Additional scan result of Farbar Recovery Scan Tool (x64) Version: 31-07-2017 Ran by [removed] (01-08-2017 03:51:39) Running from C:\Users\[removed]\Desktop Windows 10 Home Version 1703 (X64) (2017-05-10 22:45:25) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-3860361705-2985921168-4046425137-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-3860361705-2985921168-4046425137-503 - Limited - Disabled) Guest (S-1-5-21-3860361705-2985921168-4046425137-501 - Limited - Disabled) New (S-1-5-21-3860361705-2985921168-4046425137-1001 - Administrator - Enabled) => C:\Users\New ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B} AV: Bitdefender Antivirus Free Antimalware (Enabled - Up to date) {3FB17364-4FCC-0FA7-6BBF-973897395371} AS: Bitdefender Antivirus Free Antimalware (Enabled - Up to date) {84D09280-69F6-0029-510F-AC4AECBE19CC} AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Connect 9 Add-in (HKU\S-1-5-21-3860361705-2985921168-4046425137-1001\...\Adobe Connect 9 Add-in) (Version: 11.9.979.366 - Adobe Systems Incorporated) Ansel (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Ansel) (Version: 382.05 - NVIDIA Corporation) Hidden ANT Drivers Installer x64 (HKLM\...\{A1EECEC9-2A14-4BE2-8820-66747A61AA8F}) (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden AORUS GRAPHICS ENGINE (HKLM-x32\...\AORUS GRAPHICS ENGINE_is1) (Version: 1.0.3 - GIGABYTE Technology Co.,Inc.) Apple Application Support (32-bit) (HKLM-x32\...\{D2FE6376-E549-4F63-A2C5-CA24DA035DE4}) (Version: 5.6 - Apple Inc.) Apple Application Support (64-bit) (HKLM\...\{BB109E24-EE90-485B-A28B-ADDEFB40540B}) (Version: 5.6 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{0A596141-97D5-45FA-9281-98DFAF48D579}) (Version: 10.3.2.3 - Apple Inc.) Apple Software Update (HKLM-x32\...\{52D87F32-70E4-4348-8148-C0B9F35B1314}) (Version: 2.3.0.177 - Apple Inc.) Bitdefender Agent (HKLM\...\Bitdefender Agent) (Version: 1.0.1 - Bitdefender) Bitdefender Antivirus Free (HKLM\...\{1FCCF41D-5F00-4FE2-9653-162D0486C8B4}) (Version: 1.0.8.20 - Bitdefender) Blizzard App (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.) Corsair LINK 4 (HKLM-x32\...\{032993f9-ff2a-46f5-822a-f2675545a46c}) (Version: 4.7.0.77 - Corsair Components, Inc.) Corsair LINK 4 (HKLM-x32\...\{39BA5516-F1A2-433B-AAB8-03FE3BC83141}) (Version: 4.7.0.77 - Corsair Components, Inc.) Hidden Corsair Link(TM) USB Dongle (Driver Removal) (HKLM-x32\...\SIUSBXP&1B1C&1C00) (Version: - Corsair Memory, Inc.) Dropbox (HKLM-x32\...\Dropbox) (Version: 30.4.22 - Dropbox, Inc.) Dropbox Update Helper (HKLM-x32\...\{099218A5-A723-43DC-8DB5-6173656A1E94}) (Version: 1.3.65.1 - Dropbox, Inc.) Hidden Elevated Installer (HKLM-x32\...\{C07003B9-FDC4-45A1-9591-ACBF55C6B022}) (Version: 5.5.0.0 - Garmin Ltd or its subsidiaries) Hidden Epic Games Launcher (HKLM-x32\...\{557DE1DA-A23F-42DE-BDB9-6315DD4FD2C6}) (Version: 1.1.112.0 - Epic Games, Inc.) Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden Futuremark SystemInfo (HKLM-x32\...\{85F94959-7098-4B55-9F39-27D880FE5BA1}) (Version: 5.1.620.0 - Futuremark) G.SKILL (HKLM-x32\...\{7D0C0C2B-7660-4463-A29A-150C45CAA287}) (Version: 1.00.16 - G.SKILL International Enterprise) Garmin Express (HKLM-x32\...\{265e66eb-aaef-49b6-a890-ab4a7a60f4a9}) (Version: 5.5.0.0 - Garmin Ltd or its subsidiaries) Garmin Express (HKLM-x32\...\{F7E67BDA-D15C-48B3-BE25-CC97739F1FDA}) (Version: 5.5.0.0 - Garmin Ltd or its subsidiaries) Hidden Garmin Express Tray (HKLM-x32\...\{3E614111-85D4-4894-9970-AF03BD189E91}) (Version: 5.5.0.0 - Garmin Ltd or its subsidiaries) Hidden GIMP 2.8.22 (HKLM\...\GIMP-2_is1) (Version: 2.8.22 - The GIMP Team) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 59.0.3071.115 - Google Inc.) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.5 - Google Inc.) Hidden IDrive Version - 6.0 (HKLM-x32\...\IDrive_is1) (Version: 6.0 - Pro Softnet Corp) Intel(R) Chipset Device Software (HKLM-x32\...\{bb0592a7-5772-4736-9d55-2402740085db}) (Version: 10.1.1.38 - Intel(R) Corporation) Hidden Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.6.0.1030 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 15.2.0.1020 - Intel Corporation) iTunes (HKLM\...\{02F95875-9527-49CC-B32F-970ADAEBD1EF}) (Version: 12.6.2.20 - Apple Inc.) Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden Malwarebytes version 3.1.2.1733 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.1.2.1733 - Malwarebytes) Microsoft Office Professional Plus 2016 - en-us (HKLM\...\ProPlusRetail - en-us) (Version: 16.0.8229.2103 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-3860361705-2985921168-4046425137-1001\...\OneDriveSetup.exe) (Version: 17.3.6943.0625 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation) MiniTool Partition Wizard Free 10.2.1 (HKLM\...\{05D996FA-ADCB-4D23-BA3C-A7C184A8FAC6}_is1) (Version: - MiniTool Solution Ltd.) Mozilla Firefox 55.0 (x64 en-US) (HKLM\...\Mozilla Firefox 55.0 (x64 en-US)) (Version: 55.0 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 55.0 - Mozilla) NVIDIA 3D Vision Controller Driver 369.04 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 369.04 - NVIDIA Corporation) NVIDIA 3D Vision Driver 382.05 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 382.05 - NVIDIA Corporation) NVIDIA GeForce Experience 3.7.0.81 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.7.0.81 - NVIDIA Corporation) NVIDIA Graphics Driver 382.05 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 382.05 - NVIDIA Corporation) NVIDIA HD Audio Driver 1.3.34.26 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.26 - NVIDIA Corporation) NVIDIA PhysX System Software 9.17.0329 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.17.0329 - NVIDIA Corporation) NvNodejs (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvNodejs) (Version: 3.7.0.81 - NVIDIA Corporation) Hidden NvTelemetry (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvTelemetry) (Version: 2.6.1.0 - NVIDIA Corporation) Hidden NvvHci (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvvHci) (Version: 2.02.0.5 - NVIDIA Corporation) Hidden Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.8229.2103 - Microsoft Corporation) Hidden Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.8229.2103 - Microsoft Corporation) Hidden Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.8229.2103 - Microsoft Corporation) Hidden Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0409-0000-0000000FF1CE}) (Version: 16.0.8201.2075 - Microsoft Corporation) Hidden Private Internet Access Support Files (HKLM-x32\...\{7D72DAFF-DCB2-437B-BC22-4B2ABF21462B}) (Version: 1.0.0.0 - Private Internet Access) qBittorrent 3.3.13 (HKLM-x32\...\qBittorrent) (Version: 3.3.13 - The qBittorrent project) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7989 - Realtek Semiconductor Corp.) SHIELD Streaming (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.NvStreamSrv) (Version: 7.1.0380 - NVIDIA Corporation) Hidden Sophos Virus Removal Tool (HKLM-x32\...\{B829E117-D072-41EA-9606-9826A38D34C1}) (Version: 2.6.1 - Sophos Limited) Sound Blaster X-Fi MB5 (HKLM-x32\...\{918A4598-866C-4B8F-8901-13F8593EBED6}) (Version: 1.00.19 - Creative Technology Limited) Spotify (HKU\S-1-5-21-3860361705-2985921168-4046425137-1001\...\Spotify) (Version: 1.0.58.573.g57c9cd87 - Spotify AB) SumatraPDF (HKLM\...\SumatraPDF) (Version: 3.1.2 - Krzysztof Kowalczyk) Twitch (HKLM-x32\...\{DEE70742-F4E9-44CA-B2B9-EE95DCF37295}) (Version: 6.0.0.0 - Twitch Interactive, Inc.) Vulkan Run Time Libraries 1.0.42.1 (HKLM\...\VulkanRT1.0.42.1) (Version: 1.0.42.1 - LunarG, Inc.) Windows Driver Package - Corsair Components, Inc. (SIUSBXP) USB (10/30/2015 3.6) (HKLM\...\689CB8E4310D795D383E65C05A8F13A05D92E771) (Version: 10/30/2015 3.6 - Corsair Components, Inc.) Windows Driver Package - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\...\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.) Windows Driver Package - Silicon Labs Software (DSI_SiUSBXp_3_1) USB (02/06/2007 3.1) (HKLM\...\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software) World of Warcraft (HKLM-x32\...\World of Warcraft) (Version: - Blizzard Entertainment) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ShellIconOverlayIdentifiers: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-07-13] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-07-13] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-07-13] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-07-13] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-07-13] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-07-13] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-07-13] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-07-13] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-07-13] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-07-13] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ 0001IDSIcon1] -> {0FA6DCC0-CF0B-427D-A8AF-97C466AB5769} => C:\Program Files (x86)\IDriveWindows\IDSyncIntIcon64.dll [2017-06-22] (Pro-Softnet Corporation, U.S.A) ShellIconOverlayIdentifiers: [ 0001IDSIcon2] -> {66357BBE-D2E5-453C-95FF-8102EB32419D} => C:\Program Files (x86)\IDriveWindows\IDSyncIntIcon64.dll [2017-06-22] (Pro-Softnet Corporation, U.S.A) ShellIconOverlayIdentifiers: [ 0001IDSIcon3] -> {904E6336-8B13-43FA-B4C3-5B62C1C91971} => C:\Program Files (x86)\IDriveWindows\IDSyncIntIcon64.dll [2017-06-22] (Pro-Softnet Corporation, U.S.A) ShellIconOverlayIdentifiers-x32: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-07-13] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-07-13] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-07-13] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-07-13] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-07-13] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-07-13] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-07-13] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-07-13] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-07-13] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-07-13] (Dropbox, Inc.) ContextMenuHandlers1: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-07-13] (Dropbox, Inc.) ContextMenuHandlers1: [IDriveMenu] -> {AFBFEC11-0FD5-48ED-B8AF-315197F09A82} => C:\Program Files (x86)\IDriveWindows\IDContextMenu.dll [2017-06-22] () ContextMenuHandlers2: [IDriveMenu] -> {AFBFEC11-0FD5-48ED-B8AF-315197F09A82} => C:\Program Files (x86)\IDriveWindows\IDContextMenu.dll [2017-06-22] () ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-05-09] (Malwarebytes) ContextMenuHandlers4: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-07-13] (Dropbox, Inc.) ContextMenuHandlers4: [IDriveMenu] -> {AFBFEC11-0FD5-48ED-B8AF-315197F09A82} => C:\Program Files (x86)\IDriveWindows\IDContextMenu.dll [2017-06-22] () ContextMenuHandlers5: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-07-13] (Dropbox, Inc.) ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\system32\nvshext.dll [2017-05-02] (NVIDIA Corporation) ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-05-09] (Malwarebytes) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {0ED943B4-D9F8-4858-ADD8-153B2A4AE5E6} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2017-06-24] (Dropbox, Inc.) Task: {1540AF48-9DC0-4043-909E-EF7B8630F59F} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-06-21] (NVIDIA Corporation) Task: {18E08D96-AD67-4476-A54D-65D533CD49A1} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-06-21] (NVIDIA Corporation) Task: {24D62E6D-4D38-477D-9462-A442C83A3322} - System32\Tasks\Bitdefender Agent WatchDog_65D6944A0EF74FDAB96E31112AD39864 => C:\Program Files\Bitdefender Agent\WatchDog.exe [2017-04-11] (Bitdefender) Task: {311E604D-EF40-4688-97AC-DFE62C638C6E} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [2017-06-21] (NVIDIA Corporation) Task: {312F13D1-09B8-4632-A80F-28D1CFF8AD40} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2017-07-07] () Task: {3C40CDF2-899A-437E-AFE2-27C62DE8FE2E} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2017-02-14] (Apple Inc.) Task: {4A8FDB1A-6985-4D88-8A43-3B8C6AE2FE8C} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2017-07-07] () Task: {54F6A501-201B-4590-B573-5FDE71129520} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2017-06-21] (NVIDIA Corporation) Task: {70413932-D764-4860-A11E-0B71F3C63969} - System32\Tasks\Start CorsairLink4 => C:\Program Files (x86)\CorsairLink4\CorsairLink4.exe [2017-05-04] (Corsair Components, Inc.) Task: {817BD46B-65D9-4863-8618-9520D3B545C5} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express SelfUpdater\ExpressSelfUpdater.exe [2017-05-23] () Task: {8B6B06E2-193D-4B0C-A990-82AA5C4CE886} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2017-06-21] (NVIDIA Corporation) Task: {8D76AE2C-ACB0-4A42-97CC-EEF56B31147A} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-06-21] (NVIDIA Corporation) Task: {984C76FE-EBFB-4FB6-9400-AB4ACFEEAFB7} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-06-24] (Google Inc.) Task: {AC3F73AD-A1C8-4868-ADD4-A4CCD151847C} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-07-18] (Microsoft Corporation) Task: {B34778AB-DCF0-4C43-A574-0FE94924F0DA} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2017-07-27] (Microsoft Corporation) Task: {D8A4F6D6-2BF9-4C8A-BC6F-33BD3D9AB4EF} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-06-24] (Google Inc.) Task: {E35A3AF1-DB47-4542-A201-1221D392D682} - System32\Tasks\Launcher GIGABYTE AORUS GRAPHICS ENGINE => C:\Program Files (x86)\GIGABYTE\AORUS GRAPHICS ENGINE\AORUS.exe [2017-04-01] (GIGABYTE Technology Co.,Ltd.) Task: {E51F1DBC-EC3B-40C7-B05D-F0F197962B77} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-06-21] (NVIDIA Corporation) Task: {E76483A9-4CE7-44DB-AFA7-1C46584D9C4E} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2017-06-24] (Dropbox, Inc.) Task: {EA8A45EF-5298-4841-B16F-ED179FBDADA6} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2017-07-27] (Microsoft Corporation) Task: {EA93B2EF-1584-4538-B2D8-BB6B6289188E} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-07-18] (Microsoft Corporation) Task: {EE042117-53E4-42EC-A91A-F85971A96CE3} - System32\Tasks\Private Internet Access Startup => C:\Program Files\pia_manager\pia_manager.exe [2017-06-24] () Task: {FA74E113-A7AD-49EC-AA3F-23C8C885DB07} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-06-21] (NVIDIA Corporation) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Task: C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe ==================== Shortcuts & WMI ======================== (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== 2017-05-09 00:44 - 2017-05-09 00:44 - 000092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2017-07-13 20:50 - 2017-07-13 20:50 - 001354040 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2017-05-11 09:05 - 2017-06-21 17:07 - 001267320 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll 2017-06-24 00:18 - 2016-04-16 21:07 - 000280576 _____ () C:\Program Files\Bitdefender Antivirus Free\txmlutil.dll 2017-06-24 00:18 - 2017-02-07 12:29 - 001008448 _____ () C:\Program Files\Bitdefender Antivirus Free\Signatures\OTEngines\OTEngines_000_000\ashttpbr.mdl 2017-06-24 00:18 - 2017-02-07 12:29 - 000541952 _____ () C:\Program Files\Bitdefender Antivirus Free\Signatures\OTEngines\OTEngines_000_000\ashttpdsp.mdl 2017-06-24 00:18 - 2017-02-07 12:29 - 003243920 _____ () C:\Program Files\Bitdefender Antivirus Free\Signatures\OTEngines\OTEngines_000_000\ashttpph.mdl 2017-06-24 00:18 - 2017-02-07 12:29 - 001544568 _____ () C:\Program Files\Bitdefender Antivirus Free\Signatures\OTEngines\OTEngines_000_000\ashttprbl.mdl 2017-07-27 12:36 - 2017-06-27 12:06 - 002260432 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll 2017-06-23 15:12 - 2017-07-07 16:04 - 008932040 _____ () C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\1033\GrooveIntlResource.dll 2017-03-19 06:58 - 2017-03-19 06:58 - 000138000 _____ () C:\Windows\SYSTEM32\inputhost.dll 2017-06-24 00:21 - 2017-06-24 00:21 - 008928137 _____ () C:\Program Files\pia_manager\pia_manager.exe 2017-03-19 06:59 - 2017-03-19 12:31 - 001731072 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2017-07-15 09:17 - 2017-07-15 09:17 - 000074752 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.19.820.0_x64__kzf8qxf38zg5c\SkypeHost.exe 2017-07-15 09:17 - 2017-07-15 09:17 - 000203264 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.19.820.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll 2017-07-15 09:17 - 2017-07-15 09:17 - 043573248 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.19.820.0_x64__kzf8qxf38zg5c\SkyWrap.dll 2017-07-15 09:17 - 2017-07-15 09:17 - 002435584 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.19.820.0_x64__kzf8qxf38zg5c\skypert.dll 2017-05-11 08:57 - 2015-07-31 17:34 - 000089600 _____ () C:\Windows\SYSTEM32\CmdRtr64.DLL 2017-05-11 08:57 - 2015-07-31 17:33 - 000366080 _____ () C:\Windows\SYSTEM32\APOMgr64.DLL 2017-05-23 09:07 - 2017-01-14 21:10 - 000218032 _____ () C:\Program Files (x86)\GIGABYTE\AORUS GRAPHICS ENGINE\MBLed.exe 2017-05-11 09:05 - 2017-06-21 17:07 - 001040504 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\libprotobuf.dll 2017-07-13 08:04 - 2017-07-13 05:58 - 000746816 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_watchdog.dll 2017-07-13 08:04 - 2017-07-13 05:58 - 001787200 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_crashpad.dll 2017-06-24 00:12 - 2017-07-13 05:58 - 000100296 _____ () C:\Program Files (x86)\Dropbox\Client\_ctypes.pyd 2017-06-24 00:12 - 2017-07-13 05:58 - 000018888 _____ () C:\Program Files (x86)\Dropbox\Client\select.pyd 2017-06-24 00:12 - 2017-07-13 06:01 - 000020800 _____ () C:\Program Files (x86)\Dropbox\Client\tornado.speedups.pyd 2017-06-24 00:12 - 2017-07-13 05:58 - 000035792 _____ () C:\Program Files (x86)\Dropbox\Client\_multiprocessing.pyd 2017-07-13 08:04 - 2017-07-13 05:59 - 000021848 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._constant_time.pyd 2017-06-24 00:12 - 2017-07-13 05:58 - 000125904 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_backend.pyd 2017-06-24 00:12 - 2017-07-13 05:58 - 000694224 _____ () C:\Program Files (x86)\Dropbox\Client\unicodedata.pyd 2017-07-13 08:04 - 2017-07-13 05:59 - 001862992 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._openssl.pyd 2017-07-13 08:04 - 2017-07-13 05:59 - 000022864 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._padding.pyd 2017-07-13 08:04 - 2017-07-13 05:58 - 000145864 _____ () C:\Program Files (x86)\Dropbox\Client\pyexpat.pyd 2017-07-13 08:04 - 2017-07-13 05:58 - 000020432 _____ () C:\Program Files (x86)\Dropbox\Client\faulthandler.pyd 2017-07-13 08:04 - 2017-07-13 05:58 - 000116688 _____ () C:\Program Files (x86)\Dropbox\Client\pywintypes27.dll 2017-06-24 00:12 - 2017-07-13 05:58 - 000105928 _____ () C:\Program Files (x86)\Dropbox\Client\win32api.pyd 2017-06-24 00:12 - 2017-07-13 06:01 - 000022864 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.crt.compiled._winffi_crt.pyd 2017-07-13 08:04 - 2017-07-13 05:59 - 000062784 _____ () C:\Program Files (x86)\Dropbox\Client\psutil._psutil_windows.pyd 2017-07-13 08:04 - 2017-07-13 05:59 - 000040248 _____ () C:\Program Files (x86)\Dropbox\Client\fastpath.pyd 2017-06-24 00:12 - 2017-07-13 05:58 - 000024528 _____ () C:\Program Files (x86)\Dropbox\Client\win32event.pyd 2017-07-13 08:04 - 2017-07-13 05:58 - 000392656 _____ () C:\Program Files (x86)\Dropbox\Client\pythoncom27.dll 2017-07-13 08:04 - 2017-07-13 05:58 - 000020936 _____ () C:\Program Files (x86)\Dropbox\Client\mmapfile.pyd 2017-06-24 00:12 - 2017-07-13 05:58 - 000116176 _____ () C:\Program Files (x86)\Dropbox\Client\win32security.pyd 2017-06-24 00:12 - 2017-07-13 06:01 - 000392512 _____ () C:\Program Files (x86)\Dropbox\Client\win32com.shell.shell.pyd 2017-06-24 00:12 - 2017-07-13 05:58 - 000124880 _____ () C:\Program Files (x86)\Dropbox\Client\win32file.pyd 2017-06-24 00:12 - 2017-07-13 06:01 - 000026456 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.kernel32.compiled._winffi_kernel32.pyd 2017-06-24 00:12 - 2017-07-13 05:58 - 000024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32clipboard.pyd 2017-06-24 00:12 - 2017-07-13 05:58 - 000175560 _____ () C:\Program Files (x86)\Dropbox\Client\win32gui.pyd 2017-06-24 00:12 - 2017-07-13 05:58 - 000030160 _____ () C:\Program Files (x86)\Dropbox\Client\win32pipe.pyd 2017-06-24 00:12 - 2017-07-13 05:58 - 000043472 _____ () C:\Program Files (x86)\Dropbox\Client\win32process.pyd 2017-06-24 00:12 - 2017-07-13 05:58 - 000048592 _____ () C:\Program Files (x86)\Dropbox\Client\win32service.pyd 2017-06-24 00:12 - 2017-07-13 05:58 - 000057808 _____ () C:\Program Files (x86)\Dropbox\Client\win32evtlog.pyd 2017-06-24 00:12 - 2017-07-13 05:58 - 000024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32profile.pyd 2017-07-13 08:04 - 2017-07-13 05:59 - 000022336 _____ () C:\Program Files (x86)\Dropbox\Client\cpuid.compiled._cpuid.pyd 2017-06-24 00:12 - 2017-07-13 06:01 - 000082264 _____ () C:\Program Files (x86)\Dropbox\Client\winenumhandles.compiled._WinEnumHandles.pyd 2017-06-24 00:12 - 2017-07-13 06:01 - 000025432 _____ () C:\Program Files (x86)\Dropbox\Client\winscreenshot.compiled._CaptureScreenshot.pyd 2017-07-13 08:04 - 2017-07-13 05:59 - 000027488 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox.infinite.win.compiled._driverinstallation.pyd 2017-07-13 08:04 - 2017-07-13 06:00 - 003928896 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWidgets.pyd 2017-06-24 00:12 - 2017-07-13 05:58 - 000083912 _____ () C:\Program Files (x86)\Dropbox\Client\sip.pyd 2017-07-13 08:04 - 2017-07-13 05:59 - 001826104 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtCore.pyd 2017-07-13 08:04 - 2017-07-13 06:00 - 001972024 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtGui.pyd 2017-06-24 00:12 - 2017-07-13 05:58 - 000028616 _____ () C:\Program Files (x86)\Dropbox\Client\win32ts.pyd 2017-07-13 08:04 - 2017-07-13 06:00 - 000171336 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebEngineWidgets.pyd 2017-07-13 08:04 - 2017-07-13 06:00 - 000042816 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebChannel.pyd 2017-07-13 08:04 - 2017-07-13 06:00 - 000531264 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtNetwork.pyd 2017-07-13 08:04 - 2017-07-13 06:00 - 000133432 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKit.pyd 2017-07-13 08:04 - 2017-07-13 06:00 - 000224064 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKitWidgets.pyd 2017-07-13 08:04 - 2017-07-13 06:00 - 000207680 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtPrintSupport.pyd 2017-06-24 00:12 - 2017-07-13 05:58 - 000060880 _____ () C:\Program Files (x86)\Dropbox\Client\win32print.pyd 2017-06-24 00:12 - 2017-07-13 06:01 - 000054608 _____ () C:\Program Files (x86)\Dropbox\Client\winrpcserver.compiled._RPCServer.pyd 2017-06-24 00:12 - 2017-07-13 06:01 - 000022864 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.user32.compiled._winffi_user32.pyd 2017-06-24 00:12 - 2017-07-13 06:01 - 000069968 _____ () C:\Program Files (x86)\Dropbox\Client\windisplaytoast.compiled._DisplayToast.pyd 2017-06-24 00:12 - 2017-07-13 06:01 - 000022872 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.iphlpapi.compiled._winffi_iphlpapi.pyd 2017-06-24 00:12 - 2017-07-13 06:01 - 000021848 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winerror.compiled._winffi_winerror.pyd 2017-06-24 00:12 - 2017-07-13 06:01 - 000022872 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.wininet.compiled._winffi_wininet.pyd 2017-06-24 00:12 - 2017-07-13 05:58 - 000349128 _____ () C:\Program Files (x86)\Dropbox\Client\winxpgui.pyd 2017-07-13 08:04 - 2017-07-13 06:00 - 000103232 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWinExtras.pyd 2017-06-24 00:12 - 2017-07-13 06:01 - 000023896 _____ () C:\Program Files (x86)\Dropbox\Client\winverifysignature.compiled._VerifySignature.pyd 2017-07-13 08:04 - 2017-07-13 05:59 - 000025936 _____ () C:\Program Files (x86)\Dropbox\Client\librsyncffi.compiled._librsyncffi.pyd 2017-07-13 08:04 - 2017-07-13 05:58 - 000036296 _____ () C:\Program Files (x86)\Dropbox\Client\librsync.dll 2017-07-13 08:04 - 2017-07-13 05:59 - 000033112 _____ () C:\Program Files (x86)\Dropbox\Client\enterprise_data.compiled._enterprise_data.pyd 2017-07-13 08:04 - 2017-07-13 05:58 - 000293392 _____ () C:\Program Files (x86)\Dropbox\Client\EnterpriseDataAdapter.dll 2017-07-13 08:04 - 2017-07-13 05:59 - 000181056 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_sqlite_ext.DLL 2017-06-24 00:12 - 2017-07-13 06:01 - 000030536 _____ () C:\Program Files (x86)\Dropbox\Client\wind3d11.compiled._wind3d11.pyd 2017-07-13 08:04 - 2017-07-13 05:59 - 000024368 _____ () C:\Program Files (x86)\Dropbox\Client\libEGL.dll 2017-07-13 08:04 - 2017-07-13 05:59 - 001637688 _____ () C:\Program Files (x86)\Dropbox\Client\libGLESv2.dll 2017-06-24 00:12 - 2017-07-13 06:01 - 000026456 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winhttp.compiled._winffi_winhttp.pyd 2017-06-24 00:12 - 2017-07-13 06:01 - 000023368 _____ () C:\Program Files (x86)\Dropbox\Client\wincrashpad.compiled._Crashpad.pyd 2017-07-13 08:04 - 2017-07-13 06:00 - 000546104 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQuick.pyd 2017-07-13 08:04 - 2017-07-13 06:00 - 000357688 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQml.pyd 2017-05-23 09:07 - 2017-01-12 18:15 - 000105472 _____ () C:\Program Files (x86)\GIGABYTE\AORUS GRAPHICS ENGINE\ycc.DLL 2017-05-23 09:07 - 2017-02-20 15:50 - 000044544 _____ () C:\Program Files (x86)\GIGABYTE\AORUS GRAPHICS ENGINE\GvLedLib.dll 2017-08-01 03:41 - 2017-08-01 03:41 - 000012800 _____ () C:\Users\New\AppData\Local\Temp\ocr1CBF.tmp\lib\ruby\1.9.1\i386-mingw32\enc\encdb.so 2017-08-01 03:41 - 2017-08-01 03:41 - 000010240 _____ () C:\Users\New\AppData\Local\Temp\ocr1CBF.tmp\lib\ruby\1.9.1\i386-mingw32\enc\iso_8859_1.so 2017-08-01 03:41 - 2017-08-01 03:41 - 000014848 _____ () C:\Users\New\AppData\Local\Temp\ocr1CBF.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans\transdb.so 2017-08-01 03:41 - 2017-08-01 03:41 - 000028672 _____ () C:\Users\New\AppData\Local\Temp\ocr1CBF.tmp\lib\ruby\1.9.1\i386-mingw32\stringio.so 2017-08-01 03:41 - 2017-08-01 03:41 - 000094208 _____ () C:\Users\New\AppData\Local\Temp\ocr1CBF.tmp\src\rgloader\rgloader193.mswin.so 2017-08-01 03:41 - 2017-08-01 03:41 - 000009216 _____ () C:\Users\New\AppData\Local\Temp\ocr1CBF.tmp\lib\ruby\1.9.1\i386-mingw32\etc.so 2017-08-01 03:41 - 2017-08-01 03:41 - 000094208 _____ () C:\Users\New\AppData\Local\Temp\ocr1CBF.tmp\lib\ruby\site_ruby\1.9.1\rgloader\rgloader193.mswin.so 2017-08-01 03:41 - 2017-08-01 03:41 - 000131584 _____ () C:\Users\New\AppData\Local\Temp\ocr1CBF.tmp\lib\ruby\1.9.1\i386-mingw32\win32ole.so 2017-08-01 03:41 - 2017-08-01 03:41 - 000088576 _____ () C:\Users\New\AppData\Local\Temp\ocr1CBF.tmp\lib\ruby\1.9.1\i386-mingw32\dl.so 2017-08-01 03:41 - 2017-08-01 03:41 - 000016896 _____ () C:\Users\New\AppData\Local\Temp\ocr1CBF.tmp\lib\ruby\1.9.1\i386-mingw32\fiddle.so 2017-08-01 03:41 - 2017-08-01 03:41 - 000127316 _____ () C:\Users\New\AppData\Local\Temp\ocr1CBF.tmp\bin\libffi-6.dll 2017-08-01 03:41 - 2017-08-01 03:41 - 000009216 _____ () C:\Users\New\AppData\Local\Temp\ocr1CBF.tmp\lib\ruby\1.9.1\i386-mingw32\enc\utf_16le.so 2017-08-01 03:41 - 2017-08-01 03:41 - 000013824 _____ () C:\Users\New\AppData\Local\Temp\ocr1CBF.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans\utf_16_32.so 2017-08-01 03:41 - 2017-08-01 03:41 - 000095744 _____ () C:\Users\New\AppData\Local\Temp\ocr1CBF.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans\single_byte.so 2017-08-01 03:41 - 2017-08-01 03:41 - 000028672 _____ () C:\Users\New\AppData\Local\Temp\ocr1CBF.tmp\lib\ruby\gems\1.9.1\gems\win32-api-1.5.3-universal-mingw32\lib\win32\ruby19\win32\api.so 2017-08-01 03:41 - 2017-08-01 03:41 - 000012800 _____ () C:\Users\New\AppData\Local\Temp\ocr86D3.tmp\lib\ruby\1.9.1\i386-mingw32\enc\encdb.so 2017-08-01 03:41 - 2017-08-01 03:41 - 000010240 _____ () C:\Users\New\AppData\Local\Temp\ocr86D3.tmp\lib\ruby\1.9.1\i386-mingw32\enc\iso_8859_1.so 2017-08-01 03:41 - 2017-08-01 03:41 - 000014848 _____ () C:\Users\New\AppData\Local\Temp\ocr86D3.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans\transdb.so 2017-08-01 03:41 - 2017-08-01 03:41 - 000028672 _____ () C:\Users\New\AppData\Local\Temp\ocr86D3.tmp\lib\ruby\1.9.1\i386-mingw32\stringio.so 2017-08-01 03:41 - 2017-08-01 03:41 - 000094208 _____ () C:\Users\New\AppData\Local\Temp\ocr86D3.tmp\src\rgloader\rgloader193.mswin.so 2017-08-01 03:41 - 2017-08-01 03:41 - 000094208 _____ () C:\Users\New\AppData\Local\Temp\ocr86D3.tmp\lib\ruby\site_ruby\1.9.1\rgloader\rgloader193.mswin.so 2017-08-01 03:41 - 2017-08-01 03:41 - 000124416 _____ () C:\Users\New\AppData\Local\Temp\ocr86D3.tmp\lib\ruby\1.9.1\i386-mingw32\socket.so 2017-08-01 03:41 - 2017-08-01 03:41 - 000071680 _____ () C:\Users\New\AppData\Local\Temp\ocr86D3.tmp\lib\ruby\1.9.1\i386-mingw32\zlib.so 2017-08-01 03:41 - 2017-08-01 03:41 - 000091648 _____ () C:\Users\New\AppData\Local\Temp\ocr86D3.tmp\bin\zlib1.dll 2017-08-01 03:41 - 2017-08-01 03:41 - 000287744 _____ () C:\Users\New\AppData\Local\Temp\ocr86D3.tmp\lib\ruby\1.9.1\i386-mingw32\openssl.so 2017-08-01 03:41 - 2017-08-01 03:41 - 000016384 _____ () C:\Users\New\AppData\Local\Temp\ocr86D3.tmp\lib\ruby\1.9.1\i386-mingw32\digest.so 2017-08-01 03:41 - 2017-08-01 03:41 - 000008192 _____ () C:\Users\New\AppData\Local\Temp\ocr86D3.tmp\lib\ruby\1.9.1\i386-mingw32\fcntl.so 2017-08-01 03:41 - 2017-08-01 03:41 - 000009216 _____ () C:\Users\New\AppData\Local\Temp\ocr86D3.tmp\lib\ruby\1.9.1\i386-mingw32\etc.so 2017-08-01 03:41 - 2017-08-01 03:41 - 000024576 _____ () C:\Users\New\AppData\Local\Temp\ocr86D3.tmp\lib\ruby\1.9.1\i386-mingw32\json\ext\parser.so 2017-08-01 03:41 - 2017-08-01 03:41 - 000009216 _____ () C:\Users\New\AppData\Local\Temp\ocr86D3.tmp\lib\ruby\1.9.1\i386-mingw32\enc\utf_16be.so 2017-08-01 03:41 - 2017-08-01 03:41 - 000009216 _____ () C:\Users\New\AppData\Local\Temp\ocr86D3.tmp\lib\ruby\1.9.1\i386-mingw32\enc\utf_16le.so 2017-08-01 03:41 - 2017-08-01 03:41 - 000008704 _____ () C:\Users\New\AppData\Local\Temp\ocr86D3.tmp\lib\ruby\1.9.1\i386-mingw32\enc\utf_32be.so 2017-08-01 03:41 - 2017-08-01 03:41 - 000008704 _____ () C:\Users\New\AppData\Local\Temp\ocr86D3.tmp\lib\ruby\1.9.1\i386-mingw32\enc\utf_32le.so 2017-08-01 03:41 - 2017-08-01 03:41 - 000040960 _____ () C:\Users\New\AppData\Local\Temp\ocr86D3.tmp\lib\ruby\1.9.1\i386-mingw32\json\ext\generator.so 2017-08-01 03:41 - 2017-08-01 03:41 - 000131584 _____ () C:\Users\New\AppData\Local\Temp\ocr86D3.tmp\lib\ruby\1.9.1\i386-mingw32\win32ole.so 2017-08-01 03:41 - 2017-08-01 03:41 - 000088576 _____ () C:\Users\New\AppData\Local\Temp\ocr86D3.tmp\lib\ruby\1.9.1\i386-mingw32\dl.so 2017-08-01 03:41 - 2017-08-01 03:41 - 000016896 _____ () C:\Users\New\AppData\Local\Temp\ocr86D3.tmp\lib\ruby\1.9.1\i386-mingw32\fiddle.so 2017-08-01 03:41 - 2017-08-01 03:41 - 000127316 _____ () C:\Users\New\AppData\Local\Temp\ocr86D3.tmp\bin\libffi-6.dll 2017-08-01 03:41 - 2017-08-01 03:41 - 000013824 _____ () C:\Users\New\AppData\Local\Temp\ocr86D3.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans\utf_16_32.so 2017-08-01 03:41 - 2017-08-01 03:41 - 000095744 _____ () C:\Users\New\AppData\Local\Temp\ocr86D3.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans\single_byte.so 2017-08-01 03:41 - 2017-08-01 03:41 - 000028672 _____ () C:\Users\New\AppData\Local\Temp\ocr86D3.tmp\lib\ruby\gems\1.9.1\gems\win32-api-1.5.3-universal-mingw32\lib\win32\ruby19\win32\api.so 2017-06-24 00:21 - 2017-06-24 00:21 - 000939520 _____ () C:\Program Files\pia_manager\pia_tray_bin\nw-win\ffmpeg.dll 2017-06-24 00:21 - 2017-06-24 00:21 - 003115520 _____ () C:\Program Files\pia_manager\pia_tray_bin\nw-win\node.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2017-03-19 07:03 - 2017-03-19 07:01 - 000000824 ____N C:\Windows\system32\Drivers\etc\hosts ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-3860361705-2985921168-4046425137-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\New\AppData\Roaming\Mozilla\Firefox\Desktop Background.bmp DNS Servers: [removed] - [removed] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: ) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == HKLM\...\StartupApproved\Run: => "iTunesHelper" HKU\S-1-5-21-3860361705-2985921168-4046425137-1001\...\StartupApproved\Run: => "GarminExpressTrayApp" HKU\S-1-5-21-3860361705-2985921168-4046425137-1001\...\StartupApproved\Run: => "OneDrive" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{14520400-3764-4438-8297-1B0AACDAB05D}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe FirewallRules: [{2FF152CE-36D5-4E34-8D0F-87B87666C040}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe FirewallRules: [{6EB216DA-0694-4A28-BA30-9D43C06DB7BC}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe FirewallRules: [{1FBF7C50-6410-4C15-B732-159F61BD78DE}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{CCD6F89F-7B5F-4AAC-999C-E61029010639}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [TCP Query User{B75127A2-098F-46ED-99BF-76570EB20072}C:\program files (x86)\gigabyte\aorus graphics engine\aorus.exe] => (Allow) C:\program files (x86)\gigabyte\aorus graphics engine\aorus.exe FirewallRules: [UDP Query User{5C28C890-956D-4323-B3DF-4D4FCE288EFC}C:\program files (x86)\gigabyte\aorus graphics engine\aorus.exe] => (Allow) C:\program files (x86)\gigabyte\aorus graphics engine\aorus.exe FirewallRules: [{BA6B18E1-B7D8-495B-A628-CD3857EF9EEF}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [{DFABDD70-B302-4F19-BD67-9500CAD8E2E9}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [TCP Query User{D465D69A-2DEF-45AA-9989-FC70548BE2A5}C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe FirewallRules: [UDP Query User{D67E36B8-3947-410C-9ABA-18C9C61E2993}C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe FirewallRules: [TCP Query User{764ADCC4-D4D9-486C-A2D1-51899E24F37B}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe FirewallRules: [UDP Query User{F315B14A-B76F-4C28-A5B9-D28C93A85396}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe FirewallRules: [TCP Query User{E7551193-0FA9-445F-BB97-F6F42B1D83D1}C:\program files\epic games\unrealtournament\engine\binaries\win64\ue4-win64-shipping.exe] => (Allow) C:\program files\epic games\unrealtournament\engine\binaries\win64\ue4-win64-shipping.exe FirewallRules: [UDP Query User{4A8C42EC-77AB-40EA-9D99-52EDD4CB3E6B}C:\program files\epic games\unrealtournament\engine\binaries\win64\ue4-win64-shipping.exe] => (Allow) C:\program files\epic games\unrealtournament\engine\binaries\win64\ue4-win64-shipping.exe FirewallRules: [{6FDB6BED-95DD-4F6F-BBFB-E4D82C1F2E7C}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe FirewallRules: [{2E2F767E-0F05-45E9-9330-164DA2EA40BB}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe FirewallRules: [{FAF93827-1728-4065-8158-DA64D8D01865}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe FirewallRules: [{39C81A6F-4944-439E-BD04-0A564FCCBDF8}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe FirewallRules: [{FB29DD40-78C1-4213-9D47-7BB97A763A39}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe FirewallRules: [{192F1739-C6BD-47DA-B761-1505EEC693D6}] => (Allow) C:\Program Files\qBittorrent\qbittorrent.exe FirewallRules: [{05529A32-56DA-4D04-983B-A974A8442A8C}] => (Allow) C:\Program Files\qBittorrent\qbittorrent.exe FirewallRules: [{08350A69-1FCB-48B0-B577-3A6DF1879622}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{3564A9E7-BB55-4118-8E9F-23616CF00BEC}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe FirewallRules: [{85690093-F496-4FFA-A411-A7178B7D4575}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{B8E98C20-59CD-4266-A7C8-D74E1F6F18D7}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{96135F51-4DCC-4379-BC6F-7BBC0AF448A8}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{760EF441-1507-44FA-8A8A-ED40D8FE79B5}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [TCP Query User{8EFBA27F-5F8A-46A4-A231-90CA05FB411C}C:\users\new\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\new\appdata\roaming\spotify\spotify.exe FirewallRules: [UDP Query User{0446524B-6829-44DE-AAE4-788C7BE59887}C:\users\new\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\new\appdata\roaming\spotify\spotify.exe FirewallRules: [TCP Query User{A3914DDB-14B6-4913-A03E-207B40F02523}C:\program files\mozilla firefox\firefox.exe] => (Allow) C:\program files\mozilla firefox\firefox.exe FirewallRules: [UDP Query User{95665D70-60D5-4DA8-AAA6-41322DB88ECB}C:\program files\mozilla firefox\firefox.exe] => (Allow) C:\program files\mozilla firefox\firefox.exe FirewallRules: [{58148D90-CD95-4796-97C5-D73AE188977C}] => (Allow) C:\Program Files\iTunes\iTunes.exe ==================== Restore Points ========================= 28-07-2017 02:37:45 Installed Sophos Virus Removal Tool. ==================== Faulty Device Manager Devices ============= Name: DocuPrint CM205 fw Description: DocuPrint CM205 fw Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (08/01/2017 03:41:18 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: AsLedService.exe, version: 0.0.0.0, time stamp: 0x58d4e237 Faulting module name: AsLedService.exe, version: 0.0.0.0, time stamp: 0x58d4e237 Exception code: 0xc0000005 Fault offset: 0x000093c4 Faulting process id: 0xd0c Faulting application start time: 0x01d30a2433e44b21 Faulting application path: C:\Program Files (x86)\AsLedService\1.00.01\AsLedService.exe Faulting module path: C:\Program Files (x86)\AsLedService\1.00.01\AsLedService.exe Report Id: 637d5299-ed81-4058-97a0-deb079ae7e50 Faulting package full name: Faulting package-relative application ID: Error: (08/01/2017 03:41:15 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: mbamtray.exe, version: 3.0.0.1068, time stamp: 0x59125d35 Faulting module name: Qt5Core.dll, version: 5.6.2.0, time stamp: 0x58ed4d4f Exception code: 0xc0000005 Fault offset: 0x0018da93 Faulting process id: 0x1bb0 Faulting application start time: 0x01d30a2434aa6386 Faulting application path: C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe Faulting module path: C:\Program Files\Malwarebytes\Anti-Malware\Qt5Core.dll Report Id: fe4c3e88-707a-4ded-ada9-9d210bca1ef0 Faulting package full name: Faulting package-relative application ID: Error: (08/01/2017 03:13:29 AM) (Source: SideBySide) (EventID: 35) (User: ) Description: Activation context generation failed for "C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest".Error in manifest or policy file "C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0". Definition is UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0". Please use sxstrace.exe for detailed diagnosis. Error: (08/01/2017 03:09:27 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: AsLedService.exe, version: 0.0.0.0, time stamp: 0x58d4e237 Faulting module name: AsLedService.exe, version: 0.0.0.0, time stamp: 0x58d4e237 Exception code: 0xc0000005 Fault offset: 0x000093c4 Faulting process id: 0xde8 Faulting application start time: 0x01d30a1fc0834116 Faulting application path: C:\Program Files (x86)\AsLedService\1.00.01\AsLedService.exe Faulting module path: C:\Program Files (x86)\AsLedService\1.00.01\AsLedService.exe Report Id: ee78ee05-84b3-41f1-8349-2d8d94c4d18f Faulting package full name: Faulting package-relative application ID: Error: (07/31/2017 04:31:52 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program bdagent.exe version 1.0.8.28 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel. Process ID: 2160 Start Time: 01d30997aa1060af Termination Time: 6 Application Path: C:\Program Files\Bitdefender Antivirus Free\bdagent.exe Report Id: 453bdbfa-7605-44ca-8f5c-b07cd0af010b Faulting package full name: Faulting package-relative application ID: Error: (07/31/2017 02:00:00 PM) (Source: ESENT) (EventID: 104) (User: ) Description: svchost (3100) SRUJet: The database engine stopped the instance (0) with error (-510). Internal Timing Sequence: [1] 0.000003 +J(0) [2] 0.000003 +J(0) [3] 0.000079 +J(0) +M(C:0K, Fs:0, WS:-48K # 0K, PF:-48K # 0K, P:-48K) [4] 0.000002 +J(0) [5] 0.004076 +J(0) +M(C:0K, Fs:1, WS:4K # 0K, PF:0K # 0K, P:0K) [6] 0.000071 +J(0) +M(C:0K, Fs:0, WS:-88K # 0K, PF:-88K # 0K, P:-88K) [7] - [8] 0.000003 +J(0) [9] 0.026424 +J(0) +M(C:-112K, Fs:3, WS:-64K # 0K, PF:-68K # 0K, P:-68K) [10] - [11] 0.000006 +J(0) +M(C:0K, Fs:2, WS:8K # 0K, PF:0K # 0K, P:0K) [12] - [13] 0.000007 +J(0) +M(C:0K, Fs:0, WS:-4K # 0K, PF:-4K # 0K, P:-4K) [14] 0.007982 +J(0) [15] 0.000011 +J(0) +M(C:0K, Fs:0, WS:-28K # 0K, PF:-28K # 0K, P:-28K) [16] 0.000002 +J(0). Error: (07/31/2017 01:58:10 PM) (Source: ESENT) (EventID: 492) (User: ) Description: svchost (3100) SRUJet: The logfile sequence in "C:\Windows\system32\SRU\" has been halted due to a fatal error. No further updates are possible for the databases that use this logfile sequence. Please correct the problem and restart or restore from backup. Error: (07/31/2017 01:58:10 PM) (Source: ESENT) (EventID: 413) (User: ) Description: svchost (3100) SRUJet: Unable to create a new logfile because the database cannot write to the log drive. The drive may be read-only, out of disk space, misconfigured, or corrupted. Error -1032. Error: (07/31/2017 01:58:10 PM) (Source: ESENT) (EventID: 486) (User: ) Description: svchost (3100) SRUJet: An attempt to move the file "C:\Windows\system32\SRU\SRUtmp.log" to "C:\Windows\system32\SRU\SRU.log" failed with system error 5 (0x00000005): "Access is denied. ". The move file operation will fail with error -1032 (0xfffffbf8). Error: (07/31/2017 10:59:13 AM) (Source: SideBySide) (EventID: 35) (User: ) Description: Activation context generation failed for "C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest".Error in manifest or policy file "C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0". Definition is UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0". Please use sxstrace.exe for detailed diagnosis. System errors: ============= Error: (08/01/2017 03:41:22 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The AsLedService service terminated unexpectedly. It has done this 1 time(s). Error: (08/01/2017 03:41:12 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The AsRogAuraService service failed to start due to the following error: The system cannot find the file specified. Error: (08/01/2017 03:41:12 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The CldFlt service failed to start due to the following error: The request is not supported. Error: (08/01/2017 03:09:38 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The AsLedService service terminated unexpectedly. It has done this 1 time(s). Error: (08/01/2017 03:09:22 AM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-DBIP8JO) Description: The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID {7022A3B3-D004-4F52-AF11-E9E987FEE25F} and APPID {ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D} to the user DESKTOP-DBIP8JO\New SID (S-1-5-21-3860361705-2985921168-4046425137-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (08/01/2017 03:09:22 AM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-DBIP8JO) Description: The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID {7022A3B3-D004-4F52-AF11-E9E987FEE25F} and APPID {ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D} to the user DESKTOP-DBIP8JO\New SID (S-1-5-21-3860361705-2985921168-4046425137-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (08/01/2017 03:09:21 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The AsRogAuraService service failed to start due to the following error: The system cannot find the file specified. Error: (08/01/2017 03:09:20 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The CldFlt service failed to start due to the following error: The request is not supported. Error: (08/01/2017 03:08:09 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (07/31/2017 10:55:07 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The AsRogAuraService service failed to start due to the following error: The system cannot find the file specified. CodeIntegrity: =================================== Date: 2017-07-19 16:06:55.258 Description: Code Integrity determined that a process (\Device\HarddiskVolume8\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume8\Windows\System32\nvspcap64.dll that did not meet the Store signing level requirements. Date: 2017-06-22 14:22:27.686 Description: Code Integrity determined that a process (\Device\HarddiskVolume6\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume6\Windows\System32\nvspcap64.dll that did not meet the Store signing level requirements. Date: 2017-06-22 14:22:03.664 Description: Code Integrity determined that a process (\Device\HarddiskVolume6\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume6\Windows\System32\nvspcap64.dll that did not meet the Store signing level requirements. Date: 2017-06-22 14:22:00.361 Description: Code Integrity determined that a process (\Device\HarddiskVolume6\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume6\Windows\System32\nvspcap64.dll that did not meet the Store signing level requirements. Date: 2017-05-23 07:54:33.973 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Windows\System32\nvspcap64.dll that did not meet the Store signing level requirements. Date: 2017-05-23 07:54:29.689 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Windows\System32\nvspcap64.dll that did not meet the Store signing level requirements. Date: 2017-05-23 07:51:40.662 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Windows\System32\nvspcap64.dll that did not meet the Store signing level requirements. Date: 2017-05-23 07:46:15.975 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Windows\System32\nvspcap64.dll that did not meet the Store signing level requirements. Date: 2017-05-23 07:46:15.823 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Windows\System32\nvspcap64.dll that did not meet the Store signing level requirements. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i7-7700K CPU @ 4.20GHz Percentage of memory in use: 16% Total physical RAM: 32720.93 MB Available physical RAM: 27443.87 MB Total Virtual: 34768.93 MB Available Virtual: 29268.78 MB ==================== Drives ================================ Drive c: (SSD Fast) (Fixed) (Total:465.21 GB) (Free:339.27 GB) NTFS Drive d: (SSD Slow) (Fixed) (Total:223.57 GB) (Free:223.37 GB) NTFS Drive e: (Storage 1) (Fixed) (Total:1862.89 GB) (Free:1862.58 GB) NTFS Drive f: () (Removable) (Total:1.86 GB) (Free:1.86 GB) FAT Drive g: (Storage 2) (Fixed) (Total:1863.01 GB) (Free:651.32 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 465.8 GB) (Disk ID: 00000000) Partition: GPT. ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 00000000) Partition: GPT. ======================================================== Disk: 2 (Size: 223.6 GB) (Disk ID: DC45EAF0) Partition 1: (Not Active) - (Size=223.6 GB) - (Type=07 NTFS) ======================================================== Disk: 3 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: A31C6920) Partition 1: (Not Active) - (Size=1863 GB) - (Type=07 NTFS) ======================================================== Disk: 4 (Size: 1.9 GB) (Disk ID: 03868762) Partition 1: (Not Active) - (Size=1.9 GB) - (Type=06) ==================== End of Addition.txt ============================