Additional scan result of Farbar Recovery Scan Tool (x64) Version: 22-06-2019 Ran by [removed] (23-06-2019 21:38:36) Running from C:\Users\[removed]\Downloads Windows 10 Home Version 1809 17763.557 (X64) (2019-03-04 02:12:49) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-105068452-229409033-3044687292-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-105068452-229409033-3044687292-503 - Limited - Disabled) Guest (S-1-5-21-105068452-229409033-3044687292-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-105068452-229409033-3044687292-1005 - Limited - Enabled) Ken (S-1-5-21-105068452-229409033-3044687292-1001 - Administrator - Enabled) => C:\Users\Ken WDAGUtilityAccount (S-1-5-21-105068452-229409033-3044687292-504 - Limited - Disabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 19.012.20035 - Adobe Systems Incorporated) Adobe Flash Player 32 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 32.0.0.207 - Adobe) aioscnnr (HKLM-x32\...\{EF53BFAB-4C10-40DB-A82D-9B07111715C6}) (Version: 7.6.13.10 - Your Company Name) Hidden Amazon 1Button App (HKLM-x32\...\{8A7A4673-CB99-40B2-8699-FF46DFD05473}) (Version: 1.0.3 - Amazon) <==== ATTENTION Apple Application Support (32-bit) (HKLM-x32\...\{C1BCFECF-6EC2-4750-9072-5E2489423F8F}) (Version: 7.5 - Apple Inc.) Apple Application Support (64-bit) (HKLM\...\{B202C7F5-7DE3-4FBF-B259-E70E625F56FC}) (Version: 7.5 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{B5A46811-3612-4DA5-8A5A-E6DED5D7C523}) (Version: 12.2.1.12 - Apple Inc.) Apple Software Update (HKLM-x32\...\{A30EA700-5515-48F0-88B0-9E99DC356B88}) (Version: 2.6.0.1 - Apple Inc.) Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.) C4USelfUpdater (HKLM-x32\...\{48B41C3A-9A92-4B81-B653-C97FEB85C910}) (Version: 1.00.0000 - Your Company Name) Hidden CCleaner (HKLM\...\CCleaner) (Version: 5.57 - Piriform) CyberLink Media Suite Essentials (HKLM-x32\...\InstallShield_{8F14AA37-5193-4A14-BD5B-BDF9B361AEF7}) (Version: 10.0 - CyberLink Corp.) D3DX10 (HKLM-x32\...\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden Dell Touchpad (HKLM\...\SynTPDeinstKey) (Version: 19.2.17.70 - Synaptics Incorporated) Dell Update (HKLM-x32\...\{D9E0A33F-19D6-45A7-83BB-535C7B5F699B}) (Version: 1.5.3000.0 - Dell Inc.) Dell WLAN and Bluetooth Client Installation (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 10.0 - Dell Inc.) essentials (HKLM-x32\...\{BE94C681-68E2-4561-8ABC-8D2E799168B4}) (Version: 7.8.0.0 - Eastman Kodak Company) Hidden Galerie de photos (HKLM-x32\...\{446CC8CE-0E90-44F7-ADD0-774B243EF090}) (Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Google Chrome (HKLM-x32\...\Google Chrome) (Version: 75.0.3770.100 - Google LLC) Google Earth Plug-in (HKLM-x32\...\{4AB54F11-2F8C-11E3-B09F-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google) Google Toolbar for Internet Explorer (HKLM-x32\...\{18455581-E099-4BA8-BC6B-F34B2F06600C}) (Version: 1.0.0 - Google Inc.) Hidden Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.8231.2252 - Google Inc.) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.34.11 - Google LLC) Hidden Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden GoToAssist Corporate (HKLM-x32\...\GoToAssist) (Version: 10.4.0.896 - Citrix Online, a division of Citrix Systems, Inc.) HP DeskJet 2600 series Basic Device Software (HKLM\...\{FB71D010-BD89-4624-B681-355F72DE4E58}) (Version: 43.3.2478.18107 - HP Inc.) HP DeskJet 2600 series Help (HKLM-x32\...\{9A36A9D9-787C-4E75-914B-CF133FA88FC9}) (Version: 44.0.0 - HP) HP Dropbox Plugin (HKLM-x32\...\{C68BD3B6-3CC4-4871-94D1-3412A571001F}) (Version: 36.0.100.66344 - HP) HP EmailSMTP Plugin (HKLM-x32\...\{763E42DC-F6DB-49E5-AAFD-CC3273F858CB}) (Version: 43.0.0.0 - HP) HP FTP Plugin (HKLM-x32\...\{1E02EFE9-1EDB-4EE4-B02F-1B23C9AF3CD5}) (Version: 43.0.0.0 - HP) HP Google Drive Plugin (HKLM-x32\...\{ADA6C223-3EEA-4CAF-822A-5380A7A40342}) (Version: 36.0.100.66344 - HP) HP OneDrive Plugin (HKLM-x32\...\{16DB1A9B-1180-43E7-BE29-7201EE339206}) (Version: 36.0.0.0 - HP) HP SharePoint Plugin (HKLM-x32\...\{1F73FB9B-71BC-47F8-8AA6-DA9076E4E52B}) (Version: 43.0.0.0 - HP) iCloud (HKLM\...\{5FEE6A85-BB93-49AB-8927-F1D780BB6727}) (Version: 7.8.0.7 - Apple Inc.) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1252 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.4276 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.8.2.1000 - Intel Corporation) iTunes (HKLM\...\{A8AF3EF8-5010-4A92-BCCA-90F62A7D62B8}) (Version: 12.9.5.7 - Apple Inc.) Kodak AIO Printer (HKLM\...\{27EF8E7F-88D1-4ec5-ADE2-7E447FDF114E}) (Version: 7.8.1.0 - Eastman Kodak Company) Hidden Malwarebytes Anti-Exploit version 1.13.1.63 (HKLM\...\Malwarebytes Anti-Exploit_is1) (Version: 1.13.1.63 - Malwarebytes) Microsoft Mouse and Keyboard Center (HKLM\...\Microsoft Mouse and Keyboard Center) (Version: 2.5.166.0 - Microsoft Corporation) Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4454.1510 - Microsoft Corporation) Microsoft Office Word Viewer 2003 (HKLM-x32\...\{90850409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-105068452-229409033-3044687292-1001\...\OneDriveSetup.exe) (Version: 19.086.0502.0006 - Microsoft Corporation) Microsoft PowerPoint Viewer (HKLM-x32\...\{95140000-00AF-0409-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50918.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Movie Maker (HKLM-x32\...\{5BABDA39-61CF-41EE-992D-4054B6649A9B}) (Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Movie Maker (HKLM-x32\...\{A17946CA-18E5-4CF0-8D55-A56D804718F8}) (Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Movie Maker (HKLM-x32\...\{ED6C77F9-4D7E-447C-9EC0-9A212D075535}) (Version: 16.4.3505.0912 - Microsoft Corporation) Hidden ocr (HKLM-x32\...\{BFBCF96F-7361-486A-965C-54B17AC35421}) (Version: 6.2.3.50 - Eastman Kodak Company) Hidden Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9 - Google, Inc.) PocketCloud (HKLM-x32\...\{AAF1E996-6AE6-4684-88A8-41F4E98E2899}) (Version: 2.6.21 - Wyse Technology) PreReq (HKLM-x32\...\{DA5BDB2A-12F0-4343-8351-21AAEB293990}) (Version: 6.2.4.0 - Eastman Kodak Company) Hidden Qualcomm Atheros Bluetooth Suite (64) (HKLM\...\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.0.218 - Qualcomm Atheros Communications) Quickset64 (HKLM\...\{87CF757E-C1F1-4D22-865C-00C6950B5258}) (Version: 10.15.018 - Dell Inc.) QuickTime 7 (HKLM-x32\...\{80CEEB1E-0A6C-45B9-A312-37A1D25FDEBC}) (Version: 7.78.80.95 - Apple Inc.) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7544 - Realtek Semiconductor Corp.) Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.8400.39030 - Realtek Semiconductor Corp.) Shared C Run-time for x64 (HKLM\...\{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee) Should I Remove It (HKLM-x32\...\{4E62123C-4C0D-4123-A8A2-C0103B92D7EA}) (Version: 1.0.4 - Reason Software Company Inc.) Hidden Should I Remove It (HKU\S-1-5-21-105068452-229409033-3044687292-1001\...\Should I Remove It 1.0.4) (Version: 1.0.4 - Reason Software Company Inc.) Smart View 2.0 (HKLM-x32\...\{FBAAAFAE-08A8-4C63-87EA-4AEA9DEE53E1}) (Version: 1.0.0.0 - Samsung) Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{1FD817A6-63E1-4519-BFD4-228DABB7AB6B}) (Version: 2.55.0.0 - Microsoft Corporation) Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies) Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.) VLC media player (HKLM\...\VLC media player) (Version: 2.1.5 - VideoLAN) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3505.0912 - Microsoft Corporation) Packages: ========= AdBlock -> C:\Program Files\WindowsApps\BetaFish.AdBlock_2.9.0.0_neutral__c1wakc4j0nefm [2019-05-01] (BetaFish) Amazon -> C:\Program Files\WindowsApps\Amazon.com.Amazon_2018.519.2811.0_x64__343d40qqvtj1t [2019-05-01] (Amazon.com) Autodesk SketchBook -> C:\Program Files\WindowsApps\89006A2E.AutodeskSketchBook_5.0.2.0_x64__tf1gferkr813w [2019-05-28] (Autodesk Inc.) Candy Crush Saga -> C:\Program Files\WindowsApps\king.com.CandyCrushSaga_1.1530.2.0_x86__kgqvnymyfvs32 [2019-06-13] (king.com) Dell Shop -> C:\Program Files\WindowsApps\DellInc.DellShop_2.2.1.0_neutral__htrsf667h5kn2 [2019-05-01] (Dell Inc) eBay -> C:\Program Files\WindowsApps\eBayInc.eBay_1.6.0.34_neutral__1618n3s9xq8tw [2019-05-01] (eBay, Inc) EML Viewer -> C:\Program Files\WindowsApps\48861BrendanGrant.EMLViewer_1.1.0.10_neutral__9dz0c3wn4mg6e [2019-05-01] (Brendan Grant) HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_95.1.531.0_x64__v10z8vjag6ke6 [2019-05-01] (HP Inc.) Kindle -> C:\Program