Additional scan result of Farbar Recovery Scan Tool (x64) Version: 14-05-2017 Ran by [removed] (19-05-2017 18:58:02) Running from C:\Users\[removed]\Desktop Windows 10 Home Version 1607 (X64) (2016-08-03 17:41:58) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-356737074-1852378437-2674757308-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-356737074-1852378437-2674757308-503 - Limited - Disabled) Guest (S-1-5-21-356737074-1852378437-2674757308-501 - Limited - Disabled) logo (S-1-5-21-356737074-1852378437-2674757308-1001 - Administrator - Enabled) => C:\Users\logo ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF} AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 17.009.20044 - Adobe Systems Incorporated) Adobe Digital Editions 4.5 (HKLM-x32\...\Adobe Digital Editions 4.5) (Version: 4.5.1 - Adobe Systems Incorporated) Adobe Flash Player 25 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 25.0.0.171 - Adobe Systems Incorporated) Avast Free Antivirus (HKLM-x32\...\Avast Antivirus) (Version: 17.3.2291 - AVAST Software) Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.) Extended Asian Language font pack for Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-2530-0000-AC0F074E4100}) (Version: 15.007.20033 - Adobe Systems Incorporated) GCstar 1.6.1 (HKLM-x32\...\GCstar) (Version: 1.6.1 - Tian) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 20.19.15.4549 - Intel Corporation) Java 8 Update 131 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180131F0}) (Version: 8.0.1310.11 - Oracle Corporation) KeePass Password Safe 2.35 (HKLM-x32\...\KeePassPasswordSafe2_is1) (Version: 2.35 - Dominik Reichl) MAGIX Slideshow Maker 2 (HKLM-x32\...\MAGIX_MSI_Slideshow_Maker_2) (Version: 2.0.0.6 - MAGIX AG) MAGIX Slideshow Maker 2 (x32 Version: 2.0.0.6 - MAGIX AG) Hidden Malwarebytes version 3.1.2.1733 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.1.2.1733 - Malwarebytes) MEGAsync (HKLM-x32\...\MEGAsync) (Version: - Mega Limited) Microsoft Office 365 ProPlus - en-us (HKLM\...\O365ProPlusRetail - en-us) (Version: 16.0.7967.2161 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation) Mozilla Firefox 53.0.2 (x86 en-GB) (HKLM-x32\...\Mozilla Firefox 53.0.2 (x86 en-GB)) (Version: 53.0.2 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 53.0.2 - Mozilla) Office 16 Click-to-Run Extensibility Component (x32 Version: 16.0.7967.2161 - Microsoft Corporation) Hidden Office 16 Click-to-Run Extensibility Component 64-bit Registration (Version: 16.0.7967.2161 - Microsoft Corporation) Hidden Office 16 Click-to-Run Licensing Component (Version: 16.0.7967.2161 - Microsoft Corporation) Hidden Office 16 Click-to-Run Localization Component (x32 Version: 16.0.7668.2066 - Microsoft Corporation) Hidden PeaZip 6.0.3 (WIN64) (HKLM\...\{5A2BC38A-406C-4A5B-BF45-6991F9A05325}_is1) (Version: 6.0.3 - Giorgio Tani) PeaZip 6.2.0 (HKLM-x32\...\{5A2BC38A-406C-4A5B-BF45-6991F9A05325}_is1) (Version: 6.2.0 - Giorgio Tani) SafeZone Stable 3.55.2393.596 (x32 Version: 3.55.2393.596 - Avast Software) Hidden Samsung Universal Print Driver 2 (HKLM-x32\...\Samsung Universal Print Driver 2) (Version: 2.50.06.00 - Samsung Electronics Co., Ltd.) Skype™ 7.36 (HKLM-x32\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.36.101 - Skype Technologies S.A.) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 19.0.16.3 - Synaptics Incorporated) TOSHIBA Battery Check Utility (HKLM-x32\...\{5468E297-7EF8-4CB3-A091-F8714147793F}) (Version: 1.00.01.01 - Toshiba Corporation) TOSHIBA Service Station (HKLM\...\{FBFCEEA5-96EA-4C8E-9262-43CBBEBAE413}) (Version: 2.6.8 - Toshiba Corporation) Toshiba TEMPRO (HKLM-x32\...\{E4C7D9D7-19D4-4623-AF0C-EA313C466411}) (Version: 5.0.0 - Toshiba Europe GmbH) VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.4 - VideoLAN) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {269EA04E-DEE0-4BEC-9805-98574F1FDFBF} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-05-04] (Microsoft Corporation) Task: {350EF588-E82A-42FC-93C8-75BAF78EECF0} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2017-05-16] (Microsoft Corporation) Task: {36C1735B-52A5-411A-904E-87541ED42EE6} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-04-25] (Adobe Systems Incorporated) Task: {5EEE1388-2661-42D0-8EDC-32D1A42E1EB1} - System32\Tasks\TOSHIBA\Service Station => C:\Program Files\TOSHIBA\Toshiba Service Station\ToshibaServiceStation.exe [2013-07-31] (TOSHIBA Corporation) Task: {6048B96A-FBA3-4626-915A-5FCDC12F36C8} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2017-05-16] (Microsoft Corporation) Task: {95936974-1DDD-477F-A6D6-AC3C12AFE389} - System32\Tasks\Toshiba\CommonNotifier => C:\Program Files (x86)\Toshiba TEMPRO\Toshiba.Tempro.UI.CommonNotifier.exe [2015-11-17] (Toshiba Europe GmbH) Task: {967C1316-4D2C-4D24-A5A3-A5E5F9D9301E} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2017-04-13] (AVAST Software) Task: {AA0CDCC5-604B-45D3-87E3-A52EBAC0EEA9} - System32\Tasks\{8311165E-2FF4-4101-B9D4-6EC2E67EADDC} => pcalua.exe -a "C:\Program Files (x86)\Common Files\Truebam\uninstall.exe" -c shuz -f "C:\Program Files (x86)\Common Files\Truebam\uninstall.dat" -a uninstallme E3067B17-2F48-4294-982B-7E7E6BE64BF5 DeviceId=7686217e-8691-29b0-9ddb-6d4f297b6565 BarcodeId=51198003 ChannelId=3 DistributerName=APSFWakeNet Task: {AE2BA8B2-78B4-49FA-B14A-8810738294BD} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-05-12] (Adobe Systems Incorporated) Task: {B4682188-3721-426D-BA71-0B0BDFC2903C} - System32\Tasks\GridinSoft Anti-Malware => C:\Program Files\GridinSoft Anti-Malware\gsam.exe Task: {B59D82D6-FF67-4799-8F1E-F01FA1B48BCF} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2017-05-16] (Microsoft Corporation) Task: {C29A4D9E-4C24-4DAF-92DD-20F1114A7BE4} - System32\Tasks\Grkuplitersy Schedule => C:\Program Files (x86)\Bernither\reersether.exe Task: {C30A8653-D6B4-4122-A8A1-3866255A1AA3} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2017-05-09] (AVAST Software) Task: {D4A0C26B-38C0-461F-98F4-E30B7BFF219D} - System32\Tasks\SafeZone scheduled Autoupdate 1467378093 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2017-03-22] (Avast Software) Task: {D55D931F-8ED8-4E9A-87E0-15A38D1EA1C0} - \Reekury -> No File <==== ATTENTION Task: {DD340621-14DF-4B30-A272-29BB718CAB2C} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-05-04] (Microsoft Corporation) Task: {ED197AD7-0032-4C6B-8426-2168F13F8970} - \{5648A733-2EDA-3AD6-7368-9F607B5CB742} -> No File <==== ATTENTION (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) Shortcut: C:\Users\logo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\GCstar.lnk -> C:\Program Files (x86)\GCstar\bin\gcstar.bat () ==================== Loaded Modules (Whitelisted) ============== 2016-07-16 13:42 - 2016-07-16 13:42 - 00231424 _____ () C:\Windows\SYSTEM32\ism32k.dll 2017-04-12 08:34 - 2017-03-28 08:22 - 02681200 _____ () C:\Windows\system32\CoreUIComponents.dll 2016-07-02 07:33 - 2014-04-16 10:22 - 00029184 _____ () C:\Windows\System32\usp02l.dll 2016-07-02 07:35 - 2014-11-26 13:07 - 00118576 _____ () C:\WINDOWS\SysWOW64\SecUPDUtilSvc.exe 2017-04-12 08:34 - 2017-03-28 08:22 - 02681200 _____ () C:\Windows\SYSTEM32\CoreUIComponents.dll 2016-06-30 10:23 - 2017-02-04 20:40 - 00592384 _____ () C:\Users\logo\AppData\Local\MEGAsync\ShellExtX64.dll 2017-03-06 20:55 - 2017-03-06 20:55 - 00959168 _____ () C:\Users\logo\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_3\amd64\ClientTelemetry.dll 2017-03-03 11:01 - 2017-05-16 08:18 - 08931008 _____ () C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\1033\GrooveIntlResource.dll 2016-09-18 12:19 - 2016-09-07 06:56 - 00134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll 2017-03-15 09:29 - 2017-03-04 08:31 - 00474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll 2016-01-07 18:44 - 2016-12-02 08:32 - 00401912 _____ () C:\Windows\system32\igfxTray.exe 2017-03-15 09:30 - 2017-03-04 08:12 - 09760768 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2017-03-15 09:30 - 2017-03-04 08:05 - 01401856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2017-03-15 09:30 - 2017-03-04 08:05 - 00757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll 2017-04-12 08:34 - 2017-03-28 07:07 - 01033216 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll 2017-04-12 08:34 - 2017-03-28 07:08 - 02424320 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll 2017-04-12 08:35 - 2017-03-28 07:11 - 04853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll 2017-05-19 12:40 - 2017-05-19 10:48 - 00098456 _____ () C:\Program Files (x86)\Firefox\bin\FirefoxUpdate.exe 2017-05-09 13:46 - 2017-05-09 13:46 - 00170216 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll 2017-05-09 13:47 - 2017-05-09 13:47 - 00997896 _____ () C:\Program Files\AVAST Software\Avast\AvChrome.dll 2017-05-09 13:47 - 2017-05-09 13:47 - 67717632 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2017-05-09 13:46 - 2017-05-09 13:46 - 00176992 _____ () C:\Program Files\AVAST Software\Avast\event_routing_rpc.dll 2017-05-09 13:46 - 2017-05-09 13:46 - 00223224 _____ () C:\Program Files\AVAST Software\Avast\tasks_core.dll 2017-05-09 13:46 - 2017-05-09 13:46 - 00291824 _____ () C:\Program Files\AVAST Software\Avast\gaming_mode_ui.dll 2017-05-09 13:46 - 2017-05-09 13:46 - 00684656 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) IE trusted site: HKU\S-1-5-21-356737074-1852378437-2674757308-1001\...\sharepoint.com -> hxxps://ucd-files.sharepoint.com ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2016-06-29 16:52 - 2017-05-09 13:29 - 00000027 _____ C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-356737074-1852378437-2674757308-1001\Control Panel\Desktop\\Wallpaper -> c:\users\logo\appdata\roaming\mozilla\firefox\desktop background.bmp DNS Servers: 8.8.8.8 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == HKLM\...\StartupApproved\Run32: => "Wondershare Helper Compact.exe" HKU\S-1-5-21-356737074-1852378437-2674757308-1001\...\StartupApproved\Run: => "Skype" HKU\S-1-5-21-356737074-1852378437-2674757308-1001\...\StartupApproved\Run: => "SpybotPostWindows10UpgradeReInstall" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{E0A2C999-469C-48BB-9378-7DEF161311BA}] => (Allow) C:\Program Files (x86)\Samsung\Samsung Universal Print Driver 2\PrinterSelector\SUPDApp.exe FirewallRules: [{54C79331-DEB8-47D3-94D0-29D40C4A2121}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{D04B13F3-3490-42A5-8984-714A8D1267FD}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\Lync.exe FirewallRules: [{2872C0A4-ADDA-4C15-AA99-AE7F0DAB9464}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\UcMapi.exe FirewallRules: [TCP Query User{9C9D3245-7BB6-4659-BD79-65FC9B4B4366}C:\windows.old\program files (x86)\popcorn time\chromecast\node.exe] => (Allow) C:\windows.old\program files (x86)\popcorn time\chromecast\node.exe FirewallRules: [UDP Query User{07C85452-2508-4057-8442-0DCC59E29E73}C:\windows.old\program files (x86)\popcorn time\chromecast\node.exe] => (Allow) C:\windows.old\program files (x86)\popcorn time\chromecast\node.exe FirewallRules: [TCP Query User{396EA4B1-C438-44E1-9CC5-A4EC07176811}C:\windows.old\program files (x86)\popcorn time\popcorntimedesktop.exe] => (Allow) C:\windows.old\program files (x86)\popcorn time\popcorntimedesktop.exe FirewallRules: [UDP Query User{5D26BF9C-52C8-48B5-8498-5D473D3F1FF5}C:\windows.old\program files (x86)\popcorn time\popcorntimedesktop.exe] => (Allow) C:\windows.old\program files (x86)\popcorn time\popcorntimedesktop.exe FirewallRules: [{7B766080-06EB-49B7-AB50-E38BCC136644}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe FirewallRules: [{3EB0B1D7-283E-4DE0-9B22-86B79BFA246A}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe FirewallRules: [{F93AEE74-6B73-4134-A2F1-5D4D0278BC39}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{E5A2178E-1032-4B93-BAE9-916DD24D477A}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{3F1B2303-999B-4590-89F8-EE2CF12C3C4A}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{851DC6C7-F4E5-4AC4-8BF9-D4DD93FB20C8}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{8C8063DF-E17B-4032-A7B4-2EFD93567243}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe FirewallRules: [{5B5289A7-EF9F-421B-A896-FB8C5FEBCE93}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe FirewallRules: [{DC4757C6-1426-4A9E-B803-D41B929763AB}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe FirewallRules: [{D879BD20-87D6-48B9-A750-BC0EE3EAEFD3}] => (Allow) C:\Program Files\AVAST Software\SZBrowser\3.55.2393.596\SZBrowser.exe FirewallRules: [{9751EAB7-3778-40DD-9CAC-70CD6A58B1CB}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{7828DE73-9E96-4156-8D30-AB2DE5D02B88}] => (Allow) C:\Program Files\AVAST Software\SZBrowser\3.55.2393.596_0\SZBrowser.exe FirewallRules: [{3844F7B7-760F-437D-9D44-80CDF442D04C}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{E3B21068-3698-4255-AF9E-53A22FF610F3}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{682DA7E8-7478-4759-95DE-598C770E25A4}] => (Allow) C:\Program Files (x86)\MIO\loader\toshibaxmq01abd100_348esqxtsxx348esqxts.dat FirewallRules: [{EA211BCA-3C9C-4A37-B404-A67DC828BA4C}] => (Allow) C:\Program Files (x86)\MIO\loader\toshibaxmq01abd100_348esqxtsxx348esqxts.dat FirewallRules: [{833936D9-4A90-4CB3-B0DF-CDD4D6F39DE7}] => (Allow) C:\Program Files (x86)\Baglook\Application\chrome.exe FirewallRules: [{1599F6E7-EAE9-4E52-A1EF-DE093866E260}] => (Allow) C:\Program Files (x86)\Firefox\Firefox.exe ==================== Restore Points ========================= 05-05-2017 10:31:22 Removed AlphaGo 06-05-2017 11:27:40 JRT Pre-Junkware Removal 09-05-2017 14:55:48 Removed Sophos Virus Removal Tool. 12-05-2017 15:30:14 Windows Update 12-05-2017 15:31:11 Windows Update 16-05-2017 10:53:37 Windows Update 16-05-2017 10:54:49 Windows Update 19-05-2017 11:43:28 Windows Update 19-05-2017 11:44:42 Windows Update ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (05/19/2017 06:53:11 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: PHO090161) Description: Activation of application microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 failed with error: -2144927139 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (05/19/2017 06:52:08 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: PHO090161) Description: Activation of application microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 failed with error: -2144927139 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (05/19/2017 06:52:02 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: PHO090161) Description: Activation of application microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 failed with error: -2144927139 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (05/19/2017 06:37:02 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: PHO090161) Description: Activation of application microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 failed with error: -2144927139 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (05/19/2017 06:36:03 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: PHO090161) Description: Activation of application microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 failed with error: -2144927139 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (05/19/2017 06:32:07 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: PHO090161) Description: Activation of application Microsoft.Windows.Photos_8wekyb3d8bbwe!App failed with error: -2144927139 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (05/19/2017 06:20:10 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: PHO090161) Description: Activation of application microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 failed with error: -2144927139 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (05/19/2017 06:20:05 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: PHO090161) Description: Activation of application microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 failed with error: -2144927139 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (05/19/2017 06:16:41 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: PHO090161) Description: Activation of application Microsoft.Windows.Photos_8wekyb3d8bbwe!App failed with error: -2144927139 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (05/19/2017 06:04:33 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: PHO090161) Description: Activation of application Microsoft.Windows.Photos_8wekyb3d8bbwe!App failed with error: -2144927139 See the Microsoft-Windows-TWinUI/Operational log for additional information. System errors: ============= Error: (05/19/2017 01:24:02 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY) Description: Installation Failure: Windows failed to install the following update with error 0x8007371b: 2017-05 Update for Windows 10 Version 1607 for x64-based Systems (KB3150513). Error: (05/19/2017 01:21:40 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY) Description: Installation Failure: Windows failed to install the following update with error 0x80070002: 2017-05 Cumulative Update for Windows 10 Version 1607 for x64-based Systems (KB4019472). Error: (05/19/2017 01:04:33 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The CSHMDR service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 21600000 milliseconds: Restart the service. Error: (05/19/2017 12:47:54 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52} and APPID {4839DDB7-58C2-48F5-8283-E1D1807D0D7D} to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (05/19/2017 12:47:54 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52} and APPID {4839DDB7-58C2-48F5-8283-E1D1807D0D7D} to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (05/19/2017 12:47:53 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {8D8F4F83-3594-4F07-8369-FC3C3CAE4919} and APPID {F72671A9-012C-4725-9D2F-2A4D32D65169} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (05/19/2017 12:45:46 PM) (Source: DCOM) (EventID: 10010) (User: PHO090161) Description: The server {0002DF02-0000-0000-C000-000000000046} did not register with DCOM within the required timeout. Error: (05/19/2017 12:45:45 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (05/19/2017 12:39:44 PM) (Source: disk) (EventID: 7) (User: ) Description: The device, \Device\Harddisk0\DR0, has a bad block. Error: (05/19/2017 12:39:40 PM) (Source: disk) (EventID: 7) (User: ) Description: The device, \Device\Harddisk0\DR0, has a bad block. CodeIntegrity: =================================== Date: 2017-03-14 08:48:18.091 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\winhttp.dll because the set of per-page image hashes could not be found on the system. Date: 2017-03-14 08:48:18.045 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\winhttp.dll because the set of per-page image hashes could not be found on the system. Date: 2017-03-13 17:52:18.906 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\winhttp.dll because the set of per-page image hashes could not be found on the system. Date: 2017-03-13 17:52:18.859 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\winhttp.dll because the set of per-page image hashes could not be found on the system. Date: 2017-03-12 22:03:28.949 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\winhttp.dll because the set of per-page image hashes could not be found on the system. Date: 2017-03-12 22:03:28.901 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\winhttp.dll because the set of per-page image hashes could not be found on the system. Date: 2017-03-12 09:18:44.094 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\winhttp.dll because the set of per-page image hashes could not be found on the system. Date: 2017-03-12 09:18:44.050 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\winhttp.dll because the set of per-page image hashes could not be found on the system. Date: 2017-03-12 08:13:53.530 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\winhttp.dll because the set of per-page image hashes could not be found on the system. Date: 2017-03-12 08:13:53.484 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\winhttp.dll because the set of per-page image hashes could not be found on the system. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i3-4000M CPU @ 2.40GHz Percentage of memory in use: 49% Total physical RAM: 8104.13 MB Available physical RAM: 4089.07 MB Total Virtual: 9384.13 MB Available Virtual: 4938.51 MB ==================== Drives ================================ Drive c: (TI31255200A) (Fixed) (Total:919.63 GB) (Free:383.79 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 00000000) Partition: GPT. ==================== End of Addition.txt ============================