Additional scan result of Farbar Recovery Scan Tool (x64) Version:22-05-2016 01 Ran by [removed] (2016-05-23 22:45:18) Running from C:\Users\[removed]\Downloads\Programs Windows 10 Pro Version 1511 (X64) (2015-12-02 22:53:38) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-852360571-2508265549-582001874-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-852360571-2508265549-582001874-503 - Limited - Disabled) Guest (S-1-5-21-852360571-2508265549-582001874-501 - Limited - Disabled) smart (S-1-5-21-852360571-2508265549-582001874-1001 - Administrator - Enabled) => C:\Users\smart ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) «Minecraft Story Mode» 1.0.0.1 (HKLM-x32\...\«Minecraft Story Mode»_is1) (Version: 1.0.0.1 - Telltale Games) µTorrent (HKU\S-1-5-21-852360571-2508265549-582001874-1001\...\uTorrent) (Version: 3.4.7.42330 - BitTorrent Inc.) 60 Seconds version 60 Seconds (HKLM-x32\...\60 Seconds_is1) (Version: 60 Seconds - ) 60 Seconds! (HKLM-x32\...\{18ECAA06-A523-44CD-9B1A-640DF47A212C}_is1) (Version: 1.103 - Robot Gentleman Studios) A Story About My Uncle (HKLM-x32\...\A Story About My Uncle_R.G. Mechanics_is1) (Version: - R.G. Mechanics, markfiter) Adobe Flash Player 21 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 21.0.0.242 - Adobe Systems Incorporated) Amnesia: The Dark Descent (HKLM-x32\...\Steam App 57300) (Version: - Frictional Games) Batman Arkham Asylum GOTY Edition (HKLM-x32\...\Batman Arkham Asylum GOTY Edition_is1) (Version: - ) Boring Man - Online Tactical Stickman Combat (HKLM-x32\...\Steam App 346120) (Version: - Spasman Games) Canon LBP3000 (HKLM\...\Canon LBP3000) (Version: - ) CodeBlocks (HKU\S-1-5-21-852360571-2508265549-582001874-1001\...\CodeBlocks) (Version: 16.01 - The Code::Blocks Team) Cry of Fear (HKLM\...\Steam App 223710) (Version: - Team Psykskallar) Danganronpa 2 Goodbye Despair (HKLM-x32\...\Danganronpa 2 Goodbye Despair_is1) (Version: - ) Danganronpa: Trigger Happy Havoc - Limited Edition (HKLM-x32\...\Danganronpa: Trigger Happy Havoc - Limited Edition_is1) (Version: - ) Defraggler (HKLM\...\Defraggler) (Version: 2.17 - Piriform) DirectVobSub 2.41.7259 (5d3641a) Beta (64-bit) (HKLM\...\vsfilter64_is1) (Version: 2.41.7259 - MPC-HC Team) Dota 2 (HKLM-x32\...\Steam App 570) (Version: - Valve) Driver Booster 2.4 (HKLM-x32\...\Driver Booster_is1) (Version: 2.4 - IObit) envent USB2.0 UVC PC Camera (HKLM-x32\...\{71A51A91-E7D3-11DB-A386-005056C00008}) (Version: 2010.03.02 - envent) EPUB File Reader (HKLM-x32\...\{818C5857-5C74-4CAC-9F43-E5597086852D}_is1) (Version: - epubfilereader.com) Firewatch (HKLM-x32\...\Firewatch_R.G. Mechanics_is1) (Version: - R.G. Mechanics, markfiter) FTL version 1.5.13 (HKLM-x32\...\{20E23A40-38E5-4DD6-B738-BC8097AE66B6}_is1) (Version: 1.5.13 - Subset Games) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 50.0.2661.102 - Google Inc.) Google Update Helper (x32 Version: 1.3.30.3 - Google Inc.) Hidden Hotline Miami version v1.0 (HKLM-x32\...\{BA30996C-FB03-4395-BB50-727008597E5B}_is1) (Version: v1.0 - ) HP Support Solutions Framework (HKLM-x32\...\{F6A11738-3EE4-4573-AEA5-6CD5D491C167}) (Version: 12.0.30.81 - Hewlett-Packard Company) Internet Download Manager (HKLM-x32\...\Internet Download Manager) (Version: - Tonec Inc.) IPFilter Updater (HKU\S-1-5-21-852360571-2508265549-582001874-1001\...\07140e809c2bb6df) (Version: 2.0.0.4 - David Moore) Java 8 Update 60 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418060F0}) (Version: 8.0.600.27 - Oracle Corporation) K-Lite Codec Pack 11.8.5 Full (HKLM-x32\...\KLiteCodecPack_is1) (Version: 11.8.5 - KLCP) KMSpico v9.3.1 (HKLM\...\KMSpico_is1) (Version: 9.3.1 - ) LogMeIn Hamachi (HKLM-x32\...\LogMeIn Hamachi) (Version: 2.2.0.428 - LogMeIn, Inc.) Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes) Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}) (Version: 3.5.92.0 - Microsoft Corporation) Microsoft Games for Windows Marketplace (HKLM-x32\...\{67F42018-F647-4D3C-BE62-F8CB4FE2FCD5}) (Version: 3.5.67.0 - Microsoft Corporation) Microsoft Office Professional Plus 2013 (HKLM\...\Office15.PROPLUSR) (Version: 15.0.4420.1017 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable - x64 8.0.61000 (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable - x86 8.0.61001 (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 Redistributable - x64 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 Redistributable - x86 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{a2199617-3609-410f-a8e8-e8806c73545b}) (Version: 11.0.61030.0 - Корпорация Майкрософт) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{f0080ca2-80ae-4958-b6eb-e8fa916d744a}) (Version: 11.0.61030.0 - Корпорация Майкрософт) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{1a63c099-febd-4eaf-83ad-a82ea4fdac49}) (Version: 12.0.30501.0 - Корпорация Майкрософт) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{b55f7208-e02b-4828-ac78-59c73ddf5bc7}) (Version: 12.0.30501.0 - Корпорация Майкрософт) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23026 (HKLM-x32\...\{e46eca4f-393b-40df-9f49-076faf788d83}) (Version: 14.0.23026.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23026 (HKLM-x32\...\{74d0e5db-b326-4dae-a6b2-445b9de1836e}) (Version: 14.0.23026.0 - Microsoft Corporation) Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation) Mozilla Firefox 41.0.2 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 41.0.2 (x86 en-US)) (Version: 41.0.2 - Mozilla) Need For Speed The Run (HKLM-x32\...\Need For Speed The Run_R.G. Mechanics_is1) (Version: - R.G. Mechanics, spider91) NVIDIA GeForce Experience 2.9.1.22 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.9.1.22 - NVIDIA Corporation) NVIDIA Graphics Driver 361.75 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 361.75 - NVIDIA Corporation) NVIDIA HD Audio Driver 1.3.34.4 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.4 - NVIDIA Corporation) NVIDIA PhysX System Software 9.15.0428 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation) OpenAL (HKLM-x32\...\OpenAL) (Version: - ) Ori and the Blind Forest (HKLM-x32\...\Ori and the Blind Forest_R.G. Mechanics_is1) (Version: - R.G. Mechanics, markfiter) Outils de vérification linguistique 2013 de Microsoft Office - Français (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden Python 2.7 (64-bit) (HKLM\...\{20c31435-2a0a-4580-be8b-ac06fc243ca5}) (Version: 2.7.150 - Python Software Foundation) Recuva (HKLM\...\Recuva) (Version: 1.51 - Piriform) SHIELD Streaming (Version: 4.1.0260 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: 2.9.1.22 - NVIDIA Corporation) Hidden Skype™ 7.8 (HKLM-x32\...\{6A0549A9-1B96-498C-ACBC-3943001FEB19}) (Version: 7.8.102 - Skype Technologies S.A.) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) SUPERHOT v1.0 / RePack by Azaq (HKLM-x32\...\SUPERHOT_is1) (Version: - ) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.17 - TeamSpeak Systems GmbH) TeamViewer 10 (HKLM-x32\...\TeamViewer) (Version: 10.0.45862 - TeamViewer) The Beginner's Guide (HKU\S-1-5-21-852360571-2508265549-582001874-1001\...\The Beginner's Guide) (Version: 1.0.0.0 - Everything Unlimited) The Walking Dead Michonne Episode 1 (HKLM-x32\...\The Walking Dead Michonne Episode 1_is1) (Version: - ) Total War: Arena (HKLM-x32\...\Steam App 227520) (Version: - Creative Assembly) Unity Web Player (HKU\S-1-5-21-852360571-2508265549-582001874-1001\...\UnityWebPlayer) (Version: 5.2.0f3 - Unity Technologies ApS) UsbFix (HKLM-x32\...\Usbfix) (Version: 8.193 - El Desaparecido - www.usbfix.net - www.sosvirus.net) VLC media player (HKLM\...\VLC media player) (Version: 2.2.1 - VideoLAN) WinRAR 5.30 beta 3 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.30.3 - win.rar GmbH) ZAR X (HKLM\...\{85DA9B81-D7F9-4165-8E62-F776B57213F8}_is1) (Version: - www.z-a-recovery.com) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-852360571-2508265549-582001874-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\smart\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\FileCoAuth.exe (Microsoft Corporation) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {02BE9E2F-D4F2-4A86-ADA2-284C32311340} - System32\Tasks\{E37851B7-E0F0-4421-837B-8E2274CD8267} => Chrome.exe hxxp://ui.skype.com/ui/0/7.12.64.101/en/go/help.faq.installer?LastError=1603 Task: {06FC7513-79B4-4EFC-B2A3-030900E24B3D} - System32\Tasks\Microsoft Office 15 Sync Maintenance for DESKTOP-T26L6GK-smart DESKTOP-T26L6GK => C:\Program Files\Microsoft Office\Office15\MsoSync.exe [2012-10-01] (Microsoft Corporation) Task: {0D8DD923-A0C2-4D75-8111-6224C7A1B864} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation) Task: {1EB9D2A1-8B56-4095-8E59-FBE4DEE9E89B} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation) Task: {2B1785D7-0525-417E-BF48-78EDC818C1A3} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-05-12] (Microsoft Corporation) Task: {3044365F-AD59-4152-A62F-4D5EA579B59F} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-05-13] (Adobe Systems Incorporated) Task: {48C783B8-7FE6-421C-A12B-FB58C1AC31F2} - System32\Tasks\Driver Booster Update => C:\Program Files (x86)\IObit\Driver Booster\AutoUpdate.exe [2015-07-06] (IObit) Task: {6CDEA0FB-D083-4537-A0AF-698B79187CFD} - System32\Tasks\{9483A7AF-95AA-41E4-8058-42F4F788B891} => Chrome.exe hxxp://www.skype.com/go/downloading?source=lightinstaller&ver=7.10.0.101&LastError=12002 Task: {6D64288F-6519-4AED-B0F6-C9B1807380EC} - System32\Tasks\{A1BDACEA-2009-462F-BEA7-7329197C0F59} => Chrome.exe hxxp://ui.skype.com/ui/0/7.10.0.101/en/abandoninstall?source=lightinstaller&page=tsInstall Task: {7BF2A768-E961-46F7-8A22-678CC0AFD54A} - \CCleanerSkipUAC -> No File <==== ATTENTION Task: {A129CDF0-E7CC-4753-ADE1-55DEE967FA50} - System32\Tasks\IntelMemoryDiagnostic => C:\Users\smart\AppData\Roaming\d3dx10.exe [2015-08-13] () Task: {A77CF48D-25A1-4F0B-8A80-36905C2CBF5C} - System32\Tasks\Driver Booster SkipUAC (smart) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe [2015-07-06] (IObit) Task: {B2DF53F7-4ADB-4438-81A2-9975DE049D1A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-05] (Google Inc.) Task: {BD097535-655B-411E-8EEE-B3633075445D} - System32\Tasks\{EF8BA347-5BDA-4832-B80B-ED17B75B0307} => Chrome.exe hxxp://www.skype.com/go/downloading?source=lightinstaller&ver=7.10.0.101&LastError=12002 Task: {BFC061A2-2AEA-498B-A1B4-551E1B2AAF67} - System32\Tasks\Driver Booster Scan => C:\Program Files (x86)\IObit\Driver Booster\Scheduler.exe [2015-07-06] (IObit) Task: {E1F1EF32-F8C3-4846-9DAB-F325A9BF6425} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-05] (Google Inc.) Task: {EB1A7BF9-E535-41A1-A016-A2E0AFE09CBA} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2012-10-01] (Microsoft Corporation) Task: {F9EE37A5-FB2B-4407-BDC0-505439B71FA3} - System32\Tasks\AutoPico Daily Restart => C:\Program Files\KMSpico\AutoPico.exe [2014-06-29] (@ByELDI) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== 2015-10-30 12:47 - 2015-10-30 12:47 - 00028672 _____ () C:\WINDOWS\SYSTEM32\efsext.dll 2015-10-30 12:48 - 2015-10-30 12:48 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll 2015-08-22 12:34 - 2016-01-23 06:31 - 00134712 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2015-09-06 14:30 - 2015-07-07 15:18 - 00020240 _____ () C:\WINDOWS\system32\spool\PRTPROCS\x64\TeamViewer_PrintProcessor.dll 2016-02-05 20:49 - 2016-01-12 10:13 - 00291264 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamBase.dll 2016-04-13 18:11 - 2016-03-29 15:50 - 02656952 _____ () C:\WINDOWS\system32\CoreUIComponents.dll 2016-04-13 18:11 - 2016-03-29 15:50 - 02656952 _____ () C:\WINDOWS\System32\CoreUIComponents.dll 2012-10-01 20:36 - 2012-10-01 20:36 - 06522480 _____ () C:\Program Files\Microsoft Office\Office15\1033\GrooveIntlResource.dll 2015-12-18 17:38 - 2015-12-07 09:44 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll 2016-05-12 15:47 - 2016-04-23 09:55 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll 2016-05-12 15:52 - 2016-04-23 09:32 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2016-05-12 15:51 - 2016-04-23 09:28 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2016-05-12 15:52 - 2016-04-23 09:28 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll 2016-05-12 15:52 - 2016-04-23 09:31 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll 2016-04-19 15:20 - 2016-04-19 15:29 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe 2016-05-12 15:52 - 2016-04-23 09:28 - 00936960 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll 2016-05-12 15:52 - 2016-04-23 09:27 - 00098304 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\DeviceSideServicesActionUriHandler.dll 2016-05-12 15:52 - 2016-04-23 09:27 - 00529408 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.NodeWinrtWrap.dll 2015-10-30 12:48 - 2015-10-30 14:37 - 00037888 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\dss_service\node_modules\winrt-projections\bin\Winrt_Projections.node 2015-08-22 12:46 - 2016-01-12 10:13 - 00018880 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll 2016-05-21 11:43 - 2016-05-21 11:43 - 00073728 _____ () C:\Users\smart\AppData\Local\Udqmedia\WlxExt80.dll 2015-08-23 20:25 - 2016-04-30 01:40 - 00785920 _____ () D:\Steam\SDL2.dll 2015-08-23 20:24 - 2015-07-03 21:42 - 04962816 _____ () D:\Steam\v8.dll 2015-08-23 20:25 - 2016-04-30 05:40 - 02549840 _____ () D:\Steam\video.dll 2015-08-23 20:24 - 2015-07-03 21:42 - 01556992 _____ () D:\Steam\icui18n.dll 2015-08-23 20:24 - 2015-07-03 21:42 - 01187840 _____ () D:\Steam\icuuc.dll 2015-08-23 20:24 - 2016-02-09 04:44 - 02549760 _____ () D:\Steam\libavcodec-56.dll 2015-08-23 20:24 - 2016-02-09 04:44 - 00491008 _____ () D:\Steam\libavformat-56.dll 2015-08-23 20:24 - 2016-02-09 04:44 - 00332800 _____ () D:\Steam\libavresample-2.dll 2015-08-23 20:24 - 2016-02-09 04:44 - 00442880 _____ () D:\Steam\libavutil-54.dll 2015-08-23 20:24 - 2016-02-09 04:44 - 00485888 _____ () D:\Steam\libswscale-3.dll 2015-08-23 20:24 - 2016-04-30 05:40 - 00829008 _____ () D:\Steam\bin\chromehtml.DLL 2016-03-10 08:52 - 2016-02-18 03:55 - 00281088 _____ () D:\Steam\openvr_api.dll 2015-08-23 20:24 - 2016-04-28 06:30 - 49825056 _____ () D:\Steam\bin\libcef.dll 2015-08-23 20:24 - 2015-09-25 05:26 - 00119208 _____ () D:\Steam\winh264.dll 2016-04-19 15:20 - 2016-04-19 15:29 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll 2016-04-19 15:20 - 2016-04-19 15:29 - 22284800 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkyWrap.dll 2016-05-13 16:10 - 2016-05-11 17:18 - 01738904 _____ () C:\Program Files (x86)\Google\Chrome\Application\50.0.2661.102\libglesv2.dll 2016-05-13 16:10 - 2016-05-11 17:18 - 00086168 _____ () C:\Program Files (x86)\Google\Chrome\Application\50.0.2661.102\libegl.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Hamachi2Svc => ""="Service" ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2015-07-10 16:34 - 2015-07-10 16:32 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-852360571-2508265549-582001874-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\smart\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper DNS Servers: 192.168.0.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) HKLM\...\StartupApproved\Run: => "ShadowPlay" HKLM\...\StartupApproved\Run: => "NvBackend" HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched" HKLM\...\StartupApproved\Run32: => "VMonitorVMUVC" HKU\S-1-5-21-852360571-2508265549-582001874-1001\...\StartupApproved\Run: => "OneDrive" HKU\S-1-5-21-852360571-2508265549-582001874-1001\...\StartupApproved\Run: => "IDMan" HKU\S-1-5-21-852360571-2508265549-582001874-1001\...\StartupApproved\Run: => "CCleaner Monitoring" HKU\S-1-5-21-852360571-2508265549-582001874-1001\...\StartupApproved\Run: => "Insoft" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [{F642BAE4-4D95-4428-B77A-9AB2F0C0CC59}] => (Allow) D:\Games\Minecraft Story Mode\Rusfix64.reg FirewallRules: [{6DE03CE3-3E49-426C-A859-0071C612C1FC}] => (Allow) D:\Games\Minecraft Story Mode\Rusfix64.reg FirewallRules: [{49A67B1E-2FFC-4B25-85E0-3BD97BAC31A2}] => (Allow) D:\Games\Minecraft Story Mode\Rusifx32.reg FirewallRules: [{34BD9720-0650-4DDE-AA47-C496C5BFA4F5}] => (Allow) D:\Games\Minecraft Story Mode\Rusifx32.reg FirewallRules: [{256BF68C-8468-42F4-A700-8CD579965B48}] => (Allow) D:\Games\Minecraft Story Mode\MinecraftStoryMode.exe FirewallRules: [{22FF58DE-2C9E-4B41-888D-29D64ED2D462}] => (Allow) D:\Games\Minecraft Story Mode\MinecraftStoryMode.exe FirewallRules: [UDP Query User{48E96BA3-A595-4C85-A37D-6A00F4A6FA9F}D:\games\the beginner's guide\beginnersguide.exe] => (Block) D:\games\the beginner's guide\beginnersguide.exe FirewallRules: [TCP Query User{F66E7348-6B20-4BDB-B6E6-FC08F617A074}D:\games\the beginner's guide\beginnersguide.exe] => (Block) D:\games\the beginner's guide\beginnersguide.exe FirewallRules: [{47C4CB4E-EE33-4443-84C6-5A1D5CBDD9DF}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{78AE12BE-A6A0-4B38-8809-3D1870104A64}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{599CAA40-2A0C-423E-A4AC-B3F3ED263CC6}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{D7A6449E-AAC6-4461-9E5C-886A02F79057}] => (Allow) D:\Steam\steamapps\common\Amnesia The Dark Descent\Launcher.exe FirewallRules: [{648A06E2-2223-4A77-99AE-FFFEDCE06650}] => (Allow) D:\Steam\steamapps\common\Amnesia The Dark Descent\Launcher.exe FirewallRules: [{D4AE30F9-E748-42EE-B5DD-949177DB2852}] => (Allow) D:\Steam\steamapps\common\Amnesia The Dark Descent\Amnesia.exe FirewallRules: [{E08CC341-F44C-4C50-8719-1502612FA052}] => (Allow) D:\Steam\steamapps\common\Amnesia The Dark Descent\Amnesia.exe FirewallRules: [{D3841CEC-86AD-40E4-B164-7B99A634D6E2}] => (Allow) C:\Users\smart\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{EF818E5C-6E83-4053-B074-6B08B59CFF2E}] => (Allow) C:\Users\smart\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{DC19C5BF-860C-4FD8-A878-D71AD008E07F}] => (Allow) C:\Users\smart\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{8E4E5042-E613-4E18-8E73-58AF0FFA221A}] => (Allow) C:\Users\smart\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{46F77AD5-6CA9-43CE-A236-D60AAC726A0D}] => (Allow) C:\Users\smart\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{2A665581-DFB6-49B0-B890-751B728E0423}] => (Allow) C:\Users\smart\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{3BD9214B-7E74-4957-BA73-79F07B36513F}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{26E10081-C71F-4483-8F2B-1064CA8FCD13}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{904A88D4-0F6F-4EB5-9C79-85E10B12EF4B}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{4E676775-56EA-4DDD-BED5-B2A192B86DA1}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{96FF5AF3-9478-4729-AEF5-EFBC7B33B493}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{D7ED6F3A-B2A6-4492-8DF4-61F571D7DE6A}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{87CACB12-1BCC-41C4-8611-C18A48CAA322}] => (Allow) C:\Windows\System32\CNAB3RPD.EXE FirewallRules: [{A8897F26-B317-4A73-970C-47F3AED09EFA}] => (Allow) C:\Windows\System32\CNAB3RPD.EXE FirewallRules: [{23174E1B-4FA3-4B02-B0F5-AFA3D7429160}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\dota.exe FirewallRules: [{1003EF95-1775-420F-AABA-38CC909391E9}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\dota.exe FirewallRules: [{30CB0511-2F97-4405-A3E4-864FF6FAF67A}] => (Allow) D:\Steam\bin\steamwebhelper.exe FirewallRules: [{6E21F2C3-1C53-473C-A7D3-6B79EE8083F6}] => (Allow) D:\Steam\bin\steamwebhelper.exe FirewallRules: [{6DBDAE6E-65C6-4316-A451-7DD8A9967B9F}] => (Allow) D:\Steam\Steam.exe FirewallRules: [{C81B63A3-19D8-49FD-AF20-9AC7FFAE7FCC}] => (Allow) D:\Steam\Steam.exe FirewallRules: [{F0D05864-E225-4CD3-A53A-0269A4B5DD8D}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{14FDD406-9D96-4049-AE7C-13603A933683}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{CF617044-228C-4FC2-8ED2-BC2E7B871784}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe FirewallRules: [{53F2D7EB-F063-4120-B316-69180957379E}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{2D9B7536-4498-48C3-BE16-31EAE4BC07E9}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{8645135D-41A1-4691-9D08-ACBFE5EA149F}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{8B96F7A4-76D4-4A9F-B80C-4B4E5ECC015F}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [TCP Query User{DEDBE066-7006-43B6-A60E-0B9689FC1519}D:\games\ben.and.ed\benanded\binaries\win64\benanded.exe] => (Allow) D:\games\ben.and.ed\benanded\binaries\win64\benanded.exe FirewallRules: [UDP Query User{41A89D6F-58F1-4209-9F48-45226F163E31}D:\games\ben.and.ed\benanded\binaries\win64\benanded.exe] => (Allow) D:\games\ben.and.ed\benanded\binaries\win64\benanded.exe FirewallRules: [TCP Query User{BF35FE62-5DC5-470E-BD70-CD76CCF3E561}D:\games\batman arkham asylum goty edition\binaries\shippingpc-bmgame.exe] => (Allow) D:\games\batman arkham asylum goty edition\binaries\shippingpc-bmgame.exe FirewallRules: [UDP Query User{612FCE1B-7026-4B0E-9284-FC0AFDFAFBE0}D:\games\batman arkham asylum goty edition\binaries\shippingpc-bmgame.exe] => (Allow) D:\games\batman arkham asylum goty edition\binaries\shippingpc-bmgame.exe FirewallRules: [TCP Query User{8BAFE462-ACF8-45BC-91E7-8F38F50E4B91}C:\program files\java\jre1.8.0_60\bin\javaw.exe] => (Block) C:\program files\java\jre1.8.0_60\bin\javaw.exe FirewallRules: [UDP Query User{53D63F4B-3838-4A6A-A81A-9BD4CE7C5367}C:\program files\java\jre1.8.0_60\bin\javaw.exe] => (Block) C:\program files\java\jre1.8.0_60\bin\javaw.exe FirewallRules: [TCP Query User{B89D4453-9493-4584-A20D-A5FE146C62AE}D:\games\a story about my uncle\binaries\win32\asamu-win32-shipping.exe] => (Allow) D:\games\a story about my uncle\binaries\win32\asamu-win32-shipping.exe FirewallRules: [UDP Query User{7F97BCD0-5B9E-4D04-ABE4-3F6BDDDBC455}D:\games\a story about my uncle\binaries\win32\asamu-win32-shipping.exe] => (Allow) D:\games\a story about my uncle\binaries\win32\asamu-win32-shipping.exe FirewallRules: [{3843E00A-038A-4D0D-8DF8-6A7AC3E96A0B}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe FirewallRules: [{5C21B6B6-F64A-43D5-B4BF-69DEC48C5839}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe FirewallRules: [{C0A0D4E3-3810-459A-B4C1-048191509474}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe FirewallRules: [{982F8499-43D9-4681-BD77-8C83DB43F0E4}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe FirewallRules: [{80AD01D5-F3B6-43AC-A9DE-7BAB43DAB2E4}] => (Allow) C:\Program Files\KMSpico\KMSELDI.exe FirewallRules: [{925F0C5E-063C-4036-8654-609BB352DEB1}] => (Allow) C:\Program Files\KMSpico\KMSELDI.exe FirewallRules: [{A87C16D2-22DB-4521-9BFF-9B4488935B4C}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe FirewallRules: [{2C6FCD65-3573-431F-B270-23CA4D85ECD2}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe FirewallRules: [{6EB155BE-EAC6-405D-B203-D882F998D0D5}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe FirewallRules: [{B2706086-2C0F-4B05-BDFA-2F52E36FDAD3}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe FirewallRules: [TCP Query User{5519A1E8-1EAC-41C4-983A-A3F58D282E2B}C:\users\smart\appdata\local\temp\rar$exa0.659\guedin's aot fan game 0.0.10.2 - win64\aot_v02\binaries\win64\aot_v02.exe] => (Block) C:\users\smart\appdata\local\temp\rar$exa0.659\guedin's aot fan game 0.0.10.2 - win64\aot_v02\binaries\win64\aot_v02.exe FirewallRules: [UDP Query User{FC3B9A15-063E-4E6E-913E-8F4EA1AC7172}C:\users\smart\appdata\local\temp\rar$exa0.659\guedin's aot fan game 0.0.10.2 - win64\aot_v02\binaries\win64\aot_v02.exe] => (Block) C:\users\smart\appdata\local\temp\rar$exa0.659\guedin's aot fan game 0.0.10.2 - win64\aot_v02\binaries\win64\aot_v02.exe FirewallRules: [TCP Query User{FF39C82F-7BA3-4428-9C96-56A2C01579B8}C:\users\smart\appdata\local\temp\rar$exa0.805\guedin's aot fan game 0.0.10.2 - win64\aot_v02\binaries\win64\aot_v02.exe] => (Block) C:\users\smart\appdata\local\temp\rar$exa0.805\guedin's aot fan game 0.0.10.2 - win64\aot_v02\binaries\win64\aot_v02.exe FirewallRules: [UDP Query User{E4076BB9-B6AE-4AAA-97BA-614630B4C362}C:\users\smart\appdata\local\temp\rar$exa0.805\guedin's aot fan game 0.0.10.2 - win64\aot_v02\binaries\win64\aot_v02.exe] => (Block) C:\users\smart\appdata\local\temp\rar$exa0.805\guedin's aot fan game 0.0.10.2 - win64\aot_v02\binaries\win64\aot_v02.exe FirewallRules: [TCP Query User{E6C3C663-D26E-4A27-9472-ABFFE9B470E2}C:\users\smart\appdata\local\temp\rar$exa0.838\guedin's aot fan game 0.0.10.2 - win64\aot_v02\binaries\win64\aot_v02.exe] => (Block) C:\users\smart\appdata\local\temp\rar$exa0.838\guedin's aot fan game 0.0.10.2 - win64\aot_v02\binaries\win64\aot_v02.exe FirewallRules: [UDP Query User{4FAE26D3-E8F4-4E3C-B9A8-AC8226CCE0F2}C:\users\smart\appdata\local\temp\rar$exa0.838\guedin's aot fan game 0.0.10.2 - win64\aot_v02\binaries\win64\aot_v02.exe] => (Block) C:\users\smart\appdata\local\temp\rar$exa0.838\guedin's aot fan game 0.0.10.2 - win64\aot_v02\binaries\win64\aot_v02.exe FirewallRules: [{2646F866-3900-4F65-BA54-A3FC70707A5A}] => (Allow) D:\Steam\steamapps\common\Boring Man - Online Tactical Stickman Combat\BoringManGame.exe FirewallRules: [{68E6C419-087B-40CD-90D5-463F5E0F17BB}] => (Allow) D:\Steam\steamapps\common\Boring Man - Online Tactical Stickman Combat\BoringManGame.exe FirewallRules: [{7C54F893-7F5A-4C80-8C5C-E491D36030FC}] => (Allow) D:\Steam\steamapps\common\Boring Man - Online Tactical Stickman Combat\BoringEditor\BoringEditor.exe FirewallRules: [{EEFB858D-876F-4D9B-B709-709D25F090FD}] => (Allow) D:\Steam\steamapps\common\Boring Man - Online Tactical Stickman Combat\BoringEditor\BoringEditor.exe FirewallRules: [TCP Query User{CC29A296-9914-42A1-B65C-4A0EB8797020}C:\users\smart\appdata\local\temp\rar$exa0.122\guedin's aot fan game 0.0.10.2 - win64\aot_v02\binaries\win64\aot_v02.exe] => (Allow) C:\users\smart\appdata\local\temp\rar$exa0.122\guedin's aot fan game 0.0.10.2 - win64\aot_v02\binaries\win64\aot_v02.exe FirewallRules: [UDP Query User{28B08BDF-E263-4210-B3DC-71DF1B8DFCCE}C:\users\smart\appdata\local\temp\rar$exa0.122\guedin's aot fan game 0.0.10.2 - win64\aot_v02\binaries\win64\aot_v02.exe] => (Allow) C:\users\smart\appdata\local\temp\rar$exa0.122\guedin's aot fan game 0.0.10.2 - win64\aot_v02\binaries\win64\aot_v02.exe FirewallRules: [TCP Query User{5479D7BD-86EB-4AC4-BAD2-FBB2C801F8E6}C:\users\smart\downloads\compressed\atatck on titan game (demo)\guedin's aot fan game 0.0.10.2 - win64\aot_v02\binaries\win64\aot_v02.exe] => (Block) C:\users\smart\downloads\compressed\atatck on titan game (demo)\guedin's aot fan game 0.0.10.2 - win64\aot_v02\binaries\win64\aot_v02.exe FirewallRules: [UDP Query User{65C38A22-69CD-4963-B161-DB200592EC84}C:\users\smart\downloads\compressed\atatck on titan game (demo)\guedin's aot fan game 0.0.10.2 - win64\aot_v02\binaries\win64\aot_v02.exe] => (Block) C:\users\smart\downloads\compressed\atatck on titan game (demo)\guedin's aot fan game 0.0.10.2 - win64\aot_v02\binaries\win64\aot_v02.exe FirewallRules: [{45E0CB7C-07A0-435A-B706-0E750697B37D}] => (Allow) D:\Steam\steamapps\common\Cry of Fear\CoFLaunchApp.exe FirewallRules: [{3536DE83-23B9-4847-9CD3-C2F98580F0D4}] => (Allow) D:\Steam\steamapps\common\Cry of Fear\CoFLaunchApp.exe FirewallRules: [TCP Query User{2B3D8AF9-B147-4F1D-9F76-18CB15173F8A}D:\steam\steamapps\common\cry of fear\cof.exe] => (Allow) D:\steam\steamapps\common\cry of fear\cof.exe FirewallRules: [UDP Query User{77769813-3531-4463-B2BB-3717B255B249}D:\steam\steamapps\common\cry of fear\cof.exe] => (Allow) D:\steam\steamapps\common\cry of fear\cof.exe FirewallRules: [{430F765A-5F99-4351-80CB-4C4361BB1238}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{B2837A80-2187-4A1A-80F3-DD3D31414242}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe FirewallRules: [{87970862-3A47-4ABD-9D13-723C3CCAE655}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe FirewallRules: [{5792FF90-955D-4498-8865-40CFB5909346}] => (Allow) LPort=1688 FirewallRules: [{065BC5D1-7445-41A4-89A1-90F34C6D3C28}] => (Allow) LPort=1688 ==================== Restore Points ========================= ATTENTION: System Restore is disabled ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (05/23/2016 09:39:47 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: Service_KMS.exe, version: 13.3.0.0, time stamp: 0x53b06ef6 Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000 Exception code: 0x00000000 Fault offset: 0x00007ffb41880668 Faulting process id: 0x7b0 Faulting application start time: 0xService_KMS.exe0 Faulting application path: Service_KMS.exe1 Faulting module path: Service_KMS.exe2 Report Id: Service_KMS.exe3 Faulting package full name: Service_KMS.exe4 Faulting package-relative application ID: Service_KMS.exe5 Error: (05/23/2016 09:37:31 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: ShellExperienceHost.exe, version: 10.0.10586.306, time stamp: 0x571afaa5 Faulting module name: twinapi.appcore.dll, version: 10.0.10586.0, time stamp: 0x5632d2f5 Exception code: 0xc000027b Fault offset: 0x000000000004b199 Faulting process id: 0x17ac Faulting application start time: 0xShellExperienceHost.exe0 Faulting application path: ShellExperienceHost.exe1 Faulting module path: ShellExperienceHost.exe2 Report Id: ShellExperienceHost.exe3 Faulting package full name: ShellExperienceHost.exe4 Faulting package-relative application ID: ShellExperienceHost.exe5 Error: (05/23/2016 09:37:23 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: ShellExperienceHost.exe, version: 10.0.10586.306, time stamp: 0x571afaa5 Faulting module name: twinapi.appcore.dll, version: 10.0.10586.0, time stamp: 0x5632d2f5 Exception code: 0xc000027b Fault offset: 0x000000000004b199 Faulting process id: 0x1464 Faulting application start time: 0xShellExperienceHost.exe0 Faulting application path: ShellExperienceHost.exe1 Faulting module path: ShellExperienceHost.exe2 Report Id: ShellExperienceHost.exe3 Faulting package full name: ShellExperienceHost.exe4 Faulting package-relative application ID: ShellExperienceHost.exe5 Error: (05/23/2016 09:37:12 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: ShellExperienceHost.exe, version: 10.0.10586.306, time stamp: 0x571afaa5 Faulting module name: twinapi.appcore.dll, version: 10.0.10586.0, time stamp: 0x5632d2f5 Exception code: 0xc000027b Fault offset: 0x000000000004b199 Faulting process id: 0xe24 Faulting application start time: 0xShellExperienceHost.exe0 Faulting application path: ShellExperienceHost.exe1 Faulting module path: ShellExperienceHost.exe2 Report Id: ShellExperienceHost.exe3 Faulting package full name: ShellExperienceHost.exe4 Faulting package-relative application ID: ShellExperienceHost.exe5 Error: (05/23/2016 09:36:13 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: ShellExperienceHost.exe, version: 10.0.10586.306, time stamp: 0x571afaa5 Faulting module name: Windows.UI.Xaml.dll, version: 10.0.10586.306, time stamp: 0x571af9f6 Exception code: 0xc000027b Fault offset: 0x00000000006fcd2b Faulting process id: 0x730 Faulting application start time: 0xShellExperienceHost.exe0 Faulting application path: ShellExperienceHost.exe1 Faulting module path: ShellExperienceHost.exe2 Report Id: ShellExperienceHost.exe3 Faulting package full name: ShellExperienceHost.exe4 Faulting package-relative application ID: ShellExperienceHost.exe5 Error: (05/23/2016 09:35:39 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: ShellExperienceHost.exe, version: 10.0.10586.306, time stamp: 0x571afaa5 Faulting module name: twinapi.appcore.dll, version: 10.0.10586.0, time stamp: 0x5632d2f5 Exception code: 0xc000027b Fault offset: 0x000000000004b199 Faulting process id: 0x1020 Faulting application start time: 0xShellExperienceHost.exe0 Faulting application path: ShellExperienceHost.exe1 Faulting module path: ShellExperienceHost.exe2 Report Id: ShellExperienceHost.exe3 Faulting package full name: ShellExperienceHost.exe4 Faulting package-relative application ID: ShellExperienceHost.exe5 Error: (05/23/2016 09:35:30 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: Service_KMS.exe, version: 13.3.0.0, time stamp: 0x53b06ef6 Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000 Exception code: 0x00000000 Fault offset: 0x00007ff848e60668 Faulting process id: 0x724 Faulting application start time: 0xService_KMS.exe0 Faulting application path: Service_KMS.exe1 Faulting module path: Service_KMS.exe2 Report Id: Service_KMS.exe3 Faulting package full name: Service_KMS.exe4 Faulting package-relative application ID: Service_KMS.exe5 Error: (05/23/2016 09:35:21 PM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1542) (User: NT AUTHORITY) Description: Windows cannot load classes registry file. DETAIL - The process cannot access the file because it is being used by another process. Error: (05/23/2016 09:35:21 PM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1508) (User: NT AUTHORITY) Description: Windows was unable to load the registry. This problem is often caused by insufficient memory or insufficient security rights. DETAIL - The process cannot access the file because it is being used by another process. for C:\Users\smart\AppData\Local\Microsoft\Windows\\UsrClass.dat Error: (05/23/2016 08:57:20 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DESKTOP-T26L6GK) Description: Activation of app Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI failed with error: -2147024865 See the Microsoft-Windows-TWinUI/Operational log for additional information. System errors: ============= Error: (05/23/2016 09:42:29 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The Service KMSELDI service terminated unexpectedly. It has done this 1 time(s). Error: (05/23/2016 09:39:11 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: The previous system shutdown at 9:34:56 PM on ‎5/‎23/‎2016 was unexpected. Error: (05/23/2016 09:34:56 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: The previous system shutdown at 8:35:38 PM on ‎5/‎23/‎2016 was unexpected. Error: (05/23/2016 09:12:26 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-T26L6GK) Description: CortanaUI.AppXjxtspbn4351hrtx8tc95e89kaz3h2f1f.mca Error: (05/23/2016 09:07:42 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-T26L6GK) Description: CortanaUI.AppX8z5q44mt1b9k6x2nkjj0bkr2e1ac0dxy.mca Error: (05/23/2016 08:57:20 PM) (Source: DCOM) (EventID: 10001) (User: DESKTOP-T26L6GK) Description: "C:\WINDOWS\system32\backgroundTaskHost.exe" -ServerName:CortanaUI.AppXy7vb4pc2dr3kc93kfc509b1d0arkfb2x.mca31CortanaUI.AppXtpp90jhw9p0njjb85kvhxpppgrqfp117.mcaUnavailableUnavailable Error: (05/23/2016 08:57:20 PM) (Source: DCOM) (EventID: 10001) (User: DESKTOP-T26L6GK) Description: "C:\WINDOWS\system32\backgroundTaskHost.exe" -ServerName:CortanaUI.AppXy7vb4pc2dr3kc93kfc509b1d0arkfb2x.mca31CortanaUI.AppXjxtspbn4351hrtx8tc95e89kaz3h2f1f.mcaUnavailableUnavailable Error: (05/23/2016 08:57:19 PM) (Source: DCOM) (EventID: 10001) (User: DESKTOP-T26L6GK) Description: "C:\WINDOWS\system32\backgroundTaskHost.exe" -ServerName:CortanaUI.AppXy7vb4pc2dr3kc93kfc509b1d0arkfb2x.mca31CortanaUI.AppXjxtspbn4351hrtx8tc95e89kaz3h2f1f.mcaUnavailableUnavailable Error: (05/23/2016 08:57:19 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-T26L6GK) Description: CortanaUI.AppX66vvx0wsdb34y1dm8b872ypnaj4fqty0.mca Error: (05/23/2016 08:57:19 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-T26L6GK) Description: CortanaUI.AppX66vvx0wsdb34y1dm8b872ypnaj4fqty0.mca CodeIntegrity: =================================== Date: 2016-05-23 09:07:51.219 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-05-21 08:26:48.731 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-05-15 11:59:39.741 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-05-15 07:24:24.869 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-05-15 07:01:45.869 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-05-14 09:35:28.275 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-05-13 23:00:14.305 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-05-13 21:18:19.823 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-05-12 23:00:07.551 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-05-11 15:23:37.810 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. ==================== Memory info =========================== Processor: AMD Athlon(tm) 64 Processor 3500+ Percentage of memory in use: 73% Total physical RAM: 2047.55 MB Available physical RAM: 538.93 MB Total Virtual: 2943.55 MB Available Virtual: 950.2 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:97.56 GB) (Free:45.08 GB) NTFS Drive d: () (Fixed) (Total:390.62 GB) (Free:183.73 GB) NTFS Drive e: () (Fixed) (Total:443.23 GB) (Free:401.98 GB) NTFS Drive g: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS ==>[system with boot components (obtained from drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: EE29AA09) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=97.6 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=390.6 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=443.2 GB) - (Type=07 NTFS) ==================== End of Addition.txt ============================