This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

File Explorer Stopped Working

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I don't know if it's a virus. This weekend my File Explorer stopped working. I can't get into any of my files. Everything else is working perfectly normally, ie: internet, web pages, email, etc. But I cannot open any files or control panel or This PC. I've done some troubleshooting on my own but no luck. I don't know if it's a virus but I guess if I can get pointed in the right direction…that would be helpful. I am also having issues with attaching files. 

 

FRST LOG: 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 22-11-2020 01
Ran by [removed] (administrator) on DESKTOPCYBERPOW (Micro-Star International Co., Ltd. MS-7B48) (24-11-2020 15:23:48)
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows 10 Home Version 2004 19041.630 (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
() [File not signed] C:\Users\Karri Tougas\AppData\Local\RingCentral\SoftPhoneApp\tools\SoftphoneCrashMonitor.exe
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Dropbox, Inc -> Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe <3>
(Dropbox, Inc -> Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
(Dropbox, Inc -> Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
(Dropbox, Inc -> The Qt Company Ltd.) C:\Program Files (x86)\Dropbox\Client\110.4.458\QtWebEngineProcess.exe <4>
(Electronic Arts, Inc. -> Electronic Arts) C:\Program Files (x86)\Origin\OriginWebHelperService.exe
(GN AUDIO A/S -> GN Audio A/S) C:\Program Files (x86)\Jabra\Direct4\jabra-direct.exe <4>
(GN AUDIO A/S -> GN Audio A/S) C:\Program Files (x86)\Jabra\Direct4\SoftphoneIntegrations.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <53>
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.32\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.32\GoogleCrashHandler64.exe
(Hewlett Packard -> HP Inc.) C:\Program Files\HP\HP ENVY 5540 series\Bin\HPNetworkCommunicatorCom.exe
(Hewlett Packard -> HP Inc.) C:\Program Files\HP\HP ENVY 5540 series\Bin\ScanToPCActivationApp.exe
(ICEpower a/s -> ICEpower) C:\Windows\System32\ICEsoundService64.exe
(Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_ffc75848a6342fdf\jhi_service.exe
(Intel(R) Wireless Connectivity Solutions -> Intel Corporation) C:\Windows\System32\ibtsiva.exe
(Ivaylo Beltchev -> IvoSoft) [File not signed] C:\Program Files\Classic Shell\ClassicStartMenu.exe
(Logitech Inc -> ) C:\Program Files\Logitech\Collaboration\Services\Video\RightSightAPI\crashpad_handler.exe
(Logitech Inc -> Logitech Europe S.A.) C:\Program Files\Logitech\Collaboration\Services\Video\RightSightAPI\RightSightService.exe
(Logitech Inc -> Logitech) C:\Program Files\Logitech\Collaboration\Services\Video\ServiceLayer.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\Karri Tougas\AppData\Local\Microsoft\OneDrive\OneDrive.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\Karri Tougas\AppData\Local\Microsoft\Teams\current\Teams.exe <9>
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_2.2011.11613.0_x64__8wekyb3d8bbwe\Cortana.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.2009.4.0_x64__8wekyb3d8bbwe\Calculator.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_12011.1001.1.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\Speech_OneCore\common\SpeechRuntime.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(NVIDIA Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe <2>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <3>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe <3>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\RtkAudUService64.exe <2>
(RingCentral, Inc. -> RingCentral) C:\Users\Karri Tougas\AppData\Local\RingCentral\SoftPhoneApp\Softphone.exe
(RingCentral, Inc. -> RingCentral) C:\Users\Karri Tougas\AppData\Local\RingCentral\SoftPhoneApp\SPBridge.exe <3>
(RingCentral, Inc. -> RingCentral) C:\Users\Karri Tougas\AppData\Local\RingCentral\SoftPhoneApp\x64\SPBridge.exe
(Skype Software Sarl -> Skype Technologies S.A.) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe <6>
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
(The Qt Company Oy -> The Qt Company Ltd.) C:\Users\Karri Tougas\AppData\Local\RingCentral\SoftPhoneApp\QtWebEngineProcess.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe <7>
(Valve -> Valve Corporation) C:\Program Files (x86)\Steam\steam.exe
 
==================== Registry (Whitelisted) ===================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [163640 2018-07-15] (Ivaylo Beltchev -> IvoSoft) [File not signed]
HKLM\…\Run: [RtkAudUService] => C:\WINDOWS\System32\RtkAudUService64.exe [1138416 2020-07-23] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\…\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [3942864 2016-10-13] (Logitech -> Logitech, Inc.)
HKLM-x32\…\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [7992832 2020-11-16] (Dropbox, Inc -> Dropbox, Inc.)
HKLM-x32\…\Run: [Jabra Direct] => C:\Program Files (x86)\Jabra\Direct4\jabra-direct.exe [106801096 2020-11-13] (GN AUDIO A/S -> GN Audio A/S)
HKU\S-1-5-19\…\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518656 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-20\…\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518656 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-21-4234547216-3201928491-692415617-1003\…\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3424032 2020-10-28] (Valve -> Valve Corporation)
HKU\S-1-5-21-4234547216-3201928491-692415617-1003\…\Run: [RingCentral for Windows] => C:\Users\Karri Tougas\AppData\Local\RingCentral\SoftPhoneApp\Softphone.exe [60975688 2020-08-15] (RingCentral, Inc. -> RingCentral)
HKU\S-1-5-21-4234547216-3201928491-692415617-1003\…\Run: [Skype for Desktop] => C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe [90952552 2020-11-12] (Skype Software Sarl -> Skype Technologies S.A.)
HKU\S-1-5-21-4234547216-3201928491-692415617-1003\…\Run: [com.squirrel.Teams.Teams] => C:\Users\Karri Tougas\AppData\Local\Microsoft\Teams\Update.exe [2453688 2020-11-21] (Microsoft 3rd Party Application Component -> Microsoft Corporation)
HKU\S-1-5-21-4234547216-3201928491-692415617-1003\…\Run: [HP ENVY 5540 series (NET)] => C:\Program Files\HP\HP ENVY 5540 series\Bin\ScanToPCActivationApp.exe [3770504 2017-03-27] (Hewlett Packard -> HP Inc.)
HKU\S-1-5-21-4234547216-3201928491-692415617-1003\…\Run: [4D74776287CB71EC101D66D76040C72C504D4DAD._service_run] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" –type=service /prefetch:8
HKLM\…\Print\Monitors\HP CE11 Status Monitor: C:\Windows\system32\hpinkstsCE11LM.dll [393352 2017-03-19] (Hewlett Packard -> HP Inc.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\86.0.4240.198\Installer\chrmstp.exe [2020-11-16] (Google LLC -> Google LLC)
 
==================== Scheduled Tasks (Whitelisted) ============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {017A8EF8-51A7-427B-B745-52FEEF2EF75C} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [914456 2019-12-08] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {02C54118-5230-40A5-B248-FE84DE35909B} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2019-07-26] (Dropbox, Inc -> Dropbox, Inc.)
Task: {0B73E088-1B7E-4A3F-98F0-F5BE98E207C8} - System32\Tasks\DropboxUpdateTaskMachineCore1d5d65018d673f8 => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2019-07-26] (Dropbox, Inc -> Dropbox, Inc.)
Task: {0F38EDBF-CF83-4138-B801-AFBC78D93DC8} - System32\Tasks\GoogleUpdateTaskMachineUA1d57d5d435db4c => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154920 2019-07-16] (Google Inc -> Google LLC)
Task: {17137A16-AB03-4A99-9538-6FD638DD2E25} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23054728 2020-11-20] (Microsoft Corporation -> Microsoft Corporation)
Task: {2866139F-D259-4723-9F2C-FD817DB00892} - System32\Tasks\GoogleUpdateTaskMachineCore1d57d5d4331236 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154920 2019-07-16] (Google Inc -> Google LLC)
Task: {33295DD3-58A2-46E6-A580-4F13C9457597} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1341008 2020-09-06] (Adobe Inc. -> Adobe Inc.)
Task: {3EF43EE3-9D9C-4C08-89E5-AD0AC48FD547} - System32\Tasks\Driver Easy Scheduled Scan => C:\Program Files\Easeware\DriverEasy\DriverEasy.exe [3617760 2019-07-05] (Easeware Technology Limited -> Easeware)
Task: {4580D378-4803-4DB2-99A6-78D88D4DB254} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1134104 2019-12-08] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {47386F77-8E5D-433B-B465-C10004C23D68} - System32\Tasks\HPCustParticipation HP ENVY 5540 series => C:\Program Files\HP\HP ENVY 5540 series\Bin\HPCustPartic.exe [6438536 2017-03-27] (Hewlett Packard -> HP Inc.)
Task: {4C559B69-1488-47C1-B196-81AAB4DBFCE1} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154920 2019-07-16] (Google Inc -> Google LLC)
Task: {54488EE2-B7B8-4113-ADC6-79319B67CC14} - System32\Tasks\Agent Activation Runtime\S-1-5-21-4234547216-3201928491-692415617-1003 => C:\WINDOWS\System32\AgentActivationRuntimeStarter.exe [13312 2020-10-15] (Microsoft Windows -> )
Task: {54F26ACD-0479-4B7C-B97D-81A5EF26A25D} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1134104 2019-12-08] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {57A4D65E-4DCB-49A4-BAED-59B0BE0B15D4} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [5142960 2020-11-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {57FB2761-1DA9-4E61-BF9C-6DB32304BC3F} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [858480 2019-12-05] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
Task: {6820C2F5-30CE-4C99-9B16-D04F20435A48} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1134104 2019-12-08] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {76BE5A57-8F41-41F1-BD80-984273B3079D} - System32\Tasks\G2MUploadTask-S-1-5-21-4234547216-3201928491-692415617-1003 => C:\Users\Karri Tougas\AppData\Local\GoToMeeting\18962\g2mupload.exe [31320 2020-10-22] (LogMeIn, Inc. -> LogMeIn, Inc.)
Task: {7AE39871-EFE2-4681-835E-C61655CEADA6} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [670928 2020-11-23] (Mozilla Corporation -> Mozilla Foundation)
Task: {825CA1FC-83AE-4821-84B2-E9BBE66E4337} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2019-07-26] (Dropbox, Inc -> Dropbox, Inc.)
Task: {83D1B060-1307-4308-8227-9D73B53D6EC2} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [143720 2020-11-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {86EBD685-A912-4A32-B7A7-1DB08EF5C033} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [914456 2019-12-08] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {8F0FED20-912F-4525-ABA0-4644C45A5AFF} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23054728 2020-11-20] (Microsoft Corporation -> Microsoft Corporation)
Task: {A1FEB0E4-9823-435F-88C3-35B6FCEC5746} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16\OLicenseHeartbeat.exe [1532312 2020-11-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {A7D0268B-A41F-4FD2-9D5C-CBB5027F2CBD} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [858480 2019-12-05] (NVIDIA Corporation -> NVIDIA Corporation) -> -d "C:\Program Files\NVIDIA Corporation\NvBackend\NvBatteryBoostCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerBatteryBoostCheck.log
Task: {BC69A57A-9D80-4BE2-9665-7B7D9244F542} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1134104 2019-12-08] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {BE589104-14DF-413D-875A-7384FB517915} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154920 2019-07-16] (Google Inc -> Google LLC)
Task: {CF56F9CD-B185-4431-B35C-4C4041C54501} - System32\Tasks\DropboxUpdateTaskMachineUA1d5d65018e2f04f => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2019-07-26] (Dropbox, Inc -> Dropbox, Inc.)
Task: {D384533A-5174-41B2-BEB2-745DAFBC2549} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [653848 2019-12-08] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {DBA47133-4DD3-4D87-97BB-688F483F487B} - System32\Tasks\Intel PTT EK Recertification => C:\WINDOWS\System32\DriverStore\FileRepository\iclsclient.inf_amd64_75ffca5eec865b4b\lib\IntelPTTEKRecertification.exe [918288 2020-04-22] (Intel(R) Trust Services -> Intel(R) Corporation)
Task: {E556EDC9-BB88-400B-B6CF-D2921339E623} - System32\Tasks\G2MUpdateTask-S-1-5-21-4234547216-3201928491-692415617-1003 => C:\Users\Karri Tougas\AppData\Local\GoToMeeting\18962\g2mupdate.exe [31320 2020-10-22] (LogMeIn, Inc. -> LogMeIn, Inc.)
Task: {ED2E5250-AB3A-4E60-A31B-C395AA79ED32} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [5142960 2020-11-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {F1A87213-ABEA-4837-98DC-9CCBA94B9921} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [143720 2020-11-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {F4DE8CFC-897D-4666-B3C2-0DB0D6E3641C} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3302880 2019-12-08] (NVIDIA Corporation -> NVIDIA Corporation)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\WINDOWS\Tasks\Driver Easy Scheduled Scan.job => C:\Program Files\Easeware\DriverEasy\DriverEasy.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore1d5d65018d673f8.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA1d5d65018e2f04f.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-4234547216-3201928491-692415617-1003.job => C:\Users\Karri Tougas\AppData\Local\GoToMeeting\18962\g2mupdate.exe
Task: C:\WINDOWS\Tasks\G2MUploadTask-S-1-5-21-4234547216-3201928491-692415617-1003.job => C:\Users\Karri Tougas\AppData\Local\GoToMeeting\18962\g2mupload.exe
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 192.168.10.1
Tcpip\..\Interfaces\{17e5cf7f-d79a-4aea-ae93-043bbc1bd2fe}: [DhcpNameServer] 192.168.10.1
Tcpip\..\Interfaces\{1a57a767-e721-45a4-9aa4-f3258472f7de}: [DhcpNameServer] 192.168.10.1
 
Edge: 
======
DownloadDir: C:\Users\Karri Tougas\Downloads
Edge DefaultProfile: Default
Edge Profile: C:\Users\Karri Tougas\AppData\Local\Microsoft\Edge\User Data\Default [2020-11-24]
Edge DownloadDir: C:\Users\Karri Tougas\Downloads
Edge HomePage: Default -> hxxp://oem17win10.msn.com/?pc=NMTE
 
FireFox:
========
FF DefaultProfile: 29kt751l.default
FF ProfilePath: C:\Users\Karri Tougas\AppData\Roaming\Mozilla\Firefox\Profiles\29kt751l.default [2019-07-16]
FF ProfilePath: C:\Users\Karri Tougas\AppData\Roaming\Mozilla\Firefox\Profiles\cf955pwt.default-release [2020-11-24]
FF DownloadDir: C:\Users\Karri Tougas\Desktop
FF Session Restore: Mozilla\Firefox\Profiles\cf955pwt.default-release -> is enabled.
FF Extension: (Adblock Plus - free ad blocker) - C:\Users\Karri Tougas\AppData\Roaming\Mozilla\Firefox\Profiles\cf955pwt.default-release\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2020-11-18]
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2020-08-17] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=3.0.10 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.11 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.7.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2020-06-04] (VideoLAN -> VideoLAN)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2020-08-12] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2020-08-17] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2020-10-22] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-4234547216-3201928491-692415617-1003: @zoom.us/ZoomVideoPlugin -> C:\Users\Karri Tougas\AppData\Roaming\Zoom\bin\npzoomplugin.dll [2020-05-23] (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
 
Chrome: 
=======
CHR Profile: C:\Users\Karri Tougas\AppData\Local\Google\Chrome\User Data\Default [2020-11-24]
CHR DownloadDir: C:\Users\Karri Tougas\Desktop
CHR Notifications: Default -> hxxps://meet.google.com; hxxps://psychologymatters.securevideo.com; hxxps://www.facebook.com
CHR Session Restore: Default -> is enabled.
CHR Extension: (Slides) - C:\Users\Karri Tougas\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2019-07-16]
CHR Extension: (Docs) - C:\Users\Karri Tougas\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2019-07-16]
CHR Extension: (Google Drive) - C:\Users\Karri Tougas\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-10-25]
CHR Extension: (YouTube) - C:\Users\Karri Tougas\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2019-07-16]
CHR Extension: (Honey) - C:\Users\Karri Tougas\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmnlcjabgnpnenekpadlanbbkooimhnj [2020-11-17]
CHR Extension: (Sheets) - C:\Users\Karri Tougas\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2019-07-16]
CHR Extension: (Google Docs Offline) - C:\Users\Karri Tougas\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-11-17]
CHR Extension: (AdBlock — best ad blocker) - C:\Users\Karri Tougas\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2020-11-20]
CHR Extension: (hxxps://www.stitcher.com/podcast/erm-premium/) - C:\Users\Karri Tougas\AppData\Local\Google\Chrome\User Data\Default\Extensions\hamhohchodlolkhmgkppomppcdldgnee [2020-04-10]
CHR Extension: (LastPass: Free Password Manager) - C:\Users\Karri Tougas\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd [2020-11-23]
CHR Extension: (F.B.(FluffBusting)Purity) - C:\Users\Karri Tougas\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmkinhboiljjkhaknpaeaicmdjhagpep [2020-11-20]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Karri Tougas\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-06]
CHR Extension: (Gmail) - C:\Users\Karri Tougas\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-10-23]
CHR Extension: (Chrome Media Router) - C:\Users\Karri Tougas\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-10-08]
 
==================== Services (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [169544 2020-09-06] (Adobe Inc. -> Adobe Inc.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [9105800 2020-11-20] (Microsoft Corporation -> Microsoft Corporation)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2019-07-26] (Dropbox, Inc -> Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2019-07-26] (Dropbox, Inc -> Dropbox, Inc.)
R2 DbxSvc; C:\WINDOWS\system32\DbxSvc.exe [44552 2020-11-16] (Dropbox, Inc -> Dropbox, Inc.)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [7269976 2020-11-24] (Malwarebytes Inc -> Malwarebytes)
R2 nebula; C:\Program Files\Logitech\Collaboration\Services\Video\ServiceLayer.exe [4489352 2019-06-12] (Logitech Inc -> Logitech)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2329904 2019-08-23] (Electronic Arts, Inc. -> Electronic Arts)
R2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [3204912 2019-08-23] (Electronic Arts, Inc. -> Electronic Arts)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [13273104 2020-10-22] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2010.7-0\NisSrv.exe [2467088 2020-11-06] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2010.7-0\MsMpEng.exe [128376 2020-11-06] (Microsoft Windows Publisher -> Microsoft Corporation)
 
===================== Drivers (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [153312 2020-11-24] (Malwarebytes Corporation -> Malwarebytes)
S3 JabraDFU; C:\WINDOWS\System32\Drivers\JabraBcDfuX64.sys [54408 2018-03-20] (GN Netcom A/S -> QTI Ltd)
R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [220160 2020-11-24] (Malwarebytes Inc -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [19912 2020-11-24] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\System32\DRIVERS\farflt.sys [197792 2020-11-24] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\system32\DRIVERS\mbam.sys [77496 2020-11-24] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [248968 2020-11-24] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [138904 2020-11-24] (Malwarebytes Inc -> Malwarebytes)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [166760 2019-09-26] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [48536 2020-11-06] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WDC_SAM; C:\WINDOWS\System32\drivers\wdcsam64.sys [35584 2018-02-26] (WDKTestCert wdclab,130885612892544312 -> Western Digital Technologies, Inc.)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [429288 2020-11-06] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [71912 2020-11-06] (Microsoft Windows -> Microsoft Corporation)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One month (created) (Whitelisted) =========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2020-11-24 15:23 - 2020-11-24 15:24 - 000027707 _____ C:\Users\Karri Tougas\Desktop\FRST.txt
2020-11-24 15:22 - 2020-11-24 15:24 - 000000000 ____D C:\FRST
2020-11-24 15:20 - 2020-11-24 15:20 - 002295808 _____ (Farbar) C:\Users\Karri Tougas\Desktop\FRST64.exe
2020-11-24 15:04 - 2020-11-24 15:04 - 000197792 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
2020-11-24 15:04 - 2020-11-24 15:04 - 000138904 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2020-11-24 15:04 - 2020-11-24 15:04 - 000077496 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2020-11-24 15:03 - 2020-11-24 15:03 - 002649120 _____ (Kaspersky) C:\Users\Karri Tougas\Downloads\kts21.1.15.500en_fr_25338.exe
2020-11-24 15:03 - 2020-11-24 15:03 - 000000000 ____D C:\ProgramData\Kaspersky Lab Setup Files
2020-11-24 09:59 - 2020-11-24 09:59 - 000093858 _____ C:\Users\Karri Tougas\Desktop\sfcdetails.txt
2020-11-24 09:24 - 2020-11-24 09:24 - 000248968 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2020-11-24 09:24 - 2020-11-24 09:24 - 000220160 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamChameleon.sys
2020-11-24 09:24 - 2020-11-24 09:24 - 000002040 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2020-11-24 09:24 - 2020-11-24 09:24 - 000002028 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2020-11-24 09:24 - 2020-11-24 09:24 - 000002028 _____ C:\ProgramData\Desktop\Malwarebytes.lnk
2020-11-24 09:24 - 2020-11-24 09:24 - 000000000 ____D C:\Users\Karri Tougas\AppData\Local\mbam
2020-11-24 09:23 - 2020-11-24 09:23 - 000153312 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys
2020-11-24 09:23 - 2020-11-24 09:23 - 000019912 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamElam.sys
2020-11-24 09:23 - 2020-11-24 09:23 - 000000000 ____D C:\ProgramData\Malwarebytes
2020-11-24 09:23 - 2020-11-24 09:23 - 000000000 ____D C:\Program Files\Malwarebytes
2020-11-24 08:59 - 2019-12-07 00:32 - 000007168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Firewall.cpl
2020-11-23 09:32 - 2020-11-23 09:32 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2020-11-23 08:44 - 2020-11-23 21:14 - 000000000 ____D C:\Program Files\Mozilla Firefox
2020-11-21 09:40 - 2020-11-21 09:40 - 000000000 __SHD C:\found.000
2020-11-20 13:02 - 2020-11-21 20:43 - 000000000 ____D C:\Users\Karri Tougas\Documents\Diablo III
2020-11-20 11:50 - 2020-11-20 11:50 - 000000000 ____D C:\WINDOWS\system32\Tasks\Agent Activation Runtime
2020-11-20 09:57 - 2020-11-20 09:57 - 000000932 _____ C:\Users\Public\Desktop\Diablo III.lnk
2020-11-20 09:57 - 2020-11-20 09:57 - 000000932 _____ C:\ProgramData\Desktop\Diablo III.lnk
2020-11-20 09:57 - 2020-11-20 09:57 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Diablo III
2020-11-20 09:55 - 2020-11-20 10:09 - 000000000 ____D C:\Program Files (x86)\Diablo III
2020-11-20 09:55 - 2020-11-20 09:55 - 000000000 ____D C:\ProgramData\Blizzard Entertainment
2020-11-20 09:49 - 2020-11-23 21:24 - 000000000 ____D C:\Users\Karri Tougas\AppData\Local\Battle.net
2020-11-20 09:49 - 2020-11-20 13:02 - 000000000 ____D C:\Users\Karri Tougas\AppData\Roaming\Battle.net
2020-11-20 09:49 - 2020-11-20 09:49 - 000000936 _____ C:\Users\Public\Desktop\Battle.net.lnk
2020-11-20 09:49 - 2020-11-20 09:49 - 000000936 _____ C:\ProgramData\Desktop\Battle.net.lnk
2020-11-20 09:49 - 2020-11-20 09:49 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net
2020-11-20 09:48 - 2020-11-20 09:55 - 000000000 ____D C:\Program Files (x86)\Battle.net
2020-11-20 09:48 - 2020-11-20 09:48 - 000000000 ____D C:\Users\Karri Tougas\AppData\Local\Blizzard Entertainment
2020-11-20 09:47 - 2020-11-20 09:48 - 000000000 ____D C:\ProgramData\Battle.net
2020-11-20 08:43 - 2020-11-20 08:43 - 000134697 _____ C:\Users\Karri Tougas\Downloads\b05120_intake_legal_assistant.pdf
2020-11-19 13:24 - 2020-11-19 13:24 - 000000000 ____D C:\Users\Karri Tougas\Desktop\November 24
2020-11-18 09:26 - 2020-11-18 09:26 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Jabra
2020-11-16 21:43 - 2020-11-16 21:43 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2020-11-16 18:57 - 2020-11-16 18:57 - 000047600 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-stable.sys
2020-11-16 18:57 - 2020-11-16 18:57 - 000047600 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-dev.sys
2020-11-16 18:57 - 2020-11-16 18:57 - 000047600 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-canary.sys
2020-11-16 18:57 - 2020-11-16 18:57 - 000044552 _____ (Dropbox, Inc.) C:\WINDOWS\system32\DbxSvc.exe
2020-11-15 09:04 - 2020-11-15 09:05 - 003356228 _____ C:\WINDOWS\Minidump\111520-42593-01.dmp
2020-11-12 18:36 - 2020-11-12 18:36 - 000131604 _____ C:\Users\Karri Tougas\Desktop\PR142875.pdf
2020-11-12 17:14 - 2020-11-12 17:14 - 000542475 _____ C:\Users\Karri Tougas\Desktop\document-0.pdf
2020-11-12 16:20 - 2020-11-12 16:20 - 000136161 _____ C:\Users\Karri Tougas\Downloads\uvic_iliol_position_description_2020.pdf
2020-11-12 14:57 - 2020-11-12 14:58 - 000156117 _____ C:\Users\Karri Tougas\Downloads\job_posting_materials_chem_oct_1_2020_1.pdf
2020-11-11 07:52 - 2020-11-11 07:52 - 000363520 _____ C:\WINDOWS\system32\Windows.Internal.UI.Shell.WindowTabManager.dll
2020-11-11 07:52 - 2020-11-11 07:52 - 000266240 _____ C:\WINDOWS\SysWOW64\Windows.Internal.UI.Shell.WindowTabManager.dll
2020-11-11 07:52 - 2020-11-11 07:52 - 000197632 _____ C:\WINDOWS\system32\IHDS.dll
2020-11-11 07:52 - 2020-11-11 07:52 - 000152576 _____ C:\WINDOWS\system32\EoAExperiences.exe
2020-11-11 07:52 - 2020-11-11 07:52 - 000009265 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim
2020-11-11 07:41 - 2020-11-11 07:42 - 004395908 _____ C:\WINDOWS\Minidump\111120-45468-01.dmp
2020-11-10 16:07 - 2020-11-10 16:07 - 001070307 _____ C:\Users\Karri Tougas\Desktop\Skype_Picture_2020_11_10T21_07_04_982Z.jpeg
2020-11-09 07:22 - 2020-11-09 07:22 - 000000000 ____D C:\Users\Karri Tougas\AppData\Roaming\Teams
2020-11-05 20:44 - 2020-11-05 21:58 - 000000000 ____D C:\Users\Karri Tougas\Desktop\Le Creuset
2020-11-05 06:54 - 2020-07-23 04:41 - 000854120 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkApi64U.dll
2020-11-05 06:54 - 2020-07-23 04:36 - 001145480 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtCOM64.dll
2020-11-05 06:54 - 2020-07-23 04:36 - 000468792 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtDataProc64.dll
2020-11-04 14:35 - 2020-11-04 14:35 - 000253493 _____ C:\Users\Karri Tougas\Desktop\Remote Learning Model Elementary Board Report.pdf
2020-11-02 15:07 - 2020-11-02 15:07 - 000169271 _____ C:\Users\Karri Tougas\Downloads\u41623008 (1).pdf
2020-11-02 15:06 - 2020-11-02 15:06 - 000169271 _____ C:\Users\Karri Tougas\Downloads\u41623008.pdf
2020-10-26 15:31 - 2020-10-26 15:31 - 000218010 _____ C:\Users\Karri Tougas\Desktop\attachments.zip
2020-10-25 07:59 - 2020-10-25 08:00 - 004110140 _____ C:\WINDOWS\Minidump\102520-48859-01.dmp
 
==================== One month (modified) ==================
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2020-11-24 15:16 - 2019-07-29 13:52 - 000000000 ____D C:\Users\Karri Tougas\AppData\Local\CrashDumps
2020-11-24 15:12 - 2019-07-16 11:41 - 000000000 ____D C:\Users\Karri Tougas\AppData\Local\ClassicShell
2020-11-24 15:11 - 2020-06-17 22:03 - 000795738 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2020-11-24 15:11 - 2019-12-07 04:13 - 000000000 ____D C:\WINDOWS\INF
2020-11-24 15:06 - 2019-07-27 18:06 - 000000000 ____D C:\Users\Karri Tougas\AppData\Roaming\Jabra Direct
2020-11-24 15:06 - 2019-05-24 16:24 - 000000000 ____D C:\ProgramData\NVIDIA
2020-11-24 15:04 - 2020-06-17 22:05 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2020-11-24 15:04 - 2020-06-17 21:57 - 000008192 ___SH C:\DumpStack.log.tmp
2020-11-24 15:04 - 2019-12-07 04:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2020-11-24 15:04 - 2019-07-17 10:45 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2020-11-24 15:04 - 2019-07-17 10:44 - 000000000 ____D C:\Program Files (x86)\Steam
2020-11-24 15:04 - 2019-07-16 11:38 - 000000000 ___RD C:\Users\Karri Tougas\OneDrive
2020-11-24 15:03 - 2020-06-17 21:50 - 000000000 ____D C:\Users\Karri Tougas
2020-11-24 15:03 - 2019-12-07 04:03 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2020-11-24 14:58 - 2020-06-17 21:59 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2020-11-24 14:51 - 2019-10-08 09:40 - 000011895 _____ C:\Users\Karri Tougas\Desktop\Twitter Schedule.xlsx
2020-11-24 10:34 - 2019-07-16 15:13 - 000000000 ____D C:\ProgramData\Mozilla
2020-11-24 10:33 - 2019-07-16 15:13 - 000000000 ____D C:\Users\Karri Tougas\AppData\LocalLow\Mozilla
2020-11-24 10:12 - 2019-12-07 04:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2020-11-24 09:23 - 2019-12-07 04:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2020-11-24 08:42 - 2019-10-28 06:14 - 000004101 _____ C:\Users\Karri Tougas\Desktop\WordPress Password.txt
2020-11-24 07:38 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2020-11-24 07:12 - 2019-12-07 04:14 - 000000000 ___HD C:\Program Files\WindowsApps
2020-11-24 06:52 - 2020-06-17 21:05 - 000002428 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2020-11-24 06:52 - 2020-06-17 21:05 - 000002266 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2020-11-24 06:52 - 2020-06-17 21:05 - 000002266 _____ C:\ProgramData\Desktop\Microsoft Edge.lnk
2020-11-23 21:14 - 2019-07-16 15:13 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2020-11-23 09:32 - 2019-07-16 15:13 - 000001012 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2020-11-22 19:18 - 2019-07-26 09:43 - 000000000 ___RD C:\Users\Karri Tougas\Dropbox
2020-11-21 17:07 - 2019-07-16 15:25 - 000000000 ____D C:\Program Files\Microsoft Office
2020-11-21 10:11 - 2020-02-01 10:02 - 000002406 _____ C:\Users\Karri Tougas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Teams.lnk
2020-11-20 11:49 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\ServiceState
2020-11-19 16:26 - 2020-06-17 22:05 - 000003392 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-4234547216-3201928491-692415617-1003
2020-11-19 16:26 - 2020-06-17 21:50 - 000002391 _____ C:\Users\Karri Tougas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2020-11-19 13:55 - 2019-10-28 06:44 - 000000000 ____D C:\Users\Karri Tougas\Desktop\SM Curate
2020-11-18 12:42 - 2019-10-28 06:45 - 000000000 ___RD C:\Users\Karri Tougas\Desktop\Twitter Cards
2020-11-18 12:41 - 2020-04-20 07:41 - 000000000 ____D C:\Users\Karri Tougas\Desktop\Old - One Time Use Twitter Cards
2020-11-18 09:26 - 2019-07-27 18:03 - 000000000 ____D C:\Program Files (x86)\Jabra
2020-11-18 09:26 - 2019-01-10 17:31 - 000000000 ____D C:\ProgramData\Package Cache
2020-11-16 21:43 - 2019-07-26 09:31 - 000000000 ____D C:\Program Files (x86)\Dropbox
2020-11-16 18:18 - 2019-07-16 15:12 - 000002308 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-11-16 18:18 - 2019-07-16 15:12 - 000002267 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2020-11-16 18:18 - 2019-07-16 15:12 - 000002267 _____ C:\ProgramData\Desktop\Google Chrome.lnk
2020-11-16 07:23 - 2019-07-16 16:03 - 000000000 ____D C:\WINDOWS\system32\MRT
2020-11-16 07:22 - 2019-07-16 16:03 - 133736600 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2020-11-15 09:05 - 2020-08-25 06:01 - 000000000 ____D C:\WINDOWS\Minidump
2020-11-15 09:04 - 2020-08-25 06:01 - 993897965 _____ C:\WINDOWS\MEMORY.DMP
2020-11-14 14:27 - 2019-07-24 18:22 - 000000000 ____D C:\Users\Karri Tougas\Desktop\New Pics
2020-11-14 14:27 - 2019-07-24 12:02 - 000000000 ____D C:\Users\Karri Tougas\Desktop\Facebook Memes
2020-11-14 09:09 - 2019-07-16 15:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2020-11-12 15:04 - 2019-07-25 16:13 - 000000000 ____D C:\Users\Karri Tougas\AppData\Roaming\vlc
2020-11-11 21:17 - 2020-06-17 21:59 - 000446088 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2020-11-11 21:16 - 2019-12-07 04:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2020-11-11 21:16 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2020-11-11 21:16 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\SystemResources
2020-11-11 21:16 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2020-11-11 21:16 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\setup
2020-11-11 21:16 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2020-11-11 21:16 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\migwiz
2020-11-11 21:16 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\ShellExperiences
2020-11-11 21:16 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2020-11-11 21:16 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2020-11-11 07:52 - 2020-06-17 22:01 - 002876928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2020-11-06 06:53 - 2019-01-08 17:41 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2020-11-05 06:51 - 2020-01-28 21:59 - 000000948 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA1d5d65018e2f04f.job
2020-11-05 06:51 - 2020-01-28 21:59 - 000000944 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore1d5d65018d673f8.job
2020-11-03 17:31 - 2019-07-22 18:36 - 000002143 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2020-11-02 16:59 - 2020-06-17 22:05 - 000004038 _____ C:\WINDOWS\system32\Tasks\DropboxUpdateTaskMachineUA1d5d65018e2f04f
2020-11-02 16:59 - 2020-06-17 22:05 - 000003806 _____ C:\WINDOWS\system32\Tasks\DropboxUpdateTaskMachineCore1d5d65018d673f8
2020-11-01 08:18 - 2020-06-17 22:05 - 000003480 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2020-11-01 08:18 - 2020-06-17 22:05 - 000003356 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2020-10-31 13:12 - 2020-03-13 09:56 - 000000000 ____D C:\Users\Karri Tougas\AppData\Local\GoToMeeting
2020-10-30 10:40 - 2019-07-16 11:38 - 000000000 ____D C:\Users\Karri Tougas\AppData\Local\Packages
2020-10-30 05:52 - 2019-07-16 15:16 - 000795000 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2020-10-25 07:59 - 2020-03-13 09:56 - 000000708 _____ C:\WINDOWS\Tasks\G2MUploadTask-S-1-5-21-4234547216-3201928491-692415617-1003.job
2020-10-25 07:59 - 2020-03-13 09:56 - 000000612 _____ C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-4234547216-3201928491-692415617-1003.job
 
==================== SigCheck ============================
 
(There is no automatic fix for files that do not pass verification.)
 
==================== End of FRST.txt ========================
 
FRST ADDITION LOG: 
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 22-11-2020 01
Ran by [removed] (24-11-2020 15:24:45)
Running from C:\Users\[removed]\Desktop
Windows 10 Home Version 2004 19041.630 (X64) (2020-06-18 03:05:15)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-4234547216-3201928491-692415617-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-4234547216-3201928491-692415617-503 - Limited - Disabled)
Guest (S-1-5-21-4234547216-3201928491-692415617-501 - Limited - Disabled)
Karri Tougas (S-1-5-21-4234547216-3201928491-692415617-1003 - Administrator - Enabled) => C:\Users\Karri Tougas
WDAGUtilityAccount (S-1-5-21-4234547216-3201928491-692415617-504 - Limited - Disabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AV: Kaspersky Total Security (Enabled - Up to date) {0AB30972-4BAC-7BEE-CBCA-B8F9E68797D8}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Kaspersky Total Security (Enabled) {32888857-01C3-7AB6-E095-11CC1854D0A3}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Adobe Acrobat Reader DC (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 20.013.20064 - Adobe Systems Incorporated)
Battle.net (HKLM-x32\…\Battle.net) (Version:  - Blizzard Entertainment)
Classic Shell (HKLM\…\{CABCE573-0A86-42FA-A52A-C7EA61D5BE08}) (Version: 4.3.1 - IvoSoft)
DFUDriverSetupX64Setup (HKLM-x32\…\{2A9E04BE-BDF4-4F19-ABBE-5B8CAD7570F4}) (Version: 6.6.1939.0 - GN Netcom A/S) Hidden
Diablo III (HKLM-x32\…\Diablo III) (Version:  - Blizzard Entertainment)
Driver Easy 5.6.12 (HKLM\…\DriverEasy_is1) (Version: 5.6.12 - Easeware)
Dropbox (HKLM-x32\…\Dropbox) (Version: 110.4.458 - Dropbox, Inc.)
Dropbox Update Helper (HKLM-x32\…\{099218A5-A723-43DC-8DB5-6173656A1E94}) (Version: 1.3.377.1 - Dropbox, Inc.) Hidden
Foldit (HKLM-x32\…\Foldit) (Version:  - )
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 86.0.4240.198 - Google LLC)
Google Update Helper (HKLM-x32\…\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.36.31 - Google LLC) Hidden
GoTo Opener (HKLM-x32\…\{C0F33C38-345C-4C02-B161-11389350C2A5}) (Version: 1.0.533 - LogMeIn, Inc.)
GoToMeeting 10.14.0.18962 (HKU\S-1-5-21-4234547216-3201928491-692415617-1003\…\GoToMeeting) (Version: 10.14.0.18962 - LogMeIn, Inc.)
HP Dropbox Plugin (HKLM-x32\…\{D12BC084-97D6-438A-AA7C-5962608D17A0}) (Version: 36.0.41.58587 - HP)
HP ENVY 5540 series Basic Device Software (HKLM\…\{7F9C00D2-32F6-4844-AC17-290D5F06F186}) (Version: 40.11.1119.1786 - HP Inc.)
HP ENVY 5540 series Help (HKLM-x32\…\{3B1BE080-D477-4B94-AAE4-8B0BEC5D0CE3}) (Version: 35.0.0 - Hewlett Packard)
HP Google Drive Plugin (HKLM-x32\…\{BFA42100-DB54-467A-BB87-CF70732B4065}) (Version: 36.0.41.58587 - HP)
HP Photo Creations (HKLM-x32\…\HP Photo Creations) (Version: 1.0.0.9572 - HP)
Intel(R) Chipset Device Software (HKLM-x32\…\{c30dc778-ac13-4f91-9045-fea2331ceb2e}) (Version: 10.1.17711.8088 - Intel(R) Corporation) Hidden
Intel(R) Management Engine Components (HKLM\…\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 1805.12.0.1097 - Intel Corporation)
Intel(R) Trusted Connect Service Client x86 (HKLM-x32\…\{C9552825-7BF2-4344-BA91-D3CD46F4C441}) (Version: 1.48.197.0 - Intel Corporation) Hidden
Intel(R) Trusted Connect Services Client (HKLM-x32\…\{66129f84-d3f0-4884-ac54-369ae6fc2cf6}) (Version: 1.48.197.0 - Intel Corporation) Hidden
IrfanView 4.54 (64-bit) (HKLM\…\IrfanView64) (Version: 4.54 - Irfan Skiljan)
Jabra Direct (HKLM-x32\…\{49c04bb7-05d1-4c04-b370-1edbbd64388f}) (Version: 4.14.15119 - GN Audio A/S)
Jabra Direct (HKLM-x32\…\{B1C6D0D9-A9E2-488B-90E3-8A199785B80A}) (Version: 4.14.15119 - GN Audio A/S) Hidden
Logitech Camera Settings (HKLM-x32\…\LogiUCDPP) (Version: 2.10.4.0 - Logitech Europe S.A.)
Malwarebytes version 4.2.3.96 (HKLM\…\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.2.3.96 - Malwarebytes)
Microsoft 365 Apps for enterprise - en-us (HKLM\…\O365ProPlusRetail - en-us) (Version: 16.0.13426.20274 - Microsoft Corporation)
Microsoft Edge (HKLM-x32\…\Microsoft Edge) (Version: 87.0.664.47 - Microsoft Corporation)
Microsoft Edge Update (HKLM-x32\…\Microsoft Edge Update) (Version: 1.3.137.99 - )
Microsoft OneDrive (HKU\S-1-5-21-4234547216-3201928491-692415617-1003\…\OneDriveSetup.exe) (Version: 20.201.1005.0008 - Microsoft Corporation)
Microsoft Support and Recovery Assistant for Office 365 (HKU\S-1-5-21-4234547216-3201928491-692415617-1003\…\f9a89bd2a46a7606) (Version: 16.0.3235.0 - Microsoft Corporation)
Microsoft Teams (HKU\S-1-5-21-4234547216-3201928491-692415617-1003\…\Teams) (Version: 1.3.00.30866 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\…\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\…\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x64) - 14.13.26020 (HKLM-x32\…\{7474cd6e-76cc-4257-837e-5b9261e526af}) (Version: 14.13.26020.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x86) - 14.16.27012 (HKLM-x32\…\{67f67547-9693-4937-aa13-56e296bd40f6}) (Version: 14.16.27012.6 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\…\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation)
Mozilla Firefox 83.0 (x64 en-CA) (HKLM\…\Mozilla Firefox 83.0 (x64 en-CA)) (Version: 83.0 - Mozilla)
Mozilla Maintenance Service (HKLM\…\MozillaMaintenanceService) (Version: 68.0 - Mozilla)
NVAPI Monitor plugin for NvContainer (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.NvapiMonitor) (Version: 1.19 - NVIDIA Corporation) Hidden
NVIDIA GeForce Experience 3.20.2.34 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.20.2.34 - NVIDIA Corporation)
NVIDIA Graphics Driver 442.50 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 442.50 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.38.21 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.38.21 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.19.0218 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.19.0218 - NVIDIA Corporation)
NVIDIA USBC Driver 1.38.831.832 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_USBC) (Version: 1.38.831.832 - NVIDIA Corporation)
Office 16 Click-to-Run Extensibility Component (HKLM\…\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.13426.20250 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\…\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.13426.20274 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM\…\{90160000-008C-0409-1000-0000000FF1CE}) (Version: 16.0.13426.20250 - Microsoft Corporation) Hidden
Origin (HKLM-x32\…\Origin) (Version: 10.5.45.29542 - Electronic Arts, Inc.)
Product Improvement Study for HP ENVY 5540 series (HKLM\…\{9E4F436B-5B50-4D84-954A-5C8A18CEB836}) (Version: 40.11.1119.1786 - HP Inc.)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.8781.1 - Realtek Semiconductor Corp.)
RingCentral Phone (HKLM-x32\…\{53B2C588-D9D9-401E-81E7-0F54EBABDA6A}) (Version: 20.3.1.40209 - RingCentral)
Skype version 8.66 (HKLM-x32\…\Skype_is1) (Version: 8.66 - Skype Technologies S.A.)
Steam (HKLM-x32\…\Steam) (Version: 2.10.91.91 - Valve Corporation)
Teams Machine-Wide Installer (HKLM-x32\…\{731F6BAA-A986-45A4-8936-7C3AAAAA760B}) (Version: 1.2.0.19260 - Microsoft Corporation)
TeamViewer (HKLM-x32\…\TeamViewer) (Version: 15.11.6 - TeamViewer)
The Sims™ 4 (HKLM-x32\…\{48EBEBBF-B9F8-4520-A3CF-89A730721917}) (Version: 1.54.120.1020 - Electronic Arts Inc.)
Transmission 2.94 (d8e60ee44f) (x64) (HKLM\…\{F822870C-AD55-47D1-A705-21661A02386B}) (Version: 2.94.0 - Transmission Project)
TurboTax 2019 (HKLM-x32\…\{176AF9FD-3AF6-4C10-9F68-A3AA455B3D51}) (Version: 1.00.0000 - Intuit Canada)
VLC media player (HKLM\…\VLC media player) (Version: 3.0.11 - VideoLAN)
Zoom (HKU\S-1-5-21-4234547216-3201928491-692415617-1003\…\ZoomUMX) (Version: 5.0 - Zoom Video Communications, Inc.)
 
Packages:
=========
Candy Crush Friends -> C:\Program Files\WindowsApps\king.com.CandyCrushFriends_1.47.2.0_x86__kgqvnymyfvs32 [2020-11-24] (king.com)
Candy Crush Saga -> C:\Program Files\WindowsApps\king.com.CandyCrushSaga_1.1900.2.0_x86__kgqvnymyfvs32 [2020-11-20] (king.com)
HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_121.1.193.0_x64__v10z8vjag6ke6 [2020-11-03] (HP Inc.)
LinkedIn -> C:\Program Files\WindowsApps\7EE7776C.LinkedInforWindows_2.1.7098.0_neutral__w1wdnht996qgy [2019-07-16] (LinkedIn)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-07-16] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-07-16] (Microsoft Corporation) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.7.10142.0_x64__8wekyb3d8bbwe [2020-10-23] (Microsoft Studios) [MS Ad]
Minecraft for Windows 10 -> C:\Program Files\WindowsApps\Microsoft.MinecraftUWP_1.16.10004.0_x64__8wekyb3d8bbwe [2020-11-18] (Microsoft Studios)
Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.14.225.0_x64__dt26b99r8h8gj [2020-11-05] (Realtek Semiconductor Corp)
Spotify Music -> C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.146.916.0_x86__zpdnekdrzrea0 [2020-11-16] (Spotify AB) [Startup Task]
Xbox 360 SmartGlass -> C:\Program Files\WindowsApps\Microsoft.XboxCompanion_1.4.3.0_x64__8wekyb3d8bbwe [2019-12-07] (Microsoft Corporation) [MS Ad]
 
==================== Custom CLSID (Whitelisted): ==============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-4234547216-3201928491-692415617-1003_Classes\CLSID\{19A6E644-14E6-4A60-B8D7-DD20610A871D}\InprocServer32 -> C:\Users\Karri Tougas\AppData\Local\Microsoft\TeamsMeetingAddin\1.0.20275.4\x64\Microsoft.Teams.AddinLoader.dll (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-4234547216-3201928491-692415617-1003_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309}\InprocServer32 -> C:\Users\Karri Tougas\AppData\Local\GoToMeeting\18068\G2MOutlookAddin64.dll (LogMeIn, Inc. -> LogMeIn, Inc.)
CustomCLSID: HKU\S-1-5-21-4234547216-3201928491-692415617-1003_Classes\CLSID\{CB965DF1-B8EA-49C7-BDAD-5457FDC1BF92}\InprocServer32 -> C:\Users\Karri Tougas\AppData\Local\Microsoft\TeamsMeetingAddin\1.0.20244.4\x64\Microsoft.Teams.AddinLoader.dll => No File
CustomCLSID: HKU\S-1-5-21-4234547216-3201928491-692415617-1003_Classes\CLSID\{E31EA727-12ED-4702-820C-4B6445F28E1A} -> [Dropbox] => C:\Users\Karri Tougas\Dropbox [2019-07-26 09:43]
ShellIconOverlayIdentifiers: [   DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.46.0.dll [2020-10-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.46.0.dll [2020-10-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.46.0.dll [2020-10-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.46.0.dll [2020-10-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.46.0.dll [2020-10-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.46.0.dll [2020-10-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.46.0.dll [2020-10-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.46.0.dll [2020-10-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.46.0.dll [2020-10-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.46.0.dll [2020-10-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer64.dll [2018-07-15] (Ivaylo Beltchev -> IvoSoft) [File not signed]
ShellIconOverlayIdentifiers-x32: [   DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.46.0.dll [2020-10-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.46.0.dll [2020-10-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.46.0.dll [2020-10-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.46.0.dll [2020-10-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.46.0.dll [2020-10-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.46.0.dll [2020-10-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.46.0.dll [2020-10-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.46.0.dll [2020-10-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.46.0.dll [2020-10-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.46.0.dll [2020-10-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer64.dll [2018-07-15] (Ivaylo Beltchev -> IvoSoft) [File not signed]
ContextMenuHandlers1: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.46.0.dll [2020-10-06] (Dropbox, Inc -> Dropbox, Inc.)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2020-11-24] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers4: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.46.0.dll [2020-10-06] (Dropbox, Inc -> Dropbox, Inc.)
ContextMenuHandlers5: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.46.0.dll [2020-10-06] (Dropbox, Inc -> Dropbox, Inc.)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2020-02-24] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2020-11-24] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers6: [StartMenuExt] -> {E595F05F-903F-4318-8B0A-7F633B520D2B} => C:\WINDOWS\System32\StartMenuHelper64.dll [2018-07-15] (Ivaylo Beltchev -> IvoSoft) [File not signed]
 
==================== Codecs (Whitelisted) ====================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Drivers32: [vidc.i420] => C:\Windows\system32\lvcod64.dll [175392 2012-10-26] (Logitech, Inc. -> Logitech Inc.)
HKLM\…\Drivers32: [vidc.i420] => C:\Windows\SysWOW64\lvcodec2.dll [305000 2012-10-26] (Logitech, Inc. -> Logitech Inc.)
HKLM\…\Drivers32: [vidc.VP60] => C:\Windows\SysWOW64\vp6vfw.dll [447752 2014-09-16] (Electronic Arts -> On2.com)
HKLM\…\Drivers32: [vidc.VP61] => C:\Windows\SysWOW64\vp6vfw.dll [447752 2014-09-16] (Electronic Arts -> On2.com)
 
==================== Shortcuts & WMI ========================
 
==================== Loaded Modules (Whitelisted) =============
 
2019-06-18 15:21 - 2019-06-18 15:21 - 000243200 _____ () [File not signed] [File is in use] C:\Users\Karri Tougas\AppData\Local\RingCentral\SoftPhoneApp\libmpg123.dll
2020-11-13 08:23 - 2020-11-13 08:23 - 001800704 _____ () [File not signed] \\?\C:\Program Files (x86)\Jabra\Direct4\resources\app.asar.unpacked\node_modules\@gnaudio\jabra-node-sdk\build\Release\sdkintegration.node
2020-11-13 08:23 - 2020-11-13 08:23 - 001965568 _____ () [File not signed] \\?\C:\Program Files (x86)\Jabra\Direct4\resources\app.asar.unpacked\node_modules\panacastapi\build\Release\panacastapi.node
2020-11-13 08:22 - 2020-11-13 08:22 - 002608128 _____ () [File not signed] C:\Program Files (x86)\Jabra\Direct4\ffmpeg.dll
2020-11-13 08:22 - 2020-11-13 08:22 - 000356352 _____ () [File not signed] C:\Program Files (x86)\Jabra\Direct4\libegl.dll
2020-11-13 08:22 - 2020-11-13 08:22 - 008347648 _____ () [File not signed] C:\Program Files (x86)\Jabra\Direct4\libglesv2.dll
2019-07-16 15:22 - 2020-11-12 19:30 - 002072064 _____ () [File not signed] C:\Program Files (x86)\Microsoft\Skype for Desktop\ffmpeg.dll
2019-07-16 15:22 - 2020-11-12 19:30 - 000310784 _____ () [File not signed] C:\Program Files (x86)\Microsoft\Skype for Desktop\libegl.dll
2019-07-16 15:22 - 2020-11-12 19:30 - 006903808 _____ () [File not signed] C:\Program Files (x86)\Microsoft\Skype for Desktop\libglesv2.dll
2020-04-21 11:01 - 2020-04-21 11:01 - 002029056 _____ (GN Audio A/S) [File not signed] [File is in use] C:\Users\Karri Tougas\AppData\Local\RingCentral\SoftPhoneApp\libjabra.dll
2020-11-13 08:23 - 2020-11-13 08:23 - 002081792 _____ (GN Audio A/S) [File not signed] \\?\C:\Program Files (x86)\Jabra\Direct4\resources\app.asar.unpacked\node_modules\@gnaudio\jabra-node-sdk\build\Release\libjabra.dll
2020-04-21 10:52 - 2020-04-21 10:52 - 002559488 _____ (GN Audio A/S) [File not signed] C:\Users\Karri Tougas\AppData\Local\RingCentral\SoftPhoneApp\x64\libjabra.dll
2018-07-15 12:15 - 2018-07-15 12:15 - 003664696 _____ (Ivaylo Beltchev -> IvoSoft) [File not signed] C:\Program Files\Classic Shell\ClassicStartMenuDLL.dll
2018-07-15 12:15 - 2018-07-15 12:15 - 000291128 _____ (Ivaylo Beltchev -> IvoSoft) [File not signed] C:\WINDOWS\System32\StartMenuHelper64.dll
2018-10-22 19:42 - 2018-10-22 19:42 - 000854016 _____ (Microsoft Corporation) [File not signed] [File is in use] C:\Users\Karri Tougas\AppData\Local\RingCentral\SoftPhoneApp\dbghelp.dll
2020-04-26 09:11 - 2020-04-26 09:11 - 000000000 ____L (Microsoft Corporation) C:\Program Files\Microsoft Office\root\Office16\AppvIsvSubsystems64.dll
2020-04-26 09:11 - 2020-04-26 09:11 - 000000000 ____L (Microsoft Corporation) C:\Program Files\Microsoft Office\root\Office16\c2r64.dll
2019-08-23 14:18 - 2019-08-23 14:18 - 001277440 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files (x86)\Origin\LIBEAY32.dll
2019-08-23 14:18 - 2019-08-23 14:18 - 000279040 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files (x86)\Origin\ssleay32.dll
2020-03-05 15:56 - 2020-03-05 15:56 - 002097664 _____ (The OpenSSL Project, hxxps://www.openssl.org/) [File not signed] [File is in use] C:\Users\Karri Tougas\AppData\Local\RingCentral\SoftPhoneApp\libcrypto-1_1.dll
2020-03-05 15:56 - 2020-03-05 15:56 - 000503808 _____ (The OpenSSL Project, hxxps://www.openssl.org/) [File not signed] [File is in use] C:\Users\Karri Tougas\AppData\Local\RingCentral\SoftPhoneApp\libssl-1_1.dll
2020-03-05 15:48 - 2020-03-05 15:48 - 002714624 _____ (The OpenSSL Project, hxxps://www.openssl.org/) [File not signed] C:\Users\Karri Tougas\AppData\Local\RingCentral\SoftPhoneApp\x64\libcrypto-1_1-x64.dll
2020-03-05 15:48 - 2020-03-05 15:48 - 000654336 _____ (The OpenSSL Project, hxxps://www.openssl.org/) [File not signed] C:\Users\Karri Tougas\AppData\Local\RingCentral\SoftPhoneApp\x64\libssl-1_1-x64.dll
2019-08-23 14:18 - 2019-08-23 14:18 - 001611264 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\platforms\qwindows.dll
2019-08-23 14:18 - 2019-08-23 14:18 - 005487104 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Core.dll
2019-08-23 14:18 - 2019-08-23 14:18 - 005841920 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Gui.dll
2019-08-23 14:18 - 2019-08-23 14:18 - 001179136 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Network.dll
2019-08-23 14:18 - 2019-08-23 14:18 - 005089792 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Widgets.dll
2019-08-23 14:18 - 2019-08-23 14:18 - 000184832 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Xml.dll
 
==================== Alternate Data Streams (Whitelisted) ========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\Users\Karri Tougas\Desktop\20161113_164300.jpg:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Karri Tougas\Desktop\20161113_164300.jpg:com.dropbox.attrs [58]
AlternateDataStreams: C:\Users\Karri Tougas\Desktop\20200428_153527.jpg:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Karri Tougas\Desktop\20200504_190959.jpg:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Karri Tougas\Desktop\20200511_133133.jpg:com.dropbox.attrs [52]
AlternateDataStreams: C:\Users\Karri Tougas\Desktop\20200522_213446.mp4:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Karri Tougas\Desktop\20200604_185648.jpg:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Karri Tougas\Desktop\20200604_185754.jpg:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Karri Tougas\Desktop\20200730_163913.jpg:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Karri Tougas\Desktop\20200817_081715.jpg:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Karri Tougas\Desktop\20200818_122130.jpg:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Karri Tougas\Desktop\20200921_093141.jpg:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Karri Tougas\Desktop\20201023_160424.jpg:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Karri Tougas\Desktop\20201117_200754.jpg:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Karri Tougas\Desktop\EK001-12 - Get Here - Adams, Oleta.mp3:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Karri Tougas\Desktop\EK001-12 - Get Here - Adams, Oleta.mp3:com.dropbox.attrs [58]
AlternateDataStreams: C:\Users\Karri Tougas\Desktop\IMG_8577.jpg:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Karri Tougas\Desktop\Screenshot 2020-08-19 10.49.40.png:com.dropbox.attrs [54]
 
==================== Safe Mode (Whitelisted) ==================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
 
==================== Association (Whitelisted) =================
 
==================== Internet Explorer (Whitelisted) ==========
 
HKU\S-1-5-21-4234547216-3201928491-692415617-1003\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://oem17win10.msn.com/?pc=NMTE
HKU\S-1-5-21-4234547216-3201928491-692415617-1003\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://oem17win10.msn.com/?pc=NMTE
SearchScopes: HKU\S-1-5-21-4234547216-3201928491-692415617-1003 -> DefaultScope {2C4BB6F5-02EB-4ABF-987D-B816DBDF8E83} URL = hxxps://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:{language}:{referrer:source}&ie;={inputEncoding?}&oe;={outputEncoding?}
SearchScopes: HKU\S-1-5-21-4234547216-3201928491-692415617-1003 -> {2C4BB6F5-02EB-4ABF-987D-B816DBDF8E83} URL = hxxps://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:{language}:{referrer:source}&ie;={inputEncoding?}&oe;={outputEncoding?}
SearchScopes: HKU\S-1-5-21-4234547216-3201928491-692415617-1003 -> {DCD4E047-FB67-439A-9FD5-732F5B759F32} URL = 
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\Office16\OCHelper.dll [2020-08-12] (Microsoft Corporation -> Microsoft Corporation)
BHO: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer64.dll [2018-07-15] (Ivaylo Beltchev -> IvoSoft) [File not signed]
BHO: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_64.dll [2018-07-15] (Ivaylo Beltchev -> IvoSoft) [File not signed]
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2020-08-12] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer32.dll [2018-07-15] (Ivaylo Beltchev -> IvoSoft) [File not signed]
BHO-x32: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_32.dll [2018-07-15] (Ivaylo Beltchev -> IvoSoft) [File not signed]
Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll [2018-07-15] (Ivaylo Beltchev -> IvoSoft) [File not signed]
Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2018-07-15] (Ivaylo Beltchev -> IvoSoft) [File not signed]
Handler-x32: intu-tt2019 - {F526FF07-B913-4B56-85DC-D7014178A5B4} - C:\Program Files (x86)\TurboTax 2019\ic2019pp.dll [2020-06-15] (Intuit Canada ULC -> Intuit Canada, a general partnership/une société en nom collectif.)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2020-11-10] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2020-11-10] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2020-11-10] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2020-11-10] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2020-11-10] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2020-11-10] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2020-11-10] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2020-11-10] (Microsoft Corporation -> Microsoft Corporation)
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE trusted site: HKU\S-1-5-21-4234547216-3201928491-692415617-1003\…\sharepoint.com -> hxxps://responsetrac-files.sharepoint.com
 
==================== Hosts content: =========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2018-09-15 02:31 - 2018-09-15 02:31 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts
 
==================== Other Areas ===========================
 
(Currently there is no automatic fix for this section.)
 
HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\iCLS\;C:\Program Files\Intel\Intel(R) Management Engine Components\iCLS\;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Windows\System32\OpenSSH\;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\NVIDIA Corporation\NVIDIA NvDLISR;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\
HKU\S-1-5-21-4234547216-3201928491-692415617-1003\Control Panel\Desktop\\Wallpaper -> c:\windows\web\wallpaper\theme1\img2.jpg
DNS Servers: 192.168.10.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
==================== FirewallRules (Whitelisted) ================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{6BCB31D9-2D21-432F-A522-B995B61FE45C}] => (Allow) C:\Users\Karri Tougas\AppData\Local\Temp\7zS1C70\HPDiagnosticCoreUI.exe => No File
FirewallRules: [{9018DF4E-F7AA-4471-95D0-8CB95D08854A}] => (Allow) C:\Users\Karri Tougas\AppData\Local\Temp\7zS1C70\HPDiagnosticCoreUI.exe => No File
FirewallRules: [{67A230B6-AD0B-4CB4-8F3B-54D956989293}] => (Allow) C:\Users\Karri Tougas\AppData\Local\Temp\7zS01A7\HPDiagnosticCoreUI.exe => No File
FirewallRules: [{C3B32228-A6F3-4BEE-BF76-2A23B5A84D78}] => (Allow) C:\Users\Karri Tougas\AppData\Local\Temp\7zS01A7\HPDiagnosticCoreUI.exe => No File
FirewallRules: [{B68C74B8-B3B8-4859-B046-ADE512396E3A}] => (Allow) C:\Users\Karri Tougas\AppData\Local\Temp\7zS0074\HPDiagnosticCoreUI.exe => No File
FirewallRules: [{EA6D6472-75D5-4D20-960D-C5F1E90FC95D}] => (Allow) C:\Users\Karri Tougas\AppData\Local\Temp\7zS0074\HPDiagnosticCoreUI.exe => No File
FirewallRules: [{3EAE5965-DDD4-4FDA-A912-9BDDD77C5327}] => (Allow) C:\Program Files (x86)\Apowersoft\Apowersoft Photo Viewer\Apowersoft Photo Viewer.exe => No File
FirewallRules: [{6984CBEF-0493-41EA-870F-1E084EBD556F}] => (Allow) C:\Program Files (x86)\Apowersoft\Apowersoft Photo Viewer\Apowersoft Photo Viewer.exe => No File
FirewallRules: [{96BD7D70-4DDE-4574-87BC-90A318FE7A86}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Evil Genius\EvilGeniusLauncher.exe () [File not signed]
FirewallRules: [{BF848839-01CA-4FC2-8EF0-61F6D25CA6E6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Evil Genius\EvilGeniusLauncher.exe () [File not signed]
FirewallRules: [{FAFD4C35-1648-4243-9D16-DE89279C2ADE}] => (Allow) C:\Users\Karri Tougas\AppData\Roaming\Zoom\bin\airhost.exe => No File
FirewallRules: [{2C42733B-A44F-4033-AA89-9E836E15331C}] => (Allow) C:\Users\Karri Tougas\AppData\Roaming\Zoom\bin\Zoom.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FirewallRules: [{AF84DDEB-82AD-479B-A6A4-B2702F4C2818}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{D99F3F4A-CA6B-48E9-9DEE-1E27EE4AC218}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{05468C17-FD42-48FE-8C28-8A3C3A7AD6F6}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{B812399A-2C5D-4AAC-8992-5F29CDF96EDA}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{B7BD98DD-0738-48B0-9129-A0428293D162}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{3C7E9CB6-E89F-4DBD-AC33-AAC8D1771A04}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{FDB641CC-9374-4651-9401-35A835B6AD2B}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{12F13492-4DAC-49F2-A94B-A1EB29E4B059}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{42746BEA-1074-4455-89C9-10D2CB28E431}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [{0767B5A0-4CEC-4D3B-9EDD-0FC83F55B94D}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [{91846150-65F5-46B3-8364-29C8061C6E61}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{F78F00C9-C5ED-4B13-A329-70AE0350F26C}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{749D2502-6EF1-45E4-9A76-8BE152B4C00B}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{E2E04F1D-61ED-431A-B474-30EA06797B8F}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{2917D066-57A2-48A5-B9FE-78CB0C141D93}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe => No File
FirewallRules: [{5C24FD6A-E97F-4A3A-897F-9FCFA0D95670}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe => No File
FirewallRules: [TCP Query User{8DF07843-E747-41D6-BFD4-77499ABABAD7}C:\users\karri tougas\appdata\local\ringcentral\softphoneapp\softphone.exe] => (Allow) C:\users\karri tougas\appdata\local\ringcentral\softphoneapp\softphone.exe (RingCentral, Inc. -> RingCentral)
FirewallRules: [UDP Query User{64E473D1-0E67-4BBF-841A-EF137F7D0919}C:\users\karri tougas\appdata\local\ringcentral\softphoneapp\softphone.exe] => (Allow) C:\users\karri tougas\appdata\local\ringcentral\softphoneapp\softphone.exe (RingCentral, Inc. -> RingCentral)
FirewallRules: [TCP Query User{DB80B8B1-3980-46B5-BD58-FDFDF8F9C2E3}C:\users\karri tougas\appdata\local\ringcentral\softphoneapp\softphone.exe] => (Allow) C:\users\karri tougas\appdata\local\ringcentral\softphoneapp\softphone.exe (RingCentral, Inc. -> RingCentral)
FirewallRules: [UDP Query User{45CA0536-85A0-496C-A0E2-06F8ACB36CE4}C:\users\karri tougas\appdata\local\ringcentral\softphoneapp\softphone.exe] => (Allow) C:\users\karri tougas\appdata\local\ringcentral\softphoneapp\softphone.exe (RingCentral, Inc. -> RingCentral)
FirewallRules: [{A47A57CC-3DE3-4201-A3BE-5D8B3E4F7A51}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{C7432713-804E-4E34-A885-3C1C140FB59F}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{8FC043D2-26AF-4A9A-9083-15C459AA5912}] => (Allow) C:\Program Files (x86)\Origin Games\The Sims 4\Game\Bin\TS4.exe (Electronic Arts, Inc. -> Electronic Arts Inc.)
FirewallRules: [{BAAAE90B-F00D-416F-87C5-83FC3EDBB918}] => (Allow) C:\Program Files (x86)\Origin Games\The Sims 4\Game\Bin\TS4.exe (Electronic Arts, Inc. -> Electronic Arts Inc.)
FirewallRules: [{0F55C5BD-6E60-4CAC-9063-E92B6DF8A357}] => (Allow) C:\Program Files (x86)\Origin Games\The Sims 4\Game\Bin\TS4_x64.exe (Electronic Arts, Inc. -> Electronic Arts Inc.)
FirewallRules: [{0B74FE56-8BE9-48BF-B429-18F4CE8210FB}] => (Allow) C:\Program Files (x86)\Origin Games\The Sims 4\Game\Bin\TS4_x64.exe (Electronic Arts, Inc. -> Electronic Arts Inc.)
FirewallRules: [{D75AD9F8-BC2B-4BF5-8439-ECFC8A46E455}] => (Allow) C:\Users\Karri Tougas\AppData\Local\Temp\7zS0492\HPDiagnosticCoreUI.exe => No File
FirewallRules: [{52EE4BAB-CCA7-40AA-AD47-2D3473BDF225}] => (Allow) C:\Users\Karri Tougas\AppData\Local\Temp\7zS0492\HPDiagnosticCoreUI.exe => No File
FirewallRules: [{CD809EC1-643D-4BC0-ADE8-14E40DB79917}] => (Allow) C:\Users\Karri Tougas\AppData\Local\Temp\7zS080E\HPDiagnosticCoreUI.exe => No File
FirewallRules: [{632BD163-9F33-4BD1-A387-5A4F8BE4E08E}] => (Allow) C:\Users\Karri Tougas\AppData\Local\Temp\7zS080E\HPDiagnosticCoreUI.exe => No File
FirewallRules: [{92E1EEDF-054D-4824-BFA4-D4B92A92E8E4}] => (Allow) C:\Program Files\Easeware\DriverEasy\DriverEasy.exe (Easeware Technology Limited -> Easeware)
FirewallRules: [TCP Query User{08C7EAD5-397F-49D3-ADD8-4076B6505C06}C:\users\karri tougas\appdata\local\microsoft\teams\current\teams.exe] => (Allow) C:\users\karri tougas\appdata\local\microsoft\teams\current\teams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [UDP Query User{89AD8F58-3941-430B-BEFA-E1CAECF92132}C:\users\karri tougas\appdata\local\microsoft\teams\current\teams.exe] => (Allow) C:\users\karri tougas\appdata\local\microsoft\teams\current\teams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{2A174A68-1829-49D0-8940-268D4FA6E7E3}] => (Allow) C:\Users\Karri Tougas\AppData\Local\Temp\7zS7D9E\HPDiagnosticCoreUI.exe => No File
FirewallRules: [{166CE4CC-7944-4F5A-A377-47C761F7C2B9}] => (Allow) C:\Users\Karri Tougas\AppData\Local\Temp\7zS7D9E\HPDiagnosticCoreUI.exe => No File
FirewallRules: [{79C2F30F-3846-492E-AE45-EFDB25A6BE6E}] => (Allow) C:\Users\Karri Tougas\AppData\Local\Temp\7zS7F95\HPDiagnosticCoreUI.exe => No File
FirewallRules: [{084B78C6-A1F3-4FDA-B796-94955F131872}] => (Allow) C:\Users\Karri Tougas\AppData\Local\Temp\7zS7F95\HPDiagnosticCoreUI.exe => No File
FirewallRules: [{748CB5A0-61B2-485A-ABF2-68907132742B}] => (Allow) C:\Program Files\HP\HP ENVY 5540 series\Bin\DeviceSetup.exe (Hewlett Packard -> HP Inc.)
FirewallRules: [{3B0AB839-7142-4079-972A-0E113658264C}] => (Allow) LPort=5357
FirewallRules: [{D1765D52-4E81-43B6-A90B-4B31323AD997}] => (Allow) C:\Program Files\HP\HP ENVY 5540 series\Bin\HPNetworkCommunicatorCom.exe (Hewlett Packard -> HP Inc.)
FirewallRules: [TCP Query User{A2EF6148-650A-488D-9FD9-527BB83ED79A}C:\program files\transmission\transmission-qt.exe] => (Allow) C:\program files\transmission\transmission-qt.exe (Mike Gelfand -> Transmission Project)
FirewallRules: [UDP Query User{12E2AB22-B382-4E60-AAAA-F035FF66205B}C:\program files\transmission\transmission-qt.exe] => (Allow) C:\program files\transmission\transmission-qt.exe (Mike Gelfand -> Transmission Project)
FirewallRules: [{7ACD25BB-F218-4664-B23C-3FB5DE940075}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{540E139B-C771-43C5-9B21-461B0D35204D}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{9F6F772B-6FC5-4666-9B9C-938B12C95BE7}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Serial Cleaner\Cleaner.exe () [File not signed]
FirewallRules: [{A0A3F75E-496C-43FB-904B-1C470B192D94}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Serial Cleaner\Cleaner.exe () [File not signed]
FirewallRules: [{1E738190-2638-4E06-BF09-85086DEE3A69}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Portal Knights\portal_knights_x64.exe () [File not signed]
FirewallRules: [{D267C66E-FB6A-44C1-8C26-9EAE665179C0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Portal Knights\portal_knights_x64.exe () [File not signed]
FirewallRules: [{A386C507-4917-4B8E-8EFA-A259B82C679F}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{E7DE94B2-0223-41F4-B4E6-318D97D4BA94}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{228DD36B-3947-4EAC-BE06-2BE0706C4905}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{3E50D9FF-E6B6-4BF1-96A0-823864EC20C9}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{0CA6CC8A-6333-405B-AEA9-3531EB342B33}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Stardew Valley\Stardew Valley.exe (ConcernedApe) [File not signed]
FirewallRules: [{13F6DF45-B470-4C9F-B549-AE561BB79813}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Stardew Valley\Stardew Valley.exe (ConcernedApe) [File not signed]
FirewallRules: [{D585BCBB-8A57-4023-91D9-C77367464C5D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Gauntlet\binaries\gauntlet.exe () [File not signed]
FirewallRules: [{AF1B9291-82FF-4363-95E8-2E03749DCC7D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Gauntlet\binaries\gauntlet.exe () [File not signed]
FirewallRules: [{AC0D1F23-4152-44B3-B94D-13319FCC2198}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Chronicon\Chronicon.exe (Subworld AB) [File not signed]
FirewallRules: [{F8779F49-8322-4816-A676-86E1DCC4C1E0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Chronicon\Chronicon.exe (Subworld AB) [File not signed]
FirewallRules: [{D1285F1B-A3DB-4FE7-B8CF-0A9C9E3AFD19}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\YMBAB\YMBAB.exe () [File not signed]
FirewallRules: [{57A9517F-7357-4E75-B948-6A833600D9CF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\YMBAB\YMBAB.exe () [File not signed]
FirewallRules: [{BDD3DBF6-C0FF-4860-8EE3-BE03AAC3EE42}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\10000000\10000000.exe () [File not signed]
FirewallRules: [{0EDDD2BC-0A16-49D5-8C86-3C14B6D981E5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\10000000\10000000.exe () [File not signed]
FirewallRules: [{FE8B939C-25AA-45C4-AD98-ECB526B9CF4B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\CraftTheWorld\CraftWorld.exe () [File not signed]
FirewallRules: [{5829A328-815B-42E0-AF03-2802EE056B3E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\CraftTheWorld\CraftWorld.exe () [File not signed]
FirewallRules: [{1F516199-D382-4E1C-90F3-5984D7BB57C9}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\CraftTheWorld\Editor.exe () [File not signed]
FirewallRules: [{310A9315-2DAC-4DFA-B97D-993AE415D65C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\CraftTheWorld\Editor.exe () [File not signed]
FirewallRules: [{8BAD832C-287C-4209-8EC2-04EC55DFF159}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Insaniquarium Deluxe\Insaniquarium.exe (PopCap Games -> PopCap Games)
FirewallRules: [{524FBE3C-7AF2-47E3-A608-1ED4DDCD394C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Insaniquarium Deluxe\Insaniquarium.exe (PopCap Games -> PopCap Games)
FirewallRules: [{E8358D59-2077-4420-A3DB-5365DC1C76DD}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{488611DD-BD77-48DE-8BCA-4FBA032E3925}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{6BF978DA-15F7-4D5C-955C-D21432B33BBB}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{81EB29DD-2A73-4701-990E-A5989C9FD2E3}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{5E6CD904-CA8F-439B-A54E-1F69E9AD4A18}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{EC8BBDB1-1B3C-4381-AC68-1BB001505A23}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{D55BF5F4-60F5-4796-8185-68813D0E821A}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{FB3B699E-62AA-49AF-9658-6D164F00FCCE}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{8B865BB7-5B61-4138-8926-FEC5C7A79604}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.146.916.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{9D35CC75-2536-4647-A90D-AADADB8CF7D1}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.146.916.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{7A393C83-A2E9-416A-B975-E39EF4059BED}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.146.916.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{2F78B88D-D8AB-4CF8-A5F9-E4C10F2E5587}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.146.916.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{F3DC75B8-19F3-4B3B-BB3C-AE33364F85BE}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.146.916.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{E9BABA54-90D7-4A1C-B1BE-932543C50CEA}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.146.916.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{9F02A631-B662-42CA-8EA3-591859A8BCE8}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.146.916.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{6FE0EE96-39BC-4C77-AD71-4AB3B1B7F496}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.146.916.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{72294C3F-132E-41F0-A68E-990DFF668915}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (Dropbox, Inc -> Dropbox, Inc.)
FirewallRules: [{B68942D7-DE5A-4995-A50D-53C314A1E0CA}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.66.77.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{181EB6F6-60FE-443F-A340-98DE77160604}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.66.77.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{60E410B7-E39B-409E-B715-093FA34B942C}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.66.77.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{C36A7A10-47B5-4A79-AF17-C6EDA66526BF}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.66.77.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [TCP Query User{F76CF9AD-7AD8-45FF-B17B-20D8F181B97C}C:\program files (x86)\diablo iii\x64\diablo iii64.exe] => (Allow) C:\program files (x86)\diablo iii\x64\diablo iii64.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment)
FirewallRules: [UDP Query User{3B495212-12BC-4FD8-867B-6E9C82BDCD67}C:\program files (x86)\diablo iii\x64\diablo iii64.exe] => (Allow) C:\program files (x86)\diablo iii\x64\diablo iii64.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment)
 
==================== Restore Points =========================
 
21-11-2020 17:04:43 Scheduled Checkpoint
 
==================== Faulty Device Manager Devices ============
 
 
==================== Event log errors: ========================
 
Application errors:
==================
Error: (11/24/2020 03:16:51 PM) (Source: Application Error) (EventID: 1005) (User: )
Description: Windows cannot access the file C:\Program Files\Classic Shell\ClassicExplorer64.dll for one of the following reasons:
there is a problem with the network connection, the disk that the file is stored on, or the storage
drivers installed on this computer; or the disk is missing.
Windows closed the program Windows Explorer because of this error.
 
Program: Windows Explorer
File: C:\Program Files\Classic Shell\ClassicExplorer64.dll
 
The error value is listed in the Additional Data section.
User Action
1. Open the file again.
This situation might be a temporary problem that corrects itself when the program runs again.
2.
If the file still cannot be accessed and
- It is on the network,
your network administrator should verify that there is not a problem with the network and that the server can be contacted.
- It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the disk is fully inserted into the computer.
3. Check and repair the file system by running CHKDSK. To run CHKDSK, click Start, click Run, type CMD, and then click OK. At the command prompt, type CHKDSK /F, and then press ENTER.
4. If the problem persists, restore the file from a backup copy.
5. Determine whether other files on the same disk can be opened. If not, the disk might be damaged. If it is a hard disk, contact your administrator or computer hardware vendor for
further assistance.
 
Additional Data
Error value: C000009C
Disk type: 3
 
Error: (11/24/2020 03:16:51 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: explorer.exe, version: 10.0.19041.610, time stamp: 0xab30c679
Faulting module name: ntdll.dll, version: 10.0.19041.610, time stamp: 0xe5d7ed5c
Exception code: 0xc0000006
Fault offset: 0x0000000000032daf
Faulting process id: 0x4660
Faulting application start time: 0x01d6c29ebb5fb211
Faulting application path: C:\WINDOWS\explorer.exe
Faulting module path: C:\WINDOWS\SYSTEM32\ntdll.dll
Report Id: 19ddf4f8-0b26-4ed4-98fd-4e0506ed900e
Faulting package full name: 
Faulting package-relative application ID:
 
Error: (11/24/2020 03:15:16 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: explorer.exe, version: 10.0.19041.610, time stamp: 0xab30c679
Faulting module name: ntdll.dll, version: 10.0.19041.610, time stamp: 0xe5d7ed5c
Exception code: 0xc000041d
Fault offset: 0x0000000000032daf
Faulting process id: 0x3f04
Faulting application start time: 0x01d6c29e82be9966
Faulting application path: C:\WINDOWS\explorer.exe
Faulting module path: C:\WINDOWS\SYSTEM32\ntdll.dll
Report Id: 3915de93-fb9e-48a6-b565-786c25786319
Faulting package full name: 
Faulting package-relative application ID:
 
Error: (11/24/2020 03:15:11 PM) (Source: Application Error) (EventID: 1005) (User: )
Description: Windows cannot access the file C:\Program Files\Classic Shell\ClassicExplorer64.dll for one of the following reasons:
there is a problem with the network connection, the disk that the file is stored on, or the storage
drivers installed on this computer; or the disk is missing.
Windows closed the program Windows Explorer because of this error.
 
Program: Windows Explorer
File: C:\Program Files\Classic Shell\ClassicExplorer64.dll
 
The error value is listed in the Additional Data section.
User Action
1. Open the file again.
This situation might be a temporary problem that corrects itself when the program runs again.
2.
If the file still cannot be accessed and
- It is on the network,
your network administrator should verify that there is not a problem with the network and that the server can be contacted.
- It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the disk is fully inserted into the computer.
3. Check and repair the file system by running CHKDSK. To run CHKDSK, click Start, click Run, type CMD, and then click OK. At the command prompt, type CHKDSK /F, and then press ENTER.
4. If the problem persists, restore the file from a backup copy.
5. Determine whether other files on the same disk can be opened. If not, the disk might be damaged. If it is a hard disk, contact your administrator or computer hardware vendor for
further assistance.
 
Additional Data
Error value: C000009C
Disk type: 3
 
Error: (11/24/2020 03:15:11 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: explorer.exe, version: 10.0.19041.610, time stamp: 0xab30c679
Faulting module name: ntdll.dll, version: 10.0.19041.610, time stamp: 0xe5d7ed5c
Exception code: 0xc0000006
Fault offset: 0x0000000000032daf
Faulting process id: 0x3f04
Faulting application start time: 0x01d6c29e82be9966
Faulting application path: C:\WINDOWS\explorer.exe
Faulting module path: C:\WINDOWS\SYSTEM32\ntdll.dll
Report Id: a9b9b56b-7e0b-46b5-a9be-9887c12bf9b5
Faulting package full name: 
Faulting package-relative application ID:
 
Error: (11/24/2020 03:15:05 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: explorer.exe, version: 10.0.19041.610, time stamp: 0xab30c679
Faulting module name: ntdll.dll, version: 10.0.19041.610, time stamp: 0xe5d7ed5c
Exception code: 0xc000041d
Fault offset: 0x0000000000032daf
Faulting process id: 0xe28
Faulting application start time: 0x01d6c29e7c346d3b
Faulting application path: C:\WINDOWS\explorer.exe
Faulting module path: C:\WINDOWS\SYSTEM32\ntdll.dll
Report Id: 236065a7-1bb8-4486-b256-1e01cabe9b06
Faulting package full name: 
Faulting package-relative application ID:
 
Error: (11/24/2020 03:15:00 PM) (Source: Application Error) (EventID: 1005) (User: )
Description: Windows cannot access the file C:\Program Files\Classic Shell\ClassicExplorer64.dll for one of the following reasons:
there is a problem with the network connection, the disk that the file is stored on, or the storage
drivers installed on this computer; or the disk is missing.
Windows closed the program Windows Explorer because of this error.
 
Program: Windows Explorer
File: C:\Program Files\Classic Shell\ClassicExplorer64.dll
 
The error value is listed in the Additional Data section.
User Action
1. Open the file again.
This situation might be a temporary problem that corrects itself when the program runs again.
2.
If the file still cannot be accessed and
- It is on the network,
your network administrator should verify that there is not a problem with the network and that the server can be contacted.
- It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the disk is fully inserted into the computer.
3. Check and repair the file system by running CHKDSK. To run CHKDSK, click Start, click Run, type CMD, and then click OK. At the command prompt, type CHKDSK /F, and then press ENTER.
4. If the problem persists, restore the file from a backup copy.
5. Determine whether other files on the same disk can be opened. If not, the disk might be damaged. If it is a hard disk, contact your administrator or computer hardware vendor for
further assistance.
 
Additional Data
Error value: C000009C
Disk type: 3
 
Error: (11/24/2020 03:15:00 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: explorer.exe, version: 10.0.19041.610, time stamp: 0xab30c679
Faulting module name: ntdll.dll, version: 10.0.19041.610, time stamp: 0xe5d7ed5c
Exception code: 0xc0000006
Fault offset: 0x0000000000032daf
Faulting process id: 0xe28
Faulting application start time: 0x01d6c29e7c346d3b
Faulting application path: C:\WINDOWS\explorer.exe
Faulting module path: C:\WINDOWS\SYSTEM32\ntdll.dll
Report Id: d7d2b08d-4d92-4aea-a62a-7e2a82888613
Faulting package full name: 
Faulting package-relative application ID:
 
 
System errors:
=============
Error: (11/24/2020 03:25:45 PM) (Source: disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
 
Error: (11/24/2020 03:25:45 PM) (Source: disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
 
Error: (11/24/2020 03:25:45 PM) (Source: disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
 
Error: (11/24/2020 03:25:45 PM) (Source: disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
 
Error: (11/24/2020 03:25:45 PM) (Source: disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
 
Error: (11/24/2020 03:25:45 PM) (Source: disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
 
Error: (11/24/2020 03:25:45 PM) (Source: disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
 
Error: (11/24/2020 03:25:45 PM) (Source: disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.
 
 
Windows Defender:
===================================
Date: 2020-11-24 07:51:39.2750000Z
Description: 
Microsoft Defender Antivirus scan has been stopped before completion.
Scan ID: {29888965-64DF-4FD1-80FC-4591028DC240}
Scan Type: Antimalware
Scan Parameters: Quick Scan
 
Date: 2020-11-22 09:53:29.0620000Z
Description: 
Microsoft Defender Antivirus scan has been stopped before completion.
Scan ID: {33433CCA-C5FE-4615-BEFD-DD58D1C95CAD}
Scan Type: Antimalware
Scan Parameters: Quick Scan
 
Date: 2020-11-20 07:44:38.9920000Z
Description: 
Microsoft Defender Antivirus scan has been stopped before completion.
Scan ID: {650DFDAF-759F-4872-A288-D9381E14D0D3}
Scan Type: Antimalware
Scan Parameters: Quick Scan
 
Date: 2020-11-17 17:20:08.7700000Z
Description: 
Microsoft Defender Antivirus scan has been stopped before completion.
Scan ID: {9276FB2A-422D-462A-A12D-1209C5CE9F80}
Scan Type: Antimalware
Scan Parameters: Quick Scan
 
Date: 2020-11-13 07:17:51.5950000Z
Description: 
Microsoft Defender Antivirus scan has been stopped before completion.
Scan ID: {C03D2E39-FA76-4BDC-B7BE-F2250C5312E2}
Scan Type: Antimalware
Scan Parameters: Quick Scan
 
CodeIntegrity:
===================================
 
Date: 2020-11-19 09:13:32.7430000Z
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\WWAHost.exe) attempted to load \Device\HarddiskVolume4\Windows\System32\nvspcap64.dll that did not meet the Store signing level requirements.
 
Date: 2020-11-19 09:13:32.7230000Z
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\WWAHost.exe) attempted to load \Device\HarddiskVolume4\Windows\System32\nvspcap64.dll that did not meet the Store signing level requirements.
 
Date: 2020-11-19 09:11:48.9310000Z
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\WWAHost.exe) attempted to load \Device\HarddiskVolume4\Windows\System32\nvspcap64.dll that did not meet the Store signing level requirements.
 
Date: 2020-11-19 09:11:48.9100000Z
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\WWAHost.exe) attempted to load \Device\HarddiskVolume4\Windows\System32\nvspcap64.dll that did not meet the Store signing level requirements.
 
Date: 2020-11-19 08:57:15.2190000Z
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\WWAHost.exe) attempted to load \Device\HarddiskVolume4\Windows\System32\nvspcap64.dll that did not meet the Store signing level requirements.
 
Date: 2020-11-19 08:57:15.1990000Z
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\WWAHost.exe) attempted to load \Device\HarddiskVolume4\Windows\System32\nvspcap64.dll that did not meet the Store signing level requirements.
 
Date: 2020-11-19 08:55:25.0560000Z
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\WWAHost.exe) attempted to load \Device\HarddiskVolume4\Windows\System32\nvspcap64.dll that did not meet the Store signing level requirements.
 
Date: 2020-11-19 08:55:25.0350000Z
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\WWAHost.exe) attempted to load \Device\HarddiskVolume4\Windows\System32\nvspcap64.dll that did not meet the Store signing level requirements.
 
==================== Memory info =========================== 
 
BIOS: American Megatrends Inc. 2.90 04/02/2019
Motherboard: Micro-Star International Co., Ltd. Z370-A PRO (MS-7B48)
Processor: Intel(R) Core(TM) i9-9900K CPU @ 3.60GHz
Percentage of memory in use: 55%
Total physical RAM: 16329.23 MB
Available physical RAM: 7189.8 MB
Total Virtual: 31689.23 MB
Available Virtual: 18511.59 MB
 
==================== Drives ================================
 
Drive c: (Windows) (Fixed) (Total:930.91 GB) (Free:603.81 GB) NTFS
Drive d: (RYAN'S ASS) (Fixed) (Total:931.5 GB) (Free:857.6 GB) NTFS
 
\\?\Volume{31bb91c9-8523-498d-b807-e5ba54e3dd48}\ (Recovery) (Fixed) (Total:0.49 GB) (Free:0.07 GB) NTFS
\\?\Volume{949517f4-e82a-47ad-bd37-dd18dac20119}\ (SYSTEM) (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32
 
==================== MBR & Partition Table ====================
 
==========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: C7EADCAB)
 
Partition: GPT.
 
==========================================================
Disk: 1 (Protective MBR) (Size: 931.5 GB) (Disk ID: 00000000)
 
Partition: GPT.
 
==================== End of Addition.txt =======================

 

So sorry for the wait.
 
If you still need help,

Try doing a System Restore to a date prior to this problem?

No visible signs of malware so what we can do is a little bit of tidy-up and then run chkdsk


~~~
tart Farbar Recovery Scan Tool with Administrator privileges
(Right click on the FRST icon and select Run as administrator)

highlight on the text below and select Copy.
beginning with Start:: and finishing with End::
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Highlight the entire content of the quote box below and select Copy.

 

Start::
CloseProcesses:
CreateRestorePoint:
CustomCLSID: HKU\S-1-5-21-4234547216-3201928491-692415617-1003_Classes\CLSID\{CB965DF1-B8EA-49C7-BDAD-5457FDC1BF92}\InprocServer32 -> C:\Users\Karri Tougas\AppData\Local\Microsoft\TeamsMeetingAddin\1.0.20244.4\x64\Microsoft.Teams.AddinLoader.dll => No File
AlternateDataStreams: C:\Users\Karri Tougas\Desktop\20161113_164300.jpg:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Karri Tougas\Desktop\20161113_164300.jpg:com.dropbox.attrs [58]
AlternateDataStreams: C:\Users\Karri Tougas\Desktop\20200428_153527.jpg:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Karri Tougas\Desktop\20200504_190959.jpg:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Karri Tougas\Desktop\20200511_133133.jpg:com.dropbox.attrs [52]
AlternateDataStreams: C:\Users\Karri Tougas\Desktop\20200522_213446.mp4:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Karri Tougas\Desktop\20200604_185648.jpg:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Karri Tougas\Desktop\20200604_185754.jpg:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Karri Tougas\Desktop\20200730_163913.jpg:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Karri Tougas\Desktop\20200817_081715.jpg:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Karri Tougas\Desktop\20200818_122130.jpg:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Karri Tougas\Desktop\20200921_093141.jpg:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Karri Tougas\Desktop\20201023_160424.jpg:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Karri Tougas\Desktop\20201117_200754.jpg:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Karri Tougas\Desktop\EK001-12 - Get Here - Adams, Oleta.mp3:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Karri Tougas\Desktop\EK001-12 - Get Here - Adams, Oleta.mp3:com.dropbox.attrs [58]
AlternateDataStreams: C:\Users\Karri Tougas\Desktop\IMG_8577.jpg:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Karri Tougas\Desktop\Screenshot 2020-08-19 10.49.40.png:com.dropbox.attrs [54]
SearchScopes: HKU\S-1-5-21-4234547216-3201928491-692415617-1003 -> {DCD4E047-FB67-439A-9FD5-732F5B759F32} URL =
FirewallRules: [{6BCB31D9-2D21-432F-A522-B995B61FE45C}] => (Allow) C:\Users\Karri Tougas\AppData\Local\Temp\7zS1C70\HPDiagnosticCoreUI.exe => No File
FirewallRules: [{9018DF4E-F7AA-4471-95D0-8CB95D08854A}] => (Allow) C:\Users\Karri Tougas\AppData\Local\Temp\7zS1C70\HPDiagnosticCoreUI.exe => No File
FirewallRules: [{67A230B6-AD0B-4CB4-8F3B-54D956989293}] => (Allow) C:\Users\Karri Tougas\AppData\Local\Temp\7zS01A7\HPDiagnosticCoreUI.exe => No File
FirewallRules: [{C3B32228-A6F3-4BEE-BF76-2A23B5A84D78}] => (Allow) C:\Users\Karri Tougas\AppData\Local\Temp\7zS01A7\HPDiagnosticCoreUI.exe => No File
FirewallRules: [{B68C74B8-B3B8-4859-B046-ADE512396E3A}] => (Allow) C:\Users\Karri Tougas\AppData\Local\Temp\7zS0074\HPDiagnosticCoreUI.exe => No File
FirewallRules: [{EA6D6472-75D5-4D20-960D-C5F1E90FC95D}] => (Allow) C:\Users\Karri Tougas\AppData\Local\Temp\7zS0074\HPDiagnosticCoreUI.exe => No File
FirewallRules: [{3EAE5965-DDD4-4FDA-A912-9BDDD77C5327}] => (Allow) C:\Program Files (x86)\Apowersoft\Apowersoft Photo Viewer\Apowersoft Photo Viewer.exe => No File
FirewallRules: [{6984CBEF-0493-41EA-870F-1E084EBD556F}] => (Allow) C:\Program Files (x86)\Apowersoft\Apowersoft Photo Viewer\Apowersoft Photo Viewer.exe => No File
FirewallRules: [{FAFD4C35-1648-4243-9D16-DE89279C2ADE}] => (Allow) C:\Users\Karri Tougas\AppData\Roaming\Zoom\bin\airhost.exe => No File
FirewallRules: [{2917D066-57A2-48A5-B9FE-78CB0C141D93}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe => No File
FirewallRules: [{5C24FD6A-E97F-4A3A-897F-9FCFA0D95670}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe => No File
FirewallRules: [{D75AD9F8-BC2B-4BF5-8439-ECFC8A46E455}] => (Allow) C:\Users\Karri Tougas\AppData\Local\Temp\7zS0492\HPDiagnosticCoreUI.exe => No File
FirewallRules: [{52EE4BAB-CCA7-40AA-AD47-2D3473BDF225}] => (Allow) C:\Users\Karri Tougas\AppData\Local\Temp\7zS0492\HPDiagnosticCoreUI.exe => No File
FirewallRules: [{CD809EC1-643D-4BC0-ADE8-14E40DB79917}] => (Allow) C:\Users\Karri Tougas\AppData\Local\Temp\7zS080E\HPDiagnosticCoreUI.exe => No File
FirewallRules: [{632BD163-9F33-4BD1-A387-5A4F8BE4E08E}] => (Allow) C:\Users\Karri Tougas\AppData\Local\Temp\7zS080E\HPDiagnosticCoreUI.exe => No File
FirewallRules: [{2A174A68-1829-49D0-8940-268D4FA6E7E3}] => (Allow) C:\Users\Karri Tougas\AppData\Local\Temp\7zS7D9E\HPDiagnosticCoreUI.exe => No File
FirewallRules: [{166CE4CC-7944-4F5A-A377-47C761F7C2B9}] => (Allow) C:\Users\Karri Tougas\AppData\Local\Temp\7zS7D9E\HPDiagnosticCoreUI.exe => No File
FirewallRules: [{79C2F30F-3846-492E-AE45-EFDB25A6BE6E}] => (Allow) C:\Users\Karri Tougas\AppData\Local\Temp\7zS7F95\HPDiagnosticCoreUI.exe => No File
FirewallRules: [{084B78C6-A1F3-4FDA-B796-94955F131872}] => (Allow) C:\Users\Karri Tougas\AppData\Local\Temp\7zS7F95\HPDiagnosticCoreUI.exe => No File
EmptyTemp:
C:\Windows\Temp\*.*
End::

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


Start FRST (FRST64) with Administrator privileges
Press the Fix button. FRST will process the lines copied above from the clipboard.
When finished, a log file Fixlog.txt will pop up and saved in the same location the tool was ran from.

Please copy and paste its contents in your next reply.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Download and run AdwCleaner

Download AdwCleaner from here and save it to your desktop.

  • run AdwCleaner by clicking on Scan Now
  • when it has finished, leave everything that was found checked, (ticked), then click on Clean and Repair
  • if it asks to reboot, allow the reboot
  • on reboot, click on View Log File; please attach the content of the log to your next reply.

===============

After running the above scans

https://www.thewindowsclub.com/disk-error-checking-windows-8
Scroll down to ==> How to run CHKDSK in Windows 10


Please post the 2 logs when finished.

Hi Juliet, 

 

No worries. I wasn't able to go back to an earlier version but after a ton of troubleshooting I was able to determine that File Explorer was working in Safe Mode. After a chkdsk and scouring my eventviewer, I was able to determine that the issue was a corrupt .dll file. Once I repaired the program with the bad .dll, everything is back to working flawlessly.

 

I'm updating this in case anyone has the same issue. 

Hi Juliet, 

 

No worries. I wasn't able to go back to an earlier version but after a ton of troubleshooting I was able to determine that File Explorer was working in Safe Mode. After a chkdsk and scouring my eventviewer, I was able to determine that the issue was a corrupt .dll file. Once I repaired the program with the bad .dll, everything is back to working flawlessly.

 

I'm updating this in case anyone has the same issue. 

Here at home we had so much going on with the holiday I'm afraid I had overlooked you….so sorry.

I appreciate your reply back,  if nothing else is need let me know.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI