Additional scan result of Farbar Recovery Scan Tool (x64) Version: 17.03.2019 Ran by [removed] (13-04-2019 02:40:11) Running from C:\Users\[removed]\Downloads Windows 10 Pro Version 1809 17763.437 (X64) (2019-03-25 17:23:34) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-2499506162-2493231129-710038530-500 - Administrator - Enabled) c (S-1-5-21-2499506162-2493231129-710038530-1001 - Administrator - Enabled) => C:\Users\c DefaultAccount (S-1-5-21-2499506162-2493231129-710038530-503 - Limited - Disabled) Guest (S-1-5-21-2499506162-2493231129-710038530-501 - Limited - Disabled) WDAGUtilityAccount (S-1-5-21-2499506162-2493231129-710038530-504 - Limited - Disabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: McAfee VirusScan (Enabled - Up to date) {8BCDACFA-D264-3528-5EF8-E94FD0BC1FBC} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: McAfee VirusScan (Enabled - Up to date) {30AC4D1E-F45E-3AA6-6448-D23DAB3B5501} FW: McAfee Firewall (Enabled) {B3F62DDF-980B-3470-75A7-407A2E6F58C7} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) AIMP Classic (HKLM-x32\...\AIMPClassic) (Version: - ) Canon Easy-WebPrint EX (HKLM-x32\...\Easy-WebPrint EX) (Version: 1.7.0.0 - Canon Inc.) Canon IJ Scan Utility (HKLM-x32\...\Canon_IJ_Scan_Utility) (Version: - Canon Inc.) Canon MG2500 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG2500_series) (Version: 1.00 - Canon Inc.) Canon MG2500 series On-screen Manual (HKLM-x32\...\Canon MG2500 series On-screen Manual) (Version: 7.8.0 - Canon Inc.) Canon MG2500 series User Registration (HKLM-x32\...\Canon MG2500 series User Registration) (Version: - ‭Canon Inc.) Canon My Image Garden (HKLM-x32\...\Canon My Image Garden) (Version: 2.0.1 - Canon Inc.) Canon My Image Garden Design Files (HKLM-x32\...\Canon My Image Garden Design Files) (Version: 2.0.0 - Canon Inc.) Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version: 3.1.0 - Canon Inc.) Canon Quick Menu (HKLM-x32\...\CanonQuickMenu) (Version: 2.2.1 - Canon Inc.) CCleaner (HKLM\...\CCleaner) (Version: 5.55 - Piriform) Dell SupportAssist (HKLM\...\{E98E94E2-12D1-48E5-AC69-2C312F466136}) (Version: 3.1.0.142 - Dell Inc.) Dell Touchpad (HKLM\...\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version: 10.3201.101.211 - ALPS ELECTRIC CO., LTD.) Free Window Registry Repair (HKLM-x32\...\Free Window Registry Repair) (Version: - ) Glary Utilities 5.116 (HKLM-x32\...\Glary Utilities 5) (Version: 5.116.0.141 - Glarysoft Ltd) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 73.0.3683.103 - Google Inc.) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.34.7 - Google LLC) Hidden McAfee Multi Access (HKLM-x32\...\MSC) (Version: 16.0 R18 - McAfee, Inc.) McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.11.968.1 - McAfee, Inc.) McAfee WebAdvisor (HKLM-x32\...\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}) (Version: 4.1.0.29 - McAfee, Inc.) Microsoft Office 365 - en-us (HKLM\...\O365HomePremRetail - en-us) (Version: 16.0.11425.20204 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-2499506162-2493231129-710038530-1001\...\OneDriveSetup.exe) (Version: 19.033.0218.0011 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation) Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.11425.20204 - Microsoft Corporation) Hidden Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.11425.20204 - Microsoft Corporation) Hidden Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.11425.20204 - Microsoft Corporation) Hidden Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0409-0000-0000000FF1CE}) (Version: 16.0.11425.20204 - Microsoft Corporation) Hidden Security Process Explorer 1.6 (HKLM-x32\...