Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02-11-2017 Ran by [removed] (06-11-2017 15:27:40) Running from C:\Users\[removed]\Downloads Windows 10 Home Version 1703 15063.674 (X64) (2017-09-02 18:03:18) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-3843431205-3915070046-1690682533-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-3843431205-3915070046-1690682533-503 - Limited - Disabled) Guest (S-1-5-21-3843431205-3915070046-1690682533-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-3843431205-3915070046-1690682533-1003 - Limited - Enabled) Joseph (S-1-5-21-3843431205-3915070046-1690682533-1001 - Administrator - Enabled) => C:\Users\Joseph ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF} AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 7-Zip 16.02 (HKLM-x32\...\7-Zip) (Version: 16.02 - Igor Pavlov) 7-Zip 16.04 (HKLM-x32\...\{23170F69-40C1-2701-1604-000001000000}) (Version: 16.04.00.0 - Igor Pavlov) Ace Stream Media 3.1.16.2.1 (HKU\S-1-5-21-3843431205-3915070046-1690682533-1001\...\AceStream) (Version: 3.1.16.2.1 - Ace Stream Media) <==== ATTENTION Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 3.9.1.335 - Adobe Systems Incorporated) Adobe Illustrator CC 2017 (HKLM-x32\...\ILST_21_0_0) (Version: 21.0.0 - Adobe Systems Incorporated) Adobe Photoshop CC 2017 (HKLM-x32\...\PHSP_18_0_1) (Version: 18.0.1 - Adobe Systems Incorporated) AndreaMosaic 3.36.0 (HKLM-x32\...\AndreaMosaic) (Version: - ) Avast Free Antivirus (HKLM-x32\...\Avast Antivirus) (Version: 17.7.2314 - AVAST Software) Bitdefender Agent (HKLM\...\Bitdefender Agent) (Version: 1.0.1 - Bitdefender) Components (HKLM-x32\...\{1720B0E0-C520-43A6-B677-97A1D80F3B99}) (Version: 1.0.023.00 - Lenovo) Hidden Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 8.66.4.0 - Conexant) CyberLink Power2Go 8 (HKLM-x32\...\InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}) (Version: 8.0.0.4505 - CyberLink Corp.) Deluge 1.3.13 (HKLM-x32\...\Deluge) (Version: - ) Dolby Digital Plus Advanced Audio (HKLM\...\{B0BFC63F-EA07-419E-960B-3FB2ED5DD0B2}) (Version: 7.6.5.1 - Dolby Laboratories Inc) Firewatch (HKLM-x32\...\Firewatch_is1) (Version: - ) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 61.0.3163.100 - Google Inc.) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.5 - Google Inc.) Hidden ibVPN (HKLM-x32\...\ibVPN) (Version: 1.9.3.2 - ibVPN) Intel(R) Chipset Device Software (HKLM-x32\...\{60c073df-e736-4210-9c3a-5fc2b651cef3}) (Version: 10.1.1.7 - Intel(R) Corporation) Hidden Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.0.0.1153 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 20.19.15.4531 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 14.5.0.1081 - Intel Corporation) Intel(R) Wireless Bluetooth(R) (HKLM-x32\...\{DC5673D2-228D-45BC-B9BB-9610CE67DFC0}) (Version: 17.1.1524.1353 - Intel Corporation) Intel® PROSet/Wireless Software (HKLM-x32\...\{5853172b-5520-4089-9ef4-e26c594382b3}) (Version: 19.30.0 - Intel Corporation) Java 8 Update 101 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180101F0}) (Version: 8.0.1010.13 - Oracle Corporation) Java 8 Update 151 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180151F0}) (Version: 8.0.1510.12 - Oracle Corporation) Java 8 Update 71 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218071F0}) (Version: 8.0.710.15 - Oracle Corporation) Java 8 Update 91 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218091F0}) (Version: 8.0.910.14 - Oracle Corporation) Lenovo EasyCamera (HKLM-x32\...\{E399A5B3-ED53-4DEA-AF04-8011E1EB1EAC}) (Version: 6.3.9600.11105 - Realtek Semiconductor Corp.) Lenovo Experience Improvement (HKLM\...\LenovoExperienceImprovement) (Version: 2.0.9.0 - Lenovo) Lenovo FusionEngine (HKLM-x32\...\Lenovo FusionEngine) (Version: 1.0.13.0 - Lenovo, Inc.) Lenovo OneKey Recovery (HKLM\...\{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 8.1.0.4706 - CyberLink Corp.) Hidden Lenovo OneKey Recovery (HKLM-x32\...\InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 8.1.0.4706 - CyberLink Corp.) Lenovo Photo Master (HKLM-x32\...\{BC94C56A-3649-420C-8756-2ADEBE399D33}) (Version: 2.5.5720.01 - CyberLink Corp.) Lenovo PowerDVD12 (HKLM-x32\...\{B46BEA36-0B71-4A4E-AE41-87241643FA0A}) (Version: 12.0.5328.55 - CyberLink Corp.) Hidden Lenovo PowerDVD12 (HKLM-x32\...\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}) (Version: 12.0.5328.55 - CyberLink Corp.) Lenovo QuickOptimizer (HKLM\...\{8D2C871B-1B9F-45AC-9C43-2BB18089CDFA}) (Version: 1.0.019.00 - Lenovo) Lenovo Solution Center (HKLM\...\{A5591EC4-8AD6-48EE-9F8D-FACFA8BA4E35}) (Version: 3.0.002.00 - Lenovo) Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes) Metric Collection SDK (HKLM-x32\...\{DDAA788F-52E6-44EA-ADB8-92837B11BF26}) (Version: 1.1.0012.00 - Lenovo Group Limited) Hidden Metric Collection SDK 35 (HKLM-x32\...\{C2B5B5B0-2545-4E94-B4BA-548D4BF0B196}) (Version: 1.2.0010.00 - Lenovo Group Limited) Hidden Microsoft Office Professional Plus 2016 - en-us (HKLM\...\ProPlusRetail - en-us) (Version: 16.0.8528.2147 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-3843431205-3915070046-1690682533-1001\...\OneDriveSetup.exe) (Version: 17.3.7076.1026 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23918 (HKLM-x32\...\{dab68466-3a7d-41a8-a5cf-415e3ff8ef71}) (Version: 14.0.23918.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation) Microsoft XNA Framework Redistributable 3.1 (HKLM-x32\...\{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}) (Version: 3.1.10527.0 - Microsoft Corporation) Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.8528.2147 - Microsoft Corporation) Hidden Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.8528.2147 - Microsoft Corporation) Hidden Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.8528.2147 - Microsoft Corporation) Hidden Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0409-0000-0000000FF1CE}) (Version: 16.0.8326.2107 - Microsoft Corporation) Hidden REACHit (HKLM-x32\...