624-0943.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180624-1012.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180624-1042.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180625-0641.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180626-0727.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180626-0728.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180627-0626.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180629-1936.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180629-1941.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180715-1831.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180716-1830.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180718-1707.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180718-1709.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180718-1755.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180718-1828.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180718-1828a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180718-1829.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180718-1830.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180718-1947.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180718-1947a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180718-2019.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180718-2046.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180721-1020.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180721-1043.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180721-1246.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180721-1316.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180721-1346.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180722-0616.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180722-0620.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180724-2026.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180724-2031.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180727-0516.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180727-0522.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180727-0543.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180727-0612.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180727-0657.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180727-0711.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180728-0510.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180729-1911.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180729-1920.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180803-0315.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180803-0315a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180803-0347.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180803-0350.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180803-0401.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180803-0411.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180803-0418.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180803-0448.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180803-0518.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180803-1711.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180803-1713.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180803-1729.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180803-1836.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180803-1906.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180804-2129.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180805-1119.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180805-1119a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180806-1023.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180807-0847.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180807-0849.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180810-1109.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180810-1109a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180812-1158.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180812-1202.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180819-1907.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180819-1907a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180820-0908.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180825-2212.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180825-2212a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180825-2213.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180825-2229.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180825-2230.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180831-0258.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180831-0258a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180831-0301.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180831-0307.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180831-0308.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180831-0329.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180831-0330.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180831-0331.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180831-0332.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180831-0332a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180831-0754.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180831-0805.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180909-1210.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180909-1252.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180909-1252a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180909-1252b.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180910-2038.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180910-2038a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180910-2058.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180910-2106.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180910-2125.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180910-2155.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180912-0745.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180912-0745a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180923-1107.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180923-1111.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180923-1150.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180923-1150a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180923-1318.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180923-1319.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180923-1320.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180923-1324.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180930-1941.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180930-1945.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20180930-1945a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181007-0652.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181007-0700.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181007-0720.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181007-0748.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181007-0748a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181007-0751.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181007-0840.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181008-0606.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181010-2017.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181010-2022.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181010-2040.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181010-2041.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181010-2046.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181010-2126.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181010-2146.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181011-1909.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181011-1912.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181011-1926.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181011-1928.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181011-2220.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181014-1858.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181014-1858a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181015-1820.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181015-1918.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181016-1746.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181016-1747.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181016-1747a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181017-0520.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181017-0521.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181017-0522.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181029-1912.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181029-1917.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181029-1917a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181029-1935.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181030-1255.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181030-1300.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181031-1922.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181101-1550.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181102-0625.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181102-0634.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181105-1737.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181105-1743.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181106-1354.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181106-1355.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181112-0600.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181112-0749.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181112-0749a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181112-0807.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181112-0837.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181113-1813.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181120-2119.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181120-2119a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181120-2123.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181123-0524.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181123-0525.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181123-0526.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181123-0542.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181123-0545.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181123-0545a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181124-0601.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181125-0337.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181125-0814.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181129-1836.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181129-1839.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181202-0746.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181202-0801.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181202-0830.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181202-0834.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181202-0854.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181202-0938.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181202-0956.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181203-0906.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181204-1213.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181204-1217.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181208-2230.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181208-2233.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181222-0917.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181222-0947.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181222-0949.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181222-0951.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181222-1004.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181222-1005.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20181226-0855.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20190112-1414.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20190112-1419.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20190112-1432.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20190112-1432a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20190116-1851.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20190116-1851a.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20190123-2114.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20190128-2120.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20190128-2122.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20190128-2136.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20190128-2138.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20190219-1649.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20190219-1701.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20190219-1702.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20190302-0755.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20190331-2240.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20190331-2241.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20190331-2243.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20190331-2250.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20190331-2251.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20190401-1634.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20190401-1639.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20190401-1641.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20190402-1826.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20190402-1829.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20190404-2014.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20190404-2020.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20190404-2033.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20190404-2106.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20190404-2110.log => moved successfully
C:\Windows\Temp\MRSJOHNSON-20190404-2159.log => moved successfully
Could not move "C:\Windows\Temp\MRSJOHNSON-20190404-2159a.log" => Scheduled to move on reboot.
C:\Windows\Temp\MSIb9974.LOG => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(20170326073434734).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(20170327215101540).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(20170327215248634).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(2017032721565059C).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(201703272159036FC).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(201706270952284B8).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(201707081126187BC).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(2017071317572562C).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(20170722175229794).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(201708122114457A8).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(2017081512195077C).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(20170826002256718).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(20170829150034748).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(2017091602015071C).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(20170916074109720).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(20170918210033898).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(20170924053244768).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(20170929150543714).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(20170930181805704).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(201710091933346DC).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(20171014162415704).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(201710201438211074).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(201710232113246E0).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(201710281620526E8).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(201710301815206EC).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(20171104074754704).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(201711111107266F0).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(201711131954186F0).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(201711151941526D4).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(201711191609561C0).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(2017112518361476C).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(20171125185052710).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(201712051500126F4).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(20171211214504734).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(20171212210453724).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(20171214231515730).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(2017121706451575C).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(201712290908561914).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(20171231122838710).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(20180104222335748).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(20180112091536788).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(20180113191511768).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(20180116102726778).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(201801190838401CD8).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(2018020210022571C).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(20180203205352748).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(20180210180857710).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(20180214175027768).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(201802201755211484).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(20180306102834734).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(20180309191754704).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(201803272033071FBC).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(20180401145024720).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(20180401145432750).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(20180408162024744).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(2018042816264927A8).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(2018050321473572C).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(201805182056301A18).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(20180519181906758).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(20180601210727724).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(2018060913402674C).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(20180614124806760).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(201806231735442230).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(20180623201048774).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(20180623201057990).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(20180718182820764).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(20180721102042760).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(20180727054317734).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(20180803035037750).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(2018080317112874C).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(20180803171320734).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(201808200908507EC).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(20180909125259990).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(20180910203831744).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(2018092311072377C).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(20181007065204774).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(20181007070041714).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(20181010201801770).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(20181011190927740).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(2018101119121576C).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(2018101705204421B0).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(20181202083006750).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(201812220947572B84).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(20190112141920750).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(20190331224030EA0).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(201903312251451688).log => moved successfully
"C:\Windows\Temp\officeclicktorun.exe_streamserver(201904042159361F08).log" => not found
Could not move "C:\Windows\Temp\officeclicktorun.exe_streamserver(2019040421594317B8).log" => Scheduled to move on reboot.
C:\Windows\Temp\Silverlight0.log => moved successfully
C:\Windows\Temp\SilverlightMSI.log => moved successfully
C:\Windows\Temp\sp69615.exe => moved successfully
C:\Windows\Temp\sp71999.exe => moved successfully
C:\Windows\Temp\sp81404.exe => moved successfully
C:\Windows\Temp\sp87076.exe => moved successfully
C:\Windows\Temp\sp88257.exe => moved successfully
C:\Windows\Temp\sp91504.exe => moved successfully
C:\Windows\Temp\viometerHI7DQ.dat => moved successfully
C:\Windows\Temp\{00A5975D-1181-436A-8DB9-CA6AFB0E881F} - OProcSessId.dat => moved successfully
C:\Windows\Temp\{0441F8E5-E1BB-4C39-A433-76203DBB9AF2} - OProcSessId.dat => moved successfully
C:\Windows\Temp\{071B0DD6-F693-4317-97D3-6827EAF2924E} - OProcSessId.dat => moved successfully
C:\Windows\Temp\{09F4BFF5-1271-4AE0-BC97-F5F5CB826BBA} - OProcSessId.dat => moved successfully
C:\Windows\Temp\{0A48260A-4E38-4D4C-812D-E091D981FFBC} - OProcSessId.dat => moved successfully
C:\Windows\Temp\{10FD6781-90DF-42CE-969A-19EBB2F9ACEE} - OProcSessId.dat => moved successfully
C:\Windows\Temp\{133A4D1D-0D7C-46AD-8C17-BDD49EC1BB8B} - OProcSessId.dat => moved successfully
C:\Windows\Temp\{1E49DECE-54FD-4406-A360-12FFB8163DA7} - OProcSessId.dat => moved successfully
C:\Windows\Temp\{1F3E9B54-FE93-4943-A52D-44A9DAB88AC8} - OProcSessId.dat => moved successfully
C:\Windows\Temp\{22994F1F-3DD4-461B-8920-392F002D43AF} - OProcSessId.dat => moved successfully
C:\Windows\Temp\{257780C2-7ECE-40C8-BA0A-6A536B402C6D} - OProcSessId.dat => moved successfully
C:\Windows\Temp\{2EE1B31C-D594-4A88-9779-EE2B53C6DF50} - OProcSessId.dat => moved successfully
C:\Windows\Temp\{2FE83F4A-7336-4481-8694-2B6885F8618A} - OProcSessId.dat => moved successfully
C:\Windows\Temp\{30D9F7EE-90E9-48DF-BF9C-C8A5DB847842} - OProcSessId.dat => moved successfully
C:\Windows\Temp\{4E4F7F58-49F2-45ED-B4A6-27CA10062AF1} - OProcSessId.dat => moved successfully
C:\Windows\Temp\{514B2065-4BF2-4EC3-8257-A8D9D355B071} - OProcSessId.dat => moved successfully
C:\Windows\Temp\{57FC7C45-592F-4AD7-B3AF-D953B4C58979} - OProcSessId.dat => moved successfully
C:\Windows\Temp\{695241A6-1533-4126-8330-1AC193C62670} - OProcSessId.dat => moved successfully
C:\Windows\Temp\{6B863A99-8D2A-4C79-8DA6-6AB8AAC34DFC} - OProcSessId.dat => moved successfully
C:\Windows\Temp\{71426141-D50B-40F3-A8C4-2BCEAA6CA8B7} - OProcSessId.dat => moved successfully
C:\Windows\Temp\{93A274C4-988A-41EF-9BBA-E3B13D159121} - OProcSessId.dat => moved successfully
C:\Windows\Temp\{973F1EDB-1D9C-48DB-B360-9BAD51BE1183} - OProcSessId.dat => moved successfully
C:\Windows\Temp\{981E1137-B2B9-4298-A367-B70E4527CFC5} - OProcSessId.dat => moved successfully
C:\Windows\Temp\{9B8CEC91-918A-4BBE-99AD-F6E3F8ED9648} - OProcSessId.dat => moved successfully
C:\Windows\Temp\{A40430C6-BFD5-42AE-AA25-6C3FF9DA52E1} - OProcSessId.dat => moved successfully
C:\Windows\Temp\{A646C033-8D03-45A3-867F-74E9B380A966} - OProcSessId.dat => moved successfully
C:\Windows\Temp\{AD0DB133-8403-4854-AD79-D3253A1FE858} - OProcSessId.dat => moved successfully
C:\Windows\Temp\{B524013D-EC84-4904-BA17-0BA750AE9216} - OProcSessId.dat => moved successfully
C:\Windows\Temp\{BA7B7D8C-AC2D-40C6-AB87-29D1C7559804} - OProcSessId.dat => moved successfully
C:\Windows\Temp\{C253ECB7-25C8-49FD-A4C3-A5F3E8613427} - OProcSessId.dat => moved successfully
C:\Windows\Temp\{C49D2674-DAE8-423B-BEBA-3853EC9FFD04} - OProcSessId.dat => moved successfully
C:\Windows\Temp\{D28D6630-2195-4B05-8169-4C1037F4D3DC} - OProcSessId.dat => moved successfully
C:\Windows\Temp\{D402FFED-B665-4CC2-A6D2-E513BFA68FC7} - OProcSessId.dat => moved successfully
C:\Windows\Temp\{E455B4C1-8E46-4EE3-B46C-97CB37E35343} - OProcSessId.dat => moved successfully
C:\Windows\Temp\{F0327B98-BC35-4FCA-A735-A71B6278A421} - OProcSessId.dat => moved successfully
C:\Windows\Temp\{F58A0E40-1C00-4240-8204-E58A9CA98D8D} - OProcSessId.dat => moved successfully
C:\Windows\Temp\{FC494889-8743-46AF-9B0F-9609E3B5A58B} - OProcSessId.dat => moved successfully
 
