Additional scan result of Farbar Recovery Scan Tool (x64) Version: 21-06-2017 01 Ran by [removed] (21-06-2017 16:39:22) Running from C:\Users\[removed]\Desktop Windows 10 Home Version 1703 (X64) (2017-05-25 00:03:54) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-1981365061-2981269374-140316491-500 - Administrator - Disabled) => C:\Users\Administrator DefaultAccount (S-1-5-21-1981365061-2981269374-140316491-503 - Limited - Disabled) defaultuser0 (S-1-5-21-1981365061-2981269374-140316491-1000 - Limited - Disabled) => C:\Users\defaultuser0 Guest (S-1-5-21-1981365061-2981269374-140316491-501 - Limited - Disabled) PE'el HaMashiach (S-1-5-21-1981365061-2981269374-140316491-1001 - Administrator - Enabled) => C:\Users\PE'el HaMashiach ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: McAfee VirusScan (Enabled - Up to date) {8BCDACFA-D264-3528-5EF8-E94FD0BC1FBC} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: McAfee VirusScan (Enabled - Up to date) {30AC4D1E-F45E-3AA6-6448-D23DAB3B5501} FW: McAfee Firewall (Enabled) {B3F62DDF-980B-3470-75A7-407A2E6F58C7} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) . . (Version: 7.1 - Intel) Hidden . . . (x32 Version: 2.8.0.7 - Intel) Hidden Acer Quick Access (HKLM\...\{E3678E72-78E3-4F91-A9FB-913876FF6DA2}) (Version: 2.00.3008 - Acer Incorporated) Adblock Plus for IE (32-bit and 64-bit) (HKLM\...\{F6FCA281-09CC-4753-990C-937B93A52C94}) (Version: 1.6 - Eyeo GmbH) Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 17.009.20044 - Adobe Systems Incorporated) Autorun File Remover (HKLM-x32\...\Autorun File Remover 5.0) (Version: 5.0 - SecurityXploded) Autorun File Remover (x32 Version: 5.0 - SecurityXploded) Hidden Blender (HKLM\...\{437221A8-91D1-42A0-9E04-0AD64B502374}) (Version: 2.78.1 - Blender Foundation) CyberLink Media Suite 10 (HKLM-x32\...\InstallShield_{8F14AA37-5193-4A14-BD5B-BDF9B361AEF7}) (Version: 10.0 - CyberLink Corp.) Dolby Digital Plus Home Theater (HKLM\...\{7E3D8FA1-6092-469A-955B-68FC4A2C67CA}) (Version: 7.6.3.1 - Dolby Laboratories Inc) Dropbox (HKLM-x32\...\Dropbox) (Version: 28.4.14 - Dropbox, Inc.) Dropbox Update Helper (x32 Version: 1.3.59.1 - Dropbox, Inc.) Hidden Eraser 6.2.0.2979 (HKLM\...\{C5900DE9-D199-4C27-B692-354C9A6A6C8B}) (Version: 6.2.2979 - The Eraser Project) e-Sword (HKLM-x32\...\{0BF38804-B6AE-4C32-9564-B0C0E7188D62}) (Version: 11.00.0006 - Rick Meyers) Firebird SQL Server - MAGIX Edition (HKLM-x32\...\{39AB2E37-1A55-4292-A5D3-971E9F70D0F8}) (Version: 2.1.32.0 - MAGIX AG) Freemake Video Downloader (HKLM-x32\...\Freemake Video Downloader_is1) (Version: 3.8.0 - Ellora Assets Corporation) GIMP 2.8.18 (HKLM\...\GIMP-2_is1) (Version: 2.8.18 - The GIMP Team) G'MIC for GIMP version 1.7.9 (HKLM-x32\...\G'MIC for GIMP_is1) (Version: 1.7.9 - ) Google Ad Blocker (HKLM-x32\...\Google Ad Blocker 6.5) (Version: 6.5 - SecurityXploded) Google Ad Blocker (x32 Version: 6.5 - SecurityXploded) Hidden Google Chrome (HKLM-x32\...\Google Chrome) (Version: 58.0.3029.110 - Google Inc.) Google Photos Backup (HKU\S-1-5-21-1981365061-2981269374-140316491-1001\...\Google Photos Backup) (Version: 1.1.2.13 - Google, Inc.) Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.8231.2252 - Google Inc.) Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.33.5 - Google Inc.) Hidden Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.0.0.1153 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 14.5.0.1081 - Intel Corporation) Intel(R) Wireless Bluetooth(R) (HKLM-x32\...\{7FADF1ED-241A-4F82-B8FD-19BD0A82FFA0}) (Version: 19.11.1639.0649 - Intel Corporation) Intel® Driver Update Utility (HKLM-x32\...\{b480f6cc-fa56-482b-b0a3-49d69a32db6d}) (Version: 2.8.0.7 - Intel) Intel® PROSet/Wireless Software (HKLM-x32\...\{aa2c2346-d0c0-4d3e-9ab1-11a48b4cb9f3}) (Version: 19.20.3 - Intel Corporation) Intel® Security Assist (HKLM-x32\...\{4B230374-6475-4A73-BA6E-41015E9C5013}) (Version: 1.0.0.532 - Intel Corporation) Java 8 Update 131 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180131F0}) (Version: 8.0.1310.11 - Oracle Corporation) LG ODD Auto Firmware Update (HKLM-x32\...\{6179550A-3E7C-499E-BCC9-9E8113E0A285}) (Version: 10.01.0712.01 - ) MAGIX Content and Soundpools (HKLM-x32\...