Files\WindowsApps\AMZNMobileLLC.KindleforWindows8_2.1.0.2_neutral__stfe6vwa9jnbp [2019-05-01] (AMZN Mobile LLC) Mail and Calendar -> C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20174.0_x64__8wekyb3d8bbwe [2019-05-30] (Microsoft Corporation) [MS Ad] Microsoft Advertising SDK for JavaScript -> C:\Program Files\WindowsApps\Microsoft.Advertising.JavaScript_10.1805.2.0_x64__8wekyb3d8bbwe [2019-05-01] (Microsoft Corporation) [MS Ad] Microsoft Advertising SDK for JavaScript -> C:\Program Files\WindowsApps\Microsoft.Advertising.JavaScript_10.1805.2.0_x86__8wekyb3d8bbwe [2019-05-01] (Microsoft Corporation) [MS Ad] Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-05-01] (Microsoft Corporation) [MS Ad] Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-05-01] (Microsoft Corporation) [MS Ad] Microsoft News -> C:\Program Files\WindowsApps\Microsoft.BingNews_4.30.10924.0_x64__8wekyb3d8bbwe [2019-05-01] (Microsoft Corporation) [MS Ad] Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.4.6132.0_x64__8wekyb3d8bbwe [2019-06-17] (Microsoft Studios) [MS Ad] MSN Health & Fitness -> C:\Program Files\WindowsApps\Microsoft.BingHealthAndFitness_3.0.4.336_x64__8wekyb3d8bbwe [2019-05-01] (Microsoft Corporation) [MS Ad] MSN Money -> C:\Program Files\WindowsApps\Microsoft.BingFinance_4.29.10701.0_x64__8wekyb3d8bbwe [2019-05-01] (Microsoft Corporation) [MS Ad] MSN Sports -> C:\Program Files\WindowsApps\Microsoft.BingSports_4.28.3242.0_x64__8wekyb3d8bbwe [2019-05-01] (Microsoft Corporation) [MS Ad] MSN Travel -> C:\Program Files\WindowsApps\Microsoft.BingTravel_3.0.4.336_x64__8wekyb3d8bbwe [2019-05-01] (Microsoft Corporation) [MS Ad] MSN Weather -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.28.10351.0_x64__8wekyb3d8bbwe [2019-05-01] (Microsoft Corporation) [MS Ad] Network Speed Test -> C:\Program Files\WindowsApps\Microsoft.NetworkSpeedTest_1.0.0.23_x64__8wekyb3d8bbwe [2019-05-01] (Microsoft Research) Twitter -> C:\Program Files\WindowsApps\9E2F88E3.Twitter_6.1.4.1000_neutral__wgeqdkkx372wm [2019-05-01] (Twitter Inc.) Wikipedia -> C:\Program Files\WindowsApps\WikimediaFoundation.Wikipedia_1.1.0.37_neutral__54ggd3ev8bvz6 [2019-05-01] (Wikimedia Foundation) Word Viewer -> C:\Program Files\WindowsApps\9323vladw.WordViewer_1.0.0.0_neutral__1za3b51bhh22y [2019-05-01] (vladw) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-105068452-229409033-3044687292-1001_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\WINDOWS\system32\igfxEM.exe (Intel(R) pGFX -> Intel Corporation) ShellExecuteHooks-x32: No Name - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - -> No File ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File ShellIconOverlayIdentifiers: [DBARFileBackuped] -> {831cebdd-6baf-4432-be76-9e0989c14aef} => C:\Program Files (x86)\Dell Backup and Recovery\Components\Shell\DBROverlayIconBackuped.dll [2015-12-07] (SoftThinks -> SoftThinks SAS) ShellIconOverlayIdentifiers: [DBARFileNotBackuped] -> {275e4fd7-21ef-45cf-a836-832e5d2cc1b3} => C:\Program Files (x86)\Dell Backup and Recovery\Components\Shell\DBROverlayIconNotBackuped.dll [2015-12-07] (SoftThinks -> SoftThinks SAS) ShellIconOverlayIdentifiers: [DBRShellOverlayBackupFile] -> {831CEBDD-6BAF-4432-BE76-9E0989C14AEF} => C:\Program Files (x86)\Dell Backup and Recovery\Components\Shell\DBROverlayIconBackuped.dll [2015-12-07] (SoftThinks -> SoftThinks SAS) ShellIconOverlayIdentifiers: [DBRShellOverlayModifiedBackupFile] -> {275E4FD7-21EF-45CF-A836-832E5D2CC1B3} => C:\Program Files (x86)\Dell Backup and Recovery\Components\Shell\DBROverlayIconNotBackuped.dll [2015-12-07] (SoftThinks -> SoftThinks SAS) ContextMenuHandlers1: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} => C:\Program Files (x86)\Common Files\CyberLink\ShellExtComponent\CLVDShellExt.dll [2012-12-10] (CyberLink Corp. -> Cyberlink) ContextMenuHandlers1: [PhotoStreamsExt] -> {89D984B3-813B-406A-8298-118AFA3A22AE} => C:\Program Files\Common Files\Apple\Internet Services\ShellStreams64.dll [2018-10-01] (Apple Inc. -> Apple Inc.) ContextMenuHandlers2: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} => C:\Program Files (x86)\Common Files\CyberLink\ShellExtComponent\CLVDShellExt.dll [2012-12-10] (CyberLink Corp. -> Cyberlink) ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\system32\igfxDTCM.dll [2016-05-03] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation) ContextMenuHandlers5: [igfxOSP] -> {FA507C3F-30C6-4DCA-9EE5-2656072EEC14} => C:\WINDOWS\system32\igfxOSP.dll [2016-05-03] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation) ==================== Shortcuts & WMI ======================== (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== 2019-06-13 20:24 - 2019-06-13 20:24 - 025891328 _____ () [File not signed] C:\Program Files\WindowsApps\king.com.CandyCrushSaga_1.1530.2.0_x86__kgqvnymyfvs32\candycrushsaga.exe 2019-05-01 20:51 - 2019-05-01 20:51 - 001682944 _____ () [File not signed] C:\Program Files\WindowsApps\king.com.CandyCrushSaga_1.1530.2.0_x86__kgqvnymyfvs32\LIBEAY32.dll 2019-05-01 20:51 - 2019-05-01 20:52 - 000416256 _____ () [File not signed] C:\Program Files\WindowsApps\king.com.CandyCrushSaga_1.1530.2.0_x86__kgqvnymyfvs32\SSLEAY32.dll 2019-05-01 20:51 - 2019-05-01 20:52 - 000072704 _____ () [File not signed] C:\Program Files\WindowsApps\king.com.CandyCrushSaga_1.1530.2.0_x86__kgqvnymyfvs32\zlib1.dll 2015-11-30 15:22 - 2014-03-17 14:15 - 000375296 _____ (CANON INC.) [File not signed] C:\WINDOWS\System32\CNMN6PPM.DLL 2013-08-30 21:18 - 2013-08-30 21:18 - 000517120 _____ (Intel Corporation) [File not signed] C:\Program Files\Intel\Intel(R) Rapid Storage Technology\ISDI2.dll 2013-08-30 21:18 - 2013-08-30 21:18 - 000286720 _____ (Intel Corporation) [File not signed] C:\Program Files\Intel\Intel(R) Rapid Storage Technology\PsiData.dll 2013-08-03 12:46 - 2012-12-26 03:41 - 000081536 _____ (Qualcomm Atheros -> Atheros) [File not signed] C:\Program Files (x86)\Dell Wireless\Ath_WlanAgent.exe 2019-05-01 20:51 - 2019-05-01 20:51 - 000252416 _____ (The curl library, hxxps://curl.haxx.se/) [File not signed] C:\Program Files\WindowsApps\king.com.CandyCrushSaga_1.1530.2.0_x86__kgqvnymyfvs32\libcurl.dll 2013-06-21 21:46 - 2013-06-21 21:46 - 007660032 _____ (Wyse Technology) [File not signed] C:\Program Files (x86)\Wyse\PocketCloud\aethercommonlib.dll 2013-06-21 21:37 - 2013-06-21 21:37 - 000019968 _____ (Wyse Technology) [File not signed] C:\Program Files (x86)\Wyse\PocketCloud\VideoBoostHelper.dll 2012-11-29 15:56 - 2012-11-29 15:56 - 001436160 _____ (Wyse Technology.) [File not signed] C:\Program Files (x86)\Wyse\PocketCloud\WyseRemoteAccess.exe ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\Syst24CF6841:$WIMMOUNTDATA [562] AlternateDataStreams: C:\Syst40895947:$WIMMOUNTDATA [562] ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) IE trusted site: HKU\S-1-5-21-105068452-229409033-3044687292-1001\...\dell.com -> dell.com IE restricted site: HKU\S-1-5-21-105068452-229409033-3044687292-1001\...\007guard.com -> install.007guard.com IE restricted site: HKU\S-1-5-21-105068452-229409033-3044687292-1001\...\008i.com -> 008i.com IE restricted site: HKU\S-1-5-21-105068452-229409033-3044687292-1001\...\008k.com -> www.008k.com IE restricted site: HKU\S-1-5-21-105068452-229409033-3044687292-1001\...\00hq.com -> www.00hq.com IE restricted site: HKU\S-1-5-21-105068452-229409033-3044687292-1001\...\010402.com -> 010402.com IE restricted site: HKU\S-1-5-21-105068452-229409033-3044687292-1001\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com IE restricted site: HKU\S-1-5-21-105068452-229409033-3044687292-1001\...\0scan.com -> www.0scan.com IE restricted site: HKU\S-1-5-21-105068452-229409033-3044687292-1001\...\1-2005-search.com -> www.1-2005-search.com IE restricted site: HKU\S-1-5-21-105068452-229409033-3044687292-1001\...\1-domains-registrations.com -> www.1-domains-registrations.com IE restricted site: HKU\S-1-5-21-105068452-229409033-3044687292-1001\...\1000gratisproben.com -> www.1000gratisproben.com IE restricted site: HKU\S-1-5-21-105068452-229409033-3044687292-1001\...\1001namen.com -> www.1001namen.com IE restricted site: HKU\S-1-5-21-105068452-229409033-3044687292-1001\...\100888290cs.com -> mir.100888290cs.com IE restricted site: HKU\S-1-5-21-105068452-229409033-3044687292-1001\...\100sexlinks.com -> www.100sexlinks.com IE restricted site: HKU\S-1-5-21-105068452-229409033-3044687292-1001\...\10sek.com -> www.10sek.com IE restricted site: HKU\S-1-5-21-105068452-229409033-3044687292-1001\...\12-26.net -> user1.12-26.net IE restricted site: HKU\S-1-5-21-105068452-229409033-3044687292-1001\...\12-27.net -> user1.12-27.net IE restricted site: HKU\S-1-5-21-105068452-229409033-3044687292-1001\...\123fporn.info -> www.123fporn.info IE restricted site: HKU\S-1-5-21-105068452-229409033-3044687292-1001\...\123haustiereundmehr.com -> www.123haustiereundmehr.com IE restricted site: HKU\S-1-5-21-105068452-229409033-3044687292-1001\...\123moviedownload.com -> www.123moviedownload.com IE restricted site: HKU\S-1-5-21-105068452-229409033-3044687292-1001\...\123simsen.com -> www.123simsen.com There are 7865 more sites. ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2013-08-22 08:25 - 2014-08-13 15:48 - 000000952 _____ C:\WINDOWS\system32\drivers\etc\hosts 127.0.0.1 localhost ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\ProgramData\Oracle\Java\javapath;c:\Program Files (x86)\Intel\iCLS Client\;c:\Program Files\Intel\iCLS Client\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\QuickTime\QTSystem\;%SYSTEMROOT%\System32\OpenSSH\ HKU\S-1-5-21-105068452-229409033-3044687292-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Ken\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\img0.jpg DNS Servers: 192.168.100.254 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin) HKLM\software\microsoft\Windows\CurrentVersion\Telephony\Providers => ProviderFileName2 -> ndptsp.tsp (No File) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == If an entry is included in the fixlist, it will be removed. HKLM\...\StartupApproved\Run: => "IAStorIcon" HKLM\...\StartupApproved\Run: => "QuickSet" HKLM\...\StartupApproved\Run: => "iTunesHelper" HKLM\...\StartupApproved\Run32: => "RemoteControl10" HKLM\...\StartupApproved\Run32: => "APSDaemon" HKLM\...\StartupApproved\Run32: => "QuickTime Task" HKLM\...\StartupApproved\Run32: => "IJNetworkScannerSelectorEX" HKLM\...\StartupApproved\Run32: => "CanonQuickMenu" HKLM\...\StartupApproved\Run32: => "Adobe ARM" HKU\S-1-5-21-105068452-229409033-3044687292-1001\...\StartupApproved\Run: => "GarminExpressTrayApp" HKU\S-1-5-21-105068452-229409033-3044687292-1001\...\StartupApproved\Run: => "swg" HKU\S-1-5-21-105068452-229409033-3044687292-1001\...\StartupApproved\Run: => "uTorrent" HKU\S-1-5-21-105068452-229409033-3044687292-1001\...\StartupApproved\Run: => "BingSvc" HKU\S-1-5-21-105068452-229409033-3044687292-1001\...\StartupApproved\Run: => "iCloudServices" HKU\S-1-5-21-105068452-229409033-3044687292-1001\...\StartupApproved\Run: => "3E04CDCF51BC64C6D6E520520BB7F76D39810925._service_run" HKU\S-1-5-21-105068452-229409033-3044687292-1001\...\StartupApproved\Run: => "appnhost" HKU\S-1-5-21-105068452-229409033-3044687292-1001\...\StartupApproved\Run: => "DAEMON Tools Lite Automount" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{9BFAE656-72B2-48FD-A25C-C299F48AFCE2}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc. -> Apple Inc.) FirewallRules: [{0EC9EDAE-2F08-437A-A21E-81ED00811C0F}] => (Allow) C:\Program Files (x86)\SmartView2\Smart View 2.0.exe () [File not signed] FirewallRules: [{7F8B7ACA-8EBB-44C8-BF27-7EE3D941F853}] => (Allow) C:\Program Files (x86)\SmartView2\Smart View 2.0.exe () [File not signed] FirewallRules: [{23ED5C0B-1765-497C-A466-8A7C3C6E88DA}] => (Allow) C:\Program Files (x86)\SmartView2\Smart View 2.0.exe () [File not signed] FirewallRules: [{C01D4300-449D-4578-BD5B-2B0D1D1CB0DC}] => (Allow) C:\Program Files (x86)\SmartView2\Smart View 2.0.exe () [File not signed] FirewallRules: [{5D7CA46C-0461-4D00-B669-46EA7C97C375}] => (Allow) C:\Users\Ken\Downloads\solutoinstaller.exe (Soluto -> Soluto Inc) FirewallRules: [{9689C47A-E3F2-46A8-9319-B01731B4CFBA}] => (Allow) C:\Users\Ken\Downloads\solutoinstaller.exe (Soluto -> Soluto Inc) FirewallRules: [{E166FA2C-ACBF-443D-84CC-297D2C30D13F}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.) FirewallRules: [{8F3BA739-53BA-4A36-A66C-4D65EE59690B}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.) FirewallRules: [{A481E854-CA42-485B-8F6D-C0EBC4A812BB}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.) FirewallRules: [{6EC64D5C-2466-49BA-99C4-2DE477BC42E4}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.) FirewallRules: [{1AE20FAB-C592-4F74-B240-121484E924B6}] => (Allow) C:\Program Files (x86)\Wyse\PocketCloud\WyseRemoteAccess.exe (Wyse Technology.) [File not signed] FirewallRules: [{56051E5E-50B2-469F-8F6D-5D52550BB38D}] => (Allow) C:\Program Files (x86)\Wyse\PocketCloud\PocketCloudDesktopApp.exe (Wyse Technology Inc -> ) [File not signed] FirewallRules: [{41E6C5AA-2D76-45EE-898E-934E98500C3B}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDirector10\PDR10.EXE (CyberLink Corp. -> CyberLink Corp.) FirewallRules: [{1C8129C2-21CB-4537-8F96-9D49B503AA4B}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD Cinema\PowerDVDCinema10.exe (CyberLink Corp. -> CyberLink Corp.) FirewallRules: [{31955CBF-0D93-4EF0-BEDC-FA27C529869B}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD10.EXE (CyberLink Corp. -> CyberLink Corp.) FirewallRules: [{ED9E9B2C-B65F-4868-BE35-73BC124ED4A5}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{FEBF751A-1220-4866-887A-FA459977DAC8}] => (Allow) LPort=2869 FirewallRules: [{684FE34E-DAF5-4584-91FC-348AE9CAE7B4}] => (Allow) LPort=1900 FirewallRules: [{4094A5F3-7635-4697-953F-D40268F1176F}] => (Allow) LPort=5353 FirewallRules: [{ACB66893-3AFF-4E44-BA4D-6FB46C279A2C}] => (Allow) LPort=9322 FirewallRules: [{97064D67-D83E-42C4-A286-613227CFE19F}] => (Allow) LPort=5353 FirewallRules: [{D86345C3-B3D4-4E3C-AC2D-2FFA84E854AE}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.) FirewallRules: [{03484082-1404-4F9D-BE33-75DA5FEB4ACA}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.) FirewallRules: [{E36D2F73-8C78-49F1-A817-787061C5687C}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.) FirewallRules: [{C580ABF0-4617-4CED-B575-49053893BF87}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.) FirewallRules: [{87247255-C1BB-440D-ACA2-EE9E1507F6CF}] => (Allow) C:\Program Files (x86)\Kodak\AiO\Center\Kodak.Statistics.exe (Eastman Kodak Company -> Eastman Kodak Company) FirewallRules: [{15F567D2-A01D-4AD0-ABA5-C5C8B0FA61EC}] => (Allow) C:\Program Files (x86)\Kodak\AiO\Center\Kodak.Statistics.exe (Eastman Kodak Company -> Eastman Kodak Company) FirewallRules: [{E86C6252-FC99-4E11-84BB-3AAC413ABAD6}] => (Allow) C:\Program Files (x86)\Kodak\AiO\Center\NetworkPrinterDiscovery.exe (Eastman Kodak Company -> Eastman Kodak Company) FirewallRules: [{A1563EA1-22DE-4EF1-A266-9FD0734F801C}] => (Allow) C:\Program Files (x86)\Kodak\AiO\Center\NetworkPrinterDiscovery.exe (Eastman Kodak Company -> Eastman Kodak Company) FirewallRules: [{7D6E266D-A34F-459C-BDC2-A0F5F280EBAD}] => (Allow) C:\Program Files (x86)\Kodak\AiO\Firmware\KodakAiOUpdater.exe (Eastman Kodak Company -> Eastman Kodak Company) FirewallRules: [{61F6932A-6293-4253-9B4F-92094202BEF4}] => (Allow) C:\Program Files (x86)\Kodak\AiO\Firmware\KodakAiOUpdater.exe (Eastman Kodak Company -> Eastman Kodak Company) FirewallRules: [{4D9D9C5E-B967-4185-8E02-1B8E8D5A624D}] => (Allow) C:\ProgramData\Kodak\Installer\Setup.exe (Eastman Kodak Company) [File not signed] FirewallRules: [{70D65792-FA4C-4A31-ADAD-A671E18E867A}] => (Allow) C:\ProgramData\Kodak\Installer\Setup.exe (Eastman Kodak Company) [File not signed] FirewallRules: [{1F732FCE-1ADD-4E68-A044-08F8858A3744}] => (Allow) LPort=9322 FirewallRules: [{3AB8D331-00E9-462E-9A82-E1412D452B3E}] => (Allow) C:\Program Files\HP\HP DeskJet 2600 series\bin\DigitalWizards.exe (Hewlett Packard -> HP Inc.) FirewallRules: [{5190F8F1-2C06-4530-A85E-A97FDC45C2CD}] => (Allow) C:\Program Files\HP\HP DeskJet 2600 series\Bin\DeviceSetup.exe (Hewlett Packard -> HP Inc.) FirewallRules: [{BB892BF6-B1DC-47FB-BF86-10A3F8EA406C}] => (Allow) LPort=5357 FirewallRules: [{6CE00014-2C82-4671-8F75-45181123D898}] => (Allow) C:\Program Files\HP\HP DeskJet 2600 series\Bin\HPNetworkCommunicatorCom.exe (Hewlett Packard -> HP Inc.) FirewallRules: [{1B10F5E6-B1DE-4D9F-BCEA-B1D0CB4ADA66}] => (Allow) C:\Program Files\iTunes\iTunes.exe (Apple Inc. -> Apple Inc.) FirewallRules: [{DCF11C0A-6106-46CA-A5E0-0E031AB43AAA}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) ==================== Restore Points ========================= 03-06-2019 13:46:34 Scheduled Checkpoint 12-06-2019 09:35:27 Windows Update 12-06-2019 09:36:29 Windows Update 19-06-2019 20:13:56 Scheduled Checkpoint ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (06/23/2019 12:44:23 