Additional scan result of Farbar Recovery Scan Tool (x64) Version:05-03-2016 01 Ran by brennaman (2016-04-06 16:37:29) Running from C:\Users\pbren_000\Downloads Windows 10 Home Version 1511 (X64) (2016-03-14 09:58:09) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-3610044688-3067938498-1592336940-500 - Administrator - Disabled) brennaman (S-1-5-21-3610044688-3067938498-1592336940-1001 - Administrator - Enabled) => C:\Users\pbren_000 DefaultAccount (S-1-5-21-3610044688-3067938498-1592336940-503 - Limited - Disabled) Guest (S-1-5-21-3610044688-3067938498-1592336940-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-3610044688-3067938498-1592336940-1003 - Limited - Enabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) ACP Application (Version: 2016.0321.0955.20 - Advanced Micro Devices, Inc.) Hidden AMD Install Manager (HKLM\...\AMD Catalyst Install Manager) (Version: 9.0.000.4 - Advanced Micro Devices, Inc.) Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) ASUS Smart Gesture (HKLM-x32\...\{4D3286A6-F6AB-498A-82A4-E4F040529F3D}) (Version: 4.0.12 - ASUS) Catalyst Control Center Next Localization BR (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CHS (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CHT (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CS (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization DA (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization DE (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization EL (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization ES (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization FI (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization FR (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization HU (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization IT (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization JA (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization KO (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization NL (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization NO (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization PL (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization RU (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization SV (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization TH (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization TR (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden Google Chrome (HKLM-x32\...\Google Chrome) (Version: 49.0.2623.87 - Google Inc.) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden GoPro (Version: 0.1.1799 - GoPro, Inc.) Hidden GoPro for Desktop (HKLM-x32\...\{065d0333-0b05-41f3-a564-0eabddb78841}) (Version: 0.1.0.1799 - GoPro, Inc.) GoPro Studio (x32 Version: 5.8.1799 - GoPro, Inc.) Hidden Maxx Audio Installer (x64) (Version: 2.6.6168.8 - Waves Audio Ltd.) Hidden Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) OpenAL (HKLM-x32\...\OpenAL) (Version: - ) QuickTime 7 (HKLM-x32\...\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}) (Version: 7.79.80.95 - Apple Inc.) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7535 - Realtek Semiconductor Corp.) TuneGet 4.5.4 (HKLM-x32\...\{050A0D31-6B33-4137-ADE5-C0896E5FA98D}_is1) (Version: 4.5.4 - cyan soft ltd) VFW_Codec32 (x32 Version: 0.1.160.0 - GoPro, Inc.) Hidden VFW_Codec64 (Version: 0.1.160.0 - GoPro, Inc.) Hidden Vulkan Run Time Libraries 1.0.3.1 (HKLM\...\VulkanRT1.0.3.1) (Version: 1.0.3.1 - LunarG, Inc.) Web Bar 2.0.5897.26129 (HKLM\...\{0BCE8B0A-1E76-44E5-9909-3CF804D92E4D}_is1) (Version: 2.0.5897.26129 - Web Bar Media) <==== ATTENTION Windows Driver Package - ASUS (ATP) Mouse (11/11/2015 1.0.0.262) (HKLM\...