Solved Unable to open excel or words file that I receive via email.

Status
This thread has been Locked and is not open to further replies. Please start a New Thread if you're having a similar issue. View our Welcome Guide to learn how to use this site.

durhamcoffee

Thread Starter
Joined
Jul 25, 2018
Messages
13
Hi. All of the sudden my PC is unable to open excel or word files received via email. Message says that I do not have sufficient available memory or disk space which is not correct. Please see pic of message in attached. PDF. Thank you.
 

Attachments

dvk01

Derek
Retired Moderator Retired Malware Specialist
Joined
Dec 14, 2002
Messages
56,452
It looks like it might be related to the problems we thought we had fixed before
https://forums.techguy.org/threads/my-lap-top-says-i-have-no-space-left.1213489/#post-9524235

run FRST again & lets see what shows this time, Make sure you check the addition txt in the extra files section
post both new logs back here

If there is space then it is likely that the message is slightly wrong.
Do you save the files first or try to open directly from the email
Try saving them to downloads folder first, rather than trying to open directly form the email
 

durhamcoffee

Thread Starter
Joined
Jul 25, 2018
Messages
13
Hi again. No, this is unrelated. This is my PC, not my lap top. Can you send a new FRST file or should I copy (if it works) the one in my lap top?
 

dvk01

Derek
Retired Moderator Retired Malware Specialist
Joined
Dec 14, 2002
Messages
56,452
I am 99.9% sure that it won't be a disk space problem if it is a different computer, if you are sure you have space on the drive.
Recent updates to Microsoft Office have increased security and you will get that message when you try to open a document from the internet
The only fix is to either lower the security to turn off protected mode, which I strongly advise you not to do.
The best solution is to save the Excel or word doc to the computer, right click the file, select properties & then unblock
 

dvk01

Derek
Retired Moderator Retired Malware Specialist
Joined
Dec 14, 2002
Messages
56,452
Also what email client are you using? if it is Outlook, then Outlook will use a fairly small "secure temp" folder to open attachments. it is supposed to empty taht temp folder automatically, but doesn't always,

download run Outlook temp folder cleaner from https://www.howto-outlook.com/products/outlooktempcleaner.htm

I use that weekly on my computer
 

dvk01

Derek
Retired Moderator Retired Malware Specialist
Joined
Dec 14, 2002
Messages
56,452
OK lets see what FRST shows us then
Please download Farbar Recovery Scan Tool and save it to your Desktop or downloads folder.

Note: You need to download and run the 64 bit version

  • Right click to run as administrator. When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will produce a log called FRST.txt in the same directory the tool is run from.
  • Please copy and paste log back here.
  • The first time the tool is run it generates another log (Addition.txt - also located in the same directory/folder/place as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply.
 

durhamcoffee

Thread Starter
Joined
Jul 25, 2018
Messages
13
Here it goes. Other file is attached.


Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 21.07.2018
Ran by Adrian Moguel y Anza (administrator) on AMOGUELYANZA (28-07-2018 14:21:03)
Running from C:\Users\Adrian Moguel y Anza\Downloads
Loaded Profiles: Adrian Moguel y Anza (Available Profiles: Adrian Moguel y Anza)
Platform: Windows 10 Pro Version 1803 17134.112 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

() C:\Windows\System32\nvwmi64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Dell Inc.) C:\Program Files\Dell\PPO\poaSmSrv.exe
(Dell Inc.) C:\Program Files\Dell\PPO\poaTaServ.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
() C:\Program Files (x86)\TunnelBear\TunnelBear.Maintenance.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Dell Inc.) C:\Program Files\Dell\PPO\poaService.exe
(Trading Technologies International, Inc.) C:\tt\Guardian\GuardianCtrl.exe
(Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1806.18062-0\MsMpEng.exe
(Seiko Epson Corporation) C:\Program Files (x86)\epson\MyEpson Portal\mepService.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(DigitalPersona, Inc.) C:\Program Files\Dell\Dell Data Protection\Security Tools\Authentication\Bin\DpHostW.exe
(Trading Technologies International, Inc.) C:\tt\ttsim\TTSimManager.exe
(DigitalPersona, Inc.) C:\Program Files\Dell\Dell Data Protection\Security Tools\Authentication\Bin\DpCardEngine.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler64.exe
(Dell) C:\Program Files\Dell\Dell Foundation Services\DFSSvc.exe
(Dell Products, LP.) C:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology enterprise\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Trading Technologies International, Inc.) C:\tt\ttm\ttmd.exe
(Microsoft Corporation) C:\Windows\System32\LogonUI.exe
(Bomgar) C:\ProgramData\bomgar-scc-0x5b59b543\bomgar-scc.exe
(Bomgar) C:\ProgramData\bomgar-scc-0x5b59b665\bomgar-scc.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.LockApp_cw5n1h2txyewy\LockApp.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Trading Technologies International, Inc.) C:\tt\Guardian\guardian.exe
(Bloomberg Finance L.P.) C:\blp\Wintrv\Smartclient\OfficeHost\blpaddinhost.exe
(Bloomberg L.P.) C:\blp\DAPI\bbcomm.exe
(Trading Technologies International, Inc.) C:\tt\Guardian\GuardianMFC.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Dell Inc.) C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe
(Dell Inc.) C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe
(Dell Inc.) C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe
(PC-Doctor, Inc.) C:\Program Files\Dell\SupportAssistAgent\PCDr\SupportAssist\6.0.6992.1236\DSAPI.exe
(PC-Doctor, Inc.) C:\Program Files\Dell\SupportAssistAgent\PCDr\SupportAssist\6.0.6992.1236\pcdrwi.exe
(Dell Inc.) C:\Program Files\Dell\DellDataVault\nvapiw.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\office15\onenotem.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\office15\winword.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AdobeCollabSync.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
() C:\Program Files (x86)\SysTools Access to Excel Converter v2.0 DEMO\SysToolsAccess2ExcelConverter.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Bloomberg Finance L.P.) C:\blp\Wintrv\Smartclient\blpsmarthost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(PC-Doctor, Inc.) C:\Program Files\Dell\SupportAssistAgent\PCDr\SupportAssist\6.0.6992.1236\SystemIdleCheck.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [638872 2018-04-12] (Microsoft Corporation)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8513784 2015-08-03] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1411320 2015-08-03] (Realtek Semiconductor)
HKLM\...\Run: [DellPoaEvents] => C:\Program Files\Dell\PPO\DellPoaEvents.exe [396496 2014-08-15] (Dell Inc.)
HKLM\...\Run: [nwiz] => C:\Program Files\NVIDIA Corporation\nview\nwiz.exe [2728736 2014-08-04] ()
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology enterprise\IAStorIcon.exe [294896 2014-01-29] (Intel Corporation)
HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe [1189664 2016-07-18] (Intel Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-09-05] (Oracle Corporation)
HKLM-x32\...\Run: [ConnectionCenter] => C:\Program Files (x86)\Citrix\ICA Client\concentr.exe [557400 2018-01-01] (Citrix Systems, Inc.)
HKLM-x32\...\Run: [Redirector] => C:\Program Files (x86)\Citrix\ICA Client\redirector.exe [402776 2018-01-01] (Citrix Systems, Inc.)
HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,C:\Program Files (x86)\Dell\Dell Data Protection\Security Tools Authentication\Bin\DPAgent.exe,
HKU\S-1-5-19\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-12] (Microsoft Corporation)
HKU\S-1-5-20\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-12] (Microsoft Corporation)
HKU\S-1-5-21-3709382928-3884936676-3748502351-1000\...\Run: [GoogleDriveSync] => C:\Program Files\Google\Drive\googledrivesync.exe [46281248 2018-05-30] ()
HKU\S-1-5-21-3709382928-3884936676-3748502351-1000\...\Run: [EPLTarget\P0000000000000000] => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YATIHVE.EXE [241280 2017-07-31] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-3709382928-3884936676-3748502351-1000\...\Run: [Bomgar Support Reconnect [5B59B543]] => C:\ProgramData\bomgar-scc-0x5b59b543\bomgar-scc.exe [9371496 2017-08-27] (Bomgar)
HKU\S-1-5-21-3709382928-3884936676-3748502351-1000\...\Run: [Bomgar Support Reconnect [5B59B665]] => C:\ProgramData\bomgar-scc-0x5b59b665\bomgar-scc.exe [9371496 2017-08-27] (Bomgar)
HKU\S-1-5-21-3709382928-3884936676-3748502351-1000\...\Run: [Bomgar_Cleanup_ZD1738697819636] => cmd.exe /C rd /S /Q "C:\Users\ADRIAN~2\AppData\Local\Temp\nsd77.tmpb" & reg.exe delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v Bomgar_Cleanup_ZD1738697819636 /f <==== ATTENTION
HKU\S-1-5-21-3709382928-3884936676-3748502351-1000\...\Run: [Bomgar_Cleanup_ZD17767098429107] => cmd.exe /C rd /S /Q "C:\ProgramData\bomgar-scc-0x5b59bb2a" & reg.exe delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v Bomgar_Cleanup_ZD17767098429107 /f <==== ATTENTION
HKU\S-1-5-21-3709382928-3884936676-3748502351-1000\...\Run: [CLRHost] => C:\blp\API\Office Tools\bbxlcmd.exe [2160128 2018-07-13] ()
HKU\S-1-5-21-3709382928-3884936676-3748502351-1000\...\Run: [Bomgar_Cleanup_ZD2772204217113] => cmd.exe /C rd /S /Q "C:\Users\ADRIAN~2\AppData\Local\Temp\nso12C.tmpb" & reg.exe delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v Bomgar_Cleanup_ZD2772204217113 /f <==== ATTENTION
HKU\S-1-5-21-3709382928-3884936676-3748502351-1000\...\Run: [Bomgar_Cleanup_ZD27742412519685] => cmd.exe /C rd /S /Q "C:\ProgramData\bomgar-scc-0x5b5b4f46" & reg.exe delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v Bomgar_Cleanup_ZD27742412519685 /f <==== ATTENTION
HKU\S-1-5-21-3709382928-3884936676-3748502351-1000\...\Run: [Bomgar_Cleanup_ZD27863731222411] => cmd.exe /C rd /S /Q "C:\ProgramData\bomgar-scc-0x5b5b4ee1" & reg.exe delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v Bomgar_Cleanup_ZD27863731222411 /f <==== ATTENTION
HKU\S-1-5-21-3709382928-3884936676-3748502351-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\Mystify.scr [149504 2018-04-12] (Microsoft Corporation)
Lsa: [Notification Packages] DPPassFilter scecli
Startup: C:\Users\Adrian Moguel y Anza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk [2018-07-26]
ShortcutTarget: Send to OneNote.lnk -> C:\Program Files\Microsoft Office 15\root\office15\onenotem.exe (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Start Guardian.lnk [2018-07-12]
ShortcutTarget: Start Guardian.lnk -> C:\tt\Guardian\GuardianStart.exe (Trading Technologies International, Inc.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 10.0.0.1
Tcpip\..\Interfaces\{094046fc-81e2-46b8-bf37-2458999904d3}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{094046fc-81e2-46b8-bf37-2458999904d3}: [DhcpNameServer] 172.18.13.1
Tcpip\..\Interfaces\{19e413c5-f1f9-46f4-b086-3aef81e56e55}: [DhcpNameServer] 172.18.10.1
Tcpip\..\Interfaces\{2076f695-d283-41e1-b363-5c76b32bb0be}: [DhcpNameServer] 10.0.0.1
Tcpip\..\Interfaces\{952f2d60-98af-4fbb-9d17-9aceda38dd36}: [DhcpNameServer] 172.18.13.1

Internet Explorer:
==================
HKU\S-1-5-21-3709382928-3884936676-3748502351-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://lenovo17win10.msn.com/?pc=LCTE
HKU\S-1-5-21-3709382928-3884936676-3748502351-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://dell13.msn.com/?pc=DCJB
HKU\S-1-5-21-3709382928-3884936676-3748502351-1000\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://mystart.lenovo.com
SearchScopes: HKU\S-1-5-21-3709382928-3884936676-3748502351-1000 -> DefaultScope {22841ADF-367B-41D7-B90F-D0B723455C5A} URL =
SearchScopes: HKU\S-1-5-21-3709382928-3884936676-3748502351-1000 -> {22841ADF-367B-41D7-B90F-D0B723455C5A} URL =
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2017-10-24] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2017-10-24] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\ssv.dll [2017-10-30] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\jp2ssv.dll [2017-10-30] (Oracle Corporation)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2017-10-24] (Microsoft Corporation)
Filter-x32: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2018-01-01] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2018-01-01] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2018-01-01] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2018-01-01] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2018-01-01] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2018-01-01] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2018-01-01] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2018-01-01] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2018-01-01] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2018-01-01] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2018-01-01] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2018-01-01] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2018-01-01] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2018-01-01] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2018-01-01] (Citrix Systems, Inc.)
Filter-x32: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2018-01-01] (Citrix Systems, Inc.)

FireFox:
========
FF DefaultProfile: oznmvvqz.default
FF ProfilePath: C:\Users\Adrian Moguel y Anza\AppData\Roaming\Mozilla\Firefox\Profiles\oznmvvqz.default [2017-08-10]
FF Extension: (Tab Auto Reload) - C:\Users\Adrian Moguel y Anza\AppData\Roaming\Mozilla\Firefox\Profiles\oznmvvqz.default\Extensions\[email protected] [2017-05-19] [Legacy]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Dell\Dell Data Protection\Security Tools Authentication\Bin\BrowserExt\dpchrome
FF Extension: (Dell Data Protection | Security Tools) - C:\Program Files (x86)\Dell\Dell Data Protection\Security Tools Authentication\Bin\BrowserExt\dpchrome [2015-10-13] [Legacy] [not signed]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @Citrix.com/npican -> C:\Program Files (x86)\Citrix\ICA Client\npicaN.dll [2018-01-01] (Citrix Systems, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=11.151.2 -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\dtplugin\npDeployJava1.dll [2017-10-30] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.151.2 -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\plugin2\npjp2.dll [2017-10-30] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2015-07-03] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-21] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-21] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-06-29] (Adobe Systems Inc.)
FF Plugin-x32: digitalpersona.com/ChromeDPAgent -> C:\Program Files (x86)\Dell\Dell Data Protection\Security Tools Authentication\Bin\BrowserExt\components\npChromeDPAgent.dll [2014-03-17] (DigitalPersona, Inc.)
FF Plugin HKU\S-1-5-21-3709382928-3884936676-3748502351-1000: @citrixonline.com/appdetectorplugin -> C:\Users\Adrian Moguel y Anza\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2015-02-01] (Citrix Online)
FF Plugin ProgramFiles/Appdata: C:\Users\Adrian Moguel y Anza\AppData\Roaming\mozilla\plugins\npatgpc.dll [2018-07-05] (Cisco WebEx LLC)

Chrome:
=======
CHR DefaultProfile: Profile 1
CHR Profile: C:\Users\Adrian Moguel y Anza\AppData\Local\Google\Chrome\User Data\Profile 1 [2018-07-28]
CHR Extension: (Adobe Acrobat) - C:\Users\Adrian Moguel y Anza\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2018-07-22]
CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\Adrian Moguel y Anza\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2018-07-22]
CHR Extension: (Dell Data Protection | Security Tools) - C:\Users\Adrian Moguel y Anza\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ncffjdbbodifgldkcbhmiiljfcnbgjab [2018-07-22]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Adrian Moguel y Anza\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-07-22]
CHR Extension: (Smallpdf) - C:\Users\Adrian Moguel y Anza\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ohfgljdgelakfkefopgklcohadegdpjf [2018-07-26]
CHR Extension: (Chrome Media Router) - C:\Users\Adrian Moguel y Anza\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-07-22]
CHR Profile: C:\Users\Adrian Moguel y Anza\AppData\Local\Google\Chrome\User Data\System Profile [2018-07-22]
CHR HKU\S-1-5-21-3709382928-3884936676-3748502351-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [ncffjdbbodifgldkcbhmiiljfcnbgjab] - C:\Program Files (x86)\Dell\Dell Data Protection\Security Tools Authentication\Bin\BrowserExt\dpchrome.crx [2014-03-17]

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 algose_sim; C:\tt\AlgoSE_sim\AlgoSE.exe [5700608 2016-01-29] (Trading Technologies International, Inc.) [File not signed]
S2 bomgar-scc-5B59B543; C:\ProgramData\bomgar-scc-0x5b59b543\bomgar-scc.exe [9371496 2017-08-27] (Bomgar)
S2 bomgar-scc-5B59B665; C:\ProgramData\bomgar-scc-0x5b59b665\bomgar-scc.exe [9371496 2017-08-27] (Bomgar)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [3058416 2017-09-05] (Microsoft Corporation)
R2 DDVCollectorSvcApi; C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe [208792 2018-02-10] (Dell Inc.)
S2 DDVDataCollector; C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe [3346320 2018-02-10] (Dell Inc.)
R2 DDVRulesProcessor; C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe [217488 2018-02-10] (Dell Inc.)
R2 Dell Foundation Services; C:\Program Files\Dell\Dell Foundation Services\DFSSvc.exe [97616 2017-01-11] (Dell)
R2 Dell Hardware Support; C:\Program Files\Dell\SupportAssistAgent\PCDr\SupportAssist\6.0.6992.1236\DSAPI.exe [935744 2018-07-28] (PC-Doctor, Inc.)
R2 DpHost; C:\Program Files\Dell\Dell Data Protection\Security Tools\Authentication\Bin\DpHostW.exe [472912 2014-03-19] (DigitalPersona, Inc.)
R3 guardian; C:\tt\Guardian\guardian.exe [5871616 2018-04-30] (Trading Technologies International, Inc.) [File not signed]
R2 guardianctrl; C:\tt\Guardian\GuardianCtrl.exe [1272072 2018-04-30] (Trading Technologies International, Inc.)
S3 guardserver_sim; C:\tt\ttsim\guardserver_sim.exe [6340096 2016-03-07] (Trading Technologies International, Inc.) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [987432 2016-06-14] (Intel(R) Corporation)
S3 InvProtectSvc; C:\Program Files (x86)\Invincea\Enterprise\X64\InvProtectSvc64.exe [2672328 2014-07-30] (Invincea, Inc.)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [215328 2016-07-18] (Intel Corporation)
R2 MyEpson Portal Service; C:\Program Files (x86)\EPSON\MyEpson Portal\mepService.exe [714712 2017-06-28] (Seiko Epson Corporation)
R2 NVWMI; C:\Windows\system32\nvwmi64.exe [2694432 2014-08-04] ()
R2 poaService; C:\Program Files\Dell\PPO\poaService.exe [721104 2014-08-15] (Dell Inc.)
R2 PoaSMSrv; C:\Program Files\Dell\PPO\poaSmSrv.exe [312016 2014-08-15] (Dell Inc.)
R2 poaTaServ; C:\Program Files\Dell\PPO\poaTaServ.exe [645328 2014-08-16] (Dell Inc.)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [308472 2015-08-03] (Realtek Semiconductor)
S3 SboxSvc; C:\Program Files (x86)\Invincea\Enterprise\Sandbox\SboxSvc.exe [173256 2014-07-30] (Invincea, Inc.)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [4737448 2018-04-12] (Microsoft Corporation)
S4 ssh-agent; C:\WINDOWS\System32\OpenSSH\ssh-agent.exe [495616 2018-03-10] ()
R2 SupportAssistAgent; C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [45016 2018-07-08] (Dell Inc.)
S3 syntheticse_sim; C:\tt\SyntheticSE_sim\SyntheticSE.exe [5676544 2016-01-26] (Trading Technologies International, Inc.) [File not signed]
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [7534864 2016-08-25] (TeamViewer GmbH)
S3 ttkeyserver_sim; C:\tt\ttsim\ttkeyserver.exe [5284352 2012-09-17] (Trading Technologies International, Inc.) [File not signed]
R3 ttmd; C:\tt\ttm\ttmd.exe [3299328 2018-04-27] (Trading Technologies International, Inc.) [File not signed]
S3 TTSIM-ZFillServer; C:\tt\ttsim\FillServerSim.exe [7502848 2016-03-07] (Trading Technologies International, Inc.) [File not signed]
S3 TTSIM-ZOrderServer; C:\tt\ttsim\OrderServer.exe [7847424 2016-03-07] (Trading Technologies International, Inc.) [File not signed]
S3 TTSIM-ZPriceServer; C:\tt\ttsim\PriceServer.exe [7103488 2016-03-07] (Trading Technologies International, Inc.) [File not signed]
S3 TTSIM-ZSimulatedExchange; C:\tt\ttsim\SimulatedExchange.exe [7193600 2016-03-07] (Trading Technologies International, Inc.) [File not signed]
R2 TTSimManager; C:\tt\ttsim\TTSimManager.exe [1956864 2016-03-07] (Trading Technologies International, Inc.) [File not signed]
R2 TunnelBearMaintenance; C:\Program Files (x86)\TunnelBear\TunnelBear.Maintenance.exe [119680 2018-06-19] ()
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1806.18062-0\NisSrv.exe [3925648 2018-06-26] (Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1806.18062-0\MsMpEng.exe [100080 2018-06-26] (Microsoft Corporation)
S3 guardian_sim; C:\tt\ttsim\Guardian_sim.exe -aconfigpath "C:\tt\config\"
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
S3 TTSIM-ZProductServer; C:\tt\ttsim\ProductServer.exe -e TTSIM-Z -aconfigpath "C:\tt\config\"

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 DDDriver; C:\WINDOWS\system32\drivers\DDDriver64Dcsa.sys [41608 2018-02-10] (Dell Inc.)
R3 DellProf; C:\WINDOWS\system32\drivers\DellProf.sys [41208 2018-02-10] (Dell Computer Corporation)
S3 FLMckUsb; C:\WINDOWS\System32\drivers\ATTchWDF.sys [75264 2013-09-06] (AuthenTec, Inc.)
S3 iaStorS; C:\WINDOWS\system32\drivers\iaStorS.sys [658928 2014-01-29] (Intel Corporation)
R3 IntcAzAudAddService; C:\WINDOWS\system32\drivers\RTDVHD64.sys [2558208 2015-08-03] (Realtek Semiconductor Corp.)
S3 InvProtectDrv; C:\Program Files (x86)\Invincea\Enterprise\X64\InvProtectDrv64.sys [50696 2014-07-30] (Invincea, Inc.)
R1 MpKslc48f3da5; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{67E2ECBB-D4B5-4B14-8799-E1C58581D7C2}\MpKslc48f3da5.sys [58120 2018-07-28] (Microsoft Corporation)
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nv_ref_pubwu.inf_amd64_b7e5dd1387001335\nvlddmkm.sys [16936560 2017-11-09] (NVIDIA Corporation)
R3 POADrvr; C:\WINDOWS\system32\drivers\POADrvr.sys [21264 2014-08-15] (Dell Computer Corporation)
S3 SboxDrv; C:\Program Files (x86)\Invincea\Enterprise\Sandbox\SboxDrv.sys [183304 2014-07-30] (Invincea, Inc.)
R3 tap-tb-0901; C:\WINDOWS\System32\drivers\tap-tb-0901.sys [38656 2015-08-10] (The OpenVPN Project)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [46592 2018-06-26] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [340008 2018-06-26] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [59944 2018-06-26] (Microsoft Corporation)
U3 aspnet_state; no ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-07-28 14:21 - 2018-07-28 14:22 - 000030611 _____ C:\Users\Adrian Moguel y Anza\Downloads\FRST.txt
2018-07-28 14:20 - 2018-07-28 14:21 - 000000000 ____D C:\FRST
2018-07-28 14:19 - 2018-07-28 14:19 - 002412544 _____ (Farbar) C:\Users\Adrian Moguel y Anza\Downloads\FRST64.exe
2018-07-28 14:03 - 2018-07-28 14:03 - 001605408 _____ (SysTools Software ) C:\Users\Adrian Moguel y Anza\Downloads\access-to-excel.exe
2018-07-28 14:03 - 2018-07-28 14:03 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SysTools Access to Excel Converter
2018-07-28 14:03 - 2018-07-28 14:03 - 000000000 ____D C:\Program Files (x86)\SysTools Access to Excel Converter v2.0 DEMO
2018-07-28 13:27 - 2018-07-28 13:27 - 000002237 _____ C:\Users\Public\Desktop\SupportAssist.lnk
2018-07-28 13:26 - 2018-07-28 13:26 - 000003914 _____ C:\WINDOWS\System32\Tasks\Dell SupportAssistAgent AutoUpdate
2018-07-28 13:26 - 2018-07-28 13:26 - 000000000 ____D C:\ProgramData\SupportAssist
2018-07-28 13:26 - 2018-07-28 13:26 - 000000000 ____D C:\ProgramData\Dell Inc
2018-07-28 13:25 - 2018-07-28 13:25 - 000305728 _____ (Dell Inc.) C:\Users\Adrian Moguel y Anza\Downloads\SupportAssistLauncher.exe
2018-07-28 13:21 - 2018-07-28 13:21 - 000020369 _____ C:\Users\Adrian Moguel y Anza\Downloads\Book22 (3).xlsx
2018-07-28 13:19 - 2018-07-28 13:19 - 000020369 _____ C:\Users\Adrian Moguel y Anza\Downloads\Book22 (2).xlsx
2018-07-28 13:18 - 2018-07-28 13:18 - 000020369 _____ C:\Users\Adrian Moguel y Anza\Downloads\Book22 (1).xlsx
2018-07-27 18:20 - 2018-07-27 18:20 - 000004120 _____ C:\WINDOWS\System32\Tasks\Bomgar Task 278637125
2018-07-27 18:00 - 2018-07-27 18:00 - 000004120 _____ C:\WINDOWS\System32\Tasks\Bomgar Task 277424000
2018-07-27 17:58 - 2018-07-27 18:00 - 000000000 ____D C:\ProgramData\bomgar-scc-0x5b5b4f46
2018-07-27 17:57 - 2018-07-27 18:20 - 000000000 ____D C:\ProgramData\bomgar-scc-0x5b5b4ee1
2018-07-27 17:50 - 2018-07-27 17:50 - 000124076 _____ C:\Users\Adrian Moguel y Anza\Downloads\bookmarks_7_27_18.html
2018-07-27 17:31 - 2018-07-27 17:31 - 000004726 _____ C:\Users\Adrian Moguel y Anza\Desktop\Orders and Fills Window 2_FillsPane_Book 1_20180727_173108.csv
2018-07-27 17:30 - 2018-07-27 17:30 - 000004726 _____ C:\Users\Adrian Moguel y Anza\Desktop\Orders and Fills Window 2_FillsPane_Book 1_20180727_173014.csv
2018-07-27 17:24 - 2018-07-27 17:24 - 000020369 _____ C:\Users\Adrian Moguel y Anza\Downloads\Book22.xlsx
2018-07-26 14:17 - 2018-07-26 14:17 - 000004120 _____ C:\WINDOWS\System32\Tasks\Bomgar Task 177670859
2018-07-26 13:14 - 2018-07-26 14:17 - 000000000 ____D C:\ProgramData\bomgar-scc-0x5b59bb2a
2018-07-26 12:54 - 2018-07-26 13:04 - 000000000 ____D C:\ProgramData\bomgar-scc-0x5b59b665
2018-07-26 12:49 - 2018-07-26 12:51 - 000000000 ____D C:\ProgramData\bomgar-scc-0x5b59b543
2018-07-25 22:53 - 2018-07-25 22:53 - 000015853 _____ C:\Users\Adrian Moguel y Anza\Desktop\Fill Window_FillsPane_Fill 1_20180725_215908.xlsx
2018-07-25 22:00 - 2018-07-25 22:53 - 000006749 _____ C:\Users\Adrian Moguel y Anza\Desktop\Fill Window_FillsPane_Fill 1_20180725_215908.csv
2018-07-25 15:27 - 2018-07-25 15:27 - 000004118 _____ C:\WINDOWS\System32\Tasks\Bomgar Task 95429015
2018-07-25 15:23 - 2018-07-25 15:23 - 000015030 _____ C:\Users\Adrian Moguel y Anza\Downloads\SHEARWATER_CL Trader_View_PnL 2018 07 24 (2).xlsx
2018-07-25 15:22 - 2018-07-25 15:22 - 000015030 _____ C:\Users\Adrian Moguel y Anza\Downloads\SHEARWATER_CL Trader_View_PnL 2018 07 24 (1).xlsx
2018-07-25 14:50 - 2018-07-25 14:50 - 000015030 _____ C:\Users\Adrian Moguel y Anza\Downloads\SHEARWATER_CL Trader_View_PnL 2018 07 24.xlsx
2018-07-25 13:58 - 2018-07-25 13:58 - 000004118 _____ C:\WINDOWS\System32\Tasks\Bomgar Task 90130156
2018-07-25 12:53 - 2018-07-25 12:53 - 003000776 _____ (bomgar) C:\Users\Adrian Moguel y Anza\Downloads\bomgar-scc-w0yc30je5dwd8g85178hfzexgyjy1g5y8h85yic40jc90.exe
2018-07-25 11:02 - 2018-07-25 11:02 - 000107111 _____ C:\Users\Adrian Moguel y Anza\Downloads\hsk 072418.pdf
2018-07-25 10:50 - 2018-07-25 10:50 - 005084495 _____ C:\Users\Adrian Moguel y Anza\Downloads\PX_CLUSTER 2 (3).xlsx
2018-07-25 10:43 - 2018-07-25 10:43 - 000000000 ___HD C:\$SysReset
2018-07-25 10:37 - 2018-07-25 10:37 - 000008014 _____ C:\Users\Adrian Moguel y Anza\Desktop\test.xlsx
2018-07-25 10:34 - 2018-07-25 10:34 - 005084495 _____ C:\Users\Adrian Moguel y Anza\Downloads\PX_CLUSTER 2 (2).xlsx
2018-07-25 10:20 - 2018-07-25 10:20 - 005084495 _____ C:\Users\Adrian Moguel y Anza\Desktop\PX_CLUSTER 2.xlsx
2018-07-25 10:17 - 2018-07-25 10:17 - 000128874 _____ C:\Users\Adrian Moguel y Anza\Downloads\MASTER_CONTRACTS_48_V10.xlsx
2018-07-25 10:15 - 2018-07-25 10:15 - 000201149 _____ C:\Users\Adrian Moguel y Anza\Downloads\CASH CLUSTER SB_CASH_PRICES_INDIA_SUGAR_STARCH_5VAR_RAW_DAILY_V.04_LINKED.xlsx
2018-07-25 10:14 - 2018-07-25 10:14 - 000008349 _____ C:\Users\Adrian Moguel y Anza\Downloads\Book2 (2).xlsx
2018-07-25 10:13 - 2018-07-25 10:13 - 000008349 _____ C:\Users\Adrian Moguel y Anza\Downloads\Book2.xlsx
2018-07-25 10:13 - 2018-07-25 10:13 - 000008349 _____ C:\Users\Adrian Moguel y Anza\Downloads\Book2 (1).xlsx
2018-07-25 10:08 - 2018-07-25 10:08 - 005084495 _____ C:\Users\Adrian Moguel y Anza\Downloads\PX_CLUSTER 2 (1).xlsx
2018-07-25 09:52 - 2018-07-25 09:52 - 000780537 _____ C:\Users\Adrian Moguel y Anza\Downloads\VOLS_CLUSTER.xlsx
2018-07-25 09:49 - 2018-07-25 09:50 - 009808469 _____ C:\Users\Adrian Moguel y Anza\Downloads\CFTC_CLUSTER (1).xlsx
2018-07-25 09:49 - 2018-07-25 09:49 - 009808469 _____ C:\Users\Adrian Moguel y Anza\Downloads\CFTC_CLUSTER.xlsx
2018-07-25 09:45 - 2018-07-25 09:45 - 000000000 _____ C:\Users\Adrian Moguel y Anza\Downloads\PX_CLUSTER 2.xlsx
2018-07-25 09:40 - 2018-07-25 09:40 - 005085697 _____ C:\Users\Adrian Moguel y Anza\Downloads\PX_CLUSTER (2).xlsx
2018-07-25 09:31 - 2018-07-25 09:31 - 005085697 _____ C:\Users\Adrian Moguel y Anza\Downloads\PX_CLUSTER (Autosaved) (2).xlsx
2018-07-24 23:47 - 2018-07-24 23:47 - 000056295 _____ C:\Users\Adrian Moguel y Anza\Downloads\Gateway_User_ID.pdf
2018-07-24 23:37 - 2018-07-24 23:37 - 000013268 _____ C:\Users\Adrian Moguel y Anza\Downloads\SHEARWATER_CL Trader_View_PnL 2018 07 23.xlsx
2018-07-24 16:35 - 2018-07-24 16:35 - 002711389 _____ C:\Users\Adrian Moguel y Anza\Desktop\snip.pdf
2018-07-24 14:43 - 2018-07-24 14:43 - 000004116 _____ C:\WINDOWS\System32\Tasks\Bomgar Task 6391187
2018-07-24 12:46 - 2018-07-24 13:53 - 000000000 ____D C:\ProgramData\bomgar-scc-0x5b571198
2018-07-24 10:16 - 2018-07-24 10:16 - 002713033 _____ C:\Users\Adrian Moguel y Anza\Downloads\Minasul Europe Agency Contract FINAL_PORT.compressed.pdf
2018-07-24 09:57 - 2018-07-24 09:58 - 009226964 _____ C:\Users\Adrian Moguel y Anza\Downloads\Minasul Europe Agency Contract FINAL_ENG-1.pdf
2018-07-24 09:40 - 2018-07-24 09:40 - 000130882 _____ C:\Users\Adrian Moguel y Anza\Desktop\Gro Intelligence Adrian Moguel y Anza - Form Mutual NDA.pdf
2018-07-24 08:58 - 2018-07-24 08:58 - 003905236 _____ C:\Users\Adrian Moguel y Anza\Downloads\PX_CLUSTER (1).xlsx
2018-07-24 08:25 - 2018-07-24 08:25 - 003905236 _____ C:\Users\Adrian Moguel y Anza\Downloads\PX_CLUSTER.xlsx
2018-07-24 08:17 - 2018-07-24 08:17 - 006171935 _____ C:\Users\Adrian Moguel y Anza\Downloads\CASH_CLUSTER (1).xlsx
2018-07-23 09:02 - 2018-07-23 09:02 - 000001825 _____ C:\Users\Adrian Moguel y Anza\Desktop\Google Drive.lnk
2018-07-21 20:12 - 2018-07-21 20:12 - 001017424 _____ C:\Users\Adrian Moguel y Anza\Downloads\SB_LAST_PX_RAW_DAILY_V.01_LINKED (2).xlsx
2018-07-21 20:11 - 2018-07-21 20:11 - 001021389 _____ C:\Users\Adrian Moguel y Anza\Downloads\PX CLUSTER SB_LAST_PX_RAW_DAILY_V.04_LINKED.xlsx
2018-07-21 18:23 - 2018-07-21 18:23 - 000005735 _____ C:\Users\Adrian Moguel y Anza\Downloads\Edgewonk-Excel-import.xlsx
2018-07-21 17:58 - 2018-07-24 11:00 - 000000000 ____D C:\Edgewonk
2018-07-21 17:58 - 2018-07-21 17:58 - 000001563 _____ C:\Users\Adrian Moguel y Anza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Edgewonk.lnk
2018-07-21 17:58 - 2018-07-21 17:58 - 000001533 _____ C:\Users\Adrian Moguel y Anza\Desktop\Edgewonk.lnk
2018-07-20 17:32 - 2018-07-20 17:32 - 003291516 _____ C:\Users\Adrian Moguel y Anza\Downloads\tt_exchange_products.csv
2018-07-20 16:19 - 2018-07-20 16:19 - 001882021 _____ C:\Users\Adrian Moguel y Anza\Downloads\CASH_CLUSTER.xlsx
2018-07-20 15:40 - 2018-07-20 15:40 - 000780537 _____ C:\Users\Adrian Moguel y Anza\Downloads\VOLS_LINKED (2).xlsx
2018-07-19 12:38 - 2018-07-19 12:38 - 000081352 _____ C:\Users\Adrian Moguel y Anza\Desktop\Originação_Minasul_Europe_v3 (Recuperado).xlsx
2018-07-18 08:17 - 2018-04-10 21:11 - 002629120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsLexicons0009.dll
2018-07-18 08:17 - 2018-04-10 21:10 - 005739008 _____ (Microsoft Corporation) C:\WINDOWS\system32\prm0009.dll
2018-07-18 08:17 - 2018-04-10 21:09 - 002629120 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsLexicons0009.dll
2018-07-18 08:17 - 2018-04-10 21:06 - 005487616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData0009.dll
2018-07-18 08:17 - 2018-04-10 21:02 - 006350848 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData0009.dll
2018-07-16 08:28 - 2018-07-16 08:28 - 000000000 ___HD C:\OneDriveTemp
2018-07-15 08:52 - 2018-07-15 08:52 - 000193587 _____ C:\Users\Adrian Moguel y Anza\Downloads\BoardingPass (4).pdf
2018-07-13 14:49 - 2018-07-13 14:49 - 000017415 _____ C:\Users\Adrian Moguel y Anza\Desktop\Originação_Minasul_Europe.xlsx
2018-07-13 10:27 - 2018-07-13 10:27 - 000043754 _____ C:\Users\Adrian Moguel y Anza\Downloads\output (38).pdf
2018-07-13 10:27 - 2018-07-13 10:27 - 000043754 _____ C:\Users\Adrian Moguel y Anza\Downloads\Ending in N.pdf
2018-07-13 10:26 - 2018-07-13 10:26 - 000043745 _____ C:\Users\Adrian Moguel y Anza\Downloads\output (37).pdf
2018-07-13 10:26 - 2018-07-13 10:26 - 000043745 _____ C:\Users\Adrian Moguel y Anza\Downloads\Ending in X.pdf
2018-07-13 10:25 - 2018-07-13 10:25 - 000043403 _____ C:\Users\Adrian Moguel y Anza\Downloads\Ending in V.pdf
2018-07-13 10:24 - 2018-07-13 10:24 - 000043403 _____ C:\Users\Adrian Moguel y Anza\Downloads\output (36).pdf
2018-07-13 10:21 - 2018-07-13 10:21 - 000103088 _____ C:\Users\Adrian Moguel y Anza\Downloads\0240000049718501V0000_Account_Statement_20180301092626069414.pdf
2018-07-13 10:20 - 2018-07-13 10:20 - 000109656 _____ C:\Users\Adrian Moguel y Anza\Downloads\0240000049718501V0000_Account_Statement_20180201114153118796.pdf
2018-07-13 10:20 - 2018-07-13 10:20 - 000102786 _____ C:\Users\Adrian Moguel y Anza\Downloads\0240000049718560X0000_Account_Statement_20180301092437710145.pdf
2018-07-12 19:23 - 2018-07-12 19:23 - 000001804 _____ C:\Users\Public\Desktop\X_TRADER.lnk
2018-07-12 18:50 - 2018-06-18 16:35 - 105725440 _____ (Trading Technologies ) C:\Users\Adrian Moguel y Anza\Desktop\X_TRADER_r7.17.84p587 (1).exe
2018-07-12 18:47 - 2018-07-20 08:21 - 000000000 ____D C:\ProgramData\bomgar-scc-0x5b47941c
2018-07-12 16:04 - 2018-07-12 16:04 - 000982338 _____ C:\Users\Adrian Moguel y Anza\Downloads\SB_CFTC_62VAR_RAW_DAILY_V.01_LINKED (1).xlsx
2018-07-12 15:41 - 2018-07-12 15:41 - 009632073 _____ C:\Users\Adrian Moguel y Anza\Downloads\OAM-Filing-Annual-Report-and-Audited-Consolidated-Financial-S-2018-03-21.pdf
2018-07-12 14:44 - 2018-07-12 14:44 - 002459174 _____ C:\Users\Adrian Moguel y Anza\Downloads\Cockpit_NEW_v2.xlsx
2018-07-11 14:39 - 2018-07-11 14:39 - 000196592 _____ C:\Users\Adrian Moguel y Anza\Downloads\Master3 (2).xlsx
2018-07-11 14:39 - 2018-07-11 14:39 - 000196592 _____ C:\Users\Adrian Moguel y Anza\Downloads\Master3 (1).xlsx
2018-07-11 14:15 - 2018-07-11 14:15 - 000060452 _____ C:\Users\Adrian Moguel y Anza\Downloads\3e4160ae-9bed-44d3-aeef-fe7261fd5f42.tmp
2018-07-11 14:15 - 2018-07-11 14:15 - 000060452 _____ C:\Users\Adrian Moguel y Anza\Downloads\114833043.pdf
2018-07-11 11:28 - 2018-07-11 11:28 - 000203096 _____ C:\Users\Adrian Moguel y Anza\Desktop\Doc260.pdf
2018-07-11 10:57 - 2018-07-11 10:57 - 000364590 _____ C:\Users\Adrian Moguel y Anza\Downloads\QW_VOLS_10_25_40_50_60_75_90_FRONT_MONTH_V.01.xlsx
2018-07-11 10:51 - 2018-07-11 10:51 - 000270106 _____ C:\Users\Adrian Moguel y Anza\Downloads\SB_BRAZIL_EXPORTS_COUNTRY_VOLUME_VALUE_168VAR_RAW_MONTHLY_V.01_LINKED.xlsx
2018-07-10 20:46 - 2018-07-10 20:46 - 000442368 _____ C:\Users\Adrian Moguel y Anza\Desktop\Commodity trading enters the age of digitisation _ Financial Times.pdf
2018-07-10 16:31 - 2018-07-10 16:31 - 001002328 _____ C:\Users\Adrian Moguel y Anza\Downloads\SB_OPEN_INT_RAW_DAILY_V.02_LINKED (2).xlsx
2018-07-10 16:28 - 2018-07-10 16:29 - 001002328 _____ C:\Users\Adrian Moguel y Anza\Downloads\SB_OPEN_INT_RAW_DAILY_V.02_LINKED (1).xlsx
2018-07-10 14:38 - 2018-07-10 14:38 - 000274987 _____ C:\Users\Adrian Moguel y Anza\Desktop\Doc259.pdf
2018-07-10 11:15 - 2018-07-10 11:15 - 000318936 _____ C:\Users\Adrian Moguel y Anza\Downloads\SB_CASH_PRICES_BRAZIL_ESALQ_ETHANOL_14VAR_RAW_DAILY_V.01_LINKED.xlsx
2018-07-10 09:39 - 2018-07-10 09:39 - 003842784 _____ (Interactive Brokers LLC) C:\Users\Adrian Moguel y Anza\Downloads\tws-stable-windows-x64 (5).exe
2018-07-10 09:39 - 2018-07-10 09:39 - 000001441 _____ C:\Users\Adrian Moguel y Anza\Desktop\Trader Workstation.lnk
2018-07-10 09:39 - 2018-07-10 09:39 - 000000000 ____D C:\Users\Adrian Moguel y Anza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Trader Workstation
2018-07-09 19:19 - 2018-07-09 19:19 - 000188416 _____ C:\Users\Adrian Moguel y Anza\Desktop\Larry Williams Trading Lessons.pdf
2018-07-09 18:09 - 2018-07-09 18:09 - 000132866 _____ C:\Users\Adrian Moguel y Anza\Downloads\Master3.xlsx
2018-07-09 12:43 - 2018-07-09 12:43 - 001309609 _____ C:\Users\Adrian Moguel y Anza\Downloads\WIP QW_SPREADS_H1_K1_N1_V1_PLUS_PERMUTATIONS_V.01.xlsx
2018-07-09 12:35 - 2018-07-09 12:35 - 000024299 _____ C:\Users\Adrian Moguel y Anza\Downloads\WIP_SB_GREEKS_V.01.xlsx
2018-07-09 12:28 - 2018-07-09 12:28 - 000561899 _____ C:\Users\Adrian Moguel y Anza\Downloads\SB_VOLUME_RAW_DAILY_V.02_LINKED (1).xlsx
2018-07-09 12:27 - 2018-07-09 12:27 - 000561899 _____ C:\Users\Adrian Moguel y Anza\Downloads\SB_VOLUME_RAW_DAILY_V.02_LINKED.xlsx
2018-07-09 12:24 - 2018-07-09 12:24 - 000385299 _____ C:\Users\Adrian Moguel y Anza\Downloads\SB_VOLS_10_25_40_50_60_75_90_FRONT_MONTH_V.01.xlsx
2018-07-09 12:07 - 2018-07-09 12:07 - 001150963 _____ C:\Users\Adrian Moguel y Anza\Downloads\SB_SPREADS_H1_K1_N1_V1_PLUS_PERMUTATIONS_V.01.xlsx
2018-07-09 12:04 - 2018-07-09 12:04 - 000984591 _____ C:\Users\Adrian Moguel y Anza\Downloads\SB_OPEN_INT_RAW_DAILY_V.02_LINKED.xlsx
2018-07-09 12:01 - 2018-07-09 12:01 - 001017462 _____ C:\Users\Adrian Moguel y Anza\Downloads\SB_LAST_PX_RAW_DAILY_V.01_LINKED (1).xlsx
2018-07-09 11:56 - 2018-07-09 11:56 - 000982338 _____ C:\Users\Adrian Moguel y Anza\Downloads\SB_CFTC_62VAR_RAW_DAILY_V.01_LINKED.xlsx
2018-07-09 11:26 - 2018-07-28 13:32 - 000183402 _____ C:\Users\Adrian Moguel y Anza\Desktop\Doc1.pdf
2018-07-05 19:57 - 2018-07-05 19:57 - 000037891 _____ C:\Users\Adrian Moguel y Anza\Documents\algotest1.algo
2018-07-05 19:00 - 2018-07-05 19:00 - 000000000 ____D C:\Users\Adrian Moguel y Anza\AppData\Roaming\webex
2018-07-05 18:59 - 2018-07-05 20:14 - 000000000 ____D C:\Users\Adrian Moguel y Anza\AppData\LocalLow\WebEx
2018-07-05 18:59 - 2018-07-05 19:00 - 000000000 ____D C:\Users\Adrian Moguel y Anza\AppData\Local\WebEx
2018-07-05 18:59 - 2018-07-05 19:00 - 000000000 ____D C:\ProgramData\WebEx
2018-07-05 18:59 - 2018-07-05 18:59 - 001037704 _____ (Cisco WebEx LLC) C:\Users\Adrian Moguel y Anza\Downloads\Cisco_WebEx_Add-On.exe
2018-07-05 18:04 - 2018-07-12 19:23 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trading Technologies
2018-07-05 18:04 - 2018-07-12 19:18 - 000001747 _____ C:\Users\Public\Desktop\Start Guardian.lnk
2018-07-05 18:04 - 2018-07-12 19:18 - 000001742 _____ C:\Users\Public\Desktop\Stop Guardian.lnk
2018-07-05 18:04 - 2018-07-05 18:51 - 000000000 ____D C:\tt
2018-07-05 18:04 - 2018-07-05 18:51 - 000000000 ____D C:\ProgramData\Trading Technologies
2018-07-05 09:19 - 2018-07-05 09:19 - 000177178 _____ C:\Users\Adrian Moguel y Anza\Downloads\certificate (2).pdf
2018-07-05 09:18 - 2018-07-05 09:18 - 000177178 _____ C:\Users\Adrian Moguel y Anza\Downloads\certificate (1).pdf
2018-07-04 10:21 - 2018-07-04 10:21 - 000998255 _____ C:\Users\Adrian Moguel y Anza\Desktop\LNL ACQUISITION INDEX (CT1).pptx
2018-07-03 19:03 - 2018-07-03 19:24 - 001022570 _____ C:\Users\Adrian Moguel y Anza\Desktop\LW LNL (CT1).pdf
2018-07-02 11:04 - 2018-07-02 11:04 - 000000733 _____ C:\Users\Public\Desktop\Bloomberg.lnk
2018-07-02 11:00 - 2018-07-02 11:04 - 000000000 ___HD C:\ProgramData\{9ABB0713-4F82-417A-8D8E-3F8FAEF338CF}
2018-07-02 11:00 - 2018-07-02 11:00 - 000000000 ____D C:\Users\Adrian Moguel y Anza\AppData\Local\IIIQF
2018-06-28 11:56 - 2018-06-28 11:56 - 000175437 _____ C:\Users\Adrian Moguel y Anza\Downloads\Patrick Neil Morgan 957159_95019434 (1).pdf
2018-06-28 11:38 - 2018-06-28 11:38 - 000175437 _____ C:\Users\Adrian Moguel y Anza\Downloads\Patrick Neil Morgan 957159_95019434.pdf

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-07-28 14:03 - 2015-02-01 13:43 - 000000000 ____D C:\Users\Adrian Moguel y Anza\AppData\Local\VirtualStore
2018-07-28 13:58 - 2015-02-01 14:10 - 000000000 ____D C:\ProgramData\PCDr
2018-07-28 13:38 - 2018-04-12 00:38 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2018-07-28 13:37 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\AppReadiness
2018-07-28 13:27 - 2018-06-20 17:54 - 000000000 ____D C:\ProgramData\Packages
2018-07-28 13:27 - 2018-04-12 00:38 - 000000000 ___HD C:\Program Files\WindowsApps
2018-07-28 13:27 - 2018-04-12 00:36 - 000000000 ____D C:\WINDOWS\INF
2018-07-28 13:27 - 2017-12-04 23:41 - 000000000 ____D C:\Users\Adrian Moguel y Anza\AppData\Local\Packages
2018-07-28 13:27 - 2015-01-12 21:55 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell
2018-07-28 13:26 - 2015-07-13 09:18 - 000000000 __HDC C:\ProgramData\~0
2018-07-28 13:26 - 2015-01-12 22:00 - 000000000 ____D C:\Program Files (x86)\Dell
2018-07-28 13:26 - 2015-01-12 21:55 - 000000000 ____D C:\Program Files\Dell
2018-07-28 13:03 - 2018-05-21 22:35 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2018-07-27 20:39 - 2015-02-01 22:05 - 000000000 ____D C:\Users\Adrian Moguel y Anza\AppData\Local\Bloomberg
2018-07-27 19:28 - 2017-03-01 12:49 - 000000000 ____D C:\Users\Adrian Moguel y Anza\AppData\Roaming\WhatsApp
2018-07-27 19:26 - 2018-05-21 23:04 - 000004192 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{7791E7B9-0765-4671-A9C4-BC4476FDFE5E}
2018-07-27 19:19 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\system32\NDF
2018-07-26 20:10 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\system32\FxsTmp
2018-07-26 13:07 - 2017-07-27 23:43 - 000000000 ____D C:\ProgramData\NVIDIA
2018-07-24 14:33 - 2018-05-16 10:55 - 000000000 ___SD C:\Users\Adrian Moguel y Anza\Documents\My Data Sources
2018-07-24 13:02 - 2018-05-21 22:40 - 000884150 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2018-07-24 12:57 - 2018-06-25 17:04 - 000000000 ____D C:\Program Files (x86)\TunnelBear
2018-07-24 12:57 - 2018-05-21 23:04 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2018-07-24 12:55 - 2018-04-11 22:04 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2018-07-24 10:23 - 2018-04-30 11:29 - 000000000 ____D C:\Users\Adrian Moguel y Anza\Desktop\Minasul Europe
2018-07-23 09:03 - 2016-11-19 11:49 - 000000000 ___RD C:\Users\Adrian Moguel y Anza\Google Drive
2018-07-20 08:23 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2018-07-19 16:55 - 2015-02-01 15:37 - 000000000 ___RD C:\Users\Adrian Moguel y Anza\OneDrive
2018-07-18 08:23 - 2018-04-12 00:30 - 000000000 ____D C:\WINDOWS\CbsTemp
2018-07-18 08:17 - 2018-04-12 10:19 - 000000000 ____D C:\WINDOWS\OCR
2018-07-17 10:54 - 2010-11-21 04:27 - 000563832 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2018-07-13 19:51 - 2018-05-22 09:28 - 000002382 _____ C:\Users\Adrian Moguel y Anza\Desktop\WhatsApp.lnk
2018-07-13 19:51 - 2018-05-22 09:27 - 000000000 ____D C:\Users\Adrian Moguel y Anza\AppData\Local\WhatsApp
2018-07-13 19:51 - 2017-03-01 12:49 - 000000000 ____D C:\Users\Adrian Moguel y Anza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WhatsApp
2018-07-13 19:50 - 2017-03-01 12:49 - 000000000 ____D C:\Users\Adrian Moguel y Anza\AppData\Local\SquirrelTemp
2018-07-13 10:03 - 2018-05-21 23:04 - 000004562 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2018-07-13 10:03 - 2017-02-21 17:56 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2018-07-12 19:16 - 2018-05-28 09:25 - 000000000 ____D C:\Users\Adrian Moguel y Anza\AppData\Local\D3DSCache
2018-07-12 18:58 - 2018-03-26 10:05 - 000000000 ____D C:\Users\Adrian Moguel y Anza\Desktop\LDC Sugar
2018-07-10 09:57 - 2015-02-01 18:56 - 000000000 ____D C:\Jts
2018-07-10 08:57 - 2018-05-21 23:04 - 000003402 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3709382928-3884936676-3748502351-1000
2018-07-10 08:57 - 2018-05-21 22:41 - 000002458 _____ C:\Users\Adrian Moguel y Anza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2018-07-05 18:59 - 2017-05-19 11:53 - 000000000 ____D C:\Users\Adrian Moguel y Anza\AppData\Roaming\Mozilla
2018-07-02 11:08 - 2016-05-06 10:28 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2018-07-02 11:01 - 2018-02-05 13:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bloomberg

Some files in TEMP:
====================
2018-07-26 15:09 - 2018-07-13 18:08 - 007243264 _____ () C:\Users\Adrian Moguel y Anza\AppData\Local\Temp\bbxlinst_32.dll
2018-07-26 15:10 - 2015-09-04 17:56 - 000413696 _____ (Bloomberg L.P.) C:\Users\Adrian Moguel y Anza\AppData\Local\Temp\fldfind.dll

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2018-05-21 22:35

==================== End of FRST.txt ============================
 

Attachments

dvk01

Derek
Retired Moderator Retired Malware Specialist
Joined
Dec 14, 2002
Messages
56,452
I can't see anything obviously wrong
Do any of the xls files or word docs that you have downloaded open ?

pick any one of them & right click the icon, Don't open the file. Select properties then at the bottom select unblock, press apply & OK
Then try to open that document or xls sheet

If that doesn't work, temporarily turn off protected mopde as shown here
https://www.laptopmag.com/articles/disable-protected-view-microsoft-wor

However that does leave you at a very high risk of a dangerous office doc delivering a virus to the computer
 
Status
This thread has been Locked and is not open to further replies. Please start a New Thread if you're having a similar issue. View our Welcome Guide to learn how to use this site.

Users Who Are Viewing This Thread (Users: 0, Guests: 1)

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 807,865 other people just like you!

Latest posts

Members online

Top