Additional scan result of Farbar Recovery Scan Tool (x64) Version: 19-08-2016 Ran by [removed] (19-08-2016 20:07:03) Running from C:\Users\[removed]\Downloads Windows 10 Pro Version 1511 (X64) (2016-05-26 18:00:24) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-1845321876-2987096472-2773431298-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-1845321876-2987096472-2773431298-503 - Limited - Disabled) Guest (S-1-5-21-1845321876-2987096472-2773431298-501 - Limited - Disabled) SuperUser (S-1-5-21-1845321876-2987096472-2773431298-1000 - Administrator - Enabled) => C:\Users\SuperUser ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov) Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.017.20053 - Adobe Systems Incorporated) Adobe Flash Player 22 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 22.0.0.209 - Adobe Systems Incorporated) Apple Application Support (32-bit) (HKLM-x32\...\{26356515-5821-40FA-9C3D-9785052A1062}) (Version: 4.3.1 - Apple Inc.) Apple Application Support (64-bit) (HKLM\...\{C2651553-6CA3-4822-B2E6-BC4ACA6E0EA2}) (Version: 4.3.1 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{2E4AF2A6-50EA-4260-9BA4-5E582D11879A}) (Version: 9.3.0.15 - Apple Inc.) Apple Software Update (HKLM-x32\...\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.) Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.) Canon MF210 Series (HKLM\...\{14824AB4-17F5-4909-80AB-A7E24743A47C}) (Version: 4.5.0.0 - CANON INC.) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Google Chrome (HKLM-x32\...\Google Chrome) (Version: 52.0.2743.116 - Google Inc.) Google Drive (HKLM-x32\...\{709316AD-161C-4D5C-9AE7-0B3A822DA271}) (Version: 1.30.2170.0459 - Google, Inc.) Google Update Helper (x32 Version: 1.3.31.5 - Google Inc.) Hidden HP 3D DriveGuard (HKLM\...\{6C8684DD-B238-4806-9E93-BDD12CD11998}) (Version: 5.1.12.1 - Hewlett-Packard Company) HP ESU for Microsoft Windows 7 (HKLM-x32\...\{240B2BF7-E7E6-425C-A2A4-A3149189BF7F}) (Version: 2.3.1 - Hewlett-Packard Company) HP HD Webcam Driver (HKLM-x32\...\{399C37FB-08AF-493B-BFED-20FBD85EDF7F}) (Version: 6.0.1113.1_WHQL - Sonix) HP Hotkey Support (HKLM-x32\...\{7F7E2060-7212-4A53-9875-55173E4BA3F0}) (Version: 5.0.21.1 - Hewlett-Packard Company) IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6435.0 - IDT) Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1010 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.30.1349 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.1.0.1006 - Intel Corporation) Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.6.245 - Intel Corporation) IObit Uninstaller (HKLM-x32\...\IObitUninstall) (Version: 5.2.6.101 - IObit) iTunes (HKLM\...\{9F4BF859-C3A4-4AB6-BDD1-9C5D58188598}) (Version: 12.4.1.6 - Apple Inc.) JMicron Flash Media Controller Driver (HKLM-x32\...\{26604C7E-A313-4D12-867F-7C6E7820BE4C}) (Version: 1.0.76.1 - JMicron Technology Corp.) K-Lite Codec Pack 12.0.1 Standard (HKLM-x32\...\KLiteCodecPack_is1) (Version: 12.0.1 - KLCP) Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes) Microsoft Office 365 ProPlus - en-us (HKLM\...\O365ProPlusRetail - en-us) (Version: 16.0.6001.1078 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\...\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) MiniTool Partition Wizard Free 9.0 (HKLM-x32\...\{05D996FA-ADCB-4D23-BA3C-A7C184A8FAC6}_is1) (Version: - MiniTool Solution Ltd.) Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Mozilla Firefox 45.0.2 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 45.0.2 (x86 en-US)) (Version: 45.0.2 - Mozilla) Office 16 Click-to-Run Extensibility Component (x32 Version: 16.0.6001.1078 - Microsoft Corporation) Hidden Office 16 Click-to-Run Licensing Component (Version: 16.0.6001.1078 - Microsoft Corporation) Hidden Office 16 Click-to-Run Localization Component (x32 Version: 16.0.6001.1078 - Microsoft Corporation) Hidden Rainmeter (HKLM-x32\...\Rainmeter) (Version: 3.2.1 r2386 - ) Ralink RT5390R 802.11b/g/n Wi-Fi Adapter (HKLM-x32\...\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}) (Version: 5.0.15.0 - Mediatek) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.73.618.2013 - Realtek) SDK (x32 Version: 2.30.042 - Portrait Displays, Inc.) Hidden Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 19.0.12.0 - Synaptics Incorporated) US-122 MKII / US-144 MKII (HKLM\...\USB_AUDIO_DEusb-audio.deTascam) (Version: - ) VLC media player (HKLM\...\VLC media player) (Version: 2.2.1 - VideoLAN) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-1845321876-2987096472-2773431298-1000_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\SuperUser\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\FileCoAuth.exe (Microsoft Corporation) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {02706D19-6E15-4030-BFE2-200F1E52E48A} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe Task: {039E23FD-CEF8-4236-94D9-C58C732EB6F2} - \Microsoft\Windows\Setup\GWXTriggers\OnIdle-5d -> No File <==== ATTENTION Task: {04B68BF3-2D06-4606-B561-C11300A786C3} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION Task: {0B2DEF41-4086-4BAF-9D35-D32B3916B100} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION Task: {0E584E39-C5E2-438F-A197-7D764D7607D5} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\Windows\ehome\ehrec.exe Task: {1593D728-0AE0-460F-8214-B43863642EBF} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\Windows\ehome\ehPrivJob.exe Task: {16308C9D-8646-4B23-B39A-729C35285210} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.) Task: {1D2C0DBE-23F6-4760-B1B0-3AC451B98A09} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\Windows\ehome\ehPrivJob.exe Task: {1FC582B9-5AA8-43A9-8D63-06D08026FE40} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION Task: {23576F8C-5967-41E6-9602-879827BF15BE} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => c:\Program Files\Microsoft Security Client\MpCmdRun.exe Task: {246E71BC-B636-4737-8B2C-3C29E6906C3A} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\Windows\ehome\mcupdate.exe Task: {262C4004-3439-45B0-A29C-EB045AB68D32} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\Windows\ehome\MCUpdate.exe Task: {2B6577D6-5D3D-46E8-ABB9-89A637265268} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION Task: {2D48A47D-34F9-42F5-B0FC-1A3CA61E6301} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime -> No File <==== ATTENTION Task: {2DE42368-C364-472E-94E8-6726ED2352E5} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-05-11] (Google Inc.) Task: {32AA6BD4-72C3-460D-824D-96E0ADD09465} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\Windows\ehome\ehPrivJob.exe Task: {367255F1-8484-4E13-B023-232C45BE29A3} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION Task: {3E47DBE8-9A16-42A6-8239-E9C02C414AE6} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\Windows\ehome\mcupdate.exe Task: {402FBAF6-C28D-4A29-BBA0-EC7B92033ED2} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION Task: {452A39C5-90A1-420C-B86A-F9FFC12EE851} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\Windows\ehome\mcupdate.exe Task: {4ABF3CE7-4F34-40DB-A48E-E579E7BD0C37} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-05-11] (Google Inc.) Task: {5519B341-E85E-4EB9-B550-EE7CD07571CC} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2016-05-26] (Microsoft Corporation) Task: {624DAA67-A0C7-47EE-9026-4387022DC9CB} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION Task: {6878C04A-459B-4DAB-AADF-76D7C8F61621} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\Windows\ehome\ehPrivJob.exe Task: {68965DAC-B181-4598-930A-013828F61276} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION Task: {69378C67-680F-4778-BD98-C6141FB9B6C7} - System32\Tasks\{17A6CFF7-9406-468C-A750-F2578A475B8E} => pcalua.exe -a C:\Users\SuperUser\Downloads\sp63852.exe -d C:\Users\SuperUser\Downloads Task: {6B6BAFFA-9CEF-45F6-BD60-6FB778B7A95B} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2016-05-01] (Microsoft Corporation) Task: {6B85AC1B-052A-4701-ABBD-D5D9C4C73A5D} - System32\Tasks\Uninstaller_SkipUac_SuperUser => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [2016-03-04] (IObit) Task: {7EC03D21-D094-44D7-B533-7FF82D365D5C} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION Task: {82E6DCFB-0984-4C3D-9C6A-0262A4825DD8} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\Windows\ehome\ehPrivJob.exe Task: {87AFAFA1-9A86-4FB8-8EF5-71938A083CA2} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2016-05-26] (Microsoft Corporation) Task: {882CB9B7-3E0B-4955-AA18-E6CEB274B3C5} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\Windows\ehome\ehPrivJob.exe Task: {8CAA93B7-5699-45FA-ABF7-046F50A9C17A} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\Windows\ehome\ehPrivJob.exe Task: {8E13B3A6-F76F-46B5-A078-CA3B00861CFC} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-08-19] (Adobe Systems Incorporated) Task: {91531219-5CDA-41ED-937F-EA465D352F78} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\Windows\ehome\ehPrivJob.exe Task: {9666FA49-8FE8-46BE-A94A-F2C014E51BE4} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\Windows\ehome\ehPrivJob.exe Task: {A78EE33D-87B9-4F20-B125-52E4C009C165} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2016-05-01] (Microsoft Corporation) Task: {B1BECA0A-4C66-4BB3-91F5-70F113897D43} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2016-05-26] (Microsoft Corporation) Task: {BA22EFD6-C4A2-4C96-A96A-55AB36D918DA} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-06-25] (Adobe Systems Incorporated) Task: {BFDD80DA-C85F-4B37-BB38-BD10E6ACF084} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\Windows\ehome\mcupdate.exe Task: {C2DFEE57-F1E2-448A-9E0D-FD7D954ECDF2} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\Windows\ehome\ehPrivJob.exe Task: {C5BCD342-67CA-4A51-B792-895368F9BA77} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\Windows\ehome\ehPrivJob.exe Task: {D86158AF-758B-4E0B-9319-84E68F25FFA5} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION Task: {DA01553A-280A-4B52-9B9F-D40547E68EF5} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\Windows\ehome\mcupdate.exe Task: {E3DAAFAB-B96F-43F2-9916-108518FC73A0} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\Windows\ehome\mcupdate.exe Task: {EC267C8A-988F-47C6-BC93-EFCA1B405EE2} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime -> No File <==== ATTENTION Task: {F3FFAEE3-F9C9-437A-B2AA-203A583E9A8C} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\Windows\ehome\ehPrivJob.exe Task: {F4EEC74E-CEE1-4EFA-A91D-F0BE74236076} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\Windows\ehome\ehPrivJob.exe (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\Uninstaller_SkipUac_SuperUser.job => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) ShortcutWithArgument: C:\Users\SuperUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Keep - notes and lists.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory="Profile 2" --app-id=hmjkmjkepdijhoojdojkdfohbdgmmhki ShortcutWithArgument: C:\Users\SuperUser\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Keep - notes and lists.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory="Profile 2" --app-id=hmjkmjkepdijhoojdojkdfohbdgmmhki ShortcutWithArgument: C:\Users\SuperUser\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\9501e18d7c2ab92e\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory="Profile 2" ==================== Loaded Modules (Whitelisted) ============== 2016-05-26 15:23 - 2016-05-01 05:52 - 00171712 _____ () C:\Program Files\Common Files\Microsoft Shared\ClickToRun\ApiClient.dll 2016-03-18 23:56 - 2016-03-18 23:56 - 00092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2016-04-22 02:07 - 2016-04-22 02:07 - 01337144 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2015-10-30 03:18 - 2015-10-30 03:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll 2016-05-26 15:56 - 2016-05-26 15:56 - 02656952 _____ () C:\WINDOWS\system32\CoreUIComponents.dll 2016-05-26 15:56 - 2016-05-26 15:56 - 02656952 _____ () C:\Windows\System32\CoreUIComponents.dll 2016-05-31 22:39 - 2016-05-18 00:46 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2016-05-26 15:56 - 2016-05-26 15:56 - 02656952 _____ () C:\WINDOWS\System32\CoreUIComponents.dll 2016-05-26 14:06 - 2016-05-26 14:06 - 00959168 _____ () C:\Users\SuperUser\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\ClientTelemetry.dll 2016-05-26 15:42 - 2016-05-26 15:42 - 08911040 _____ () C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\1033\GrooveIntlResource.dll 2016-02-13 08:54 - 2016-02-13 08:54 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll 2016-05-31 22:38 - 2016-05-18 01:13 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll 2016-05-31 22:39 - 2016-05-18 00:53 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2016-05-31 22:39 - 2016-05-18 00:47 - 00936960 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll 2016-05-31 22:39 - 2016-05-18 00:47 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll 2016-05-31 22:39 - 2016-05-18 00:49 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll 2016-05-31 22:38 - 2016-05-18 00:46 - 00529408 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.NodeWinrtWrap.dll 2015-10-30 03:18 - 2016-02-13 09:03 - 00037888 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\dss_service\node_modules\winrt-projections\bin\Winrt_Projections.node 2015-10-30 03:18 - 2016-02-13 09:03 - 00796160 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\dss_service\node_modules\windows.web.http\bin\NodeRT_Windows_Web_Http.node 2015-10-30 03:18 - 2016-02-13 09:03 - 00961024 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\dss_service\node_modules\windows.web.http.headers\bin\NodeRT_Windows_Web_Http_Headers.node 2015-10-30 03:18 - 2016-02-13 09:03 - 00206336 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\dss_service\node_modules\windows.web.http.filters\bin\NodeRT_Windows_Web_Http_Filters.node 2015-10-30 03:18 - 2016-02-13 09:03 - 00558592 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\dss_service\node_modules\windows.storage.streams\bin\NodeRT_Windows_Storage_Streams.node 2015-10-30 03:18 - 2016-02-13 09:03 - 00397824 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\dss_service\node_modules\windows.foundation\bin\NodeRT_Windows_Foundation.node 2015-10-30 03:18 - 2016-02-13 09:03 - 00181248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\dss_service\node_modules\nodert-buffer-utils\bin\NodeRT_Buffer_Utils.node 2015-10-30 03:18 - 2016-02-13 09:03 - 00093696 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\dss_service\node_modules\windows.security.cryptography\bin\NodeRT_Windows_Security_Cryptography.node 2015-10-30 03:18 - 2016-02-13 09:03 - 00200192 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\dss_service\node_modules\windows.cortana.pal\bin\NodeRT_Windows_Cortana_PAL.node 2015-06-01 22:00 - 2015-06-01 22:00 - 00102912 _____ () C:\Windows\System32\IccLibDll_x64.dll 2015-03-24 09:28 - 2015-03-24 09:28 - 00036544 _____ () C:\Program Files\Rainmeter\Rainmeter.exe 2015-03-24 09:28 - 2015-03-24 09:28 - 00775872 _____ () C:\Program Files\Rainmeter\Rainmeter.dll 2015-03-24 09:27 - 2015-03-24 09:27 - 00058368 _____ () C:\Program Files\Rainmeter\Plugins\WebParser.DLL 2016-05-26 15:02 - 2016-05-26 15:03 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe 2016-08-19 17:40 - 2016-08-19 17:41 - 03790336 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1605.1582.0_x64__8wekyb3d8bbwe\Calculator.exe 2016-05-26 14:56 - 2016-05-26 14:57 - 00258560 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1605.1582.0_x64__8wekyb3d8bbwe\StoreRatingPromotion.dll 2016-08-19 17:39 - 2016-08-19 17:39 - 00016896 _____ () C:\Program Files\WindowsApps\Microsoft.XboxApp_19.19.28029.0_x64__8wekyb3d8bbwe\XboxApp.exe 2016-08-19 17:39 - 2016-08-19 17:39 - 30082560 _____ () C:\Program Files\WindowsApps\Microsoft.XboxApp_19.19.28029.0_x64__8wekyb3d8bbwe\XboxApp.dll 2016-08-19 17:39 - 2016-08-19 17:39 - 01651112 _____ () C:\Program Files\WindowsApps\Microsoft.XboxApp_19.19.28029.0_x64__8wekyb3d8bbwe\winsdkfb.dll 2016-08-19 17:44 - 2016-08-19 17:45 - 00017408 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.722.10060.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe 2016-08-19 17:44 - 2016-08-19 17:45 - 13475840 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.722.10060.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll 2016-05-27 13:26 - 2016-05-27 13:26 - 00680448 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.722.10060.0_x64__8wekyb3d8bbwe\Microsoft.DesignCore.dll 2016-05-26 14:57 - 2016-05-26 14:57 - 00291328 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.722.10060.0_x64__8wekyb3d8bbwe\StoreRatingPromotion.dll 2015-05-12 05:01 - 2015-05-12 05:00 - 00622880 _____ () C:\Program Files (x86)\IObit\LiveUpdate\ProductStatistics.dll 2016-05-27 14:12 - 2016-05-27 14:12 - 00172032 _____ () C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\IsdiInterop\849cd5a86641daede17cca3b54131fd2\IsdiInterop.ni.dll 2016-03-19 15:30 - 2012-02-01 18:25 - 00059904 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll 2015-05-12 20:47 - 2013-01-15 00:25 - 01200088 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll 2016-05-26 14:06 - 2016-05-26 14:06 - 00679624 _____ () C:\Users\SuperUser\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\ClientTelemetry.dll 2016-08-19 17:23 - 2016-08-19 17:23 - 00098816 ____R () C:\Users\SuperUser\AppData\Local\Temp\_MEI29362\win32api.pyd 2016-08-19 17:23 - 2016-08-19 17:23 - 00110080 ____R () C:\Users\SuperUser\AppData\Local\Temp\_MEI29362\pywintypes27.dll 2016-08-19 17:23 - 2016-08-19 17:23 - 00364544 ____R () C:\Users\SuperUser\AppData\Local\Temp\_MEI29362\pythoncom27.dll 2016-08-19 17:23 - 2016-08-19 17:23 - 00320512 ____R () C:\Users\SuperUser\AppData\Local\Temp\_MEI29362\win32com.shell.shell.pyd 2016-08-19 17:23 - 2016-08-19 17:23 - 00776704 ____R () C:\Users\SuperUser\AppData\Local\Temp\_MEI29362\_hashlib.pyd 2016-08-19 17:23 - 2016-08-19 17:23 - 01176576 ____R () C:\Users\SuperUser\AppData\Local\Temp\_MEI29362\wx._core_.pyd 2016-08-19 17:23 - 2016-08-19 17:23 - 00806400 ____R () C:\Users\SuperUser\AppData\Local\Temp\_MEI29362\wx._gdi_.pyd 2016-08-19 17:23 - 2016-08-19 17:23 - 00816128 ____R () C:\Users\SuperUser\AppData\Local\Temp\_MEI29362\wx._windows_.pyd 2016-08-19 17:23 - 2016-08-19 17:23 - 01067008 ____R () C:\Users\SuperUser\AppData\Local\Temp\_MEI29362\wx._controls_.pyd 2016-08-19 17:23 - 2016-08-19 17:23 - 00733184 ____R () C:\Users\SuperUser\AppData\Local\Temp\_MEI29362\wx._misc_.pyd 2016-08-19 17:23 - 2016-08-19 17:23 - 00682496 ____R () C:\Users\SuperUser\AppData\Local\Temp\_MEI29362\pysqlite2._sqlite.pyd 2016-08-19 17:23 - 2016-08-19 17:23 - 00088064 ____R () C:\Users\SuperUser\AppData\Local\Temp\_MEI29362\_ctypes.pyd 2016-08-19 17:23 - 2016-08-19 17:23 - 00119808 ____R () C:\Users\SuperUser\AppData\Local\Temp\_MEI29362\win32file.pyd 2016-08-19 17:23 - 2016-08-19 17:23 - 00108544 ____R () C:\Users\SuperUser\AppData\Local\Temp\_MEI29362\win32security.pyd 2016-08-19 17:23 - 2016-08-19 17:23 - 00007168 ____R () C:\Users\SuperUser\AppData\Local\Temp\_MEI29362\hashobjs_ext.pyd 2016-08-19 17:23 - 2016-08-19 17:23 - 00017920 ____R () C:\Users\SuperUser\AppData\Local\Temp\_MEI29362\thumbnails_ext.pyd 2016-08-19 17:23 - 2016-08-19 17:23 - 00088064 ____R () C:\Users\SuperUser\AppData\Local\Temp\_MEI29362\usb_ext.pyd 2016-08-19 17:23 - 2016-08-19 17:23 - 00012288 ____R () C:\Users\SuperUser\AppData\Local\Temp\_MEI29362\common.time34.pyd 2016-08-19 17:23 - 2016-08-19 17:23 - 00018432 ____R () C:\Users\SuperUser\AppData\Local\Temp\_MEI29362\win32event.pyd 2016-08-19 17:23 - 2016-08-19 17:23 - 00167936 ____R () C:\Users\SuperUser\AppData\Local\Temp\_MEI29362\win32gui.pyd 2016-08-19 17:23 - 2016-08-19 17:23 - 00046080 ____R () C:\Users\SuperUser\AppData\Local\Temp\_MEI29362\_socket.pyd 2016-08-19 17:23 - 2016-08-19 17:23 - 01208320 ____R () C:\Users\SuperUser\AppData\Local\Temp\_MEI29362\_ssl.pyd 2016-08-19 17:23 - 2016-08-19 17:23 - 00128512 ____R () C:\Users\SuperUser\AppData\Local\Temp\_MEI29362\_elementtree.pyd 2016-08-19 17:23 - 2016-08-19 17:23 - 00127488 ____R () C:\Users\SuperUser\AppData\Local\Temp\_MEI29362\pyexpat.pyd 2016-08-19 17:23 - 2016-08-19 17:23 - 00038912 ____R () C:\Users\SuperUser\AppData\Local\Temp\_MEI29362\win32inet.pyd 2016-08-19 17:23 - 2016-08-19 17:23 - 00036864 ____R () C:\Users\SuperUser\AppData\Local\Temp\_MEI29362\_psutil_windows.pyd 2016-08-19 17:23 - 2016-08-19 17:23 - 00525208 ____R () C:\Users\SuperUser\AppData\Local\Temp\_MEI29362\windows._lib_cacheinvalidation.pyd 2016-08-19 17:23 - 2016-08-19 17:23 - 00011264 ____R () C:\Users\SuperUser\AppData\Local\Temp\_MEI29362\win32crypt.pyd 2016-08-19 17:23 - 2016-08-19 17:23 - 00077312 ____R () C:\Users\SuperUser\AppData\Local\Temp\_MEI29362\wx._html2.pyd 2016-08-19 17:23 - 2016-08-19 17:23 - 00027136 ____R () C:\Users\SuperUser\AppData\Local\Temp\_MEI29362\_multiprocessing.pyd 2016-08-19 17:23 - 2016-08-19 17:23 - 00020480 ____R () C:\Users\SuperUser\AppData\Local\Temp\_MEI29362\_yappi.pyd 2016-08-19 17:23 - 2016-08-19 17:23 - 00035840 ____R () C:\Users\SuperUser\AppData\Local\Temp\_MEI29362\win32process.pyd 2016-08-19 17:23 - 2016-08-19 17:23 - 00686080 ____R () C:\Users\SuperUser\AppData\Local\Temp\_MEI29362\unicodedata.pyd 2016-08-19 17:23 - 2016-08-19 17:23 - 00078848 ____R () C:\Users\SuperUser\AppData\Local\Temp\_MEI29362\wx._animate.pyd 2016-08-19 17:23 - 2016-08-19 17:23 - 00123392 ____R () C:\Users\SuperUser\AppData\Local\Temp\_MEI29362\wx._wizard.pyd 2016-08-19 17:23 - 2016-08-19 17:23 - 00024064 ____R () C:\Users\SuperUser\AppData\Local\Temp\_MEI29362\win32pipe.pyd 2016-08-19 17:23 - 2016-08-19 17:23 - 00010240 ____R () C:\Users\SuperUser\AppData\Local\Temp\_MEI29362\select.pyd 2016-08-19 17:23 - 2016-08-19 17:23 - 00025600 ____R () C:\Users\SuperUser\AppData\Local\Temp\_MEI29362\win32pdh.pyd 2016-08-19 17:23 - 2016-08-19 17:23 - 00017408 ____R () C:\Users\SuperUser\AppData\Local\Temp\_MEI29362\win32profile.pyd 2016-08-19 17:23 - 2016-08-19 17:23 - 00022528 ____R () C:\Users\SuperUser\AppData\Local\Temp\_MEI29362\win32ts.pyd 2016-04-07 02:11 - 2015-12-23 19:32 - 00190240 _____ () C:\Program Files (x86)\IObit\IObit Uninstaller\madBasic_.bpl 2016-04-07 02:11 - 2015-12-23 19:32 - 00057632 _____ () C:\Program Files (x86)\IObit\IObit Uninstaller\madDisAsm_.bpl 2016-08-19 17:37 - 2016-08-02 20:24 - 01771336 _____ () C:\Program Files (x86)\Google\Chrome\Application\52.0.2743.116\libglesv2.dll 2016-08-19 17:37 - 2016-08-02 20:23 - 00094024 _____ () C:\Program Files (x86)\Google\Chrome\Application\52.0.2743.116\libegl.dll 2016-05-26 15:02 - 2016-05-26 15:03 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll 2016-05-26 15:02 - 2016-05-26 15:03 - 22284800 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkyWrap.dll 2016-08-19 17:30 - 2016-08-19 17:30 - 00964096 _____ () C:\Program Files\WindowsApps\Microsoft.BingNews_4.11.156.0_x86__8wekyb3d8bbwe\SQLite3Wrapper.dll 2016-02-13 09:07 - 2016-02-13 09:07 - 00645120 _____ () C:\Program Files\WindowsApps\Microsoft.BingNews_4.11.156.0_x86__8wekyb3d8bbwe\Microsoft.Aria.ClientTelemetry.dll 2016-08-19 17:30 - 2016-08-19 17:30 - 03311000 _____ () C:\Program Files\WindowsApps\Microsoft.BingNews_4.11.156.0_x86__8wekyb3d8bbwe\Microsoft.Advertising.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) IE trusted site: HKU\S-1-5-21-1845321876-2987096472-2773431298-1000\...\sharepoint.com -> hxxps://ucollege-files.sharepoint.com ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-13 22:34 - 2016-05-26 14:53 - 00000830 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-1845321876-2987096472-2773431298-1000\Control Panel\Desktop\\Wallpaper -> c:\windows\web\wallpaper\windows\img0.jpg DNS Servers: [removed] - [removed] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [MSMQ-In-TCP] => (Allow) %systemroot%\system32\mqsvc.exe FirewallRules: [MSMQ-Out-TCP] => (Allow) %systemroot%\system32\mqsvc.exe FirewallRules: [MSMQ-In-UDP] => (Allow) %systemroot%\system32\mqsvc.exe FirewallRules: [MSMQ-Out-UDP] => (Allow) %systemroot%\system32\mqsvc.exe FirewallRules: [WCF-NetTcpActivator-In-TCP-64bit] => (Allow) LPort=808 FirewallRules: [{68AFED70-D5D2-4834-A121-9D05AE06D6CE}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{97AC380A-5A84-4411-B94C-4D18355728EC}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{3AC2A6D7-961F-4E08-BB65-A8952317CEAC}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{1393213E-04A1-430C-B887-C00B405110BC}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{E8F00A80-DBD3-4579-B1C8-DD2E65863E99}] => (Allow) LPort=1900 FirewallRules: [{2FCDF07D-6257-49F0-93DC-E2604E074E71}] => (Allow) LPort=2869 FirewallRules: [{4A066D76-626F-4EE6-863B-6BD5B894CEA7}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe FirewallRules: [{47315C81-2C4D-4E89-A9E4-3AABE4FD86DD}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{B06911C7-6D80-49F5-93DA-DC31ED2A3967}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{45E28EF6-657E-4101-B996-670D8EDE5DD9}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe FirewallRules: [{24ECD9BB-FB3F-414B-89DD-31E206E58B66}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe FirewallRules: [{A3FC6399-1F12-4212-94ED-59571754222D}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe FirewallRules: [{50F15D06-4A55-4CA6-AB56-CB7D7C5687FD}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe FirewallRules: [{04825D0C-0A60-46C0-A08D-39EB945A6D57}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe FirewallRules: [TCP Query User{6445FF5B-01D4-41B5-B056-0B29EBD8B963}C:\users\superuser\downloads\ethereum-wallet-win64-0-7-4\ethereum-wallet-win64-0-7-4\resources\node\geth\geth.exe] => (Allow) C:\users\superuser\downloads\ethereum-wallet-win64-0-7-4\ethereum-wallet-win64-0-7-4\resources\node\geth\geth.exe FirewallRules: [UDP Query User{7D9B83D8-51C3-4D13-ABF5-A58F7A11E1C8}C:\users\superuser\downloads\ethereum-wallet-win64-0-7-4\ethereum-wallet-win64-0-7-4\resources\node\geth\geth.exe] => (Allow) C:\users\superuser\downloads\ethereum-wallet-win64-0-7-4\ethereum-wallet-win64-0-7-4\resources\node\geth\geth.exe FirewallRules: [{28E9F49B-3511-46F0-B852-57C30E25111C}] => (Allow) C:\Program Files\iTunes\iTunes.exe FirewallRules: [{B8E3E8B4-6377-4ECC-BB16-3B1934FFDA77}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Restore Points ========================= ATTENTION: System Restore is disabled ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (08/19/2016 05:49:17 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: SUPERUSER-PC) Description: Activation of app Microsoft.WindowsMaps_8wekyb3d8bbwe!App failed with error: -2144927148 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (08/19/2016 05:49:17 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: SUPERUSER-PC) Description: Activation of app Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI failed with error: -2144927141 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (08/19/2016 05:49:17 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: SUPERUSER-PC) Description: Activation of app Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI failed with error: -2147023170 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (08/19/2016 05:33:12 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: SUPERUSER-PC) Description: Activation of app Microsoft.Messaging_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 failed with error: -2147009280 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (08/19/2016 05:32:22 PM) (Source: Office 2016 Licensing Service) (EventID: 0) (User: ) Description: Subscription licensing service failed: -1073418220 Error: (08/19/2016 05:25:39 PM) (Source: Windows Backup) (EventID: 4103) (User: ) Description: The backup did not complete because of an error writing to the backup location Z:\. The error is: The backup location cannot be found or is not valid. Review your backup settings and check the backup location. (0x81000006). Error: (06/06/2016 02:12:40 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 3096328 Error: (06/06/2016 02:12:40 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 3096328 Error: (06/06/2016 02:12:40 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (06/05/2016 10:02:39 PM) (Source: Office 2016 Licensing Service) (EventID: 0) (User: ) Description: Subscription licensing service failed: -1073418220 System errors: ============= Error: (08/19/2016 05:43:13 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY) Description: Installation Failure: Windows failed to install the following update with error 0x80070643: Definition Update for Windows Defender - KB2267602 (Definition 1.227.206.0). Error: (08/19/2016 05:33:12 PM) (Source: DCOM) (EventID: 10001) (User: SUPERUSER-PC) Description: "C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe" -ServerName:SkypeHost.ServerServer15616App.AppXck5aaxyarfx8gxrgfk6pvakmmxeqvepc.mcaUnavailableUnavailable Error: (06/06/2016 04:49:37 PM) (Source: DCOM) (EventID: 10010) (User: SUPERUSER-PC) Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF} Error: (06/06/2016 04:49:35 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: A timeout was reached (30000 milliseconds) while waiting for the Sync Host_38e828 service to connect. Error: (06/06/2016 04:49:35 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: A timeout was reached (30000 milliseconds) while waiting for the User Data Storage_38e828 service to connect. Error: (06/06/2016 04:49:35 PM) (Source: Service Control Manager) (EventID: 7032) (User: ) Description: The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the User Data Storage_38e828 service, but this action failed with the following error: %%1056 = An instance of the service is already running. Error: (06/06/2016 04:49:29 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: A timeout was reached (30000 milliseconds) while waiting for the User Data Storage_38e828 service to connect. Error: (06/06/2016 04:49:25 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The User Data Access_38e828 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service. Error: (06/06/2016 04:49:25 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The User Data Storage_38e828 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service. Error: (06/06/2016 04:49:25 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The Contact Data_38e828 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service. CodeIntegrity: =================================== Date: 2016-08-19 20:06:37.166 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-08-19 20:06:37.147 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-08-19 20:06:36.509 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-08-19 20:06:36.489 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-08-19 20:06:36.442 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-08-19 17:53:32.562 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-08-19 17:53:32.548 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-08-19 17:53:31.696 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-08-19 17:53:31.682 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-08-19 17:53:31.640 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. ==================== Memory info =========================== Processor: Intel(R) Celeron(R) CPU B840 @ 1.90GHz Percentage of memory in use: 55% Total physical RAM: 8075.51 MB Available physical RAM: 3563.13 MB Total Virtual: 16267.51 MB Available Virtual: 10353.63 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:247.9 GB) (Free:198.89 GB) NTFS ==>[drive with boot components (obtained from BCD)] Drive z: () (Fixed) (Total:45.35 GB) (Free:45.25 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: 5BC53D8B) Partition 1: (Not Active) - (Size=47.4 GB) - (Type=OF Extended) Partition 2: (Not Active) - (Size=2 GB) - (Type=1B) Partition 3: (Active) - (Size=247.9 GB) - (Type=07 NTFS) ==================== End of Addition.txt ============================