Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15-03-2017 Ran by [removed] (15-04-2017 17:23:24) Running from C:\Users\[removed]\Downloads Windows 7 Home Premium Service Pack 1 (X64) (2014-03-21 17:38:11) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-1446484643-1097288149-3862632497-500 - Administrator - Disabled) Andre (S-1-5-21-1446484643-1097288149-3862632497-1000 - Administrator - Enabled) => C:\Users\Andre Guest (S-1-5-21-1446484643-1097288149-3862632497-501 - Limited - Enabled) => C:\Users\Guest HomeGroupUser$ (S-1-5-21-1446484643-1097288149-3862632497-1003 - Limited - Enabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 17.009.20044 - Adobe Systems Incorporated) Adobe Flash Player 25 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 25.0.0.148 - Adobe Systems Incorporated) Adobe Flash Player 25 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 25.0.0.148 - Adobe Systems Incorporated) Adobe Flash Player 25 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 25.0.0.148 - Adobe Systems Incorporated) AI Suite III (HKLM-x32\...\{D46DA5F0-25AD-4B77-98DA-6DD6AF39FBD9}) (Version: 1.00.44 - ASUSTeK Computer Inc.) Ansel (Version: 381.65 - NVIDIA Corporation) Hidden ASUS Boot Setting (HKLM-x32\...\{7AAE9187-C24F-4073-A951-36C370E7A3A5}) (Version: 1.00.09 - ASUSTeK Computer Inc.) ASUS Product Register Program (HKLM-x32\...\{C87D79F6-F813-4812-B7A9-CCCAAB8B1188}) (Version: 1.0.020 - ASUSTek Computer Inc.) CameraHelperMsi (x32 Version: 13.51.815.0 - Logitech) Hidden CCleaner (HKLM\...\CCleaner) (Version: 5.28 - Piriform) CPUID ASUS CPU-Z 1.63 (HKLM\...\CPUID ASUS CPU-Z_is1) (Version: 1.63 - CPUID, Inc.) Crossout Launcher 1.0.0.28 (HKLM-x32\...\CrossOutLauncher_is1) (Version: - ) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Entity Framework Designer for Visual Studio 2012 - enu (HKLM-x32\...\{AFA4B0BF-3289-495A-B949-BA91F39B1A44}) (Version: 11.1.21009.00 - Microsoft Corporation) erLT (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden Google Chrome (HKLM-x32\...\Google Chrome) (Version: 57.0.2987.133 - Google Inc.) Google Drive (HKLM-x32\...\{12ADFB82-D5A3-43E4-B2F4-FCD9B690315B}) (Version: 1.24.9931.5480 - Google, Inc.) Google Drive (HKLM-x32\...\{A1238426-ECDF-4639-BE2F-8D12A97AE23C}) (Version: 2.34.5075.1619 - Google, Inc.) Google Update Helper (x32 Version: 1.3.33.3 - Google Inc.) Hidden HitmanPro 3.7 (HKLM\...\HitmanPro37) (Version: 3.7.18.284 - SurfRight B.V.) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.0.0.1323 - Intel Corporation) Intel(R) Network Connections 18.1.59.0 (HKLM\...\PROSetDX) (Version: 18.1.59.0 - Intel) Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.0.0.1083 - Intel Corporation) Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 2.5.0.19 - Intel Corporation) Junk Mail filter update (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden Logitech G430 Driver (HKLM-x32\...\G430_Driver) (Version: 8.53.0.2 - Logitech) Logitech Gaming Software 8.76 (HKLM\...\Logitech Gaming Software) (Version: 8.76.155 - Logitech Inc.) Magical Jelly Bean KeyFinder (HKLM-x32\...\KeyFinder_is1) (Version: 2.0.10.12 - Magical Jelly Bean) Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes) Microsoft .NET Framework 4.5 Multi-Targeting Pack (HKLM-x32\...\{5CBFF3F3-2D40-34EE-BCA5-A95BC19E400D}) (Version: 4.5.50709 - Microsoft Corporation) Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation) Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation) Microsoft Office 365 - en-us (HKLM\...\O365HomePremRetail - en-us) (Version: 15.0.4911.1002 - Microsoft Corporation) Microsoft Office 365 ProPlus - en-us (HKLM\...\O365ProPlusRetail - en-us) (Version: 15.0.4911.1002 - Microsoft Corporation) Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office Outlook Connector (HKLM-x32\...\{95140000-007A-0409-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-1446484643-1097288149-3862632497-1000\...\OneDriveSetup.exe) (Version: 17.3.1171.0714 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft SQL Server 2012 Command Line Utilities (HKLM\...\{9D573E71-1077-4C7E-B4DB-4E22A5D2B48B}) (Version: 11.0.2100.60 - Microsoft Corporation) Microsoft SQL Server 2012 Data-Tier App Framework (HKLM\...\{36E619BC-A234-4EC3-849B-779A7C865A45}) (Version: 11.0.2316.0 - Microsoft Corporation) Microsoft SQL Server 2012 Data-Tier App Framework (HKLM-x32\...\{FBA6F90E-36EC-4FC9-9B25-3834E3BD46A8}) (Version: 11.0.2316.0 - Microsoft Corporation) Microsoft SQL Server 2012 Native Client (HKLM\...\{49D665A2-4C2A-476E-9AB8-FCC425F526FC}) (Version: 11.0.2100.60 - Microsoft Corporation) Microsoft SQL Server 2012 Transact-SQL Compiler Service (HKLM\...\{BEB0F91E-F2EA-48A1-B938-7857ABF2A93D}) (Version: 11.0.2100.60 - Microsoft Corporation) Microsoft SQL Server 2012 Transact-SQL ScriptDom (HKLM\...\{0E8670B8-3965-4930-ADA6-570348B67153}) (Version: 11.0.2100.60 - Microsoft Corporation) Microsoft SQL Server 2012 T-SQL Language Service (HKLM-x32\...\{6D6D43E5-218C-4B05-92D3-2240810F4760}) (Version: 11.0.2100.60 - Microsoft Corporation) Microsoft SQL Server Data Tools - enu (11.1.20627.00) (HKLM-x32\...\{FA804794-2CCB-4301-954F-2C2894698876}) (Version: 11.1.20627.00 - Microsoft Corporation) Microsoft SQL Server Data Tools Build Utilities - enu (11.1.20627.00) (HKLM-x32\...\{790E9425-8570-493F-9AE7-81AFC9E46930}) (Version: 11.1.20627.00 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23506 (HKLM-x32\...\{23daf363-3020-4059-b3ae-dc4ad39fed19}) (Version: 14.0.23506.0 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Movie Maker (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 40.0 - Mozilla) NVIDIA 3D Vision Controller Driver 369.04 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 369.04 - NVIDIA Corporation) NVIDIA 3D Vision Driver 381.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 381.65 - NVIDIA Corporation) NVIDIA GeForce Experience 3.4.0.70 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.4.0.70 - NVIDIA Corporation) NVIDIA Graphics Driver 381.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 381.65 - NVIDIA Corporation) NVIDIA HD Audio Driver 1.3.34.26 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.26 - NVIDIA Corporation) NVIDIA PhysX System Software 9.17.0329 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.17.0329 - NVIDIA Corporation) NvNodejs (Version: 3.4.0.70 - NVIDIA Corporation) Hidden NvTelemetry (Version: 2.4.5.0 - NVIDIA Corporation) Hidden NvvHci (Version: 2.02.0.5 - NVIDIA Corporation) Hidden Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4911.1002 - Microsoft Corporation) Hidden Office 15 Click-to-Run Licensing Component (Version: 15.0.4911.1002 - Microsoft Corporation) Hidden Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4911.1002 - Microsoft Corporation) Hidden OpenOffice 4.0.1 (HKLM-x32\...\{47F460DA-D1BE-4D85-8DF2-AA1F31D3445F}) (Version: 4.01.9714 - Apache Software Foundation) Prerequisites for SSDT (HKLM-x32\...\{9169C939-ED01-446A-BD0C-29873BAF4E48}) (Version: 11.0.2100.60 - Microsoft Corporation) puush (HKLM-x32\...\{C3592426-531E-4110-911D-BFECE2CE284B}) (Version: 1.0.0.0 - Dean Herbert) Razer Synapse (HKLM-x32\...\{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}) (Version: 2.20.17.302 - Razer Inc.) RealDownloader (x32 Version: 1.3.4 - RealNetworks, Inc.) Hidden RealNetworks - Microsoft Visual C++ 2008 Runtime (x32 Version: 9.0 - RealNetworks, Inc) Hidden RealNetworks - Microsoft Visual C++ 2010 Runtime (x32 Version: 10.0 - RealNetworks, Inc) Hidden RealPlayer (HKLM-x32\...\RealPlayer 16.0) (Version: 16.0.4 - RealNetworks) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6853 - Realtek Semiconductor Corp.) RealUpgrade 1.1 (x32 Version: 1.1.0 - RealNetworks, Inc.) Hidden SHIELD Streaming (Version: 7.1.0351 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: 3.4.0.70 - NVIDIA Corporation) Hidden Skype Click to Call (HKLM-x32\...\{873F8E7C-10E6-449F-BD7E-5FBA7C8E1C9B}) (Version: 8.5.0.9167 - Microsoft Corporation) Skype™ 7.32 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.32.104 - Skype Technologies S.A.) Star Citizen Launcher (HKU\S-1-5-21-1446484643-1097288149-3862632497-1000\...\Star Citizen Launcher) (Version: 00.01.00.00 - Cloud Imperium Games) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.1.3 - TeamSpeak Systems GmbH) Update for (KB2504637) (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}.KB2504637) (Version: 1 - Microsoft Corporation) VC_CRT_x64 (Version: 1.02.0000 - Intel Corporation) Hidden VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN) VMware Horizon Client (HKLM\...\{4CE5CE6C-14DA-41E7-8728-07C95F3CBC59}) (Version: 3.3.0.25749 - VMware, Inc.) War Thunder (HKLM\...\Steam App 236390) (Version: - Gaijin Entertainment) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3522.0110 - Microsoft Corporation) WinRAR 5.21 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH) World of Tanks - Common Test (HKU\S-1-5-21-1446484643-1097288149-3862632497-1000\...\{1EAC1D02-C6AC-4FA6-9A44-96258C37C812ct}_is1) (Version: - Wargaming.net) World of Tanks - Sandbox (HKU\S-1-5-21-1446484643-1097288149-3862632497-1000\...\{1EAC1D02-C6AC-4FA6-9A44-96258C37C812sb}_is1) (Version: - Wargaming.net) World of Tanks (HKU\S-1-5-21-1446484643-1097288149-3862632497-1000\...\{1EAC1D02-C6AC-4FA6-9A44-96258C37C812na}_is1) (Version: - Wargaming.net) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-1446484643-1097288149-3862632497-1000_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\Andre\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1446484643-1097288149-3862632497-1000_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\Andre\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1446484643-1097288149-3862632497-1000_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\Andre\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1446484643-1097288149-3862632497-1000_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\Andre\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1446484643-1097288149-3862632497-1000_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Andre\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\amd64\FileSyncApi64.dll (Microsoft Corporation) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {02918035-DDA4-4BED-8C7D-248E7BD9295A} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2016-11-01] (Microsoft Corporation) Task: {0437D84A-B20D-4B10-A6FF-9EED16C621E5} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2016-11-01] (Microsoft Corporation) Task: {075EFE02-1052-4DD4-A81D-24626E118C5A} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-02-23] (NVIDIA Corporation) Task: {1A8AD0C3-C48A-4C74-BDC1-68A1A3E3F1D3} - System32\Tasks\McAfeeLogon => C:\PROGRA~1\COMMON~1\McAfee\Platform\McUICnt.exe Task: {293D2280-40F5-49A2-8838-3ABCB0DD47F7} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_25_0_0_148_pepper.exe [2017-04-12] (Adobe Systems Incorporated) Task: {2B3CE3F2-EAEC-4454-8479-17066E08EDB7} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-02-23] (NVIDIA Corporation) Task: {2E07D462-08D1-48D9-92B3-FF73668A4D81} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-02-23] (NVIDIA Corporation) Task: {3641513F-6DBF-4062-A4A5-ECA1B7EF9A0C} - System32\Tasks\IEError => C:\Program Files (x86)\PCMATICPLUSSOL\virusIEFilter.exe Task: {46747C78-3B9E-4E4D-9F99-D1E2E9E76603} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-02-02] (Adobe Systems Incorporated) Task: {48204896-4D5A-41F6-AC27-F9D33AC545B2} - System32\Tasks\{C3D94928-6B50-40ED-B1FB-E8FF9556CC13} => Chrome.exe Task: {4F433990-68FE-420A-A6E8-0967D1FCEDFE} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2017-02-23] (NVIDIA Corporation) Task: {514B2A2F-52CB-4561-AD01-3B51673CC7FE} - System32\Tasks\{202B2D06-A1BB-4850-B112-6817867A86C2} => Chrome.exe Task: {5620A2AD-A5D9-4642-88E0-5F2332FFEDC2} - \OMYQNNDMU1 -> No File <==== ATTENTION Task: {59898CE7-7804-46F0-A0B5-8B7D553482BC} - System32\Tasks\4a752bbc-e718-4ff5-8948-5413ae8b7094 => C:\Users\Andre\AppData\Roaming\JV Update\SecureWebUpdate.exe Task: {5E8D3CA9-D40C-48F7-93B1-EE8342629471} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-02-23] (NVIDIA Corporation) Task: {64A41113-4EAC-4DFE-9C78-30FF9CFA7CA0} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2017-02-23] (NVIDIA Corporation) Task: {67953870-A5BE-4A58-B13B-0E8FE62C3FED} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2017-01-17] (Microsoft Corporation) Task: {6B78F60E-4BD5-435F-9AFB-D802B2C63FC5} - System32\Tasks\ASUS\ASUS WiFi GO! Server Execute => C:\Program Files (x86)\ASUS\AI Suite III\Remote GO!\AssistTools\WiFi GO! Server.exe [2013-05-02] (ASUSTeK Computer Inc.) Task: {6F9D3E92-D9BF-4372-8335-D26085F98F8A} - System32\Tasks\ASUS\ASUS Network iControl Help Execute => C:\Program Files (x86)\ASUS\AI Suite III\Network iControl\NetSvcHelp\NetSvcHelpEntry.exe [2013-02-07] (ASUSTeK Computer Inc.) Task: {71DC9D9F-CDD4-48AF-964D-9BD97E17EEE9} - System32\Tasks\{66672EF2-201C-478B-94DE-EBA349FBAE6B} => C:\Games\World_of_Tanks\WOTLauncher.exe [2017-02-28] (Wargaming.net) Task: {7722696F-081E-4607-8B23-C90FBAD574F2} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.) Task: {78B44602-6BFA-4D59-ABCC-B97B019E7630} - System32\Tasks\System Cleaner Pro Auto Start => C:\Program Files (x86)\System Cleaner Pro\SystemCleanerPro.exe Task: {7BCA793A-A90F-408C-8F5E-89355F3C5C3E} - System32\Tasks\GoogleUpdateTaskMachineUA1d2033175af73bc => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.) Task: {82179C9B-22EA-45A2-8F55-F3C339D91C71} - System32\Tasks\ASUS\ASUS AISuiteIII => C:\Program Files (x86)\ASUS\AI Suite III\AISuite3.exe [2013-05-07] (ASUSTeK Computer Inc.) Task: {8990BA10-F806-453F-99E9-D40E7E88BBA0} - System32\Tasks\{F341C99E-E0BE-4376-9A51-A7969BF849BF} => C:\Users\Andre\Desktop\RzSynapse.exe Task: {95DD40C0-B100-4658-A668-3E071E9F27E3} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-04-12] (Adobe Systems Incorporated) Task: {96FE272B-EF43-4EBB-A9EA-EFC75F126949} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonx86\Microsoft Shared\OFFICE15\OLicenseHeartbeat.exe [2016-11-01] (Microsoft Corporation) Task: {98C3075B-EAF4-4AE8-AC2A-147E51A18398} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2017-01-17] (Microsoft Corporation) Task: {A14F92E8-40B5-4511-858D-4117EB7B6B86} - System32\Tasks\Notify Helper => C:\Program Files (x86)\System Cleaner Pro\\NotifyHelper.exe Task: {A9F773A1-3D71-49CF-A77A-942A22480864} - System32\Tasks\ASUS\USB 3.0 Boost Service => C:\Program Files (x86)\ASUS\AI Suite III\USB 3.0 Boost\U3BoostSvr.exe [2011-09-09] () Task: {AA4255A4-978F-408D-B692-29A80D60F422} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-02-23] (NVIDIA Corporation) Task: {ACCAC8CD-37F0-403B-BDC5-7B33A9000A48} - System32\Tasks\ASUS\ASUS DIPAwayMode => C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DipAwayMode.exe [2013-05-09] () Task: {B2D33202-E98C-4E87-9261-60E9E9ACAD1B} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.) Task: {B6683C82-8E54-4244-8CD4-C942712D160F} - System32\Tasks\ASUS\ASUS Product Register Service => C:\Program Files (x86)\ASUS\APRP\aprp.exe [2013-01-25] (ASUSTek Computer Inc.) Task: {BA3BD538-67E3-42AC-BB29-2ACCD35C251E} - System32\Tasks\GoogleUpdateTaskMachineCore1d2033175a49e24 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.) Task: {C093B326-098D-4A22-8822-8F44DE25C88F} - System32\Tasks\McAfee Remediation (Prepare) => C:\Program Files\Common Files\AV\McAfee Anti-Virus And Anti-Spyware\upgrade.exe Task: {CA7E6569-0F90-4A28-8AB4-7ACB38CCC7C1} - System32\Tasks\833cc6d2-8ea1-410b-81e6-688ff4f32372 => C:\Users\Andre\AppData\Roaming\JV Update\JavaUpdater.exe Task: {D849F08F-6E85-443F-88F9-A48C39BE4B44} - System32\Tasks\AI_Updater => C:\Program Files (x86)\PCMATICPLUSSOL\updater.exe Task: {E2D8483A-1318-4ADB-90AB-2041EF27189F} - System32\Tasks\AVUXIBKKIYXHMGUE => C:\ProgramData\Service1291\Service1291.exe <==== ATTENTION Task: {E321276E-24D6-470D-9B12-19CAEBB0570B} - System32\Tasks\{85ABF6A7-85B7-4C0F-BB2A-9C7E8C36F013} => Chrome.exe Task: {E5D98751-D0D7-44C2-A41C-A5693232FCB5} - System32\Tasks\{F86A6569-80B7-4DE6-8E27-B7FB6DEE6154} => pcalua.exe -a "C:\Program Files (x86)\TeamSpeak 3 Client\package_inst.exe" -d C:\Users\Andre\Downloads -c "C:\Users\Andre\Downloads\VentriloSoundpack.ts3_soundpack" Task: {EE1B4110-0438-4648-ACA1-E7C5B8ECC4F1} - System32\Tasks\{E61F5019-F7C6-4EC2-8B12-DD1CB3996858} => Chrome.exe Task: {F09719EF-BCC5-437A-BBBF-8B3FAA806326} - System32\Tasks\{38458A0D-AFDD-4F06-9376-23BFDA4469BC} => Chrome.exe Task: {FCBCB174-755B-4FDA-B9BE-2DF2CB08C56C} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2017-03-03] (Piriform Ltd) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\AVUXIBKKIYXHMGUE.job => C:\ProgramData\Service1291\Service1291.exe <==== ATTENTION Task: C:\Windows\Tasks\Chrome Cleanup Tool logs upload retry.job => C:\Users\Andre\AppData\Local\Temp\FF21.exe <==== ATTENTION Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d0f03ba15ea696.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\McAfeeLogon.job => C:\PROGRA~1\COMMON~1\McAfee\Platform\McUICnt.exe ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== 2013-05-07 02:45 - 2013-05-07 02:45 - 00936728 _____ () C:\Program Files (x86)\ASUS\AXSP\1.01.02\atkexComSvc.exe 2014-05-30 13:50 - 2017-01-17 03:25 - 00117440 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll 2015-06-16 11:10 - 2015-06-16 11:10 - 00226240 _____ () C:\Program Files\Common Files\VMware\DeviceRedirectionCommon\ftnlsv.exe 2015-07-31 15:42 - 2015-07-31 15:42 - 06363792 _____ () C:\Program Files (x86)\VMware\ScannerRedirection\ftscanmgr.exe 2016-11-28 19:41 - 2017-02-23 13:35 - 01147328 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll 2016-11-28 19:41 - 2017-02-23 13:35 - 04489152 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\Poco.dll 2016-09-24 17:20 - 2016-09-24 17:21 - 00189264 _____ () C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe 2014-08-12 11:34 - 2014-08-12 11:34 - 00039056 _____ () C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe 2017-03-24 19:19 - 2017-01-31 07:34 - 08909512 _____ () C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\1033\GrooveIntlResource.dll 2014-03-21 13:50 - 2013-05-09 11:08 - 01218360 _____ () C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DipAwayMode.exe 2015-03-06 19:07 - 2015-03-06 19:07 - 00908568 _____ () C:\Program Files\Logitech Gaming Software\libGLESv2.dll 2015-11-20 16:41 - 2015-11-20 16:41 - 01095448 _____ () C:\Program Files\Logitech Gaming Software\platforms\qwindows.dll 2015-03-06 19:07 - 2015-03-06 19:07 - 00060184 _____ () C:\Program Files\Logitech Gaming Software\libEGL.dll 2015-11-20 16:41 - 2015-11-20 16:41 - 00240408 _____ () C:\Program Files\Logitech Gaming Software\imageformats\qjpeg.dll 2012-01-10 14:41 - 2015-03-29 23:04 - 00568904 _____ () C:\Users\Andre\Desktop\computer crap\puush.exe 2012-09-13 01:38 - 2012-09-13 01:38 - 00264040 _____ () Z:\Logitech\LWS\Webcam Software\CameraHelperShell.exe 2017-01-18 22:22 - 2017-01-18 22:22 - 00298448 _____ () C:\ProgramData\Razer\Synapse\RzStats\RzStats.Manager.exe 2014-03-21 13:50 - 2013-05-09 11:08 - 01221432 _____ () C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\EPUShortCut.exe 2017-03-23 09:47 - 2017-04-14 21:55 - 00176408 _____ () Z:\ts3\quazip.dll 2017-03-13 11:37 - 2017-03-13 11:37 - 00020248 _____ () Z:\ts3\libEGL.DLL 2017-03-13 11:37 - 2017-03-13 11:37 - 01975064 _____ () Z:\ts3\libGLESv2.dll 2017-03-23 09:47 - 2017-04-14 21:55 - 00107288 _____ () Z:\ts3\soundbackends\directsound_win64.dll 2017-03-23 09:47 - 2017-04-14 21:55 - 00128280 _____ () Z:\ts3\soundbackends\windowsaudiosession_win64.dll 2017-04-09 00:51 - 2017-04-09 00:51 - 00345880 _____ () C:\Users\Andre\AppData\Roaming\TS3Client\plugins\clientquery_plugin_win64.dll 2017-04-09 00:51 - 2017-04-09 00:51 - 00139264 _____ () C:\Users\Andre\AppData\Roaming\TS3Client\plugins\gamepad_joystick_win64.dll 2014-03-21 13:50 - 2017-04-15 16:35 - 00028672 _____ () C:\Program Files (x86)\ASUS\AXSP\1.01.02\PEbiosinterface32.dll 2014-03-21 13:50 - 2013-05-07 02:45 - 00104448 _____ () C:\Program Files (x86)\ASUS\AXSP\1.01.02\ATKEX.dll 2015-06-16 11:04 - 2015-06-16 11:04 - 00239552 _____ () C:\Program Files (x86)\Common Files\VMware\DeviceRedirectionCommon\ftnlapi.dll 2015-11-30 13:38 - 2017-02-23 13:35 - 00018880 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll 2016-11-28 19:41 - 2017-02-23 13:35 - 00900032 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\libprotobuf.dll 2016-11-28 19:41 - 2017-02-23 13:35 - 03774400 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\Poco.dll 2014-03-21 13:51 - 2012-05-02 18:04 - 00233472 _____ () C:\Program Files (x86)\ASUS\AI Suite III\Remote GO!\AssistTools\AudioProjection.dll 2014-03-21 13:51 - 2010-12-14 17:46 - 00067584 _____ () C:\Program Files (x86)\ASUS\AI Suite III\Remote GO!\AssistTools\CoreAudioCap.dll 2014-03-21 13:51 - 2012-10-03 15:01 - 00161792 _____ () C:\Program Files (x86)\ASUS\AI Suite III\Remote GO!\AssistTools\DLCapPP.dll 2014-03-21 13:51 - 2012-10-09 10:54 - 00425984 _____ () C:\Program Files (x86)\ASUS\AI Suite III\Remote GO!\AssistTools\awiscale.DLL 2014-03-21 13:51 - 2010-10-29 18:58 - 00221184 _____ () C:\Program Files (x86)\ASUS\AI Suite III\Remote GO!\AssistTools\JpegCD.DLL 2014-03-21 13:51 - 2012-07-25 17:39 - 02486272 _____ () C:\Program Files (x86)\ASUS\AI Suite III\Remote GO!\AssistTools\xH264E.DLL 2014-03-21 13:51 - 2012-01-12 16:44 - 00475136 _____ () C:\Program Files (x86)\ASUS\AI Suite III\Remote GO!\AssistTools\WiFiGO_HookKey.dll 2014-03-21 13:51 - 2013-03-21 17:07 - 00154112 _____ () C:\Program Files (x86)\InstallShield Installation Information\{104BE4B8-D1DB-4170-977B-364960893DC8}\CloudAPI\CloudAPI.dll 2014-03-21 13:51 - 2013-03-21 19:38 - 00716800 _____ () C:\Program Files (x86)\ASUS\AI Suite III\Remote GO!\AssistTools\WiMoveHelp.dll 2014-03-21 13:51 - 2012-04-25 14:47 - 00659456 _____ () C:\Program Files (x86)\ASUS\AI Suite III\Remote GO!\AssistTools\PhoneCtrlAPI.dll 2014-03-21 13:50 - 2013-05-07 15:45 - 00147456 _____ () C:\Program Files (x86)\ASUS\AI Suite III\AssistFunc.dll 2014-03-21 13:50 - 2013-03-13 17:12 - 00870912 _____ () C:\Program Files (x86)\ASUS\AI Suite III\AI Charger+\AIChargerPlus.dll 2014-03-21 13:50 - 2013-05-09 11:13 - 02686464 _____ () C:\Program Files (x86)\ASUS\AI Suite III\DIP4\dip4.dll 2014-03-21 13:51 - 2013-05-03 18:40 - 01111040 _____ () C:\Program Files (x86)\ASUS\AI Suite III\EZ Update\EasyUpdt.dll 2014-03-21 13:51 - 2013-04-02 17:32 - 01173504 _____ () C:\Program Files (x86)\ASUS\AI Suite III\Network iControl\Network iControl.dll 2014-03-21 13:51 - 2013-04-30 15:39 - 02051584 _____ () C:\Program Files (x86)\ASUS\AI Suite III\Remote GO!\WiFiGO.dll 2014-03-21 13:50 - 2013-05-07 02:45 - 00662016 ____R () C:\Program Files (x86)\ASUS\AAHM\1.00.22\aaHMLib.dll 2014-03-21 13:50 - 2013-05-07 15:45 - 00053248 _____ () C:\Program Files (x86)\ASUS\AI Suite III\cpuutil.dll 2014-03-21 13:50 - 2013-05-09 11:08 - 00010240 _____ () C:\Program Files (x86)\ASUS\AI Suite III\DIP4\IccHelper.dll 2014-03-21 13:52 - 2012-01-19 09:39 - 00028672 _____ () C:\Program Files (x86)\ASUS\AI Suite III\USB BIOS Flashback\PEInfo.dll 2014-03-21 13:50 - 2013-05-07 15:45 - 00208896 _____ () C:\Program Files (x86)\ASUS\AI Suite III\ImageHelper.dll 2014-03-21 13:50 - 2013-05-07 15:45 - 00253952 _____ () C:\Program Files (x86)\ASUS\AI Suite III\pngio.dll 2014-03-21 13:52 - 2010-09-23 11:51 - 00114688 _____ () C:\Program Files (x86)\ASUS\AI Suite III\USB BIOS Flashback\AsIdxParser.dll 2014-03-21 13:52 - 2010-02-25 14:01 - 00139264 _____ () C:\Program Files (x86)\ASUS\AI Suite III\USB BIOS Flashback\Aszip.dll 2014-03-21 13:50 - 2013-05-09 11:08 - 00497664 _____ () C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\vvc2.dll 2014-03-21 13:50 - 2013-05-09 11:08 - 00685056 _____ () C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\DIP4DIGIPowerControlAction.dll 2014-03-21 13:50 - 2013-05-09 11:08 - 00784384 _____ () C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\DIP4EpuAction.dll 2014-03-21 13:50 - 2013-05-09 11:08 - 00765952 _____ () C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\DIP4FanAction.dll 2014-03-21 13:50 - 2013-05-09 11:08 - 00769024 _____ () C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\DIP4TurboVEVOAction.dll 2014-03-21 13:50 - 2013-05-09 11:08 - 00904704 _____ () C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DIPDLL\UsbPowerManager.dll 2017-03-24 19:19 - 2017-01-31 05:14 - 08909512 _____ () C:\Program Files\Microsoft Office 15\root\Office15\1033\GrooveIntlResource.dll 2017-01-16 06:40 - 2017-01-16 06:40 - 00143824 _____ () C:\ProgramData\Razer\Synapse\CrashReporter\CrashRpt1402.dll 2012-09-13 01:38 - 2012-09-13 01:38 - 02144104 _____ () Z:\Logitech\LWS\Webcam Software\QtCore4.dll 2012-09-13 01:38 - 2012-09-13 01:38 - 07955304 _____ () Z:\Logitech\LWS\Webcam Software\QtGui4.dll 2012-09-13 01:38 - 2012-09-13 01:38 - 00341352 _____ () Z:\Logitech\LWS\Webcam Software\QtXml4.dll 2012-09-13 01:38 - 2012-09-13 01:38 - 00028008 _____ () Z:\Logitech\LWS\Webcam Software\imageformats\QGif4.dll 2012-09-13 01:38 - 2012-09-13 01:38 - 00127336 _____ () Z:\Logitech\LWS\Webcam Software\imageformats\QJpeg4.dll 2012-09-13 01:39 - 2012-09-13 01:39 - 00336232 _____ () C:\Program Files (x86)\Common Files\logishrd\LWSPlugins\LWS\Applets\CameraHelper\DevManagerCore.dll 2016-11-28 19:42 - 2017-02-23 13:34 - 65708992 _____ () C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\libcef.dll 2016-11-28 19:42 - 2017-02-23 09:30 - 00338488 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVAccountAPINode.node 2016-11-28 19:42 - 2017-02-23 09:30 - 00252352 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\DriverInstall.node 2016-11-28 19:42 - 2017-02-23 09:30 - 02443320 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\Downloader.node 2016-11-28 19:42 - 2017-02-23 09:30 - 00385592 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvGameShareAPINode.node 2016-11-28 19:42 - 2017-02-23 09:30 - 00543288 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvSpCapsAPINode.node 2016-11-28 19:42 - 2017-02-23 09:30 - 00468536 _____ () \\?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvGalleryAPINode.node 2017-04-09 23:40 - 2016-10-08 02:13 - 50656768 _____ () C:\Users\Andre\AppData\Local\razer\InGameEngine\cache\RzStats.Manager\cef\libcef.dll 2017-04-09 23:40 - 2016-10-08 02:13 - 01874944 _____ () C:\Users\Andre\AppData\Local\razer\InGameEngine\cache\RzStats.Manager\cef\libglesv2.dll 2017-04-09 23:40 - 2016-10-08 02:13 - 00075264 _____ () C:\Users\Andre\AppData\Local\razer\InGameEngine\cache\RzStats.Manager\cef\libegl.dll 2016-12-10 15:11 - 2016-09-06 12:00 - 05197312 _____ () C:\Users\Andre\AppData\Local\Google\Chrome\User Data\SwiftShader\3.3.0.1\libglesv2.dll 2016-12-10 15:11 - 2016-09-06 12:00 - 00147456 _____ () C:\Users\Andre\AppData\Local\Google\Chrome\User Data\SwiftShader\3.3.0.1\libegl.dll 2017-04-07 04:36 - 2017-04-07 04:36 - 67108352 _____ () C:\Users\Andre\AppData\Local\cbcb4c75\libcef.dll 2017-04-07 04:37 - 2017-04-07 04:37 - 17840216 _____ () C:\Users\Andre\AppData\Local\cbcb4c75\plugins\pepflashplayer32_24_0_0_221.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WeWatcherProxy => ""="service" ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) IE trusted site: HKU\S-1-5-21-1446484643-1097288149-3862632497-1000\...\sharepoint.com -> hxxps://uwplatt.sharepoint.com ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-13 21:34 - 2017-04-10 00:51 - 00000826 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-1446484643-1097288149-3862632497-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Andre\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg HKU\S-1-5-21-1446484643-1097288149-3862632497-501\Control Panel\Desktop\\Wallpaper -> C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.1.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 0) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == MSCONFIG\startupreg: ASUS WiFi GO! FileTransfer Execute => C:\Program Files (x86)\ASUS\AI Suite III\Remote GO!\AssistTools\WiFile\WiFileTransfer.exe MSCONFIG\startupreg: CCleaner => "C:\Program Files\CCleaner\CCleaner64.exe" /AUTO MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR MSCONFIG\startupreg: Dropbox => "C:\Program Files (x86)\Dropbox\Client\Dropbox.exe" /systemstartup MSCONFIG\startupreg: iPrint Event Monitor => C:\Windows\system32\iprntlgn.exe MSCONFIG\startupreg: iPrint Tray => C:\Windows\system32\iprntctl.exe TRAY_ICON ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{95C8BC8F-B97D-4ADD-8E88-674C680F9FE9}] => (Allow) LPort=2869 FirewallRules: [{BD0AFC16-34C4-44A2-9394-84EAE9532CC0}] => (Allow) LPort=1900 FirewallRules: [{706ED49C-E91E-4BFF-80F8-957B9B56BCCF}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{917B3907-45E5-413C-BF49-8A10CB3C3D3C}] => (Allow) C:\Users\Andre\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe FirewallRules: [{C3179C70-597D-40B7-9049-0D71A2C23CCA}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe FirewallRules: [{CC4EC0DB-508D-423A-B7E6-85A151381ADD}] => (Allow) LPort=2869 FirewallRules: [{8CC04D68-77DC-4735-8D9D-34B369B666C2}] => (Allow) LPort=1900 FirewallRules: [{2F5CAD67-1BCB-46A9-88EC-048204F4AFA8}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe FirewallRules: [{0867BDE5-C81D-4487-986B-37CCAF4CFBD4}] => (Allow) LPort=2869 FirewallRules: [{1845B969-B1C4-4208-86DE-6001DF2FD9BB}] => (Allow) LPort=1900 FirewallRules: [{3BEA4EE9-81AB-4C36-A78F-B6F5A4278C2B}] => (Allow) LPort=2869 FirewallRules: [{4DF5318B-1BC5-48A3-894E-69F8DE91AC41}] => (Allow) LPort=1900 FirewallRules: [{F1D5FF8F-3280-467C-8D27-209240AC1081}] => (Allow) Z:\Steam\Steam.exe FirewallRules: [{8DA88CFB-09EB-47DB-B775-C6E231289972}] => (Allow) Z:\Steam\Steam.exe FirewallRules: [TCP Query User{4EA76E49-6680-4A52-BB45-ECC765AA6366}C:\program files (x86)\asus\ai suite iii\aisuite3.exe] => (Block) C:\program files (x86)\asus\ai suite iii\aisuite3.exe FirewallRules: [UDP Query User{6BB9F884-C7BE-4C7E-9D52-C879A3380DC4}C:\program files (x86)\asus\ai suite iii\aisuite3.exe] => (Block) C:\program files (x86)\asus\ai suite iii\aisuite3.exe FirewallRules: [TCP Query User{44E26713-82B0-4365-B4AE-5A7DA15E02D8}Z:\steam\steamapps\common\war thunder\aces.exe] => (Allow) Z:\steam\steamapps\common\war thunder\aces.exe FirewallRules: [UDP Query User{11C30A23-867A-4738-8709-F511852BB85A}Z:\steam\steamapps\common\war thunder\aces.exe] => (Allow) Z:\steam\steamapps\common\war thunder\aces.exe FirewallRules: [TCP Query User{DCDAE093-D016-4A74-895C-0D7170874D79}Z:\star cit\starcitizen\citizenclient\bin64\starcitizen.exe] => (Allow) Z:\star cit\starcitizen\citizenclient\bin64\starcitizen.exe FirewallRules: [UDP Query User{1B8665B7-2F61-46D5-973A-A30C0B6ABE04}Z:\star cit\starcitizen\citizenclient\bin64\starcitizen.exe] => (Allow) Z:\star cit\starcitizen\citizenclient\bin64\starcitizen.exe FirewallRules: [TCP Query User{AF8303DE-17C1-4B6F-A67A-0F1F83FA4318}Z:\steam\steamapps\common\war thunder\aces.exe] => (Allow) Z:\steam\steamapps\common\war thunder\aces.exe FirewallRules: [UDP Query User{F5F0A90C-161E-4FD8-B0C8-C8AB8D03DE86}Z:\steam\steamapps\common\war thunder\aces.exe] => (Allow) Z:\steam\steamapps\common\war thunder\aces.exe FirewallRules: [{89FABDCB-94E2-4577-A95F-C511044542D0}] => (Allow) C:\Users\Andre\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{81C7D232-0BC1-4C95-B88B-CA7032BA32CA}] => (Allow) C:\Users\Andre\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{7CC0C4D7-E6B6-4EA5-8CA7-B3356E4DE28B}] => (Allow) Z:\Steam\bin\steamwebhelper.exe FirewallRules: [{00A6A625-4B93-4157-B9F2-9007111C3FE0}] => (Allow) Z:\Steam\bin\steamwebhelper.exe FirewallRules: [TCP Query User{AC886B7F-4E1D-465D-AD78-5861AFD07474}C:\games\world_of_tanks\worldoftanks.exe] => (Allow) C:\games\world_of_tanks\worldoftanks.exe FirewallRules: [UDP Query User{7C91E24F-82E3-40B4-84AF-ED199C0BE0CE}C:\games\world_of_tanks\worldoftanks.exe] => (Allow) C:\games\world_of_tanks\worldoftanks.exe FirewallRules: [TCP Query User{02FF73F4-EB21-4898-A1E9-42897AE66D48}C:\program files (x86)\asus\ai suite iii\aisuite3.exe] => (Allow) C:\program files (x86)\asus\ai suite iii\aisuite3.exe FirewallRules: [UDP Query User{6A98A584-1AD2-4553-B292-615D16AB32DE}C:\program files (x86)\asus\ai suite iii\aisuite3.exe] => (Allow) C:\program files (x86)\asus\ai suite iii\aisuite3.exe FirewallRules: [TCP Query User{71F3D227-26A6-42DA-BA66-ABC9439FAEBF}Z:\star cit\starcitizen\citizenclient\bin64\starcitizen.exe] => (Allow) Z:\star cit\starcitizen\citizenclient\bin64\starcitizen.exe FirewallRules: [UDP Query User{EC0DA8DD-7556-4796-A754-6C1A27C80785}Z:\star cit\starcitizen\citizenclient\bin64\starcitizen.exe] => (Allow) Z:\star cit\starcitizen\citizenclient\bin64\starcitizen.exe FirewallRules: [{8000DB06-BC23-43A2-A142-D3BBDA5A9714}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\outlook.exe FirewallRules: [{549AE17F-5A09-4CC6-8C19-547AEBCA6464}] => (Allow) C:\Program Files (x86)\VMware\VMware Horizon View Client\vmware-remotemks.exe FirewallRules: [{63835D1F-11BA-4E0E-996B-536649873DDB}] => (Allow) C:\Program Files (x86)\VMware\VMware Horizon View Client\vmware-remotemks.exe FirewallRules: [{72F68583-9539-4C15-B37D-5BD9773005E7}] => (Allow) C:\Program Files (x86)\VMware\VMware Horizon View Client\vmware-remotemks.exe FirewallRules: [{7C9B003B-2815-4361-AE5A-61201984DB68}] => (Allow) C:\Program Files (x86)\VMware\VMware Horizon View Client\vmware-remotemks.exe FirewallRules: [{8CB4EAF5-672F-4577-B63A-43FFB291DC0C}] => (Allow) C:\Program Files (x86)\VMware\VMware Horizon View Client\vmware-remotemks.exe FirewallRules: [{03E3A0E2-E20A-4E6D-88B6-065B7BB782A6}] => (Allow) C:\Program Files (x86)\VMware\VMware Horizon View Client\vmware-remotemks.exe FirewallRules: [{DEBC3199-5FD6-4B25-9BC8-01B26DA61E17}] => (Allow) C:\Program Files (x86)\VMware\VMware Horizon View Client\vmware-view.exe FirewallRules: [{CD78C9A0-3FA9-4858-AA21-0FD4E29DBF2A}] => (Allow) C:\Program Files (x86)\VMware\VMware Horizon View Client\vmware-view.exe FirewallRules: [{4BF2C591-9C5F-4B16-AA2E-EF0B89DC6C69}] => (Allow) C:\Program Files (x86)\VMware\VMware Horizon View Client\vmware-view.exe FirewallRules: [{F67FC697-846D-40FE-AD02-7E128DC119E9}] => (Allow) C:\Program Files (x86)\VMware\VMware Horizon View Client\vmware-view.exe FirewallRules: [{3F78A14C-0171-4536-A0EA-28F7520EDBD8}] => (Allow) C:\Program Files (x86)\VMware\VMware Horizon View Client\vmware-view.exe FirewallRules: [{B8DF37FF-6C23-4E65-8F20-5D3D1B125BE8}] => (Allow) C:\Program Files (x86)\VMware\VMware Horizon View Client\vmware-view.exe FirewallRules: [{F4F9DCEF-6225-4394-8E30-77C4287D6475}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe FirewallRules: [{33354D55-C336-4AC7-B6E1-D0C938855036}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe FirewallRules: [{97353DB1-04CE-4EAC-BE79-C5087FCD83D2}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe FirewallRules: [{055FDC88-EF93-453B-9D88-491F33C8AB20}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe FirewallRules: [{9C82CC9B-658B-43D7-8B7E-FD2E7FFC79A8}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\LaunchGFExperience.exe FirewallRules: [{8C570F85-8BD1-4812-AC7E-75C4D7EE0F1D}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\LaunchGFExperience.exe FirewallRules: [{43FFC350-B460-4A73-9CD2-B82CE7DE523E}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\LaunchGFExperience.exe FirewallRules: [{5C8FCD06-0C7A-4DED-B920-9DB5AB708CE7}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\LaunchGFExperience.exe FirewallRules: [{AF40731D-7C47-4B5B-92A7-7CF5284DBEEA}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\Lync.exe FirewallRules: [{D91265C7-6D12-4420-8EB5-E5B36DB66280}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\Lync.exe FirewallRules: [{DC6D4635-D4F6-4791-B1E8-F8C23AE15A1B}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\UcMapi.exe FirewallRules: [{85B37B54-9A14-4812-9434-2327DF328E82}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\UcMapi.exe FirewallRules: [TCP Query User{20E67A93-489B-49B5-B6F0-D798B1A49D02}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe FirewallRules: [UDP Query User{CFF8355F-9B81-4C6C-B310-2FC8764B7E22}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe FirewallRules: [{D8810DE8-0AB3-4496-AFAA-FD822772743C}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\NvContainer.exe FirewallRules: [{D058AADC-7BDB-4AD9-B13E-3126431F1A6D}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe FirewallRules: [{3210778F-1793-4DC6-8878-D19CDD8D28B5}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{5660E011-5AAF-4543-9FD6-205D52587214}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [TCP Query User{9B7BB42F-17F3-4953-BF27-2ACE96EE283C}C:\program files (x86)\crossout\launcher.exe] => (Allow) C:\program files (x86)\crossout\launcher.exe FirewallRules: [UDP Query User{8775ACBB-95BB-4594-97FE-6F0EB276FB24}C:\program files (x86)\crossout\launcher.exe] => (Allow) C:\program files (x86)\crossout\launcher.exe FirewallRules: [TCP Query User{723DDED9-E0C8-40AA-AAC6-1975F0205F48}C:\games\world_of_tanks\wotlauncher.exe] => (Allow) C:\games\world_of_tanks\wotlauncher.exe FirewallRules: [UDP Query User{98F7F9E9-FC68-49A5-AFED-91D6A1A6A637}C:\games\world_of_tanks\wotlauncher.exe] => (Allow) C:\games\world_of_tanks\wotlauncher.exe FirewallRules: [{856098E4-2785-4FB9-8EAD-6C1B19367EAF}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\NvContainer.exe FirewallRules: [{6DAC15A2-4EEE-4B2B-AEC2-F6284A61FE54}] => (Allow) Z:\Steam\SteamApps\common\War Thunder\launcher.exe FirewallRules: [{8535B74D-310E-450F-8780-B871DD3ED125}] => (Allow) Z:\Steam\SteamApps\common\War Thunder\launcher.exe FirewallRules: [TCP Query User{D35846F2-63DA-4C93-BABC-ABEDE635FCCF}Z:\steam\steamapps\common\war thunder\win64\aces.exe] => (Allow) Z:\steam\steamapps\common\war thunder\win64\aces.exe FirewallRules: [UDP Query User{661A720F-B204-4A5D-A5FD-5BC4D7DA480C}Z:\steam\steamapps\common\war thunder\win64\aces.exe] => (Allow) Z:\steam\steamapps\common\war thunder\win64\aces.exe FirewallRules: [{CCF4EDEE-D8C4-4BE1-8327-6625F2521AC4}] => (Allow) Z:\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{F5901704-A381-422E-98F1-4D5DE6E9FEEE}] => (Allow) Z:\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{C06C2626-EB0B-483C-BFD7-9D803A5035A2}] => (Allow) Z:\Steam\SteamApps\common\3DMark\bin\x86\3DMark.exe FirewallRules: [{FFCAAAF0-715B-421E-A94A-7A0378F81BAE}] => (Allow) Z:\Steam\SteamApps\common\3DMark\bin\x86\3DMark.exe FirewallRules: [{7709333C-EFCD-452D-A648-3A2AB5CF5545}] => (Allow) Z:\Steam\SteamApps\common\3DMark\bin\x64\3DMark.exe FirewallRules: [{823459F7-66CF-4CF9-9BBF-AA6543746D3F}] => (Allow) Z:\Steam\SteamApps\common\3DMark\bin\x64\3DMark.exe FirewallRules: [TCP Query User{9A4585CE-10B4-442F-860B-E44C8473BB9C}C:\program files\cloud imperium games\patcher\cigpatcher.exe] => (Allow) C:\program files\cloud imperium games\patcher\cigpatcher.exe FirewallRules: [UDP Query User{FD0B9673-9638-441B-BEFE-744DB7D017CF}C:\program files\cloud imperium games\patcher\cigpatcher.exe] => (Allow) C:\program files\cloud imperium games\patcher\cigpatcher.exe FirewallRules: [TCP Query User{55773A88-291F-49E9-A91A-5DEC6D5961FD}Z:\star cit\cloud imperium games\patcher\cigpatcher.exe] => (Allow) Z:\star cit\cloud imperium games\patcher\cigpatcher.exe FirewallRules: [UDP Query User{A76AFCCC-2488-4BAD-B164-4894147C8B81}Z:\star cit\cloud imperium games\patcher\cigpatcher.exe] => (Allow) Z:\star cit\cloud imperium games\patcher\cigpatcher.exe FirewallRules: [TCP Query User{C023A821-E0BA-4DCA-8974-7F4C28D1518D}Z:\star cit\cloud imperium games\starcitizen\public\bin64\starcitizen.exe] => (Allow) Z:\star cit\cloud imperium games\starcitizen\public\bin64\starcitizen.exe FirewallRules: [UDP Query User{2427504F-307F-4E19-910D-EF57E14CB6B0}Z:\star cit\cloud imperium games\starcitizen\public\bin64\starcitizen.exe] => (Allow) Z:\star cit\cloud imperium games\starcitizen\public\bin64\starcitizen.exe FirewallRules: [{B33F5A47-6A0B-4632-BF4B-91102DBB2D8A}] => (Allow) Z:\World of TanksSB\WoTLauncher.exe FirewallRules: [{C91F2B49-EC78-4442-8B0A-2069E82379B0}] => (Allow) Z:\World of TanksSB\WoTLauncher.exe FirewallRules: [{0F8A2848-B42E-496C-824E-0A3507D82FE9}] => (Allow) Z:\World of TanksSB\worldoftanks.exe FirewallRules: [{AE5D3B8A-A62F-46AB-9C6C-3202BE48FEB8}] => (Allow) Z:\World of TanksSB\worldoftanks.exe FirewallRules: [TCP Query User{9BDB31F9-DC99-4F85-BF89-46EBCA309A71}Z:\crossout\launcher.exe] => (Allow) Z:\crossout\launcher.exe FirewallRules: [UDP Query User{9D191445-B0BF-41EB-8EB6-2F4074B38223}Z:\crossout\launcher.exe] => (Allow) Z:\crossout\launcher.exe FirewallRules: [{41D60500-2BED-4D40-9768-D6598BFEAE23}] => (Allow) C:\Users\Andre\AppData\Local\Temp\Rar$EXa0.423\WGCheck.exe FirewallRules: [{FF637D39-ED78-4034-99C7-06763AC9015C}] => (Allow) C:\Users\Andre\AppData\Local\Temp\Rar$EXa0.423\WGCheck.exe FirewallRules: [{7FAC7B16-D8B7-4E0A-8F64-ECCA030F310F}] => (Allow) C:\Games\World_of_Tanks\WorldOfTanks.exe FirewallRules: [{961D043D-2C35-44FD-900C-8289C6E767A0}] => (Allow) C:\Games\World_of_Tanks\WorldOfTanks.exe FirewallRules: [{A4979033-48E9-4B5F-9C93-40A8CE3594EC}] => (Allow) C:\Games\World_of_Tanks\WoTLauncher.exe FirewallRules: [{41AE9801-3E03-4B87-AD72-6B08F6919C4F}] => (Allow) C:\Games\World_of_Tanks\WoTLauncher.exe FirewallRules: [{FF083CB1-F55F-40D0-88AB-6D39787020F8}] => (Allow) Z:\World_of_Tanks_CT\WoTLauncher.exe FirewallRules: [{E8D2D13E-5D28-4430-8AE1-AA2FF54EEC65}] => (Allow) Z:\World_of_Tanks_CT\WoTLauncher.exe FirewallRules: [{980EEC9E-9255-49F6-A27C-BD677D76F24C}] => (Allow) Z:\World_of_Tanks_CT\worldoftanks.exe FirewallRules: [{93B2DF3B-2589-49E0-B2E2-EBDE9591C545}] => (Allow) Z:\World_of_Tanks_CT\worldoftanks.exe FirewallRules: [{0AFBD817-45E5-4878-862A-BEFF3C6C7D14}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{F70ABD0B-3C79-4930-8C5C-799EAD02D24F}] => (Allow) C:\Program Files (x86)\ASUS\AI Suite III\Remote GO!\AssistTools\WiFi GO! Server.exe FirewallRules: [{2624F546-992A-48B8-B0AC-076A6C8ADDC5}] => (Allow) C:\Program Files (x86)\ASUS\AI Suite III\Remote GO!\AssistTools\WiFi GO! Server.exe FirewallRules: [{05962CEC-494A-4863-999C-C936DA58B355}] => (Allow) C:\Program Files (x86)\ASUS\AI Suite III\Remote GO!\ASUSDMS.exe FirewallRules: [{BD7DE8EE-6A65-4D20-970A-C71C327995F4}] => (Allow) C:\Program Files (x86)\ASUS\AI Suite III\Remote GO!\ASUSDMS.exe ==================== Restore Points ========================= 15-04-2017 03:00:15 Windows Update 15-04-2017 16:08:51 Windows Update 15-04-2017 17:00:19 Removed Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 15-04-2017 17:00:28 Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23506 15-04-2017 17:00:55 Removed Futuremark SystemInfo 15-04-2017 17:01:02 Removed Java 8 Update 51 ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (04/15/2017 04:37:02 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Error: (04/14/2017 01:51:12 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Error: (04/10/2017 10:43:58 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: worldoftanks.exe, version: 0.0.0.0, time stamp: 0x58cf8cb1 Faulting module name: worldoftanks.exe, version: 0.0.0.0, time stamp: 0x58cf8cb1 Exception code: 0xc0000005 Fault offset: 0x002daf13 Faulting process id: 0x63c Faulting application start time: 0x01d2b2744cd7fe95 Faulting application path: Z:\World of TanksSB\worldoftanks.exe Faulting module path: Z:\World of TanksSB\worldoftanks.exe Report Id: 17df7ce5-1e69-11e7-8698-74d02b97155f Error: (04/10/2017 08:10:41 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Error: (04/10/2017 07:56:22 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Activation context generation failed for "C:\Windows\Installer\{6935C750-2D8C-4705-B4F9-052F550D225D}\recordingmanager.exe". Dependent Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0" could not be found. Please use sxstrace.exe for detailed diagnosis. Error: (04/10/2017 07:56:22 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Activation context generation failed for "C:\Windows\Installer\{6935C750-2D8C-4705-B4F9-052F550D225D}\recordingmanager.exe". Dependent Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0" could not be found. Please use sxstrace.exe for detailed diagnosis. Error: (04/10/2017 07:48:48 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Error: (04/10/2017 07:42:58 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Activation context generation failed for "C:\Windows\Installer\{6935C750-2D8C-4705-B4F9-052F550D225D}\recordingmanager.exe". Dependent Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0" could not be found. Please use sxstrace.exe for detailed diagnosis. Error: (04/10/2017 07:42:58 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Activation context generation failed for "C:\Windows\Installer\{6935C750-2D8C-4705-B4F9-052F550D225D}\recordingmanager.exe". Dependent Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0" could not be found. Please use sxstrace.exe for detailed diagnosis. Error: (04/10/2017 06:07:28 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. System errors: ============= Error: (04/15/2017 04:36:21 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID {C97FCC79-E628-407D-AE68-A06AD6D8B4D1} and APPID {344ED43D-D086-4961-86A6-1106F4ACAD9B} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool. Error: (04/15/2017 04:35:11 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The RuntimeManager service failed to start due to the following error: The system cannot find the file specified. Error: (04/15/2017 04:35:10 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The Service Installer TrueKey service failed to start due to the following error: The system cannot find the file specified. Error: (04/15/2017 04:35:04 PM) (Source: volmgr) (EventID: 46) (User: ) Description: Crash dump initialization failed! Error: (04/15/2017 04:19:04 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: The Server service terminated with the following error: The data is invalid. Error: (04/15/2017 04:19:02 PM) (Source: Microsoft-Windows-Directory-Services-SAM) (EventID: 12291) (User: NT AUTHORITY) Description: SAM failed to start the TCP/IP or SPX/IPX listening thread Error: (04/15/2017 04:19:00 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The WinHTTP Web Proxy Auto-Discovery Service service failed to start due to the following error: The service did not start due to a logon failure. Error: (04/15/2017 04:19:00 PM) (Source: Service Control Manager) (EventID: 7038) (User: ) Description: The WinHttpAutoProxySvc service was unable to log on as NT AUTHORITY\LocalService with the currently configured password due to the following error: The security account manager (SAM) or local security authority (LSA) server was in the wrong state to perform the security operation. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC). Error: (04/15/2017 04:19:00 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The RuntimeManager service failed to start due to the following error: The system cannot find the file specified. Error: (04/15/2017 04:18:57 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The Service Installer TrueKey service failed to start due to the following error: The system cannot find the file specified. CodeIntegrity: =================================== Date: 2017-04-15 16:36:33.346 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\lgLowAudio.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2017-04-15 16:36:33.328 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\lgLowAudio.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2017-04-14 21:55:54.600 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\lgLowAudio.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2017-04-14 21:55:54.582 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\lgLowAudio.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2017-04-14 21:55:29.840 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\lgLowAudio.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2017-04-14 21:55:29.822 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\lgLowAudio.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2017-04-09 23:00:26.340 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\lgLowAudio.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2017-04-09 23:00:26.323 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\lgLowAudio.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2017-04-09 22:59:27.083 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\lgLowAudio.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2017-04-09 22:59:27.066 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\lgLowAudio.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i5-4670K CPU @ 3.40GHz Percentage of memory in use: 43% Total physical RAM: 8130.25 MB Available physical RAM: 4561.7 MB Total Virtual: 8128.45 MB Available Virtual: 4247.3 MB ==================== Drives ================================ Drive c: (SSD) (Fixed) (Total:111.69 GB) (Free:25.17 GB) NTFS Drive z: (1TBHD) (Fixed) (Total:931.51 GB) (Free:621.92 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 111.8 GB) (Disk ID: 2C35EAFA) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=111.7 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 62A3177F) Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS) ==================== End of Addition.txt ============================