Additional scan result of Farbar Recovery Scan Tool (x64) Version:07-01-2015 Ran by [removed] (2016-01-09 11:11:54) Running from C:\Users\[removed]\Desktop Windows 10 Home (X64) (2015-12-22 11:10:33) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= DefaultAccount (S-1-5-21-3322993352-708763500-3136390609-503 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-3322993352-708763500-3136390609-1006 - Limited - Enabled) Järjestelmänvalvoja (S-1-5-21-3322993352-708763500-3136390609-500 - Administrator - Disabled) UpdatusUser (S-1-5-21-3322993352-708763500-3136390609-1001 - Limited - Enabled) => C:\Users\UpdatusUser Vesa (S-1-5-21-3322993352-708763500-3136390609-1002 - Administrator - Enabled) => C:\Users\Vesa Vieras (S-1-5-21-3322993352-708763500-3136390609-501 - Limited - Disabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Ace Stream Media 3.0.12 (HKU\S-1-5-21-3322993352-708763500-3136390609-1002\...\AceStream) (Version: 3.0.12 - Ace Stream Media) <==== ATTENTION Avast Premier (HKLM-x32\...\Avast) (Version: 11.1.2245 - AVAST Software) BOINC (HKLM\...\{085CC3D7-09D0-4488-BAD2-A57E909EE1EC}) (Version: 7.6.9 - Space Sciences Laboratory, U.C. Berkeley) ELAN Touchpad 15.8.4.3_X64_WHQL (HKLM\...\Elantech) (Version: 15.8.4.3 - ELAN Microelectronic Corp.) eLicenser Control (HKLM-x32\...\eLicenser Control) (Version: 6.9.2.1182 - Steinberg Media Technologies GmbH) f.lux (HKU\S-1-5-21-3322993352-708763500-3136390609-1002\...\Flux) (Version: - ) Freemake Audio Converter version 1.1.7 (HKLM-x32\...\Freemake Audio Converter_is1) (Version: 1.1.7 - Ellora Assets Corporation) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 47.0.2526.106 - Google Inc.) Google Update Helper (x32 Version: 1.3.29.1 - Google Inc.) Hidden Lexicon Alpha Driver (HKLM-x32\...\Lexicon Alpha Driver) (Version: - Lexicon) Lexicon Alpha Driver (Version: 2.6 - Lexicon) Hidden Lexicon Pantheon VST Plug-in (remove only) (HKLM-x32\...\LexiconStudio) (Version: - ) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) MyHeritage Family Tree Builder (HKLM-x32\...\Family Tree Builder) (Version: 7.0.0.7143 - MyHeritage.com) OpenOffice 4.1.0 (HKLM-x32\...\{0F524843-3FEE-4FF7-BBE1-D718319D92F4}) (Version: 4.10.9764 - Apache Software Foundation) Oracle VM VirtualBox 4.3.12 (HKLM\...\{B5121457-0126-4E62-BCBF-6DC7C73D9E4A}) (Version: 4.3.12 - Oracle Corporation) Popcorn Time (HKU\S-1-5-21-3322993352-708763500-3136390609-1002\...\Popcorn Time) (Version: - Popcorn Official) SafeZone Stable 1.46.1990.139 (x32 Version: 1.46.1990.139 - Avast Software) Hidden SopCast 3.9.6 (HKLM-x32\...\SopCast) (Version: 3.9.6 - www.sopcast.com) Spotify (HKU\S-1-5-21-3322993352-708763500-3136390609-1002\...\Spotify) (Version: 1.0.20.94.g8f8543b3 - Spotify AB) Steinberg Cubase LE 5 (HKLM-x32\...\{50C78780-1A54-4A5C-B3A7-FF828C62C5C2}) (Version: 5.1.2 - Steinberg Media Technologies GmbH) Steinberg HALionOne (HKLM-x32\...\{E70E7159-93B1-470D-9FBD-D8E9EF34B538}) (Version: 1.1.0.457 - Steinberg Media Technologies GmbH) Steinberg HALionOne Essential Set (HKLM-x32\...