1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

Solved Unable to open excel or words file that I receive via email.

Discussion in 'Business Applications' started by durhamcoffee, Jul 28, 2018.

Thread Status:
Not open for further replies.
Advertisement
  1. durhamcoffee

    durhamcoffee Thread Starter

    Joined:
    Jul 25, 2018
    Messages:
    13
    Hi. All of the sudden my PC is unable to open excel or word files received via email. Message says that I do not have sufficient available memory or disk space which is not correct. Please see pic of message in attached. PDF. Thank you.
     

    Attached Files:

  2. dvk01

    dvk01 Moderator Malware Specialist

    Joined:
    Dec 14, 2002
    Messages:
    56,371
    First Name:
    Derek
    It looks like it might be related to the problems we thought we had fixed before
    https://forums.techguy.org/threads/my-lap-top-says-i-have-no-space-left.1213489/#post-9524235

    run FRST again & lets see what shows this time, Make sure you check the addition txt in the extra files section
    post both new logs back here

    If there is space then it is likely that the message is slightly wrong.
    Do you save the files first or try to open directly from the email
    Try saving them to downloads folder first, rather than trying to open directly form the email
     
  3. durhamcoffee

    durhamcoffee Thread Starter

    Joined:
    Jul 25, 2018
    Messages:
    13
    Hi again. No, this is unrelated. This is my PC, not my lap top. Can you send a new FRST file or should I copy (if it works) the one in my lap top?
     
  4. dvk01

    dvk01 Moderator Malware Specialist

    Joined:
    Dec 14, 2002
    Messages:
    56,371
    First Name:
    Derek
    I am 99.9% sure that it won't be a disk space problem if it is a different computer, if you are sure you have space on the drive.
    Recent updates to Microsoft Office have increased security and you will get that message when you try to open a document from the internet
    The only fix is to either lower the security to turn off protected mode, which I strongly advise you not to do.
    The best solution is to save the Excel or word doc to the computer, right click the file, select properties & then unblock
     
  5. durhamcoffee

    durhamcoffee Thread Starter

    Joined:
    Jul 25, 2018
    Messages:
    13
    I have tried to download and open from excel, but still I get the same message.
     
  6. dvk01

    dvk01 Moderator Malware Specialist

    Joined:
    Dec 14, 2002
    Messages:
    56,371
    First Name:
    Derek
    Also what email client are you using? if it is Outlook, then Outlook will use a fairly small "secure temp" folder to open attachments. it is supposed to empty taht temp folder automatically, but doesn't always,

    download run Outlook temp folder cleaner from https://www.howto-outlook.com/products/outlooktempcleaner.htm

    I use that weekly on my computer
     
  7. durhamcoffee

    durhamcoffee Thread Starter

    Joined:
    Jul 25, 2018
    Messages:
    13
    I use regular Google Chrome. I tried through the Microsoft browser but same result.
     
  8. dvk01

    dvk01 Moderator Malware Specialist

    Joined:
    Dec 14, 2002
    Messages:
    56,371
    First Name:
    Derek
    OK lets see what FRST shows us then
    Please download Farbar Recovery Scan Tool and save it to your Desktop or downloads folder.

    Note: You need to download and run the 64 bit version

    • Right click to run as administrator. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will produce a log called FRST.txt in the same directory the tool is run from.
    • Please copy and paste log back here.
    • The first time the tool is run it generates another log (Addition.txt - also located in the same directory/folder/place as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply.
     
  9. durhamcoffee

    durhamcoffee Thread Starter

    Joined:
    Jul 25, 2018
    Messages:
    13
    Here it goes. Other file is attached.


    Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 21.07.2018
    Ran by Adrian Moguel y Anza (administrator) on AMOGUELYANZA (28-07-2018 14:21:03)
    Running from C:\Users\Adrian Moguel y Anza\Downloads
    Loaded Profiles: Adrian Moguel y Anza (Available Profiles: Adrian Moguel y Anza)
    Platform: Windows 10 Pro Version 1803 17134.112 (X64) Language: English (United States)
    Internet Explorer Version 11 (Default browser: Chrome)
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    () C:\Windows\System32\nvwmi64.exe
    (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
    (Dell Inc.) C:\Program Files\Dell\PPO\poaSmSrv.exe
    (Dell Inc.) C:\Program Files\Dell\PPO\poaTaServ.exe
    (Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
    (Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
    () C:\Program Files (x86)\TunnelBear\TunnelBear.Maintenance.exe
    (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    (Dell Inc.) C:\Program Files\Dell\PPO\poaService.exe
    (Trading Technologies International, Inc.) C:\tt\Guardian\GuardianCtrl.exe
    (Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1806.18062-0\MsMpEng.exe
    (Seiko Epson Corporation) C:\Program Files (x86)\epson\MyEpson Portal\mepService.exe
    (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
    (DigitalPersona, Inc.) C:\Program Files\Dell\Dell Data Protection\Security Tools\Authentication\Bin\DpHostW.exe
    (Trading Technologies International, Inc.) C:\tt\ttsim\TTSimManager.exe
    (DigitalPersona, Inc.) C:\Program Files\Dell\Dell Data Protection\Security Tools\Authentication\Bin\DpCardEngine.exe
    (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler.exe
    (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler64.exe
    (Dell) C:\Program Files\Dell\Dell Foundation Services\DFSSvc.exe
    (Dell Products, LP.) C:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology enterprise\IAStorDataMgrSvc.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
    (Trading Technologies International, Inc.) C:\tt\ttm\ttmd.exe
    (Microsoft Corporation) C:\Windows\System32\LogonUI.exe
    (Bomgar) C:\ProgramData\bomgar-scc-0x5b59b543\bomgar-scc.exe
    (Bomgar) C:\ProgramData\bomgar-scc-0x5b59b665\bomgar-scc.exe
    (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
    (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.LockApp_cw5n1h2txyewy\LockApp.exe
    (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
    (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
    (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
    (Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
    (Microsoft Corporation) C:\Windows\System32\wlanext.exe
    (Trading Technologies International, Inc.) C:\tt\Guardian\guardian.exe
    (Bloomberg Finance L.P.) C:\blp\Wintrv\Smartclient\OfficeHost\blpaddinhost.exe
    (Bloomberg L.P.) C:\blp\DAPI\bbcomm.exe
    (Trading Technologies International, Inc.) C:\tt\Guardian\GuardianMFC.exe
    (Microsoft Corporation) C:\Windows\System32\dllhost.exe
    (Microsoft Corporation) C:\Windows\System32\dllhost.exe
    (Dell Inc.) C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe
    (Dell Inc.) C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe
    (Dell Inc.) C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe
    (PC-Doctor, Inc.) C:\Program Files\Dell\SupportAssistAgent\PCDr\SupportAssist\6.0.6992.1236\DSAPI.exe
    (PC-Doctor, Inc.) C:\Program Files\Dell\SupportAssistAgent\PCDr\SupportAssist\6.0.6992.1236\pcdrwi.exe
    (Dell Inc.) C:\Program Files\Dell\DellDataVault\nvapiw.exe
    (Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\office15\onenotem.exe
    (Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\office15\winword.exe
    (Microsoft Corporation) C:\Windows\splwow64.exe
    (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe
    (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe
    (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe
    (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe
    (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AdobeCollabSync.exe
    (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    () C:\Program Files (x86)\SysTools Access to Excel Converter v2.0 DEMO\SysToolsAccess2ExcelConverter.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Bloomberg Finance L.P.) C:\blp\Wintrv\Smartclient\blpsmarthost.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (PC-Doctor, Inc.) C:\Program Files\Dell\SupportAssistAgent\PCDr\SupportAssist\6.0.6992.1236\SystemIdleCheck.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Microsoft Corporation) C:\Windows\System32\smartscreen.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    ==================== Registry (Whitelisted) ===========================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [638872 2018-04-12] (Microsoft Corporation)
    HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8513784 2015-08-03] (Realtek Semiconductor)
    HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1411320 2015-08-03] (Realtek Semiconductor)
    HKLM\...\Run: [DellPoaEvents] => C:\Program Files\Dell\PPO\DellPoaEvents.exe [396496 2014-08-15] (Dell Inc.)
    HKLM\...\Run: [nwiz] => C:\Program Files\NVIDIA Corporation\nview\nwiz.exe [2728736 2014-08-04] ()
    HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology enterprise\IAStorIcon.exe [294896 2014-01-29] (Intel Corporation)
    HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe [1189664 2016-07-18] (Intel Corporation)
    HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-09-05] (Oracle Corporation)
    HKLM-x32\...\Run: [ConnectionCenter] => C:\Program Files (x86)\Citrix\ICA Client\concentr.exe [557400 2018-01-01] (Citrix Systems, Inc.)
    HKLM-x32\...\Run: [Redirector] => C:\Program Files (x86)\Citrix\ICA Client\redirector.exe [402776 2018-01-01] (Citrix Systems, Inc.)
    HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,C:\Program Files (x86)\Dell\Dell Data Protection\Security Tools Authentication\Bin\DPAgent.exe,
    HKU\S-1-5-19\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-12] (Microsoft Corporation)
    HKU\S-1-5-20\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-12] (Microsoft Corporation)
    HKU\S-1-5-21-3709382928-3884936676-3748502351-1000\...\Run: [GoogleDriveSync] => C:\Program Files\Google\Drive\googledrivesync.exe [46281248 2018-05-30] ()
    HKU\S-1-5-21-3709382928-3884936676-3748502351-1000\...\Run: [EPLTarget\P0000000000000000] => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YATIHVE.EXE [241280 2017-07-31] (SEIKO EPSON CORPORATION)
    HKU\S-1-5-21-3709382928-3884936676-3748502351-1000\...\Run: [Bomgar Support Reconnect [5B59B543]] => C:\ProgramData\bomgar-scc-0x5b59b543\bomgar-scc.exe [9371496 2017-08-27] (Bomgar)
    HKU\S-1-5-21-3709382928-3884936676-3748502351-1000\...\Run: [Bomgar Support Reconnect [5B59B665]] => C:\ProgramData\bomgar-scc-0x5b59b665\bomgar-scc.exe [9371496 2017-08-27] (Bomgar)
    HKU\S-1-5-21-3709382928-3884936676-3748502351-1000\...\Run: [Bomgar_Cleanup_ZD1738697819636] => cmd.exe /C rd /S /Q "C:\Users\ADRIAN~2\AppData\Local\Temp\nsd77.tmpb" & reg.exe delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v Bomgar_Cleanup_ZD1738697819636 /f <==== ATTENTION
    HKU\S-1-5-21-3709382928-3884936676-3748502351-1000\...\Run: [Bomgar_Cleanup_ZD17767098429107] => cmd.exe /C rd /S /Q "C:\ProgramData\bomgar-scc-0x5b59bb2a" & reg.exe delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v Bomgar_Cleanup_ZD17767098429107 /f <==== ATTENTION
    HKU\S-1-5-21-3709382928-3884936676-3748502351-1000\...\Run: [CLRHost] => C:\blp\API\Office Tools\bbxlcmd.exe [2160128 2018-07-13] ()
    HKU\S-1-5-21-3709382928-3884936676-3748502351-1000\...\Run: [Bomgar_Cleanup_ZD2772204217113] => cmd.exe /C rd /S /Q "C:\Users\ADRIAN~2\AppData\Local\Temp\nso12C.tmpb" & reg.exe delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v Bomgar_Cleanup_ZD2772204217113 /f <==== ATTENTION
    HKU\S-1-5-21-3709382928-3884936676-3748502351-1000\...\Run: [Bomgar_Cleanup_ZD27742412519685] => cmd.exe /C rd /S /Q "C:\ProgramData\bomgar-scc-0x5b5b4f46" & reg.exe delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v Bomgar_Cleanup_ZD27742412519685 /f <==== ATTENTION
    HKU\S-1-5-21-3709382928-3884936676-3748502351-1000\...\Run: [Bomgar_Cleanup_ZD27863731222411] => cmd.exe /C rd /S /Q "C:\ProgramData\bomgar-scc-0x5b5b4ee1" & reg.exe delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v Bomgar_Cleanup_ZD27863731222411 /f <==== ATTENTION
    HKU\S-1-5-21-3709382928-3884936676-3748502351-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\Mystify.scr [149504 2018-04-12] (Microsoft Corporation)
    Lsa: [Notification Packages] DPPassFilter scecli
    Startup: C:\Users\Adrian Moguel y Anza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk [2018-07-26]
    ShortcutTarget: Send to OneNote.lnk -> C:\Program Files\Microsoft Office 15\root\office15\onenotem.exe (Microsoft Corporation)
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Start Guardian.lnk [2018-07-12]
    ShortcutTarget: Start Guardian.lnk -> C:\tt\Guardian\GuardianStart.exe (Trading Technologies International, Inc.)

    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    Tcpip\Parameters: [DhcpNameServer] 10.0.0.1
    Tcpip\..\Interfaces\{094046fc-81e2-46b8-bf37-2458999904d3}: [NameServer] 8.8.8.8
    Tcpip\..\Interfaces\{094046fc-81e2-46b8-bf37-2458999904d3}: [DhcpNameServer] 172.18.13.1
    Tcpip\..\Interfaces\{19e413c5-f1f9-46f4-b086-3aef81e56e55}: [DhcpNameServer] 172.18.10.1
    Tcpip\..\Interfaces\{2076f695-d283-41e1-b363-5c76b32bb0be}: [DhcpNameServer] 10.0.0.1
    Tcpip\..\Interfaces\{952f2d60-98af-4fbb-9d17-9aceda38dd36}: [DhcpNameServer] 172.18.13.1

    Internet Explorer:
    ==================
    HKU\S-1-5-21-3709382928-3884936676-3748502351-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://lenovo17win10.msn.com/?pc=LCTE
    HKU\S-1-5-21-3709382928-3884936676-3748502351-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://dell13.msn.com/?pc=DCJB
    HKU\S-1-5-21-3709382928-3884936676-3748502351-1000\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://mystart.lenovo.com
    SearchScopes: HKU\S-1-5-21-3709382928-3884936676-3748502351-1000 -> DefaultScope {22841ADF-367B-41D7-B90F-D0B723455C5A} URL =
    SearchScopes: HKU\S-1-5-21-3709382928-3884936676-3748502351-1000 -> {22841ADF-367B-41D7-B90F-D0B723455C5A} URL =
    BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2017-10-24] (Microsoft Corporation)
    BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2017-10-24] (Microsoft Corporation)
    BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\ssv.dll [2017-10-30] (Oracle Corporation)
    BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\jp2ssv.dll [2017-10-30] (Oracle Corporation)
    Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2017-10-24] (Microsoft Corporation)
    Filter-x32: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2018-01-01] (Citrix Systems, Inc.)
    Filter-x32: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2018-01-01] (Citrix Systems, Inc.)
    Filter-x32: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2018-01-01] (Citrix Systems, Inc.)
    Filter-x32: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2018-01-01] (Citrix Systems, Inc.)
    Filter-x32: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2018-01-01] (Citrix Systems, Inc.)
    Filter-x32: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2018-01-01] (Citrix Systems, Inc.)
    Filter-x32: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2018-01-01] (Citrix Systems, Inc.)
    Filter-x32: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2018-01-01] (Citrix Systems, Inc.)
    Filter-x32: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2018-01-01] (Citrix Systems, Inc.)
    Filter-x32: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2018-01-01] (Citrix Systems, Inc.)
    Filter-x32: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2018-01-01] (Citrix Systems, Inc.)
    Filter-x32: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2018-01-01] (Citrix Systems, Inc.)
    Filter-x32: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2018-01-01] (Citrix Systems, Inc.)
    Filter-x32: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2018-01-01] (Citrix Systems, Inc.)
    Filter-x32: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2018-01-01] (Citrix Systems, Inc.)
    Filter-x32: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2018-01-01] (Citrix Systems, Inc.)