\Security Process Explorer_is1) (Version: - GlarySoft.com) SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 6.0.1260 - SUPERAntiSpyware.com) uTorrent Web (HKU\S-1-5-21-2499506162-2493231129-710038530-1001\...\utweb) (Version: 0.21.0 - BitTorrent, Inc.) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-2499506162-2493231129-710038530-1001_Classes\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6} -> [OneDrive] => {a52bba46-e9e1-435f-b3d9-28daa648c0f6} CustomCLSID: HKU\S-1-5-21-2499506162-2493231129-710038530-1001_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\Windows\system32\igfxEM.exe (Intel Corporation - pGFX -> Intel Corporation) ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File ContextMenuHandlers1-x32: [AIMPClassic] -> {1F77B17B-F531-44DB-ACA4-76ABB5010A28} => C:\Program Files (x86)\AIMP Classic\System\aimp_shell.dll [2007-05-13] (Artem Izmaylov) [File not signed] ContextMenuHandlers1: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => C:\Program Files (x86)\Glary Utilities 5\x64\ContextHandler.dll [2019-03-10] (Glarysoft LTD -> Glarysoft Ltd) ContextMenuHandlers1: [McCtxMenuFrmWrk] -> {CCA9EFD3-29ED-430A-BA6D-E6BBFF0A60C2} => c:\program files\mcafee\msc\mcctxmenufrmwrk.dll [2019-01-07] (McAfee, Inc. -> McAfee, Inc.) ContextMenuHandlers2: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => C:\Program Files (x86)\Glary Utilities 5\x64\ContextHandler.dll [2019-03-10] (Glarysoft LTD -> Glarysoft Ltd) ContextMenuHandlers4-x32: [AIMPClassic] -> {1F77B17B-F531-44DB-ACA4-76ABB5010A28} => C:\Program Files (x86)\AIMP Classic\System\aimp_shell.dll [2007-05-13] (Artem Izmaylov) [File not signed] ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\Windows\system32\igfxDTCM.dll [2015-07-30] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation) ContextMenuHandlers6: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => C:\Program Files (x86)\Glary Utilities 5\x64\ContextHandler.dll [2019-03-10] (Glarysoft LTD -> Glarysoft Ltd) ContextMenuHandlers6: [McCtxMenuFrmWrk] -> {CCA9EFD3-29ED-430A-BA6D-E6BBFF0A60C2} => c:\program files\mcafee\msc\mcctxmenufrmwrk.dll [2019-01-07] (McAfee, Inc. -> McAfee, Inc.) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {0AAF2840-77AB-4833-B605-A844DE98EC91} - System32\Tasks\McAfee\McAfee Auto Maintenance Task Agent Task: {14E64E0A-F830-4A37-B591-6D3A22E1173A} - System32\Tasks\Dell SupportAssistAgent AutoUpdate => C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistInstaller.exe (Dell Inc. -> Dell Inc.) Task: {1C273534-0AA8-4001-950F-3C6A6619B135} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe (Google Inc -> Google Inc.) "C:\Windows\System32\Tasks\McAfee\McAfee Idle Detection Task" was unlocked. <==== ATTENTION Task: {246BD539-38CE-48D5-9942-FBE7E219B28E} - System32\Tasks\McAfee\McAfee Idle Detection Task Task: {2DE1682B-20E8-4B34-8A51-F651843FBF65} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe (Piriform Software Ltd -> Piriform Software Ltd) Task: {3072EBBB-4B7A-4FB8-8790-950473F0CBDA} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe (Piriform Software Ltd -> Piriform Software Ltd) Task: {326FAB20-3306-417B-A275-B69F89126CF3} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe (Microsoft Corporation -> Microsoft Corporation) Task: {4157094C-073C-4299-8E10-406915057A74} - System32\Tasks\GlaryInitialize 5 => C:\Program Files (x86)\Glary Utilities 5\Initialize.exe (Glarysoft LTD -> Glarysoft Ltd) Task: {4B91A1A8-C249-48D5-8054-DB282F0BA1DE} - System32\Tasks\McAfee Remediation (Prepare) => C:\Program Files\Common Files\AV\McAfee VirusScan\upgrade.exe (McAfee, Inc. -> McAfee, Inc.) Task: {4BD58A70-59D3-43A8-8E4B-AECEB2A638B1} - System32\Tasks\SUPERAntiSpyware Scheduled Task ffc6208a-941b-495b-9ccf-196e00f3510b => C:\Program