Additional scan result of Farbar Recovery Scan Tool (x64) Version: 12-08-2020 Ran by User (18-08-2020 12:47:13) Running from C:\Users\User\Desktop Windows 10 Pro Version 2004 19041.450 (X64) (2020-08-13 08:24:41) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-1315945748-2372567203-217578743-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-1315945748-2372567203-217578743-503 - Limited - Disabled) Guest (S-1-5-21-1315945748-2372567203-217578743-501 - Limited - Disabled) User (S-1-5-21-1315945748-2372567203-217578743-1001 - Administrator - Enabled) => C:\Users\User WDAGUtilityAccount (S-1-5-21-1315945748-2372567203-217578743-504 - Limited - Disabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 20.012.20041 - Adobe Systems Incorporated) Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) Blitz 1.11.8 (HKU\S-1-5-21-1315945748-2372567203-217578743-1001\...\153f8ce0-b97a-575b-ba12-4ff8b1481894) (Version: 1.11.8 - Blitz, Inc.) CCleaner (HKLM\...\CCleaner) (Version: 5.63 - Piriform) Discord (HKU\S-1-5-21-1315945748-2372567203-217578743-1001\...\Discord) (Version: 0.0.307 - Discord Inc.) DisplayDriverAnalyzer (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_DisplayDriverAnalyzer) (Version: 391.35 - NVIDIA Corporation) Hidden Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden Google Chrome (HKLM-x32\...\Google Chrome) (Version: 84.0.4147.125 - Google LLC) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.451 - Google LLC) Hidden Intel Driver && Support Assistant (HKLM-x32\...\{3EAAD5EA-1D87-442D-8426-FD4FCE62119D}) (Version: 19.12.50.5 - Intel) Hidden Intel(R) Computing Improvement Program (HKLM\...\{D40D4164-EEDB-4F0F-85C6-2058A9E34CC7}) (Version: 2.4.04370 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 26.20.100.6890 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 16.8.2.1002 - Intel Corporation) Intel® Driver & Support Assistant (HKLM-x32\...\{8d174f37-ea1a-4e4d-be82-c10521a3c687}) (Version: 19.12.50.5 - Intel) Java 8 Update 261 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180261F0}) (Version: 8.0.2610.12 - Oracle Corporation) Kaspersky Secure Connection (HKLM-x32\...\{145AE349-477A-45E5-A57C-5F5BF2BB5775}) (Version: 20.0.14.1085 - Kaspersky) Hidden Kaspersky Secure Connection (HKLM-x32\...\InstallWIX_{145AE349-477A-45E5-A57C-5F5BF2BB5775}) (Version: 20.0.14.1085 - Kaspersky) Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden League of Legends (HKU\S-1-5-21-1315945748-2372567203-217578743-1001\...\Riot Game league_of_legends.live) (Version: - Riot Games, Inc) Legends of Runeterra (HKU\S-1-5-21-1315945748-2372567203-217578743-1001\...\Riot Game bacon.live) (Version: - Riot Games, Inc) Lightshot-5.5.0.7 (HKLM-x32\...\{30A5B3C9-2084-4063-A32A-628A98DE512B}_is1) (Version: 5.5.0.7 - Skillbrains) Malwarebytes version 4.1.2.73 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.1.2.73 - Malwarebytes) Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 84.0.522.59 - Microsoft Corporation) Microsoft Edge Update (HKLM-x32\...\Microsoft Edge Update) (Version: 1.3.133.5 - ) Microsoft Office Professional Plus 2016 (HKLM-x32\...\Office16.PROPLUS) (Version: 16.0.4266.1001 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-1315945748-2372567203-217578743-1001\...\OneDriveSetup.exe) (Version: 20.124.0621.0006 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.24.28127 (HKLM-x32\...\{282975d8-55fe-4991-bbbb-06a72581ce58}) (Version: 14.24.28127.4 - Microsoft Corporation) Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.24.28127 (HKLM-x32\...\{e31cb1a4-76b5-46a5-a084-3fa419e82201}) (Version: 14.24.28127.4 - Microsoft Corporation) Microsoft Visual Studio Code (HKLM-x32\...\{F8A2A208-72B3-4D61-95FC-8A65D340689B}_is1) (Version: 1.7.1 - Microsoft Corporation) NVIDIA תכנת PhysX מערכת 9.17.0524 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.17.0524 - NVIDIA Corporation) Outils de vérification linguistique 2016 de Microsoft Office - Français (HKLM-x32\...\{90160000-001F-040C-0000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden PowerISO (HKLM-x32\...\PowerISO) (Version: 6.8 - Power Software Ltd) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8569 - Realtek Semiconductor Corp.) Riot Vanguard (HKLM\...\Riot Vanguard) (Version: - Riot Games, Inc.) Spotify (HKU\S-1-5-21-1315945748-2372567203-217578743-1001\...\Spotify) (Version: 1.1.39.612.g1e7e78a4 - Spotify AB) StarCraft II (HKLM-x32\...\StarCraft II) (Version: - Blizzard Entertainment) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) Ubisoft Game Launcher (HKLM-x32\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT) Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{16AD6161-2E47-4BF1-AA77-0946EFE93E08}) (Version: 2.61.0.0 - Microsoft Corporation) VALORANT (HKU\S-1-5-21-1315945748-2372567203-217578743-1001\...\Riot Game valorant.live) (Version: - Riot Games, Inc) VMware Horizon Client (HKLM\...\{CD5FD442-ED2C-4BE0-8D97-A4705121898F}) (Version: 5.4.0.10892 - VMware, Inc.) Hidden VMware Horizon Client (HKLM-x32\...\{85486250-85ab-4720-a412-cdc3c82a2ce9}) (Version: 5.4.0.10892 - VMware, Inc.) VMware Horizon HTML5 Multimedia Redirection Client (HKLM\...\{2DF351BE-C14C-4B0F-BF7D-3A396E4B30D7}) (Version: 7.12.0 - VMware, Inc.) Hidden VMware Horizon Media Engine 11.0.0.613 (64-bit) (HKLM\...\{3747D742-8099-43C1-AEB5-EBC516D062A6}) (Version: 11.0.0.613 - VMware, Inc.) Hidden VMware Horizon Media Redirection for Microsoft Teams (HKLM\...\{7B2A57F9-9A4C-4120-B04C-D747370DCBC6}) (Version: 7.12.0 - VMware, Inc.) Hidden Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1) (Version: 1.0.65.1 - LunarG, Inc.) Hidden Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1-2) (Version: 1.0.65.1 - LunarG, Inc.) Hidden WinRAR 5.21 (64-סיביות) (HKLM\...\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH) Zoom (HKU\S-1-5-21-1315945748-2372567203-217578743-1001\...\ZoomUMX) (Version: 5.0 - Zoom Video Communications, Inc.) Средства проверки правописания Microsoft Office 2016 — русский (HKLM-x32\...\{90160000-001F-0419-0000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden כלי ההגהה של Microsoft Office 2016 - עברית (HKLM-x32\...\{90160000-001F-040D-0000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden לוח הבקרה של NVIDIA 391.35 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel) (Version: 391.35 - NVIDIA Corporation) Hidden עדכוני NVIDIA 10.4.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 10.4.0 - NVIDIA Corporation) Packages: ========= Autodesk SketchBook -> C:\Program Files\WindowsApps\89006A2E.AutodeskSketchBook_5.1.0.0_x64__tf1gferkr813w [2019-11-06] (Autodesk Inc.) HyperX NGENUITY -> C:\Program Files\WindowsApps\33C30B79.HyperXNGenuity_5.1.41.0_x64__0a78dr3hq0pvt [2020-08-14] (HyperX Gaming) [Startup Task] Intel® Graphics Command Center -> C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.2731.0_x64__8j3eq9eme6ctt [2020-06-11] (INTEL CORP) [Startup Task] Intel® Graphics Control Panel -> C:\Program Files\WindowsApps\AppUp.IntelGraphicsControlPanel_3.3.0.0_x64__8j3eq9eme6ctt [2020-02-18] (INTEL CORP) Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1808.3.0_x64__8wekyb3d8bbwe [2020-08-13] (Microsoft Corporation) [MS Ad] Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-01-18] (Microsoft Corporation) [MS Ad] Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-01-18] (Microsoft Corporation) [MS Ad] Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.7.8042.0_x64__8wekyb3d8bbwe [2020-08-07] (Microsoft Studios) [MS Ad] MSN Money -> C:\Program Files\WindowsApps\Microsoft.BingFinance_4.36.20714.0_x64__8wekyb3d8bbwe [2020-03-25] (Microsoft Corporation) [MS Ad] MSN Sports -> C:\Program Files\WindowsApps\Microsoft.BingSports_4.36.20714.0_x64__8wekyb3d8bbwe [2020-03-25] (Microsoft Corporation) [MS Ad] MSN Weather -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.36.20714.0_x64__8wekyb3d8bbwe [2020-03-25] (Microsoft Corporation) [MS Ad] Photos Add-on -> C:\Program Files\WindowsApps\Microsoft.Windows.Photos.DLC.Main_2017.39121.36610.0_x64__8wekyb3d8bbwe [2019-08-01] (Microsoft Corporation) Photos Media Engine Add-on -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2019-09-11] (Microsoft Corporation) Reader Notification Client -> C:\Program Files\WindowsApps\ReaderNotificationClient_1.0.4.0_x86__e1rzdqpraam7r [2020-02-26] (Adobe Systems Incorporated) Twitter -> C:\Program Files\WindowsApps\9E2F88E3.Twitter_6.1.4.1000_neutral__wgeqdkkx372wm [2018-09-09] (Twitter Inc.) ==================== Custom CLSID (Whitelisted): ============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-1315945748-2372567203-217578743-1001_Classes\CLSID\{233525e0-5434-46ef-b464-fd7e45e2e145}\localserver32 -> C:\Program Files (x86)\Intel\Driver and Support Assistant\DSATray.exe (IDSA Production signing key -> Intel) ShellIconOverlayIdentifiers: [ MEGA (Pending)] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => -> No File ShellIconOverlayIdentifiers: [ MEGA (Synced)] -> {05B38830-F4E9-4329-978B-1DD28605D202} => -> No File ShellIconOverlayIdentifiers: [ MEGA (Syncing)] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => -> No File ShellIconOverlayIdentifiers-x32: [ MEGA (Pending)] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => -> No File ShellIconOverlayIdentifiers-x32: [ MEGA (Synced)] -> {05B38830-F4E9-4329-978B-1DD28605D202} => -> No File ShellIconOverlayIdentifiers-x32: [ MEGA (Syncing)] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => -> No File ContextMenuHandlers1: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => -> No File ContextMenuHandlers1: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => C:\Program Files (x86)\PowerISO\PWRISOSH.DLL [2017-02-02] (Power Software Limited -> Power Software Ltd) ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2015-02-15] (win.rar GmbH -> Alexander Roshal) ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2015-02-15] (win.rar GmbH -> Alexander Roshal) ContextMenuHandlers2: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => -> No File ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2020-01-01] (Malwarebytes Corporation -> Malwarebytes) ContextMenuHandlers3: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => -> No File ContextMenuHandlers4: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => -> No File ContextMenuHandlers4: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => C:\Program Files (x86)\PowerISO\PWRISOSH.DLL [2017-02-02] (Power Software Limited -> Power Software Ltd) ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2018-03-24] (NVIDIA Corporation -> NVIDIA Corporation) ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2020-01-01] (Malwarebytes Corporation -> Malwarebytes) ContextMenuHandlers6: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => C:\Program Files (x86)\PowerISO\PWRISOSH.DLL [2017-02-02] (Power Software Limited -> Power Software Ltd) ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2015-02-15] (win.rar GmbH -> Alexander Roshal) ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2015-02-15] (win.rar GmbH -> Alexander Roshal) ==================== Codecs (Whitelisted) ==================== ==================== Shortcuts & WMI ======================== ==================== Loaded Modules (Whitelisted) ============= ==================== Alternate Data Streams (Whitelisted) ======== (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\Users\Public\AppData:CSM [468] AlternateDataStreams: C:\Users\User\Downloads\JavaSetup8u261.exe:SmartScreen [7] ==================== Safe Mode (Whitelisted) ================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Association (Whitelisted) ================= ==================== Internet Explorer trusted/restricted ========== (If an entry is included in the fixlist, it will be removed from the registry.) IE trusted site: HKU\S-1-5-21-1315945748-2372567203-217578743-1001\...\hola.org -> hxxp://hola.org ==================== Hosts content: ========================= (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2015-10-30 10:24 - 2020-04-02 10:58 - 000000886 _____ C:\WINDOWS\system32\drivers\etc\hosts 127.0.0.1 view-localhost # view localhost server ==================== Other Areas =========================== (Currently there is no automatic fix for this section.) HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\ProgramData\Oracle\Java\javapath;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\WINDOWS\System32\OpenSSH\;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\ HKU\S-1-5-21-1315945748-2372567203-217578743-1001\Control Panel\Desktop\\Wallpaper -> c:\windows\web\wallpaper\theme1\img1.jpg DNS Servers: 8.8.8.8 - 8.8.4.4 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Warn) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == (If an entry is included in the fixlist, it will be removed.) MSCONFIG\Services: AdobeARMservice => 2 MSCONFIG\Services: BEService => 3 MSCONFIG\Services: cphs => 3 MSCONFIG\Services: cplspcon => 2 MSCONFIG\Services: DSAService => 2 MSCONFIG\Services: DSAUpdateService => 3 MSCONFIG\Services: EasyAntiCheat => 3 MSCONFIG\Services: GoogleChromeElevationService => 3 MSCONFIG\Services: gupdate => 2 MSCONFIG\Services: gupdatem => 3 MSCONFIG\Services: HiPatchService => 2 MSCONFIG\Services: IAStorDataMgrSvc => 2 MSCONFIG\Services: ICEsoundService => 2 MSCONFIG\Services: igfxCUIService2.0.0.0 => 2 MSCONFIG\Services: Intel(R) SUR QC SAM => 3 MSCONFIG\Services: LMIGuardianSvc => 2 MSCONFIG\Services: NSM => 2 MSCONFIG\Services: NVDisplay.ContainerLocalSystem => 2 MSCONFIG\Services: qengine => 2 MSCONFIG\Services: qupdate => 2 MSCONFIG\Services: SkypeUpdate => 2 MSCONFIG\Services: Steam Client Service => 3 MSCONFIG\Services: TampMon => 2 MSCONFIG\Services: Update service => 2 HKLM\...\StartupApproved\StartupFolder: => "AnyDesk.lnk" HKLM\...\StartupApproved\StartupFolder: => "McAfee Security Scan Plus.lnk" HKLM\...\StartupApproved\Run: => "SecurityHealth" HKLM\...\StartupApproved\Run: => "NvBackend" HKLM\...\StartupApproved\Run: => "RTHDVCPL" HKLM\...\StartupApproved\Run: => "IAStorIcon" HKLM\...\StartupApproved\Run: => "Riot Vanguard" HKLM\...\StartupApproved\Run32: => "Lightshot" HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched" HKLM\...\StartupApproved\Run32: => "Intel Driver & Support Assistant" HKU\S-1-5-21-1315945748-2372567203-217578743-1001\...\StartupApproved\StartupFolder: => "Nexon Launcher.lnk" HKU\S-1-5-21-1315945748-2372567203-217578743-1001\...\StartupApproved\StartupFolder: => "Twitch.lnk" HKU\S-1-5-21-1315945748-2372567203-217578743-1001\...\StartupApproved\Run: => "Discord" HKU\S-1-5-21-1315945748-2372567203-217578743-1001\...\StartupApproved\Run: => "OneDrive" HKU\S-1-5-21-1315945748-2372567203-217578743-1001\...\StartupApproved\Run: => "Steam" HKU\S-1-5-21-1315945748-2372567203-217578743-1001\...\StartupApproved\Run: => "EpicGamesLauncher" HKU\S-1-5-21-1315945748-2372567203-217578743-1001\...\StartupApproved\Run: => "GoogleChromeAutoLaunch_BCEA24321E5E4F1401136BBEDFB545FE" HKU\S-1-5-21-1315945748-2372567203-217578743-1001\...\StartupApproved\Run: => "CCleaner Smart Cleaning" HKU\S-1-5-21-1315945748-2372567203-217578743-1001\...\StartupApproved\Run: => "Spotify" HKU\S-1-5-21-1315945748-2372567203-217578743-1001\...\StartupApproved\Run: => "Adobe Reader Synchronizer" HKU\S-1-5-21-1315945748-2372567203-217578743-1001\...\StartupApproved\Run: => "com.blitz.app" ==================== FirewallRules (Whitelisted) ================ (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{1908346A-A46E-46D8-AE6D-874C86CBB3FB}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) FirewallRules: [{732889E1-6869-4868-884B-45CD2711A663}] => (Block) C:\program files (x86)\starcraft ii\versions\base81102\sc2_x64.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment, Inc.) FirewallRules: [{FB12677B-A297-4F15-B015-01C829EC2B16}] => (Block) C:\program files (x86)\starcraft ii\versions\base81102\sc2_x64.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment, Inc.) FirewallRules: [UDP Query User{A59BE1DA-78F4-44DE-BCE2-B7DA612B5610}C:\program files (x86)\starcraft ii\versions\base81102\sc2_x64.exe] => (Allow) C:\program files (x86)\starcraft ii\versions\base81102\sc2_x64.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment, Inc.) FirewallRules: [TCP Query User{ED32A5ED-64FD-4771-8105-4B6B14F81708}C:\program files (x86)\starcraft ii\versions\base81102\sc2_x64.exe] => (Allow) C:\program files (x86)\starcraft ii\versions\base81102\sc2_x64.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment, Inc.) FirewallRules: [UDP Query User{7547CF66-BCCC-4D31-822B-34A5C9AAFA7E}C:\program files (x86)\starcraft ii\versions\base81009\sc2_x64.exe] => (Allow) C:\program files (x86)\starcraft ii\versions\base81009\sc2_x64.exe => No File FirewallRules: [TCP Query User{5CC6AFC0-567F-4A7D-B5D9-E3F2423198BC}C:\program files (x86)\starcraft ii\versions\base81009\sc2_x64.exe] => (Allow) C:\program files (x86)\starcraft ii\versions\base81009\sc2_x64.exe => No File FirewallRules: [{1247570F-6596-4257-9247-BA6188FA8861}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\COMBAT ARMS THE CLASSIC\NMService.exe => No File FirewallRules: [{7EDC78A0-8274-4A32-BC76-F491B4692292}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\COMBAT ARMS THE CLASSIC\NMService.exe => No File FirewallRules: [UDP Query User{BAFB26A9-D2CF-4936-81A3-3601885120F1}C:\program files (x86)\steam\steamapps\common\combat arms the classic\voicechat.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\combat arms the classic\voicechat.exe => No File FirewallRules: [TCP Query User{7C03B198-9DB3-4A79-B7F1-A61B93529A01}C:\program files (x86)\steam\steamapps\common\combat arms the classic\voicechat.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\combat arms the classic\voicechat.exe => No File FirewallRules: [{7AFE7046-297F-44D1-BEDF-542AC50A0D4D}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.61.100.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{480750CE-0B84-42A8-8ABC-743059AF44D1}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.61.100.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{D6988FF6-5401-4E82-946D-8065BF51AB6D}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.61.100.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{B8943FC9-117C-49F2-BAE5-A1674657BA82}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.61.100.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{88F806B1-2D7C-47BC-A0C2-27DDDCF05FB6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\GarrysMod\hl2.exe () [File not signed] FirewallRules: [{9DDDA189-47E4-46D5-9898-C01A1A7ED919}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\GarrysMod\hl2.exe () [File not signed] FirewallRules: [UDP Query User{EA3D6D08-C84E-43D7-9A35-40592EFE944F}C:\users\user\appdata\local\programs\blitz\blitz.exe] => (Allow) C:\users\user\appdata\local\programs\blitz\blitz.exe (Swift Media Entertainment, Inc. -> Blitz, Inc.) FirewallRules: [TCP Query User{71BDC8B1-1C48-4E5C-9F9B-1CD5E03AC94F}C:\users\user\appdata\local\programs\blitz\blitz.exe] => (Allow) C:\users\user\appdata\local\programs\blitz\blitz.exe (Swift Media Entertainment, Inc. -> Blitz, Inc.) FirewallRules: [UDP Query User{EBBB9094-BF84-4978-8B36-2A771339E6ED}C:\program files (x86)\starcraft ii\support64\sc2editor_x64.exe] => (Allow) C:\program files (x86)\starcraft ii\support64\sc2editor_x64.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment, Inc.) FirewallRules: [TCP Query User{490887AC-AC4D-42F8-B2A7-52FCCAD4F1EF}C:\program files (x86)\starcraft ii\support64\sc2editor_x64.exe] => (Allow) C:\program files (x86)\starcraft ii\support64\sc2editor_x64.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment, Inc.) FirewallRules: [UDP Query User{E1DF57E1-A9D5-405F-B7E0-BFE1973FDD0A}C:\program files (x86)\starcraft ii\versions\base80188\sc2_x64.exe] => (Allow) C:\program files (x86)\starcraft ii\versions\base80188\sc2_x64.exe => No File FirewallRules: [TCP Query User{21AB142A-9469-418C-A130-F1C1D4734899}C:\program files (x86)\starcraft ii\versions\base80188\sc2_x64.exe] => (Allow) C:\program files (x86)\starcraft ii\versions\base80188\sc2_x64.exe => No File FirewallRules: [{85924650-C306-4B31-8402-B3BAB8576954}] => (Allow) C:\Users\User\AppData\Roaming\Zoom\bin\Zoom.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.) FirewallRules: [UDP Query User{0A42CB48-C3EA-4EAE-9CF1-8548798D02AB}C:\users\user\appdata\roaming\ftba\bin\runtime\jre-x64\bin\javaw.exe] => (Allow) C:\users\user\appdata\roaming\ftba\bin\runtime\jre-x64\bin\javaw.exe FirewallRules: [TCP Query User{A43EF936-C6ED-4328-8EDD-52B7DC0FCBAC}C:\users\user\appdata\roaming\ftba\bin\runtime\jre-x64\bin\javaw.exe] => (Allow) C:\users\user\appdata\roaming\ftba\bin\runtime\jre-x64\bin\javaw.exe FirewallRules: [{8083112F-7559-4A1B-94F7-CA8E4017D5D2}] => (Allow) C:\Program Files (x86)\VMware\VMware Horizon View Client\x64\vmware-remotemks.exe (VMware, Inc. -> VMware, Inc.) FirewallRules: [{94609993-706F-4566-AE35-E6B1FE3A1951}] => (Allow) C:\Program Files (x86)\VMware\VMware Horizon View Client\x64\vmware-remotemks.exe (VMware, Inc. -> VMware, Inc.) FirewallRules: [{43EBE378-6644-4391-8727-4D878C813C3F}] => (Allow) C:\Program Files (x86)\VMware\VMware Horizon View Client\x64\vmware-remotemks.exe (VMware, Inc. -> VMware, Inc.) FirewallRules: [{3C106599-49BF-443D-9887-79ED08136B89}] => (Allow) C:\Program Files (x86)\VMware\VMware Horizon View Client\x64\vmware-remotemks.exe (VMware, Inc. -> VMware, Inc.) FirewallRules: [{F26D5ED6-6B7F-4F1F-9899-189E9288857D}] => (Allow) C:\Program Files (x86)\VMware\VMware Horizon View Client\x64\vmware-remotemks.exe (VMware, Inc. -> VMware, Inc.) FirewallRules: [{0B4E506C-4179-4723-9B43-7D313B3BFA12}] => (Allow) C:\Program Files (x86)\VMware\VMware Horizon View Client\x64\vmware-remotemks.exe (VMware, Inc. -> VMware, Inc.) FirewallRules: [UDP Query User{5BDB2534-1DDE-44A3-A46C-46C1F74DDF4A}C:\users\user\appdata\local\deskforcephone\deskforcephone.exe] => (Allow) C:\users\user\appdata\local\deskforcephone\deskforcephone.exe => No File FirewallRules: [TCP Query User{DB0E7C88-58E1-445F-B3E2-E74D0F13ECF2}C:\users\user\appdata\local\deskforcephone\deskforcephone.exe] => (Allow) C:\users\user\appdata\local\deskforcephone\deskforcephone.exe => No File FirewallRules: [{226F2940-E05F-4ADC-B15F-7CE6DFBA47B4}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation) FirewallRules: [{A58CF791-9D82-4159-B4E7-9E0F0F04B597}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation) FirewallRules: [{77335E48-D368-4F67-A168-0BD9136D13B7}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe => No File FirewallRules: [{320DB5C1-1AB3-476A-9C5A-075E9D13E8E2}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe => No File FirewallRules: [{9A3C3A1E-FDDA-4BE0-89AD-766C7C06ADAF}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe (Even Balance, Inc. -> ) FirewallRules: [{938E5F78-6127-4AB0-A6CD-B8E96E385462}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe (Even Balance, Inc. -> ) FirewallRules: [{35D974F3-0E4D-4C84-B6E1-3AA373CA3E38}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe (Even Balance, Inc. -> ) FirewallRules: [{3F644E87-5AE0-4530-83E0-63F515BAB42A}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe (Even Balance, Inc. -> ) FirewallRules: [{4D4D1B48-283A-46A0-BEB7-3750ECA1CD13}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation) FirewallRules: [{42C2F908-B1B0-4E61-95FA-997F5F712613}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation) FirewallRules: [{438CD202-A3D9-4283-A745-797C2465E2BA}] => (Block) C:\Riot Games\League of Legends\LeagueClient.exe (Riot Games, Inc. -> Riot Games, Inc.) FirewallRules: [{5C99BE44-7452-44EA-9FEF-3781F631D34F}] => (Allow) C:\Users\User\AppData\Roaming\Zoom\bin\Zoom.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.) FirewallRules: [UDP Query User{31E3DF1B-C0E2-43C5-8C5E-8D2C13AD393B}C:\users\user\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\user\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [TCP Query User{ED767F59-0277-4085-AE04-8825EF0AF940}C:\users\user\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\user\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{3811C7A2-F7BC-47E8-9F75-F74405E5C4EE}] => (Allow) C:\Riot Games\League of Legends\LeagueClient.exe (Riot Games, Inc. -> Riot Games, Inc.) FirewallRules: [{05C11E41-95E3-458B-83B3-D9DE9D5F69A4}] => (Allow) C:\Riot Games\League of Legends\LeagueClient.exe (Riot Games, Inc. -> Riot Games, Inc.) FirewallRules: [{DCE8BDB0-A705-439E-8DD1-2BB1C2B45DA1}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) FirewallRules: [{3559D9B6-EB91-40B6-9FB2-7880E385C904}] => (Allow) C:\Riot Games\League of Legends\LeagueClient.exe (Riot Games, Inc. -> Riot Games, Inc.) FirewallRules: [{F9D7584F-A2B3-46FD-95AE-D73C40B9A96D}] => (Allow) C:\Riot Games\League of Legends\LeagueClient.exe (Riot Games, Inc. -> Riot Games, Inc.) FirewallRules: [TCP Query User{475F491E-7D42-456D-BC69-03602616C628}C:\riot games\league of legends\game\league of legends.exe] => (Allow) C:\riot games\league of legends\game\league of legends.exe (Riot Games, Inc. -> Riot Games, Inc.) FirewallRules: [UDP Query User{3BD653B8-F76C-4243-B70F-09602A44F69A}C:\riot games\league of legends\game\league of legends.exe] => (Allow) C:\riot games\league of legends\game\league of legends.exe (Riot Games, Inc. -> Riot Games, Inc.) FirewallRules: [{DA24ED28-2E6D-44E0-B6AE-20C27A00DF69}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe => No File FirewallRules: [{3CE818A5-47CE-4DAD-A84C-B8A5EAC1A07C}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe => No File FirewallRules: [{F075CBF0-F365-4B8A-A093-D3969DB6F7BF}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe => No File FirewallRules: [{360AB6CD-656A-4350-8219-AB5BD060B463}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe => No File FirewallRules: [{EAB40C64-7ACF-4E62-BEF7-E2968407B23F}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe => No File FirewallRules: [{82252EBC-7521-4AAA-99E5-8FEFE6CD1F41}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe => No File ==================== Restore Points ========================= 13-08-2020 14:32:45 Windows Modules Installer ==================== Faulty Device Manager Devices ============ Name: Standard PS/2 Keyboard Description: Standard PS/2 Keyboard Class Guid: {4d36e96b-e325-11ce-bfc1-08002be10318} Manufacturer: (Standard keyboards) Service: i8042prt Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. Name: Microsoft PS/2 Mouse Description: Microsoft PS/2 Mouse Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: i8042prt Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. ==================== Event log errors: ======================== Application errors: ================== Error: (08/16/2020 01:44:01 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: ‏‏שם יישום שחלות בו תקלות: Blitz.exe, גירסה: 1.11.0.0, חותמת זמן: 0x5f2828cc שם מודול שחלות בו תקלות: CoreMessaging.dll, גירסה: 10.0.19041.423, חותמת זמן: 0xbca69586 קוד חריגה: 0xc0000602 היסט תקלה: 0x0000f662 מזהה תהליך שחלות בו תקלות: 0x1f58 שעת ההפעלה של היישום שחלות בו תקלות: 0x01d673ba0e4ac7cb נתיב היישום שחלות בו תקלות: C:\Users\User\AppData\Local\Programs\Blitz\Blitz.exe נתיב המודול שחלות בו תקלות: C:\WINDOWS\SYSTEM32\CoreMessaging.dll מזהה דוח: 3d090475-d760-42b5-ba75-160daf3cec17 שם מלא של החבילה שחלות בה תקלות: מזהה יישום יחסי לחבילה שחלות בה תקלות: Error: (08/16/2020 09:46:55 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program LeagueClientUx.exe version 10.16.330.9186 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel. Process ID: 8f0 Start Time: 01d673975ab38b8a Termination Time: 4294967295 Application Path: C:\Riot Games\League of Legends\LeagueClientUx.exe Report Id: 949e620c-e8f4-4148-a556-1dd57dd41636 Faulting package full name: Faulting package-relative application ID: Hang type: Top level window is idle Error: (08/13/2020 11:27:53 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: ‏‏שם יישום שחלות בו תקלות: igfxEM.exe, גירסה: 6.15.100.7262, חותמת זמן: 0x5d8bde80 שם מודול שחלות בו תקלות: igfxEM.exe, גירסה: 6.15.100.7262, חותמת זמן: 0x5d8bde80 קוד חריגה: 0xc0000005 היסט תקלה: 0x000000000001b66d מזהה תהליך שחלות בו תקלות: 0x15f0 שעת ההפעלה של היישום שחלות בו תקלות: 0x01d6714b54ba8614 נתיב היישום שחלות בו תקלות: C:\WINDOWS\System32\DriverStore\FileRepository\cui_dch.inf_amd64_f3a64c75ee4defb7\igfxEM.exe נתיב המודול שחלות בו תקלות: C:\WINDOWS\System32\DriverStore\FileRepository\cui_dch.inf_amd64_f3a64c75ee4defb7\igfxEM.exe מזהה דוח: f3f497bd-989e-48c4-8b18-b9125d9d97b0 שם מלא של החבילה שחלות בה תקלות: מזהה יישום יחסי לחבילה שחלות בה תקלות: Error: (08/13/2020 11:12:45 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3001) (User: NT AUTHORITY) Description: The performance counter name string value in the registry is not formatted correctly. The malformed string is 9988. The first DWORD in the Data section contains the index value to the malformed string while the second and third DWORDs in the Data section contain the last valid index values. Error: (08/13/2020 10:53:28 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 257) (User: ) Description: ‏‏שירות Cryptographic Services לא הצליח לאתחל את מסד נתוני הקטלוג. שגיאת ה- ESENT היתה: -1409. System errors: ============= Error: (08/18/2020 12:34:36 PM) (Source: Application Popup) (EventID: 56) (User: ) Description: ACPI1 Error: (08/18/2020 11:54:18 AM) (Source: Application Popup) (EventID: 56) (User: ) Description: ACPI1 Error: (08/18/2020 11:53:16 AM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY) Description: The server {924DC564-16A6-42EB-929A-9A61FA7DA06F} did not register with DCOM within the required timeout. Error: (08/18/2020 11:53:16 AM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY) Description: The server {924DC564-16A6-42EB-929A-9A61FA7DA06F} did not register with DCOM within the required timeout. Error: (08/17/2020 01:36:01 PM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY) Description: The server {924DC564-16A6-42EB-929A-9A61FA7DA06F} did not register with DCOM within the required timeout. Error: (08/17/2020 01:36:01 PM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY) Description: The server {924DC564-16A6-42EB-929A-9A61FA7DA06F} did not register with DCOM within the required timeout. Error: (08/14/2020 05:49:43 PM) (Source: DCOM) (EventID: 10000) (User: AT) Description: Unable to start a DCOM Server: {0358B920-0AC7-461F-98F4-58E32CD89148}. The error: "2147942767" Happened while starting this command: C:\WINDOWS\system32\DllHost.exe /Processid:{3EB3C877-1F16-487C-9050-104DBCD66683} Error: (08/14/2020 12:15:32 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: ‏‏המערכת הגיעה לפרק זמן קצוב (30000 אלפיות שניה) במהלך המתנה לתגובת טרנזקציה משירות igfxCUIService2.0.0.0. ==================== Memory info =========================== BIOS: American Megatrends Inc. P1.70A 07/04/2016 Motherboard: ASRock H110M-HDV Processor: Intel(R) Core(TM) i3-6100 CPU @ 3.70GHz Percentage of memory in use: 43% Total physical RAM: 8082.87 MB Available physical RAM: 4596.3 MB Total Virtual: 13458.87 MB Available Virtual: 9600 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:213.38 GB) (Free:79.12 GB) NTFS Drive d: () (Fixed) (Total:250.92 GB) (Free:250.76 GB) NTFS \\?\Volume{6cb467c9-0000-0000-0000-100000000000}\ (‏‏שמור על-ידי המערכת) (Fixed) (Total:0.49 GB) (Free:0.45 GB) NTFS \\?\Volume{6cb467c9-0000-0000-0000-e07735000000}\ () (Fixed) (Total:0.51 GB) (Free:0.08 GB) NTFS ==================== MBR & Partition Table ==================== ========================================================== Disk: 0 (MBR Code: Windows 7/8/10) (Size: 465.8 GB) (Disk ID: 6CB467C9) Partition 1: (Active) - (Size=500 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=213.4 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=525 MB) - (Type=27) Partition 4: (Not Active) - (Size=250.9 GB) - (Type=07 NTFS) ==================== End of Addition.txt =======================