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: mDNSCoreReceiveResponse: Unexpected conflict discarding 20 110.100.168.192.in-addr.arpa. PTR KensComputer.local. Error: (06/23/2019 12:44:23 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: mDNSCoreReceiveResponse: Received from 192.168.100.110:5353 22 110.100.168.192.in-addr.arpa. PTR KensComputer-2.local. Error: (06/23/2019 08:54:58 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: mDNSCoreReceiveResponse: Unexpected conflict discarding 20 110.100.168.192.in-addr.arpa. PTR KensComputer.local. Error: (06/23/2019 08:54:58 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: mDNSCoreReceiveResponse: Received from 192.168.100.110:5353 22 110.100.168.192.in-addr.arpa. PTR KensComputer-2.local. Error: (06/22/2019 05:52:55 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: mDNSCoreReceiveResponse: Unexpected conflict discarding 20 110.100.168.192.in-addr.arpa. PTR KensComputer.local. Error: (06/22/2019 05:52:55 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: mDNSCoreReceiveResponse: Received from 192.168.100.110:5353 22 110.100.168.192.in-addr.arpa. PTR KensComputer-2.local. Error: (06/20/2019 08:08:55 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: mDNSCoreReceiveResponse: Unexpected conflict discarding 20 110.100.168.192.in-addr.arpa. PTR KensComputer.local. Error: (06/20/2019 08:08:55 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: mDNSCoreReceiveResponse: Received from 192.168.100.110:5353 22 110.100.168.192.in-addr.arpa. PTR KensComputer-2.local. System errors: ============= Error: (06/23/2019 08:34:28 PM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY) Description: The server {F3B4E234-7A68-4E43-B813-E4BA55A065F6} did not register with DCOM within the required timeout. Error: (06/23/2019 08:07:00 PM) (Source: DCOM) (EventID: 10016) (User: KENSCOMPUTER) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54} and APPID {15C20B67-12E7-4BB6-92BB-7AFF07997402} to the user KensComputer\Ken SID (S-1-5-21-105068452-229409033-3044687292-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (06/23/2019 08:05:40 PM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY) Description: The server {784E29F4-5EBE-4279-9948-1E8FE941646D} did not register with DCOM within the required timeout. Error: (06/23/2019 12:47:31 PM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY) Description: The server {784E29F4-5EBE-4279-9948-1E8FE941646D} did not register with DCOM within the required timeout. Error: (06/23/2019 12:46:58 PM) (Source: DCOM) (EventID: 10016) (User: KENSCOMPUTER) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54} and APPID {15C20B67-12E7-4BB6-92BB-7AFF07997402} to the user KensComputer\Ken SID (S-1-5-21-105068452-229409033-3044687292-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (06/23/2019 09:00:16 AM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY) Description: The server {784E29F4-5EBE-4279-9948-1E8FE941646D} did not register with DCOM within the required timeout. Error: (06/23/2019 08:59:23 AM) (Source: DCOM) (EventID: 10016) (User: KENSCOMPUTER) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54} and APPID {15C20B67-12E7-4BB6-92BB-7AFF07997402} to the user KensComputer\Ken SID (S-1-5-21-105068452-229409033-3044687292-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (06/22/2019 11:09:02 PM) (Source: DCOM) (EventID: 10000) (User: KENSCOMPUTER) Description: Unable to start a DCOM Server: {0358B920-0AC7-461F-98F4-58E32CD89148}. The error: "0" Happened while starting this command: C:\WINDOWS\system32\DllHost.exe /Processid:{3EB3C877-1F16-487C-9050-104DBCD66683} Windows Defender: =================================== Date: 2019-06-23 13:45:57.524 Description: C:\Program Files\Synaptics\SynTP\SynTPEnh.exe has been blocked from modifying %userprofile%\Desktop by Controlled Folder Access. Detection time: 2019-06-23T18:45:57.524Z Path: %userprofile%\Desktop Process Name: C:\Program Files\Synaptics\SynTP\SynTPEnh.exe Signature Version: 1.295.1278.0 Engine Version: 1.1.16000.6 Product Version: 4.18.1905.4 Date: 2019-06-23 11:17:51.766 Description: C:\Program Files\Synaptics\SynTP\SynTPEnh.exe has been blocked from modifying %userprofile%\Desktop by Controlled Folder Access. Detection time: 2019-06-23T16:17:51.766Z Path: %userprofile%\Desktop Process Name: C:\Program Files\Synaptics\SynTP\SynTPEnh.exe Signature Version: 1.295.1278.0 Engine Version: 1.1.16000.6 Product Version: 4.18.1905.4 Date: 2019-06-21 09:27:25.246 Description: Windows Defender Antivirus scan has been stopped before completion. Scan ID: {CDE8240D-3319-448B-891A-EC15916123F2} Scan Type: Antimalware Scan Parameters: Quick Scan Date: 2019-06-20 23:23:33.674 Description: Windows Defender Antivirus scan has been stopped before completion. Scan ID: {19955E68-3170-4DF9-968E-7CBB5CCEE138} Scan Type: Antimalware Scan Parameters: Quick Scan Date: 2019-06-20 22:13:25.740 Description: Windows Defender Antivirus scan has been stopped before completion. Scan ID: {0043C418-DAD7-4ED0-8F83-5E7FAFADFABF} Scan Type: Antimalware Scan Parameters: Quick Scan CodeIntegrity: =================================== Date: 2019-04-30 21:14:19.475 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\System32\browser_broker.exe) attempted to load \Device\HarddiskVolume5\Program Files\Common Files\Apple\Internet Services\ShellStreams64.dll that did not meet the Microsoft signing level requirements. Date: 2019-04-30 21:14:19.217 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\System32\browser_broker.exe) attempted to load \Device\HarddiskVolume5\Program Files\Common Files\Apple\Internet Services\ShellStreams64.dll that did not meet the Microsoft signing level requirements. Date: 2019-04-30 21:14:18.978 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\System32\browser_broker.exe) attempted to load \Device\HarddiskVolume5\Program Files\Common Files\Apple\Internet Services\ShellStreams64.dll that did not meet the Microsoft signing level requirements. Date: 2019-04-30 16:37:06.918 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\System32\browser_broker.exe) attempted to load \Device\HarddiskVolume5\Program Files\Common Files\Apple\Internet Services\ShellStreams64.dll that did not meet the Microsoft signing level requirements. Date: 2019-04-26 11:19:59.441 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\System32\browser_broker.exe) attempted to load \Device\HarddiskVolume5\Program Files\Common Files\Apple\Internet Services\ShellStreams64.dll that did not meet the Microsoft signing level requirements. Date: 2019-04-13 10:56:31.372 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\System32\browser_broker.exe) attempted to load \Device\HarddiskVolume5\Program Files\Common Files\Apple\Internet Services\ShellStreams64.dll that did not meet the Microsoft signing level requirements. Date: 2019-03-21 12:51:32.018 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\System32\browser_broker.exe) attempted to load \Device\HarddiskVolume5\Program Files\Common Files\Apple\Internet Services\ShellStreams64.dll that did not meet the Microsoft signing level requirements. Date: 2019-03-19 15:03:56.911 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\System32\browser_broker.exe) attempted to load \Device\HarddiskVolume5\Program Files\Common Files\Apple\Internet Services\ShellStreams64.dll that did not meet the Microsoft signing level requirements. ==================== Memory info =========================== BIOS: Dell Inc. A14 07/31/2015 Motherboard: Dell Inc. 0FXP6Y Processor: Intel(R) Pentium(R) CPU 2127U @ 1.90GHz Percentage of memory in use: 76% Total physical RAM: 3977.27 MB Available physical RAM: 926.26 MB Total Virtual: 6471.06 MB Available Virtual: 2406.2 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:449.78 GB) (Free:357.49 GB) NTFS \\?\Volume{21958d85-a81d-4109-b65d-7eb7403f1ad5}\ (WINRETOOLS) (Fixed) (Total:2 GB) (Free:1.66 GB) NTFS \\?\Volume{f4c2396d-a132-4733-ad05-92e9621532eb}\ () (Fixed) (Total:0.9 GB) (Free:0.34 GB) NTFS \\?\Volume{b03a627f-d2a9-4ac1-983b-5a412b9832af}\ () (Fixed) (Total:0.34 GB) (Free:0.31 GB) NTFS \\?\Volume{e58201b4-9981-4b58-a078-acbdb7b75a02}\ (PBR Image) (Fixed) (Total:12.08 GB) (Free:0.69 GB) NTFS \\?\Volume{bc5a8545-b63d-4f1d-9320-a58ed9c07cc1}\ (ESP) (Fixed) (Total:0.48 GB) (Free:0.43 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 465.8 GB) (Disk ID: 5A89C120) Partition: GPT. ==================== End of Addition.txt ============================