========= End -> "C:\Windows\Temp\*.*" ========
 
 
=========== EmptyTemp: ==========
 
BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 20115991 B
Java, Flash, Steam htmlcache => 1206 B
Windows/system/drivers => 783883703 B
Edge => 0 B
Chrome => 788827457 B
Firefox => 0 B
Opera => 0 B
 
Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 128 B
LocalService => 0 B
NetworkService => 215797886 B
Jacquelyn => 31085455 B
Annette => 1561182474 B
 
RecycleBin => 1247158 B
EmptyTemp: => 3.2 GB temporary data Removed.
 
================================
 
Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 07-04-2019 00:18:58)
 
C:\Windows\Temp\MRSJOHNSON-20190404-2159a.log => Is moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(2019040421594317B8).log => Is moved successfully
 
==== End of Fixlog 00:18:58 ====
# ——————————-
# Malwarebytes AdwCleaner 7.3.0.0
# ——————————-
# Build:    04-04-2019
# Database: 2019-04-05.4 (Cloud)
# Support:  https://www.malwarebytes.com/support
#
# ——————————-
# Mode: Clean
# ——————————-
# Start:    04-07-2019
# Duration: 00:00:09
# OS:       Windows 8.1
# Cleaned:  9
# Failed:   0
 
 
***** [ Services ] *****
 
No malicious services cleaned.
 
***** [ Folders ] *****
 
Deleted       C:\ProgramData\UAB
 
***** [ Files ] *****
 
No malicious files cleaned.
 
***** [ DLL ] *****
 
No malicious DLLs cleaned.
 
***** [ WMI ] *****
 
No malicious WMI cleaned.
 
***** [ Shortcuts ] *****
 
No malicious shortcuts cleaned.
 
***** [ Tasks ] *****
 
No malicious tasks cleaned.
 
***** [ Registry ] *****
 
Deleted       HKCU\Software\ActiveOptimization
Deleted       HKLM\Software\Wow6432Node\ActiveOptimization
Deleted       HKU\.DEFAULT\Software\ActiveOptimization
Deleted       HKU\S-1-5-18\Software\ActiveOptimization
Deleted       HKU\S-1-5-19\Software\ActiveOptimization
Deleted       HKU\S-1-5-20\Software\ActiveOptimization
 
***** [ Chromium (and derivatives) ] *****
 
Deleted       AVG Web TuneUp
Deleted       Search Encrypt
 
***** [ Chromium URLs ] *****
 
No malicious Chromium URLs cleaned.
 
***** [ Firefox (and derivatives) ] *****
 
No malicious Firefox entries cleaned.
 
***** [ Firefox URLs ] *****
 
No malicious Firefox URLs cleaned.
 
 
*************************
 
[+] Delete Tracing Keys
[+] Reset Winsock
 
*************************
 
AdwCleaner[S00].txt - [1729 octets] - [07/04/2019 00:33:09]
 
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########
RogueKiller Anti-Malware V13.1.9.0 (x64) [Mar 27 2019] (Free) by Adlice Software
mail : https://adlice.com/contact/
Website : https://adlice.com/download/roguekiller/
Operating System : Windows 8.1 (6.3.9600) 64 bits
Started in : Normal mode
User : Annette [Administrator]
Started from : C:\Users\Annette\Desktop\RogueKiller_portable64.exe
Signatures : 20190326_132530, Driver : Loaded
Mode : Standard Scan, Delete – Date : 2019/04/07 01:31:10 (Duration : 00:34:37)
 
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Delete ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
[PUP.Gen0 (Potentially Malicious)] AVG Web TuneUp – chfdnecihphmhljaaejmgoiahnihplgn -> Deleted
[PUP.SearchEncrypt (Potentially Malicious)] Search Encrypt – oodblefojaocanejnikhhjcglbaelpbp -> Deleted
Your version of Malwarebytes Anti-Malware is outdated

Malwarebytes Anti-Malware version 2.2.1 it should be 3.0.5 or higher
Since this appears to be a free version of the tool let's delete the one you have and download another free install.

When installing it may ask if you want the premium version for a trial, this is fine it will revert to free version in 30 days.

Please download the Malwarebytes Anti-Malware setup file to your Desktop.

OR from this location Here
  • Open mbam-setup.x.x.xxxx.exe (x represents the version #) and follow the prompts to install the programme.
  • Windows Vista, Windows 7 , 8, 8.1 and 10 : Right click and select "Run as Administrator"
    [external image: MBAM3_zpsw0f8rn9n.jpg]

    Then click on the Scan tab and select Threat Scan and click on Start Scan button.
    If threats are detected, click the Apply Actions button. You will now be prompted to reboot. Click Yes.
    Upon completion of the scan (or after the reboot), click the Reports tab.
    Double-click the Scan Log.
    At the bottom click Export and choose Text file.
  • You can access the logs by going in the "Reports" tab, clicking on the latest "Scan" entry (the one with detections), then clicking on the "Export" button in the bottom-left corner and select "Copy to clipboard". After that, all you have to do is paste it here
    ~~~~~~~~~~~~~~~~~~~~~~

    [external image: G0tu5D9.png]Emsisoft Emergency Kit - Fix Mode
    Follow the instructions below to run a scan using the Emsisoft Emergency Kit.
    • Download the Emsisoft Emergency Kit and execute it. From there, click on the Install button to extract the program in the EEK folder;
    • Once the extraction is complete, the EEK folder will open. Right-click on [external image: G0tu5D9.png]start emergency kit scanner.exe and select [external image: Spcusrh.png]Run as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users);
    • EEK will suggest that you run an online update before using the program. Click on Yes to launch it.
    • After the update, click on Malware Scan under 2. Scan and accept to let EEK detect PUPs (click on Yes).
    • Once the scan is complete, make sure that every item in the list is checked, and click on the Quarantine selected button;
    • If it asks you for a reboot to delete some items, click on Ok to reboot automatically;
    • After the restart, open EEK again (in the C:\EEK folder);
    • This time, click on Logs;
    • From there, go under the Quarantine Log tab, and click on the Export button;
    • Save the log on your desktop, then open it, and copy/paste its content in your next reply;
    Please post these 2 logs when finished.

    Also, tell me how the computer is now.
Malwarebytes
www.malwarebytes.com
 
-Log Details-
Scan Date: 4/7/19
Scan Time: 10:44 PM
Log File: a12861bc-59b0-11e9-a9e0-00ff4f781b5c.json
 
-Software Information-
Version: 3.7.1.2839
Components Version: 1.0.563
Update Package Version: 1.0.10042
License: Trial
 
-System Information-
OS: Windows 8.1
CPU: x64
File System: NTFS
User: MRSJOHNSON\Annette
 
-Scan Summary-
Scan Type: Threat Scan
Scan Initiated By: Manual
Result: Completed
Objects Scanned: 286802
Threats Detected: 179
Threats Quarantined: 0
Time Elapsed: 10 min, 52 sec
 
-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Detect
PUM: Detect
 
-Scan Details-
Process: 0
(No malicious items detected)
 
Module: 0
(No malicious items detected)
 
Registry Key: 0
(No malicious items detected)
 
Registry Value: 5
PUP.Optional.Spigot.Generic, HKU\S-1-5-21-1409944621-189731363-133459071-1005\SOFTWARE\GOOGLE\CHROME\PREFERENCEMACS\Default\extensions.settings|odhkbaigkdgomaoipjcnnphjdlpnjjka, No Action By User, [217], [454579],1.0.10042
PUP.Optional.Spigot.Generic, HKU\S-1-5-21-1409944621-189731363-133459071-1005\SOFTWARE\GOOGLE\CHROME\PREFERENCEMACS\Profile 1\extensions.settings|eikdkoejhlpkgdeodpbpaigmbikhmbhn, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, HKU\S-1-5-21-1409944621-189731363-133459071-1005\SOFTWARE\GOOGLE\CHROME\PREFERENCEMACS\Profile 1\extensions.settings|mpiffdmfpioemhakbaapeeopdppjloec, No Action By User, [217], [575422],1.0.10042
PUP.Optional.SearchEncrypt.Generic, HKU\S-1-5-21-1409944621-189731363-133459071-1005\SOFTWARE\GOOGLE\CHROME\PREFERENCEMACS\Profile 1\extensions.settings|iiihmlfhnchcalmhhoilcamhpjcfafge, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, HKU\S-1-5-21-1409944621-189731363-133459071-1005\SOFTWARE\GOOGLE\CHROME\PREFERENCEMACS\Profile 1\extensions.settings|oodblefojaocanejnikhhjcglbaelpbp, No Action By User, [14754], [448980],1.0.10042
 
Registry Data: 0
(No malicious items detected)
 
Data Stream: 0
(No malicious items detected)
 
