==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76 Tcpip\..\Interfaces\{37ef24cf-62bb-4f6b-b274-2e8996d27f33}: [NameServer] 8.26.56.26,156.154.70.22 Tcpip\..\Interfaces\{37ef24cf-62bb-4f6b-b274-2e8996d27f33}: [DhcpNameServer] 75.75.75.75 75.75.76.76 Tcpip\..\Interfaces\{b1347ba8-b255-43ca-9188-c5cfa2650ddc}: [NameServer] 8.26.56.26,156.154.70.22 Tcpip\..\Interfaces\{b1347ba8-b255-43ca-9188-c5cfa2650ddc}: [DhcpNameServer] 75.75.75.75 75.75.76.76 Internet Explorer: ================== HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <==== ATTENTION HKU\S-1-5-21-16598370-1499477397-4195015670-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://go.microsoft.com/fwlink/p/?LinkId=619797&pc=UE01&ocid=UE01DHP SearchScopes: HKLM -> DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE SearchScopes: HKLM -> {49606DC7-976D-4030-A74E-9FB5C842FA68} URL = hxxp://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox SearchScopes: HKLM -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE SearchScopes: HKLM -> {fcd9f10e-0daa-405f-bca0-0dd3f37c59d9} URL = SearchScopes: HKLM-x32 -> DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE SearchScopes: HKLM-x32 -> {49606DC7-976D-4030-A74E-9FB5C842FA68} URL = hxxp://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox SearchScopes: HKLM-x32 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE SearchScopes: HKU\S-1-5-21-16598370-1499477397-4195015670-1000 -> DefaultScope {740D10C0-1120-4DB2-8337-83413B8FBEB3} URL = hxxp://go.paradiskus.com/?B9371EE09A8FF0128D28715DBFE6196F=H1xAXFBDXlxZUVQNEQQwBw9cQ1hYQVxZWFdDVVVHX1ldU1QJDB0LUyknNy4nNikoW1FCXlFCLllaWTdfWEVfWF1VRV5WQCsrWSMxKFNCV1k&q={searchTerms} SearchScopes: HKU\S-1-5-21-16598370-1499477397-4195015670-1000 -> {49606DC7-976D-4030-A74E-9FB5C842FA68} URL = SearchScopes: HKU\S-1-5-21-16598370-1499477397-4195015670-1000 -> {740D10C0-1120-4DB2-8337-83413B8FBEB3} URL = hxxp://go.paradiskus.com/?B9371EE09A8FF0128D28715DBFE6196F=H1xAXFBDXlxZUVQNEQQwBw9cQ1hYQVxZWFdDVVVHX1ldU1QJDB0LUyknNy4nNikoW1FCXlFCLllaWTdfWEVfWF1VRV5WQCsrWSMxKFNCV1k&q={searchTerms} SearchScopes: HKU\S-1-5-21-16598370-1499477397-4195015670-1000 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = SearchScopes: HKU\S-1-5-21-16598370-1499477397-4195015670-1000 -> {fcd9f10e-0daa-405f-bca0-0dd3f37c59d9} URL = hxxps://mysearch.avg.com/search?cid={AE070354-6493-49D0-9256-55BBAFBD06BA}&mid=1e9e7d76c69b47d382f7c94a35379396-85116faf5f6267821ce8bd8b6ae342ca2bc2311a&lang=en&ds=AVG&coid=avgtbavg&cmpid=0615tb&pr=fr&d=2014-02-06 20:21:08&v=19.0.0.10&pid=safeguard&sg=0&sap=dsp&q={searchTerms} BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2015-02-23] (Canon Inc. -> CANON INC.) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_231\bin\ssv.dll [2020-01-09] (Oracle America, Inc. -> Oracle Corporation) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation -> Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_231\bin\jp2ssv.dll [2020-01-09] (Oracle America, Inc. -> Oracle Corporation) BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll [2013-08-14] (RealNetworks, Inc. -> RealDownloader) BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2015-02-23] (Canon Inc. -> CANON INC.) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_231\bin\ssv.dll [2020-01-09] (Oracle America, Inc. -> Oracle Corporation) BHO-x32: No Name -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> No File BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation -> Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_231\bin\jp2ssv.dll [2020-01-09] (Oracle America, Inc. -> Oracle Corporation) Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2015-02-23] (Canon Inc. -> CANON INC.) Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2015-02-23] (Canon Inc. -> CANON INC.) Edge: ====== DownloadDir: C:\Users\Tiffany\Downloads FireFox: ======== FF DefaultProfile: cm5j4z02.default FF ProfilePath: C:\Users\Tiffany\AppData\Roaming\Mozilla\Firefox\Profiles\cm5j4z02.default [2020-01-09] FF Homepage: Mozilla\Firefox\Profiles\cm5j4z02.default -> hxxp://www.bing.com/search?FORM=INCOH1&PC=IC04&PTAG=ICO-b8dee14f FF Notifications: Mozilla\Firefox\Profiles\cm5j4z02.default -> hxxps://www.facebook.com FF HomepageOverride: Mozilla\Firefox\Profiles\cm5j4z02.default -> Disabled: _65Members_@download.fromdoctopdf.com FF NewTabOverride: Mozilla\Firefox\Profiles\cm5j4z02.default -> Disabled: _65Members_@download.fromdoctopdf.com FF Extension: (Mozilla add-on that supports the roll-out of DoH) - C:\Users\Tiffany\AppData\Roaming\Mozilla\Firefox\Profiles\cm5j4z02.default\Extensions\doh-rollout@mozilla.org.xpi [2019-11-30] FF Extension: (Avast SafePrice | Comparison, deals, coupons) - C:\Users\Tiffany\AppData\Roaming\Mozilla\Firefox\Profiles\cm5j4z02.default\Extensions\sp@avast.com.xpi [2019-12-26] FF Extension: (Avast Online Security) - C:\Users\Tiffany\AppData\Roaming\Mozilla\Firefox\Profiles\cm5j4z02.default\Extensions\wrc@avast.com.xpi [2020-01-09] FF Extension: (FromDocToPDF) - C:\Users\Tiffany\AppData\Roaming\Mozilla\Firefox\Profiles\cm5j4z02.default\Extensions\_65Members_@download.fromdoctopdf.com.xpi [2019-11-19] [UpdateUrl:hxxps:\/\/updates.tb.ask.com\/updateXpi.json?id=207743773&version=8.924.16.54486&track=TTAB02&trackRevision=1&fromId=_65Members_%40download.fromdoctopdf.com&isBridgeExtension=false] FF HKLM-x32\...\Firefox\Extensions: [{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext FF Extension: (RealDownloader) - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-09-29] [Legacy] [not signed] FF HKLM-x32\...\Firefox\Extensions: [avg@toolbar] - C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\19.0.0.10 => not found FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_32_0_0_303.dll [2019-12-11] (Adobe Inc. -> ) FF Plugin: @java.com/DTPlugin,version=11.231.2 -> C:\Program Files\Java\jre1.8.0_231\bin\dtplugin\npDeployJava1.dll [2020-01-09] (Oracle America, Inc. -> Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.231.2 -> C:\Program Files\Java\jre1.8.0_231\bin\plugin2\npjp2.dll [2020-01-09] (Oracle America, Inc. -> Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation) FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2019-09-27] (Adobe Inc. -> Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_303.dll [2019-12-11] (Adobe Inc. -> ) FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2011-11-30] (CANON INC.) [File not signed] FF Plugin-x32: @java.com/DTPlugin,version=11.231.2 -> C:\Program Files (x86)\Java\jre1.8.0_231\bin\dtplugin\npDeployJava1.dll [2020-01-09] (Oracle America, Inc. -> Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.231.2 -> C:\Program Files (x86)\Java\jre1.8.0_231\bin\plugin2\npjp2.dll [2020-01-09] (Oracle America, Inc. -> Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @real.com/nppl3260;version=16.0.3.51 -> C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll [2013-09-29] (RealNetworks, Inc. -> RealNetworks, Inc.) FF Plugin-x32: @real.com/nprndlchromebrowserrecordext;version=1.3.3 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll [2013-08-14] (RealNetworks, Inc.) [File not signed] FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=1.3.3 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll [2013-08-14] (RealNetworks, Inc.) [File not signed] FF Plugin-x32: @real.com/nprndlpepperflashvideoshim;version=1.3.3 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll [2013-08-14] (RealNetworks, Inc.) [File not signed] FF Plugin-x32: @real.com/nprpplugin;version=16.0.3.51 -> C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpplugin.dll [2013-09-29] (RealNetworks, Inc. -> RealPlayer) FF Plugin-x32: @realnetworks.com/npdlplugin;version=1 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll [2013-08-14] (RealNetworks, Inc. -> RealDownloader) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2015-09-24] (Adobe Systems, Incorporated -> Adobe Systems Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2019-09-27] (Adobe Inc. -> Adobe Systems) Chrome: ======= CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx CHR HKLM-x32\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2013-08-14] ==================== Services (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [823352 2019-09-27] (Adobe Inc. -> Adobe Inc.) R2 AGMService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [3147344 2019-10-08] (Adobe Inc. -> Adobe Systems, Incorporated) R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2914896 2019-10-08] (Adobe Inc. -> Adobe Systems, Incorporated) R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2017-11-27] (Apple Inc. -> Apple Inc.) R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\aswidsagent.exe [6259592 2019-12-19] (AVAST Software s.r.o. -> AVAST Software) S2 avast; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2018-08-23] (AVAST Software s.r.o. -> AVAST Software) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [996880 2019-10-06] (AVAST Software s.r.o. -> AVAST Software) S3 avastm; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2018-08-23] (AVAST Software s.r.o. -> AVAST Software) S3 AvastSecureBrowserElevationService; C:\Program Files (x86)\AVAST Software\Browser\Application\77.2.2153.120\elevation_service.exe [970088 2019-11-04] (AVAST Software s.r.o. -> AVAST Software) R2 AvastWscReporter; C:\Program Files\AVAST Software\Avast\wsc_proxy.exe [57504 2019-10-06] (AVAST Software s.r.o. -> AVAST Software) S2 CLKMSVC10_9EC60124; C:\Program Files (x86)\Cyberlink\PowerDVD9\NavFilter\kmsvc.exe [248304 2011-08-11] (CyberLink -> CyberLink) S2 DellDigitalDelivery; C:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe [173056 2012-08-02] (Dell Products, LP.) [File not signed] R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [253528 2015-07-09] (Canon Inc. -> ) R2 NOBU; C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe [4375880 2014-11-18] (Symantec Corporation -> Dell, Inc.) R2 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-08-14] (RealNetworks, Inc. -> ) R2 SftService; C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE [1692480 2011-09-22] (Dell Inc -> SoftThinks SAS) R2 WDDMService; C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [129536 2009-11-13] (WDC) [File not signed] S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1907.4-0\NisSrv.exe [2552416 2019-08-22] (Microsoft Windows Publisher -> Microsoft Corporation) S2 WDSmartWareBackgroundService; C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe [20480 2009-06-16] (Memeo) [File not signed] S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1907.4-0\MsMpEng.exe [108832 2019-08-22] (Microsoft Windows Publisher -> Microsoft Corporation) ===================== Drivers (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R0 aswArDisk; C:\WINDOWS\System32\drivers\aswArDisk.sys [37616 2019-10-06] (AVAST Software s.r.o. -> AVAST Software) R1 aswArPot; C:\WINDOWS\System32\drivers\aswArPot.sys [204824 2019-10-06] (AVAST Software s.r.o. -> AVAST Software) R1 aswbidsdriver; C:\WINDOWS\System32\drivers\aswbidsdriver.sys [274456 2019-10-06] (AVAST Software s.r.o. -> AVAST Software) R0 aswbidsh; C:\WINDOWS\System32\drivers\aswbidsh.sys [209552 2019-10-06] (AVAST Software s.r.o. -> AVAST Software) R0 aswbuniv; C:\WINDOWS\System32\drivers\aswbuniv.sys [65120 2019-10-06] (AVAST Software s.r.o. -> AVAST Software) R0 aswElam; C:\WINDOWS\System32\drivers\aswElam.sys [16304 2019-10-06] (Microsoft Windows Early Launch Anti-malware Publisher -> AVAST Software) R1 aswKbd; C:\WINDOWS\System32\drivers\aswKbd.sys [42736 2019-10-06] (AVAST Software s.r.o. -> AVAST Software) R2 aswMonFlt; C:\WINDOWS\System32\drivers\aswMonFlt.sys [161544 2019-11-17] (AVAST Software s.r.o. -> AVAST Software) R1 aswRdr; C:\WINDOWS\System32\drivers\aswRdr2.sys [110320 2019-10-06] (AVAST Software s.r.o. -> AVAST Software) R0 aswRvrt; C:\WINDOWS\System32\drivers\aswRvrt.sys [83792 2019-10-06] (AVAST Software s.r.o. -> AVAST Software) R1 aswSnx; C:\WINDOWS\System32\drivers\aswSnx.sys [848432 2019-10-06] (AVAST Software s.r.o. -> AVAST Software) R1 aswSP; C:\WINDOWS\System32\drivers\aswSP.sys [460448 2019-10-06] (AVAST Software s.r.o. -> AVAST Software) R2 aswStm; C:\WINDOWS\System32\drivers\aswStm.sys [236024 2019-10-06] (AVAST Software s.r.o. -> AVAST Software) R0 aswVmm; C:\WINDOWS\System32\drivers\aswVmm.sys [316528 2019-10-06] (AVAST Software s.r.o. -> AVAST Software) R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nvddwu.inf_amd64_22a22f778ced373c\nvlddmkm.sys [13754928 2016-08-26] (NVIDIA Corporation -> NVIDIA Corporation) S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [47496 2019-08-22] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [344288 2019-08-22] (Microsoft Windows -> Microsoft Corporation) S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [54496 2019-08-22] (Microsoft Windows -> Microsoft Corporation) U3 idsvc; no ImagePath U5 REALPLAYERUPDATESVC; no ImagePath ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One month (created) =================== (If an entry is included in the fixlist, the file/folder will be moved.) 2020-01-09 23:21 - 2020-01-09 23:21 - 000000000 ____D C:\Users\Tiffany\Desktop\FRST-OlderVersion 2020-01-09 23:19 - 2020-01-09 23:19 - 000025503 _____ C:\Users\Tiffany\Desktop\ckfiles.txt 2020-01-09 21:53 - 2020-01-09 21:52 - 000129080 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-64.dll 2020-01-09 21:49 - 2020-01-09 21:49 - 000468480 _____ () C:\Users\Tiffany\Desktop\CKScanner.exe 2020-01-09 21:47 - 2020-01-09 21:47 - 000003582 _____ C:\WINDOWS\system32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-16598370-1499477397-4195015670-1000 2020-01-09 21:47 - 2020-01-09 21:47 - 000003518 _____ C:\WINDOWS\system32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-16598370-1499477397-4195015670-1000 2020-01-09 13:15 - 2020-01-09 13:15 - 000000000 ____D C:\Users\Tiffany\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2020-01-05 23:18 - 2020-01-05 23:18 - 000001066 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop 2020.lnk 2020-01-05 23:18 - 2020-01-05 23:18 - 000000000 ____D C:\Users\Tiffany\Documents\Adobe 2020-01-05 23:18 - 2020-01-05 23:18 - 000000000 ____D C:\Users\Tiffany\AppData\Local\UXP 2020-01-05 23:06 - 2020-01-05 23:06 - 000001052 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Lightroom.lnk 2020-01-05 23:06 - 2020-01-05 23:06 - 000001040 _____ C:\Users\Tiffany\Desktop\Lightroom.lnk 2020-01-05 23:04 - 2020-01-09 21:50 - 000000000 ___RD C:\Users\Tiffany\Creative Cloud Files 2020-01-05 23:00 - 2020-01-09 21:23 - 000000000 ___HD C:\Users\Public\Documents\AdobeGCData 2020-01-05 23:00 - 2020-01-09 21:23 - 000000000 ___HD C:\ProgramData\Documents\AdobeGCData 2020-01-05 23:00 - 2020-01-05 23:00 - 000003518 _____ C:\WINDOWS\system32\Tasks\AdobeGCInvoker-1.0 2020-01-05 22:59 - 2020-01-05 22:59 - 000001366 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Creative Cloud.lnk 2020-01-05 22:59 - 2020-01-05 22:59 - 000001354 _____ C:\Users\Public\Desktop\Adobe Creative Cloud.lnk 2020-01-05 22:59 - 2020-01-05 22:59 - 000001354 _____ C:\ProgramData\Desktop\Adobe Creative Cloud.lnk 2019-12-30 22:26 - 2020-01-09 23:23 - 000017788 _____ C:\Users\Tiffany\Desktop\FRST.txt 2019-12-30 22:25 - 2020-01-09 23:22 - 000000000 ____D C:\FRST 2019-12-30 22:23 - 2020-01-09 23:21 - 002573312 _____ (Farbar) C:\Users\Tiffany\Desktop\FRST64.exe 2019-12-30 22:18 - 2019-12-30 22:18 - 002272256 _____ (Farbar) C:\Users\Tiffany\Downloads\FRST64.exe 2019-12-19 15:25 - 2019-12-19 15:26 - 000000000 ____D C:\ProgramData\SWRoes 2019-12-19 15:25 - 2019-12-19 15:25 - 000002455 _____ C:\Users\Public\Desktop\WHCC ROES.lnk 2019-12-19 15:25 - 2019-12-19 15:25 - 000002455 _____ C:\ProgramData\Desktop\WHCC ROES.lnk 2019-12-19 15:25 - 2019-12-19 15:25 - 000000000 ____D C:\Users\Tiffany\AppData\Roaming\ROES 2019-12-19 15:25 - 2019-12-19 15:25 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WHCC ROES 2019-12-19 15:25 - 2019-12-19 15:25 - 000000000 ____D C:\Program Files (x86)\ROES 2019-12-19 15:15 - 2019-12-19 15:15 - 000000000 ____D C:\Users\Tiffany\AppData\Roaming\java 2019-12-19 15:14 - 2020-01-09 21:53 - 000002557 _____ C:\Users\Tiffany\Desktop\WHCC ROES.lnk 2019-12-19 15:14 - 2019-12-19 22:39 - 000000000 ____D C:\Users\Tiffany\.WHCCROES 2019-12-19 15:14 - 2019-12-19 15:14 - 000000000 ____D C:\Users\Tiffany\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WHCC ROES 2019-12-19 15:14 - 2019-12-19 15:14 - 000000000 ____D C:\Users\Tiffany\AppData\Local\Sun 2019-12-12 22:38 - 2019-12-12 22:38 - 003580468 _____ C:\Users\Tiffany\Downloads\132444881.jpeg 2019-12-12 22:38 - 2019-12-12 22:38 - 003578842 _____ C:\Users\Tiffany\Downloads\132444864.jpeg 2019-12-12 22:38 - 2019-12-12 22:38 - 003576603 _____ C:\Users\Tiffany\Downloads\132444874.jpeg 2019-12-12 22:38 - 2019-12-12 22:38 - 003510904 _____ C:\Users\Tiffany\Downloads\132444862.jpeg 2019-12-12 22:37 - 2019-12-12 22:37 - 003548364 _____ C:\Users\Tiffany\Downloads\132444878.jpeg 2019-12-11 17:24 - 2019-12-11 17:24 - 025443840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 018020352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 009927992 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2019-12-11 17:24 - 2019-12-11 17:24 - 007905000 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 007754240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 007600448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 007278592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 007263992 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 006516648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 006083832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 005943296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 005914112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 005764664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 004129416 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 003729408 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys 2019-12-11 17:24 - 2019-12-11 17:24 - 003703296 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 002800640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys 2019-12-11 17:24 - 2019-12-11 17:24 - 002762296 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 002716672 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys 2019-12-11 17:24 - 2019-12-11 17:24 - 002698768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys 2019-12-11 17:24 - 2019-12-11 17:24 - 002494432 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 002284544 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 002147328 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnidui.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 002082208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 001757304 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi 2019-12-11 17:24 - 2019-12-11 17:24 - 001748480 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 001743888 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 001697280 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 001664904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 001656600 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 001647072 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 001610752 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramCompositor.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 001539584 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 001512528 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe 2019-12-11 17:24 - 2019-12-11 17:24 - 001458688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 001451520 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocoreworker.exe 2019-12-11 17:24 - 2019-12-11 17:24 - 001413840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 001399312 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe 2019-12-11 17:24 - 2019-12-11 17:24 - 001366128 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi 2019-12-11 17:24 - 2019-12-11 17:24 - 001261464 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 001182448 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe 2019-12-11 17:24 - 2019-12-11 17:24 - 001149712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe 2019-12-11 17:24 - 2019-12-11 17:24 - 001098928 _____ (Microsoft Corporation) C:\WINDOWS\system32\DolbyDecMFT.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 001072952 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe 2019-12-11 17:24 - 2019-12-11 17:24 - 001066496 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 001054864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 001006904 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostCommon.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 000986936 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\refsv1.sys 2019-12-11 17:24 - 2019-12-11 17:24 - 000921600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 000878080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Service.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 000842552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudExperienceHostCommon.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 000826368 _____ (Microsoft Corporation) C:\WINDOWS\system32\printfilterpipelinesvc.exe 2019-12-11 17:24 - 2019-12-11 17:24 - 000822416 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe 2019-12-11 17:24 - 2019-12-11 17:24 - 000797112 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 000774456 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe 2019-12-11 17:24 - 2019-12-11 17:24 - 000701440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.Internal.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 000674280 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe 2019-12-11 17:24 - 2019-12-11 17:24 - 000673456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe 2019-12-11 17:24 - 2019-12-11 17:24 - 000646144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 000598016 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe 2019-12-11 17:24 - 2019-12-11 17:24 - 000595968 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 000593128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 000578560 _____ (Microsoft Corporation) C:\WINDOWS\system32\SppExtComObj.Exe 2019-12-11 17:24 - 2019-12-11 17:24 - 000550400 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys 2019-12-11 17:24 - 2019-12-11 17:24 - 000532480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 000530944 _____ (Microsoft Corporation) C:\WINDOWS\system32\usosvc.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 000524264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Enumeration.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 000513536 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe 2019-12-11 17:24 - 2019-12-11 17:24 - 000511000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64win.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 000457216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cldflt.sys 2019-12-11 17:24 - 2019-12-11 17:24 - 000430080 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhcfg.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 000422712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fastfat.sys 2019-12-11 17:24 - 2019-12-11 17:24 - 000406480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Enumeration.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 000404480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\exfat.sys 2019-12-11 17:24 - 2019-12-11 17:24 - 000342528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\udfs.sys 2019-12-11 17:24 - 2019-12-11 17:24 - 000324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys 2019-12-11 17:24 - 2019-12-11 17:24 - 000210744 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcbloader.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 000201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 000179712 _____ (Microsoft Corporation) C:\WINDOWS\system32\t2embed.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 000155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 000139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakrathunk.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 000138752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\t2embed.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 000127272 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32u.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 000125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 000117248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 000105472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakrathunk.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 000100352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cdfs.sys 2019-12-11 17:24 - 2019-12-11 17:24 - 000099328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 000097080 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 000089536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32u.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 000077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\CustomInstallExec.exe 2019-12-11 17:24 - 2019-12-11 17:24 - 000076288 _____ (Microsoft Corporation) C:\WINDOWS\system32\autopilot.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 000070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.EnrollmentStatusTracking.ConfigProvider.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 000068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdProxy.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 000067112 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsManagementServiceWinRt.ProxyStub.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 000046592 _____ (Microsoft Corporation) C:\WINDOWS\system32\printfilterpipelineprxy.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 000034816 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevQueryBroker.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 000032056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdpvideominiport.sys 2019-12-11 17:24 - 2019-12-11 17:24 - 000025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\autopilotdiag.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 000014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\dciman32.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 000011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dciman32.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 000010752 _____ (Microsoft Corporation) C:\WINDOWS\system32\DMAlertListener.ProxyStub.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 000007680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DMAlertListener.ProxyStub.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 000003072 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpk.dll 2019-12-11 17:24 - 2019-12-11 17:24 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\lpk.dll 2019-12-11 16:33 - 2019-12-11 16:33 - 002579467 _____ C:\Users\Tiffany\Desktop\AdultSizeEarTemplate.pdf 2019-12-11 16:32 - 2019-12-11 16:32 - 001094469 _____ C:\Users\Tiffany\Desktop\SpacingTemplate.pdf ==================== One month (modified) ================== (If an entry is included in the fixlist, the file/folder will be moved.) 2020-01-09 23:16 - 2012-01-28 10:38 - 000000000 ____D C:\Users\Tiffany\AppData\Local\ElevatedDiagnostics 2020-01-09 23:08 - 2019-03-18 23:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2020-01-09 22:57 - 2012-01-15 21:37 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auto FX Software 2020-01-09 22:03 - 2012-01-22 11:37 - 000000000 ____D C:\Users\Tiffany\AppData\Local\Nero 2020-01-09 21:53 - 2013-09-29 15:43 - 000000000 ____D C:\Program Files\Java 2020-01-09 21:53 - 2013-09-29 15:42 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2020-01-09 21:53 - 2013-09-29 15:42 - 000000000 ____D C:\Program Files (x86)\Java 2020-01-09 21:52 - 2013-09-29 15:43 - 000129080 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge-64.dll 2020-01-09 21:51 - 2013-11-06 19:42 - 000000000 ____D C:\ProgramData\boost_interprocess 2020-01-09 21:51 - 2013-09-29 15:42 - 000114232 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll 2020-01-09 21:49 - 2018-08-23 17:19 - 000000000 ____D C:\Users\Tiffany\AppData\Local\AVAST Software 2020-01-09 21:44 - 2016-09-30 03:05 - 000000000 ____D C:\Users\Default\AppData\Local\SoftThinks 2020-01-09 21:44 - 2016-09-30 03:05 - 000000000 ____D C:\Users\Default User\AppData\Local\SoftThinks 2020-01-09 21:43 - 2011-12-01 22:14 - 000000000 ____D C:\Program Files (x86)\Dell DataSafe Local Backup 2020-01-09 21:42 - 2016-05-05 00:08 - 000153072 ____N (CyberLink Corp.) C:\WINDOWS\system32\Drivers\rikvm_9EC60124.sys 2020-01-09 21:41 - 2019-08-21 01:09 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2020-01-09 21:40 - 2019-08-21 00:45 - 000000000 ____D C:\Users\Tiffany 2020-01-09 21:40 - 2019-03-18 23:37 - 000786432 _____ C:\WINDOWS\system32\config\BBI 2020-01-09 21:33 - 2011-12-01 22:26 - 000000000 ____D C:\ProgramData\Adobe 2020-01-09 21:33 - 2011-12-01 22:25 - 000000000 ____D C:\Program Files (x86)\Adobe 2020-01-09 21:32 - 2016-02-20 13:27 - 000000000 ____D C:\Program Files\Common Files\Adobe 2020-01-09 21:21 - 2014-08-01 17:54 - 000000000 ____D C:\Users\Tiffany\Desktop\PhotoshopPrograms 2020-01-09 21:18 - 2019-08-21 01:09 - 000004158 _____ C:\WINDOWS\system32\Tasks\User_Feed_Synchronization-{326376A5-4C85-4AC2-A8E5-C1782EE661E3} 2020-01-09 21:17 - 2019-03-18 23:52 - 000000000 ____D C:\WINDOWS\system32\NDF 2020-01-09 21:12 - 2012-01-15 22:29 - 000000000 ____D C:\Program Files (x86)\Jasc Software Inc 2020-01-09 21:09 - 2012-01-15 16:55 - 000000000 ____D C:\Program Files\Adobe 2020-01-09 21:00 - 2019-08-21 01:09 - 000004264 _____ C:\WINDOWS\system32\Tasks\Avast Emergency Update 2020-01-09 20:59 - 2019-08-21 00:35 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2020-01-09 17:13 - 2019-03-18 23:52 - 000000000 ___HD C:\Program Files\WindowsApps 2020-01-09 17:13 - 2019-03-18 23:52 - 000000000 ____D C:\WINDOWS\AppReadiness 2020-01-09 16:20 - 2016-02-20 16:08 - 000000000 ____D C:\ProgramData\AVAST Software 2020-01-09 13:16 - 2014-01-08 16:47 - 000000000 ____D C:\Users\Tiffany\AppData\Roaming\Dropbox 2020-01-09 12:48 - 2016-11-23 11:48 - 000000000 ____D C:\Users\Tiffany\AppData\LocalLow\Mozilla 2020-01-09 12:45 - 2019-05-06 11:22 - 000000000 ____D C:\Users\Tiffany\AppData\Local\CrashDumps 2020-01-07 23:10 - 2018-07-27 16:29 - 000000000 ____D C:\Users\Tiffany\AppData\Local\D3DSCache 2020-01-05 23:18 - 2012-01-09 21:11 - 000000000 ____D C:\Users\Tiffany\AppData\Roaming\Adobe 2020-01-05 23:07 - 2012-01-15 17:00 - 000000000 ____D C:\Users\Tiffany\AppData\Local\Adobe 2020-01-05 23:02 - 2018-06-25 15:42 - 000000000 ____D C:\ProgramData\Packages 2020-01-05 23:02 - 2017-12-29 02:17 - 000000000 ____D C:\Users\Tiffany\AppData\Local\Packages 2020-01-05 22:58 - 2017-07-14 22:24 - 000000000 ____D C:\ProgramData\Package Cache 2019-12-30 22:32 - 2019-03-18 23:50 - 000000000 ____D C:\WINDOWS\INF 2019-12-30 22:15 - 2016-01-10 21:24 - 000000000 ____D C:\ProgramData\CanonIJPLM 2019-12-22 23:30 - 2012-01-15 22:29 - 000000000 ____D C:\Users\Tiffany\Documents\My PSP8 Files 2019-12-19 15:14 - 2012-01-29 02:04 - 000000000 ____D C:\Users\Tiffany\.roescache 2019-12-19 09:34 - 2016-08-07 08:12 - 000000000 ____D C:\Users\Tiffany\Documents\Outlook Files 2019-12-11 19:17 - 2019-08-21 00:57 - 000972220 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2019-12-11 19:13 - 2018-01-03 14:56 - 000000000 ___RD C:\Users\Tiffany\3D Objects 2019-12-11 19:13 - 2016-05-05 21:14 - 000000000 __RHD C:\Users\Public\AccountPictures 2019-12-11 19:12 - 2019-08-21 00:34 - 005712024 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2019-12-11 19:07 - 2019-03-18 23:52 - 000000000 ____D C:\WINDOWS\SystemResources 2019-12-11 19:07 - 2019-03-18 23:52 - 000000000 ____D C:\WINDOWS\ShellExperiences 2019-12-11 19:07 - 2019-03-18 23:52 - 000000000 ____D C:\WINDOWS\bcastdvr 2019-12-11 17:52 - 2013-07-29 02:00 - 000000000 ____D C:\WINDOWS\system32\MRT 2019-12-11 17:31 - 2019-03-18 23:37 - 000000000 ____D C:\WINDOWS\CbsTemp 2019-12-11 17:31 - 2012-01-09 22:27 - 129221664 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2019-12-11 16:26 - 2019-08-21 00:45 - 000000000 ____D C:\Users\DefaultAppPool 2019-12-11 16:26 - 2019-08-21 00:44 - 000000000 ____D C:\Users\TiffanyK 2019-12-11 16:12 - 2019-12-06 01:13 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox 2019-12-11 16:12 - 2013-06-08 17:21 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2019-12-11 01:13 - 2019-08-21 01:09 - 000004582 _____ C:\WINDOWS\system32\Tasks\Adobe Flash Player NPAPI Notifier 2019-12-11 01:13 - 2019-03-18 23:52 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed 2019-12-11 01:13 - 2019-03-18 23:52 - 000000000 ____D C:\WINDOWS\system32\Macromed ==================== Files in the root of some directories ======== 2009-07-19 20:42 - 2009-07-19 20:42 - 000000000 _____ () C:\Users\Tiffany\settings.dat 2013-08-26 11:40 - 2014-06-02 15:32 - 000003745 _____ () C:\Program Files (x86)\Mozilla Firefoxsafeguard-secure-search.xml 2006-12-14 21:40 - 2008-01-08 19:21 - 000000426 _____ () C:\Users\Tiffany\AppData\Roaming\wklnhst.dat 2018-05-24 20:15 - 2006-08-19 17:00 - 000000136 _____ () C:\Users\Tiffany\AppData\Local\fusioncache.dat 2020-01-05 23:07 - 2020-01-05 23:07 - 000000000 _____ () C:\Users\Tiffany\AppData\Local\oobelibMkey.log 2012-04-25 09:37 - 2012-04-25 09:37 - 000000017 _____ () C:\Users\Tiffany\AppData\Local\resmon.resmoncfg ==================== SigCheck ============================ (There is no automatic fix for files that do not pass verification.) ==================== End of FRST.txt ========================