Slow Laptop

Discussion in 'Malware Help (A Specialist Will Reply)' started by amateur09, Dec 8, 2025.

  1. amateur09

    amateur09 Private E-2

    My sons laptop runs real slow to start and shut down as well as opening and closing apps after it's started. I know he previously had similar issues with this laptop, but I don't know the specifics as he died about 3 years ago and has had very limited usage since his passing. If I bring up task manager, the disc usage stays at 100%. Attached are the logs I ran about a month ago. The battery was shot after only a year and I just replaced it yesterday. I'm guessing the battery issue isn't related to these problems but rather a bad battery. Thanks in advance for your help.
     

    Attached Files:

  2. Oh My!

    Oh My! Malware Expert Staff Member

    Greetings and welcome back to the Major Geeks Malware Forum.

    I am so sorry to hear about your son. I can't even imagine how difficult that would be.

    While I review things please do this.

    ===================================================

    Farbar Recovery Scan Tool (FRST)

    --------------------
    • Download FRST64 and save the file on your Desktop
    • If your computer language is other than English right click on the FRST64 icon and rename it to FRST64english
    • Right click on the icon and select Run as administrator
    • Note: If you receive any warning about the download it is a false positive and you can ignore it. Click on More info to get the Run anyway option
    • Click Yes to the disclaimer
    • Click Scan and allow the program to run
    • When completed, FRST.txt and Addition.txt reports will be saved on the Desktop
    • Please attach the reports to your reply
    ===================================================

    Things I would like to see in your next reply.
    • Attached reports
     
    D.H. likes this.
  3. amateur09

    amateur09 Private E-2

    Attached is the requested reports.
     

    Attached Files:

  4. Oh My!

    Oh My! Malware Expert Staff Member

    Thank you for your patience.

    There is no evidence of malicious software on the system but let's see what we can do.

    Please start with this.

    ===================================================

    Rerun AdwCleaner and select the option to remove all Preinstalled software. Copy and paste the report in your reply.

    ===================================================

    Farbar Recovery Scan Tool Fix

    --------------------
    • Right click on the FRST64 icon and select Run as administrator
    • Highlight the below information then hit the Ctrl + C keys at the same time and the text will be copied
    • There is no need to paste the information anywhere, FRST64 will do it for you
    Code:
    Start::
    CreateRestorePoint:
    CloseProcesses:
    AS: Kaspersky Free (Enabled - Up to date) {B1D2E896-6D96-7460-F17A-838B9D00DD65}
    Edge HKLM-x32\...\Edge\Extension: [fphgeikpdcdcheaochkhldmnfblfogla]
    2025-11-03 20:41 - 2025-11-03 20:41 - 000135168 _____ C:\Users\twron\Downloads\MGtools.3-vkHVAF.exe.part
    2020-03-18 18:57 - 2020-11-05 21:31 - 000000081 _____ () C:\Users\twron\AppData\Local\.bidstack.fault
    HKU\S-1-5-21-1942162625-1406552919-4237404059-1005\...\StartupApproved\Run: => "NordVPN"
    Task: {077BA067-7C15-40F0-B22E-C9DC2A54B4A2} - System32\Tasks\Microsoft\Windows\Location\Notifications => %windir%\System32\LocationNotificationWindows.exe  (No File)
    Task: {CCDFC0B8-01A3-4E74-A820-4F13F51D269E} - System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => %SystemRoot%\System32\MbaeParserTask.exe  (No File)
    Task: {18405566-0481-49A4-A65D-1CC7CAF2276A} - System32\Tasks\Microsoft\Windows\PI\SecureBootEncodeUEFI => %WINDIR%\system32\SecureBootEncodeUEFI.exe  (No File)
    Task: {DB607E7D-7179-4ECA-BC0C-B046A83D214F} - System32\Tasks\Microsoft\Windows\rempl\shell-usoscan => %ProgramFiles%\rempl\remsh.exe  /RunUsoScanOnly (No File)
    Task: {0BB36A32-0D9E-4297-AFD7-6BD7B5DB4C9B} - System32\Tasks\Microsoft\Windows\UNP\RunUpdateNotificationMgr => %windir%\System32\UNP\UpdateNotificationMgr.exe  (No File)
    Task: {6ECC17BA-2F21-4D1D-A937-AF5B7E29ED7A} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot => %systemroot%\system32\MusNotification.exe  Reboot (No File)
    Task: {1C8CB2FE-56D5-4457-B4B3-9C6753B62AAF} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_AC => %systemroot%\system32\MusNotification.exe  /RunOnAC RebootDialog (No File)
    Task: {98F8B1E5-776E-4E44-A484-47B1D3B8418E} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery => %systemroot%\system32\MusNotification.exe  /RunOnBattery RebootDialog (No File)
    Task: {CFC2C4F4-EEA5-4B91-96F2-A16C1BBDA4BF} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_Broker_Display => %systemroot%\system32\MusNotification.exe  Display (No File)
    Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe  (No File)
    CustomCLSID: HKU\S-1-5-21-1942162625-1406552919-4237404059-1005_Classes\CLSID\{CB965DF1-B8EA-49C7-BDAD-5457FDC1BF92}\InprocServer32 -> C:\Users\twron\AppData\Local\Microsoft\TeamsMeetingAddin\1.0.20130.1\x64\Microsoft.Teams.AddinLoader.dll => No File
    ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} =>  -> No File
    cmd: netsh winsock reset catalog
    cmd: netsh int ip reset resetlog.txt
    Reg: reg export HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Defaults\FirewallPolicy\FirewallRules C:\Firewall.reg
    C:\Firewall.reg
    cmd: netsh advfirewall reset
    cmd: netsh advfirewall set allprofiles state ON
    cmd: ipconfig /flushdns
    Removeproxy:
    hosts:
    cmd: sfc /scannow
    cmd: DISM /Online /Cleanup-Image /CheckHealth
    Emptytemp:
    End::
    
