Additional scan result of Farbar Recovery Scan Tool (x64) Version: 07-05-2017 Ran by [removed] (07-05-2017 23:57:22) Running from E:\Downloads Windows 10 Pro Version 1607 (X64) (2016-08-02 20:05:07) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-914517813-2310829996-1314125057-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-914517813-2310829996-1314125057-503 - Limited - Disabled) Doug (S-1-5-21-914517813-2310829996-1314125057-1000 - Administrator - Enabled) => C:\Users\Doug Guest (S-1-5-21-914517813-2310829996-1314125057-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-914517813-2310829996-1314125057-1006 - Limited - Enabled) SophosSAUDOUGLAS-PC0 (S-1-5-21-914517813-2310829996-1314125057-1007 - Limited - Enabled) SophosSAUDOUGLAS-PC1 (S-1-5-21-914517813-2310829996-1314125057-1017 - Limited - Enabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Sophos Anti-Virus (Enabled - Up to date) {FFADE7EA-DC92-4602-D6B2-626CD3450A0F} AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Spybot - Search and Destroy (Enabled - Up to date) {A16C3F68-9280-E053-1818-342707FECF4D} AS: Sophos Anti-Virus (Enabled - Up to date) {44CC060E-FAA8-498C-EC02-591EA8C240B2} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Acrobat XI Standard (HKLM-x32\...\{AC76BA86-1033-FFFF-BA7E-000000000006}) (Version: 11.0.20 - Adobe Systems) Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 3.7.0.272 - Adobe Systems Incorporated) Adobe Lightroom (HKLM-x32\...\{8048A5DF-8A70-5BE1-954B-E0FDE1BD0D0D}) (Version: 6.5.1 - Adobe Systems Incorporated) Adobe Photoshop CC 2015 (HKLM-x32\...\{793C2BF7-A4FE-4608-91C9-9282C5801C21}) (Version: 16.1.2 - Adobe Systems Incorporated) AMD Settings (HKLM\...\WUCCCApp) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) ANT Drivers Installer x64 (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden APP Shop v1.0.20 (HKLM-x32\...\{90242E9B-BC60-46E3-8EE7-8E953F702280}_is1) (Version: 1.0.20 - ASRock Inc.) Apple Application Support (32-bit) (HKLM-x32\...\{05E07D23-91E9-4E70-A4CC-EF505088F967}) (Version: 5.4.1 - Apple Inc.) Apple Application Support (64-bit) (HKLM\...\{741291DA-2B34-4D44-8FB6-58EDE21261D8}) (Version: 5.4.1 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{DB18F1C0-846F-46F5-A074-5B97C8AF5C8E}) (Version: 10.3.1.2 - Apple Inc.) Apple Software Update (HKLM-x32\...\{52D87F32-70E4-4348-8148-C0B9F35B1314}) (Version: 2.3.0.177 - Apple Inc.) Ascendo DataVault 6.0.8 (HKLM-x32\...\DataVault) (Version: 6.0.8 - Ascendo) ASRock App Charger v1.0.6 (HKLM\...\ASRock App Charger_is1) (Version: 1.0.6 - ASRock Inc.) Audacity 2.1.2 (HKLM-x32\...\Audacity®_is1) (Version: 2.1.2 - Audacity Team) AudioBox version 1.3 (HKLM\...\{554BB593-3543-4AEB-A192-2AC87EC3FF31}_is1) (Version: 1.3 - PreSonus) Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.) calibre (HKLM-x32\...\{E287031B-230C-4127-AA44-598FA9CE3478}) (Version: 2.69.0 - Kovid Goyal) Catalyst Control Center Next Localization BR (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization BR (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CHS (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CHS (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CHT (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CHT (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CS (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CS (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization DA (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization DA (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization DE (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization DE (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization EL (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization EL (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization ES (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization ES (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization FI (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization FI (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization FR (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization FR (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization HU (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization HU (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization IT (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization IT (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization JA (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization JA (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization KO (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization KO (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization NL (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization NL (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization NO (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization NO (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization PL (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization PL (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization RU (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization RU (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization SV (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization SV (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization TH (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization TH (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization TR (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization TR (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Dropbox (HKU\S-1-5-21-914517813-2310829996-1314125057-1000\...\Dropbox) (Version: 25.4.28 - Dropbox, Inc.) Elevated Installer (x32 Version: 5.3.1.0 - Garmin Ltd or its subsidiaries) Hidden Expanse 2.7.2 (HKLM-x32\...\{74EAF571-E33B-4536-B82D-5586A0C8C3CB}_is1) (Version: 2.7.2 - Neunaber Technology LLC) EZ-RC (HKLM-x32\...\EZ-RC) (Version: 1.0.0.308 - Universal Electronics) FileZilla Client 3.23.0.2 (HKLM-x32\...\FileZilla Client) (Version: 3.23.0.2 - Tim Kosse) Garmin BaseCamp (HKLM-x32\...\{23A4DBD1-D847-4957-995D-8B1CC527E2E2}) (Version: 4.6.2.0 - Garmin Ltd or its subsidiaries) Garmin Express (HKLM-x32\...\{bd8bd200-9a60-4969-b267-6b565f36e3da}) (Version: 5.3.1.0 - Garmin Ltd or its subsidiaries) Garmin Express (x32 Version: 5.3.1.0 - Garmin Ltd or its subsidiaries) Hidden Garmin Express Tray (x32 Version: 5.3.1.0 - Garmin Ltd or its subsidiaries) Hidden Google Chrome (HKLM-x32\...\Google Chrome) (Version: 57.0.2987.133 - Google Inc.) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.33.5 - Google Inc.) Hidden GoPro Studio (x32 Version: 5.12.5383 - GoPro, Inc.) Hidden H&R Block California 2016 (HKLM-x32\...\{BBC917D4-2752-484D-BEEA-1005B72B253F}) (Version: 1.16.5801 - HRB Technology, LLC.) H&R Block Deluxe + Efile + State 2016 (HKLM-x32\...\{E7065AD9-D2DB-423B-B853-8310038D7D42}) (Version: 16.05.6301 - HRB Technology, LLC.) HandBrake 0.10.5 (HKLM-x32\...\HandBrake) (Version: 0.10.5 - ) HitmanPro 3.7 (HKLM\...\HitmanPro37) (Version: 3.7.18.284 - SurfRight B.V.) ImgBurn (HKLM-x32\...\ImgBurn) (Version: 2.5.8.0 - LIGHTNING UK!) Insperity Ultimate Employer (HKLM-x32\...\{F00CDDE5-DF5D-4763-8DE8-FB95F6CB8100}) (Version: 8.01.49 - Insperity) Intel(R) Chipset Device Software (x32 Version: 10.1.1.9 - Intel(R) Corporation) Hidden Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.0.0.1153 - Intel Corporation) Intel(R) Network Connections 20.2.4001.0 (HKLM\...\PROSetDX) (Version: 20.2.4001.0 - Intel) Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 14.6.0.1029 - Intel Corporation) Intel(R) Smart Connect Technology (HKLM\...\{3CC1CC76-AB3A-4360-AB6F-1355D05A2A17}) (Version: 5.0.10.2907 - Intel Corporation) iSEEK AnswerWorks English Runtime (HKLM-x32\...\{18A8E78B-9EF2-496E-B310-BCD8E4C1DAB3}) (Version: [removed] - Vantage Linguistics) iTunes (HKLM\...\{6C01A0A7-7440-4D48-93C6-2927A1E93FE6}) (Version: 12.6.0.100 - Apple Inc.) Java 8 Update 91 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218091F0}) (Version: 8.0.910.15 - Oracle Corporation) Jihosoft ISO Maker version 3.0 (HKLM-x32\...\{FA289A40-0F71-428E-B3A2-546EDC04DB93}_is1) (Version: 3.0 - Jihosoft Studio) LAME v3.99.3 (for Windows) (HKLM-x32\...\LAME_is1) (Version: - ) Line 6 Driver2 AMPLIFi Audio v1.77 Uninstaller (HKLM-x32\...\Line 6 Driver2 AmplifiAudio Uninstaller) (Version: - Line 6) Line 6 Line 6 Updater Uninstaller (HKLM-x32\...\Line 6 Line 6 Updater Uninstaller) (Version: 1.11 - Line 6) Line 6 Uninstaller (HKLM-x32\...\Line 6 Uninstaller) (Version: - Line 6) Logitech Harmony Remote Software 7 (HKLM-x32\...\{5C6F884D-680C-448B-B4C9-22296EE1B206}) (Version: 7.7.0.0 - Logitech) Logitech SetPoint 6.67 (HKLM\...\sp6) (Version: 6.67.83 - Logitech) Macrium Reflect Server Edition (HKLM\...\MacriumReflect) (Version: 7.0 - Paramount Software (UK) Ltd.) Macrium Reflect Server Edition (Version: 7.0.2161 - Paramount Software (UK) Ltd.) Hidden Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes) Melodyne 4 (HKLM-x32\...\{16DF894D-FC3F-4B87-908D-671E201CD7A8}) (Version: 4.00.0203 - Celemony Software GmbH) Melodyne Runtime 4.1 (x64) (HKLM\...\{721E4E34-AF7C-4345-93F9-282CCC8CCCB5}) (Version: 1.0.2 - Celemony Software GmbH) Microsoft Office 365 - en-us (HKLM\...\O365HomePremRetail - en-us) (Version: 16.0.7967.2139 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-914517813-2310829996-1314125057-1000\...\OneDriveSetup.exe) (Version: 17.3.6799.0327 - Microsoft Corporation) Microsoft ReportViewer 2010 Redistributable (HKLM-x32\...\{C19B3EB6-B54C-3204-A4DF-88432E0C79F7}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft SQL Server Compact 4.0 x64 ENU (HKLM\...\{8424B163-D1E0-48B7-88A2-C7A61767B3D7}) (Version: 4.0.8482.1 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23918 (HKLM-x32\...\{2e085fd2-a3e4-4b39-8e10-6b8d35f55244}) (Version: 14.0.23918.0 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Office 16 Click-to-Run Extensibility Component (Version: 16.0.7967.2139 - Microsoft Corporation) Hidden Office 16 Click-to-Run Licensing Component (Version: 16.0.7967.2139 - Microsoft Corporation) Hidden Office 16 Click-to-Run Localization Component (Version: 16.0.7668.2066 - Microsoft Corporation) Hidden OpenAL (HKLM-x32\...\OpenAL) (Version: - ) PCRecruiter Control Pack (HKLM-x32\...\{97733134-F287-41C4-BF3D-4793B736895B}) (Version: 8.6.3 - Main Sequence Technologies) Plex Media Player (HKLM-x32\...\{bfc9ba0b-92e5-432f-82ae-ee43753cb4f1}) (Version: 1.2.2 - Plex) Plex Media Player (Version: 1.2.2 - Plex) Hidden PreSonus Studio One 3 x64 (HKLM\...\PreSonus Studio One 3) (Version: 3.3.3.41198 - PreSonus Audio Electronics) Quicken 2014 (HKLM-x32\...\{0877F595-254F-45F4-991D-3F72E86B17CE}) (Version: 23.1.8.8 - Intuit) Quik (HKLM-x32\...\{b15a4fb5-7637-45ca-b230-33d94af786a7}) (Version: 2.3.0.5383 - GoPro, Inc.) Quik (Version: 0.1.5383 - GoPro, Inc.) Hidden Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7560 - Realtek Semiconductor Corp.) Remote Control USB Driver (HKLM-x32\...\{8471021C-F529-43DE-84DF-3612E10F58C4}) (Version: 2.3.2.317 - ) Replay Music 7 (7.0.1.54) (HKLM-x32\...\Replay Music 7) (Version: 7.0.1.54 - Applian Technologies) Silicon Laboratories CP210x USB to UART Bridge (Driver Removal) (HKLM-x32\...\SLABCOMM&10C4&EA60) (Version: - Silicon Laboratories) Sophos Anti-Virus (x32 Version: 10.7.1.32 - Sophos Limited) Hidden Sophos AutoUpdate XG (x32 Version: 5.6.388 - Sophos Limited) Hidden Sophos Diagnostic Utility (x32 Version: 1.14.0.123 - Sophos Limited) Hidden Sophos Endpoint (Version: 1.1.44 - Sophos Limited) Hidden Sophos Endpoint Agent (HKLM\...\Sophos Endpoint Agent) (Version: 11.5.4 - Sophos Ltd) Sophos Endpoint Defense (Version: 1.0.0.265 - Sophos Limited) Hidden Sophos Endpoint Self Help (Version: 1.3.23 - Sophos Limited) Hidden Sophos Health (x32 Version: 2.0.3.32 - Sophos Limited) Hidden Sophos Management Communications System (x32 Version: 4.3.2.1 - Sophos Limited) Hidden Sophos Network Threat Protection (Version: 1.3.1.12 - Sophos Limited) Hidden Sophos System Protection (Version: 2.6.0.71 - Sophos Limited) Hidden Splashtop Personal (HKLM-x32\...\{E7CF0F14-8C1D-41F3-85ED-579C108262C7}) (Version: 2.6.4.0 - Splashtop Inc.) Splashtop Software Updater (HKLM-x32\...\Splashtop Software Updater) (Version: 1.5.6.15 - Splashtop Inc.) Splashtop Streamer (HKLM-x32\...\{B7C5EA94-B96A-41F5-BE95-25D78B486678}) (Version: 3.1.2.1 - Splashtop Inc.) SpO2 Assistant V1.5 (HKLM-x32\...\SpO2_is1) (Version: - ) Spotify (HKU\S-1-5-21-914517813-2310829996-1314125057-1000\...\Spotify) (Version: 1.0.51.693.g6ea1e7f6 - Spotify AB) Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.4.40 - Safer-Networking Ltd.) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 6.0.1240 - SUPERAntiSpyware.com) TablEdit 2.76 (HKLM-x32\...\TablEdit Demo_is1) (Version: - TablEdit) TeamViewer 11 (HKLM-x32\...\TeamViewer) (Version: 11.0.66695 - TeamViewer) Tixati (HKLM-x32\...\tixati) (Version: - ) VFW_Codec32 (x32 Version: 0.1.160.0 - GoPro, Inc.) Hidden VFW_Codec64 (Version: 0.1.160.0 - GoPro, Inc.) Hidden VLC media player (HKLM-x32\...\VLC media player) (Version: 2.1.5 - VideoLAN) Web Components (HKLM-x32\...\{03B13AF8-9625-478A-AF0E-205337B9415A}_is1) (Version: - ) Windows Driver Package - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\...\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.) Windows Driver Package - Silicon Laboratories (silabenm) Ports (12/10/2012 6.6.1.0) (HKLM\...\D680DEE0F68D64EC53D0C5769879D15D387054CC) (Version: 12/10/2012 6.6.1.0 - Silicon Laboratories) Windows Driver Package - Silicon Labs Software (DSI_SiUSBXp_3_1) USB (02/06/2007 3.1) (HKLM\...\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software) WinRAR 5.10 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.10.0 - win.rar GmbH) Zemana AntiMalware (HKLM-x32\...\{8F0CD7D1-42F3-4195-95CD-833578D45057}_is1) (Version: 2.72.0.388 - Zemana Ltd.) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-914517813-2310829996-1314125057-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Doug\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-914517813-2310829996-1314125057-1000_Classes\CLSID\{0E270DAA-1BE6-48F2-AC49-CB0287D7E810}\InprocServer32 -> %%systemroot%%\system32\shell32.dll => No File CustomCLSID: HKU\S-1-5-21-914517813-2310829996-1314125057-1000_Classes\CLSID\{e8c77137-e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems) CustomCLSID: HKU\S-1-5-21-914517813-2310829996-1314125057-1000_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Doug\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-914517813-2310829996-1314125057-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Doug\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-914517813-2310829996-1314125057-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Doug\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-914517813-2310829996-1314125057-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Doug\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-914517813-2310829996-1314125057-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Doug\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-914517813-2310829996-1314125057-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Doug\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-914517813-2310829996-1314125057-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Doug\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-914517813-2310829996-1314125057-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Doug\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-914517813-2310829996-1314125057-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Doug\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-914517813-2310829996-1314125057-1000_Classes\CLSID\{FB314EE1-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Doug\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-914517813-2310829996-1314125057-1000_Classes\CLSID\{FB314EE2-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Doug\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-914517813-2310829996-1314125057-1000_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\Doug\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll (Dropbox, Inc.) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {0BD17648-D591-430A-BC70-3B647A07D461} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION Task: {0F4E93AD-433E-4B72-B73C-4D8240F46779} - System32\Tasks\AMD Updater => C:\Program Files\AMD\CIM\\Bin64\InstallManagerApp.exe Task: {0F7F6B57-FBFF-4B72-B897-41CC2DBF2051} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express SelfUpdater\ExpressSelfUpdater.exe [2017-03-28] () Task: {11DCE453-0F88-4401-A3B7-723F51CA4279} - \WPD\SqmUpload_S-1-5-21-914517813-2310829996-1314125057-1000 -> No File <==== ATTENTION Task: {1D1E1C6B-BD5C-43A7-9128-97ED695B9601} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-914517813-2310829996-1314125057-1000UA1d23702b0532f82 => C:\Users\Doug\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2016-11-04] (Dropbox, Inc.) Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => %SystemRoot%\System32\AutoWorkplace.exe Task: {35DA0070-62E5-486A-ACCF-207F3722CD18} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2017-05-06] (Microsoft Corporation) Task: {3EC0ABDE-B21D-49A1-BE09-04DFBF60B714} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-04-25] (Adobe Systems Incorporated) Task: {3F6D2D5F-BDDE-4209-82E3-A20B2EAA7854} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION Task: {41377AEC-6B0A-47F2-965A-6B3D1E06AFFE} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION Task: {4558ADD8-3AD1-40D1-B1C1-760CFA703E1F} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION Task: {45748E86-520D-46FB-A4C8-4B6D5FF7E78B} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION Task: {4C1F6131-E422-443D-A342-59F055F9997C} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2017-02-14] (Apple Inc.) Task: {6552E384-4751-47C7-9492-59DD89997C06} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION Task: {70CCB71E-3107-4C2F-A9FE-3203A698D6DD} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2017-05-01] (Microsoft Corporation) Task: {84748F35-AE8B-402B-85AE-04437DD1B451} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION Task: {897C33C2-D6E0-4907-825A-8FF3AB101F8B} - System32\Tasks\[removed] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2016-05-05] (Adobe Systems Incorporated) Task: {8BBF8FE7-983A-425F-8A4E-2791686DEDC2} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-04-19] (Microsoft Corporation) Task: {94389E90-1E44-4068-9A15-73A383FF3C73} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION Task: {99CF5BB1-AC3B-41E7-BA02-6CA2A00CC8D1} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.) Task: {A2A3D97B-0BA0-470C-8011-E8A951997A57} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION Task: {AAF0604C-F28B-4F5F-97E4-2E7B759D4727} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe [2014-06-27] (Safer-Networking Ltd.) Task: {C077CB92-DA91-42AD-8356-F3A88417D0F5} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-04-19] (Microsoft Corporation) Task: {C45E41B8-F04B-46CC-9920-19292BBC764D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.) Task: {D6949378-3C27-4BB7-A9A1-91D3E1C35EA6} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-914517813-2310829996-1314125057-1000Core1d23702b04d04db => C:\Users\Doug\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2016-11-04] (Dropbox, Inc.) Task: {E2DDD228-2E21-4E5E-9DC1-B52131871E37} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION Task: {ED0946B6-AC4F-42E8-A94E-9EA6A8567EFA} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-914517813-2310829996-1314125057-1000Core1d23702b04d04db.job => C:\Users\Doug\AppData\Local\Dropbox\Update\DropboxUpdate.exe Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-914517813-2310829996-1314125057-1000UA1d23702b0532f82.job => C:\Users\Doug\AppData\Local\Dropbox\Update\DropboxUpdate.exe Task: C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task 5c23b192-7463-4c1e-aced-9bf32ad2ee3b.job => C:\Program Files\SUPERAntiSpyware\SASTask.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe Task: C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task bd7ca218-4298-48ba-9137-c9e09f4fdf47.job => C:\Program Files\SUPERAntiSpyware\SASTask.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) ShortcutWithArgument: C:\Users\Doug\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\2X RDP Client for 2X RAS.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=jbefefbcoggageojgcmipnfgjlekmpjp ShortcutWithArgument: C:\Users\Doug\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Play Music.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=fahmaaghhglfmonjliepjlchgpgfmobi ShortcutWithArgument: C:\Users\Doug\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Pocket.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=mjcnijlhddpbdemagnpefmlkjdagkogk ==================== Loaded Modules (Whitelisted) ============== 2016-07-16 04:42 - 2016-07-16 04:42 - 00231424 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll 2017-05-01 21:12 - 2017-03-27 23:22 - 02681200 _____ () C:\WINDOWS\system32\CoreUIComponents.dll 2017-03-16 16:08 - 2017-03-16 16:08 - 01354040 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2016-09-01 18:12 - 2016-09-01 18:12 - 00092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2016-10-19 09:25 - 2016-10-19 09:25 - 00234336 _____ () C:\Program Files\Sophos\Sophos Network Threat Protection\bin\plugins\http.plg 2016-10-19 09:25 - 2016-10-19 09:25 - 00141432 _____ () C:\Program Files\Sophos\Sophos Network Threat Protection\bin\plugins\ip.plg 2016-10-19 09:25 - 2016-10-19 09:25 - 00120080 _____ () C:\Program Files\Sophos\Sophos Network Threat Protection\bin\plugins\ipv6.plg 2016-10-19 09:25 - 2016-10-19 09:25 - 00077432 _____ () C:\Program Files\Sophos\Sophos Network Threat Protection\bin\plugins\portmap.plg 2016-10-19 09:25 - 2016-10-19 09:25 - 00165736 _____ () C:\Program Files\Sophos\Sophos Network Threat Protection\bin\plugins\tcp.plg 2016-10-19 09:25 - 2016-10-19 09:25 - 00149168 _____ () C:\Program Files\Sophos\Sophos Network Threat Protection\bin\plugins\udp.plg 2017-05-01 21:12 - 2017-03-27 23:22 - 02681200 _____ () C:\WINDOWS\SYSTEM32\CoreUIComponents.dll 2016-05-22 19:33 - 2016-05-22 19:33 - 00491184 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll 2017-05-06 19:12 - 2017-05-06 19:12 - 00154480 _____ () C:\Program Files (x86)\Zemana AntiMalware\ZAMShellExt64.dll 2016-09-15 18:47 - 2016-09-06 21:56 - 00134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll 2017-03-14 11:00 - 2017-03-03 23:31 - 00474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll 2017-03-14 11:00 - 2017-03-03 23:30 - 00693248 _____ () C:\Windows\ShellExperiences\MtcUvc.dll 2017-05-01 21:17 - 2017-05-01 21:17 - 00077312 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.14.675.0_x64__kzf8qxf38zg5c\SkypeHost.exe 2017-05-01 21:17 - 2017-05-01 21:17 - 00190464 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.14.675.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll 2017-05-01 21:17 - 2017-05-01 21:17 - 43012096 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.14.675.0_x64__kzf8qxf38zg5c\SkyWrap.dll 2017-05-01 21:17 - 2017-05-01 21:17 - 02451456 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.14.675.0_x64__kzf8qxf38zg5c\skypert.dll 2016-06-30 20:12 - 2016-06-30 20:12 - 00014336 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick.2\qtquick2plugin.dll 2016-06-30 20:12 - 2016-06-30 20:12 - 00739840 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Controls\qtquickcontrolsplugin.dll 2016-06-30 20:12 - 2016-06-30 20:12 - 00014336 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Window.2\windowplugin.dll 2016-06-30 20:12 - 2016-06-30 20:12 - 00071168 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Layouts\qquicklayoutsplugin.dll 2016-06-30 20:12 - 2016-06-30 20:12 - 00011776 _____ () C:\Program Files\AMD\CNext\CNext\libEGL.dll 2016-06-30 20:12 - 2016-06-30 20:12 - 02013696 _____ () C:\Program Files\AMD\CNext\CNext\libGLESv2.dll 2017-03-27 12:20 - 2017-03-27 12:20 - 00092472 _____ () C:\Program Files\iTunes\zlib1.dll 2017-03-27 12:20 - 2017-03-27 12:20 - 01354040 _____ () C:\Program Files\iTunes\libxml2.dll 2017-03-16 17:15 - 2017-03-16 17:15 - 00866224 _____ () C:\Program Files\GoPro\GoPro Desktop App\GoProDesktopSystemTray.exe 2016-12-27 18:28 - 2014-07-16 17:54 - 07593984 _____ () C:\Program Files\PreSonus\AudioBox\AudioBox.exe 2010-08-31 15:19 - 2010-08-31 15:19 - 00131440 _____ () C:\Program Files (x86)\EZ-RC\ez-rc-tray.exe 2016-05-22 19:32 - 2016-05-22 19:32 - 31680176 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe 2016-11-21 18:19 - 2016-11-21 18:19 - 00155016 _____ () C:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe 2017-03-16 17:15 - 2017-03-16 17:15 - 00037808 _____ () C:\Program Files\GoPro\GoPro Desktop App\GoProDeviceDetection.exe 2017-05-02 17:58 - 2017-05-02 17:58 - 01710080 _____ () C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.8126.42377.0_x64__8wekyb3d8bbwe\HxMail.exe 2017-05-02 17:58 - 2017-05-02 17:58 - 13358272 _____ () C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.8126.42377.0_x64__8wekyb3d8bbwe\Office.UI.Xaml.Core.dll 2017-03-14 11:01 - 2017-03-03 23:05 - 01401856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2017-03-16 16:58 - 2017-03-16 16:58 - 07784848 _____ () C:\Program Files (x86)\GoPro\tools\GoPro Studio.exe 2017-03-14 11:01 - 2017-03-03 23:12 - 09760768 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2017-03-14 11:01 - 2017-03-03 23:05 - 00757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll 2017-05-01 21:12 - 2017-03-27 22:07 - 01033216 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll 2017-05-01 21:12 - 2017-03-27 22:08 - 02424320 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll 2017-05-01 21:12 - 2017-03-27 22:11 - 04853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll 2017-02-14 09:42 - 2017-02-14 09:42 - 00326144 _____ () C:\Program Files (x86)\Garmin\Device Interaction Service\GpsImgWrapper.dll 2017-03-28 15:32 - 2017-03-28 15:32 - 00073216 _____ () C:\Program Files (x86)\Garmin\Device Interaction Service\FixBootSector.dll 2017-05-04 10:38 - 2014-05-13 12:04 - 00109400 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl 2017-05-04 10:38 - 2014-05-13 12:04 - 00167768 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl 2017-05-04 10:38 - 2014-05-13 12:04 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl 2017-05-04 10:38 - 2012-08-23 10:38 - 00574840 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll 2017-05-04 10:38 - 2012-04-03 17:06 - 00565640 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\av\BDSmartDB.dll 2016-12-27 18:28 - 2014-04-16 12:22 - 00192512 _____ () C:\Program Files\PreSonus\AudioBox\paeusbaudioapi.dll 2016-06-03 03:36 - 2016-06-03 03:36 - 40523456 _____ () C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\CEF\libcef.dll 2017-05-02 14:19 - 2017-05-01 07:44 - 00870720 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\dropbox_watchdog.dll 2016-05-16 10:21 - 2017-04-12 16:43 - 00035792 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\_multiprocessing.pyd 2016-05-16 10:21 - 2017-04-12 16:43 - 00100296 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\_ctypes.pyd 2016-05-16 10:22 - 2017-04-12 16:43 - 00018888 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\select.pyd 2016-05-16 10:22 - 2017-05-01 07:48 - 00019776 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\tornado.speedups.pyd 2017-05-02 14:19 - 2017-05-01 07:48 - 00020824 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\cryptography.hazmat.bindings._constant_time.pyd 2016-05-16 10:21 - 2017-04-12 16:44 - 00123856 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\_cffi_backend.pyd 2016-05-16 10:22 - 2017-04-12 16:43 - 00694224 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\unicodedata.pyd 2017-05-02 14:19 - 2017-05-01 07:48 - 01729360 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\cryptography.hazmat.bindings._openssl.pyd 2017-05-02 14:19 - 2017-05-01 07:48 - 00020816 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\cryptography.hazmat.bindings._padding.pyd 2017-05-02 14:19 - 2017-04-12 16:43 - 00145864 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\pyexpat.pyd 2017-05-02 14:19 - 2017-04-12 16:44 - 00019408 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\faulthandler.pyd 2017-05-02 14:19 - 2017-04-12 16:43 - 00116688 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\pywintypes27.dll 2016-05-16 10:22 - 2017-04-12 16:46 - 00105928 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\win32api.pyd 2016-08-05 12:36 - 2017-05-01 07:49 - 00022864 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\winffi.crt.compiled._winffi_crt.pyd 2017-05-02 14:19 - 2017-05-01 07:48 - 00060736 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\psutil._psutil_windows.pyd 2017-05-02 14:19 - 2017-05-01 07:48 - 00038712 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\fastpath.pyd 2016-05-16 10:22 - 2017-04-12 16:46 - 00024528 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\win32event.pyd 2017-05-02 14:19 - 2017-04-12 16:43 - 00392656 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\pythoncom27.dll 2017-05-02 14:19 - 2017-04-12 16:46 - 00020936 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\mmapfile.pyd 2016-05-16 10:22 - 2017-04-12 16:46 - 00116176 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\win32security.pyd 2016-05-16 10:22 - 2017-05-01 07:49 - 00392512 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\win32com.shell.shell.pyd 2016-05-16 10:22 - 2017-04-12 16:46 - 00124880 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\win32file.pyd 2016-08-05 12:36 - 2017-05-01 07:49 - 00026456 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\winffi.kernel32.compiled._winffi_kernel32.pyd 2016-05-16 10:22 - 2017-04-12 16:46 - 00024016 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\win32clipboard.pyd 2016-05-16 10:22 - 2017-04-12 16:46 - 00175560 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\win32gui.pyd 2016-05-16 10:22 - 2017-04-12 16:46 - 00030160 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\win32pipe.pyd 2016-05-16 10:22 - 2017-04-12 16:46 - 00043472 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\win32process.pyd 2016-05-16 10:22 - 2017-04-12 16:46 - 00048592 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\win32service.pyd 2016-05-16 10:22 - 2017-04-12 16:46 - 00057808 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\win32evtlog.pyd 2016-05-16 10:22 - 2017-04-12 16:46 - 00024016 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\win32profile.pyd 2017-05-02 14:19 - 2017-05-01 07:48 - 00246608 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\breakpad.client.windows.handler.pyd 2017-05-02 14:19 - 2017-05-01 07:48 - 00027488 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\dropbox.infinite.win.compiled._driverinstallation.pyd 2016-08-05 12:36 - 2017-04-12 16:45 - 00241104 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\_jpegtran.pyd 2017-05-02 14:19 - 2017-05-01 07:48 - 00022336 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\cpuid.compiled._cpuid.pyd 2016-05-16 10:21 - 2017-05-01 07:49 - 00025432 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\winscreenshot.compiled._CaptureScreenshot.pyd 2016-05-16 10:22 - 2017-04-12 16:46 - 00028616 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\win32ts.pyd 2017-05-02 14:19 - 2017-05-01 07:48 - 01826104 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\PyQt5.QtCore.pyd 2016-05-16 10:22 - 2017-04-12 16:44 - 00083912 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\sip.pyd 2017-05-02 14:19 - 2017-05-01 07:48 - 01972024 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\PyQt5.QtGui.pyd 2017-05-02 14:19 - 2017-05-01 07:48 - 03928896 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\PyQt5.QtWidgets.pyd 2017-05-02 14:19 - 2017-05-01 07:48 - 00171336 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\PyQt5.QtWebEngineWidgets.pyd 2017-05-02 14:19 - 2017-05-01 07:48 - 00042816 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\PyQt5.QtWebChannel.pyd 2017-05-02 14:19 - 2017-05-01 07:48 - 00531264 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\PyQt5.QtNetwork.pyd 2017-05-02 14:19 - 2017-05-01 07:48 - 00133432 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\PyQt5.QtWebKit.pyd 2017-05-02 14:19 - 2017-05-01 07:48 - 00224064 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\PyQt5.QtWebKitWidgets.pyd 2017-05-02 14:19 - 2017-05-01 07:48 - 00207680 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\PyQt5.QtPrintSupport.pyd 2016-05-16 10:22 - 2017-04-12 16:46 - 00060880 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\win32print.pyd 2017-02-27 15:30 - 2017-05-01 07:49 - 00054608 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\winrpcserver.compiled._RPCServer.pyd 2017-01-23 11:52 - 2017-05-01 07:49 - 00022864 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\winffi.user32.compiled._winffi_user32.pyd 2016-05-16 10:22 - 2017-05-01 07:49 - 00069968 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\windisplaytoast.compiled._DisplayToast.pyd 2017-01-23 11:52 - 2017-05-01 07:49 - 00022872 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\winffi.iphlpapi.compiled._winffi_iphlpapi.pyd 2017-01-23 11:52 - 2017-05-01 07:49 - 00021848 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\winffi.winerror.compiled._winffi_winerror.pyd 2017-01-23 11:52 - 2017-05-01 07:49 - 00022872 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\winffi.wininet.compiled._winffi_wininet.pyd 2016-05-16 10:21 - 2017-04-12 16:46 - 00349128 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\winxpgui.pyd 2017-05-02 14:19 - 2017-05-01 07:48 - 00103232 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\PyQt5.QtWinExtras.pyd 2016-05-16 10:21 - 2017-05-01 07:49 - 00023896 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\winverifysignature.compiled._VerifySignature.pyd 2017-05-02 14:19 - 2017-05-01 07:48 - 00025936 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\librsyncffi.compiled._librsyncffi.pyd 2017-05-02 14:19 - 2017-04-12 16:37 - 00036296 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\librsync.dll 2017-05-02 14:19 - 2017-05-01 07:48 - 00033112 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\enterprise_data.compiled._enterprise_data.pyd 2017-05-02 14:19 - 2017-03-21 18:42 - 00293392 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\EnterpriseDataAdapter.dll 2017-05-02 14:19 - 2017-05-01 07:48 - 00084288 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\dropbox_sqlite_ext.DLL 2016-07-12 14:32 - 2017-05-01 07:49 - 00030536 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\wind3d11.compiled._wind3d11.pyd 2017-05-02 14:19 - 2017-04-12 16:50 - 00017864 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\libEGL.dll 2017-05-02 14:19 - 2017-04-12 16:50 - 01631184 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\libGLESv2.dll 2017-05-02 14:19 - 2017-05-01 07:48 - 00357688 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\PyQt5.QtQml.pyd 2016-08-05 12:36 - 2017-05-01 07:49 - 00026456 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\winffi.winhttp.compiled._winffi_winhttp.pyd 2017-05-02 14:19 - 2017-05-01 07:48 - 00546104 _____ () C:\Users\Doug\AppData\Roaming\Dropbox\bin\PyQt5.QtQuick.pyd 2016-06-08 00:10 - 2016-06-08 00:10 - 00118272 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\node_modules\fs-ext\build\Release\fs-ext.node 2016-06-08 00:10 - 2016-06-08 00:10 - 00205824 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\node_modules\node-vulcanjs\build\Release\VulcanJS.node 2016-06-08 00:10 - 2016-06-08 00:10 - 00117248 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\node_modules\ref\build\Release\binding.node 2016-06-08 00:10 - 2016-06-08 00:10 - 00125440 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\node_modules\ffi\build\Release\ffi_bindings.node 2016-06-08 00:41 - 2016-06-08 00:41 - 00098496 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\node_modules\node-ProxyResolver\build\Release\ProxyResolverWin.dll 2016-06-08 00:10 - 2016-06-08 00:10 - 00166400 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\node_modules\idle-gc\build\Release\idle-gc.node 2017-03-16 16:58 - 2017-03-16 16:58 - 04420096 _____ () C:\Program Files (x86)\GoPro\tools\CFMediaPlayerLibG2ManagedDLL.dll 2017-03-16 16:58 - 2017-03-16 16:58 - 00112142 _____ () C:\Program Files (x86)\GoPro\tools\libgcc_s_dw2-1.dll 2017-03-16 16:58 - 2017-03-16 16:58 - 04163072 _____ () C:\Program Files (x86)\GoPro\tools\KronosGoPro.dll 2017-03-16 16:58 - 2017-03-16 16:58 - 01856000 _____ () C:\Program Files (x86)\GoPro\tools\gopro-lib-win-analytics_vs2008.dll 2017-03-16 16:58 - 2017-03-16 16:58 - 00073728 _____ () C:\Program Files (x86)\GoPro\tools\FirmwareUpdaterLib.dll 2017-03-16 16:58 - 2017-03-16 16:58 - 00068096 _____ () C:\Program Files (x86)\GoPro\tools\PreviewPlayer.dll 2016-02-21 06:25 - 2017-05-01 20:56 - 08930496 _____ () C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\1033\GrooveIntlResource.dll 2017-03-16 16:58 - 2017-03-16 16:58 - 00075776 _____ () C:\Program Files (x86)\GoPro\Tools\QTDeMux.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SAVService => ""="service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SAVService => ""="service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SntpService => ""="service" ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) IE trusted site: HKU\S-1-5-21-914517813-2310829996-1314125057-1000\...\ralphandersen.com -> hxxps://mail.ralphandersen.com ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2013-08-22 06:25 - 2015-12-04 13:41 - 00000824 _____ C:\WINDOWS\system32\Drivers\etc\hosts ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-914517813-2310829996-1314125057-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Doug\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\img4.jpg DNS Servers: 192.168.10.254 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{76E657DE-B186-43BC-A37B-71638A0AF927}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe FirewallRules: [{0F16CCEB-816B-460D-AACB-749A75CE3E05}] => (Allow) C:\Users\Doug\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [{27EEACCF-1A0F-40E1-B363-AE66E1635B9D}] => (Allow) C:\Users\Doug\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [UDP Query User{8B97CFB3-3817-48A2-A97B-96BF6CF12978}C:\program files\tixati\tixati.exe] => (Allow) C:\program files\tixati\tixati.exe FirewallRules: [TCP Query User{05461ADA-F65B-4D48-892D-5CB4A798B41C}C:\program files\tixati\tixati.exe] => (Allow) C:\program files\tixati\tixati.exe FirewallRules: [{940A5C1A-8B1D-411B-8E13-4FB4061A063A}] => (Allow) E:\Program Files (x86)\Steam\SteamApps\common\Rocksmith2014\Rocksmith2014.exe FirewallRules: [{8C8F7D88-1A61-4D78-9346-F8A47A6DF1D7}] => (Allow) E:\Program Files (x86)\Steam\SteamApps\common\Rocksmith2014\Rocksmith2014.exe FirewallRules: [UDP Query User{6A2E7FFA-2FFA-400C-BF62-39F461915695}C:\users\doug\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\doug\appdata\roaming\spotify\spotify.exe FirewallRules: [TCP Query User{B8465156-E08B-4403-98C4-EB2C54AA31A6}C:\users\doug\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\doug\appdata\roaming\spotify\spotify.exe FirewallRules: [{D0E78306-FB5D-4FA0-AE46-5CC730C876DF}] => (Allow) E:\Program Files (x86)\Steam\SteamApps\common\Sniper Elite 3\Launcher\Sniper3Launcher.exe FirewallRules: [{3592F6ED-403F-47CA-B7F0-FEBAB922EED1}] => (Allow) E:\Program Files (x86)\Steam\SteamApps\common\Sniper Elite 3\Launcher\Sniper3Launcher.exe FirewallRules: [{DBF226CA-F045-4B0E-9A48-6E05C1D884AD}] => (Allow) E:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{7CD3ED88-85B0-4647-9ECB-2FC224D724CE}] => (Allow) E:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{DBD4A3AD-4CD3-4318-BD3E-257879106B51}] => (Allow) E:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{F0B98ABA-C6DC-49A0-B6C5-930DF218E010}] => (Allow) E:\Program Files (x86)\Steam\Steam.exe FirewallRules: [UDP Query User{F893BCD7-9D91-4BC1-84F4-E07695B3A43A}C:\users\doug\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\doug\appdata\roaming\spotify\spotify.exe FirewallRules: [TCP Query User{CAB9D14E-C898-45FD-91C2-19F84474843C}C:\users\doug\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\doug\appdata\roaming\spotify\spotify.exe FirewallRules: [UDP Query User{7D1339F3-3887-49A0-BE41-F1DF1147987D}C:\program files\tixati\tixati.exe] => (Allow) C:\program files\tixati\tixati.exe FirewallRules: [TCP Query User{7B78B6AC-6F81-43E9-BC40-FB823FC48364}C:\program files\tixati\tixati.exe] => (Allow) C:\program files\tixati\tixati.exe FirewallRules: [{35E1502A-03DC-4BA3-848C-59B964EE47F1}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{8997AE9E-68DC-4BB1-BC67-D69180CC105D}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{14DF095E-B6EA-49CD-B3BF-FD6AD7DD50FB}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{5CEE578B-377D-4654-B83C-10729539C456}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{AF866CE7-5E7E-4046-88C9-3C25F6A7C015}] => (Allow) E:\Program Files (x86)\Applian Technologies\Replay Music 7\jrmp.exe FirewallRules: [{61561090-E7B2-4B04-88F6-516784108C72}] => (Allow) E:\Program Files (x86)\Applian Technologies\Replay Music 7\jrmp.exe FirewallRules: [{AE750E3F-721D-4F9C-8305-C748F49C91B1}] => (Allow) C:\Users\Doug\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe FirewallRules: [TCP Query User{EF690174-9C18-4DC7-8831-54FF2801FD5D}C:\users\doug\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\doug\appdata\roaming\dropbox\bin\dropbox.exe FirewallRules: [UDP Query User{F22B0228-774A-4AEA-A121-1254AC04FCE5}C:\users\doug\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\doug\appdata\roaming\dropbox\bin\dropbox.exe FirewallRules: [{FD577FA6-4EB2-4B41-8CD4-379D303D4C4B}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{E310772F-4F8D-43A5-BF84-32EB54604E85}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{3350347E-E00D-40AF-8B80-9DBD9DFDFA2B}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{4C06075E-F0F2-4DE4-BDB1-382889A82566}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{827995E9-054D-45D0-B62A-405889CFDE30}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe FirewallRules: [{8A6F1CA1-9F00-4E30-AB24-9E289CC58D5A}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe FirewallRules: [{B3747F8E-970B-436D-855B-6257C01B9944}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe FirewallRules: [{33BCFA64-FC22-41C9-9AB9-87A0FC2E47B4}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe FirewallRules: [{2C9EDAFF-643A-4916-8A26-689F72FDCD99}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{51043D9E-52D7-489F-B44E-5956BC7897C0}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{E3C0BA2D-F699-425A-AFB0-12EE4E355849}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{2FD79B13-EF48-487E-8456-8379C909DC0A}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{37EC3A29-C63A-4FDF-AD28-B12CADBD948E}] => (Allow) C:\Program Files (x86)\Applian Technologies\Replay Music 7\jrmp.exe FirewallRules: [{2FC59671-29F4-407B-B85A-F43E8F00EC05}] => (Allow) C:\Program Files (x86)\Applian Technologies\Replay Music 7\jrmp.exe FirewallRules: [{6F7636C1-7670-4F9C-A992-FD20F3F0C427}] => (Allow) C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRFeature.exe FirewallRules: [{1186C2BD-B918-4C63-8EAC-B47D77F2ADEB}] => (Allow) C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\DataProxy.exe FirewallRules: [{F1737AC6-E251-476E-A790-AD7DCF33B965}] => (Allow) C:\Program Files\PreSonus\Studio One 3\Studio One.exe FirewallRules: [TCP Query User{795471A4-5719-4ECE-BF91-7A6EACA1DD24}C:\program files\presonus\audiobox\audiobox.exe] => (Allow) C:\program files\presonus\audiobox\audiobox.exe FirewallRules: [UDP Query User{184F66A1-4FAD-47A6-A8CD-11DA0FF82003}C:\program files\presonus\audiobox\audiobox.exe] => (Allow) C:\program files\presonus\audiobox\audiobox.exe FirewallRules: [{B660A4B8-3F28-4710-A975-84E7985B98D9}] => (Allow) C:\Program Files\Plex\Plex Media Player\PlexMediaPlayer.exe FirewallRules: [{63DF471B-00E9-40E0-A09C-EA8DB0F759C9}] => (Allow) C:\Program Files\Plex\Plex Media Player\PMPHelper.exe FirewallRules: [{739A5E87-8689-467E-A4A5-76E515214B2D}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{DD9798B1-BC58-4A20-B722-0F51CD299BF5}] => (Allow) C:\Program Files\iTunes\iTunes.exe FirewallRules: [{04E91ACA-D955-48CF-8104-4E20575EB245}] => (Allow) C:\Program Files\GoPro\GoPro Desktop App\GoPro Quik.exe FirewallRules: [{A11E19B6-4E4B-4629-B7C0-4327DD64CF68}] => (Allow) C:\Program Files\GoPro\GoPro Desktop App\GoProMsgBus.exe FirewallRules: [{7B6F3BAB-2A11-4E2A-941B-1A7FAA0D9084}] => (Allow) C:\Program Files\GoPro\GoPro Desktop App\GoProIDService.exe FirewallRules: [{1E8C4E03-C62A-4FB3-B3F2-93BFB4F8985B}] => (Allow) C:\Program Files\GoPro\GoPro Desktop App\GoProLauncher.exe FirewallRules: [{52F0BE05-BD5E-4B4D-B58E-95AA8C381F9C}] => (Allow) C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRManager.exe FirewallRules: [{AF85149D-F5B0-4D84-89AE-5FFC83CC4C8D}] => (Allow) C:\Program Files (x86)\Applian Technologies\Replay Music 7\jrmp.exe FirewallRules: [{C7AF88E4-D90B-47DA-ACEA-ACAF19A69277}] => (Allow) C:\Program Files (x86)\Applian Technologies\Replay Music 7\jrmp.exe DomainProfile\AuthorizedApplications: [C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe] => Enabled:Logitech Harmony Remote Software 7 StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe] => Enabled:Logitech Harmony Remote Software 7 StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe] => Enabled:Spybot - Search & Destroy tray access StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe] => Enabled:Spybot-S&D 2 Scanner Service StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe] => Enabled:Spybot-S&D 2 Updater StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe] => Enabled:Spybot-S&D 2 Background update service ==================== Restore Points ========================= 05-05-2017 06:27:02 Restore Operation 06-05-2017 07:00:25 Installed Macrium Reflect Server Edition 06-05-2017 19:47:50 Malwarebytes Anti-Rootkit Restore Point 06-05-2017 22:34:20 Restore Operation ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (05/07/2017 05:46:56 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: IEXPLORE.EXE, version: 11.0.14393.953, time stamp: 0x58ba5cce Faulting module name: MSHTML.dll, version: 11.0.14393.1066, time stamp: 0x58d9f36e Exception code: 0xc0000005 Fault offset: 0x0054b75a Faulting process id: 0x36b0 Faulting application start time: 0x01d2c7947794fe0e Faulting application path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE Faulting module path: C:\WINDOWS\SYSTEM32\MSHTML.dll Report Id: c7007263-847d-4aa5-b340-937b4af53926 Faulting package full name: Faulting package-relative application ID: Error: (05/07/2017 02:37:29 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Activation context generation failed for "c:\program files (x86)\adobe\adobe creative cloud\utils\Creative Cloud Uninstaller.exe".Error in manifest or policy file "" on line . A component version required by the application conflicts with another component version already active. Conflicting components are:. Component 1: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171.manifest. Component 2: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b.manifest. Error: (05/07/2017 08:07:44 AM) (Source: Sophos Management Communications System) (EventID: 8001) (User: ) Description: The Sophos Management Communications System client service has received an HTTP status 503 from the server. This might indicate that action is necessary. Error: (05/07/2017 03:56:46 AM) (Source: SideBySide) (EventID: 78) (User: ) Description: Activation context generation failed for "c:\program files (x86)\adobe\adobe creative cloud\utils\Creative Cloud Uninstaller.exe".Error in manifest or policy file "" on line . A component version required by the application conflicts with another component version already active. Conflicting components are:. Component 1: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171.manifest. Component 2: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b.manifest. Error: (05/07/2017 02:00:32 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: esu.exe, version: 1.0.0.0, time stamp: 0x58dac8d5 Faulting module name: KERNELBASE.dll, version: 10.0.14393.1066, time stamp: 0x58d9f07f Exception code: 0xe0434352 Fault offset: 0x000da932 Faulting process id: 0x1a04 Faulting application start time: 0x01d2c71061534924 Faulting application path: C:\Program Files (x86)\Garmin\Express SelfUpdater\esu.exe Faulting module path: C:\WINDOWS\System32\KERNELBASE.dll Report Id: 51e90a84-c0ea-44cc-afb5-15ae11c2798a Faulting package full name: Faulting package-relative application ID: Error: (05/07/2017 02:00:32 AM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Application: esu.exe Framework Version: v4.0.30319 Description: The process was terminated due to an unhandled exception. Exception Info: System.IO.FileNotFoundException at Garmin.Omt.Service.Shared.Overrides+d__61.MoveNext() at System.Runtime.CompilerServices.AsyncTaskMethodBuilder.Start[[Garmin.Omt.Service.Shared.Overrides+d__61, ExpressSelfUpdater, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null]](d__61 ByRef) at Garmin.Omt.Service.Shared.Overrides.UpdateDatacenterOverridesAsync(Boolean) at Garmin.Omt.Service.Shared.Overrides..cctor() Exception Info: System.TypeInitializationException at Garmin.Omt.Service.Shared.Overrides.get_OmtBaseUrl() at Garmin.Omt.Express.SelfUpdater.Program.RealMain() at Garmin.Omt.Express.SelfUpdater.Program.Main(System.String[]) Error: (05/06/2017 10:39:14 PM) (Source: Microsoft-Windows-EFS) (EventID: 4401) (User: DOUGLAS-PC) Description: 7.488: EFS service failed to provision a user for EDP. Error code: 0x80070005. Error: (05/06/2017 10:36:39 PM) (Source: System Restore) (EventID: 8210) (User: ) Description: An unspecified error occurred during System Restore: (Windows Update). Additional information: 0x8007045b. Error: (05/06/2017 10:34:21 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol. System Error: Access is denied. . Error: (05/06/2017 07:48:53 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Local Hostname Douglas-PC.local already in use; will try Douglas-PC-2.local instead System errors: ============= Error: (05/07/2017 05:56:53 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The dmwappushsvc service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. Error: (05/07/2017 05:56:53 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the dmwappushservice service. Error: (05/07/2017 05:56:23 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The Network Setup Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. Error: (05/07/2017 05:56:23 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the NetSetupSvc service. Error: (05/07/2017 05:55:53 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ShellHWDetection service. Error: (05/07/2017 05:55:23 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the RasMan service. Error: (05/06/2017 10:53:28 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The ZAM Controller Service service terminated unexpectedly. It has done this 1 time(s). Error: (05/06/2017 10:38:48 PM) (Source: DCOM) (EventID: 10016) (User: DOUGLAS-PC) Description: The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {C2F03A33-21F5-47FA-B4BB-156362A2F239} and APPID {316CDED5-E4AE-4B15-9113-7055D84DCC97} to the user Douglas-PC\Doug SID (S-1-5-21-914517813-2310829996-1314125057-1000) from address LocalHost (Using LRPC) running in the application container Microsoft.Windows.Cortana_1.7.0.14393_neutral_neutral_cw5n1h2txyewy SID (S-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742). This security permission can be modified using the Component Services administrative tool. Error: (05/06/2017 10:38:47 PM) (Source: DCOM) (EventID: 10016) (User: DOUGLAS-PC) Description: The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {C2F03A33-21F5-47FA-B4BB-156362A2F239} and APPID {316CDED5-E4AE-4B15-9113-7055D84DCC97} to the user Douglas-PC\Doug SID (S-1-5-21-914517813-2310829996-1314125057-1000) from address LocalHost (Using LRPC) running in the application container Microsoft.Windows.Cortana_1.7.0.14393_neutral_neutral_cw5n1h2txyewy SID (S-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742). This security permission can be modified using the Component Services administrative tool. Error: (05/06/2017 10:38:47 PM) (Source: DCOM) (EventID: 10016) (User: DOUGLAS-PC) Description: The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {C2F03A33-21F5-47FA-B4BB-156362A2F239} and APPID {316CDED5-E4AE-4B15-9113-7055D84DCC97} to the user Douglas-PC\Doug SID (S-1-5-21-914517813-2310829996-1314125057-1000) from address LocalHost (Using LRPC) running in the application container Microsoft.Windows.Cortana_1.7.0.14393_neutral_neutral_cw5n1h2txyewy SID (S-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742). This security permission can be modified using the Component Services administrative tool. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i5-4690 CPU @ 3.50GHz Percentage of memory in use: 32% Total physical RAM: 16334.96 MB Available physical RAM: 11045.52 MB Total Virtual: 18254.96 MB Available Virtual: 13152.75 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:237.94 GB) (Free:137.75 GB) NTFS Drive d: (KRD10) (CDROM) (Total:0.3 GB) (Free:0 GB) CDFS Drive e: () (Fixed) (Total:1397.26 GB) (Free:488.25 GB) NTFS ==>[system with boot components (obtained from drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 0545224B) Partition 1: (Active) - (Size=1397.3 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 238.5 GB) (Disk ID: DF2E2BAE) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=237.9 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=450 MB) - (Type=27) ==================== End of Addition.txt ============================