    FireFox:
    ========
    FF DefaultProfile: oznmvvqz.default
    FF ProfilePath: C:\Users\Adrian Moguel y Anza\AppData\Roaming\Mozilla\Firefox\Profiles\oznmvvqz.default [2017-08-10]
    FF Extension: (Tab Auto Reload) - C:\Users\Adrian Moguel y Anza\AppData\Roaming\Mozilla\Firefox\Profiles\oznmvvqz.default\Extensions\[email protected] [2017-05-19] [Legacy]
    FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Dell\Dell Data Protection\Security Tools Authentication\Bin\BrowserExt\dpchrome
    FF Extension: (Dell Data Protection | Security Tools) - C:\Program Files (x86)\Dell\Dell Data Protection\Security Tools Authentication\Bin\BrowserExt\dpchrome [2015-10-13] [Legacy] [not signed]
    FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
    FF Plugin-x32: @Citrix.com/npican -> C:\Program Files (x86)\Citrix\ICA Client\npicaN.dll [2018-01-01] (Citrix Systems, Inc.)
    FF Plugin-x32: @java.com/DTPlugin,version=11.151.2 -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\dtplugin\npDeployJava1.dll [2017-10-30] (Oracle Corporation)
    FF Plugin-x32: @java.com/JavaPlugin,version=11.151.2 -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\plugin2\npjp2.dll [2017-10-30] (Oracle Corporation)
    FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2015-07-03] (Microsoft Corporation)
    FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-21] (Google Inc.)
    FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-21] (Google Inc.)
    FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-06-29] (Adobe Systems Inc.)
    FF Plugin-x32: digitalpersona.com/ChromeDPAgent -> C:\Program Files (x86)\Dell\Dell Data Protection\Security Tools Authentication\Bin\BrowserExt\components\npChromeDPAgent.dll [2014-03-17] (DigitalPersona, Inc.)
    FF Plugin HKU\S-1-5-21-3709382928-3884936676-3748502351-1000: @citrixonline.com/appdetectorplugin -> C:\Users\Adrian Moguel y Anza\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2015-02-01] (Citrix Online)
    FF Plugin ProgramFiles/Appdata: C:\Users\Adrian Moguel y Anza\AppData\Roaming\mozilla\plugins\npatgpc.dll [2018-07-05] (Cisco WebEx LLC)

    Chrome:
    =======
    CHR DefaultProfile: Profile 1
    CHR Profile: C:\Users\Adrian Moguel y Anza\AppData\Local\Google\Chrome\User Data\Profile 1 [2018-07-28]
    CHR Extension: (Adobe Acrobat) - C:\Users\Adrian Moguel y Anza\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2018-07-22]
    CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\Adrian Moguel y Anza\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2018-07-22]
    CHR Extension: (Dell Data Protection | Security Tools) - C:\Users\Adrian Moguel y Anza\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ncffjdbbodifgldkcbhmiiljfcnbgjab [2018-07-22]
    CHR Extension: (Chrome Web Store Payments) - C:\Users\Adrian Moguel y Anza\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-07-22]
    CHR Extension: (Smallpdf) - C:\Users\Adrian Moguel y Anza\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ohfgljdgelakfkefopgklcohadegdpjf [2018-07-26]
    CHR Extension: (Chrome Media Router) - C:\Users\Adrian Moguel y Anza\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-07-22]
    CHR Profile: C:\Users\Adrian Moguel y Anza\AppData\Local\Google\Chrome\User Data\System Profile [2018-07-22]
    CHR HKU\S-1-5-21-3709382928-3884936676-3748502351-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [ncffjdbbodifgldkcbhmiiljfcnbgjab] - C:\Program Files (x86)\Dell\Dell Data Protection\Security Tools Authentication\Bin\BrowserExt\dpchrome.crx [2014-03-17]

    ==================== Services (Whitelisted) ====================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    S3 algose_sim; C:\tt\AlgoSE_sim\AlgoSE.exe [5700608 2016-01-29] (Trading Technologies International, Inc.) [File not signed]
    S2 bomgar-scc-5B59B543; C:\ProgramData\bomgar-scc-0x5b59b543\bomgar-scc.exe [9371496 2017-08-27] (Bomgar)
    S2 bomgar-scc-5B59B665; C:\ProgramData\bomgar-scc-0x5b59b665\bomgar-scc.exe [9371496 2017-08-27] (Bomgar)
    R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [3058416 2017-09-05] (Microsoft Corporation)
    R2 DDVCollectorSvcApi; C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe [208792 2018-02-10] (Dell Inc.)
    S2 DDVDataCollector; C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe [3346320 2018-02-10] (Dell Inc.)
    R2 DDVRulesProcessor; C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe [217488 2018-02-10] (Dell Inc.)
    R2 Dell Foundation Services; C:\Program Files\Dell\Dell Foundation Services\DFSSvc.exe [97616 2017-01-11] (Dell)
    R2 Dell Hardware Support; C:\Program Files\Dell\SupportAssistAgent\PCDr\SupportAssist\6.0.6992.1236\DSAPI.exe [935744 2018-07-28] (PC-Doctor, Inc.)
    R2 DpHost; C:\Program Files\Dell\Dell Data Protection\Security Tools\Authentication\Bin\DpHostW.exe [472912 2014-03-19] (DigitalPersona, Inc.)
    R3 guardian; C:\tt\Guardian\guardian.exe [5871616 2018-04-30] (Trading Technologies International, Inc.) [File not signed]
    R2 guardianctrl; C:\tt\Guardian\GuardianCtrl.exe [1272072 2018-04-30] (Trading Technologies International, Inc.)
    S3 guardserver_sim; C:\tt\ttsim\guardserver_sim.exe [6340096 2016-03-07] (Trading Technologies International, Inc.) [File not signed]
    S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [987432 2016-06-14] (Intel(R) Corporation)
    S3 InvProtectSvc; C:\Program Files (x86)\Invincea\Enterprise\X64\InvProtectSvc64.exe [2672328 2014-07-30] (Invincea, Inc.)
    R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [215328 2016-07-18] (Intel Corporation)
    R2 MyEpson Portal Service; C:\Program Files (x86)\EPSON\MyEpson Portal\mepService.exe [714712 2017-06-28] (Seiko Epson Corporation)
    R2 NVWMI; C:\Windows\system32\nvwmi64.exe [2694432 2014-08-04] ()
    R2 poaService; C:\Program Files\Dell\PPO\poaService.exe [721104 2014-08-15] (Dell Inc.)
    R2 PoaSMSrv; C:\Program Files\Dell\PPO\poaSmSrv.exe [312016 2014-08-15] (Dell Inc.)
    R2 poaTaServ; C:\Program Files\Dell\PPO\poaTaServ.exe [645328 2014-08-16] (Dell Inc.)
    R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [308472 2015-08-03] (Realtek Semiconductor)
    S3 SboxSvc; C:\Program Files (x86)\Invincea\Enterprise\Sandbox\SboxSvc.exe [173256 2014-07-30] (Invincea, Inc.)
    S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [4737448 2018-04-12] (Microsoft Corporation)
    S4 ssh-agent; C:\WINDOWS\System32\OpenSSH\ssh-agent.exe [495616 2018-03-10] ()
    R2 SupportAssistAgent; C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [45016 2018-07-08] (Dell Inc.)
    S3 syntheticse_sim; C:\tt\SyntheticSE_sim\SyntheticSE.exe [5676544 2016-01-26] (Trading Technologies International, Inc.) [File not signed]
    R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [7534864 2016-08-25] (TeamViewer GmbH)
    S3 ttkeyserver_sim; C:\tt\ttsim\ttkeyserver.exe [5284352 2012-09-17] (Trading Technologies International, Inc.) [File not signed]
    R3 ttmd; C:\tt\ttm\ttmd.exe [3299328 2018-04-27] (Trading Technologies International, Inc.) [File not signed]
    S3 TTSIM-ZFillServer; C:\tt\ttsim\FillServerSim.exe [7502848 2016-03-07] (Trading Technologies International, Inc.) [File not signed]
    S3 TTSIM-ZOrderServer; C:\tt\ttsim\OrderServer.exe [7847424 2016-03-07] (Trading Technologies International, Inc.) [File not signed]
    S3 TTSIM-ZPriceServer; C:\tt\ttsim\PriceServer.exe [7103488 2016-03-07] (Trading Technologies International, Inc.) [File not signed]
    S3 TTSIM-ZSimulatedExchange; C:\tt\ttsim\SimulatedExchange.exe [7193600 2016-03-07] (Trading Technologies International, Inc.) [File not signed]
    R2 TTSimManager; C:\tt\ttsim\TTSimManager.exe [1956864 2016-03-07] (Trading Technologies International, Inc.) [File not signed]
    R2 TunnelBearMaintenance; C:\Program Files (x86)\TunnelBear\TunnelBear.Maintenance.exe [119680 2018-06-19] ()
    S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1806.18062-0\NisSrv.exe [3925648 2018-06-26] (Microsoft Corporation)
    R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1806.18062-0\MsMpEng.exe [100080 2018-06-26] (Microsoft Corporation)
    S3 guardian_sim; C:\tt\ttsim\Guardian_sim.exe -aconfigpath "C:\tt\config\"
    R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
    S3 TTSIM-ZProductServer; C:\tt\ttsim\ProductServer.exe -e TTSIM-Z -aconfigpath "C:\tt\config\"