Folder: 52
PUP.Optional.Spigot.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Sync Extension Settings\odhkbaigkdgomaoipjcnnphjdlpnjjka, No Action By User, [217], [454579],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\odhkbaigkdgomaoipjcnnphjdlpnjjka\4.3_0\_locales\en, No Action By User, [217], [454579],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\odhkbaigkdgomaoipjcnnphjdlpnjjka\4.3_0\html\popup, No Action By User, [217], [454579],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\odhkbaigkdgomaoipjcnnphjdlpnjjka\4.3_0\_metadata, No Action By User, [217], [454579],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\odhkbaigkdgomaoipjcnnphjdlpnjjka\4.3_0\js\popup, No Action By User, [217], [454579],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\odhkbaigkdgomaoipjcnnphjdlpnjjka\4.3_0\_locales, No Action By User, [217], [454579],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\odhkbaigkdgomaoipjcnnphjdlpnjjka\4.3_0\newtab, No Action By User, [217], [454579],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\odhkbaigkdgomaoipjcnnphjdlpnjjka\4.3_0\html, No Action By User, [217], [454579],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\odhkbaigkdgomaoipjcnnphjdlpnjjka\4.3_0\css, No Action By User, [217], [454579],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\odhkbaigkdgomaoipjcnnphjdlpnjjka\4.3_0\js, No Action By User, [217], [454579],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\odhkbaigkdgomaoipjcnnphjdlpnjjka\4.3_0, No Action By User, [217], [454579],1.0.10042
PUP.Optional.Spigot.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\ODHKBAIGKDGOMAOIPJCNNPHJDLPNJJKA, No Action By User, [217], [454579],1.0.10042
PUP.Optional.Spigot.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Profile 1\Sync Extension Settings\eikdkoejhlpkgdeodpbpaigmbikhmbhn, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eikdkoejhlpkgdeodpbpaigmbikhmbhn\3.3_1\html\browserAction, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eikdkoejhlpkgdeodpbpaigmbikhmbhn\3.3_1\_locales\en, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eikdkoejhlpkgdeodpbpaigmbikhmbhn\3.3_1\html\popup, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eikdkoejhlpkgdeodpbpaigmbikhmbhn\3.3_1\_metadata, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eikdkoejhlpkgdeodpbpaigmbikhmbhn\3.3_1\js\popup, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eikdkoejhlpkgdeodpbpaigmbikhmbhn\3.3_1\_locales, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eikdkoejhlpkgdeodpbpaigmbikhmbhn\3.3_1\newtab, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eikdkoejhlpkgdeodpbpaigmbikhmbhn\3.3_1\html, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eikdkoejhlpkgdeodpbpaigmbikhmbhn\3.3_1\css, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eikdkoejhlpkgdeodpbpaigmbikhmbhn\3.3_1\js, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eikdkoejhlpkgdeodpbpaigmbikhmbhn\3.3_1, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\PROFILE 1\EXTENSIONS\EIKDKOEJHLPKGDEODPBPAIGMBIKHMBHN, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Profile 1\Sync Extension Settings\mpiffdmfpioemhakbaapeeopdppjloec, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mpiffdmfpioemhakbaapeeopdppjloec\2.1_0\html\browserAction, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mpiffdmfpioemhakbaapeeopdppjloec\2.1_0\_locales\en, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mpiffdmfpioemhakbaapeeopdppjloec\2.1_0\_metadata, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mpiffdmfpioemhakbaapeeopdppjloec\2.1_0\_locales, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mpiffdmfpioemhakbaapeeopdppjloec\2.1_0\newtab, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mpiffdmfpioemhakbaapeeopdppjloec\2.1_0\html, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mpiffdmfpioemhakbaapeeopdppjloec\2.1_0\css, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mpiffdmfpioemhakbaapeeopdppjloec\2.1_0\js, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mpiffdmfpioemhakbaapeeopdppjloec\2.1_0, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\PROFILE 1\EXTENSIONS\MPIFFDMFPIOEMHAKBAAPEEOPDPPJLOEC, No Action By User, [217], [575422],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Profile 1\Sync Extension Settings\iiihmlfhnchcalmhhoilcamhpjcfafge, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.4.0.8_1\_metadata, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.4.0.8_1\img\se, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.4.0.8_1\css, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.4.0.8_1\img, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.4.0.8_1\lib, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.4.0.8_1, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\PROFILE 1\EXTENSIONS\IIIHMLFHNCHCALMHHOILCAMHPJCFAFGE, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Profile 1\Sync Extension Settings\oodblefojaocanejnikhhjcglbaelpbp, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2_0\_metadata, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2_0\img\se, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2_0\css, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2_0\img, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2_0\lib, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2_0, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\PROFILE 1\EXTENSIONS\OODBLEFOJAOCANEJNIKHHJCGLBAELPBP, No Action By User, [14754], [448980],1.0.10042
 