    • Click Fix
    • When completed the tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
    • Note: This step resets your Firewall settings and you may be asked later to grant permission for legitimate programs to pass through the Firewall. If you recognize the program agree to the request.
    • Note: The Emptytemp: command will remove cookies and may result in some websites (like banking) indicating they do not recognize your computer. It may be necessary to receive and apply a verification code.
    ===================================================

    Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
    • AdwCleaner report
    • Fixlog
     
  5. amateur09

    amateur09 Private E-2

    One odd behavior I forgot to mention earlier is a window will come up saying another version of acrobat distiller is starting up. Doesn't happen all the time but when it does there are 5-10 instances of that message that need to closed. Anyway here is the AdwCleaner report

    # -------------------------------
    # Malwarebytes AdwCleaner 8.5.0.595
    # -------------------------------
    # Build: 03-05-2025
    # Database: 2024-10-23.4 (Local)
    # Support: https://www.malwarebytes.com/support
    #
    # -------------------------------
    # Mode: Clean
    # -------------------------------
    # Start: 12-09-2025
    # Duration: 00:02:29
    # OS: Windows 11 (Build 26100.6899)
    # Cleaned: 33
    # Failed: 0


    ***** [ Services ] *****

    No malicious services cleaned.

    ***** [ Folders ] *****

    No malicious folders cleaned.

    ***** [ Files ] *****

    No malicious files cleaned.

    ***** [ DLL ] *****

    No malicious DLLs cleaned.

    ***** [ WMI ] *****

    No malicious WMI cleaned.

    ***** [ Shortcuts ] *****

    No malicious shortcuts cleaned.

    ***** [ Tasks ] *****

    No malicious tasks cleaned.

    ***** [ Registry ] *****

    No malicious registry entries cleaned.

    ***** [ Chromium (and derivatives) ] *****

    No malicious Chromium entries cleaned.

    ***** [ Chromium URLs ] *****

    No malicious Chromium URLs cleaned.

    ***** [ Firefox (and derivatives) ] *****

    No malicious Firefox entries cleaned.

    ***** [ Firefox URLs ] *****

    No malicious Firefox URLs cleaned.

    ***** [ Hosts File Entries ] *****

    No malicious hosts file entries cleaned.

