Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15-03-2017 Ran by [removed] (17-03-2017 13:56:01) Running from C:\Users\[removed]\Desktop Windows 10 Home Version 1607 (X64) (2017-03-14 09:26:07) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-1540712080-551408199-3099575163-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-1540712080-551408199-3099575163-503 - Limited - Disabled) defaultuser0 (S-1-5-21-1540712080-551408199-3099575163-1000 - Limited - Disabled) => C:\Users\defaultuser0 Guest (S-1-5-21-1540712080-551408199-3099575163-501 - Limited - Disabled) Shannon (S-1-5-21-1540712080-551408199-3099575163-1001 - Administrator - Enabled) => C:\Users\Shannon ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: ESET Smart Security 10.0.390.0 (Enabled - Up to date) {EC1D6F37-E411-475A-DF50-12FF7FE4AC70} AS: ESET Smart Security 10.0.390.0 (Enabled - Up to date) {577C8ED3-C22B-48D4-E5E0-298D0463E6CD} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: ESET Personal firewall (Enabled) {D426EE12-AE7E-4602-F40F-BBCA8137EB0B} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) ESET Smart Security (HKLM\...\{5EEA8197-9CED-4AEA-925D-D32595AD3A57}) (Version: 10.0.390.0 - ESET, spol. s r.o.) Everything 1.2.1.371 (HKLM-x32\...\Everything) (Version: - ) Facebook Gameroom 1.3.1.3 (HKLM-x32\...\{7E155A45-DE1A-46E0-A6B2-10FE1D8501FC}) (Version: 1.3.1.3 - Facebook) Mozilla Firefox 52.0 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 52.0 (x86 en-US)) (Version: 52.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 52.0 - Mozilla) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7562 - Realtek Semiconductor Corp.) RogueKiller version 12.10.0.0 (HKLM\...\8B3D7924-ED89-486B-8322-E8594065D5CB_is1) (Version: 12.10.0.0 - Adlice Software) Synaptics ClickPad Driver (HKLM\...\SynTPDeinstKey) (Version: 19.2.4.10 - Synaptics Incorporated) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {5BF4A9B6-6D15-4C52-9BF5-4719E7EE6C02} - System32\Tasks\Microsoft\Windows\Windows Media Sharing\UpdateLibrary => %ProgramFiles%\Windows Media Player\wmpnscfg.exe Task: {D25EEB3E-056E-4BE6-B994-FC796A7E6A6C} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_ERROR_HB => C:\WINDOWS\system32\MRT.exe [2017-03-17] (Microsoft Corporation) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== 2016-07-16 04:42 - 2016-07-16 04:42 - 00231424 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll 2017-03-14 05:52 - 2016-12-09 03:29 - 02681200 _____ () C:\WINDOWS\system32\CoreUIComponents.dll 2017-03-14 05:52 - 2016-12-09 03:29 - 02681200 _____ () C:\WINDOWS\SYSTEM32\CoreUIComponents.dll 2016-11-20 11:11 - 2016-11-20 11:11 - 00134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll 2017-03-14 05:51 - 2016-12-21 00:09 - 00474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll 2017-03-14 05:51 - 2016-12-21 00:08 - 00693248 _____ () C:\Windows\ShellExperiences\MtcUvc.dll 2017-03-14 05:51 - 2016-12-20 23:54 - 09760768 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2017-03-14 05:51 - 2016-12-20 23:48 - 01401856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2017-03-14 05:51 - 2016-12-20 23:48 - 00757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll 2017-03-14 05:51 - 2016-12-20 23:48 - 01033216 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll 2017-03-14 05:51 - 2016-12-20 23:48 - 02424320 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll 2017-03-14 05:51 - 2016-12-20 23:53 - 04853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll 2009-03-12 18:18 - 2009-03-12 18:18 - 00602624 _____ () C:\Program Files (x86)\Everything\Everything.exe 2017-03-14 05:58 - 2017-03-14 06:00 - 10650112 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_11701.1001.79.0_x64__8wekyb3d8bbwe\WinStore.Entertainment.Mobile.dll 2017-03-14 05:58 - 2017-03-14 06:00 - 02653184 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_11701.1001.79.0_x64__8wekyb3d8bbwe\MS.Entertainment.Common.Mobile.dll 2017-03-14 05:58 - 2017-03-14 06:00 - 00761344 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_11701.1001.79.0_x64__8wekyb3d8bbwe\WinStore.Vui.dll 2017-02-15 17:58 - 2017-02-15 17:58 - 00752640 _____ () C:\Users\Shannon\AppData\Local\Facebook\Games\CefSharp.BrowserSubprocess.Core.dll 2017-02-15 17:58 - 2017-02-15 17:58 - 67197440 _____ () C:\Users\Shannon\AppData\Local\Facebook\Games\libcef.dll 2017-02-15 17:58 - 2017-02-15 17:58 - 01162752 _____ () C:\Users\Shannon\AppData\Local\Facebook\Games\CefSharp.Core.dll 2017-02-15 17:58 - 2017-02-15 17:58 - 01886208 _____ () C:\Users\Shannon\AppData\Local\Facebook\Games\libglesv2.dll 2017-02-15 17:58 - 2017-02-15 17:58 - 00078848 _____ () C:\Users\Shannon\AppData\Local\Facebook\Games\libegl.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2017-03-14 01:26 - 2017-03-14 01:22 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-1540712080-551408199-3099575163-1001\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\web\wallpaper\Windows\img0.jpg DNS Servers: 192.168.1.254 - [removed] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [{4C518804-4D7A-4CFD-871C-56CFF8A8424E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{8E8EAC9E-004A-43A4-ACBE-5559062192F4}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Restore Points ========================= ATTENTION: System Restore is disabled ==================== Faulty Device Manager Devices ============= Name: Trusted Platform Module 2.0 Description: Trusted Platform Module 2.0 Class Guid: {d94ee5d8-d189-4994-83d2-f68d7d41b0e6} Manufacturer: (Standard) Service: TPM Problem: : A driver (service) for this device has been disabled. An alternate driver may be providing this functionality (Code 32) Resolution: The start type for this driver is set to disabled in the registry. Uninstall the driver from Device Manager, and then scan for new hardware to install the driver again. If this does not work, you might have to change the device start type parameter in the registry. ==================== Event log errors: ========================= Application errors: ================== Error: (03/17/2017 01:53:32 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DESKTOP-4EL592D) Description: Activation of app Microsoft.MicrosoftEdge_8wekyb3d8bbwe!MicrosoftEdge failed with error: -2147023170 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (03/17/2017 01:53:31 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: MicrosoftEdge.exe, version: 11.0.14393.693, time stamp: 0x585a26c4 Faulting module name: eModel.dll, version: 11.0.14393.693, time stamp: 0x585a27a4 Exception code: 0xc0000409 Fault offset: 0x00000000000d4ad0 Faulting process id: 0x193c Faulting application start time: 0x01d29f60886754b6 Faulting application path: C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe Faulting module path: C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\eModel.dll Report Id: 5db01676-a1a7-42fe-bf43-705d2cd6208c Faulting package full name: Microsoft.MicrosoftEdge_38.14393.0.0_neutral__8wekyb3d8bbwe Faulting package-relative application ID: MicrosoftEdge Error: (03/17/2017 01:50:38 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DESKTOP-4EL592D) Description: Activation of app Microsoft.MicrosoftEdge_8wekyb3d8bbwe!MicrosoftEdge failed with error: -2147023170 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (03/17/2017 01:50:36 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: MicrosoftEdge.exe, version: 11.0.14393.693, time stamp: 0x585a26c4 Faulting module name: eModel.dll, version: 11.0.14393.693, time stamp: 0x585a27a4 Exception code: 0xc0000409 Fault offset: 0x00000000000d4ad0 Faulting process id: 0x580 Faulting application start time: 0x01d29f602011d70e Faulting application path: C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe Faulting module path: C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\eModel.dll Report Id: 5698b107-7c5c-4359-95c3-19c903ec85c4 Faulting package full name: Microsoft.MicrosoftEdge_38.14393.0.0_neutral__8wekyb3d8bbwe Faulting package-relative application ID: MicrosoftEdge Error: (03/17/2017 01:50:15 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DESKTOP-4EL592D) Description: Activation of app Microsoft.MicrosoftEdge_8wekyb3d8bbwe!MicrosoftEdge failed with error: -2147023170 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (03/17/2017 01:50:14 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: MicrosoftEdge.exe, version: 11.0.14393.693, time stamp: 0x585a26c4 Faulting module name: eModel.dll, version: 11.0.14393.693, time stamp: 0x585a27a4 Exception code: 0xc0000409 Fault offset: 0x00000000000d4ad0 Faulting process id: 0xf4 Faulting application start time: 0x01d29f6012c73d7c Faulting application path: C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe Faulting module path: C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\eModel.dll Report Id: 3c9acb0f-1e47-40df-a491-e56cfe7cb4ef Faulting package full name: Microsoft.MicrosoftEdge_38.14393.0.0_neutral__8wekyb3d8bbwe Faulting package-relative application ID: MicrosoftEdge Error: (03/17/2017 01:05:27 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: svchost.exe_RasMan, version: 10.0.14393.0, time stamp: 0x57899b1c Faulting module name: ntdll.dll, version: 10.0.14393.479, time stamp: 0x5825887f Exception code: 0xc0000005 Fault offset: 0x000000000002f7db Faulting process id: 0x8ac Faulting application start time: 0x01d29f59d127d0c9 Faulting application path: C:\WINDOWS\system32\svchost.exe Faulting module path: C:\WINDOWS\SYSTEM32\ntdll.dll Report Id: 24f665c4-c550-4fed-9c49-e70fb2cc527d Faulting package full name: Faulting package-relative application ID: Error: (03/17/2017 01:04:16 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: svchost.exe_RasMan, version: 10.0.14393.0, time stamp: 0x57899b1c Faulting module name: ntdll.dll, version: 10.0.14393.479, time stamp: 0x5825887f Exception code: 0xc0000005 Fault offset: 0x000000000002f7db Faulting process id: 0x7f4 Faulting application start time: 0x01d29f322f175e39 Faulting application path: C:\WINDOWS\system32\svchost.exe Faulting module path: C:\WINDOWS\SYSTEM32\ntdll.dll Report Id: 169b156a-a3f4-48b8-b816-e56637d555d5 Faulting package full name: Faulting package-relative application ID: Error: (03/17/2017 10:56:34 AM) (Source: Perflib) (EventID: 1008) (User: ) Description: The Open Procedure for service "BITS" in DLL "C:\Windows\System32\bitsperf.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code. Error: (03/17/2017 10:46:46 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DESKTOP-4EL592D) Description: Activation of app Microsoft.Getstarted_8wekyb3d8bbwe!App failed with error: -2147024894 See the Microsoft-Windows-TWinUI/Operational log for additional information. System errors: ============= Error: (03/17/2017 01:56:54 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-4EL592D) Description: The server {4991D34B-80A1-4291-83B6-3328366B9097} did not register with DCOM within the required timeout. Error: (03/17/2017 01:54:54 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-4EL592D) Description: The server {4991D34B-80A1-4291-83B6-3328366B9097} did not register with DCOM within the required timeout. Error: (03/17/2017 01:52:54 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-4EL592D) Description: The server {4991D34B-80A1-4291-83B6-3328366B9097} did not register with DCOM within the required timeout. Error: (03/17/2017 01:50:54 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-4EL592D) Description: The server {4991D34B-80A1-4291-83B6-3328366B9097} did not register with DCOM within the required timeout. Error: (03/17/2017 01:38:00 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (03/17/2017 01:34:10 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: The Windows Update service terminated with the following error: %%2147953403 = A non-recoverable error occurred during a database lookup. Error: (03/17/2017 01:15:51 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The Windows Search service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service. Error: (03/17/2017 01:10:42 PM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY) Description: The server {E60687F7-01A1-40AA-86AC-DB1CBF673334} did not register with DCOM within the required timeout. Error: (03/17/2017 01:08:42 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: The Windows Update service terminated with the following error: %%2147953403 = A non-recoverable error occurred during a database lookup. Error: (03/17/2017 01:08:01 PM) (Source: Service Control Manager) (EventID: 7024) (User: ) Description: The Server service terminated with the following service-specific error: %%2182 = The requested service has already been started. CodeIntegrity: =================================== Date: 2017-03-17 13:55:10.368 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\facecredentialprovider.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2017-03-17 13:55:10.355 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\facecredentialprovider.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2017-03-17 13:55:03.277 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\aadcloudap.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2017-03-17 13:55:03.265 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\aadcloudap.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2017-03-17 13:51:08.111 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\facecredentialprovider.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2017-03-17 13:51:08.095 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\facecredentialprovider.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2017-03-17 13:50:54.370 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\aadcloudap.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2017-03-17 13:50:54.355 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\aadcloudap.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2017-03-17 13:26:41.563 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\facecredentialprovider.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2017-03-17 13:26:41.546 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\facecredentialprovider.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. ==================== Memory info =========================== Processor: Intel(R) Celeron(R) CPU N3050 @ 1.60GHz Percentage of memory in use: 89% Total physical RAM: 1905.27 MB Available physical RAM: 203.03 MB Total Virtual: 3057.27 MB Available Virtual: 683.7 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:28.57 GB) (Free:7.58 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 29.1 GB) (Disk ID: C89E2E1A) Partition: GPT. ==================== End of Addition.txt ============================