Files\SUPERAntiSpyware\SASTask.exe (SUPERAntiSpyware.com -> SUPERAdBlocker.com) Task: {4FCA8CE0-417A-48BD-B1AB-43191BAF6D06} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\sdxhelper.exe (Microsoft Corporation -> Microsoft Corporation) Task: {6E3CBC71-36BE-4E27-911A-1C44A8A8AA94} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe (AVAST Software s.r.o. -> AVAST Software) Task: {82DC83EB-D1CE-4E13-853F-E85AD5C5BBB6} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe (Google Inc -> Google Inc.) Task: {845AC705-2FF1-40D3-BB59-EE976C68F3A5} - System32\Tasks\McAfee\DAD.Execute.Updates => C:\Program Files\Common Files\McAfee\DynamicAppDownloader\1.1.207\DADUpdater.exe (McAfee, Inc. -> McAfee, Inc.) Task: {845C20FB-FA1A-4CDD-9CEE-81DA4A47F9FF} - System32\Tasks\SUPERAntiSpyware Scheduled Task 9eb51e46-2e25-4e24-9e30-ee1864fcfd8a => C:\Program Files\SUPERAntiSpyware\SASTask.exe (SUPERAntiSpyware.com -> SUPERAdBlocker.com) Task: {8DF4E99A-3F62-4B54-8B30-04A8D77AE9D1} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\sdxhelper.exe (Microsoft Corporation -> Microsoft Corporation) Task: {9039FB51-A532-43D9-AFAF-FD958D34F2F0} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe (Microsoft Corporation -> Microsoft Corporation) Task: {95A5C2E8-43BD-46A8-81BA-B8FA28A748B3} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe (Microsoft Corporation -> Microsoft Corporation) Task: {BA06D0A9-EE94-4F92-A412-B7ADA5524092} - System32\Tasks\Event Viewer Tasks\Security_Microsoft-Windows-Security-Auditing_4799 => C:\Program Files (x86)\Glarysoft\Malware Hunter\MalwareHunter.exe Task: {CF61BBEA-B081-4694-A7D4-589C4116BB28} - System32\Tasks\SUPERAntiSpyware Scheduled Task 156fb62b-b81e-4684-95e9-a7fc5d7caaba => C:\Program Files\SUPERAntiSpyware\SASTask.exe (SUPERAntiSpyware.com -> SUPERAdBlocker.com) Task: {DED2E93F-C10A-477E-8D61-EF83CB3A56BE} - System32\Tasks\McAfeeLogon => C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe (McAfee, Inc. -> McAfee, Inc.) Task: {F38A615A-7A29-4091-BF8C-01B881D02F38} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe (Microsoft Corporation -> Microsoft Corporation) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task 156fb62b-b81e-4684-95e9-a7fc5d7caaba.job => C:\Program Files\SUPERAntiSpyware\SASTask.exe C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE Task: C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task 9eb51e46-2e25-4e24-9e30-ee1864fcfd8a.job => C:\Program Files\SUPERAntiSpyware\SASTask.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe Task: C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task ffc6208a-941b-495b-9ccf-196e00f3510b.job => C:\Program Files\SUPERAntiSpyware\SASTask.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe ==================== Shortcuts & WMI ======================== (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== 2019-01-15 13:56 - 2019-01-15 13:56 - 005413080 _____ (Jenkins Win Client Build SPC -> BitTorrent Inc.) [File not signed] C:\Users\c\AppData\Roaming\uTorrent Web\utweb.exe 2019-01-15 13:56 - 2019-01-15 13:56 - 000902656 _____ () [File not signed] C:\Users\c\AppData\Roaming\uTorrent Web\avformat-58.dll 2019-01-15 13:56 - 2019-01-15 13:56 - 001277952 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Users\c\AppData\Roaming\uTorrent Web\LIBEAY32.dll 2019-01-15 13:56 - 2019-01-15 13:56 - 000452608 _____ () [File not signed] C:\Users\c\AppData\Roaming\uTorrent Web\avutil-56.dll 2019-01-15 13:56 - 2019-01-15 13:56 - 000279040 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Users\c\AppData\Roaming\uTorrent Web\SSLEAY32.dll 2019-01-15 13:56 - 2019-01-15 13:56 - 001415168 _____ () [File not signed] C:\Users\c\AppData\Roaming\uTorrent Web\avcodec-58.dll 2019-01-15 13:56 - 2019-01-15 13:56 - 000151552 _____ () [File not signed] C:\Users\c\AppData\Roaming\uTorrent Web\swresample-3.dll 2019-04-01 02:49 - 2013-04-26 18:31 - 000521216 _____ (CANON INC.) [File not signed] C:\Program Files (x86)\Canon\Quick Menu\CNQMMWRP.dll 2019-04-01 02:49 - 2013-04-26 18:28 - 000561152 _____ (CANON INC. ) [File not signed] C:\Program Files (x86)\Canon\Quick Menu\CCL.