\{4532E4C5-C84D-4040-A044-ECFCC5C6995B}) (Version: 2.5.005.12 - Lenovo) Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.10125.31214 - Realtek Semiconductor Corp.) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.1.505.2015 - Realtek) SaferVPN 4.0.9 (HKLM-x32\...\OpenVPN) (Version: 4.0.9 - ) SafeZone Stable 4.58.2552.909 (HKLM-x32\...\SafeZone 4.58.2552.909) (Version: 4.58.2552.909 - Avast Software) Hidden SHAREit (HKLM-x32\...\SHAREit_is1) (Version: 2.5.5.0 - Lenovo) Skype™ 7.40 (HKLM-x32\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.40.103 - Skype Technologies S.A.) Spotify (HKU\S-1-5-21-3843431205-3915070046-1690682533-1001\...\Spotify) (Version: 1.0.42.151.g19de0aa6 - Spotify AB) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) The Banner Saga (HKLM-x32\...\The Banner Saga_R.G. Mechanics_is1) (Version: - R.G. Mechanics, markfiter) The Elder Scrolls V Skyrim - Extended Edition version 1.9.32.0.8 (HKLM-x32\...\The Elder Scrolls V Skyrim - Extended Edition_is1) (Version: 1.9.32.0.8 - Ra3or) This War of Mine (HKLM-x32\...\1207666873_is1) (Version: 2.2.0.6 - GOG.com) User Manuals (HKLM-x32\...\{F07C2CF8-4C53-4EC3-8162-A6221E36EB88}) (Version: 4.0.0.1 - Lenovo) Hidden User Manuals (HKLM-x32\...\InstallShield_{F07C2CF8-4C53-4EC3-8162-A6221E36EB88}) (Version: 4.0.0.1 - Lenovo) Video Thumbnails Maker by Scorp (remove only) (HKLM-x32\...\Video Thumbnails Maker) (Version: - ) VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.6 - VideoLAN) Windows 10 Update and Privacy Settings (HKLM\...\{4DFCD818-036A-4229-A67D-CF17DC461D92}) (Version: 1.0.14.0 - Microsoft Corporation) WinRAR 5.40 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 5.40.0 - win.rar GmbH) WinZip 21.0 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C2410D}) (Version: 21.0.12288 - WinZip Computing, S.L. ) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-3843431205-3915070046-1690682533-1001_Classes\CLSID\{0E270DAA-1BE6-48F2-AC49-CF295C30B57B}\InprocServer32 -> %%systemroot%%\system32\shell32.dll => No File CustomCLSID: HKU\S-1-5-21-3843431205-3915070046-1690682533-1001_Classes\CLSID\{CB2B673F-D441-4CD4-AFBE-DC4037CA4220}\InprocServer32 -> C:\Program Files\WinZip\adxloader64.dll () CustomCLSID: HKU\S-1-5-21-3843431205-3915070046-1690682533-1001_Classes\CLSID\{cece6816-6107-4dc7-bdbc-20cd5ae1ffed}\localserver32 -> C:\ProgramData\Lenovo\ImController\Plugins\LenovoAppPromotionPlugin\x64\DesktopToastsHelper.exe => No File CustomCLSID: HKU\S-1-5-21-3843431205-3915070046-1690682533-1001_Classes\CLSID\{e8c77137-e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems) ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] () ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] () ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] () ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-10-14] (AVAST Software) ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-10-14] (AVAST Software) ContextMenuHandlers1-x32: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files (x86)\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov) ContextMenuHandlers1-x32: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] () ContextMenuHandlers1-x32: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-10-14] (AVAST Software) ContextMenuHandlers1-x32: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} => C:\Program Files (x86)\Common Files\CyberLink\ShellExtComponent\CLVDShellExt.dll [2014-09-10] (Cyberlink) ContextMenuHandlers1-x32: [SHAREit.FileContextMenuExt] -> {430BD134-576D-4E75-87CD-0F5C6221A82B} => C:\Program Files (x86)\Lenovo\SHAREit\ShellEx\ShellExt64.dll [2015-07-12] (Lenovo) ContextMenuHandlers1-x32: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2016-08-14] (Alexander Roshal) ContextMenuHandlers1-x32-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext.dll [2016-08-14] (Alexander Roshal) ContextMenuHandlers1-x32-x32: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\wzshls64.dll [2017-02-10] (WinZip Computing, S.L.) ContextMenuHandlers2: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} => C:\Program Files (x86)\Common Files\CyberLink\ShellExtComponent\CLVDShellExt.dll [2014-09-10] (Cyberlink) ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-10-14] (AVAST Software) ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamext.dll [2016-03-10] (Malwarebytes) ContextMenuHandlers4-x32: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files (x86)\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov) ContextMenuHandlers4-x32: [SHAREit.FileContextMenuExt] -> {430BD134-576D-4E75-87CD-0F5C6221A82B} => C:\Program Files (x86)\Lenovo\SHAREit\ShellEx\ShellExt64.dll [2015-07-12] (Lenovo) ContextMenuHandlers4-x32: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\wzshls64.dll [2017-02-10] (WinZip Computing, S.L.) ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\system32\igfxDTCM.dll [2017-05-26] (Intel Corporation) ContextMenuHandlers6-x32: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files (x86)\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov) ContextMenuHandlers6-x32: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] () ContextMenuHandlers6-x32: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-10-14] (AVAST Software) ContextMenuHandlers6-x32: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamext.dll [2016-03-10] (Malwarebytes) ContextMenuHandlers6-x32: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2016-08-14] (Alexander Roshal) ContextMenuHandlers6-x32-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext.dll [2016-08-14] (Alexander Roshal) ContextMenuHandlers6-x32-x32: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\wzshls64.dll [2017-02-10] (WinZip Computing, S.L.) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {06071B8C-34E5-410F-BAA8-60DAF7481C68} - System32\Tasks\Lenovo\ImController\Plugins\LenovoSystemUpdatePlugin_WeeklyTask => %windir%\System32\reg.exe add hklm\SOFTWARE\Lenovo\SystemUpdatePlugin\scheduler /v start /t reg_dword /d 1 /f /reg:32 Task: {0AB07911-CDF0-443D-9C38-337C1201E70F} - System32\Tasks\WinZip Update Notifier => C:\Program Files\WinZip\WZUpdateNotifier.exe [2017-02-10] (WinZip) Task: {0E9DEAA0-9CCD-4437-AD1E-A2BD1246D2FF} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-10-23] (Microsoft Corporation) Task: {1274B14B-B131-48A1-A62E-102E9039A9C4} - System32\Tasks\Lenovo\LSC\Lenovo Solution Center Notifications => C:\Program Files\Lenovo\Lenovo Solution Center\LSCNotify.exe [2015-07-01] (Lenovo) Task: {23803462-86B1-4D1F-ACC6-69D035AA302A} - System32\Tasks\Lenovo\Experience Improvement => C:\Program Files\Lenovo\ExperienceImprovement\LenovoExperienceImprovement.exe [2016-01-22] (Lenovo) Task: {2DD2E887-0EA1-4E2F-A3B9-CAAF133B6873} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2017-10-14] (AVAST Software) Task: {3066DE4E-D09E-4940-BAFE-19183530887F} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\c43aad73-91ee-4d12-9f9a-ce54dabc0a6c => C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [2017-09-08] (Lenovo Group Limited) Task: {313498ED-7D6C-43FD-816B-9AF6F0193078} - System32\Tasks\Microsoft\Windows\PLA\LSC Memory => C:\Windows\system32\rundll32.exe C:\Windows\system32\pla.dll,PlaHost "LSC Memory" "$(Arg0)" Task: {31985D31-DA51-4489-A11C-10978F4D7E80} - System32\Tasks\Lenovo\SHPrompt => C:\Program Files (x86)\Lenovo\SHAREit\ShareitPrompt.exe [2015-07-12] () Task: {3C4E3155-CFD5-41F5-8DE8-101345D99BC3} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2017-10-12] (Microsoft Corporation) Task: {45952076-CB53-4CE7-852C-AF1D4A47C695} - System32\Tasks\Lenovo\ImController\Lenovo iM Controller Scheduled Maintenance => %windir%\system32\sc.exe START ImControllerService Task: {4F563F7D-5FC5-440E-AAE3-BC89E6FC389B} - System32\Tasks\Lenovo\SHUpdate => C:\Program Files (x86)\Lenovo\SHAREit\ShareitUpdater.exe [2015-07-12] () Task: {61EBDA53-E9C0-46F6-A2E5-E5A4DFB39F25} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2017-10-29] (Microsoft Corporation) Task: {64EE18BF-B65D-481D-B8D2-6853F8400D82} - System32\Tasks\WinZipBackGroundToolsTask => C:\Program Files\WinZip\WzBGTools.exe [2017-02-10] (WinZip Computing, S.L.) Task: {651A4F2D-EC1D-48BB-B4F9-67C4D26795A0} - System32\Tasks\ibVPN-Service => C:\Program Files (x86)\ibVPN\ibVPN.service.exe [2016-05-12] () Task: {67118750-B942-4A13-AC14-3D6924530B2B} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-01-24] (Google Inc.) Task: {6D26FE03-D043-42FE-B1AE-03FC98C0A760} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe Task: {7CB96773-EC2B-4B84-A33F-2B89F2A6A0CD} - System32\Tasks\Lenovo\LSC\LSCHardwareScan => C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe [2015-07-01] () Task: {810BF206-6BED-4A31-A5EB-D30DABCF7410} - System32\Tasks\Lenovo\LSC\LSCHardwareScanPostpone => C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe [2015-07-01] () Task: {813D1A12-6EED-47A6-9721-CA5F98AEDA86} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\97714319-6e95-49e0-89b2-ff66303c32d8 => C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [2017-09-08] (Lenovo Group Limited) Task: {8295A9E3-D9F1-4593-9231-08BA23419C20} - System32\Tasks\PDVDServ12 Task => C:\Program Files (x86)\Lenovo\PowerDVD12\PDVD12Serv.exe [2015-05-28] (CyberLink Corp.) Task: {8C9EF4F0-0DAD-400B-8753-67FDEB25E091} - \{7E0D0C47-0905-057D-0911-787D08791109} -> No File <==== ATTENTION Task: {A1B28DCD-B266-49D2-827E-5994165C0B92} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program 64 => C:\Program Files (x86)\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe [2015-07-08] (Lenovo) Task: {AD39C6E1-7C4C-4D97-9C79-265092EA3B9E} - System32\Tasks\Bitdefender Agent WatchDog_65D6944A0EF74FDAB96E31112AD39864 => C:\Program Files\Bitdefender Agent\WatchDog.exe [2017-04-11] (Bitdefender) Task: {B1C44DA7-7FCB-4DF1-BF30-0D3C98A00053} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\e677b90d-5650-4067-bbb7-4ea0663f493a => C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [2017-09-08] (Lenovo Group Limited) Task: {B5F8F2CB-6AC6-438B-8C68-9FE610DF9BB7} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-10-23] (Microsoft Corporation) Task: {B9899586-9D06-4535-B65A-A3757401880D} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\157f3c45-26d9-4c58-9535-99f0124effda => C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [2017-09-08] (Lenovo Group Limited) Task: {C937CA28-0136-4087-B7D3-4A74E523CA6C} - System32\Tasks\SafeZone scheduled Autoupdate 1467359609 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2017-08-04] (Avast Software) Task: {CCA2583A-9717-49F5-95DE-3AEC3A7BE466} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2017-09-28] () Task: {D0431C2C-CDE5-44A9-93C5-897D98CA5F2A} - System32\Tasks\CyberLink\Photo Master Gadget startup => C:\Program Files (x86)\Lenovo\Lenovo Photo Master\PhotoMasterWorker.exe [2016-09-21] (CyberLink Corp.) Task: {DD37E3E6-F3C0-4547-8FDF-FE03A1E8EB79} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2017-09-28] () Task: {E2664D6D-87B0-4470-B498-07D83222EA2C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-01-24] (Google Inc.) Task: {E2B8121B-9DD2-4722-B7B9-E30DFB40411C} - System32\Tasks\Lenovo\REACHit Agent Update => C:\Program Files (x86)\Lenovo\REACHit\REACHitAgent.exe [2016-05-18] (Lenovo) Task: {E45E351C-4CD0-4EA9-9AB5-1AE34EDF1233} - System32\Tasks\Lenovo\REACHit Agent Startup => C:\Program Files (x86)\Lenovo\REACHit\REACHitAgent.exe [2016-05-18] (Lenovo) Task: {EC205F48-B13A-412B-8C38-5604ADEB8FFC} - System32\Tasks\[removed] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2016-07-01] (Adobe Systems Incorporated) Task: {F49711E6-DA69-4C68-8F83-E3B1BD1CF40C} - System32\Tasks\Lenovo\Lenovo Solution Center Launcher => C:\Program Files\lenovo\lenovo solution center\App\LSCService.exe [2015-07-01] (Lenovo) Task: {FB659924-2953-4235-8E5F-4E348F7D5530} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2017-10-29] (Microsoft Corporation) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) ==================== Shortcuts & WMI ======================== (The entries could be listed to be restored or removed.) ShortcutWithArgument: C:\Users\Joseph\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\PassesForTheMasses - Powered by vBull.._.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=ehkmioaibhmebopjllmclchklobcjdoi ShortcutWithArgument: C:\Users\Joseph\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Pocket (1).lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=melekjlemdlndekpnpeednjhikmpadbp ShortcutWithArgument: C:\Users\Joseph\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Pocket (2).lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=melekjlemdlndekpnpeednjhikmpadbp ShortcutWithArgument: C:\Users\Joseph\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Pocket (3).lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=melekjlemdlndekpnpeednjhikmpadbp ShortcutWithArgument: C:\Users\Joseph\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Pocket (4).lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=melekjlemdlndekpnpeednjhikmpadbp ShortcutWithArgument: C:\Users\Joseph\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Pocket (5).lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=melekjlemdlndekpnpeednjhikmpadbp ShortcutWithArgument: C:\Users\Joseph\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Pocket.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=melekjlemdlndekpnpeednjhikmpadbp ==================== Loaded Modules (Whitelisted) ============== 2017-08-09 05:27 - 2017-08-09 05:27 - 002227560 _____ () C:\Program Files (x86)\SaferVPN\SaferVPN.Service.exe 2017-03-18 12:58 - 2017-03-18 12:58 - 000138000 _____ () C:\WINDOWS\SYSTEM32\inputhost.dll 2016-10-25 09:57 - 2016-10-25 09:57 - 000491184 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll 2017-05-26 04:11 - 2017-05-26 04:11 - 000401840 _____ () C:\WINDOWS\system32\igfxTray.exe 2017-03-18 12:59 - 2017-03-18 18:31 - 001731072 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2017-09-01 23:40 - 2010-10-26 11:40 - 000049056 _____ () C:\Program Files\CONEXANT\ForteConfig\fmapp.exe 2017-08-09 05:27 - 2017-08-09 05:27 - 009993064 _____ () C:\Program Files (x86)\SaferVPN\SaferVPN.exe 2016-10-25 09:57 - 2016-10-25 09:57 - 031723696 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe 2015-11-09 22:54 - 2015-11-09 22:54 - 000027000 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\updater\ace_update.exe 2017-10-14 03:31 - 2017-10-14 03:31 - 000067408 _____ () C:\Program Files\AVAST Software\Avast\x64\module_lifetime.dll 2017-03-18 12:58 - 2017-03-18 12:58 - 001899008 _____ () C:\Windows\System32\speech_onecore\engines\tts\MSTTSEngine_OneCore.dll 2017-03-18 12:58 - 2017-03-18 12:58 - 000758272 _____ () C:\Windows\System32\speech_onecore\engines\tts\MSTTSLoc_OneCore.DLL 2017-09-26 09:38 - 2017-09-20 23:29 - 004022616 _____ () C:\Program Files (x86)\Google\Chrome\Application\61.0.3163.100\libglesv2.dll 2017-09-26 09:38 - 2017-09-20 23:29 - 000100184 _____ () C:\Program Files (x86)\Google\Chrome\Application\61.0.3163.100\libegl.dll 2017-10-31 16:40 - 2017-10-31 16:41 - 000015872 _____ () C:\Program Files\WindowsApps\Microsoft.People_10.2.2791.0_x64__8wekyb3d8bbwe\PeopleApp.exe 2017-10-31 16:40 - 2017-10-31 16:41 - 009347072 _____ () C:\Program Files\WindowsApps\Microsoft.People_10.2.2791.0_x64__8wekyb3d8bbwe\PeopleApp.dll 2017-10-31 16:40 - 2017-10-31 16:41 - 000132096 _____ () C:\Program Files\WindowsApps\Microsoft.People_10.2.2791.0_x64__8wekyb3d8bbwe\PeopleUtilRT.Windows.dll 2017-09-02 10:43 - 2017-09-02 10:44 - 003553704 _____ () C:\Program Files\WindowsApps\Microsoft.People_10.2.2791.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll 2017-10-31 16:40 - 2017-10-31 16:41 - 004176896 _____ () C:\Program Files\WindowsApps\Microsoft.People_10.2.2791.0_x64__8wekyb3d8bbwe\Microsoft.Apps.People.Shared.dll 2017-10-31 16:40 - 2017-10-31 16:41 - 002963968 _____ () C:\Program Files\WindowsApps\Microsoft.People_10.2.2791.0_x64__8wekyb3d8bbwe\People.BackgroundTasks.dll 2017-10-31 16:40 - 2017-10-31 16:41 - 001989120 _____ () C:\Program Files\WindowsApps\Microsoft.People_10.2.2791.0_x64__8wekyb3d8bbwe\Microsoft.People.Relevance.dll 2017-10-31 16:40 - 2017-10-31 16:41 - 006637056 _____ () C:\Program Files\WindowsApps\Microsoft.People_10.2.2791.0_x64__8wekyb3d8bbwe\Microsoft.People.NativeComponents.dll 2016-07-16 06:30 - 2016-07-16 06:30 - 000258560 _____ () C:\Program Files\WindowsApps\Microsoft.People_10.2.2791.0_x64__8wekyb3d8bbwe\StoreRatingPromotion.dll 2017-11-06 13:56 - 2017-11-06 13:56 - 000087552 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.8.480.0_x64__kzf8qxf38zg5c\SkypeHost.exe 2017-11-06 13:56 - 2017-11-06 13:56 - 000206336 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.8.480.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll 2017-11-06 13:56 - 2017-11-06 13:56 - 025461760 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.8.480.0_x64__kzf8qxf38zg5c\SkyWrap.dll 2017-11-06 13:56 - 2017-11-06 13:56 - 002552832 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.8.480.0_x64__kzf8qxf38zg5c\skypert.dll 2017-11-06 13:56 - 2017-11-06 13:56 - 000685056 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.8.480.0_x64__kzf8qxf38zg5c\RtmMvrUap.dll 2016-02-27 21:20 - 2017-10-22 02:27 - 008929464 _____ () C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\1033\GrooveIntlResource.dll 2017-08-01 05:49 - 2017-08-01 05:49 - 000131072 _____ () C:\Program Files (x86)\SaferVPN\nfapi.DLL 2017-10-14 03:31 - 2017-10-14 03:31 - 000167096 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll 2017-10-14 03:31 - 2017-10-14 03:31 - 000059040 _____ () C:\Program Files\AVAST Software\Avast\module_lifetime.dll 2017-07-11 23:54 - 2017-07-11 23:54 - 067109376 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2017-10-14 03:31 - 2017-10-14 03:31 - 000217088 _____ () C:\Program Files\AVAST Software\Avast\event_routing_rpc.dll 2017-10-14 03:31 - 2017-10-14 03:31 - 000244584 _____ () C:\Program Files\AVAST Software\Avast\tasks_core.dll 2017-10-14 03:31 - 2017-10-14 03:31 - 000234280 _____ () C:\Program Files\AVAST Software\Avast\gaming_mode_ui.dll 2017-10-14 03:31 - 2017-10-14 03:31 - 000700656 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll 2017-08-21 01:15 - 2017-10-04 16:56 - 000340480 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\engine\lib\acestreamengine.Core.pyd 2016-12-17 09:45 - 2016-12-17 09:45 - 000046592 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\engine\lib\_socket.pyd 2016-12-17 09:45 - 2016-12-17 09:45 - 001410048 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\engine\lib\_ssl.pyd 2016-12-17 09:46 - 2016-12-17 09:46 - 001016832 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\engine\lib\_hashlib.pyd 2015-04-16 04:27 - 2015-04-16 04:27 - 000018944 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\engine\lib\acestreamengine.pycompat.pyd 2016-12-17 09:44 - 2016-12-17 09:44 - 000136704 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\engine\lib\_elementtree.pyd 2016-12-17 09:44 - 2016-12-17 09:44 - 000136704 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\engine\lib\pyexpat.pyd 2015-11-07 04:14 - 2015-11-07 04:14 - 002977792 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\engine\lib\lxml.etree.pyd 2012-02-07 08:37 - 2012-02-07 08:37 - 000167424 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\engine\lib\win32gui.pyd 2012-02-07 08:35 - 2012-02-07 08:35 - 000110080 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\engine\lib\pywintypes27.dll 2012-02-07 08:36 - 2012-02-07 08:36 - 000035840 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\engine\lib\win32process.pyd 2014-01-23 03:37 - 2014-01-23 03:37 - 000036352 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\engine\lib\_psutil_mswindows.pyd 2012-02-07 08:37 - 2012-02-07 08:37 - 000098816 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\engine\lib\win32api.pyd 2012-02-07 08:38 - 2012-02-07 08:38 - 000358912 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\engine\lib\pythoncom27.dll 2012-02-07 08:36 - 2012-02-07 08:36 - 000111616 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\engine\lib\win32file.pyd 2012-02-07 08:36 - 2012-02-07 08:36 - 000024064 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\engine\lib\win32pdh.pyd 2015-04-16 04:27 - 2015-04-16 04:27 - 002386432 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\engine\lib\acestreamengine.pywebrtc.pyd 2017-08-21 01:11 - 2017-10-04 16:56 - 003189760 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\engine\lib\acestreamengine.live.pyd 2013-12-21 05:20 - 2013-12-21 05:20 - 000053248 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\engine\lib\_blist.pyd 2016-12-17 09:44 - 2016-12-17 09:44 - 000091648 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\engine\lib\_ctypes.pyd 2013-12-21 05:20 - 2013-12-21 05:20 - 000040448 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\engine\lib\bitarray._bitarray.pyd 2016-12-17 09:44 - 2016-12-17 09:44 - 000010240 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\engine\lib\select.pyd 2011-01-18 13:56 - 2011-01-18 13:56 - 000334336 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\engine\lib\M2Crypto.__m2crypto.pyd 2011-02-13 07:02 - 2011-02-13 07:02 - 000031232 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\engine\lib\Crypto.Cipher.AES.pyd 2017-08-21 01:47 - 2017-10-04 16:56 - 005688832 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\engine\lib\acestreamengine.CoreApp.pyd 2016-12-17 09:45 - 2016-12-17 09:45 - 000050688 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\engine\lib\_sqlite3.pyd 2016-12-17 09:45 - 2016-12-17 09:45 - 000551424 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\engine\lib\sqlite3.dll 2016-05-08 11:48 - 2016-05-08 11:48 - 000014848 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\engine\lib\netifaces.pyd 2010-10-10 14:23 - 2010-10-10 14:23 - 000723968 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\engine\lib\apsw.pyd 2013-01-29 08:20 - 2013-01-29 08:20 - 000082944 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\engine\lib\cpyamf.util.pyd 2011-07-15 11:37 - 2011-07-15 11:37 - 000981504 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\engine\lib\wx._core_.pyd 2011-07-15 11:38 - 2011-07-15 11:38 - 000746496 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\engine\lib\wx._gdi_.pyd 2011-07-15 11:38 - 2011-07-15 11:38 - 000670720 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\engine\lib\wx._windows_.pyd 2011-07-15 11:38 - 2011-07-15 11:38 - 000966144 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\engine\lib\wx._controls_.pyd 2011-07-15 11:38 - 2011-07-15 11:38 - 000674816 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\engine\lib\wx._misc_.pyd 2016-12-17 09:44 - 2016-12-17 09:44 - 000687104 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\engine\lib\unicodedata.pyd 2017-01-14 16:56 - 2017-10-04 16:56 - 000273000 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\engine\lib\acestreamengine.pysegmenter.pyd 2015-04-16 04:29 - 2015-04-16 04:29 - 000112142 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\engine\lib\libgcc_s_dw2-1.dll 2015-04-16 04:29 - 2015-04-16 04:29 - 000061952 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\engine\lib\miniupnpc.pyd 2016-12-17 09:44 - 2016-12-17 09:44 - 000027648 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\engine\lib\_multiprocessing.pyd 2013-01-29 08:20 - 2013-01-29 08:20 - 000066048 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\engine\lib\cpyamf.amf0.pyd 2015-08-11 06:50 - 2014-07-03 20:35 - 000627672 _____ () C:\Program Files (x86)\Lenovo\Power2Go\CLMediaLibrary.dll 2014-07-04 11:35 - 2014-07-04 11:35 - 000016856 _____ () C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvcPS.dll 2016-10-25 10:51 - 2016-10-25 10:51 - 040523456 _____ () C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\CEF\libcef.dll 2016-10-12 01:08 - 2016-10-12 01:08 - 000118272 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\node_modules\fs-ext\build\Release\fs-ext.node 2016-10-12 01:08 - 2016-10-12 01:08 - 000223232 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\node_modules\node-vulcanjs\build\Release\VulcanJS.node 2016-10-12 01:08 - 2016-10-12 01:08 - 000117248 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\node_modules\ref\build\Release\binding.node 2016-10-12 01:08 - 2016-10-12 01:08 - 000124928 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\node_modules\ffi\build\Release\ffi_bindings.node 2016-10-25 10:49 - 2016-10-25 10:49 - 000098496 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\node_modules\node-ProxyResolver\build\Release\ProxyResolverWin.dll 2016-10-12 01:08 - 2016-10-12 01:08 - 000166400 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\node_modules\idle-gc\build\Release\idle-gc.node 2016-12-30 00:18 - 2017-10-04 16:56 - 000318976 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\engine\lib\acestreamengine.jsplayer.pyd 2016-09-27 07:42 - 2016-09-27 07:42 - 000350720 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\engine\lib\acestreamengine.pyvlc.pyd 2017-01-18 04:51 - 2017-01-18 04:51 - 000165216 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\player\libtsplayer.dll 2017-01-18 04:51 - 2017-01-18 04:51 - 001968480 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\player\libtsplayercore.dll 2011-06-12 05:09 - 2011-06-12 05:09 - 000038400 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\updater\lib\_socket.pyd 2011-06-12 05:09 - 2011-06-12 05:09 - 000720896 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\updater\lib\_ssl.pyd 2011-07-15 11:37 - 2011-07-15 11:37 - 000981504 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\updater\lib\wx._core_.pyd 2011-07-15 11:38 - 2011-07-15 11:38 - 000746496 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\updater\lib\wx._gdi_.pyd 2011-07-15 11:38 - 2011-07-15 11:38 - 000670720 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\updater\lib\wx._windows_.pyd 2011-07-15 11:38 - 2011-07-15 11:38 - 000966144 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\updater\lib\wx._controls_.pyd 2011-07-15 11:38 - 2011-07-15 11:38 - 000674816 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\updater\lib\wx._misc_.pyd 2011-06-12 05:06 - 2011-06-12 05:06 - 000287232 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\updater\lib\_hashlib.pyd 2011-01-18 13:56 - 2011-01-18 13:56 - 000334336 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\updater\lib\M2Crypto.__m2crypto.pyd 2011-06-12 05:06 - 2011-06-12 05:06 - 000011776 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\updater\lib\select.pyd 2011-06-12 05:06 - 2011-06-12 05:06 - 000152576 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\updater\lib\pyexpat.pyd 2012-02-07 08:37 - 2012-02-07 08:37 - 000098816 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\updater\lib\win32api.pyd 2012-02-07 08:35 - 2012-02-07 08:35 - 000110080 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\updater\lib\pywintypes27.dll 2012-02-07 08:38 - 2012-02-07 08:38 - 000358912 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\updater\lib\pythoncom27.dll 2012-02-07 08:36 - 2012-02-07 08:36 - 000111616 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\updater\lib\win32file.pyd 2012-02-07 08:36 - 2012-02-07 08:36 - 000024064 _____ () C:\Users\Joseph\AppData\Roaming\ACEStream\updater\lib\win32pdh.pyd 2017-10-06 02:01 - 2017-10-06 02:01 - 033617920 _____ () C:\Program Files\WindowsApps\E046963F.LenovoCompanion_4.5.3.0_x86__k1h2ywk1493x8\Lenovo.Discovery.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2015-07-10 03:04 - 2015-07-10 03:02 - 000000824 _____ C:\WINDOWS\system32\Drivers\etc\hosts ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-3843431205-3915070046-1690682533-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Joseph\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\PhotosAppBackground\{1c154789-2a71-46f7-a1dd-7dc69f3a5303}.jpg DNS Servers: 8.8.8.8 - 4.2.2.4 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [UDP Query User{51B71EE3-F2AA-4F93-844E-CFE8E5F489AB}C:\users\joseph\appdata\roaming\acestream\engine\ace_engine.exe] => (Block) C:\users\joseph\appdata\roaming\acestream\engine\ace_engine.exe FirewallRules: [TCP Query User{2BFE9321-F08C-4B43-A797-398B7B98053E}C:\users\joseph\appdata\roaming\acestream\engine\ace_engine.exe] => (Block) C:\users\joseph\appdata\roaming\acestream\engine\ace_engine.exe FirewallRules: [{54AEAFA3-77CD-4078-8CA5-803EF757D605}] => (Allow) C:\Users\Joseph\AppData\Roaming\ACEStream\engine\ace_engine.exe FirewallRules: [{D63BD3B0-71E8-4C2C-8444-A874F5D9DDAA}] => (Allow) C:\Users\Joseph\AppData\Roaming\ACEStream\engine\ace_engine.exe FirewallRules: [{383F988F-382C-4127-9A69-73E811C0AABE}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe FirewallRules: [{BF027DDE-5B94-49E2-BAE2-4ED15457EC80}] => (Allow) C:\Program Files\AVAST Software\SZBrowser\4.58.2552.909\SZBrowser.exe FirewallRules: [{1DBD15EA-934A-4F58-B111-2B2E1E6B3DB3}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{C4B11D0A-FDDD-41C3-8F2D-14FE573779A3}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{A23D8D6D-8921-402A-932A-00E47A080DAA}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe FirewallRules: [{9BEE680A-13E6-4B4E-8F85-4E0C54B18117}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe FirewallRules: [{6A8D8C6F-CC75-4080-9FAB-B1A9B860A36C}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe FirewallRules: [{3D2402B8-6EB7-4443-895A-882AEA57FF20}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe FirewallRules: [{1F50F79E-A3CD-48AB-990C-91605D6AFC6C}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe FirewallRules: [{FFFAD3D2-5F98-4F16-90B9-603B0E644A51}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SunlessSea\Sunless Sea.exe FirewallRules: [{CDED63F5-F739-44F4-A191-A1B01FD8A4D5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SunlessSea\Sunless Sea.exe FirewallRules: [{B8E17267-4E44-4DD9-9E76-8A8AE61B003F}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{4404DF50-816D-4669-A2C3-61FA906066A4}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{14C23F72-D304-471A-873D-30349A2B1858}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{6C1A3619-C461-4442-A6EB-F75AD9C10305}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{1B89AF26-8088-4FA5-AC06-0AD24E6FD54A}] => (Allow) C:\Program Files (x86)\Lenovo\SHAREit\SHAREit.exe FirewallRules: [{CA00B2BA-A4CD-4B30-8D97-E94F58871AA6}] => (Allow) C:\Program Files (x86)\Lenovo\SHAREit\SHAREit.exe FirewallRules: [TCP Query User{CDD43EDF-18F0-410D-89EC-1BC7BCA91127}C:\users\joseph\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\joseph\appdata\roaming\spotify\spotify.exe FirewallRules: [UDP Query User{BAB19359-262B-4DB3-BADA-CC8019E9F1FC}C:\users\joseph\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\joseph\appdata\roaming\spotify\spotify.exe FirewallRules: [{79F93D76-C1D6-49CF-B57B-D418BBF870A2}] => (Allow) LPort=1688 FirewallRules: [{589F6060-9A63-4872-BCF7-A7D26883423F}] => (Allow) C:\Program Files\Vuze\Azureus.exe FirewallRules: [{4C1C08B1-802B-4226-927F-89748E07F540}] => (Allow) C:\Program Files\Vuze\Azureus.exe FirewallRules: [TCP Query User{514CACDB-568E-480D-AD56-BF5A3AA7D65B}C:\program files (x86)\videolan\vlc\vlc.exe] => (Allow) C:\program files (x86)\videolan\vlc\vlc.exe FirewallRules: [UDP Query User{B388513F-FA0D-4A11-A293-504BF63B1BB9}C:\program files (x86)\videolan\vlc\vlc.exe] => (Allow) C:\program files (x86)\videolan\vlc\vlc.exe FirewallRules: [{D42A96DB-E868-478D-8DDF-262A2C7058C2}] => (Allow) C:\Users\Joseph\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{AB6444A2-DA10-46D9-AE42-B691869D34B9}] => (Allow) C:\Users\Joseph\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{BE352895-8958-4D27-8978-E10F2123EA57}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [TCP Query User{60EF31DA-F42C-4EE7-B4DF-237EE24E5A95}C:\users\joseph\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\joseph\appdata\roaming\spotify\spotify.exe FirewallRules: [UDP Query User{4366FD68-F1E2-40A3-841F-13FF12C8C4D9}C:\users\joseph\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\joseph\appdata\roaming\spotify\spotify.exe FirewallRules: [{17A1844B-654A-41F3-82CF-24A044BBEB91}] => (Allow) C:\Program Files\AVAST Software\SZBrowser\4.58.2552.909_0\SZBrowser.exe FirewallRules: [{DA71AF4C-42F0-45C5-8C33-C5A3D3C583A5}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Restore Points ========================= 17-10-2017 19:33:35 Windows Update 24-10-2017 21:34:34 Scheduled Checkpoint 02-11-2017 15:17:35 Scheduled Checkpoint ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (11/06/2017 11:02:55 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: VENOMOUS-PC) Description: Activation of app Microsoft.Windows.Photos_8wekyb3d8bbwe!App failed with error: -2144927142 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (11/05/2017 03:50:25 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: VENOMOUS-PC) Description: Package 4DF9E0F8.Netflix_6.40.199.0_x64__mcm4njqhnhss8+Netflix.App was terminated because it took too long to suspend. Error: (11/04/2017 02:55:20 AM) (Source: SideBySide) (EventID: 78) (User: ) Description: Activation context generation failed for "c:\program files (x86)\adobe\adobe creative cloud\utils\Creative Cloud Uninstaller.exe".Error in manifest or policy file "" on line . A component version required by the application conflicts with another component version already active. Conflicting components are:. Component 1: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.483_none_6dad63fefc436da8.manifest. Component 2: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.483_none_26002d27e7c744a2.manifest. Error: (11/04/2017 02:54:36 AM) (Source: SideBySide) (EventID: 9) (User: ) Description: Activation context generation failed for "C:\Program Files\WinZip\adxloader.dll.Manifest".Error in manifest or policy file "C:\Program Files\WinZip\adxloader.dll.Manifest" on line 2. The manifest file root element must be assembly. Error: (11/04/2017 02:53:34 AM) (Source: SideBySide) (EventID: 35) (User: ) Description: Activation context generation failed for "C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest".Error in manifest or policy file "C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0". Definition is UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0". Please use sxstrace.exe for detailed diagnosis. Error: (11/01/2017 07:00:18 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Activation context generation failed for "c:\program files (x86)\adobe\adobe creative cloud\utils\Creative Cloud Uninstaller.exe".Error in manifest or policy file "" on line . A component version required by the application conflicts with another component version already active. Conflicting components are:. Component 1: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.483_none_6dad63fefc436da8.manifest. Component 2: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.483_none_26002d27e7c744a2.manifest. Error: (11/01/2017 06:58:37 PM) (Source: SideBySide) (EventID: 9) (User: ) Description: Activation context generation failed for "C:\Program Files\WinZip\adxloader.dll.Manifest".Error in manifest or policy file "C:\Program Files\WinZip\adxloader.dll.Manifest" on line 2. The manifest file root element must be assembly. Error: (11/01/2017 06:39:15 PM) (Source: SideBySide) (EventID: 35) (User: ) Description: Activation context generation failed for "C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest".Error in manifest or policy file "C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0". Definition is UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0". Please use sxstrace.exe for detailed diagnosis. Error: (10/30/2017 06:31:12 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: VENOMOUS-PC) Description: Activation of app Microsoft.LockApp_cw5n1h2txyewy!WindowsDefaultLockScreen failed with error: -2144927142 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (10/29/2017 07:11:01 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Activation context generation failed for "c:\program files (x86)\adobe\adobe creative cloud\utils\Creative Cloud Uninstaller.exe".Error in manifest or policy file "" on line . A component version required by the application conflicts with another component version already active. Conflicting components are:. Component 1: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.483_none_6dad63fefc436da8.manifest. Component 2: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.483_none_26002d27e7c744a2.manifest. System errors: ============= Error: (11/06/2017 09:29:46 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (11/05/2017 11:42:18 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (11/05/2017 08:48:46 PM) (Source: bowser) (EventID: 8003) (User: ) Description: The master browser has received a server announcement from the computer IMAC-2C1A60 that believes that it is the master browser for the domain on transport NetBT_Tcpip_{7178B53C-D272-4DE1-9C37-1ADDBFE03591}. The master browser is stopping or an election is being forced. Error: (11/05/2017 03:48:51 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (11/03/2017 09:11:45 PM) (Source: bowser) (EventID: 8003) (User: ) Description: The master browser has received a server announcement from the computer IMAC-2C1A60 that believes that it is the master browser for the domain on transport NetBT_Tcpip_{7178B53C-D272-4DE1-9C37-1ADDBFE03591}. The master browser is stopping or an election is being forced. Error: (11/03/2017 09:01:37 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (11/03/2017 08:20:33 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (11/03/2017 06:49:14 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (11/02/2017 06:04:53 PM) (Source: bowser) (EventID: 8003) (User: ) Description: The master browser has received a server announcement from the computer IMAC-2C1A60 that believes that it is the master browser for the domain on transport NetBT_Tcpip_{7178B53C-D272-4DE1-9C37-1ADDBFE03591}. The master browser is stopping or an election is being forced. Error: (11/02/2017 09:36:01 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. CodeIntegrity: =================================== Date: 2017-09-03 01:56:11.853 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\Windows.UI.dll because the set of per-page image hashes could not be found on the system. Date: 2017-09-03 01:53:04.546 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\Windows.UI.dll because the set of per-page image hashes could not be found on the system. Date: 2017-09-03 01:48:10.639 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\Windows.UI.dll because the set of per-page image hashes could not be found on the system. Date: 2017-09-03 01:40:08.603 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\Windows.UI.dll because the set of per-page image hashes could not be found on the system. Date: 2017-09-03 00:40:16.087 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\Windows.UI.dll because the set of per-page image hashes could not be found on the system. Date: 2017-09-03 00:07:40.101 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\Windows.UI.dll because the set of per-page image hashes could not be found on the system. Date: 2017-09-03 00:07:34.281 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\Windows.UI.dll because the set of per-page image hashes could not be found on the system. Date: 2017-09-02 22:57:34.659 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\Windows.UI.dll because the set of per-page image hashes could not be found on the system. Date: 2017-09-02 22:57:25.078 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\Windows.UI.dll because the set of per-page image hashes could not be found on the system. Date: 2017-09-02 22:44:57.883 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\Windows.UI.dll because the set of per-page image hashes could not be found on the system. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i3-4030U CPU @ 1.90GHz Percentage of memory in use: 86% Total physical RAM: 4017.09 MB Available physical RAM: 551.13 MB Total Virtual: 13745.09 MB Available Virtual: 3098.24 MB ==================== Drives ================================ Drive c: (Windows) (Fixed) (Total:886.37 GB) (Free:196.1 GB) NTFS ==>[system with boot components (obtained from drive)] Drive d: (LENOVO) (Fixed) (Total:25 GB) (Free:22.94 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 931.5 GB) (Disk ID: CDFC8C5C) Partition: GPT. ==================== End of Addition.txt ============================