Hi, Wolfie.
Please uninstall the following:
Norton Anti-Theft
Norton Online Backup
Norton PC Checkup
Norton Security Dashboard
Restart the computer and give me fresh FRST logs to check.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 27-02-2022
Ran by Michelle (administrator) on MINE (TOSHIBA Satellite C855D) (05-03-2022 16:34:04)
Running from C:\Users\Michelle\Documents
Loaded Profiles: Michelle
Platform: Microsoft Windows 8 (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
(atiesrxx.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atieclxx.exe
(C:\Program Files\Synaptics\SynTP\SynTPEnh.exe ->) (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.122\GoogleCrashHandler.exe
(C:\Program Files\Synaptics\SynTP\SynTPEnh.exe ->) (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.122\GoogleCrashHandler64.exe
(explorer.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\msra.exe
(explorer.exe ->) (Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(explorer.exe ->) (TOSHIBA CORPORATION -> TOSHIBA Corporation) C:\Program Files\Toshiba\Hotkey\TCrdMain_Win8.exe
(explorer.exe ->) (TOSHIBA CORPORATION -> TOSHIBA Corporation) C:\Program Files\Toshiba\Teco\TecoResident.exe
(Microsoft Windows -> Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(SearchFilterHost.exe ->) (TOSHIBA CORPORATION -> TOSHIBA Corporation) C:\Program Files\Toshiba\TPHM\TPCHWMsg.exe
(services.exe ->) (Adobe Systems, Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(services.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\msiexec.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atiesrxx.exe
(services.exe ->) (Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(services.exe ->) (TOSHIBA CORPORATION -> TOSHIBA Corporation) C:\Program Files\Toshiba\Teco\TecoService.exe
(services.exe ->) (TOSHIBA CORPORATION -> TOSHIBA Corporation) C:\Program Files\Toshiba\TPHM\TPCHSrv.exe
(services.exe ->) (TOSHIBA CORPORATION -> TOSHIBA Corporation) C:\Windows\System32\TODDSrv.exe
(svchost.exe ->) (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe\LiveComm.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.2.9200.17516_none_6276a5b950d43361\TiWorker.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Toshiba) [File not signed] C:\Program Files (x86)\Toshiba\Toshiba App Place\ToshibaAppPlace.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [] => [X]
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12936848 2012-07-13] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\...\Run: [TCrdMain] => C:\Program Files\TOSHIBA\Hotkey\TCrdMain_Win8.exe [2608040 2012-08-13] (TOSHIBA CORPORATION -> TOSHIBA Corporation)
HKLM\...\Run: [TecoResident] => C:\Program Files\TOSHIBA\Teco\TecoResident.exe [169896 2012-08-13] (TOSHIBA CORPORATION -> TOSHIBA Corporation)
HKLM\...\Run: [TosWaitSrv] => C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe [356776 2012-07-11] (TOSHIBA CORPORATION -> TOSHIBA Corporation)
HKLM\...\Run: [TODDMain] => C:\Program Files (x86)\TOSHIBA\System Setting\TODDMain.exe [213136 2012-08-04] (TOSHIBA CORPORATION -> )
HKLM-x32\...\Run: [ToshibaAppPlace] => C:\Program Files (x86)\Toshiba\Toshiba App Place\ToshibaAppPlace.exe [552960 2010-09-23] (Toshiba) [File not signed]
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642216 2012-08-08] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{89820200-ECBD-11cf-8B85-00AA005B4340}] -> regsvr32.exe /s /n /i:U %SystemRoot%\System32\shell32.dll
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\98.0.4758.102\Installer\chrmstp.exe [2022-02-18] (Google LLC -> Google LLC)
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {09BB031A-97CB-42D4-A1AD-C8C6DF9392C5} - System32\Tasks\TOSHIBA\Service Station => C:\Program Files\TOSHIBA\Toshiba Service Station\ToshibaServiceStation.exe [1295496 2012-07-27] (TOSHIBA CORPORATION -> TOSHIBA Corporation)
Task: {3DA41B1B-B561-4E0B-91D3-996406C487FA} - System32\Tasks\Norton Anti-Theft\Norton Error Analyzer => C:\Program Files (x86)\Norton Anti-Theft\Engine\1.6.0.17\SymErr.exe /analyze (No File)
Task: {4116063D-89A2-4BC7-9E8A-518ED6379533} - System32\Tasks\Synaptics TouchPad Enhancements => \Program Files\Synaptics\SynTP\SynTPEnh.exe [2916152 2012-08-16] (Synaptics Incorporated -> Synaptics Incorporated)
Task: {44B3F1B8-5943-4072-8D8C-A9484676AC44} - System32\Tasks\Microsoft\Windows\Live\Roaming\SynchronizeWithStorage => {5F074BDF-4BA3-4E68-AE86-2A6B0B5963B0} C:\WINDOWS\system32\wlroamextension.dll [543232 2012-07-25] (Microsoft Windows -> Microsoft Corporation)
Task: {692A017E-FFCB-4B50-8C35-612C0B3068F9} - System32\Tasks\GoogleUpdateTaskMachineUA{2110CD26-E00F-4E8A-B759-D7DAC3E8E389} => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156232 2022-02-18] (Google LLC -> Google LLC)
Task: {938E1B73-6C12-4B71-B308-201220D512C8} - System32\Tasks\Norton Anti-Theft\Norton Error Processor => C:\Program Files (x86)\Norton Anti-Theft\Engine\1.6.0.17\SymErr.exe /submit (No File)
Task: {97013C2E-DD2C-4A33-BDD6-8394F3425D4C} - System32\Tasks\GoogleUpdateTaskMachineCore{AB007181-87B4-4265-A36C-C2F24D4432C1} => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156232 2022-02-18] (Google LLC -> Google LLC)
Task: {A800277E-E202-4492-AD38-3312641CBC04} - System32\Tasks\Microsoft\Windows\Live\Roaming\MaintenanceTask => {0AC1DBCA-7F9F-47FC-A090-34E5FEB291E8} C:\WINDOWS\system32\wlroamextension.dll [543232 2012-07-25] (Microsoft Windows -> Microsoft Corporation)
Task: {AA9BC3E2-3924-4D30-A0D7-C4274AB654F4} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task => {3519154C-227E-47F3-9CC9-12C3F05817F1}
Task: {AEB0B5BD-B9E5-458A-898A-E559BD9EB51B} - System32\Tasks\Microsoft\Windows\SettingSync\BackgroundUploadTask => {59B9640B-3F70-4D1C-B159-F26EEB8A4C87} C:\WINDOWS\system32\SettingSyncInfo.dll [128512 2012-07-25] (Microsoft Windows -> Microsoft Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\..\Interfaces\{065C6981-2C5E-4AD4-AA72-907768FCFCF3}: [NameServer] 192.168.0.1
HKLM\System\...\Parameters\PersistentRoutes: [0.0.0.0,0.0.0.0,192.168.0.1,-1]
FireFox:
========
FF HKLM-x32\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\IPSFFPlgn => not found
FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\coFFPlgn => not found
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3503.0728 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-07-28] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2012-05-11] (WildTangent Inc -> )
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2012-04-04] (Adobe Systems, Incorporated -> Adobe Systems Inc.)