File: 122
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\odhkbaigkdgomaoipjcnnphjdlpnjjka\000003.log, No Action By User, [217], [454579],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\odhkbaigkdgomaoipjcnnphjdlpnjjka\CURRENT, No Action By User, [217], [454579],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\odhkbaigkdgomaoipjcnnphjdlpnjjka\LOCK, No Action By User, [217], [454579],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\odhkbaigkdgomaoipjcnnphjdlpnjjka\LOG, No Action By User, [217], [454579],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\odhkbaigkdgomaoipjcnnphjdlpnjjka\MANIFEST-000001, No Action By User, [217], [454579],1.0.10042
PUP.Optional.Spigot.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Secure Preferences, No Action By User, [217], [454579],1.0.10042
PUP.Optional.Spigot.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Preferences, No Action By User, [217], [454579],1.0.10042
PUP.Optional.Spigot.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\ODHKBAIGKDGOMAOIPJCNNPHJDLPNJJKA\4.3_0\CHROMERESTORE.JS, No Action By User, [217], [454579],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\odhkbaigkdgomaoipjcnnphjdlpnjjka\4.3_0\css\description.css, No Action By User, [217], [454579],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\odhkbaigkdgomaoipjcnnphjdlpnjjka\4.3_0\css\popup.css, No Action By User, [217], [454579],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\odhkbaigkdgomaoipjcnnphjdlpnjjka\4.3_0\html\popup\description.html, No Action By User, [217], [454579],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\odhkbaigkdgomaoipjcnnphjdlpnjjka\4.3_0\html\popup\popup.html, No Action By User, [217], [454579],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\odhkbaigkdgomaoipjcnnphjdlpnjjka\4.3_0\js\popup\popup.js, No Action By User, [217], [454579],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\odhkbaigkdgomaoipjcnnphjdlpnjjka\4.3_0\js\userNewTab.js, No Action By User, [217], [454579],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\odhkbaigkdgomaoipjcnnphjdlpnjjka\4.3_0\newtab\quicktab.html, No Action By User, [217], [454579],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\odhkbaigkdgomaoipjcnnphjdlpnjjka\4.3_0\_locales\en\messages.json, No Action By User, [217], [454579],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\odhkbaigkdgomaoipjcnnphjdlpnjjka\4.3_0\_metadata\verified_contents.json, No Action By User, [217], [454579],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\odhkbaigkdgomaoipjcnnphjdlpnjjka\4.3_0\after.js, No Action By User, [217], [454579],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\odhkbaigkdgomaoipjcnnphjdlpnjjka\4.3_0\background.js, No Action By User, [217], [454579],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\odhkbaigkdgomaoipjcnnphjdlpnjjka\4.3_0\contentscript.js, No Action By User, [217], [454579],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\odhkbaigkdgomaoipjcnnphjdlpnjjka\4.3_0\icon.png, No Action By User, [217], [454579],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\odhkbaigkdgomaoipjcnnphjdlpnjjka\4.3_0\manifest.json, No Action By User, [217], [454579],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Sync Extension Settings\eikdkoejhlpkgdeodpbpaigmbikhmbhn\000003.log, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Sync Extension Settings\eikdkoejhlpkgdeodpbpaigmbikhmbhn\CURRENT, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Sync Extension Settings\eikdkoejhlpkgdeodpbpaigmbikhmbhn\LOCK, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Sync Extension Settings\eikdkoejhlpkgdeodpbpaigmbikhmbhn\LOG, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Sync Extension Settings\eikdkoejhlpkgdeodpbpaigmbikhmbhn\LOG.old, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Sync Extension Settings\eikdkoejhlpkgdeodpbpaigmbikhmbhn\MANIFEST-000001, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Profile 1\Secure Preferences, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Profile 1\Preferences, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Profile 1\Sync Data\SyncData.sqlite3, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\PROFILE 1\EXTENSIONS\EIKDKOEJHLPKGDEODPBPAIGMBIKHMBHN\3.3_1\BACKGROUND.JS, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eikdkoejhlpkgdeodpbpaigmbikhmbhn\3.3_1\css\browserAction.css, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eikdkoejhlpkgdeodpbpaigmbikhmbhn\3.3_1\css\description.css, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eikdkoejhlpkgdeodpbpaigmbikhmbhn\3.3_1\html\browserAction\browserAction.html, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eikdkoejhlpkgdeodpbpaigmbikhmbhn\3.3_1\html\browserAction\description.html, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eikdkoejhlpkgdeodpbpaigmbikhmbhn\3.3_1\js\userNewTab.js, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eikdkoejhlpkgdeodpbpaigmbikhmbhn\3.3_1\newtab\quicknewtabpage.html, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eikdkoejhlpkgdeodpbpaigmbikhmbhn\3.3_1\_locales\en\messages.json, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eikdkoejhlpkgdeodpbpaigmbikhmbhn\3.3_1\_metadata\verified_contents.json, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eikdkoejhlpkgdeodpbpaigmbikhmbhn\3.3_1\after.js, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eikdkoejhlpkgdeodpbpaigmbikhmbhn\3.3_1\chromeRestore.js, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eikdkoejhlpkgdeodpbpaigmbikhmbhn\3.3_1\contentscript.js, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eikdkoejhlpkgdeodpbpaigmbikhmbhn\3.3_1\icon.png, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eikdkoejhlpkgdeodpbpaigmbikhmbhn\3.3_1\manifest.json, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Sync Extension Settings\mpiffdmfpioemhakbaapeeopdppjloec\000003.log, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Sync Extension Settings\mpiffdmfpioemhakbaapeeopdppjloec\CURRENT, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Sync Extension Settings\mpiffdmfpioemhakbaapeeopdppjloec\LOCK, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Sync Extension Settings\mpiffdmfpioemhakbaapeeopdppjloec\LOG, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Sync Extension Settings\mpiffdmfpioemhakbaapeeopdppjloec\LOG.old, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Sync Extension Settings\mpiffdmfpioemhakbaapeeopdppjloec\MANIFEST-000001, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Profile 1\Secure Preferences, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Profile 1\Preferences, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Profile 1\Sync Data\SyncData.sqlite3, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\PROFILE 1\EXTENSIONS\MPIFFDMFPIOEMHAKBAAPEEOPDPPJLOEC\2.1_0\BACKGROUND.JS, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mpiffdmfpioemhakbaapeeopdppjloec\2.1_0\css\browserAction.css, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mpiffdmfpioemhakbaapeeopdppjloec\2.1_0\css\description.css, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mpiffdmfpioemhakbaapeeopdppjloec\2.1_0\html\browserAction\browserAction.html, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mpiffdmfpioemhakbaapeeopdppjloec\2.1_0\html\browserAction\description.html, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mpiffdmfpioemhakbaapeeopdppjloec\2.1_0\js\userNewTab.js, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mpiffdmfpioemhakbaapeeopdppjloec\2.1_0\newtab\quicknewtabpage.html, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mpiffdmfpioemhakbaapeeopdppjloec\2.1_0\_locales\en\messages.json, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mpiffdmfpioemhakbaapeeopdppjloec\2.1_0\_metadata\verified_contents.json, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mpiffdmfpioemhakbaapeeopdppjloec\2.1_0\after.js, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mpiffdmfpioemhakbaapeeopdppjloec\2.1_0\chromeRestore.js, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mpiffdmfpioemhakbaapeeopdppjloec\2.1_0\contentscript.js, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mpiffdmfpioemhakbaapeeopdppjloec\2.1_0\icon.png, No Action By User, [217], [575422],1.0.10042
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mpiffdmfpioemhakbaapeeopdppjloec\2.1_0\manifest.json, No Action By User, [217], [575422],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Sync Extension Settings\iiihmlfhnchcalmhhoilcamhpjcfafge\000003.log, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Sync Extension Settings\iiihmlfhnchcalmhhoilcamhpjcfafge\CURRENT, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Sync Extension Settings\iiihmlfhnchcalmhhoilcamhpjcfafge\LOCK, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Sync Extension Settings\iiihmlfhnchcalmhhoilcamhpjcfafge\LOG, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Sync Extension Settings\iiihmlfhnchcalmhhoilcamhpjcfafge\LOG.old, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Sync Extension Settings\iiihmlfhnchcalmhhoilcamhpjcfafge\MANIFEST-000001, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Profile 1\Secure Preferences, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Profile 1\Preferences, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Profile 1\Sync Data\SyncData.sqlite3, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\PROFILE 1\EXTENSIONS\IIIHMLFHNCHCALMHHOILCAMHPJCFAFGE\3.4.0.8_1\MANIFEST.JSON, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.4.0.8_1\css\tooltip.css, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.4.0.8_1\img\se\icon128.png, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.4.0.8_1\img\se\icon16.png, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.4.0.8_1\img\se\icon16_disabled.png, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.4.0.8_1\img\se\icon48.png, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.4.0.8_1\img\se\input-checked.png, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.4.0.8_1\img\se\input-unchecked.png, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.4.0.8_1\img\se\si-logo.png, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.4.0.8_1\lib\bg.js, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.4.0.8_1\lib\page-protection.js, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.4.0.8_1\lib\panel.js, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.4.0.8_1\lib\savesettings.js, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.4.0.8_1\_metadata\verified_contents.json, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.4.0.8_1\background.html, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.4.0.8_1\panel.html, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.4.0.8_1\settings.html, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Sync Extension Settings\oodblefojaocanejnikhhjcglbaelpbp\000003.log, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Sync Extension Settings\oodblefojaocanejnikhhjcglbaelpbp\CURRENT, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Sync Extension Settings\oodblefojaocanejnikhhjcglbaelpbp\LOCK, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Sync Extension Settings\oodblefojaocanejnikhhjcglbaelpbp\LOG, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Sync Extension Settings\oodblefojaocanejnikhhjcglbaelpbp\LOG.old, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Sync Extension Settings\oodblefojaocanejnikhhjcglbaelpbp\MANIFEST-000001, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Profile 1\Secure Preferences, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Profile 1\Preferences, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\PROFILE 1\EXTENSIONS\OODBLEFOJAOCANEJNIKHHJCGLBAELPBP\3.4.2_0\MANIFEST.JSON, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2_0\css\tooltip.css, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2_0\img\se\icon128.png, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2_0\img\se\icon16.png, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2_0\img\se\icon16_disabled.png, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2_0\img\se\icon48.png, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2_0\img\se\input-checked.png, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2_0\img\se\input-unchecked.png, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2_0\img\se\si-logo.png, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2_0\lib\bg.js, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2_0\lib\page-protection.js, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2_0\lib\panel.js, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2_0\lib\savesettings.js, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2_0\_metadata\verified_contents.json, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2_0\background.html, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2_0\panel.html, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2_0\settings.html, No Action By User, [14754], [448980],1.0.10042
PUP.Optional.DriverSupport, C:\PROGRAM FILES (X86)\DRIVER SUPPORT\DRIVERSUPPORT.EXE, No Action By User, [12926], [645741],1.0.10042
PUP.Optional.DriverSupport, C:\USERS\ANNETTE\DOWNLOADS\DRIVERSUPPORT.EXE, No Action By User, [12926], [645741],1.0.10042
PUP.Optional.InstallCore, C:\USERS\JACQUELYN\DOWNLOADS\UTORRENT SETUP.ZIP, No Action By User, [427], [99385],1.0.10042
 
