Additional scan result of Farbar Recovery Scan Tool (x64) Version: 12-11-2016 Ran by [removed] (17-11-2016 04:43:59) Running from C:\Users\[removed]\Downloads Windows 10 Home Version 1607 (X64) (2016-09-26 17:57:40) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-3634378098-2526221181-1815557863-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-3634378098-2526221181-1815557863-503 - Limited - Disabled) Guest (S-1-5-21-3634378098-2526221181-1815557863-501 - Limited - Disabled) JOHN (S-1-5-21-3634378098-2526221181-1815557863-1001 - Administrator - Enabled) => C:\Users\JOHN SophosSAUASUS0 (S-1-5-21-3634378098-2526221181-1815557863-1002 - Limited - Enabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: Sophos Anti-Virus (Enabled - Up to date) {6BABF8F7-3EB6-BD1D-9167-8C5ECA060A29} AS: Sophos Anti-Virus (Enabled - Up to date) {D0CA1913-188C-B293-ABD7-B72CB1814094} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Flash Player 23 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 23.0.0.207 - Adobe Systems Incorporated) Apple Application Support (64-bit) (HKLM\...\{5905C8CF-1C88-4478-A48E-4E458AD1BC7E}) (Version: 5.0.1 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{D4D86CB2-2370-4691-8272-3869EDED6C64}) (Version: 10.0.0.18 - Apple Inc.) Apple Software Update (HKLM-x32\...\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.) ASUS GIFTBOX Desktop (HKLM-x32\...\{4701E5AB-AF91-4D40-8F18-358CC80E4E5B}) (Version: 1.1.2 - ASUS) ASUS Live Update (HKLM-x32\...\{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}) (Version: 3.2.9 - ASUS) ASUS Smart Gesture (HKLM-x32\...\{4D3286A6-F6AB-498A-82A4-E4F040529F3D}) (Version: 3.0.10 - ASUS) ASUS Splendid Video Enhancement Technology (HKLM-x32\...\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 3.03.0006 - ASUS) ASUS USB Charger Plus (HKLM-x32\...\{A859E3E5-C62F-4BFA-AF1D-2B95E03166AF}) (Version: 4.0.2 - ASUS) ATK Package (HKLM-x32\...\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0037 - ASUS) AudioWizard (HKLM-x32\...\{57E770A2-2BAF-4CAA-BAA3-BD896E2254D3}) (Version: 1.0.0.31 - ICEpower a/s) Blackboard Collaborate Launcher (HKLM-x32\...\{11BC8796-4F0D-4561-94EA-1571E28E9C2D}) (Version: 1.6.2.0 - Blackboard) Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.) CCleaner (HKLM\...\CCleaner) (Version: 5.20 - Piriform) Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 8.66.4.60 - Conexant) Device Setup (HKLM-x32\...\{1F07F2C7-596F-4F34-B805-2C61A3E50E5A}) (Version: 1.0.20 - ASUSTek Computer Inc.) Foxit Reader (HKLM-x32\...\Foxit Reader_is1) (Version: 8.0.2.805 - Foxit Software Inc.) Genesys USB Mass Storage Device (HKLM-x32\...\{959B7F35-2819-40C5-A0CD-3C53B5FCC935}) (Version: 4.3.2.2.1001 - Genesys Logic) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 54.0.2840.99 - Google Inc.) Google Drive (HKLM-x32\...\{3D7AB4D4-2E45-4986-BAC5-5B3CEED21FAA}) (Version: 1.32.3592.6117 - Google, Inc.) Google Update Helper (x32 Version: 1.3.21.169 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.31.5 - Google Inc.) Hidden Grammarly (HKU\S-1-5-21-3634378098-2526221181-1815557863-1001\...\GrammarlyForWindows) (Version: 1.4.23 - Grammarly) Grammarly for Microsoft® Office Suite (HKU\S-1-5-21-3634378098-2526221181-1815557863-1001\...\{b1eb8775-bc01-49f5-9885-9ff3c9b4a7a3}) (Version: 6.5.57 - Grammarly) Grammarly for Microsoft® Office Suite (Version: 6.5.57 - Grammarly) Hidden HP Support Assistant (HKLM-x32\...\{78E2C850-ADA6-420D-BA35-2F4A9BE733CC}) (Version: 8.3.34.7 - HP) HP Support Solutions Framework (HKLM-x32\...\{CE7447C2-EF12-4EF3-BE51-BFC3B049C0F6}) (Version: 12.5.32.37 - HP) Intel Collaborative Processor Performance Control (HKLM-x32\...\0E7DAF70-FB54-4B91-B192-7E771C25AEEB) (Version: 1.0.0.1017 - Intel Corporation) Intel(R) Chipset Device Software (x32 Version: 10.0.22 - Intel(R) Corporation) Hidden Intel(R) Dynamic Platform and Thermal Framework (HKLM-x32\...\{654EE65D-FAA4-4EA6-8C07-DC94E6A304D4}) (Version: 8.0.10100.71 - Intel Corporation) Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 10.0.28.1006 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.4013 - Intel Corporation) Intel(R) WiDi (HKLM\...\{2F97FBC6-7992-4DF7-A7C7-B68455E307F7}) (Version: 5.1.20.0 - Intel Corporation) Intel(R) Wireless Bluetooth(R) (HKLM-x32\...\{06A5031E-3B1E-4FB9-AC4C-BA0FE2706152}) (Version: 17.1.1433.02 - Intel Corporation) Intel® PROSet/Wireless Software (HKLM-x32\...\{c78a13fd-4324-4ddb-a613-746d2461441d}) (Version: 17.13.1 - Intel Corporation) iTunes (HKLM\...\{9946A4F7-E0FD-4A33-82D1-06CBFFBBB9F9}) (Version: 12.5.1.21 - Apple Inc.) Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUS) (Version: 14.0.4734.1000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation) Mobile Upgrade S 4.4.4 (HKLM-x32\...\{C9A7E6A6-110D-4DBC-A8E2-F634613B5A8C}_is1) (Version: - TCL Communication Technology Holdings Limited) Private Internet Access Support Files (HKLM-x32\...\{7D72DAFF-DCB2-437B-BC22-4B2ABF21462B}) (Version: 1.0.0.0 - Private Internet Access) Realtek USB Fast Ethernet Controller All-In-One Windows Driver (HKLM-x32\...\{D2B61BE0-B18B-4091-81B4-F234F4C30DFD}) (Version: 8.13.106.2014 - Realtek) Sophos Anti-Virus (HKLM-x32\...\{09863DA9-7A9B-4430-9561-E04D178D7017}) (Version: 10.6.3.537 - Sophos Limited) Sophos AutoUpdate (HKLM-x32\...\{BCF53039-A7FC-4C79-A3E3-437AE28FD918}) (Version: 5.2.0.276 - Sophos Limited) Sophos Network Threat Protection (HKLM\...\{66967E5F-43E8-4402-87A4-04685EE5C2CB}) (Version: 1.2.2.50 - Sophos Limited) Sophos System Protection (HKLM-x32\...\{1093B57D-A613-47F3-90CF-0FD5C5DCFFE6}) (Version: 1.3.0 - Sophos Limited) Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1) (Version: 1.6.2 - Safer Networking Limited) Tipard iPhone Transfer Ultimate 8.2.10 (HKLM-x32\...\{03905CD1-11B5-4cae-9508-C0EAD274D250}_is1) (Version: 8.2.10 - Tipard Studio) Unlocker 1.9.2 (HKLM\...\Unlocker) (Version: 1.9.2 - Cedrick Collomb) Viber (HKU\S-1-5-21-3634378098-2526221181-1815557863-1001\...\{28758ae6-92af-41a4-b9de-53a3eb0ccd3a}) (Version: 6.0.5.1518 - Viber Media Inc.) Viber (x32 Version: 6.0.5.1518 - Viber Media Inc.) Hidden Waterfox 49.0.3 (x64 en-US) (HKLM\...\Waterfox 49.0.3 (x64 en-US)) (Version: 49.0.3 - Mozilla) WebStorage (HKLM-x32\...\WebStorage) (Version: 2.1.15.458 - ASUS Cloud Corporation) Windows 10 Upgrade Assistant (HKLM-x32\...\{D5C69738-B486-402E-85AC-2456D98A64E4}) (Version: 1.4.9200.17323 - Microsoft Corporation) Windows Driver Package - ASUS (ATP) Mouse (07/02/2014 6.0.0.39) (HKLM\...\51B9B97722559D76D6429B83B71A86106A35BFCE) (Version: 07/02/2014 6.0.0.39 - ASUS) WinFlash (HKLM-x32\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 2.42.0 - ASUS) WinRAR 5.31 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.31.0 - win.rar GmbH) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-3634378098-2526221181-1815557863-1001_Classes\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6}\InprocServer32 -> C:\WINDOWS\system32\shell32.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3634378098-2526221181-1815557863-1001_Classes\CLSID\{2AD206F1-152C-4F9D-A24E-6F93FE7A4AFC}\InprocServer32 -> C:\Users\JOHN\AppData\Local\Grammarly\Grammarly for Microsoft Office Suite\6.5.57\DC18C44E5152464E87AFAF0E8BBA6A29\GrammarlyShim64.dll (CompanyName) CustomCLSID: HKU\S-1-5-21-3634378098-2526221181-1815557863-1001_Classes\CLSID\{4BE56754-B616-4998-B825-D16983AEE1B2}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3634378098-2526221181-1815557863-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\JOHN\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\FileCoAuth.exe (Microsoft Corporation) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {0B1B0048-6823-4826-8CE7-8DED040FA6E6} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION Task: {17314671-B9A7-4A45-8307-126F5C013ACD} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION Task: {1DDC0F49-1A88-4391-9FAC-6AAD77D3CC18} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2016-08-23] (HP Inc.) Task: {20870CA4-E073-4A07-85EF-1C07385B5B40} - System32\Tasks\{29061B78-16D2-4530-ACB4-5AF9AD4A68F1} => pcalua.exe -a "C:\Program Files (x86)\Doulci Team\Doulci iCloud Unlocker\Doulci HostSetup.exe" -d "C:\Program Files (x86)\Doulci Team\Doulci iCloud Unlocker" Task: {227ABF02-6587-4A09-8472-C1B4643EAB83} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION Task: {274CA3E1-CE7A-4E07-8964-E446CC3F9B60} - System32\Tasks\ATK Package 36D18D69AFC3 => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SimAppExec.exe [2014-06-12] (ASUSTek Computer Inc.) Task: {31D983B0-4972-4954-A0A8-FF0FC77F4CF2} - System32\Tasks\UMonitor Task => C:\Windows\SysWOW64\UMonit64.exe [2014-03-05] () Task: {32CF0819-9693-40CD-BD19-980D52367FD9} - System32\Tasks\ASUS Patch for Touch Panel => C:\ProgramData\AsTouchPanel\AsPatchTouchPanel64.exe [2013-01-09] (ASUSTek Computer INC.) Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\WINDOWS\System32\AutoWorkplace.exe Task: {3939B0A9-26ED-491E-8EEE-70E2423425B6} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-07-14] (Piriform Ltd) Task: {3CDED00E-880C-40C3-8D57-3C7AA50D022E} - System32\Tasks\ASUS Live Update2 => C:\Program Files (x86) [Argument = -check] Task: {3DA61184-80FF-4AF6-80D8-DB9545C8320E} - System32\Tasks\HPCeeScheduleForJOHN => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2016-01-22] (Hewlett-Packard) Task: {4B78B4F8-FE64-4A8A-9558-92B592B8F9FD} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [2016-05-09] (Hewlett-Packard) Task: {4F81C7CC-3BF8-4F31-9B30-9AC90847E8A1} - System32\Tasks\Update Checker => C:\Program Files (x86)\ASUS\ASUS Live Update\UpdateChecker.exe [2014-04-11] () Task: {5C2404B3-3F2C-4A35-B858-7BAE274BAAA5} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-06-09] (Google Inc.) Task: {67DB2BF7-6884-4C80-B0C3-6152D92F3691} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2016-08-03] (HP Inc.) Task: {6DF39014-EF99-4995-9C33-E406E70AE35D} - \McAfee\McAfee Idle Detection Task -> No File <==== ATTENTION Task: {7729754D-3918-49E6-BA26-8E611CA6597C} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2016-08-23] (HP Inc.) Task: {7F06BB5C-9179-4137-9274-EC227A7E8406} - System32\Tasks\{98502C34-8310-40C3-8418-F60938D04A15} => pcalua.exe -a "C:\Program Files (x86)\Tencent\QQPCMgr\11.8.17915.212\Uninst.exe" Task: {7FD70A5C-5653-4502-A6CC-9EDC689BCF4C} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION Task: {9BC22B17-40A4-484F-96D7-FAAAF8311E66} - System32\Tasks\iToolsDaemon => C:\Program Files (x86)\ThinkSky\iTools 3\iToolsDaemon.exe Task: {9E3A9912-6034-47D1-82AF-1AF9121486AD} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.) Task: {9EAF3C60-332D-40B7-A60B-A0A6F7E5C4D3} - System32\Tasks\ASUS Splendid ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2014-09-12] (ASUS) Task: {A72F3467-CBE5-40A8-9136-937006F1FE74} - System32\Tasks\ASUS Live Update1 => C:\Program Files (x86) [Argument = -critical] Task: {A8E0CE84-CDF0-472C-993F-EC0A03166374} - System32\Tasks\ASUS USB Charger Plus => C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [2014-09-12] (ASUSTek Computer Inc.) Task: {AD2B6ACF-937E-4BD9-B0B0-3634E2EA944C} - System32\Tasks\Private Internet Access Startup => C:\Program Files\pia_manager\pia_manager.exe [2016-10-03] () Task: {B89E83BC-8AFD-46D2-80BA-AFE7218926C1} - \WPD\SqmUpload_S-1-5-21-3634378098-2526221181-1815557863-1001 -> No File <==== ATTENTION Task: {BF14CB3F-9347-4F4E-89F5-A82DCA5B5470} - System32\Tasks\ASUS Smart Gesture Launcher => C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLauncher.exe [2014-11-21] (AsusTek) Task: {D47D7F47-79C9-4573-B9D9-9AC9D95FC6C1} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION Task: {ECF442F1-88C9-40C5-B127-B8B30E2358B0} - System32\Tasks\Hewlett-Packard\HP Active Health\HP Active Health Scan (HPSA) => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.exe [2016-08-18] (HP Inc.) Task: {F21F1823-400C-4525-B121-978C65A520F8} - System32\Tasks\ASUS\ASUS Product Register Service => C:\Program Files (x86)\ASUS\APRP\aprp.exe [2015-03-04] (ASUSTek Computer Inc.) Task: {FB8AB3E6-6D2D-41E7-B0BC-3B307CAADBE5} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-06-09] (Google Inc.) Task: {FD7F591B-1281-4AAA-9850-6FE770BD5616} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-11-14] (Adobe Systems Incorporated) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\HPCeeScheduleForJOHN.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe Task: C:\WINDOWS\Tasks\iToolsDaemon.job => C:\Program Files (x86)\ThinkSky\iTools 3\iToolsDaemon.exe ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== 2016-09-01 18:12 - 2016-09-01 18:12 - 00092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2016-09-01 18:12 - 2016-09-01 18:12 - 01353528 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2016-07-10 21:01 - 2016-07-10 21:01 - 00233608 _____ () C:\Program Files\Sophos\Sophos Network Threat Protection\bin\plugins\http.plg 2016-07-10 21:01 - 2016-07-10 21:01 - 00140696 _____ () C:\Program Files\Sophos\Sophos Network Threat Protection\bin\plugins\ip.plg 2016-07-10 21:01 - 2016-07-10 21:01 - 00119344 _____ () C:\Program Files\Sophos\Sophos Network Threat Protection\bin\plugins\ipv6.plg 2016-07-10 21:01 - 2016-07-10 21:01 - 00076704 _____ () C:\Program Files\Sophos\Sophos Network Threat Protection\bin\plugins\portmap.plg 2016-07-10 21:00 - 2016-07-10 21:00 - 00165000 _____ () C:\Program Files\Sophos\Sophos Network Threat Protection\bin\plugins\tcp.plg 2016-07-10 21:01 - 2016-07-10 21:01 - 00148440 _____ () C:\Program Files\Sophos\Sophos Network Threat Protection\bin\plugins\udp.plg 2016-07-16 21:42 - 2016-07-16 21:42 - 00231424 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll 2016-10-03 16:27 - 2016-09-16 03:25 - 02681200 _____ () C:\WINDOWS\System32\CoreUIComponents.dll 2016-10-03 16:27 - 2016-09-16 03:25 - 02681200 _____ () C:\WINDOWS\system32\CoreUIComponents.dll 2016-06-09 21:37 - 2016-10-03 20:58 - 07711966 _____ () C:\Program Files\pia_manager\pia_manager.exe 2016-10-03 16:27 - 2016-09-16 03:25 - 02681200 _____ () C:\WINDOWS\SYSTEM32\CoreUIComponents.dll 2016-09-27 14:39 - 2016-09-27 14:39 - 01864384 ____H () C:\Users\JOHN\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\amd64\ClientTelemetry.dll 2016-09-27 21:44 - 2016-09-27 21:44 - 00134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll 2016-11-10 12:51 - 2016-11-02 20:30 - 00474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll 2016-11-10 12:51 - 2016-11-02 20:21 - 09760768 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2016-11-10 12:51 - 2016-11-02 20:15 - 01401856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2016-11-10 12:51 - 2016-11-02 20:14 - 00757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll 2016-11-10 12:51 - 2016-11-02 20:15 - 01033216 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll 2016-11-10 12:51 - 2016-11-02 20:16 - 02424320 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll 2016-11-10 12:51 - 2016-11-02 20:17 - 04853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll 2016-11-07 06:15 - 2016-11-07 06:15 - 00072192 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.9.251.0_x64__kzf8qxf38zg5c\SkypeHost.exe 2016-11-07 06:15 - 2016-11-07 06:15 - 00178688 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.9.251.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll 2016-11-07 06:15 - 2016-11-07 06:15 - 41608704 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.9.251.0_x64__kzf8qxf38zg5c\SkyWrap.dll 2016-05-27 15:50 - 2016-05-27 15:50 - 00402520 _____ () C:\WINDOWS\system32\igfxTray.exe 2016-01-07 02:41 - 2016-01-07 02:41 - 00062168 _____ () C:\Program Files\CCleaner\branding.dll 2016-02-25 06:54 - 2014-03-05 18:49 - 00053248 _____ () C:\Windows\SysWOW64\UMonit64.exe 2016-06-09 21:37 - 2016-10-03 20:58 - 00693760 _____ () C:\Program Files\pia_manager\openvpn.exe 2016-06-09 21:37 - 2016-10-03 20:58 - 00108441 _____ () C:\Program Files\pia_manager\libpkcs11-helper-1.dll 2016-06-09 21:37 - 2016-10-03 20:58 - 00190317 _____ () C:\Program Files\pia_manager\liblzo2-2.dll 2016-06-09 21:37 - 2016-10-03 20:58 - 00144896 _____ () C:\Program Files\pia_manager\pia-openvpn.dll 2014-09-04 05:03 - 2014-09-04 05:03 - 01241560 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll 2014-09-12 12:31 - 2014-09-12 12:31 - 00037424 _____ () C:\Program Files (x86)\ASUS\Splendid\DetectDisplayDC.dll 2014-09-12 12:31 - 2014-09-12 12:31 - 00018992 _____ () C:\Program Files (x86)\ASUS\Splendid\AMDColorEnhance.dll 2014-09-12 12:31 - 2014-09-12 12:31 - 00124928 _____ () C:\Program Files (x86)\ASUS\Splendid\CCTAdjust.dll 2014-09-12 12:31 - 2014-09-12 12:31 - 00020528 _____ () C:\Program Files (x86)\ASUS\Splendid\AMDRegammaAndGamut.dll 2016-11-17 04:13 - 2016-11-17 04:13 - 00012800 _____ () C:\Users\JOHN\AppData\Local\Temp\ocr71DD.tmp\lib\ruby\1.9.1\i386-mingw32\enc\encdb.so 2016-11-17 04:13 - 2016-11-17 04:13 - 00009728 _____ () C:\Users\JOHN\AppData\Local\Temp\ocr71DD.tmp\lib\ruby\1.9.1\i386-mingw32\enc\iso_8859_1.so 2016-11-17 04:13 - 2016-11-17 04:13 - 00014848 _____ () C:\Users\JOHN\AppData\Local\Temp\ocr71DD.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans\transdb.so 2016-11-17 04:13 - 2016-11-17 04:13 - 00094208 _____ () C:\Users\JOHN\AppData\Local\Temp\ocr71DD.tmp\src\rgloader\rgloader193.mswin.so 2016-11-17 04:13 - 2016-11-17 04:13 - 00009216 _____ () C:\Users\JOHN\AppData\Local\Temp\ocr71DD.tmp\lib\ruby\1.9.1\i386-mingw32\etc.so 2016-11-17 04:13 - 2016-11-17 04:13 - 00094208 _____ () C:\Users\JOHN\AppData\Local\Temp\ocr71DD.tmp\lib\ruby\site_ruby\1.9.1\rgloader\rgloader193.mswin.so 2016-11-17 04:13 - 2016-11-17 04:13 - 00126976 _____ () C:\Users\JOHN\AppData\Local\Temp\ocr71DD.tmp\lib\ruby\1.9.1\i386-mingw32\win32ole.so 2016-11-17 04:13 - 2016-11-17 04:13 - 00087552 _____ () C:\Users\JOHN\AppData\Local\Temp\ocr71DD.tmp\lib\ruby\1.9.1\i386-mingw32\dl.so 2016-11-17 04:13 - 2016-11-17 04:13 - 00016384 _____ () C:\Users\JOHN\AppData\Local\Temp\ocr71DD.tmp\lib\ruby\1.9.1\i386-mingw32\fiddle.so 2016-11-17 04:13 - 2016-11-17 04:13 - 00127316 _____ () C:\Users\JOHN\AppData\Local\Temp\ocr71DD.tmp\bin\libffi-6.dll 2016-11-17 04:13 - 2016-11-17 04:13 - 00008704 _____ () C:\Users\JOHN\AppData\Local\Temp\ocr71DD.tmp\lib\ruby\1.9.1\i386-mingw32\enc\utf_16le.so 2016-11-17 04:13 - 2016-11-17 04:13 - 00013312 _____ () C:\Users\JOHN\AppData\Local\Temp\ocr71DD.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans\utf_16_32.so 2016-11-17 04:13 - 2016-11-17 04:13 - 00095744 _____ () C:\Users\JOHN\AppData\Local\Temp\ocr71DD.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans\single_byte.so 2016-11-17 04:13 - 2016-11-17 04:13 - 00026624 _____ () C:\Users\JOHN\AppData\Local\Temp\ocr71DD.tmp\lib\ruby\gems\1.9.1\gems\win32-api-1.5.0-universal-mingw32\lib\win32\ruby19\win32\api.so 2016-11-17 04:13 - 2016-11-17 04:13 - 00012800 _____ () C:\Users\JOHN\AppData\Local\Temp\ocrBC63.tmp\lib\ruby\1.9.1\i386-mingw32\enc\encdb.so 2016-11-17 04:13 - 2016-11-17 04:13 - 00009728 _____ () C:\Users\JOHN\AppData\Local\Temp\ocrBC63.tmp\lib\ruby\1.9.1\i386-mingw32\enc\iso_8859_1.so 2016-11-17 04:13 - 2016-11-17 04:13 - 00014848 _____ () C:\Users\JOHN\AppData\Local\Temp\ocrBC63.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans\transdb.so 2016-11-17 04:13 - 2016-11-17 04:13 - 00094208 _____ () C:\Users\JOHN\AppData\Local\Temp\ocrBC63.tmp\src\rgloader\rgloader193.mswin.so 2016-11-17 04:13 - 2016-11-17 04:13 - 00094208 _____ () C:\Users\JOHN\AppData\Local\Temp\ocrBC63.tmp\lib\ruby\site_ruby\1.9.1\rgloader\rgloader193.mswin.so 2016-11-17 04:13 - 2016-11-17 04:13 - 00118784 _____ () C:\Users\JOHN\AppData\Local\Temp\ocrBC63.tmp\lib\ruby\1.9.1\i386-mingw32\socket.so 2016-11-17 04:13 - 2016-11-17 04:13 - 00069120 _____ () C:\Users\JOHN\AppData\Local\Temp\ocrBC63.tmp\lib\ruby\1.9.1\i386-mingw32\zlib.so 2016-11-17 04:13 - 2016-11-17 04:13 - 00083968 _____ () C:\Users\JOHN\AppData\Local\Temp\ocrBC63.tmp\bin\zlib1.dll 2016-11-17 04:13 - 2016-11-17 04:13 - 00026624 _____ () C:\Users\JOHN\AppData\Local\Temp\ocrBC63.tmp\lib\ruby\1.9.1\i386-mingw32\stringio.so 2016-11-17 04:13 - 2016-11-17 04:13 - 00275968 _____ () C:\Users\JOHN\AppData\Local\Temp\ocrBC63.tmp\lib\ruby\1.9.1\i386-mingw32\openssl.so 2016-11-17 04:13 - 2016-11-17 04:13 - 00015360 _____ () C:\Users\JOHN\AppData\Local\Temp\ocrBC63.tmp\lib\ruby\1.9.1\i386-mingw32\digest.so 2016-11-17 04:13 - 2016-11-17 04:13 - 00008192 _____ () C:\Users\JOHN\AppData\Local\Temp\ocrBC63.tmp\lib\ruby\1.9.1\i386-mingw32\fcntl.so 2016-11-17 04:13 - 2016-11-17 04:13 - 00009216 _____ () C:\Users\JOHN\AppData\Local\Temp\ocrBC63.tmp\lib\ruby\1.9.1\i386-mingw32\etc.so 2016-11-17 04:13 - 2016-11-17 04:13 - 00023552 _____ () C:\Users\JOHN\AppData\Local\Temp\ocrBC63.tmp\lib\ruby\1.9.1\i386-mingw32\json\ext\parser.so 2016-11-17 04:13 - 2016-11-17 04:13 - 00008704 _____ () C:\Users\JOHN\AppData\Local\Temp\ocrBC63.tmp\lib\ruby\1.9.1\i386-mingw32\enc\utf_16be.so 2016-11-17 04:13 - 2016-11-17 04:13 - 00008704 _____ () C:\Users\JOHN\AppData\Local\Temp\ocrBC63.tmp\lib\ruby\1.9.1\i386-mingw32\enc\utf_16le.so 2016-11-17 04:13 - 2016-11-17 04:13 - 00008704 _____ () C:\Users\JOHN\AppData\Local\Temp\ocrBC63.tmp\lib\ruby\1.9.1\i386-mingw32\enc\utf_32be.so 2016-11-17 04:13 - 2016-11-17 04:13 - 00008704 _____ () C:\Users\JOHN\AppData\Local\Temp\ocrBC63.tmp\lib\ruby\1.9.1\i386-mingw32\enc\utf_32le.so 2016-11-17 04:13 - 2016-11-17 04:13 - 00036352 _____ () C:\Users\JOHN\AppData\Local\Temp\ocrBC63.tmp\lib\ruby\1.9.1\i386-mingw32\json\ext\generator.so 2016-11-17 04:13 - 2016-11-17 04:13 - 00126976 _____ () C:\Users\JOHN\AppData\Local\Temp\ocrBC63.tmp\lib\ruby\1.9.1\i386-mingw32\win32ole.so 2016-11-17 04:13 - 2016-11-17 04:13 - 00087552 _____ () C:\Users\JOHN\AppData\Local\Temp\ocrBC63.tmp\lib\ruby\1.9.1\i386-mingw32\dl.so 2016-11-17 04:13 - 2016-11-17 04:13 - 00016384 _____ () C:\Users\JOHN\AppData\Local\Temp\ocrBC63.tmp\lib\ruby\1.9.1\i386-mingw32\fiddle.so 2016-11-17 04:13 - 2016-11-17 04:13 - 00127316 _____ () C:\Users\JOHN\AppData\Local\Temp\ocrBC63.tmp\bin\libffi-6.dll 2016-11-17 04:13 - 2016-11-17 04:13 - 00013312 _____ () C:\Users\JOHN\AppData\Local\Temp\ocrBC63.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans\utf_16_32.so 2016-11-17 04:13 - 2016-11-17 04:13 - 00095744 _____ () C:\Users\JOHN\AppData\Local\Temp\ocrBC63.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans\single_byte.so 2016-11-17 04:13 - 2016-11-17 04:13 - 00026624 _____ () C:\Users\JOHN\AppData\Local\Temp\ocrBC63.tmp\lib\ruby\gems\1.9.1\gems\win32-api-1.5.0-universal-mingw32\lib\win32\ruby19\win32\api.so 2016-07-25 20:17 - 2016-10-03 20:58 - 00939520 _____ () C:\Program Files\pia_manager\pia_tray_bin\nw-win\ffmpeg.dll 2016-07-25 20:17 - 2016-10-03 20:58 - 03115520 _____ () C:\Program Files\pia_manager\pia_tray_bin\nw-win\node.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SAVService => ""="service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SAVService => ""="service" ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2013-08-22 23:25 - 2013-08-22 23:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-3634378098-2526221181-1815557863-1001\Control Panel\Desktop\\Wallpaper -> c:\windows\web\wallpaper\windows\img0.jpg DNS Servers: [removed] - [removed] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == HKLM\...\StartupApproved\Run: => "SmartAudio" HKLM\...\StartupApproved\Run: => "iTunesHelper" HKLM\...\StartupApproved\Run32: => "WebStorage" HKLM\...\StartupApproved\Run32: => "GrooveMonitor" HKU\S-1-5-21-3634378098-2526221181-1815557863-1001\...\StartupApproved\Run: => "OneDrive" HKU\S-1-5-21-3634378098-2526221181-1815557863-1001\...\StartupApproved\Run: => "GoogleDriveSync" HKU\S-1-5-21-3634378098-2526221181-1815557863-1001\...\StartupApproved\Run: => "AnyName " ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [{9175F132-2CA3-45A5-9BD9-A73D1840F213}] => (Allow) E:\iTunes.exe FirewallRules: [{23264694-7C9E-41D4-935E-B99205220787}] => (Allow) C:\program files (x86)\common files\tencent\qqdownload\130\bugreport_xf.exe FirewallRules: [{400E9A72-CD40-44D4-9FE2-C91C9888D1D2}] => (Allow) C:\program files (x86)\common files\tencent\qqdownload\130\tencentdl.exe FirewallRules: [{1618DB6A-C001-45E8-8ED8-BEDCFDC4C8BD}] => (Block) C:\users\john\appdata\local\programs\blackboard\blackboard collaborate launcher\resources\java\jre1.7.0_40\bin\javaw.exe FirewallRules: [{D43C1FDF-4E1F-4BB9-83C1-0490229240AC}] => (Block) C:\users\john\appdata\local\programs\blackboard\blackboard collaborate launcher\resources\java\jre1.7.0_40\bin\javaw.exe FirewallRules: [UDP Query User{9F5F2C23-E376-4D1D-879D-FC5221E97515}C:\users\john\appdata\local\programs\blackboard\blackboard collaborate launcher\resources\java\jre1.7.0_40\bin\javaw.exe] => (Allow) C:\users\john\appdata\local\programs\blackboard\blackboard collaborate launcher\resources\java\jre1.7.0_40\bin\javaw.exe FirewallRules: [TCP Query User{88FFB24A-E749-49EA-83B4-71738F9B9D58}C:\users\john\appdata\local\programs\blackboard\blackboard collaborate launcher\resources\java\jre1.7.0_40\bin\javaw.exe] => (Allow) C:\users\john\appdata\local\programs\blackboard\blackboard collaborate launcher\resources\java\jre1.7.0_40\bin\javaw.exe FirewallRules: [{9F3D817D-CBD8-45DB-AF9C-79DB182FB212}] => (Block) C:\program files (x86)\deluge\deluge.exe FirewallRules: [{2EBF70C0-CE6C-4CB5-947E-D9032B1A54F0}] => (Block) C:\program files (x86)\deluge\deluge.exe FirewallRules: [UDP Query User{63180165-737A-444D-8959-11400F087FA1}C:\program files (x86)\deluge\deluge.exe] => (Allow) C:\program files (x86)\deluge\deluge.exe FirewallRules: [TCP Query User{B38394FA-4BF7-4B5F-924E-21F2B8C59BA9}C:\program files (x86)\deluge\deluge.exe] => (Allow) C:\program files (x86)\deluge\deluge.exe FirewallRules: [{16D02290-F33D-42CA-9535-6C78828B3147}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{84BAED5C-7CBC-4E94-A149-BC717C840698}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{E07AE947-FD2F-4533-BD54-FD915DB052F8}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{9E0D398B-6541-4652-8F10-F258B4F78C94}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{9C8E458F-848E-4861-8731-3797DEE43D1A}] => (Allow) C:\Program Files\Waterfox\waterfox.exe FirewallRules: [{77F9B5BC-3D97-4EA5-9B46-407A5B130774}] => (Allow) C:\Program Files\Waterfox\waterfox.exe FirewallRules: [{826ABAEA-6A24-4BBB-B3C4-661FBC1EAC85}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe FirewallRules: [{C97F61E7-E23B-468F-8A3D-BF98B33F0276}] => (Allow) C:\Program Files\Intel Corporation\Intel WiDi\WiDiApp.exe FirewallRules: [{A8ADE790-869D-4478-9D54-32B7BF39DC8F}] => (Allow) C:\Program Files\Intel Corporation\USB over IP\bin\UoipService.exe FirewallRules: [TCP Query User{E1B4F8D8-3806-4369-B2DF-6FB906DC5AFF}C:\program files (x86)\sonos\sonos.exe] => (Allow) C:\program files (x86)\sonos\sonos.exe FirewallRules: [UDP Query User{1F0069CD-4A91-4DB3-B532-EA33218FAD79}C:\program files (x86)\sonos\sonos.exe] => (Allow) C:\program files (x86)\sonos\sonos.exe FirewallRules: [{461AF054-1C14-4130-B625-F13CC89922BC}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Restore Points ========================= ATTENTION: System Restore is disabled ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (11/17/2016 04:16:34 AM) (Source: Perflib) (EventID: 1008) (User: ) Description: The Open Procedure for service "BITS" in DLL "C:\Windows\System32\bitsperf.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code. Error: (11/17/2016 04:13:19 AM) (Source: SideBySide) (EventID: 63) (User: ) Description: Activation context generation failed for "C:\Program Files (x86)\Spybot - Search & Destroy\DelZip179.dll".Error in manifest or policy file "C:\Program Files (x86)\Spybot - Search & Destroy\DelZip179.dll" on line 8. The value "*" of attribute "language" in element "assemblyIdentity" is invalid. Error: (11/16/2016 02:22:42 PM) (Source: SideBySide) (EventID: 63) (User: ) Description: Activation context generation failed for "c:\program files (x86)\spybot - search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program files (x86)\spybot - search & destroy\DelZip179.dll" on line 8. The value "*" of attribute "language" in element "assemblyIdentity" is invalid. Error: (11/16/2016 02:37:21 AM) (Source: SideBySide) (EventID: 63) (User: ) Description: Activation context generation failed for "C:\Program Files (x86)\Spybot - Search & Destroy\DelZip179.dll".Error in manifest or policy file "C:\Program Files (x86)\Spybot - Search & Destroy\DelZip179.dll" on line 8. The value "*" of attribute "language" in element "assemblyIdentity" is invalid. Error: (11/16/2016 02:37:14 AM) (Source: SideBySide) (EventID: 63) (User: ) Description: Activation context generation failed for "C:\Program Files (x86)\Spybot - Search & Destroy\DelZip179.dll".Error in manifest or policy file "C:\Program Files (x86)\Spybot - Search & Destroy\DelZip179.dll" on line 8. The value "*" of attribute "language" in element "assemblyIdentity" is invalid. Error: (11/16/2016 02:26:32 AM) (Source: Microsoft-Windows-EapHost) (EventID: 2002) (User: NT AUTHORITY) Description: Skipping: Eap method DLL path validation failed. Error: typeId=43, authorId=9, vendorId=0, vendorType=0 Error: (11/16/2016 02:26:32 AM) (Source: Microsoft-Windows-EapHost) (EventID: 2002) (User: NT AUTHORITY) Description: Skipping: Eap method DLL path validation failed. Error: typeId=25, authorId=9, vendorId=0, vendorType=0 Error: (11/16/2016 02:26:32 AM) (Source: Microsoft-Windows-EapHost) (EventID: 2002) (User: NT AUTHORITY) Description: Skipping: Eap method DLL path validation failed. Error: typeId=17, authorId=9, vendorId=0, vendorType=0 Error: (11/16/2016 02:26:32 AM) (Source: Microsoft-Windows-EapHost) (EventID: 2002) (User: NT AUTHORITY) Description: Skipping: Eap method DLL path validation failed. Error: typeId=43, authorId=9, vendorId=0, vendorType=0 Error: (11/16/2016 02:26:32 AM) (Source: Microsoft-Windows-EapHost) (EventID: 2002) (User: NT AUTHORITY) Description: Skipping: Eap method DLL path validation failed. Error: typeId=25, authorId=9, vendorId=0, vendorType=0 System errors: ============= Error: (11/17/2016 04:13:24 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {8D8F4F83-3594-4F07-8369-FC3C3CAE4919} and APPID {F72671A9-012C-4725-9D2F-2A4D32D65169} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (11/16/2016 02:22:42 PM) (Source: DCOM) (EventID: 10010) (User: ASUS) Description: The server {9BA05972-F6A8-11CF-A442-00A0C90A8F39} did not register with DCOM within the required timeout. Error: (11/16/2016 03:51:24 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (11/16/2016 02:52:59 AM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY) Description: The server {F3B4E234-7A68-4E43-B813-E4BA55A065F6} did not register with DCOM within the required timeout. Error: (11/16/2016 02:47:01 AM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY) Description: The server {F3B4E234-7A68-4E43-B813-E4BA55A065F6} did not register with DCOM within the required timeout. Error: (11/16/2016 02:26:40 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52} and APPID {4839DDB7-58C2-48F5-8283-E1D1807D0D7D} to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (11/16/2016 02:26:40 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52} and APPID {4839DDB7-58C2-48F5-8283-E1D1807D0D7D} to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (11/16/2016 02:26:40 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {8D8F4F83-3594-4F07-8369-FC3C3CAE4919} and APPID {F72671A9-012C-4725-9D2F-2A4D32D65169} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (11/16/2016 02:26:10 AM) (Source: DCOM) (EventID: 10010) (User: ASUS) Description: The server microsoft.windowslive.calendar.AppXwkn9j84yh1kvnt49k5r8h6y1ecsv09hs.mca did not register with DCOM within the required timeout. Error: (11/16/2016 02:26:10 AM) (Source: DCOM) (EventID: 10010) (User: ASUS) Description: The server App.AppX3qxxjkzpw5zjvwsr56rsmztd1r9trjzt.mca did not register with DCOM within the required timeout. CodeIntegrity: =================================== Date: 2016-09-27 03:48:47.409 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe because the set of per-page image hashes could not be found on the system. Date: 2016-09-27 03:48:47.404 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe because the set of per-page image hashes could not be found on the system. Date: 2016-09-27 03:48:47.399 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe because the set of per-page image hashes could not be found on the system. Date: 2016-09-27 03:48:47.394 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe because the set of per-page image hashes could not be found on the system. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i5-5200U CPU @ 2.20GHz Percentage of memory in use: 40% Total physical RAM: 8094.69 MB Available physical RAM: 4820.48 MB Total Virtual: 9374.69 MB Available Virtual: 6125.86 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:95.39 GB) (Free:7.2 GB) NTFS ==>[system with boot components (obtained from drive)] Drive d: (Data) (Fixed) (Total:127.85 GB) (Free:44.42 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 238.5 GB) (Disk ID: 5D211201) Partition: GPT. ==================== End of Addition.txt ============================