FRST info:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 17-04-2021
Ran by Samantha Karnes (administrator) on SAMANTHA (TOSHIBA Satellite C55D-B) (18-04-2021 17:39:34)
Running from C:\Users\Samantha Karnes\Desktop
Loaded Profiles: Samantha Karnes
Platform: Windows 10 Home Version 2004 19041.928 (X64) Language: English (United States)
Default browser: Edge
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
() [File not signed] C:\Program Files\ATI Technologies\ATI.ACE\a4\AdaptiveSleepService.exe
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender Agent\DiscoverySrv.exe
(Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender Agent\ProductAgentService.exe
(Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender Antivirus Free\bdagent.exe
(Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender Antivirus Free\bdredline.exe
(Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender Antivirus Free\updatesrv.exe
(Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender Antivirus Free\vsserv.exe
(Bitdefender SRL -> Bitdefender) C:\Program Files\Bitdefender Antivirus Free\vsservppl.exe
(Bose Corporation -> Bose Corporation) C:\Program Files (x86)\Bose Updater\BOSEUPDATER.EXE
(Compal Electronics, Inc. -> TOSHIBA CORPORATION) C:\Program Files (x86)\Toshiba\Utilities\KeNotify.exe
(DTS, Inc. -> ) C:\Program Files (x86)\DTS, Inc\DTS Studio Sound\dts_apo_service.exe
(Dynabook Inc. -> Dynabook Inc.) C:\Windows\System32\DriverStore\FileRepository\tossrvctl.inf_amd64_4d5c54c80b005163\DSDFunctionKeyCtlService.exe <2>
(Dynabook Inc. -> Dynabook Inc.) C:\Windows\System32\DriverStore\FileRepository\tossrvctl.inf_amd64_4d5c54c80b005163\RMService.exe
(ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(Fitbit, Inc. -> Fitbit, Inc.) [File not signed] C:\Program Files (x86)\Fitbit Connect\Fitbit Connect.exe
(Fitbit, Inc. -> Fitbit, Inc.) [File not signed] C:\Program Files (x86)\Fitbit Connect\FitbitConnectService.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <12>
(Microsoft Corporation -> Microsoft Corporation) C:\Users\Samantha Karnes\AppData\Local\Microsoft\OneDrive\OneDrive.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\oobe\UserOOBEBroker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atiesrxx.exe
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Qualcomm Atheros -> Windows (R) Win 7 DDK provider) [File not signed] C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(SEIKO EPSON Corporation -> Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe
(TOSHIBA CORPORATION -> TOSHIBA Corporation) C:\Program Files\TOSHIBA\Hotkey\TCrdMain_Win8.exe
(TOSHIBA CORPORATION -> TOSHIBA Corporation) C:\Program Files\TOSHIBA\Teco\TecoResident.exe
(TOSHIBA CORPORATION -> Toshiba Corporation) C:\Program Files\TOSHIBA\Teco\TecoService.exe
(TOSHIBA CORPORATION -> TOSHIBA) C:\Program Files\TOSHIBA\TOSHIBA Smart View Utility\TDUSrv64.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [3873000 2016-06-02] (ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.)
HKLM\...\Run: [TCrdMain] => C:\Program Files\TOSHIBA\Hotkey\TCrdMain_Win8.exe [2556768 2013-10-08] (TOSHIBA CORPORATION -> TOSHIBA Corporation)
HKLM\...\Run: [TecoResident] => C:\Program Files\TOSHIBA\Teco\TecoResident.exe [179288 2014-04-17] (TOSHIBA CORPORATION -> TOSHIBA Corporation)
HKLM\...\Run: [TSSSrv] => C:\Program Files (x86)\TOSHIBA\System Setting\TSSSrv.exe [296008 2013-10-21] (TOSHIBA CORPORATION -> TOSHIBA Corporation)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [303928 2017-05-09] (Apple Inc. -> Apple Inc.)
HKLM-x32\...\Run: [KeNotify] => C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe [34160 2013-08-05] (Compal Electronics, Inc. -> TOSHIBA CORPORATION)
HKLM-x32\...\Run: [TSVU] => c:\Program Files\TOSHIBA\TOSHIBA Smart View Utility\TosSmartViewLauncher.exe [516512 2013-07-23] (TOSHIBA CORPORATION -> TOSHIBA)
HKLM-x32\...\Run: [Fitbit Connect] => C:\Program Files (x86)\Fitbit Connect\Fitbit Connect.exe [4377256 2015-09-04] (Fitbit, Inc. -> Fitbit, Inc.) [File not signed]
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [646160 2019-12-11] (Oracle America, Inc. -> Oracle Corporation)
HKU\S-1-5-21-316880295-4286440006-4187134797-1001\...\Run: [Fitbit Connect] => C:\Program Files (x86)\Fitbit Connect\Fitbit Connect.exe [4377256 2015-09-04] (Fitbit, Inc. -> Fitbit, Inc.) [File not signed]
HKU\S-1-5-21-316880295-4286440006-4187134797-1001\...\Run: [Bose Updater] => C:\Program Files (x86)\Bose Updater\BOSEUPDATER.EXE [414552 2021-03-27] (Bose Corporation -> Bose Corporation)
HKU\S-1-5-21-316880295-4286440006-4187134797-1001\...\MountPoints2: {b8fb6b3e-0f51-11eb-8323-4cbb5866d705} - "E:\OnePlus_setup.exe" /s
HKLM\...\Windows x64\Print Processors\Canon MX490 series Print Processor: C:\Windows\System32\spool\prtprocs\x64\CNMPDCK.DLL [30208 2014-09-10] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\Canon BJ FAX Language Monitor MX490 series: C:\WINDOWS\system32\CNCALCK.DLL [303104 2014-09-22] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\Canon BJ Language Monitor MX490 series: C:\WINDOWS\system32\CNMLMCK.DLL [406528 2014-09-10] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\EPSON WF-2540 Series 64MonitorBE: C:\WINDOWS\system32\E_YLMIUE.DLL [120320 2015-01-06] (Microsoft Windows Hardware Compatibility Publisher -> SEIKO EPSON CORPORATION)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\90.0.4430.72\Installer\chrmstp.exe [2021-04-18] (Google LLC -> Google LLC)
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\WINDOWS\System32\AutoWorkplace.exe
Task: {38E4C892-700E-413C-9B9F-3181F47A154E} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16690424 2016-08-26] (Realtek Semiconductor Corp -> Realtek Semiconductor)
Task: {4FBE1633-37C9-40D6-A2A7-860515D0E76D} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyUpload => {EBF00FCB-0769-4B81-9BEC-6C05514111AA}
Task: {6172A990-3C78-4E71-B197-01B43205C717} - System32\Tasks\Bitdefender Agent WatchDog_65D6944A0EF74FDAB96E31112AD39864 => C:\Program Files\Bitdefender Agent\WatchDog.exe [888232 2021-01-29] (Bitdefender SRL -> Bitdefender)
Task: {64B37D51-B107-4CED-BA9F-02F275424D45} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154440 2021-04-18] (Google LLC -> Google LLC)
Task: {66CCAF17-0997-41D6-A177-4BA55115A843} - System32\Tasks\TOSHIBA\Service Station => C:\Program Files\TOSHIBA\Toshiba Service Station\ToshibaServiceStation.exe [699496 2013-09-24] (TOSHIBA CORPORATION -> TOSHIBA Corporation)
Task: {69500F3F-673E-4ADB-A50F-9BC20C5ECD0D} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2103.7-0\MpCmdRun.exe [566368 2021-04-18] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task => {BF6C1E47-86EC-4194-9CE5-13C15DCB2001}
Task: {85825ECF-F972-40F9-B74F-FF0B0A6C6DDF} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1557200 2021-01-25] (Adobe Inc. -> Adobe Inc.)
Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task => {1B1F472E-3221-4826-97DB-2C2324D389AE}
Task: {94180BDD-2A23-4EC0-8F43-C3D059897F5C} - System32\Tasks\{8FBC408D-7A98-49A0-B52F-ABD4D2DA31C3} => "c:\program files (x86)\google\chrome\application\chrome.exe"
http://ui.skype.com/ui/0/7.17.0.105/en/abandoninstall?source=lightinstaller&page=tsBing
Task: {A626C9DB-305E-4C44-ADD6-265E09F0CD33} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2103.7-0\MpCmdRun.exe [566368 2021-04-18] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {BC7EB884-DF6B-4B59-AB6D-4D0B211B91CC} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [570240 2017-02-14] (Apple Inc. -> Apple Inc.)
Task: {C492B274-9FDA-4BE6-909D-BCE39CFD328C} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2103.7-0\MpCmdRun.exe [566368 2021-04-18] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {CE2DE968-E342-40D7-9566-427D45E4A886} - System32\Tasks\Microsoft\Windows\PerfTrack\BackgroundConfigSurveyor => {EA9155A3-8A39-40B4-8963-D3C761B18371}
Task: {D8D09AAC-7220-47C9-ACF5-833EC074CCF6} - System32\Tasks\Pokki => C:\Users\Samantha Karnes\AppData\Local\Pokki\Engine\ServiceHostAppUpdater.exe
Task: {E253D3A9-6D41-4370-AB69-EA697FB8B668} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154440 2021-04-18] (Google LLC -> Google LLC)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 68.105.28.11 68.105.29.11 68.105.28.12
Tcpip\..\Interfaces\{37c530e7-186d-44b4-b753-6b27bcd6789a}: [DhcpNameServer] 68.105.28.11 68.105.29.11 68.105.28.12
Tcpip\..\Interfaces\{e301b961-b921-494f-b828-e0c62aa8ca74}: [DhcpNameServer] 192.168.1.1
Edge:
=======
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
Edge Profile: C:\Users\Samantha Karnes\AppData\Local\Microsoft\Edge\User Data\Default [2021-04-16]
Edge HomePage: Default -> hxxp://www.google.com/
Edge Extension: (Read&Write for Microsoft Edge™) - C:\Users\Samantha Karnes\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\bjglhpoliipklkfjcahfefdlfpifcinb [2021-04-14]
Edge Extension: (Skype Calling) - C:\Users\Samantha Karnes\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\blakpkgjpemejpbmfiglncklihnhjkij [2020-08-27]
Edge Extension: (Save to Google Drive) - C:\Users\Samantha Karnes\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\gmbmikajjgmnabiglmofipeabaddhgne [2021-04-14]
Edge Extension: (Adblock Plus - free ad blocker) - C:\Users\Samantha Karnes\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\gmgoamodcdcjnbaobigkjelfplakmdhh [2021-04-14]
Edge Extension: ((Deprecated) G Suite Training) - C:\Users\Samantha Karnes\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\idkloemkmldbemijiamdiolojbffnjlh [2020-08-27]
Edge Extension: (uBlock Plus Adblocker) - C:\Users\Samantha Karnes\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\oofnbdifeelbaidfgpikinijekkjcicg [2020-08-27]
FireFox:
========
FF DefaultProfile: 2ymu52ic.default
FF ProfilePath: C:\Users\Samantha Karnes\AppData\Roaming\Mozilla\Firefox\Profiles\2ymu52ic.default [2021-04-18]
FF Homepage: Mozilla\Firefox\Profiles\2ymu52ic.default -> hxxps://links.malwarebytes.com/link/restorebrowser?lic=trial&product=MBAM-C/?s=toshibaupd&m=start
FF Extension: (New Tab by Yahoo) - C:\Users\Samantha Karnes\AppData\Roaming\Mozilla\Firefox\Profiles\2ymu52ic.default\Extensions\
jid1-G80Ec8LLEbK5fQ@jetpack.xpi [2015-08-06] [Legacy] [not signed]
FF Plugin: @java.com/DTPlugin,version=11.241.2 -> C:\Program Files\Java\jre1.8.0_241\bin\dtplugin\npDeployJava1.dll [2020-01-16] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.241.2 -> C:\Program Files\Java\jre1.8.0_241\bin\plugin2\npjp2.dll [2020-01-16] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.241.2 -> C:\Program Files (x86)\Java\jre1.8.0_241\bin\dtplugin\npDeployJava1.dll [2020-01-16] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.241.2 -> C:\Program Files (x86)\Java\jre1.8.0_241\bin\plugin2\npjp2.dll [2020-01-16] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2021-04-13] (Adobe Inc. -> Adobe Systems Inc.)
StartMenuInternet: FIREFOX.EXE - firefox.exe
Chrome:
=======
CHR Profile: C:\Users\Samantha Karnes\AppData\Local\Google\Chrome\User Data\Default [2021-04-18]
CHR Notifications: Default -> hxxps://www.facebook.com
CHR HomePage: Default -> hxxp://www.google.com/
CHR StartupUrls: Default -> "hxxp://www.google.com"
CHR Extension: (Google Drive) - C:\Users\Samantha Karnes\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2021-04-18]
CHR Extension: (Skype Calling) - C:\Users\Samantha Karnes\AppData\Local\Google\Chrome\User Data\Default\Extensions\blakpkgjpemejpbmfiglncklihnhjkij [2021-04-18]
CHR Extension: (YouTube) - C:\Users\Samantha Karnes\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2021-04-18]
CHR Extension: (Adblock Plus - free ad blocker) - C:\Users\Samantha Karnes\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2021-04-18]
CHR Extension: (Google Docs Offline) - C:\Users\Samantha Karnes\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2021-04-18]
CHR Extension: (Save to Google Drive) - C:\Users\Samantha Karnes\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmbmikajjgmnabiglmofipeabaddhgne [2021-04-18]
CHR Extension: (Read&Write for Google Chrome™) - C:\Users\Samantha Karnes\AppData\Local\Google\Chrome\User Data\Default\Extensions\inoeonmfapjbbkmdafoankkfajkcphgd [2021-04-18]
CHR Extension: (Google Forms) - C:\Users\Samantha Karnes\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhknlonaankphkkbnmjdlpehkinifeeg [2021-04-18]
CHR Extension: (Skype) - C:\Users\Samantha Karnes\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2021-04-18]
CHR Extension: (Google Drawings) - C:\Users\Samantha Karnes\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkaakpdehdafacodkgkpghoibnmamcme [2021-04-18]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Samantha Karnes\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-04-18]
CHR Extension: (Gmail) - C:\Users\Samantha Karnes\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2021-04-18]
CHR Extension: (Chrome Media Router) - C:\Users\Samantha Karnes\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2021-04-18]
CHR HKLM-x32\...\Chrome\Extension: [dofoafnmdocgkdphpkdooahjkhpmakjd]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdaptiveSleepService; C:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe [140288 2014-04-22] () [File not signed]
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [169672 2021-01-25] (Adobe Inc. -> Adobe Inc.)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2017-04-03] (Apple Inc. -> Apple Inc.)
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [319104 2014-03-19] (Qualcomm Atheros -> Windows (R) Win 7 DDK provider) [File not signed]
R2 bdredline; C:\Program Files\Bitdefender Antivirus Free\bdredline.exe [2461792 2019-03-27] (Bitdefender SRL -> Bitdefender)
R2 DSDFunctionKeyCtlService; C:\WINDOWS\System32\DriverStore\FileRepository\tossrvctl.inf_amd64_4d5c54c80b005163\DSDFunctionKeyCtlService.exe [615776 2021-02-22] (Dynabook Inc. -> Dynabook Inc.)
R2 dts_apo_service; C:\Program Files (x86)\DTS, Inc\DTS Studio Sound\dts_apo_service.exe [21840 2014-03-03] (DTS, Inc. -> )
R2 EpsonScanSvc; C:\WINDOWS\system32\EscSvc64.exe [135824 2011-12-12] (SEIKO EPSON Corporation -> Seiko Epson Corporation)
R2 Fitbit Connect; C:\Program Files (x86)\Fitbit Connect\FitbitConnectService.exe [5750440 2015-09-04] (Fitbit, Inc. -> Fitbit, Inc.) [File not signed]
R2 ProductAgentService; C:\Program Files\Bitdefender Agent\ProductAgentService.exe [1358248 2021-01-29] (Bitdefender SRL -> Bitdefender)
S2 TSDSettingService; C:\WINDOWS\System32\DriverStore\FileRepository\tossrvctl.inf_amd64_4d5c54c80b005163\dynabookSystemService.exe [44767048 2021-02-22] (Dynabook Inc. -> Dynabook Inc.)
S2 TSDTabletControlService; C:\WINDOWS\System32\DriverStore\FileRepository\tossrvctl.inf_amd64_4d5c54c80b005163\TOSTABSYSSVC.exe [296272 2021-02-22] (Dynabook Inc. -> Dynabook Inc.)
R2 TSDWirelessLEDCtlService; C:\WINDOWS\System32\DriverStore\FileRepository\tossrvctl.inf_amd64_4d5c54c80b005163\RMService.exe [446248 2021-02-22] (Dynabook Inc. -> Dynabook Inc.)
R2 updatesrv; C:\Program Files\Bitdefender Antivirus Free\updatesrv.exe [236128 2020-11-26] (Bitdefender SRL -> Bitdefender)
R2 vsserv; C:\Program Files\Bitdefender Antivirus Free\vsserv.exe [559200 2021-04-02] (Bitdefender SRL -> Bitdefender)
R2 vsservppl; C:\Program Files\Bitdefender Antivirus Free\vsservppl.exe [240352 2020-11-26] (Bitdefender SRL -> Bitdefender)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2103.7-0\NisSrv.exe [2624104 2021-04-18] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2103.7-0\MsMpEng.exe [128376 2021-04-18] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 atc; C:\WINDOWS\System32\DRIVERS\atc.sys [2718744 2021-02-26] (Bitdefender SRL -> Bitdefender S.R.L. Bucharest, ROMANIA)
R2 BdDci; C:\WINDOWS\system32\DRIVERS\bddci.sys [802976 2020-12-04] (Bitdefender SRL -> Bitdefender)
S0 bdelam; C:\WINDOWS\System32\drivers\bdelam.sys [22976 2020-12-18] (Microsoft Windows Early Launch Anti-malware Publisher -> Bitdefender)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [File not signed]
S3 edrsensor; C:\WINDOWS\System32\DRIVERS\edrsensor.sys [309120 2020-02-03] (Bitdefender SRL -> BitDefender S.R.L. Bucharest, ROMANIA)
R1 Gemma; C:\WINDOWS\System32\DRIVERS\gemma.sys [488592 2021-02-16] (Bitdefender SRL -> BitDefender S.R.L. Bucharest, ROMANIA)
R3 RSP2STOR; C:\WINDOWS\system32\DRIVERS\RtsP2Stor.sys [310528 2015-06-09] (Realtek Semiconductor Corp -> Realtek Semiconductor Corp.)
R3 Thotkey; C:\WINDOWS\System32\drivers\Thotkey.sys [47816 2020-07-21] (Dynabook Inc. -> Dynabook Inc.)
R3 tosrfec; C:\WINDOWS\System32\drivers\tosrfec.sys [37808 2019-04-30] (Dynabook Inc. -> Dynabook Inc.)
R1 TosSrvCtlDrv; C:\WINDOWS\System32\DriverStore\FileRepository\tossrvctl.inf_amd64_4d5c54c80b005163\TosSrvCtlDrv.sys [25816 2021-02-22] (Dynabook Inc. -> Dynabook Inc.)
R2 trufos; C:\WINDOWS\System32\drivers\trufos.sys [641728 2021-02-26] (Bitdefender SRL -> Bitdefender)
S0 TVALZ; C:\WINDOWS\System32\drivers\TVALZ_O.SYS [46088 2019-04-30] (Dynabook Inc. -> Dynabook Inc.)
R0 TVALZ_O; C:\WINDOWS\System32\drivers\TVALZ_O.SYS [46088 2019-04-30] (Dynabook Inc. -> Dynabook Inc.)
S3 USBAAPL64; C:\WINDOWS\System32\Drivers\usbaapl64.sys [54784 2015-06-10] (Apple, Inc.) [File not signed]
R0 vlflt; C:\WINDOWS\System32\DRIVERS\vlflt.sys [386800 2020-10-20] (Bitdefender SRL -> Bitdefender)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [49560 2021-04-18] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [421088 2021-04-18] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [72928 2021-04-18] (Microsoft Windows -> Microsoft Corporation)
U3 aswbdisk; no ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-04-18 16:35 - 2021-04-18 16:35 - 000002312 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2021-04-18 16:35 - 2021-04-18 16:35 - 000002271 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2021-04-18 16:35 - 2021-04-18 16:35 - 000002271 _____ C:\ProgramData\Desktop\Google Chrome.lnk
2021-04-18 16:34 - 2021-04-18 16:39 - 000003418 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2021-04-18 16:34 - 2021-04-18 16:39 - 000003294 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2021-04-18 16:23 - 2021-04-18 16:23 - 001622528 _____ C:\Users\Samantha Karnes\Desktop\ResetBrowser.exe
2021-04-18 14:17 - 2021-04-18 14:40 - 000033142 _____ C:\Users\Samantha Karnes\Desktop\Fixlog.txt
2021-04-18 14:17 - 2021-04-18 14:17 - 000000000 ____D C:\Users\Samantha Karnes\Desktop\FRST-OlderVersion
2021-04-16 08:49 - 2021-04-16 09:00 - 000039920 _____ C:\Users\Samantha Karnes\Desktop\Addition.txt
2021-04-16 08:38 - 2021-04-18 17:44 - 000023286 _____ C:\Users\Samantha Karnes\Desktop\FRST.txt
2021-04-16 08:35 - 2021-04-18 17:41 - 000000000 ____D C:\FRST
2021-04-16 08:31 - 2021-04-18 14:17 - 002298368 _____ (Farbar) C:\Users\Samantha Karnes\Desktop\FRST64.exe
2021-04-14 18:09 - 2021-04-14 18:09 - 000088428 _____ C:\ProgramData\agent.update.1618448903.bdinstall.v2.bin
2021-04-14 15:03 - 2021-04-14 15:03 - 000001203 _____ C:\Users\Samantha Karnes\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bitdefender Antivirus Free.lnk
2021-04-14 15:02 - 2021-04-14 15:02 - 000000000 ____D C:\ProgramData\48C4687D-9760-4F5B-BAB3-60351B0841E4
2021-04-14 14:58 - 2020-12-18 02:37 - 000022976 _____ (Bitdefender) C:\WINDOWS\system32\Drivers\bdelam.sys
2021-04-14 14:56 - 2021-04-14 14:56 - 000001218 _____ C:\Users\Public\Desktop\Bitdefender Antivirus Free.lnk
2021-04-14 14:56 - 2021-04-14 14:56 - 000001218 _____ C:\ProgramData\Desktop\Bitdefender Antivirus Free.lnk
2021-04-14 14:56 - 2021-02-26 18:31 - 000641728 _____ (Bitdefender) C:\WINDOWS\system32\Drivers\trufos.sys
2021-04-14 14:55 - 2021-04-14 14:55 - 000000000 ____D C:\ProgramData\Bitdefender
2021-04-14 14:55 - 2020-02-03 16:53 - 000309120 _____ (BitDefender S.R.L. Bucharest, ROMANIA) C:\WINDOWS\system32\Drivers\edrsensor.sys
2021-04-14 14:54 - 2021-02-26 13:40 - 002718744 _____ (Bitdefender S.R.L. Bucharest, ROMANIA) C:\WINDOWS\system32\Drivers\atc.sys
2021-04-14 14:54 - 2020-12-04 15:15 - 000802976 _____ (Bitdefender) C:\WINDOWS\system32\Drivers\bddci.sys
2021-04-14 14:54 - 2020-10-20 13:18 - 000386800 _____ (Bitdefender) C:\WINDOWS\system32\Drivers\vlflt.sys
2021-04-14 14:53 - 2021-02-16 15:31 - 000488592 _____ (BitDefender S.R.L. Bucharest, ROMANIA) C:\WINDOWS\system32\Drivers\gemma.sys
2021-04-14 14:31 - 2021-04-18 17:55 - 000000000 ____D C:\Program Files\Bitdefender Antivirus Free
2021-04-14 14:30 - 2021-04-14 14:30 - 000003802 _____ C:\WINDOWS\system32\Tasks\Bitdefender Agent WatchDog_65D6944A0EF74FDAB96E31112AD39864
2021-04-14 14:29 - 2021-04-14 14:29 - 000116636 _____ C:\ProgramData\agent.1618435725.bdinstall.v2.bin
2021-04-14 14:28 - 2021-04-14 18:09 - 000000000 ____D C:\Program Files\Bitdefender Agent
2021-04-14 14:28 - 2021-04-14 14:28 - 000000000 ____D C:\ProgramData\Bitdefender Agent
2021-04-14 14:27 - 2021-04-14 14:27 - 013543384 _____ C:\Users\Samantha Karnes\Downloads\bitdefender_online.exe
2021-04-13 22:49 - 2021-04-13 22:53 - 000938756 _____ C:\WINDOWS\Minidump\041321-39468-01.dmp
2021-04-13 20:16 - 2021-04-13 20:16 - 000011357 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim
2021-04-13 20:14 - 2021-04-13 20:14 - 001823304 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2021-04-13 20:13 - 2021-04-13 20:13 - 000231248 _____ C:\WINDOWS\system32\containerdevicemanagement.dll
2021-04-11 07:47 - 2021-04-11 07:47 - 000000000 ____D C:\Program Files\Avast Software
2021-04-11 07:46 - 2021-04-14 14:39 - 000000000 ____D C:\ProgramData\Avast Software
2021-04-08 13:33 - 2021-04-08 13:33 - 000001313 _____ C:\Users\Samantha Karnes\Downloads - Shortcut.lnk
2021-04-08 09:31 - 2021-04-08 09:31 - 000000000 ____D C:\Users\Samantha Karnes\AppData\Local\mbam
2021-03-27 17:44 - 2021-03-27 17:44 - 000000000 ____D C:\Program Files (x86)\Bose Updater
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-04-18 18:03 - 2019-12-07 02:03 - 000065536 _____ C:\WINDOWS\system32\config\ELAM
2021-04-18 17:55 - 2019-12-07 02:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2021-04-18 17:34 - 2020-10-06 18:26 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2021-04-18 17:17 - 2020-05-15 17:40 - 000002147 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2021-04-18 16:58 - 2020-10-06 19:06 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2021-04-18 16:58 - 2020-09-14 20:51 - 000008192 ___SH C:\DumpStack.log.tmp
2021-04-18 16:57 - 2019-12-07 02:03 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2021-04-18 16:57 - 2017-07-29 20:13 - 000065536 _____ C:\WINDOWS\system32\spu_storage.bin
2021-04-18 16:34 - 2015-03-13 17:33 - 000000000 ____D C:\Program Files (x86)\Google
2021-04-18 15:10 - 2018-02-15 06:21 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2021-04-18 14:45 - 2019-12-07 02:14 - 000000000 ___HD C:\Program Files\WindowsApps
2021-04-18 14:45 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2021-04-18 14:36 - 2016-06-28 20:11 - 000000000 ____D C:\Users\Samantha Karnes\AppData\LocalLow\Temp
2021-04-18 14:26 - 2015-03-29 14:11 - 000000000 ____D C:\Users\Samantha Karnes\AppData\Local\CrashDumps
2021-04-16 07:17 - 2020-08-27 13:58 - 000002449 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2021-04-16 07:17 - 2020-08-27 13:58 - 000002287 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2021-04-16 07:17 - 2020-08-27 13:58 - 000002287 _____ C:\ProgramData\Desktop\Microsoft Edge.lnk
2021-04-15 07:45 - 2020-10-06 19:06 - 000003384 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-316880295-4286440006-4187134797-1001
2021-04-15 07:45 - 2020-10-06 18:33 - 000002404 _____ C:\Users\Samantha Karnes\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2021-04-15 07:45 - 2015-03-13 17:05 - 000000000 ___RD C:\Users\Samantha Karnes\OneDrive
2021-04-14 18:41 - 2015-09-17 21:48 - 000000000 ___HD C:\Users\Samantha Karnes\AppData\Local\0fa5a48f5b9676cf
2021-04-14 15:02 - 2019-12-07 02:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2021-04-14 14:53 - 2020-10-06 18:48 - 000840602 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2021-04-14 14:53 - 2019-12-07 02:13 - 000000000 ____D C:\WINDOWS\INF
2021-04-14 14:36 - 2020-10-06 18:33 - 000000000 ____D C:\Users\Samantha Karnes
2021-04-13 22:54 - 2020-11-18 17:01 - 000000000 ____D C:\WINDOWS\Minidump
2021-04-13 22:49 - 2020-05-08 06:57 - 485690090 _____ C:\WINDOWS\MEMORY.DMP
2021-04-13 21:11 - 2020-10-06 18:25 - 000257904 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2021-04-13 21:07 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\SystemResources
2021-04-13 21:06 - 2019-12-07 02:14 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2021-04-13 21:06 - 2019-12-07 02:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2021-04-13 21:06 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\setup
2021-04-13 21:06 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2021-04-13 21:06 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\lv-LV
2021-04-13 21:06 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\lt-LT
2021-04-13 21:06 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\et-EE
2021-04-13 21:06 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\system32\es-MX
2021-04-13 21:06 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\Provisioning
2021-04-13 21:06 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2021-04-13 21:06 - 2019-12-07 02:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2021-04-13 20:31 - 2019-12-07 02:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2021-04-13 20:12 - 2020-10-06 18:28 - 002877440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2021-04-13 18:44 - 2015-03-15 09:36 - 000000000 ____D C:\WINDOWS\system32\MRT
2021-04-13 18:44 - 2015-03-15 09:35 - 131963968 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2021-04-12 21:08 - 2020-10-06 19:06 - 000003480 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2021-04-12 21:08 - 2020-10-06 19:06 - 000003356 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2021-04-08 09:53 - 2014-08-11 01:46 - 000000000 ____D C:\Program Files (x86)\Amazon
==================== Files in the root of some directories ========
2015-08-16 18:48 - 2015-10-17 08:48 - 000000184 _____ () C:\Users\Samantha Karnes\AppData\Roaming\WB.CFG
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================