\MAGIX_GlobalContent) (Version: 1.0.0.0 - MAGIX Software GmbH) MAGIX Goya burnR (MSI) (HKLM-x32\...\MAGIX_{9902D28C-2886-4425-907C-B779083A42DE}) (Version: 4.3.1.6 - MAGIX AG) MAGIX Goya burnR (MSI) (Version: 4.3.1.6 - MAGIX AG) Hidden MAGIX Music Maker 2014 (Demo songs) (HKLM-x32\...\MX.{5890A059-203C-4BEC-8542-2B465B36A5C8}) (Version: 1.0.0.0 - MAGIX AG) MAGIX Music Maker 2014 (Demo songs) (Version: 1.0.0.0 - MAGIX AG) Hidden MAGIX Music Maker 2014 (HKLM-x32\...\MX.{B916F437-CECC-4493-A8A6-3AD43CFA5DBC}) (Version: 20.0.2.35 - MAGIX AG) MAGIX Music Maker 2014 (Introductory videos) (HKLM-x32\...\MX.{E815D727-F15F-40DB-A877-DF9F7600D2B2}) (Version: 1.0.0.0 - MAGIX AG) MAGIX Music Maker 2014 (Introductory videos) (Version: 1.0.0.0 - MAGIX AG) Hidden MAGIX Music Maker 2014 (Synthesizer and effects) (HKLM-x32\...\MX.{DBA8147C-D96E-449D-8B7D-8527F0AF866A}) (Version: 1.0.0.0 - MAGIX AG) MAGIX Music Maker 2014 (Synthesizer and effects) (Version: 1.0.0.0 - MAGIX AG) Hidden MAGIX Music Maker 2014 (Version: 20.0.2.35 - MAGIX AG) Hidden MAGIX Music Maker 2014 (Visuals) (HKLM-x32\...\MX.{62CE7C6A-F54A-45F1-9C4D-6C4BE74B84FE}) (Version: 1.0.0.0 - MAGIX AG) MAGIX Music Maker 2014 (Visuals) (Version: 1.0.0.0 - MAGIX AG) Hidden MAGIX Music Maker 2014 Soundpools (Version: 1.0.0.0 - MAGIX Software GmbH) Hidden Malwarebytes version 3.1.2.1733 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.1.2.1733 - Malwarebytes) McAfee All Access – Internet Security (HKLM-x32\...\MSC) (Version: 14.0 R13 - McAfee, Inc.) McAfee WebAdvisor (HKLM-x32\...\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}) (Version: 4.0.139 - McAfee, Inc.) Microsoft Office 365 - en-us (HKLM\...\O365HomePremRetail - en-us) (Version: 16.0.8201.2102 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-1981365061-2981269374-140316491-1001\...\OneDriveSetup.exe) (Version: 17.3.6816.0313 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation) Office 16 Click-to-Run Extensibility Component (x32 Version: 16.0.8201.2102 - Microsoft Corporation) Hidden Office 16 Click-to-Run Extensibility Component 64-bit Registration (Version: 16.0.8201.2102 - Microsoft Corporation) Hidden Office 16 Click-to-Run Licensing Component (Version: 16.0.8201.2102 - Microsoft Corporation) Hidden Office 16 Click-to-Run Localization Component (x32 Version: 16.0.8201.2075 - Microsoft Corporation) Hidden Password Sniffer Spy (x32 Version: 6.0 - SecurityXploded) Hidden Prey Anti-Theft (x32 Version: 1.6.5 - Prey, Inc.) Hidden Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.10125.21277 - Realtek Semiconductor Corp.) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.1.505.2015 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7553 - Realtek Semiconductor Corp.) Recuva (HKLM\...\Recuva) (Version: 1.53 - Piriform) Revo Uninstaller Pro 3.1.9 (HKLM\...\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 3.1.9 - VS Revo Group, Ltd.) RogueKiller version 12.10.10.0 (HKLM\...\8B3D7924-ED89-486B-8322-E8594065D5CB_is1) (Version: 12.10.10.0 - Adlice Software) Security Task Manager 2.1h (HKLM-x32\...\Security Task Manager) (Version: 2.1h - Neuber Software) Spy BHO Remover (HKLM-x32\...\Spy BHO Remover 7.0) (Version: 7.0 - SecurityXploded) Spy BHO Remover (x32 Version: 7.0 - SecurityXploded) Hidden SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 6.0.1230 - SUPERAntiSpyware.com) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 19.1.3.6 - Synaptics Incorporated) Tweaking.com - Windows Repair (HKLM-x32\...\Tweaking.com - Windows Repair) (Version: 3.9.25 - Tweaking.com) Vegas Movie Studio HD 11.0 (HKLM-x32\...\{EF5F161E-9904-11E0-AAE2-0013D3D69929}) (Version: 11.0.29 - Sony) Vita 2 (Version: 2.4.0.79 - MAGIX Software GmbH) Hidden Vita Drum Engine (Version: 2.4.0.79 - MAGIX Software GmbH) Hidden Vita Electric Piano (Version: 2.4.0.78 - MAGIX Software GmbH) Hidden Vita Power Guitar (Version: 2.4.0.78 - MAGIX Software GmbH) Hidden VT-Julie-M16-SAPI5 (HKLM-x32\...\{C496F7CD-ED09-4D8D-872E-3470D4717714}) (Version: - ) VT-Kate-M16-SAPI5 (HKLM-x32\...\{9FAD67A7-3A4E-4754-AAC4-0397F370611D}) (Version: - ) VT-Paul-M16-SAPI5 (HKLM-x32\...\{942DF6BD-E4F2-4915-B4FB-09C02B71284F}) (Version: - ) Windows 10 Upgrade Assistant (HKLM-x32\...\{D5C69738-B486-402E-85AC-2456D98A64E4}) (Version: 1.4.9200.17387 - Microsoft Corporation) WinPcap 4.1.2 (HKLM-x32\...\WinPcapInst) (Version: 4.1.0.2001 - CACE Technologies) WinRAR 5.40 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.40.0 - win.rar GmbH) YouCam (x32 Version: 3.1.5324 - CyberLink Corp.) Hidden Zoom (HKU\S-1-5-21-1981365061-2981269374-140316491-1001\...\ZoomUMX) (Version: 4.0 - Zoom Video Communications, Inc.) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-1981365061-2981269374-140316491-1001_Classes\CLSID\{144DF3B2-2402-47AE-9583-5A045929A8D4}\InprocServer32 -> C:\Users\PE'el HaMashiach\AppData\Local\Google\Update\1.3.33.5\psuser_64.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-1981365061-2981269374-140316491-1001_Classes\CLSID\{8C46158B-D978-483C-A312-16EE5013BE04}\InprocServer32 -> C:\Users\PE'el HaMashiach\AppData\Local\Google\Update\1.3.33.3\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-1981365061-2981269374-140316491-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\PE'el HaMashiach\AppData\Local\Google\Update\1.3.33.5\psuser_64.dll (Google Inc.) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {0B99E40A-CF72-4E90-B744-416EB0579C03} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-12-24] (Dropbox, Inc.) Task: {159483E9-E361-4003-9753-041B4873C2BD} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1981365061-2981269374-140316491-1001UA => C:\Users\PE'el HaMashiach\AppData\Local\Google\Update\GoogleUpdate.exe [2017-04-13] (Google Inc.) Task: {1A5BC64B-62DC-4891-8ACC-22B0A3D1DFE0} - System32\Tasks\McAfeeLogon => C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe [2017-02-22] (McAfee, Inc.) Task: {1DC73408-E54F-4935-89DC-AE2386E146F4} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-12-24] (Dropbox, Inc.) Task: {20F57C65-47B0-4C02-A2D8-13CF3B3A76E9} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-04-25] (Adobe Systems Incorporated) Task: {293F4E67-5F11-41F8-90AF-945627716F19} - System32\Tasks\Microsoft\Windows\UNP\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\OutOfIdle => C:\WINDOWS\system32\UNP\UNPUXLauncher.exe Task: {2A295D00-925B-43EE-A048-D31A6FF38676} - System32\Tasks\McAfee\McAfee Idle Detection Task Task: {3567F796-BF9D-43C9-A2C0-CE20415AD6E6} - System32\Tasks\Microsoft\Windows\UNP\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Unlock => C:\WINDOWS\system32\UNP\UNPUXLauncher.exe Task: {3F6DE7B2-ACD4-41AC-8675-6DEB5EEAC2DA} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2017-06-20] () Task: {4ED17940-B4DA-4658-9958-EBBC16D510AB} - System32\Tasks\Microsoft\Windows\UNP\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Logon => C:\WINDOWS\system32\UNP\UNPUXLauncher.exe Task: {5267DF5E-40D4-449A-866B-5540668C30EB} - System32\Tasks\Microsoft\Windows\UNP\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\OnIdle => C:\WINDOWS\system32\UNP\UNPUXLauncher.exe Task: {58CE3EC9-EB3D-48E4-91A0-F74C67A6283E} - System32\Tasks\Intel\Intel Telemetry 2 => C:\Program Files\Intel\Telemetry 2.0\lrio.exe [2016-03-17] (Intel Corporation) Task: {5D754EB9-05D2-42AC-BC36-F3691CEB2A8C} - System32\Tasks\{C83656A0-9A28-489E-81E3-FD8279D756FE} => pcalua.exe -a "C:\Program Files\ByteFence\ByteFence.exe" -c /uninstall Task: {61943BD2-4C90-4F9E-B1E9-F156F7240E5E} - System32\Tasks\McAfee\McAfee Auto Maintenance Task Agent Task: {6EC76AA4-72C6-4B17-9F03-6992A26330AC} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1981365061-2981269374-140316491-1001Core => C:\Users\PE'el HaMashiach\AppData\Local\Google\Update\GoogleUpdate.exe [2017-04-13] (Google Inc.) Task: {72BE6AF9-4519-4C5F-B04F-FA5EDE636EF4} - System32\Tasks\Software Update Application => C:\ProgramData\OEM\UpgradeTool\ListCheck.exe [2015-09-04] (Acer Incorporated) Task: {730040ED-DA86-406A-8C79-E80665C2FD43} - \Avast Emergency Update -> No File <==== ATTENTION Task: {73EF50EF-C69E-476B-825E-23009505A81F} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2017-06-20] () Task: {75D1CE9D-1698-4787-AF5F-0DF7F30E4F7C} - System32\Tasks\Synaptics TouchPad Enhancements => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2017-01-17] (Synaptics Incorporated) Task: {8040A185-F432-4CC4-8137-18D9D3396D17} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-06-10] (Microsoft Corporation) Task: {88F1F91D-54C8-4E98-A442-416C0A6AF6CF} - System32\Tasks\Intel Security DAT Reputation (AMCore) periodic endpoint safety pulse => C:\Program Files\Common Files\McAfee\AMContent\scanners\x86_64\datrep\1.50.1291.1\mcdatrep.exe [2016-10-20] (McAfee, Inc.) Task: {A161DC1E-CF24-4C5C-8BA8-66E7E5F036AD} - System32\Tasks\Intel Security DAT Reputation (AMCore) Post DAT update endpoint safety pulse => C:\Program Files\Common Files\McAfee\AMContent\scanners\x86_64\datrep\1.50.1291.1\mcdatrep.exe [2016-10-20] (McAfee, Inc.) Task: {A875F926-A43C-4012-B551-DB478F7709D2} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-06-10] (Microsoft Corporation) Task: {AF9E8535-D679-4919-8FDD-82295DD32928} - System32\Tasks\Quick Access => C:\Program Files\Acer\Acer Quick Access\QALauncher.exe [2015-09-04] (Acer Incorporated) Task: {B6EB999E-34C9-47C6-A41C-E213818E2189} - System32\Tasks\DolbySelectorTask => C:\Program Files\Dolby Digital Plus\ddp.exe [2014-04-07] (Dolby Laboratories Inc.) Task: {C04329AC-ECFC-4291-8DE8-07A322D077B6} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2017-06-20] (Microsoft Corporation) Task: {C53E50B5-885E-4845-94BA-7208F0799113} - System32\Tasks\Microsoft\Windows\UNP\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Time => C:\WINDOWS\system32\UNP\UNPUXLauncher.exe Task: {DBAA7ACB-32C9-466B-BA03-0FF011A31EB5} - System32\Tasks\Tweaking.com - Windows Repair Tray Icon => C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe [2015-03-11] (Tweaking.com) Task: {DE9619EE-6E00-4563-B486-928A77C2C6DA} - System32\Tasks\Microsoft\Windows\UNP\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\RunCampaignManager2 => C:\Windows\system32\UNP\UNPCampaignManager.exe Task: {E51CF346-0AA0-4110-B7A1-A372F1B63C83} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-05-13] (Google Inc.) Task: {F497D836-7B45-42D4-B92C-44FB7B819E0C} - System32\Tasks\MirageAgent => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [2012-06-14] (CyberLink) Task: {F6CBA214-A333-4641-AB38-35D14218186C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-05-13] (Google Inc.) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe ==================== Shortcuts & WMI ======================== (The entries could be listed to be restored or removed.) Shortcut: C:\Users\PE'el HaMashiach\Desktop\VIRUS PROTECTION\TORENNTIAL\Tor Browser\Stаrt Тоr Вrоwsеr.lnk -> C:\Users\PE'el HaMashiach\Desktop\VIRUS PROTECTION\TORENNTIAL\Tor Browser\Browser\firefox.bat () Shortcut: C:\Users\PE'el HaMashiach\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Stаrt Тоr Вrоwsеr.lnk -> C:\Users\PE'el HaMashiach\Desktop\VIRUS PROTECTION\TORENNTIAL\Tor Browser\Browser\firefox.bat () Shortcut: C:\Users\PE'el HaMashiach\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Gооglе Сhrоmе.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.bat (No File) ShortcutWithArgument: C:\Users\PE'el HaMashiach\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Achieve3000 Mobile.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=kbfipcllgebfgodpghepikipjbpmccnd ShortcutWithArgument: C:\Users\PE'el HaMashiach\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Fraction Percentage Decimal.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=dokbakpodhppfpnifjmnkakjbpabhgdp ShortcutWithArgument: C:\Users\PE'el HaMashiach\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Greek Study Tool Offline.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=fpmdchblkegdjpblcocdfhbkaggepdgk ShortcutWithArgument: C:\Users\PE'el HaMashiach\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\LabCamera.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=bodcgnjlbckbnlojccdilhfckfpmkhoh ShortcutWithArgument: C:\Users\PE'el HaMashiach\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Math Vocab Cards, by The Math Learning Center.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=mbedahlhfedefficmodbeebfcepgejeb ShortcutWithArgument: C:\Users\PE'el HaMashiach\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Meme Maker.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=ioohoenpdnbgbnonfkanalnlcodcljdd ShortcutWithArgument: C:\Users\PE'el HaMashiach\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Model PeriodicTable.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=kiemhhpameemkpmhlfhijlmifnbmcmdd ShortcutWithArgument: C:\Users\PE'el HaMashiach\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Multiplication Table.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=comgffmbijjjjjmdcifgifmeijcehccn ShortcutWithArgument: C:\Users\PE'el HaMashiach\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\myHomework Student Planner.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=pembccdigcahnckbjcbehhcacplbbomj ShortcutWithArgument: C:\Users\PE'el HaMashiach\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Number Frames, by The Math Learning Center.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=idlcfdihcafblaoadpfeofbcbcmfogbc ShortcutWithArgument: C:\Users\PE'el HaMashiach\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Number Line, by The Math Learning Center.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=ociighkhkffcoplfkofojilfjholclge ShortcutWithArgument: C:\Users\PE'el HaMashiach\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Number Pieces.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=fhcpnppigjdhghbohcbogmmhmfkobgbm ShortcutWithArgument: C:\Users\PE'el HaMashiach\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Number Recall.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=jbakmadmlkdpibamdkdpdonimkkbgich ShortcutWithArgument: C:\Users\PE'el HaMashiach\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Pattern Shapes, by The Math Learning Center.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=moheohlmdhjkibapcidpmdponeaefnoi ShortcutWithArgument: C:\Users\PE'el HaMashiach\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\PDF2Ebook - PDF to EPUB Offline Converter.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=icmgmaiaohgicppgcfmnjjifkdenfiob ShortcutWithArgument: C:\Users\PE'el HaMashiach\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Periodex.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=jgchjobgkeggomcdilponoebejfjedpo ShortcutWithArgument: C:\Users\PE'el HaMashiach\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sails Live.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=hcabckokmgcienfmiadckelpjhhnfklp ShortcutWithArgument: C:\Users\PE'el HaMashiach\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\System Performance.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=cifpncnhgpcfcoknhkcflpbinkfkhapp ShortcutWithArgument: C:\Users\PE'el HaMashiach\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\tblr (1).lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=hfpbmgjmknhcakmgmfofmjloiecbocjj ShortcutWithArgument: C:\Users\PE'el HaMashiach\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\The 50 States Free.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=aghnkdcgdglcilikhaclnbbhlpfbcdko ShortcutWithArgument: C:\Users\PE'el HaMashiach\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Word Seek Word Search Puzzles.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=mabcpjfkciefmefgkfneaogfmbljljif ==================== Loaded Modules (Whitelisted) ============== 2017-03-18 16:58 - 2017-03-18 16:58 - 00138000 _____ () C:\WINDOWS\SYSTEM32\inputhost.dll 2015-09-30 20:39 - 2015-09-30 20:39 - 00415128 _____ () C:\WINDOWS\system32\igfxTray.exe 2017-03-18 16:59 - 2017-03-18 22:31 - 01731072 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2017-06-15 00:35 - 2017-06-09 08:03 - 00073216 _____ () C:\Program Files (x86)\Common Files\Freemake Shared\ProductUpdater\ProductUpdater.exe 2017-05-08 20:26 - 2017-05-08 20:26 - 10601984 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_11703.1001.45.0_x64__8wekyb3d8bbwe\WinStore.Entertainment.Mobile.dll 2017-05-08 20:26 - 2017-05-08 20:26 - 02640384 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_11703.1001.45.0_x64__8wekyb3d8bbwe\MS.Entertainment.Common.Mobile.dll 2017-05-08 20:26 - 2017-05-08 20:26 - 00765440 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_11703.1001.45.0_x64__8wekyb3d8bbwe\WinStore.Vui.dll 2017-06-01 04:26 - 2017-06-01 04:26 - 23661056 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.17042.14211.0_x64__8wekyb3d8bbwe\Video.UI.exe 2017-06-01 04:26 - 2017-06-01 04:26 - 09016320 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.17042.14211.0_x64__8wekyb3d8bbwe\EntCommon.dll 2017-05-27 10:40 - 2017-05-27 10:40 - 03140520 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.17042.14211.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll 2017-06-20 09:01 - 2017-06-20 09:01 - 00020480 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.18062.12990.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe 2017-06-20 09:01 - 2017-06-20 09:01 - 27430400 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.18062.12990.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll 2017-06-14 20:34 - 2017-06-14 20:35 - 00460288 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.18062.12990.0_x64__8wekyb3d8bbwe\Microsoft.Photos.AGM.Native.Windows.dll 2017-06-14 20:34 - 2017-06-14 20:35 - 02275328 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.18062.12990.0_x64__8wekyb3d8bbwe\MediaEngine.dll 2017-06-08 03:10 - 2017-06-08 03:10 - 03139496 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.18062.12990.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll 2017-06-14 20:34 - 2017-06-14 20:35 - 00046080 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.18062.12990.0_x64__8wekyb3d8bbwe\Microsoft.Photos.Edit.Services.dll 2016-12-15 02:32 - 2016-12-15 02:33 - 00680448 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.18062.12990.0_x64__8wekyb3d8bbwe\Microsoft.DesignCore.dll 2017-06-14 20:34 - 2017-06-14 20:35 - 00900096 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.18062.12990.0_x64__8wekyb3d8bbwe\Microsoft.RichMedia.Ink.Controls.dll 2017-05-04 22:22 - 2017-05-04 22:23 - 01062400 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.18062.12990.0_x64__8wekyb3d8bbwe\Microsoft.Sharing.dll 2017-06-20 09:01 - 2017-06-20 09:01 - 00291328 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.18062.12990.0_x64__8wekyb3d8bbwe\StoreRatingPromotion.dll 2016-12-15 06:07 - 2017-06-20 06:06 - 08931008 _____ () C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\1033\GrooveIntlResource.dll 2017-01-17 21:06 - 2015-02-08 23:18 - 00124440 _____ () C:\Program Files\Realtek\Audio\HDA\FMAPP.exe 2017-05-09 14:03 - 2017-05-09 14:03 - 00899584 _____ () \\?\C:\Windows\Prey\versions\1.6.8\node_modules\sqlite3\lib\binding\node-v46-win32-ia32\node_sqlite3.node 2015-06-24 02:07 - 2015-06-24 02:07 - 01243936 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll 2016-04-08 18:35 - 2016-04-08 18:35 - 03481600 _____ () C:\Users\PE'el HaMashiach\AppData\Local\Programs\Google\Google Photos Backup\gpuploader_i18n.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMSwissArmy => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ModuleCoreService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMSwissArmy => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcapexe => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McNaiAnn => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfemms => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeplk => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeplk.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ModuleCoreService => ""="Service" ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2016-12-14 12:05 - 2017-05-10 23:18 - 00000855 _____ C:\WINDOWS\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-1981365061-2981269374-140316491-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\PE'el HaMashiach\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper DNS Servers: [removed] - [removed] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == HKLM\...\StartupApproved\Run: => "Malwarebytes TrayApp" HKLM\...\StartupApproved\Run: => "Onboard" HKLM\...\StartupApproved\Run: => "Eraser" HKLM\...\StartupApproved\Run: => "Malwarebytes App" HKLM\...\StartupApproved\Run32: => "Dropbox" HKLM\...\StartupApproved\Run32: => "CLMLServer" HKLM\...\StartupApproved\Run32: => "LGODDFU" HKLM\...\StartupApproved\Run32: => "YouCam Tray" HKLM\...\StartupApproved\Run32: => "YouCam Mirage" HKU\S-1-5-21-1981365061-2981269374-140316491-1001\...\StartupApproved\Run: => "OneDrive" HKU\S-1-5-21-1981365061-2981269374-140316491-1001\...\StartupApproved\Run: => "SUPERAntiSpyware" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{14926550-8842-49B2-BFD1-A4017FD4ED59}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{D3EFCD2D-8C90-432F-AD37-39DD28AFABDC}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{DCD37736-8FBD-4BB6-B0B4-BF8BFFA0EDD8}] => (Allow) C:\Windows\Prey\versions\1.6.8\bin\node.exe FirewallRules: [{5D0219DB-5ADE-453D-9DC8-F1D43F32FAEF}] => (Allow) C:\Users\PE'el\airhost.exe FirewallRules: [{1322501D-0CA1-435D-B4AE-D7F6E06A8F95}] => (Allow) C:\Users\PE'el\Zoom.exe FirewallRules: [{9003FD77-2647-4F2B-96F2-7A691EA2A478}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe FirewallRules: [{E245E3B9-BA2F-48AF-8846-4CF8C923205F}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe FirewallRules: [{51647463-164D-4E10-BF24-C899BDD9C95F}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe FirewallRules: [{0405A1E6-CAF3-4809-B6D7-B49E31E9A607}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe ==================== Restore Points ========================= 21-06-2017 09:52:07 Scheduled Checkpoint ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (06/21/2017 04:39:59 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program iexplore.exe version 11.0.15063.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel. Process ID: 24e0 Start Time: 01d2eaca993a63e6 Termination Time: 0 Application Path: C:\Program Files\Internet Explorer\iexplore.exe Report Id: 45b6ff8a-36d7-4faa-ab63-12480f2ebcc6 Faulting package full name: Faulting package-relative application ID: Error: (06/21/2017 04:11:42 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program iexplore.exe version 11.0.15063.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel. Process ID: 2018 Start Time: 01d2eaca09f7ce2b Termination Time: 0 Application Path: C:\Program Files\Internet Explorer\iexplore.exe Report Id: b9e2c1c6-e435-4445-aa7a-9107207104a0 Faulting package full name: Faulting package-relative application ID: Error: (06/21/2017 03:41:59 PM) (Source: System Restore) (EventID: 8193) (User: ) Description: Failed to create restore point (Process = C:\Program Files\VS Revo Group\Revo Uninstaller Pro\RevoUninPro.exe Files\VS Revo Group\Revo Uninstaller Pro\RevoUninPro.exe" ; Description = Revo Uninstaller Pro's restore point - Avast Antivirus ; Error = 0x8007043c). Error: (06/21/2017 03:03:28 PM) (Source: System Restore) (EventID: 8193) (User: ) Description: Failed to create restore point (Process = C:\Program Files\VS Revo Group\Revo Uninstaller Pro\RevoUninPro.exe Files\VS Revo Group\Revo Uninstaller Pro\RevoUninPro.exe" ; Description = Revo Uninstaller Pro's restore point - ; Error = 0x8007043c). Error: (06/21/2017 02:55:48 PM) (Source: System Restore) (EventID: 8193) (User: ) Description: Failed to create restore point (Process = C:\Program Files\VS Revo Group\Revo Uninstaller Pro\RevoUninPro.exe Files\VS Revo Group\Revo Uninstaller Pro\RevoUninPro.exe" ; Description = Revo Uninstaller Pro's restore point - ; Error = 0x8007043c). Error: (06/21/2017 02:42:35 PM) (Source: System Restore) (EventID: 8193) (User: ) Description: Failed to create restore point (Process = C:\Program Files\VS Revo Group\Revo Uninstaller Pro\RevoUninPro.exe Files\VS Revo Group\Revo Uninstaller Pro\RevoUninPro.exe" ; Description = Revo Uninstaller Pro's restore point - ; Error = 0x8007043c). Error: (06/21/2017 07:21:43 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: PARADIGMPURPOSE) Description: Activation of app 27470VenomApps.MP4ToMP3_hjp7q0791xena!App failed with error: -2144927141 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (06/21/2017 06:34:40 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program iexplore.exe version 11.0.15063.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel. Process ID: 50c Start Time: 01d2ea6d169c969e Termination Time: 24 Application Path: C:\Program Files\Internet Explorer\iexplore.exe Report Id: c8305116-b5aa-4bb0-86a2-ba034faafdf8 Faulting package full name: Faulting package-relative application ID: Error: (06/21/2017 05:20:31 AM) (Source: ESENT) (EventID: 489) (User: ) Description: SettingSyncHost (10432) {FC8E8EE0-4FE1-42B8-9CEA-A7A03E23FFFA}: An attempt to open the file "C:\Users\PE'el HaMashiach\AppData\Local\Microsoft\Windows\SettingSync\metastore\meta.edb" for read only access failed with system error 32 (0x00000020): "The process cannot access the file because it is being used by another process. ". The open file operation will fail with error -1032 (0xfffffbf8). Error: (06/21/2017 05:20:21 AM) (Source: ESENT) (EventID: 489) (User: ) Description: SettingSyncHost (10432) {0C19BE4A-3686-4577-8453-5E45FE125A7B}: An attempt to open the file "C:\Users\PE'el HaMashiach\AppData\Local\Microsoft\Windows\SettingSync\metastore\meta.edb" for read only access failed with system error 32 (0x00000020): "The process cannot access the file because it is being used by another process. ". The open file operation will fail with error -1032 (0xfffffbf8). System errors: ============= Error: (06/21/2017 03:44:04 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: The WMPNetworkSvc service terminated with the following error: An attempt was made to reference a token that does not exist. Error: (06/21/2017 03:43:52 PM) (Source: NETLOGON) (EventID: 3095) (User: ) Description: This computer is configured as a member of a workgroup, not as a member of a domain. The Netlogon service does not need to run in this configuration. Error: (06/21/2017 03:43:50 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The CldFlt service failed to start due to the following error: The request is not supported. Error: (06/21/2017 03:43:10 PM) (Source: DCOM) (EventID: 10005) (User: NT AUTHORITY) Description: DCOM got error "1084" attempting to start the service dps with arguments "Unavailable" in order to run the server: {DDCFD26B-FEED-44CD-B71D-79487D2E5E5A} Error: (06/21/2017 03:43:10 PM) (Source: DCOM) (EventID: 10005) (User: NT AUTHORITY) Description: DCOM got error "1084" attempting to start the service dps with arguments "Unavailable" in order to run the server: {DDCFD26B-FEED-44CD-B71D-79487D2E5E5A} Error: (06/21/2017 03:43:04 PM) (Source: DCOM) (EventID: 10005) (User: PARADIGMPURPOSE) Description: DCOM got error "1084" attempting to start the service TokenBroker with arguments "Unavailable" in order to run the server: Windows.Internal.Security.Authentication.Web.TokenBrokerInternal Error: (06/21/2017 03:42:57 PM) (Source: DCOM) (EventID: 10005) (User: PARADIGMPURPOSE) Description: DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "Unavailable" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC} Error: (06/21/2017 03:42:39 PM) (Source: DCOM) (EventID: 10005) (User: PARADIGMPURPOSE) Description: DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "Unavailable" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC} Error: (06/21/2017 03:41:59 PM) (Source: DCOM) (EventID: 10005) (User: NT AUTHORITY) Description: DCOM got error "1084" attempting to start the service EventSystem with arguments "Unavailable" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} Error: (06/21/2017 03:41:53 PM) (Source: DCOM) (EventID: 10005) (User: PARADIGMPURPOSE) Description: DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "Unavailable" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC} CodeIntegrity: =================================== Date: 2017-06-14 05:47:21.658 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2017-06-14 05:47:21.071 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2017-06-14 05:47:20.833 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2017-06-13 23:48:23.384 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2017-06-13 23:46:42.122 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2017-06-13 23:45:52.128 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2017-06-13 23:45:51.628 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2017-06-13 23:45:05.749 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2017-06-13 23:45:05.267 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2017-06-13 23:45:05.049 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i7-4500U CPU @ 1.80GHz Percentage of memory in use: 39% Total physical RAM: 8072.27 MB Available physical RAM: 4917.23 MB Total Virtual: 8584.27 MB Available Virtual: 5310.79 MB ==================== Drives ================================ Drive c: (Acer) (Fixed) (Total:912.7 GB) (Free:431.47 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 931.5 GB) (Disk ID: 46D5C8F6) Partition: GPT. ==================== End of Addition.txt ============================