This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer running veeery slow and hard drive constantly spinning

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My laptop in the last two weeks had suddenly slowed down quite a bit - to the point where I sometimes have to do a reboot to see if it helps. The hard drive also seems to be constantly spinning a lot of the time, even though I'm not running anything intensive. I don't do anything other than surf the Internet and run word processing programs, so I'm not sure why things are suddenly slow. Lastly, my desktop wallpaper changed from yesterday, and I'm the only one who uses this computer. Why would that change? Something's going on.

 

FYI, I do have uTorrents installed, but I don't download anything illegal. I just use it to move really large files to my out-of-state family.

—

 

Farbar scan tool attached:

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 28-04-2021
Ran by [removed] (05-05-2021 15:34:49)
Running from C:\Users\[removed]\Downloads
Windows 10 Home Version 2004 19041.928 (X64) (2020-09-08 08:27:28)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-2242047713-980872803-1690996654-500 - Administrator - Enabled) => C:\Users\Administrator
DefaultAccount (S-1-5-21-2242047713-980872803-1690996654-503 - Limited - Disabled)
Guest (S-1-5-21-2242047713-980872803-1690996654-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-2242047713-980872803-1690996654-504 - Limited - Disabled)
young (S-1-5-21-2242047713-980872803-1690996654-1001 - Administrator - Enabled) => C:\Users\young

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

µTorrent (HKU\S-1-5-21-2242047713-980872803-1690996654-1001\…\uTorrent) (Version: 3.5.5.45852 - BitTorrent Inc.)
Adobe Acrobat Reader DC (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 21.001.20150 - Adobe Systems Incorporated)
Adobe Acrobat X Pro - English, Français, Deutsch (HKLM-x32\…\{AC76BA86-1033-F400-7760-000000000005}) (Version: 10.1.16 - Adobe Systems)
Adobe Creative Suite 6 Master Collection (HKLM-x32\…\{E8AD3069-9EB7-4BA8-8BFE-83F4E69355C0}) (Version: 6 - Adobe Systems Incorporated)
bl (HKLM-x32\…\{2A075BB4-E976-4278-BF3F-E5C6945D84C0}) (Version: 1.0.0 - Your Company Name) Hidden
Citrix Workspace 2008 (HKLM-x32\…\CitrixOnlinePluginPackWeb) (Version: 20.8.0.46 - Citrix Systems, Inc.)
EaseUS Tools M Beta 0.6.5 (HKLM-x32\…\D72C2F7D-B75E-4641-AFBE-199B95066617_is1) (Version:  - EaseUS)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 90.0.4430.93 - Google LLC)
GoToMeeting 10.16.0.19598 (HKU\S-1-5-21-2242047713-980872803-1690996654-1001\…\GoToMeeting) (Version: 10.16.0.19598 - LogMeIn, Inc.)
Icecream Screen Recorder version 4.50 (HKLM-x32\…\{7ADEC622-3230-4C9A-9DCE-9BD462B74095}_is1) (Version: 4.50 - Icecream Apps)
Intel® Optane™ Pinning Explorer Extensions (HKLM\…\{94979CD2-0904-47DE-A4AC-04F1C4524650}) (Version: 17.2.8.1029 - Intel Corporation)
Microsoft 365 - en-us (HKLM\…\O365HomePremRetail - en-us) (Version: 16.0.13929.20296 - Microsoft Corporation)
Microsoft Edge (HKLM-x32\…\Microsoft Edge) (Version: 90.0.818.51 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\…\Microsoft EdgeWebView) (Version: 90.0.818.51 - Microsoft Corporation)
Microsoft Office XP Media Content (HKLM-x32\…\{90300409-6000-11D3-8CFE-0050048383C9}) (Version: 10.0.2619.0 - Microsoft Corporation)
Microsoft Office XP Standard for Students and Teachers (HKLM-x32\…\{913D0409-6000-11D3-8CFE-0050048383C9}) (Version: 10.0.2627.0 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-2242047713-980872803-1690996654-1001\…\OneDriveSetup.exe) (Version: 21.062.0328.0001 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-2242047713-980872803-1690996654-500\…\OneDriveSetup.exe) (Version: 19.232.1124.0008 - Microsoft Corporation)
Microsoft SQL Server 2008 Setup Support Files  (HKLM-x32\…\{D441BD04-E548-4F8E-97A4-1B66135BAAA8}) (Version: 10.1.2731.0 - Microsoft Corporation)
Microsoft SQL Server 2012 (HKLM-x32\…\Microsoft SQL Server SQLServer2012) (Version:  - Microsoft Corporation)
Microsoft SQL Server 2012 Native Client  (HKLM\…\{49D665A2-4C2A-476E-9AB8-FCC425F526FC}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2012 Setup (English) (HKLM-x32\…\{FEC535DD-0EB2-4709-87BD-1708C6364EB6}) (Version: 11.1.3128.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Transact-SQL ScriptDom  (HKLM\…\{0E8670B8-3965-4930-ADA6-570348B67153}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\…\{A0E1B43D-5F4A-46AF-9925-ABA3423325DC}) (Version: 2.77.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\…\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\…\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.24.28127 (HKLM-x32\…\{282975d8-55fe-4991-bbbb-06a72581ce58}) (Version: 14.24.28127.4 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.24.28127 (HKLM-x32\…\{e31cb1a4-76b5-46a5-a084-3fa419e82201}) (Version: 14.24.28127.4 - Microsoft Corporation)
Microsoft VSS Writer for SQL Server 2012 (HKLM\…\{3E0DD83F-BE4C-4478-86A0-AD0D79D1353E}) (Version: 11.0.2100.60 - Microsoft Corporation)
Mozilla Firefox 88.0 (x64 en-US) (HKLM\…\Mozilla Firefox 88.0 (x64 en-US)) (Version: 88.0 - Mozilla)
Mozilla Maintenance Service (HKLM\…\MozillaMaintenanceService) (Version: 73.0.1 - Mozilla)
Office 16 Click-to-Run Extensibility Component (HKLM\…\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.13929.20296 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\…\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.13929.20296 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM\…\{90160000-008C-0409-1000-0000000FF1CE}) (Version: 16.0.13929.20216 - Microsoft Corporation) Hidden
Online Plug-in (HKLM-x32\…\{2DD52CE9-DE2C-4842-86EB-639E761F546D}) (Version: 20.8.0.24 - Citrix Systems, Inc.) Hidden
PDF Settings CS6 (HKLM-x32\…\{BFEAAE77-BD7F-4534-B286-9C5CB4697EB1}) (Version: 11.0 - Adobe Systems Incorporated) Hidden
ph (HKLM-x32\…\{185F9795-9663-4F13-9EF9-307A282ADB5A}) (Version: 1.0.0 - Your Company Name) Hidden
Self-service Plug-in (HKLM-x32\…\{12B40BBD-B0D8-4C37-AB68-CB27E49E2881}) (Version: 20.8.0.29 - Citrix Systems, Inc.) Hidden
Skype Meetings App (HKLM-x32\…\{BC1D9E47-8927-4AA1-A891-7763BC2475B7}) (Version: 16.2.0.511 - Microsoft Corporation)
SQL Server 2012 Common Files (HKLM-x32\…\{124D51A1-F3C2-45AE-B812-D3CA71247093}) (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server 2012 Common Files (HKLM-x32\…\{7D29ED63-84F9-4EC7-B49F-994A3A3195B2}) (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server 2012 Database Engine Services (HKLM-x32\…\{87D50333-E534-493A-8E98-0A49BC28F64B}) (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server 2012 Database Engine Services (HKLM-x32\…\{C22613C2-C7A4-4761-A906-116ECD4E7477}) (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server 2012 Database Engine Shared (HKLM-x32\…\{54F84805-0116-467F-8713-899DFC472235}) (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server 2012 Database Engine Shared (HKLM-x32\…\{D0F44C37-A22B-4733-BBA7-86C9F4988725}) (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server Browser for SQL Server 2012 (HKLM-x32\…\{4B9E6EB0-0EED-4E74-9479-F982C3254F71}) (Version: 11.0.2100.60 - Microsoft Corporation)
Sql Server Customer Experience Improvement Program (HKLM-x32\…\{30CA21F2-901A-44DB-A43F-FC31CD0F2493}) (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
TeamViewer (HKLM-x32\…\TeamViewer) (Version: 15.9.4 - TeamViewer)
VLC media player (HKLM-x32\…\VLC media player) (Version: 3.0.4 - VideoLAN)
WebM Project Directshow Filters (HKU\S-1-5-21-2242047713-980872803-1690996654-1001\…\webmdshow) (Version: 1.0.4.1 - WebM Project)
WinX DVD Ripper Platinum 8.20.3 (HKLM-x32\…\WinX DVD Ripper Platinum_is1) (Version:  - Digiarty Software, Inc.)
Xiph.Org Open Codecs 0.85.17777 (HKLM-x32\…\Open Codecs) (Version: 0.85.17777 - Xiph.Org)
Zoom (HKU\S-1-5-21-2242047713-980872803-1690996654-1001\…\ZoomUMX) (Version: 5.2.0 (42619.0804) - Zoom Video Communications, Inc.)

Packages:
=========
HP Audio Center -> C:\Program Files\WindowsApps\AD2F1837.HPAudioCenter_1.10.216.0_x64__v10z8vjag6ke6 [2020-09-14] (HP Inc.)
HP Privacy Settings -> C:\Program Files\WindowsApps\AD2F1837.HPPrivacySettings_1.0.42.0_x64__v10z8vjag6ke6 [2021-04-13] (HP Inc.)
Intel® Graphics Command Center -> C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.3282.0_x64__8j3eq9eme6ctt [2020-12-30] (INTEL CORP) [Startup Task]
Intel® Graphics Control Panel -> C:\Program Files\WindowsApps\AppUp.IntelGraphicsControlPanel_3.3.0.0_x64__8j3eq9eme6ctt [2021-02-08] (INTEL CORP)
Intel® Optane™ Memory and Storage Management -> C:\Program Files\WindowsApps\AppUp.IntelOptaneMemoryandStorageManagement_18.1.1015.0_x64__8j3eq9eme6ctt [2021-03-12] (INTEL CORP)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2020-03-01] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2020-03-01] (Microsoft Corporation) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.9.4213.0_x64__8wekyb3d8bbwe [2021-04-30] (Microsoft Studios) [MS Ad]
One Photo Viewer -> C:\Program Files\WindowsApps\48914EllipticPhenomena.OnePhotoViewer_1.14.2.0_neutral__8w313s78tpvfc [2021-03-17] (Elliptic Phenomena)
Photos Media Engine Add-on -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2020-03-08] (Microsoft Corporation)
Slow Motion Video -> C:\Program Files\WindowsApps\6291Lachlan.SlowMotionVideo_1.1.12.0_x64__kqhy9awb13v5j [2021-03-13] (Lachlan) [MS Ad]
VUDU Movies and TV -> C:\Program Files\WindowsApps\95FE1D22.VUDUMoviesandTV_1.1.244.0_x64__0wkekwh8d6p78 [2020-12-09] (VUDU Inc.)

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-2242047713-980872803-1690996654-1001_Classes\CLSID\{3E3AD4BD-346A-460A-80E8-90699B75C00B}\InprocServer32 -> C:\Users\young\AppData\Local\Microsoft\SkypeForBusinessPlugin\16.2.0.511\GatewayActiveX-x64.dll (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2242047713-980872803-1690996654-1001_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309}\InprocServer32 -> C:\Users\young\AppData\Local\GoToMeeting\16786\G2MOutlookAddin64.dll => No File
ShellIconOverlayIdentifiers: [  OptaneIconOverlay] -> {A3AF6F6C-8BED-3D93-8B5D-33427B5D38E9} => C:\WINDOWS\System32\DriverStore\FileRepository\iastorpinningcomponent.inf_amd64_a41f71ab3b5175b6\OptaneShellExt.dll [2020-07-09] (Intel(R) Rapid Storage Technology -> )
ContextMenuHandlers1: [Adobe.Acrobat.ContextMenu] -> {D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802} => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\..\Acrobat Elements\ContextMenu64.dll [2015-09-24] (Adobe Systems, Incorporated -> Adobe Systems Inc.)
ContextMenuHandlers3: [OptaneContextMenu] -> {AD7EBB13-617D-3270-8FA8-46583499C4FB} => C:\WINDOWS\System32\DriverStore\FileRepository\iastorpinningcomponent.inf_amd64_a41f71ab3b5175b6\OptaneShellExt.dll [2020-07-09] (Intel(R) Rapid Storage Technology -> )
ContextMenuHandlers6: [Adobe.Acrobat.ContextMenu] -> {D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802} => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\..\Acrobat Elements\ContextMenu64.dll [2015-09-24] (Adobe Systems, Incorporated -> Adobe Systems Inc.)

==================== Codecs (Whitelisted) ====================

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)

ShortcutWithArgument: C:\Users\young\Desktop\Claims\Accurence.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) ->  –profile-directory=Default –app-id=apdemjalhbjphbbmnibpneopekgmnclb
ShortcutWithArgument: C:\Users\young\Desktop\Claims\ERD.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) ->  –profile-directory=Default –app-id=fjhahnjekojlhchcdmpppimlbilkdmkn
ShortcutWithArgument: C:\Users\young\Desktop\Claims\Move to adjuster compter\Allstate Webpages\Accurence.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) ->  –profile-directory=Default –app-id=apdemjalhbjphbbmnibpneopekgmnclb
ShortcutWithArgument: C:\Users\young\Desktop\Claims\Move to adjuster compter\Allstate Webpages\ERD Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) ->  –profile-directory=Default –app-id=fjhahnjekojlhchcdmpppimlbilkdmkn
ShortcutWithArgument: C:\Users\young\Desktop\Claims\Hurricane Lara\Allstate Webpages\Allstate Webpages\Accurence.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) ->  –profile-directory=Default –app-id=apdemjalhbjphbbmnibpneopekgmnclb
ShortcutWithArgument: C:\Users\young\Desktop\Claims\Hurricane Lara\Allstate Webpages\Allstate Webpages\ERD Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) ->  –profile-directory=Default –app-id=fjhahnjekojlhchcdmpppimlbilkdmkn
ShortcutWithArgument: C:\Users\young\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Accurence.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) ->  –profile-directory=Default –app-id=apdemjalhbjphbbmnibpneopekgmnclb
ShortcutWithArgument: C:\Users\young\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\ERD.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) ->  –profile-directory=Default –app-id=fjhahnjekojlhchcdmpppimlbilkdmkn

==================== Loaded Modules (Whitelisted) =============

2000-11-06 12:15 - 2000-11-06 12:15 - 000126976 _____ () [File not signed] C:\Program Files (x86)\Microsoft Office\Office10\intldate.dll
2001-01-22 21:39 - 2001-01-22 21:39 - 002498560 _____ (Microsoft Corporation) [File not signed] [File is in use] C:\Program Files (x86)\Common Files\Microsoft Shared\VBA\VBA6\VBE6.DLL
2001-02-09 21:12 - 2001-02-09 21:12 - 000524339 _____ (Microsoft Corporation) [File not signed] C:\Program Files (x86)\Common Files\Microsoft Shared\office10\riched20.dll
2001-01-15 11:32 - 2001-01-15 11:32 - 000325120 _____ (Microsoft Corporation) [File not signed] C:\Program Files (x86)\Common Files\Microsoft Shared\Office10\usp10.dll
2000-11-03 21:39 - 2000-11-03 21:39 - 003346432 _____ (Microsoft Corporation) [File not signed] C:\Program Files (x86)\Common Files\Microsoft Shared\Proof\1033\MSGR3EN.DLL
1998-11-05 08:27 - 1998-11-05 08:27 - 000536576 _____ (Microsoft Corporation) [File not signed] C:\Program Files (x86)\Common Files\Microsoft Shared\Proof\mslid.dll
2000-07-17 15:09 - 2000-07-17 15:09 - 000077824 _____ (Microsoft Corporation) [File not signed] C:\Program Files (x86)\Common Files\Microsoft Shared\Proof\MSSPELL3.DLL
2001-01-22 21:39 - 2001-01-22 21:39 - 000159744 _____ (Microsoft Corporation) [File not signed] C:\Program Files (x86)\Common Files\Microsoft Shared\VBA\VBA6\1033\VBE6INTL.DLL

==================== Alternate Data Streams (Whitelisted) ========

==================== Safe Mode (Whitelisted) ==================

==================== Association (Whitelisted) =================

==================== Internet Explorer (Whitelisted) ==========

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://hp17win10.msn.com/?pc=HCTE
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp17win10.msn.com/?pc=HCTE
HKU\S-1-5-21-2242047713-980872803-1690996654-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp17win10.msn.com/?pc=HCTE
HKU\S-1-5-21-2242047713-980872803-1690996654-500\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://hp17win10.msn.com/?pc=HCTE
HKU\S-1-5-21-2242047713-980872803-1690996654-500\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp17win10.msn.com/?pc=HCTE
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2021-03-03] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2015-09-24] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
BHO-x32: SmartSelect Class -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2015-09-24] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2015-09-24] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
DPF: HKLM-x32 {D171451B-94CB-4952-98E9-77D25F23F10D} hxxps://claimaccess.allstate.com/ngaa/AllstateCTSNG/Desktop/EComm/VSSPELL8.CAB
Handler-x32: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files (x86)\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL [2001-01-22] (Microsoft Corporation) [File not signed]
Handler-x32: http - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll [2001-02-12] (Microsoft Corporation) [File not signed]
Handler-x32: http - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll [2001-02-12] (Microsoft Corporation) [File not signed]
Handler-x32: https - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll [2001-02-12] (Microsoft Corporation) [File not signed]
Handler-x32: https - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll [2001-02-12] (Microsoft Corporation) [File not signed]
Handler-x32: msdaipp - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll [2001-02-12] (Microsoft Corporation) [File not signed]
Handler-x32: msdaipp - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll [2001-02-12] (Microsoft Corporation) [File not signed]
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2021-05-02] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2021-05-02] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2021-05-02] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2021-05-02] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2021-05-02] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2021-05-02] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2021-05-02] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2021-05-02] (Microsoft Corporation -> Microsoft Corporation)
Filter-x32: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2020-08-18] (Citrix Systems, Inc. -> Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2020-08-18] (Citrix Systems, Inc. -> Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2020-08-18] (Citrix Systems, Inc. -> Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2020-08-18] (Citrix Systems, Inc. -> Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2020-08-18] (Citrix Systems, Inc. -> Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2020-08-18] (Citrix Systems, Inc. -> Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2020-08-18] (Citrix Systems, Inc. -> Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2020-08-18] (Citrix Systems, Inc. -> Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2020-08-18] (Citrix Systems, Inc. -> Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2020-08-18] (Citrix Systems, Inc. -> Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2020-08-18] (Citrix Systems, Inc. -> Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2020-08-18] (Citrix Systems, Inc. -> Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2020-08-18] (Citrix Systems, Inc. -> Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2020-08-18] (Citrix Systems, Inc. -> Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2020-08-18] (Citrix Systems, Inc. -> Citrix Systems, Inc.)
Filter-x32: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2020-08-18] (Citrix Systems, Inc. -> Citrix Systems, Inc.)

(If an entry is included in the fixlist, it will be removed from the registry.)

IE trusted site: HKU\S-1-5-21-2242047713-980872803-1690996654-1001\…\allstate.com -> allstate.com
IE trusted site: HKU\S-1-5-21-2242047713-980872803-1690996654-1001\…\pilotcat.com -> pilotcat.com
IE trusted site: HKU\S-1-5-21-2242047713-980872803-1690996654-1001\…\surfshark.com -> hxxps://surfshark.com

==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2019-03-19 00:49 - 2020-03-07 17:42 - 000001028 _____ C:\WINDOWS\system32\drivers\etc\hosts
127.0.0.1                   activate.adobe.com
127.0.0.1                   practivate.adobe.com
127.0.0.1                   lmlicenses.wip4.adobe.com
127.0.0.1                   lm.licenses.adobe.com

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-2242047713-980872803-1690996654-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\young\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\guyfieri.jpg
HKU\S-1-5-21-2242047713-980872803-1690996654-500\Control Panel\Desktop\\Wallpaper -> C:\windows\web\wallpaper\HP Backgrounds\backgroundDefault.jpg
DNS Servers: [removed] - [removed]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(If an entry is included in the fixlist, it will be removed.)