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ModuleCoreService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcapexe => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfemms => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeplk => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeplk.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ModuleCoreService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver" ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2018-09-15 00:31 - 2019-04-06 21:26 - 000000856 _____ C:\Windows\system32\drivers\etc\hosts ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-2499506162-2493231129-710038530-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\c\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\img0.jpg DNS Servers: 192.168.1.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: ) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == If an entry is included in the fixlist, it will be removed. ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{2CD3C234-FB77-45E1-8AF9-7C69FCB7C394}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{B072AED0-EAF9-45C5-9F2C-5B259C5E6208}] => (Allow) C:\Program Files (x86)\Common Files\Mcafee\MMSSHost\MMSSHost.exe (McAfee, Inc. -> McAfee, Inc.) FirewallRules: [{CC4FCDB6-A9BB-4856-9984-DEF0882A1B8D}] => (Allow) C:\Program Files\Common Files\McAfee\MMSSHost\MMSSHost.exe (McAfee, Inc. -> McAfee, Inc.) FirewallRules: [{86472902-3FE2-4E4E-B105-F60DB31D59C3}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe (McAfee, Inc. -> McAfee, Inc.) FirewallRules: [{2345F94C-BDE6-4940-BEAE-A4C03655E03A}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google Inc.) FirewallRules: [{9344054A-FD7C-447B-BE1A-915AE21631EA}] => (Allow) C:\Users\c\AppData\Roaming\uTorrent Web\utweb.exe (Jenkins Win Client Build SPC -> BitTorrent Inc.) [File not signed] FirewallRules: [{FCE9EEB5-12C4-4D83-8E27-4444640E283E}] => (Allow) C:\Users\c\AppData\Roaming\uTorrent Web\utweb.exe (Jenkins Win Client Build SPC -> BitTorrent Inc.) [File not signed] ==================== Restore Points ========================= 01-04-2019 06:29:09 Windows Modules Installer 10-04-2019 10:01:50 Windows Update ==================== Faulty Device Manager Devices ============= Name: Root Print Queue Description: Local Print Queue Class Guid: {1ed2bbf9-11f0-4084-b21f-ad83a8e6dcdc} Manufacturer: Microsoft Service: Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (04/11/2019 05:37:58 PM) (Source: ESENT) (EventID: 455) (User: ) Description: DllHost (15036,R,98) WebCacheLocal: Error -1811 (0xfffff8ed) occurred while opening logfile C:\Users\c\AppData\Local\Microsoft\Windows\WebCache\V01.log. Error: (04/11/2019 05:34:45 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: SUPERANTISPYWARE.EXE, version: 8.0.0.1038, time stamp: 0x5cabe30d Faulting module name: SUPERANTISPYWARE.EXE, version: 8.0.0.1038, time stamp: 0x5cabe30d Exception code: 0xc0000005 Fault offset: 0x00000000002485d9 Faulting process id: 0x265c Faulting application start time: 0x01d4f062e55cc016 Faulting application path: C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE Faulting module path: C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE Report Id: a467e227-1f70-4574-9c5a-ca107127b486 Faulting package full name: Faulting package-relative application ID: Error: (04/10/2019 08:03:27 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: SUPERANTISPYWARE.EXE, version: 8.0.0.1038, time stamp: 0x5cabe30d Faulting module name: SUPERANTISPYWARE.EXE, version: 8.0.0.1038, time stamp: 0x5cabe30d Exception code: 0xc0000005 Fault offset: 0x00000000002485d9 Faulting process id: 0x68c Faulting application start time: 0x01d4f0131b7b466c Faulting application path: C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE Faulting module path: C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE Report Id: feeef06e-7a1c-48fc-8945-a161968d6fef Faulting package full name: Faulting package-relative application ID: Error: (04/10/2019 06:58:49 PM) (Source: ESENT) (EventID: 455) (User: ) Description: taskhostw (5856,R,98) WebCacheLocal: Error -1032 (0xfffffbf8) occurred while opening logfile C:\Users\c\AppData\Local\Microsoft\Windows\WebCache\V01.log. Error: (04/10/2019 06:58:49 PM) (Source: ESENT) (EventID: 490) (User: ) Description: taskhostw (5856,R,98) WebCacheLocal: An attempt to open the file "C:\Users\c\AppData\Local\Microsoft\Windows\WebCache\V01.log" for read / write access failed with system error 32 (0x00000020): "The process cannot access the file because it is being used by another process. ". The open file operation will fail with error -1032 (0xfffffbf8). Error: (04/10/2019 09:41:02 AM) (Source: ESENT) (EventID: 455) (User: ) Description: DllHost (2920,R,98) WebCacheLocal: Error -1032 (0xfffffbf8) occurred while opening logfile C:\Users\c\AppData\Local\Microsoft\Windows\WebCache\V01.log. Error: (04/10/2019 09:41:02 AM) (Source: ESENT) (EventID: 490) (User: ) Description: DllHost (2920,R,98) WebCacheLocal: An attempt to open the file "C:\Users\c\AppData\Local\Microsoft\Windows\WebCache\V01.log" for read / write access failed with system error 32 (0x00000020): "The process cannot access the file because it is being used by another process. ". The open file operation will fail with error -1032 (0xfffffbf8). Error: (04/09/2019 11:35:03 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program LockApp.exe version 10.0.17763.1 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel. Process ID: ae0 Start Time: 01d4ef02e232a50c Termination Time: 4294967295 Application Path: C:\Windows\SystemApps\Microsoft.LockApp_cw5n1h2txyewy\LockApp.exe Report Id: 5f30c771-94ed-49d9-8146-6cc525b77c32 Faulting package full name: Microsoft.LockApp_10.0.17763.1_neutral__cw5n1h2txyewy Faulting package-relative application ID: WindowsDefaultLockScreen Hang type: Quiesce System errors: ============= Error: (04/12/2019 11:41:30 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-5EPIC4R) Description: The server {209500FC-6B45-4693-8871-6296C4843751} did not register with DCOM within the required timeout. Error: (04/12/2019 10:02:01 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-5EPIC4R) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54} and APPID {15C20B67-12E7-4BB6-92BB-7AFF07997402} to the user DESKTOP-5EPIC4R\c SID (S-1-5-21-2499506162-2493231129-710038530-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (04/12/2019 10:02:01 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-5EPIC4R) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54} and APPID {15C20B67-12E7-4BB6-92BB-7AFF07997402} to the user DESKTOP-5EPIC4R\c SID (S-1-5-21-2499506162-2493231129-710038530-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (04/12/2019 10:02:01 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-5EPIC4R) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54} and APPID {15C20B67-12E7-4BB6-92BB-7AFF07997402} to the user DESKTOP-5EPIC4R\c SID (S-1-5-21-2499506162-2493231129-710038530-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (04/12/2019 10:02:01 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-5EPIC4R) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54} and APPID {15C20B67-12E7-4BB6-92BB-7AFF07997402} to the user DESKTOP-5EPIC4R\c SID (S-1-5-21-2499506162-2493231129-710038530-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (04/12/2019 10:02:01 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-5EPIC4R) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54} and APPID {15C20B67-12E7-4BB6-92BB-7AFF07997402} to the user DESKTOP-5EPIC4R\c SID (S-1-5-21-2499506162-2493231129-710038530-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (04/12/2019 10:02:01 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-5EPIC4R) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54} and APPID {15C20B67-12E7-4BB6-92BB-7AFF07997402} to the user DESKTOP-5EPIC4R\c SID (S-1-5-21-2499506162-2493231129-710038530-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (04/12/2019 10:02:01 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-5EPIC4R) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54} and APPID {15C20B67-12E7-4BB6-92BB-7AFF07997402} to the user DESKTOP-5EPIC4R\c SID (S-1-5-21-2499506162-2493231129-710038530-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Windows Defender: =================================== Date: 2019-04-05 20:05:48.139 Description: Windows Defender Antivirus scan has been stopped before completion. Scan ID: {541B9CF7-ABE6-4DDD-8BCE-8CCC66D09DC8} Scan Type: Antimalware Scan Parameters: Quick Scan Date: 2019-04-03 21:51:21.874 Description: Windows Defender Antivirus scan has been stopped before completion. Scan ID: {24AE8AB3-A6D9-4382-A372-7ADE2AF37365} Scan Type: Antimalware Scan Parameters: Quick Scan Date: 2019-04-01 11:26:48.886 Description: Windows Defender Antivirus has detected malware or other potentially unwanted software. For more information please see the following: https://go.microsoft.com/fwlink/?linkid=37020&name=Program:Win32/Unwaders.C!ml&threatid=242874&enterprise=0 Name: Program:Win32/Unwaders.C!ml ID: 242874 Severity: Severe Category: Potentially Unwanted Software Path: file:_C:\Users\c\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\TempState\Downloads\Microsoft Office 2017 Cracked – Activator_2280238021 (1).exe Detection Origin: Local machine Detection Type: FastPath Detection Source: Real-Time Protection Process Name: C:\Windows\System32\svchost.exe Signature Version: AV: 1.291.889.0, AS: 1.291.889.0, NIS: 1.291.889.0 Engine Version: AM: 1.1.15800.1, NIS: 1.1.15800.1 Date: 2019-04-01 11:26:47.295 Description: Windows Defender Antivirus has detected malware or other potentially unwanted software. For more information please see the following: https://go.microsoft.com/fwlink/?linkid=37020&name=Program:Win32/Unwaders.C!ml&threatid=242874&enterprise=0 Name: Program:Win32/Unwaders.C!ml ID: 242874 Severity: Severe Category: Potentially Unwanted Software Path: amsiuac:_pid:00002F0C; file:_C:\Users\c\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\TempState\Downloads\Microsoft Office 2017 Cracked – Activator_2280238021 (1).exe; file:_C:\Users\c\AppData\Local\Packages\MICROS~1.MIC\TEMPST~1\DOWNLO~1\MICROS~1.EXE; process:_pid:12044,ProcessStart:131986166877663212 Detection Origin: Local machine Detection Type: Concrete Detection Source: AMSI UAC provider Process Name: C:\Users\c\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\TempState\Downloads\Microsoft Office 2017 Cracked – Activator_2280238021 (1).exe Signature Version: AV: 1.291.889.0, AS: 1.291.889.0, NIS: 1.291.889.0 Engine Version: AM: 1.1.15800.1, NIS: 1.1.15800.1 Date: 2019-04-01 11:25:53.778 Description: Windows Defender Antivirus has detected malware or other potentially unwanted software. For more information please see the following: https://go.microsoft.com/fwlink/?linkid=37020&name=Program:Win32/Unwaders.C!ml&threatid=242874&enterprise=0 Name: Program:Win32/Unwaders.C!ml ID: 242874 Severity: Severe Category: Potentially Unwanted Software Path: file:_C:\Users\c\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\TempState\Downloads\Microsoft Office 2017 Cracked – Activator_2280238021 (1).exe Detection Origin: Local machine Detection Type: FastPath Detection Source: Real-Time Protection Process Name: C:\Windows\System32\svchost.exe Signature Version: AV: 1.291.889.0, AS: 1.291.889.0, NIS: 1.291.889.0 Engine Version: AM: 1.1.15800.1, NIS: 1.1.15800.1 Date: 2019-04-06 21:46:25.973 Description: Windows Defender Antivirus has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.291.1275.0 Update Source: Microsoft Update Server Signature Type: AntiVirus Update Type: Full Current Engine Version: Previous Engine Version: 1.1.15800.1 Error code: 0x80240016 Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support. Date: 2019-04-03 02:28:08.350 Description: Windows Defender Antivirus has encountered an error trying to update signatures. New Signature Version: 1.291.1061.0 Previous Signature Version: 1.291.1037.0 Update Source: User Signature Type: AntiSpyware Update Type: Delta Current Engine Version: 1.1.15800.1 Previous Engine Version: 1.1.15800.1 Error code: 0x80509004 Error description: An unexpected problem occurred. Install any available updates, and then try to start the program again. For information on installing updates, see Help and Support. Date: 2019-04-03 02:28:08.349 Description: Windows Defender Antivirus has encountered an error trying to update signatures. New Signature Version: 1.291.1061.0 Previous Signature Version: 1.291.1037.0 Update Source: User Signature Type: AntiVirus Update Type: Delta Current Engine Version: 1.1.15800.1 Previous Engine Version: 1.1.15800.1 Error code: 0x80509004 Error description: An unexpected problem occurred. Install any available updates, and then try to start the program again. For information on installing updates, see Help and Support. Date: 2019-03-27 02:29:08.839 Description: Windows Defender Antivirus has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.291.481.0 Update Source: Microsoft Update Server Signature Type: AntiVirus Update Type: Full Current Engine Version: Previous Engine Version: 1.1.15800.1 Error code: 0x80240438 Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support. Date: 2019-03-27 02:19:22.390 Description: Windows Defender Antivirus has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.273.933.0 Update Source: Microsoft Malware Protection Center Signature Type: AntiVirus Update Type: Full Current Engine Version: Previous Engine Version: 1.1.15100.1 Error code: 0x80072ee7 Error description: The server name or address could not be resolved ==================== Memory info =========================== Processor: Intel(R) Core(TM) i5-3210M CPU @ 2.50GHz Percentage of memory in use: 84% Total physical RAM: 4000.86 MB Available physical RAM: 639.58 MB Total Virtual: 7840.86 MB Available Virtual: 2498.65 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:297.55 GB) (Free:249 GB) NTFS \\?\Volume{b4c3be5f-0000-0000-0000-100000000000}\ (System Reserved) (Fixed) (Total:0.54 GB) (Free:0.13 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7/8/10) (Size: 298.1 GB) (Disk ID: B4C3BE5F) Partition 1: (Active) - (Size=549 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=297.6 GB) - (Type=07 NTFS) ==================== End of Addition.txt ============================