1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

New Need help with Wifi on laptop running Windows 7 Professional

Discussion in 'Virus & Other Malware Removal' started by Goodtaste1892, Jun 20, 2017.

Thread Status:
Not open for further replies.
Advertisement
  1. Goodtaste1892

    Goodtaste1892 Thread Starter

    Joined:
    Jun 20, 2017
    Messages:
    10
    Hello! I am very glad I found you guys yesterday. I was attacked by a bad virus which changed a lot of things in my laptop. After getting rid of it, I could no longer go online. My wifi was gone. I called the tech support of the phone company which gives the internet service since the computer could not find their server and after two guys took care of me it was concluded that the language which told the computer to look for the network was corrupted. We deleted the network and created it again. Now the only way I can go online is by hooking a LAN cable to the back of our modem, the laptop does not recognize it has any WiFi, and it even says that it has no network. It lack any other mode of connectivity that I can rig. I wonder if I should get a small USB router and attach it to the thing. I NEED the internet, I use it ever day.
    I ran antivirus software after talking to the phone company tech and it said I had nothing, still the machine won't work properly. I posted originally in the Networking section and was sent here.
    Can anybody help me? Thank you so very much!


    Tech Support Guy System Info Utility version 1.0.0.4
    OS Version: Microsoft Windows 7 Professional, Service Pack 1, 64 bit
    Processor: Intel(R) Core(TM) i5-5200U CPU @ 2.20GHz, Intel64 Family 6 Model 61 Stepping 4
    Processor Count: 4
    RAM: 6072 Mb
    Graphics Card: Intel(R) HD Graphics 5500, 1024 Mb
    Hard Drives: C: 436 GB (338 GB Free); D: 29 GB (3 GB Free);
    Motherboard: Hewlett-Packard, 8093
    Antivirus: None (I do have Norton Antivirus, I don't know why it did not pick it up)
     
  2. Sponsor

  3. Goodtaste1892

    Goodtaste1892 Thread Starter

    Joined:
    Jun 20, 2017
    Messages:
    10
  4. Goodtaste1892

    Goodtaste1892 Thread Starter

    Joined:
    Jun 20, 2017
    Messages:
    10
    Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 25-06-2017 01
    Ran by Clotilde (administrator) on CLOTILDE-HP (26-06-2017 20:44:47)
    Running from C:\Users\Clotilde\Downloads
    Loaded Profiles: Clotilde (Available Profiles: Clotilde)
    Platform: Windows 7 Professional Service Pack 1 (X64) Language: English (United States)
    Internet Explorer Version 11 (Default browser: IE)
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (Softex Inc.) C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe
    (Intel Corporation) C:\Windows\System32\igfxCUIService.exe
    (Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
    (Microsoft Corporation) C:\Windows\System32\wlanext.exe
    (SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
    (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
    (Intel Corporation) C:\Windows\SysWOW64\esif_uf.exe
    (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
    (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\ibtsiva.exe
    (Microsoft) C:\Program Files\Softland\novaPDF 8\Server\novapdfs.exe
    (Symantec Corporation) C:\Program Files (x86)\Norton Security\Engine\22.9.1.12\ns.exe
    (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
    (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
    (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
    (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
    (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
    (Intel) C:\Program Files\Intel Corporation\USB over IP\bin\UoipService.exe
    (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
    (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
    (Intel Corporation) C:\Windows\Temp\DPTF\esif_assist.exe
    (Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\ClientCore.exe
    (Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe
    (Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
    (Intel Corporation) C:\Windows\System32\igfxEM.exe
    (Intel Corporation) C:\Windows\System32\igfxHK.exe
    (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
    (Microsoft Corporation) C:\Windows\System32\rundll32.exe
    (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
    (SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.11.551\SSScheduler.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP 3D DriveGuard\AccelerometerSt.exe
    (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
    (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
    (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
    (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe
    (CyberLink Corp.) C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe
    (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
    (Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
    (Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
    (Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
    (Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
    (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
    (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
    (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
    () C:\Program Files (x86)\Anvsoft\Syncios\SynciosDeviceService.exe
    () C:\Program Files (x86)\Anvsoft\Syncios\androidnotifier.exe
    () C:\Program Files (x86)\Anvsoft\Syncios\adb.exe
    (Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
    (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWelcome.exe
    (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe
    (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe
    (Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office\WINWORD.EXE
    (Microsoft Corporation) C:\Windows\splwow64.exe
    (Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
    (Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
    (Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
    (Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
    (Microsoft Corporation) C:\Windows\System32\dllhost.exe

    ==================== Registry (Whitelisted) ====================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8459480 2015-03-04] (Realtek Semiconductor)
    HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
    HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2871464 2015-02-13] (Synaptics Incorporated)
    HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176440 2017-01-19] (Apple Inc.)
    HKLM-x32\...\Run: [AccelerometerSysTrayApplet] => C:\Program Files (x86)\Hewlett-Packard\HP 3D DriveGuard\AccelerometerST.exe [127624 2015-01-30] (Hewlett-Packard Company)
    HKLM-x32\...\Run: [HP Quick Launch] => C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [581432 2014-06-09] (Hewlett-Packard Development Company, L.P.)
    HKLM-x32\...\Run: [HPOSD] => C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe [380680 2014-08-20] (Hewlett-Packard Development Company, L.P.)
    HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [296208 2015-05-18] (Intel Corporation)
    HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
    HKLM-x32\...\Run: [] => [X]
    HKLM-x32\...\Run: [Microsoft Works Update Detection] => C:\Program Files (x86)\Common Files\Microsoft Shared\Works Shared\WkUFind.exe [28672 2002-07-16] (Microsoft® Corporation)
    HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [3486520 2017-06-26] (Dropbox, Inc.)
    HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.)
    HKLM-x32\...\Run: [Syncios device service] => C:\Program Files (x86)\Anvsoft\Syncios\SynciosDeviceService.exe [1925136 2016-07-14] ()
    Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
    HKU\S-1-5-21-3234161016-1841907741-4207892495-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8418584 2015-07-17] (Piriform Ltd)
    HKU\S-1-5-21-3234161016-1841907741-4207892495-1001\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [7935768 2015-09-23] (SUPERAntiSpyware)
    HKU\S-1-5-21-3234161016-1841907741-4207892495-1001\...\Run: [Spybot-S&D Cleaning] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [5915776 2016-03-21] (Safer-Networking Ltd.)
    HKU\S-1-5-21-3234161016-1841907741-4207892495-1001\...\Run: [GoogleChromeAutoLaunch_16607C324ED4E596B6395F17C4EFCFF5] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1143640 2017-05-09] (Google Inc.)
    Lsa: [Notification Packages] scecli C:\Program Files\TrueKey\McAfeeTrueKeyPasswordFilter
    ShellIconOverlayIdentifiers: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-06-26] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-06-26] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-06-26] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-06-26] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-06-26] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-06-26] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-06-26] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-06-26] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-06-26] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-06-26] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: [ OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files (x86)\Norton Security\Engine\22.9.1.12\buShell.dll [2017-03-16] (Symantec Corporation)
    ShellIconOverlayIdentifiers: [ OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files (x86)\Norton Security\Engine\22.9.1.12\buShell.dll [2017-03-16] (Symantec Corporation)
    ShellIconOverlayIdentifiers: [ OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files (x86)\Norton Security\Engine\22.9.1.12\buShell.dll [2017-03-16] (Symantec Corporation)
    ShellIconOverlayIdentifiers-x32: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-06-26] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-06-26] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-06-26] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-06-26] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-06-26] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-06-26] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-06-26] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-06-26] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-06-26] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-06-26] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [ OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files (x86)\Norton Security\Engine32\22.9.1.12\buShell.dll [2017-03-16] (Symantec Corporation)
    ShellIconOverlayIdentifiers-x32: [ OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files (x86)\Norton Security\Engine32\22.9.1.12\buShell.dll [2017-03-16] (Symantec Corporation)
    ShellIconOverlayIdentifiers-x32: [ OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files (x86)\Norton Security\Engine32\22.9.1.12\buShell.dll [2017-03-16] (Symantec Corporation)
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2017-05-13]
    ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.551\SSScheduler.exe (McAfee, Inc.)
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk [2015-08-16]
    ShortcutTarget: Microsoft Office.lnk -> C:\Program Files (x86)\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)

    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
    Tcpip\Parameters: [DhcpNameServer] 192.168.254.254
    Tcpip\..\Interfaces\{2E0FBAF7-F609-4654-BB40-E540844808C8}: [DhcpNameServer] 192.168.254.254
    Tcpip\..\Interfaces\{5B2D7231-D837-430A-89C4-D25A80A7D10D}: [DhcpNameServer] 192.168.254.254

    Internet Explorer:
    ==================
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp13.msn.com
    HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp13.msn.com
    HKU\S-1-5-21-3234161016-1841907741-4207892495-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp13.msn.com
    HKU\S-1-5-21-3234161016-1841907741-4207892495-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://js.redirect.hp.com/jumpstation?bd=all&c=144&locale=ww_ww&pf=cnnb&s=ieHPtab&tp=iehome
    SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKLM -> OldSearch URL =
    SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKLM-x32 -> {87C4DFC6-8FE5-47E4-8807-72EBDF32E200} URL = hxxp://www.amazon.com/s/ref=azs_osd_iea?ie=UTF-8&tag=hp-us2-vsb-20&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
    SearchScopes: HKU\S-1-5-21-3234161016-1841907741-4207892495-1001 -> {85A60A59-D3D8-468F-B598-FB4393789EF4} URL = hxxps://www.google.com/search?q={searchTerms}
    SearchScopes: HKU\S-1-5-21-3234161016-1841907741-4207892495-1001 -> {87C4DFC6-8FE5-47E4-8807-72EBDF32E200} URL = hxxp://www.amazon.com/s/ref=azs_osd_iea?ie=UTF-8&tag=hp-us2-vsb-20&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
    BHO: True Key Helper -> {0F4B8786-5502-4803-8EBC-F652A1153BB6} -> C:\Program Files\Intel Security\True Key\MSIE\truekey_ie64.dll [2017-04-26] (Intel Security)
    BHO: Norton Identity Safety -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton Security\Engine\22.9.1.12\coIEPlg.dll [2017-03-16] (Symantec Corporation)
    BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
    BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-07-25] (Google Inc.)
    BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2013-08-28] (Hewlett-Packard)
    BHO-x32: True Key Helper -> {0F4B8786-5502-4803-8EBC-F652A1153BB6} -> C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll [2017-04-26] (Intel Security)
    BHO-x32: Norton Identity Safety -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton Security\Engine32\22.9.1.12\coIEPlg.dll [2017-03-16] (Symantec Corporation)
    BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
    BHO-x32: Evernote extension -> {92EF2EAD-A7CE-4424-B0DB-499CF856608E} -> C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll [2014-12-17] (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
    BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-07-25] (Google Inc.)
    BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2013-08-28] (Hewlett-Packard)
    Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-07-25] (Google Inc.)
    Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Security\Engine\22.9.1.12\coIEPlg.dll [2017-03-16] (Symantec Corporation)
    Toolbar: HKLM - True Key - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie64.dll [2017-04-26] (Intel Security)
    Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Security\Engine32\22.9.1.12\coIEPlg.dll [2017-03-16] (Symantec Corporation)
    Toolbar: HKLM-x32 - True Key - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll [2017-04-26] (Intel Security)
    Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-07-25] (Google Inc.)
    Toolbar: HKU\S-1-5-21-3234161016-1841907741-4207892495-1001 -> Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Security\Engine\22.9.1.12\coIEPlg.dll [2017-03-16] (Symantec Corporation)

    FireFox:
    ========
    FF DefaultProfile: ilensolw.default
    FF ProfilePath: C:\Users\Clotilde\AppData\Roaming\Mozilla\Firefox\Profiles\ilensolw.default [2017-06-26]
    FF DefaultSearchEngine: Mozilla\Firefox\Profiles\ilensolw.default -> Bing®
    FF DefaultSearchEngine.US: Mozilla\Firefox\Profiles\ilensolw.default -> Google
    FF SelectedSearchEngine: Mozilla\Firefox\Profiles\ilensolw.default -> Bing®
    FF Extension: (Avira Browser Safety) - C:\Users\Clotilde\AppData\Roaming\Mozilla\Firefox\Profiles\ilensolw.default\Extensions\[email protected] [2017-04-25]
    FF Extension: (Norton Identity Safe) - C:\Users\Clotilde\AppData\Roaming\Mozilla\Firefox\Profiles\ilensolw.default\Extensions\[email protected] [2017-03-15]
    FF Extension: (Save Button for Pinterest) - C:\Users\Clotilde\AppData\Roaming\Mozilla\Firefox\Profiles\ilensolw.default\Extensions\{677a8f98-fd64-40b0-a883-b8c95d0cbf17}.xpi [2017-05-15]
    FF HKLM\...\Firefox\Extensions: [{C1A2A613-35F1-4FCF-B27F-2840527B6556}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NS_22.6.0.142\coFFAddon
    FF Extension: (Norton Security Toolbar) - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NS_22.6.0.142\coFFAddon [2017-06-25]
    FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files\Hewlett-Packard\SimplePass\FFBHOExt
    FF Extension: (HP SimplePass) - C:\Program Files\Hewlett-Packard\SimplePass\FFBHOExt [2015-06-12] [not signed]
    FF HKLM-x32\...\Firefox\Extensions: [{C1A2A613-35F1-4FCF-B27F-2840527B6556}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NS_22.6.0.142\coFFAddon
    FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
    FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
    FF Plugin: @videolan.org/vlc,version=2.2.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
    FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1217157.dll [2015-02-05] (Adobe Systems, Inc.)
    FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2014-10-20] (Foxit Corporation)
    FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2014-10-20] (Foxit Corporation)
    FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xdp -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2014-10-20] (Foxit Corporation)
    FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2014-10-20] (Foxit Corporation)
    FF Plugin-x32: @Intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.56 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2014-11-10] (Intel Corporation)
    FF Plugin-x32: @Intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2014-11-10] (Intel Corporation)
    FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
    FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
    FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-27] (Google Inc.)
    FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-27] (Google Inc.)
    FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-04-04] (Adobe Systems Inc.)

    Chrome:
    =======
    CHR HomePage: Default -> hxxp://www.mozilla.com/en-US/firefox/central/
    CHR StartupUrls: Default -> "hxxp://www.google.com/","hxxp://mysearch.avg.com/?cid={98A9DCF9-23B7-4499-BFAE-BD7DDE2C274C}&mid=492c8b23105647d3a655d1565033bcec-6f585ccd9e409817ae25410f8ae9b323b5b65e9e&lang=en&ds=co012&pr=sa&d=2013-09-15 14:17:53&v=15.4.0.5&pid=safeguard&sg=0&sap=hp"
    CHR Profile: C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default [2017-06-26]
    CHR Extension: (Google Slides) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-08-17]
    CHR Extension: (3DTin) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\algoakekcdmbbikdjgjdahbfihboglmi [2015-08-17]
    CHR Extension: (Google Docs) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-08-17]
    CHR Extension: (Google Drive) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-19]
    CHR Extension: (UJAM - Make your music.) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdiogojbmdncjdpljocafnigiokgmci [2015-08-17]
    CHR Extension: (BeFunky Photo Editor) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\apfkepiiddolifkgjmfdgpnipgnfejab [2015-08-17]
    CHR Extension: (Audiense) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\bagknoiagpifjfbempgignagkejmkljm [2016-03-10]
    CHR Extension: (Hootsuite Hootlet) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\bjgfdlplhmndoonmofmflcbiohgbkifn [2016-09-20]
    CHR Extension: (Audiotool) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkgoccjhfjgjedhkiefaclppgbmoobnk [2015-08-17]
    CHR Extension: (YouTube) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-23]
    CHR Extension: (Fancy) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\cehbnekkmkknacpgjlpcilfbckclafki [2015-08-17]
    CHR Extension: (AddThis - Share & Bookmark (new)) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgbogdmdefihhljhfeiklfiedefalcde [2016-01-16]
    CHR Extension: (QR Code Generator - 1 click to Create QR Code) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\cicimfkkbejhggfjaabggafffgdnjgjp [2017-06-26]
    CHR Extension: (Norton Security Toolbar) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjabmdjcfcfdmffimndhafhblfmpjdpe [2017-06-26]
    CHR Extension: (Google Search) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-26]
    CHR Extension: (Email this page (by Google)) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\dbeoemfhkdniadbojeencpkgmobndpai [2015-08-17]
    CHR Extension: (rotoscope) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhimnnhmaanmanmmokfpijgambokcpni [2015-08-17]
    CHR Extension: (Sumo Paint) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\dpgjihldbpodlmnjolekemlfbcajnmod [2015-08-17]
    CHR Extension: (Button for Pinterest™) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\fbfjhllmkehmdajjlkolhdjjlfcmmlpl [2016-09-01]
    CHR Extension: (Google Sheets) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-08-17]
    CHR Extension: (Sprout Social) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\ffiilepjogcpodmgneknklaecmeoenbc [2015-08-17]
    CHR Extension: (PicMonkey) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\fgdgokchhicmaiacmgegjnppjkgogdhm [2016-06-07]
    CHR Extension: (Virtual Piano Black) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjagcpcbacoaogfljhglghpjhkmmfeeo [2015-08-17]
    CHR Extension: (Stupeflix Video Maker) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkdmcfnoimoilncpjchamnenebopocem [2015-08-17]
    CHR Extension: (Nice Tumblr) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\fpfdfdgcjljkdijjbaipabnalhakbcok [2015-08-17]
    CHR Extension: (Collect images on Indulgy.com) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\gegdkoobknknikkhmnbkpnejehkchcom [2015-08-17]
    CHR Extension: (Google Docs Offline) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-14]
    CHR Extension: (SwagButton) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\gngocbkfmikdgphklgmmehbjjlfgdemm [2017-06-26]
    CHR Extension: (Pinterest Save Button) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpdjojdkbbmdfjfahjcgigfpmkopogic [2017-04-22]
    CHR Extension: (Marqueed Web App) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbbhliifccolgoaijmaielecailmjnoo [2015-08-17]
    CHR Extension: (FabCam) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\hejilffmihldhlfocnabcgndjjpgadfl [2015-08-17]
    CHR Extension: (Pixlr Express) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\hojmjpdlmjopaeginhldhiokeidchjid [2015-08-17]
    CHR Extension: (Kindle Cloud Reader) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdipabjmbhpdkjaihfjoikhjjeneebd [2017-04-19]
    CHR Extension: (Norton Identity Safe) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\iikflkcanblccfahdhdonehdalibjnif [2016-07-03]
    CHR Extension: (Glitterboo) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\ikkpgihagilojnkmkkfcbhlainmnkicp [2016-11-06]
    CHR Extension: (iPiccy Photo Editor) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\imokeandodnlammaoenbgcnbhigjbpjh [2015-08-17]
    CHR Extension: (Shareaholic for Google Chrome™) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbmipnjdeifmobkhgogdnomkihhgojep [2015-08-17]
    CHR Extension: (StumbleBar by StumbleUpon) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcahibnffhnnjcedflmchmokndkjnhpg [2017-06-26]
    CHR Extension: (Hootsuite) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\kneloppijbcidgidihgdjnooihjcdbij [2015-08-17]
    CHR Extension: (Pix: Pixel Mixer) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbjiacdnbellpbhocabghholhnlboibg [2015-08-17]
    CHR Extension: (Polyvore Clipper) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\liilchbbmdohoilfeonmdpcbhpekaiac [2015-08-17]
    CHR Extension: (Wordtracker Scout) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkalodfoplipapmeogaehmiabdhhjapb [2015-08-17]
    CHR Extension: (AudioSauna) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkgfemnodkdnenmfkblebnkjpckkjcae [2015-08-17]
    CHR Extension: (Buffer) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjojodpkaeeclkgaidibcbknlhjflhle [2015-08-17]
    CHR Extension: (Chrome Web Store Payments) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-08]
    CHR Extension: (GIFPAL) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\noohoboklgjeccnihfkbdakbchbhjlch [2015-08-17]
    CHR Extension: (Buffer) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\noojglkidnpfjbincgijbaiedldjfbhh [2017-06-26]
    CHR Extension: (piZap Photo Editor) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\occpjibghkbopohbefbejkklnfdkdmok [2015-08-17]
    CHR Extension: (WiseStamp - Email Signatures for Gmail) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbcgnkmbeodkmiijjfnliicelkjfcldg [2017-05-15]
    CHR Extension: (Psykopaint) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgjchkcfmigkkhedgjedmffdepgmpfil [2015-08-17]
    CHR Extension: (Gmail) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-08-17]
    CHR Extension: (Chrome Media Router) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-05-17]
    CHR HKLM\...\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files (x86)\Norton Security\Engine\22.9.1.12\Exts\Chrome.crx <not found>
    CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files (x86)\Norton Security\Engine\22.9.1.12\Exts\Chrome.crx <not found>
    CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx

    ==================== Services (Whitelisted) ====================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [172344 2014-07-22] (SUPERAntiSpyware.com)
    R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-09-22] (Apple Inc.)
    S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-03] (Dropbox, Inc.)
    S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-03] (Dropbox, Inc.)
    R2 DbxSvc; C:\Windows\system32\DbxSvc.exe [49992 2017-06-26] (Dropbox, Inc.)
    R2 esifsvc; C:\Windows\SysWOW64\esif_uf.exe [1037568 2015-05-18] (Intel Corporation)
    R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [18584 2014-10-09] (Intel Corporation)
    R2 iBtSiva; C:\Program Files (x86)\Intel\Bluetooth\ibtsiva.exe [124520 2014-12-13] (Intel Corporation)
    R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [344168 2015-05-18] (Intel Corporation)
    S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [887256 2014-05-13] (Intel(R) Corporation)
    R2 IntelUSBoverIP; C:\Program Files\Intel Corporation\USB over IP\bin\UoipService.exe [395744 2015-01-14] (Intel)
    R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [158496 2014-11-10] (Intel Corporation)
    S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.551\McCHSvc.exe [404376 2017-04-17] (McAfee, Inc.)
    S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [268192 2015-03-04] ()
    R2 NovaPdfServer; C:\Program Files\Softland\novaPDF 8\Server\novapdfs.exe [41760 2015-07-14] (Microsoft)
    R2 NS; C:\Program Files (x86)\Norton Security\Engine\22.9.1.12\NS.exe [326160 2017-03-16] (Symantec Corporation)
    R2 omniserv; C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe [103424 2015-01-30] (Softex Inc.) [File not signed]
    R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [293080 2015-03-04] (Realtek Semiconductor)
    S2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
    R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [4088608 2016-09-21] (Safer-Networking Ltd.) [File not signed]
    R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [235984 2016-11-24] (Safer-Networking Ltd.) [File not signed]
    R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [220840 2015-02-13] (Synaptics Incorporated)
    S2 TrueKey; C:\Program Files\TrueKey\McAfee.TrueKey.Service.exe [996736 2017-04-18] (McAfee, Inc.)
    S2 TrueKeyScheduler; C:\Program Files\TrueKey\McTkSchedulerService.exe [16160 2017-04-18] (McAfee, Inc.)
    S3 TrueKeyServiceHelper; C:\Program Files\TrueKey\McAfee.TrueKey.ServiceHelper.exe [86776 2017-04-18] (McAfee, Inc.)
    S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)
    R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3820960 2015-03-04] (Intel® Corporation)
    S2 InstallerService; C:\Program Files\TrueKey\Mcafee.TrueKey.InstallerService.exe -originalversion 4.4.127.0 [X]

    ===================== Drivers (Whitelisted) ======================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    S1 BHDrvx64; C:\Program Files (x86)\Norton Security\NortonData\22.6.0.142\Definitions\BASHDefs\20170516.001\BHDrvx64.sys [1831064 2017-04-06] (Symantec Corporation)
    S3 btmaux; C:\Windows\System32\DRIVERS\btmaux.sys [141624 2014-10-28] (Motorola Solutions, Inc.)
    S3 btmhsf; C:\Windows\System32\DRIVERS\btmhsf.sys [1448248 2014-11-26] (Motorola Solutions, Inc.)
    S3 btmlehid; C:\Windows\system32\drivers\btmlehid.sys [83768 2014-11-05] (Motorola Solutions, Inc.)
    R1 ccSet_NS; C:\Windows\system32\drivers\NSx64\1609010.00C\ccSetx64.sys [174240 2017-02-20] (Symantec Corporation)
    R1 CLVirtualDrive; C:\Windows\System32\DRIVERS\CLVirtualDrive.sys [91912 2013-11-12] (CyberLink)
    R3 dptf_cpu; C:\Windows\System32\DRIVERS\dptf_cpu.sys [38720 2015-05-18] (Intel Corporation)
    R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [507032 2017-05-09] (Symantec Corporation)
    R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [156824 2017-05-09] (Symantec Corporation)
    R3 esif_lf; C:\Windows\System32\DRIVERS\esif_lf.sys [216360 2015-05-18] (Intel Corporation)
    R0 iaStorF; C:\Windows\System32\drivers\iaStorF.sys [30360 2014-10-09] (Intel Corporation)
    S3 ibtusb; C:\Windows\System32\DRIVERS\ibtusb.sys [230128 2014-12-03] (Intel Corporation)
    R1 IDSVia64; C:\Program Files (x86)\Norton Security\NortonData\22.6.0.142\Definitions\IPSDefs\20170519.001\IDSvia64.sys [1053824 2017-05-20] (Symantec Corporation)
    R3 MEIx64; C:\Windows\system32\drivers\TeeDriverx64.sys [129312 2014-11-10] (Intel Corporation)
    R3 NETwNs64; C:\Windows\System32\DRIVERS\Netwsw02.sys [3429656 2015-03-04] (Intel Corporation)
    S3 RTSPER; C:\Windows\System32\DRIVERS\RtsPer.sys [781528 2015-03-03] (Realsil Semiconductor Corporation)
    S3 RTSUER; C:\Windows\system32\Drivers\RtsUer.sys [377048 2015-03-03] (Realsil Semiconductor Corporation)
    R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
    R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
    S3 SmbDrv; C:\Windows\system32\drivers\Smb_driver_AMDASF.sys [33448 2015-02-13] (Synaptics Incorporated)
    R3 SmbDrvI; C:\Windows\system32\drivers\Smb_driver_Intel.sys [33448 2015-02-13] (Synaptics Incorporated)
    R1 SRTSP; C:\Windows\System32\Drivers\NSx64\1609010.00C\SRTSP64.SYS [770200 2017-03-16] (Symantec Corporation)
    R1 SRTSPX; C:\Windows\system32\drivers\NSx64\1609010.00C\SRTSPX64.SYS [49312 2017-03-16] (Symantec Corporation)
    R0 SymEFASI; C:\Windows\System32\drivers\NSx64\1609010.00C\SYMEFASI64.SYS [1716896 2017-02-20] (Symantec Corporation)
    R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [102608 2017-03-07] (Symantec Corporation)
    R1 SymIRON; C:\Windows\system32\drivers\NSx64\1609010.00C\Ironx64.SYS [291480 2017-02-20] (Symantec Corporation)
    R1 SymNetS; C:\Windows\System32\Drivers\NSx64\1609010.00C\SYMNETS.SYS [567512 2017-02-20] (Symantec Corporation)
    R3 usb3Hub; C:\Windows\System32\DRIVERS\usb3Hub.sys [212056 2015-01-14] (Windows (R) Win 7 DDK provider)
    S3 dbx; system32\DRIVERS\dbx.sys [X]
    S3 NAVENG; \??\C:\Program Files (x86)\Norton Security\NortonData\22.6.0.142\Definitions\SDSDefs\20160714.009\ENG64.SYS [X]
    S3 NAVEX15; \??\C:\Program Files (x86)\Norton Security\NortonData\22.6.0.142\Definitions\SDSDefs\20160714.009\EX64.SYS [X]
    S3 NPF; system32\drivers\NPF.sys [X]

    ==================== NetSvcs (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


    ==================== One Month Created files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2017-06-26 20:44 - 2017-06-26 20:47 - 00042403 _____ C:\Users\Clotilde\Downloads\FRST.txt
    2017-06-26 20:44 - 2017-06-26 20:44 - 00000000 ____D C:\FRST
    2017-06-26 20:43 - 2017-06-26 20:43 - 02441216 _____ (Farbar) C:\Users\Clotilde\Downloads\FRST64.exe
    2017-06-26 20:39 - 2017-06-26 20:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
    2017-06-26 19:55 - 2017-06-26 19:55 - 00000000 ____H C:\Users\Clotilde\AppData\Local\BIT6E5.tmp
    2017-06-26 19:54 - 2017-06-26 19:54 - 00000000 _____ C:\Users\Clotilde\AppData\Local\{A80A0140-647F-45FB-BEC3-F54EF6A5506C}
    2017-06-26 03:27 - 2017-06-26 03:27 - 00049992 _____ (Dropbox, Inc.) C:\Windows\system32\DbxSvc.exe
    2017-06-26 03:27 - 2017-06-26 03:27 - 00045640 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-stable.sys
    2017-06-26 03:27 - 2017-06-26 03:27 - 00045640 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-dev.sys
    2017-06-26 03:27 - 2017-06-26 03:27 - 00045640 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-canary.sys
    2017-06-25 22:32 - 2017-06-25 22:32 - 00082773 _____ C:\Users\Clotilde\.recently-used.xbel
    2017-06-24 21:59 - 2017-06-24 21:59 - 00000000 _____ C:\Users\Clotilde\AppData\Local\{7DB36966-0951-4270-AE0A-546CA4B3D61C}
    2017-06-24 21:57 - 2017-06-24 21:57 - 00000000 _____ C:\Users\Clotilde\AppData\Local\{FC8B0682-13E7-4663-9087-AEB2F7AE0FA2}
    2017-06-24 21:51 - 2017-06-24 21:51 - 00000000 _____ C:\Users\Clotilde\AppData\Local\{D40B59C7-2736-49C3-A0CD-DF91DB47961A}
    2017-06-24 21:50 - 2017-06-24 21:50 - 00000000 _____ C:\Users\Clotilde\AppData\Local\{65A86BB1-9895-4CE6-9F2D-A8AF7401182D}
    2017-06-24 21:50 - 2017-06-24 21:50 - 00000000 _____ C:\Users\Clotilde\AppData\Local\{641310F6-A324-43EA-A7FA-EC07B79A31CF}
    2017-06-23 17:14 - 2017-06-23 17:14 - 00014211 _____ C:\Users\Clotilde\Documents\Windows 7 No internet Access but network connected .txt
    2017-06-14 21:34 - 2017-06-14 21:34 - 03390359 _____ C:\Users\Clotilde\Downloads\Edison-His-Life-and-Inventions.pdf
    2017-06-12 01:10 - 2017-06-12 01:10 - 01291080 _____ C:\Users\Clotilde\Downloads\Product Launching Made Simple Workbook.pdf
    2017-06-08 22:18 - 2017-06-08 22:18 - 00000000 _____ C:\Users\Clotilde\AppData\Local\{9ECE6F41-E4BC-4056-A587-9EAC78722A7A}
    2017-06-08 22:16 - 2017-06-08 22:16 - 00000000 _____ C:\Users\Clotilde\AppData\Local\{8ED71472-C0CC-4D61-B296-D4A135F3AB52}
    2017-06-07 23:56 - 2017-06-07 23:56 - 00000000 _____ C:\Users\Clotilde\AppData\Local\{EF55D457-75D3-4CC4-BFEA-F8D6086B8C11}
    2017-06-07 23:54 - 2017-06-07 23:54 - 00000000 _____ C:\Users\Clotilde\AppData\Local\{C7F8DAC9-6CDC-4B1B-B39A-A36A0AF80E72}
    2017-06-07 05:58 - 2017-06-07 05:58 - 00000384 _____ C:\Users\Clotilde\Documents\To make your own garbanzo nuts.txt
    2017-06-06 05:34 - 2017-06-06 05:34 - 00052857 _____ C:\Users\Clotilde\AppData\Local\recently-used.xbel
    2017-05-31 10:16 - 2017-05-31 10:16 - 00000000 _____ C:\Users\Clotilde\AppData\Local\{C64C9F1B-78EC-41D8-824E-EECDE4BD0643}
    2017-05-31 09:01 - 2017-05-31 09:01 - 00192973 _____ C:\Users\Clotilde\Downloads\archive (1).zip
    2017-05-31 09:00 - 2017-05-31 09:00 - 00192973 _____ C:\Users\Clotilde\Downloads\archive.zip
    2017-05-31 02:30 - 2017-05-31 02:55 - 00000376 _____ C:\Users\Clotilde\Documents\Growing Gum Tissue Is Easy.txt
    2017-05-29 04:44 - 2017-06-06 08:23 - 03575660 _____ C:\Users\Clotilde\Documents\Zuri The Female Rhino.pdf
    2017-05-29 04:18 - 2017-05-29 04:18 - 03575294 _____ C:\Users\Clotilde\Documents\Zuri The Female Rhino2.pdf
    2017-05-28 07:52 - 2017-05-28 07:52 - 00541553 _____ C:\Users\Clotilde\Downloads\FDS-Valentine-Sticker-Hearts (1).zip
    2017-05-28 07:51 - 2017-05-28 07:52 - 36026628 _____ C:\Users\Clotilde\Downloads\mls-wlsnsd17mini.zip
    2017-05-28 07:50 - 2017-05-28 07:51 - 02559358 _____ C:\Users\Clotilde\Downloads\ink-stained-hearts.zip
    2017-05-28 07:50 - 2017-05-28 07:50 - 02066812 _____ C:\Users\Clotilde\Downloads\FDS-Star-Stamps (1).zip
    2017-05-28 03:35 - 2017-05-28 03:35 - 00000205 _____ C:\Users\Clotilde\Documents\joint pain release and relief.txt
    2017-05-27 06:32 - 2017-05-27 10:40 - 00040423 _____ C:\Users\Clotilde\Documents\antiwrinkle ferulic acid ceramides rice bran oil.txt

    ==================== One Month Modified files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2017-06-26 20:40 - 2015-07-31 10:27 - 00000000 ____D C:\Program Files (x86)\Dropbox
    2017-06-26 20:15 - 2015-08-18 01:10 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
    2017-06-26 20:11 - 2009-07-13 21:45 - 00035632 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2017-06-26 20:11 - 2009-07-13 21:45 - 00035632 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2017-06-26 20:06 - 2015-08-19 00:43 - 00000912 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job
    2017-06-26 20:04 - 2015-08-16 01:32 - 00000000 ____D C:\Users\Clotilde\Documents\Youcam
    2017-06-26 20:03 - 2015-08-19 00:43 - 00000908 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job
    2017-06-26 20:03 - 2015-08-16 01:31 - 00000000 __SHD C:\Users\Clotilde\IntelGraphicsProfiles
    2017-06-26 19:59 - 2009-07-13 22:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
    2017-06-26 19:56 - 2016-01-16 02:03 - 00000000 ____D C:\AdwCleaner
    2017-06-25 23:54 - 2016-08-20 03:26 - 00000000 ____D C:\Program Files\TrueKey
    2017-06-25 23:52 - 2015-08-16 01:30 - 00000000 ____D C:\Users\Clotilde
    2017-06-25 23:51 - 2017-05-13 05:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
    2017-06-25 23:51 - 2017-05-13 05:08 - 00000000 ____D C:\Program Files\McAfee Security Scan
    2017-06-25 23:51 - 2017-05-13 05:07 - 00000000 ____D C:\ProgramData\McAfee Security Scan
    2017-06-25 23:51 - 2017-03-08 01:05 - 00000000 ____D C:\Windows\System32\Tasks\Norton Security
    2017-06-25 23:51 - 2017-01-25 07:32 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
    2017-06-25 23:51 - 2016-12-05 04:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
    2017-06-25 23:51 - 2016-12-05 04:28 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
    2017-06-25 23:51 - 2016-08-16 07:05 - 00000000 ____D C:\Users\Clotilde\.android
    2017-06-25 23:51 - 2016-07-03 03:46 - 00000000 ____D C:\Windows\System32\Tasks\Remediation
    2017-06-25 23:51 - 2016-07-03 03:46 - 00000000 ____D C:\Program Files\Common Files\AV
    2017-06-25 23:51 - 2016-07-03 03:43 - 00000000 ____D C:\Program Files\Common Files\Symantec Shared
    2017-06-25 23:51 - 2016-07-03 03:41 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Security
    2017-06-25 23:51 - 2016-07-03 03:41 - 00000000 ____D C:\Windows\system32\Drivers\NSx64
    2017-06-25 23:51 - 2016-07-03 03:41 - 00000000 ____D C:\Program Files (x86)\Norton Security
    2017-06-25 23:51 - 2016-07-03 03:25 - 00000000 ____D C:\ProgramData\Norton
    2017-06-25 23:51 - 2015-09-22 06:42 - 00000000 ____D C:\Users\Clotilde\AppData\Roaming\gtk-2.0
    2017-06-25 23:51 - 2015-08-19 00:54 - 00000000 ____D C:\Users\Clotilde\AppData\Roaming\IrfanView
    2017-06-25 23:51 - 2015-08-18 01:10 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
    2017-06-25 23:51 - 2015-08-17 01:44 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
    2017-06-25 23:51 - 2015-07-31 10:25 - 00000000 ___RD C:\Users\Public\Recorded TV
    2017-06-25 23:51 - 2015-07-31 10:12 - 00000000 ___HD C:\Windows\system32\WLANProfiles
    2017-06-25 23:51 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\SysWOW64\migwiz
    2017-06-25 23:51 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\system32\NDF
    2017-06-25 23:51 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\system32\Msdtc
    2017-06-25 23:51 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\system32\migwiz
    2017-06-25 23:51 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\PolicyDefinitions
    2017-06-25 23:51 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\inf
    2017-06-25 23:51 - 2009-07-13 20:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
    2017-06-25 23:49 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\registration
    2017-06-25 23:47 - 2015-08-17 00:54 - 00000000 ____D C:\Users\Clotilde\AppData\Local\Google
    2017-06-25 23:20 - 2015-08-18 04:29 - 00890217 _____ C:\Users\Clotilde\Documents\sunglow.txt
    2017-06-25 22:35 - 2015-09-22 06:32 - 00000000 ____D C:\Users\Clotilde\.gimp-2.6
    2017-06-23 02:42 - 2015-08-18 02:21 - 00000000 ____D C:\Users\Clotilde\Documents\crochet
    2017-06-22 20:51 - 2015-08-25 04:23 - 00000000 ____D C:\Users\Clotilde\Documents\sayings and quotes to copy
    2017-06-22 18:49 - 2015-08-18 04:11 - 00027569 _____ C:\Users\Clotilde\Documents\maranata.txt
    2017-06-21 16:49 - 2015-08-18 03:16 - 00040743 _____ C:\Users\Clotilde\Documents\dog and kitty names.txt
    2017-06-20 18:02 - 2017-01-03 00:30 - 00000000 ____D C:\Windows\system32\MRT
    2017-06-19 22:27 - 2017-02-14 09:50 - 00000000 ____D C:\Users\Clotilde\AppData\LocalLow\Mozilla
    2017-06-19 20:46 - 2016-07-03 07:04 - 00000000 ____D C:\Users\Clotilde\AppData\Local\CrashDumps
    2017-06-18 23:35 - 2015-08-18 03:44 - 00154232 _____ C:\Users\Clotilde\Documents\How to create great tag lines.txt
    2017-06-14 17:09 - 2015-08-19 00:42 - 00000000 ____D C:\Users\Clotilde\AppData\Local\Dropbox
    2017-06-13 17:44 - 2016-08-20 03:39 - 00000000 ____D C:\Program Files (x86)\McAfee
    2017-06-13 02:47 - 2016-08-11 21:45 - 00000000 ____D C:\Users\Clotilde\Documents\craftybegonia business
    2017-06-11 09:47 - 2015-08-18 04:12 - 00007518 _____ C:\Users\Clotilde\Documents\names for my scarfs.txt
    2017-06-10 08:41 - 2017-02-16 01:23 - 00028702 _____ C:\Users\Clotilde\Documents\make wrinkles disappear antiaging antiwrinkle.txt
    2017-06-08 09:06 - 2016-04-28 03:42 - 00022229 _____ C:\Users\Clotilde\Documents\How to Tighten Sagging Skin on Face.txt
    2017-06-03 10:30 - 2015-08-25 04:13 - 00000000 ____D C:\Users\Clotilde\Documents\All Dolls
    2017-06-01 10:13 - 2015-08-18 01:31 - 00141453 _____ C:\Users\Clotilde\Documents\Anti wrinkle essential oil formula.txt
    2017-06-01 08:26 - 2016-10-01 06:38 - 00184320 ___SH C:\Users\Clotilde\Thumbs.db
    2017-05-31 10:06 - 2017-05-18 10:05 - 00002832 _____ C:\Users\Clotilde\Documents\Avocado Seed Anti Aging Antioxidants and for warts.txt
    2017-05-29 09:17 - 2015-11-23 07:52 - 00000000 ____D C:\Users\Clotilde\Documents\gemstones for scrapbooking embellishments
    2017-05-29 05:31 - 2016-02-29 06:41 - 00017064 _____ C:\Users\Clotilde\Documents\remedies for melasma and brown spots.txt
    2017-05-29 03:38 - 2017-05-25 07:55 - 19032064 ____H C:\Users\Clotilde\Documents\~WRL1670.tmp
    2017-05-29 02:57 - 2017-05-25 07:55 - 16524800 ____H C:\Users\Clotilde\Documents\~WRL0655.tmp
    2017-05-29 02:56 - 2017-05-25 07:55 - 14428672 ____H C:\Users\Clotilde\Documents\~WRL3781.tmp
    2017-05-29 02:56 - 2017-05-25 07:55 - 12129280 ____H C:\Users\Clotilde\Documents\~WRL2805.tmp
    2017-05-29 02:47 - 2017-05-25 07:55 - 09085952 ____H C:\Users\Clotilde\Documents\~WRL0436.tmp
    2017-05-29 00:51 - 2017-05-25 07:55 - 02675200 ____H C:\Users\Clotilde\Documents\~WRL3906.tmp
    2017-05-29 00:49 - 2017-05-25 07:55 - 00040448 ____H C:\Users\Clotilde\Documents\~WRL3818.tmp
    2017-05-29 00:27 - 2017-05-25 07:55 - 00040448 ____H C:\Users\Clotilde\Documents\~WRL3785.tmp

    ==================== Files in the root of some directories =======

    2015-08-18 02:33 - 2017-02-14 08:21 - 0007480 _____ () C:\Users\Clotilde\AppData\Roaming\mainhst.zgh
    2015-08-16 02:22 - 1996-12-09 00:00 - 0000002 _____ () C:\Users\Clotilde\AppData\Roaming\Microsoft\ArtGalry.cag
    2016-01-14 05:03 - 2016-09-18 00:21 - 0119649 _____ () C:\Users\Clotilde\AppData\Local\ars.cache
    2017-06-26 19:55 - 2017-06-26 19:55 - 0000000 ____H () C:\Users\Clotilde\AppData\Local\BIT6E5.tmp
    2016-01-14 05:05 - 2016-09-18 00:22 - 1147695 _____ () C:\Users\Clotilde\AppData\Local\census.cache
    2016-01-14 04:33 - 2016-01-14 04:33 - 0000036 _____ () C:\Users\Clotilde\AppData\Local\housecall.guid.cache
    2017-06-06 05:34 - 2017-06-06 05:34 - 0052857 _____ () C:\Users\Clotilde\AppData\Local\recently-used.xbel
    2016-01-14 05:00 - 2016-09-18 00:02 - 0000010 _____ () C:\Users\Clotilde\AppData\Local\sponge.last.runtime.cache
    2017-03-12 08:30 - 2017-03-12 08:30 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{07714512-AE7E-473E-B700-D563215B2695}
    2016-12-05 01:35 - 2016-12-05 01:35 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{1317ECBA-05CD-409F-91D9-4C879B67F2F2}
    2017-02-16 09:59 - 2017-02-16 09:59 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{19003E94-8559-4EA1-A92B-3E9E21B905ED}
    2017-01-22 01:47 - 2017-01-22 01:47 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{1D57D9A3-D130-4B26-9D7D-7F39794EBAED}
    2017-03-19 22:37 - 2017-03-19 22:37 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{237E9194-68C3-473F-9703-A65E0E7337D0}
    2017-03-19 22:35 - 2017-03-19 22:35 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{23E83A05-DA8A-4AC6-92BC-626E70EA71D7}
    2017-02-08 10:49 - 2017-02-08 10:49 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{23FCF4FA-0026-4ECA-BAD8-E23576A47AA3}
    2017-05-18 12:41 - 2017-05-18 12:41 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{3A5F19F7-CB1D-4561-B1DF-99A295C1C5B2}
    2017-02-02 02:19 - 2017-02-02 02:19 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{479D3EDD-4C31-4951-9150-8760D48EAC97}
    2017-01-04 02:41 - 2017-01-04 02:41 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{4D5F73ED-0212-497D-80FB-7B1831486F92}
    2016-11-26 00:41 - 2016-11-26 00:41 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{5A9AD334-07E2-485D-B4D9-D5335455C610}
    2017-02-27 01:41 - 2017-02-27 01:41 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{5C49EBE9-A0C8-4CC1-82B5-5353D231092F}
    2017-06-24 21:50 - 2017-06-24 21:50 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{641310F6-A324-43EA-A7FA-EC07B79A31CF}
    2017-06-24 21:50 - 2017-06-24 21:50 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{65A86BB1-9895-4CE6-9F2D-A8AF7401182D}
    2017-05-25 10:55 - 2017-05-25 10:55 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{68CC50F9-BAA6-45BB-ACBA-BDCDB97330EB}
    2017-01-04 02:42 - 2017-01-04 02:42 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{69205A7E-7024-4703-B051-4040F9051DDD}
    2017-03-22 23:35 - 2017-03-22 23:35 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{6A31E062-88C4-4ADD-AD59-28016D9E584E}
    2017-03-22 23:36 - 2017-03-22 23:36 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{6C4D4C8F-D37A-4DB3-903B-23FC7352DEDE}
    2017-01-22 01:45 - 2017-01-22 01:45 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{6D76836C-246F-49B6-9DAF-6493D18C932E}
    2017-01-16 01:00 - 2017-01-16 01:00 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{72EBEFF1-544A-4DC1-8BB4-57B0FC35A189}
    2017-01-28 01:07 - 2017-01-28 01:07 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{7751E484-CD2C-4068-A236-E85A072B0559}
    2017-05-21 09:15 - 2017-05-21 09:15 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{78348B4A-FF94-4B83-A702-B07E1C8D4528}
    2017-02-22 02:18 - 2017-02-22 02:18 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{79B65D9E-CAEA-49E4-B244-33157003053E}
    2017-06-24 21:59 - 2017-06-24 21:59 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{7DB36966-0951-4270-AE0A-546CA4B3D61C}
    2017-03-07 09:33 - 2017-03-07 09:33 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{7DCA24C9-5644-4A15-939E-5377D0DDDC77}
    2017-02-27 01:40 - 2017-02-27 01:40 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{8978618F-208C-4291-AA74-35785CD0C27C}
    2017-06-08 22:16 - 2017-06-08 22:16 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{8ED71472-C0CC-4D61-B296-D4A135F3AB52}
    2017-01-22 01:45 - 2017-01-22 01:45 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{8F862C2B-D839-4218-B211-FD79C40C4565}
    2017-01-14 02:06 - 2017-01-14 02:06 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{92CC695D-EA78-4AAF-8486-D6D4C8077094}
    2016-11-26 00:42 - 2016-11-26 00:42 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{94E25F0C-7EBA-4FEC-8F72-B966565AAF4D}
    2017-02-05 05:31 - 2017-02-05 05:31 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{9840DDD3-6873-48F9-A216-825E672C3F0C}
    2017-06-08 22:18 - 2017-06-08 22:18 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{9ECE6F41-E4BC-4056-A587-9EAC78722A7A}
    2017-01-04 02:40 - 2017-01-04 02:40 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{A42C2E1E-B47E-4D5C-9506-6CBA676823C6}
    2017-04-15 09:54 - 2017-04-15 09:54 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{A4F28471-D224-44DC-91D0-DC9E822DF5BA}
    2017-06-26 19:54 - 2017-06-26 19:54 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{A80A0140-647F-45FB-BEC3-F54EF6A5506C}
    2017-01-09 09:25 - 2017-01-09 09:25 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{A86E36BF-8C40-4532-AE8F-593CAE0D3E3A}
    2017-02-27 01:41 - 2017-02-27 01:41 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{B0278538-1BCE-4136-A4FD-5B85C3E5364C}
    2017-05-13 04:49 - 2017-05-13 04:49 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{B1A21CA5-2440-47C1-A184-205906EA2597}
    2017-02-05 05:30 - 2017-02-05 05:30 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{B3E187A0-96CB-46D4-A56E-12DF55E78374}
    2017-03-29 02:14 - 2017-03-29 02:14 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{B79184F0-DD8D-4207-94AF-2E8AFC489AA5}
    2017-01-16 01:00 - 2017-01-16 01:00 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{BD5FCE8C-0394-4822-9F11-F8ED8680C624}
    2017-05-13 04:47 - 2017-05-13 04:47 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{C3C70A52-8663-4023-8CBC-780B4F116E9D}
    2017-01-28 01:08 - 2017-01-28 01:08 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{C4F2BB76-DBC1-4752-BD9C-6809E25ED750}
    2017-05-31 10:16 - 2017-05-31 10:16 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{C64C9F1B-78EC-41D8-824E-EECDE4BD0643}
    2017-06-07 23:54 - 2017-06-07 23:54 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{C7F8DAC9-6CDC-4B1B-B39A-A36A0AF80E72}
    2017-03-29 02:17 - 2017-03-29 02:17 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{D181516F-6DF0-4B3B-86C8-DAC763F3D850}
    2017-06-24 21:51 - 2017-06-24 21:51 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{D40B59C7-2736-49C3-A0CD-DF91DB47961A}
    2017-01-14 02:05 - 2017-01-14 02:05 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{DDFCFF52-C4FF-4D63-8E1D-63AB52EE732E}
    2017-01-16 01:01 - 2017-01-16 01:01 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{E11383DB-9513-4ED5-A96C-D9B9DC1BE54A}
    2017-02-05 05:30 - 2017-02-05 05:30 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{E42A6205-0E63-4D70-BECB-51666026D542}
    2016-12-05 01:37 - 2016-12-05 01:37 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{E8FDE8B1-6A43-48DA-AB90-8AE8F77419FE}
    2017-02-22 02:16 - 2017-02-22 02:16 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{EA475488-5A7D-4C16-840C-E7104EAD6863}
    2017-02-20 10:17 - 2017-02-20 10:17 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{EEB696BC-4D3A-4074-8A12-12D7F8637F63}
    2017-06-07 23:56 - 2017-06-07 23:56 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{EF55D457-75D3-4CC4-BFEA-F8D6086B8C11}
    2017-02-16 09:52 - 2017-02-16 09:52 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{F08288F2-AEDF-48C2-A0A3-B434FA3172C6}
    2017-01-09 09:23 - 2017-01-09 09:23 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{F3A6B8EA-92A0-43AC-9C18-47CCAAFE4C17}
    2016-11-26 00:43 - 2016-11-26 00:43 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{F929BB5B-2640-48EA-8886-BD665F90ECEE}
    2017-05-01 00:01 - 2017-05-01 00:01 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{FAD0D0A7-9E2B-42EE-9F67-140073AFCBE0}
    2017-06-24 21:57 - 2017-06-24 21:57 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{FC8B0682-13E7-4663-9087-AEB2F7AE0FA2}
    2017-02-02 02:21 - 2017-02-02 02:21 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{FDB4AC16-E6FD-442C-8F19-ADF16E4013D2}
    2017-02-08 10:49 - 2017-02-08 10:49 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{FEDE0DAE-1BA4-45EB-BCB6-395910EC1132}
    2017-05-01 00:03 - 2017-05-01 00:03 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{FEFAAEE9-6008-462A-904D-7518FB049247}
    2015-08-16 02:07 - 2015-08-16 02:07 - 0000057 _____ () C:\ProgramData\Ament.ini

    ==================== Bamital & volsnap ======================

    (There is no automatic fix for files that do not pass verification.)

    C:\Windows\system32\winlogon.exe => File is digitally signed
    C:\Windows\system32\wininit.exe => File is digitally signed
    C:\Windows\SysWOW64\wininit.exe => File is digitally signed
    C:\Windows\explorer.exe => File is digitally signed
    C:\Windows\SysWOW64\explorer.exe => File is digitally signed
    C:\Windows\system32\svchost.exe => File is digitally signed
    C:\Windows\SysWOW64\svchost.exe => File is digitally signed
    C:\Windows\system32\services.exe => File is digitally signed
    C:\Windows\system32\User32.dll => File is digitally signed
    C:\Windows\SysWOW64\User32.dll => File is digitally signed
    C:\Windows\system32\userinit.exe => File is digitally signed
    C:\Windows\SysWOW64\userinit.exe => File is digitally signed
    C:\Windows\system32\rpcss.dll => File is digitally signed
    C:\Windows\system32\dnsapi.dll => File is digitally signed
    C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
    C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

    LastRegBack: 2017-04-02 05:27

    ==================== End of FRST.txt ============================
     
  5. Goodtaste1892

    Goodtaste1892 Thread Starter

    Joined:
    Jun 20, 2017
    Messages:
    10
    Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 25-06-2017 01
    Ran by Clotilde (administrator) on CLOTILDE-HP (26-06-2017 20:54:45)
    Running from C:\Users\Clotilde\Downloads
    Loaded Profiles: Clotilde (Available Profiles: Clotilde)
    Platform: Windows 7 Professional Service Pack 1 (X64) Language: English (United States)
    Internet Explorer Version 11 (Default browser: IE)
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (Softex Inc.) C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe
    (Intel Corporation) C:\Windows\System32\igfxCUIService.exe
    (Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
    (Microsoft Corporation) C:\Windows\System32\wlanext.exe
    (SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
    (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
    (Intel Corporation) C:\Windows\SysWOW64\esif_uf.exe
    (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
    (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\ibtsiva.exe
    (Microsoft) C:\Program Files\Softland\novaPDF 8\Server\novapdfs.exe
    (Symantec Corporation) C:\Program Files (x86)\Norton Security\Engine\22.9.1.12\ns.exe
    (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
    (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
    (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
    (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
    (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
    (Intel) C:\Program Files\Intel Corporation\USB over IP\bin\UoipService.exe
    (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
    (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
    (Intel Corporation) C:\Windows\Temp\DPTF\esif_assist.exe
    (Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\ClientCore.exe
    (Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe
    (Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
    (Intel Corporation) C:\Windows\System32\igfxEM.exe
    (Intel Corporation) C:\Windows\System32\igfxHK.exe
    (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
    (Microsoft Corporation) C:\Windows\System32\rundll32.exe
    (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
    (SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.11.551\SSScheduler.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP 3D DriveGuard\AccelerometerSt.exe
    (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
    (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
    (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
    (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe
    (CyberLink Corp.) C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe
    (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
    (Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
    (Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
    (Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
    (Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
    (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
    (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
    (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
    () C:\Program Files (x86)\Anvsoft\Syncios\SynciosDeviceService.exe
    () C:\Program Files (x86)\Anvsoft\Syncios\androidnotifier.exe
    () C:\Program Files (x86)\Anvsoft\Syncios\adb.exe
    (Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
    (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWelcome.exe
    (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe
    (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe
    (Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office\WINWORD.EXE
    (Microsoft Corporation) C:\Windows\splwow64.exe
    (Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
    (Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
    (Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
    (Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
    (Irfan Skiljan) C:\Program Files (x86)\IrfanView\i_view32.exe
    (Microsoft Corporation) C:\Program Files (x86)\Microsoft Picture It! 7\Pip.exe
    (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe

    ==================== Registry (Whitelisted) ====================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8459480 2015-03-04] (Realtek Semiconductor)
    HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
    HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2871464 2015-02-13] (Synaptics Incorporated)
    HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176440 2017-01-19] (Apple Inc.)
    HKLM-x32\...\Run: [AccelerometerSysTrayApplet] => C:\Program Files (x86)\Hewlett-Packard\HP 3D DriveGuard\AccelerometerST.exe [127624 2015-01-30] (Hewlett-Packard Company)
    HKLM-x32\...\Run: [HP Quick Launch] => C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [581432 2014-06-09] (Hewlett-Packard Development Company, L.P.)
    HKLM-x32\...\Run: [HPOSD] => C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe [380680 2014-08-20] (Hewlett-Packard Development Company, L.P.)
    HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [296208 2015-05-18] (Intel Corporation)
    HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
    HKLM-x32\...\Run: [] => [X]
    HKLM-x32\...\Run: [Microsoft Works Update Detection] => C:\Program Files (x86)\Common Files\Microsoft Shared\Works Shared\WkUFind.exe [28672 2002-07-16] (Microsoft® Corporation)
    HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [3486520 2017-06-26] (Dropbox, Inc.)
    HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.)
    HKLM-x32\...\Run: [Syncios device service] => C:\Program Files (x86)\Anvsoft\Syncios\SynciosDeviceService.exe [1925136 2016-07-14] ()
    Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
    HKU\S-1-5-21-3234161016-1841907741-4207892495-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8418584 2015-07-17] (Piriform Ltd)
    HKU\S-1-5-21-3234161016-1841907741-4207892495-1001\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [7935768 2015-09-23] (SUPERAntiSpyware)
    HKU\S-1-5-21-3234161016-1841907741-4207892495-1001\...\Run: [Spybot-S&D Cleaning] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [5915776 2016-03-21] (Safer-Networking Ltd.)
    HKU\S-1-5-21-3234161016-1841907741-4207892495-1001\...\Run: [GoogleChromeAutoLaunch_16607C324ED4E596B6395F17C4EFCFF5] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1143640 2017-05-09] (Google Inc.)
    Lsa: [Notification Packages] scecli C:\Program Files\TrueKey\McAfeeTrueKeyPasswordFilter
    ShellIconOverlayIdentifiers: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-06-26] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-06-26] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-06-26] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-06-26] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-06-26] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-06-26] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-06-26] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-06-26] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-06-26] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-06-26] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: [ OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files (x86)\Norton Security\Engine\22.9.1.12\buShell.dll [2017-03-16] (Symantec Corporation)
    ShellIconOverlayIdentifiers: [ OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files (x86)\Norton Security\Engine\22.9.1.12\buShell.dll [2017-03-16] (Symantec Corporation)
    ShellIconOverlayIdentifiers: [ OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files (x86)\Norton Security\Engine\22.9.1.12\buShell.dll [2017-03-16] (Symantec Corporation)
    ShellIconOverlayIdentifiers-x32: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-06-26] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-06-26] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-06-26] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-06-26] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-06-26] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-06-26] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-06-26] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-06-26] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-06-26] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-06-26] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [ OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files (x86)\Norton Security\Engine32\22.9.1.12\buShell.dll [2017-03-16] (Symantec Corporation)
    ShellIconOverlayIdentifiers-x32: [ OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files (x86)\Norton Security\Engine32\22.9.1.12\buShell.dll [2017-03-16] (Symantec Corporation)
    ShellIconOverlayIdentifiers-x32: [ OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files (x86)\Norton Security\Engine32\22.9.1.12\buShell.dll [2017-03-16] (Symantec Corporation)
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2017-05-13]
    ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.551\SSScheduler.exe (McAfee, Inc.)
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk [2015-08-16]
    ShortcutTarget: Microsoft Office.lnk -> C:\Program Files (x86)\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)

    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
    Tcpip\Parameters: [DhcpNameServer] 192.168.254.254
    Tcpip\..\Interfaces\{2E0FBAF7-F609-4654-BB40-E540844808C8}: [DhcpNameServer] 192.168.254.254
    Tcpip\..\Interfaces\{5B2D7231-D837-430A-89C4-D25A80A7D10D}: [DhcpNameServer] 192.168.254.254

    Internet Explorer:
    ==================
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp13.msn.com
    HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp13.msn.com
    HKU\S-1-5-21-3234161016-1841907741-4207892495-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp13.msn.com
    HKU\S-1-5-21-3234161016-1841907741-4207892495-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://js.redirect.hp.com/jumpstation?bd=all&c=144&locale=ww_ww&pf=cnnb&s=ieHPtab&tp=iehome
    SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKLM -> OldSearch URL =
    SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKLM-x32 -> {87C4DFC6-8FE5-47E4-8807-72EBDF32E200} URL = hxxp://www.amazon.com/s/ref=azs_osd_iea?ie=UTF-8&tag=hp-us2-vsb-20&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
    SearchScopes: HKU\S-1-5-21-3234161016-1841907741-4207892495-1001 -> {85A60A59-D3D8-468F-B598-FB4393789EF4} URL = hxxps://www.google.com/search?q={searchTerms}
    SearchScopes: HKU\S-1-5-21-3234161016-1841907741-4207892495-1001 -> {87C4DFC6-8FE5-47E4-8807-72EBDF32E200} URL = hxxp://www.amazon.com/s/ref=azs_osd_iea?ie=UTF-8&tag=hp-us2-vsb-20&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
    BHO: True Key Helper -> {0F4B8786-5502-4803-8EBC-F652A1153BB6} -> C:\Program Files\Intel Security\True Key\MSIE\truekey_ie64.dll [2017-04-26] (Intel Security)
    BHO: Norton Identity Safety -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton Security\Engine\22.9.1.12\coIEPlg.dll [2017-03-16] (Symantec Corporation)
    BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
    BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-07-25] (Google Inc.)
    BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2013-08-28] (Hewlett-Packard)
    BHO-x32: True Key Helper -> {0F4B8786-5502-4803-8EBC-F652A1153BB6} -> C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll [2017-04-26] (Intel Security)
    BHO-x32: Norton Identity Safety -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton Security\Engine32\22.9.1.12\coIEPlg.dll [2017-03-16] (Symantec Corporation)
    BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
    BHO-x32: Evernote extension -> {92EF2EAD-A7CE-4424-B0DB-499CF856608E} -> C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll [2014-12-17] (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
    BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-07-25] (Google Inc.)
    BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2013-08-28] (Hewlett-Packard)
    Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-07-25] (Google Inc.)
    Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Security\Engine\22.9.1.12\coIEPlg.dll [2017-03-16] (Symantec Corporation)
    Toolbar: HKLM - True Key - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie64.dll [2017-04-26] (Intel Security)
    Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Security\Engine32\22.9.1.12\coIEPlg.dll [2017-03-16] (Symantec Corporation)
    Toolbar: HKLM-x32 - True Key - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll [2017-04-26] (Intel Security)
    Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-07-25] (Google Inc.)
    Toolbar: HKU\S-1-5-21-3234161016-1841907741-4207892495-1001 -> Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Security\Engine\22.9.1.12\coIEPlg.dll [2017-03-16] (Symantec Corporation)

    FireFox:
    ========
    FF DefaultProfile: ilensolw.default
    FF ProfilePath: C:\Users\Clotilde\AppData\Roaming\Mozilla\Firefox\Profiles\ilensolw.default [2017-06-26]
    FF DefaultSearchEngine: Mozilla\Firefox\Profiles\ilensolw.default -> Bing®
    FF DefaultSearchEngine.US: Mozilla\Firefox\Profiles\ilensolw.default -> Google
    FF SelectedSearchEngine: Mozilla\Firefox\Profiles\ilensolw.default -> Bing®
    FF Extension: (Avira Browser Safety) - C:\Users\Clotilde\AppData\Roaming\Mozilla\Firefox\Profiles\ilensolw.default\Extensions\[email protected] [2017-04-25]
    FF Extension: (Norton Identity Safe) - C:\Users\Clotilde\AppData\Roaming\Mozilla\Firefox\Profiles\ilensolw.default\Extensions\[email protected] [2017-03-15]
    FF Extension: (Save Button for Pinterest) - C:\Users\Clotilde\AppData\Roaming\Mozilla\Firefox\Profiles\ilensolw.default\Extensions\{677a8f98-fd64-40b0-a883-b8c95d0cbf17}.xpi [2017-05-15]
    FF HKLM\...\Firefox\Extensions: [{C1A2A613-35F1-4FCF-B27F-2840527B6556}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NS_22.6.0.142\coFFAddon
    FF Extension: (Norton Security Toolbar) - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NS_22.6.0.142\coFFAddon [2017-06-25]
    FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files\Hewlett-Packard\SimplePass\FFBHOExt
    FF Extension: (HP SimplePass) - C:\Program Files\Hewlett-Packard\SimplePass\FFBHOExt [2015-06-12] [not signed]
    FF HKLM-x32\...\Firefox\Extensions: [{C1A2A613-35F1-4FCF-B27F-2840527B6556}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NS_22.6.0.142\coFFAddon
    FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
    FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
    FF Plugin: @videolan.org/vlc,version=2.2.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
    FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1217157.dll [2015-02-05] (Adobe Systems, Inc.)
    FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2014-10-20] (Foxit Corporation)
    FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2014-10-20] (Foxit Corporation)
    FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xdp -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2014-10-20] (Foxit Corporation)
    FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2014-10-20] (Foxit Corporation)
    FF Plugin-x32: @Intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.56 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2014-11-10] (Intel Corporation)
    FF Plugin-x32: @Intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2014-11-10] (Intel Corporation)
    FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
    FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
    FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-27] (Google Inc.)
    FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-27] (Google Inc.)
    FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-04-04] (Adobe Systems Inc.)

    Chrome:
    =======
    CHR HomePage: Default -> hxxp://www.mozilla.com/en-US/firefox/central/
    CHR StartupUrls: Default -> "hxxp://www.google.com/","hxxp://mysearch.avg.com/?cid={98A9DCF9-23B7-4499-BFAE-BD7DDE2C274C}&mid=492c8b23105647d3a655d1565033bcec-6f585ccd9e409817ae25410f8ae9b323b5b65e9e&lang=en&ds=co012&pr=sa&d=2013-09-15 14:17:53&v=15.4.0.5&pid=safeguard&sg=0&sap=hp"
    CHR Profile: C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default [2017-06-26]
    CHR Extension: (Google Slides) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-08-17]
    CHR Extension: (3DTin) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\algoakekcdmbbikdjgjdahbfihboglmi [2015-08-17]
    CHR Extension: (Google Docs) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-08-17]
    CHR Extension: (Google Drive) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-19]
    CHR Extension: (UJAM - Make your music.) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdiogojbmdncjdpljocafnigiokgmci [2015-08-17]
    CHR Extension: (BeFunky Photo Editor) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\apfkepiiddolifkgjmfdgpnipgnfejab [2015-08-17]
    CHR Extension: (Audiense) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\bagknoiagpifjfbempgignagkejmkljm [2016-03-10]
    CHR Extension: (Hootsuite Hootlet) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\bjgfdlplhmndoonmofmflcbiohgbkifn [2016-09-20]
    CHR Extension: (Audiotool) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkgoccjhfjgjedhkiefaclppgbmoobnk [2015-08-17]
    CHR Extension: (YouTube) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-23]
    CHR Extension: (Fancy) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\cehbnekkmkknacpgjlpcilfbckclafki [2015-08-17]
    CHR Extension: (AddThis - Share & Bookmark (new)) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgbogdmdefihhljhfeiklfiedefalcde [2016-01-16]
    CHR Extension: (QR Code Generator - 1 click to Create QR Code) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\cicimfkkbejhggfjaabggafffgdnjgjp [2017-06-26]
    CHR Extension: (Norton Security Toolbar) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjabmdjcfcfdmffimndhafhblfmpjdpe [2017-06-26]
    CHR Extension: (Google Search) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-26]
    CHR Extension: (Email this page (by Google)) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\dbeoemfhkdniadbojeencpkgmobndpai [2015-08-17]
    CHR Extension: (rotoscope) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhimnnhmaanmanmmokfpijgambokcpni [2015-08-17]
    CHR Extension: (Sumo Paint) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\dpgjihldbpodlmnjolekemlfbcajnmod [2015-08-17]
    CHR Extension: (Button for Pinterest™) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\fbfjhllmkehmdajjlkolhdjjlfcmmlpl [2016-09-01]
    CHR Extension: (Google Sheets) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-08-17]
    CHR Extension: (Sprout Social) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\ffiilepjogcpodmgneknklaecmeoenbc [2015-08-17]
    CHR Extension: (PicMonkey) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\fgdgokchhicmaiacmgegjnppjkgogdhm [2016-06-07]
    CHR Extension: (Virtual Piano Black) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjagcpcbacoaogfljhglghpjhkmmfeeo [2015-08-17]
    CHR Extension: (Stupeflix Video Maker) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkdmcfnoimoilncpjchamnenebopocem [2015-08-17]
    CHR Extension: (Nice Tumblr) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\fpfdfdgcjljkdijjbaipabnalhakbcok [2015-08-17]
    CHR Extension: (Collect images on Indulgy.com) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\gegdkoobknknikkhmnbkpnejehkchcom [2015-08-17]
    CHR Extension: (Google Docs Offline) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-14]
    CHR Extension: (SwagButton) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\gngocbkfmikdgphklgmmehbjjlfgdemm [2017-06-26]
    CHR Extension: (Pinterest Save Button) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpdjojdkbbmdfjfahjcgigfpmkopogic [2017-04-22]
    CHR Extension: (Marqueed Web App) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbbhliifccolgoaijmaielecailmjnoo [2015-08-17]
    CHR Extension: (FabCam) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\hejilffmihldhlfocnabcgndjjpgadfl [2015-08-17]
    CHR Extension: (Pixlr Express) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\hojmjpdlmjopaeginhldhiokeidchjid [2015-08-17]
    CHR Extension: (Kindle Cloud Reader) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdipabjmbhpdkjaihfjoikhjjeneebd [2017-04-19]
    CHR Extension: (Norton Identity Safe) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\iikflkcanblccfahdhdonehdalibjnif [2016-07-03]
    CHR Extension: (Glitterboo) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\ikkpgihagilojnkmkkfcbhlainmnkicp [2016-11-06]
    CHR Extension: (iPiccy Photo Editor) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\imokeandodnlammaoenbgcnbhigjbpjh [2015-08-17]
    CHR Extension: (Shareaholic for Google Chrome™) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbmipnjdeifmobkhgogdnomkihhgojep [2015-08-17]
    CHR Extension: (StumbleBar by StumbleUpon) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcahibnffhnnjcedflmchmokndkjnhpg [2017-06-26]
    CHR Extension: (Hootsuite) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\kneloppijbcidgidihgdjnooihjcdbij [2015-08-17]
    CHR Extension: (Pix: Pixel Mixer) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbjiacdnbellpbhocabghholhnlboibg [2015-08-17]
    CHR Extension: (Polyvore Clipper) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\liilchbbmdohoilfeonmdpcbhpekaiac [2015-08-17]
    CHR Extension: (Wordtracker Scout) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkalodfoplipapmeogaehmiabdhhjapb [2015-08-17]
    CHR Extension: (AudioSauna) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkgfemnodkdnenmfkblebnkjpckkjcae [2015-08-17]
    CHR Extension: (Buffer) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjojodpkaeeclkgaidibcbknlhjflhle [2015-08-17]
    CHR Extension: (Chrome Web Store Payments) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-08]
    CHR Extension: (GIFPAL) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\noohoboklgjeccnihfkbdakbchbhjlch [2015-08-17]
    CHR Extension: (Buffer) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\noojglkidnpfjbincgijbaiedldjfbhh [2017-06-26]
    CHR Extension: (piZap Photo Editor) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\occpjibghkbopohbefbejkklnfdkdmok [2015-08-17]
    CHR Extension: (WiseStamp - Email Signatures for Gmail) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbcgnkmbeodkmiijjfnliicelkjfcldg [2017-05-15]
    CHR Extension: (Psykopaint) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgjchkcfmigkkhedgjedmffdepgmpfil [2015-08-17]
    CHR Extension: (Gmail) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-08-17]
    CHR Extension: (Chrome Media Router) - C:\Users\Clotilde\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-05-17]
    CHR HKLM\...\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files (x86)\Norton Security\Engine\22.9.1.12\Exts\Chrome.crx <not found>
    CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files (x86)\Norton Security\Engine\22.9.1.12\Exts\Chrome.crx <not found>
    CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx

    ==================== Services (Whitelisted) ====================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [172344 2014-07-22] (SUPERAntiSpyware.com)
    R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-09-22] (Apple Inc.)
    S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-03] (Dropbox, Inc.)
    S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-03] (Dropbox, Inc.)
    R2 DbxSvc; C:\Windows\system32\DbxSvc.exe [49992 2017-06-26] (Dropbox, Inc.)
    R2 esifsvc; C:\Windows\SysWOW64\esif_uf.exe [1037568 2015-05-18] (Intel Corporation)
    R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [18584 2014-10-09] (Intel Corporation)
    R2 iBtSiva; C:\Program Files (x86)\Intel\Bluetooth\ibtsiva.exe [124520 2014-12-13] (Intel Corporation)
    R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [344168 2015-05-18] (Intel Corporation)
    S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [887256 2014-05-13] (Intel(R) Corporation)
    R2 IntelUSBoverIP; C:\Program Files\Intel Corporation\USB over IP\bin\UoipService.exe [395744 2015-01-14] (Intel)
    R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [158496 2014-11-10] (Intel Corporation)
    S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.551\McCHSvc.exe [404376 2017-04-17] (McAfee, Inc.)
    S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [268192 2015-03-04] ()
    R2 NovaPdfServer; C:\Program Files\Softland\novaPDF 8\Server\novapdfs.exe [41760 2015-07-14] (Microsoft)
    R2 NS; C:\Program Files (x86)\Norton Security\Engine\22.9.1.12\NS.exe [326160 2017-03-16] (Symantec Corporation)
    R2 omniserv; C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe [103424 2015-01-30] (Softex Inc.) [File not signed]
    R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [293080 2015-03-04] (Realtek Semiconductor)
    S2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
    R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [4088608 2016-09-21] (Safer-Networking Ltd.) [File not signed]
    R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [235984 2016-11-24] (Safer-Networking Ltd.) [File not signed]
    R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [220840 2015-02-13] (Synaptics Incorporated)
    S2 TrueKey; C:\Program Files\TrueKey\McAfee.TrueKey.Service.exe [996736 2017-04-18] (McAfee, Inc.)
    S2 TrueKeyScheduler; C:\Program Files\TrueKey\McTkSchedulerService.exe [16160 2017-04-18] (McAfee, Inc.)
    S3 TrueKeyServiceHelper; C:\Program Files\TrueKey\McAfee.TrueKey.ServiceHelper.exe [86776 2017-04-18] (McAfee, Inc.)
    S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)
    R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3820960 2015-03-04] (Intel® Corporation)
    S2 InstallerService; C:\Program Files\TrueKey\Mcafee.TrueKey.InstallerService.exe -originalversion 4.4.127.0 [X]

    ===================== Drivers (Whitelisted) ======================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    S1 BHDrvx64; C:\Program Files (x86)\Norton Security\NortonData\22.6.0.142\Definitions\BASHDefs\20170516.001\BHDrvx64.sys [1831064 2017-04-06] (Symantec Corporation)
    S3 btmaux; C:\Windows\System32\DRIVERS\btmaux.sys [141624 2014-10-28] (Motorola Solutions, Inc.)
    S3 btmhsf; C:\Windows\System32\DRIVERS\btmhsf.sys [1448248 2014-11-26] (Motorola Solutions, Inc.)
    S3 btmlehid; C:\Windows\system32\drivers\btmlehid.sys [83768 2014-11-05] (Motorola Solutions, Inc.)
    R1 ccSet_NS; C:\Windows\system32\drivers\NSx64\1609010.00C\ccSetx64.sys [174240 2017-02-20] (Symantec Corporation)
    R1 CLVirtualDrive; C:\Windows\System32\DRIVERS\CLVirtualDrive.sys [91912 2013-11-12] (CyberLink)
    R3 dptf_cpu; C:\Windows\System32\DRIVERS\dptf_cpu.sys [38720 2015-05-18] (Intel Corporation)
    R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [507032 2017-05-09] (Symantec Corporation)
    R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [156824 2017-05-09] (Symantec Corporation)
    R3 esif_lf; C:\Windows\System32\DRIVERS\esif_lf.sys [216360 2015-05-18] (Intel Corporation)
    R0 iaStorF; C:\Windows\System32\drivers\iaStorF.sys [30360 2014-10-09] (Intel Corporation)
    S3 ibtusb; C:\Windows\System32\DRIVERS\ibtusb.sys [230128 2014-12-03] (Intel Corporation)
    R1 IDSVia64; C:\Program Files (x86)\Norton Security\NortonData\22.6.0.142\Definitions\IPSDefs\20170519.001\IDSvia64.sys [1053824 2017-05-20] (Symantec Corporation)
    R3 MEIx64; C:\Windows\system32\drivers\TeeDriverx64.sys [129312 2014-11-10] (Intel Corporation)
    R3 NETwNs64; C:\Windows\System32\DRIVERS\Netwsw02.sys [3429656 2015-03-04] (Intel Corporation)
    S3 RTSPER; C:\Windows\System32\DRIVERS\RtsPer.sys [781528 2015-03-03] (Realsil Semiconductor Corporation)
    S3 RTSUER; C:\Windows\system32\Drivers\RtsUer.sys [377048 2015-03-03] (Realsil Semiconductor Corporation)
    R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
    R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
    S3 SmbDrv; C:\Windows\system32\drivers\Smb_driver_AMDASF.sys [33448 2015-02-13] (Synaptics Incorporated)
    R3 SmbDrvI; C:\Windows\system32\drivers\Smb_driver_Intel.sys [33448 2015-02-13] (Synaptics Incorporated)
    R1 SRTSP; C:\Windows\System32\Drivers\NSx64\1609010.00C\SRTSP64.SYS [770200 2017-03-16] (Symantec Corporation)
    R1 SRTSPX; C:\Windows\system32\drivers\NSx64\1609010.00C\SRTSPX64.SYS [49312 2017-03-16] (Symantec Corporation)
    R0 SymEFASI; C:\Windows\System32\drivers\NSx64\1609010.00C\SYMEFASI64.SYS [1716896 2017-02-20] (Symantec Corporation)
    R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [102608 2017-03-07] (Symantec Corporation)
    R1 SymIRON; C:\Windows\system32\drivers\NSx64\1609010.00C\Ironx64.SYS [291480 2017-02-20] (Symantec Corporation)
    R1 SymNetS; C:\Windows\System32\Drivers\NSx64\1609010.00C\SYMNETS.SYS [567512 2017-02-20] (Symantec Corporation)
    R3 usb3Hub; C:\Windows\System32\DRIVERS\usb3Hub.sys [212056 2015-01-14] (Windows (R) Win 7 DDK provider)
    S3 dbx; system32\DRIVERS\dbx.sys [X]
    S3 NAVENG; \??\C:\Program Files (x86)\Norton Security\NortonData\22.6.0.142\Definitions\SDSDefs\20160714.009\ENG64.SYS [X]
    S3 NAVEX15; \??\C:\Program Files (x86)\Norton Security\NortonData\22.6.0.142\Definitions\SDSDefs\20160714.009\EX64.SYS [X]
    S3 NPF; system32\drivers\NPF.sys [X]

    ==================== NetSvcs (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


    ==================== One Month Created files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2017-06-26 20:48 - 2017-06-26 20:51 - 00502485 _____ C:\Users\Clotilde\Downloads\Addition.txt
    2017-06-26 20:44 - 2017-06-26 20:54 - 00042578 _____ C:\Users\Clotilde\Downloads\FRST.txt
    2017-06-26 20:44 - 2017-06-26 20:54 - 00000000 ____D C:\FRST
    2017-06-26 20:43 - 2017-06-26 20:43 - 02441216 _____ (Farbar) C:\Users\Clotilde\Downloads\FRST64.exe
    2017-06-26 20:39 - 2017-06-26 20:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
    2017-06-26 19:55 - 2017-06-26 19:55 - 00000000 ____H C:\Users\Clotilde\AppData\Local\BIT6E5.tmp
    2017-06-26 19:54 - 2017-06-26 19:54 - 00000000 _____ C:\Users\Clotilde\AppData\Local\{A80A0140-647F-45FB-BEC3-F54EF6A5506C}
    2017-06-26 03:27 - 2017-06-26 03:27 - 00049992 _____ (Dropbox, Inc.) C:\Windows\system32\DbxSvc.exe
    2017-06-26 03:27 - 2017-06-26 03:27 - 00045640 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-stable.sys
    2017-06-26 03:27 - 2017-06-26 03:27 - 00045640 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-dev.sys
    2017-06-26 03:27 - 2017-06-26 03:27 - 00045640 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-canary.sys
    2017-06-25 22:32 - 2017-06-25 22:32 - 00082773 _____ C:\Users\Clotilde\.recently-used.xbel
    2017-06-24 21:59 - 2017-06-24 21:59 - 00000000 _____ C:\Users\Clotilde\AppData\Local\{7DB36966-0951-4270-AE0A-546CA4B3D61C}
    2017-06-24 21:57 - 2017-06-24 21:57 - 00000000 _____ C:\Users\Clotilde\AppData\Local\{FC8B0682-13E7-4663-9087-AEB2F7AE0FA2}
    2017-06-24 21:51 - 2017-06-24 21:51 - 00000000 _____ C:\Users\Clotilde\AppData\Local\{D40B59C7-2736-49C3-A0CD-DF91DB47961A}
    2017-06-24 21:50 - 2017-06-24 21:50 - 00000000 _____ C:\Users\Clotilde\AppData\Local\{65A86BB1-9895-4CE6-9F2D-A8AF7401182D}
    2017-06-24 21:50 - 2017-06-24 21:50 - 00000000 _____ C:\Users\Clotilde\AppData\Local\{641310F6-A324-43EA-A7FA-EC07B79A31CF}
    2017-06-23 17:14 - 2017-06-23 17:14 - 00014211 _____ C:\Users\Clotilde\Documents\Windows 7 No internet Access but network connected .txt
    2017-06-14 21:34 - 2017-06-14 21:34 - 03390359 _____ C:\Users\Clotilde\Downloads\Edison-His-Life-and-Inventions.pdf
    2017-06-12 01:10 - 2017-06-12 01:10 - 01291080 _____ C:\Users\Clotilde\Downloads\Product Launching Made Simple Workbook.pdf
    2017-06-08 22:18 - 2017-06-08 22:18 - 00000000 _____ C:\Users\Clotilde\AppData\Local\{9ECE6F41-E4BC-4056-A587-9EAC78722A7A}
    2017-06-08 22:16 - 2017-06-08 22:16 - 00000000 _____ C:\Users\Clotilde\AppData\Local\{8ED71472-C0CC-4D61-B296-D4A135F3AB52}
    2017-06-07 23:56 - 2017-06-07 23:56 - 00000000 _____ C:\Users\Clotilde\AppData\Local\{EF55D457-75D3-4CC4-BFEA-F8D6086B8C11}
    2017-06-07 23:54 - 2017-06-07 23:54 - 00000000 _____ C:\Users\Clotilde\AppData\Local\{C7F8DAC9-6CDC-4B1B-B39A-A36A0AF80E72}
    2017-06-07 05:58 - 2017-06-07 05:58 - 00000384 _____ C:\Users\Clotilde\Documents\To make your own garbanzo nuts.txt
    2017-06-06 05:34 - 2017-06-06 05:34 - 00052857 _____ C:\Users\Clotilde\AppData\Local\recently-used.xbel
    2017-05-31 10:16 - 2017-05-31 10:16 - 00000000 _____ C:\Users\Clotilde\AppData\Local\{C64C9F1B-78EC-41D8-824E-EECDE4BD0643}
    2017-05-31 09:01 - 2017-05-31 09:01 - 00192973 _____ C:\Users\Clotilde\Downloads\archive (1).zip
    2017-05-31 09:00 - 2017-05-31 09:00 - 00192973 _____ C:\Users\Clotilde\Downloads\archive.zip
    2017-05-31 02:30 - 2017-05-31 02:55 - 00000376 _____ C:\Users\Clotilde\Documents\Growing Gum Tissue Is Easy.txt
    2017-05-29 04:44 - 2017-06-06 08:23 - 03575660 _____ C:\Users\Clotilde\Documents\Zuri The Female Rhino.pdf
    2017-05-29 04:18 - 2017-05-29 04:18 - 03575294 _____ C:\Users\Clotilde\Documents\Zuri The Female Rhino2.pdf
    2017-05-28 07:52 - 2017-05-28 07:52 - 00541553 _____ C:\Users\Clotilde\Downloads\FDS-Valentine-Sticker-Hearts (1).zip
    2017-05-28 07:51 - 2017-05-28 07:52 - 36026628 _____ C:\Users\Clotilde\Downloads\mls-wlsnsd17mini.zip
    2017-05-28 07:50 - 2017-05-28 07:51 - 02559358 _____ C:\Users\Clotilde\Downloads\ink-stained-hearts.zip
    2017-05-28 07:50 - 2017-05-28 07:50 - 02066812 _____ C:\Users\Clotilde\Downloads\FDS-Star-Stamps (1).zip
    2017-05-28 03:35 - 2017-05-28 03:35 - 00000205 _____ C:\Users\Clotilde\Documents\joint pain release and relief.txt
    2017-05-27 06:32 - 2017-05-27 10:40 - 00040423 _____ C:\Users\Clotilde\Documents\antiwrinkle ferulic acid ceramides rice bran oil.txt

    ==================== One Month Modified files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2017-06-26 20:40 - 2015-07-31 10:27 - 00000000 ____D C:\Program Files (x86)\Dropbox
    2017-06-26 20:15 - 2015-08-18 01:10 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
    2017-06-26 20:11 - 2009-07-13 21:45 - 00035632 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2017-06-26 20:11 - 2009-07-13 21:45 - 00035632 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2017-06-26 20:06 - 2015-08-19 00:43 - 00000912 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job
    2017-06-26 20:04 - 2015-08-16 01:32 - 00000000 ____D C:\Users\Clotilde\Documents\Youcam
    2017-06-26 20:03 - 2015-08-19 00:43 - 00000908 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job
    2017-06-26 20:03 - 2015-08-16 01:31 - 00000000 __SHD C:\Users\Clotilde\IntelGraphicsProfiles
    2017-06-26 19:59 - 2009-07-13 22:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
    2017-06-26 19:56 - 2016-01-16 02:03 - 00000000 ____D C:\AdwCleaner
    2017-06-25 23:54 - 2016-08-20 03:26 - 00000000 ____D C:\Program Files\TrueKey
    2017-06-25 23:52 - 2015-08-16 01:30 - 00000000 ____D C:\Users\Clotilde
    2017-06-25 23:51 - 2017-05-13 05:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
    2017-06-25 23:51 - 2017-05-13 05:08 - 00000000 ____D C:\Program Files\McAfee Security Scan
    2017-06-25 23:51 - 2017-05-13 05:07 - 00000000 ____D C:\ProgramData\McAfee Security Scan
    2017-06-25 23:51 - 2017-03-08 01:05 - 00000000 ____D C:\Windows\System32\Tasks\Norton Security
    2017-06-25 23:51 - 2017-01-25 07:32 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
    2017-06-25 23:51 - 2016-12-05 04:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
    2017-06-25 23:51 - 2016-12-05 04:28 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
    2017-06-25 23:51 - 2016-08-16 07:05 - 00000000 ____D C:\Users\Clotilde\.android
    2017-06-25 23:51 - 2016-07-03 03:46 - 00000000 ____D C:\Windows\System32\Tasks\Remediation
    2017-06-25 23:51 - 2016-07-03 03:46 - 00000000 ____D C:\Program Files\Common Files\AV
    2017-06-25 23:51 - 2016-07-03 03:43 - 00000000 ____D C:\Program Files\Common Files\Symantec Shared
    2017-06-25 23:51 - 2016-07-03 03:41 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Security
    2017-06-25 23:51 - 2016-07-03 03:41 - 00000000 ____D C:\Windows\system32\Drivers\NSx64
    2017-06-25 23:51 - 2016-07-03 03:41 - 00000000 ____D C:\Program Files (x86)\Norton Security
    2017-06-25 23:51 - 2016-07-03 03:25 - 00000000 ____D C:\ProgramData\Norton
    2017-06-25 23:51 - 2015-09-22 06:42 - 00000000 ____D C:\Users\Clotilde\AppData\Roaming\gtk-2.0
    2017-06-25 23:51 - 2015-08-19 00:54 - 00000000 ____D C:\Users\Clotilde\AppData\Roaming\IrfanView
    2017-06-25 23:51 - 2015-08-18 01:10 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
    2017-06-25 23:51 - 2015-08-17 01:44 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
    2017-06-25 23:51 - 2015-07-31 10:25 - 00000000 ___RD C:\Users\Public\Recorded TV
    2017-06-25 23:51 - 2015-07-31 10:12 - 00000000 ___HD C:\Windows\system32\WLANProfiles
    2017-06-25 23:51 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\SysWOW64\migwiz
    2017-06-25 23:51 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\system32\NDF
    2017-06-25 23:51 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\system32\Msdtc
    2017-06-25 23:51 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\system32\migwiz
    2017-06-25 23:51 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\PolicyDefinitions
    2017-06-25 23:51 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\inf
    2017-06-25 23:51 - 2009-07-13 20:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
    2017-06-25 23:49 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\registration
    2017-06-25 23:47 - 2015-08-17 00:54 - 00000000 ____D C:\Users\Clotilde\AppData\Local\Google
    2017-06-25 23:20 - 2015-08-18 04:29 - 00890217 _____ C:\Users\Clotilde\Documents\sunglow.txt
    2017-06-25 22:35 - 2015-09-22 06:32 - 00000000 ____D C:\Users\Clotilde\.gimp-2.6
    2017-06-23 02:42 - 2015-08-18 02:21 - 00000000 ____D C:\Users\Clotilde\Documents\crochet
    2017-06-22 20:51 - 2015-08-25 04:23 - 00000000 ____D C:\Users\Clotilde\Documents\sayings and quotes to copy
    2017-06-22 18:49 - 2015-08-18 04:11 - 00027569 _____ C:\Users\Clotilde\Documents\maranata.txt
    2017-06-21 16:49 - 2015-08-18 03:16 - 00040743 _____ C:\Users\Clotilde\Documents\dog and kitty names.txt
    2017-06-20 18:02 - 2017-01-03 00:30 - 00000000 ____D C:\Windows\system32\MRT
    2017-06-19 22:27 - 2017-02-14 09:50 - 00000000 ____D C:\Users\Clotilde\AppData\LocalLow\Mozilla
    2017-06-19 20:46 - 2016-07-03 07:04 - 00000000 ____D C:\Users\Clotilde\AppData\Local\CrashDumps
    2017-06-18 23:35 - 2015-08-18 03:44 - 00154232 _____ C:\Users\Clotilde\Documents\How to create great tag lines.txt
    2017-06-14 17:09 - 2015-08-19 00:42 - 00000000 ____D C:\Users\Clotilde\AppData\Local\Dropbox
    2017-06-13 17:44 - 2016-08-20 03:39 - 00000000 ____D C:\Program Files (x86)\McAfee
    2017-06-13 02:47 - 2016-08-11 21:45 - 00000000 ____D C:\Users\Clotilde\Documents\craftybegonia business
    2017-06-11 09:47 - 2015-08-18 04:12 - 00007518 _____ C:\Users\Clotilde\Documents\names for my scarfs.txt
    2017-06-10 08:41 - 2017-02-16 01:23 - 00028702 _____ C:\Users\Clotilde\Documents\make wrinkles disappear antiaging antiwrinkle.txt
    2017-06-08 09:06 - 2016-04-28 03:42 - 00022229 _____ C:\Users\Clotilde\Documents\How to Tighten Sagging Skin on Face.txt
    2017-06-03 10:30 - 2015-08-25 04:13 - 00000000 ____D C:\Users\Clotilde\Documents\All Dolls
    2017-06-01 10:13 - 2015-08-18 01:31 - 00141453 _____ C:\Users\Clotilde\Documents\Anti wrinkle essential oil formula.txt
    2017-06-01 08:26 - 2016-10-01 06:38 - 00184320 ___SH C:\Users\Clotilde\Thumbs.db
    2017-05-31 10:06 - 2017-05-18 10:05 - 00002832 _____ C:\Users\Clotilde\Documents\Avocado Seed Anti Aging Antioxidants and for warts.txt
    2017-05-29 09:17 - 2015-11-23 07:52 - 00000000 ____D C:\Users\Clotilde\Documents\gemstones for scrapbooking embellishments
    2017-05-29 05:31 - 2016-02-29 06:41 - 00017064 _____ C:\Users\Clotilde\Documents\remedies for melasma and brown spots.txt
    2017-05-29 03:38 - 2017-05-25 07:55 - 19032064 ____H C:\Users\Clotilde\Documents\~WRL1670.tmp
    2017-05-29 02:57 - 2017-05-25 07:55 - 16524800 ____H C:\Users\Clotilde\Documents\~WRL0655.tmp
    2017-05-29 02:56 - 2017-05-25 07:55 - 14428672 ____H C:\Users\Clotilde\Documents\~WRL3781.tmp
    2017-05-29 02:56 - 2017-05-25 07:55 - 12129280 ____H C:\Users\Clotilde\Documents\~WRL2805.tmp
    2017-05-29 02:47 - 2017-05-25 07:55 - 09085952 ____H C:\Users\Clotilde\Documents\~WRL0436.tmp
    2017-05-29 00:51 - 2017-05-25 07:55 - 02675200 ____H C:\Users\Clotilde\Documents\~WRL3906.tmp
    2017-05-29 00:49 - 2017-05-25 07:55 - 00040448 ____H C:\Users\Clotilde\Documents\~WRL3818.tmp
    2017-05-29 00:27 - 2017-05-25 07:55 - 00040448 ____H C:\Users\Clotilde\Documents\~WRL3785.tmp

    ==================== Files in the root of some directories =======

    2015-08-18 02:33 - 2017-02-14 08:21 - 0007480 _____ () C:\Users\Clotilde\AppData\Roaming\mainhst.zgh
    2015-08-16 02:22 - 1996-12-09 00:00 - 0000002 _____ () C:\Users\Clotilde\AppData\Roaming\Microsoft\ArtGalry.cag
    2016-01-14 05:03 - 2016-09-18 00:21 - 0119649 _____ () C:\Users\Clotilde\AppData\Local\ars.cache
    2017-06-26 19:55 - 2017-06-26 19:55 - 0000000 ____H () C:\Users\Clotilde\AppData\Local\BIT6E5.tmp
    2016-01-14 05:05 - 2016-09-18 00:22 - 1147695 _____ () C:\Users\Clotilde\AppData\Local\census.cache
    2016-01-14 04:33 - 2016-01-14 04:33 - 0000036 _____ () C:\Users\Clotilde\AppData\Local\housecall.guid.cache
    2017-06-06 05:34 - 2017-06-06 05:34 - 0052857 _____ () C:\Users\Clotilde\AppData\Local\recently-used.xbel
    2016-01-14 05:00 - 2016-09-18 00:02 - 0000010 _____ () C:\Users\Clotilde\AppData\Local\sponge.last.runtime.cache
    2017-03-12 08:30 - 2017-03-12 08:30 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{07714512-AE7E-473E-B700-D563215B2695}
    2016-12-05 01:35 - 2016-12-05 01:35 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{1317ECBA-05CD-409F-91D9-4C879B67F2F2}
    2017-02-16 09:59 - 2017-02-16 09:59 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{19003E94-8559-4EA1-A92B-3E9E21B905ED}
    2017-01-22 01:47 - 2017-01-22 01:47 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{1D57D9A3-D130-4B26-9D7D-7F39794EBAED}
    2017-03-19 22:37 - 2017-03-19 22:37 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{237E9194-68C3-473F-9703-A65E0E7337D0}
    2017-03-19 22:35 - 2017-03-19 22:35 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{23E83A05-DA8A-4AC6-92BC-626E70EA71D7}
    2017-02-08 10:49 - 2017-02-08 10:49 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{23FCF4FA-0026-4ECA-BAD8-E23576A47AA3}
    2017-05-18 12:41 - 2017-05-18 12:41 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{3A5F19F7-CB1D-4561-B1DF-99A295C1C5B2}
    2017-02-02 02:19 - 2017-02-02 02:19 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{479D3EDD-4C31-4951-9150-8760D48EAC97}
    2017-01-04 02:41 - 2017-01-04 02:41 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{4D5F73ED-0212-497D-80FB-7B1831486F92}
    2016-11-26 00:41 - 2016-11-26 00:41 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{5A9AD334-07E2-485D-B4D9-D5335455C610}
    2017-02-27 01:41 - 2017-02-27 01:41 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{5C49EBE9-A0C8-4CC1-82B5-5353D231092F}
    2017-06-24 21:50 - 2017-06-24 21:50 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{641310F6-A324-43EA-A7FA-EC07B79A31CF}
    2017-06-24 21:50 - 2017-06-24 21:50 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{65A86BB1-9895-4CE6-9F2D-A8AF7401182D}
    2017-05-25 10:55 - 2017-05-25 10:55 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{68CC50F9-BAA6-45BB-ACBA-BDCDB97330EB}
    2017-01-04 02:42 - 2017-01-04 02:42 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{69205A7E-7024-4703-B051-4040F9051DDD}
    2017-03-22 23:35 - 2017-03-22 23:35 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{6A31E062-88C4-4ADD-AD59-28016D9E584E}
    2017-03-22 23:36 - 2017-03-22 23:36 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{6C4D4C8F-D37A-4DB3-903B-23FC7352DEDE}
    2017-01-22 01:45 - 2017-01-22 01:45 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{6D76836C-246F-49B6-9DAF-6493D18C932E}
    2017-01-16 01:00 - 2017-01-16 01:00 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{72EBEFF1-544A-4DC1-8BB4-57B0FC35A189}
    2017-01-28 01:07 - 2017-01-28 01:07 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{7751E484-CD2C-4068-A236-E85A072B0559}
    2017-05-21 09:15 - 2017-05-21 09:15 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{78348B4A-FF94-4B83-A702-B07E1C8D4528}
    2017-02-22 02:18 - 2017-02-22 02:18 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{79B65D9E-CAEA-49E4-B244-33157003053E}
    2017-06-24 21:59 - 2017-06-24 21:59 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{7DB36966-0951-4270-AE0A-546CA4B3D61C}
    2017-03-07 09:33 - 2017-03-07 09:33 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{7DCA24C9-5644-4A15-939E-5377D0DDDC77}
    2017-02-27 01:40 - 2017-02-27 01:40 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{8978618F-208C-4291-AA74-35785CD0C27C}
    2017-06-08 22:16 - 2017-06-08 22:16 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{8ED71472-C0CC-4D61-B296-D4A135F3AB52}
    2017-01-22 01:45 - 2017-01-22 01:45 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{8F862C2B-D839-4218-B211-FD79C40C4565}
    2017-01-14 02:06 - 2017-01-14 02:06 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{92CC695D-EA78-4AAF-8486-D6D4C8077094}
    2016-11-26 00:42 - 2016-11-26 00:42 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{94E25F0C-7EBA-4FEC-8F72-B966565AAF4D}
    2017-02-05 05:31 - 2017-02-05 05:31 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{9840DDD3-6873-48F9-A216-825E672C3F0C}
    2017-06-08 22:18 - 2017-06-08 22:18 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{9ECE6F41-E4BC-4056-A587-9EAC78722A7A}
    2017-01-04 02:40 - 2017-01-04 02:40 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{A42C2E1E-B47E-4D5C-9506-6CBA676823C6}
    2017-04-15 09:54 - 2017-04-15 09:54 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{A4F28471-D224-44DC-91D0-DC9E822DF5BA}
    2017-06-26 19:54 - 2017-06-26 19:54 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{A80A0140-647F-45FB-BEC3-F54EF6A5506C}
    2017-01-09 09:25 - 2017-01-09 09:25 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{A86E36BF-8C40-4532-AE8F-593CAE0D3E3A}
    2017-02-27 01:41 - 2017-02-27 01:41 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{B0278538-1BCE-4136-A4FD-5B85C3E5364C}
    2017-05-13 04:49 - 2017-05-13 04:49 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{B1A21CA5-2440-47C1-A184-205906EA2597}
    2017-02-05 05:30 - 2017-02-05 05:30 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{B3E187A0-96CB-46D4-A56E-12DF55E78374}
    2017-03-29 02:14 - 2017-03-29 02:14 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{B79184F0-DD8D-4207-94AF-2E8AFC489AA5}
    2017-01-16 01:00 - 2017-01-16 01:00 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{BD5FCE8C-0394-4822-9F11-F8ED8680C624}
    2017-05-13 04:47 - 2017-05-13 04:47 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{C3C70A52-8663-4023-8CBC-780B4F116E9D}
    2017-01-28 01:08 - 2017-01-28 01:08 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{C4F2BB76-DBC1-4752-BD9C-6809E25ED750}
    2017-05-31 10:16 - 2017-05-31 10:16 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{C64C9F1B-78EC-41D8-824E-EECDE4BD0643}
    2017-06-07 23:54 - 2017-06-07 23:54 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{C7F8DAC9-6CDC-4B1B-B39A-A36A0AF80E72}
    2017-03-29 02:17 - 2017-03-29 02:17 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{D181516F-6DF0-4B3B-86C8-DAC763F3D850}
    2017-06-24 21:51 - 2017-06-24 21:51 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{D40B59C7-2736-49C3-A0CD-DF91DB47961A}
    2017-01-14 02:05 - 2017-01-14 02:05 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{DDFCFF52-C4FF-4D63-8E1D-63AB52EE732E}
    2017-01-16 01:01 - 2017-01-16 01:01 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{E11383DB-9513-4ED5-A96C-D9B9DC1BE54A}
    2017-02-05 05:30 - 2017-02-05 05:30 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{E42A6205-0E63-4D70-BECB-51666026D542}
    2016-12-05 01:37 - 2016-12-05 01:37 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{E8FDE8B1-6A43-48DA-AB90-8AE8F77419FE}
    2017-02-22 02:16 - 2017-02-22 02:16 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{EA475488-5A7D-4C16-840C-E7104EAD6863}
    2017-02-20 10:17 - 2017-02-20 10:17 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{EEB696BC-4D3A-4074-8A12-12D7F8637F63}
    2017-06-07 23:56 - 2017-06-07 23:56 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{EF55D457-75D3-4CC4-BFEA-F8D6086B8C11}
    2017-02-16 09:52 - 2017-02-16 09:52 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{F08288F2-AEDF-48C2-A0A3-B434FA3172C6}
    2017-01-09 09:23 - 2017-01-09 09:23 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{F3A6B8EA-92A0-43AC-9C18-47CCAAFE4C17}
    2016-11-26 00:43 - 2016-11-26 00:43 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{F929BB5B-2640-48EA-8886-BD665F90ECEE}
    2017-05-01 00:01 - 2017-05-01 00:01 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{FAD0D0A7-9E2B-42EE-9F67-140073AFCBE0}
    2017-06-24 21:57 - 2017-06-24 21:57 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{FC8B0682-13E7-4663-9087-AEB2F7AE0FA2}
    2017-02-02 02:21 - 2017-02-02 02:21 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{FDB4AC16-E6FD-442C-8F19-ADF16E4013D2}
    2017-02-08 10:49 - 2017-02-08 10:49 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{FEDE0DAE-1BA4-45EB-BCB6-395910EC1132}
    2017-05-01 00:03 - 2017-05-01 00:03 - 0000000 _____ () C:\Users\Clotilde\AppData\Local\{FEFAAEE9-6008-462A-904D-7518FB049247}
    2015-08-16 02:07 - 2015-08-16 02:07 - 0000057 _____ () C:\ProgramData\Ament.ini

    ==================== Bamital & volsnap ======================

    (There is no automatic fix for files that do not pass verification.)

    C:\Windows\system32\winlogon.exe => File is digitally signed
    C:\Windows\system32\wininit.exe => File is digitally signed
    C:\Windows\SysWOW64\wininit.exe => File is digitally signed
    C:\Windows\explorer.exe => File is digitally signed
    C:\Windows\SysWOW64\explorer.exe => File is digitally signed
    C:\Windows\system32\svchost.exe => File is digitally signed
    C:\Windows\SysWOW64\svchost.exe => File is digitally signed
    C:\Windows\system32\services.exe => File is digitally signed
    C:\Windows\system32\User32.dll => File is digitally signed
    C:\Windows\SysWOW64\User32.dll => File is digitally signed
    C:\Windows\system32\userinit.exe => File is digitally signed
    C:\Windows\SysWOW64\userinit.exe => File is digitally signed
    C:\Windows\system32\rpcss.dll => File is digitally signed
    C:\Windows\system32\dnsapi.dll => File is digitally signed
    C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
    C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

    LastRegBack: 2017-04-02 05:27

    ==================== End of FRST.txt ============================
     
  6. Goodtaste1892

    Goodtaste1892 Thread Starter

    Joined:
    Jun 20, 2017
    Messages:
    10
    help! cannot seem to post the Addition.txt, the machine won't let me!
     
  7. Goodtaste1892

    Goodtaste1892 Thread Starter

    Joined:
    Jun 20, 2017
    Messages:
    10
    I do not have a virus problem, I have a connectivity problem. My computer has the wifi turned off and I do not know how to turn it back on since I do not have a clear wifi key among the F keys. I downloaded the manual for my laptop and it does not have the use of the F keys clearly stated. I need help in networking, I just got Malwarebytes Premium and it says I have no threats. I posted originally on the right section but was sent here. Can anyone help me?
     
  8. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/1191803