HKLM\…\StartupApproved\Run: => "RtkAudUService"
HKLM\…\StartupApproved\Run: => "RtlS5Wake"
HKLM\…\StartupApproved\Run: => "WindowsDefender"
HKLM\…\StartupApproved\Run: => "AdobeAAMUpdater-1.0"
HKLM\…\StartupApproved\Run: => "Data Migration Tool"
HKLM\…\StartupApproved\Run32: => "AdobeCS6ServiceManager"
HKLM\…\StartupApproved\Run32: => "SwitchBoard"
HKLM\…\StartupApproved\Run32: => "ConnectionCenter"
HKLM\…\StartupApproved\Run32: => "Redirector"
HKLM\…\StartupApproved\Run32: => "XCDownloadApplet"
HKLM\…\StartupApproved\Run32: => "EaseUS FixTool"
HKLM\…\StartupApproved\Run32: => "Adobe Acrobat Speed Launcher"
HKU\S-1-5-21-2242047713-980872803-1690996654-1001\…\StartupApproved\Run: => "HPSEU_Host_Launcher"
HKU\S-1-5-21-2242047713-980872803-1690996654-1001\…\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-2242047713-980872803-1690996654-1001\…\StartupApproved\Run: => "GoToMeeting"
HKU\S-1-5-21-2242047713-980872803-1690996654-1001\…\StartupApproved\Run: => "uTorrent"
HKU\S-1-5-21-2242047713-980872803-1690996654-1001\…\StartupApproved\Run: => "3FDB53E6025D31ACCA9E8EA7D3615DB60EAE8958._service_run"

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [UDP Query User{94B08DB1-C795-4325-8B27-FB62948DB85F}C:\users\young\appdata\local\microsoft\skypeforbusinessplugin\16.2.0.511\pluginhost.exe] => (Allow) C:\users\young\appdata\local\microsoft\skypeforbusinessplugin\16.2.0.511\pluginhost.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [TCP Query User{3B2969FD-9B26-4E4F-99F0-1FAD91C341F9}C:\users\young\appdata\local\microsoft\skypeforbusinessplugin\16.2.0.511\pluginhost.exe] => (Allow) C:\users\young\appdata\local\microsoft\skypeforbusinessplugin\16.2.0.511\pluginhost.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{FA7E0A5E-8072-4855-B490-46136D079E1F}] => (Allow) C:\Users\young\AppData\Roaming\Zoom\bin\airhost.exe => No File
FirewallRules: [{D8CCC298-CCFA-4630-B289-F46203924683}] => (Allow) C:\Users\young\AppData\Roaming\Zoom\bin\Zoom.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FirewallRules: [{D1A38A40-A7C9-4F06-868D-8D0A34615A6B}] => (Allow) LPort=7935
FirewallRules: [{EF175066-4B3B-40E7-B2B5-BDB2683621B7}] => (Allow) C:\Program Files (x86)\Adobe\Adobe Flash Builder 4.6\FlashBuilder.exe (Adobe Systems Incorporated -> )
FirewallRules: [{91615912-D203-4D56-9472-E0A99E9F7B8E}] => (Allow) C:\Program Files (x86)\Adobe\Adobe Flash Builder 4.6\FlashBuilder.exe (Adobe Systems Incorporated -> )
FirewallRules: [{DE76BBFF-3A6B-4611-8FAA-CC164B90A8AC}] => (Allow) C:\Users\young\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{B0A989BB-B4EA-4782-AA10-6859A92AB184}] => (Allow) C:\Users\young\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{C6A12427-3085-48C5-80C7-35B0765A2D9F}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{2AAC56DE-AD82-4CAE-BC7C-D84B2665F5D6}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{62897341-874B-4DC3-AA97-AB1382463D1B}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{DE6D4A31-5CB7-4688-9EE8-8B7509117026}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{01812A90-D801-4B11-9F3D-DDCDA610CA01}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{673BC802-A6D5-428F-A18C-BF5026F3FAB0}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [TCP Query User{EFA75C2D-52A7-4E63-AAD6-FE62F362F070}C:\program files\mozilla firefox\firefox.exe] => (Allow) C:\program files\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [UDP Query User{9605A672-EC18-4E2B-8519-037654A15381}C:\program files\mozilla firefox\firefox.exe] => (Allow) C:\program files\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{4A64380C-3132-4E33-B0F4-758F898BF5A8}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.68.96.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{97D70DC8-A0FF-48EC-B068-28AD8C520A48}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.68.96.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{5DE0F30C-7D43-4ED3-9217-1DD3FA77FC2D}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.68.96.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{823863C4-199B-4D8E-9822-5C2186C5DA92}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.68.96.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [TCP Query User{0F8E9BAF-44B8-4E23-80E4-D9F3E70298DF}C:\program files (x86)\5kplayer\5kplayer.exe] => (Allow) C:\program files (x86)\5kplayer\5kplayer.exe => No File
FirewallRules: [UDP Query User{9BB8CDA2-6C74-498E-8919-2431125AF5D2}C:\program files (x86)\5kplayer\5kplayer.exe] => (Allow) C:\program files (x86)\5kplayer\5kplayer.exe => No File
FirewallRules: [{FEE7BA8C-D796-4DF7-83AC-BE09AEF17E5F}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{3CE34051-360E-43C5-BDD7-E11D05B54999}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\90.0.818.51\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{0025C4DD-E760-44C6-A1AD-C62840771A7F}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)

==================== Restore Points =========================

28-04-2021 21:43:00 Scheduled Checkpoint

==================== Faulty Device Manager Devices ============

Name: System Firmware
Description: System Firmware
Class Guid: {f2e7dd72-6468-4e36-b6f1-6488f42c1b52}
Manufacturer: HP Inc.
Service:
Problem: : This device cannot work properly until you restart your computer. (Code14)
Resolution: Restart your computer.


==================== Event log errors: ========================

Application errors:
==================
Error: (05/05/2021 03:03:07 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program Photoshop.exe version 13.0.0.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.

Process ID: 32e0

Start Time: 01d73e53ba96b113

Termination Time: 4294967295

Application Path: C:\Program Files\Adobe\Adobe Photoshop CS6 (64 Bit)\Photoshop.exe

Report Id: defbc70a-b813-493c-8338-92cf096aaef8

Faulting package full name:

Faulting package-relative application ID:

Hang type: Top level window is idle

Error: (05/05/2021 03:02:51 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program firefox.exe version 88.0.0.7775 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.

Process ID: 474c

Start Time: 01d73e07ab5080e4

Termination Time: 4294967295

Application Path: C:\Program Files\Mozilla Firefox\firefox.exe

Report Id: 428596bb-9869-425f-a1f8-6b6ba1fa0ade

Faulting package full name:

Faulting package-relative application ID:

Hang type: Top level window is idle

Error: (05/02/2021 06:27:12 PM) (Source: Windows Search Service) (EventID: 3007) (User: )
Description: Performance monitoring cannot be initialized for the gatherer object, because the counters are not loaded or the shared memory object cannot be opened. This only affects availability of the perfmon counters. Restart the computer.

Context:  Application, SystemIndex Catalog

Error: (04/28/2021 01:00:57 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: AUDIODG.EXE, version: 10.0.19041.906, time stamp: 0x985b4154
Faulting module name: ntdll.dll, version: 10.0.19041.928, time stamp: 0x9bed63d6
Exception code: 0xc0000005
Fault offset: 0x000000000001c286
Faulting process id: 0x2aa0
Faulting application start time: 0x01d73c038334a13f
Faulting application path: C:\WINDOWS\system32\AUDIODG.EXE
Faulting module path: C:\WINDOWS\SYSTEM32\ntdll.dll
Report Id: 2c42cba4-03f0-430d-b6cf-734b28fe61ad
Faulting package full name:
Faulting package-relative application ID:

Error: (04/22/2021 12:04:12 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program Microsoft.Photos.exe version 2020.20120.4004.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.

Process ID: 904

Start Time: 01d7372e469994d0

Termination Time: 4294967295

Application Path: C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2020.20120.4004.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe

Report Id: 85b7362c-b349-4717-a574-fd90a637ddc4

Faulting package full name: Microsoft.Windows.Photos_2020.20120.4004.0_x64__8wekyb3d8bbwe

Faulting package-relative application ID: App

Hang type: Quiesce

Error: (04/18/2021 08:07:01 PM) (Source: Firefox Default Browser Agent) (EventID: 12007) (User: )
Description: Event-ID 12007

Error: (04/18/2021 08:07:01 PM) (Source: Firefox Default Browser Agent) (EventID: 0) (User: )
Description: Event-ID 0

Error: (04/17/2021 03:24:50 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance.  hr = 0x8007045b, A system shutdown is in progress.
.


System errors:
=============
Error: (05/02/2021 07:36:17 PM) (Source: DCOM) (EventID: 10010) (User: LAPTOP-6R6IN514)
Description: The server microsoft.windowscommunicationsapps_16005.13426.20920.0_x64__8wekyb3d8bbwe!microsoft.windowslive.calendar.AppXwkn9j84yh1kvnt49k5r8h6y1ecsv09hs.mca did not register with DCOM within the required timeout.

Error: (05/01/2021 11:22:19 PM) (Source: DCOM) (EventID: 10010) (User: LAPTOP-6R6IN514)
Description: The server microsoft.windowscommunicationsapps_16005.13426.20920.0_x64__8wekyb3d8bbwe!microsoft.windowslive.calendar.AppXwkn9j84yh1kvnt49k5r8h6y1ecsv09hs.mca did not register with DCOM within the required timeout.

Error: (04/30/2021 03:29:41 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Microsoft Defender Antivirus Network Inspection Service service failed to start due to the following error:
The service did not respond to the start or control request in a timely fashion.

Error: (04/30/2021 03:29:41 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Microsoft Defender Antivirus Network Inspection Service service to connect.

Error: (04/30/2021 03:26:58 PM) (Source: DCOM) (EventID: 10010) (User: LAPTOP-6R6IN514)
Description: The server {94269C4E-071A-4116-90E6-52E557067E4E} did not register with DCOM within the required timeout.

Error: (04/30/2021 11:22:23 AM) (Source: Schannel) (EventID: 4103) (User: NT AUTHORITY)
Description: A fatal error occurred while creating a TLS client credential. The internal error state is 10013.