Physical Sector: 0
(No malicious items detected)
 
WMI: 0
(No malicious items detected)
 
 
(end)
Were you able to run the Emsisoft Emergency Kit scan?

Also, did you allow Malwarebytes anti malware to quarantine what it found?
Malwarebytes
www.malwarebytes.com
 
-Log Details-
Scan Date: 4/9/19
Scan Time: 6:17 PM
Log File: ad516d6c-5b1d-11e9-b5b8-00ff4f781b5c.json
 
-Software Information-
Version: 3.7.1.2839
Components Version: 1.0.563
Update Package Version: 1.0.10074
License: Trial
 
-System Information-
OS: Windows 8.1
CPU: x64
File System: NTFS
User: System
 
-Scan Summary-
Scan Type: Threat Scan
Scan Initiated By: Scheduler
Result: Completed
Objects Scanned: 283528
Threats Detected: 225
Threats Quarantined: 225
Time Elapsed: 22 min, 22 sec
 
-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Detect
PUM: Detect
 
-Scan Details-
Process: 0
(No malicious items detected)
 
Module: 0
(No malicious items detected)
 
Registry Key: 0
(No malicious items detected)
 
Registry Value: 5
PUP.Optional.Spigot.Generic, HKU\S-1-5-21-1409944621-189731363-133459071-1005\SOFTWARE\GOOGLE\CHROME\PREFERENCEMACS\Default\extensions.settings|odhkbaigkdgomaoipjcnnphjdlpnjjka, Quarantined, [217], [495178],1.0.10074
PUP.Optional.SearchEncrypt.Generic, HKU\S-1-5-21-1409944621-189731363-133459071-1005\SOFTWARE\GOOGLE\CHROME\PREFERENCEMACS\Profile 1\extensions.settings|iiihmlfhnchcalmhhoilcamhpjcfafge, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, HKU\S-1-5-21-1409944621-189731363-133459071-1005\SOFTWARE\GOOGLE\CHROME\PREFERENCEMACS\Profile 1\extensions.settings|oodblefojaocanejnikhhjcglbaelpbp, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.Spigot.Generic, HKU\S-1-5-21-1409944621-189731363-133459071-1005\SOFTWARE\GOOGLE\CHROME\PREFERENCEMACS\Profile 1\extensions.settings|eikdkoejhlpkgdeodpbpaigmbikhmbhn, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, HKU\S-1-5-21-1409944621-189731363-133459071-1005\SOFTWARE\GOOGLE\CHROME\PREFERENCEMACS\Profile 1\extensions.settings|mpiffdmfpioemhakbaapeeopdppjloec, Quarantined, [217], [575422],1.0.10074
 
Registry Data: 0
(No malicious items detected)
 
Data Stream: 0
(No malicious items detected)
 
Folder: 64
PUP.Optional.Spigot.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Sync Extension Settings\odhkbaigkdgomaoipjcnnphjdlpnjjka, Quarantined, [217], [495178],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\odhkbaigkdgomaoipjcnnphjdlpnjjka\4.3_0\_locales\en, Quarantined, [217], [495178],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\odhkbaigkdgomaoipjcnnphjdlpnjjka\4.3_0\html\popup, Quarantined, [217], [495178],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\odhkbaigkdgomaoipjcnnphjdlpnjjka\4.3_0\_metadata, Quarantined, [217], [495178],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\odhkbaigkdgomaoipjcnnphjdlpnjjka\4.3_0\js\popup, Quarantined, [217], [495178],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\odhkbaigkdgomaoipjcnnphjdlpnjjka\4.3_0\_locales, Quarantined, [217], [495178],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\odhkbaigkdgomaoipjcnnphjdlpnjjka\4.3_0\newtab, Quarantined, [217], [495178],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\odhkbaigkdgomaoipjcnnphjdlpnjjka\4.3_0\html, Quarantined, [217], [495178],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\odhkbaigkdgomaoipjcnnphjdlpnjjka\4.3_0\css, Quarantined, [217], [495178],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\odhkbaigkdgomaoipjcnnphjdlpnjjka\4.3_0\js, Quarantined, [217], [495178],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\odhkbaigkdgomaoipjcnnphjdlpnjjka\4.3_0, Quarantined, [217], [495178],1.0.10074
PUP.Optional.Spigot.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\ODHKBAIGKDGOMAOIPJCNNPHJDLPNJJKA, Quarantined, [217], [495178],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Profile 1\Sync Extension Settings\iiihmlfhnchcalmhhoilcamhpjcfafge, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.4.0.8_1\_metadata, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.4.0.8_1\img\se, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.4.0.8_1\css, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.4.0.8_1\img, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.4.0.8_1\lib, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.4.0.8_1, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\PROFILE 1\EXTENSIONS\IIIHMLFHNCHCALMHHOILCAMHPJCFAFGE, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Profile 1\Sync Extension Settings\oodblefojaocanejnikhhjcglbaelpbp, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2.3_0\_metadata, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2.3_1\_metadata, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2_0\_metadata, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2.3_0\img\se, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2.3_1\img\se, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2_0\img\se, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2.3_0\css, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2.3_0\img, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2.3_0\lib, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2.3_1\css, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2.3_1\img, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2.3_1\lib, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2_0\css, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2_0\img, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2_0\lib, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2.3_0, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2.3_1, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2_0, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\PROFILE 1\EXTENSIONS\OODBLEFOJAOCANEJNIKHHJCGLBAELPBP, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.Spigot.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Profile 1\Sync Extension Settings\eikdkoejhlpkgdeodpbpaigmbikhmbhn, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eikdkoejhlpkgdeodpbpaigmbikhmbhn\3.3_1\html\browserAction, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eikdkoejhlpkgdeodpbpaigmbikhmbhn\3.3_1\_locales\en, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eikdkoejhlpkgdeodpbpaigmbikhmbhn\3.3_1\html\popup, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eikdkoejhlpkgdeodpbpaigmbikhmbhn\3.3_1\_metadata, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eikdkoejhlpkgdeodpbpaigmbikhmbhn\3.3_1\js\popup, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eikdkoejhlpkgdeodpbpaigmbikhmbhn\3.3_1\_locales, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eikdkoejhlpkgdeodpbpaigmbikhmbhn\3.3_1\newtab, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eikdkoejhlpkgdeodpbpaigmbikhmbhn\3.3_1\html, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eikdkoejhlpkgdeodpbpaigmbikhmbhn\3.3_1\css, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eikdkoejhlpkgdeodpbpaigmbikhmbhn\3.3_1\js, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eikdkoejhlpkgdeodpbpaigmbikhmbhn\3.3_1, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\PROFILE 1\EXTENSIONS\EIKDKOEJHLPKGDEODPBPAIGMBIKHMBHN, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Profile 1\Sync Extension Settings\mpiffdmfpioemhakbaapeeopdppjloec, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mpiffdmfpioemhakbaapeeopdppjloec\2.1_0\html\browserAction, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mpiffdmfpioemhakbaapeeopdppjloec\2.1_0\_locales\en, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mpiffdmfpioemhakbaapeeopdppjloec\2.1_0\_metadata, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mpiffdmfpioemhakbaapeeopdppjloec\2.1_0\_locales, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mpiffdmfpioemhakbaapeeopdppjloec\2.1_0\newtab, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mpiffdmfpioemhakbaapeeopdppjloec\2.1_0\html, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mpiffdmfpioemhakbaapeeopdppjloec\2.1_0\css, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mpiffdmfpioemhakbaapeeopdppjloec\2.1_0\js, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mpiffdmfpioemhakbaapeeopdppjloec\2.1_0, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\PROFILE 1\EXTENSIONS\MPIFFDMFPIOEMHAKBAAPEEOPDPPJLOEC, Quarantined, [217], [575422],1.0.10074
 