    ===================== Drivers (Whitelisted) ======================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R3 DDDriver; C:\WINDOWS\system32\drivers\DDDriver64Dcsa.sys [41608 2018-02-10] (Dell Inc.)
    R3 DellProf; C:\WINDOWS\system32\drivers\DellProf.sys [41208 2018-02-10] (Dell Computer Corporation)
    S3 FLMckUsb; C:\WINDOWS\System32\drivers\ATTchWDF.sys [75264 2013-09-06] (AuthenTec, Inc.)
    S3 iaStorS; C:\WINDOWS\system32\drivers\iaStorS.sys [658928 2014-01-29] (Intel Corporation)
    R3 IntcAzAudAddService; C:\WINDOWS\system32\drivers\RTDVHD64.sys [2558208 2015-08-03] (Realtek Semiconductor Corp.)
    S3 InvProtectDrv; C:\Program Files (x86)\Invincea\Enterprise\X64\InvProtectDrv64.sys [50696 2014-07-30] (Invincea, Inc.)
    R1 MpKslc48f3da5; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{67E2ECBB-D4B5-4B14-8799-E1C58581D7C2}\MpKslc48f3da5.sys [58120 2018-07-28] (Microsoft Corporation)
    R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nv_ref_pubwu.inf_amd64_b7e5dd1387001335\nvlddmkm.sys [16936560 2017-11-09] (NVIDIA Corporation)
    R3 POADrvr; C:\WINDOWS\system32\drivers\POADrvr.sys [21264 2014-08-15] (Dell Computer Corporation)
    S3 SboxDrv; C:\Program Files (x86)\Invincea\Enterprise\Sandbox\SboxDrv.sys [183304 2014-07-30] (Invincea, Inc.)
    R3 tap-tb-0901; C:\WINDOWS\System32\drivers\tap-tb-0901.sys [38656 2015-08-10] (The OpenVPN Project)
    S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [46592 2018-06-26] (Microsoft Corporation)
    R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [340008 2018-06-26] (Microsoft Corporation)
    S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [59944 2018-06-26] (Microsoft Corporation)
    U3 aspnet_state; no ImagePath

    ==================== NetSvcs (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


    ==================== One Month Created files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2018-07-28 14:21 - 2018-07-28 14:22 - 000030611 _____ C:\Users\Adrian Moguel y Anza\Downloads\FRST.txt
    2018-07-28 14:20 - 2018-07-28 14:21 - 000000000 ____D C:\FRST
    2018-07-28 14:19 - 2018-07-28 14:19 - 002412544 _____ (Farbar) C:\Users\Adrian Moguel y Anza\Downloads\FRST64.exe
    2018-07-28 14:03 - 2018-07-28 14:03 - 001605408 _____ (SysTools Software ) C:\Users\Adrian Moguel y Anza\Downloads\access-to-excel.exe
    2018-07-28 14:03 - 2018-07-28 14:03 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SysTools Access to Excel Converter
    2018-07-28 14:03 - 2018-07-28 14:03 - 000000000 ____D C:\Program Files (x86)\SysTools Access to Excel Converter v2.0 DEMO
    2018-07-28 13:27 - 2018-07-28 13:27 - 000002237 _____ C:\Users\Public\Desktop\SupportAssist.lnk
    2018-07-28 13:26 - 2018-07-28 13:26 - 000003914 _____ C:\WINDOWS\System32\Tasks\Dell SupportAssistAgent AutoUpdate
    2018-07-28 13:26 - 2018-07-28 13:26 - 000000000 ____D C:\ProgramData\SupportAssist
    2018-07-28 13:26 - 2018-07-28 13:26 - 000000000 ____D C:\ProgramData\Dell Inc
    2018-07-28 13:25 - 2018-07-28 13:25 - 000305728 _____ (Dell Inc.) C:\Users\Adrian Moguel y Anza\Downloads\SupportAssistLauncher.exe
    2018-07-28 13:21 - 2018-07-28 13:21 - 000020369 _____ C:\Users\Adrian Moguel y Anza\Downloads\Book22 (3).xlsx
    2018-07-28 13:19 - 2018-07-28 13:19 - 000020369 _____ C:\Users\Adrian Moguel y Anza\Downloads\Book22 (2).xlsx
    2018-07-28 13:18 - 2018-07-28 13:18 - 000020369 _____ C:\Users\Adrian Moguel y Anza\Downloads\Book22 (1).xlsx
    2018-07-27 18:20 - 2018-07-27 18:20 - 000004120 _____ C:\WINDOWS\System32\Tasks\Bomgar Task 278637125
    2018-07-27 18:00 - 2018-07-27 18:00 - 000004120 _____ C:\WINDOWS\System32\Tasks\Bomgar Task 277424000
    2018-07-27 17:58 - 2018-07-27 18:00 - 000000000 ____D C:\ProgramData\bomgar-scc-0x5b5b4f46
    2018-07-27 17:57 - 2018-07-27 18:20 - 000000000 ____D C:\ProgramData\bomgar-scc-0x5b5b4ee1
    2018-07-27 17:50 - 2018-07-27 17:50 - 000124076 _____ C:\Users\Adrian Moguel y Anza\Downloads\bookmarks_7_27_18.html
    2018-07-27 17:31 - 2018-07-27 17:31 - 000004726 _____ C:\Users\Adrian Moguel y Anza\Desktop\Orders and Fills Window 2_FillsPane_Book 1_20180727_173108.csv
    2018-07-27 17:30 - 2018-07-27 17:30 - 000004726 _____ C:\Users\Adrian Moguel y Anza\Desktop\Orders and Fills Window 2_FillsPane_Book 1_20180727_173014.csv
    2018-07-27 17:24 - 2018-07-27 17:24 - 000020369 _____ C:\Users\Adrian Moguel y Anza\Downloads\Book22.xlsx
    2018-07-26 14:17 - 2018-07-26 14:17 - 000004120 _____ C:\WINDOWS\System32\Tasks\Bomgar Task 177670859
    2018-07-26 13:14 - 2018-07-26 14:17 - 000000000 ____D C:\ProgramData\bomgar-scc-0x5b59bb2a
    2018-07-26 12:54 - 2018-07-26 13:04 - 000000000 ____D C:\ProgramData\bomgar-scc-0x5b59b665
    2018-07-26 12:49 - 2018-07-26 12:51 - 000000000 ____D C:\ProgramData\bomgar-scc-0x5b59b543
    2018-07-25 22:53 - 2018-07-25 22:53 - 000015853 _____ C:\Users\Adrian Moguel y Anza\Desktop\Fill Window_FillsPane_Fill 1_20180725_215908.xlsx
    2018-07-25 22:00 - 2018-07-25 22:53 - 000006749 _____ C:\Users\Adrian Moguel y Anza\Desktop\Fill Window_FillsPane_Fill 1_20180725_215908.csv
    2018-07-25 15:27 - 2018-07-25 15:27 - 000004118 _____ C:\WINDOWS\System32\Tasks\Bomgar Task 95429015
    2018-07-25 15:23 - 2018-07-25 15:23 - 000015030 _____ C:\Users\Adrian Moguel y Anza\Downloads\SHEARWATER_CL Trader_View_PnL 2018 07 24 (2).xlsx
    2018-07-25 15:22 - 2018-07-25 15:22 - 000015030 _____ C:\Users\Adrian Moguel y Anza\Downloads\SHEARWATER_CL Trader_View_PnL 2018 07 24 (1).xlsx
    2018-07-25 14:50 - 2018-07-25 14:50 - 000015030 _____ C:\Users\Adrian Moguel y Anza\Downloads\SHEARWATER_CL Trader_View_PnL 2018 07 24.xlsx
    2018-07-25 13:58 - 2018-07-25 13:58 - 000004118 _____ C:\WINDOWS\System32\Tasks\Bomgar Task 90130156
    2018-07-25 12:53 - 2018-07-25 12:53 - 003000776 _____ (bomgar) C:\Users\Adrian Moguel y Anza\Downloads\bomgar-scc-w0yc30je5dwd8g85178hfzexgyjy1g5y8h85yic40jc90.exe
    2018-07-25 11:02 - 2018-07-25 11:02 - 000107111 _____ C:\Users\Adrian Moguel y Anza\Downloads\hsk 072418.pdf
    2018-07-25 10:50 - 2018-07-25 10:50 - 005084495 _____ C:\Users\Adrian Moguel y Anza\Downloads\PX_CLUSTER 2 (3).xlsx
    2018-07-25 10:43 - 2018-07-25 10:43 - 000000000 ___HD C:\$SysReset
    2018-07-25 10:37 - 2018-07-25 10:37 - 000008014 _____ C:\Users\Adrian Moguel y Anza\Desktop\test.xlsx
    2018-07-25 10:34 - 2018-07-25 10:34 - 005084495 _____ C:\Users\Adrian Moguel y Anza\Downloads\PX_CLUSTER 2 (2).xlsx
    2018-07-25 10:20 - 2018-07-25 10:20 - 005084495 _____ C:\Users\Adrian Moguel y Anza\Desktop\PX_CLUSTER 2.xlsx
    2018-07-25 10:17 - 2018-07-25 10:17 - 000128874 _____ C:\Users\Adrian Moguel y Anza\Downloads\MASTER_CONTRACTS_48_V10.xlsx
    2018-07-25 10:15 - 2018-07-25 10:15 - 000201149 _____ C:\Users\Adrian Moguel y Anza\Downloads\CASH CLUSTER SB_CASH_PRICES_INDIA_SUGAR_STARCH_5VAR_RAW_DAILY_V.04_LINKED.xlsx
    2018-07-25 10:14 - 2018-07-25 10:14 - 000008349 _____ C:\Users\Adrian Moguel y Anza\Downloads\Book2 (2).xlsx
    2018-07-25 10:13 - 2018-07-25 10:13 - 000008349 _____ C:\Users\Adrian Moguel y Anza\Downloads\Book2.xlsx
    2018-07-25 10:13 - 2018-07-25 10:13 - 000008349 _____ C:\Users\Adrian Moguel y Anza\Downloads\Book2 (1).xlsx
    2018-07-25 10:08 - 2018-07-25 10:08 - 005084495 _____ C:\Users\Adrian Moguel y Anza\Downloads\PX_CLUSTER 2 (1).xlsx
    2018-07-25 09:52 - 2018-07-25 09:52 - 000780537 _____ C:\Users\Adrian Moguel y Anza\Downloads\VOLS_CLUSTER.xlsx
    2018-07-25 09:49 - 2018-07-25 09:50 - 009808469 _____ C:\Users\Adrian Moguel y Anza\Downloads\CFTC_CLUSTER (1).xlsx
    2018-07-25 09:49 - 2018-07-25 09:49 - 009808469 _____ C:\Users\Adrian Moguel y Anza\Downloads\CFTC_CLUSTER.xlsx
    2018-07-25 09:45 - 2018-07-25 09:45 - 000000000 _____ C:\Users\Adrian Moguel y Anza\Downloads\PX_CLUSTER 2.xlsx
    2018-07-25 09:40 - 2018-07-25 09:40 - 005085697 _____ C:\Users\Adrian Moguel y Anza\Downloads\PX_CLUSTER (2).xlsx
    2018-07-25 09:31 - 2018-07-25 09:31 - 005085697 _____ C:\Users\Adrian Moguel y Anza\Downloads\PX_CLUSTER (Autosaved) (2).xlsx
    2018-07-24 23:47 - 2018-07-24 23:47 - 000056295 _____ C:\Users\Adrian Moguel y Anza\Downloads\Gateway_User_ID.pdf
    2018-07-24 23:37 - 2018-07-24 23:37 - 000013268 _____ C:\Users\Adrian Moguel y Anza\Downloads\SHEARWATER_CL Trader_View_PnL 2018 07 23.xlsx
    2018-07-24 16:35 - 2018-07-24 16:35 - 002711389 _____ C:\Users\Adrian Moguel y Anza\Desktop\snip.pdf
    2018-07-24 14:43 - 2018-07-24 14:43 - 000004116 _____ C:\WINDOWS\System32\Tasks\Bomgar Task 6391187
    2018-07-24 12:46 - 2018-07-24 13:53 - 000000000 ____D C:\ProgramData\bomgar-scc-0x5b571198
    2018-07-24 10:16 - 2018-07-24 10:16 - 002713033 _____ C:\Users\Adrian Moguel y Anza\Downloads\Minasul Europe Agency Contract FINAL_PORT.compressed.pdf
    2018-07-24 09:57 - 2018-07-24 09:58 - 009226964 _____ C:\Users\Adrian Moguel y Anza\Downloads\Minasul Europe Agency Contract FINAL_ENG-1.pdf
    2018-07-24 09:40 - 2018-07-24 09:40 - 000130882 _____ C:\Users\Adrian Moguel y Anza\Desktop\Gro Intelligence Adrian Moguel y Anza - Form Mutual NDA.pdf
    2018-07-24 08:58 - 2018-07-24 08:58 - 003905236 _____ C:\Users\Adrian Moguel y Anza\Downloads\PX_CLUSTER (1).xlsx
    2018-07-24 08:25 - 2018-07-24 08:25 - 003905236 _____ C:\Users\Adrian Moguel y Anza\Downloads\PX_CLUSTER.xlsx
    2018-07-24 08:17 - 2018-07-24 08:17 - 006171935 _____ C:\Users\Adrian Moguel y Anza\Downloads\CASH_CLUSTER (1).xlsx
    2018-07-23 09:02 - 2018-07-23 09:02 - 000001825 _____ C:\Users\Adrian Moguel y Anza\Desktop\Google Drive.lnk
    2018-07-21 20:12 - 2018-07-21 20:12 - 001017424 _____ C:\Users\Adrian Moguel y Anza\Downloads\SB_LAST_PX_RAW_DAILY_V.01_LINKED (2).xlsx
    2018-07-21 20:11 - 2018-07-21 20:11 - 001021389 _____ C:\Users\Adrian Moguel y Anza\Downloads\PX CLUSTER SB_LAST_PX_RAW_DAILY_V.04_LINKED.xlsx
    2018-07-21 18:23 - 2018-07-21 18:23 - 000005735 _____ C:\Users\Adrian Moguel y Anza\Downloads\Edgewonk-Excel-import.xlsx
    2018-07-21 17:58 - 2018-07-24 11:00 - 000000000 ____D C:\Edgewonk
    2018-07-21 17:58 - 2018-07-21 17:58 - 000001563 _____ C:\Users\Adrian Moguel y Anza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Edgewonk.lnk
    2018-07-21 17:58 - 2018-07-21 17:58 - 000001533 _____ C:\Users\Adrian Moguel y Anza\Desktop\Edgewonk.lnk
    2018-07-20 17:32 - 2018-07-20 17:32 - 003291516 _____ C:\Users\Adrian Moguel y Anza\Downloads\tt_exchange_products.csv
    2018-07-20 16:19 - 2018-07-20 16:19 - 001882021 _____ C:\Users\Adrian Moguel y Anza\Downloads\CASH_CLUSTER.xlsx
    2018-07-20 15:40 - 2018-07-20 15:40 - 000780537 _____ C:\Users\Adrian Moguel y Anza\Downloads\VOLS_LINKED (2).xlsx
