Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15-06-2017 01 Ran by [removed] (17-06-2017 15:02:48) Running from C:\Users\[removed]\Downloads Windows 10 Pro Version 1607 (X64) (2017-03-20 17:52:13) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-3656457744-1074379417-2173692989-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-3656457744-1074379417-2173692989-503 - Limited - Disabled) defaultuser0 (S-1-5-21-3656457744-1074379417-2173692989-1000 - Limited - Disabled) => C:\Users\defaultuser0 Guest (S-1-5-21-3656457744-1074379417-2173692989-501 - Limited - Disabled) sampr (S-1-5-21-3656457744-1074379417-2173692989-1001 - Administrator - Enabled) => C:\Users\sampr ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 7-Zip 16.04 (x64) (HKLM\...\7-Zip) (Version: 16.04 - Igor Pavlov) Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 17.009.20044 - Adobe Systems Incorporated) Adobe Flash Player 25 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 25.0.0.127 - Adobe Systems Incorporated) Amazon Kindle (HKU\S-1-5-21-3656457744-1074379417-2173692989-1001\...\Amazon Kindle) (Version: 1.20.1.47037 - Amazon) Any Video Converter 6.1.3 (HKLM-x32\...\Any Video Converter) (Version: 6.1.3 - Anvsoft) Apowersoft Screen Recorder Pro V2.1.9 (HKLM-x32\...\{dc9006db-6b05-4f0f-833b-79ef3f284c24}_is1) (Version: 2.1.9 - APOWERSOFT LIMITED) Apple Application Support (32-bit) (HKLM-x32\...\{05E07D23-91E9-4E70-A4CC-EF505088F967}) (Version: 5.4.1 - Apple Inc.) Apple Application Support (64-bit) (HKLM\...\{741291DA-2B34-4D44-8FB6-58EDE21261D8}) (Version: 5.4.1 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{DB18F1C0-846F-46F5-A074-5B97C8AF5C8E}) (Version: 10.3.1.2 - Apple Inc.) Apple Software Update (HKLM-x32\...\{52D87F32-70E4-4348-8148-C0B9F35B1314}) (Version: 2.3.0.177 - Apple Inc.) ArcGIS Desktop 10.5 (HKLM-x32\...\ArcGIS Desktop 10.5) (Version: 10.5.6491 - Environmental Systems Research Institute, Inc.) ArcGIS Desktop 10.5 (x32 Version: 10.5.6491 - Environmental Systems Research Institute, Inc.) Hidden Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.) Cisco AnyConnect Secure Mobility Client (HKLM-x32\...\Cisco AnyConnect Secure Mobility Client) (Version: 4.4.01054 - Cisco Systems, Inc.) Cisco AnyConnect Secure Mobility Client (x32 Version: 4.4.01054 - Cisco Systems, Inc.) Hidden Citrix Online Launcher (HKLM-x32\...\{48947098-A67C-46D4-90C5-9F2F6F0F96FE}) (Version: 1.0.449 - Citrix) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Dell Touchpad (HKLM\...\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version: 10.1207.101.113 - ALPS ELECTRIC CO., LTD.) Dropbox (HKLM-x32\...\Dropbox) (Version: 28.4.14 - Dropbox, Inc.) Dropbox Update Helper (x32 Version: 1.3.65.1 - Dropbox, Inc.) Hidden Duplicate File Finder (HKLM-x32\...\{1041487C-12E6-47FE-B83A-E9891782C8FE}}_is1) (Version: 6.3 - Ashisoft) EmEditor (64-bit) (HKLM\...\{C995A5C2-B870-42FC-A0E0-E179133E84D5}) (Version: 16.6.0 - Emurasoft, Inc.) ENVI 5.4 (HKLM\...\{D9358990-708B-4c4b-BE97-23E3626D59F8}_is1) (Version: 5.4 - Exelis Visual Information Solutions, Inc., a subsidiary of Harris Corporation) Extended Asian Language font pack for Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-2530-0000-AC0F074E4100}) (Version: 15.007.20033 - Adobe Systems Incorporated) FileZilla Client 3.25.1 (HKU\S-1-5-21-3656457744-1074379417-2173692989-1001\...\FileZilla Client) (Version: 3.25.1 - Tim Kosse) FlexNet Server 2016.03.0 (HKLM\...\{6B83EC09-FAB9-4219-BC88-1B4126B2D862}_is1) (Version: 2016.03.0 - Exelis Visual Information Solutions, Inc., a subsidiary of Harris Corporation) GIMP 2.8.18 (HKLM\...\GIMP-2_is1) (Version: 2.8.18 - The GIMP Team) Git version 2.13.0 (HKLM\...\Git_is1) (Version: 2.13.0 - The Git Development Community) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 59.0.3071.104 - Google Inc.) Google Earth (HKLM-x32\...\{F6430171-B86B-4639-839E-374913E7911D}) (Version: 7.1.8.3036 - Google) Google Update Helper (x32 Version: 1.3.33.5 - Google Inc.) Hidden GoToMeeting 8.7.0.7155 (HKU\S-1-5-21-3656457744-1074379417-2173692989-1001\...\GoToMeeting) (Version: 8.7.0.7155 - CitrixOnline) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 20.19.15.4531 - Intel Corporation) iTunes (HKLM\...\{6C01A0A7-7440-4D48-93C6-2927A1E93FE6}) (Version: 12.6.0.100 - Apple Inc.) Java 8 Update 131 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180131F0}) (Version: 8.0.1310.11 - Oracle Corporation) Java 8 Update 131 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180131F0}) (Version: 8.0.1310.11 - Oracle Corporation) Lazarus 1.6.4 (HKLM\...\lazarus_is1) (Version: 1.6.4 - Lazarus Team) LocalExplorer (HKU\S-1-5-21-3656457744-1074379417-2173692989-1001\...\LocalExplorer) (Version: 1.0 - LocalExplorer) Malwarebytes version 3.1.2.1733 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.1.2.1733 - Malwarebytes) Maxx Audio Installer (x64) (Version: 2.6.6448.1 - Waves Audio Ltd.) Hidden Microsoft Office 365 ProPlus - en-us (HKLM\...\O365ProPlusRetail - en-us) (Version: 16.0.8201.2102 - Microsoft Corporation) Microsoft Office Access database engine 2007 (English) (HKLM-x32\...\{90120000-00D1-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-3656457744-1074379417-2173692989-1001\...\OneDriveSetup.exe) (Version: 17.3.6917.0607 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23026 (HKLM-x32\...\{e46eca4f-393b-40df-9f49-076faf788d83}) (Version: 14.0.23026.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation) Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Mozilla Firefox 53.0.3 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 53.0.3 (x86 en-US)) (Version: 53.0.3 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 53.0.3.6347 - Mozilla) Notepad++ (64-bit x64) (HKLM\...\Notepad++) (Version: 7.3.3 - Notepad++ Team) NVIDIA 3D Vision Driver 376.54 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 376.54 - NVIDIA Corporation) NVIDIA Graphics Driver 376.54 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 376.54 - NVIDIA Corporation) NVIDIA HD Audio Driver 1.3.34.17 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.17 - NVIDIA Corporation) NVIDIA nView 148.03 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NView) (Version: 148.03 - NVIDIA Corporation) NVIDIA WMI 2.29.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVWMI) (Version: 2.29.0 - NVIDIA Corporation) Office 16 Click-to-Run Extensibility Component (Version: 16.0.8201.2102 - Microsoft Corporation) Hidden Office 16 Click-to-Run Licensing Component (Version: 16.0.8201.2102 - Microsoft Corporation) Hidden Office 16 Click-to-Run Localization Component (Version: 16.0.8201.2075 - Microsoft Corporation) Hidden QGIS 2.14 2.14.12 Essen (HKLM\...\QGIS 2.14) (Version: - QGIS Development Team) R for Windows 3.0.0 (HKLM\...\R for Windows 3.0.0_is1) (Version: 3.0.0 - R Core Team) R for Windows 3.3.2 (HKLM\...\R for Windows 3.3.2_is1) (Version: 3.3.2 - R Core Team) R for Windows 3.3.3 (HKLM\...\R for Windows 3.3.3_is1) (Version: 3.3.3 - R Core Team) Realtek Audio COM Components (HKLM-x32\...\{2355B503-9B11-4449-861D-1C1748B26320}) (Version: 1.0.2 - Realtek Semiconductor Corp.) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6086 - Realtek Semiconductor Corp.) RoboForm 8-3-5-5 (HKU\S-1-5-21-3656457744-1074379417-2173692989-1001\...\AI RoboForm) (Version: 8-3-5-5 - Siber Systems) RStudio (HKLM-x32\...\RStudio) (Version: 1.0.136 - RStudio) SaTScan 9.4 (HKLM\...\SaTScan 9.4) (Version: - ) Skype™ 7.37 (HKLM-x32\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.37.103 - Skype Technologies S.A.) TeamViewer 12 (HKLM-x32\...\TeamViewer) (Version: 12.0.78313 - TeamViewer) TerrSet (HKLM-x32\...\TerrSet) (Version: 18.30 - Clark Labs / Clark University) TerrSet (x32 Version: 18.30 - Clark Labs / Clark University) Hidden Turbo Pascal 7 for Windows7-8-8.1 by TechApple.Net (HKU\S-1-5-21-3656457744-1074379417-2173692989-1001\...\Turbo Pascal 7 for Windows7-8-8.1 by TechApple.Net) (Version: 00.07.00.00 - TechApple.Net) Video Win Movie Maker 2016 (HKLM-x32\...\{3CC29C1A-B5FE-457B-8F22-32A2videowin}}_is1) (Version: - videowinsoft.com) VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.4 - VideoLAN) VSModules (Version: 2.0.0.0 - Exelis Visual Information Solutions, Inc., a subsidiary of Harris Corporation) Hidden Vulkan Run Time Libraries 1.0.26.0 (HKLM\...\VulkanRT1.0.26.0) (Version: 1.0.26.0 - LunarG, Inc.) WinHTTrack Website Copier 3.49-2 (x64) (HKLM\...\WinHTTrack Website Copier_is1) (Version: 3.49.2 - HTTrack) Zoom (HKU\S-1-5-21-3656457744-1074379417-2173692989-1001\...\ZoomUMX) (Version: 4.0 - Zoom Video Communications, Inc.) Zotero Standalone 4.0.29.17 (x86 en-US) (HKLM-x32\...\Zotero Standalone 4.0.29.17 (x86 en-US)) (Version: 4.0.29.17 - Zotero) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-3656457744-1074379417-2173692989-1001_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309}\InprocServer32 -> C:\Users\sampr\AppData\Local\Citrix\GoToMeeting\6956\G2MOutlookAddin64.dll (Citrix Online, a division of Citrix Systems, Inc.) CustomCLSID: HKU\S-1-5-21-3656457744-1074379417-2173692989-1001_Classes\CLSID\{D4D48C93-BDC7-4E76-B530-2E4D13B0150F}\InprocServer32 -> C:\Users\sampr\AppData\Local\Programs\EmEditor\emedshl64.dll (Emurasoft, Inc.) CustomCLSID: HKU\S-1-5-21-3656457744-1074379417-2173692989-1001_Classes\CLSID\{DFA0CC7F-D36B-47D1-8EF5-415C1DA53F57}\InprocServer32 -> C:\Users\sampr\AppData\Local\Programs\EmEditor\emedshl64.dll (Emurasoft, Inc.) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {1529C81E-3C54-4E15-B1D8-72588E971244} - System32\Tasks\Run RoboForm TaskBar Icon => C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe [2017-06-01] (Siber Systems) Task: {38C52528-F992-4F95-BE58-2A72CAAC7471} - System32\Tasks\LocalExplorer Update => C:\Program Files (x86)\LocalExplorer\LocalExplorer.exe [2014-08-08] (VNProDev) Task: {3E2A5CD4-EEAC-45A8-8C2B-ADA0F906FA2D} - System32\Tasks\G2MUploadTask-S-1-5-21-3656457744-1074379417-2173692989-1001 => C:\Users\sampr\AppData\Local\Citrix\GoToMeeting\7155\g2mupload.exe [2017-06-13] (Citrix Online, a division of Citrix Systems, Inc.) Task: {485916D9-1E25-4761-AB8A-066934227933} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2017-06-16] () Task: {4C003B69-6DC3-49AF-81F3-2A206AD19B0F} - System32\Tasks\nWizard_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\nview\nwiz.exe [2017-03-14] () Task: {5FE5BEF9-837D-4677-A2A7-0026D7D021F3} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2017-03-21] (Dropbox, Inc.) Task: {65FFA9FD-543B-41D8-BE93-26EC205DB863} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-06-10] (Microsoft Corporation) Task: {7421D512-6412-49A3-B5D0-F68FD065F80E} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-06-10] (Microsoft Corporation) Task: {8189722A-9486-4AA7-A0F8-EB8FC17FAED6} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [2017-06-16] (Microsoft Corporation) Task: {8353DFFC-26EC-40CD-A05B-2E4297B87066} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-03-20] (Google Inc.) Task: {85D5D16B-A699-4BFE-9F33-146ED2049888} - System32\Tasks\G2MUpdateTask-S-1-5-21-3656457744-1074379417-2173692989-1001 => C:\Users\sampr\AppData\Local\Citrix\GoToMeeting\7155\g2mupdate.exe [2017-06-13] (Citrix Online, a division of Citrix Systems, Inc.) Task: {8EF288C2-7C47-43BE-AF6D-3F7D48A6ED7D} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-03-20] (Google Inc.) Task: {935E54B8-7142-4EDF-B784-F5988E19E8E5} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-04-25] (Adobe Systems Incorporated) Task: {97B67592-87CA-4634-B77D-8C798BB542A5} - System32\Tasks\Open URL by RoboForm => Rundll32.exe url.dll,FileProtocolHandler "hxxps://www.roboform.com/test-pass.html?aaa=KICMHMLJMJOMMMPMKJMJCNGMLJJMKMCNLMLJKJMJCNOJNJNMIMCNJJMJGMOJOJOMNMKMIMKMHMJMJNJICMHMCNMMCNKMFMOMOMCNOMOMGMHMCNOMLMMMGMMMFMPMCNPMCNOMLMMMGMMMCNNMJNPICMOMFMEKMICNJJCKFMIMNMJNHICMEKMICNJJCKJNBJCMMIOJCJPINIJNKJCMJNNICMJNDJCMKJBJJNM (the data entry has 48 more characters). Task: {BD8DC5B2-0301-4FA2-B815-6817F3B2E92F} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2017-02-14] (Apple Inc.) Task: {C7C85B48-83D2-4389-A6AF-38F7C0AD38BC} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2017-06-16] () Task: {E015532E-C42F-4496-B38E-D9F68DEE7748} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2017-06-16] (Microsoft Corporation) Task: {E3372CF3-D391-4077-85FB-90CCB7329838} - System32\Tasks\RtHDVBg_PushButton => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2015-09-30] (Realtek Semiconductor) Task: {EED4AA7F-7F3F-4D94-91AF-CF6EAF074AE9} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2017-03-21] (Dropbox, Inc.) Task: {FC1E9EDB-1CC8-4FEF-A32E-BB9641C7CAC8} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [2017-06-16] (Microsoft Corporation) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Task: C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Task: C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-3656457744-1074379417-2173692989-1001.job => C:\Users\sampr\AppData\Local\Citrix\GoToMeeting\7155\g2mupdate.exe Task: C:\Windows\Tasks\G2MUploadTask-S-1-5-21-3656457744-1074379417-2173692989-1001.job => C:\Users\sampr\AppData\Local\Citrix\GoToMeeting\7155\g2mupload.exe ==================== Shortcuts & WMI ======================== (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== 2017-03-16 16:08 - 2017-03-16 16:08 - 00092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2017-03-16 16:08 - 2017-03-16 16:08 - 01354040 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2017-03-20 19:59 - 2017-03-20 19:59 - 09963520 _____ () C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp\llsnc-2016.03-SNAPSHOT-amd64-connector.dll 2016-07-16 05:42 - 2016-07-16 05:42 - 00231424 _____ () C:\Windows\SYSTEM32\ism32k.dll 2017-06-13 12:26 - 2017-06-03 04:01 - 02681200 _____ () C:\Windows\System32\CoreUIComponents.dll 2017-03-20 12:17 - 2016-12-29 07:16 - 00134712 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2017-03-20 09:44 - 2017-03-20 09:44 - 00052392 _____ () C:\Program Files\FileZilla FTP Client\fzshellext_64.dll 2017-03-20 12:18 - 2017-03-14 10:12 - 00794672 _____ () C:\Program Files\NVIDIA Corporation\nview\nvshell.dll 2016-10-25 02:08 - 2016-10-25 02:08 - 00401912 _____ () C:\Windows\system32\igfxTray.exe 2017-03-21 14:06 - 2016-09-06 22:56 - 00134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll 2017-03-21 14:05 - 2017-03-04 00:31 - 00474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll 2017-03-21 14:05 - 2017-03-04 00:30 - 00693248 _____ () C:\Windows\ShellExperiences\MtcUvc.dll 2017-03-21 14:06 - 2017-03-04 00:12 - 09760768 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2017-03-21 14:06 - 2017-03-04 00:05 - 01401856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2017-03-21 14:05 - 2017-03-04 00:05 - 00757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll 2017-06-13 12:26 - 2017-06-03 02:47 - 01033216 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll 2017-06-13 12:26 - 2017-06-03 02:47 - 02424320 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll 2017-06-13 12:26 - 2017-06-03 02:51 - 04853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll 2017-03-27 12:20 - 2017-03-27 12:20 - 00092472 _____ () C:\Program Files\iTunes\zlib1.dll 2017-03-27 12:20 - 2017-03-27 12:20 - 01354040 _____ () C:\Program Files\iTunes\libxml2.dll 2017-04-18 09:27 - 2017-05-25 14:11 - 02270664 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll 2017-03-23 15:36 - 2017-03-23 15:36 - 01628504 _____ () C:\Users\sampr\AppData\Local\Programs\EmEditor\emedres.dll 2017-04-04 13:04 - 2017-04-04 13:04 - 00446808 _____ () C:\Users\sampr\AppData\Local\Programs\EmEditor\mui\1033\emedloc.dll 2017-03-20 18:08 - 2017-06-16 18:35 - 08931008 _____ () C:\Program Files\Microsoft Office\root\Office16\1033\GrooveIntlResource.dll 2017-06-15 14:35 - 2017-06-15 01:29 - 03807064 _____ () C:\Program Files (x86)\Google\Chrome\Application\59.0.3071.104\libglesv2.dll 2017-06-15 14:35 - 2017-06-15 01:29 - 00100184 _____ () C:\Program Files (x86)\Google\Chrome\Application\59.0.3071.104\libegl.dll 2017-06-14 12:55 - 2017-06-14 14:12 - 00020480 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.524.10020.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe 2017-06-14 12:55 - 2017-06-14 14:12 - 27430400 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.524.10020.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll 2017-06-14 12:55 - 2017-06-14 14:12 - 00460288 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.524.10020.0_x64__8wekyb3d8bbwe\Microsoft.Photos.AGM.Native.Windows.dll 2017-06-14 12:55 - 2017-06-14 14:12 - 02275328 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.524.10020.0_x64__8wekyb3d8bbwe\MediaEngine.dll 2017-06-07 21:00 - 2017-06-07 21:01 - 03139496 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.524.10020.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll 2017-06-14 12:55 - 2017-06-14 14:12 - 00046080 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.524.10020.0_x64__8wekyb3d8bbwe\Microsoft.Photos.Edit.Services.dll 2017-03-20 14:58 - 2017-03-20 15:14 - 00680448 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.524.10020.0_x64__8wekyb3d8bbwe\Microsoft.DesignCore.dll 2017-06-14 12:55 - 2017-06-14 14:12 - 00900096 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.524.10020.0_x64__8wekyb3d8bbwe\Microsoft.RichMedia.Ink.Controls.dll 2017-05-09 04:48 - 2017-05-09 04:48 - 01062400 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.524.10020.0_x64__8wekyb3d8bbwe\Microsoft.Sharing.dll 2016-07-16 08:37 - 2016-07-16 08:37 - 00291328 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.524.10020.0_x64__8wekyb3d8bbwe\StoreRatingPromotion.dll 2017-06-01 06:01 - 2017-06-01 06:01 - 23661056 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.17042.14211.0_x64__8wekyb3d8bbwe\Video.UI.exe 2017-06-01 06:01 - 2017-06-01 06:01 - 09016320 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.17042.14211.0_x64__8wekyb3d8bbwe\EntCommon.dll 2017-05-26 06:38 - 2017-05-26 06:39 - 03140520 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.17042.14211.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll 2017-05-22 16:54 - 2017-05-22 16:54 - 03918848 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1705.1301.0_x64__8wekyb3d8bbwe\Calculator.exe 2017-04-07 12:44 - 2017-04-07 12:45 - 01695440 _____ () C:\Program Files\WindowsApps\Microsoft.Office.OneNote_17.8269.57641.0_x64__8wekyb3d8bbwe\Microsoft.Applications.Telemetry.Windows.dll 2017-06-17 05:30 - 2017-06-17 05:30 - 13187264 _____ () C:\Program Files\WindowsApps\Microsoft.Office.OneNote_17.8269.57641.0_x64__8wekyb3d8bbwe\Office.UI.Xaml.Core.dll 2017-02-28 14:24 - 2017-02-28 14:24 - 00073728 _____ () C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\zlib1.dll 2017-06-13 12:56 - 2017-06-12 05:52 - 00775488 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_watchdog.dll 2017-06-13 12:56 - 2017-06-12 05:52 - 01787200 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_crashpad.dll 2017-03-21 05:01 - 2017-06-12 05:52 - 00100296 _____ () C:\Program Files (x86)\Dropbox\Client\_ctypes.pyd 2017-03-21 05:01 - 2017-06-12 05:52 - 00018888 _____ () C:\Program Files (x86)\Dropbox\Client\select.pyd 2017-03-21 05:01 - 2017-06-12 05:54 - 00019776 _____ () C:\Program Files (x86)\Dropbox\Client\tornado.speedups.pyd 2017-03-21 05:01 - 2017-06-12 05:52 - 00035792 _____ () C:\Program Files (x86)\Dropbox\Client\_multiprocessing.pyd 2017-06-13 12:56 - 2017-06-12 05:54 - 00020824 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._constant_time.pyd 2017-03-21 05:01 - 2017-06-12 05:52 - 00123856 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_backend.pyd 2017-03-21 05:01 - 2017-06-12 05:52 - 00694224 _____ () C:\Program Files (x86)\Dropbox\Client\unicodedata.pyd 2017-06-13 12:56 - 2017-06-12 05:54 - 01729360 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._openssl.pyd 2017-06-13 12:56 - 2017-06-12 05:54 - 00020816 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._padding.pyd 2017-06-13 12:56 - 2017-06-12 05:52 - 00145864 _____ () C:\Program Files (x86)\Dropbox\Client\pyexpat.pyd 2017-06-13 12:56 - 2017-06-12 05:52 - 00019408 _____ () C:\Program Files (x86)\Dropbox\Client\faulthandler.pyd 2017-06-13 12:56 - 2017-06-12 05:52 - 00116688 _____ () C:\Program Files (x86)\Dropbox\Client\pywintypes27.dll 2017-03-21 05:01 - 2017-06-12 05:52 - 00105928 _____ () C:\Program Files (x86)\Dropbox\Client\win32api.pyd 2017-03-21 05:01 - 2017-06-12 05:55 - 00022864 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.crt.compiled._winffi_crt.pyd 2017-06-13 12:56 - 2017-06-12 05:54 - 00060736 _____ () C:\Program Files (x86)\Dropbox\Client\psutil._psutil_windows.pyd 2017-06-13 12:56 - 2017-06-12 05:54 - 00038712 _____ () C:\Program Files (x86)\Dropbox\Client\fastpath.pyd 2017-03-21 05:01 - 2017-06-12 05:52 - 00024528 _____ () C:\Program Files (x86)\Dropbox\Client\win32event.pyd 2017-06-13 12:56 - 2017-06-12 05:52 - 00392656 _____ () C:\Program Files (x86)\Dropbox\Client\pythoncom27.dll 2017-06-13 12:56 - 2017-06-12 05:52 - 00020936 _____ () C:\Program Files (x86)\Dropbox\Client\mmapfile.pyd 2017-03-21 05:01 - 2017-06-12 05:52 - 00116176 _____ () C:\Program Files (x86)\Dropbox\Client\win32security.pyd 2017-03-21 05:01 - 2017-06-12 05:54 - 00392512 _____ () C:\Program Files (x86)\Dropbox\Client\win32com.shell.shell.pyd 2017-03-21 05:01 - 2017-06-12 05:52 - 00124880 _____ () C:\Program Files (x86)\Dropbox\Client\win32file.pyd 2017-03-21 05:01 - 2017-06-12 05:55 - 00026456 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.kernel32.compiled._winffi_kernel32.pyd 2017-03-21 05:01 - 2017-06-12 05:52 - 00024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32clipboard.pyd 2017-03-21 05:01 - 2017-06-12 05:52 - 00175560 _____ () C:\Program Files (x86)\Dropbox\Client\win32gui.pyd 2017-03-21 05:01 - 2017-06-12 05:52 - 00030160 _____ () C:\Program Files (x86)\Dropbox\Client\win32pipe.pyd 2017-03-21 05:01 - 2017-06-12 05:52 - 00043472 _____ () C:\Program Files (x86)\Dropbox\Client\win32process.pyd 2017-03-21 05:01 - 2017-06-12 05:52 - 00048592 _____ () C:\Program Files (x86)\Dropbox\Client\win32service.pyd 2017-03-21 05:01 - 2017-06-12 05:52 - 00057808 _____ () C:\Program Files (x86)\Dropbox\Client\win32evtlog.pyd 2017-03-21 05:01 - 2017-06-12 05:52 - 00024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32profile.pyd 2017-06-13 12:56 - 2017-06-12 05:54 - 00022336 _____ () C:\Program Files (x86)\Dropbox\Client\cpuid.compiled._cpuid.pyd 2017-05-17 11:54 - 2017-06-12 05:55 - 00082264 _____ () C:\Program Files (x86)\Dropbox\Client\winenumhandles.compiled._WinEnumHandles.pyd 2017-03-21 05:01 - 2017-06-12 05:55 - 00025432 _____ () C:\Program Files (x86)\Dropbox\Client\winscreenshot.compiled._CaptureScreenshot.pyd 2017-06-13 12:56 - 2017-06-12 05:54 - 00246608 _____ () C:\Program Files (x86)\Dropbox\Client\breakpad.client.windows.handler.pyd 2017-06-13 12:56 - 2017-06-12 05:54 - 00027488 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox.infinite.win.compiled._driverinstallation.pyd 2017-06-13 12:56 - 2017-06-12 05:54 - 03928896 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWidgets.pyd 2017-03-21 05:01 - 2017-06-12 05:52 - 00083912 _____ () C:\Program Files (x86)\Dropbox\Client\sip.pyd 2017-06-13 12:56 - 2017-06-12 05:54 - 01826104 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtCore.pyd 2017-06-13 12:56 - 2017-06-12 05:54 - 01972024 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtGui.pyd 2017-03-21 05:01 - 2017-06-12 05:52 - 00028616 _____ () C:\Program Files (x86)\Dropbox\Client\win32ts.pyd 2017-06-13 12:56 - 2017-06-12 05:54 - 00171336 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebEngineWidgets.pyd 2017-06-13 12:56 - 2017-06-12 05:54 - 00042816 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebChannel.pyd 2017-06-13 12:56 - 2017-06-12 05:54 - 00531264 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtNetwork.pyd 2017-06-13 12:56 - 2017-06-12 05:54 - 00133432 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKit.pyd 2017-06-13 12:56 - 2017-06-12 05:54 - 00224064 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKitWidgets.pyd 2017-06-13 12:56 - 2017-06-12 05:54 - 00207680 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtPrintSupport.pyd 2017-03-21 05:01 - 2017-06-12 05:52 - 00060880 _____ () C:\Program Files (x86)\Dropbox\Client\win32print.pyd 2017-03-21 05:01 - 2017-06-12 05:55 - 00054608 _____ () C:\Program Files (x86)\Dropbox\Client\winrpcserver.compiled._RPCServer.pyd 2017-03-21 05:01 - 2017-06-12 05:55 - 00022864 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.user32.compiled._winffi_user32.pyd 2017-03-21 05:01 - 2017-06-12 05:55 - 00069968 _____ () C:\Program Files (x86)\Dropbox\Client\windisplaytoast.compiled._DisplayToast.pyd 2017-03-21 05:01 - 2017-06-12 05:55 - 00022872 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.iphlpapi.compiled._winffi_iphlpapi.pyd 2017-03-21 05:01 - 2017-06-12 05:55 - 00021848 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winerror.compiled._winffi_winerror.pyd 2017-03-21 05:01 - 2017-06-12 05:55 - 00022872 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.wininet.compiled._winffi_wininet.pyd 2017-03-21 05:01 - 2017-06-12 05:52 - 00349128 _____ () C:\Program Files (x86)\Dropbox\Client\winxpgui.pyd 2017-06-13 12:56 - 2017-06-12 05:54 - 00103232 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWinExtras.pyd 2017-03-21 05:01 - 2017-06-12 05:55 - 00023896 _____ () C:\Program Files (x86)\Dropbox\Client\winverifysignature.compiled._VerifySignature.pyd 2017-06-13 12:56 - 2017-06-12 05:54 - 00025936 _____ () C:\Program Files (x86)\Dropbox\Client\librsyncffi.compiled._librsyncffi.pyd 2017-06-13 12:56 - 2017-06-12 05:52 - 00036296 _____ () C:\Program Files (x86)\Dropbox\Client\librsync.dll 2017-06-13 12:56 - 2017-06-12 05:54 - 00033112 _____ () C:\Program Files (x86)\Dropbox\Client\enterprise_data.compiled._enterprise_data.pyd 2017-06-13 12:56 - 2017-06-12 05:52 - 00293392 _____ () C:\Program Files (x86)\Dropbox\Client\EnterpriseDataAdapter.dll 2017-06-13 12:56 - 2017-06-12 05:54 - 00084288 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_sqlite_ext.DLL 2017-03-21 05:01 - 2017-06-12 05:54 - 00030536 _____ () C:\Program Files (x86)\Dropbox\Client\wind3d11.compiled._wind3d11.pyd 2017-06-13 12:56 - 2017-06-12 05:52 - 00017864 _____ () C:\Program Files (x86)\Dropbox\Client\libEGL.dll 2017-06-13 12:56 - 2017-06-12 05:52 - 01631184 _____ () C:\Program Files (x86)\Dropbox\Client\libGLESv2.dll 2017-03-21 05:01 - 2017-06-12 05:55 - 00026456 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winhttp.compiled._winffi_winhttp.pyd 2017-04-07 12:02 - 2017-06-12 05:54 - 00023368 _____ () C:\Program Files (x86)\Dropbox\Client\wincrashpad.compiled._Crashpad.pyd 2017-06-13 12:56 - 2017-06-12 05:54 - 00546104 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQuick.pyd 2017-06-13 12:56 - 2017-06-12 05:54 - 00357688 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQml.pyd 2017-03-21 05:01 - 2017-06-12 05:52 - 00697304 _____ () C:\Program Files (x86)\Dropbox\Client\QtQuick\Controls\qtquickcontrolsplugin.dll 2017-05-31 11:41 - 2017-05-31 11:41 - 01982976 ____R () C:\Program Files (x86)\Skype\Phone\skypert.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\Users\sampr\Downloads\Munoz Brenes Carlos Dissertation.pptx:com.dropbox.attributes [168] ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver" ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) IE trusted site: HKU\S-1-5-21-3656457744-1074379417-2173692989-1001\...\sharepoint.com -> hxxps://vandalsuidaho-myfiles.sharepoint.com ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2016-07-16 05:47 - 2016-07-16 05:45 - 00000824 _____ C:\Windows\system32\Drivers\etc\hosts ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-3656457744-1074379417-2173692989-1001\Control Panel\Desktop\\Wallpaper -> DNS Servers: 172.21.3.103 - 172.21.3.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{C38F5F98-2CC1-4083-83A5-078DE3286378}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{2E4E167F-6294-46DC-B7CB-0B0CF92733B4}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{4E14A019-2D1D-425F-8101-8EF1BFB1B782}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{D2897571-2EF2-4C58-A513-7DB80430C007}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe FirewallRules: [{2D4726C8-0CD5-4DF4-806B-4443C36AC50E}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe FirewallRules: [{2AA4CE57-63B3-436A-977E-A3E0DB1F6DB3}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe FirewallRules: [{1C85A2B0-0506-4968-BA02-022870707E82}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe FirewallRules: [{76B03604-4860-429E-8EF0-C0D186A412E8}] => (Allow) C:\Program Files (x86)\Apowersoft\Apowersoft Screen Recorder Pro 2\Apowersoft Screen Recorder Pro 2.exe FirewallRules: [{5B4D7DB0-5BEB-420E-A9E4-5E093E5C5B99}] => (Allow) C:\Program Files (x86)\Apowersoft\Apowersoft Screen Recorder Pro 2\Apowersoft Screen Recorder Pro 2.exe FirewallRules: [{2383B9DF-E523-4958-93A2-4781B836B00A}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{1B8978C9-9D1D-4C1C-A482-96B448107FD9}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{49567718-A161-4195-AC7D-179190A0B338}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{8A9B4831-6E04-48C1-8DDB-884D51A68AFB}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{2C62871E-4FAC-4FD9-B528-B7A6C71952F3}] => (Allow) C:\Program Files\iTunes\iTunes.exe FirewallRules: [{145F0F61-CE85-49F4-8337-85653B9F4B7E}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe FirewallRules: [{B52C0266-EB5A-4940-8A6B-4BEECFACE757}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{E6FB8F7D-C7C1-48A3-A650-5B3FEF43E839}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{83F6E297-092E-43C5-B411-725E56337741}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{8E0D58C7-F0C8-4A01-8FF2-2EFEC6DBAC5D}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{C0BE8305-5DBC-451E-B841-92FDB66C7218}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe FirewallRules: [{5C1A1A1F-94F4-46E4-8FC7-FDF9E5E69A0F}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Restore Points ========================= 16-06-2017 13:59:47 Scheduled Checkpoint ==================== Faulty Device Manager Devices ============= Name: Broadcom USH Description: Broadcom USH Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64 Description: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64 Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Cisco Systems Service: vpnva Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (06/17/2017 04:25:13 AM) (Source: SideBySide) (EventID: 63) (User: ) Description: Activation context generation failed for "c:\program files\r\r-3.0.0\tcl\bin64\tk85.dll".Error in manifest or policy file "c:\program files\r\r-3.0.0\tcl\bin64\tk85.dll" on line 9. The value "x64" of attribute "processorArchitecture" in element "assemblyIdentity" is invalid. Error: (06/17/2017 04:25:06 AM) (Source: SideBySide) (EventID: 63) (User: ) Description: Activation context generation failed for "c:\program files\r\r-3.3.2\tcl\bin64\tk85.dll".Error in manifest or policy file "c:\program files\r\r-3.3.2\tcl\bin64\tk85.dll" on line 9. The value "x64" of attribute "processorArchitecture" in element "assemblyIdentity" is invalid. Error: (06/17/2017 04:24:39 AM) (Source: SideBySide) (EventID: 63) (User: ) Description: Activation context generation failed for "c:\program files\r\r-3.3.3\tcl\bin64\tk85.dll".Error in manifest or policy file "c:\program files\r\r-3.3.3\tcl\bin64\tk85.dll" on line 9. The value "x64" of attribute "processorArchitecture" in element "assemblyIdentity" is invalid. Error: (06/16/2017 06:28:49 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: BSvcProcessor.exe, version: 1.0.6.0, time stamp: 0x563b2359 Faulting module name: BSvcProcessor.exe, version: 1.0.6.0, time stamp: 0x563b2359 Exception code: 0xc0000005 Fault offset: 0x00007b80 Faulting process id: 0x18ec Faulting application start time: 0x01d2e700ac868a81 Faulting application path: C:\Users\sampr\AppData\Local\Microsoft\BingSvc\BSvcProcessor.exe Faulting module path: C:\Users\sampr\AppData\Local\Microsoft\BingSvc\BSvcProcessor.exe Report Id: 6d7d160d-c717-4076-95a4-e423c1029611 Faulting package full name: Faulting package-relative application ID: Error: (06/16/2017 01:59:48 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol. System Error: Access is denied. . Error: (06/16/2017 04:57:12 AM) (Source: SideBySide) (EventID: 63) (User: ) Description: Activation context generation failed for "c:\program files\r\r-3.0.0\tcl\bin64\tk85.dll".Error in manifest or policy file "c:\program files\r\r-3.0.0\tcl\bin64\tk85.dll" on line 9. The value "x64" of attribute "processorArchitecture" in element "assemblyIdentity" is invalid. Error: (06/16/2017 04:57:10 AM) (Source: SideBySide) (EventID: 63) (User: ) Description: Activation context generation failed for "c:\program files\r\r-3.3.2\tcl\bin64\tk85.dll".Error in manifest or policy file "c:\program files\r\r-3.3.2\tcl\bin64\tk85.dll" on line 9. The value "x64" of attribute "processorArchitecture" in element "assemblyIdentity" is invalid. Error: (06/16/2017 04:57:00 AM) (Source: SideBySide) (EventID: 63) (User: ) Description: Activation context generation failed for "c:\program files\r\r-3.3.3\tcl\bin64\tk85.dll".Error in manifest or policy file "c:\program files\r\r-3.3.3\tcl\bin64\tk85.dll" on line 9. The value "x64" of attribute "processorArchitecture" in element "assemblyIdentity" is invalid. Error: (06/15/2017 03:56:58 AM) (Source: SideBySide) (EventID: 63) (User: ) Description: Activation context generation failed for "c:\program files\r\r-3.0.0\tcl\bin64\tk85.dll".Error in manifest or policy file "c:\program files\r\r-3.0.0\tcl\bin64\tk85.dll" on line 9. The value "x64" of attribute "processorArchitecture" in element "assemblyIdentity" is invalid. Error: (06/15/2017 03:56:56 AM) (Source: SideBySide) (EventID: 63) (User: ) Description: Activation context generation failed for "c:\program files\r\r-3.3.2\tcl\bin64\tk85.dll".Error in manifest or policy file "c:\program files\r\r-3.3.2\tcl\bin64\tk85.dll" on line 9. The value "x64" of attribute "processorArchitecture" in element "assemblyIdentity" is invalid. System errors: ============= Error: (06/17/2017 05:40:01 AM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-K802GD4) Description: The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {C2F03A33-21F5-47FA-B4BB-156362A2F239} and APPID {316CDED5-E4AE-4B15-9113-7055D84DCC97} to the user DESKTOP-K802GD4\sampr SID (S-1-5-21-3656457744-1074379417-2173692989-1001) from address LocalHost (Using LRPC) running in the application container Microsoft.Windows.Cortana_1.7.0.14393_neutral_neutral_cw5n1h2txyewy SID (S-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742). This security permission can be modified using the Component Services administrative tool. Error: (06/17/2017 05:40:01 AM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-K802GD4) Description: The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {C2F03A33-21F5-47FA-B4BB-156362A2F239} and APPID {316CDED5-E4AE-4B15-9113-7055D84DCC97} to the user DESKTOP-K802GD4\sampr SID (S-1-5-21-3656457744-1074379417-2173692989-1001) from address LocalHost (Using LRPC) running in the application container Microsoft.Windows.Cortana_1.7.0.14393_neutral_neutral_cw5n1h2txyewy SID (S-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742). This security permission can be modified using the Component Services administrative tool. Error: (06/17/2017 05:40:01 AM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-K802GD4) Description: The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {C2F03A33-21F5-47FA-B4BB-156362A2F239} and APPID {316CDED5-E4AE-4B15-9113-7055D84DCC97} to the user DESKTOP-K802GD4\sampr SID (S-1-5-21-3656457744-1074379417-2173692989-1001) from address LocalHost (Using LRPC) running in the application container Microsoft.Windows.Cortana_1.7.0.14393_neutral_neutral_cw5n1h2txyewy SID (S-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742). This security permission can be modified using the Component Services administrative tool. Error: (06/17/2017 05:40:01 AM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-K802GD4) Description: The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {C2F03A33-21F5-47FA-B4BB-156362A2F239} and APPID {316CDED5-E4AE-4B15-9113-7055D84DCC97} to the user DESKTOP-K802GD4\sampr SID (S-1-5-21-3656457744-1074379417-2173692989-1001) from address LocalHost (Using LRPC) running in the application container Microsoft.Windows.Cortana_1.7.0.14393_neutral_neutral_cw5n1h2txyewy SID (S-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742). This security permission can be modified using the Component Services administrative tool. Error: (06/17/2017 05:40:01 AM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-K802GD4) Description: The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {C2F03A33-21F5-47FA-B4BB-156362A2F239} and APPID {316CDED5-E4AE-4B15-9113-7055D84DCC97} to the user DESKTOP-K802GD4\sampr SID (S-1-5-21-3656457744-1074379417-2173692989-1001) from address LocalHost (Using LRPC) running in the application container Microsoft.Windows.Cortana_1.7.0.14393_neutral_neutral_cw5n1h2txyewy SID (S-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742). This security permission can be modified using the Component Services administrative tool. Error: (06/17/2017 05:40:01 AM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-K802GD4) Description: The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {C2F03A33-21F5-47FA-B4BB-156362A2F239} and APPID {316CDED5-E4AE-4B15-9113-7055D84DCC97} to the user DESKTOP-K802GD4\sampr SID (S-1-5-21-3656457744-1074379417-2173692989-1001) from address LocalHost (Using LRPC) running in the application container Microsoft.Windows.Cortana_1.7.0.14393_neutral_neutral_cw5n1h2txyewy SID (S-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742). This security permission can be modified using the Component Services administrative tool. Error: (06/17/2017 05:40:01 AM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-K802GD4) Description: The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {C2F03A33-21F5-47FA-B4BB-156362A2F239} and APPID {316CDED5-E4AE-4B15-9113-7055D84DCC97} to the user DESKTOP-K802GD4\sampr SID (S-1-5-21-3656457744-1074379417-2173692989-1001) from address LocalHost (Using LRPC) running in the application container Microsoft.Windows.Cortana_1.7.0.14393_neutral_neutral_cw5n1h2txyewy SID (S-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742). This security permission can be modified using the Component Services administrative tool. Error: (06/16/2017 06:13:34 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52} and APPID {4839DDB7-58C2-48F5-8283-E1D1807D0D7D} to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (06/16/2017 06:13:34 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52} and APPID {4839DDB7-58C2-48F5-8283-E1D1807D0D7D} to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (06/16/2017 06:13:34 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52} and APPID {4839DDB7-58C2-48F5-8283-E1D1807D0D7D} to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. CodeIntegrity: =================================== Date: 2017-06-13 13:34:46.797 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\nvdm.inf_amd64_72f356f138a86324\nvinitx.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-06-07 14:40:42.125 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\nvdm.inf_amd64_72f356f138a86324\nvinitx.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-06-04 14:24:43.901 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\nvdm.inf_amd64_72f356f138a86324\nvinitx.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-05-13 15:12:58.403 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\nvdm.inf_amd64_72f356f138a86324\nvinitx.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-05-10 12:21:34.106 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\nvdm.inf_amd64_72f356f138a86324\nvinitx.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-04-25 15:37:44.365 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\nvdm.inf_amd64_72f356f138a86324\nvinitx.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-04-24 15:34:49.353 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\nvdm.inf_amd64_72f356f138a86324\nvinitx.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-04-14 12:23:33.545 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\nvdm.inf_amd64_72f356f138a86324\nvinitx.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-04-13 18:38:48.424 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\nvdm.inf_amd64_72f356f138a86324\nvinitx.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-03-31 11:59:04.388 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\DriverStore\FileRepository\nvdm.inf_amd64_72f356f138a86324\nvinitx.dll that did not meet the Custom 3 / Antimalware signing level requirements. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i7-4810MQ CPU @ 2.80GHz Percentage of memory in use: 24% Total physical RAM: 32673.12 MB Available physical RAM: 24829.62 MB Total Virtual: 37537.12 MB Available Virtual: 28844.66 MB ==================== Drives ================================ Drive c: (DATAPART1) (Fixed) (Total:238.47 GB) (Free:21.99 GB) NTFS Drive d: (DATAPART3) (Fixed) (Total:1862.53 GB) (Free:723.51 GB) NTFS Drive e: (DATAPART2) (Fixed) (Total:1863.01 GB) (Free:279.06 GB) NTFS Drive f: (Seagate Backup Plus Drive) (Fixed) (Total:7452.03 GB) (Free:1003.54 GB) NTFS Drive h: (Seagate Backup Plus Drive) (Fixed) (Total:7451.91 GB) (Free:5775.12 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 1E19B9F9) Partition 1: (Active) - (Size=500 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=1862.5 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 238.5 GB) (Disk ID: 6B83BDD1) Partition 1: (Not Active) - (Size=238.5 GB) - (Type=07 NTFS) ======================================================== Disk: 2 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 6B83BD2C) Partition 1: (Not Active) - (Size=1863 GB) - (Type=07 NTFS) ======================================================== Disk: 3 (MBR Code: Windows 7 or 8) (Size: 7452 GB) (Disk ID: 9AF9CB7F) Partition: GPT. Attempted reading MBR returned 0 bytes. Could not read MBR for disk 4. ==================== End of Addition.txt ============================