Additional scan result of Farbar Recovery Scan Tool (x64) Version: 25-07-2016 Ran by [removed] (2016-07-25 12:05:40) Running from C:\Users\[removed]\Desktop Windows 10 Home Version 1511 (X64) (2015-12-09 19:00:07) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-609271163-2674588117-1738407549-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-609271163-2674588117-1738407549-503 - Limited - Disabled) Guest (S-1-5-21-609271163-2674588117-1738407549-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-609271163-2674588117-1738407549-1003 - Limited - Enabled) Rohit (S-1-5-21-609271163-2674588117-1738407549-1001 - Administrator - Enabled) => C:\Users\Rohit ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov) Ableton Live 9 Suite (HKLM\...\{99C4D476-0AF0-4045-998F-E11CA4957BDB}) (Version: 9.0.0.0 - Ableton) ACPI Driver Installer (HKLM-x32\...\553E35CD-0415-41bc-B39A-410375E88534) (Version: 2.1 - Intel Corporation) Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.017.20050 - Adobe Systems Incorporated) Adobe Flash Player 22 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 22.0.0.209 - Adobe Systems Incorporated) Apple Application Support (32-bit) (HKLM-x32\...\{D4B07658-F443-4445-A261-E643996E139D}) (Version: 4.3.2 - Apple Inc.) Apple Application Support (64-bit) (HKLM\...\{A6B0442B-E159-444B-B49D-6B9AC531EAE3}) (Version: 4.3.2 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{2E4AF2A6-50EA-4260-9BA4-5E582D11879A}) (Version: 9.3.0.15 - Apple Inc.) Apple Software Update (HKLM-x32\...\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.) ASIO4ALL (HKLM-x32\...\ASIO4ALL) (Version: 2.12 - Michael Tippach) Audacity 2.1.1 (HKLM-x32\...\Audacity®_is1) (Version: 2.1.1 - Audacity Team) Bastion (HKLM-x32\...\Steam App 107100) (Version: - Supergiant Games) Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.) Brother MFL-Pro Suite MFC-J450DW (HKLM-x32\...\{7B4C83B6-17C1-4BFD-B86D-4D7AD4498CBB}) (Version: 1.0.4.0 - Brother Industries, Ltd.) Evernote v. 6.1.2 (HKLM-x32\...\{A46ABD1E-2837-11E6-9E7C-005056951CAD}) (Version: 6.1.2.2292 - Evernote Corp.) Fallout 4 (HKLM-x32\...\Steam App 377160) (Version: - Bethesda Game Studios) Focusrite Scarlett Family Audio Driver 3.1.10 (HKLM\...\Focusrite Scarlett Family Audio Driver_is1) (Version: 3.1.10 - Focusrite Audio Engineering Limited.) Freemake Audio Converter version 1.1.8 (HKLM-x32\...\Freemake Audio Converter_is1) (Version: 1.1.8 - Ellora Assets Corporation) GOG Galaxy (HKLM-x32\...\{7258BA11-600C-430E-A759-27E2C691A335}_is1) (Version: - GOG.com) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 51.0.2704.103 - Google Inc.) Google Drive (HKLM-x32\...\{709316AD-161C-4D5C-9AE7-0B3A822DA271}) (Version: 1.30.2170.0459 - Google, Inc.) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.30.3 - Google Inc.) Hidden Intel(R) Chipset Device Software (x32 Version: 10.0.20 - Intel(R) Corporation) Hidden Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 10.0.28.1006 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3650 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 13.1.0.1058 - Intel Corporation) Intel(R) Smart Connect Technology (HKLM\...\{3CC1CC76-AB3A-4360-AB6F-1355D05A2A17}) (Version: 5.0.10.2907 - Intel Corporation) Intel® Watchdog Timer Driver (Intel® WDT) (HKLM-x32\...\{3FD0C489-0F02-481a-A3E1-9754CD396761}) (Version: - Intel Corporation) Intel® Watchdog Timer Driver (Intel® WDT) (HKLM-x32\...\3FD0C489-0F02-481a-A3E1-9754CD396761) (Version: - Intel Corporation) iTunes (HKLM\...\{E109B4A3-9883-4E6E-9A19-4D7E1A88AFE8}) (Version: 12.4.2.4 - Apple Inc.) Java 8 Update 101 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180101F0}) (Version: 8.0.1010.13 - Oracle Corporation) Kodi (HKU\S-1-5-21-609271163-2674588117-1738407549-1001\...\Kodi) (Version: - XBMC-Foundation) Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes) Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation) Microsoft Office Professional 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50428.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23918 (HKLM-x32\...\{dab68466-3a7d-41a8-a5cf-415e3ff8ef71}) (Version: 14.0.23918.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23918 (HKLM-x32\...\{2e085fd2-a3e4-4b39-8e10-6b8d35f55244}) (Version: 14.0.23918.0 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Microsoft XNA Framework Redistributable 3.1 (HKLM-x32\...\{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}) (Version: 3.1.10527.0 - Microsoft Corporation) Mozilla Firefox 47.0 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 47.0 (x86 en-US)) (Version: 47.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 47.0.0.5999 - Mozilla) MSI Intel Extreme Tuning Utility (HKLM-x32\...\{56351c83-306c-4135-a570-2784d3025548}) (Version: 5.1.0.101 - Intel Corporation) MSI Intel Extreme Tuning Utility (x32 Version: 5.1.0.101 - Intel Corporation) Hidden MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation) Native Instruments Abbey Road 60s Drums Vintage (HKLM-x32\...\Native Instruments Abbey Road 60s Drums Vintage) (Version: - Native Instruments) Native Instruments Controller Editor (HKLM-x32\...\Native Instruments Controller Editor) (Version: 1.9.3.355 - Native Instruments) Native Instruments Guitar Rig 5 (HKLM-x32\...\Native Instruments Guitar Rig 5) (Version: 5.2.0.2770 - Native Instruments) Native Instruments Guitar Rig Elements for Maschine (HKLM-x32\...\Native Instruments Guitar Rig Elements for Maschine) (Version: - Native Instruments) Native Instruments Guitar Rig Mobile IO Driver (HKLM-x32\...\Native Instruments Guitar Rig Mobile IO Driver) (Version: - Native Instruments) Native Instruments Guitar Rig Session IO Driver (HKLM-x32\...\Native Instruments Guitar Rig Session IO Driver) (Version: - Native Instruments) Native Instruments Komplete Elements Mk2 (HKLM-x32\...\Native Instruments Komplete Elements Mk2) (Version: - Native Instruments) Native Instruments Komplete Kontrol Driver (HKLM-x32\...\Native Instruments Komplete Kontrol Driver) (Version: - Native Instruments) Native Instruments Kontakt 5 (HKLM-x32\...\Native Instruments Kontakt 5) (Version: 5.5.1.451 - Native Instruments) Native Instruments Kontakt Elements Selection R2 (HKLM-x32\...\Native Instruments Kontakt Elements Selection R2) (Version: - Native Instruments) Native Instruments Maschine (HKLM-x32\...\Native Instruments Maschine) (Version: - Native Instruments) Native Instruments Maschine 2 (HKLM-x32\...\Native Instruments Maschine 2) (Version: 2.4.0.4769 - Native Instruments) Native Instruments Maschine 2 Factory Library (HKLM-x32\...\Native Instruments Maschine 2 Factory Library) (Version: 1.2.0.4 - Native Instruments) Native Instruments Maschine Controller Driver (HKLM-x32\...\Native Instruments Maschine Controller Driver) (Version: - Native Instruments) Native Instruments Maschine Controller MK2 Driver (HKLM-x32\...\Native Instruments Maschine Controller MK2 Driver) (Version: - Native Instruments) Native Instruments Maschine Mikro Driver (HKLM-x32\...\Native Instruments Maschine Mikro Driver) (Version: - Native Instruments) Native Instruments Maschine Mikro MK2 Driver (HKLM-x32\...\Native Instruments Maschine Mikro MK2 Driver) (Version: - Native Instruments) Native Instruments Massive (HKLM-x32\...\Native Instruments Massive) (Version: 1.5.1.637 - Native Instruments) Native Instruments Reaktor 5 (HKLM-x32\...\Native Instruments Reaktor 5) (Version: 5.9.3.1344 - Native Instruments) Native Instruments Reaktor Elements Selection (HKLM-x32\...\Native Instruments Reaktor Elements Selection) (Version: - Native Instruments) Native Instruments Reaktor Spark R2 (HKLM-x32\...\Native Instruments Reaktor Spark R2) (Version: 1.4.0.3 - Native Instruments) Native Instruments Rig Kontrol 3 Driver (HKLM-x32\...\Native Instruments Rig Kontrol 3 Driver) (Version: - Native Instruments) Native Instruments Service Center (HKLM-x32\...\Native Instruments Service Center) (Version: 2.6.0.137 - Native Instruments) Nexus Mod Manager (HKLM\...\6af12c54-643b-4752-87d0-8335503010de_is1) (Version: 0.61.2 - Black Tree Gaming) Nuance PaperPort 12 (HKLM-x32\...\{869FCC6C-5669-4B0B-827E-2BBAACD88A87}) (Version: 12.1.0006 - Nuance Communications, Inc.) Nuance PDF Viewer Plus (HKLM-x32\...\{28656860-4728-433C-8AD4-D1A930437BC8}) (Version: 5.30.3290 - Nuance Communications, Inc) NVIDIA 3D Vision Controller Driver 352.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 352.65 - NVIDIA Corporation) NVIDIA 3D Vision Driver 361.43 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 361.43 - NVIDIA Corporation) NVIDIA GeForce Experience 2.8.1.21 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.8.1.21 - NVIDIA Corporation) NVIDIA Graphics Driver 361.43 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 361.43 - NVIDIA Corporation) NVIDIA HD Audio Driver 1.3.34.4 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.4 - NVIDIA Corporation) NVIDIA Miracast Virtual Audio 358.50 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Miracast.VirtualAudio) (Version: 358.50 - NVIDIA Corporation) NVIDIA PhysX System Software 9.15.0428 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation) PaperPort Image Printer 64-bit (HKLM\...\{715CAACC-579B-4831-A5F4-A83A8DE3EFE2}) (Version: 14.00.0000 - Nuance Communications, Inc.) Popcorn-Time (HKU\S-1-5-21-609271163-2674588117-1738407549-1001\...\Popcorn-Time) (Version: 0.3.9 - Popcorn Time) Qualcomm Atheros Bandwidth Control Filter Driver (Version: 1.1.47.1058 - Qualcomm Atheros) Hidden Qualcomm Atheros Killer E220x Drivers (Version: 1.1.47.1058 - Qualcomm Atheros) Hidden Qualcomm Atheros Killer Performance Suite (HKLM-x32\...\{E70DB50B-10B4-46BC-9DE2-AB8B49E061EE}) (Version: 1.1.47.1058 - Qualcomm Atheros) Qualcomm Atheros Network Manager (Version: 1.1.47.1058 - Qualcomm Atheros) Hidden Razer Chroma SDK Core Components (HKLM-x32\...\Razer Chroma SDK) (Version: 1.7.8 - Razer Inc.) Razer Synapse (HKLM-x32\...\{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}) (Version: 2.20.15.707 - Razer Inc.) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7293 - Realtek Semiconductor Corp.) Samsung Magician (HKLM-x32\...\{29AE3F9F-7158-4ca7-B1ED-28A73ECDB215}_is1) (Version: 4.9 - Samsung Electronics) Scansoft PDF Professional (x32 Version: - ) Hidden Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft) SHIELD Streaming (Version: 4.1.0260 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: 2.9.1.22 - NVIDIA Corporation) Hidden Skype™ 7.15 (HKLM-x32\...\{6A0549A9-1B96-498C-ACBC-3943001FEB19}) (Version: 7.15.103 - Skype Technologies S.A.) Sound Blaster Cinema 2 (HKLM-x32\...\{B4F6F8CC-2C61-42CC-A4CC-76621F25BDC7}) (Version: 1.00.07 - Creative Technology Limited) Spotify (HKU\S-1-5-21-609271163-2674588117-1738407549-1001\...\Spotify) (Version: 1.0.33.106.g60b5d1f0 - Spotify AB) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) The Witcher 3 - Wild Hunt (HKLM-x32\...\1207664643_is1) (Version: 1.22.0.0 - GOG.com) The Witcher 3: Wild Hunt - Free DLC program (16 DLC) (HKLM-x32\...\Free DLC program (16 DLC)_is1) (Version: 1.22.0.0 - GOG.com) The Witcher 3: Wild Hunt - Hearts of Stone (HKLM-x32\...\Hearts of Stone_is1) (Version: 1.22.0.0 - GOG.com) VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.4 - VideoLAN) WIDCOMM Bluetooth Software (HKLM\...\{C6D9ED03-6FCF-4410-9CB7-45CA285F9E11}) (Version: 12.0.0.2700 - Broadcom Corporation) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-609271163-2674588117-1738407549-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Rohit\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\FileCoAuth.exe (Microsoft Corporation) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {038E4D98-B27D-4172-98C1-AF2883A11DD8} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION Task: {05F2A23E-0229-4CFF-877A-3CD4E7BB0DE0} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION Task: {0A2D20D5-953C-4D9E-8C1B-49F0AB2CE9C1} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-18] (Google Inc.) Task: {2849E0FB-4122-4EF3-AAA8-B36D115F829B} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.) Task: {328F6C4E-3E29-4110-9446-6A633A929894} - System32\Tasks\{D63366CC-55E1-4C20-9967-FDE2DF5180D9} => pcalua.exe -a C:\Users\Rohit\Desktop\Setup_WIN8.exe -d C:\Users\Rohit\Desktop Task: {37BD1151-4955-4AD1-A708-ECF2D4B1054E} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION Task: {3E7E5970-2AC7-419F-AF3D-1D8888890EF2} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-07-12] (Adobe Systems Incorporated) Task: {420A986B-CB98-483E-AEE2-3CF9482DEB9D} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION Task: {47386723-8C19-42B2-B8F8-6D284666EC92} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION Task: {47D5D66E-C53F-4776-84E4-75133E5B8BE3} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-07-13] (Microsoft Corporation) Task: {86EA1EE8-68FA-421A-91B1-6860752A4CDB} - System32\Tasks\SamsungMagician => C:\Program Files (x86)\Samsung\Samsung Magician\Samsung Magician.exe [2015-11-06] (Samsung Electronics.) Task: {902B5CF4-90C6-42B1-A680-A34537DAA192} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION Task: {997E9138-1120-430B-9B23-1A2C9805AB95} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION Task: {9E054B76-6A00-40F4-B66F-7428BFC3C289} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION Task: {B6F56F92-FD40-45D8-88C2-7396AEE18666} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION Task: {B837B058-040D-4116-8A9B-C8B4F6BCB503} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION Task: {CB013AB5-956A-4204-BBFB-0BA65A4AAF7D} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-18] (Google Inc.) Task: {EBA20AC9-6035-4124-BF44-1914218B0477} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-06-25] (Adobe Systems Incorporated) Task: {F12565E6-86F4-474A-A259-33D106D3037D} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION Task: {FC54F7CB-B029-476A-97FF-76850BFA41E5} - System32\Tasks\{0ACCC56E-D680-EEE9-57A8-62B47713AF21} => C:\Users\Rohit\AppData\Roaming\{F6A8C~1\sync.exe [2013-04-17] () <==== ATTENTION (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\{0ACCC56E-D680-EEE9-57A8-62B47713AF21}.job => C:\Users\Rohit\AppData\Roaming\{F6A8C~1\sync.exe <==== ATTENTION ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) ShortcutWithArgument: C:\Users\Rohit\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\69639df789022856\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory="Profile 1" ==================== Loaded Modules (Whitelisted) ============== 2015-10-30 00:17 - 2015-10-30 00:17 - 00028672 _____ () C:\WINDOWS\SYSTEM32\efsext.dll 2016-03-18 22:56 - 2016-03-18 22:56 - 00092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2016-07-05 15:23 - 2016-07-05 15:23 - 01354040 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2015-12-25 20:53 - 2016-01-11 21:43 - 00291264 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamBase.dll 2014-12-12 23:20 - 2005-04-21 21:36 - 00143360 ____R () C:\WINDOWS\system32\BrSNMP64.dll 2015-11-04 17:11 - 2015-11-04 17:12 - 00188072 _____ () C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe 2015-10-30 00:18 - 2015-10-30 00:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll 2015-12-09 11:54 - 2015-12-16 07:54 - 00126256 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2016-07-12 10:52 - 2016-06-30 21:48 - 02656408 _____ () C:\WINDOWS\system32\CoreUIComponents.dll 2016-07-12 10:52 - 2016-06-30 21:48 - 02656408 _____ () C:\WINDOWS\System32\CoreUIComponents.dll 2016-05-14 11:17 - 2016-05-14 11:17 - 00959168 _____ () C:\Users\Rohit\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\ClientTelemetry.dll 2015-12-17 11:41 - 2015-12-06 21:14 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll 2016-07-12 10:53 - 2016-06-30 20:48 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll 2014-12-12 22:00 - 2014-02-21 12:21 - 00089600 _____ () C:\Windows\SYSTEM32\CmdRtr64.DLL 2014-12-12 22:00 - 2014-02-21 12:19 - 00366080 _____ () C:\Windows\SYSTEM32\APOMgr64.DLL 2014-09-19 17:15 - 2014-09-19 17:15 - 00330240 _____ () C:\Program Files\Qualcomm Atheros\Network Manager\NetworkManager.exe 2015-12-25 15:49 - 2016-07-05 16:04 - 00075776 _____ () C:\Program Files (x86)\Common Files\Freemake Shared\ProductUpdater\ProductUpdater.exe 2016-04-19 12:18 - 2016-04-19 12:19 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe 2016-07-12 10:52 - 2016-06-30 20:27 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2016-07-12 10:52 - 2016-06-30 20:21 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2016-07-12 10:52 - 2016-06-30 20:22 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll 2016-07-12 10:52 - 2016-06-30 20:24 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll 2014-12-12 23:20 - 2009-02-27 17:38 - 00139264 ____R () C:\Program Files (x86)\Brother\BrUtilities\BrLogAPI.dll 2014-09-03 12:03 - 2014-09-03 12:03 - 01241560 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll 2015-09-18 14:47 - 2016-01-11 21:43 - 00018880 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll 2016-07-25 11:07 - 2016-07-25 11:07 - 00098816 ____R () C:\Users\Rohit\AppData\Local\Temp\_MEI96482\win32api.pyd 2016-07-25 11:07 - 2016-07-25 11:07 - 00110080 ____R () C:\Users\Rohit\AppData\Local\Temp\_MEI96482\pywintypes27.dll 2016-07-25 11:07 - 2016-07-25 11:07 - 00364544 ____R () C:\Users\Rohit\AppData\Local\Temp\_MEI96482\pythoncom27.dll 2016-07-25 11:07 - 2016-07-25 11:07 - 00320512 ____R () C:\Users\Rohit\AppData\Local\Temp\_MEI96482\win32com.shell.shell.pyd 2016-07-25 11:07 - 2016-07-25 11:07 - 00776704 ____R () C:\Users\Rohit\AppData\Local\Temp\_MEI96482\_hashlib.pyd 2016-07-25 11:07 - 2016-07-25 11:07 - 01176576 ____R () C:\Users\Rohit\AppData\Local\Temp\_MEI96482\wx._core_.pyd 2016-07-25 11:07 - 2016-07-25 11:07 - 00806400 ____R () C:\Users\Rohit\AppData\Local\Temp\_MEI96482\wx._gdi_.pyd 2016-07-25 11:07 - 2016-07-25 11:07 - 00816128 ____R () C:\Users\Rohit\AppData\Local\Temp\_MEI96482\wx._windows_.pyd 2016-07-25 11:07 - 2016-07-25 11:07 - 01067008 ____R () C:\Users\Rohit\AppData\Local\Temp\_MEI96482\wx._controls_.pyd 2016-07-25 11:07 - 2016-07-25 11:07 - 00733184 ____R () C:\Users\Rohit\AppData\Local\Temp\_MEI96482\wx._misc_.pyd 2016-07-25 11:07 - 2016-07-25 11:07 - 00682496 ____R () C:\Users\Rohit\AppData\Local\Temp\_MEI96482\pysqlite2._sqlite.pyd 2016-07-25 11:07 - 2016-07-25 11:07 - 00088064 ____R () C:\Users\Rohit\AppData\Local\Temp\_MEI96482\_ctypes.pyd 2016-07-25 11:07 - 2016-07-25 11:07 - 00119808 ____R () C:\Users\Rohit\AppData\Local\Temp\_MEI96482\win32file.pyd 2016-07-25 11:07 - 2016-07-25 11:07 - 00108544 ____R () C:\Users\Rohit\AppData\Local\Temp\_MEI96482\win32security.pyd 2016-07-25 11:07 - 2016-07-25 11:07 - 00007168 ____R () C:\Users\Rohit\AppData\Local\Temp\_MEI96482\hashobjs_ext.pyd 2016-07-25 11:07 - 2016-07-25 11:07 - 00017920 ____R () C:\Users\Rohit\AppData\Local\Temp\_MEI96482\thumbnails_ext.pyd 2016-07-25 11:07 - 2016-07-25 11:07 - 00088064 ____R () C:\Users\Rohit\AppData\Local\Temp\_MEI96482\usb_ext.pyd 2016-07-25 11:07 - 2016-07-25 11:07 - 00012288 ____R () C:\Users\Rohit\AppData\Local\Temp\_MEI96482\common.time34.pyd 2016-07-25 11:07 - 2016-07-25 11:07 - 00018432 ____R () C:\Users\Rohit\AppData\Local\Temp\_MEI96482\win32event.pyd 2016-07-25 11:07 - 2016-07-25 11:07 - 00167936 ____R () C:\Users\Rohit\AppData\Local\Temp\_MEI96482\win32gui.pyd 2016-07-25 11:07 - 2016-07-25 11:07 - 00046080 ____R () C:\Users\Rohit\AppData\Local\Temp\_MEI96482\_socket.pyd 2016-07-25 11:07 - 2016-07-25 11:07 - 01208320 ____R () C:\Users\Rohit\AppData\Local\Temp\_MEI96482\_ssl.pyd 2016-07-25 11:07 - 2016-07-25 11:07 - 00128512 ____R () C:\Users\Rohit\AppData\Local\Temp\_MEI96482\_elementtree.pyd 2016-07-25 11:07 - 2016-07-25 11:07 - 00127488 ____R () C:\Users\Rohit\AppData\Local\Temp\_MEI96482\pyexpat.pyd 2016-07-25 11:07 - 2016-07-25 11:07 - 00038912 ____R () C:\Users\Rohit\AppData\Local\Temp\_MEI96482\win32inet.pyd 2016-07-25 11:07 - 2016-07-25 11:07 - 00036864 ____R () C:\Users\Rohit\AppData\Local\Temp\_MEI96482\_psutil_windows.pyd 2016-07-25 11:07 - 2016-07-25 11:07 - 00525208 ____R () C:\Users\Rohit\AppData\Local\Temp\_MEI96482\windows._lib_cacheinvalidation.pyd 2016-07-25 11:07 - 2016-07-25 11:07 - 00011264 ____R () C:\Users\Rohit\AppData\Local\Temp\_MEI96482\win32crypt.pyd 2016-07-25 11:07 - 2016-07-25 11:07 - 00077312 ____R () C:\Users\Rohit\AppData\Local\Temp\_MEI96482\wx._html2.pyd 2016-07-25 11:07 - 2016-07-25 11:07 - 00027136 ____R () C:\Users\Rohit\AppData\Local\Temp\_MEI96482\_multiprocessing.pyd 2016-07-25 11:07 - 2016-07-25 11:07 - 00020480 ____R () C:\Users\Rohit\AppData\Local\Temp\_MEI96482\_yappi.pyd 2016-07-25 11:07 - 2016-07-25 11:07 - 00035840 ____R () C:\Users\Rohit\AppData\Local\Temp\_MEI96482\win32process.pyd 2016-07-25 11:07 - 2016-07-25 11:07 - 00686080 ____R () C:\Users\Rohit\AppData\Local\Temp\_MEI96482\unicodedata.pyd 2016-07-25 11:07 - 2016-07-25 11:07 - 00078848 ____R () C:\Users\Rohit\AppData\Local\Temp\_MEI96482\wx._animate.pyd 2016-07-25 11:07 - 2016-07-25 11:07 - 00123392 ____R () C:\Users\Rohit\AppData\Local\Temp\_MEI96482\wx._wizard.pyd 2016-07-25 11:07 - 2016-07-25 11:07 - 00024064 ____R () C:\Users\Rohit\AppData\Local\Temp\_MEI96482\win32pipe.pyd 2016-07-25 11:07 - 2016-07-25 11:07 - 00010240 ____R () C:\Users\Rohit\AppData\Local\Temp\_MEI96482\select.pyd 2016-07-25 11:07 - 2016-07-25 11:07 - 00025600 ____R () C:\Users\Rohit\AppData\Local\Temp\_MEI96482\win32pdh.pyd 2016-07-25 11:07 - 2016-07-25 11:07 - 00017408 ____R () C:\Users\Rohit\AppData\Local\Temp\_MEI96482\win32profile.pyd 2016-07-25 11:07 - 2016-07-25 11:07 - 00022528 ____R () C:\Users\Rohit\AppData\Local\Temp\_MEI96482\win32ts.pyd 2016-05-14 11:17 - 2016-05-14 11:17 - 00679624 _____ () C:\Users\Rohit\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\ClientTelemetry.dll 2015-12-03 10:47 - 2015-11-06 12:59 - 00021600 _____ () C:\Program Files (x86)\Samsung\Samsung Magician\SAMSUNG_SSD.dll 2015-09-24 19:25 - 2016-04-25 19:20 - 00500736 _____ () C:\Program Files (x86)\GalaxyClient\PocoUtil.dll 2015-09-24 19:25 - 2015-09-24 19:28 - 45069312 _____ () C:\Program Files (x86)\GalaxyClient\libcef.dll 2015-09-24 19:25 - 2016-04-25 19:20 - 01847296 _____ () C:\Program Files (x86)\GalaxyClient\PocoData.dll 2015-09-24 19:25 - 2016-04-25 19:20 - 01069568 _____ () C:\Program Files (x86)\GalaxyClient\PocoNet.dll 2015-09-24 19:25 - 2016-04-25 19:20 - 00386048 _____ () C:\Program Files (x86)\GalaxyClient\PocoDataSQLite.dll 2015-09-24 19:25 - 2016-04-25 19:20 - 00513536 _____ () C:\Program Files (x86)\GalaxyClient\PocoXML.dll 2015-09-24 19:25 - 2016-04-25 19:20 - 01582080 _____ () C:\Program Files (x86)\GalaxyClient\PocoFoundation.dll 2015-09-24 19:25 - 2016-04-25 19:20 - 00300544 _____ () C:\Program Files (x86)\GalaxyClient\PocoNetSSL.dll 2015-09-24 19:25 - 2016-04-25 19:20 - 00323584 _____ () C:\Program Files (x86)\GalaxyClient\PocoJSON.dll 2015-09-24 19:25 - 2016-03-23 12:45 - 00096768 _____ () C:\Program Files (x86)\GalaxyClient\zlib.dll 2015-09-24 19:25 - 2016-04-25 19:20 - 00265216 _____ () C:\Program Files (x86)\GalaxyClient\PocoZip.dll 2015-09-24 19:25 - 2016-03-23 12:45 - 00672768 _____ () C:\Program Files (x86)\GalaxyClient\sqlite.dll 2015-09-24 19:25 - 2016-04-25 19:20 - 00418304 _____ () C:\Program Files (x86)\GalaxyClient\pcre.dll 2015-09-24 19:25 - 2016-04-25 19:19 - 00144896 _____ () C:\Program Files (x86)\GalaxyClient\expat.dll 2015-09-24 19:25 - 2016-04-25 19:20 - 00150528 _____ () C:\Program Files (x86)\GalaxyClient\PocoCrypto.dll 2016-06-01 14:39 - 2016-06-01 14:39 - 00439480 _____ () C:\Program Files (x86)\Evernote\Evernote\libxml2.dll 2016-06-01 14:39 - 2016-06-01 14:39 - 00321208 _____ () C:\Program Files (x86)\Evernote\Evernote\libtidy.dll 2015-09-24 19:25 - 2015-09-24 19:28 - 01643008 _____ () C:\Program Files (x86)\GalaxyClient\libglesv2.dll 2015-09-24 19:25 - 2015-09-24 19:28 - 00074752 _____ () C:\Program Files (x86)\GalaxyClient\libegl.dll 2016-06-22 19:34 - 2016-06-22 19:34 - 00143824 _____ () C:\ProgramData\Razer\Synapse\CrashReporter\CrashRpt1402.dll 2016-04-19 12:18 - 2016-04-19 12:19 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll 2016-04-19 12:18 - 2016-04-19 12:19 - 22284800 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkyWrap.dll 2015-09-18 20:11 - 2016-07-14 00:54 - 52042352 _____ () C:\Users\Rohit\AppData\Roaming\Spotify\libcef.dll 2015-09-18 20:11 - 2016-07-14 00:54 - 01741936 _____ () C:\Users\Rohit\AppData\Roaming\Spotify\libglesv2.dll 2015-09-18 20:11 - 2016-07-14 00:54 - 00087664 _____ () C:\Users\Rohit\AppData\Roaming\Spotify\libegl.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2013-08-22 06:25 - 2016-07-14 01:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-609271163-2674588117-1738407549-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Rohit\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\PhotosAppBackground\{cec1c472-710c-44f5-bd50-5f8f65487a2e}.jpg DNS Servers: 192.168.1.254 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [{E3A980F3-D702-44D9-96AE-77A65BBE87FF}] => (Allow) C:\Games\Steam\steamapps\common\Fallout 4\Fallout4Launcher.exe FirewallRules: [{69BA4B6A-2AD2-43C9-9B42-3B1A8335BC53}] => (Allow) C:\Games\Steam\steamapps\common\Fallout 4\Fallout4Launcher.exe FirewallRules: [{B117CECB-1D48-4E3A-B9A2-125EBD770F97}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{267CB515-3DC9-4377-907A-44EFAF20C32A}] => (Allow) E:\Games\Steam\bin\steamwebhelper.exe FirewallRules: [{0F25F181-A495-475F-B1D2-69951AF4535C}] => (Allow) E:\Games\Steam\bin\steamwebhelper.exe FirewallRules: [{3B68F889-7836-4531-9B48-DD1034FFDDCC}] => (Allow) E:\Games\Steam\steamapps\common\CastleCrashers\castle.exe FirewallRules: [{6B538C98-85F5-4781-A11E-34B2762E3EBB}] => (Allow) E:\Games\Steam\steamapps\common\CastleCrashers\castle.exe FirewallRules: [{DE7982D3-BCEC-4A5B-A71D-CC7A91E3418F}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{165B3DE5-E23F-4971-9419-346AA19F4E3D}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{7C4F7CD9-1FA0-4137-97F0-CFDBFC718615}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{A37F77B9-09F8-4A55-9CA3-55F7F46E39CA}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [TCP Query User{7A850D80-D5FD-4A1B-BC66-69334D365317}C:\users\rohit\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\rohit\appdata\roaming\spotify\spotify.exe FirewallRules: [UDP Query User{9225375B-E79E-42EA-AAFE-DA2BA6CEC0A7}C:\users\rohit\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\rohit\appdata\roaming\spotify\spotify.exe FirewallRules: [{8E9F2BB0-91ED-4A02-81CB-038B710C7752}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{C7C039F8-A830-4CB7-8B74-19173A22413F}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{99D4A044-241C-4754-90D5-F1711CE143B5}] => (Allow) E:\Games\Steam\Steam.exe FirewallRules: [{EBA584D2-A600-4A19-8756-227CB1539FAC}] => (Allow) E:\Games\Steam\Steam.exe FirewallRules: [{D809470A-321A-4EAB-84ED-2E1D1428E7F9}] => (Allow) C:\Program Files (x86)\Brother\Brmfl13b\FAXRX.EXE FirewallRules: [{1630E412-9D5D-4CDF-80F2-4EFD2C8D7400}] => (Allow) LPort=54925 FirewallRules: [{58DE607F-16EA-4A4F-A7C2-ED69F985A576}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{9BD6C495-126B-466A-8663-EB17DE445EA7}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{673CEFD3-F629-41B9-806B-970D891B9C78}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{5C6E2F55-09E5-4DCA-BA65-51F4AE700078}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{EC9EE78F-F29C-40C9-AED0-7496863DF83A}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe FirewallRules: [{D3BEAD14-4608-425B-85CC-4713A62EAFBE}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{42CECB5B-F044-47D4-9203-1298B635BB66}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{6D660180-8118-48C9-B5CB-F8EF33E053EA}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{1C3BB2C4-1744-41FC-A333-36BF48937A1B}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{0B593BA8-40D1-4993-B001-073AAC35230B}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{2BE28867-B549-44D9-B37F-7DD4466FFC40}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{C33D3595-8E79-4212-8FF6-18E8006933EA}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{98498321-FC9B-4D78-84E5-D6C33FB65C33}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{D12F21BA-FED7-4BDA-97DB-6D4419C068A6}] => (Allow) E:\Games\Steam\steamapps\common\Rust\Rust.exe FirewallRules: [{6F9F8DED-D3A8-453C-984F-9005AEFCCAEB}] => (Allow) E:\Games\Steam\steamapps\common\Rust\Rust.exe FirewallRules: [{9D8C231C-DE50-483F-8384-34656756F9EC}] => (Allow) E:\Games\Steam\steamapps\common\Bastion\Bastion.exe FirewallRules: [{B606BB59-7B5E-4BB3-A60D-F7479D5E1E61}] => (Allow) E:\Games\Steam\steamapps\common\Bastion\Bastion.exe FirewallRules: [TCP Query User{7AA9DA7D-ECD7-454D-9B4B-18A6ACAF0C64}C:\program files (x86)\kodi\kodi.exe] => (Allow) C:\program files (x86)\kodi\kodi.exe FirewallRules: [UDP Query User{89D7D05F-5507-4476-93DD-E4ED47BBF553}C:\program files (x86)\kodi\kodi.exe] => (Allow) C:\program files (x86)\kodi\kodi.exe FirewallRules: [{7B42A8F7-0D0A-49AA-ABB7-7D5605035CE0}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{4197C2E8-68FF-4774-A302-8D9F6F6A7E76}] => (Allow) C:\Users\Rohit\AppData\Local\Chromium\Application\chrome.exe FirewallRules: [{FF1666BA-09B5-4923-A336-4E5B8AD0BD22}] => (Allow) C:\Program Files\iTunes\iTunes.exe ==================== Restore Points ========================= 09-07-2016 11:15:55 Scheduled Checkpoint 13-07-2016 15:23:44 Windows Update 20-07-2016 11:11:00 Removed Microsoft Xbox 360 Accessories 1.2 ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (07/25/2016 01:59:39 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: RED) Description: Package Microsoft.Windows.Photos_16.526.11220.0_x64__8wekyb3d8bbwe+App was terminated because it took too long to suspend. Error: (07/25/2016 01:59:30 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: RED) Description: Package Microsoft.Windows.Photos_16.526.11220.0_x64__8wekyb3d8bbwe+App was terminated because it took too long to suspend. Error: (07/24/2016 07:00:00 PM) (Source: Windows Backup) (EventID: 4103) (User: ) Description: The backup did not complete because of an error writing to the backup location H:\. The error is: The backup location cannot be found or is not valid. Review your backup settings and check the backup location. (0x81000006). Error: (07/24/2016 12:40:13 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 28103984 Error: (07/24/2016 12:40:13 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 28103984 Error: (07/24/2016 12:40:13 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (07/24/2016 01:52:06 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 1062 Error: (07/24/2016 01:52:06 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 1062 Error: (07/24/2016 01:52:06 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (07/22/2016 03:23:56 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: RED) Description: Package Microsoft.Windows.Photos_16.526.11220.0_x64__8wekyb3d8bbwe+App was terminated because it took too long to suspend. System errors: ============= Error: (07/25/2016 11:25:11 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: application-specificLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)UnavailableUnavailable Error: (07/25/2016 03:09:38 AM) (Source: DCOM) (EventID: 10010) (User: RED) Description: {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} Error: (07/25/2016 03:09:38 AM) (Source: DCOM) (EventID: 10010) (User: RED) Description: {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} Error: (07/25/2016 03:09:38 AM) (Source: DCOM) (EventID: 10010) (User: RED) Description: {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} Error: (07/25/2016 03:09:38 AM) (Source: DCOM) (EventID: 10010) (User: RED) Description: {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} Error: (07/25/2016 03:09:33 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The Sync Host_c24256f service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service. Error: (07/25/2016 03:09:33 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: application-specificLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)UnavailableUnavailable Error: (07/24/2016 09:55:53 PM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY) Description: {F3B4E234-7A68-4E43-B813-E4BA55A065F6} Error: (07/24/2016 05:25:02 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: application-specificLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)UnavailableUnavailable Error: (07/24/2016 01:52:05 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: application-specificLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)UnavailableUnavailable CodeIntegrity: =================================== Date: 2016-07-23 03:17:31.647 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-07-23 03:17:31.590 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-07-23 03:17:31.529 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-07-23 03:17:30.822 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-07-23 03:17:30.765 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-07-23 03:17:30.683 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-07-23 03:17:30.626 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-07-23 03:17:30.541 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-07-23 03:17:30.483 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-07-23 03:17:30.398 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i5-4690K CPU @ 3.50GHz Percentage of memory in use: 49% Total physical RAM: 8141.02 MB Available physical RAM: 4139.6 MB Total Virtual: 9421.02 MB Available Virtual: 4372.31 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:231.93 GB) (Free:102.98 GB) NTFS Drive e: (Data) (Fixed) (Total:931.51 GB) (Free:210.05 GB) NTFS Drive f: (Backup) (Fixed) (Total:931.51 GB) (Free:637.63 GB) NTFS Drive g: (Audio) (Fixed) (Total:931.51 GB) (Free:923.59 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 232.9 GB) (Disk ID: 4757C905) Partition: GPT. ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 2EC2DE58) Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS) ======================================================== Disk: 2 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 2EC2DE5B) Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS) ======================================================== Disk: 3 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 415FAC83) Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS) ==================== End of Addition.txt ============================