Additional scan result of Farbar Recovery Scan Tool (x64) Version: 29-01-2017 Ran by [removed] (30-01-2017 16:36:15) Running from C:\Users\[removed]\Downloads Windows 8.1 (Update) (X64) (2013-12-11 22:16:46) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-2419766067-897465512-1457611607-500 - Administrator - Disabled) Guest (S-1-5-21-2419766067-897465512-1457611607-501 - Limited - Disabled) Vapor 2 (S-1-5-21-2419766067-897465512-1457611607-1001 - Administrator - Enabled) => C:\Users\Janet ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 64 Bit HP CIO Components Installer (Version: 7.2.8 - Hewlett-Packard) Hidden Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.023.20056 - Adobe Systems Incorporated) Adobe Flash Player 24 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 24.0.0.194 - Adobe Systems Incorporated) AVG Web TuneUp (HKLM-x32\...\AVG Web TuneUp) (Version: 4.3.6.255 - AVG Technologies) bpd_scan (x32 Version: 3.00.0000 - Hewlett-Packard) Hidden CCleaner (HKLM\...\CCleaner) (Version: 5.21 - Piriform) CMS2000 version 1.0.1.35 (HKLM-x32\...\{992EF7D5-3D70-4B7F-AFDC-CMS200076BD4A}_is1) (Version: 1.0.1.35 - ) CyberLink Media Suite Essentials (HKLM-x32\...\InstallShield_{8F14AA37-5193-4A14-BD5B-BDF9B361AEF7}) (Version: 10.0 - CyberLink Corp.) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Dell Backup and Recovery (HKLM-x32\...\{0ED7EE95-6A97-47AA-AD73-152C08A15B04}) (Version: 1.9.2.8 - Dell Inc.) Dell Customer Connect (HKLM-x32\...\{124DE80C-9BFE-4D04-A8D9-69C5019DEEBF}) (Version: 1.3.28.0 - Dell Inc.) Dell Data Vault (Version: 4.3.8.0 - Dell Inc.) Hidden Dell Digital Delivery (HKLM-x32\...\{693A23FB-F28B-4F7A-A720-4C1263F97F43}) (Version: 3.1.1002.0 - Dell Products, LP) Dell Service Tag Detection Tool (HKU\S-1-5-21-2419766067-897465512-1457611607-1001\...\8ab5c01ee3209028) (Version: 1.0.0.0 - Dell Inc.) Dell SupportAssist (HKLM\...\PC-Doctor for Windows) (Version: 1.3.6855.61 - Dell) Dell SupportAssistAgent (HKLM-x32\...\{27130E51-9555-408B-8134-7BFF54EDE27B}) (Version: 1.3.0.72 - Dell) Dell System Detect - 1 (HKU\S-1-5-21-2419766067-897465512-1457611607-1001\...\73f463568823ebbe) (Version: 6.0.0.9 - Dell) Dell Update (HKLM-x32\...\{DB82968B-57A4-4397-81A5-ECAB21B5DFCD}) (Version: 1.7.1015.0 - Dell Inc.) Dell WLAN and Bluetooth Client Installation (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 10.0 - Dell Inc.) DELLOSD (HKLM-x32\...\{699D0EFA-5AC2-4DAB-846E-E4EFDA00ACAC}) (Version: 1.0.2.1108 - DELL) DivX Setup (HKLM-x32\...\DivX Setup) (Version: 2.7.0.31 - DivX, LLC) Driver Support (HKLM-x32\...\DriverSupport) (Version: 10.1.4.37 - PC Drivers HeadQuarters LP) <==== ATTENTION Google Chrome (HKLM-x32\...\Google Chrome) (Version: 56.0.2924.76 - Google Inc.) Google Earth (HKLM-x32\...\{A0C18B96-AB79-46BD-8321-6FA83E6D25B9}) (Version: 7.1.7.2606 - Google) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.32.7 - Google Inc.) Hidden HP Photo Creations (HKU\S-1-5-21-2419766067-897465512-1457611607-1001\...\HP Photo Creations) (Version: 1.0.0.18142 - HP) I.R.I.S. OCR (HKLM-x32\...\{CA6BCA2F-EDEB-408F-850B-31404BE16A61}) (Version: 12.3.4.0 - HP) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.13.1706 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.4276 - Intel Corporation) Java 8 Update 66 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218066F0}) (Version: 8.0.660.18 - Oracle Corporation) JPG To PDF 2.2.1 (HKLM-x32\...\JPG To PDF_is1) (Version: - JPG To PDF Developer Team) Kodi (HKU\S-1-5-21-2419766067-897465512-1457611607-1001\...\Kodi) (Version: - XBMC-Foundation) Logitech Vid (HKLM-x32\...\{4FBCEA31-5D18-4212-9231-DE7CF1BE7DBB}) (Version: 1.10.1009 - Logitech Inc.) Logitech Webcam Software (HKLM\...\{987FE247-4E69-4A2E-A961-D14F901FDBF6}) (Version: 12.10.1113 - Logitech Inc.) Logitech Webcam Software Driver Package (HKLM\...\lvdrivers_12.10) (Version: 12.10.1110 - Logitech Inc.) Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes) Microsoft .NET Framework 1.1 (HKLM-x32\...\{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}) (Version: 1.1.4322 - Microsoft) Microsoft Office 365 - en-us (HKLM\...\O365HomePremRetail - en-us) (Version: 16.0.7571.2109 - Microsoft Corporation) Microsoft Office 365 ProPlus - en-us (HKLM\...\O365ProPlusRetail - en-us) (Version: 16.0.7571.2109 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-2419766067-897465512-1457611607-1001\...\OneDriveSetup.exe) (Version: 17.3.6743.1212 - Microsoft Corporation) Microsoft SharePoint Designer 2013 (HKLM\...\Office15.SharePointDesigner) (Version: 15.0.4569.1506 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50901.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Movie Maker (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Office 16 Click-to-Run Extensibility Component (x32 Version: 16.0.7571.2109 - Microsoft Corporation) Hidden Office 16 Click-to-Run Extensibility Component 64-bit Registration (Version: 16.0.7571.2109 - Microsoft Corporation) Hidden Office 16 Click-to-Run Licensing Component (Version: 16.0.7571.2109 - Microsoft Corporation) Hidden Office 16 Click-to-Run Localization Component (x32 Version: 16.0.7571.2109 - Microsoft Corporation) Hidden Outils de vérification linguistique 2013 de Microsoft Office - Français (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden PhoneMyPC (HKLM\...\{4B6CAE5A-1863-49CF-9F0E-CF8CFDFDADEE}) (Version: 2.0.3 - SoftwareForMe Inc.) Qualcomm Atheros Bluetooth Suite (64) (HKLM\...\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.0.209 - Qualcomm Atheros Communications) QuickBooks Point of Sale 6.0 (HKLM-x32\...\{264908A0-87AD-4248-9B4E-C0E9C8798670}) (Version: 6.01.0010 - Intuit Inc.) QuickBooks Point Of Sale Product Listing Service (HKLM-x32\...\{6D949ED4-ECEE-408B-BB98-8EC73B446E78}) (Version: 2.0.126 - Intuit) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7404 - Realtek Semiconductor Corp.) Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (HKLM\...\{90150000-0017-0000-1000-0000000FF1CE}_Office15.SharePointDesigner_{67A083C6-0A9E-48E8-BC90-C1EDA8028ED4}) (Version: - Microsoft) Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (Version: - Microsoft) Hidden Service Pack 1 for Microsoft Project 2013 (KB2817433) 64-Bit Edition (Version: - Microsoft) Hidden Shared C Run-time for x64 (HKLM\...\{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee) Unity Web Player (HKU\S-1-5-21-2419766067-897465512-1457611607-1001\...\UnityWebPlayer) (Version: 4.6.4f1 - Unity Technologies ApS) Update for Skype for Business 2015 (KB3141468) 64-Bit Edition (HKLM\...\{90150000-00C1-0000-1000-0000000FF1CE}_Office15.SharePointDesigner_{CB85A0CF-0448-43D8-8006-173A8C84A018}) (Version: - Microsoft) VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3505.0912 - Microsoft Corporation) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-2419766067-897465512-1457611607-1001_Classes\CLSID\{162C6FB5-44D3-435B-903D-E613FA093FB5}\InprocServer32 -> C:\Users\Janet\AppData\Local\Microsoft\OneDrive\17.3.6743.1212_1\amd64\FileCoAuthLib64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2419766067-897465512-1457611607-1001_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\WINDOWS\system32\igfxEM.exe (Intel Corporation) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {08765F16-DF10-4C85-999D-306CC66F36F1} - System32\Tasks\Driver Support-RTMUpdater => C:\Program Files (x86)\Driver Support\DriverSupport.exe [2017-01-18] (PC Drivers Headquarters LP) Task: {0D8A891D-890C-4808-84D8-2F436AB14653} - \Microsoft\Windows\Application Experience\AitAgent -> No File <==== ATTENTION Task: {11063B61-6812-471C-AE84-D295A9219511} - System32\Tasks\Driver Support => C:\Program Files (x86)\Driver Support\DriverSupport.exe [2017-01-18] (PC Drivers Headquarters LP) Task: {1274336E-AB06-46B6-A48C-0671C5557CC6} - \Microsoft\Windows\TaskScheduler\Maintenance Configurator -> No File <==== ATTENTION Task: {1687544D-7247-4F5A-965A-A6E920E55278} - \Microsoft\Windows\TaskScheduler\Manual Maintenance -> No File <==== ATTENTION Task: {30727637-D9C3-466B-B5DE-C133488C9BE6} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_ERROR_HB => C:\WINDOWS\system32\MRT.exe [2017-01-21] (Microsoft Corporation) Task: {3115D9F1-B8D3-4C3E-A181-BDF036636281} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-07-12] (Google Inc.) Task: {327A6376-5A43-4BF3-9250-402745476811} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonx86\Microsoft Shared\OFFICE15\OLicenseHeartbeat.exe Task: {3EDA7299-AB31-4917-9DDE-43E3A827C8DE} - System32\Tasks\Dell SupportAssistAgent AutoUpdate => C:\Program Files (x86)\Dell\SupportAssistAgent\bin\SupportAssist.exe [2016-09-09] (Dell Inc.) Task: {40525C58-79C2-47A1-9AA2-F1D7FC4F0691} - \Microsoft\Windows\WindowsBackup\ConfigNotification -> No File <==== ATTENTION Task: {443DF0CC-A233-442C-9BA4-8AA2C14396B6} - System32\Tasks\PC Health Advisor Update => C:\Program Files (x86)\ParetoLogic\PCHA\PCHA.exe <==== ATTENTION Task: {4A129B7A-4D5B-4605-8FCA-A795262E4096} - System32\Tasks\PCDDataUploadTask => uaclauncher.exe Task: {4E2ECA25-E5E4-4A98-A84B-3BE56BE5CE8A} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2017-01-23] (Microsoft Corporation) Task: {4ED401D7-7A49-432E-8F3A-124E29380AAF} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-07-12] (Google Inc.) Task: {52312E4E-7227-4D0F-93DB-F0713EF12177} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-08-05] (Piriform Ltd) Task: {5D23D5D6-DC70-46FA-BD56-B41106E53CEB} - System32\Tasks\Driver Support-RTMRules => C:\Program Files (x86)\Driver Support\DriverSupport.exe [2017-01-18] (PC Drivers Headquarters LP) Task: {5DF54033-02E1-4DAA-B3B2-9C4F56FEF41C} - System32\Tasks\0316tbUpdateInfo => C:\ProgramData\Avg_Update_0316tb\0316tb_{CE07A536-F8E6-470B-98D7-8EC6B10A68B5}.exe Task: {5E18FC4A-4B64-45CA-94C7-019069D09E54} - System32\Tasks\UpdateTask => C:\Users\Janet\AppData\Local\{FE11C~1\UNINST~1.EXE Task: {63B930AE-B434-44E5-A729-3810AD9F07F8} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2014-01-23] (Microsoft Corporation) Task: {64E293DB-B189-4864-AD38-29AC04C09BC9} - System32\Tasks\iolo System Checkup => C:\ProgramData\iolo\scustask.lnk [Argument = /toaster] Task: {6D9E8458-DFBB-4DDE-8072-97204F026F56} - System32\Tasks\Coinify => c:\programdata\{6dd79297-a6cf-3a8d-6dd7-79297a6c4a5e}\v50020_aboot_twrp_v2.zip.exe <==== ATTENTION Task: {6F02587F-8A2B-4552-97F6-DEEF229E335B} - \Microsoft\Windows\TaskScheduler\Idle Maintenance -> No File <==== ATTENTION Task: {721C6FD3-0DE2-42F7-AF13-51BE6E5018AF} - System32\Tasks\SystemToolsDailyTest => uaclauncher.exe Task: {727D546E-BAEA-4673-8B5F-D874DDF299DA} - System32\Tasks\Driver Support-RTMScan => C:\Program Files (x86)\Driver Support\DriverSupport.exe [2017-01-18] (PC Drivers Headquarters LP) Task: {76298D36-C23A-46B7-A469-F42B969E6ECF} - System32\Tasks\PCDEventLauncherTask => C:\Program Files\Dell\SupportAssist\sessionchecker.exe [2016-09-13] (PC-Doctor, Inc.) Task: {930D88EA-5B7F-4134-B984-CD7D4420DEC9} - \gameo_update -> No File <==== ATTENTION Task: {98BE4658-5183-48BC-B361-BDF98DD49951} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2016-12-28] (Microsoft Corporation) Task: {9CC13DA5-AF72-4CC2-85C1-C75CFAA7BA51} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2017-01-23] (Microsoft Corporation) Task: {A19BBE7D-879D-4F44-811C-8DD5B7DB0B09} - System32\Tasks\PCDoctorBackgroundMonitorTask => C:\Program Files\Dell\SupportAssist\uaclauncher.exe [2016-09-13] (PC-Doctor, Inc.) Task: {A3A76923-B466-463A-88A9-4200731AD6F1} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-12-19] (Adobe Systems Incorporated) Task: {ABAC6192-B715-4091-982D-810DAA5B0B36} - System32\Tasks\HP Photo Creations Communicator => C:\Users\Janet\AppData\Roaming\HP Photo Creations\Communicator.exe [2011-04-15] () Task: {B50AE062-86FD-433B-BAAD-B6D5193610E5} - System32\Tasks\Microsoft Office 15 Sync Maintenance for HOMEOFFICE-Vapor 2 HomeOffice => C:\Program Files\Microsoft Office\Office15\MsoSync.exe [2016-02-09] (Microsoft Corporation) Task: {B7992938-01F1-4F40-A0EC-0D23D2F0F152} - \Microsoft\Windows\TaskScheduler\Regular Maintenance -> No File <==== ATTENTION Task: {C2D82A54-5FC9-4A5F-8E58-599937F37008} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_24_0_0_194_pepper.exe [2017-01-21] (Adobe Systems Incorporated) Task: {CFD7C21A-808B-487B-A6EC-8A10E44E8360} - \Microsoft\Windows\SettingSync\BackupTask -> No File <==== ATTENTION Task: {D0BDF5E6-F494-420C-9C3F-1BA0888910B9} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2017-01-21] (Microsoft Corporation) Task: {D6F4A061-CEFB-4F38-81EC-6E80ECDD3011} - System32\Tasks\Microsoft\Windows\Location\Notifications => C:\WINDOWS\System32\LocationNotificationWindows.exe Task: {D94E51DF-B9E1-4116-84F9-A782B4300C82} - System32\Tasks\Optimize Push Notification Data File-S-1-5-21-2419766067-897465512-1457611607-1001 Task: {DB2E8D66-7ED5-42E7-93E5-AA11E1A861B1} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-01-21] (Adobe Systems Incorporated) Task: {EC5B69E9-8C38-4C2A-B124-8A49BB6FC230} - System32\Tasks\Microsoft\Windows\DiskFootprint\Diagnostics => C:\WINDOWS\system32\disksnapshot.exe Task: {FD6819D1-50D1-4546-B0C9-9E9AE0ABA747} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe Task: {FFF0C770-674C-402C-8C4E-AD8C13493629} - System32\Tasks\HPCustParticipation HP ENVY 4500 series => C:\Program Files\HP\HP ENVY 4500 series\Bin\HPCustPartic.exe (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\0316tbUpdateInfo.job => C:\ProgramData\Avg_Update_0316tb\0316tb_{CE07A536-F8E6-470B-98D7-8EC6B10A68B5}.exe Task: C:\WINDOWS\Tasks\Adobe Flash Player PPAPI Notifier.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_24_0_0_194_pepper.exe Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\Coinify.job => c:\programdata\{6dd79297-a6cf-3a8d-6dd7-79297a6c4a5e}\v50020_aboot_twrp_v2.zip.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\HP Photo Creations Communicator.job => C:\Users\Janet\AppData\Roaming\HP Photo Creations\Communicator.exe Task: C:\WINDOWS\Tasks\PC Health Advisor Update.job => C:\Program Files (x86)\ParetoLogic\PCHA\PCHA.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\UpdateTask.job => C:\Users\Janet\AppData\Local\{FE11C~1\UNINST~1.EXE ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) ShortcutWithArgument: C:\Users\Janet\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\9501e18d7c2ab92e\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory="Profile 2" ShortcutWithArgument: C:\Users\Janet\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\69639df789022856\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory="Profile 1" ==================== Loaded Modules (Whitelisted) ============== 2015-07-14 10:49 - 2017-01-20 06:08 - 00980552 ____N () C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe 2017-01-23 15:53 - 2017-01-23 15:53 - 08924864 _____ () C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\1033\GrooveIntlResource.dll 2011-04-15 01:11 - 2011-04-15 01:11 - 00186368 _____ () C:\Users\Janet\AppData\Roaming\HP Photo Creations\Communicator.exe 2016-12-26 18:56 - 2013-08-19 08:12 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll 2016-01-05 09:17 - 2015-12-18 15:52 - 01607920 _____ () C:\Program Files (x86)\Dell Backup and Recovery\Components\Restore\STRestoreAPI.dll 2013-04-27 07:42 - 2012-11-25 21:19 - 01153384 _____ () C:\Program Files (x86)\Dell Backup and Recovery\Components\Restore\libxml2.dll 2015-02-26 09:07 - 2014-02-18 11:12 - 00117568 _____ () C:\Program Files (x86)\Dell Backup and Recovery\Components\Restore\zlib1.dll 2016-12-14 13:24 - 2016-12-07 23:29 - 01829208 _____ () C:\Program Files (x86)\Google\Chrome\Application\55.0.2883.87\libglesv2.dll 2016-12-14 13:24 - 2016-12-07 23:29 - 00085848 _____ () C:\Program Files (x86)\Google\Chrome\Application\55.0.2883.87\libegl.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Dell Click 2 Fix => "DisplayName"="Dell" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Dell Click 2 Fix => "ErrorControl"="1" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Dell Click 2 Fix => "ImagePath"="C:\Program Files\Dell\Click 2 Fix\srvc.exe" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Dell Click 2 Fix => "ObjectName"="LocalSystem" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Dell Click 2 Fix => "Start"="2" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Dell Click 2 Fix => "Type"="272" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Dell Click 2 Fix+ => "DisplayName"="Dell" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Dell Click 2 Fix+ => "ErrorControl"="1" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Dell Click 2 Fix+ => "ImagePath"="C:\Program Files\Dell\Click 2 Fix+\srvc.exe" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Dell Click 2 Fix+ => "ObjectName"="LocalSystem" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Dell Click 2 Fix+ => "Start"="2" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Dell Click 2 Fix+ => "Type"="272" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MSIServer => ""="Service" ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) IE trusted site: HKU\S-1-5-21-2419766067-897465512-1457611607-1001\...\dell.com -> dell.com IE trusted site: HKU\S-1-5-21-2419766067-897465512-1457611607-1001\...\driversupport.com -> hxxp://apps.driversupport.com IE trusted site: HKU\S-1-5-21-2419766067-897465512-1457611607-1001\...\driversupport.com -> hxxps://apps.driversupport.com ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2014-08-03 00:16 - 2016-01-16 00:11 - 00000734 ____A C:\WINDOWS\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-2419766067-897465512-1457611607-1001\Control Panel\Desktop\\Wallpaper -> DNS Servers: [removed] - [removed] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == MSCONFIG\Services: AdobeARMservice => 2 MSCONFIG\Services: AdobeFlashPlayerUpdateSvc => 3 MSCONFIG\Services: AERTFilters => 2 MSCONFIG\Services: Apple Mobile Device Service => 2 MSCONFIG\Services: AtherosSvc => 2 MSCONFIG\Services: avgsvc => 2 MSCONFIG\Services: Bonjour Service => 2 MSCONFIG\Services: cphs => 3 MSCONFIG\Services: Dell Customer Connect => 2 MSCONFIG\Services: DellDataVault => 2 MSCONFIG\Services: DellDataVaultWiz => 2 MSCONFIG\Services: DellDigitalDelivery => 2 MSCONFIG\Services: DellUpdate => 2 MSCONFIG\Services: gupdate => 2 MSCONFIG\Services: gupdatem => 3 MSCONFIG\Services: HPSupportSolutionsFrameworkService => 2 MSCONFIG\Services: igfxCUIService1.0.0.0 => 2 MSCONFIG\Services: Intel(R) Capability Licensing Service Interface => 2 MSCONFIG\Services: Intel(R) Capability Licensing Service TCP IP Interface => 3 MSCONFIG\Services: Intuit Entitlement Service v3 => 2 MSCONFIG\Services: iPod Service => 3 MSCONFIG\Services: LVPrcS64 => 2 MSCONFIG\Services: MozillaMaintenance => 3 MSCONFIG\Services: PhoneMyPC_Helper => 3 MSCONFIG\Services: QBPOSDBServiceV6 => 2 MSCONFIG\Services: RichVideo => 2 MSCONFIG\Services: RtkAudioService => 2 MSCONFIG\Services: SftService => 2 MSCONFIG\Services: SkypeUpdate => 2 MSCONFIG\Services: VolumeCtlSrv => 2 MSCONFIG\Services: vToolbarUpdater40.2.8 => 2 MSCONFIG\Services: WtuSystemSupport => 2 MSCONFIG\Services: ZAtheros Wlan Agent => 2 HKLM\...\StartupApproved\StartupFolder: => "QuickBooks Update Agent.lnk" HKLM\...\StartupApproved\StartupFolder: => "HP Digital Imaging Monitor.lnk" HKLM\...\StartupApproved\Run: => "BtTray" HKLM\...\StartupApproved\Run: => "BtvStack" HKLM\...\StartupApproved\Run: => "RtHDVBg" HKLM\...\StartupApproved\Run: => "PocketCloud Location" HKLM\...\StartupApproved\Run: => "iTunesHelper" HKLM\...\StartupApproved\Run32: => "CLMLServer_For_P2G8" HKLM\...\StartupApproved\Run32: => "CLVirtualDrive" HKLM\...\StartupApproved\Run32: => "RemoteControl10" HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched" HKLM\...\StartupApproved\Run32: => "SearchProtectAll" HKLM\...\StartupApproved\Run32: => "ArcSoft Connection Service" HKLM\...\StartupApproved\Run32: => "Adobe ARM" HKLM\...\StartupApproved\Run32: => "ApnTBMon" HKLM\...\StartupApproved\Run32: => "LogitechQuickCamRibbon" HKLM\...\StartupApproved\Run32: => "HP Software Update" HKLM\...\StartupApproved\Run32: => "DivXMediaServer" HKLM\...\StartupApproved\Run32: => "DivXUpdate" HKLM\...\StartupApproved\Run32: => "BrowserAppCoreService" HKLM\...\StartupApproved\Run32: => "AVG_UI" HKLM\...\StartupApproved\Run32: => "AvgUi" HKLM\...\StartupApproved\Run32: => "vProt" HKU\S-1-5-21-2419766067-897465512-1457611607-1001\...\StartupApproved\StartupFolder: => "Send to OneNote.lnk" HKU\S-1-5-21-2419766067-897465512-1457611607-1001\...\StartupApproved\StartupFolder: => "RocketTab3.1.zip.lnk" HKU\S-1-5-21-2419766067-897465512-1457611607-1001\...\StartupApproved\StartupFolder: => "Monitor Ink Alerts - HP Officejet Pro 8610.lnk" HKU\S-1-5-21-2419766067-897465512-1457611607-1001\...\StartupApproved\Run: => "Facebook Update" HKU\S-1-5-21-2419766067-897465512-1457611607-1001\...\StartupApproved\Run: => "SkyDrive" HKU\S-1-5-21-2419766067-897465512-1457611607-1001\...\StartupApproved\Run: => "SearchProtect" HKU\S-1-5-21-2419766067-897465512-1457611607-1001\...\StartupApproved\Run: => "Logitech Vid" HKU\S-1-5-21-2419766067-897465512-1457611607-1001\...\StartupApproved\Run: => "Speech Recognition" HKU\S-1-5-21-2419766067-897465512-1457611607-1001\...\StartupApproved\Run: => "CCleaner Monitoring" HKU\S-1-5-21-2419766067-897465512-1457611607-1001\...\StartupApproved\Run: => "OneDrive" HKU\S-1-5-21-2419766067-897465512-1457611607-1001\...\StartupApproved\Run: => "Bubble Dock" HKU\S-1-5-21-2419766067-897465512-1457611607-1001\...\StartupApproved\Run: => "Selection Tools" HKU\S-1-5-21-2419766067-897465512-1457611607-1001\...\StartupApproved\Run: => "WindApp" HKU\S-1-5-21-2419766067-897465512-1457611607-1001\...\StartupApproved\Run: => "GoogleChromeAutoLaunch_155109F5304778AED68B806938791979" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [vm-monitoring-nb-session] => LPort=139 FirewallRules: [{5D5844B0-78AC-4529-B020-8A786FE25053}] => LPort=1900 FirewallRules: [{4AE7A360-F6AE-47EC-BAE3-AF0A1D2AFCF2}] => LPort=2869 FirewallRules: [{A52A65AC-E34B-4491-929E-51844C007543}] => C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe FirewallRules: [{67098152-BF58-4E92-86A2-405D4D206D22}] => C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD10.EXE FirewallRules: [{22B4661F-E76F-4109-99BC-8C6BD6E3E372}] => C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD Cinema\PowerDVDCinema10.exe FirewallRules: [{AA23862E-AC90-4172-BE5A-D00137FD8EFF}] => C:\Program Files (x86)\CyberLink\PowerDirector10\PDR10.EXE FirewallRules: [{1761745B-70D5-446A-AFD2-A39F6F9E85F3}] => C:\Program Files (x86)\Intuit\QuickBooks Point of Sale 6.0\EftSvr.exe FirewallRules: [{FFD9CC51-390B-495E-BABC-6B26E7043941}] => C:\Program Files (x86)\Intuit\QuickBooks Point of Sale 6.0\EftSvr.exe FirewallRules: [{43759F9E-7247-46F2-95B9-8E38AF1E148A}] => C:\Program Files (x86)\Intuit\QuickBooks Point of Sale 6.0\DatabaseServer\QBDBMgrN.exe FirewallRules: [{03EC71F9-4822-496D-81DC-B7ADC8ADAE19}] => C:\Program Files (x86)\Intuit\QuickBooks Point of Sale 6.0\DatabaseServer\QBDBMgrN.exe FirewallRules: [{99CD8E0E-A463-4CAC-A399-5AC5F2FD5B10}] => C:\Program Files (x86)\Intuit\QuickBooks Point of Sale 6.0\DatabaseServer\QBDBMgr.exe FirewallRules: [{C879A950-23D7-4E20-958E-D6E96F0CB4BF}] => C:\Program Files (x86)\Intuit\QuickBooks Point of Sale 6.0\DatabaseServer\QBDBMgr.exe FirewallRules: [{71A654EA-1FEE-40DE-B94A-5A839A448396}] => C:\Program Files (x86)\Logitech\Logitech Vid\Vid.exe FirewallRules: [{C0313D7D-E17D-4F0B-BECD-0C50277D7D47}] => C:\Program Files (x86)\Logitech\Logitech Vid\Vid.exe FirewallRules: [TCP Query User{54637D86-C5D9-44EC-9FC6-3AAF6B027011}C:\program files (x86)\logitech\logitech vid\vid.exe] => C:\program files (x86)\logitech\logitech vid\vid.exe FirewallRules: [UDP Query User{F42FDD91-46C9-4082-9653-B8C696EDF06F}C:\program files (x86)\logitech\logitech vid\vid.exe] => C:\program files (x86)\logitech\logitech vid\vid.exe FirewallRules: [WCF-NetTcpActivator-In-TCP-64bit] => LPort=808 FirewallRules: [{30C97314-9331-4DC6-918B-3A661E64A5F9}] => C:\Program Files\SoftwareForMe Inc\PhoneMyPC\PhoneMyPC.exe FirewallRules: [{A2C03157-E742-498B-9157-CB2E72002C5A}] => C:\Program Files\SoftwareForMe Inc\PhoneMyPC\PhoneMyPC.exe FirewallRules: [{CD4AD130-2900-47FE-884D-6166EEC94733}] => C:\Program Files\SoftwareForMe Inc\PhoneMyPC\PhoneMyPC.exe FirewallRules: [{732D7239-EFC4-473A-AAC4-BFB57489692C}] => C:\Program Files\SoftwareForMe Inc\PhoneMyPC\PhoneMyPC.exe FirewallRules: [{1889D03D-9669-411E-A287-886642EA9B3A}] => C:\Program Files (x86)\Common Files\Intuit\Entitlement Client\v3\Server\Intuit.Spc.Map.EntitlementClient.Server.Service.exe FirewallRules: [{1D9C51B4-078E-48DE-A4E5-E430AA3EBC8A}] => C:\Program Files (x86)\Common Files\Intuit\Entitlement Client\v3\Server\Intuit.Spc.Map.EntitlementClient.Server.Service.exe FirewallRules: [{AB029AD9-0FD2-4291-84EF-E8E951C9DED6}] => C:\Program Files (x86)\CyberLink\PowerDirector10\PDR10.EXE FirewallRules: [{55744BC3-419D-4682-9D41-7BA200753791}] => C:\Program Files (x86)\CyberLink\PowerDirector10\PDR10.EXE FirewallRules: [{53301EB9-CCB5-42E7-9736-E55EEA5C462D}] => C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD10.EXE FirewallRules: [{04B66D98-05F3-430F-ABCD-13185999FBBF}] => C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD10.EXE FirewallRules: [{219D59C6-0FC0-4FB9-9759-981C2E727783}] => C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD Cinema\PowerDVDCinema10.exe FirewallRules: [{1446A717-879D-4A2D-8165-565D2BE174F3}] => C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD Cinema\PowerDVDCinema10.exe FirewallRules: [TCP Query User{5A294D91-0AD1-477F-9D5C-1E475F11F709}C:\program files (x86)\kodi\kodi.exe] => C:\program files (x86)\kodi\kodi.exe FirewallRules: [UDP Query User{9E736B5B-2268-4027-87EB-54E73D3CF563}C:\program files (x86)\kodi\kodi.exe] => C:\program files (x86)\kodi\kodi.exe FirewallRules: [TCP Query User{1B185C72-DBCD-4F2E-B122-F61C4B817431}C:\program files (x86)\kodi\kodi.exe] => C:\program files (x86)\kodi\kodi.exe FirewallRules: [UDP Query User{0D88D313-916C-4822-893B-023A7FE05C67}C:\program files (x86)\kodi\kodi.exe] => C:\program files (x86)\kodi\kodi.exe FirewallRules: [{705BF5EC-050E-44A6-934D-FCF46FEF1085}] => LPort=5354 FirewallRules: [{5EE5329F-8712-4A45-AD38-7590F544BA6D}] => LPort=5354 FirewallRules: [{7A241012-CD3D-490D-9F19-F2D4D1F39601}] => LPort=5354 FirewallRules: [{2BFAC187-C170-457C-A171-053128F8D871}] => LPort=5354 FirewallRules: [{1AE9712E-F4EE-4A73-ABB5-B1ED640C4B76}] => C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe FirewallRules: [{0BC39208-58CC-4B37-961B-36469C09B015}] => C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe FirewallRules: [{2F8AF91B-60A0-4FAE-AF94-2F7777CDFED5}] => C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe FirewallRules: [{0F4095D3-1C6F-4F75-890A-22BDAFB422F3}] => C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe FirewallRules: [{10F2C95F-2AE7-4EFC-B7FB-A86492AC4E4F}] => C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe FirewallRules: [{C7393A82-9C0C-459C-9CC0-8BF05ADC6170}] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Restore Points ========================= 23-01-2017 16:13:51 Installed Microsoft SharePoint Designer 2013 23-01-2017 16:14:25 SHAREPOINTDESIGNER 26-01-2017 07:50:17 Removed AVG 26-01-2017 07:53:48 Removed AVG 2016 26-01-2017 13:55:07 Removed Microsoft SQL Server 2005 Compact Edition [ENU] 30-01-2017 15:18:28 Windows Update ==================== Faulty Device Manager Devices ============= Name: Dell Wireless 1703 802.11b|g|n (2.4GHz) Description: Dell Wireless 1703 802.11b|g|n (2.4GHz) Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Qualcomm Atheros Communications Inc. Service: athr Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: Bluetooth Device (Personal Area Network) Description: Bluetooth Device (Personal Area Network) Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: BthPan Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (01/28/2017 02:34:47 PM) (Source: System Restore) (EventID: 8193) (User: ) Description: Failed to create restore point (Process = C:\Program Files (x86)\InstallShield Installation Information\{8F14AA37-5193-4A14-BD5B-BDF9B361AEF7}\setup.exe Files (x86)\InstallShield Installation Information\{8F14AA37-5193-4A14-BD5B-BDF9B361AEF7}\setup.exe" /z-uninstall; Description = Installed Suite; Error = 0x8007043c). Error: (01/28/2017 02:32:59 PM) (Source: System Restore) (EventID: 8193) (User: ) Description: Failed to create restore point (Process = C:\WINDOWS\system32\msiexec.exe /V; Description = Removed Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17; Error = 0x8007043c). Error: (01/28/2017 02:32:59 PM) (Source: System Restore) (EventID: 8193) (User: ) Description: Failed to create restore point (Process = C:\WINDOWS\system32\msiexec.exe /V; Description = Removed Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17; Error = 0x8007043c). Error: (01/28/2017 02:32:25 PM) (Source: System Restore) (EventID: 8193) (User: ) Description: Failed to create restore point (Process = C:\WINDOWS\system32\msiexec.exe /V; Description = Removed Microsoft Visual C++ 2005 Redistributable; Error = 0x8007043c). Error: (01/28/2017 02:32:25 PM) (Source: System Restore) (EventID: 8193) (User: ) Description: Failed to create restore point (Process = C:\WINDOWS\system32\msiexec.exe /V; Description = Removed Microsoft Visual C++ 2005 Redistributable; Error = 0x8007043c). Error: (01/28/2017 02:31:29 PM) (Source: System Restore) (EventID: 8193) (User: ) Description: Failed to create restore point (Process = C:\WINDOWS\system32\msiexec.exe /V; Description = Removed Visual Studio 2012 x86 Redistributables; Error = 0x8007043c). Error: (01/28/2017 02:31:28 PM) (Source: System Restore) (EventID: 8193) (User: ) Description: Failed to create restore point (Process = C:\WINDOWS\system32\msiexec.exe /V; Description = Removed Visual Studio 2012 x86 Redistributables; Error = 0x8007043c). Error: (01/27/2017 01:17:49 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program Kodi.exe version 16.0.0.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: 1230 Start Time: 01d278d2b3560207 Termination Time: 60 Application Path: C:\Program Files (x86)\Kodi\Kodi.exe Report Id: 056f437f-e4d6-11e6-bf3e-a41f7275f882 Faulting package full name: Faulting package-relative application ID: System errors: ============= Error: (01/30/2017 03:21:21 PM) (Source: DCOM) (EventID: 10005) (User: NT AUTHORITY) Description: DCOM got error "1079" attempting to start the service upnphost with arguments "Unavailable" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} Error: (01/30/2017 03:21:21 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The UPnP Device Host service failed to start due to the following error: The account specified for this service is different from the account specified for other services running in the same process. Error: (01/30/2017 03:21:20 PM) (Source: DCOM) (EventID: 10005) (User: NT AUTHORITY) Description: DCOM got error "1079" attempting to start the service upnphost with arguments "Unavailable" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} Error: (01/30/2017 03:21:20 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The UPnP Device Host service failed to start due to the following error: The account specified for this service is different from the account specified for other services running in the same process. Error: (01/30/2017 03:21:20 PM) (Source: DCOM) (EventID: 10005) (User: NT AUTHORITY) Description: DCOM got error "1079" attempting to start the service upnphost with arguments "Unavailable" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} Error: (01/30/2017 03:21:20 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The UPnP Device Host service failed to start due to the following error: The account specified for this service is different from the account specified for other services running in the same process. Error: (01/29/2017 06:40:55 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The vToolbarUpdater40.3.6 service terminated unexpectedly. It has done this 1 time(s). Error: (01/28/2017 02:36:56 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The UPnP Device Host service failed to start due to the following error: The account specified for this service is different from the account specified for other services running in the same process. Error: (01/28/2017 02:36:03 PM) (Source: DCOM) (EventID: 10005) (User: HOMEOFFICE) Description: DCOM got error "1084" attempting to start the service WSearch with arguments "Unavailable" in order to run the server: {9E175B68-F52A-11D8-B9A5-505054503030} Error: (01/28/2017 02:36:03 PM) (Source: DCOM) (EventID: 10005) (User: HOMEOFFICE) Description: DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "Unavailable" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC} CodeIntegrity: =================================== Date: 2017-01-27 10:10:05.454 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-01-27 10:10:04.896 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-01-27 10:10:04.088 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-01-27 10:10:03.622 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-01-27 10:10:03.161 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-01-27 10:10:02.664 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-01-27 10:10:02.183 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-01-27 10:10:01.344 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-01-27 10:10:00.873 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-01-27 10:10:00.415 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. ==================== Memory info =========================== Processor: Intel(R) Pentium(R) CPU G2020T @ 2.50GHz Percentage of memory in use: 45% Total physical RAM: 3985.32 MB Available physical RAM: 2186.41 MB Total Virtual: 8081.32 MB Available Virtual: 5866.66 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:917.81 GB) (Free:641.04 GB) NTFS Drive e: (ESP) (Fixed) (Total:0.48 GB) (Free:0.44 GB) FAT32 Drive w: (PBR Image) (Fixed) (Total:12.12 GB) (Free:0.21 GB) NTFS Drive x: (WINRETOOLS) (Fixed) (Total:0.49 GB) (Free:0.22 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 931.5 GB) (Disk ID: FA7524AE) Partition: GPT. ==================== End of Addition.txt ============================