This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Slow laptop, Malware removal needed [Closed]

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi

 

I believe my Windows 8 laptop is highly infected with virus and has malware issues. Your assistance in addressing my concerns will be greatly appreciated.

 

Thanks

Hello BJ2011 and welcome to WTT.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:

  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!

IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

===================================================

Note: Please complete these tasks in the order given in the instructions.

===================================================

Download and run AdwCleaner

Download AdwCleaner from here and save it to your desktop.

  • run AdwCleaner by clicking on Scan Now
  • when it has finished, leave everything that was found checked, (ticked), then click on Clean and Repair
  • if it asks to reboot, allow the reboot
  • on reboot a log will be produced; please attach the content of the log to your next reply.

===================================================

Run Malwarebytes Anti-Malware

You may have Malwarebytes Anti-Malware installed but if not, you can download it from here:
run the program.

  • click on the ‘Dashboard’ to make sure everything is up to date, (it is not necessary to upgrade to the premium version of MBAM)
  • click on the ‘Scan’ tab, (directly below the Dashboard tab)
  • select the Threat Scan option
  • slick the Scan Now button
  • Threat Scan will begin
  • when the scan has completed and if malware was found, click the Quarantine Selected button to allow MBAM to quarantine what was found
  • if prompted to restart the computer, close all other programs and click Yes to restart your computer
  • once you are back at your desktop, open MBAM once more
  • click on the ‘Reports’ tab
  • double-click on the most recent Scan Report
  • click on Export, then Copy to Clipboard

===================================================

Run Farbar Recovery Scan Tool

Please download Farbar Recovery Scan Tool and save it to your Desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

  • right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • press Scan button
  • it will produce a log called Frst.txt in the same directory the tool is run from
  • please copy and paste log back here.
  • the first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the Frst.txt into your reply.

Logs to include with next post:

AdwCleaner log
Mbam.txt
Frst.txt
Addition.txt


Thanks

Satchfan

 

Malwarebytes
www.malwarebytes.com
 
-Log Details-
Scan Date: 8/8/19
Scan Time: 5:50 PM
Log File: f4862dce-ba2e-11e9-a149-00ff4f781b5c.json
 
-Software Information-
Version: 3.8.3.2965
Components Version: 1.0.613
Update Package Version: 1.0.11924
License: Trial
 
-System Information-
OS: Windows 8.1
CPU: x64
File System: NTFS
User: System
 
-Scan Summary-
Scan Type: Threat Scan
Scan Initiated By: Scheduler
Result: Completed
Objects Scanned: 284584
Threats Detected: 54
Threats Quarantined: 54
Time Elapsed: 1 hr, 16 min, 55 sec
 
-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Detect
PUM: Detect
 
-Scan Details-
Process: 0
(No malicious items detected)
 
Module: 0
(No malicious items detected)
 
Registry Key: 0
(No malicious items detected)
 
Registry Value: 2
PUP.Optional.SearchEncrypt.Generic, HKU\S-1-5-21-1409944621-189731363-133459071-1005\SOFTWARE\GOOGLE\CHROME\PREFERENCEMACS\Profile 1\extensions.settings|iiihmlfhnchcalmhhoilcamhpjcfafge, Quarantined, [14692], [448980],1.0.11924
PUP.Optional.SearchEncrypt.Generic, HKU\S-1-5-21-1409944621-189731363-133459071-1005\SOFTWARE\GOOGLE\CHROME\PREFERENCEMACS\Profile 1\extensions.settings|oodblefojaocanejnikhhjcglbaelpbp, Quarantined, [14692], [448980],1.0.11924
 
Registry Data: 0
(No malicious items detected)
 
Data Stream: 0
(No malicious items detected)
 
Folder: 14
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.8.0.0_1\_metadata, Quarantined, [14692], [448980],1.0.11924
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.8.0.0_1\img\se, Quarantined, [14692], [448980],1.0.11924
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.8.0.0_1\css, Quarantined, [14692], [448980],1.0.11924
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.8.0.0_1\img, Quarantined, [14692], [448980],1.0.11924
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.8.0.0_1\lib, Quarantined, [14692], [448980],1.0.11924
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.8.0.0_1, Quarantined, [14692], [448980],1.0.11924
PUP.Optional.SearchEncrypt.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\PROFILE 1\EXTENSIONS\IIIHMLFHNCHCALMHHOILCAMHPJCFAFGE, Quarantined, [14692], [448980],1.0.11924
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.8.0.0_0\_metadata, Quarantined, [14692], [448980],1.0.11924
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.8.0.0_0\img\se, Quarantined, [14692], [448980],1.0.11924
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.8.0.0_0\css, Quarantined, [14692], [448980],1.0.11924
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.8.0.0_0\img, Quarantined, [14692], [448980],1.0.11924
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.8.0.0_0\lib, Quarantined, [14692], [448980],1.0.11924
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.8.0.0_0, Quarantined, [14692], [448980],1.0.11924
PUP.Optional.SearchEncrypt.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\PROFILE 1\EXTENSIONS\OODBLEFOJAOCANEJNIKHHJCGLBAELPBP, Quarantined, [14692], [448980],1.0.11924
 
File: 38
PUP.Optional.SearchEncrypt.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Profile 1\Secure Preferences, Replaced, [14692], [448980],1.0.11924
PUP.Optional.SearchEncrypt.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Profile 1\Preferences, Replaced, [14692], [448980],1.0.11924
PUP.Optional.SearchEncrypt.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\PROFILE 1\EXTENSIONS\IIIHMLFHNCHCALMHHOILCAMHPJCFAFGE\3.8.0.0_1\MANIFEST.JSON, Quarantined, [14692], [448980],1.0.11924
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.8.0.0_1\css\tooltip.css, Quarantined, [14692], [448980],1.0.11924
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.8.0.0_1\img\se\icon128.png, Quarantined, [14692], [448980],1.0.11924
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.8.0.0_1\img\se\icon16.png, Quarantined, [14692], [448980],1.0.11924
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.8.0.0_1\img\se\icon16_disabled.png, Quarantined, [14692], [448980],1.0.11924
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.8.0.0_1\img\se\icon48.png, Quarantined, [14692], [448980],1.0.11924
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.8.0.0_1\img\se\input-checked.png, Quarantined, [14692], [448980],1.0.11924
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.8.0.0_1\img\se\input-unchecked.png, Quarantined, [14692], [448980],1.0.11924
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.8.0.0_1\img\se\si-logo.png, Quarantined, [14692], [448980],1.0.11924
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.8.0.0_1\lib\bg.js, Quarantined, [14692], [448980],1.0.11924
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.8.0.0_1\lib\page-protection.js, Quarantined, [14692], [448980],1.0.11924
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.8.0.0_1\lib\panel.js, Quarantined, [14692], [448980],1.0.11924
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.8.0.0_1\lib\savesettings.js, Quarantined, [14692], [448980],1.0.11924
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.8.0.0_1\_metadata\verified_contents.json, Quarantined, [14692], [448980],1.0.11924
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.8.0.0_1\background.html, Quarantined, [14692], [448980],1.0.11924
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.8.0.0_1\panel.html, Quarantined, [14692], [448980],1.0.11924
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge\3.8.0.0_1\settings.html, Quarantined, [14692], [448980],1.0.11924
PUP.Optional.SearchEncrypt.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Profile 1\Secure Preferences, Replaced, [14692], [448980],1.0.11924
PUP.Optional.SearchEncrypt.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Profile 1\Preferences, Replaced, [14692], [448980],1.0.11924
PUP.Optional.SearchEncrypt.Generic, C:\USERS\ANNETTE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\PROFILE 1\EXTENSIONS\OODBLEFOJAOCANEJNIKHHJCGLBAELPBP\3.8.0.0_0\MANIFEST.JSON, Quarantined, [14692], [448980],1.0.11924
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.8.0.0_0\css\tooltip.css, Quarantined, [14692], [448980],1.0.11924
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.8.0.0_0\img\se\icon128.png, Quarantined, [14692], [448980],1.0.11924
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.8.0.0_0\img\se\icon16.png, Quarantined, [14692], [448980],1.0.11924
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.8.0.0_0\img\se\icon16_disabled.png, Quarantined, [14692], [448980],1.0.11924
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.8.0.0_0\img\se\icon48.png, Quarantined, [14692], [448980],1.0.11924
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.8.0.0_0\img\se\input-checked.png, Quarantined, [14692], [448980],1.0.11924
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.8.0.0_0\img\se\input-unchecked.png, Quarantined, [14692], [448980],1.0.11924
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.8.0.0_0\img\se\si-logo.png, Quarantined, [14692], [448980],1.0.11924
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.8.0.0_0\lib\bg.js, Quarantined, [14692], [448980],1.0.11924
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.8.0.0_0\lib\page-protection.js, Quarantined, [14692], [448980],1.0.11924
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.8.0.0_0\lib\panel.js, Quarantined, [14692], [448980],1.0.11924
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.8.0.0_0\lib\savesettings.js, Quarantined, [14692], [448980],1.0.11924
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.8.0.0_0\_metadata\verified_contents.json, Quarantined, [14692], [448980],1.0.11924
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.8.0.0_0\background.html, Quarantined, [14692], [448980],1.0.11924
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.8.0.0_0\panel.html, Quarantined, [14692], [448980],1.0.11924
PUP.Optional.SearchEncrypt.Generic, C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp\3.8.0.0_0\settings.html, Quarantined, [14692], [448980],1.0.11924
 
Physical Sector: 0
(No malicious items detected)
 
WMI: 0
(No malicious items detected)
 
 
(end)

First log

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 07-08-2019 02
Ran by [removed] (administrator) on MRSJOHNSON (Hewlett-Packard HP 15 Notebook PC) (09-08-2019 05:11:38)
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows 8.1 (Update) (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
() [File not signed] C:\Program Files\ATI Technologies\ATI.ACE\a4\AdaptiveSleepService.exe
() [File not signed] C:\Program Files\Hewlett-Packard\SimplePass\cachesrvr.exe
() [File not signed] C:\Program Files\Hewlett-Packard\SimplePass\opvapp.exe
(Adobe Systems, Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Advanced Micro Devices, Inc.) [File not signed] C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(CenturyLink -> CenturyLink Inc) C:\Program Files (x86)\CenturyLink\Desktop\CenturyLinkTouchPointAgent.exe
(CyberLink Corp. -> CyberLink Corp.) C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe
(Google Inc -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.34.11\GoogleCrashHandler.exe
(Google Inc -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.34.11\GoogleCrashHandler64.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(HP Inc. -> HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(HP Inc. -> HP Inc.) C:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe
(Huawei Technologies Co., Ltd. -> ) [File not signed] C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe
(Intuit, Inc. -> Intuit Inc.) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
(Malwarebytes Corporation -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Corporation -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\StikyNot.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atiesrxx.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Softex Inc.) [File not signed] C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe
(Softex Incorporated -> Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\HPSmplPass.exe
(Softex Incorporated -> Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBroker.exe
(Softex Incorporated -> Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe
(Symantec Corporation -> Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
(Symantec Corporation -> Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [SimplePass] => C:\Program Files\Hewlett-Packard\SimplePass\HPSmplPass.exe [2755640 2013-09-26] (Softex Incorporated -> Hewlett-Packard)
HKLM\…\Run: [OPBHOBroker] => C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBroker.exe [155704 2013-09-26] (Softex Incorporated -> Hewlett-Packard)
HKLM\…\Run: [OPBHOBrokerDesktop] => C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe [155704 2013-09-26] (Softex Incorporated -> Hewlett-Packard)
HKLM\…\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2771184 2013-07-26] (Synaptics Incorporated -> Synaptics Incorporated)
HKLM\…\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8843520 2016-02-19] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\…\Run: [WindowsDefender] => "%ProgramFiles%\Windows Defender\MSASCuiL.exe"
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [507776 2014-10-07] (Oracle America, Inc. -> Oracle Corporation)
HKLM-x32\…\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation -> Microsoft Corporation)
HKLM-x32\…\Run: [CenturyLinkTouchPointAgent] => C:\Program Files (x86)\CenturyLink\Desktop\CenturyLinkTouchPointAgent.exe [48904 2014-11-04] (CenturyLink -> CenturyLink Inc)
HKLM-x32\…\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767200 2014-06-06] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
HKLM-x32\…\Run: [HPMessageService] => C:\Program Files (x86)\HP\HP System Event\HPMSGSVC.exe [707624 2018-08-08] (HP Inc. -> HP Inc.)
HKU\S-1-5-21-1409944621-189731363-133459071-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050213346\…\Run: [Power2GoExpress8] => C:\Program Files (x86)\CyberLink\Power2Go8\Power2GoExpress8.exe [1728952 2015-06-22] (CyberLink Corp. -> CyberLink Corp.)
HKU\S-1-5-21-1409944621-189731363-133459071-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050213346\…\Run: [B0CA40A7B020DFFA8668D20001A42ED77693A62A._service_run] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1535472 2019-08-05] (Google LLC -> Google LLC)
HKU\S-1-5-21-1409944621-189731363-133459071-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050213346\…\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [479744 2014-10-28] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-21-1409944621-189731363-133459071-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050213346\…\MountPoints2: {e1d9e33d-70cc-11e4-825e-3863bb8eae0e} - "F:\AutoRun.exe" 
HKU\S-1-5-21-1409944621-189731363-133459071-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050213346\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Bubbles.scr [788480 2014-10-28] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\Run: [GoogleChromeAutoLaunch_0C9337CDD31A557C75EB2CDF52C45A5A] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1535472 2019-08-05] (Google LLC -> Google LLC)
HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [479744 2014-10-28] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\MountPoints2: {0971029e-8ae2-11e8-830f-3863bb8eae0e} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\MountPoints2: {097102d7-8ae2-11e8-830f-3863bb8eae0e} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\MountPoints2: {803e9b84-3b72-11e8-8302-3863bb8eae0e} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\MountPoints2: {ed76fc77-6b0a-11e5-8270-3863bb8eae0e} - "F:\AutoRun.exe" 
HKU\S-1-5-21-1409944621-189731363-133459071-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050214551\…\Run: [GoogleChromeAutoLaunch_0C9337CDD31A557C75EB2CDF52C45A5A] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1535472 2019-08-05] (Google LLC -> Google LLC)
HKU\S-1-5-21-1409944621-189731363-133459071-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050214551\…\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [479744 2014-10-28] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-21-1409944621-189731363-133459071-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050214551\…\MountPoints2: {0971029e-8ae2-11e8-830f-3863bb8eae0e} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-1409944621-189731363-133459071-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050214551\…\MountPoints2: {097102d7-8ae2-11e8-830f-3863bb8eae0e} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-1409944621-189731363-133459071-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050214551\…\MountPoints2: {803e9b84-3b72-11e8-8302-3863bb8eae0e} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-1409944621-189731363-133459071-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050214551\…\MountPoints2: {ed76fc77-6b0a-11e5-8270-3863bb8eae0e} - "F:\AutoRun.exe" 
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\76.0.3809.100\Installer\chrmstp.exe [2019-08-07] (Google LLC -> Google LLC)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{A6EADE66-0000-0000-484E-7E8A45000000}] -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Esl\AiodLite.dll [2019-06-10] (Adobe Inc. -> Adobe Systems, Inc.)
HKLM\Software\…\Authentication\Credential Providers: [{538C240D-3DEE-4032-AB4C-08A3A6EB0861}] -> C:\Program Files (x86)\CyberLink\YouCam\CLCredProv\x64\CLCredProv.dll [2014-10-28] (CyberLink Corp. -> CyberLink)
HKLM\Software\…\Authentication\Credential Providers: [{F3F1B0FA-4775-41d8-8578-436772D93FB4}] -> C:\Program Files\Hewlett-Packard\SimplePass\OmniPassCredProv.dll [2013-09-26] (Softex Inc..) [File not signed]
HKLM\Software\…\Authentication\Credential Provider Filters: [{F3F1B0FA-4775-41d8-8578-436772D93FB4}] -> C:\Program Files\Hewlett-Packard\SimplePass\OmniPassCredProv.dll [2013-09-26] (Softex Inc..) [File not signed]
Startup: C:\Users\Annette\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Facebook Gameroom.lnk [2018-08-03]
ShortcutTarget: Facebook Gameroom.lnk -> C:\Users\Annette\AppData\Local\Facebook\Games\FacebookGameroom.exe (Facebook, Inc. -> Facebook) [File not signed]
Startup: C:\Users\Annette\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk [2018-01-08]
ShortcutTarget: Send to OneNote.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE (Microsoft Corporation -> Microsoft Corporation)
Startup: C:\Users\Jacquelyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk [2016-05-14]
ShortcutTarget: Send to OneNote.lnk -> C:\Program Files (x86)\Microsoft Office\Office15\ONENOTEM.EXE (Microsoft Corporation -> Microsoft Corporation)
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {10A0396E-4397-432D-A61A-B29936C98279} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-09-27] (Google Inc -> Google Inc.)
Task: {246C5721-0523-4DE8-812A-4947EAF60BFB} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1195544 2018-12-16] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
Task: {2FE82A44-7615-47C1-88DD-E0D568E5D0F2} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe
Task: {3165798A-F44B-4387-8B96-BD947DFDF94F} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [376496 2014-01-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {3CCC318D-E72D-4C49-9C74-C4C063155CBC} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\sdxhelper.exe [103464 2019-07-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {3E898CDD-32F4-47D1-A2F4-BCF33E88AEBC} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [651400 2017-09-20] (Hewlett Packard -> HP Inc.)
Task: {422808BD-6F70-41BF-945D-E13AA06AE45A} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis Install => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [1459056 2018-05-04] (HP Inc. -> HP Inc.)
Task: {468B13AD-B541-4A27-B004-9B018EEA3275} - System32\Tasks\Java Platform SE Auto Updater => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [507776 2014-10-07] (Oracle America, Inc. -> Oracle Corporation)
Task: {48426B74-A917-4AA1-A961-4CBF7B9F1EC5} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [1403536 2019-07-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {5200926D-6DAC-44AC-95C0-5C3C6F4AEBD1} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26045472 2019-06-27] (Microsoft Corporation -> Microsoft Corporation)
Task: {54D4B427-D571-42BD-AD1D-6FB9814F3F84} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [1403536 2019-07-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {55DCE214-7F3F-463F-BECE-5A67E73B6324} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [1459056 2018-05-04] (HP Inc. -> HP Inc.)
Task: {562E632A-822A-4DE0-8BCC-5EE113487084} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26045472 2019-06-27] (Microsoft Corporation -> Microsoft Corporation)
Task: {5B7B1C4A-9A07-4CAC-869E-5279651131BE} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [376496 2014-01-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {69D3BA23-D578-4DE2-AFDE-D9EF27762CEC} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-09-27] (Google Inc -> Google Inc.)
Task: {85D70D96-CB3D-4E56-AB0F-24B26C54D6BF} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [1059704 2018-11-09] (HP Inc. -> HP Inc.)
Task: {B73A7C7B-CF7F-4A7E-A613-BFBB8A73789D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater - Resources => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [651400 2017-09-20] (Hewlett Packard -> HP Inc.)
Task: {B95640C8-286C-4ADA-AF7B-A685867BC4F3} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task => {3519154C-227E-47F3-9CC9-12C3F05817F1}
Task: {BA1B1F3F-67C4-4B2E-AC43-EFB3069BC508} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\sdxhelper.exe [103464 2019-07-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {C20748E5-0782-4E30-A3BC-A01FF02DECE2} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [4404888 2019-07-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {C45E956E-E070-4332-B57C-DF9D8B626B72} - System32\Tasks\Hewlett-Packard\HP Active Health\HP Active Health Scan (HPSA) => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.exe [198696 2016-11-07] (HP Inc. -> HP Inc.)
Task: {C7300FA3-0507-4B0B-9200-F7F2EF465D7B} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [4404888 2019-07-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {CD39A3B5-0980-4947-BD6C-3D87425A7FCE} - System32\Tasks\Synaptics TouchPad Enhancements => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2771184 2013-07-26] (Synaptics Incorporated -> Synaptics Incorporated)
Task: {CE133C13-C983-4DC1-90A2-2F3469BB80A3} - System32\Tasks\RogueKiller Anti-Malware => C:\Users\Annette\Desktop\RogueKiller_portable64.exe
Task: {D04BBF70-03A8-413B-9CA3-5AC3314706E2} - System32\Tasks\G2MUpdateTask-S-1-5-21-1409944621-189731363-133459071-1005 => C:\Users\Annette\AppData\Local\GoToMeeting\13761\g2mupdate.exe [32256 2019-07-31] (LogMeIn, Inc. -> LogMeIn, Inc.)
Task: {D0F920D8-40AD-4B42-9F6C-ADA01607FCCD} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Product Configurator => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\ProductConfig.exe [217976 2018-11-08] (HP Inc. -> HP Inc.)
Task: {D5C531E1-84FD-4B99-81A6-F1B6E401FECD} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [758400 2019-07-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {DCEFA36E-E149-4C02-99DB-E3F29CC3066E} - System32\Tasks\YCMServiceAgent => C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe [267224 2014-10-28] (CyberLink Corp. -> CyberLink Corp.)
Task: {E6B7EE15-0DF8-473B-AA30-3C92EDE7356E} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [1459056 2018-05-04] (HP Inc. -> HP Inc.)
Task: {EC860F0E-1C8E-4761-BA2C-9ACF03169D98} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [124280 2018-08-17] (HP Inc. -> HP Inc.)
Task: {EFE6E304-849C-4527-A6F6-903B564B9663} - System32\Tasks\G2MUploadTask-S-1-5-21-1409944621-189731363-133459071-1005 => C:\Users\Annette\AppData\Local\GoToMeeting\13761\g2mupload.exe [32256 2019-07-31] (LogMeIn, Inc. -> LogMeIn, Inc.)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-1409944621-189731363-133459071-1005.job => C:\Users\Annette\AppData\Local\GoToMeeting\13761\g2mupdate.exe
Task: C:\Windows\Tasks\G2MUploadTask-S-1-5-21-1409944621-189731363-133459071-1005.job => C:\Users\Annette\AppData\Local\GoToMeeting\13761\g2mupload.exe
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{2BE7FA48-E3A9-4398-8011-4CBB02E6ACC5}: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{8E02059E-EC13-441B-AFD6-CD70C258610A}: [DhcpNameServer] 192.168.0.1 [removed]
 
Internet Explorer:
==================
HKU\S-1-5-21-1409944621-189731363-133459071-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050213346\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/HPNOT14/1
HKU\S-1-5-21-1409944621-189731363-133459071-1005\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/
HKU\S-1-5-21-1409944621-189731363-133459071-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050214551\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/
SearchScopes: HKU\S-1-5-21-1409944621-189731363-133459071-1005 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1409944621-189731363-133459071-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050214551 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2019-06-25] (Microsoft Corporation -> Microsoft Corporation)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation -> Microsoft Corporation)
BHO: No Name -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> No File
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2016-07-21] (Hewlett-Packard Company -> HP Inc.)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2019-06-25] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: No Name -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> No File
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2016-07-21] (Hewlett-Packard Company -> HP Inc.)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-07-22] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-07-22] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-07-22] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-07-22] (Microsoft Corporation -> Microsoft Corporation)
 
FireFox:
========
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation ->  Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\SysWOW64\Adobe\Director\np32dsw_1204144.dll [2013-09-05] (Adobe Systems, Inc.) [File not signed]
FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll [No File]
FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll [No File]
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2016-07-19] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation ->  Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2019-07-22] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2013-02-06] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-07-31] (Google Inc -> Google LLC)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-07-31] (Google Inc -> Google LLC)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\3\NP_wtapp.dll [No File]
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2019-06-10] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1409944621-189731363-133459071-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050213346: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Jacquelyn\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [No File]
FF Plugin HKU\S-1-5-21-1409944621-189731363-133459071-1005: @zoom.us/ZoomVideoPlugin -> C:\Users\Annette\AppData\Roaming\Zoom\bin\npzoomplugin.dll [2017-11-05] (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FF Plugin HKU\S-1-5-21-1409944621-189731363-133459071-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050214551: @zoom.us/ZoomVideoPlugin -> C:\Users\Annette\AppData\Roaming\Zoom\bin\npzoomplugin.dll [2017-11-05] (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
 
Chrome: 
=======
CHR DefaultProfile: Profile 1
CHR HomePage: Profile 1 -> mysearch.avg.com
CHR Profile: C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default [2019-04-04]
CHR Extension: (Slides) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-07-29]
CHR Extension: (Docs) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-07-29]
CHR Extension: (Google Drive) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-07-29]
CHR Extension: (YouTube) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-07-29]
CHR Extension: (Honey) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmnlcjabgnpnenekpadlanbbkooimhnj [2018-07-29]
CHR Extension: (Adobe Acrobat) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-03-26]
CHR Extension: (Sheets) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-07-29]
CHR Extension: (Yahoo Partner) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\fpdpdomdpmhpgncppolomeniknkgpbhm [2018-05-09]
CHR Extension: (Google Docs Offline) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-07-29]
CHR Extension: (Piggy - Automatic Coupons & Cash Back) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\hfapbcheiepjppjbnkphkmegjlipojba [2018-07-18]
CHR Extension: (HP Network Check Launcher) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\jkfpchpiljkaemlpmpebnglgkomamfeo [2017-03-26]
CHR Extension: (Grammarly for Chrome) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbfnbcaeplbcioakkpcpgfkobkghlhen [2018-08-03]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-07]
CHR Extension: (No Name) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbjikboenpfhbbejgkoklgkhjpfogcam [2018-07-29]
CHR Extension: (Gmail) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-07-29]
CHR Extension: (Chrome Media Router) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-07-27]
CHR Profile: C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1 [2019-08-09]
CHR Extension: (Slides) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-07-29]
CHR Extension: (Docs) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2018-07-29]
CHR Extension: (Google Drive) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-11-06]
CHR Extension: (DuckDuckGo) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bkdgflcldnnnapblkhphbgpggdiikppg [2019-07-22]
CHR Extension: (YouTube) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-07-29]
CHR Extension: (AVG Secure Search) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\chfdnecihphmhljaaejmgoiahnihplgn [2019-08-04]
CHR Extension: (Adobe Acrobat) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2019-08-04]
CHR Extension: (Sheets) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-07-29]
CHR Extension: (Google Docs Offline) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-08-25]
CHR Extension: (ShopRunner) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ianmjeonbapghpedipabfmiffojmolma [2019-08-09]
CHR Extension: (Search Encrypt) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge [2019-08-08]
CHR Extension: (HP Network Check Launcher) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\jkfpchpiljkaemlpmpebnglgkomamfeo [2018-08-31]
CHR Extension: (Yahoo Web) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\njajpefejmjnhcddhaleakkcehiilppa [2018-08-03]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-07-29]
CHR Extension: (Search Encrypt) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp [2019-08-08]
CHR Extension: (Gmail) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-07-22]
CHR Extension: (Chrome Media Router) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-08-08]
CHR Profile: C:\Users\Annette\AppData\Local\Google\Chrome\User Data\System Profile [2019-04-04]
CHR HKLM-x32\…\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [jkfpchpiljkaemlpmpebnglgkomamfeo] - hxxps://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AdaptiveSleepService; C:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe [140288 2014-06-05] () [File not signed]
R2 AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [239616 2013-09-25] (Microsoft Windows Hardware Compatibility Publisher -> AMD)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2014-06-05] (Advanced Micro Devices, Inc.) [File not signed]
R2 Cachedrv server; C:\Program Files\Hewlett-Packard\SimplePass\cachesrvr.exe [109568 2013-09-26] () [File not signed]
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [11153952 2019-06-27] (Microsoft Corporation -> Microsoft Corporation)
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [333688 2018-06-13] (HP Inc. -> HP Inc.)
R2 HPWMISVC; C:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe [628768 2017-07-13] (HP Inc. -> HP Inc.)
R2 HuaweiHiSuiteService64.exe; C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe [190784 2018-04-20] (Huawei Technologies Co., Ltd. -> ) [File not signed]
S2 KSDE1.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 1.0\ksde.exe [241544 2016-06-28] (Kaspersky Lab -> AO Kaspersky Lab)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6744288 2019-06-26] (Malwarebytes Corporation -> Malwarebytes)
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [4278112 2013-08-02] (Symantec Corporation -> Symantec Corporation)
R2 omniserv; C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe [87552 2013-09-26] (Softex Inc.) [File not signed]
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [310016 2016-02-19] (Realtek Semiconductor Corp -> Realtek Semiconductor)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [361824 2017-01-12] (Microsoft Corporation -> Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [119872 2017-01-12] (Microsoft Corporation -> Microsoft Corporation)
S2 DSAO; "C:\Program Files (x86)\driver support\svc\DriverSupportAOsvc.exe" [X]
S3 GamesAppService; "C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe" [X]
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 AmdAS4; C:\Windows\System32\drivers\AmdAS4.sys [17640 2017-07-21] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, INC.)
R3 amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [12533760 2013-09-25] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.)
R3 amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [619008 2013-09-25] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [222720 2017-07-21] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices)
S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-12] (Broadcom Corporation -> Windows (R) Win 7 DDK provider)
S3 dg_ssudbus; C:\Windows\system32\DRIVERS\ssudbus.sys [131984 2017-05-18] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [153328 2019-01-08] (Malwarebytes Corporation -> Malwarebytes)
S3 ew_usbccgpfilter; C:\Windows\System32\drivers\ew_usbccgpfilter.sys [18944 2018-04-20] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
U5 hw_usbdev; C:\Windows\System32\Drivers\hw_usbdev.sys [116864 2018-04-20] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
R3 kltap; C:\Windows\system32\DRIVERS\kltap.sys [52152 2016-06-07] (AnchorFree Inc -> The OpenVPN Project)
R2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [199768 2019-08-07] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMFarflt; C:\Windows\System32\DRIVERS\farflt.sys [224408 2019-08-07] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMProtection; C:\Windows\system32\DRIVERS\mbam.sys [73584 2019-08-07] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [275232 2019-08-07] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMWebProtection; C:\Windows\system32\DRIVERS\mwac.sys [116112 2019-08-07] (Malwarebytes Corporation -> Malwarebytes)
R3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [294104 2014-11-28] (Realtek Semiconductor Corp -> Realtek Semiconductor Corp.)
R3 RTWlanE; C:\Windows\system32\DRIVERS\rtwlane.sys [3636440 2014-12-22] (Realtek Semiconductor Corp -> Realtek Semiconductor Corporation )
R3 RTWlanE; C:\Windows\SysWOW64\DRIVERS\rtwlane.sys [2945240 2013-09-12] (Realtek Semiconductor Corp -> Realtek Semiconductor Corporation )
S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [30448 2013-07-26] (Synaptics Incorporated -> Synaptics Incorporated)
S3 SmbDrvI; C:\Windows\System32\drivers\Smb_driver_Intel.sys [34544 2013-07-26] (Synaptics Incorporated -> Synaptics Incorporated)
S3 ssudmdm; C:\Windows\system32\DRIVERS\ssudmdm.sys [166288 2017-05-18] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
S3 usbrndis6; C:\Windows\system32\DRIVERS\usb80236.sys [20992 2015-04-24] (Microsoft Windows -> Microsoft Corporation)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [46600 2017-02-10] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WDC_SAM; C:\Windows\System32\drivers\wdcsam64.sys [26880 2015-11-12] (WDKTestCert wdclab,130885612892544312 -> Western Digital Technologies, Inc.)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [274776 2017-01-12] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [117592 2017-01-12] (Microsoft Windows -> Microsoft Corporation)
R3 WirelessButtonDriver; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [30384 2015-06-23] (Hewlett-Packard Company -> HP Inc.)
S1 epp; \??\C:\Program Files\Emsisoft Anti-Malware\epp.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One month (created) ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2019-08-08 19:39 - 2019-08-08 19:39 - 002096640 _____ (Farbar) C:\Users\Annette\Desktop\FRST64 (1).exe
2019-08-07 21:53 - 2019-08-07 21:53 - 000224408 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
2019-08-07 21:53 - 2019-08-07 21:53 - 000199768 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys
2019-08-07 21:53 - 2019-08-07 21:53 - 000116112 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2019-08-07 21:53 - 2019-08-07 21:53 - 000073584 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2019-08-07 21:52 - 2019-08-07 21:52 - 000275232 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2019-08-07 21:52 - 2019-08-07 21:52 - 000001850 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2019-08-07 21:52 - 2019-08-07 21:52 - 000001850 _____ C:\ProgramData\Desktop\Malwarebytes.lnk
2019-08-07 21:52 - 2019-08-07 21:52 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2019-08-07 21:52 - 2019-01-08 16:32 - 000153328 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbae64.sys
2019-08-07 21:44 - 2019-08-07 21:47 - 064333800 _____ (Malwarebytes ) C:\Users\Annette\Desktop\mb3-setup-1878.1878-3.8.3.2965 (1).exe
2019-08-06 16:30 - 2019-08-06 16:30 - 064333800 _____ (Malwarebytes ) C:\Users\Annette\Desktop\mb3-setup-1878.1878-3.8.3.2965.exe
2019-08-05 23:20 - 2019-08-05 23:20 - 002096640 _____ (Farbar) C:\Users\Annette\Desktop\FRST64.exe
2019-08-04 16:27 - 2019-08-04 16:28 - 007623880 _____ (Malwarebytes) C:\Users\Annette\Desktop\ADWCLNR.exe
2019-08-01 08:12 - 2019-08-01 23:14 - 000002352 _____ C:\Users\Annette\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive for Business.lnk
2019-07-31 21:46 - 2019-07-31 21:46 - 000002448 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype for Business.lnk
2019-07-31 21:46 - 2019-07-31 21:46 - 000002443 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk
2019-07-31 21:46 - 2019-07-31 21:46 - 000002442 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk
2019-07-31 21:46 - 2019-07-31 21:46 - 000002406 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access.lnk
2019-07-31 21:46 - 2019-07-31 21:46 - 000002405 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk
2019-07-31 21:46 - 2019-07-31 21:46 - 000002399 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook.lnk
2019-07-31 21:46 - 2019-07-31 21:46 - 000002393 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher.lnk
2019-07-31 21:46 - 2019-07-31 21:46 - 000002385 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk
2019-07-31 21:46 - 2019-07-31 21:46 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools
2019-07-22 23:15 - 2019-08-02 00:40 - 000000000 ____D C:\Users\Annette\free ebooks
 
==================== One month (modified) ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2019-08-09 05:15 - 2019-04-02 19:58 - 000042072 _____ C:\Users\Annette\Desktop\FRST.txt
2019-08-09 05:11 - 2019-04-02 19:50 - 000000000 ____D C:\FRST
2019-08-09 05:05 - 2015-11-17 17:45 - 000003942 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{3464BE36-788D-4EB3-890E-849F1DD7BE9F}
2019-08-08 19:30 - 2018-04-14 00:12 - 000000572 _____ C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-1409944621-189731363-133459071-1005.job
2019-08-08 19:08 - 2013-08-22 10:36 - 000000000 ____D C:\Windows\rescache
2019-08-08 18:52 - 2015-09-14 16:50 - 000003596 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1409944621-189731363-133459071-1005
2019-08-08 18:48 - 2013-08-22 10:36 - 000000000 ___HD C:\Program Files\WindowsApps
2019-08-08 18:48 - 2013-08-22 10:36 - 000000000 ____D C:\Windows\AppReadiness
2019-08-08 18:41 - 2018-04-14 00:12 - 000000668 _____ C:\Windows\Tasks\G2MUploadTask-S-1-5-21-1409944621-189731363-133459071-1005.job
2019-08-08 18:13 - 2013-08-22 10:20 - 000000000 ____D C:\Windows\CbsTemp
2019-08-07 21:51 - 2019-04-07 22:41 - 000000000 ____D C:\Program Files\Malwarebytes
2019-08-07 21:51 - 2016-02-13 23:07 - 000000000 ____D C:\ProgramData\Malwarebytes
2019-08-07 21:50 - 2014-11-19 18:48 - 000002251 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2019-08-07 21:41 - 2015-09-14 16:49 - 000000000 ____D C:\Users\Annette\Documents\Youcam
2019-08-07 21:37 - 2018-08-10 22:13 - 000000000 ____D C:\Users\Annette\AppData\Local\CrashDumps
2019-08-07 21:37 - 2015-09-14 16:49 - 000000000 ___DO C:\Users\Annette\OneDrive
2019-08-07 21:31 - 2015-03-19 15:56 - 000000000 ____D C:\ProgramData\boost_interprocess
2019-08-07 21:30 - 2017-03-08 20:56 - 000000000 ____D C:\ProgramData\Kaspersky Lab
2019-08-07 21:27 - 2019-04-09 23:58 - 000000000 ____D C:\Program Files\Emsisoft Anti-Malware
2019-08-07 21:27 - 2013-08-22 09:45 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2019-08-07 21:27 - 2013-08-22 08:25 - 000524288 ___SH C:\Windows\system32\config\BBI
2019-08-07 21:24 - 2017-03-11 09:31 - 000000000 ____D C:\ProgramData\Emsisoft
2019-08-06 16:26 - 2016-08-21 23:56 - 000030720 ___SH C:\Users\Annette\Desktop\Thumbs.db
2019-08-05 20:43 - 2013-08-22 08:36 - 000000000 ____D C:\Windows\Inf
2019-08-04 19:03 - 2016-03-24 09:59 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2019-08-04 18:56 - 2013-08-22 08:25 - 000000262 _____ C:\Windows\win.ini
2019-08-04 18:42 - 2014-11-23 19:05 - 136618864 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2019-08-04 18:42 - 2014-11-23 19:05 - 000000000 ____D C:\Windows\system32\MRT
2019-08-04 16:39 - 2015-04-07 21:03 - 000000000 ____D C:\Users\Annette
2019-08-04 16:30 - 2018-04-14 00:11 - 000000000 ____D C:\Users\Annette\AppData\Local\GoToMeeting
2019-08-02 00:45 - 2015-01-14 17:12 - 000004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2019-08-02 00:42 - 2015-12-12 14:20 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2019-08-01 23:23 - 2018-12-22 12:09 - 000003182 _____ C:\Windows\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1409944621-189731363-133459071-1005
2019-08-01 00:05 - 2014-11-19 18:47 - 000003332 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2019-08-01 00:05 - 2014-11-19 18:47 - 000003204 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2019-07-31 22:17 - 2018-04-14 00:12 - 000003676 _____ C:\Windows\System32\Tasks\G2MUploadTask-S-1-5-21-1409944621-189731363-133459071-1005
2019-07-31 22:17 - 2018-04-14 00:12 - 000003580 _____ C:\Windows\System32\Tasks\G2MUpdateTask-S-1-5-21-1409944621-189731363-133459071-1005
2019-07-31 21:57 - 2013-08-22 10:36 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2019-07-31 21:37 - 2014-04-22 12:28 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2019-07-22 21:12 - 2014-09-09 21:21 - 000065536 _____ C:\Windows\system32\spu_storage.bin
 
==================== SigCheck ===============================
 
(There is no automatic fix for files that do not pass verification.)
 
 
LastRegBack: 2019-08-08 18:54
==================== End of FRST.txt ============================Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 07-08-2019 02
Ran by [removed] (administrator) on MRSJOHNSON (Hewlett-Packard HP 15 Notebook PC) (09-08-2019 05:11:38)
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows 8.1 (Update) (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
() [File not signed] C:\Program Files\ATI Technologies\ATI.ACE\a4\AdaptiveSleepService.exe
() [File not signed] C:\Program Files\Hewlett-Packard\SimplePass\cachesrvr.exe
() [File not signed] C:\Program Files\Hewlett-Packard\SimplePass\opvapp.exe
(Adobe Systems, Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Advanced Micro Devices, Inc.) [File not signed] C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(CenturyLink -> CenturyLink Inc) C:\Program Files (x86)\CenturyLink\Desktop\CenturyLinkTouchPointAgent.exe
(CyberLink Corp. -> CyberLink Corp.) C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe
(Google Inc -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.34.11\GoogleCrashHandler.exe
(Google Inc -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.34.11\GoogleCrashHandler64.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(HP Inc. -> HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(HP Inc. -> HP Inc.) C:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe
(Huawei Technologies Co., Ltd. -> ) [File not signed] C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe
(Intuit, Inc. -> Intuit Inc.) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
(Malwarebytes Corporation -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Corporation -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\StikyNot.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atiesrxx.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Softex Inc.) [File not signed] C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe
(Softex Incorporated -> Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\HPSmplPass.exe
(Softex Incorporated -> Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBroker.exe
(Softex Incorporated -> Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe
(Symantec Corporation -> Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
(Symantec Corporation -> Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [SimplePass] => C:\Program Files\Hewlett-Packard\SimplePass\HPSmplPass.exe [2755640 2013-09-26] (Softex Incorporated -> Hewlett-Packard)
HKLM\…\Run: [OPBHOBroker] => C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBroker.exe [155704 2013-09-26] (Softex Incorporated -> Hewlett-Packard)
HKLM\…\Run: [OPBHOBrokerDesktop] => C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe [155704 2013-09-26] (Softex Incorporated -> Hewlett-Packard)
HKLM\…\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2771184 2013-07-26] (Synaptics Incorporated -> Synaptics Incorporated)
HKLM\…\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8843520 2016-02-19] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\…\Run: [WindowsDefender] => "%ProgramFiles%\Windows Defender\MSASCuiL.exe"
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [507776 2014-10-07] (Oracle America, Inc. -> Oracle Corporation)
HKLM-x32\…\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation -> Microsoft Corporation)
HKLM-x32\…\Run: [CenturyLinkTouchPointAgent] => C:\Program Files (x86)\CenturyLink\Desktop\CenturyLinkTouchPointAgent.exe [48904 2014-11-04] (CenturyLink -> CenturyLink Inc)
HKLM-x32\…\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767200 2014-06-06] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
HKLM-x32\…\Run: [HPMessageService] => C:\Program Files (x86)\HP\HP System Event\HPMSGSVC.exe [707624 2018-08-08] (HP Inc. -> HP Inc.)
HKU\S-1-5-21-1409944621-189731363-133459071-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050213346\…\Run: [Power2GoExpress8] => C:\Program Files (x86)\CyberLink\Power2Go8\Power2GoExpress8.exe [1728952 2015-06-22] (CyberLink Corp. -> CyberLink Corp.)
HKU\S-1-5-21-1409944621-189731363-133459071-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050213346\…\Run: [B0CA40A7B020DFFA8668D20001A42ED77693A62A._service_run] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1535472 2019-08-05] (Google LLC -> Google LLC)
HKU\S-1-5-21-1409944621-189731363-133459071-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050213346\…\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [479744 2014-10-28] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-21-1409944621-189731363-133459071-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050213346\…\MountPoints2: {e1d9e33d-70cc-11e4-825e-3863bb8eae0e} - "F:\AutoRun.exe" 
HKU\S-1-5-21-1409944621-189731363-133459071-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050213346\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Bubbles.scr [788480 2014-10-28] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\Run: [GoogleChromeAutoLaunch_0C9337CDD31A557C75EB2CDF52C45A5A] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1535472 2019-08-05] (Google LLC -> Google LLC)
HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [479744 2014-10-28] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\MountPoints2: {0971029e-8ae2-11e8-830f-3863bb8eae0e} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\MountPoints2: {097102d7-8ae2-11e8-830f-3863bb8eae0e} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\MountPoints2: {803e9b84-3b72-11e8-8302-3863bb8eae0e} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\MountPoints2: {ed76fc77-6b0a-11e5-8270-3863bb8eae0e} - "F:\AutoRun.exe" 
HKU\S-1-5-21-1409944621-189731363-133459071-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050214551\…\Run: [GoogleChromeAutoLaunch_0C9337CDD31A557C75EB2CDF52C45A5A] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1535472 2019-08-05] (Google LLC -> Google LLC)
HKU\S-1-5-21-1409944621-189731363-133459071-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050214551\…\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [479744 2014-10-28] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-21-1409944621-189731363-133459071-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050214551\…\MountPoints2: {0971029e-8ae2-11e8-830f-3863bb8eae0e} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-1409944621-189731363-133459071-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050214551\…\MountPoints2: {097102d7-8ae2-11e8-830f-3863bb8eae0e} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-1409944621-189731363-133459071-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050214551\…\MountPoints2: {803e9b84-3b72-11e8-8302-3863bb8eae0e} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-1409944621-189731363-133459071-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050214551\…\MountPoints2: {ed76fc77-6b0a-11e5-8270-3863bb8eae0e} - "F:\AutoRun.exe" 
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\76.0.3809.100\Installer\chrmstp.exe [2019-08-07] (Google LLC -> Google LLC)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{A6EADE66-0000-0000-484E-7E8A45000000}] -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Esl\AiodLite.dll [2019-06-10] (Adobe Inc. -> Adobe Systems, Inc.)
HKLM\Software\…\Authentication\Credential Providers: [{538C240D-3DEE-4032-AB4C-08A3A6EB0861}] -> C:\Program Files (x86)\CyberLink\YouCam\CLCredProv\x64\CLCredProv.dll [2014-10-28] (CyberLink Corp. -> CyberLink)
HKLM\Software\…\Authentication\Credential Providers: [{F3F1B0FA-4775-41d8-8578-436772D93FB4}] -> C:\Program Files\Hewlett-Packard\SimplePass\OmniPassCredProv.dll [2013-09-26] (Softex Inc..) [File not signed]
HKLM\Software\…\Authentication\Credential Provider Filters: [{F3F1B0FA-4775-41d8-8578-436772D93FB4}] -> C:\Program Files\Hewlett-Packard\SimplePass\OmniPassCredProv.dll [2013-09-26] (Softex Inc..) [File not signed]
Startup: C:\Users\Annette\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Facebook Gameroom.lnk [2018-08-03]
ShortcutTarget: Facebook Gameroom.lnk -> C:\Users\Annette\AppData\Local\Facebook\Games\FacebookGameroom.exe (Facebook, Inc. -> Facebook) [File not signed]
Startup: C:\Users\Annette\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk [2018-01-08]
ShortcutTarget: Send to OneNote.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE (Microsoft Corporation -> Microsoft Corporation)
Startup: C:\Users\Jacquelyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk [2016-05-14]
ShortcutTarget: Send to OneNote.lnk -> C:\Program Files (x86)\Microsoft Office\Office15\ONENOTEM.EXE (Microsoft Corporation -> Microsoft Corporation)
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {10A0396E-4397-432D-A61A-B29936C98279} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-09-27] (Google Inc -> Google Inc.)
Task: {246C5721-0523-4DE8-812A-4947EAF60BFB} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1195544 2018-12-16] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
Task: {2FE82A44-7615-47C1-88DD-E0D568E5D0F2} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe
Task: {3165798A-F44B-4387-8B96-BD947DFDF94F} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [376496 2014-01-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {3CCC318D-E72D-4C49-9C74-C4C063155CBC} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\sdxhelper.exe [103464 2019-07-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {3E898CDD-32F4-47D1-A2F4-BCF33E88AEBC} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [651400 2017-09-20] (Hewlett Packard -> HP Inc.)
Task: {422808BD-6F70-41BF-945D-E13AA06AE45A} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis Install => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [1459056 2018-05-04] (HP Inc. -> HP Inc.)
Task: {468B13AD-B541-4A27-B004-9B018EEA3275} - System32\Tasks\Java Platform SE Auto Updater => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [507776 2014-10-07] (Oracle America, Inc. -> Oracle Corporation)
Task: {48426B74-A917-4AA1-A961-4CBF7B9F1EC5} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [1403536 2019-07-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {5200926D-6DAC-44AC-95C0-5C3C6F4AEBD1} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26045472 2019-06-27] (Microsoft Corporation -> Microsoft Corporation)
Task: {54D4B427-D571-42BD-AD1D-6FB9814F3F84} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [1403536 2019-07-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {55DCE214-7F3F-463F-BECE-5A67E73B6324} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [1459056 2018-05-04] (HP Inc. -> HP Inc.)
Task: {562E632A-822A-4DE0-8BCC-5EE113487084} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26045472 2019-06-27] (Microsoft Corporation -> Microsoft Corporation)
Task: {5B7B1C4A-9A07-4CAC-869E-5279651131BE} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [376496 2014-01-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {69D3BA23-D578-4DE2-AFDE-D9EF27762CEC} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-09-27] (Google Inc -> Google Inc.)
Task: {85D70D96-CB3D-4E56-AB0F-24B26C54D6BF} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [1059704 2018-11-09] (HP Inc. -> HP Inc.)
Task: {B73A7C7B-CF7F-4A7E-A613-BFBB8A73789D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater - Resources => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [651400 2017-09-20] (Hewlett Packard -> HP Inc.)
Task: {B95640C8-286C-4ADA-AF7B-A685867BC4F3} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task => {3519154C-227E-47F3-9CC9-12C3F05817F1}
Task: {BA1B1F3F-67C4-4B2E-AC43-EFB3069BC508} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\sdxhelper.exe [103464 2019-07-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {C20748E5-0782-4E30-A3BC-A01FF02DECE2} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [4404888 2019-07-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {C45E956E-E070-4332-B57C-DF9D8B626B72} - System32\Tasks\Hewlett-Packard\HP Active Health\HP Active Health Scan (HPSA) => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.exe [198696 2016-11-07] (HP Inc. -> HP Inc.)
Task: {C7300FA3-0507-4B0B-9200-F7F2EF465D7B} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [4404888 2019-07-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {CD39A3B5-0980-4947-BD6C-3D87425A7FCE} - System32\Tasks\Synaptics TouchPad Enhancements => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2771184 2013-07-26] (Synaptics Incorporated -> Synaptics Incorporated)
Task: {CE133C13-C983-4DC1-90A2-2F3469BB80A3} - System32\Tasks\RogueKiller Anti-Malware => C:\Users\Annette\Desktop\RogueKiller_portable64.exe
Task: {D04BBF70-03A8-413B-9CA3-5AC3314706E2} - System32\Tasks\G2MUpdateTask-S-1-5-21-1409944621-189731363-133459071-1005 => C:\Users\Annette\AppData\Local\GoToMeeting\13761\g2mupdate.exe [32256 2019-07-31] (LogMeIn, Inc. -> LogMeIn, Inc.)
Task: {D0F920D8-40AD-4B42-9F6C-ADA01607FCCD} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Product Configurator => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\ProductConfig.exe [217976 2018-11-08] (HP Inc. -> HP Inc.)
Task: {D5C531E1-84FD-4B99-81A6-F1B6E401FECD} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [758400 2019-07-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {DCEFA36E-E149-4C02-99DB-E3F29CC3066E} - System32\Tasks\YCMServiceAgent => C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe [267224 2014-10-28] (CyberLink Corp. -> CyberLink Corp.)
Task: {E6B7EE15-0DF8-473B-AA30-3C92EDE7356E} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [1459056 2018-05-04] (HP Inc. -> HP Inc.)
Task: {EC860F0E-1C8E-4761-BA2C-9ACF03169D98} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [124280 2018-08-17] (HP Inc. -> HP Inc.)
Task: {EFE6E304-849C-4527-A6F6-903B564B9663} - System32\Tasks\G2MUploadTask-S-1-5-21-1409944621-189731363-133459071-1005 => C:\Users\Annette\AppData\Local\GoToMeeting\13761\g2mupload.exe [32256 2019-07-31] (LogMeIn, Inc. -> LogMeIn, Inc.)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-1409944621-189731363-133459071-1005.job => C:\Users\Annette\AppData\Local\GoToMeeting\13761\g2mupdate.exe
Task: C:\Windows\Tasks\G2MUploadTask-S-1-5-21-1409944621-189731363-133459071-1005.job => C:\Users\Annette\AppData\Local\GoToMeeting\13761\g2mupload.exe
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{2BE7FA48-E3A9-4398-8011-4CBB02E6ACC5}: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{8E02059E-EC13-441B-AFD6-CD70C258610A}: [DhcpNameServer] 192.168.0.1 [removed]
 
Internet Explorer:
==================
HKU\S-1-5-21-1409944621-189731363-133459071-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050213346\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/HPNOT14/1
HKU\S-1-5-21-1409944621-189731363-133459071-1005\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/
HKU\S-1-5-21-1409944621-189731363-133459071-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050214551\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/
SearchScopes: HKU\S-1-5-21-1409944621-189731363-133459071-1005 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1409944621-189731363-133459071-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050214551 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2019-06-25] (Microsoft Corporation -> Microsoft Corporation)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation -> Microsoft Corporation)
BHO: No Name -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> No File
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2016-07-21] (Hewlett-Packard Company -> HP Inc.)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2019-06-25] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: No Name -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> No File
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2016-07-21] (Hewlett-Packard Company -> HP Inc.)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-07-22] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-07-22] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-07-22] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-07-22] (Microsoft Corporation -> Microsoft Corporation)
 
FireFox:
========
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation ->  Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\SysWOW64\Adobe\Director\np32dsw_1204144.dll [2013-09-05] (Adobe Systems, Inc.) [File not signed]
FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll [No File]
FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll [No File]
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2016-07-19] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation ->  Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2019-07-22] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2013-02-06] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-07-31] (Google Inc -> Google LLC)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-07-31] (Google Inc -> Google LLC)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\3\NP_wtapp.dll [No File]
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2019-06-10] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1409944621-189731363-133459071-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050213346: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Jacquelyn\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [No File]
FF Plugin HKU\S-1-5-21-1409944621-189731363-133459071-1005: @zoom.us/ZoomVideoPlugin -> C:\Users\Annette\AppData\Roaming\Zoom\bin\npzoomplugin.dll [2017-11-05] (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FF Plugin HKU\S-1-5-21-1409944621-189731363-133459071-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050214551: @zoom.us/ZoomVideoPlugin -> C:\Users\Annette\AppData\Roaming\Zoom\bin\npzoomplugin.dll [2017-11-05] (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
 
Chrome: 
=======
CHR DefaultProfile: Profile 1
CHR HomePage: Profile 1 -> mysearch.avg.com
CHR Profile: C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default [2019-04-04]
CHR Extension: (Slides) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-07-29]
CHR Extension: (Docs) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-07-29]
CHR Extension: (Google Drive) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-07-29]
CHR Extension: (YouTube) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-07-29]
CHR Extension: (Honey) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmnlcjabgnpnenekpadlanbbkooimhnj [2018-07-29]
CHR Extension: (Adobe Acrobat) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-03-26]
CHR Extension: (Sheets) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-07-29]
CHR Extension: (Yahoo Partner) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\fpdpdomdpmhpgncppolomeniknkgpbhm [2018-05-09]
CHR Extension: (Google Docs Offline) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-07-29]
CHR Extension: (Piggy - Automatic Coupons & Cash Back) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\hfapbcheiepjppjbnkphkmegjlipojba [2018-07-18]
CHR Extension: (HP Network Check Launcher) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\jkfpchpiljkaemlpmpebnglgkomamfeo [2017-03-26]
CHR Extension: (Grammarly for Chrome) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbfnbcaeplbcioakkpcpgfkobkghlhen [2018-08-03]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-07]
CHR Extension: (No Name) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbjikboenpfhbbejgkoklgkhjpfogcam [2018-07-29]
CHR Extension: (Gmail) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-07-29]
CHR Extension: (Chrome Media Router) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-07-27]
CHR Profile: C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1 [2019-08-09]
CHR Extension: (Slides) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-07-29]
CHR Extension: (Docs) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2018-07-29]
CHR Extension: (Google Drive) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-11-06]
CHR Extension: (DuckDuckGo) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bkdgflcldnnnapblkhphbgpggdiikppg [2019-07-22]
CHR Extension: (YouTube) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-07-29]
CHR Extension: (AVG Secure Search) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\chfdnecihphmhljaaejmgoiahnihplgn [2019-08-04]
CHR Extension: (Adobe Acrobat) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2019-08-04]
CHR Extension: (Sheets) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-07-29]
CHR Extension: (Google Docs Offline) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-08-25]
CHR Extension: (ShopRunner) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ianmjeonbapghpedipabfmiffojmolma [2019-08-09]
CHR Extension: (Search Encrypt) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge [2019-08-08]
CHR Extension: (HP Network Check Launcher) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\jkfpchpiljkaemlpmpebnglgkomamfeo [2018-08-31]
CHR Extension: (Yahoo Web) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\njajpefejmjnhcddhaleakkcehiilppa [2018-08-03]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-07-29]
CHR Extension: (Search Encrypt) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp [2019-08-08]
CHR Extension: (Gmail) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-07-22]
CHR Extension: (Chrome Media Router) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-08-08]
CHR Profile: C:\Users\Annette\AppData\Local\Google\Chrome\User Data\System Profile [2019-04-04]
CHR HKLM-x32\…\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [jkfpchpiljkaemlpmpebnglgkomamfeo] - hxxps://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AdaptiveSleepService; C:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe [140288 2014-06-05] () [File not signed]
R2 AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [239616 2013-09-25] (Microsoft Windows Hardware Compatibility Publisher -> AMD)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2014-06-05] (Advanced Micro Devices, Inc.) [File not signed]
R2 Cachedrv server; C:\Program Files\Hewlett-Packard\SimplePass\cachesrvr.exe [109568 2013-09-26] () [File not signed]
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [11153952 2019-06-27] (Microsoft Corporation -> Microsoft Corporation)
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [333688 2018-06-13] (HP Inc. -> HP Inc.)
R2 HPWMISVC; C:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe [628768 2017-07-13] (HP Inc. -> HP Inc.)
R2 HuaweiHiSuiteService64.exe; C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe [190784 2018-04-20] (Huawei Technologies Co., Ltd. -> ) [File not signed]
S2 KSDE1.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 1.0\ksde.exe [241544 2016-06-28] (Kaspersky Lab -> AO Kaspersky Lab)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6744288 2019-06-26] (Malwarebytes Corporation -> Malwarebytes)
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [4278112 2013-08-02] (Symantec Corporation -> Symantec Corporation)
R2 omniserv; C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe [87552 2013-09-26] (Softex Inc.) [File not signed]
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [310016 2016-02-19] (Realtek Semiconductor Corp -> Realtek Semiconductor)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [361824 2017-01-12] (Microsoft Corporation -> Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [119872 2017-01-12] (Microsoft Corporation -> Microsoft Corporation)
S2 DSAO; "C:\Program Files (x86)\driver support\svc\DriverSupportAOsvc.exe" [X]
S3 GamesAppService; "C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe" [X]
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 AmdAS4; C:\Windows\System32\drivers\AmdAS4.sys [17640 2017-07-21] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, INC.)
R3 amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [12533760 2013-09-25] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.)
R3 amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [619008 2013-09-25] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [222720 2017-07-21] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices)
S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-12] (Broadcom Corporation -> Windows (R) Win 7 DDK provider)
S3 dg_ssudbus; C:\Windows\system32\DRIVERS\ssudbus.sys [131984 2017-05-18] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [153328 2019-01-08] (Malwarebytes Corporation -> Malwarebytes)
S3 ew_usbccgpfilter; C:\Windows\System32\drivers\ew_usbccgpfilter.sys [18944 2018-04-20] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
U5 hw_usbdev; C:\Windows\System32\Drivers\hw_usbdev.sys [116864 2018-04-20] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
R3 kltap; C:\Windows\system32\DRIVERS\kltap.sys [52152 2016-06-07] (AnchorFree Inc -> The OpenVPN Project)
R2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [199768 2019-08-07] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMFarflt; C:\Windows\System32\DRIVERS\farflt.sys [224408 2019-08-07] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMProtection; C:\Windows\system32\DRIVERS\mbam.sys [73584 2019-08-07] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [275232 2019-08-07] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMWebProtection; C:\Windows\system32\DRIVERS\mwac.sys [116112 2019-08-07] (Malwarebytes Corporation -> Malwarebytes)
R3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [294104 2014-11-28] (Realtek Semiconductor Corp -> Realtek Semiconductor Corp.)
R3 RTWlanE; C:\Windows\system32\DRIVERS\rtwlane.sys [3636440 2014-12-22] (Realtek Semiconductor Corp -> Realtek Semiconductor Corporation )
R3 RTWlanE; C:\Windows\SysWOW64\DRIVERS\rtwlane.sys [2945240 2013-09-12] (Realtek Semiconductor Corp -> Realtek Semiconductor Corporation )
S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [30448 2013-07-26] (Synaptics Incorporated -> Synaptics Incorporated)
S3 SmbDrvI; C:\Windows\System32\drivers\Smb_driver_Intel.sys [34544 2013-07-26] (Synaptics Incorporated -> Synaptics Incorporated)
S3 ssudmdm; C:\Windows\system32\DRIVERS\ssudmdm.sys [166288 2017-05-18] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
S3 usbrndis6; C:\Windows\system32\DRIVERS\usb80236.sys [20992 2015-04-24] (Microsoft Windows -> Microsoft Corporation)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [46600 2017-02-10] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WDC_SAM; C:\Windows\System32\drivers\wdcsam64.sys [26880 2015-11-12] (WDKTestCert wdclab,130885612892544312 -> Western Digital Technologies, Inc.)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [274776 2017-01-12] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [117592 2017-01-12] (Microsoft Windows -> Microsoft Corporation)
R3 WirelessButtonDriver; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [30384 2015-06-23] (Hewlett-Packard Company -> HP Inc.)
S1 epp; \??\C:\Program Files\Emsisoft Anti-Malware\epp.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One month (created) ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2019-08-08 19:39 - 2019-08-08 19:39 - 002096640 _____ (Farbar) C:\Users\Annette\Desktop\FRST64 (1).exe
2019-08-07 21:53 - 2019-08-07 21:53 - 000224408 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
2019-08-07 21:53 - 2019-08-07 21:53 - 000199768 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys
2019-08-07 21:53 - 2019-08-07 21:53 - 000116112 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2019-08-07 21:53 - 2019-08-07 21:53 - 000073584 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2019-08-07 21:52 - 2019-08-07 21:52 - 000275232 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2019-08-07 21:52 - 2019-08-07 21:52 - 000001850 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2019-08-07 21:52 - 2019-08-07 21:52 - 000001850 _____ C:\ProgramData\Desktop\Malwarebytes.lnk
2019-08-07 21:52 - 2019-08-07 21:52 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2019-08-07 21:52 - 2019-01-08 16:32 - 000153328 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbae64.sys
2019-08-07 21:44 - 2019-08-07 21:47 - 064333800 _____ (Malwarebytes ) C:\Users\Annette\Desktop\mb3-setup-1878.1878-3.8.3.2965 (1).exe
2019-08-06 16:30 - 2019-08-06 16:30 - 064333800 _____ (Malwarebytes ) C:\Users\Annette\Desktop\mb3-setup-1878.1878-3.8.3.2965.exe
2019-08-05 23:20 - 2019-08-05 23:20 - 002096640 _____ (Farbar) C:\Users\Annette\Desktop\FRST64.exe
2019-08-04 16:27 - 2019-08-04 16:28 - 007623880 _____ (Malwarebytes) C:\Users\Annette\Desktop\ADWCLNR.exe
2019-08-01 08:12 - 2019-08-01 23:14 - 000002352 _____ C:\Users\Annette\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive for Business.lnk
2019-07-31 21:46 - 2019-07-31 21:46 - 000002448 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype for Business.lnk
2019-07-31 21:46 - 2019-07-31 21:46 - 000002443 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk
2019-07-31 21:46 - 2019-07-31 21:46 - 000002442 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk
2019-07-31 21:46 - 2019-07-31 21:46 - 000002406 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access.lnk
2019-07-31 21:46 - 2019-07-31 21:46 - 000002405 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk
2019-07-31 21:46 - 2019-07-31 21:46 - 000002399 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook.lnk
2019-07-31 21:46 - 2019-07-31 21:46 - 000002393 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher.lnk
2019-07-31 21:46 - 2019-07-31 21:46 - 000002385 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk
2019-07-31 21:46 - 2019-07-31 21:46 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools
2019-07-22 23:15 - 2019-08-02 00:40 - 000000000 ____D C:\Users\Annette\free ebooks
 
==================== One month (modified) ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2019-08-09 05:15 - 2019-04-02 19:58 - 000042072 _____ C:\Users\Annette\Desktop\FRST.txt
2019-08-09 05:11 - 2019-04-02 19:50 - 000000000 ____D C:\FRST
2019-08-09 05:05 - 2015-11-17 17:45 - 000003942 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{3464BE36-788D-4EB3-890E-849F1DD7BE9F}
2019-08-08 19:30 - 2018-04-14 00:12 - 000000572 _____ C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-1409944621-189731363-133459071-1005.job
2019-08-08 19:08 - 2013-08-22 10:36 - 000000000 ____D C:\Windows\rescache
2019-08-08 18:52 - 2015-09-14 16:50 - 000003596 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1409944621-189731363-133459071-1005
2019-08-08 18:48 - 2013-08-22 10:36 - 000000000 ___HD C:\Program Files\WindowsApps
2019-08-08 18:48 - 2013-08-22 10:36 - 000000000 ____D C:\Windows\AppReadiness
2019-08-08 18:41 - 2018-04-14 00:12 - 000000668 _____ C:\Windows\Tasks\G2MUploadTask-S-1-5-21-1409944621-189731363-133459071-1005.job
2019-08-08 18:13 - 2013-08-22 10:20 - 000000000 ____D C:\Windows\CbsTemp
2019-08-07 21:51 - 2019-04-07 22:41 - 000000000 ____D C:\Program Files\Malwarebytes
2019-08-07 21:51 - 2016-02-13 23:07 - 000000000 ____D C:\ProgramData\Malwarebytes
2019-08-07 21:50 - 2014-11-19 18:48 - 000002251 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2019-08-07 21:41 - 2015-09-14 16:49 - 000000000 ____D C:\Users\Annette\Documents\Youcam
2019-08-07 21:37 - 2018-08-10 22:13 - 000000000 ____D C:\Users\Annette\AppData\Local\CrashDumps
2019-08-07 21:37 - 2015-09-14 16:49 - 000000000 ___DO C:\Users\Annette\OneDrive
2019-08-07 21:31 - 2015-03-19 15:56 - 000000000 ____D C:\ProgramData\boost_interprocess
2019-08-07 21:30 - 2017-03-08 20:56 - 000000000 ____D C:\ProgramData\Kaspersky Lab
2019-08-07 21:27 - 2019-04-09 23:58 - 000000000 ____D C:\Program Files\Emsisoft Anti-Malware
2019-08-07 21:27 - 2013-08-22 09:45 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2019-08-07 21:27 - 2013-08-22 08:25 - 000524288 ___SH C:\Windows\system32\config\BBI
2019-08-07 21:24 - 2017-03-11 09:31 - 000000000 ____D C:\ProgramData\Emsisoft
2019-08-06 16:26 - 2016-08-21 23:56 - 000030720 ___SH C:\Users\Annette\Desktop\Thumbs.db
2019-08-05 20:43 - 2013-08-22 08:36 - 000000000 ____D C:\Windows\Inf
2019-08-04 19:03 - 2016-03-24 09:59 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2019-08-04 18:56 - 2013-08-22 08:25 - 000000262 _____ C:\Windows\win.ini
2019-08-04 18:42 - 2014-11-23 19:05 - 136618864 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2019-08-04 18:42 - 2014-11-23 19:05 - 000000000 ____D C:\Windows\system32\MRT
2019-08-04 16:39 - 2015-04-07 21:03 - 000000000 ____D C:\Users\Annette
2019-08-04 16:30 - 2018-04-14 00:11 - 000000000 ____D C:\Users\Annette\AppData\Local\GoToMeeting
2019-08-02 00:45 - 2015-01-14 17:12 - 000004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2019-08-02 00:42 - 2015-12-12 14:20 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2019-08-01 23:23 - 2018-12-22 12:09 - 000003182 _____ C:\Windows\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1409944621-189731363-133459071-1005
2019-08-01 00:05 - 2014-11-19 18:47 - 000003332 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2019-08-01 00:05 - 2014-11-19 18:47 - 000003204 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2019-07-31 22:17 - 2018-04-14 00:12 - 000003676 _____ C:\Windows\System32\Tasks\G2MUploadTask-S-1-5-21-1409944621-189731363-133459071-1005
2019-07-31 22:17 - 2018-04-14 00:12 - 000003580 _____ C:\Windows\System32\Tasks\G2MUpdateTask-S-1-5-21-1409944621-189731363-133459071-1005
2019-07-31 21:57 - 2013-08-22 10:36 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2019-07-31 21:37 - 2014-04-22 12:28 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2019-07-22 21:12 - 2014-09-09 21:21 - 000065536 _____ C:\Windows\system32\spu_storage.bin
 
==================== SigCheck ===============================
 
(There is no automatic fix for files that do not pass verification.)
 
 
LastRegBack: 2019-08-08 18:54
==================== End of FRST.txt ============================Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 07-08-2019 02
Ran by [removed] (administrator) on MRSJOHNSON (Hewlett-Packard HP 15 Notebook PC) (09-08-2019 05:11:38)
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows 8.1 (Update) (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
() [File not signed] C:\Program Files\ATI Technologies\ATI.ACE\a4\AdaptiveSleepService.exe
() [File not signed] C:\Program Files\Hewlett-Packard\SimplePass\cachesrvr.exe
() [File not signed] C:\Program Files\Hewlett-Packard\SimplePass\opvapp.exe
(Adobe Systems, Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Advanced Micro Devices, Inc.) [File not signed] C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(CenturyLink -> CenturyLink Inc) C:\Program Files (x86)\CenturyLink\Desktop\CenturyLinkTouchPointAgent.exe
(CyberLink Corp. -> CyberLink Corp.) C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe
(Google Inc -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.34.11\GoogleCrashHandler.exe
(Google Inc -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.34.11\GoogleCrashHandler64.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(HP Inc. -> HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(HP Inc. -> HP Inc.) C:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe
(Huawei Technologies Co., Ltd. -> ) [File not signed] C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe
(Intuit, Inc. -> Intuit Inc.) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
(Malwarebytes Corporation -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Corporation -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\StikyNot.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atiesrxx.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Softex Inc.) [File not signed] C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe
(Softex Incorporated -> Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\HPSmplPass.exe
(Softex Incorporated -> Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBroker.exe
(Softex Incorporated -> Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe
(Symantec Corporation -> Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
(Symantec Corporation -> Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [SimplePass] => C:\Program Files\Hewlett-Packard\SimplePass\HPSmplPass.exe [2755640 2013-09-26] (Softex Incorporated -> Hewlett-Packard)
HKLM\…\Run: [OPBHOBroker] => C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBroker.exe [155704 2013-09-26] (Softex Incorporated -> Hewlett-Packard)
HKLM\…\Run: [OPBHOBrokerDesktop] => C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe [155704 2013-09-26] (Softex Incorporated -> Hewlett-Packard)
HKLM\…\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2771184 2013-07-26] (Synaptics Incorporated -> Synaptics Incorporated)
HKLM\…\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8843520 2016-02-19] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\…\Run: [WindowsDefender] => "%ProgramFiles%\Windows Defender\MSASCuiL.exe"
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [507776 2014-10-07] (Oracle America, Inc. -> Oracle Corporation)
HKLM-x32\…\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation -> Microsoft Corporation)
HKLM-x32\…\Run: [CenturyLinkTouchPointAgent] => C:\Program Files (x86)\CenturyLink\Desktop\CenturyLinkTouchPointAgent.exe [48904 2014-11-04] (CenturyLink -> CenturyLink Inc)
HKLM-x32\…\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767200 2014-06-06] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
HKLM-x32\…\Run: [HPMessageService] => C:\Program Files (x86)\HP\HP System Event\HPMSGSVC.exe [707624 2018-08-08] (HP Inc. -> HP Inc.)
HKU\S-1-5-21-1409944621-189731363-133459071-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050213346\…\Run: [Power2GoExpress8] => C:\Program Files (x86)\CyberLink\Power2Go8\Power2GoExpress8.exe [1728952 2015-06-22] (CyberLink Corp. -> CyberLink Corp.)
HKU\S-1-5-21-1409944621-189731363-133459071-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050213346\…\Run: [B0CA40A7B020DFFA8668D20001A42ED77693A62A._service_run] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1535472 2019-08-05] (Google LLC -> Google LLC)
HKU\S-1-5-21-1409944621-189731363-133459071-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050213346\…\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [479744 2014-10-28] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-21-1409944621-189731363-133459071-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050213346\…\MountPoints2: {e1d9e33d-70cc-11e4-825e-3863bb8eae0e} - "F:\AutoRun.exe" 
HKU\S-1-5-21-1409944621-189731363-133459071-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050213346\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Bubbles.scr [788480 2014-10-28] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\Run: [GoogleChromeAutoLaunch_0C9337CDD31A557C75EB2CDF52C45A5A] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1535472 2019-08-05] (Google LLC -> Google LLC)
HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [479744 2014-10-28] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\MountPoints2: {0971029e-8ae2-11e8-830f-3863bb8eae0e} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\MountPoints2: {097102d7-8ae2-11e8-830f-3863bb8eae0e} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\MountPoints2: {803e9b84-3b72-11e8-8302-3863bb8eae0e} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\MountPoints2: {ed76fc77-6b0a-11e5-8270-3863bb8eae0e} - "F:\AutoRun.exe" 
HKU\S-1-5-21-1409944621-189731363-133459071-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050214551\…\Run: [GoogleChromeAutoLaunch_0C9337CDD31A557C75EB2CDF52C45A5A] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1535472 2019-08-05] (Google LLC -> Google LLC)
HKU\S-1-5-21-1409944621-189731363-133459071-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050214551\…\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [479744 2014-10-28] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-21-1409944621-189731363-133459071-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050214551\…\MountPoints2: {0971029e-8ae2-11e8-830f-3863bb8eae0e} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-1409944621-189731363-133459071-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050214551\…\MountPoints2: {097102d7-8ae2-11e8-830f-3863bb8eae0e} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-1409944621-189731363-133459071-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050214551\…\MountPoints2: {803e9b84-3b72-11e8-8302-3863bb8eae0e} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-1409944621-189731363-133459071-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050214551\…\MountPoints2: {ed76fc77-6b0a-11e5-8270-3863bb8eae0e} - "F:\AutoRun.exe" 
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\76.0.3809.100\Installer\chrmstp.exe [2019-08-07] (Google LLC -> Google LLC)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{A6EADE66-0000-0000-484E-7E8A45000000}] -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Esl\AiodLite.dll [2019-06-10] (Adobe Inc. -> Adobe Systems, Inc.)
HKLM\Software\…\Authentication\Credential Providers: [{538C240D-3DEE-4032-AB4C-08A3A6EB0861}] -> C:\Program Files (x86)\CyberLink\YouCam\CLCredProv\x64\CLCredProv.dll [2014-10-28] (CyberLink Corp. -> CyberLink)
HKLM\Software\…\Authentication\Credential Providers: [{F3F1B0FA-4775-41d8-8578-436772D93FB4}] -> C:\Program Files\Hewlett-Packard\SimplePass\OmniPassCredProv.dll [2013-09-26] (Softex Inc..) [File not signed]
HKLM\Software\…\Authentication\Credential Provider Filters: [{F3F1B0FA-4775-41d8-8578-436772D93FB4}] -> C:\Program Files\Hewlett-Packard\SimplePass\OmniPassCredProv.dll [2013-09-26] (Softex Inc..) [File not signed]
Startup: C:\Users\Annette\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Facebook Gameroom.lnk [2018-08-03]
ShortcutTarget: Facebook Gameroom.lnk -> C:\Users\Annette\AppData\Local\Facebook\Games\FacebookGameroom.exe (Facebook, Inc. -> Facebook) [File not signed]
Startup: C:\Users\Annette\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk [2018-01-08]
ShortcutTarget: Send to OneNote.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE (Microsoft Corporation -> Microsoft Corporation)
Startup: C:\Users\Jacquelyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk [2016-05-14]
ShortcutTarget: Send to OneNote.lnk -> C:\Program Files (x86)\Microsoft Office\Office15\ONENOTEM.EXE (Microsoft Corporation -> Microsoft Corporation)
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {10A0396E-4397-432D-A61A-B29936C98279} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-09-27] (Google Inc -> Google Inc.)
Task: {246C5721-0523-4DE8-812A-4947EAF60BFB} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1195544 2018-12-16] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
Task: {2FE82A44-7615-47C1-88DD-E0D568E5D0F2} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe
Task: {3165798A-F44B-4387-8B96-BD947DFDF94F} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [376496 2014-01-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {3CCC318D-E72D-4C49-9C74-C4C063155CBC} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\sdxhelper.exe [103464 2019-07-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {3E898CDD-32F4-47D1-A2F4-BCF33E88AEBC} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [651400 2017-09-20] (Hewlett Packard -> HP Inc.)
Task: {422808BD-6F70-41BF-945D-E13AA06AE45A} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis Install => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [1459056 2018-05-04] (HP Inc. -> HP Inc.)
Task: {468B13AD-B541-4A27-B004-9B018EEA3275} - System32\Tasks\Java Platform SE Auto Updater => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [507776 2014-10-07] (Oracle America, Inc. -> Oracle Corporation)
Task: {48426B74-A917-4AA1-A961-4CBF7B9F1EC5} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [1403536 2019-07-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {5200926D-6DAC-44AC-95C0-5C3C6F4AEBD1} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26045472 2019-06-27] (Microsoft Corporation -> Microsoft Corporation)
Task: {54D4B427-D571-42BD-AD1D-6FB9814F3F84} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [1403536 2019-07-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {55DCE214-7F3F-463F-BECE-5A67E73B6324} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [1459056 2018-05-04] (HP Inc. -> HP Inc.)
Task: {562E632A-822A-4DE0-8BCC-5EE113487084} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26045472 2019-06-27] (Microsoft Corporation -> Microsoft Corporation)
Task: {5B7B1C4A-9A07-4CAC-869E-5279651131BE} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [376496 2014-01-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {69D3BA23-D578-4DE2-AFDE-D9EF27762CEC} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-09-27] (Google Inc -> Google Inc.)
Task: {85D70D96-CB3D-4E56-AB0F-24B26C54D6BF} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [1059704 2018-11-09] (HP Inc. -> HP Inc.)
Task: {B73A7C7B-CF7F-4A7E-A613-BFBB8A73789D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater - Resources => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [651400 2017-09-20] (Hewlett Packard -> HP Inc.)
Task: {B95640C8-286C-4ADA-AF7B-A685867BC4F3} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task => {3519154C-227E-47F3-9CC9-12C3F05817F1}
Task: {BA1B1F3F-67C4-4B2E-AC43-EFB3069BC508} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\sdxhelper.exe [103464 2019-07-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {C20748E5-0782-4E30-A3BC-A01FF02DECE2} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [4404888 2019-07-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {C45E956E-E070-4332-B57C-DF9D8B626B72} - System32\Tasks\Hewlett-Packard\HP Active Health\HP Active Health Scan (HPSA) => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.exe [198696 2016-11-07] (HP Inc. -> HP Inc.)
Task: {C7300FA3-0507-4B0B-9200-F7F2EF465D7B} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [4404888 2019-07-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {CD39A3B5-0980-4947-BD6C-3D87425A7FCE} - System32\Tasks\Synaptics TouchPad Enhancements => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2771184 2013-07-26] (Synaptics Incorporated -> Synaptics Incorporated)
Task: {CE133C13-C983-4DC1-90A2-2F3469BB80A3} - System32\Tasks\RogueKiller Anti-Malware => C:\Users\Annette\Desktop\RogueKiller_portable64.exe
Task: {D04BBF70-03A8-413B-9CA3-5AC3314706E2} - System32\Tasks\G2MUpdateTask-S-1-5-21-1409944621-189731363-133459071-1005 => C:\Users\Annette\AppData\Local\GoToMeeting\13761\g2mupdate.exe [32256 2019-07-31] (LogMeIn, Inc. -> LogMeIn, Inc.)
Task: {D0F920D8-40AD-4B42-9F6C-ADA01607FCCD} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Product Configurator => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\ProductConfig.exe [217976 2018-11-08] (HP Inc. -> HP Inc.)
Task: {D5C531E1-84FD-4B99-81A6-F1B6E401FECD} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [758400 2019-07-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {DCEFA36E-E149-4C02-99DB-E3F29CC3066E} - System32\Tasks\YCMServiceAgent => C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe [267224 2014-10-28] (CyberLink Corp. -> CyberLink Corp.)
Task: {E6B7EE15-0DF8-473B-AA30-3C92EDE7356E} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [1459056 2018-05-04] (HP Inc. -> HP Inc.)
Task: {EC860F0E-1C8E-4761-BA2C-9ACF03169D98} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [124280 2018-08-17] (HP Inc. -> HP Inc.)
Task: {EFE6E304-849C-4527-A6F6-903B564B9663} - System32\Tasks\G2MUploadTask-S-1-5-21-1409944621-189731363-133459071-1005 => C:\Users\Annette\AppData\Local\GoToMeeting\13761\g2mupload.exe [32256 2019-07-31] (LogMeIn, Inc. -> LogMeIn, Inc.)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-1409944621-189731363-133459071-1005.job => C:\Users\Annette\AppData\Local\GoToMeeting\13761\g2mupdate.exe
Task: C:\Windows\Tasks\G2MUploadTask-S-1-5-21-1409944621-189731363-133459071-1005.job => C:\Users\Annette\AppData\Local\GoToMeeting\13761\g2mupload.exe
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{2BE7FA48-E3A9-4398-8011-4CBB02E6ACC5}: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{8E02059E-EC13-441B-AFD6-CD70C258610A}: [DhcpNameServer] 192.168.0.1 [removed]
 
Internet Explorer:
==================
HKU\S-1-5-21-1409944621-189731363-133459071-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050213346\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/HPNOT14/1
HKU\S-1-5-21-1409944621-189731363-133459071-1005\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/
HKU\S-1-5-21-1409944621-189731363-133459071-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050214551\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/
SearchScopes: HKU\S-1-5-21-1409944621-189731363-133459071-1005 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1409944621-189731363-133459071-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050214551 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2019-06-25] (Microsoft Corporation -> Microsoft Corporation)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation -> Microsoft Corporation)
BHO: No Name -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> No File
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2016-07-21] (Hewlett-Packard Company -> HP Inc.)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2019-06-25] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: No Name -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> No File
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2016-07-21] (Hewlett-Packard Company -> HP Inc.)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-07-22] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-07-22] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-07-22] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-07-22] (Microsoft Corporation -> Microsoft Corporation)
 
FireFox:
========
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation ->  Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\SysWOW64\Adobe\Director\np32dsw_1204144.dll [2013-09-05] (Adobe Systems, Inc.) [File not signed]
FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll [No File]
FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll [No File]
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2016-07-19] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation ->  Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2019-07-22] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2013-02-06] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-07-31] (Google Inc -> Google LLC)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-07-31] (Google Inc -> Google LLC)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\3\NP_wtapp.dll [No File]
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2019-06-10] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1409944621-189731363-133459071-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050213346: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Jacquelyn\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [No File]
FF Plugin HKU\S-1-5-21-1409944621-189731363-133459071-1005: @zoom.us/ZoomVideoPlugin -> C:\Users\Annette\AppData\Roaming\Zoom\bin\npzoomplugin.dll [2017-11-05] (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FF Plugin HKU\S-1-5-21-1409944621-189731363-133459071-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050214551: @zoom.us/ZoomVideoPlugin -> C:\Users\Annette\AppData\Roaming\Zoom\bin\npzoomplugin.dll [2017-11-05] (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
 
Chrome: 
=======
CHR DefaultProfile: Profile 1
CHR HomePage: Profile 1 -> mysearch.avg.com
CHR Profile: C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default [2019-04-04]
CHR Extension: (Slides) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-07-29]
CHR Extension: (Docs) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-07-29]
CHR Extension: (Google Drive) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-07-29]
CHR Extension: (YouTube) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-07-29]
CHR Extension: (Honey) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmnlcjabgnpnenekpadlanbbkooimhnj [2018-07-29]
CHR Extension: (Adobe Acrobat) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-03-26]
CHR Extension: (Sheets) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-07-29]
CHR Extension: (Yahoo Partner) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\fpdpdomdpmhpgncppolomeniknkgpbhm [2018-05-09]
CHR Extension: (Google Docs Offline) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-07-29]
CHR Extension: (Piggy - Automatic Coupons & Cash Back) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\hfapbcheiepjppjbnkphkmegjlipojba [2018-07-18]
CHR Extension: (HP Network Check Launcher) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\jkfpchpiljkaemlpmpebnglgkomamfeo [2017-03-26]
CHR Extension: (Grammarly for Chrome) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbfnbcaeplbcioakkpcpgfkobkghlhen [2018-08-03]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-07]
CHR Extension: (No Name) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbjikboenpfhbbejgkoklgkhjpfogcam [2018-07-29]
CHR Extension: (Gmail) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-07-29]
CHR Extension: (Chrome Media Router) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-07-27]
CHR Profile: C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1 [2019-08-09]
CHR Extension: (Slides) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-07-29]
CHR Extension: (Docs) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2018-07-29]
CHR Extension: (Google Drive) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-11-06]
CHR Extension: (DuckDuckGo) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bkdgflcldnnnapblkhphbgpggdiikppg [2019-07-22]
CHR Extension: (YouTube) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-07-29]
CHR Extension: (AVG Secure Search) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\chfdnecihphmhljaaejmgoiahnihplgn [2019-08-04]
CHR Extension: (Adobe Acrobat) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2019-08-04]
CHR Extension: (Sheets) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-07-29]
CHR Extension: (Google Docs Offline) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-08-25]
CHR Extension: (ShopRunner) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ianmjeonbapghpedipabfmiffojmolma [2019-08-09]
CHR Extension: (Search Encrypt) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iiihmlfhnchcalmhhoilcamhpjcfafge [2019-08-08]
CHR Extension: (HP Network Check Launcher) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\jkfpchpiljkaemlpmpebnglgkomamfeo [2018-08-31]
CHR Extension: (Yahoo Web) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\njajpefejmjnhcddhaleakkcehiilppa [2018-08-03]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-07-29]
CHR Extension: (Search Encrypt) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp [2019-08-08]
CHR Extension: (Gmail) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-07-22]
CHR Extension: (Chrome Media Router) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-08-08]
CHR Profile: C:\Users\Annette\AppData\Local\Google\Chrome\User Data\System Profile [2019-04-04]
CHR HKLM-x32\…\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [jkfpchpiljkaemlpmpebnglgkomamfeo] - hxxps://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AdaptiveSleepService; C:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe [140288 2014-06-05] () [File not signed]
R2 AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [239616 2013-09-25] (Microsoft Windows Hardware Compatibility Publisher -> AMD)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2014-06-05] (Advanced Micro Devices, Inc.) [File not signed]
R2 Cachedrv server; C:\Program Files\Hewlett-Packard\SimplePass\cachesrvr.exe [109568 2013-09-26] () [File not signed]
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [11153952 2019-06-27] (Microsoft Corporation -> Microsoft Corporation)
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [333688 2018-06-13] (HP Inc. -> HP Inc.)
R2 HPWMISVC; C:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe [628768 2017-07-13] (HP Inc. -> HP Inc.)
R2 HuaweiHiSuiteService64.exe; C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe [190784 2018-04-20] (Huawei Technologies Co., Ltd. -> ) [File not signed]
S2 KSDE1.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 1.0\ksde.exe [241544 2016-06-28] (Kaspersky Lab -> AO Kaspersky Lab)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6744288 2019-06-26] (Malwarebytes Corporation -> Malwarebytes)
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [4278112 2013-08-02] (Symantec Corporation -> Symantec Corporation)
R2 omniserv; C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe [87552 2013-09-26] (Softex Inc.) [File not signed]
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [310016 2016-02-19] (Realtek Semiconductor Corp -> Realtek Semiconductor)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [361824 2017-01-12] (Microsoft Corporation -> Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [119872 2017-01-12] (Microsoft Corporation -> Microsoft Corporation)
S2 DSAO; "C:\Program Files (x86)\driver support\svc\DriverSupportAOsvc.exe" [X]
S3 GamesAppService; "C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe" [X]
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 AmdAS4; C:\Windows\System32\drivers\AmdAS4.sys [17640 2017-07-21] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, INC.)
R3 amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [12533760 2013-09-25] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.)
R3 amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [619008 2013-09-25] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [222720 2017-07-21] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices)
S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-12] (Broadcom Corporation -> Windows (R) Win 7 DDK provider)
S3 dg_ssudbus; C:\Windows\system32\DRIVERS\ssudbus.sys [131984 2017-05-18] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [153328 2019-01-08] (Malwarebytes Corporation -> Malwarebytes)
S3 ew_usbccgpfilter; C:\Windows\System32\drivers\ew_usbccgpfilter.sys [18944 2018-04-20] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
U5 hw_usbdev; C:\Windows\System32\Drivers\hw_usbdev.sys [116864 2018-04-20] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
R3 kltap; C:\Windows\system32\DRIVERS\kltap.sys [52152 2016-06-07] (AnchorFree Inc -> The OpenVPN Project)
R2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [199768 2019-08-07] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMFarflt; C:\Windows\System32\DRIVERS\farflt.sys [224408 2019-08-07] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMProtection; C:\Windows\system32\DRIVERS\mbam.sys [73584 2019-08-07] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [275232 2019-08-07] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMWebProtection; C:\Windows\system32\DRIVERS\mwac.sys [116112 2019-08-07] (Malwarebytes Corporation -> Malwarebytes)
R3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [294104 2014-11-28] (Realtek Semiconductor Corp -> Realtek Semiconductor Corp.)
R3 RTWlanE; C:\Windows\system32\DRIVERS\rtwlane.sys [3636440 2014-12-22] (Realtek Semiconductor Corp -> Realtek Semiconductor Corporation )
R3 RTWlanE; C:\Windows\SysWOW64\DRIVERS\rtwlane.sys [2945240 2013-09-12] (Realtek Semiconductor Corp -> Realtek Semiconductor Corporation )
S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [30448 2013-07-26] (Synaptics Incorporated -> Synaptics Incorporated)
S3 SmbDrvI; C:\Windows\System32\drivers\Smb_driver_Intel.sys [34544 2013-07-26] (Synaptics Incorporated -> Synaptics Incorporated)
S3 ssudmdm; C:\Windows\system32\DRIVERS\ssudmdm.sys [166288 2017-05-18] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
S3 usbrndis6; C:\Windows\system32\DRIVERS\usb80236.sys [20992 2015-04-24] (Microsoft Windows -> Microsoft Corporation)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [46600 2017-02-10] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WDC_SAM; C:\Windows\System32\drivers\wdcsam64.sys [26880 2015-11-12] (WDKTestCert wdclab,130885612892544312 -> Western Digital Technologies, Inc.)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [274776 2017-01-12] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [117592 2017-01-12] (Microsoft Windows -> Microsoft Corporation)
R3 WirelessButtonDriver; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [30384 2015-06-23] (Hewlett-Packard Company -> HP Inc.)
S1 epp; \??\C:\Program Files\Emsisoft Anti-Malware\epp.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One month (created) ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2019-08-08 19:39 - 2019-08-08 19:39 - 002096640 _____ (Farbar) C:\Users\Annette\Desktop\FRST64 (1).exe
2019-08-07 21:53 - 2019-08-07 21:53 - 000224408 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
2019-08-07 21:53 - 2019-08-07 21:53 - 000199768 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys
2019-08-07 21:53 - 2019-08-07 21:53 - 000116112 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2019-08-07 21:53 - 2019-08-07 21:53 - 000073584 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2019-08-07 21:52 - 2019-08-07 21:52 - 000275232 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2019-08-07 21:52 - 2019-08-07 21:52 - 000001850 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2019-08-07 21:52 - 2019-08-07 21:52 - 000001850 _____ C:\ProgramData\Desktop\Malwarebytes.lnk
2019-08-07 21:52 - 2019-08-07 21:52 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2019-08-07 21:52 - 2019-01-08 16:32 - 000153328 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbae64.sys
2019-08-07 21:44 - 2019-08-07 21:47 - 064333800 _____ (Malwarebytes ) C:\Users\Annette\Desktop\mb3-setup-1878.1878-3.8.3.2965 (1).exe
2019-08-06 16:30 - 2019-08-06 16:30 - 064333800 _____ (Malwarebytes ) C:\Users\Annette\Desktop\mb3-setup-1878.1878-3.8.3.2965.exe
2019-08-05 23:20 - 2019-08-05 23:20 - 002096640 _____ (Farbar) C:\Users\Annette\Desktop\FRST64.exe
2019-08-04 16:27 - 2019-08-04 16:28 - 007623880 _____ (Malwarebytes) C:\Users\Annette\Desktop\ADWCLNR.exe
2019-08-01 08:12 - 2019-08-01 23:14 - 000002352 _____ C:\Users\Annette\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive for Business.lnk
2019-07-31 21:46 - 2019-07-31 21:46 - 000002448 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype for Business.lnk
2019-07-31 21:46 - 2019-07-31 21:46 - 000002443 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk
2019-07-31 21:46 - 2019-07-31 21:46 - 000002442 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk
2019-07-31 21:46 - 2019-07-31 21:46 - 000002406 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access.lnk
2019-07-31 21:46 - 2019-07-31 21:46 - 000002405 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk
2019-07-31 21:46 - 2019-07-31 21:46 - 000002399 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook.lnk
2019-07-31 21:46 - 2019-07-31 21:46 - 000002393 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher.lnk
2019-07-31 21:46 - 2019-07-31 21:46 - 000002385 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk
2019-07-31 21:46 - 2019-07-31 21:46 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools
2019-07-22 23:15 - 2019-08-02 00:40 - 000000000 ____D C:\Users\Annette\free ebooks
 
==================== One month (modified) ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2019-08-09 05:15 - 2019-04-02 19:58 - 000042072 _____ C:\Users\Annette\Desktop\FRST.txt
2019-08-09 05:11 - 2019-04-02 19:50 - 000000000 ____D C:\FRST
2019-08-09 05:05 - 2015-11-17 17:45 - 000003942 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{3464BE36-788D-4EB3-890E-849F1DD7BE9F}
2019-08-08 19:30 - 2018-04-14 00:12 - 000000572 _____ C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-1409944621-189731363-133459071-1005.job
2019-08-08 19:08 - 2013-08-22 10:36 - 000000000 ____D C:\Windows\rescache
2019-08-08 18:52 - 2015-09-14 16:50 - 000003596 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1409944621-189731363-133459071-1005
2019-08-08 18:48 - 2013-08-22 10:36 - 000000000 ___HD C:\Program Files\WindowsApps
2019-08-08 18:48 - 2013-08-22 10:36 - 000000000 ____D C:\Windows\AppReadiness
2019-08-08 18:41 - 2018-04-14 00:12 - 000000668 _____ C:\Windows\Tasks\G2MUploadTask-S-1-5-21-1409944621-189731363-133459071-1005.job
2019-08-08 18:13 - 2013-08-22 10:20 - 000000000 ____D C:\Windows\CbsTemp
2019-08-07 21:51 - 2019-04-07 22:41 - 000000000 ____D C:\Program Files\Malwarebytes
2019-08-07 21:51 - 2016-02-13 23:07 - 000000000 ____D C:\ProgramData\Malwarebytes
2019-08-07 21:50 - 2014-11-19 18:48 - 000002251 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2019-08-07 21:41 - 2015-09-14 16:49 - 000000000 ____D C:\Users\Annette\Documents\Youcam
2019-08-07 21:37 - 2018-08-10 22:13 - 000000000 ____D C:\Users\Annette\AppData\Local\CrashDumps
2019-08-07 21:37 - 2015-09-14 16:49 - 000000000 ___DO C:\Users\Annette\OneDrive
2019-08-07 21:31 - 2015-03-19 15:56 - 000000000 ____D C:\ProgramData\boost_interprocess
2019-08-07 21:30 - 2017-03-08 20:56 - 000000000 ____D C:\ProgramData\Kaspersky Lab
2019-08-07 21:27 - 2019-04-09 23:58 - 000000000 ____D C:\Program Files\Emsisoft Anti-Malware
2019-08-07 21:27 - 2013-08-22 09:45 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2019-08-07 21:27 - 2013-08-22 08:25 - 000524288 ___SH C:\Windows\system32\config\BBI
2019-08-07 21:24 - 2017-03-11 09:31 - 000000000 ____D C:\ProgramData\Emsisoft
2019-08-06 16:26 - 2016-08-21 23:56 - 000030720 ___SH C:\Users\Annette\Desktop\Thumbs.db
2019-08-05 20:43 - 2013-08-22 08:36 - 000000000 ____D C:\Windows\Inf
2019-08-04 19:03 - 2016-03-24 09:59 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2019-08-04 18:56 - 2013-08-22 08:25 - 000000262 _____ C:\Windows\win.ini
2019-08-04 18:42 - 2014-11-23 19:05 - 136618864 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2019-08-04 18:42 - 2014-11-23 19:05 - 000000000 ____D C:\Windows\system32\MRT
2019-08-04 16:39 - 2015-04-07 21:03 - 000000000 ____D C:\Users\Annette
2019-08-04 16:30 - 2018-04-14 00:11 - 000000000 ____D C:\Users\Annette\AppData\Local\GoToMeeting
2019-08-02 00:45 - 2015-01-14 17:12 - 000004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2019-08-02 00:42 - 2015-12-12 14:20 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2019-08-01 23:23 - 2018-12-22 12:09 - 000003182 _____ C:\Windows\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1409944621-189731363-133459071-1005
2019-08-01 00:05 - 2014-11-19 18:47 - 000003332 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2019-08-01 00:05 - 2014-11-19 18:47 - 000003204 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2019-07-31 22:17 - 2018-04-14 00:12 - 000003676 _____ C:\Windows\System32\Tasks\G2MUploadTask-S-1-5-21-1409944621-189731363-133459071-1005
2019-07-31 22:17 - 2018-04-14 00:12 - 000003580 _____ C:\Windows\System32\Tasks\G2MUpdateTask-S-1-5-21-1409944621-189731363-133459071-1005
2019-07-31 21:57 - 2013-08-22 10:36 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2019-07-31 21:37 - 2014-04-22 12:28 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2019-07-22 21:12 - 2014-09-09 21:21 - 000065536 _____ C:\Windows\system32\spu_storage.bin
 
==================== SigCheck ===============================
 
(There is no automatic fix for files that do not pass verification.)
 
 
LastRegBack: 2019-08-08 18:54
==================== End of FRST.txt ============================

Addtn txt

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 07-08-2019 02
Ran by [removed] (09-08-2019 05:19:37)
Running from C:\Users\[removed]\Desktop
Windows 8.1 (Update) (X64) (2014-11-19 21:48:55)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-1409944621-189731363-133459071-500 - Administrator - Disabled)
Annette (S-1-5-21-1409944621-189731363-133459071-1005 - Administrator - Enabled) => C:\Users\Annette
Guest (S-1-5-21-1409944621-189731363-133459071-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1409944621-189731363-133459071-1004 - Limited - Enabled)
Jacquelyn (S-1-5-21-1409944621-189731363-133459071-1002 - Administrator - Enabled) => C:\Users\Jacquelyn
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
4 Elements II (HKLM-x32\…\WTA-f594756d-cea3-422d-a8fc-ced5205c861a) (Version: 2.2.0.98 - WildTangent) Hidden
7-Zip 9.20 (x64 edition) (HKLM\…\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Adobe Acrobat Reader DC (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 19.012.20035 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.0 (HKLM-x32\…\Adobe Shockwave Player) (Version: 12.0.4.144 - Adobe Systems, Inc.)
Airport Mania (HKLM-x32\…\WTA-67a03dfc-1d66-47d3-bc08-9a960e05c1bc) (Version: 2.2.0.95 - WildTangent) Hidden
Amazon Kindle (HKU\S-1-5-21-1409944621-189731363-133459071-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050213346\…\Amazon Kindle) (Version:  - Amazon)
AMD Catalyst Install Manager (HKLM\…\{89D9FBD5-7D44-509B-D17D-71FF2B2E7BDD}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.)
Azkend 2: The World Beneath (HKLM-x32\…\WTA-d289ec68-1f25-4f2b-ba18-86a20a21bc62) (Version: 2.2.0.98 - WildTangent) Hidden
Bejeweled 3 (HKLM-x32\…\WTA-8c1524c4-154e-48c1-9d0e-de089ad24105) (Version: 2.2.0.98 - WildTangent) Hidden
Bonjour (HKLM\…\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Bounce Symphony (HKLM-x32\…\WTA-73552c2f-075c-4734-8305-d61cc64f6bff) (Version: 2.2.0.97 - WildTangent) Hidden
Build-a-lot (HKLM-x32\…\WTA-51d1343d-3d81-4ede-9006-04b2be370e43) (Version: 2.2.0.98 - WildTangent) Hidden
CenturyLink Installer (HKLM-x32\…\{C96FF998-45BD-411E-9253-B7F2660FE280}) (Version: 1.0 - CenturyLink, Inc.)
Cisco EAP-FAST Module (HKLM-x32\…\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM-x32\…\{AF312B06-5C5C-468E-89B3-BE6DE2645722}) (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM-x32\…\{0A4EF0E6-A912-4CDE-A7F3-6E56E7C13A2F}) (Version: 1.1.6 - Cisco Systems, Inc.)
Cradle Of Egypt Collector's Edition (HKLM-x32\…\WTA-7a3200ac-a8c8-4a24-8f9d-1322c5984d44) (Version: 2.2.0.110 - WildTangent) Hidden
Cradle of Rome 2 (HKLM-x32\…\WTA-41e95925-8de8-4966-8b6f-39104fca2c0d) (Version: 2.2.0.98 - WildTangent) Hidden
Crescendo Music Notation Editor (HKLM-x32\…\Crescendo) (Version: 1.86 - NCH Software)
Curse at Twilight (HKLM-x32\…\WTA-bb4b4313-02fb-4516-b909-11928a5a3ef3) (Version: 3.0.2.32 - WildTangent) Hidden
CyberLink LabelPrint (HKLM-x32\…\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.5.6902 - CyberLink Corp.)
CyberLink Media Suite 10 (HKLM-x32\…\InstallShield_{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}) (Version: 10.0.9.4928 - CyberLink Corp.)
Cyberlink PhotoDirector (HKLM-x32\…\InstallShield_{39337565-330E-4ab6-A9AE-AC81E0720B10}) (Version: 3.0.4.4824 - CyberLink Corp.)
CyberLink Power Media Player 12 (HKLM-x32\…\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}) (Version: 12.0.6.5104 - CyberLink Corp.)
CyberLink Power2Go 8 (HKLM-x32\…\InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}) (Version: 8.0.10.5422 - CyberLink Corp.)
CyberLink PowerDirector 10 (HKLM-x32\…\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.6.3912 - CyberLink Corp.)
CyberLink YouCam (HKLM-x32\…\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 5.0.5.4628 - CyberLink Corp.)
D3DX10 (HKLM-x32\…\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden
Delicious: Emily's Childhood Memories Premium Edition (HKLM-x32\…\WTA-410ced0d-8414-4126-a7e5-3a4c77c6d5e8) (Version: 3.0.2.32 - WildTangent) Hidden
DisableMSDefender (HKLM\…\{74FE39A0-FB76-47CD-84BA-91E2BBB17EF2}) (Version: 1.0.0 - Hewlett-Packard Company) Hidden
Driver Support (HKLM-x32\…\DriverSupport) (Version: 10.1.4.86 - PC Drivers HeadQuarters LP) <==== ATTENTION
Energy Star (HKLM-x32\…\{FC0ADA4D-8FA5-4452-8AFF-F0A0BAC97EF7}) (Version: 1.0.9 - Hewlett-Packard Company)
Facebook Gameroom 1.21.6697.19829 (HKLM-x32\…\{7BE2211B-F86C-40CA-A6CC-69564D9BD5E2}) (Version: 1.21.6697.19829 - Facebook)
Farkle 3.0.13.10 (HKLM-x32\…\Farkle_is1) (Version:  - )
Farm Frenzy (HKLM-x32\…\WTA-46580f9e-769c-43d3-9dea-256e9e1d09df) (Version: 2.2.0.98 - WildTangent) Hidden
Fishdom 3: Collector's Edition (HKLM-x32\…\WTA-0d9b177b-6105-4263-8018-fbf6cbf55172) (Version: 3.0.2.38 - WildTangent) Hidden
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 76.0.3809.100 - Google LLC)
Google Earth Pro (HKLM\…\{70A0F34E-564B-4F93-ADD6-3BAEC6E44075}) (Version: 7.3.2.5776 - Google)
Google Update Helper (HKLM-x32\…\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.34.11 - Google LLC) Hidden
Google Update Helper (HKLM-x32\…\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden
GoTo Opener (HKLM-x32\…\{1F803452-798F-49FB-A5DD-9F527F7017E4}) (Version: 1.0.473 - LogMeIn, Inc.)
GoToMeeting 8.46.0.13761 (HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\GoToMeeting) (Version: 8.46.0.13761 - LogMeIn, Inc.)
GoToMeeting 8.46.0.13761 (HKU\S-1-5-21-1409944621-189731363-133459071-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050214551\…\GoToMeeting) (Version: 8.46.0.13761 - LogMeIn, Inc.)
Governor of Poker 2 Premium Edition (HKLM-x32\…\WTA-68d441b2-c8f5-499f-96e1-6c93f7dab728) (Version: 2.2.0.110 - WildTangent) Hidden
Grammarly (HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\GrammarlyForWindows) (Version: 1.5.29 - Grammarly)
Grammarly (HKU\S-1-5-21-1409944621-189731363-133459071-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050214551\…\GrammarlyForWindows) (Version: 1.5.29 - Grammarly)
Grammarly for Microsoft® Office Suite (HKLM\…\{32A50269-D356-4E0E-8726-2D4CE92E5308}) (Version: 6.6.116 - Grammarly) Hidden
Grammarly for Microsoft® Office Suite (HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\{57565765-d384-47b2-bf69-37839b58e08e}) (Version: 6.6.116 - Grammarly)
Grammarly for Microsoft® Office Suite (HKU\S-1-5-21-1409944621-189731363-133459071-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050214551\…\{57565765-d384-47b2-bf69-37839b58e08e}) (Version: 6.6.116 - Grammarly)
Hewlett-Packard ACLM.NET v1.2.2.3 (HKLM-x32\…\{6F340107-F9AA-47C6-B54C-C3A19F11553F}) (Version: 1.00.0000 - Hewlett-Packard Company) Hidden
HiSuite (HKLM-x32\…\Hi Suite) (Version: 8.0.1.300 - )
House of 1000 Doors: Family Secrets (HKLM-x32\…\WTA-7f58df73-a448-48ba-b304-fc490ae02a7f) (Version: 2.2.0.98 - WildTangent) Hidden
HP Documentation (HKLM-x32\…\{2C0CCB21-5ED3-4417-93D2-CC6BEEB3C7CF}) (Version: 1.1.0.0 - Hewlett-Packard)
HP Registration Service (HKLM\…\{D1E8F2D7-7794-4245-B286-87ED86C1893C}) (Version: 1.2.7127.4628 - Hewlett-Packard)
HP SimplePass (HKLM-x32\…\InstallShield_{314FAD12-F785-4471-BCE8-AB506642B9A1}) (Version: 8.00.54 - Hewlett-Packard)
HP Support Assistant (HKLM-x32\…\{79C54A05-F146-4EA0-8A70-D4EFE6181E52}) (Version: 8.6.18.11 - Hewlett-Packard Company)
HP Support Solutions Framework (HKLM-x32\…\{55065080-504F-43BB-BE00-36B80D7D39A5}) (Version: 12.9.24.3 - Hewlett-Packard Company)
HP System Event Utility (HKLM-x32\…\{57058272-92B0-4EFA-8FDD-ED3E5D689D37}) (Version: 1.4.32 - HP Inc.)
HP Utility Center (HKLM\…\{7A75E042-0D30-43C2-BD2A-684F4BE38FF7}) (Version: 2.3.1 - Hewlett-Packard Company)
HP Wireless Button Driver (HKLM-x32\…\{EFA01423-3857-468C-B7B6-F30AA08E50BC}) (Version: 1.1.5.1 - Hewlett-Packard)
Inst5675 (HKLM\…\{2DE6247C-7077-451B-8BA7-FFD1A2ABBB47}) (Version: 8.00.54 - Softex Inc.) Hidden
Inst5676 (HKLM\…\{878F6913-7421-4713-97F7-0A736EE2A188}) (Version: 8.00.54 - Softex Inc.) Hidden
Java 8 Update 25 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83218025F0}) (Version: 8.0.250 - Oracle Corporation)
Jewel Match 3 (HKLM-x32\…\WTA-85145c7b-75a2-48d4-89bb-4168d89f47a0) (Version: 2.2.0.98 - WildTangent) Hidden
John Deere Drive Green (HKLM-x32\…\WTA-537118ba-a615-4d10-8bd5-6a461f5e5fa4) (Version: 2.2.0.95 - WildTangent) Hidden
Kaspersky Secure Connection (HKLM-x32\…\{1CF84962-50F8-48CA-9082-B70F3A02C686}) (Version: 17.0.0.611 - Kaspersky Lab) Hidden
Kaspersky Secure Connection (HKLM-x32\…\InstallWIX_{1CF84962-50F8-48CA-9082-B70F3A02C686}) (Version: 17.0.0.611 - Kaspersky Lab)
King Oddball (HKLM-x32\…\WTA-23746366-401a-4c3e-8074-4cd5e7772844) (Version: 3.0.2.48 - WildTangent) Hidden
Luxor Evolved (HKLM-x32\…\WTA-c636fc44-f491-4f3b-9e82-fed402533998) (Version: 2.2.0.98 - WildTangent) Hidden
Mahjongg Dimensions Deluxe (HKLM-x32\…\WTA-f60926f8-4f6a-4a38-9df5-e2927ec1f7fc) (Version: 2.2.0.95 - WildTangent) Hidden
Malwarebytes version 3.8.3.2965 (HKLM\…\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.8.3.2965 - Malwarebytes)
Microsoft Office 365 ProPlus - en-us (HKLM\…\O365ProPlusRetail - en-us) (Version: 16.0.11328.20368 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-0081-0409-0000-0000000FF1CE}) (Version: 14.0.6123.5001 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM-x32\…\Office14.PROPLUSR) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Professional Plus 2013 (HKLM-x32\…\Office15.PROPLUSR) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft OneDrive (HKU\.DEFAULT\…\OneDriveSetup.exe) (Version: 17.3.6743.1212 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1409944621-189731363-133459071-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050213346\…\OneDriveSetup.exe) (Version: 17.3.6917.0607 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\OneDriveSetup.exe) (Version: 19.103.0527.0003 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1409944621-189731363-133459071-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050214551\…\OneDriveSetup.exe) (Version: 19.103.0527.0003 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50918.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\…\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\…\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23026 (HKLM-x32\…\{e46eca4f-393b-40df-9f49-076faf788d83}) (Version: 14.0.23026.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Monopoly® (HKLM-x32\…\WTA-a2f0ba12-04c0-4194-af8a-79ed3a597c9d) (Version: 3.0.2.51 - WildTangent) Hidden
Movie Maker (HKLM-x32\…\{45898170-E68C-4F02-AA35-C2186BF347A3}) (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Movie Maker (HKLM-x32\…\{B39A6825-EA20-43EA-AB2D-A6BC0298D9A1}) (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Mystery P.I. - Curious Case of Counterfeit Cove (HKLM-x32\…\WTA-2b23e2e0-e38c-4d60-8e17-7ee68c32006b) (Version: 2.2.0.98 - WildTangent) Hidden
NCH Tone Generator (HKLM-x32\…\ToneGen) (Version: 3.26 - NCH Software)
Norton Online Backup (HKLM-x32\…\{1969BD50-331D-4B7A-8116-29A7DC6D45B4}) (Version: 2.8.0.44 - Symantec Corporation)
OEM Application Profile (HKLM-x32\…\{1D464EFF-EC8B-F225-2F74-F74143200DDF}) (Version: 1.00.0000 - Advanced Micro Devices, Inc.)
OEM Application Profile (HKLM-x32\…\{70D5F822-F4C4-33D9-7EEC-2A4AF4EA7BDC}) (Version: 1.00.0000 - Advanced Micro Devices, Inc.)
Office 16 Click-to-Run Extensibility Component (HKLM-x32\…\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.11328.20368 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\…\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.11328.20368 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\…\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.11328.20368 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM-x32\…\{90160000-008C-0409-0000-0000000FF1CE}) (Version: 16.0.11328.20368 - Microsoft Corporation) Hidden
Outils de vérification linguistique 2013 de Microsoft Office - Français (HKLM-x32\…\{90150000-001F-040C-0000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Peggle Nights (HKLM-x32\…\WTA-e36ab41b-84de-4891-b4ac-4c42415d828a) (Version: 2.2.0.98 - WildTangent) Hidden
Penguins! (HKLM-x32\…\WTA-9b6dc59b-5d81-4c6f-8733-82ae9078a7f8) (Version: 2.2.0.98 - WildTangent) Hidden
Pinger (HKLM-x32\…\{9B56B031-A6C0-4BB7-8F61-938548C1B759}) (Version: 1.4.0.1 - Pinger Inc.) Hidden
Pinger (HKLM-x32\…\Pinger 1.4.0.1) (Version: 1.4.0.1 - Pinger Inc.)
Plants vs. Zombies - Game of the Year (HKLM-x32\…\WTA-1624dfaa-74eb-4a04-b0d1-2816bc270b19) (Version: 2.2.0.98 - WildTangent) Hidden
Polar Bowler (HKLM-x32\…\WTA-bb0a5787-6371-4fdd-ac8a-5702d596c923) (Version: 2.2.0.97 - WildTangent) Hidden
Realtek Card Reader (HKLM-x32\…\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.3.9600.29080 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.32.508.2014 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7730 - Realtek Semiconductor Corp.)
REALTEK Wireless LAN Driver (HKLM-x32\…\{A5107464-AA9B-4177-8129-5FF2F42DD322}) (Version: 1.0.0.41 - REALTEK Semiconductor Corp.)
Roads of Rome 3 (HKLM-x32\…\WTA-24b516d7-0fa5-49af-b5f8-2b3dd95cd50d) (Version: 2.2.0.98 - WildTangent) Hidden
SecondLifeViewer (HKLM-x32\…\SecondLifeViewer) (Version: 5.0.3.324435 - Linden Research, Inc.)
Service Pack 1 for Microsoft Office 2013 (KB2850036) 32-Bit Edition (HKLM-x32\…\{91150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUSR_{7F6C4883-A18C-459A-82C1-A2F9403F2DA6}) (Version:  - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\…\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
swMSM (HKLM-x32\…\{612C34C7-5E90-47D8-9B5C-0F717DD82726}) (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synaptics Pointing Device Driver (HKLM\…\SynTPDeinstKey) (Version: 17.0.6.2 - Synaptics Incorporated)
Tales of Lagoona (HKLM-x32\…\WTA-61166e11-25af-458a-bdb6-58e3bdab6835) (Version: 2.2.0.110 - WildTangent) Hidden
TurboTax 2014 (HKLM-x32\…\TurboTax 2014) (Version: 2014.0 - Intuit, Inc)
Unity Web Player (HKU\S-1-5-21-1409944621-189731363-133459071-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050213346\…\UnityWebPlayer) (Version: 4.6.0f2 - Unity Technologies ApS)
Vacation Quest™ - Australia (HKLM-x32\…\WTA-05973e5c-9595-40e3-910a-ba1b6178d68c) (Version: 3.0.2.32 - WildTangent) Hidden
Visual Studio 2012 x64 Redistributables (HKLM\…\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\…\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
WavePad Sound Editor (HKLM-x32\…\WavePad) (Version: 7.00 - NCH Software)
WhatsApp (HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\WhatsApp) (Version: 0.2.1455 - WhatsApp)
WhatsApp (HKU\S-1-5-21-1409944621-189731363-133459071-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050214551\…\WhatsApp) (Version: 0.2.1455 - WhatsApp)
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 16.4.3508.0205 - Microsoft Corporation)
Youda Jewel Shop (HKLM-x32\…\WTA-9173cba2-bfe3-462a-8bbc-6e837f324d64) (Version: 3.0.2.32 - WildTangent) Hidden
Zoom (HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\ZoomUMX) (Version: 4.1 - Zoom Video Communications, Inc.)
Zoom (HKU\S-1-5-21-1409944621-189731363-133459071-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050214551\…\ZoomUMX) (Version: 4.1 - Zoom Video Communications, Inc.)
Zulu DJ Software (HKLM-x32\…\Zulu) (Version: 3.70 - NCH Software)
Zuma's Revenge (HKLM-x32\…\WTA-11f72db7-03ee-4570-8cc1-e63492ed09eb) (Version: 2.2.0.98 - WildTangent) Hidden
 
Packages:
=========
- Games App - -> C:\Program Files\WindowsApps\WildTangentGames.-GamesApp-_1.0.3.28_x86__qt5r5pa5dyg8m [2017-03-23] (WildTangent Games)
Box for Windows 8 -> C:\Program Files\WindowsApps\134D4F5B.Box_2.1.4.4_neutral__2qk4zy5s3qmee [2017-03-23] (Box, Inc.)
Games -> C:\Program Files\WindowsApps\Microsoft.XboxLIVEGames_2.0.139.0_x64__8wekyb3d8bbwe [2017-03-23] (Microsoft Corporation) [MS Ad]
Getting Started with Windows 8 -> C:\Program Files\WindowsApps\AD2F1837.GettingStartedwithWindows8_1.6.0.0_neutral__v10z8vjag6ke6 [2017-03-23] (Hewlett-Packard Company)
HP All-in-One Printer Remote -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_55.1.43.0_x86__v10z8vjag6ke6 [2017-08-23] (Hewlett-Packard Company)
HP Connected Drive -> C:\Program Files\WindowsApps\AD2F1837.HPFileViewer_4.4.32.190_x64__v10z8vjag6ke6 [2017-03-23] (HP Inc.)
HP Registration -> C:\Program Files\WindowsApps\AD2F1837.HPRegistration_1.2.1.166_neutral__v10z8vjag6ke6 [2017-03-23] (Hewlett-Packard Company)
Kindle -> C:\Program Files\WindowsApps\AMZNMobileLLC.KindleforWindows8_2.1.0.2_neutral__stfe6vwa9jnbp [2017-03-23] (AMZN Mobile LLC)
McAfee® Central for HP -> C:\Program Files\WindowsApps\2703103D.McAfeeCentral_5.0.177.1_x64__4ehj4w4frejdr [2018-04-05] (.-McAfee Inc-.)
MSN Food & Drink -> C:\Program Files\WindowsApps\Microsoft.BingFoodAndDrink_3.0.4.336_x64__8wekyb3d8bbwe [2017-03-23] (Microsoft Corporation) [MS Ad]
MSN Health & Fitness -> C:\Program Files\WindowsApps\Microsoft.BingHealthAndFitness_3.0.4.336_x64__8wekyb3d8bbwe [2017-03-23] (Microsoft Corporation) [MS Ad]
MSN Money -> C:\Program Files\WindowsApps\Microsoft.BingFinance_3.0.4.344_x64__8wekyb3d8bbwe [2017-03-23] (Microsoft Corporation) [MS Ad]
MSN News -> C:\Program Files\WindowsApps\Microsoft.BingNews_3.0.4.344_x64__8wekyb3d8bbwe [2017-03-23] (Microsoft Corporation) [MS Ad]
MSN Sports -> C:\Program Files\WindowsApps\Microsoft.BingSports_3.0.4.345_x64__8wekyb3d8bbwe [2017-03-23] (Microsoft Corporation) [MS Ad]
MSN Travel -> C:\Program Files\WindowsApps\Microsoft.BingTravel_3.0.4.336_x64__8wekyb3d8bbwe [2017-03-23] (Microsoft Corporation) [MS Ad]
MSN Weather -> C:\Program Files\WindowsApps\Microsoft.BingWeather_3.0.4.350_x64__8wekyb3d8bbwe [2017-03-23] (Microsoft Corporation) [MS Ad]
Music -> C:\Program Files\WindowsApps\Microsoft.ZuneMusic_2.6.672.0_x64__8wekyb3d8bbwe [2017-03-23] (Microsoft Corporation) [MS Ad]
Netflix -> C:\Program Files\WindowsApps\4DF9E0F8.Netflix_2.22.0.39_x64__mcm4njqhnhss8 [2018-10-29] (Netflix, Inc.)
Skype -> C:\Program Files\WindowsApps\Microsoft.SkypeApp_3.1.0.1016_x86__kzf8qxf38zg5c [2017-03-23] (Skype) [MS Ad]
Snapfish -> C:\Program Files\WindowsApps\AD2F1837.HPConnectedPhotopoweredbySnapfish_5.5.0.8_x86__v10z8vjag6ke6 [2017-03-23] (HP Inc.)
Video -> C:\Program Files\WindowsApps\Microsoft.ZuneVideo_2.6.446.0_x64__8wekyb3d8bbwe [2017-03-23] (Microsoft Corporation) [MS Ad]
Xbox 360 SmartGlass -> C:\Program Files\WindowsApps\Microsoft.XboxCompanion_1.4.3.0_x64__8wekyb3d8bbwe [2017-07-13] (Microsoft Corporation) [MS Ad]
Xbox One SmartGlass -> C:\Program Files\WindowsApps\Microsoft.XboxOneSmartGlass_2.2.1702.2004_x64__8wekyb3d8bbwe [2019-04-10] (Microsoft Corporation)
YouCam for HP -> C:\Program Files\WindowsApps\CyberLinkCorp.hs.YouCamforHP_1.0.2.29632_x86__06qsbagp91rvg [2017-03-23] (CYBERLINKCOM CORP)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
HKU\S-1-5-21-1409944621-189731363-133459071-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050213346\…\ChromeHTML: ->  <==== ATTENTION
CustomCLSID: HKU\S-1-5-21-1409944621-189731363-133459071-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050213346_Classes\CLSID\{D9AC5E73-BB10-467b-B884-AA1E475C51F5}\Shell\Open\Command -> C:\Program Files\Synaptics\SynTP\SynTPCpl.dll (Synaptics Incorporated -> Synaptics Incorporated)
CustomCLSID: HKU\S-1-5-21-1409944621-189731363-133459071-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050214551_Classes\CLSID\{2AD206F1-152C-4F9D-A24E-6F93FE7A4AFC}\InprocServer32 -> C:\Users\Annette\AppData\Local\Grammarly\Grammarly for Microsoft Office Suite\6.6.116\07470D8E98\GrammarlyShim64.dll (Grammarly, Inc. -> CompanyName)
CustomCLSID: HKU\S-1-5-21-1409944621-189731363-133459071-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050214551_Classes\CLSID\{4BE56754-B616-4998-B825-D16983AEE1B2}\InprocServer32 -> C:\Users\Annette\AppData\Local\Grammarly\Grammarly for Microsoft Office Suite\6.6.116\07470D8E98\Grammarly.AddIn.Connect.ActiveX.dll (Grammarly, Inc. -> Grammarly)
CustomCLSID: HKU\S-1-5-21-1409944621-189731363-133459071-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050214551_Classes\CLSID\{D9AC5E73-BB10-467b-B884-AA1E475C51F5}\Shell\Open\Command -> C:\Program Files\Synaptics\SynTP\SynTPCpl.dll (Synaptics Incorporated -> Synaptics Incorporated)
CustomCLSID: HKU\S-1-5-21-1409944621-189731363-133459071-1005_Classes\CLSID\{2AD206F1-152C-4F9D-A24E-6F93FE7A4AFC}\InprocServer32 -> C:\Users\Annette\AppData\Local\Grammarly\Grammarly for Microsoft Office Suite\6.6.116\07470D8E98\GrammarlyShim64.dll (Grammarly, Inc. -> CompanyName)
CustomCLSID: HKU\S-1-5-21-1409944621-189731363-133459071-1005_Classes\CLSID\{4BE56754-B616-4998-B825-D16983AEE1B2}\InprocServer32 -> C:\Users\Annette\AppData\Local\Grammarly\Grammarly for Microsoft Office Suite\6.6.116\07470D8E98\Grammarly.AddIn.Connect.ActiveX.dll (Grammarly, Inc. -> Grammarly)
CustomCLSID: HKU\S-1-5-21-1409944621-189731363-133459071-1005_Classes\CLSID\{D9AC5E73-BB10-467b-B884-AA1E475C51F5}\Shell\Open\Command -> C:\Program Files\Synaptics\SynTP\SynTPCpl.dll (Synaptics Incorporated -> Synaptics Incorporated)
ShellExecuteHooks: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [6671064 2013-12-19] (Microsoft Corporation -> Microsoft Corporation)
ShellExecuteHooks-x32: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [4171480 2013-12-19] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2010-11-18] (Igor Pavlov) [File not signed]
ContextMenuHandlers1: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} => C:\Program Files (x86)\Common Files\CyberLink\ShellExtComponent\CLVDShellExt.dll [2015-12-05] (CyberLink Corp. -> Cyberlink)
ContextMenuHandlers2: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} => C:\Program Files (x86)\Common Files\CyberLink\ShellExtComponent\CLVDShellExt.dll [2015-12-05] (CyberLink Corp. -> Cyberlink)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-06-26] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2010-11-18] (Igor Pavlov) [File not signed]
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\atiacm64.dll [2014-06-05] (Advanced Micro Devices, Inc.) [File not signed]
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-06-26] (Malwarebytes Corporation -> Malwarebytes)
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
 
==================== Loaded Modules (Whitelisted) ==============
 
2015-03-19 14:48 - 2014-11-04 17:10 - 000180224 _____ ( ) [File not signed] C:\Program Files (x86)\CenturyLink\Desktop\ICSharpCode.SharpZipLib.dll
2014-06-05 22:42 - 2014-06-05 22:42 - 000140288 _____ () [File not signed] C:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe
2014-06-05 22:40 - 2014-06-05 22:40 - 000127488 _____ () [File not signed] C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.Wlan.dll
2013-09-26 13:28 - 2013-09-26 13:28 - 002540544 _____ () [File not signed] C:\Program Files\Hewlett-Packard\SimplePass\autheng.dll
2013-09-26 13:32 - 2013-09-26 13:32 - 000627200 _____ () [File not signed] C:\Program Files\Hewlett-Packard\SimplePass\cachedrv.dll
2013-09-26 13:26 - 2013-09-26 13:26 - 000109568 _____ () [File not signed] C:\Program Files\Hewlett-Packard\SimplePass\cachesrvr.exe
2013-09-26 13:25 - 2013-09-26 13:25 - 000021504 _____ () [File not signed] C:\Program Files\Hewlett-Packard\SimplePass\cryptodll.dll
2013-09-26 13:34 - 2013-09-26 13:34 - 000064000 _____ () [File not signed] C:\Program Files\Hewlett-Packard\SimplePass\opvapp.exe
2013-09-26 13:25 - 2013-09-26 13:25 - 000055296 _____ () [File not signed] C:\Program Files\Hewlett-Packard\SimplePass\RandomPass.dll
2013-09-26 13:25 - 2013-09-26 13:25 - 000035328 _____ () [File not signed] C:\Program Files\Hewlett-Packard\SimplePass\ssplogon.dll
2014-06-05 22:40 - 2014-06-05 22:40 - 000344064 _____ (Advanced Micro Devices, Inc.) [File not signed] C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
2015-03-19 14:48 - 2014-11-04 17:11 - 000124416 _____ (CenturyLink Inc) [File not signed] C:\Program Files (x86)\CenturyLink\Desktop\CenturyLink.Desktop.Shared.dll
2013-09-26 13:38 - 2013-09-26 13:38 - 000764416 _____ (Hewlett-Packard) [File not signed] C:\Program Files\Hewlett-Packard\SimplePass\OpBHO64.dll
2013-09-26 13:27 - 2013-09-26 13:27 - 000690176 _____ (Hewlett-Packard) [File not signed] C:\Program Files\Hewlett-Packard\SimplePass\storeng.dll
2013-09-26 13:28 - 2013-09-26 13:28 - 001097216 _____ (Hewlett-Packard) [File not signed] C:\Program Files\Hewlett-Packard\SimplePass\userdata.dll
2018-04-20 01:28 - 2018-04-20 01:28 - 000190784 _____ (Huawei Technologies Co., Ltd. -> ) [File not signed] C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe
2010-11-18 23:08 - 2010-11-18 23:08 - 000086016 _____ (Igor Pavlov) [File not signed] C:\Program Files\7-Zip\7-zip.dll
2014-09-09 21:32 - 2014-09-09 21:32 - 001093120 _____ (Microsoft Corporation) [File not signed] C:\Windows\WinSxS\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.6195_none_cbf5e994470a1a8f\MFC80U.DLL
2014-09-09 21:32 - 2014-09-09 21:32 - 000057344 _____ (Microsoft Corporation) [File not signed] C:\Windows\WinSxS\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.6195_none_03ce2c72205943d3\MFC80ENU.DLL
2015-03-19 14:48 - 2014-11-04 17:12 - 000200704 _____ (Microsoft) [File not signed] C:\Program Files (x86)\CenturyLink\Desktop\Qwest.Facilitator.Desktop.Agent.dll
2014-11-28 20:57 - 2013-04-02 00:19 - 000574464 _____ (Realtek Semiconductor Corp. ) [File not signed] C:\Windows\system32\Rtlihvs.dll
2013-09-26 13:32 - 2013-09-26 13:32 - 000087552 _____ (Softex Inc.) [File not signed] C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe
2013-09-26 13:39 - 2013-09-26 13:39 - 001298832 _____ (Softex Incorporated -> ) [File not signed] C:\Program Files\Hewlett-Packard\SimplePass\GraphicalPwd.dll
2013-09-26 13:39 - 2013-09-26 13:39 - 000306064 _____ (Softex Incorporated -> ) [File not signed] C:\Program Files\Hewlett-Packard\SimplePass\mstrpwd.dll
2013-09-26 13:39 - 2013-09-26 13:39 - 000599952 _____ (Softex Incorporated -> Hewlett-Packard) [File not signed] C:\Program Files\Hewlett-Packard\SimplePass\hdddrv.dll
2013-09-26 13:39 - 2013-09-26 13:39 - 000208272 _____ (Softex Incorporated -> Hewlett-Packard) [File not signed] C:\Program Files\Hewlett-Packard\SimplePass\ldapdrv.dll
2013-09-26 13:39 - 2013-09-26 13:39 - 002050960 _____ (Softex Incorporated -> Hewlett-Packard) [File not signed] C:\Program Files\Hewlett-Packard\SimplePass\Wbf.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE trusted site: HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\sharepoint.com -> hxxps://liveedurdale-files.sharepoint.com
IE trusted site: HKU\S-1-5-21-1409944621-189731363-133459071-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050214551\…\sharepoint.com -> hxxps://liveedurdale-files.sharepoint.com
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2013-08-22 08:25 - 2017-03-26 07:31 - 000000035 _____ C:\Windows\system32\drivers\etc\hosts
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\ProgramData\Oracle\Java\javapath;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files\Hewlett-Packard\SimplePass\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static
HKU\S-1-5-21-1409944621-189731363-133459071-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050213346\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Theme2\img11.jpg
HKU\S-1-5-21-1409944621-189731363-133459071-1005\Control Panel\Desktop\\Wallpaper -> C:\Users\Annette\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\windows photo viewer wallpaper.jpg
HKU\S-1-5-21-1409944621-189731363-133459071-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050214551\Control Panel\Desktop\\Wallpaper -> C:\Users\Annette\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\windows photo viewer wallpaper.jpg
DNS Servers: 75.75.75.75 - 75.75.76.76
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
Windows Firewall is disabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
If an entry is included in the fixlist, it will be removed.
 
HKLM\…\StartupApproved\Run: => "WindowsDefender"
HKLM\…\StartupApproved\Run32: => "YouCam Service"
HKLM\…\StartupApproved\Run32: => "SunJavaUpdateSched"
HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\StartupApproved\StartupFolder: => "Facebook Gameroom.lnk"
HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\StartupApproved\StartupFolder: => "Send to OneNote.lnk"
HKU\S-1-5-21-1409944621-189731363-133459071-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050214551\…\StartupApproved\StartupFolder: => "Facebook Gameroom.lnk"
HKU\S-1-5-21-1409944621-189731363-133459071-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050214551\…\StartupApproved\StartupFolder: => "Send to OneNote.lnk"
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{8D444952-FDB7-4FA5-901C-2462C1A37F99}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{AF3331A2-97B7-4313-AC3F-01DBA6B2C4FE}] => (Allow) LPort=2869
FirewallRules: [{150FBC6F-7AB5-4063-A0FB-EAC794994B93}] => (Allow) LPort=1900
FirewallRules: [{E39BD188-517F-4E06-97D0-5C42D5838F7E}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{F1948981-D69A-4ED2-8B17-9EFB0572B092}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{1402E48A-D816-4233-BC99-5439A3F6EDF5}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{8F1DB3E0-F2A7-42ED-91C7-FB0C90AC0852}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{BAB834BF-B807-4BB0-9914-BEB323488AC5}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe No File
FirewallRules: [{B4EC793D-9BBE-49AF-B2AF-C979A6135B15}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe No File
FirewallRules: [{711CA439-540E-400F-96B4-03755DDF5D83}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDirector10\PDR10.EXE (CyberLink Corp. -> CyberLink Corp.)
FirewallRules: [{A58108F8-825B-42DE-A8B0-03908ED19304}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe No File
FirewallRules: [{37B0BF0A-6A5B-4084-8C13-81F803B4FF7C}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe No File
FirewallRules: [{7281462C-F67B-4492-905D-4C4B321E723A}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\outlook.exe No File
FirewallRules: [{3B61AE1B-6103-477A-8F0D-4BAE585A8645}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPSOCKSVC.exe No File
FirewallRules: [TCP Query User{ACBD9CE9-88F2-4D23-8571-2E3C7E52DE4E}C:\program files (x86)\symantec\norton online backup\nobuclient.exe] => (Allow) C:\program files (x86)\symantec\norton online backup\nobuclient.exe (Symantec Corporation -> Symantec Corporation)
FirewallRules: [UDP Query User{02717F8A-ABC2-4205-9C6C-6DD19E9FB7DF}C:\program files (x86)\symantec\norton online backup\nobuclient.exe] => (Allow) C:\program files (x86)\symantec\norton online backup\nobuclient.exe (Symantec Corporation -> Symantec Corporation)
FirewallRules: [{D7AA5C63-D072-4153-8525-465AED706750}] => (Block) C:\program files (x86)\symantec\norton online backup\nobuclient.exe (Symantec Corporation -> Symantec Corporation)
FirewallRules: [{ED315B61-5CAE-477B-92D2-6F17C887849E}] => (Block) C:\program files (x86)\symantec\norton online backup\nobuclient.exe (Symantec Corporation -> Symantec Corporation)
FirewallRules: [TCP Query User{07B278D4-21FF-4CD2-A965-9B4438E8948A}C:\windows\system32\settingsynchost.exe] => (Block) C:\windows\system32\settingsynchost.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [UDP Query User{F79BB37B-92F4-474B-AD1B-CF9F1568C6B7}C:\windows\system32\settingsynchost.exe] => (Block) C:\windows\system32\settingsynchost.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{5407BD3E-4D9F-460E-A8AA-0B2BD11CE977}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{C767F0A0-DC9F-430D-81AC-BA6847226F1E}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPDeviceDetection3.exe No File
FirewallRules: [TCP Query User{DF2CC86E-9A5F-4831-B378-C0A56490E11E}C:\program files (x86)\tams11\games\farkle\farkle.exe] => (Allow) C:\program files (x86)\tams11\games\farkle\farkle.exe (Tams11 Software) [File not signed]
FirewallRules: [UDP Query User{BEB80554-9B9D-4AB0-90E7-0640D3A57881}C:\program files (x86)\tams11\games\farkle\farkle.exe] => (Allow) C:\program files (x86)\tams11\games\farkle\farkle.exe (Tams11 Software) [File not signed]
FirewallRules: [TCP Query User{136FA891-6E6C-483B-8803-A3420AA28CD3}C:\program files (x86)\tams11\games\farkle\farkle.exe] => (Allow) C:\program files (x86)\tams11\games\farkle\farkle.exe (Tams11 Software) [File not signed]
FirewallRules: [UDP Query User{11852EA3-54FD-4B1C-96D7-470540C49779}C:\program files (x86)\tams11\games\farkle\farkle.exe] => (Allow) C:\program files (x86)\tams11\games\farkle\farkle.exe (Tams11 Software) [File not signed]
FirewallRules: [{D1E14E70-55FD-433A-BA10-0FDA73C5FA47}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{702D7745-DB5D-4710-8D92-015A472B9C96}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{CB1CDFB6-8E46-4267-A529-C2D1099F4180}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{0CDC5D99-44C4-49B6-8130-528ED1F07E26}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{83F18E26-E83F-4F9C-A56D-8B5D7A93C367}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{BD161ADE-0A7C-44D3-8915-BB5980B4305B}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{A6A9097C-7008-48A2-AD29-13120F59BAAF}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{7F39D004-385E-48B2-9AC7-02CFC9CB9DF9}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{F5E466D7-9CCD-4E00-B99F-B4B6D6F4D8D7}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{6C701C59-B17B-486B-9D50-93844C0B482F}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{FD5590CC-017D-44AE-86A9-00E3FE28FB6D}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdater.exe (Intuit, Inc. -> Intuit Inc.)
FirewallRules: [{C66BD5C9-1AB8-46C3-BC95-4795126CAECB}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe (Intuit, Inc. -> Intuit Inc.)
FirewallRules: [{071AC728-7D57-4B67-BAD1-F2BF4D1009DC}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe (Intuit, Inc. -> Intuit Inc.)
FirewallRules: [{75E91A46-1BBE-4E2D-A34A-3E22273BBB32}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe (Intuit, Inc. -> Intuit Inc.)
FirewallRules: [{B4F8DCE1-4FF7-4C1F-BC65-B49B02A489B3}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe (Intuit, Inc. -> Intuit Inc.)
FirewallRules: [{C3F65FC8-FCC0-4EDC-841B-E344B116F68B}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe (Intuit, Inc. -> Intuit Inc.)
FirewallRules: [{F92EFA33-3CBA-4D48-A37F-EAA5C3B85EAC}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12.exe (CyberLink Corp. -> CyberLink Corp.)
FirewallRules: [{7F0BE56E-50CB-4D65-BA66-69B59B4E5837}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMR\PowerDVD12DMREngine.exe No File
FirewallRules: [{5BDC7800-C619-4DAF-9158-04EC99DFB02E}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe (CyberLink Corp. -> CyberLink)
FirewallRules: [{BD129EA8-910D-4761-95EF-F4BD429148F1}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12Agent.exe No File
FirewallRules: [{1FA56378-6A82-4A35-99DE-8725DADA7EE5}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12ML.exe (CyberLink Corp. -> CyberLink Corp.)
FirewallRules: [{B5A22037-BC5A-4720-A169-8A51A0B6DD94}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Movie\PowerDVD.exe (CyberLink Corp. -> CyberLink Corp.)
FirewallRules: [TCP Query User{B628FD1B-686E-4D16-9BD7-3D9B41C5AF98}C:\program files (x86)\secondlifeviewer\slvoice.exe] => (Allow) C:\program files (x86)\secondlifeviewer\slvoice.exe (Mercer Road Corp -> Vivox Inc.)
FirewallRules: [UDP Query User{FAB3A586-55FD-47A4-B4D2-14B68F8DBD70}C:\program files (x86)\secondlifeviewer\slvoice.exe] => (Allow) C:\program files (x86)\secondlifeviewer\slvoice.exe (Mercer Road Corp -> Vivox Inc.)
FirewallRules: [TCP Query User{3C2FA513-AA5A-4427-AEAD-A957A609EA28}C:\windows\system32\settingsynchost.exe] => (Block) C:\windows\system32\settingsynchost.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [UDP Query User{EE6ADDC5-C232-4D80-A82B-0308C9010AD3}C:\windows\system32\settingsynchost.exe] => (Block) C:\windows\system32\settingsynchost.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{7555495A-4293-4DF5-B232-FE35A7213725}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{07950D66-E207-4F23-8ACA-522AF8E2B3F4}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{EB923377-3D92-458E-887A-201786B89644}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
 
==================== Restore Points =========================
 
Could not list restore points
Check "winmgmt" service or repair WMI.
 
 
==================== Faulty Device Manager Devices =============
 
Could not list Devices. Check "winmgmt" service or repair WMI.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (08/08/2019 06:22:09 PM) (Source: Office 2016 Licensing Service) (EventID: 0) (User: )
Description: Event-ID 0
 
Error: (08/08/2019 06:11:46 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program LiveComm.exe version 17.5.9600.22013 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
 
Process ID: 1f54
 
Start Time: 01d54e3de80e9841
 
Termination Time: 4294967295
 
Application Path: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.22013_x64__8wekyb3d8bbwe\LiveComm.exe
 
Report Id: dc87849a-ba31-11e9-8335-3863bb8eae0e
 
Faulting package full name: microsoft.windowscommunicationsapps_17.5.9600.22013_x64__8wekyb3d8bbwe
 
Faulting package-relative application ID: ppleae38af2e007f4358a809ac99a64a67c1
 
Error: (08/08/2019 05:55:02 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program LiveComm.exe version 17.5.9600.22013 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
 
Process ID: 1a14
 
Start Time: 01d54e3b9106fb05
 
Termination Time: 4294967295
 
Application Path: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.22013_x64__8wekyb3d8bbwe\LiveComm.exe
 
Report Id: 84a77c37-ba2f-11e9-8335-3863bb8eae0e
 
Faulting package full name: microsoft.windowscommunicationsapps_17.5.9600.22013_x64__8wekyb3d8bbwe
 
Faulting package-relative application ID: ppleae38af2e007f4358a809ac99a64a67c1
 
Error: (08/07/2019 09:37:21 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: HPMSGSVC.exe, version: 1.4.32.0, time stamp: 0x5b640370
Faulting module name: HPMSGSVC.exe, version: 1.4.32.0, time stamp: 0x5b640370
Exception code: 0xc000041d
Fault offset: 0x0000919a
Faulting process id: 0x1434
Faulting application start time: 0x01d54d9220ee5266
Faulting application path: C:\Program Files (x86)\HP\HP System Event\HPMSGSVC.exe
Faulting module path: C:\Program Files (x86)\HP\HP System Event\HPMSGSVC.exe
Report Id: 71a8e956-b985-11e9-8335-3863bb8eae0e
Faulting package full name: 
Faulting package-relative application ID:
 
Error: (08/07/2019 09:37:01 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: HPMSGSVC.exe, version: 1.4.32.0, time stamp: 0x5b640370
Faulting module name: HPMSGSVC.exe, version: 1.4.32.0, time stamp: 0x5b640370
Exception code: 0xc0000005
Fault offset: 0x0000919a
Faulting process id: 0x1434
Faulting application start time: 0x01d54d9220ee5266
Faulting application path: C:\Program Files (x86)\HP\HP System Event\HPMSGSVC.exe
Faulting module path: C:\Program Files (x86)\HP\HP System Event\HPMSGSVC.exe
Report Id: 663b8388-b985-11e9-8335-3863bb8eae0e
Faulting package full name: 
Faulting package-relative application ID:
 
Error: (08/07/2019 09:31:07 PM) (Source: SecurityCenter) (EventID: 3) (User: )
Description: The Windows Security Center Service was unable to establish event queries with WMI to monitor third party AntiVirus, AntiSpyware and Firewall.
 
Error: (08/07/2019 09:28:22 PM) (Source: Microsoft-Windows-WMI) (EventID: 28) (User: NT AUTHORITY)
Description: Failed to Initialize WMI Core or Provider SubSystem or Event SubSystem with error number 0x80041002. This could be due to a badly installed version of WMI, WMI repository upgrade failure, insufficient disk space or insufficient memory.
 
Error: (08/07/2019 09:26:36 PM) (Source: Office 2016 Licensing Service) (EventID: 0) (User: )
Description: Event-ID 0
 
 
System errors:
=============
Error: (08/08/2019 06:02:34 PM) (Source: DCOM) (EventID: 10005) (User: NT AUTHORITY)
Description: DCOM got error "1053" attempting to start the service gupdate with arguments "/comsvc" in order to run the server:
{4EB61BAC-A3B6-4760-9581-655041EF4D69}
 
Error: (08/08/2019 06:02:33 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Google Update Service (gupdate) service failed to start due to the following error: 
The service did not respond to the start or control request in a timely fashion.
 
Error: (08/08/2019 06:02:33 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Google Update Service (gupdate) service to connect.
 
Error: (08/07/2019 09:28:06 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Driver Support AO Service service failed to start due to the following error: 
The system cannot find the file specified.
 
Error: (08/07/2019 09:19:18 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Software Protection service failed to start due to the following error: 
The service did not respond to the start or control request in a timely fashion.
 
Error: (08/07/2019 09:19:18 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Software Protection service to connect.
 
Error: (08/06/2019 04:50:10 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The AppX Deployment Service (AppXSVC) service failed to start due to the following error: 
The service did not respond to the start or control request in a timely fashion.
 
Error: (08/06/2019 04:50:10 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the AppX Deployment Service (AppXSVC) service to connect.
 
 
Windows Defender:
===================================
Date: 2019-08-08 19:16:42.230
Description: 
Windows Defender scan has been stopped before completion.
Scan ID: {B4EB9551-C27F-4BD4-80FC-0BB55490D7B2}
Scan Type: Antimalware
Scan Parameters: Quick Scan
 
Date: 2019-08-08 19:01:08.160
Description: 
Windows Defender scan has been stopped before completion.
Scan ID: {F68C8C88-4CC0-4144-91C8-D8C298EF2527}
Scan Type: Antimalware
Scan Parameters: Quick Scan
 
Date: 2019-05-02 20:21:04.141
Description: 
Windows Defender scan has been stopped before completion.
Scan ID: {632807FD-0C30-442A-A253-552449623A2D}
Scan Type: Antimalware
Scan Parameters: Quick Scan
 
Date: 2019-04-17 19:13:42.361
Description: 
Windows Defender scan has been stopped before completion.
Scan ID: {CFBF0166-027C-4D3D-A9BA-0D84E3A94CEC}
Scan Type: Antimalware
Scan Parameters: Quick Scan
 
Date: 2019-04-07 02:28:42.505
Description: 
Windows Defender scan has been stopped before completion.
Scan ID: {9D403929-3EB0-42B5-B42A-714A5E180EEF}
Scan Type: Antimalware
Scan Parameters: Quick Scan
 
Date: 2019-08-04 16:38:50.272
Description: 
Windows Defender has encountered an error trying to update signatures.
New Signature Version: 
Previous Signature Version: 
Update Source: User
Signature Type: 
Update Type: 
Current Engine Version: 
Previous Engine Version: 
Error code: 0x80070652
Error description: Another installation is already in progress. Complete that installation before proceeding with this install. 
 
Date: 2019-08-04 16:25:16.738
Description: 
Windows Defender has encountered an error trying to update signatures.
New Signature Version: 
Previous Signature Version: 1.291.2375.0
Update Source: Microsoft Malware Protection Center
Signature Type: AntiSpyware
Update Type: Full
Current Engine Version: 
Previous Engine Version: 1.1.15900.4
Error code: 0x80070652
Error description: Another installation is already in progress. Complete that installation before proceeding with this install. 
 
Date: 2019-08-04 16:25:16.738
Description: 
Windows Defender has encountered an error trying to update signatures.
New Signature Version: 
Previous Signature Version: 1.291.2375.0
Update Source: Microsoft Malware Protection Center
Signature Type: AntiVirus
Update Type: Full
Current Engine Version: 
Previous Engine Version: 1.1.15900.4
Error code: 0x80070652
Error description: Another installation is already in progress. Complete that installation before proceeding with this install. 
 
Date: 2019-08-04 16:24:57.178
Description: 
Windows Defender has encountered an error trying to update signatures.
New Signature Version: 
Previous Signature Version: 
Update Source: User
Signature Type: 
Update Type: 
Current Engine Version: 
Previous Engine Version: 
Error code: 0x80070652
Error description: Another installation is already in progress. Complete that installation before proceeding with this install. 
 
Date: 2019-08-04 16:24:57.136
Description: 
Windows Defender has encountered an error trying to update signatures.
New Signature Version: 
Previous Signature Version: 
Update Source: User
Signature Type: 
Update Type: 
Current Engine Version: 
Previous Engine Version: 
Error code: 0x80070652
Error description: Another installation is already in progress. Complete that installation before proceeding with this install. 
 
CodeIntegrity:
===================================
 
Date: 2019-08-09 05:10:58.246
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
Date: 2019-08-09 05:10:55.973
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
Date: 2019-08-08 19:43:47.846
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
Date: 2019-08-08 19:43:45.742
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
Date: 2019-08-08 19:03:21.234
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
 
Date: 2019-08-07 21:26:13.482
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Emsisoft Anti-Malware\a2hooks64.dll because the set of per-page image hashes could not be found on the system.
 
Date: 2019-08-07 00:42:23.273
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Emsisoft Anti-Malware\a2hooks64.dll because the set of per-page image hashes could not be found on the system.
 
Date: 2019-08-07 00:39:43.459
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Emsisoft Anti-Malware\a2hooks64.dll because the set of per-page image hashes could not be found on the system.
 
==================== Memory info =========================== 
 
BIOS: Insyde F.33 08/04/2015
Motherboard: Hewlett-Packard 2330
Processor: AMD A6-5200 APU with Radeon(TM) HD Graphics 
Percentage of memory in use: 91%
Total physical RAM: 3554.01 MB
Available physical RAM: 311.27 MB
Total Virtual: 5858.01 MB
Available Virtual: 2058.95 MB
 
==================== Drives ================================
 
Drive c: (Windows) (Fixed) (Total:677.63 GB) (Free:387.33 GB) NTFS
Drive d: (RECOVERY) (Fixed) (Total:19.99 GB) (Free:1.28 GB) NTFS ==>[system with boot components (obtained from drive)]
 
\\?\Volume{f0d011a2-f7dc-43a9-8b7c-0875843c6a46}\ (WINRE) (Fixed) (Total:0.63 GB) (Free:0.36 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 698.6 GB) (Disk ID: A9A16C4F)
 
Partition: GPT.
 
==================== End of Addition.txt ============================

Percentage of memory in use: 91%


You need to close all unnecessary tabs/programmes and/or get more ram. This, apart from infections, is why your computer is slow.

We can disable some unnecessary startups later but meanwhile, avoid using the Internet except to answer these logs as Windows Defender and Firewall are both disabled at the moment.

===================================================

Uninstall programs

Uninstall the following programs:


Driver Support (HKLM-x32


===================================================

Remove Chrome Extensions

Remove the following extensions:

AVG Secure Search
Search Encrypt

  • type chrome://extensions in the address bar and press Enter
  • click the trash can icon by the extension you'd like to completely remove
  • a confirmation dialog appears, click Remove.

===================================================

Run Farbar Recovery Scan Tool

Open notepad. Please copy the contents of the code box below and paste it into Notepad.

CloseProcesses:
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [507776 2014-10-07] (Oracle America, Inc. -> Oracle Corporation)
HKU\S-1-5-21-1409944621-189731363-133459071-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050213346\…\MountPoints2: {e1d9e33d-70cc-11e4-825e-3863bb8eae0e} - "F:\AutoRun.exe"
HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\MountPoints2: {0971029e-8ae2-11e8-830f-3863bb8eae0e} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\MountPoints2: {097102d7-8ae2-11e8-830f-3863bb8eae0e} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\MountPoints2: {803e9b84-3b72-11e8-8302-3863bb8eae0e} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\MountPoints2: {ed76fc77-6b0a-11e5-8270-3863bb8eae0e} - "F:\AutoRun.exe"
HKU\S-1-5-21-1409944621-189731363-133459071-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050214551\…\MountPoints2: {0971029e-8ae2-11e8-830f-3863bb8eae0e} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-1409944621-189731363-133459071-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050214551\…\MountPoints2: {097102d7-8ae2-11e8-830f-3863bb8eae0e} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-1409944621-189731363-133459071-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050214551\…\MountPoints2: {803e9b84-3b72-11e8-8302-3863bb8eae0e} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-1409944621-189731363-133459071-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050214551\…\MountPoints2: {ed76fc77-6b0a-11e5-8270-3863bb8eae0e} - "F:\AutoRun.exe"
Task: {468B13AD-B541-4A27-B004-9B018EEA3275} - System32\Tasks\Java Platform SE Auto Updater => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [507776 2014-10-07] (Oracle America, Inc. -> Oracle Corporation)
Task: C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-1409944621-189731363-133459071-1005.job => C:\Users\Annette\AppData\Local\GoToMeeting\13761\g2mupdate.exe
Task: C:\Windows\Tasks\G2MUploadTask-S-1-5-21-1409944621-189731363-133459071-1005.job => C:\Users\Annette\AppData\Local\GoToMeeting\13761\g2mupload.exe
BHO-x32: No Name -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> No File
FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll [No File]
FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll [No File]
CHR HomePage: Profile 1 -> mysearch.avg.com
CHR Extension: (AVG Secure Search) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\chfdnecihphmhljaaejmgoiahnihplgn [2019-08-04]
CHR Extension: (Search Encrypt) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oodblefojaocanejnikhhjcglbaelpbp [2019-08-08]
S2 DSAO; "C:\Program Files (x86)\driver support\svc\DriverSupportAOsvc.exe" [X]
S3 GamesAppService; "C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe" [X]
S1 epp; \??\C:\Program Files\Emsisoft Anti-Malware\epp.sys [X]
2019-08-07 21:27 - 2019-04-09 23:58 - 000000000 ____D C:\Program Files\Emsisoft Anti-Malware
2019-08-07 21:24 - 2017-03-11 09:31 - 000000000 ____D C:\ProgramData\Emsisoft
HKU\S-1-5-21-1409944621-189731363-133459071-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08092019050213346\…\ChromeHTML: ->  <==== ATTENTION
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
FirewallRules: [{BAB834BF-B807-4BB0-9914-BEB323488AC5}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe No File
FirewallRules: [{B4EC793D-9BBE-49AF-B2AF-C979A6135B15}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe No File
FirewallRules: [{A58108F8-825B-42DE-A8B0-03908ED19304}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe No File
FirewallRules: [{37B0BF0A-6A5B-4084-8C13-81F803B4FF7C}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe No File
FirewallRules: [{7281462C-F67B-4492-905D-4C4B321E723A}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\outlook.exe No File
FirewallRules: [{3B61AE1B-6103-477A-8F0D-4BAE585A8645}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPSOCKSVC.exe No File
FirewallRules: [{C767F0A0-DC9F-430D-81AC-BA6847226F1E}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPDeviceDetection3.exe No File
FirewallRules: [{7F0BE56E-50CB-4D65-BA66-69B59B4E5837}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMR\PowerDVD12DMREngine.exe No File
FirewallRules: [{BD129EA8-910D-4761-95EF-F4BD429148F1}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12Agent.exe No File
Available physical RAM: 311.27 MB
EmptyTemp:

NOTE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

  • save the files as fixlist.txt in the same folder as FRST – NOTE: It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work
  • run FRST64 then click Fix just once and wait
  • it will create a log on your desktop, (Fixlog.txt); please post it to your reply.

===================================================

Download and run Tweaking.com - Windows Repair

Download Windows Repair from here and save it to your desktop.

  • install and then run the programme
  • when it starts, it will check that all its files are present
  • when the next window opens,click on the middle tab, ‘Jump to Repairs’
  • in the next window click on ‘Open Repairs’, (the programme will make a backup of your registry)
  • place a checkmark next to 05, Repair WMI
  • click Start
  • leave the default selected items as they are and check Restart System When Finished
  • now press Start Repairs.

================================================

Please run FRST again and make sure there is a checkmark next to ‘Addition.txt’ before you hit Scan.

Logs to include with next post:

Fixlog.txt
New Frst.txt
New Addition.txt


Thanks

Satchfan

Hi Satchfan,

 

I didn't see you message regarding not to avoid using the Internet except to answer these logs as Windows Defender and Firewall are both disabled at the moment. I had left home yesterday, shortly after 9am not returning until 9pm. I didn't see your message until 4:30am. With that said, my computer had been on the entire time. My question is do you still want me to follow your above instructions? Or will I need to run other tests due to having my computer on and being on the internet all that time?

 

Thanks,

Annette

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 10-08-2019
Ran by [removed] (administrator) on MRSJOHNSON (Hewlett-Packard HP 15 Notebook PC) (12-08-2019 15:44:05)
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows 8.1 (Update) (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
() [File not signed] C:\Program Files\ATI Technologies\ATI.ACE\a4\AdaptiveSleepService.exe
() [File not signed] C:\Program Files\Hewlett-Packard\SimplePass\cachesrvr.exe
() [File not signed] C:\Program Files\Hewlett-Packard\SimplePass\opvapp.exe
(Adobe Inc. -> Adobe Systems) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Advanced Micro Devices, Inc.) [File not signed] C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(CenturyLink -> CenturyLink Inc) C:\Program Files (x86)\CenturyLink\Desktop\CenturyLinkTouchPointAgent.exe
(CyberLink Corp. -> CyberLink Corp.) C:\Program Files (x86)\CyberLink\YouCam\Youcam_webcam_camera_video.exe
(CyberLink Corp. -> CyberLink Corp.) C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe
(Google Inc -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.34.11\GoogleCrashHandler.exe
(Google Inc -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.34.11\GoogleCrashHandler64.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(HP Inc. -> HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(HP Inc. -> HP Inc.) C:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe
(Huawei Technologies Co., Ltd. -> ) [File not signed] C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe
(Intuit, Inc. -> Intuit Inc.) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
(Malwarebytes Corporation -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Corporation -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\SoftwareDistribution\Download\Install\AM_Delta.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\System32\MpSigStub.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.22013_x64__8wekyb3d8bbwe\livecomm.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\StikyNot.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atiesrxx.exe
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Softex Inc.) [File not signed] C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe
(Softex Incorporated -> Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\HPSmplPass.exe
(Softex Incorporated -> Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBroker.exe
(Softex Incorporated -> Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe
(Symantec Corporation -> Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
(Symantec Corporation -> Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Tweaking LLC -> Tweaking.com) C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe
Failed to access process -> HPMSGSVC.exe
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [SimplePass] => C:\Program Files\Hewlett-Packard\SimplePass\HPSmplPass.exe [2755640 2013-09-26] (Softex Incorporated -> Hewlett-Packard)
HKLM\…\Run: [OPBHOBroker] => C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBroker.exe [155704 2013-09-26] (Softex Incorporated -> Hewlett-Packard)
HKLM\…\Run: [OPBHOBrokerDesktop] => C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe [155704 2013-09-26] (Softex Incorporated -> Hewlett-Packard)
HKLM\…\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2771184 2013-07-26] (Synaptics Incorporated -> Synaptics Incorporated)
HKLM\…\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8843520 2016-02-19] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\…\Run: [WindowsDefender] => "%ProgramFiles%\Windows Defender\MSASCuiL.exe"
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [507776 2014-10-07] (Oracle America, Inc. -> Oracle Corporation)
HKLM-x32\…\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation -> Microsoft Corporation)
HKLM-x32\…\Run: [CenturyLinkTouchPointAgent] => C:\Program Files (x86)\CenturyLink\Desktop\CenturyLinkTouchPointAgent.exe [48904 2014-11-04] (CenturyLink -> CenturyLink Inc)
HKLM-x32\…\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767200 2014-06-06] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
HKLM-x32\…\Run: [HPMessageService] => C:\Program Files (x86)\HP\HP System Event\HPMSGSVC.exe [707624 2018-08-08] (HP Inc. -> HP Inc.)
HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\Run: [GoogleChromeAutoLaunch_0C9337CDD31A557C75EB2CDF52C45A5A] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1535472 2019-08-05] (Google LLC -> Google LLC)
HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [479744 2014-10-28] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\MountPoints2: {0971029e-8ae2-11e8-830f-3863bb8eae0e} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\MountPoints2: {097102d7-8ae2-11e8-830f-3863bb8eae0e} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\MountPoints2: {803e9b84-3b72-11e8-8302-3863bb8eae0e} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\MountPoints2: {ed76fc77-6b0a-11e5-8270-3863bb8eae0e} - "F:\AutoRun.exe" 
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\76.0.3809.100\Installer\chrmstp.exe [2019-08-07] (Google LLC -> Google LLC)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{A6EADE66-0000-0000-484E-7E8A45000000}] -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Esl\AiodLite.dll [2019-06-10] (Adobe Inc. -> Adobe Systems, Inc.)
HKLM\Software\…\Authentication\Credential Providers: [{538C240D-3DEE-4032-AB4C-08A3A6EB0861}] -> C:\Program Files (x86)\CyberLink\YouCam\CLCredProv\x64\CLCredProv.dll [2014-10-28] (CyberLink Corp. -> CyberLink)
HKLM\Software\…\Authentication\Credential Providers: [{F3F1B0FA-4775-41d8-8578-436772D93FB4}] -> C:\Program Files\Hewlett-Packard\SimplePass\OmniPassCredProv.dll [2013-09-26] (Softex Inc..) [File not signed]
HKLM\Software\…\Authentication\Credential Provider Filters: [{F3F1B0FA-4775-41d8-8578-436772D93FB4}] -> C:\Program Files\Hewlett-Packard\SimplePass\OmniPassCredProv.dll [2013-09-26] (Softex Inc..) [File not signed]
Startup: C:\Users\Annette\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Facebook Gameroom.lnk [2018-08-03]
ShortcutTarget: Facebook Gameroom.lnk -> C:\Users\Annette\AppData\Local\Facebook\Games\FacebookGameroom.exe (Facebook, Inc. -> Facebook) [File not signed]
Startup: C:\Users\Annette\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk [2018-01-08]
ShortcutTarget: Send to OneNote.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE (Microsoft Corporation -> Microsoft Corporation)
Startup: C:\Users\Jacquelyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk [2016-05-14]
ShortcutTarget: Send to OneNote.lnk -> C:\Program Files (x86)\Microsoft Office\Office15\ONENOTEM.EXE (Microsoft Corporation -> Microsoft Corporation)
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {10A0396E-4397-432D-A61A-B29936C98279} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-09-27] (Google Inc -> Google Inc.)
Task: {2FE82A44-7615-47C1-88DD-E0D568E5D0F2} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe
Task: {3165798A-F44B-4387-8B96-BD947DFDF94F} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [376496 2014-01-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {3CCC318D-E72D-4C49-9C74-C4C063155CBC} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\sdxhelper.exe [103464 2019-07-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {3E898CDD-32F4-47D1-A2F4-BCF33E88AEBC} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [651400 2017-09-20] (Hewlett Packard -> HP Inc.)
Task: {422808BD-6F70-41BF-945D-E13AA06AE45A} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis Install => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [1459056 2018-05-04] (HP Inc. -> HP Inc.)
Task: {468B13AD-B541-4A27-B004-9B018EEA3275} - System32\Tasks\Java Platform SE Auto Updater => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [507776 2014-10-07] (Oracle America, Inc. -> Oracle Corporation)
Task: {48426B74-A917-4AA1-A961-4CBF7B9F1EC5} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [1403536 2019-07-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {5200926D-6DAC-44AC-95C0-5C3C6F4AEBD1} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26045472 2019-06-27] (Microsoft Corporation -> Microsoft Corporation)
Task: {54D4B427-D571-42BD-AD1D-6FB9814F3F84} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [1403536 2019-07-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {55DCE214-7F3F-463F-BECE-5A67E73B6324} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [1459056 2018-05-04] (HP Inc. -> HP Inc.)
Task: {562E632A-822A-4DE0-8BCC-5EE113487084} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26045472 2019-06-27] (Microsoft Corporation -> Microsoft Corporation)
Task: {5B7B1C4A-9A07-4CAC-869E-5279651131BE} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [376496 2014-01-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {69D3BA23-D578-4DE2-AFDE-D9EF27762CEC} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-09-27] (Google Inc -> Google Inc.)
Task: {B2899F8C-8C39-47C3-82D8-3DD3813BCCD1} - System32\Tasks\Tweaking.com - Windows Repair Tray Icon => C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe [218336 2017-05-02] (Tweaking LLC -> Tweaking.com)
Task: {B73A7C7B-CF7F-4A7E-A613-BFBB8A73789D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater - Resources => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [651400 2017-09-20] (Hewlett Packard -> HP Inc.)
Task: {B95640C8-286C-4ADA-AF7B-A685867BC4F3} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task => {3519154C-227E-47F3-9CC9-12C3F05817F1}
Task: {BA1B1F3F-67C4-4B2E-AC43-EFB3069BC508} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\sdxhelper.exe [103464 2019-07-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {C20748E5-0782-4E30-A3BC-A01FF02DECE2} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [4404888 2019-07-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {C45E956E-E070-4332-B57C-DF9D8B626B72} - System32\Tasks\Hewlett-Packard\HP Active Health\HP Active Health Scan (HPSA) => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.exe [198696 2016-11-07] (HP Inc. -> HP Inc.)
Task: {C7300FA3-0507-4B0B-9200-F7F2EF465D7B} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [4404888 2019-07-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {C94E5254-03C1-467D-A46E-FBD7F2862845} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1236048 2019-07-24] (Adobe Inc. -> Adobe Systems)
Task: {CD39A3B5-0980-4947-BD6C-3D87425A7FCE} - System32\Tasks\Synaptics TouchPad Enhancements => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2771184 2013-07-26] (Synaptics Incorporated -> Synaptics Incorporated)
Task: {CE133C13-C983-4DC1-90A2-2F3469BB80A3} - System32\Tasks\RogueKiller Anti-Malware => C:\Users\Annette\Desktop\RogueKiller_portable64.exe
Task: {D04BBF70-03A8-413B-9CA3-5AC3314706E2} - System32\Tasks\G2MUpdateTask-S-1-5-21-1409944621-189731363-133459071-1005 => C:\Users\Annette\AppData\Local\GoToMeeting\13761\g2mupdate.exe [32256 2019-07-31] (LogMeIn, Inc. -> LogMeIn, Inc.)
Task: {D0F920D8-40AD-4B42-9F6C-ADA01607FCCD} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Product Configurator => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\ProductConfig.exe [217976 2018-11-08] (HP Inc. -> HP Inc.)
Task: {DCEFA36E-E149-4C02-99DB-E3F29CC3066E} - System32\Tasks\YCMServiceAgent => C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe [267224 2014-10-28] (CyberLink Corp. -> CyberLink Corp.)
Task: {E6B7EE15-0DF8-473B-AA30-3C92EDE7356E} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [1459056 2018-05-04] (HP Inc. -> HP Inc.)
Task: {EBA6C294-4F16-422D-A3CF-3B92AE0ADC8B} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [758400 2019-07-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {EC860F0E-1C8E-4761-BA2C-9ACF03169D98} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [124280 2018-08-17] (HP Inc. -> HP Inc.)
Task: {EFE6E304-849C-4527-A6F6-903B564B9663} - System32\Tasks\G2MUploadTask-S-1-5-21-1409944621-189731363-133459071-1005 => C:\Users\Annette\AppData\Local\GoToMeeting\13761\g2mupload.exe [32256 2019-07-31] (LogMeIn, Inc. -> LogMeIn, Inc.)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-1409944621-189731363-133459071-1005.job => C:\Users\Annette\AppData\Local\GoToMeeting\13761\g2mupdate.exe
Task: C:\Windows\Tasks\G2MUploadTask-S-1-5-21-1409944621-189731363-133459071-1005.job => C:\Users\Annette\AppData\Local\GoToMeeting\13761\g2mupload.exe
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{2BE7FA48-E3A9-4398-8011-4CBB02E6ACC5}: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{8E02059E-EC13-441B-AFD6-CD70C258610A}: [DhcpNameServer] 192.168.0.1 [removed]
 
Internet Explorer:
==================
HKU\S-1-5-21-1409944621-189731363-133459071-1005\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/
SearchScopes: HKU\S-1-5-21-1409944621-189731363-133459071-1005 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2019-06-25] (Microsoft Corporation -> Microsoft Corporation)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation -> Microsoft Corporation)
BHO: No Name -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> No File
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2016-07-21] (Hewlett-Packard Company -> HP Inc.)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2019-06-25] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: No Name -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> No File
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2016-07-21] (Hewlett-Packard Company -> HP Inc.)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-07-22] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-07-22] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-07-22] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-07-22] (Microsoft Corporation -> Microsoft Corporation)
 
FireFox:
========
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation ->  Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\SysWOW64\Adobe\Director\np32dsw_1204144.dll [2013-09-05] (Adobe Systems, Inc.) [File not signed]
FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll [No File]
FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll [No File]
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2016-07-19] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation ->  Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2019-07-22] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2013-02-06] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-07-31] (Google Inc -> Google LLC)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-07-31] (Google Inc -> Google LLC)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\3\NP_wtapp.dll [No File]
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2019-06-10] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1409944621-189731363-133459071-1005: @zoom.us/ZoomVideoPlugin -> C:\Users\Annette\AppData\Roaming\Zoom\bin\npzoomplugin.dll [2017-11-05] (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
 
Chrome: 
=======
CHR DefaultProfile: Profile 1
CHR Profile: C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default [2019-04-04]
CHR Extension: (Slides) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-07-29]
CHR Extension: (Docs) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-07-29]
CHR Extension: (Google Drive) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-07-29]
CHR Extension: (YouTube) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-07-29]
CHR Extension: (Honey) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmnlcjabgnpnenekpadlanbbkooimhnj [2018-07-29]
CHR Extension: (Adobe Acrobat) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-03-26]
CHR Extension: (Sheets) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-07-29]
CHR Extension: (Yahoo Partner) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\fpdpdomdpmhpgncppolomeniknkgpbhm [2018-05-09]
CHR Extension: (Google Docs Offline) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-07-29]
CHR Extension: (Piggy - Automatic Coupons & Cash Back) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\hfapbcheiepjppjbnkphkmegjlipojba [2018-07-18]
CHR Extension: (HP Network Check Launcher) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\jkfpchpiljkaemlpmpebnglgkomamfeo [2017-03-26]
CHR Extension: (Grammarly for Chrome) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbfnbcaeplbcioakkpcpgfkobkghlhen [2018-08-03]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-07]
CHR Extension: (No Name) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbjikboenpfhbbejgkoklgkhjpfogcam [2018-07-29]
CHR Extension: (Gmail) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-07-29]
CHR Extension: (Chrome Media Router) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-07-27]
CHR Profile: C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1 [2019-08-12]
CHR Extension: (Slides) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-07-29]
CHR Extension: (Docs) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2018-07-29]
CHR Extension: (Google Drive) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-11-06]
CHR Extension: (DuckDuckGo) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bkdgflcldnnnapblkhphbgpggdiikppg [2019-07-22]
CHR Extension: (YouTube) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-07-29]
CHR Extension: (Adobe Acrobat) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2019-08-04]
CHR Extension: (Sheets) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-07-29]
CHR Extension: (Google Docs Offline) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-08-25]
CHR Extension: (ShopRunner) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ianmjeonbapghpedipabfmiffojmolma [2019-08-11]
CHR Extension: (HP Network Check Launcher) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\jkfpchpiljkaemlpmpebnglgkomamfeo [2018-08-31]
CHR Extension: (Yahoo Web) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\njajpefejmjnhcddhaleakkcehiilppa [2018-08-03]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-07-29]
CHR Extension: (Gmail) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-07-22]
CHR Extension: (Chrome Media Router) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-08-08]
CHR Profile: C:\Users\Annette\AppData\Local\Google\Chrome\User Data\System Profile [2019-04-04]
CHR HKLM-x32\…\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [jkfpchpiljkaemlpmpebnglgkomamfeo] - hxxps://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AdaptiveSleepService; C:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe [140288 2014-06-05] () [File not signed]
R2 AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [239616 2013-09-25] (Microsoft Windows Hardware Compatibility Publisher -> AMD)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2014-06-05] (Advanced Micro Devices, Inc.) [File not signed]
R2 Cachedrv server; C:\Program Files\Hewlett-Packard\SimplePass\cachesrvr.exe [109568 2013-09-26] () [File not signed]
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [11153952 2019-06-27] (Microsoft Corporation -> Microsoft Corporation)
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [333688 2018-06-13] (HP Inc. -> HP Inc.)
R2 HPWMISVC; C:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe [628768 2017-07-13] (HP Inc. -> HP Inc.)
R2 HuaweiHiSuiteService64.exe; C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe [190784 2018-04-20] (Huawei Technologies Co., Ltd. -> ) [File not signed]
S2 KSDE1.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 1.0\ksde.exe [241544 2016-06-28] (Kaspersky Lab -> AO Kaspersky Lab)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6744288 2019-06-26] (Malwarebytes Corporation -> Malwarebytes)
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [4278112 2013-08-02] (Symantec Corporation -> Symantec Corporation)
R2 omniserv; C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe [87552 2013-09-26] (Softex Inc.) [File not signed]
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [310016 2016-02-19] (Realtek Semiconductor Corp -> Realtek Semiconductor)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [361824 2017-01-12] (Microsoft Corporation -> Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [119872 2017-01-12] (Microsoft Corporation -> Microsoft Corporation)
S2 DSAO; "C:\Program Files (x86)\driver support\svc\DriverSupportAOsvc.exe" [X]
S3 GamesAppService; "C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe" [X]
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 AmdAS4; C:\Windows\System32\drivers\AmdAS4.sys [17640 2017-07-21] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, INC.)
R3 amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [12533760 2013-09-25] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.)
R3 amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [619008 2013-09-25] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [222720 2017-07-21] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices)
S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-12] (Broadcom Corporation -> Windows (R) Win 7 DDK provider)
S3 dg_ssudbus; C:\Windows\system32\DRIVERS\ssudbus.sys [131984 2017-05-18] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [153328 2019-01-08] (Malwarebytes Corporation -> Malwarebytes)
S3 ew_usbccgpfilter; C:\Windows\System32\drivers\ew_usbccgpfilter.sys [18944 2018-04-20] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
U5 hw_usbdev; C:\Windows\System32\Drivers\hw_usbdev.sys [116864 2018-04-20] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
R3 kltap; C:\Windows\system32\DRIVERS\kltap.sys [52152 2016-06-07] (AnchorFree Inc -> The OpenVPN Project)
R2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [199768 2019-08-12] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMFarflt; C:\Windows\System32\DRIVERS\farflt.sys [224408 2019-08-12] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMProtection; C:\Windows\system32\DRIVERS\mbam.sys [73584 2019-08-12] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [275232 2019-08-11] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMWebProtection; C:\Windows\system32\DRIVERS\mwac.sys [116112 2019-08-12] (Malwarebytes Corporation -> Malwarebytes)
R3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [294104 2014-11-28] (Realtek Semiconductor Corp -> Realtek Semiconductor Corp.)
R3 RTWlanE; C:\Windows\system32\DRIVERS\rtwlane.sys [3636440 2014-12-22] (Realtek Semiconductor Corp -> Realtek Semiconductor Corporation )
R3 RTWlanE; C:\Windows\SysWOW64\DRIVERS\rtwlane.sys [2945240 2013-09-12] (Realtek Semiconductor Corp -> Realtek Semiconductor Corporation )
S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [30448 2013-07-26] (Synaptics Incorporated -> Synaptics Incorporated)
S3 SmbDrvI; C:\Windows\System32\drivers\Smb_driver_Intel.sys [34544 2013-07-26] (Synaptics Incorporated -> Synaptics Incorporated)
S3 ssudmdm; C:\Windows\system32\DRIVERS\ssudmdm.sys [166288 2017-05-18] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
S3 usbrndis6; C:\Windows\system32\DRIVERS\usb80236.sys [20992 2015-04-24] (Microsoft Windows -> Microsoft Corporation)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [46600 2017-02-10] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WDC_SAM; C:\Windows\System32\drivers\wdcsam64.sys [26880 2015-11-12] (WDKTestCert wdclab,130885612892544312 -> Western Digital Technologies, Inc.)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [274776 2017-01-12] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [117592 2017-01-12] (Microsoft Windows -> Microsoft Corporation)
R3 WirelessButtonDriver; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [30384 2015-06-23] (Hewlett-Packard Company -> HP Inc.)
S1 epp; \??\C:\Program Files\Emsisoft Anti-Malware\epp.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One month (created) ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2019-08-12 15:44 - 2019-08-12 15:47 - 000036896 _____ C:\Users\Annette\Desktop\FRST.txt
2019-08-12 15:30 - 2019-08-12 15:46 - 000000000 ____D C:\Users\Annette\AppData\Local\PackageStaging
2019-08-12 15:29 - 2019-08-12 15:29 - 000224408 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
2019-08-12 15:29 - 2019-08-12 15:29 - 000199768 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys
2019-08-12 15:29 - 2019-08-12 15:29 - 000116112 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2019-08-12 15:29 - 2019-08-12 15:29 - 000073584 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2019-08-11 23:33 - 2019-08-11 23:33 - 000275232 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2019-08-11 15:55 - 2019-08-11 15:55 - 000000207 _____ C:\Windows\tweaking.com-regbackup-MRSJOHNSON-Windows-8.1-(64-bit).dat
2019-08-11 15:54 - 2019-08-11 15:54 - 000000000 ____D C:\RegBackup
2019-08-11 15:52 - 2019-08-11 15:52 - 000002182 _____ C:\Users\Annette\Desktop\Tweaking.com - Windows Repair.lnk
2019-08-11 15:50 - 2019-08-11 15:50 - 000003662 _____ C:\Windows\System32\Tasks\Tweaking.com - Windows Repair Tray Icon
2019-08-11 15:50 - 2019-08-11 15:50 - 000000000 ____D C:\Users\Annette\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Tweaking.com
2019-08-11 15:49 - 2019-08-11 15:49 - 000000000 ____D C:\Program Files (x86)\Tweaking.com
2019-08-11 15:47 - 2019-08-11 15:52 - 000311878 _____ C:\Windows\Tweaking.com - Windows Repair Setup Log.txt
2019-08-11 15:42 - 2019-08-11 15:42 - 038907848 _____ (Tweaking.com) C:\Users\Annette\Desktop\TWKG.exe
2019-08-11 04:47 - 2019-08-12 15:43 - 000000000 ____D C:\Users\Annette\Desktop\FRST-OlderVersion
2019-08-07 21:52 - 2019-08-07 21:52 - 000001850 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2019-08-07 21:52 - 2019-08-07 21:52 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2019-08-07 21:52 - 2019-01-08 16:32 - 000153328 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbae64.sys
2019-08-07 21:44 - 2019-08-07 21:47 - 064333800 _____ (Malwarebytes ) C:\Users\Annette\Desktop\mb3-setup-1878.1878-3.8.3.2965 (1).exe
2019-08-06 16:30 - 2019-08-06 16:30 - 064333800 _____ (Malwarebytes ) C:\Users\Annette\Desktop\mb3-setup-1878.1878-3.8.3.2965.exe
2019-08-05 23:20 - 2019-08-11 04:47 - 002097664 _____ (Farbar) C:\Users\Annette\Desktop\FRST64.exe
2019-08-04 16:27 - 2019-08-04 16:28 - 007623880 _____ (Malwarebytes) C:\Users\Annette\Desktop\ADWCLNR.exe
2019-08-01 08:12 - 2019-08-11 04:52 - 000002352 _____ C:\Users\Annette\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive for Business.lnk
2019-07-31 23:46 - 2019-06-24 21:59 - 004169728 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2019-07-31 23:46 - 2019-06-17 23:34 - 025730560 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2019-07-31 23:46 - 2019-06-17 23:07 - 000578560 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2019-07-31 23:46 - 2019-06-17 22:59 - 005775872 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2019-07-31 23:46 - 2019-06-17 22:56 - 020274688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2019-07-31 23:46 - 2019-06-17 22:56 - 000790528 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2019-07-31 23:46 - 2019-06-17 22:39 - 000496128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2019-07-31 23:46 - 2019-06-17 22:29 - 000663040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2019-07-31 23:46 - 2019-06-17 22:28 - 001033216 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2019-07-31 23:46 - 2019-06-17 22:20 - 000809472 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2019-07-31 23:46 - 2019-06-17 22:19 - 015311872 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2019-07-31 23:46 - 2019-06-17 22:08 - 000880640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2019-07-31 23:46 - 2019-06-17 22:07 - 004494336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2019-07-31 23:46 - 2019-06-17 22:06 - 004858880 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2019-07-31 23:46 - 2019-06-17 22:03 - 013706752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2019-07-31 23:46 - 2019-06-17 22:03 - 000696320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2019-07-31 23:46 - 2019-06-17 21:55 - 001557504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2019-07-31 23:46 - 2019-06-17 21:44 - 004386304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2019-07-31 23:46 - 2019-06-17 21:41 - 001323008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2019-07-31 23:46 - 2019-06-15 10:22 - 000910848 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2019-07-31 23:46 - 2019-06-06 17:49 - 007362800 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2019-07-31 23:46 - 2019-06-06 12:14 - 000809472 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll
2019-07-31 23:46 - 2019-05-24 21:36 - 022373096 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2019-07-31 23:46 - 2019-05-24 21:30 - 000500464 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2019-07-31 23:46 - 2019-05-24 21:30 - 000272184 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2019-07-31 23:46 - 2019-05-24 20:59 - 019790160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2019-07-31 23:46 - 2019-05-24 20:56 - 000370872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2019-07-31 23:46 - 2019-05-24 20:22 - 002903552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2019-07-31 23:46 - 2019-05-24 19:50 - 000315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2019-07-31 23:46 - 2019-05-24 19:42 - 002297344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2019-07-31 23:46 - 2019-05-24 19:40 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2019-07-31 23:46 - 2019-05-24 19:38 - 000728064 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2019-07-31 23:46 - 2019-05-24 19:38 - 000381440 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2019-07-31 23:46 - 2019-05-24 19:36 - 002136064 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2019-07-31 23:46 - 2019-05-24 19:23 - 000279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2019-07-31 23:46 - 2019-05-24 19:23 - 000076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2019-07-31 23:46 - 2019-05-24 19:17 - 000230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2019-07-31 23:46 - 2019-05-24 19:16 - 000333312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2019-07-31 23:46 - 2019-05-24 19:15 - 002060288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2019-07-31 23:46 - 2019-05-11 10:50 - 001441792 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2019-07-31 23:46 - 2019-05-09 02:41 - 003325440 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2019-07-31 23:46 - 2019-05-09 01:30 - 003619328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2019-07-31 23:46 - 2019-05-05 22:47 - 001311768 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2019-07-31 23:46 - 2019-05-05 22:33 - 001136208 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2019-07-31 23:46 - 2019-05-05 21:12 - 000861184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2019-07-31 23:46 - 2019-05-05 21:08 - 001040384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2019-07-31 23:46 - 2019-05-05 20:41 - 001197056 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Globalization.dll
2019-07-31 23:46 - 2019-04-06 19:57 - 001214720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2019-07-31 23:46 - 2019-04-06 13:39 - 002172832 _____ (Microsoft Corporation) C:\Windows\system32\combase.dll
2019-07-31 23:46 - 2019-04-06 13:39 - 001662512 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2019-07-31 23:46 - 2019-04-04 18:58 - 000863232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Globalization.dll
2019-07-31 23:46 - 2019-04-04 17:15 - 000513416 _____ C:\Windows\SysWOW64\locale.nls
2019-07-31 23:46 - 2019-04-04 17:15 - 000513416 _____ C:\Windows\system32\locale.nls
2019-07-31 23:45 - 2019-06-24 22:54 - 001368080 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2019-07-31 23:45 - 2019-06-24 21:36 - 000128512 _____ (Microsoft Corporation) C:\Windows\splwow64.exe
2019-07-31 23:45 - 2019-06-24 21:07 - 001994240 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2019-07-31 23:45 - 2019-06-24 20:48 - 001756160 _____ (Microsoft Corporation) C:\Windows\system32\GdiPlus.dll
2019-07-31 23:45 - 2019-06-24 20:44 - 000302080 _____ (Microsoft Corporation) C:\Windows\system32\ProximityService.dll
2019-07-31 23:45 - 2019-06-24 20:42 - 000175616 _____ (Microsoft Corporation) C:\Windows\system32\TpmTasks.dll
2019-07-31 23:45 - 2019-06-24 20:41 - 001085440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2019-07-31 23:45 - 2019-06-24 20:41 - 000302080 _____ (Microsoft Corporation) C:\Windows\system32\wlanapi.dll
2019-07-31 23:45 - 2019-06-24 20:39 - 001559552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2019-07-31 23:45 - 2019-06-24 20:36 - 001549824 _____ (Microsoft Corporation) C:\Windows\system32\wlansvc.dll
2019-07-31 23:45 - 2019-06-24 20:31 - 001494016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\GdiPlus.dll
2019-07-31 23:45 - 2019-06-24 20:28 - 000827392 _____ (Microsoft Corporation) C:\Windows\system32\spoolsv.exe
2019-07-31 23:45 - 2019-06-24 20:26 - 000238080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanapi.dll
2019-07-31 23:45 - 2019-06-17 22:13 - 000166912 _____ (Microsoft Corporation) C:\Windows\system32\AppxAllUserStore.dll
2019-07-31 23:45 - 2019-06-17 22:06 - 000269312 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentClient.dll
2019-07-31 23:45 - 2019-06-17 21:55 - 000214528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppXDeploymentClient.dll
2019-07-31 23:45 - 2019-06-17 21:43 - 000800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2019-07-31 23:45 - 2019-06-17 21:42 - 001349120 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentServer.dll
2019-07-31 23:45 - 2019-06-17 21:39 - 000710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2019-07-31 23:45 - 2019-06-17 21:33 - 000956416 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.dll
2019-07-31 23:45 - 2019-06-11 19:51 - 000169256 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2019-07-31 23:45 - 2019-06-11 08:37 - 000293888 _____ (Microsoft Corporation) C:\Windows\system32\Dism.exe
2019-07-31 23:45 - 2019-06-11 08:35 - 000215040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Dism.exe
2019-07-31 23:45 - 2019-06-10 16:42 - 001712640 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2019-07-31 23:45 - 2019-06-10 16:42 - 000801792 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2019-07-31 23:45 - 2019-06-10 16:42 - 000732160 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2019-07-31 23:45 - 2019-06-10 16:42 - 000634368 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2019-07-31 23:45 - 2019-06-10 16:42 - 000501760 _____ (Microsoft Corporation) C:\Windows\system32\centel.dll
2019-07-31 23:45 - 2019-06-10 16:42 - 000456192 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2019-07-31 23:45 - 2019-06-10 16:42 - 000315904 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2019-07-31 23:45 - 2019-06-10 16:42 - 000257024 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2019-07-31 23:45 - 2019-06-08 11:09 - 000445440 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2019-07-31 23:45 - 2019-06-08 10:55 - 001101824 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2019-07-31 23:45 - 2019-06-08 10:43 - 000324096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2019-07-31 23:45 - 2019-06-08 10:33 - 000856064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll
2019-07-31 23:45 - 2019-06-08 09:55 - 007035392 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2019-07-31 23:45 - 2019-06-08 09:53 - 006217216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2019-07-31 23:45 - 2019-06-02 10:42 - 000365056 _____ (Microsoft Corporation) C:\Windows\system32\rdpclip.exe
2019-07-31 23:45 - 2019-05-31 11:55 - 001265152 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2019-07-31 23:45 - 2019-05-31 11:54 - 000504832 _____ (Microsoft Corporation) C:\Windows\system32\taskcomp.dll
2019-07-31 23:45 - 2019-05-31 11:53 - 000394240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\taskcomp.dll
2019-07-31 23:45 - 2019-05-24 21:32 - 002013432 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2019-07-31 23:45 - 2019-05-24 21:30 - 000394568 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2019-07-31 23:45 - 2019-05-24 20:56 - 000344984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
2019-07-31 23:45 - 2019-05-24 19:52 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2019-07-31 23:45 - 2019-05-24 19:50 - 000145408 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2019-07-31 23:45 - 2019-05-24 19:31 - 000963072 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2019-07-31 23:45 - 2019-05-24 19:23 - 000128000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2019-07-31 23:45 - 2019-05-24 19:19 - 000551152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vhdmp.sys
2019-07-31 23:45 - 2019-05-24 19:17 - 000230400 _____ (Microsoft Corporation) C:\Windows\system32\AudioEndpointBuilder.dll
2019-07-31 23:45 - 2019-05-22 13:20 - 000120312 _____ (Microsoft Corporation) C:\Windows\system32\userenv.dll
2019-07-31 23:45 - 2019-05-22 12:50 - 000098320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\userenv.dll
2019-07-31 23:45 - 2019-05-20 19:50 - 001383424 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2019-07-31 23:45 - 2019-05-16 23:47 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\mf3216.dll
2019-07-31 23:45 - 2019-05-16 23:07 - 000046080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf3216.dll
2019-07-31 23:45 - 2019-05-16 13:23 - 000444144 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2019-07-31 23:45 - 2019-05-16 13:22 - 000334280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2019-07-31 23:45 - 2019-05-15 15:33 - 000333552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Classpnp.sys
2019-07-31 23:45 - 2019-05-14 19:53 - 000136800 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2019-07-31 23:45 - 2019-05-14 15:23 - 000377800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\clfs.sys
2019-07-31 23:45 - 2019-05-14 09:18 - 003718144 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2019-07-31 23:45 - 2019-05-11 10:46 - 000840704 _____ (Microsoft Corporation) C:\Windows\system32\netlogon.dll
2019-07-31 23:45 - 2019-05-11 10:34 - 000697344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netlogon.dll
2019-07-31 23:45 - 2019-05-10 08:20 - 001311744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjet40.dll
2019-07-31 23:45 - 2019-05-10 08:20 - 000353280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrd3x40.dll
2019-07-31 23:45 - 2019-05-10 08:20 - 000341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msexcl40.dll
2019-07-31 23:45 - 2019-05-10 08:20 - 000241152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msltus40.dll
2019-07-31 23:45 - 2019-05-09 01:40 - 002779648 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2019-07-31 23:45 - 2019-05-09 00:47 - 002464256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2019-07-31 23:45 - 2019-05-05 22:36 - 001677024 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2019-07-31 23:45 - 2019-05-05 22:36 - 001537776 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2019-07-31 23:45 - 2019-05-05 22:34 - 000805384 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2019-07-31 23:45 - 2019-04-24 17:38 - 002452208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2019-07-31 23:45 - 2019-04-14 11:37 - 000096768 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2019-07-31 23:45 - 2019-04-14 11:35 - 000148992 _____ (Microsoft Corporation) C:\Windows\system32\t2embed.dll
2019-07-31 23:45 - 2019-04-14 11:09 - 000078336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2019-07-31 23:45 - 2019-04-14 11:07 - 000113664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\t2embed.dll
2019-07-31 23:45 - 2019-04-12 08:20 - 000994384 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll
2019-07-31 23:45 - 2019-04-12 08:20 - 000914584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll
2019-07-31 23:45 - 2019-04-12 08:20 - 000064248 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll
2019-07-31 23:45 - 2019-04-08 17:17 - 000537096 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2019-07-31 23:45 - 2019-04-08 17:17 - 000139912 _____ (Microsoft Corporation) C:\Windows\system32\wermgr.exe
2019-07-31 23:45 - 2019-04-08 17:13 - 000449744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2019-07-31 23:45 - 2019-04-08 17:12 - 000136736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wermgr.exe
2019-07-31 23:45 - 2019-04-08 16:40 - 000136432 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wfplwfs.sys
2019-07-31 23:45 - 2019-04-06 15:31 - 000376320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mspbde40.dll
2019-07-31 23:45 - 2019-04-05 17:47 - 000096208 _____ (Microsoft Corporation) C:\Windows\system32\cryptdll.dll
2019-07-31 23:45 - 2019-04-05 17:46 - 000177608 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2019-07-31 23:45 - 2019-04-05 17:44 - 000073248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptdll.dll
2019-07-31 23:45 - 2019-04-05 09:06 - 001253888 _____ (Microsoft Corporation) C:\Windows\system32\werconcpl.dll
2019-07-31 23:45 - 2019-04-05 09:06 - 000176640 _____ (Microsoft Corporation) C:\Windows\system32\werui.dll
2019-07-31 23:45 - 2019-04-05 09:06 - 000086528 _____ (Microsoft Corporation) C:\Windows\system32\wercplsupport.dll
2019-07-31 23:45 - 2019-04-05 09:01 - 000160256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\werui.dll
2019-07-31 23:45 - 2019-04-04 13:01 - 000469504 _____ (Microsoft Corporation) C:\Windows\system32\nltest.exe
2019-07-31 23:45 - 2019-04-04 12:10 - 001080320 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2019-07-31 23:45 - 2019-04-04 11:48 - 000713216 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2019-07-31 23:45 - 2019-04-04 11:15 - 000562176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2019-07-31 21:46 - 2019-07-31 21:46 - 000002448 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype for Business.lnk
2019-07-31 21:46 - 2019-07-31 21:46 - 000002443 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk
2019-07-31 21:46 - 2019-07-31 21:46 - 000002442 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk
2019-07-31 21:46 - 2019-07-31 21:46 - 000002406 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access.lnk
2019-07-31 21:46 - 2019-07-31 21:46 - 000002405 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk
2019-07-31 21:46 - 2019-07-31 21:46 - 000002399 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook.lnk
2019-07-31 21:46 - 2019-07-31 21:46 - 000002393 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher.lnk
2019-07-31 21:46 - 2019-07-31 21:46 - 000002385 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk
2019-07-31 21:46 - 2019-07-31 21:46 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools
2019-07-22 23:15 - 2019-08-02 00:40 - 000000000 ____D C:\Users\Annette\free ebooks
 
==================== One month (modified) ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2019-08-12 15:47 - 2013-08-22 10:36 - 000000000 ____D C:\Windows\AppReadiness
2019-08-12 15:46 - 2015-09-14 16:50 - 000003594 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1409944621-189731363-133459071-1005
2019-08-12 15:44 - 2019-04-02 19:50 - 000000000 ____D C:\FRST
2019-08-12 15:42 - 2015-09-14 16:49 - 000000000 ____D C:\Users\Annette\Documents\Youcam
2019-08-12 15:34 - 2018-08-10 22:13 - 000000000 ____D C:\Users\Annette\AppData\Local\CrashDumps
2019-08-12 15:30 - 2018-04-14 00:12 - 000000572 _____ C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-1409944621-189731363-133459071-1005.job
2019-08-12 15:29 - 2015-09-14 16:49 - 000000000 __RDO C:\Users\Annette\OneDrive
2019-08-12 15:20 - 2015-03-19 15:56 - 000000000 ____D C:\ProgramData\boost_interprocess
2019-08-11 23:45 - 2017-03-08 20:56 - 000000000 ____D C:\ProgramData\Kaspersky Lab
2019-08-11 23:33 - 2013-08-22 09:45 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2019-08-11 23:32 - 2013-08-22 09:44 - 000502256 _____ C:\Windows\system32\FNTCACHE.DAT
2019-08-11 23:31 - 2013-08-22 08:25 - 000524288 ___SH C:\Windows\system32\config\BBI
2019-08-11 23:16 - 2013-08-22 10:20 - 000000000 ____D C:\Windows\CbsTemp
2019-08-11 22:41 - 2018-04-14 00:12 - 000000668 _____ C:\Windows\Tasks\G2MUploadTask-S-1-5-21-1409944621-189731363-133459071-1005.job
2019-08-11 18:33 - 2017-03-27 08:16 - 000000000 ____D C:\Users\Annette\Documents\Human Relations & Team Bldg - PSA
2019-08-11 18:33 - 2015-01-31 19:38 - 000000000 ____D C:\Users\Jacquelyn\Downloads\movies
2019-08-11 18:33 - 2015-01-20 12:30 - 000000000 ____D C:\Users\Jacquelyn\Downloads\New folder
2019-08-11 18:33 - 2014-11-19 16:51 - 000000000 ____D C:\Users\Jacquelyn\Documents\Youcam
2019-08-11 17:37 - 2013-08-22 08:25 - 000000298 _____ C:\Windows\win.ini
2019-08-11 16:56 - 2015-11-17 17:45 - 000003942 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{3464BE36-788D-4EB3-890E-849F1DD7BE9F}
2019-08-11 09:46 - 2013-08-22 08:36 - 000000000 ____D C:\Windows\Inf
2019-08-11 09:38 - 2013-08-22 10:36 - 000000000 ___RD C:\Windows\ToastData
2019-08-11 09:37 - 2014-12-17 21:22 - 000000000 ____D C:\Windows\system32\appraiser
2019-08-11 09:37 - 2013-08-22 08:36 - 000000000 ____D C:\Windows\SysWOW64\Dism
2019-08-11 09:37 - 2013-08-22 08:36 - 000000000 ____D C:\Windows\system32\Dism
2019-08-11 04:53 - 2018-12-22 12:09 - 000003182 _____ C:\Windows\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1409944621-189731363-133459071-1005
2019-08-11 04:44 - 2015-01-14 17:12 - 000004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2019-08-11 04:41 - 2018-07-29 19:22 - 000000000 ____D C:\Program Files (x86)\Driver Support
2019-08-08 19:08 - 2013-08-22 10:36 - 000000000 ____D C:\Windows\rescache
2019-08-08 18:48 - 2013-08-22 10:36 - 000000000 ___HD C:\Program Files\WindowsApps
2019-08-07 21:51 - 2019-04-07 22:41 - 000000000 ____D C:\Program Files\Malwarebytes
2019-08-07 21:51 - 2016-02-13 23:07 - 000000000 ____D C:\ProgramData\Malwarebytes
2019-08-07 21:50 - 2014-11-19 18:48 - 000002251 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2019-08-07 21:27 - 2019-04-09 23:58 - 000000000 ____D C:\Program Files\Emsisoft Anti-Malware
2019-08-07 21:24 - 2017-03-11 09:31 - 000000000 ____D C:\ProgramData\Emsisoft
2019-08-04 19:03 - 2016-03-24 09:59 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2019-08-04 18:42 - 2014-11-23 19:05 - 136618864 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2019-08-04 18:42 - 2014-11-23 19:05 - 000000000 ____D C:\Windows\system32\MRT
2019-08-04 16:39 - 2015-04-07 21:03 - 000000000 ____D C:\Users\Annette
2019-08-04 16:30 - 2018-04-14 00:11 - 000000000 ____D C:\Users\Annette\AppData\Local\GoToMeeting
2019-08-02 00:42 - 2015-12-12 14:20 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2019-08-01 00:05 - 2014-11-19 18:47 - 000003332 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2019-08-01 00:05 - 2014-11-19 18:47 - 000003204 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2019-07-31 22:17 - 2018-04-14 00:12 - 000003676 _____ C:\Windows\System32\Tasks\G2MUploadTask-S-1-5-21-1409944621-189731363-133459071-1005
2019-07-31 22:17 - 2018-04-14 00:12 - 000003580 _____ C:\Windows\System32\Tasks\G2MUpdateTask-S-1-5-21-1409944621-189731363-133459071-1005
2019-07-31 21:57 - 2013-08-22 10:36 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2019-07-31 21:37 - 2014-04-22 12:28 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2019-07-22 21:12 - 2014-09-09 21:21 - 000065536 _____ C:\Windows\system32\spu_storage.bin
 
==================== SigCheck ===============================
 
(There is no automatic fix for files that do not pass verification.)
 
 
LastRegBack: 2019-08-08 18:54
==================== End of FRST.txt ============================

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI