Additional scan result of Farbar Recovery Scan Tool (x64) Version: 31-07-2017 Ran by [removed] (03-08-2017 10:15:39) Running from C:\Users\[removed]\Downloads Windows 10 Home Version 1703 (X64) (2017-07-04 16:21:25) Boot Mode: Safe Mode (with Networking) ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-4044022209-2194366084-123958388-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-4044022209-2194366084-123958388-503 - Limited - Disabled) Guest (S-1-5-21-4044022209-2194366084-123958388-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-4044022209-2194366084-123958388-1003 - Limited - Enabled) Sylvia (S-1-5-21-4044022209-2194366084-123958388-1000 - Administrator - Enabled) => C:\Users\Sylvia Work (S-1-5-21-4044022209-2194366084-123958388-1004 - Administrator - Enabled) => C:\Users\Work ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: Bitdefender Antivirus (Disabled - Up to date) {3FB17364-4FCC-0FA7-6BBF-973897395371} AS: Bitdefender Antispyware (Disabled - Up to date) {84D09280-69F6-0029-510F-AC4AECBE19CC} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: Bitdefender Firewall (Disabled) {078AF241-05A3-0EFF-40E0-3E0D69EA140A} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 7-Zip 15.14 (x64) (HKLM\...\7-Zip) (Version: 15.14 - Igor Pavlov) A.I.type (HKLM-x32\...\{CA708BFE-EE7F-4B9D-88B5-AFA091047BEC}) (Version: 0.8 - A.I.type) AC-3 ACM Codec x64 2.1 (HKLM\...\AC3ACM) (Version: 2.1 - fccHandler) Acrobat.com (HKLM-x32\...\{287ECFA4-719A-2143-A09B-D6A12DE54E40}) (Version: 1.6.65 - Adobe Systems Incorporated) Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.010.20060 - Adobe Systems Incorporated) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 21.0.0.176 - Adobe Systems Incorporated) Adobe Flash Player 25 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 25.0.0.148 - Adobe Systems Incorporated) Adobe Photoshop CS2 (HKLM-x32\...\Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0409-1E257A25E34D}) (Version: 9.0 - Adobe Systems, Inc.) Amazon Cloud Drive (HKU\S-1-5-21-4044022209-2194366084-123958388-1000\...\Amazon Cloud Drive) (Version: 2.5.1.38 - Amazon Digital Services, LLC.) Amazon Kindle (HKU\S-1-5-21-4044022209-2194366084-123958388-1000\...\Amazon Kindle) (Version: - Amazon) Amazon Music (HKU\S-1-5-21-4044022209-2194366084-123958388-1000\...\Amazon Amazon Music) (Version: 5.6.1.1094 - Amazon Services LLC) Apple Application Support (32-bit) (HKLM-x32\...\{AFA1153A-F547-409B-B837-3A0D6C5A3FEC}) (Version: 3.1.3 - Apple Inc.) Apple Application Support (64-bit) (HKLM\...\{0DF7096B-715A-4233-8633-C7A16ED6D616}) (Version: 3.1.2 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{C4123106-B685-48E6-B9BD-E4F911841EB4}) (Version: 8.1.1.3 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) AVSDK5 (HKLM\...\{D5A6E342-907C-4CEF-96CC-FC2F4990DC9C}) (Version: 5.4.30 - CYREN Inc.) Hidden Bitdefender Agent (HKLM\...\Bitdefender Agent) (Version: 21.0.24.36 - Bitdefender) Bitdefender Device Management (HKLM\...\Bitdefender Device Management) (Version: 21.0.23.1101 - Bitdefender) Bitdefender Total Security 2017 (HKLM\...\Bitdefender) (Version: 21.0.24.62 - Bitdefender) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Canon MP Navigator EX 1.0 (HKLM-x32\...\MP Navigator EX 1.0) (Version: - ) Canon MX310 series User Registration (HKLM-x32\...\Canon MX310 series User Registration) (Version: - ) Canon My Printer (HKLM\...\CanonMyPrinter) (Version: - ) Canon Utilities Easy-PhotoPrint EX (HKLM-x32\...\Easy-PhotoPrint EX) (Version: - ) Canon Utilities Solution Menu (HKLM-x32\...\CanonSolutionMenu) (Version: - ) CCleaner (HKLM\...\CCleaner) (Version: 5.32 - Piriform) Compatibility Pack for the 2007 Office system (HKLM-x32\...\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) CopyTrans Control Center Uninstall Only (HKU\S-1-5-21-4044022209-2194366084-123958388-1000\...\CopyTrans Suite) (Version: 4.004 - WindSolutions) CurationSoft (HKLM-x32\...\{B14211FD-2F7B-276A-BDE0-AD3986706EDE}) (Version: 3.94 - UNKNOWN) Hidden CurationSoft (HKLM-x32\...\CurationSoft) (Version: 3.94 - UNKNOWN) D3DX10 (HKLM-x32\...\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden Dropbox (HKLM-x32\...\Dropbox) (Version: 31.4.24 - Dropbox, Inc.) Dropbox Update Helper (HKLM-x32\...\{099218A5-A723-43DC-8DB5-6173656A1E94}) (Version: 1.3.59.1 - Dropbox, Inc.) Hidden EaseUS Todo Backup Free 10.5 (HKLM-x32\...\EaseUS Todo Backup_is1) (Version: 10.5 - CHENGDU YIWO Tech Development Co., Ltd) ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - ) FlashBack Express 5 (HKLM-x32\...\FlashBack Express 5) (Version: 5.22.0.4178 - Blueberry) Freemake Audio Converter version 1.1.4 (HKLM-x32\...\Freemake Audio Converter_is1) (Version: 1.1.4 - Ellora Assets Corporation) Freemake Video Converter version 4.1.9 (HKLM-x32\...\Freemake Video Converter_is1) (Version: 4.1.9 - Ellora Assets Corporation) Freemake Video Downloader (HKLM-x32\...\Freemake Video Downloader_is1) (Version: 3.8.0 - Ellora Assets Corporation) Freemake YouTube To MP3 Boom (HKLM-x32\...\Freemake YouTube To MP3 Boom_is1) (Version: 1.0.4 - Ellora Assets Corporation) Gateway Recovery Management (HKLM-x32\...\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 5.00.3002 - Gateway Incorporated) Gateway Registration (HKLM-x32\...\Gateway Registration) (Version: 1.03.3003 - Gateway Incorporated) Gateway ScreenSaver (HKLM-x32\...\Gateway Screensaver) (Version: 1.1.0225.2011 - Gateway Incorporated) GIMP 2.8.14 (HKLM\...\GIMP-2_is1) (Version: 2.8.14 - The GIMP Team) GML Poster Pro version 1.8 (HKLM-x32\...\{7D03BD6D-4A6C-4073-9595-925ACE1C85FD}_is1) (Version: 1.8 - Global MoneyLine) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 59.0.3071.115 - Google Inc.) Google Drive (HKLM-x32\...\{A1238426-ECDF-4639-BE2F-8D12A97AE23C}) (Version: 2.34.5075.1619 - Google, Inc.) Google Photos Backup (HKU\S-1-5-21-4044022209-2194366084-123958388-1000\...\Google Photos Backup) (Version: 1.1.2.13 - Google, Inc.) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.5 - Google Inc.) Hidden GoToMeeting 5.1.0.880 (HKU\S-1-5-21-4044022209-2194366084-123958388-1000\...\GoToMeeting) (Version: 5.1.0.880 - CitrixOnline) Grammarly (HKU\S-1-5-21-4044022209-2194366084-123958388-1000\...\GrammarlyForWindows) (Version: 1.5.25 - Grammarly) Hotkey Utility (HKLM-x32\...\Hotkey Utility) (Version: 2.05.3014 - Gateway Incorporated) Identity Card (HKLM-x32\...\Identity Card) (Version: 1.00.3006 - Gateway Incorporated) InPixio Photo Clip Demo (HKU\S-1-5-21-4044022209-2194366084-123958388-1000\...\{2FFE93F0-BB72-4E52-8761-354D1AAA9387}) (Version: 6.00 - Avanquest) Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation) Intel(R) Graphics Media Accelerator Driver (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2869 - Intel Corporation) IObit Uninstaller (HKLM-x32\...\IObitUninstall) (Version: 5.2.6.101 - IObit) iTunes (HKLM\...\{5D239A92-31A4-4FCA-967D-F9EA8E1FDF6A}) (Version: 12.1.2.27 - Apple Inc.) Jarte (HKLM-x32\...\Jarte_is1) (Version: 6.1 - Carolina Road Software L.L.C.) Java 8 Update 77 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218077F0}) (Version: 8.0.770.3 - Oracle Corporation) Junk Mail filter update (HKLM-x32\...\{0BE9E708-5DC0-4963-9CFD-0AA519090E79}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden KeyScrambler (HKLM-x32\...\KeyScrambler) (Version: 2.9.1.0 - QFX Software Corporation) Keyword Blaze (HKLM-x32\...\{680C5A18-6B9A-1BA8-390D-C16B6DA54568}) (Version: 1.8.5 - UNKNOWN) Hidden Keyword Blaze (HKLM-x32\...\com.blueprintcentral.keywordblaze) (Version: 1.8.5 - UNKNOWN) K-Lite Mega Codec Pack 8.7.0 (HKLM-x32\...\KLiteCodecPack_is1) (Version: 8.7.0 - ) Lightshot-5.4.0.10 (HKLM-x32\...\{30A5B3C9-2084-4063-A32A-628A98DE512B}_is1) (Version: 5.4.0.10 - Skillbrains) Logitech Scroll App 3.0 (HKLM\...\Sn1) (Version: 3.00.31 - Logitech) Malwarebytes Anti-Exploit version 1.8.1.2572 (HKLM\...\Malwarebytes Anti-Exploit_is1) (Version: 1.8.1.2572 - Malwarebytes) Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes) MEGAsync (HKLM-x32\...\MEGAsync) (Version: - Mega Limited) Messenger for Desktop (HKU\S-1-5-21-4044022209-2194366084-123958388-1000\...\messengerfordesktop) (Version: 2.0.9 - MessengerForDesktop.com) Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Click-to-Run 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Converter Pack (HKLM-x32\...\{6EECB283-E65F-40EF-86D3-D51BF02A8D43}) (Version: 11.0.0.0 - Microsoft Corporation - Office Resource Kit Group) Microsoft Office Live Meeting 2007 (HKLM-x32\...\{E30E7561-A466-4393-B8BF-FD93E733EF3C}) (Version: 8.0.6362.202 - Microsoft Corporation) Microsoft Office Starter 2010 - English (HKLM-x32\...\{90140011-0066-0409-0000-0000000FF1CE}) (Version: 14.0.5131.5000 - Microsoft Corporation) Microsoft Office Word Viewer 2003 (HKLM-x32\...\{90850409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-4044022209-2194366084-123958388-1000\...\OneDriveSetup.exe) (Version: 17.3.6943.0625 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Mozilla Firefox 54.0.1 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 54.0.1 (x86 en-US)) (Version: 54.0.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 54.0.1.6388 - Mozilla) MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) Multi PDF Converter version 5.3 (HKLM-x32\...\{43CF388F-EB3B-4AF2-9A3C-0E5A2013F598}_is1) (Version: 5.3 - Essex Software, LLC) Music Manager (HKU\S-1-5-21-4044022209-2194366084-123958388-1000\...\MusicManager) (Version: - Google, Inc.) Nero DiscSpeed 10 (HKLM-x32\...\{34490F4E-48D0-492E-8249-B48BECF0537C}) (Version: 6.2.10500.2.100 - Nero AG) Nero Express 10 (HKLM-x32\...\{70550193-1C22-445C-8FA4-564E155DB1A7}) (Version: 10.2.12000.21.100 - Nero AG) Nero Multimedia Suite 10 Essentials (HKLM-x32\...\{62BF4BD3-B1F6-4FA2-8388-CC0647ACBF86}) (Version: 10.5.10300 - Nero AG) Nero StartSmart 10 (HKLM-x32\...\{F61D489E-6C44-49AC-AD02-7DA8ACA73A65}) (Version: 10.2.11600.14.100 - Nero AG) Nero Update (HKLM-x32\...\{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}) (Version: 1.0.0018 - Nero AG) Ninja Blaster (HKLM-x32\...\{7789DDA6-C790-4B7E-9E49-732236536333}) (Version: 1.0.0 - Ninja Blaster) OpenOffice.org 3.3 (HKLM-x32\...\{3E171899-0175-47CC-84C4-562ACDD4C021}) (Version: 3.3.9567 - OpenOffice.org) PeaZip 6.0.0 (HKLM-x32\...\{5A2BC38A-406C-4A5B-BF45-6991F9A05325}_is1) (Version: 6.0.0 - Giorgio Tani) PeaZip 6.0.3 (WIN64) (HKLM\...\{5A2BC38A-406C-4A5B-BF45-6991F9A05325}_is1) (Version: 6.0.3 - Giorgio Tani) Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9.141.259 - Google, Inc.) PIXMA Extended Survey Program (HKLM-x32\...\CANONIJPLM100) (Version: - ) Presto! PageManager 7.15.16 (HKLM-x32\...\{D2D6B9EB-C6DC-4DAA-B4DE-BB7D9735E7DA}) (Version: 7.15.16 - NewSoft Technology Corporation) Pure Networks Platform (HKLM-x32\...\{FBDBC490-089D-4476-BF72-1F7A6368200A}) (Version: 11.1.9051.0 - Pure Networks) Hidden Pushbullet version 338 (HKLM-x32\...\{7578F204-49E7-4830-B051-14C23F408BFE}_is1) (Version: 338 - Pushbullet Inc) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7535 - Realtek Semiconductor Corp.) ScanSoft OmniPage SE 4 (HKLM-x32\...\{B2F3DBD9-A9D2-4838-B45D-C917DAB32BC3}) (Version: 15.2.0020 - Nuance Communications, Inc.) Spotify (HKU\S-1-5-21-4044022209-2194366084-123958388-1000\...\Spotify) (Version: 1.0.25.127.g58007b4c - Spotify AB) SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 6.0.1126 - SUPERAntiSpyware.com) System Mechanic (HKLM-x32\...\{BF979795-8FC8-4FB5-AC26-CC753CA140BE}) (Version: 17.0.1.11 - iolo technologies, LLC) Hidden System Mechanic (HKLM-x32\...\InstallShield_{BF979795-8FC8-4FB5-AC26-CC753CA140BE}) (Version: 17.0.1.11 - iolo technologies, LLC) System Mechanic (HKLM-x32\...\InstallShield_{DD0DFA41-5139-45D0-986C-3C1A5C648CAA}) (Version: 16.5.3.1 - iolo technologies, LLC) System Mechanic Scan (HKLM\...\{1E5E7177-5156-4541-B8D5-B0C7E9064329}) (Version: 16.5.2 - ) Hidden System Requirements Lab for Intel (HKLM-x32\...\{04C4B49D-45D9-4A28-9ED1-B45CBD99B8C7}) (Version: 4.5.24.0 - Husdawg, LLC) Tweaking.com - Windows Repair (HKLM-x32\...\Tweaking.com - Windows Repair) (Version: 3.9.28 - Tweaking.com) Unity Web Player (HKU\S-1-5-21-4044022209-2194366084-123958388-1000\...\UnityWebPlayer) (Version: 4.6.4f1 - Unity Technologies ApS) VirtualDub Filter Pack 1.1 (HKLM-x32\...\VirtualDub Filter Pack_is1) (Version: - Infognition Co. Ltd.) VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.6 - VideoLAN) Waterfox 12.0 (x64 en-US) (HKLM\...\Waterfox 12.0 (x64 en-US)) (Version: 12.0 - Mozilla) WavePad Sound Editor (HKLM-x32\...\WavePad) (Version: 6.11 - NCH Software) WebDwarf V2 (HKLM-x32\...\{8E77A94F-AEE6-4B44-9330-514B08D042BA}) (Version: 2.92.17 - Virtual Mechanics) Welcome Center (HKLM-x32\...\Gateway Welcome Center) (Version: 1.02.3102 - Gateway Incorporated) WhatsApp (HKU\S-1-5-21-4044022209-2194366084-123958388-1000\...\WhatsApp) (Version: 0.2.3699 - WhatsApp) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation) WinPcap 4.1.2 (HKLM-x32\...\WinPcapInst) (Version: 4.1.0.2001 - CACE Technologies) WinPDFEditor V3.2.6 (HKLM-x32\...\WinPDFEditor_is1) (Version: - hxxp://www.WinPDFEditor.com) Wondershare PDF to Word (Build 3.5.0) (HKLM-x32\...\{DE718DF0-3874-4873-9BC3-3A94944C916E}_is1) (Version: 3.5.0 - Wondershare Software) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-4044022209-2194366084-123958388-1000_Classes\CLSID\{144DF3B2-2402-47AE-9583-5A045929A8D4}\InprocServer32 -> C:\Users\Sylvia\AppData\Local\Google\Update\1.3.33.5\psuser_64.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-4044022209-2194366084-123958388-1000_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309}\InprocServer32 -> C:\Program Files (x86)\Citrix\GoToMeeting\880\G2MOutlookAddin64.dll (Citrix Online, a division of Citrix Systems, Inc.) CustomCLSID: HKU\S-1-5-21-4044022209-2194366084-123958388-1000_Classes\CLSID\{8C46158B-D978-483C-A312-16EE5013BE04}\InprocServer32 -> C:\Users\Sylvia\AppData\Local\Google\Update\1.3.33.3\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-4044022209-2194366084-123958388-1000_Classes\CLSID\{CB492AF1-2CEF-4E58-BE47-471C77D0C8BA}\InprocServer32 -> C:\Users\Sylvia\AppData\Local\Google\Update\1.3.32.7\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-4044022209-2194366084-123958388-1000_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Sylvia\AppData\Local\Google\Update\1.3.33.5\psuser_64.dll (Google Inc.) ShellIconOverlayIdentifiers: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-08-01] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-08-01] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-08-01] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-08-01] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-08-01] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-08-01] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-08-01] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-08-01] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-08-01] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-08-01] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2017-03-21] (Google) ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2017-03-21] (Google) ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2017-03-21] (Google) ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File ShellIconOverlayIdentifiers-x32: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-08-01] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-08-01] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-08-01] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-08-01] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-08-01] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-08-01] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-08-01] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-08-01] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-08-01] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-08-01] (Dropbox, Inc.) ContextMenuHandlers1: [###MegaContextMenuExt] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\Sylvia\AppData\Local\MEGAsync\ShellExtX64.dll [2014-05-01] () ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2015-12-31] (Igor Pavlov) ContextMenuHandlers1: [BB FlashBack 2] -> {A8065B9E-193F-4797-B62D-8F6321E7FCCB} => -> No File ContextMenuHandlers1: [BDFVCtxMenuExt] -> {9E96C1F5-0EFA-4348-9460-15D6802C70AA} => C:\Program Files\Bitdefender\Bitdefender 2017\bdfvsctx.dll [2017-07-26] (Bitdefender) ContextMenuHandlers1: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-08-01] (Dropbox, Inc.) ContextMenuHandlers1: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files (x86)\Google\Drive\contextmenu64.dll [2017-03-21] (Google) ContextMenuHandlers1-x32: [HotShellExt_40] -> {6872D785-FE43-44cb-9B2A-2DF4C5EB13B2} => C:\Program Files (x86)\eFax Messenger 4.4\J2GShell.dll [2010-07-02] (j2 Global Communications, Inc.) ContextMenuHandlers1-x32: [Incinerator] -> {E8215BEA-3290-4C73-964B-75502B9B41B2} => C:\Program Files (x86)\System Mechanic\Incinerator.dll [2017-06-27] (iolo technologies, LLC) ContextMenuHandlers1-x32: [IObitUnstaler] -> {B19ED566-D419-470b-B111-3C89040BC027} => C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMenuRight.dll [2015-11-12] (IObit) ContextMenuHandlers1-x32: [QuickShare] -> {A8065B9E-193F-4797-B62D-8F6321E7FCCB} => -> No File ContextMenuHandlers1-x32: [SimpleShlExt] -> {45203D3B-3D73-4497-8AFE-D29950AC6C55} => C:\Program Files (x86)\EaseUS\Todo Backup\bin\x64\ImageSh.dll [2017-06-23] (CHENGDU YIWO Tech Development Co.,Ltd) ContextMenuHandlers1-x32: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => -> No File ContextMenuHandlers1-x32: [WondershareVideoConverterFileOpreation] -> {FEB746CA-95C2-485F-B386-C30D4E56D22E} => -> No File ContextMenuHandlers1-x32: [ZipItFreeContextMenu] -> {9FCB3717-B87B-421E-BB30-61769539EA23} => -> No File ContextMenuHandlers1-x32: [_Movavivc11] -> {1C604495-4D32-476e-8D7E-FBF50F6C80BF} => -> No File ContextMenuHandlers2: [SimpleShlExt] -> {45203D3B-3D73-4497-8AFE-D29950AC6C55} => C:\Program Files (x86)\EaseUS\Todo Backup\bin\x64\ImageSh.dll [2017-06-23] (CHENGDU YIWO Tech Development Co.,Ltd) ContextMenuHandlers3: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamext.dll [2016-03-10] (Malwarebytes) ContextMenuHandlers4: [###MegaContextMenuExt] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\Sylvia\AppData\Local\MEGAsync\ShellExtX64.dll [2014-05-01] () ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2015-12-31] (Igor Pavlov) ContextMenuHandlers4: [BDFVCtxMenuExt] -> {9E96C1F5-0EFA-4348-9460-15D6802C70AA} => C:\Program Files\Bitdefender\Bitdefender 2017\bdfvsctx.dll [2017-07-26] (Bitdefender) ContextMenuHandlers4: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-08-01] (Dropbox, Inc.) ContextMenuHandlers4: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files (x86)\Google\Drive\contextmenu64.dll [2017-03-21] (Google) ContextMenuHandlers4: [Incinerator] -> {E8215BEA-3290-4C73-964B-75502B9B41B2} => C:\Program Files (x86)\System Mechanic\Incinerator.dll [2017-06-27] (iolo technologies, LLC) ContextMenuHandlers4: [IObitUnstaler] -> {B19ED566-D419-470b-B111-3C89040BC027} => C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMenuRight.dll [2015-11-12] (IObit) ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File ContextMenuHandlers4: [SimpleShlExt] -> {45203D3B-3D73-4497-8AFE-D29950AC6C55} => C:\Program Files (x86)\EaseUS\Todo Backup\bin\x64\ImageSh.dll [2017-06-23] (CHENGDU YIWO Tech Development Co.,Ltd) ContextMenuHandlers4: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => -> No File ContextMenuHandlers4: [ZipItFree] -> {9FCB3717-B87B-421E-BB30-61769539EA23} => -> No File ContextMenuHandlers5: [BDFVCtxMenuExt] -> {9E96C1F5-0EFA-4348-9460-15D6802C70AA} => C:\Program Files\Bitdefender\Bitdefender 2017\bdfvsctx.dll [2017-07-26] (Bitdefender) ContextMenuHandlers5: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-08-01] (Dropbox, Inc.) ContextMenuHandlers5: [Gadgets] -> {6B9228DA-9C15-419e-856C-19E768A13BDC} => -> No File ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2015-12-31] (Igor Pavlov) ContextMenuHandlers6: [BDFVCtxMenuExt] -> {9E96C1F5-0EFA-4348-9460-15D6802C70AA} => C:\Program Files\Bitdefender\Bitdefender 2017\bdfvsctx.dll [2017-07-26] (Bitdefender) ContextMenuHandlers6: [IObitUnstaler] -> {B19ED566-D419-470b-B111-3C89040BC027} => C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMenuRight.dll [2015-11-12] (IObit) ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamext.dll [2016-03-10] (Malwarebytes) ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File ContextMenuHandlers6: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => -> No File ContextMenuHandlers6: [ZipItFree] -> {9FCB3717-B87B-421E-BB30-61769539EA23} => -> No File ContextMenuHandlers6: [_Movavivc11] -> {1C604495-4D32-476e-8D7E-FBF50F6C80BF} => -> No File ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {042B28F6-96D1-4E94-B120-19D7BE96CE16} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {05A58A71-313A-491D-B65F-AEBC746CA3A1} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\WINDOWS\ehome\ehPrivJob.exe Task: {0902CC0F-B401-4A6D-AFAC-AD7F1CE1B23B} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4044022209-2194366084-123958388-1000Core => C:\Users\Sylvia\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.) Task: {0F39EEE8-80EC-4973-A106-C4A64A594F31} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\WINDOWS\ehome\ehPrivJob.exe Task: {14F57CD1-CFEB-4005-B36E-F4840717E44B} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION Task: {15ED5D55-F4F2-4352-A540-304BCCA2A368} - System32\Tasks\{51544CC1-1D98-4A6B-A4F1-DB814B5295E3} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\VS Revo Group\Revo Uninstaller\Revouninstaller.exe" -d "C:\Program Files (x86)\VS Revo Group\Revo Uninstaller" Task: {1621C9ED-1D6C-4023-80B9-9B0606E23586} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION Task: {1ABDDF65-6589-4B51-BE42-2ED072D372DA} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\WINDOWS\ehome\ehPrivJob.exe Task: {2264806E-0E9A-4136-B397-4C08C8C3F63A} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\WINDOWS\ehome\ehrec.exe Task: {291CF3B5-7795-4233-B59C-DC336A4E0B6D} - System32\Tasks\SUPERAntiSpyware Scheduled Task 2a22458e-257e-4b72-8313-12aa3d1e78b8 => C:\Program Files\SUPERAntiSpyware\SASTask.exe [2013-11-07] (SUPERAdBlocker.com) Task: {2C0C3086-949D-4B8C-89EF-382B2166B98C} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2017-07-11] (Microsoft Corporation) Task: {2D42AB1F-3CA3-43D3-BE13-32F50501BABC} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\WINDOWS\ehome\mcupdate.exe Task: {356CCD50-D33C-483D-AEF5-B760414E7EE4} - System32\Tasks\Run RoboForm TaskBar Icon => C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe Task: {35BFCAC6-8E38-4FB7-970E-3FE921274964} - System32\Tasks\SUPERAntiSpyware Scheduled Task dbfffb97-9cf2-4b86-b186-7cc759ae2f0d => C:\Program Files\SUPERAntiSpyware\SASTask.exe [2013-11-07] (SUPERAdBlocker.com) Task: {3DA6EA8A-51B2-4C80-A938-9069DDA71028} - \update-S-1-5-21-4044022209-2194366084-123958388-1000 -> No File <==== ATTENTION Task: {4076FAB7-3BCE-4986-880F-98474B302D22} - System32\Tasks\Microsoft\Windows\PLA\System\{905FBC35-0E28-4852-8B30-E07737937AD1}_System Diagnostics => C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\pla.dll,PlaHost "system\System Diagnostics" "$(Arg0)" Task: {455C8359-2783-4FEB-9DC4-F4ED24A21BE1} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\WINDOWS\ehome\ehPrivJob.exe Task: {4C418F44-C026-4FA3-A451-283B58E36C42} - System32\Tasks\ioloSmartUpdater => C:\Program Files (x86)\System Mechanic\ioloSmartUpdater.exe [2017-06-27] (iolo technologies, LLC) Task: {4DBA1C39-5CE9-4576-9953-022434906B65} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\WINDOWS\ehome\ehPrivJob.exe Task: {5965114A-B5B9-423B-950B-C0B21D317C96} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION Task: {5EF093E4-0E4F-4D27-8752-A2278486FB92} - System32\Tasks\ASC Task (One-Time) => C:\Program Files (x86)\IObit\Advanced SystemCare\ASCPromote.exe Task: {607CA9C1-7BF0-4F9F-9006-0C4AB2196CFB} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4044022209-2194366084-123958388-1000Core1d257e5885855de => C:\Users\Sylvia\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.) Task: {61932A53-C79A-45C5-BCB8-E60916DC989F} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\WINDOWS\ehome\ehPrivJob.exe Task: {66C1BA5E-0D6A-48D1-93DC-5B02BC9A20B9} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION Task: {6C36EFDF-1AA0-4706-BC95-1D262ADA61E5} - System32\Tasks\{7FF363EE-EFEA-48B2-AE93-9B4C2E30F8E8} => C:\Windows\system32\pcalua.exe -a C:\Users\Sylvia\Downloads\AudibleDM_iTunesSetup.exe -d "C:\Program Files (x86)\Mozilla Firefox" Task: {6C4F11DB-7945-4923-8CD5-4BFFDC39EB2D} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION Task: {710DC475-F5EB-4D8B-AE15-57BE32433448} - \update-sys -> No File <==== ATTENTION Task: {7333543E-CD29-4134-84F1-BECEEC588092} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\WINDOWS\ehome\MCUpdate.exe Task: {77C93557-7547-49E8-B0D5-FBA2CA76828B} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION Task: {78B7336F-8B5E-46CF-BF3A-4D0F5F0AFDC4} - System32\Tasks\Tweaking.com - Windows Repair Tray Icon => C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe [2015-03-11] (Tweaking.com) Task: {7D2C8AAD-3DEE-4FF5-BD7A-AFCBA0144ACA} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-12-14] (Adobe Systems Incorporated) Task: {7EF9970B-7260-421E-A8B0-CE4061C2DCA2} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\WINDOWS\ehome\ehPrivJob.exe Task: {80C19242-1AAB-4F8B-908C-934E444A2312} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {8196B0C5-09F7-4DA7-9797-705E9A9BE591} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION Task: {8558D2CA-7BAA-447C-97DC-0B3D3B54E2EA} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4044022209-2194366084-123958388-1000UA1d257e5886a3077 => C:\Users\Sylvia\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.) Task: {8663A52A-EEE9-4649-9155-B8DE4F4CA24A} - System32\Tasks\ioloToaster => C:\Program Files (x86)\System Mechanic\ioloToaster.exe [2017-06-27] (iolo technologies, LLC) Task: {87CAA953-331E-4C17-884E-A11887A833AC} - System32\Tasks\ioloAVDefsDownloader => C:\Program Files (x86)\System Mechanic\ioloSmartUpdater.exe [2017-06-27] (iolo technologies, LLC) Task: {8C837870-9581-4564-9956-DBBC4445455F} - System32\Tasks\{C71D4CB6-41FA-46D3-B69E-5478F015EE5C} => C:\WINDOWS\system32\pcalua.exe -a "C:\Program Files\Desktop Calendar\DesktopCalendar.exe" -d C:\Users\Sylvia\Desktop Task: {91FC9C37-8E9A-4D31-9489-591557A9CC2C} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\WINDOWS\ehome\ehPrivJob.exe Task: {9278E4D9-846D-461A-976D-0AC731173278} - System32\Tasks\ioloSystemShield => C:\Program Files (x86)\System Mechanic\ioloSSTray.exe [2017-06-27] (iolo technologies, LLC) Task: {950C8664-1814-4C9B-9034-F4DC40AA09BD} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4044022209-2194366084-123958388-1000Core1d1ab1d3a97e7f4 => C:\Users\Sylvia\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.) Task: {9E938577-801A-4777-B539-3C4FEC44E78C} - System32\Tasks\Open URL by RoboForm => C:\Windows\system32\rundll32.exe url.dll,FileProtocolHandler "hxxp://www.roboform.com/uninstall.html?aaa=KICMNMLMKMKJLMMJOMNJCNNMMJGMOMCNLMIMMMKMCNHMOMNJKJCNKJJJIMPMKJJMNMMMJJHMKMHMJNJICMIMCNIMCNGMFMGMCNOMOMCNGMJMPMPMFMJMCNOMCNIMJMPMOMCNNMJNPICMOMFMFMHMMMMMJNHICMOMNMKJOMMMJNBJCMMKGIDJJIGJOJPNMKPIKJBJMJKJJNKJCMJNNICMJNDJCMKJBJ" Task: {A138CCA1-D67E-4D4D-B317-ED0ACF0A0E77} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {A1960278-F172-47F9-A9E8-DBFACC9870F2} - System32\Tasks\ioloTUDsDownloader => C:\Program Files (x86)\System Mechanic\ioloSmartUpdater.exe [2017-06-27] (iolo technologies, LLC) Task: {A223E981-9EF8-4300-9AA4-5D4C3D66F49D} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION Task: {A379950E-135A-4FB5-B14E-F24BA6B0D0A2} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-11-04] (Dropbox, Inc.) Task: {A6496C87-F958-4F24-B4EC-CD1352E8E4AE} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\WINDOWS\ehome\mcupdate.exe Task: {AE59EC9C-C5AC-4805-BA59-2E787E6E5C45} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION Task: {B2F019B2-52D0-4279-A381-06A1B6373AB6} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\WINDOWS\ehome\ehPrivJob.exe Task: {B7463965-AA8E-4D15-ADA8-C8DCB5CDEACE} - System32\Tasks\{BCDDBC84-315E-481E-8CF3-0C0BBF98CD66} => C:\Windows\system32\pcalua.exe -a "C:\Users\Sylvia\Documents\My Downloads\Install_CopyTransControlCenter.exe" -d "C:\Users\Sylvia\Documents\My Downloads" Task: {B7D44FD6-F1D2-4836-A7DC-2EEBA3DE8770} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {BB4FD66B-8147-4A4C-8CFF-13C67F2E2C7A} - System32\Tasks\Uninstaller_SkipUac_Administrator => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [2016-03-04] (IObit) Task: {C2C9ABB4-EEDD-4CF1-B40C-095E21A32F83} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\WINDOWS\explorer.exe /NOUACCHECK Task: {C6D6E601-0232-4EAA-9705-ADE7D5EF83D8} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION Task: {C6ED9901-85EA-4E65-82E3-02D61396B41D} - System32\Tasks\{1C08320F-9E50-44CA-8099-F73BE4F2E066} => C:\Windows\system32\pcalua.exe -a D:\startinstall.exe -d D:\ Task: {CB26A212-C42A-4841-80C9-C7119EEFF0AA} - System32\Tasks\Bitdefender Agent WatchDog_65D6944A0EF74FDAB96E31112AD39864 => C:\Program Files\Bitdefender Agent\WatchDog.exe [2017-04-11] (Bitdefender) Task: {CF0A5A7D-AE0A-4D7E-9945-0CB58F5FAE0C} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\WINDOWS\ehome\ehPrivJob.exe Task: {D2CF1736-AB75-4A39-A971-A37F73C06855} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4044022209-2194366084-123958388-1000UA => C:\Users\Sylvia\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.) Task: {DB66B2F4-D513-42AB-9F46-991321993373} - System32\Tasks\iolo Process Governor => C:\Program Files (x86)\System Mechanic\iologovernor64.exe [2017-06-27] (iolo technologies, LLC) Task: {DB690CDF-FE8F-4691-B8A8-69BBCAA18053} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION Task: {DB69E688-45BC-426A-971F-221B50219D63} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4044022209-2194366084-123958388-1000UA1d1e921612e7e10 => C:\Users\Sylvia\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.) Task: {DCE0B87C-39C8-4188-8FC3-271981EC5475} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4044022209-2194366084-123958388-1000UA1d1ab1d3d44e9b7 => C:\Users\Sylvia\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.) Task: {DE234142-6602-4FA6-B0BB-910EEB22441B} - \Driver Booster SkipUAC (Sylvia) -> No File <==== ATTENTION Task: {E6C69022-3807-4A75-BBC2-64FB25E61A39} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\WINDOWS\ehome\ehPrivJob.exe Task: {E820ADF2-7DB3-4B17-A4AF-009A65F7E8EA} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-04-14] (Google Inc.) Task: {E86DD3A2-474B-4CC8-917C-12426AF7BB6D} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4044022209-2194366084-123958388-1000Core1d1e92160e1955b => C:\Users\Sylvia\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.) Task: {E8F191B5-69BC-4A84-88B6-B245FD87221C} - System32\Tasks\ioloActiveCare => C:\Program Files (x86)\System Mechanic\SystemMechanic.exe [2017-06-27] (iolo technologies, LLC) Task: {E988998B-2511-4A26-9C10-CA82734C9BA1} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2017-06-30] (Piriform Ltd) Task: {EE153C7C-5A18-4308-8ABF-DAA32DCD4EC4} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\WINDOWS\ehome\ehPrivJob.exe Task: {EE3E13E2-E0D6-44E2-AF29-50EDF04786B9} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\WINDOWS\ehome\mcupdate.exe Task: {F36F239B-EBA1-48E3-B313-4F3A0C6043BF} - System32\Tasks\SidebarExecute => C:\Program Files\Windows Sidebar\sidebar.exe Task: {F4D5ADD0-907C-4704-A3B1-1287878ACDAB} - System32\Tasks\Uninstaller_SkipUac_Sylvia => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [2016-03-04] (IObit) Task: {F5738708-4C9C-4BB0-B7DB-6022122C1D41} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-11-04] (Dropbox, Inc.) Task: {F5AFD05F-B6A7-4959-8F29-5A79A4F121A3} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\WINDOWS\ehome\ehPrivJob.exe Task: {FBB73A29-00C5-43B0-8002-4F451CDCEB6B} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-04-14] (Google Inc.) Task: {FBCA1D63-0397-47BC-8084-D89B14A736C2} - System32\Tasks\Bitdefender AgentTask_AD394AE64E874073B10A89FEEC305A3C => C:\Program Files\Bitdefender\Bitdefender 2017\bdagent.exe [2017-07-26] (Bitdefender) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-4044022209-2194366084-123958388-1000Core.job => C:\Users\Sylvia\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-4044022209-2194366084-123958388-1000Core1d1ab1d3a97e7f4.job => C:\Users\Sylvia\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-4044022209-2194366084-123958388-1000Core1d1e92160e1955b.job => C:\Users\Sylvia\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-4044022209-2194366084-123958388-1000UA.job => C:\Users\Sylvia\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-4044022209-2194366084-123958388-1000UA1d1ab1d3d44e9b7.job => C:\Users\Sylvia\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-4044022209-2194366084-123958388-1000UA1d1e921612e7e10.job => C:\Users\Sylvia\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task 2a22458e-257e-4b72-8313-12aa3d1e78b8.job => C:\Program Files\SUPERAntiSpyware\SASTask.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe Task: C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task dbfffb97-9cf2-4b86-b186-7cc759ae2f0d.job => C:\Program Files\SUPERAntiSpyware\SASTask.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe Task: C:\WINDOWS\Tasks\Uninstaller_SkipUac_Sylvia.job => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe ==================== Shortcuts & WMI ======================== (The entries could be listed to be restored or removed.) Shortcut: C:\Users\Sylvia\Favorites\NCH Software Download Site.lnk -> hxxp://www.nch.com.au/index.htm ==================== Loaded Modules (Whitelisted) ============== 2017-03-18 16:58 - 2017-03-18 16:58 - 000138000 _____ () C:\WINDOWS\SYSTEM32\inputhost.dll 2017-03-18 16:59 - 2017-03-18 22:31 - 001731072 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2014-05-01 10:13 - 2014-05-01 10:13 - 000470016 _____ () C:\Users\Sylvia\AppData\Local\MEGAsync\ShellExtX64.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\Users\Sylvia\Desktop\CKScanner.exe:BDU [0] AlternateDataStreams: C:\Users\Sylvia\Downloads\7z1514-x64.exe:BDU [0] AlternateDataStreams: C:\Users\Sylvia\Downloads\AdobeAIRInstaller.exe:BDU [0] AlternateDataStreams: C:\Users\Sylvia\Downloads\AdwCleaner (1).exe:BDU [0] AlternateDataStreams: C:\Users\Sylvia\Downloads\AdwCleaner.exe:BDU [0] AlternateDataStreams: C:\Users\Sylvia\Downloads\Amazon_Music_PC.exe:BDU [0] AlternateDataStreams: C:\Users\Sylvia\Downloads\b-total-video-converter.exe:BDU [0] AlternateDataStreams: C:\Users\Sylvia\Downloads\bbfbex5.exe:BDU [0] AlternateDataStreams: C:\Users\Sylvia\Downloads\ccsetup532pro.exe:BDU [0] AlternateDataStreams: C:\Users\Sylvia\Downloads\DriverTalent_setup.exe:BDU [0] AlternateDataStreams: C:\Users\Sylvia\Downloads\driver_booster_setup_cnet.exe:BDU [0] AlternateDataStreams: C:\Users\Sylvia\Downloads\EIE11_EN-US_MCM_WIN764(1).EXE:BDU [0] AlternateDataStreams: C:\Users\Sylvia\Downloads\esetsmartinstaller_enu.exe:BDU [0] AlternateDataStreams: C:\Users\Sylvia\Downloads\filmora_setup_full846.exe:BDU [0] AlternateDataStreams: C:\Users\Sylvia\Downloads\Firefox Setup Stub 46.0.1.exe:BDU [0] AlternateDataStreams: C:\Users\Sylvia\Downloads\FreemakeVideoConverterFull (1).exe:BDU [0] AlternateDataStreams: C:\Users\Sylvia\Downloads\FreemakeVideoConverterFull.exe:BDU [0] AlternateDataStreams: C:\Users\Sylvia\Downloads\FreemakeVideoDownloaderSetup.exe:BDU [0] AlternateDataStreams: C:\Users\Sylvia\Downloads\Ginger.exe:BDU [0] AlternateDataStreams: C:\Users\Sylvia\Downloads\GrammarlySetup.exe:BDU [0] AlternateDataStreams: C:\Users\Sylvia\Downloads\hd-video-converter-pro.exe:BDU [0] AlternateDataStreams: C:\Users\Sylvia\Downloads\InPixio_PhotoClip_EN_FT.exe:BDU [0] AlternateDataStreams: C:\Users\Sylvia\Downloads\jarte_54_setup.exe:BDU [0] AlternateDataStreams: C:\Users\Sylvia\Downloads\jarte_61_setup.exe:BDU [0] AlternateDataStreams: C:\Users\Sylvia\Downloads\jing.exe:BDU [0] AlternateDataStreams: C:\Users\Sylvia\Downloads\MagistoInstaller_1.12.2103.exe:BDU [0] AlternateDataStreams: C:\Users\Sylvia\Downloads\mbae-setup-1.08.1.1045 (1).exe:BDU [0] AlternateDataStreams: C:\Users\Sylvia\Downloads\mbae-setup-1.08.1.1045.exe:BDU [0] AlternateDataStreams: C:\Users\Sylvia\Downloads\mbae-setup-1.08.1.1196.exe:BDU [0] AlternateDataStreams: C:\Users\Sylvia\Downloads\mbam-setup-2.2.1.1043.exe:BDU [0] AlternateDataStreams: C:\Users\Sylvia\Downloads\MediaCreationTool.exe:BDU [0] AlternateDataStreams: C:\Users\Sylvia\Downloads\MEGAsyncSetup.exe:BDU [0] AlternateDataStreams: C:\Users\Sylvia\Downloads\memorymechanic.exe:BDU [0] AlternateDataStreams: C:\Users\Sylvia\Downloads\messengerfordesktop-2.0.9-win32-setup.exe:BDU [0] AlternateDataStreams: C:\Users\Sylvia\Downloads\MessengerSetup.exe:BDU [0] AlternateDataStreams: C:\Users\Sylvia\Downloads\MultiPDFConverter-Install5.3.exe:BDU [0] AlternateDataStreams: C:\Users\Sylvia\Downloads\musicmanagerinstaller.exe:BDU [0] AlternateDataStreams: C:\Users\Sylvia\Downloads\NDP461-KB3102438-Web.exe:BDU [0] AlternateDataStreams: C:\Users\Sylvia\Downloads\peazip-6.0.3.WIN64.exe:BDU [0] AlternateDataStreams: C:\Users\Sylvia\Downloads\pushbullet_installer.exe:BDU [0] AlternateDataStreams: C:\Users\Sylvia\Downloads\sd5_setup.exe:BDU [0] AlternateDataStreams: C:\Users\Sylvia\Downloads\setup-lightshot.exe:BDU [0] AlternateDataStreams: C:\Users\Sylvia\Downloads\setupBacklinkPirate.exe:BDU [0] AlternateDataStreams: C:\Users\Sylvia\Downloads\smpro_dm.exe:BDU [0] AlternateDataStreams: C:\Users\Sylvia\Downloads\tweaking.com_windows_repair_aio_setup (1).exe:BDU [0] AlternateDataStreams: C:\Users\Sylvia\Downloads\tweaking.com_windows_repair_aio_setup(1).exe:BDU [0] AlternateDataStreams: C:\Users\Sylvia\Downloads\tweaking.com_windows_repair_aio_setup(2).exe:BDU [0] AlternateDataStreams: C:\Users\Sylvia\Downloads\uninstall_flash_player.exe:BDU [0] AlternateDataStreams: C:\Users\Sylvia\Downloads\WhatsAppSetup.exe:BDU [0] AlternateDataStreams: C:\Users\Sylvia\Downloads\winpdfeditor.exe:BDU [0] AlternateDataStreams: C:\Users\Sylvia\Downloads\wlsetup-web (1).exe:BDU [0] AlternateDataStreams: C:\Users\Sylvia\Downloads\wlsetup-web (2).exe:BDU [0] AlternateDataStreams: C:\Users\Sylvia\Downloads\wlsetup-web (3).exe:BDU [0] AlternateDataStreams: C:\Users\Sylvia\Downloads\wlsetup-web.exe:BDU [0] AlternateDataStreams: C:\Users\Sylvia\Downloads\YP-DNA-Setup.exe:BDU [0] ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Option => "OptionValue"="2" iver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mbamchameleon => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mbamchameleon => ""="Driver" ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-13 22:34 - 2017-08-03 10:03 - 000000824 _____ C:\WINDOWS\system32\Drivers\etc\hosts ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-4044022209-2194366084-123958388-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Sylvia\AppData\Roaming\Microsoft\Windows Live Photo Gallery\Windows Live Photo Gallery Wallpaper.jpg DNS Servers: Media is not connected to internet. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 1) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Prompt) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == MSCONFIG\Services: !SASCORE => 3 MSCONFIG\Services: Adobe LM Service => 3 MSCONFIG\Services: AdobeARMservice => 2 MSCONFIG\Services: AdobeFlashPlayerUpdateSvc => 3 MSCONFIG\Services: AdvancedSystemCareService9 => 2 MSCONFIG\Services: Apple Mobile Device => 2 MSCONFIG\Services: Apple Mobile Device Service => 2 MSCONFIG\Services: Bonjour Service => 2 MSCONFIG\Services: Browser => 3 MSCONFIG\Services: dbupdate => 2 MSCONFIG\Services: dbupdatem => 3 MSCONFIG\Services: DbxSvc => 2 MSCONFIG\Services: DevMgmtService => 2 MSCONFIG\Services: EaseUS Agent => 2 MSCONFIG\Services: Freemake Improver => 2 MSCONFIG\Services: gupdate => 3 MSCONFIG\Services: gupdatem => 3 MSCONFIG\Services: LDrvSvc => 2 MSCONFIG\Services: LiveUpdateSvc => 2 MSCONFIG\Services: MbaeSvc => 2 MSCONFIG\Services: MBAMService => 2 MSCONFIG\Services: MediaBrowser => 3 MSCONFIG\Services: MF NTFS Monitor => 2 MSCONFIG\Services: MSMQ => 3 MSCONFIG\Services: OnlineStorageService => 3 MSCONFIG\Services: ProductAgentService => 2 MSCONFIG\Services: ProfSvc => 2 MSCONFIG\Services: SplashtopRemoteService => 3 MSCONFIG\Services: SSUService => 2 MSCONFIG\Services: TabletInputService => 2 MSCONFIG\Services: TeamViewer => 2 MSCONFIG\Services: TeamViewer9 => 2 MSCONFIG\Services: TrueKeyScheduler => 2 MSCONFIG\Services: vseamps => 2 MSCONFIG\Services: vsedsps => 2 MSCONFIG\Services: vseqrts => 2 MSCONFIG\Services: WMPNetworkSvc => 2 MSCONFIG\Services: WMZuneComm => 3 MSCONFIG\Services: WpnService => 3 MSCONFIG\Services: WSearch => 2 MSCONFIG\Services: ZuneNetworkSvc => 3 MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Trend Micro SafeSync.lnk => C:\Windows\pss\Trend Micro SafeSync.lnk.CommonStartup MSCONFIG\startupfolder: C:^Users^Sylvia^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Jacquie Lawson Quick Send Widget.lnk => C:\Windows\pss\Jacquie Lawson Quick Send Widget.lnk.Startup MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" MSCONFIG\startupreg: Amazon Music => "C:\Users\Sylvia\AppData\Local\Amazon Music\Amazon Music Helper.exe" MSCONFIG\startupreg: CanonMyPrinter => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon MSCONFIG\startupreg: CanonSolutionMenu => C:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.exe /logon MSCONFIG\startupreg: CCleaner Monitoring => MSCONFIG\startupreg: Dashlane => MSCONFIG\startupreg: DelaypluginInstall => MSCONFIG\startupreg: Dropbox => "C:\Program Files (x86)\Dropbox\Client\Dropbox.exe" /systemstartup MSCONFIG\startupreg: Google Update => "C:\Users\Sylvia\AppData\Local\Google\Update\GoogleUpdate.exe" /c MSCONFIG\startupreg: Google+ Auto Backup => MSCONFIG\startupreg: GoogleChromeAutoLaunch_D2E080A0B0D3FA5E85FCBE61F49B379B => MSCONFIG\startupreg: Hotkey Utility => C:\Program Files (x86)\Gateway\Hotkey Utility\HotkeyUtility.exe MSCONFIG\startupreg: HotKeysCmds => MSCONFIG\startupreg: IgfxTray => MSCONFIG\startupreg: iolo Startup => "C:\Program Files (x86)\iolo\Common\Lib\ioloLManager.exe" MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe" MSCONFIG\startupreg: LogiScrollApp => C:\Program Files\Logitech\ScrollApp\KhalScroll.exe MSCONFIG\startupreg: MediaFire Tray => MSCONFIG\startupreg: OOTag => C:\Program Files (x86)\Gateway\OOBEOffer\ootag.exe MSCONFIG\startupreg: OpwareSE4 => "C:\Program Files (x86)\ScanSoft\OmniPageSE4\OpwareSE4.exe" MSCONFIG\startupreg: Persistence => MSCONFIG\startupreg: RtHDVCpl => "C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s MSCONFIG\startupreg: Sidebar => MSCONFIG\startupreg: Spotify => "C:\Users\Sylvia\AppData\Roaming\Spotify\Spotify.exe" /uri spotify:autostart MSCONFIG\startupreg: Spotify Web Helper => MSCONFIG\startupreg: SSBkgdUpdate => "C:\Program Files (x86)\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot MSCONFIG\startupreg: SUPERAntiSpyware => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe MSCONFIG\startupreg: Wondershare Helper Compact.exe => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe MSCONFIG\startupreg: WrtMon.exe => C:\Windows\system32\spool\drivers\x64\3\WrtMon.exe MSCONFIG\startupreg: Zune Launcher => HKLM\...\StartupApproved\StartupFolder: => "System Mechanic.lnk" HKLM\...\StartupApproved\Run: => "SecurityHealth" HKLM\...\StartupApproved\Run: => "RTHDVCPL" HKLM\...\StartupApproved\Run: => "CanonSolutionMenu" HKLM\...\StartupApproved\Run: => "CanonMyPrinter" HKLM\...\StartupApproved\Run: => "WrtMon.exe" HKLM\...\StartupApproved\Run32: => "Dropbox" HKLM\...\StartupApproved\Run32: => "ProductUpdater" HKLM\...\StartupApproved\Run32: => "Malwarebytes Anti-Exploit" HKLM\...\StartupApproved\Run32: => "Lightshot" HKLM\...\StartupApproved\Run32: => "OpwareSE4" HKLM\...\StartupApproved\Run32: => "SSBkgdUpdate" HKU\S-1-5-21-4044022209-2194366084-123958388-1000\...\StartupApproved\StartupFolder: => "Facebook Gameroom.lnk" HKU\S-1-5-21-4044022209-2194366084-123958388-1000\...\StartupApproved\StartupFolder: => "startup.bat" HKU\S-1-5-21-4044022209-2194366084-123958388-1000\...\StartupApproved\Run: => "OneDrive" HKU\S-1-5-21-4044022209-2194366084-123958388-1000\...\StartupApproved\Run: => "PlayOn" HKU\S-1-5-21-4044022209-2194366084-123958388-1000\...\StartupApproved\Run: => "Google Update" HKU\S-1-5-21-4044022209-2194366084-123958388-1000\...\StartupApproved\Run: => "Pushbullet" HKU\S-1-5-21-4044022209-2194366084-123958388-1000\...\StartupApproved\Run: => "Spotify" HKU\S-1-5-21-4044022209-2194366084-123958388-1000\...\StartupApproved\Run: => "Spotify Web Helper" HKU\S-1-5-21-4044022209-2194366084-123958388-1000\...\StartupApproved\Run: => "Amazon Music" HKU\S-1-5-21-4044022209-2194366084-123958388-1000\...\StartupApproved\Run: => "MusicManager" HKU\S-1-5-21-4044022209-2194366084-123958388-1000\...\StartupApproved\Run: => "WhatsApp" HKU\S-1-5-21-4044022209-2194366084-123958388-1000\...\StartupApproved\Run: => "GoogleChromeAutoLaunch_D2E080A0B0D3FA5E85FCBE61F49B379B" HKU\S-1-5-21-4044022209-2194366084-123958388-1000\...\StartupApproved\Run: => "CCleaner Monitoring" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{3D3AE1A1-1264-484F-920E-4671CE37C73E}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [UDP Query User{AB01CD34-E30E-4396-991A-C4C73BBE8C7B}C:\lc\mining_proxy.exe] => (Block) C:\lc\mining_proxy.exe FirewallRules: [TCP Query User{37649504-B6A6-4481-9C76-29D3ED2F5FE0}C:\lc\mining_proxy.exe] => (Block) C:\lc\mining_proxy.exe FirewallRules: [{FB32CFC7-68D9-445B-A7B9-6F07297BEDD2}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{F7795259-585F-402F-B4D7-40F92E513FCC}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{02457991-DF03-4F56-A23E-7660FF178298}] => (Allow) C:\Program Files (x86)\Microsoft Office\Live Meeting 8\Console\PWConsole.exe FirewallRules: [{65A33E0B-B7CB-4B6A-8F51-BDF86A3A10FE}] => (Allow) C:\Program Files (x86)\Microsoft Office\Live Meeting 8\Console\PWConsole.exe FirewallRules: [{CAC566DA-FDB0-4E86-B7B2-762CA9114877}] => (Allow) C:\Program Files (x86)\Microsoft Office\Live Meeting 8\Console\PWConsole.exe FirewallRules: [{42A8A587-1D3D-4553-9513-FFD67A53D171}] => (Allow) C:\Program Files (x86)\Microsoft Office\Live Meeting 8\Console\PWConsole.exe FirewallRules: [{047C476F-FD62-49BE-86B1-768CE4D7EEF4}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{2C65A81F-367D-41AD-B84A-51C6B01D95EB}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [TCP Query User{26500248-0376-478A-B17E-B4DC00752783}C:\users\sylvia\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\sylvia\appdata\roaming\spotify\spotify.exe FirewallRules: [UDP Query User{11F2F9D5-F007-47B5-A5B8-1DDE6CDFF95D}C:\users\sylvia\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\sylvia\appdata\roaming\spotify\spotify.exe FirewallRules: [{F34C6A53-249E-41CB-8069-4E37373C7602}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{9E641E34-93E2-448A-A219-B35799C7444C}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{E442368C-AB9E-4C80-A44C-BB8FF54FEDEA}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{FBBDB62B-A19C-4959-93ED-0D3FCD828109}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{F968339B-69A8-45B2-AF55-11CB06C893D6}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{C6A88EF3-F768-4A51-8BEE-C299F9DCB1BB}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{F2FE9E56-F0F2-47C2-8439-E8E628186957}] => (Allow) C:\Program Files (x86)\iTunes\iTunes.exe FirewallRules: [{6C392394-4065-474C-88D4-F72925F8B91A}] => (Allow) LPort=7359 FirewallRules: [{CB73A292-2717-458E-9752-A8E76034A324}] => (Allow) LPort=8096 FirewallRules: [{7BDE6EA8-D327-4310-A7F8-9FCBB1C7EA62}] => (Allow) LPort=8920 FirewallRules: [{0CAE64AA-E546-4EA4-B9A8-3B6212BAE79F}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe FirewallRules: [{850446E3-D83A-4E13-9A7A-ECB669DC6997}] => (Allow) LPort=2869 FirewallRules: [{0BFB1E3F-463A-4AFA-B65C-0C302563D6B9}] => (Allow) LPort=1900 FirewallRules: [{AE95069D-2838-4412-A2FE-7294D786DB02}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe FirewallRules: [TCP Query User{A8A7529B-4C53-4AE0-AE2E-5E6E29F43EB6}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe FirewallRules: [UDP Query User{1095D696-C278-4C3A-A446-1994ADB0734A}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe FirewallRules: [{FEAAB8B7-72F3-4722-82FB-9921443774D4}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TbService.exe FirewallRules: [{58E9A145-8EDB-4037-AA84-82314E143DC5}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TbService.exe FirewallRules: [{5A8FF5DF-9FA0-4C95-AE6C-CBEE7F115D66}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TBConsoleUI.exe FirewallRules: [{3FE5821C-3273-47EB-BF67-42713F50F34C}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TBConsoleUI.exe FirewallRules: [{DDFC3C30-12D4-45F7-B957-2E85B1899FCE}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe FirewallRules: [{F74BEFA7-1D0C-47F4-BE20-6E9D3E8FF7FA}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe FirewallRules: [{61AA9079-DB64-4C5D-A2FA-D7317428174F}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe ==================== Restore Points ========================= 25-07-2017 19:15:35 Scheduled Checkpoint 30-07-2017 19:00:07 Windows Backup ==================== Faulty Device Manager Devices ============= Name: Intel(R) 82567V-2 Gigabit Network Connection Description: Intel(R) 82567V-2 Gigabit Network Connection Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Intel Service: e1yexpress Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: Microsoft PS/2 Mouse Description: Microsoft PS/2 Mouse Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: i8042prt Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. ==================== Event log errors: ========================= Application errors: ================== Error: (08/03/2017 10:13:17 AM) (Source: SideBySide) (EventID: 78) (User: ) Description: Activation context generation failed for "C:\Users\Sylvia\Downloads\esetsmartinstaller_enu.exe".Error in manifest or policy file "" on line . A component version required by the application conflicts with another component version already active. Conflicting components are:. Component 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.483_none_26002d27e7c744a2.manifest. Component 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.483_none_6dad63fefc436da8.manifest. Error: (08/03/2017 12:49:35 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Sylvia-PC) Description: Activation of app Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy!App failed with error: -2144927141 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (08/02/2017 08:34:48 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: The Open Procedure for service "BITS" in DLL "C:\Windows\System32\bitsperf.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code. Error: (08/02/2017 06:45:50 PM) (Source: MsiInstaller) (EventID: 1023) (User: Sylvia-PC) Description: Product: Adobe Acrobat Reader DC - Update '{AC76BA86-7AD7-0000-2550-AC0F174E6600}' could not be installed. Error code 1625. Additional information is available in the log file C:\Users\Sylvia\AppData\Local\Temp\MSI4e988.LOG. Error: (08/02/2017 11:54:13 AM) (Source: SideBySide) (EventID: 78) (User: ) Description: Activation context generation failed for "c:\program files (x86)\eset\eset online scanner\ESETSmartInstaller.exe".Error in manifest or policy file "" on line . A component version required by the application conflicts with another component version already active. Conflicting components are:. Component 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.483_none_26002d27e7c744a2.manifest. Component 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.483_none_6dad63fefc436da8.manifest. Error: (08/02/2017 11:46:01 AM) (Source: MsiInstaller) (EventID: 1023) (User: Sylvia-PC) Description: Product: Adobe Acrobat Reader DC - Update '{AC76BA86-7AD7-0000-2550-AC0F174E6600}' could not be installed. Error code 1625. Additional information is available in the log file C:\Users\Sylvia\AppData\Local\Temp\MSI480e7.LOG. Error: (08/01/2017 08:13:26 PM) (Source: SecurityCenter) (EventID: 16) (User: ) Description: Error while updating status to SECURITY_PRODUCT_STATE_OFF. Error: (08/01/2017 08:13:26 PM) (Source: SecurityCenter) (EventID: 16) (User: ) Description: Error while updating status to SECURITY_PRODUCT_STATE_OFF. Error: (08/01/2017 05:13:39 PM) (Source: SecurityCenter) (EventID: 16) (User: ) Description: Error while updating status to SECURITY_PRODUCT_STATE_OFF. Error: (08/01/2017 05:13:38 PM) (Source: SecurityCenter) (EventID: 16) (User: ) Description: Error while updating status to SECURITY_PRODUCT_STATE_OFF. System errors: ============= Error: (08/03/2017 10:17:11 AM) (Source: DCOM) (EventID: 10005) (User: NT AUTHORITY) Description: DCOM got error "1084" attempting to start the service EventSystem with arguments "Unavailable" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} Error: (08/03/2017 10:17:04 AM) (Source: DCOM) (EventID: 10005) (User: Sylvia-PC) Description: DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "Unavailable" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC} Error: (08/03/2017 10:15:40 AM) (Source: DCOM) (EventID: 10005) (User: Sylvia-PC) Description: DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "Unavailable" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC} Error: (08/03/2017 10:15:31 AM) (Source: DCOM) (EventID: 10005) (User: Sylvia-PC) Description: DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "Unavailable" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC} Error: (08/03/2017 10:14:00 AM) (Source: DCOM) (EventID: 10005) (User: Sylvia-PC) Description: DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "Unavailable" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC} Error: (08/03/2017 10:13:49 AM) (Source: DCOM) (EventID: 10005) (User: Sylvia-PC) Description: DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "Unavailable" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC} Error: (08/03/2017 10:13:32 AM) (Source: DCOM) (EventID: 10005) (User: Sylvia-PC) Description: DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "Unavailable" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC} Error: (08/03/2017 10:13:25 AM) (Source: DCOM) (EventID: 10005) (User: Sylvia-PC) Description: DCOM got error "1084" attempting to start the service WSearch with arguments "Unavailable" in order to run the server: {B52D54BB-4818-4EB9-AA80-F9EACD371DF8} Error: (08/03/2017 10:13:25 AM) (Source: DCOM) (EventID: 10005) (User: Sylvia-PC) Description: DCOM got error "1084" attempting to start the service WSearch with arguments "Unavailable" in order to run the server: {B52D54BB-4818-4EB9-AA80-F9EACD371DF8} Error: (08/03/2017 10:13:25 AM) (Source: DCOM) (EventID: 10005) (User: Sylvia-PC) Description: DCOM got error "1084" attempting to start the service WSearch with arguments "Unavailable" in order to run the server: {B52D54BB-4818-4EB9-AA80-F9EACD371DF8} CodeIntegrity: =================================== Date: 2017-07-31 18:40:43.833 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Bitdefender\Bitdefender 2017\vsservp.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bitdefender\Bitdefender 2017\dbghelp.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-07-20 09:37:33.859 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Bitdefender\Bitdefender 2017\vsservp.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bitdefender\Bitdefender 2017\dbghelp.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-07-19 20:49:51.071 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Bitdefender\Bitdefender 2017\vsservp.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bitdefender\Bitdefender 2017\dbghelp.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-07-19 18:31:44.256 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Bitdefender\Bitdefender 2017\vsservp.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bitdefender\Bitdefender 2017\dbghelp.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-07-19 18:07:32.122 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Bitdefender\Bitdefender 2017\vsservp.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bitdefender\Bitdefender 2017\dbghelp.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-07-19 16:28:15.505 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Bitdefender\Bitdefender 2017\vsservp.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bitdefender\Bitdefender 2017\dbghelp.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-07-19 16:21:04.132 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Bitdefender\Bitdefender 2017\vsservp.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bitdefender\Bitdefender 2017\dbghelp.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-07-19 16:14:36.723 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Bitdefender\Bitdefender 2017\vsservp.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bitdefender\Bitdefender 2017\dbghelp.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-07-19 14:15:49.958 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Bitdefender\Bitdefender 2017\vsservp.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bitdefender\Bitdefender 2017\dbghelp.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-07-19 13:55:51.342 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Bitdefender\Bitdefender 2017\vsservp.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bitdefender\Bitdefender 2017\dbghelp.dll that did not meet the Custom 3 / Antimalware signing level requirements. ==================== Memory info =========================== Processor: Pentium(R) Dual-Core CPU E6700 @ 3.20GHz Percentage of memory in use: 23% Total physical RAM: 4061.17 MB Available physical RAM: 3098.25 MB Total Virtual: 8157.17 MB Available Virtual: 7339.65 MB ==================== Drives ================================ Drive c: (Gateway) (Fixed) (Total:914.91 GB) (Free:626.8 GB) NTFS Drive d: (CANON_IJ) (CDROM) (Total:0.31 GB) (Free:0 GB) CDFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: C7CF2891) Partition 1: (Not Active) - (Size=16.5 GB) - (Type=27) Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=914.9 GB) - (Type=07 NTFS) ==================== End of Addition.txt ============================