1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

Receiving Notice at Start-Up That a File is Missing

Discussion in 'Windows 10' started by referee07, Jan 5, 2018.

Advertisement
  1. referee07

    referee07 Thread Starter

    Joined:
    Sep 11, 2003
    Messages:
    1,304
    I do not know if this is the correct forum but since I have A Windows 10 computer, I am going to start here. Several weeks ago, when I turn-on my computer, I receive two notices on my screen which are the same, one right after the other. The notices read:

    "C:\program files\WindowsApps\DB6EA5DB.Power2GoforDell_8.0.7610.0_x86_mcez...\CLMLSvc_P2G8.exe.
    The specified path does not exist.

    Check the path, and then try again."

    I am wondering if anyone knows what this message means and what the file shown is supposed to do/mean? Thanks in advance for any and all replies/suggestions.
     
  2. Sponsor

  3. DaveA

    DaveA Trusted Advisor

    Joined:
    Nov 16, 1999
    Messages:
    14,375
    First Name:
    David
    I found the following
    Do you have this installed on your machine?
     
  4. referee07

    referee07 Thread Starter

    Joined:
    Sep 11, 2003
    Messages:
    1,304
    DaveA, thanks for your repl. I don't think that it's installed. I did a search and nothing showed up. My computer has Windows 10 installed. Does it need this file. And, if so, do you know where I can download it? Thanks again for your reply.
     
  5. DaveA

    DaveA Trusted Advisor

    Joined:
    Nov 16, 1999
    Messages:
    14,375
    First Name:
    David
    I see no requirement if you do not have Medical library installed
     
  6. referee07

    referee07 Thread Starter

    Joined:
    Sep 11, 2003
    Messages:
    1,304
    DaveA, thanks again for your reply. I don't believe that I have a medical library installed on my computer and I am wondering why this file was installed? Also, I am wondering if I can find this file to download just to have it on my computer since it apparently was there previously and also to prevent the two pop-up that are shown each time that I start my computer telling me that the file is missing.
     
  7. dvk01

    dvk01 Moderator Malware Specialist

    Joined:
    Dec 14, 2002
    Messages:
    52,578
    First Name:
    Derek
    It is NOT MEDICAL library it is MEDIA library

    It is part of power to go for dell
    That is a specially customised, reduced functionality version of cyberlink dvd /cd burning software and media playing software. Because W10 uses APPS rather than programs, it will almost certainly auto-update and in some cases the old startup entry will not be removed when a new one is created
    Lets see what this shows us & work from there. Probably the best way will be for us to remove the auto-start entry to stop the alerts. The program will still be available when you need to use it from start menu.
    However it also could be that an anti-malware program like adwcleaner or MBAM will have accidentally removed the App because it can be seen or detected as adware due to the prompts to update to the full featured edition at the appropriate price.

    Please download Farbar Recovery Scan Tool and save it to your Desktop.

    Note: You need to download and run the 64 bit version

    • Right click to run as administrator. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will produce a log called FRST.txt in the same directory the tool is run from.
    • Please copy and paste log back here.
    • The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply.
     
  8. referee07

    referee07 Thread Starter

    Joined:
    Sep 11, 2003
    Messages:
    1,304
    dvk01, thanks for your reply. Because of the size limitations, I will need to send Thanks again for your help.

    Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 17.01.2018 01
    Ran by Refer (administrator) on DESKTOP-T60B7T6 (21-01-2018 14:02:09)
    Running from C:\Users\Refer\Desktop
    Loaded Profiles: Refer (Available Profiles: Refer)
    Platform: Windows 10 Home Version 1709 16299.192 (X64) Language: English (United States)
    Internet Explorer Version 11 (Default browser: IE)
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (ESET) C:\Program Files\ESET\ESET Security\ekrn.exe
    (SurfRight B.V.) C:\Program Files (x86)\HitmanPro.Alert\hmpalert.exe
    (AMD) C:\Windows\System32\atiesrxx.exe
    (AMD) C:\Windows\System32\atieclxx.exe
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
    (SurfRight B.V.) C:\Program Files (x86)\HitmanPro.Alert\hmpalert.exe
    (SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
    (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    (Windows (R) Win 7 DDK provider) C:\Program Files (x86)\Qualcomm\Bluetooth Suite\AdminService.exe
    (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
    () C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
    (Nuance Communications, Inc.) C:\Program Files (x86)\Common Files\Nuance\dgnsvc.exe
    (Waves Audio Ltd.) C:\Program Files\Waves\MaxxAudio\WavesSysSvc64.exe
    () C:\Program Files\WinZip\WinZip Smart Monitor\WinZip Compression Smart Monitor Service.exe
    () C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
    (Acronis International GmbH) C:\Program Files (x86)\Common Files\Acronis\Infrastructure\mms_mini.exe
    () C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe
    (Acronis International GmbH) C:\Program Files (x86)\Common Files\Acronis\ActiveProtection\anti_ransomware_service.exe
    (Nuance Communications, Inc.) C:\Program Files (x86)\Common Files\Nuance\loggerservice.exe
    (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
    (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
    (Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe
    (Corel Corporation) C:\Program Files\WinZip\WinZip Smart Monitor\WinZipCompressionSmartMonitor.exe
    (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
    (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
    (Dell Inc.) C:\Program Files\Dell\QuickSet\quickset.exe
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
    (Waves Audio Ltd.) C:\Program Files\Waves\MaxxAudio\WavesSvc64.exe
    (ESET) C:\Program Files\ESET\ESET Security\egui.exe
    (WinZip Computing, S.L.) C:\Program Files\WinZip\WzPreloader.exe
    (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
    (SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
    (Flexera Software LLC.) C:\ProgramData\FLEXnet\Connect\11\agent.exe
    (Siber Systems) C:\Program Files (x86)\Siber Systems\AI RoboForm\robotaskbaricon.exe
    (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
    (Flexera Software LLC.) C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe
    () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.13.274.0_x64__kzf8qxf38zg5c\SkypeHost.exe
    (Dell Inc.) C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe
    (Dell Inc.) C:\Program Files (x86)\Dell Customer Connect\DCCService.exe
    (Dell) C:\Program Files\Dell\Dell Foundation Services\DFSSvc.exe
    (Dell Inc.) C:\Program Files\Dell\Dell Help & Support\MDLCSvc.exe
    (Dell) C:\Program Files\Dell\SARemediation\agent\DellSupportAssistRemedationService.exe
    (Dell Products, LP.) C:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe
    (Dell Inc.) C:\Program Files (x86)\Dell Update\DellUpService.exe
    (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe
    (Dell) C:\Program Files\Dell\Dell Product Registration\PRSvc.exe
    (Dell Inc.) C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe
    () C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe
    (Dell Inc.) C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe
    (Dell Inc.) C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe
    (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.LockApp_cw5n1h2txyewy\LockApp.exe
    (Dell) C:\Program Files\Dell\Dell Foundation Services\DFS.Common.Agent.exe
    (MySoftware, Inc.) C:\Program Files (x86)\Common Files\MySoftware\Newsflsh.exe
    () C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe
    () C:\Program Files (x86)\LanInfo\laninfo.exe
    (Acronis International GmbH) C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe
    (Microsoft Corporation) C:\Windows\System32\dllhost.exe
    (Dell Inc.) C:\Program Files\Dell\DellDataVault\atiw.exe
    (Strong Technology, LLC) C:\Program Files (x86)\StrongVPN\StrongDial.exe
    (Transparent Language) C:\Program Files (x86)\Transparent\Byki 4\Deluxe\BYKI4Deluxe.exe
    (Apple Inc.) C:\Program Files\iTunes\iTunes.exe
    (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
    (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe
    (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe
    (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_11712.1001.13.0_x64__8wekyb3d8bbwe\WinStore.App.exe
    () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.39101.16720.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
    (Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
    (Dell Inc.) C:\Program Files (x86)\Dell Update\DellUpTray.exe
    (Microsoft Corporation) C:\Windows\System32\smartscreen.exe

    ==================== Registry (Whitelisted) ===========================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [630168 2017-09-29] (Microsoft Corporation)
    HKLM\...\Run: [QuickSet] => c:\Program Files\Dell\QuickSet\QuickSet.exe [7823824 2016-05-24] (Dell Inc.)
    HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9072128 2016-11-18] (Realtek Semiconductor)
    HKLM\...\Run: [WavesSvc] => C:\Program Files\Waves\MaxxAudio\WavesSvc64.exe [940976 2016-11-20] (Waves Audio Ltd.)
    HKLM\...\Run: [Acronis Scheduler2 Service] => C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [585296 2017-11-22] ()
    HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Security\ecmdS.exe [324216 2017-11-04] (ESET)
    HKLM\...\Run: [WinZip UN] => C:\Program Files\WinZip\WZUpdateNotifier.exe [2047744 2017-11-01] (WinZip)
    HKLM\...\Run: [WinZip PreLoader] => C:\Program Files\WinZip\WzPreloader.exe [117760 2017-11-01] (WinZip Computing, S.L.)
    HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [297272 2017-12-11] (Apple Inc.)
    HKLM-x32\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\\isuspm.exe [2068856 2011-10-12] (Flexera Software LLC.)
    HKLM-x32\...\Run: [TrueImageMonitor.exe] => C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe [4620736 2017-12-22] ()
    HKLM-x32\...\Run: [LanInfo] => C:\Program Files (x86)\LanInfo\laninfo.exe [184832 2016-11-22] ()
    HKLM-x32\...\Run: [AcronisTibMounterMonitor] => C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe [425864 2017-09-26] (Acronis International GmbH)
    HKU\S-1-5-21-1534629146-3426154806-933795594-1001\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [7964080 2018-01-18] (SUPERAntiSpyware)
    HKU\S-1-5-21-1534629146-3426154806-933795594-1001\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [2068856 2011-10-12] (Flexera Software LLC.)
    HKU\S-1-5-21-1534629146-3426154806-933795594-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27832264 2017-10-06] (Skype Technologies S.A.)
    HKU\S-1-5-21-1534629146-3426154806-933795594-1001\...\Run: [RoboForm] => C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe [110376 2018-01-05] (Siber Systems)
    HKU\S-1-5-21-1534629146-3426154806-933795594-1001\...\RunOnce: [Privacy Controls] => C:\Program Files (x86)\ParetoLogic\Privacy Controls\Pareto_PC.exe [2061816 2016-11-18] (ParetoLogic, Inc.)
    HKU\S-1-5-21-1534629146-3426154806-933795594-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Bubbles.scr [805888 2017-09-29] (Microsoft Corporation)
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\MySoftware NewsFlash.lnk [2017-10-05]
    ShortcutTarget: MySoftware NewsFlash.lnk -> C:\Program Files (x86)\Common Files\MySoftware\Newsflsh.exe (MySoftware, Inc.)
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk [2017-09-28]
    ShortcutTarget: Quicken Scheduled Updates.lnk -> C:\Program Files (x86)\Quicken\bagent.exe (Intuit Inc.)

    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    Tcpip\..\Interfaces\{3197186E-6C44-4500-A03A-030DE019BF7F}: [NameServer] 216.131.91.251 216.131.91.252
    Tcpip\..\Interfaces\{9905572e-877c-4a6d-804c-362917bb6d1e}: [DhcpNameServer] 61.41.153.2 1.214.68.2

    Internet Explorer:
    ==================
    HKU\S-1-5-21-1534629146-3426154806-933795594-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://dell17win10.msn.com/?pc=DCTE
    HKU\S-1-5-21-1534629146-3426154806-933795594-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://npr.com/
    SearchScopes: HKU\S-1-5-21-1534629146-3426154806-933795594-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02&pc=UE04
    SearchScopes: HKU\S-1-5-21-1534629146-3426154806-933795594-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02&pc=UE04
    SearchScopes: HKU\S-1-5-21-1534629146-3426154806-933795594-1001 -> {8DB2F297-9754-4064-B256-2A7E3BC4C603} URL = hxxp://www.google.com/search?q={searchTerms}
    SearchScopes: HKU\S-1-5-21-1534629146-3426154806-933795594-1001 -> {CE0A30BD-C6F2-4758-9F20-2CDB3FFAF1BE} URL =
    BHO: No Name -> {0ddcea2a-7b00-4349-8acb-af7ba6da251f} -> No File
    BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2018-01-21] (Microsoft Corporation)
    BHO: Dragon Web Extension For Internet Explorer -> {609C0837-8DD3-4F9B-AAC5-446F36BC0353} -> C:\Program Files (x86)\Nuance\NaturallySpeaking13\Program\x64\dgnriaie_x64.dll [2014-07-23] (Nuance Communications, Inc.)
    BHO: RoboForm Toolbar Helper -> {724d43a9-0d85-11d4-9908-00400523e39a} -> C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll [2018-01-05] (Siber Systems Inc.)
    BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2017-09-30] (Google Inc.)
    BHO-x32: AcroIEHlprObj Class -> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -> C:\Program Files (x86)\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx [2001-04-16] ()
    BHO-x32: No Name -> {0ddcea2a-7b00-4349-8acb-af7ba6da251f} -> No File
    BHO-x32: Dragon Web Extension For Internet Explorer -> {609C0837-8DD3-4F9B-AAC5-446F36BC0353} -> C:\Program Files (x86)\Nuance\NaturallySpeaking13\Program\dgnriaie.dll [2014-07-23] (Nuance Communications, Inc.)
    BHO-x32: RoboForm Toolbar Helper -> {724d43a9-0d85-11d4-9908-00400523e39a} -> C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll [2018-01-05] (Siber Systems Inc.)
    BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2017-09-30] (Google Inc.)
    Toolbar: HKLM - &RoboForm Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll [2018-01-05] (Siber Systems Inc.)
    Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2017-09-30] (Google Inc.)
    Toolbar: HKLM-x32 - &RoboForm Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll [2018-01-05] (Siber Systems Inc.)
    Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2017-09-30] (Google Inc.)
    Toolbar: HKU\S-1-5-21-1534629146-3426154806-933795594-1001 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2017-09-30] (Google Inc.)
    Toolbar: HKU\S-1-5-21-1534629146-3426154806-933795594-1001 -> &RoboForm Toolbar - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll [2018-01-05] (Siber Systems Inc.)
    Handler-x32: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\BelarcAdvisor\System\BAVoilaX.dll [2016-01-04] (Belarc, Inc.)
    Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-01-21] (Microsoft Corporation)
    Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-01-21] (Microsoft Corporation)
    Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-01-21] (Microsoft Corporation)
    Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-01-21] (Microsoft Corporation)

    FireFox:
    ========
    FF Plugin: nuance.com/DgnRia2_x86_64 -> C:\Program Files (x86)\Nuance\NaturallySpeaking13\Program\x64\npDgnRia2_x64.dll [2014-07-23] (Nuance Communications, Inc.)
    FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2018-01-21] (Microsoft Corporation)
    FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-15] (Google Inc.)
    FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-15] (Google Inc.)
    FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-11-05] (Adobe Systems Inc.)
    FF Plugin-x32: nuance.com/DgnRia2 -> C:\Program Files (x86)\Nuance\NaturallySpeaking13\Program\npDgnRia2.dll [2014-07-23] (Nuance Communications, Inc.)
    FF Plugin HKU\S-1-5-21-1534629146-3426154806-933795594-1001: SkypePlugin -> C:\Users\Refer\AppData\Local\SkypePlugin\7.32.6.278\npGatewayNpapi.dll [2017-04-18] (Skype Technologies S.A.)
    FF Plugin HKU\S-1-5-21-1534629146-3426154806-933795594-1001: SkypePlugin64 -> C:\Users\Refer\AppData\Local\SkypePlugin\7.32.6.278\npGatewayNpapi-x64.dll [2017-04-18] (Skype Technologies S.A.)

    ==================== Services (Whitelisted) ====================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [173472 2017-01-31] (SUPERAntiSpyware.com)
    R2 AcronisActiveProtectionService; C:\Program Files (x86)\Common Files\Acronis\ActiveProtection\anti_ransomware_service.exe [2723872 2017-12-22] (Acronis International GmbH)
    R2 AcrSch2Svc; C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe [1216760 2017-11-22] ()
    R2 afcdpsrv; C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe [6096688 2017-12-23] ()
    R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2017-11-27] (Apple Inc.)
    R2 AtherosSvc; C:\Program Files (x86)\Qualcomm\Bluetooth Suite\adminservice.exe [414728 2017-11-09] (Windows (R) Win 7 DDK provider)
    R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [7780528 2018-01-15] (Microsoft Corporation)
    R2 DDVCollectorSvcApi; C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe [208792 2017-12-14] (Dell Inc.)
    R2 DDVDataCollector; C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe [3294608 2017-12-14] (Dell Inc.)
    R2 DDVRulesProcessor; C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe [217488 2017-12-14] (Dell Inc.)
    R2 Dell Customer Connect; C:\Program Files (x86)\Dell Customer Connect\DCCService.exe [130936 2017-09-19] (Dell Inc.)
    R2 Dell Foundation Services; C:\Program Files\Dell\Dell Foundation Services\DFSSvc.exe [97616 2017-01-12] (Dell)
    R2 Dell Help & Support; C:\Program Files\Dell\Dell Help & Support\MDLCSvc.exe [40976 2017-09-18] (Dell Inc.)
    R2 Dell SupportAssist Remediation; C:\Program Files\Dell\SARemediation\agent\DellSupportAssistRemedationService.exe [122400 2017-10-13] (Dell)
    R2 DellUpdate; C:\Program Files (x86)\Dell Update\DellUpService.exe [232320 2017-11-21] (Dell Inc.)
    R2 DragonLoggerService; C:\Program Files (x86)\Common Files\Nuance\loggerservice.exe [137280 2014-07-23] (Nuance Communications, Inc.)
    R2 ekrn; C:\Program Files\ESET\ESET Security\ekrn.exe [2648184 2017-11-04] (ESET)
    R2 hmpalertsvc; C:\Program Files (x86)\HitmanPro.Alert\hmpalert.exe [4451976 2018-01-10] (SurfRight B.V.)
    R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6234056 2017-11-01] (Malwarebytes)
    R2 mmsminisrv; C:\Program Files (x86)\Common Files\Acronis\Infrastructure\mms_mini.exe [4808088 2017-09-26] (Acronis International GmbH)
    S3 mobile_backup_server; C:\Program Files (x86)\Common Files\Acronis\MobileBackupServer\mobile_backup_server.exe [3004128 2017-09-26] (Acronis International GmbH)
    S3 mobile_backup_status_server; C:\Program Files (x86)\Acronis\TrueImageHome\mobile_backup_status_server.exe [1742464 2017-12-22] ()
    R2 Product Registration; C:\Program Files\Dell\Dell Product Registration\PRSvc.exe [46632 2017-04-18] (Dell)
    R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [321024 2016-11-18] (Realtek Semiconductor)
    R2 SupportAssistAgent; C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [41432 2017-12-22] (Dell Inc.)
    R2 syncagentsrv; C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe [7003048 2017-09-26] ()
    R2 WavesSysSvc; C:\Program Files\Waves\MaxxAudio\WavesSysSvc64.exe [410032 2016-11-20] (Waves Audio Ltd.)
    S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [355304 2017-09-29] (Microsoft Corporation)
    S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [105944 2017-09-29] (Microsoft Corporation)
    R2 WinZip Compression Smart Monitor Service; C:\Program Files\WinZip\WinZip Smart Monitor\WinZip Compression Smart Monitor Service.exe [495872 2017-09-01] ()

    ===================== Drivers (Whitelisted) ======================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R3 amdgpio2; C:\WINDOWS\System32\drivers\amdgpio2.sys [34704 2016-08-14] (Advanced Micro Devices, Inc)
    R3 amdi2c; C:\WINDOWS\System32\drivers\amdi2c.sys [54128 2017-05-12] (Advanced Micro Devices, Inc)
    S3 amdkmcsp; C:\WINDOWS\system32\DRIVERS\amdkmcsp.sys [101232 2017-06-16] (Advanced Micro Devices, Inc. )
    R3 amdkmdag; C:\WINDOWS\System32\DriverStore\FileRepository\c0317141.inf_amd64_2eed390644ee8b7a\atikmdag.sys [36574616 2017-08-23] (Advanced Micro Devices, Inc.)
    R3 amdkmdap; C:\WINDOWS\System32\DriverStore\FileRepository\c0317141.inf_amd64_2eed390644ee8b7a\atikmpag.sys [528792 2017-08-23] (Advanced Micro Devices, Inc.)
    R0 amdpsp; C:\WINDOWS\System32\DRIVERS\amdpsp.sys [243048 2017-06-16] (Advanced Micro Devices, Inc. )
    R3 AtiHDAudioService; C:\WINDOWS\system32\drivers\AtihdWT6.sys [110088 2017-04-26] (Advanced Micro Devices)
    R3 BtFilter; C:\WINDOWS\system32\DRIVERS\btfilter.sys [70544 2017-11-09] (Qualcomm)
    R3 DDDriver; C:\WINDOWS\system32\drivers\DDDriver64Dcsa.sys [41608 2017-12-14] (Dell Inc.)
    R3 DellProf; C:\WINDOWS\system32\drivers\DellProf.sys [41208 2017-12-14] (Dell Computer Corporation)
    R3 DellRbtn; C:\WINDOWS\System32\drivers\DellRbtn.sys [22864 2016-10-27] (OSR Open Systems Resources, Inc.)
    R3 dot4; C:\WINDOWS\system32\DRIVERS\Dot4.sys [151968 2012-10-19] (Windows (R) Win 7 DDK provider)
    R3 Dot4Print; C:\WINDOWS\System32\drivers\Dot4Prt.sys [27040 2012-10-19] (Windows (R) Win 7 DDK provider)
    R1 eamonm; C:\WINDOWS\System32\DRIVERS\eamonm.sys [132848 2017-11-04] (ESET)
    S0 eelam; C:\WINDOWS\System32\DRIVERS\eelam.sys [15392 2017-11-04] (ESET)
    R1 ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [180088 2017-11-04] (ESET)
    R1 epfwwfpr; C:\WINDOWS\system32\DRIVERS\epfwwfpr.sys [77736 2017-11-04] (ESET)
    R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [77432 2017-11-29] ()
    R2 file_protector; C:\WINDOWS\System32\DRIVERS\file_protector.sys [569392 2017-12-23] (Acronis International GmbH)
    R0 file_tracker; C:\WINDOWS\System32\DRIVERS\file_tracker.sys [379664 2017-12-23] (Acronis International GmbH)
    R1 hmpalert; C:\Windows\system32\drivers\hmpalert.sys [293560 2018-01-10] (SurfRight B.V.)
    R3 hmpnet; C:\Windows\system32\drivers\hmpnet.sys [93800 2018-01-10] (SurfRight B.V.)
    R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [193968 2017-12-13] (Malwarebytes)
    R3 MBAMFarflt; C:\WINDOWS\system32\DRIVERS\farflt.sys [110016 2018-01-21] (Malwarebytes)
    R3 MBAMProtection; C:\WINDOWS\system32\DRIVERS\mbam.sys [46008 2018-01-21] (Malwarebytes)
    R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [253880 2018-01-21] (Malwarebytes)
    R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [94144 2018-01-21] (Malwarebytes)
    R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [943112 2016-08-23] (Realtek )
    R3 RTSUER; C:\WINDOWS\system32\Drivers\RtsUer.sys [418784 2016-08-05] (Realsil Semiconductor Corporation)
    R3 rtsuvc; C:\WINDOWS\system32\DRIVERS\rtsuvc.sys [3224576 2016-12-22] (Realtek Semiconductor Corp.)
    R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-23] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
    R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-13] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
    R0 tib; C:\WINDOWS\System32\DRIVERS\tib.sys [1310552 2017-12-23] (Acronis International GmbH)
    R2 tib_mounter; C:\WINDOWS\system32\DRIVERS\tib_mounter.sys [213336 2017-12-23] (Acronis International GmbH)
    S3 tnd; C:\WINDOWS\system32\DRIVERS\tnd.sys [690520 2017-12-23] (Acronis International GmbH)
    R2 virtual_file; C:\WINDOWS\System32\DRIVERS\virtual_file.sys [331976 2017-12-23] (Acronis International GmbH)
    R0 volume_tracker; C:\WINDOWS\System32\DRIVERS\volume_tracker.sys [243472 2017-12-23] (Acronis International GmbH)
    S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44608 2017-09-29] (Microsoft Corporation)
    S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [309144 2017-09-29] (Microsoft Corporation)
    S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [119192 2017-09-29] (Microsoft Corporation)
    R3 WirelessKeyboardFilter; C:\WINDOWS\System32\drivers\WirelessKeyboardFilter.sys [49896 2016-07-22] (Microsoft Corporation)

    ==================== NetSvcs (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


    ==================== One Month Created files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2018-01-21 14:02 - 2018-01-21 14:03 - 000024224 _____ C:\Users\Refer\Desktop\FRST.txt
    2018-01-21 14:01 - 2018-01-21 14:02 - 000000000 ____D C:\FRST
    2018-01-21 14:00 - 2018-01-21 14:00 - 002393088 _____ (Farbar) C:\Users\Refer\Desktop\FRST64.exe
    2018-01-18 22:49 - 2018-01-18 22:49 - 000000214 _____ C:\Users\Refer\Desktop\South Korea Jobs - Osan Jobs.url
    2018-01-18 20:41 - 2018-01-18 20:48 - 000000000 ____D C:\Users\Refer\AppData\Roaming\PCDr
    2018-01-15 15:10 - 2018-01-15 15:10 - 000000000 ____D C:\ProgramData\Dell Inc
    2018-01-13 18:29 - 2018-01-13 18:29 - 000000000 ____D C:\Program Files (x86)\Dell Update
    2018-01-13 10:49 - 2018-01-13 10:49 - 000001818 _____ C:\Users\Public\Desktop\iTunes.lnk
    2018-01-13 10:49 - 2018-01-13 10:49 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
    2018-01-13 10:49 - 2018-01-13 10:49 - 000000000 ____D C:\Program Files\iPod
    2018-01-13 10:43 - 2018-01-13 10:49 - 000000000 ____D C:\Program Files\iTunes
    2018-01-10 09:09 - 2018-01-10 09:09 - 050863932 _____ C:\Users\Refer\Desktop\korean-grammar-in-use-beginner-to-Early- Intermediate.pdf
    2018-01-06 08:55 - 2018-01-01 21:51 - 001055128 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
    2018-01-06 08:55 - 2018-01-01 21:51 - 000059800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bam.sys
    2018-01-06 08:55 - 2018-01-01 21:49 - 008605080 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
    2018-01-06 08:55 - 2018-01-01 21:48 - 001954048 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
    2018-01-06 08:55 - 2018-01-01 21:47 - 000082840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volmgr.sys
    2018-01-06 08:55 - 2018-01-01 21:46 - 002709704 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
    2018-01-06 08:55 - 2018-01-01 21:46 - 000471960 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll
    2018-01-06 08:55 - 2018-01-01 21:45 - 000398744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fltMgr.sys
    2018-01-06 08:55 - 2018-01-01 21:42 - 000571288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
    2018-01-06 08:55 - 2018-01-01 21:39 - 000902416 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
    2018-01-06 08:55 - 2018-01-01 21:39 - 000362904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
    2018-01-06 08:55 - 2018-01-01 21:39 - 000129432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvsocket.sys
    2018-01-06 08:55 - 2018-01-01 21:37 - 001426664 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
    2018-01-06 08:55 - 2018-01-01 21:36 - 000166296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\partmgr.sys
    2018-01-06 08:55 - 2018-01-01 21:34 - 007385088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
    2018-01-06 08:55 - 2018-01-01 21:33 - 000603920 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
    2018-01-06 08:55 - 2018-01-01 21:26 - 000428952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
    2018-01-06 08:55 - 2018-01-01 21:25 - 000147864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wcifs.sys
    2018-01-06 08:55 - 2018-01-01 20:53 - 001615712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
    2018-01-06 08:55 - 2018-01-01 20:45 - 005615968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll
    2018-01-06 08:55 - 2018-01-01 20:45 - 002192624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
    2018-01-06 08:55 - 2018-01-01 20:42 - 006479552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
    2018-01-06 08:55 - 2018-01-01 20:42 - 004644912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
    2018-01-06 08:55 - 2018-01-01 20:42 - 001246432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
    2018-01-06 08:55 - 2018-01-01 20:42 - 000982528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
    2018-01-06 08:55 - 2018-01-01 20:34 - 000703568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
    2018-01-06 08:55 - 2018-01-01 20:25 - 002905600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
    2018-01-06 08:55 - 2018-01-01 20:25 - 000344576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgeIso.dll
    2018-01-06 08:55 - 2018-01-01 20:24 - 003668480 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
    2018-01-06 08:55 - 2018-01-01 20:24 - 000202240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
    2018-01-06 08:55 - 2018-01-01 20:23 - 000536576 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeIso.dll
    2018-01-06 08:55 - 2018-01-01 20:21 - 000192512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netvsc.sys
    2018-01-06 08:55 - 2018-01-01 20:20 - 019337216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
    2018-01-06 08:55 - 2018-01-01 20:20 - 018917888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
    2018-01-06 08:55 - 2018-01-01 20:19 - 000369152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll
    2018-01-06 08:55 - 2018-01-01 20:19 - 000365568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
    2018-01-06 08:55 - 2018-01-01 20:18 - 000374784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FirewallAPI.dll
    2018-01-06 08:55 - 2018-01-01 20:18 - 000261632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
    2018-01-06 08:55 - 2018-01-01 20:17 - 011923968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
    2018-01-06 08:55 - 2018-01-01 20:17 - 000708096 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
    2018-01-06 08:55 - 2018-01-01 20:17 - 000559104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
    2018-01-06 08:55 - 2018-01-01 20:17 - 000542208 _____ (Microsoft Corporation) C:\WINDOWS\system32\FirewallAPI.dll
    2018-01-06 08:55 - 2018-01-01 20:16 - 003676672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
    2018-01-06 08:55 - 2018-01-01 20:16 - 000815616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
    2018-01-06 08:55 - 2018-01-01 20:16 - 000664576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
    2018-01-06 08:55 - 2018-01-01 20:16 - 000594944 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
    2018-01-06 08:55 - 2018-01-01 20:16 - 000463360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
    2018-01-06 08:55 - 2018-01-01 20:15 - 012687872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
    2018-01-06 08:55 - 2018-01-01 20:15 - 006029312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
    2018-01-06 08:55 - 2018-01-01 20:15 - 000588800 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
    2018-01-06 08:55 - 2018-01-01 20:14 - 002465280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
    2018-01-06 08:55 - 2018-01-01 20:13 - 012830208 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
    2018-01-06 08:55 - 2018-01-01 20:13 - 002869760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
    2018-01-06 08:55 - 2018-01-01 20:12 - 001547776 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
    2018-01-06 08:55 - 2018-01-01 20:11 - 008108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
    2018-01-06 08:55 - 2018-01-01 20:11 - 004748288 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
    2018-01-06 08:55 - 2018-01-01 20:11 - 000812032 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
    2018-01-06 08:55 - 2018-01-01 20:09 - 001487872 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
    2018-01-06 08:55 - 2018-01-01 20:08 - 000685056 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
    2018-01-06 08:55 - 2018-01-01 20:08 - 000424448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv.sys
    2018-01-06 08:54 - 2018-01-02 02:15 - 000956416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Spectrum.exe
    2018-01-06 08:54 - 2018-01-01 21:50 - 005905752 _____ (Microsoft Corporation) C:\WINDOWS\system32\StartTileData.dll
    2018-01-06 08:54 - 2018-01-01 21:49 - 000319352 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64.dll
    2018-01-06 08:54 - 2018-01-01 21:48 - 007831760 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll
    2018-01-06 08:54 - 2018-01-01 21:45 - 002395032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
    2018-01-06 08:54 - 2018-01-01 21:45 - 001277848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
    2018-01-06 08:54 - 2018-01-01 21:42 - 000184984 _____ (Microsoft Corporation) C:\WINDOWS\system32\sspicli.dll
    2018-01-06 08:54 - 2018-01-01 21:41 - 007676296 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
    2018-01-06 08:54 - 2018-01-01 21:40 - 001206680 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
    2018-01-06 08:54 - 2018-01-01 21:38 - 003904808 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
    2018-01-06 08:54 - 2018-01-01 21:35 - 001170008 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
    2018-01-06 08:54 - 2018-01-01 21:32 - 004481240 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
    2018-01-06 08:54 - 2018-01-01 21:27 - 000713624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys
    2018-01-06 08:54 - 2018-01-01 21:25 - 000615768 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe
    2018-01-06 08:54 - 2018-01-01 21:23 - 021352144 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
    2018-01-06 08:54 - 2018-01-01 21:03 - 000123512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sspicli.dll
    2018-01-06 08:54 - 2018-01-01 20:46 - 003485392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
    2018-01-06 08:54 - 2018-01-01 20:45 - 006092152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
    2018-01-06 08:54 - 2018-01-01 20:43 - 020286120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
    2018-01-06 08:54 - 2018-01-01 20:37 - 025247232 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
    2018-01-06 08:54 - 2018-01-01 20:23 - 000250368 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
    2018-01-06 08:54 - 2018-01-01 20:19 - 000461312 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansec.dll
    2018-01-06 08:54 - 2018-01-01 20:19 - 000334848 _____ (Microsoft Corporation) C:\WINDOWS\system32\dusmsvc.dll
    2018-01-06 08:54 - 2018-01-01 20:18 - 000431616 _____ (Microsoft Corporation) C:\WINDOWS\system32\msIso.dll
    2018-01-06 08:54 - 2018-01-01 20:16 - 000812544 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
    2018-01-06 08:54 - 2018-01-01 20:16 - 000720896 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
    2018-01-06 08:54 - 2018-01-01 20:14 - 023655936 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
    2018-01-06 08:54 - 2018-01-01 20:13 - 013657600 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
    2018-01-06 08:54 - 2018-01-01 20:13 - 003121664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Bluetooth.Profiles.Gatt.dll
    2018-01-06 08:54 - 2018-01-01 20:12 - 002633216 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
    2018-01-06 08:54 - 2018-01-01 20:12 - 001424896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
    2018-01-06 08:54 - 2018-01-01 20:11 - 003334144 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
    2018-01-06 08:54 - 2018-01-01 20:11 - 002859520 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
    2018-01-06 08:54 - 2018-01-01 20:09 - 000925184 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
    2018-01-06 08:53 - 2018-01-01 21:54 - 000924648 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
    2018-01-06 08:53 - 2018-01-01 21:53 - 001090984 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
    2018-01-06 08:53 - 2018-01-01 21:51 - 001414784 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
    2018-01-06 08:53 - 2018-01-01 21:51 - 001209240 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
    2018-01-06 08:53 - 2018-01-01 21:50 - 000780464 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
    2018-01-06 08:53 - 2018-01-01 21:50 - 000479912 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase_enclave.dll
    2018-01-06 08:53 - 2018-01-01 21:48 - 000382360 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
    2018-01-06 08:53 - 2018-01-01 21:46 - 000898216 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
    2018-01-06 08:53 - 2018-01-01 21:43 - 001173576 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
    2018-01-06 08:53 - 2018-01-01 21:41 - 000559512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
    2018-01-06 08:53 - 2018-01-01 21:39 - 000677784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
    2018-01-06 08:53 - 2018-01-01 21:38 - 000519152 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthService.exe
    2018-01-06 08:53 - 2018-01-01 21:37 - 000461720 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifitask.exe
    2018-01-06 08:53 - 2018-01-01 21:36 - 000374032 _____ (Microsoft Corporation) C:\WINDOWS\system32\vac.exe
    2018-01-06 08:53 - 2018-01-01 21:34 - 001336344 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
    2018-01-06 08:53 - 2018-01-01 21:33 - 002773400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
    2018-01-06 08:53 - 2018-01-01 21:06 - 000311192 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
    2018-01-06 08:53 - 2018-01-01 21:03 - 000650328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
    2018-01-06 08:53 - 2018-01-01 20:42 - 001003152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
    2018-01-06 08:53 - 2018-01-01 20:25 - 001008640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallService.dll
    2018-01-06 08:53 - 2018-01-01 20:25 - 000475648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieui.dll
    2018-01-06 08:53 - 2018-01-01 20:25 - 000097792 _____ C:\WINDOWS\system32\runexehelper.exe
    2018-01-06 08:53 - 2018-01-01 20:23 - 001313792 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallService.dll
    2018-01-06 08:53 - 2018-01-01 20:23 - 000561152 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieui.dll
    2018-01-06 08:53 - 2018-01-01 20:20 - 000524288 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
    2018-01-06 08:53 - 2018-01-01 20:20 - 000204288 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
    2018-01-06 08:53 - 2018-01-01 20:19 - 008014848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
    2018-01-06 08:53 - 2018-01-01 20:19 - 000450048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TileDataRepository.dll
    2018-01-06 08:53 - 2018-01-01 20:19 - 000416768 _____ (Microsoft Corporation) C:\WINDOWS\system32\html.iec
    2018-01-06 08:53 - 2018-01-01 20:19 - 000073216 _____ (Microsoft Corporation) C:\WINDOWS\system32\provtool.exe
    2018-01-06 08:53 - 2018-01-01 20:18 - 000699904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll
    2018-01-06 08:53 - 2018-01-01 20:18 - 000432640 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
    2018-01-06 08:53 - 2018-01-01 20:18 - 000427008 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
    2018-01-06 08:53 - 2018-01-01 20:18 - 000380928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EncDec.dll
    2018-01-06 08:53 - 2018-01-01 20:17 - 006564864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
    2018-01-06 08:53 - 2018-01-01 20:17 - 000616960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
    2018-01-06 08:53 - 2018-01-01 20:17 - 000568832 _____ (Microsoft Corporation) C:\WINDOWS\system32\TileDataRepository.dll
    2018-01-06 08:53 - 2018-01-01 20:16 - 005833216 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll
    2018-01-06 08:53 - 2018-01-01 20:16 - 004839424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll
    2018-01-06 08:53 - 2018-01-01 20:15 - 002349568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll
    2018-01-06 08:53 - 2018-01-01 20:15 - 000951808 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll
    2018-01-06 08:53 - 2018-01-01 20:15 - 000434176 _____ (Microsoft Corporation) C:\WINDOWS\system32\EncDec.dll
    2018-01-06 08:53 - 2018-01-01 20:14 - 001495040 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
    2018-01-06 08:53 - 2018-01-01 20:14 - 000917504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
    2018-01-06 08:53 - 2018-01-01 20:14 - 000870912 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll
    2018-01-06 08:53 - 2018-01-01 20:13 - 001559552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
    2018-01-06 08:53 - 2018-01-01 20:12 - 002208768 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
    2018-01-06 08:53 - 2018-01-01 20:12 - 001573376 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataService.dll
    2018-01-06 08:53 - 2018-01-01 20:11 - 003165696 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
    2018-01-06 08:53 - 2018-01-01 20:11 - 001822208 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
    2018-01-06 08:53 - 2018-01-01 20:11 - 001816576 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
    2018-01-06 08:53 - 2018-01-01 20:11 - 001343488 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
    2018-01-06 08:53 - 2018-01-01 20:11 - 001231872 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
    2018-01-06 08:53 - 2018-01-01 20:11 - 000880640 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
    2018-01-06 08:53 - 2018-01-01 20:11 - 000715776 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
    2018-01-06 08:53 - 2018-01-01 20:10 - 003126272 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
    2018-01-06 08:53 - 2018-01-01 20:09 - 000666624 _____ (Microsoft Corporation) C:\WINDOWS\system32\DbgModel.dll
    2018-01-06 08:53 - 2018-01-01 20:09 - 000599552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
    2018-01-06 08:53 - 2018-01-01 20:08 - 000963072 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
    2018-01-06 08:53 - 2018-01-01 20:08 - 000726016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
    2018-01-06 08:53 - 2018-01-01 20:05 - 002510848 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll
    2018-01-06 08:53 - 2018-01-01 20:05 - 001160704 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
    2018-01-06 08:52 - 2018-01-01 21:52 - 000066712 _____ (Microsoft Corporation) C:\WINDOWS\system32\iumcrypt.dll
    2018-01-06 08:52 - 2018-01-01 21:51 - 000191816 _____ (Microsoft Corporation) C:\WINDOWS\system32\skci.dll
    2018-01-06 08:52 - 2018-01-01 21:50 - 000077208 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll
    2018-01-06 08:52 - 2018-01-01 21:49 - 000599448 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
    2018-01-06 08:52 - 2018-01-01 21:49 - 000292376 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscapi.dll
    2018-01-06 08:52 - 2018-01-01 21:47 - 000649304 _____ (Microsoft Corporation) C:\WINDOWS\system32\advapi32.dll
    2018-01-06 08:52 - 2018-01-01 21:46 - 000733592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\acpi.sys
    2018-01-06 08:52 - 2018-01-01 21:43 - 000367336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll
    2018-01-06 08:52 - 2018-01-01 21:43 - 000062872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fsdepends.sys
    2018-01-06 08:52 - 2018-01-01 21:42 - 001029016 _____ (Microsoft Corporation) C:\WINDOWS\system32\efscore.dll
    2018-01-06 08:52 - 2018-01-01 21:42 - 000494488 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll
    2018-01-06 08:52 - 2018-01-01 21:42 - 000109976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmbus.sys
    2018-01-06 08:52 - 2018-01-01 21:41 - 000549552 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWanAPI.dll
    2018-01-06 08:52 - 2018-01-01 21:39 - 000508264 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe
    2018-01-06 08:52 - 2018-01-01 21:38 - 000727448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fvevol.sys
    2018-01-06 08:52 - 2018-01-01 21:38 - 000103320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\stornvme.sys
    2018-01-06 08:52 - 2018-01-01 21:36 - 000413888 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
    2018-01-06 08:52 - 2018-01-01 21:34 - 000260896 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
    2018-01-06 08:52 - 2018-01-01 21:34 - 000087384 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll
    2018-01-06 08:52 - 2018-01-01 21:32 - 000617304 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
    2018-01-06 08:52 - 2018-01-01 21:27 - 000163736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wfplwfs.sys
    2018-01-06 08:52 - 2018-01-01 21:26 - 000081304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmbkmcl.sys
    2018-01-06 08:52 - 2018-01-01 21:21 - 001103768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
    2018-01-06 08:52 - 2018-01-01 21:21 - 000614296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys
    2018-01-06 08:52 - 2018-01-01 21:03 - 000777904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
    2018-01-06 08:52 - 2018-01-01 21:03 - 000566664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
    2018-01-06 08:52 - 2018-01-01 20:49 - 000481464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\advapi32.dll
    2018-01-06 08:52 - 2018-01-01 20:49 - 000258808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscapi.dll
    2018-01-06 08:52 - 2018-01-01 20:46 - 000289816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.ApplicationData.dll
    2018-01-06 08:52 - 2018-01-01 20:45 - 000450928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWanAPI.dll
    2018-01-06 08:52 - 2018-01-01 20:42 - 000386424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
    2018-01-06 08:52 - 2018-01-01 20:42 - 000129184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfps.dll
    2018-01-06 08:52 - 2018-01-01 20:42 - 000074992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\remoteaudioendpoint.dll
    2018-01-06 08:52 - 2018-01-01 20:24 - 000240640 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboutSettingsHandlers.dll
    2018-01-06 08:52 - 2018-01-01 20:23 - 000385024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cldflt.sys
    2018-01-06 08:52 - 2018-01-01 20:20 - 000212992 _____ (Microsoft Corporation) C:\WINDOWS\system32\container.dll
    2018-01-06 08:52 - 2018-01-01 20:19 - 000795136 _____ (Microsoft Corporation) C:\WINDOWS\system32\NaturalAuth.dll
    2018-01-06 08:52 - 2018-01-01 20:19 - 000366080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
    2018-01-06 08:52 - 2018-01-01 20:19 - 000043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\nshhttp.dll
    2018-01-06 08:52 - 2018-01-01 20:18 - 000391168 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
    2018-01-06 08:52 - 2018-01-01 20:18 - 000369664 _____ (Microsoft Corporation) C:\WINDOWS\system32\APHostService.dll
    2018-01-06 08:52 - 2018-01-01 20:18 - 000276480 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
    2018-01-06 08:52 - 2018-01-01 20:18 - 000259072 _____ (Microsoft Corporation) C:\WINDOWS\system32\SCardSvr.dll
    2018-01-06 08:52 - 2018-01-01 20:17 - 000423936 _____ (Microsoft Corporation) C:\WINDOWS\system32\p2psvc.dll
    2018-01-06 08:52 - 2018-01-01 20:16 - 000956928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpbase.dll
    2018-01-06 08:52 - 2018-01-01 20:16 - 000831488 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
    2018-01-06 08:52 - 2018-01-01 20:16 - 000401920 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll
    2018-01-06 08:52 - 2018-01-01 20:15 - 001657856 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpserverbase.dll
    2018-01-06 08:52 - 2018-01-01 20:15 - 001245184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
    2018-01-06 08:52 - 2018-01-01 20:15 - 000970240 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysmain.dll
    2018-01-06 08:52 - 2018-01-01 20:15 - 000756736 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
    2018-01-06 08:52 - 2018-01-01 20:15 - 000366080 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlasvc.dll
    2018-01-06 08:52 - 2018-01-01 20:14 - 001097728 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpbase.dll
    2018-01-06 08:52 - 2018-01-01 20:14 - 001003008 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
    2018-01-06 08:52 - 2018-01-01 20:14 - 000985600 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
    2018-01-06 08:52 - 2018-01-01 20:13 - 000897024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
    2018-01-06 08:52 - 2018-01-01 20:12 - 000464384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
    2018-01-06 08:52 - 2018-01-01 20:11 - 002082304 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
    2018-01-06 08:52 - 2018-01-01 20:11 - 001597952 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
    2018-01-06 08:51 - 2018-01-01 21:38 - 000038808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Diskdump.sys
    2018-01-06 08:51 - 2018-01-01 21:36 - 000113560 _____ (Microsoft Corporation) C:\WINDOWS\system32\icfupgd.dll
    2018-01-06 08:51 - 2018-01-01 21:36 - 000057752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netbios.sys
    2018-01-06 08:51 - 2018-01-01 21:35 - 000075160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthProxyStub.dll
    2018-01-06 08:51 - 2018-01-01 20:24 - 000096256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
    2018-01-06 08:51 - 2018-01-01 20:23 - 000232960 _____ (Microsoft Corporation) C:\WINDOWS\system32\convertvhd.exe
    2018-01-06 08:51 - 2018-01-01 20:23 - 000121344 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
    2018-01-06 08:51 - 2018-01-01 20:23 - 000080384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmbkmclr.sys
    2018-01-06 08:51 - 2018-01-01 20:22 - 000025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Dumpstorport.sys
    2018-01-06 08:51 - 2018-01-01 20:22 - 000017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\VmApplicationHealthMonitorProxy.dll
    2018-01-06 08:51 - 2018-01-01 20:21 - 000268288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
    2018-01-06 08:51 - 2018-01-01 20:21 - 000233984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppLockerCSP.dll
    2018-01-06 08:51 - 2018-01-01 20:21 - 000133632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wificonnapi.dll
    2018-01-06 08:51 - 2018-01-01 20:21 - 000097280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WcnApi.dll
    2018-01-06 08:51 - 2018-01-01 20:21 - 000097280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\raspptp.sys
    2018-01-06 08:51 - 2018-01-01 20:21 - 000080896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wanarp.sys
    2018-01-06 08:51 - 2018-01-01 20:21 - 000062976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndproxy.sys
    2018-01-06 08:51 - 2018-01-01 20:20 - 000459776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
    2018-01-06 08:51 - 2018-01-01 20:20 - 000397824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtmsft.dll
    2018-01-06 08:51 - 2018-01-01 20:20 - 000225792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\winnat.sys
    2018-01-06 08:51 - 2018-01-01 20:20 - 000215552 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwpolicyiomgr.dll
    2018-01-06 08:51 - 2018-01-01 20:20 - 000186368 _____ (Microsoft Corporation) C:\WINDOWS\system32\ACPBackgroundManagerPolicy.dll
    2018-01-06 08:51 - 2018-01-01 20:20 - 000175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fwpolicyiomgr.dll
    2018-01-06 08:51 - 2018-01-01 20:20 - 000134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\WcnApi.dll
    2018-01-06 08:51 - 2018-01-01 20:20 - 000104960 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasauto.dll
    2018-01-06 08:51 - 2018-01-01 20:20 - 000082432 _____ (Microsoft Corporation) C:\WINDOWS\system32\SCardDlg.dll
    2018-01-06 08:51 - 2018-01-01 20:20 - 000043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\RfxVmt.sys
    2018-01-06 08:51 - 2018-01-01 20:20 - 000035328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nshhttp.dll
    2018-01-06 08:51 - 2018-01-01 20:19 - 000675328 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
    2018-01-06 08:51 - 2018-01-01 20:19 - 000430080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll
    2018-01-06 08:51 - 2018-01-01 20:19 - 000340480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\html.iec
    2018-01-06 08:51 - 2018-01-01 20:19 - 000316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netbt.sys
    2018-01-06 08:51 - 2018-01-01 20:19 - 000188416 _____ (Microsoft Corporation) C:\WINDOWS\system32\PimIndexMaintenance.dll
    2018-01-06 08:51 - 2018-01-01 20:19 - 000174592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\P2P.dll
    2018-01-06 08:51 - 2018-01-01 20:19 - 000149504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\container.dll
    2018-01-06 08:51 - 2018-01-01 20:19 - 000097792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msoert2.dll
    2018-01-06 08:51 - 2018-01-01 20:19 - 000093696 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
    2018-01-06 08:51 - 2018-01-01 20:19 - 000079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlaapi.dll
    2018-01-06 08:51 - 2018-01-01 20:19 - 000063488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nlaapi.dll
    2018-01-06 08:51 - 2018-01-01 20:18 - 000748032 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneProviders.dll
    2018-01-06 08:51 - 2018-01-01 20:18 - 000588800 _____ (Microsoft Corporation) C:\WINDOWS\system32\SmsRouterSvc.dll
    2018-01-06 08:51 - 2018-01-01 20:18 - 000465920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcncsvc.dll
    2018-01-06 08:51 - 2018-01-01 20:18 - 000436224 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
    2018-01-06 08:51 - 2018-01-01 20:18 - 000425984 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmrdvcore.dll
    2018-01-06 08:51 - 2018-01-01 20:18 - 000343040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
    2018-01-06 08:51 - 2018-01-01 20:18 - 000336896 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppLockerCSP.dll
    2018-01-06 08:51 - 2018-01-01 20:18 - 000210944 _____ (Microsoft Corporation) C:\WINDOWS\system32\P2P.dll
    2018-01-06 08:51 - 2018-01-01 20:18 - 000144896 _____ (Microsoft Corporation) C:\WINDOWS\system32\appinfo.dll
    2018-01-06 08:51 - 2018-01-01 20:18 - 000082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\provdatastore.dll
    2018-01-06 08:51 - 2018-01-01 20:17 - 001485312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpserverbase.dll
    2018-01-06 08:51 - 2018-01-01 20:17 - 000791552 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneService.dll
    2018-01-06 08:51 - 2018-01-01 20:17 - 000594432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
    2018-01-06 08:51 - 2018-01-01 20:17 - 000555520 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll
    2018-01-06 08:51 - 2018-01-01 20:17 - 000456704 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll
    2018-01-06 08:51 - 2018-01-01 20:17 - 000341504 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnrpsvc.dll
    2018-01-06 08:51 - 2018-01-01 20:17 - 000228352 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
    2018-01-06 08:51 - 2018-01-01 20:17 - 000112640 _____ (Microsoft Corporation) C:\WINDOWS\system32\msoert2.dll
    2018-01-06 08:51 - 2018-01-01 20:16 - 000966656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll
    2018-01-06 08:51 - 2018-01-01 20:16 - 000668160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
    2018-01-06 08:51 - 2018-01-01 20:16 - 000624128 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncController.dll
    2018-01-06 08:51 - 2018-01-01 20:16 - 000235008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll
    2018-01-06 08:51 - 2018-01-01 20:16 - 000086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\cldapi.dll
    2018-01-06 08:51 - 2018-01-01 20:16 - 000076288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cldapi.dll
    2018-01-06 08:51 - 2018-01-01 20:15 - 000258560 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
    2018-01-06 08:51 - 2018-01-01 20:13 - 002013184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
    2018-01-06 08:51 - 2018-01-01 20:13 - 001474560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
    2018-01-06 08:51 - 2018-01-01 20:12 - 000760320 _____ (Microsoft Corporation) C:\WINDOWS\system32\spoolsv.exe
    2018-01-06 08:51 - 2018-01-01 20:10 - 002528256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
    2018-01-06 08:51 - 2018-01-01 20:10 - 000012800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscproxystub.dll
    2018-01-06 08:51 - 2018-01-01 20:08 - 000505344 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskcomp.dll
    2018-01-06 08:51 - 2018-01-01 20:06 - 000018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscproxystub.dll
    2018-01-06 08:51 - 2018-01-01 20:05 - 000050176 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcalua.exe
    2018-01-06 08:50 - 2018-01-01 20:24 - 000038912 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
    2018-01-06 08:50 - 2018-01-01 20:23 - 000047104 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
    2018-01-06 08:50 - 2018-01-01 20:22 - 000031744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Provisioning.ProxyStub.dll
    2018-01-06 08:50 - 2018-01-01 20:20 - 000133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll
    2018-01-06 08:50 - 2018-01-01 20:19 - 000142848 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
    2018-01-05 18:07 - 2018-01-05 18:07 - 000000185 _____ C:\Users\Refer\Desktop\My TurboTax® Login – Sign in to TurboTax to work on Your Tax Return.url
    2018-01-04 22:32 - 2018-01-04 22:32 - 000371153 _____ C:\Users\Refer\Documents\Signed TASS Registration Request Form - Inverness Technologies.pdf
    2018-01-03 20:49 - 2018-01-03 20:48 - 000245814 _____ C:\Users\Refer\Documents\Inverness Technologies Health Coverage opt-Out Notification Form.jpeg
    2018-01-02 19:01 - 2018-01-02 19:01 - 000000350 _____ C:\Users\Refer\Documents\SFL-TAP Counselor Final Examination 1.url
    2018-01-02 18:35 - 2018-01-03 22:32 - 000144626 _____ C:\Users\Refer\Documents\Inverness Technologies - System Authorization Access Request (SAAR) Form.pdf
    2017-12-28 23:14 - 2017-12-28 23:14 - 000000150 _____ C:\Users\Refer\Desktop\Welcome to SYMPAQ eTX!.url
    2017-12-27 22:20 - 2017-12-27 22:20 - 000000000 ____D C:\WINDOWS\system32\ihvmanager
    2017-12-27 22:08 - 2017-12-27 22:08 - 000000133 _____ C:\Users\Refer\Desktop\Civilian Human Resources Agency - Far East Region.url
    2017-12-27 21:43 - 2017-12-27 21:43 - 000048265 _____ C:\Users\Refer\Documents\Counselor Certification Memo SEPT 2017.pdf
    2017-12-24 18:37 - 2017-12-24 18:37 - 000000000 ____D C:\Users\Public\Documents\CyberLink
    2017-12-24 18:36 - 2017-12-24 18:36 - 000000000 ____D C:\Users\Public\CyberLink
    2017-12-24 18:35 - 2017-12-24 18:36 - 000000000 ____D C:\ProgramData\CyberLink

    ==================== One Month Modified files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2018-01-21 14:03 - 2017-09-29 22:48 - 000000000 ____D C:\Users\Refer\Documents\Outlook Files
    2018-01-21 14:02 - 2017-09-28 15:40 - 000000000 ____D C:\WINDOWS\CryptoGuard
    2018-01-21 13:54 - 2017-12-16 13:22 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
    2018-01-21 13:02 - 2017-12-13 23:15 - 000094144 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
    2018-01-21 10:31 - 2017-09-28 15:57 - 000000000 ____D C:\Users\Refer\AppData\Roaming\.strongvpn
    2018-01-21 10:29 - 2017-09-29 22:46 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
    2018-01-21 10:21 - 2017-09-28 14:18 - 000000000 ____D C:\Users\Refer\AppData\Roaming\Skype
    2018-01-21 10:21 - 2017-07-05 03:40 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
    2018-01-21 10:19 - 2017-12-13 23:16 - 000046008 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
    2018-01-21 10:19 - 2017-12-13 23:15 - 000253880 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
    2018-01-21 10:19 - 2017-12-13 23:15 - 000110016 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
    2018-01-21 10:17 - 2017-12-16 13:55 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
    2018-01-21 10:17 - 2017-09-28 15:40 - 000000000 ____D C:\ProgramData\HitmanPro.Alert
    2018-01-21 10:16 - 2017-09-29 17:45 - 000786432 _____ C:\WINDOWS\system32\config\BBI
    2018-01-21 10:16 - 2017-09-28 15:40 - 000000000 ____D C:\ProgramData\HitmanPro
    2018-01-21 10:16 - 2017-07-05 03:10 - 000065536 _____ C:\WINDOWS\psp_storage.bin
    2018-01-21 09:56 - 2017-09-29 22:46 - 000000000 ___HD C:\Program Files\WindowsApps
    2018-01-21 09:56 - 2017-09-29 22:46 - 000000000 ____D C:\WINDOWS\DeliveryOptimization
    2018-01-21 09:56 - 2017-09-29 22:46 - 000000000 ____D C:\WINDOWS\AppReadiness
    2018-01-21 00:00 - 2017-12-16 13:28 - 000000000 ____D C:\Users\Refer
    2018-01-20 09:45 - 2017-07-05 03:04 - 000000000 ____D C:\ProgramData\PCDr
    2018-01-18 20:31 - 2017-09-28 15:32 - 000000000 ____D C:\Program Files\SUPERAntiSpyware
    2018-01-15 16:39 - 2017-09-28 22:06 - 000000000 ____D C:\Program Files (x86)\Quicken
    2018-01-15 15:16 - 2017-09-29 22:44 - 000000000 ____D C:\WINDOWS\INF
    2018-01-15 15:08 - 2017-09-28 12:59 - 000000000 ____D C:\ProgramData\SupportAssist
    2018-01-14 09:49 - 2017-12-17 06:00 - 000757078 _____ C:\WINDOWS\system32\perfh012.dat
    2018-01-14 09:49 - 2017-12-17 06:00 - 000205056 _____ C:\WINDOWS\system32\perfc012.dat
    2018-01-14 09:49 - 2017-12-16 13:48 - 002133950 _____ C:\WINDOWS\system32\PerfStringBackup.INI
    2018-01-14 09:39 - 2017-09-28 15:40 - 000000000 ____D C:\Program Files (x86)\HitmanPro.Alert
    2018-01-13 23:06 - 2017-09-28 20:37 - 000000000 ____D C:\ProgramData\TEMP
    2018-01-13 18:29 - 2017-07-05 03:04 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell
    2018-01-13 11:46 - 2017-11-11 11:47 - 000000000 ____D C:\Users\Refer\Documents\MyDataBase
    2018-01-13 09:50 - 2017-09-28 21:42 - 000002275 _____ C:\Users\Refer\AppData\Roaming\SAS7_000.DAT
    2018-01-10 21:44 - 2017-09-29 22:37 - 000000000 ____D C:\WINDOWS\CbsTemp
    2018-01-10 19:57 - 2017-12-16 13:29 - 000000000 ____D C:\Users\Refer\AppData\Local\Packages
    2018-01-10 19:09 - 2017-09-28 15:40 - 001236616 _____ (SurfRight B.V.) C:\WINDOWS\system32\hmpalert.dll
    2018-01-10 19:09 - 2017-09-28 15:40 - 000848008 _____ (SurfRight B.V.) C:\WINDOWS\SysWOW64\hmpalert.dll
    2018-01-10 19:09 - 2017-09-28 15:40 - 000293560 _____ (SurfRight B.V.) C:\WINDOWS\system32\Drivers\hmpalert.sys
    2018-01-10 19:09 - 2017-09-28 15:40 - 000093800 _____ (SurfRight B.V.) C:\WINDOWS\system32\Drivers\hmpnet.sys
    2018-01-10 08:41 - 2017-09-28 23:14 - 000000000 ____D C:\WINDOWS\system32\MRT
    2018-01-10 08:32 - 2017-10-12 09:59 - 129365736 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT-KB890830.exe
    2018-01-10 08:32 - 2017-09-28 23:13 - 129365736 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
    2018-01-08 22:35 - 2017-09-29 22:46 - 000000000 ____D C:\WINDOWS\system32\NDF
    2018-01-08 21:06 - 2017-09-29 22:46 - 000000000 ____D C:\WINDOWS\rescache
    2018-01-07 11:16 - 2017-09-29 22:47 - 000000000 ____D C:\Users\Refer\Documents\iFree Skype Recorder
    2018-01-07 10:34 - 2017-12-16 13:59 - 000000000 ___RD C:\Users\Refer\3D Objects
    2018-01-07 10:34 - 2017-07-05 03:28 - 000000000 __RHD C:\Users\Public\AccountPictures
    2018-01-07 10:26 - 2017-12-16 13:22 - 000425328 _____ C:\WINDOWS\system32\FNTCACHE.DAT
    2018-01-07 10:23 - 2017-09-29 22:46 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
    2018-01-07 10:23 - 2017-09-29 22:46 - 000000000 ___SD C:\WINDOWS\system32\F12
    2018-01-07 10:23 - 2017-09-29 22:46 - 000000000 ____D C:\WINDOWS\TextInput
    2018-01-07 10:23 - 2017-09-29 22:46 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
    2018-01-07 10:23 - 2017-09-29 22:46 - 000000000 ____D C:\WINDOWS\system32\oobe
    2018-01-07 10:23 - 2017-09-29 22:46 - 000000000 ____D C:\WINDOWS\system32\migwiz
    2018-01-07 10:23 - 2017-09-29 22:46 - 000000000 ____D C:\WINDOWS\system32\appraiser
    2018-01-07 10:23 - 2017-09-29 17:45 - 000000000 ____D C:\WINDOWS\system32\Dism
    2018-01-07 10:22 - 2017-09-29 22:46 - 000000000 ____D C:\WINDOWS\Provisioning
    2018-01-06 09:10 - 2017-09-29 22:41 - 000403968 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpAXHolder.dll
    2018-01-06 09:06 - 2017-09-29 22:41 - 000106496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
    2018-01-06 09:05 - 2017-09-29 22:41 - 000140800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
    2018-01-05 17:43 - 2017-12-16 13:55 - 000004204 _____ C:\WINDOWS\System32\Tasks\Open URL by RoboForm
    2018-01-05 17:43 - 2017-12-16 13:55 - 000003692 _____ C:\WINDOWS\System32\Tasks\Run RoboForm TaskBar Icon
    2018-01-05 17:43 - 2017-09-28 16:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RoboForm
    2018-01-03 20:49 - 2017-09-29 22:52 - 000000000 ____D C:\Users\Refer\Documents\Scanned Documents
    2018-01-01 21:39 - 2017-09-29 22:13 - 000000218 _____ C:\Users\Refer\Desktop\Home - eBenefits.url
    2018-01-01 17:47 - 2017-09-29 22:46 - 000000000 ____D C:\WINDOWS\LiveKernelReports
    2017-12-31 23:06 - 2017-09-29 22:27 - 000000000 ____D C:\Users\Refer\Documents\Coffee Tree Coffee Shop The
    2017-12-30 18:59 - 2017-09-28 16:08 - 000000000 ____D C:\Users\Refer\AppData\Local\RoboForm
    2017-12-30 10:37 - 2017-12-17 06:18 - 000000000 ____D C:\Windows.old
    2017-12-27 22:25 - 2017-07-05 03:17 - 000000000 ____D C:\Program Files (x86)\Qualcomm
    2017-12-24 14:38 - 2017-11-08 18:48 - 000000000 ____D C:\Users\Refer\AppData\Local\ElevatedDiagnostics
    2017-12-23 22:14 - 2017-10-12 12:45 - 000569392 _____ (Acronis International GmbH) C:\WINDOWS\system32\Drivers\file_protector.sys
    2017-12-23 22:14 - 2017-10-12 12:44 - 000379664 _____ (Acronis International GmbH) C:\WINDOWS\system32\Drivers\file_tracker.sys
    2017-12-23 22:10 - 2017-10-12 12:43 - 000331976 _____ (Acronis International GmbH) C:\WINDOWS\system32\Drivers\virtual_file.sys
    2017-12-23 22:10 - 2017-10-12 12:43 - 000243472 _____ (Acronis International GmbH) C:\WINDOWS\system32\Drivers\volume_tracker.sys
    2017-12-23 22:09 - 2017-10-12 12:43 - 001310552 _____ (Acronis International GmbH) C:\WINDOWS\system32\Drivers\tib.sys
    2017-12-23 22:09 - 2017-10-12 12:43 - 000690520 _____ (Acronis International GmbH) C:\WINDOWS\system32\Drivers\tnd.sys
    2017-12-23 22:09 - 2017-10-12 12:43 - 000213336 _____ (Acronis International GmbH) C:\WINDOWS\system32\Drivers\tib_mounter.sys
    2017-12-23 22:09 - 2017-10-12 12:42 - 000371472 _____ (Acronis International GmbH) C:\WINDOWS\system32\Drivers\snapman.sys
    2017-12-23 22:08 - 2017-10-12 12:41 - 000001288 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acronis True Image.lnk
    2017-12-23 22:08 - 2017-10-12 12:41 - 000001259 _____ C:\Users\Public\Desktop\Acronis True Image.lnk
    2017-12-22 22:45 - 2017-09-29 22:49 - 000835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
    2017-12-22 22:45 - 2017-09-29 22:49 - 000177648 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl

    ==================== Files in the root of some directories =======

    2017-10-04 10:40 - 2017-10-04 10:40 - 000038416 _____ () C:\Users\Refer\AppData\Roaming\Comma Separated Values.ADR
    2017-09-28 21:42 - 2018-01-13 09:50 - 000002275 _____ () C:\Users\Refer\AppData\Roaming\SAS7_000.DAT

    ==================== Bamital & volsnap ======================

    (There is no automatic fix for files that do not pass verification.)

    C:\WINDOWS\system32\winlogon.exe => File is digitally signed
    C:\WINDOWS\system32\wininit.exe => File is digitally signed
    C:\WINDOWS\explorer.exe => File is digitally signed
    C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
    C:\WINDOWS\system32\svchost.exe => File is digitally signed
    C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
    C:\WINDOWS\system32\services.exe => File is digitally signed
    C:\WINDOWS\system32\User32.dll => File is digitally signed
    C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
    C:\WINDOWS\system32\userinit.exe => File is digitally signed
    C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
    C:\WINDOWS\system32\rpcss.dll => File is digitally signed
    C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
    C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
    C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
    C:\WINDOWS\system32\drivers\eamonm.sys -> Access Denied <======= ATTENTION
    C:\WINDOWS\system32\drivers\eelam.sys -> Access Denied <======= ATTENTION
    C:\WINDOWS\system32\drivers\ehdrv.sys -> Access Denied <======= ATTENTION
    C:\WINDOWS\system32\drivers\epfwwfpr.sys -> Access Denied <======= ATTENTION

    LastRegBack: 2018-01-20 11:15

    ==================== End of FRST.txt ============================
     
  9. referee07

    referee07 Thread Starter

    Joined:
    Sep 11, 2003
    Messages:
    1,304
    Additional scan result of Farbar Recovery Scan Tool (x64) Version: 17.01.2018 01
    Ran by Refer (21-01-2018 14:04:46)
    Running from C:\Users\Refer\Desktop
    Windows 10 Home Version 1709 16299.192 (X64) (2017-12-16 04:57:20)
    Boot Mode: Normal
    ==========================================================


    ==================== Accounts: =============================

    Administrator (S-1-5-21-1534629146-3426154806-933795594-500 - Administrator - Disabled)
    DefaultAccount (S-1-5-21-1534629146-3426154806-933795594-503 - Limited - Disabled)
    Guest (S-1-5-21-1534629146-3426154806-933795594-501 - Limited - Disabled)
    Refer (S-1-5-21-1534629146-3426154806-933795594-1001 - Administrator - Enabled) => C:\Users\Refer
    WDAGUtilityAccount (S-1-5-21-1534629146-3426154806-933795594-504 - Limited - Disabled)

    ==================== Security Center ========================

    (If an entry is included in the fixlist, it will be removed.)

    AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
    AV: ESET NOD32 Antivirus (Enabled - Up to date) {EC1D6F37-E411-475A-DF50-12FF7FE4AC70}
    AS: ESET NOD32 Antivirus (Enabled - Up to date) {577C8ED3-C22B-48D4-E5E0-298D0463E6CD}
    AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
    AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    ==================== Installed Programs ======================

    (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

    Acronis True Image (HKLM-x32\...\{027399E9-B197-43FF-BE79-490D9F106DDF}) (Version: 22.5.10640 - Acronis) Hidden
    Acronis True Image (HKLM-x32\...\{027399E9-B197-43FF-BE79-490D9F106DDF}Visible) (Version: 22.5.10640 - Acronis)
    Adobe Acrobat 5.0 (HKLM-x32\...\Adobe Acrobat 5.0) (Version: 5.0 - Adobe Systems, Inc.)
    Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 18.009.20050 - Adobe Systems Incorporated)
    Amazon Kindle (HKU\S-1-5-21-1534629146-3426154806-933795594-1001\...\Amazon Kindle) (Version: 1.20.1.47037 - Amazon)
    AMD Install Manager (HKLM\...\AMD Catalyst Install Manager) (Version: 9.0.000.6 - Advanced Micro Devices, Inc.)
    AMD Settings (HKLM\...\WUCCCApp) (Version: 2017.0817.14.41794 - Advanced Micro Devices, Inc.)
    Apple Application Support (32-bit) (HKLM-x32\...\{BC7C46A4-D7A7-48EC-A98C-32A7762B5EFA}) (Version: 6.2.1 - Apple Inc.)
    Apple Application Support (64-bit) (HKLM\...\{F0C4B709-8BF4-4A72-B527-12E7BF5482F8}) (Version: 6.2.1 - Apple Inc.)
    Apple Mobile Device Support (HKLM\...\{BD6778C5-6FA5-492A-ADD6-E706339C2A7B}) (Version: 11.0.2.4 - Apple Inc.)
    Apple Software Update (HKLM-x32\...\{C1BBFD2A-BCDD-45B3-8C0B-66BD434970A8}) (Version: 2.4.8.1 - Apple Inc.)
    Belarc Advisor 8.5c (HKLM-x32\...\Belarc Advisor) (Version: 8.5.3.0 - Belarc Inc.)
    Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
    Business Plan Pro 2004 (HKLM-x32\...\{C7BA228D-D0E9-44E5-B0B6-7AD4B0D6EBB0}) (Version: 7.19.0002 - Palo Alto Software)
    Byki (HKLM-x32\...\{FD9E03B5-AEEA-4D59-B512-6CE4AA0281D4}) (Version: 4.0 - Transparent Language, Inc.) Hidden
    Byki Deluxe (HKLM-x32\...\Byki Deluxe) (Version: - Transparent Language, Inc.)
    Defraggler (HKLM\...\Defraggler) (Version: 2.21 - Piriform)
    Dell Customer Connect (HKLM-x32\...\{04A41EBC-AB30-4574-A14D-E0CDFE31AB70}) (Version: 1.5.1.0 - Dell Inc.)
    Dell Digital Delivery (HKLM-x32\...\{7294961D-6EC1-4418-9017-0180A0C78A91}) (Version: 3.2.1006.0 - Dell Products, LP)
    Dell Foundation Services (HKLM\...\{BDB50421-E961-42F3-B803-6DAC6F173834}) (Version: 3.4.16100.0 - Dell Inc.)
    Dell Help & Support (HKLM\...\{457EFE69-8F49-43E0-80F9-1DEF4F7690C2}) (Version: 2.5.23.0 - Dell Inc.) Hidden
    Dell Help & Support (HKLM-x32\...\InstallShield_{457EFE69-8F49-43E0-80F9-1DEF4F7690C2}) (Version: 2.5.23.0 - Dell Inc.)
    Dell Product Registration (HKLM-x32\...\InstallShield_{0CB75726-FC62-4609-B5DA-0031E64F771B}) (Version: 3.0.128.0 - Dell Inc.)
    Dell SupportAssist (HKLM\...\PC-Doctor for Windows) (Version: 1.3.6855.212 - Dell)
    Dell SupportAssist Remediation (HKLM\...\{4164FBBB-3428-4EFE-863F-30CAC3ADE51A}) (Version: 3.1.2.3837 - Dell Inc.) Hidden
    Dell SupportAssist Remediation (HKLM-x32\...\{80642b68-d76d-4777-a9dc-4ca30647e8a8}) (Version: 3.1.2.3837 - Dell Inc.)
    Dell SupportAssistAgent (HKLM\...\{8D7B279C-A661-465C-9658-F62FBD6A6B91}) (Version: 2.1.3.5 - Dell)
    Dell Update - SupportAssist Update Plugin (HKLM\...\{2228BC43-73DA-4F9A-BEE6-8E9C15328513}) (Version: 3.1.1.3832 - Dell Inc.)
    Dell Update (HKLM-x32\...\{632610E3-5B12-403C-9C93-EF533ED1C113}) (Version: 1.10.5.0 - Dell Inc.)
    Dragon NaturallySpeaking 13 (HKLM-x32\...\{33EA20FB-5389-4938-BA59-2BCD9BB68F41}) (Version: 13.00.000 - Nuance Communications Inc.)
    DSC/AA Factory Installer (HKLM\...\{F7A70D00-F283-45C8-B163-49EC365D7E27}) (Version: 1.3.6855.212 - PC-Doctor, Inc.) Hidden
    ESET NOD32 Antivirus (HKLM\...\{3B4AB7BA-0734-4547-9604-3FCC40873B3D}) (Version: 10.1.219.0 - ESET, spol. s r.o.)
    Google Toolbar for Internet Explorer (HKLM-x32\...\{18455581-E099-4BA8-BC6B-F34B2F06600C}) (Version: 1.0.0 - Google Inc.) Hidden
    Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.8231.2252 - Google Inc.)
    Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.7 - Google Inc.) Hidden
    HitmanPro.Alert 3 (HKLM\...\HitmanPro.Alert) (Version: 3.7.3.729 - SurfRight B.V.)
    iFree Skype Recorder 7.0.23 (HKLM-x32\...\iFree Skype Recorder) (Version: 7.0.23 - iFree Skype Recorder)
    iTunes (HKLM\...\{D7D4465C-B3B6-4BC1-B336-2803FB57BFAF}) (Version: 12.7.2.60 - Apple Inc.)
    Lan Info v1.0 (HKLM-x32\...\Lan Info_is1) (Version: - )
    Malwarebytes version 3.3.1.2183 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.3.1.2183 - Malwarebytes)
    Maxx Audio Installer (x64) (HKLM\...\{307032B2-6AF2-46D7-B933-62438DEB2B9A}) (Version: 2.7.8942.2 - Waves Audio Ltd.) Hidden
    Microsoft Office 365 - en-us (HKLM\...\O365HomePremRetail - en-us) (Version: 16.0.8827.2148 - Microsoft Corporation)
    Microsoft OneDrive (HKU\S-1-5-21-1534629146-3426154806-933795594-1001\...\OneDriveSetup.exe) (Version: 17.3.7131.1115 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
    Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
    Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
    Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation)
    Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
    MSXML 4.0 SP2 Parser and SDK (HKLM-x32\...\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation)
    MyDataBase (HKLM-x32\...\{AB856C83-7CA0-4EB5-8D86-792B29EB4A10}) (Version: - )
    OEM Application Profile (HKLM-x32\...\{B4B7FD8F-06FC-E277-4F29-8F75F8281D8F}) (Version: 1.00.0000 - Advanced Micro Devices, Inc.)
    Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.8827.2148 - Microsoft Corporation) Hidden
    Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.8827.2148 - Microsoft Corporation) Hidden
    Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.8827.2148 - Microsoft Corporation) Hidden
    Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0409-0000-0000000FF1CE}) (Version: 16.0.8827.2148 - Microsoft Corporation) Hidden
    ParetoLogic Privacy Controls (HKLM-x32\...\{29ACDA07-0CAD-4751-B3A4-3E03C5F74673}) (Version: 3.3.0.0 - ParetoLogic, Inc.)
    Product Registration (HKLM\...\{0CB75726-FC62-4609-B5DA-0031E64F771B}) (Version: 3.0.128.0 - Dell Inc.) Hidden
    Qualcomm 11ac Wireless LAN&Bluetooth Installer (HKLM-x32\...\{E7086B15-806E-4519-A876-DBA9FDDE9A13}) (Version: 11.0.0.10454 - Qualcomm)
    Quicken 2004 (HKLM-x32\...\{54DE0B75-6CD9-44C4-B10A-1F25DA9899D8}) (Version: 13.00.0000 - Intuit) Hidden
    Quicken 2004 (HKLM-x32\...\InstallShield_{54DE0B75-6CD9-44C4-B10A-1F25DA9899D8}) (Version: 13.00.0000 - Intuit)
    Quickset64 (HKLM\...\{87CF757E-C1F1-4D22-865C-00C6950B5258}) (Version: 10.17.016 - Dell Inc.)
    Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.14393.31228 - Realtek Semiconductor Corp.)
    Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7989 - Realtek Semiconductor Corp.)
    Realtek PC Camera Driver (HKLM-x32\...\{E399A5B3-ED53-4DEA-AF04-8011E1EB1EAC}) (Version: 10.0.14393.11242 - Realtek Semiconductor Corp.)
    Revo Uninstaller Pro 3.2.0 (HKLM\...\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 3.2.0 - VS Revo Group, Ltd.)
    RoboForm 8-4-6-6 (All Users) (HKLM-x32\...\AI RoboForm) (Version: 8-4-6-6 - Siber Systems)
    Skype Web Plugin (HKLM-x32\...\{EB96DF8B-65A7-4E72-BFB1-38DB36870D16}) (Version: 7.32.6.278 - Skype Technologies S.A.)
    Skype™ 7.40 (HKLM-x32\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.40.151 - Skype Technologies S.A.)
    Stamps.com Internet Postage (HKLM-x32\...\Stamps.com Internet Postage) (Version: - )
    StrongVPN Client (HKLM-x32\...\{6EB6293C-9286-4981-8672-956E1A92F33B}_is1) (Version: 1.6.5 - Strong Technology, LLC)
    SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 6.0.1248 - SUPERAntiSpyware.com)
    Vulkan Run Time Libraries 1.0.21.0 (HKLM\...\VulkanRT1.0.21.0) (Version: 1.0.21.0 - LunarG, Inc.)
    Vulkan Run Time Libraries 1.0.26.0 (HKLM\...\VulkanRT1.0.26.0) (Version: 1.0.26.0 - LunarG, Inc.)
    Windows 10 Update Assistant (HKLM-x32\...\{D5C69738-B486-402E-85AC-2456D98A64E4}) (Version: 1.4.9200.22256 - Microsoft Corporation)
    WinZip 22.0 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C24115}) (Version: 22.0.12670 - Corel Corporation)
    WYO Home Inventory 4.20 (HKLM-x32\...\WYO Home Inventory) (Version: 4.20 - M-One Studio)

    ==================== Custom CLSID (Whitelisted): ==========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    CustomCLSID: HKU\S-1-5-21-1534629146-3426154806-933795594-1001_Classes\CLSID\{41052F6E-3662-4584-BCD3-77BCCAAE8470}\InprocServer32 -> C:\Users\Refer\AppData\Local\SkypePlugin\7.32.6.278\GatewayActiveX-x64.dll (Skype Technologies S.A.)
    CustomCLSID: HKU\S-1-5-21-1534629146-3426154806-933795594-1001_Classes\CLSID\{60813F68-E9F7-4B3C-80B4-A76A66211660}\localserver32 -> C:\Users\Refer\AppData\Local\SkypePlugin\7.32.6.278\GatewayVersion-x64.exe (Skype Technologies S.A.)
    CustomCLSID: HKU\S-1-5-21-1534629146-3426154806-933795594-1001_Classes\CLSID\{CB2B673F-D441-4CD4-AFBE-DC4037CA4220}\InprocServer32 -> C:\Program Files\WinZip\adxloader64.WinZipExpressForOffice.dll ()
    CustomCLSID: HKU\S-1-5-21-1534629146-3426154806-933795594-1001_Classes\CLSID\{CBF9CD8C-2714-4F36-B76A-43E6C7547BC2}\localserver32 -> C:\Users\Refer\AppData\Local\SkypePlugin\7.32.6.278\EdgeCalling.exe (Skype Technologies S.A.)
    ShellIconOverlayIdentifiers: [ AcronisDrive] -> {5D74FD4B-4EFB-4586-8022-8637BBE40970} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [2017-09-26] ()
    ShellIconOverlayIdentifiers: [ AcronisSyncError] -> {934BC6C0-FEC2-4df5-A100-961DE2C8A0ED} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [2017-09-26] ()
    ShellIconOverlayIdentifiers: [ AcronisSyncInProgress] -> {00F848DC-B1D4-4892-9C25-CAADC86A215D} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [2017-09-26] ()
    ShellIconOverlayIdentifiers: [ AcronisSyncOk] -> {71573297-552E-46fc-BE3D-3DFAF88D47B7} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [2017-09-26] ()
    ContextMenuHandlers1: [ESET Smart Security - Context Menu Shell Extension] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2017-11-04] (ESET)
    ContextMenuHandlers1: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\wzshls64.dll [2017-11-01] (WinZip Computing, S.L.)
    ContextMenuHandlers2: [ESET Smart Security - Context Menu Shell Extension] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2017-11-04] (ESET)
    ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-11-01] (Malwarebytes)
    ContextMenuHandlers4: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\wzshls64.dll [2017-11-01] (WinZip Computing, S.L.)
    ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Program Files\AMD\CNext\CNext\atiacm64.dll [2017-08-17] (Advanced Micro Devices, Inc.)
    ContextMenuHandlers6: [ESET Smart Security - Context Menu Shell Extension] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2017-11-04] (ESET)
    ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-11-01] (Malwarebytes)
    ContextMenuHandlers6: [RUShellExt] -> {2C5515DC-2A7E-4BFD-B813-CACC2B685EB7} => C:\Program Files\VS Revo Group\Revo Uninstaller Pro\RUExt.dll [2016-12-15] (VS Revo Group)
    ContextMenuHandlers6: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\wzshls64.dll [2017-11-01] (WinZip Computing, S.L.)

    ==================== Scheduled Tasks (Whitelisted) =============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    Task: {0858C6B9-3DB8-4F90-B522-CAA45B4656FB} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-09-30] (Google Inc.)
    Task: {0F706005-5061-4A7B-A183-7C1AD819A56E} - System32\Tasks\Open URL by RoboForm => C:\WINDOWS\system32\rundll32.exe url.dll,FileProtocolHandler "hxxps://www.roboform.com/test-pass.html?aaa=KICMJMLJNMKJHMHMOJLMCNOJGMIMKJCNLMPMNMJMCNOJIMJJKMCNIMHMMJKJLJPMMMOMNJPMNJNMJNJICMHMCNLMCNJMFMOMOMCNOMNMKMCNOMJMNMGMGMFMPMCNPMCNOMJMNMGMGMCNNMJNPICMOMFMEKMICNJJCKFMGMGMJNHICMEKMICNJJCKJNBJCMNKKJJJKJNIJNKJCMJNNICMJNDJCMKJBJJNMJC (the data entry has 46 more characters).
    Task: {16F9037C-4EDE-44DD-A13F-DE53D149A529} - System32\Tasks\SystemToolsDailyTest => uaclauncher.exe
    Task: {32038BF9-EBC0-4EF8-80A2-1BE427E64205} - System32\Tasks\SUPERAntiSpyware Scheduled Task 3b953fdd-2662-494e-a974-c9d54b46f88f => C:\Program Files\SUPERAntiSpyware\SASTask.exe [2013-11-08] (SUPERAdBlocker.com)
    Task: {362F5EB7-0B32-4395-8626-2C4E87C28643} - System32\Tasks\PCDDataUploadTask => uaclauncher.exe
    Task: {42985D1B-F3E3-4027-8EEC-1B4E2AE259CC} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe [2017-08-17] (Advanced Micro Devices, Inc.)
    Task: {44E1A99C-4C2D-4580-AAB2-525770C7C6E3} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2018-01-15] (Microsoft Corporation)
    Task: {4F2F0E9B-E89C-4180-AFD7-0D6737861025} - System32\Tasks\Privacy Controls_{CD8C1E48-C2A8-11E7-AA6B-F8DA0C4C0331} => C:\Program Files (x86)\ParetoLogic\Privacy Controls\Pareto_PC.exe [2016-11-18] (ParetoLogic, Inc.) <==== ATTENTION
    Task: {598427FE-221A-4F9D-8362-C3F64F7FDDB5} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-09-30] (Google Inc.)
    Task: {72160BCC-B7D3-4764-8550-1E069CDAA95F} - System32\Tasks\PCDEventLauncherTask => C:\Program Files\Dell\SupportAssist\sessionchecker.exe [2017-04-18] (PC-Doctor, Inc.)
    Task: {756F07BF-6F13-457F-81BE-5BC9610085FC} - System32\Tasks\Dell SupportAssistAgent AutoUpdate => C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssist.exe [2017-12-22] (Dell Inc.)
    Task: {7E1A6D03-A64F-43AE-9128-14A3412D3FC3} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2018-01-21] (Microsoft Corporation)
    Task: {84E0A811-DE98-464A-B417-984C95EC2902} - System32\Tasks\PCDoctorBackgroundMonitorTask => C:\Program Files\Dell\SupportAssist\uaclauncher.exe [2017-04-18] (PC-Doctor, Inc.)
    Task: {9BFCA463-11FB-41F7-9045-BFEE74667741} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2017-07-24] (Apple Inc.)
    Task: {A4263EA3-4616-465A-8517-028E14567D03} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-09-27] (Adobe Systems Incorporated)
    Task: {A9ACBE7A-2EE1-45A8-9FD3-BC15C55E8CD9} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2018-01-21] (Microsoft Corporation)
    Task: {BB448F1C-D052-4C30-8690-1C46E35E5919} - System32\Tasks\SUPERAntiSpyware Scheduled Task abb3f931-6b91-4172-9b88-9b8b21b9ce83 => C:\Program Files\SUPERAntiSpyware\SASTask.exe [2013-11-08] (SUPERAdBlocker.com)
    Task: {C62649A7-8954-4321-884A-0B860872BAD0} - System32\Tasks\Run RoboForm TaskBar Icon => C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe [2018-01-05] (Siber Systems)
    Task: {DAD2D0BC-A6B1-40CD-B31A-F672AD31289C} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2018-01-15] (Microsoft Corporation)
    Task: {DF05B119-03A6-4DAD-8452-7C93495B1789} - System32\Tasks\RtHDVBg_PushButton => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2016-11-18] (Realtek Semiconductor)
    Task: {F195393B-9984-4AA9-87FE-EFD68D2D252A} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2018-01-21] (Microsoft Corporation)
    Task: {F9AABC9B-7EA2-4563-A70A-E1BF08D0BD54} - System32\Tasks\Dell SupportAssistAgent AnonymousRegistration => C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssist.exe [2017-12-22] (Dell Inc.)

    (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

    Task: C:\WINDOWS\Tasks\Privacy Controls_{CD8C1E48-C2A8-11E7-AA6B-F8DA0C4C0331}.job => C:\Program Files (x86)\ParetoLogic\Privacy Controls\Pareto_PC.exe <==== ATTENTION
    Task: C:\WINDOWS\Tasks\RunDLC.job => cmd c sc start Dell Help SupportWORKGROUP DESKTOP T60B7T6
    Task: C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task 3b953fdd-2662-494e-a974-c9d54b46f88f.job => C:\Program Files\SUPERAntiSpyware\SASTask.exe C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
    Task: C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task abb3f931-6b91-4172-9b88-9b8b21b9ce83.job => C:\Program Files\SUPERAntiSpyware\SASTask.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

    ==================== Shortcuts & WMI ========================

    (The entries could be listed to be restored or removed.)


    ==================== Loaded Modules (Whitelisted) ==============

    2017-09-29 22:41 - 2017-09-29 22:41 - 000184432 _____ () C:\WINDOWS\SYSTEM32\inputhost.dll
    2017-09-26 13:41 - 2017-09-26 13:41 - 005825576 _____ () C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll
    2017-11-30 18:54 - 2017-11-30 18:54 - 000088888 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
    2017-11-30 18:54 - 2017-11-30 18:54 - 001356088 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
    2017-11-22 11:20 - 2017-11-22 11:20 - 001216760 _____ () C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
    2017-09-01 20:15 - 2017-09-01 20:15 - 000495872 _____ () C:\Program Files\WinZip\WinZip Smart Monitor\WinZip Compression Smart Monitor Service.exe
    2017-12-23 22:13 - 2017-12-23 22:13 - 006096688 _____ () C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
    2017-11-22 11:06 - 2017-11-22 11:06 - 000585296 _____ () C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe
    2017-12-13 23:14 - 2017-11-29 09:11 - 002301384 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\SelfProtectionSdk.dll
    2017-12-13 23:14 - 2017-11-29 09:11 - 002358728 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll
    2017-12-17 06:06 - 2017-12-17 06:06 - 011044864 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
    2017-12-17 06:06 - 2017-12-17 06:06 - 001804288 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
    2016-06-30 19:01 - 2016-06-30 19:01 - 000014336 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick.2\qtquick2plugin.dll
    2016-06-30 19:01 - 2016-06-30 19:01 - 000739840 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Controls\qtquickcontrolsplugin.dll
    2016-06-30 19:01 - 2016-06-30 19:01 - 000014336 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Window.2\windowplugin.dll
    2016-06-30 19:01 - 2016-06-30 19:01 - 000071168 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Layouts\qquicklayoutsplugin.dll
    2016-06-30 19:00 - 2016-06-30 19:00 - 000011776 _____ () C:\Program Files\AMD\CNext\CNext\libEGL.dll
    2016-06-30 19:00 - 2016-06-30 19:00 - 002013696 _____ () C:\Program Files\AMD\CNext\CNext\libGLESv2.dll
    2016-06-30 19:01 - 2016-06-30 19:01 - 000191488 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Dialogs\dialogplugin.dll
    2017-12-11 11:05 - 2017-12-11 11:05 - 000088888 _____ () C:\Program Files\iTunes\zlib1.dll
    2017-12-11 11:05 - 2017-12-11 11:05 - 001356088 _____ () C:\Program Files\iTunes\libxml2.dll
    2018-01-20 10:05 - 2018-01-20 10:10 - 000086528 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.13.274.0_x64__kzf8qxf38zg5c\SkypeHost.exe
    2018-01-20 10:05 - 2018-01-20 10:10 - 000195072 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.13.274.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll
    2018-01-20 10:05 - 2018-01-20 10:10 - 024677376 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.13.274.0_x64__kzf8qxf38zg5c\SkyWrap.dll
    2018-01-03 20:44 - 2018-01-03 20:53 - 002550272 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.13.274.0_x64__kzf8qxf38zg5c\skypert.dll
    2018-01-20 10:05 - 2018-01-20 10:10 - 000667648 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.13.274.0_x64__kzf8qxf38zg5c\RtmMvrUap.dll
    2017-09-26 13:41 - 2017-09-26 13:41 - 007003048 _____ () C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe
    2017-12-22 01:45 - 2017-12-22 01:45 - 004620736 _____ () C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe
    2017-12-09 15:02 - 2016-11-22 11:14 - 000184832 _____ () C:\Program Files (x86)\LanInfo\laninfo.exe
    2017-09-28 15:56 - 2017-08-08 09:30 - 000018840 _____ () C:\Program Files (x86)\StrongVPN\CrashReporter.dll
    2017-12-11 11:04 - 2017-12-11 11:04 - 000235832 _____ () C:\Program Files\iTunes\libxslt.dll
    2018-01-10 08:41 - 2018-01-10 08:43 - 004698840 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_11712.1001.13.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll
    2017-12-12 09:32 - 2017-12-12 09:37 - 000477184 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.39101.16720.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
    2017-12-12 09:32 - 2017-12-12 09:37 - 058590720 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.39101.16720.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll
    2017-10-04 22:24 - 2017-10-04 22:25 - 002523136 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.39101.16720.0_x64__8wekyb3d8bbwe\UnityEngineDelegates.dll
    2017-11-14 08:52 - 2017-11-14 08:54 - 000164864 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.39101.16720.0_x64__8wekyb3d8bbwe\VideoPlugin.dll
    2017-10-04 22:24 - 2017-10-04 22:25 - 000675328 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.39101.16720.0_x64__8wekyb3d8bbwe\IPPNativePlugin.dll
    2017-12-12 09:32 - 2017-12-12 09:37 - 003727360 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.39101.16720.0_x64__8wekyb3d8bbwe\MediaEngineCSWrapper.dll
    2017-12-12 09:32 - 2017-12-12 09:37 - 002270720 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.39101.16720.0_x64__8wekyb3d8bbwe\TrackingDLLUWP.dll
    2017-12-12 09:32 - 2017-12-12 09:37 - 016395264 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.39101.16720.0_x64__8wekyb3d8bbwe\PhotosApp.Windows.dll
    2017-12-12 09:32 - 2017-12-12 09:37 - 003579904 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.39101.16720.0_x64__8wekyb3d8bbwe\MediaEngine.dll
    2017-12-12 09:32 - 2017-12-12 09:37 - 003204096 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.39101.16720.0_x64__8wekyb3d8bbwe\AppCore.Windows.dll
    2017-09-28 14:13 - 2017-09-28 14:14 - 003553704 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.39101.16720.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll
    2017-12-12 09:32 - 2017-12-12 09:37 - 000043520 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.39101.16720.0_x64__8wekyb3d8bbwe\Microsoft.Photos.Edit.Services.dll
    2017-12-12 09:32 - 2017-12-12 09:37 - 004038144 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.39101.16720.0_x64__8wekyb3d8bbwe\Microsoft.People.PeoplePicker.dll
    2017-12-12 09:32 - 2017-12-12 09:37 - 001367040 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.39101.16720.0_x64__8wekyb3d8bbwe\Microsoft.RichMedia.Ink.Controls.dll
    2017-12-12 09:32 - 2017-12-12 09:37 - 000214528 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.39101.16720.0_x64__8wekyb3d8bbwe\SKU.dll
    2017-12-22 01:44 - 2017-12-22 01:44 - 003485808 _____ () C:\Program Files (x86)\Common Files\Acronis\Infrastructure\atih_mms_addon.dll
    2017-12-22 01:43 - 2017-12-22 01:43 - 001331696 _____ () C:\Program Files (x86)\Common Files\Acronis\Infrastructure\services_mms_addon.dll
    2017-09-26 13:41 - 2017-09-26 13:41 - 000685488 _____ () C:\Program Files (x86)\Common Files\Acronis\Home\sqlite3.dll
    2017-12-22 01:43 - 2017-12-22 01:43 - 022715144 _____ () C:\Program Files (x86)\Acronis\TrueImageHome\ti_managers.dll
    2017-12-22 00:48 - 2017-12-22 00:48 - 000412704 _____ () C:\Program Files (x86)\Common Files\Acronis\Home\resource.dll
    2017-11-22 10:51 - 2017-11-22 10:51 - 000136736 _____ () C:\Program Files (x86)\Acronis\TrueImageHome\afcdpapi.dll
    2017-09-26 13:41 - 2017-09-26 13:41 - 000255008 _____ () C:\Program Files (x86)\Common Files\Acronis\Home\sync_agent_api.dll
    2017-09-26 13:41 - 2017-09-26 13:41 - 000160168 _____ () C:\Program Files (x86)\Common Files\Acronis\Home\libevent.dll
    2017-09-26 13:41 - 2017-09-26 13:41 - 000277538 _____ () C:\Program Files (x86)\Common Files\Acronis\ActiveProtection\LIBMAGIC.dll
    2017-09-26 13:41 - 2017-09-26 13:41 - 002386352 _____ () C:\Program Files (x86)\Common Files\Acronis\ActiveProtection\xerces_c.dll
    2017-12-07 10:56 - 2017-12-07 10:56 - 000102088 _____ () C:\Users\Refer\AppData\Local\Microsoft\OneDrive\17.3.7131.1115\UpdateRingSettings.dll
    2017-09-19 10:35 - 2017-09-19 10:35 - 000134008 _____ () C:\Program Files (x86)\Dell Customer Connect\ServiceTagPlusPlus.dll
    2017-04-28 23:05 - 2017-04-28 23:05 - 000134008 _____ () c:\Program Files (x86)\Dell Digital Delivery\ServiceTagPlusPlus.dll
    2017-11-21 13:50 - 2017-11-21 13:50 - 000134016 _____ () C:\Program Files (x86)\Dell Update\ServiceTagPlusPlus.dll
    2017-09-26 13:41 - 2017-09-26 13:41 - 000444336 _____ () C:\Program Files (x86)\Common Files\Acronis\Home\ulxmlrpcpp.dll
    2017-09-26 13:31 - 2017-09-26 13:31 - 000115632 _____ () C:\Program Files (x86)\Common Files\Acronis\Home\expat.dll
    2017-12-22 00:45 - 2017-12-22 00:45 - 008986144 _____ () C:\Program Files (x86)\Acronis\TrueImageHome\qt_resources.dll
    2017-11-22 11:04 - 2017-11-22 11:04 - 000796192 _____ () C:\Program Files (x86)\Acronis\TrueImageHome\qt_supp.dll
    2017-12-22 00:46 - 2017-12-22 00:46 - 000054816 _____ () C:\Program Files (x86)\Common Files\Acronis\Home\rpc_client.dll
    2009-05-21 10:00 - 2009-05-21 10:00 - 000303104 _____ () C:\Program Files (x86)\Transparent\Byki 4\Deluxe\KeyMapper.dll
    2009-05-21 10:00 - 2009-05-21 10:00 - 000278528 _____ () C:\Program Files (x86)\Transparent\Byki 4\Deluxe\AEEngine.dll
    2009-05-21 10:00 - 2009-05-21 10:00 - 002535424 _____ () C:\Program Files (x86)\Transparent\Byki 4\Deluxe\TLVideo.dll
    2009-05-21 10:00 - 2009-05-21 10:00 - 000409600 _____ () C:\Program Files (x86)\Transparent\Byki 4\Deluxe\svg-cairo.dll
    2017-11-13 21:45 - 2017-11-30 10:20 - 001452728 _____ () C:\Program Files (x86)\Microsoft Office\root\Office16\ClientTelemetry.dll
    2017-11-13 21:46 - 2018-01-21 10:05 - 000543408 _____ () C:\Program Files (x86)\Microsoft Office\root\Office16\msfad.dll
    2017-11-30 18:55 - 2017-11-30 18:55 - 001042232 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
    2017-11-30 18:55 - 2017-11-30 18:55 - 000076088 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll

    ==================== Alternate Data Streams (Whitelisted) =========

    (If an entry is included in the fixlist, only the ADS will be removed.)

    AlternateDataStreams: C:\ProgramData\TEMP:0FF263E8 [548]
    AlternateDataStreams: C:\Users\Refer\Documents\Copy of VA Notice of Annuity Adjustment.jpeg:3or4kl4x13tuuug3Byamue2s4b [83]
    AlternateDataStreams: C:\Users\Refer\Documents\Copy of VA Notice of Annuity Adjustment.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]
    AlternateDataStreams: C:\Users\Refer\Documents\Corrected 700-19 - 12-12-2017.jpeg:3or4kl4x13tuuug3Byamue2s4b [83]
    AlternateDataStreams: C:\Users\Refer\Documents\Corrected 700-19 - 12-12-2017.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]
    AlternateDataStreams: C:\Users\Refer\Documents\GEHA Letter Verifying Group Health Inaurance Coverage and the Date That Covergage Began.jpeg:3or4kl4x13tuuug3Byamue2s4b [83]
    AlternateDataStreams: C:\Users\Refer\Documents\GEHA Letter Verifying Group Health Inaurance Coverage and the Date That Covergage Began.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]
    AlternateDataStreams: C:\Users\Refer\Documents\Inverness Technologies Employment Offer Letter Signature Page With Revised Start Date - Dated 12-07-2017.jpeg:3or4kl4x13tuuug3Byamue2s4b [83]
    AlternateDataStreams: C:\Users\Refer\Documents\Inverness Technologies Employment Offer Letter Signature Page With Revised Start Date - Dated 12-07-2017.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]
    AlternateDataStreams: C:\Users\Refer\Documents\Inverness Technologies Health Coverage opt-Out Notification Form.jpeg:3or4kl4x13tuuug3Byamue2s4b [83]
    AlternateDataStreams: C:\Users\Refer\Documents\Inverness Technologies Health Coverage opt-Out Notification Form.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]
    AlternateDataStreams: C:\Users\Refer\Documents\IRS Form 673 - Statement for Claiming Exemption From Withholding on Foreign Earned Income - Inveness Technologies.jpeg:3or4kl4x13tuuug3Byamue2s4b [83]
    AlternateDataStreams: C:\Users\Refer\Documents\IRS Form 673 - Statement for Claiming Exemption From Withholding on Foreign Earned Income - Inveness Technologies.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]
    AlternateDataStreams: C:\Users\Refer\Documents\Social Security Government Pension Questionnaire Form.tiff:3or4kl4x13tuuug3Byamue2s4b [83]
    AlternateDataStreams: C:\Users\Refer\Documents\Social Security Government Pension Questionnaire Form.tiff:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]

    ==================== Safe Mode (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


    ==================== Association (Whitelisted) ===============

    (If an entry is included in the fixlist, the registry item will be restored to default or removed.)


    ==================== Internet Explorer trusted/restricted ===============

    (If an entry is included in the fixlist, it will be removed from the registry.)


    ==================== Hosts content: ===============================

    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

    2017-03-19 06:03 - 2017-03-19 06:01 - 000000824 _____ C:\WINDOWS\system32\Drivers\etc\hosts


    ==================== Other Areas ============================

    (Currently there is no automatic fix for this section.)

    HKU\S-1-5-21-1534629146-3426154806-933795594-1001\Control Panel\Desktop\\Wallpaper -> c:\windows\web\wallpaper\theme1\img1.jpg
    DNS Servers: 216.131.91.251 - 216.131.91.252
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
    Windows Firewall is enabled.

    ==================== MSCONFIG/TASK MANAGER disabled items ==

    HKLM\...\StartupApproved\StartupFolder: => "MySoftware NewsFlash.lnk"
    HKLM\...\StartupApproved\StartupFolder: => "Quicken Scheduled Updates.lnk"
    HKLM\...\StartupApproved\Run: => "QuickSet"
    HKLM\...\StartupApproved\Run: => "WavesSvc"
    HKLM\...\StartupApproved\Run: => "Acronis Scheduler2 Service"
    HKLM\...\StartupApproved\Run: => "WinZip UN"
    HKLM\...\StartupApproved\Run: => "WinZip PreLoader"
    HKLM\...\StartupApproved\Run: => "iTunesHelper"
    HKLM\...\StartupApproved\Run32: => "TrueImageMonitor.exe"
    HKLM\...\StartupApproved\Run32: => "AcronisTibMounterMonitor"
    HKLM\...\StartupApproved\Run32: => "LanInfo"

    ==================== FirewallRules (Whitelisted) ===============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    FirewallRules: [{D638C5D9-3363-47EE-B30B-59A39AA3DCBB}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
    FirewallRules: [{9D7009FF-A80D-4B72-9438-7B9229CB5CBD}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe
    FirewallRules: [{0C760F58-9421-46C2-A8FC-27D05CB86244}] => (Block) C:\program files\itunes\itunes.exe
    FirewallRules: [{1069BF14-8A80-4824-8EAD-6C43178D7ADD}] => (Block) C:\program files\itunes\itunes.exe
    FirewallRules: [UDP Query User{A8414EE8-F1ED-4240-A57E-5EBC9A103C80}C:\program files\itunes\itunes.exe] => (Allow) C:\program files\itunes\itunes.exe
    FirewallRules: [TCP Query User{66CB5706-B2E4-49E0-9630-2BF053D784E4}C:\program files\itunes\itunes.exe] => (Allow) C:\program files\itunes\itunes.exe
    FirewallRules: [{8F84C46B-3B57-4887-880B-DC29776980EA}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
    FirewallRules: [{899C0180-03BD-4625-A127-04EFDEB1E8F8}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
    FirewallRules: [{9EBC9824-4084-444A-A3A3-0AC820572961}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
    FirewallRules: [{B1C74E15-CD51-48AD-BD7E-B26DA6B918A9}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
    FirewallRules: [UDP Query User{50375A96-60FD-4323-8586-CFA983296C1A}C:\users\refer\appdata\local\skypeplugin\pluginhost.exe] => (Allow) C:\users\refer\appdata\local\skypeplugin\pluginhost.exe
    FirewallRules: [TCP Query User{6EE450BE-F5BE-4606-9447-773783067072}C:\users\refer\appdata\local\skypeplugin\pluginhost.exe] => (Allow) C:\users\refer\appdata\local\skypeplugin\pluginhost.exe
    FirewallRules: [{DCC59472-AAF6-4ADC-A29F-AF93C3CA6736}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
    FirewallRules: [{ED035A3E-6E43-47B5-BA92-AF624811515B}] => (Allow) LPort=51001
    FirewallRules: [{2E56A79A-2D3B-46EB-A02F-46C75A00FE3D}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe
    FirewallRules: [{69A86353-69D1-427E-8B15-1349AF474AFC}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\Infrastructure\mms_mini.exe
    FirewallRules: [{0ED36CA2-EE15-4FC8-851B-2B560F658570}] => (Allow) C:\Program Files (x86)\Acronis\TrueImageHome\TrueImage.exe
    FirewallRules: [{C06CE1DB-33A0-4007-9FB2-75281B78EA5D}] => (Allow) C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe
    FirewallRules: [{4E9B1717-334E-46CA-AEAF-1EAE6E0C9CF3}] => (Allow) C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageTools.exe
    FirewallRules: [{5C5560E8-2649-4B96-BB42-988D16A25B86}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\TrueImageHome\TrueImageHomeService.exe
    FirewallRules: [{EB16D150-56E0-4DDE-B951-98AE7216D5DF}] => (Allow) C:\Program Files (x86)\Acronis\TrueImageHome\MediaBuilder.exe
    FirewallRules: [{B1FA62CE-288B-4956-B288-AFE02776A53C}] => (Allow) C:\Program Files (x86)\Acronis\TrueImageHome\SystemReport.exe
    FirewallRules: [{79E491ED-B678-4783-8B79-0277717EE9EE}] => (Allow) C:\Program Files (x86)\Acronis\TrueImageHome\acronis_drive.exe
    FirewallRules: [{BB42DEF8-B22A-45FB-9326-00A9E1B9A323}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\MobileBackupServer\mobile_backup_server.exe
    FirewallRules: [{20F6E2F2-856A-4A12-85EE-CD2EA7B594C3}] => (Allow) C:\Program Files (x86)\Acronis\TrueImageHome\mobile_backup_status_server.exe
    FirewallRules: [{0BA0F268-A00A-4F28-B28B-FED3BAB81024}] => (Allow) C:\Program Files (x86)\Acronis\TrueImageHome\ga_service.exe
    FirewallRules: [{62D4E0D2-0025-4B75-B36F-FFDF3A34D4FD}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\ActiveProtection\anti_ransomware_service.exe
    FirewallRules: [{6D929A56-D60C-4B37-AABE-BAA2DE7FD5FB}] => (Allow) C:\Program Files\iTunes\iTunes.exe

    ==================== Restore Points =========================

    06-01-2018 08:47:25 Windows Update
    10-01-2018 08:29:53 Windows Update
    20-01-2018 14:30:45 Scheduled Checkpoint

    ==================== Faulty Device Manager Devices =============


    ==================== Event log errors: =========================

    Application errors:
    ==================
    Error: (01/21/2018 01:13:34 PM) (Source: COM) (EventID: 10031) (User: )
    Description: An unmarshaling policy check was performed when unmarshaling a custom marshaled object and the class {95CABCC9-BC57-4C12-B8DF-BA193232AA01} was rejected

    Error: (01/21/2018 10:19:17 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: DESKTOP-T60B7T6)
    Description: Package Microsoft.Windows.ShellExperienceHost_10.0.16299.15_neutral_neutral_cw5n1h2txyewy+App was terminated because it took too long to suspend.

    Error: (01/21/2018 10:16:12 AM) (Source: SupportAssistAgent) (EventID: 0) (User: )
    Description: An exception occurred in session change of service start: Object reference not set to an instance of an object.

    Error: (01/21/2018 10:14:05 AM) (Source: SupportAssistAgent) (EventID: 0) (User: )
    Description: An exception occurred in session change of service start: Object reference not set to an instance of an object.

    Error: (01/21/2018 10:13:47 AM) (Source: SupportAssistAgent) (EventID: 0) (User: )
    Description: An exception occurred in session change of service start: Object reference not set to an instance of an object.

    Error: (01/21/2018 10:12:45 AM) (Source: DNS logging) (EventID: 0) (User: )
    Description: Event-ID 0

    Error: (01/21/2018 12:00:14 AM) (Source: SupportAssistAgent) (EventID: 0) (User: )
    Description: An exception occurred in session change of service start: Object reference not set to an instance of an object.

    Error: (01/20/2018 11:59:45 PM) (Source: Acronis Scheduler) (EventID: 1) (User: NT AUTHORITY)
    Description: Scheduler failed to run task >> "" with GUID '48E6C910-9690-493F-A5D2-790F78F331DC' because of error 87> (Scheduler has received a request with an invalid parameter.).

    Error: (01/20/2018 11:59:12 PM) (Source: DNS logging) (EventID: 0) (User: )
    Description: Event-ID 0

    Error: (01/20/2018 10:00:08 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: DESKTOP-T60B7T6)
    Description: Package Microsoft.Windows.Photos_2017.39101.16720.0_x64__8wekyb3d8bbwe+App was terminated because it took too long to suspend.


    System errors:
    =============
    Error: (01/21/2018 01:15:56 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
    Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
    {D63B10C5-BB46-4990-A94F-E40B9D520160}
    and APPID
    {9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
    to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

    Error: (01/21/2018 12:40:38 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-T60B7T6)
    Description: The server Microsoft.Windows.Photos_2017.39101.16720.0_x64__8wekyb3d8bbwe!App.AppXy9rh3t8m2jfpvhhxp6y2ksgeq77vymbq.mca did not register with DCOM within the required timeout.

    Error: (01/21/2018 10:33:51 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
    Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
    {D63B10C5-BB46-4990-A94F-E40B9D520160}
    and APPID
    {9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
    to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

    Error: (01/21/2018 10:27:55 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
    Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
    {D63B10C5-BB46-4990-A94F-E40B9D520160}
    and APPID
    {9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
    to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

    Error: (01/21/2018 10:21:27 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
    Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
    {D63B10C5-BB46-4990-A94F-E40B9D520160}
    and APPID
    {9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
    to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

    Error: (01/21/2018 10:18:04 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
    Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
    {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
    and APPID
    {4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
    to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

    Error: (01/21/2018 10:18:04 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
    Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
    {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
    and APPID
    {4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
    to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

    Error: (01/21/2018 10:15:59 AM) (Source: Service Control Manager) (EventID: 7043) (User: )
    Description: The Acronis Nonstop Backup Service service did not shut down properly after receiving a preshutdown control.

    Error: (01/21/2018 10:15:39 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-T60B7T6)
    Description: The server {A463FCB9-6B1C-4E0D-A80B-A2CA7999E25D} did not register with DCOM within the required timeout.

    Error: (01/21/2018 10:15:39 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-T60B7T6)
    Description: The server {1EF75F33-893B-4E8F-9655-C3D602BA4897} did not register with DCOM within the required timeout.


    CodeIntegrity:
    ===================================
    Date: 2018-01-21 14:03:35.884
    Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\ESET\ESET Security\ekrn.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

    Date: 2018-01-21 14:03:35.880
    Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\ESET\ESET Security\ekrn.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

    Date: 2018-01-21 14:03:29.830
    Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Microsoft signing level requirements.

    Date: 2018-01-21 14:03:29.825
    Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Microsoft signing level requirements.

    Date: 2018-01-21 14:00:06.527
    Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\ESET\ESET Security\ekrn.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

    Date: 2018-01-21 14:00:06.408
    Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\ESET\ESET Security\ekrn.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

    Date: 2018-01-21 13:59:29.095
    Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\ESET\ESET Security\ekrn.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

    Date: 2018-01-21 13:59:29.071
    Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\ESET\ESET Security\ekrn.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

    Date: 2018-01-21 13:59:29.066
    Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\ESET\ESET Security\ekrn.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

    Date: 2018-01-21 13:59:29.060
    Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\ESET\ESET Security\ekrn.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.


    ==================== Memory info ===========================

    Processor: AMD A9-9400 RADEON R5, 5 COMPUTE CORES 2C+3G
    Percentage of memory in use: 57%
    Total physical RAM: 7638.37 MB
    Available physical RAM: 3269.82 MB
    Total Virtual: 8854.37 MB
    Available Virtual: 3671.15 MB

    ==================== Drives ================================

    Drive c: (OS) (Fixed) (Total:917.84 GB) (Free:548.06 GB) NTFS

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (Size: 931.5 GB) (Disk ID: 9319F5D9)

    Partition: GPT.

    ==================== End of Addition.txt ============================
     
  10. dvk01

    dvk01 Moderator Malware Specialist

    Joined:
    Dec 14, 2002
    Messages:
    52,578
    First Name:
    Derek
    There are no signs of cyberlink actually being installed on the computer or any start up entries in the logs
    There are a couple of cyberlink data folders that look like they were created just before Christmas, probably by an auto-update by dell updates or whatever
    From your original post it looks like a windows store app and they don't show up well in logs
    open the store link from start menu/desktop/start screen look for anything cyberlink & right click & select remove or uninstall
     
  11. referee07

    referee07 Thread Starter

    Joined:
    Sep 11, 2003
    Messages:
    1,304
    dvk01, thanks for your reply. I am so frustrated with my computer now I feel like doing exactly what the gentleman in your logo is doing, smashing my computer. This computer is a Windows 10 computer and IMHO it is a garbage OS. (I may be wrong in this and it may be something in the programs on the computer.) I hope that I will excuse me but I would like to tell you what happening and gain your advise. Recently, when I click on the Windows icon in the Task Bar nothing happens. Also, when I try to type something in the search area, nothing is displayed. Getting to the Internet takes a loooong time. Oftentimes, when I type something (such as when I am typing this message) nothing happens or characters are missing and I have to go back and retype the characters. (I should let you know that I use StrongVPN and I don't know if that has anything to do with it. I also use Hitman Pro which encrypts everything that I type which may have something to do with connecting with the Internet or in the slow response-time regarding typing.) If I could, I would buy a Windows 7 computer and be happy with that until 2020. I know that this message really does not have anything to do with your response above, but I can't get to the Start Menu because when I click on the Windows icon in the Task Bar, nothing happens. Thanks again for your help and please excuse this message if it is not appropriate to this thread but I am really frustrated with my computer at this point.
     
  12. dvk01

    dvk01 Moderator Malware Specialist

    Joined:
    Dec 14, 2002
    Messages:
    52,578
    First Name:
    Derek
    Any VPN will cause problems with internet connections. Using encryption via hitman pro of everything typed is very possibly the root cause of many of your problems.

    Overkill on security tools can cause as many problems as no security at all
     
  13. referee07

    referee07 Thread Starter

    Joined:
    Sep 11, 2003
    Messages:
    1,304
    dvk01, I forgot to mention that Outlook also frequently freezes for a short period of time. Do you think that I need to install more RAM?
     
  14. referee07

    referee07 Thread Starter

    Joined:
    Sep 11, 2003
    Messages:
    1,304
    dvk10, can you take a look at the programs that I am using and suggest some that I don't need? Also, I am wondering if I have two programs (one I installed and one that came with Windows) that may be in conflict with each other?
     
  15. referee07

    referee07 Thread Starter

    Joined:
    Sep 11, 2003
    Messages:
    1,304
    dvk10, now when I click on the Outlook icon in the Task Bar, nothing happens. I can see that there are three windows open in Outlook, but when I click on the icon, nothing happens.
     
  16. dvk01

    dvk01 Moderator Malware Specialist

    Joined:
    Dec 14, 2002
    Messages:
    52,578
    First Name:
    Derek
    shut everything & then reboot the computer
    Do not shut down & start up but right click start button and select restart or reboot
    Outlook and other office programs will auto-update but sometimes unless there has been a reboot, it gets to the stage where old copies are still running in memory and cause problems

    At least once a week with W8/W10 do a restart not shut down & start up or sleep or hibernate.
     
  17. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Similar Threads - Receiving Notice Start
  1. speddog
    Replies:
    6
    Views:
    301

Short URL to this thread: https://techguy.org/1202377