\A044C5901003C24E6891688653ABA1068D04A1A0) (Version: 11/11/2015 1.0.0.262 - ASUS) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-3610044688-3067938498-1592336940-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\pbren_000\AppData\Local\Microsoft\OneDrive\17.3.6302.0225_1\FileCoAuth.exe (Microsoft Corporation) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {01070F9D-E5CE-4386-91F6-1952CE5AA2FB} - System32\Tasks\WebBarLaunchTask => C:\Program Files\WebBar\wbsvc.exe [2016-02-23] (Web Bar Media) <==== ATTENTION Task: {03BA6F44-B38F-41DD-834A-2F8909BB11C1} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-03-12] (Google Inc.) Task: {49FD1A45-0F92-490B-8716-B97A77604E8F} - System32\Tasks\ASUS Smart Gesture Launcher => C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLauncher.exe [2015-12-14] (AsusTek) Task: {5F8D7336-CF79-4458-9F5B-22BA40B836AB} - System32\Tasks\WebBarUpdateTask => C:\Program Files\WebBar\wbsvc.exe [2016-02-23] (Web Bar Media) <==== ATTENTION Task: {66E9D742-1E8C-444D-AAD5-184E7F616AE1} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-03-12] (Google Inc.) Task: {76946680-EFAB-4C56-ADF3-A35E59F74F56} - System32\Tasks\AMD Updater => C:\Program Files\AMD\CIM\\Bin64\InstallManagerApp.exe [2016-03-21] (Advanced Micro Devices, Inc.) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\System HealerPeriod.job => Task: C:\WINDOWS\Tasks\System HealerStartUp.job => C:\Program Files (x86)\SystemHealer\SystemHealer.exe ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== 2015-10-30 02:18 - 2015-10-30 02:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll 2015-12-30 15:08 - 2015-12-30 15:08 - 03587000 _____ () C:\ProgramData\System32\SafeGuard64.dll 2016-02-26 21:26 - 2016-02-26 21:26 - 00037808 _____ () C:\Program Files\GoPro\GoPro Desktop App\GoProDeviceDetection.exe 2016-03-14 07:17 - 2016-03-14 07:17 - 02654872 _____ () C:\WINDOWS\system32\CoreUIComponents.dll 2016-03-14 07:17 - 2016-03-14 07:17 - 02654872 _____ () C:\WINDOWS\System32\CoreUIComponents.dll 2016-02-13 07:54 - 2016-02-13 07:54 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll 2016-03-14 07:18 - 2016-03-14 07:18 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll 2016-02-13 07:54 - 2016-02-13 07:54 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2016-02-13 07:54 - 2016-02-13 07:54 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2016-02-13 07:54 - 2016-02-13 07:54 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll 2016-02-13 07:54 - 2016-02-13 07:54 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll 2016-02-26 21:26 - 2016-02-26 21:26 - 01088944 _____ () C:\Program Files\GoPro\GoPro Desktop App\GoProDesktopSystemTray.exe 2015-06-25 17:34 - 2015-06-25 17:34 - 00014336 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick.2\qtquick2plugin.dll 2015-06-25 17:37 - 2015-06-25 17:37 - 00739840 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Controls\qtquickcontrolsplugin.dll 2015-06-25 17:35 - 2015-06-25 17:35 - 00014336 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Window.2\windowplugin.dll 2015-06-25 17:38 - 2015-06-25 17:38 - 00071168 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Layouts\qquicklayoutsplugin.dll 2015-06-25 16:53 - 2015-06-25 16:53 - 00011776 _____ () C:\Program Files\AMD\CNext\CNext\libEGL.dll 2015-06-25 16:51 - 2015-06-25 16:51 - 02013696 _____ () C:\Program Files\AMD\CNext\CNext\libGLESv2.dll 2015-12-30 15:08 - 2015-12-30 15:08 - 02771896 _____ () C:\ProgramData\System32\SafeGuard32.dll 2016-03-12 20:42 - 2016-03-04 16:51 - 00096768 _____ () C:\Program Files (x86)\Google\Chrome\Application\49.0.2623.87\chrome_elf.dll 2016-03-12 20:48 - 2016-03-04 16:51 - 00732160 _____ () C:\Program Files (x86)\Google\Chrome\Application\49.0.2623.87\chrome_elf_wk.dll 2016-03-12 20:42 - 2016-03-07 21:48 - 01676440 _____ () C:\Program Files (x86)\Google\Chrome\Application\49.0.2623.87\libglesv2.dll 2016-03-12 20:42 - 2016-03-07 21:48 - 00086168 _____ () C:\Program Files (x86)\Google\Chrome\Application\49.0.2623.87\libegl.dll 2016-03-14 20:21 - 2016-03-14 20:21 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe 2016-03-14 20:21 - 2016-03-14 20:21 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll 2016-03-14 20:21 - 2016-03-14 20:21 - 22330368 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkyWrap.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\WINDOWS\SysWOW64\mswinsck32.ocx:rsrc [34] ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2016-03-12 21:05 - 2016-03-12 20:55 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-3610044688-3067938498-1592336940-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\pbren_000\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\asus.jpg DNS Servers: 192.168.1.254 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) HKLM\...\StartupApproved\Run32: => "APSDaemon" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [{0A9F8759-CB93-4CC4-AAB3-F82F5CCC1021}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{6D38891C-A486-40F5-9AD5-9678AB8B816A}] => (Allow) C:\Program Files\GoPro\GoPro Desktop App\GoPro.exe FirewallRules: [{DA3F27AC-13C9-48F3-8613-DAE438210210}] => (Allow) C:\Program Files\GoPro\GoPro Desktop App\GoProMsgBus.exe FirewallRules: [{86EA5626-26C7-411D-9F5F-DC3C684E0959}] => (Allow) C:\Program Files\GoPro\GoPro Desktop App\GoProIDService.exe FirewallRules: [{DE480FA8-0D97-4068-82AD-EF3571752018}] => (Allow) C:\Program Files\GoPro\GoPro Desktop App\GoProLauncher.exe FirewallRules: [{54212043-7048-45C2-AFE8-0F7326EEE4B3}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe ==================== Restore Points ========================= 21-03-2016 17:50:15 Installed City Navigator North America NT v7 26-03-2016 11:19:28 Installed PL-2303 USB-to-Serial 03-04-2016 17:22:43 Scheduled Checkpoint 05-04-2016 20:00:58 Restore Operation ==================== Faulty Device Manager Devices ============= Name: M76USB Bluetooth Device Driver Description: M76USB Bluetooth Device Driver Class Guid: {d2de069d-7286-420b-baf8-225d700ce748} Manufacturer: MediaTek Technology Corp. Service: m76usb Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31) Resolution: Update the driver ==================== Event log errors: ========================= Application errors: ================== Error: (04/05/2016 09:01:29 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: CompatTelRunner.exe, version: 10.0.10586.0, time stamp: 0x5632d82f Faulting module name: SafeGuard64.dll_unloaded, version: 2.2.0.40, time stamp: 0x5683828f Exception code: 0xc0000005 Fault offset: 0x000000000005827b Faulting process id: 0xaf0 Faulting application start time: 0xCompatTelRunner.exe0 Faulting application path: CompatTelRunner.exe1 Faulting module path: CompatTelRunner.exe2 Report Id: CompatTelRunner.exe3 Faulting package full name: CompatTelRunner.exe4 Faulting package-relative application ID: CompatTelRunner.exe5 Error: (04/05/2016 08:58:37 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: svchost.exe_DiagTrack, version: 10.0.10586.0, time stamp: 0x5632d7ba Faulting module name: SafeGuard64.dll_unloaded, version: 2.2.0.40, time stamp: 0x5683828f Exception code: 0xc0000005 Fault offset: 0x000000000005827b Faulting process id: 0x62c Faulting application start time: 0xsvchost.exe_DiagTrack0 Faulting application path: svchost.exe_DiagTrack1 Faulting module path: svchost.exe_DiagTrack2 Report Id: svchost.exe_DiagTrack3 Faulting package full name: svchost.exe_DiagTrack4 Faulting package-relative application ID: svchost.exe_DiagTrack5 Error: (04/05/2016 08:56:23 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: svchost.exe_DiagTrack, version: 10.0.10586.0, time stamp: 0x5632d7ba Faulting module name: SafeGuard64.dll_unloaded, version: 2.2.0.40, time stamp: 0x5683828f Exception code: 0xc0000005 Fault offset: 0x000000000005827b Faulting process id: 0xe6c Faulting application start time: 0xsvchost.exe_DiagTrack0 Faulting application path: svchost.exe_DiagTrack1 Faulting module path: svchost.exe_DiagTrack2 Report Id: svchost.exe_DiagTrack3 Faulting package full name: svchost.exe_DiagTrack4 Faulting package-relative application ID: svchost.exe_DiagTrack5 Error: (04/05/2016 08:54:41 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: svchost.exe_DiagTrack, version: 10.0.10586.0, time stamp: 0x5632d7ba Faulting module