File: 156
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\odhkbaigkdgomaoipjcnnphjdlpnjjka\000003.log, Quarantined, [217], [495178],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\odhkbaigkdgomaoipjcnnphjdlpnjjka\CURRENT, Quarantined, [217], [495178],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\odhkbaigkdgomaoipjcnnphjdlpnjjka\LOCK, Quarantined, [217], [495178],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\odhkbaigkdgomaoipjcnnphjdlpnjjka\LOG, Quarantined, [217], [495178],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\odhkbaigkdgomaoipjcnnphjdlpnjjka\MANIFEST-000001, Quarantined, [217], [495178],1.0.10074
PUP.Optional.Spigot.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Secure Preferences, Replaced, [217], [495178],1.0.10074
PUP.Optional.Spigot.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Preferences, Replaced, [217], [495178],1.0.10074
PUP.Optional.Spigot.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\ODHKBAIGKDGOMAOIPJCNNPHJDLPNJJKA\4.3_0\BACKGROUND.JS, Quarantined, [217], [495178],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\odhkbaigkdgomaoipjcnnphjdlpnjjka\4.3_0\css\description.css, Quarantined, [217], [495178],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\odhkbaigkdgomaoipjcnnphjdlpnjjka\4.3_0\css\popup.css, Quarantined, [217], [495178],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\odhkbaigkdgomaoipjcnnphjdlpnjjka\4.3_0\html\popup\description.html, Quarantined, [217], [495178],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\odhkbaigkdgomaoipjcnnphjdlpnjjka\4.3_0\html\popup\popup.html, Quarantined, [217], [495178],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\odhkbaigkdgomaoipjcnnphjdlpnjjka\4.3_0\js\popup\popup.js, Quarantined, [217], [495178],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\odhkbaigkdgomaoipjcnnphjdlpnjjka\4.3_0\js\userNewTab.js, Quarantined, [217], [495178],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\odhkbaigkdgomaoipjcnnphjdlpnjjka\4.3_0\newtab\quicktab.html, Quarantined, [217], [495178],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\odhkbaigkdgomaoipjcnnphjdlpnjjka\4.3_0\_locales\en\messages.json, Quarantined, [217], [495178],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\odhkbaigkdgomaoipjcnnphjdlpnjjka\4.3_0\_metadata\verified_contents.json, Quarantined, [217], [495178],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\odhkbaigkdgomaoipjcnnphjdlpnjjka\4.3_0\after.js, Quarantined, [217], [495178],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\odhkbaigkdgomaoipjcnnphjdlpnjjka\4.3_0\chromeRestore.js, Quarantined, [217], [495178],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\odhkbaigkdgomaoipjcnnphjdlpnjjka\4.3_0\contentscript.js, Quarantined, [217], [495178],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\odhkbaigkdgomaoipjcnnphjdlpnjjka\4.3_0\icon.png, Quarantined, [217], [495178],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\odhkbaigkdgomaoipjcnnphjdlpnjjka\4.3_0\manifest.json, Quarantined, [217], [495178],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Sync Extension Settings\iiihmlfhnchcalmhhoilcamhpjcfafge\000003.log, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Sync Extension Settings\iiihmlfhnchcalmhhoilcamhpjcfafge\CURRENT, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Sync Extension Settings\iiihmlfhnchcalmhhoilcamhpjcfafge\LOCK, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Sync Extension Settings\iiihmlfhnchcalmhhoilcamhpjcfafge\LOG, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Sync Extension Settings\iiihmlfhnchcalmhhoilcamhpjcfafge\LOG.old, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Sync Extension Settings\iiihmlfhnchcalmhhoilcamhpjcfafge\MANIFEST-000001, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Profile 1\Secure Preferences, Replaced, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Profile 1\Preferences, Replaced, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Profile 1\Sync Data\SyncData.sqlite3, Replaced, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\PROFILE 1\EXTENSIONS\IIIHMLFHNCHCALMHHOILCAMHPJCFAFGE\3.4.0.8_1\MANIFEST.JSON, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.4.0.8_1\css\tooltip.css, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.4.0.8_1\img\se\icon128.png, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.4.0.8_1\img\se\icon16.png, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.4.0.8_1\img\se\icon16_disabled.png, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.4.0.8_1\img\se\icon48.png, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.4.0.8_1\img\se\input-checked.png, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.4.0.8_1\img\se\input-unchecked.png, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.4.0.8_1\img\se\si-logo.png, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.4.0.8_1\lib\bg.js, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.4.0.8_1\lib\page-protection.js, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.4.0.8_1\lib\panel.js, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.4.0.8_1\lib\savesettings.js, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.4.0.8_1\_metadata\verified_contents.json, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.4.0.8_1\background.html, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.4.0.8_1\panel.html, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.4.0.8_1\settings.html, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Sync Extension Settings\oodblefojaocanejnikhhjcglbaelpbp\000003.log, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Sync Extension Settings\oodblefojaocanejnikhhjcglbaelpbp\CURRENT, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Sync Extension Settings\oodblefojaocanejnikhhjcglbaelpbp\LOCK, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Sync Extension Settings\oodblefojaocanejnikhhjcglbaelpbp\LOG, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Sync Extension Settings\oodblefojaocanejnikhhjcglbaelpbp\LOG.old, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Sync Extension Settings\oodblefojaocanejnikhhjcglbaelpbp\MANIFEST-000001, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Profile 1\Secure Preferences, Replaced, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Profile 1\Preferences, Replaced, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\PROFILE 1\EXTENSIONS\OODBLEFOJAOCANEJNIKHHJCGLBAELPBP\3.4.2.3_0\MANIFEST.JSON, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2.3_0\css\tooltip.css, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2.3_0\img\se\icon128.png, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2.3_0\img\se\icon16.png, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2.3_0\img\se\icon16_disabled.png, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2.3_0\img\se\icon48.png, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2.3_0\img\se\input-checked.png, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2.3_0\img\se\input-unchecked.png, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2.3_0\img\se\si-logo.png, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2.3_0\lib\bg.js, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2.3_0\lib\page-protection.js, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2.3_0\lib\panel.js, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2.3_0\lib\savesettings.js, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2.3_0\_metadata\verified_contents.json, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2.3_0\background.html, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2.3_0\panel.html, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2.3_0\settings.html, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2.3_1\css\tooltip.css, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2.3_1\img\se\icon128.png, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2.3_1\img\se\icon16.png, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2.3_1\img\se\icon16_disabled.png, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