Additional scan result of Farbar Recovery Scan Tool (x64) Version: 28-01-2017 01 Ran by [removed] (29-01-2017 13:07:06) Running from C:\Users\[removed]\Desktop Windows 7 Home Premium Service Pack 1 (X64) (2013-10-29 15:41:40) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-612254933-2129405712-312933494-500 - Administrator - Disabled) AFAFA (S-1-5-21-612254933-2129405712-312933494-1000 - Administrator - Enabled) => C:\Users\AFAFA Authenticated User (S-1-5-21-612254933-2129405712-312933494-1008 - Limited - Enabled) Guest (S-1-5-21-612254933-2129405712-312933494-501 - Limited - Disabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Avast Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Avast Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 7-Zip 15.14 (x64) (HKLM\...\7-Zip) (Version: 15.14 - Igor Pavlov) Actron Scanning Suite (HKLM-x32\...\{7572B8A1-72A2-448E-8F69-1A3506800D67}) (Version: 4.000.0025 - Actron) Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 3.5.1.209 - Adobe Systems Incorporated) Adobe Dreamweaver CC 2015 (HKLM-x32\...\{EE2A0AA8-0386-11E5-8603-BC82F5DB1A71}) (Version: 16.1.2 - Adobe Systems Incorporated) Adobe Flash Player 24 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 24.0.0.194 - Adobe Systems Incorporated) Adobe Flash Player 24 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 24.0.0.194 - Adobe Systems Incorporated) Adobe Flash Player 24 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 24.0.0.194 - Adobe Systems Incorporated) Adobe Reader X (10.1.16) MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.1.16 - Adobe Systems Incorporated) Adobe Shockwave Player 12.2 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.2.5.195 - Adobe Systems, Inc.) Advanced SystemCare 10 (HKLM-x32\...\Advanced SystemCare_is1) (Version: 10.1.0 - IObit) ANT Drivers Installer x64 (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden ArduoPdfMerger (HKLM-x32\...\ArduoPdfMerger_is1) (Version: - hxxp://www.arduosoft.com) Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 12.3.2280 - AVAST Software) BackupManager (HKLM-x32\...\{0B0FABBA-6F8D-4087-B0FB-BF8AB57A0FEF}) (Version: 1.00.0000 - GLi) Blio (HKLM-x32\...\{74A8E1BE-D438-4C35-ABFF-3A1EAF17526E}) (Version: 2.2.8530 - K-NFB Reading Technology, Inc.) Brother MFL-Pro Suite HL-2280DW (HKLM-x32\...\{3ACCCFB3-7B17-4E9F-ACB0-46868FCD4487}) (Version: 1.1.3.0 - Brother Industries, Ltd.) Camtasia Studio 8 (HKLM-x32\...\{AF33D0D2-2627-4AC8-8473-FDBB7892129C}) (Version: 8.6.0.2079 - TechSmith Corporation) Canon IJ Scan Utility (HKLM-x32\...\Canon_IJ_Scan_Utility) (Version: - ‪Canon Inc.‬) Canon MG6300 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG6300_series) (Version: 1.00 - Canon Inc.) Common Desktop Agent (Version: 1.62.0 - OEM) Hidden Comodo Dragon (HKLM-x32\...\Comodo Dragon) (Version: 52.15.25.664 - Comodo) Comodo IceDragon (HKLM-x32\...\Comodo IceDragon) (Version: 50.0.0.2 - COMODO) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Dora's World Adventure (x32 Version: 2.2.0.95 - WildTangent) Hidden Dropbox (HKLM-x32\...\Dropbox) (Version: 17.4.33 - Dropbox, Inc.) Dropbox Update Helper (x32 Version: 1.3.59.1 - Dropbox, Inc.) Hidden Elevated Installer (x32 Version: 4.1.17.0 - Garmin Ltd or its subsidiaries) Hidden Elevated Installer (x32 Version: 4.1.19.0 - Garmin Ltd or its subsidiaries) Hidden Elevated Installer (x32 Version: 4.1.22.0 - Garmin Ltd or its subsidiaries) Hidden ESU for Microsoft Windows 7 SP1 (HKLM-x32\...\{768A6276-5822-489C-8A2B-67190F745655}) (Version: 4.1.2 - Hewlett-Packard) ESU for Microsoft Windows 7 SP1 (HKLM-x32\...\{B18BEB15-A9DA-43D7-BAE1-C6C67484C2C0}) (Version: 5.1.1 - Hewlett-Packard) Evernote v. 4.5.2 (HKLM-x32\...\{8CE152BA-1D16-11E1-867D-984BE15F174E}) (Version: 4.5.2.5904 - Evernote Corp.) File Association Manager (HKLM-x32\...\FileAssociationManager) (Version: 0.5 - Amnis Technology Ltd) Free YouTube Downloader 4.1.593 (HKLM-x32\...\{A7E19604-93AF-4611-8C9F-CE509C2B286F}_is1) (Version: - HOW Inc.) Garmin Express (x32 Version: 4.1.17.0 - Garmin Ltd or its subsidiaries) Hidden Garmin Express (x32 Version: 4.1.19.0 - Garmin Ltd or its subsidiaries) Hidden Garmin Express Tray (x32 Version: 4.1.17.0 - Garmin Ltd or its subsidiaries) Hidden Garmin Express Tray (x32 Version: 4.1.19.0 - Garmin Ltd or its subsidiaries) Hidden Garmin Express Tray (x32 Version: 4.1.22.0 - Garmin Ltd or its subsidiaries) Hidden Google Chrome (HKLM-x32\...\Google Chrome) (Version: 55.0.2883.87 - Google Inc.) Google Drive (HKLM-x32\...\{07A12123-B717-496B-B471-48AF6407B433}) (Version: 1.32.4066.7445 - Google, Inc.) Google Earth (HKLM-x32\...\{28E82311-8616-11E1-BEB0-B8AC6F97B88E}) (Version: 6.2.2.6613 - Google) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.32.7 - Google Inc.) Hidden Greenshot 1.2.8.14 (HKLM\...\Greenshot_is1) (Version: 1.2.8.14 - Greenshot) Hewlett-Packard ACLM.NET v1.1.2.0 (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden Hoyle Card Games (x32 Version: 2.2.0.95 - WildTangent) Hidden HP 3D DriveGuard (HKLM\...\{54CE68A8-4F2D-4328-B1F7-D6C720405F7F}) (Version: 4.2.9.1 - Hewlett-Packard Company) HP Application Assistant (HKLM\...\{0CE7EBAF-157D-4111-9146-057CB2A4023E}) (Version: 1.1.466.3970 - Hewlett-Packard) HP CoolSense (HKLM-x32\...\{11AF9A96-6D83-4C3B-8DCB-16EA2A358E3F}) (Version: 2.10.51 - Hewlett-Packard Company) HP Documentation (HKLM-x32\...\{B288E426-9954-451C-B811-B0F234CF0EDD}) (Version: 1.3.0.0 - Hewlett-Packard) HP Games (HKLM-x32\...\WildTangent hp Master Uninstall) (Version: 1.0.2.5 - WildTangent) HP Launch Box (HKLM\...\{5A847522-375C-4D05-BD3D-88C450CC047F}) (Version: 1.1.5 - Hewlett-Packard Company) HP MediaSmart Webcam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 4.1.3130 - Hewlett-Packard) HP MovieStore (HKLM-x32\...\{9008D736-35CA-40DB-A2BE-5F32D954E5AA}) (Version: 2.1.21096.0 - Hewlett-Packard Company) HP On Screen Display (HKLM-x32\...\{ED1BD69A-07E3-418C-91F1-D856582581BF}) (Version: 1.3.5 - Hewlett-Packard Company) HP Power Manager (HKLM-x32\...\{D8BCE5B9-67CF-4F3F-93AE-3ACC754C72EB}) (Version: 1.4.7 - Hewlett-Packard Company) HP Quick Launch (HKLM-x32\...\{E5823036-6F09-4D0A-B05C-E2BAA129288A}) (Version: 3.0.6 - Hewlett-Packard Company) HP Security Assistant (HKLM\...\{ED6CD3AC-616B-4B20-BCF3-6E637B92A5AD}) (Version: 3.0.4 - Hewlett-Packard Company) HP Security Assistant (HKLM\...\{F9DF0B5D-554B-45D2-8698-7C467FAF4BCA}) (Version: 2.0.2 - Hewlett-Packard Company) HP Setup (HKLM-x32\...\{F5E7D9AF-60F6-4A30-87E3-4EA94D322CE1}) (Version: 9.0.15109.3899 - Hewlett-Packard Company) HP Setup Manager (HKLM-x32\...\{AE856388-AFAD-4753-81DF-D96B19D0A17C}) (Version: 1.2.14901.3869 - Hewlett-Packard Company) HP Software Framework (HKLM-x32\...\{6DE80866-EF92-47C1-80F5-1EA83B7A0AA2}) (Version: 4.5.4.1 - Hewlett-Packard Company) HP Software Framework (HKLM-x32\...\{962CB079-85E6-405F-8704-1C62365AE46F}) (Version: 4.5.10.1 - Hewlett-Packard Company) HP Support Assistant (HKLM-x32\...\{61EB474B-67A6-47F4-B1B7-386851BAB3D0}) (Version: 8.0.29.6 - Hewlett-Packard Company) HP Support Assistant (HKLM-x32\...\{78E2C850-ADA6-420D-BA35-2F4A9BE733CC}) (Version: 8.2.8.25 - HP) HP Support Solutions Framework (HKLM-x32\...\{5F084DD8-AF2C-4004-9C92-820C32E4BD55}) (Version: 12.2.8.17 - HP) HP Support Solutions Framework (HKLM-x32\...\{F6A11738-3EE4-4573-AEA5-6CD5D491C167}) (Version: 12.0.30.81 - Hewlett-Packard Company) IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6381.0 - IDT) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.0.0.1351 - Intel Corporation) Intel(R) OpenCL CPU Runtime (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2626 - Intel Corporation) Intel(R) PROSet/Wireless for Bluetooth(R) + High Speed (HKLM\...\{BEE86606-EFB5-4353-9F34-29E0C59CDCFA}) (Version: 15.2.0.0284 - Intel Corporation) Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (HKLM\...\{F0932859-AA60-459E-B843-0BDECA34E2C7}) (Version: 2.0.0.0086 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.0.0.1032 - Intel Corporation) Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.0.199 - Intel Corporation) Intel(R) WiDi (HKLM-x32\...\{93F34C5C-ACAA-48F3-9B26-70359A117F12}) (Version: 3.0.12.0 - Intel Corporation) Intel(R) Wireless Display (HKLM\...\{28EF7372-9087-4AC3-9B9F-D9751FCDF830}) (Version: - ) Intel(R) Wireless Music device driver (HKLM\...\{4169B8AC-D144-4E38-A9CA-637EA44129ED}) (Version: 1.5.5310.0 - Intel Corporation) Intel® PROSet/Wireless WiFi Software (HKLM\...\{181BBF43-CA17-4E1A-A78D-81E67A57B8A4}) (Version: 15.02.0000.1258 - Intel Corporation) Intel® Trusted Connect Service Client (HKLM\...\{6199B534-A1B6-46ED-873B-97B0ECF8F81E}) (Version: 1.23.216.0 - Intel Corporation) IObit Apps Toolbar v10.9 (HKLM-x32\...\{F24EACD5-A33B-4DBB-ABCD-94AB54C04EC1}) (Version: 10.9 - Spigot, Inc.) <==== ATTENTION IObit Uninstaller (HKLM-x32\...\IObitUninstall) (Version: 6.1.0.510 - IObit) Java 8 Update 111 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180111F0}) (Version: 8.0.1110.14 - Oracle Corporation) Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Logitech SetPoint 6.67 (HKLM\...\sp6) (Version: 6.67.83 - Logitech) Macrorit Disk Partition Expert Free 2016 (HKLM-x32\...\Macrorit_MDE) (Version: 2016 - Macrorit Inc.) Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes) Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office Professional Plus 2007 (HKLM-x32\...\PROPLUS) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Professional Plus 2013 - en-us (HKLM\...\ProPlusRetail - en-us) (Version: 15.0.4893.1002 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-612254933-2129405712-312933494-1000\...\OneDriveSetup.exe) (Version: 17.3.6720.1207 - Microsoft Corporation) Microsoft SAPI 5.1- DO NOT REMOVE (HKLM-x32\...\{DF0BEF15-A82E-40C5-A051-DE0B7F009895}) (Version: 5.1.0.0 - ReadPlease Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Text-to-Speech Engine 4.0 (English) (HKLM-x32\...\MSTTS) (Version: - ) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Mozilla Firefox 50.1.0 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 50.1.0 (x86 en-US)) (Version: 50.1.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 50.1.0 - Mozilla) MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4885.1001 - Microsoft Corporation) Hidden Office 15 Click-to-Run Licensing Component (Version: 15.0.4885.1001 - Microsoft Corporation) Hidden Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4885.1001 - Microsoft Corporation) Hidden opensource (x32 Version: 1.0.14960.3876 - Your Company Name) Hidden PDFlite 0.11.2.0 (HKLM-x32\...\PDFlite) (Version: 0.11.2.0 - Amnis Technology Ltd) PlayReady PC Runtime x86 (HKLM-x32\...\{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}) (Version: 1.3.0 - Microsoft Corporation) PrivDog (HKLM-x32\...\PrivDog) (Version: 1.8.0.15 - privdog.com) ReadingBar for Internet Explorer - 2.0 - (remove only) (HKLM-x32\...\ReadBar) (Version: - ) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.48.823.2011 - Realtek) Realtek PCIE Card Reader (HKLM-x32\...\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.1.7601.29005 - Realtek Semiconductor Corp.) SafeZone Stable 1.51.2220.62 (x32 Version: 1.51.2220.62 - Avast Software) Hidden Samsung Easy Document Creator (HKLM-x32\...\Samsung Easy Document Creator) (Version: 1.06.46 (10/30/2014) - Samsung Electronics Co., Ltd.) Samsung Easy Printer Manager (HKLM-x32\...\Samsung Easy Printer Manager) (Version: 1.05.66.00(10/30/2014) - Samsung Electronics Co., Ltd.) Samsung M288x Series (HKLM-x32\...\Samsung M288x Series) (Version: 1.13 (12/16/2014) - Samsung Electronics Co., Ltd.) Samsung Magician (HKLM-x32\...\{29AE3F9F-7158-4ca7-B1ED-28A73ECDB215}_is1) (Version: 4.5.1 - Samsung Electronics) Samsung Network PC Fax (HKLM-x32\...\Samsung Network PC Fax) (Version: 1.11.14 (11/4/2014) - Samsung Electronics Co., Ltd.) Samsung OCR Software (HKLM-x32\...\Samsung OCR Software) (Version: 1.01.10 (6/20/2014) - Samsung Electronics Co., Ltd.) Samsung Printer Diagnostics (HKLM-x32\...\Samsung Printer Diagnostics) (Version: 1.0.1.6.02 - Samsung Electronics Co., Ltd.) Samsung Printer Live Update (HKLM-x32\...\Samsung Printer Live Update) (Version: 1.01.00:04(2013-04-22) - Samsung Electronics Co., Ltd.) Samsung Scan Process Machine (x32 Version: 1.03.05.18 - Samsung Electronics Co., Ltd.) Hidden Skype™ 7.0 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.) Skype™ 7.27 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.27.101 - Skype Technologies S.A.) Smart Defrag 4 (HKLM-x32\...\Smart Defrag 4_is1) (Version: 4.3 - IObit) swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.3.29.0 - Synaptics Incorporated) TeamViewer 11 (HKLM-x32\...\TeamViewer) (Version: 11.0.66695 - TeamViewer) Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Validity WBF DDK (HKLM\...\{DA83578A-7DB2-4CF6-9453-CF24C7917AB8}) (Version: 4.3.301.0 - Validity Sensors, Inc.) View User's Guide (HKLM-x32\...\View User Guide) (Version: 3.60.45.0 - ) WildTangent Games App (HP Games) (x32 Version: 4.0.5.32 - WildTangent) Hidden Windows Driver Package - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\...\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.) Windows Driver Package - FTDI CDM Driver Package (07/12/2010 2.08.02) (HKLM\...\7A3873EEB4807FBDE9271D1C3DA50F100D5B8A7D) (Version: 07/12/2010 2.08.02 - FTDI) Windows Driver Package - FTDI CDM Driver Package (07/12/2010 2.08.02) (HKLM\...\C6554C9DFBD939292E343034D2836B952A9D4B66) (Version: 07/12/2010 2.08.02 - FTDI) Windows Driver Package - Silicon Labs Software (DSI_SiUSBXp_3_1) USB (02/06/2007 3.1) (HKLM\...\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software) Windows Driver Package - SPX Service Solutions, Inc (usbser) Ports (01/07/2010 2.0.0) (HKLM\...\BA81E6D589C849EA72D1C2CF16057B36C83BAEA8) (Version: 01/07/2010 2.0.0 - SPX Service Solutions, Inc) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation) Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation) WinHTTrack Website Copier 3.48-22 (x64) (HKLM\...\WinHTTrack Website Copier_is1) (Version: 3.48.22 - HTTrack) Wondershare Video Converter Ultimate(Build 8.5.7.1) (HKLM-x32\...\Wondershare Video Converter Ultimate_is1) (Version: 8.5.7.1 - Wondershare Software) YouTube Free Downloader (HKLM-x32\...\YouTube Free Downloader) (Version: - ) Zoom (HKU\S-1-5-21-612254933-2129405712-312933494-1000\...\ZoomUMX) (Version: 3.5 - Zoom Video Communications, Inc.) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-612254933-2129405712-312933494-1000_Classes\CLSID\{162C6FB5-44D3-435B-903D-E613FA093FB5}\InprocServer32 -> C:\Users\AFAFA\AppData\Local\Microsoft\OneDrive\17.3.6720.1207\amd64\FileCoAuthLib64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-612254933-2129405712-312933494-1000_Classes\CLSID\{e8c77137-e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {03FD6142-8778-45C4-B207-38D80FD16A7C} - System32\Tasks\{0F098EA3-0A19-4DF2-979C-8646A72FF716} => pcalua.exe -a C:\Users\AFAFA\Downloads\jre-8u60-windows-i586.exe -d C:\Users\AFAFA\Downloads Task: {128D2DE9-EB89-4F79-926E-47A12FF16A00} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2016-11-01] (Microsoft Corporation) Task: {180DE644-BD41-4C52-B66D-B55D50B350F2} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2016-02-18] (Hewlett-Packard Company) Task: {23A30DAE-812C-4D5D-A21C-6A88AC51A28E} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-07-26] (Dropbox, Inc.) Task: {2C91CA8E-A98A-4971-95FB-2E6B1ADDB1AA} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2016-08-29] (AVAST Software) Task: {32CC136A-AAB6-4911-A80D-3EB4A421C349} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2016-12-07] (HP Inc.) Task: {3D9F036C-1834-4425-8533-8DD10DF1F4C0} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-04-22] (Adobe Systems Incorporated) Task: {4846E2D8-C86A-4343-9A28-DFE9B4863951} - System32\Tasks\Driver Booster SkipUAC (AFAFA) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe Task: {4FBA33BB-645E-4FBE-A4C8-457A2366E9A1} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.) Task: {605690A2-BB6E-4276-866F-E1F41D0BFF3F} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-01-16] (Adobe Systems Incorporated) Task: {7444D228-9157-4ABC-BE04-430F77900732} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2016-11-01] (Microsoft Corporation) Task: {769D3D38-650D-4A61-8390-B7069E9F0BD1} - System32\Tasks\{0ED743AF-110F-438F-857A-07D0CDEE5031} => pcalua.exe -a "C:\Users\AFAFA\Documents\Jakes Docs from F\Program Downloads\camtasia.exe" -d "C:\Users\AFAFA\Documents\Jakes Docs from F\Program Downloads" Task: {7E782F97-790A-4396-864A-EB81EA330A0D} - System32\Tasks\SafeZone scheduled Autoupdate 1465015902 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2016-09-06] (Avast Software) Task: {83F4F359-8382-4FDD-A9E4-14ED0F84B614} - System32\Tasks\ASC10_PerformanceMonitor => C:\Program Files (x86)\IObit\Advanced SystemCare\Monitor.exe [2016-12-05] (IObit) Task: {8FC3D321-DE74-431B-B531-5C521E39C83C} - System32\Tasks\{54C2B55B-7BBF-42BE-8B8F-1537BA58E15F} => Chrome.exe hxxps://ui.skype.com/ui/0/7.30.80.105/en/go/help.faq.installer?LastError=1601 Task: {9178A039-F275-4A6F-AE4A-A8398216DFAE} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-07-26] (Dropbox, Inc.) Task: {9EF1141A-F67E-45A1-9FCC-A7977A22E6B7} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.) Task: {AAEE6DFB-4054-4160-B1A3-CE34F8E56E30} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [2016-02-18] (Hewlett-Packard) Task: {BA0668E4-1EA3-4046-A185-92213509C5B6} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2016-11-01] (Microsoft Corporation) Task: {BCE2CA23-F8B0-4246-A498-5C3AB9C92071} - System32\Tasks\ASC10_SkipUac_Temp => C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe [2016-12-20] (IObit) Task: {C8B8EE49-13E3-4CCB-9656-E9664BC24DF2} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2016-11-01] (Microsoft Corporation) Task: {C925C91A-203B-477A-A01C-254DF050C1C5} - System32\Tasks\{F15BC9CB-A46D-4729-A974-4D40197F6127} => pcalua.exe -a C:\Users\AFAFA\Downloads\sp61617.exe -d C:\Users\AFAFA\Downloads Task: {C9833F61-0DEF-4E6B-A9C1-2B67D9D5225B} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2017-01-27] (AVAST Software) Task: {E1EEF97C-EDD4-4D8F-830E-FD620DDAB7A6} - System32\Tasks\{1FDE7613-8D57-4223-B70C-1477649384DB} => Chrome.exe hxxps://ui.skype.com/ui/0/7.30.80.105/en/go/help.faq.installer?LastError=1601 Task: {E6384EA4-6ABB-4B17-9D8A-BCFD3E5FE255} - System32\Tasks\MirageAgent => C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\YCMMirage.exe [2010-07-30] (CyberLink) Task: {E74DC8E6-C6C9-47F4-A85A-136E7F15FD57} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2016-02-18] (Hewlett-Packard Company) Task: {F3C79FC3-9D72-4BFF-AB51-744E0A66F2E2} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Active Health Launcher => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.exe [2016-02-17] (Hewlett-Packard) Task: {F7BC3483-CE19-4B15-8255-3A926775A1B3} - System32\Tasks\Uninstaller_SkipUac_AFAFA => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [2016-12-15] (IObit) Task: {F7E793C6-5E1A-43F8-8348-DAD308D8EB48} - System32\Tasks\ASC10_SkipUac_AFAFA => C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe [2016-12-20] (IObit) Task: {FB84738C-82E5-4722-905F-5A974DEBD7C2} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_24_0_0_194_pepper.exe [2017-01-16] (Adobe Systems Incorporated) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\Adobe Flash Player PPAPI Notifier.job => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_24_0_0_194_pepper.exe Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Task: C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) Shortcut: C:\Users\AFAFA\Desktop\HP Quad Core Docs\HPUser\Favorites\NCH Software Download Site.lnk -> hxxp://www.nch.com.au/index.htm ==================== Loaded Modules (Whitelisted) ============== 2014-01-23 22:27 - 2013-08-26 07:12 - 00087040 _____ () C:\Windows\System32\redmonnt.dll 2015-04-26 15:35 - 2014-10-30 07:32 - 00029184 _____ () C:\Windows\System32\ssa7mlm.dll 2016-06-10 06:12 - 2016-05-24 08:51 - 00116416 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll 2016-03-25 15:54 - 2015-02-27 13:38 - 00721263 _____ () C:\Windows\SysWOW64\WSCM64.dll 2016-01-22 12:55 - 2016-01-22 12:55 - 00553136 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll 2016-12-17 07:28 - 2016-12-17 07:28 - 01678560 _____ () C:\Users\AFAFA\AppData\Local\Microsoft\OneDrive\17.3.6720.1207\amd64\ClientTelemetry.dll 2012-08-14 14:15 - 2011-12-16 15:37 - 00128280 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe 2016-05-02 18:50 - 2005-04-21 23:36 - 00143360 _____ () C:\Windows\system32\BrSNMP64.dll 2016-08-29 15:48 - 2016-08-29 15:48 - 00169064 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll 2016-08-29 15:48 - 2016-08-29 15:48 - 00482928 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll 2017-01-29 12:09 - 2017-01-29 12:09 - 04377600 _____ () C:\Program Files\AVAST Software\Avast\defs\17012901\algo.dll 2016-12-20 19:04 - 2016-08-18 18:43 - 00442144 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare\madExcept_.bpl 2016-12-20 19:04 - 2016-08-18 18:43 - 00210720 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare\madBasic_.bpl 2016-12-20 19:04 - 2016-08-18 18:43 - 00059680 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare\madDisAsm_.bpl 2016-12-20 19:03 - 2015-12-28 13:50 - 00899872 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare\webres.dll 2016-12-20 19:03 - 2016-11-01 10:11 - 00078624 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare\GetProcessDLL.dll 2016-07-25 17:23 - 2016-05-24 10:21 - 08909504 _____ () C:\Program Files\Microsoft Office 15\root\Office15\1033\GrooveIntlResource.dll 2012-08-14 14:15 - 2011-12-16 13:39 - 01198872 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll 2016-12-20 19:04 - 2016-06-21 19:30 - 00442144 _____ () C:\Program Files (x86)\IObit\IObit Uninstaller\madExcept_.bpl 2016-12-20 19:04 - 2016-06-21 19:29 - 00210720 _____ () C:\Program Files (x86)\IObit\IObit Uninstaller\madBasic_.bpl 2016-12-20 19:04 - 2016-06-21 19:29 - 00059680 _____ () C:\Program Files (x86)\IObit\IObit Uninstaller\madDisAsm_.bpl 2016-12-20 19:04 - 2015-12-28 13:50 - 00899872 _____ () C:\Program Files (x86)\IObit\IObit Uninstaller\webres.dll 2016-12-20 19:04 - 2016-09-26 13:59 - 00631072 _____ () C:\Program Files (x86)\IObit\IObit Uninstaller\ProductStatistics.dll 2016-12-20 19:03 - 2016-09-26 13:59 - 00631072 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare\ProductStatistics.dll 2016-06-30 16:18 - 2016-06-30 16:18 - 48936448 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2016-12-20 19:03 - 2016-12-20 16:36 - 01362720 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare\Scan.dll 2016-06-18 13:09 - 2016-06-18 13:09 - 00172032 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\5a8eeeddc97028a9f94d0518c22f4c2c\IsdiInterop.ni.dll 2012-08-14 14:18 - 2011-11-29 23:00 - 00059392 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll 2016-12-17 07:28 - 2016-12-17 07:28 - 01244376 _____ () C:\Users\AFAFA\AppData\Local\Microsoft\OneDrive\17.3.6720.1207\ClientTelemetry.dll 2016-12-14 18:29 - 2016-12-08 02:29 - 01829208 _____ () C:\Program Files (x86)\Google\Chrome\Application\55.0.2883.87\libglesv2.dll 2016-12-14 18:29 - 2016-12-08 02:29 - 00085848 _____ () C:\Program Files (x86)\Google\Chrome\Application\55.0.2883.87\libegl.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\ProgramData\Temp:8C35AEA7 [129] ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) IE trusted site: HKU\S-1-5-21-612254933-2129405712-312933494-1000\...\cricketwireless.com -> cricketwireless.com IE trusted site: HKU\S-1-5-21-612254933-2129405712-312933494-1000\...\wheatgrassgreenhouse.com -> hxxp://www.wheatgrassgreenhouse.com IE trusted site: HKU\S-1-5-21-612254933-2129405712-312933494-1000\...\wmich.edu -> hxxps://www.wmich.edu IE restricted site: HKU\S-1-5-21-612254933-2129405712-312933494-1000\...\008i.com -> 008i.com IE restricted site: HKU\S-1-5-21-612254933-2129405712-312933494-1000\...\008k.com -> 008k.com IE restricted site: HKU\S-1-5-21-612254933-2129405712-312933494-1000\...\00hq.com -> 00hq.com IE restricted site: HKU\S-1-5-21-612254933-2129405712-312933494-1000\...\0190-dialers.com -> 0190-dialers.com IE restricted site: HKU\S-1-5-21-612254933-2129405712-312933494-1000\...\01i.info -> 01i.info IE restricted site: HKU\S-1-5-21-612254933-2129405712-312933494-1000\...\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com IE restricted site: HKU\S-1-5-21-612254933-2129405712-312933494-1000\...\05p.com -> 05p.com IE restricted site: HKU\S-1-5-21-612254933-2129405712-312933494-1000\...\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com IE restricted site: HKU\S-1-5-21-612254933-2129405712-312933494-1000\...\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com IE restricted site: HKU\S-1-5-21-612254933-2129405712-312933494-1000\...\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com IE restricted site: HKU\S-1-5-21-612254933-2129405712-312933494-1000\...\0calories.net -> 0calories.net IE restricted site: HKU\S-1-5-21-612254933-2129405712-312933494-1000\...\0cj.net -> 0cj.net IE restricted site: HKU\S-1-5-21-612254933-2129405712-312933494-1000\...\0scan.com -> 0scan.com IE restricted site: HKU\S-1-5-21-612254933-2129405712-312933494-1000\...\1-britney-spears-nude.com -> 1-britney-spears-nude.com IE restricted site: HKU\S-1-5-21-612254933-2129405712-312933494-1000\...\1-domains-registrations.com -> 1-domains-registrations.com IE restricted site: HKU\S-1-5-21-612254933-2129405712-312933494-1000\...\1-se.com -> 1-se.com IE restricted site: HKU\S-1-5-21-612254933-2129405712-312933494-1000\...\1001movie.com -> 1001movie.com IE restricted site: HKU\S-1-5-21-612254933-2129405712-312933494-1000\...\1001night.biz -> 1001night.biz IE restricted site: HKU\S-1-5-21-612254933-2129405712-312933494-1000\...\100gal.net -> 100gal.net IE restricted site: HKU\S-1-5-21-612254933-2129405712-312933494-1000\...\100sexlinks.com -> 100sexlinks.com There are 4788 more sites. ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-13 21:34 - 2015-12-08 21:23 - 00000872 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ::1 localhost ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-612254933-2129405712-312933494-1000\Control Panel\Desktop\\Wallpaper -> DNS Servers: 172.16.134.201 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == MSCONFIG\Services: AdvancedSystemCareService9 => 2 MSCONFIG\Services: AGSService => 3 MSCONFIG\Services: BBSvc => 2 MSCONFIG\Services: BrYNSvc => 3 MSCONFIG\Services: CLPSLauncher => 2 MSCONFIG\Services: cmdAgent => 2 MSCONFIG\Services: cmdvirth => 3 MSCONFIG\Services: dbupdate => 2 MSCONFIG\Services: dbupdatem => 3 MSCONFIG\Services: DbxSvc => 3 MSCONFIG\Services: defragsvc => 2 MSCONFIG\Services: DiagTrack => 3 MSCONFIG\Services: DragonUpdater => 3 MSCONFIG\Services: EaseUS Agent => 3 MSCONFIG\Services: GamesAppService => 3 MSCONFIG\Services: GeekBuddyRSP => 2 MSCONFIG\Services: IceDragonUpdater => 2 MSCONFIG\Services: LBTServ => 2 MSCONFIG\Services: LiveUpdateSvc => 2 MSCONFIG\Services: MBAMService => 2 MSCONFIG\Services: MozillaMaintenance => 2 MSCONFIG\Services: RasAuto => 3 MSCONFIG\Services: RasMan => 3 MSCONFIG\Services: SCM_Service => 2 MSCONFIG\Services: SensrSvc => 3 MSCONFIG\Services: SessionEnv => 3 MSCONFIG\Services: SkypeUpdate => 3 MSCONFIG\Services: TapiSrv => 2 MSCONFIG\Services: TermService => 2 MSCONFIG\Services: TheScreenSnapshotService => 3 MSCONFIG\Services: WAS => 2 MSCONFIG\Services: WatAdminSvc => 2 MSCONFIG\Services: WbioSrvc => 2 MSCONFIG\Services: WinRM => 3 MSCONFIG\Services: wuauserv => 3 MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^NETGEAR WG111v2 Smart Wizard.lnk => C:\Windows\pss\NETGEAR WG111v2 Smart Wizard.lnk.CommonStartup MSCONFIG\startupfolder: C:^Users^AFAFA^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^PdaNet Desktop.lnk => C:\Windows\pss\PdaNet Desktop.lnk.Startup MSCONFIG\startupfolder: C:^Users^AFAFA^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Send to OneNote.lnk => C:\Windows\pss\Send to OneNote.lnk.Startup MSCONFIG\startupreg: Adobe Creative Cloud => "c:\program files (x86)\adobe\adobe creative cloud\acc\creative cloud.exe" --showwindow=false --onosstartup=true MSCONFIG\startupreg: Advanced SystemCare 9 => MSCONFIG\startupreg: BrStsMon00 => C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe /AUTORUN MSCONFIG\startupreg: Dropbox => "C:\Program Files (x86)\Dropbox\Client\Dropbox.exe" /systemstartup MSCONFIG\startupreg: EEDSpeedLauncher => rundll32.exe c:\windows\system32\eed_ec.dll,speedlauncher MSCONFIG\startupreg: GoogleDriveSync => "C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{30619996-2116-4374-B153-1BE5ECBA8500}] => C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{49C65AEB-C563-4FFB-A392-B0A1EFC38296}] => C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe FirewallRules: [{55D1C4B7-94F9-4DB4-B2D7-7C997BFF26C2}] => LPort=2869 FirewallRules: [{C70AFE95-889D-49E3-9D77-0B295105F0EA}] => LPort=1900 FirewallRules: [{567ECD1E-9340-4BDE-B2AF-6CA619B81F73}] => C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe FirewallRules: [{D5798595-B761-4611-A762-EAD6CC5FEA60}] => C:\Program Files (x86)\Windows Live\Mesh\MOE.exe FirewallRules: [{AFCB6D5A-7715-457A-99FD-1F09956286BE}] => C:\Program Files (x86)\Hewlett-Packard\MediaSmart\RoxioNow\RNow.exe FirewallRules: [{77C30E2D-6696-420B-8671-63F05A462038}] => C:\Program Files (x86)\Hewlett-Packard\MediaSmart\RoxioNow\RNow.exe FirewallRules: [{09BD30C7-ED3B-4EA9-B862-29749CF45D8A}] => C:\Program Files (x86)\Hewlett-Packard\MediaSmart\RoxioNow\RNow.exe FirewallRules: [{E0F94D39-DC4A-4627-870D-48F17D47BBE4}] => C:\Program Files (x86)\Hewlett-Packard\MediaSmart\RoxioNow\RNow.exe FirewallRules: [{4E4DFE71-4E45-49B5-A41F-3C966E7BAB85}] => C:\Program Files (x86)\Hewlett-Packard\MediaSmart\RoxioNow\IndivDRM.exe FirewallRules: [{8315BFBD-0204-4339-A402-64B6A6D5153B}] => C:\Program Files (x86)\Hewlett-Packard\MediaSmart\RoxioNow\IndivDRM.exe FirewallRules: [{D0FB9EC1-7D7B-412D-A7AB-900CF7538138}] => C:\Program Files (x86)\Hewlett-Packard\MediaSmart\RoxioNow\IndivDRM.exe FirewallRules: [{EA3B0FB0-C35D-4821-B53D-3E97A988C63B}] => C:\Program Files (x86)\Hewlett-Packard\MediaSmart\RoxioNow\IndivDRM.exe FirewallRules: [{9697AC5E-D15C-426D-B0DD-C4E87CDACB01}] => C:\Program Files (x86)\Intel Corporation\Intel WiDi\WiDiApp.exe FirewallRules: [TCP Query User{E5D78840-B923-4651-972C-A46C30A1339B}C:\program files (x86)\java\jre7\bin\javaw.exe] => C:\program files (x86)\java\jre7\bin\javaw.exe FirewallRules: [UDP Query User{40FBFE65-E5A0-4EDD-BAF3-21B96686AEB6}C:\program files (x86)\java\jre7\bin\javaw.exe] => C:\program files (x86)\java\jre7\bin\javaw.exe FirewallRules: [{EC655A20-E3CD-4463-AC05-DA9E964A978D}] => C:\Windows\twain_32\Samsung\SLM288x\ScanCDLM\ScanCDLM.exe FirewallRules: [{F02FBB23-7905-4BAB-9D7B-3D14DEBD0CFA}] => C:\Windows\twain_32\Samsung\SLM288x\ScanCDLM\ScanCDLM.exe FirewallRules: [{44C96DEB-0236-4621-A60A-247718A52465}] => C:\Program Files (x86)\Samsung\Easy Document Creator\EDC.exe FirewallRules: [{C217275B-17CB-4399-B4F1-116116DBCC0D}] => C:\Program Files (x86)\Samsung\Easy Document Creator\EDC.exe FirewallRules: [TCP Query User{9284C051-C1CF-457D-8E84-6560E1CC539F}C:\windows\system32\mmc.exe] => C:\windows\system32\mmc.exe FirewallRules: [UDP Query User{9708DC69-D544-448D-B97C-4DD1891A8B11}C:\windows\system32\mmc.exe] => C:\windows\system32\mmc.exe FirewallRules: [{FA92110E-7AEF-4E10-9AC2-118D59B62D7A}] => C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{71B3242C-55E4-4130-AD79-43E641989E8E}] => C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [TCP Query User{C6BD9370-85AA-4ADB-9B4B-AC6F4A7C19A6}C:\program files (x86)\samsung\easy document creator\edc.exe] => C:\program files (x86)\samsung\easy document creator\edc.exe FirewallRules: [UDP Query User{04C8EAC4-3147-4D87-9E86-03BBEE4DE0C9}C:\program files (x86)\samsung\easy document creator\edc.exe] => C:\program files (x86)\samsung\easy document creator\edc.exe FirewallRules: [TelnetServer-TlntSvr-TCP-In] => %systemroot%\system32\tlntsvr.exe FirewallRules: [TelnetServer-Tlntadmn-RPC-In] => %systemroot%\system32\tlntsvr.exe FirewallRules: [SNMP-In-UDP] => %SystemRoot%\system32\snmp.exe FirewallRules: [SNMP-Out-UDP] => %SystemRoot%\system32\snmp.exe FirewallRules: [SNMP-In-UDP-NoScope] => %SystemRoot%\system32\snmp.exe FirewallRules: [SNMP-Out-UDP-NoScope] => %SystemRoot%\system32\snmp.exe FirewallRules: [MSMQ-In-TCP] => %systemroot%\system32\mqsvc.exe FirewallRules: [MSMQ-Out-TCP] => %systemroot%\system32\mqsvc.exe FirewallRules: [MSMQ-In-UDP] => %systemroot%\system32\mqsvc.exe FirewallRules: [MSMQ-Out-UDP] => %systemroot%\system32\mqsvc.exe FirewallRules: [WCF-NetTcpActivator-In-TCP-64bit] => %systemroot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe FirewallRules: [{6786270F-B6E1-43E8-90B8-19E44F46DD9A}] => C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{4B754107-4270-4786-8709-1DBD8F7C7976}] => C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{5E8EE431-F68F-42FA-8EA8-668B6A96553F}] => C:\Windows\twain_32\Samsung\SLM288x\ScanCDLM\ScanCDLM.exe FirewallRules: [{1855BDB4-D807-404F-9BAF-80903E5BA3A8}] => C:\Windows\twain_32\Samsung\SLM288x\ScanCDLM\ScanCDLM.exe FirewallRules: [{EC40E100-7E15-4412-946B-4719CCB9CDE1}] => LPort=54925 FirewallRules: [{55CE708B-E2B0-45DB-B21B-4D2799C4097B}] => C:\Program Files\Microsoft Office 15\root\Office15\outlook.exe FirewallRules: [{5736B31D-F93E-4B40-B2D3-F1A0FD3A9476}] => C:\Program Files\Microsoft Office 15\root\Office15\Lync.exe FirewallRules: [{3E376683-0423-46E6-9BB6-90B5FCB3F449}] => C:\Program Files\Microsoft Office 15\root\Office15\UcMapi.exe FirewallRules: [{4F13432C-BBEA-496A-8E30-C76A5AEF8EF0}] => LPort=8317 FirewallRules: [{A85F198F-5785-4350-9992-09A2FF45A21F}] => C:\Program Files\Microsoft Office 15\root\Office15\Lync.exe FirewallRules: [{174A1CEE-A2CF-4497-AA3F-E62A1C880069}] => C:\Program Files\Microsoft Office 15\root\Office15\UcMapi.exe FirewallRules: [{80DDFB9F-4868-4F7A-B9C6-BC08049D6FAB}] => C:\Program Files (x86)\Samsung\Easy Printer Manager\IDS.Application.exe FirewallRules: [{943D022D-606C-43AF-B8EF-4D8E6E629470}] => C:\Program Files (x86)\Samsung\Easy Printer Manager\OrderSupplies.exe FirewallRules: [{F2A3A250-CBB7-4F45-8737-B075FFF7161A}] => C:\Program Files (x86)\Samsung\Easy Printer Manager\IDSAlert.exe FirewallRules: [{FA1B4236-CED9-47A5-BC37-9B0E00B93CFC}] => C:\Program Files (x86)\Samsung\Easy Printer Manager\uninstall.exe FirewallRules: [{714317A4-BA31-4D94-9506-B61AE9F1696B}] => C:\Program Files (x86)\Samsung\Easy Printer Manager\CDAS2PC\CDAS2PC.exe FirewallRules: [{EB3B24E2-4B6A-4745-A815-AF65B6C892D5}] => C:\Program Files (x86)\Samsung\Easy Printer Manager\CDAS2PC\ScanProcess.exe FirewallRules: [{19F56E1B-6AF0-47C0-B8EA-C3F0CFA7E0CB}] => C:\Program Files (x86)\Samsung\Easy Printer Manager\CDAS2PC\Scan2PCNotify.exe FirewallRules: [{02CEA05F-382B-41F8-A68B-94088E4ADD55}] => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe FirewallRules: [{98AE380D-98BE-48C6-A664-9F8CE13C4669}] => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe FirewallRules: [TCP Query User{241942A0-4F92-410D-B3A5-D580ABBE3626}C:\program files\common files\common desktop agent\cdasrv.exe] => C:\program files\common files\common desktop agent\cdasrv.exe FirewallRules: [UDP Query User{CB6BCFF5-3E5E-4100-85FF-7202F88751F5}C:\program files\common files\common desktop agent\cdasrv.exe] => C:\program files\common files\common desktop agent\cdasrv.exe FirewallRules: [{73020CCA-1247-4873-89D1-28345FD946A2}] => C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{664B8B06-623C-4A65-98B0-E6EFB539EB46}] => C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{CD5BADC5-AF29-4C95-AE29-1F3022AECE45}] => C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{1620B39F-FB7B-4FA9-A0FA-4CB7EBBF914D}] => C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{D839E9C3-4137-4077-8660-B4A79756AED5}] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{79AF91DA-EDB4-4273-9943-A533F24D3EC4}] => C:\Program Files (x86)\IObit\Advanced SystemCare\Surfing Protection\FFNativeMessage.exe FirewallRules: [{38CD7D81-CEBB-4862-938C-0E63194131DA}] => C:\Program Files (x86)\IObit\Advanced SystemCare\Surfing Protection\FFNativeMessage.exe FirewallRules: [TCP Query User{3A185ADB-01BA-4FCE-B49A-1666117CA697}C:\program files (x86)\samsung\easy printer manager\ids.application.exe] => C:\program files (x86)\samsung\easy printer manager\ids.application.exe FirewallRules: [UDP Query User{BB23453D-9505-46F4-8E50-8793636DAE3C}C:\program files (x86)\samsung\easy printer manager\ids.application.exe] => C:\program files (x86)\samsung\easy printer manager\ids.application.exe FirewallRules: [{6A564CF7-3408-4FB0-8B30-8AFDE1C1C327}] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe FirewallRules: [{E8B280F7-8D00-4833-8134-2E4EA3CA8FE8}] => C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe ==================== Restore Points ========================= 01-01-2017 00:00:03 Scheduled Checkpoint 10-01-2017 18:24:37 Scheduled Checkpoint 14-01-2017 22:27:04 Garmin Express 22-01-2017 09:27:21 Scheduled Checkpoint ==================== Faulty Device Manager Devices ============= Name: Simultaneous Dual-Band Wireless-AC Gigabit Router Description: Simultaneous Dual-Band Wireless-AC Gigabit Router Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (01/29/2017 12:17:13 PM) (Source: HP Active Health) (EventID: 91) (User: ) Description: Unhandled Exception. Application will terminate immediately. System.ArgumentNullException: Value cannot be null. at System.Threading.Monitor.Enter(Object obj) at HP.ActiveHealth.Commons.Security.HashStore.Validate(String filePath) at HP.ActiveHealth.Core.Program..ctor(String[] args, Boolean mustCheckSignature, Boolean validateIni) at HP.ActiveHealth.Core.ActiveHealthMain.Main(String[] args) Error: (01/29/2017 12:04:16 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Error: (01/29/2017 12:02:33 PM) (Source: ESENT) (EventID: 455) (User: ) Description: taskhost (2120) WebCacheLocal: Error -1811 occurred while opening logfile C:\Users\AFAFA\AppData\Local\Microsoft\Windows\WebCache\V010004B.log. Error: (01/22/2017 11:49:03 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: SP_Connector.exe, version: 3.0.1.1, time stamp: 0x4e291877 Faulting module name: SP_Connector.exe, version: 3.0.1.1, time stamp: 0x4e291877 Exception code: 0xc0000409 Fault offset: 0x0001daf2 Faulting process id: 0xb84 Faulting application start time: 0x01d27534028683ca Faulting application path: C:\Program Files (x86)\SamsungPrinterLiveUpdate\SP_Connector.exe Faulting module path: C:\Program Files (x86)\SamsungPrinterLiveUpdate\SP_Connector.exe Report Id: 42d7462a-e127-11e6-a7ae-6817298df5e9 Error: (01/22/2017 10:01:19 AM) (Source: HP Active Health) (EventID: 91) (User: ) Description: Unhandled Exception. Application will terminate immediately. System.ArgumentNullException: Value cannot be null. at System.Threading.Monitor.Enter(Object obj) at HP.ActiveHealth.Commons.Security.HashStore.Validate(String filePath) at HP.ActiveHealth.Core.Program..ctor(String[] args, Boolean mustCheckSignature, Boolean validateIni) at HP.ActiveHealth.Core.ActiveHealthMain.Main(String[] args) Error: (01/22/2017 09:51:53 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Error: (01/21/2017 03:36:31 PM) (Source: HP Active Health) (EventID: 91) (User: ) Description: Unhandled Exception. Application will terminate immediately. System.ArgumentNullException: Value cannot be null. at System.Threading.Monitor.Enter(Object obj) at HP.ActiveHealth.Commons.Security.HashStore.Validate(String filePath) at HP.ActiveHealth.Core.Program..ctor(String[] args, Boolean mustCheckSignature, Boolean validateIni) at HP.ActiveHealth.Core.ActiveHealthMain.Main(String[] args) Error: (01/20/2017 10:24:25 PM) (Source: HP Active Health) (EventID: 91) (User: ) Description: Unhandled Exception. Application will terminate immediately. System.ArgumentNullException: Value cannot be null. at System.Threading.Monitor.Enter(Object obj) at HP.ActiveHealth.Commons.Security.HashStore.Validate(String filePath) at HP.ActiveHealth.Core.Program..ctor(String[] args, Boolean mustCheckSignature, Boolean validateIni) at HP.ActiveHealth.Core.ActiveHealthMain.Main(String[] args) Error: (01/20/2017 10:19:56 PM) (Source: SideBySide) (EventID: 35) (User: ) Description: Activation context generation failed for "C:\Program Files\Microsoft Office 15\root\office15\lync.exe.Manifest".Error in manifest or policy file "C:\Program Files\Microsoft Office 15\root\office15\UccApi.DLL" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0". Definition is UccApi,processorArchitecture="x86",type="win32",version="15.0.0.0". Please use sxstrace.exe for detailed diagnosis. Error: (01/20/2017 10:19:52 PM) (Source: SideBySide) (EventID: 35) (User: ) Description: Activation context generation failed for "C:\Program Files\Microsoft Office 15\root\office15\lync.exe.Manifest".Error in manifest or policy file "C:\Program Files\Microsoft Office 15\root\office15\UccApi.DLL" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0". Definition is UccApi,processorArchitecture="x86",type="win32",version="15.0.0.0". Please use sxstrace.exe for detailed diagnosis. System errors: ============= Error: (01/29/2017 12:04:34 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the IPBusEnum service. Error: (01/29/2017 12:04:23 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The Wireless PAN DHCP Server service terminated unexpectedly. It has done this 1 time(s). Error: (01/29/2017 12:03:24 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The World Wide Web Publishing Service service depends on the Windows Process Activation Service service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Error: (01/29/2017 12:03:19 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The Internet Connection Sharing (ICS) service depends on the Remote Access Connection Manager service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Error: (01/29/2017 12:03:19 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The Routing and Remote Access service depends on the Remote Access Connection Manager service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Error: (01/29/2017 12:03:19 PM) (Source: SNMP) (EventID: 1500) (User: ) Description: The SNMP Service encountered an error while accessing the registry key SYSTEM\CurrentControlSet\Services\SNMP\Parameters\TrapConfiguration. Error: (01/29/2017 12:03:16 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The PNRP Machine Name Publication Service service depends on the Peer Name Resolution Protocol service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Error: (01/29/2017 12:03:01 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The Net.Tcp Listener Adapter service depends on the Windows Process Activation Service service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Error: (01/29/2017 12:02:50 PM) (Source: Service Control Manager) (EventID: 7003) (User: ) Description: The Link-Layer Topology Discovery Mapper service depends the following service: lltdio. This service might not be installed. Error: (01/29/2017 12:02:22 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The Fax service depends on the Telephony service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. CodeIntegrity: =================================== Date: 2016-08-23 19:33:58.305 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\appid.sys because the set of per-page image hashes could not be found on the system. Date: 2016-08-23 19:32:49.228 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\aswKbd.sys because the set of per-page image hashes could not be found on the system. Date: 2016-08-23 19:32:49.103 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\aswSnx.sys because the set of per-page image hashes could not be found on the system. Date: 2016-08-22 06:27:09.204 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\appid.sys because the set of per-page image hashes could not be found on the system. Date: 2016-08-22 06:26:01.994 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\aswKbd.sys because the set of per-page image hashes could not be found on the system. Date: 2016-08-22 06:26:00.683 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\aswSnx.sys because the set of per-page image hashes could not be found on the system. Date: 2016-08-15 22:43:53.001 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\appid.sys because the set of per-page image hashes could not be found on the system. Date: 2016-08-15 22:42:03.250 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\aswKbd.sys because the set of per-page image hashes could not be found on the system. Date: 2016-08-15 22:42:02.173 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\aswSnx.sys because the set of per-page image hashes could not be found on the system. Date: 2016-08-09 19:31:49.495 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\appid.sys because the set of per-page image hashes could not be found on the system. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i7-3610QM CPU @ 2.30GHz Percentage of memory in use: 52% Total physical RAM: 3995.31 MB Available physical RAM: 1905.42 MB Total Virtual: 7988.8 MB Available Virtual: 5398 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:909.66 GB) (Free:394.83 GB) NTFS ==>[system with boot components (obtained from drive)] Drive d: (Recovery) (Fixed) (Total:21.55 GB) (Free:2.28 GB) NTFS ==>[system with boot components (obtained from drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 1E75F28A) Partition 1: (Active) - (Size=199 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=909.7 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=21.6 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=102 MB) - (Type=0C) ==================== End of Addition.txt ============================