Additional scan result of Farbar Recovery Scan Tool (x64) Version: 14-01-2017 Ran by [removed] (14-01-2017 23:42:01) Running from C:\Users\[removed]\Downloads Windows 10 Enterprise Version 1607 (X64) (2016-10-29 17:05:36) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-191997543-2862670574-3806412288-500 - Administrator - Disabled) => C:\Users\Administrator DefaultAccount (S-1-5-21-191997543-2862670574-3806412288-503 - Limited - Disabled) Guest (S-1-5-21-191997543-2862670574-3806412288-501 - Limited - Disabled) nasibeh (S-1-5-21-191997543-2862670574-3806412288-1001 - Administrator - Enabled) => C:\Users\nasibeh ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: Malwarebytes (Enabled - Out of date) {23007AD3-69FE-687C-2629-D584AFFAF72B} AV: 360 Total Security (Enabled - Up to date) {0371CA44-3F80-A1D3-BECE-910620B58D50} AS: Malwarebytes (Enabled - Out of date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: 360 Total Security (Enabled - Up to date) {B8102BA0-19BA-AE5D-847E-AA745B32C7ED} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) µTorrent (HKU\S-1-5-21-191997543-2862670574-3806412288-1001\...\uTorrent) (Version: 3.4.9.42606 - BitTorrent Inc.) 360 Total Security (HKLM-x32\...\360TotalSecurity) (Version: 9.0.0.1085 - 360 Security Center) Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.010.20056 - Adobe Systems Incorporated) Adobe Flash Player 21 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 21.0.0.213 - Adobe Systems Incorporated) Adobe Flash Player 21 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 21.0.0.213 - Adobe Systems Incorporated) Adobe Flash Player 21.0.0.213 (HKLM-x32\...\Adobe Flash Player_is1) (Version: 21.0.0.213 - Parand ® Software Group) CCleaner (HKLM\...\CCleaner) (Version: 5.25 - Piriform) Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 8.66.16.59 - Conexant) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 55.0.2883.87 - Google Inc.) Google Update Helper (x32 Version: 1.3.32.7 - Google Inc.) Hidden Herramientas de corrección de Microsoft Office 2016: español (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 20.19.15.4377 - Intel Corporation) Internet Download Manager (HKLM-x32\...\Internet Download Manager) (Version: - Tonec Inc.) K-Lite Mega Codec Pack 12.7.5 (HKLM-x32\...\KLiteCodecPack_is1) (Version: 12.7.5 - KLCP) KMPlayer (remove only) (HKLM-x32\...\The KMPlayer) (Version: 4.1.5.8 - PandoraTV) KMSpico (HKLM\...\{8B29D47F-92E2-4C20-9EE0-F710991F5D7C}_is1) (Version: - ) Malwarebytes version 3.0.5.1299 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.0.5.1299 - Malwarebytes) Microsoft Office Professional Plus 2016 (HKLM\...\Office16.PROPLUS) (Version: 16.0.4266.1001 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-191997543-2862670574-3806412288-1001\...\OneDriveSetup.exe) (Version: 17.3.6743.1212 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Outils de vérification linguistique 2016 de Microsoft Office - Français (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden Passport Photo Studio 1.5.1 (HKLM-x32\...\{FBBB318F-3769-4B1C-B8B2-AF7ED4DA2272}_is1) (Version: - Grogware LLC) Ritopofo version 5.4 (HKLM-x32\...\Ritopofo_is1) (Version: 5.4 - ) Skype™ 7.30 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.30.105 - Skype Technologies S.A.) TeamViewer Corporate 11.0.56083 (HKLM-x32\...\TeamViewer_is1) (Version: 11.0.56083 - Parand ® Software Group) Telegram Desktop version 1.0 (HKU\S-1-5-21-191997543-2862670574-3806412288-1001\...\{53F49750-6209-4FBF-9CA8-7A333C87D1ED}_is1) (Version: 1.0 - Telegram Messenger LLP) WhatsApp (HKU\S-1-5-21-191997543-2862670574-3806412288-1001\...\WhatsApp) (Version: 0.2.2732 - WhatsApp) WinRAR 5.31 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.31.0 - win.rar GmbH) WinZip 14.0 (HKLM-x32\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240BC}) (Version: 14.0.9029 - WinZip Computing, S.L. ) Xilisoft PDF to Word Converter (HKLM-x32\...\Xilisoft PDF to Word Converter) (Version: 1.0.2.20120228 - Xilisoft) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {40722444-F0E8-4B67-8690-EB2D604046FA} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-10-21] (Adobe Systems Incorporated) Task: {40A1CD1B-9B68-41C2-951A-0492B7F663B4} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\Office16\msoia.exe [2015-07-31] (Microsoft Corporation) Task: {40E4F2B4-1094-4197-BC30-2ED2EC16C82D} - System32\Tasks\OneDrive Standalone Update Task => C:\Users\nasibeh\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\OneDriveStandaloneUpdater.exe Task: {54D8AA15-046E-4D15-92D6-13E133824041} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-09-25] (Google Inc.) Task: {5FBE499D-6489-47E3-9CC3-D615C92E49A1} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2015-07-31] (Microsoft Corporation) Task: {6A0C4B39-34AA-4AFB-A47D-70A4A6DB32AF} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS\AutoKMS.exe [2016-10-28] () Task: {79521B73-E290-4D1B-9541-B2DF1FADD90F} - \AutoPico Daily Restart -> No File <==== ATTENTION Task: {ACE57A22-A9D2-4E5A-823F-3E5C594C5895} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-09-25] (Google Inc.) Task: {BA2D908C-CD71-4126-BEAC-EB1B04C7DF1D} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-12-06] (Piriform Ltd) Task: {D4C15E07-7E7F-4B37-9B25-0DA93E68D28D} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\Office16\msoia.exe [2015-07-31] (Microsoft Corporation) Task: {F9F7D55D-0C0F-48E4-AD78-A26DC845950F} - System32\Tasks\klcp_update => C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [2016-12-20] () (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== 2016-07-16 15:12 - 2016-07-16 15:12 - 00231424 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll 2016-12-14 15:29 - 2016-12-09 13:59 - 02681200 _____ () C:\WINDOWS\system32\CoreUIComponents.dll 2016-10-29 20:15 - 2016-08-01 16:24 - 00133056 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2017-01-14 22:58 - 2016-12-14 12:55 - 02259232 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\PoliciesControllerImpl.dll 2017-01-14 22:58 - 2016-12-14 12:55 - 02247632 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll 2017-01-14 22:58 - 2016-12-14 12:55 - 02813904 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\arwlib.dll 2016-12-14 15:29 - 2016-12-09 13:59 - 02681200 _____ () C:\WINDOWS\SYSTEM32\CoreUIComponents.dll 2015-07-31 09:58 - 2015-07-31 09:58 - 08901800 _____ () C:\Program Files\Microsoft Office\Office16\1033\GrooveIntlResource.dll 2016-10-04 22:11 - 2016-10-04 22:11 - 00402912 _____ () C:\WINDOWS\system32\igfxTray.exe 2016-10-29 23:03 - 2016-09-07 08:26 - 00134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll 2017-01-10 23:51 - 2016-12-21 10:39 - 00474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll 2016-11-29 09:59 - 2016-11-29 10:00 - 01787080 _____ () C:\Program Files\WindowsApps\Microsoft.MicrosoftStickyNotes_1.2.14.0_x64__8wekyb3d8bbwe\Microsoft.Applications.Telemetry.Windows.dll 2016-11-29 09:59 - 2016-11-29 10:00 - 00381440 _____ () C:\Program Files\WindowsApps\Microsoft.MicrosoftStickyNotes_1.2.14.0_x64__8wekyb3d8bbwe\Microsoft.Notes.Upgrade.dll 2017-01-10 23:51 - 2016-12-21 10:24 - 09760768 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2017-01-10 23:51 - 2016-12-21 10:18 - 01401856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2017-01-10 23:51 - 2016-12-21 10:18 - 00757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll 2017-01-10 23:51 - 2016-12-21 10:18 - 01033216 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll 2017-01-10 23:51 - 2016-12-21 10:18 - 02424320 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll 2017-01-10 23:51 - 2016-12-21 10:23 - 04853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll 2016-12-15 13:12 - 2016-12-08 11:33 - 02412888 _____ () C:\Program Files (x86)\Google\Chrome\Application\55.0.2883.87\libglesv2.dll 2016-12-15 13:12 - 2016-12-08 11:33 - 00099672 _____ () C:\Program Files (x86)\Google\Chrome\Application\55.0.2883.87\libegl.dll 2016-12-15 09:57 - 2016-12-15 09:58 - 00072192 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.10.145.0_x64__kzf8qxf38zg5c\SkypeHost.exe 2016-12-15 09:57 - 2016-12-15 09:58 - 00179712 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.10.145.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll 2016-12-15 09:57 - 2016-12-15 09:58 - 42130432 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.10.145.0_x64__kzf8qxf38zg5c\SkyWrap.dll 2016-12-15 09:57 - 2016-12-15 09:58 - 02216448 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.10.145.0_x64__kzf8qxf38zg5c\roottools.dll 2017-01-14 22:52 - 2016-12-30 10:52 - 00099240 _____ () C:\Program Files (x86)\360\Total Security\deepscan\qutmload.dll 2017-01-14 22:52 - 2016-12-30 10:52 - 00584616 _____ () C:\Program Files (x86)\360\Total Security\safemon\wdui2.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2015-07-10 14:34 - 2017-01-14 20:52 - 00000828 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-191997543-2862670574-3806412288-1001\Control Panel\Desktop\\Wallpaper -> c:\windows\web\wallpaper\theme1\img1.jpg HKU\S-1-5-21-191997543-2862670574-3806412288-500-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-01142017231446647\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Windows\img0.jpg DNS Servers: 192.168.1.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [vm-monitoring-nb-session] => LPort=139 FirewallRules: [UDP Query User{244401C5-22A2-4EF6-A7F2-BBC624B2524E}C:\program files (x86)\skype\phone\skype.exe] => C:\program files (x86)\skype\phone\skype.exe FirewallRules: [TCP Query User{090CE43F-1096-4938-9F13-42E08CC71669}C:\program files (x86)\skype\phone\skype.exe] => C:\program files (x86)\skype\phone\skype.exe FirewallRules: [{04ACC629-FA1B-47D9-8A7A-59F98D03DE03}] => C:\Users\nasibeh\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{DD352310-DB6B-4767-8490-A98431F51493}] => C:\Users\nasibeh\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{C4D033D4-8CD0-4A9B-9CD9-F6C6FA329CAF}] => C:\Users\nasibeh\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{7A55A351-D8D2-42A2-B805-3C25CF1ED018}] => C:\Users\nasibeh\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{A5065B07-2C45-4B56-8685-3A9F8A2DE8C0}] => C:\Users\nasibeh\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{923AD728-429A-48AB-A089-ABF8786D466F}] => C:\Users\nasibeh\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{22BB7E6F-C8BD-4923-AF08-3303B6E9F9B1}] => C:\Program Files\Microsoft Office\Office16\UcMapi.exe FirewallRules: [{D64C40E6-73BA-45B2-BC5D-A12AB9E7B076}] => C:\Program Files\Microsoft Office\Office16\UcMapi.exe FirewallRules: [{24DDD12F-D60A-4FAA-B74C-3EA6EC9F22D5}] => C:\Program Files\Microsoft Office\Office16\lync.exe FirewallRules: [{5A4A2817-1BA6-4827-AE51-2365D4A0DDBF}] => C:\Program Files\Microsoft Office\Office16\lync.exe FirewallRules: [UDP Query User{3013E88A-480A-4B97-962C-12B9FA2F4165}F:\programs\programs(86)\skype\phone\skype.exe] => F:\programs\programs(86)\skype\phone\skype.exe FirewallRules: [TCP Query User{C4497ABB-9FBA-4796-A3FB-9CCE2C70943F}F:\programs\programs(86)\skype\phone\skype.exe] => F:\programs\programs(86)\skype\phone\skype.exe FirewallRules: [{D5AC72CA-77AA-44C2-BE11-25845C988F1E}] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{97EDA52D-5D93-477C-8044-64E6674D366C}] => C:\Program Files (x86)\360\Total Security\softmgr\360InstantSetup.exe FirewallRules: [{5044E3AC-4863-44C0-A47B-5143825BEB37}] => C:\Program Files (x86)\360\Total Security\softmgr\360InstantSetup.exe FirewallRules: [{9E303C60-29F0-4C98-A6C8-7964706E9D23}] => C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe FirewallRules: [{7D17AB5B-AE0A-46E3-A5E7-7D488B327C2D}] => C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe FirewallRules: [{2108227C-0BB6-4F00-9F96-AC7B79BA002C}] => C:\Program Files (x86)\360\Total Security\LiveUpdate360.exe FirewallRules: [{944A216D-5A68-47E6-BC16-1E8BE1DC6940}] => C:\Program Files (x86)\360\Total Security\LiveUpdate360.exe ==================== Restore Points ========================= ATTENTION: System Restore is disabled ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (01/14/2017 10:53:36 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY) Description: SCEP Certificate enrollment initialization for WORKGROUP\DESKTOP-AA2P17R$ via https://INTC-KeyId-5e73c89aa3e902b272b9f0741f7d8730e3ec724a.microsoftaik.azure.net/templates/Aik/scep failed: GetCACaps Method: GET(156ms) Stage: GetCACaps The server name or address could not be resolved 0x80072ee7 (WinHttp: 12007 ERROR_WINHTTP_NAME_NOT_RESOLVED) Error: (01/14/2017 10:53:02 PM) (Source: SecurityCenter) (EventID: 16) (User: ) Description: Error while updating status to SECURITY_PRODUCT_STATE_ON (error %3). Error: (01/14/2017 10:52:51 PM) (Source: SecurityCenter) (EventID: 16) (User: ) Description: Error while updating status to SECURITY_PRODUCT_STATE_ON (error %3). Error: (01/14/2017 09:53:33 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DESKTOP-AA2P17R) Description: Activation of app Microsoft.Getstarted_4.2.29.0_x64__8wekyb3d8bbwe:App.AppX7mv0s3r0wanj0n66dy6vax24ps6avzvz.mca failed with error: -2144927149 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (01/14/2017 09:53:24 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DESKTOP-AA2P17R) Description: Activation of app Microsoft.MicrosoftStickyNotes_8wekyb3d8bbwe!App failed with error: -2144927149 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (01/14/2017 09:15:28 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DESKTOP-AA2P17R) Description: Activation of app Microsoft.Getstarted_4.2.29.0_x64__8wekyb3d8bbwe:App.AppX7mv0s3r0wanj0n66dy6vax24ps6avzvz.mca failed with error: -2144927149 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (01/14/2017 09:15:19 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DESKTOP-AA2P17R) Description: Activation of app Microsoft.MicrosoftStickyNotes_8wekyb3d8bbwe!App failed with error: -2144927149 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (01/14/2017 08:49:38 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DESKTOP-AA2P17R) Description: Activation of app Microsoft.Getstarted_4.2.29.0_x64__8wekyb3d8bbwe:App.AppX7mv0s3r0wanj0n66dy6vax24ps6avzvz.mca failed with error: -2144927149 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (01/14/2017 08:49:25 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DESKTOP-AA2P17R) Description: Activation of app Microsoft.MicrosoftStickyNotes_8wekyb3d8bbwe!App failed with error: -2144927149 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (01/14/2017 08:19:46 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: ShellExperienceHost.exe, version: 10.0.14393.447, time stamp: 0x5819bf85 Faulting module name: BatteryFlyoutExperience.dll, version: 10.0.14393.447, time stamp: 0x5819c00c Exception code: 0xc0000005 Fault offset: 0x00000000000155bc Faulting process id: 0xdc4 Faulting application start time: 0x01d26db26a2d5fac Faulting application path: C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe Faulting module path: C:\Windows\ShellExperiences\BatteryFlyoutExperience.dll Report Id: 2316d82a-cf18-47de-be19-a8859ad4c425 Faulting package full name: Microsoft.Windows.ShellExperienceHost_10.0.14393.693_neutral_neutral_cw5n1h2txyewy Faulting package-relative application ID: App System errors: ============= Error: (01/14/2017 11:14:48 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {8D8F4F83-3594-4F07-8369-FC3C3CAE4919} and APPID {F72671A9-012C-4725-9D2F-2A4D32D65169} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (01/14/2017 11:14:22 PM) (Source: TPM) (EventID: 15) (User: NT AUTHORITY) Description: The device driver for the Trusted Platform Module (TPM) encountered a non-recoverable error in the TPM hardware, which prevents TPM services (such as data encryption) from being used. For further help, please contact the computer manufacturer. Error: (01/14/2017 11:13:36 PM) (Source: Service Control Manager) (EventID: 7043) (User: ) Description: The Group Policy Client service did not shut down properly after receiving a preshutdown control. Error: (01/14/2017 11:10:59 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SystemEventsBroker service. Error: (01/14/2017 11:10:29 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the BrokerInfrastructure service. Error: (01/14/2017 11:08:49 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (01/14/2017 10:48:39 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {8D8F4F83-3594-4F07-8369-FC3C3CAE4919} and APPID {F72671A9-012C-4725-9D2F-2A4D32D65169} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (01/14/2017 10:46:00 PM) (Source: TPM) (EventID: 15) (User: NT AUTHORITY) Description: The device driver for the Trusted Platform Module (TPM) encountered a non-recoverable error in the TPM hardware, which prevents TPM services (such as data encryption) from being used. For further help, please contact the computer manufacturer. Error: (01/14/2017 10:45:28 PM) (Source: DCOM) (EventID: 10005) (User: NT AUTHORITY) Description: DCOM got error "1084" attempting to start the service dps with arguments "Unavailable" in order to run the server: {DDCFD26B-FEED-44CD-B71D-79487D2E5E5A} Error: (01/14/2017 10:45:28 PM) (Source: DCOM) (EventID: 10005) (User: NT AUTHORITY) Description: DCOM got error "1084" attempting to start the service dps with arguments "Unavailable" in order to run the server: {DDCFD26B-FEED-44CD-B71D-79487D2E5E5A} CodeIntegrity: =================================== Date: 2017-01-13 23:32:08.743 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\DriverStore\FileRepository\nvamwu.inf_amd64_d4715679184092a8\nvinitx.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-01-13 23:32:06.664 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\OFFICE16\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-01-06 21:07:28.412 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\DriverStore\FileRepository\nvamwu.inf_amd64_d4715679184092a8\nvinitx.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-01-06 21:07:25.095 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\OFFICE16\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-12-27 21:02:02.564 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\DriverStore\FileRepository\nvamwu.inf_amd64_d4715679184092a8\nvinitx.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-12-27 21:02:00.161 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\OFFICE16\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-12-24 23:21:41.804 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\DriverStore\FileRepository\nvamwu.inf_amd64_d4715679184092a8\nvinitx.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-12-24 23:21:39.707 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\OFFICE16\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-12-21 18:54:40.758 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\DriverStore\FileRepository\nvamwu.inf_amd64_d4715679184092a8\nvinitx.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-12-21 15:18:15.314 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\OFFICE16\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i7-6500U CPU @ 2.50GHz Percentage of memory in use: 40% Total physical RAM: 8080.85 MB Available physical RAM: 4791.33 MB Total Virtual: 16784.85 MB Available Virtual: 13447.02 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:120.61 GB) (Free:82.54 GB) NTFS Drive d: (New Volume) (Fixed) (Total:276.69 GB) (Free:269.12 GB) NTFS Drive e: (New Volume) (Fixed) (Total:257.03 GB) (Free:192.9 GB) NTFS Drive f: (New Volume) (Fixed) (Total:276.69 GB) (Free:269.71 GB) NTFS Drive g: (NasiUSB 09122992187) (Removable) (Total:28.86 GB) (Free:28.58 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 6C07A060) Partition 1: (Active) - (Size=500 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=120.6 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=276.7 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=533.7 GB) - (Type=OF Extended) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 14.9 GB) (Disk ID: D839E6E2) ======================================================== Disk: 2 (MBR Code: Windows 7 or Vista) (Size: 28.9 GB) (Disk ID: 4F69F8A6) Partition 1: (Active) - (Size=28.9 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=32 KB) - (Type=21) ==================== End of Addition.txt ============================