    ***** [ Preinstalled Software ] *****

    Deleted Preinstalled.HPAudioSwitch Folder C:\Program Files (x86)\HP\HPAUDIOSWITCH
    Deleted Preinstalled.HPAudioSwitch Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9BD8955D-816C-4F65-997F-8841B321318A}
    Deleted Preinstalled.HPAudioSwitch Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\HPAudioSwitch
    Deleted Preinstalled.HPAudioSwitch Task C:\Windows\System32\Tasks\HPAUDIOSWITCH
    Deleted Preinstalled.HPCoolSense Folder C:\Program Files (x86)\HP\HP COOLSENSE
    Deleted Preinstalled.HPCoolSense Folder C:\Users\twron\AppData\Local\HP\HP COOLSENSE
    Deleted Preinstalled.HPCoolSense Folder C:\Windows\System32\Tasks\HP\HP COOLSENSE
    Deleted Preinstalled.HPCoolSense Registry HKLM\Software\Classes\CLSID\{224695A4-BD5E-4C38-B354-A4C828E61BF7}
    Deleted Preinstalled.HPJumpStartApps Folder C:\Program Files (x86)\HP\HP JUMPSTART APPS
    Deleted Preinstalled.HPJumpStartApps Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\HP JumpStart Apps
    Deleted Preinstalled.HPJumpStartBridge Folder C:\Program Files (x86)\HP\HP JUMPSTART BRIDGE
    Deleted Preinstalled.HPJumpStartBridge Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{EB0912FF-C311-4E0F-A6B1-420FDD3C295E}
    Deleted Preinstalled.HPJumpStartLaunch Folder C:\Program Files (x86)\HP\HP JUMPSTART LAUNCH
    Deleted Preinstalled.HPJumpStartLaunch Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{ECDEBDC9-1284-47FA-9F72-CEF3308BB88A}
    Deleted Preinstalled.HPJumpStartLaunch Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\HPJumpStartLaunch
    Deleted Preinstalled.HPJumpStartLaunch Task C:\Windows\System32\Tasks\HPJUMPSTARTLAUNCH
    Deleted Preinstalled.HPRegistrationService Folder C:\Program Files (x86)\HP\HP REGISTRATION SERVICE
    Deleted Preinstalled.HPRegistrationService Folder C:\ProgramData\HP\HP REGISTRATION SERVICE
    Deleted Preinstalled.HPSupportAssistant Folder C:\HP\SUPPORT
    Deleted Preinstalled.HPSupportAssistant Folder C:\Program Files (x86)\HEWLETT-PACKARD\HP CUSTOMER FEEDBACK
    Deleted Preinstalled.HPSupportAssistant Folder C:\Program Files (x86)\HEWLETT-PACKARD\HP SUPPORT FRAMEWORK
    Deleted Preinstalled.HPSupportAssistant Folder C:\Program Files (x86)\HEWLETT-PACKARD\HP SUPPORT SOLUTIONS
    Deleted Preinstalled.HPSupportAssistant Folder C:\ProgramData\HEWLETT-PACKARD\HP SUPPORT FRAMEWORK
    Deleted Preinstalled.HPSupportAssistant Folder C:\Users\twron\AppData\Local\HEWLETT-PACKARD\HP SUPPORT FRAMEWORK
    Deleted Preinstalled.HPSupportAssistant Folder C:\Users\twron\AppData\Roaming\HEWLETT-PACKARD\HP SUPPORT FRAMEWORK
    Deleted Preinstalled.HPSupportAssistant Registry HKLM\Software\Classes\CLSID\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}
    Deleted Preinstalled.HPSupportAssistant Registry HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}
    Deleted Preinstalled.HPSupportAssistant Registry HKLM\Software\Wow6432Node\\Classes\CLSID\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}
    Deleted Preinstalled.HPSupportAssistant Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}
    Deleted Preinstalled.HPSupportAssistant Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{05F81C27-62A5-4A0C-8519-60CB66CF87C6}
    Deleted Preinstalled.HPSupportAssistant Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{930B5F2B-8DB9-42F4-90E4-5D3DC30541C3}
    Deleted Preinstalled.HPSureConnect Folder C:\Program Files\HPCOMMRECOVERY
    Deleted Preinstalled.HPSureConnect Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{6468C4A5-E47E-405F-B675-A70A70983EA6}


    *************************

    [+] Delete Tracing Keys
    [+] Reset Winsock

    *************************

    AdwCleaner[S00].txt - [5210 octets] - [24/07/2024 19:37:26]
    AdwCleaner[C00].txt - [1678 octets] - [24/07/2024 19:49:30]
    AdwCleaner[S01].txt - [5244 octets] - [23/07/2025 15:46:59]
    AdwCleaner[S02].txt - [5305 octets] - [03/11/2025 19:13:12]
    AdwCleaner[S03].txt - [5366 octets] - [09/12/2025 17:28:45]

    ########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C03].txt ##########

    And Fixlog

    Fix result of Farbar Recovery Scan Tool (x64) Version: 20-11-2025
    Ran by twron (09-12-2025 18:19:06) Run:1
    Running from C:\Users\twron\Desktop
    Loaded Profiles: twron
    Boot Mode: Normal
    ==============================================

    fixlist content:
    *****************
    Start::
    CreateRestorePoint:
    CloseProcesses:
    AS: Kaspersky Free (Enabled - Up to date) {B1D2E896-6D96-7460-F17A-838B9D00DD65}
    Edge HKLM-x32\...\Edge\Extension: [fphgeikpdcdcheaochkhldmnfblfogla]
    2025-11-03 20:41 - 2025-11-03 20:41 - 000135168 _____ C:\Users\twron\Downloads\MGtools.3-vkHVAF.exe.part
    2020-03-18 18:57 - 2020-11-05 21:31 - 000000081 _____ () C:\Users\twron\AppData\Local\.bidstack.fault
    HKU\S-1-5-21-1942162625-1406552919-4237404059-1005\...\StartupApproved\Run: => "NordVPN"
    Task: {077BA067-7C15-40F0-B22E-C9DC2A54B4A2} - System32\Tasks\Microsoft\Windows\Location\Notifications => %windir%\System32\LocationNotificationWindows.exe (No File)
    Task: {CCDFC0B8-01A3-4E74-A820-4F13F51D269E} - System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => %SystemRoot%\System32\MbaeParserTask.exe (No File)
    Task: {18405566-0481-49A4-A65D-1CC7CAF2276A} - System32\Tasks\Microsoft\Windows\PI\SecureBootEncodeUEFI => %WINDIR%\system32\SecureBootEncodeUEFI.exe (No File)
    Task: {DB607E7D-7179-4ECA-BC0C-B046A83D214F} - System32\Tasks\Microsoft\Windows\rempl\shell-usoscan => %ProgramFiles%\rempl\remsh.exe /RunUsoScanOnly (No File)
    Task: {0BB36A32-0D9E-4297-AFD7-6BD7B5DB4C9B} - System32\Tasks\Microsoft\Windows\UNP\RunUpdateNotificationMgr => %windir%\System32\UNP\UpdateNotificationMgr.exe (No File)
    Task: {6ECC17BA-2F21-4D1D-A937-AF5B7E29ED7A} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot => %systemroot%\system32\MusNotification.exe Reboot (No File)
    Task: {1C8CB2FE-56D5-4457-B4B3-9C6753B62AAF} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_AC => %systemroot%\system32\MusNotification.exe /RunOnAC RebootDialog (No File)
    Task: {98F8B1E5-776E-4E44-A484-47B1D3B8418E} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery => %systemroot%\system32\MusNotification.exe /RunOnBattery RebootDialog (No File)
    Task: {CFC2C4F4-EEA5-4B91-96F2-A16C1BBDA4BF} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_Broker_Display => %systemroot%\system32\MusNotification.exe Display (No File)
    Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
    CustomCLSID: HKU\S-1-5-21-1942162625-1406552919-4237404059-1005_Classes\CLSID\{CB965DF1-B8EA-49C7-BDAD-5457FDC1BF92}\InprocServer32 -> C:\Users\twron\AppData\Local\Microsoft\TeamsMeetingAddin\1.0.20130.1\x64\Microsoft.Teams.AddinLoader.dll => No File
    ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
    cmd: netsh winsock reset catalog
    cmd: netsh int ip reset resetlog.txt
    Reg: reg export HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Defaults\FirewallPolicy\FirewallRules C:\Firewall.reg
    C:\Firewall.reg
    cmd: netsh advfirewall reset
    cmd: netsh advfirewall set allprofiles state ON
    cmd: ipconfig /flushdns
    Removeproxy:
    hosts:
    cmd: sfc /scannow
    cmd: DISM /Online /Cleanup-Image /CheckHealth
    Emptytemp:
    End::
    *****************

    Restore point was successfully created.
    Processes closed successfully.
    "AS: Kaspersky Free (Enabled - Up to date) {B1D2E896-6D96-7460-F17A-838B9D00DD65}" => removed successfully
    HKLM\SOFTWARE\Wow6432Node\Microsoft\Edge\Extensions\fphgeikpdcdcheaochkhldmnfblfogla => removed successfully
    C:\Users\twron\Downloads\MGtools.3-vkHVAF.exe.part => moved successfully
    C:\Users\twron\AppData\Local\.bidstack.fault => moved successfully
    "HKU\S-1-5-21-1942162625-1406552919-4237404059-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run\\NordVPN" => removed successfully
    "HKU\S-1-5-21-1942162625-1406552919-4237404059-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\NordVPN" => not found
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{077BA067-7C15-40F0-B22E-C9DC2A54B4A2}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{077BA067-7C15-40F0-B22E-C9DC2A54B4A2}" => removed successfully
    C:\WINDOWS\System32\Tasks\Microsoft\Windows\Location\Notifications => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Location\Notifications" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CCDFC0B8-01A3-4E74-A820-4F13F51D269E}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CCDFC0B8-01A3-4E74-A820-4F13F51D269E}" => removed successfully
    C:\WINDOWS\System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{18405566-0481-49A4-A65D-1CC7CAF2276A}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{18405566-0481-49A4-A65D-1CC7CAF2276A}" => removed successfully
    C:\WINDOWS\System32\Tasks\Microsoft\Windows\PI\SecureBootEncodeUEFI => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\PI\SecureBootEncodeUEFI" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DB607E7D-7179-4ECA-BC0C-B046A83D214F}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DB607E7D-7179-4ECA-BC0C-B046A83D214F}" => removed successfully
    C:\WINDOWS\System32\Tasks\Microsoft\Windows\rempl\shell-usoscan => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\rempl\shell-usoscan" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0BB36A32-0D9E-4297-AFD7-6BD7B5DB4C9B}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0BB36A32-0D9E-4297-AFD7-6BD7B5DB4C9B}" => removed successfully
    C:\WINDOWS\System32\Tasks\Microsoft\Windows\UNP\RunUpdateNotificationMgr => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UNP\RunUpdateNotificationMgr" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6ECC17BA-2F21-4D1D-A937-AF5B7E29ED7A}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6ECC17BA-2F21-4D1D-A937-AF5B7E29ED7A}" => removed successfully
    C:\WINDOWS\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\Reboot" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1C8CB2FE-56D5-4457-B4B3-9C6753B62AAF}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1C8CB2FE-56D5-4457-B4B3-9C6753B62AAF}" => removed successfully
    C:\WINDOWS\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_AC => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\Reboot_AC" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{98F8B1E5-776E-4E44-A484-47B1D3B8418E}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{98F8B1E5-776E-4E44-A484-47B1D3B8418E}" => removed successfully
    C:\WINDOWS\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CFC2C4F4-EEA5-4B91-96F2-A16C1BBDA4BF}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CFC2C4F4-EEA5-4B91-96F2-A16C1BBDA4BF}" => removed successfully
    C:\WINDOWS\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_Broker_Display => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\USO_Broker_Display" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F3E6E7ED-A196-4E44-8803-55FAB3AD4E29}" => removed successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F3E6E7ED-A196-4E44-8803-55FAB3AD4E29}" => removed successfully
    C:\WINDOWS\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => moved successfully
    "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker" => removed successfully
    HKU\S-1-5-21-1942162625-1406552919-4237404059-1005_Classes\CLSID\{CB965DF1-B8EA-49C7-BDAD-5457FDC1BF92} => removed successfully
    HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxcui => removed successfully

    ========= netsh winsock reset catalog =========


    Sucessfully reset the Winsock Catalog.
    You must restart the computer in order to complete the reset.



    ========= End of CMD: =========


    ========= netsh int ip reset resetlog.txt =========

    Resetting Compartment Forwarding, OK!
    Resetting Compartment, OK!
    Resetting Control Protocol, OK!
    Resetting Echo Sequence Request, OK!
    Resetting Global, OK!
    Resetting Interface, OK!
    Resetting Anycast Address, OK!
    Resetting Multicast Address, OK!
    Resetting Unicast Address, OK!
    Resetting Neighbor, OK!
    Resetting Path, OK!
    Resetting Potential, OK!
    Resetting Prefix Policy, OK!
    Resetting Proxy Neighbor, OK!
    Resetting Route, OK!
    Resetting Site Prefix, OK!
    Resetting Subinterface, OK!
    Resetting Wakeup Pattern, OK!
    Resetting Resolve Neighbor, OK!
    Resetting , OK!
    Resetting , OK!
    Resetting , OK!
    Resetting , OK!
    Resetting , failed.
    Access is denied.

    Resetting , OK!
    Resetting , OK!
    Resetting , OK!
    Resetting , OK!
    Resetting , OK!
    Resetting , OK!
    Resetting , OK!
    Resetting , OK!
    Resetting , OK!
    Resetting , OK!
    Restart the computer to complete this action.



    ========= End of CMD: =========


    ========= reg export HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Defaults\FirewallPolicy\FirewallRules C:\Firewall.reg =========

    The operation completed successfully.


    ========= End of Reg: =========

    C:\Firewall.reg => moved successfully

    ========= netsh advfirewall reset =========

    Ok.



    ========= End of CMD: =========


    ========= netsh advfirewall set allprofiles state ON =========

    Ok.



    ========= End of CMD: =========


    ========= ipconfig /flushdns =========


    Windows IP Configuration

    Successfully flushed the DNS Resolver Cache.


    ========= End of CMD: =========


    ========= RemoveProxy: =========

    "HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully
    "HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully
    "HKU\S-1-5-21-1942162625-1406552919-4237404059-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully
    "HKU\S-1-5-21-1942162625-1406552919-4237404059-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully


    ========= End of RemoveProxy: =========

    C:\Windows\System32\Drivers\etc\hosts => moved successfully
    Hosts restored successfully.

    ========= sfc /scannow =========


    Beginning system scan. This process will take some time.

    Beginning verification phase of system scan.

    Verification 0% complete.
    Verification 1% complete.
    Verification 1% complete.
    Verification 2% complete.
    Verification 2% complete.
    Verification 3% complete.
    Verification 4% complete.
    Verification 4% complete.
    Verification 5% complete.
    Verification 5% complete.
    Verification 6% complete.
    Verification 7% complete.
    Verification 7% complete.
    Verification 8% complete.
    Verification 8% complete.
    Verification 9% complete.
    Verification 9% complete.
    Verification 10% complete.
    Verification 11% complete.
    Verification 11% complete.
    Verification 12% complete.
    Verification 12% complete.
    Verification 13% complete.
    Verification 14% complete.
    Verification 14% complete.
    Verification 15% complete.
    Verification 15% complete.
    Verification 16% complete.
    Verification 16% complete.
    Verification 17% complete.
    Verification 18% complete.
    Verification 18% complete.
    Verification 19% complete.
    Verification 19% complete.
    Verification 20% complete.
    Verification 21% complete.
    Verification 21% complete.
    Verification 22% complete.
    Verification 22% complete.
    Verification 23% complete.
    Verification 24% complete.
    Verification 24% complete.
    Verification 25% complete.
    Verification 25% complete.
    Verification 26% complete.
    Verification 26% complete.
    Verification 27% complete.
    Verification 28% complete.
    Verification 28% complete.
    Verification 29% complete.
    Verification 29% complete.
    Verification 30% complete.
    Verification 31% complete.
    Verification 31% complete.
    Verification 32% complete.
    Verification 32% complete.
    Verification 33% complete.
    Verification 33% complete.
    Verification 34% complete.
    Verification 35% complete.
    Verification 35% complete.
    Verification 36% complete.
    Verification 36% complete.
    Verification 37% complete.
    Verification 38% complete.
    Verification 38% complete.
    Verification 39% complete.
    Verification 39% complete.
    Verification 40% complete.
    Verification 41% complete.
    Verification 41% complete.
    Verification 42% complete.
    Verification 42% complete.
    Verification 43% complete.
    Verification 43% complete.
    Verification 44% complete.
    Verification 45% complete.
    Verification 45% complete.
    Verification 46% complete.
    Verification 46% complete.
    Verification 47% complete.
    Verification 48% complete.
    Verification 48% complete.
    Verification 49% complete.
    Verification 49% complete.
    Verification 50% complete.
    Verification 50% complete.
    Verification 51% complete.
    Verification 52% complete.
    Verification 52% complete.
    Verification 53% complete.
    Verification 53% complete.
    Verification 54% complete.
    Verification 55% complete.
    Verification 55% complete.
    Verification 56% complete.
    Verification 56% complete.
    Verification 57% complete.
    Verification 57% complete.
    Verification 58% complete.
    Verification 59% complete.
    Verification 59% complete.
    Verification 60% complete.
    Verification 60% complete.
    Verification 61% complete.
    Verification 62% complete.
    Verification 62% complete.
    Verification 63% complete.
    Verification 63% complete.
    Verification 64% complete.
    Verification 65% complete.
    Verification 65% complete.
    Verification 66% complete.
    Verification 66% complete.
    Verification 67% complete.
    Verification 67% complete.
    Verification 68% complete.
    Verification 69% complete.
    Verification 69% complete.
    Verification 70% complete.
    Verification 70% complete.
    Verification 71% complete.
    Verification 72% complete.
    Verification 72% complete.
    Verification 73% complete.
    Verification 73% complete.
    Verification 74% complete.
    Verification 74% complete.
    Verification 75% complete.
    Verification 76% complete.
    Verification 76% complete.
    Verification 77% complete.
    Verification 77% complete.
    Verification 78% complete.
    Verification 79% complete.
    Verification 79% complete.
    Verification 80% complete.
    Verification 80% complete.
    Verification 81% complete.
    Verification 82% complete.
    Verification 82% complete.
    Verification 83% complete.
    Verification 83% complete.
    Verification 84% complete.
    Verification 84% complete.
    Verification 85% complete.
    Verification 86% complete.
    Verification 86% complete.
    Verification 87% complete.
    Verification 87% complete.
    Verification 88% complete.
    Verification 89% complete.
    Verification 89% complete.
    Verification 90% complete.
    Verification 90% complete.
    Verification 91% complete.
    Verification 91% complete.
    Verification 92% complete.
    Verification 93% complete.
    Verification 93% complete.
    Verification 94% complete.
    Verification 94% complete.
    Verification 95% complete.
    Verification 96% complete.
    Verification 96% complete.
    Verification 97% complete.
    Verification 97% complete.
    Verification 98% complete.
    Verification 99% complete.
    Verification 99% complete.
    Verification 100% complete.

    Windows Resource Protection found corrupt files and successfully repaired them.
    For online repairs, details are included in the CBS log file located at
    windir\Logs\CBS\CBS.log. For example C:\Windows\Logs\CBS\CBS.log. For offline
    repairs, details are included in the log file provided by the /OFFLOGFILE flag.


    ========= End of CMD: =========


    ========= DISM /Online /Cleanup-Image /CheckHealth =========


    Deployment Image Servicing and Management tool
    Version: 10.0.26100.5074

    Image Version: 10.0.26100.6899

    The component store is repairable.
    The operation completed successfully.


    ========= End of CMD: =========


    =========== EmptyTemp: ==========

    FlushDNS => completed
    BITS transfer queue => 0 B
    DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 49763916 B
    Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 326855702 B
    Windows/system/drivers => 120476053 B
    Edge => 0 B
    Chrome => 36290837 B
    Firefox => 278470139 B
    Opera => 180316 B

    Temp, IE cache, history, cookies, recent:
    Default => 6656 B
    ProgramData => 6656 B
    Public => 6656 B
    systemprofile => 6656 B
    systemprofile32 => 6864 B
    LocalService => 6864 B
    NetworkService => 20656 B
    twron => 986874915 B

    RecycleBin => 0 B
    EmptyTemp: => 1.7 GB temporary data Removed.

    ================================


    The system needed a reboot.

    ==== End of Fixlog 19:33:57 ====
     
  6. Oh My!

    Oh My! Malware Expert Staff Member

    Let's try to repair Adobe Acrobat and see if that helps.

    ===================================================

    Repairing a Program through Programs and Features

    --------------------
    • Click Start, type appwiz.cpl then hit Enter
    • Left click on Adobe Acrobat
    • Click Repair and complete the steps
    • Monitor the system for Adobe notifications
    ===================================================

    Farbar Recovery Scan Tool Fix

    --------------------
    • Right click on the FRST64 icon and select Run as administrator
    • Highlight the below information then hit the Ctrl + C keys at the same time and the text will be copied
    • There is no need to paste the information anywhere, FRST64 will do it for you
    Code:
    Start::
    CloseProcesses:
    cmd: DISM /Online /Cleanup-Image /RestoreHealth
    End::
    
    • Click Fix
    • When completed the tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
    ===================================================

    Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
    • Adobe Acrobat repaired?
    • Fixlog
    • How is the computer running?
     
  7. amateur09

    amateur09 Private E-2

    Trying to do the first step of repair a program, I get to the list of programs but only have 3 choices, organize, uninstall or change, even though the language on the top of the page says repair should be an option. And if I right click the program from that screen only options offered are uninstall or change. Suggestion? I haven't tried the second requested item yet with FRST64.
     
  8. amateur09

    amateur09 Private E-2

    I found the other way to get to repair the adobe program. Running the FRST64 fix now.
     
  9. amateur09

    amateur09 Private E-2

    I did the Adobe repair. I tried running FRST64 twice but I think it timed out after 60 minutes. Computer running better after a web browser is opened and making changes within the tab of a browser. Still overall slow and the disc operation in task manager still shows 100%. Below if the log.
    Fix result of Farbar Recovery Scan Tool (x64) Version: 20-11-2025
    Ran by twron (10-12-2025 18:42:39) Run:3
    Running from C:\Users\twron\Desktop
    Loaded Profiles: twron
    Boot Mode: Normal
    ==============================================

    fixlist content:
    *****************
    Start::
    CloseProcesses:
    cmd: DISM /Online /Cleanup-Image /RestoreHealth
    End::
    *****************

    Processes closed successfully.

    ========= DISM /Online /Cleanup-Image /RestoreHealth =========


    Fixing is terminated due to reaching maximum fixing time of 60 minutes. <==== ATTENTION
     
  10. Oh My!

    Oh My! Malware Expert Staff Member

    Great.

    Please run the FRST Fix again. It may complete this time.
     
  11. amateur09

    amateur09 Private E-2

    Timed out again. Will try tomorrow--you never know what a different day will bring.
     
  12. Oh My!

    Oh My! Malware Expert Staff Member

    The process can take a long time, even longer than FRST64 allows. Rather than try it through FRST64 let's try it another way.

    Click Start, type cmd then select Run as administrator
    type DISM /Online /Cleanup-Image /RestoreHealth and hit Enter
    Let it run for a long time, even more than an hour
     
  13. amateur09

    amateur09 Private E-2

    The last script took just under 6 hours to run. But completed with message at end saying it ran successfully. Takes about 3-4 minutes to start computer after pushing on button and then another minute after putting in log in credentials. First use of an app after starting up, such as firefox, takes a bit to start but works good after that. Much better than before. Downside is this morning I left the computer on and the adobe distiller message came up again wit 13 instances of notitfication running at the same time. I ended up closing those through task manager because it was taking a long time to close each window by clicking on OK. Was running slow after those cleared. I shut down and just started back up as I was out running errands. Will see how it goes. Hopefully good
     
  14. Oh My!

    Oh My! Malware Expert Staff Member

    Thank you for the updated information.

    The computer is an older system so there is only so much we can expect from it.

    Please do this.

    • Remove all power sources from the laptop including the battery if it is accessible
    • Hold down the power button for 30 seconds
    • Reconnect power and boot the computer
    • Monitor boot time to see if there is improvement
    ===================================================

    Farbar Recovery Scan Tool Fix

    --------------------
    • Right click on the FRST64 icon and select Run as administrator
    • Highlight the below information then hit the Ctrl + C keys at the same time and the text will be copied
    • There is no need to paste the information anywhere, FRST64 will do it for you
    Code:
    Start::
    CloseProcesses:
    ExportKey: HKEY_CURRENT_USER\Software\Adobe\Acrobat Distiller\DC\Preferences
    cmd: powercfg /h off
    End::
    
    • Click Fix
    • When completed the tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
    ===================================================

    Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
    • Boot time?
    • Fixlog
     
  15. amateur09

    amateur09 Private E-2

    I can't readily remove the battery, but after depressing the power button, it rebooted quickly. After pressing the power button it took 1:15 to get to the picture screen. After entering log in credentials, the desktop screen came on in 25 seconds and the task bar appeared 15 seconds later. After running FRST64 and restarting it took longer with the spinning dots and took 2:30 to get to the picture screen and then 20 seconds to get to the desktop screen and 1:15 for the taskbar to show. Still not bad. It also looks like there is a security update that keeps trying to install but takes forever. It's KB5072033. I was just doing some web browsing on firefox and the speed that pages were loading was real good--almost immediate.

    Here is the fixlog

    Fix result of Farbar Recovery Scan Tool (x64) Version: 20-11-2025
    Ran by twron (12-12-2025 19:11:08) Run:8
    Running from C:\Users\twron\Desktop
    Loaded Profiles: twron
    Boot Mode: Normal
    ==============================================

    fixlist content:
    *****************
    Start::
    CloseProcesses:
    ExportKey: HKEY_CURRENT_USER\Software\Adobe\Acrobat Distiller\DC\Preferences
    cmd: powercfg /h off
    End::
    *****************

    Processes closed successfully.
    ================== ExportKey: ===================

    [HKU\S-1-5-21-1942162625-1406552919-4237404059-1005\Software\Adobe\Acrobat Distiller\DC\Preferences]

    === End of ExportKey ===

    ========= powercfg /h off =========

    0

    ========= End of CMD: =========



    The system needed a reboot.

    ==== End of Fixlog 19:11:23 ====
     
  16. Oh My!

    Oh My! Malware Expert Staff Member

    Thanks.

    Now this.

    ===================================================

    Farbar Recovery Scan Tool Fix

    --------------------
    • Right click on the FRST64 icon and select Run as administrator
    • Highlight the below information then hit the Ctrl + C keys at the same time and the text will be copied
    • There is no need to paste the information anywhere, FRST64 will do it for you
    Code:
    Start::
    CloseProcesses:
    cmd: powercfg /h on
    Zip: C:\Windows\Logs\CBS
    End::
    
    • Click Fix
    • When completed the tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
    • The tool will create a zipped folder in the same location from where FRST was run with today's date, example: 06.11.2016_13.24.50.zip. Upload the file to GoFile or the file hosting site of your choice and post the download link in your reply.
    ===================================================

    Farbar Recovery Scan Tool SearchAll

    --------------------
    • Launch FRST
    • Copy and paste the following in the Search: box
    Code:
    SearchAll: "Acrobat Distiller"
    
    • Click the Search Files button
    • When completed click OK and a Search.txt document will open on your desktop
    • Attach the report to your reply
    ===================================================

    Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
    • Fixlog
    • Search.txt
    • Download link
     
  17. amateur09

    amateur09 Private E-2

    From running the first scan I couldn't find a .zip file anywhere.


    Fix result of Farbar Recovery Scan Tool (x64) Version: 20-11-2025
    Ran by twron (12-12-2025 21:49:00) Run:9
    Running from C:\Users\twron\Desktop
    Loaded Profiles: twron
    Boot Mode: Normal
    ==============================================

    fixlist content:
    *****************
    Start::
    CloseProcesses:
    cmd: powercfg /h on
    End::
    *****************

    Processes closed successfully.

    ========= powercfg /h on =========

    0

    ========= End of CMD: =========



    The system needed a reboot.

    ==== End of Fixlog 21:51:21 ====
     

    Attached Files:

  18. amateur09

    amateur09 Private E-2

    Further update, disc usage shown in task manager is way down, no longer 100% but when "idling" it's in the single digits.
     
  19. Oh My!

    Oh My! Malware Expert Staff Member

    Are you still getting the Acrobat pop ups?
     
  20. amateur09

    amateur09 Private E-2

    Not yesterday and I had left if on for quite a bit. Will leave on today just to double check.
     
  21. Oh My!

    Oh My! Malware Expert Staff Member

    Good.

    • Using Windows Explorer navigate to the C:\Windows\Logs\CBS folder
    • Right click on the folder, select Send to, then Compressed (zipped) folder
    • A zip file will appear on the Desktop
    • Upload the file to GoFile or the file hosting site of your choice and post the download link in your reply
     
  22. amateur09

    amateur09 Private E-2

  23. Oh My!

    Oh My! Malware Expert Staff Member

    Did this ever complete?
     
  24. amateur09

    amateur09 Private E-2

    It did. I just checked windows update again and it's not there.
     
  25. Oh My!

    Oh My! Malware Expert Staff Member

    Great.

    Let's watch things for a day and see if there are any issues.
     
  26. amateur09

    amateur09 Private E-2

    The computer was on all day and I used it a few times throughout the day. Seems to run really good. Only 1 instance of Acrobat Distiller with the message of "unable to create the temporary folder. Error 5; access denied." This was a different message than I used to get before. It cleared when I hit OK and no other instances of it, so I'm guessing an oddball glitch.
     
  27. Oh My!

    Oh My! Malware Expert Staff Member

    This is a known issue. The 2 recommendations are updating the program or completing an uninstall/reinstall of the program.

    If you would like to pursue it Update Adobe Acrobat.
     
  28. amateur09

    amateur09 Private E-2

    I tried opening adobe to update but I needed log in credentials which I don't have. Will try to guess at some but didn't have time this morning.
     
  29. amateur09

    amateur09 Private E-2

    Not having any luck guessing at the credentials to sign in to adobe. I'll probably leave it for now or delete it later.
     
  30. Oh My!

    Oh My! Malware Expert Staff Member

    Other than that are you having any issues or concerns?
     
  31. amateur09

    amateur09 Private E-2

    Everything seems good. Thanks so much for straightening this out. Probably sounds goofy, but the laptop has sentimental value as I remember being with my son when he bought it. Thanks again!
     
  32. Oh My!

    Oh My! Malware Expert Staff Member

    Doesn't sound goofy at all. Cherish remembrances from the past.

    Here is our final step and some additional information to consider.

    ===================================================

    KpRm by Kernel-panik

    --------------
    • Download KpRm and save it to your Desktop (see here if you must use Chrome)
    • Note: If the file is detected as malware it is not and it is safe to download. The detection is a false positive.
    • Right click on the icon and select Run as administrator
    • Click Yes on the Disclaimer
    • Place a check mark in Delete Tools, Create Restore Point, and Delete in 7 days
    • Click Run
    • Click OK on All operations are completed
    • KpRm will delete itself from you Desktop and you can either save or remove the report that is generated
    • You are free to remove any other tools/reports still remaining
    ===================================================

    All Clean!

    --------------

    Your computer is now clean. Please consider this going forward.

    Thank you for placing your trust in Major Geeks. It was a pleasure serving you.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds