Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 93100 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

Unexpected Chrome Shutdown & Black Screens

Chrome shutdown Black screen

  • This topic is locked This topic is locked
11 replies to this topic

#1 rockaway1

rockaway1

    Authentic Member

  • Authentic Member
  • PipPip
  • 35 posts

Posted 13 April 2022 - 04:18 PM

I've experienced unexpected instability while running chrome.  In some instances chrome shuts down and other times the screen goes black.

Here are 2 logs from Farbar

 

Log 1

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 13-04-2022 01
Ran by AA583803 (administrator) on AA585803-L (Dell Inc. Latitude 7390 2-in-1) (13-04-2022 18:09:20)
Running from C:\Users\AA583803\OneDrive - MassMutual\Desktop
Loaded Profiles: AA583803
Platform: Microsoft Windows 10 Pro Version 21H2 19044.1586 (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(ALPS ALPINE CO., LTD. -> ALPSALPINE CO., LTD.) C:\Windows\System32\DellTPad\ApntEx.exe
(Apple Inc.) C:\Program Files\WindowsApps\AppleInc.iCloud_13.0.201.0_x86__nzyj5cx40ttqa\iCloud\iCloudIE.exe
(C:\Program Files (x86)\Airwatch\AgentUI\TaskScheduler.exe ->) (VMware, Inc. -> VMware, Inc.) C:\Program Files (x86)\Airwatch\AgentUI\AWACMClient.exe
(C:\Program Files (x86)\Airwatch\AgentUI\TaskScheduler.exe ->) (VMware, Inc. -> VMware, Inc.) C:\Program Files (x86)\Airwatch\AgentUI\AwWindowsIpc.exe
(C:\Program Files (x86)\Dropbox\Client\Dropbox.exe ->) (Dropbox, Inc -> The Qt Company Ltd.) C:\Program Files (x86)\Dropbox\Client\145.4.4921\QtWebEngineProcess.exe <2>
(C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\splwow64.exe
(C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe ->) (Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe <17>
(C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe ->) (Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe <2>
(C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe <2>
(C:\Program Files\CrowdStrike\CSFalconService.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> CrowdStrike, Inc.) C:\Program Files\CrowdStrike\CSFalconContainer.exe <2>
(C:\Program Files\Logitech\LogiOptions\LogiOptions.exe ->) (Logitech Inc -> Logitech) C:\ProgramData\Logishrd\LogiOptions\Software\Current\LogiOverlay.exe
(C:\Program Files\Logitech\LogiOptions\LogiOptions.exe ->) (Logitech Inc -> Logitech, Inc.) C:\ProgramData\Logishrd\LogiOptions\Software\Current\LogiOptionsMgr.exe
(C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe <3>
(Canon Inc. -> CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe
(Canon Inc. -> CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX2\CNMNSST2.exe
(DellTPad\Apoint.exe ->) (ALPS ALPINE CO., LTD. -> ALPSALPINE CO., LTD.) C:\Windows\System32\DellTPad\ApMsgFwd.exe
(DellTPad\Apoint.exe ->) (ALPS ALPINE CO., LTD. -> ALPSALPINE Co., Ltd.) C:\Windows\System32\DellTPad\hidfind.exe
(DellTPad\Apoint.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> ALPSALPINE Co., Ltd.) C:\Windows\System32\DellTPad\ApRemote.exe
(DellTPad\HidMonitorSvc.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> ALPSALPINE Co., Ltd.) C:\Windows\System32\DellTPad\Apoint.exe
(DriverStore\FileRepository\igdlh64.inf_amd64_45855586d601d062\igfxCUIService.exe ->) (Intel® pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_45855586d601d062\igfxEM.exe
(Dropbox, Inc -> Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe <3>
(explorer.exe ->) (Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe <2>
(explorer.exe ->) (Apple Inc.) C:\Program Files\WindowsApps\AppleInc.iCloud_13.0.201.0_x86__nzyj5cx40ttqa\iCloud\ApplePhotoStreams.exe
(explorer.exe ->) (Apple Inc.) C:\Program Files\WindowsApps\AppleInc.iCloud_13.0.201.0_x86__nzyj5cx40ttqa\iCloud\iCloudDrive.exe
(explorer.exe ->) (Apple Inc.) C:\Program Files\WindowsApps\AppleInc.iCloud_13.0.201.0_x86__nzyj5cx40ttqa\iCloud\iCloudPhotos.exe
(explorer.exe ->) (Apple Inc.) C:\Program Files\WindowsApps\AppleInc.iCloud_13.0.201.0_x86__nzyj5cx40ttqa\iCloud\iCloudServices.exe
(explorer.exe ->) (Apple Inc.) C:\Program Files\WindowsApps\AppleInc.iTunes_12123.5.56009.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe
(explorer.exe ->) (Google LLC -> ) C:\Program Files\Google\Drive File Stream\56.0.11.0\crashpad_handler.exe <3>
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <14>
(explorer.exe ->) (Google LLC -> Google, Inc.) C:\Program Files\Google\Drive File Stream\56.0.11.0\GoogleDriveFS.exe <7>
(explorer.exe ->) (Logitech Inc -> Logitech, Inc.) C:\Program Files\Logitech\LogiOptions\LogiOptions.exe
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
(explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(explorer.exe ->) (U3 LLC -> ) C:\ProgramData\U3\U3Launcher\LaunchU3.exe
(explorer.exe ->) (Waves Inc -> Waves Audio Ltd.) C:\Program Files\Waves\MaxxAudio\WavesSvc64.exe
(explorer.exe ->) (Xerox Corporation) [File not signed] C:\Program Files\Xerox\Xerox Workplace Cloud Client\JobSubmission\JobSubmission.exe
(explorer.exe ->) (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.) C:\Users\AA583803\AppData\Roaming\Zoom\bin\Zoom.exe <2>
(Intel\DPTF\esif_uf.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\Intel\DPTF\dptf_helper.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\msoasb.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\AA583803\AppData\Local\Microsoft\Teams\current\Teams.exe <8>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MusNotifyIcon.exe
(SearchIndexer.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (ALPS ALPINE CO., LTD. -> ALPSALPINE Co., Ltd.) C:\Windows\System32\DellTPad\HidMonitorSvc.exe
(services.exe ->) (Canon Inc. -> ) C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(services.exe ->) (Dell Inc -> ) C:\Program Files (x86)\Dell\UpdateService\ServiceShell.exe
(services.exe ->) (Dell Inc -> Dell Inc.) C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe
(services.exe ->) (Dell Technologies Inc. -> Dell Technologies Inc.) C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe
(services.exe ->) (Dell Technologies Inc. -> Dell Technologies Inc.) C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe
(services.exe ->) (Dell Technologies Inc. -> Dell Technologies Inc.) C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe
(services.exe ->) (Dropbox, Inc -> Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
(services.exe ->) (GeoComply USA, Inc. -> GeoComply) C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\service.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\Intel\DPTF\esif_uf.exe
(services.exe ->) (Intel Corporation -> Intel® Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(services.exe ->) (Intel Corporation -> Intel® Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(services.exe ->) (Intel Corporation -> Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(services.exe ->) (Intel® Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe
(services.exe ->) (Intel® Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(services.exe ->) (Intel® pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_45855586d601d062\igfxCUIService.exe
(services.exe ->) (Intel® pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_45855586d601d062\IntelCpHDCPSvc.exe
(services.exe ->) (Intel® pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_45855586d601d062\IntelCpHeciSvc.exe
(services.exe ->) (Intel® Rapid Storage Technology -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iastorac.inf_amd64_9c788f1d162b1224\RstMwService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> CrowdStrike, Inc.) C:\Program Files\CrowdStrike\CSFalconService.exe
(services.exe ->) (PC-Doctor, Inc. -> PC-Doctor, Inc.) C:\Program Files\Dell\SupportAssistAgent\PCD\SupportAssist\Dsapi.exe
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(services.exe ->) (VMware, Inc. -> VMware, Inc.) C:\Program Files (x86)\Airwatch\AgentUI\TaskScheduler.exe
(services.exe ->) (VMware, Inc. -> VMware, Inc.) C:\Program Files (x86)\Airwatch\HealthMonitoring\Service\VMwareHubHealthMonitoring.exe
(services.exe ->) (Wacom Technology Corporation -> Wacom Technology, Corp.) C:\Windows\System32\DriverStore\FileRepository\wtabletserviceisd.inf_amd64_30083e9f0e289fee\WTabletServiceISD.exe <2>
(services.exe ->) (Waves Inc -> Waves Audio Ltd.) C:\Program Files\Waves\MaxxAudio\WavesSysSvc64.exe
(services.exe ->) (Xerox Corporation) [File not signed] C:\Program Files\Xerox\Xerox Workplace Cloud Client\Xerox.Cloud.VirtualPrint.ClientService\Xerox.Cloud.VirtualPrint.ClientService.exe
(svchost.exe ->) (Apple Inc.) C:\Program Files\WindowsApps\AppleInc.iCloud_13.0.201.0_x86__nzyj5cx40ttqa\iCloud\APSDaemon.exe
(svchost.exe ->) (Apple Inc.) C:\Program Files\WindowsApps\AppleInc.iCloud_13.0.201.0_x86__nzyj5cx40ttqa\iCloud\secd.exe
(svchost.exe ->) (Dropbox, Inc -> Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Users\AA583803\AppData\Local\Microsoft\OneDrive\22.055.0313.0001\FileCoAuth.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
 
==================== Registry (Whitelisted) ===================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [11235936 2020-08-14] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_PushButton] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [3618096 2020-08-14] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [LogiOptions] => C:\Program Files\Logitech\LogiOptions\LogiOptions.exe [2176648 2018-12-14] (Logitech Inc -> Logitech, Inc.)
HKLM\...\Run: [XMPCJobMonitor] => C:\Program Files\Xerox\Xerox Workplace Cloud Client\JobSubmission\JobSubmission.exe [195584 2019-11-12] (Xerox Corporation) [File not signed]
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [3831808 2021-08-30] (Microsoft Windows Hardware Compatibility Publisher -> Logitech)
HKLM\...\Run: [WavesSvc] => c:\Program Files\Waves\MaxxAudio\WavesSvc64.exe [1229080 2020-03-31] (Waves Inc -> Waves Audio Ltd.)
HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [438888 2014-01-15] (Canon Inc. -> CANON INC.)
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [10585376 2022-03-27] (Dropbox, Inc -> Dropbox, Inc.)
HKLM-x32\...\Run: [IJNetworkScannerSelectorEX2] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX2\CNMNSST2.exe [278440 2019-12-05] (Canon Inc. -> CANON INC.)
HKU\S-1-5-19\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\56.0.11.0\GoogleDriveFS.exe [53664656 2022-03-30] (Google LLC -> Google, Inc.)
HKU\S-1-5-20\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\56.0.11.0\GoogleDriveFS.exe [53664656 2022-03-30] (Google LLC -> Google, Inc.)
HKU\S-1-5-21-1146508179-405363288-658039003-1003\...\Run: [com.squirrel.Teams.Teams] => C:\Users\AA583803\AppData\Local\Microsoft\Teams\Update.exe [2490040 2022-03-03] (Microsoft 3rd Party Application Component -> Microsoft Corporation)
HKU\S-1-5-21-1146508179-405363288-658039003-1003\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\56.0.11.0\GoogleDriveFS.exe [53664656 2022-03-30] (Google LLC -> Google, Inc.)
HKU\S-1-5-21-1146508179-405363288-658039003-1003\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\scrnsave.scr [39936 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-18\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [324976 2010-05-21] (Flexera Software, Inc.  -> Flexera Software, Inc.)
HKU\S-1-5-18\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\56.0.11.0\GoogleDriveFS.exe [53664656 2022-03-30] (Google LLC -> Google, Inc.)
HKLM\...\Windows x64\Print Processors\Canon TR8600 series Print Processor: C:\Windows\System32\spool\prtprocs\x64\CNMPDGU.DLL [525824 2021-09-12] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Windows x64\Print Processors\hpcpp215: C:\Windows\System32\spool\prtprocs\x64\hpcpp215.dll [770232 2018-03-04] (HP Inc. -> HP Inc.)
HKLM\...\Windows x64\Print Processors\XeroxV5Print: C:\Windows\System32\spool\prtprocs\x64\x5print.dll [95232 2021-06-03] (Microsoft Windows Hardware Compatibility Publisher -> Xerox Corporation)
HKLM\...\Print\Monitors\Canon BJ FAX Language Monitor TR8600 series: C:\WINDOWS\system32\CNCALGU.DLL [258048 2020-03-18] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\Canon BJ Language Monitor MG6600 series: CNMLMC9.DLL
HKLM\...\Print\Monitors\Canon BJ Language Monitor TR8600 series: C:\WINDOWS\system32\CNMLMGU.DLL [1355264 2021-09-12] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\Canon BJNP Port: C:\WINDOWS\system32\CNMN6PPM.DLL [375296 2014-03-17] (CANON INC.) [File not signed]
HKLM\...\Print\Monitors\HP Universal Print Monitor: C:\WINDOWS\system32\HPMPW082.DLL [128184 2018-03-04] (HP Inc. -> HP Inc.)
HKLM\...\Print\Monitors\HPMLM190: C:\WINDOWS\system32\hpmlm190.dll [310968 2018-03-04] (HP Inc. -> HP Inc.)
HKLM\...\Print\Monitors\Xerox Cloud Port Monitor: C:\WINDOWS\system32\XMPCPortMon.dll [349184 2018-04-18] (Xerox Corporation) [File not signed]
HKLM\...\Print\Monitors\Xerox Virtualization Port: C:\WINDOWS\system32\x5lrsl.dll [135168 2021-06-03] (Microsoft Windows Hardware Compatibility Publisher -> Xerox Corporation)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\100.0.4896.75\Installer\chrmstp.exe [2022-04-06] (Google LLC -> Google LLC)
Startup: C:\Users\AA583803\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LaunchU3.exe.lnk [2019-02-11]
ShortcutTarget: LaunchU3.exe.lnk -> C:\Users\AA583803\AppData\Roaming\Microsoft\Installer\{D8E363A7-88B7-446D-B2C0-E26CE4DC8E54}\_294823.exe () [File not signed]
Startup: C:\Users\AA583803\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RingCentral.lnk [2021-09-14]
ShortcutTarget: RingCentral.lnk -> C:\Users\AA583803\AppData\Local\Programs\RingCentral\RingCentral.exe (No File)
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION
 
==================== Scheduled Tasks (Whitelisted) ============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {0467277A-332B-4A71-8C89-79A851937A08} - System32\Tasks\Symantec Endpoint Protection\Symantec Endpoint Protection Error Analyzer => C:\Program Files\Symantec\14.0.3752.1000.105\Bin\SymErr.exe /analyze (No File)
Task: {047C7BF7-AB0B-4D37-8547-506A575A121B} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2019-01-08] (Google Inc -> Google Inc.)
Task: {05AD6016-3472-4E40-8589-69C3570095C9} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1564424 2021-11-18] (Adobe Inc. -> Adobe Inc.)
Task: {069FCE3D-C175-4042-A733-78E36B819635} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt application on switch user if service is up => C:\Program Files (x86)\Intel\Thunderbolt Software\\ConditionalAppStarter.exe [226008 2018-12-25] (Intel® Client Connectivity Division SW -> Intel Corporation)
Task: {0BC0BA1F-6AC2-4536-A85B-1C2268DE5290} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [115632 2022-04-12] (Microsoft Corporation -> Microsoft Corporation)
Task: {10721086-7850-46D7-A2DC-12E78C41483B} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\2FCDED1F-9CF4-452B-AD3C-CEAE571798E2\OS Edition Upgrade event listener created by enrollment client => C:\WINDOWS\system32\deviceenroller.exe [448512 2022-02-11] (Microsoft Windows -> Microsoft Corporation)
Task: {12508CED-FA9C-4D50-A94B-E12C3EFB9E57} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt application on login if service is up => C:\Program Files (x86)\Intel\Thunderbolt Software\\ConditionalAppStarter.exe [226008 2018-12-25] (Intel® Client Connectivity Division SW -> Intel Corporation)
Task: {1D8674D0-474A-47ED-B537-31A675053690} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\2FCDED1F-9CF4-452B-AD3C-CEAE571798E2\Schedule #1 created by enrollment client => C:\WINDOWS\system32\deviceenroller.exe [448512 2022-02-11] (Microsoft Windows -> Microsoft Corporation)
Task: {2137CF50-1EAF-4BAC-8340-3B0BAF21548B} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\2FCDED1F-9CF4-452B-AD3C-CEAE571798E2\Schedule to run OMADMClient by client => C:\WINDOWS\system32\omadmclient.exe [432128 2022-03-08] (Microsoft Windows -> Microsoft Corporation)
Task: {3A1CF712-6D22-4FE0-8D46-602DB456E46E} - \OneDrive Standalone Update Task-S-1-5-21-1146508179-405363288-658039003-1001 -> No File <==== ATTENTION
Task: {3F345019-E5A1-46B2-8F24-DB73B7BE34A9} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\2FCDED1F-9CF4-452B-AD3C-CEAE571798E2\Schedule #3 created by enrollment client => C:\WINDOWS\system32\deviceenroller.exe [448512 2022-02-11] (Microsoft Windows -> Microsoft Corporation)
Task: {4C52EDAE-B5AF-4D5C-8B6D-001A95F35383} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt service when hardware is detected => sc.exe start ThunderboltService
Task: {4EBADE0C-CD84-449F-B631-3770A8C22F40} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\2FCDED1F-9CF4-452B-AD3C-CEAE571798E2\Schedule created by enrollment client for renewal of certificate warning => C:\WINDOWS\system32\deviceenroller.exe [448512 2022-02-11] (Microsoft Windows -> Microsoft Corporation)
Task: {4EF4B17D-010E-4EBE-8602-18A72085EAAE} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [5439888 2022-01-20] (Microsoft Corporation -> Microsoft Corporation)
Task: {51FEA407-1BE9-4928-81A5-287B65F63451} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\2FCDED1F-9CF4-452B-AD3C-CEAE571798E2\PushRenewal => C:\WINDOWS\system32\deviceenroller.exe [448512 2022-02-11] (Microsoft Windows -> Microsoft Corporation)
Task: {5516DEF5-18A9-45F7-9E52-F85E5FA333A9} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\2FCDED1F-9CF4-452B-AD3C-CEAE571798E2\Schedule to run OMADMClient by server => C:\WINDOWS\system32\omadmclient.exe [432128 2022-03-08] (Microsoft Windows -> Microsoft Corporation)
Task: {5FDD8265-4F24-4869-B704-C17EB3720F10} - System32\Tasks\GeoComply Update Task => C:\Program Files (x86)\GeoComply\\PlayerLocationCheck\Update\GeoComplyUpdate.exe [3191272 2022-01-10] (GeoComply USA, Inc. -> GeoComply) -> /config=C:\Program Files (x86)\GeoComply\\PlayerLocationCheck\Update\GeoComplyUpdate.xml
Task: {66B71282-8905-4249-92DE-7FAEA5524D44} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [5439888 2022-01-20] (Microsoft Corporation -> Microsoft Corporation)
Task: {67A95341-70AC-4A00-BC39-5EB37DC18C42} - System32\Tasks\VMware\SfdAgent\Check Required Apps => C:\Program Files\VMware\SfdAgent\VMware.Hub.SfdAgent.DeployCmd.exe [30608 2021-08-20] (VMware, Inc. -> VMware EUC)
Task: {727D92C4-0CA5-4348-84B0-EA817BADA23C} - System32\Tasks\G2MUpdateTask-S-1-5-21-1146508179-405363288-658039003-1003 => C:\Users\AA583803\AppData\Local\GoToMeeting\19932\g2mupdate.exe [31176 2021-11-11] (LogMeIn, Inc. -> LogMeIn, Inc.)
Task: {81D3FADB-33BF-4658-A73C-F867C78EFE96} - System32\Tasks\Symantec Endpoint Protection\Symantec Endpoint Protection Error Processor => C:\Program Files\Symantec\14.0.3752.1000.105\Bin\SymErr.exe /submit (No File)
Task: {89C52B1D-7C79-413A-98EC-4C486F6EB81D} - System32\Tasks\VMwareHubHealthMonitoringJob => C:\Program Files (x86)\Airwatch\HealthMonitoring\Maintenance\VMwareHubHealthMonitoring.exe [15568 2022-03-17] (VMware, Inc. -> VMware, Inc.)
Task: {97FE8533-1FFE-4892-A97A-A8D974105433} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\2FCDED1F-9CF4-452B-AD3C-CEAE571798E2\PushLaunch => C:\WINDOWS\system32\deviceenroller.exe [448512 2022-02-11] (Microsoft Windows -> Microsoft Corporation)
Task: {99482EF8-F4AB-4A4E-A286-DC8A726FABB1} - System32\Tasks\LastPassUpdater => C:\Program Files (x86)\LastPass\Updater\Updater.exe [1319288 2022-02-14] (LogMeIn, Inc. -> LogMeIn Inc.)
Task: {A6EE8131-D7F3-4130-B755-F2D8459DBF6A} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\2FCDED1F-9CF4-452B-AD3C-CEAE571798E2\Provisioning initiated session => C:\WINDOWS\system32\deviceenroller.exe [448512 2022-02-11] (Microsoft Windows -> Microsoft Corporation)
Task: {A92012C5-75C4-44E4-A49C-1D47FE040D31} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [21864400 2022-04-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {B1A4FF7F-2F01-4E26-8E65-99AA3859DA8E} - System32\Tasks\Dell SupportAssistAgent AutoUpdate => C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistInstaller.exe [1060384 2021-11-15] (Dell Inc -> Dell Inc.)
Task: {B43156A6-74DD-469A-B9F9-732E1B8939C1} - System32\Tasks\VMware\SfdAgent\Install Validation Task => C:\Program Files\VMware\SfdAgent\VMware.Hub.SfdAgent.DeployCmd.exe [30608 2021-08-20] (VMware, Inc. -> VMware EUC)
Task: {BB7422E5-15E9-432E-AA68-406E6C3D1EEE} - System32\Tasks\Microsoft\Office\Office Serviceability Manager => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\officesvcmgr.exe [4102784 2022-02-06] (Microsoft Corporation -> Microsoft Corporation)
Task: {C1C51FF5-FF55-4566-A0EC-2D091017740E} - System32\Tasks\ApowerREC => C:\Program Files (x86)\Apowersoft\ApowerREC\ApowerREC.exe /autoStart (No File)
Task: {C5F8B471-9FDC-4E55-B966-6B6691E5A6C9} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [130320 2021-11-10] (Dropbox, Inc -> Dropbox, Inc.)
Task: {C85B7E30-F968-441A-9317-CACE4A6EEE4C} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\2FCDED1F-9CF4-452B-AD3C-CEAE571798E2\Passport for Work alert created by enrollment client => C:\WINDOWS\system32\deviceenroller.exe [448512 2022-02-11] (Microsoft Windows -> Microsoft Corporation)
Task: {CA3A1867-0675-452A-8C7A-DAC7FB0C6CBE} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\2FCDED1F-9CF4-452B-AD3C-CEAE571798E2\Win10 S Mode event listener created by enrollment client => C:\WINDOWS\system32\deviceenroller.exe [448512 2022-02-11] (Microsoft Windows -> Microsoft Corporation)
Task: {CD356E30-F06F-4078-B746-DEE1516EF923} - System32\Tasks\G2MUploadTask-S-1-5-21-1146508179-405363288-658039003-1003 => C:\Users\AA583803\AppData\Local\GoToMeeting\19932\g2mupload.exe [31176 2021-11-11] (LogMeIn, Inc. -> LogMeIn, Inc.)
Task: {CE895677-286B-4511-A3C0-51EAB2691BF6} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2019-01-08] (Google Inc -> Google Inc.)
Task: {CF377CCA-4259-4304-B839-F09C94A06BBB} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [1158576 2022-04-12] (Microsoft Corporation -> Microsoft Corporation)
Task: {D055B4B6-FC78-4474-A589-D1EA5CC0B67A} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt application when hardware is detected => C:\Program Files (x86)\Intel\Thunderbolt Software\\ConditionalAppStarter.exe [226008 2018-12-25] (Intel® Client Connectivity Division SW -> Intel Corporation)
Task: {D6909D20-0CD9-43AA-88D8-7B3C218A2755} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\2FCDED1F-9CF4-452B-AD3C-CEAE571798E2\Schedule #2 created by enrollment client => C:\WINDOWS\system32\deviceenroller.exe [448512 2022-02-11] (Microsoft Windows -> Microsoft Corporation)
Task: {D81D3ACE-DB1D-43BD-A45E-36C564BE8791} - System32\Tasks\Symantec Endpoint Protection\Symantec Endpoint Protection Autofix => C:\Program Files\Symantec\14.0.3752.1000.105\Bin\SymErr.exe /ui (No File)
Task: {D8602836-D7AC-4E00-912A-C92CE18E1D62} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\2FCDED1F-9CF4-452B-AD3C-CEAE571798E2\Wsc Startup event listener created by enrollment client => C:\WINDOWS\system32\deviceenroller.exe [448512 2022-02-11] (Microsoft Windows -> Microsoft Corporation)
Task: {E24B7596-7FF3-42EA-BE35-F0FDF8903B06} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\2FCDED1F-9CF4-452B-AD3C-CEAE571798E2\PushUpgrade => C:\WINDOWS\system32\deviceenroller.exe [448512 2022-02-11] (Microsoft Windows -> Microsoft Corporation)
Task: {EB72CF1A-6DAC-4E26-9993-7406966499B3} - System32\Tasks\VMware\SfdAgent\Software Distribution Queue Task => C:\Program Files\VMware\SfdAgent\VMware.Hub.SfdAgent.DeployCmd.exe [30608 2021-08-20] (VMware, Inc. -> VMware EUC)
Task: {EF49295D-3116-4D15-A093-1012862D40E5} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [21864400 2022-04-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {F5A18EDF-B5B1-48B8-B46E-797CE32A2D2C} - System32\Tasks\GeoComply Service Check => "C:\Program Files (x86)\GeoComply\\PlayerLocationCheck\Application\PlayerLocationCheckTask.cmd"  (No File)
Task: {F5F3A743-915F-40E0-B360-C85F1B54137D} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [115632 2022-04-12] (Microsoft Corporation -> Microsoft Corporation)
Task: {FC3BA724-6E91-4146-83E1-96E1052EEF9C} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt service on boot if driver is up => C:\Program Files (x86)\Intel\Thunderbolt Software\\tbtsvc.exe [2302168 2018-12-25] (Intel® Client Connectivity Division SW -> Intel Corporation)
Task: {FECAF8C5-FDC6-4FD2-B1AD-DB661C45C115} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [130320 2021-11-10] (Dropbox, Inc -> Dropbox, Inc.)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-1146508179-405363288-658039003-1003.job => C:\Users\AA583803\AppData\Local\GoToMeeting\19932\g2mupdate.exe
Task: C:\WINDOWS\Tasks\G2MUploadTask-S-1-5-21-1146508179-405363288-658039003-1003.job => C:\Users\AA583803\AppData\Local\GoToMeeting\19932\g2mupload.exe
Task: C:\WINDOWS\Tasks\VMwareHubHealthMonitoringJob.job => C:\Program Files (x86)\Airwatch\HealthMonitoring\Maintenance\VMwareHubHealthMonitoring.exe
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 170.6.240.26 170.6.241.166
Tcpip\..\Interfaces\{84e76070-f2bf-49f1-bbb2-4bfd1a7d3ce4}: [DhcpNameServer] 170.6.240.26 170.6.241.166
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <==== ATTENTION
 
Edge: 
=======
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
Edge Extension: (No Name) -> hdokiejnpimakedhajhdlcegeplioahd_LastPassLastPassFreePasswordManager_qq0fmhteeht3j => C:\Program Files\WindowsApps\LastPass.LastPassFreePasswordManager_4.48.0.0_neutral__qq0fmhteeht3j [not found]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
Edge DefaultProfile: Default
Edge Profile: C:\Users\AA583803\AppData\Local\Microsoft\Edge\User Data\Default [2022-04-06]
Edge HomePage: Default -> hxxps://massmutual.okta.com/
Edge Extension: (LastPass: Free Password Manager) - C:\Users\AA583803\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\bbcinlkgjjkejfdpemiealijmmooekmp [2022-03-28]
 
FireFox:
========
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation ->  Microsoft Corporation)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2022-03-02] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2017-10-17] (CANON INC.) [File not signed]
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2022-01-20] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation ->  Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2022-01-20] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin HKU\S-1-5-21-1146508179-405363288-658039003-1003: SkypeForBusinessPlugin-16.2 -> C:\Users\AA583803\AppData\Local\Microsoft\SkypeForBusinessPlugin\16.2.0.282\npGatewayNpapi.dll [2018-10-19] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin HKU\S-1-5-21-1146508179-405363288-658039003-1003: SkypeForBusinessPlugin64-16.2 -> C:\Users\AA583803\AppData\Local\Microsoft\SkypeForBusinessPlugin\16.2.0.282\npGatewayNpapi-x64.dll [2018-10-19] (Microsoft Corporation -> Microsoft Corporation)
 
Chrome: 
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\AA583803\AppData\Local\Google\Chrome\User Data\Default [2022-04-13]
CHR Notifications: Default -> hxxps://app.gotowebinar.com; hxxps://chatsupport.apple.com; hxxps://ocsnext.ebay.com; hxxps://www.jetblue.com; hxxps://www.verizon.com
CHR StartupUrls: Default -> "hxxps://massmutual.okta.com/"
CHR Extension: (Slides) - C:\Users\AA583803\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2019-01-08]
CHR Extension: (Docs) - C:\Users\AA583803\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2019-01-08]
CHR Extension: (Google Drive) - C:\Users\AA583803\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-10-27]
CHR Extension: (YouTube) - C:\Users\AA583803\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2019-01-08]
CHR Extension: (Honey) - C:\Users\AA583803\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmnlcjabgnpnenekpadlanbbkooimhnj [2022-04-13]
CHR Extension: (Screencast-O-Matic Launcher) - C:\Users\AA583803\AppData\Local\Google\Chrome\User Data\Default\Extensions\eefedolmcildfckjamddopaplfiiankl [2019-05-28]
CHR Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\AA583803\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2022-04-12]
CHR Extension: (Sheets) - C:\Users\AA583803\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2019-01-08]
CHR Extension: (Google Docs Offline) - C:\Users\AA583803\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2022-04-12]
CHR Extension: (LastPass: Free Password Manager) - C:\Users\AA583803\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd [2022-04-12]
CHR Extension: (App Launcher for Google Maps) - C:\Users\AA583803\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmiegoigendlbmjjllhjmkjenjechmhg [2019-01-09]
CHR Extension: (Application Launcher For Drive (by Google)) - C:\Users\AA583803\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2021-02-06]
CHR Extension: (Chrome Web Store Payments) - C:\Users\AA583803\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-02-06]
CHR Extension: (Print Friendly & PDF) - C:\Users\AA583803\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohlencieiipommannpdfcmfdpjjmeolj [2021-04-11]
CHR Extension: (Gmail) - C:\Users\AA583803\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-10-27]
CHR Profile: C:\Users\AA583803\AppData\Local\Google\Chrome\User Data\System Profile [2019-08-24]
CHR HKU\S-1-5-21-1146508179-405363288-658039003-1003\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
 
==================== Services (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [169728 2021-11-18] (Adobe Inc. -> Adobe Inc.)
R2 AirwatchService; C:\Program Files (x86)\Airwatch\AgentUI\TaskScheduler.exe [22224 2022-03-17] (VMware, Inc. -> VMware, Inc.)
R2 ApHidMonitorService; C:\WINDOWS\system32\DellTPad\HidMonitorSvc.exe [894880 2021-05-24] (ALPS ALPINE CO., LTD. -> ALPSALPINE Co., Ltd.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [9192328 2022-02-06] (Microsoft Corporation -> Microsoft Corporation)
R2 CsFalconService; C:\Program Files\CrowdStrike\CSFalconService.exe [2939160 2022-03-13] (Microsoft Windows Hardware Compatibility Publisher -> CrowdStrike, Inc.)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [130320 2021-11-10] (Dropbox, Inc -> Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [130320 2021-11-10] (Dropbox, Inc -> Dropbox, Inc.)
R2 DbxSvc; C:\WINDOWS\system32\DbxSvc.exe [44328 2022-03-27] (Dropbox, Inc -> Dropbox, Inc.)
R2 DDVCollectorSvcApi; C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe [436256 2021-09-29] (Dell Technologies Inc. -> Dell Technologies Inc.)
R2 DDVDataCollector; C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe [3847712 2021-09-29] (Dell Technologies Inc. -> Dell Technologies Inc.)
R2 DDVRulesProcessor; C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe [462880 2021-09-29] (Dell Technologies Inc. -> Dell Technologies Inc.)
R2 Dell Hardware Support; C:\Program Files\Dell\SupportAssistAgent\PCD\SupportAssist\Dsapi.exe [1024680 2021-09-02] (PC-Doctor, Inc. -> PC-Doctor, Inc.)
R2 DellClientManagementService; C:\Program Files (x86)\Dell\UpdateService\ServiceShell.exe [38600 2021-11-12] (Dell Inc -> )
S2 ETActiveSteeringHelper; C:\WINDOWS\Ethertronics\ETservice.exe [389616 2017-11-26] (Microsoft Windows Hardware Compatibility Publisher -> )
S3 GoToAssist; C:\Program Files (x86)\LogMeIn\GoToAssist Corporate\1280\G2AC_Service.exe [316872 2019-06-27] (LogMeIn, Inc. -> LogMeIn, Inc.)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [445432 2021-04-19] (Canon Inc. -> )
R2 Net Driver HPZ12; C:\Windows\System32\HPZinw12.dll [50688 2016-06-15] (HP Inc.) [File not signed]
S3 OfficeSvcManagerAddons; C:\WINDOWS\system32\dllhost.exe /Processid:{2CA2E202-932F-4BA2-8771-195BB86398F5} [21312 2020-10-19] (Microsoft Windows -> Microsoft Corporation)
R2 Player Location Check; C:\Program Files (x86)\GeoComply\//PlayerLocationCheck///Application/service.exe [3141608 2022-01-10] (GeoComply USA, Inc. -> GeoComply)
R2 Pml Driver HPZ12; C:\Windows\System32\HPZipm12.dll [66048 2016-06-15] (HP Inc.) [File not signed]
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [6228008 2022-03-08] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 SupportAssistAgent; C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [39968 2021-11-15] (Dell Inc -> Dell Inc.)
R2 VMware Hub Health Monitoring Service; C:\Program Files (x86)\Airwatch\HealthMonitoring\Service\VMwareHubHealthMonitoring.exe [15568 2022-03-17] (VMware, Inc. -> VMware, Inc.)
S2 VMWOSQEXT; C:\Program Files (x86)\Airwatch\AgentUI\Telemetry\vmwosqext.exe [24367560 2022-03-17] (VMware, Inc. -> VMware, Inc.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [3004048 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103384 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 XMPC VirtualPrint Client Service; C:\Program Files\Xerox\Xerox Workplace Cloud Client\Xerox.Cloud.VirtualPrint.ClientService\Xerox.Cloud.VirtualPrint.ClientService.exe [10752 2019-11-12] (Xerox Corporation) [File not signed]
 
===================== Drivers (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 ApHidfiltrService; C:\WINDOWS\System32\drivers\ApHidfiltrSW.sys [362512 2021-05-24] (WDKTestCert CHT1HTSH3180,132475688214743128 -> ALPSALPINE Co., Ltd.)
S3 AppleKmdfFilter; C:\WINDOWS\System32\drivers\AppleKmdfFilter.sys [20032 2020-10-09] (WDKTestCert build,132303256403278908 -> Apple Inc.)
S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35976 2020-10-09] (WDKTestCert build,132303256403278908 -> Apple Inc.)
S3 bcmnfcusb; C:\WINDOWS\System32\drivers\bcmnfcusb.sys [45656 2018-06-02] (Broadcom Corporation -> Broadcom Corporation.)
R1 CSAgent; C:\WINDOWS\system32\drivers\CrowdStrike\csagent.sys [2810072 2022-03-13] (Microsoft Windows Hardware Compatibility Publisher -> CrowdStrike, Inc.)
S0 CSBoot; C:\WINDOWS\System32\drivers\CrowdStrike\CSBoot.sys [24208 2022-03-13] (Microsoft Windows Early Launch Anti-malware Publisher -> CrowdStrike, Inc.)
R3 CSDeviceControl; C:\WINDOWS\System32\drivers\CSDeviceControl.sys [224448 2022-01-22] (Microsoft Windows Hardware Compatibility Publisher -> CrowdStrike, Inc.)
R0 CSFirmwareAnalysis; C:\WINDOWS\System32\DRIVERS\CSFirmwareAnalysis.sys [93248 2021-10-21] (Microsoft Windows Hardware Compatibility Publisher -> CrowdStrike, Inc.)
R3 DDDriver; C:\WINDOWS\System32\drivers\dddriver64Dcsa.sys [43400 2021-09-09] (Microsoft Windows Hardware Compatibility Publisher -> Dell Technologies)
S3 DellRbtn; C:\WINDOWS\System32\drivers\DellRbtn.sys [22848 2017-10-13] (WDKTestCert Andy_Chen6,131219483243550933 -> OSR Open Systems Resources, Inc.)
S3 ETActiveSteering; C:\WINDOWS\System32\drivers\ETActiveSteering.sys [38680 2017-11-26] (WDKTestCert norikd,131383411497448652 -> Ethertronics I2C driver for ASA)
R1 googledrivefs3688; C:\WINDOWS\System32\DRIVERS\googledrivefs3688.sys [381456 2021-12-14] (Microsoft Windows Hardware Compatibility Publisher -> Google, Inc.)
R1 googledrivefs3758; C:\WINDOWS\System32\DRIVERS\googledrivefs3758.sys [384584 2022-03-14] (Microsoft Windows Hardware Compatibility Publisher -> Google, Inc.)
S3 Netaapl; C:\WINDOWS\System32\drivers\netaapl64.sys [32352 2017-11-28] (Microsoft Windows Hardware Compatibility Publisher -> Apple Inc.)
S3 SnapCameraVirtualDevice; C:\WINDOWS\System32\drivers\SnapCameraVirtualDevice.sys [2800232 2020-03-21] (Snap Inc. -> Windows ® Win 7 DDK provider)
S3 swmbbser05; C:\WINDOWS\System32\drivers\swmbbser05.sys [287816 2018-01-31] (Sierra Wireless, Inc -> Sierra Wireless Incorporated)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [46688 2019-12-07] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [350136 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [54200 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
S4 DBUtilDrv2; \SystemRoot\System32\drivers\DBUtilDrv2.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One month (created) (Whitelisted) =========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2022-04-13 18:08 - 2022-04-13 18:09 - 000000000 ____D C:\FRST
2022-04-13 17:57 - 2022-04-13 17:57 - 000003320 _____ C:\WINDOWS\system32\Tasks\GeoComply Service Check
2022-04-13 14:26 - 2022-04-13 14:27 - 000033623 _____ C:\Users\AA583803\Downloads\TaxDocumentsView (14).pdf
2022-04-13 14:25 - 2022-04-13 14:25 - 000055733 _____ C:\Users\AA583803\Downloads\TaxDocumentsView (13).pdf
2022-04-13 14:24 - 2022-04-13 14:24 - 000012509 _____ C:\Users\AA583803\Downloads\TaxDocumentsView (12).pdf
2022-04-13 14:23 - 2022-04-13 14:30 - 000000000 ____D C:\Users\AA583803\Downloads\murphy tax docs
2022-04-13 14:23 - 2022-04-13 14:23 - 000025347 _____ C:\Users\AA583803\Downloads\TaxDocumentsView (11).pdf
2022-04-13 14:04 - 2022-04-13 14:04 - 000000000 ___HD C:\$WinREAgent
2022-04-13 12:16 - 2022-04-13 12:16 - 000082511 _____ C:\Users\AA583803\Downloads\MML0018_YTD_NONDISCRIMATIONTESTING.pdf
2022-04-12 19:04 - 2022-04-12 19:04 - 000320363 _____ C:\Users\AA583803\Downloads\return history.pdf
2022-04-12 18:54 - 2022-04-12 18:54 - 000176948 _____ C:\Users\AA583803\Downloads\Anand B Lincoln account summary.pdf
2022-04-12 16:29 - 2022-04-12 16:29 - 000227511 _____ C:\Users\AA583803\Downloads\VA-LVBSH-RST001_FINAL.pdf
2022-04-12 16:26 - 2022-04-12 16:27 - 000300864 _____ C:\Users\AA583803\Downloads\QA_InterimValue_Nov2021.pdf
2022-04-12 15:59 - 2022-04-12 15:59 - 000000289 _____ C:\Users\AA583803\Google Drive.lnk
2022-04-12 15:27 - 2022-04-12 15:27 - 001362758 _____ C:\Users\AA583803\Downloads\LevelAdv_RefGuide_Feb2022.pdf
2022-04-12 15:00 - 2022-04-12 15:00 - 000983993 _____ C:\Users\AA583803\Downloads\162699_03f8a4f6-cdbb-4dca-b530-586cf51e43b8.pdf
2022-04-12 14:51 - 2022-04-12 14:51 - 001591847 _____ C:\Users\AA583803\Downloads\SCS PLUS 21 Cap Rate Flyer Series B - PreAnnounced (3).pdf
2022-04-12 13:55 - 2022-04-12 13:55 - 000026320 _____ C:\Users\AA583803\Downloads\Invoice INV-23240 (1).pdf
2022-04-12 13:42 - 2022-04-12 13:42 - 000542370 _____ C:\Users\AA583803\Downloads\report_1243.pdf
2022-04-12 12:28 - 2022-04-12 12:28 - 001176797 _____ C:\Users\AA583803\Downloads\Planning_Agreement_from_Joel_Bernstein____Mp.pdf
2022-04-12 11:42 - 2022-04-12 11:42 - 000054211 _____ C:\Users\AA583803\Downloads\780x-A585803-O256-dt20220411.xlsx
2022-04-12 11:28 - 2022-04-12 11:28 - 001493131 _____ C:\Users\AA583803\Downloads\sheeh_220408_ON_Partial_Withdrawal (1).pdf
2022-04-12 11:27 - 2022-04-12 11:27 - 000108535 _____ C:\Users\AA583803\Downloads\sheehan fax cover sheet.xlsx
2022-04-12 11:27 - 2022-04-12 11:27 - 000099216 _____ C:\Users\AA583803\Downloads\sheehan fax cover sheet.pdf
2022-04-12 11:21 - 2022-04-12 11:21 - 001410279 _____ C:\Users\AA583803\Downloads\sheeh_220408_ON_Partial_Withdrawal.pdf
2022-04-12 11:17 - 2022-04-12 11:17 - 000907547 _____ C:\Users\AA583803\Downloads\sheeh 220408 ON Partial Withdrawal.pdf
2022-04-12 11:12 - 2022-04-12 11:12 - 001427349 _____ C:\Users\AA583803\Downloads\combinepdf (53).pdf
2022-04-12 11:12 - 2022-04-12 11:12 - 001421759 _____ C:\Users\AA583803\Downloads\combinepdf (54).pdf
2022-04-12 11:08 - 2022-04-12 11:08 - 000496756 _____ C:\Users\AA583803\Downloads\sheehan ohio national.pdf
2022-04-11 19:36 - 2022-04-11 19:36 - 000263606 _____ C:\Users\AA583803\Downloads\combinepdf (52).pdf
2022-04-11 19:35 - 2022-04-11 19:35 - 000052079 _____ C:\Users\AA583803\Downloads\ixa-053-m.pdf
2022-04-11 19:33 - 2022-04-11 19:33 - 000583207 _____ C:\Users\AA583803\Downloads\iva-009-protection.pdf
2022-04-11 19:31 - 2022-04-11 19:31 - 000834606 _____ C:\Users\AA583803\Downloads\iva-009-performance-3.pdf
2022-04-11 19:29 - 2022-04-11 19:29 - 000061703 _____ C:\Users\AA583803\Downloads\iva-009-performance-multi.pdf
2022-04-11 19:28 - 2022-04-11 19:28 - 000825560 _____ C:\Users\AA583803\Downloads\iva-009-performance-1.pdf
2022-04-11 19:25 - 2022-04-11 19:25 - 000805583 _____ C:\Users\AA583803\Downloads\iva-009-guard.pdf
2022-04-11 19:24 - 2022-04-11 19:24 - 000842073 _____ C:\Users\AA583803\Downloads\iva-009-precision.pdf
2022-04-11 19:22 - 2022-04-11 19:22 - 000204976 _____ C:\Users\AA583803\Downloads\Bundle.pdf
2022-04-11 19:13 - 2022-04-11 19:13 - 008962881 _____ C:\Users\AA583803\Downloads\ppt-302.pptx
2022-04-11 19:07 - 2022-04-11 19:07 - 000959830 _____ C:\Users\AA583803\Downloads\Archive (4).zip
2022-04-11 19:04 - 2022-04-11 19:04 - 001260775 _____ C:\Users\AA583803\Downloads\ixa-118.pdf
2022-04-11 19:02 - 2022-04-11 19:02 - 000045155 _____ C:\Users\AA583803\Downloads\ixa-178-6.pdf
2022-04-11 18:59 - 2022-04-11 18:59 - 000066267 _____ C:\Users\AA583803\Downloads\iva-026-3.pdf
2022-04-11 18:58 - 2022-04-11 18:58 - 000050297 _____ C:\Users\AA583803\Downloads\iva-026-6.pdf
2022-04-11 18:54 - 2022-04-11 18:54 - 000045993 _____ C:\Users\AA583803\Downloads\ixa-178-3.pdf
2022-04-11 18:23 - 2022-04-11 18:23 - 000559504 _____ C:\Users\AA583803\Downloads\iny-187 (1).pdf
2022-04-11 18:22 - 2022-04-11 18:22 - 000559504 _____ C:\Users\AA583803\Downloads\iny-187.pdf
2022-04-11 18:20 - 2022-04-11 18:20 - 000078076 _____ C:\Users\AA583803\Downloads\iva-009-lock.pdf
2022-04-11 18:16 - 2022-04-11 18:16 - 002293182 _____ C:\Users\AA583803\Downloads\ixa-013-perf.pdf
2022-04-11 18:16 - 2022-04-11 18:16 - 002289269 _____ C:\Users\AA583803\Downloads\Archive (3).zip
2022-04-11 18:15 - 2022-04-11 18:15 - 002289269 _____ C:\Users\AA583803\Downloads\Archive (2).zip
2022-04-11 18:13 - 2022-04-11 18:13 - 000101897 _____ C:\Users\AA583803\Downloads\Archive (1).zip
2022-04-11 18:09 - 2022-04-11 18:09 - 000121154 _____ C:\Users\AA583803\Downloads\ixa-014.pdf
2022-04-11 16:51 - 2022-04-11 16:51 - 000542597 _____ C:\Users\AA583803\Downloads\report_3584.pdf
2022-04-11 16:40 - 2022-04-11 16:40 - 001591847 _____ C:\Users\AA583803\Downloads\SCS PLUS 21 Cap Rate Flyer Series B - PreAnnounced (2).pdf
2022-04-11 16:37 - 2022-04-11 16:37 - 000140552 _____ C:\Users\AA583803\Downloads\ixa_012 (1).pdf
2022-04-11 16:02 - 2022-04-11 16:02 - 000601586 _____ C:\Users\AA583803\Downloads\flex-guard-comm-rates (3).pdf
2022-04-11 15:06 - 2022-04-11 15:06 - 000048675 _____ C:\Users\AA583803\Downloads\MML0018_AUTOMATED FUNDING REPORT.pdf
2022-04-11 11:15 - 2022-04-11 11:15 - 000026320 _____ C:\Users\AA583803\Downloads\Invoice INV-23240.pdf
2022-04-11 11:13 - 2022-04-11 11:13 - 001716147 _____ C:\Users\AA583803\Downloads\FBP503r3_41_ePay_for_Financial_Planning_Services_RS (3).pdf
2022-04-09 16:39 - 2022-04-09 16:39 - 001591847 _____ C:\Users\AA583803\Downloads\SCS PLUS 21 Cap Rate Flyer Series B - PreAnnounced (1).pdf
2022-04-09 09:54 - 2022-04-09 09:54 - 000008904 _____ C:\Users\AA583803\Downloads\360Export (9).xls
2022-04-09 09:47 - 2022-04-09 09:47 - 000005684 _____ C:\Users\AA583803\Downloads\360Export (8).xls
2022-04-09 09:37 - 2022-04-09 09:37 - 000012091 _____ C:\Users\AA583803\Downloads\360Export (7).xls.xlsx
2022-04-09 09:27 - 2022-04-09 09:27 - 000008231 _____ C:\Users\AA583803\Downloads\360Export (7).xls
2022-04-08 16:43 - 2022-04-08 16:43 - 000718689 _____ C:\Users\AA583803\Downloads\combinepdf (51).pdf
2022-04-08 15:26 - 2022-04-08 15:26 - 000032778 _____ C:\Users\AA583803\Downloads\jennings rack wait list receipt.pdf
2022-04-08 15:24 - 2022-04-08 15:24 - 000032488 _____ C:\Users\AA583803\Downloads\000702403 (3).pdf
2022-04-08 15:19 - 2022-04-08 15:19 - 000590252 _____ C:\Users\AA583803\Downloads\Please_Review_and_Sign_Application_Amendment.pdf
2022-04-08 14:02 - 2022-04-08 14:02 - 000032488 _____ C:\Users\AA583803\Downloads\000702403 (2).pdf
2022-04-08 13:59 - 2022-04-08 13:59 - 000264191 _____ C:\Users\AA583803\Downloads\AI01158316-Bill-361977459-04082022123635.pdf
2022-04-08 12:58 - 2022-04-08 12:58 - 000003304 _____ C:\Users\AA583803\Downloads\Mass Mutual _ Social Selling 101.ics
2022-04-08 09:48 - 2022-04-08 09:48 - 000017675 _____ C:\Users\AA583803\Downloads\wenke Performance_Attribution_Summary.pdf
2022-04-08 09:44 - 2022-04-08 09:44 - 000132368 _____ C:\Users\AA583803\Downloads\wenke OD portfolio.PDF
2022-04-07 17:16 - 2022-04-07 17:16 - 000361154 _____ C:\Users\AA583803\Downloads\AI01158316-Amendment-361965063.pdf
2022-04-07 17:16 - 2022-04-07 17:16 - 000252678 _____ C:\Users\AA583803\Downloads\Service Online 2020.pdf
2022-04-07 17:16 - 2022-04-07 17:16 - 000252678 _____ C:\Users\AA583803\Downloads\Service Online 2020 (1).pdf
2022-04-07 16:54 - 2022-04-07 16:54 - 000063232 _____ C:\Users\AA583803\Downloads\cobra.wageworks.com-Make a One-Time Premium Payment.pdf
2022-04-07 16:54 - 2022-04-07 16:54 - 000057943 _____ C:\Users\AA583803\Downloads\mybenefits.wageworks.com-Make a One-Time Premium Payment.pdf
2022-04-07 15:54 - 2022-04-07 15:54 - 000024512 _____ C:\Users\AA583803\Downloads\Performance_by_Security_2 (9).xls
2022-04-07 15:53 - 2022-04-07 15:53 - 000032704 _____ C:\Users\AA583803\Downloads\Performance_by_Security_2 (7).xls
2022-04-07 15:53 - 2022-04-07 15:53 - 000024512 _____ C:\Users\AA583803\Downloads\Performance_by_Security_2 (8).xls
2022-04-07 15:13 - 2022-04-07 15:13 - 002431808 _____ C:\Users\AA583803\Downloads\403018124_Application_Packet.pdf
2022-04-07 15:13 - 2022-04-07 15:13 - 002431808 _____ C:\Users\AA583803\Downloads\403018124_Application_Packet (1).pdf
2022-04-07 15:10 - 2022-04-07 15:10 - 002266524 _____ C:\Users\AA583803\Downloads\403018125_Application_Packet (1).pdf
2022-04-07 15:08 - 2022-04-07 15:08 - 002266524 _____ C:\Users\AA583803\Downloads\403018125_Application_Packet.pdf
2022-04-07 14:15 - 2022-04-07 14:15 - 000024512 _____ C:\Users\AA583803\Downloads\Performance_by_Security_2 (6).xls
2022-04-07 13:58 - 2022-04-07 13:58 - 000024512 _____ C:\Users\AA583803\Downloads\Performance_by_Security_2 (5).xls
2022-04-07 00:17 - 2022-04-07 00:17 - 000051712 _____ C:\Users\AA583803\Downloads\anand Performance_by_Security_2 (1).xls
2022-04-07 00:17 - 2022-04-07 00:17 - 000026383 _____ C:\Users\AA583803\Downloads\anand Performance_by_Security_2 (1).xlsx
2022-04-07 00:13 - 2022-04-07 00:13 - 000024512 _____ C:\Users\AA583803\Downloads\Purchase_and_Sales (1).xls
2022-04-07 00:08 - 2022-04-07 00:08 - 000024512 _____ C:\Users\AA583803\Downloads\Purchase_and_Sales.xls
2022-04-06 23:39 - 2022-04-06 23:39 - 000024512 _____ C:\Users\AA583803\Downloads\Performance_by_Security_2 (4).xls
2022-04-06 23:38 - 2022-04-06 23:38 - 000024512 _____ C:\Users\AA583803\Downloads\Performance_by_Security_2 (3).xls
2022-04-06 22:47 - 2022-04-06 22:47 - 000024512 _____ C:\Users\AA583803\Downloads\Performance_by_Security_2 (2).xls
2022-04-06 22:38 - 2022-04-06 22:38 - 000024512 _____ C:\Users\AA583803\Downloads\Performance_by_Security_2 (1).xls
2022-04-06 22:19 - 2022-04-06 22:19 - 000024512 _____ C:\Users\AA583803\Downloads\Portfolio_Holdings.xls
2022-04-06 21:56 - 2022-04-06 21:57 - 000155559 _____ C:\Users\AA583803\Downloads\Anand OD portfolio report.PDF
2022-04-06 17:53 - 2022-04-06 17:53 - 002579000 _____ C:\Users\AA583803\Downloads\400072643_Application_Packet (2).pdf
2022-04-06 17:33 - 2022-04-06 17:33 - 002579000 _____ C:\Users\AA583803\Downloads\400072643_Application_Packet (1).pdf
2022-04-06 17:26 - 2022-04-06 17:26 - 002579000 _____ C:\Users\AA583803\Downloads\400072643_Application_Packet.pdf
2022-04-06 16:20 - 2022-04-06 16:20 - 002993577 _____ C:\Users\AA583803\Downloads\cavaliere mass di.pdf
2022-04-06 11:16 - 2022-04-06 11:16 - 001716147 _____ C:\Users\AA583803\Downloads\FBP503r3_41_ePay_for_Financial_Planning_Services_RS (2).pdf
2022-04-05 14:29 - 2022-04-05 14:29 - 000157799 _____ C:\Users\AA583803\Downloads\sheehan portfolio report.PDF
2022-04-05 13:47 - 2022-04-05 14:30 - 000515617 _____ C:\Users\AA583803\Downloads\sheehan 2022 RMD.pdf
2022-04-05 13:41 - 2022-04-05 13:41 - 000000165 ____H C:\Users\AA583803\Downloads\~$MML0018_CVRMissingInformation.xlsx
2022-04-05 13:30 - 2022-04-05 13:30 - 000036295 _____ C:\Users\AA583803\Downloads\Jocie Consolidated_Statement.pdf
2022-04-05 12:50 - 2022-04-05 12:50 - 000057804 _____ C:\Users\AA583803\Downloads\offerreport (1).pdf
2022-04-05 11:51 - 2022-04-05 11:51 - 000058084 _____ C:\Users\AA583803\Downloads\offerreport.pdf
2022-04-05 11:12 - 2022-04-05 11:13 - 000103185 _____ C:\Users\AA583803\Downloads\knox muni details.pdf
2022-04-04 21:24 - 2022-04-04 21:24 - 000024512 _____ C:\Users\AA583803\Downloads\Performance_by_Security_2.xls
2022-04-04 20:43 - 2022-04-04 20:43 - 002980699 _____ C:\Users\AA583803\Downloads\1095-C Form 2021.pdf
2022-04-04 20:42 - 2022-04-04 20:42 - 000294844 _____ C:\Users\AA583803\Downloads\Tax Information - Documents - Nelnet (1).pdf
2022-04-04 20:42 - 2022-04-04 20:42 - 000003372 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1146508179-405363288-658039003-1003
2022-04-04 20:42 - 2022-04-04 20:42 - 000002388 _____ C:\Users\AA583803\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2022-04-04 20:41 - 2022-04-04 20:41 - 001639655 _____ C:\Users\AA583803\Downloads\W-2_Form_2021_Bernstein_2022_03_31_10_46_36_-0700_W-2_ESS (2).pdf
2022-04-04 20:41 - 2022-04-04 20:41 - 000196346 _____ C:\Users\AA583803\Downloads\0430114784 - Jenna Bernstein - MDBS Inc - 1099-NEC - TY2021 (1).pdf
2022-04-04 19:04 - 2022-04-04 19:04 - 001639655 _____ C:\Users\AA583803\Downloads\W-2_Form_2021_Bernstein_2022_03_31_10_46_36_-0700_W-2_ESS (1).pdf
2022-04-04 19:04 - 2022-04-04 19:04 - 000294844 _____ C:\Users\AA583803\Downloads\Tax Information - Documents - Nelnet.pdf
2022-04-04 18:51 - 2022-04-04 18:52 - 000012287 _____ C:\Users\AA583803\Downloads\balasu Change_in_Market_Value_Register (1).pdf
2022-04-04 18:49 - 2022-04-04 18:49 - 001639655 _____ C:\Users\AA583803\Downloads\W-2_Form_2021_Bernstein_2022_03_31_10_46_36_-0700_W-2_ESS.pdf
2022-04-04 18:48 - 2022-04-04 18:48 - 000196346 _____ C:\Users\AA583803\Downloads\0430114784 - Jenna Bernstein - MDBS Inc - 1099-NEC - TY2021.pdf
2022-04-04 14:49 - 2022-04-04 14:49 - 001700820 _____ C:\Users\AA583803\Downloads\combinepdf (50).pdf
2022-04-04 14:46 - 2022-04-04 14:46 - 000123238 _____ C:\Users\AA583803\Downloads\Polino SP500 Low volatility performance.pdf
2022-04-04 14:42 - 2022-04-04 14:42 - 000687066 _____ C:\Users\AA583803\Downloads\whitney FPAS.pdf
2022-04-04 14:40 - 2022-04-04 14:40 - 001262511 _____ C:\Users\AA583803\Downloads\Planning_Agreement_from_Joel_Bernstein____M.zip
2022-04-03 21:12 - 2022-04-04 14:50 - 000267610 _____ C:\Users\AA583803\Downloads\pollino Transaction_Activity.pdf
2022-04-03 20:57 - 2022-04-03 20:57 - 000011806 _____ C:\Users\AA583803\Downloads\TaxDocumentsView (10).pdf
2022-04-03 20:56 - 2022-04-03 20:56 - 000011980 _____ C:\Users\AA583803\Downloads\TaxDocumentsView (9).pdf
2022-04-03 20:54 - 2022-04-03 20:54 - 000011735 _____ C:\Users\AA583803\Downloads\TaxDocumentsView (7).pdf
2022-04-03 20:54 - 2022-04-03 20:54 - 000011727 _____ C:\Users\AA583803\Downloads\TaxDocumentsView (8).pdf
2022-04-03 20:52 - 2022-04-03 20:52 - 000011966 _____ C:\Users\AA583803\Downloads\TaxDocumentsView (6).pdf
2022-04-03 20:50 - 2022-04-03 20:50 - 000044937 _____ C:\Users\AA583803\Downloads\TaxDocumentsView (5).pdf
2022-04-03 20:48 - 2022-04-03 20:48 - 000051118 _____ C:\Users\AA583803\Downloads\TaxDocumentsView (4).pdf
2022-04-01 18:28 - 2022-04-01 18:28 - 001716147 _____ C:\Users\AA583803\Downloads\FBP503r3_41_ePay_for_Financial_Planning_Services_RS (1).pdf
2022-04-01 18:26 - 2022-04-01 18:26 - 000501273 _____ C:\Users\AA583803\Downloads\MyPDF (6).pdf
2022-04-01 18:24 - 2022-04-01 18:24 - 000167007 _____ C:\Users\AA583803\Downloads\MyPDF (5).pdf
2022-04-01 18:24 - 2022-04-01 18:24 - 000122036 _____ C:\Users\AA583803\Downloads\Form CRS.pdf
2022-04-01 18:12 - 2022-04-01 18:12 - 000503025 _____ C:\Users\AA583803\Downloads\A3MFBP100r2_21_Financial_Planning_Submission_and_Approval_Process_RS_V3 (2).pdf
2022-03-31 18:56 - 2022-03-31 18:57 - 000220160 _____ C:\Users\AA583803\Downloads\pollino low vol index performance.xls
2022-03-31 18:41 - 2022-03-31 18:41 - 004666543 _____ C:\Users\AA583803\Downloads\The Freedom Point eBook (1).pdf
2022-03-31 16:38 - 2022-03-31 16:38 - 001284805 _____ C:\Users\AA583803\Downloads\combinepdf (49).pdf
2022-03-31 15:25 - 2022-03-31 15:25 - 000234620 _____ C:\Users\AA583803\Downloads\EN-05-10026.pdf
2022-03-31 15:11 - 2022-03-31 15:11 - 004666543 _____ C:\Users\AA583803\Downloads\The Freedom Point eBook.pdf
2022-03-31 14:36 - 2022-04-13 14:03 - 000000000 ____D C:\Program Files\dotnet
2022-03-31 12:08 - 2022-03-31 12:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2022-03-31 11:53 - 2022-03-31 11:53 - 000002427 _____ C:\Users\AA583803\Downloads\MassMutual Academy_  Advanced Sales Forum.ics
2022-03-30 16:44 - 2022-03-30 16:44 - 000121760 _____ C:\Users\AA583803\Downloads\4751085107_PPP_Loan_Amount.pdf
2022-03-30 12:10 - 2022-03-30 12:10 - 000000940 _____ C:\Users\AA583803\Downloads\Introduction to Customized Portfolios.ics
2022-03-30 12:09 - 2022-03-30 12:09 - 000000000 ____D C:\WINDOWS\system32\Tasks\VMware
2022-03-30 00:10 - 2022-03-30 00:10 - 000000000 ____D C:\WINDOWS\system32\%programdata%
2022-03-29 23:57 - 2022-03-29 23:57 - 000000000 ____D C:\WINDOWS\SysWOW64\%programdata%
2022-03-29 23:57 - 2022-03-29 23:57 - 000000000 ____D C:\Users\AA583803\AppData\Local\VMware
2022-03-29 18:12 - 2022-03-29 18:12 - 001089837 _____ C:\Users\AA583803\Downloads\MML0018_2021_AdvisorTrust_Custodial_Restatement.pdf
2022-03-29 17:47 - 2022-03-29 17:47 - 004273923 _____ C:\Users\AA583803\Downloads\MML0018_Executed_Final_Plan_Document_Package.pdf
2022-03-29 15:46 - 2022-03-29 15:46 - 000012458 _____ C:\Users\AA583803\Downloads\MML0018_CVRMissingInformation (1).xlsx
2022-03-29 15:41 - 2022-03-29 15:41 - 000387072 _____ C:\Users\AA583803\Downloads\RE_ Reminder_ WSD Digital_ LLC 401(k) Plan - 2021 Year-End Employer Contribution    _ ref__00D306J2H__5005x1g7VOU_ref _.msg
2022-03-29 14:58 - 2022-03-29 14:58 - 002218318 _____ C:\Users\AA583803\Downloads\To Sell Is Human The Surprising Truth About Moving Others.pdf
2022-03-29 12:29 - 2022-03-29 12:29 - 000081401 _____ C:\Users\AA583803\Downloads\express-path-fluidless-underwriting-program-faqs_FINAL.docx.pdf
2022-03-28 16:41 - 2022-03-28 16:41 - 000163232 _____ C:\Users\AA583803\Downloads\Statement Dated 02_28_2022.pdf
2022-03-28 16:12 - 2022-03-28 16:12 - 000224455 _____ C:\Users\AA583803\Downloads\_V3_be_71_CLNT-be71b1d1-c643-4376-a93f-61ab024a3a68.pdf
2022-03-28 16:11 - 2022-03-28 16:11 - 000223045 _____ C:\Users\AA583803\Downloads\_V3_7f_72_CLNT-7f72c931-50a5-4748-b30c-7fbb0be30c86.pdf
2022-03-28 15:36 - 2022-03-28 15:36 - 000070873 _____ C:\Users\AA583803\Downloads\Catania Trust 1099.pdf
2022-03-28 15:36 - 2022-03-28 15:36 - 000067323 _____ C:\Users\AA583803\Downloads\TaxDocumentsView (3).pdf
2022-03-28 14:08 - 2022-03-28 14:08 - 000062025 _____ C:\Users\AA583803\Downloads\pollino Historical_Market_Value_with_Hypothetical_BM.pdf
2022-03-28 13:17 - 2022-03-31 18:55 - 000220160 _____ C:\Users\AA583803\Downloads\PerformanceGraphExport (1).xls
2022-03-28 13:16 - 2022-03-28 13:16 - 000178176 _____ C:\Users\AA583803\Downloads\PerformanceGraphExport.xls
2022-03-28 13:08 - 2022-03-28 13:08 - 000176480 _____ C:\Users\AA583803\Downloads\pollino lincoln summary.pdf
2022-03-28 13:06 - 2022-03-28 13:06 - 000106855 _____ C:\Users\AA583803\Downloads\pollino account summary.pdf
2022-03-28 12:55 - 2022-03-28 12:55 - 000071200 _____ C:\Users\AA583803\Downloads\1d784de2-445c-4927-99f7-6290c1aa2121.PDF
2022-03-27 22:47 - 2022-03-27 22:47 - 000296132 _____ C:\Users\AA583803\Downloads\19MPsful_015819609-20130417170605.pdf
2022-03-27 21:48 - 2022-03-27 21:48 - 000058250 _____ C:\Users\AA583803\Downloads\Coverpath Eligibility 1-7-22.pdf
2022-03-27 19:08 - 2022-03-27 19:08 - 000133992 _____ C:\Users\AA583803\Downloads\neiditz emails with CPA.pdf
2022-03-27 13:52 - 2022-03-27 13:52 - 000047600 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-stable.sys
2022-03-27 13:52 - 2022-03-27 13:52 - 000047600 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-dev.sys
2022-03-27 13:52 - 2022-03-27 13:52 - 000047600 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-canary.sys
2022-03-27 13:52 - 2022-03-27 13:52 - 000044328 _____ (Dropbox, Inc.) C:\WINDOWS\system32\DbxSvc.exe
2022-03-26 17:00 - 2022-03-26 17:00 - 000346901 _____ C:\Users\AA583803\Downloads\Neiditz_1099-B_Inventrust_IVT_817_shs_sold.pdf
2022-03-26 16:57 - 2022-03-26 16:57 - 000354792 _____ C:\Users\AA583803\Downloads\ViewDocument (2).pdf
2022-03-26 16:56 - 2022-03-26 16:56 - 000347673 _____ C:\Users\AA583803\Downloads\Neiditz_1099-B_Inventrust_IVT_585_shs_sold.pdf
2022-03-26 16:42 - 2022-03-26 16:42 - 000355564 _____ C:\Users\AA583803\Downloads\ViewDocument (1).pdf
2022-03-26 12:11 - 2022-03-26 12:11 - 000004562 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2022-03-26 12:11 - 2022-03-26 12:11 - 000002075 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat DC.lnk
2022-03-25 17:01 - 2022-03-25 17:01 - 000001175 _____ C:\Users\AA583803\Downloads\tab_account_modelexplorer_1795.csv
2022-03-25 16:38 - 2022-03-25 16:38 - 000561342 _____ C:\Users\AA583803\Downloads\2977f593-de9a-4754-bf52-86f0b1edcae7.pdf
2022-03-25 13:27 - 2022-03-25 13:27 - 000164547 _____ C:\Users\AA583803\Downloads\A_document_is_ready_for_your_electronic_signa.zip
2022-03-25 12:07 - 2022-03-25 12:07 - 000012458 _____ C:\Users\AA583803\Downloads\MML0018_CVRMissingInformation.xlsx
2022-03-25 11:30 - 2022-03-25 11:30 - 000445695 _____ C:\Users\AA583803\Downloads\economictimes.indiatimes.com-Tightening financial conditions sound alarm for world economy (1).pdf
2022-03-25 11:29 - 2022-03-25 11:29 - 000446514 _____ C:\Users\AA583803\Downloads\economictimes.indiatimes.com-Tightening financial conditions sound alarm for world economy.pdf
2022-03-24 18:38 - 2022-03-24 18:38 - 001692607 _____ C:\Users\AA583803\Downloads\Jun_30_2020_Statement.pdf
2022-03-24 18:32 - 2022-03-24 18:32 - 001696439 _____ C:\Users\AA583803\Downloads\Dec_31_2021_Statement.pdf
2022-03-24 17:37 - 2022-03-24 17:37 - 000532252 _____ C:\Users\AA583803\Downloads\report_4426.pdf
2022-03-24 17:36 - 2022-03-24 17:36 - 000529997 _____ C:\Users\AA583803\Downloads\report_2872.pdf
2022-03-24 17:25 - 2022-03-24 17:25 - 000071632 _____ C:\Users\AA583803\Downloads\Anand YTD Portfolio_Summary.pdf
2022-03-24 17:22 - 2022-03-24 17:23 - 000155005 _____ C:\Users\AA583803\Downloads\anand portfolio.PDF
2022-03-24 15:08 - 2022-03-24 15:08 - 000138951 _____ C:\Users\AA583803\Downloads\Ensight & Life Insurance Request Form.pdf
2022-03-24 14:49 - 2022-03-24 14:49 - 000001423 _____ C:\Users\AA583803\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Outlook.lnk
2022-03-24 13:01 - 2022-03-24 13:01 - 000157068 _____ C:\Users\AA583803\Downloads\Water-Line-General-Terms-Conditions.pdf
2022-03-23 15:39 - 2022-03-23 15:39 - 002814695 _____ C:\Users\AA583803\Downloads\etien 220323 DI reinstatement.pdf
2022-03-23 14:52 - 2022-03-23 14:53 - 000156284 _____ C:\Users\AA583803\Downloads\monthly market recap feb22.pdf
2022-03-23 14:49 - 2022-03-23 14:49 - 000809206 _____ C:\Users\AA583803\Downloads\wealth-mgt-update-031422.pdf
2022-03-23 14:08 - 2022-03-23 14:08 - 000219803 _____ C:\Users\AA583803\Downloads\combinepdf (48).pdf
2022-03-23 14:05 - 2022-03-23 14:05 - 001154610 _____ C:\Users\AA583803\Downloads\combinepdf (47).pdf
2022-03-23 14:05 - 2022-03-23 14:05 - 000574342 _____ C:\Users\AA583803\Downloads\report_3830.pdf
2022-03-23 14:04 - 2022-03-23 14:04 - 000577175 _____ C:\Users\AA583803\Downloads\report_5946.pdf
2022-03-23 13:53 - 2022-03-23 13:53 - 001074297 _____ C:\Users\AA583803\Downloads\combinepdf (46).pdf
2022-03-23 12:37 - 2022-03-23 12:37 - 000001324 _____ C:\Users\AA583803\Downloads\tab_account_modelexplorer_1482.csv
2022-03-23 10:46 - 2022-03-23 10:46 - 000000509 _____ C:\Users\AA583803\Downloads\event (1).ics
2022-03-22 16:36 - 2022-03-22 16:36 - 000044722 _____ C:\Users\AA583803\Downloads\Neiditz 1099-B.pdf
2022-03-22 15:48 - 2022-03-22 15:48 - 000527442 _____ C:\Users\AA583803\Downloads\report_5217.pdf
2022-03-22 15:44 - 2022-03-22 15:44 - 000010604 _____ C:\Users\AA583803\Downloads\warren Calendar_Market_Value_and_Performance.pdf
2022-03-22 15:39 - 2022-03-22 15:39 - 000062380 _____ C:\Users\AA583803\Downloads\warren port summary.PDF
2022-03-22 15:37 - 2022-03-22 15:37 - 000151694 _____ C:\Users\AA583803\Downloads\warren perf report.PDF
2022-03-22 13:33 - 2022-03-22 13:33 - 000546392 _____ C:\Users\AA583803\Downloads\report_1775.pdf
2022-03-22 13:29 - 2022-03-22 13:29 - 000544166 _____ C:\Users\AA583803\Downloads\report_7281.pdf
2022-03-22 13:16 - 2022-03-22 13:16 - 001984797 _____ C:\Users\AA583803\Downloads\di1075.pdf
2022-03-22 13:09 - 2022-03-22 13:09 - 000107520 _____ C:\Users\AA583803\Downloads\di7137 (4).xls
2022-03-22 12:10 - 2022-03-22 12:10 - 000545094 _____ C:\Users\AA583803\Downloads\report_2399.pdf
2022-03-22 11:54 - 2022-03-14 12:02 - 000384584 _____ (Google, Inc.) C:\WINDOWS\system32\Drivers\googledrivefs3758.sys
2022-03-22 09:11 - 2022-03-22 09:11 - 000045596 _____ C:\Users\AA583803\Downloads\HSA Transaction Confirmation $2000.pdf
2022-03-22 01:11 - 2022-04-06 10:58 - 000000000 ____D C:\Program Files\CrowdStrike
2022-03-21 18:44 - 2022-03-21 18:44 - 000141468 _____ C:\Users\AA583803\Downloads\PslfApplicationResults_02-18-2022.pdf
2022-03-21 18:41 - 2022-03-21 18:41 - 000133126 _____ C:\Users\AA583803\Downloads\PslfQualifyingPaymentUpdate_02-18-2022.pdf
2022-03-21 16:33 - 2022-03-21 16:33 - 001589578 _____ C:\Users\AA583803\Downloads\combinepdf (45).pdf
2022-03-18 16:34 - 2022-03-18 16:34 - 001511185 _____ C:\Users\AA583803\Downloads\combinepdf (44).pdf
2022-03-18 15:59 - 2022-03-18 15:59 - 001193560 _____ C:\Users\AA583803\Downloads\combinepdf (43).pdf
2022-03-18 15:58 - 2022-03-18 15:58 - 001193562 _____ C:\Users\AA583803\Downloads\combinepdf (42).pdf
2022-03-18 12:38 - 2022-03-18 12:38 - 000058166 _____ C:\Users\AA583803\Downloads\Bernstein Sales Proposal.pdf
2022-03-18 11:35 - 2022-03-18 11:35 - 000001265 _____ C:\Users\AA583803\Downloads\2022 MassMutual Academy Virtual March.ics
2022-03-17 16:28 - 2022-03-17 16:30 - 001331508 _____ C:\Users\AA583803\Downloads\cavaliere DI fact finder.pdf
2022-03-17 15:52 - 2022-03-17 15:52 - 001088224 _____ C:\Users\AA583803\Downloads\di90018.pdf
2022-03-17 14:38 - 2022-03-18 12:27 - 000148515 _____ C:\Users\AA583803\Downloads\mm academy schedule spring 2022.pdf
2022-03-16 18:03 - 2022-03-16 18:03 - 000001624 _____ C:\Users\AA583803\Downloads\reichman 401k transactions.csv
2022-03-16 17:59 - 2022-03-16 17:59 - 000003599 _____ C:\Users\AA583803\Downloads\InvestmentTransactions (3).csv
2022-03-16 14:26 - 2022-03-16 14:26 - 000240526 _____ C:\Users\AA583803\Downloads\CanNutritionValues_E (1).pdf
2022-03-16 14:20 - 2022-03-16 14:20 - 000240526 _____ C:\Users\AA583803\Downloads\CanNutritionValues_E.pdf
2022-03-16 11:30 - 2022-03-16 11:30 - 000153513 _____ C:\Users\AA583803\Downloads\Reichman OD report.PDF
2022-03-16 11:02 - 2022-03-16 11:02 - 000565919 _____ C:\Users\AA583803\Downloads\reichman presentation.pdf
2022-03-15 23:49 - 2022-03-15 23:49 - 001941738 _____ C:\Users\AA583803\Downloads\barn door track 3132194.pdf
2022-03-15 23:49 - 2022-03-15 23:49 - 000305354 _____ C:\Users\AA583803\Downloads\barn door pull 681 manual.pdf
2022-03-15 23:46 - 2022-03-15 23:46 - 000304324 _____ C:\Users\AA583803\Downloads\681 manual.pdf
2022-03-15 23:11 - 2022-03-15 23:11 - 001941722 _____ C:\Users\AA583803\Downloads\3132194.pdf
2022-03-15 13:36 - 2022-03-15 13:36 - 001073453 _____ C:\Users\AA583803\Downloads\combinepdf (41).pdf
2022-03-15 13:36 - 2022-03-15 13:36 - 001073453 _____ C:\Users\AA583803\Downloads\combinepdf (40).pdf
2022-03-15 13:35 - 2022-03-15 13:35 - 000098850 _____ C:\Users\AA583803\Downloads\metlife fax cover sheet.pdf
2022-03-15 13:32 - 2022-03-15 13:35 - 000108088 _____ C:\Users\AA583803\Downloads\metlife fax cover sheet.xlsx
2022-03-15 13:22 - 2022-03-15 13:22 - 000993676 _____ C:\Users\AA583803\Downloads\03152022131826-0001-pages-deleted.pdf
2022-03-15 13:21 - 2022-03-15 13:21 - 000998040 _____ C:\Users\AA583803\Downloads\03152022131826-0001.pdf
2022-03-15 11:25 - 2022-03-15 11:25 - 000130548 _____ C:\Users\AA583803\Downloads\Wenke Portfolio Report 03-14-22.PDF
2022-03-15 11:21 - 2022-03-15 11:21 - 000052144 _____ C:\Users\AA583803\Downloads\jbod1 Portfolio_Summary.pdf
2022-03-15 11:17 - 2022-03-15 11:18 - 000041685 _____ C:\Users\AA583803\Downloads\jbod2 Performance_Summary.pdf
2022-03-15 11:11 - 2022-03-15 11:11 - 000011706 _____ C:\Users\AA583803\Downloads\jbod4 Portfolio Holdings.pdf
2022-03-15 10:29 - 2022-03-15 10:29 - 000041408 _____ C:\Users\AA583803\Downloads\jbod3 Allocation and Holdings Summary.pdf
2022-03-15 09:59 - 2022-03-15 10:00 - 000068371 _____ C:\Users\AA583803\Downloads\qwnkw MyPDF (5).PDF
2022-03-14 17:55 - 2022-03-14 17:55 - 000316872 _____ C:\Users\AA583803\Downloads\2015-03-12.pdf
2022-03-14 17:23 - 2022-03-14 17:23 - 001416035 _____ C:\Users\AA583803\Downloads\2387cfe1-1f98-4baf-bc39-a67b698a9418.pdf
2022-03-14 15:10 - 2022-03-14 15:10 - 001321424 _____ C:\Users\AA583803\Downloads\IVT-Reallocations-2005-2021.pdf
2022-03-14 13:35 - 2022-03-14 13:35 - 000009168 _____ C:\Users\AA583803\Downloads\Copy of Cost Basis Spreadsheet Template.xlsx
 
==================== One month (modified) ==================
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2022-04-13 17:58 - 2019-12-07 05:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2022-04-13 17:52 - 2019-01-08 16:13 - 000000000 ____D C:\Program Files (x86)\Google
2022-04-13 17:42 - 2020-12-17 07:19 - 000000000 ____D C:\WINDOWS\system32\Drivers\CrowdStrike
2022-04-13 14:17 - 2019-12-07 05:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2022-04-13 14:08 - 2020-10-17 17:23 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2022-04-13 14:03 - 2019-01-10 01:08 - 000000000 ____D C:\ProgramData\Package Cache
2022-04-13 10:42 - 2019-12-07 05:13 - 000000000 ____D C:\WINDOWS\INF
2022-04-12 19:02 - 2019-01-08 13:12 - 000000000 ____D C:\Users\AA583803\AppData\Local\D3DSCache
2022-04-12 16:41 - 2019-12-07 05:14 - 000000000 ___HD C:\Program Files\WindowsApps
2022-04-12 16:41 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2022-04-12 16:23 - 2020-10-17 17:27 - 000842522 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2022-04-12 16:06 - 2021-03-11 15:37 - 000000000 ___RD C:\Users\AA583803\OneDrive - MassMutual
2022-04-12 16:02 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2022-04-12 16:00 - 2021-06-14 11:35 - 000000000 ____D C:\Users\AA583803\AppData\Local\Dropbox
2022-04-12 15:59 - 2021-03-12 13:34 - 000000000 ___RD C:\Users\AA583803\iCloudPhotos
2022-04-12 15:59 - 2020-10-17 17:24 - 000000000 ____D C:\Users\AA583803
2022-04-12 15:59 - 2020-08-20 12:05 - 000000000 ___RD C:\Users\AA583803\iCloudDrive
2022-04-12 15:59 - 2019-01-08 13:10 - 000000000 ___RD C:\Users\AA583803\OneDrive
2022-04-12 15:58 - 2022-02-08 07:12 - 000008192 ___SH C:\DumpStack.log.tmp
2022-04-12 15:58 - 2021-06-14 11:35 - 000000934 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job
2022-04-12 15:58 - 2021-06-14 11:35 - 000000930 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job
2022-04-12 15:58 - 2021-05-03 16:29 - 000000000 ____D C:\ProgramData\VMWOSQEXT
2022-04-12 15:58 - 2021-01-23 14:38 - 000000000 ____D C:\ProgramData\CrowdStrike
2022-04-12 15:58 - 2020-10-17 17:30 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2022-04-12 15:58 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\ServiceState
2022-04-12 15:58 - 2019-12-07 05:03 - 000016384 _____ C:\WINDOWS\system32\config\ELAM
2022-04-12 15:58 - 2019-01-08 13:10 - 000000000 __SHD C:\Users\AA583803\IntelGraphicsProfiles
2022-04-12 15:58 - 2018-12-17 21:38 - 000000000 ____D C:\Intel
2022-04-12 15:58 - 2018-07-25 09:07 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2022-04-12 11:57 - 2019-04-22 10:02 - 000000000 ____D C:\Users\AA583803\AppData\Roaming\Zoom Plugin
2022-04-12 11:44 - 2019-01-08 13:10 - 000000000 ____D C:\Users\AA583803\AppData\Local\Packages
2022-04-12 11:32 - 2020-06-18 00:53 - 000002440 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2022-04-07 01:35 - 2020-09-30 01:24 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
2022-04-06 15:18 - 2019-01-08 16:13 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2022-04-06 15:16 - 2021-09-21 11:21 - 000002076 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive.lnk
2022-04-06 15:16 - 2021-09-21 11:21 - 000001907 _____ C:\Users\Default\Desktop\Google Slides.lnk
2022-04-06 15:16 - 2021-09-21 11:21 - 000001907 _____ C:\Users\Default\Desktop\Google Sheets.lnk
2022-04-06 15:16 - 2021-09-21 11:21 - 000001895 _____ C:\Users\Default\Desktop\Google Docs.lnk
2022-04-06 10:58 - 2019-12-07 05:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2022-04-06 10:16 - 2020-10-18 14:55 - 000003386 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore1d6a4cc79b7edab
2022-04-06 10:16 - 2020-10-17 17:30 - 000003480 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2022-04-04 20:42 - 2021-12-11 16:47 - 000003584 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-1146508179-405363288-658039003-1003
2022-04-04 15:03 - 2021-12-21 19:42 - 000000000 ____D C:\ProgramData\CanonIJPLM
2022-04-01 18:26 - 2021-05-25 14:35 - 000491691 _____ C:\Users\AA583803\Downloads\Planning ADV.PDF
2022-03-31 12:09 - 2021-06-14 11:35 - 000000000 ____D C:\Program Files (x86)\Dropbox
2022-03-29 15:04 - 2021-07-15 11:01 - 000000000 ____D C:\Users\AA583803\OneDrive - MassMutual\Documents\My Kindle Content
2022-03-29 14:59 - 2021-07-15 11:00 - 000000000 ____D C:\Users\AA583803\AppData\Local\Amazon
2022-03-23 21:13 - 2020-09-30 01:24 - 000601432 _____ (Microsoft Corporation) C:\WINDOWS\system32\sedplugins.dll
2022-03-23 21:12 - 2020-09-30 01:24 - 000483664 _____ (Microsoft Corporation) C:\WINDOWS\system32\QualityUpdateAssistant.dll
 
==================== Files in the root of some directories ========
 
2020-03-17 19:33 - 2020-03-17 19:33 - 000022273 _____ () C:\Users\AA583803\AppData\Roaming\Comma Separated Values.ADR
 
==================== SigCheck ============================
 
(There is no automatic fix for files that do not pass verification.)
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 13-04-2022 01
Ran by AA583803 (administrator) on AA585803-L (Dell Inc. Latitude 7390 2-in-1) (13-04-2022 18:09:20)
Running from C:\Users\AA583803\OneDrive - MassMutual\Desktop
Loaded Profiles: AA583803
Platform: Microsoft Windows 10 Pro Version 21H2 19044.1586 (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(ALPS ALPINE CO., LTD. -> ALPSALPINE CO., LTD.) C:\Windows\System32\DellTPad\ApntEx.exe
(Apple Inc.) C:\Program Files\WindowsApps\AppleInc.iCloud_13.0.201.0_x86__nzyj5cx40ttqa\iCloud\iCloudIE.exe
(C:\Program Files (x86)\Airwatch\AgentUI\TaskScheduler.exe ->) (VMware, Inc. -> VMware, Inc.) C:\Program Files (x86)\Airwatch\AgentUI\AWACMClient.exe
(C:\Program Files (x86)\Airwatch\AgentUI\TaskScheduler.exe ->) (VMware, Inc. -> VMware, Inc.) C:\Program Files (x86)\Airwatch\AgentUI\AwWindowsIpc.exe
(C:\Program Files (x86)\Dropbox\Client\Dropbox.exe ->) (Dropbox, Inc -> The Qt Company Ltd.) C:\Program Files (x86)\Dropbox\Client\145.4.4921\QtWebEngineProcess.exe <2>
(C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\splwow64.exe
(C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe ->) (Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe <17>
(C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe ->) (Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Acrobat.exe <2>
(C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe <2>
(C:\Program Files\CrowdStrike\CSFalconService.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> CrowdStrike, Inc.) C:\Program Files\CrowdStrike\CSFalconContainer.exe <2>
(C:\Program Files\Logitech\LogiOptions\LogiOptions.exe ->) (Logitech Inc -> Logitech) C:\ProgramData\Logishrd\LogiOptions\Software\Current\LogiOverlay.exe
(C:\Program Files\Logitech\LogiOptions\LogiOptions.exe ->) (Logitech Inc -> Logitech, Inc.) C:\ProgramData\Logishrd\LogiOptions\Software\Current\LogiOptionsMgr.exe
(C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe <3>
(Canon Inc. -> CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe
(Canon Inc. -> CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX2\CNMNSST2.exe
(DellTPad\Apoint.exe ->) (ALPS ALPINE CO., LTD. -> ALPSALPINE CO., LTD.) C:\Windows\System32\DellTPad\ApMsgFwd.exe
(DellTPad\Apoint.exe ->) (ALPS ALPINE CO., LTD. -> ALPSALPINE Co., Ltd.) C:\Windows\System32\DellTPad\hidfind.exe
(DellTPad\Apoint.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> ALPSALPINE Co., Ltd.) C:\Windows\System32\DellTPad\ApRemote.exe
(DellTPad\HidMonitorSvc.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> ALPSALPINE Co., Ltd.) C:\Windows\System32\DellTPad\Apoint.exe
(DriverStore\FileRepository\igdlh64.inf_amd64_45855586d601d062\igfxCUIService.exe ->) (Intel® pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_45855586d601d062\igfxEM.exe
(Dropbox, Inc -> Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe <3>
(explorer.exe ->) (Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe <2>
(explorer.exe ->) (Apple Inc.) C:\Program Files\WindowsApps\AppleInc.iCloud_13.0.201.0_x86__nzyj5cx40ttqa\iCloud\ApplePhotoStreams.exe
(explorer.exe ->) (Apple Inc.) C:\Program Files\WindowsApps\AppleInc.iCloud_13.0.201.0_x86__nzyj5cx40ttqa\iCloud\iCloudDrive.exe
(explorer.exe ->) (Apple Inc.) C:\Program Files\WindowsApps\AppleInc.iCloud_13.0.201.0_x86__nzyj5cx40ttqa\iCloud\iCloudPhotos.exe
(explorer.exe ->) (Apple Inc.) C:\Program Files\WindowsApps\AppleInc.iCloud_13.0.201.0_x86__nzyj5cx40ttqa\iCloud\iCloudServices.exe
(explorer.exe ->) (Apple Inc.) C:\Program Files\WindowsApps\AppleInc.iTunes_12123.5.56009.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe
(explorer.exe ->) (Google LLC -> ) C:\Program Files\Google\Drive File Stream\56.0.11.0\crashpad_handler.exe <3>
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <14>
(explorer.exe ->) (Google LLC -> Google, Inc.) C:\Program Files\Google\Drive File Stream\56.0.11.0\GoogleDriveFS.exe <7>
(explorer.exe ->) (Logitech Inc -> Logitech, Inc.) C:\Program Files\Logitech\LogiOptions\LogiOptions.exe
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
(explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(explorer.exe ->) (U3 LLC -> ) C:\ProgramData\U3\U3Launcher\LaunchU3.exe
(explorer.exe ->) (Waves Inc -> Waves Audio Ltd.) C:\Program Files\Waves\MaxxAudio\WavesSvc64.exe
(explorer.exe ->) (Xerox Corporation) [File not signed] C:\Program Files\Xerox\Xerox Workplace Cloud Client\JobSubmission\JobSubmission.exe
(explorer.exe ->) (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.) C:\Users\AA583803\AppData\Roaming\Zoom\bin\Zoom.exe <2>
(Intel\DPTF\esif_uf.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\Intel\DPTF\dptf_helper.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\msoasb.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\AA583803\AppData\Local\Microsoft\Teams\current\Teams.exe <8>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MusNotifyIcon.exe
(SearchIndexer.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (ALPS ALPINE CO., LTD. -> ALPSALPINE Co., Ltd.) C:\Windows\System32\DellTPad\HidMonitorSvc.exe
(services.exe ->) (Canon Inc. -> ) C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(services.exe ->) (Dell Inc -> ) C:\Program Files (x86)\Dell\UpdateService\ServiceShell.exe
(services.exe ->) (Dell Inc -> Dell Inc.) C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe
(services.exe ->) (Dell Technologies Inc. -> Dell Technologies Inc.) C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe
(services.exe ->) (Dell Technologies Inc. -> Dell Technologies Inc.) C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe
(services.exe ->) (Dell Technologies Inc. -> Dell Technologies Inc.) C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe
(services.exe ->) (Dropbox, Inc -> Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
(services.exe ->) (GeoComply USA, Inc. -> GeoComply) C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\service.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\Intel\DPTF\esif_uf.exe
(services.exe ->) (Intel Corporation -> Intel® Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(services.exe ->) (Intel Corporation -> Intel® Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(services.exe ->) (Intel Corporation -> Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(services.exe ->) (Intel® Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe
(services.exe ->) (Intel® Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(services.exe ->) (Intel® pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_45855586d601d062\igfxCUIService.exe
(services.exe ->) (Intel® pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_45855586d601d062\IntelCpHDCPSvc.exe
(services.exe ->) (Intel® pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_45855586d601d062\IntelCpHeciSvc.exe
(services.exe ->) (Intel® Rapid Storage Technology -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iastorac.inf_amd64_9c788f1d162b1224\RstMwService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> CrowdStrike, Inc.) C:\Program Files\CrowdStrike\CSFalconService.exe
(services.exe ->) (PC-Doctor, Inc. -> PC-Doctor, Inc.) C:\Program Files\Dell\SupportAssistAgent\PCD\SupportAssist\Dsapi.exe
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(services.exe ->) (VMware, Inc. -> VMware, Inc.) C:\Program Files (x86)\Airwatch\AgentUI\TaskScheduler.exe
(services.exe ->) (VMware, Inc. -> VMware, Inc.) C:\Program Files (x86)\Airwatch\HealthMonitoring\Service\VMwareHubHealthMonitoring.exe
(services.exe ->) (Wacom Technology Corporation -> Wacom Technology, Corp.) C:\Windows\System32\DriverStore\FileRepository\wtabletserviceisd.inf_amd64_30083e9f0e289fee\WTabletServiceISD.exe <2>
(services.exe ->) (Waves Inc -> Waves Audio Ltd.) C:\Program Files\Waves\MaxxAudio\WavesSysSvc64.exe
(services.exe ->) (Xerox Corporation) [File not signed] C:\Program Files\Xerox\Xerox Workplace Cloud Client\Xerox.Cloud.VirtualPrint.ClientService\Xerox.Cloud.VirtualPrint.ClientService.exe
(svchost.exe ->) (Apple Inc.) C:\Program Files\WindowsApps\AppleInc.iCloud_13.0.201.0_x86__nzyj5cx40ttqa\iCloud\APSDaemon.exe
(svchost.exe ->) (Apple Inc.) C:\Program Files\WindowsApps\AppleInc.iCloud_13.0.201.0_x86__nzyj5cx40ttqa\iCloud\secd.exe
(svchost.exe ->) (Dropbox, Inc -> Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Users\AA583803\AppData\Local\Microsoft\OneDrive\22.055.0313.0001\FileCoAuth.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
 
==================== Registry (Whitelisted) ===================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [11235936 2020-08-14] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_PushButton] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [3618096 2020-08-14] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [LogiOptions] => C:\Program Files\Logitech\LogiOptions\LogiOptions.exe [2176648 2018-12-14] (Logitech Inc -> Logitech, Inc.)
HKLM\...\Run: [XMPCJobMonitor] => C:\Program Files\Xerox\Xerox Workplace Cloud Client\JobSubmission\JobSubmission.exe [195584 2019-11-12] (Xerox Corporation) [File not signed]
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [3831808 2021-08-30] (Microsoft Windows Hardware Compatibility Publisher -> Logitech)
HKLM\...\Run: [WavesSvc] => c:\Program Files\Waves\MaxxAudio\WavesSvc64.exe [1229080 2020-03-31] (Waves Inc -> Waves Audio Ltd.)
HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [438888 2014-01-15] (Canon Inc. -> CANON INC.)
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [10585376 2022-03-27] (Dropbox, Inc -> Dropbox, Inc.)
HKLM-x32\...\Run: [IJNetworkScannerSelectorEX2] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX2\CNMNSST2.exe [278440 2019-12-05] (Canon Inc. -> CANON INC.)
HKU\S-1-5-19\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\56.0.11.0\GoogleDriveFS.exe [53664656 2022-03-30] (Google LLC -> Google, Inc.)
HKU\S-1-5-20\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\56.0.11.0\GoogleDriveFS.exe [53664656 2022-03-30] (Google LLC -> Google, Inc.)
HKU\S-1-5-21-1146508179-405363288-658039003-1003\...\Run: [com.squirrel.Teams.Teams] => C:\Users\AA583803\AppData\Local\Microsoft\Teams\Update.exe [2490040 2022-03-03] (Microsoft 3rd Party Application Component -> Microsoft Corporation)
HKU\S-1-5-21-1146508179-405363288-658039003-1003\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\56.0.11.0\GoogleDriveFS.exe [53664656 2022-03-30] (Google LLC -> Google, Inc.)
HKU\S-1-5-21-1146508179-405363288-658039003-1003\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\scrnsave.scr [39936 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-18\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [324976 2010-05-21] (Flexera Software, Inc.  -> Flexera Software, Inc.)
HKU\S-1-5-18\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\56.0.11.0\GoogleDriveFS.exe [53664656 2022-03-30] (Google LLC -> Google, Inc.)
HKLM\...\Windows x64\Print Processors\Canon TR8600 series Print Processor: C:\Windows\System32\spool\prtprocs\x64\CNMPDGU.DLL [525824 2021-09-12] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Windows x64\Print Processors\hpcpp215: C:\Windows\System32\spool\prtprocs\x64\hpcpp215.dll [770232 2018-03-04] (HP Inc. -> HP Inc.)
HKLM\...\Windows x64\Print Processors\XeroxV5Print: C:\Windows\System32\spool\prtprocs\x64\x5print.dll [95232 2021-06-03] (Microsoft Windows Hardware Compatibility Publisher -> Xerox Corporation)
HKLM\...\Print\Monitors\Canon BJ FAX Language Monitor TR8600 series: C:\WINDOWS\system32\CNCALGU.DLL [258048 2020-03-18] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\Canon BJ Language Monitor MG6600 series: CNMLMC9.DLL
HKLM\...\Print\Monitors\Canon BJ Language Monitor TR8600 series: C:\WINDOWS\system32\CNMLMGU.DLL [1355264 2021-09-12] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\Canon BJNP Port: C:\WINDOWS\system32\CNMN6PPM.DLL [375296 2014-03-17] (CANON INC.) [File not signed]
HKLM\...\Print\Monitors\HP Universal Print Monitor: C:\WINDOWS\system32\HPMPW082.DLL [128184 2018-03-04] (HP Inc. -> HP Inc.)
HKLM\...\Print\Monitors\HPMLM190: C:\WINDOWS\system32\hpmlm190.dll [310968 2018-03-04] (HP Inc. -> HP Inc.)
HKLM\...\Print\Monitors\Xerox Cloud Port Monitor: C:\WINDOWS\system32\XMPCPortMon.dll [349184 2018-04-18] (Xerox Corporation) [File not signed]
HKLM\...\Print\Monitors\Xerox Virtualization Port: C:\WINDOWS\system32\x5lrsl.dll [135168 2021-06-03] (Microsoft Windows Hardware Compatibility Publisher -> Xerox Corporation)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\100.0.4896.75\Installer\chrmstp.exe [2022-04-06] (Google LLC -> Google LLC)
Startup: C:\Users\AA583803\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LaunchU3.exe.lnk [2019-02-11]
ShortcutTarget: LaunchU3.exe.lnk -> C:\Users\AA583803\AppData\Roaming\Microsoft\Installer\{D8E363A7-88B7-446D-B2C0-E26CE4DC8E54}\_294823.exe () [File not signed]
Startup: C:\Users\AA583803\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RingCentral.lnk [2021-09-14]
ShortcutTarget: RingCentral.lnk -> C:\Users\AA583803\AppData\Local\Programs\RingCentral\RingCentral.exe (No File)
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION
 
==================== Scheduled Tasks (Whitelisted) ============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {0467277A-332B-4A71-8C89-79A851937A08} - System32\Tasks\Symantec Endpoint Protection\Symantec Endpoint Protection Error Analyzer => C:\Program Files\Symantec\14.0.3752.1000.105\Bin\SymErr.exe /analyze (No File)
Task: {047C7BF7-AB0B-4D37-8547-506A575A121B} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2019-01-08] (Google Inc -> Google Inc.)
Task: {05AD6016-3472-4E40-8589-69C3570095C9} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1564424 2021-11-18] (Adobe Inc. -> Adobe Inc.)
Task: {069FCE3D-C175-4042-A733-78E36B819635} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt application on switch user if service is up => C:\Program Files (x86)\Intel\Thunderbolt Software\\ConditionalAppStarter.exe [226008 2018-12-25] (Intel® Client Connectivity Division SW -> Intel Corporation)
Task: {0BC0BA1F-6AC2-4536-A85B-1C2268DE5290} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [115632 2022-04-12] (Microsoft Corporation -> Microsoft Corporation)
Task: {10721086-7850-46D7-A2DC-12E78C41483B} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\2FCDED1F-9CF4-452B-AD3C-CEAE571798E2\OS Edition Upgrade event listener created by enrollment client => C:\WINDOWS\system32\deviceenroller.exe [448512 2022-02-11] (Microsoft Windows -> Microsoft Corporation)
Task: {12508CED-FA9C-4D50-A94B-E12C3EFB9E57} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt application on login if service is up => C:\Program Files (x86)\Intel\Thunderbolt Software\\ConditionalAppStarter.exe [226008 2018-12-25] (Intel® Client Connectivity Division SW -> Intel Corporation)
Task: {1D8674D0-474A-47ED-B537-31A675053690} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\2FCDED1F-9CF4-452B-AD3C-CEAE571798E2\Schedule #1 created by enrollment client => C:\WINDOWS\system32\deviceenroller.exe [448512 2022-02-11] (Microsoft Windows -> Microsoft Corporation)
Task: {2137CF50-1EAF-4BAC-8340-3B0BAF21548B} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\2FCDED1F-9CF4-452B-AD3C-CEAE571798E2\Schedule to run OMADMClient by client => C:\WINDOWS\system32\omadmclient.exe [432128 2022-03-08] (Microsoft Windows -> Microsoft Corporation)
Task: {3A1CF712-6D22-4FE0-8D46-602DB456E46E} - \OneDrive Standalone Update Task-S-1-5-21-1146508179-405363288-658039003-1001 -> No File <==== ATTENTION
Task: {3F345019-E5A1-46B2-8F24-DB73B7BE34A9} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\2FCDED1F-9CF4-452B-AD3C-CEAE571798E2\Schedule #3 created by enrollment client => C:\WINDOWS\system32\deviceenroller.exe [448512 2022-02-11] (Microsoft Windows -> Microsoft Corporation)
Task: {4C52EDAE-B5AF-4D5C-8B6D-001A95F35383} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt service when hardware is detected => sc.exe start ThunderboltService
Task: {4EBADE0C-CD84-449F-B631-3770A8C22F40} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\2FCDED1F-9CF4-452B-AD3C-CEAE571798E2\Schedule created by enrollment client for renewal of certificate warning => C:\WINDOWS\system32\deviceenroller.exe [448512 2022-02-11] (Microsoft Windows -> Microsoft Corporation)
Task: {4EF4B17D-010E-4EBE-8602-18A72085EAAE} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [5439888 2022-01-20] (Microsoft Corporation -> Microsoft Corporation)
Task: {51FEA407-1BE9-4928-81A5-287B65F63451} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\2FCDED1F-9CF4-452B-AD3C-CEAE571798E2\PushRenewal => C:\WINDOWS\system32\deviceenroller.exe [448512 2022-02-11] (Microsoft Windows -> Microsoft Corporation)
Task: {5516DEF5-18A9-45F7-9E52-F85E5FA333A9} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\2FCDED1F-9CF4-452B-AD3C-CEAE571798E2\Schedule to run OMADMClient by server => C:\WINDOWS\system32\omadmclient.exe [432128 2022-03-08] (Microsoft Windows -> Microsoft Corporation)
Task: {5FDD8265-4F24-4869-B704-C17EB3720F10} - System32\Tasks\GeoComply Update Task => C:\Program Files (x86)\GeoComply\\PlayerLocationCheck\Update\GeoComplyUpdate.exe [3191272 2022-01-10] (GeoComply USA, Inc. -> GeoComply) -> /config=C:\Program Files (x86)\GeoComply\\PlayerLocationCheck\Update\GeoComplyUpdate.xml
Task: {66B71282-8905-4249-92DE-7FAEA5524D44} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [5439888 2022-01-20] (Microsoft Corporation -> Microsoft Corporation)
Task: {67A95341-70AC-4A00-BC39-5EB37DC18C42} - System32\Tasks\VMware\SfdAgent\Check Required Apps => C:\Program Files\VMware\SfdAgent\VMware.Hub.SfdAgent.DeployCmd.exe [30608 2021-08-20] (VMware, Inc. -> VMware EUC)
Task: {727D92C4-0CA5-4348-84B0-EA817BADA23C} - System32\Tasks\G2MUpdateTask-S-1-5-21-1146508179-405363288-658039003-1003 => C:\Users\AA583803\AppData\Local\GoToMeeting\19932\g2mupdate.exe [31176 2021-11-11] (LogMeIn, Inc. -> LogMeIn, Inc.)
Task: {81D3FADB-33BF-4658-A73C-F867C78EFE96} - System32\Tasks\Symantec Endpoint Protection\Symantec Endpoint Protection Error Processor => C:\Program Files\Symantec\14.0.3752.1000.105\Bin\SymErr.exe /submit (No File)
Task: {89C52B1D-7C79-413A-98EC-4C486F6EB81D} - System32\Tasks\VMwareHubHealthMonitoringJob => C:\Program Files (x86)\Airwatch\HealthMonitoring\Maintenance\VMwareHubHealthMonitoring.exe [15568 2022-03-17] (VMware, Inc. -> VMware, Inc.)
Task: {97FE8533-1FFE-4892-A97A-A8D974105433} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\2FCDED1F-9CF4-452B-AD3C-CEAE571798E2\PushLaunch => C:\WINDOWS\system32\deviceenroller.exe [448512 2022-02-11] (Microsoft Windows -> Microsoft Corporation)
Task: {99482EF8-F4AB-4A4E-A286-DC8A726FABB1} - System32\Tasks\LastPassUpdater => C:\Program Files (x86)\LastPass\Updater\Updater.exe [1319288 2022-02-14] (LogMeIn, Inc. -> LogMeIn Inc.)
Task: {A6EE8131-D7F3-4130-B755-F2D8459DBF6A} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\2FCDED1F-9CF4-452B-AD3C-CEAE571798E2\Provisioning initiated session => C:\WINDOWS\system32\deviceenroller.exe [448512 2022-02-11] (Microsoft Windows -> Microsoft Corporation)
Task: {A92012C5-75C4-44E4-A49C-1D47FE040D31} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [21864400 2022-04-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {B1A4FF7F-2F01-4E26-8E65-99AA3859DA8E} - System32\Tasks\Dell SupportAssistAgent AutoUpdate => C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistInstaller.exe [1060384 2021-11-15] (Dell Inc -> Dell Inc.)
Task: {B43156A6-74DD-469A-B9F9-732E1B8939C1} - System32\Tasks\VMware\SfdAgent\Install Validation Task => C:\Program Files\VMware\SfdAgent\VMware.Hub.SfdAgent.DeployCmd.exe [30608 2021-08-20] (VMware, Inc. -> VMware EUC)
Task: {BB7422E5-15E9-432E-AA68-406E6C3D1EEE} - System32\Tasks\Microsoft\Office\Office Serviceability Manager => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\officesvcmgr.exe [4102784 2022-02-06] (Microsoft Corporation -> Microsoft Corporation)
Task: {C1C51FF5-FF55-4566-A0EC-2D091017740E} - System32\Tasks\ApowerREC => C:\Program Files (x86)\Apowersoft\ApowerREC\ApowerREC.exe /autoStart (No File)
Task: {C5F8B471-9FDC-4E55-B966-6B6691E5A6C9} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [130320 2021-11-10] (Dropbox, Inc -> Dropbox, Inc.)
Task: {C85B7E30-F968-441A-9317-CACE4A6EEE4C} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\2FCDED1F-9CF4-452B-AD3C-CEAE571798E2\Passport for Work alert created by enrollment client => C:\WINDOWS\system32\deviceenroller.exe [448512 2022-02-11] (Microsoft Windows -> Microsoft Corporation)
Task: {CA3A1867-0675-452A-8C7A-DAC7FB0C6CBE} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\2FCDED1F-9CF4-452B-AD3C-CEAE571798E2\Win10 S Mode event listener created by enrollment client => C:\WINDOWS\system32\deviceenroller.exe [448512 2022-02-11] (Microsoft Windows -> Microsoft Corporation)
Task: {CD356E30-F06F-4078-B746-DEE1516EF923} - System32\Tasks\G2MUploadTask-S-1-5-21-1146508179-405363288-658039003-1003 => C:\Users\AA583803\AppData\Local\GoToMeeting\19932\g2mupload.exe [31176 2021-11-11] (LogMeIn, Inc. -> LogMeIn, Inc.)
Task: {CE895677-286B-4511-A3C0-51EAB2691BF6} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2019-01-08] (Google Inc -> Google Inc.)
Task: {CF377CCA-4259-4304-B839-F09C94A06BBB} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [1158576 2022-04-12] (Microsoft Corporation -> Microsoft Corporation)
Task: {D055B4B6-FC78-4474-A589-D1EA5CC0B67A} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt application when hardware is detected => C:\Program Files (x86)\Intel\Thunderbolt Software\\ConditionalAppStarter.exe [226008 2018-12-25] (Intel® Client Connectivity Division SW -> Intel Corporation)
Task: {D6909D20-0CD9-43AA-88D8-7B3C218A2755} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\2FCDED1F-9CF4-452B-AD3C-CEAE571798E2\Schedule #2 created by enrollment client => C:\WINDOWS\system32\deviceenroller.exe [448512 2022-02-11] (Microsoft Windows -> Microsoft Corporation)
Task: {D81D3ACE-DB1D-43BD-A45E-36C564BE8791} - System32\Tasks\Symantec Endpoint Protection\Symantec Endpoint Protection Autofix => C:\Program Files\Symantec\14.0.3752.1000.105\Bin\SymErr.exe /ui (No File)
Task: {D8602836-D7AC-4E00-912A-C92CE18E1D62} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\2FCDED1F-9CF4-452B-AD3C-CEAE571798E2\Wsc Startup event listener created by enrollment client => C:\WINDOWS\system32\deviceenroller.exe [448512 2022-02-11] (Microsoft Windows -> Microsoft Corporation)
Task: {E24B7596-7FF3-42EA-BE35-F0FDF8903B06} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\2FCDED1F-9CF4-452B-AD3C-CEAE571798E2\PushUpgrade => C:\WINDOWS\system32\deviceenroller.exe [448512 2022-02-11] (Microsoft Windows -> Microsoft Corporation)
Task: {EB72CF1A-6DAC-4E26-9993-7406966499B3} - System32\Tasks\VMware\SfdAgent\Software Distribution Queue Task => C:\Program Files\VMware\SfdAgent\VMware.Hub.SfdAgent.DeployCmd.exe [30608 2021-08-20] (VMware, Inc. -> VMware EUC)
Task: {EF49295D-3116-4D15-A093-1012862D40E5} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [21864400 2022-04-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {F5A18EDF-B5B1-48B8-B46E-797CE32A2D2C} - System32\Tasks\GeoComply Service Check => "C:\Program Files (x86)\GeoComply\\PlayerLocationCheck\Application\PlayerLocationCheckTask.cmd"  (No File)
Task: {F5F3A743-915F-40E0-B360-C85F1B54137D} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [115632 2022-04-12] (Microsoft Corporation -> Microsoft Corporation)
Task: {FC3BA724-6E91-4146-83E1-96E1052EEF9C} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt service on boot if driver is up => C:\Program Files (x86)\Intel\Thunderbolt Software\\tbtsvc.exe [2302168 2018-12-25] (Intel® Client Connectivity Division SW -> Intel Corporation)
Task: {FECAF8C5-FDC6-4FD2-B1AD-DB661C45C115} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [130320 2021-11-10] (Dropbox, Inc -> Dropbox, Inc.)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-1146508179-405363288-658039003-1003.job => C:\Users\AA583803\AppData\Local\GoToMeeting\19932\g2mupdate.exe
Task: C:\WINDOWS\Tasks\G2MUploadTask-S-1-5-21-1146508179-405363288-658039003-1003.job => C:\Users\AA583803\AppData\Local\GoToMeeting\19932\g2mupload.exe
Task: C:\WINDOWS\Tasks\VMwareHubHealthMonitoringJob.job => C:\Program Files (x86)\Airwatch\HealthMonitoring\Maintenance\VMwareHubHealthMonitoring.exe
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 170.6.240.26 170.6.241.166
Tcpip\..\Interfaces\{84e76070-f2bf-49f1-bbb2-4bfd1a7d3ce4}: [DhcpNameServer] 170.6.240.26 170.6.241.166
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <==== ATTENTION
 
Edge: 
=======
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
Edge Extension: (No Name) -> hdokiejnpimakedhajhdlcegeplioahd_LastPassLastPassFreePasswordManager_qq0fmhteeht3j => C:\Program Files\WindowsApps\LastPass.LastPassFreePasswordManager_4.48.0.0_neutral__qq0fmhteeht3j [not found]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
Edge DefaultProfile: Default
Edge Profile: C:\Users\AA583803\AppData\Local\Microsoft\Edge\User Data\Default [2022-04-06]
Edge HomePage: Default -> hxxps://massmutual.okta.com/
Edge Extension: (LastPass: Free Password Manager) - C:\Users\AA583803\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\bbcinlkgjjkejfdpemiealijmmooekmp [2022-03-28]
 
FireFox:
========
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation ->  Microsoft Corporation)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2022-03-02] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2017-10-17] (CANON INC.) [File not signed]
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2022-01-20] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation ->  Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2022-01-20] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin HKU\S-1-5-21-1146508179-405363288-658039003-1003: SkypeForBusinessPlugin-16.2 -> C:\Users\AA583803\AppData\Local\Microsoft\SkypeForBusinessPlugin\16.2.0.282\npGatewayNpapi.dll [2018-10-19] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin HKU\S-1-5-21-1146508179-405363288-658039003-1003: SkypeForBusinessPlugin64-16.2 -> C:\Users\AA583803\AppData\Local\Microsoft\SkypeForBusinessPlugin\16.2.0.282\npGatewayNpapi-x64.dll [2018-10-19] (Microsoft Corporation -> Microsoft Corporation)
 
Chrome: 
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\AA583803\AppData\Local\Google\Chrome\User Data\Default [2022-04-13]
CHR Notifications: Default -> hxxps://app.gotowebinar.com; hxxps://chatsupport.apple.com; hxxps://ocsnext.ebay.com; hxxps://www.jetblue.com; hxxps://www.verizon.com
CHR StartupUrls: Default -> "hxxps://massmutual.okta.com/"
CHR Extension: (Slides) - C:\Users\AA583803\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2019-01-08]
CHR Extension: (Docs) - C:\Users\AA583803\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2019-01-08]
CHR Extension: (Google Drive) - C:\Users\AA583803\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-10-27]
CHR Extension: (YouTube) - C:\Users\AA583803\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2019-01-08]
CHR Extension: (Honey) - C:\Users\AA583803\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmnlcjabgnpnenekpadlanbbkooimhnj [2022-04-13]
CHR Extension: (Screencast-O-Matic Launcher) - C:\Users\AA583803\AppData\Local\Google\Chrome\User Data\Default\Extensions\eefedolmcildfckjamddopaplfiiankl [2019-05-28]
CHR Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\AA583803\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2022-04-12]
CHR Extension: (Sheets) - C:\Users\AA583803\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2019-01-08]
CHR Extension: (Google Docs Offline) - C:\Users\AA583803\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2022-04-12]
CHR Extension: (LastPass: Free Password Manager) - C:\Users\AA583803\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd [2022-04-12]
CHR Extension: (App Launcher for Google Maps) - C:\Users\AA583803\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmiegoigendlbmjjllhjmkjenjechmhg [2019-01-09]
CHR Extension: (Application Launcher For Drive (by Google)) - C:\Users\AA583803\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2021-02-06]
CHR Extension: (Chrome Web Store Payments) - C:\Users\AA583803\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-02-06]
CHR Extension: (Print Friendly & PDF) - C:\Users\AA583803\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohlencieiipommannpdfcmfdpjjmeolj [2021-04-11]
CHR Extension: (Gmail) - C:\Users\AA583803\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-10-27]
CHR Profile: C:\Users\AA583803\AppData\Local\Google\Chrome\User Data\System Profile [2019-08-24]
CHR HKU\S-1-5-21-1146508179-405363288-658039003-1003\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
 
==================== Services (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [169728 2021-11-18] (Adobe Inc. -> Adobe Inc.)
R2 AirwatchService; C:\Program Files (x86)\Airwatch\AgentUI\TaskScheduler.exe [22224 2022-03-17] (VMware, Inc. -> VMware, Inc.)
R2 ApHidMonitorService; C:\WINDOWS\system32\DellTPad\HidMonitorSvc.exe [894880 2021-05-24] (ALPS ALPINE CO., LTD. -> ALPSALPINE Co., Ltd.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [9192328 2022-02-06] (Microsoft Corporation -> Microsoft Corporation)
R2 CsFalconService; C:\Program Files\CrowdStrike\CSFalconService.exe [2939160 2022-03-13] (Microsoft Windows Hardware Compatibility Publisher -> CrowdStrike, Inc.)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [130320 2021-11-10] (Dropbox, Inc -> Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [130320 2021-11-10] (Dropbox, Inc -> Dropbox, Inc.)
R2 DbxSvc; C:\WINDOWS\system32\DbxSvc.exe [44328 2022-03-27] (Dropbox, Inc -> Dropbox, Inc.)
R2 DDVCollectorSvcApi; C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe [436256 2021-09-29] (Dell Technologies Inc. -> Dell Technologies Inc.)
R2 DDVDataCollector; C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe [3847712 2021-09-29] (Dell Technologies Inc. -> Dell Technologies Inc.)
R2 DDVRulesProcessor; C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe [462880 2021-09-29] (Dell Technologies Inc. -> Dell Technologies Inc.)
R2 Dell Hardware Support; C:\Program Files\Dell\SupportAssistAgent\PCD\SupportAssist\Dsapi.exe [1024680 2021-09-02] (PC-Doctor, Inc. -> PC-Doctor, Inc.)
R2 DellClientManagementService; C:\Program Files (x86)\Dell\UpdateService\ServiceShell.exe [38600 2021-11-12] (Dell Inc -> )
S2 ETActiveSteeringHelper; C:\WINDOWS\Ethertronics\ETservice.exe [389616 2017-11-26] (Microsoft Windows Hardware Compatibility Publisher -> )
S3 GoToAssist; C:\Program Files (x86)\LogMeIn\GoToAssist Corporate\1280\G2AC_Service.exe [316872 2019-06-27] (LogMeIn, Inc. -> LogMeIn, Inc.)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [445432 2021-04-19] (Canon Inc. -> )
R2 Net Driver HPZ12; C:\Windows\System32\HPZinw12.dll [50688 2016-06-15] (HP Inc.) [File not signed]
S3 OfficeSvcManagerAddons; C:\WINDOWS\system32\dllhost.exe /Processid:{2CA2E202-932F-4BA2-8771-195BB86398F5} [21312 2020-10-19] (Microsoft Windows -> Microsoft Corporation)
R2 Player Location Check; C:\Program Files (x86)\GeoComply\//PlayerLocationCheck///Application/service.exe [3141608 2022-01-10] (GeoComply USA, Inc. -> GeoComply)
R2 Pml Driver HPZ12; C:\Windows\System32\HPZipm12.dll [66048 2016-06-15] (HP Inc.) [File not signed]
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [6228008 2022-03-08] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 SupportAssistAgent; C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [39968 2021-11-15] (Dell Inc -> Dell Inc.)
R2 VMware Hub Health Monitoring Service; C:\Program Files (x86)\Airwatch\HealthMonitoring\Service\VMwareHubHealthMonitoring.exe [15568 2022-03-17] (VMware, Inc. -> VMware, Inc.)
S2 VMWOSQEXT; C:\Program Files (x86)\Airwatch\AgentUI\Telemetry\vmwosqext.exe [24367560 2022-03-17] (VMware, Inc. -> VMware, Inc.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [3004048 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103384 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 XMPC VirtualPrint Client Service; C:\Program Files\Xerox\Xerox Workplace Cloud Client\Xerox.Cloud.VirtualPrint.ClientService\Xerox.Cloud.VirtualPrint.ClientService.exe [10752 2019-11-12] (Xerox Corporation) [File not signed]
 
===================== Drivers (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 ApHidfiltrService; C:\WINDOWS\System32\drivers\ApHidfiltrSW.sys [362512 2021-05-24] (WDKTestCert CHT1HTSH3180,132475688214743128 -> ALPSALPINE Co., Ltd.)
S3 AppleKmdfFilter; C:\WINDOWS\System32\drivers\AppleKmdfFilter.sys [20032 2020-10-09] (WDKTestCert build,132303256403278908 -> Apple Inc.)
S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35976 2020-10-09] (WDKTestCert build,132303256403278908 -> Apple Inc.)
S3 bcmnfcusb; C:\WINDOWS\System32\drivers\bcmnfcusb.sys [45656 2018-06-02] (Broadcom Corporation -> Broadcom Corporation.)
R1 CSAgent; C:\WINDOWS\system32\drivers\CrowdStrike\csagent.sys [2810072 2022-03-13] (Microsoft Windows Hardware Compatibility Publisher -> CrowdStrike, Inc.)
S0 CSBoot; C:\WINDOWS\System32\drivers\CrowdStrike\CSBoot.sys [24208 2022-03-13] (Microsoft Windows Early Launch Anti-malware Publisher -> CrowdStrike, Inc.)
R3 CSDeviceControl; C:\WINDOWS\System32\drivers\CSDeviceControl.sys [224448 2022-01-22] (Microsoft Windows Hardware Compatibility Publisher -> CrowdStrike, Inc.)
R0 CSFirmwareAnalysis; C:\WINDOWS\System32\DRIVERS\CSFirmwareAnalysis.sys [93248 2021-10-21] (Microsoft Windows Hardware Compatibility Publisher -> CrowdStrike, Inc.)
R3 DDDriver; C:\WINDOWS\System32\drivers\dddriver64Dcsa.sys [43400 2021-09-09] (Microsoft Windows Hardware Compatibility Publisher -> Dell Technologies)
S3 DellRbtn; C:\WINDOWS\System32\drivers\DellRbtn.sys [22848 2017-10-13] (WDKTestCert Andy_Chen6,131219483243550933 -> OSR Open Systems Resources, Inc.)
S3 ETActiveSteering; C:\WINDOWS\System32\drivers\ETActiveSteering.sys [38680 2017-11-26] (WDKTestCert norikd,131383411497448652 -> Ethertronics I2C driver for ASA)
R1 googledrivefs3688; C:\WINDOWS\System32\DRIVERS\googledrivefs3688.sys [381456 2021-12-14] (Microsoft Windows Hardware Compatibility Publisher -> Google, Inc.)
R1 googledrivefs3758; C:\WINDOWS\System32\DRIVERS\googledrivefs3758.sys [384584 2022-03-14] (Microsoft Windows Hardware Compatibility Publisher -> Google, Inc.)
S3 Netaapl; C:\WINDOWS\System32\drivers\netaapl64.sys [32352 2017-11-28] (Microsoft Windows Hardware Compatibility Publisher -> Apple Inc.)
S3 SnapCameraVirtualDevice; C:\WINDOWS\System32\drivers\SnapCameraVirtualDevice.sys [2800232 2020-03-21] (Snap Inc. -> Windows ® Win 7 DDK provider)
S3 swmbbser05; C:\WINDOWS\System32\drivers\swmbbser05.sys [287816 2018-01-31] (Sierra Wireless, Inc -> Sierra Wireless Incorporated)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [46688 2019-12-07] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [350136 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [54200 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
S4 DBUtilDrv2; \SystemRoot\System32\drivers\DBUtilDrv2.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One month (created) (Whitelisted) =========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2022-04-13 18:08 - 2022-04-13 18:09 - 000000000 ____D C:\FRST
2022-04-13 17:57 - 2022-04-13 17:57 - 000003320 _____ C:\WINDOWS\system32\Tasks\GeoComply Service Check
2022-04-13 14:26 - 2022-04-13 14:27 - 000033623 _____ C:\Users\AA583803\Downloads\TaxDocumentsView (14).pdf
2022-04-13 14:25 - 2022-04-13 14:25 - 000055733 _____ C:\Users\AA583803\Downloads\TaxDocumentsView (13).pdf
2022-04-13 14:24 - 2022-04-13 14:24 - 000012509 _____ C:\Users\AA583803\Downloads\TaxDocumentsView (12).pdf
2022-04-13 14:23 - 2022-04-13 14:30 - 000000000 ____D C:\Users\AA583803\Downloads\murphy tax docs
2022-04-13 14:23 - 2022-04-13 14:23 - 000025347 _____ C:\Users\AA583803\Downloads\TaxDocumentsView (11).pdf
2022-04-13 14:04 - 2022-04-13 14:04 - 000000000 ___HD C:\$WinREAgent
2022-04-13 12:16 - 2022-04-13 12:16 - 000082511 _____ C:\Users\AA583803\Downloads\MML0018_YTD_NONDISCRIMATIONTESTING.pdf
2022-04-12 19:04 - 2022-04-12 19:04 - 000320363 _____ C:\Users\AA583803\Downloads\return history.pdf
2022-04-12 18:54 - 2022-04-12 18:54 - 000176948 _____ C:\Users\AA583803\Downloads\Anand B Lincoln account summary.pdf
2022-04-12 16:29 - 2022-04-12 16:29 - 000227511 _____ C:\Users\AA583803\Downloads\VA-LVBSH-RST001_FINAL.pdf
2022-04-12 16:26 - 2022-04-12 16:27 - 000300864 _____ C:\Users\AA583803\Downloads\QA_InterimValue_Nov2021.pdf
2022-04-12 15:59 - 2022-04-12 15:59 - 000000289 _____ C:\Users\AA583803\Google Drive.lnk
2022-04-12 15:27 - 2022-04-12 15:27 - 001362758 _____ C:\Users\AA583803\Downloads\LevelAdv_RefGuide_Feb2022.pdf
2022-04-12 15:00 - 2022-04-12 15:00 - 000983993 _____ C:\Users\AA583803\Downloads\162699_03f8a4f6-cdbb-4dca-b530-586cf51e43b8.pdf
2022-04-12 14:51 - 2022-04-12 14:51 - 001591847 _____ C:\Users\AA583803\Downloads\SCS PLUS 21 Cap Rate Flyer Series B - PreAnnounced (3).pdf
2022-04-12 13:55 - 2022-04-12 13:55 - 000026320 _____ C:\Users\AA583803\Downloads\Invoice INV-23240 (1).pdf
2022-04-12 13:42 - 2022-04-12 13:42 - 000542370 _____ C:\Users\AA583803\Downloads\report_1243.pdf
2022-04-12 12:28 - 2022-04-12 12:28 - 001176797 _____ C:\Users\AA583803\Downloads\Planning_Agreement_from_Joel_Bernstein____Mp.pdf
2022-04-12 11:42 - 2022-04-12 11:42 - 000054211 _____ C:\Users\AA583803\Downloads\780x-A585803-O256-dt20220411.xlsx
2022-04-12 11:28 - 2022-04-12 11:28 - 001493131 _____ C:\Users\AA583803\Downloads\sheeh_220408_ON_Partial_Withdrawal (1).pdf
2022-04-12 11:27 - 2022-04-12 11:27 - 000108535 _____ C:\Users\AA583803\Downloads\sheehan fax cover sheet.xlsx
2022-04-12 11:27 - 2022-04-12 11:27 - 000099216 _____ C:\Users\AA583803\Downloads\sheehan fax cover sheet.pdf
2022-04-12 11:21 - 2022-04-12 11:21 - 001410279 _____ C:\Users\AA583803\Downloads\sheeh_220408_ON_Partial_Withdrawal.pdf
2022-04-12 11:17 - 2022-04-12 11:17 - 000907547 _____ C:\Users\AA583803\Downloads\sheeh 220408 ON Partial Withdrawal.pdf
2022-04-12 11:12 - 2022-04-12 11:12 - 001427349 _____ C:\Users\AA583803\Downloads\combinepdf (53).pdf
2022-04-12 11:12 - 2022-04-12 11:12 - 001421759 _____ C:\Users\AA583803\Downloads\combinepdf (54).pdf
2022-04-12 11:08 - 2022-04-12 11:08 - 000496756 _____ C:\Users\AA583803\Downloads\sheehan ohio national.pdf
2022-04-11 19:36 - 2022-04-11 19:36 - 000263606 _____ C:\Users\AA583803\Downloads\combinepdf (52).pdf
2022-04-11 19:35 - 2022-04-11 19:35 - 000052079 _____ C:\Users\AA583803\Downloads\ixa-053-m.pdf
2022-04-11 19:33 - 2022-04-11 19:33 - 000583207 _____ C:\Users\AA583803\Downloads\iva-009-protection.pdf
2022-04-11 19:31 - 2022-04-11 19:31 - 000834606 _____ C:\Users\AA583803\Downloads\iva-009-performance-3.pdf
2022-04-11 19:29 - 2022-04-11 19:29 - 000061703 _____ C:\Users\AA583803\Downloads\iva-009-performance-multi.pdf
2022-04-11 19:28 - 2022-04-11 19:28 - 000825560 _____ C:\Users\AA583803\Downloads\iva-009-performance-1.pdf
2022-04-11 19:25 - 2022-04-11 19:25 - 000805583 _____ C:\Users\AA583803\Downloads\iva-009-guard.pdf
2022-04-11 19:24 - 2022-04-11 19:24 - 000842073 _____ C:\Users\AA583803\Downloads\iva-009-precision.pdf
2022-04-11 19:22 - 2022-04-11 19:22 - 000204976 _____ C:\Users\AA583803\Downloads\Bundle.pdf
2022-04-11 19:13 - 2022-04-11 19:13 - 008962881 _____ C:\Users\AA583803\Downloads\ppt-302.pptx
2022-04-11 19:07 - 2022-04-11 19:07 - 000959830 _____ C:\Users\AA583803\Downloads\Archive (4).zip
2022-04-11 19:04 - 2022-04-11 19:04 - 001260775 _____ C:\Users\AA583803\Downloads\ixa-118.pdf
2022-04-11 19:02 - 2022-04-11 19:02 - 000045155 _____ C:\Users\AA583803\Downloads\ixa-178-6.pdf
2022-04-11 18:59 - 2022-04-11 18:59 - 000066267 _____ C:\Users\AA583803\Downloads\iva-026-3.pdf
2022-04-11 18:58 - 2022-04-11 18:58 - 000050297 _____ C:\Users\AA583803\Downloads\iva-026-6.pdf
2022-04-11 18:54 - 2022-04-11 18:54 - 000045993 _____ C:\Users\AA583803\Downloads\ixa-178-3.pdf
2022-04-11 18:23 - 2022-04-11 18:23 - 000559504 _____ C:\Users\AA583803\Downloads\iny-187 (1).pdf
2022-04-11 18:22 - 2022-04-11 18:22 - 000559504 _____ C:\Users\AA583803\Downloads\iny-187.pdf
2022-04-11 18:20 - 2022-04-11 18:20 - 000078076 _____ C:\Users\AA583803\Downloads\iva-009-lock.pdf
2022-04-11 18:16 - 2022-04-11 18:16 - 002293182 _____ C:\Users\AA583803\Downloads\ixa-013-perf.pdf
2022-04-11 18:16 - 2022-04-11 18:16 - 002289269 _____ C:\Users\AA583803\Downloads\Archive (3).zip
2022-04-11 18:15 - 2022-04-11 18:15 - 002289269 _____ C:\Users\AA583803\Downloads\Archive (2).zip
2022-04-11 18:13 - 2022-04-11 18:13 - 000101897 _____ C:\Users\AA583803\Downloads\Archive (1).zip
2022-04-11 18:09 - 2022-04-11 18:09 - 000121154 _____ C:\Users\AA583803\Downloads\ixa-014.pdf
2022-04-11 16:51 - 2022-04-11 16:51 - 000542597 _____ C:\Users\AA583803\Downloads\report_3584.pdf
2022-04-11 16:40 - 2022-04-11 16:40 - 001591847 _____ C:\Users\AA583803\Downloads\SCS PLUS 21 Cap Rate Flyer Series B - PreAnnounced (2).pdf
2022-04-11 16:37 - 2022-04-11 16:37 - 000140552 _____ C:\Users\AA583803\Downloads\ixa_012 (1).pdf
2022-04-11 16:02 - 2022-04-11 16:02 - 000601586 _____ C:\Users\AA583803\Downloads\flex-guard-comm-rates (3).pdf
2022-04-11 15:06 - 2022-04-11 15:06 - 000048675 _____ C:\Users\AA583803\Downloads\MML0018_AUTOMATED FUNDING REPORT.pdf
2022-04-11 11:15 - 2022-04-11 11:15 - 000026320 _____ C:\Users\AA583803\Downloads\Invoice INV-23240.pdf
2022-04-11 11:13 - 2022-04-11 11:13 - 001716147 _____ C:\Users\AA583803\Downloads\FBP503r3_41_ePay_for_Financial_Planning_Services_RS (3).pdf
2022-04-09 16:39 - 2022-04-09 16:39 - 001591847 _____ C:\Users\AA583803\Downloads\SCS PLUS 21 Cap Rate Flyer Series B - PreAnnounced (1).pdf
2022-04-09 09:54 - 2022-04-09 09:54 - 000008904 _____ C:\Users\AA583803\Downloads\360Export (9).xls
2022-04-09 09:47 - 2022-04-09 09:47 - 000005684 _____ C:\Users\AA583803\Downloads\360Export (8).xls
2022-04-09 09:37 - 2022-04-09 09:37 - 000012091 _____ C:\Users\AA583803\Downloads\360Export (7).xls.xlsx
2022-04-09 09:27 - 2022-04-09 09:27 - 000008231 _____ C:\Users\AA583803\Downloads\360Export (7).xls
2022-04-08 16:43 - 2022-04-08 16:43 - 000718689 _____ C:\Users\AA583803\Downloads\combinepdf (51).pdf
2022-04-08 15:26 - 2022-04-08 15:26 - 000032778 _____ C:\Users\AA583803\Downloads\jennings rack wait list receipt.pdf
2022-04-08 15:24 - 2022-04-08 15:24 - 000032488 _____ C:\Users\AA583803\Downloads\000702403 (3).pdf
2022-04-08 15:19 - 2022-04-08 15:19 - 000590252 _____ C:\Users\AA583803\Downloads\Please_Review_and_Sign_Application_Amendment.pdf
2022-04-08 14:02 - 2022-04-08 14:02 - 000032488 _____ C:\Users\AA583803\Downloads\000702403 (2).pdf
2022-04-08 13:59 - 2022-04-08 13:59 - 000264191 _____ C:\Users\AA583803\Downloads\AI01158316-Bill-361977459-04082022123635.pdf
2022-04-08 12:58 - 2022-04-08 12:58 - 000003304 _____ C:\Users\AA583803\Downloads\Mass Mutual _ Social Selling 101.ics
2022-04-08 09:48 - 2022-04-08 09:48 - 000017675 _____ C:\Users\AA583803\Downloads\wenke Performance_Attribution_Summary.pdf
2022-04-08 09:44 - 2022-04-08 09:44 - 000132368 _____ C:\Users\AA583803\Downloads\wenke OD portfolio.PDF
2022-04-07 17:16 - 2022-04-07 17:16 - 000361154 _____ C:\Users\AA583803\Downloads\AI01158316-Amendment-361965063.pdf
2022-04-07 17:16 - 2022-04-07 17:16 - 000252678 _____ C:\Users\AA583803\Downloads\Service Online 2020.pdf
2022-04-07 17:16 - 2022-04-07 17:16 - 000252678 _____ C:\Users\AA583803\Downloads\Service Online 2020 (1).pdf
2022-04-07 16:54 - 2022-04-07 16:54 - 000063232 _____ C:\Users\AA583803\Downloads\cobra.wageworks.com-Make a One-Time Premium Payment.pdf
2022-04-07 16:54 - 2022-04-07 16:54 - 000057943 _____ C:\Users\AA583803\Downloads\mybenefits.wageworks.com-Make a One-Time Premium Payment.pdf
2022-04-07 15:54 - 2022-04-07 15:54 - 000024512 _____ C:\Users\AA583803\Downloads\Performance_by_Security_2 (9).xls
2022-04-07 15:53 - 2022-04-07 15:53 - 000032704 _____ C:\Users\AA583803\Downloads\Performance_by_Security_2 (7).xls
2022-04-07 15:53 - 2022-04-07 15:53 - 000024512 _____ C:\Users\AA583803\Downloads\Performance_by_Security_2 (8).xls
2022-04-07 15:13 - 2022-04-07 15:13 - 002431808 _____ C:\Users\AA583803\Downloads\403018124_Application_Packet.pdf
2022-04-07 15:13 - 2022-04-07 15:13 - 002431808 _____ C:\Users\AA583803\Downloads\403018124_Application_Packet (1).pdf
2022-04-07 15:10 - 2022-04-07 15:10 - 002266524 _____ C:\Users\AA583803\Downloads\403018125_Application_Packet (1).pdf
2022-04-07 15:08 - 2022-04-07 15:08 - 002266524 _____ C:\Users\AA583803\Downloads\403018125_Application_Packet.pdf
2022-04-07 14:15 - 2022-04-07 14:15 - 000024512 _____ C:\Users\AA583803\Downloads\Performance_by_Security_2 (6).xls
2022-04-07 13:58 - 2022-04-07 13:58 - 000024512 _____ C:\Users\AA583803\Downloads\Performance_by_Security_2 (5).xls
2022-04-07 00:17 - 2022-04-07 00:17 - 000051712 _____ C:\Users\AA583803\Downloads\anand Performance_by_Security_2 (1).xls
2022-04-07 00:17 - 2022-04-07 00:17 - 000026383 _____ C:\Users\AA583803\Downloads\anand Performance_by_Security_2 (1).xlsx
2022-04-07 00:13 - 2022-04-07 00:13 - 000024512 _____ C:\Users\AA583803\Downloads\Purchase_and_Sales (1).xls
2022-04-07 00:08 - 2022-04-07 00:08 - 000024512 _____ C:\Users\AA583803\Downloads\Purchase_and_Sales.xls
2022-04-06 23:39 - 2022-04-06 23:39 - 000024512 _____ C:\Users\AA583803\Downloads\Performance_by_Security_2 (4).xls
2022-04-06 23:38 - 2022-04-06 23:38 - 000024512 _____ C:\Users\AA583803\Downloads\Performance_by_Security_2 (3).xls
2022-04-06 22:47 - 2022-04-06 22:47 - 000024512 _____ C:\Users\AA583803\Downloads\Performance_by_Security_2 (2).xls
2022-04-06 22:38 - 2022-04-06 22:38 - 000024512 _____ C:\Users\AA583803\Downloads\Performance_by_Security_2 (1).xls
2022-04-06 22:19 - 2022-04-06 22:19 - 000024512 _____ C:\Users\AA583803\Downloads\Portfolio_Holdings.xls
2022-04-06 21:56 - 2022-04-06 21:57 - 000155559 _____ C:\Users\AA583803\Downloads\Anand OD portfolio report.PDF
2022-04-06 17:53 - 2022-04-06 17:53 - 002579000 _____ C:\Users\AA583803\Downloads\400072643_Application_Packet (2).pdf
2022-04-06 17:33 - 2022-04-06 17:33 - 002579000 _____ C:\Users\AA583803\Downloads\400072643_Application_Packet (1).pdf
2022-04-06 17:26 - 2022-04-06 17:26 - 002579000 _____ C:\Users\AA583803\Downloads\400072643_Application_Packet.pdf
2022-04-06 16:20 - 2022-04-06 16:20 - 002993577 _____ C:\Users\AA583803\Downloads\cavaliere mass di.pdf
2022-04-06 11:16 - 2022-04-06 11:16 - 001716147 _____ C:\Users\AA583803\Downloads\FBP503r3_41_ePay_for_Financial_Planning_Services_RS (2).pdf
2022-04-05 14:29 - 2022-04-05 14:29 - 000157799 _____ C:\Users\AA583803\Downloads\sheehan portfolio report.PDF
2022-04-05 13:47 - 2022-04-05 14:30 - 000515617 _____ C:\Users\AA583803\Downloads\sheehan 2022 RMD.pdf
2022-04-05 13:41 - 2022-04-05 13:41 - 000000165 ____H C:\Users\AA583803\Downloads\~$MML0018_CVRMissingInformation.xlsx
2022-04-05 13:30 - 2022-04-05 13:30 - 000036295 _____ C:\Users\AA583803\Downloads\Jocie Consolidated_Statement.pdf
2022-04-05 12:50 - 2022-04-05 12:50 - 000057804 _____ C:\Users\AA583803\Downloads\offerreport (1).pdf
2022-04-05 11:51 - 2022-04-05 11:51 - 000058084 _____ C:\Users\AA583803\Downloads\offerreport.pdf
2022-04-05 11:12 - 2022-04-05 11:13 - 000103185 _____ C:\Users\AA583803\Downloads\knox muni details.pdf
2022-04-04 21:24 - 2022-04-04 21:24 - 000024512 _____ C:\Users\AA583803\Downloads\Performance_by_Security_2.xls
2022-04-04 20:43 - 2022-04-04 20:43 - 002980699 _____ C:\Users\AA583803\Downloads\1095-C Form 2021.pdf
2022-04-04 20:42 - 2022-04-04 20:42 - 000294844 _____ C:\Users\AA583803\Downloads\Tax Information - Documents - Nelnet (1).pdf
2022-04-04 20:42 - 2022-04-04 20:42 - 000003372 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1146508179-405363288-658039003-1003
2022-04-04 20:42 - 2022-04-04 20:42 - 000002388 _____ C:\Users\AA583803\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2022-04-04 20:41 - 2022-04-04 20:41 - 001639655 _____ C:\Users\AA583803\Downloads\W-2_Form_2021_Bernstein_2022_03_31_10_46_36_-0700_W-2_ESS (2).pdf
2022-04-04 20:41 - 2022-04-04 20:41 - 000196346 _____ C:\Users\AA583803\Downloads\0430114784 - Jenna Bernstein - MDBS Inc - 1099-NEC - TY2021 (1).pdf
2022-04-04 19:04 - 2022-04-04 19:04 - 001639655 _____ C:\Users\AA583803\Downloads\W-2_Form_2021_Bernstein_2022_03_31_10_46_36_-0700_W-2_ESS (1).pdf
2022-04-04 19:04 - 2022-04-04 19:04 - 000294844 _____ C:\Users\AA583803\Downloads\Tax Information - Documents - Nelnet.pdf
2022-04-04 18:51 - 2022-04-04 18:52 - 000012287 _____ C:\Users\AA583803\Downloads\balasu Change_in_Market_Value_Register (1).pdf
2022-04-04 18:49 - 2022-04-04 18:49 - 001639655 _____ C:\Users\AA583803\Downloads\W-2_Form_2021_Bernstein_2022_03_31_10_46_36_-0700_W-2_ESS.pdf
2022-04-04 18:48 - 2022-04-04 18:48 - 000196346 _____ C:\Users\AA583803\Downloads\0430114784 - Jenna Bernstein - MDBS Inc - 1099-NEC - TY2021.pdf
2022-04-04 14:49 - 2022-04-04 14:49 - 001700820 _____ C:\Users\AA583803\Downloads\combinepdf (50).pdf
2022-04-04 14:46 - 2022-04-04 14:46 - 000123238 _____ C:\Users\AA583803\Downloads\Polino SP500 Low volatility performance.pdf
2022-04-04 14:42 - 2022-04-04 14:42 - 000687066 _____ C:\Users\AA583803\Downloads\whitney FPAS.pdf
2022-04-04 14:40 - 2022-04-04 14:40 - 001262511 _____ C:\Users\AA583803\Downloads\Planning_Agreement_from_Joel_Bernstein____M.zip
2022-04-03 21:12 - 2022-04-04 14:50 - 000267610 _____ C:\Users\AA583803\Downloads\pollino Transaction_Activity.pdf
2022-04-03 20:57 - 2022-04-03 20:57 - 000011806 _____ C:\Users\AA583803\Downloads\TaxDocumentsView (10).pdf
2022-04-03 20:56 - 2022-04-03 20:56 - 000011980 _____ C:\Users\AA583803\Downloads\TaxDocumentsView (9).pdf
2022-04-03 20:54 - 2022-04-03 20:54 - 000011735 _____ C:\Users\AA583803\Downloads\TaxDocumentsView (7).pdf
2022-04-03 20:54 - 2022-04-03 20:54 - 000011727 _____ C:\Users\AA583803\Downloads\TaxDocumentsView (8).pdf
2022-04-03 20:52 - 2022-04-03 20:52 - 000011966 _____ C:\Users\AA583803\Downloads\TaxDocumentsView (6).pdf
2022-04-03 20:50 - 2022-04-03 20:50 - 000044937 _____ C:\Users\AA583803\Downloads\TaxDocumentsView (5).pdf
2022-04-03 20:48 - 2022-04-03 20:48 - 000051118 _____ C:\Users\AA583803\Downloads\TaxDocumentsView (4).pdf
2022-04-01 18:28 - 2022-04-01 18:28 - 001716147 _____ C:\Users\AA583803\Downloads\FBP503r3_41_ePay_for_Financial_Planning_Services_RS (1).pdf
2022-04-01 18:26 - 2022-04-01 18:26 - 000501273 _____ C:\Users\AA583803\Downloads\MyPDF (6).pdf
2022-04-01 18:24 - 2022-04-01 18:24 - 000167007 _____ C:\Users\AA583803\Downloads\MyPDF (5).pdf
2022-04-01 18:24 - 2022-04-01 18:24 - 000122036 _____ C:\Users\AA583803\Downloads\Form CRS.pdf
2022-04-01 18:12 - 2022-04-01 18:12 - 000503025 _____ C:\Users\AA583803\Downloads\A3MFBP100r2_21_Financial_Planning_Submission_and_Approval_Process_RS_V3 (2).pdf
2022-03-31 18:56 - 2022-03-31 18:57 - 000220160 _____ C:\Users\AA583803\Downloads\pollino low vol index performance.xls
2022-03-31 18:41 - 2022-03-31 18:41 - 004666543 _____ C:\Users\AA583803\Downloads\The Freedom Point eBook (1).pdf
2022-03-31 16:38 - 2022-03-31 16:38 - 001284805 _____ C:\Users\AA583803\Downloads\combinepdf (49).pdf
2022-03-31 15:25 - 2022-03-31 15:25 - 000234620 _____ C:\Users\AA583803\Downloads\EN-05-10026.pdf
2022-03-31 15:11 - 2022-03-31 15:11 - 004666543 _____ C:\Users\AA583803\Downloads\The Freedom Point eBook.pdf
2022-03-31 14:36 - 2022-04-13 14:03 - 000000000 ____D C:\Program Files\dotnet
2022-03-31 12:08 - 2022-03-31 12:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2022-03-31 11:53 - 2022-03-31 11:53 - 000002427 _____ C:\Users\AA583803\Downloads\MassMutual Academy_  Advanced Sales Forum.ics
2022-03-30 16:44 - 2022-03-30 16:44 - 000121760 _____ C:\Users\AA583803\Downloads\4751085107_PPP_Loan_Amount.pdf
2022-03-30 12:10 - 2022-03-30 12:10 - 000000940 _____ C:\Users\AA583803\Downloads\Introduction to Customized Portfolios.ics
2022-03-30 12:09 - 2022-03-30 12:09 - 000000000 ____D C:\WINDOWS\system32\Tasks\VMware
2022-03-30 00:10 - 2022-03-30 00:10 - 000000000 ____D C:\WINDOWS\system32\%programdata%
2022-03-29 23:57 - 2022-03-29 23:57 - 000000000 ____D C:\WINDOWS\SysWOW64\%programdata%
2022-03-29 23:57 - 2022-03-29 23:57 - 000000000 ____D C:\Users\AA583803\AppData\Local\VMware
2022-03-29 18:12 - 2022-03-29 18:12 - 001089837 _____ C:\Users\AA583803\Downloads\MML0018_2021_AdvisorTrust_Custodial_Restatement.pdf
2022-03-29 17:47 - 2022-03-29 17:47 - 004273923 _____ C:\Users\AA583803\Downloads\MML0018_Executed_Final_Plan_Document_Package.pdf
2022-03-29 15:46 - 2022-03-29 15:46 - 000012458 _____ C:\Users\AA583803\Downloads\MML0018_CVRMissingInformation (1).xlsx
2022-03-29 15:41 - 2022-03-29 15:41 - 000387072 _____ C:\Users\AA583803\Downloads\RE_ Reminder_ WSD Digital_ LLC 401(k) Plan - 2021 Year-End Employer Contribution    _ ref__00D306J2H__5005x1g7VOU_ref _.msg
2022-03-29 14:58 - 2022-03-29 14:58 - 002218318 _____ C:\Users\AA583803\Downloads\To Sell Is Human The Surprising Truth About Moving Others.pdf
2022-03-29 12:29 - 2022-03-29 12:29 - 000081401 _____ C:\Users\AA583803\Downloads\express-path-fluidless-underwriting-program-faqs_FINAL.docx.pdf
2022-03-28 16:41 - 2022-03-28 16:41 - 000163232 _____ C:\Users\AA583803\Downloads\Statement Dated 02_28_2022.pdf
2022-03-28 16:12 - 2022-03-28 16:12 - 000224455 _____ C:\Users\AA583803\Downloads\_V3_be_71_CLNT-be71b1d1-c643-4376-a93f-61ab024a3a68.pdf
2022-03-28 16:11 - 2022-03-28 16:11 - 000223045 _____ C:\Users\AA583803\Downloads\_V3_7f_72_CLNT-7f72c931-50a5-4748-b30c-7fbb0be30c86.pdf
2022-03-28 15:36 - 2022-03-28 15:36 - 000070873 _____ C:\Users\AA583803\Downloads\Catania Trust 1099.pdf
2022-03-28 15:36 - 2022-03-28 15:36 - 000067323 _____ C:\Users\AA583803\Downloads\TaxDocumentsView (3).pdf
2022-03-28 14:08 - 2022-03-28 14:08 - 000062025 _____ C:\Users\AA583803\Downloads\pollino Historical_Market_Value_with_Hypothetical_BM.pdf
2022-03-28 13:17 - 2022-03-31 18:55 - 000220160 _____ C:\Users\AA583803\Downloads\PerformanceGraphExport (1).xls
2022-03-28 13:16 - 2022-03-28 13:16 - 000178176 _____ C:\Users\AA583803\Downloads\PerformanceGraphExport.xls
2022-03-28 13:08 - 2022-03-28 13:08 - 000176480 _____ C:\Users\AA583803\Downloads\pollino lincoln summary.pdf
2022-03-28 13:06 - 2022-03-28 13:06 - 000106855 _____ C:\Users\AA583803\Downloads\pollino account summary.pdf
2022-03-28 12:55 - 2022-03-28 12:55 - 000071200 _____ C:\Users\AA583803\Downloads\1d784de2-445c-4927-99f7-6290c1aa2121.PDF
2022-03-27 22:47 - 2022-03-27 22:47 - 000296132 _____ C:\Users\AA583803\Downloads\19MPsful_015819609-20130417170605.pdf
2022-03-27 21:48 - 2022-03-27 21:48 - 000058250 _____ C:\Users\AA583803\Downloads\Coverpath Eligibility 1-7-22.pdf
2022-03-27 19:08 - 2022-03-27 19:08 - 000133992 _____ C:\Users\AA583803\Downloads\neiditz emails with CPA.pdf
2022-03-27 13:52 - 2022-03-27 13:52 - 000047600 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-stable.sys
2022-03-27 13:52 - 2022-03-27 13:52 - 000047600 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-dev.sys
2022-03-27 13:52 - 2022-03-27 13:52 - 000047600 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-canary.sys
2022-03-27 13:52 - 2022-03-27 13:52 - 000044328 _____ (Dropbox, Inc.) C:\WINDOWS\system32\DbxSvc.exe
2022-03-26 17:00 - 2022-03-26 17:00 - 000346901 _____ C:\Users\AA583803\Downloads\Neiditz_1099-B_Inventrust_IVT_817_shs_sold.pdf
2022-03-26 16:57 - 2022-03-26 16:57 - 000354792 _____ C:\Users\AA583803\Downloads\ViewDocument (2).pdf
2022-03-26 16:56 - 2022-03-26 16:56 - 000347673 _____ C:\Users\AA583803\Downloads\Neiditz_1099-B_Inventrust_IVT_585_shs_sold.pdf
2022-03-26 16:42 - 2022-03-26 16:42 - 000355564 _____ C:\Users\AA583803\Downloads\ViewDocument (1).pdf
2022-03-26 12:11 - 2022-03-26 12:11 - 000004562 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2022-03-26 12:11 - 2022-03-26 12:11 - 000002075 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat DC.lnk
2022-03-25 17:01 - 2022-03-25 17:01 - 000001175 _____ C:\Users\AA583803\Downloads\tab_account_modelexplorer_1795.csv
2022-03-25 16:38 - 2022-03-25 16:38 - 000561342 _____ C:\Users\AA583803\Downloads\2977f593-de9a-4754-bf52-86f0b1edcae7.pdf
2022-03-25 13:27 - 2022-03-25 13:27 - 000164547 _____ C:\Users\AA583803\Downloads\A_document_is_ready_for_your_electronic_signa.zip
2022-03-25 12:07 - 2022-03-25 12:07 - 000012458 _____ C:\Users\AA583803\Downloads\MML0018_CVRMissingInformation.xlsx
2022-03-25 11:30 - 2022-03-25 11:30 - 000445695 _____ C:\Users\AA583803\Downloads\economictimes.indiatimes.com-Tightening financial conditions sound alarm for world economy (1).pdf
2022-03-25 11:29 - 2022-03-25 11:29 - 000446514 _____ C:\Users\AA583803\Downloads\economictimes.indiatimes.com-Tightening financial conditions sound alarm for world economy.pdf
2022-03-24 18:38 - 2022-03-24 18:38 - 001692607 _____ C:\Users\AA583803\Downloads\Jun_30_2020_Statement.pdf
2022-03-24 18:32 - 2022-03-24 18:32 - 001696439 _____ C:\Users\AA583803\Downloads\Dec_31_2021_Statement.pdf
2022-03-24 17:37 - 2022-03-24 17:37 - 000532252 _____ C:\Users\AA583803\Downloads\report_4426.pdf
2022-03-24 17:36 - 2022-03-24 17:36 - 000529997 _____ C:\Users\AA583803\Downloads\report_2872.pdf
2022-03-24 17:25 - 2022-03-24 17:25 - 000071632 _____ C:\Users\AA583803\Downloads\Anand YTD Portfolio_Summary.pdf
2022-03-24 17:22 - 2022-03-24 17:23 - 000155005 _____ C:\Users\AA583803\Downloads\anand portfolio.PDF
2022-03-24 15:08 - 2022-03-24 15:08 - 000138951 _____ C:\Users\AA583803\Downloads\Ensight & Life Insurance Request Form.pdf
2022-03-24 14:49 - 2022-03-24 14:49 - 000001423 _____ C:\Users\AA583803\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Outlook.lnk
2022-03-24 13:01 - 2022-03-24 13:01 - 000157068 _____ C:\Users\AA583803\Downloads\Water-Line-General-Terms-Conditions.pdf
2022-03-23 15:39 - 2022-03-23 15:39 - 002814695 _____ C:\Users\AA583803\Downloads\etien 220323 DI reinstatement.pdf
2022-03-23 14:52 - 2022-03-23 14:53 - 000156284 _____ C:\Users\AA583803\Downloads\monthly market recap feb22.pdf
2022-03-23 14:49 - 2022-03-23 14:49 - 000809206 _____ C:\Users\AA583803\Downloads\wealth-mgt-update-031422.pdf
2022-03-23 14:08 - 2022-03-23 14:08 - 000219803 _____ C:\Users\AA583803\Downloads\combinepdf (48).pdf
2022-03-23 14:05 - 2022-03-23 14:05 - 001154610 _____ C:\Users\AA583803\Downloads\combinepdf (47).pdf
2022-03-23 14:05 - 2022-03-23 14:05 - 000574342 _____ C:\Users\AA583803\Downloads\report_3830.pdf
2022-03-23 14:04 - 2022-03-23 14:04 - 000577175 _____ C:\Users\AA583803\Downloads\report_5946.pdf
2022-03-23 13:53 - 2022-03-23 13:53 - 001074297 _____ C:\Users\AA583803\Downloads\combinepdf (46).pdf
2022-03-23 12:37 - 2022-03-23 12:37 - 000001324 _____ C:\Users\AA583803\Downloads\tab_account_modelexplorer_1482.csv
2022-03-23 10:46 - 2022-03-23 10:46 - 000000509 _____ C:\Users\AA583803\Downloads\event (1).ics
2022-03-22 16:36 - 2022-03-22 16:36 - 000044722 _____ C:\Users\AA583803\Downloads\Neiditz 1099-B.pdf
2022-03-22 15:48 - 2022-03-22 15:48 - 000527442 _____ C:\Users\AA583803\Downloads\report_5217.pdf
2022-03-22 15:44 - 2022-03-22 15:44 - 000010604 _____ C:\Users\AA583803\Downloads\warren Calendar_Market_Value_and_Performance.pdf
2022-03-22 15:39 - 2022-03-22 15:39 - 000062380 _____ C:\Users\AA583803\Downloads\warren port summary.PDF
2022-03-22 15:37 - 2022-03-22 15:37 - 000151694 _____ C:\Users\AA583803\Downloads\warren perf report.PDF
2022-03-22 13:33 - 2022-03-22 13:33 - 000546392 _____ C:\Users\AA583803\Downloads\report_1775.pdf
2022-03-22 13:29 - 2022-03-22 13:29 - 000544166 _____ C:\Users\AA583803\Downloads\report_7281.pdf
2022-03-22 13:16 - 2022-03-22 13:16 - 001984797 _____ C:\Users\AA583803\Downloads\di1075.pdf
2022-03-22 13:09 - 2022-03-22 13:09 - 000107520 _____ C:\Users\AA583803\Downloads\di7137 (4).xls
2022-03-22 12:10 - 2022-03-22 12:10 - 000545094 _____ C:\Users\AA583803\Downloads\report_2399.pdf
2022-03-22 11:54 - 2022-03-14 12:02 - 000384584 _____ (Google, Inc.) C:\WINDOWS\system32\Drivers\googledrivefs3758.sys
2022-03-22 09:11 - 2022-03-22 09:11 - 000045596 _____ C:\Users\AA583803\Downloads\HSA Transaction Confirmation $2000.pdf
2022-03-22 01:11 - 2022-04-06 10:58 - 000000000 ____D C:\Program Files\CrowdStrike
2022-03-21 18:44 - 2022-03-21 18:44 - 000141468 _____ C:\Users\AA583803\Downloads\PslfApplicationResults_02-18-2022.pdf
2022-03-21 18:41 - 2022-03-21 18:41 - 000133126 _____ C:\Users\AA583803\Downloads\PslfQualifyingPaymentUpdate_02-18-2022.pdf
2022-03-21 16:33 - 2022-03-21 16:33 - 001589578 _____ C:\Users\AA583803\Downloads\combinepdf (45).pdf
2022-03-18 16:34 - 2022-03-18 16:34 - 001511185 _____ C:\Users\AA583803\Downloads\combinepdf (44).pdf
2022-03-18 15:59 - 2022-03-18 15:59 - 001193560 _____ C:\Users\AA583803\Downloads\combinepdf (43).pdf
2022-03-18 15:58 - 2022-03-18 15:58 - 001193562 _____ C:\Users\AA583803\Downloads\combinepdf (42).pdf
2022-03-18 12:38 - 2022-03-18 12:38 - 000058166 _____ C:\Users\AA583803\Downloads\Bernstein Sales Proposal.pdf
2022-03-18 11:35 - 2022-03-18 11:35 - 000001265 _____ C:\Users\AA583803\Downloads\2022 MassMutual Academy Virtual March.ics
2022-03-17 16:28 - 2022-03-17 16:30 - 001331508 _____ C:\Users\AA583803\Downloads\cavaliere DI fact finder.pdf
2022-03-17 15:52 - 2022-03-17 15:52 - 001088224 _____ C:\Users\AA583803\Downloads\di90018.pdf
2022-03-17 14:38 - 2022-03-18 12:27 - 000148515 _____ C:\Users\AA583803\Downloads\mm academy schedule spring 2022.pdf
2022-03-16 18:03 - 2022-03-16 18:03 - 000001624 _____ C:\Users\AA583803\Downloads\reichman 401k transactions.csv
2022-03-16 17:59 - 2022-03-16 17:59 - 000003599 _____ C:\Users\AA583803\Downloads\InvestmentTransactions (3).csv
2022-03-16 14:26 - 2022-03-16 14:26 - 000240526 _____ C:\Users\AA583803\Downloads\CanNutritionValues_E (1).pdf
2022-03-16 14:20 - 2022-03-16 14:20 - 000240526 _____ C:\Users\AA583803\Downloads\CanNutritionValues_E.pdf
2022-03-16 11:30 - 2022-03-16 11:30 - 000153513 _____ C:\Users\AA583803\Downloads\Reichman OD report.PDF
2022-03-16 11:02 - 2022-03-16 11:02 - 000565919 _____ C:\Users\AA583803\Downloads\reichman presentation.pdf
2022-03-15 23:49 - 2022-03-15 23:49 - 001941738 _____ C:\Users\AA583803\Downloads\barn door track 3132194.pdf
2022-03-15 23:49 - 2022-03-15 23:49 - 000305354 _____ C:\Users\AA583803\Downloads\barn door pull 681 manual.pdf
2022-03-15 23:46 - 2022-03-15 23:46 - 000304324 _____ C:\Users\AA583803\Downloads\681 manual.pdf
2022-03-15 23:11 - 2022-03-15 23:11 - 001941722 _____ C:\Users\AA583803\Downloads\3132194.pdf
2022-03-15 13:36 - 2022-03-15 13:36 - 001073453 _____ C:\Users\AA583803\Downloads\combinepdf (41).pdf
2022-03-15 13:36 - 2022-03-15 13:36 - 001073453 _____ C:\Users\AA583803\Downloads\combinepdf (40).pdf
2022-03-15 13:35 - 2022-03-15 13:35 - 000098850 _____ C:\Users\AA583803\Downloads\metlife fax cover sheet.pdf
2022-03-15 13:32 - 2022-03-15 13:35 - 000108088 _____ C:\Users\AA583803\Downloads\metlife fax cover sheet.xlsx
2022-03-15 13:22 - 2022-03-15 13:22 - 000993676 _____ C:\Users\AA583803\Downloads\03152022131826-0001-pages-deleted.pdf
2022-03-15 13:21 - 2022-03-15 13:21 - 000998040 _____ C:\Users\AA583803\Downloads\03152022131826-0001.pdf
2022-03-15 11:25 - 2022-03-15 11:25 - 000130548 _____ C:\Users\AA583803\Downloads\Wenke Portfolio Report 03-14-22.PDF
2022-03-15 11:21 - 2022-03-15 11:21 - 000052144 _____ C:\Users\AA583803\Downloads\jbod1 Portfolio_Summary.pdf
2022-03-15 11:17 - 2022-03-15 11:18 - 000041685 _____ C:\Users\AA583803\Downloads\jbod2 Performance_Summary.pdf
2022-03-15 11:11 - 2022-03-15 11:11 - 000011706 _____ C:\Users\AA583803\Downloads\jbod4 Portfolio Holdings.pdf
2022-03-15 10:29 - 2022-03-15 10:29 - 000041408 _____ C:\Users\AA583803\Downloads\jbod3 Allocation and Holdings Summary.pdf
2022-03-15 09:59 - 2022-03-15 10:00 - 000068371 _____ C:\Users\AA583803\Downloads\qwnkw MyPDF (5).PDF
2022-03-14 17:55 - 2022-03-14 17:55 - 000316872 _____ C:\Users\AA583803\Downloads\2015-03-12.pdf
2022-03-14 17:23 - 2022-03-14 17:23 - 001416035 _____ C:\Users\AA583803\Downloads\2387cfe1-1f98-4baf-bc39-a67b698a9418.pdf
2022-03-14 15:10 - 2022-03-14 15:10 - 001321424 _____ C:\Users\AA583803\Downloads\IVT-Reallocations-2005-2021.pdf
2022-03-14 13:35 - 2022-03-14 13:35 - 000009168 _____ C:\Users\AA583803\Downloads\Copy of Cost Basis Spreadsheet Template.xlsx
 
==================== One month (modified) ==================
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2022-04-13 17:58 - 2019-12-07 05:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2022-04-13 17:52 - 2019-01-08 16:13 - 000000000 ____D C:\Program Files (x86)\Google
2022-04-13 17:42 - 2020-12-17 07:19 - 000000000 ____D C:\WINDOWS\system32\Drivers\CrowdStrike
2022-04-13 14:17 - 2019-12-07 05:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2022-04-13 14:08 - 2020-10-17 17:23 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2022-04-13 14:03 - 2019-01-10 01:08 - 000000000 ____D C:\ProgramData\Package Cache
2022-04-13 10:42 - 2019-12-07 05:13 - 000000000 ____D C:\WINDOWS\INF
2022-04-12 19:02 - 2019-01-08 13:12 - 000000000 ____D C:\Users\AA583803\AppData\Local\D3DSCache
2022-04-12 16:41 - 2019-12-07 05:14 - 000000000 ___HD C:\Program Files\WindowsApps
2022-04-12 16:41 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2022-04-12 16:23 - 2020-10-17 17:27 - 000842522 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2022-04-12 16:06 - 2021-03-11 15:37 - 000000000 ___RD C:\Users\AA583803\OneDrive - MassMutual
2022-04-12 16:02 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2022-04-12 16:00 - 2021-06-14 11:35 - 000000000 ____D C:\Users\AA583803\AppData\Local\Dropbox
2022-04-12 15:59 - 2021-03-12 13:34 - 000000000 ___RD C:\Users\AA583803\iCloudPhotos
2022-04-12 15:59 - 2020-10-17 17:24 - 000000000 ____D C:\Users\AA583803
2022-04-12 15:59 - 2020-08-20 12:05 - 000000000 ___RD C:\Users\AA583803\iCloudDrive
2022-04-12 15:59 - 2019-01-08 13:10 - 000000000 ___RD C:\Users\AA583803\OneDrive
2022-04-12 15:58 - 2022-02-08 07:12 - 000008192 ___SH C:\DumpStack.log.tmp
2022-04-12 15:58 - 2021-06-14 11:35 - 000000934 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job
2022-04-12 15:58 - 2021-06-14 11:35 - 000000930 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job
2022-04-12 15:58 - 2021-05-03 16:29 - 000000000 ____D C:\ProgramData\VMWOSQEXT
2022-04-12 15:58 - 2021-01-23 14:38 - 000000000 ____D C:\ProgramData\CrowdStrike
2022-04-12 15:58 - 2020-10-17 17:30 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2022-04-12 15:58 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\ServiceState
2022-04-12 15:58 - 2019-12-07 05:03 - 000016384 _____ C:\WINDOWS\system32\config\ELAM
2022-04-12 15:58 - 2019-01-08 13:10 - 000000000 __SHD C:\Users\AA583803\IntelGraphicsProfiles
2022-04-12 15:58 - 2018-12-17 21:38 - 000000000 ____D C:\Intel
2022-04-12 15:58 - 2018-07-25 09:07 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2022-04-12 11:57 - 2019-04-22 10:02 - 000000000 ____D C:\Users\AA583803\AppData\Roaming\Zoom Plugin
2022-04-12 11:44 - 2019-01-08 13:10 - 000000000 ____D C:\Users\AA583803\AppData\Local\Packages
2022-04-12 11:32 - 2020-06-18 00:53 - 000002440 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2022-04-07 01:35 - 2020-09-30 01:24 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
2022-04-06 15:18 - 2019-01-08 16:13 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2022-04-06 15:16 - 2021-09-21 11:21 - 000002076 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive.lnk
2022-04-06 15:16 - 2021-09-21 11:21 - 000001907 _____ C:\Users\Default\Desktop\Google Slides.lnk
2022-04-06 15:16 - 2021-09-21 11:21 - 000001907 _____ C:\Users\Default\Desktop\Google Sheets.lnk
2022-04-06 15:16 - 2021-09-21 11:21 - 000001895 _____ C:\Users\Default\Desktop\Google Docs.lnk
2022-04-06 10:58 - 2019-12-07 05:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2022-04-06 10:16 - 2020-10-18 14:55 - 000003386 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore1d6a4cc79b7edab
2022-04-06 10:16 - 2020-10-17 17:30 - 000003480 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2022-04-04 20:42 - 2021-12-11 16:47 - 000003584 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-1146508179-405363288-658039003-1003
2022-04-04 15:03 - 2021-12-21 19:42 - 000000000 ____D C:\ProgramData\CanonIJPLM
2022-04-01 18:26 - 2021-05-25 14:35 - 000491691 _____ C:\Users\AA583803\Downloads\Planning ADV.PDF
2022-03-31 12:09 - 2021-06-14 11:35 - 000000000 ____D C:\Program Files (x86)\Dropbox
2022-03-29 15:04 - 2021-07-15 11:01 - 000000000 ____D C:\Users\AA583803\OneDrive - MassMutual\Documents\My Kindle Content
2022-03-29 14:59 - 2021-07-15 11:00 - 000000000 ____D C:\Users\AA583803\AppData\Local\Amazon
2022-03-23 21:13 - 2020-09-30 01:24 - 000601432 _____ (Microsoft Corporation) C:\WINDOWS\system32\sedplugins.dll
2022-03-23 21:12 - 2020-09-30 01:24 - 000483664 _____ (Microsoft Corporation) C:\WINDOWS\system32\QualityUpdateAssistant.dll
 
==================== Files in the root of some directories ========
 
2020-03-17 19:33 - 2020-03-17 19:33 - 000022273 _____ () C:\Users\AA583803\AppData\Roaming\Comma Separated Values.ADR
 
==================== SigCheck ============================
 
(There is no automatic fix for files that do not pass verification.)
 

 

Log 2

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-04-2022 01
Ran by AA583803 (13-04-2022 18:10:47)
Running from C:\Users\AA583803\OneDrive - MassMutual\Desktop
Microsoft Windows 10 Pro Version 21H2 19044.1586 (X64) (2020-10-17 21:31:01)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
 
(If an entry is included in the fixlist, it will be removed.)
 
AA583803 (S-1-5-21-1146508179-405363288-658039003-1003 - Administrator - Enabled) => C:\Users\AA583803
Administrator (S-1-5-21-1146508179-405363288-658039003-500 - Administrator - Disabled)
ATS (S-1-5-21-1146508179-405363288-658039003-1004 - Administrator - Enabled)
DefaultAccount (S-1-5-21-1146508179-405363288-658039003-503 - Limited - Disabled)
Guest (S-1-5-21-1146508179-405363288-658039003-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-1146508179-405363288-658039003-504 - Limited - Disabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: CrowdStrike Falcon Sensor (Enabled - Up to date) {3D0E1D53-D039-A3B8-7762-303B3C8A5FC6}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: CrowdStrike Falcon Sensor (Enabled - Up to date) {90606BDC-9C7B-24DE-66D2-B63E0A9FC596}
AV: CrowdStrike Falcon Sensor (Enabled - Up to date) {8FE1C46C-23A5-1FF0-A73E-DAABB9E7B3CD}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: CrowdStrike Falcon Sensor (Enabled) {B7DA4549-69CA-1EA8-8C61-739E4734F4B6}
FW: CrowdStrike Falcon Sensor (Enabled) {05359C76-9A56-A2E0-5C3D-990EC25918BD}
FW: CrowdStrike Falcon Sensor (Enabled) {A85BEAF9-D614-2586-4D8D-1F0BF44C82ED}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
64 Bit HP CIO Components Installer (HKLM\...\{13DA9C7C-EBFB-40D0-94A1-55B42883DF21}) (Version: 21.2.1 - HP Inc.) Hidden
Ablebits Ultimate Suite for Microsoft Excel (HKLM-x32\...\{B5DB957E-E9E1-4FC3-A456-BA3D8BC5AF18}) (Version: 18.5.1788.8625 - Ablebits)
Adobe Acrobat DC (64-bit) (HKLM\...\{AC76BA86-1033-1033-7760-BC15014EA700}) (Version: 22.001.20085 - Adobe)
Adobe Digital Editions 4.5 (HKLM-x32\...\Adobe Digital Editions 4.5) (Version: 4.5.11 - Adobe Systems Incorporated)
Amazon Kindle (HKU\S-1-5-21-1146508179-405363288-658039003-1003\...\Amazon Kindle) (Version: 1.34.1.63103 - Amazon)
Canon Easy-WebPrint EX (HKLM-x32\...\Easy-WebPrint EX) (Version: 1.7.0.0 - Canon Inc.)
Canon IJ Network Scanner Selector EX (HKLM-x32\...\Canon_IJ_Network_Scanner_Selector_EX) (Version: 1.5.2.3 - Canon Inc.)
Canon IJ Network Scanner Selector EX2 (HKLM-x32\...\Canon_IJ_Network_Scanner_Selector_EX2) (Version: 2.0.15.2 - Canon Inc.)
Canon IJ Network Tool (HKLM-x32\...\Canon_IJ_Network_UTILITY) (Version: 3.5.0 - Canon Inc.)
Canon IJ Printer Assistant Tool (HKLM-x32\...\Canon IJ Printer Assistant Tool) (Version: 1.45.1.51 - Canon Inc.)
Canon IJ Scan Utility (HKLM-x32\...\Canon_IJ_Scan_Utility) (Version: 1.6.0.2 - Canon Inc.)
Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM-x32\...\CANONIJPLM100) (Version: 6.4.0 - Canon Inc.)
Canon My Image Garden (HKLM-x32\...\Canon My Image Garden) (Version: 3.6.1 - Canon Inc.)
Canon My Image Garden Design Files (HKLM-x32\...\Canon My Image Garden Design Files) (Version: 3.6.0 - Canon Inc.)
Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version: 3.3.0 - Canon Inc.)
Canon TR8600 series Driver (HKLM\...\{1199FAD5-9546-44F3-81CF-FFDB8040B7BF}_Canon_TR8600_series) (Version: 1.02 - Canon Inc.)
Cisco Webex Meetings (HKU\S-1-5-21-1146508179-405363288-658039003-1003\...\ActiveTouchMeetingClient) (Version: 41.6.7 - Cisco Webex LLC)
Crestron AirMedia (HKU\S-1-5-21-1146508179-405363288-658039003-1003\...\Airmedia) (Version: 3.2.1.16 - Crestron Electronics, Inc.)
CrowdStrike Device Control (HKLM\...\{A6EA9DFB-60D0-49BC-8EDF-8536C85D18A6}) (Version: 6.35.14960.0 - CrowdStrike, Inc.) Hidden
CrowdStrike Firmware Analysis (HKLM\...\{50908576-1AF3-495B-82CE-C390DE362701}) (Version: 6.32.14651.0 - CrowdStrike, Inc.) Hidden
CrowdStrike Sensor Platform (HKLM\...\{492E4904-2EEF-4C18-B835-41B8760A4E36}) (Version: 6.37.15103.0 - CrowdStrike, Inc.) Hidden
CrowdStrike Windows Sensor (HKLM-x32\...\{b1f3c507-e9ff-4702-b21c-eb90bd962324}) (Version: 6.37.15103.0 - CrowdStrike, Inc.)
Dell Active Pen Service (HKLM\...\ISD Tablet Driver) (Version: 7.6.1.9 - Wacom Technology Corp.)
Dell Command | Update for Windows Universal (HKLM\...\{4CCADC13-F3AE-454F-B724-33F6D4E52022}) (Version: 4.4.0 - Dell Inc.)
Dell SupportAssist (HKLM\...\{E0659C89-D276-4B77-A5EC-A8F2F042E78F}) (Version: 3.10.4.18 - Dell Inc.)
Dell SupportAssist OS Recovery Plugin for Dell Update (HKLM\...\{900D0BCD-0B86-4DAA-B639-89BE70449569}) (Version: 5.4.1.14954 - Dell Inc.) Hidden
Dell SupportAssist OS Recovery Plugin for Dell Update (HKLM-x32\...\{ec40a028-983b-4213-af2c-77ed6f6fe1d5}) (Version: 5.4.1.14954 - Dell Inc.)
Dell Touchpad (HKLM\...\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version: 10.3201.101.216 - ALPSALPINE CO., LTD.)
DreamPlan Home Design Software (HKLM-x32\...\DreamPlan) (Version: 6.78 - NCH Software)
Dropbox (HKLM-x32\...\Dropbox) (Version: 145.4.4921 - Dropbox, Inc.)
Dropbox Update Helper (HKLM-x32\...\{099218A5-A723-43DC-8DB5-6173656A1E94}) (Version: 1.3.583.1 - Dropbox, Inc.) Hidden
Edge Compatibility Site List (HKLM-x32\...\{53B2B431-5E5B-42B8-B1AF-761B389B5942}) (Version: 1.0 - MassMutual Financial Group)
Flexnet Setup (HKLM-x32\...\{B608EFA2-977B-4039-8C71-2DD823B058A6}) (Version: 1.00.0000 - MassMutual Financial Group)
FNCInstaller (HKLM-x32\...\{956BE19D-1540-4B0E-B3FA-855BD4AC0DC8}) (Version: 12.01.0000 - Flexera Software, Inc.) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 100.0.4896.75 - Google LLC)
Google Drive (HKLM\...\{6BBAE539-2232-434A-A4E5-9A33560C6283}) (Version: 56.0.11.0 - Google LLC)
GoTo Opener (HKLM-x32\...\{D144D2C2-4F96-48B7-BB2A-E9185050B619}) (Version: 1.0.491 - LogMeIn, Inc.)
GoToAssist Corporate (HKLM-x32\...\GoToAssist) (Version: 11.9.0.1280 - LogMeIn, Inc.)
GoToMeeting 10.18.0.19932 (HKU\S-1-5-21-1146508179-405363288-658039003-1003\...\GoToMeeting) (Version: 10.18.0.19932 - LogMeIn, Inc.)
iCloud Outlook (HKLM\...\{B87F5B14-C118-472C-93C9-05F35D0361DB}) (Version: 11.3.0.59 - Apple Inc.)
InstantStorm 2.0.1 (HKLM-x32\...\InstantStorm_is1) (Version: 2.0.1 - Jan Kolarik and Ondrej Vaverka)
Intel® Chipset Device Software (HKLM-x32\...\{4551f75f-3c54-4f09-8221-8c8a061bad00}) (Version: 10.1.18019.8144 - Intel® Corporation)
Intel® HID Event Filter (HKLM-x32\...\3FB06EEC-013D-4366-9918-71B97DFB84EB) (Version: 2.2.1.377 - Intel Corporation)
Intel® Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 2105.15.0.2157 - Intel Corporation)
Intel® Serial IO (HKLM\...\{9FD91C5C-44AE-4D9D-85BE-AE52816B0294}) (Version: 30.100.1943.2 - Intel Corporation)
Intel® Trusted Connect Service Client x86 (HKLM-x32\...\{C9552825-7BF2-4344-BA91-D3CD46F4C441}) (Version: 1.62.321.1 - Intel Corporation) Hidden
Intel® Trusted Connect Services Client (HKLM-x32\...\{c3964069-17c1-45dd-85a5-949576ceeaa3}) (Version: 1.62.321.1 - Intel Corporation) Hidden
Intel® Wireless Bluetooth® (HKLM-x32\...\{00000110-0210-1033-84C8-B8D95FA3C8C3}) (Version: 21.110.0.3 - Intel Corporation)
Intel® Integrated Sensor Solution (HKLM-x32\...\{98970ddc-844d-4ec3-b93e-52f5f693b305}) (Version: 3.10.100.3429 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\...\{86f7f90f-40a4-4cf2-b9dc-cfde74107a2f}) (Version: 21.20.1 - Intel Corporation)
Intel® Software Installer (HKLM-x32\...\{f5127890-fbaf-476e-821f-de116610484e}) (Version: 21.80.2.1 - Intel Corporation) Hidden
ISS_Drivers_x64 (HKLM\...\{9315B8DE-B183-4126-A69E-150B8ABF3690}) (Version: 3.10.100.3429 - Intel Corporation) Hidden
LastPass (HKLM-x32\...\{8A6242E7-4345-42F3-92D6-02C9E0B73250}) (Version: 4.89.0.2402 - LogMeIn)
Logitech Options (HKLM\...\LogiOptions) (Version: 7.10.3 - Logitech)
Maxx Audio Installer (x64) (HKLM\...\{307032B2-6AF2-46D7-B933-62438DEB2B9A}) (Version: 2.7.12560.1 - Waves Audio Ltd.) Hidden
Microsoft .NET Runtime - 5.0.16 (x64) (HKLM-x32\...\{68696b91-f423-4e8e-a58f-631366d0f77a}) (Version: 5.0.16.31117 - Microsoft Corporation)
Microsoft 365 Apps for enterprise - en-us (HKLM\...\O365ProPlusRetail - en-us) (Version: 16.0.14326.20910 - Microsoft Corporation)
Microsoft ASP.NET MVC 2 (HKLM-x32\...\{DD8FF2F3-0D97-4CF3-AF78-FA0E1B242244}) (Version: 2.0.60926.0 - Microsoft Corporation)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 100.0.1185.39 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 100.0.1185.36 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1146508179-405363288-658039003-1003\...\OneDriveSetup.exe) (Version: 22.055.0313.0001 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50918.0 - Microsoft Corporation)
Microsoft Teams (HKU\S-1-5-21-1146508179-405363288-658039003-1003\...\Teams) (Version: 1.5.00.4689 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{7B1FCD52-8F6B-4F12-A143-361EA39F5E7C}) (Version: 3.67.0.0 - Microsoft Corporation)
Microsoft Visual Basic PowerPacks 1.2 (HKLM-x32\...\{5169D2E2-0B94-3320-8C7A-718F92BE20CE}) (Version: 9.0.30729 - Microsoft)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x64) - 14.16.27033 (HKLM-x32\...\{cc3a7c63-31fb-4129-9024-63ebefd86a95}) (Version: 14.16.27033.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x86) - 14.16.27033 (HKLM-x32\...\{624ba875-fdfc-4efa-9c66-b170dfebc3ec}) (Version: 14.16.27033.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.60724 - Microsoft Corporation)
Microsoft WSE 3.0 (HKLM-x32\...\{EDEA8AB7-7683-4ED2-AA19-E6C078064C0D}) (Version: 3.0.5305.0 - Microsoft Corporation)
MM.Enterprise.WebServices Setup (HKLM-x32\...\{37D7831B-F91E-45EB-A733-25C993D1AD04}) (Version: 1.0.0 - MassMutual Financial Group)
Movavi Screen Recorder 21 (HKU\S-1-5-21-1146508179-405363288-658039003-1003\...\Movavi Screen Recorder 21) (Version: 21.0.0 - Movavi)
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.14326.20910 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.14326.20910 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.14326.20910 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0409-0000-0000000FF1CE}) (Version: 16.0.13801.20638 - Microsoft Corporation) Hidden
OptaneDowngradeGuard (HKLM\...\{86B0E6C1-32E0-42CC-BC4F-BF3C0730CECB}) (Version: 18.0.0.0 - Intel Corporation) Hidden
OutlookRegistryFix (HKLM-x32\...\{409932D6-5678-42AC-857A-9C42489E8DF1}) (Version: 1.00.0000 - {COMPANY_NAME} MassMutual)
Player Location Check (HKLM-x32\...\{F0753064-8D66-41A7-9F23-7691290387BF}) (Version: 3.1.1.3 - GeoComply)
Printer Registration (HKLM-x32\...\Canon EISRegistration) (Version: 1.8.0 - Canon Inc.)
Realtek Audio COM Components (HKLM-x32\...\{2355B503-9B11-4449-861D-1C1748B26320}) (Version: 1.0.2 - Realtek Semiconductor Corp.)
Realtek Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.9000.1 - Realtek Semiconductor Corp.)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.18362.31252 - Realtek Semiconductor Corp.)
RstDowngradeGuard (HKLM\...\{13C2A26E-7AD4-4D82-BB4F-DEA6E871B958}) (Version: 18.0.0.0 - Intel Corporation) Hidden
skiing (HKLM-x32\...\skiing_is1) (Version:  - )
Skype Meetings App (HKLM-x32\...\{56FC471B-6B4E-4CEF-AA29-D3F5D9387731}) (Version: 16.2.0.282 - Microsoft Corporation)
Teams Machine-Wide Installer (HKLM-x32\...\{39AF0813-FA7B-4860-ADBE-93B9B214B914}) (Version: 1.2.0.34161 - Microsoft Corporation)
Thunderbolt™ Software (HKLM-x32\...\{30F0067F-DD79-431B-BA5F-6CB4897785A5}) (Version: 17.4.79.510 - Intel Corporation)
TuneFab Screen Recorder 2.1.26 (HKLM-x32\...\{0AB6B9D1-ED73-491D-96DF-F7A8E80FF1A0}_is1) (Version: 2.1.26 - TuneFab Software Inc)
U3Launcher (HKLM-x32\...\{D8E363A7-88B7-446D-B2C0-E26CE4DC8E54}) (Version: 1.0.0 - U3)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{32DC821E-4A7D-4878-BEE8-337FA153D7F2}) (Version: 2.63.0.0 - Microsoft Corporation) Hidden
VMware SfdAgent (HKLM\...\{545571C3-8454-4002-914B-B411F82CCB76}) (Version: 21.05.11 - VMware) Hidden
Web Launch Recorder (HKU\S-1-5-21-1146508179-405363288-658039003-1003\...\WebLaunchRecorder) (Version: 2.0 - )
Windows PC Health Check (HKLM\...\{B1E7D0FD-7CFE-4E0C-A5DA-0F676499DB91}) (Version: 3.2.2110.14001 - Microsoft Corporation)
Workspace ONE Intelligent Hub Installer (HKLM-x32\...\{4B212D70-1501-6FA7-83EB-3DBAA27FC4BE}) (Version: 21.7.9.0 - VMware, Inc.)
Xerox Workplace Cloud Client (HKLM\...\{32F16584-856D-495B-BE83-EB06F5E039EA}) (Version: 5.4.99 - Xerox)
Zoom (HKU\S-1-5-21-1146508179-405363288-658039003-1003\...\ZoomUMX) (Version: 5.9.1 (2581) - Zoom Video Communications, Inc.)
Zoom Outlook Plugin (HKLM-x32\...\{FCF95040-F0A2-4EE7-BD9E-9407845F6636}) (Version: 4.8.13401 - Zoom)
 
Packages:
=========
Active Pen -> C:\Program Files\WindowsApps\WacomTechnologyCorp.DellActivePen_7.7.35.0_neutral__ss941bf8mfs8a [2021-08-10] (Wacom Technology Corp.)
Canon Inkjet Print Utility -> C:\Program Files\WindowsApps\34791E63.CanonInkjetPrintUtility_3.1.0.0_neutral__6e5tt8cgb93ep [2021-02-18] (Canon Inc.)
Dell Command | Update -> C:\Program Files\WindowsApps\DellInc.DellCommandUpdate_4.4.18.0_x86__htrsf667h5kn2 [2022-02-07] (Dell Inc)
Dell SupportAssist for Home PCs -> C:\Program Files\WindowsApps\DellInc.DellSupportAssistforPCs_3.10.7.0_x64__htrsf667h5kn2 [2022-02-08] (Dell Inc)
HEVC Video Extensions -> C:\Program Files\WindowsApps\Microsoft.HEVCVideoExtensions_1.0.50362.0_x64__8wekyb3d8bbwe [2022-03-01] (Microsoft Corporation)
HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_135.1.385.0_x64__v10z8vjag6ke6 [2022-03-21] (HP Inc.)
iCloud -> C:\Program Files\WindowsApps\AppleInc.iCloud_12.5.74.0_x86__nzyj5cx40ttqa [2021-11-30] (Apple Inc.) [Startup Task]
iCloud -> C:\Program Files\WindowsApps\AppleInc.iCloud_13.0.201.0_x86__nzyj5cx40ttqa [2022-02-04] (Apple Inc.) [Startup Task]
Intel® Optane™ Memory and Storage Management -> C:\Program Files\WindowsApps\AppUp.IntelOptaneMemoryandStorageManagement_18.1.1026.0_x64__8j3eq9eme6ctt [2022-04-01] (INTEL CORP)
iTunes -> C:\Program Files\WindowsApps\AppleInc.iTunes_12123.5.56009.0_x64__nzyj5cx40ttqa [2022-03-11] (Apple Inc.) [Startup Task]
LastPass: Free Password Manager -> C:\Program Files\WindowsApps\LastPass.LastPassFreePasswordManager_4.69.0.0_neutral__qq0fmhteeht3j [2021-04-10] (LastPass)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-01-22] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-01-22] (Microsoft Corporation) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.12.3171.0_x64__8wekyb3d8bbwe [2022-03-26] (Microsoft Studios) [MS Ad]
Microsoft Whiteboard -> C:\Program Files\WindowsApps\Microsoft.Whiteboard_52.10404.374.0_x64__8wekyb3d8bbwe [2022-04-06] (Microsoft Corporation)
Photos Add-on -> C:\Program Files\WindowsApps\Microsoft.Windows.Photos.DLC.Main_2021.39122.10110.0_x64__8wekyb3d8bbwe [2021-03-12] (Microsoft Corporation)
Photos Media Engine Add-on -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2019-12-11] (Microsoft Corporation)
Workspace ONE Intelligent Hub -> C:\Program Files\WindowsApps\AirWatchLLC.WorkspaceONEIntelligentHub_21.7.9.0_x86__htcwkw4rx2gx4 [2022-03-29] (VMware)
 
==================== Custom CLSID (Whitelisted): ==============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-1146508179-405363288-658039003-1003_Classes\CLSID\{01D049A1-C5A8-343F-8E51-90B16CEB68A0}\InprocServer32 -> C:\Users\AA583803\AppData\Local\Ablebits\Ultimate Suite for Microsoft Excel\1D4C31B65E64C28\AblebitsUltimateSuite.DLL (4Bits Ltd. -> Ablebits)
CustomCLSID: HKU\S-1-5-21-1146508179-405363288-658039003-1003_Classes\CLSID\{04271989-C4D2-FCD0-CDCF-C126DA82EE4B} -> [OneDrive - MassMutual] => C:\Users\AA583803\OneDrive - MassMutual [2021-03-11 15:37]
CustomCLSID: HKU\S-1-5-21-1146508179-405363288-658039003-1003_Classes\CLSID\{0736E843-6185-3363-92F9-385B51434E68}\InprocServer32 -> C:\Users\AA583803\AppData\Local\Ablebits\Ultimate Suite for Microsoft Excel\1D4C31B65E64C28\AblebitsUltimateSuite.DLL (4Bits Ltd. -> Ablebits)
CustomCLSID: HKU\S-1-5-21-1146508179-405363288-658039003-1003_Classes\CLSID\{078D8098-6D64-45F1-BE1A-3C6E66335A38} -> [iCloud Photos] => C:\Users\AA583803\Pictures\iCloud Photos\Photos [2020-08-20 12:03]
CustomCLSID: HKU\S-1-5-21-1146508179-405363288-658039003-1003_Classes\CLSID\{0B026475-E01D-314C-B973-9CE3801BA0F4}\InprocServer32 -> C:\Users\AA583803\AppData\Local\Ablebits\Ultimate Suite for Microsoft Excel\1D4C31B65E64C28\AblebitsUltimateSuite.DLL (4Bits Ltd. -> Ablebits)
CustomCLSID: HKU\S-1-5-21-1146508179-405363288-658039003-1003_Classes\CLSID\{1019ADC7-17CB-4489-AFD5-6642C7400ACE}\localserver32 -> C:\Users\AA583803\AppData\Local\Webex\Webex\Applications\ptOIEx64.exe (Cisco WebEx LLC -> Cisco WebEx LLC)
CustomCLSID: HKU\S-1-5-21-1146508179-405363288-658039003-1003_Classes\CLSID\{11340409-D9B9-3E95-A44E-457BC334175D}\InprocServer32 -> C:\Users\AA583803\AppData\Local\Ablebits\Ultimate Suite for Microsoft Excel\1D4C31B65E64C28\AblebitsUltimateSuite.DLL (4Bits Ltd. -> Ablebits)
CustomCLSID: HKU\S-1-5-21-1146508179-405363288-658039003-1003_Classes\CLSID\{14068B5A-A762-3E2A-AD9C-5007FFA7C8B8}\InprocServer32 -> C:\Users\AA583803\AppData\Local\Ablebits\Ultimate Suite for Microsoft Excel\1D4C31B65E64C28\AblebitsUltimateSuite.DLL (4Bits Ltd. -> Ablebits)
CustomCLSID: HKU\S-1-5-21-1146508179-405363288-658039003-1003_Classes\CLSID\{18DEA14E-6C68-4C17-9824-A37B359C6E35} -> [iCloud Drive] => C:\Users\AA583803\iCloudDrive [2020-08-20 12:05]
CustomCLSID: HKU\S-1-5-21-1146508179-405363288-658039003-1003_Classes\CLSID\{19A6E644-14E6-4A60-B8D7-DD20610A871D}\InprocServer32 -> C:\Users\AA583803\AppData\Local\Microsoft\TeamsMeetingAddin\1.0.21348.1\x64\Microsoft.Teams.AddinLoader.dll (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1146508179-405363288-658039003-1003_Classes\CLSID\{1B04E5D0-8BF7-385E-B7EF-A75C960D9226}\InprocServer32 -> C:\Users\AA583803\AppData\Local\Ablebits\Ultimate Suite for Microsoft Excel\1D4C31B65E64C28\AblebitsUltimateSuite.DLL (4Bits Ltd. -> Ablebits)
CustomCLSID: HKU\S-1-5-21-1146508179-405363288-658039003-1003_Classes\CLSID\{1CD65DD7-0514-3845-B0EB-94C5ED3E08D9}\InprocServer32 -> C:\Users\AA583803\AppData\Local\Ablebits\Ultimate Suite for Microsoft Excel\1D4C31B65E64C28\AblebitsUltimateSuite.DLL (4Bits Ltd. -> Ablebits)
CustomCLSID: HKU\S-1-5-21-1146508179-405363288-658039003-1003_Classes\CLSID\{1D2AB166-4AB6-338E-BF89-8248BB48BC4B}\InprocServer32 -> C:\Users\AA583803\AppData\Local\Ablebits\Ultimate Suite for Microsoft Excel\1D4C31B65E64C28\AblebitsUltimateSuite.DLL (4Bits Ltd. -> Ablebits)
CustomCLSID: HKU\S-1-5-21-1146508179-405363288-658039003-1003_Classes\CLSID\{23423CAF-1507-3656-91CD-CDC6A57290A2}\InprocServer32 -> C:\Users\AA583803\AppData\Local\Ablebits\Ultimate Suite for Microsoft Excel\1D4C31B65E64C28\AblebitsUltimateSuite.DLL (4Bits Ltd. -> Ablebits)
CustomCLSID: HKU\S-1-5-21-1146508179-405363288-658039003-1003_Classes\CLSID\{2DC5EF7E-1EE0-3443-BC65-4C82DF8DCF96}\InprocServer32 -> C:\Users\AA583803\AppData\Local\Ablebits\Ultimate Suite for Microsoft Excel\1D4C31B65E64C28\AblebitsUltimateSuite.DLL (4Bits Ltd. -> Ablebits)
CustomCLSID: HKU\S-1-5-21-1146508179-405363288-658039003-1003_Classes\CLSID\{3D617CE6-C7CF-4B1D-86B4-BF8C8C530210}\InprocServer32 -> C:\Users\AA583803\AppData\Local\Ablebits\Ultimate Suite for Microsoft Excel\1D4C31B65E64C28\adxloader64.dll (4Bits Ltd. -> Ablebits)
CustomCLSID: HKU\S-1-5-21-1146508179-405363288-658039003-1003_Classes\CLSID\{3E3AD4BD-346A-460A-80E8-90699B75C00B}\InprocServer32 -> C:\Users\AA583803\AppData\Local\Microsoft\SkypeForBusinessPlugin\16.2.0.282\GatewayActiveX-x64.dll (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1146508179-405363288-658039003-1003_Classes\CLSID\{444F60B6-5B6D-3561-AD80-88A0585A2701}\InprocServer32 -> C:\Users\AA583803\AppData\Local\Ablebits\Ultimate Suite for Microsoft Excel\1D4C31B65E64C28\AblebitsUltimateSuite.DLL (4Bits Ltd. -> Ablebits)
CustomCLSID: HKU\S-1-5-21-1146508179-405363288-658039003-1003_Classes\CLSID\{4D2F086C-6EA3-101B-A18A-00AA00446E07}\InprocServer32 -> C:\WINDOWS\system32\mapi32.dll (Microsoft Windows -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1146508179-405363288-658039003-1003_Classes\CLSID\{4E876FFE-9320-326A-84D0-DE7E7D4F5FDC}\InprocServer32 -> C:\Users\AA583803\AppData\Local\Ablebits\Ultimate Suite for Microsoft Excel\1D4C31B65E64C28\AblebitsUltimateSuite.DLL (4Bits Ltd. -> Ablebits)
CustomCLSID: HKU\S-1-5-21-1146508179-405363288-658039003-1003_Classes\CLSID\{50ECC686-8E78-3BAE-A310-A9407B9D04DD}\InprocServer32 -> C:\Users\AA583803\AppData\Local\Ablebits\Ultimate Suite for Microsoft Excel\1D4C31B65E64C28\AblebitsUltimateSuite.DLL (4Bits Ltd. -> Ablebits)
CustomCLSID: HKU\S-1-5-21-1146508179-405363288-658039003-1003_Classes\CLSID\{5590759E-A52F-35C5-9FF6-435B4355B1F0}\InprocServer32 -> C:\Users\AA583803\AppData\Local\Ablebits\Ultimate Suite for Microsoft Excel\1D4C31B65E64C28\AblebitsUltimateSuite.DLL (4Bits Ltd. -> Ablebits)
CustomCLSID: HKU\S-1-5-21-1146508179-405363288-658039003-1003_Classes\CLSID\{5D70F043-465B-31B3-AF67-6B7BE85178C7}\InprocServer32 -> C:\Users\AA583803\AppData\Local\Ablebits\Ultimate Suite for Microsoft Excel\1D4C31B65E64C28\AblebitsUltimateSuite.DLL (4Bits Ltd. -> Ablebits)
CustomCLSID: HKU\S-1-5-21-1146508179-405363288-658039003-1003_Classes\CLSID\{5E4BA212-6EC5-3E7C-B42A-9D9B8E6A1CD3}\InprocServer32 -> C:\Users\AA583803\AppData\Local\Ablebits\Ultimate Suite for Microsoft Excel\1D4C31B65E64C28\AblebitsUltimateSuite.DLL (4Bits Ltd. -> Ablebits)
CustomCLSID: HKU\S-1-5-21-1146508179-405363288-658039003-1003_Classes\CLSID\{6721DB0F-CE28-3B02-AA8A-4C04FDD53202}\InprocServer32 -> C:\Users\AA583803\AppData\Local\Ablebits\Ultimate Suite for Microsoft Excel\1D4C31B65E64C28\AblebitsUltimateSuite.DLL (4Bits Ltd. -> Ablebits)
CustomCLSID: HKU\S-1-5-21-1146508179-405363288-658039003-1003_Classes\CLSID\{6A0EE0C2-F247-3D24-B787-3003842F06CA}\InprocServer32 -> C:\Users\AA583803\AppData\Local\Ablebits\Ultimate Suite for Microsoft Excel\1D4C31B65E64C28\AblebitsUltimateSuite.DLL (4Bits Ltd. -> Ablebits)
 

    Advertisements

Register to Remove


#2 Juliet

Juliet

    SuperHelper

  • Retired Classroom Teacher
  • 7,686 posts
  • Interests:Boo!....
  • MVP

Posted 15 April 2022 - 04:21 PM

Hi and welcome
 
When Farbar Recovery tool ran did it also produce an Addition.txt    I need to see this.
So far from what you've posted are a few items that could be tidied up.

Also, have you tried to update, or check for updates on Google Chrome?


Sometimes the angels fly close enough to you that you can hear the flutter of their wings...


MS - MVP Consumer Security 2009 - 2016, WI-MVP 2016-17
Antivirus Scanners Online Scanners Firewalls Slow Computer??

#3 Juliet

Juliet

    SuperHelper

  • Retired Classroom Teacher
  • 7,686 posts
  • Interests:Boo!....
  • MVP

Posted 16 April 2022 - 07:15 AM

The Addition.txt was not in it's entirety but, we can run a couple of quick scans to see what's going on,
You may need to disable your computer antivirus in order to download and run uninterrupted.

Malwarebytes AdwCleaner

-------------------
  • Please download AdwCleaner and save it to your Desktop
  • Close all open programs and browsers
  • Right click on the icon and select Run as administrator
  • Click Scan now
  • Allow the program to Quarantine what it finds except for Pre-installed applications if you would like to keep those or other entries you would like to keep
  • When completed click View Scan Log File
  • Copy and paste the contents in your reply
  • Click Skip Basic Repair if it appears then close the program
===================================================

Run Malwarebytes Anti-Malware

You may have Malwarebytes Anti-Malware installed but if not, you can download it from here:
  • run the program
  • click on the Dashboard to make sure everything is up to date, (it is not necessary to upgrade to the premium version of MBAM)
  • click on the Scan tab, (directly below the Dashboard tab)
  • select the Threat Scan option
  • slick the Scan Now button
  • Threat Scan will begin
  • when the scan has completed and if malware was found, click the Quarantine Selected button to allow MBAM to quarantine what was found
  • if prompted to restart the computer, close all other programs and click Yes to restart your computer
  • once you are back at your desktop, open MBAM once more
  • click on the Reports tab
  • double-click on the most recent Scan Report
  • click on Export, then Copy to Clipboard
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~`

Please post these 2 logs when finished.
Sometimes the angels fly close enough to you that you can hear the flutter of their wings...


MS - MVP Consumer Security 2009 - 2016, WI-MVP 2016-17
Antivirus Scanners Online Scanners Firewalls Slow Computer??

#4 rockaway1

rockaway1

    Authentic Member

  • Authentic Member
  • PipPip
  • 35 posts

Posted 17 April 2022 - 05:13 PM

This is the Addition.txt log

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-04-2022 01

Ran by AA583803 (13-04-2022 18:10:47)
Running from C:\Users\AA583803\OneDrive - MassMutual\Desktop
Microsoft Windows 10 Pro Version 21H2 19044.1586 (X64) (2020-10-17 21:31:01)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
 
(If an entry is included in the fixlist, it will be removed.)
 
AA583803 (S-1-5-21-1146508179-405363288-658039003-1003 - Administrator - Enabled) => C:\Users\AA583803
Administrator (S-1-5-21-1146508179-405363288-658039003-500 - Administrator - Disabled)
ATS (S-1-5-21-1146508179-405363288-658039003-1004 - Administrator - Enabled)
DefaultAccount (S-1-5-21-1146508179-405363288-658039003-503 - Limited - Disabled)
Guest (S-1-5-21-1146508179-405363288-658039003-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-1146508179-405363288-658039003-504 - Limited - Disabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: CrowdStrike Falcon Sensor (Enabled - Up to date) {3D0E1D53-D039-A3B8-7762-303B3C8A5FC6}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: CrowdStrike Falcon Sensor (Enabled - Up to date) {90606BDC-9C7B-24DE-66D2-B63E0A9FC596}
AV: CrowdStrike Falcon Sensor (Enabled - Up to date) {8FE1C46C-23A5-1FF0-A73E-DAABB9E7B3CD}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: CrowdStrike Falcon Sensor (Enabled) {B7DA4549-69CA-1EA8-8C61-739E4734F4B6}
FW: CrowdStrike Falcon Sensor (Enabled) {05359C76-9A56-A2E0-5C3D-990EC25918BD}
FW: CrowdStrike Falcon Sensor (Enabled) {A85BEAF9-D614-2586-4D8D-1F0BF44C82ED}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
64 Bit HP CIO Components Installer (HKLM\...\{13DA9C7C-EBFB-40D0-94A1-55B42883DF21}) (Version: 21.2.1 - HP Inc.) Hidden
Ablebits Ultimate Suite for Microsoft Excel (HKLM-x32\...\{B5DB957E-E9E1-4FC3-A456-BA3D8BC5AF18}) (Version: 18.5.1788.8625 - Ablebits)
Adobe Acrobat DC (64-bit) (HKLM\...\{AC76BA86-1033-1033-7760-BC15014EA700}) (Version: 22.001.20085 - Adobe)
Adobe Digital Editions 4.5 (HKLM-x32\...\Adobe Digital Editions 4.5) (Version: 4.5.11 - Adobe Systems Incorporated)
Amazon Kindle (HKU\S-1-5-21-1146508179-405363288-658039003-1003\...\Amazon Kindle) (Version: 1.34.1.63103 - Amazon)
Canon Easy-WebPrint EX (HKLM-x32\...\Easy-WebPrint EX) (Version: 1.7.0.0 - Canon Inc.)
Canon IJ Network Scanner Selector EX (HKLM-x32\...\Canon_IJ_Network_Scanner_Selector_EX) (Version: 1.5.2.3 - Canon Inc.)
Canon IJ Network Scanner Selector EX2 (HKLM-x32\...\Canon_IJ_Network_Scanner_Selector_EX2) (Version: 2.0.15.2 - Canon Inc.)
Canon IJ Network Tool (HKLM-x32\...\Canon_IJ_Network_UTILITY) (Version: 3.5.0 - Canon Inc.)
Canon IJ Printer Assistant Tool (HKLM-x32\...\Canon IJ Printer Assistant Tool) (Version: 1.45.1.51 - Canon Inc.)
Canon IJ Scan Utility (HKLM-x32\...\Canon_IJ_Scan_Utility) (Version: 1.6.0.2 - Canon Inc.)
Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM-x32\...\CANONIJPLM100) (Version: 6.4.0 - Canon Inc.)
Canon My Image Garden (HKLM-x32\...\Canon My Image Garden) (Version: 3.6.1 - Canon Inc.)
Canon My Image Garden Design Files (HKLM-x32\...\Canon My Image Garden Design Files) (Version: 3.6.0 - Canon Inc.)
Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version: 3.3.0 - Canon Inc.)
Canon TR8600 series Driver (HKLM\...\{1199FAD5-9546-44F3-81CF-FFDB8040B7BF}_Canon_TR8600_series) (Version: 1.02 - Canon Inc.)
Cisco Webex Meetings (HKU\S-1-5-21-1146508179-405363288-658039003-1003\...\ActiveTouchMeetingClient) (Version: 41.6.7 - Cisco Webex LLC)
Crestron AirMedia (HKU\S-1-5-21-1146508179-405363288-658039003-1003\...\Airmedia) (Version: 3.2.1.16 - Crestron Electronics, Inc.)
CrowdStrike Device Control (HKLM\...\{A6EA9DFB-60D0-49BC-8EDF-8536C85D18A6}) (Version: 6.35.14960.0 - CrowdStrike, Inc.) Hidden
CrowdStrike Firmware Analysis (HKLM\...\{50908576-1AF3-495B-82CE-C390DE362701}) (Version: 6.32.14651.0 - CrowdStrike, Inc.) Hidden
CrowdStrike Sensor Platform (HKLM\...\{492E4904-2EEF-4C18-B835-41B8760A4E36}) (Version: 6.37.15103.0 - CrowdStrike, Inc.) Hidden
CrowdStrike Windows Sensor (HKLM-x32\...\{b1f3c507-e9ff-4702-b21c-eb90bd962324}) (Version: 6.37.15103.0 - CrowdStrike, Inc.)
Dell Active Pen Service (HKLM\...\ISD Tablet Driver) (Version: 7.6.1.9 - Wacom Technology Corp.)
Dell Command | Update for Windows Universal (HKLM\...\{4CCADC13-F3AE-454F-B724-33F6D4E52022}) (Version: 4.4.0 - Dell Inc.)
Dell SupportAssist (HKLM\...\{E0659C89-D276-4B77-A5EC-A8F2F042E78F}) (Version: 3.10.4.18 - Dell Inc.)
Dell SupportAssist OS Recovery Plugin for Dell Update (HKLM\...\{900D0BCD-0B86-4DAA-B639-89BE70449569}) (Version: 5.4.1.14954 - Dell Inc.) Hidden
Dell SupportAssist OS Recovery Plugin for Dell Update (HKLM-x32\...\{ec40a028-983b-4213-af2c-77ed6f6fe1d5}) (Version: 5.4.1.14954 - Dell Inc.)
Dell Touchpad (HKLM\...\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version: 10.3201.101.216 - ALPSALPINE CO., LTD.)
DreamPlan Home Design Software (HKLM-x32\...\DreamPlan) (Version: 6.78 - NCH Software)
Dropbox (HKLM-x32\...\Dropbox) (Version: 145.4.4921 - Dropbox, Inc.)
Dropbox Update Helper (HKLM-x32\...\{099218A5-A723-43DC-8DB5-6173656A1E94}) (Version: 1.3.583.1 - Dropbox, Inc.) Hidden
Edge Compatibility Site List (HKLM-x32\...\{53B2B431-5E5B-42B8-B1AF-761B389B5942}) (Version: 1.0 - MassMutual Financial Group)
Flexnet Setup (HKLM-x32\...\{B608EFA2-977B-4039-8C71-2DD823B058A6}) (Version: 1.00.0000 - MassMutual Financial Group)
FNCInstaller (HKLM-x32\...\{956BE19D-1540-4B0E-B3FA-855BD4AC0DC8}) (Version: 12.01.0000 - Flexera Software, Inc.) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 100.0.4896.75 - Google LLC)
Google Drive (HKLM\...\{6BBAE539-2232-434A-A4E5-9A33560C6283}) (Version: 56.0.11.0 - Google LLC)
GoTo Opener (HKLM-x32\...\{D144D2C2-4F96-48B7-BB2A-E9185050B619}) (Version: 1.0.491 - LogMeIn, Inc.)
GoToAssist Corporate (HKLM-x32\...\GoToAssist) (Version: 11.9.0.1280 - LogMeIn, Inc.)
GoToMeeting 10.18.0.19932 (HKU\S-1-5-21-1146508179-405363288-658039003-1003\...\GoToMeeting) (Version: 10.18.0.19932 - LogMeIn, Inc.)
iCloud Outlook (HKLM\...\{B87F5B14-C118-472C-93C9-05F35D0361DB}) (Version: 11.3.0.59 - Apple Inc.)
InstantStorm 2.0.1 (HKLM-x32\...\InstantStorm_is1) (Version: 2.0.1 - Jan Kolarik and Ondrej Vaverka)
Intel® Chipset Device Software (HKLM-x32\...\{4551f75f-3c54-4f09-8221-8c8a061bad00}) (Version: 10.1.18019.8144 - Intel® Corporation)
Intel® HID Event Filter (HKLM-x32\...\3FB06EEC-013D-4366-9918-71B97DFB84EB) (Version: 2.2.1.377 - Intel Corporation)
Intel® Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 2105.15.0.2157 - Intel Corporation)
Intel® Serial IO (HKLM\...\{9FD91C5C-44AE-4D9D-85BE-AE52816B0294}) (Version: 30.100.1943.2 - Intel Corporation)
Intel® Trusted Connect Service Client x86 (HKLM-x32\...\{C9552825-7BF2-4344-BA91-D3CD46F4C441}) (Version: 1.62.321.1 - Intel Corporation) Hidden
Intel® Trusted Connect Services Client (HKLM-x32\...\{c3964069-17c1-45dd-85a5-949576ceeaa3}) (Version: 1.62.321.1 - Intel Corporation) Hidden
Intel® Wireless Bluetooth® (HKLM-x32\...\{00000110-0210-1033-84C8-B8D95FA3C8C3}) (Version: 21.110.0.3 - Intel Corporation)
Intel® Integrated Sensor Solution (HKLM-x32\...\{98970ddc-844d-4ec3-b93e-52f5f693b305}) (Version: 3.10.100.3429 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\...\{86f7f90f-40a4-4cf2-b9dc-cfde74107a2f}) (Version: 21.20.1 - Intel Corporation)
Intel® Software Installer (HKLM-x32\...\{f5127890-fbaf-476e-821f-de116610484e}) (Version: 21.80.2.1 - Intel Corporation) Hidden
ISS_Drivers_x64 (HKLM\...\{9315B8DE-B183-4126-A69E-150B8ABF3690}) (Version: 3.10.100.3429 - Intel Corporation) Hidden
LastPass (HKLM-x32\...\{8A6242E7-4345-42F3-92D6-02C9E0B73250}) (Version: 4.89.0.2402 - LogMeIn)
Logitech Options (HKLM\...\LogiOptions) (Version: 7.10.3 - Logitech)
Maxx Audio Installer (x64) (HKLM\...\{307032B2-6AF2-46D7-B933-62438DEB2B9A}) (Version: 2.7.12560.1 - Waves Audio Ltd.) Hidden
Microsoft .NET Runtime - 5.0.16 (x64) (HKLM-x32\...\{68696b91-f423-4e8e-a58f-631366d0f77a}) (Version: 5.0.16.31117 - Microsoft Corporation)
Microsoft 365 Apps for enterprise - en-us (HKLM\...\O365ProPlusRetail - en-us) (Version: 16.0.14326.20910 - Microsoft Corporation)
Microsoft ASP.NET MVC 2 (HKLM-x32\...\{DD8FF2F3-0D97-4CF3-AF78-FA0E1B242244}) (Version: 2.0.60926.0 - Microsoft Corporation)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 100.0.1185.39 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 100.0.1185.36 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1146508179-405363288-658039003-1003\...\OneDriveSetup.exe) (Version: 22.055.0313.0001 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50918.0 - Microsoft Corporation)
Microsoft Teams (HKU\S-1-5-21-1146508179-405363288-658039003-1003\...\Teams) (Version: 1.5.00.4689 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{7B1FCD52-8F6B-4F12-A143-361EA39F5E7C}) (Version: 3.67.0.0 - Microsoft Corporation)
Microsoft Visual Basic PowerPacks 1.2 (HKLM-x32\...\{5169D2E2-0B94-3320-8C7A-718F92BE20CE}) (Version: 9.0.30729 - Microsoft)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x64) - 14.16.27033 (HKLM-x32\...\{cc3a7c63-31fb-4129-9024-63ebefd86a95}) (Version: 14.16.27033.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x86) - 14.16.27033 (HKLM-x32\...\{624ba875-fdfc-4efa-9c66-b170dfebc3ec}) (Version: 14.16.27033.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.60724 - Microsoft Corporation)
Microsoft WSE 3.0 (HKLM-x32\...\{EDEA8AB7-7683-4ED2-AA19-E6C078064C0D}) (Version: 3.0.5305.0 - Microsoft Corporation)
MM.Enterprise.WebServices Setup (HKLM-x32\...\{37D7831B-F91E-45EB-A733-25C993D1AD04}) (Version: 1.0.0 - MassMutual Financial Group)
Movavi Screen Recorder 21 (HKU\S-1-5-21-1146508179-405363288-658039003-1003\...\Movavi Screen Recorder 21) (Version: 21.0.0 - Movavi)
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.14326.20910 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.14326.20910 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.14326.20910 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0409-0000-0000000FF1CE}) (Version: 16.0.13801.20638 - Microsoft Corporation) Hidden
OptaneDowngradeGuard (HKLM\...\{86B0E6C1-32E0-42CC-BC4F-BF3C0730CECB}) (Version: 18.0.0.0 - Intel Corporation) Hidden
OutlookRegistryFix (HKLM-x32\...\{409932D6-5678-42AC-857A-9C42489E8DF1}) (Version: 1.00.0000 - {COMPANY_NAME} MassMutual)
Player Location Check (HKLM-x32\...\{F0753064-8D66-41A7-9F23-7691290387BF}) (Version: 3.1.1.3 - GeoComply)
Printer Registration (HKLM-x32\...\Canon EISRegistration) (Version: 1.8.0 - Canon Inc.)
Realtek Audio COM Components (HKLM-x32\...\{2355B503-9B11-4449-861D-1C1748B26320}) (Version: 1.0.2 - Realtek Semiconductor Corp.)
Realtek Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.9000.1 - Realtek Semiconductor Corp.)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.18362.31252 - Realtek Semiconductor Corp.)
RstDowngradeGuard (HKLM\...\{13C2A26E-7AD4-4D82-BB4F-DEA6E871B958}) (Version: 18.0.0.0 - Intel Corporation) Hidden
skiing (HKLM-x32\...\skiing_is1) (Version:  - )
Skype Meetings App (HKLM-x32\...\{56FC471B-6B4E-4CEF-AA29-D3F5D9387731}) (Version: 16.2.0.282 - Microsoft Corporation)
Teams Machine-Wide Installer (HKLM-x32\...\{39AF0813-FA7B-4860-ADBE-93B9B214B914}) (Version: 1.2.0.34161 - Microsoft Corporation)
Thunderbolt™ Software (HKLM-x32\...\{30F0067F-DD79-431B-BA5F-6CB4897785A5}) (Version: 17.4.79.510 - Intel Corporation)
TuneFab Screen Recorder 2.1.26 (HKLM-x32\...\{0AB6B9D1-ED73-491D-96DF-F7A8E80FF1A0}_is1) (Version: 2.1.26 - TuneFab Software Inc)
U3Launcher (HKLM-x32\...\{D8E363A7-88B7-446D-B2C0-E26CE4DC8E54}) (Version: 1.0.0 - U3)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{32DC821E-4A7D-4878-BEE8-337FA153D7F2}) (Version: 2.63.0.0 - Microsoft Corporation) Hidden
VMware SfdAgent (HKLM\...\{545571C3-8454-4002-914B-B411F82CCB76}) (Version: 21.05.11 - VMware) Hidden
Web Launch Recorder (HKU\S-1-5-21-1146508179-405363288-658039003-1003\...\WebLaunchRecorder) (Version: 2.0 - )
Windows PC Health Check (HKLM\...\{B1E7D0FD-7CFE-4E0C-A5DA-0F676499DB91}) (Version: 3.2.2110.14001 - Microsoft Corporation)
Workspace ONE Intelligent Hub Installer (HKLM-x32\...\{4B212D70-1501-6FA7-83EB-3DBAA27FC4BE}) (Version: 21.7.9.0 - VMware, Inc.)
Xerox Workplace Cloud Client (HKLM\...\{32F16584-856D-495B-BE83-EB06F5E039EA}) (Version: 5.4.99 - Xerox)
Zoom (HKU\S-1-5-21-1146508179-405363288-658039003-1003\...\ZoomUMX) (Version: 5.9.1 (2581) - Zoom Video Communications, Inc.)
Zoom Outlook Plugin (HKLM-x32\...\{FCF95040-F0A2-4EE7-BD9E-9407845F6636}) (Version: 4.8.13401 - Zoom)
 
Packages:
=========
Active Pen -> C:\Program Files\WindowsApps\WacomTechnologyCorp.DellActivePen_7.7.35.0_neutral__ss941bf8mfs8a [2021-08-10] (Wacom Technology Corp.)
Canon Inkjet Print Utility -> C:\Program Files\WindowsApps\34791E63.CanonInkjetPrintUtility_3.1.0.0_neutral__6e5tt8cgb93ep [2021-02-18] (Canon Inc.)
Dell Command | Update -> C:\Program Files\WindowsApps\DellInc.DellCommandUpdate_4.4.18.0_x86__htrsf667h5kn2 [2022-02-07] (Dell Inc)
Dell SupportAssist for Home PCs -> C:\Program Files\WindowsApps\DellInc.DellSupportAssistforPCs_3.10.7.0_x64__htrsf667h5kn2 [2022-02-08] (Dell Inc)
HEVC Video Extensions -> C:\Program Files\WindowsApps\Microsoft.HEVCVideoExtensions_1.0.50362.0_x64__8wekyb3d8bbwe [2022-03-01] (Microsoft Corporation)
HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_135.1.385.0_x64__v10z8vjag6ke6 [2022-03-21] (HP Inc.)
iCloud -> C:\Program Files\WindowsApps\AppleInc.iCloud_12.5.74.0_x86__nzyj5cx40ttqa [2021-11-30] (Apple Inc.) [Startup Task]
iCloud -> C:\Program Files\WindowsApps\AppleInc.iCloud_13.0.201.0_x86__nzyj5cx40ttqa [2022-02-04] (Apple Inc.) [Startup Task]
Intel® Optane™ Memory and Storage Management -> C:\Program Files\WindowsApps\AppUp.IntelOptaneMemoryandStorageManagement_18.1.1026.0_x64__8j3eq9eme6ctt [2022-04-01] (INTEL CORP)
iTunes -> C:\Program Files\WindowsApps\AppleInc.iTunes_12123.5.56009.0_x64__nzyj5cx40ttqa [2022-03-11] (Apple Inc.) [Startup Task]
LastPass: Free Password Manager -> C:\Program Files\WindowsApps\LastPass.LastPassFreePasswordManager_4.69.0.0_neutral__qq0fmhteeht3j [2021-04-10] (LastPass)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-01-22] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-01-22] (Microsoft Corporation) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.12.3171.0_x64__8wekyb3d8bbwe [2022-03-26] (Microsoft Studios) [MS Ad]
Microsoft Whiteboard -> C:\Program Files\WindowsApps\Microsoft.Whiteboard_52.10404.374.0_x64__8wekyb3d8bbwe [2022-04-06] (Microsoft Corporation)
Photos Add-on -> C:\Program Files\WindowsApps\Microsoft.Windows.Photos.DLC.Main_2021.39122.10110.0_x64__8wekyb3d8bbwe [2021-03-12] (Microsoft Corporation)
Photos Media Engine Add-on -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2019-12-11] (Microsoft Corporation)
Workspace ONE Intelligent Hub -> C:\Program Files\WindowsApps\AirWatchLLC.WorkspaceONEIntelligentHub_21.7.9.0_x86__htcwkw4rx2gx4 [2022-03-29] (VMware)
 
==================== Custom CLSID (Whitelisted): ==============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-1146508179-405363288-658039003-1003_Classes\CLSID\{01D049A1-C5A8-343F-8E51-90B16CEB68A0}\InprocServer32 -> C:\Users\AA583803\AppData\Local\Ablebits\Ultimate Suite for Microsoft Excel\1D4C31B65E64C28\AblebitsUltimateSuite.DLL (4Bits Ltd. -> Ablebits)
CustomCLSID: HKU\S-1-5-21-1146508179-405363288-658039003-1003_Classes\CLSID\{04271989-C4D2-FCD0-CDCF-C126DA82EE4B} -> [OneDrive - MassMutual] => C:\Users\AA583803\OneDrive - MassMutual [2021-03-11 15:37]
CustomCLSID: HKU\S-1-5-21-1146508179-405363288-658039003-1003_Classes\CLSID\{0736E843-6185-3363-92F9-385B51434E68}\InprocServer32 -> C:\Users\AA583803\AppData\Local\Ablebits\Ultimate Suite for Microsoft Excel\1D4C31B65E64C28\AblebitsUltimateSuite.DLL (4Bits Ltd. -> Ablebits)
CustomCLSID: HKU\S-1-5-21-1146508179-405363288-658039003-1003_Classes\CLSID\{078D8098-6D64-45F1-BE1A-3C6E66335A38} -> [iCloud Photos] => C:\Users\AA583803\Pictures\iCloud Photos\Photos [2020-08-20 12:03]
CustomCLSID: HKU\S-1-5-21-1146508179-405363288-658039003-1003_Classes\CLSID\{0B026475-E01D-314C-B973-9CE3801BA0F4}\InprocServer32 -> C:\Users\AA583803\AppData\Local\Ablebits\Ultimate Suite for Microsoft Excel\1D4C31B65E64C28\AblebitsUltimateSuite.DLL (4Bits Ltd. -> Ablebits)
CustomCLSID: HKU\S-1-5-21-1146508179-405363288-658039003-1003_Classes\CLSID\{1019ADC7-17CB-4489-AFD5-6642C7400ACE}\localserver32 -> C:\Users\AA583803\AppData\Local\Webex\Webex\Applications\ptOIEx64.exe (Cisco WebEx LLC -> Cisco WebEx LLC)
CustomCLSID: HKU\S-1-5-21-1146508179-405363288-658039003-1003_Classes\CLSID\{11340409-D9B9-3E95-A44E-457BC334175D}\InprocServer32 -> C:\Users\AA583803\AppData\Local\Ablebits\Ultimate Suite for Microsoft Excel\1D4C31B65E64C28\AblebitsUltimateSuite.DLL (4Bits Ltd. -> Ablebits)
CustomCLSID: HKU\S-1-5-21-1146508179-405363288-658039003-1003_Classes\CLSID\{14068B5A-A762-3E2A-AD9C-5007FFA7C8B8}\InprocServer32 -> C:\Users\AA583803\AppData\Local\Ablebits\Ultimate Suite for Microsoft Excel\1D4C31B65E64C28\AblebitsUltimateSuite.DLL (4Bits Ltd. -> Ablebits)
CustomCLSID: HKU\S-1-5-21-1146508179-405363288-658039003-1003_Classes\CLSID\{18DEA14E-6C68-4C17-9824-A37B359C6E35} -> [iCloud Drive] => C:\Users\AA583803\iCloudDrive [2020-08-20 12:05]
CustomCLSID: HKU\S-1-5-21-1146508179-405363288-658039003-1003_Classes\CLSID\{19A6E644-14E6-4A60-B8D7-DD20610A871D}\InprocServer32 -> C:\Users\AA583803\AppData\Local\Microsoft\TeamsMeetingAddin\1.0.21348.1\x64\Microsoft.Teams.AddinLoader.dll (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1146508179-405363288-658039003-1003_Classes\CLSID\{1B04E5D0-8BF7-385E-B7EF-A75C960D9226}\InprocServer32 -> C:\Users\AA583803\AppData\Local\Ablebits\Ultimate Suite for Microsoft Excel\1D4C31B65E64C28\AblebitsUltimateSuite.DLL (4Bits Ltd. -> Ablebits)
CustomCLSID: HKU\S-1-5-21-1146508179-405363288-658039003-1003_Classes\CLSID\{1CD65DD7-0514-3845-B0EB-94C5ED3E08D9}\InprocServer32 -> C:\Users\AA583803\AppData\Local\Ablebits\Ultimate Suite for Microsoft Excel\1D4C31B65E64C28\AblebitsUltimateSuite.DLL (4Bits Ltd. -> Ablebits)
CustomCLSID: HKU\S-1-5-21-1146508179-405363288-658039003-1003_Classes\CLSID\{1D2AB166-4AB6-338E-BF89-8248BB48BC4B}\InprocServer32 -> C:\Users\AA583803\AppData\Local\Ablebits\Ultimate Suite for Microsoft Excel\1D4C31B65E64C28\AblebitsUltimateSuite.DLL (4Bits Ltd. -> Ablebits)
CustomCLSID: HKU\S-1-5-21-1146508179-405363288-658039003-1003_Classes\CLSID\{23423CAF-1507-3656-91CD-CDC6A57290A2}\InprocServer32 -> C:\Users\AA583803\AppData\Local\Ablebits\Ultimate Suite for Microsoft Excel\1D4C31B65E64C28\AblebitsUltimateSuite.DLL (4Bits Ltd. -> Ablebits)
CustomCLSID: HKU\S-1-5-21-1146508179-405363288-658039003-1003_Classes\CLSID\{2DC5EF7E-1EE0-3443-BC65-4C82DF8DCF96}\InprocServer32 -> C:\Users\AA583803\AppData\Local\Ablebits\Ultimate Suite for Microsoft Excel\1D4C31B65E64C28\AblebitsUltimateSuite.DLL (4Bits Ltd. -> Ablebits)
CustomCLSID: HKU\S-1-5-21-1146508179-405363288-658039003-1003_Classes\CLSID\{3D617CE6-C7CF-4B1D-86B4-BF8C8C530210}\InprocServer32 -> C:\Users\AA583803\AppData\Local\Ablebits\Ultimate Suite for Microsoft Excel\1D4C31B65E64C28\adxloader64.dll (4Bits Ltd. -> Ablebits)
CustomCLSID: HKU\S-1-5-21-1146508179-405363288-658039003-1003_Classes\CLSID\{3E3AD4BD-346A-460A-80E8-90699B75C00B}\InprocServer32 -> C:\Users\AA583803\AppData\Local\Microsoft\SkypeForBusinessPlugin\16.2.0.282\GatewayActiveX-x64.dll (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1146508179-405363288-658039003-1003_Classes\CLSID\{444F60B6-5B6D-3561-AD80-88A0585A2701}\InprocServer32 -> C:\Users\AA583803\AppData\Local\Ablebits\Ultimate Suite for Microsoft Excel\1D4C31B65E64C28\AblebitsUltimateSuite.DLL (4Bits Ltd. -> Ablebits)
CustomCLSID: HKU\S-1-5-21-1146508179-405363288-658039003-1003_Classes\CLSID\{4D2F086C-6EA3-101B-A18A-00AA00446E07}\InprocServer32 -> C:\WINDOWS\system32\mapi32.dll (Microsoft Windows -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1146508179-405363288-658039003-1003_Classes\CLSID\{4E876FFE-9320-326A-84D0-DE7E7D4F5FDC}\InprocServer32 -> C:\Users\AA583803\AppData\Local\Ablebits\Ultimate Suite for Microsoft Excel\1D4C31B65E64C28\AblebitsUltimateSuite.DLL (4Bits Ltd. -> Ablebits)
CustomCLSID: HKU\S-1-5-21-1146508179-405363288-658039003-1003_Classes\CLSID\{50ECC686-8E78-3BAE-A310-A9407B9D04DD}\InprocServer32 -> C:\Users\AA583803\AppData\Local\Ablebits\Ultimate Suite for Microsoft Excel\1D4C31B65E64C28\AblebitsUltimateSuite.DLL (4Bits Ltd. -> Ablebits)
CustomCLSID: HKU\S-1-5-21-1146508179-405363288-658039003-1003_Classes\CLSID\{5590759E-A52F-35C5-9FF6-435B4355B1F0}\InprocServer32 -> C:\Users\AA583803\AppData\Local\Ablebits\Ultimate Suite for Microsoft Excel\1D4C31B65E64C28\AblebitsUltimateSuite.DLL (4Bits Ltd. -> Ablebits)
CustomCLSID: HKU\S-1-5-21-1146508179-405363288-658039003-1003_Classes\CLSID\{5D70F043-465B-31B3-AF67-6B7BE85178C7}\InprocServer32 -> C:\Users\AA583803\AppData\Local\Ablebits\Ultimate Suite for Microsoft Excel\1D4C31B65E64C28\AblebitsUltimateSuite.DLL (4Bits Ltd. -> Ablebits)
CustomCLSID: HKU\S-1-5-21-1146508179-405363288-658039003-1003_Classes\CLSID\{5E4BA212-6EC5-3E7C-B42A-9D9B8E6A1CD3}\InprocServer32 -> C:\Users\AA583803\AppData\Local\Ablebits\Ultimate Suite for Microsoft Excel\1D4C31B65E64C28\AblebitsUltimateSuite.DLL (4Bits Ltd. -> Ablebits)
CustomCLSID: HKU\S-1-5-21-1146508179-405363288-658039003-1003_Classes\CLSID\{6721DB0F-CE28-3B02-AA8A-4C04FDD53202}\InprocServer32 -> C:\Users\AA583803\AppData\Local\Ablebits\Ultimate Suite for Microsoft Excel\1D4C31B65E64C28\AblebitsUltimateSuite.DLL (4Bits Ltd. -> Ablebits)
CustomCLSID: HKU\S-1-5-21-1146508179-405363288-658039003-1003_Classes\CLSID\{6A0EE0C2-F247-3D24-B787-3003842F06CA}\InprocServer32 -> C:\Users\AA583803\AppData\Local\Ablebits\Ultimate Suite for Microsoft Excel\1D4C31B65E64C28\AblebitsUltimateSuite.DLL (4Bits Ltd. -> Ablebits)
 
 
This is the ADW cleaner log
# -------------------------------
# Malwarebytes AdwCleaner 8.3.2.0
# -------------------------------
# Build:    03-23-2022
# Database: 2022-03-15.3 (Cloud)
#
# -------------------------------
# Mode: Scan
# -------------------------------
# Start:    04-17-2022
# Duration: 00:00:07
# OS:       Windows 10 Pro
# Scanned:  32044
# Detected: 11
 
 
***** [ Services ] *****
 
No malicious services found.
 
***** [ Folders ] *****
 
No malicious folders found.
 
***** [ Files ] *****
 
No malicious files found.
 
***** [ DLL ] *****
 
No malicious DLLs found.
 
***** [ WMI ] *****
 
No malicious WMI found.
 
***** [ Shortcuts ] *****
 
No malicious shortcuts found.
 
***** [ Tasks ] *****
 
No malicious tasks found.
 
***** [ Registry ] *****
 
No malicious registry entries found.
 
***** [ Chromium (and derivatives) ] *****
 
No malicious Chromium entries found.
 
***** [ Chromium URLs ] *****
 
No malicious Chromium URLs found.
 
***** [ Firefox (and derivatives) ] *****
 
No malicious Firefox entries found.
 
***** [ Firefox URLs ] *****
 
No malicious Firefox URLs found.
 
***** [ Hosts File Entries ] *****
 
No malicious hosts file entries found.
 
***** [ Preinstalled Software ] *****
 
Preinstalled.DellCommand|Update   Folder   C:\Program Files\DELL\COMMANDUPDATE 
Preinstalled.DellSupportAssistAgent   Folder   C:\Program Files\DELL\SAREMEDIATION\AUDIT 
Preinstalled.DellSupportAssistAgent   Folder   C:\Program Files\DELL\SAREMEDIATION\PLUGIN 
Preinstalled.DellSupportAssistAgent   Folder   C:\Program Files\DELL\SUPPORTASSISTAGENT 
Preinstalled.DellSupportAssistAgent   Folder   C:\ProgramData\SUPPORTASSIST\CLIENT\TECHNICIANTOOLKIT 
Preinstalled.DellSupportAssistAgent   Registry   HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B1A4FF7F-2F01-4E26-8E65-99AA3859DA8E}  
Preinstalled.DellSupportAssistAgent   Registry   HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B1A4FF7F-2F01-4E26-8E65-99AA3859DA8E}  
Preinstalled.DellSupportAssistAgent   Registry   HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Dell SupportAssistAgent AutoUpdate 
Preinstalled.DellSupportAssistAgent   Task   C:\Windows\System32\Tasks\DELL SUPPORTASSISTAGENT AUTOUPDATE 
Preinstalled.DellUpdateforWindows10   Folder   C:\Program Files (x86)\DELL\UPDATESERVICE 
Preinstalled.DellUpdateforWindows10   Folder   C:\ProgramData\DELL\UPDATESERVICE 
 
 
 
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S00].txt ##########
 
 
Malewarebytes log
Malwarebytes
www.malwarebytes.com
 
-Log Details-
Scan Date: 4/17/22
Scan Time: 7:01 PM
Log File: 5cc927e0-bea2-11ec-b1c8-1c1bb5d2effa.json
 
-Software Information-
Version: 4.5.2.157
Components Version: 1.0.1562
Update Package Version: 1.0.53827
License: Trial
 
-System Information-
OS: Windows 10 (Build 19044.1645)
CPU: x64
File System: NTFS
User: AA585803-L\AA583803
 
-Scan Summary-
Scan Type: Threat Scan
Scan Initiated By: Manual
Result: Completed
Objects Scanned: 328255
Threats Detected: 0
Threats Quarantined: 0
Time Elapsed: 4 min, 31 sec
 
-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Detect
PUM: Detect
 
-Scan Details-
Process: 0
(No malicious items detected)
 
Module: 0
(No malicious items detected)
 
Registry Key: 0
(No malicious items detected)
 
Registry Value: 0
(No malicious items detected)
 
Registry Data: 0
(No malicious items detected)
 
Data Stream: 0
(No malicious items detected)
 
Folder: 0
(No malicious items detected)
 
File: 0
(No malicious items detected)
 
Physical Sector: 0
(No malicious items detected)
 
WMI: 0
(No malicious items detected)
 
 
(end)


#5 Juliet

Juliet

    SuperHelper

  • Retired Classroom Teacher
  • 7,686 posts
  • Interests:Boo!....
  • MVP

Posted 19 April 2022 - 10:01 AM

Post not acting right, I'll try this again.
Sometimes the angels fly close enough to you that you can hear the flutter of their wings...


MS - MVP Consumer Security 2009 - 2016, WI-MVP 2016-17
Antivirus Scanners Online Scanners Firewalls Slow Computer??

#6 Juliet

Juliet

    SuperHelper

  • Retired Classroom Teacher
  • 7,686 posts
  • Interests:Boo!....
  • MVP

Posted 19 April 2022 - 10:07 AM

Start Farbar Recovery Scan Tool with Administrator privileges
(Right click on the FRST icon and select Run as administrator, just open it and let it wait)

highlight on the text below and select Copy.
beginning with Start:: and finishing with End::

Highlight the entire content of the quote box below and select Copy.

 

Start::
CloseProcesses:
CreateRestorePoint:
ShortcutTarget: RingCentral.lnk -> C:\Users\AA583803\AppData\Local\Programs\RingCentral\RingCentral.exe (No File)
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION
Task: {0467277A-332B-4A71-8C89-79A851937A08} - System32\Tasks\Symantec Endpoint Protection\Symantec Endpoint Protection Error Analyzer => C:\Program Files\Symantec\14.0.3752.1000.105\Bin\SymErr.exe /analyze (No File)
Task: {81D3FADB-33BF-4658-A73C-F867C78EFE96} - System32\Tasks\Symantec Endpoint Protection\Symantec Endpoint Protection Error Processor => C:\Program Files\Symantec\14.0.3752.1000.105\Bin\SymErr.exe /submit (No File)
Task: {D81D3ACE-DB1D-43BD-A45E-36C564BE8791} - System32\Tasks\Symantec Endpoint Protection\Symantec Endpoint Protection Autofix => C:\Program Files\Symantec\14.0.3752.1000.105\Bin\SymErr.exe /ui (No File)
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <==== ATTENTION
Hosts:
CMD: netsh int ip reset
CMD: ipconfig /flushDNS
EmptyTemp:
C:\Windows\Temp\*.*
SystemRestore:
End::

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Start FRST (FRST64) with Administrator privileges
Press the Fix button. FRST will process the lines copied above from the clipboard.
When finished, a log file (Fixlog.txt) will pop up and saved in the same location the tool was ran from.

Please copy and paste its contents in your next reply.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~`

ESET Online Scanner:

  • Download ESET Online Scanner from the ESET website by clicking the ONE-TIME-SCAN button on that webpage
  • Double-click the esetonlinescanner.exe file you downloaded to run the application
  • Select product language
  • Click Get started and confirm the User access control dialog of Windows
  • In the Terms of use screen, click Accept if you agree to the Terms of use. After accepting the terms of use, the shortcut for ESET Online Scanner is created on the Desktop
  • Click Get started in the welcome screen
  • Select whether or not you want to join the Customer Experience Improvement Program, and whether or not to enable the feedback system, then click Continue
  • Select the Full Scan type
  • Select the choice to enable detections of potentially unwanted applications (PUA)
  • After the detection module updates are downloaded, the scan starts. Scan progress is shown via the progress bar along with the path and title of file being scanned. You can pause or cancel the scan at any time
  • Note: The scan make take several hours depending on how many files are on your computer..When the scan has finished and if threats have been detected, click Save scan log and save the text file with a unique name such as, ESET results.txt then click Continue.
  • Copy and paste the contents of this ESET results report into your next reply to me (If no threats were detected, you do not need to save the results)
  • The following steps are optional and are not required
    • If there has been no ESET security product detected on your machine, and your user account has administrator privileges, ESET Online Scanner will offer you to turn on Periodic scan. This choice is up to you
    • In the Thank you for using ESET Online Scanner screen you can rate the application and leave feedback. In addition, to delete all detection modules and settings of ESET Online Scanner configured in previous steps, select Delete application's data on closing
    • Click Submit and close if you rated the application and/or left a feedback, or click Close without feedback
  • Click Finish to exit ESET Online Scanner
  • Please check Chrome again to see if it is operational.

Sometimes the angels fly close enough to you that you can hear the flutter of their wings...


MS - MVP Consumer Security 2009 - 2016, WI-MVP 2016-17
Antivirus Scanners Online Scanners Firewalls Slow Computer??

#7 rockaway1

rockaway1

    Authentic Member

  • Authentic Member
  • PipPip
  • 35 posts

Posted 20 April 2022 - 09:16 PM

Fix result of Farbar Recovery Scan Tool (x64) Version: 18-04-2022 01
Ran by AA583803 (20-04-2022 23:06:16) Run:1
Running from C:\Users\AA583803\OneDrive - MassMutual\Desktop\virus scans
Loaded Profiles: AA583803
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
CloseProcesses:
CreateRestorePoint:
ShortcutTarget: RingCentral.lnk -> C:\Users\AA583803\AppData\Local\Programs\RingCentral\RingCentral.exe (No File)
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION
Task: {0467277A-332B-4A71-8C89-79A851937A08} - System32\Tasks\Symantec Endpoint Protection\Symantec Endpoint Protection Error Analyzer => C:\Program Files\Symantec\14.0.3752.1000.105\Bin\SymErr.exe /analyze (No File)
Task: {81D3FADB-33BF-4658-A73C-F867C78EFE96} - System32\Tasks\Symantec Endpoint Protection\Symantec Endpoint Protection Error Processor => C:\Program Files\Symantec\14.0.3752.1000.105\Bin\SymErr.exe /submit (No File)
Task: {D81D3ACE-DB1D-43BD-A45E-36C564BE8791} - System32\Tasks\Symantec Endpoint Protection\Symantec Endpoint Protection Autofix => C:\Program Files\Symantec\14.0.3752.1000.105\Bin\SymErr.exe /ui (No File)
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <==== ATTENTION
Hosts:
CMD: netsh int ip reset
CMD: ipconfig /flushDNS
EmptyTemp:
C:\Windows\Temp\*.*
SystemRestore:
 
*****************
 
Processes closed successfully.
Restore point was successfully created.
"C:\Users\AA583803\AppData\Local\Programs\RingCentral\RingCentral.exe" => not found
C:\WINDOWS\system32\GroupPolicy\Machine => moved successfully
C:\WINDOWS\system32\GroupPolicy\GPT.ini => moved successfully
C:\ProgramData\NTUSER.pol => moved successfully
HKLM\SOFTWARE\Policies\Microsoft\Edge => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0467277A-332B-4A71-8C89-79A851937A08}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0467277A-332B-4A71-8C89-79A851937A08}" => removed successfully
C:\WINDOWS\System32\Tasks\Symantec Endpoint Protection\Symantec Endpoint Protection Error Analyzer => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Symantec Endpoint Protection\Symantec Endpoint Protection Error Analyzer" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{81D3FADB-33BF-4658-A73C-F867C78EFE96}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{81D3FADB-33BF-4658-A73C-F867C78EFE96}" => removed successfully
C:\WINDOWS\System32\Tasks\Symantec Endpoint Protection\Symantec Endpoint Protection Error Processor => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Symantec Endpoint Protection\Symantec Endpoint Protection Error Processor" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D81D3ACE-DB1D-43BD-A45E-36C564BE8791}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D81D3ACE-DB1D-43BD-A45E-36C564BE8791}" => removed successfully
C:\WINDOWS\System32\Tasks\Symantec Endpoint Protection\Symantec Endpoint Protection Autofix => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Symantec Endpoint Protection\Symantec Endpoint Protection Autofix" => removed successfully
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer => removed successfully
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.
 
========= netsh int ip reset =========
 
Resetting Compartment Forwarding, OK!
Resetting Compartment, OK!
Resetting Control Protocol, OK!
Resetting Echo Sequence Request, OK!
Resetting Global, OK!
Resetting Interface, OK!
Resetting Anycast Address, OK!
Resetting Multicast Address, OK!
Resetting Unicast Address, OK!
Resetting Neighbor, OK!
Resetting Path, OK!
Resetting Potential, OK!
Resetting Prefix Policy, OK!
Resetting Proxy Neighbor, OK!
Resetting Route, OK!
Resetting Site Prefix, OK!
Resetting Subinterface, OK!
Resetting Wakeup Pattern, OK!
Resetting Resolve Neighbor, OK!
Resetting , OK!
Resetting , OK!
Resetting , OK!
Resetting , OK!
Resetting , failed.
Access is denied.
 
Resetting , OK!
Resetting , OK!
Resetting , OK!
Resetting , OK!
Resetting , OK!
Resetting , OK!
Resetting , OK!
Restart the computer to complete this action.
 
 
========= End of CMD: =========
 
 
========= ipconfig /flushDNS =========
 
 
Windows IP Configuration
 
Successfully flushed the DNS Resolver Cache.
 
========= End of CMD: =========
 
 
=========== "C:\Windows\Temp\*.*" ==========
 
C:\Windows\Temp\719b0ff0-2e96-4766-b44e-05d6da6ae90e.tmp => moved successfully
C:\Windows\Temp\AA585803-L-20220308-2337.log => moved successfully
C:\Windows\Temp\AA585803-L-20220409-2010.log => moved successfully
C:\Windows\Temp\AA585803-L-20220409-2011.log => moved successfully
C:\Windows\Temp\AA585803-L-20220409-2013.log => moved successfully
C:\Windows\Temp\AA585803-L-20220409-2014.log => moved successfully
C:\Windows\Temp\AA585803-L-20220409-2227.log => moved successfully
C:\Windows\Temp\AA585803-L-20220409-2227a.log => moved successfully
C:\Windows\Temp\AA585803-L-20220410-0045.log => moved successfully
C:\Windows\Temp\AA585803-L-20220410-0045a.log => moved successfully
C:\Windows\Temp\AA585803-L-20220410-0045b.log => moved successfully
C:\Windows\Temp\AA585803-L-20220410-0046.log => moved successfully
C:\Windows\Temp\AA585803-L-20220410-0308.log => moved successfully
C:\Windows\Temp\AA585803-L-20220410-0308a.log => moved successfully
C:\Windows\Temp\AA585803-L-20220410-0550.log => moved successfully
C:\Windows\Temp\AA585803-L-20220410-0550a.log => moved successfully
C:\Windows\Temp\AA585803-L-20220410-0550b.log => moved successfully
C:\Windows\Temp\AA585803-L-20220410-0551.log => moved successfully
C:\Windows\Temp\AA585803-L-20220410-0551a.log => moved successfully
C:\Windows\Temp\AA585803-L-20220410-0606.log => moved successfully
C:\Windows\Temp\AA585803-L-20220410-0718.log => moved successfully
C:\Windows\Temp\AA585803-L-20220410-0718a.log => moved successfully
C:\Windows\Temp\AA585803-L-20220410-1322.log => moved successfully
C:\Windows\Temp\AA585803-L-20220410-1322a.log => moved successfully
C:\Windows\Temp\AA585803-L-20220410-1323.log => moved successfully
C:\Windows\Temp\AA585803-L-20220410-1323a.log => moved successfully
C:\Windows\Temp\AA585803-L-20220410-1532.log => moved successfully
C:\Windows\Temp\AA585803-L-20220410-1532a.log => moved successfully
C:\Windows\Temp\AA585803-L-20220410-1758.log => moved successfully
C:\Windows\Temp\AA585803-L-20220410-1758a.log => moved successfully
C:\Windows\Temp\AA585803-L-20220410-1759.log => moved successfully
C:\Windows\Temp\AA585803-L-20220410-1759a.log => moved successfully
C:\Windows\Temp\AA585803-L-20220410-1959.log => moved successfully
C:\Windows\Temp\AA585803-L-20220410-1959a.log => moved successfully
C:\Windows\Temp\AA585803-L-20220410-2159.log => moved successfully
C:\Windows\Temp\AA585803-L-20220410-2159a.log => moved successfully
C:\Windows\Temp\AA585803-L-20220411-0415.log => moved successfully
C:\Windows\Temp\AA585803-L-20220411-0415a.log => moved successfully
C:\Windows\Temp\AA585803-L-20220411-0416.log => moved successfully
C:\Windows\Temp\AA585803-L-20220411-0416a.log => moved successfully
C:\Windows\Temp\AA585803-L-20220411-0444.log => moved successfully
C:\Windows\Temp\AA585803-L-20220411-0445.log => moved successfully
C:\Windows\Temp\AA585803-L-20220411-0512.log => moved successfully
C:\Windows\Temp\AA585803-L-20220411-0550.log => moved successfully
C:\Windows\Temp\AA585803-L-20220411-0618.log => moved successfully
C:\Windows\Temp\AA585803-L-20220411-0618a.log => moved successfully
C:\Windows\Temp\AA585803-L-20220411-0818.log => moved successfully
C:\Windows\Temp\AA585803-L-20220411-0818a.log => moved successfully
C:\Windows\Temp\AA585803-L-20220411-0818b.log => moved successfully
C:\Windows\Temp\AA585803-L-20220411-0818c.log => moved successfully
C:\Windows\Temp\AA585803-L-20220411-1049.log => moved successfully
C:\Windows\Temp\AA585803-L-20220411-1050.log => moved successfully
C:\Windows\Temp\AA585803-L-20220411-1207.log => moved successfully
C:\Windows\Temp\AA585803-L-20220411-1207a.log => moved successfully
C:\Windows\Temp\AA585803-L-20220411-1211.log => moved successfully
C:\Windows\Temp\AA585803-L-20220411-1211a.log => moved successfully
C:\Windows\Temp\AA585803-L-20220411-1311.log => moved successfully
C:\Windows\Temp\AA585803-L-20220411-1312.log => moved successfully
C:\Windows\Temp\AA585803-L-20220411-1627.log => moved successfully
C:\Windows\Temp\AA585803-L-20220411-1627a.log => moved successfully
C:\Windows\Temp\AA585803-L-20220411-1655.log => moved successfully
C:\Windows\Temp\AA585803-L-20220411-1655a.log => moved successfully
C:\Windows\Temp\AA585803-L-20220411-1750.log => moved successfully
C:\Windows\Temp\AA585803-L-20220411-1750a.log => moved successfully
C:\Windows\Temp\AA585803-L-20220411-1750b.log => moved successfully
C:\Windows\Temp\AA585803-L-20220411-1940.log => moved successfully
C:\Windows\Temp\AA585803-L-20220411-1940a.log => moved successfully
C:\Windows\Temp\AA585803-L-20220411-1945.log => moved successfully
C:\Windows\Temp\AA585803-L-20220411-1946.log => moved successfully
C:\Windows\Temp\AA585803-L-20220412-0010.log => moved successfully
C:\Windows\Temp\AA585803-L-20220412-0011.log => moved successfully
C:\Windows\Temp\AA585803-L-20220412-0012.log => moved successfully
C:\Windows\Temp\AA585803-L-20220412-0012a.log => moved successfully
C:\Windows\Temp\AA585803-L-20220412-0227.log => moved successfully
C:\Windows\Temp\AA585803-L-20220412-0227a.log => moved successfully
C:\Windows\Temp\AA585803-L-20220412-0427.log => moved successfully
C:\Windows\Temp\AA585803-L-20220412-0427a.log => moved successfully
C:\Windows\Temp\AA585803-L-20220412-0512.log => moved successfully
C:\Windows\Temp\AA585803-L-20220412-0827.log => moved successfully
C:\Windows\Temp\AA585803-L-20220412-0827a.log => moved successfully
C:\Windows\Temp\AA585803-L-20220412-0918.log => moved successfully
C:\Windows\Temp\AA585803-L-20220412-0918a.log => moved successfully
C:\Windows\Temp\AA585803-L-20220412-0918b.log => moved successfully
C:\Windows\Temp\AA585803-L-20220412-0923.log => moved successfully
C:\Windows\Temp\AA585803-L-20220412-0924.log => moved successfully
C:\Windows\Temp\AA585803-L-20220412-0938.log => moved successfully
C:\Windows\Temp\AA585803-L-20220412-0938a.log => moved successfully
C:\Windows\Temp\AA585803-L-20220412-1034.log => moved successfully
C:\Windows\Temp\AA585803-L-20220412-1034a.log => moved successfully
C:\Windows\Temp\AA585803-L-20220412-1150.log => moved successfully
C:\Windows\Temp\AA585803-L-20220412-1150a.log => moved successfully
C:\Windows\Temp\AA585803-L-20220412-1457.log => moved successfully
C:\Windows\Temp\AA585803-L-20220412-1457a.log => moved successfully
C:\Windows\Temp\AA585803-L-20220412-1530.log => moved successfully
C:\Windows\Temp\AA585803-L-20220412-1530a.log => moved successfully
C:\Windows\Temp\AA585803-L-20220412-1558.log => moved successfully
C:\Windows\Temp\AA585803-L-20220412-1558a.log => moved successfully
C:\Windows\Temp\AA585803-L-20220412-1558b.log => moved successfully
C:\Windows\Temp\AA585803-L-20220412-1559.log => moved successfully
C:\Windows\Temp\AA585803-L-20220412-1600.log => moved successfully
C:\Windows\Temp\AA585803-L-20220412-1641.log => moved successfully
C:\Windows\Temp\AA585803-L-20220412-1655.log => moved successfully
C:\Windows\Temp\AA585803-L-20220412-1716.log => moved successfully
C:\Windows\Temp\AA585803-L-20220412-1726.log => moved successfully
C:\Windows\Temp\AA585803-L-20220412-1811.log => moved successfully
C:\Windows\Temp\AA585803-L-20220412-1817.log => moved successfully
C:\Windows\Temp\AA585803-L-20220412-1824.log => moved successfully
C:\Windows\Temp\AA585803-L-20220412-1843.log => moved successfully
C:\Windows\Temp\AA585803-L-20220412-2031.log => moved successfully
C:\Windows\Temp\AA585803-L-20220412-2035.log => moved successfully
C:\Windows\Temp\AA585803-L-20220413-1025.log => moved successfully
C:\Windows\Temp\AA585803-L-20220413-1032.log => moved successfully
C:\Windows\Temp\AA585803-L-20220413-1053.log => moved successfully
C:\Windows\Temp\AA585803-L-20220413-1057.log => moved successfully
C:\Windows\Temp\AA585803-L-20220413-1106.log => moved successfully
C:\Windows\Temp\AA585803-L-20220413-1111.log => moved successfully
C:\Windows\Temp\AA585803-L-20220413-1117.log => moved successfully
C:\Windows\Temp\AA585803-L-20220413-1202.log => moved successfully
C:\Windows\Temp\AA585803-L-20220413-1224.log => moved successfully
C:\Windows\Temp\AA585803-L-20220413-1258.log => moved successfully
C:\Windows\Temp\AA585803-L-20220413-1303.log => moved successfully
C:\Windows\Temp\AA585803-L-20220413-1411.log => moved successfully
C:\Windows\Temp\AA585803-L-20220413-1543.log => moved successfully
C:\Windows\Temp\AA585803-L-20220413-1544.log => moved successfully
C:\Windows\Temp\AA585803-L-20220413-1613.log => moved successfully
C:\Windows\Temp\AA585803-L-20220413-1618.log => moved successfully
C:\Windows\Temp\AA585803-L-20220413-1822.log => moved successfully
C:\Windows\Temp\AA585803-L-20220413-1823.log => moved successfully
C:\Windows\Temp\AA585803-L-20220413-1825.log => moved successfully
C:\Windows\Temp\AA585803-L-20220413-1828.log => moved successfully
C:\Windows\Temp\AA585803-L-20220413-1828a.log => moved successfully
C:\Windows\Temp\AA585803-L-20220413-1829.log => moved successfully
C:\Windows\Temp\AA585803-L-20220413-1830.log => moved successfully
C:\Windows\Temp\AA585803-L-20220413-1833.log => moved successfully
C:\Windows\Temp\AA585803-L-20220413-1838.log => moved successfully
C:\Windows\Temp\AA585803-L-20220413-1849.log => moved successfully
C:\Windows\Temp\AA585803-L-20220413-1851.log => moved successfully
C:\Windows\Temp\AA585803-L-20220413-1916.log => moved successfully
C:\Windows\Temp\AA585803-L-20220413-1921.log => moved successfully
C:\Windows\Temp\AA585803-L-20220413-1922.log => moved successfully
C:\Windows\Temp\AA585803-L-20220413-1927.log => moved successfully
C:\Windows\Temp\AA585803-L-20220413-2023.log => moved successfully
C:\Windows\Temp\AA585803-L-20220413-2023a.log => moved successfully
C:\Windows\Temp\AA585803-L-20220413-2025.log => moved successfully
C:\Windows\Temp\AA585803-L-20220413-2027.log => moved successfully
C:\Windows\Temp\AA585803-L-20220413-2031.log => moved successfully
C:\Windows\Temp\AA585803-L-20220413-2032.log => moved successfully
C:\Windows\Temp\AA585803-L-20220413-2039.log => moved successfully
C:\Windows\Temp\AA585803-L-20220413-2044.log => moved successfully
C:\Windows\Temp\AA585803-L-20220413-2258.log => moved successfully
C:\Windows\Temp\AA585803-L-20220413-2303.log => moved successfully
C:\Windows\Temp\AA585803-L-20220414-0015.log => moved successfully
C:\Windows\Temp\AA585803-L-20220414-0135.log => moved successfully
C:\Windows\Temp\AA585803-L-20220414-0140.log => moved successfully
C:\Windows\Temp\AA585803-L-20220414-0334.log => moved successfully
C:\Windows\Temp\AA585803-L-20220414-0400.log => moved successfully
C:\Windows\Temp\AA585803-L-20220414-0408.log => moved successfully
C:\Windows\Temp\AA585803-L-20220414-0433.log => moved successfully
C:\Windows\Temp\AA585803-L-20220414-0541.log => moved successfully
C:\Windows\Temp\AA585803-L-20220414-0756.log => moved successfully
C:\Windows\Temp\AA585803-L-20220414-1542.log => moved successfully
C:\Windows\Temp\AA585803-L-20220414-1600.log => moved successfully
C:\Windows\Temp\AA585803-L-20220414-1831.log => moved successfully
C:\Windows\Temp\AA585803-L-20220414-1837.log => moved successfully
C:\Windows\Temp\AA585803-L-20220414-1900.log => moved successfully
C:\Windows\Temp\AA585803-L-20220414-1909.log => moved successfully
C:\Windows\Temp\AA585803-L-20220414-1914.log => moved successfully
C:\Windows\Temp\AA585803-L-20220414-1919.log => moved successfully
C:\Windows\Temp\AA585803-L-20220414-1924.log => moved successfully
C:\Windows\Temp\AA585803-L-20220414-2037.log => moved successfully
C:\Windows\Temp\AA585803-L-20220414-2041.log => moved successfully
C:\Windows\Temp\AA585803-L-20220414-2133.log => moved successfully
C:\Windows\Temp\AA585803-L-20220414-2138.log => moved successfully
C:\Windows\Temp\AA585803-L-20220414-2153.log => moved successfully
C:\Windows\Temp\AA585803-L-20220414-2201.log => moved successfully
C:\Windows\Temp\AA585803-L-20220414-2206.log => moved successfully
C:\Windows\Temp\AA585803-L-20220414-2215.log => moved successfully
C:\Windows\Temp\AA585803-L-20220414-2220.log => moved successfully
C:\Windows\Temp\AA585803-L-20220415-0022.log => moved successfully
C:\Windows\Temp\AA585803-L-20220415-0027.log => moved successfully
C:\Windows\Temp\AA585803-L-20220415-0413.log => moved successfully
C:\Windows\Temp\AA585803-L-20220415-0433.log => moved successfully
C:\Windows\Temp\AA585803-L-20220415-0626.log => moved successfully
C:\Windows\Temp\AA585803-L-20220415-0752.log => moved successfully
C:\Windows\Temp\AA585803-L-20220415-0855.log => moved successfully
C:\Windows\Temp\AA585803-L-20220415-0915.log => moved successfully
C:\Windows\Temp\AA585803-L-20220415-0920.log => moved successfully
C:\Windows\Temp\AA585803-L-20220416-1507.log => moved successfully
C:\Windows\Temp\AA585803-L-20220416-1509.log => moved successfully
C:\Windows\Temp\AA585803-L-20220416-1509a.log => moved successfully
C:\Windows\Temp\AA585803-L-20220416-1511.log => moved successfully
C:\Windows\Temp\AA585803-L-20220416-1531.log => moved successfully
C:\Windows\Temp\AA585803-L-20220416-1616.log => moved successfully
C:\Windows\Temp\AA585803-L-20220416-1644.log => moved successfully
C:\Windows\Temp\AA585803-L-20220416-1648.log => moved successfully
C:\Windows\Temp\AA585803-L-20220416-1915.log => moved successfully
C:\Windows\Temp\AA585803-L-20220416-2134.log => moved successfully
C:\Windows\Temp\AA585803-L-20220416-2200.log => moved successfully
C:\Windows\Temp\AA585803-L-20220416-2205.log => moved successfully
C:\Windows\Temp\AA585803-L-20220416-2220.log => moved successfully
C:\Windows\Temp\AA585803-L-20220416-2225.log => moved successfully
C:\Windows\Temp\AA585803-L-20220416-2233.log => moved successfully
C:\Windows\Temp\AA585803-L-20220416-2236.log => moved successfully
C:\Windows\Temp\AA585803-L-20220416-2241.log => moved successfully
C:\Windows\Temp\AA585803-L-20220417-0905.log => moved successfully
C:\Windows\Temp\AA585803-L-20220417-0905a.log => moved successfully
C:\Windows\Temp\AA585803-L-20220417-0907.log => moved successfully
C:\Windows\Temp\AA585803-L-20220417-0911.log => moved successfully
C:\Windows\Temp\AA585803-L-20220417-0913.log => moved successfully
C:\Windows\Temp\AA585803-L-20220417-1826.log => moved successfully
C:\Windows\Temp\AA585803-L-20220417-1831.log => moved successfully
C:\Windows\Temp\AA585803-L-20220417-1919.log => moved successfully
C:\Windows\Temp\AA585803-L-20220417-1923.log => moved successfully
C:\Windows\Temp\AA585803-L-20220417-1923a.log => moved successfully
C:\Windows\Temp\AA585803-L-20220417-1932.log => moved successfully
C:\Windows\Temp\AA585803-L-20220417-2239.log => moved successfully
C:\Windows\Temp\AA585803-L-20220418-0121.log => moved successfully
C:\Windows\Temp\AA585803-L-20220418-0326.log => moved successfully
C:\Windows\Temp\AA585803-L-20220418-0526.log => moved successfully
C:\Windows\Temp\AA585803-L-20220418-0736.log => moved successfully
C:\Windows\Temp\AA585803-L-20220418-0837.log => moved successfully
C:\Windows\Temp\AA585803-L-20220418-0905.log => moved successfully
C:\Windows\Temp\AA585803-L-20220418-0914.log => moved successfully
C:\Windows\Temp\AA585803-L-20220418-0914a.log => moved successfully
C:\Windows\Temp\AA585803-L-20220418-1024.log => moved successfully
C:\Windows\Temp\AA585803-L-20220418-1024a.log => moved successfully
C:\Windows\Temp\AA585803-L-20220418-1037.log => moved successfully
C:\Windows\Temp\AA585803-L-20220418-1150.log => moved successfully
C:\Windows\Temp\AA585803-L-20220418-1244.log => moved successfully
C:\Windows\Temp\AA585803-L-20220418-1449.log => moved successfully
C:\Windows\Temp\AA585803-L-20220418-1541.log => moved successfully
C:\Windows\Temp\AA585803-L-20220418-1726.log => moved successfully
C:\Windows\Temp\AA585803-L-20220418-1731.log => moved successfully
C:\Windows\Temp\AA585803-L-20220418-1820.log => moved successfully
C:\Windows\Temp\AA585803-L-20220418-1901.log => moved successfully
C:\Windows\Temp\AA585803-L-20220418-1906.log => moved successfully
C:\Windows\Temp\AA585803-L-20220418-1923.log => moved successfully
C:\Windows\Temp\AA585803-L-20220419-0101.log => moved successfully
C:\Windows\Temp\AA585803-L-20220419-0106.log => moved successfully
C:\Windows\Temp\AA585803-L-20220419-0441.log => moved successfully
C:\Windows\Temp\AA585803-L-20220419-0750.log => moved successfully
C:\Windows\Temp\AA585803-L-20220419-0907.log => moved successfully
C:\Windows\Temp\AA585803-L-20220419-0912.log => moved successfully
C:\Windows\Temp\AA585803-L-20220419-0918.log => moved successfully
C:\Windows\Temp\AA585803-L-20220419-1450.log => moved successfully
C:\Windows\Temp\AA585803-L-20220419-1450a.log => moved successfully
C:\Windows\Temp\AA585803-L-20220419-1644.log => moved successfully
C:\Windows\Temp\AA585803-L-20220419-1649.log => moved successfully
C:\Windows\Temp\AA585803-L-20220419-1728.log => moved successfully
C:\Windows\Temp\AA585803-L-20220419-1804.log => moved successfully
C:\Windows\Temp\AA585803-L-20220419-1810.log => moved successfully
C:\Windows\Temp\AA585803-L-20220419-1814.log => moved successfully
C:\Windows\Temp\AA585803-L-20220420-0031.log => moved successfully
C:\Windows\Temp\AA585803-L-20220420-0036.log => moved successfully
C:\Windows\Temp\AA585803-L-20220420-0248.log => moved successfully
C:\Windows\Temp\AA585803-L-20220420-0506.log => moved successfully
C:\Windows\Temp\AA585803-L-20220420-0507.log => moved successfully
C:\Windows\Temp\AA585803-L-20220420-0707.log => moved successfully
C:\Windows\Temp\AA585803-L-20220420-0722.log => moved successfully
C:\Windows\Temp\AA585803-L-20220420-0723.log => moved successfully
C:\Windows\Temp\AA585803-L-20220420-0923.log => moved successfully
C:\Windows\Temp\AA585803-L-20220420-1034.log => moved successfully
C:\Windows\Temp\AA585803-L-20220420-1052.log => moved successfully
C:\Windows\Temp\AA585803-L-20220420-1057.log => moved successfully
C:\Windows\Temp\AA585803-L-20220420-1144.log => moved successfully
C:\Windows\Temp\AA585803-L-20220420-1216.log => moved successfully
C:\Windows\Temp\AA585803-L-20220420-1450.log => moved successfully
C:\Windows\Temp\AA585803-L-20220420-1452.log => moved successfully
C:\Windows\Temp\AA585803-L-20220420-1457.log => moved successfully
C:\Windows\Temp\AA585803-L-20220420-1509.log => moved successfully
C:\Windows\Temp\AA585803-L-20220420-1650.log => moved successfully
C:\Windows\Temp\AA585803-L-20220420-1709.log => moved successfully
C:\Windows\Temp\AA585803-L-20220420-1718.log => moved successfully
C:\Windows\Temp\AA585803-L-20220420-1745.log => moved successfully
C:\Windows\Temp\AA585803-L-20220420-1921.log => moved successfully
C:\Windows\Temp\AA585803-L-20220420-1927.log => moved successfully
C:\Windows\Temp\AA585803-L-20220420-2147.log => moved successfully
C:\Windows\Temp\AA585803-L-20220420-2238.log => moved successfully
C:\Windows\Temp\AA585803-L-20220420-2243.log => moved successfully
Could not move "C:\Windows\Temp\AA585803-L-20220420-2306.log" => Scheduled to move on reboot.
C:\Windows\Temp\AdobeARM.log => moved successfully
C:\Windows\Temp\AdobeARM_Helper.log => moved successfully
C:\Windows\Temp\APPX.a4f0_4d_miw030_2n3pvq8p0e.tmp => moved successfully
C:\Windows\Temp\ArmUI.ini => moved successfully
C:\Windows\Temp\chrome_installer.log => moved successfully
C:\Windows\Temp\FXSAPIDebugLogFile.txt => moved successfully
C:\Windows\Temp\FXSTIFFDebugLogFile.txt => moved successfully
C:\Windows\Temp\GoogleDFSSetup_220414230859_20540.log => moved successfully
C:\Windows\Temp\GoogleDFSSetup_220418193331_26016.log => moved successfully
C:\Windows\Temp\mbamiservice.log => moved successfully
C:\Windows\Temp\mb_errors999.log => moved successfully
C:\Windows\Temp\Microsoft_.NET_Runtime_-_5.0.15_(x64)_20220413140333.log => moved successfully
C:\Windows\Temp\Microsoft_.NET_Runtime_-_5.0.15_(x64)_20220413140333_000_dotnet_hostfxr_5.0.15_win_x64.msi.log => moved successfully
C:\Windows\Temp\Microsoft_.NET_Runtime_-_5.0.15_(x64)_20220413140333_001_dotnet_runtime_5.0.15_win_x64.msi.log => moved successfully
C:\Windows\Temp\Microsoft_.NET_Runtime_-_5.0.16_(x64)_20220413140323.log => moved successfully
C:\Windows\Temp\Microsoft_.NET_Runtime_-_5.0.16_(x64)_20220413140323_000_dotnet_runtime_5.0.16_win_x64.msi.log => moved successfully
C:\Windows\Temp\Microsoft_.NET_Runtime_-_5.0.16_(x64)_20220413140323_001_dotnet_hostfxr_5.0.16_win_x64.msi.log => moved successfully
C:\Windows\Temp\Microsoft_.NET_Runtime_-_5.0.16_(x64)_20220413140323_002_dotnet_host_5.0.16_win_x64.msi.log => moved successfully
C:\Windows\Temp\MpCmdRun.log => moved successfully
C:\Windows\Temp\msedge_installer.log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(202204132031341328).log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(2022041320393412F8).log => moved successfully
Could not move "C:\Windows\Temp\officeclicktorun.exe_streamserver(202204202306225414).log" => Scheduled to move on reboot.
C:\Windows\Temp\WER-2992797031-0.sysdata.xml => moved successfully
C:\Windows\Temp\WER-2992797046-0.sysdata.xml => moved successfully
 
========= End -> "C:\Windows\Temp\*.*" ========
 
SystemRestore: => Error: No automatic fix found for this entry.
 
=========== EmptyTemp: ==========
 
BITS transfer queue => 0 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 156837997 B
Java, Flash, Steam htmlcache => 10874081 B
Windows/system/drivers => 9462597 B
Edge => 1366850 B
Chrome => 485995607 B
Firefox => 0 B
Opera => 0 B
 
Temp, IE cache, history, cookies, recent:
Default => 45779 B
ProgramData => 45779 B
Public => 45779 B
systemprofile => 45779 B
systemprofile32 => 45779 B
LocalService => 334491 B
NetworkService => 334491 B
 
Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 20-04-2022 23:12:25)
 
C:\Windows\Temp\AA585803-L-20220420-2306.log => Could not move
C:\Windows\Temp\officeclicktorun.exe_streamserver(202204202306225414).log => Could not move
 
==== End of Fixlog 23:12:25 ====


#8 rockaway1

rockaway1

    Authentic Member

  • Authentic Member
  • PipPip
  • 35 posts

Posted 21 April 2022 - 09:26 AM

ESET found 0 infections

 

4/21/2022 11:22:38 AM
Files scanned: 598965
Detected files: 0
Cleaned files: 0
Total scan time: 00:45:47
Scan status: Finished


#9 Juliet

Juliet

    SuperHelper

  • Retired Classroom Teacher
  • 7,686 posts
  • Interests:Boo!....
  • MVP

Posted 21 April 2022 - 03:31 PM

Looks good

Tell me what the computer is doing now.


Sometimes the angels fly close enough to you that you can hear the flutter of their wings...


MS - MVP Consumer Security 2009 - 2016, WI-MVP 2016-17
Antivirus Scanners Online Scanners Firewalls Slow Computer??

#10 rockaway1

rockaway1

    Authentic Member

  • Authentic Member
  • PipPip
  • 35 posts

Posted 21 April 2022 - 04:01 PM

It appears OK, I havent experienced the issues with Chrome while weve been troubleshooting over the last week or so.

#11 Juliet

Juliet

    SuperHelper

  • Retired Classroom Teacher
  • 7,686 posts
  • Interests:Boo!....
  • MVP

Posted 21 April 2022 - 04:27 PM

Good deal
I think your good to go.

Use this tool to remove quarantined items:

Please download KpRm by Kernel-panik and save to your Desktop.

  • Click on KpRm.exe to run the tool.

Vista/Windows 7/8/10 users right-click and select Run As Administrator.

  • Put a check mark next to these items:

- Delete tools
- Delete now

  • Click the "Run" button.

automatic.png

  • When the tool has finished, it will create and open a log report and delete itself.

~~

  • AdBlock is a browser add-on that blocks annoying banners, pop-ups and video ads.
  • E8I37RF.pngCryptoPrevent places policy restrictions on loading points for ransomware (eg. CryptoWall), helping prevent the execution of malware.
  • EG85Vjt.png Malwarebytes Anti-Exploit (MBAE) is designed to prevent zero-day malware from exploiting vulnerable software.
  • 6YRrgUC.png Malwarebytes Anti-Malware Premium (MBAM) works in real-time along side your Anti-Virus to prevent malware execution.
  • jv4nhMJ.png NoScript is a Firefox add-on that blocks the actions of malicious scripts by using whitelisting and other technology.
  • 3O8r9Uq.png Sandboxie isolates programmes of your choice, preventing files from being written to your HDD unless approved by you.
  • DgW1XL2.png Secunia PSI will scan your computer for vulnerable software that is outdated, and automatically find the latest update for you.
  • j1OLIec.png SpywareBlaster is a form of passive protection, designed to block the actions of malicious websites and tracking cookies.
  • sHjS79L.png Unchecky automatically removes checkmarks for bunlded software in programme installers; helping you avoid adware and PUPs.

For those interested in how to make a backup of your computer
https://forums.malwa...ackup-software/


Sometimes the angels fly close enough to you that you can hear the flutter of their wings...


MS - MVP Consumer Security 2009 - 2016, WI-MVP 2016-17
Antivirus Scanners Online Scanners Firewalls Slow Computer??

#12 Juliet

Juliet

    SuperHelper

  • Retired Classroom Teacher
  • 7,686 posts
  • Interests:Boo!....
  • MVP

Posted 23 April 2022 - 10:08 AM

Glad we could help. SakDYGv.gif
Since this issue appears resolved ... this Topic is closed.


Sometimes the angels fly close enough to you that you can hear the flutter of their wings...


MS - MVP Consumer Security 2009 - 2016, WI-MVP 2016-17
Antivirus Scanners Online Scanners Firewalls Slow Computer??

Related Topics




Also tagged with one or more of these keywords: Chrome shutdown, Black screen

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users