\{C04D5974-F528-4347-A494-EAF56124CC1A}) (Version: 1.0.1.457 - Steinberg Media Technologies GmbH) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-3322993352-708763500-3136390609-1002_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Vesa\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\FileCoAuth.exe (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3322993352-708763500-3136390609-1002_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\WINDOWS\system32\igfxEM.exe (Intel Corporation) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {71203B43-8870-4080-A768-51020F91BE66} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-12-22] (Google Inc.) Task: {75AAD5AD-3B56-4C28-A8AA-9667BD4B32FA} - System32\Tasks\Microsoft\Windows\UPnP\UPnPHostConfig => config upnphost start= auto Task: {97C6B3E3-83C1-4A55-917F-52308B947B43} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-12-22] (Google Inc.) Task: {AA8A5A78-2FF3-4BFD-AB84-81DF523721E7} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2016-01-08] (AVAST Software) Task: {D2A6536C-EA25-46EA-A585-DACD69DF1CC8} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-11-23] (Microsoft Corporation) Task: {D2E6DE16-3302-4CC5-9FA3-7C21DF924348} - System32\Tasks\SafeZone scheduled Autoupdate 1452330455 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2015-12-01] (Avast Software) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== 2015-10-30 09:18 - 2015-10-30 09:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll 2015-07-13 19:45 - 2015-07-13 19:45 - 00011920 _____ () C:\Program Files\NVIDIA Corporation\CoProcManager\detoured.dll 2015-12-22 13:00 - 2015-07-13 19:37 - 00116552 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2015-12-21 17:34 - 2015-11-22 12:47 - 02653816 _____ () C:\WINDOWS\system32\CoreUIComponents.dll 2015-12-21 17:34 - 2015-11-22 12:47 - 02653816 _____ () C:\WINDOWS\System32\CoreUIComponents.dll 2015-12-21 17:34 - 2015-12-07 06:14 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll 2015-12-21 17:34 - 2015-12-07 06:00 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll 2015-12-21 17:35 - 2015-12-07 05:37 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2015-12-21 17:34 - 2015-12-07 05:33 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2015-12-21 17:34 - 2015-12-07 05:34 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll 2015-12-21 17:34 - 2015-12-07 05:36 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll 2014-10-01 18:37 - 2015-12-18 16:07 - 00027000 _____ () C:\Users\Vesa\AppData\Roaming\ACEStream\updater\ace_update.exe 2015-12-26 13:43 - 2015-12-23 15:22 - 00073216 _____ () C:\Program Files (x86)\Common Files\Freemake Shared\ProductUpdater\ProductUpdater.exe 2013-10-15 13:31 - 2013-10-15 13:31 - 00106496 _____ () C:\Program Files\BOINC\zlib1.dll 2015-12-23 09:44 - 2015-12-23 09:44 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.12.15004.0_x86__8wekyb3d8bbwe\SkypeHost.exe 2015-12-22 15:14 - 2015-12-22 15:14 - 01690624 _____ () C:\ProgramData\BOINC\projects\milkyway.cs.rpi.edu_milkyway\milkyway_nbody_1.54_windows_x86_64__mt.exe 2016-01-08 20:57 - 2016-01-08 20:57 - 00103888 _____ () C:\Program Files\AVAST Software\Avast\log.dll 2016-01-08 20:57 - 2016-01-08 20:57 - 00125512 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll 2016-01-08 20:58 - 2016-01-08 20:58 - 02990080 _____ () C:\Program Files\AVAST Software\Avast\defs\15110499\algo.dll 2016-01-08 20:57 - 2016-01-08 20:57 - 00469008 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll 2016-01-08 20:57 - 2016-01-08 20:57 - 00241896 _____ () C:\Program Files\AVAST Software\Avast\browser_pass.dll 2016-01-09 01:01 - 2016-01-09 01:01 - 02821120 _____ () C:\Program Files\AVAST Software\Avast\defs\16010801\algo.dll 2015-12-22 13:51 - 2015-12-11 05:54 - 01583432 _____ () C:\Program Files (x86)\Google\Chrome\Application\47.0.2526.106\libglesv2.dll 2015-12-22 13:51 - 2015-12-11 05:54 - 00081224 _____ () C:\Program Files (x86)\Google\Chrome\Application\47.0.2526.106\libegl.dll 2015-07-13 19:45 - 2015-07-13 19:45 - 00011920 _____ () C:\Program Files (x86)\NVIDIA Corporation\CoProcManager\detoured.dll 2011-06-12 15:09 - 2011-06-12 15:09 - 00038400 _____ () C:\Users\Vesa\AppData\Roaming\ACEStream\updater\lib\_socket.pyd 2011-06-12 15:09 - 2011-06-12 15:09 - 00720896 _____ () C:\Users\Vesa\AppData\Roaming\ACEStream\updater\lib\_ssl.pyd 2011-07-15 21:37 - 2011-07-15 21:37 - 00981504 _____ () C:\Users\Vesa\AppData\Roaming\ACEStream\updater\lib\wx._core_.pyd 2011-07-15 21:38 - 2011-07-15 21:38 - 00746496 _____ () C:\Users\Vesa\AppData\Roaming\ACEStream\updater\lib\wx._gdi_.pyd 2011-07-15 21:38 - 2011-07-15 21:38 - 00670720 _____ () C:\Users\Vesa\AppData\Roaming\ACEStream\updater\lib\wx._windows_.pyd 2011-07-15 21:38 - 2011-07-15 21:38 - 00966144 _____ () C:\Users\Vesa\AppData\Roaming\ACEStream\updater\lib\wx._controls_.pyd 2011-07-15 21:38 - 2011-07-15 21:38 - 00674816 _____ () C:\Users\Vesa\AppData\Roaming\ACEStream\updater\lib\wx._misc_.pyd 2011-06-12 15:06 - 2011-06-12 15:06 - 00287232 _____ () C:\Users\Vesa\AppData\Roaming\ACEStream\updater\lib\_hashlib.pyd 2011-01-18 23:56 - 2011-01-18 23:56 - 00334336 _____ () C:\Users\Vesa\AppData\Roaming\ACEStream\updater\lib\M2Crypto.__m2crypto.pyd 2011-06-12 15:06 - 2011-06-12 15:06 - 00011776 _____ () C:\Users\Vesa\AppData\Roaming\ACEStream\updater\lib\select.pyd 2011-06-12 15:06 - 2011-06-12 15:06 - 00152576 _____ () C:\Users\Vesa\AppData\Roaming\ACEStream\updater\lib\pyexpat.pyd 2012-02-07 18:37 - 2012-02-07 18:37 - 00098816 _____ () C:\Users\Vesa\AppData\Roaming\ACEStream\updater\lib\win32api.pyd 2012-02-07 18:35 - 2012-02-07 18:35 - 00110080 _____ () C:\Users\Vesa\AppData\Roaming\ACEStream\updater\lib\pywintypes27.dll 2012-02-07 18:38 - 2012-02-07 18:38 - 00358912 _____ () C:\Users\Vesa\AppData\Roaming\ACEStream\updater\lib\pythoncom27.dll 2012-02-07 18:36 - 2012-02-07 18:36 - 00111616 _____ () C:\Users\Vesa\AppData\Roaming\ACEStream\updater\lib\win32file.pyd 2012-02-07 18:36 - 2012-02-07 18:36 - 00024064 _____ () C:\Users\Vesa\AppData\Roaming\ACEStream\updater\lib\win32pdh.pyd 2016-01-08 20:57 - 2016-01-08 20:57 - 40539648 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2015-12-23 09:44 - 2015-12-23 09:44 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.12.15004.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll 2015-12-23 09:44 - 2015-12-23 09:44 - 21845504 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.12.15004.0_x86__8wekyb3d8bbwe\SkyWrap.dll 2015-12-25 21:51 - 2015-12-24 07:46 - 16792256 _____ () C:\Users\Vesa\AppData\Local\Google\Chrome\User Data\PepperFlash\20.0.0.267\pepflashplayer.dll 2016-01-08 20:57 - 2016-01-08 20:57 - 00984576 _____ () C:\Program Files\AVAST Software\Avast\ffmpegsumo.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2015-12-22 12:39 - 2015-12-22 12:36 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-3322993352-708763500-3136390609-1002\Control Panel\Desktop\\Wallpaper -> C:\Users\Vesa\Desktop\thaimed.jpg DNS Servers: 192.168.8.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [{58050EBE-DF07-4F6F-A104-7B5D23DB8A07}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [TCP Query User{0CF960BA-14C1-450F-B5CC-33D6AB9F04EE}C:\users\vesa\appdata\roaming\acestream\engine\ace_engine.exe] => (Allow) C:\users\vesa\appdata\roaming\acestream\engine\ace_engine.exe FirewallRules: [UDP Query User{244CE049-C63E-41DB-8894-AADED711CCAA}C:\users\vesa\appdata\roaming\acestream\engine\ace_engine.exe] => (Allow) C:\users\vesa\appdata\roaming\acestream\engine\ace_engine.exe FirewallRules: [{287D243F-8D93-4FE3-BFCF-3C5422811390}] => (Block) C:\users\vesa\appdata\roaming\acestream\engine\ace_engine.exe FirewallRules: [{A4E3FC11-10F4-4CE1-81C7-8BD50BF122E8}] => (Block) C:\users\vesa\appdata\roaming\acestream\engine\ace_engine.exe FirewallRules: [TCP Query User{04D26DAA-DD52-4130-AB9B-F3C9CC37814C}C:\users\vesa\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\vesa\appdata\roaming\spotify\spotify.exe FirewallRules: [UDP Query User{49982E40-BB0A-4305-BC11-4D58A1F3426F}C:\users\vesa\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\vesa\appdata\roaming\spotify\spotify.exe FirewallRules: [{6B2DD1C5-A23F-41D4-A9A3-2522FC73B0C3}] => (Block) C:\users\vesa\appdata\roaming\spotify\spotify.exe FirewallRules: [{05C13E01-D53F-4435-82A2-D3E725BE9702}] => (Block) C:\users\vesa\appdata\roaming\spotify\spotify.exe FirewallRules: [TCP Query User{927A9F3D-B1EB-42E1-B6CD-72164E823D22}C:\users\vesa\appdata\local\popcorn time\nw.exe] => (Allow) C:\users\vesa\appdata\local\popcorn time\nw.exe FirewallRules: [UDP Query User{C160BF1D-D105-44D5-AE45-E3E36A8F13CA}C:\users\vesa\appdata\local\popcorn time\nw.exe] => (Allow) C:\users\vesa\appdata\local\popcorn time\nw.exe FirewallRules: [{BD49A0A1-B308-4E4A-BA57-EB10EB8111E2}] => (Block) C:\users\vesa\appdata\local\popcorn time\nw.exe FirewallRules: [{68B6F90F-661B-4E26-9D97-E610CDC40A09}] => (Block) C:\users\vesa\appdata\local\popcorn time\nw.exe ==================== Restore Points ========================= 22-12-2015 13:32:16 Installed Steinberg Cubase LE 5 29-12-2015 18:09:35 Windowsin moduulien asennusohjelma 05-01-2016 21:39:06 Windows Update ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (01/08/2016 04:32:04 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: BITSC:\Windows\System32\bitsperf.dll8 Error: (01/07/2016 10:06:17 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: VESKUNKONE) Description: Sovelluksen Microsoft.Windows.Photos_8wekyb3d8bbwe!App aktivointi epäonnistui, virhe: -2147023170. Lisätietoja on Microsoft-Windows-TWinUI/Toiminnassa-lokissa. Error: (01/06/2016 10:24:40 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: VESKUNKONE) Description: Sovelluksen Microsoft.Windows.Photos_8wekyb3d8bbwe!App aktivointi epäonnistui, virhe: -2147023170. Lisätietoja on Microsoft-Windows-TWinUI/Toiminnassa-lokissa. Error: (01/06/2016 10:24:40 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: VESKUNKONE) Description: Sovelluksen Microsoft.Windows.Photos_8wekyb3d8bbwe!App aktivointi epäonnistui, virhe: -2147023170. Lisätietoja on Microsoft-Windows-TWinUI/Toiminnassa-lokissa. Error: (01/05/2016 09:39:15 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Salauspalvelut eivät voineet käsitellä OnIdentity()-kutsua järjestelmän kirjoitusobjektissa. Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoftin linkkikerroksen etsintäprotokolla. System Error: Käyttö estetty. . Error: (01/05/2016 10:28:17 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Viallisen sovelluksen nimi: ShellExperienceHost.exe, versio: 10.0.10586.35, aikaleima: 0x566505bc Viallisen moduulin nimi: QuickActions.dll, versio: 0.0.0.0, aikaleima: 0x56650458 Poikkeuskoodi: 0xc0000005 Virhepoikkeama: 0x0000000000001931 Viallisen prosessin tunnus: 0xc1c Viallisen sovelluksen käynnistysaika: 0xShellExperienceHost.exe0 Viallisen sovelluksen polku: ShellExperienceHost.exe1 Viallisen moduulin polku: ShellExperienceHost.exe2 Raportin tunnus: ShellExperienceHost.exe3 Viallisen paketin koko nimi: ShellExperienceHost.exe4 Viallisen paketin suhteellinen sovellustunnus: ShellExperienceHost.exe5 Error: (01/04/2016 02:44:26 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Viallisen sovelluksen nimi: winsat.exe, versio: 10.0.10586.0, aikaleima: 0x5632d4bb Viallisen moduulin nimi: igdumdim64.dll_unloaded, versio: 10.18.10.4276, aikaleima: 0x55d1ff23 Poikkeuskoodi: 0xc0000005 Virhepoikkeama: 0x0000000000021260 Viallisen prosessin tunnus: 0x574 Viallisen sovelluksen käynnistysaika: 0xwinsat.exe0 Viallisen sovelluksen polku: winsat.exe1 Viallisen moduulin polku: winsat.exe2 Raportin tunnus: winsat.exe3 Viallisen paketin koko nimi: winsat.exe4 Viallisen paketin suhteellinen sovellustunnus: winsat.exe5 Error: (01/04/2016 02:36:47 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: VESKUNKONE) Description: Sovelluksen Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI aktivointi epäonnistui, virhe: -2144927141. Lisätietoja on Microsoft-Windows-TWinUI/Toiminnassa-lokissa. Error: (01/04/2016 02:36:47 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: VESKUNKONE) Description: Sovelluksen Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI aktivointi epäonnistui, virhe: -2144927141. Lisätietoja on Microsoft-Windows-TWinUI/Toiminnassa-lokissa. Error: (01/04/2016 10:08:03 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: VESKUNKONE) Description: Sovelluksen Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI aktivointi epäonnistui, virhe: -2144927141. Lisätietoja on Microsoft-Windows-TWinUI/Toiminnassa-lokissa. System errors: ============= Error: (01/09/2016 11:07:43 AM) (Source: DCOM) (EventID: 10016) (User: VESKUNKONE) Description: tietokoneen oletusarvoPaikallinenAktivointi{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}VeskunkoneVesaS-1-5-21-3322993352-708763500-3136390609-1002LocalHost (LRPC käytössä)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742 Error: (01/09/2016 11:07:43 AM) (Source: DCOM) (EventID: 10016) (User: VESKUNKONE) Description: tietokoneen oletusarvoPaikallinenAktivointi{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}VeskunkoneVesaS-1-5-21-3322993352-708763500-3136390609-1002LocalHost (LRPC käytössä)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742 Error: (01/09/2016 10:05:45 AM) (Source: DCOM) (EventID: 10016) (User: NT-hallinta) Description: sovelluskohtainenPaikallinenAktivointi{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT-hallintaSYSTEMS-1-5-18LocalHost (LRPC käytössä)Ei käytettävissäEi käytettävissä Error: (01/09/2016 01:33:40 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Palvelu Käyttäjätietojen käyttöoikeudet_1f8f4e on päättynyt odottamatta. Tämä on tapahtunut 1 kertaa. 10000 millisekunnin kuluttua suoritetaan seuraava korjaustoimi: Käynnistä palvelu uudelleen. Error: (01/09/2016 01:33:40 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Palvelu Käyttäjätietosäilö_1f8f4e on päättynyt odottamatta. Tämä on tapahtunut 1 kertaa. 10000 millisekunnin kuluttua suoritetaan seuraava korjaustoimi: Käynnistä palvelu uudelleen. Error: (01/09/2016 01:33:40 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Palvelu Yhteystiedot_1f8f4e on päättynyt odottamatta. Tämä on tapahtunut 1 kertaa. 10000 millisekunnin kuluttua suoritetaan seuraava korjaustoimi: Käynnistä palvelu uudelleen. Error: (01/09/2016 01:33:40 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Palvelu Synkronoi isäntä_1f8f4e on päättynyt odottamatta. Tämä on tapahtunut 1 kertaa. 10000 millisekunnin kuluttua suoritetaan seuraava korjaustoimi: Käynnistä palvelu uudelleen. Error: (01/09/2016 01:33:40 AM) (Source: DCOM) (EventID: 10016) (User: NT-hallinta) Description: sovelluskohtainenPaikallinenAktivointi{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT-hallintaSYSTEMS-1-5-18LocalHost (LRPC käytössä)Ei käytettävissäEi käytettävissä Error: (01/09/2016 01:33:12 AM) (Source: DCOM) (EventID: 10016) (User: VESKUNKONE) Description: tietokoneen oletusarvoPaikallinenAktivointi{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}VeskunkoneVesaS-1-5-21-3322993352-708763500-3136390609-1002LocalHost (LRPC käytössä)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742 Error: (01/08/2016 08:02:30 PM) (Source: DCOM) (EventID: 10016) (User: NT-hallinta) Description: sovelluskohtainenPaikallinenAktivointi{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT-hallintaSYSTEMS-1-5-18LocalHost (LRPC käytössä)Ei käytettävissäEi käytettävissä CodeIntegrity: =================================== Date: 2016-01-06 21:14:24.035 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-01-06 10:27:52.411 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2015-12-31 08:00:30.577 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2015-12-29 18:14:00.227 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2015-12-23 09:34:49.703 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2015-12-22 16:26:59.430 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2015-12-22 15:45:29.772 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2015-12-22 15:22:40.777 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2015-12-22 13:33:04.270 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2015-12-22 12:58:02.319 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i5-3230M CPU @ 2.60GHz Percentage of memory in use: 34% Total physical RAM: 8077.57 MB Available physical RAM: 5265.43 MB Total Virtual: 9357.57 MB Available Virtual: 6360.31 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:185.86 GB) (Free:147.35 GB) NTFS ==>[system with boot components (obtained from drive)] Drive d: (Data) (Fixed) (Total:258.44 GB) (Free:210.9 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 465.8 GB) (Disk ID: 253E1A55) Partition: GPT. ==================== End of Addition.txt ============================