    2018-07-19 12:38 - 2018-07-19 12:38 - 000081352 _____ C:\Users\Adrian Moguel y Anza\Desktop\Originação_Minasul_Europe_v3 (Recuperado).xlsx
    2018-07-18 08:17 - 2018-04-10 21:11 - 002629120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsLexicons0009.dll
    2018-07-18 08:17 - 2018-04-10 21:10 - 005739008 _____ (Microsoft Corporation) C:\WINDOWS\system32\prm0009.dll
    2018-07-18 08:17 - 2018-04-10 21:09 - 002629120 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsLexicons0009.dll
    2018-07-18 08:17 - 2018-04-10 21:06 - 005487616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData0009.dll
    2018-07-18 08:17 - 2018-04-10 21:02 - 006350848 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData0009.dll
    2018-07-16 08:28 - 2018-07-16 08:28 - 000000000 ___HD C:\OneDriveTemp
    2018-07-15 08:52 - 2018-07-15 08:52 - 000193587 _____ C:\Users\Adrian Moguel y Anza\Downloads\BoardingPass (4).pdf
    2018-07-13 14:49 - 2018-07-13 14:49 - 000017415 _____ C:\Users\Adrian Moguel y Anza\Desktop\Originação_Minasul_Europe.xlsx
    2018-07-13 10:27 - 2018-07-13 10:27 - 000043754 _____ C:\Users\Adrian Moguel y Anza\Downloads\output (38).pdf
    2018-07-13 10:27 - 2018-07-13 10:27 - 000043754 _____ C:\Users\Adrian Moguel y Anza\Downloads\Ending in N.pdf
    2018-07-13 10:26 - 2018-07-13 10:26 - 000043745 _____ C:\Users\Adrian Moguel y Anza\Downloads\output (37).pdf
    2018-07-13 10:26 - 2018-07-13 10:26 - 000043745 _____ C:\Users\Adrian Moguel y Anza\Downloads\Ending in X.pdf
    2018-07-13 10:25 - 2018-07-13 10:25 - 000043403 _____ C:\Users\Adrian Moguel y Anza\Downloads\Ending in V.pdf
    2018-07-13 10:24 - 2018-07-13 10:24 - 000043403 _____ C:\Users\Adrian Moguel y Anza\Downloads\output (36).pdf
    2018-07-13 10:21 - 2018-07-13 10:21 - 000103088 _____ C:\Users\Adrian Moguel y Anza\Downloads\0240000049718501V0000_Account_Statement_20180301092626069414.pdf
    2018-07-13 10:20 - 2018-07-13 10:20 - 000109656 _____ C:\Users\Adrian Moguel y Anza\Downloads\0240000049718501V0000_Account_Statement_20180201114153118796.pdf
    2018-07-13 10:20 - 2018-07-13 10:20 - 000102786 _____ C:\Users\Adrian Moguel y Anza\Downloads\0240000049718560X0000_Account_Statement_20180301092437710145.pdf
    2018-07-12 19:23 - 2018-07-12 19:23 - 000001804 _____ C:\Users\Public\Desktop\X_TRADER.lnk
    2018-07-12 18:50 - 2018-06-18 16:35 - 105725440 _____ (Trading Technologies ) C:\Users\Adrian Moguel y Anza\Desktop\X_TRADER_r7.17.84p587 (1).exe
    2018-07-12 18:47 - 2018-07-20 08:21 - 000000000 ____D C:\ProgramData\bomgar-scc-0x5b47941c
    2018-07-12 16:04 - 2018-07-12 16:04 - 000982338 _____ C:\Users\Adrian Moguel y Anza\Downloads\SB_CFTC_62VAR_RAW_DAILY_V.01_LINKED (1).xlsx
    2018-07-12 15:41 - 2018-07-12 15:41 - 009632073 _____ C:\Users\Adrian Moguel y Anza\Downloads\OAM-Filing-Annual-Report-and-Audited-Consolidated-Financial-S-2018-03-21.pdf
    2018-07-12 14:44 - 2018-07-12 14:44 - 002459174 _____ C:\Users\Adrian Moguel y Anza\Downloads\Cockpit_NEW_v2.xlsx
    2018-07-11 14:39 - 2018-07-11 14:39 - 000196592 _____ C:\Users\Adrian Moguel y Anza\Downloads\Master3 (2).xlsx
    2018-07-11 14:39 - 2018-07-11 14:39 - 000196592 _____ C:\Users\Adrian Moguel y Anza\Downloads\Master3 (1).xlsx
    2018-07-11 14:15 - 2018-07-11 14:15 - 000060452 _____ C:\Users\Adrian Moguel y Anza\Downloads\3e4160ae-9bed-44d3-aeef-fe7261fd5f42.tmp
    2018-07-11 14:15 - 2018-07-11 14:15 - 000060452 _____ C:\Users\Adrian Moguel y Anza\Downloads\114833043.pdf
    2018-07-11 11:28 - 2018-07-11 11:28 - 000203096 _____ C:\Users\Adrian Moguel y Anza\Desktop\Doc260.pdf
    2018-07-11 10:57 - 2018-07-11 10:57 - 000364590 _____ C:\Users\Adrian Moguel y Anza\Downloads\QW_VOLS_10_25_40_50_60_75_90_FRONT_MONTH_V.01.xlsx
    2018-07-11 10:51 - 2018-07-11 10:51 - 000270106 _____ C:\Users\Adrian Moguel y Anza\Downloads\SB_BRAZIL_EXPORTS_COUNTRY_VOLUME_VALUE_168VAR_RAW_MONTHLY_V.01_LINKED.xlsx
    2018-07-10 20:46 - 2018-07-10 20:46 - 000442368 _____ C:\Users\Adrian Moguel y Anza\Desktop\Commodity trading enters the age of digitisation _ Financial Times.pdf
    2018-07-10 16:31 - 2018-07-10 16:31 - 001002328 _____ C:\Users\Adrian Moguel y Anza\Downloads\SB_OPEN_INT_RAW_DAILY_V.02_LINKED (2).xlsx
    2018-07-10 16:28 - 2018-07-10 16:29 - 001002328 _____ C:\Users\Adrian Moguel y Anza\Downloads\SB_OPEN_INT_RAW_DAILY_V.02_LINKED (1).xlsx
    2018-07-10 14:38 - 2018-07-10 14:38 - 000274987 _____ C:\Users\Adrian Moguel y Anza\Desktop\Doc259.pdf
    2018-07-10 11:15 - 2018-07-10 11:15 - 000318936 _____ C:\Users\Adrian Moguel y Anza\Downloads\SB_CASH_PRICES_BRAZIL_ESALQ_ETHANOL_14VAR_RAW_DAILY_V.01_LINKED.xlsx
    2018-07-10 09:39 - 2018-07-10 09:39 - 003842784 _____ (Interactive Brokers LLC) C:\Users\Adrian Moguel y Anza\Downloads\tws-stable-windows-x64 (5).exe
    2018-07-10 09:39 - 2018-07-10 09:39 - 000001441 _____ C:\Users\Adrian Moguel y Anza\Desktop\Trader Workstation.lnk
    2018-07-10 09:39 - 2018-07-10 09:39 - 000000000 ____D C:\Users\Adrian Moguel y Anza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Trader Workstation
    2018-07-09 19:19 - 2018-07-09 19:19 - 000188416 _____ C:\Users\Adrian Moguel y Anza\Desktop\Larry Williams Trading Lessons.pdf
    2018-07-09 18:09 - 2018-07-09 18:09 - 000132866 _____ C:\Users\Adrian Moguel y Anza\Downloads\Master3.xlsx
    2018-07-09 12:43 - 2018-07-09 12:43 - 001309609 _____ C:\Users\Adrian Moguel y Anza\Downloads\WIP QW_SPREADS_H1_K1_N1_V1_PLUS_PERMUTATIONS_V.01.xlsx
    2018-07-09 12:35 - 2018-07-09 12:35 - 000024299 _____ C:\Users\Adrian Moguel y Anza\Downloads\WIP_SB_GREEKS_V.01.xlsx
    2018-07-09 12:28 - 2018-07-09 12:28 - 000561899 _____ C:\Users\Adrian Moguel y Anza\Downloads\SB_VOLUME_RAW_DAILY_V.02_LINKED (1).xlsx
    2018-07-09 12:27 - 2018-07-09 12:27 - 000561899 _____ C:\Users\Adrian Moguel y Anza\Downloads\SB_VOLUME_RAW_DAILY_V.02_LINKED.xlsx
    2018-07-09 12:24 - 2018-07-09 12:24 - 000385299 _____ C:\Users\Adrian Moguel y Anza\Downloads\SB_VOLS_10_25_40_50_60_75_90_FRONT_MONTH_V.01.xlsx
    2018-07-09 12:07 - 2018-07-09 12:07 - 001150963 _____ C:\Users\Adrian Moguel y Anza\Downloads\SB_SPREADS_H1_K1_N1_V1_PLUS_PERMUTATIONS_V.01.xlsx
    2018-07-09 12:04 - 2018-07-09 12:04 - 000984591 _____ C:\Users\Adrian Moguel y Anza\Downloads\SB_OPEN_INT_RAW_DAILY_V.02_LINKED.xlsx
    2018-07-09 12:01 - 2018-07-09 12:01 - 001017462 _____ C:\Users\Adrian Moguel y Anza\Downloads\SB_LAST_PX_RAW_DAILY_V.01_LINKED (1).xlsx
    2018-07-09 11:56 - 2018-07-09 11:56 - 000982338 _____ C:\Users\Adrian Moguel y Anza\Downloads\SB_CFTC_62VAR_RAW_DAILY_V.01_LINKED.xlsx
    2018-07-09 11:26 - 2018-07-28 13:32 - 000183402 _____ C:\Users\Adrian Moguel y Anza\Desktop\Doc1.pdf
    2018-07-05 19:57 - 2018-07-05 19:57 - 000037891 _____ C:\Users\Adrian Moguel y Anza\Documents\algotest1.algo
    2018-07-05 19:00 - 2018-07-05 19:00 - 000000000 ____D C:\Users\Adrian Moguel y Anza\AppData\Roaming\webex
    2018-07-05 18:59 - 2018-07-05 20:14 - 000000000 ____D C:\Users\Adrian Moguel y Anza\AppData\LocalLow\WebEx
    2018-07-05 18:59 - 2018-07-05 19:00 - 000000000 ____D C:\Users\Adrian Moguel y Anza\AppData\Local\WebEx
    2018-07-05 18:59 - 2018-07-05 19:00 - 000000000 ____D C:\ProgramData\WebEx
    2018-07-05 18:59 - 2018-07-05 18:59 - 001037704 _____ (Cisco WebEx LLC) C:\Users\Adrian Moguel y Anza\Downloads\Cisco_WebEx_Add-On.exe
    2018-07-05 18:04 - 2018-07-12 19:23 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trading Technologies
    2018-07-05 18:04 - 2018-07-12 19:18 - 000001747 _____ C:\Users\Public\Desktop\Start Guardian.lnk
    2018-07-05 18:04 - 2018-07-12 19:18 - 000001742 _____ C:\Users\Public\Desktop\Stop Guardian.lnk
    2018-07-05 18:04 - 2018-07-05 18:51 - 000000000 ____D C:\tt
    2018-07-05 18:04 - 2018-07-05 18:51 - 000000000 ____D C:\ProgramData\Trading Technologies
    2018-07-05 09:19 - 2018-07-05 09:19 - 000177178 _____ C:\Users\Adrian Moguel y Anza\Downloads\certificate (2).pdf
    2018-07-05 09:18 - 2018-07-05 09:18 - 000177178 _____ C:\Users\Adrian Moguel y Anza\Downloads\certificate (1).pdf
    2018-07-04 10:21 - 2018-07-04 10:21 - 000998255 _____ C:\Users\Adrian Moguel y Anza\Desktop\LNL ACQUISITION INDEX (CT1).pptx
    2018-07-03 19:03 - 2018-07-03 19:24 - 001022570 _____ C:\Users\Adrian Moguel y Anza\Desktop\LW LNL (CT1).pdf
    2018-07-02 11:04 - 2018-07-02 11:04 - 000000733 _____ C:\Users\Public\Desktop\Bloomberg.lnk
    2018-07-02 11:00 - 2018-07-02 11:04 - 000000000 ___HD C:\ProgramData\{9ABB0713-4F82-417A-8D8E-3F8FAEF338CF}
    2018-07-02 11:00 - 2018-07-02 11:00 - 000000000 ____D C:\Users\Adrian Moguel y Anza\AppData\Local\IIIQF
    2018-06-28 11:56 - 2018-06-28 11:56 - 000175437 _____ C:\Users\Adrian Moguel y Anza\Downloads\Patrick Neil Morgan 957159_95019434 (1).pdf
    2018-06-28 11:38 - 2018-06-28 11:38 - 000175437 _____ C:\Users\Adrian Moguel y Anza\Downloads\Patrick Neil Morgan 957159_95019434.pdf

    ==================== One Month Modified files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2018-07-28 14:03 - 2015-02-01 13:43 - 000000000 ____D C:\Users\Adrian Moguel y Anza\AppData\Local\VirtualStore
    2018-07-28 13:58 - 2015-02-01 14:10 - 000000000 ____D C:\ProgramData\PCDr
    2018-07-28 13:38 - 2018-04-12 00:38 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
    2018-07-28 13:37 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\AppReadiness
    2018-07-28 13:27 - 2018-06-20 17:54 - 000000000 ____D C:\ProgramData\Packages
    2018-07-28 13:27 - 2018-04-12 00:38 - 000000000 ___HD C:\Program Files\WindowsApps
    2018-07-28 13:27 - 2018-04-12 00:36 - 000000000 ____D C:\WINDOWS\INF
    2018-07-28 13:27 - 2017-12-04 23:41 - 000000000 ____D C:\Users\Adrian Moguel y Anza\AppData\Local\Packages
    2018-07-28 13:27 - 2015-01-12 21:55 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell
    2018-07-28 13:26 - 2015-07-13 09:18 - 000000000 __HDC C:\ProgramData\~0
    2018-07-28 13:26 - 2015-01-12 22:00 - 000000000 ____D C:\Program Files (x86)\Dell
    2018-07-28 13:26 - 2015-01-12 21:55 - 000000000 ____D C:\Program Files\Dell
    2018-07-28 13:03 - 2018-05-21 22:35 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
    2018-07-27 20:39 - 2015-02-01 22:05 - 000000000 ____D C:\Users\Adrian Moguel y Anza\AppData\Local\Bloomberg
    2018-07-27 19:28 - 2017-03-01 12:49 - 000000000 ____D C:\Users\Adrian Moguel y Anza\AppData\Roaming\WhatsApp
    2018-07-27 19:26 - 2018-05-21 23:04 - 000004192 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{7791E7B9-0765-4671-A9C4-BC4476FDFE5E}
    2018-07-27 19:19 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\system32\NDF
    2018-07-26 20:10 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\system32\FxsTmp
    2018-07-26 13:07 - 2017-07-27 23:43 - 000000000 ____D C:\ProgramData\NVIDIA
    2018-07-24 14:33 - 2018-05-16 10:55 - 000000000 ___SD C:\Users\Adrian Moguel y Anza\Documents\My Data Sources
    2018-07-24 13:02 - 2018-05-21 22:40 - 000884150 _____ C:\WINDOWS\system32\PerfStringBackup.INI
    2018-07-24 12:57 - 2018-06-25 17:04 - 000000000 ____D C:\Program Files (x86)\TunnelBear
    2018-07-24 12:57 - 2018-05-21 23:04 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
    2018-07-24 12:55 - 2018-04-11 22:04 - 000524288 _____ C:\WINDOWS\system32\config\BBI
    2018-07-24 10:23 - 2018-04-30 11:29 - 000000000 ____D C:\Users\Adrian Moguel y Anza\Desktop\Minasul Europe
    2018-07-23 09:03 - 2016-11-19 11:49 - 000000000 ___RD C:\Users\Adrian Moguel y Anza\Google Drive
    2018-07-20 08:23 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\LiveKernelReports
    2018-07-19 16:55 - 2015-02-01 15:37 - 000000000 ___RD C:\Users\Adrian Moguel y Anza\OneDrive
    2018-07-18 08:23 - 2018-04-12 00:30 - 000000000 ____D C:\WINDOWS\CbsTemp
    2018-07-18 08:17 - 2018-04-12 10:19 - 000000000 ____D C:\WINDOWS\OCR
    2018-07-17 10:54 - 2010-11-21 04:27 - 000563832 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
    2018-07-13 19:51 - 2018-05-22 09:28 - 000002382 _____ C:\Users\Adrian Moguel y Anza\Desktop\WhatsApp.lnk
    2018-07-13 19:51 - 2018-05-22 09:27 - 000000000 ____D C:\Users\Adrian Moguel y Anza\AppData\Local\WhatsApp
    2018-07-13 19:51 - 2017-03-01 12:49 - 000000000 ____D C:\Users\Adrian Moguel y Anza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WhatsApp
    2018-07-13 19:50 - 2017-03-01 12:49 - 000000000 ____D C:\Users\Adrian Moguel y Anza\AppData\Local\SquirrelTemp
    2018-07-13 10:03 - 2018-05-21 23:04 - 000004562 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
    2018-07-13 10:03 - 2017-02-21 17:56 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
    2018-07-12 19:16 - 2018-05-28 09:25 - 000000000 ____D C:\Users\Adrian Moguel y Anza\AppData\Local\D3DSCache
    2018-07-12 18:58 - 2018-03-26 10:05 - 000000000 ____D C:\Users\Adrian Moguel y Anza\Desktop\LDC Sugar
    2018-07-10 09:57 - 2015-02-01 18:56 - 000000000 ____D C:\Jts
    2018-07-10 08:57 - 2018-05-21 23:04 - 000003402 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3709382928-3884936676-3748502351-1000
    2018-07-10 08:57 - 2018-05-21 22:41 - 000002458 _____ C:\Users\Adrian Moguel y Anza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
    2018-07-05 18:59 - 2017-05-19 11:53 - 000000000 ____D C:\Users\Adrian Moguel y Anza\AppData\Roaming\Mozilla
    2018-07-02 11:08 - 2016-05-06 10:28 - 000000000 ____D C:\Program Files (x86)\TeamViewer
    2018-07-02 11:01 - 2018-02-05 13:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bloomberg

    Some files in TEMP:
    ====================
    2018-07-26 15:09 - 2018-07-13 18:08 - 007243264 _____ () C:\Users\Adrian Moguel y Anza\AppData\Local\Temp\bbxlinst_32.dll
    2018-07-26 15:10 - 2015-09-04 17:56 - 000413696 _____ (Bloomberg L.P.) C:\Users\Adrian Moguel y Anza\AppData\Local\Temp\fldfind.dll

    ==================== Bamital & volsnap ======================

    (There is no automatic fix for files that do not pass verification.)

    C:\WINDOWS\system32\winlogon.exe => File is digitally signed
    C:\WINDOWS\system32\wininit.exe => File is digitally signed
    C:\WINDOWS\explorer.exe => File is digitally signed
    C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
    C:\WINDOWS\system32\svchost.exe => File is digitally signed
    C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
    C:\WINDOWS\system32\services.exe => File is digitally signed
    C:\WINDOWS\system32\User32.dll => File is digitally signed
    C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
    C:\WINDOWS\system32\userinit.exe => File is digitally signed
    C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
    C:\WINDOWS\system32\rpcss.dll => File is digitally signed
    C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
    C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
    C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

    LastRegBack: 2018-05-21 22:35

    ==================== End of FRST.txt ============================
     

    Attached Files:

  10. dvk01

    dvk01 Moderator Malware Specialist

    Joined:
    Dec 14, 2002
    Messages:
    56,371
    First Name:
    Derek
    I can't see anything obviously wrong
    Do any of the xls files or word docs that you have downloaded open ?

    pick any one of them & right click the icon, Don't open the file. Select properties then at the bottom select unblock, press apply & OK
    Then try to open that document or xls sheet

    If that doesn't work, temporarily turn off protected mopde as shown here
    https://www.laptopmag.com/articles/disable-protected-view-microsoft-wor

    However that does leave you at a very high risk of a dangerous office doc delivering a virus to the computer
     
  11. durhamcoffee

    durhamcoffee Thread Starter

    Joined:
    Jul 25, 2018
    Messages:
    13
    Your first suggestion works : )
    One more time, thank you very much.
     
  12. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/1213657

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice