Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02.08.2018 Ran by [removed] (18-08-2018 22:10:29) Running from E:\Downloads Windows 7 Professional Service Pack 1 (X64) (2012-06-25 15:12:56) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Admin (S-1-5-21-1067577084-1865836317-3027311478-1000 - Administrator - Enabled) => C:\Users\Admin Administrator (S-1-5-21-1067577084-1865836317-3027311478-500 - Administrator - Disabled) Alex (S-1-5-21-1067577084-1865836317-3027311478-1004 - Limited - Enabled) => C:\Users\Alex Andy (S-1-5-21-1067577084-1865836317-3027311478-1003 - Administrator - Enabled) => C:\Users\Andy Charlotte (S-1-5-21-1067577084-1865836317-3027311478-1005 - Limited - Enabled) => C:\Users\Charlotte Guest (S-1-5-21-1067577084-1865836317-3027311478-501 - Limited - Enabled) => C:\Users\Guest HomeGroupUser$ (S-1-5-21-1067577084-1865836317-3027311478-1002 - Limited - Enabled) Julie (S-1-5-21-1067577084-1865836317-3027311478-1006 - Limited - Enabled) => C:\Users\Julie ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B} AV: Bitdefender Antivirus (Enabled - Up to date) {0E17DB7D-A20F-62CE-B95B-17DB0CDFE318} AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Bitdefender Antispyware (Enabled - Up to date) {B5763A99-8435-6D40-83EB-2CA97758A9A5} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Acrobat 9 Pro (HKLM-x32\...\{AC76BA86-1033-0000-7760-000000000004}{AC76BA86-1033-0000-7760-000000000004}) (Version: 9.5.5 - Adobe Systems) Adobe Acrobat 9.5.5 - CPSID_83708 (HKLM-x32\...\{AC76BA86-1033-0000-7760-000000000004}_955) (Version: - Adobe Systems Incorporated) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 14.0.0.178 - Adobe Systems Incorporated) Adobe CSI CS4 x64 (HKLM\...\{8DAA31EB-6830-4006-A99F-4DF8AB24714F}) (Version: 1 - Adobe Systems Incorporated) Hidden Adobe Flash Player 30 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 30.0.0.154 - Adobe Systems Incorporated) Adobe Flash Player 30 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 30.0.0.154 - Adobe Systems Incorporated) Adobe InDesign CS4 (HKLM-x32\...\Adobe_1710d324011afc3e7658e969025f4ba) (Version: 6.0 - Adobe Systems Incorporated) Adobe InDesign CS4 Icon Handler x64 (HKLM\...\{B37A99DD-88E2-4ED0-80B4-1E054AB354BF}) (Version: 6.0 - Adobe Systems Incorporated) Hidden Adobe Media Player (HKLM-x32\...\com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.1 - Adobe Systems Incorporated) Aimersoft Helper Compact 2.5.2 (HKLM-x32\...\{405147F7-FCC5-499B-A27E-EA6BD4A80435}_is1) (Version: 2.5.2 - Aimersoft) ALDI Print Software (HKLM-x32\...\ALDI Print Software) (Version: 4.8.7 - CEWE COLOR AG u Co. OHG) AMD Software (HKLM\...\AMD Catalyst Install Manager) (Version: 18.5.1 - Advanced Micro Devices, Inc.) AnyRail5 (HKLM-x32\...\{D28B1ACE-B6C5-47EA-8261-76AA9973D512}) (Version: 5.25.2 - DRail Modelspoor Software) Hidden AnyRail5 (HKLM-x32\...\AnyRail5 5.25.2) (Version: 5.25.2 - DRail Modelspoor Software) AnyRail6 (HKLM-x32\...\{142C3679-5EC7-46EB-A2C2-31AC56DD3CF4}) (Version: 6.16.3 - DRail Modelspoor Software) Hidden AnyRail6 (HKLM-x32\...\AnyRail6 6.16.3) (Version: 6.16.3 - DRail Modelspoor Software) ASUS Product Register Program (HKLM-x32\...\{C87D79F6-F813-4812-B7A9-CCCAAB8B1188}) (Version: 1.0.031 - ASUSTek Computer Inc.) AVEO USB2.0 PC Camera (HKLM-x32\...\{7235252A-39A3-4889-AF58-18B82040310E}) (Version: 1.0.0.6 - AVEO) BBC iPlayer Downloads (HKLM-x32\...\{476A047B-BDA1-4B37-BB40-0710C7E9EB61}) (Version: 1.4.1 - BBC) Bitdefender Agent (HKLM\...\Bitdefender Agent) (Version: 1.0.1 - Bitdefender) Bitdefender Antivirus Plus (HKLM\...\Bitdefender) (Version: 23.0.8.20 - Bitdefender) Canon MG7500 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG7500_series) (Version: 1.00 - Canon Inc.) Canon MG7500 series User Registration (HKLM-x32\...\Canon MG7500 series User Registration) (Version: - ‭Canon Inc.) Canon Utilities EOS Utility 2 (HKLM-x32\...\EOS Utility 2) (Version: 2.14.0.0 - Canon Inc.) Canon Utilities PhotoStitch (HKLM-x32\...\PhotoStitch) (Version: 3.1.23.47 - Canon Inc.) CCleaner (HKLM\...\CCleaner) (Version: 5.44 - Piriform) Connect (HKLM-x32\...\{B29AD377-CC12-490A-A480-1452337C618D}) (Version: 1.0.0.1 - Adobe Systems Incorporated) Hidden Corel Applications (HKLM-x32\...\Corel Applications) (Version: - ) Corel KPT Collection (HKLM-x32\...\_{5ACF958F-3106-4F13-B947-FC6DF23E1A53}) (Version: 1.0.0.103 - Corel Corporation) Corel KPT Collection (HKLM-x32\...\{5ACF958F-3106-4F13-B947-FC6DF23E1A53}) (Version: 1.0.0.103 - Corel Corporation) Hidden Corel Paint Shop Pro Photo X2 (HKLM-x32\...\{64E72FB1-2343-4977-B4A8-262CD53D0BD3}) (Version: 12.50.0001 - Corel Corporation) Corel PaintShop Pro 2018 (HKLM-x32\...\_{6000096B-318C-40F8-A450-043B6A602D16}) (Version: 20.2.0.1 - Corel Corporation) Corel PaintShop Pro X6 (HKLM-x32\...\_{166D1CB6-DD8A-40DD-9E25-4D31D2D6DE4D}) (Version: 16.2.0.20 - Corel Corporation) Corel PaintShop Pro X6 (HKLM-x32\...\{161AB62E-65D6-46E5-B3D8-2AC15D3B920B}) (Version: 16.2.0.20 - Corel Corporation) Hidden Corel Update Manager (HKLM\...\{67881956-8135-4804-9465-BA1419010638}) (Version: 2.9.389 - Corel corporation) Hidden Creative Content (HKLM-x32\...\_{696F7D83-CB87-471A-A37A-E09F758733C9}) (Version: 1.0.0.103 - Corel Corporation) Hidden Creative Content (HKLM-x32\...\{696F7D83-CB87-471A-A37A-E09F758733C9}) (Version: 1.0.0.103 - Corel Corporation) Hidden Cybereason RansomFree 2.4.2.0 (HKLM-x32\...\{2A15E1FB-A1F5-4F11-B033-D8DB1E37C1E9}) (Version: 2.4.2.0 - Cybereason Inc.) D3DX10 (HKLM-x32\...\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden Dropbox (HKU\S-1-5-21-1067577084-1865836317-3027311478-1003\...\Dropbox) (Version: 55.4.171 - Dropbox, Inc.) Dropbox (HKU\S-1-5-21-1067577084-1865836317-3027311478-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08182018021844803\...\Dropbox) (Version: 55.4.171 - Dropbox, Inc.) Dropbox (HKU\S-1-5-21-1067577084-1865836317-3027311478-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08182018021848422\...\Dropbox) (Version: 55.4.171 - Dropbox, Inc.) Facebook Video Calling 3.1.0.521 (HKLM-x32\...\{2091F234-EB58-4B80-8C96-8EB78C808CF7}) (Version: 3.1.521 - Skype Limited) FlvPlayer (HKU\S-1-5-21-1067577084-1865836317-3027311478-1003\...\FlvPlayer) (Version: ${VERSION} - ) <==== ATTENTION FlvPlayer (HKU\S-1-5-21-1067577084-1865836317-3027311478-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08182018021844803\...\FlvPlayer) (Version: ${VERSION} - ) <==== ATTENTION FlvPlayer (HKU\S-1-5-21-1067577084-1865836317-3027311478-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08182018021848422\...\FlvPlayer) (Version: ${VERSION} - ) <==== ATTENTION Free AVI Video Converter version 5.0.44.623 (HKLM-x32\...\Free AVI Video Converter_is1) (Version: 5.0.44.623 - DVDVideoSoft Ltd.) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 68.0.3440.106 - Google Inc.) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.17 - Google Inc.) Hidden Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden ICA (HKLM-x32\...\{166D1CB6-DD8A-40DD-9E25-4D31D2D6DE4D}) (Version: 16.1.0.48 - Corel Corporation) Hidden ICA (HKLM-x32\...\{6000096B-318C-40F8-A450-043B6A602D16}) (Version: 20.2.0.1 - Corel Corporation) Hidden Intel(R) Desktop Utilities (HKLM-x32\...\{D5712598-E05C-4B51-B97B-66A2EBC80170}) (Version: 3.2.1 - Intel Corporation) Hidden Intel(R) Desktop Utilities (HKLM-x32\...\InstallShield_{D5712598-E05C-4B51-B97B-66A2EBC80170}) (Version: 3.2.1 - Intel Corporation) Intel(R) Network Connections 16.8.46.0 (HKLM\...\PROSetDX) (Version: 16.8.46.0 - Intel) Intel(R) SMBus (HKLM\...\SMBus) (Version: - ) IPM_PSP_COM (HKLM-x32\...\{164D34E1-0271-4960-8A26-E8990A302DB1}) (Version: 16.1.0.48 - Corel Corporation) Hidden IPM_PSP_COM64 (HKLM\...\{1678F86C-889D-4198-8249-F4625058256B}) (Version: 16.1.0.48 - Corel Corporation) Hidden IPM_PSP_COM64 (HKLM\...\{2013AABB-7212-4D79-B13B-25E567C2D0E4}) (Version: 20.2.0.1 - Corel Corporation) Hidden Java 8 Update 40 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418040F0}) (Version: 8.0.400 - Oracle Corporation) Java 8 Update 40 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218040F0}) (Version: 8.0.400 - Oracle Corporation) JavaFX 2.1.1 (HKLM-x32\...\{1111706F-666A-4037-7777-211328764D10}) (Version: 2.1.1 - Oracle Corporation) KeepVid Pro(Build 6.4.1.1) (HKLM-x32\...\KeepVid Pro_is1) (Version: 6.4.1.1 - KeepVid Studio) kuler (HKLM-x32\...\{098727E1-775A-4450-B573-3F441F1CA243}) (Version: 2.0 - Adobe Systems Incorporated) Hidden Malwarebytes version 3.5.1.2522 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.5.1.2522 - Malwarebytes) Microsoft .NET Framework 4.7.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.02558 - Microsoft Corporation) Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUSR) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-1067577084-1865836317-3027311478-1003\...\OneDriveSetup.exe) (Version: 18.131.0701.0007 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-1067577084-1865836317-3027311478-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08182018021844803\...\OneDriveSetup.exe) (Version: 18.131.0701.0007 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-1067577084-1865836317-3027311478-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08182018021848422\...\OneDriveSetup.exe) (Version: 18.131.0701.0007 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24123 (HKLM-x32\...\{2cbcedbb-f38c-48a3-a3e1-6c6fd821a7f4}) (Version: 14.0.24123.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24123 (HKLM-x32\...\{206898cc-4b41-4d98-ac28-9f9ae57f91fe}) (Version: 14.0.24123.0 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Movie Maker (HKLM-x32\...\{38F03569-A636-4CF3-BDDE-032C8C251304}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Movie Maker (HKLM-x32\...\{DD67BE4B-7E62-4215-AFA3-F123A800A389}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Mozilla Firefox 61.0.2 (x64 en-US) (HKLM\...\Mozilla Firefox 61.0.2 (x64 en-US)) (Version: 61.0.2 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 61.0.2.6793 - Mozilla) MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) PDF Settings CS4 (HKLM-x32\...\{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}) (Version: 9.0 - Adobe Systems Incorporated) Hidden PHOTORECOVERY LE (HKLM-x32\...\{8D03A164-B586-4318-AFE6-870A5E2739C1}) (Version: 1.0.0 - LC Technology International) Photoshop Camera Raw (HKLM-x32\...\{CC75AB5C-2110-4A7F-AF52-708680D22FE8}) (Version: 5.0 - Adobe Systems Incorporated) Hidden PSPPContent (HKLM-x32\...\{162BD2D6-6C63-41A7-8151-93188450D36A}) (Version: 16.1.0.48 - Corel Corporation) Hidden PSPPContent (HKLM-x32\...\{CC719875-8939-48D2-BA50-D5F5673C4C6A}) (Version: 20.2.0.1 - Corel Corporation) Hidden PSPPHelp (HKLM-x32\...\{16346B2A-87BC-407C-9D6B-72A4D21ABF03}) (Version: 16.1.0.48 - Corel Corporation) Hidden PSPPHelp (HKLM-x32\...\{BBF5A9A0-82BD-4C51-9EAD-624651FE765B}) (Version: 20.2.0.1 - Corel Corporation) Hidden PSPPro64 (HKLM\...\{16582334-495C-4F1C-A66B-3BFD8866B674}) (Version: 16.2.0.20 - Corel Corporation) Hidden PSPPro64 (HKLM\...\{A8A7345E-0111-4A73-9F0F-560A837BF901}) (Version: 20.2.0.1 - Corel Corporation) Hidden QuickTime 7 (HKLM-x32\...\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}) (Version: 7.79.80.95 - Apple Inc.) Raptr (HKLM-x32\...\Raptr) (Version: - ) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6526 - Realtek Semiconductor Corp.) Recuva (HKLM\...\Recuva) (Version: 1.53 - Piriform) RemoteComms External Disk Access (HKLM-x32\...\{04FCD5DE-1662-4F99-BDA9-C57212113EF2}) (Version: 1.25.0003 - PLX Technology) Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.1.28.0 - Renesas Electronics Corporation) Hidden Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.1.28.0 - Renesas Electronics Corporation) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft) Setup (HKLM-x32\...\{16006EE1-DDB7-4E5F-8696-9FEF32C0151A}) (Version: 16.1.0.48 - Corel Corporation) Hidden Setup (HKLM-x32\...\{C9C9ACD1-F275-45CB-B507-96486DB5E608}) (Version: 20.2.0.1 - Corel Corporation) Hidden Skype™ 7.30 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.30.105 - Skype Technologies S.A.) Suite Shared Configuration CS4 (HKLM-x32\...\{842B4B72-9E8F-4962-B3C1-1C422A5C4434}) (Version: 1.0 - Adobe Systems Incorporated) Hidden TC (HKLM-x32\...\{9D244037-7E69-4D6E-9729-0797D9294831}) (Version: 1.00.000 - ) The Photographer's Ephemeris (HKLM-x32\...\{06B00A49-0278-FF02-5169-347BB52E7940}) (Version: 1.1.2 - UNKNOWN) Hidden The Photographer's Ephemeris (HKLM-x32\...\Flexrise.9F3FBFC56E7DF11606748B3513468A7A7FB809D1.1) (Version: 1.1.2 - UNKNOWN) Trainz (HKLM-x32\...\{F03D7004-F232-4B7A-A4A0-4B8FC118C4BD}) (Version: 1.00.000 - ) Trainz Paint Shed (HKLM-x32\...\{6202DCFE-2F03-445C-9885-CB54B062BC0F}) (Version: RC1 - ) Trainz Simulator 12 (HKLM-x32\...\AuranTS2009_is1) (Version: - Auran) trakaxPC (HKLM-x32\...\{F6E2EFE5-E14E-433D-997A-260C6A5EE050}) (Version: 5.10.3 - HighAndes) TRS2004 (HKLM-x32\...\{BDE1289F-4025-41A5-AD17-101DB4D82CA7}) (Version: 1.00.000 - ) TRS2006 (HKLM-x32\...\{5ED9E38C-9A96-49D8-89B3-92E278003FCF}) (Version: 1.00.000 - ) Visual Studio 2008 x64 Redistributables (HKLM-x32\...\{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}) (Version: 10.0.0.2 - AVG Technologies) Visual Studio 2010 x64 Redistributables (HKLM\...\{21B133D6-5979-47F0-BE1C-F6A6B304693F}) (Version: 13.0.0.1 - AVG Technologies) Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies) Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.) Vulkan Run Time Libraries 1.0.26.0 (HKLM\...\VulkanRT1.0.26.0) (Version: 1.0.26.0 - LunarG, Inc.) Vulkan Run Time Libraries 1.0.39.1 (HKLM\...\VulkanRT1.0.39.1) (Version: 1.0.39.1 - LunarG, Inc.) Vulkan Run Time Libraries 1.0.51.0 (HKLM\...\VulkanRT1.0.51.0) (Version: 1.0.51.0 - LunarG, Inc.) Vulkan Run Time Libraries 1.0.61.0 (HKLM\...\VulkanRT1.0.61.0) (Version: 1.0.61.0 - LunarG, Inc.) Hidden Vulkan Run Time Libraries 1.0.65.0 (HKLM\...\VulkanRT1.0.65.0) (Version: 1.0.65.0 - LunarG, Inc.) Hidden Vulkan Run Time Libraries 1.1.70.0 (HKLM\...\VulkanRT1.1.70.0) (Version: 1.1.70.0 - LunarG, Inc.) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation) XTrkCAD 4.0.3a (HKLM-x32\...\XTrkCAD 4.0.3a) (Version: 4.0.3a - hxxp://www.xtrkcad.org) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-1067577084-1865836317-3027311478-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08182018021844709_Classes\CLSID\{e8c77137-e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll => No File CustomCLSID: HKU\S-1-5-21-1067577084-1865836317-3027311478-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08182018021848344_Classes\CLSID\{e8c77137-e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll => No File CustomCLSID: HKU\S-1-5-21-1067577084-1865836317-3027311478-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08182018021844803_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Andy\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1067577084-1865836317-3027311478-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08182018021844803_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Andy\AppData\Roaming\Dropbox\bin\DropboxExt64.22.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1067577084-1865836317-3027311478-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08182018021844803_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Andy\AppData\Roaming\Dropbox\bin\DropboxExt64.22.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1067577084-1865836317-3027311478-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08182018021844803_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Andy\AppData\Roaming\Dropbox\bin\DropboxExt64.22.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1067577084-1865836317-3027311478-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08182018021844803_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Andy\AppData\Roaming\Dropbox\bin\DropboxExt64.22.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1067577084-1865836317-3027311478-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08182018021844803_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Andy\AppData\Roaming\Dropbox\bin\DropboxExt64.22.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1067577084-1865836317-3027311478-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08182018021844803_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Andy\AppData\Roaming\Dropbox\bin\DropboxExt64.22.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1067577084-1865836317-3027311478-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08182018021844803_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Andy\AppData\Roaming\Dropbox\bin\DropboxExt64.22.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1067577084-1865836317-3027311478-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08182018021844803_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Andy\AppData\Roaming\Dropbox\bin\DropboxExt64.22.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1067577084-1865836317-3027311478-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08182018021844803_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Andy\AppData\Roaming\Dropbox\bin\DropboxExt64.22.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1067577084-1865836317-3027311478-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08182018021844803_Classes\CLSID\{FB314EE1-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Andy\AppData\Roaming\Dropbox\bin\DropboxExt64.22.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1067577084-1865836317-3027311478-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08182018021844803_Classes\CLSID\{FB314EE2-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Andy\AppData\Roaming\Dropbox\bin\DropboxExt64.22.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1067577084-1865836317-3027311478-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08182018021844803_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\Andy\AppData\Roaming\Dropbox\bin\DropboxExt64.22.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1067577084-1865836317-3027311478-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08182018021848422_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Andy\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1067577084-1865836317-3027311478-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08182018021848422_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Andy\AppData\Roaming\Dropbox\bin\DropboxExt64.22.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1067577084-1865836317-3027311478-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08182018021848422_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Andy\AppData\Roaming\Dropbox\bin\DropboxExt64.22.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1067577084-1865836317-3027311478-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08182018021848422_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Andy\AppData\Roaming\Dropbox\bin\DropboxExt64.22.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1067577084-1865836317-3027311478-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08182018021848422_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Andy\AppData\Roaming\Dropbox\bin\DropboxExt64.22.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1067577084-1865836317-3027311478-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08182018021848422_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Andy\AppData\Roaming\Dropbox\bin\DropboxExt64.22.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1067577084-1865836317-3027311478-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08182018021848422_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Andy\AppData\Roaming\Dropbox\bin\DropboxExt64.22.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1067577084-1865836317-3027311478-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08182018021848422_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Andy\AppData\Roaming\Dropbox\bin\DropboxExt64.22.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1067577084-1865836317-3027311478-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08182018021848422_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Andy\AppData\Roaming\Dropbox\bin\DropboxExt64.22.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1067577084-1865836317-3027311478-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08182018021848422_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Andy\AppData\Roaming\Dropbox\bin\DropboxExt64.22.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1067577084-1865836317-3027311478-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08182018021848422_Classes\CLSID\{FB314EE1-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Andy\AppData\Roaming\Dropbox\bin\DropboxExt64.22.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1067577084-1865836317-3027311478-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08182018021848422_Classes\CLSID\{FB314EE2-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Andy\AppData\Roaming\Dropbox\bin\DropboxExt64.22.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1067577084-1865836317-3027311478-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08182018021848422_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\Andy\AppData\Roaming\Dropbox\bin\DropboxExt64.22.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1067577084-1865836317-3027311478-1003_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Andy\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1067577084-1865836317-3027311478-1003_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Andy\AppData\Roaming\Dropbox\bin\DropboxExt64.22.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1067577084-1865836317-3027311478-1003_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Andy\AppData\Roaming\Dropbox\bin\DropboxExt64.22.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1067577084-1865836317-3027311478-1003_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Andy\AppData\Roaming\Dropbox\bin\DropboxExt64.22.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1067577084-1865836317-3027311478-1003_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Andy\AppData\Roaming\Dropbox\bin\DropboxExt64.22.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1067577084-1865836317-3027311478-1003_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Andy\AppData\Roaming\Dropbox\bin\DropboxExt64.22.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1067577084-1865836317-3027311478-1003_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Andy\AppData\Roaming\Dropbox\bin\DropboxExt64.22.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1067577084-1865836317-3027311478-1003_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Andy\AppData\Roaming\Dropbox\bin\DropboxExt64.22.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1067577084-1865836317-3027311478-1003_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Andy\AppData\Roaming\Dropbox\bin\DropboxExt64.22.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1067577084-1865836317-3027311478-1003_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Andy\AppData\Roaming\Dropbox\bin\DropboxExt64.22.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1067577084-1865836317-3027311478-1003_Classes\CLSID\{FB314EE1-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Andy\AppData\Roaming\Dropbox\bin\DropboxExt64.22.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1067577084-1865836317-3027311478-1003_Classes\CLSID\{FB314EE2-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Andy\AppData\Roaming\Dropbox\bin\DropboxExt64.22.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1067577084-1865836317-3027311478-1003_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\Andy\AppData\Roaming\Dropbox\bin\DropboxExt64.22.0.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Andy\AppData\Roaming\Dropbox\bin\DropboxExt64.22.0.dll [2018-08-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Andy\AppData\Roaming\Dropbox\bin\DropboxExt64.22.0.dll [2018-08-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Andy\AppData\Roaming\Dropbox\bin\DropboxExt64.22.0.dll [2018-08-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Andy\AppData\Roaming\Dropbox\bin\DropboxExt64.22.0.dll [2018-08-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Andy\AppData\Roaming\Dropbox\bin\DropboxExt64.22.0.dll [2018-08-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Andy\AppData\Roaming\Dropbox\bin\DropboxExt64.22.0.dll [2018-08-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Andy\AppData\Roaming\Dropbox\bin\DropboxExt64.22.0.dll [2018-08-14] (Dropbox, Inc.) ContextMenuHandlers1: [Adobe.Acrobat.ContextMenu] -> {D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802} => C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\..\Acrobat Elements\ContextMenu64.dll [2013-05-08] (Adobe Systems Inc.) ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-05-09] (Malwarebytes) ContextMenuHandlers4: [RecuvaShellExt] -> {435E5DF5-2510-463C-B223-BDA47006D002} => C:\Program Files\Recuva\RecuvaShell64.dll [2016-06-06] (Piriform Ltd) ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Program Files\AMD\CNext\CNext\atiacm64.dll [2018-05-16] (Advanced Micro Devices, Inc.) ContextMenuHandlers6: [Adobe.Acrobat.ContextMenu] -> {D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802} => C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\..\Acrobat Elements\ContextMenu64.dll [2013-05-08] (Adobe Systems Inc.) ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-05-09] (Malwarebytes) ContextMenuHandlers6: [RecuvaShellExt] -> {435E5DF5-2510-463C-B223-BDA47006D002} => C:\Program Files\Recuva\RecuvaShell64.dll [2016-06-06] (Piriform Ltd) ContextMenuHandlers1_S-1-5-21-1067577084-1865836317-3027311478-1003: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Users\Andy\AppData\Roaming\Dropbox\bin\DropboxExt64.22.0.dll [2018-08-14] (Dropbox, Inc.) ContextMenuHandlers4_S-1-5-21-1067577084-1865836317-3027311478-1003: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Users\Andy\AppData\Roaming\Dropbox\bin\DropboxExt64.22.0.dll [2018-08-14] (Dropbox, Inc.) ContextMenuHandlers5_S-1-5-21-1067577084-1865836317-3027311478-1003: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Users\Andy\AppData\Roaming\Dropbox\bin\DropboxExt64.22.0.dll [2018-08-14] (Dropbox, Inc.) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {0D741F4C-602A-4B9C-BC99-413446493B96} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-06-25] (Adobe Systems Incorporated) Task: {157347A9-D7D0-4011-BF73-F8D53FD03493} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1067577084-1865836317-3027311478-1004Core => C:\Users\Alex\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-10-17] (Facebook Inc.) Task: {1C1AD407-2ED6-41E9-90E8-B5154EE39ADA} - System32\Tasks\Bitdefender Agent WatchDog_65D6944A0EF74FDAB96E31112AD39864 => C:\Program Files\Bitdefender Agent\WatchDog.exe [2018-07-31] (Bitdefender) Task: {1E5BA1F2-B8AF-4651-817A-847270BC1B71} - System32\Tasks\{A09B3FB5-9491-4076-9919-9A81FA8F183B} => C:\Program Files (x86)\Mozilla Firefox\firefox.exe Task: {26F576C5-C523-4653-AD94-092FDD264921} - System32\Tasks\StartDVR => C:\Program Files\AMD\CNext\CNext\dvrcmd.exe [2018-05-16] (Advanced Micro Devices, Inc.) Task: {49230476-A3F3-482E-BA9E-FE03748B8DA1} - System32\Tasks\Digital Sites => C:\Users\Andy\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: {49519E89-40FD-454A-818C-2C94B3B24365} - System32\Tasks\{F843FFE5-CA3C-49AF-8A27-6EC6911CAF35} => C:\Program Files (x86)\Mozilla Firefox\firefox.exe Task: {4D217076-BA1F-40E6-BBDC-F569F03C75FE} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-08-15] (Adobe Systems Incorporated) Task: {4DAC8FD0-7FBA-43FD-B3B0-E19EFB5F54EF} - System32\Tasks\CorelUpdateHelperTaskCore => c:\Program Files (x86)\Corel\CUH\v2\CUH.exe [2018-06-21] (Corel Corporation) Task: {53105B53-14F5-4558-9A2F-68429915D170} - System32\Tasks\{14EA3CE9-124F-483A-9078-584E67005FD7} => "c:\program files (x86)\mozilla firefox\firefox.exe" hxxp://ui.skype.com/ui/0/7.22.0.109/en/go/help.faq.installer?LastError=1603 Task: {5367361F-540F-46E9-8561-3BBEADE9B6E1} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.) Task: {5B7C91AD-626E-46B3-8871-B62731575750} - System32\Tasks\CorelUpdateHelperTask-8BD911328D29CA31D96C43134CB51E73 => C:\Program Files (x86)\Corel\CUH\v2\CUH.exe [2018-06-21] (Corel Corporation) Task: {663DF697-6631-4B2C-826F-416C05F2B5CE} - System32\Tasks\RealDownloader Update Check => C:\Program Files (x86)\RealNetworks\RealDownloader\downloader2.exe Task: {6831F37F-ACDF-45B4-B753-A822B2B1132D} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2018-08-10] (Piriform Ltd) Task: {72BF35DD-ABC4-46A4-B6AA-B6F0C8CE8D96} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1067577084-1865836317-3027311478-1004UA => C:\Users\Alex\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-10-17] (Facebook Inc.) Task: {8330406F-7498-4BAE-936C-83F3AA06FC15} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.) Task: {846C19AE-A616-468C-85F6-4AFAF3544F51} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_30_0_0_154_Plugin.exe [2018-08-15] (Adobe Systems Incorporated) Task: {9249D674-2C1C-4B4B-8D83-5FE131AEC72D} - System32\Tasks\Cybereason RansomFree Keepalive => C:\Program Files (x86)\Cybereason\RansomFree\CybereasonRansomFree.exe [2017-11-20] (Cybereason) Task: {9B8AC54E-306C-46F9-ACA0-2A68D13CA504} - System32\Tasks\{1D9544E5-6EE0-4C63-B9AC-B07C1BAD56B0} => "c:\program files (x86)\mozilla firefox\firefox.exe" hxxp://ui.skype.com/ui/0/7.28.80.101/en/go/help.faq.installer?LastError=1603 Task: {A28E7445-D86B-4179-8DE6-C5120183CCF4} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-1067577084-1865836317-3027311478-1003UA => C:\Users\Andy\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2016-12-27] (Dropbox, Inc.) Task: {AC49E5FD-8541-4FA2-A921-C1ADFAFCE71A} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-1067577084-1865836317-3027311478-1003Core => C:\Users\Andy\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2016-12-27] (Dropbox, Inc.) Task: {AEE38D03-1941-4B0D-BA4F-7F78B0C595DD} - \RealPlayer Cloud (32-bit) -> No File <==== ATTENTION Task: {B8589B9C-B7FE-408B-AFC3-7A806DFE0DC2} - System32\Tasks\Cybereason RansomFree Autostart => C:\Program Files (x86)\Cybereason\RansomFree\CybereasonRansomFree.exe [2017-11-20] (Cybereason) Task: {C96F4B89-888E-4067-96D5-B56F64503CC9} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [2018-08-10] (Piriform Ltd) Task: {D7747EE6-C8EB-47DE-AA66-072C30887E4B} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe [2018-05-16] (Advanced Micro Devices, Inc.) Task: {D91A1ECC-9D10-479B-ACAE-88D40411F228} - System32\Tasks\{52AB6CD0-B109-4859-A4B6-ED9FC74B5EDD} => C:\Program Files (x86)\Mozilla Firefox\firefox.exe Task: {F55A9C29-67F1-46FE-AE62-3FC5CB78B444} - System32\Tasks\ASUS\ASUS Product Register Service => C:\Program Files (x86)\ASUS\APRP\aprp.exe [2015-05-18] () Task: {F57AC780-2383-453F-85F9-8555B78A5FCF} - System32\Tasks\{F132A08C-E271-43D7-9678-FF8C1500F576} => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3utl.exe [2011-08-03] (Renesas Electronics Corporation) Task: {F64B55F9-0CB8-454C-8E84-EA5B4B3A56F4} - System32\Tasks\{EEF48E3E-9A0E-43B6-96CE-87CBD2E4643F} => "c:\program files (x86)\mozilla firefox\firefox.exe" hxxp://ui.skype.com/ui/0/7.28.80.101/en/abandoninstall?page=tsProgressBar Task: {FD65B0FC-8AAA-4002-B0B0-730F0910B732} - System32\Tasks\Adobe Reader and Acrobat Manager => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-06-25] (Adobe Systems Incorporated) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-1067577084-1865836317-3027311478-1003Core.job => C:\Users\Andy\AppData\Local\Dropbox\Update\DropboxUpdate.exe Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-1067577084-1865836317-3027311478-1003UA.job => C:\Users\Andy\AppData\Local\Dropbox\Update\DropboxUpdate.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1067577084-1865836317-3027311478-1004Core.job => C:\Users\Alex\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1067577084-1865836317-3027311478-1004UA.job => C:\Users\Alex\AppData\Local\Facebook\Update\FacebookUpdate.exe ==================== Shortcuts & WMI ======================== (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== 2018-08-10 20:54 - 2018-07-18 14:21 - 000993728 ____C () C:\Program Files\Bitdefender\Bitdefender Security\otengines_001_001\ashttpbr.mdl 2018-08-10 20:54 - 2018-07-18 14:21 - 000544880 ____C () C:\Program Files\Bitdefender\Bitdefender Security\otengines_001_001\ashttpdsp.mdl 2018-08-10 20:54 - 2018-07-18 14:21 - 003232216 ____C () C:\Program Files\Bitdefender\Bitdefender Security\otengines_001_001\ashttpph.mdl 2018-08-10 20:54 - 2018-07-18 14:21 - 001528320 ____C () C:\Program Files\Bitdefender\Bitdefender Security\otengines_001_001\ashttprbl.mdl 2018-08-18 21:42 - 2018-08-18 21:42 - 000066632 _____ () C:\Program Files\Common Files\Bitdefender\Bitdefender Threat Scanner\Antivirus_53401_099\bdcore.dll 2018-08-11 21:39 - 2018-08-18 01:31 - 002681424 ____C () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\SelfProtectionSdk.dll 2018-08-11 21:39 - 2018-08-18 01:31 - 002769768 ____C () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll 2013-09-05 01:17 - 2013-09-05 01:17 - 004300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF 2010-10-20 15:23 - 2010-10-20 15:23 - 008801632 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll 2018-04-24 22:12 - 2018-04-24 22:12 - 000015360 ____C () C:\Program Files\AMD\CNext\CNext\libEGL.DLL 2018-04-24 22:12 - 2018-04-24 22:12 - 002519040 ____C () C:\Program Files\AMD\CNext\CNext\libGLESv2.dll 2018-06-24 12:26 - 2018-06-24 12:26 - 000061408 _____ () C:\Program Files\CCleaner\branding.dll 2017-09-17 14:45 - 2017-09-06 10:16 - 000033912 _____ () C:\Program Files (x86)\Keepvid\KeepVid KeepVid Pro\KeepVidProUpdateHelper.exe 2018-08-08 23:36 - 2018-08-08 01:41 - 004855640 _____ () C:\Program Files (x86)\Google\Chrome\Application\68.0.3440.106\libglesv2.dll 2018-08-08 23:36 - 2018-08-08 01:41 - 000115544 _____ () C:\Program Files (x86)\Google\Chrome\Application\68.0.3440.106\libegl.dll 2013-12-17 10:31 - 2013-12-17 10:31 - 000491520 _____ () C:\Program Files (x86)\Canon\EOS Utility\EDSDK.dll 2017-09-17 14:46 - 2016-10-08 17:03 - 001506304 _____ () C:\Program Files (x86)\Common Files\Aimersoft\Aimersoft Helper Compact\DAQExp.dll 2017-09-17 14:46 - 2016-07-21 10:54 - 000137728 _____ () C:\Program Files (x86)\Common Files\Aimersoft\Aimersoft Helper Compact\CBSCreateVC.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\Windows:nlsPreferences [386] ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 03:34 - 2018-08-18 14:27 - 000000027 _____ C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-1067577084-1865836317-3027311478-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08182018021844709\Control Panel\Desktop\\Wallpaper -> C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg HKU\S-1-5-21-1067577084-1865836317-3027311478-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08182018021848344\Control Panel\Desktop\\Wallpaper -> C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg HKU\S-1-5-21-1067577084-1865836317-3027311478-1003\Control Panel\Desktop\\Wallpaper -> C:\Users\Andy\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg HKU\S-1-5-21-1067577084-1865836317-3027311478-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08182018021844803\Control Panel\Desktop\\Wallpaper -> C:\Users\Andy\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg HKU\S-1-5-21-1067577084-1865836317-3027311478-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08182018021848422\Control Panel\Desktop\\Wallpaper -> C:\Users\Andy\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg HKU\S-1-5-21-1067577084-1865836317-3027311478-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08182018021846019\Control Panel\Desktop\\Wallpaper -> C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg HKU\S-1-5-21-1067577084-1865836317-3027311478-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08182018021849748\Control Panel\Desktop\\Wallpaper -> C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg HKU\S-1-5-21-1067577084-1865836317-3027311478-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08182018021846129\Control Panel\Desktop\\Wallpaper -> C:\Users\Charlotte\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg HKU\S-1-5-21-1067577084-1865836317-3027311478-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08182018021849826\Control Panel\Desktop\\Wallpaper -> C:\Users\Charlotte\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg HKU\S-1-5-21-1067577084-1865836317-3027311478-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08182018021846191\Control Panel\Desktop\\Wallpaper -> C:\Users\Julie\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg HKU\S-1-5-21-1067577084-1865836317-3027311478-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08182018021849873\Control Panel\Desktop\\Wallpaper -> C:\Users\Julie\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg HKU\S-1-5-21-1067577084-1865836317-3027311478-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08182018021846269\Control Panel\Desktop\\Wallpaper -> C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg HKU\S-1-5-21-1067577084-1865836317-3027311478-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-08182018021849935\Control Panel\Desktop\\Wallpaper -> C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: [removed] - [removed] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^RealPlayer Cloud Service UI.lnk => C:\Windows\pss\RealPlayer Cloud Service UI.lnk.CommonStartup MSCONFIG\startupfolder: C:^Users^Andy^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk => C:\Windows\pss\Dropbox.lnk.Startup MSCONFIG\startupreg: Acrobat Assistant 8.0 => "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" MSCONFIG\startupreg: Corel Photo Downloader => "C:\Program Files (x86)\Common Files\Corel\Corel PhotoDownloader\Corel Photo Downloader.exe" -startup MSCONFIG\startupreg: Dropbox Update => "C:\Users\Andy\AppData\Local\Dropbox\Update\DropboxUpdate.exe" /c MSCONFIG\startupreg: NUSB3MON => "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" MSCONFIG\startupreg: OneDrive => "C:\Users\Andy\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe FirewallRules: [TCP Query User{4A5E4BA4-3C04-4499-9C7B-47FEC1FBB352}C:\users\alex\appdata\local\facebook\video\skype\facebookvideocalling.exe] => (Allow) C:\users\alex\appdata\local\facebook\video\skype\facebookvideocalling.exe FirewallRules: [UDP Query User{7BC725C3-9A35-40D3-A85D-48B6291591A8}C:\users\alex\appdata\local\facebook\video\skype\facebookvideocalling.exe] => (Allow) C:\users\alex\appdata\local\facebook\video\skype\facebookvideocalling.exe FirewallRules: [TCP Query User{4D65FCDC-F035-441E-9A57-B1E343D57481}E:\trainz12\bin\taddaemon.exe] => (Allow) E:\trainz12\bin\taddaemon.exe FirewallRules: [UDP Query User{251B5FE6-3EA2-4719-A62F-D6FFFBA6CE65}E:\trainz12\bin\taddaemon.exe] => (Allow) E:\trainz12\bin\taddaemon.exe FirewallRules: [{CE33BB58-E7BA-4A26-80B0-B2FD8D1F7E2E}] => (Allow) LPort=5353 FirewallRules: [{326D71BB-7146-4364-8530-60B376760458}] => (Allow) C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe FirewallRules: [{6A99FFEB-6672-437F-A43B-FDE7EA039F05}] => (Allow) C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe FirewallRules: [TCP Query User{22CBA910-1949-4494-973F-A73735F18F2F}D:\age2\age2_x1.exe] => (Block) D:\age2\age2_x1.exe FirewallRules: [UDP Query User{571D72AE-82EA-4221-BDD2-AB2C064956B5}D:\age2\age2_x1.exe] => (Block) D:\age2\age2_x1.exe FirewallRules: [{A10F3417-C52B-43B8-B018-1F3DC2E8EFF8}] => (Allow) C:\Program Files (x86)\Canon\EOS Utility\EOSUPNPSV.exe FirewallRules: [{5455A869-23C3-4C61-A0F5-EA601CB51E8F}] => (Allow) C:\Program Files (x86)\Canon\EOS Utility\EOSUPNPSV.exe FirewallRules: [{C23E2BD4-EE78-4BF7-B655-B340C65E0851}] => (Allow) C:\Users\Andy\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [{C1464C55-D6D7-48C4-835B-08BD9F2EC9E6}] => (Allow) C:\Users\Andy\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [{9B2438F2-1E5B-4CD2-A41F-563C112E1489}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe FirewallRules: [{7EFA2E7E-712E-40B1-BB90-0664CBAA84F9}] => (Allow) LPort=2869 FirewallRules: [{9E7C73E8-59DA-4C73-8F3F-A0604569613A}] => (Allow) LPort=1900 FirewallRules: [TCP Query User{B928C565-A32A-4182-B56C-11D30748A4A5}C:\users\andy\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\andy\appdata\roaming\dropbox\bin\dropbox.exe FirewallRules: [UDP Query User{ED55CE81-CB9A-42F4-956A-F58839CE7918}C:\users\andy\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\andy\appdata\roaming\dropbox\bin\dropbox.exe FirewallRules: [{31B8950A-FBB2-4D1D-BE83-5AFB7463D52D}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{6E6267E3-B5F1-4B58-A218-C96D3F648A0F}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [TCP Query User{CB6E3B68-0935-4D86-AE41-CE88EE0E90E5}C:\program files (x86)\microsoft office\office14\groove.exe] => (Block) C:\program files (x86)\microsoft office\office14\groove.exe FirewallRules: [UDP Query User{04E029B5-72D5-4693-82B7-B4603C8F5814}C:\program files (x86)\microsoft office\office14\groove.exe] => (Block) C:\program files (x86)\microsoft office\office14\groove.exe FirewallRules: [{47F5E608-3E2B-434E-967F-DC1D26A2B28D}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{6F54F25F-4682-471E-9055-A1E22F5D4F07}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{BFF39FCC-BCBF-4377-98E1-E89709F4BE2B}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{DCF8C35D-6E9A-4897-B39A-8252C0218B88}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Restore Points ========================= 12-08-2018 19:00:20 Windows Backup 15-08-2018 03:01:54 Windows Update ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (08/17/2018 06:38:05 PM) (Source: Microsoft Office 14) (EventID: 2000) (User: ) Description: Microsoft Word: Accepted Safe Mode action : Word failed to start correctly last time. Starting Word in safe mode will help you correct or isolate a startup problem in order to successfully start the program. Some functionality may be disabled in this mode. Do you want to start Word in safe mode?. Accepted Safe Mode action : Microsoft Word. Error: (08/17/2018 07:29:14 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Error: (08/17/2018 06:55:11 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Error: (08/16/2018 09:04:59 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Error: (08/15/2018 03:37:34 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Error: (08/15/2018 03:17:30 AM) (Source: .NET Runtime Optimization Service) (EventID: 1101) (User: ) Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - 1>Failed to compile: System.Workflow.Runtime, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35 . Error code = 0x80070005 Error: (08/15/2018 03:16:51 AM) (Source: .NET Runtime Optimization Service) (EventID: 1101) (User: ) Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - 1>Failed to compile: System.Web.Services, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a . Error code = 0x80070005 Error: (08/15/2018 03:16:08 AM) (Source: .NET Runtime Optimization Service) (EventID: 1101) (User: ) Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - 1>Failed to compile: System.Web, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a . Error code = 0x80070005 System errors: ============= Error: (08/18/2018 03:51:39 AM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY) Description: The following fatal alert was received: 70. Error: (08/17/2018 07:28:34 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID {C97FCC79-E628-407D-AE68-A06AD6D8B4D1} and APPID {344ED43D-D086-4961-86A6-1106F4ACAD9B} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool. Error: (08/17/2018 06:55:58 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID {C97FCC79-E628-407D-AE68-A06AD6D8B4D1} and APPID {344ED43D-D086-4961-86A6-1106F4ACAD9B} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool. Error: (08/16/2018 09:04:16 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID {C97FCC79-E628-407D-AE68-A06AD6D8B4D1} and APPID {344ED43D-D086-4961-86A6-1106F4ACAD9B} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool. Error: (08/15/2018 03:37:24 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID {C97FCC79-E628-407D-AE68-A06AD6D8B4D1} and APPID {344ED43D-D086-4961-86A6-1106F4ACAD9B} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool. Error: (08/11/2018 09:42:51 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY) Description: The following fatal alert was received: 70. Error: (08/11/2018 09:42:51 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY) Description: The following fatal alert was generated: 10. The internal error state is 10. Error: (08/11/2018 09:22:43 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID {C97FCC79-E628-407D-AE68-A06AD6D8B4D1} and APPID {344ED43D-D086-4961-86A6-1106F4ACAD9B} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool. CodeIntegrity: =================================== Date: 2012-12-20 14:06:02.382 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2012-12-20 14:06:02.366 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i7-2600K CPU @ 3.40GHz Percentage of memory in use: 82% Total physical RAM: 8161.41 MB Available physical RAM: 1435.85 MB Total Virtual: 16320.97 MB Available Virtual: 8034.16 MB ==================== Drives ================================ Drive a: () (Network) (Total:447.03 GB) (Free:104.21 GB) NTFS Drive c: () (Fixed) (Total:447.03 GB) (Free:104.21 GB) NTFS Drive d: (Trains @ Trinity) (CDROM) (Total:0.69 GB) (Free:0.66 GB) UDF Drive e: (Drive2) (Fixed) (Total:931.51 GB) (Free:0.05 GB) NTFS \\?\Volume{3f686d8e-bed7-11e1-8ac7-806e6f6e6963}\ (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS ==================== MBR & Partition Table ================== ==================== End of Addition.txt ============================