2.3_1\img\se\icon48.png, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2.3_1\img\se\input-checked.png, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2.3_1\img\se\input-unchecked.png, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2.3_1\img\se\si-logo.png, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2.3_1\lib\bg.js, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2.3_1\lib\page-protection.js, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2.3_1\lib\panel.js, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2.3_1\lib\savesettings.js, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2.3_1\_metadata\verified_contents.json, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2.3_1\background.html, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2.3_1\manifest.json, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2.3_1\panel.html, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2.3_1\settings.html, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2_0\css\tooltip.css, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2_0\img\se\icon128.png, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2_0\img\se\icon16.png, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2_0\img\se\icon16_disabled.png, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2_0\img\se\icon48.png, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2_0\img\se\input-checked.png, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2_0\img\se\input-unchecked.png, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2_0\img\se\si-logo.png, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2_0\lib\bg.js, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2_0\lib\page-protection.js, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2_0\lib\panel.js, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2_0\lib\savesettings.js, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2_0\_metadata\verified_contents.json, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2_0\background.html, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2_0\manifest.json, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2_0\panel.html, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.4.2_0\settings.html, Quarantined, [14749], [448980],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Sync Extension Settings\eikdkoejhlpkgdeodpbpaigmbikhmbhn\000003.log, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Sync Extension Settings\eikdkoejhlpkgdeodpbpaigmbikhmbhn\CURRENT, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Sync Extension Settings\eikdkoejhlpkgdeodpbpaigmbikhmbhn\LOCK, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Sync Extension Settings\eikdkoejhlpkgdeodpbpaigmbikhmbhn\LOG, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Sync Extension Settings\eikdkoejhlpkgdeodpbpaigmbikhmbhn\LOG.old, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Sync Extension Settings\eikdkoejhlpkgdeodpbpaigmbikhmbhn\MANIFEST-000001, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Profile 1\Secure Preferences, Replaced, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Profile 1\Preferences, Replaced, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Profile 1\Sync Data\SyncData.sqlite3, Replaced, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\PROFILE 1\EXTENSIONS\EIKDKOEJHLPKGDEODPBPAIGMBIKHMBHN\3.3_1\BACKGROUND.JS, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eikdkoejhlpkgdeodpbpaigmbikhmbhn\3.3_1\css\browserAction.css, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eikdkoejhlpkgdeodpbpaigmbikhmbhn\3.3_1\css\description.css, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eikdkoejhlpkgdeodpbpaigmbikhmbhn\3.3_1\html\browserAction\browserAction.html, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eikdkoejhlpkgdeodpbpaigmbikhmbhn\3.3_1\html\browserAction\description.html, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eikdkoejhlpkgdeodpbpaigmbikhmbhn\3.3_1\js\userNewTab.js, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eikdkoejhlpkgdeodpbpaigmbikhmbhn\3.3_1\newtab\quicknewtabpage.html, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eikdkoejhlpkgdeodpbpaigmbikhmbhn\3.3_1\_locales\en\messages.json, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eikdkoejhlpkgdeodpbpaigmbikhmbhn\3.3_1\_metadata\verified_contents.json, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eikdkoejhlpkgdeodpbpaigmbikhmbhn\3.3_1\after.js, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eikdkoejhlpkgdeodpbpaigmbikhmbhn\3.3_1\chromeRestore.js, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eikdkoejhlpkgdeodpbpaigmbikhmbhn\3.3_1\contentscript.js, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eikdkoejhlpkgdeodpbpaigmbikhmbhn\3.3_1\icon.png, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eikdkoejhlpkgdeodpbpaigmbikhmbhn\3.3_1\manifest.json, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Sync Extension Settings\mpiffdmfpioemhakbaapeeopdppjloec\000003.log, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Sync Extension Settings\mpiffdmfpioemhakbaapeeopdppjloec\CURRENT, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Sync Extension Settings\mpiffdmfpioemhakbaapeeopdppjloec\LOCK, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Sync Extension Settings\mpiffdmfpioemhakbaapeeopdppjloec\LOG, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Sync Extension Settings\mpiffdmfpioemhakbaapeeopdppjloec\LOG.old, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Sync Extension Settings\mpiffdmfpioemhakbaapeeopdppjloec\MANIFEST-000001, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Profile 1\Secure Preferences, Replaced, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Profile 1\Preferences, Replaced, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Profile 1\Sync Data\SyncData.sqlite3, Replaced, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\PROFILE 1\EXTENSIONS\MPIFFDMFPIOEMHAKBAAPEEOPDPPJLOEC\2.1_0\BACKGROUND.JS, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mpiffdmfpioemhakbaapeeopdppjloec\2.1_0\css\browserAction.css, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mpiffdmfpioemhakbaapeeopdppjloec\2.1_0\css\description.css, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mpiffdmfpioemhakbaapeeopdppjloec\2.1_0\html\browserAction\browserAction.html, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mpiffdmfpioemhakbaapeeopdppjloec\2.1_0\html\browserAction\description.html, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mpiffdmfpioemhakbaapeeopdppjloec\2.1_0\js\userNewTab.js, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mpiffdmfpioemhakbaapeeopdppjloec\2.1_0\newtab\quicknewtabpage.html, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mpiffdmfpioemhakbaapeeopdppjloec\2.1_0\_locales\en\messages.json, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mpiffdmfpioemhakbaapeeopdppjloec\2.1_0\_metadata\verified_contents.json, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mpiffdmfpioemhakbaapeeopdppjloec\2.1_0\after.js, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mpiffdmfpioemhakbaapeeopdppjloec\2.1_0\chromeRestore.js, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mpiffdmfpioemhakbaapeeopdppjloec\2.1_0\contentscript.js, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mpiffdmfpioemhakbaapeeopdppjloec\2.1_0\icon.png, Quarantined, [217], [575422],1.0.10074
PUP.Optional.Spigot.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mpiffdmfpioemhakbaapeeopdppjloec\2.1_0\manifest.json, Quarantined, [217], [575422],1.0.10074
PUP.Optional.DriverSupport, C:\PROGRAM FILES (X86)\DRIVER SUPPORT\DRIVERSUPPORT.EXE, Quarantined, [12924], [645741],1.0.10074
PUP.Optional.DriverSupport, C:\USERS\ANNETTE\DOWNLOADS\DRIVERSUPPORT.EXE, Quarantined, [12924], [645741],1.0.10074
PUP.Optional.InstallCore, C:\USERS\JACQUELYN\DOWNLOADS\UTORRENT SETUP.ZIP, Quarantined, [427], [99385],1.0.10074
 
Physical Sector: 0
(No malicious items detected)
 
WMI: 0
(No malicious items detected)
 
 
(end)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI