Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 19-02-2017 Ran by [removed] (administrator) on IAM (19-02-2017 20:04:42) Running from C:\Users\[removed]\Desktop\Registry Repair Spora [removed] Platform: Windows 7 Professional Service Pack 1 (X64) Language: English (United States) Internet Explorer Version 10 (Default browser: Chrome) Boot Mode: Safe Mode (with Networking) Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (DigitalPersona, Inc.) C:\Program Files\DigitalPersona\Bin\DpHostW.exe (McAfee, Inc.) C:\Windows\System32\mfevtps.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe (DigitalPersona, Inc.) C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (DigitalPersona, Inc.) C:\Program Files\DigitalPersona\Bin\DpAgent.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ==================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [Apoint] => C:\Program Files\DellTPad\Apoint.exe [592240 2011-01-05] (Alps Electric Co., Ltd.) HKLM\...\Run: [IntelWireless] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1933584 2010-12-17] (Intel(R) Corporation) HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp HKLM\...\Run: [IntelTBRunOnce] => wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs" HKLM\...\Run: [IntelliPoint] => c:\Program Files\Microsoft IntelliPoint\ipoint.exe [2399632 2011-04-13] (Microsoft Corporation) HKLM\...\Run: [SymantecPaui] => C:\Program Files\Symantec.cloud\PlatformAgent\PAUI.exe [6741984 2017-01-31] (Symantec Corporation) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2397120 2016-06-14] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] => "C:\Windows\system32\rundll32.exe" C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe [239672 2017-02-13] (AVG Technologies CZ, s.r.o.) HKLM\...\Run: [DBRMTray] => C:\Dell\DBRM\Reminder\DbrmTrayIcon.exe [206336 2010-05-20] (Microsoft) HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [2780112 2017-01-20] (Malwarebytes) HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1353680 2016-11-14] (Microsoft Corporation) HKLM\...\Run: [QuickSet] => c:\Program Files\Dell\QuickSet\QuickSet.exe [4479648 2011-01-25] (Dell Inc.) HKLM\...\Run: [iTunesHelper] => "C:\Program Files\iTunes\iTunesHelper.exe" HKLM\...\Run: [FreeFallProtection] => C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe [727664 2010-10-01] () HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500208 2010-03-06] (Adobe Systems Incorporated) HKLM\...\Run: [AdAwareTray] => "C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.15.1046.10613\AdAwareTray.exe" HKLM-x32\...\Run: [RemoteControl9] => C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe [87336 2009-07-06] (CyberLink Corp.) HKLM-x32\...\Run: [PDVD9LanguageShortcut] => C:\Program Files (x86)\CyberLink\PowerDVD9\Language\Language.exe [50472 2010-04-29] (CyberLink Corp.) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [Dell Webcam Central] => C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe [487562 2010-08-19] (Creative Technology Ltd) HKLM-x32\...\Run: [AVGUI.exe] => C:\Program Files (x86)\AVG\Antivirus\AVGUI.exe [9511480 2017-02-13] (AVG Technologies CZ, s.r.o.) HKLM-x32\...\Run: [EEventManager] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [1058400 2012-01-26] (SEIKO EPSON CORPORATION) HKLM-x32\...\Run: [NisUpgrade] => C:\Program Files\Symantec.cloud\AntiVirus_NEW\LUMSIWrapper.exe [842568 2016-11-18] (Symantec Corporation) HKLM-x32\...\Run: [The Assistant] => C:\Program Files (x86)\a la mode\Sched\eSched.exe [95144 2016-07-27] (a la mode, inc.) HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.) HKLM-x32\...\Run: [RoxWatchTray] => C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe [240112 2010-09-04] (Sonic Solutions) HKLM-x32\...\Run: [FUFAXSTM] => C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe [863360 2012-02-29] (SEIKO EPSON CORPORATION) HKLM-x32\...\Run: [FUFAXRCV] => C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe [502912 2012-02-29] (SEIKO EPSON CORPORATION) HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [26220296 2017-02-06] (Dropbox, Inc.) HKLM-x32\...\Run: [Desktop Disc Tool] => C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe [518640 2010-09-03] () HKLM-x32\...\Run: [APSDaemon] => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" HKLM-x32\...\Run: [AdobeCS5ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [406992 2010-02-22] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] => C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe [38840 2009-12-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe [640440 2009-12-21] (Adobe Systems Inc.) HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe, Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X] HKU\S-1-5-21-1307699844-331912778-3280394059-500\...\Run: [PCShowServer] => C:\Users\Administrator.jwilson-PC\AppData\Local\DIRECTV Player\PCShowServerPMWrapper.exe [1632504 2016-02-14] (Cisco) <===== ATTENTION HKU\S-1-5-21-1307699844-331912778-3280394059-500\...\Run: [SpybotPostWindows10UpgradeReInstall] => C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [1011200 2015-07-28] (Safer-Networking Ltd.) HKU\S-1-5-21-1307699844-331912778-3280394059-500\...\Run: [Spybot-S&D Cleaning] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [5915776 2016-03-21] (Safer-Networking Ltd.) HKU\S-1-5-21-1307699844-331912778-3280394059-500\...\Run: [Octoshape Streaming Services] => C:\Users\Administrator.jwilson-PC\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe [500016 2014-08-01] (Octoshape ApS) HKU\S-1-5-21-1307699844-331912778-3280394059-500\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [67384 2016-11-17] (Apple Inc.) HKU\S-1-5-21-1307699844-331912778-3280394059-500\...\RunOnce: [Uninstall C:\Users\Administrator.jwilson-PC\AppData\Local\Microsoft\OneDrive\17.3.6281.1202] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Administrator.jwilson-PC\AppData\Local\Microsoft\OneDrive\17.3.6281.1202" HKU\S-1-5-21-1307699844-331912778-3280394059-500\Control Panel\Desktop\\SCRNSAVE.EXE -> MARINE~1.SCR AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [178136 2016-06-03] (NVIDIA Corporation) AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [155768 2016-06-03] (NVIDIA Corporation) Lsa: [Notification Packages] DPPassFilter scecli C:\Program Files\TrueKey\McAfeeTrueKeyPasswordFilter ShellIconOverlayIdentifiers: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.14.0.dll [2017-02-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.14.0.dll [2017-02-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.14.0.dll [2017-02-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.14.0.dll [2017-02-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.14.0.dll [2017-02-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.14.0.dll [2017-02-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.14.0.dll [2017-02-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.14.0.dll [2017-02-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.14.0.dll [2017-02-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.14.0.dll [2017-02-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files\Symantec.cloud\EndpointProtectionAgent\Engine64\22.5.4.24\buShell.dll [2015-08-27] (Symantec Corporation) ShellIconOverlayIdentifiers: [ OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files\Symantec.cloud\EndpointProtectionAgent\Engine64\22.5.4.24\buShell.dll [2015-08-27] (Symantec Corporation) ShellIconOverlayIdentifiers: [ OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files\Symantec.cloud\EndpointProtectionAgent\Engine64\22.5.4.24\buShell.dll [2015-08-27] (Symantec Corporation) ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File ShellIconOverlayIdentifiers-x32: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.14.0.dll [2017-02-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.14.0.dll [2017-02-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.14.0.dll [2017-02-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.14.0.dll [2017-02-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.14.0.dll [2017-02-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.14.0.dll [2017-02-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.14.0.dll [2017-02-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.14.0.dll [2017-02-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.14.0.dll [2017-02-06] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.14.0.dll [2017-02-06] (Dropbox, Inc.) Startup: C:\Users\Administrator.jwilson-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Craftsman Software Update.lnk [2016-07-12] ShortcutTarget: Craftsman Software Update.lnk -> C:\Program Files (x86)\Common Files\Craftsman\CSU\CSUClient.exe (Craftsman Book Company) Startup: C:\Users\Administrator.jwilson-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\US79B-8DKGO-ETAKH-FTXKA-TXRXK-GTHXK-GGOTX-ZKAOY.html [2017-02-13] () Startup: C:\Users\Administrator.jwilson-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Craftsman Software Update.lnk [2016-07-12] ShortcutTarget: Craftsman Software Update.lnk -> C:\Program Files (x86)\Common Files\Craftsman\CSU\CSUClient.exe (Craftsman Book Company) Startup: C:\Users\Administrator.jwilson-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\US79B-8DKGO-ETAKH-FTXKA-TXRXK-GTHXK-GGOTX-ZKAOY.html [2017-02-13] () Startup: C:\Users\jlwilson2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Trillian.lnk [2011-08-05] ShortcutTarget: Trillian.lnk -> C:\Program Files (x86)\Trillian\trillian.exe (No File) Startup: C:\Users\jlwilson2.US\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Intel(R) Turbo Boost Technology Monitor 2.0.lnk [2011-04-12] ShortcutTarget: Intel(R) Turbo Boost Technology Monitor 2.0.lnk -> C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe (Intel® Corporation) Startup: C:\Users\jlwilson2.US\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Trillian.lnk [2015-01-27] ShortcutTarget: Trillian.lnk -> C:\Program Files (x86)\Trillian\trillian.exe (No File) BootExecute: autocheck autochk * sdnclean64.exe ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 Tcpip\..\Interfaces\{8F8BC948-D794-4FCA-99E4-F45A39133AAA}: [DhcpNameServer] 192.168.2.1 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/?bcutc=sp-014-756 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?bcutc=sp-014-756&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.symantec.com/redirects/security_response/fix_homepage/index.jsp?lg=en&pid=NIS&pvid=21.5.0.19 HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.symantec.com/redirects/security_response/fix_homepage/index.jsp?lg=en&pid=NIS&pvid=21.5.0.19 HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.symantec.com/redirects/security_response/fix_homepage/index.jsp?lg=en&pid=NIS&pvid=21.5.0.19 HKU\S-1-5-21-1307699844-331912778-3280394059-500\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?bcutc=sp-014-756&q={searchTerms} HKU\S-1-5-21-1307699844-331912778-3280394059-500\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/?bcutc=sp-014-756 URLSearchHook: HKLM-x32 -> Default = {855F3B16-6D32-4fe6-8A56-BBB695989046} SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM -> {DDB5BD24-0E80-467A-8B4E-AC25903F041B} URL = hxxp://www.bing.com/search?q={searchTerms}&form=DLSDF8&pc=MDDS&src=IE-SearchBox SearchScopes: HKLM-x32 -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?bcutc=sp-014-756&q={searchTerms} SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> {8F9E5B69-A385-4DC2-BE68-97A5FAAAD9C8} URL = hxxp://www.bing.com/search?q={searchTerms}&form=DLSDF8&pc=MDDS&src=IE-SearchBox SearchScopes: HKLM-x32 -> {DDB4CD6D-3E35-4517-AA9D-E2070BA8B701} URL = hxxp://www.google.com/search?q={searchTerms} SearchScopes: HKLM-x32 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?bcutc=sp-014-756&q={searchTerms} SearchScopes: HKU\S-1-5-21-1307699844-331912778-3280394059-500 -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?bcutc=sp-014-756&q={searchTerms} SearchScopes: HKU\S-1-5-21-1307699844-331912778-3280394059-500 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?bcutc=sp-014-756&q={searchTerms} BHO: No Name -> {1CA1377B-DC1D-4A52-9585-6E06050FAC53} -> No File BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2016-12-28] (Microsoft Corporation) BHO: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files\Symantec.cloud\EndpointProtectionAgent\Engine64\22.5.4.24\coIEPlg.dll [2015-09-23] (Symantec Corporation) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll [2015-02-11] (Oracle Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\URLREDIR.DLL [2016-12-28] (Microsoft Corporation) BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2016-12-28] (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-02-11] (Oracle Corporation) BHO-x32: No Name -> {02478D38-C3F9-4efb-9B51-7695ECA05670} -> No File BHO-x32: True Key Helper -> {0F4B8786-5502-4803-8EBC-F652A1153BB6} -> C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll [2016-06-28] (Intel Security) BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2016-12-28] (Microsoft Corporation) BHO-x32: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files\Symantec.cloud\EndpointProtectionAgent\Engine\22.5.4.24\coIEPlg.dll [2015-09-23] (Symantec Corporation) BHO-x32: SecureDocnPrivacynProtectionBHO -> {6B2466D6-E2A0-451E-A17D-8D8ED4ED3E1D} -> C:\Program Files (x86)\SecureDoc Privacy Protection\8.6\KangoBHO.dll [2012-08-03] (KangoExtensions) BHO-x32: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files\Symantec.cloud\EndpointProtectionAgent\Engine\21.5.0.19\IPS\IPSBHO.DLL => No File BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-02-11] (Oracle Corporation) BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.) BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2009-12-21] (Adobe Systems Incorporated) BHO-x32: McAfee SiteAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> C:\Program Files (x86)\McAfee\SiteAdvisor Enterprise\McIEPlg.dll [2011-05-12] (McAfee, Inc.) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\URLREDIR.DLL [2016-12-28] (Microsoft Corporation) BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2016-12-28] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-02-11] (Oracle Corporation) BHO-x32: Avaya one-X® Click-to-Dial Add-on -> {E6DF0B46-7D6F-407A-A6A2-62D17A021A9A} -> C:\Program Files (x86)\Avaya\Avaya one-X Communicator\AvayaIEHelper.dll [2013-05-17] (Avaya Inc.) BHO-x32: SmartSelect Class -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2009-12-21] (Adobe Systems Incorporated) Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Symantec.cloud\EndpointProtectionAgent\Engine64\22.5.4.24\coIEPlg.dll [2015-09-23] (Symantec Corporation) Toolbar: HKLM-x32 - SecureDocnPrivacynProtection - {6B818187-4C67-4A7A-98D9-4873D7C8CB95} - C:\Program Files (x86)\SecureDoc Privacy Protection\8.6\KangoBHO.dll [2012-08-03] (KangoExtensions) Toolbar: HKLM-x32 - No Name - {b4de90bb-150d-4b33-95fe-6baac97e1c21} - No File Toolbar: HKLM-x32 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files (x86)\McAfee\SiteAdvisor Enterprise\McIEPlg.dll [2011-05-12] (McAfee, Inc.) Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Symantec.cloud\EndpointProtectionAgent\Engine\22.5.4.24\coIEPlg.dll [2015-09-23] (Symantec Corporation) Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2009-12-21] (Adobe Systems Incorporated) Toolbar: HKLM-x32 - True Key - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll [2016-06-28] (Intel Security) Toolbar: HKU\S-1-5-21-1307699844-331912778-3280394059-500 -> No Name - {6B818187-4C67-4A7A-98D9-4873D7C8CB95} - No File Toolbar: HKU\S-1-5-21-1307699844-331912778-3280394059-500 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File DPF: HKLM-x32 {55963676-2F5E-4BAF-AC28-CF26AA587566} hxxps://asa01.east.gannett.com/CACHE/stc/1/binaries/vpnweb.cab DPF: HKLM-x32 {F27237D7-93C8-44C2-AC6E-D6057B9A918F} hxxps://access.gannett.com/dana-cached/sc/JuniperSetupClient.cab DPF: HKLM-x32 {F8FC1530-0608-11DF-2008-0800200C9A66} hxxps://asa02.east.gannett.com/CACHE/sdesktop/install/binaries/instweb.cab Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor Enterprise\McIEPlg.dll [2011-05-12] (McAfee, Inc.) Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-12-28] (Microsoft Corporation) Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-12-28] (Microsoft Corporation) Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-12-28] (Microsoft Corporation) Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-12-28] (Microsoft Corporation) Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor Enterprise\McIEPlg.dll [2011-05-12] (McAfee, Inc.) Handler: tmpx - {0E526CB5-7446-41D1-A403-19BFE95E8C23} - No File FireFox: ======== FF DefaultProfile: 7prg00oe.default FF ProfilePath: C:\Users\Administrator.jwilson-PC\AppData\Roaming\Mozilla\Firefox\Profiles\7prg00oe.default [2017-02-15] FF SearchPlugin: C:\Users\Administrator.jwilson-PC\AppData\Roaming\Mozilla\Firefox\Profiles\7prg00oe.default\searchplugins\google-avast.xml [2017-02-14] FF Extension: (Java Console) - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2015-01-29] [not signed] FF HKLM-x32\...\Firefox\Extensions: [{22C7F6C6-8D67-4534-92B5-529A0EC09405}] - c:\Program Files (x86)\Trend Micro\Client Server Security Agent\bho\1009\FirefoxExtension => not found FF HKLM-x32\...\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\DigitalPersona\Bin\FirefoxExt => not found FF HKLM-x32\...\Firefox\Extensions: [{B7082FAA-CB62-4872-9106-E42DD88EDE45}] - C:\Program Files (x86)\McAfee\SiteAdvisor Enterprise FF Extension: (McAfee SiteAdvisor Enterprise) - C:\Program Files (x86)\McAfee\SiteAdvisor Enterprise [2016-06-15] [not signed] FF HKLM-x32\...\Firefox\Extensions: [{A0CBD44F-4031-4796-AFA8-6AD0FBE6BFED}] - C:\Program Files (x86)\Avaya\Avaya one-X Communicator\Firefox FF Extension: (Avaya Extension) - C:\Program Files (x86)\Avaya\Avaya one-X Communicator\Firefox [2014-12-10] [not signed] FF HKLM-x32\...\Firefox\Extensions: [{EBA722F5-038F-4CAF-9EE2-545A221628BC}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_22.5.4.24\coFFPlgn FF Extension: (No Name) - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_22.5.4.24\coFFPlgn [2016-07-30] [not signed] FF HKLM-x32\...\Firefox\Extensions: [{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}] - C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9} FF Extension: (Adobe Contribute Toolbar) - C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9} [2016-06-15] [not signed] FF HKU\.DEFAULT\...\Firefox\Extensions: [{b64982b1-d112-42b5-b1e4-d3867c4533f8}] - C:\ProgramData\Browser Manager\2.2.643.41\{16cdff19-861d-48e3-a751-d99a27784753}\FirefoxExtension => not found FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_108.dll [2014-08-07] () FF Plugin: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-02-11] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-02-11] (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE -> disabled [No File] FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_108.dll [2014-08-07] () FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1216156.dll [2015-01-09] (Adobe Systems, Inc.) FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-02-11] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-02-11] (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File] FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2016-12-28] (Microsoft Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2016-12-28] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-06-02] (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-06-02] (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-12-23] (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-1307699844-331912778-3280394059-500: @citrixonline.com/appdetectorplugin -> C:\Users\Administrator.jwilson-PC\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2017-01-18] (Citrix Online) FF Plugin HKU\S-1-5-21-1307699844-331912778-3280394059-500: @octoshape.com/Octoshape Streaming Services,version=1.0 -> C:\Users\Administrator.jwilson-PC\AppData\Roaming\Octoshape\Octoshape Streaming Services\sua-1411300-0-npoctoshape.dll [2014-11-30] (Octoshape ApS) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npContribute.dll [2010-03-27] (Adobe Systems, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2016-12-23] (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Users\Administrator.jwilson-PC\AppData\Roaming\mozilla\plugins\npoctoshape.dll [2016-06-18] (Octoshape ApS) Chrome: ======= CHR DefaultProfile: Profile 1 CHR HomePage: Profile 1 -> hxxp://us.yhs4.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_dnldwz_15_43_j2¶m1=1¶m2=f%3D1%26b%3DChrome%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzutDtDtC0C0B0F0A0AyC0C0AyEtDzz0D0BtN0D0Tzu0StCtAzytCtN1L2XzutAtFtCtBtFyBtFtDtN1L1Czu1BtAtN1L1G1B1V1N2Y1L1Qzu2SyB0C0A0CyBzy0AyDtGtC0EyEyEtG0ByCyD0CtGyBtDtAtCtG0BtCzytCyBtCtC0CtDtC0D0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0AtAzyyB0E0DyB0DtG0CtCyEyBtGyE0C0B0FtG0BtAyDzytGtA0Czy0FyCtCyEtCzyzyzytC2QtN0A0LzutBtN1B2Z1V1T1S1NzutCtDzzzy%26cr%3D1258179954%26a%3Dwbf_dnldwz_15_43_j2%26os%3DWindows%2BVista%2B(TM)%2BBusiness CHR StartupUrls: Profile 1 -> "hxxps://www.google.com/webhp?sourceid=chrome-instant&rlz=1C1EODB_enUS509US514&ion=1&espv=2&es_th=1&ie=UTF-8#safe=active&q=google%20search" CHR Profile: C:\Users\Administrator.jwilson-PC\AppData\Local\Google\Chrome\User Data\Default [2017-02-15] CHR Profile: C:\Users\Administrator.jwilson-PC\AppData\Local\Google\Chrome\User Data\Profile 1 [2017-02-19] CHR Extension: (Google Slides) - C:\Users\Administrator.jwilson-PC\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-07-01] CHR Extension: (Yahoo Web) - C:\Users\Administrator.jwilson-PC\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\acjpdakpjonkfmggcmanlhdakfkhloii [2016-07-01] CHR Extension: (Google Docs) - C:\Users\Administrator.jwilson-PC\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2016-07-01] CHR Extension: (Google Drive) - C:\Users\Administrator.jwilson-PC\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-07-01] CHR Extension: (YouTube) - C:\Users\Administrator.jwilson-PC\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-07-01] CHR Extension: (Norton Security Toolbar) - C:\Users\Administrator.jwilson-PC\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\cjabmdjcfcfdmffimndhafhblfmpjdpe [2017-02-10] CHR Extension: (Adobe Acrobat) - C:\Users\Administrator.jwilson-PC\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-01-30] CHR Extension: (Google Sheets) - C:\Users\Administrator.jwilson-PC\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-07-01] CHR Extension: (Login Faster) - C:\Users\Administrator.jwilson-PC\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\flbefbhoeaoaokleoambldklhifcgppg [2016-07-01] CHR Extension: (Google Docs Offline) - C:\Users\Administrator.jwilson-PC\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-07-02] CHR Extension: (Save to Google Drive) - C:\Users\Administrator.jwilson-PC\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gmbmikajjgmnabiglmofipeabaddhgne [2016-07-01] CHR Extension: (Norton Identity Safe) - C:\Users\Administrator.jwilson-PC\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iikflkcanblccfahdhdonehdalibjnif [2016-07-01] CHR Extension: (Email Backgrounds, Email Stationery) - C:\Users\Administrator.jwilson-PC\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nepmejfbdnfgkkeklbhejggabembdfmo [2016-07-01] CHR Extension: (Chrome Web Store Payments) - C:\Users\Administrator.jwilson-PC\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-01-18] CHR Extension: (Gmail) - C:\Users\Administrator.jwilson-PC\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-07-01] CHR Extension: (Chrome Media Router) - C:\Users\Administrator.jwilson-PC\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-02-08] CHR Profile: C:\Users\Administrator.jwilson-PC\AppData\Local\Google\Chrome\User Data\System Profile [2015-10-07] CHR Extension: (Google Slides) - C:\Users\Administrator.jwilson-PC\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-10-07] CHR Extension: (Google Docs) - C:\Users\Administrator.jwilson-PC\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\aohghmighlieiainnegkcijnfilokake [2015-10-07] CHR Extension: (Google Drive) - C:\Users\Administrator.jwilson-PC\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-07] CHR Extension: (YouTube) - C:\Users\Administrator.jwilson-PC\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-10-07] CHR Extension: (Google Search) - C:\Users\Administrator.jwilson-PC\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-07] CHR Extension: (Google Sheets) - C:\Users\Administrator.jwilson-PC\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-10-07] CHR Extension: (Norton Identity Safe) - C:\Users\Administrator.jwilson-PC\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\iikflkcanblccfahdhdonehdalibjnif [2015-10-07] CHR Extension: (MixiDJ V34) - C:\Users\Administrator.jwilson-PC\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\kldbiondcoemmofebkcgcnbigliglcnl [2015-10-07] [UpdateUrl: hxxp://autoupdate.chromewebtb.conduit-services.com/sb/?productId=CT3298570&extensionData=\u003Cextension_data>] <==== ATTENTION CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Administrator.jwilson-PC\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-10-07] CHR Extension: (Skype Click to Call) - C:\Users\Administrator.jwilson-PC\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2015-10-07] CHR Extension: (Norton Security Toolbar) - C:\Users\Administrator.jwilson-PC\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk [2015-10-07] CHR Extension: (Chrome Web Store Payments) - C:\Users\Administrator.jwilson-PC\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-10-07] CHR Extension: (Gmail) - C:\Users\Administrator.jwilson-PC\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-10-07] CHR HKLM\...\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files\Symantec.cloud\EndpointProtectionAgent\Engine\22.5.4.24\Exts\Chrome.crx CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files\Symantec.cloud\EndpointProtectionAgent\Engine\22.5.4.24\Exts\Chrome.crx CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx ==================== Services (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S2 ABBYY.Licensing.FineReader.Sprint.9.0; C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [764216 2013-08-15] (ABBYY Production LLC) S2 AVG Antivirus; C:\Program Files (x86)\AVG\Antivirus\AVGSvc.exe [260080 2017-02-13] (AVG Technologies CZ, s.r.o.) S3 avgbIDSAgent; C:\Program Files (x86)\AVG\Antivirus\x64\aswidsagenta.exe [6183576 2017-02-13] (AVG Technologies CZ, s.r.o.) S2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [1256872 2017-02-13] (AVG Technologies CZ, s.r.o.) S2 BitDefenderCOM; C:\Program Files\BDServices\BitDefenderCom.exe [1028096 2016-12-12] (Digital Care Solutions) [File not signed] S2 Bluetooth Device Monitor; C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe [901184 2010-12-14] (Intel Corporation) [File not signed] S3 Bluetooth Media Service; C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe [1298496 2010-12-14] (Intel Corporation) [File not signed] S2 Bluetooth OBEX Service; C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe [974912 2010-12-14] (Intel Corporation) [File not signed] S2 CcmExec; C:\Windows\CCM\CcmExec.exe [1571000 2013-09-11] (Microsoft Corporation) S2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [3699904 2016-12-28] (Microsoft Corporation) S2 CmRcService; C:\Windows\CCM\RemCtrl\CmRcService.exe [577704 2014-08-24] (Microsoft Corporation) S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-07-01] (Dropbox, Inc.) S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-07-01] (Dropbox, Inc.) S2 DbxSvc; C:\Windows\system32\DbxSvc.exe [46400 2017-02-06] (Dropbox, Inc.) S2 dldt_device; C:\Windows\system32\dldtcoms.exe [1044648 2009-07-09] ( ) S2 EpsonScanSvc; C:\Windows\system32\EscSvc64.exe [135824 2011-12-11] (Seiko Epson Corporation) S3 FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [651720 2016-06-15] (Macrovision Europe Ltd.) [File not signed] S2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1163712 2016-06-14] (NVIDIA Corporation) S2 iClarityQoSService; C:\Program Files (x86)\Common Files\Avaya\QoS\QosServM.exe [1650688 2013-05-17] (Avaya Inc.) [File not signed] S2 IntelBCAsvc; C:\Program Files\Intel\BCA\pabeSvc64.exe [3026584 2016-05-06] (Intel(R) Corporation) S3 lpasvc; C:\Program Files\Microsoft Policy Platform\policyHost.exe [50280 2012-08-02] (Microsoft Corporation) S3 lppsvc; C:\Program Files\Microsoft Policy Platform\policyHost.exe [50280 2012-08-02] (Microsoft Corporation) S2 magent; C:\Program Files (x86)\Products\MIRAgent\MIRAgent.exe [13404976 2013-04-18] () R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4355024 2017-01-20] (Malwarebytes) S2 McAfee SiteAdvisor Enterprise Service; C:\Program Files (x86)\McAfee\SiteAdvisor Enterprise\McSACore.exe [324928 2011-05-12] (McAfee, Inc.) R2 mfevtp; C:\Windows\system32\mfevtps.exe [185280 2014-08-13] (McAfee, Inc.) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [119864 2016-11-14] (Microsoft Corporation) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2010-12-17] () S2 NIS; C:\Program Files\Symantec.cloud\EndpointProtectionAgent\Engine\22.5.4.24\NIS.exe [282016 2015-10-05] (Symantec Corporation) S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [361816 2016-11-14] (Microsoft Corporation) S2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1879488 2016-06-14] (NVIDIA Corporation) S3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [3632576 2016-06-14] (NVIDIA Corporation) S2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2521024 2016-06-14] (NVIDIA Corporation) S3 scan; C:\Program Files\BDServices\scan.dll [627688 2016-12-12] (Bitdefender) S2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.) S2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [4088608 2016-09-21] (Safer-Networking Ltd.) S2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [235984 2016-11-24] (Safer-Networking Ltd.) S2 sesvc; C:\Program Files (x86)\ShadowExplorer\sesvc.exe [9216 2013-01-02] (www.shadowexplorer.com) [File not signed] S3 smstsmgr; C:\Windows\CCM\TSManager.exe [276152 2013-09-11] (Microsoft Corporation) S2 SsPaAdm; C:\Program Files\Symantec.cloud\PlatformAgent\ccSvcHst.exe [199464 2016-09-21] (Symantec Corporation) S2 ssPaSetMgr; C:\Program Files\Symantec.cloud\PlatformAgent32\ccSvcHst.exe [153632 2016-09-21] (Symantec Corporation) S2 ssSpnAv; C:\Program Files\Symantec.cloud\AntiVirus\AVAgent.exe [458056 2016-11-18] (Symantec Corporation) S2 ss_conn_service; C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [754784 2016-01-08] (DEVGURU Co., LTD.) S2 SWGVCSvc; C:\Program Files\Dell SonicWALL\Global VPN Client\SWGVCSvc.exe [336616 2013-12-03] (Dell SonicWALL, Inc.) S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed] S2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5702416 2015-09-11] (TeamViewer GmbH) S2 TrueKey; C:\Program Files\TrueKey\McAfee.TrueKey.Service.exe [905672 2016-06-22] (McAfee, Inc.) S2 TrueKeyScheduler; C:\Program Files\TrueKey\McTkSchedulerService.exe [15736 2016-06-22] (McAfee, Inc.) S3 TrueKeyServiceHelper; C:\Program Files\TrueKey\McAfee.TrueKey.ServiceHelper.exe [86864 2016-06-22] (McAfee, Inc.) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation) S2 Ziften; C:\Program Files (x86)\Ziften\Ziften.exe [1952640 2014-04-22] (Ziften Technologies, Inc.) S2 InstallerService; "C:\Program Files\TrueKey\Mcafee.TrueKey.InstallerService.exe" [X] ===================== Drivers (Whitelisted) ====================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S1 avgbdisk; C:\Windows\system32\drivers\avgbdiska.sys [165624 2017-02-13] (AVG Technologies CZ, s.r.o.) S1 avgbidsdriver; C:\Windows\system32\drivers\avgbidsdrivera.sys [311592 2017-02-13] (AVG Technologies CZ, s.r.o.) R0 avgbidsh; C:\Windows\system32\drivers\avgbidsha.sys [192096 2017-02-13] (AVG Technologies CZ, s.r.o.) S0 avgblog; C:\Windows\system32\drivers\avgbloga.sys [336920 2017-02-13] (AVG Technologies CZ, s.r.o.) S0 avgbuniv; C:\Windows\system32\drivers\avgbuniva.sys [50848 2017-02-13] (AVG Technologies CZ, s.r.o.) S3 avgHwid; C:\Windows\system32\drivers\avgHwid.sys [39288 2017-02-13] (AVG Technologies CZ, s.r.o.) S2 avgMonFlt; C:\Windows\system32\drivers\avgMonFlt.sys [127072 2017-02-13] (AVG Technologies CZ, s.r.o.) R1 avgRdr; C:\Windows\system32\drivers\avgRdr2.sys [101624 2017-02-13] (AVG Technologies CZ, s.r.o.) S0 avgRvrt; C:\Windows\system32\drivers\avgRvrt.sys [75664 2017-02-13] (AVG Technologies CZ, s.r.o.) S1 avgSnx; C:\Windows\system32\drivers\avgSnx.sys [992488 2017-02-13] (AVG Technologies CZ, s.r.o.) S1 avgSP; C:\Windows\system32\drivers\avgSP.sys [555152 2017-02-13] (AVG Technologies CZ, s.r.o.) S2 avgStm; C:\Windows\system32\drivers\avgStm.sys [163512 2017-02-13] (AVG Technologies CZ, s.r.o.) S0 avgVmm; C:\Windows\system32\drivers\avgVmm.sys [311472 2017-02-13] (AVG Technologies CZ, s.r.o.) S3 bcm; C:\Windows\System32\DRIVERS\drxvi314_64.sys [359040 2010-03-26] (Beceem communications pvt ltd.) S3 bcmbusctr; C:\Windows\System32\DRIVERS\BcmBusCtr_64.sys [62976 2010-03-26] (Beceem communications pvt ltd.) S1 BHDrvx64; C:\Program Files\Symantec.cloud\EndpointProtectionAgent\NortonData\22.5.4.24\Definitions\BASHDefs\20160711.001\BHDrvx64.sys [1832176 2016-06-01] (Symantec Corporation) S1 ccSet_Cloud; C:\Windows\SysWOW64\Drivers\Symantec.cloud\ccSetx64.sys [174328 2016-09-21] (Symantec Corporation) S1 ccSet_NIS; C:\Windows\system32\drivers\NISx64\1605040.018\ccSetx64.sys [173808 2015-09-23] (Symantec Corporation) S3 cm_net; C:\Windows\System32\DRIVERS\cm_net.sys [133120 2008-05-29] (C-motech Co.,Ltd.) S3 cm_ser; C:\Windows\System32\DRIVERS\cm_ser.sys [118272 2008-05-29] (C-motech Co.,Ltd.) S3 dg_ssudbus; C:\Windows\System32\DRIVERS\ssudbus.sys [129152 2016-04-24] (Samsung Electronics Co., Ltd.) R1 DNE; C:\Windows\System32\DRIVERS\dnelwf64.sys [133456 2013-10-03] (Citrix Systems, Inc.) S1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [497392 2016-06-14] (Symantec Corporation) S3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [156912 2016-06-14] (Symantec Corporation) S1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [77416 2017-01-20] () S1 IDSVia64; C:\Program Files\Symantec.cloud\EndpointProtectionAgent\NortonData\22.5.4.24\Definitions\IPSDefs\20160719.001\IDSvia64.sys [876760 2016-07-07] (Symantec Corporation) S3 Mandiant_Tools; C:\ProgramData\Application Data\MIRAgent\mktools.sys [25168 2014-11-10] () S1 MBAMChameleon; C:\Windows\system32\drivers\MBAMChameleon.sys [176584 2017-02-17] (Malwarebytes) S3 MBAMProtection; C:\Windows\system32\drivers\mbam.sys [43968 2017-02-19] (Malwarebytes) R0 MBAMSwissArmy; C:\Windows\System32\drivers\MBAMSwissArmy.sys [251848 2017-02-19] (Malwarebytes) R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [782968 2014-08-13] (McAfee, Inc.) R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [344176 2014-08-13] (McAfee, Inc.) S0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [295000 2016-08-25] (Microsoft Corporation) S3 NAVENG; C:\Program Files\Symantec.cloud\EndpointProtectionAgent\NortonData\22.5.4.24\Definitions\VirusDefs\20160719.002\ENG64.SYS [138456 2016-06-14] (Symantec Corporation) S3 NAVEX15; C:\Program Files\Symantec.cloud\EndpointProtectionAgent\NortonData\22.5.4.24\Definitions\VirusDefs\20160719.002\EX64.SYS [2148056 2016-06-14] (Symantec Corporation) S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [135928 2016-08-25] (Microsoft Corporation) S1 nvkflt; C:\Windows\System32\DRIVERS\nvkflt.sys [306112 2016-06-03] (NVIDIA Corporation) S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [26560 2016-06-14] (NVIDIA Corporation) S3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [56384 2016-06-03] (NVIDIA Corporation) S3 prepdrvr; C:\Windows\System32\DRIVERS\prepdrv.sys [26984 2013-09-11] (Microsoft Corporation) S3 SRTSP; C:\Windows\System32\Drivers\NISx64\1605040.018\SRTSP64.SYS [930024 2015-09-23] (Symantec Corporation) S1 SRTSPX; C:\Windows\system32\drivers\NISx64\1605040.018\SRTSPX64.SYS [50936 2015-09-23] (Symantec Corporation) S3 ssudmdm; C:\Windows\System32\DRIVERS\ssudmdm.sys [221824 2016-04-24] (Samsung Electronics Co., Ltd.) S3 SWDUMon; C:\Windows\System32\DRIVERS\SWDUMon.sys [16152 2017-02-17] () S2 SWIPsec; C:\Windows\system32\Drivers\SWIPsec.sys [110064 2013-12-03] (Dell SonicWALL, Inc.) R0 SymEFASI; C:\Windows\System32\drivers\NISx64\1605040.018\SYMEFASI64.SYS [1620720 2015-09-23] (Symantec Corporation) S3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [111344 2016-06-14] (Symantec Corporation) S1 SymIRON; C:\Windows\system32\drivers\NISx64\1605040.018\Ironx64.SYS [297720 2015-09-23] (Symantec Corporation) S1 SymNetS; C:\Windows\System32\Drivers\NISx64\1605040.018\SYMNETS.SYS [577768 2015-09-23] (Symantec Corporation) S3 Trufos; C:\Windows\System32\DRIVERS\Trufos.sys [485512 2016-12-12] (BitDefender S.R.L.) S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [54784 2014-07-28] (Apple, Inc.) [File not signed] S3 vpnva; C:\Windows\System32\DRIVERS\vpnva64-6.sys [52592 2014-11-19] (Cisco Systems, Inc.) S1 wStLibG64; no ImagePath S3 dbx; system32\DRIVERS\dbx.sys [X] S3 IntcAzAudAddService; system32\drivers\RTKVHD64.sys [X] S3 PCDSRVC{1E208CE0-FB7451FF-06020101}_0; \??\c:\program files\dell support center\pcdsrvc_x64.pkms [X] S3 PCTINDIS5X64; \??\C:\Windows\system32\PCTINDIS5X64.SYS [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2017-02-19 20:04 - 2017-02-19 20:04 - 00000000 ____D C:\FRST 2017-02-19 19:56 - 2017-02-19 19:57 - 00266288 _____ C:\Windows\Minidump\021917-37393-01.dmp 2017-02-19 19:36 - 2017-02-19 19:36 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDVD 9.5 2017-02-18 13:54 - 2017-02-18 13:54 - 00002119 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk 2017-02-18 13:53 - 2017-02-18 13:54 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client 2017-02-18 13:51 - 2017-02-18 13:54 - 00000000 ____D C:\Program Files\Microsoft Security Client 2017-02-18 13:39 - 2017-02-18 13:54 - 00001945 _____ C:\Windows\epplauncher.mif 2017-02-18 13:28 - 2017-02-18 13:52 - 00000000 ____D C:\Program Files\BDServices 2017-02-18 13:28 - 2017-02-18 13:28 - 00001192 _____ C:\Users\Administrator.jwilson-PC\Desktop\RegCure Pro.lnk 2017-02-18 13:28 - 2017-02-18 13:28 - 00000579 _____ C:\Windows\Tasks\RegCure Pro_sch_71174A8D-F610-11E6-85DA-14FEB5A1C695.job 2017-02-18 13:28 - 2017-02-18 13:28 - 00000476 _____ C:\Windows\Tasks\RegCure Pro Startup.job 2017-02-18 13:28 - 2017-02-18 13:28 - 00000474 _____ C:\Windows\Tasks\RegCure Pro Update.job 2017-02-18 13:28 - 2017-02-18 13:28 - 00000000 ____D C:\Users\Administrator.jwilson-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ParetoLogic 2017-02-18 13:28 - 2017-02-18 13:28 - 00000000 ____D C:\Program Files (x86)\ParetoLogic 2017-02-18 12:37 - 2017-02-18 13:28 - 00000000 ____D C:\Users\Administrator.jwilson-PC\AppData\Roaming\ParetoLogic 2017-02-18 12:36 - 2017-02-18 13:28 - 00000000 ____D C:\ProgramData\ParetoLogic 2017-02-17 22:24 - 2017-02-19 19:57 - 00429014 _____ C:\Windows\ntbtlog.txt 2017-02-17 13:21 - 2017-02-17 14:05 - 00000258 __RSH C:\ProgramData\ntuser.pol 2017-02-17 12:05 - 2017-02-17 12:05 - 00176584 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMChameleon.sys 2017-02-17 12:04 - 2017-02-19 19:59 - 00110536 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys 2017-02-17 12:04 - 2017-02-19 19:58 - 00043968 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys 2017-02-17 12:04 - 2017-02-19 09:37 - 00081696 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys 2017-02-17 12:03 - 2017-02-19 19:58 - 00251848 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2017-02-17 12:02 - 2017-02-17 12:02 - 00001869 _____ C:\Users\Public\Desktop\Malwarebytes.lnk 2017-02-17 12:02 - 2017-02-17 12:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes 2017-02-17 12:02 - 2017-02-17 12:02 - 00000000 ____D C:\ProgramData\Malwarebytes 2017-02-17 12:02 - 2017-02-17 12:02 - 00000000 ____D C:\Program Files\Malwarebytes 2017-02-17 12:02 - 2017-01-20 07:47 - 00077416 _____ C:\Windows\system32\Drivers\mbae64.sys 2017-02-17 07:00 - 2017-02-17 07:00 - 03052804 _____ C:\Users\Administrator.jwilson-PC\Downloads\ACBE.tmp 2017-02-16 12:06 - 2017-02-16 12:06 - 00000000 _____ C:\autoexec.bat 2017-02-15 07:16 - 2017-02-15 07:16 - 00000122 _____ C:\Windows\wininit.ini 2017-02-15 00:06 - 2017-02-15 00:06 - 00000000 ____D C:\Users\Administrator.jwilson-PC\AppData\Roaming\www.shadowexplorer.com 2017-02-15 00:03 - 2017-02-15 00:03 - 00001887 _____ C:\Users\Administrator.jwilson-PC\Desktop\ShadowExplorer.lnk 2017-02-15 00:03 - 2017-02-15 00:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ShadowExplorer 2017-02-15 00:03 - 2017-02-15 00:03 - 00000000 ____D C:\Program Files (x86)\ShadowExplorer 2017-02-14 23:38 - 2017-02-19 20:04 - 00000000 ____D C:\Users\Administrator.jwilson-PC\Desktop\Registry Repair Spora 2017-02-14 22:06 - 2015-07-28 17:52 - 00821920 _____ (Safer-Networking Ltd. ) C:\Users\Public\Desktop\Post Win10 Spybot-install.exe 2017-02-14 21:55 - 2017-02-14 21:55 - 00000000 ____D C:\Program Files\Common Files\Lavasoft 2017-02-14 11:48 - 2017-02-14 11:48 - 00000000 ____D C:\Program Files\Common Files\adaware 2017-02-14 11:44 - 2017-02-14 11:44 - 00000000 ____D C:\Program Files (x86)\Windows Resource Kits 2017-02-14 11:39 - 2017-02-14 11:39 - 00000000 ____D C:\ProgramData\adaware 2017-02-13 21:20 - 2017-01-05 12:52 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2017-02-13 21:20 - 2017-01-05 12:52 - 01212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2017-02-13 21:20 - 2016-11-09 10:33 - 03244032 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2017-02-13 21:20 - 2016-11-09 10:17 - 02365440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll 2017-02-13 21:20 - 2016-11-06 10:01 - 03219456 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2017-02-13 21:20 - 2016-10-11 09:37 - 05547752 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2017-02-13 21:20 - 2016-10-11 09:34 - 01732864 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2017-02-13 21:20 - 2016-10-11 09:31 - 00880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2017-02-13 21:20 - 2016-10-11 09:24 - 04000488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2017-02-13 21:20 - 2016-10-11 09:24 - 03944680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2017-02-13 21:20 - 2016-10-11 09:21 - 01314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2017-02-13 21:20 - 2016-10-04 09:31 - 01483264 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2017-02-13 21:20 - 2016-10-04 09:13 - 01176064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2017-02-13 21:19 - 2017-01-05 12:55 - 00154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2017-02-13 21:19 - 2017-01-05 12:55 - 00095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2017-02-13 21:19 - 2017-01-05 12:52 - 00730624 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2017-02-13 21:19 - 2017-01-05 12:52 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2017-02-13 21:19 - 2017-01-05 12:52 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll 2017-02-13 21:19 - 2017-01-05 12:52 - 00345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2017-02-13 21:19 - 2017-01-05 12:52 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2017-02-13 21:19 - 2017-01-05 12:52 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2017-02-13 21:19 - 2017-01-05 12:52 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2017-02-13 21:19 - 2017-01-05 12:52 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll 2017-02-13 21:19 - 2017-01-05 12:52 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2017-02-13 21:19 - 2017-01-05 12:52 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2017-02-13 21:19 - 2017-01-05 12:52 - 00123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll 2017-02-13 21:19 - 2017-01-05 12:52 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2017-02-13 21:19 - 2017-01-05 12:52 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2017-02-13 21:19 - 2017-01-05 12:52 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll 2017-02-13 21:19 - 2017-01-05 12:52 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2017-02-13 21:19 - 2017-01-05 12:52 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2017-02-13 21:19 - 2017-01-05 12:52 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2017-02-13 21:19 - 2017-01-05 11:43 - 00666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2017-02-13 21:19 - 2017-01-05 11:43 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2017-02-13 21:19 - 2017-01-05 11:43 - 00342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll 2017-02-13 21:19 - 2017-01-05 11:43 - 00261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2017-02-13 21:19 - 2017-01-05 11:43 - 00254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2017-02-13 21:19 - 2017-01-05 11:43 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2017-02-13 21:19 - 2017-01-05 11:43 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2017-02-13 21:19 - 2017-01-05 11:43 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2017-02-13 21:19 - 2017-01-05 11:43 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll 2017-02-13 21:19 - 2017-01-05 11:43 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2017-02-13 21:19 - 2017-01-05 11:43 - 00082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll 2017-02-13 21:19 - 2017-01-05 11:43 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2017-02-13 21:19 - 2017-01-05 11:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll 2017-02-13 21:19 - 2017-01-05 11:43 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2017-02-13 21:19 - 2017-01-05 11:43 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2017-02-13 21:19 - 2017-01-05 11:42 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2017-02-13 21:19 - 2017-01-05 11:32 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2017-02-13 21:19 - 2017-01-05 11:25 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2017-02-13 21:19 - 2017-01-05 11:24 - 00291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys 2017-02-13 21:19 - 2017-01-05 11:24 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys 2017-02-13 21:19 - 2017-01-05 11:24 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2017-02-13 21:19 - 2017-01-05 11:23 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe 2017-02-13 21:19 - 2017-01-05 11:19 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll 2017-02-13 21:19 - 2016-11-21 12:12 - 00109568 _____ (Microsoft Corporation) C:\Windows\system32\hlink.dll 2017-02-13 21:19 - 2016-11-20 10:19 - 00084992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\hlink.dll 2017-02-13 21:19 - 2016-11-20 08:07 - 00467392 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2017-02-13 21:19 - 2016-11-17 10:41 - 00370920 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys 2017-02-13 21:19 - 2016-11-10 10:32 - 01009152 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll 2017-02-13 21:19 - 2016-11-10 10:19 - 00833024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll 2017-02-13 21:19 - 2016-11-09 10:41 - 00114408 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe 2017-02-13 21:19 - 2016-11-09 10:33 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2017-02-13 21:19 - 2016-11-09 10:33 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll 2017-02-13 21:19 - 2016-11-09 10:33 - 00070144 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll 2017-02-13 21:19 - 2016-11-09 10:33 - 00025088 _____ (Microsoft Corporation) C:\Windows\system32\msimsg.dll 2017-02-13 21:19 - 2016-11-09 10:33 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2017-02-13 21:19 - 2016-11-09 10:17 - 01806848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2017-02-13 21:19 - 2016-11-09 10:17 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll 2017-02-13 21:19 - 2016-11-09 10:17 - 00025088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msimsg.dll 2017-02-13 21:19 - 2016-11-09 10:17 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2017-02-13 21:19 - 2016-11-09 10:02 - 00128512 _____ (Microsoft Corporation) C:\Windows\system32\msiexec.exe 2017-02-13 21:19 - 2016-11-09 09:55 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe 2017-02-13 21:19 - 2016-11-06 10:33 - 00404992 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2017-02-13 21:19 - 2016-11-06 10:16 - 00312832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2017-02-13 21:19 - 2016-10-27 09:33 - 00802304 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll 2017-02-13 21:19 - 2016-10-27 09:20 - 00627712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll 2017-02-13 21:19 - 2016-10-11 09:40 - 00631176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi 2017-02-13 21:19 - 2016-10-11 09:37 - 00706792 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi 2017-02-13 21:19 - 2016-10-11 09:32 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2017-02-13 21:19 - 2016-10-11 09:32 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2017-02-13 21:19 - 2016-10-11 09:32 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2017-02-13 21:19 - 2016-10-11 09:32 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2017-02-13 21:19 - 2016-10-11 09:32 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\nlsbres.dll 2017-02-13 21:19 - 2016-10-11 09:32 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll 2017-02-13 21:19 - 2016-10-11 09:32 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2017-02-13 21:19 - 2016-10-11 09:32 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2017-02-13 21:19 - 2016-10-11 09:32 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2017-02-13 21:19 - 2016-10-11 09:31 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2017-02-13 21:19 - 2016-10-11 09:31 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2017-02-13 21:19 - 2016-10-11 09:31 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll 2017-02-13 21:19 - 2016-10-11 09:31 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2017-02-13 21:19 - 2016-10-11 09:31 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll 2017-02-13 21:19 - 2016-10-11 09:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2017-02-13 21:19 - 2016-10-11 09:31 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2017-02-13 21:19 - 2016-10-11 09:31 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2017-02-13 21:19 - 2016-10-11 09:31 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2017-02-13 21:19 - 2016-10-11 09:31 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2017-02-13 21:19 - 2016-10-11 09:31 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2017-02-13 21:19 - 2016-10-11 09:31 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2017-02-13 21:19 - 2016-10-11 09:31 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2017-02-13 21:19 - 2016-10-11 09:31 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2017-02-13 21:19 - 2016-10-11 09:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2017-02-13 21:19 - 2016-10-11 09:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2017-02-13 21:19 - 2016-10-11 09:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2017-02-13 21:19 - 2016-10-11 09:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2017-02-13 21:19 - 2016-10-11 09:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2017-02-13 21:19 - 2016-10-11 09:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2017-02-13 21:19 - 2016-10-11 09:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2017-02-13 21:19 - 2016-10-11 09:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2017-02-13 21:19 - 2016-10-11 09:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2017-02-13 21:19 - 2016-10-11 09:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2017-02-13 21:19 - 2016-10-11 09:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2017-02-13 21:19 - 2016-10-11 09:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2017-02-13 21:19 - 2016-10-11 09:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2017-02-13 21:19 - 2016-10-11 09:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2017-02-13 21:19 - 2016-10-11 09:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2017-02-13 21:19 - 2016-10-11 09:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2017-02-13 21:19 - 2016-10-11 09:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2017-02-13 21:19 - 2016-10-11 09:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2017-02-13 21:19 - 2016-10-11 09:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2017-02-13 21:19 - 2016-10-11 09:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2017-02-13 21:19 - 2016-10-11 09:18 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2017-02-13 21:19 - 2016-10-11 09:18 - 00644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2017-02-13 21:19 - 2016-10-11 09:18 - 00275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2017-02-13 21:19 - 2016-10-11 09:18 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlsbres.dll 2017-02-13 21:19 - 2016-10-11 09:18 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll 2017-02-13 21:19 - 2016-10-11 09:18 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2017-02-13 21:19 - 2016-10-11 09:18 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2017-02-13 21:19 - 2016-10-11 09:18 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2017-02-13 21:19 - 2016-10-11 09:18 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2017-02-13 21:19 - 2016-10-11 09:18 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2017-02-13 21:19 - 2016-10-11 09:18 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2017-02-13 21:19 - 2016-10-11 09:18 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2017-02-13 21:19 - 2016-10-11 09:18 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2017-02-13 21:19 - 2016-10-11 09:18 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2017-02-13 21:19 - 2016-10-11 09:18 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2017-02-13 21:19 - 2016-10-11 09:18 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2017-02-13 21:19 - 2016-10-11 09:18 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2017-02-13 21:19 - 2016-10-11 09:18 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2017-02-13 21:19 - 2016-10-11 09:18 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2017-02-13 21:19 - 2016-10-11 09:18 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2017-02-13 21:19 - 2016-10-11 09:18 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2017-02-13 21:19 - 2016-10-11 09:18 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2017-02-13 21:19 - 2016-10-11 09:18 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2017-02-13 21:19 - 2016-10-11 09:18 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2017-02-13 21:19 - 2016-10-11 09:18 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2017-02-13 21:19 - 2016-10-11 09:18 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2017-02-13 21:19 - 2016-10-11 09:18 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2017-02-13 21:19 - 2016-10-11 09:18 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2017-02-13 21:19 - 2016-10-11 09:18 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2017-02-13 21:19 - 2016-10-11 09:18 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2017-02-13 21:19 - 2016-10-11 09:18 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2017-02-13 21:19 - 2016-10-11 09:18 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2017-02-13 21:19 - 2016-10-11 09:03 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe 2017-02-13 21:19 - 2016-10-11 09:03 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys 2017-02-13 21:19 - 2016-10-11 09:03 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe 2017-02-13 21:19 - 2016-10-11 08:59 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2017-02-13 21:19 - 2016-10-11 08:59 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2017-02-13 21:19 - 2016-10-11 08:55 - 00346112 _____ (Microsoft Corporation) C:\Windows\system32\bcdedit.exe 2017-02-13 21:19 - 2016-10-11 08:55 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2017-02-13 21:19 - 2016-10-11 08:51 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2017-02-13 21:19 - 2016-10-11 08:51 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2017-02-13 21:19 - 2016-10-11 08:51 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2017-02-13 21:19 - 2016-10-11 08:51 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2017-02-13 21:19 - 2016-10-11 08:50 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2017-02-13 21:19 - 2016-10-11 08:50 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2017-02-13 21:19 - 2016-10-11 08:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2017-02-13 21:19 - 2016-10-11 08:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2017-02-13 21:19 - 2016-10-11 07:18 - 00419648 _____ C:\Windows\SysWOW64\locale.nls 2017-02-13 21:19 - 2016-10-11 07:17 - 00419648 _____ C:\Windows\system32\locale.nls 2017-02-13 21:19 - 2016-10-08 07:06 - 00633296 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe 2017-02-13 21:19 - 2016-10-04 09:31 - 00229376 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2017-02-13 21:19 - 2016-10-04 09:31 - 00190976 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2017-02-13 21:19 - 2016-10-04 09:31 - 00141824 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2017-02-13 21:19 - 2016-10-04 09:13 - 00179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2017-02-13 21:19 - 2016-10-04 09:13 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2017-02-13 21:19 - 2016-10-04 09:13 - 00106496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2017-02-13 20:33 - 2017-02-13 20:33 - 00000000 ____D C:\Users\Administrator.jwilson-PC\AppData\Roaming\AVG 2017-02-13 20:29 - 2017-02-17 21:58 - 00004178 _____ C:\Windows\System32\Tasks\Antivirus Emergency Update 2017-02-13 20:28 - 2017-02-13 20:29 - 00992488 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgsnx.sys 2017-02-13 20:28 - 2017-02-13 20:26 - 00555152 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgSP.sys 2017-02-13 20:28 - 2017-02-13 20:26 - 00336920 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgbloga.sys 2017-02-13 20:28 - 2017-02-13 20:26 - 00311592 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgbidsdrivera.sys 2017-02-13 20:28 - 2017-02-13 20:26 - 00311472 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgVmm.sys 2017-02-13 20:28 - 2017-02-13 20:26 - 00192096 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgbidsha.sys 2017-02-13 20:28 - 2017-02-13 20:26 - 00165624 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgbdiska.sys 2017-02-13 20:28 - 2017-02-13 20:26 - 00163512 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgStm.sys 2017-02-13 20:28 - 2017-02-13 20:26 - 00127072 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgMonFlt.sys 2017-02-13 20:28 - 2017-02-13 20:26 - 00101624 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgRdr2.sys 2017-02-13 20:28 - 2017-02-13 20:26 - 00075664 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgRvrt.sys 2017-02-13 20:28 - 2017-02-13 20:26 - 00050848 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgbuniva.sys 2017-02-13 20:28 - 2017-02-13 20:26 - 00039288 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgHwid.sys 2017-02-13 20:26 - 2017-02-13 20:26 - 00397800 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\avgBoot.exe 2017-02-13 20:21 - 2017-02-16 22:35 - 00000984 _____ C:\Users\Public\Desktop\AVG.lnk 2017-02-13 20:21 - 2017-02-16 22:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG Zen 2017-02-13 20:15 - 2017-02-18 13:59 - 00003600 _____ C:\Windows\System32\Tasks\AVG EUpdate Task 2017-02-13 20:15 - 2017-02-13 20:22 - 00000000 ____D C:\Program Files (x86)\AVG 2017-02-13 20:12 - 2017-02-13 22:05 - 00000000 ____D C:\ProgramData\Avg 2017-02-13 20:12 - 2017-02-13 20:21 - 00000000 ____D C:\Users\Administrator.jwilson-PC\AppData\Local\AvgSetupLog 2017-02-13 20:12 - 2017-02-13 20:12 - 00000000 ____D C:\Users\Administrator.jwilson-PC\AppData\Local\Avg 2017-02-13 09:53 - 2017-02-13 09:53 - 00000041 _____ C:\Users\Administrator.jwilson-PC\AppData\Roaming\mbam.context.scan 2017-02-13 09:50 - 2017-02-15 07:19 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2017-02-13 09:50 - 2017-02-14 22:06 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2 2017-02-13 09:50 - 2017-02-13 09:50 - 00001393 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk 2017-02-13 09:50 - 2017-02-13 09:50 - 00001381 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk 2017-02-13 09:50 - 2017-02-13 09:50 - 00000000 ____D C:\Windows\System32\Tasks\Safer-Networking 2017-02-13 09:50 - 2017-02-13 09:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2 2017-02-13 09:50 - 2013-09-20 10:49 - 00021040 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean64.exe 2017-02-13 01:14 - 2017-02-13 01:14 - 00016721 _____ C:\Users\Public\Documents\US79B-8DKGO-ETAKH-FTXKA-TXRXK-GTHXK-GGOTX-ZKAOY.html 2017-02-13 01:14 - 2017-02-13 01:14 - 00016721 _____ C:\Users\Administrator.jwilson-PC\AppData\Roaming\US79B-8DKGO-ETAKH-FTXKA-TXRXK-GTHXK-GGOTX-ZKAOY.html 2017-02-13 01:14 - 2017-02-13 01:14 - 00001088 _____ C:\Users\Administrator.jwilson-PC\AppData\Roaming\US79B-8DKGO-ETAKH-FTXKA-TXRXK-GTHXK-GGOTX-ZKAOY 2017-02-13 00:11 - 2017-02-13 01:14 - 96588424 _____ C:\Users\Administrator.jwilson-PC\AppData\Roaming\3091558760 2017-02-12 16:11 - 2017-02-12 16:11 - 00067594 _____ C:\Windows\alaredun.ini 2017-02-07 17:38 - 2017-02-07 17:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox 2017-02-06 22:38 - 2017-02-06 22:38 - 00046400 _____ (Dropbox, Inc.) C:\Windows\system32\DbxSvc.exe 2017-02-06 22:38 - 2017-02-06 22:38 - 00046192 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-stable.sys 2017-02-06 22:38 - 2017-02-06 22:38 - 00046192 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-dev.sys 2017-02-06 22:38 - 2017-02-06 22:38 - 00046192 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-canary.sys 2017-02-01 11:48 - 2017-02-01 11:48 - 00000990 _____ C:\Users\Administrator.jwilson-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\join.me.lnk 2017-02-01 11:48 - 2017-02-01 11:48 - 00000982 _____ C:\Users\Administrator.jwilson-PC\Desktop\join.me.lnk 2017-02-01 10:45 - 2017-02-01 11:48 - 00000000 ____D C:\Users\Administrator.jwilson-PC\AppData\Local\join.me 2017-01-27 09:01 - 2017-02-13 01:35 - 01401230 _____ C:\Users\Administrator.jwilson-PC\Documents\Appraisal.pdf ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2017-02-19 19:57 - 2012-04-16 08:14 - 00065536 _____ C:\Windows\system32\Ikeext.etl 2017-02-19 19:56 - 2011-08-07 08:22 - 692450290 _____ C:\Windows\MEMORY.DMP 2017-02-19 19:56 - 2011-08-07 08:22 - 00000000 ____D C:\Windows\Minidump 2017-02-19 19:54 - 2016-06-14 23:07 - 00000000 ____D C:\Users\Administrator.jwilson-PC\Documents\Outlook Files 2017-02-19 19:49 - 2015-01-28 13:24 - 00000000 ____D C:\Program Files (x86)\NortonInstaller 2017-02-19 19:46 - 2015-01-28 13:21 - 00000000 ____D C:\ProgramData\Symantec.cloud 2017-02-19 19:43 - 2015-01-28 13:21 - 00000000 ____D C:\Program Files\Symantec.cloud 2017-02-19 19:43 - 2009-07-13 21:20 - 00000000 ____D C:\Windows\tracing 2017-02-19 19:33 - 2016-07-01 21:56 - 00000918 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job 2017-02-19 19:32 - 2016-07-01 21:56 - 00000922 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job 2017-02-19 19:32 - 2011-04-12 14:31 - 00000000 ____D C:\ProgramData\NVIDIA 2017-02-19 19:32 - 2009-07-13 23:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2017-02-19 19:16 - 2009-07-13 23:13 - 00803850 _____ C:\Windows\system32\PerfStringBackup.INI 2017-02-19 19:16 - 2009-07-13 21:20 - 00000000 ____D C:\Windows\inf 2017-02-19 19:15 - 2017-01-18 13:17 - 00000554 _____ C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-1307699844-331912778-3280394059-500.job 2017-02-19 19:12 - 2013-04-08 07:39 - 00000000 ____D C:\Users\Administrator.jwilson-PC\AppData\Local\Deployment 2017-02-19 18:55 - 2016-10-21 22:50 - 00000000 ____D C:\Windows\pss 2017-02-19 08:56 - 2012-04-11 13:42 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2017-02-19 08:26 - 2017-01-18 13:17 - 00000650 _____ C:\Windows\Tasks\G2MUploadTask-S-1-5-21-1307699844-331912778-3280394059-500.job 2017-02-19 05:02 - 2009-07-13 22:45 - 00025424 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2017-02-19 05:02 - 2009-07-13 22:45 - 00025424 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2017-02-19 04:48 - 2014-11-10 11:49 - 00000000 ____D C:\ProgramData\MIRAgent 2017-02-18 18:12 - 2013-04-13 17:44 - 00000534 _____ C:\Windows\SMSCFG.INI 2017-02-18 14:31 - 2017-01-18 13:17 - 00003686 _____ C:\Windows\System32\Tasks\G2MUploadTask-S-1-5-21-1307699844-331912778-3280394059-500 2017-02-18 14:31 - 2017-01-18 13:17 - 00003590 _____ C:\Windows\System32\Tasks\G2MUpdateTask-S-1-5-21-1307699844-331912778-3280394059-500 2017-02-18 13:34 - 2016-06-27 17:00 - 00000000 ____D C:\Appraisal PDFs 2017-02-17 13:55 - 2016-06-25 21:10 - 00000000 ____D C:\Windows\SysWOW64\NV 2017-02-17 13:55 - 2016-06-25 21:10 - 00000000 ____D C:\Windows\system32\NV 2017-02-17 13:53 - 2016-07-01 20:53 - 00000000 ____D C:\Users\Administrator.jwilson-PC\AppData\Local\SlimWare Utilities Inc 2017-02-17 13:20 - 2012-03-23 07:29 - 00000000 ____D C:\Users\jlwilson2.US 2017-02-17 13:19 - 2014-03-28 08:11 - 00000000 ____D C:\Users\jlwilson2.US\AppData\Local\SoftUpdate 2017-02-17 13:17 - 2015-01-30 09:50 - 00000000 ____D C:\Users\jlwilson2.US\AppData\Local\SlimWare Utilities Inc 2017-02-17 13:10 - 2011-06-08 11:13 - 00000000 ____D C:\ProgramData\ICQ 2017-02-17 13:08 - 2013-05-13 14:20 - 00000000 ____D C:\ProgramData\APN 2017-02-17 13:08 - 2012-08-16 09:08 - 00000000 ____D C:\ProgramData\Browser Manager 2017-02-17 07:53 - 2016-07-01 20:53 - 00016152 _____ C:\Windows\system32\Drivers\SWDUMon.sys 2017-02-16 08:43 - 2009-07-13 21:20 - 00000000 ____D C:\Windows\system32\NDF 2017-02-16 08:33 - 2016-06-14 21:23 - 00000000 ____D C:\Users\Administrator.jwilson-PC\AppData\Local\ElevatedDiagnostics 2017-02-16 08:33 - 2011-04-12 15:05 - 00000000 ____D C:\ProgramData\Sonic 2017-02-15 21:02 - 2009-07-13 21:20 - 00000000 ____D C:\Windows\rescache 2017-02-15 11:38 - 2016-06-14 19:58 - 00000000 ____D C:\ProgramData\alamode 2017-02-15 11:31 - 2009-07-13 22:45 - 05058960 _____ C:\Windows\system32\FNTCACHE.DAT 2017-02-15 11:30 - 2012-03-23 07:21 - 00133312 _____ C:\Users\Administrator.jwilson-PC\AppData\Local\GDIPFONTCACHEV1.DAT 2017-02-15 07:25 - 2011-08-22 07:59 - 00000000 ____D C:\QUARANTINE 2017-02-15 07:16 - 2014-04-02 06:30 - 00000000 ____D C:\Users\jlwilson2.US\AppData\Local\TB 2017-02-14 22:06 - 2016-06-28 10:04 - 00000000 ____D C:\Program Files\Common Files\AV 2017-02-14 20:42 - 2016-06-28 10:05 - 00000000 ____D C:\Users\Administrator.jwilson-PC\AppData\Local\tkdata 2017-02-14 11:52 - 2016-06-23 21:23 - 00000000 ____D C:\Users\Administrator.jwilson-PC\AppData\Local\CrashDumps 2017-02-14 09:32 - 2012-08-17 06:11 - 00001141 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2017-02-14 09:32 - 2012-08-17 06:11 - 00001141 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2017-02-14 08:32 - 2016-07-01 22:04 - 00000000 ___RD C:\Users\Administrator.jwilson-PC\Dropbox 2017-02-13 22:42 - 2011-06-17 06:30 - 00798718 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2017-02-13 22:11 - 2014-06-05 10:54 - 00000000 ____D C:\Windows\system32\MRT 2017-02-13 21:26 - 2011-06-03 09:36 - 135657872 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe 2017-02-13 10:01 - 2013-09-02 13:15 - 00000000 ____D C:\Program Files\Common Files\Apple 2017-02-13 09:19 - 2016-07-05 09:37 - 00000000 ____D C:\Users\Administrator.jwilson-PC\AppData\Local\CutePDF Writer 2017-02-13 01:36 - 2015-02-25 15:28 - 00076799 _____ C:\Users\jlwilson2.US\Downloads\LC06QF.pdf 2017-02-13 01:36 - 2015-02-25 09:45 - 00181730 _____ C:\Users\jlwilson2.US\Downloads\Football Schedule 2014 (3).pdf 2017-02-13 01:36 - 2015-02-25 09:44 - 00181730 _____ C:\Users\jlwilson2.US\Downloads\Football Schedule 2014.pdf 2017-02-13 01:36 - 2015-02-25 09:44 - 00181730 _____ C:\Users\jlwilson2.US\Downloads\Football Schedule 2014 (2).pdf 2017-02-13 01:36 - 2015-02-25 09:44 - 00181730 _____ C:\Users\jlwilson2.US\Downloads\Football Schedule 2014 (1).pdf 2017-02-13 01:36 - 2015-02-25 07:59 - 05385601 _____ C:\Users\jlwilson2.US\Downloads\Sched Star- Big Teams.pptx 2017-02-13 01:36 - 2015-02-17 12:37 - 00134062 _____ C:\Users\jlwilson2.US\Downloads\Arbiter SetUp (1).pdf 2017-02-13 01:36 - 2015-02-17 12:36 - 00134062 _____ C:\Users\jlwilson2.US\Downloads\Arbiter SetUp.pdf 2017-02-13 01:36 - 2015-02-09 12:59 - 00439499 _____ C:\Users\jlwilson2.US\Downloads\dxweb (2).pdf 2017-02-13 01:36 - 2015-02-09 12:57 - 00439409 _____ C:\Users\jlwilson2.US\Downloads\dxweb (1).pdf 2017-02-13 01:36 - 2015-02-09 08:09 - 00107781 _____ C:\Users\jlwilson2.US\Documents\Schedule Star Big Teams Sales.pdf 2017-02-13 01:36 - 2015-02-05 13:27 - 00168948 _____ C:\Users\jlwilson2.US\Documents\Michigan eligibility.pdf 2017-02-13 01:36 - 2015-02-05 13:24 - 00127918 _____ C:\Users\jlwilson2.US\Documents\Student Import Guide.pdf 2017-02-13 01:36 - 2015-02-05 13:23 - 00142233 _____ C:\Users\jlwilson2.US\Documents\Stats User Guide.pdf 2017-02-13 01:36 - 2015-02-05 13:22 - 00069430 _____ C:\Users\jlwilson2.US\Documents\SS_Parent_Guide.pdf 2017-02-13 01:36 - 2015-02-05 13:21 - 00073030 _____ C:\Users\jlwilson2.US\Documents\Sig Logo Order Form.pdf 2017-02-13 01:36 - 2015-02-05 13:19 - 00362685 _____ C:\Users\jlwilson2.US\Documents\Resetting Internet Options.pdf 2017-02-13 01:36 - 2015-02-05 13:19 - 00157173 _____ C:\Users\jlwilson2.US\Documents\Reminder Setup.pdf 2017-02-13 01:36 - 2015-02-05 13:17 - 00521544 _____ C:\Users\jlwilson2.US\Documents\Registering for Alerts.pdf 2017-02-13 01:36 - 2015-02-05 13:16 - 00083648 _____ C:\Users\jlwilson2.US\Documents\Pricing Sheet.pdf 2017-02-13 01:36 - 2015-02-05 13:15 - 00174611 _____ C:\Users\jlwilson2.US\Documents\Mirror Guide.pdf 2017-02-13 01:36 - 2015-02-05 12:32 - 00485668 _____ C:\Users\jlwilson2.US\Documents\League Central.pdf 2017-02-13 01:36 - 2015-02-04 10:05 - 00439409 _____ C:\Users\jlwilson2.US\Downloads\dxweb.pdf 2017-02-13 01:36 - 2015-02-02 12:35 - 00206870 _____ C:\Users\jlwilson2.US\Downloads\Job Description Principal.pdf 2017-02-13 01:36 - 2015-02-02 12:33 - 00166667 _____ C:\Users\jlwilson2.US\Downloads\Winter Sports Schedule 2014-15.pdf 2017-02-13 01:36 - 2015-01-27 10:05 - 00215636 _____ C:\Users\jlwilson2.US\Documents\Order_Form.pdf 2017-02-13 01:36 - 2015-01-13 09:12 - 00010801 _____ C:\Users\jlwilson2.US\Downloads\PDF - GIRLS BKB SNFORM - 11-17-14.pdf 2017-02-13 01:36 - 2015-01-13 09:12 - 00010758 _____ C:\Users\jlwilson2.US\Downloads\PDF - BOYS BKB SNFORM - 11-17-14.pdf 2017-02-13 01:36 - 2015-01-02 20:20 - 00016575 _____ C:\Users\jlwilson2.US\Downloads\officiatingContract_2046516.pdf 2017-02-13 01:36 - 2014-12-17 10:57 - 00078662 _____ C:\Users\jlwilson2.US\Documents\Schedule Star logo.signature order form.pdf 2017-02-13 01:36 - 2014-12-16 13:43 - 00016565 _____ C:\Users\jlwilson2.US\Downloads\officiatingContract_2107243.pdf 2017-02-13 01:36 - 2014-12-16 08:51 - 00066554 _____ C:\Users\jlwilson2.US\Documents\National Show Expenses 14.pdf 2017-02-13 01:36 - 2014-11-25 08:39 - 00026437 _____ C:\Users\jlwilson2.US\Documents\Schedule for the Week of 11-29.pdf 2017-02-13 01:36 - 2014-11-20 07:37 - 01210368 _____ C:\Users\jlwilson2.US\Downloads\Closed Date Form 2014-15 (1).pdf 2017-02-13 01:36 - 2014-11-19 13:41 - 00750624 _____ C:\Users\jlwilson2.US\Documents\OIAAA Conf. Expenses.pdf 2017-02-13 01:36 - 2014-11-07 11:11 - 00551439 _____ C:\Users\jlwilson2.US\Downloads\QRKDXRJT-PDF-20758-16390-1-PDF.pdf 2017-02-13 01:36 - 2014-11-07 07:14 - 00116246 _____ C:\Users\jlwilson2.US\Documents\Wilson, James 11-4-2014.pdf 2017-02-13 01:36 - 2014-10-23 11:52 - 00016569 _____ C:\Users\jlwilson2.US\Downloads\officiatingContract_2046153.pdf 2017-02-13 01:36 - 2014-10-23 11:50 - 00028117 _____ C:\Users\jlwilson2.US\Downloads\officiatingContract_2030892.pdf 2017-02-13 01:36 - 2014-10-17 11:31 - 00016579 _____ C:\Users\jlwilson2.US\Downloads\officiatingContract_2037840.pdf 2017-02-13 01:36 - 2014-10-16 12:30 - 06384778 _____ C:\Users\jlwilson2.US\Documents\ScheduleStar_6x6_booklet.pdf 2017-02-13 01:36 - 2014-10-16 08:11 - 00316575 _____ C:\Users\jlwilson2.US\Downloads\2013-14 Calendar.pdf 2017-02-13 01:36 - 2014-10-16 08:08 - 00152892 _____ C:\Users\jlwilson2.US\Downloads\Winter Sports 13-14.pdf 2017-02-13 01:36 - 2014-10-15 07:41 - 00027862 _____ C:\Users\jlwilson2.US\Downloads\officiatingContract.pdf 2017-02-13 01:36 - 2014-10-14 08:40 - 00279236 _____ C:\Users\jlwilson2.US\Downloads\Wilson, James.pdf 2017-02-13 01:36 - 2014-10-13 10:57 - 00016612 _____ C:\Users\jlwilson2.US\Downloads\officiatingContract_2030884.pdf 2017-02-13 01:36 - 2014-10-13 10:57 - 00016612 _____ C:\Users\jlwilson2.US\Downloads\officiatingContract_2030884 (1).pdf 2017-02-13 01:36 - 2014-10-13 09:51 - 00031742 _____ C:\Users\jlwilson2.US\Documents\Portage Central Invoice & Receipt.pdf 2017-02-13 01:36 - 2014-10-09 11:50 - 00259036 _____ C:\Users\jlwilson2.US\Documents\James Wilson's Schedule.pdf 2017-02-13 01:36 - 2014-09-24 06:51 - 00291227 _____ C:\Users\jlwilson2.US\Downloads\HCHS-Fall-Sports-Schedule-2014.pdf 2017-02-13 01:36 - 2014-08-13 07:17 - 00086035 _____ C:\Users\jlwilson2.US\Documents\Schedule Star Quick Start Guide.pdf 2017-02-13 01:36 - 2014-06-24 11:41 - 00085788 _____ C:\Users\jlwilson2.US\Downloads\OSSAA Eligibility Record Form.pdf 2017-02-13 01:36 - 2014-06-20 06:36 - 00042784 _____ C:\Users\jlwilson2.US\Downloads\067277 (1).pdf 2017-02-13 01:36 - 2014-06-18 12:34 - 00042784 _____ C:\Users\jlwilson2.US\Downloads\067277.pdf 2017-02-13 01:36 - 2014-06-10 11:19 - 00083890 _____ C:\Users\jlwilson2.US\Downloads\ahs-football.pdf 2017-02-13 01:36 - 2014-06-02 06:30 - 01210368 _____ C:\Users\jlwilson2.US\Downloads\Closed Date Form 2014-15.pdf 2017-02-13 01:36 - 2014-05-07 07:14 - 00161256 _____ C:\Users\jlwilson2.US\Downloads\2013-14 Physical Exam Form.pdf 2017-02-13 01:36 - 2014-05-07 07:14 - 00161256 _____ C:\Users\jlwilson2.US\Downloads\2013-14 Physical Exam Form (1).pdf 2017-02-13 01:36 - 2014-04-29 07:13 - 00049046 _____ C:\Users\jlwilson2.US\Documents\Upgrade Form.pdf 2017-02-13 01:36 - 2014-04-25 12:25 - 00085635 _____ C:\Users\jlwilson2.US\Downloads\Miner_volleyball.pdf 2017-02-13 01:36 - 2014-04-24 08:58 - 00024460 _____ C:\Users\jlwilson2.US\Downloads\officiatingContract_1764867.pdf 2017-02-13 01:36 - 2014-04-24 08:58 - 00013218 _____ C:\Users\jlwilson2.US\Downloads\officiatingContract_1879325.pdf 2017-02-13 01:36 - 2014-04-23 08:46 - 00024375 _____ C:\Users\jlwilson2.US\Downloads\officiatingContract_1874927.pdf 2017-02-13 01:36 - 2014-04-23 08:45 - 00024423 _____ C:\Users\jlwilson2.US\Downloads\officiatingContract_1850254.pdf 2017-02-13 01:36 - 2014-03-11 09:58 - 07798965 _____ C:\Users\jlwilson2.US\Documents\Phone List 2013-14.pdf 2017-02-13 01:36 - 2014-01-06 08:23 - 00013926 _____ C:\Users\jlwilson2.US\Documents\Server's List.pdf 2017-02-13 01:36 - 2013-12-13 11:37 - 00356071 _____ C:\Users\jlwilson2.US\Documents\Schedule Star Resetting Internet Options.pdf 2017-02-13 01:36 - 2013-12-12 10:03 - 03934167 _____ C:\Users\jlwilson2.US\Documents\SS.AllPlayers(v2).pdf 2017-02-13 01:36 - 2013-12-12 10:03 - 00211760 _____ C:\Users\jlwilson2.US\Documents\SS OnLine Registration.pdf 2017-02-13 01:36 - 2013-11-26 18:46 - 00207598 _____ C:\Users\jlwilson2.US\Documents\Presentation1.pptx 2017-02-13 01:36 - 2013-11-17 13:50 - 00072298 _____ C:\Users\jlwilson2.US\Documents\Schedule Star LINKING TO SS.com.pdf-3.doc.pdf 2017-02-13 01:36 - 2013-10-29 09:01 - 00148905 _____ C:\Users\jlwilson2.US\Documents\SS - Parent Guide.pdf 2017-02-13 01:36 - 2013-10-25 10:36 - 07233645 _____ C:\Users\jlwilson2.US\Documents\Schedule Star.pdf 2017-02-13 01:36 - 2013-10-01 12:04 - 00165365 _____ C:\Users\jlwilson2.US\Documents\Stats Guide for Coaches.pdf 2017-02-13 01:36 - 2013-09-29 09:14 - 00546710 _____ C:\Users\jlwilson2.US\Documents\Wilson, James.pdf 2017-02-13 01:36 - 2013-09-06 06:30 - 00031709 _____ C:\Users\jlwilson2.US\Documents\Jimmy's Frequent Flyer Info.pdf 2017-02-13 01:36 - 2013-09-06 06:19 - 00566563 _____ C:\Users\jlwilson2.US\Documents\OIAAA Exhibitor & Sponsor Prospectus-2013.pdf 2017-02-13 01:36 - 2013-04-25 12:50 - 00065698 _____ C:\Users\jlwilson2.US\Documents\James Wilson Resume.pdf 2017-02-13 01:36 - 2012-11-12 22:00 - 00321713 _____ C:\Users\jlwilson2.US\Documents\Ohio AD Show 12.pdf 2017-02-13 01:36 - 2012-08-02 11:27 - 00150947 _____ C:\Users\jlwilson2.US\Documents\Why Salespeople Fail.pdf 2017-02-13 01:35 - 2017-01-18 10:50 - 00008434 _____ C:\Users\Administrator.jwilson-PC\Downloads\Appraisal_For_JasmineLRunaas&BenjaminRRunaas_Loan_00668289000.pdf 2017-02-13 01:35 - 2017-01-18 10:49 - 03122899 _____ C:\Users\Administrator.jwilson-PC\Downloads\MyAMCEngagementLetter_30618 (1).pdf 2017-02-13 01:35 - 2017-01-18 10:48 - 00236049 _____ C:\Users\Administrator.jwilson-PC\Downloads\FHA_1004_Specs_03302016.pdf 2017-02-13 01:35 - 2017-01-18 10:46 - 03122899 _____ C:\Users\Administrator.jwilson-PC\Downloads\MyAMCEngagementLetter_30618.pdf 2017-02-13 01:35 - 2017-01-18 10:45 - 00966105 _____ C:\Users\Administrator.jwilson-PC\Downloads\Runaas_AO.pdf 2017-02-13 01:35 - 2016-06-30 11:51 - 00010567 _____ C:\Users\Administrator.jwilson-PC\Downloads\order959-1467309123.pdf 2017-02-13 01:35 - 2016-06-30 11:50 - 00010567 _____ C:\Users\Administrator.jwilson-PC\Downloads\order959-1467309050.pdf 2017-02-13 01:35 - 2016-06-29 13:52 - 00119637 _____ C:\Users\Administrator.jwilson-PC\Downloads\LegacyBill.pdf 2017-02-13 01:35 - 2016-06-29 13:52 - 00119637 _____ C:\Users\Administrator.jwilson-PC\Downloads\LegacyBill (1).pdf 2017-02-13 01:35 - 2016-06-28 18:24 - 00154750 _____ C:\Users\Administrator.jwilson-PC\Downloads\order_message_842.pdf 2017-02-13 01:35 - 2016-06-28 12:53 - 00291569 _____ C:\Users\Administrator.jwilson-PC\Downloads\ExportedReport.pdf 2017-02-13 01:35 - 2016-06-27 12:55 - 00019671 _____ C:\Users\Administrator.jwilson-PC\Documents\ACH Advisement.pdf 2017-02-13 01:35 - 2016-06-15 16:34 - 00020956 _____ C:\Users\Administrator.jwilson-PC\Downloads\calendar_2016-07-01_2016-08-01.pdf 2017-02-13 01:35 - 2015-02-25 08:00 - 05385601 _____ C:\Users\jlwilson2.US\Desktop\Sched Star- Big Teams.pptx 2017-02-13 01:35 - 2015-02-17 12:37 - 00134062 _____ C:\Users\jlwilson2.US\Desktop\Arbiter SetUp (1).pdf 2017-02-13 01:35 - 2015-02-09 08:07 - 00051482 _____ C:\Users\jlwilson2.US\Documents\2015 W-9.pdf 2017-02-13 01:35 - 2015-02-05 14:47 - 00092130 _____ C:\Users\jlwilson2.US\Desktop\Credit Card Form w fields.pdf 2017-02-13 01:35 - 2015-02-05 12:31 - 00141150 _____ C:\Users\jlwilson2.US\Documents\iCal Setup.pdf 2017-02-13 01:35 - 2015-02-05 12:30 - 00427941 _____ C:\Users\jlwilson2.US\Documents\Game Wizard.pdf 2017-02-13 01:35 - 2015-02-05 12:30 - 00318240 _____ C:\Users\jlwilson2.US\Documents\Granting Permissions for Stats Access.pdf 2017-02-13 01:35 - 2015-02-05 12:17 - 00075998 _____ C:\Users\jlwilson2.US\Documents\Creating SS Links.pdf 2017-02-13 01:35 - 2015-02-05 12:08 - 00172852 _____ C:\Users\jlwilson2.US\Documents\Creating Season Links.pdf 2017-02-13 01:35 - 2015-02-05 12:05 - 00361377 _____ C:\Users\jlwilson2.US\Documents\Clearing Cookies.pdf 2017-02-13 01:35 - 2015-01-27 10:05 - 00215636 _____ C:\Users\jlwilson2.US\Desktop\Order_Form.pdf 2017-02-13 01:35 - 2015-01-13 11:06 - 00029580 _____ C:\Users\jlwilson2.US\Documents\Boys Self Nomination.pdf 2017-02-13 01:35 - 2015-01-13 11:06 - 00029501 _____ C:\Users\jlwilson2.US\Documents\Girls Self Nomination.pdf 2017-02-13 01:35 - 2014-12-16 10:28 - 00053024 _____ C:\Users\jlwilson2.US\Documents\James Wilson Exp. Report Nationals.pdf 2017-02-13 01:35 - 2014-12-03 10:08 - 00030857 _____ C:\Users\jlwilson2.US\Documents\Ecorse HS Quote.pdf 2017-02-13 01:35 - 2014-11-21 10:24 - 00141822 _____ C:\Users\jlwilson2.US\Documents\All Players Online Registration.pdf 2017-02-13 01:35 - 2014-11-20 07:49 - 00173761 _____ C:\Users\jlwilson2.US\Documents\J. Mack's Closeout Dates.pdf 2017-02-13 01:35 - 2014-10-22 11:16 - 20890682 _____ C:\Users\jlwilson2.US\Desktop\2014 Show PPT-final(v4.1).pdf 2017-02-13 01:35 - 2014-07-25 07:28 - 00405872 _____ C:\Users\jlwilson2.US\Documents\Brown Paper Ticket.pdf 2017-02-13 01:35 - 2014-06-02 07:56 - 00345290 _____ C:\Users\jlwilson2.US\Documents\Closeouts Dates Sheet.pdf 2017-02-13 01:35 - 2014-04-17 06:22 - 00795514 _____ C:\Users\jlwilson2.US\Documents\HighSchoolCube.pdf 2017-02-13 01:35 - 2013-11-17 13:54 - 00565401 _____ C:\Users\jlwilson2.US\Documents\Creating Team Page Links(2).pdf 2017-02-13 01:35 - 2013-10-04 06:35 - 00097864 _____ C:\Users\jlwilson2.US\Documents\Call Forwarding info.pdf 2017-02-13 01:35 - 2013-09-06 06:18 - 04694584 _____ C:\Users\jlwilson2.US\Documents\1193371-1.pdf 2017-02-13 01:35 - 2012-03-12 17:21 - 00097795 _____ C:\Users\jlwilson2\Desktop\certificate BB.pdf 2017-02-13 01:35 - 2012-03-05 21:30 - 00097795 _____ C:\Users\jlwilson2\Desktop\certificate.pdf 2017-02-13 01:35 - 2011-07-19 11:17 - 03371017 _____ C:\Users\jlwilson2\Desktop\4701 Tournament event.pdf 2017-02-13 01:35 - 2011-07-19 11:17 - 00395013 _____ C:\Users\jlwilson2\Desktop\4701 Meet event.pdf 2017-02-13 01:16 - 2015-03-02 13:14 - 00043140 _____ C:\Users\jlwilson2.US\Documents\NV Show Expense 15.xls 2017-02-13 01:16 - 2015-03-02 12:49 - 00043652 _____ C:\Users\jlwilson2.US\Desktop\BT Expense Report.xls 2017-02-13 01:16 - 2015-03-02 11:04 - 00277124 _____ C:\Users\jlwilson2.US\Documents\Spartanburg School District Quote.xls 2017-02-13 01:16 - 2015-02-18 09:35 - 00022148 _____ C:\Users\jlwilson2.US\Downloads\JHBBB_13-14_schedule(bus).xls 2017-02-13 01:16 - 2015-02-18 09:34 - 00024708 _____ C:\Users\jlwilson2.US\Downloads\VB 14_schedule(bus).xls 2017-02-13 01:16 - 2015-01-30 12:27 - 00011994 _____ C:\Users\jlwilson2.US\Downloads\HS Football.xlsx 2017-02-13 01:16 - 2015-01-30 12:27 - 00011994 _____ C:\Users\jlwilson2.US\Downloads\HS Football (1).xlsx 2017-02-13 01:16 - 2015-01-20 08:33 - 00034084 _____ C:\Users\jlwilson2.US\Desktop\8to18list.xlsx 2017-02-13 01:16 - 2015-01-15 08:37 - 00043652 _____ C:\Users\jlwilson2.US\Downloads\WHSAthleticSchedules2014-2015.xls 2017-02-13 01:16 - 2015-01-08 14:38 - 00143793 _____ C:\Users\jlwilson2.US\Desktop\BigTeamsContacts1_8_15.xlsx 2017-02-13 01:16 - 2014-12-30 09:50 - 00013367 _____ C:\Users\jlwilson2.US\Desktop\2014 Nationals.xlsx 2017-02-13 01:16 - 2014-12-23 08:20 - 00016795 _____ C:\Users\jlwilson2.US\Downloads\basketball phone list 2014-15.xlsx 2017-02-13 01:16 - 2014-12-23 08:20 - 00016795 _____ C:\Users\jlwilson2.US\Desktop\basketball phone list 2014-15.xlsx 2017-02-13 01:16 - 2014-12-18 08:51 - 00060245 _____ C:\Users\jlwilson2.US\Desktop\BigTeamsClients12_18_14.xlsx 2017-02-13 01:16 - 2014-12-17 15:02 - 00014944 _____ C:\Users\jlwilson2.US\Downloads\School District.xlsx 2017-02-13 01:16 - 2014-12-16 12:02 - 00045700 _____ C:\Users\jlwilson2.US\Desktop\Contact List.xls 2017-02-13 01:16 - 2014-12-16 10:22 - 00042628 _____ C:\Users\jlwilson2.US\Documents\National Show Expense 2.xls 2017-02-13 01:16 - 2014-12-16 10:19 - 00042116 _____ C:\Users\jlwilson2.US\Documents\National Show Expense 1.xls 2017-02-13 01:16 - 2014-12-16 10:10 - 00042628 _____ C:\Users\jlwilson2.US\Downloads\National Show Expense.xls 2017-02-13 01:16 - 2014-11-26 12:22 - 00080458 _____ C:\Users\jlwilson2.US\Downloads\32 Board - 2014 (6).xlsx 2017-02-13 01:16 - 2014-11-21 10:19 - 00272516 _____ C:\Users\jlwilson2.US\Downloads\Frankel-Jewish-Academy-Quote_1360542139471412878298.xls 2017-02-13 01:16 - 2014-11-21 08:25 - 00080359 _____ C:\Users\jlwilson2.US\Downloads\32 Board - 2014 (5).xlsx 2017-02-13 01:16 - 2014-11-17 09:50 - 00027264 _____ C:\Users\jlwilson2.US\Downloads\TeamSchedule (1).xls 2017-02-13 01:16 - 2014-11-14 15:24 - 00013860 _____ C:\Users\jlwilson2.US\Documents\OIAAA Estimate Expenses.xlsx 2017-02-13 01:16 - 2014-11-13 10:15 - 00027616 _____ C:\Users\jlwilson2.US\Desktop\User Testing Names-2[2].xlsx 2017-02-13 01:16 - 2014-11-11 10:38 - 00078991 _____ C:\Users\jlwilson2.US\Downloads\32 Board - 2014 (4).xlsx 2017-02-13 01:16 - 2014-11-11 07:29 - 00000295 _____ C:\Users\jlwilson2.US\Downloads\TeamSchedule.xls 2017-02-13 01:16 - 2014-10-28 09:39 - 00078819 _____ C:\Users\jlwilson2.US\Downloads\32 Board - 2014 (3).xlsx 2017-02-13 01:16 - 2014-10-21 07:32 - 00078726 _____ C:\Users\jlwilson2.US\Downloads\32 Board - 2014 (2).xlsx 2017-02-13 01:16 - 2014-10-17 11:43 - 00077956 _____ C:\Users\jlwilson2.US\Documents\Off-phone-2014-15 (1).xls 2017-02-13 01:16 - 2014-10-17 11:38 - 00077956 _____ C:\Users\jlwilson2.US\Downloads\Off-phone-2014-15 (1).xls 2017-02-13 01:16 - 2014-10-14 08:34 - 00077956 _____ C:\Users\jlwilson2.US\Desktop\Off-phone-2014-15.xls 2017-02-13 01:16 - 2014-10-14 08:32 - 00077956 _____ C:\Users\jlwilson2.US\Downloads\Off-phone-2014-15.xls 2017-02-13 01:16 - 2014-10-08 11:57 - 00010309 _____ C:\Users\jlwilson2.US\Documents\Copy of '14 Sales Flex Spreadsheet.xlsx 2017-02-13 01:16 - 2014-09-30 06:26 - 00080108 _____ C:\Users\jlwilson2.US\Downloads\32 Board - 2014 (1).xlsx 2017-02-13 01:16 - 2014-09-29 13:13 - 00272004 _____ C:\Users\jlwilson2.US\Downloads\Highland-High-School-Quote_1360542139471412017617 (1).xls 2017-02-13 01:16 - 2014-09-29 13:07 - 00272516 _____ C:\Users\jlwilson2.US\Downloads\Highland-High-School-Quote_1360542139471412017617.xls 2017-02-13 01:16 - 2014-09-10 10:23 - 00012107 _____ C:\Users\jlwilson2.US\Documents\Copy of Copy of '14 J Wilson Commission Structure.xlsx 2017-02-13 01:16 - 2014-09-10 08:33 - 00082052 _____ C:\Users\jlwilson2.US\Downloads\2014 MIAAA Vendors at Conference (1).xls 2017-02-13 01:16 - 2014-09-10 08:32 - 00082052 _____ C:\Users\jlwilson2.US\Downloads\2014 MIAAA Vendors at Conference.xls 2017-02-13 01:16 - 2014-09-09 14:25 - 00010829 _____ C:\Users\jlwilson2.US\Documents\Copy of Sales Terriorities(9 9 14).xlsx 2017-02-13 01:16 - 2014-09-09 11:24 - 00004534 _____ C:\Users\jlwilson2.US\Downloads\eligibility.xls 2017-02-13 01:16 - 2014-09-09 07:15 - 00073430 _____ C:\Users\jlwilson2.US\Downloads\32 Board - 2014.xlsx 2017-02-13 01:16 - 2014-09-05 12:13 - 00035475 _____ C:\Users\jlwilson2.US\Documents\Sales Terriorities(9.5.14).xlsx 2017-02-13 01:16 - 2014-08-28 13:25 - 00090281 _____ C:\Users\jlwilson2.US\Documents\Copy of AD Contacts 2014-15 (2).xlsx 2017-02-13 01:16 - 2014-08-28 08:15 - 00088817 _____ C:\Users\jlwilson2.US\Desktop\AD Contacts 2014-15.xlsx 2017-02-13 01:16 - 2014-08-15 13:50 - 00013691 _____ C:\Users\jlwilson2.US\Documents\June-July Retention.xlsx 2017-02-13 01:16 - 2014-08-13 10:22 - 00272516 _____ C:\Users\jlwilson2.US\Downloads\Intermountain-League-Quote-5-7-2014_1360542139471400098171 (1).xls 2017-02-13 01:16 - 2014-07-22 13:18 - 00272516 _____ C:\Users\jlwilson2.US\Documents\Riverview Gardens Quote.xls 2017-02-13 01:16 - 2014-07-08 11:56 - 00013596 _____ C:\Users\jlwilson2.US\Downloads\13-14 Football schedules.xlsx 2017-02-13 01:16 - 2014-06-04 11:22 - 00272516 _____ C:\Users\jlwilson2.US\Downloads\Beaver-High-School-Quote_1360542139471401456598.xls 2017-02-13 01:16 - 2014-06-04 10:39 - 00095364 _____ C:\Users\jlwilson2.US\Documents\Sales Lead Sheet Angela.xls 2017-02-13 01:16 - 2014-06-04 08:30 - 00038532 _____ C:\Users\jlwilson2.US\Documents\Okla Check Req Form.xls 2017-02-13 01:16 - 2014-05-30 08:55 - 00272516 _____ C:\Users\jlwilson2.US\Downloads\Intermountain-League-Quote-5-7-2014_1360542139471400098171.xls 2017-02-13 01:16 - 2014-05-13 07:47 - 00272004 _____ C:\Users\jlwilson2.US\Documents\Wray School District Quote.xls 2017-02-13 01:16 - 2014-05-07 09:31 - 00272516 _____ C:\Users\jlwilson2.US\Documents\Intermountain League Quote 5-7-2014.xls 2017-02-13 01:16 - 2014-04-30 12:55 - 00111525 _____ C:\Users\jlwilson2.US\Downloads\studhistoryexcel (3).xls 2017-02-13 01:16 - 2014-04-22 11:20 - 00029828 _____ C:\Users\jlwilson2.US\Downloads\Copy of 2013-2014 Schedule.xls 2017-02-13 01:16 - 2014-04-09 12:04 - 00011806 _____ C:\Users\jlwilson2.US\Downloads\studlistexcel (2).xls 2017-02-13 01:16 - 2014-04-09 12:01 - 00007392 _____ C:\Users\jlwilson2.US\Downloads\studcontactsexcel.xls 2017-02-13 01:16 - 2014-04-09 11:59 - 00011806 _____ C:\Users\jlwilson2.US\Downloads\studlistexcel (1).xls 2017-02-13 01:16 - 2014-04-09 08:28 - 01553028 _____ C:\Users\jlwilson2.US\Downloads\2013FallEligibility.xls 2017-02-13 01:16 - 2014-04-09 08:28 - 00181892 _____ C:\Users\jlwilson2.US\Downloads\2014SpringEligibility.xls 2017-02-13 01:16 - 2014-04-07 09:38 - 00038473 _____ C:\Users\jlwilson2.US\Downloads\studhistoryexcel (2).xls 2017-02-13 01:16 - 2014-04-07 09:37 - 00075395 _____ C:\Users\jlwilson2.US\Downloads\studlistexcel.xls 2017-02-13 01:16 - 2014-04-07 09:35 - 00163026 _____ C:\Users\jlwilson2.US\Downloads\studhistoryexcel.xls 2017-02-13 01:16 - 2014-04-07 09:35 - 00163026 _____ C:\Users\jlwilson2.US\Downloads\studhistoryexcel (1).xls 2017-02-13 01:16 - 2014-03-27 12:59 - 00038532 _____ C:\Users\jlwilson2.US\Documents\Chk Req PO Form.xls 2017-02-13 01:16 - 2014-03-11 09:59 - 00013897 _____ C:\Users\jlwilson2.US\Documents\T&E Estimate Worksheet(rev8.26.13).xlsx 2017-02-13 01:16 - 2014-03-10 11:21 - 00019641 _____ C:\Users\jlwilson2.US\Documents\SS2 controlled test group.xlsx 2017-02-13 01:16 - 2014-02-10 08:15 - 00012089 _____ C:\Users\jlwilson2.US\Documents\'14 J Wilson Commission Structure.xlsx 2017-02-13 01:16 - 2012-03-20 13:14 - 01025156 _____ C:\Users\jlwilson2\Desktop\SS Schools - Feb 2012.xls 2017-02-13 01:16 - 2012-03-20 13:14 - 00049796 _____ C:\Users\jlwilson2\Desktop\'12 MAR-Subscription Analysis.xls 2017-02-13 01:16 - 2012-03-08 12:19 - 00030923 _____ C:\Users\jlwilson2\Desktop\SS sales Terrirtory list(12.14.11).xlsx 2017-02-13 01:16 - 2012-01-24 11:02 - 00028804 _____ C:\Users\jlwilson2\Desktop\'12 JAN-Subscription Analysis.xls 2017-02-13 01:16 - 2012-01-06 07:10 - 00085636 _____ C:\Users\jlwilson2\Desktop\cms master list 1.5.12(AMC).xls 2017-02-13 01:16 - 2011-12-08 07:33 - 00030947 _____ C:\Users\jlwilson2\Desktop\SS sales Terrirtory list(8.4.11).xlsx 2017-02-12 16:11 - 2016-06-14 21:16 - 00000951 _____ C:\Windows\alamode.ini 2017-02-11 14:30 - 2015-01-28 13:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Symantec.cloud 2017-02-10 12:21 - 2016-06-28 12:15 - 00000197 _____ C:\Windows\HASHTABLE 2017-02-08 12:41 - 2009-07-13 23:32 - 00000000 ____D C:\Windows\system32\FxsTmp 2017-02-07 17:38 - 2016-07-01 21:56 - 00000000 ____D C:\Program Files (x86)\Dropbox 2017-02-06 17:57 - 2014-03-28 08:00 - 00002197 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2017-02-06 17:57 - 2014-03-28 08:00 - 00002185 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2017-01-29 18:33 - 2016-12-09 09:24 - 00000000 ____D C:\Real Estate 2017-01-28 08:57 - 2009-07-13 23:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD 2017-01-27 12:24 - 2009-07-13 22:57 - 00001547 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk 2017-01-21 00:46 - 2016-06-29 09:09 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk ==================== Files in the root of some directories ======= 2016-07-02 21:34 - 2016-07-02 21:34 - 2570096 _____ (Acro Software Inc. ) C:\Program Files\CuteWriter.exe 2016-07-03 19:23 - 2016-07-03 19:24 - 8657773 _____ () C:\Program Files\DreamAquariumXP (1).exe 2016-07-03 19:21 - 2016-07-03 19:21 - 8657773 _____ () C:\Program Files\DreamAquariumXP.exe 2016-07-04 17:08 - 2016-07-04 17:08 - 3598128 _____ (Prolific Publishing, Inc. ) C:\Program Files\MarineAquarium3.exe 2016-07-05 15:33 - 2016-07-05 15:33 - 9509032 _____ (TeamViewer GmbH) C:\Program Files\TeamViewer_Setup.exe 2016-07-05 17:17 - 2016-07-05 17:18 - 28237766 _____ () C:\Program Files\wdnr-brrts-data.zip 2016-07-03 19:37 - 2016-07-03 19:37 - 2279912 _____ () C:\Program Files\_0MxA4K7QY_0MO4bL.dai 2017-02-13 00:11 - 2017-02-13 01:14 - 96588424 _____ () C:\Users\Administrator.jwilson-PC\AppData\Roaming\3091558760 2016-06-15 20:01 - 2017-01-18 00:09 - 0038407 _____ () C:\Users\Administrator.jwilson-PC\AppData\Roaming\Comma Separated Values.ADR 2017-02-18 12:37 - 2017-02-18 19:26 - 0000115 _____ () C:\Users\Administrator.jwilson-PC\AppData\Roaming\LogFile.txt 2017-02-13 09:53 - 2017-02-13 09:53 - 0000041 _____ () C:\Users\Administrator.jwilson-PC\AppData\Roaming\mbam.context.scan 2017-02-13 01:14 - 2017-02-13 01:14 - 0001088 _____ () C:\Users\Administrator.jwilson-PC\AppData\Roaming\US79B-8DKGO-ETAKH-FTXKA-TXRXK-GTHXK-GGOTX-ZKAOY 2017-02-13 01:14 - 2017-02-13 01:14 - 0016721 _____ () C:\Users\Administrator.jwilson-PC\AppData\Roaming\US79B-8DKGO-ETAKH-FTXKA-TXRXK-GTHXK-GGOTX-ZKAOY.html 2013-07-27 13:56 - 2017-02-13 01:46 - 0002024 _____ () C:\ProgramData\hpzinstall.log Files to move or delete: ==================== C:\Users\Administrator.jwilson-PC\AppData\Local\DIRECTV Player\PCShowServerPMWrapper.exe C:\Windows\Tasks\At1.job C:\Windows\Tasks\At2.job Some files in TEMP: ==================== 2017-02-14 23:25 - 2017-02-14 23:25 - 0007680 _____ () C:\Users\Administrator.jwilson-PC\AppData\Local\Temp\4lfasxkf.dll 2017-02-14 23:28 - 2017-02-14 23:29 - 0043520 _____ () C:\Users\Administrator.jwilson-PC\AppData\Local\Temp\zcyjwy2y.dll 2011-08-05 10:15 - 2011-08-05 10:15 - 0334848 _____ (Bunndle, Inc.) C:\Users\jlwilson2\AppData\Local\Temp\BunndleOfferManager.dll 2011-10-05 11:57 - 2011-12-16 10:21 - 0047280 _____ (Cisco Systems, Inc.) C:\Users\jlwilson2\AppData\Local\Temp\CSDWebLaunch.exe 2011-09-23 10:10 - 2011-09-23 10:10 - 1215728 _____ () C:\Users\jlwilson2\AppData\Local\Temp\dsHostCheckerSetup.exe 2012-02-28 06:53 - 2012-02-28 06:53 - 8045936 _____ () C:\Users\jlwilson2\AppData\Local\Temp\JingSetup.exe 2011-07-14 15:45 - 2011-07-14 15:45 - 0909088 _____ (Sun Microsystems, Inc.) C:\Users\jlwilson2\AppData\Local\Temp\jre-6u26-windows-i586-iftw-rv.exe 2011-10-18 22:21 - 2011-10-18 22:21 - 0909088 _____ (Sun Microsystems, Inc.) C:\Users\jlwilson2\AppData\Local\Temp\jre-6u29-windows-i586-iftw-rv.exe 2011-07-12 07:37 - 2011-11-23 10:20 - 0077824 _____ (Citrix Online) C:\Users\jlwilson2\AppData\Local\Temp\upgrader.exe 2011-08-05 10:18 - 2011-08-05 10:18 - 6525576 _____ (Xobni) C:\Users\jlwilson2\AppData\Local\Temp\xobni.exe 2011-08-05 10:18 - 2011-08-05 10:18 - 6525224 _____ (Xobni) C:\Users\jlwilson2\AppData\Local\Temp\XobniSetup.exe 2015-01-30 09:49 - 2015-01-30 09:49 - 0056672 _____ (SlimWare Utilities, Inc.) C:\Users\jlwilson2.US\AppData\Local\Temp\scp8807.tmp.exe ==================== Bamital & volsnap ====================== (There is no automatic fix for files that do not pass verification.) C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\dnsapi.dll => File is digitally signed C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2017-02-13 16:18 ==================== End of FRST.txt ============================