Chrome:
=======
CHR Profile: C:\Users\Michelle\AppData\Local\Google\Chrome\User Data\Default [2022-03-05]
CHR Extension: (Slides) - C:\Users\Michelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2022-02-18]
CHR Extension: (Docs) - C:\Users\Michelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2022-02-18]
CHR Extension: (Google Drive) - C:\Users\Michelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2022-02-18]
CHR Extension: (YouTube) - C:\Users\Michelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2022-02-18]
CHR Extension: (Sheets) - C:\Users\Michelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2022-02-18]
CHR Extension: (Google Docs Offline) - C:\Users\Michelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2022-02-18]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Michelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2022-02-18]
CHR Extension: (Gmail) - C:\Users\Michelle\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2022-02-18]
CHR HKLM-x32\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton Internet Security\Engine\20.0.0.136\Exts\Chrome.crx <not found>
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [63928 2012-04-04] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [15440 2012-07-25] (Microsoft Windows -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [509904 2022-02-18] (Microsoft Windows Hardware Compatibility Publisher -> Broadcom)
S3 EraserUtilDrv11913; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilDrv11913.sys [145376 2022-03-02] (Microsoft Windows Hardware Compatibility Publisher -> Broadcom)
S3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [145376 2022-03-02] (Microsoft Windows Hardware Compatibility Publisher -> Broadcom)
R3 FwLnk; C:\WINDOWS\System32\drivers\FwLnk.sys [9216 2012-07-10] (Microsoft Windows Hardware Compatibility Publisher -> TOSHIBA Corporation)
R3 Thotkey; C:\WINDOWS\System32\drivers\Thotkey.sys [28632 2012-07-31] (TOSHIBA CORPORATION -> Windows ® Win 7 DDK provider)
S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [34216 2012-07-25] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [258288 2012-07-25] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2022-03-05 16:33 - 2022-03-05 16:33 - 000001139 _____ C:\Users\Michelle\Documents\Invitation.c282.rbcw.vbgy.msrcIncident
2022-03-05 16:25 - 2022-03-05 16:25 - 000000117 _____ C:\WINDOWS\system32\netcfg-38735.txt
2022-03-05 16:24 - 2022-03-05 16:24 - 000000117 _____ C:\WINDOWS\system32\netcfg-4506447.txt
2022-03-05 15:10 - 2022-03-05 15:10 - 000000117 _____ C:\WINDOWS\system32\netcfg-28485.txt
2022-03-05 15:09 - 2022-03-05 15:09 - 000000117 _____ C:\WINDOWS\system32\netcfg-13342500.txt
2022-03-05 13:40 - 2022-03-05 13:47 - 000039828 _____ C:\Users\Michelle\Documents\Addition.txt
2022-03-05 13:10 - 2022-03-05 16:35 - 000012360 _____ C:\Users\Michelle\Documents\FRST.txt
2022-03-05 13:07 - 2022-03-05 13:07 - 000001235 _____ C:\Users\Michelle\Desktop\msra - Shortcut.lnk
2022-03-05 11:27 - 2022-03-05 11:27 - 000000117 _____ C:\WINDOWS\system32\netcfg-34242.txt
2022-03-05 11:26 - 2022-03-05 11:26 - 000000117 _____ C:\WINDOWS\system32\netcfg-2171830.txt
2022-03-05 11:16 - 2022-03-02 18:30 - 002312192 _____ (Farbar) C:\Users\Michelle\Documents\FRST64.exe
2022-03-05 11:15 - 2022-03-05 11:20 - 000000000 ____D C:\WINDOWS\system32\Tasks\Remediation
2022-03-05 10:51 - 2022-03-05 10:51 - 000000117 _____ C:\WINDOWS\system32\netcfg-40622.txt
2022-03-05 10:50 - 2022-03-05 10:50 - 000000117 _____ C:\WINDOWS\system32\netcfg-202910.txt
2022-03-05 10:47 - 2022-03-05 10:47 - 000000117 _____ C:\WINDOWS\system32\netcfg-45661.txt
2022-03-05 10:39 - 2022-03-05 10:39 - 000000117 _____ C:\WINDOWS\system32\netcfg-1056563.txt
2022-03-02 17:00 - 2022-03-02 17:00 - 000000117 _____ C:\WINDOWS\system32\netcfg-7552710.txt
2022-03-02 17:00 - 2022-03-02 17:00 - 000000117 _____ C:\WINDOWS\system32\netcfg-7549574.txt
2022-03-02 16:59 - 2022-03-02 17:00 - 000001095 _____ C:\WINDOWS\system32\netcfg-7466301.txt
2022-03-02 16:59 - 2022-03-02 16:59 - 000000156 _____ C:\WINDOWS\system32\netcfg-7444024.txt
2022-03-02 16:58 - 2022-03-02 16:58 - 000000156 _____ C:\WINDOWS\system32\netcfg-7391124.txt
2022-03-02 16:51 - 2022-03-02 16:51 - 000000117 _____ C:\WINDOWS\system32\netcfg-7017502.txt
2022-03-02 16:51 - 2022-03-02 16:51 - 000000117 _____ C:\WINDOWS\system32\netcfg-7015271.txt
2022-03-02 16:23 - 2022-03-05 11:15 - 000000000 ____D C:\Program Files\Common Files\AV
2022-03-02 15:54 - 2022-03-02 16:06 - 000041665 _____ C:\Users\Michelle\Downloads\Addition.txt
2022-03-02 15:45 - 2022-03-02 16:06 - 000027307 _____ C:\Users\Michelle\Downloads\FRST.txt
2022-03-02 15:41 - 2022-03-05 16:35 - 000000000 ____D C:\FRST
2022-03-02 15:40 - 2022-03-02 15:40 - 002299904 _____ (Farbar) C:\Users\Michelle\Downloads\FRST64.exe
2022-03-02 15:30 - 2022-03-02 15:30 - 000000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2022-03-02 15:26 - 2022-03-05 16:33 - 000000000 ____D C:\Users\Michelle\Documents\Remote Assistance Logs
2022-03-02 15:14 - 2022-03-02 15:14 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CrystalDiskInfo
2022-03-02 15:14 - 2022-03-02 15:14 - 000000000 ____D C:\Program Files\CrystalDiskInfo
2022-03-02 15:13 - 2022-03-02 15:13 - 004628000 _____ (Crystal Dew World ) C:\Users\Michelle\Downloads\CrystalDiskInfo8_15_2.exe
2022-03-02 14:58 - 2022-03-02 14:58 - 000000117 _____ C:\WINDOWS\system32\netcfg-210819.txt
2022-03-02 14:58 - 2022-03-02 14:58 - 000000117 _____ C:\WINDOWS\system32\netcfg-210601.txt
