Additional scan result of Farbar Recovery Scan Tool (x64) Version: 14.03.2018 Ran by [removed] (19-03-2018 10:25:50) Running from C:\Users\[removed]\Downloads Windows 10 Home Version 1709 16299.248 (X64) (2018-02-04 01:18:44) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-1580677906-789884366-343230679-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-1580677906-789884366-343230679-503 - Limited - Disabled) Guest (S-1-5-21-1580677906-789884366-343230679-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-1580677906-789884366-343230679-1002 - Limited - Enabled) Terri (S-1-5-21-1580677906-789884366-343230679-1001 - Administrator - Enabled) => C:\Users\Terri WDAGUtilityAccount (S-1-5-21-1580677906-789884366-343230679-504 - Limited - Disabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Avast Antivirus (Disabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF} AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Avast Antivirus (Disabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 18.009.20050 - Adobe Systems Incorporated) Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Avast Free Antivirus (HKLM-x32\...\Avast Antivirus) (Version: 18.2.2328 - AVAST Software) DivX Setup (HKLM\...\DivX Setup) (Version: 3.0.0.141 - DivX, LLC) Fitbit Connect (HKLM-x32\...\{3EFA7006-AFA8-4A75-8FFA-5A43FC797A90}) (Version: 2.0.1.6782 - Fitbit Inc.) FlipShare (HKLM-x32\...\{97C658D2-61FB-027F-0D76-E9CDC84AFEC7}) (Version: 5.12.3.0 - Flip Video) Free VOB To MP4 Converter (HKLM-x32\...\{91F8F9B9-D73E-4F5B-B386-7D203DDE4094}) (Version: 1.0.0 - Convert Audio Free) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 64.0.3282.186 - Google Inc.) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.7 - Google Inc.) Hidden Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden H&R Block Deluxe + Efile 2015 (HKLM-x32\...\{D64EF8D5-1C1C-4B30-AB97-73F2C6024AD3}) (Version: 15.04.8101 - HRB Technology, LLC.) KB4023057 (HKLM\...\{ED06689A-33B7-4D35-8F76-36A82CD03406}) (Version: 2.3.0.0 - Microsoft Corporation) Microsoft Office 2000 Disc 2 (HKLM-x32\...\{00040409-78E1-11D2-B60F-006097C998E7}) (Version: 9.00.2720 - Microsoft Corporation) Microsoft Office 2000 Small Business (HKLM-x32\...\{00030409-78E1-11D2-B60F-006097C998E7}) (Version: 9.00.2720 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-1580677906-789884366-343230679-1001\...\OneDriveSetup.exe) (Version: 17.3.7294.0108 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 31.1.2 - Mozilla) Mozilla Thunderbird 31.1.2 (x86 en-US) (HKLM-x32\...\Mozilla Thunderbird 31.1.2 (x86 en-US)) (Version: 31.1.2 - Mozilla) Nmap 5.51 (HKLM-x32\...\Nmap) (Version: - ) TweakBit Driver Updater (HKLM-x32\...\{62D64B30-6E10-4C49-95FE-EDD8F8165DED}_is1) (Version: 1.8.2.19 - Auslogics Labs Pty Ltd) TweakBit PCSpeedUp (HKLM-x32\...\{2FFDD819-5ACF-49D5-9F18-980B42E5DA66}_is1) (Version: 1.8.2.19 - Auslogics Labs Pty Ltd) UpdateAssistant (HKLM-x32\...\{B7AFAF92-D1C8-49A0-B34A-B5DAF9C9D5C6}) (Version: 1.9.0.0 - Microsoft Corporation) Hidden VC80CRTRedist - 8.0.50727.6195 (HKLM-x32\...\{933B4015-4618-4716-A828-5289FC03165F}) (Version: 1.2.0 - DivX, Inc) Hidden VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.4 - VideoLAN) Windows 10 Update Assistant (HKLM-x32\...\{D5C69738-B486-402E-85AC-2456D98A64E4}) (Version: 1.4.9200.22334 - Microsoft Corporation) WinPcap 4.1.2 (HKLM-x32\...\WinPcapInst) (Version: 4.1.0.2001 - CACE Technologies) WinZip 21.0 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C2410D}) (Version: 21.0.12288 - WinZip Computing, S.L. ) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-03-01] (AVAST Software) ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-03-01] (AVAST Software) ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-03-01] (AVAST Software) ContextMenuHandlers1: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\wzshls64.dll [2017-02-13] (WinZip Computing, S.L.) ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-03-01] (AVAST Software) ContextMenuHandlers4: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\wzshls64.dll [2017-02-13] (WinZip Computing, S.L.) ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\WINDOWS\system32\igfxpph.dll [2012-11-27] (Intel Corporation) ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-03-01] (AVAST Software) ContextMenuHandlers6: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\wzshls64.dll [2017-02-13] (WinZip Computing, S.L.) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {01BB7F56-DA0F-497B-B1FA-F3D6C824404D} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-09-27] (Adobe Systems Incorporated) Task: {08CCDD46-CF49-4EF3-913D-2BB7686910BB} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION Task: {0B9C406C-3954-4471-9440-1507B3169831} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.18022-0\MpCmdRun.exe [2018-03-19] (Microsoft Corporation) Task: {0BC9BB65-94FF-4F2F-B2ED-2FEBC5977F2E} - System32\Tasks\TweakBit\PCSpeedUp\Start PCSpeedUp оn logon => C:\Program Files (x86)\TweakBit\PCSpeedUp\PCSpeedUp.exe [2018-01-11] (TweakBit) <==== ATTENTION Task: {20F87D1F-9D72-4726-948B-1FA0576FC2A6} - System32\Tasks\iolo DelOnReboot => cmd.exe /c del /f C:\ProgramData\iolo\ops\smrr.dll Task: {248143D8-7A4E-40B7-AD1F-574BC97B50C5} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime -> No File <==== ATTENTION Task: {25A07FFE-7A1B-486F-96F2-24046DBA4049} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2018-03-01] (AVAST Software) Task: {27EC1ACB-7AF9-4546-A9CA-08AA61BA7860} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.18022-0\MpCmdRun.exe [2018-03-19] (Microsoft Corporation) Task: {2AD822BA-8A77-4176-B125-62FBCC0CF9EE} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION Task: {2E73D1A2-E7F8-48E8-9549-F87F63A76A2D} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\WINDOWS\System32\AutoWorkplace.exe Task: {36E57232-1B61-4D11-803A-25A45464CAD2} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION Task: {440CE6DF-561A-401F-991F-476367205404} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION Task: {470F8F24-E649-4AB8-929A-680048ECEE1D} - System32\Tasks\Avast Software\Overseer => C:\Program Files\AVAST Software\Avast\setup\overseer.exe [2018-03-01] (AVAST Software) Task: {47240613-99BF-4652-8890-929296A4E99F} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION Task: {5CF4F3A2-CF53-4D13-8DDD-448F9CBD5A43} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.) Task: {750C383A-4537-4235-BC10-9FBC2A3078E4} - System32\Tasks\TweakBit\Driver Updater\Time for deal => C:\Program Files (x86)\TweakBit\Driver Updater\DriverUpdater.exe [2018-01-11] (TweakBit) <==== ATTENTION Task: {7936F24E-DCF0-41A1-A2DF-791283E3B1FE} - System32\Tasks\DivXUpdate => C:\Program Files (x86)\Common Files\DivX Shared\DivX Update\DivXUpdate.exe [2016-12-15] (DivX, LLC) Task: {7C7F6CB9-600A-4A27-833A-8D84A047AF7C} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.18022-0\MpCmdRun.exe [2018-03-19] (Microsoft Corporation) Task: {8D340956-A06E-46A1-AE5C-4F4ECF069894} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION Task: {9ED9F5DE-40A6-4330-8F4E-3C905AE37EDB} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.18022-0\MpCmdRun.exe [2018-03-19] (Microsoft Corporation) Task: {A191CEC6-88FE-4615-9A7F-086801D83407} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION Task: {A8E7AC82-1018-4527-B623-E060D2BDF1FE} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime -> No File <==== ATTENTION Task: {B01F042A-979C-420E-8563-DB1A17B6CB9A} - System32\Tasks\WinZipBackGroundToolsTask => C:\Program Files\WinZip\WzBGTools.exe [2017-02-13] (WinZip Computing, S.L.) Task: {BD9D7621-8E92-4682-A91F-C5B5A975C7D5} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION Task: {C0DC343E-7DBA-4AD9-8B02-C4FCEEEFA943} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION Task: {C1A85714-385B-4728-975C-7FC1E64089D6} - System32\Tasks\WinZip Update Notifier => C:\Program Files\WinZip\WZUpdateNotifier.exe [2017-02-13] (WinZip) Task: {DD725D96-1E65-4AD5-B045-8C9537133216} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.) Task: {EF1E6CC8-C3EB-4447-AB80-49099F951A5F} - System32\Tasks\TweakBit\Driver Updater\Start Driver Updater оn logon => C:\Program Files (x86)\TweakBit\Driver Updater\DriverUpdater.exe [2018-01-11] (TweakBit) <==== ATTENTION Task: {F01A1C9B-0604-4004-90BC-5172B6D9566F} - System32\Tasks\TweakBit\PCSpeedUp\Time for deal => C:\Program Files (x86)\TweakBit\PCSpeedUp\PCSpeedUp.exe [2018-01-11] (TweakBit) <==== ATTENTION Task: {F0753B4D-CC17-47E3-A034-76467D57CDF6} - System32\Tasks\TweakBit\Driver Updater\Start Driver Updater automatic scanning => C:\Program Files (x86)\TweakBit\Driver Updater\DriverUpdater.exe [2018-01-11] (TweakBit) <==== ATTENTION (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe ==================== Shortcuts & WMI ======================== (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== 2017-09-29 06:41 - 2017-09-29 06:41 - 000184432 _____ () C:\WINDOWS\SYSTEM32\inputhost.dll 2011-05-06 12:58 - 2011-05-06 12:58 - 001085440 _____ () C:\Program Files (x86)\Flip Video\FlipShareServer\FlipShareServer.exe 2011-05-06 13:07 - 2011-05-06 13:07 - 000460144 _____ () C:\Program Files (x86)\Flip Video\FlipShare\FlipShareService.exe 2018-03-03 16:55 - 2018-02-09 21:39 - 011044864 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2018-03-03 16:55 - 2018-02-09 21:36 - 001804288 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2012-11-27 00:54 - 2012-11-27 00:54 - 000094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2018-03-01 13:07 - 2018-03-01 13:07 - 000287960 _____ () c:\program files\avast software\avast\streamback.dll 2018-03-01 13:07 - 2018-03-01 13:07 - 000280280 _____ () C:\Program Files\AVAST Software\Avast\tasks_core.dll 2018-03-19 09:25 - 2018-03-19 09:25 - 005800080 _____ () c:\program files\avast software\avast\defs\18031902\algo.dll 2018-03-01 13:07 - 2018-03-01 13:07 - 000756952 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll 2018-03-01 13:06 - 2018-03-01 13:06 - 000172760 _____ () C:\Program Files\AVAST Software\Avast\hns_tools.dll 2018-03-01 13:06 - 2018-03-01 13:06 - 000964824 _____ () C:\Program Files\AVAST Software\Avast\shepherdsync.dll 2018-03-01 13:06 - 2018-03-01 13:06 - 000475352 _____ () C:\Program Files\AVAST Software\Avast\gui_cache.dll 2018-03-01 13:06 - 2018-03-01 13:06 - 000339672 _____ () C:\Program Files\AVAST Software\Avast\streamback_avast.dll 2010-10-26 00:06 - 2010-10-26 00:06 - 002248704 _____ () C:\Program Files (x86)\Flip Video\FlipShareServer\QtCore4.dll 2010-10-26 00:08 - 2010-10-26 00:08 - 000983040 _____ () C:\Program Files (x86)\Flip Video\FlipShareServer\QtNetwork4.dll 2010-10-26 00:23 - 2010-10-26 00:23 - 000204800 _____ () C:\Program Files (x86)\Flip Video\FlipShareServer\QtSql4.dll 2010-05-20 13:49 - 2010-05-20 13:49 - 000258048 _____ () C:\Program Files (x86)\Flip Video\FlipShareServer\boost_serialization-vc80-mt-1_43.dll 2010-05-17 09:47 - 2010-05-17 09:47 - 001199104 _____ () C:\Program Files (x86)\Flip Video\FlipShareServer\PocoFoundation.dll 2010-05-17 09:47 - 2010-05-17 09:47 - 000642048 _____ () C:\Program Files (x86)\Flip Video\FlipShareServer\PocoNet.dll 2010-05-17 09:47 - 2010-05-17 09:47 - 000175616 _____ () C:\Program Files (x86)\Flip Video\FlipShareServer\PocoNetSSL.dll 2010-05-17 09:47 - 2010-05-17 09:47 - 000291840 _____ () C:\Program Files (x86)\Flip Video\FlipShareServer\PocoUtil.dll 2010-05-17 09:47 - 2010-05-17 09:47 - 000511488 _____ () C:\Program Files (x86)\Flip Video\FlipShareServer\PocoXML.dll 2010-05-17 09:47 - 2010-05-17 09:47 - 000110592 _____ () C:\Program Files (x86)\Flip Video\FlipShareServer\PocoCrypto.dll 2010-10-26 00:06 - 2010-10-26 00:06 - 002248704 _____ () C:\Program Files (x86)\Flip Video\FlipShare\QtCore4.dll 2011-05-06 13:07 - 2011-05-06 13:07 - 004317184 _____ () C:\Program Files (x86)\Flip Video\FlipShare\Core.dll 2010-10-26 00:08 - 2010-10-26 00:08 - 000983040 _____ () C:\Program Files (x86)\Flip Video\FlipShare\QtNetwork4.dll 2010-10-26 00:23 - 2010-10-26 00:23 - 008351744 _____ () C:\Program Files (x86)\Flip Video\FlipShare\QtGui4.dll 2010-10-26 00:23 - 2010-10-26 00:23 - 000204800 _____ () C:\Program Files (x86)\Flip Video\FlipShare\QtSql4.dll 2010-10-26 00:06 - 2010-10-26 00:06 - 000364544 _____ () C:\Program Files (x86)\Flip Video\FlipShare\QtXml4.dll 2011-05-06 13:02 - 2011-05-06 13:02 - 000737280 _____ () C:\Program Files (x86)\Flip Video\FlipShare\qca2.dll 2010-05-20 13:49 - 2010-05-20 13:49 - 000258048 _____ () C:\Program Files (x86)\Flip Video\FlipShare\boost_serialization-vc80-mt-1_43.dll 2010-10-26 08:34 - 2010-10-26 08:34 - 011853824 _____ () C:\Program Files (x86)\Flip Video\FlipShare\QtWebKit4.dll 2010-05-17 09:47 - 2010-05-17 09:47 - 001199104 _____ () C:\Program Files (x86)\Flip Video\FlipShare\PocoFoundation.dll 2010-05-17 09:47 - 2010-05-17 09:47 - 000511488 _____ () C:\Program Files (x86)\Flip Video\FlipShare\PocoXML.dll 2010-05-17 09:47 - 2010-05-17 09:47 - 000642048 _____ () C:\Program Files (x86)\Flip Video\FlipShare\PocoNet.dll 2010-10-26 00:37 - 2010-10-26 00:37 - 000258048 _____ () C:\Program Files (x86)\Flip Video\FlipShare\phonon4.dll 2014-12-11 17:40 - 2014-12-11 17:40 - 040622592 ____R () C:\Program Files (x86)\Fitbit Connect\libcef.dll 2018-03-01 13:07 - 2018-03-01 13:07 - 067126928 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2018-03-01 13:06 - 2018-03-01 13:06 - 000275160 _____ () C:\Program Files\AVAST Software\Avast\gaming_mode_ui.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2013-08-22 06:25 - 2013-08-22 06:25 - 000000824 _____ C:\WINDOWS\system32\Drivers\etc\hosts ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-1580677906-789884366-343230679-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Terri\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper DNS Servers: 192.168.254.254 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == HKLM\...\StartupApproved\StartupFolder: => "Microsoft Office.lnk" HKLM\...\StartupApproved\StartupFolder: => "TechGenie.lnk" HKLM\...\StartupApproved\StartupFolder: => "WinZip Preloader.lnk" HKLM\...\StartupApproved\StartupFolder: => "Update Notifier.lnk" HKLM\...\StartupApproved\Run32: => "iYogi Support Dock" HKLM\...\StartupApproved\Run32: => "TechGenieRealTime" HKLM\...\StartupApproved\Run32: => "AntivirusUpdateApp" HKLM\...\StartupApproved\Run32: => "InboxAce EPM Support" HKLM\...\StartupApproved\Run32: => "DivXMediaServer" HKU\S-1-5-21-1580677906-789884366-343230679-1001\...\StartupApproved\Run: => "OneDrive" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{B4B402D0-7FC7-47B7-83FC-8EF498459C72}] => (Allow) LPort=24726 FirewallRules: [{72DBF12C-319B-49DB-95FA-0FFE7BFE9943}] => (Allow) LPort=24727 FirewallRules: [{833698AE-07FC-49F4-931D-934AD9E5E03A}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe FirewallRules: [{211BD158-9083-45C0-884A-F7C310D6886D}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Restore Points ========================= 01-03-2018 12:40:20 Windows Update 18-03-2018 17:57:12 Scheduled Checkpoint ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (03/19/2018 09:49:04 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program Au_.exe version 5.7.7.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel. Process ID: 1cc Start Time: 01d3bfa1b49d6487 Termination Time: 12 Application Path: C:\Users\Terri\AppData\Local\Temp\~nsu.tmp\Au_.exe Report Id: 90ce17ea-bcdb-49f7-8100-ea84ca04af6e Faulting package full name: Faulting package-relative application ID: Error: (03/19/2018 09:48:46 AM) (Source: Perflib) (EventID: 1008) (User: ) Description: The Open Procedure for service "BITS" in DLL "C:\Windows\System32\bitsperf.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code. Error: (03/19/2018 09:45:12 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program Au_.exe version 5.8.1.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel. Process ID: 25c4 Start Time: 01d3bfa16544c579 Termination Time: 17 Application Path: C:\Users\Terri\AppData\Local\Temp\~nsu.tmp\Au_.exe Report Id: 094bd9ea-7e47-4a57-b8b4-3ec590b4e6cb Faulting package full name: Faulting package-relative application ID: Error: (03/19/2018 09:43:10 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program Au_.exe version 5.8.1.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel. Process ID: 1d9c Start Time: 01d3bfa0ff723de9 Termination Time: 7 Application Path: C:\Users\Terri\AppData\Local\Temp\~nsu.tmp\Au_.exe Report Id: 3ca7cddc-2389-490c-994f-323e2786cd15 Faulting package full name: Faulting package-relative application ID: Error: (03/19/2018 09:42:06 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: TERRI-PC) Description: Package microsoft.windowscommunicationsapps_17.9029.22105.0_x64__8wekyb3d8bbwe+microsoft.windowslive.mail was terminated because it took too long to suspend. Error: (03/03/2018 04:31:09 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: TERRI-PC) Description: Package Microsoft.Windows.Photos_2018.18021.12420.0_x64__8wekyb3d8bbwe+App was terminated because it took too long to suspend. Error: (03/01/2018 01:38:28 PM) (Source: COM) (EventID: 10031) (User: ) Description: An unmarshaling policy check was performed when unmarshaling a custom marshaled object and the class {41FD88F7-F295-4D39-91AC-A85F3149A05B} was rejected Error: (03/01/2018 01:38:28 PM) (Source: COM) (EventID: 10031) (User: ) Description: An unmarshaling policy check was performed when unmarshaling a custom marshaled object and the class {41FD88F7-F295-4D39-91AC-A85F3149A05B} was rejected System errors: ============= Error: (03/19/2018 10:08:01 AM) (Source: DCOM) (EventID: 10016) (User: TERRI-PC) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the user Terri-PC\Terri SID (S-1-5-21-1580677906-789884366-343230679-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (03/19/2018 09:50:12 AM) (Source: DCOM) (EventID: 10010) (User: TERRI-PC) Description: The server windows.immersivecontrolpanel_10.0.1.1000_neutral_neutral_cw5n1h2txyewy!microsoft.windows.immersivecontrolpanel did not register with DCOM within the required timeout. Error: (03/19/2018 09:46:32 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY) Description: Installation Failure: Windows failed to install the following update with error 0x80070020: 2018-03 Cumulative Update for Windows 10 Version 1709 for x64-based Systems (KB4088776). Error: (03/19/2018 09:38:39 AM) (Source: DCOM) (EventID: 10016) (User: TERRI-PC) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the user Terri-PC\Terri SID (S-1-5-21-1580677906-789884366-343230679-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (03/19/2018 09:36:34 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52} and APPID {4839DDB7-58C2-48F5-8283-E1D1807D0D7D} to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (03/19/2018 09:36:34 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52} and APPID {4839DDB7-58C2-48F5-8283-E1D1807D0D7D} to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (03/19/2018 09:36:34 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52} and APPID {4839DDB7-58C2-48F5-8283-E1D1807D0D7D} to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (03/19/2018 09:36:34 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52} and APPID {4839DDB7-58C2-48F5-8283-E1D1807D0D7D} to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Windows Defender: =================================== Date: 2018-03-19 09:33:08.636 Description: Windows Defender Antivirus has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.205.391.0 Update Source: Microsoft Malware Protection Center Signature Type: AntiVirus Update Type: Full Current Engine Version: Previous Engine Version: 1.1.12002.0 Error code: 0x80072742 Error description: A socket operation encountered a dead network. Date: 2018-03-19 09:33:08.635 Description: Windows Defender Antivirus has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 0.0.0.0 Update Source: Microsoft Malware Protection Center Signature Type: Network Inspection System Update Type: Full Current Engine Version: Previous Engine Version: 0.0.0.0 Error code: 0x80072742 Error description: A socket operation encountered a dead network. Date: 2018-03-19 09:33:08.633 Description: Windows Defender Antivirus has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.205.391.0 Update Source: Microsoft Malware Protection Center Signature Type: AntiVirus Update Type: Full Current Engine Version: Previous Engine Version: 1.1.12002.0 Error code: 0x80072742 Error description: A socket operation encountered a dead network. Date: 2018-03-19 09:33:08.633 Description: Windows Defender Antivirus has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.205.391.0 Update Source: Microsoft Malware Protection Center Signature Type: AntiSpyware Update Type: Full Current Engine Version: Previous Engine Version: 1.1.12002.0 Error code: 0x80072742 Error description: A socket operation encountered a dead network. Date: 2018-03-19 09:33:08.632 Description: Windows Defender Antivirus has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.205.391.0 Update Source: Microsoft Malware Protection Center Signature Type: AntiVirus Update Type: Full Current Engine Version: Previous Engine Version: 1.1.12002.0 Error code: 0x80072742 Error description: A socket operation encountered a dead network. CodeIntegrity: =================================== Date: 2018-03-01 13:41:47.950 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows.old\WINDOWS\WinSxS\x86_microsoft-windows-utilman_31bf3856ad364e35_10.0.10586.0_none_3310acc4233710cd\Utilman.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2018-03-01 13:41:47.948 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows.old\WINDOWS\WinSxS\x86_microsoft-windows-utilman_31bf3856ad364e35_10.0.10586.0_none_3310acc4233710cd\Utilman.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2018-03-01 13:41:47.945 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows.old\WINDOWS\WinSxS\x86_microsoft-windows-utilman_31bf3856ad364e35_10.0.10586.0_none_3310acc4233710cd\Utilman.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2018-03-01 13:41:47.903 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows.old\WINDOWS\WinSxS\x86_microsoft-windows-utilman_31bf3856ad364e35_10.0.10586.0_none_3310acc4233710cd\Utilman.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i3 CPU 550 @ 3.20GHz Percentage of memory in use: 29% Total physical RAM: 5943.11 MB Available physical RAM: 4177.41 MB Total Virtual: 14857.11 MB Available Virtual: 13267.11 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:917.66 GB) (Free:721.12 GB) NTFS \\?\Volume{6fed172e-87c9-11e0-88ae-806e6f6e6963}\ (RECOVERY) (Fixed) (Total:13.81 GB) (Free:5.08 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 931.5 GB) (Disk ID: 1512C6F0) Partition 1: (Not Active) - (Size=39 MB) - (Type=DE) Partition 2: (Active) - (Size=13.8 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=917.7 GB) - (Type=07 NTFS) ==================== End of Addition.txt ============================