Additional scan result of Farbar Recovery Scan Tool (x64) Version: 14.03.2018 Ran by [removed] (18-03-2018 17:34:20) Running from C:\Users\[removed]\Downloads Windows 10 Home Version 1709 16299.248 (X64) (2018-02-04 01:18:44) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-1580677906-789884366-343230679-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-1580677906-789884366-343230679-503 - Limited - Disabled) Guest (S-1-5-21-1580677906-789884366-343230679-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-1580677906-789884366-343230679-1002 - Limited - Enabled) Terri (S-1-5-21-1580677906-789884366-343230679-1001 - Administrator - Enabled) => C:\Users\Terri WDAGUtilityAccount (S-1-5-21-1580677906-789884366-343230679-504 - Limited - Disabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Avast Antivirus (Disabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF} AV: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: 360 Total Security (Enabled - Up to date) {0371CA44-3F80-A1D3-BECE-910620B58D50} AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: 360 Total Security (Enabled - Up to date) {B8102BA0-19BA-AE5D-847E-AA745B32C7ED} AS: Avast Antivirus (Disabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) µTorrent (HKU\S-1-5-21-1580677906-789884366-343230679-1001\...\uTorrent) (Version: 3.4.3.40298 - BitTorrent Inc.) 360 Total Security (HKLM-x32\...\360TotalSecurity) (Version: 9.2.0.1090 - 360 Security Center) Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 18.009.20050 - Adobe Systems Incorporated) Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Avast Free Antivirus (HKLM-x32\...\Avast Antivirus) (Version: 18.2.2328 - AVAST Software) DivX Setup (HKLM\...\DivX Setup) (Version: 3.0.0.141 - DivX, LLC) Fitbit Connect (HKLM-x32\...\{3EFA7006-AFA8-4A75-8FFA-5A43FC797A90}) (Version: 2.0.1.6782 - Fitbit Inc.) FlipShare (HKLM-x32\...\{97C658D2-61FB-027F-0D76-E9CDC84AFEC7}) (Version: 5.12.3.0 - Flip Video) Free VOB To MP4 Converter (HKLM-x32\...\{91F8F9B9-D73E-4F5B-B386-7D203DDE4094}) (Version: 1.0.0 - Convert Audio Free) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 64.0.3282.186 - Google Inc.) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.7 - Google Inc.) Hidden Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden H&R Block Deluxe + Efile 2015 (HKLM-x32\...\{D64EF8D5-1C1C-4B30-AB97-73F2C6024AD3}) (Version: 15.04.8101 - HRB Technology, LLC.) iPNA (HKLM-x32\...\{6158223B-8DB0-4CB7-B8B3-B78AF964B134}) (Version: 1.0.0 - iYogi) iYogi Support Dock (HKLM-x32\...\iYogi Support Dock) (Version: 5.8.1 - iYogi) iYogiPasswordManager (HKLM-x32\...\{65CECF99-19C7-4F86-BD61-C8ECACBCC916}) (Version: 1.0.0 - iYogi) KB4023057 (HKLM\...\{ED06689A-33B7-4D35-8F76-36A82CD03406}) (Version: 2.3.0.0 - Microsoft Corporation) MaintenanceTool (HKLM-x32\...\{499A4914-6123-42BC-A2A1-BBCB04CB3F00}) (Version: 1.0.0 - iYogi Support Dock) Microsoft Office 2000 Disc 2 (HKLM-x32\...\{00040409-78E1-11D2-B60F-006097C998E7}) (Version: 9.00.2720 - Microsoft Corporation) Microsoft Office 2000 Small Business (HKLM-x32\...\{00030409-78E1-11D2-B60F-006097C998E7}) (Version: 9.00.2720 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-1580677906-789884366-343230679-1001\...\OneDriveSetup.exe) (Version: 17.3.7294.0108 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 31.1.2 - Mozilla) Mozilla Thunderbird 31.1.2 (x86 en-US) (HKLM-x32\...\Mozilla Thunderbird 31.1.2 (x86 en-US)) (Version: 31.1.2 - Mozilla) Nmap 5.51 (HKLM-x32\...\Nmap) (Version: - ) TechGenie (HKLM\...\{0D21CFFE-7282-4BBF-9BEF-7A2377F4E2D9}) (Version: 1.0.0 - iYogi) Hidden TechGenie (HKLM\...\{47FC7E57-20EB-4A86-9BEE-522BAEDB9DB8}) (Version: 1.0.0 - iYogi) Hidden TechGenie (HKLM\...\{C49B9BB0-0351-41E7-B48F-3F1F062591DC}) (Version: 1.0.0 - iYogi) Hidden TechGenie (HKLM-x32\...\TechGenie) (Version: 5.7.7 - iYogi) TuneUp Utilities 2014 (en-US) (HKLM-x32\...\{14C8CE46-C68C-461B-BCA9-E276A85851C6}) (Version: 14.0.1000.353 - TuneUp Software) Hidden TuneUp Utilities 2014 (HKLM-x32\...\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C}) (Version: 14.0.1000.353 - TuneUp Software) Hidden TuneUp Utilities 2014 (HKLM-x32\...\TuneUp Utilities) (Version: 14.0.1000.353 - TuneUp Software) TuneUpTool (HKLM-x32\...\{816C887C-611C-4397-8A16-ACA2BE87FAA2}) (Version: 1.0.0 - iYogi Support Dock) TweakBit Driver Updater (HKLM-x32\...\{62D64B30-6E10-4C49-95FE-EDD8F8165DED}_is1) (Version: 1.8.2.19 - Auslogics Labs Pty Ltd) TweakBit PCSpeedUp (HKLM-x32\...\{2FFDD819-5ACF-49D5-9F18-980B42E5DA66}_is1) (Version: 1.8.2.19 - Auslogics Labs Pty Ltd) UpdateAssistant (HKLM-x32\...\{B7AFAF92-D1C8-49A0-B34A-B5DAF9C9D5C6}) (Version: 1.9.0.0 - Microsoft Corporation) Hidden VC80CRTRedist - 8.0.50727.6195 (HKLM-x32\...\{933B4015-4618-4716-A828-5289FC03165F}) (Version: 1.2.0 - DivX, Inc) Hidden VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.4 - VideoLAN) Windows 10 Update Assistant (HKLM-x32\...\{D5C69738-B486-402E-85AC-2456D98A64E4}) (Version: 1.4.9200.22334 - Microsoft Corporation) WinPcap 4.1.2 (HKLM-x32\...\WinPcapInst) (Version: 4.1.0.2001 - CACE Technologies) WinZip 21.0 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C2410D}) (Version: 21.0.12288 - WinZip Computing, S.L. ) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-03-01] (AVAST Software) ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-03-01] (AVAST Software) ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-03-01] (AVAST Software) ContextMenuHandlers1: [iYogiTGForFiles] -> {4709ee0e-9e36-3cb4-9ff2-1588669c818e} => C:\WINDOWS\system32\mscoree.dll [2017-09-29] (Microsoft Corporation) ContextMenuHandlers1: [SD360] -> {086F171D-5ED1-4ED2-B736-CFF3AD6A128E} => C:\Program Files (x86)\360\Total Security\MenuEx64.dll [2017-07-26] () ContextMenuHandlers1: [TuneUp Shredder Shell Extension] -> {4858E7D9-8E12-45a3-B6A3-1CD128C9D403} => C:\Program Files (x86)\TuneUp Utilities 2014\SDShelEx-x64.dll [2015-06-25] (TuneUp Software) ContextMenuHandlers1: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\wzshls64.dll [2017-02-13] (WinZip Computing, S.L.) ContextMenuHandlers2: [iYogiTGForDrive] -> {977ec786-adc9-33b2-82b8-60b145bbdab9} => C:\WINDOWS\system32\mscoree.dll [2017-09-29] (Microsoft Corporation) ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-03-01] (AVAST Software) ContextMenuHandlers4: [iYogiTGForDirectory] -> {ccb9217b-f5fe-3b96-b310-61ecadc754a4} => C:\WINDOWS\system32\mscoree.dll [2017-09-29] (Microsoft Corporation) ContextMenuHandlers4: [SD360] -> {086F171D-5ED1-4ED2-B736-CFF3AD6A128E} => C:\Program Files (x86)\360\Total Security\MenuEx64.dll [2017-07-26] () ContextMenuHandlers4: [TuneUp Disk Space Explorer Shell Extension] -> {4838CD50-7E5D-4811-9B17-C47A85539F28} => C:\Program Files (x86)\TuneUp Utilities 2014\DseShExt-x64.dll [2015-06-25] (TuneUp Software) ContextMenuHandlers4: [TuneUp Shredder Shell Extension] -> {4858E7D9-8E12-45a3-B6A3-1CD128C9D403} => C:\Program Files (x86)\TuneUp Utilities 2014\SDShelEx-x64.dll [2015-06-25] (TuneUp Software) ContextMenuHandlers4: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\wzshls64.dll [2017-02-13] (WinZip Computing, S.L.) ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\WINDOWS\system32\igfxpph.dll [2012-11-27] (Intel Corporation) ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-03-01] (AVAST Software) ContextMenuHandlers6: [SD360] -> {086F171D-5ED1-4ED2-B736-CFF3AD6A128E} => C:\Program Files (x86)\360\Total Security\MenuEx64.dll [2017-07-26] () ContextMenuHandlers6: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\wzshls64.dll [2017-02-13] (WinZip Computing, S.L.) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {01BB7F56-DA0F-497B-B1FA-F3D6C824404D} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-09-27] (Adobe Systems Incorporated) Task: {08CCDD46-CF49-4EF3-913D-2BB7686910BB} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION Task: {0BC9BB65-94FF-4F2F-B2ED-2FEBC5977F2E} - System32\Tasks\TweakBit\PCSpeedUp\Start PCSpeedUp оn logon => C:\Program Files (x86)\TweakBit\PCSpeedUp\PCSpeedUp.exe [2018-01-11] (TweakBit) <==== ATTENTION Task: {20F87D1F-9D72-4726-948B-1FA0576FC2A6} - System32\Tasks\iolo DelOnReboot => cmd.exe /c del /f C:\ProgramData\iolo\ops\smrr.dll Task: {248143D8-7A4E-40B7-AD1F-574BC97B50C5} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime -> No File <==== ATTENTION Task: {25A07FFE-7A1B-486F-96F2-24046DBA4049} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2018-03-01] (AVAST Software) Task: {2AD822BA-8A77-4176-B125-62FBCC0CF9EE} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION Task: {2E73D1A2-E7F8-48E8-9549-F87F63A76A2D} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\WINDOWS\System32\AutoWorkplace.exe Task: {36E57232-1B61-4D11-803A-25A45464CAD2} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION Task: {440CE6DF-561A-401F-991F-476367205404} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION Task: {470F8F24-E649-4AB8-929A-680048ECEE1D} - System32\Tasks\Avast Software\Overseer => C:\Program Files\AVAST Software\Avast\setup\overseer.exe [2018-03-01] (AVAST Software) Task: {47240613-99BF-4652-8890-929296A4E99F} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION Task: {5CF4F3A2-CF53-4D13-8DDD-448F9CBD5A43} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.) Task: {7936F24E-DCF0-41A1-A2DF-791283E3B1FE} - System32\Tasks\DivXUpdate => C:\Program Files (x86)\Common Files\DivX Shared\DivX Update\DivXUpdate.exe [2016-12-15] (DivX, LLC) Task: {8D340956-A06E-46A1-AE5C-4F4ECF069894} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION Task: {A191CEC6-88FE-4615-9A7F-086801D83407} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION Task: {A8E7AC82-1018-4527-B623-E060D2BDF1FE} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime -> No File <==== ATTENTION Task: {AC5A8199-53FB-4BC2-BADA-C412898ED155} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 => C:\Program Files (x86)\TuneUp Utilities 2014\OneClick.exe [2015-06-25] (TuneUp Software) Task: {B01F042A-979C-420E-8563-DB1A17B6CB9A} - System32\Tasks\WinZipBackGroundToolsTask => C:\Program Files\WinZip\WzBGTools.exe [2017-02-13] (WinZip Computing, S.L.) Task: {BC09944C-D43E-4255-A393-FB92881FAC28} - System32\Tasks\TweakBit\Driver Updater\Time for deal => C:\Program Files (x86)\TweakBit\Driver Updater\DriverUpdater.exe [2018-01-11] (TweakBit) <==== ATTENTION Task: {BD9D7621-8E92-4682-A91F-C5B5A975C7D5} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION Task: {C0DC343E-7DBA-4AD9-8B02-C4FCEEEFA943} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION Task: {C1A85714-385B-4728-975C-7FC1E64089D6} - System32\Tasks\WinZip Update Notifier => C:\Program Files\WinZip\WZUpdateNotifier.exe [2017-02-13] (WinZip) Task: {D0776C23-08B0-4E33-A3A4-A3FCB8E94DFC} - System32\Tasks\TweakBit\PCSpeedUp\Time for deal => C:\Program Files (x86)\TweakBit\PCSpeedUp\PCSpeedUp.exe [2018-01-11] (TweakBit) <==== ATTENTION Task: {DD725D96-1E65-4AD5-B045-8C9537133216} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.) Task: {EF1E6CC8-C3EB-4447-AB80-49099F951A5F} - System32\Tasks\TweakBit\Driver Updater\Start Driver Updater оn logon => C:\Program Files (x86)\TweakBit\Driver Updater\DriverUpdater.exe [2018-01-11] (TweakBit) <==== ATTENTION Task: {F0753B4D-CC17-47E3-A034-76467D57CDF6} - System32\Tasks\TweakBit\Driver Updater\Start Driver Updater automatic scanning => C:\Program Files (x86)\TweakBit\Driver Updater\DriverUpdater.exe [2018-01-11] (TweakBit) <==== ATTENTION (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) ==================== Shortcuts & WMI ======================== (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== 2017-09-29 06:41 - 2017-09-29 06:41 - 000184432 _____ () C:\WINDOWS\SYSTEM32\inputhost.dll 2011-05-06 12:58 - 2011-05-06 12:58 - 001085440 _____ () C:\Program Files (x86)\Flip Video\FlipShareServer\FlipShareServer.exe 2015-08-24 11:57 - 2017-07-26 03:36 - 000791136 _____ () C:\Program Files (x86)\360\Total Security\MenuEx64.dll 2018-03-03 16:55 - 2018-02-09 21:39 - 011044864 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2018-03-03 16:55 - 2018-02-09 21:36 - 001804288 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2018-03-01 13:37 - 2018-03-01 13:39 - 000086528 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1807.264.0_x64__kzf8qxf38zg5c\SkypeHost.exe 2018-03-01 13:37 - 2018-03-01 13:39 - 000195072 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1807.264.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll 2018-03-01 13:37 - 2018-03-01 13:40 - 021824000 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1807.264.0_x64__kzf8qxf38zg5c\SkyWrap.dll 2018-03-01 13:37 - 2018-03-01 13:39 - 002529792 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1807.264.0_x64__kzf8qxf38zg5c\skypert.dll 2018-03-01 13:37 - 2018-03-01 13:37 - 000649216 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1807.264.0_x64__kzf8qxf38zg5c\RtmMvrUap.dll 2012-11-27 00:54 - 2012-11-27 00:54 - 000094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2014-07-30 21:45 - 2014-07-30 21:45 - 000673048 _____ () C:\Program Files (x86)\iYogi\TechGenie\iYogi.TechGenie.RealTime.exe 2014-07-30 21:45 - 2014-07-30 21:45 - 000690456 _____ () C:\Program Files (x86)\iYogi\TechGenie\iYogi.TechGenie.AntivirusUpdateApp.exe 2013-09-06 04:22 - 2013-09-06 04:22 - 003272568 _____ () C:\Program Files (x86)\iYogi Support Dock\iYogiSupportDock.exe 2014-08-22 05:13 - 2014-08-22 05:13 - 002208416 _____ () C:\Program Files (x86)\TechGenie\TechGenie.exe 2014-08-27 05:04 - 2014-08-27 05:04 - 000576792 _____ () C:\Program Files (x86)\iYogi\TechGenie\TechGenieApp.exe 2018-03-09 12:29 - 2018-03-09 12:30 - 000173568 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_11802.1001.8.0_x64__8wekyb3d8bbwe\WinStore.Preview.dll 2018-03-09 12:29 - 2018-03-09 12:29 - 002250240 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_11802.1001.8.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll 2015-08-24 11:57 - 2017-07-26 03:36 - 000705120 _____ () C:\Program Files (x86)\360\Total Security\LiveUpdate360.exe 2018-03-01 12:29 - 2018-02-21 20:57 - 004433752 _____ () C:\Program Files (x86)\Google\Chrome\Application\64.0.3282.186\libglesv2.dll 2018-03-01 12:29 - 2018-02-21 20:57 - 000099672 _____ () C:\Program Files (x86)\Google\Chrome\Application\64.0.3282.186\libegl.dll 2015-08-24 11:57 - 2017-07-26 03:36 - 000099240 _____ () C:\Program Files (x86)\360\Total Security\deepscan\qutmload.dll 2018-03-01 13:07 - 2018-03-01 13:07 - 000287960 _____ () c:\program files\avast software\avast\streamback.dll 2018-03-01 13:07 - 2018-03-01 13:07 - 000280280 _____ () C:\Program Files\AVAST Software\Avast\tasks_core.dll 2018-03-03 16:31 - 2018-03-03 16:31 - 005826192 _____ () c:\program files\avast software\avast\defs\18030300\algo.dll 2018-03-01 13:07 - 2018-03-01 13:07 - 000756952 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll 2018-03-01 13:06 - 2018-03-01 13:06 - 000172760 _____ () C:\Program Files\AVAST Software\Avast\hns_tools.dll 2018-03-01 13:06 - 2018-03-01 13:06 - 000964824 _____ () C:\Program Files\AVAST Software\Avast\shepherdsync.dll 2018-03-01 13:06 - 2018-03-01 13:06 - 000475352 _____ () C:\Program Files\AVAST Software\Avast\gui_cache.dll 2018-03-01 13:06 - 2018-03-01 13:06 - 000339672 _____ () C:\Program Files\AVAST Software\Avast\streamback_avast.dll 2018-03-18 17:29 - 2018-03-18 17:29 - 005800080 _____ () c:\program files\avast software\avast\defs\18031800\algo.dll 2010-05-20 13:49 - 2010-05-20 13:49 - 000258048 _____ () C:\Program Files (x86)\Flip Video\FlipShareServer\boost_serialization-vc80-mt-1_43.dll 2010-10-26 00:08 - 2010-10-26 00:08 - 000983040 _____ () C:\Program Files (x86)\Flip Video\FlipShareServer\QtNetwork4.dll 2010-10-26 00:23 - 2010-10-26 00:23 - 000204800 _____ () C:\Program Files (x86)\Flip Video\FlipShareServer\QtSql4.dll 2010-10-26 00:06 - 2010-10-26 00:06 - 002248704 _____ () C:\Program Files (x86)\Flip Video\FlipShareServer\QtCore4.dll 2010-05-17 09:47 - 2010-05-17 09:47 - 000175616 _____ () C:\Program Files (x86)\Flip Video\FlipShareServer\PocoNetSSL.dll 2010-05-17 09:47 - 2010-05-17 09:47 - 000642048 _____ () C:\Program Files (x86)\Flip Video\FlipShareServer\PocoNet.dll 2010-05-17 09:47 - 2010-05-17 09:47 - 000291840 _____ () C:\Program Files (x86)\Flip Video\FlipShareServer\PocoUtil.dll 2010-05-17 09:47 - 2010-05-17 09:47 - 000511488 _____ () C:\Program Files (x86)\Flip Video\FlipShareServer\PocoXML.dll 2010-05-17 09:47 - 2010-05-17 09:47 - 001199104 _____ () C:\Program Files (x86)\Flip Video\FlipShareServer\PocoFoundation.dll 2010-05-17 09:47 - 2010-05-17 09:47 - 000110592 _____ () C:\Program Files (x86)\Flip Video\FlipShareServer\PocoCrypto.dll 2014-12-11 17:40 - 2014-12-11 17:40 - 040622592 ____R () C:\Program Files (x86)\Fitbit Connect\libcef.dll 2018-03-01 13:07 - 2018-03-01 13:07 - 067126928 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2018-03-01 13:06 - 2018-03-01 13:06 - 000275160 _____ () C:\Program Files\AVAST Software\Avast\gaming_mode_ui.dll 2015-08-24 11:57 - 2017-07-26 03:36 - 000499296 _____ () C:\Program Files (x86)\360\Total Security\safemon\wdui2.dll 2013-09-06 04:29 - 2013-09-06 04:29 - 000435200 _____ () C:\Program Files (x86)\iYogi Support Dock\ResDll.dll 2014-05-21 06:39 - 2014-05-21 06:39 - 000456192 _____ () C:\Program Files (x86)\TechGenie\ResDll.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2013-08-22 06:25 - 2013-08-22 06:25 - 000000824 _____ C:\WINDOWS\system32\Drivers\etc\hosts ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-1580677906-789884366-343230679-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Terri\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper DNS Servers: 192.168.254.254 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == HKLM\...\StartupApproved\StartupFolder: => "Microsoft Office.lnk" HKLM\...\StartupApproved\StartupFolder: => "WinZip Preloader.lnk" HKLM\...\StartupApproved\StartupFolder: => "Update Notifier.lnk" HKLM\...\StartupApproved\Run32: => "InboxAce EPM Support" HKLM\...\StartupApproved\Run32: => "DivXMediaServer" HKU\S-1-5-21-1580677906-789884366-343230679-1001\...\StartupApproved\Run: => "OneDrive" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{A6D6A210-5BA5-4E50-B728-B0A56B875D93}] => (Allow) C:\Program Files (x86)\360\Total Security\softmgr\360InstantSetup.exe FirewallRules: [{05EC6DE4-8B07-42A6-B47F-2FC85D89701D}] => (Allow) C:\Program Files (x86)\360\Total Security\softmgr\360InstantSetup.exe FirewallRules: [{930B2F74-4155-4B08-B1FA-515718463DCF}] => (Allow) C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe FirewallRules: [{4F1E96BA-17C6-43A6-8E1A-BDB779E9BD65}] => (Allow) C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe FirewallRules: [{82C0A5FA-169F-4E49-BAFB-FA4AED129522}] => (Allow) C:\Program Files (x86)\360\Total Security\softmgr\360InstantSetup.exe FirewallRules: [{E1E76331-88AE-4CF7-ABC3-00C985582CF3}] => (Allow) C:\Program Files (x86)\360\Total Security\softmgr\360InstantSetup.exe FirewallRules: [{B4B402D0-7FC7-47B7-83FC-8EF498459C72}] => (Allow) LPort=24726 FirewallRules: [{72DBF12C-319B-49DB-95FA-0FFE7BFE9943}] => (Allow) LPort=24727 FirewallRules: [{833698AE-07FC-49F4-931D-934AD9E5E03A}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe FirewallRules: [{009D0257-4742-4D65-8EA0-F8CA7924A388}] => (Allow) C:\Users\Terri\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{4A9F3F05-8CBF-455E-AC07-78B1CE3DC244}] => (Allow) C:\Users\Terri\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{FA30A110-070D-4605-9DAE-16C2601B727C}] => (Allow) C:\Program Files (x86)\360\Total Security\LiveUpdate360.exe FirewallRules: [{B14EF992-8182-4605-A766-52EEB3FB112E}] => (Allow) C:\Program Files (x86)\360\Total Security\LiveUpdate360.exe FirewallRules: [{96022EAD-33E3-4549-B515-BD66436A34D8}] => (Allow) C:\Program Files (x86)\360\Total Security\LiveUpdate360.exe FirewallRules: [{BBD0C172-4E21-4CE9-AE56-FD31906FFF2A}] => (Allow) C:\Program Files (x86)\360\Total Security\LiveUpdate360.exe FirewallRules: [{211BD158-9083-45C0-884A-F7C310D6886D}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{47028AA4-05B0-495D-BEB3-B0D515FB9117}] => (Allow) C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe FirewallRules: [{5C1C3CC8-93FE-48EA-9C57-B19ABDA2F60F}] => (Allow) C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe ==================== Restore Points ========================= 01-03-2018 12:40:20 Windows Update ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (03/03/2018 04:31:09 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: TERRI-PC) Description: Package Microsoft.Windows.Photos_2018.18021.12420.0_x64__8wekyb3d8bbwe+App was terminated because it took too long to suspend. Error: (03/01/2018 01:38:28 PM) (Source: COM) (EventID: 10031) (User: ) Description: An unmarshaling policy check was performed when unmarshaling a custom marshaled object and the class {41FD88F7-F295-4D39-91AC-A85F3149A05B} was rejected Error: (03/01/2018 01:38:28 PM) (Source: COM) (EventID: 10031) (User: ) Description: An unmarshaling policy check was performed when unmarshaling a custom marshaled object and the class {41FD88F7-F295-4D39-91AC-A85F3149A05B} was rejected Error: (03/01/2018 12:46:03 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: The Open Procedure for service "BITS" in DLL "C:\Windows\System32\bitsperf.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code. Error: (02/03/2018 06:14:32 PM) (Source: MSDTC Client 2) (EventID: 4104) (User: ) Description: Failed trying to get the state of the cluster node: .The error code returned: 0x8007085A Error: (02/03/2018 06:14:23 PM) (Source: Microsoft-Windows-WMI) (EventID: 24) (User: NT AUTHORITY) Description: Event provider wsp_sr attempted to register query "select * from WSP_ReplicationGroupModificationEvent" whose target class "WSP_ReplicationGroupModificationEvent" in //./root/Microsoft/Windows/Storage/Providers_v2 namespace does not exist. The query will be ignored. Error: (02/03/2018 06:14:23 PM) (Source: Microsoft-Windows-WMI) (EventID: 24) (User: NT AUTHORITY) Description: Event provider wsp_sr attempted to register query "select * from WSP_ReplicationGroupDepartureEvent" whose target class "WSP_ReplicationGroupDepartureEvent" in //./root/Microsoft/Windows/Storage/Providers_v2 namespace does not exist. The query will be ignored. Error: (02/03/2018 06:14:23 PM) (Source: Microsoft-Windows-WMI) (EventID: 24) (User: NT AUTHORITY) Description: Event provider wsp_sr attempted to register query "select * from WSP_ReplicationGroupArrivalEvent" whose target class "WSP_ReplicationGroupArrivalEvent" in //./root/Microsoft/Windows/Storage/Providers_v2 namespace does not exist. The query will be ignored. System errors: ============= Error: (03/18/2018 05:27:51 PM) (Source: DCOM) (EventID: 10016) (User: TERRI-PC) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the user Terri-PC\Terri SID (S-1-5-21-1580677906-789884366-343230679-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (03/09/2018 12:27:27 PM) (Source: DCOM) (EventID: 10016) (User: TERRI-PC) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the user Terri-PC\Terri SID (S-1-5-21-1580677906-789884366-343230679-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (03/04/2018 03:26:25 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {C2F03A33-21F5-47FA-B4BB-156362A2F239} and APPID {316CDED5-E4AE-4B15-9113-7055D84DCC97} to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (03/04/2018 03:26:25 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52} and APPID {4839DDB7-58C2-48F5-8283-E1D1807D0D7D} to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (03/04/2018 03:26:25 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {C2F03A33-21F5-47FA-B4BB-156362A2F239} and APPID {316CDED5-E4AE-4B15-9113-7055D84DCC97} to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (03/04/2018 03:26:25 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52} and APPID {4839DDB7-58C2-48F5-8283-E1D1807D0D7D} to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (03/04/2018 03:26:25 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {C2F03A33-21F5-47FA-B4BB-156362A2F239} and APPID {316CDED5-E4AE-4B15-9113-7055D84DCC97} to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (03/04/2018 03:26:25 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52} and APPID {4839DDB7-58C2-48F5-8283-E1D1807D0D7D} to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. CodeIntegrity: =================================== Date: 2018-03-01 13:41:47.950 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows.old\WINDOWS\WinSxS\x86_microsoft-windows-utilman_31bf3856ad364e35_10.0.10586.0_none_3310acc4233710cd\Utilman.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2018-03-01 13:41:47.948 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows.old\WINDOWS\WinSxS\x86_microsoft-windows-utilman_31bf3856ad364e35_10.0.10586.0_none_3310acc4233710cd\Utilman.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2018-03-01 13:41:47.945 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows.old\WINDOWS\WinSxS\x86_microsoft-windows-utilman_31bf3856ad364e35_10.0.10586.0_none_3310acc4233710cd\Utilman.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2018-03-01 13:41:47.903 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows.old\WINDOWS\WinSxS\x86_microsoft-windows-utilman_31bf3856ad364e35_10.0.10586.0_none_3310acc4233710cd\Utilman.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i3 CPU 550 @ 3.20GHz Percentage of memory in use: 53% Total physical RAM: 5943.11 MB Available physical RAM: 2787.43 MB Total Virtual: 14857.11 MB Available Virtual: 11362.32 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:917.66 GB) (Free:721.45 GB) NTFS \\?\Volume{6fed172e-87c9-11e0-88ae-806e6f6e6963}\ (RECOVERY) (Fixed) (Total:13.81 GB) (Free:5.08 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 931.5 GB) (Disk ID: 1512C6F0) Partition 1: (Not Active) - (Size=39 MB) - (Type=DE) Partition 2: (Active) - (Size=13.8 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=917.7 GB) - (Type=07 NTFS) ==================== End of Addition.txt ============================