Additional scan result of Farbar Recovery Scan Tool (x64) Version: 20.06.2018 Ran by [removed] (04-07-2018 12:15:05) Running from C:\Users\[removed]\Downloads Windows 7 Home Premium Service Pack 1 (X64) (2011-10-13 19:20:57) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-1963740025-2681597282-1959595548-500 - Administrator - Disabled) Dee (S-1-5-21-1963740025-2681597282-1959595548-1001 - Administrator - Enabled) => C:\Users\Dee Guest (S-1-5-21-1963740025-2681597282-1959595548-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-1963740025-2681597282-1959595548-1003 - Limited - Enabled) UpdatusUser (S-1-5-21-1963740025-2681597282-1959595548-1005 - Limited - Enabled) => C:\Users\UpdatusUser ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Microsoft Security Essentials (Enabled - Up to date) {71A27EC9-3DA6-45FC-60A7-004F623C6189} AS: Microsoft Security Essentials (Enabled - Up to date) {CAC39F2D-1B9C-4A72-5A17-3B3D19BB2B34} AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 64 Bit HP CIO Components Installer (HKLM\...\{FF21C3E6-97FD-474F-9518-8DCBE94C2854}) (Version: 7.2.8 - Hewlett-Packard) Hidden AccelerometerP11 (HKLM-x32\...\{87434D51-51DB-4109-B68F-A829ECDCF380}) (Version: 2.00.11.22 - STMicroelectronics) Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 4.6.0.384 - Adobe Systems Incorporated) Adobe Lightroom (HKLM-x32\...\{8048A5DF-8A70-5BE1-954B-E0FDE1BD0D0D}) (Version: 6.14 - Adobe Systems Incorporated) Adobe Lightroom Classic CC (HKLM-x32\...\LTRM_7_4) (Version: 7.4 - Adobe Systems Incorporated) Adobe Photoshop CC 2018 (HKLM-x32\...\PHSP_19_1_5) (Version: 19.1.5 - Adobe Systems Incorporated) Brother MFL-Pro Suite DCP-J152W (HKLM-x32\...\{B742757A-7658-4E09-A51A-085CF0F7F4D3}) (Version: 1.0.0.0 - Brother Industries, Ltd.) D3DX10 (HKLM-x32\...\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden Dell Data Vault (HKLM\...\{2E55EEFD-2162-4A7D-9158-EDB0305603A6}) (Version: 4.3.8.0 - Dell Inc.) Hidden Dell Edoc Viewer (HKLM\...\{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}) (Version: 1.0.0 - Dell Inc) Dell Stage Remote (HKLM-x32\...\{2299EEBD-0A83-4B26-AA4A-057AE9E5BAE8}) (Version: 2.0.0.50 - ArcSoft) Dell SupportAssistAgent (HKLM-x32\...\{3ED468C2-2235-4747-90AD-A7A34F0FE70A}) (Version: 1.2.2.8 - Dell) Dell Webcam Central (HKLM-x32\...\Dell Webcam Central) (Version: 2.00.44 - Creative Technology Ltd) DivX Setup (HKLM-x32\...\DivX Setup) (Version: 2.6.1.22 - DivX, LLC) Fundy Designer 7 version 8.0.23 (HKLM\...\{85dee4e3-c2e4-4fb2-8ae9-78a06e1c96d7}_is1) (Version: 8.0.23 - Fundy Software) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 67.0.3396.99 - Google Inc.) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.17 - Google Inc.) Hidden Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden HPDiagnosticAlert (HKLM-x32\...\{B6465A32-8BE9-4B38-ADC5-4B4BDDC10B0D}) (Version: 1.00.0001 - Microsoft) Hidden Intel PROSet Wireless (HKLM-x32\...\ProInst) (Version: - ) Hidden Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.3347 - Intel Corporation) Intel(R) PROSet/Wireless WiFi Software (HKLM\...\{25FBDA9A-E868-4B3B-B9FF-D923818511A1}) (Version: 14.2.0000 - Intel Corporation) Intel(R) Turbo Boost Technology Monitor 2.0 (HKLM\...\{B77EFA0B-9BD3-4122-9F9A-15A963B5EA24}) (Version: 2.1.23.0 - Intel) Intel(R) WiDi (HKLM-x32\...\{0DD706AF-B542-438C-999E-B30C7F625C8D}) (Version: 2.1.39.0 - Intel Corporation) Intel(R) Wireless Display (HKLM\...\{28EF7372-9087-4AC3-9B9F-D9751FCDF830}) (Version: - ) Java 8 Update 31 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418031F0}) (Version: 8.0.310 - Oracle Corporation) Java 8 Update 31 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation) JavaFX 2.1.1 (HKLM-x32\...\{1111706F-666A-4037-7777-211328764D10}) (Version: 2.1.1 - Oracle Corporation) Junk Mail filter update (HKLM-x32\...\{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}) (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden LibreOffice 6.0.3.2 (HKLM\...\{9739EFFE-C402-4A4B-AE2E-092682D1D07B}) (Version: 6.0.3.2 - The Document Foundation) Mesh Runtime (HKLM-x32\...\{8C6D6116-B724-4810-8F2D-D047E6B7D68E}) (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.7.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.02558 - Microsoft Corporation) Microsoft Camera Codec Pack (HKLM\...\{D553E8CC-5C56-4B06-AC1A-A443DFF31092}) (Version: 6.3.9723.0 - Microsoft Corporation) Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.10.209.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{820B6609-4C97-3A2B-B644-573B06A0F0CC}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2017 Redistributable (x64) - 14.12.25810 (HKLM-x32\...\{e2ee15e2-a480-4bc5-bfb7-e9803d1d9823}) (Version: 14.12.25810.0 - Microsoft Corporation) Microsoft Visual C++ 2017 Redistributable (x86) - 14.12.25810 (HKLM-x32\...\{56e11d69-7cc9-40a5-a4f9-8f6190c4d84d}) (Version: 14.12.25810.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) NVIDIA 3D Vision Driver 331.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 331.65 - NVIDIA Corporation) NVIDIA Graphics Driver 331.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 331.65 - NVIDIA Corporation) NVIDIA HD Audio Driver 1.3.26.4 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.26.4 - NVIDIA Corporation) NVIDIA PhysX System Software 9.12.1031 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.12.1031 - NVIDIA Corporation) NVIDIA Update 1.15.2 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.15.2 - NVIDIA Corporation) OpenOffice.org 3.3 (HKLM-x32\...\{82AF3E91-57E1-4754-84D0-40A46E2479AB}) (Version: 3.3.9567 - OpenOffice.org) Phone to PC 4.1.6.2 (HKLM-x32\...\{D3D1D696-84A8-465A-BC61-CDAC852B24CD}_is1) (Version: - Macroplant, LLC) PlayReady PC Runtime x86 (HKLM-x32\...\{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}) (Version: 1.3.0 - Microsoft Corporation) Quickset64 (HKLM\...\{87CF757E-C1F1-4D22-865C-00C6950B5258}) (Version: 11.0.10 - Dell Inc.) QuickTime (HKLM-x32\...\{B67BAFBA-4C9F-48FA-9496-933E3B255044}) (Version: 7.74.80.86 - Apple Inc.) RealDownloader (HKLM-x32\...\{AF7EBCA4-9FAF-4DC8-8D09-67854BB84D34}) (Version: 1.3.0 - RealNetworks, Inc.) Hidden RealNetworks - Microsoft Visual C++ 2008 Runtime (HKLM-x32\...\{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}) (Version: 9.0 - RealNetworks, Inc) Hidden RealNetworks - Microsoft Visual C++ 2010 Runtime (HKLM-x32\...\{AAECF7BA-E83B-4A10-87EA-DE0B333F8734}) (Version: 10.0 - RealNetworks, Inc) Hidden Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6312 - Realtek Semiconductor Corp.) RealUpgrade 1.1 (HKLM-x32\...\{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}) (Version: 1.1.0 - RealNetworks, Inc.) Hidden Seagate Dashboard (HKLM-x32\...\{EA266F00-A8E7-43A0-8DED-FBFE3F076934}) (Version: 4.4.11.0 - Seagate) SimWare_EU (HKU\S-1-5-21-1963740025-2681597282-1959595548-1001\...\SimWare_EU) (Version: SimWare_EU 2017.3.1 - Sim2000 Imaging) Skype Click to Call (HKLM-x32\...\{873F8E7C-10E6-449F-BD7E-5FBA7C8E1C9B}) (Version: 8.5.0.9167 - Microsoft Corporation) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.1.15.0 - Synaptics Incorporated) TuneUp Utilities Language Pack (en-US) (HKLM-x32\...\{A95A76C9-6F65-477E-83A0-9F884B6DC21B}) (Version: 12.0.3600.104 - TuneUp Software) Hidden VC80CRTRedist - 8.0.50727.6195 (HKLM-x32\...\{933B4015-4618-4716-A828-5289FC03165F}) (Version: 1.2.0 - DivX, Inc) Hidden Visual Studio 2008 x64 Redistributables (HKLM-x32\...\{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}) (Version: 10.0.0.2 - AVG Technologies) VLC media player 1.1.11 (HKLM-x32\...\VLC media player) (Version: 1.1.11 - VideoLAN) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation) Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation) WinSCP 4.3.5 (HKLM-x32\...\winscp3_is1) (Version: 4.3.5 - Martin Prikryl) Wondershare Data Recovery(Build 4.8.3.4) (HKLM-x32\...\{FEA3976F-D621-45F3-AFBD-E812A1F2F00D}_is1) (Version: 4.8.3.4 - Wondershare Software Co.,Ltd.) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) HKU\S-1-5-21-1963740025-2681597282-1959595548-1001\...\ChromeHTML: -> <==== ATTENTION CustomCLSID: HKU\S-1-5-21-1963740025-2681597282-1959595548-1001_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\Dee\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-1963740025-2681597282-1959595548-1001_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\Dee\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-1963740025-2681597282-1959595548-1001_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\Dee\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-1963740025-2681597282-1959595548-1001_Classes\CLSID\{590C4387-5EBD-4D46-8A84-CD0BA2EF2856}\InprocServer32 -> C:\Users\Dee\AppData\Local\Google\Update\1.3.30.3\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-1963740025-2681597282-1959595548-1001_Classes\CLSID\{5C8C2A98-6133-4EBA-BBCC-34D9EA01FC2E}\InprocServer32 -> C:\Users\Dee\AppData\Local\Google\Update\1.3.28.1\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-1963740025-2681597282-1959595548-1001_Classes\CLSID\{78550997-5DEF-4A8A-BAF9-D5774E87AC98}\InprocServer32 -> C:\Users\Dee\AppData\Local\Google\Update\1.3.28.13\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-1963740025-2681597282-1959595548-1001_Classes\CLSID\{793EE463-1304-471C-ADF1-68C2FFB01247}\InprocServer32 -> C:\Users\Dee\AppData\Local\Google\Update\1.3.29.5\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-1963740025-2681597282-1959595548-1001_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\Dee\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-1963740025-2681597282-1959595548-1001_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\Dee\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-1963740025-2681597282-1959595548-1001_Classes\CLSID\{CC182BE1-84CE-4A57-B85C-FD4BBDF78CB2}\InprocServer32 -> C:\Users\Dee\AppData\Local\Google\Update\1.3.29.1\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-1963740025-2681597282-1959595548-1001_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\Dee\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-1963740025-2681597282-1959595548-1001_Classes\CLSID\{D1EDC4F5-7F4D-4B12-906A-614ECF66DDAF}\InprocServer32 -> C:\Users\Dee\AppData\Local\Google\Update\1.3.28.15\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-1963740025-2681597282-1959595548-1001_Classes\CLSID\{e8c77137-e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems) CustomCLSID: HKU\S-1-5-21-1963740025-2681597282-1959595548-1001_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\Dee\AppData\Local\Google\Update\1.3.24.7\psuser_64.dll => No File ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-02-27] () ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-02-27] () ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-02-27] () ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => -> No File ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => -> No File ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => -> No File ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => -> No File ShellIconOverlayIdentifiers: [SugarSyncBackedUp] -> {0C4A258A-3F3B-4FFF-80A7-9B3BEC139472} => -> No File ShellIconOverlayIdentifiers: [SugarSyncSharedPending] -> {F7395C2E-A5D8-4a32-9536-5C6A9F1DC450} => -> No File ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => -> No File ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => -> No File ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => -> No File ContextMenuHandlers1: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-02-27] () ContextMenuHandlers1: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => C:\Program Files\Microsoft Security Client\shellext.dll [2016-11-14] (Microsoft Corporation) ContextMenuHandlers2: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => C:\Program Files\Microsoft Security Client\shellext.dll [2016-11-14] (Microsoft Corporation) ContextMenuHandlers4: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => C:\Program Files\Microsoft Security Client\shellext.dll [2016-11-14] (Microsoft Corporation) ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\Windows\system32\igfxpph.dll [2014-01-30] (Intel Corporation) ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\system32\nvshext.dll [2013-10-23] (NVIDIA Corporation) ContextMenuHandlers6: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-02-27] () ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {17A6CC30-9A91-48ED-B518-214C7706EE50} - System32\Tasks\Games\UpdateCheck_S-1-5-21-1963740025-2681597282-1959595548-1001 Task: {1EF92795-36E5-42BF-874E-4CF76F7A1E95} - System32\Tasks\AdobeAAMUpdater-1.0-Dee-PC-Dee => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2018-04-11] (Adobe Systems Incorporated) Task: {2103BF4E-1645-46BE-B1B4-FD6428F490C2} - System32\Tasks\{803BA9F5-01F3-4758-89EB-A4AC7DCED698} => C:\Windows\system32\pcalua.exe -a C:\Users\Dee\Downloads\Loxley_Designer_Pro_Setup.exe -d C:\Users\Dee\Downloads Task: {255D814C-7E88-4554-9D89-F501C9A89F3A} - System32\Tasks\{0CD950B0-59D7-4715-AEE7-29FA4C13BA1D} => C:\Windows\system32\pcalua.exe -a F:\Setup.exe -d F:\ Task: {32F2C023-7FC8-4260-BDA0-BC95E21DAFE3} - System32\Tasks\Dell SupportAssistAgent AutoUpdate => C:\Program Files (x86)\Dell\SupportAssistAgent\bin\SupportAssist.exe [2016-04-22] (Dell Inc.) Task: {33AE4DD3-749F-4E9F-92FD-6B1FE9307DE5} - System32\Tasks\{EFC888E9-D67D-4FA9-A298-C7C01A446E8B} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\O2\O2 Broadband USB Modem\O2 Broadband\uninst.exe" Task: {35C84CEB-7313-4018-ACE8-88FE87E29E40} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => c:\Program Files\Microsoft Security Client\\MpCmdRun.exe [2016-11-14] (Microsoft Corporation) Task: {35F19C26-FCF5-4CDE-AC94-EF2646B7A96B} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-1963740025-2681597282-1959595548-1001 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2012-11-30] (RealNetworks, Inc.) Task: {3FE64CD8-5BD3-4EA1-A037-7BE88A617B64} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-1963740025-2681597282-1959595548-1001 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2012-11-30] (RealNetworks, Inc.) Task: {48021BAD-1E0C-4EF8-8D71-FEB80F3B1437} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-10-28] (Adobe Systems Incorporated) Task: {524B8475-8476-4C31-8E96-9879F4A74B5E} - System32\Tasks\Adobe Uninstaller => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2018-06-22] (Adobe Systems Incorporated) Task: {52A0D27E-B212-4BEA-B3AD-4C447DFA573E} - System32\Tasks\Seagate_Install_Launch => C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Dashboard.exe [2016-04-05] (Seagate Technology LLC) Task: {57277F3D-8C16-4EBA-8ED5-D4A55160CE86} - System32\Tasks\Dee DBAgent 2 0 => C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\DBAgent.exe [2016-04-05] (Seagate Technology LLC) Task: {5E66EB9B-4414-4B83-9560-D319ABBA3C9E} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-1963740025-2681597282-1959595548-1001 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2012-11-30] (RealNetworks, Inc.) Task: {705115B5-B8AE-46CF-8945-F68523F7ECB8} - System32\Tasks\{64784357-E851-4381-AD0B-5F038218D50A} => C:\Windows\system32\pcalua.exe -a G:\SetupWi-Fi.exe -d G:\ Task: {7D0FF9C4-E940-42B2-8253-79C3BC0882CE} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-01] (Google Inc.) Task: {82B28F34-BCE5-4487-B713-966CED7BA6A7} - System32\Tasks\{8C51E00E-C099-46C5-BDCE-C76F09259554} => C:\Windows\system32\pcalua.exe -a C:\Users\Dee\AppData\Local\Evernote\Evernote\AutoUpdate\Evernote_5.6.4.4632.exe -d "C:\Program Files (x86)\Evernote\Evernote" -c /qb Task: {9C25A498-4D4B-4B18-A67A-C8CA55C257F8} - System32\Tasks\AdobeGCInvoker-1.0-Dee-PC-Dee => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [2018-05-11] (Adobe Systems, Incorporated) Task: {B9EB6316-0907-416A-B720-D7AB5265C580} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-1963740025-2681597282-1959595548-1001 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2012-11-30] (RealNetworks, Inc.) Task: {FC1A6D5F-3A30-41A8-8F35-4A6020E59043} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-01] (Google Inc.) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) ==================== Shortcuts & WMI ======================== (The entries could be listed to be restored or removed.) ShortcutWithArgument: C:\Users\Dee\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Loxley ROES\Loxley ROES.lnk -> C:\Windows\SysWOW64\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://www.roeslaunch.com/ROES/labs/LoxleyColour/launchram.jnlp "C:\Users\Dee\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32\151aa9a0-7bee666e" ==================== Loaded Modules (Whitelisted) ============== 2012-09-20 17:13 - 2013-10-23 09:20 - 000102176 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2011-07-28 02:07 - 2011-07-28 02:07 - 001501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\Libeay32.dll 2018-02-27 20:08 - 2018-02-27 20:08 - 000614856 _____ () C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll 2011-10-10 08:11 - 2011-03-07 21:07 - 000094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2012-11-30 03:06 - 2012-11-30 03:06 - 001263512 _____ () C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe 2018-06-08 16:34 - 2018-06-08 16:34 - 035475912 _____ () C:\Program Files (x86)\Adobe\Adobe Sync\Coresync\Coresync.exe 2018-06-25 19:54 - 2018-06-22 20:15 - 004608856 _____ () C:\Program Files (x86)\Google\Chrome\Application\67.0.3396.99\libglesv2.dll 2018-06-25 19:54 - 2018-06-22 20:15 - 000099672 _____ () C:\Program Files (x86)\Google\Chrome\Application\67.0.3396.99\libegl.dll 2012-11-30 03:07 - 2012-11-30 03:07 - 000100248 _____ () C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll 2018-06-07 14:35 - 2018-06-07 14:35 - 081764304 _____ () C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\CEF\libcef.dll 2018-06-07 14:35 - 2018-06-07 14:35 - 002257360 _____ () C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\CEF\swiftshader\libglesv2.dll 2018-06-07 14:35 - 2018-06-07 14:35 - 000110544 _____ () C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\CEF\swiftshader\libegl.dll 2018-05-28 16:21 - 2009-02-27 16:38 - 000139264 ____R () C:\Program Files (x86)\Brother\BrUtilities\BrLogAPI.dll 2018-04-12 21:33 - 2018-04-12 21:33 - 000142376 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\js\node_modules\fs-ext\build\Release\fs-ext.node 2018-04-12 21:33 - 2018-04-12 21:33 - 000271400 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\js\node_modules\node-vulcanjs\build\Release\VulcanJS.node 2018-04-12 21:33 - 2018-04-12 21:33 - 000141864 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\js\node_modules\ref\build\Release\binding.node 2018-04-12 21:33 - 2018-04-12 21:33 - 000150568 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\js\node_modules\ffi\build\Release\ffi_bindings.node 2018-04-12 21:33 - 2018-04-12 21:33 - 000111144 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\js\node_modules\node-ProxyResolver\build\Release\ProxyResolverWin7.dll 2018-04-12 21:33 - 2018-04-12 21:33 - 000110120 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\js\node_modules\idle-gc\build\Release\idle-gc.node 2018-06-28 10:46 - 2018-06-28 10:46 - 000125976 _____ () \\?\C:\Program Files (x86)\Common Files\Adobe\Creative Cloud Libraries\js\node_modules\fs-ext\build\Release\fs-ext.node 2018-06-28 10:46 - 2018-06-28 10:46 - 000124952 _____ () \\?\C:\Program Files (x86)\Common Files\Adobe\Creative Cloud Libraries\js\node_modules\ref\build\Release\binding.node 2018-06-28 10:46 - 2018-06-28 10:46 - 000133144 _____ () \\?\C:\Program Files (x86)\Common Files\Adobe\Creative Cloud Libraries\js\node_modules\ffi\build\Release\ffi_bindings.node 2018-06-28 10:46 - 2018-06-28 10:46 - 000222232 _____ () \\?\C:\Program Files (x86)\Common Files\Adobe\Creative Cloud Libraries\js\node_modules\node-vulcanjs\build\Release\VulcanJS.node 2018-06-28 10:46 - 2018-06-28 10:46 - 000111128 _____ () C:\Program Files (x86)\Common Files\Adobe\Creative Cloud Libraries\js\node_modules\node-ProxyResolver\build\Release\ProxyResolverWin7.dll 2018-06-28 10:46 - 2018-06-28 10:46 - 000106520 _____ () \\?\C:\Program Files (x86)\Common Files\Adobe\Creative Cloud Libraries\js\node_modules\bufferutil\build\Release\bufferutil.node 2018-06-28 10:46 - 2018-06-28 10:46 - 000094232 _____ () \\?\C:\Program Files (x86)\Common Files\Adobe\Creative Cloud Libraries\js\node_modules\idle-gc\build\Release\idle-gc.node ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\Windows:nlsPreferences [386] AlternateDataStreams: C:\ProgramData\Temp:D1B5B4F1 [226] ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) IE trusted site: HKU\S-1-5-21-1963740025-2681597282-1959595548-1001\...\dell.com -> dell.com ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 03:34 - 2009-06-10 22:00 - 000000824 _____ C:\Windows\system32\Drivers\etc\hosts ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-1963740025-2681597282-1959595548-1001\Control Panel\Desktop\\Wallpaper -> DNS Servers: 192.168.1.254 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) MpsSvc => Firewall Service is not running. bfe => Firewall Service is not running. ==================== MSCONFIG/TASK MANAGER disabled items == MSCONFIG\Services: AdobeARMservice => 2 MSCONFIG\Services: AERTFilters => 2 MSCONFIG\Services: Apple Mobile Device => 2 MSCONFIG\Services: gupdate => 2 MSCONFIG\Services: gupdatem => 3 MSCONFIG\Services: iPod Service => 3 MSCONFIG\Services: MyWiFiDHCPDNS => 3 MSCONFIG\Services: RealNetworks Downloader Resolver Service => 2 MSCONFIG\Services: SkypeUpdate => 2 MSCONFIG\Services: ss_conn_service => 2 MSCONFIG\Services: SwitchBoard => 3 MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk => C:\Windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup MSCONFIG\startupfolder: C:^Users^Dee^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk => C:\Windows\pss\Dropbox.lnk.Startup MSCONFIG\startupfolder: C:^Users^Dee^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Intel(R) Turbo Boost Technology Monitor 2.0.lnk => C:\Windows\pss\Intel(R) Turbo Boost Technology Monitor 2.0.lnk.Startup MSCONFIG\startupfolder: C:^Users^Dee^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.3.lnk => C:\Windows\pss\OpenOffice.org 3.3.lnk.Startup MSCONFIG\startupreg: AccuWeatherWidget => "C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe" "C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\start.umj" --startup MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" MSCONFIG\startupreg: Adobe Creative Cloud => "C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true MSCONFIG\startupreg: Adobe Reader Speed Launcher => "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" MSCONFIG\startupreg: AdobeAAMUpdater-1.0 => "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" MSCONFIG\startupreg: AdobeBridge => "C:\Program Files (x86)\Adobe\Adobe Bridge CS5.1\Bridge.exe" -stealth MSCONFIG\startupreg: AdobeCS5.5ServiceManager => "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" MSCONFIG\startupreg: Dell Webcam Central => "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2 MSCONFIG\startupreg: Desktop Disc Tool => "C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe" MSCONFIG\startupreg: DivXUpdate => "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW MSCONFIG\startupreg: Dropbox Update => "C:\Users\Dee\AppData\Local\Dropbox\Update\DropboxUpdate.exe" /c MSCONFIG\startupreg: Facebook Update => "C:\Users\Dee\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver MSCONFIG\startupreg: FreeFallProtection => C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe MSCONFIG\startupreg: Google Update => "C:\Users\Dee\AppData\Local\Google\Update\GoogleUpdate.exe" /c MSCONFIG\startupreg: hpqSRMon => C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe" MSCONFIG\startupreg: MITSUBISHI CP70D Series(USB) => C:\Windows\system32\spool\DRIVERS\x64\3\CPD70NM.EXE MSCONFIG\startupreg: NeroLauncher => C:\Program Files (x86)\Nero\SyncUP\NeroLauncher.exe 900 MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun MSCONFIG\startupreg: Spotify Web Helper => "C:\Users\Dee\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" MSCONFIG\startupreg: SwitchBoard => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe MSCONFIG\startupreg: TkBellExe => "c:\program files (x86)\real\realplayer\Update\realsched.exe" -osboot MSCONFIG\startupreg: VodafoneMobileWiFi => C:\Program Files (x86)\Vodafone\Vodafone Mobile Wi-Fi\Launcher.exe ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{02DA652A-16E6-48F2-AF5E-4B53B01F006F}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe FirewallRules: [{4424B0A8-458A-4845-826B-7D26B5C40DCA}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe FirewallRules: [{571B6D8D-845C-4A7A-90FF-F0FA7D2C4DE4}] => (Allow) C:\Program Files (x86)\Intel Corporation\Intel WiDi\WiDiApp.exe FirewallRules: [{18B9B181-C6FA-4A1E-97A7-05578B4CA06F}] => (Allow) c:\Program Files (x86)\Dell\VideoStage\VideoStage.exe FirewallRules: [{F78820C6-5416-4F16-848F-B359DD6DCB98}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe FirewallRules: [{857F8729-63F6-4FFC-BA09-2FC95DD88015}] => (Allow) LPort=2869 FirewallRules: [{34DF7F21-90C3-4DD3-9DDB-290456F7A3AC}] => (Allow) LPort=1900 FirewallRules: [{185FCE41-B2E2-4BE6-9243-965A9D15DDF3}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe FirewallRules: [{80BC65BC-430B-4414-BFDD-3BFD9B90A7C2}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe FirewallRules: [{42A3D445-AAC4-463E-AEEE-9A18121CA378}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe FirewallRules: [{4D755A9D-4085-4068-9025-6E231468DCAA}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe FirewallRules: [{5D3E4927-4A2E-4D6F-A58C-62BB4F0127B2}] => (Allow) C:\Program Files\dell stage\dell stage\accuweather\accuweather.exe FirewallRules: [{27289BC5-394C-460F-A0F7-BFF7D3DEC8D2}] => (Allow) C:\Program Files\dell stage\musicstage\musicstageengine.exe FirewallRules: [{72E21ACA-8C0A-4CF9-ADBD-028077B2CF9A}] => (Allow) C:\Program Files\dell stage\dell stage\stage_primary.exe FirewallRules: [{6B60F45B-B059-4654-A227-A9FEC8611E1E}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe FirewallRules: [{5AF0F9C6-9F3B-4875-9A7A-5EBB734D185C}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe FirewallRules: [{9BD12175-D259-40EC-9209-09DFCF71B297}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpofxm08.exe FirewallRules: [{043F1A77-9326-4606-B17E-9925EFC5A278}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposfx08.exe FirewallRules: [{B9063AA7-96AD-45C6-9B22-DE5E7A03E26B}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposid01.exe FirewallRules: [{C6D387B0-007B-4FDF-AB4F-C072206CA788}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqkygrp.exe FirewallRules: [{E396F851-9938-4B91-87E1-29EB4B66DE71}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcopy2.exe FirewallRules: [{6997D55F-5726-4DF1-8E66-3AD3F32B16C8}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpfccopy.exe FirewallRules: [{AAFD291A-0BE1-4F10-822A-64AB9510690D}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpzwiz01.exe FirewallRules: [{613BC8A5-9D82-4C1C-9D04-29A1BFF42BB2}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpoews01.exe FirewallRules: [{1E88C40D-B9A2-4AB9-96B7-FDFE2C10612A}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqnrs08.exe FirewallRules: [{D33588CE-821B-457D-84F3-8EDF8CA19359}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpiscnapp.exe FirewallRules: [{C86FE1B9-638E-4CED-AFCA-54C267385BC3}] => (Allow) C:\Program Files (x86)\common files\hp\digital imaging\bin\hpqphotocrm.exe FirewallRules: [{C3F73B4A-E8AF-40AD-BECA-031A6CF46A22}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqsudi.exe FirewallRules: [{25BBB996-1B3C-40C4-BF17-F6CCCBD06EC8}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqpsapp.exe FirewallRules: [{1E164486-E6A1-4034-AF17-6FB51A62C301}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpofxs08.exe FirewallRules: [{F1D9330D-8BA0-4821-9768-A3BEFD1555F7}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqfxt08.exe FirewallRules: [{6B9084D1-AA10-4F3E-B7C7-5939916387E7}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqpse.exe FirewallRules: [{739D24EC-7281-4EF2-83B8-71EA1419B59D}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgplgtupl.exe FirewallRules: [{A00B1A38-FB02-45CD-ADF3-6E451F44BFB6}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe FirewallRules: [{D2C130D1-E23D-4BBA-A323-807C6B9C7FB3}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgm.exe FirewallRules: [{5278C2AF-DAB2-4D33-A90C-80D743A1787F}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgh.exe FirewallRules: [{D5B66415-0B45-407E-A60C-E756BE5A1027}] => (Allow) C:\Program Files (x86)\HP\hp software update\hpwucli.exe FirewallRules: [{85233C49-EF95-4F0E-B390-74B9ACFC1110}] => (Allow) C:\Program Files (x86)\HP\digital imaging\smart web printing\smartwebprintexe.exe FirewallRules: [{F1F32619-B695-446C-96E2-D60F46EFAF9D}] => (Allow) C:\Program Files (x86)\AVG\AVG2012\avgmfapx.exe FirewallRules: [{1C1D0A20-7A33-41FB-839E-1EE75BD061C3}] => (Allow) C:\Program Files (x86)\AVG\AVG2012\avgmfapx.exe FirewallRules: [TCP Query User{7E1B0C1F-4F27-452D-ADB1-7E0D466FBC1C}C:\program files (x86)\dell\dell datasafe online\nobuclient.exe] => (Allow) C:\program files (x86)\dell\dell datasafe online\nobuclient.exe FirewallRules: [UDP Query User{9A08C883-414B-48D8-96AC-BFA9D9E404F9}C:\program files (x86)\dell\dell datasafe online\nobuclient.exe] => (Allow) C:\program files (x86)\dell\dell datasafe online\nobuclient.exe FirewallRules: [{C17AA92F-725F-41A1-8452-CC5E0722E0AA}] => (Allow) C:\Dg Foto Krafter\Krafter.exe FirewallRules: [{B54E58F3-0CA1-4D85-B799-54194F908383}] => (Allow) C:\Dg Foto Krafter\Krafter.exe FirewallRules: [{B8BB16C6-A080-40F2-A628-66B86C3A9421}] => (Allow) LPort=80 FirewallRules: [{6D208B5E-5266-43BC-B6AC-3A8A60C2D5A6}] => (Allow) C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\DeviceSetup.exe FirewallRules: [{1C4034EE-94CD-480F-BE75-B9741C834A10}] => (Allow) C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\DeviceSetup.exe FirewallRules: [{D584933B-FEE1-4D3B-990C-F39202EC7BC7}] => (Allow) C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\HPNetworkCommunicator.exe FirewallRules: [{83DC394F-8C8C-42B4-9821-088E9BD76D7A}] => (Allow) C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\HPNetworkCommunicator.exe FirewallRules: [{6A8731F7-9EB5-4D0D-AD6E-D6B345CD4FE8}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{A09D1B0A-BBF2-43B8-BDBA-10578E187E8B}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{F7C0E172-9309-47CB-9075-8628DD2CCD08}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{075B742F-166E-4209-8076-C428B981D2CB}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [TCP Query User{997DEC5D-FBF5-48F1-9A62-0B2031D066AE}C:\program files (x86)\1clickdownload\1clickdownloader.exe] => (Block) C:\program files (x86)\1clickdownload\1clickdownloader.exe FirewallRules: [UDP Query User{BAB95D7D-5515-4F7D-B3CE-5F3D287AE743}C:\program files (x86)\1clickdownload\1clickdownloader.exe] => (Block) C:\program files (x86)\1clickdownload\1clickdownloader.exe FirewallRules: [TCP Query User{087BEC6D-56E3-4B16-AEC0-7E98C2D445B7}C:\users\dee\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\dee\appdata\roaming\dropbox\bin\dropbox.exe FirewallRules: [UDP Query User{B7C85274-7ECF-4B8E-956D-C5AFB98F4428}C:\users\dee\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\dee\appdata\roaming\dropbox\bin\dropbox.exe FirewallRules: [TCP Query User{C0948D1A-ED0E-4991-974D-F71DC2FF93F6}C:\users\dee\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\dee\appdata\roaming\spotify\spotify.exe FirewallRules: [UDP Query User{07C0BE40-8EAE-4396-91D5-AAF7F44BE7EF}C:\users\dee\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\dee\appdata\roaming\spotify\spotify.exe FirewallRules: [TCP Query User{BEA28DDB-DB17-4017-8403-DA8C9BFC171D}C:\users\dee\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\dee\appdata\roaming\spotify\spotify.exe FirewallRules: [UDP Query User{C8BC0DA5-AFD0-43E9-9CAD-372AF972261C}C:\users\dee\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\dee\appdata\roaming\spotify\spotify.exe FirewallRules: [{1DE0B741-3584-4A28-B721-C33098C152C9}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe FirewallRules: [{F577CE83-E236-464D-87B1-7F74E156CD36}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe FirewallRules: [{681C0640-63A4-4FD1-A751-D7AC34D0EA2C}] => (Allow) C:\Users\Dee\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [{70E8BF2A-3750-4E27-958A-7DB514258CA3}] => (Allow) C:\Users\Dee\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [TCP Query User{4688DE00-19BA-48B7-AFFF-30D013CD91EC}C:\program files (x86)\java\jre7\bin\java.exe] => (Allow) C:\program files (x86)\java\jre7\bin\java.exe FirewallRules: [UDP Query User{0CAF8454-845A-4C9F-9015-55E1C0B82A23}C:\program files (x86)\java\jre7\bin\java.exe] => (Allow) C:\program files (x86)\java\jre7\bin\java.exe FirewallRules: [TCP Query User{FDBCEA23-6FE8-4812-9166-4F1B2BBE7F12}C:\program files (x86)\torntv.com\torntv downloader.exe] => (Allow) C:\program files (x86)\torntv.com\torntv downloader.exe FirewallRules: [UDP Query User{63C29F31-35BB-4BE1-AED6-5DC49FA61BE6}C:\program files (x86)\torntv.com\torntv downloader.exe] => (Allow) C:\program files (x86)\torntv.com\torntv downloader.exe FirewallRules: [TCP Query User{C992F1DC-B0C5-4A1A-8E99-E515887AE13F}C:\program files (x86)\torntv.com\torntv downloader.exe] => (Allow) C:\program files (x86)\torntv.com\torntv downloader.exe FirewallRules: [UDP Query User{AB961C7C-6E93-42B2-80B5-C301229B5384}C:\program files (x86)\torntv.com\torntv downloader.exe] => (Allow) C:\program files (x86)\torntv.com\torntv downloader.exe FirewallRules: [TCP Query User{E118AC15-3156-4431-B8D5-730139FBC1F2}C:\users\dee\appdata\local\google\chrome\application\chrome.exe] => (Allow) C:\users\dee\appdata\local\google\chrome\application\chrome.exe FirewallRules: [UDP Query User{E58FF997-BFB7-48F5-B700-A250D3D2A46D}C:\users\dee\appdata\local\google\chrome\application\chrome.exe] => (Allow) C:\users\dee\appdata\local\google\chrome\application\chrome.exe FirewallRules: [TCP Query User{EF95526F-57B9-4888-9D23-291E231943E8}C:\users\dee\appdata\local\google\chrome\application\chrome.exe] => (Allow) C:\users\dee\appdata\local\google\chrome\application\chrome.exe FirewallRules: [UDP Query User{E78B5850-68F1-4568-9919-85EC97A6458A}C:\users\dee\appdata\local\google\chrome\application\chrome.exe] => (Allow) C:\users\dee\appdata\local\google\chrome\application\chrome.exe FirewallRules: [{4AE60C33-464D-4D32-BA17-C29358033F2C}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [TCP Query User{93C35B76-7E49-4207-BA91-30BE9E83B630}C:\program files (x86)\camera bits\photo mechanic 5\photo mechanic.exe] => (Allow) C:\program files (x86)\camera bits\photo mechanic 5\photo mechanic.exe FirewallRules: [UDP Query User{17F3C017-A388-4535-B8F7-1A2C2601D425}C:\program files (x86)\camera bits\photo mechanic 5\photo mechanic.exe] => (Allow) C:\program files (x86)\camera bits\photo mechanic 5\photo mechanic.exe FirewallRules: [{E5B0FE8F-E392-4148-AB5A-FB58CFFB841F}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe FirewallRules: [{4EAD6F5C-6B7E-4E3F-A0F2-46573A50E42C}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe FirewallRules: [{0551ADFF-3A3B-44AC-AE4E-D8B2CD4BF513}] => (Allow) C:\Program Files (x86)\Popcorn Time\Updater.exe FirewallRules: [{3A5F603B-6EED-4FA4-8586-82E9D09E54E6}] => (Allow) C:\Program Files (x86)\Popcorn Time\Updater.exe FirewallRules: [TCP Query User{FC123F26-89D2-4EA3-B7C1-DEC87F8664A5}C:\program files\andy\andy.exe] => (Allow) C:\program files\andy\andy.exe FirewallRules: [UDP Query User{6C4DCF84-C9AC-43BC-9D02-3C0BBB9A8C0F}C:\program files\andy\andy.exe] => (Allow) C:\program files\andy\andy.exe FirewallRules: [{F1011503-4157-40CE-BD8E-AA3D87EA1B9B}] => (Block) C:\program files\andy\andy.exe FirewallRules: [{C7681677-03CA-4E34-8D6C-0DB4F877419E}] => (Block) C:\program files\andy\andy.exe FirewallRules: [{4CA5A033-608B-48B0-989F-04765DB7732F}] => (Allow) LPort=8888 FirewallRules: [TCP Query User{66858065-BEE7-4F96-9EA0-5B2497F7D3A4}C:\program files (x86)\seagate\seagate dashboard 2.0\dashboard.exe] => (Allow) C:\program files (x86)\seagate\seagate dashboard 2.0\dashboard.exe FirewallRules: [UDP Query User{51DDB93A-4847-4EE0-9C82-FF6F6CCFC87B}C:\program files (x86)\seagate\seagate dashboard 2.0\dashboard.exe] => (Allow) C:\program files (x86)\seagate\seagate dashboard 2.0\dashboard.exe FirewallRules: [{A71FB1C9-1A90-4FBB-9B66-C2A379106104}] => (Allow) LPort=8888 FirewallRules: [{972A3067-65DF-4BF8-9920-9E39DF803CD4}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe FirewallRules: [{37CDC656-A213-4989-B921-4B19C8370D15}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{63957389-9289-4FFE-B04E-8277A96B30FF}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{E5092428-AED9-4DDF-AE02-BB46902AE40F}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Restore Points ========================= 28-06-2018 23:18:35 Windows Update 03-07-2018 11:35:22 Windows Update ==================== Faulty Device Manager Devices ============= Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Microsoft Teredo Tunneling Adapter Description: Microsoft Teredo Tunneling Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (07/04/2018 10:52:21 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY) Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code. Error: (07/04/2018 10:52:21 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY) Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section. Error: (07/04/2018 10:48:24 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Error: (07/03/2018 04:12:15 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: Photoshop.exe, version: 19.1.5.61161, time stamp: 0x5b14ec8f Faulting module name: Photoshop.exe, version: 19.1.5.61161, time stamp: 0x5b14ec8f Exception code: 0xc0000005 Fault offset: 0x00000000095128df Faulting process id: 0x1338 Faulting application start time: 0x01d412d6dba1a78d Faulting application path: C:\Program Files\Adobe\Adobe Photoshop CC 2018\Photoshop.exe Faulting module path: C:\Program Files\Adobe\Adobe Photoshop CC 2018\Photoshop.exe Report Id: 77a8be22-7ed3-11e8-ba33-848f69b02f5d Error: (07/03/2018 12:41:59 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: Adobe QT32 Server.exe, version: 11.1.0.0, time stamp: 0x59784aad Faulting module name: QuickTime.qts_unloaded, version: 0.0.0.0, time stamp: 0x5180f322 Exception code: 0xc0000005 Fault offset: 0x5399cc49 Faulting process id: 0x1f68 Faulting application start time: 0x01d412b8564183f0 Faulting application path: C:\Program Files\Adobe\Adobe Lightroom Classic CC\Helpers\DynamicLinkMediaServer\dynamiclinkmediaserver\1.0\32\Adobe QT32 Server.exe Faulting module path: QuickTime.qts Report Id: 17ad4399-7eb6-11e8-ba33-848f69b02f5d Error: (07/03/2018 11:27:47 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY) Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code. Error: (07/03/2018 11:27:47 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY) Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section. Error: (07/03/2018 11:21:39 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. System errors: ============= Error: (07/04/2018 12:04:11 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: The Base Filtering Engine service terminated with the following error: Access is denied. Error: (07/04/2018 12:04:11 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The Windows Firewall service depends on the Base Filtering Engine service which failed to start because of the following error: Access is denied. Error: (07/04/2018 12:03:42 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: The Base Filtering Engine service terminated with the following error: Access is denied. Error: (07/04/2018 12:03:42 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The Windows Firewall service depends on the Base Filtering Engine service which failed to start because of the following error: Access is denied. Error: (07/04/2018 12:03:38 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The Windows Firewall service depends on the Base Filtering Engine service which failed to start because of the following error: Access is denied. Error: (07/04/2018 12:03:38 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: The Base Filtering Engine service terminated with the following error: Access is denied. Error: (07/04/2018 12:03:30 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The Windows Firewall service depends on the Base Filtering Engine service which failed to start because of the following error: Access is denied. Error: (07/04/2018 12:03:30 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: The Base Filtering Engine service terminated with the following error: Access is denied. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i7-2630QM CPU @ 2.00GHz Percentage of memory in use: 75% Total physical RAM: 6038.17 MB Available physical RAM: 1507.14 MB Total Virtual: 12074.5 MB Available Virtual: 7626.01 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:446.13 GB) (Free:132.86 GB) NTFS Drive d: () (Fixed) (Total:465.76 GB) (Free:193.66 GB) NTFS Drive h: (Seagate 2016 small black) (Fixed) (Total:3725.91 GB) (Free:969.22 GB) NTFS \\?\Volume{42d7455c-f312-11e0-a1aa-806e6f6e6963}\ (RECOVERY) (Fixed) (Total:19.53 GB) (Free:10.74 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 465.8 GB) (Disk ID: 07F2837E) Partition 1: (Not Active) - (Size=102 MB) - (Type=DE) Partition 2: (Active) - (Size=19.5 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=446.1 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7/8/10) (Size: 465.8 GB) (Disk ID: F89FC0B0) Partition 1: (Not Active) - (Size=465.8 GB) - (Type=07 NTFS) ======================================================== Disk: 2 (Size: 3726 GB) (Disk ID: D3E45BC4) Partition: GPT. ==================== End of Addition.txt ============================