Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 11-12-2021
Ran by bailey (administrator) on YOGA720-15IKB (LENOVO 80X7) (13-12-2021 02:21:43)
Running from C:\Users\baile\Desktop
Loaded Profiles: bailey
Platform: Microsoft Windows 10 Home Version 21H2 19044.1348 (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe
(Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\WindowsApps\AppleInc.iCloud_13.0.201.0_x86__nzyj5cx40ttqa\iCloud\APSDaemon.exe
(Apple Inc.) C:\Program Files\WindowsApps\AppleInc.iCloud_13.0.201.0_x86__nzyj5cx40ttqa\iCloud\iCloudServices.exe
(Dolby Laboratories, Inc. -> ) C:\Program Files\Dolby\Dolby DAX3\API\DAX3API.exe
(Dolby Laboratories, Inc. -> Dolby Laboratories, Inc.) C:\Program Files\Dolby\Dolby DAX3\APP\DAX3TrayIcon.exe
(Express Vpn LLC -> ExpressVPN) C:\Program Files (x86)\ExpressVPN\bootstrap\amd64\nssm.exe
(Express Vpn LLC -> ExpressVPN) C:\Program Files (x86)\ExpressVPN\expressvpnd\expressvpnd.exe
(Express Vpn LLC -> ExpressVPN) C:\Program Files (x86)\ExpressVPN\expressvpn-ui\ExpressVPN.exe
(Express Vpn LLC -> ExpressVPN) C:\Program Files (x86)\ExpressVPN\expressvpn-ui\ExpressVPNNotificationService.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <14>
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.112\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.112\GoogleCrashHandler64.exe
(HP Inc. -> HP Inc.) C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\Intel\DPTF\esif_uf.exe
(Intel Corporation -> Intel Corporation) C:\Windows\Temp\DPTF\esif_assist_64.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_3d757484a892eacf\igfxCUIService.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_3d757484a892eacf\igfxEM.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_3d757484a892eacf\IntelCpHDCPSvc.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_3d757484a892eacf\IntelCpHeciSvc.exe
(Intel(R) Wireless Connectivity Solutions -> Intel Corporation) C:\Windows\System32\ibtsiva.exe
(Logitech Inc -> Logitech) C:\ProgramData\Logishrd\LogiOptions\Software\Current\LogiOverlay.exe
(Logitech Inc -> Logitech, Inc.) C:\Program Files\Logitech\LogiOptions\LogiOptions.exe
(Logitech Inc -> Logitech, Inc.) C:\ProgramData\Logishrd\LogiOptions\Software\Current\LogiOptionsMgr.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\office15\ONENOTEM.EXE
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\office15\outlook.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_3.2110.13603.0_x64__8wekyb3d8bbwe\Cortana.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.721.12013.0_x64__8wekyb3d8bbwe\GameBar.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.721.12013.0_x64__8wekyb3d8bbwe\GameBarFTServer.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.YourPhone_1.21111.123.0_x64__8wekyb3d8bbwe\YourPhoneAppProxy\YourPhoneAppProxy.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.21102.11411.0_x64__8wekyb3d8bbwe\Music.UI.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\IESettingSync.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2110.6-0\MpCopyAccelerator.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2110.6-0\MsMpEng.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2110.6-0\NisSrv.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe <3>
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Wacom Technology Corp. -> Wacom Technology) C:\Program Files\Tablet\ISD\WacomHost.exe
(Wacom Technology Corporation -> Wacom Technology, Corp.) C:\Program Files\Tablet\ISD\ISD_Tablet.exe
(Wacom Technology Corporation -> Wacom Technology, Corp.) C:\Program Files\Tablet\ISD\ISD_TabletUser.exe
(Wacom Technology Corporation -> Wacom Technology, Corp.) C:\Program Files\Tablet\ISD\WTabletServiceISD.exe
(Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD App Manager\Plugins\WD Backup\App\WDBackupService.exe
(Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD App Manager\WDAppManager.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-10] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [3426560 2021-11-23] (Adobe Inc. -> Adobe Systems, Incorporated)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [18382824 2017-08-10] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1493992 2017-08-10] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_LENOVO_DOLBYDRAGON] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1493992 2017-08-10] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [iTunesHelper] => C:\Users\baile\Downloads\iTunesHelper.exe [340440 2021-04-16] (Apple Inc. -> Apple Inc.)
HKLM\...\Run: [LogiOptions] => C:\Program Files\Logitech\LogiOptions\LogiOptions.exe [1675680 2021-09-24] (Logitech Inc -> Logitech, Inc.)
HKLM\...\Run: [APP] => C:\Program Files\Dolby\Dolby DAX3\APP\DAX3TrayIcon.exe [999216 2017-04-28] (Dolby Laboratories, Inc. -> Dolby Laboratories, Inc.)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [3831808 2021-08-30] (Microsoft Windows Hardware Compatibility Publisher -> Logitech)
HKLM-x32\...\Run: [WDAppManager] => C:\Program Files (x86)\Western Digital\WD App Manager\AppManagerLauncher.exe [21888 2018-01-24] (Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.)
HKLM-x32\...\Run: [Polarr] => C:\ProgramData\SquirrelMachineInstalls\Polarr.exe [73300232 2020-06-16] (Polarr, Inc. -> Polarr, Inc.) [File not signed]
HKLM-x32\...\Run: [Fitbit Connect] => C:\Users\baile\Downloads\Fitbit Connect.exe [3414184 2015-09-11] (Fitbit, Inc. -> Fitbit, Inc.) [File not signed]
HKLM-x32\...\Run: [ExpressVPNNotificationService] => C:\Program Files (x86)\ExpressVPN\expressvpn-ui\ExpressVPNNotificationServiceStarter.exe [373600 2021-01-18] (Express Vpn LLC -> ExpressVPN)
HKU\S-1-5-21-260720292-2504253849-2348319339-1001\...\Run: [Fitbit Connect] => C:\Users\baile\Downloads\Fitbit Connect.exe [3414184 2015-09-11] (Fitbit, Inc. -> Fitbit, Inc.) [File not signed]
HKU\S-1-5-21-260720292-2504253849-2348319339-1001\...\Run: [Steam] => C:\Users\baile\New folder\steam.exe [3421984 2020-12-07] (Valve -> Valve Corporation)
HKU\S-1-5-21-260720292-2504253849-2348319339-1001\...\Run: [ExpressVPN4] => C:\Program Files (x86)\ExpressVPN\expressvpn-ui\ExpressVPN.exe [850272 2021-01-18] (Express Vpn LLC -> ExpressVPN)
HKU\S-1-5-21-260720292-2504253849-2348319339-1001\...\RunOnce: [Delete Cached Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\baile\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe"
HKU\S-1-5-21-260720292-2504253849-2348319339-1001\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\baile\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe"
HKU\S-1-5-21-260720292-2504253849-2348319339-1001\...\RunOnce: [Uninstall 21.220.1024.0005] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\baile\AppData\Local\Microsoft\OneDrive\21.220.1024.0005"
HKLM\...\Print\Monitors\HP 5912 Status Monitor: hpinksts5912LM.dll
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\96.0.4664.93\Installer\chrmstp.exe [2021-12-08] (Google LLC -> Google LLC)
Startup: C:\Users\baile\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk [2021-12-09]
ShortcutTarget: Send to OneNote.lnk -> C:\Program Files\Microsoft Office 15\root\office15\ONENOTEM.EXE (Microsoft Corporation -> Microsoft Corporation)
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {0E41EACB-602F-472D-A50B-BAC99EBC6892} - System32\Tasks\
AdobeAAMUpdater-1.0-MicrosoftAccount-baileyl032017@outlook.com => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-10] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
Task: {10D771B3-2D11-4309-B81F-F345B570E2B4} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\WINDOWS\Explorer.exe /NOUACCHECK
Task: {138C7D27-E8F7-45CF-824E-5382F35FB876} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2017-12-30] (Google Inc -> Google Inc.)
Task: {1F3D31A8-1D0B-47FF-8300-4DE9302035ED} - System32\Tasks\HPPSDrTelemetryWatch => C:\Program Files (x86)\HP\Diagnostics\TelemetryWatch\PSDrTelemetryWatch.exe [32808 2020-01-14] (HP Inc. -> )
Task: {20FDF483-B4A8-4CEF-A0DD-BFD065B5ED91} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2110.6-0\MpCmdRun.exe [901056 2021-11-02] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {25B126E2-E129-4B8C-A051-AE8F6C2AC12F} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2017-12-30] (Google Inc -> Google Inc.)
Task: {59866E19-5E2E-4586-9F79-52A3BD86C3B6} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2110.6-0\MpCmdRun.exe [901056 2021-11-02] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {75101032-CD10-4D65-928B-35A3A80C5829} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2110.6-0\MpCmdRun.exe [901056 2021-11-02] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {8B91E542-FE4C-432F-BF64-0EC991CA49A9} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2110.6-0\MpCmdRun.exe [901056 2021-11-02] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {90484D13-C697-40E3-9114-7AF344EA07BB} - System32\Tasks\AdobeGCInvoker-1.0 => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [3426560 2021-11-23] (Adobe Inc. -> Adobe Systems, Incorporated)
Task: {A9273BAF-7D29-4FA6-8AD5-DB9A00224729} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [972184 2021-03-17] (Microsoft Corporation -> Microsoft Corporation)
Task: {BBEF7351-1502-4175-AC87-4BAB29443B41} - \Agent Activation Runtime\S-1-5-21-260720292-2504253849-2348319339-1001 -> No File <==== ATTENTION
Task: {D7E912F0-CD6F-456B-A47A-42DCED783974} - System32\Tasks\AdobeAAMUpdater-1.0-YOGA720-15IKB-bailey => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-10] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
Task: {E631038B-2CFE-4CA4-9F1F-8732D0DFB9A8} - \Apple\AppleSoftwareUpdate -> No File <==== ATTENTION
Task: {EC6B61A4-0F42-49F5-83DA-B1C2D337B005} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [972184 2021-03-17] (Microsoft Corporation -> Microsoft Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{22bdf8f0-d55e-4cab-bdff-f39f79a367ff}: [NameServer] 10.186.0.1
Tcpip\..\Interfaces\{3c4a9f21-8085-4361-98eb-ab3060e81302}: [DhcpNameServer] 192.168.1.1
Edge:
=======
DownloadDir: C:\Users\baile\Downloads
Edge Notifications: HKU\S-1-5-21-260720292-2504253849-2348319339-1001 -> hxxps://gundersenhealthengage.mrcommunities.com
Edge DefaultProfile: Default
Edge Profile: C:\Users\baile\AppData\Local\Microsoft\Edge\User Data\Default [2021-12-13]
Edge HomePage: Default -> hxxp://www.google.com/
Edge StartupUrls: Default -> "hxxp://www.google.com/"
Edge Extension: (Honey) - C:\Users\baile\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\amnbcmdbanbkjhnfoeceemmmdiepnbpp [2021-12-04]
Edge Extension: (LastPass: Free Password Manager) - C:\Users\baile\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\bbcinlkgjjkejfdpemiealijmmooekmp [2021-12-04]
Edge Extension: (Grammarly for Microsoft Edge) - C:\Users\baile\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\cnlefmmeadmemmdciolhbnfeacpdfbkd [2021-12-10]
Edge Extension: (Fancy & Cool Text Generator) - C:\Users\baile\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\fafnphaopehepcmfnakggljonnhkofpk [2021-12-04]
Edge Extension: (Rakuten: Get Cash Back For Shopping) - C:\Users\baile\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\gmmlpenookphoknnpfilofakghemolmg [2021-12-04]
Edge HKLM-x32\...\Edge\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
FireFox:
========
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2017-12-20] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @parallelgraphics.com/Cortona -> C:\Program Files (x86)\Common Files\ParallelGraphics\Cortona\npcortona.dll [2019-09-12] (Parallel Graphics Limited -> ParallelGraphics)
FF Plugin HKU\S-1-5-21-260720292-2504253849-2348319339-1001: @rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5 -> C:\Users\baile\AppData\Roaming\Visan\plugins\npRLSecurePluginLayer.dll [2011-11-15] (RocketLife -> RocketLife, LLP)
FF Plugin HKU\S-1-5-21-260720292-2504253849-2348319339-1001: SkypeForBusinessPlugin-16.2 -> C:\Users\baile\AppData\Local\Microsoft\SkypeForBusinessPlugin\16.2.0.511\npGatewayNpapi.dll [2019-08-03] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin HKU\S-1-5-21-260720292-2504253849-2348319339-1001: SkypeForBusinessPlugin64-16.2 -> C:\Users\baile\AppData\Local\Microsoft\SkypeForBusinessPlugin\16.2.0.511\npGatewayNpapi-x64.dll [2019-08-03] (Microsoft Corporation -> Microsoft Corporation)
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\baile\AppData\Local\Google\Chrome\User Data\Default [2021-12-13]
CHR Notifications: Default -> hxxps://typiccor.com; hxxps://www.facebook.com; hxxps://www.youtube.com
CHR HomePage: Default -> file:///C:/Users/Owner/Documents/Medical
CHR StartupUrls: Default -> "hxxp://google.com/"
CHR Extension: (Slides) - C:\Users\baile\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-12-30]
CHR Extension: (Docs) - C:\Users\baile\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-12-30]
CHR Extension: (Google Drive) - C:\Users\baile\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-10-20]
CHR Extension: (YouTube) - C:\Users\baile\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-12-30]
CHR Extension: (Honey) - C:\Users\baile\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmnlcjabgnpnenekpadlanbbkooimhnj [2021-11-19]
CHR Extension: (Rakuten: Get Cash Back For Shopping) - C:\Users\baile\AppData\Local\Google\Chrome\User Data\Default\Extensions\chhjbpecpncaggjpdakmflnfcopglcmi [2021-11-18]
CHR Extension: (Netflix) - C:\Users\baile\AppData\Local\Google\Chrome\User Data\Default\Extensions\deceagebecbceejblnlcjooeohmmeldh [2017-12-30]
CHR Extension: (Sheets) - C:\Users\baile\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-12-30]
CHR Extension: (Google Docs Offline) - C:\Users\baile\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2021-11-30]
CHR Extension: (LastPass: Free Password Manager) - C:\Users\baile\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd [2021-11-25]
CHR Extension: (Malwarebytes Browser Guard) - C:\Users\baile\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihcjicgdanjaechkgeegckofjjedodee [2021-11-24]
CHR Extension: (Grammarly for Chrome) - C:\Users\baile\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbfnbcaeplbcioakkpcpgfkobkghlhen [2021-12-05]
CHR Extension: (Capital One Shopping: Add to Chrome for Free) - C:\Users\baile\AppData\Local\Google\Chrome\User Data\Default\Extensions\nenlahapcbofgnanklpelkaejcehkggg [2021-12-07]
CHR Extension: (Chrome Web Store Payments) - C:\Users\baile\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-28]
CHR Extension: (Gmail) - C:\Users\baile\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-10-22]
CHR Profile: C:\Users\baile\AppData\Local\Google\Chrome\User Data\Guest Profile [2020-08-15]
CHR Profile: C:\Users\baile\AppData\Local\Google\Chrome\User Data\System Profile [2020-08-15]
CHR HKLM-x32\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AGMService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [3849472 2021-11-23] (Adobe Inc. -> Adobe Systems, Incorporated)
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [3617024 2021-11-23] (Adobe Inc. -> Adobe Systems, Incorporated)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [99104 2021-03-16] (Apple Inc. -> Apple Inc.)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [8473200 2019-06-09] (BattlEye Innovations e.K. -> )
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [3052952 2021-03-17] (Microsoft Corporation -> Microsoft Corporation)
R2 Dolby DAX API Service; C:\Program Files\Dolby\Dolby DAX3\API\DAX3API.exe [212784 2017-04-28] (Dolby Laboratories, Inc. -> )
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [803440 2019-06-09] (EasyAntiCheat Oy -> EasyAntiCheat Ltd)
R2 ExpressVPNService; C:\Program Files (x86)\ExpressVPN\bootstrap\amd64\nssm.exe [437088 2021-01-18] (Express Vpn LLC -> ExpressVPN)
R2 HPPrintScanDoctorService; C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe [299680 2021-11-01] (HP Inc. -> HP Inc.)
S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [7848632 2021-11-07] (Malwarebytes Inc -> Malwarebytes)
S3 WD Backup Drive Helper; C:\WINDOWS\SysWOW64\dllhost.exe /Processid:{4AB831D3-8315-414C-8A7A-303105288D0B} [19256 2021-10-06] (Microsoft Windows -> Microsoft Corporation)
S3 WD Backup Snapshot; C:\WINDOWS\SysWOW64\dllhost.exe /Processid:{302480DF-3AC5-4400-BE7B-DD77AF93B6DD} [19256 2021-10-06] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2110.6-0\NisSrv.exe [2872024 2021-11-02] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2110.6-0\MsMpEng.exe [128376 2021-11-02] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 aftap0901; C:\WINDOWS\System32\drivers\aftap0901.sys [48624 2018-03-06] (AnchorFree Inc -> The OpenVPN Project)
S3 expressvpnsplittunnel; C:\Program Files (x86)\ExpressVPN\splittunnel\expressvpnsplittunnel.sys [37024 2021-01-18] (ExprsVPN LLC -> ExpressVPN)
R3 expressvpnwintun; C:\WINDOWS\System32\drivers\expressvpn-wintun.sys [46824 2021-01-18] (Express VPN International Ltd. -> ExpressVPN)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [19912 2020-12-27] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
S3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [248992 2021-11-07] (Malwarebytes Inc -> Malwarebytes)
S3 Netaapl; C:\WINDOWS\System32\drivers\netaapl64.sys [23040 2017-11-27] (Microsoft Windows Hardware Compatibility Publisher -> Apple Inc.)
R3 tap0901; C:\WINDOWS\System32\drivers\tap0901.sys [39040 2018-08-15] (GZ Systems Limited -> The OpenVPN Project)
R3 tapexpressvpn; C:\WINDOWS\System32\drivers\tapexpressvpn.sys [52904 2021-01-18] (ExprsVPN LLC -> The OpenVPN Project)
S3 USBAAPL64; C:\WINDOWS\System32\Drivers\usbaapl64.sys [54784 2017-11-27] (Microsoft Windows Hardware Compatibility Publisher -> Apple, Inc.)
R3 WacHidRouterISD; C:\WINDOWS\system32\DRIVERS\wachidrouter_isd.sys [142424 2017-05-24] (Wacom Technology Corporation -> Wacom Technology, Corp.)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [48520 2021-11-02] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WDC_SAM; C:\WINDOWS\System32\drivers\wdcsam64.sys [26880 2015-11-12] (WDKTestCert wdclab,130885612892544312 -> Western Digital Technologies, Inc.)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [435424 2021-11-02] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [86240 2021-11-02] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-12-13 02:21 - 2021-12-13 02:22 - 000024680 _____ C:\Users\baile\Desktop\FRST.txt
2021-12-12 23:08 - 2021-12-12 23:08 - 000003588 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-260720292-2504253849-2348319339-1001
2021-12-12 13:58 - 2021-12-12 13:59 - 000001299 _____ C:\Users\baile\Desktop\Fixlog.txt
2021-12-12 11:01 - 2021-12-12 11:01 - 000000166 _____ C:\Users\baile\Desktop\fix.reg
2021-12-11 23:14 - 2021-12-11 23:14 - 000000000 ____D C:\Users\baile\Documents\My Media
2021-12-11 00:13 - 2021-12-11 00:13 - 000003386 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore1d7eac7dfec1a48
2021-12-10 22:03 - 2021-12-10 22:03 - 000000000 ____D C:\Users\baile\Documents\New folder
2021-12-07 09:55 - 2021-12-07 09:55 - 000000000 ____D C:\Users\baile\AppData\Local\TempTaskUpdateDetection571071D5-D41E-4820-80EE-1A7417AC8614
2021-12-06 13:33 - 2021-12-06 11:41 - 000000000 ____D C:\Windows.old
2021-12-06 12:40 - 2021-12-12 01:04 - 000000000 ____D C:\Users\baile\Desktop\FRST-OlderVersion
2021-12-06 11:44 - 2021-12-12 14:07 - 000840598 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2021-12-06 11:43 - 2021-12-06 11:43 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2021-12-06 11:41 - 2021-12-12 23:08 - 000003376 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-260720292-2504253849-2348319339-1001
2021-12-06 11:41 - 2021-12-12 22:24 - 000004164 _____ C:\WINDOWS\system32\Tasks\User_Feed_Synchronization-{B393C7FE-B95B-48A2-8819-C5B1623E23B2}
2021-12-06 11:41 - 2021-12-12 13:59 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2021-12-06 11:41 - 2021-12-11 00:13 - 000003480 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2021-12-06 11:41 - 2021-12-10 14:45 - 000003522 _____ C:\WINDOWS\system32\Tasks\AdobeGCInvoker-1.0
2021-12-06 11:41 - 2021-12-07 09:56 - 000000000 ____D C:\WINDOWS\system32\Tasks\Intel
2021-12-06 11:41 - 2021-12-06 11:41 - 000003348 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2021-12-06 11:41 - 2021-12-06 11:41 - 000003184 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2021-12-06 11:41 - 2021-12-06 11:41 - 000003124 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2021-12-06 11:41 - 2021-12-06 11:41 - 000002858 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-260720292-2504253849-2348319339-1003
2021-12-06 11:41 - 2021-12-06 11:41 - 000002848 _____ C:\WINDOWS\system32\Tasks\HPPSDrTelemetryWatch
2021-12-06 11:41 - 2021-12-06 11:41 - 000002814 _____ C:\WINDOWS\system32\Tasks\
AdobeAAMUpdater-1.0-MicrosoftAccount-baileyl032017@outlook.com
2021-12-06 11:41 - 2021-12-06 11:41 - 000002770 _____ C:\WINDOWS\system32\Tasks\AdobeAAMUpdater-1.0-YOGA720-15IKB-bailey
2021-12-06 11:41 - 2021-12-06 11:41 - 000002768 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task v2
2021-12-06 11:41 - 2021-12-06 11:41 - 000002588 _____ C:\WINDOWS\system32\Tasks\CreateExplorerShellUnelevatedTask
2021-12-06 11:41 - 2021-12-06 11:41 - 000000020 ___SH C:\Users\baile\ntuser.ini
2021-12-06 11:41 - 2021-12-06 11:41 - 000000000 ____D C:\WINDOWS\system32\Tasks\S-1-5-21-260720292-2504253849-2348319339-1001
2021-12-06 11:40 - 2021-12-06 11:41 - 000007623 _____ C:\WINDOWS\diagwrn.xml
2021-12-06 11:40 - 2021-12-06 11:41 - 000007623 _____ C:\WINDOWS\diagerr.xml
2021-12-06 11:35 - 2021-12-06 11:35 - 000001087 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wacom Pen.lnk
2021-12-06 11:35 - 2021-12-06 11:35 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dolby
2021-12-06 11:35 - 2021-12-06 11:35 - 000000000 ____D C:\Program Files\Dolby
2021-12-06 11:35 - 2021-12-06 11:35 - 000000000 ____D C:\Program Files\Common Files\Dolby
2021-12-06 11:35 - 2017-09-18 05:22 - 000140312 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.DLL
2021-12-06 11:35 - 2017-09-18 05:22 - 000116760 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.DLL
2021-12-06 11:34 - 2021-12-12 23:42 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2021-12-06 11:34 - 2021-12-06 11:34 - 000442704 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2021-12-06 11:19 - 2021-12-06 13:33 - 000000000 ____D C:\WINDOWS\system32\config\bbimigrate
2021-12-06 11:18 - 2021-12-12 23:08 - 000002386 _____ C:\Users\baile\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2021-12-06 11:18 - 2021-12-06 11:41 - 000000000 ____D C:\Users\baile
2021-12-06 11:16 - 2021-12-06 11:19 - 000000000 ____D C:\WINDOWS\ServiceProfiles
2021-12-06 11:11 - 2021-12-06 11:11 - 000272384 _____ C:\WINDOWS\system32\TpmTool.exe
2021-12-06 11:11 - 2021-12-06 11:11 - 000223744 _____ C:\WINDOWS\SysWOW64\TpmTool.exe
2021-12-06 11:11 - 2021-12-06 11:11 - 000060928 _____ C:\WINDOWS\system32\runexehelper.exe
2021-12-06 11:11 - 2021-12-06 11:11 - 000011363 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim
2021-12-06 11:05 - 2019-10-15 13:53 - 000076060 _____ C:\WINDOWS\system32\xpsrchvw.xml
2021-12-06 11:05 - 2019-04-18 18:49 - 000076060 _____ C:\WINDOWS\SysWOW64\xpsrchvw.xml
2021-12-06 11:04 - 2021-12-06 13:33 - 000000000 ____D C:\WINDOWS\IAStorAfsService
2021-12-06 11:04 - 2021-12-06 11:04 - 000000000 ____D C:\Program Files\Reference Assemblies
2021-12-06 11:04 - 2021-12-06 11:04 - 000000000 ____D C:\Program Files\MSBuild
2021-12-06 11:04 - 2021-12-06 11:04 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies
2021-12-06 11:04 - 2021-12-06 11:04 - 000000000 ____D C:\Program Files (x86)\MSBuild
2021-12-06 10:59 - 2021-12-06 10:59 - 000008192 _____ C:\WINDOWS\system32\config\userdiff
2021-12-06 03:09 - 2021-12-06 11:41 - 000000000 ___DC C:\WINDOWS\Panther
2021-12-06 03:04 - 2021-12-06 03:08 - 000000000 ____D C:\ESD
2021-12-06 03:03 - 2021-12-06 03:03 - 000000000 ___HD C:\$Windows.~WS
2021-12-04 05:50 - 2021-12-04 05:50 - 008540344 _____ (Malwarebytes) C:\Users\baile\Desktop\AdwCleaner.exe
2021-12-03 03:18 - 2021-12-03 03:18 - 000048251 _____ C:\Users\baile\AppData\LocalLow\wbkF666.tmp
2021-12-03 03:17 - 2021-12-08 02:14 - 000000000 ____D C:\Users\baile\Documents\Stem Cells
2021-12-01 22:14 - 2021-12-12 01:04 - 002311168 _____ (Farbar) C:\Users\baile\Desktop\FRST64.exe
2021-12-01 22:12 - 2021-12-01 22:12 - 000064513 _____ C:\Users\baile\Desktop\frst.htm
2021-12-01 21:51 - 2021-12-01 21:55 - 002311680 _____ (Farbar) C:\Users\baile\Downloads\FRST64.exe
2021-11-30 05:32 - 2021-11-30 05:32 - 000001942 _____ C:\Users\baile\Desktop\PC Health Check.lnk
2021-11-30 05:32 - 2021-11-30 05:32 - 000001352 _____ C:\Users\baile\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC Health Check.lnk
2021-11-30 05:32 - 2021-11-30 05:32 - 000000000 ___RD C:\Users\baile\AppData\Local\PCHealthCheck
2021-11-30 05:31 - 2021-11-30 05:31 - 014233600 _____ C:\Users\baile\Downloads\WindowsPCHealthCheckSetup.msi
2021-11-29 17:54 - 2021-11-29 17:54 - 000000000 ____D C:\Users\baile\AppData\Local\LogiBolt
2021-11-29 17:53 - 2021-12-06 13:33 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech
2021-11-29 17:53 - 2021-12-06 13:33 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logi
2021-11-29 17:53 - 2021-11-29 17:54 - 000000000 ____D C:\ProgramData\Logishrd
2021-11-29 17:53 - 2021-11-29 17:53 - 000000000 ____D C:\Users\baile\AppData\Roaming\Logishrd
2021-11-29 17:53 - 2021-11-29 17:53 - 000000000 ____D C:\Program Files\Logitech
2021-11-29 17:53 - 2021-11-29 17:53 - 000000000 ____D C:\Program Files\Logi
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-12-13 02:21 - 2020-08-05 03:17 - 000000000 ____D C:\FRST
2021-12-13 02:12 - 2017-12-20 15:47 - 000000000 ____D C:\Users\baile\Documents\Outlook Files
2021-12-13 02:00 - 2017-12-20 00:53 - 000000000 ____D C:\Users\baile\AppData\Local\Adobe
2021-12-13 01:50 - 2019-12-07 03:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2021-12-13 01:27 - 2017-12-30 22:57 - 000000000 ____D C:\Program Files (x86)\Google
2021-12-12 23:44 - 2018-04-24 19:10 - 000000000 ____D C:\Users\baile\Documents\Amazon
2021-12-12 22:25 - 2019-10-01 20:08 - 000000000 ___HD C:\Users\Public\Documents\AdobeGCData
2021-12-12 22:03 - 2019-03-11 01:04 - 000000000 ____D C:\Users\baile\Documents\Kitchen
2021-12-12 19:20 - 2018-01-05 00:17 - 000000000 ____D C:\Users\baile\Documents\Dog Information
2021-12-12 14:07 - 2019-12-07 03:13 - 000000000 ____D C:\WINDOWS\INF
2021-12-12 13:59 - 2020-06-17 16:53 - 000008192 ___SH C:\DumpStack.log.tmp
2021-12-12 13:59 - 2019-12-07 03:14 - 000000000 ____D C:\WINDOWS\ServiceState
2021-12-12 13:59 - 2019-12-07 03:03 - 001048576 _____ C:\WINDOWS\system32\config\BBI
2021-12-12 11:25 - 2019-12-07 03:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2021-12-12 11:05 - 2020-06-18 10:02 - 000000000 ____D C:\WINDOWS\Lenovo
2021-12-12 11:05 - 2017-11-09 18:26 - 000000000 ____D C:\ProgramData\Lenovo
2021-12-12 09:56 - 2020-06-26 02:38 - 000002445 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2021-12-12 09:56 - 2020-06-26 02:38 - 000002283 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2021-12-12 09:56 - 2019-12-07 03:14 - 000000000 ___HD C:\Program Files\WindowsApps
2021-12-11 00:13 - 2021-01-23 13:37 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
2021-12-10 19:34 - 2019-12-07 03:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2021-12-10 01:31 - 2018-02-12 23:29 - 000000000 ____D C:\Users\baile\Documents\Recipies
2021-12-08 21:04 - 2020-07-13 22:29 - 000002267 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2021-12-08 21:04 - 2017-12-30 22:58 - 000002308 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2021-12-08 04:08 - 2019-12-07 03:14 - 000000000 ____D C:\WINDOWS\appcompat
2021-12-07 09:59 - 2019-12-07 03:14 - 000000000 ____D C:\WINDOWS\system32\NDF
2021-12-06 14:04 - 2017-12-19 21:12 - 000000000 ____D C:\Users\baile\AppData\Local\Packages
2021-12-06 13:52 - 2019-06-21 12:20 - 000000000 ____D C:\Users\baile\Documents\Social Security
2021-12-06 13:33 - 2021-04-26 13:56 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2021-12-06 13:33 - 2020-11-26 14:07 - 000000000 ____D C:\Users\baile\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Zoom
2021-12-06 13:33 - 2020-11-24 15:24 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2021-12-06 13:33 - 2020-08-01 00:51 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fitbit Connect
2021-12-06 13:33 - 2020-07-05 21:02 - 000000000 ____D C:\Users\baile\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GitHub, Inc
2021-12-06 13:33 - 2020-03-28 21:56 - 000000000 ____D C:\Users\baile\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
2021-12-06 13:33 - 2019-12-07 03:14 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template
2021-12-06 13:33 - 2019-12-07 03:14 - 000000000 __RHD C:\Users\Public\Libraries
2021-12-06 13:33 - 2019-12-07 03:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2021-12-06 13:33 - 2019-12-07 03:14 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
2021-12-06 13:33 - 2019-12-07 03:14 - 000000000 ____D C:\WINDOWS\system32\Tasks_Migrated
2021-12-06 13:33 - 2019-12-07 03:14 - 000000000 ____D C:\WINDOWS\system32\spool
2021-12-06 13:33 - 2019-12-07 03:14 - 000000000 ____D C:\WINDOWS\system32\Macromed
2021-12-06 13:33 - 2019-12-07 03:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2021-12-06 13:33 - 2019-12-07 03:14 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2021-12-06 13:33 - 2019-06-18 10:29 - 000000000 ____D C:\Program Files\UNP
2021-12-06 13:33 - 2018-12-29 22:02 - 000000000 ____D C:\Users\baile\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2021-12-06 13:33 - 2018-11-28 18:21 - 000000000 ____D C:\Users\baile\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Grammarly
2021-12-06 13:33 - 2018-09-15 01:33 - 000000000 ____D C:\WINDOWS\system32\MsDtc
2021-12-06 13:33 - 2018-05-18 20:26 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wacom Tablet
2021-12-06 13:33 - 2018-04-12 03:19 - 000000000 ____D C:\WINDOWS\SysWOW64\gd-GB
2021-12-06 13:33 - 2018-01-13 00:06 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OverDrive for Windows
2021-12-06 13:33 - 2017-12-20 16:49 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2021-12-06 13:33 - 2017-12-20 01:08 - 000000000 ____D C:\ProgramData\regid.1986-12.com.adobe
2021-12-06 13:33 - 2017-11-09 18:43 - 000000000 ____D C:\Program Files\Tablet
2021-12-06 13:33 - 2017-11-09 18:41 - 000000000 ____D C:\Program Files\Intel
2021-12-06 12:39 - 2017-12-20 00:25 - 000000000 ____D C:\Users\baile\AppData\Local\PlaceholderTileLogoFolder
2021-12-06 11:57 - 2019-12-07 03:14 - 000000000 ___RD C:\WINDOWS\PrintDialog
2021-12-06 11:41 - 2019-12-07 03:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2021-12-06 11:41 - 2019-12-07 03:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2021-12-06 11:41 - 2019-12-07 03:14 - 000000000 ____D C:\Program Files\Windows Defender
2021-12-06 11:41 - 2019-12-07 03:03 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2021-12-06 11:41 - 2017-12-19 21:41 - 000000000 ___RD C:\Users\baile\3D Objects
2021-12-06 11:41 - 2017-03-23 11:27 - 000000000 __RHD C:\Users\Public\AccountPictures
2021-12-06 11:38 - 2019-12-07 03:14 - 000000000 __RSD C:\WINDOWS\Media
2021-12-06 11:38 - 2019-12-07 03:14 - 000000000 ____D C:\WINDOWS\Registration
2021-12-06 11:38 - 2017-12-19 21:14 - 000027280 _____ C:\WINDOWS\system32\emptyregdb.dat
2021-12-06 11:35 - 2019-12-07 03:14 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2021-12-06 11:35 - 2017-11-09 18:43 - 000312687 _____ C:\WINDOWS\system32\Drivers\rtkhdasetting.zip
2021-12-06 11:35 - 2017-11-09 18:43 - 000000000 ____D C:\WINDOWS\system32\DAX3
2021-12-06 11:35 - 2017-11-09 18:43 - 000000000 ____D C:\WINDOWS\system32\DAX2
2021-12-06 11:35 - 2017-11-09 18:42 - 000000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2021-12-06 11:33 - 2019-12-07 03:18 - 000000000 ____D C:\WINDOWS\Setup
2021-12-06 11:30 - 2019-12-07 03:14 - 000000000 ____D C:\ProgramData\USOPrivate
2021-12-06 11:19 - 2020-01-12 00:04 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WD Discovery
2021-12-06 11:19 - 2019-12-07 03:14 - 000000000 ____D C:\WINDOWS\Resources
2021-12-06 11:19 - 2017-11-09 18:43 - 000000000 ____D C:\WINDOWS\system32\Intel
2021-12-06 11:19 - 2017-11-09 18:42 - 000000000 ____D C:\Program Files\Realtek
2021-12-06 11:14 - 2019-12-07 03:14 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2021-12-06 11:14 - 2019-12-07 03:14 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2021-12-06 11:14 - 2019-12-07 03:14 - 000000000 ____D C:\WINDOWS\SysWOW64\lv-LV
2021-12-06 11:14 - 2019-12-07 03:14 - 000000000 ____D C:\WINDOWS\SysWOW64\lt-LT
2021-12-06 11:14 - 2019-12-07 03:14 - 000000000 ____D C:\WINDOWS\SysWOW64\et-EE
2021-12-06 11:14 - 2019-12-07 03:14 - 000000000 ____D C:\WINDOWS\SysWOW64\es-MX
2021-12-06 11:14 - 2019-12-07 03:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2021-12-06 11:14 - 2019-12-07 03:14 - 000000000 ____D C:\WINDOWS\SystemResources
2021-12-06 11:14 - 2019-12-07 03:14 - 000000000 ____D C:\WINDOWS\system32\setup
2021-12-06 11:14 - 2019-12-07 03:14 - 000000000 ____D C:\WINDOWS\system32\lv-LV
2021-12-06 11:14 - 2019-12-07 03:14 - 000000000 ____D C:\WINDOWS\system32\lt-LT
2021-12-06 11:14 - 2019-12-07 03:14 - 000000000 ____D C:\WINDOWS\system32\et-EE
2021-12-06 11:14 - 2019-12-07 03:14 - 000000000 ____D C:\WINDOWS\system32\es-MX
2021-12-06 11:14 - 2019-12-07 03:14 - 000000000 ____D C:\WINDOWS\system32\Dism
2021-12-06 11:14 - 2019-12-07 03:14 - 000000000 ____D C:\WINDOWS\ShellExperiences
2021-12-06 11:14 - 2019-12-07 03:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2021-12-06 11:14 - 2019-12-07 03:03 - 000000000 ____D C:\WINDOWS\servicing
2021-12-04 18:50 - 2018-04-09 19:37 - 000000000 ____D C:\Users\baile\Documents\Purchases off Internet
2021-12-04 18:47 - 2018-04-29 19:25 - 000000000 ____D C:\Users\baile\Documents\Mom and Dad
2021-12-04 18:45 - 2018-10-16 22:39 - 000000000 ____D C:\Users\baile\Documents\Ricki Lowe
2021-12-04 18:43 - 2018-08-10 22:37 - 000000000 ____D C:\Users\baile\Documents\Politics
2021-12-04 18:42 - 2018-01-30 22:07 - 000000000 ____D C:\Users\baile\Documents\Insurance
2021-12-04 18:40 - 2018-03-31 18:25 - 000000000 ____D C:\Users\baile\Documents\Margie Birthday
2021-12-04 18:37 - 2019-10-15 21:06 - 000000000 ____D C:\Users\baile\Documents\Medicare
2021-12-04 18:36 - 2021-06-02 20:30 - 000000000 ____D C:\Users\baile\Documents\Fax
2021-12-04 18:34 - 2018-01-05 00:16 - 000000000 ____D C:\Users\baile\Documents\Crafts
2021-12-04 18:33 - 2018-01-05 00:16 - 000000000 ____D C:\Users\baile\Documents\Computer
2021-12-04 18:30 - 2018-01-07 19:34 - 000000000 ____D C:\Users\baile\Documents\Camping
2021-12-04 18:27 - 2018-01-05 00:16 - 000000000 ____D C:\Users\baile\Documents\Cabin Oct 2017
2021-12-04 18:24 - 2018-01-13 01:01 - 000000000 ____D C:\Users\baile\Documents\Boat
2021-12-04 18:23 - 2021-01-17 14:59 - 000000000 ____D C:\Users\baile\Documents\Barrett Cook Book
2021-12-04 18:23 - 2018-02-12 18:35 - 000000000 ____D C:\Users\baile\Documents\Bank of America
2021-12-04 18:13 - 2020-12-04 00:11 - 000000000 ____D C:\ProgramData\Luminar 4
2021-12-04 05:34 - 2020-08-12 21:25 - 000000000 ____D C:\Users\baile\AppData\LocalLow\Temp
2021-12-02 01:34 - 2018-05-05 14:45 - 000000000 ____D C:\Users\baile\Documents\Pam
2021-12-01 21:58 - 2020-08-05 03:18 - 000039246 _____ C:\Users\baile\Downloads\Addition.txt
2021-12-01 21:58 - 2020-08-05 03:17 - 000042236 _____ C:\Users\baile\Downloads\FRST.txt
2021-11-28 20:30 - 2020-01-16 21:03 - 000000000 ____D C:\Users\baile\Documents\2020 Calif Trip
2021-11-28 20:30 - 2018-01-05 00:16 - 000000000 ____D C:\Users\baile\Documents\2 Pam Health Savings Account
2021-11-26 23:41 - 2018-04-10 00:41 - 000000000 ____D C:\Users\baile\Documents\Battle Pirates
2021-11-26 23:01 - 2018-06-21 03:36 - 000000000 ____D C:\Users\baile\AppData\Local\CrashDumps
2021-11-26 22:39 - 2020-12-20 18:18 - 000000000 ____D C:\Users\baile\Documents\Christmas
2021-11-25 21:02 - 2018-01-05 00:17 - 000000000 ____D C:\Users\baile\Documents\Verizon
2021-11-19 13:49 - 2018-06-17 15:34 - 000000000 ____D C:\ProgramData\Packages
2021-11-19 03:34 - 2017-12-20 16:49 - 000000000 ____D C:\Program Files\Microsoft Office 15
2021-11-17 16:36 - 2018-05-27 12:01 - 000000000 ____D C:\Users\baile\Documents\DNR Licenses
==================== Files in the root of some directories ========
2018-09-25 22:03 - 2018-09-25 22:03 - 000000000 _____ () C:\Users\baile\AppData\Local\oobelibMkey.log
2019-08-09 16:03 - 2019-08-09 16:03 - 000000017 _____ () C:\Users\baile\AppData\Local\resmon.resmoncfg
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================