Error: (04/27/2021 10:36:43 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The NcbService service terminated with the following error:
A device attached to the system is not functioning.

Error: (04/27/2021 10:36:23 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 10:12:48 PM on ‎4/‎27/‎2021 was unexpected.


Windows Defender:
================
Date: 2021-05-02 13:40:36
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2021-05-01 14:45:27
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2021-04-30 17:53:34
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2021-04-29 13:24:03
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2021-04-28 14:19:40
Description:
Microsoft Defender Antivirus scan has been stopped before completion.
Scan Type: Antimalware
Scan Parameters: Quick Scan

==================== Memory info ===========================

BIOS: Insyde F.33 10/08/2020
Motherboard: HP 85EF
Processor: Intel(R) Core(TM) i3-8145U CPU @ 2.10GHz
Percentage of memory in use: 64%
Total physical RAM: 8079.3 MB
Available physical RAM: 2868.16 MB
Total Virtual: 12943.3 MB
Available Virtual: 5358.41 MB

==================== Drives ================================

Drive c: (Windows) (Fixed) (Total:930.7 GB) (Free:438.79 GB) NTFS

\\?\Volume{a262b600-9771-4112-b2f6-4e4dd0d6ad5c}\ () (Fixed) (Total:0.54 GB) (Free:0.08 GB) NTFS
\\?\Volume{dbc9bedb-b95e-4778-8596-5f67c7ca7135}\ (SYSTEM) (Fixed) (Total:0.25 GB) (Free:0.17 GB) FAT32

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: D43069B4)

Partition: GPT.

==================== End of Addition.txt =======================

When you ran Farbar Recovery Scan Tool (FRST) Scan

Two logs should had been created
FRST.txt & Addition.txt

You posted the Addition.txt, now can I have you search for and copy and paste in the FRST.txt

Sorry about that. Not familiar with Farbar. Here it is.

 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 28-04-2021
Ran by [removed] (administrator) on LAPTOP-6R6IN514 (HP HP Laptop 15-dw0xxx) (05-05-2021 15:28:25)
Running from C:\Users\[removed]\Downloads
[removed] Platform: Windows 10 Home Version 2004 19041.928 (X64) Language: English (United States)
Default browser: IE
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Adobe Systems Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
(Adobe Systems, Incorporated -> Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
(Citrix Systems, Inc. -> Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\Receiver\UpdaterService.exe
(ELAN MICROELECTRONICS CORPORATION -> ELAN Microelectronics Corp.) C:\Windows\System32\ETDCtrl.exe
(ELAN MICROELECTRONICS CORPORATION -> ELAN Microelectronics Corp.) C:\Windows\System32\ETDService.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.82\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.82\GoogleCrashHandler64.exe
(HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpanalyticscomp.inf_amd64_eb7ea98d07646ece\x64\TouchpointAnalyticsClientService.exe
(HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_d9cbd6bbac564232\x64\AppHelperCap.exe
(HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_d9cbd6bbac564232\x64\DiagsCap.exe
(HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_d9cbd6bbac564232\x64\NetworkCap.exe
(HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_d9cbd6bbac564232\x64\SysInfoCap.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dptf_cpu.inf_amd64_9196e89091d8bdbb\esif_uf.exe
(Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_ffc75848a6342fdf\jhi_service.exe
(Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_efb119a73d6b56f6\igfxCUIService.exe
(Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_efb119a73d6b56f6\igfxEM.exe
(Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_577b4722c749a41f\OneApp.IGCC.WinService.exe
(Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_2b1d9e395a05d1c9\IntelCpHDCPSvc.exe
(Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_2b1d9e395a05d1c9\IntelCpHeciSvc.exe
(Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iastorac.inf_amd64_42f9d9bfb72d84cf\RstMwService.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office10\WINWORD.EXE
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft SQL Server\MSSQL11.XACTWARE\MSSQL\Binn\sqlservr.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\young\AppData\Local\Microsoft\OneDrive\21.062.0328.0001\FileCoAuth.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.BingWeather_4.46.31121.0_x64__8wekyb3d8bbwe\Microsoft.Msn.Weather.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_12104.1001.1.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Microsoft Windows -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe <2>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\splwow64.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <3>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MusNotifyIcon.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\oobe\UserOOBEBroker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Windows Hardware Compatibility Publisher -> Realtek Semiconductor Corp.) C:\Windows\RtkBtManServ.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2104.9-0\MsMpEng.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2104.9-0\NisSrv.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <11>
(Raberles Investments Ltd -> Icecream) C:\Program Files (x86)\Icecream Screen Recorder\recorder.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\RtkAudUService64.exe
(Sound Research Corporation -> Sound Research, Corp.) C:\Windows\System32\SECOCL64.exe
(Sound Research Corporation -> Sound Research, Corp.) C:\Windows\System32\SECOMN64.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(WildTangent Inc -> ) C:\Program Files (x86)\WildTangent Games\Integration\WildTangentHelperService.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\…\Run: [RtkAudUService] => C:\WINDOWS\System32\RtkAudUService64.exe [1076000 2020-03-30] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\…\Run: [RtlS5Wake] => C:\Program Files (x86)\Realtek\PCIE Wireless LAN\RtlS5Wake\RtlS5Wake.exe [2097600 2018-04-17] (Realtek Semiconductor Corp. -> Realtek)
HKLM\…\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM-x32\…\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Test Signing Certificate -> Adobe Systems Incorporated) [File not signed]
HKLM-x32\…\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM-x32\…\Run: [Adobe Acrobat Speed Launcher] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [41360 2015-09-24] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
HKLM-x32\…\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [840592 2015-09-24] (Adobe Systems, Incorporated -> Adobe Systems Inc.)
HKLM-x32\…\Run: [EaseUS FixTool] => C:\Program Files (x86)\EaseUS\EaseUS Tools M\bin\UpdateExe.exe [132776 2020-01-14] (CHENGDU YIWO Tech Development Co., Ltd. -> )
HKLM-x32\…\Run: [ConnectionCenter] => C:\Program Files (x86)\Citrix\ICA Client\concentr.exe [904288 2020-08-18] (Citrix Systems, Inc. -> Citrix Systems, Inc.)
HKLM-x32\…\Run: [Redirector] => C:\Program Files (x86)\Citrix\ICA Client\redirector.exe [460896 2020-08-18] (Citrix Systems, Inc. -> Citrix Systems, Inc.)
HKLM-x32\…\Run: [] => [X]
HKU\S-1-5-19\…\Run: [HPSEU_Host_Launcher] => C:\System.sav\util\HpseuHostLauncher.exe [1114112 2019-05-10] (HP Inc.) [File not signed]
HKU\S-1-5-20\…\Run: [HPSEU_Host_Launcher] => C:\System.sav\util\HpseuHostLauncher.exe [1114112 2019-05-10] (HP Inc.) [File not signed]
HKU\S-1-5-21-2242047713-980872803-1690996654-1001\…\Run: [HPSEU_Host_Launcher] => C:\System.sav\util\HpseuHostLauncher.exe [1114112 2019-05-10] (HP Inc.) [File not signed]
HKU\S-1-5-21-2242047713-980872803-1690996654-1001\…\Run: [uTorrent] => C:\Users\young\AppData\Roaming\uTorrent\uTorrent.exe [2142936 2021-01-05] (BitTorrent Inc -> BitTorrent Inc.)
HKU\S-1-5-21-2242047713-980872803-1690996654-1001\…\Run: [3FDB53E6025D31ACCA9E8EA7D3615DB60EAE8958._service_run] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" –type=service /prefetch:8
HKU\S-1-5-21-2242047713-980872803-1690996654-1001\…\RunOnce: [Delete Cached Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\young\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe"
HKU\S-1-5-21-2242047713-980872803-1690996654-1001\…\RunOnce: [Delete Cached Standalone Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Users\young\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe"
HKU\S-1-5-21-2242047713-980872803-1690996654-1001\…\RunOnce: [Uninstall 21.052.0314.0001\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\young\AppData\Local\Microsoft\OneDrive\21.052.0314.0001\amd64"
HKU\S-1-5-21-2242047713-980872803-1690996654-1001\…\RunOnce: [Uninstall 21.052.0314.0001] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\young\AppData\Local\Microsoft\OneDrive\21.052.0314.0001"
HKU\S-1-5-21-2242047713-980872803-1690996654-500\…\Run: [HPSEU_Host_Launcher] => C:\System.sav\util\HpseuHostLauncher.exe [1114112 2019-05-10] (HP Inc.) [File not signed]
HKLM\…\Print\Monitors\Adobe PDF Port Monitor: C:\WINDOWS\system32\AdobePDF.dll [55872 2015-09-24] (Adobe Systems, Incorporated -> Adobe Systems Inc)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\90.0.4430.93\Installer\chrmstp.exe [2021-04-26] (Google LLC -> Google LLC)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{73FA19D0-2D75-11D2-995D-00C04F98BBC9}] ->
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk [2020-03-02]
ShortcutTarget: Microsoft Office.lnk -> C:\Program Files (x86)\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation -> Microsoft Corporation)

==================== Scheduled Tasks (Whitelisted) ============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {010AA101-6B5C-447B-B7F5-D74BB137B617} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [141144 2021-05-02] (Microsoft Corporation -> Microsoft Corporation)
Task: {1A9C20EC-A198-4906-AACF-2D8ED4693C96} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2104.9-0\MpCmdRun.exe [591168 2021-05-05] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {1ED65B7F-684D-4403-A5A2-1308109F138C} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156104 2020-07-14] (Google LLC -> Google LLC)
Task: {25B0917F-3B6B-4DD2-B22D-49CCE7AE180F} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [1099640 2020-03-09] (HP Inc. -> HP Inc.)
Task: {2B3F9615-9041-4F25-8F77-589EDDC1FFAF} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2104.9-0\MpCmdRun.exe [591168 2021-05-05] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {2DAD7EEE-6D9F-47F0-A09A-9D8C06A42FDD} - System32\Tasks\G2MUpdateTask-S-1-5-21-2242047713-980872803-1690996654-1001 => C:\Users\young\AppData\Local\GoToMeeting\19598\g2mupdate.exe [31320 2021-04-09] (LogMeIn, Inc. -> LogMeIn, Inc.)
Task: {52261021-7F4C-4DDA-969C-18E715BB6FAC} - System32\Tasks\G2MUploadTask-S-1-5-21-2242047713-980872803-1690996654-1001 => C:\Users\young\AppData\Local\GoToMeeting\19598\g2mupload.exe [31320 2021-04-09] (LogMeIn, Inc. -> LogMeIn, Inc.)
Task: {7BB44CFA-08A6-4A5A-BD79-C6E422824A58} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [1099640 2020-03-09] (HP Inc. -> HP Inc.)
Task: {901A8671-864A-41E2-9284-CD72DF78916F} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1557200 2021-01-25] (Adobe Inc. -> Adobe Inc.)
Task: {94BF8624-8BCC-4E7F-A2DE-72573EA581D3} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPSFReport.exe [147320 2020-03-09] (HP Inc. -> HP Inc.)
Task: {ABD2DB27-BE5D-4512-B3E0-01DD13D247B9} - System32\Tasks\HP\Consent Manager Launcher => sc start hptouchpointanalyticsservice
Task: {ADCE5FFB-146C-47A4-A886-9ABC3DB878FD} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23103392 2021-04-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {B0D350BD-5071-4C9E-A82A-13E94CE2E3AF} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [141144 2021-05-02] (Microsoft Corporation -> Microsoft Corporation)
Task: {B1C6ECE9-19F0-4490-8354-5EF2F821B07D} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2104.9-0\MpCmdRun.exe [591168 2021-05-05] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {C3E3120D-2F8F-4DE6-A901-75649F923B9F} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2104.9-0\MpCmdRun.exe [591168 2021-05-05] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {D27CF1D8-05D3-457B-B15E-D8131C071A4A} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [696304 2021-04-22] (Mozilla Corporation -> Mozilla Foundation)
Task: {EDB81EFE-FEEE-4B3C-B999-631744E65795} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23103392 2021-04-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {F04C128C-359A-4D5B-A9F0-B311DC422A6C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156104 2020-07-14] (Google LLC -> Google LLC)
Task: {FDE874A7-9493-46E1-A871-8430B1717473} - System32\Tasks\[removed] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated -> Adobe Systems Incorporated)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-2242047713-980872803-1690996654-1001.job => C:\Users\young\AppData\Local\GoToMeeting\19598\g2mupdate.exe
Task: C:\WINDOWS\Tasks\G2MUploadTask-S-1-5-21-2242047713-980872803-1690996654-1001.job => C:\Users\young\AppData\Local\GoToMeeting\19598\g2mupload.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] [removed] [removed]
Tcpip\..\Interfaces\{43f43aaa-5f1b-422d-b3cf-6e907129b7c2}: [DhcpNameServer] [removed] [removed]
Tcpip\..\Interfaces\{94405d69-9694-4e12-b88c-309919e46921}: [DhcpNameServer] [removed] [removed]

Edge:
=======
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
Edge Profile: C:\Users\young\AppData\Local\Microsoft\Edge\User Data\Default [2021-05-05]

FireFox:
========
FF DefaultProfile: vejzafav.default
FF ProfilePath: C:\Users\young\AppData\Roaming\Mozilla\Firefox\Profiles\vejzafav.default [2020-02-29]
FF ProfilePath: C:\Users\young\AppData\Roaming\Mozilla\Firefox\Profiles\qz9fvi9b.default-release [2021-05-05]
FF Homepage: Mozilla\Firefox\Profiles\qz9fvi9b.default-release -> www.duckduckgo.com
FF Notifications: Mozilla\Firefox\Profiles\qz9fvi9b.default-release -> hxxps://ptsemail.pilotcat.com
FF Extension: (AdBlock — best ad blocker) - C:\Users\young\AppData\Roaming\Mozilla\Firefox\Profiles\qz9fvi9b.default-release\Extensions\[removed] [2021-04-13]
FF Extension: (AdBlocker for YouTube™) - C:\Users\young\AppData\Roaming\Mozilla\Firefox\Profiles\qz9fvi9b.default-release\Extensions\[removed] [2020-11-23]
FF Extension: (uBlock Origin) - C:\Users\young\AppData\Roaming\Mozilla\Firefox\Profiles\qz9fvi9b.default-release\Extensions\[removed] [2021-05-05]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn
FF Extension: (Adobe Acrobat - Create PDF) - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2021-04-22] [Legacy] [not signed]
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2021-05-02] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @Citrix.com/npican -> C:\Program Files (x86)\Citrix\ICA Client\npicaN.dll [2020-08-18] (Citrix Systems, Inc. -> Citrix Systems, Inc.)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2021-03-03] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=3.0.4 -> C:\Program Files (x86)\VLC\npvlc.dll [2018-08-09] (VideoLAN -> VideoLAN)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll [2015-09-24] (Adobe Systems, Incorporated -> Adobe Systems Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2021-04-20] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2242047713-980872803-1690996654-1001: SkypeForBusinessPlugin-16.2 -> C:\Users\young\AppData\Local\Microsoft\SkypeForBusinessPlugin\16.2.0.511\npGatewayNpapi.dll [2019-08-03] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin HKU\S-1-5-21-2242047713-980872803-1690996654-1001: SkypeForBusinessPlugin64-16.2 -> C:\Users\young\AppData\Local\Microsoft\SkypeForBusinessPlugin\16.2.0.511\npGatewayNpapi-x64.dll [2019-08-03] (Microsoft Corporation -> Microsoft Corporation)

Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\young\AppData\Local\Google\Chrome\User Data\Default [2021-05-01]
CHR StartupUrls: Default -> "hxxp://www.google.com/"
CHR DefaultSearchURL: Default -> hxxps://erd.allstate.com/vpn/images/AccessGateway.ico
CHR Extension: (Slides) - C:\Users\young\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2020-07-14]
CHR Extension: (Docs) - C:\Users\young\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2020-07-14]
CHR Extension: (Accurence) - C:\Users\young\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdemjalhbjphbbmnibpneopekgmnclb [2020-09-01]
CHR Extension: (Google Drive) - C:\Users\young\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-10-26]
CHR Extension: (YouTube) - C:\Users\young\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2020-07-14]
CHR Extension: (Sheets) - C:\Users\young\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2020-07-14]
CHR Extension: (ERD) - C:\Users\young\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjhahnjekojlhchcdmpppimlbilkdmkn [2020-09-01]
CHR Extension: (Google Docs Offline) - C:\Users\young\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2021-04-27]
CHR Extension: (Honorlock) - C:\Users\young\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnbmpkmhjackfpkpcbapafmpepgmmddc [2021-04-27]
CHR Extension: (Chrome Web Store Payments) - C:\Users\young\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-02-08]
CHR Extension: (Gmail) - C:\Users\young\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-10-26]
CHR Extension: (Chrome Media Router) - C:\Users\young\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2021-04-27]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [169672 2021-01-25] (Adobe Inc. -> Adobe Inc.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [8798600 2021-04-21] (Microsoft Corporation -> Microsoft Corporation)
R2 CWAUpdaterService; C:\Program Files (x86)\Citrix\ICA Client\Receiver\UpdaterService.exe [43616 2020-08-25] (Citrix Systems, Inc. -> Citrix Systems, Inc.)
R2 HPAppHelperCap; C:\WINDOWS\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_d9cbd6bbac564232\x64\AppHelperCap.exe [731152 2021-03-24] (HP Inc. -> HP Inc.)
R2 HPDiagsCap; C:\WINDOWS\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_d9cbd6bbac564232\x64\DiagsCap.exe [728608 2021-03-24] (HP Inc. -> HP Inc.)
R2 HPNetworkCap; C:\WINDOWS\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_d9cbd6bbac564232\x64\NetworkCap.exe [728608 2021-03-24] (HP Inc. -> HP Inc.)
R2 HPSysInfoCap; C:\WINDOWS\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_d9cbd6bbac564232\x64\SysInfoCap.exe [729608 2021-03-24] (HP Inc. -> HP Inc.)
R2 HpTouchpointAnalyticsService; C:\WINDOWS\System32\DriverStore\FileRepository\hpanalyticscomp.inf_amd64_eb7ea98d07646ece\x64\TouchpointAnalyticsClientService.exe [480280 2021-03-17] (HP Inc. -> HP Inc.)
R2 MSSQL$XACTWARE; c:\Program Files (x86)\Microsoft SQL Server\MSSQL11.XACTWARE\MSSQL\Binn\sqlservr.exe [206424 2012-02-11] (Microsoft Corporation -> Microsoft Corporation)
S4 SQLAgent$XACTWARE; c:\Program Files (x86)\Microsoft SQL Server\MSSQL11.XACTWARE\MSSQL\Binn\SQLAGENT.EXE [438360 2012-02-11] (Microsoft Corporation -> Microsoft Corporation)
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Test Signing Certificate -> Adobe Systems Incorporated) [File not signed]
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [13147152 2020-08-21] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2104.9-0\NisSrv.exe [2599296 2021-05-05] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WildTangentHelper; C:\Program Files (x86)\WildTangent Games\Integration\WildTangentHelperService.exe [1502568 2019-02-20] (WildTangent Inc -> )
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2104.9-0\MsMpEng.exe [128360 2021-05-05] (Microsoft Windows Publisher -> Microsoft Corporation)

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 AmUStor; C:\WINDOWS\system32\drivers\AmUStorU.sys [127936 2019-03-28] (Alcorlink Corp. -> )
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [File not signed]
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [159600 2020-11-11] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R3 HPCustomCapDriver; C:\WINDOWS\System32\DriverStore\FileRepository\hpcustomcapdriver.inf_amd64_1f5602eb8a12ac4c\x64\hpcustomcapdriver.sys [25024 2019-04-18] (Microsoft Windows Hardware Compatibility Publisher -> HP Inc.)
R3 MpKsl369d4d16; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3CD97D80-8885-4BBB-B83E-37853E3150A2}\MpKslDrv.sys [47336 2021-05-05] (Microsoft Windows -> Microsoft Corporation)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [167280 2020-11-11] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R1 vbdenum; C:\WINDOWS\System32\drivers\vbdenum.sys [119432 2020-04-14] (Citrix Systems, Inc. -> Citrix Systems, Inc.)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [49544 2021-05-05] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [421112 2021-05-05] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [73976 2021-05-05] (Microsoft Windows -> Microsoft Corporation)
R3 WirelessButtonDriver64; C:\WINDOWS\System32\drivers\WirelessButtonDriver64.sys [35392 2020-06-08] (HP Inc. -> HP)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) (Whitelisted) =========

(If an entry is included in the fixlist, the file/folder will be moved.)

2021-05-05 15:28 - 2021-05-05 15:32 - 000026935 _____ C:\Users\young\Downloads\FRST.txt
2021-05-05 15:27 - 2021-05-05 15:30 - 000000000 ____D C:\FRST
2021-05-05 15:26 - 2021-05-05 15:26 - 002298368 _____ (Farbar) C:\Users\young\Downloads\FRST64.exe
2021-04-28 16:31 - 2021-04-28 16:31 - 000002852 _____ C:\Users\young\Documents\job-notes-II.txt
2021-04-23 15:13 - 2021-04-23 15:13 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2021-04-22 12:36 - 2021-04-27 18:07 - 000000000 ____D C:\Program Files\Mozilla Firefox
2021-04-19 16:53 - 2021-04-19 16:53 - 000000189 _____ C:\Users\young\Documents\Tampa Tribune ad.txt
2021-04-19 06:41 - 2021-04-19 06:41 - 005440191 _____ C:\Users\young\Desktop\ice_video_20210419-064108.webm
2021-04-17 15:10 - 2021-04-17 15:10 - 000011357 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim
2021-04-17 15:09 - 2021-04-17 15:09 - 001823304 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2021-04-17 15:09 - 2021-04-17 15:09 - 000231248 _____ C:\WINDOWS\system32\containerdevicemanagement.dll
2021-04-07 23:25 - 2021-04-07 23:25 - 000000000 ____D C:\Users\young\Documents\New folder

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2021-05-05 15:20 - 2020-03-14 19:48 - 000000000 ____D C:\Users\young\AppData\Roaming\vlc
2021-05-05 15:08 - 2020-02-29 19:03 - 000000000 ____D C:\ProgramData\Mozilla
2021-05-05 15:07 - 2020-02-29 19:03 - 000000000 ____D C:\Users\young\AppData\LocalLow\Mozilla
2021-05-05 15:04 - 2021-03-13 00:27 - 000000000 ____D C:\Users\young\AppData\Roaming\5KPlayer
2021-05-05 15:03 - 2019-12-07 05:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2021-05-05 15:01 - 2020-09-08 04:03 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2021-05-05 14:10 - 2019-04-15 11:38 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2021-05-05 02:00 - 2020-03-07 16:52 - 000000000 ____D C:\Users\young\AppData\Local\Adobe
2021-05-04 23:45 - 2020-09-06 10:04 - 000000000 ____D C:\WINDOWS\Firmware
2021-05-04 23:45 - 2019-12-07 05:13 - 000000000 ____D C:\WINDOWS\INF
2021-05-02 18:26 - 2019-05-24 14:58 - 000000000 ____D C:\Program Files\Microsoft Office
2021-05-02 14:03 - 2019-12-07 05:14 - 000000000 ___HD C:\Program Files\WindowsApps
2021-05-02 14:03 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2021-05-02 01:16 - 2020-02-29 11:49 - 000000000 ____D C:\Users\young\AppData\Local\Packages
2021-04-30 15:33 - 2020-02-29 19:15 - 000000000 ____D C:\Users\young\Documents\Resumes
2021-04-30 11:58 - 2020-06-20 01:03 - 000002445 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2021-04-30 11:58 - 2020-06-20 01:03 - 000002283 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2021-04-30 11:58 - 2020-06-20 01:03 - 000002283 _____ C:\ProgramData\Desktop\Microsoft Edge.lnk
2021-04-30 11:28 - 2020-02-29 19:12 - 000000000 ____D C:\Users\young\Documents\Job stuff
2021-04-30 00:42 - 2020-02-29 19:11 - 000000000 ____D C:\Users\young\Documents\Firefox bookmarks
2021-04-29 13:14 - 2020-09-08 04:26 - 000003378 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2242047713-980872803-1690996654-1001
2021-04-29 13:13 - 2020-09-06 10:06 - 000002370 _____ C:\Users\young\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2021-04-29 13:13 - 2020-02-29 11:51 - 000000000 ___RD C:\Users\young\OneDrive
2021-04-28 16:59 - 2020-02-29 11:48 - 000000000 __SHD C:\Users\young\IntelGraphicsProfiles
2021-04-28 16:31 - 2020-09-06 10:06 - 000000000 ____D C:\Users\young
2021-04-28 02:14 - 2020-02-29 19:10 - 000000000 ____D C:\Users\young\Documents\Books
2021-04-27 22:40 - 2020-09-08 04:21 - 000970184 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2021-04-27 22:37 - 2020-09-01 09:39 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2021-04-27 22:36 - 2020-09-08 04:26 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2021-04-27 22:36 - 2020-09-08 04:02 - 000008192 ___SH C:\DumpStack.log.tmp
2021-04-27 22:36 - 2019-12-29 23:20 - 000000000 ____D C:\Intel
2021-04-27 22:36 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\ServiceState
2021-04-27 18:07 - 2020-02-29 19:03 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2021-04-27 18:06 - 2019-12-07 05:03 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2021-04-26 15:04 - 2020-07-14 12:11 - 000002308 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2021-04-26 15:04 - 2020-07-14 12:11 - 000002267 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2021-04-26 15:04 - 2020-07-14 12:11 - 000002267 _____ C:\ProgramData\Desktop\Google Chrome.lnk
2021-04-26 14:52 - 2020-09-08 04:26 - 000003480 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2021-04-26 14:52 - 2020-09-08 04:26 - 000003356 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2021-04-23 15:13 - 2020-02-29 19:03 - 000001012 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2021-04-23 15:09 - 2020-08-22 04:11 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
2021-04-22 19:11 - 2020-03-07 17:33 - 000002481 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller X.lnk
2021-04-22 19:11 - 2020-03-07 17:33 - 000002469 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat X Pro.lnk
2021-04-22 19:11 - 2020-03-07 17:33 - 000002110 _____ C:\Users\Public\Desktop\Adobe Acrobat X Pro.lnk
2021-04-22 19:11 - 2020-03-07 17:33 - 000002110 _____ C:\ProgramData\Desktop\Adobe Acrobat X Pro.lnk
2021-04-22 19:11 - 2020-03-07 17:33 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe LiveCycle ES2
2021-04-22 13:36 - 2020-04-18 21:49 - 000002143 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2021-04-21 16:48 - 2020-04-22 20:23 - 000000879 _____ C:\Users\young\Desktop\JRT.txt
2021-04-21 14:05 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2021-04-20 16:34 - 2020-02-29 19:11 - 000000000 ____D C:\Users\young\Documents\Dieting
2021-04-20 15:55 - 2020-09-08 04:26 - 000003418 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2021-04-20 15:55 - 2020-09-08 04:26 - 000003294 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2021-04-17 15:29 - 2020-09-08 04:03 - 005110608 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2021-04-17 15:23 - 2020-09-06 08:41 - 000000000 ____D C:\WINDOWS\HoloShell
2021-04-17 15:23 - 2019-12-07 05:14 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2021-04-17 15:23 - 2019-12-07 05:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2021-04-17 15:23 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\SystemResources
2021-04-17 15:23 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\setup
2021-04-17 15:23 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2021-04-17 15:23 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\lv-LV
2021-04-17 15:23 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\lt-LT
2021-04-17 15:23 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\et-EE
2021-04-17 15:23 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\es-MX
2021-04-17 15:23 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\Provisioning
2021-04-17 15:23 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2021-04-17 15:23 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2021-04-17 15:22 - 2019-12-07 05:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2021-04-17 15:08 - 2020-09-08 04:09 - 002877440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2021-04-16 09:28 - 2020-03-01 02:02 - 000000000 ____D C:\WINDOWS\system32\MRT
2021-04-16 09:24 - 2020-03-01 02:02 - 131963968 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2021-04-15 09:55 - 2020-02-29 19:15 - 000000000 ____D C:\Users\young\Documents\Mohela
2021-04-13 17:33 - 2020-03-27 16:48 - 000000666 _____ C:\WINDOWS\Tasks\G2MUploadTask-S-1-5-21-2242047713-980872803-1690996654-1001.job
2021-04-13 17:33 - 2020-03-27 16:48 - 000000570 _____ C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-2242047713-980872803-1690996654-1001.job
2021-04-13 08:41 - 2020-10-23 14:06 - 000000000 ____D C:\Users\young\AppData\Local\CrashDumps
2021-04-09 03:19 - 2020-09-08 04:26 - 000003838 _____ C:\WINDOWS\system32\Tasks\G2MUploadTask-S-1-5-21-2242047713-980872803-1690996654-1001
2021-04-09 03:19 - 2020-09-08 04:26 - 000003742 _____ C:\WINDOWS\system32\Tasks\G2MUpdateTask-S-1-5-21-2242047713-980872803-1690996654-1001
2021-04-09 03:19 - 2020-03-27 16:48 - 000000000 ____D C:\Users\young\AppData\Local\GoToMeeting
2021-04-07 23:33 - 2020-02-29 19:15 - 000000000 ____D C:\Users\young\Documents\Table Tennis

==================== Files in the root of some directories ========

2021-02-27 17:51 - 2021-02-27 17:51 - 000000132 _____ () C:\Users\young\AppData\Roaming\Adobe PNG Format CS6 Prefs
2020-07-18 17:36 - 2020-07-18 17:39 - 000013824 _____ () C:\Users\young\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2020-12-20 13:15 - 2020-12-20 13:15 - 000007601 _____ () C:\Users\young\AppData\Local\Resmon.ResmonCfg

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================

OK
As far as visual signs of malware and reasons why the computer is lagging, no but
We can try to tidy up and run a few tools and look for things these logs possibly can't find.



***
Start Farbar Recovery Scan Tool with Administrator privileges
(Right click on the FRST icon and select Run as administrator)

highlight on the text below and select Copy.
beginning with Start:: and finishing with End::
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Highlight the entire content of the quote box below and select Copy.

 

Start::
CloseProcesses:
CreateRestorePoint:
CustomCLSID: HKU\S-1-5-21-2242047713-980872803-1690996654-1001_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309}\InprocServer32 -> C:\Users\young\AppData\Local\GoToMeeting\16786\G2MOutlookAddin64.dll => No File
ShortcutWithArgument: C:\Users\young\Desktop\Claims\Accurence.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> –profile-directory=Default –app-id=apdemjalhbjphbbmnibpneopekgmnclb
ShortcutWithArgument: C:\Users\young\Desktop\Claims\ERD.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> –profile-directory=Default –app-id=fjhahnjekojlhchcdmpppimlbilkdmkn
ShortcutWithArgument: C:\Users\young\Desktop\Claims\Move to adjuster compter\Allstate Webpages\Accurence.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> –profile-directory=Default –app-id=apdemjalhbjphbbmnibpneopekgmnclb
ShortcutWithArgument: C:\Users\young\Desktop\Claims\Move to adjuster compter\Allstate Webpages\ERD Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> –profile-directory=Default –app-id=fjhahnjekojlhchcdmpppimlbilkdmkn
ShortcutWithArgument: C:\Users\young\Desktop\Claims\Hurricane Lara\Allstate Webpages\Allstate Webpages\Accurence.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> –profile-directory=Default –app-id=apdemjalhbjphbbmnibpneopekgmnclb
ShortcutWithArgument: C:\Users\young\Desktop\Claims\Hurricane Lara\Allstate Webpages\Allstate Webpages\ERD Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> –profile-directory=Default –app-id=fjhahnjekojlhchcdmpppimlbilkdmkn
ShortcutWithArgument: C:\Users\young\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Accurence.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> –profile-directory=Default –app-id=apdemjalhbjphbbmnibpneopekgmnclb
ShortcutWithArgument: C:\Users\young\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\ERD.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> –profile-directory=Default –app-id=fjhahnjekojlhchcdmpppimlbilkdmkn
FirewallRules: [{FA7E0A5E-8072-4855-B490-46136D079E1F}] => (Allow) C:\Users\young\AppData\Roaming\Zoom\bin\airhost.exe => No File
HKLM-x32\…\Run: [] => [X]
EmptyTemp:
C:\Windows\Temp\*.*
End::

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


Start FRST (FRST64) with Administrator privileges
Press the Fix button. FRST will process the lines copied above from the clipboard.
When finished, a log file Fixlog.txt will pop up and saved in the same location the tool was ran from.

Please copy and paste its contents in your next reply.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~`


Download and run AdwCleaner

Download AdwCleaner from here and save it to your desktop.
you can download AdwCleaner here: https://malwarebytes.com/adwcleaner

  • run AdwCleaner by clicking on Scan Now
  • when it has finished, leave everything that was found checked, (ticked), then click on Clean and Repair
  • if it asks to reboot, allow the reboot
  • on reboot, click on View Log File; please attach the content of the log to your next reply.

============================================

Run Malwarebytes Anti-Malware

You may have Malwarebytes Anti-Malware installed but if not, you can download it from here:

  • run the program
  • click on the ‘Dashboard’ to make sure everything is up to date, (it is not necessary to upgrade to the premium version of MBAM)
  • click on the ‘Scan’ tab, (directly below the Dashboard tab)
  • select the Threat Scan option
  • slick the Scan Now button
  • Threat Scan will begin
  • when the scan has completed and if malware was found, click the Quarantine Selected button to allow MBAM to quarantine what was found
  • if prompted to restart the computer, close all other programs and click Yes to restart your computer
  • once you are back at your desktop, open MBAM once more
  • click on the ‘Reports’ tab
  • double-click on the most recent Scan Report
  • click on Export, then Copy to Clipboard

Logs to include with the next post:

Fixlog.txt
AdwCleaner log
Mbam.txt

After I highlighted your tailored script in your reply, selected copy, then clicked start in FRST, it took a while to run it, then it rebooted my computer. No log resulted.

 

Below are the other two items.

 

 

 

# ——————————-
# Malwarebytes AdwCleaner 8.2.0.0
# ——————————-
# Build:    03-22-2021
# Database: 2021-04-28.3 (Cloud)
# Support:  https://www.malwarebytes.com/support
#
# ——————————-
# Mode: Clean
# ——————————-
# Start:    05-06-2021
# Duration: 00:00:15
# OS:       Windows 10 Home
# Cleaned:  13
# Failed:   0


***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

No malicious folders cleaned.

***** [ Files ] *****

No malicious files cleaned.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks cleaned.

***** [ Registry ] *****

No malicious registry entries cleaned.

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries cleaned.

***** [ Chromium URLs ] *****

No malicious Chromium URLs cleaned.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.

***** [ Hosts File Entries ] *****

No malicious hosts file entries cleaned.

***** [ Preinstalled Software ] *****

Deleted       Preinstalled.HPCleanFLC   Registry   HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run|HPSEU_Host_Launcher
Deleted       Preinstalled.HPCleanFLC   Registry   HKCU\Software\Microsoft\Windows\CurrentVersion\Run|HPSEU_Host_Launcher
Deleted       Preinstalled.HPCleanFLC   Registry   HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run|HPSEU_Host_Launcher
Deleted       Preinstalled.HPCleanFLC   Registry   HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run|HPSEU_Host_Launcher
Deleted       Preinstalled.HPRegistrationService   Folder   C:\ProgramData\HP\HP REGISTRATION SERVICE
Deleted       Preinstalled.HPSupportAssistant   Folder   C:\HP\SUPPORT
Deleted       Preinstalled.HPSupportAssistant   Folder   C:\ProgramData\HEWLETT-PACKARD\HP SUPPORT FRAMEWORK
Deleted       Preinstalled.HPSupportAssistant   Folder   C:\Users\Administrator\AppData\Roaming\HEWLETT-PACKARD\HP SUPPORT FRAMEWORK
Deleted       Preinstalled.HPSupportAssistant   Folder   C:\Users\young\AppData\Roaming\HEWLETT-PACKARD\HP SUPPORT FRAMEWORK
Deleted       Preinstalled.HPTouchpointAnalyticsClient   Folder   C:\ProgramData\HP\HP TOUCHPOINT ANALYTICS CLIENT
Deleted       Preinstalled.HPTouchpointAnalyticsClient   Registry   HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{E5FB98E0-0784-44F0-8CEC-95CD4690C43F}
Deleted       Preinstalled.WildTangentGamesBundle   Folder   C:\Program Files (x86)\WILDTANGENT GAMES
Deleted       Preinstalled.WildTangentGamesBundle   Folder   C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WILDTANGENT GAMES


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************

AdwCleaner[S00].txt - [2800 octets] - [06/05/2021 20:24:34]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########

 

 

——–

 

Malwarebytes
www.malwarebytes.com

-Log Details-
Scan Date: 5/6/21
Scan Time: 8:33 PM
Log File: e6d7f4da-aecb-11eb-b7f6-e8d8d1d628a4.json

-Software Information-
Version: 4.3.3.116
Components Version: 1.0.1292
Update Package Version: 1.0.40187
License: Free

-System Information-
OS: Windows 10 (Build 19041.928)
CPU: x64
File System: NTFS
User: LAPTOP-6R6IN514\young

-Scan Summary-
Scan Type: Threat Scan
Scan Initiated By: Manual
Result: Completed
Objects Scanned: 369565
Threats Detected: 1
Threats Quarantined: 0
Time Elapsed: 6 min, 52 sec

-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Detect
PUM: Detect

-Scan Details-
Process: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registry Key: 0
(No malicious items detected)

Registry Value: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Data Stream: 0
(No malicious items detected)

Folder: 0
(No malicious items detected)

File: 1
PUP.Optional.BundleInstaller, C:\USERS\YOUNG\DOWNLOADS\UTORRENT.EXE, No Action By User, 526, 790622, 1.0.40187, , ame, , 24E8D2B74D88BC02867ED654C2C9D99E, F1C5A0D1DB66ECD461A49CDF2A861BDFDE702E47E82ADA582D871A9F95035BB5

Physical Sector: 0
(No malicious items detected)

WMI: 0
(No malicious items detected)


(end)

 

——

Do a search on your computer for Fixlog.txt

What I'm finding is just some preinstalled items that was from the manufacturer, no biggie
Then a bundled tool bar I think for uTorrent.

I don't think we're going to find much, could be something trying to update in the background and or the system is trying to do backups.

Let's attempt to do an online scan to look for remnants.


ESET Online Scanner

Download ESET Online Scanner and save it to your desktop.

 

  • Right-click on esetonlinescanner_enu.exe and select Run as Administrator.
  • When the tool opens, click Get Started.
  • Read and accept the license agreement.
  • At the Welcome to ESET Online Scanner window, click Get Started.
  • Select whether you would like to send anonymous data to ESET.
  • Note: if you see the "Welcome Back to ESET Online Scanner" screen, click Computer Scan > Full Scan.
  • Click on the Full Scan option.
  • Select Enable ESET to detect and remove potentially unwanted applications, then click Start scan.
  • ESET will now begin scanning your computer. This may take some time.
  • When the scan is finished and if threats have been detected, select Save scan log. Save it to your desktop as eset.txt. Click on Continue.
  • ESET Online Scanner may ask if you'd like to turn on the Periodic Scan feature. Click on Continue.
  • On the next screen, you can leave feedback about the program if you wish. Check the box for Delete application data on closing. If you left feedback, click Submit and continue. If not, Close without feedback.
  • Open the scan log on your desktop (eset.txt) and copy and paste its contents into your next reply.

————————————————–

How is the computer today?
 

I'll get back with you in a few days on that ESET scan. I'm having to work almost 40 hours in the next three days and can't keep my eyes open.

 

—

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 28-04-2021
Ran by [removed] (06-05-2021 20:06:18) Run:1
Running from C:\Users\[removed]\Downloads
[removed] Boot Mode: Normal
==============================================

fixlist content:
*****************
CloseProcesses:
CreateRestorePoint:
CustomCLSID: HKU\S-1-5-21-2242047713-980872803-1690996654-1001_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309}\InprocServer32 -> C:\Users\young\AppData\Local\GoToMeeting\16786\G2MOutlookAddin64.dll => No File
ShortcutWithArgument: C:\Users\young\Desktop\Claims\Accurence.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> –profile-directory=Default –app-id=apdemjalhbjphbbmnibpneopekgmnclb
ShortcutWithArgument: C:\Users\young\Desktop\Claims\ERD.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> –profile-directory=Default –app-id=fjhahnjekojlhchcdmpppimlbilkdmkn
ShortcutWithArgument: C:\Users\young\Desktop\Claims\Move to adjuster compter\Allstate Webpages\Accurence.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> –profile-directory=Default –app-id=apdemjalhbjphbbmnibpneopekgmnclb
ShortcutWithArgument: C:\Users\young\Desktop\Claims\Move to adjuster compter\Allstate Webpages\ERD Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> –profile-directory=Default –app-id=fjhahnjekojlhchcdmpppimlbilkdmkn
ShortcutWithArgument: C:\Users\young\Desktop\Claims\Hurricane Lara\Allstate Webpages\Allstate Webpages\Accurence.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> –profile-directory=Default –app-id=apdemjalhbjphbbmnibpneopekgmnclb
ShortcutWithArgument: C:\Users\young\Desktop\Claims\Hurricane Lara\Allstate Webpages\Allstate Webpages\ERD Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> –profile-directory=Default –app-id=fjhahnjekojlhchcdmpppimlbilkdmkn
ShortcutWithArgument: C:\Users\young\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Accurence.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> –profile-directory=Default –app-id=apdemjalhbjphbbmnibpneopekgmnclb
ShortcutWithArgument: C:\Users\young\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\ERD.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> –profile-directory=Default –app-id=fjhahnjekojlhchcdmpppimlbilkdmkn
FirewallRules: [{FA7E0A5E-8072-4855-B490-46136D079E1F}] => (Allow) C:\Users\young\AppData\Roaming\Zoom\bin\airhost.exe => No File
HKLM-x32\…\Run: [] => [X]
EmptyTemp:
C:\Windows\Temp\*.*

*****************

Processes closed successfully.
Restore point was successfully created.
HKU\S-1-5-21-2242047713-980872803-1690996654-1001_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309} => removed successfully
C:\Users\young\Desktop\Claims\Accurence.lnk => Shortcut argument removed successfully
C:\Users\young\Desktop\Claims\ERD.lnk => Shortcut argument removed successfully
C:\Users\young\Desktop\Claims\Move to adjuster compter\Allstate Webpages\Accurence.lnk => Shortcut argument removed successfully
C:\Users\young\Desktop\Claims\Move to adjuster compter\Allstate Webpages\ERD Chrome.lnk => Shortcut argument removed successfully
C:\Users\young\Desktop\Claims\Hurricane Lara\Allstate Webpages\Allstate Webpages\Accurence.lnk => Shortcut argument removed successfully
C:\Users\young\Desktop\Claims\Hurricane Lara\Allstate Webpages\Allstate Webpages\ERD Chrome.lnk => Shortcut argument removed successfully
C:\Users\young\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Accurence.lnk => Shortcut argument removed successfully
C:\Users\young\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\ERD.lnk => Shortcut argument removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{FA7E0A5E-8072-4855-B490-46136D079E1F}" => removed successfully
"HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\" => removed successfully

=========== "C:\Windows\Temp\*.*" ==========

C:\Windows\Temp\LAPTOP-6R6IN514-20210427-2237.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210429-1653.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210429-1842.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210429-2343.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210430-0148.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210430-1114.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210430-1117.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210430-1117a.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210430-1213.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210430-1251.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210430-1311.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210430-1316.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210430-1757.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210430-1859.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210430-2217.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210501-0009.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210501-1245.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210501-1253.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210501-1306.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210501-1445.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210501-1455.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210501-1607.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210501-1710.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210501-1736.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210501-1807.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210501-1822.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210502-1305.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210502-1307.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210502-1307a.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210502-1340.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210502-1402.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210502-1609.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210502-1812.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210502-1814.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210502-1826.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210502-1826a.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210502-1826b.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210502-2203.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210502-2208.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210504-2340.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210504-2344.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210504-2344a.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210504-2344b.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210505-0422.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210505-1302.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210505-1440.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210505-1554.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210505-1636.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210505-2001.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210505-2047.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210505-2118.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210505-2243.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210505-2343.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210506-0252.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210506-0405.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210506-1450.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210506-1456.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210506-1456a.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210506-1514.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210506-1630.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210506-1712.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210506-1732.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210506-1837.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210506-1850.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210506-1923.log => moved successfully
C:\Windows\Temp\LAPTOP-6R6IN514-20210506-1928.log => moved successfully
Could not move "C:\Windows\Temp\LAPTOP-6R6IN514-20210506-2006.log" => Scheduled to move on reboot.
C:\Windows\Temp\mat-debug-10664.log => moved successfully
C:\Windows\Temp\mat-debug-14608.log => moved successfully
C:\Windows\Temp\mat-debug-17680.log => moved successfully
C:\Windows\Temp\mat-debug-4520.log => moved successfully
C:\Windows\Temp\mat-debug-6872.log => moved successfully
C:\Windows\Temp\mat-debug-7984.log => moved successfully
C:\Windows\Temp\mat-debug-8444.log => moved successfully
C:\Windows\Temp\MpCmdRun.log => moved successfully
C:\Windows\Temp\MpSigStub.log => moved successfully
C:\Windows\Temp\msedge_installer.log => moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(202105061450341460).log => moved successfully
Could not move "C:\Windows\Temp\officeclicktorun.exe_streamserver(202105062006212DC4).log" => Scheduled to move on reboot.
C:\Windows\Temp\UpdHealthTools.msi => moved successfully
C:\Windows\Temp\{0542356D-0250-4480-A9FD-8033608F9518} - OProcSessId.dat => moved successfully
C:\Windows\Temp\{319DA32A-4564-41C2-9015-6583BC1F8B01} - OProcSessId.dat => moved successfully
C:\Windows\Temp\{5C3F78DA-D440-4271-9B5B-725C99E3D9C4} - OProcSessId.dat => moved successfully

========= End -> "C:\Windows\Temp\*.*" ========


=========== EmptyTemp: ==========

BITS transfer queue => 10510336 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 634286660 B
Java, Flash, Steam htmlcache => 524 B
Windows/system/drivers => 172 B
Edge => 361584 B
Chrome => 529247612 B
Firefox => 1321762483 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 7344 B
NetworkService => 277592 B
young => 183920947 B
Administrator => 183940509 B

RecycleBin => 14725309984 B
EmptyTemp: => 16.4 GB temporary data Removed.

================================

Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 06-05-2021 20:19:03)

C:\Windows\Temp\LAPTOP-6R6IN514-20210506-2006.log => Is moved successfully
C:\Windows\Temp\officeclicktorun.exe_streamserver(202105062006212DC4).log => Is moved successfully

==== End of Fixlog 20:19:04 ====

That did take a long time to scan. I didn't see anything in it, though, that looked like a threat.

 

—

 

5/10/2021 22:43:02 PM
Files scanned: 597143
Detected files: 13
Cleaned files: 13
Total scan time 05:46:39
Scan status: Finished


C:\Documents and Settings\young\AppData\Roaming\uTorrent\updates\3.5.5_45449.exe    a variant of Win32/uTorrent.C potentially unwanted application    cleaned by deleting
C:\Documents and Settings\young\AppData\Roaming\uTorrent\updates\3.5.5_45574.exe    a variant of Win32/uTorrent.C potentially unwanted application    cleaned by deleting
C:\Documents and Settings\young\AppData\Roaming\uTorrent\updates\3.5.5_45608.exe    a variant of Win32/uTorrent.C potentially unwanted application    cleaned by deleting
C:\Documents and Settings\young\AppData\Roaming\uTorrent\updates\3.5.5_45628.exe    a variant of Win32/uTorrent.C potentially unwanted application    cleaned by deleting
C:\Documents and Settings\young\AppData\Roaming\uTorrent\updates\3.5.5_45672.exe    a variant of Win32/uTorrent.C potentially unwanted application    cleaned by deleting
C:\Documents and Settings\young\AppData\Roaming\uTorrent\updates\3.5.5_45704.exe    a variant of Win32/uTorrent.C potentially unwanted application    cleaned by deleting
C:\Documents and Settings\young\AppData\Roaming\uTorrent\updates\3.5.5_45776.exe    a variant of Win32/uTorrent.C potentially unwanted application    cleaned by deleting
C:\Documents and Settings\young\AppData\Roaming\uTorrent\updates\3.5.5_45790.exe    a variant of Win32/uTorrent.C potentially unwanted application    cleaned by deleting
C:\Documents and Settings\young\Documents\Laptop-to 9-6-14\Adobe Master Collection CS6\disable_activation.cmd    BAT/HostsChanger.A potentially unsafe application    cleaned by deleting
C:\Documents and Settings\young\Downloads\Adobe CS6 Master Collection\Downloaded\disable_activation.cmd    BAT/HostsChanger.A potentially unsafe application    cleaned by deleting
C:\Documents and Settings\young\Downloads\Adobe CS6 Master Collection\disable_activation.cmd    BAT/HostsChanger.A potentially unsafe application    cleaned by deleting
C:\Documents and Settings\young\Downloads\Software\WinXDVD\WinX DVD Ripper Platinum 8.5.0.192 + keygen - Crackingpatching.com\WinX DVD Ripper Platinum 8.5.0.192 + keygen - Crackingpatching.com\keygen\Keygen.exe    a variant of Win32/HackTool.Crack.FQ.gen potentially unsafe application    deleted
C:\Documents and Settings\young\Downloads\uTorrent.exe    a variant of Win32/uTorrent.C potentially unwanted application,a variant of Win32/WebCompanion.B potentially unwanted application    cleaned by deleting

 

Sorry for the delay. A family emergency. The slowness still comes and goes. The only thing I can think of is that when numerous programs are running, they may be slowing things down. I mean, at one point a video I was playing would freeze for a second, then play for four or five seconds, freeze again, etc. I'd like to see how much RAM I have and if I could upgrade this laptop any. In any event, I do appreciate your help. At least I ruled out malware.

More weirdness. I woke up this morning, opened my laptop, and I can hear the hard drive doing something in there but the screen stays black. After waiting a bit with no response, I had to manually shut the laptop down. A minute or two after I turned it back on, I get a default desktop screen, default everything, and a popup tells me it can't sign me back in and should I sign out or close the window? Not sure what was happening and why it was doing this I opted to close, and it booted up to a default configuration(!) I had to re-sign in to my account from the Windows start menu button, then it signed me back in to my account that I recognize. This has never happened before, and it's been several times now that I would just get a black screen when opening the laptop up the next day, making me force a reboot.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI