Additional scan result of Farbar Recovery Scan Tool (x64) Version: 29-03-2020 Ran by chris (31-03-2020 14:12:31) Running from C:\Users\chris\Desktop Windows 10 Pro Version 1909 18363.720 (X64) (2020-03-28 19:33:53) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-1547701397-687303812-3400344658-500 - Administrator - Enabled) => C:\Users\Administrator chris (S-1-5-21-1547701397-687303812-3400344658-1001 - Limited - Enabled) => C:\Users\chris DefaultAccount (S-1-5-21-1547701397-687303812-3400344658-503 - Limited - Disabled) defaultuser0 (S-1-5-21-1547701397-687303812-3400344658-1000 - Limited - Disabled) => C:\Users\defaultuser0 Guest (S-1-5-21-1547701397-687303812-3400344658-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-1547701397-687303812-3400344658-1003 - Limited - Enabled) WDAGUtilityAccount (S-1-5-21-1547701397-687303812-3400344658-504 - Limited - Disabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: McAfee VirusScan (Disabled - Up to date) {F682A51C-4EAD-6A3A-F460-B9C1D4A2DB09} AV: McAfee VirusScan (Disabled - Up to date) {9D4501E6-72F6-2877-C789-89AF6F535B2C} AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B} AS: McAfee VirusScan (Disabled - Up to date) {4DE344F8-6897-65B4-CED0-82B3AF2591B4} AS: McAfee VirusScan (Disabled - Up to date) {2624E002-54CC-27F9-FD39-B2DD14D41191} AS: Malwarebytes (Disabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: McAfee Firewall (Disabled) {A57E80C3-3899-292F-ECD6-209A91801C57} FW: McAfee Firewall (Disabled) {CEB92439-04C2-6B62-DF3F-10F42A719C72} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Act! (HKLM-x32\...\{890CAC1B-C777-4DBD-95E8-7844A64243A1}) (Version: 22.0.205.0 - Swiftpage ACT! LLC) Hidden Act! (HKLM-x32\...\InstallShield_{890CAC1B-C777-4DBD-95E8-7844A64243A1}) (Version: 22.0.205.0 - Swiftpage ACT! LLC) Act! Connect Link version 1.1.9 (HKLM\...\{CBDA6D20-FF3D-48F5-8EC7-3B89BD47C24D}_is1) (Version: 1.1.9 - Cloud Elements) Actian Btrieve 12 (HKLM\...\{0A3238D7-BB64-1206-B717-F3E3F18B4A8C}) (Version: 12.06.017 - Actian Corporation) Hidden Actian Btrieve 12 (HKLM\...\Actian Btrieve 12) (Version: 12.06.017 - Actian Corporation) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 28.0.0.127 - Adobe Systems Incorporated) AnyTrans (HKLM-x32\...\AnyTrans) (Version: 6.3.6.0 - iMobie Inc.) Apple Application Support (32-bit) (HKLM-x32\...\{BED24701-751B-41C5-8888-A8EABAB9FE8C}) (Version: 8.1 - Apple Inc.) Apple Application Support (64-bit) (HKLM\...\{88F21C94-88AF-4665-AF4F-FECB1FA059B9}) (Version: 8.1 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{45DDDFED-AABC-450C-B49C-5B4A5E547F5B}) (Version: 13.0.0.38 - Apple Inc.) Apple Software Update (HKLM-x32\...\{A3985C05-7386-411F-A4BF-32A73F37EB44}) (Version: 2.6.3.1 - Apple Inc.) Applian Director (HKLM-x32\...\Applian Director3.02) (Version: 3.02 - Applian Technologies Inc.) Audacity 2.3.3 (HKLM-x32\...\Audacity_is1) (Version: 2.3.3 - Audacity Team) AVS Audio Editor 8.4.4 (HKLM-x32\...\AVS Audio Editor_is1) (Version: 8.4.4.521 - Online Media Technologies Ltd.) AVS Video Converter 10.0.4 (HKLM-x32\...\AVS4YOU Video Converter 7_is1) (Version: 10.0.4.616 - Online Media Technologies Ltd.) AVS Video Editor 8.0.4 (HKLM-x32\...\AVS Video Editor_is1) (Version: 8.0.4.305 - Online Media Technologies Ltd.) Basecamp 3 (HKU\S-1-5-21-1547701397-687303812-3400344658-1001\...\basecamp3) (Version: 2.0.0 - Basecamp, LLC) Bookmark Buddy (HKLM-x32\...\Bookmark Buddy) (Version: - ) BRC Excel to QIF Converter (HKLM-x32\...\Excel to QIF Converter) (Version: 7.79 - Big Red Consulting) Carbonite (HKLM-x32\...\{9C78C26C-C5B3-4B1C-8B13-802223B2614D}) (Version: 6.3.5 build 8094 (Apr-30-2019) - Carbonite) CCleaner (HKLM\...\CCleaner) (Version: 5.63 - Piriform) Cisco Webex Meetings (HKU\S-1-5-21-1547701397-687303812-3400344658-1001\...\ActiveTouchMeetingClient) (Version: 39.11.0 - Cisco Webex LLC) ClipMate 7 (HKLM-x32\...\{2E924A2A-8FBC-4C84-8A3A-63FB386C9A29}_is1) (Version: 7 - Thornsoft Development, Inc.) Defraggler (HKLM\...\Defraggler) (Version: 2.22 - Piriform) Dolby Digital Plus Advanced Audio (HKLM\...\{B0BFC63F-EA07-419E-960B-3FB2ED5DD0B2}) (Version: 7.6.3.1 - Dolby Laboratories Inc) Dropbox (HKLM-x32\...\Dropbox) (Version: 93.4.273 - Dropbox, Inc.) Dropbox Update Helper (HKLM-x32\...\{099218A5-A723-43DC-8DB5-6173656A1E94}) (Version: 1.3.295.1 - Dropbox, Inc.) Hidden Duplicate Email Remover (HKLM-x32\...\{7AA36634-4324-4EF4-8C0C-D8EF1FC2BEA4}) (Version: 3.2.0 - MAPILab Ltd.) Duplicate Files Fixer (HKLM-x32\...\DA71BA65-680A-4212-9150-6239217B53DC_Systweak_Du~3015B8CD_is1) (Version: 1.1.1000.5885 - Systweak Software) <==== ATTENTION Easy Duplicate Finder 5 (HKLM\...\{DA060B99-6B87-4D85-8B1A-29BCF6DF2B06}_is1) (Version: 5.19.1.1041 - WebMinds, Inc.) Express Scribe Transcription Software (HKLM-x32\...\Scribe) (Version: 6.10 - NCH Software) FileZilla Client 3.37.4 (HKLM-x32\...\FileZilla Client) (Version: 3.37.4 - Tim Kosse) Freemake Video Converter version 4.1.10 (HKLM-x32\...\Freemake Video Converter_is1) (Version: 4.1.10 - Mixbyte Inc.) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 80.0.3987.149 - Google LLC) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.451 - Google LLC) Hidden GoTo Opener (HKLM-x32\...\{8B2D47CC-1558-4939-B27F-41E30530072A}) (Version: 1.0.467 - LogMeIn, Inc.) GoToMeeting 10.9.0.17052 (HKU\S-1-5-21-1547701397-687303812-3400344658-1001\...\GoToMeeting) (Version: 10.9.0.17052 - LogMeIn, Inc.) HubSpot for Windows (HKU\S-1-5-21-1547701397-687303812-3400344658-1001\...\43cd4a6240bf2444) (Version: 1.0.0.73 - Hubspot) HubSpot Sales for Outlook (HKU\S-1-5-21-1547701397-687303812-3400344658-1001\...\53945AAB78C7BE1D8B51DF62BA71EE58B9C07135) (Version: 3.0.1.156 - HubSpot, Inc.) Integration Services Patch for Act! (HKLM-x32\...\{58AEEE89-2CD8-45D0-BC80-A9F5E3DE465C}) (Version: 1.0.1150.0 - Integration Services Patch for Act!) Intel Driver && Support Assistant (HKLM-x32\...\{4DF3098D-2A9A-46DF-8B8C-9DD31D319739}) (Version: 20.2.9.6 - Intel) Hidden Intel(R) Chipset Device Software (HKLM-x32\...\{c7f54569-0018-439c-809a-48046a4d4ebc}) (Version: 10.1.1.9 - Intel(R) Corporation) Hidden Intel(R) Computing Improvement Program (HKLM\...\{A9133872-C9FE-45CC-8F01-D1947B0F09EA}) (Version: 2.4.04755 - Intel Corporation) Intel(R) Network Connections Drivers (HKLM\...\PROSet) (Version: 18.5 - Intel) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.5100 - Intel Corporation) Intel® Driver & Support Assistant (HKLM-x32\...\{a2f234ef-6c54-4ad2-a401-107bcbdfdef2}) (Version: 20.2.9.6 - Intel) iSEEK AnswerWorks English Runtime (HKLM-x32\...\{18A8E78B-9EF2-496E-B310-BCD8E4C1DAB3}) (Version: 010.000.0101 - Vantage Linguistics) iTunes (HKLM\...\{38749252-C55E-44D9-9CB6-52199D0173AB}) (Version: 12.10.2.3 - Apple Inc.) Java 8 Update 211 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180211F0}) (Version: 8.0.2110.12 - Oracle Corporation) Jing (HKLM-x32\...\{8C784F8B-89D0-4A59-A000-7EEF129E1574}) (Version: 2.9.15255.1 - TechSmith Corporation) Lenovo Active Protection System (HKLM\...\{46A84694-59EC-48F0-964C-7E76E9F8A2ED}) (Version: 1.82.00.03 - Lenovo) Hidden Lenovo On Screen Display (HKLM\...\OnScreenDisplay) (Version: 8.85.03 - Lenovo) Hidden Lenovo Power Management Driver (HKLM\...\Power Management Driver) (Version: 1.67.12.24 - Lenovo) Hidden Lenovo Service Bridge (HKU\S-1-5-21-1547701397-687303812-3400344658-1001\...\{2C74547D-EF88-47F4-85F5-BE46A31E26B7}_is1) (Version: 5.0.0.4 - Lenovo) Lenovo Solution Center (HKLM\...\{5E35CA26-A9A2-47B8-AB52-8D0C9A3CA685}) (Version: 03.12.003 - Lenovo) Lenovo System Interface Foundation (Inf Install) (HKLM\...\SIFT) (Version: 1.0.90.0 - Lenovo) Logitech SetPoint 6.67 (HKLM\...\sp6) (Version: 6.67.83 - Logitech) LogMeIn Hamachi (HKLM-x32\...\{ECC0FA07-863E-44BC-8B1D-DA22F96E5FB7}) (Version: 2.2.0.633 - LogMeIn, Inc.) Hidden LogMeIn Hamachi (HKLM-x32\...\LogMeIn Hamachi) (Version: 2.2.0.633 - LogMeIn, Inc.) Malwarebytes version 4.1.0.56 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.1.0.56 - Malwarebytes) Market Samurai (HKLM-x32\...\{0176F90F-8090-F6F7-9949-ABE38F2DB3F2}) (Version: 0.94.20 - Alliance Software Pty Ltd) Hidden Market Samurai (HKLM-x32\...\MarketSamurai.6E37012E1CBD7F47B14488FCC715944F3EBDCEDC.1) (Version: 0.94.20 - Alliance Software Pty Ltd) McAfee WebAdvisor (HKLM-x32\...\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}) (Version: 4.1.1.87 - McAfee, LLC.) Metric Collection SDK (HKLM-x32\...\{DDAA788F-52E6-44EA-ADB8-92837B11BF26}) (Version: 1.1.0008.00 - Lenovo Group Limited) Hidden Microsoft ODBC Driver 11 for SQL Server (HKLM\...\{A106FA6F-E94C-44C9-8A0F-C34BD82C9FE6}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft Office 365 - en-us (HKLM\...\O365HomePremRetail - en-us) (Version: 16.0.12527.20278 - Microsoft Corporation) Microsoft Office 365 - fr-fr (HKLM\...\O365HomePremRetail - fr-fr) (Version: 16.0.12527.20278 - Microsoft Corporation) Microsoft OneNote Home and Student 2016 - en-us (HKLM\...\OneNoteFreeRetail - en-us) (Version: 16.0.12527.20278 - Microsoft Corporation) Microsoft SQL Server 2008 Setup Support Files (HKLM\...\{6292D514-17A4-403F-98F9-E150F10C043D}) (Version: 10.3.5500.0 - Microsoft Corporation) Microsoft SQL Server 2012 Native Client (HKLM\...\{49D665A2-4C2A-476E-9AB8-FCC425F526FC}) (Version: 11.0.2100.60 - Microsoft Corporation) Microsoft SQL Server 2014 (64-bit) (HKLM\...\Microsoft SQL Server SQLServer2014) (Version: - Microsoft Corporation) Microsoft SQL Server 2014 Setup (English) (HKLM\...\{0EEBDCCA-EF5D-4896-9FEA-D7D410A57E8A}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server 2014 Transact-SQL ScriptDom (HKLM\...\{020CDFE0-C127-4047-B571-37C82396B662}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server System CLR Types (HKLM-x32\...\{C3F6F200-6D7B-4879-B9EE-700C0CE1FCDA}) (Version: 10.51.2500.0 - Microsoft Corporation) Microsoft Sync Framework 2.0 Core Components (x64) ENU (HKLM\...\{8CCBEC22-D2DB-4DC9-A58A-E1A1F3A38C8A}) (Version: 2.0.1578.0 - Microsoft Corporation) Microsoft Sync Framework 2.0 Core Components (x86) ENU (HKLM-x32\...\{FF63121D-91C6-42CC-B341-F1AA729728E7}) (Version: 2.0.1578.0 - Microsoft Corporation) Microsoft Sync Framework 2.0 Provider Services (x64) ENU (HKLM\...\{03AC245F-4C64-425C-89CF-7783C1D3AB2C}) (Version: 2.0.1578.0 - Microsoft Corporation) Microsoft Sync Framework 2.0 Provider Services (x86) ENU (HKLM-x32\...\{D3A80508-CD83-4CA3-8671-914A1BC78B61}) (Version: 2.0.1578.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4048 (HKLM\...\{91415F19-4C22-3609-A105-92ED3522D83C}) (Version: 9.0.30729.4048 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4048 (HKLM-x32\...\{5B1F2843-B379-3FF2-B0D3-64DD143ED53A}) (Version: 9.0.30729.4048 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.60724 - Microsoft Corporation) Microsoft VSS Writer for SQL Server 2014 (HKLM\...\{366CD715-2FF4-40B4-A8B4-A05E5D21A945}) (Version: 12.0.2000.8 - Microsoft Corporation) MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation) NEO Pro (HKLM-x32\...\{AC6149AA-EB0F-4831-8A72-2BABD657835B}) (Version: 7.10.7120 - Caelo Software BV) Node.js (HKLM\...\{3B7D7D6B-6811-4E43-9206-2D20FFCB2AF2}) (Version: 4.2.4 - Node.js Foundation) Nuance PaperPort 14 (HKLM-x32\...\{AEF2D1F4-0696-11D5-8E6A-00C04F7FA234}) (Version: 14.5.0000 - Nuance Communications, Inc.) Nuance PDF Viewer Plus (HKLM-x32\...\{28656860-4728-433C-8AD4-D1A930437BC8}) (Version: 5.30.3290 - Nuance Communications, Inc) Nuance Power PDF Standard (HKLM\...\{A71E5DA3-8DBF-4033-90A1-26536CEE4805}) (Version: 2.10.6413 - Nuance Communications, Inc.) Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.12527.20278 - Microsoft Corporation) Hidden Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.12527.20278 - Microsoft Corporation) Hidden Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.12527.20278 - Microsoft Corporation) Hidden Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0409-0000-0000000FF1CE}) (Version: 16.0.12527.20278 - Microsoft Corporation) Hidden Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-040C-0000-0000000FF1CE}) (Version: 16.0.12527.20278 - Microsoft Corporation) Hidden Office Timeline (HKLM-x32\...\{49D3E175-F5DE-4C56-8A8B-F4D0CF83999A}) (Version: 3.23.0 - Office Timeline) Outlook Google Calendar Sync (HKU\S-1-5-21-1547701397-687303812-3400344658-1001\...\OutlookGoogleCalendarSync) (Version: 2.7.0-beta - Paul Woolcock) PaperPort Image Printer 64-bit (HKLM\...\{715CAACC-579B-4831-A5F4-A83A8DE3EFE2}) (Version: 1.00.0001 - Nuance Communications, Inc.) Pixel Ruler (HKLM-x32\...\Pixel Ruler) (Version: - ) Prism Video File Converter (HKLM-x32\...\Prism) (Version: 5.00 - NCH Software) Quicken (HKLM-x32\...\{E5212415-A5A2-484E-B772-06E737B4F81D}) (Version: 27.1.22.29 - Quicken) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7614 - Realtek Semiconductor Corp.) Recuva (HKLM\...\Recuva) (Version: 1.53 - Piriform) Replay Converter 6 (6.0.3.1) (HKLM-x32\...\Replay Converter 6) (Version: 6.0.3.1 - Applian Technologies) Replay Media Catcher 7 (7.0.1.35) (HKLM-x32\...\Replay Media Catcher 7) (Version: 7.0.1.35 - Applian Technologies) Replay Video Capture 8 (HKLM-x32\...\Replay Video Capture 8) (Version: 8.12.1 - Applian Technologies Inc.) RoboForm 8-6-5-5 (All Users) (HKLM-x32\...\AI RoboForm) (Version: 8-6-5-5 - Siber Systems) Scansoft PDF Professional (HKLM-x32\...\{068724F8-D8BE-4B43-8DDD-B9FE9E49FD76}) (Version: - ) Hidden SIW Pro Edition (HKLM-x32\...\{69D2DFEE-F831-4843-B08F-59B2E62B6749}_is1) (Version: 2017.10.29 - Topala Software Solutions) Snagit 13 (HKLM-x32\...\{507c35df-03b5-4452-a86c-f50425c2c6ab}) (Version: 13.1.2.7933 - TechSmith Corporation) Snagit 13 (HKLM-x32\...\{EA84355E-0DCC-4A14-9ADC-FCF9ABF57EA8}) (Version: 13.1.2 - TechSmith Corporation) Hidden Speccy (HKLM\...\Speccy) (Version: 1.32 - Piriform) SQL Server 2014 Common Files (HKLM\...\{BD1CD96B-FE4B-4EAE-83D4-6EF55AB5779C}) (Version: 12.0.2000.8 - Microsoft Corporation) Hidden SQL Server 2014 Common Files (HKLM\...\{F7012F84-80F5-4C25-852E-B1BA03276FE6}) (Version: 12.0.2000.8 - Microsoft Corporation) Hidden SQL Server 2014 Database Engine Services (HKLM\...\{17531BCD-C627-46A2-9F1E-7CC920E0E94A}) (Version: 12.0.2000.8 - Microsoft Corporation) Hidden SQL Server 2014 Database Engine Services (HKLM\...\{5082A9F3-AEE5-4639-9BA7-C19661BA7331}) (Version: 12.0.2000.8 - Microsoft Corporation) Hidden SQL Server 2014 Database Engine Shared (HKLM\...\{ACC530B8-B6B4-40D6-B59B-152468CF47D0}) (Version: 12.0.2000.8 - Microsoft Corporation) Hidden SQL Server 2014 Database Engine Shared (HKLM\...\{D1B847A9-B06B-4264-9EF0-78E6E1571E65}) (Version: 12.0.2000.8 - Microsoft Corporation) Hidden SQL Server Browser for SQL Server 2014 (HKLM-x32\...\{3204DE95-97D2-4261-A286-98A262E171D4}) (Version: 12.0.2000.8 - Microsoft Corporation) Sql Server Customer Experience Improvement Program (HKLM\...\{6476DB81-F263-4C04-8574-AAD31136C304}) (Version: 12.0.2000.8 - Microsoft Corporation) Hidden Stellar Repair for Outlook (HKLM\...\Stellar Repair for Outlook_is1) (Version: 9.0.0.0 - Stellar Information Technology Pvt. Ltd.) Swift To-Do List 10.301 (HKLM-x32\...\Swift To-Do List_is1) (Version: 10.301 - Jiri Novotny, Dextronet) Switch Sound File Converter (HKU\S-1-5-21-1547701397-687303812-3400344658-1001\...\Switch) (Version: 8.03 - NCH Software) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 19.0.17.141 - Synaptics Incorporated) SysInfoTools PST Recovery(Demo) v7.0 (HKLM-x32\...\{C6005FC4-EE8D-4A81-A800-B0922B98BBF6}_is1) (Version: 7.0.0.0 - SysInfoTools) TeamSlide add-in (HKLM-x32\...\{C0367A8F-796C-4D24-BFAF-C63F12065DC4}) (Version: 4.2.1915.0 - Aploris GmbH) TeamSlide Engine (HKLM-x32\...\{43F34575-E6D0-4126-BC4E-B5C034DE4D3A}) (Version: 2.0.1325.0 - Aploris GmbH) TeamViewer 12 (HKLM-x32\...\TeamViewer) (Version: 12.0.75813 - TeamViewer) ThinkPad Settings Dependency (HKLM\...\{08515684-CE49-47EF-B509-326A2E91BC5C}_is1) (Version: 3.0.1.48 - Lenovo) Hidden Video Download Capture V6.4.8.5 (HKLM-x32\...\{b3336f66-e079-4ff6-abdb-51e2fab781d5}_is1) (Version: 6.4.8.5 - APOWERSOFT LIMITED) VideoPad Video Editor (HKLM-x32\...\VideoPad) (Version: 7.32 - NCH Software) VLC media player (HKLM-x32\...\VLC media player) (Version: 3.0.8 - VideoLAN) WavePad Sound Editor (HKLM-x32\...\WavePad) (Version: 7.05 - NCH Software) WavePad Sound Editor (HKU\S-1-5-21-1547701397-687303812-3400344658-1001\...\WavePad) (Version: 10.26 - NCH Software) WhatsApp (HKU\S-1-5-21-1547701397-687303812-3400344658-1001\...\WhatsApp) (Version: 0.4.1302 - WhatsApp) Windows 10 Update Assistant (HKLM-x32\...\{D5C69738-B486-402E-85AC-2456D98A64E4}) (Version: 1.4.9200.22925 - Microsoft Corporation) Windows Driver Package - AMD (amdkmpfd) System (12/09/2016 16.60.0.0000) (HKLM\...\D2BE684635541753B7ADEB903A532F1A701A5CB7) (Version: 12/09/2016 16.60.0.0000 - AMD) Windows Driver Package - Brother (brparimg) Image (06/21/2009 6.2.8306.0) (HKLM\...\F1CBD50426852EA833A2A9D28D435E985D16C7EE) (Version: 06/21/2009 6.2.8306.0 - Brother) Windows Driver Package - Challenger Backup Solutions, LLC (FlashBoot) DiskDrive (08/11/2013 2.3.72.0) (HKLM\...\CA8BFE662913F62CB908BA31685037C57A7DD973) (Version: 08/11/2013 2.3.72.0 - Challenger Backup Solutions, LLC) Windows Driver Package - ELAN SMBus (ETDSMBus) System (05/31/2016 15.1.2.9) (HKLM\...\F069782784DB514BAC37C846F2CF3B7C1374AFB3) (Version: 05/31/2016 15.1.2.9 - ELAN SMBus) Windows Driver Package - ELAN SMBus (ETDSMBus) System (11/09/2016 15.1.2.10) (HKLM\...\77D13CB31BA00EAEA7E651CAE7C67F5894E47A0C) (Version: 11/09/2016 15.1.2.10 - ELAN SMBus) Windows Driver Package - Intel (e1cexpress) Net (03/29/2016 12.15.31.4) (HKLM\...\F5284A197B118A8E03ABB5E43B8AF967B9C7FDA0) (Version: 03/29/2016 12.15.31.4 - Intel) Windows Driver Package - Intel (MEIx64) System (03/28/2016 11.0.5.1189) (HKLM\...\63CEF5543DBF9887E6220C5C2F7F85C2D4C726D5) (Version: 03/28/2016 11.0.5.1189 - Intel) Windows Driver Package - INTEL System (01/03/2017 10.1.1.40) (HKLM\...\8CEDD5129B707E5E3DBDA8D3505BBF287C775830) (Version: 01/03/2017 10.1.1.40 - INTEL) Windows Driver Package - INTEL System (01/03/2017 10.1.1.40) (HKLM\...\FDF41EC50250C5521FE27B83ED0C111EDF03AF17) (Version: 01/03/2017 10.1.1.40 - INTEL) Windows Driver Package - Intel USB (07/09/2013 9.3.0.1028) (HKLM\...\6AB557A44DB5C90C1F398266C338F5468520E2C0) (Version: 07/09/2013 9.3.0.1028 - Intel) Windows Driver Package - Intel(R) Corporation (IntcDAud) MEDIA (06/22/2017 6.16.00.3200) (HKLM\...\35F10B39A811B52865C4B4B57EE6D46592307FD6) (Version: 06/22/2017 6.16.00.3200 - Intel(R) Corporation) Windows Driver Package - Lenovo (LnvHIDHW) HIDClass (04/07/2014 1.0.0.58) (HKLM\...\9E1610969548C620898F20CB8DB4FF84A5F31EFD) (Version: 04/07/2014 1.0.0.58 - Lenovo) Windows Driver Package - Lenovo (LnvHIDHW) HIDClass (07/20/2017 1.0.0.58) (HKLM\...\873879933BEFA9B4F22D1FAA45F3F8E35CDCD3AD) (Version: 07/20/2017 1.0.0.58 - Lenovo) Windows Driver Package - Lenovo (WUDFRd) System (02/24/2017 6.4.0.0) (HKLM\...\06F50E689B2093B4AA9877F1B758395F9B5C147A) (Version: 02/24/2017 6.4.0.0 - Lenovo) Windows Driver Package - Lenovo 1.67.12.23 (02/15/2017 1.67.12.23) (HKLM\...\98A1A803F188A82E8BCFC7AFD0A3FA8BE6FD8CAF) (Version: 02/15/2017 1.67.12.23 - Lenovo) Windows Driver Package - Lenovo 1.67.12.24 (03/28/2017 1.67.12.24) (HKLM\...\93C208C7BB9D0EE3DF0383C9C1AE7D65F9DFE35D) (Version: 03/28/2017 1.67.12.24 - Lenovo) Windows Driver Package - Lenovo Monitor (03/16/2017 6.04.0.0) (HKLM\...\79DA32819DE9C757A5E747ABFF78C86A3F97A044) (Version: 03/16/2017 6.04.0.0 - Lenovo) Windows Driver Package - Lenovo Monitor (08/01/2017 6.05.0.0) (HKLM\...\F77E1533A8CB754329E1511239AB16CD7D7FA86D) (Version: 08/01/2017 6.05.0.0 - Lenovo) Windows Driver Package - Lenovo Power Management Driver (07/31/2017 1.67.13.12) (HKLM\...\8218E2CCCCD1B13A1BEC79A0E96886756DE027AE) (Version: 07/31/2017 1.67.13.12 - Lenovo) Windows Driver Package - LG Electronics Inc. (AirModeBtn) HIDClass (11/04/2016 1.0.1611.0401) (HKLM\...\FD1DB0C9F96D75B2DBE15DC8D24593B0C671BAB6) (Version: 11/04/2016 1.0.1611.0401 - LG Electronics Inc.) Windows Driver Package - Logitech (usbccgp) USB (11/04/2010 1.0.2.11) (HKLM\...\8A87028F68EFC3B6D4F26F7EF2DDB31C8F6767EF) (Version: 11/04/2010 1.0.2.11 - Logitech) Windows Driver Package - Microsoft Battery (11/13/2015 1.2.0.2) (HKLM\...\D94A6ADF78DC5F14DEE64147DCDF230ED63FD734) (Version: 11/13/2015 1.2.0.2 - Microsoft) Windows Driver Package - Ricoh (RCUVCAVS) Image (07/05/2013 1.0.0.30) (HKLM\...\30FD262823921AEE20CC479B84C16FDCEC431DC5) (Version: 07/05/2013 1.0.0.30 - Ricoh) Wondershare Filmora(Build 8.4.0) (HKLM\...\Wondershare Filmora_is1) (Version: - Wondershare Software) Wondershare Helper Compact 2.6.0 (HKLM-x32\...\{5363CE84-5F09-48A1-8B6C-6BB590FFEDF2}_is1) (Version: 2.6.0 - Wondershare) Wondershare UniConverter(Build 11.7.2.6) (HKLM-x32\...\UniConverter_is1) (Version: 11.7.2.6 - Wondershare Software) Zoner Photo Studio X (HKLM\...\ZonerPhotoStudioX_EN_is1) (Version: 19.1806.2.72 - ZONER software) Zoom (HKU\S-1-5-21-1547701397-687303812-3400344658-1001\...\ZoomUMX) (Version: 4.5 - Zoom Video Communications, Inc.) Packages: ========= Autodesk SketchBook -> C:\Program Files\WindowsApps\89006A2E.AutodeskSketchBook_5.1.0.0_x64__tf1gferkr813w [0000-00-00] (Autodesk Inc.) Disney Magic Kingdoms -> C:\Program Files\WindowsApps\A278AB0D.DisneyMagicKingdoms_4.9.0.6_x86__h6adky7gbf63m [0000-00-00] (Gameloft SE) Facebook -> C:\Program Files\WindowsApps\Facebook.Facebook_186.2619.19263.0_x86__8xx8rvfyw5nnt [0000-00-00] (Facebook Inc) Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [0000-00-00] (Microsoft Corporation) [MS Ad] Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [0000-00-00] (Microsoft Corporation) [MS Ad] Microsoft News -> C:\Program Files\WindowsApps\Microsoft.BingNews_4.36.20714.0_x64__8wekyb3d8bbwe [0000-00-00] (Microsoft Corporation) [MS Ad] Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.6.1224.0_x64__8wekyb3d8bbwe [0000-00-00] (Microsoft Studios) [MS Ad] Microsoft To Do -> C:\Program Files\WindowsApps\Microsoft.Todos_2.13.3701.0_x64__8wekyb3d8bbwe [0000-00-00] (Microsoft Corporation) MPEG-2 Video Extension -> C:\Program Files\WindowsApps\Microsoft.MPEG2VideoExtension_1.0.22661.0_x64__8wekyb3d8bbwe [0000-00-00] (Microsoft Corporation) MSN Weather -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.36.20714.0_x64__8wekyb3d8bbwe [0000-00-00] (Microsoft Corporation) [MS Ad] Photos Add-on -> C:\Program Files\WindowsApps\Microsoft.Windows.Photos.DLC.Main_2017.39121.36610.0_x64__8wekyb3d8bbwe [0000-00-00] (Microsoft Corporation) RoboForm Password Manager -> C:\Program Files\WindowsApps\SiberSystemsInc.RoboFormEdge_8.5.7.0_x86__7kk3kr9e0p1np [0000-00-00] (Siber Systems Inc) Twitter -> C:\Program Files\WindowsApps\9E2F88E3.Twitter_6.1.4.1000_neutral__wgeqdkkx372wm [0000-00-00] (Twitter Inc.) Zip Extractor Pro -> C:\Program Files\WindowsApps\38526MediaLife.ZipPlus_2.0.1.0_x86__1crh1k73ty8mg [0000-00-00] (Media Life) Самоучитель Microsoft Project -> C:\Program Files\WindowsApps\47054NKsoft.MicrosoftProject_1.1.3.0_x64__qv26zcc6ec1jt [0000-00-00] (NKsoft) ==================== Custom CLSID (Whitelisted): ============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) HKU\S-1-5-21-1547701397-687303812-3400344658-1001\...\ChromeHTML: -> <==== ATTENTION CustomCLSID: HKU\S-1-5-21-1547701397-687303812-3400344658-1001_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32 -> C:\Users\chris\AppData\Local\Microsoft\OneDrive\19.232.1124.0005\amd64\FileSyncShell64.dll => No File CustomCLSID: HKU\S-1-5-21-1547701397-687303812-3400344658-1001_Classes\CLSID\{233525e0-5434-46ef-b464-fd7e45e2e145}\localserver32 -> C:\Program Files (x86)\Intel\Driver and Support Assistant\DSATray.exe (IDSA Production signing key -> Intel) CustomCLSID: HKU\S-1-5-21-1547701397-687303812-3400344658-1001_Classes\CLSID\{6A80FF4F-13D8-4BE3-AD84-915B304A0C1B}\InprocServer32 -> C:\Users\chris\AppData\Local\Swift To-Do List/SwiftToDoListAddIn.dll (Dextronet) [File not signed] CustomCLSID: HKU\S-1-5-21-1547701397-687303812-3400344658-1001_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32 -> C:\Users\chris\AppData\Local\Microsoft\OneDrive\19.232.1124.0005\amd64\FileSyncShell64.dll => No File CustomCLSID: HKU\S-1-5-21-1547701397-687303812-3400344658-1001_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\WINDOWS\system32\igfxEM.exe (Intel(R) pGFX -> Intel Corporation) CustomCLSID: HKU\S-1-5-21-1547701397-687303812-3400344658-1001_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32 -> C:\Users\chris\AppData\Local\Microsoft\OneDrive\19.232.1124.0005\amd64\FileSyncShell64.dll => No File CustomCLSID: HKU\S-1-5-21-1547701397-687303812-3400344658-1001_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309}\InprocServer32 -> C:\Users\chris\AppData\Local\GoToMeeting\16576\G2MOutlookAddin64.dll (LogMeIn, Inc. -> LogMeIn, Inc.) CustomCLSID: HKU\S-1-5-21-1547701397-687303812-3400344658-1001_Classes\CLSID\{E31EA727-12ED-4702-820C-4B6445F28E1A} -> [Dropbox] => C:\Users\chris\Dropbox [2017-04-25 12:22] ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File ShellIconOverlayIdentifiers: [ Carbonite.Green] -> {95A27763-F62A-4114-9072-E81D87DE3B68} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2019-04-30] (Carbonite -> Carbonite, Inc.) ShellIconOverlayIdentifiers: [ Carbonite.Partial] -> {E300CD91-100F-4E67-9AF3-1384A6124015} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2019-04-30] (Carbonite -> Carbonite, Inc.) ShellIconOverlayIdentifiers: [ Carbonite.Yellow] -> {5E529433-B50E-4bef-A63B-16A6B71B071A} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2019-04-30] (Carbonite -> Carbonite, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File ShellIconOverlayIdentifiers: [GladinetIconOverlay] -> {3C3DC57A-7535-48AF-BB9E-C3576A4F34D0} => C:\Program Files (x86)\Nuance\Nuance Cloud Connector\GlOverlayIcon.dll [2013-05-05] (Gladinet, Inc. -> Gladinet, INC) ShellIconOverlayIdentifiers: [GladinetUploading] -> {959A18D3-9CC9-41e8-B76F-34ED9A89D4EA} => C:\Program Files (x86)\Nuance\Nuance Cloud Connector\GlOverlayIconU.dll [2013-05-05] (Gladinet, Inc. -> Gladinet, INC) ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File ShellIconOverlayIdentifiers-x32: [ Carbonite.Green] -> {95A27763-F62A-4114-9072-E81D87DE3B68} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2019-04-30] (Carbonite -> Carbonite, Inc.) ShellIconOverlayIdentifiers-x32: [ Carbonite.Partial] -> {E300CD91-100F-4E67-9AF3-1384A6124015} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2019-04-30] (Carbonite -> Carbonite, Inc.) ShellIconOverlayIdentifiers-x32: [ Carbonite.Yellow] -> {5E529433-B50E-4bef-A63B-16A6B71B071A} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2019-04-30] (Carbonite -> Carbonite, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File ShellIconOverlayIdentifiers-x32: [GladinetIconOverlay] -> {3C3DC57A-7535-48AF-BB9E-C3576A4F34D0} => C:\Program Files (x86)\Nuance\Nuance Cloud Connector\GlOverlayIcon.dll [2013-05-05] (Gladinet, Inc. -> Gladinet, INC) ShellIconOverlayIdentifiers-x32: [GladinetUploading] -> {959A18D3-9CC9-41e8-B76F-34ED9A89D4EA} => C:\Program Files (x86)\Nuance\Nuance Cloud Connector\GlOverlayIconU.dll [2013-05-05] (Gladinet, Inc. -> Gladinet, INC) ContextMenuHandlers1: [Carbonite] -> {FE8BD682-9A64-4740-A92B-EE7E5F7FA0A5} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2019-04-30] (Carbonite -> Carbonite, Inc.) ContextMenuHandlers1: [DefragglerShellExtension] -> {4380C993-0C43-4E02-9A7A-0D40B6EA7590} => C:\Program Files\Defraggler\DefragglerShell64.dll [2018-05-02] (Piriform Ltd -> Piriform Ltd) ContextMenuHandlers1: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.) ContextMenuHandlers1: [NPDF.ShellExtension] -> {03DDC0E5-AF08-40a2-85B9-FEDF1F4A780C} => C:\Program Files (x86)\Nuance\Power PDF 21\ShellExt.dll [2017-05-16] (Nuance Communications, Inc. -> Nuance Communications, Inc.) ContextMenuHandlers1: [Nuance.SMFCDirectShellExt] -> {B080A0B4-C3ED-4E09-B92C-66D5829AA764} => C:\Program Files (x86)\Nuance\Power PDF 21\bin\SDirectShellExt.dll [2017-04-28] (ZEON CORPORATION -> Zeon International Investment Corp. ) ContextMenuHandlers1: [ShellConverter] -> {30A4E07E-068A-4d91-8F05-691283A1336B} => C:\Program Files (x86)\Common Files\AVSMedia\ActiveX\AVSShellConverter64.dll [2017-12-18] (Online Media Technologies Ltd. -> Online Media Technologies Ltd.) ContextMenuHandlers1: [SnagItMainShellExt] -> {CF74B903-3389-469c-B3B6-0204D204FCBD} => C:\Program Files (x86)\TechSmith\Snagit 13\DLLx64\SnagitShellExt64.dll [2017-04-11] (TechSmith Corporation -> TechSmith Corporation) ContextMenuHandlers2: [Carbonite] -> {FE8BD682-9A64-4740-A92B-EE7E5F7FA0A5} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2019-04-30] (Carbonite -> Carbonite, Inc.) ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-06-26] (Malwarebytes Corporation -> Malwarebytes) ContextMenuHandlers3: [Open With Gladinet] -> {81695C6B-C2CA-492F-951D-5469840B2098} => C:\Program Files (x86)\Nuance\Nuance Cloud Connector\GladinetShellProxy.dll [2013-05-05] (Gladinet, Inc. -> Gladinet, INC) ContextMenuHandlers4: [Carbonite] -> {FE8BD682-9A64-4740-A92B-EE7E5F7FA0A5} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2019-04-30] (Carbonite -> Carbonite, Inc.) ContextMenuHandlers4: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.) ContextMenuHandlers4: [RecuvaShellExt] -> {435E5DF5-2510-463C-B223-BDA47006D002} => C:\Program Files\Recuva\RecuvaShell64.dll [2016-06-06] (Piriform Ltd -> Piriform Ltd) ContextMenuHandlers4: [SnagItMainShellExt] -> {CF74B903-3389-469c-B3B6-0204D204FCBD} => C:\Program Files (x86)\TechSmith\Snagit 13\DLLx64\SnagitShellExt64.dll [2017-04-11] (TechSmith Corporation -> TechSmith Corporation) ContextMenuHandlers5: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.) ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\system32\igfxDTCM.dll [2019-12-18] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation) ContextMenuHandlers6: [DefragglerShellExtension] -> {4380C993-0C43-4E02-9A7A-0D40B6EA7590} => C:\Program Files\Defraggler\DefragglerShell64.dll [2018-05-02] (Piriform Ltd -> Piriform Ltd) ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-06-26] (Malwarebytes Corporation -> Malwarebytes) ContextMenuHandlers6: [RecuvaShellExt] -> {435E5DF5-2510-463C-B223-BDA47006D002} => C:\Program Files\Recuva\RecuvaShell64.dll [2016-06-06] (Piriform Ltd -> Piriform Ltd) ==================== Codecs (Whitelisted) ==================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Drivers32: [msacm.voxacm160] => C:\WINDOWS\system32\vct3216.acm [82944 2003-05-21] (Voxware, Inc.) [File not signed] HKLM\...\Drivers32: [msacm.scg726] => C:\WINDOWS\system32\scg726.acm [13239 2000-03-14] (SHARP Corporation) [File not signed] HKLM\...\Drivers32: [msacm.alf2cd] => C:\WINDOWS\system32\alf2cd.acm [38912 2003-05-21] (NCT Company) [File not signed] HKLM\...\Drivers32: [msacm.ac3acm] => C:\WINDOWS\system32\AC3ACM.acm [81920 2004-02-04] (fccHandler) [File not signed] HKLM\...\Drivers32: [msacm.lame] => C:\WINDOWS\system32\lame.ax [245760 2005-08-01] () [File not signed] HKLM\...\Drivers32: [vidc.dvsd] => C:\WINDOWS\system32\mcdvd_32.dll [261632 2003-05-21] (MainConcept) [File not signed] HKLM\...\Drivers32: [vidc.mpg4] => C:\WINDOWS\system32\mpg4c32.dll [413760 2002-08-19] (Microsoft Corporation) [File not signed] HKLM\...\Drivers32: [vidc.mp42] => C:\WINDOWS\system32\mpg4c32.dll [413760 2002-08-19] (Microsoft Corporation) [File not signed] HKLM\...\Drivers32: [vidc.mp43] => C:\WINDOWS\system32\mpg4c32.dll [413760 2002-08-19] (Microsoft Corporation) [File not signed] HKLM\...\Drivers32: [vidc.xvid] => C:\WINDOWS\system32\xvidvfw.dll [139264 2004-07-03] () [File not signed] HKLM\...\Drivers32: [vidc.DIVX] => C:\WINDOWS\system32\DivX.dll [638976 2003-05-22] (DivXNetworks, Inc.) [File not signed] HKLM\...\Drivers32: [vidc.VP60] => C:\WINDOWS\system32\vp6vfw.dll [438272 2004-12-10] (On2.com) [File not signed] HKLM\...\Drivers32: [vidc.VP61] => C:\WINDOWS\system32\vp6vfw.dll [438272 2004-12-10] (On2.com) [File not signed] HKLM\...\Drivers32: [vidc.VP62] => C:\WINDOWS\system32\vp6vfw.dll [438272 2004-12-10] (On2.com) [File not signed] HKLM\...\Drivers32: [vidc.LAGS] => C:\WINDOWS\system32\lagarith.dll [216064 2011-12-07] ( ) [File not signed] ==================== Shortcuts & WMI ======================== (The entries could be listed to be restored or removed.) ShortcutWithArgument: C:\Users\chris\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\d249d9ddd424b688\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory=Default ==================== Loaded Modules (Whitelisted) ============= 2015-12-04 15:02 - 2015-12-04 15:02 - 001152512 _____ () [File not signed] C:\Program Files (x86)\TechSmith\Snagit 13\cairo.dll 2015-12-04 15:02 - 2015-12-04 15:02 - 000601088 _____ () [File not signed] C:\Program Files (x86)\TechSmith\Snagit 13\fontconfig.dll 2015-12-04 15:02 - 2015-12-04 15:02 - 000778240 _____ () [File not signed] C:\Program Files (x86)\TechSmith\Snagit 13\harfbuzz.dll 2015-12-04 15:02 - 2015-12-04 15:02 - 000023552 _____ () [File not signed] C:\Program Files (x86)\TechSmith\Snagit 13\iconv.dll 2015-12-04 15:02 - 2015-12-04 15:02 - 000165888 _____ () [File not signed] C:\Program Files (x86)\TechSmith\Snagit 13\libpng16.dll 2015-12-04 15:02 - 2015-12-04 15:02 - 001015296 _____ () [File not signed] C:\Program Files (x86)\TechSmith\Snagit 13\libxml2.dll 2016-01-27 18:05 - 2016-01-27 18:05 - 008968192 _____ () [File not signed] C:\Program Files (x86)\TechSmith\Snagit 13\opencv_core300.dll 2016-03-04 15:10 - 2016-03-04 15:10 - 008968192 _____ () [File not signed] C:\Program Files (x86)\TechSmith\Snagit 13\opencv_core310.dll 2016-01-27 18:05 - 2016-01-27 18:05 - 020629504 _____ () [File not signed] C:\Program Files (x86)\TechSmith\Snagit 13\opencv_imgproc300.dll 2016-03-04 15:10 - 2016-03-04 15:10 - 020629504 _____ () [File not signed] C:\Program Files (x86)\TechSmith\Snagit 13\opencv_imgproc310.dll 2016-03-04 15:10 - 2016-03-04 15:10 - 000800768 _____ () [File not signed] C:\Program Files (x86)\TechSmith\Snagit 13\opencv_photo310.dll 2015-12-04 15:02 - 2015-12-04 15:02 - 000588288 _____ () [File not signed] C:\Program Files (x86)\TechSmith\Snagit 13\pixman-1.dll 2015-12-04 15:02 - 2015-12-04 15:02 - 000071680 _____ () [File not signed] C:\Program Files (x86)\TechSmith\Snagit 13\zlib1.dll 2017-04-19 18:27 - 2013-07-03 18:27 - 000105472 _____ (Dextronet) [File not signed] C:\Users\chris\AppData\Local\Swift To-Do List\SwiftToDoListAddIn.dll 2015-12-04 15:02 - 2015-12-04 15:02 - 000058880 _____ (Free Software Foundation) [File not signed] C:\Program Files (x86)\TechSmith\Snagit 13\libintl.dll 2016-01-08 13:28 - 2016-01-08 13:28 - 000306688 _____ (hxxp://hunspell.sourceforge.net/) [File not signed] C:\Program Files (x86)\TechSmith\Snagit 13\libhunspell.dll 2017-04-19 18:27 - 2013-03-28 14:57 - 000049664 _____ (hxxp://netoffice.codeplex.com) [File not signed] C:\Users\chris\AppData\Local\Swift To-Do List\NetOffice.dll 2016-07-13 11:41 - 2016-07-13 11:41 - 000066192 _____ (LEAD Technologies, Inc -> LEAD Technologies, Inc.) [File not signed] C:\Program Files (x86)\TechSmith\Snagit 13\LFJbg15U.DLL 2016-07-13 11:41 - 2016-07-13 11:41 - 000126096 _____ (LEAD Technologies, Inc -> LEAD Technologies, Inc.) [File not signed] C:\Program Files (x86)\TechSmith\Snagit 13\LFPng15U.DLL 2016-07-13 11:41 - 2016-07-13 11:41 - 000212112 _____ (LEAD Technologies, Inc -> LEAD Technologies, Inc.) [File not signed] C:\Program Files (x86)\TechSmith\Snagit 13\Ltimgclr15u.dll 2016-07-13 11:41 - 2016-07-13 11:41 - 000134288 _____ (LEAD Technologies, Inc -> LEAD Technologies, Inc.) [File not signed] C:\Program Files (x86)\TechSmith\Snagit 13\Ltimgutl15u.dll 2016-07-13 11:41 - 2016-07-13 11:41 - 000122000 _____ (LEAD Technologies, Inc -> LEAD Technologies, Inc.) [File not signed] C:\Program Files (x86)\TechSmith\Snagit 13\Lttwn15u.dll 2020-03-28 15:23 - 2020-03-28 15:23 - 000113664 _____ (Microsoft Corporation) [File not signed] C:\WINDOWS\WinSxS\amd64_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.6229_none_8a167c0b2edeae4c\ATL80.DLL 2020-03-28 15:23 - 2020-03-28 15:23 - 001093632 _____ (Microsoft Corporation) [File not signed] C:\WINDOWS\WinSxS\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.6229_none_cbee8c4a4710d003\MFC80U.DLL 2020-03-28 15:23 - 2020-03-28 15:23 - 000057344 _____ (Microsoft Corporation) [File not signed] C:\WINDOWS\WinSxS\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.6229_none_03c6cf28205ff947\MFC80ENU.DLL 2019-10-27 18:54 - 2019-10-27 18:54 - 000000000 ____L (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Client\AppVIsvSubsystems32.dll 2019-10-27 18:54 - 2019-10-27 18:54 - 000000000 ____L (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\AppVIsvSubsystems32.dll 2019-10-27 18:54 - 2019-10-27 18:54 - 000000000 ____L (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\c2r32.dll 2017-04-19 18:27 - 2013-03-28 14:57 - 000771072 _____ (netoffice.codeplex.com) [File not signed] C:\Users\chris\AppData\Local\Swift To-Do List\OfficeApi.dll 2017-04-19 18:27 - 2013-03-28 14:57 - 001271808 _____ (netoffice.codeplex.com) [File not signed] C:\Users\chris\AppData\Local\Swift To-Do List\OutlookApi.dll 2015-12-04 15:02 - 2015-12-04 15:02 - 000248832 _____ (Red Hat Software) [File not signed] C:\Program Files (x86)\TechSmith\Snagit 13\pango-1.0.dll 2015-12-04 15:02 - 2015-12-04 15:02 - 000449024 _____ (Red Hat Software) [File not signed] C:\Program Files (x86)\TechSmith\Snagit 13\pangocairo-1.0.dll 2015-12-04 15:02 - 2015-12-04 15:02 - 000468992 _____ (Red Hat Software) [File not signed] C:\Program Files (x86)\TechSmith\Snagit 13\pangoft2-1.0.dll 2015-12-04 15:02 - 2015-12-04 15:02 - 000055808 _____ (Red Hat Software) [File not signed] C:\Program Files (x86)\TechSmith\Snagit 13\pangowin32-1.0.dll 2019-11-27 10:32 - 2019-10-27 06:36 - 001261568 _____ (Robert Simpson, et al.) [File not signed] C:\ProgramData\Lenovo\iMController\Plugins\GenericMessagingPlugin\x86\x86\SQLite.Interop.dll 2019-08-16 15:29 - 2019-08-16 15:29 - 001902080 _____ (SQLite Development Team) [File not signed] C:\Program Files\Intel\SUR\QUEENCREEK\x64\sqlite3.dll 2018-07-13 15:37 - 2016-10-17 19:29 - 003842048 _____ (Terra Informatica Software, Inc.) [File not signed] C:\Program Files\Zoner\Photo Studio 19\Program32\sciter32.dll 2015-12-04 15:02 - 2015-12-04 15:02 - 001093632 _____ (The GLib developer community) [File not signed] C:\Program Files (x86)\TechSmith\Snagit 13\glib-2.0.dll 2015-12-04 15:02 - 2015-12-04 15:02 - 000015872 _____ (The GLib developer community) [File not signed] C:\Program Files (x86)\TechSmith\Snagit 13\gmodule-2.0.dll 2015-12-04 15:02 - 2015-12-04 15:02 - 000232960 _____ (The GLib developer community) [File not signed] C:\Program Files (x86)\TechSmith\Snagit 13\gobject-2.0.dll 2011-06-27 00:22 - 2011-06-27 00:22 - 001032192 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files (x86)\Nuance\Nuance Cloud Connector\LIBEAY32.dll ==================== Alternate Data Streams (Whitelisted) ======== (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\ProgramData\TEMP:AB1A1E3D [742] AlternateDataStreams: C:\ProgramData\TEMP:B0D4D817 [434] AlternateDataStreams: C:\ProgramData\TEMP:FD9CE1F3 [254] AlternateDataStreams: C:\Users\chris\Desktop\Ralf - Madrid Agile_Talent.mp4:com.dropbox.attributes [168] ==================== Safe Mode (Whitelisted) ================== ==================== Association (Whitelisted) ================= ==================== Internet Explorer trusted/restricted ========== (If an entry is included in the fixlist, it will be removed from the registry.) IE trusted site: HKU\S-1-5-21-1547701397-687303812-3400344658-1001\...\sharepoint.com -> hxxps://lululemon-files.sharepoint.com ==================== Hosts content: ========================= (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2016-07-16 07:47 - 2016-07-16 07:45 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts ==================== Other Areas =========================== (Currently there is no automatic fix for this section.) HKU\S-1-5-21-1547701397-687303812-3400344658-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\chris\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\img1.jpg DNS Servers: 192.168.2.1 - 198.235.214.4 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 1) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == (If an entry is included in the fixlist, it will be removed.) HKLM\...\StartupApproved\Run: => "SecurityHealth" HKLM\...\StartupApproved\Run: => "iTunesHelper" HKLM\...\StartupApproved\Run32: => "PDFHook" HKLM\...\StartupApproved\Run32: => "PDF5 Registry Controller" HKLM\...\StartupApproved\Run32: => "PaperPort PTD" HKLM\...\StartupApproved\Run32: => "IndexSearch" HKLM\...\StartupApproved\Run32: => "LogMeIn Hamachi Ui" HKLM\...\StartupApproved\Run32: => "Wondershare Helper Compact.exe" HKLM\...\StartupApproved\Run32: => "Act.Outlook64.Service" HKU\S-1-5-21-1547701397-687303812-3400344658-1001\...\StartupApproved\Run: => "QuickenScheduledUpdates" HKU\S-1-5-21-1547701397-687303812-3400344658-1001\...\StartupApproved\Run: => "TeamSlideEngine" ==================== FirewallRules (Whitelisted) ================ (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{A485F2A2-2985-4B76-B485-F00DA4D9AC41}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (Dropbox, Inc -> Dropbox, Inc.) FirewallRules: [{9417FFCC-A6C5-4486-94CA-1364D7BE98CC}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) FirewallRules: [UDP Query User{89285381-286B-4465-895B-A076F1A638DE}C:\program files (x86)\videolan\vlc\vlc.exe] => (Block) C:\program files (x86)\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN) FirewallRules: [TCP Query User{8BA91510-0C99-48DD-973D-78F099D7CB4D}C:\program files (x86)\videolan\vlc\vlc.exe] => (Block) C:\program files (x86)\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN) FirewallRules: [{C0A1D3A9-7BC6-48F1-B596-D728DEF220BB}] => (Allow) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe (Intel(R) Software Development Products -> ) FirewallRules: [{72DCEF0A-B4E6-4912-87D1-61CAEA943EC6}] => (Allow) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe (Intel(R) Software Development Products -> ) FirewallRules: [{B7A47B03-3BC3-4866-884A-D946702C885E}] => (Block) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe (Intel(R) Software Development Products -> ) FirewallRules: [{134274B5-6953-4AFA-A747-7410F2115D69}] => (Block) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe (Intel(R) Software Development Products -> ) FirewallRules: [{4A105B56-0248-4822-8C39-16854FF44B3E}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.126.501.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{B46E890A-D708-497A-89FD-C2B7B97C0A79}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.126.501.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{CEECA537-A2AB-4BD6-BA44-A5308F3AB010}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.126.501.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{92BF031C-468C-457C-A59E-04CEB3DC44F1}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.126.501.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{56D78F78-2EC9-41D2-B281-4D363319198E}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.126.501.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{221AA289-EDB9-4A05-A793-8635F6AACB20}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.126.501.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{4747BC94-D6E5-4768-B6DD-4E0BBFF7F8C8}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.126.501.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{FF24401D-23C5-4ADF-BCB8-A8B887025548}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.126.501.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{537FB3DA-A28A-456D-ADCE-72214F066B67}] => (Allow) C:\Program Files\Microsoft SQL Server\MSSQL12.ACT7\MSSQL\Binn\sqlservr.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{34519FFA-1818-4371-84B1-6BCD9BD26F36}] => (Allow) C:\Program Files\Microsoft SQL Server\MSSQL12.ACT7\MSSQL\Binn\sqlservr.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{9E2C070B-255D-4F9F-9343-C9A8C07B0C88}] => (Allow) C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{276DC7A9-253D-4489-9264-4512E5663878}] => (Allow) C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{C2A0626B-8294-44A9-B3EC-F01B7452761B}] => (Allow) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe No File FirewallRules: [{50B51DCC-F91E-4E3B-A8D1-4C27F5A87CFB}] => (Allow) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe No File FirewallRules: [{9135B9AA-E33B-432C-AC6F-57F90E3984F1}] => (Allow) C:\Program Files (x86)\ACT\Act for Windows\Act.Server.Host.exe (Microsoft) [File not signed] FirewallRules: [{8E1BA8B4-30AC-42C9-8581-D2C4578B795A}] => (Allow) C:\Program Files (x86)\ACT\Act for Windows\Act.Server.Host.exe (Microsoft) [File not signed] FirewallRules: [{9A536975-A83E-4B05-9582-30070E989414}] => (Allow) C:\Program Files (x86)\ACT\Act for Windows\Act15.exe (Swiftpage ACT! LLC -> Swiftpage ACT! LLC) FirewallRules: [{9C0C8552-D47C-4FBF-806D-67673851C19F}] => (Allow) C:\Program Files (x86)\ACT\Act for Windows\Act15.exe (Swiftpage ACT! LLC -> Swiftpage ACT! LLC) FirewallRules: [{A3E274BA-0068-4CFA-8055-170EA29FD838}] => (Allow) C:\Program Files (x86)\ACT\Act for Windows\ActEmail.exe (Swiftpage ACT! LLC) [File not signed] FirewallRules: [{C447D963-70E4-4190-8887-0393DB97E84A}] => (Allow) C:\Program Files (x86)\ACT\Act for Windows\ActEmail.exe (Swiftpage ACT! LLC) [File not signed] FirewallRules: [{CB87BFB8-3269-4DF4-B83C-3DAE893A9193}] => (Allow) C:\Program Files (x86)\ACT\Act for Windows\Act!.exe (Swiftpage ACT! LLC -> Swiftpage ACT! LLC) FirewallRules: [{8FFD75EF-E712-47BA-8CD8-F1389AA2572C}] => (Allow) C:\Program Files (x86)\ACT\Act for Windows\Act!.exe (Swiftpage ACT! LLC -> Swiftpage ACT! LLC) FirewallRules: [{913A2B6D-6F99-4996-ABE6-E5236B4B9596}] => (Allow) C:\Program Files\iTunes\iTunes.exe (Apple Inc. -> Apple Inc.) FirewallRules: [{669C10BE-E05E-4A54-B24F-DAE0048B22D1}] => (Allow) C:\Users\chris\AppData\Roaming\Zoom\bin\airhost.exe No File FirewallRules: [{AB2457CE-CB03-4180-849C-86E30DEE036C}] => (Allow) C:\Users\chris\AppData\Roaming\Zoom\bin\Zoom.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.) FirewallRules: [{13864833-4404-4900-BDAB-5DB334D0011E}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{B59868CE-89A4-4946-B006-3754927B823F}] => (Allow) C:\Program Files (x86)\Apowersoft\Video Download Capture 6\rtmpsrv.exe (Apowersoft Ltd -> ) FirewallRules: [{02304213-B7D4-4293-89C1-37986B166E43}] => (Allow) C:\Program Files (x86)\Apowersoft\Video Download Capture 6\rtmpsrv.exe (Apowersoft Ltd -> ) FirewallRules: [{468A4D56-E85C-4067-8CB2-BABD7F8B403B}] => (Allow) C:\Program Files (x86)\Apowersoft\Video Download Capture 6\Video Download Capture 6.exe (Apowersoft Ltd -> Apowersoft) FirewallRules: [{D2085A30-10EE-4579-AFBB-63D7E67DE5A1}] => (Allow) C:\Program Files (x86)\Apowersoft\Video Download Capture 6\Video Download Capture 6.exe (Apowersoft Ltd -> Apowersoft) FirewallRules: [{390DE1FF-1C55-4703-BB6C-CF32B6AF55C1}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe No File FirewallRules: [{99EA646A-293D-45F8-9EAC-936DF5397C24}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe No File FirewallRules: [{806D0A6A-37C7-433F-9866-79DA8610536C}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe No File FirewallRules: [{56B3BF34-B18A-40C5-96B3-BE5F1DE3A58F}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe No File FirewallRules: [{A7087FBD-2E65-46A4-9E52-F87C9192CC9F}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc. -> Apple Inc.) FirewallRules: [{7F747C8D-1F3F-41F0-960D-3748448C7A9A}] => (Allow) C:\Program Files (x86)\Nuance\Nuance Cloud Connector\WOSVSSSvr2003.exe (Gladinet, Inc. -> ) FirewallRules: [{7169B729-DCD8-46FB-B8B2-66DC0F554BBC}] => (Allow) C:\Program Files (x86)\Nuance\Nuance Cloud Connector\WOSVSSSvr2003.exe (Gladinet, Inc. -> ) FirewallRules: [{E5B98581-3C19-49D3-BD4D-D1C1CBA42765}] => (Allow) C:\Program Files (x86)\Nuance\Nuance Cloud Connector\WOSVSSSvr.exe (Gladinet, Inc. -> ) FirewallRules: [{1C1FC887-C455-4EEE-A1C7-70E8DEC4D6EE}] => (Allow) C:\Program Files (x86)\Nuance\Nuance Cloud Connector\WOSVSSSvr.exe (Gladinet, Inc. -> ) FirewallRules: [{DA3BD734-96F3-479F-BCF4-7ED0D37BFF60}] => (Allow) C:\Program Files (x86)\Nuance\Nuance Cloud Connector\GladinetClient.exe (Gladinet, Inc. -> Gladinet, INC) FirewallRules: [{CF7B9C98-46CE-4D69-B135-51213F7EE911}] => (Allow) C:\Program Files (x86)\Nuance\Nuance Cloud Connector\GladinetClient.exe (Gladinet, Inc. -> Gladinet, INC) FirewallRules: [{ECF3DE3F-62D1-4FEB-96D3-F1ABEAE468B7}] => (Allow) LPort=8298 FirewallRules: [{327C07FC-2AD8-4F42-94F9-8341595B2BB6}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer GmbH -> TeamViewer GmbH) FirewallRules: [{71325BD0-E269-4B49-A127-BE65435F6285}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer GmbH -> TeamViewer GmbH) FirewallRules: [{5CB80829-8813-4923-8C5C-3023A6572DD3}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH -> TeamViewer GmbH) FirewallRules: [{96AA582B-10EE-46C3-8531-7F55A39A8CD8}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH -> TeamViewer GmbH) FirewallRules: [{6DC2D33F-3FE5-48C3-B1D2-44A718EB0B8E}] => (Allow) C:\Program Files (x86)\Actian\Btrieve\bin\w3dbsmgr.exe (Actian Corporation -> Actian Corporation) FirewallRules: [{3E8371AF-891A-40FB-AEE3-0708CC54AD83}] => (Allow) LPort=1434 FirewallRules: [{DA2BE24F-E4F7-424E-A15B-FDC03E2BECCD}] => (Allow) C:\Program Files\nodejs\node.exe (Node.js Foundation -> Node.js) FirewallRules: [{C2B4B497-9238-4C60-9F53-B7244F48ABE8}] => (Allow) C:\Program Files\nodejs\node.exe (Node.js Foundation -> Node.js) FirewallRules: [{6FFBE5E1-6894-4C8A-ABE8-47F2E770CDEC}] => (Allow) C:\Program Files\Common Files\McAfee\MMSSHost\MMSSHost.exe No File FirewallRules: [{EE7C1358-90CB-4E89-994B-BF0651217770}] => (Allow) C:\Program Files (x86)\ACT\Act for Windows\Act!.exe (Swiftpage ACT! LLC -> Swiftpage ACT! LLC) FirewallRules: [{2CC406DD-2701-43CC-B847-6D145E4C0BD7}] => (Allow) C:\Program Files (x86)\ACT\Act for Windows\Act!.exe (Swiftpage ACT! LLC -> Swiftpage ACT! LLC) FirewallRules: [{BE75E1CD-B6ED-41EC-AB24-E9023F05D0C4}] => (Allow) C:\Program Files (x86)\ACT\Act for Windows\ActEmail.exe (Swiftpage ACT! LLC) [File not signed] FirewallRules: [{DC42B4F9-B73E-46D8-AA24-AAA349C7F549}] => (Allow) C:\Program Files (x86)\ACT\Act for Windows\ActEmail.exe (Swiftpage ACT! LLC) [File not signed] FirewallRules: [{6D289DBB-BF1E-4DF8-BB1D-DA6AB0A2ED4B}] => (Allow) C:\Program Files (x86)\ACT\Act for Windows\Act15.exe (Swiftpage ACT! LLC -> Swiftpage ACT! LLC) FirewallRules: [{224186F2-BB16-413E-9965-800D7E55DEAB}] => (Allow) C:\Program Files (x86)\ACT\Act for Windows\Act15.exe (Swiftpage ACT! LLC -> Swiftpage ACT! LLC) FirewallRules: [{6403D1F1-05B3-47E0-B690-21B636DC5039}] => (Allow) C:\Program Files (x86)\ACT\Act for Windows\Act.Server.Host.exe (Microsoft) [File not signed] FirewallRules: [{2C7FA17A-78F3-41C4-9BCE-E6260BACB2E1}] => (Allow) C:\Program Files (x86)\ACT\Act for Windows\Act.Server.Host.exe (Microsoft) [File not signed] FirewallRules: [{96323AFE-60B4-41FE-BF7C-E9A1F980E11B}] => (Allow) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe No File FirewallRules: [{9F30FCEF-EC80-498A-9B37-17F41EF5DB60}] => (Allow) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe No File FirewallRules: [{66F88E36-5163-4682-99E8-298846307E24}] => (Allow) C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{EE468AB6-8432-4610-9D11-17B02EA8054E}] => (Allow) C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{A300D077-36F2-4C8D-A694-C65561726B51}] => (Allow) C:\Program Files\Microsoft SQL Server\MSSQL12.ACT7\MSSQL\Binn\sqlservr.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{12DBB2C7-DE8A-493D-AAD7-67E3008DEB8C}] => (Allow) C:\Program Files\Microsoft SQL Server\MSSQL12.ACT7\MSSQL\Binn\sqlservr.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{AE72F58C-EAB4-4670-98B6-38FF0A6D8619}] => (Allow) LPort=1434 FirewallRules: [TCP Query User{6EE40AD5-EDE1-4E0D-8FA7-E75B0457575B}C:\program files (x86)\nuance\nuance cloud connector\gladinetclient.exe] => (Block) C:\program files (x86)\nuance\nuance cloud connector\gladinetclient.exe (Gladinet, Inc. -> Gladinet, INC) FirewallRules: [UDP Query User{DAF0D46E-0CBA-4DA0-AECA-21BF54EB3A32}C:\program files (x86)\nuance\nuance cloud connector\gladinetclient.exe] => (Block) C:\program files (x86)\nuance\nuance cloud connector\gladinetclient.exe (Gladinet, Inc. -> Gladinet, INC) FirewallRules: [{4552AE46-8B0F-4A2D-A2A2-30FACA146A8F}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe No File FirewallRules: [{52B742FA-2D45-4C1B-8F6C-0D7D022EC3A3}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe No File FirewallRules: [TCP Query User{637912A2-6B6B-4D3E-9FDD-F17FAD0D1F84}C:\program files (x86)\act\act for windows\act!.integration.exe] => (Allow) C:\program files (x86)\act\act for windows\act!.integration.exe (Swiftpage ACT! LLC) [File not signed] FirewallRules: [UDP Query User{8DF88AF1-A013-4CBC-811E-3BCE14A07149}C:\program files (x86)\act\act for windows\act!.integration.exe] => (Allow) C:\program files (x86)\act\act for windows\act!.integration.exe (Swiftpage ACT! LLC) [File not signed] FirewallRules: [TCP Query User{0178E895-EF13-4142-9351-FA9920DE25D4}C:\program files (x86)\neo pro\neopro.exe] => (Allow) C:\program files (x86)\neo pro\neopro.exe (Caelo Software B.V. -> Caelo Software BV.) FirewallRules: [UDP Query User{8E898744-B6D0-4392-8962-F0FA85380200}C:\program files (x86)\neo pro\neopro.exe] => (Allow) C:\program files (x86)\neo pro\neopro.exe (Caelo Software B.V. -> Caelo Software BV.) FirewallRules: [TCP Query User{4D96A4C8-BB38-48BB-9C80-38ED563995E4}C:\windows\syswow64\dllhost.exe] => (Allow) C:\windows\syswow64\dllhost.exe (Microsoft Windows -> Microsoft Corporation) FirewallRules: [UDP Query User{742D3DA5-7FBB-4846-B3FA-6E5EA9D29851}C:\windows\syswow64\dllhost.exe] => (Allow) C:\windows\syswow64\dllhost.exe (Microsoft Windows -> Microsoft Corporation) ==================== Restore Points ========================= ATTENTION: System Restore is disabled (Total:237.17 GB) (Free:29.35 GB) (12%) Check "VSS" service ==================== Faulty Device Manager Devices ============ ==================== Event log errors: ======================== Application errors: ================== Error: (03/31/2020 01:31:51 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: svchost.exe_WbioSrvc, version: 10.0.18362.1, time stamp: 0x32d6c210 Faulting module name: UPKBU.DLL, version: 1.6.1.341, time stamp: 0x502239a7 Exception code: 0xc0000005 Fault offset: 0x00000000000cccd7 Faulting process id: 0x3210 Faulting application start time: 0x01d607528762a44e Faulting application path: C:\WINDOWS\system32\svchost.exe Faulting module path: C:\WINDOWS\SYSTEM32\WINBIOPLUGINS\UPKBU.DLL Report Id: a2986204-ad8c-422f-9bd5-fdfc0b337101 Faulting package full name: Faulting package-relative application ID: Error: (03/31/2020 10:54:20 AM) (Source: Microsoft-Windows-Perflib) (EventID: 1020) (User: NT AUTHORITY) Description: The required buffer size is greater than the buffer size passed to the Collect function of the "C:\Windows\System32\perfts.dll" Extensible Counter DLL for the "LSM" service. The given buffer size was 19520 and the required size was 47024. Error: (03/31/2020 07:42:29 AM) (Source: Microsoft-Windows-PerfNet) (EventID: 2004) (User: DESKTOP-JITGEPI) Description: Unable to open the Server service performance object. The first four bytes (DWORD) of the Data section contains the status code. Error: (03/31/2020 07:42:08 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: svchost.exe_WbioSrvc, version: 10.0.18362.1, time stamp: 0x32d6c210 Faulting module name: UPKBU.DLL, version: 1.6.1.341, time stamp: 0x502239a7 Exception code: 0xc0000005 Fault offset: 0x00000000000cccd7 Faulting process id: 0x10cc Faulting application start time: 0x01d606e4f57ddedd Faulting application path: C:\WINDOWS\system32\svchost.exe Faulting module path: C:\WINDOWS\SYSTEM32\WINBIOPLUGINS\UPKBU.DLL Report Id: a0e8f461-a2d7-4494-8312-b603bcaea34e Faulting package full name: Faulting package-relative application ID: Error: (03/30/2020 06:50:04 PM) (Source: Microsoft-Windows-PerfNet) (EventID: 2004) (User: DESKTOP-JITGEPI) Description: Unable to open the Server service performance object. The first four bytes (DWORD) of the Data section contains the status code. Error: (03/30/2020 06:48:39 PM) (Source: ActWebApiService) (EventID: 0) (User: ) Description: Service cannot be started. System.Reflection.TargetInvocationException: Exception has been thrown by the target of an invocation. ---> System.Net.HttpListenerException: The process cannot access the file because it is being used by another process at System.Net.HttpListener.AddAllPrefixes() at System.Net.HttpListener.Start() at Microsoft.Owin.Host.HttpListener.OwinHttpListener.Start(HttpListener listener, Func`2 appFunc, IList`1 addresses, IDictionary`2 capabilities, Func`2 loggerFactory) at Microsoft.Owin.Host.HttpListener.OwinServerFactory.Create(Func`2 app, IDictionary`2 properties) --- End of inner exception stack trace --- at System.RuntimeMethodHandle.InvokeMethod(Object target, Object[] arguments, Signature sig, Boolean constructor) at System.Reflection.RuntimeMethodInfo.UnsafeInvokeInternal(Object obj, Object[] parameters, Object[] arguments) at System.Reflection.RuntimeMethodInfo.Invoke(Object obj, BindingFlags invokeAttr, Binder binder, Object[] parameters, CultureInfo culture) at Micros... Error: (03/30/2020 06:46:19 PM) (Source: MSSQL$ACT7) (EventID: 17187) (User: ) Description: SQL Server is not ready to accept new client connections. Wait a few minutes before trying again. If you have access to the error log, look for the informational message that indicates that SQL Server is ready before trying to connect again. [CLIENT: fe80::45bc:ba6d:edea:7e3c%8] Error: (03/30/2020 06:45:56 PM) (Source: MSSQL$ACT7) (EventID: 8317) (User: ) Description: Cannot query value 'First Counter' associated with registry key 'HKLM\SYSTEM\CurrentControlSet\Services\MSSQL$ACT7\Performance'. SQL Server performance counters are disabled. System errors: ============= Error: (03/31/2020 01:32:01 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The Windows Biometric Service service terminated unexpectedly. It has done this 2 time(s). Error: (03/31/2020 01:08:05 PM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: ) Description: 4 Error: (03/31/2020 08:00:06 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The Malwarebytes Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service. Error: (03/31/2020 07:42:37 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The Windows Biometric Service service terminated unexpectedly. It has done this 1 time(s). Error: (03/30/2020 06:48:39 PM) (Source: HTTP) (EventID: 15005) (User: ) Description: Unable to bind to the underlying transport for [::]:80. The IP Listen-Only list may contain a reference to an interface which may not exist on this machine. The data field contains the error number. Error: (03/30/2020 06:18:17 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The Malwarebytes Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service. Error: (03/30/2020 05:59:15 PM) (Source: HTTP) (EventID: 15005) (User: ) Description: Unable to bind to the underlying transport for [::]:80. The IP Listen-Only list may contain a reference to an interface which may not exist on this machine. The data field contains the error number. Error: (03/30/2020 05:51:18 PM) (Source: Service Control Manager) (EventID: 7043) (User: ) Description: The Malwarebytes Service service did not shut down properly after receiving a preshutdown control. CodeIntegrity: =================================== Date: 2020-03-31 13:47:22.045 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe) attempted to load \Device\HarddiskVolume4\Program Files\McAfee\MfeAV\AMSIExt.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2020-03-31 13:47:22.038 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe) attempted to load \Device\HarddiskVolume4\Program Files\McAfee\MfeAV\AMSIExt.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2020-03-31 13:47:22.031 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe) attempted to load \Device\HarddiskVolume4\Program Files\McAfee\MfeAV\AMSIExt.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2020-03-31 13:47:22.023 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe) attempted to load \Device\HarddiskVolume4\Program Files\McAfee\MfeAV\AMSIExt.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2020-03-31 13:47:22.017 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe) attempted to load \Device\HarddiskVolume4\Program Files\McAfee\MfeAV\AMSIExt.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2020-03-31 13:47:22.009 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe) attempted to load \Device\HarddiskVolume4\Program Files\McAfee\MfeAV\AMSIExt.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2020-03-31 13:47:06.537 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe) attempted to load \Device\HarddiskVolume4\Program Files\McAfee\MfeAV\AMSIExt.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2020-03-31 13:47:06.530 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe) attempted to load \Device\HarddiskVolume4\Program Files\McAfee\MfeAV\AMSIExt.dll that did not meet the Custom 3 / Antimalware signing level requirements. ==================== Memory info =========================== BIOS: LENOVO G1ETB7WW (2.77 ) 06/05/2018 Motherboard: LENOVO 2347H91 Processor: Intel(R) Core(TM) i5-3320M CPU @ 2.60GHz Percentage of memory in use: 55% Total physical RAM: 16203.12 MB Available physical RAM: 7268.9 MB Total Virtual: 19147.12 MB Available Virtual: 7270.84 MB ==================== Drives ================================ Drive c: (Windows) (Fixed) (Total:237.17 GB) (Free:29.35 GB) NTFS Drive n: () (Network) (Total:237.17 GB) (Free:29.35 GB) FAT \\?\Volume{2577b36b-21ec-486d-aa0a-730516ca9f19}\ (Recovery) (Fixed) (Total:0.93 GB) (Free:0.37 GB) NTFS \\?\Volume{ffe30c88-63e5-4458-a4e8-968cc3d53946}\ (SYSTEM) (Fixed) (Total:0.25 GB) (Free:0.23 GB) FAT32 ==================== MBR & Partition Table ==================== ==================== End of Addition.txt =======================