name: SafeGuard64.dll_unloaded, version: 2.2.0.40, time stamp: 0x5683828f Exception code: 0xc0000005 Fault offset: 0x000000000005827b Faulting process id: 0x7fc Faulting application start time: 0xsvchost.exe_DiagTrack0 Faulting application path: svchost.exe_DiagTrack1 Faulting module path: svchost.exe_DiagTrack2 Report Id: svchost.exe_DiagTrack3 Faulting package full name: svchost.exe_DiagTrack4 Faulting package-relative application ID: svchost.exe_DiagTrack5 Error: (04/05/2016 08:43:47 PM) (Source: Microsoft-Windows-RestartManager) (EventID: 10007) (User: brennaman) Description: Application or service 'AMD FUEL Service' could not be restarted. Error: (04/05/2016 08:28:50 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: svchost.exe_DiagTrack, version: 10.0.10586.0, time stamp: 0x5632d7ba Faulting module name: SafeGuard64.dll_unloaded, version: 2.2.0.40, time stamp: 0x5683828f Exception code: 0xc0000005 Fault offset: 0x000000000005827b Faulting process id: 0xaf4 Faulting application start time: 0xsvchost.exe_DiagTrack0 Faulting application path: svchost.exe_DiagTrack1 Faulting module path: svchost.exe_DiagTrack2 Report Id: svchost.exe_DiagTrack3 Faulting package full name: svchost.exe_DiagTrack4 Faulting package-relative application ID: svchost.exe_DiagTrack5 Error: (04/05/2016 08:27:55 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: taskhostw.exe, version: 10.0.10586.0, time stamp: 0x5632d756 Faulting module name: ntdll.dll, version: 10.0.10586.122, time stamp: 0x56cbf9dd Exception code: 0xc0000005 Fault offset: 0x00000000000231f7 Faulting process id: 0x1568 Faulting application start time: 0xtaskhostw.exe0 Faulting application path: taskhostw.exe1 Faulting module path: taskhostw.exe2 Report Id: taskhostw.exe3 Faulting package full name: taskhostw.exe4 Faulting package-relative application ID: taskhostw.exe5 Error: (04/05/2016 08:25:43 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: svchost.exe_DiagTrack, version: 10.0.10586.0, time stamp: 0x5632d7ba Faulting module name: SafeGuard64.dll_unloaded, version: 2.2.0.40, time stamp: 0x5683828f Exception code: 0xc0000005 Fault offset: 0x000000000005827b Faulting process id: 0x17dc Faulting application start time: 0xsvchost.exe_DiagTrack0 Faulting application path: svchost.exe_DiagTrack1 Faulting module path: svchost.exe_DiagTrack2 Report Id: svchost.exe_DiagTrack3 Faulting package full name: svchost.exe_DiagTrack4 Faulting package-relative application ID: svchost.exe_DiagTrack5 Error: (04/05/2016 08:23:51 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: svchost.exe_DiagTrack, version: 10.0.10586.0, time stamp: 0x5632d7ba Faulting module name: SafeGuard64.dll_unloaded, version: 2.2.0.40, time stamp: 0x5683828f Exception code: 0xc0000005 Fault offset: 0x000000000005827b Faulting process id: 0x7b0 Faulting application start time: 0xsvchost.exe_DiagTrack0 Faulting application path: svchost.exe_DiagTrack1 Faulting module path: svchost.exe_DiagTrack2 Report Id: svchost.exe_DiagTrack3 Faulting package full name: svchost.exe_DiagTrack4 Faulting package-relative application ID: svchost.exe_DiagTrack5 Error: (04/05/2016 08:22:28 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: SkypeUpdateEx.exe, version: 2000.0.0.106, time stamp: 0x56ebc18a Faulting module name: SafeGuard32.dll_unloaded, version: 2.2.0.40, time stamp: 0x568382a8 Exception code: 0xc00001a5 Fault offset: 0x001442c3 Faulting process id: 0x894 Faulting application start time: 0xSkypeUpdateEx.exe0 Faulting application path: SkypeUpdateEx.exe1 Faulting module path: SkypeUpdateEx.exe2 Report Id: SkypeUpdateEx.exe3 Faulting package full name: SkypeUpdateEx.exe4 Faulting package-relative application ID: SkypeUpdateEx.exe5 System errors: ============= Error: (04/06/2016 04:38:05 PM) (Source: DCOM) (EventID: 10016) (User: brennaman) Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}brennamanbrennamanS-1-5-21-3610044688-3067938498-1592336940-1001LocalHost (Using LRPC)Microsoft.Windows.FeatureOnDemand.InsiderHub_10.0.10586.0_neutral_neutral_cw5n1h2txyewyS-1-15-2-4016783169-893401051-2237370320-274899566-412088533-2398988950-2155762795 Error: (04/06/2016 04:05:38 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: application-specificLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)UnavailableUnavailable Error: (04/06/2016 05:25:14 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: application-specificLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)UnavailableUnavailable Error: (04/05/2016 08:58:37 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The Connected User Experiences and Telemetry service terminated unexpectedly. It has done this 3 time(s). Error: (04/05/2016 08:56:23 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The Connected User Experiences and Telemetry service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service. Error: (04/05/2016 08:54:43 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The Connected User Experiences and Telemetry service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service. Error: (04/05/2016 08:52:02 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The Google Update Service (gupdate) service failed to start due to the following error: %%1053 Error: (04/05/2016 08:52:02 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: A timeout was reached (30000 milliseconds) while waiting for the gupdate service to connect. Error: (04/05/2016 08:48:40 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The User Data Access_36082 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service. Error: (04/05/2016 08:48:40 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The User Data Storage_36082 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service. CodeIntegrity: =================================== Date: 2016-04-05 20:26:09.088 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-04-05 19:52:51.556 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\ProgramData\System32\SafeGuard64.dll that did not meet the security requirements for Shared Sections. Date: 2016-04-05 19:52:51.556 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\ProgramData\System32\SafeGuard64.dll that did not meet the security requirements for Shared Sections. Date: 2016-04-05 16:32:36.085 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\ProgramData\System32\SafeGuard64.dll that did not meet the security requirements for Shared Sections. Date: 2016-04-05 16:32:36.084 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\ProgramData\System32\SafeGuard64.dll that did not meet the security requirements for Shared Sections. Date: 2016-03-26 11:19:28.515 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\ProgramData\System32\SafeGuard64.dll that did not meet the security requirements for Shared Sections. Date: 2016-03-26 11:19:28.515 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\ProgramData\System32\SafeGuard64.dll that did not meet the security requirements for Shared Sections. Date: 2016-03-26 10:54:42.647 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\ProgramData\System32\SafeGuard64.dll that did not meet the security requirements for Shared Sections. Date: 2016-03-26 10:54:42.647 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\ProgramData\System32\SafeGuard64.dll that did not meet the security requirements for Shared Sections. Date: 2016-03-25 19:53:21.193 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. ==================== Memory info =========================== Processor: AMD A10-7400P Radeon R6, 10 Compute Cores 4C+6G Percentage of memory in use: 25% Total physical RAM: 7114.52 MB Available physical RAM: 5282.37 MB Total Virtual: 8266.52 MB Available Virtual: 6464.41 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:915.4 GB) (Free:660.28 GB) NTFS ==>[system with boot components (obtained from drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 931.5 GB) (Disk ID: E9A24556) Partition: GPT. ==================== End of Addition.txt ============================