2022-03-02 14:58 - 2022-03-02 14:58 - 000000117 _____ C:\WINDOWS\system32\netcfg-207060.txt
2022-03-02 14:41 - 2022-03-02 14:41 - 201879933 _____ C:\WINDOWS\MEMORY.DMP
2022-03-02 14:41 - 2022-03-02 14:41 - 000279744 _____ C:\WINDOWS\Minidump\030222-19390-01.dmp
2022-03-02 14:41 - 2022-03-02 14:41 - 000000000 ____D C:\WINDOWS\Minidump
2022-02-27 05:27 - 2022-02-27 05:27 - 000000117 _____ C:\WINDOWS\system32\netcfg-56753.txt
2022-02-27 05:15 - 2022-02-27 05:15 - 000000117 _____ C:\WINDOWS\system32\netcfg-724818615.txt
2022-02-20 12:25 - 2022-02-20 12:26 - 000000117 _____ C:\WINDOWS\system32\netcfg-145839968.txt
2022-02-20 12:24 - 2022-02-20 12:24 - 000001139 _____ C:\WINDOWS\system32\netcfg-145741984.txt
2022-02-20 12:12 - 2022-02-20 12:12 - 000000117 _____ C:\WINDOWS\system32\netcfg-145059479.txt
2022-02-20 12:12 - 2022-02-20 12:12 - 000000117 _____ C:\WINDOWS\system32\netcfg-145058652.txt
2022-02-19 03:58 - 2022-02-19 03:58 - 000000117 _____ C:\WINDOWS\system32\netcfg-29008042.txt
2022-02-19 03:58 - 2022-02-19 03:58 - 000000117 _____ C:\WINDOWS\system32\netcfg-29004392.txt
2022-02-18 19:21 - 2022-02-18 19:21 - 000000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2022-02-18 18:56 - 2022-02-18 18:56 - 000000117 _____ C:\WINDOWS\system32\netcfg-77623835.txt
2022-02-18 18:08 - 2022-02-18 18:08 - 000000117 _____ C:\WINDOWS\system32\netcfg-74735180.txt
2022-02-18 17:10 - 2022-02-18 17:10 - 000000117 _____ C:\WINDOWS\system32\netcfg-71271864.txt
2022-02-18 15:20 - 2022-02-18 15:20 - 000000117 _____ C:\WINDOWS\system32\netcfg-64647828.txt
2022-02-18 15:17 - 2022-02-18 15:18 - 000000117 _____ C:\WINDOWS\system32\netcfg-64515102.txt
2022-02-18 15:17 - 2022-02-18 15:17 - 000000117 _____ C:\WINDOWS\system32\netcfg-64514431.txt
2022-02-18 15:17 - 2022-02-18 15:17 - 000000117 _____ C:\WINDOWS\system32\netcfg-64500235.txt
2022-02-18 15:16 - 2022-02-18 15:16 - 000000117 _____ C:\WINDOWS\system32\netcfg-64424169.txt
2022-02-18 15:16 - 2022-02-18 15:16 - 000000117 _____ C:\WINDOWS\system32\netcfg-64416744.txt
2022-02-18 15:13 - 2022-02-18 15:13 - 000000117 _____ C:\WINDOWS\system32\netcfg-64271990.txt
2022-02-18 15:03 - 2022-02-18 15:03 - 000000117 _____ C:\WINDOWS\system32\netcfg-63650311.txt
2022-02-18 15:03 - 2022-02-18 15:03 - 000000117 _____ C:\WINDOWS\system32\netcfg-63648969.txt
2022-02-18 14:58 - 2022-02-18 14:58 - 000000117 _____ C:\WINDOWS\system32\netcfg-63335126.txt
2022-02-18 14:58 - 2022-02-18 14:58 - 000000117 _____ C:\WINDOWS\system32\netcfg-63334861.txt
2022-02-18 14:58 - 2022-02-18 14:58 - 000000117 _____ C:\WINDOWS\system32\netcfg-63331679.txt
2022-02-18 10:56 - 2022-02-18 10:56 - 000000117 _____ C:\WINDOWS\system32\netcfg-39144488.txt
2022-02-18 10:56 - 2022-02-18 08:15 - 000000117 _____ C:\WINDOWS\system32\netcfg-39149854.txt
2022-02-18 09:53 - 2022-02-18 09:53 - 000000000 ____D C:\Users\Michelle\AppData\Roaming\Macromedia
2022-02-18 09:48 - 2022-02-18 09:48 - 000000117 _____ C:\WINDOWS\system32\netcfg-44732366.txt
2022-02-18 09:45 - 2022-02-18 09:45 - 000000117 _____ C:\WINDOWS\system32\netcfg-44543620.txt
2022-02-18 09:43 - 2022-02-18 09:43 - 000000117 _____ C:\WINDOWS\system32\netcfg-44431253.txt
2022-02-18 08:53 - 2022-02-18 08:53 - 000000117 _____ C:\WINDOWS\system32\netcfg-41463458.txt
2022-02-18 08:53 - 2022-02-18 08:53 - 000000117 _____ C:\WINDOWS\system32\netcfg-41456329.txt
2022-02-18 08:51 - 2022-02-18 08:51 - 000000013 __RSH C:\WINDOWS\system32\Drivers\fbd.sys
2022-02-18 08:46 - 2022-02-18 08:46 - 000002257 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2022-02-18 08:46 - 2022-02-18 08:46 - 000002216 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2022-02-18 08:46 - 2022-02-18 08:46 - 000000000 ____D C:\Program Files\Google
2022-02-18 08:44 - 2022-03-05 16:31 - 000000000 ____D C:\Program Files (x86)\Google
2022-02-18 08:44 - 2022-02-18 17:52 - 000000000 ____D C:\Users\Michelle\AppData\Local\Google
2022-02-18 08:44 - 2022-02-18 08:44 - 000003334 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA{2110CD26-E00F-4E8A-B759-D7DAC3E8E389}
2022-02-18 08:44 - 2022-02-18 08:44 - 000003206 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore{AB007181-87B4-4265-A36C-C2F24D4432C1}
2022-02-18 08:29 - 2022-03-05 13:56 - 000003600 _____ C:\WINDOWS\system32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1354572454-1105605337-2006680600-1001
2022-02-18 08:27 - 2022-02-18 08:27 - 000000000 ____D C:\Users\Michelle\AppData\Roaming\ATI
2022-02-18 08:27 - 2022-02-18 08:27 - 000000000 ____D C:\Users\Michelle\AppData\Local\ATI
2022-02-18 08:22 - 2022-02-18 08:22 - 000000000 ____D C:\WINDOWS\system32\Tasks\WPD
2022-02-18 08:22 - 2022-02-18 08:22 - 000000000 ____D C:\Users\Michelle\AppData\Local\TOSHIBA
2022-02-18 08:21 - 2022-02-18 08:21 - 000001445 _____ C:\Users\Michelle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2022-02-18 08:21 - 2022-02-18 08:21 - 000000000 ____D C:\Users\Michelle\AppData\Roaming\WinBatch
2022-02-18 08:21 - 2022-02-18 08:21 - 000000000 ____D C:\Users\Michelle\AppData\Roaming\Adobe
2022-02-18 08:19 - 2022-02-18 08:19 - 000000000 ____D C:\Users\Michelle\AppData\Local\VirtualStore
2022-02-18 08:18 - 2022-03-05 10:28 - 000000000 ____D C:\WINDOWS\system32\Tasks\Norton Anti-Theft
2022-02-18 08:18 - 2022-02-18 08:21 - 000000000 ____D C:\Users\Michelle\AppData\Local\Packages
2022-02-18 08:17 - 2022-02-18 08:17 - 000000020 ___SH C:\Users\Michelle\ntuser.ini
2022-02-18 08:17 - 2012-09-07 00:13 - 000002111 _____ C:\Users\Michelle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SkyDrive.lnk
2022-02-18 08:15 - 2022-02-27 05:17 - 000000000 ____D C:\Users\Michelle
2022-02-18 08:15 - 2022-02-18 08:15 - 000000117 _____ C:\WINDOWS\system32\netcfg-39152912.txt
2022-02-18 01:04 - 2022-02-18 01:04 - 000000000 _____ C:\Recovery.txt
2022-02-18 00:05 - 2022-02-18 00:05 - 000000000 __RHD C:\Users\Public\AccountPictures
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2022-03-05 16:34 - 2012-07-26 02:59 - 000000000 ____D C:\WINDOWS\CbsTemp
2022-03-05 16:29 - 2012-07-26 02:28 - 000848230 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2022-03-05 16:29 - 2012-07-26 00:37 - 000000000 ____D C:\WINDOWS\Inf
2022-03-05 16:25 - 2012-09-06 23:50 - 000000000 ____D C:\ProgramData\Norton
2022-03-05 16:25 - 2012-07-26 02:22 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2022-03-05 16:23 - 2012-07-26 02:52 - 000000000 ____D C:\Program Files\Windows Journal
2022-03-05 16:22 - 2012-07-26 00:38 - 000000000 ____D C:\WINDOWS\system32\oobe
2022-03-05 16:09 - 2012-09-06 23:49 - 000000000 ____D C:\ProgramData\NortonInstaller
2022-03-05 15:09 - 2012-07-26 00:26 - 000262144 ___SH C:\WINDOWS\system32\config\BBI
2022-03-05 11:40 - 2012-07-26 00:26 - 000262144 ___SH C:\WINDOWS\system32\config\ELAM
2022-03-05 11:20 - 2012-07-26 03:12 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2022-03-05 10:48 - 2012-07-26 00:37 - 000000000 ____D C:\WINDOWS\servicing
2022-03-03 01:40 - 2012-07-26 03:12 - 000000000 ___HD C:\Program Files\WindowsApps
2022-03-03 01:40 - 2012-07-26 03:12 - 000000000 ____D C:\WINDOWS\AUInstallAgent
2022-02-18 15:16 - 2012-07-26 03:12 - 000000000 ____D C:\WINDOWS\system32\NDF
2022-02-18 08:21 - 2012-09-06 23:55 - 000000000 ____D C:\ProgramData\Toshiba
2022-02-18 08:21 - 2012-07-26 02:49 - 000000000 ____D C:\WINDOWS\SysWOW64\sysprep
2022-02-18 08:18 - 2012-07-26 03:12 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2022-02-18 08:18 - 2012-07-26 03:12 - 000000000 ____D C:\WINDOWS\WinStore
2022-02-18 01:03 - 2012-07-26 03:13 - 000262144 _____ C:\WINDOWS\system32\config\BCD-Template
2022-02-18 00:06 - 2012-07-26 03:12 - 000000000 ____D C:\WINDOWS\rescache
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
LastRegBack: 2022-03-02 16:25
==================== End of FRST.txt ========================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 27-02-2022
Ran by Michelle (05-03-2022 16:37:55)
Running from C:\Users\Michelle\Documents
Microsoft Windows 8 (X64) (2022-02-18 13:17:35)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
(If an entry is included in the fixlist, it will be removed.)
Administrator (S-1-5-21-1354572454-1105605337-2006680600-500 - Administrator - Disabled)
Guest (S-1-5-21-1354572454-1105605337-2006680600-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1354572454-1105605337-2006680600-1003 - Limited - Enabled)
Michelle (S-1-5-21-1354572454-1105605337-2006680600-1001 - Administrator - Enabled) => C:\Users\Michelle
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe Reader X (10.1.3) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AA1000000001}) (Version: 10.1.3 - Adobe Systems Incorporated)
AMD Catalyst Install Manager (HKLM\...\{14718008-7D73-53AA-D0FF-88E805958D42}) (Version: 8.0.881.0 - Advanced Micro Devices, Inc.)
Bejeweled 3 (HKLM-x32\...\WTA-81c59777-621e-4806-9416-36dd66c270ab) (Version: 2.2.0.97 - WildTangent) Hidden
CrystalDiskInfo 8.15.2 (HKLM\...\CrystalDiskInfo_is1) (Version: 8.15.2 - Crystal Dew World)
D3DX10 (HKLM-x32\...\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden
Farmscapes (HKLM-x32\...\WTA-a7e7ee1b-7d47-4331-a795-4c9d14f19a6c) (Version: 2.2.0.98 - WildTangent) Hidden
FATE (HKLM-x32\...\WTA-32a3717d-6449-4dc6-839a-5304267673c1) (Version: 2.2.0.97 - WildTangent) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 98.0.4758.102 - Google LLC)
Microsoft Office (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.6120.5004 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Movie Maker (HKLM-x32\...\{40F55150-F43D-4C9F-9A00-1A0A6F1EB7F0}) (Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Movie Maker (HKLM-x32\...\{D71BC54E-A4E6-4E06-866C-FD6EE16EA187}) (Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Origin (HKLM-x32\...\Origin) (Version: 8.6.3.49 - Electronic Arts, Inc.)
Penguins! (HKLM-x32\...\WTA-5b2c080f-efe1-4fe4-b2a0-b479b2cf5e59) (Version: 2.2.0.98 - WildTangent) Hidden
Plants vs. Zombies - Game of the Year (HKLM-x32\...\WTA-200eaec2-9234-47d1-8867-2da6179703e6) (Version: 2.2.0.98 - WildTangent) Hidden
PlayReady PC Runtime amd64 (HKLM\...\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation)
Polar Bowler (HKLM-x32\...\WTA-e3e47cae-06ed-43c0-ab20-a96239c84835) (Version: 2.2.0.97 - WildTangent) Hidden
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.2.612.2012 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6690 - Realtek Semiconductor Corp.)
Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.8400.39030 - Realtek Semiconductor Corp.)
Realtek WLAN Driver (HKLM-x32\...\{9D3D8C60-A55F-4fed-B2B9-173001290E16}) (Version: 2.00.0020 - REALTEK Semiconductor Corp.)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 16.2.10.5 - Synaptics Incorporated)
Toshiba App Place (HKLM-x32\...\{ED3CBA78-488F-4E8C-B33F-8E3BF4DDB4D2}) (Version: 1.0.6.3 - Toshiba)
TOSHIBA Application Installer (HKLM-x32\...\{970472D0-F5F9-4158-A6E3-1AE49EFEF2D3}) (Version: 9.0.1.4 - TOSHIBA)
TOSHIBA Audio Enhancement (HKLM\...\{F2DE0088-CF05-4DAB-AC4D-9D2C4D657456}) (Version: 1.0.2.8 - TOSHIBA Corporation)
Toshiba Book Place (HKLM-x32\...\{24B45620-22B6-4E4A-B836-FF30A0B0404E}) (Version: 3.1.9534 - K-NFB Reading Technology, Inc.)
TOSHIBA Desktop Assist (HKLM\...\{95CCACF0-010D-45F0-82BF-858643D8BC02}) (Version: 1.00.0007.00002 - Toshiba Corporation)
TOSHIBA eco Utility (HKLM\...\{5944B9D4-3C2A-48DE-931E-26B31714A2F7}) (Version: 2.0.0.6414 - Toshiba Corporation)
TOSHIBA Function Key (HKLM\...\{16562A90-71BC-41A0-B890-D91B0C267120}) (Version: 1.00.6425 - Toshiba Corporation)
TOSHIBA Password Utility (HKLM-x32\...\{B1786E63-2127-42C9-95A3-146E5F727BF1}) (Version: v1.0.0.8 - TOSHIBA Corporation)
TOSHIBA PC Health Monitor (HKLM\...\{9DECD0F9-D3E8-48B0-A390-1CF09F54E3A4}) (Version: 1.8.17.640104 - Toshiba Corporation)
TOSHIBA Quality Application (HKLM-x32\...\{E69992ED-A7F6-406C-9280-1C156417BC49}) (Version: 1.0.8 - TOSHIBA)
TOSHIBA Recovery Media Creator (HKLM-x32\...\{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}) (Version: 2.2.0.54043005 - Toshiba Corporation)
TOSHIBA Service Station (HKLM\...\{B8C8422F-01F1-4791-B084-047AAFF9BFCC}) (Version: 2.4.4 - TOSHIBA)
TOSHIBA System Driver (HKLM-x32\...\{1E6A96A1-2BAB-43EF-8087-30437593C66C}) (Version: 1.00.0013 - Toshiba Corporation)
TOSHIBA System Settings (HKLM-x32\...\{05A55927-DB9B-4E26-BA44-828EBFF829F0}) (Version: 1.00.0002.32002 - Toshiba Corporation)
TOSHIBA User's Guide (HKLM-x32\...\{3384E1D9-3F18-4A98-8655-180FEF0DFC02}) (Version: 1.00.02 - TOSHIBA)
TOSHIBA VIDEO PLAYER (HKLM\...\{FF07604E-C860-40E9-A230-E37FA41F103A}) (Version: 5.1.0.12-A - Toshiba Corporation)
TOSHIBARegistration (HKLM-x32\...\{5AF550B4-BB67-4E7E-82F1-2C4300279050}) (Version: 1.1.6 - TOSHIBA)
Update Installer for WildTangent Games App (HKLM-x32\...\{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App) (Version: - WildTangent) Hidden
Virtual Villagers 4 - The Tree of Life (HKLM-x32\...\WTA-1ae4582f-e96d-4155-a248-36b47d775e6f) (Version: 2.2.0.97 - WildTangent) Hidden
WildTangent Games (HKLM-x32\...\WildTangent toshiba Master Uninstall) (Version: 1.0.3.0 - WildTangent)
WildTangent Games App (Toshiba Games) (HKLM-x32\...\{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-toshiba) (Version: 4.0.8.7 - WildTangent) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3503.0728 - Microsoft Corporation)
Packages:
=========
- Games App - -> C:\Program Files\WindowsApps\WildTangentGames.-GamesApp-_1.0.0.80_neutral__qt5r5pa5dyg8m [2012-10-27] (WildTangent Games)
Amazon for Windows -> C:\Program Files\WindowsApps\Amazon.com.Amazon_1.0.4.0_neutral__343d40qqvtj1t [2012-10-27] (Amazon.com)
Bing -> C:\Program Files\WindowsApps\Microsoft.Bing_1.2.0.137_x64__8wekyb3d8bbwe [2022-02-18] (Microsoft Corporation)
Book Place -> C:\Program Files\WindowsApps\K-NFBReadingTechnologiesI.BookPlace_1.0.0.77_x86__vwcaa66y1ah8t [2022-02-18] (K-NFB Reading Technologies, Inc.)
Camera -> C:\Program Files\WindowsApps\Microsoft.Camera_6.2.8514.0_x64__8wekyb3d8bbwe [2022-02-18] (Microsoft Corporation)
eBay -> C:\Program Files\WindowsApps\eBayInc.eBay_1.0.0.0_neutral__1618n3s9xq8tw [2012-10-27] (eBay, Inc)
Encyclopaedia Britannica -> C:\Program Files\WindowsApps\EncyclopaediaBritannica.EncyclopaediaBritannica_1.0.0.17_neutral__k5b3gy2wfywap [2012-10-27] (Encyclopaedia Britannica)
Finance -> C:\Program Files\WindowsApps\Microsoft.BingFinance_1.2.0.135_x64__8wekyb3d8bbwe [2022-02-18] (Microsoft Corporation) [MS Ad]
Games -> C:\Program Files\WindowsApps\Microsoft.XboxLIVEGames_1.0.927.0_x64__8wekyb3d8bbwe [2022-02-18] (Microsoft Corporation) [MS Ad]
iCookbook SE -> C:\Program Files\WindowsApps\PublicationsInternational.iCookbookSE_0.9.2.5_neutral__d33n3f4t8bm20 [2012-10-27] (Publications International, Ltd)
iHeartRadio -> C:\Program Files\WindowsApps\ClearChannelRadioDigital.iHeartRadio_4.0.1.6_neutral__a76a11dkgb644 [2022-02-18] (Clear Channel Management Services, Inc.)
Merriam-Webster Dictionary -> C:\Program Files\WindowsApps\D22CCC44.Merriam-WebsterDictionary_1.0.0.16_neutral__mbv6ra3y34fnr [2012-10-27] (Merriam-Webster, Inc.)
Microsoft Windows Library for JavaScript -> C:\Program Files\WindowsApps\Microsoft.WinJS.1.0.RC_1.0.8377.0_neutral__8wekyb3d8bbwe [2022-02-18] (Microsoft Platform Extensions)
Music -> C:\Program Files\WindowsApps\Microsoft.ZuneMusic_1.0.927.0_x64__8wekyb3d8bbwe [2022-02-18] (Microsoft Corporation) [MS Ad]
Netflix -> C:\Program Files\WindowsApps\4DF9E0F8.Netflix_1.0.0.11_x64__mcm4njqhnhss8 [2012-10-27] (Netflix, Inc.)
News -> C:\Program Files\WindowsApps\Microsoft.BingNews_1.2.0.135_x64__8wekyb3d8bbwe [2022-02-18] (Microsoft Corporation) [MS Ad]
News Place -> C:\Program Files\WindowsApps\2B24874D.NewsPlace_1.0.0.2_neutral__v10edqkhnj0dg [2022-02-18] (Synacor, Inc.)
Norton Studio -> C:\Program Files\WindowsApps\SymantecCorporation.NortonStudio_1.0.0.62_x86__v68kp9n051hdp [2012-10-27] (Symantec Corporation)
Photos -> C:\Program Files\WindowsApps\microsoft.windowsphotos_16.4.4204.712_x64__8wekyb3d8bbwe [2022-02-18] (Microsoft Corporation)
SkyDrive -> C:\Program Files\WindowsApps\microsoft.microsoftskydrive_16.4.4204.712_x64__8wekyb3d8bbwe [2022-02-18] (Microsoft Corporation)
Sports -> C:\Program Files\WindowsApps\Microsoft.BingSports_1.2.0.135_x64__8wekyb3d8bbwe [2022-02-18] (Microsoft Corporation) [MS Ad]
StumbleUpon -> C:\Program Files\WindowsApps\06DAC6F6.StumbleUpon_2.0.5.0_neutral__9pdyks8yk4v0j [2012-10-27] (StumbleUpon, Inc.)
Toshiba Central -> C:\Program Files\WindowsApps\ToshibaAmericaInformation.ToshibaCentral_1.0.0.24_neutral__r8x1fxsdcnpjw [2012-10-27] (Toshiba America Information Systems, Inc.)
TOSHIBA Media Player by sMedio TrueLink+ -> C:\Program Files\WindowsApps\sMedioforToshiba.TOSHIBAMediaPlayerbysMedioTrueLin_1.0.0.44_x64__679ekb9hp1h62 [2022-02-18] (sMedio)
Travel -> C:\Program Files\WindowsApps\Microsoft.BingTravel_1.2.0.145_x64__8wekyb3d8bbwe [2022-02-18] (Microsoft Corporation) [MS Ad]
Video -> C:\Program Files\WindowsApps\Microsoft.ZuneVideo_1.0.927.0_x64__8wekyb3d8bbwe [2022-02-18] (Microsoft Corporation) [MS Ad]
Vimeo -> C:\Program Files\WindowsApps\Vimeo.Vimeo_1.1.0.0_neutral__cfs1vy0wkzthc [2022-02-18] (Vimeo)
Weather -> C:\Program Files\WindowsApps\Microsoft.BingWeather_1.2.0.135_x64__8wekyb3d8bbwe [2022-02-18] (Microsoft Corporation) [MS Ad]
==================== Custom CLSID (Whitelisted): ==============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File
ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File
ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\atiacm64.dll [2012-08-08] (Advanced Micro Devices, Inc.) [File not signed]
==================== Codecs (Whitelisted) ====================
==================== Shortcuts & WMI ========================
==================== Loaded Modules (Whitelisted) =============
2012-08-08 12:19 - 2012-08-08 12:19 - 000008704 _____ (Advanced Micro Devices Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\AEM.Actions.CCAA.Shared.dll
2012-08-08 12:20 - 2012-08-08 12:20 - 000006656 _____ (Advanced Micro Devices Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\AEM.Plugin.DPPE.Shared.dll
2012-08-08 12:19 - 2012-08-08 12:19 - 000005632 _____ (Advanced Micro Devices Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\AEM.Plugin.EEU.Shared.dll
2012-08-08 12:19 - 2012-08-08 12:19 - 000005632 _____ (Advanced Micro Devices Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\AEM.Plugin.GD.Shared.dll
2012-08-08 12:19 - 2012-08-08 12:19 - 000007168 _____ (Advanced Micro Devices Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\AEM.Plugin.Hotkeys.Shared.dll
2012-08-08 12:19 - 2012-08-08 12:19 - 000005632 _____ (Advanced Micro Devices Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\AEM.Plugin.REG.Shared.dll
2012-08-08 12:20 - 2012-08-08 12:20 - 000048128 _____ (Advanced Micro Devices Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\AEM.Plugin.Source.Kit.Server.dll
2012-08-08 12:19 - 2012-08-08 12:19 - 000006656 _____ (Advanced Micro Devices Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\AEM.Plugin.WinMessages.Shared.dll
2012-08-08 12:19 - 2012-08-08 12:19 - 000035328 _____ (Advanced Micro Devices Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\AEM.Server.dll
2012-08-08 12:19 - 2012-08-08 12:19 - 000006144 _____ (Advanced Micro Devices Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\AEM.Server.Shared.dll
2012-08-08 12:19 - 2012-08-08 12:19 - 000024576 _____ (Advanced Micro Devices Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\APM.Foundation.dll
2012-08-08 12:19 - 2012-08-08 12:19 - 000032768 _____ (Advanced Micro Devices Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\ATICCCom.dll
2012-08-08 12:20 - 2012-08-08 12:20 - 000022016 _____ (Advanced Micro Devices Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.Implementation.dll
2012-08-08 12:23 - 2012-08-08 12:23 - 000040448 _____ (Advanced Micro Devices Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.AMDOverDrive.Platform.Dashboard.dll
2012-08-08 12:23 - 2012-08-08 12:23 - 000015360 _____ (Advanced Micro Devices Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.AMDOverDrive.Platform.Runtime.dll
2012-08-08 12:20 - 2012-08-08 12:20 - 000012800 _____ (Advanced Micro Devices Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.AMDOverDrive.Platform.Shared.dll
2012-08-08 12:23 - 2012-08-08 12:23 - 000019456 _____ (Advanced Micro Devices Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CPUOverDrive.Fuel.Shared.dll
2012-08-08 12:20 - 2012-08-08 12:20 - 000050688 _____ (Advanced Micro Devices Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.OverDrive5.Graphics.Shared.dll
2012-08-08 12:21 - 2012-08-08 12:21 - 000008704 _____ (Advanced Micro Devices Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Caste.Fuel.Dashboard.dll
2012-08-08 12:21 - 2012-08-08 12:21 - 000020480 _____ (Advanced Micro Devices Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Caste.Fuel.Runtime.dll
2012-08-08 12:21 - 2012-08-08 12:21 - 000010752 _____ (Advanced Micro Devices Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Caste.Fuel.Shared.dll
2012-08-08 12:20 - 2012-08-08 12:20 - 000176128 _____ (Advanced Micro Devices Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Caste.Graphics.Dashboard.dll
2012-08-08 12:20 - 2012-08-08 12:20 - 001007616 _____ (Advanced Micro Devices Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Caste.Graphics.Dashboard.Shared.dll
2012-08-08 12:20 - 2012-08-08 12:20 - 000008704 _____ (Advanced Micro Devices Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Caste.HydraVision.Dashboard.dll
2012-08-08 12:20 - 2012-08-08 12:20 - 000011776 _____ (Advanced Micro Devices Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Caste.HydraVision.Runtime.dll
2012-08-08 12:20 - 2012-08-08 12:20 - 000008704 _____ (Advanced Micro Devices Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Caste.HydraVision.Shared.dll
2012-08-08 12:23 - 2012-08-08 12:23 - 000008192 _____ (Advanced Micro Devices Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Caste.Platform.Dashboard.dll
2012-08-08 12:23 - 2012-08-08 12:23 - 000011264 _____ (Advanced Micro Devices Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Caste.Platform.Runtime.dll
2012-08-08 12:23 - 2012-08-08 12:23 - 000009216 _____ (Advanced Micro Devices Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Caste.Platform.Shared.dll
2012-08-08 12:19 - 2012-08-08 12:19 - 000008192 _____ (Advanced Micro Devices Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Component.Client.Shared.dll
2012-08-08 12:21 - 2012-08-08 12:21 - 000061440 _____ (Advanced Micro Devices Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Component.Dashboard.ProfileManager2.dll
2012-08-08 12:19 - 2012-08-08 12:19 - 000032768 _____ (Advanced Micro Devices Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Component.Dashboard.Shared.dll
2012-08-08 12:20 - 2012-08-08 12:20 - 001395712 _____ (Advanced Micro Devices Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Component.Dashboard.Shared.Private.dll
2012-08-08 12:19 - 2012-08-08 12:19 - 000007168 _____ (Advanced Micro Devices Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Component.Runtime.Extension.EEU.dll
2012-08-08 12:19 - 2012-08-08 12:19 - 000005632 _____ (Advanced Micro Devices Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Component.Runtime.Shared.dll
2012-08-08 12:19 - 2012-08-08 12:19 - 000038912 _____ (Advanced Micro Devices Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Component.Runtime.Shared.Private.dll
2012-08-08 12:19 - 2012-08-08 12:19 - 000307200 _____ (Advanced Micro Devices Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Foundation.Client.dll
2012-08-08 12:19 - 2012-08-08 12:19 - 000020480 _____ (Advanced Micro Devices Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Foundation.CoreAudioAPI.dll
2012-08-08 12:19 - 2012-08-08 12:19 - 000061440 _____ (Advanced Micro Devices Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Foundation.dll
2012-08-08 12:19 - 2012-08-08 12:19 - 000029184 _____ (Advanced Micro Devices Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Foundation.Private.dll
2012-08-08 12:20 - 2012-08-08 12:20 - 000018432 _____ (Advanced Micro Devices Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Foundation.XManifest.dll
2012-08-08 12:19 - 2012-08-08 12:19 - 000006656 _____ (Advanced Micro Devices Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\DEM.Graphics.dll
2012-08-08 12:21 - 2012-08-08 12:21 - 000013312 _____ (Advanced Micro Devices Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\Fuel.Foundation.dll
2012-08-08 12:19 - 2012-08-08 12:19 - 000031744 _____ (Advanced Micro Devices Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\LOG.Foundation.dll
2012-08-08 12:20 - 2012-08-08 12:20 - 000048128 _____ (Advanced Micro Devices Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\LOG.Foundation.Implementation.dll
2012-08-08 12:19 - 2012-08-08 12:19 - 000020480 _____ (Advanced Micro Devices Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\LOG.Foundation.Implementation.Private.dll
2012-08-08 12:19 - 2012-08-08 12:19 - 000025088 _____ (Advanced Micro Devices Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\LOG.Foundation.Private.dll
2012-08-08 12:19 - 2012-08-08 12:19 - 000005632 _____ (Advanced Micro Devices Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Foundation.dll
2012-08-08 12:20 - 2012-08-08 12:20 - 000097792 _____ (Advanced Micro Devices Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll
2012-08-08 12:19 - 2012-08-08 12:19 - 000015360 _____ (Advanced Micro Devices Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\NEWAEM.Foundation.dll
2012-07-12 08:56 - 2012-07-12 08:56 - 000175104 _____ (Advanced Micro Devices, Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\ADL.Foundation.dll
2012-08-08 12:19 - 2012-08-08 12:19 - 000066560 _____ (Advanced Micro Devices, Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\APM.Server.dll
2012-08-08 12:19 - 2012-08-08 12:19 - 000036864 _____ (Advanced Micro Devices, Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Component.Client.Shared.Private.dll
2012-08-08 12:20 - 2012-08-08 12:20 - 000385024 _____ (Advanced Micro Devices, Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Component.Dashboard.dll
2012-08-08 12:19 - 2012-08-08 12:19 - 000061440 _____ (Advanced Micro Devices, Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Component.Runtime.dll
2011-10-17 18:48 - 2011-10-17 18:48 - 000006656 _____ (Advanced Micro Devices, Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\DEM.Graphics.I0709.dll
2012-08-08 12:19 - 2012-08-08 12:19 - 000303616 _____ (Advanced Micro Devices, Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\Localization.Foundation.Implementation.default_Localization.dll
2012-08-08 12:19 - 2012-08-08 12:19 - 000479744 _____ (Advanced Micro Devices, Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\Localization.Foundation.Private.dll
2012-08-08 12:21 - 2012-08-08 12:21 - 000175104 _____ (Advanced Micro Devices, Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\ResourceManagement.Foundation.Implementation.dll
2012-08-08 12:19 - 2012-08-08 12:19 - 000008704 _____ (Advanced Micro Devices, Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\ResourceManagement.Foundation.Private.dll
2012-08-08 12:19 - 2012-08-08 12:19 - 000311296 _____ (Advanced Mirco Devices, Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Caste.Graphics.Runtime.dll
2012-08-08 12:19 - 2012-08-08 12:19 - 000196608 _____ (Advanced Mirco Devices, Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Caste.Graphics.Shared.dll
2011-10-17 18:48 - 2011-10-17 18:48 - 000016384 _____ (ATI Technologies Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\DEM.Foundation.dll
2011-10-17 18:48 - 2011-10-17 18:48 - 000045056 _____ (ATI Technologies Inc.) [File not signed] [File is in use] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\DEM.Graphics.I0601.dll
2012-10-27 08:14 - 2012-02-14 21:37 - 000594432 _____ (Realtek Semiconductor Corp.) [File not signed] C:\WINDOWS\system32\Rtlihvs.dll
2012-07-19 11:53 - 2012-07-19 11:53 - 000265728 _____ (TOSHIBA Corporation) [File not signed] C:\Program Files\Toshiba\Hotkey\TCrdMain.dll
==================== Alternate Data Streams (Whitelisted) ========
==================== Safe Mode (Whitelisted) ==================
==================== Association (Whitelisted) =================
==================== Internet Explorer (Whitelisted) ==========
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://toshiba13.msn.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://toshiba13.msn.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://toshiba13.msn.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://toshiba13.msn.com
HKU\S-1-5-21-1354572454-1105605337-2006680600-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://toshiba13.msn.com
HKU\S-1-5-21-1354572454-1105605337-2006680600-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://toshiba13.msn.com
HKU\S-1-5-21-1354572454-1105605337-2006680600-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://mystart.toshiba.com
SearchScopes: HKU\S-1-5-21-1354572454-1105605337-2006680600-1001 -> DefaultScope {7D826E84-F143-4808-AA3C-E7F4FDAFE171} URL =
SearchScopes: HKU\S-1-5-21-1354572454-1105605337-2006680600-1001 -> {7D826E84-F143-4808-AA3C-E7F4FDAFE171} URL =
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-04-04] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
BHO-x32: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files (x86)\Norton Internet Security\Engine\20.0.0.136\IPS\IPSBHO.DLL => No File
==================== Hosts content: =========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2012-07-26 00:26 - 2012-07-26 00:26 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts
==================== Other Areas ===========================
(Currently there is no automatic fix for this section.)
HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\AMD APP\bin\x86_64;C:\Program Files (x86)\AMD APP\bin\x86;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static
HKU\S-1-5-21-1354572454-1105605337-2006680600-1001\Control Panel\Desktop\\Wallpaper ->
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
==================== FirewallRules (Whitelisted) ================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{C1FE97EC-B03D-48FF-94D5-E5FC0E1F9A37}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{6243A023-8B9C-4A2F-A4C1-53569B92F894}] => (Allow) LPort=2869
FirewallRules: [{0F7812EE-19D9-4517-ADAB-248F4E6E6FC5}] => (Allow) LPort=1900
FirewallRules: [{F0E3B040-8913-4C64-86F1-0E59EDF6AE44}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
==================== Restore Points =========================
02-03-2022 18:43:13 Windows Update
05-03-2022 15:21:32 Windows Modules Installer
==================== Faulty Device Manager Devices ============
==================== Event log errors: ========================
Application errors:
==================
Error: (03/05/2022 04:31:47 PM) (Source: Toshiba App Place) (EventID: 0) (User: )
Description: System.Runtime.Serialization.SerializationException: There was an error deserializing the object of type SnappCloud.ActivationReminder.Models.InitClientResponse. Encountered unexpected character '<'.
Stack Trace:
at System.Runtime.Serialization.XmlObjectSerializer.ReadObjectHandleExceptions(XmlReaderDelegator reader, Boolean verifyObjectName)
at System.Runtime.Serialization.Json.DataContractJsonSerializer.ReadObject(XmlDictionaryReader reader)
at System.Runtime.Serialization.Json.DataContractJsonSerializer.ReadObject(Stream stream)
at SnappCloud.ActivationReminder.AraClient.DeserializeJson[T](String json)
at SnappCloud.ActivationReminder.AraClient.GetResponseCallback[T](IAsyncResult result)
Error: (03/05/2022 04:07:09 PM) (Source: Toshiba App Place) (EventID: 0) (User: )
Description: System.Runtime.Serialization.SerializationException: There was an error deserializing the object of type SnappCloud.ActivationReminder.Models.InitClientResponse. Encountered unexpected character '<'.
Stack Trace:
at System.Runtime.Serialization.XmlObjectSerializer.ReadObjectHandleExceptions(XmlReaderDelegator reader, Boolean verifyObjectName)
at System.Runtime.Serialization.Json.DataContractJsonSerializer.ReadObject(XmlDictionaryReader reader)
at System.Runtime.Serialization.Json.DataContractJsonSerializer.ReadObject(Stream stream)
at SnappCloud.ActivationReminder.AraClient.DeserializeJson[T](String json)
at SnappCloud.ActivationReminder.AraClient.GetResponseCallback[T](IAsyncResult result)
Error: (03/05/2022 01:02:48 PM) (Source: Toshiba App Place) (EventID: 0) (User: )
Description: System.Runtime.Serialization.SerializationException: There was an error deserializing the object of type SnappCloud.ActivationReminder.Models.InitClientResponse. Encountered unexpected character '<'.
Stack Trace:
at System.Runtime.Serialization.XmlObjectSerializer.ReadObjectHandleExceptions(XmlReaderDelegator reader, Boolean verifyObjectName)
at System.Runtime.Serialization.Json.DataContractJsonSerializer.ReadObject(XmlDictionaryReader reader)
at System.Runtime.Serialization.Json.DataContractJsonSerializer.ReadObject(Stream stream)
at SnappCloud.ActivationReminder.AraClient.DeserializeJson[T](String json)
at SnappCloud.ActivationReminder.AraClient.GetResponseCallback[T](IAsyncResult result)
Error: (03/05/2022 10:55:50 AM) (Source: Toshiba App Place) (EventID: 0) (User: )
Description: System.Runtime.Serialization.SerializationException: There was an error deserializing the object of type SnappCloud.ActivationReminder.Models.InitClientResponse. Encountered unexpected character '<'.
Stack Trace:
at System.Runtime.Serialization.XmlObjectSerializer.ReadObjectHandleExceptions(XmlReaderDelegator reader, Boolean verifyObjectName)
at System.Runtime.Serialization.Json.DataContractJsonSerializer.ReadObject(XmlDictionaryReader reader)
at System.Runtime.Serialization.Json.DataContractJsonSerializer.ReadObject(Stream stream)
at SnappCloud.ActivationReminder.AraClient.DeserializeJson[T](String json)
at SnappCloud.ActivationReminder.AraClient.GetResponseCallback[T](IAsyncResult result)
Error: (03/05/2022 10:17:48 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: LogonUI.exe, version: 6.2.9200.16384, time stamp: 0x5010a7f4
Faulting module name: MSVCR90.dll, version: 9.0.30729.6871, time stamp: 0x4fee5fd5
Exception code: 0xc0000005
Fault offset: 0x00000000000747e7
Faulting process id: 0x54
Faulting application start time: 0x01d830a41e2c8f08
Faulting application path: C:\WINDOWS\system32\LogonUI.exe
Faulting module path: C:\WINDOWS\WinSxS\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6871_none_08e717a5a83adddf\MSVCR90.dll
Report Id: 69d56e9c-9c97-11ec-be73-008cfa246f8e
Faulting package full name:
Faulting package-relative application ID:
Error: (03/05/2022 10:15:37 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: MINE)
Description: Activation of app microsoft.windowsphotos_8wekyb3d8bbwe!Microsoft.WindowsLive.ModernPhotos failed with error: -2144980991 See the Microsoft-Windows-TWinUI/Operational log for additional information.
Error: (03/05/2022 10:15:36 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: MINE)
Description: Activation of app microsoft.windowsphotos_8wekyb3d8bbwe!Microsoft.WindowsLive.ModernPhotos failed with error: -2144980991 See the Microsoft-Windows-TWinUI/Operational log for additional information.
Error: (03/02/2022 03:09:04 PM) (Source: Toshiba App Place) (EventID: 0) (User: )
Description: System.Runtime.Serialization.SerializationException: There was an error deserializing the object of type SnappCloud.ActivationReminder.Models.InitClientResponse. Encountered unexpected character '<'.
Stack Trace:
at System.Runtime.Serialization.XmlObjectSerializer.ReadObjectHandleExceptions(XmlReaderDelegator reader, Boolean verifyObjectName)
at System.Runtime.Serialization.Json.DataContractJsonSerializer.ReadObject(XmlDictionaryReader reader)
at System.Runtime.Serialization.Json.DataContractJsonSerializer.ReadObject(Stream stream)
at SnappCloud.ActivationReminder.AraClient.DeserializeJson[T](String json)
at SnappCloud.ActivationReminder.AraClient.GetResponseCallback[T](IAsyncResult result)
System errors:
=============
Error: (03/05/2022 04:44:04 PM) (Source: DCOM) (EventID: 10010) (User: MINE)
Description: The server {BB6DF56B-CACE-11DC-9992-0019B93A3A84} did not register with DCOM within the required timeout.
Error: (03/05/2022 04:42:04 PM) (Source: DCOM) (EventID: 10010) (User: MINE)
Description: The server {1ECCA34C-E88A-44E3-8D6A-8921BDE9E452} did not register with DCOM within the required timeout.
Error: (03/05/2022 04:33:57 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: A fatal alert was received from the remote endpoint. The TLS protocol defined fatal alert code is 70.
Error: (03/05/2022 04:33:57 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: A fatal alert was received from the remote endpoint. The TLS protocol defined fatal alert code is 70.
Error: (03/05/2022 04:09:46 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: A fatal alert was received from the remote endpoint. The TLS protocol defined fatal alert code is 40.
Error: (03/05/2022 04:09:46 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: A fatal alert was received from the remote endpoint. The TLS protocol defined fatal alert code is 70.
Error: (03/05/2022 03:08:32 PM) (Source: DCOM) (EventID: 10010) (User: MINE)
Description: The server {9BA05972-F6A8-11CF-A442-00A0C90A8F39} did not register with DCOM within the required timeout.
Error: (03/05/2022 01:52:11 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: A fatal alert was received from the remote endpoint. The TLS protocol defined fatal alert code is 70.
==================== Memory info ===========================
BIOS: Insyde Corp. 6.20 01/09/2013
Motherboard: TOSHIBA Portable PC
Processor: AMD E-300 APU with Radeon HD Graphics
Percentage of memory in use: 80%
Total physical RAM: 1630.25 MB
Available physical RAM: 311.73 MB
Total Virtual: 9822.25 MB
Available Virtual: 7347.83 MB
==================== Drives ================================
Drive c: (TI10653500D) (Fixed) (Total:287.51 GB) (Free:248.44 GB) NTFS
\\?\Volume{19b1796e-fc7e-11e1-b415-c03b3d1fbb80}\ (System) (Fixed) (Total:0.44 GB) (Free:0.16 GB) NTFS
\\?\Volume{47d0c280-9aae-4391-834a-3561580c3cdb}\ () (Fixed) (Total:0.34 GB) (Free:0.31 GB) NTFS
\\?\Volume{092cbfbc-60b1-4534-ad27-85aa4fd28450}\ (Recovery) (Fixed) (Total:9.42 GB) (Free:0.64 GB) NTFS
==================== MBR & Partition Table ====================
==========================================================
Disk: 0 (Protective MBR) (Size: 298.1 GB) (Disk ID: 00000000)
Partition: GPT.
==================== End of Addition.txt =======================