As far as what to do with the Google Drive Sync at startup I really couldn't say as I don't know what it is or does. So I await your advice.
Fix result of Farbar Recovery Scan Tool (x64) Version: 15-05-2021
Ran by Michael McDonald (15-05-2021 07:29:47) Run:1
Running from C:\Users\Michael McDonald\Desktop
Loaded Profiles: defaultuser0 & Michael McDonald
Boot Mode: Normal
==============================================
fixlist content:
*****************
CreateRestorePoint:
CloseProcesses:
AV: Total AV (Enabled - Up to date) {AC3490DF-B2AE-610F-9290-A5E6E0CD5323}
AV: Webroot SecureAnywhere (Enabled - Up to date) {A16A5B28-D1C0-417E-771B-123558EECC69}
ContextMenuHandlers1: [WRShellExt] -> {69D72956-317C-44bd-B369-8E44D4EF9802} => C:\WINDOWS\system32\WRusr.dll [2021-05-15] (Webroot Inc. -> Webroot)
ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File
ContextMenuHandlers6: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> No File
ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File
ContextMenuHandlers6: [WRShellExt] -> {69D72956-317C-44bd-B369-8E44D4EF9802} => C:\WINDOWS\system32\WRusr.dll [2021-05-15] (Webroot Inc. -> Webroot)
BHO: Webroot Filtering Extension -> {C9C42510-9B41-42c1-9DCD-7282A2D07C61} -> C:\Program Files\Common Files\Webroot\WebFiltering\wrflt.dll [2020-08-05] (Webroot Inc. -> Webroot)
BHO-x32: Webroot Filtering Extension -> {C9C42510-9B41-42c1-9DCD-7282A2D07C61} -> C:\Program Files (x86)\Common Files\Webroot\WebFiltering\wrflt.dll [2020-08-05] (Webroot Inc. -> Webroot)
FirewallRules: [{2BDCEC9C-2FDE-40D3-8274-129A16A37A33}] => (Block) C:\Program Files (x86)\Avira\SoftwareUpdater\avirasoftwareupdatertoastnotificationsbridge.exe => No File
FirewallRules: [{E427FC73-C470-451E-9D9D-D9C6C02C11BD}] => (Allow) C:\Program Files (x86)\Avira\SoftwareUpdater\avirasoftwareupdatertoastnotificationsbridge.exe => No File
FirewallRules: [{3D51B831-32D7-412C-AEFF-2B25BFC9ECED}] => (Allow) C:\Program Files (x86)\Avira\SoftwareUpdater\avirasoftwareupdatertoastnotificationsbridge.exe => No File
HKLM\...\Run: [OODefragTray] => C:\Program Files\OO Software\Defrag\oodtray.exe
HKLM\...\Run: [] => [X]
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [WRSVC] => C:\Program Files\Webroot\WRSA.exe [5555632 2021-05-04] (Webroot Inc. -> Webroot)
HKU\S-1-5-21-1034979164-3765340690-1298794446-1001\...\Run: [] => [X]
HKU\S-1-5-21-1034979164-3765340690-1298794446-1001\...\Policies\system: [shell] explorer.exe <==== ATTENTION
HKU\S-1-5-21-1034979164-3765340690-1298794446-1001\...\MountPoints2: {09fc3325-bdc3-11e6-9317-708bcd7c3e70} - "E:\WD SmartWare.exe" autoplay=true
Lsa: [Notification Packages] scecli C:\Program Files\TrueKey\McAfeeTrueKeyPasswordFilter "C:\Program Files\TrueKey\McAfeeTrueKeyPasswordFilter"
GroupPolicy-Firefox: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION
Task: {411D4897-DC00-496B-A63E-668C25DDE4D8} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
FF Extension: (Web Threat Shield) - C:\Users\Michael McDonald\AppData\Roaming\Mozilla\Firefox\Profiles\pzgz7htx.default-release\Extensions\
webrootsecure@webroot.com.xpi [2021-01-25]
CHR NewTab: Default -> Not-active:"chrome-extension://appnhedojingciaakebonapfgmpfabac/web_page_home.html"
CHR HKLM-x32\...\Chrome\Extension: [caljgklbbfbcjjanaijlacgncafpegll]
CHR HKLM-x32\...\Chrome\Extension: [ccbpbkebodcjkknkfkpmfeciinhidaeh]
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk]
R2 WRCoreService; C:\Program Files\Webroot\Core\WRCoreService.x64.exe [2037856 2020-08-25] (Webroot Inc. -> Webroot, Inc.)
R3 WRSkyClient; C:\Program Files\Webroot\Core\WRSkyClient.x64.exe [3002624 2020-08-25] (Webroot Inc. -> Webroot, Inc.)
R2 WRSVC; C:\Program Files\Webroot\WRSA.exe [5555632 2021-05-04] (Webroot Inc. -> Webroot)
S3 Browser; %SystemRoot%\System32\browser.dll [X]
R1 webshieldfilter; C:\WINDOWS\System32\drivers\webshieldfilter.sys [79048 2019-10-15] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider) <==== ATTENTION
R1 WRCore; C:\Program Files\Webroot\Core\WRCore.x64.sys [268720 2020-06-15] (Webroot Inc. -> Webroot, Inc.)
R0 WRkrn; C:\WINDOWS\System32\drivers\WRkrn.sys [149224 2020-08-05] (Webroot Inc. -> Webroot)
R3 wrUrlFlt; C:\WINDOWS\system32\DRIVERS\wrUrlFlt.sys [58304 2020-08-05] (Webroot, Inc -> Webroot)
U1 aswbdisk; no ImagePath
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Webroot SecureAnywhere
C:\Users\Michael McDonald\Downloads\driverfixwebdl-8368122072.exe
C:\Users\Michael McDonald\Downloads\DCS_World_web.exe
C:\WINDOWS\system32\Drivers\avkmgr.sys
C:\Users\Michael McDonald\Downloads\avira_en_sptl1_f8dc36737754b924__prtz1.exe
C:\Users\Michael McDonald\AppData\LocalLow\IObit
C:\Users\Michael McDonald\Downloads\db-installer.exe
C:\Users\Michael McDonald\Downloads\ks4.021.3.10.391en_25092.exe
C:\Users\Michael McDonald\AppData\Local\O&O_Software_GmbH
C:\Users\Michael McDonald\AppData\Local\O&O
C:\WINDOWS\system32\oodag
C:\ProgramData\OO Software
C:\Users\Michael McDonald\Downloads\OODefrag24Professional64Enu.exe
C:\ProgramData\IObit
C:\Users\Michael McDonald\AppData\Roaming\IObit
C:\Users\Michael McDonald\Downloads\asc-trial-setup - Copy.exe
C:\Users\Michael McDonald\Downloads\asc-trial-setup.exe
C:\WINDOWS\system32\Tasks\Avira
C:\Users\Public\Security Sessions
C:\Users\Michael McDonald\AppData\Local\Avira
C:\Program Files (x86)\Avira
C:\ProgramData\Avira
C:\Users\Michael McDonald\Downloads\avira_en_sptl1_8d6cb677dffb2ecd__pfsws-spotlight-release(1).exe
C:\Users\Michael McDonald\Downloads\avira_en_sptl1_8d6cb677dffb2ecd__pfsws-spotlight-release.exe
C:\Users\Michael McDonald\AppData\Local\AVAST Software
C:\ProgramData\Avast Software
C:\Users\Michael McDonald\Downloads\avast_free_antivirus_setup_online.exe
C:\Users\Michael McDonald\Downloads\TotalAV_Setup(1).exe
2C:\ProgramData\TotalAV
C:\Users\Michael McDonald\Downloads\TotalAV_Setup.exe
C:\WINDOWS\SysWOW64\WRusr.dll
C:\WINDOWS\system32\WRusr.dll
C:\ProgramData\WRData
C:\Program Files\Webroot
C:\Users\Michael McDonald\AppData\Roaming\Easeware
C:\Users\Michael McDonald\Documents\.tmp.drivedownload
C:\Program Files\Common Files\McAfee
C:\ProgramData\McAfee
C:\Program Files\McAfee
C:\WINDOWS\system32\Drivers\WRBoot.sys
C:\Ranulph
C:\WINDOWS\system32\WRusr.dll
C:\Program Files\Common Files\Webroot
C:\Program Files (x86)\Common Files\Webroot
C:\Program Files (x86)\Avira
C:\Program Files\OO Software
C:\Program Files\Webroot
C:\Program Files\TrueKe
C:\WINDOWS\System32\drivers\webshieldfilter.sys
C:\WINDOWS\System32\drivers\WRkrn.sys
C:\WINDOWS\system32\DRIVERS\wrUrlFlt.sys
EmptyTemp:
*****************
Restore point was successfully created.
Processes closed successfully.
"AV: Total AV (Enabled - Up to date) {AC3490DF-B2AE-610F-9290-A5E6E0CD5323}" => removed successfully
"AV: Webroot SecureAnywhere (Enabled - Up to date) {A16A5B28-D1C0-417E-771B-123558EECC69}" => removed successfully
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\WRShellExt => removed successfully
HKLM\Software\Classes\CLSID\{69D72956-317C-44bd-B369-8E44D4EF9802} => removed successfully
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\Offline Files => removed successfully
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\BriefcaseMenu => removed successfully
"HKLM\Software\Classes\CLSID\{85BBD920-42A0-1069-A2E4-08002B30309D}" => removed successfully
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\Offline Files => removed successfully
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\WRShellExt => removed successfully
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C9C42510-9B41-42c1-9DCD-7282A2D07C61} => removed successfully
HKLM\Software\Classes\CLSID\{C9C42510-9B41-42c1-9DCD-7282A2D07C61} => removed successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C9C42510-9B41-42c1-9DCD-7282A2D07C61} => removed successfully
HKLM\Software\Wow6432Node\Classes\CLSID\{C9C42510-9B41-42c1-9DCD-7282A2D07C61} => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{2BDCEC9C-2FDE-40D3-8274-129A16A37A33}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{E427FC73-C470-451E-9D9D-D9C6C02C11BD}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{3D51B831-32D7-412C-AEFF-2B25BFC9ECED}" => removed successfully
"HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\OODefragTray" => removed successfully
"HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\" => removed successfully
"HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\" => removed successfully
"HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\WRSVC" => removed successfully
"HKU\S-1-5-21-1034979164-3765340690-1298794446-1001\Software\Microsoft\Windows\CurrentVersion\Run\\" => removed successfully
"HKU\S-1-5-21-1034979164-3765340690-1298794446-1001\Software\Microsoft\Windows\CurrentVersion\Policies\system\\shell" => removed successfully
HKU\S-1-5-21-1034979164-3765340690-1298794446-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{09fc3325-bdc3-11e6-9317-708bcd7c3e70} => removed successfully
HKLM\System\CurrentControlSet\Control\Lsa\\"Notification Packages"="scecli" => value restored successfully
C:\Program Files\Mozilla Firefox\distribution\policies.json => moved successfully
HKLM\SOFTWARE\Policies\Mozilla => removed successfully
HKLM\SOFTWARE\Policies\Microsoft\Edge => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{411D4897-DC00-496B-A63E-668C25DDE4D8}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{411D4897-DC00-496B-A63E-668C25DDE4D8}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UNP\RunCampaignManager" => not found
HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => removed successfully
HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\BookReader_B171F20233094AC88D05A8EF7B9763E8 => removed successfully
HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => removed successfully
HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => removed successfully
C:\Users\Michael McDonald\AppData\Roaming\Mozilla\Firefox\Profiles\pzgz7htx.default-release\Extensions\
webrootsecure@webroot.com.xpi => moved successfully
"Chrome NewTab" => removed successfully
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\caljgklbbfbcjjanaijlacgncafpegll => removed successfully
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ccbpbkebodcjkknkfkpmfeciinhidaeh => removed successfully
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\flliilndjeohchalpbbcdekjklbdgfkk => removed successfully
WRCoreService => Unable to stop service.
HKLM\System\CurrentControlSet\Services\WRCoreService => could not remove, key could be protected
WRSkyClient => Unable to stop service.
HKLM\System\CurrentControlSet\Services\WRSkyClient => could not remove, key could be protected
WRSVC => Unable to stop service.
HKLM\System\CurrentControlSet\Services\WRSVC => removed successfully
HKLM\System\CurrentControlSet\Services\Browser => removed successfully
Browser => service removed successfully
webshieldfilter => Service stopped successfully.
HKLM\System\CurrentControlSet\Services\webshieldfilter => removed successfully
webshieldfilter => service removed successfully
WRCore => Unable to stop service.
HKLM\System\CurrentControlSet\Services\WRCore => could not remove, key could be protected
WRkrn => Unable to stop service.
Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 15-05-2021 07:53:58)
Result of scheduled keys to remove after reboot:
HKLM\System\CurrentControlSet\Services\WRCoreService => could not remove, key could be protected
HKLM\System\CurrentControlSet\Services\WRSkyClient => could not remove, key could be protected
HKLM\System\CurrentControlSet\Services\WRCore => could not remove, key could be protected
==== End of Fixlog 07:53:58 ====