Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Spora- Still opening in Edge/IE


  • This topic is locked This topic is locked
12 replies to this topic

#1 csquared

csquared

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:09:07 PM

Posted 16 February 2017 - 12:56 PM

Got Spora, ended up paying for encryption. Have run MalwareBytes, Zemana AntiMalware and AVG and unable to find anything but Edge opens with the ransomware screen  whenever I turn on computer. 
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 15-02-2017 02
Ran by Carol (administrator) on CHU (16-02-2017 10:18:33)
Running from C:\Users\Carol\Downloads
Loaded Profiles: Carol (Available Profiles: Carol & Administrator)
Platform: Windows 10 Home Version 1607 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Edge)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(SurfRight B.V.) C:\Program Files\HitmanPro\hmpsched.exe
(Intel® Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe
(www.shadowexplorer.com) C:\Program Files (x86)\ShadowExplorer\sesvc.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Copyright 2017.) C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Acer Cloud Technology) C:\Program Files (x86)\Acer\AOP Framework\acer\ccd.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler64.exe
(Acer Incorporated) C:\Users\Carol\AppData\Local\clear.fi\Docs\abDocsSetup.exe
(Acer Incorporated) C:\Windows\Temp\7zS3DE.tmp\AcerDocsSetup.exe
(Acer Incorporated) C:\Windows\Temp\7zS3DE.tmp\AcerDocs.exe
(Karlis Blumentals) C:\Program Files (x86)\Rapid PHP 2014\rapidphp.exe
(TODO: <Company name>) C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(acer) C:\Program Files\Acer\User Experience Improvement Program\Framework\UBTService.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\AVGSvc.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\x64\aswidsagenta.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
() C:\Windows\System32\igfxTray.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.105.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Copyright 2017.) C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avguix.exe
(Spotify Ltd) C:\Users\Carol\AppData\Roaming\Spotify\SpotifyWebHelper.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.11.500\SSScheduler.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\AVGUI.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
 
==================== Registry (Whitelisted) ====================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13885696 2015-06-24] (Realtek Semiconductor)
HKLM\...\Run: [IgfxTray] => C:\Windows\system32\igfxtray.exe [401896 2016-11-01] ()
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [557768 2014-10-14] (Adobe Systems Incorporated)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169768 2015-04-06] (Apple Inc.)
HKLM\...\Run: [ZAM] => C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe [14416624 2017-02-02] (Copyright 2017.)
HKLM\...\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe [239672 2017-01-09] (AVG Technologies CZ, s.r.o.)
HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [2780112 2017-01-20] (Malwarebytes)
HKLM-x32\...\Run: [BacKGround Agent] => C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe [62208 2014-11-17] (Acer Incorporated)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2015-05-15] (Apple Inc.)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2694320 2015-01-07] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [596504 2016-06-16] (Oracle Corporation)
HKLM-x32\...\Run: [AVGUI.exe] => C:\Program Files (x86)\AVG\Antivirus\AVGUI.exe [9523496 2017-02-16] (AVG Technologies CZ, s.r.o.)
HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe
HKU\AvGeneric_S-1-5-21-1893927633-78115024-1840190309-500\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [516608 2016-07-16] (Microsoft Corporation)
HKU\S-1-5-21-1893927633-78115024-1840190309-1001\...\Run: [msnmsgr] => C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe [4272840 2014-03-31] (Microsoft Corporation)
HKU\S-1-5-21-1893927633-78115024-1840190309-1001\...\Run: [Google Update] => C:\Users\Carol\AppData\Local\Google\Update\1.3.32.7\GoogleUpdateCore.exe [601752 2016-12-16] (Google Inc.)
HKU\S-1-5-21-1893927633-78115024-1840190309-1001\...\Run: [Spotify Web Helper] => C:\Users\Carol\AppData\Roaming\Spotify\SpotifyWebHelper.exe [1433712 2016-12-05] (Spotify Ltd)
ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2014-12-19] ()
ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2014-12-19] ()
ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2014-12-19] ()
ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ShellIconOverlayIdentifiers: [ACloudSyncedRF] -> {5CCE71FA-9F61-4F24-9CD1-98D819B40D68} => C:\Program Files (x86)\Acer\Acer Portal\x64\shellext_win.dll [2014-11-19] (Acer Incorporated)
ShellIconOverlayIdentifiers: [ACloudSyncedSF] -> {5D5F18B7-D59B-4B18-A3E9-0A4BDCCCB699} => C:\Program Files (x86)\Acer\Acer Portal\x64\shellext_win.dll [2014-11-19] (Acer Incorporated)
ShellIconOverlayIdentifiers: [ACloudSyncing] -> {C1E1456F-C2D8-4C96-870D-35F1E13941EE} => C:\Program Files (x86)\Acer\Acer Portal\x64\shellext_win.dll [2014-11-19] (Acer Incorporated)
ShellIconOverlayIdentifiers: [ACloudToBeSynced] -> {307523FA-DDC0-4068-983F-2A6B34627744} => C:\Program Files (x86)\Acer\Acer Portal\x64\shellext_win.dll [2014-11-19] (Acer Incorporated)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2017-02-05]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.500\SSScheduler.exe (McAfee, Inc.)
Startup: C:\Users\Carol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CA9FD-43XXH-ETGGH-TXATX-GHZTO-AFRGT-XFGOY.html [2017-02-14] ()
Startup: C:\Users\Carol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk [2016-06-24]
ShortcutTarget: Send to OneNote.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE (Microsoft Corporation)
GroupPolicy: Restriction - Chrome <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{090c0ac6-bc0f-44ee-b59b-1eae0e992a82}: [DhcpNameServer] 192.168.43.1
Tcpip\..\Interfaces\{80d0df59-bbe0-4a63-aade-8e3e25db8589}: [DhcpNameServer] 192.168.1.1
 
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\AvGeneric_S-1-5-21-1893927633-78115024-1840190309-500\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://acer13.msn.com/?pc=ACJB
HKU\AvGeneric_S-1-5-21-1893927633-78115024-1840190309-500\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer13.msn.com/?pc=ACJB
HKU\S-1-5-21-1893927633-78115024-1840190309-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-1893927633-78115024-1840190309-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer13.msn.com/?pc=ACJB
SearchScopes: HKLM-x32 -> {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://ca.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms}
SearchScopes: HKU\S-1-5-21-1893927633-78115024-1840190309-1001 -> DefaultScope {BC878E6E-1C7F-4F71-BDB2-ADD6EE8D70B1} URL = 
SearchScopes: HKU\S-1-5-21-1893927633-78115024-1840190309-1001 -> {BC878E6E-1C7F-4F71-BDB2-ADD6EE8D70B1} URL = 
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2016-12-28] (Microsoft Corporation)
BHO: saver box -> {8dce820a-a9c0-4902-b025-3a7827ae6806} -> C:\ProgramData\saver box\YsdWAKPBFAr6I5.x64.dll => No File
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-04-26] (Google Inc.)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2016-12-28] (Microsoft Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2016-12-28] (Microsoft Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\ssv.dll [2016-06-25] (Oracle Corporation)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-04-26] (Google Inc.)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2016-12-28] (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\jp2ssv.dll [2016-06-25] (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-04-26] (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-04-26] (Google Inc.)
Toolbar: HKU\S-1-5-21-1893927633-78115024-1840190309-1001 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-04-26] (Google Inc.)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-12-28] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-12-28] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-12-28] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-12-28] (Microsoft Corporation)
 
FireFox:
========
FF DefaultProfile: pqtgs6mb.default-1417400995430
FF ProfilePath: C:\Users\Carol\AppData\Roaming\Mozilla\Firefox\Profiles\pqtgs6mb.default-1417400995430 [2017-02-16]
FF NetworkProxy: Mozilla\Firefox\Profiles\pqtgs6mb.default-1417400995430 -> type", 0
FF Extension: (MediaHint) - C:\Users\Carol\AppData\Roaming\Mozilla\Firefox\Profiles\pqtgs6mb.default-1417400995430\Extensions\firefox@mediahint.com.xpi [2016-04-03]
FF Extension: (ZenMate Security, Privacy & Unblock VPN) - C:\Users\Carol\AppData\Roaming\Mozilla\Firefox\Profiles\pqtgs6mb.default-1417400995430\Extensions\firefox@zenmate.com.xpi [2016-08-28]
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK => not found
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_24_0_0_221.dll [2017-02-15] ()
FF Plugin: @mcafee.com/MSC,version=10 -> C:\Program Files\mcafee\msc\npMcSnFFPl64.dll [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect_x86_64 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2015-01-07] (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWoW64\Macromed\Flash\NPSWF32_24_0_0_221.dll [2017-02-15] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2015-10-13] (Google, Inc.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-08-19] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-08-19] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.91.2 -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\dtplugin\npDeployJava1.dll [2016-06-25] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.91.2 -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\plugin2\npjp2.dll [2016-06-25] (Oracle Corporation)
FF Plugin-x32: @mcafee.com/MSC,version=10 -> C:\Program Files (x86)\McAfee\msc\npMcSnFFPl.dll [No File]
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2016-12-28] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2016-12-28] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2013-07-12] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2016-12-17] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2015-01-07] (Adobe Systems)
FF Plugin HKU\S-1-5-21-1893927633-78115024-1840190309-1001: @citrixonline.com/appdetectorplugin -> C:\Users\Carol\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2015-06-25] (Citrix Online)
FF Plugin HKU\S-1-5-21-1893927633-78115024-1840190309-1001: @talk.google.com/GoogleTalkPlugin -> C:\Users\Carol\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll [2015-12-08] (Google)
FF Plugin HKU\S-1-5-21-1893927633-78115024-1840190309-1001: @talk.google.com/O1DPlugin -> C:\Users\Carol\AppData\Roaming\Mozilla\plugins\npo1d.dll [2015-12-08] (Google)
FF Plugin HKU\S-1-5-21-1893927633-78115024-1840190309-1001: @tools.google.com/Google Update;version=3 -> C:\Users\Carol\AppData\Local\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin HKU\S-1-5-21-1893927633-78115024-1840190309-1001: @tools.google.com/Google Update;version=9 -> C:\Users\Carol\AppData\Local\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Carol\AppData\Roaming\mozilla\plugins\npgoogletalk.dll [2015-12-08] (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\Carol\AppData\Roaming\mozilla\plugins\npo1d.dll [2015-12-08] (Google)
 
Chrome: 
=======
CHR DefaultProfile: Default
CHR Plugin: (Widevine Content Decryption Module) - C:\Users\Carol\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.6.703\_platform_specific\win_x86\widevinecdmadapter.dll => No File
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\56.0.2924.87\PepperFlash\pepflashplayer.dll => No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\56.0.2924.87\pdf.dll => No File
CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll => No File
CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll => No File
CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll => No File
CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll => No File
CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll => No File
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL => No File
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL => No File
CHR Plugin: (AdobeAAMDetect) - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems)
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Picasa) - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
CHR Plugin: (Intel® Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
CHR Plugin: (Intel® Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
CHR Plugin: (Java Deployment Toolkit 8.0.310.13) - C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll => No File
CHR Plugin: (Java™ Platform SE 8 U31) - C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll => No File
CHR Plugin: (WildTangent Games App V2 Presence Detector) - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
CHR Plugin: (Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Google Update) - C:\Users\Carol\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll => No File
CHR Plugin: (Google Talk Plugin) - C:\Users\Carol\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
CHR Plugin: (Google Talk Plugin Video Renderer) - C:\Users\Carol\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
CHR Plugin: (Shockwave Flash) - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll => No File
CHR Plugin: (McAfee SecurityCenter) - c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL => No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll => No File
CHR Profile: C:\Users\Carol\AppData\Local\Google\Chrome\User Data\Default [2017-02-16]
CHR Extension: (Google Slides) - C:\Users\Carol\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-02-05]
CHR Extension: (Google Docs) - C:\Users\Carol\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-05]
CHR Extension: (Google Drive) - C:\Users\Carol\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-11-08]
CHR Extension: (YouTube) - C:\Users\Carol\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-26]
CHR Extension: (Google Search) - C:\Users\Carol\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-08]
CHR Extension: (Google Sheets) - C:\Users\Carol\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-02-05]
CHR Extension: (Google Docs Offline) - C:\Users\Carol\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-26]
CHR Extension: (AdBlock) - C:\Users\Carol\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2017-02-05]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Carol\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-02-05]
CHR Extension: (Gmail) - C:\Users\Carol\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-29]
CHR Extension: (Chrome Media Router) - C:\Users\Carol\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-02-15]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-05-29] (Apple Inc.)
R2 AVG Antivirus; C:\Program Files (x86)\AVG\Antivirus\AVGSvc.exe [260080 2017-02-16] (AVG Technologies CZ, s.r.o.)
R3 avgbIDSAgent; C:\Program Files (x86)\AVG\Antivirus\x64\aswidsagenta.exe [6183576 2017-02-16] (AVG Technologies CZ, s.r.o.)
R2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [1255272 2017-01-09] (AVG Technologies CZ, s.r.o.)
R2 CCDMonitorService; C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe [2709760 2014-11-16] (Acer Incorporated)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [3699904 2016-12-28] (Microsoft Corporation)
R2 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [235008 2013-07-16] (TODO: <Company name>) [File not signed]
R2 HitmanProScheduler; C:\Program Files\HitmanPro\hmpsched.exe [135496 2017-02-15] (SurfRight B.V.)
R2 igfxCUIService2.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [373744 2016-11-01] (Intel Corporation)
R2 Intel® Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-11] (Intel® Corporation) [File not signed]
S3 Intel® Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel® Corporation)
R2 Intel® ME Service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-08-19] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [169432 2013-08-19] (Intel Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4355024 2017-01-20] (Malwarebytes)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.500\McCHSvc.exe [329480 2017-01-18] (McAfee, Inc.)
R2 sesvc; C:\Program Files (x86)\ShadowExplorer\sesvc.exe [9216 2013-01-02] (www.shadowexplorer.com) [File not signed]
R3 UEIPSvc; C:\Program Files\Acer\User Experience Improvement Program\Framework\UBTService.exe [222952 2014-01-24] (acer)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation)
R2 ZAMSvc; C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe [14416624 2017-02-02] (Copyright 2017.)
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R1 avgbdisk; C:\WINDOWS\system32\drivers\avgbdiska.sys [165624 2017-02-16] (AVG Technologies CZ, s.r.o.)
R1 avgbidsdriver; C:\WINDOWS\system32\drivers\avgbidsdrivera.sys [311592 2017-02-16] (AVG Technologies CZ, s.r.o.)
R0 avgbidsh; C:\WINDOWS\system32\drivers\avgbidsha.sys [192096 2017-02-16] (AVG Technologies CZ, s.r.o.)
R0 avgblog; C:\WINDOWS\system32\drivers\avgbloga.sys [336920 2017-02-16] (AVG Technologies CZ, s.r.o.)
R0 avgbuniv; C:\WINDOWS\system32\drivers\avgbuniva.sys [50848 2017-02-16] (AVG Technologies CZ, s.r.o.)
S3 avgHwid; C:\WINDOWS\system32\drivers\avgHwid.sys [39288 2017-02-16] (AVG Technologies CZ, s.r.o.)
R2 avgMonFlt; C:\WINDOWS\system32\drivers\avgMonFlt.sys [127072 2017-02-16] (AVG Technologies CZ, s.r.o.)
R1 avgRdr; C:\WINDOWS\system32\drivers\avgRdr2.sys [101624 2017-02-16] (AVG Technologies CZ, s.r.o.)
S0 avgRvrt; C:\WINDOWS\system32\drivers\avgRvrt.sys [75664 2017-02-16] (AVG Technologies CZ, s.r.o.)
R1 avgSnx; C:\WINDOWS\system32\drivers\avgSnx.sys [992488 2017-02-16] (AVG Technologies CZ, s.r.o.)
R1 avgSP; C:\WINDOWS\system32\drivers\avgSP.sys [555152 2017-02-16] (AVG Technologies CZ, s.r.o.)
R2 avgStm; C:\WINDOWS\system32\drivers\avgStm.sys [163512 2017-02-16] (AVG Technologies CZ, s.r.o.)
R0 avgVmm; C:\WINDOWS\system32\drivers\avgVmm.sys [311472 2017-02-16] (AVG Technologies CZ, s.r.o.)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [129152 2016-04-24] (Samsung Electronics Co., Ltd.)
R3 dot4; C:\WINDOWS\system32\DRIVERS\Dot4.sys [151968 2012-10-19] (Windows ® Win 7 DDK provider)
R3 Dot4Print; C:\WINDOWS\System32\drivers\Dot4Prt.sys [27040 2012-10-19] (Windows ® Win 7 DDK provider)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [77416 2017-01-20] ()
R2 MBAMChameleon; C:\WINDOWS\system32\drivers\MBAMChameleon.sys [176584 2017-02-16] (Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\system32\drivers\farflt.sys [110536 2017-02-16] (Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\system32\drivers\mbam.sys [43968 2017-02-16] (Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [251848 2017-02-16] (Malwarebytes)
R3 MEIx64; C:\WINDOWS\system32\DRIVERS\TeeDriverx64.sys [99288 2013-08-19] (Intel Corporation)
S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
R2 RtkIOAC60; C:\WINDOWS\system32\DRIVERS\RtkIOAC60.sys [29912 2013-07-18] (Realtek semiconductor corp)
R3 RTSUER; C:\WINDOWS\system32\Drivers\RtsUer.sys [402960 2015-05-14] (Realsil Semiconductor Corporation)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [221824 2016-04-24] (Samsung Electronics Co., Ltd.)
S3 ssudserd; C:\WINDOWS\system32\DRIVERS\ssudserd.sys [214832 2015-12-08] (DEVGURU Co., LTD.(www.devguru.co.kr))
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
R1 ZAM; C:\WINDOWS\System32\drivers\zam64.sys [203680 2017-02-15] (Zemana Ltd.)
R1 ZAM_Guard; C:\WINDOWS\System32\drivers\zamguard64.sys [203680 2017-02-15] (Zemana Ltd.)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2017-02-16 10:18 - 2017-02-16 10:19 - 00031749 _____ C:\Users\Carol\Downloads\FRST.txt
2017-02-16 10:17 - 2017-02-16 10:18 - 00000000 ____D C:\FRST
2017-02-16 10:17 - 2017-02-16 10:17 - 02422272 _____ (Farbar) C:\Users\Carol\Downloads\FRST64.exe
2017-02-16 10:03 - 2017-02-16 10:03 - 00176584 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMChameleon.sys
2017-02-16 10:02 - 2017-02-16 10:02 - 00251848 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2017-02-16 10:02 - 2017-02-16 10:02 - 00110536 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
2017-02-16 10:02 - 2017-02-16 10:02 - 00043968 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2017-02-16 10:02 - 2017-02-16 10:02 - 00001916 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2017-02-16 10:02 - 2017-02-16 10:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2017-02-16 10:02 - 2017-01-20 07:47 - 00077416 _____ C:\WINDOWS\system32\Drivers\mbae64.sys
2017-02-16 10:00 - 2017-02-16 10:02 - 55566792 _____ (Malwarebytes ) C:\Users\Carol\Downloads\mb3-setup-consumer-3.0.6.1469 (1).exe
2017-02-16 09:29 - 2017-02-16 09:29 - 00000000 ___HD C:\OneDriveTemp
2017-02-16 00:19 - 2017-02-16 00:19 - 00000000 ____D C:\Users\Carol\AppData\Roaming\AVG
2017-02-16 00:17 - 2017-02-16 00:17 - 00992488 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgsnx.sys.148722947785901
2017-02-16 00:17 - 2017-02-16 00:17 - 00992488 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgsnx.sys
2017-02-16 00:17 - 2017-02-16 00:17 - 00555152 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgSP.sys
2017-02-16 00:17 - 2017-02-16 00:17 - 00397800 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\avgBoot.exe
2017-02-16 00:17 - 2017-02-16 00:17 - 00311472 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgVmm.sys
2017-02-16 00:17 - 2017-02-16 00:17 - 00163512 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgStm.sys
2017-02-16 00:17 - 2017-02-16 00:17 - 00127072 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgMonFlt.sys
2017-02-16 00:17 - 2017-02-16 00:17 - 00101624 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgRdr2.sys
2017-02-16 00:17 - 2017-02-16 00:17 - 00075664 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgRvrt.sys
2017-02-16 00:17 - 2017-02-16 00:17 - 00039288 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgHwid.sys
2017-02-16 00:17 - 2017-02-16 00:17 - 00004008 _____ C:\WINDOWS\System32\Tasks\Antivirus Emergency Update
2017-02-16 00:17 - 2017-02-16 00:16 - 00336920 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgbloga.sys
2017-02-16 00:17 - 2017-02-16 00:16 - 00311592 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgbidsdrivera.sys
2017-02-16 00:17 - 2017-02-16 00:16 - 00192096 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgbidsha.sys
2017-02-16 00:17 - 2017-02-16 00:16 - 00165624 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgbdiska.sys
2017-02-16 00:17 - 2017-02-16 00:16 - 00050848 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgbuniva.sys
2017-02-16 00:15 - 2017-02-16 00:15 - 00000943 _____ C:\Users\Public\Desktop\AVG.lnk
2017-02-16 00:15 - 2017-02-16 00:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG Zen
2017-02-16 00:14 - 2017-02-16 00:16 - 00000000 ____D C:\Program Files (x86)\AVG
2017-02-16 00:14 - 2017-02-16 00:14 - 00003668 _____ C:\WINDOWS\System32\Tasks\AVG EUpdate Task
2017-02-16 00:13 - 2017-02-16 00:17 - 00000000 ____D C:\ProgramData\Avg
2017-02-16 00:13 - 2017-02-16 00:15 - 00000000 ____D C:\Users\Carol\AppData\Local\AvgSetupLog
2017-02-16 00:13 - 2017-02-16 00:13 - 00000000 ____D C:\Users\Carol\AppData\Local\Avg
2017-02-15 22:40 - 2017-02-16 00:13 - 03449304 _____ (AVG Technologies CZ, s.r.o.) C:\Users\Carol\Downloads\AVG_Protection_Free_1606.exe
2017-02-15 22:26 - 2017-02-15 22:27 - 147118352 _____ (Microsoft Corporation) C:\Users\Carol\Downloads\msert.exe
2017-02-15 21:35 - 2017-02-16 10:19 - 00672917 _____ C:\WINDOWS\ZAM.krnl.trace
2017-02-15 21:35 - 2017-02-16 10:18 - 00111853 _____ C:\WINDOWS\ZAM_Guard.krnl.trace
2017-02-15 21:35 - 2017-02-15 21:35 - 00203680 _____ (Zemana Ltd.) C:\WINDOWS\system32\Drivers\zamguard64.sys
2017-02-15 21:35 - 2017-02-15 21:35 - 00203680 _____ (Zemana Ltd.) C:\WINDOWS\system32\Drivers\zam64.sys
2017-02-15 21:35 - 2017-02-15 21:35 - 00001221 _____ C:\Users\Public\Desktop\Zemana AntiMalware.lnk
2017-02-15 21:35 - 2017-02-15 21:35 - 00000000 ____D C:\Users\Carol\AppData\Local\Zemana
2017-02-15 21:35 - 2017-02-15 21:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zemana AntiMalware
2017-02-15 21:35 - 2017-02-15 21:35 - 00000000 ____D C:\Program Files (x86)\Zemana AntiMalware
2017-02-15 21:34 - 2017-02-15 21:35 - 05677776 _____ (Zemana Ltd. ) C:\Users\Carol\Downloads\Zemana.AntiMalware.Setup.exe
2017-02-15 20:52 - 2017-02-15 20:52 - 00001966 _____ C:\Users\Public\Desktop\HitmanPro.lnk
2017-02-15 20:52 - 2017-02-15 20:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HitmanPro
2017-02-15 20:52 - 2017-02-15 20:52 - 00000000 ____D C:\Program Files\HitmanPro
2017-02-15 20:49 - 2017-02-15 20:51 - 11581544 _____ (SurfRight B.V.) C:\Users\Carol\Downloads\hitmanpro_x64 (1).exe
2017-02-15 19:37 - 2017-02-15 21:55 - 00000000 ____D C:\Users\Carol\Downloads\TOTAL_AB2F70FD7450BD (1)
2017-02-15 18:32 - 2017-02-15 22:02 - 00000000 ____D C:\Users\Carol\Downloads\TOTAL_AB2F70FD7450BD
2017-02-14 13:55 - 2017-02-14 13:55 - 01966227 _____ C:\Users\Carol\Downloads\BitGo Keycard for My BitGo Wallet.pdf
2017-02-14 13:28 - 2017-02-14 13:28 - 00000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2017-02-14 12:38 - 2017-02-14 12:38 - 55566792 _____ (Malwarebytes ) C:\Users\Carol\Downloads\mb3-setup-consumer-3.0.6.1469.exe
2017-02-14 12:38 - 2017-02-14 12:38 - 00000000 ____D C:\Program Files\Malwarebytes
2017-02-14 12:35 - 2017-02-14 13:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ShadowExplorer
2017-02-14 12:35 - 2017-02-14 13:16 - 00000000 ____D C:\Program Files (x86)\ShadowExplorer
2017-02-14 12:35 - 2017-02-14 12:35 - 00001958 _____ C:\Users\Carol\Desktop\ShadowExplorer.lnk
2017-02-14 12:34 - 2017-02-14 12:34 - 00969845 _____ (ShadowExplorer.com ) C:\Users\Carol\Downloads\ShadowExplorer-0.9-setup.exe
2017-02-14 11:41 - 2017-02-14 11:42 - 00412660 _____ C:\WINDOWS\Minidump\021417-78046-01.dmp
2017-02-14 11:41 - 2017-02-14 11:41 - 00000000 ____D C:\WINDOWS\Minidump
2017-02-14 11:13 - 2017-02-14 11:13 - 00016715 _____ C:\Users\Carol\AppData\Roaming\CA9FD-43XXH-ETGGH-TXATX-GHZTO-AFRGT-XFGOY.html
2017-02-14 11:13 - 2017-02-14 11:13 - 00001088 _____ C:\Users\Carol\AppData\Roaming\CA9FD-43XXH-ETGGH-TXATX-GHZTO-AFRGT-XFGOY
2017-02-14 11:12 - 2017-02-15 20:21 - 00000234 _____ C:\Users\Carol\AppData\Roaming\4238841256
2017-02-10 16:35 - 2017-02-15 19:56 - 00051011 _____ C:\Users\Carol\Downloads\SalsFlatbreadInvoiceUpdated.pdf
2017-02-08 21:26 - 2017-02-15 19:56 - 00051067 _____ C:\Users\Carol\Downloads\SalsFlatbreadInvoice.pdf
2017-02-06 23:42 - 2017-02-15 19:56 - 00052067 _____ C:\Users\Carol\Downloads\InvoiceFeb6Kristin.pdf
2017-02-05 11:18 - 2017-02-05 11:18 - 00002013 _____ C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
2017-02-05 11:18 - 2017-02-05 11:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
2017-01-30 14:49 - 2017-02-15 19:56 - 01031102 _____ C:\Users\Carol\Downloads\Win Free Breakfast for a week.pdf
2017-01-30 11:17 - 2017-02-15 19:56 - 00746875 _____ C:\Users\Carol\Downloads\sals_logoGOOD (1).pdf
2017-01-28 21:20 - 2017-01-28 18:55 - 51262945 ____N C:\Users\Carol\Desktop\VID_20170128_185420711.mp4
2017-01-28 21:19 - 2017-01-28 18:46 - 136170505 ____N C:\Users\Carol\Desktop\VID_20170128_184501414.mp4
2017-01-28 21:19 - 2017-01-28 18:42 - 137671181 ____N C:\Users\Carol\Desktop\VID_20170128_184011521.mp4
2017-01-25 11:40 - 2016-12-21 00:08 - 00142848 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe
2017-01-25 11:40 - 2016-12-20 21:44 - 00120320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe
2017-01-24 22:02 - 2017-01-24 22:03 - 117186608 _____ C:\Users\Carol\Downloads\1_11819.tif
2017-01-24 22:00 - 2017-01-24 22:00 - 117189612 _____ C:\Users\Carol\Downloads\1_11865 (1).tif
2017-01-24 14:37 - 2017-01-24 14:37 - 117186812 _____ C:\Users\Carol\Downloads\1_11852 (1).tif
2017-01-23 14:03 - 2017-02-15 19:56 - 00026146 _____ C:\Users\Carol\Downloads\GreatToSkatePartyWaiver (1).pdf
2017-01-23 13:55 - 2017-02-15 19:56 - 00026146 _____ C:\Users\Carol\Downloads\GreatToSkatePartyWaiver.pdf
2017-01-23 13:39 - 2017-02-15 19:56 - 00050079 _____ C:\Users\Carol\Downloads\InvoiceJan16Kristin (1).pdf
2017-01-23 13:34 - 2017-02-15 19:56 - 00049457 _____ C:\Users\Carol\Downloads\InvoiceJan16Kristin.pdf
2017-01-19 10:03 - 2017-01-19 10:04 - 117186812 _____ C:\Users\Carol\Downloads\1_11852.tif
2017-01-19 10:03 - 2017-01-19 10:04 - 117186416 _____ C:\Users\Carol\Downloads\1_11783.tif
2017-01-18 21:05 - 2017-01-18 21:05 - 117189612 _____ C:\Users\Carol\Downloads\1_11865.tif
2017-01-18 12:00 - 2017-01-18 12:00 - 00446266 _____ C:\Users\Carol\Downloads\C17WfCxUQAADh4l (1).jpg-large
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2017-02-16 10:02 - 2014-11-27 22:45 - 00000000 ____D C:\ProgramData\Malwarebytes
2017-02-16 10:01 - 2014-09-14 22:32 - 00000000 ____D C:\Users\Carol\AppData\Local\Adobe
2017-02-16 09:35 - 2016-07-16 04:47 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-02-16 09:31 - 2014-09-14 19:18 - 00000000 ____D C:\Users\Carol\AppData\Local\clear.fi
2017-02-16 09:29 - 2015-02-15 15:46 - 00000000 ___RD C:\Users\Carol\OneDrive
2017-02-16 09:28 - 2016-09-29 08:25 - 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2017-02-16 09:28 - 2015-08-06 07:53 - 00000000 __SHD C:\Users\Carol\IntelGraphicsProfiles
2017-02-16 00:41 - 2016-07-16 04:47 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2017-02-15 23:07 - 2016-09-29 08:23 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2017-02-15 22:06 - 2014-09-16 20:24 - 00000000 ____D C:\Users\Carol\AppData\Local\CrashDumps
2017-02-15 22:03 - 2015-08-06 00:26 - 01139954 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-02-15 21:56 - 2016-09-29 08:53 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-02-15 21:55 - 2016-07-15 23:04 - 00524288 _____ C:\WINDOWS\system32\config\BBI
2017-02-15 20:53 - 2016-07-16 04:47 - 00000000 ___HD C:\Program Files\WindowsApps
2017-02-15 20:49 - 2016-07-15 23:04 - 00032768 _____ C:\WINDOWS\system32\config\ELAM
2017-02-15 20:46 - 2014-09-14 22:33 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2017-02-15 20:31 - 2014-09-05 19:39 - 00000000 ____D C:\Users\Carol\AppData\Local\Packages
2017-02-15 19:57 - 2016-07-25 09:16 - 01841934 _____ C:\Users\Carol\Downloads\lagree6.jpeg
2017-02-15 19:57 - 2016-07-10 14:31 - 00258194 _____ C:\Users\Carol\Downloads\canada olympic park.jpeg
2017-02-15 19:57 - 2016-03-30 14:05 - 00027215 _____ C:\Users\Carol\Downloads\Blank Print Document.jpeg
2017-02-15 19:57 - 2016-03-04 15:38 - 00113478 _____ C:\Users\Carol\Downloads\Monochrome (Portrait) (3).jpeg
2017-02-15 19:57 - 2016-03-04 15:06 - 00118117 _____ C:\Users\Carol\Downloads\Monochrome (Portrait) (2).jpeg
2017-02-15 19:57 - 2016-03-03 22:38 - 00105707 _____ C:\Users\Carol\Downloads\Monochrome (Portrait) (1).jpeg
2017-02-15 19:57 - 2016-03-03 22:21 - 00106763 _____ C:\Users\Carol\Downloads\Monochrome (Portrait).jpeg
2017-02-15 19:57 - 2015-10-15 11:57 - 00107590 _____ C:\Users\Carol\Downloads\Newsletterholidayad.jpeg
2017-02-15 19:57 - 2015-10-12 13:43 - 00464553 _____ C:\Users\Carol\Downloads\Blank Digital Document.jpeg
2017-02-15 19:57 - 2015-10-12 12:06 - 01093277 _____ C:\Users\Carol\Downloads\Facebook Post.jpeg
2017-02-15 19:57 - 2015-10-05 13:13 - 00923275 _____ C:\Users\Carol\Downloads\Christmas AD (1).jpeg
2017-02-15 19:57 - 2015-09-30 09:56 - 00910293 _____ C:\Users\Carol\Downloads\GreattoSkateChristmas AD (1).jpeg
2017-02-15 19:57 - 2015-09-30 09:53 - 00184632 _____ C:\Users\Carol\Downloads\Christmas AD.jpeg
2017-02-15 19:57 - 2015-09-30 09:51 - 00184632 _____ C:\Users\Carol\Downloads\Copy of Blank Print Document.jpeg
2017-02-15 19:57 - 2015-08-16 20:06 - 00783880 _____ C:\Users\Carol\Downloads\Blank Digital Document - Blank (2).jpeg
2017-02-15 19:57 - 2015-08-06 23:29 - 00351853 _____ C:\Users\Carol\Downloads\Blank Digital Document - Blank (1).jpeg
2017-02-15 19:57 - 2015-08-06 23:25 - 00351335 _____ C:\Users\Carol\Downloads\Blank Digital Document - Blank.jpeg
2017-02-15 19:57 - 2015-06-14 23:55 - 00827358 _____ C:\Users\Carol\Downloads\Newsletter - Untitled Page.jpeg
2017-02-15 19:57 - 2015-06-14 23:53 - 00382298 _____ C:\Users\Carol\Downloads\JulySchedule - Untitled Page (1).jpeg
2017-02-15 19:57 - 2015-06-14 23:52 - 00654554 _____ C:\Users\Carol\Downloads\Get Going July events newsletter - Untitled Page.jpeg
2017-02-15 19:57 - 2015-06-14 23:51 - 00942670 _____ C:\Users\Carol\Downloads\Get Going May-June pictures - Untitled Page.jpeg
2017-02-15 19:57 - 2015-06-12 23:02 - 00459344 _____ C:\Users\Carol\Downloads\Blank Print Document - Untitled Page (2).jpeg
2017-02-15 19:57 - 2015-06-12 11:41 - 00939834 _____ C:\Users\Carol\Downloads\Blank Print Document - Untitled Page.jpeg
2017-02-15 19:57 - 2015-05-15 00:12 - 00793625 _____ C:\Users\Carol\Downloads\GetGoingNewsletter.jpeg
2017-02-15 19:57 - 2015-05-15 00:09 - 00321901 _____ C:\Users\Carol\Downloads\JulySchedule - Untitled Page.jpeg
2017-02-15 19:57 - 2015-05-14 23:28 - 00791798 _____ C:\Users\Carol\Downloads\Blank Print Document - Untitled Page (1).jpeg
2017-02-15 19:57 - 2015-05-14 23:28 - 00361854 _____ C:\Users\Carol\Downloads\MayJuneSchedule.jpeg
2017-02-15 19:56 - 2017-01-09 10:48 - 00013326 _____ C:\Users\Carol\Downloads\Class Listsz (1).xlsx
2017-02-15 19:56 - 2017-01-04 22:54 - 00126826 _____ C:\Users\Carol\Downloads\merged_document (7).pdf
2017-02-15 19:56 - 2017-01-04 22:53 - 00071379 _____ C:\Users\Carol\Downloads\CopyofCarolResume2016Marcomm (5).2-3.pdf
2017-02-15 19:56 - 2017-01-04 22:43 - 00054819 _____ C:\Users\Carol\Downloads\CoverLetterUofC.pdf
2017-02-15 19:56 - 2017-01-04 21:44 - 00070841 _____ C:\Users\Carol\Downloads\CopyofCarolResume2016Marcomm (5).pdf
2017-02-15 19:56 - 2017-01-03 19:17 - 00072038 _____ C:\Users\Carol\Downloads\CarolResume2016SocialMedia (4).2-3.pdf
2017-02-15 19:56 - 2017-01-03 19:13 - 00071520 _____ C:\Users\Carol\Downloads\CarolResume2016SocialMedia (4).pdf
2017-02-15 19:56 - 2016-12-30 18:02 - 00009599 _____ C:\Users\Carol\Downloads\Class Listsz.xlsx
2017-02-15 19:56 - 2016-12-18 22:17 - 00786845 _____ C:\Users\Carol\Downloads\attracting-new-girls-and-women-into-football2.pdf
2017-02-15 19:56 - 2016-12-11 15:56 - 00527190 _____ C:\Users\Carol\Downloads\Confirmation (1).pdf
2017-02-15 19:56 - 2016-12-02 14:35 - 00110722 _____ C:\Users\Carol\Downloads\GreattoSkateMidnaporeLakeContract2017 (2).pdf
2017-02-15 19:56 - 2016-12-02 14:34 - 00110723 _____ C:\Users\Carol\Downloads\GreattoSkateMidnaporeLakeContract2017 (1).pdf
2017-02-15 19:56 - 2016-12-02 14:34 - 00071682 _____ C:\Users\Carol\Downloads\InvoiceMidnaporeLake2017 (1).pdf
2017-02-15 19:56 - 2016-12-02 14:25 - 00110723 _____ C:\Users\Carol\Downloads\GreattoSkateMidnaporeLakeContract2017.pdf
2017-02-15 19:56 - 2016-12-02 14:25 - 00071682 _____ C:\Users\Carol\Downloads\InvoiceMidnaporeLake2017.pdf
2017-02-15 19:56 - 2016-11-12 15:44 - 00345109 _____ C:\Users\Carol\Downloads\Online Video Resource Library List 160516.pdf
2017-02-15 19:56 - 2016-11-09 23:01 - 01063645 _____ C:\Users\Carol\Downloads\Archery.pdf
2017-02-15 19:56 - 2016-11-08 23:15 - 00243544 _____ C:\Users\Carol\Downloads\Personal Training Voucher.pdf
2017-02-15 19:56 - 2016-10-28 11:02 - 00011612 _____ C:\Users\Carol\Downloads\onlineStatement.pdf
2017-02-15 19:56 - 2016-10-24 09:06 - 03813280 _____ C:\Users\Carol\Downloads\Freeset Tees Standard Canada Catalog 2016.pdf
2017-02-15 19:56 - 2016-10-09 22:31 - 00082030 _____ C:\Users\Carol\Downloads\ProblemparentParentwithProblemsSlide.pdf
2017-02-15 19:56 - 2016-10-08 20:05 - 00104531 _____ C:\Users\Carol\Downloads\26696057627-555768936-ticket.pdf
2017-02-15 19:56 - 2016-10-05 10:43 - 00071309 _____ C:\Users\Carol\Downloads\CopyofCarolResume2016Marcomm (4).2-3.pdf
2017-02-15 19:56 - 2016-10-05 10:42 - 00056198 _____ C:\Users\Carol\Downloads\CoverLetterCSLA.pdf
2017-02-15 19:56 - 2016-10-05 10:42 - 00055604 _____ C:\Users\Carol\Downloads\CoverLetterCity (1).pdf
2017-02-15 19:56 - 2016-10-05 09:12 - 00070590 _____ C:\Users\Carol\Downloads\CopyofCarolResume2016Marcomm (4).pdf
2017-02-15 19:56 - 2016-10-04 12:24 - 00036696 _____ C:\Users\Carol\Downloads\Rate+Sheet+PHSPCA2013.pdf
2017-02-15 19:56 - 2016-10-03 19:07 - 00706129 _____ C:\Users\Carol\Downloads\Inspiration_Puzzle_Pack.pdf
2017-02-15 19:56 - 2016-10-02 21:59 - 05151110 _____ C:\Users\Carol\Downloads\calgary-2016-package.pdf
2017-02-15 19:56 - 2016-09-14 10:24 - 00049330 _____ C:\Users\Carol\Downloads\2016 TimesheetsSept2016.xlsx
2017-02-15 19:56 - 2016-09-12 20:44 - 00122095 _____ C:\Users\Carol\Downloads\September 2016.pdf
2017-02-15 19:56 - 2016-09-01 08:01 - 00049329 _____ C:\Users\Carol\Downloads\2016 TimesheetsAugend2016.xlsx
2017-02-15 19:56 - 2016-08-31 17:49 - 00022580 _____ C:\Users\Carol\Downloads\Calgary (2).xlsx
2017-02-15 19:56 - 2016-08-31 17:40 - 00022580 _____ C:\Users\Carol\Downloads\Calgary (1).xlsx
2017-02-15 19:56 - 2016-08-31 09:54 - 00070704 _____ C:\Users\Carol\Downloads\CopyofCarolResume2016Marcomm (3).pdf
2017-02-15 19:56 - 2016-08-31 09:54 - 00070198 _____ C:\Users\Carol\Downloads\CopyofCarolResume2016Marcomm (2).pdf
2017-02-15 19:56 - 2016-08-31 09:40 - 00070027 _____ C:\Users\Carol\Downloads\CopyofCarolResume2016Marcomm (1).pdf
2017-02-15 19:56 - 2016-08-19 18:32 - 00004633 _____ C:\Users\Carol\Downloads\Tasks%2FCalendar.xlsx
2017-02-15 19:56 - 2016-08-14 12:31 - 00049338 _____ C:\Users\Carol\Downloads\2016 TimesheetsAug2016.xlsx
2017-02-15 19:56 - 2016-08-08 15:19 - 00196092 _____ C:\Users\Carol\Downloads\CIC-summer-drop-in-2016 (1).pdf
2017-02-15 19:56 - 2016-08-08 15:18 - 00196092 _____ C:\Users\Carol\Downloads\CIC-summer-drop-in-2016.pdf
2017-02-15 19:56 - 2016-08-02 16:10 - 00022309 _____ C:\Users\Carol\Downloads\Calgary.xlsx
2017-02-15 19:56 - 2016-07-28 09:06 - 00049281 _____ C:\Users\Carol\Downloads\2016 TimesheetsCarolJuly.xlsx
2017-02-15 19:56 - 2016-07-26 18:39 - 00573136 _____ C:\Users\Carol\Downloads\brochure.pdf
2017-02-15 19:56 - 2016-07-22 08:55 - 01157373 _____ C:\Users\Carol\Downloads\1 Move Better (1).pdf
2017-02-15 19:56 - 2016-07-22 08:14 - 01103678 _____ C:\Users\Carol\Downloads\1 Move Better.pdf
2017-02-15 19:56 - 2016-07-04 20:10 - 00491564 _____ C:\Users\Carol\Downloads\Adult Program Spring  Summer 2016 (5-17-2016).pdf
2017-02-15 19:56 - 2016-06-27 13:42 - 00049323 _____ C:\Users\Carol\Downloads\2016 Timesheets CarolJune.xlsx
2017-02-15 19:56 - 2016-06-27 13:36 - 00051557 _____ C:\Users\Carol\Downloads\2016 Timesheets (2).xlsx
2017-02-15 19:56 - 2016-06-16 12:12 - 00020443 _____ C:\Users\Carol\Downloads\frmTeams.xlsx
2017-02-15 19:56 - 2016-06-08 10:02 - 01275271 _____ C:\Users\Carol\Downloads\cotton_ranking_report___june_2016_2.pdf
2017-02-15 19:56 - 2016-06-06 12:00 - 05971815 _____ C:\Users\Carol\Downloads\2016 June Newsletter.pdf
2017-02-15 19:56 - 2016-05-19 13:46 - 00184039 _____ C:\Users\Carol\Downloads\merged_document (6).pdf
2017-02-15 19:56 - 2016-05-19 13:45 - 00102005 _____ C:\Users\Carol\Downloads\CopyofCarolResume2016Marcomm.2-3.pdf
2017-02-15 19:56 - 2016-05-19 13:44 - 00080163 _____ C:\Users\Carol\Downloads\CoverLetterCity.pdf
2017-02-15 19:56 - 2016-05-19 12:58 - 00100778 _____ C:\Users\Carol\Downloads\CopyofCarolResume2016Marcomm.pdf
2017-02-15 19:56 - 2016-05-17 12:37 - 00100625 _____ C:\Users\Carol\Downloads\CarolResume2015Volunteer (10).2-3.pdf
2017-02-15 19:56 - 2016-05-17 12:37 - 00100059 _____ C:\Users\Carol\Downloads\CarolResume2015Volunteer (10).pdf
2017-02-15 19:56 - 2016-05-16 21:09 - 01258419 _____ C:\Users\Carol\Downloads\www.greattoskate.net.pdf
2017-02-15 19:56 - 2016-05-16 20:27 - 00979597 _____ C:\Users\Carol\Downloads\Untitled design.pdf
2017-02-15 19:56 - 2016-05-16 00:25 - 00067542 _____ C:\Users\Carol\Downloads\CoverLetterAU.pdf
2017-02-15 19:56 - 2016-05-15 22:31 - 00112068 _____ C:\Users\Carol\Downloads\CarolCVAU (1).2-4.pdf
2017-02-15 19:56 - 2016-05-15 22:30 - 00110820 _____ C:\Users\Carol\Downloads\CarolCVAU (1).pdf
2017-02-15 19:56 - 2016-05-15 22:29 - 00110771 _____ C:\Users\Carol\Downloads\CarolCVAU.pdf
2017-02-15 19:56 - 2016-05-15 20:45 - 00040771 _____ C:\Users\Carol\Downloads\References (5).pdf
2017-02-15 19:56 - 2016-05-15 20:42 - 00039689 _____ C:\Users\Carol\Downloads\References (4).pdf
2017-02-15 19:56 - 2016-04-29 09:44 - 00067461 _____ C:\Users\Carol\Downloads\Stampede Exhibitor Agreement.pdf
2017-02-15 19:56 - 2016-04-26 20:59 - 00070140 _____ C:\Users\Carol\Downloads\16_-_Specialist_Media__Public_Relations.pdf
2017-02-15 19:56 - 2016-04-22 14:51 - 00240877 _____ C:\Users\Carol\Downloads\Invoice-158808.pdf
2017-02-15 19:56 - 2016-04-19 19:13 - 00066843 _____ C:\Users\Carol\Downloads\YYCFitnessVolunteerPositions (1).pdf
2017-02-15 19:56 - 2016-04-19 19:08 - 00066462 _____ C:\Users\Carol\Downloads\YYCFitnessVolunteerPositions.pdf
2017-02-15 19:56 - 2016-04-18 23:10 - 00103631 _____ C:\Users\Carol\Downloads\CarolResume2016Marcomm (5).2-3.pdf
2017-02-15 19:56 - 2016-04-18 23:08 - 00067470 _____ C:\Users\Carol\Downloads\CoverLetterInnovateCalgary.pdf
2017-02-15 19:56 - 2016-04-18 21:05 - 00102387 _____ C:\Users\Carol\Downloads\CarolResume2016Marcomm (5).pdf
2017-02-15 19:56 - 2016-04-18 21:04 - 00103624 _____ C:\Users\Carol\Downloads\CarolResume2016Marcomm (4).pdf
2017-02-15 19:56 - 2016-04-17 22:22 - 00173531 _____ C:\Users\Carol\Downloads\merged_document (5).pdf
2017-02-15 19:56 - 2016-04-17 22:17 - 00105189 _____ C:\Users\Carol\Downloads\CarolResume2016Marcomm (3).2-3.pdf
2017-02-15 19:56 - 2016-04-17 22:15 - 00067664 _____ C:\Users\Carol\Downloads\CoverletterCarolChuInsideEducation.pdf
2017-02-15 19:56 - 2016-04-17 15:28 - 00104644 _____ C:\Users\Carol\Downloads\CarolResume2016Marcomm (3).pdf
2017-02-15 19:56 - 2016-04-17 15:26 - 00105269 _____ C:\Users\Carol\Downloads\CarolResume2016Marcomm (2).pdf
2017-02-15 19:56 - 2016-04-10 19:55 - 00079185 _____ C:\Users\Carol\Downloads\Feb-2016-Test-Day-Schedule.xlsx
2017-02-15 19:56 - 2016-03-23 21:32 - 00049239 _____ C:\Users\Carol\Downloads\2016 Timesheets (1).xlsx
2017-02-15 19:56 - 2016-03-23 21:24 - 00051698 _____ C:\Users\Carol\Downloads\2016 Timesheets.xlsx
2017-02-15 19:56 - 2016-03-23 21:21 - 00158265 _____ C:\Users\Carol\Downloads\ReceiptM2316NL.pdf
2017-02-15 19:56 - 2016-03-23 21:21 - 00158265 _____ C:\Users\Carol\Downloads\ReceiptM2316NL (1).pdf
2017-02-15 19:56 - 2016-03-22 11:50 - 02557225 _____ C:\Users\Carol\Downloads\Flames_Player_FunFacts (1).pdf
2017-02-15 19:56 - 2016-03-13 20:55 - 00153981 _____ C:\Users\Carol\Downloads\ReceiptNadalOmoleme (2).pdf
2017-02-15 19:56 - 2016-03-13 20:54 - 00154701 _____ C:\Users\Carol\Downloads\ReceiptNadalOmoleme (1).pdf
2017-02-15 19:56 - 2016-03-04 15:41 - 00059559 _____ C:\Users\Carol\Downloads\Monochrome (Portrait) (3).pdf
2017-02-15 19:56 - 2016-03-04 15:06 - 00059030 _____ C:\Users\Carol\Downloads\Monochrome (Portrait) (2).pdf
2017-02-15 19:56 - 2016-03-03 22:38 - 00058790 _____ C:\Users\Carol\Downloads\Monochrome (Portrait) (1).pdf
2017-02-15 19:56 - 2016-03-03 22:21 - 00058802 _____ C:\Users\Carol\Downloads\Monochrome (Portrait).pdf
2017-02-15 19:56 - 2016-03-03 21:54 - 00068942 _____ C:\Users\Carol\Downloads\Business Card.pdf
2017-02-15 19:56 - 2016-03-02 15:35 - 00081982 _____ C:\Users\Carol\Downloads\CarolResume2016CA (3).2-4.2-3.pdf
2017-02-15 19:56 - 2016-03-02 15:34 - 00102559 _____ C:\Users\Carol\Downloads\CarolResume2016CA (3).2-4.pdf
2017-02-15 19:56 - 2016-03-02 15:14 - 00103868 _____ C:\Users\Carol\Downloads\CarolResume2016CA (3).pdf
2017-02-15 19:56 - 2016-03-02 15:14 - 00103850 _____ C:\Users\Carol\Downloads\CarolResume2016CA (2).pdf
2017-02-15 19:56 - 2016-03-02 15:14 - 00103837 _____ C:\Users\Carol\Downloads\CarolResume2016CA (1).pdf
2017-02-15 19:56 - 2016-02-16 16:46 - 00065368 _____ C:\Users\Carol\Downloads\InvoiceMidnaporeLake (3).pdf
2017-02-15 19:56 - 2016-02-07 21:28 - 00111330 _____ C:\Users\Carol\Downloads\Untitled drawing.pdf
2017-02-15 19:56 - 2016-02-01 16:31 - 00068323 _____ C:\Users\Carol\Downloads\CoverletterCarolChuCalgaryCA.pdf
2017-02-15 19:56 - 2016-02-01 10:46 - 00100622 _____ C:\Users\Carol\Downloads\CarolResume2016CA.2-3.pdf
2017-02-15 19:56 - 2016-02-01 10:45 - 00103899 _____ C:\Users\Carol\Downloads\CarolResume2016CA.pdf
2017-02-15 19:56 - 2016-01-30 22:25 - 00102009 _____ C:\Users\Carol\Downloads\Blogpostwritingsample (1).pdf
2017-02-15 19:56 - 2016-01-30 22:25 - 00044791 _____ C:\Users\Carol\Downloads\BlogPostWritingSample2.pdf
2017-02-15 19:56 - 2016-01-25 22:19 - 00167972 _____ C:\Users\Carol\Downloads\merged_document (4).pdf
2017-02-15 19:56 - 2016-01-25 22:15 - 00067458 _____ C:\Users\Carol\Downloads\CoverletterCarolChuCalgaryMEOW.pdf
2017-02-15 19:56 - 2016-01-25 20:46 - 00101599 _____ C:\Users\Carol\Downloads\CarolResume2016SocialMedia (3).2-3.pdf
2017-02-15 19:56 - 2016-01-25 20:42 - 00104816 _____ C:\Users\Carol\Downloads\CarolResume2016SocialMedia (3).pdf
2017-02-15 19:56 - 2016-01-25 20:41 - 00104966 _____ C:\Users\Carol\Downloads\CarolResume2016SocialMedia (2).pdf
2017-02-15 19:56 - 2016-01-25 20:40 - 00105587 _____ C:\Users\Carol\Downloads\CarolResume2016SocialMedia (1).pdf
2017-02-15 19:56 - 2016-01-18 23:56 - 00071369 _____ C:\Users\Carol\Downloads\CoverletterCarolChuCalgaryYVC.pdf
2017-02-15 19:56 - 2016-01-18 22:53 - 00103016 _____ C:\Users\Carol\Downloads\CarolChu2016YouthCentral (1).2-3.pdf
2017-02-15 19:56 - 2016-01-18 22:51 - 00104287 _____ C:\Users\Carol\Downloads\CarolChu2016YouthCentral (1).pdf
2017-02-15 19:56 - 2016-01-18 22:50 - 00105438 _____ C:\Users\Carol\Downloads\CarolChu2016YouthCentral.pdf
2017-02-15 19:56 - 2016-01-18 16:17 - 00101131 _____ C:\Users\Carol\Downloads\CarolResume2016Community (1).2-3.pdf
2017-02-15 19:56 - 2016-01-18 16:16 - 00102397 _____ C:\Users\Carol\Downloads\CarolResume2016Community (1).pdf
2017-02-15 19:56 - 2016-01-18 16:15 - 00103952 _____ C:\Users\Carol\Downloads\CarolResume2016Community.pdf
2017-02-15 19:56 - 2016-01-18 10:50 - 00418528 _____ C:\Users\Carol\Downloads\Confirmation.pdf
2017-02-15 19:56 - 2016-01-08 17:42 - 00070834 _____ C:\Users\Carol\Downloads\CoverletterCarolChuCalgaryAirport (1).pdf
2017-02-15 19:56 - 2016-01-08 14:52 - 00114743 _____ C:\Users\Carol\Downloads\CarolResume2015Volunteer (9).2-3.pdf
2017-02-15 19:56 - 2016-01-08 14:50 - 00116513 _____ C:\Users\Carol\Downloads\CarolResume2015Volunteer (9).pdf
2017-02-15 19:56 - 2016-01-08 14:49 - 00117037 _____ C:\Users\Carol\Downloads\CarolResume2015Volunteer (8).pdf
2017-02-15 19:56 - 2016-01-08 14:47 - 00117486 _____ C:\Users\Carol\Downloads\CarolResume2015Volunteer (7).pdf
2017-02-15 19:56 - 2016-01-08 13:36 - 00103668 _____ C:\Users\Carol\Downloads\CarolResume2016Benevity (1).2-3.pdf
2017-02-15 19:56 - 2016-01-08 13:35 - 00105566 _____ C:\Users\Carol\Downloads\CarolResume2016Benevity (1).pdf
2017-02-15 19:56 - 2016-01-08 13:31 - 00105715 _____ C:\Users\Carol\Downloads\CarolResume2016Benevity.pdf
2017-02-15 19:56 - 2016-01-07 20:12 - 00049552 _____ C:\Users\Carol\Downloads\Telpay Biller Information Form.pdf
2017-02-15 19:56 - 2016-01-07 16:16 - 00108266 _____ C:\Users\Carol\Downloads\CarolResume2016Marcomm (1).2-3.pdf
2017-02-15 19:56 - 2016-01-07 16:15 - 00069977 _____ C:\Users\Carol\Downloads\CoverletterCarolChuChildrensWish.pdf
2017-02-15 19:56 - 2016-01-07 15:24 - 00109470 _____ C:\Users\Carol\Downloads\CarolResume2016Marcomm (1).pdf
2017-02-15 19:56 - 2016-01-07 11:53 - 00106187 _____ C:\Users\Carol\Downloads\CarolResume2016Marcomm.2-3.pdf
2017-02-15 19:56 - 2016-01-06 12:12 - 00011955 _____ C:\Users\Carol\Downloads\registration list Midnapore.xlsx
2017-02-15 19:56 - 2016-01-06 11:51 - 00102371 _____ C:\Users\Carol\Downloads\CarolResume2016SocialMedia.2-3.pdf
2017-02-15 19:56 - 2016-01-06 11:42 - 00105588 _____ C:\Users\Carol\Downloads\CarolResume2016SocialMedia.pdf
2017-02-15 19:56 - 2016-01-06 10:33 - 00020084 _____ C:\Users\Carol\Downloads\Bank.pdf
2017-02-15 19:56 - 2016-01-05 16:12 - 00104101 _____ C:\Users\Carol\Downloads\CarolResume2016General (2).2-3.pdf
2017-02-15 19:56 - 2016-01-05 16:10 - 00071571 _____ C:\Users\Carol\Downloads\CoverletterCarolChuWard8.pdf
2017-02-15 19:56 - 2016-01-05 14:40 - 00105288 _____ C:\Users\Carol\Downloads\CarolResume2016General (2).pdf
2017-02-15 19:56 - 2016-01-05 14:39 - 00105270 _____ C:\Users\Carol\Downloads\CarolResume2016General (1).pdf
2017-02-15 19:56 - 2016-01-05 14:39 - 00105250 _____ C:\Users\Carol\Downloads\CarolResume2016General.pdf
2017-02-15 19:56 - 2016-01-05 09:40 - 00009333 _____ C:\Users\Carol\Downloads\registration list.xlsx
2017-02-15 19:56 - 2016-01-04 23:27 - 00071917 _____ C:\Users\Carol\Downloads\CoverletterCarolChuAAISA.pdf
2017-02-15 19:56 - 2016-01-04 23:19 - 00029736 _____ C:\Users\Carol\Downloads\WritingSample2.pdf
2017-02-15 19:56 - 2016-01-04 16:12 - 00554055 _____ C:\Users\Carol\Downloads\WritingSampleBrochure.pdf
2017-02-15 19:56 - 2016-01-04 14:37 - 00107392 _____ C:\Users\Carol\Downloads\CarolResume2016Marcomm.pdf
2017-02-15 19:56 - 2016-01-04 10:21 - 00091708 _____ C:\Users\Carol\Downloads\InvoiceWestHillhurst (1).pdf
2017-02-15 19:56 - 2016-01-03 20:55 - 00091708 _____ C:\Users\Carol\Downloads\InvoiceWestHillhurst.pdf
2017-02-15 19:56 - 2016-01-03 19:50 - 00173337 _____ C:\Users\Carol\Downloads\ReceiptNadalOmoleme.pdf
2017-02-15 19:56 - 2015-12-31 13:01 - 00116641 _____ C:\Users\Carol\Downloads\S.M.A.R.T..pdf
2017-02-15 19:56 - 2015-12-30 14:58 - 00075719 _____ C:\Users\Carol\Downloads\InvoiceMidnaporeLake (2).pdf
2017-02-15 19:56 - 2015-12-21 14:26 - 00497281 _____ C:\Users\Carol\Downloads\398319.pdf
2017-02-15 19:56 - 2015-12-20 21:54 - 00106058 _____ C:\Users\Carol\Downloads\CarolResume2015Marcomm (9).2-3.pdf
2017-02-15 19:56 - 2015-12-20 21:53 - 00107262 _____ C:\Users\Carol\Downloads\CarolResume2015Marcomm (9).pdf
2017-02-15 19:56 - 2015-12-20 21:53 - 00107260 _____ C:\Users\Carol\Downloads\CarolResume2015Marcomm (8).pdf
2017-02-15 19:56 - 2015-12-20 21:17 - 00108123 _____ C:\Users\Carol\Downloads\CarolResume2015GeneralIDI.2-3.pdf
2017-02-15 19:56 - 2015-12-20 21:13 - 00109329 _____ C:\Users\Carol\Downloads\CarolResume2015GeneralIDI.pdf
2017-02-15 19:56 - 2015-12-20 21:10 - 00069380 _____ C:\Users\Carol\Downloads\CoverletterCarolChuIDICalgary.pdf
2017-02-15 19:56 - 2015-12-20 13:28 - 00102368 _____ C:\Users\Carol\Downloads\CarolResume2015SocialMedia (7).2-3.pdf
2017-02-15 19:56 - 2015-12-20 13:24 - 00091599 _____ C:\Users\Carol\Downloads\CoverletterCarolChuAlpineCanada.pdf
2017-02-15 19:56 - 2015-12-20 11:39 - 00105585 _____ C:\Users\Carol\Downloads\CarolResume2015SocialMedia (7).pdf
2017-02-15 19:56 - 2015-12-20 11:38 - 00105598 _____ C:\Users\Carol\Downloads\CarolResume2015SocialMedia (5).pdf
2017-02-15 19:56 - 2015-12-20 11:38 - 00105550 _____ C:\Users\Carol\Downloads\CarolResume2015SocialMedia (6).pdf
2017-02-15 19:56 - 2015-12-10 23:53 - 00174419 _____ C:\Users\Carol\Downloads\merged_document_4 (1).pdf
2017-02-15 19:56 - 2015-12-10 23:53 - 00067558 _____ C:\Users\Carol\Downloads\CoverletterCarolChuBankview (1).pdf
2017-02-15 19:56 - 2015-12-10 23:52 - 00107948 _____ C:\Users\Carol\Downloads\CarolResume2015General.2-3.pdf
2017-02-15 19:56 - 2015-12-10 23:51 - 00067559 _____ C:\Users\Carol\Downloads\CoverletterCarolChuBankview.pdf
2017-02-15 19:56 - 2015-12-10 22:16 - 00109153 _____ C:\Users\Carol\Downloads\CarolResume2015General.pdf
2017-02-15 19:56 - 2015-12-08 21:23 - 00188230 _____ C:\Users\Carol\Downloads\merged_document_3 (1).pdf
2017-02-15 19:56 - 2015-12-08 21:23 - 00114470 _____ C:\Users\Carol\Downloads\CarolResume2015Volunteer (6).2-3.pdf
2017-02-15 19:56 - 2015-12-08 21:19 - 00074847 _____ C:\Users\Carol\Downloads\CoverletterCarolChuSTARS (1).pdf
2017-02-15 19:56 - 2015-12-08 20:27 - 00115746 _____ C:\Users\Carol\Downloads\CarolResume2015Volunteer (6).pdf
2017-02-15 19:56 - 2015-12-08 19:53 - 00102771 _____ C:\Users\Carol\Downloads\CarolResume2015Volunteer (5).pdf
2017-02-15 19:56 - 2015-12-08 19:53 - 00101072 _____ C:\Users\Carol\Downloads\CarolResume2015Volunteer (5).2-3.pdf
2017-02-15 19:56 - 2015-12-08 19:52 - 00101052 _____ C:\Users\Carol\Downloads\CarolResume2015Volunteer (4).2-3.pdf
2017-02-15 19:56 - 2015-12-08 19:45 - 00077199 _____ C:\Users\Carol\Downloads\CoverletterCarolChuSTARS.pdf
2017-02-15 19:56 - 2015-12-08 19:04 - 00102258 _____ C:\Users\Carol\Downloads\CarolResume2015Volunteer (4).pdf
2017-02-15 19:56 - 2015-12-07 22:48 - 00073772 _____ C:\Users\Carol\Downloads\InvoiceMidnaporeLake (1).pdf
2017-02-15 19:56 - 2015-12-07 22:46 - 00073772 _____ C:\Users\Carol\Downloads\InvoiceMidnaporeLake.pdf
2017-02-15 19:56 - 2015-12-02 16:36 - 00077798 _____ C:\Users\Carol\Downloads\19201104019-474682641-ticket (2).pdf
2017-02-15 19:56 - 2015-12-02 11:29 - 00061667 _____ C:\Users\Carol\Downloads\MidnaporeLakeWaiver (2).1.pdf
2017-02-15 19:56 - 2015-12-02 11:28 - 00062598 _____ C:\Users\Carol\Downloads\MidnaporeLakeWaiver (2).pdf
2017-02-15 19:56 - 2015-12-01 17:20 - 00198779 _____ C:\Users\Carol\Downloads\151130-34153.pdf
2017-02-15 19:56 - 2015-12-01 10:09 - 00060675 _____ C:\Users\Carol\Downloads\MidnaporeLakeWaiver (1).1.pdf
2017-02-15 19:56 - 2015-12-01 10:06 - 00061978 _____ C:\Users\Carol\Downloads\MidnaporeLakeWaiver.pdf
2017-02-15 19:56 - 2015-12-01 10:06 - 00061606 _____ C:\Users\Carol\Downloads\MidnaporeLakeWaiver (1).pdf
2017-02-15 19:56 - 2015-11-30 19:48 - 00077798 _____ C:\Users\Carol\Downloads\19201104019-474682641-ticket (1).pdf
2017-02-15 19:56 - 2015-11-30 19:26 - 00077798 _____ C:\Users\Carol\Downloads\19201104019-474682641-ticket.pdf
2017-02-15 19:56 - 2015-11-30 14:47 - 00148878 _____ C:\Users\Carol\Downloads\GreattoSkateMidnaporeLakeContract (3).pdf
2017-02-15 19:56 - 2015-11-30 14:46 - 00148908 _____ C:\Users\Carol\Downloads\GreattoSkateMidnaporeLakeContract (1).pdf
2017-02-15 19:56 - 2015-11-30 14:46 - 00148878 _____ C:\Users\Carol\Downloads\GreattoSkateMidnaporeLakeContract (2).pdf
2017-02-15 19:56 - 2015-11-29 20:52 - 00147384 _____ C:\Users\Carol\Downloads\GreattoSkateMidnaporeLakeContract.pdf
2017-02-15 19:56 - 2015-11-29 14:46 - 00184708 _____ C:\Users\Carol\Downloads\GreatToSkateContract125 (1).pdf
2017-02-15 19:56 - 2015-11-23 15:45 - 00041850 _____ C:\Users\Carol\Downloads\References (3).pdf
2017-02-15 19:56 - 2015-11-23 15:44 - 00101963 _____ C:\Users\Carol\Downloads\CarolResume2015Volunteer (3).2-3.pdf
2017-02-15 19:56 - 2015-11-23 15:41 - 00103661 _____ C:\Users\Carol\Downloads\CarolResume2015Volunteer (3).pdf
2017-02-15 19:56 - 2015-11-23 15:36 - 00107217 _____ C:\Users\Carol\Downloads\CarolResume2015Volunteer (2).pdf
2017-02-15 19:56 - 2015-11-23 15:35 - 00108906 _____ C:\Users\Carol\Downloads\CarolResume2015Recreation (2).pdf
2017-02-15 19:56 - 2015-11-23 15:23 - 00073764 _____ C:\Users\Carol\Downloads\CoverletterCarolChuCPL.pdf
2017-02-15 19:56 - 2015-11-23 14:04 - 00755090 _____ C:\Users\Carol\Downloads\New Patient Intake Form (2015).pdf
2017-02-15 19:56 - 2015-11-22 16:04 - 00136761 _____ C:\Users\Carol\Downloads\2016CampaignandEventsAssistantPosting_Final.pdf
2017-02-15 19:56 - 2015-11-21 23:27 - 00105825 _____ C:\Users\Carol\Downloads\CarolResume2015Marcomm ARPA.pdf
2017-02-15 19:56 - 2015-11-21 23:23 - 00070930 _____ C:\Users\Carol\Downloads\CoverletterCarolChu(ARPA).pdf
2017-02-15 19:56 - 2015-11-21 21:19 - 00107030 _____ C:\Users\Carol\Downloads\CopyofCarolResume2015Marcomm (2).pdf
2017-02-15 19:56 - 2015-11-21 21:17 - 00107685 _____ C:\Users\Carol\Downloads\CopyofCarolResume2015Marcomm (1).pdf
2017-02-15 19:56 - 2015-11-21 21:16 - 00107886 _____ C:\Users\Carol\Downloads\CopyofCarolResume2015Marcomm.pdf
2017-02-15 19:56 - 2015-11-17 15:31 - 00103260 _____ C:\Users\Carol\Downloads\CarolResume2015Marcomm (7).2-3.pdf
2017-02-15 19:56 - 2015-11-17 15:30 - 00104465 _____ C:\Users\Carol\Downloads\CarolResume2015Marcomm (7).pdf
2017-02-15 19:56 - 2015-11-17 13:46 - 00102211 _____ C:\Users\Carol\Downloads\CarolResume2015SocialMedia (4).2-3.pdf
2017-02-15 19:56 - 2015-11-17 12:43 - 00105428 _____ C:\Users\Carol\Downloads\CarolResume2015SocialMedia (4).pdf
2017-02-15 19:56 - 2015-11-16 21:35 - 00187645 _____ C:\Users\Carol\Downloads\merged_document_2 (2).pdf
2017-02-15 19:56 - 2015-11-16 21:34 - 00114528 _____ C:\Users\Carol\Downloads\CarolResume2015LTS (2).2-3.pdf
2017-02-15 19:56 - 2015-11-16 21:33 - 00115800 _____ C:\Users\Carol\Downloads\CarolResume2015LTS (2).pdf
2017-02-15 19:56 - 2015-11-16 21:29 - 00074208 _____ C:\Users\Carol\Downloads\CoverletterLTSCarolChu.pdf
2017-02-15 19:56 - 2015-11-16 20:22 - 00115805 _____ C:\Users\Carol\Downloads\CarolResume2015LTS (1).pdf
2017-02-15 19:56 - 2015-11-16 20:09 - 00102622 _____ C:\Users\Carol\Downloads\CarolResume2015LTS.pdf
2017-02-15 19:56 - 2015-11-11 21:16 - 00104409 _____ C:\Users\Carol\Downloads\CarolResume2015Marcomm (4iiii) (1).2-3.pdf
2017-02-15 19:56 - 2015-11-11 21:16 - 00104409 _____ C:\Users\Carol\Downloads\CarolResume2015Marcomm (4iiii) (1).2-3 (1).pdf
2017-02-15 19:56 - 2015-11-11 21:15 - 00106314 _____ C:\Users\Carol\Downloads\CarolResume2015Marcomm (4iiii) (1).pdf
2017-02-15 19:56 - 2015-11-11 21:13 - 00068312 _____ C:\Users\Carol\Downloads\Coverletter4iiiCarolChu (1).pdf
2017-02-15 19:56 - 2015-11-11 21:09 - 00068169 _____ C:\Users\Carol\Downloads\Coverletter4iiiCarolChu.pdf
2017-02-15 19:56 - 2015-11-11 18:16 - 00106314 _____ C:\Users\Carol\Downloads\CarolResume2015Marcomm (4iiii).pdf
2017-02-15 19:56 - 2015-11-11 10:36 - 00102187 _____ C:\Users\Carol\Downloads\CarolResume2015SocialMedia (3).2-3.pdf
2017-02-15 19:56 - 2015-11-11 10:23 - 00105404 _____ C:\Users\Carol\Downloads\CarolResume2015SocialMedia (3).pdf
2017-02-15 19:56 - 2015-11-11 10:21 - 00105362 _____ C:\Users\Carol\Downloads\CarolResume2015SocialMedia (2).pdf
2017-02-15 19:56 - 2015-11-11 10:20 - 00105352 _____ C:\Users\Carol\Downloads\CarolResume2015SocialMedia (1).pdf
2017-02-15 19:56 - 2015-11-02 14:37 - 00104038 _____ C:\Users\Carol\Downloads\CarolResume2015Marcomm (6).2-3.pdf
2017-02-15 19:56 - 2015-11-02 14:34 - 00105243 _____ C:\Users\Carol\Downloads\CarolResume2015Marcomm (6).pdf
2017-02-15 19:56 - 2015-11-02 14:30 - 00107485 _____ C:\Users\Carol\Downloads\CarolResume2015Marcomm (5).pdf
2017-02-15 19:56 - 2015-11-02 12:47 - 00076392 _____ C:\Users\Carol\Downloads\CoverletterCarolChuAgaKhan.pdf
2017-02-15 19:56 - 2015-11-02 10:16 - 00102471 _____ C:\Users\Carol\Downloads\CarolResume2015AgaKhan (1).2-3.pdf
2017-02-15 19:56 - 2015-11-02 10:15 - 00104371 _____ C:\Users\Carol\Downloads\CarolResume2015AgaKhan (1).pdf
2017-02-15 19:56 - 2015-11-02 10:14 - 00104252 _____ C:\Users\Carol\Downloads\CarolResume2015AgaKhan.pdf
2017-02-15 19:56 - 2015-11-01 22:21 - 00104967 _____ C:\Users\Carol\Downloads\CarolResume2015CI (2).pdf
2017-02-15 19:56 - 2015-11-01 22:21 - 00103768 _____ C:\Users\Carol\Downloads\CarolResume2015CI (2).2-3.pdf
2017-02-15 19:56 - 2015-11-01 22:16 - 00104995 _____ C:\Users\Carol\Downloads\CarolResume2015CI (1).pdf
2017-02-15 19:56 - 2015-11-01 22:03 - 00103222 _____ C:\Users\Carol\Downloads\CarolResume2015CI.2-3.pdf
2017-02-15 19:56 - 2015-11-01 22:00 - 00104423 _____ C:\Users\Carol\Downloads\CarolResume2015CI.pdf
2017-02-15 19:56 - 2015-11-01 19:03 - 00073662 _____ C:\Users\Carol\Downloads\CoverletterCarolChuStMarys.pdf
2017-02-15 19:56 - 2015-11-01 19:02 - 00101263 _____ C:\Users\Carol\Downloads\CarolResume2015StMarys.2-3.pdf
2017-02-15 19:56 - 2015-11-01 10:19 - 00102469 _____ C:\Users\Carol\Downloads\CarolResume2015StMarys.pdf
2017-02-15 19:56 - 2015-10-30 21:03 - 00101829 _____ C:\Users\Carol\Downloads\CarolResume2015Calgary.2-3.pdf
2017-02-15 19:56 - 2015-10-30 21:02 - 00105045 _____ C:\Users\Carol\Downloads\CarolResume2015Calgary.pdf
2017-02-15 19:56 - 2015-10-30 15:03 - 00105045 _____ C:\Users\Carol\Downloads\CarolResume2015MarcommDigital (4).pdf
2017-02-15 19:56 - 2015-10-30 15:03 - 00101829 _____ C:\Users\Carol\Downloads\CarolResume2015MarcommDigital (4).2-3.pdf
2017-02-15 19:56 - 2015-10-30 15:02 - 00101827 _____ C:\Users\Carol\Downloads\CarolResume2015MarcommDigital (3).2-3.pdf
2017-02-15 19:56 - 2015-10-30 14:58 - 00105043 _____ C:\Users\Carol\Downloads\CarolResume2015MarcommDigital (3).pdf
2017-02-15 19:56 - 2015-10-30 14:57 - 00105049 _____ C:\Users\Carol\Downloads\CarolResume2015MarcommDigital (2).pdf
2017-02-15 19:56 - 2015-10-29 21:20 - 00100544 _____ C:\Users\Carol\Downloads\CarolResume2015Recreation (1).2-3.pdf
2017-02-15 19:56 - 2015-10-29 21:00 - 00101750 _____ C:\Users\Carol\Downloads\CarolResume2015Recreation (1).pdf
2017-02-15 19:56 - 2015-10-29 20:59 - 00074698 _____ C:\Users\Carol\Downloads\CoverletterCarolChuABRecreation.pdf
2017-02-15 19:56 - 2015-10-29 19:51 - 00101805 _____ C:\Users\Carol\Downloads\CarolResume2015Recreation.pdf
2017-02-15 19:56 - 2015-10-29 19:50 - 00101810 _____ C:\Users\Carol\Downloads\CarolResume2015Volunteer (1).pdf
2017-02-15 19:56 - 2015-10-29 13:07 - 00070971 _____ C:\Users\Carol\Downloads\CoverletterCarolChuNaturalFoods.pdf
2017-02-15 19:56 - 2015-10-29 10:09 - 00104963 _____ C:\Users\Carol\Downloads\CarolResume2015SocialMedia.pdf
2017-02-15 19:56 - 2015-10-29 10:09 - 00103762 _____ C:\Users\Carol\Downloads\CarolResume2015SocialMedia.2-3.pdf
2017-02-15 19:56 - 2015-10-28 22:33 - 00167674 _____ C:\Users\Carol\Downloads\merged_document (3).pdf
2017-02-15 19:56 - 2015-10-28 22:33 - 00066026 _____ C:\Users\Carol\Downloads\CoverletterCarolChuCityofCalgaryDigitalCommunications.pdf
2017-02-15 19:56 - 2015-10-28 22:32 - 00102741 _____ C:\Users\Carol\Downloads\CarolResume2015MarcommDigital (1).2-3.pdf
2017-02-15 19:56 - 2015-10-28 22:31 - 00103941 _____ C:\Users\Carol\Downloads\CarolResume2015MarcommDigital (1).pdf
2017-02-15 19:56 - 2015-10-28 21:16 - 00103941 _____ C:\Users\Carol\Downloads\CarolResume2015MarcommDigital.pdf
2017-02-15 19:56 - 2015-10-27 21:35 - 00277887 _____ C:\Users\Carol\Downloads\HOW TO PARTICIPATE.pdf
2017-02-15 19:56 - 2015-10-27 21:33 - 00277887 _____ C:\Users\Carol\Downloads\FB explanantion.pdf
2017-02-15 19:56 - 2015-10-26 21:22 - 00103510 _____ C:\Users\Carol\Downloads\CarolResume2015Benevity (1).2-3.pdf
2017-02-15 19:56 - 2015-10-26 20:35 - 00107867 _____ C:\Users\Carol\Downloads\CarolResume2015Marcomm (4).2-3.pdf
2017-02-15 19:56 - 2015-10-26 20:34 - 00109072 _____ C:\Users\Carol\Downloads\CarolResume2015Marcomm (4).pdf
2017-02-15 19:56 - 2015-10-26 19:33 - 00104711 _____ C:\Users\Carol\Downloads\CarolResume2015Benevity (1).pdf
2017-02-15 19:56 - 2015-10-26 19:31 - 00105350 _____ C:\Users\Carol\Downloads\CarolResume2015Benevity.pdf
2017-02-15 19:56 - 2015-10-15 11:58 - 00112544 _____ C:\Users\Carol\Downloads\convert-jpg-to-pdf.net_2015-10-15_20-58-29.pdf
2017-02-15 19:56 - 2015-10-14 17:12 - 00079908 _____ C:\Users\Carol\Downloads\CoverletterCarolChuTelusSpark (1).pdf
2017-02-15 19:56 - 2015-10-14 16:56 - 00107408 _____ C:\Users\Carol\Downloads\CarolResume2015Volunteer.2-3.pdf
2017-02-15 19:56 - 2015-10-14 16:53 - 00108614 _____ C:\Users\Carol\Downloads\CarolResume2015Volunteer.pdf
2017-02-15 19:56 - 2015-10-14 15:18 - 00077968 _____ C:\Users\Carol\Downloads\CoverletterCarolChuTelusSpark.pdf
2017-02-15 19:56 - 2015-10-09 21:54 - 00109155 _____ C:\Users\Carol\Downloads\CarolResume2015Marcomm (3).pdf
2017-02-15 19:56 - 2015-10-09 15:25 - 00064105 _____ C:\Users\Carol\Downloads\CoverletterCarolChuWM.pdf
2017-02-15 19:56 - 2015-10-09 14:15 - 00072776 _____ C:\Users\Carol\Downloads\CoverletterCarolChuRonaldMc (1).pdf
2017-02-15 19:56 - 2015-10-09 14:11 - 00041850 _____ C:\Users\Carol\Downloads\References (2).pdf
2017-02-15 19:56 - 2015-10-09 14:07 - 00072800 _____ C:\Users\Carol\Downloads\CoverletterCarolChuRonaldMc.pdf
2017-02-15 19:56 - 2015-10-07 14:56 - 00072633 _____ C:\Users\Carol\Downloads\CoverletterCarolChuBetweenFriends.pdf
2017-02-15 19:56 - 2015-10-07 13:45 - 00919088 _____ C:\Users\Carol\Downloads\support-refugees-walk2.pdf
2017-02-15 19:56 - 2015-10-05 15:03 - 00038430 _____ C:\Users\Carol\Downloads\GreattoSkateHolidayCampWaiver.pdf
2017-02-15 19:56 - 2015-10-04 21:51 - 00207217 _____ C:\Users\Carol\Downloads\Order_Canvas_V2.pdf
2017-02-15 19:56 - 2015-10-01 13:58 - 00109155 _____ C:\Users\Carol\Downloads\CarolResume2015Marcomm (2) (1).pdf
2017-02-15 19:56 - 2015-10-01 13:47 - 00066782 _____ C:\Users\Carol\Downloads\CoverletterCarolChuABM.pdf
2017-02-15 19:56 - 2015-09-30 19:51 - 00059100 _____ C:\Users\Carol\Downloads\Untitleddocument (3).pdf
2017-02-15 19:56 - 2015-09-30 19:46 - 00059069 _____ C:\Users\Carol\Downloads\Untitleddocument (2).pdf
2017-02-15 19:56 - 2015-09-30 19:28 - 00057111 _____ C:\Users\Carol\Downloads\Untitleddocument (1).pdf
2017-02-15 19:56 - 2015-09-30 18:51 - 00027054 _____ C:\Users\Carol\Downloads\Untitleddocument.pdf
2017-02-15 19:56 - 2015-09-30 14:16 - 00070080 _____ C:\Users\Carol\Downloads\CoverletterCarolChuVecova.pdf
2017-02-15 19:56 - 2015-09-25 09:24 - 00607079 _____ C:\Users\Carol\Downloads\moraine-shuttle-2015.pdf
2017-02-15 19:56 - 2015-09-24 22:47 - 00066448 _____ C:\Users\Carol\Downloads\CoverletterCarolChuCBCF.pdf
2017-02-15 19:56 - 2015-09-23 10:31 - 07637737 _____ C:\Users\Carol\Downloads\EWB Calgary AGM - updated with finance slides.pptx
2017-02-15 19:56 - 2015-09-22 21:58 - 00108239 _____ C:\Users\Carol\Downloads\CarolResume2015Blend (2).2-3.pdf
2017-02-15 19:56 - 2015-09-22 20:41 - 00184708 _____ C:\Users\Carol\Downloads\GreatToSkateContract125.pdf
2017-02-15 19:56 - 2015-09-22 15:10 - 00109368 _____ C:\Users\Carol\Downloads\CarolResume2015Blend (3).pdf
2017-02-15 19:56 - 2015-09-22 15:08 - 00107950 _____ C:\Users\Carol\Downloads\CarolChuResume2015Marcomm .pdf
2017-02-15 19:56 - 2015-09-22 15:07 - 00109155 _____ C:\Users\Carol\Downloads\CarolResume2015Marcomm (2).pdf
2017-02-15 19:56 - 2015-09-22 15:05 - 00109143 _____ C:\Users\Carol\Downloads\CarolResume2015Marcomm (1).pdf
2017-02-15 19:56 - 2015-09-22 15:02 - 00109444 _____ C:\Users\Carol\Downloads\CarolResume2015Blend (2).pdf
2017-02-15 19:56 - 2015-09-22 15:00 - 00109459 _____ C:\Users\Carol\Downloads\CarolResume2015Blend (1).pdf
2017-02-15 19:56 - 2015-09-22 14:56 - 00110010 _____ C:\Users\Carol\Downloads\CarolResume2015Blend.pdf
2017-02-15 19:56 - 2015-09-22 11:12 - 00072964 _____ C:\Users\Carol\Downloads\CoverletterCarolChuCUPS.pdf
2017-02-15 19:56 - 2015-09-21 21:39 - 00068115 _____ C:\Users\Carol\Downloads\CoverletterCarolChuTheAlex (1).pdf
2017-02-15 19:56 - 2015-09-21 21:34 - 00068183 _____ C:\Users\Carol\Downloads\CoverletterCarolChuTheAlex.pdf
2017-02-15 19:56 - 2015-09-21 14:35 - 00066569 _____ C:\Users\Carol\Downloads\CoverletterCarolChuSAIT.pdf
2017-02-15 19:56 - 2015-09-11 13:58 - 00173346 _____ C:\Users\Carol\Downloads\merged_document (2).pdf
2017-02-15 19:56 - 2015-09-11 13:56 - 00067433 _____ C:\Users\Carol\Downloads\CoverletterCarolChuUofC.pdf
2017-02-15 19:56 - 2015-09-10 21:32 - 00107752 _____ C:\Users\Carol\Downloads\CarolResume2015Events.2-3.pdf
2017-02-15 19:56 - 2015-09-10 21:30 - 00073219 _____ C:\Users\Carol\Downloads\CoverletterCarolChuWellspring.pdf
2017-02-15 19:56 - 2015-09-10 15:08 - 00078727 _____ C:\Users\Carol\Downloads\17812075397-454152947-ticket (2).pdf
2017-02-15 19:56 - 2015-09-10 15:06 - 00078727 _____ C:\Users\Carol\Downloads\17812075397-454152947-ticket.pdf
2017-02-15 19:56 - 2015-09-10 15:06 - 00078248 _____ C:\Users\Carol\Downloads\17812075397-454152947-ticket (1).pdf
2017-02-15 19:56 - 2015-09-10 14:34 - 00109656 _____ C:\Users\Carol\Downloads\CarolResume2015Events.pdf
2017-02-15 19:56 - 2015-09-09 19:59 - 00014917 _____ C:\Users\Carol\Downloads\Calgary Non-Profit Database edited.xlsx
2017-02-15 19:56 - 2015-09-09 19:11 - 00015020 _____ C:\Users\Carol\Downloads\Calgary Non-Profit Database (3).xlsx
2017-02-15 19:56 - 2015-09-08 21:05 - 00168266 _____ C:\Users\Carol\Downloads\combined_document_2.pdf
2017-02-15 19:56 - 2015-09-08 21:05 - 00105047 _____ C:\Users\Carol\Downloads\CarolResume2015Human.2-3.pdf
2017-02-15 19:56 - 2015-09-08 20:57 - 00064307 _____ C:\Users\Carol\Downloads\CoverletterCarolChuYEC.pdf
2017-02-15 19:56 - 2015-09-08 20:30 - 00106252 _____ C:\Users\Carol\Downloads\CarolResume2015Human.pdf
2017-02-15 19:56 - 2015-09-08 14:16 - 00152884 _____ C:\Users\Carol\Downloads\Blank Digital Document.pdf
2017-02-15 19:56 - 2015-09-08 14:16 - 00030145 _____ C:\Users\Carol\Downloads\Blank Digital Document(1).pdf
2017-02-15 19:56 - 2015-09-08 14:15 - 00918262 _____ C:\Users\Carol\Downloads\Blank Print Document(1).pdf
2017-02-15 19:56 - 2015-09-08 14:15 - 00279299 _____ C:\Users\Carol\Downloads\Newsletter.pdf
2017-02-15 19:56 - 2015-09-08 14:12 - 00032075 _____ C:\Users\Carol\Downloads\Smoking(1).pdf
2017-02-15 19:56 - 2015-09-08 14:12 - 00005035 _____ C:\Users\Carol\Downloads\Skate Park(1).pdf
2017-02-15 19:56 - 2015-09-08 14:11 - 00103649 _____ C:\Users\Carol\Downloads\GetGoingSignSummer(1).pdf
2017-02-15 19:56 - 2015-09-08 14:11 - 00007460 _____ C:\Users\Carol\Downloads\Family Fun Day(1).pdf
2017-02-15 19:56 - 2015-09-08 14:00 - 00839422 _____ C:\Users\Carol\Downloads\Get Going May_June pictures.pdf
2017-02-15 19:56 - 2015-09-08 14:00 - 00009913 _____ C:\Users\Carol\Downloads\Blank Print Document.pdf
2017-02-15 19:56 - 2015-09-08 13:59 - 00010083 _____ C:\Users\Carol\Downloads\Equipment List.pdf
2017-02-15 19:56 - 2015-09-08 12:58 - 00173599 _____ C:\Users\Carol\Downloads\ReceiptSChan.pdf
2017-02-15 19:56 - 2015-09-03 14:36 - 00015020 _____ C:\Users\Carol\Downloads\Calgary Non-Profit Database (2).xlsx
2017-02-15 19:56 - 2015-09-02 11:02 - 00173415 _____ C:\Users\Carol\Downloads\ChuC-application-Digital-Coordinator-Specialist-2015.pdf
2017-02-15 19:56 - 2015-09-02 10:56 - 00067506 _____ C:\Users\Carol\Downloads\CoverletterCarolChuPembinaInstitute.pdf
2017-02-15 19:56 - 2015-09-01 07:31 - 00080535 _____ C:\Users\Carol\Downloads\CoverletterCarolChuDucksUnlimited.pdf
2017-02-15 19:56 - 2015-08-31 20:23 - 00084397 _____ C:\Users\Carol\Downloads\CoverletterCarolChuMRU.pdf
2017-02-15 19:56 - 2015-08-31 12:56 - 00082516 _____ C:\Users\Carol\Downloads\CoverletterCarolChuTrico.pdf
2017-02-15 19:56 - 2015-08-31 11:28 - 00107002 _____ C:\Users\Carol\Downloads\CarolResume2015Marcomm.2-3.pdf
2017-02-15 19:56 - 2015-08-31 11:25 - 00108206 _____ C:\Users\Carol\Downloads\CarolResume2015Marcomm.pdf
2017-02-15 19:56 - 2015-08-30 15:20 - 00086103 _____ C:\Users\Carol\Downloads\CoverletterCarolChuWinsport.pdf
2017-02-15 19:56 - 2015-08-30 13:39 - 00106708 _____ C:\Users\Carol\Downloads\CarolResume2015SocialEntrepreneur.2-3.pdf
2017-02-15 19:56 - 2015-08-30 13:38 - 00107907 _____ C:\Users\Carol\Downloads\CarolResume2015SocialEntrepreneur.pdf
2017-02-15 19:56 - 2015-08-26 21:00 - 00014985 _____ C:\Users\Carol\Downloads\Expense statement.xlsx
2017-02-15 19:56 - 2015-08-25 19:02 - 00077795 _____ C:\Users\Carol\Downloads\CoverletterSheratonSuites.pdf
2017-02-15 19:56 - 2015-08-25 18:47 - 00081742 _____ C:\Users\Carol\Downloads\CoverletterCarolChuFairmontBanffSprings (1).pdf
2017-02-15 19:56 - 2015-08-25 18:04 - 00106708 _____ C:\Users\Carol\Downloads\CarolChuResume2014-12Communications (11).2-3.pdf
2017-02-15 19:56 - 2015-08-25 18:02 - 00107907 _____ C:\Users\Carol\Downloads\CarolChuResume2014-12Communications (11).pdf
2017-02-15 19:56 - 2015-08-24 20:31 - 00046756 _____ C:\Users\Carol\Downloads\InvoiceTemplate.pdf
2017-02-15 19:56 - 2015-08-23 22:15 - 00015020 _____ C:\Users\Carol\Downloads\Calgary Non-Profit Database (1).xlsx
2017-02-15 19:56 - 2015-08-23 22:12 - 00015020 _____ C:\Users\Carol\Downloads\Calgary Non-Profit Database.xlsx
2017-02-15 19:56 - 2015-08-22 16:37 - 00560796 _____ C:\Users\Carol\Downloads\20039.pdf
2017-02-15 19:56 - 2015-08-18 11:01 - 00106322 _____ C:\Users\Carol\Downloads\CarolChuResume2014-12Communications (10).2-3.pdf
2017-02-15 19:56 - 2015-08-18 11:00 - 00107520 _____ C:\Users\Carol\Downloads\CarolChuResume2014-12Communications (10).pdf
2017-02-15 19:56 - 2015-08-18 11:00 - 00087415 _____ C:\Users\Carol\Downloads\CarolChuResume2014-12Communications (9).1-2.pdf
2017-02-15 19:56 - 2015-08-18 10:58 - 00107484 _____ C:\Users\Carol\Downloads\CarolChuResume2014-12Communications (9).pdf
2017-02-15 19:56 - 2015-08-17 21:48 - 00364501 _____ C:\Users\Carol\Downloads\TIF Calgary  Aug 26 poster.pdf
2017-02-15 19:56 - 2015-08-17 20:47 - 00251257 _____ C:\Users\Carol\Downloads\fair trade poster r3.pdf
2017-02-15 19:56 - 2015-08-16 14:57 - 04037811 _____ C:\Users\Carol\Downloads\Flames_Player_FunFacts.pdf
2017-02-15 19:56 - 2015-08-15 21:50 - 03390359 _____ C:\Users\Carol\Downloads\F_S_PhysEd_stretching.pdf
2017-02-15 19:56 - 2015-07-16 09:49 - 01805363 _____ C:\Users\Carol\Downloads\What-Sways-Women-To-Play-Sport.pdf
2017-02-15 19:56 - 2015-07-14 21:50 - 00099300 _____ C:\Users\Carol\Downloads\ProgramsTimesheet1-15.pdf
2017-02-15 19:56 - 2015-07-11 15:37 - 06070220 _____ C:\Users\Carol\Downloads\Richmond_Physical_Literacy_Manual.pdf
2017-02-15 19:56 - 2015-06-16 18:04 - 01394688 _____ C:\Users\Carol\Downloads\sample_data-trifon25Apr.xls
2017-02-15 19:56 - 2015-06-09 20:49 - 00927418 _____ C:\Users\Carol\Downloads\Retreat_Registration_Form.xlsx
2017-02-15 19:56 - 2015-06-05 22:45 - 00177636 _____ C:\Users\Carol\Downloads\Wrestling Summer.pdf
2017-02-15 19:56 - 2015-06-05 21:16 - 00020795 _____ C:\Users\Carol\Downloads\DOC001.pdf
2017-02-15 19:56 - 2015-05-26 15:01 - 00034434 _____ C:\Users\Carol\Downloads\GetGoingExpenses - Sheet1 (1).pdf
2017-02-15 19:56 - 2015-05-26 15:00 - 00034430 _____ C:\Users\Carol\Downloads\GetGoingExpenses - Sheet1.pdf
2017-02-15 19:56 - 2015-05-26 13:54 - 00011881 _____ C:\Users\Carol\Downloads\invoiceto.me.pdf
2017-02-15 19:56 - 2015-05-20 20:48 - 00005160 _____ C:\Users\Carol\Downloads\Equipment List (1).xlsx
2017-02-15 19:56 - 2015-05-15 10:47 - 00877852 _____ C:\Users\Carol\Downloads\Brochure 02 (2).pdf
2017-02-15 19:56 - 2015-05-15 00:10 - 00384575 _____ C:\Users\Carol\Downloads\convert-jpg-to-pdf.net_2015-05-15_09-09-53.pdf
2017-02-15 19:56 - 2015-05-13 08:49 - 00019544 _____ C:\Users\Carol\Downloads\Sign in Sheet - Sheet1 (2).pdf
2017-02-15 19:56 - 2015-05-13 08:47 - 00020631 _____ C:\Users\Carol\Downloads\Sign in Sheet - Sheet1 (1).pdf
2017-02-15 19:56 - 2015-05-13 08:43 - 00020624 _____ C:\Users\Carol\Downloads\Sign in Sheet - Sheet1.pdf
2017-02-15 19:56 - 2015-05-13 08:41 - 00004234 _____ C:\Users\Carol\Downloads\Sign in Sheet.xlsx
2017-02-15 19:56 - 2015-05-11 09:48 - 00004816 _____ C:\Users\Carol\Downloads\Equipment List.xlsx
2017-02-15 19:56 - 2015-05-11 09:42 - 00058531 _____ C:\Users\Carol\Downloads\Smoking.pdf
2017-02-15 19:56 - 2015-05-11 09:00 - 00027134 _____ C:\Users\Carol\Downloads\Bike sign.pdf
2017-02-15 19:56 - 2015-05-11 08:20 - 00004718 _____ C:\Users\Carol\Downloads\Skate Park.pdf
2017-02-15 19:56 - 2015-05-11 08:18 - 00004783 _____ C:\Users\Carol\Downloads\At Soccer Fields.pdf
2017-02-15 19:56 - 2015-05-11 08:18 - 00004631 _____ C:\Users\Carol\Downloads\At Playground.pdf
2017-02-15 19:56 - 2015-05-11 08:18 - 00004568 _____ C:\Users\Carol\Downloads\At Tennis Courts.pdf
2017-02-15 19:56 - 2015-05-11 08:11 - 00055346 _____ C:\Users\Carol\Downloads\Wait.pdf
2017-02-15 19:56 - 2015-05-11 08:08 - 00007156 _____ C:\Users\Carol\Downloads\Family Fun Day.pdf
2017-02-15 19:56 - 2015-05-11 08:05 - 00005669 _____ C:\Users\Carol\Downloads\Weather.pdf
2017-02-15 19:56 - 2015-05-11 08:00 - 00102940 _____ C:\Users\Carol\Downloads\GetGoingSignSummer.pdf
2017-02-15 19:56 - 2015-05-11 07:55 - 00102693 _____ C:\Users\Carol\Downloads\Get Going Hut sign.pdf
2017-02-15 19:56 - 2015-05-07 15:07 - 00024522 _____ C:\Users\Carol\Downloads\SimplifiedSchedule.pdf
2017-02-15 19:56 - 2015-05-07 14:54 - 00117639 _____ C:\Users\Carol\Downloads\Waiver.pdf
2017-02-15 19:56 - 2015-05-07 12:30 - 00016432 _____ C:\Users\Carol\Downloads\Blank August 2015 Calendar.xlsx
2017-02-15 19:56 - 2015-05-07 11:56 - 00016065 _____ C:\Users\Carol\Downloads\Blank July 2015 Calendar.xlsx
2017-02-15 19:56 - 2015-05-07 11:55 - 00085672 _____ C:\Users\Carol\Downloads\2015-Monthly-Calendar.xlsx
2017-02-15 19:56 - 2015-05-07 11:06 - 05847809 _____ C:\Users\Carol\Downloads\Brochure 02 (1).pdf
2017-02-15 19:56 - 2015-05-07 10:43 - 05847871 _____ C:\Users\Carol\Downloads\Brochure 02.pdf
2017-02-15 19:56 - 2015-05-06 12:12 - 00015975 _____ C:\Users\Carol\Downloads\June-2015-Calendar.xlsx
2017-02-15 19:56 - 2015-05-05 21:45 - 00016170 _____ C:\Users\Carol\Downloads\May-2015-CalendarGet Going.xlsx
2017-02-15 19:56 - 2015-05-05 20:42 - 00016558 _____ C:\Users\Carol\Downloads\May-2015-Calendar (2).xlsx
2017-02-15 19:56 - 2015-05-05 20:32 - 00016558 _____ C:\Users\Carol\Downloads\May-2015-Calendar (1).xlsx
2017-02-15 19:56 - 2015-05-05 13:43 - 00016558 _____ C:\Users\Carol\Downloads\May-2015-Calendar.xlsx
2017-02-15 19:56 - 2015-05-01 21:47 - 00243545 _____ C:\Users\Carol\Downloads\10-189_H5_Coach_Kit_pages_v2_1_editable.pdf
2017-02-15 19:56 - 2015-03-27 13:57 - 00228977 _____ C:\Users\Carol\Downloads\ReceiptAli.1.pdf
2017-02-15 19:56 - 2015-03-27 13:56 - 00233663 _____ C:\Users\Carol\Downloads\ReceiptAli.pdf
2017-02-15 19:56 - 2015-03-23 08:55 - 00151089 _____ C:\Users\Carol\Downloads\GreattoSkateNigar.1 (1).pdf
2017-02-15 19:56 - 2015-03-23 08:10 - 00151089 _____ C:\Users\Carol\Downloads\GreattoSkateNigar.1.pdf
2017-02-15 19:56 - 2015-03-23 08:09 - 00155806 _____ C:\Users\Carol\Downloads\GreattoSkateNigar (1).pdf
2017-02-15 19:56 - 2015-03-23 08:01 - 00155806 _____ C:\Users\Carol\Downloads\GreattoSkateNigar.pdf
2017-02-15 19:56 - 2015-03-20 20:16 - 25616606 _____ C:\Users\Carol\Downloads\en - CanSkate Manual (1).pdf
2017-02-15 19:56 - 2015-03-20 20:08 - 25616606 _____ C:\Users\Carol\Downloads\en - CanSkate Manual.pdf
2017-02-15 19:56 - 2015-03-13 13:33 - 00167454 _____ C:\Users\Carol\Downloads\GreattoSkateReceiptAyoAug2014 (1).pdf
2017-02-15 19:56 - 2015-03-13 13:32 - 00152171 _____ C:\Users\Carol\Downloads\GreattoSkateReceiptAyoAug2014.pdf
2017-02-15 19:56 - 2015-03-04 12:01 - 00297947 _____ C:\Users\Carol\Downloads\RetailBenefitsDocument.pdf
2017-02-15 19:56 - 2015-03-04 12:01 - 00197516 _____ C:\Users\Carol\Downloads\AssistantShopManager.pdf
2017-02-15 19:56 - 2015-02-25 17:03 - 00259134 _____ C:\Users\Carol\Downloads\combined_document.pdf
2017-02-15 19:56 - 2015-02-25 17:03 - 00079576 _____ C:\Users\Carol\Downloads\CoverletterCarolChuCityofCalgary (3).pdf
2017-02-15 19:56 - 2015-02-25 17:00 - 00180004 _____ C:\Users\Carol\Downloads\CarolChuResume2014-12Communications (8).2-3.pdf
2017-02-15 19:56 - 2015-02-25 15:49 - 00181449 _____ C:\Users\Carol\Downloads\CarolChuResume2014-12Communications (8).pdf
2017-02-15 19:56 - 2015-02-25 15:48 - 00181563 _____ C:\Users\Carol\Downloads\CarolChuResume2014-12Communications (7).pdf
2017-02-15 19:56 - 2015-02-22 13:45 - 00015030 _____ C:\Users\Carol\Downloads\EWB Calgary Chapter Structure 2015 (1).xlsx
2017-02-15 19:56 - 2015-02-18 23:51 - 00200010 _____ C:\Users\Carol\Downloads\merged_document_2 (1).pdf
2017-02-15 19:56 - 2015-02-18 23:50 - 00079368 _____ C:\Users\Carol\Downloads\CoverletterCarolChuCityofCalgary (2).pdf
2017-02-15 19:56 - 2015-02-18 23:49 - 00122072 _____ C:\Users\Carol\Downloads\CarolChuResume2014-12Communications (6).2-4.pdf
2017-02-15 19:56 - 2015-02-18 23:49 - 00121088 _____ C:\Users\Carol\Downloads\CarolChuResume2014-12Communications (6).2-3.pdf
2017-02-15 19:56 - 2015-02-18 19:20 - 00122533 _____ C:\Users\Carol\Downloads\CarolChuResume2014-12Communications (6).pdf
2017-02-15 19:56 - 2015-02-18 19:17 - 00122404 _____ C:\Users\Carol\Downloads\CarolChuResume2014-12Communications (5).pdf
2017-02-15 19:56 - 2015-02-18 18:57 - 00123988 _____ C:\Users\Carol\Downloads\CarolChuResume2014-12Communications (4).pdf
2017-02-15 19:56 - 2015-02-18 18:52 - 00123550 _____ C:\Users\Carol\Downloads\CarolChuResume2014-12Communications (3).pdf
2017-02-15 19:56 - 2015-02-16 16:23 - 17936170 _____ C:\Users\Carol\Downloads\greattoskatepostcard.pdf
2017-02-15 19:56 - 2015-02-11 21:48 - 00079028 _____ C:\Users\Carol\Downloads\CoverletterCarolChuCanadianTireCorporation.pdf
2017-02-15 19:56 - 2015-02-11 20:02 - 00134941 _____ C:\Users\Carol\Downloads\ResumeJS2015.1-2.pdf
2017-02-15 19:56 - 2015-02-11 20:00 - 00122309 _____ C:\Users\Carol\Downloads\ResumeJS2015 (1).pdf
2017-02-15 19:56 - 2015-02-11 19:59 - 00135442 _____ C:\Users\Carol\Downloads\ResumeJS2015.pdf
2017-02-15 19:56 - 2015-02-06 14:00 - 00089939 _____ C:\Users\Carol\Downloads\CoverletterCarolChuCalgaryFoundation.pdf
2017-02-15 19:56 - 2015-02-05 23:34 - 00110973 _____ C:\Users\Carol\Downloads\CarolChuResume2015Communications  (1) (1).pdf
2017-02-15 19:56 - 2015-02-05 23:27 - 00103455 _____ C:\Users\Carol\Downloads\CoverLetterCarolChuCalgaryArts.pdf
2017-02-15 19:56 - 2015-02-05 21:13 - 00210908 _____ C:\Users\Carol\Downloads\merged_document (1).pdf
2017-02-15 19:56 - 2015-02-05 21:12 - 00134387 _____ C:\Users\Carol\Downloads\ResumeCity2015 (1).pdf
2017-02-15 19:56 - 2015-02-05 21:11 - 00134377 _____ C:\Users\Carol\Downloads\ResumeCity2015.pdf
2017-02-15 19:56 - 2015-02-05 21:11 - 00076992 _____ C:\Users\Carol\Downloads\CoverLetterCarolChuCityofCalgary (1).pdf
2017-02-15 19:56 - 2015-02-04 23:24 - 00082294 _____ C:\Users\Carol\Downloads\CoverLetterCarolChuHeritagePark.pdf
2017-02-15 19:56 - 2015-02-04 14:35 - 00040450 _____ C:\Users\Carol\Downloads\References (1).pdf
2017-02-15 19:56 - 2015-02-03 21:58 - 00134524 _____ C:\Users\Carol\Downloads\CopyofCarolChuResume2015HeritagePark (1).pdf
2017-02-15 19:56 - 2015-02-03 21:57 - 00134527 _____ C:\Users\Carol\Downloads\CopyofCarolChuResume2015HeritagePark.pdf
2017-02-15 19:56 - 2015-01-28 09:16 - 00014984 _____ C:\Users\Carol\Downloads\EWB Calgary Chapter Structure 2015.xlsx
2017-02-15 19:56 - 2015-01-27 23:58 - 00200228 _____ C:\Users\Carol\Downloads\merged_document_4.pdf
2017-02-15 19:56 - 2015-01-27 23:58 - 00089808 _____ C:\Users\Carol\Downloads\CoverletterCarolChuServiceLearning.pdf
2017-02-15 19:56 - 2015-01-27 23:55 - 00110866 _____ C:\Users\Carol\Downloads\CarolChuResume2014Volunteer (1).1-2.pdf
2017-02-15 19:56 - 2015-01-27 23:54 - 00073924 _____ C:\Users\Carol\Downloads\CarolChuResume2014Volunteer (1).2-3.pdf
2017-02-15 19:56 - 2015-01-27 19:32 - 00090562 _____ C:\Users\Carol\Downloads\CoverletterCarolChuVolunteerServices.pdf
2017-02-15 19:56 - 2015-01-27 00:00 - 00079581 _____ C:\Users\Carol\Downloads\CoverletterCarolChuCalgaryAirport.pdf
2017-02-15 19:56 - 2015-01-26 13:25 - 00051018 _____ C:\Users\Carol\Downloads\Community Manager Case Study.pdf
2017-02-15 19:56 - 2015-01-23 12:46 - 00105605 _____ C:\Users\Carol\Downloads\skateboardemo.pdf
2017-02-15 19:56 - 2015-01-23 12:43 - 06656994 _____ C:\Users\Carol\Downloads\Skateboard Demosmall.pdf
2017-02-15 19:56 - 2015-01-21 21:47 - 00080531 _____ C:\Users\Carol\Downloads\CoverletterCarolChuGrahamManagementServices.pdf
2017-02-15 19:56 - 2015-01-21 14:56 - 00084177 _____ C:\Users\Carol\Downloads\CoverletterCarolChuWoodsHomes.pdf
2017-02-15 19:56 - 2015-01-20 11:42 - 00080760 _____ C:\Users\Carol\Downloads\CoverletterCarolChuAthabascaUniversity.pdf
2017-02-15 19:56 - 2015-01-17 14:43 - 00110973 _____ C:\Users\Carol\Downloads\CarolChuResume2015Communications  (1)Do not use.pdf
2017-02-15 19:56 - 2015-01-17 14:42 - 00081453 _____ C:\Users\Carol\Downloads\CoverletterCarolChuMoneyMentors.pdf
2017-02-15 19:56 - 2015-01-16 14:44 - 00084255 _____ C:\Users\Carol\Downloads\CoverletterCarolChuAlbertaSocietyofProfessionalBiologists.pdf
2017-02-15 19:56 - 2015-01-14 22:26 - 00083682 _____ C:\Users\Carol\Downloads\CoverletterCarolChuCalgaryGirlsChoir.pdf
2017-02-15 19:56 - 2015-01-13 23:32 - 00111480 _____ C:\Users\Carol\Downloads\CarolChuResume2015Communications BMF.1-2.pdf
2017-02-15 19:56 - 2015-01-13 23:10 - 00084867 _____ C:\Users\Carol\Downloads\CoverletterCarolChuBurnsMemorialFund.pdf
2017-02-15 19:56 - 2015-01-13 23:08 - 00111887 _____ C:\Users\Carol\Downloads\CarolChuResume2015Communications BMF.pdf
2017-02-15 19:56 - 2015-01-13 23:07 - 00111410 _____ C:\Users\Carol\Downloads\CarolChuResume2014-12Communications (2).pdf
2017-02-15 19:56 - 2015-01-13 14:20 - 00114798 _____ C:\Users\Carol\Downloads\CoverletterCarolChuEducationMatters.pdf
2017-02-15 19:56 - 2015-01-13 14:19 - 00110227 _____ C:\Users\Carol\Downloads\CarolChuResume2015Admin (1).pdf
2017-02-15 19:56 - 2015-01-13 14:13 - 00111498 _____ C:\Users\Carol\Downloads\CopyofCarolChuResume2015Admin.pdf
2017-02-15 19:56 - 2015-01-10 23:59 - 00085160 _____ C:\Users\Carol\Downloads\CoverletterCarolChuYMCA.pdf
2017-02-15 19:56 - 2015-01-10 21:53 - 00110973 _____ C:\Users\Carol\Downloads\CarolChuResume2015Communications .pdf
2017-02-15 19:56 - 2014-12-20 22:07 - 00110973 _____ C:\Users\Carol\Downloads\CarolChuResume2014-12Communications (1).pdf
2017-02-15 19:56 - 2014-12-20 22:06 - 00110948 _____ C:\Users\Carol\Downloads\CarolChuResume2014-12Communications.pdf
2017-02-15 19:56 - 2014-12-20 22:01 - 00081790 _____ C:\Users\Carol\Downloads\CoverletterCarolChuUnitedWay.pdf
2017-02-15 19:56 - 2014-12-17 20:32 - 00077646 _____ C:\Users\Carol\Downloads\CoverletterCarolChuHyatt.pdf
2017-02-15 19:56 - 2014-12-15 16:12 - 00187080 _____ C:\Users\Carol\Downloads\merged_document_3.pdf
2017-02-15 19:56 - 2014-12-15 16:10 - 00075526 _____ C:\Users\Carol\Downloads\CoverletterCarolChuCityCommunity.pdf
2017-02-15 19:56 - 2014-12-15 14:40 - 00079098 _____ C:\Users\Carol\Downloads\CoverletterCarolChuShaw.pdf
2017-02-15 19:56 - 2014-12-11 12:39 - 00081742 _____ C:\Users\Carol\Downloads\CoverletterCarolChuFairmontBanffSprings.pdf
2017-02-15 19:56 - 2014-12-09 16:05 - 00084645 _____ C:\Users\Carol\Downloads\CoverletterCarolChuCanadaSportsHallofFame.pdf
2017-02-15 19:56 - 2014-12-09 16:03 - 00112001 _____ C:\Users\Carol\Downloads\CarolChuResume2014-12Sports.1-2.pdf
2017-02-15 19:56 - 2014-12-09 15:52 - 00112944 _____ C:\Users\Carol\Downloads\CarolChuResume2014-12Sports.pdf
2017-02-15 19:56 - 2014-12-09 10:13 - 00079867 _____ C:\Users\Carol\Downloads\Manager of Education and Programming - Job Posting.pdf
2017-02-15 19:56 - 2014-12-08 21:58 - 00082409 _____ C:\Users\Carol\Downloads\CoverletterCarolChuBBBS.pdf
2017-02-15 19:56 - 2014-12-05 21:25 - 00189278 _____ C:\Users\Carol\Downloads\merged_document_2.pdf
2017-02-15 19:56 - 2014-12-05 21:21 - 00079071 _____ C:\Users\Carol\Downloads\CoverletterCarolChuImmigrantServicesCalgary (2).pdf
2017-02-15 19:56 - 2014-12-05 21:21 - 00079071 _____ C:\Users\Carol\Downloads\CoverletterCarolChuCityofCalgary.pdf
2017-02-15 19:56 - 2014-12-04 21:06 - 00111271 _____ C:\Users\Carol\Downloads\CarolChuResume2014liaison.pdf
2017-02-15 19:56 - 2014-12-04 21:06 - 00110866 _____ C:\Users\Carol\Downloads\CarolChuResume2014liaison.1-2.pdf
2017-02-15 19:56 - 2014-12-04 20:56 - 00111271 _____ C:\Users\Carol\Downloads\CarolChuResume2014Volunteer (1).pdf
2017-02-15 19:56 - 2014-12-03 21:47 - 00088192 _____ C:\Users\Carol\Downloads\CoverletterCarolChuImmigrantServicesCalgary (1).pdf
2017-02-15 19:56 - 2014-12-03 21:47 - 00088189 _____ C:\Users\Carol\Downloads\CoverletterCarolChuImmigrantServicesCalgary.pdf
2017-02-15 19:56 - 2014-12-02 15:45 - 00099562 _____ C:\Users\Carol\Downloads\CarolChuResume2014EverActive.1-2.pdf
2017-02-15 19:56 - 2014-12-02 15:41 - 00039606 _____ C:\Users\Carol\Downloads\ReferenceNames.pdf
2017-02-15 19:56 - 2014-12-02 15:40 - 00099914 _____ C:\Users\Carol\Downloads\CarolChuResume2014EverActive.pdf
2017-02-15 19:56 - 2014-12-02 15:39 - 00082924 _____ C:\Users\Carol\Downloads\CoverletterCarolChuEverActiveSchools.pdf
2017-02-15 19:56 - 2014-11-20 15:16 - 00015117 _____ C:\Users\Carol\Downloads\Invoice 1411.pdf
2017-02-15 19:56 - 2014-11-17 11:55 - 00183256 _____ C:\Users\Carol\Downloads\merged_document.pdf
2017-02-15 19:56 - 2014-11-12 20:20 - 00031010 _____ C:\Users\Carol\Downloads\Winter 2015.xlsx
2017-02-15 19:56 - 2014-11-12 08:43 - 00190651 _____ C:\Users\Carol\Downloads\Invoice_Download_25423959_2014_11_07 (2).pdf
2017-02-15 19:56 - 2014-11-12 08:40 - 00190651 _____ C:\Users\Carol\Downloads\Invoice_Download_25423959_2014_11_07 (1).pdf
2017-02-15 19:56 - 2014-11-12 08:35 - 00190748 _____ C:\Users\Carol\Downloads\Invoice_Download_25423959_2014_11_07.pdf
2017-02-15 19:56 - 2014-11-06 10:03 - 00053017 _____ C:\Users\Carol\Downloads\11260918711-367241265-registration (2).pdf
2017-02-15 19:56 - 2014-11-06 09:59 - 00053016 _____ C:\Users\Carol\Downloads\11260918711-367241265-registration (1).pdf
2017-02-15 19:56 - 2014-11-06 09:58 - 00053017 _____ C:\Users\Carol\Downloads\11260918711-367241265-registration.pdf
2017-02-15 19:56 - 2014-11-05 21:37 - 00084411 _____ C:\Users\Carol\Downloads\CoverletterCarolChuYWCA.pdf
2017-02-15 19:56 - 2014-11-02 22:27 - 00084127 _____ C:\Users\Carol\Downloads\CoverletterCarolChuBetweenFriends (1).pdf
2017-02-15 19:56 - 2014-11-02 22:27 - 00084127 _____ C:\Users\Carol\Downloads\CoverletterCarolChuBetweenFriends (1) (1).pdf
2017-02-15 19:56 - 2014-10-30 21:20 - 00013965 _____ C:\Users\Carol\Downloads\Invoice 1410.pdf
2017-02-15 19:56 - 2014-10-30 00:29 - 00030342 _____ C:\Users\Carol\Downloads\DimensionDentistryblurb.pdf
2017-02-15 19:56 - 2014-10-30 00:08 - 00012774 _____ C:\Users\Carol\Downloads\Independent Contractor Agreement-signed.pdf
2017-02-15 19:56 - 2014-10-30 00:06 - 00006791 _____ C:\Users\Carol\Downloads\Independent Contractor Agreement.pdf
2017-02-15 19:56 - 2014-10-23 13:32 - 01224118 _____ C:\Users\Carol\Downloads\Quest Tool 14_24 scanned copy.pdf
2017-02-15 19:56 - 2014-10-14 10:56 - 00768975 _____ C:\Users\Carol\Downloads\USS2014_Poster_FINAL.pdf
2017-02-15 19:56 - 2014-10-07 21:36 - 00088815 _____ C:\Users\Carol\Downloads\CarolChuresumekids (1).pdf
2017-02-15 19:56 - 2014-10-07 14:07 - 00088815 _____ C:\Users\Carol\Downloads\CarolChuresumekids.pdf
2017-02-15 19:56 - 2014-10-06 11:45 - 00013464 _____ C:\Users\Carol\Downloads\Invoice 141 (1).pdf
2017-02-15 19:56 - 2014-10-06 11:43 - 00013464 _____ C:\Users\Carol\Downloads\Invoice 141.pdf
2017-02-15 19:56 - 2014-09-27 19:09 - 00012001 _____ C:\Users\Carol\Downloads\EWB Conference Booth Volunteers List - JessH.xlsx
2017-02-15 19:56 - 2014-09-20 17:18 - 01335168 _____ C:\Users\Carol\Downloads\Jewish Fair Trade Festival Poster.pdf
2017-02-15 19:56 - 2014-09-18 14:38 - 00100420 _____ C:\Users\Carol\Downloads\CarolChuResume2014Communications.1-2.pdf
2017-02-15 19:56 - 2014-09-18 14:38 - 00074056 _____ C:\Users\Carol\Downloads\CarolChuResume2014Communications.2-3.pdf
2017-02-15 19:56 - 2014-09-17 19:39 - 00132393 _____ C:\Users\Carol\Downloads\Carol Chu 2014-signed.pdf
2017-02-15 19:56 - 2014-09-17 19:35 - 00121829 _____ C:\Users\Carol\Downloads\Carol Chu 2014.pdf
2017-02-15 19:56 - 2014-09-09 21:20 - 00080664 _____ C:\Users\Carol\Downloads\CoverletterCarolChuABCRC(1).pdf
2017-02-15 19:56 - 2014-09-09 20:51 - 00079422 _____ C:\Users\Carol\Downloads\CoverletterCarolChuABCRC.pdf
2017-02-15 19:56 - 2014-09-09 19:49 - 00100773 _____ C:\Users\Carol\Downloads\CarolChuResume2014Communications.pdf
2017-02-15 19:56 - 2014-09-09 16:24 - 00040790 _____ C:\Users\Carol\Downloads\References.pdf
2017-02-15 19:56 - 2014-09-09 12:48 - 00097991 _____ C:\Users\Carol\Downloads\CarolChuResume2014Volunteer.pdf
2017-02-15 19:54 - 2014-11-29 20:57 - 00034027 _____ C:\Users\Carol\Documents\Waiver(3).pdf
2017-02-15 19:53 - 2014-11-25 18:12 - 01911917 _____ C:\Users\Carol\Documents\Health Plus- NG combo -132010-signed.pdf
2017-02-15 19:53 - 2014-11-25 18:11 - 01835608 _____ C:\Users\Carol\Documents\Personal Choice Carol-signed.pdf
2017-02-15 17:21 - 2016-07-16 04:47 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed
2017-02-15 17:21 - 2016-07-16 04:47 - 00000000 ____D C:\WINDOWS\system32\Macromed
2017-02-14 13:16 - 2016-07-16 04:45 - 00000000 ____D C:\WINDOWS\INF
2017-02-14 13:16 - 2014-09-14 22:33 - 00000000 ____D C:\ProgramData\McAfee Security Scan
2017-02-14 13:08 - 2016-07-16 04:47 - 00000000 ____D C:\WINDOWS\registration
2017-02-14 12:50 - 2014-09-14 19:16 - 00000000 ____D C:\Program Files (x86)\Amazon
2017-02-14 11:54 - 2016-09-29 08:30 - 00000000 ____D C:\Users\Carol
2017-02-14 11:40 - 2014-09-14 19:13 - 858236030 _____ C:\WINDOWS\MEMORY.DMP
2017-02-14 11:14 - 2014-09-14 19:16 - 00000000 ____D C:\Users\Carol\AppData\Local\VirtualStore
2017-02-06 14:24 - 2014-09-14 19:55 - 00002276 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-02-06 14:24 - 2014-09-14 19:55 - 00002264 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-02-05 11:18 - 2015-11-15 09:51 - 00000000 ____D C:\Program Files\McAfee Security Scan
2017-02-05 11:13 - 2015-06-25 09:02 - 00000666 _____ C:\WINDOWS\Tasks\G2MUploadTask-S-1-5-21-1893927633-78115024-1840190309-1001.job
2017-02-05 11:13 - 2015-06-25 09:02 - 00000570 _____ C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-1893927633-78115024-1840190309-1001.job
2017-01-28 21:49 - 2014-11-29 22:07 - 00000000 ____D C:\Users\Carol\Documents\YYC Fitness
2017-01-28 12:04 - 2016-07-16 04:36 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-01-27 00:07 - 2015-10-26 11:00 - 00000000 ____D C:\Users\Carol\Desktop\YYC Fitness
2017-01-20 22:44 - 2016-12-14 21:49 - 00003266 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task v2
2017-01-20 22:44 - 2015-08-06 07:57 - 00002367 _____ C:\Users\Carol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
 
==================== Files in the root of some directories =======
 
2017-02-14 11:12 - 2017-02-15 20:21 - 0000234 _____ () C:\Users\Carol\AppData\Roaming\4238841256
2017-02-14 11:13 - 2017-02-14 11:13 - 0001088 _____ () C:\Users\Carol\AppData\Roaming\CA9FD-43XXH-ETGGH-TXATX-GHZTO-AFRGT-XFGOY
2017-02-14 11:13 - 2017-02-14 11:13 - 0016715 _____ () C:\Users\Carol\AppData\Roaming\CA9FD-43XXH-ETGGH-TXATX-GHZTO-AFRGT-XFGOY.html
2014-11-04 09:35 - 2014-12-09 09:47 - 0000600 _____ () C:\Users\Carol\AppData\Roaming\winscp.rnd
2015-06-13 21:45 - 2015-10-04 21:07 - 0053248 _____ () C:\Users\Carol\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-11-03 23:06 - 2016-10-03 09:54 - 0000600 _____ () C:\Users\Carol\AppData\Local\PUTTY.RND
2016-03-03 17:08 - 2016-03-03 17:08 - 0000837 _____ () C:\Users\Carol\AppData\Local\recently-used.xbel
2016-09-29 08:26 - 2016-09-29 08:26 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
 
Some files in TEMP:
====================
2016-12-25 12:50 - 2016-12-25 12:50 - 53408320 _____ () C:\Users\Carol\AppData\Local\Temp\D27E.exe
2016-10-27 09:57 - 2016-10-27 09:57 - 0737856 _____ (Oracle Corporation) C:\Users\Carol\AppData\Local\Temp\jre-8u111-windows-au.exe
2017-01-18 18:44 - 2017-01-18 18:44 - 0739904 _____ (Oracle Corporation) C:\Users\Carol\AppData\Local\Temp\jre-8u121-windows-au.exe
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
 
LastRegBack: 2017-02-09 10:55
 
==================== End of FRST.txt ============================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15-02-2017 02
Ran by Carol (16-02-2017 10:21:28)
Running from C:\Users\Carol\Downloads
Windows 10 Home Version 1607 (X64) (2016-09-29 15:59:37)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-1893927633-78115024-1840190309-500 - Administrator - Disabled) => C:\Users\Administrator
Carol (S-1-5-21-1893927633-78115024-1840190309-1001 - Administrator - Enabled) => C:\Users\Carol
DefaultAccount (S-1-5-21-1893927633-78115024-1840190309-503 - Limited - Disabled)
Guest (S-1-5-21-1893927633-78115024-1840190309-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1893927633-78115024-1840190309-1003 - Limited - Enabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AV: AVG Antivirus (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413}
AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG Antivirus (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

abDocs (HKLM-x32\...\{CA4FE8B0-298C-4E5D-A486-F33B126D6A0A}) (Version: 1.04.3005 - Acer Incorporated)
abDocs Office AddIn (HKLM-x32\...\{DCBF3379-246B-47E1-8173-639B63940838}) (Version: 3.01.2002 - Acer Incorporated)
abMedia (HKLM-x32\...\{E9AF1707-3F3A-49E2-8345-4F2D629D0876}) (Version: 2.05.2011.0 - Acer Incorporated)
abPhoto (HKLM-x32\...\{B5AD89F2-03D3-4206-8487-018298007DD0}) (Version: 3.00.2013.0 - Acer Incorporated)
Acer Explorer Agent (HKLM\...\{4D0F42CF-1693-43D9-BDC8-19141D023EE0}) (Version: 2.00.3000 - Acer Incorporated)
Acer Portal (HKLM-x32\...\{A5AD0B17-F34D-49BE-A157-C8B3D52ACD13}) (Version: 3.03.2002 - Acer Incorporated)
Acer Recovery Management (HKLM\...\{07F2005A-8CAC-4A4B-83A2-DA98A722CA61}) (Version: 6.00.8106 - Acer Incorporated)
Acer Remote Files (HKLM\...\{13885028-098C-4799-9B71-27DAC96502D5}) (Version: 1.02.2003 - Acer Incorporated)
Acer User Experience Improvement Program App Monitor Plugin (HKLM\...\{978724F6-1863-4DD5-9E66-FB77F5AB5613}) (Version: 1.01.3003 - Acer Incorporated)
Acer User Experience Improvement Program Framework (HKLM\...\{12A718F2-2357-4D41-9E1F-18583A4745F7}) (Version: 1.01.3003 - Acer Incorporated)
Acer Video Player (HKLM-x32\...\{B6846F20-4821-11E3-8F96-0800200C9A66}) (Version: 1.00.2001.4 - Acer Incorporated)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 14.0.0.178 - Adobe Systems Incorporated)
Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 2.9.0.465 - Adobe Systems Incorporated)
Adobe Dreamweaver CC 2014 (HKLM-x32\...\{7F823F8E-4348-11E4-8BF8-81763C49AA32}) (Version: 15.0.0 - Adobe Systems Incorporated)
Adobe Flash Player 24 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 24.0.0.221 - Adobe Systems Incorporated)
Adobe InDesign CC 2014 (HKLM-x32\...\{CCDCB9C4-72BA-1014-A3F8-D123F2F18BC2}) (Version: 10.1.0.070 - Adobe Systems Incorporated)
Adobe Photoshop CC 2014 (HKLM-x32\...\{D7A4F897-B20A-42D0-862D-CB5F6DB7391D}) (Version: 15.2.2 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.04) MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AB0000000001}) (Version: 11.0.04 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.19) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.19 - Adobe Systems Incorporated)
Adobe® Content Viewer (HKLM-x32\...\com.adobe.dmp.contentviewer) (Version: 3.4.3 - Adobe Systems, Incorporated)
Aloha TriPeaks (x32 Version: 2.2.0.98 - WildTangent) Hidden
Amazon 1Button App (HKLM-x32\...\{0A7D6F3C-F2AB-48ED-BE23-99791BFF87D6}) (Version: 1.0.0.4 - Amazon) <==== ATTENTION
AOP Framework (HKLM-x32\...\{4A37A114-702F-4055-A4B6-16571D4A5353}) (Version: 3.03.2001.0 - Acer Incorporated)
Apple Application Support (32-bit) (HKLM-x32\...\{7FE25256-B7C1-480D-B736-10A67A833AEA}) (Version: 3.2 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\...\{B255D495-4734-4E9B-B4F5-96702FD4A7B9}) (Version: 3.2 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{5D61F006-168C-4B8B-B7FD-F113C10AE0E4}) (Version: 8.2.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
AVG (HKLM\...\AvgZen) (Version: 1.126.2.56387 - AVG Technologies)
AVG Protection (HKLM-x32\...\AVG Antivirus) (Version: 17.1.3006 - AVG Technologies)
AVG Zen (Version: 1.126.7 - AVG Technologies) Hidden
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Citrix Online Launcher (HKLM-x32\...\{8A16C63D-027A-4645-B394-C033665D0195}) (Version: 1.0.325 - Citrix)
Cradle Of Egypt Collector's Edition (x32 Version: 2.2.0.110 - WildTangent) Hidden
CyberLink PowerDVD 12 (HKLM-x32\...\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}) (Version: 12.0.4314.55 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
eBay Worldwide (HKLM-x32\...\{91589413-6675-4C27-8AFC-EFB9103B90A5}) (Version: 2.4.0105 - OEM)
FileZilla Client 3.21.0 (HKLM-x32\...\FileZilla Client) (Version: 3.21.0 - Tim Kosse)
FMW 1 (Version: 1.152.5 - AVG Technologies) Hidden
Game Channels (HKLM-x32\...\WildTangentGameProvider-acer-genres) (Version: 9.2.0.11 - WildTangent, Inc.)
GimpShop 2.8 (HKLM-x32\...\{3F1C9552-58E0-4AAC-A616-AE3A28720EC6}) (Version: 2.8 - GimpShop)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 56.0.2924.87 - Google Inc.)
Google Photos Backup (HKU\S-1-5-21-1893927633-78115024-1840190309-1001\...\Google Photos Backup) (Version: 1.1.2.13 - Google, Inc.)
Google Talk Plugin (HKLM-x32\...\{F9B579C2-D854-300A-BE62-A09EB9D722E4}) (Version: 5.41.3.0 - Google)
Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.8231.2252 - Google Inc.)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.32.7 - Google Inc.) Hidden
GoToMeeting 7.31.0.6291 (HKU\S-1-5-21-1893927633-78115024-1840190309-1001\...\GoToMeeting) (Version: 7.31.0.6291 - CitrixOnline)
Governor of Poker 2 Premium Edition (x32 Version: 2.2.0.110 - WildTangent) Hidden
Gramblr (HKU\S-1-5-21-1893927633-78115024-1840190309-1001\...\Gramblr) (Version: 1.0.0 - Gramblr)
Handy Recovery 5.5 (HKLM-x32\...\{4196D960-68B0-4BEB-B312-3C1B4654068D}) (Version: 5.5 - SoftLogica)
HitmanPro 3.7 (HKLM\...\HitmanPro37) (Version: 3.7.15.281 - SurfRight B.V.)
Hotkey Utility (HKLM-x32\...\{A6DC88AD-501A-44BC-884D-57435F972E2C}) (Version: 3.00.8102 - Acer Incorporated)
Identity Card (HKLM-x32\...\{3D9CB654-99AD-4301-89C6-0D12A790767C}) (Version: 2.00.8101 - Acer Incorporated)
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.13.1706 - Intel Corporation)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 20.19.15.4531 - Intel Corporation)
iTunes (HKLM\...\{93F2A022-6C37-48B8-B241-FFABD9F60C30}) (Version: 12.1.2.27 - Apple Inc.)
Java 8 Update 91 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218091F0}) (Version: 8.0.910.60 - Oracle Corporation)
Junk Mail filter update (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Live Updater (HKLM-x32\...\{EE26E302-876A-48D9-9058-3129E5B99999}) (Version: 2.00.8100 - Acer Incorporated)
Luxor Evolved (x32 Version: 2.2.0.98 - WildTangent) Hidden
Magic Academy (x32 Version: 2.2.0.98 - WildTangent) Hidden
Malwarebytes version 3.0.6.1469 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.0.6.1469 - Malwarebytes)
McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.11.500.3 - McAfee, Inc.)
Microsoft Office Professional Plus 2016 - en-us (HKLM\...\ProPlusRetail - en-us) (Version: 16.0.7571.2109 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1893927633-78115024-1840190309-1001\...\OneDriveSetup.exe) (Version: 17.3.6743.1212 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50901.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Mozilla Firefox 45.0.1 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 45.0.1 (x86 en-US)) (Version: 45.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 45.0.1.5918 - Mozilla)
Nero BackItUp 12 Essentials OEM.a01 (HKLM-x32\...\{551AC8F2-FEA2-4B45-ACF7-C98681233CC9}) (Version: 12.5.01200 - Nero AG)
Office 16 Click-to-Run Extensibility Component (x32 Version: 16.0.7571.2109 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (Version: 16.0.7571.2109 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (Version: 16.0.7571.2109 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (x32 Version: 16.0.7571.2109 - Microsoft Corporation) Hidden
PandoraRecovery (Remove Only) (HKLM-x32\...\PandoraRecovery) (Version: - )
Peggle Nights (x32 Version: 2.2.0.98 - WildTangent) Hidden
PHP 5.4.9 with xDebug 2.2.1 (VC9 Non Thread Safe) (HKLM-x32\...\PHP with xDebug_is1) (Version: 5.4.9 - Blumentals Software)
Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9.141.259 - Google, Inc.)
Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.98 - WildTangent) Hidden
Plotagon (HKLM-x32\...\Plotagon 0.17.0) (Version: 0.17.0 - Plotagon)
Plotagon (x32 Version: 0.17.0 - Plotagon) Hidden
Poedit (HKLM-x32\...\{68EB2C37-083A-4303-B5D8-41FA67E50B8F}_is1) (Version: 1.8.8 - Vaclav Slavik)
Pokki Start Menu (HKU\S-1-5-21-1893927633-78115024-1840190309-1001\...\Pokki_Start_Menu) (Version: 0.269.4.112 - Pokki)
Prerequisite installer (x32 Version: 12.0.0003 - Nero AG) Hidden
Qualcomm Atheros Bluetooth Suite (64) (HKLM\...\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.1.314 - Qualcomm Atheros Communications)
Qualcomm Atheros WLAN and Bluetooth Client Installation Program (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 12.25 - Qualcomm Atheros)
Rapid PHP 2014 v12.3 (HKLM-x32\...\Rapid PHP 2014_is1) (Version: 12.0 - Karlis Blumentals)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.3.3.34 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.18.621.2013 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7535 - Realtek Semiconductor Corp.)
Recuva (HKLM\...\Recuva) (Version: 1.52 - Piriform)
ShadowExplorer 0.9 (HKLM-x32\...\ShadowExplorer_is1) (Version: 0.9.462.0 - ShadowExplorer.com)
Skype Click to Call (HKLM-x32\...\{873F8E7C-10E6-449F-BD7E-5FBA7C8E1C9B}) (Version: 8.5.0.9167 - Microsoft Corporation)
Skype™ 7.26 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.26.101 - Skype Technologies S.A.)
Sparkol VideoScribe (HKLM-x32\...\Sparkol VideoScribe 2.3.2002) (Version: 2.3.2002 - Sparkol)
Sparkol VideoScribe (x32 Version: 2.3.2002 - Sparkol) Hidden
Spotify (HKLM-x32\...\Spotify) (Version: 0.9.6.81.gd359a796 - Spotify AB)
StudioTax 2013 (HKLM-x32\...\{28B28C36-EB35-44CB-9396-C994E927ABA7}) (Version: 9.1.11.1 - BHOK IT Consulting)
StudioTax 2014 (HKLM-x32\...\{9D16247E-27DC-4958-8EDB-599CC041CCB6}) (Version: 10.0.8.0 - BHOK IT Consulting)
StudioTax 2015 (HKLM-x32\...\{10DC0B0F-E7D6-4F37-9CF9-0A76A689AAB0}) (Version: 11.0.8.7 - BHOK IT Consulting)
The Chronicles of Emerland Solitaire (x32 Version: 3.0.2.32 - WildTangent) Hidden
Trinklit Supreme (x32 Version: 2.2.0.98 - WildTangent) Hidden
Update Installer for WildTangent Games App (x32 Version: - WildTangent) Hidden
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
WildTangent Games (HKLM-x32\...\WildTangent wildgames Master Uninstall) (Version: 1.0.4.0 - WildTangent)
WildTangent Games App (x32 Version: 4.0.10.20 - WildTangent) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
WinSCP 5.5.6 (HKLM-x32\...\winscp3_is1) (Version: 5.5.6 - Martin Prikryl)
Zemana AntiMalware (HKLM-x32\...\{8F0CD7D1-42F3-4195-95CD-833578D45057}_is1) (Version: 2.72.101 - Zemana Ltd.)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-1893927633-78115024-1840190309-1001_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\Carol\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1893927633-78115024-1840190309-1001_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\Carol\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1893927633-78115024-1840190309-1001_Classes\CLSID\{590C4387-5EBD-4D46-8A84-CD0BA2EF2856}\InprocServer32 -> C:\Users\Carol\AppData\Local\Google\Update\1.3.30.3\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1893927633-78115024-1840190309-1001_Classes\CLSID\{59B55F04-DE14-4BB8-92FF-C4A22EF2E5F4}\InprocServer32 -> C:\Users\Carol\AppData\Local\Google\Update\1.3.31.5\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1893927633-78115024-1840190309-1001_Classes\CLSID\{5C8C2A98-6133-4EBA-BBCC-34D9EA01FC2E}\InprocServer32 -> C:\Users\Carol\AppData\Local\Google\Update\1.3.28.1\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1893927633-78115024-1840190309-1001_Classes\CLSID\{78550997-5DEF-4A8A-BAF9-D5774E87AC98}\InprocServer32 -> C:\Users\Carol\AppData\Local\Google\Update\1.3.28.13\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1893927633-78115024-1840190309-1001_Classes\CLSID\{793EE463-1304-471C-ADF1-68C2FFB01247}\InprocServer32 -> C:\Users\Carol\AppData\Local\Google\Update\1.3.29.5\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1893927633-78115024-1840190309-1001_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309}\InprocServer32 -> C:\Users\Carol\AppData\Local\Citrix\GoToMeeting\2759\G2MOutlookAddin64.dll (Citrix Online, a division of Citrix Systems, Inc.)
CustomCLSID: HKU\S-1-5-21-1893927633-78115024-1840190309-1001_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\Carol\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1893927633-78115024-1840190309-1001_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\Carol\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1893927633-78115024-1840190309-1001_Classes\CLSID\{CB492AF1-2CEF-4E58-BE47-471C77D0C8BA}\InprocServer32 -> C:\Users\Carol\AppData\Local\Google\Update\1.3.32.7\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1893927633-78115024-1840190309-1001_Classes\CLSID\{CC182BE1-84CE-4A57-B85C-FD4BBDF78CB2}\InprocServer32 -> C:\Users\Carol\AppData\Local\Google\Update\1.3.29.1\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1893927633-78115024-1840190309-1001_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\Carol\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1893927633-78115024-1840190309-1001_Classes\CLSID\{D1EDC4F5-7F4D-4B12-906A-614ECF66DDAF}\InprocServer32 -> C:\Users\Carol\AppData\Local\Google\Update\1.3.28.15\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1893927633-78115024-1840190309-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Carol\AppData\Local\Google\Update\1.3.32.7\psuser_64.dll (Google Inc.)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {04BE28D7-C6F3-49FA-8656-8C36465E5099} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1893927633-78115024-1840190309-1001UA1d257dc39d46a67 => C:\Users\Carol\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {130B2627-F980-4D1F-BDFD-EC43C6F520C1} - System32\Tasks\ALU => C:\Program Files (x86)\Acer\Live Updater\updater.exe [2013-07-08] ()
Task: {14B69308-5A09-4005-AE0F-ECC44F3EF9F1} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {1557F2C7-AD70-4A4F-A2CD-74898D9CA5E0} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {18EDBAD7-3BDE-4B95-8BAB-760D1D5510C7} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2017-01-13] (Microsoft Corporation)
Task: {19B9F8A3-E65A-4F32-ACC0-0A09133EA939} - System32\Tasks\ALUAgent => C:\Program Files (x86)\Acer\Live Updater\liveupdater_agent.exe [2013-01-22] ()
Task: {1D3E4B54-3A06-405F-BCEA-A45FD0D1B646} - System32\Tasks\UbtFrameworkService => C:\Program Files\Acer\User Experience Improvement Program\Framework\TriggerFramework.exe [2014-01-24] (TODO: <Company name>)
Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => %SystemRoot%\System32\AutoWorkplace.exe
Task: {3C6092BE-5C01-4A78-AD54-8D8CAB32756A} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {4F2507FE-D958-4879-9972-81AE86E17441} - System32\Tasks\OneDrive Standalone Update Task => C:\Users\Carol\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\OneDriveStandaloneUpdater.exe
Task: {5103E6B0-5CF5-40BB-9647-4B9433A16897} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2016-12-28] (Microsoft Corporation)
Task: {54EBE034-5BBE-4C7E-9413-3ABD86DB5664} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2016-12-28] (Microsoft Corporation)
Task: {57E46A23-C453-44D4-A3B8-2420FC61DFD6} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {5A93F71E-FF18-4067-A070-4C42B2697A4F} - \WPD\SqmUpload_S-1-5-21-1893927633-78115024-1840190309-1001 -> No File <==== ATTENTION
Task: {6A3A5BBF-731E-46D2-840A-686F36E2B2D1} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {6C7BA903-5FDD-4FC8-99DC-8BBFC87E9116} - System32\Tasks\Recovery Management\Notification => C:\Program Files\Acer\Acer Recovery Management\Notification\Notification.exe [2014-03-18] (Acer Incorporated)
Task: {868214AD-F3DC-4854-BD53-A616A48062D2} - System32\Tasks\Antivirus Emergency Update => C:\Program Files (x86)\AVG\Antivirus\AvEmUpdate.exe [2017-02-16] (AVG Technologies CZ, s.r.o.)
Task: {8CC1CB44-9671-41F4-818C-796DA9AD03AD} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {996D8E13-9D34-44A0-81E1-C8E1D0BE1EE7} - System32\Tasks\McAfee Remediation (Prepare) => C:\Program Files\Common Files\AV\McAfee Anti-Virus And Anti-Spyware\upgrade.exe [2015-06-01] (McAfee, Inc.)
Task: {9A729153-D9CA-4A51-9C06-B226A1179718} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2016-12-28] (Microsoft Corporation)
Task: {A4F469ED-3487-4AA5-947D-44CF605118B7} - System32\Tasks\G2MUpdateTask-S-1-5-21-1893927633-78115024-1840190309-1001 => C:\Users\Carol\AppData\Local\Citrix\GoToMeeting\5573\g2mupdate.exe [2016-09-19] (Citrix Online, a division of Citrix Systems, Inc.)
Task: {A60DC74A-1D02-45FA-8CBF-1310B554B5C0} - System32\Tasks\Hotkey Utility => C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe [2013-12-30] (Acer Incorporated)
Task: {A8C1ABF2-6A3C-48D2-BF8A-4D3936EF0FF4} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1893927633-78115024-1840190309-1001Core => C:\Users\Carol\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {AD41D871-F097-4ECC-A96E-91D0C204DB1E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {B113DDDB-5C9D-478B-9FAA-457B38A80123} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1893927633-78115024-1840190309-1001Core1d257dc39be04bd => C:\Users\Carol\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {B3289E25-E016-4327-B7B8-290364E3CAE1} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {B8E017CB-067D-4C0B-9A20-16F5C276427D} - System32\Tasks\AdobeAAMUpdater-1.0-Chu-Carol => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2014-10-14] (Adobe Systems Incorporated)
Task: {B9834D8D-1024-4F0B-ADDB-DB6DEF5E5B15} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1893927633-78115024-1840190309-1001UA1cfd74f253531e6 => C:\Users\Carol\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {BB67235E-77A1-4EC4-87DE-65583878C207} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {BCE6F242-9F2C-4A9A-B998-D5381F15997F} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-02-15] (Adobe Systems Incorporated)
Task: {C8E1E7FC-058C-4288-82E1-236C40B0BA2E} - \OfficeSoftwareProtectionPlatform\SvcRestartTask -> No File <==== ATTENTION
Task: {CA4DCF95-2E4E-4F29-A539-8DAA8CA65407} - System32\Tasks\AdobeAAMUpdater-1.0-MicrosoftAccount-figureskaterlorac@hotmail.com => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2014-10-14] (Adobe Systems Incorporated)
Task: {D14A75FB-316B-4015-9F19-5332EABFC114} - System32\Tasks\G2MUploadTask-S-1-5-21-1893927633-78115024-1840190309-1001 => C:\Users\Carol\AppData\Local\Citrix\GoToMeeting\5573\g2mupload.exe [2016-09-19] (Citrix Online, a division of Citrix Systems, Inc.)
Task: {D296B47F-1C25-40FF-8D23-975AAA826656} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {E0C98AD0-805F-4165-B2C8-0FF891ACA94F} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2016-12-28] (Microsoft Corporation)
Task: {E8EE9484-F52E-44F6-8358-7A1CE498C090} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-12-19] (Adobe Systems Incorporated)
Task: {EB3F91D1-A172-4D94-B49A-9CA76A48DA0C} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {EB711DAD-1090-4285-BA2A-3643956FC4FD} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {FA5828AB-F2D1-4B61-9773-10357C662FA3} - System32\Tasks\AVG EUpdate Task => avgsetupx.exe
Task: {FC0ED3B0-8878-400E-8905-647E8C403989} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
Task: C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-1893927633-78115024-1840190309-1001.job => C:\Users\Carol\AppData\Local\Citrix\GoToMeeting\6291\g2mupdate.exe
Task: C:\WINDOWS\Tasks\G2MUploadTask-S-1-5-21-1893927633-78115024-1840190309-1001.job => C:\Users\Carol\AppData\Local\Citrix\GoToMeeting\6291\g2mupload.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1893927633-78115024-1840190309-1001Core.job => C:\Users\Carol\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1893927633-78115024-1840190309-1001UA1cfd74f253531e6.job => C:\Users\Carol\AppData\Local\Google\Update\GoogleUpdate.exe

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

==================== Loaded Modules (Whitelisted) ==============

2015-03-20 17:12 - 2015-03-20 17:12 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2015-05-15 15:26 - 2015-05-15 15:26 - 01346344 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2016-07-16 04:42 - 2016-07-16 04:42 - 00231424 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2016-12-13 23:09 - 2016-12-09 03:29 - 02681200 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2016-12-13 23:09 - 2016-12-09 03:29 - 02681200 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2016-12-13 23:09 - 2016-12-09 03:29 - 02681200 _____ () C:\WINDOWS\SYSTEM32\CoreUIComponents.dll
2014-12-19 15:57 - 2014-12-19 15:57 - 01039008 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll
2016-06-24 14:33 - 2016-12-28 10:03 - 08924864 _____ () C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\1033\GrooveIntlResource.dll
2016-05-27 14:50 - 2016-11-01 22:05 - 00401896 _____ () C:\WINDOWS\system32\igfxTray.exe
2016-09-29 10:18 - 2016-09-29 10:18 - 00134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll
2017-01-10 20:25 - 2016-12-21 00:09 - 00474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll
2017-01-10 20:25 - 2016-12-20 23:54 - 09760768 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2017-01-10 20:25 - 2016-12-20 23:48 - 01401856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2017-01-10 20:25 - 2016-12-20 23:48 - 00757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll
2017-01-10 20:25 - 2016-12-20 23:48 - 01033216 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll
2017-01-10 20:25 - 2016-12-20 23:48 - 02424320 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2017-01-10 20:25 - 2016-12-20 23:53 - 04853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2017-02-06 18:08 - 2017-02-06 18:08 - 00073728 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.105.0_x64__kzf8qxf38zg5c\SkypeHost.exe
2017-02-06 18:08 - 2017-02-06 18:08 - 00179712 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.105.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll
2017-02-06 18:08 - 2017-02-06 18:08 - 42895872 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.105.0_x64__kzf8qxf38zg5c\SkyWrap.dll
2017-02-06 18:08 - 2017-02-06 18:08 - 02215424 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.105.0_x64__kzf8qxf38zg5c\roottools.dll
2017-02-16 10:02 - 2017-01-20 07:47 - 02264352 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\PoliciesControllerImpl.dll
2017-02-16 10:02 - 2017-01-20 07:47 - 02829776 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\arwlib.dll
2014-05-16 16:08 - 2013-08-19 11:12 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\ACE.dll
2017-02-16 00:14 - 2017-02-16 00:14 - 48920064 _____ () C:\Program Files (x86)\AVG\UiDll\2623\libcef.dll
2016-09-29 08:32 - 2016-09-29 08:32 - 00015616 _____ () C:\WINDOWS\assembly\GAC_MSIL\MyService\1.0.0.1__2dfa3f50f0bed57d\MyService.dll
2014-11-17 10:57 - 2014-11-17 10:57 - 00013568 _____ () C:\Program Files (x86)\Acer\AOP Framework\ServiceInterface.dll
2014-08-20 16:45 - 2014-08-20 16:45 - 00279296 _____ () C:\Program Files (x86)\Acer\AcerCloud Docs\libcurl.dll
2014-09-16 09:15 - 2014-09-16 09:15 - 00203008 _____ () C:\Program Files (x86)\Acer\abPhoto\curllib.dll
2014-09-16 09:16 - 2014-09-16 09:16 - 00630528 _____ () C:\Program Files (x86)\Acer\abPhoto\tag.dll
2014-09-16 09:16 - 2014-09-16 09:16 - 00654552 _____ () C:\Program Files (x86)\Acer\abPhoto\sqlite3.dll
2014-09-16 09:16 - 2014-09-16 09:16 - 00119552 _____ () C:\Program Files (x86)\Acer\abPhoto\OpenLDAP.dll
2017-02-16 00:17 - 2017-02-16 00:17 - 00171208 _____ () C:\Program Files (x86)\AVG\Antivirus\JsonRpcServer.dll
2017-02-16 00:17 - 2017-02-16 00:17 - 48936448 _____ () C:\Program Files (x86)\AVG\Antivirus\libcef.dll
2017-02-16 00:17 - 2017-02-16 00:17 - 00656040 _____ () C:\Program Files (x86)\AVG\Antivirus\ffl2.dll
2017-02-06 14:24 - 2017-02-01 02:01 - 01870168 _____ () C:\Program Files (x86)\Google\Chrome\Application\56.0.2924.87\libglesv2.dll
2017-02-06 14:24 - 2017-02-01 02:01 - 00085848 _____ () C:\Program Files (x86)\Google\Chrome\Application\56.0.2924.87\libegl.dll
2014-05-16 16:22 - 2014-01-03 14:13 - 00090368 _____ () C:\Program Files (x86)\Acer\clear.fi plug-in\Clearfishellext.dll
2016-08-23 06:05 - 2016-08-23 06:05 - 00048304 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2013-08-22 06:25 - 2017-02-15 21:55 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\AvGeneric_S-1-5-21-1893927633-78115024-1840190309-500\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Windows\img0.jpg
HKU\S-1-5-21-1893927633-78115024-1840190309-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\acer01.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

HKLM\...\StartupApproved\Run32: => "Adobe Creative Cloud"
HKU\S-1-5-21-1893927633-78115024-1840190309-1001\...\StartupApproved\Run: => "msnmsgr"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{3856F056-5C5A-451D-ADD2-7A8109FC78C8}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe
FirewallRules: [{5F1F2DF8-6171-4266-9C1A-F5D619208393}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{B16C3506-ED98-4386-BFB4-0CE1BC02C0D1}] => (Allow) C:\Program Files (x86)\Ubisoft\Your Shape\YourShape.exe
FirewallRules: [{89A32F29-0B3C-4D68-A1E4-2436824D5E37}] => (Allow) C:\Program Files (x86)\Ubisoft\Your Shape\YourShape.exe
FirewallRules: [{7498F481-1022-4FB3-83FB-FF45BE449F0E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{A894E0A4-B724-4D13-9E9A-C327C559B3B9}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{FB659721-6517-4AF2-BCE8-512C87624F0C}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{BA15BE71-3F07-48E6-AE70-6DE7A09BF795}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{5DA70CD8-6C1F-4CB7-960B-4E5C134F7849}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{4F0768D1-0C60-4723-832E-7234632A3B0D}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{9694F65F-B4EE-4C53-B01C-BE6E4739509B}] => (Allow) C:\Program Files (x86)\FileZilla FTP Client\filezilla.exe
FirewallRules: [{1A255C1A-A125-44AC-AFC5-B309867FA168}] => (Allow) C:\Program Files (x86)\FileZilla FTP Client\filezilla.exe
FirewallRules: [{58C482BE-1665-46FB-868E-CFD139132106}] => (Allow) C:\Program Files (x86)\FileZilla FTP Client\filezilla.exe
FirewallRules: [{552BD309-C0A3-4803-80EC-EC5E800318E3}] => (Allow) C:\Program Files (x86)\FileZilla FTP Client\filezilla.exe
FirewallRules: [{9C8C4371-BE63-429F-A45A-D498465F3B77}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{2160C316-118A-4DBC-8C19-E9772AA207F9}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{7D60FA56-B30D-4712-B68B-6A0B0E61B837}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{D0B1E5F3-B08C-4E83-9DCF-C0026E8764B7}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{50B1862C-10FA-49E8-ACD5-1BBC12A36998}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{27504280-9DF3-4C13-ADF7-0928C5E18CB3}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{6071C3B8-C75F-4B7F-9043-2FECF0F10C2E}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{D37D81FE-0DA0-476C-B818-DA1EBE1E2F27}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{64077B2A-CDA1-497D-AC44-BA8F552F8560}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\WindowsUpnpMV.exe
FirewallRules: [{3D503388-BBAB-46D9-AEE1-7C451540F614}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\WindowsUpnpMV.exe
FirewallRules: [{559C6551-FE41-47C2-9401-C26C58863629}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\DMCDaemon.exe
FirewallRules: [{3496B3D1-5880-4052-8BF9-BE4490F3A6F5}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\DMCDaemon.exe
FirewallRules: [{C35CC333-BA00-49F5-B319-3FBDD8876E33}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\WindowsUpnpMV.exe
FirewallRules: [{D1320B14-218B-447A-8974-97091BCB0BC1}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\WindowsUpnpMV.exe
FirewallRules: [{C163D89B-6675-4D9D-A03E-6077EDC3B19E}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\DMCDaemon.exe
FirewallRules: [{738F5519-08AC-4A05-A3DF-BBA54A0C37FD}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\DMCDaemon.exe
FirewallRules: [{0F737E32-9A67-473D-8028-C5C2C721CAA1}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{EA512CE7-26CB-492A-A560-DFB08C368A09}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{31542131-9423-45CB-8B3F-91E16B58F3F2}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{EBB7D7E1-E8AE-4D39-80FB-C13280A2144C}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{5F28CF02-071D-44F8-B665-10271F9A7D9C}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{89047C60-33AC-47A3-BC90-7C868F53AAE4}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{D406895C-E3B9-4BAD-A3C2-30B3652E69A3}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{CC856095-0B72-4F90-951F-34CF299F9AE2}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{BF44B1DF-381E-45E3-9117-3897B3FBB7F4}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\WindowsUpnpMV.exe
FirewallRules: [{995122A1-041B-4E16-906E-445B09DCA42D}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\WindowsUpnpMV.exe
FirewallRules: [{A5193DF2-BDCB-414E-AECC-52A143BB67D4}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\DMCDaemon.exe
FirewallRules: [{FE9DE26C-ADFC-46B9-B249-30ABA9B359C4}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\DMCDaemon.exe
FirewallRules: [{C86C9D3B-E2BC-487C-BF00-8E77C8F3CDB7}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\WindowsUpnpMV.exe
FirewallRules: [{248CDBA4-B724-4C9A-B8C7-AD6771AE5107}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\WindowsUpnpMV.exe
FirewallRules: [{EEFFDE89-CED0-47F8-948B-9919DC91D509}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\DMCDaemon.exe
FirewallRules: [{E5E63805-A641-4AA1-B7FF-0DA5E6E21359}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\DMCDaemon.exe
FirewallRules: [UDP Query User{D502F8CC-B274-46BC-9A7A-14AD074F5106}C:\users\carol\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\carol\appdata\roaming\spotify\spotify.exe
FirewallRules: [TCP Query User{1159713E-4780-45A3-A818-DD160957EA92}C:\users\carol\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\carol\appdata\roaming\spotify\spotify.exe
FirewallRules: [{ED3E1574-9FC4-43E7-AE7C-32A3C4B4CC54}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{7F191F42-3C91-4157-A0E9-E2A20F3F54A6}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{D612D267-D52E-4BD1-9943-F1F0860FC0A9}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{04A3AB86-8698-4599-AB56-99FBDFAA592B}] => (Allow) LPort=1900
FirewallRules: [{B8B321DF-7981-40DD-866B-EE192C3025B7}] => (Allow) LPort=2869
FirewallRules: [{C773A19B-9979-4450-9C16-52ACB96E60D9}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{11EBED88-CB4D-4A2B-97E7-36F28A4AE2CE}] => (Allow) C:\Users\Carol\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
FirewallRules: [{00B979B6-FED5-48F9-9BDF-A60A2A6E50CE}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{A347C966-EE53-4404-A8A8-DFE23194A7EC}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{02D34392-D75D-4480-B57D-2C261A3999F4}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{D320A32D-EEE9-49E2-960E-2A7CB68C3E27}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{0E88E061-93D8-4155-8FCF-0BF2B2EEBBB7}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{F46982E8-98AC-4CEA-9111-A26617BAB6A1}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{E9E287CE-5106-4F6A-BF66-865C122DCA76}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{9C50550D-070D-416D-95F4-CF4FC6A76663}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{C19C6DF7-2228-4C06-9A1A-636721D0E3A8}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\WindowsUpnpMV.exe
FirewallRules: [{EC5C4750-32D1-46DD-82EE-30997B1505CA}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\WindowsUpnpMV.exe
FirewallRules: [{B4519C9F-54BD-4E41-A922-616120A57656}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\DMCDaemon.exe
FirewallRules: [{7F7EA96C-4F4A-4E6B-82E1-F6492A8777D2}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\DMCDaemon.exe
FirewallRules: [{488A1A52-5582-441B-82BF-7D6C509120B6}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\WindowsUpnpMV.exe
FirewallRules: [{38B4F46E-ED5C-4C87-9192-73EC71393F5C}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\WindowsUpnpMV.exe
FirewallRules: [{928FE5FB-DB3B-4C77-83FB-018E26F11032}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\DMCDaemon.exe
FirewallRules: [{080E3B6E-6A0A-4D18-B89D-5C4C03E1C259}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\DMCDaemon.exe
FirewallRules: [{DEE3B499-1DBD-4CDE-A3CA-C9B77579D0DF}] => (Allow) C:\Program Files (x86)\Acer\Acer Portal\ccd.exe
FirewallRules: [{BED84033-9105-43DF-95A0-316EC4FF074A}] => (Allow) C:\Program Files (x86)\Acer\Acer Portal\ccd.exe
FirewallRules: [{4160AA2B-F3A6-43E9-819A-7F60F16114A4}] => (Allow) C:\Program Files (x86)\Acer\Acer Portal\virtualdrive.exe
FirewallRules: [{4D166D35-674A-4EF7-BE50-2CE35D2BBC63}] => (Allow) C:\Program Files (x86)\Acer\Acer Portal\virtualdrive.exe
FirewallRules: [{7CFB4179-773E-4717-850D-AC9F960F0F5D}] => (Allow) C:\Program Files (x86)\Acer\Acer Portal\Sdd.exe
FirewallRules: [{329726E1-2954-419A-943F-A9EB6C068758}] => (Allow) C:\Program Files (x86)\Acer\Acer Portal\Sdd.exe
FirewallRules: [{47A50AB0-4723-4AD0-975B-7467723621D4}] => (Allow) C:\Program Files (x86)\Acer\Acer Portal\ccd.exe
FirewallRules: [{48B13EF3-871D-4284-9D95-FE7024841C5C}] => (Allow) C:\Program Files (x86)\Acer\Acer Portal\ccd.exe
FirewallRules: [{76224E3F-07EA-4D40-A9FD-A830370AA6AA}] => (Allow) C:\Program Files (x86)\Acer\Acer Photo\WindowsUpnp.exe
FirewallRules: [{5A3C6713-4FE6-4F89-94A4-965CE78A3682}] => (Allow) C:\Program Files (x86)\Acer\Acer Photo\WindowsUpnp.exe
FirewallRules: [{8CC9BD91-A6DC-4BC1-8364-33604FACA02F}] => (Allow) C:\Program Files (x86)\Acer\Acer Photo\DMCDaemon.exe
FirewallRules: [{761EBEBC-1867-43F0-8247-21C5F3CA1180}] => (Allow) C:\Program Files (x86)\Acer\Acer Photo\DMCDaemon.exe
FirewallRules: [{29228B0B-B594-4587-9869-084050E735A3}] => (Allow) C:\Program Files (x86)\Acer\Acer Photo\WindowsUpnp.exe
FirewallRules: [{06327C56-0905-4D7C-BC0C-48260B424682}] => (Allow) C:\Program Files (x86)\Acer\Acer Photo\WindowsUpnp.exe
FirewallRules: [{0358F5A9-E30C-4263-A63B-9BA38E7F987A}] => (Allow) C:\Program Files (x86)\Acer\Acer Photo\DMCDaemon.exe
FirewallRules: [{8B1E65AA-DE42-474D-BC9E-F26E2E5D27EC}] => (Allow) C:\Program Files (x86)\Acer\Acer Photo\DMCDaemon.exe
FirewallRules: [{D40AC7CD-9EED-4F86-9E82-115398A24C61}] => (Allow) C:\Program Files (x86)\Acer\Acer Media\WindowsUpnpMV.exe
FirewallRules: [{E1FD1609-EB68-4EC5-87BC-44F33BA2D357}] => (Allow) C:\Program Files (x86)\Acer\Acer Media\WindowsUpnpMV.exe
FirewallRules: [{28B22635-AC4C-4045-9E1D-C5D484820142}] => (Allow) C:\Program Files (x86)\Acer\Acer Media\DMCDaemon.exe
FirewallRules: [{7C655462-7A45-497F-B3C5-96639ADB6479}] => (Allow) C:\Program Files (x86)\Acer\Acer Media\DMCDaemon.exe
FirewallRules: [{2A9E51A8-F6FE-43B2-9456-3EC16A9719EC}] => (Allow) C:\Program Files (x86)\Acer\Acer Media\WindowsUpnpMV.exe
FirewallRules: [{5425F257-78CD-46D9-ABAD-B2A52B7A1A03}] => (Allow) C:\Program Files (x86)\Acer\Acer Media\WindowsUpnpMV.exe
FirewallRules: [{FC7DFB33-86B9-47D2-AC1C-CCA2BD9A1362}] => (Allow) C:\Program Files (x86)\Acer\Acer Media\DMCDaemon.exe
FirewallRules: [{C29F2482-B794-4673-AC0B-6AD68314B25B}] => (Allow) C:\Program Files (x86)\Acer\Acer Media\DMCDaemon.exe
FirewallRules: [{A3F0D979-C5FF-45DD-92BB-14E7AAB75FAB}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\Movie\PowerDVD.exe
FirewallRules: [{4BF50A45-49DB-4337-A31B-78EB647DDBF9}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12ML.exe
FirewallRules: [{49C712B6-395F-40FE-8A68-AFF006DE1A0F}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12Agent.exe
FirewallRules: [{C2FCF49F-5FB5-4154-AD15-507BBFFC0008}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe
FirewallRules: [{14D86FDF-7AFB-47A9-8239-917E3DBF95FB}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMR\PowerDVD12DMREngine.exe
FirewallRules: [{90C25B62-D8F8-4196-BE1D-042069ABA607}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12.exe
FirewallRules: [{25F785BC-5FB2-438F-8EBD-80D3DBDF2E6D}] => (Allow) C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe
FirewallRules: [{59C33720-2C50-49B6-B32A-259D13A80311}] => (Allow) C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe
FirewallRules: [{906FE9FB-CFD5-403C-A769-07E6DE93C835}] => (Allow) C:\Program Files (x86)\Spotify\spotify.exe
FirewallRules: [{B662CA88-CA5E-4EA2-A730-69827EACD2DC}] => (Allow) C:\Program Files (x86)\Spotify\spotify.exe
FirewallRules: [{D85C7AE4-5AA5-47CC-B60A-A30A900E7885}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{267B4964-5880-49C0-BB58-A6AC28520179}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{AB948F10-9A91-4328-B7A1-914127CFA8B4}] => (Allow) C:\Program Files (x86)\Nero\Nero 12\Nero BackItUp\BackItUp.exe
FirewallRules: [{29CE96CD-A7A0-410A-8A31-EFFED185FF26}] => (Allow) C:\Program Files (x86)\Nero\Nero 12\Nero BackItUp\BackItUp.exe
FirewallRules: [TCP Query User{CAD174E9-8708-4E44-8A29-97E8F98E5212}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [UDP Query User{88FB4FD3-5201-449D-B1E4-7E144F729986}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [{18DB65C9-B896-44EA-A747-D2E025FDDC11}] => (Block) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [{06443F07-8E6A-42A2-9813-E6927B1DE3DB}] => (Block) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [TCP Query User{D4C5242D-4E76-461D-A7A8-89E3ECFA921B}C:\users\carol\appdata\local\popcorn time\nw.exe] => (Allow) C:\users\carol\appdata\local\popcorn time\nw.exe
FirewallRules: [UDP Query User{6B3FB498-EFBF-4D57-AA51-B17F46B40090}C:\users\carol\appdata\local\popcorn time\nw.exe] => (Allow) C:\users\carol\appdata\local\popcorn time\nw.exe
FirewallRules: [TCP Query User{CC4E6915-EBD7-4815-9AF6-F5B6EEAC148C}C:\program files (x86)\acer\abphoto\dmcdaemon.exe] => (Block) C:\program files (x86)\acer\abphoto\dmcdaemon.exe
FirewallRules: [UDP Query User{F0EADAE2-392D-4B2E-8B83-C115B048F6E2}C:\program files (x86)\acer\abphoto\dmcdaemon.exe] => (Block) C:\program files (x86)\acer\abphoto\dmcdaemon.exe
FirewallRules: [TCP Query User{44E3ED3F-D877-495C-B043-AFAA069615AC}C:\program files (x86)\acer\abphoto\windowsupnp.exe] => (Allow) C:\program files (x86)\acer\abphoto\windowsupnp.exe
FirewallRules: [UDP Query User{C2DAE9D9-04E4-494A-BEFB-4495A26D7C5E}C:\program files (x86)\acer\abphoto\windowsupnp.exe] => (Allow) C:\program files (x86)\acer\abphoto\windowsupnp.exe
FirewallRules: [TCP Query User{B7C00EA3-4734-46E8-A882-19329372CEFA}C:\users\carol\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\carol\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{BA2C7712-2291-4494-B51B-FB4E53967D56}C:\users\carol\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\carol\appdata\roaming\spotify\spotify.exe
FirewallRules: [{BAED756A-E366-4C56-9653-147549C766B9}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{4FC0DA39-E176-4E3A-9E39-D40BE1F34EEB}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{078046FE-A7CD-4F83-AE03-49176F23F6B9}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [{8CEF97B7-8225-44A3-AD16-DCE391DD0F76}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [{A2176A90-9F6C-46FE-9FDA-14EADAD2EEB6}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Restore Points =========================

14-02-2017 12:11:01 Scheduled Checkpoint
14-02-2017 13:03:29 Restore Operation

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (02/16/2017 09:35:54 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: svchost.exe_TimeBrokerSvc, version: 10.0.14393.0, time stamp: 0x57899b1c
Faulting module name: combase.dll, version: 10.0.14393.576, time stamp: 0x584a7796
Exception code: 0xc0000005
Fault offset: 0x00000000000b071c
Faulting process id: 0x420
Faulting application start time: 0x01d2881106af95ae
Faulting application path: C:\WINDOWS\System32\svchost.exe
Faulting module path: C:\WINDOWS\System32\combase.dll
Report Id: ff0e1657-30f6-4661-a33d-1917dbf8a850
Faulting package full name:
Faulting package-relative application ID:

Error: (02/16/2017 12:41:50 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 31297

Error: (02/16/2017 12:41:50 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 31297

Error: (02/16/2017 12:41:50 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (02/16/2017 12:41:35 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 15782

Error: (02/16/2017 12:41:35 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 15782

Error: (02/16/2017 12:41:35 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (02/16/2017 12:23:17 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.

System Error:
Access is denied.
.

Error: (02/16/2017 12:19:10 AM) (Source: SideBySide) (EventID: 35) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest".Error in manifest or policy file "C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL" on line 1.
Component identity found in manifest does not match the identity of the component requested.
Reference is UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0".
Definition is UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0".
Please use sxstrace.exe for detailed diagnosis.

Error: (02/16/2017 12:18:13 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\AVG\Antivirus\setup\iplugins\IStats.dll".
Dependent Assembly Avast.VC110.CRT,processorArchitecture="x86",publicKeyToken="2036b14a11e83e4a",type="win32",version="11.0.60610.1" could not be found.
Please use sxstrace.exe for detailed diagnosis.


System errors:
=============
Error: (02/16/2017 09:38:36 AM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Time Broker service, but this action failed with the following error:
An instance of the service is already running.

Error: (02/16/2017 09:36:36 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Security Center service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.

Error: (02/16/2017 09:36:36 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Time Broker service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.

Error: (02/16/2017 09:36:36 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The TCP/IP NetBIOS Helper service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 100 milliseconds: Restart the service.

Error: (02/16/2017 09:36:36 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Event Log service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.

Error: (02/16/2017 09:36:36 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The DHCP Client service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.

Error: (02/16/2017 09:28:26 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
and APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (02/16/2017 09:28:26 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
and APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (02/16/2017 09:28:26 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
and APPID
{F72671A9-012C-4725-9D2F-2A4D32D65169}
to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (02/16/2017 12:40:59 AM) (Source: DCOM) (EventID: 10010) (User: CHU)
Description: The server {0002DF02-0000-0000-C000-000000000046} did not register with DCOM within the required timeout.


CodeIntegrity:
===================================
Date: 2017-02-16 10:03:08.868
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements.

Date: 2017-02-15 20:32:00.657
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements.

Date: 2017-02-15 20:32:00.657
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements.

Date: 2017-02-15 20:32:00.657
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements.

Date: 2017-02-15 20:32:00.657
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements.

Date: 2017-02-15 20:32:00.657
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements.

Date: 2017-02-15 20:32:00.657
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements.

Date: 2017-02-15 18:30:58.948
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2017-02-15 18:30:58.939
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2017-02-15 18:30:58.561
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.


==================== Memory info ===========================

Processor: Intel® Core™ i5-4460 CPU @ 3.20GHz
Percentage of memory in use: 57%
Total physical RAM: 8001.34 MB
Available physical RAM: 3382.31 MB
Total Virtual: 21313.34 MB
Available Virtual: 16105.07 MB

==================== Drives ================================

Drive c: (Acer) (Fixed) (Total:914.01 GB) (Free:672.17 GB) NTFS
Drive d: (SPIVS) (CDROM) (Total:4.01 GB) (Free:0 GB) UDF

==================== MBR & Partition Table ==================

==================== End of Addition.txt ============================

Attached Files


Edited by Oh My!, 16 February 2017 - 02:46 PM.


BC AdBot (Login to Remove)

 


#2 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,997 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:08:07 PM

Posted 16 February 2017 - 12:59 PM

Greetings csquared and :welcome: to BleepingComputer's Virus/Trojan/Spyware/Malware Removal forum.

My name is Oh My! and I am here to help you! Now that we are "friends" please call me Gary.

If you would allow me to call you by your first name I would prefer to do that.

===================================================

Ground Rules:
  • First, I would like to inform you that most of us here at Bleeping Computer offer our expert assistance out of the goodness of our hearts. Please try to match our commitment to you with your patience toward us. If this was easy we would never have met.
  • Please do not run any tools or take any steps other than those I will provide for you while we work on your computer together. I need to be certain about the state of your computer in order to provide appropriate and effective steps for you to take. Most often "well intentioned" (and usually panic driven!) independent efforts can make things much worse for both of us. If at any point you would prefer to take your own steps please let me know, I will not be offended. I would be happy to focus on the many others who are waiting in line for assistance.
  • Please perform all steps in the order they are listed in each set of instructions. Some steps may be a bit complicated. If things are not clear, be sure to stop and let me know. We need to work on this together with confidence.
  • Please copy and paste all logs into your post unless directed otherwise. Please do not re-run any programs I suggest. If you encounter problems simply stop and tell me.
  • When you post your reply, use the Replytopic.jpg button instead.
  • In the upper right hand corner of the topic you will see the Followtopic.jpg button. Click on this then choose Immediate E-Mail notification and then Proceed and you will be sent an email once I have posted a response.
  • If you do not reply to your topic after 5 days we assume it has been abandoned and I will close it.
  • When your computer is clean I will alert you of such. I will also provide for you detailed information about how you can combat future infections.
  • I would like to remind you to make no further changes to your computer unless I direct you to do so.
===================================================

Now that I am assisting you, you can expect that I will be very responsive to your situation. If you are able, I would request you check this thread at least once per day so that we can try to resolve your issues effectively and efficiently. If you are going to be delayed please be considerate and post that information so that I know you are still with me. Unfortunately, there are many people waiting to be assisted and not enough of us at BleepingComputer to go around. I appreciate your understanding and diligence.

Thank you for your patience thus far. Please allow me just a bit of time to review what you have posted.
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#3 RayS

RayS

  • Malware Response Team
  • 2,434 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:11:07 PM

Posted 19 February 2017 - 10:48 AM

Hi csquared,

Please call me "Ray". If you would permit me to call you by your first name, please tell it to me.

Gary, who is a Malware Response Instructor, has made this topic available to me to work on as a part of my training here at Bleeping Computer. Since I'm still a trainee, all my posts have to be reviewed by my instructor prior to being posted to make sure that you receive the best assistance possible. My reply to you has taken longer than usual because of an internal glitch in communication between me and Gary. I apologize for the delay.

Thank you for your understanding.

Removing malware is hazardous. I will not knowingly advise actions that will damage your computer, but it is impossible to guarantee the safety of your system. It may even become necessary to re-format and re-install your operating system. As you are by now painfully aware, the best protection against ransomware is backups. Before we proceed, you should back up all your data -- preferably to a different computer that can then be disconnected or to off-line storage. If backups are accessible to you by ordinary means, then they are accessible to ransomware.


Let's run Farbar Recovery Scan Tool (FRST) in FIX mode

Save your work and exit all programs because Farbar Recovery Scan Tool may reboot your computer.

Press the Windows key+ R on your keyboard at the same time. This will open the Run dialog box.
Type Notepad into the Run box and click OK.
Please copy and paste the entire contents of the code box below into a new file.

Startup: C:\Users\Carol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CA9FD-43XXH-ETGGH-TXATX-GHZTO-AFRGT-XFGOY.html [2017-02-14] ()
CA9FD-43XXH-ETGGH-TXATX-GHZTO-AFRGT-XFGOY.html
GroupPolicy: Restriction - Chrome <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\ssv.dll [2016-06-25] (Oracle Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\jp2ssv.dll [2016-06-25] (Oracle Corporation)
File: C:\Users\Carol\Downloads\BitGo Keycard for My BitGo Wallet.pdf
File: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2017-02-14 11:13 - 2017-02-14 11:13 - 00016715 _____ C:\Users\Carol\AppData\Roaming\CA9FD-43XXH-ETGGH-TXATX-GHZTO-AFRGT-XFGOY.html
2017-02-14 11:13 - 2017-02-14 11:13 - 00001088 _____ C:\Users\Carol\AppData\Roaming\CA9FD-43XXH-ETGGH-TXATX-GHZTO-AFRGT-XFGOY
File: C:\Users\Carol\AppData\Roaming\4238841256
File: C:\Users\Carol\AppData\Roaming\winscp.rnd
File: C:\Users\Carol\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

On the Notepad menu, click Format and remove the checkmark from Word Wrap.
Save the file as fixlist.txt into the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the FRST.txt log you have submitted.

Run FRST64.exe and click Fix only once and wait until the program completes execution.

NOTICE: This script was written specifically for this user to be used on this particular machine. Running this script on another machine may cause damage to your operating system.

If requested, restart the computer normally to reset the registry.

The tool will create a log (Fixlog.txt). Please post it into your reply.

 

 

Test your results

 

Open the Edge browser to see whether it operates normally. Regardless of whether Edge operates normally or abnormally, please restart your PC and launch a different browser (Firefox or Chrome) and test for normal operation. Report your results in your reply.

 

 

In your next reply...

  • Confirm you have backed up all your important data.
  • Copy and paste the entire contents of the Fixlog.txt report into the body of your message.
  • Tell me whether Edge operates normally.
  • After reboot, tell me whether an alternate browser operates normally.
  • Tell me how your PC is running now. Describe symptoms, include verbatim error messages (if any).
  • Do you have any questions?

 

Thank you,

 

Ray


I don't accept payment for my help, but it would please me if you perform a kindness for your neighbor. You might also contact your local animal shelter. They can always use a bag of kibble or a few cans of pet food. Who knows... you might even find a life-long furry friend there.


#4 csquared

csquared
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:09:07 PM

Posted 19 February 2017 - 10:50 PM

Hello,

 

My name is Carol.

Thank you for your help Ray and Gary.  

I have followed the above and backed up my important data. 

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 18-02-2017 01
Ran by Carol (19-02-2017 17:41:29) Run:1
Running from C:\Users\Carol\Downloads
Loaded Profiles: Carol (Available Profiles: Carol & Administrator)
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
Startup: C:\Users\Carol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CA9FD-43XXH-ETGGH-TXATX-GHZTO-AFRGT-XFGOY.html [2017-02-14] ()
CA9FD-43XXH-ETGGH-TXATX-GHZTO-AFRGT-XFGOY.html
GroupPolicy: Restriction - Chrome <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\ssv.dll [2016-06-25] (Oracle Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\jp2ssv.dll [2016-06-25] (Oracle Corporation)
File:
C:\Users\Carol\Downloads\BitGo Keycard for My BitGo Wallet.pdf
File: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2017-02-14 11:13 - 2017-02-14 11:13 - 00016715 _____ C:\Users\Carol\AppData\Roaming\CA9FD-43XXH-ETGGH-TXATX-GHZTO-AFRGT-XFGOY.html
2017-02-14 11:13 - 2017-02-14 11:13 - 00001088 _____ C:\Users\Carol\AppData\Roaming\CA9FD-43XXH-ETGGH-TXATX-GHZTO-AFRGT-XFGOY
File: C:\Users\Carol\AppData\Roaming\4238841256
File: C:\Users\Carol\AppData\Roaming\winscp.rnd
File: C:\Users\Carol\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
*****************
 
C:\Users\Carol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CA9FD-43XXH-ETGGH-TXATX-GHZTO-AFRGT-XFGOY.html => moved successfully
CA9FD-43XXH-ETGGH-TXATX-GHZTO-AFRGT-XFGOY.html => Error: No automatic fix found for this entry.
C:\WINDOWS\system32\GroupPolicy\Machine => moved successfully
C:\WINDOWS\system32\GroupPolicy\GPT.ini => moved successfully
C:\WINDOWS\SysWOW64\GroupPolicy\GPT.ini => moved successfully
HKLM\SOFTWARE\Policies\Google => key removed successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} => key removed successfully
HKCR\Wow6432Node\CLSID\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} => key not found. 
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9} => key removed successfully
HKCR\Wow6432Node\CLSID\{DBC80044-A445-435b-BC74-9C25C1C588A9} => key not found. 
 
========================= File: ========================
 
"File:" => not found.
====== End of File: ======
 
C:\Users\Carol\Downloads\BitGo Keycard for My BitGo Wallet.pdf => moved successfully
 
========================= File: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job ========================
 
File not signed
MD5: 8DED2F83F428BCDB6ECCB3E61B51F058
Creation and modification date: 2017-02-14 13:28 - 2017-02-14 13:28
Size: 0000214
Attributes: ----A
Company Name: 
Internal Name: 
Original Name: 
Product: 
Description: 
File Version: 
Product Version: 
Copyright: 
 
====== End of File: ======
 
C:\Users\Carol\AppData\Roaming\CA9FD-43XXH-ETGGH-TXATX-GHZTO-AFRGT-XFGOY.html => moved successfully
C:\Users\Carol\AppData\Roaming\CA9FD-43XXH-ETGGH-TXATX-GHZTO-AFRGT-XFGOY => moved successfully
 
========================= File: C:\Users\Carol\AppData\Roaming\4238841256 ========================
 
File not signed
MD5: 7819DCB58FA38CF9FDD11A25FD39EA14
Creation and modification date: 2017-02-14 11:12 - 2017-02-15 20:21
Size: 0000234
Attributes: ----A
Company Name: 
Internal Name: 
Original Name: 
Product: 
Description: 
File Version: 
Product Version: 
Copyright: 
 
====== End of File: ======
 
 
========================= File: C:\Users\Carol\AppData\Roaming\winscp.rnd ========================
 
File not signed
MD5: 1FC0AAE8BAE598B8F815E4418C2A3407
Creation and modification date: 2014-11-04 09:35 - 2014-12-09 09:47
Size: 0000600
Attributes: ----A
Company Name: 
Internal Name: 
Original Name: 
Product: 
Description: 
File Version: 
Product Version: 
Copyright: 
 
====== End of File: ======
 
 
========================= File: C:\Users\Carol\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini ========================
 
File not signed
MD5: C09A9085FBF60B4636407777AA966580
Creation and modification date: 2015-06-13 21:45 - 2015-10-04 21:07
Size: 0053248
Attributes: ----A
Company Name: 
Internal Name: 
Original Name: 
Product: 
Description: 
File Version: 
Product Version: 
Copyright: 
 
====== End of File: ======
 
 
 
The system needed a reboot.
 
==== End of Fixlog 17:41:32 ====
 
Edge and alternate browsers are all working normally after reboot! 
My PC seems to be running normally. 
 
Thanks so much,
 
Carol 


#5 RayS

RayS

  • Malware Response Team
  • 2,434 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:11:07 PM

Posted 21 February 2017 - 05:31 PM

Hi Carol,

Thank you for the Fixlog.txt results. It indicates that the ransom note was incorporated into the computer's startup routine. We eliminated the trigger, but the part of my script for deleting the note failed because of a problem with word wrap in Notepad. The file, however, was removed in a separate line of my script. When you copy and paste my scripts, be sure to remove the checkmark from Word Wrap in Notepad's Format menu.

In my original script the following was all on one line:

File: C:\Users\Carol\Downloads\BitGo Keycard for My BitGo Wallet.pdf

But when it was submitted to FRST, it appears as two lines:

File:
C:\Users\Carol\Downloads\BitGo Keycard for My BitGo Wallet.pdf

As a result, instead of generating a report showing detailed info about the file, the file was moved into quarantine. If this is a valuable file and you want it restored, please run the entire script as shown in my instructions below. If you no longer need the file, please delete the following line from my script before you run it:

RestoreQuarantine: C:\Users\Carol\Downloads\BitGo Keycard for My BitGo Wallet.pdf

If you do restore the file from quarantine, and you are sure its contents are not malicious you can skip my instructions below for submitting the file to VirusTotal.com. In any case, please do run the second line in the script.


Let's run Farbar Recovery Scan Tool (FRST) in FIX mode

Save your work and exit all programs because Farbar Recovery Scan Tool may reboot your computer.

Press the Windows key + R on your keyboard at the same time. This will open the Run dialog box.
Type Notepad into the Run box and click OK.
Please copy and paste the entire contents of the code box below into a new file.

RestoreQuarantine: C:\Users\Carol\Downloads\BitGo Keycard for My BitGo Wallet.pdf
2017-02-14 11:12 - 2017-02-15 20:21 - 0000234 _____ () C:\Users\Carol\AppData\Roaming\4238841256

On the Notepad menu, click Format and remove the checkmark from Word Wrap.
Save the file as fixlist.txt into the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the FRST.txt log you have submitted.

Run FRST64.exe and click Fix only once and wait until the program completes execution.

NOTICE: This script was written specifically for this user to be used on this particular machine. Running this script on another machine may cause damage to your operating system.

If requested, restart the computer normally to reset the registry.

The tool will create a log (Fixlog.txt). Please post it into your reply.



Submit a file to VirusTotal.com

You may skip these instructions if you are sure the file is legitimate. Otherwise, please submit it to VirusTotal for an online scan:

C:\Users\Carol\Downloads\BitGo Keycard for My BitGo Wallet.pdf

  • Please visit https://www.virustotal.com/.
  • Click the File tab.
  • Click Choose File.
  • Use the File Upload window to navigate to the file named above on your local PC and click Open.
  • Click the Scan it! button on the VirusTotal website.
  • If a File already analyzed window pops up, click Reanalyze.
  • After a short time, the analysis will be presented on a web page.
  • Please copy the URL of that page (https:// etc.) and paste it into your reply to me.
  • Rescan with Farbar Recovery Scan Tool
    This tool is frequently updated. Please download a fresh copy of Farbar Recovery Scan Tool and save it to your Desktop.

    Note: You need to run the version compatible with your system. If you are not sure which version applies to your system, download both of them and try to run them. Only one of them will run on your system, that will be the right version.
  • Right-click FRST then click Run as administrator.
  • When the tool opens, click Yes to disclaimer.
  • Press the Scan button.
  • When finished, it will produce logs called FRST.txt and Addition.txt in the same directory where the tool was run from.
  • Please copy and paste both logs into your next reply.

In your next reply...

  • Copy and paste the entire contents of Fixlog.txt into the body of your message.
  • If you restored C:\Users\Carol\Downloads\BitGo Keycard for My BitGo Wallet.pdf, are you sure it is a legitimate file? If not, please supply a link to the VirusTotal scan.
  • Copy and paste the entire contents of Frst.txt and Addition.txt into the body of your message.
  • How is your PC running now?

Thank you,

Ray


I don't accept payment for my help, but it would please me if you perform a kindness for your neighbor. You might also contact your local animal shelter. They can always use a bag of kibble or a few cans of pet food. Who knows... you might even find a life-long furry friend there.


#6 csquared

csquared
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:09:07 PM

Posted 21 February 2017 - 11:24 PM

Hello Ray, 

 

Thanks again for your help. 

I did remove the wordwrap option last time, the previous script does appear on 2 different lines on my computer for some reason. 

I have rerun the new script, I did not restore the file as I do not need it. 

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 19-02-2017
Ran by Carol (21-02-2017 20:33:34) Run:2
Running from C:\Users\Carol\Downloads
Loaded Profiles: Carol (Available Profiles: Carol & Administrator)
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
2017-02-14 11:12 - 2017-02-15 20:21 - 0000234 _____ () C:\Users\Carol\AppData\Roaming\4238841256
*****************
 
C:\Users\Carol\AppData\Roaming\4238841256 => moved successfully
 
==== End of Fixlog 20:33:34 ====
 
I did not do the virus total part. 
 
Here is the FRST.txt and Addition.txt
 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 19-02-2017
Ran by Carol (administrator) on CHU (21-02-2017 21:11:37)
Running from C:\Users\Carol\Downloads
Loaded Profiles: Carol (Available Profiles: Carol & Administrator)
Platform: Windows 10 Home Version 1607 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Edge)
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(SurfRight B.V.) C:\Program Files\HitmanPro\hmpsched.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\AVGSvc.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Intel® Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(www.shadowexplorer.com) C:\Program Files (x86)\ShadowExplorer\sesvc.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe
(Seagate Technology LLC) C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.DASWindowsService.exe
(Seagate Technology LLC) C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\MobileService.exe
(Copyright 2017.) C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\x64\aswidsagenta.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler64.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Acer Cloud Technology) C:\Program Files (x86)\Acer\AOP Framework\acer\ccd.exe
(Acer Incorporated) C:\Users\Carol\AppData\Local\clear.fi\Docs\abDocsSetup.exe
(TODO: <Company name>) C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe
(Acer Incorporated) C:\Windows\Temp\7zS78FA.tmp\AcerDocsSetup.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(Acer Incorporated) C:\Windows\Temp\7zS78FA.tmp\AcerDocs.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.11.500\McCHSvc.exe
(Karlis Blumentals) C:\Program Files (x86)\Rapid PHP 2014\rapidphp.exe
(acer) C:\Program Files\Acer\User Experience Improvement Program\Framework\UBTService.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
() C:\Windows\System32\igfxTray.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Copyright 2017.) C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Spotify Ltd) C:\Users\Carol\AppData\Roaming\Spotify\SpotifyWebHelper.exe
(Seagate Technology LLC) C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.Uploader.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.11.500\SSScheduler.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE
(Acer Incorporated) C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\avgui.exe
(Seagate Technology LLC) C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\DBAgent.exe
(Seagate Technology LLC) C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\DeviceAgent.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.109.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
() C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.1118.10000.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avguix.exe
() C:\Program Files (x86)\Acer\Live Updater\updater.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.Office.OneNote_17.7870.57621.0_x64__8wekyb3d8bbwe\onenoteim.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Farbar) C:\Users\Carol\Downloads\FRST64 (1).exe
 
==================== Registry (Whitelisted) ====================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13885696 2015-06-24] (Realtek Semiconductor)
HKLM\...\Run: [IgfxTray] => C:\Windows\system32\igfxtray.exe [401896 2016-11-01] ()
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [557768 2014-10-14] (Adobe Systems Incorporated)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169768 2015-04-06] (Apple Inc.)
HKLM\...\Run: [ZAM] => C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe [14416624 2017-02-02] (Copyright 2017.)
HKLM\...\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe [239672 2017-02-20] (AVG Technologies CZ, s.r.o.)
HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [2780112 2017-01-20] (Malwarebytes)
HKLM-x32\...\Run: [BacKGround Agent] => C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe [62208 2014-11-17] (Acer Incorporated)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2015-05-15] (Apple Inc.)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2694320 2015-01-07] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [596504 2016-06-16] (Oracle Corporation)
HKLM-x32\...\Run: [AVGUI.exe] => C:\Program Files (x86)\AVG\Antivirus\AVGUI.exe [9511480 2017-02-16] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [DBAgent] => C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\DBAgent.exe [1563424 2016-06-28] (Seagate Technology LLC)
HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe
HKU\S-1-5-21-1893927633-78115024-1840190309-1001\...\Run: [msnmsgr] => C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe [4272840 2014-03-31] (Microsoft Corporation)
HKU\S-1-5-21-1893927633-78115024-1840190309-1001\...\Run: [Google Update] => C:\Users\Carol\AppData\Local\Google\Update\1.3.32.7\GoogleUpdateCore.exe [601752 2016-12-16] (Google Inc.)
HKU\S-1-5-21-1893927633-78115024-1840190309-1001\...\Run: [Spotify Web Helper] => C:\Users\Carol\AppData\Roaming\Spotify\SpotifyWebHelper.exe [1433712 2016-12-05] (Spotify Ltd)
HKU\S-1-5-21-1893927633-78115024-1840190309-1001\...\Run: [Uploader] => C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.Uploader.exe [127816 2016-06-28] (Seagate Technology LLC)
HKU\S-1-5-21-1893927633-78115024-1840190309-1001\...\Run: [Spotify] => C:\Users\Carol\AppData\Roaming\Spotify\Spotify.exe [7071344 2016-12-05] (Spotify Ltd)
ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2014-12-19] ()
ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2014-12-19] ()
ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2014-12-19] ()
ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ShellIconOverlayIdentifiers: [ACloudSyncedRF] -> {5CCE71FA-9F61-4F24-9CD1-98D819B40D68} => C:\Program Files (x86)\Acer\Acer Portal\x64\shellext_win.dll [2014-11-19] (Acer Incorporated)
ShellIconOverlayIdentifiers: [ACloudSyncedSF] -> {5D5F18B7-D59B-4B18-A3E9-0A4BDCCCB699} => C:\Program Files (x86)\Acer\Acer Portal\x64\shellext_win.dll [2014-11-19] (Acer Incorporated)
ShellIconOverlayIdentifiers: [ACloudSyncing] -> {C1E1456F-C2D8-4C96-870D-35F1E13941EE} => C:\Program Files (x86)\Acer\Acer Portal\x64\shellext_win.dll [2014-11-19] (Acer Incorporated)
ShellIconOverlayIdentifiers: [ACloudToBeSynced] -> {307523FA-DDC0-4068-983F-2A6B34627744} => C:\Program Files (x86)\Acer\Acer Portal\x64\shellext_win.dll [2014-11-19] (Acer Incorporated)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2017-02-05]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.500\SSScheduler.exe (McAfee, Inc.)
Startup: C:\Users\Carol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk [2016-06-24]
ShortcutTarget: Send to OneNote.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE (Microsoft Corporation)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{090c0ac6-bc0f-44ee-b59b-1eae0e992a82}: [DhcpNameServer] 192.168.43.1
Tcpip\..\Interfaces\{80d0df59-bbe0-4a63-aade-8e3e25db8589}: [DhcpNameServer] 192.168.1.1
 
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-1893927633-78115024-1840190309-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-1893927633-78115024-1840190309-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer13.msn.com/?pc=ACJB
SearchScopes: HKLM-x32 -> {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://ca.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms}
SearchScopes: HKU\S-1-5-21-1893927633-78115024-1840190309-1001 -> DefaultScope {BC878E6E-1C7F-4F71-BDB2-ADD6EE8D70B1} URL = 
SearchScopes: HKU\S-1-5-21-1893927633-78115024-1840190309-1001 -> {BC878E6E-1C7F-4F71-BDB2-ADD6EE8D70B1} URL = 
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2016-12-28] (Microsoft Corporation)
BHO: saver box -> {8dce820a-a9c0-4902-b025-3a7827ae6806} -> C:\ProgramData\saver box\YsdWAKPBFAr6I5.x64.dll => No File
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-04-26] (Google Inc.)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2016-12-28] (Microsoft Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2016-12-28] (Microsoft Corporation)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-04-26] (Google Inc.)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2016-12-28] (Microsoft Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-04-26] (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-04-26] (Google Inc.)
Toolbar: HKU\S-1-5-21-1893927633-78115024-1840190309-1001 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-04-26] (Google Inc.)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-12-28] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-12-28] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-12-28] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-12-28] (Microsoft Corporation)
 
FireFox:
========
FF DefaultProfile: pqtgs6mb.default-1417400995430
FF ProfilePath: C:\Users\Carol\AppData\Roaming\Mozilla\Firefox\Profiles\pqtgs6mb.default-1417400995430 [2017-02-19]
FF NetworkProxy: Mozilla\Firefox\Profiles\pqtgs6mb.default-1417400995430 -> type", 0
FF Extension: (Firefox Hotfix) - C:\Users\Carol\AppData\Roaming\Mozilla\Firefox\Profiles\pqtgs6mb.default-1417400995430\Extensions\firefox-hotfix@mozilla.org.xpi [2017-02-19]
FF Extension: (MediaHint) - C:\Users\Carol\AppData\Roaming\Mozilla\Firefox\Profiles\pqtgs6mb.default-1417400995430\Extensions\firefox@mediahint.com.xpi [2016-04-03]
FF Extension: (ZenMate Security, Privacy & Unblock VPN) - C:\Users\Carol\AppData\Roaming\Mozilla\Firefox\Profiles\pqtgs6mb.default-1417400995430\Extensions\firefox@zenmate.com.xpi [2017-02-19]
FF Extension: (Skype) - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2016-01-06]
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK => not found
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_24_0_0_221.dll [2017-02-15] ()
FF Plugin: @mcafee.com/MSC,version=10 -> C:\Program Files\mcafee\msc\npMcSnFFPl64.dll [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect_x86_64 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2015-01-07] (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWoW64\Macromed\Flash\NPSWF32_24_0_0_221.dll [2017-02-15] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2015-10-13] (Google, Inc.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-08-19] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-08-19] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.91.2 -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\dtplugin\npDeployJava1.dll [2016-06-25] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.91.2 -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\plugin2\npjp2.dll [2016-06-25] (Oracle Corporation)
FF Plugin-x32: @mcafee.com/MSC,version=10 -> C:\Program Files (x86)\McAfee\msc\npMcSnFFPl.dll [No File]
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2016-12-28] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2016-12-28] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2013-07-12] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2016-12-17] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2015-01-07] (Adobe Systems)
FF Plugin HKU\S-1-5-21-1893927633-78115024-1840190309-1001: @citrixonline.com/appdetectorplugin -> C:\Users\Carol\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2015-06-25] (Citrix Online)
FF Plugin HKU\S-1-5-21-1893927633-78115024-1840190309-1001: @talk.google.com/GoogleTalkPlugin -> C:\Users\Carol\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll [2015-12-08] (Google)
FF Plugin HKU\S-1-5-21-1893927633-78115024-1840190309-1001: @talk.google.com/O1DPlugin -> C:\Users\Carol\AppData\Roaming\Mozilla\plugins\npo1d.dll [2015-12-08] (Google)
FF Plugin HKU\S-1-5-21-1893927633-78115024-1840190309-1001: @tools.google.com/Google Update;version=3 -> C:\Users\Carol\AppData\Local\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin HKU\S-1-5-21-1893927633-78115024-1840190309-1001: @tools.google.com/Google Update;version=9 -> C:\Users\Carol\AppData\Local\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Carol\AppData\Roaming\mozilla\plugins\npgoogletalk.dll [2015-12-08] (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\Carol\AppData\Roaming\mozilla\plugins\npo1d.dll [2015-12-08] (Google)
 
Chrome: 
=======
CHR DefaultProfile: Default
CHR Plugin: (Widevine Content Decryption Module) - C:\Users\Carol\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.6.703\_platform_specific\win_x86\widevinecdmadapter.dll => No File
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\56.0.2924.87\PepperFlash\pepflashplayer.dll => No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\56.0.2924.87\pdf.dll => No File
CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll => No File
CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll => No File
CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll => No File
CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll => No File
CHR Plugin: (QuickTime Plug-in 7.7.5) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll => No File
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL => No File
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL => No File
CHR Plugin: (AdobeAAMDetect) - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems)
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Picasa) - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
CHR Plugin: (Intel® Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
CHR Plugin: (Intel® Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
CHR Plugin: (Java Deployment Toolkit 8.0.310.13) - C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll => No File
CHR Plugin: (Java™ Platform SE 8 U31) - C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll => No File
CHR Plugin: (WildTangent Games App V2 Presence Detector) - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
CHR Plugin: (Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Google Update) - C:\Users\Carol\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll => No File
CHR Plugin: (Google Talk Plugin) - C:\Users\Carol\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
CHR Plugin: (Google Talk Plugin Video Renderer) - C:\Users\Carol\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
CHR Plugin: (Shockwave Flash) - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll => No File
CHR Plugin: (McAfee SecurityCenter) - c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL => No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll => No File
CHR Profile: C:\Users\Carol\AppData\Local\Google\Chrome\User Data\Default [2017-02-21]
CHR Extension: (Google Slides) - C:\Users\Carol\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-02-05]
CHR Extension: (Google Docs) - C:\Users\Carol\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-05]
CHR Extension: (Google Drive) - C:\Users\Carol\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-11-08]
CHR Extension: (YouTube) - C:\Users\Carol\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-26]
CHR Extension: (Google Search) - C:\Users\Carol\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-08]
CHR Extension: (Google Sheets) - C:\Users\Carol\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-02-05]
CHR Extension: (Google Docs Offline) - C:\Users\Carol\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-26]
CHR Extension: (AdBlock) - C:\Users\Carol\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2017-02-17]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Carol\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-02-05]
CHR Extension: (Gmail) - C:\Users\Carol\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-29]
CHR Extension: (Chrome Media Router) - C:\Users\Carol\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-02-15]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-05-29] (Apple Inc.)
R2 AVG Antivirus; C:\Program Files (x86)\AVG\Antivirus\AVGSvc.exe [260080 2017-02-16] (AVG Technologies CZ, s.r.o.)
R3 avgbIDSAgent; C:\Program Files (x86)\AVG\Antivirus\x64\aswidsagenta.exe [6183576 2017-02-16] (AVG Technologies CZ, s.r.o.)
R2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [1256872 2017-02-20] (AVG Technologies CZ, s.r.o.)
R2 CCDMonitorService; C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe [2709760 2014-11-16] (Acer Incorporated)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [3699904 2016-12-28] (Microsoft Corporation)
R2 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [235008 2013-07-16] (TODO: <Company name>) [File not signed]
R2 HitmanProScheduler; C:\Program Files\HitmanPro\hmpsched.exe [135496 2017-02-15] (SurfRight B.V.)
R2 igfxCUIService2.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [373744 2016-11-01] (Intel Corporation)
R2 Intel® Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-11] (Intel® Corporation) [File not signed]
S3 Intel® Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel® Corporation)
R2 Intel® ME Service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-08-19] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [169432 2013-08-19] (Intel Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4355024 2017-01-20] (Malwarebytes)
R3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.500\McCHSvc.exe [329480 2017-01-18] (McAfee, Inc.)
R2 Seagate Dashboard Services; C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.DASWindowsService.exe [16216 2016-06-28] (Seagate Technology LLC)
R2 Seagate MobileBackup Service; C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\MobileService.exe [143656 2016-06-28] (Seagate Technology LLC)
R2 sesvc; C:\Program Files (x86)\ShadowExplorer\sesvc.exe [9216 2013-01-02] (www.shadowexplorer.com) [File not signed]
R3 UEIPSvc; C:\Program Files\Acer\User Experience Improvement Program\Framework\UBTService.exe [222952 2014-01-24] (acer)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation)
R2 ZAMSvc; C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe [14416624 2017-02-02] (Copyright 2017.)
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R1 avgbdisk; C:\WINDOWS\system32\drivers\avgbdiska.sys [165624 2017-02-16] (AVG Technologies CZ, s.r.o.)
R1 avgbidsdriver; C:\WINDOWS\system32\drivers\avgbidsdrivera.sys [311592 2017-02-16] (AVG Technologies CZ, s.r.o.)
R0 avgbidsh; C:\WINDOWS\system32\drivers\avgbidsha.sys [192096 2017-02-16] (AVG Technologies CZ, s.r.o.)
R0 avgblog; C:\WINDOWS\system32\drivers\avgbloga.sys [336920 2017-02-16] (AVG Technologies CZ, s.r.o.)
R0 avgbuniv; C:\WINDOWS\system32\drivers\avgbuniva.sys [50848 2017-02-16] (AVG Technologies CZ, s.r.o.)
S3 avgHwid; C:\WINDOWS\system32\drivers\avgHwid.sys [39288 2017-02-16] (AVG Technologies CZ, s.r.o.)
R2 avgMonFlt; C:\WINDOWS\system32\drivers\avgMonFlt.sys [127072 2017-02-16] (AVG Technologies CZ, s.r.o.)
R1 avgRdr; C:\WINDOWS\system32\drivers\avgRdr2.sys [101624 2017-02-16] (AVG Technologies CZ, s.r.o.)
R0 avgRvrt; C:\WINDOWS\system32\drivers\avgRvrt.sys [75664 2017-02-16] (AVG Technologies CZ, s.r.o.)
R1 avgSnx; C:\WINDOWS\system32\drivers\avgSnx.sys [992488 2017-02-16] (AVG Technologies CZ, s.r.o.)
R1 avgSP; C:\WINDOWS\system32\drivers\avgSP.sys [555152 2017-02-16] (AVG Technologies CZ, s.r.o.)
R2 avgStm; C:\WINDOWS\system32\drivers\avgStm.sys [163512 2017-02-16] (AVG Technologies CZ, s.r.o.)
R0 avgVmm; C:\WINDOWS\system32\drivers\avgVmm.sys [311472 2017-02-16] (AVG Technologies CZ, s.r.o.)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [129152 2016-04-24] (Samsung Electronics Co., Ltd.)
R3 dot4; C:\WINDOWS\system32\DRIVERS\Dot4.sys [151968 2012-10-19] (Windows ® Win 7 DDK provider)
R3 Dot4Print; C:\WINDOWS\System32\drivers\Dot4Prt.sys [27040 2012-10-19] (Windows ® Win 7 DDK provider)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [77416 2017-01-20] ()
R2 MBAMChameleon; C:\WINDOWS\system32\drivers\MBAMChameleon.sys [176584 2017-02-16] (Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\system32\drivers\farflt.sys [110536 2017-02-19] (Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\system32\drivers\mbam.sys [43968 2017-02-19] (Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [251848 2017-02-19] (Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\drivers\mwac.sys [91584 2017-02-21] (Malwarebytes)
R3 MEIx64; C:\WINDOWS\system32\DRIVERS\TeeDriverx64.sys [99288 2013-08-19] (Intel Corporation)
S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
R2 RtkIOAC60; C:\WINDOWS\system32\DRIVERS\RtkIOAC60.sys [29912 2013-07-18] (Realtek semiconductor corp)
R3 RTSUER; C:\WINDOWS\system32\Drivers\RtsUer.sys [402960 2015-05-14] (Realsil Semiconductor Corporation)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [221824 2016-04-24] (Samsung Electronics Co., Ltd.)
S3 ssudserd; C:\WINDOWS\system32\DRIVERS\ssudserd.sys [214832 2015-12-08] (DEVGURU Co., LTD.(www.devguru.co.kr))
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
R1 ZAM; C:\WINDOWS\System32\drivers\zam64.sys [203680 2017-02-15] (Zemana Ltd.)
R1 ZAM_Guard; C:\WINDOWS\System32\drivers\zamguard64.sys [203680 2017-02-15] (Zemana Ltd.)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2017-02-21 21:00 - 2017-02-21 21:10 - 02422784 _____ (Farbar) C:\Users\Carol\Downloads\FRST64 (1).exe
2017-02-20 11:30 - 2017-02-20 11:30 - 00016353 _____ C:\Users\Carol\Downloads\Letter.pdf
2017-02-20 10:04 - 2017-02-20 10:04 - 00070944 _____ C:\Users\Carol\Downloads\CarolChuOlympic.pdf
2017-02-20 10:00 - 2017-02-20 10:00 - 00070259 _____ C:\Users\Carol\Downloads\CarolChu2016YouthCentral (4).pdf
2017-02-20 10:00 - 2017-02-20 10:00 - 00069757 _____ C:\Users\Carol\Downloads\CarolChu2016YouthCentral (3).pdf
2017-02-20 09:59 - 2017-02-20 09:59 - 00069748 _____ C:\Users\Carol\Downloads\CarolChu2016YouthCentral (2).pdf
2017-02-19 19:55 - 2017-02-19 19:55 - 00000000 ___HD C:\OneDriveTemp
2017-02-19 17:44 - 2017-02-21 20:48 - 00091584 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2017-02-19 17:41 - 2017-02-21 20:33 - 00000540 _____ C:\Users\Carol\Downloads\Fixlog.txt
2017-02-19 17:41 - 2017-02-21 20:33 - 00000000 ____D C:\Users\Carol\Downloads\FRST-OlderVersion
2017-02-19 15:49 - 2017-02-19 15:49 - 00003564 _____ C:\WINDOWS\System32\Tasks\Seagate_Install_Launch
2017-02-19 15:49 - 2017-02-19 15:49 - 00003542 _____ C:\WINDOWS\System32\Tasks\Carol DBAgent 2 0
2017-02-19 15:49 - 2017-02-19 15:49 - 00000000 ____D C:\Users\Carol\AppData\Roaming\Nero
2017-02-19 15:46 - 2017-02-19 15:46 - 00002182 _____ C:\Users\Public\Desktop\Seagate Dashboard.lnk
2017-02-19 15:46 - 2017-02-19 15:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Seagate Dashboard
2017-02-19 15:46 - 2017-02-19 15:46 - 00000000 ____D C:\Program Files (x86)\Seagate
2017-02-19 15:45 - 2017-02-19 15:45 - 00000000 ____D C:\Users\Carol\AppData\Roaming\Seagate
2017-02-19 15:44 - 2017-02-19 15:45 - 147628976 _____ (Seagate) C:\Users\Carol\Downloads\Seagate_Dashboard_Installer.exe
2017-02-16 10:21 - 2017-02-16 10:24 - 00061401 _____ C:\Users\Carol\Downloads\Addition.txt
2017-02-16 10:18 - 2017-02-21 21:11 - 00032266 _____ C:\Users\Carol\Downloads\FRST.txt
2017-02-16 10:17 - 2017-02-21 21:11 - 00000000 ____D C:\FRST
2017-02-16 10:17 - 2017-02-21 20:33 - 02422784 _____ (Farbar) C:\Users\Carol\Downloads\FRST64.exe
2017-02-16 10:03 - 2017-02-16 10:03 - 00176584 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMChameleon.sys
2017-02-16 10:02 - 2017-02-19 17:44 - 00110536 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
2017-02-16 10:02 - 2017-02-19 17:44 - 00043968 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2017-02-16 10:02 - 2017-02-19 17:43 - 00251848 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2017-02-16 10:02 - 2017-02-16 10:02 - 00001916 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2017-02-16 10:02 - 2017-02-16 10:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2017-02-16 10:02 - 2017-01-20 07:47 - 00077416 _____ C:\WINDOWS\system32\Drivers\mbae64.sys
2017-02-16 10:00 - 2017-02-16 10:02 - 55566792 _____ (Malwarebytes ) C:\Users\Carol\Downloads\mb3-setup-consumer-3.0.6.1469 (1).exe
2017-02-16 00:19 - 2017-02-16 00:19 - 00000000 ____D C:\Users\Carol\AppData\Roaming\AVG
2017-02-16 00:17 - 2017-02-16 00:17 - 00992488 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgsnx.sys
2017-02-16 00:17 - 2017-02-16 00:17 - 00555152 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgSP.sys
2017-02-16 00:17 - 2017-02-16 00:17 - 00397800 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\avgBoot.exe
2017-02-16 00:17 - 2017-02-16 00:17 - 00311472 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgVmm.sys
2017-02-16 00:17 - 2017-02-16 00:17 - 00163512 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgStm.sys
2017-02-16 00:17 - 2017-02-16 00:17 - 00127072 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgMonFlt.sys
2017-02-16 00:17 - 2017-02-16 00:17 - 00101624 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgRdr2.sys
2017-02-16 00:17 - 2017-02-16 00:17 - 00075664 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgRvrt.sys
2017-02-16 00:17 - 2017-02-16 00:17 - 00039288 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgHwid.sys
2017-02-16 00:17 - 2017-02-16 00:17 - 00004008 _____ C:\WINDOWS\System32\Tasks\Antivirus Emergency Update
2017-02-16 00:17 - 2017-02-16 00:16 - 00336920 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgbloga.sys
2017-02-16 00:17 - 2017-02-16 00:16 - 00311592 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgbidsdrivera.sys
2017-02-16 00:17 - 2017-02-16 00:16 - 00192096 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgbidsha.sys
2017-02-16 00:17 - 2017-02-16 00:16 - 00165624 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgbdiska.sys
2017-02-16 00:17 - 2017-02-16 00:16 - 00050848 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgbuniva.sys
2017-02-16 00:15 - 2017-02-17 09:55 - 00000943 _____ C:\Users\Public\Desktop\AVG.lnk
2017-02-16 00:15 - 2017-02-17 09:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG Zen
2017-02-16 00:14 - 2017-02-21 12:29 - 00003668 _____ C:\WINDOWS\System32\Tasks\AVG EUpdate Task
2017-02-16 00:14 - 2017-02-16 00:16 - 00000000 ____D C:\Program Files (x86)\AVG
2017-02-16 00:13 - 2017-02-16 10:26 - 00000000 ____D C:\ProgramData\Avg
2017-02-16 00:13 - 2017-02-16 00:15 - 00000000 ____D C:\Users\Carol\AppData\Local\AvgSetupLog
2017-02-16 00:13 - 2017-02-16 00:13 - 00000000 ____D C:\Users\Carol\AppData\Local\Avg
2017-02-15 22:40 - 2017-02-16 00:13 - 03449304 _____ (AVG Technologies CZ, s.r.o.) C:\Users\Carol\Downloads\AVG_Protection_Free_1606.exe
2017-02-15 22:26 - 2017-02-15 22:27 - 147118352 _____ (Microsoft Corporation) C:\Users\Carol\Downloads\msert.exe
2017-02-15 21:35 - 2017-02-21 21:11 - 02662003 _____ C:\WINDOWS\ZAM.krnl.trace
2017-02-15 21:35 - 2017-02-21 21:11 - 00352368 _____ C:\WINDOWS\ZAM_Guard.krnl.trace
2017-02-15 21:35 - 2017-02-15 21:35 - 00203680 _____ (Zemana Ltd.) C:\WINDOWS\system32\Drivers\zamguard64.sys
2017-02-15 21:35 - 2017-02-15 21:35 - 00203680 _____ (Zemana Ltd.) C:\WINDOWS\system32\Drivers\zam64.sys
2017-02-15 21:35 - 2017-02-15 21:35 - 00001221 _____ C:\Users\Public\Desktop\Zemana AntiMalware.lnk
2017-02-15 21:35 - 2017-02-15 21:35 - 00000000 ____D C:\Users\Carol\AppData\Local\Zemana
2017-02-15 21:35 - 2017-02-15 21:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zemana AntiMalware
2017-02-15 21:35 - 2017-02-15 21:35 - 00000000 ____D C:\Program Files (x86)\Zemana AntiMalware
2017-02-15 21:34 - 2017-02-15 21:35 - 05677776 _____ (Zemana Ltd. ) C:\Users\Carol\Downloads\Zemana.AntiMalware.Setup.exe
2017-02-15 20:52 - 2017-02-15 20:52 - 00001966 _____ C:\Users\Public\Desktop\HitmanPro.lnk
2017-02-15 20:52 - 2017-02-15 20:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HitmanPro
2017-02-15 20:52 - 2017-02-15 20:52 - 00000000 ____D C:\Program Files\HitmanPro
2017-02-15 20:49 - 2017-02-15 20:51 - 11581544 _____ (SurfRight B.V.) C:\Users\Carol\Downloads\hitmanpro_x64 (1).exe
2017-02-15 19:37 - 2017-02-15 21:55 - 00000000 ____D C:\Users\Carol\Downloads\TOTAL_AB2F70FD7450BD (1)
2017-02-15 18:32 - 2017-02-15 22:02 - 00000000 ____D C:\Users\Carol\Downloads\TOTAL_AB2F70FD7450BD
2017-02-14 13:28 - 2017-02-14 13:28 - 00000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2017-02-14 12:38 - 2017-02-14 12:38 - 55566792 _____ (Malwarebytes ) C:\Users\Carol\Downloads\mb3-setup-consumer-3.0.6.1469.exe
2017-02-14 12:38 - 2017-02-14 12:38 - 00000000 ____D C:\Program Files\Malwarebytes
2017-02-14 12:35 - 2017-02-14 13:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ShadowExplorer
2017-02-14 12:35 - 2017-02-14 13:16 - 00000000 ____D C:\Program Files (x86)\ShadowExplorer
2017-02-14 12:35 - 2017-02-14 12:35 - 00001958 _____ C:\Users\Carol\Desktop\ShadowExplorer.lnk
2017-02-14 12:34 - 2017-02-14 12:34 - 00969845 _____ (ShadowExplorer.com ) C:\Users\Carol\Downloads\ShadowExplorer-0.9-setup.exe
2017-02-14 11:41 - 2017-02-14 11:42 - 00412660 _____ C:\WINDOWS\Minidump\021417-78046-01.dmp
2017-02-14 11:41 - 2017-02-14 11:41 - 00000000 ____D C:\WINDOWS\Minidump
2017-02-10 16:35 - 2017-02-15 19:56 - 00051011 _____ C:\Users\Carol\Downloads\SalsFlatbreadInvoiceUpdated.pdf
2017-02-08 21:26 - 2017-02-15 19:56 - 00051067 _____ C:\Users\Carol\Downloads\SalsFlatbreadInvoice.pdf
2017-02-06 23:42 - 2017-02-15 19:56 - 00052067 _____ C:\Users\Carol\Downloads\InvoiceFeb6Kristin.pdf
2017-02-05 11:18 - 2017-02-05 11:18 - 00002013 _____ C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
2017-02-05 11:18 - 2017-02-05 11:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
2017-01-30 14:49 - 2017-02-15 19:56 - 01031102 _____ C:\Users\Carol\Downloads\Win Free Breakfast for a week.pdf
2017-01-30 11:17 - 2017-02-15 19:56 - 00746875 _____ C:\Users\Carol\Downloads\sals_logoGOOD (1).pdf
2017-01-28 21:20 - 2017-01-28 18:55 - 51262945 ____N C:\Users\Carol\Desktop\VID_20170128_185420711.mp4
2017-01-28 21:19 - 2017-01-28 18:46 - 136170505 ____N C:\Users\Carol\Desktop\VID_20170128_184501414.mp4
2017-01-28 21:19 - 2017-01-28 18:42 - 137671181 ____N C:\Users\Carol\Desktop\VID_20170128_184011521.mp4
2017-01-25 11:40 - 2016-12-21 00:08 - 00142848 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe
2017-01-25 11:40 - 2016-12-20 21:44 - 00120320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe
2017-01-24 22:02 - 2017-01-24 22:03 - 117186608 _____ C:\Users\Carol\Downloads\1_11819.tif
2017-01-24 22:00 - 2017-01-24 22:00 - 117189612 _____ C:\Users\Carol\Downloads\1_11865 (1).tif
2017-01-24 14:37 - 2017-01-24 14:37 - 117186812 _____ C:\Users\Carol\Downloads\1_11852 (1).tif
2017-01-23 14:03 - 2017-02-15 19:56 - 00026146 _____ C:\Users\Carol\Downloads\GreatToSkatePartyWaiver (1).pdf
2017-01-23 13:55 - 2017-02-15 19:56 - 00026146 _____ C:\Users\Carol\Downloads\GreatToSkatePartyWaiver.pdf
2017-01-23 13:39 - 2017-02-15 19:56 - 00050079 _____ C:\Users\Carol\Downloads\InvoiceJan16Kristin (1).pdf
2017-01-23 13:34 - 2017-02-15 19:56 - 00049457 _____ C:\Users\Carol\Downloads\InvoiceJan16Kristin.pdf
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2017-02-21 20:22 - 2016-09-29 08:23 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2017-02-21 20:18 - 2016-07-16 04:47 - 00000000 ___HD C:\Program Files\WindowsApps
2017-02-21 20:18 - 2016-07-16 04:47 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-02-21 20:09 - 2016-07-16 04:36 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-02-20 21:33 - 2014-09-14 19:18 - 00000000 ____D C:\Users\Carol\AppData\Local\clear.fi
2017-02-20 09:22 - 2014-09-18 11:13 - 00000000 ____D C:\Users\Carol\AppData\Roaming\Spotify
2017-02-20 09:20 - 2014-09-14 22:32 - 00000000 ____D C:\Users\Carol\AppData\Local\Adobe
2017-02-20 09:17 - 2014-09-18 11:14 - 00000000 ____D C:\Users\Carol\AppData\Local\Spotify
2017-02-19 20:13 - 2016-08-29 08:16 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-02-19 19:58 - 2016-07-16 04:47 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2017-02-19 19:57 - 2016-07-16 04:45 - 00000000 ____D C:\WINDOWS\INF
2017-02-19 19:57 - 2014-09-14 19:39 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-02-19 19:55 - 2015-02-15 15:46 - 00000000 ___RD C:\Users\Carol\OneDrive
2017-02-19 19:54 - 2016-09-29 08:25 - 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2017-02-19 19:54 - 2015-08-06 07:53 - 00000000 __SHD C:\Users\Carol\IntelGraphicsProfiles
2017-02-19 17:47 - 2015-08-06 00:26 - 01148602 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-02-19 17:43 - 2016-09-29 08:53 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-02-19 17:43 - 2015-08-07 02:32 - 00000008 __RSH C:\ProgramData\ntuser.pol
2017-02-19 17:43 - 2015-06-25 09:02 - 00000666 _____ C:\WINDOWS\Tasks\G2MUploadTask-S-1-5-21-1893927633-78115024-1840190309-1001.job
2017-02-19 17:43 - 2015-06-25 09:02 - 00000570 _____ C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-1893927633-78115024-1840190309-1001.job
2017-02-19 17:42 - 2016-07-15 23:04 - 00524288 _____ C:\WINDOWS\system32\config\BBI
2017-02-19 17:41 - 2016-07-16 04:47 - 00000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy
2017-02-19 17:41 - 2013-08-22 08:36 - 00000000 ___HD C:\WINDOWS\system32\GroupPolicy
2017-02-18 10:02 - 2015-10-26 11:00 - 00000000 ____D C:\Users\Carol\Desktop\YYC Fitness
2017-02-17 12:18 - 2014-09-16 20:24 - 00000000 ____D C:\Users\Carol\AppData\Local\CrashDumps
2017-02-16 10:02 - 2014-11-27 22:45 - 00000000 ____D C:\ProgramData\Malwarebytes
2017-02-15 20:49 - 2016-07-15 23:04 - 00032768 _____ C:\WINDOWS\system32\config\ELAM
2017-02-15 20:46 - 2014-09-14 22:33 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2017-02-15 20:31 - 2014-09-05 19:39 - 00000000 ____D C:\Users\Carol\AppData\Local\Packages
2017-02-15 19:57 - 2016-07-25 09:16 - 01841934 _____ C:\Users\Carol\Downloads\lagree6.jpeg
2017-02-15 19:57 - 2016-07-10 14:31 - 00258194 _____ C:\Users\Carol\Downloads\canada olympic park.jpeg
2017-02-15 19:57 - 2016-03-30 14:05 - 00027215 _____ C:\Users\Carol\Downloads\Blank Print Document.jpeg
2017-02-15 19:57 - 2016-03-04 15:38 - 00113478 _____ C:\Users\Carol\Downloads\Monochrome (Portrait) (3).jpeg
2017-02-15 19:57 - 2016-03-04 15:06 - 00118117 _____ C:\Users\Carol\Downloads\Monochrome (Portrait) (2).jpeg
2017-02-15 19:57 - 2016-03-03 22:38 - 00105707 _____ C:\Users\Carol\Downloads\Monochrome (Portrait) (1).jpeg
2017-02-15 19:57 - 2016-03-03 22:21 - 00106763 _____ C:\Users\Carol\Downloads\Monochrome (Portrait).jpeg
2017-02-15 19:57 - 2015-10-15 11:57 - 00107590 _____ C:\Users\Carol\Downloads\Newsletterholidayad.jpeg
2017-02-15 19:57 - 2015-10-12 13:43 - 00464553 _____ C:\Users\Carol\Downloads\Blank Digital Document.jpeg
2017-02-15 19:57 - 2015-10-12 12:06 - 01093277 _____ C:\Users\Carol\Downloads\Facebook Post.jpeg
2017-02-15 19:57 - 2015-10-05 13:13 - 00923275 _____ C:\Users\Carol\Downloads\Christmas AD (1).jpeg
2017-02-15 19:57 - 2015-09-30 09:56 - 00910293 _____ C:\Users\Carol\Downloads\GreattoSkateChristmas AD (1).jpeg
2017-02-15 19:57 - 2015-09-30 09:53 - 00184632 _____ C:\Users\Carol\Downloads\Christmas AD.jpeg
2017-02-15 19:57 - 2015-09-30 09:51 - 00184632 _____ C:\Users\Carol\Downloads\Copy of Blank Print Document.jpeg
2017-02-15 19:57 - 2015-08-16 20:06 - 00783880 _____ C:\Users\Carol\Downloads\Blank Digital Document - Blank (2).jpeg
2017-02-15 19:57 - 2015-08-06 23:29 - 00351853 _____ C:\Users\Carol\Downloads\Blank Digital Document - Blank (1).jpeg
2017-02-15 19:57 - 2015-08-06 23:25 - 00351335 _____ C:\Users\Carol\Downloads\Blank Digital Document - Blank.jpeg
2017-02-15 19:57 - 2015-06-14 23:55 - 00827358 _____ C:\Users\Carol\Downloads\Newsletter - Untitled Page.jpeg
2017-02-15 19:57 - 2015-06-14 23:53 - 00382298 _____ C:\Users\Carol\Downloads\JulySchedule - Untitled Page (1).jpeg
2017-02-15 19:57 - 2015-06-14 23:52 - 00654554 _____ C:\Users\Carol\Downloads\Get Going July events newsletter - Untitled Page.jpeg
2017-02-15 19:57 - 2015-06-14 23:51 - 00942670 _____ C:\Users\Carol\Downloads\Get Going May-June pictures - Untitled Page.jpeg
2017-02-15 19:57 - 2015-06-12 23:02 - 00459344 _____ C:\Users\Carol\Downloads\Blank Print Document - Untitled Page (2).jpeg
2017-02-15 19:57 - 2015-06-12 11:41 - 00939834 _____ C:\Users\Carol\Downloads\Blank Print Document - Untitled Page.jpeg
2017-02-15 19:57 - 2015-05-15 00:12 - 00793625 _____ C:\Users\Carol\Downloads\GetGoingNewsletter.jpeg
2017-02-15 19:57 - 2015-05-15 00:09 - 00321901 _____ C:\Users\Carol\Downloads\JulySchedule - Untitled Page.jpeg
2017-02-15 19:57 - 2015-05-14 23:28 - 00791798 _____ C:\Users\Carol\Downloads\Blank Print Document - Untitled Page (1).jpeg
2017-02-15 19:57 - 2015-05-14 23:28 - 00361854 _____ C:\Users\Carol\Downloads\MayJuneSchedule.jpeg
2017-02-15 19:56 - 2017-01-09 10:48 - 00013326 _____ C:\Users\Carol\Downloads\Class Listsz (1).xlsx
2017-02-15 19:56 - 2017-01-04 22:54 - 00126826 _____ C:\Users\Carol\Downloads\merged_document (7).pdf
2017-02-15 19:56 - 2017-01-04 22:53 - 00071379 _____ C:\Users\Carol\Downloads\CopyofCarolResume2016Marcomm (5).2-3.pdf
2017-02-15 19:56 - 2017-01-04 22:43 - 00054819 _____ C:\Users\Carol\Downloads\CoverLetterUofC.pdf
2017-02-15 19:56 - 2017-01-04 21:44 - 00070841 _____ C:\Users\Carol\Downloads\CopyofCarolResume2016Marcomm (5).pdf
2017-02-15 19:56 - 2017-01-03 19:17 - 00072038 _____ C:\Users\Carol\Downloads\CarolResume2016SocialMedia (4).2-3.pdf
2017-02-15 19:56 - 2017-01-03 19:13 - 00071520 _____ C:\Users\Carol\Downloads\CarolResume2016SocialMedia (4).pdf
2017-02-15 19:56 - 2016-12-30 18:02 - 00009599 _____ C:\Users\Carol\Downloads\Class Listsz.xlsx
2017-02-15 19:56 - 2016-12-18 22:17 - 00786845 _____ C:\Users\Carol\Downloads\attracting-new-girls-and-women-into-football2.pdf
2017-02-15 19:56 - 2016-12-11 15:56 - 00527190 _____ C:\Users\Carol\Downloads\Confirmation (1).pdf
2017-02-15 19:56 - 2016-12-02 14:35 - 00110722 _____ C:\Users\Carol\Downloads\GreattoSkateMidnaporeLakeContract2017 (2).pdf
2017-02-15 19:56 - 2016-12-02 14:34 - 00110723 _____ C:\Users\Carol\Downloads\GreattoSkateMidnaporeLakeContract2017 (1).pdf
2017-02-15 19:56 - 2016-12-02 14:34 - 00071682 _____ C:\Users\Carol\Downloads\InvoiceMidnaporeLake2017 (1).pdf
2017-02-15 19:56 - 2016-12-02 14:25 - 00110723 _____ C:\Users\Carol\Downloads\GreattoSkateMidnaporeLakeContract2017.pdf
2017-02-15 19:56 - 2016-12-02 14:25 - 00071682 _____ C:\Users\Carol\Downloads\InvoiceMidnaporeLake2017.pdf
2017-02-15 19:56 - 2016-11-12 15:44 - 00345109 _____ C:\Users\Carol\Downloads\Online Video Resource Library List 160516.pdf
2017-02-15 19:56 - 2016-11-09 23:01 - 01063645 _____ C:\Users\Carol\Downloads\Archery.pdf
2017-02-15 19:56 - 2016-11-08 23:15 - 00243544 _____ C:\Users\Carol\Downloads\Personal Training Voucher.pdf
2017-02-15 19:56 - 2016-10-28 11:02 - 00011612 _____ C:\Users\Carol\Downloads\onlineStatement.pdf
2017-02-15 19:56 - 2016-10-24 09:06 - 03813280 _____ C:\Users\Carol\Downloads\Freeset Tees Standard Canada Catalog 2016.pdf
2017-02-15 19:56 - 2016-10-09 22:31 - 00082030 _____ C:\Users\Carol\Downloads\ProblemparentParentwithProblemsSlide.pdf
2017-02-15 19:56 - 2016-10-08 20:05 - 00104531 _____ C:\Users\Carol\Downloads\26696057627-555768936-ticket.pdf
2017-02-15 19:56 - 2016-10-05 10:43 - 00071309 _____ C:\Users\Carol\Downloads\CopyofCarolResume2016Marcomm (4).2-3.pdf
2017-02-15 19:56 - 2016-10-05 10:42 - 00056198 _____ C:\Users\Carol\Downloads\CoverLetterCSLA.pdf
2017-02-15 19:56 - 2016-10-05 10:42 - 00055604 _____ C:\Users\Carol\Downloads\CoverLetterCity (1).pdf
2017-02-15 19:56 - 2016-10-05 09:12 - 00070590 _____ C:\Users\Carol\Downloads\CopyofCarolResume2016Marcomm (4).pdf
2017-02-15 19:56 - 2016-10-04 12:24 - 00036696 _____ C:\Users\Carol\Downloads\Rate+Sheet+PHSPCA2013.pdf
2017-02-15 19:56 - 2016-10-03 19:07 - 00706129 _____ C:\Users\Carol\Downloads\Inspiration_Puzzle_Pack.pdf
2017-02-15 19:56 - 2016-10-02 21:59 - 05151110 _____ C:\Users\Carol\Downloads\calgary-2016-package.pdf
2017-02-15 19:56 - 2016-09-14 10:24 - 00049330 _____ C:\Users\Carol\Downloads\2016 TimesheetsSept2016.xlsx
2017-02-15 19:56 - 2016-09-12 20:44 - 00122095 _____ C:\Users\Carol\Downloads\September 2016.pdf
2017-02-15 19:56 - 2016-09-01 08:01 - 00049329 _____ C:\Users\Carol\Downloads\2016 TimesheetsAugend2016.xlsx
2017-02-15 19:56 - 2016-08-31 17:49 - 00022580 _____ C:\Users\Carol\Downloads\Calgary (2).xlsx
2017-02-15 19:56 - 2016-08-31 17:40 - 00022580 _____ C:\Users\Carol\Downloads\Calgary (1).xlsx
2017-02-15 19:56 - 2016-08-31 09:54 - 00070704 _____ C:\Users\Carol\Downloads\CopyofCarolResume2016Marcomm (3).pdf
2017-02-15 19:56 - 2016-08-31 09:54 - 00070198 _____ C:\Users\Carol\Downloads\CopyofCarolResume2016Marcomm (2).pdf
2017-02-15 19:56 - 2016-08-31 09:40 - 00070027 _____ C:\Users\Carol\Downloads\CopyofCarolResume2016Marcomm (1).pdf
2017-02-15 19:56 - 2016-08-19 18:32 - 00004633 _____ C:\Users\Carol\Downloads\Tasks%2FCalendar.xlsx
2017-02-15 19:56 - 2016-08-14 12:31 - 00049338 _____ C:\Users\Carol\Downloads\2016 TimesheetsAug2016.xlsx
2017-02-15 19:56 - 2016-08-08 15:19 - 00196092 _____ C:\Users\Carol\Downloads\CIC-summer-drop-in-2016 (1).pdf
2017-02-15 19:56 - 2016-08-08 15:18 - 00196092 _____ C:\Users\Carol\Downloads\CIC-summer-drop-in-2016.pdf
2017-02-15 19:56 - 2016-08-02 16:10 - 00022309 _____ C:\Users\Carol\Downloads\Calgary.xlsx
2017-02-15 19:56 - 2016-07-28 09:06 - 00049281 _____ C:\Users\Carol\Downloads\2016 TimesheetsCarolJuly.xlsx
2017-02-15 19:56 - 2016-07-26 18:39 - 00573136 _____ C:\Users\Carol\Downloads\brochure.pdf
2017-02-15 19:56 - 2016-07-22 08:55 - 01157373 _____ C:\Users\Carol\Downloads\1 Move Better (1).pdf
2017-02-15 19:56 - 2016-07-22 08:14 - 01103678 _____ C:\Users\Carol\Downloads\1 Move Better.pdf
2017-02-15 19:56 - 2016-07-04 20:10 - 00491564 _____ C:\Users\Carol\Downloads\Adult Program Spring  Summer 2016 (5-17-2016).pdf
2017-02-15 19:56 - 2016-06-27 13:42 - 00049323 _____ C:\Users\Carol\Downloads\2016 Timesheets CarolJune.xlsx
2017-02-15 19:56 - 2016-06-27 13:36 - 00051557 _____ C:\Users\Carol\Downloads\2016 Timesheets (2).xlsx
2017-02-15 19:56 - 2016-06-16 12:12 - 00020443 _____ C:\Users\Carol\Downloads\frmTeams.xlsx
2017-02-15 19:56 - 2016-06-08 10:02 - 01275271 _____ C:\Users\Carol\Downloads\cotton_ranking_report___june_2016_2.pdf
2017-02-15 19:56 - 2016-06-06 12:00 - 05971815 _____ C:\Users\Carol\Downloads\2016 June Newsletter.pdf
2017-02-15 19:56 - 2016-05-19 13:46 - 00184039 _____ C:\Users\Carol\Downloads\merged_document (6).pdf
2017-02-15 19:56 - 2016-05-19 13:45 - 00102005 _____ C:\Users\Carol\Downloads\CopyofCarolResume2016Marcomm.2-3.pdf
2017-02-15 19:56 - 2016-05-19 13:44 - 00080163 _____ C:\Users\Carol\Downloads\CoverLetterCity.pdf
2017-02-15 19:56 - 2016-05-19 12:58 - 00100778 _____ C:\Users\Carol\Downloads\CopyofCarolResume2016Marcomm.pdf
2017-02-15 19:56 - 2016-05-17 12:37 - 00100625 _____ C:\Users\Carol\Downloads\CarolResume2015Volunteer (10).2-3.pdf
2017-02-15 19:56 - 2016-05-17 12:37 - 00100059 _____ C:\Users\Carol\Downloads\CarolResume2015Volunteer (10).pdf
2017-02-15 19:56 - 2016-05-16 21:09 - 01258419 _____ C:\Users\Carol\Downloads\www.greattoskate.net.pdf
2017-02-15 19:56 - 2016-05-16 20:27 - 00979597 _____ C:\Users\Carol\Downloads\Untitled design.pdf
2017-02-15 19:56 - 2016-05-16 00:25 - 00067542 _____ C:\Users\Carol\Downloads\CoverLetterAU.pdf
2017-02-15 19:56 - 2016-05-15 22:31 - 00112068 _____ C:\Users\Carol\Downloads\CarolCVAU (1).2-4.pdf
2017-02-15 19:56 - 2016-05-15 22:30 - 00110820 _____ C:\Users\Carol\Downloads\CarolCVAU (1).pdf
2017-02-15 19:56 - 2016-05-15 22:29 - 00110771 _____ C:\Users\Carol\Downloads\CarolCVAU.pdf
2017-02-15 19:56 - 2016-05-15 20:45 - 00040771 _____ C:\Users\Carol\Downloads\References (5).pdf
2017-02-15 19:56 - 2016-05-15 20:42 - 00039689 _____ C:\Users\Carol\Downloads\References (4).pdf
2017-02-15 19:56 - 2016-04-29 09:44 - 00067461 _____ C:\Users\Carol\Downloads\Stampede Exhibitor Agreement.pdf
2017-02-15 19:56 - 2016-04-26 20:59 - 00070140 _____ C:\Users\Carol\Downloads\16_-_Specialist_Media__Public_Relations.pdf
2017-02-15 19:56 - 2016-04-22 14:51 - 00240877 _____ C:\Users\Carol\Downloads\Invoice-158808.pdf
2017-02-15 19:56 - 2016-04-19 19:13 - 00066843 _____ C:\Users\Carol\Downloads\YYCFitnessVolunteerPositions (1).pdf
2017-02-15 19:56 - 2016-04-19 19:08 - 00066462 _____ C:\Users\Carol\Downloads\YYCFitnessVolunteerPositions.pdf
2017-02-15 19:56 - 2016-04-18 23:10 - 00103631 _____ C:\Users\Carol\Downloads\CarolResume2016Marcomm (5).2-3.pdf
2017-02-15 19:56 - 2016-04-18 23:08 - 00067470 _____ C:\Users\Carol\Downloads\CoverLetterInnovateCalgary.pdf
2017-02-15 19:56 - 2016-04-18 21:05 - 00102387 _____ C:\Users\Carol\Downloads\CarolResume2016Marcomm (5).pdf
2017-02-15 19:56 - 2016-04-18 21:04 - 00103624 _____ C:\Users\Carol\Downloads\CarolResume2016Marcomm (4).pdf
2017-02-15 19:56 - 2016-04-17 22:22 - 00173531 _____ C:\Users\Carol\Downloads\merged_document (5).pdf
2017-02-15 19:56 - 2016-04-17 22:17 - 00105189 _____ C:\Users\Carol\Downloads\CarolResume2016Marcomm (3).2-3.pdf
2017-02-15 19:56 - 2016-04-17 22:15 - 00067664 _____ C:\Users\Carol\Downloads\CoverletterCarolChuInsideEducation.pdf
2017-02-15 19:56 - 2016-04-17 15:28 - 00104644 _____ C:\Users\Carol\Downloads\CarolResume2016Marcomm (3).pdf
2017-02-15 19:56 - 2016-04-17 15:26 - 00105269 _____ C:\Users\Carol\Downloads\CarolResume2016Marcomm (2).pdf
2017-02-15 19:56 - 2016-04-10 19:55 - 00079185 _____ C:\Users\Carol\Downloads\Feb-2016-Test-Day-Schedule.xlsx
2017-02-15 19:56 - 2016-03-23 21:32 - 00049239 _____ C:\Users\Carol\Downloads\2016 Timesheets (1).xlsx
2017-02-15 19:56 - 2016-03-23 21:24 - 00051698 _____ C:\Users\Carol\Downloads\2016 Timesheets.xlsx
2017-02-15 19:56 - 2016-03-23 21:21 - 00158265 _____ C:\Users\Carol\Downloads\ReceiptM2316NL.pdf
2017-02-15 19:56 - 2016-03-23 21:21 - 00158265 _____ C:\Users\Carol\Downloads\ReceiptM2316NL (1).pdf
2017-02-15 19:56 - 2016-03-22 11:50 - 02557225 _____ C:\Users\Carol\Downloads\Flames_Player_FunFacts (1).pdf
2017-02-15 19:56 - 2016-03-13 20:55 - 00153981 _____ C:\Users\Carol\Downloads\ReceiptNadalOmoleme (2).pdf
2017-02-15 19:56 - 2016-03-13 20:54 - 00154701 _____ C:\Users\Carol\Downloads\ReceiptNadalOmoleme (1).pdf
2017-02-15 19:56 - 2016-03-04 15:41 - 00059559 _____ C:\Users\Carol\Downloads\Monochrome (Portrait) (3).pdf
2017-02-15 19:56 - 2016-03-04 15:06 - 00059030 _____ C:\Users\Carol\Downloads\Monochrome (Portrait) (2).pdf
2017-02-15 19:56 - 2016-03-03 22:38 - 00058790 _____ C:\Users\Carol\Downloads\Monochrome (Portrait) (1).pdf
2017-02-15 19:56 - 2016-03-03 22:21 - 00058802 _____ C:\Users\Carol\Downloads\Monochrome (Portrait).pdf
2017-02-15 19:56 - 2016-03-03 21:54 - 00068942 _____ C:\Users\Carol\Downloads\Business Card.pdf
2017-02-15 19:56 - 2016-03-02 15:35 - 00081982 _____ C:\Users\Carol\Downloads\CarolResume2016CA (3).2-4.2-3.pdf
2017-02-15 19:56 - 2016-03-02 15:34 - 00102559 _____ C:\Users\Carol\Downloads\CarolResume2016CA (3).2-4.pdf
2017-02-15 19:56 - 2016-03-02 15:14 - 00103868 _____ C:\Users\Carol\Downloads\CarolResume2016CA (3).pdf
2017-02-15 19:56 - 2016-03-02 15:14 - 00103850 _____ C:\Users\Carol\Downloads\CarolResume2016CA (2).pdf
2017-02-15 19:56 - 2016-03-02 15:14 - 00103837 _____ C:\Users\Carol\Downloads\CarolResume2016CA (1).pdf
2017-02-15 19:56 - 2016-02-16 16:46 - 00065368 _____ C:\Users\Carol\Downloads\InvoiceMidnaporeLake (3).pdf
2017-02-15 19:56 - 2016-02-07 21:28 - 00111330 _____ C:\Users\Carol\Downloads\Untitled drawing.pdf
2017-02-15 19:56 - 2016-02-01 16:31 - 00068323 _____ C:\Users\Carol\Downloads\CoverletterCarolChuCalgaryCA.pdf
2017-02-15 19:56 - 2016-02-01 10:46 - 00100622 _____ C:\Users\Carol\Downloads\CarolResume2016CA.2-3.pdf
2017-02-15 19:56 - 2016-02-01 10:45 - 00103899 _____ C:\Users\Carol\Downloads\CarolResume2016CA.pdf
2017-02-15 19:56 - 2016-01-30 22:25 - 00102009 _____ C:\Users\Carol\Downloads\Blogpostwritingsample (1).pdf
2017-02-15 19:56 - 2016-01-30 22:25 - 00044791 _____ C:\Users\Carol\Downloads\BlogPostWritingSample2.pdf
2017-02-15 19:56 - 2016-01-25 22:19 - 00167972 _____ C:\Users\Carol\Downloads\merged_document (4).pdf
2017-02-15 19:56 - 2016-01-25 22:15 - 00067458 _____ C:\Users\Carol\Downloads\CoverletterCarolChuCalgaryMEOW.pdf
2017-02-15 19:56 - 2016-01-25 20:46 - 00101599 _____ C:\Users\Carol\Downloads\CarolResume2016SocialMedia (3).2-3.pdf
2017-02-15 19:56 - 2016-01-25 20:42 - 00104816 _____ C:\Users\Carol\Downloads\CarolResume2016SocialMedia (3).pdf
2017-02-15 19:56 - 2016-01-25 20:41 - 00104966 _____ C:\Users\Carol\Downloads\CarolResume2016SocialMedia (2).pdf
2017-02-15 19:56 - 2016-01-25 20:40 - 00105587 _____ C:\Users\Carol\Downloads\CarolResume2016SocialMedia (1).pdf
2017-02-15 19:56 - 2016-01-18 23:56 - 00071369 _____ C:\Users\Carol\Downloads\CoverletterCarolChuCalgaryYVC.pdf
2017-02-15 19:56 - 2016-01-18 22:53 - 00103016 _____ C:\Users\Carol\Downloads\CarolChu2016YouthCentral (1).2-3.pdf
2017-02-15 19:56 - 2016-01-18 22:51 - 00104287 _____ C:\Users\Carol\Downloads\CarolChu2016YouthCentral (1).pdf
2017-02-15 19:56 - 2016-01-18 22:50 - 00105438 _____ C:\Users\Carol\Downloads\CarolChu2016YouthCentral.pdf
2017-02-15 19:56 - 2016-01-18 16:17 - 00101131 _____ C:\Users\Carol\Downloads\CarolResume2016Community (1).2-3.pdf
2017-02-15 19:56 - 2016-01-18 16:16 - 00102397 _____ C:\Users\Carol\Downloads\CarolResume2016Community (1).pdf
2017-02-15 19:56 - 2016-01-18 16:15 - 00103952 _____ C:\Users\Carol\Downloads\CarolResume2016Community.pdf
2017-02-15 19:56 - 2016-01-18 10:50 - 00418528 _____ C:\Users\Carol\Downloads\Confirmation.pdf
2017-02-15 19:56 - 2016-01-08 17:42 - 00070834 _____ C:\Users\Carol\Downloads\CoverletterCarolChuCalgaryAirport (1).pdf
2017-02-15 19:56 - 2016-01-08 14:52 - 00114743 _____ C:\Users\Carol\Downloads\CarolResume2015Volunteer (9).2-3.pdf
2017-02-15 19:56 - 2016-01-08 14:50 - 00116513 _____ C:\Users\Carol\Downloads\CarolResume2015Volunteer (9).pdf
2017-02-15 19:56 - 2016-01-08 14:49 - 00117037 _____ C:\Users\Carol\Downloads\CarolResume2015Volunteer (8).pdf
2017-02-15 19:56 - 2016-01-08 14:47 - 00117486 _____ C:\Users\Carol\Downloads\CarolResume2015Volunteer (7).pdf
2017-02-15 19:56 - 2016-01-08 13:36 - 00103668 _____ C:\Users\Carol\Downloads\CarolResume2016Benevity (1).2-3.pdf
2017-02-15 19:56 - 2016-01-08 13:35 - 00105566 _____ C:\Users\Carol\Downloads\CarolResume2016Benevity (1).pdf
2017-02-15 19:56 - 2016-01-08 13:31 - 00105715 _____ C:\Users\Carol\Downloads\CarolResume2016Benevity.pdf
2017-02-15 19:56 - 2016-01-07 20:12 - 00049552 _____ C:\Users\Carol\Downloads\Telpay Biller Information Form.pdf
2017-02-15 19:56 - 2016-01-07 16:16 - 00108266 _____ C:\Users\Carol\Downloads\CarolResume2016Marcomm (1).2-3.pdf
2017-02-15 19:56 - 2016-01-07 16:15 - 00069977 _____ C:\Users\Carol\Downloads\CoverletterCarolChuChildrensWish.pdf
2017-02-15 19:56 - 2016-01-07 15:24 - 00109470 _____ C:\Users\Carol\Downloads\CarolResume2016Marcomm (1).pdf
2017-02-15 19:56 - 2016-01-07 11:53 - 00106187 _____ C:\Users\Carol\Downloads\CarolResume2016Marcomm.2-3.pdf
2017-02-15 19:56 - 2016-01-06 12:12 - 00011955 _____ C:\Users\Carol\Downloads\registration list Midnapore.xlsx
2017-02-15 19:56 - 2016-01-06 11:51 - 00102371 _____ C:\Users\Carol\Downloads\CarolResume2016SocialMedia.2-3.pdf
2017-02-15 19:56 - 2016-01-06 11:42 - 00105588 _____ C:\Users\Carol\Downloads\CarolResume2016SocialMedia.pdf
2017-02-15 19:56 - 2016-01-06 10:33 - 00020084 _____ C:\Users\Carol\Downloads\Bank.pdf
2017-02-15 19:56 - 2016-01-05 16:12 - 00104101 _____ C:\Users\Carol\Downloads\CarolResume2016General (2).2-3.pdf
2017-02-15 19:56 - 2016-01-05 16:10 - 00071571 _____ C:\Users\Carol\Downloads\CoverletterCarolChuWard8.pdf
2017-02-15 19:56 - 2016-01-05 14:40 - 00105288 _____ C:\Users\Carol\Downloads\CarolResume2016General (2).pdf
2017-02-15 19:56 - 2016-01-05 14:39 - 00105270 _____ C:\Users\Carol\Downloads\CarolResume2016General (1).pdf
2017-02-15 19:56 - 2016-01-05 14:39 - 00105250 _____ C:\Users\Carol\Downloads\CarolResume2016General.pdf
2017-02-15 19:56 - 2016-01-05 09:40 - 00009333 _____ C:\Users\Carol\Downloads\registration list.xlsx
2017-02-15 19:56 - 2016-01-04 23:27 - 00071917 _____ C:\Users\Carol\Downloads\CoverletterCarolChuAAISA.pdf
2017-02-15 19:56 - 2016-01-04 23:19 - 00029736 _____ C:\Users\Carol\Downloads\WritingSample2.pdf
2017-02-15 19:56 - 2016-01-04 16:12 - 00554055 _____ C:\Users\Carol\Downloads\WritingSampleBrochure.pdf
2017-02-15 19:56 - 2016-01-04 14:37 - 00107392 _____ C:\Users\Carol\Downloads\CarolResume2016Marcomm.pdf
2017-02-15 19:56 - 2016-01-04 10:21 - 00091708 _____ C:\Users\Carol\Downloads\InvoiceWestHillhurst (1).pdf
2017-02-15 19:56 - 2016-01-03 20:55 - 00091708 _____ C:\Users\Carol\Downloads\InvoiceWestHillhurst.pdf
2017-02-15 19:56 - 2016-01-03 19:50 - 00173337 _____ C:\Users\Carol\Downloads\ReceiptNadalOmoleme.pdf
2017-02-15 19:56 - 2015-12-31 13:01 - 00116641 _____ C:\Users\Carol\Downloads\S.M.A.R.T..pdf
2017-02-15 19:56 - 2015-12-30 14:58 - 00075719 _____ C:\Users\Carol\Downloads\InvoiceMidnaporeLake (2).pdf
2017-02-15 19:56 - 2015-12-21 14:26 - 00497281 _____ C:\Users\Carol\Downloads\398319.pdf
2017-02-15 19:56 - 2015-12-20 21:54 - 00106058 _____ C:\Users\Carol\Downloads\CarolResume2015Marcomm (9).2-3.pdf
2017-02-15 19:56 - 2015-12-20 21:53 - 00107262 _____ C:\Users\Carol\Downloads\CarolResume2015Marcomm (9).pdf
2017-02-15 19:56 - 2015-12-20 21:53 - 00107260 _____ C:\Users\Carol\Downloads\CarolResume2015Marcomm (8).pdf
2017-02-15 19:56 - 2015-12-20 21:17 - 00108123 _____ C:\Users\Carol\Downloads\CarolResume2015GeneralIDI.2-3.pdf
2017-02-15 19:56 - 2015-12-20 21:13 - 00109329 _____ C:\Users\Carol\Downloads\CarolResume2015GeneralIDI.pdf
2017-02-15 19:56 - 2015-12-20 21:10 - 00069380 _____ C:\Users\Carol\Downloads\CoverletterCarolChuIDICalgary.pdf
2017-02-15 19:56 - 2015-12-20 13:28 - 00102368 _____ C:\Users\Carol\Downloads\CarolResume2015SocialMedia (7).2-3.pdf
2017-02-15 19:56 - 2015-12-20 13:24 - 00091599 _____ C:\Users\Carol\Downloads\CoverletterCarolChuAlpineCanada.pdf
2017-02-15 19:56 - 2015-12-20 11:39 - 00105585 _____ C:\Users\Carol\Downloads\CarolResume2015SocialMedia (7).pdf
2017-02-15 19:56 - 2015-12-20 11:38 - 00105598 _____ C:\Users\Carol\Downloads\CarolResume2015SocialMedia (5).pdf
2017-02-15 19:56 - 2015-12-20 11:38 - 00105550 _____ C:\Users\Carol\Downloads\CarolResume2015SocialMedia (6).pdf
2017-02-15 19:56 - 2015-12-10 23:53 - 00174419 _____ C:\Users\Carol\Downloads\merged_document_4 (1).pdf
2017-02-15 19:56 - 2015-12-10 23:53 - 00067558 _____ C:\Users\Carol\Downloads\CoverletterCarolChuBankview (1).pdf
2017-02-15 19:56 - 2015-12-10 23:52 - 00107948 _____ C:\Users\Carol\Downloads\CarolResume2015General.2-3.pdf
2017-02-15 19:56 - 2015-12-10 23:51 - 00067559 _____ C:\Users\Carol\Downloads\CoverletterCarolChuBankview.pdf
2017-02-15 19:56 - 2015-12-10 22:16 - 00109153 _____ C:\Users\Carol\Downloads\CarolResume2015General.pdf
2017-02-15 19:56 - 2015-12-08 21:23 - 00188230 _____ C:\Users\Carol\Downloads\merged_document_3 (1).pdf
2017-02-15 19:56 - 2015-12-08 21:23 - 00114470 _____ C:\Users\Carol\Downloads\CarolResume2015Volunteer (6).2-3.pdf
2017-02-15 19:56 - 2015-12-08 21:19 - 00074847 _____ C:\Users\Carol\Downloads\CoverletterCarolChuSTARS (1).pdf
2017-02-15 19:56 - 2015-12-08 20:27 - 00115746 _____ C:\Users\Carol\Downloads\CarolResume2015Volunteer (6).pdf
2017-02-15 19:56 - 2015-12-08 19:53 - 00102771 _____ C:\Users\Carol\Downloads\CarolResume2015Volunteer (5).pdf
2017-02-15 19:56 - 2015-12-08 19:53 - 00101072 _____ C:\Users\Carol\Downloads\CarolResume2015Volunteer (5).2-3.pdf
2017-02-15 19:56 - 2015-12-08 19:52 - 00101052 _____ C:\Users\Carol\Downloads\CarolResume2015Volunteer (4).2-3.pdf
2017-02-15 19:56 - 2015-12-08 19:45 - 00077199 _____ C:\Users\Carol\Downloads\CoverletterCarolChuSTARS.pdf
2017-02-15 19:56 - 2015-12-08 19:04 - 00102258 _____ C:\Users\Carol\Downloads\CarolResume2015Volunteer (4).pdf
2017-02-15 19:56 - 2015-12-07 22:48 - 00073772 _____ C:\Users\Carol\Downloads\InvoiceMidnaporeLake (1).pdf
2017-02-15 19:56 - 2015-12-07 22:46 - 00073772 _____ C:\Users\Carol\Downloads\InvoiceMidnaporeLake.pdf
2017-02-15 19:56 - 2015-12-02 16:36 - 00077798 _____ C:\Users\Carol\Downloads\19201104019-474682641-ticket (2).pdf
2017-02-15 19:56 - 2015-12-02 11:29 - 00061667 _____ C:\Users\Carol\Downloads\MidnaporeLakeWaiver (2).1.pdf
2017-02-15 19:56 - 2015-12-02 11:28 - 00062598 _____ C:\Users\Carol\Downloads\MidnaporeLakeWaiver (2).pdf
2017-02-15 19:56 - 2015-12-01 17:20 - 00198779 _____ C:\Users\Carol\Downloads\151130-34153.pdf
2017-02-15 19:56 - 2015-12-01 10:09 - 00060675 _____ C:\Users\Carol\Downloads\MidnaporeLakeWaiver (1).1.pdf
2017-02-15 19:56 - 2015-12-01 10:06 - 00061978 _____ C:\Users\Carol\Downloads\MidnaporeLakeWaiver.pdf
2017-02-15 19:56 - 2015-12-01 10:06 - 00061606 _____ C:\Users\Carol\Downloads\MidnaporeLakeWaiver (1).pdf
2017-02-15 19:56 - 2015-11-30 19:48 - 00077798 _____ C:\Users\Carol\Downloads\19201104019-474682641-ticket (1).pdf
2017-02-15 19:56 - 2015-11-30 19:26 - 00077798 _____ C:\Users\Carol\Downloads\19201104019-474682641-ticket.pdf
2017-02-15 19:56 - 2015-11-30 14:47 - 00148878 _____ C:\Users\Carol\Downloads\GreattoSkateMidnaporeLakeContract (3).pdf
2017-02-15 19:56 - 2015-11-30 14:46 - 00148908 _____ C:\Users\Carol\Downloads\GreattoSkateMidnaporeLakeContract (1).pdf
2017-02-15 19:56 - 2015-11-30 14:46 - 00148878 _____ C:\Users\Carol\Downloads\GreattoSkateMidnaporeLakeContract (2).pdf
2017-02-15 19:56 - 2015-11-29 20:52 - 00147384 _____ C:\Users\Carol\Downloads\GreattoSkateMidnaporeLakeContract.pdf
2017-02-15 19:56 - 2015-11-29 14:46 - 00184708 _____ C:\Users\Carol\Downloads\GreatToSkateContract125 (1).pdf
2017-02-15 19:56 - 2015-11-23 15:45 - 00041850 _____ C:\Users\Carol\Downloads\References (3).pdf
2017-02-15 19:56 - 2015-11-23 15:44 - 00101963 _____ C:\Users\Carol\Downloads\CarolResume2015Volunteer (3).2-3.pdf
2017-02-15 19:56 - 2015-11-23 15:41 - 00103661 _____ C:\Users\Carol\Downloads\CarolResume2015Volunteer (3).pdf
2017-02-15 19:56 - 2015-11-23 15:36 - 00107217 _____ C:\Users\Carol\Downloads\CarolResume2015Volunteer (2).pdf
2017-02-15 19:56 - 2015-11-23 15:35 - 00108906 _____ C:\Users\Carol\Downloads\CarolResume2015Recreation (2).pdf
2017-02-15 19:56 - 2015-11-23 15:23 - 00073764 _____ C:\Users\Carol\Downloads\CoverletterCarolChuCPL.pdf
2017-02-15 19:56 - 2015-11-23 14:04 - 00755090 _____ C:\Users\Carol\Downloads\New Patient Intake Form (2015).pdf
2017-02-15 19:56 - 2015-11-22 16:04 - 00136761 _____ C:\Users\Carol\Downloads\2016CampaignandEventsAssistantPosting_Final.pdf
2017-02-15 19:56 - 2015-11-21 23:27 - 00105825 _____ C:\Users\Carol\Downloads\CarolResume2015Marcomm ARPA.pdf
2017-02-15 19:56 - 2015-11-21 23:23 - 00070930 _____ C:\Users\Carol\Downloads\CoverletterCarolChu(ARPA).pdf
2017-02-15 19:56 - 2015-11-21 21:19 - 00107030 _____ C:\Users\Carol\Downloads\CopyofCarolResume2015Marcomm (2).pdf
2017-02-15 19:56 - 2015-11-21 21:17 - 00107685 _____ C:\Users\Carol\Downloads\CopyofCarolResume2015Marcomm (1).pdf
2017-02-15 19:56 - 2015-11-21 21:16 - 00107886 _____ C:\Users\Carol\Downloads\CopyofCarolResume2015Marcomm.pdf
2017-02-15 19:56 - 2015-11-17 15:31 - 00103260 _____ C:\Users\Carol\Downloads\CarolResume2015Marcomm (7).2-3.pdf
2017-02-15 19:56 - 2015-11-17 15:30 - 00104465 _____ C:\Users\Carol\Downloads\CarolResume2015Marcomm (7).pdf
2017-02-15 19:56 - 2015-11-17 13:46 - 00102211 _____ C:\Users\Carol\Downloads\CarolResume2015SocialMedia (4).2-3.pdf
2017-02-15 19:56 - 2015-11-17 12:43 - 00105428 _____ C:\Users\Carol\Downloads\CarolResume2015SocialMedia (4).pdf
2017-02-15 19:56 - 2015-11-16 21:35 - 00187645 _____ C:\Users\Carol\Downloads\merged_document_2 (2).pdf
2017-02-15 19:56 - 2015-11-16 21:34 - 00114528 _____ C:\Users\Carol\Downloads\CarolResume2015LTS (2).2-3.pdf
2017-02-15 19:56 - 2015-11-16 21:33 - 00115800 _____ C:\Users\Carol\Downloads\CarolResume2015LTS (2).pdf
2017-02-15 19:56 - 2015-11-16 21:29 - 00074208 _____ C:\Users\Carol\Downloads\CoverletterLTSCarolChu.pdf
2017-02-15 19:56 - 2015-11-16 20:22 - 00115805 _____ C:\Users\Carol\Downloads\CarolResume2015LTS (1).pdf
2017-02-15 19:56 - 2015-11-16 20:09 - 00102622 _____ C:\Users\Carol\Downloads\CarolResume2015LTS.pdf
2017-02-15 19:56 - 2015-11-11 21:16 - 00104409 _____ C:\Users\Carol\Downloads\CarolResume2015Marcomm (4iiii) (1).2-3.pdf
2017-02-15 19:56 - 2015-11-11 21:16 - 00104409 _____ C:\Users\Carol\Downloads\CarolResume2015Marcomm (4iiii) (1).2-3 (1).pdf
2017-02-15 19:56 - 2015-11-11 21:15 - 00106314 _____ C:\Users\Carol\Downloads\CarolResume2015Marcomm (4iiii) (1).pdf
2017-02-15 19:56 - 2015-11-11 21:13 - 00068312 _____ C:\Users\Carol\Downloads\Coverletter4iiiCarolChu (1).pdf
2017-02-15 19:56 - 2015-11-11 21:09 - 00068169 _____ C:\Users\Carol\Downloads\Coverletter4iiiCarolChu.pdf
2017-02-15 19:56 - 2015-11-11 18:16 - 00106314 _____ C:\Users\Carol\Downloads\CarolResume2015Marcomm (4iiii).pdf
2017-02-15 19:56 - 2015-11-11 10:36 - 00102187 _____ C:\Users\Carol\Downloads\CarolResume2015SocialMedia (3).2-3.pdf
2017-02-15 19:56 - 2015-11-11 10:23 - 00105404 _____ C:\Users\Carol\Downloads\CarolResume2015SocialMedia (3).pdf
2017-02-15 19:56 - 2015-11-11 10:21 - 00105362 _____ C:\Users\Carol\Downloads\CarolResume2015SocialMedia (2).pdf
2017-02-15 19:56 - 2015-11-11 10:20 - 00105352 _____ C:\Users\Carol\Downloads\CarolResume2015SocialMedia (1).pdf
2017-02-15 19:56 - 2015-11-02 14:37 - 00104038 _____ C:\Users\Carol\Downloads\CarolResume2015Marcomm (6).2-3.pdf
2017-02-15 19:56 - 2015-11-02 14:34 - 00105243 _____ C:\Users\Carol\Downloads\CarolResume2015Marcomm (6).pdf
2017-02-15 19:56 - 2015-11-02 14:30 - 00107485 _____ C:\Users\Carol\Downloads\CarolResume2015Marcomm (5).pdf
2017-02-15 19:56 - 2015-11-02 12:47 - 00076392 _____ C:\Users\Carol\Downloads\CoverletterCarolChuAgaKhan.pdf
2017-02-15 19:56 - 2015-11-02 10:16 - 00102471 _____ C:\Users\Carol\Downloads\CarolResume2015AgaKhan (1).2-3.pdf
2017-02-15 19:56 - 2015-11-02 10:15 - 00104371 _____ C:\Users\Carol\Downloads\CarolResume2015AgaKhan (1).pdf
2017-02-15 19:56 - 2015-11-02 10:14 - 00104252 _____ C:\Users\Carol\Downloads\CarolResume2015AgaKhan.pdf
2017-02-15 19:56 - 2015-11-01 22:21 - 00104967 _____ C:\Users\Carol\Downloads\CarolResume2015CI (2).pdf
2017-02-15 19:56 - 2015-11-01 22:21 - 00103768 _____ C:\Users\Carol\Downloads\CarolResume2015CI (2).2-3.pdf
2017-02-15 19:56 - 2015-11-01 22:16 - 00104995 _____ C:\Users\Carol\Downloads\CarolResume2015CI (1).pdf
2017-02-15 19:56 - 2015-11-01 22:03 - 00103222 _____ C:\Users\Carol\Downloads\CarolResume2015CI.2-3.pdf
2017-02-15 19:56 - 2015-11-01 22:00 - 00104423 _____ C:\Users\Carol\Downloads\CarolResume2015CI.pdf
2017-02-15 19:56 - 2015-11-01 19:03 - 00073662 _____ C:\Users\Carol\Downloads\CoverletterCarolChuStMarys.pdf
2017-02-15 19:56 - 2015-11-01 19:02 - 00101263 _____ C:\Users\Carol\Downloads\CarolResume2015StMarys.2-3.pdf
2017-02-15 19:56 - 2015-11-01 10:19 - 00102469 _____ C:\Users\Carol\Downloads\CarolResume2015StMarys.pdf
2017-02-15 19:56 - 2015-10-30 21:03 - 00101829 _____ C:\Users\Carol\Downloads\CarolResume2015Calgary.2-3.pdf
2017-02-15 19:56 - 2015-10-30 21:02 - 00105045 _____ C:\Users\Carol\Downloads\CarolResume2015Calgary.pdf
2017-02-15 19:56 - 2015-10-30 15:03 - 00105045 _____ C:\Users\Carol\Downloads\CarolResume2015MarcommDigital (4).pdf
2017-02-15 19:56 - 2015-10-30 15:03 - 00101829 _____ C:\Users\Carol\Downloads\CarolResume2015MarcommDigital (4).2-3.pdf
2017-02-15 19:56 - 2015-10-30 15:02 - 00101827 _____ C:\Users\Carol\Downloads\CarolResume2015MarcommDigital (3).2-3.pdf
2017-02-15 19:56 - 2015-10-30 14:58 - 00105043 _____ C:\Users\Carol\Downloads\CarolResume2015MarcommDigital (3).pdf
2017-02-15 19:56 - 2015-10-30 14:57 - 00105049 _____ C:\Users\Carol\Downloads\CarolResume2015MarcommDigital (2).pdf
2017-02-15 19:56 - 2015-10-29 21:20 - 00100544 _____ C:\Users\Carol\Downloads\CarolResume2015Recreation (1).2-3.pdf
2017-02-15 19:56 - 2015-10-29 21:00 - 00101750 _____ C:\Users\Carol\Downloads\CarolResume2015Recreation (1).pdf
2017-02-15 19:56 - 2015-10-29 20:59 - 00074698 _____ C:\Users\Carol\Downloads\CoverletterCarolChuABRecreation.pdf
2017-02-15 19:56 - 2015-10-29 19:51 - 00101805 _____ C:\Users\Carol\Downloads\CarolResume2015Recreation.pdf
2017-02-15 19:56 - 2015-10-29 19:50 - 00101810 _____ C:\Users\Carol\Downloads\CarolResume2015Volunteer (1).pdf
2017-02-15 19:56 - 2015-10-29 13:07 - 00070971 _____ C:\Users\Carol\Downloads\CoverletterCarolChuNaturalFoods.pdf
2017-02-15 19:56 - 2015-10-29 10:09 - 00104963 _____ C:\Users\Carol\Downloads\CarolResume2015SocialMedia.pdf
2017-02-15 19:56 - 2015-10-29 10:09 - 00103762 _____ C:\Users\Carol\Downloads\CarolResume2015SocialMedia.2-3.pdf
2017-02-15 19:56 - 2015-10-28 22:33 - 00167674 _____ C:\Users\Carol\Downloads\merged_document (3).pdf
2017-02-15 19:56 - 2015-10-28 22:33 - 00066026 _____ C:\Users\Carol\Downloads\CoverletterCarolChuCityofCalgaryDigitalCommunications.pdf
2017-02-15 19:56 - 2015-10-28 22:32 - 00102741 _____ C:\Users\Carol\Downloads\CarolResume2015MarcommDigital (1).2-3.pdf
2017-02-15 19:56 - 2015-10-28 22:31 - 00103941 _____ C:\Users\Carol\Downloads\CarolResume2015MarcommDigital (1).pdf
2017-02-15 19:56 - 2015-10-28 21:16 - 00103941 _____ C:\Users\Carol\Downloads\CarolResume2015MarcommDigital.pdf
2017-02-15 19:56 - 2015-10-27 21:35 - 00277887 _____ C:\Users\Carol\Downloads\HOW TO PARTICIPATE.pdf
2017-02-15 19:56 - 2015-10-27 21:33 - 00277887 _____ C:\Users\Carol\Downloads\FB explanantion.pdf
2017-02-15 19:56 - 2015-10-26 21:22 - 00103510 _____ C:\Users\Carol\Downloads\CarolResume2015Benevity (1).2-3.pdf
2017-02-15 19:56 - 2015-10-26 20:35 - 00107867 _____ C:\Users\Carol\Downloads\CarolResume2015Marcomm (4).2-3.pdf
2017-02-15 19:56 - 2015-10-26 20:34 - 00109072 _____ C:\Users\Carol\Downloads\CarolResume2015Marcomm (4).pdf
2017-02-15 19:56 - 2015-10-26 19:33 - 00104711 _____ C:\Users\Carol\Downloads\CarolResume2015Benevity (1).pdf
2017-02-15 19:56 - 2015-10-26 19:31 - 00105350 _____ C:\Users\Carol\Downloads\CarolResume2015Benevity.pdf
2017-02-15 19:56 - 2015-10-15 11:58 - 00112544 _____ C:\Users\Carol\Downloads\convert-jpg-to-pdf.net_2015-10-15_20-58-29.pdf
2017-02-15 19:56 - 2015-10-14 17:12 - 00079908 _____ C:\Users\Carol\Downloads\CoverletterCarolChuTelusSpark (1).pdf
2017-02-15 19:56 - 2015-10-14 16:56 - 00107408 _____ C:\Users\Carol\Downloads\CarolResume2015Volunteer.2-3.pdf
2017-02-15 19:56 - 2015-10-14 16:53 - 00108614 _____ C:\Users\Carol\Downloads\CarolResume2015Volunteer.pdf
2017-02-15 19:56 - 2015-10-14 15:18 - 00077968 _____ C:\Users\Carol\Downloads\CoverletterCarolChuTelusSpark.pdf
2017-02-15 19:56 - 2015-10-09 21:54 - 00109155 _____ C:\Users\Carol\Downloads\CarolResume2015Marcomm (3).pdf
2017-02-15 19:56 - 2015-10-09 15:25 - 00064105 _____ C:\Users\Carol\Downloads\CoverletterCarolChuWM.pdf
2017-02-15 19:56 - 2015-10-09 14:15 - 00072776 _____ C:\Users\Carol\Downloads\CoverletterCarolChuRonaldMc (1).pdf
2017-02-15 19:56 - 2015-10-09 14:11 - 00041850 _____ C:\Users\Carol\Downloads\References (2).pdf
2017-02-15 19:56 - 2015-10-09 14:07 - 00072800 _____ C:\Users\Carol\Downloads\CoverletterCarolChuRonaldMc.pdf
2017-02-15 19:56 - 2015-10-07 14:56 - 00072633 _____ C:\Users\Carol\Downloads\CoverletterCarolChuBetweenFriends.pdf
2017-02-15 19:56 - 2015-10-07 13:45 - 00919088 _____ C:\Users\Carol\Downloads\support-refugees-walk2.pdf
2017-02-15 19:56 - 2015-10-05 15:03 - 00038430 _____ C:\Users\Carol\Downloads\GreattoSkateHolidayCampWaiver.pdf
2017-02-15 19:56 - 2015-10-04 21:51 - 00207217 _____ C:\Users\Carol\Downloads\Order_Canvas_V2.pdf
2017-02-15 19:56 - 2015-10-01 13:58 - 00109155 _____ C:\Users\Carol\Downloads\CarolResume2015Marcomm (2) (1).pdf
2017-02-15 19:56 - 2015-10-01 13:47 - 00066782 _____ C:\Users\Carol\Downloads\CoverletterCarolChuABM.pdf
2017-02-15 19:56 - 2015-09-30 19:51 - 00059100 _____ C:\Users\Carol\Downloads\Untitleddocument (3).pdf
2017-02-15 19:56 - 2015-09-30 19:46 - 00059069 _____ C:\Users\Carol\Downloads\Untitleddocument (2).pdf
2017-02-15 19:56 - 2015-09-30 19:28 - 00057111 _____ C:\Users\Carol\Downloads\Untitleddocument (1).pdf
2017-02-15 19:56 - 2015-09-30 18:51 - 00027054 _____ C:\Users\Carol\Downloads\Untitleddocument.pdf
2017-02-15 19:56 - 2015-09-30 14:16 - 00070080 _____ C:\Users\Carol\Downloads\CoverletterCarolChuVecova.pdf
2017-02-15 19:56 - 2015-09-25 09:24 - 00607079 _____ C:\Users\Carol\Downloads\moraine-shuttle-2015.pdf
2017-02-15 19:56 - 2015-09-24 22:47 - 00066448 _____ C:\Users\Carol\Downloads\CoverletterCarolChuCBCF.pdf
2017-02-15 19:56 - 2015-09-23 10:31 - 07637737 _____ C:\Users\Carol\Downloads\EWB Calgary AGM - updated with finance slides.pptx
2017-02-15 19:56 - 2015-09-22 21:58 - 00108239 _____ C:\Users\Carol\Downloads\CarolResume2015Blend (2).2-3.pdf
2017-02-15 19:56 - 2015-09-22 20:41 - 00184708 _____ C:\Users\Carol\Downloads\GreatToSkateContract125.pdf
2017-02-15 19:56 - 2015-09-22 15:10 - 00109368 _____ C:\Users\Carol\Downloads\CarolResume2015Blend (3).pdf
2017-02-15 19:56 - 2015-09-22 15:08 - 00107950 _____ C:\Users\Carol\Downloads\CarolChuResume2015Marcomm .pdf
2017-02-15 19:56 - 2015-09-22 15:07 - 00109155 _____ C:\Users\Carol\Downloads\CarolResume2015Marcomm (2).pdf
2017-02-15 19:56 - 2015-09-22 15:05 - 00109143 _____ C:\Users\Carol\Downloads\CarolResume2015Marcomm (1).pdf
2017-02-15 19:56 - 2015-09-22 15:02 - 00109444 _____ C:\Users\Carol\Downloads\CarolResume2015Blend (2).pdf
2017-02-15 19:56 - 2015-09-22 15:00 - 00109459 _____ C:\Users\Carol\Downloads\CarolResume2015Blend (1).pdf
2017-02-15 19:56 - 2015-09-22 14:56 - 00110010 _____ C:\Users\Carol\Downloads\CarolResume2015Blend.pdf
2017-02-15 19:56 - 2015-09-22 11:12 - 00072964 _____ C:\Users\Carol\Downloads\CoverletterCarolChuCUPS.pdf
2017-02-15 19:56 - 2015-09-21 21:39 - 00068115 _____ C:\Users\Carol\Downloads\CoverletterCarolChuTheAlex (1).pdf
2017-02-15 19:56 - 2015-09-21 21:34 - 00068183 _____ C:\Users\Carol\Downloads\CoverletterCarolChuTheAlex.pdf
2017-02-15 19:56 - 2015-09-21 14:35 - 00066569 _____ C:\Users\Carol\Downloads\CoverletterCarolChuSAIT.pdf
2017-02-15 19:56 - 2015-09-11 13:58 - 00173346 _____ C:\Users\Carol\Downloads\merged_document (2).pdf
2017-02-15 19:56 - 2015-09-11 13:56 - 00067433 _____ C:\Users\Carol\Downloads\CoverletterCarolChuUofC.pdf
2017-02-15 19:56 - 2015-09-10 21:32 - 00107752 _____ C:\Users\Carol\Downloads\CarolResume2015Events.2-3.pdf
2017-02-15 19:56 - 2015-09-10 21:30 - 00073219 _____ C:\Users\Carol\Downloads\CoverletterCarolChuWellspring.pdf
2017-02-15 19:56 - 2015-09-10 15:08 - 00078727 _____ C:\Users\Carol\Downloads\17812075397-454152947-ticket (2).pdf
2017-02-15 19:56 - 2015-09-10 15:06 - 00078727 _____ C:\Users\Carol\Downloads\17812075397-454152947-ticket.pdf
2017-02-15 19:56 - 2015-09-10 15:06 - 00078248 _____ C:\Users\Carol\Downloads\17812075397-454152947-ticket (1).pdf
2017-02-15 19:56 - 2015-09-10 14:34 - 00109656 _____ C:\Users\Carol\Downloads\CarolResume2015Events.pdf
2017-02-15 19:56 - 2015-09-09 19:59 - 00014917 _____ C:\Users\Carol\Downloads\Calgary Non-Profit Database edited.xlsx
2017-02-15 19:56 - 2015-09-09 19:11 - 00015020 _____ C:\Users\Carol\Downloads\Calgary Non-Profit Database (3).xlsx
2017-02-15 19:56 - 2015-09-08 21:05 - 00168266 _____ C:\Users\Carol\Downloads\combined_document_2.pdf
2017-02-15 19:56 - 2015-09-08 21:05 - 00105047 _____ C:\Users\Carol\Downloads\CarolResume2015Human.2-3.pdf
2017-02-15 19:56 - 2015-09-08 20:57 - 00064307 _____ C:\Users\Carol\Downloads\CoverletterCarolChuYEC.pdf
2017-02-15 19:56 - 2015-09-08 20:30 - 00106252 _____ C:\Users\Carol\Downloads\CarolResume2015Human.pdf
2017-02-15 19:56 - 2015-09-08 14:16 - 00152884 _____ C:\Users\Carol\Downloads\Blank Digital Document.pdf
2017-02-15 19:56 - 2015-09-08 14:16 - 00030145 _____ C:\Users\Carol\Downloads\Blank Digital Document(1).pdf
2017-02-15 19:56 - 2015-09-08 14:15 - 00918262 _____ C:\Users\Carol\Downloads\Blank Print Document(1).pdf
2017-02-15 19:56 - 2015-09-08 14:15 - 00279299 _____ C:\Users\Carol\Downloads\Newsletter.pdf
2017-02-15 19:56 - 2015-09-08 14:12 - 00032075 _____ C:\Users\Carol\Downloads\Smoking(1).pdf
2017-02-15 19:56 - 2015-09-08 14:12 - 00005035 _____ C:\Users\Carol\Downloads\Skate Park(1).pdf
2017-02-15 19:56 - 2015-09-08 14:11 - 00103649 _____ C:\Users\Carol\Downloads\GetGoingSignSummer(1).pdf
2017-02-15 19:56 - 2015-09-08 14:11 - 00007460 _____ C:\Users\Carol\Downloads\Family Fun Day(1).pdf
2017-02-15 19:56 - 2015-09-08 14:00 - 00839422 _____ C:\Users\Carol\Downloads\Get Going May_June pictures.pdf
2017-02-15 19:56 - 2015-09-08 14:00 - 00009913 _____ C:\Users\Carol\Downloads\Blank Print Document.pdf
2017-02-15 19:56 - 2015-09-08 13:59 - 00010083 _____ C:\Users\Carol\Downloads\Equipment List.pdf
2017-02-15 19:56 - 2015-09-08 12:58 - 00173599 _____ C:\Users\Carol\Downloads\ReceiptSChan.pdf
2017-02-15 19:56 - 2015-09-03 14:36 - 00015020 _____ C:\Users\Carol\Downloads\Calgary Non-Profit Database (2).xlsx
2017-02-15 19:56 - 2015-09-02 11:02 - 00173415 _____ C:\Users\Carol\Downloads\ChuC-application-Digital-Coordinator-Specialist-2015.pdf
2017-02-15 19:56 - 2015-09-02 10:56 - 00067506 _____ C:\Users\Carol\Downloads\CoverletterCarolChuPembinaInstitute.pdf
2017-02-15 19:56 - 2015-09-01 07:31 - 00080535 _____ C:\Users\Carol\Downloads\CoverletterCarolChuDucksUnlimited.pdf
2017-02-15 19:56 - 2015-08-31 20:23 - 00084397 _____ C:\Users\Carol\Downloads\CoverletterCarolChuMRU.pdf
2017-02-15 19:56 - 2015-08-31 12:56 - 00082516 _____ C:\Users\Carol\Downloads\CoverletterCarolChuTrico.pdf
2017-02-15 19:56 - 2015-08-31 11:28 - 00107002 _____ C:\Users\Carol\Downloads\CarolResume2015Marcomm.2-3.pdf
2017-02-15 19:56 - 2015-08-31 11:25 - 00108206 _____ C:\Users\Carol\Downloads\CarolResume2015Marcomm.pdf
2017-02-15 19:56 - 2015-08-30 15:20 - 00086103 _____ C:\Users\Carol\Downloads\CoverletterCarolChuWinsport.pdf
2017-02-15 19:56 - 2015-08-30 13:39 - 00106708 _____ C:\Users\Carol\Downloads\CarolResume2015SocialEntrepreneur.2-3.pdf
2017-02-15 19:56 - 2015-08-30 13:38 - 00107907 _____ C:\Users\Carol\Downloads\CarolResume2015SocialEntrepreneur.pdf
2017-02-15 19:56 - 2015-08-26 21:00 - 00014985 _____ C:\Users\Carol\Downloads\Expense statement.xlsx
2017-02-15 19:56 - 2015-08-25 19:02 - 00077795 _____ C:\Users\Carol\Downloads\CoverletterSheratonSuites.pdf
2017-02-15 19:56 - 2015-08-25 18:47 - 00081742 _____ C:\Users\Carol\Downloads\CoverletterCarolChuFairmontBanffSprings (1).pdf
2017-02-15 19:56 - 2015-08-25 18:04 - 00106708 _____ C:\Users\Carol\Downloads\CarolChuResume2014-12Communications (11).2-3.pdf
2017-02-15 19:56 - 2015-08-25 18:02 - 00107907 _____ C:\Users\Carol\Downloads\CarolChuResume2014-12Communications (11).pdf
2017-02-15 19:56 - 2015-08-24 20:31 - 00046756 _____ C:\Users\Carol\Downloads\InvoiceTemplate.pdf
2017-02-15 19:56 - 2015-08-23 22:15 - 00015020 _____ C:\Users\Carol\Downloads\Calgary Non-Profit Database (1).xlsx
2017-02-15 19:56 - 2015-08-23 22:12 - 00015020 _____ C:\Users\Carol\Downloads\Calgary Non-Profit Database.xlsx
2017-02-15 19:56 - 2015-08-22 16:37 - 00560796 _____ C:\Users\Carol\Downloads\20039.pdf
2017-02-15 19:56 - 2015-08-18 11:01 - 00106322 _____ C:\Users\Carol\Downloads\CarolChuResume2014-12Communications (10).2-3.pdf
2017-02-15 19:56 - 2015-08-18 11:00 - 00107520 _____ C:\Users\Carol\Downloads\CarolChuResume2014-12Communications (10).pdf
2017-02-15 19:56 - 2015-08-18 11:00 - 00087415 _____ C:\Users\Carol\Downloads\CarolChuResume2014-12Communications (9).1-2.pdf
2017-02-15 19:56 - 2015-08-18 10:58 - 00107484 _____ C:\Users\Carol\Downloads\CarolChuResume2014-12Communications (9).pdf
2017-02-15 19:56 - 2015-08-17 21:48 - 00364501 _____ C:\Users\Carol\Downloads\TIF Calgary  Aug 26 poster.pdf
2017-02-15 19:56 - 2015-08-17 20:47 - 00251257 _____ C:\Users\Carol\Downloads\fair trade poster r3.pdf
2017-02-15 19:56 - 2015-08-16 14:57 - 04037811 _____ C:\Users\Carol\Downloads\Flames_Player_FunFacts.pdf
2017-02-15 19:56 - 2015-08-15 21:50 - 03390359 _____ C:\Users\Carol\Downloads\F_S_PhysEd_stretching.pdf
2017-02-15 19:56 - 2015-07-16 09:49 - 01805363 _____ C:\Users\Carol\Downloads\What-Sways-Women-To-Play-Sport.pdf
2017-02-15 19:56 - 2015-07-14 21:50 - 00099300 _____ C:\Users\Carol\Downloads\ProgramsTimesheet1-15.pdf
2017-02-15 19:56 - 2015-07-11 15:37 - 06070220 _____ C:\Users\Carol\Downloads\Richmond_Physical_Literacy_Manual.pdf
2017-02-15 19:56 - 2015-06-16 18:04 - 01394688 _____ C:\Users\Carol\Downloads\sample_data-trifon25Apr.xls
2017-02-15 19:56 - 2015-06-09 20:49 - 00927418 _____ C:\Users\Carol\Downloads\Retreat_Registration_Form.xlsx
2017-02-15 19:56 - 2015-06-05 22:45 - 00177636 _____ C:\Users\Carol\Downloads\Wrestling Summer.pdf
2017-02-15 19:56 - 2015-06-05 21:16 - 00020795 _____ C:\Users\Carol\Downloads\DOC001.pdf
2017-02-15 19:56 - 2015-05-26 15:01 - 00034434 _____ C:\Users\Carol\Downloads\GetGoingExpenses - Sheet1 (1).pdf
2017-02-15 19:56 - 2015-05-26 15:00 - 00034430 _____ C:\Users\Carol\Downloads\GetGoingExpenses - Sheet1.pdf
2017-02-15 19:56 - 2015-05-26 13:54 - 00011881 _____ C:\Users\Carol\Downloads\invoiceto.me.pdf
2017-02-15 19:56 - 2015-05-20 20:48 - 00005160 _____ C:\Users\Carol\Downloads\Equipment List (1).xlsx
2017-02-15 19:56 - 2015-05-15 10:47 - 00877852 _____ C:\Users\Carol\Downloads\Brochure 02 (2).pdf
2017-02-15 19:56 - 2015-05-15 00:10 - 00384575 _____ C:\Users\Carol\Downloads\convert-jpg-to-pdf.net_2015-05-15_09-09-53.pdf
2017-02-15 19:56 - 2015-05-13 08:49 - 00019544 _____ C:\Users\Carol\Downloads\Sign in Sheet - Sheet1 (2).pdf
2017-02-15 19:56 - 2015-05-13 08:47 - 00020631 _____ C:\Users\Carol\Downloads\Sign in Sheet - Sheet1 (1).pdf
2017-02-15 19:56 - 2015-05-13 08:43 - 00020624 _____ C:\Users\Carol\Downloads\Sign in Sheet - Sheet1.pdf
2017-02-15 19:56 - 2015-05-13 08:41 - 00004234 _____ C:\Users\Carol\Downloads\Sign in Sheet.xlsx
2017-02-15 19:56 - 2015-05-11 09:48 - 00004816 _____ C:\Users\Carol\Downloads\Equipment List.xlsx
2017-02-15 19:56 - 2015-05-11 09:42 - 00058531 _____ C:\Users\Carol\Downloads\Smoking.pdf
2017-02-15 19:56 - 2015-05-11 09:00 - 00027134 _____ C:\Users\Carol\Downloads\Bike sign.pdf
2017-02-15 19:56 - 2015-05-11 08:20 - 00004718 _____ C:\Users\Carol\Downloads\Skate Park.pdf
2017-02-15 19:56 - 2015-05-11 08:18 - 00004783 _____ C:\Users\Carol\Downloads\At Soccer Fields.pdf
2017-02-15 19:56 - 2015-05-11 08:18 - 00004631 _____ C:\Users\Carol\Downloads\At Playground.pdf
2017-02-15 19:56 - 2015-05-11 08:18 - 00004568 _____ C:\Users\Carol\Downloads\At Tennis Courts.pdf
2017-02-15 19:56 - 2015-05-11 08:11 - 00055346 _____ C:\Users\Carol\Downloads\Wait.pdf
2017-02-15 19:56 - 2015-05-11 08:08 - 00007156 _____ C:\Users\Carol\Downloads\Family Fun Day.pdf
2017-02-15 19:56 - 2015-05-11 08:05 - 00005669 _____ C:\Users\Carol\Downloads\Weather.pdf
2017-02-15 19:56 - 2015-05-11 08:00 - 00102940 _____ C:\Users\Carol\Downloads\GetGoingSignSummer.pdf
2017-02-15 19:56 - 2015-05-11 07:55 - 00102693 _____ C:\Users\Carol\Downloads\Get Going Hut sign.pdf
2017-02-15 19:56 - 2015-05-07 15:07 - 00024522 _____ C:\Users\Carol\Downloads\SimplifiedSchedule.pdf
2017-02-15 19:56 - 2015-05-07 14:54 - 00117639 _____ C:\Users\Carol\Downloads\Waiver.pdf
2017-02-15 19:56 - 2015-05-07 12:30 - 00016432 _____ C:\Users\Carol\Downloads\Blank August 2015 Calendar.xlsx
2017-02-15 19:56 - 2015-05-07 11:56 - 00016065 _____ C:\Users\Carol\Downloads\Blank July 2015 Calendar.xlsx
2017-02-15 19:56 - 2015-05-07 11:55 - 00085672 _____ C:\Users\Carol\Downloads\2015-Monthly-Calendar.xlsx
2017-02-15 19:56 - 2015-05-07 11:06 - 05847809 _____ C:\Users\Carol\Downloads\Brochure 02 (1).pdf
2017-02-15 19:56 - 2015-05-07 10:43 - 05847871 _____ C:\Users\Carol\Downloads\Brochure 02.pdf
2017-02-15 19:56 - 2015-05-06 12:12 - 00015975 _____ C:\Users\Carol\Downloads\June-2015-Calendar.xlsx
2017-02-15 19:56 - 2015-05-05 21:45 - 00016170 _____ C:\Users\Carol\Downloads\May-2015-CalendarGet Going.xlsx
2017-02-15 19:56 - 2015-05-05 20:42 - 00016558 _____ C:\Users\Carol\Downloads\May-2015-Calendar (2).xlsx
2017-02-15 19:56 - 2015-05-05 20:32 - 00016558 _____ C:\Users\Carol\Downloads\May-2015-Calendar (1).xlsx
2017-02-15 19:56 - 2015-05-05 13:43 - 00016558 _____ C:\Users\Carol\Downloads\May-2015-Calendar.xlsx
2017-02-15 19:56 - 2015-05-01 21:47 - 00243545 _____ C:\Users\Carol\Downloads\10-189_H5_Coach_Kit_pages_v2_1_editable.pdf
2017-02-15 19:56 - 2015-03-27 13:57 - 00228977 _____ C:\Users\Carol\Downloads\ReceiptAli.1.pdf
2017-02-15 19:56 - 2015-03-27 13:56 - 00233663 _____ C:\Users\Carol\Downloads\ReceiptAli.pdf
2017-02-15 19:56 - 2015-03-23 08:55 - 00151089 _____ C:\Users\Carol\Downloads\GreattoSkateNigar.1 (1).pdf
2017-02-15 19:56 - 2015-03-23 08:10 - 00151089 _____ C:\Users\Carol\Downloads\GreattoSkateNigar.1.pdf
2017-02-15 19:56 - 2015-03-23 08:09 - 00155806 _____ C:\Users\Carol\Downloads\GreattoSkateNigar (1).pdf
2017-02-15 19:56 - 2015-03-23 08:01 - 00155806 _____ C:\Users\Carol\Downloads\GreattoSkateNigar.pdf
2017-02-15 19:56 - 2015-03-20 20:16 - 25616606 _____ C:\Users\Carol\Downloads\en - CanSkate Manual (1).pdf
2017-02-15 19:56 - 2015-03-20 20:08 - 25616606 _____ C:\Users\Carol\Downloads\en - CanSkate Manual.pdf
2017-02-15 19:56 - 2015-03-13 13:33 - 00167454 _____ C:\Users\Carol\Downloads\GreattoSkateReceiptAyoAug2014 (1).pdf
2017-02-15 19:56 - 2015-03-13 13:32 - 00152171 _____ C:\Users\Carol\Downloads\GreattoSkateReceiptAyoAug2014.pdf
2017-02-15 19:56 - 2015-03-04 12:01 - 00297947 _____ C:\Users\Carol\Downloads\RetailBenefitsDocument.pdf
2017-02-15 19:56 - 2015-03-04 12:01 - 00197516 _____ C:\Users\Carol\Downloads\AssistantShopManager.pdf
2017-02-15 19:56 - 2015-02-25 17:03 - 00259134 _____ C:\Users\Carol\Downloads\combined_document.pdf
2017-02-15 19:56 - 2015-02-25 17:03 - 00079576 _____ C:\Users\Carol\Downloads\CoverletterCarolChuCityofCalgary (3).pdf
2017-02-15 19:56 - 2015-02-25 17:00 - 00180004 _____ C:\Users\Carol\Downloads\CarolChuResume2014-12Communications (8).2-3.pdf
2017-02-15 19:56 - 2015-02-25 15:49 - 00181449 _____ C:\Users\Carol\Downloads\CarolChuResume2014-12Communications (8).pdf
2017-02-15 19:56 - 2015-02-25 15:48 - 00181563 _____ C:\Users\Carol\Downloads\CarolChuResume2014-12Communications (7).pdf
2017-02-15 19:56 - 2015-02-22 13:45 - 00015030 _____ C:\Users\Carol\Downloads\EWB Calgary Chapter Structure 2015 (1).xlsx
2017-02-15 19:56 - 2015-02-18 23:51 - 00200010 _____ C:\Users\Carol\Downloads\merged_document_2 (1).pdf
2017-02-15 19:56 - 2015-02-18 23:50 - 00079368 _____ C:\Users\Carol\Downloads\CoverletterCarolChuCityofCalgary (2).pdf
2017-02-15 19:56 - 2015-02-18 23:49 - 00122072 _____ C:\Users\Carol\Downloads\CarolChuResume2014-12Communications (6).2-4.pdf
2017-02-15 19:56 - 2015-02-18 23:49 - 00121088 _____ C:\Users\Carol\Downloads\CarolChuResume2014-12Communications (6).2-3.pdf
2017-02-15 19:56 - 2015-02-18 19:20 - 00122533 _____ C:\Users\Carol\Downloads\CarolChuResume2014-12Communications (6).pdf
2017-02-15 19:56 - 2015-02-18 19:17 - 00122404 _____ C:\Users\Carol\Downloads\CarolChuResume2014-12Communications (5).pdf
2017-02-15 19:56 - 2015-02-18 18:57 - 00123988 _____ C:\Users\Carol\Downloads\CarolChuResume2014-12Communications (4).pdf
2017-02-15 19:56 - 2015-02-18 18:52 - 00123550 _____ C:\Users\Carol\Downloads\CarolChuResume2014-12Communications (3).pdf
2017-02-15 19:56 - 2015-02-16 16:23 - 17936170 _____ C:\Users\Carol\Downloads\greattoskatepostcard.pdf
2017-02-15 19:56 - 2015-02-11 21:48 - 00079028 _____ C:\Users\Carol\Downloads\CoverletterCarolChuCanadianTireCorporation.pdf
2017-02-15 19:56 - 2015-02-11 20:02 - 00134941 _____ C:\Users\Carol\Downloads\ResumeJS2015.1-2.pdf
2017-02-15 19:56 - 2015-02-11 20:00 - 00122309 _____ C:\Users\Carol\Downloads\ResumeJS2015 (1).pdf
2017-02-15 19:56 - 2015-02-11 19:59 - 00135442 _____ C:\Users\Carol\Downloads\ResumeJS2015.pdf
2017-02-15 19:56 - 2015-02-06 14:00 - 00089939 _____ C:\Users\Carol\Downloads\CoverletterCarolChuCalgaryFoundation.pdf
2017-02-15 19:56 - 2015-02-05 23:34 - 00110973 _____ C:\Users\Carol\Downloads\CarolChuResume2015Communications  (1) (1).pdf
2017-02-15 19:56 - 2015-02-05 23:27 - 00103455 _____ C:\Users\Carol\Downloads\CoverLetterCarolChuCalgaryArts.pdf
2017-02-15 19:56 - 2015-02-05 21:13 - 00210908 _____ C:\Users\Carol\Downloads\merged_document (1).pdf
2017-02-15 19:56 - 2015-02-05 21:12 - 00134387 _____ C:\Users\Carol\Downloads\ResumeCity2015 (1).pdf
2017-02-15 19:56 - 2015-02-05 21:11 - 00134377 _____ C:\Users\Carol\Downloads\ResumeCity2015.pdf
2017-02-15 19:56 - 2015-02-05 21:11 - 00076992 _____ C:\Users\Carol\Downloads\CoverLetterCarolChuCityofCalgary (1).pdf
2017-02-15 19:56 - 2015-02-04 23:24 - 00082294 _____ C:\Users\Carol\Downloads\CoverLetterCarolChuHeritagePark.pdf
2017-02-15 19:56 - 2015-02-04 14:35 - 00040450 _____ C:\Users\Carol\Downloads\References (1).pdf
2017-02-15 19:56 - 2015-02-03 21:58 - 00134524 _____ C:\Users\Carol\Downloads\CopyofCarolChuResume2015HeritagePark (1).pdf
2017-02-15 19:56 - 2015-02-03 21:57 - 00134527 _____ C:\Users\Carol\Downloads\CopyofCarolChuResume2015HeritagePark.pdf
2017-02-15 19:56 - 2015-01-28 09:16 - 00014984 _____ C:\Users\Carol\Downloads\EWB Calgary Chapter Structure 2015.xlsx
2017-02-15 19:56 - 2015-01-27 23:58 - 00200228 _____ C:\Users\Carol\Downloads\merged_document_4.pdf
2017-02-15 19:56 - 2015-01-27 23:58 - 00089808 _____ C:\Users\Carol\Downloads\CoverletterCarolChuServiceLearning.pdf
2017-02-15 19:56 - 2015-01-27 23:55 - 00110866 _____ C:\Users\Carol\Downloads\CarolChuResume2014Volunteer (1).1-2.pdf
2017-02-15 19:56 - 2015-01-27 23:54 - 00073924 _____ C:\Users\Carol\Downloads\CarolChuResume2014Volunteer (1).2-3.pdf
2017-02-15 19:56 - 2015-01-27 19:32 - 00090562 _____ C:\Users\Carol\Downloads\CoverletterCarolChuVolunteerServices.pdf
2017-02-15 19:56 - 2015-01-27 00:00 - 00079581 _____ C:\Users\Carol\Downloads\CoverletterCarolChuCalgaryAirport.pdf
2017-02-15 19:56 - 2015-01-26 13:25 - 00051018 _____ C:\Users\Carol\Downloads\Community Manager Case Study.pdf
2017-02-15 19:56 - 2015-01-23 12:46 - 00105605 _____ C:\Users\Carol\Downloads\skateboardemo.pdf
2017-02-15 19:56 - 2015-01-23 12:43 - 06656994 _____ C:\Users\Carol\Downloads\Skateboard Demosmall.pdf
2017-02-15 19:56 - 2015-01-21 21:47 - 00080531 _____ C:\Users\Carol\Downloads\CoverletterCarolChuGrahamManagementServices.pdf
2017-02-15 19:56 - 2015-01-21 14:56 - 00084177 _____ C:\Users\Carol\Downloads\CoverletterCarolChuWoodsHomes.pdf
2017-02-15 19:56 - 2015-01-20 11:42 - 00080760 _____ C:\Users\Carol\Downloads\CoverletterCarolChuAthabascaUniversity.pdf
2017-02-15 19:56 - 2015-01-17 14:43 - 00110973 _____ C:\Users\Carol\Downloads\CarolChuResume2015Communications  (1)Do not use.pdf
2017-02-15 19:56 - 2015-01-17 14:42 - 00081453 _____ C:\Users\Carol\Downloads\CoverletterCarolChuMoneyMentors.pdf
2017-02-15 19:56 - 2015-01-16 14:44 - 00084255 _____ C:\Users\Carol\Downloads\CoverletterCarolChuAlbertaSocietyofProfessionalBiologists.pdf
2017-02-15 19:56 - 2015-01-14 22:26 - 00083682 _____ C:\Users\Carol\Downloads\CoverletterCarolChuCalgaryGirlsChoir.pdf
2017-02-15 19:56 - 2015-01-13 23:32 - 00111480 _____ C:\Users\Carol\Downloads\CarolChuResume2015Communications BMF.1-2.pdf
2017-02-15 19:56 - 2015-01-13 23:10 - 00084867 _____ C:\Users\Carol\Downloads\CoverletterCarolChuBurnsMemorialFund.pdf
2017-02-15 19:56 - 2015-01-13 23:08 - 00111887 _____ C:\Users\Carol\Downloads\CarolChuResume2015Communications BMF.pdf
2017-02-15 19:56 - 2015-01-13 23:07 - 00111410 _____ C:\Users\Carol\Downloads\CarolChuResume2014-12Communications (2).pdf
2017-02-15 19:56 - 2015-01-13 14:20 - 00114798 _____ C:\Users\Carol\Downloads\CoverletterCarolChuEducationMatters.pdf
2017-02-15 19:56 - 2015-01-13 14:19 - 00110227 _____ C:\Users\Carol\Downloads\CarolChuResume2015Admin (1).pdf
2017-02-15 19:56 - 2015-01-13 14:13 - 00111498 _____ C:\Users\Carol\Downloads\CopyofCarolChuResume2015Admin.pdf
2017-02-15 19:56 - 2015-01-10 23:59 - 00085160 _____ C:\Users\Carol\Downloads\CoverletterCarolChuYMCA.pdf
2017-02-15 19:56 - 2015-01-10 21:53 - 00110973 _____ C:\Users\Carol\Downloads\CarolChuResume2015Communications .pdf
2017-02-15 19:56 - 2014-12-20 22:07 - 00110973 _____ C:\Users\Carol\Downloads\CarolChuResume2014-12Communications (1).pdf
2017-02-15 19:56 - 2014-12-20 22:06 - 00110948 _____ C:\Users\Carol\Downloads\CarolChuResume2014-12Communications.pdf
2017-02-15 19:56 - 2014-12-20 22:01 - 00081790 _____ C:\Users\Carol\Downloads\CoverletterCarolChuUnitedWay.pdf
2017-02-15 19:56 - 2014-12-17 20:32 - 00077646 _____ C:\Users\Carol\Downloads\CoverletterCarolChuHyatt.pdf
2017-02-15 19:56 - 2014-12-15 16:12 - 00187080 _____ C:\Users\Carol\Downloads\merged_document_3.pdf
2017-02-15 19:56 - 2014-12-15 16:10 - 00075526 _____ C:\Users\Carol\Downloads\CoverletterCarolChuCityCommunity.pdf
2017-02-15 19:56 - 2014-12-15 14:40 - 00079098 _____ C:\Users\Carol\Downloads\CoverletterCarolChuShaw.pdf
2017-02-15 19:56 - 2014-12-11 12:39 - 00081742 _____ C:\Users\Carol\Downloads\CoverletterCarolChuFairmontBanffSprings.pdf
2017-02-15 19:56 - 2014-12-09 16:05 - 00084645 _____ C:\Users\Carol\Downloads\CoverletterCarolChuCanadaSportsHallofFame.pdf
2017-02-15 19:56 - 2014-12-09 16:03 - 00112001 _____ C:\Users\Carol\Downloads\CarolChuResume2014-12Sports.1-2.pdf
2017-02-15 19:56 - 2014-12-09 15:52 - 00112944 _____ C:\Users\Carol\Downloads\CarolChuResume2014-12Sports.pdf
2017-02-15 19:56 - 2014-12-09 10:13 - 00079867 _____ C:\Users\Carol\Downloads\Manager of Education and Programming - Job Posting.pdf
2017-02-15 19:56 - 2014-12-08 21:58 - 00082409 _____ C:\Users\Carol\Downloads\CoverletterCarolChuBBBS.pdf
2017-02-15 19:56 - 2014-12-05 21:25 - 00189278 _____ C:\Users\Carol\Downloads\merged_document_2.pdf
2017-02-15 19:56 - 2014-12-05 21:21 - 00079071 _____ C:\Users\Carol\Downloads\CoverletterCarolChuImmigrantServicesCalgary (2).pdf
2017-02-15 19:56 - 2014-12-05 21:21 - 00079071 _____ C:\Users\Carol\Downloads\CoverletterCarolChuCityofCalgary.pdf
2017-02-15 19:56 - 2014-12-04 21:06 - 00111271 _____ C:\Users\Carol\Downloads\CarolChuResume2014liaison.pdf
2017-02-15 19:56 - 2014-12-04 21:06 - 00110866 _____ C:\Users\Carol\Downloads\CarolChuResume2014liaison.1-2.pdf
2017-02-15 19:56 - 2014-12-04 20:56 - 00111271 _____ C:\Users\Carol\Downloads\CarolChuResume2014Volunteer (1).pdf
2017-02-15 19:56 - 2014-12-03 21:47 - 00088192 _____ C:\Users\Carol\Downloads\CoverletterCarolChuImmigrantServicesCalgary (1).pdf
2017-02-15 19:56 - 2014-12-03 21:47 - 00088189 _____ C:\Users\Carol\Downloads\CoverletterCarolChuImmigrantServicesCalgary.pdf
2017-02-15 19:56 - 2014-12-02 15:45 - 00099562 _____ C:\Users\Carol\Downloads\CarolChuResume2014EverActive.1-2.pdf
2017-02-15 19:56 - 2014-12-02 15:41 - 00039606 _____ C:\Users\Carol\Downloads\ReferenceNames.pdf
2017-02-15 19:56 - 2014-12-02 15:40 - 00099914 _____ C:\Users\Carol\Downloads\CarolChuResume2014EverActive.pdf
2017-02-15 19:56 - 2014-12-02 15:39 - 00082924 _____ C:\Users\Carol\Downloads\CoverletterCarolChuEverActiveSchools.pdf
2017-02-15 19:56 - 2014-11-20 15:16 - 00015117 _____ C:\Users\Carol\Downloads\Invoice 1411.pdf
2017-02-15 19:56 - 2014-11-17 11:55 - 00183256 _____ C:\Users\Carol\Downloads\merged_document.pdf
2017-02-15 19:56 - 2014-11-12 20:20 - 00031010 _____ C:\Users\Carol\Downloads\Winter 2015.xlsx
2017-02-15 19:56 - 2014-11-12 08:43 - 00190651 _____ C:\Users\Carol\Downloads\Invoice_Download_25423959_2014_11_07 (2).pdf
2017-02-15 19:56 - 2014-11-12 08:40 - 00190651 _____ C:\Users\Carol\Downloads\Invoice_Download_25423959_2014_11_07 (1).pdf
2017-02-15 19:56 - 2014-11-12 08:35 - 00190748 _____ C:\Users\Carol\Downloads\Invoice_Download_25423959_2014_11_07.pdf
2017-02-15 19:56 - 2014-11-06 10:03 - 00053017 _____ C:\Users\Carol\Downloads\11260918711-367241265-registration (2).pdf
2017-02-15 19:56 - 2014-11-06 09:59 - 00053016 _____ C:\Users\Carol\Downloads\11260918711-367241265-registration (1).pdf
2017-02-15 19:56 - 2014-11-06 09:58 - 00053017 _____ C:\Users\Carol\Downloads\11260918711-367241265-registration.pdf
2017-02-15 19:56 - 2014-11-05 21:37 - 00084411 _____ C:\Users\Carol\Downloads\CoverletterCarolChuYWCA.pdf
2017-02-15 19:56 - 2014-11-02 22:27 - 00084127 _____ C:\Users\Carol\Downloads\CoverletterCarolChuBetweenFriends (1).pdf
2017-02-15 19:56 - 2014-11-02 22:27 - 00084127 _____ C:\Users\Carol\Downloads\CoverletterCarolChuBetweenFriends (1) (1).pdf
2017-02-15 19:56 - 2014-10-30 21:20 - 00013965 _____ C:\Users\Carol\Downloads\Invoice 1410.pdf
2017-02-15 19:56 - 2014-10-30 00:29 - 00030342 _____ C:\Users\Carol\Downloads\DimensionDentistryblurb.pdf
2017-02-15 19:56 - 2014-10-30 00:08 - 00012774 _____ C:\Users\Carol\Downloads\Independent Contractor Agreement-signed.pdf
2017-02-15 19:56 - 2014-10-30 00:06 - 00006791 _____ C:\Users\Carol\Downloads\Independent Contractor Agreement.pdf
2017-02-15 19:56 - 2014-10-23 13:32 - 01224118 _____ C:\Users\Carol\Downloads\Quest Tool 14_24 scanned copy.pdf
2017-02-15 19:56 - 2014-10-14 10:56 - 00768975 _____ C:\Users\Carol\Downloads\USS2014_Poster_FINAL.pdf
2017-02-15 19:56 - 2014-10-07 21:36 - 00088815 _____ C:\Users\Carol\Downloads\CarolChuresumekids (1).pdf
2017-02-15 19:56 - 2014-10-07 14:07 - 00088815 _____ C:\Users\Carol\Downloads\CarolChuresumekids.pdf
2017-02-15 19:56 - 2014-10-06 11:45 - 00013464 _____ C:\Users\Carol\Downloads\Invoice 141 (1).pdf
2017-02-15 19:56 - 2014-10-06 11:43 - 00013464 _____ C:\Users\Carol\Downloads\Invoice 141.pdf
2017-02-15 19:56 - 2014-09-27 19:09 - 00012001 _____ C:\Users\Carol\Downloads\EWB Conference Booth Volunteers List - JessH.xlsx
2017-02-15 19:56 - 2014-09-20 17:18 - 01335168 _____ C:\Users\Carol\Downloads\Jewish Fair Trade Festival Poster.pdf
2017-02-15 19:56 - 2014-09-18 14:38 - 00100420 _____ C:\Users\Carol\Downloads\CarolChuResume2014Communications.1-2.pdf
2017-02-15 19:56 - 2014-09-18 14:38 - 00074056 _____ C:\Users\Carol\Downloads\CarolChuResume2014Communications.2-3.pdf
2017-02-15 19:56 - 2014-09-17 19:39 - 00132393 _____ C:\Users\Carol\Downloads\Carol Chu 2014-signed.pdf
2017-02-15 19:56 - 2014-09-17 19:35 - 00121829 _____ C:\Users\Carol\Downloads\Carol Chu 2014.pdf
2017-02-15 19:56 - 2014-09-09 21:20 - 00080664 _____ C:\Users\Carol\Downloads\CoverletterCarolChuABCRC(1).pdf
2017-02-15 19:56 - 2014-09-09 20:51 - 00079422 _____ C:\Users\Carol\Downloads\CoverletterCarolChuABCRC.pdf
2017-02-15 19:56 - 2014-09-09 19:49 - 00100773 _____ C:\Users\Carol\Downloads\CarolChuResume2014Communications.pdf
2017-02-15 19:56 - 2014-09-09 16:24 - 00040790 _____ C:\Users\Carol\Downloads\References.pdf
2017-02-15 19:56 - 2014-09-09 12:48 - 00097991 _____ C:\Users\Carol\Downloads\CarolChuResume2014Volunteer.pdf
2017-02-15 19:54 - 2014-11-29 20:57 - 00034027 _____ C:\Users\Carol\Documents\Waiver(3).pdf
2017-02-15 19:53 - 2014-11-25 18:12 - 01911917 _____ C:\Users\Carol\Documents\Health Plus- NG combo -132010-signed.pdf
2017-02-15 19:53 - 2014-11-25 18:11 - 01835608 _____ C:\Users\Carol\Documents\Personal Choice Carol-signed.pdf
2017-02-15 17:21 - 2016-07-16 04:47 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed
2017-02-15 17:21 - 2016-07-16 04:47 - 00000000 ____D C:\WINDOWS\system32\Macromed
2017-02-14 13:16 - 2014-09-14 22:33 - 00000000 ____D C:\ProgramData\McAfee Security Scan
2017-02-14 13:08 - 2016-07-16 04:47 - 00000000 ____D C:\WINDOWS\registration
2017-02-14 12:50 - 2014-09-14 19:16 - 00000000 ____D C:\Program Files (x86)\Amazon
2017-02-14 11:54 - 2016-09-29 08:30 - 00000000 ____D C:\Users\Carol
2017-02-14 11:40 - 2014-09-14 19:13 - 858236030 _____ C:\WINDOWS\MEMORY.DMP
2017-02-14 11:14 - 2014-09-14 19:16 - 00000000 ____D C:\Users\Carol\AppData\Local\VirtualStore
2017-02-06 14:24 - 2014-09-14 19:55 - 00002276 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-02-06 14:24 - 2014-09-14 19:55 - 00002264 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-02-06 12:48 - 2016-07-16 04:49 - 00835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2017-02-06 12:48 - 2016-07-16 04:49 - 00177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2017-02-05 11:18 - 2015-11-15 09:51 - 00000000 ____D C:\Program Files\McAfee Security Scan
2017-01-28 21:49 - 2014-11-29 22:07 - 00000000 ____D C:\Users\Carol\Documents\YYC Fitness
 
==================== Files in the root of some directories =======
 
2014-11-04 09:35 - 2014-12-09 09:47 - 0000600 _____ () C:\Users\Carol\AppData\Roaming\winscp.rnd
2015-06-13 21:45 - 2015-10-04 21:07 - 0053248 _____ () C:\Users\Carol\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-11-03 23:06 - 2016-10-03 09:54 - 0000600 _____ () C:\Users\Carol\AppData\Local\PUTTY.RND
2016-03-03 17:08 - 2016-03-03 17:08 - 0000837 _____ () C:\Users\Carol\AppData\Local\recently-used.xbel
2016-09-29 08:26 - 2016-09-29 08:26 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
 
Some files in TEMP:
====================
2016-12-25 12:50 - 2016-12-25 12:50 - 53408320 _____ () C:\Users\Carol\AppData\Local\Temp\D27E.exe
2016-10-27 09:57 - 2016-10-27 09:57 - 0737856 _____ (Oracle Corporation) C:\Users\Carol\AppData\Local\Temp\jre-8u111-windows-au.exe
2017-01-18 18:44 - 2017-01-18 18:44 - 0739904 _____ (Oracle Corporation) C:\Users\Carol\AppData\Local\Temp\jre-8u121-windows-au.exe
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
 
LastRegBack: 2017-02-19 09:52
 
==================== End of FRST.txt ============================
 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 19-02-2017
Ran by Carol (21-02-2017 21:13:19)
Running from C:\Users\Carol\Downloads
Windows 10 Home Version 1607 (X64) (2016-09-29 15:59:37)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-1893927633-78115024-1840190309-500 - Administrator - Disabled) => C:\Users\Administrator
Carol (S-1-5-21-1893927633-78115024-1840190309-1001 - Administrator - Enabled) => C:\Users\Carol
DefaultAccount (S-1-5-21-1893927633-78115024-1840190309-503 - Limited - Disabled)
Guest (S-1-5-21-1893927633-78115024-1840190309-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1893927633-78115024-1840190309-1003 - Limited - Enabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AV: AVG Antivirus (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413}
AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG Antivirus (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
abDocs (HKLM-x32\...\{CA4FE8B0-298C-4E5D-A486-F33B126D6A0A}) (Version: 1.04.3005 - Acer Incorporated)
abDocs Office AddIn (HKLM-x32\...\{DCBF3379-246B-47E1-8173-639B63940838}) (Version: 3.01.2002 - Acer Incorporated)
abMedia (HKLM-x32\...\{E9AF1707-3F3A-49E2-8345-4F2D629D0876}) (Version: 2.05.2011.0 - Acer Incorporated)
abPhoto (HKLM-x32\...\{B5AD89F2-03D3-4206-8487-018298007DD0}) (Version: 3.00.2013.0 - Acer Incorporated)
Acer Explorer Agent (HKLM\...\{4D0F42CF-1693-43D9-BDC8-19141D023EE0}) (Version: 2.00.3000 - Acer Incorporated)
Acer Portal (HKLM-x32\...\{A5AD0B17-F34D-49BE-A157-C8B3D52ACD13}) (Version: 3.03.2002 - Acer Incorporated)
Acer Recovery Management (HKLM\...\{07F2005A-8CAC-4A4B-83A2-DA98A722CA61}) (Version: 6.00.8106 - Acer Incorporated)
Acer Remote Files (HKLM\...\{13885028-098C-4799-9B71-27DAC96502D5}) (Version: 1.02.2003 - Acer Incorporated)
Acer User Experience Improvement Program App Monitor Plugin (HKLM\...\{978724F6-1863-4DD5-9E66-FB77F5AB5613}) (Version: 1.01.3003 - Acer Incorporated)
Acer User Experience Improvement Program Framework (HKLM\...\{12A718F2-2357-4D41-9E1F-18583A4745F7}) (Version: 1.01.3003 - Acer Incorporated)
Acer Video Player (HKLM-x32\...\{B6846F20-4821-11E3-8F96-0800200C9A66}) (Version: 1.00.2001.4 - Acer Incorporated)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 14.0.0.178 - Adobe Systems Incorporated)
Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 2.9.0.465 - Adobe Systems Incorporated)
Adobe Dreamweaver CC 2014 (HKLM-x32\...\{7F823F8E-4348-11E4-8BF8-81763C49AA32}) (Version: 15.0.0 - Adobe Systems Incorporated)
Adobe Flash Player 24 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 24.0.0.221 - Adobe Systems Incorporated)
Adobe InDesign CC 2014 (HKLM-x32\...\{CCDCB9C4-72BA-1014-A3F8-D123F2F18BC2}) (Version: 10.1.0.070 - Adobe Systems Incorporated)
Adobe Photoshop CC 2014 (HKLM-x32\...\{D7A4F897-B20A-42D0-862D-CB5F6DB7391D}) (Version: 15.2.2 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.04)  MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AB0000000001}) (Version: 11.0.04 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.19) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.19 - Adobe Systems Incorporated)
Adobe® Content Viewer (HKLM-x32\...\com.adobe.dmp.contentviewer) (Version: 3.4.3 - Adobe Systems, Incorporated)
Aloha TriPeaks (x32 Version: 2.2.0.98 - WildTangent) Hidden
Amazon 1Button App (HKLM-x32\...\{0A7D6F3C-F2AB-48ED-BE23-99791BFF87D6}) (Version: 1.0.0.4 - Amazon) <==== ATTENTION
AOP Framework (HKLM-x32\...\{4A37A114-702F-4055-A4B6-16571D4A5353}) (Version: 3.03.2001.0 - Acer Incorporated)
Apple Application Support (32-bit) (HKLM-x32\...\{7FE25256-B7C1-480D-B736-10A67A833AEA}) (Version: 3.2 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\...\{B255D495-4734-4E9B-B4F5-96702FD4A7B9}) (Version: 3.2 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{5D61F006-168C-4B8B-B7FD-F113C10AE0E4}) (Version: 8.2.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
AVG (HKLM\...\AvgZen) (Version: 1.151.2.59606 - AVG Technologies)
AVG Protection (HKLM-x32\...\AVG Antivirus) (Version: 17.1.3006 - AVG Technologies)
AVG Zen (Version: 1.151.26 - AVG Technologies) Hidden
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Citrix Online Launcher (HKLM-x32\...\{8A16C63D-027A-4645-B394-C033665D0195}) (Version: 1.0.325 - Citrix)
Cradle Of Egypt Collector's Edition (x32 Version: 2.2.0.110 - WildTangent) Hidden
CyberLink PowerDVD 12 (HKLM-x32\...\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}) (Version: 12.0.4314.55 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
eBay Worldwide (HKLM-x32\...\{91589413-6675-4C27-8AFC-EFB9103B90A5}) (Version: 2.4.0105 - OEM)
FileZilla Client 3.21.0 (HKLM-x32\...\FileZilla Client) (Version: 3.21.0 - Tim Kosse)
FMW 1 (Version: 1.163.1 - AVG Technologies) Hidden
Game Channels (HKLM-x32\...\WildTangentGameProvider-acer-genres) (Version: 9.2.0.11 - WildTangent, Inc.)
GimpShop 2.8 (HKLM-x32\...\{3F1C9552-58E0-4AAC-A616-AE3A28720EC6}) (Version: 2.8 - GimpShop)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 56.0.2924.87 - Google Inc.)
Google Photos Backup (HKU\S-1-5-21-1893927633-78115024-1840190309-1001\...\Google Photos Backup) (Version: 1.1.2.13 - Google, Inc.)
Google Talk Plugin (HKLM-x32\...\{F9B579C2-D854-300A-BE62-A09EB9D722E4}) (Version: 5.41.3.0 - Google)
Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.8231.2252 - Google Inc.)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.32.7 - Google Inc.) Hidden
GoToMeeting 8.0.0.6441 (HKU\S-1-5-21-1893927633-78115024-1840190309-1001\...\GoToMeeting) (Version: 8.0.0.6441 - CitrixOnline)
Governor of Poker 2 Premium Edition (x32 Version: 2.2.0.110 - WildTangent) Hidden
Gramblr (HKU\S-1-5-21-1893927633-78115024-1840190309-1001\...\Gramblr) (Version: 1.0.0 - Gramblr)
Handy Recovery 5.5 (HKLM-x32\...\{4196D960-68B0-4BEB-B312-3C1B4654068D}) (Version: 5.5 - SoftLogica)
HitmanPro 3.7 (HKLM\...\HitmanPro37) (Version: 3.7.15.281 - SurfRight B.V.)
Hotkey Utility (HKLM-x32\...\{A6DC88AD-501A-44BC-884D-57435F972E2C}) (Version: 3.00.8102 - Acer Incorporated)
Identity Card (HKLM-x32\...\{3D9CB654-99AD-4301-89C6-0D12A790767C}) (Version: 2.00.8101 - Acer Incorporated)
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.13.1706 - Intel Corporation)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 20.19.15.4531 - Intel Corporation)
iTunes (HKLM\...\{93F2A022-6C37-48B8-B241-FFABD9F60C30}) (Version: 12.1.2.27 - Apple Inc.)
Java 8 Update 91 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218091F0}) (Version: 8.0.910.60 - Oracle Corporation)
Junk Mail filter update (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Live Updater (HKLM-x32\...\{EE26E302-876A-48D9-9058-3129E5B99999}) (Version: 2.00.8100 - Acer Incorporated)
Luxor Evolved (x32 Version: 2.2.0.98 - WildTangent) Hidden
Magic Academy (x32 Version: 2.2.0.98 - WildTangent) Hidden
Malwarebytes version 3.0.6.1469 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.0.6.1469 - Malwarebytes)
McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.11.500.3 - McAfee, Inc.)
Microsoft Office Professional Plus 2016 - en-us (HKLM\...\ProPlusRetail - en-us) (Version: 16.0.7571.2109 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1893927633-78115024-1840190309-1001\...\OneDriveSetup.exe) (Version: 17.3.6743.1212 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50901.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Mozilla Firefox 47.0.1 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 47.0.1 (x86 en-US)) (Version: 47.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 47.0.1.6018 - Mozilla)
Nero BackItUp 12 Essentials OEM.a01 (HKLM-x32\...\{551AC8F2-FEA2-4B45-ACF7-C98681233CC9}) (Version: 12.5.01200 - Nero AG)
Office 16 Click-to-Run Extensibility Component (x32 Version: 16.0.7571.2109 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (Version: 16.0.7571.2109 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (Version: 16.0.7571.2109 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (x32 Version: 16.0.7571.2109 - Microsoft Corporation) Hidden
PandoraRecovery (Remove Only) (HKLM-x32\...\PandoraRecovery) (Version:  - )
Peggle Nights (x32 Version: 2.2.0.98 - WildTangent) Hidden
PHP 5.4.9 with xDebug 2.2.1 (VC9 Non Thread Safe) (HKLM-x32\...\PHP with xDebug_is1) (Version: 5.4.9 - Blumentals Software)
Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9.141.259 - Google, Inc.)
Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.98 - WildTangent) Hidden
Plotagon (HKLM-x32\...\Plotagon 0.17.0) (Version: 0.17.0 - Plotagon)
Plotagon (x32 Version: 0.17.0 - Plotagon) Hidden
Poedit (HKLM-x32\...\{68EB2C37-083A-4303-B5D8-41FA67E50B8F}_is1) (Version: 1.8.8 - Vaclav Slavik)
Pokki Start Menu (HKU\S-1-5-21-1893927633-78115024-1840190309-1001\...\Pokki_Start_Menu) (Version: 0.269.4.112 - Pokki)
Prerequisite installer (x32 Version: 12.0.0003 - Nero AG) Hidden
Qualcomm Atheros Bluetooth Suite (64) (HKLM\...\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.1.314 - Qualcomm Atheros Communications)
Qualcomm Atheros WLAN and Bluetooth Client Installation Program (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 12.25 - Qualcomm Atheros)
Rapid PHP 2014 v12.3 (HKLM-x32\...\Rapid PHP 2014_is1) (Version: 12.0 - Karlis Blumentals)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.3.3.34 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.18.621.2013 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7535 - Realtek Semiconductor Corp.)
Recuva (HKLM\...\Recuva) (Version: 1.52 - Piriform)
Seagate Dashboard (HKLM-x32\...\{EA266F00-A8E7-43A0-8DED-FBFE3F076934}) (Version: 4.4.19.0 - Seagate)
ShadowExplorer 0.9 (HKLM-x32\...\ShadowExplorer_is1) (Version: 0.9.462.0 - ShadowExplorer.com)
Skype Click to Call (HKLM-x32\...\{873F8E7C-10E6-449F-BD7E-5FBA7C8E1C9B}) (Version: 8.5.0.9167 - Microsoft Corporation)
Skype™ 7.26 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.26.101 - Skype Technologies S.A.)
Sparkol VideoScribe (HKLM-x32\...\Sparkol VideoScribe 2.3.2002) (Version: 2.3.2002 - Sparkol)
Sparkol VideoScribe (x32 Version: 2.3.2002 - Sparkol) Hidden
Spotify (HKLM-x32\...\Spotify) (Version: 0.9.6.81.gd359a796 - Spotify AB)
StudioTax 2013 (HKLM-x32\...\{28B28C36-EB35-44CB-9396-C994E927ABA7}) (Version: 9.1.11.1 - BHOK IT Consulting)
StudioTax 2014 (HKLM-x32\...\{9D16247E-27DC-4958-8EDB-599CC041CCB6}) (Version: 10.0.8.0 - BHOK IT Consulting)
StudioTax 2015 (HKLM-x32\...\{10DC0B0F-E7D6-4F37-9CF9-0A76A689AAB0}) (Version: 11.0.8.7 - BHOK IT Consulting)
The Chronicles of Emerland Solitaire (x32 Version: 3.0.2.32 - WildTangent) Hidden
Trinklit Supreme (x32 Version: 2.2.0.98 - WildTangent) Hidden
Update Installer for WildTangent Games App (x32 Version:  - WildTangent) Hidden
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
WildTangent Games (HKLM-x32\...\WildTangent wildgames Master Uninstall) (Version: 1.0.4.0 - WildTangent)
WildTangent Games App (x32 Version: 4.0.10.20 - WildTangent) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
WinSCP 5.5.6 (HKLM-x32\...\winscp3_is1) (Version: 5.5.6 - Martin Prikryl)
Zemana AntiMalware (HKLM-x32\...\{8F0CD7D1-42F3-4195-95CD-833578D45057}_is1) (Version: 2.72.101 - Zemana Ltd.)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-1893927633-78115024-1840190309-1001_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\Carol\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1893927633-78115024-1840190309-1001_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\Carol\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1893927633-78115024-1840190309-1001_Classes\CLSID\{590C4387-5EBD-4D46-8A84-CD0BA2EF2856}\InprocServer32 -> C:\Users\Carol\AppData\Local\Google\Update\1.3.30.3\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1893927633-78115024-1840190309-1001_Classes\CLSID\{59B55F04-DE14-4BB8-92FF-C4A22EF2E5F4}\InprocServer32 -> C:\Users\Carol\AppData\Local\Google\Update\1.3.31.5\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1893927633-78115024-1840190309-1001_Classes\CLSID\{5C8C2A98-6133-4EBA-BBCC-34D9EA01FC2E}\InprocServer32 -> C:\Users\Carol\AppData\Local\Google\Update\1.3.28.1\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1893927633-78115024-1840190309-1001_Classes\CLSID\{78550997-5DEF-4A8A-BAF9-D5774E87AC98}\InprocServer32 -> C:\Users\Carol\AppData\Local\Google\Update\1.3.28.13\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1893927633-78115024-1840190309-1001_Classes\CLSID\{793EE463-1304-471C-ADF1-68C2FFB01247}\InprocServer32 -> C:\Users\Carol\AppData\Local\Google\Update\1.3.29.5\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1893927633-78115024-1840190309-1001_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309}\InprocServer32 -> C:\Users\Carol\AppData\Local\Citrix\GoToMeeting\2759\G2MOutlookAddin64.dll (Citrix Online, a division of Citrix Systems, Inc.)
CustomCLSID: HKU\S-1-5-21-1893927633-78115024-1840190309-1001_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\Carol\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1893927633-78115024-1840190309-1001_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\Carol\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1893927633-78115024-1840190309-1001_Classes\CLSID\{CB492AF1-2CEF-4E58-BE47-471C77D0C8BA}\InprocServer32 -> C:\Users\Carol\AppData\Local\Google\Update\1.3.32.7\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1893927633-78115024-1840190309-1001_Classes\CLSID\{CC182BE1-84CE-4A57-B85C-FD4BBDF78CB2}\InprocServer32 -> C:\Users\Carol\AppData\Local\Google\Update\1.3.29.1\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1893927633-78115024-1840190309-1001_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\Carol\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1893927633-78115024-1840190309-1001_Classes\CLSID\{D1EDC4F5-7F4D-4B12-906A-614ECF66DDAF}\InprocServer32 -> C:\Users\Carol\AppData\Local\Google\Update\1.3.28.15\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1893927633-78115024-1840190309-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Carol\AppData\Local\Google\Update\1.3.32.7\psuser_64.dll (Google Inc.)
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {04BE28D7-C6F3-49FA-8656-8C36465E5099} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1893927633-78115024-1840190309-1001UA1d257dc39d46a67 => C:\Users\Carol\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {130B2627-F980-4D1F-BDFD-EC43C6F520C1} - System32\Tasks\ALU => C:\Program Files (x86)\Acer\Live Updater\updater.exe [2013-07-08] ()
Task: {14B69308-5A09-4005-AE0F-ECC44F3EF9F1} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {1557F2C7-AD70-4A4F-A2CD-74898D9CA5E0} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {18EDBAD7-3BDE-4B95-8BAB-760D1D5510C7} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2017-01-13] (Microsoft Corporation)
Task: {19B9F8A3-E65A-4F32-ACC0-0A09133EA939} - System32\Tasks\ALUAgent => C:\Program Files (x86)\Acer\Live Updater\liveupdater_agent.exe [2013-01-22] ()
Task: {1D3E4B54-3A06-405F-BCEA-A45FD0D1B646} - System32\Tasks\UbtFrameworkService => C:\Program Files\Acer\User Experience Improvement Program\Framework\TriggerFramework.exe [2014-01-24] (TODO: <Company name>)
Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => %SystemRoot%\System32\AutoWorkplace.exe 
Task: {3C6092BE-5C01-4A78-AD54-8D8CAB32756A} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {4F2507FE-D958-4879-9972-81AE86E17441} - System32\Tasks\OneDrive Standalone Update Task => C:\Users\Carol\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\OneDriveStandaloneUpdater.exe 
Task: {5103E6B0-5CF5-40BB-9647-4B9433A16897} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2016-12-28] (Microsoft Corporation)
Task: {53AC6BF0-743A-40D8-BB66-63AB429C8B77} - System32\Tasks\Seagate_Install_Launch => C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Dashboard.exe [2016-06-28] (Seagate Technology LLC)
Task: {54EBE034-5BBE-4C7E-9413-3ABD86DB5664} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2016-12-28] (Microsoft Corporation)
Task: {57E46A23-C453-44D4-A3B8-2420FC61DFD6} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {5A93F71E-FF18-4067-A070-4C42B2697A4F} - \WPD\SqmUpload_S-1-5-21-1893927633-78115024-1840190309-1001 -> No File <==== ATTENTION
Task: {6A3A5BBF-731E-46D2-840A-686F36E2B2D1} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {6C7BA903-5FDD-4FC8-99DC-8BBFC87E9116} - System32\Tasks\Recovery Management\Notification => C:\Program Files\Acer\Acer Recovery Management\Notification\Notification.exe [2014-03-18] (Acer Incorporated)
Task: {868214AD-F3DC-4854-BD53-A616A48062D2} - System32\Tasks\Antivirus Emergency Update => C:\Program Files (x86)\AVG\Antivirus\AvEmUpdate.exe [2017-02-16] (AVG Technologies CZ, s.r.o.)
Task: {8CC1CB44-9671-41F4-818C-796DA9AD03AD} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {996D8E13-9D34-44A0-81E1-C8E1D0BE1EE7} - System32\Tasks\McAfee Remediation (Prepare) => C:\Program Files\Common Files\AV\McAfee Anti-Virus And Anti-Spyware\upgrade.exe [2015-06-01] (McAfee, Inc.)
Task: {9A729153-D9CA-4A51-9C06-B226A1179718} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2016-12-28] (Microsoft Corporation)
Task: {A4190D24-CF9E-4BBF-A8A5-6EF58267B9CF} - System32\Tasks\Carol DBAgent 2 0 => C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\DBAgent.exe [2016-06-28] (Seagate Technology LLC)
Task: {A4F469ED-3487-4AA5-947D-44CF605118B7} - System32\Tasks\G2MUpdateTask-S-1-5-21-1893927633-78115024-1840190309-1001 => C:\Users\Carol\AppData\Local\Citrix\GoToMeeting\5573\g2mupdate.exe [2016-09-19] (Citrix Online, a division of Citrix Systems, Inc.)
Task: {A60DC74A-1D02-45FA-8CBF-1310B554B5C0} - System32\Tasks\Hotkey Utility => C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe [2013-12-30] (Acer Incorporated)
Task: {A8C1ABF2-6A3C-48D2-BF8A-4D3936EF0FF4} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1893927633-78115024-1840190309-1001Core => C:\Users\Carol\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {AD41D871-F097-4ECC-A96E-91D0C204DB1E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {B113DDDB-5C9D-478B-9FAA-457B38A80123} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1893927633-78115024-1840190309-1001Core1d257dc39be04bd => C:\Users\Carol\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {B3289E25-E016-4327-B7B8-290364E3CAE1} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {B8E017CB-067D-4C0B-9A20-16F5C276427D} - System32\Tasks\AdobeAAMUpdater-1.0-Chu-Carol => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2014-10-14] (Adobe Systems Incorporated)
Task: {B9834D8D-1024-4F0B-ADDB-DB6DEF5E5B15} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1893927633-78115024-1840190309-1001UA1cfd74f253531e6 => C:\Users\Carol\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {BB67235E-77A1-4EC4-87DE-65583878C207} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {BCE6F242-9F2C-4A9A-B998-D5381F15997F} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-02-15] (Adobe Systems Incorporated)
Task: {C8E1E7FC-058C-4288-82E1-236C40B0BA2E} - \OfficeSoftwareProtectionPlatform\SvcRestartTask -> No File <==== ATTENTION
Task: {CA4DCF95-2E4E-4F29-A539-8DAA8CA65407} - System32\Tasks\AdobeAAMUpdater-1.0-MicrosoftAccount-figureskaterlorac@hotmail.com => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2014-10-14] (Adobe Systems Incorporated)
Task: {D14A75FB-316B-4015-9F19-5332EABFC114} - System32\Tasks\G2MUploadTask-S-1-5-21-1893927633-78115024-1840190309-1001 => C:\Users\Carol\AppData\Local\Citrix\GoToMeeting\5573\g2mupload.exe [2016-09-19] (Citrix Online, a division of Citrix Systems, Inc.)
Task: {D296B47F-1C25-40FF-8D23-975AAA826656} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {E0C98AD0-805F-4165-B2C8-0FF891ACA94F} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2016-12-28] (Microsoft Corporation)
Task: {E8EE9484-F52E-44F6-8358-7A1CE498C090} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-12-19] (Adobe Systems Incorporated)
Task: {EB3F91D1-A172-4D94-B49A-9CA76A48DA0C} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {EB711DAD-1090-4285-BA2A-3643956FC4FD} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {FA5828AB-F2D1-4B61-9773-10357C662FA3} - System32\Tasks\AVG EUpdate Task => avgsetupx.exe 
Task: {FC0ED3B0-8878-400E-8905-647E8C403989} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
Task: C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-1893927633-78115024-1840190309-1001.job => C:\Users\Carol\AppData\Local\Citrix\GoToMeeting\6441\g2mupdate.exe
Task: C:\WINDOWS\Tasks\G2MUploadTask-S-1-5-21-1893927633-78115024-1840190309-1001.job => C:\Users\Carol\AppData\Local\Citrix\GoToMeeting\6441\g2mupload.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1893927633-78115024-1840190309-1001Core.job => C:\Users\Carol\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1893927633-78115024-1840190309-1001UA1cfd74f253531e6.job => C:\Users\Carol\AppData\Local\Google\Update\GoogleUpdate.exe
 
==================== Shortcuts =============================
 
(The entries could be listed to be restored or removed.)
 
==================== Loaded Modules (Whitelisted) ==============
 
2015-03-20 17:12 - 2015-03-20 17:12 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2015-05-15 15:26 - 2015-05-15 15:26 - 01346344 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2017-02-16 10:02 - 2017-01-20 07:47 - 02264352 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\PoliciesControllerImpl.dll
2017-02-16 10:02 - 2017-01-20 07:47 - 02829776 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\arwlib.dll
2017-02-16 10:02 - 2017-01-20 07:47 - 02254800 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll
2016-07-16 04:42 - 2016-07-16 04:42 - 00231424 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2016-12-13 23:09 - 2016-12-09 03:29 - 02681200 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2016-12-13 23:09 - 2016-12-09 03:29 - 02681200 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2016-12-13 23:09 - 2016-12-09 03:29 - 02681200 _____ () C:\WINDOWS\SYSTEM32\CoreUIComponents.dll
2014-12-19 15:57 - 2014-12-19 15:57 - 01039008 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll
2016-06-24 14:33 - 2016-12-28 10:03 - 08924864 _____ () C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\1033\GrooveIntlResource.dll
2017-02-15 21:35 - 2017-02-15 21:35 - 00154480 _____ () C:\Program Files (x86)\Zemana AntiMalware\ZAMShellExt64.dll
2016-09-29 10:18 - 2016-09-29 10:18 - 00134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll
2017-01-10 20:25 - 2016-12-21 00:09 - 00474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll
2017-01-10 20:25 - 2016-12-21 00:08 - 00693248 _____ () C:\Windows\ShellExperiences\MtcUvc.dll
2016-05-27 14:50 - 2016-11-01 22:05 - 00401896 _____ () C:\WINDOWS\system32\igfxTray.exe
2014-05-16 16:22 - 2014-01-03 14:13 - 00111872 _____ () C:\Program Files (x86)\Acer\clear.fi plug-in\Clearfishellext_x64.dll
2016-08-23 06:05 - 2016-08-23 06:05 - 00052400 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll
2017-02-17 19:41 - 2017-02-17 19:41 - 00073728 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.109.0_x64__kzf8qxf38zg5c\SkypeHost.exe
2017-02-17 19:41 - 2017-02-17 19:41 - 00179712 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.109.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll
2017-02-17 19:41 - 2017-02-17 19:41 - 42895360 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.109.0_x64__kzf8qxf38zg5c\SkyWrap.dll
2017-02-06 18:08 - 2017-02-06 18:08 - 02215424 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.109.0_x64__kzf8qxf38zg5c\roottools.dll
2016-11-22 23:29 - 2016-11-22 23:29 - 00019456 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.1118.10000.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
2016-11-22 23:29 - 2016-11-22 23:29 - 20433408 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.1118.10000.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll
2016-06-02 16:50 - 2016-06-02 16:50 - 00680448 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.1118.10000.0_x64__8wekyb3d8bbwe\Microsoft.DesignCore.dll
2016-11-22 23:29 - 2016-11-22 23:29 - 01046528 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.1118.10000.0_x64__8wekyb3d8bbwe\Microsoft.Sharing.dll
2016-11-22 23:29 - 2016-11-22 23:29 - 00353792 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.1118.10000.0_x64__8wekyb3d8bbwe\Photos.Inking.dll
2013-07-08 15:34 - 2013-07-08 15:34 - 04150312 _____ () C:\Program Files (x86)\Acer\Live Updater\updater.exe
2016-11-21 21:59 - 2016-11-21 21:59 - 01369288 _____ () C:\Program Files\WindowsApps\Microsoft.Office.OneNote_17.7870.57621.0_x64__8wekyb3d8bbwe\Microsoft.Applications.Telemetry.Windows.dll
2017-02-21 20:02 - 2017-02-21 20:02 - 13326536 _____ () C:\Program Files\WindowsApps\Microsoft.Office.OneNote_17.7870.57621.0_x64__8wekyb3d8bbwe\Office.UI.Xaml.Core.dll
2017-01-10 20:25 - 2016-12-20 23:54 - 09760768 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2017-01-10 20:25 - 2016-12-20 23:48 - 01401856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2017-01-10 20:25 - 2016-12-20 23:48 - 00757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll
2017-01-10 20:25 - 2016-12-20 23:48 - 01033216 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll
2017-01-10 20:25 - 2016-12-20 23:48 - 02424320 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2017-01-10 20:25 - 2016-12-20 23:53 - 04853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2014-05-16 16:08 - 2013-08-19 11:12 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\ACE.dll
2016-09-29 08:32 - 2016-09-29 08:32 - 00015616 _____ () C:\WINDOWS\assembly\GAC_MSIL\MyService\1.0.0.1__2dfa3f50f0bed57d\MyService.dll
2014-11-17 10:57 - 2014-11-17 10:57 - 00013568 _____ () C:\Program Files (x86)\Acer\AOP Framework\ServiceInterface.dll
2014-08-20 16:45 - 2014-08-20 16:45 - 00279296 _____ () C:\Program Files (x86)\Acer\AcerCloud Docs\libcurl.dll
2014-09-16 09:15 - 2014-09-16 09:15 - 00203008 _____ () C:\Program Files (x86)\Acer\abPhoto\curllib.dll
2014-09-16 09:16 - 2014-09-16 09:16 - 00630528 _____ () C:\Program Files (x86)\Acer\abPhoto\tag.dll
2014-09-16 09:16 - 2014-09-16 09:16 - 00654552 _____ () C:\Program Files (x86)\Acer\abPhoto\sqlite3.dll
2014-09-16 09:16 - 2014-09-16 09:16 - 00119552 _____ () C:\Program Files (x86)\Acer\abPhoto\OpenLDAP.dll
2017-02-16 00:17 - 2017-02-16 00:17 - 00171208 _____ () C:\Program Files (x86)\AVG\Antivirus\JsonRpcServer.dll
2017-02-16 00:17 - 2017-02-16 00:17 - 48936448 _____ () C:\Program Files (x86)\AVG\Antivirus\libcef.dll
2017-02-16 00:17 - 2017-02-16 00:17 - 00656040 _____ () C:\Program Files (x86)\AVG\Antivirus\ffl2.dll
2014-05-16 16:22 - 2014-01-03 14:13 - 00090368 _____ () C:\Program Files (x86)\Acer\clear.fi plug-in\Clearfishellext.dll
2016-08-23 06:05 - 2016-08-23 06:05 - 00048304 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext.dll
2017-02-16 00:14 - 2017-02-16 00:14 - 48920064 _____ () C:\Program Files (x86)\AVG\UiDll\2623\libcef.dll
2016-06-24 14:34 - 2016-12-28 04:41 - 08924872 _____ () C:\Program Files (x86)\Microsoft Office\root\Office16\1033\GrooveIntlResource.dll
2017-02-06 14:24 - 2017-02-01 02:01 - 01870168 _____ () C:\Program Files (x86)\Google\Chrome\Application\56.0.2924.87\libglesv2.dll
2017-02-06 14:24 - 2017-02-01 02:01 - 00085848 _____ () C:\Program Files (x86)\Google\Chrome\Application\56.0.2924.87\libegl.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2013-08-22 06:25 - 2017-02-15 21:55 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-1893927633-78115024-1840190309-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\acer01.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
HKLM\...\StartupApproved\Run32: => "Adobe Creative Cloud"
HKU\S-1-5-21-1893927633-78115024-1840190309-1001\...\StartupApproved\Run: => "msnmsgr"
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{3856F056-5C5A-451D-ADD2-7A8109FC78C8}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe
FirewallRules: [{5F1F2DF8-6171-4266-9C1A-F5D619208393}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{B16C3506-ED98-4386-BFB4-0CE1BC02C0D1}] => (Allow) C:\Program Files (x86)\Ubisoft\Your Shape\YourShape.exe
FirewallRules: [{89A32F29-0B3C-4D68-A1E4-2436824D5E37}] => (Allow) C:\Program Files (x86)\Ubisoft\Your Shape\YourShape.exe
FirewallRules: [{7498F481-1022-4FB3-83FB-FF45BE449F0E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{A894E0A4-B724-4D13-9E9A-C327C559B3B9}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{FB659721-6517-4AF2-BCE8-512C87624F0C}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{BA15BE71-3F07-48E6-AE70-6DE7A09BF795}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{5DA70CD8-6C1F-4CB7-960B-4E5C134F7849}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{4F0768D1-0C60-4723-832E-7234632A3B0D}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{9694F65F-B4EE-4C53-B01C-BE6E4739509B}] => (Allow) C:\Program Files (x86)\FileZilla FTP Client\filezilla.exe
FirewallRules: [{1A255C1A-A125-44AC-AFC5-B309867FA168}] => (Allow) C:\Program Files (x86)\FileZilla FTP Client\filezilla.exe
FirewallRules: [{58C482BE-1665-46FB-868E-CFD139132106}] => (Allow) C:\Program Files (x86)\FileZilla FTP Client\filezilla.exe
FirewallRules: [{552BD309-C0A3-4803-80EC-EC5E800318E3}] => (Allow) C:\Program Files (x86)\FileZilla FTP Client\filezilla.exe
FirewallRules: [{9C8C4371-BE63-429F-A45A-D498465F3B77}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{2160C316-118A-4DBC-8C19-E9772AA207F9}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{7D60FA56-B30D-4712-B68B-6A0B0E61B837}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{D0B1E5F3-B08C-4E83-9DCF-C0026E8764B7}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{50B1862C-10FA-49E8-ACD5-1BBC12A36998}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{27504280-9DF3-4C13-ADF7-0928C5E18CB3}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{6071C3B8-C75F-4B7F-9043-2FECF0F10C2E}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{D37D81FE-0DA0-476C-B818-DA1EBE1E2F27}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{64077B2A-CDA1-497D-AC44-BA8F552F8560}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\WindowsUpnpMV.exe
FirewallRules: [{3D503388-BBAB-46D9-AEE1-7C451540F614}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\WindowsUpnpMV.exe
FirewallRules: [{559C6551-FE41-47C2-9401-C26C58863629}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\DMCDaemon.exe
FirewallRules: [{3496B3D1-5880-4052-8BF9-BE4490F3A6F5}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\DMCDaemon.exe
FirewallRules: [{C35CC333-BA00-49F5-B319-3FBDD8876E33}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\WindowsUpnpMV.exe
FirewallRules: [{D1320B14-218B-447A-8974-97091BCB0BC1}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\WindowsUpnpMV.exe
FirewallRules: [{C163D89B-6675-4D9D-A03E-6077EDC3B19E}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\DMCDaemon.exe
FirewallRules: [{738F5519-08AC-4A05-A3DF-BBA54A0C37FD}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\DMCDaemon.exe
FirewallRules: [{0F737E32-9A67-473D-8028-C5C2C721CAA1}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{EA512CE7-26CB-492A-A560-DFB08C368A09}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{31542131-9423-45CB-8B3F-91E16B58F3F2}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{EBB7D7E1-E8AE-4D39-80FB-C13280A2144C}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{5F28CF02-071D-44F8-B665-10271F9A7D9C}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{89047C60-33AC-47A3-BC90-7C868F53AAE4}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{D406895C-E3B9-4BAD-A3C2-30B3652E69A3}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{CC856095-0B72-4F90-951F-34CF299F9AE2}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{BF44B1DF-381E-45E3-9117-3897B3FBB7F4}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\WindowsUpnpMV.exe
FirewallRules: [{995122A1-041B-4E16-906E-445B09DCA42D}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\WindowsUpnpMV.exe
FirewallRules: [{A5193DF2-BDCB-414E-AECC-52A143BB67D4}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\DMCDaemon.exe
FirewallRules: [{FE9DE26C-ADFC-46B9-B249-30ABA9B359C4}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\DMCDaemon.exe
FirewallRules: [{C86C9D3B-E2BC-487C-BF00-8E77C8F3CDB7}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\WindowsUpnpMV.exe
FirewallRules: [{248CDBA4-B724-4C9A-B8C7-AD6771AE5107}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\WindowsUpnpMV.exe
FirewallRules: [{EEFFDE89-CED0-47F8-948B-9919DC91D509}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\DMCDaemon.exe
FirewallRules: [{E5E63805-A641-4AA1-B7FF-0DA5E6E21359}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\DMCDaemon.exe
FirewallRules: [UDP Query User{D502F8CC-B274-46BC-9A7A-14AD074F5106}C:\users\carol\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\carol\appdata\roaming\spotify\spotify.exe
FirewallRules: [TCP Query User{1159713E-4780-45A3-A818-DD160957EA92}C:\users\carol\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\carol\appdata\roaming\spotify\spotify.exe
FirewallRules: [{ED3E1574-9FC4-43E7-AE7C-32A3C4B4CC54}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{7F191F42-3C91-4157-A0E9-E2A20F3F54A6}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{D612D267-D52E-4BD1-9943-F1F0860FC0A9}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{04A3AB86-8698-4599-AB56-99FBDFAA592B}] => (Allow) LPort=1900
FirewallRules: [{B8B321DF-7981-40DD-866B-EE192C3025B7}] => (Allow) LPort=2869
FirewallRules: [{C773A19B-9979-4450-9C16-52ACB96E60D9}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{11EBED88-CB4D-4A2B-97E7-36F28A4AE2CE}] => (Allow) C:\Users\Carol\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
FirewallRules: [{00B979B6-FED5-48F9-9BDF-A60A2A6E50CE}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{A347C966-EE53-4404-A8A8-DFE23194A7EC}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{02D34392-D75D-4480-B57D-2C261A3999F4}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{D320A32D-EEE9-49E2-960E-2A7CB68C3E27}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{0E88E061-93D8-4155-8FCF-0BF2B2EEBBB7}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{F46982E8-98AC-4CEA-9111-A26617BAB6A1}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{E9E287CE-5106-4F6A-BF66-865C122DCA76}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{9C50550D-070D-416D-95F4-CF4FC6A76663}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{C19C6DF7-2228-4C06-9A1A-636721D0E3A8}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\WindowsUpnpMV.exe
FirewallRules: [{EC5C4750-32D1-46DD-82EE-30997B1505CA}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\WindowsUpnpMV.exe
FirewallRules: [{B4519C9F-54BD-4E41-A922-616120A57656}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\DMCDaemon.exe
FirewallRules: [{7F7EA96C-4F4A-4E6B-82E1-F6492A8777D2}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\DMCDaemon.exe
FirewallRules: [{488A1A52-5582-441B-82BF-7D6C509120B6}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\WindowsUpnpMV.exe
FirewallRules: [{38B4F46E-ED5C-4C87-9192-73EC71393F5C}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\WindowsUpnpMV.exe
FirewallRules: [{928FE5FB-DB3B-4C77-83FB-018E26F11032}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\DMCDaemon.exe
FirewallRules: [{080E3B6E-6A0A-4D18-B89D-5C4C03E1C259}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\DMCDaemon.exe
FirewallRules: [{DEE3B499-1DBD-4CDE-A3CA-C9B77579D0DF}] => (Allow) C:\Program Files (x86)\Acer\Acer Portal\ccd.exe
FirewallRules: [{BED84033-9105-43DF-95A0-316EC4FF074A}] => (Allow) C:\Program Files (x86)\Acer\Acer Portal\ccd.exe
FirewallRules: [{4160AA2B-F3A6-43E9-819A-7F60F16114A4}] => (Allow) C:\Program Files (x86)\Acer\Acer Portal\virtualdrive.exe
FirewallRules: [{4D166D35-674A-4EF7-BE50-2CE35D2BBC63}] => (Allow) C:\Program Files (x86)\Acer\Acer Portal\virtualdrive.exe
FirewallRules: [{7CFB4179-773E-4717-850D-AC9F960F0F5D}] => (Allow) C:\Program Files (x86)\Acer\Acer Portal\Sdd.exe
FirewallRules: [{329726E1-2954-419A-943F-A9EB6C068758}] => (Allow) C:\Program Files (x86)\Acer\Acer Portal\Sdd.exe
FirewallRules: [{47A50AB0-4723-4AD0-975B-7467723621D4}] => (Allow) C:\Program Files (x86)\Acer\Acer Portal\ccd.exe
FirewallRules: [{48B13EF3-871D-4284-9D95-FE7024841C5C}] => (Allow) C:\Program Files (x86)\Acer\Acer Portal\ccd.exe
FirewallRules: [{76224E3F-07EA-4D40-A9FD-A830370AA6AA}] => (Allow) C:\Program Files (x86)\Acer\Acer Photo\WindowsUpnp.exe
FirewallRules: [{5A3C6713-4FE6-4F89-94A4-965CE78A3682}] => (Allow) C:\Program Files (x86)\Acer\Acer Photo\WindowsUpnp.exe
FirewallRules: [{8CC9BD91-A6DC-4BC1-8364-33604FACA02F}] => (Allow) C:\Program Files (x86)\Acer\Acer Photo\DMCDaemon.exe
FirewallRules: [{761EBEBC-1867-43F0-8247-21C5F3CA1180}] => (Allow) C:\Program Files (x86)\Acer\Acer Photo\DMCDaemon.exe
FirewallRules: [{29228B0B-B594-4587-9869-084050E735A3}] => (Allow) C:\Program Files (x86)\Acer\Acer Photo\WindowsUpnp.exe
FirewallRules: [{06327C56-0905-4D7C-BC0C-48260B424682}] => (Allow) C:\Program Files (x86)\Acer\Acer Photo\WindowsUpnp.exe
FirewallRules: [{0358F5A9-E30C-4263-A63B-9BA38E7F987A}] => (Allow) C:\Program Files (x86)\Acer\Acer Photo\DMCDaemon.exe
FirewallRules: [{8B1E65AA-DE42-474D-BC9E-F26E2E5D27EC}] => (Allow) C:\Program Files (x86)\Acer\Acer Photo\DMCDaemon.exe
FirewallRules: [{D40AC7CD-9EED-4F86-9E82-115398A24C61}] => (Allow) C:\Program Files (x86)\Acer\Acer Media\WindowsUpnpMV.exe
FirewallRules: [{E1FD1609-EB68-4EC5-87BC-44F33BA2D357}] => (Allow) C:\Program Files (x86)\Acer\Acer Media\WindowsUpnpMV.exe
FirewallRules: [{28B22635-AC4C-4045-9E1D-C5D484820142}] => (Allow) C:\Program Files (x86)\Acer\Acer Media\DMCDaemon.exe
FirewallRules: [{7C655462-7A45-497F-B3C5-96639ADB6479}] => (Allow) C:\Program Files (x86)\Acer\Acer Media\DMCDaemon.exe
FirewallRules: [{2A9E51A8-F6FE-43B2-9456-3EC16A9719EC}] => (Allow) C:\Program Files (x86)\Acer\Acer Media\WindowsUpnpMV.exe
FirewallRules: [{5425F257-78CD-46D9-ABAD-B2A52B7A1A03}] => (Allow) C:\Program Files (x86)\Acer\Acer Media\WindowsUpnpMV.exe
FirewallRules: [{FC7DFB33-86B9-47D2-AC1C-CCA2BD9A1362}] => (Allow) C:\Program Files (x86)\Acer\Acer Media\DMCDaemon.exe
FirewallRules: [{C29F2482-B794-4673-AC0B-6AD68314B25B}] => (Allow) C:\Program Files (x86)\Acer\Acer Media\DMCDaemon.exe
FirewallRules: [{A3F0D979-C5FF-45DD-92BB-14E7AAB75FAB}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\Movie\PowerDVD.exe
FirewallRules: [{4BF50A45-49DB-4337-A31B-78EB647DDBF9}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12ML.exe
FirewallRules: [{49C712B6-395F-40FE-8A68-AFF006DE1A0F}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12Agent.exe
FirewallRules: [{C2FCF49F-5FB5-4154-AD15-507BBFFC0008}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe
FirewallRules: [{14D86FDF-7AFB-47A9-8239-917E3DBF95FB}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMR\PowerDVD12DMREngine.exe
FirewallRules: [{90C25B62-D8F8-4196-BE1D-042069ABA607}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12.exe
FirewallRules: [{25F785BC-5FB2-438F-8EBD-80D3DBDF2E6D}] => (Allow) C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe
FirewallRules: [{59C33720-2C50-49B6-B32A-259D13A80311}] => (Allow) C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe
FirewallRules: [{906FE9FB-CFD5-403C-A769-07E6DE93C835}] => (Allow) C:\Program Files (x86)\Spotify\spotify.exe
FirewallRules: [{B662CA88-CA5E-4EA2-A730-69827EACD2DC}] => (Allow) C:\Program Files (x86)\Spotify\spotify.exe
FirewallRules: [{D85C7AE4-5AA5-47CC-B60A-A30A900E7885}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{267B4964-5880-49C0-BB58-A6AC28520179}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{AB948F10-9A91-4328-B7A1-914127CFA8B4}] => (Allow) C:\Program Files (x86)\Nero\Nero 12\Nero BackItUp\BackItUp.exe
FirewallRules: [{29CE96CD-A7A0-410A-8A31-EFFED185FF26}] => (Allow) C:\Program Files (x86)\Nero\Nero 12\Nero BackItUp\BackItUp.exe
FirewallRules: [TCP Query User{CAD174E9-8708-4E44-8A29-97E8F98E5212}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [UDP Query User{88FB4FD3-5201-449D-B1E4-7E144F729986}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [{18DB65C9-B896-44EA-A747-D2E025FDDC11}] => (Block) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [{06443F07-8E6A-42A2-9813-E6927B1DE3DB}] => (Block) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [TCP Query User{D4C5242D-4E76-461D-A7A8-89E3ECFA921B}C:\users\carol\appdata\local\popcorn time\nw.exe] => (Allow) C:\users\carol\appdata\local\popcorn time\nw.exe
FirewallRules: [UDP Query User{6B3FB498-EFBF-4D57-AA51-B17F46B40090}C:\users\carol\appdata\local\popcorn time\nw.exe] => (Allow) C:\users\carol\appdata\local\popcorn time\nw.exe
FirewallRules: [TCP Query User{CC4E6915-EBD7-4815-9AF6-F5B6EEAC148C}C:\program files (x86)\acer\abphoto\dmcdaemon.exe] => (Block) C:\program files (x86)\acer\abphoto\dmcdaemon.exe
FirewallRules: [UDP Query User{F0EADAE2-392D-4B2E-8B83-C115B048F6E2}C:\program files (x86)\acer\abphoto\dmcdaemon.exe] => (Block) C:\program files (x86)\acer\abphoto\dmcdaemon.exe
FirewallRules: [TCP Query User{44E3ED3F-D877-495C-B043-AFAA069615AC}C:\program files (x86)\acer\abphoto\windowsupnp.exe] => (Allow) C:\program files (x86)\acer\abphoto\windowsupnp.exe
FirewallRules: [UDP Query User{C2DAE9D9-04E4-494A-BEFB-4495A26D7C5E}C:\program files (x86)\acer\abphoto\windowsupnp.exe] => (Allow) C:\program files (x86)\acer\abphoto\windowsupnp.exe
FirewallRules: [TCP Query User{B7C00EA3-4734-46E8-A882-19329372CEFA}C:\users\carol\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\carol\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{BA2C7712-2291-4494-B51B-FB4E53967D56}C:\users\carol\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\carol\appdata\roaming\spotify\spotify.exe
FirewallRules: [{BAED756A-E366-4C56-9653-147549C766B9}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{4FC0DA39-E176-4E3A-9E39-D40BE1F34EEB}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{078046FE-A7CD-4F83-AE03-49176F23F6B9}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [{8CEF97B7-8225-44A3-AD16-DCE391DD0F76}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [{A2176A90-9F6C-46FE-9FDA-14EADAD2EEB6}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{72D9CD3D-1069-4C10-BF42-88B60A132E0D}] => (Allow) LPort=8888
FirewallRules: [TCP Query User{15C51DFF-278B-46CB-9A80-81305B70BC3A}C:\program files (x86)\seagate\seagate dashboard 2.0\dashboard.exe] => (Allow) C:\program files (x86)\seagate\seagate dashboard 2.0\dashboard.exe
FirewallRules: [UDP Query User{50B44A74-DE9A-49BE-B4F2-522DA8C9CDDF}C:\program files (x86)\seagate\seagate dashboard 2.0\dashboard.exe] => (Allow) C:\program files (x86)\seagate\seagate dashboard 2.0\dashboard.exe
 
==================== Restore Points =========================
 
19-02-2017 15:45:45 Installed Seagate Dashboard.
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (02/21/2017 01:19:58 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 4187
 
Error: (02/21/2017 01:19:58 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 4187
 
Error: (02/21/2017 01:19:58 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
 
Error: (02/21/2017 01:19:56 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 2406
 
Error: (02/21/2017 01:19:56 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 2406
 
Error: (02/21/2017 01:19:56 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
 
Error: (02/20/2017 12:27:35 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1344
 
Error: (02/20/2017 12:27:35 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 1344
 
Error: (02/20/2017 12:27:35 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
 
Error: (02/19/2017 03:45:57 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.
 
Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.
 
System Error:
Access is denied.
.
 
 
System errors:
=============
Error: (02/21/2017 12:55:03 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID 
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Error: (02/21/2017 01:19:51 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID 
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Error: (02/20/2017 05:15:30 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID 
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Error: (02/20/2017 12:47:04 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID 
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Error: (02/20/2017 12:27:25 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID 
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Error: (02/19/2017 07:54:35 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Error: (02/19/2017 07:54:35 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Error: (02/19/2017 07:54:34 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
 and APPID 
{F72671A9-012C-4725-9D2F-2A4D32D65169}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Error: (02/19/2017 05:51:20 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID 
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Error: (02/19/2017 05:45:04 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
 
CodeIntegrity:
===================================
  Date: 2017-02-16 10:03:08.868
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements.
 
  Date: 2017-02-15 20:32:00.657
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements.
 
  Date: 2017-02-15 20:32:00.657
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements.
 
  Date: 2017-02-15 20:32:00.657
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements.
 
  Date: 2017-02-15 20:32:00.657
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements.
 
  Date: 2017-02-15 20:32:00.657
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements.
 
  Date: 2017-02-15 20:32:00.657
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements.
 
  Date: 2017-02-15 18:30:58.948
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2017-02-15 18:30:58.939
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2017-02-15 18:30:58.561
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
 
==================== Memory info =========================== 
 
Processor: Intel® Core™ i5-4460 CPU @ 3.20GHz
Percentage of memory in use: 45%
Total physical RAM: 8001.34 MB
Available physical RAM: 4322.33 MB
Total Virtual: 20801.34 MB
Available Virtual: 15689.16 MB
 
==================== Drives ================================
 
Drive c: (Acer) (Fixed) (Total:914.01 GB) (Free:668.01 GB) NTFS
Drive d: (SPIVS) (CDROM) (Total:4.01 GB) (Free:0 GB) UDF
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: B228FFD2)
 
Partition: GPT.
 
==================== End of Addition.txt ============================
 
My PC appears to be running normally now. 
Thanks very much.
 
Carol


#7 RayS

RayS

  • Malware Response Team
  • 2,434 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:11:07 PM

Posted 22 February 2017 - 10:24 PM

Hi Carol,

Thank you for the logs.

Let's clean up some loose ends and do two final scans.


Update Java

Important Note: Your version of Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system.

Please follow these steps to update Java and remove any existing older versions:

  • Click here to Verify Java version
  • If you are notified your Java version is out of date, click Update (recommended)
  • Click Agree and Start Free Java Download
  • Save jxpiinstall.exe to your desktop
  • Double click the icon then click Install
  • Uncheck all optional offers
  • Click Next
  • Once completed, you should be notified You have successfully installed Java
  • If Java notifies you older versions of the program need to be removed, check each of the versions and click Uninstall
  • Verify the older version(s) was uninstalled. Then click Next
  • Click Close

 

 

Scan with Malwarebytes Antimalware (MBAM)

Please launch the copy of MBAM that is currently installed on your PC.

  • After MBAM opens, if it says Your databases are out of date, click Fix Now (yellow button in upper right of MBAM window).
  • Click the Settings tab at the top, and then in the left column, select Detections and Protections, and, if not already checked, place a checkmark in the selection box for Scan for rootkits.
  • Click the Scan tab at the top of the program window, select Threat Scan and click Scan Now.
  • If you receive a message that updates are available, click Update Now (the update will be downloaded, installed, and the scan will start).
  • When MBAM is finished scanning, it will display any detected threats.
  • Click Remove Selected.
  • MBAM will move infected files and registry keys into quarantine. If MBAM displays a message stating that it needs to reboot, please allow it to do so after the next three steps.
  • Don't click Finish yet.
  • While still on the Scan tab, click Save Results in lower right corner, and, in the window that opens, click Text file (*.txt), and save the log to your Desktop. Send the log to me in your next reply.
  • Go back to Scan tab and click Finish.

An abbreviated log is automatically saved by MBAM and can also be viewed by clicking the History tab > Application Logs > Export.



ESET Online Scanner

Note: You will need to disable your currently installed Anti-Virus, how to do so can be found here.

  • Click this link to open ESET Online Scanner.
  • Click SCAN NOW.
  • esetonlinescanner_enu.exe will be downloaded to your PC. Take note of the folder to which it is downloaded.
  • Double-click on esetonlinescanner_enu.exe. If you see a Security Warning pop-up, click Run.
  • On the Terms of Use pop-up, click Accept.
  • In the new window that opens, tic the radio button next to Enable detection of potentially unwanted applications.
  • Then click Advanced settings, and make sure there is a checkmark next to the first four items as follows. (uncheck everything else):
    • Scan for potentially unsafe applications
    • Scan for potentially suspicious applications
    • Scan archives
    • Enable Anti-Stealth technology
  • Then click Scan. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, click Save to text file... (only if anything is found) and give it a unique name, such as ESETScan.txt. Include the contents of this report in your next reply.
  • Click Finish to exit ESET Online Scanner.
  • Don't forget to re-enable your antivirus when finished!

 

 

In your next reply...

  • Confirm whether you deleted or updated the Java Runtime Environment.
  • Copy and paste the entire contents of the MBAM report into the body of your message.
  • Confirm that the ESET online scan ran to completion. Copy and paste the scan report (if any) into the body of your message.
  • How is your PC running now?

 

Thank you,
Ray


I don't accept payment for my help, but it would please me if you perform a kindness for your neighbor. You might also contact your local animal shelter. They can always use a bag of kibble or a few cans of pet food. Who knows... you might even find a life-long furry friend there.


#8 csquared

csquared
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:09:07 PM

Posted 23 February 2017 - 12:57 PM

Hello Ray,

 

Thanks for the detailed instructions. 

I have updated Java. 

 

This is the MBAM report

Malwarebytes
www.malwarebytes.com
 
-Log Details-
Scan Date: 2/22/17
Scan Time: 11:22 PM
Logfile: virus.txt
Administrator: Yes
 
-Software Information-
Version: 3.0.6.1469
Components Version: 1.0.50
Update Package Version: 1.0.1329
License: Trial
 
-System Information-
OS: Windows 10
CPU: x64
File System: NTFS
User: CHU\Carol
 
-Scan Summary-
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 471782
Time Elapsed: 15 min, 3 sec
 
-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
 
-Scan Details-
Process: 0
(No malicious items detected)
 
Module: 0
(No malicious items detected)
 
Registry Key: 0
(No malicious items detected)
 
Registry Value: 0
(No malicious items detected)
 
Registry Data: 0
(No malicious items detected)
 
Data Stream: 0
(No malicious items detected)
 
Folder: 0
(No malicious items detected)
 
File: 0
(No malicious items detected)
 
Physical Sector: 0
(No malicious items detected)
 
 
(end)
 
The ESET link you gave me didn't work, I ran this one https://www.eset.com/int/home/online-scanner/.
Here is the report. 
 
C:\AdwCleaner\Quarantine\C\Program Files (x86)\GetPrivate\tasks.dll.vir a variant of Win32/Tasks.A potentially unwanted application
C:\AdwCleaner\Quarantine\C\ProgramData\Interenet Optimizer\InterenetOptimizer_x64.dll.vir a variant of Win64/SProtector.B potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Carol\AppData\Roaming\GetPrivate\tasks.dll.vir a variant of Win32/Tasks.A potentially unwanted application
C:\Users\Carol\AppData\Local\VirtualStore\CA9FD-43XXH-ETGGH-TXATX-GHZTO-AFRGT-XFGOY.html Win32/Filecoder.Spora trojan
C:\Users\Carol\AppData\LocalLow\Oracle\Java\jre1.8.0_111\java_sp.dll a variant of Win32/Bundled.Toolbar.Ask.N potentially unsafe application
C:\Users\Carol\AppData\LocalLow\Oracle\Java\jre1.8.0_111\java_sp\JavaIC.dll a variant of Win32/Bundled.Toolbar.Ask.N potentially unsafe application
C:\Users\Carol\Downloads\PandoraRecovery2.1.1Setup.exe a variant of Win32/Bundled.Toolbar.Ask.G potentially unsafe application
C:\Users\Carol\Downloads\rcsetup152.exe Win32/Bundled.Toolbar.Google.D potentially unsafe application
C:\Windows\SysWOW64\tasks.dll a variant of Win32/Tasks.A potentially unwanted application
 
 
Should I select clean all?
Computer still seems to be running normally. 
 
Thank you again for the help,
 
Carol


#9 RayS

RayS

  • Malware Response Team
  • 2,434 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:11:07 PM

Posted 24 February 2017 - 09:14 PM

Hi Carol,

Thank you for the logs.

 

The ESET link you gave me didn't work, I ran this one https://www.eset.com/int/home/online-scanner/.

That's very odd. The link I sent to you works for me as well as for others. In any event, both links arrive at the same ESET screen and it is safe to delete all the items revealed by the scan.

 

Should I select clean all?

Yes. Unfortunately, there is no way to address the items without scanning again. Please temporarily disable your AV products and launch esetonlinescanner_enu.exe again. When it completes, select all items and click Clean. Then re-enable your AV products.



Recover storage space

Please examine your Recycle Bin for the unlikely chance that it contains any file(s)/folder(s) that you may want to keep because (among other things) the next step will permanently empty the Recycle Bin.

Save all your work because this script will cause your computer to reboot.

  • Press the windows key Windows_Logo_key.gif+ R on your keyboard at the same time. This will open the Run dialog box.
  • Type Notepad into the Run box and click OK.
  • Please copy the entire contents of the code box below into a new file.
Start
CloseProcesses:
EmptyTemp:
End
  • Save the file as fixlist.txt into the same folder where the Farbar tool is running from.
  • Run FRST64.exe and click Fix only once and wait until the program completes execution.
  • Restart the computer normally to reset the registry.
  • The tool will create a log (Fixlog.txt).

 

 

In your next reply...

  • Copy and paste the ESET report into the body of your message.
  • Copy and paste Fixlog.txt into the body of your message.
  • Tell me how your PC is running now.

Thank you,

Ray


I don't accept payment for my help, but it would please me if you perform a kindness for your neighbor. You might also contact your local animal shelter. They can always use a bag of kibble or a few cans of pet food. Who knows... you might even find a life-long furry friend there.


#10 csquared

csquared
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:09:07 PM

Posted 26 February 2017 - 02:01 AM

Hello Ray, 

 

Weird as the link still doesn't work for me. 

ESET Report found nothing.

Fixlog

Fix result of Farbar Recovery Scan Tool (x64) Version: 25-02-2017
Ran by Carol (25-02-2017 23:38:24) Run:3
Running from C:\Users\Carol\Downloads
Loaded Profiles: Carol (Available Profiles: Carol & Administrator)
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
Start
CloseProcesses:
EmptyTemp:
End
*****************
 
Processes closed successfully.
 
=========== EmptyTemp: ==========
 
BITS transfer queue => 32768 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 112859332 B
Java, Flash, Steam htmlcache => 61098 B
Windows/system/drivers => 2329001892 B
Edge => 93231011 B
Chrome => 993843548 B
Firefox => 375933206 B
Opera => 0 B
 
Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 102902 B
NetworkService => 1010474 B
Carol => 889016148 B
Administrator => 12245 B
 
RecycleBin => 10306925217 B
EmptyTemp: => 14.1 GB temporary data Removed.
 
================================
 
 
The system needed a reboot.
 
==== End of Fixlog 23:44:04 ====
 
Computer seems to be running normally. 
 
Thanks,
Carol 


#11 RayS

RayS

  • Malware Response Team
  • 2,434 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:11:07 PM

Posted 26 February 2017 - 10:45 AM

Hi Carol,

Good job! Now, let's do a final clean-up.


Remove tools and logs

Run Delfix by Xplode

  • Download Delfix and save it to your Desktop
  • Double click the icon
  • Place checkmarks next to:

Remove disinfection tools
Create registry backup
Purge system restore

  • Click Run

You may delete any additional programs or logs on your computer which were not automatically removed by Delfix. Simply delete the log files or desktop icons.



Here's some food for thought:


Guard against ransomware
A growing trend among cybercriminals is to encrypt all your data and then demand payment for the decryption key. For an example of one variety of ransomware, see the very comprehensive article, CryptoLocker Ransomware Information Guide and FAQ by Lawrence Abrams.

Prevention is far better than attempting to cure, therefore, I recommend the free version of CryptoPrevent. The Premium version includes some advanced features. Other security companies are developing products in this area as well.


Manage your passwords
Use different passwords on each account. Install one of the password managers like LastPass (free or premium version) or KeePass Password Safe.


Backup your data
Make frequent backups of all your important files such as documents, spreadsheets, photos, business records, etc. Synchronized files are convenient, but are just as vulnerable as local files. Offline storage is best because malware can infect all machines in a network. Fire and theft can affect all devices in a single physical location. Consider cloud storage, but be sure to encrypt all traffic to and from the cloud and protect your files with strong passwords. Disconnect from the service except when you are actually storing or retrieving files.

Please also take the time to read below on how to secure the machine and take the necessary steps to keep it clean :thumbsup:

Lawrence Abrams, the founder of BleepingComputer.com, has developed an excellent tutorial which will provide you with the information you need to know to keep your computer secure and clean. Please take the time to read:

In addition, here are a few more links you might find of interest:


Thank you for placing your trust in BleepingComputer. It was a pleasure serving you.

Please reply to this post to let us know we can close the topic.

Best regards,

Ray


I don't accept payment for my help, but it would please me if you perform a kindness for your neighbor. You might also contact your local animal shelter. They can always use a bag of kibble or a few cans of pet food. Who knows... you might even find a life-long furry friend there.


#12 csquared

csquared
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:09:07 PM

Posted 28 February 2017 - 12:40 AM

Hello Ray,

 

Thank you very much for your help. 

I have deleted the tools and logs and installed CryptoLocker. 

You can close the topic. 

 

Thanks again,

Carol



#13 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,997 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:08:07 PM

Posted 28 February 2017 - 10:18 AM

It appears that this issue is resolved, therefore I am closing the topic. If that is not the case and you need or wish to continue with this topic, please send me or any Moderator a Personal Message (PM) that you would like this topic re-opened.
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users