Additional scan result of Farbar Recovery Scan Tool (x64) Version: 25-06-2017 01 Ran by [removed] (25-06-2017 15:47:13) Running from C:\Users\[removed]\Downloads Windows 10 Pro Version 1607 (X64) (2017-04-06 02:19:39) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-132686726-2462809040-1152197200-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-132686726-2462809040-1152197200-503 - Limited - Disabled) Guest (S-1-5-21-132686726-2462809040-1152197200-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-132686726-2462809040-1152197200-1004 - Limited - Enabled) PC (S-1-5-21-132686726-2462809040-1152197200-1005 - Administrator - Enabled) => C:\Users\PC ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Apple Application Support (32-bit) (HKLM-x32\...\{649A1FD9-5892-46AD-8DF0-C4A43FF61CB7}) (Version: 4.1 - Apple Inc.) Apple Application Support (64-bit) (HKLM\...\{0DE0A178-AC7B-4650-806C-CF226DE03766}) (Version: 4.1 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{3540181E-340A-4E7A-B409-31663472B2F7}) (Version: 9.1.0.6 - Apple Inc.) Apple Software Update (HKLM-x32\...\{FFD1F7F1-1AC9-4BC4-A908-0686D635ABAF}) (Version: 2.1.4.131 - Apple Inc.) Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.) Discord (HKU\S-1-5-21-132686726-2462809040-1152197200-1005\...\Discord) (Version: 0.0.297 - Hammer & Chisel, Inc.) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 58.0.3029.110 - Google Inc.) Google Update Helper (x32 Version: 1.3.33.5 - Google Inc.) Hidden iTunes (HKLM\...\{E690A491-702F-4DEC-9977-C015D1DBB57C}) (Version: 12.3.1.23 - Apple Inc.) LonelyScreen 1.2 (HKLM-x32\...\LonelyScreen AirPlay Receiver_is1) (Version: 1.2 - IMTIGER Technologies Inc.) LonelyScreen 1.2.15 (HKLM-x32\...\LonelyScreen_is1) (Version: 1.2.15 - IMTIGER Technologies Inc.) MalwareFox AntiMalware (HKLM-x32\...\{8F0CD7D1-42F3-4195-95CD-833578D45057}_is1) (Version: 2.74.0.76 - Wolf of Webstreet OPC Private Limited) Microsoft OneDrive (HKU\S-1-5-21-132686726-2462809040-1152197200-1005\...\OneDriveSetup.exe) (Version: 17.3.6917.0607 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23918 (HKLM-x32\...\{dab68466-3a7d-41a8-a5cf-415e3ff8ef71}) (Version: 14.0.23918.0 - Microsoft Corporation) Morrowind (HKLM-x32\...\{C325F588-D6B1-4A7F-B6A2-914C75DDA348}) (Version: - ) ROBLOX Player for PC (HKU\S-1-5-21-132686726-2462809040-1152197200-1005\...\{373B1718-8CC5-4567-8EE2-9033AD08A680}) (Version: - ROBLOX Corporation) RollerCoaster Tycoon: Deluxe (HKLM\...\Steam App 285310) (Version: - Chris Sawyer Productions) RuneScape Launcher 2.2.2 (HKLM\...\RuneScape Launcher_is1) (Version: 2.2.2 - Jagex Ltd) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) System Requirements Lab Detection (HKLM-x32\...\{58D48435-7586-402D-BE1C-93936C0542E8}) (Version: 6.1.6.0 - Husdawg, LLC) TES Construction Set (HKLM-x32\...\{DB3C800B-081B-4146-B4E3-EFB5B77AA913}) (Version: - ) UpdateAssistant (x32 Version: 1.3.0.0 - Microsoft Corporation) Hidden Windows 10 Upgrade Assistant (HKLM-x32\...\{D5C69738-B486-402E-85AC-2456D98A64E4}) (Version: 1.4.9200.17364 - Microsoft Corporation) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {1672141C-CF2F-416A-A771-9D44D5894475} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-11-23] (Google Inc.) Task: {31E83C29-A48E-407B-A5D6-8CF1BFBDCEDF} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\UpdateAssistant => C:\WINDOWS\UpdateAssistant\UpdateAssistant.exe [2016-09-12] (Microsoft Corporation) Task: {406A836D-225F-49AF-AD84-E23888A93432} - System32\Tasks\Microsoft\Windows\SysResetDelayedCleanup => Rundll32.exe ResetEng.dll,RjvDelayedCleanupEntryPoint Task: {722B4FF4-9FE0-4843-8D3F-0B145EEF1F4B} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-11-23] (Google Inc.) Task: {7423D26C-9B85-43F3-BA3B-5BF515D3D7BB} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2015-08-27] (Apple Inc.) Task: {89814059-D5D3-4E99-8304-A3D95BB736CF} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2017-06-22] (Microsoft Corporation) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe ==================== Shortcuts & WMI ======================== (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== 2015-10-13 06:45 - 2015-10-13 06:45 - 00085800 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2015-10-13 06:45 - 2015-10-13 06:45 - 01328912 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2016-07-16 06:42 - 2016-07-16 06:42 - 00231424 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll 2017-06-22 00:53 - 2017-06-03 05:01 - 02681200 _____ () C:\WINDOWS\System32\CoreUIComponents.dll 2016-11-20 13:11 - 2016-11-20 13:11 - 00134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll 2017-04-05 23:45 - 2017-04-05 23:45 - 00474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll 2017-04-05 23:45 - 2017-04-05 23:45 - 09760768 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2017-04-05 23:45 - 2017-04-05 23:45 - 01401856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2017-04-05 23:45 - 2017-04-05 23:45 - 00757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll 2017-06-22 00:53 - 2017-06-03 03:47 - 01033216 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll 2017-06-22 00:53 - 2017-06-03 03:47 - 02424320 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll 2017-06-22 00:53 - 2017-06-03 03:51 - 04853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll 2017-06-22 01:32 - 2017-06-22 01:33 - 00074752 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.18.614.0_x64__kzf8qxf38zg5c\SkypeHost.exe 2017-06-22 01:32 - 2017-06-22 01:33 - 00203264 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.18.614.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll 2017-06-22 01:32 - 2017-06-22 01:33 - 43454464 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.18.614.0_x64__kzf8qxf38zg5c\SkyWrap.dll 2017-06-22 01:32 - 2017-06-22 01:33 - 02437120 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.18.614.0_x64__kzf8qxf38zg5c\skypert.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2015-11-12 19:44 - 2015-11-12 19:41 - 00000824 _____ C:\WINDOWS\system32\Drivers\etc\hosts ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-132686726-2462809040-1152197200-1005\Control Panel\Desktop\\Wallpaper -> C:\Users\PC\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\wallpaper.jpg DNS Servers: 172.16.0.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == HKLM\...\StartupApproved\Run: => "WindowsDefender" HKLM\...\StartupApproved\Run: => "iTunesHelper" HKLM\...\StartupApproved\Run: => "ZAM" HKLM\...\StartupApproved\Run32: => "SoundMAXPnP" HKU\S-1-5-21-132686726-2462809040-1152197200-1005\...\StartupApproved\Run: => "Discord" HKU\S-1-5-21-132686726-2462809040-1152197200-1005\...\StartupApproved\Run: => "DriverAgent Plus" HKU\S-1-5-21-132686726-2462809040-1152197200-1005\...\StartupApproved\Run: => "GoogleChromeAutoLaunch_73B90D4D0D4A45E4E1249D0D8EDB5EB0" HKU\S-1-5-21-132686726-2462809040-1152197200-1005\...\StartupApproved\Run: => "LonelyScreen" HKU\S-1-5-21-132686726-2462809040-1152197200-1005\...\StartupApproved\Run: => "OneDrive" HKU\S-1-5-21-132686726-2462809040-1152197200-1005\...\StartupApproved\Run: => "Steam" HKU\S-1-5-21-132686726-2462809040-1152197200-1005\...\StartupApproved\Run: => "UpdateReminder" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [UDP Query User{A1024111-DB75-4796-B970-9FDC06503168}C:\users\pc\downloads\draw with friends launcher.exe] => (Block) C:\users\pc\downloads\draw with friends launcher.exe FirewallRules: [TCP Query User{0CBAEB6F-D86E-494A-BDB9-3D6B8F96515E}C:\users\pc\downloads\draw with friends launcher.exe] => (Block) C:\users\pc\downloads\draw with friends launcher.exe FirewallRules: [{992E1F79-F871-4806-9584-29BEF79E7A3C}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{0C00B4B8-BDA0-4E1A-A744-D9D2B336B74C}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{1175D31B-569D-4D2E-AEBB-80334A81E458}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{E11BF62D-60FD-44E9-B584-B153602A1869}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{3F428477-8473-4B57-B6E3-0640DFAD6F34}] => (Allow) C:\Program Files\iTunes\iTunes.exe FirewallRules: [{AFC2A0B8-9514-40CC-819B-F22800B4DD04}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{B7380EB2-C418-4636-B982-84F6390ED943}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{183EA393-927E-4E2D-A21E-C39D2BAB1E65}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{0775CBB3-0ADD-4294-B2AD-EAB148D4D9FE}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [TCP Query User{46E4A211-B651-4833-B5CC-D3B5CC84E195}C:\program files (x86)\lonelyscreen\lonelyscreen.exe] => (Allow) C:\program files (x86)\lonelyscreen\lonelyscreen.exe FirewallRules: [UDP Query User{34F05278-F830-47CD-BB72-834DEE5BDDA5}C:\program files (x86)\lonelyscreen\lonelyscreen.exe] => (Allow) C:\program files (x86)\lonelyscreen\lonelyscreen.exe FirewallRules: [{16325BF1-3839-4543-BAF0-6D79045DFF0A}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{A3238153-F786-41DB-81F3-412ADFCEE6A5}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{203212EE-4E9A-4975-9F5A-6AD0CA49F3A1}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{0A6DD52B-7E51-48B1-94EA-7965D5DDA395}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\RollerCoaster Tycoon Deluxe\RCT.EXE FirewallRules: [{88125F84-DDC6-4DBC-AFB3-34ED950BC139}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\RollerCoaster Tycoon Deluxe\RCT.EXE ==================== Restore Points ========================= ATTENTION: System Restore is disabled ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (06/24/2017 10:12:09 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: ISAAC) Description: Activation of app Microsoft.WindowsStore_8wekyb3d8bbwe!App failed with error: -2147023170 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (06/24/2017 09:27:40 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: ISAAC) Description: Activation of app Microsoft.Getstarted_5.10.1441.0_x64__8wekyb3d8bbwe:App.AppX7mv0s3r0wanj0n66dy6vax24ps6avzvz.mca failed with error: -2144927149 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (06/24/2017 09:01:17 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: mbamservice.exe, version: 3.1.0.479, time stamp: 0x58f6af02 Faulting module name: mbamservice.exe, version: 3.1.0.479, time stamp: 0x58f6af02 Exception code: 0xc0000005 Fault offset: 0x0000000000048a86 Faulting process id: 0x7b8 Faulting application start time: 0x01d2ed564acd4a02 Faulting application path: C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe Faulting module path: C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe Report Id: 5f5b36a2-9717-4fef-9d1d-157e4d982239 Faulting package full name: Faulting package-relative application ID: Error: (06/24/2017 08:47:25 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: ISAAC) Description: Activation of app Microsoft.Getstarted_5.10.1441.0_x64__8wekyb3d8bbwe:App.AppX7mv0s3r0wanj0n66dy6vax24ps6avzvz.mca failed with error: -2144927149 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (06/23/2017 06:10:43 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: ISAAC) Description: Activation of app Microsoft.LockApp_cw5n1h2txyewy!WindowsDefaultLockScreen failed with error: -2144927142 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (06/23/2017 12:50:14 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: ISAAC) Description: Activation of app Microsoft.LockApp_cw5n1h2txyewy!WindowsDefaultLockScreen failed with error: -2144927142 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (06/22/2017 06:10:32 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program RobloxPlayerBeta.exe version 0.296.0.65131 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel. Process ID: ae0 Start Time: 01d2ebac82e9b5d2 Termination Time: 4294967295 Application Path: C:\Users\PC\AppData\Local\Roblox\Versions\version-2a8acf3f502a4eca\RobloxPlayerBeta.exe Report Id: fbfa310d-579f-11e7-97b9-0023ae9f51a8 Faulting package full name: Faulting package-relative application ID: Error: (06/21/2017 10:39:06 PM) (Source: COM) (EventID: 10031) (User: ) Description: An unmarshaling policy check was performed when unmarshaling a custom marshaled object and the class {2CD39202-3A2F-4935-9A86-65B919919A7F} was rejected Error: (04/30/2017 08:55:27 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: MRT.exe, version: 5.47.13703.0, time stamp: 0x58dec9f9 Faulting module name: combase.dll, version: 10.0.14393.953, time stamp: 0x58ba5954 Exception code: 0xc0000005 Fault offset: 0x00000000000b071c Faulting process id: 0x119c Faulting application start time: 0x01d2c21dc5412fa8 Faulting application path: C:\WINDOWS\system32\MRT.exe Faulting module path: C:\WINDOWS\System32\combase.dll Report Id: bff9a406-e5b7-4a0a-93a8-59e9e97582cd Faulting package full name: Faulting package-relative application ID: Error: (04/30/2017 08:52:55 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: ISAAC) Description: Activation of app Microsoft.BingWeather_8wekyb3d8bbwe!App failed with error: -2144927148 See the Microsoft-Windows-TWinUI/Operational log for additional information. System errors: ============= Error: (06/25/2017 03:38:12 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {8D8F4F83-3594-4F07-8369-FC3C3CAE4919} and APPID {F72671A9-012C-4725-9D2F-2A4D32D65169} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (06/25/2017 12:29:28 PM) (Source: DCOM) (EventID: 10010) (User: ISAAC) Description: The server {4AA0A5C4-1B9B-4F2E-99D7-99C6AEC83474} did not register with DCOM within the required timeout. Error: (06/25/2017 12:29:28 PM) (Source: DCOM) (EventID: 10010) (User: ISAAC) Description: The server {4AA0A5C4-1B9B-4F2E-99D7-99C6AEC83474} did not register with DCOM within the required timeout. Error: (06/25/2017 12:29:28 PM) (Source: DCOM) (EventID: 10010) (User: ISAAC) Description: The server {4AA0A5C4-1B9B-4F2E-99D7-99C6AEC83474} did not register with DCOM within the required timeout. Error: (06/25/2017 12:29:28 PM) (Source: DCOM) (EventID: 10010) (User: ISAAC) Description: The server {4AA0A5C4-1B9B-4F2E-99D7-99C6AEC83474} did not register with DCOM within the required timeout. Error: (06/25/2017 12:28:41 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {8D8F4F83-3594-4F07-8369-FC3C3CAE4919} and APPID {F72671A9-012C-4725-9D2F-2A4D32D65169} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (06/25/2017 12:28:39 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: A timeout was reached (30000 milliseconds) while waiting for the ZAMSvc service to connect. Error: (06/25/2017 12:28:02 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: The previous system shutdown at 10:33:35 PM on ‎6/‎24/‎2017 was unexpected. Error: (06/24/2017 10:34:17 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {8D8F4F83-3594-4F07-8369-FC3C3CAE4919} and APPID {F72671A9-012C-4725-9D2F-2A4D32D65169} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (06/24/2017 10:33:35 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: The previous system shutdown at 10:08:51 PM on ‎6/‎24/‎2017 was unexpected. CodeIntegrity: =================================== Date: 2017-06-25 15:43:54.823 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-06-25 15:43:54.820 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-06-24 21:06:40.326 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-06-24 21:06:40.324 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-04-30 20:49:45.147 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-04-30 20:49:45.144 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-04-30 20:49:20.014 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-04-30 20:49:20.012 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. ==================== Memory info =========================== Processor: Intel(R) Core(TM)2 Duo CPU E7400 @ 2.80GHz Percentage of memory in use: 49% Total physical RAM: 4020.96 MB Available physical RAM: 2036.78 MB Total Virtual: 4276.96 MB Available Virtual: 2282.02 MB ==================== Drives ================================ Drive c: (Windows) (Fixed) (Total:927.32 GB) (Free:871.05 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: DAD8CE68) Partition 1: (Active) - (Size=3.8 GB) - (Type=27) Partition 2: (Not Active) - (Size=927.3 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=450 MB) - (Type=27) ==================== End of Addition.txt ============================