Additional scan result of Farbar Recovery Scan Tool (x64) Version: 14-12-2020 Ran by vtmck (14-12-2020 16:53:15) Running from C:\Users\vtmck\OneDrive\Desktop Windows 10 Home Version 1909 18363.1256 (X64) (2020-08-25 17:43:38) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-1792065088-1724429800-3796853536-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-1792065088-1724429800-3796853536-503 - Limited - Disabled) Guest (S-1-5-21-1792065088-1724429800-3796853536-501 - Limited - Disabled) vtmck (S-1-5-21-1792065088-1724429800-3796853536-1001 - Administrator - Enabled) => C:\Users\vtmck WDAGUtilityAccount (S-1-5-21-1792065088-1724429800-3796853536-504 - Limited - Disabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Dell Digital Delivery Services (HKLM-x32\...\{CC5730C7-C867-43BD-94DA-00BB3836906F}) (Version: 4.0.52.0 - Dell Inc.) Dell Mobile Connect Drivers (HKLM\...\{1E754E2C-CF3B-42CB-B36D-D560CEA96149}) (Version: 2.0.7811 - Screenovate Technologies Ltd.) Dell Power Manager Service (HKLM\...\{18469ED8-8C36-4CF7-BD43-0FC9B1931AF8}) (Version: 3.2.0 - Dell Inc.) Dell SupportAssist (HKLM\...\{684820E8-F6AA-4162-A547-317DA6BED1FB}) (Version: 3.8.0.108 - Dell Inc.) Dell SupportAssist Remediation (HKLM\...\{8FA6BC9C-CF6A-45E7-92BD-1585DFAFB32C}) (Version: 4.4.1.9851 - Dell Inc.) Hidden Dell SupportAssist Remediation (HKLM-x32\...\{5f9ca6e9-c7d9-49c9-88fa-196d35d8eb82}) (Version: 4.4.1.9851 - Dell Inc.) Dell Update - SupportAssist Update Plugin (HKLM\...\{AADBB088-81DE-4EC8-B176-D98669BE09D4}) (Version: 4.4.1.9851 - Dell Inc.) Hidden Dell Update - SupportAssist Update Plugin (HKLM-x32\...\{31581d2d-a9e8-4f15-aa85-d6f9473b619e}) (Version: 4.4.1.9851 - Dell Inc.) Dell Update for Windows 10 (HKLM\...\{41D2D254-D869-4CD8-B440-5DF49083C4BA}) (Version: 4.0.0 - Dell, Inc.) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 87.0.4280.88 - Google LLC) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.36.51 - Google LLC) Hidden Intel(R) Chipset Device Software (HKLM-x32\...\{70281077-96c3-4f75-938c-dc4746110c00}) (Version: 10.1.17903.8106 - Intel(R) Corporation) Intel(R) Dynamic Platform and Thermal Framework (HKLM-x32\...\{654EE65D-FAA4-4EA6-8C07-DC94E6A304D4}) (Version: 8.5.10103.7263 - Intel Corporation) Intel(R) HID Event Filter (HKLM-x32\...\3FB06EEC-013D-4366-9918-71B97DFB84EB) (Version: 2.2.1.375 - Intel Corporation) Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 1910.12.0.1239 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 25.20.100.6577 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 17.2.4.1011 - Intel Corporation) Intel(R) Trusted Connect Service Client x86 (HKLM-x32\...\{C9552825-7BF2-4344-BA91-D3CD46F4C441}) (Version: 1.52.230.1 - Intel Corporation) Hidden Intel(R) Trusted Connect Services Client (HKLM-x32\...\{c6de84fd-ece7-4c2a-9f06-8cabe7ab79a0}) (Version: 1.52.230.1 - Intel Corporation) Hidden Intel® Optane™ Pinning Explorer Extensions (HKLM\...\{C81FD018-F151-460F-B4F9-0D58039503E2}) (Version: 17.2.4.9002 - Intel Corporation) Microsoft 365 - en-us (HKLM\...\O365HomePremRetail - en-us) (Version: 16.0.13426.20308 - Microsoft Corporation) Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 87.0.664.60 - Microsoft Corporation) Microsoft Edge Update (HKLM-x32\...\Microsoft Edge Update) (Version: 1.3.139.59 - ) Microsoft OneDrive (HKU\S-1-5-21-1792065088-1724429800-3796853536-1001\...\OneDriveSetup.exe) (Version: 20.201.1005.0009 - Microsoft Corporation) Microsoft Update Health Tools (HKLM\...\{0BCA8FBE-0C1C-4C65-98A3-5D34AAF41737}) (Version: 2.70.0.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation) Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.13426.20294 - Microsoft Corporation) Hidden Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.13426.20308 - Microsoft Corporation) Hidden Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0409-1000-0000000FF1CE}) (Version: 16.0.13426.20294 - Microsoft Corporation) Hidden Oracle VM VirtualBox 6.1.14 (HKLM\...\{1B1CFE9F-D421-4193-ACB8-FDE4D565C715}) (Version: 6.1.14 - Oracle Corporation) Qualcomm 11ac Wireless LAN&Bluetooth Installer (HKLM-x32\...\{E7086B15-806E-4519-A876-DBA9FDDE9A13}) (Version: 11.0.0.10494 - Qualcomm) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8642 - Realtek Semiconductor Corp.) SmartByte Drivers and Services (HKLM\...\{9668B1BB-D0FE-4C0C-800C-B1555E069A62}) (Version: 3.1.940 - Rivet Networks) VcXsrv (HKLM\...\VcXsrv) (Version: 1.20.8.1 - marha@users.sourceforge.net) Zoom (HKU\S-1-5-21-1792065088-1724429800-3796853536-1001\...\ZoomUMX) (Version: 5.4.2 (58740.1105) - Zoom Video Communications, Inc.) Packages: ========= BreeZip -> C:\Program Files\WindowsApps\3138AweZip.AweZip_1.3.18.0_x86__ffd303wmbhcjt [2020-11-21] (BreeZip) [MS Ad] Dell CinemaColor -> C:\Program Files\WindowsApps\PortraitDisplays.DellCinemaColor_2.2.22.0_x64__2dgmkzkw4h30c [2020-09-16] (Portrait Displays) Dell Customer Connect -> C:\Program Files\WindowsApps\DellInc.DellCustomerConnect_5.2.45.0_x64__htrsf667h5kn2 [2020-08-27] (Dell Inc) Dell Digital Delivery -> C:\Program Files\WindowsApps\DellInc.DellDigitalDelivery_4.0.52.0_x64__htrsf667h5kn2 [2020-08-27] (Dell Inc) Dell Mobile Connect -> C:\Program Files\WindowsApps\ScreenovateTechnologies.DellMobileConnect_3.2.9660.0_x64__0vhbc3ng4wbp0 [2020-12-09] (Screenovate Technologies) [Startup Task] Dell Power Manager -> C:\Program Files\WindowsApps\DellInc.DellPowerManager_3.7.10.0_x64__htrsf667h5kn2 [2020-10-02] (Dell Inc) Dell SupportAssist for Home PCs -> C:\Program Files\WindowsApps\DellInc.DellSupportAssistforPCs_3.8.8.0_x64__htrsf667h5kn2 [2020-12-08] (Dell Inc) Dell Update -> C:\Program Files\WindowsApps\DellInc.DellUpdate_4.0.33.0_x86__htrsf667h5kn2 [2020-12-08] (Dell Inc) Dropbox promotion -> C:\Program Files\WindowsApps\C27EB4BA.DropboxOEM_20.4.3.0_x64__xbfy0k16fey96 [2020-08-27] (Dropbox Inc.) Intel® Graphics Command Center -> C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.2970.0_x64__8j3eq9eme6ctt [2020-11-12] (INTEL CORP) [Startup Task] Intel® Graphics Control Panel -> C:\Program Files\WindowsApps\AppUp.IntelGraphicsControlPanel_3.3.0.0_x64__8j3eq9eme6ctt [2020-08-27] (INTEL CORP) Intel® Optane™ Memory and Storage Management -> C:\Program Files\WindowsApps\AppUp.IntelOptaneMemoryandStorageManagement_18.0.1017.0_x64__8j3eq9eme6ctt [2020-11-26] (INTEL CORP) LinkedIn -> C:\Program Files\WindowsApps\7EE7776C.LinkedInforWindows_2.0.1.0_neutral__w1wdnht996qgy [2019-07-19] (LinkedIn) Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2020-08-27] (Microsoft Corporation) [MS Ad] Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2020-08-27] (Microsoft Corporation) [MS Ad] Microsoft Office Outlook Desktop Integration -> C:\Program Files\WindowsApps\Microsoft.OutlookDesktopIntegrationServices_16009.11426.10000.0_x64__8wekyb3d8bbwe [2020-08-28] (Microsoft Corporation) Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.7.10142.0_x64__8wekyb3d8bbwe [2020-10-25] (Microsoft Studios) [MS Ad] Microsoft Ultimate Word Games -> C:\Program Files\WindowsApps\Microsoft.Studios.Wordament_3.8.904.0_x64__8wekyb3d8bbwe [2020-10-12] (Microsoft Studios) [MS Ad] MPEG-2 Video Extension -> C:\Program Files\WindowsApps\Microsoft.MPEG2VideoExtension_1.0.22661.0_x64__8wekyb3d8bbwe [2020-08-27] (Microsoft Corporation) My Dell -> C:\Program Files\WindowsApps\DellInc.MyDell_1.7.25.0_x64__htrsf667h5kn2 [2020-12-11] (Dell Inc) Netflix -> C:\Program Files\WindowsApps\4DF9E0F8.Netflix_6.97.752.0_x64__mcm4njqhnhss8 [2020-08-27] (Netflix, Inc.) Orange Countdown -> C:\Program Files\WindowsApps\55817AlanJulliard.OrangeCountdown_1.0.22.0_x64__vvk4t38p5d5hg [2020-12-04] (Alan Julliard) PDF Studio 2019 Viewer -> C:\Program Files\WindowsApps\QoppaSoftware.PDFStudio2019Viewer_2019.1.3.0_x64__6g7jve40hxx5w [2020-10-29] (Qoppa Software LLC) SmartByte -> C:\Program Files\WindowsApps\RivetNetworks.SmartByte_3.1.940.0_x64__rh07ty8m5nkag [2020-09-03] (Rivet Networks LLC) Translator -> C:\Program Files\WindowsApps\Microsoft.BingTranslator_5.6.0.0_x64__8wekyb3d8bbwe [2020-08-27] (Microsoft Corporation) Waves MaxxAudio Pro for Dell 2019 -> C:\Program Files\WindowsApps\WavesAudio.MaxxAudioProforDell2019_2.0.54.0_x64__fh4rh281wavaa [2020-08-27] (Waves Audio) Wordplay: Exercise your brain -> C:\Program Files\WindowsApps\828B5831.WordplayExerciseyourbrain_1.8.1001.0_x86__ytsefhwckbdv6 [2020-12-03] (G5 Entertainment AB) ==================== Custom CLSID (Whitelisted): ============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-1792065088-1724429800-3796853536-1001_Classes\CLSID\{0BAD39CB-DD3E-4F21-9156-649B0156C28E}\localserver32 -> C:\Windows\System32\DriverStore\FileRepository\wavesapo8de.inf_amd64_9384fc4d30af89c3\WavesSvc64.exe (Waves Inc -> Waves Audio Ltd.) ShellIconOverlayIdentifiers: [ OptaneIconOverlay] -> {A3AF6F6C-8BED-3D93-8B5D-33427B5D38E9} => C:\Program Files\Intel\OptaneShellExtensions\OptaneShellExt.dll [2019-02-25] () [File not signed] [File is in use] ContextMenuHandlers1: [McCtxMenuFrmWrk] -> {CCA9EFD3-29ED-430A-BA6D-E6BBFF0A60C2} => -> No File ContextMenuHandlers3: [OptaneContextMenu] -> {AD7EBB13-617D-3270-8FA8-46583499C4FB} => C:\Program Files\Intel\OptaneShellExtensions\OptaneShellExt.dll [2019-02-25] () [File not signed] [File is in use] ContextMenuHandlers6: [McCtxMenuFrmWrk] -> {CCA9EFD3-29ED-430A-BA6D-E6BBFF0A60C2} => -> No File ==================== Codecs (Whitelisted) ==================== ==================== Shortcuts & WMI ======================== ==================== Loaded Modules (Whitelisted) ============= 2020-04-09 19:11 - 2020-04-09 19:11 - 000019456 _____ () [File not signed] C:\Program Files (x86)\Dell Digital Delivery Services\Dell.D3.HSA.Server.dll 2019-02-25 16:15 - 2019-02-25 16:15 - 000126976 _____ (Intel Corporation) [File not signed] C:\Program Files\Intel\OptaneShellExtensions\iaStorAfsServiceApi.dll 2019-07-19 17:21 - 2019-07-19 17:21 - 000000000 ____L (Microsoft Corporation) C:\Program Files\Microsoft Office\root\Office16\AppVIsvSubsystems64.dll 2019-07-19 17:21 - 2019-07-19 17:21 - 000000000 ____L (Microsoft Corporation) C:\Program Files\Microsoft Office\root\Office16\c2r64.dll 2020-08-14 21:29 - 2020-08-14 21:29 - 000122880 _____ (Rivet Networks) [File not signed] C:\Program Files\Rivet Networks\SmartByte\KillerNetworkServicePS.dll 2020-12-01 00:14 - 2020-12-01 00:14 - 001638912 _____ (Robert Simpson, et al.) [File not signed] C:\Program Files\Dell\SupportAssistAgent\bin\x64\SQLite.Interop.dll ==================== Alternate Data Streams (Whitelisted) ======== ==================== Safe Mode (Whitelisted) ================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ModuleCoreService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcapexe => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfemms => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeplk => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeplk.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ModuleCoreService => ""="Service" ==================== Association (Whitelisted) ================= ==================== Internet Explorer (Whitelisted) ========== HKU\S-1-5-21-1792065088-1724429800-3796853536-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://hp17win10.msn.com/?pc=HCTE HKU\S-1-5-21-1792065088-1724429800-3796853536-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://dell17win10.msn.com/?pc=DCTE SearchScopes: HKU\S-1-5-21-1792065088-1724429800-3796853536-1001 -> DefaultScope {794A06E2-34E3-4CE8-8011-71D97AFF72AB} URL = SearchScopes: HKU\S-1-5-21-1792065088-1724429800-3796853536-1001 -> {794A06E2-34E3-4CE8-8011-71D97AFF72AB} URL = BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2020-09-03] (Microsoft Corporation -> Microsoft Corporation) Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2020-12-05] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2020-12-05] (Microsoft Corporation -> Microsoft Corporation) Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2020-12-05] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2020-12-05] (Microsoft Corporation -> Microsoft Corporation) Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2020-12-05] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2020-12-05] (Microsoft Corporation -> Microsoft Corporation) Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2020-12-05] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2020-12-05] (Microsoft Corporation -> Microsoft Corporation) Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - No File ==================== Hosts content: ========================= (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2019-03-18 23:49 - 2020-10-21 17:15 - 000000865 _____ C:\WINDOWS\system32\drivers\etc\hosts 192.168.1.216 desktop-spkbe9h ==================== Other Areas =========================== (Currently there is no automatic fix for this section.) HKU\S-1-5-21-1792065088-1724429800-3796853536-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\vtmck\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\img1.jpg DNS Servers: 192.168.1.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Warn) Windows Firewall is enabled. Network Binding: ============= Wi-Fi: VirtualBox NDIS6 Bridged Networking Driver -> oracle_VBoxNetLwf (enabled) VirtualBox Host-Only Network: VirtualBox NDIS6 Bridged Networking Driver -> oracle_VBoxNetLwf (enabled) Ethernet: VirtualBox NDIS6 Bridged Networking Driver -> oracle_VBoxNetLwf (enabled) ==================== MSCONFIG/TASK MANAGER disabled items == ==================== FirewallRules (Whitelisted) ================ (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{E666C600-5039-4A62-94D9-4B892D5DB653}] => (Allow) C:\Users\vtmck\AppData\Roaming\Zoom\bin\Zoom.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.) FirewallRules: [{4DD4579E-3FF6-492B-97DE-11FB49146E90}] => (Allow) C:\Users\vtmck\AppData\Roaming\Zoom\bin\airhost.exe => No File FirewallRules: [{824A9BFA-4A76-4028-9D86-24AE8FC04D1B}] => (Allow) C:\Users\vtmck\AppData\Roaming\Zoom\bin\airhost.exe => No File FirewallRules: [{323F8E77-4ED4-4CE9-B7C3-7EAFF747DBEC}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.66.77.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{1F490C8D-B0A4-418F-8C62-9E51DE4143AA}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.66.77.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{01CB96EC-790E-4A34-B98E-CD3A748FE059}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.66.77.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{212982FB-54E2-4533-81E0-297A45F675A6}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.66.77.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{CA6DB006-0CAE-4BE2-B98C-6B7A2969F927}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) FirewallRules: [TCP Query User{E6D29550-A9B0-413A-BDB3-F4DFD7253B76}C:\program files\vcxsrv\vcxsrv.exe] => (Allow) C:\program files\vcxsrv\vcxsrv.exe () [File not signed] FirewallRules: [UDP Query User{2E9708C9-4549-4580-9944-1E97C8D33F6B}C:\program files\vcxsrv\vcxsrv.exe] => (Allow) C:\program files\vcxsrv\vcxsrv.exe () [File not signed] FirewallRules: [{04BC0812-D0CA-43D7-85DA-03CE75D05069}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{DFE1DABE-E874-4251-A99D-43889280E1CA}] => (Allow) C:\Program Files\WindowsApps\ScreenovateTechnologies.DellMobileConnect_3.2.9660.0_x64__0vhbc3ng4wbp0\app\DellMobileConnectClient.exe (SCREENOVATE TECHNOLOGIES LTD. -> Screenovate Technologies Ltd.) FirewallRules: [{5BF3AD9E-7C86-4DD4-8056-3DD9D335E9D4}] => (Allow) C:\Program Files\WindowsApps\ScreenovateTechnologies.DellMobileConnect_3.2.9660.0_x64__0vhbc3ng4wbp0\app\DellMobileConnectClient.exe (SCREENOVATE TECHNOLOGIES LTD. -> Screenovate Technologies Ltd.) ==================== Restore Points ========================= 30-11-2020 20:45:57 Scheduled Checkpoint 04-12-2020 19:29:26 Removed Python Launcher 08-12-2020 14:42:00 Dell Client Management Service 08-12-2020 14:43:07 Dell Client Management Service ==================== Faulty Device Manager Devices ============ ==================== Event log errors: ======================== Application errors: ================== Error: (12/14/2020 04:50:03 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: DllHost.exe, version: 10.0.18362.1, time stamp: 0x4250d5de Faulting module name: combase.dll, version: 10.0.18362.1237, time stamp: 0x3e460a61 Exception code: 0xc0000005 Fault offset: 0x000fdf5d Faulting process id: 0x25dc Faulting application start time: 0x01d6d258757a7066 Faulting application path: C:\WINDOWS\SysWOW64\DllHost.exe Faulting module path: C:\WINDOWS\System32\combase.dll Report Id: 7dda20b5-f2d0-4c02-8f6c-2d403d6b5910 Faulting package full name: Microsoft.SkypeApp_15.66.77.0_x86__kzf8qxf38zg5c Faulting package-relative application ID: App Error: (12/14/2020 04:48:28 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: HxOutlook.exe, version: 16.0.13426.20310, time stamp: 0x5fc801df Faulting module name: Windows.UI.Xaml.dll, version: 10.0.18362.1171, time stamp: 0x3065fca2 Exception code: 0xc000027b Fault offset: 0x0000000000712c96 Faulting process id: 0x2058 Faulting application start time: 0x01d6d262db6f6198 Faulting application path: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.13426.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exe Faulting module path: C:\Windows\System32\Windows.UI.Xaml.dll Report Id: 2be33d8f-b5dd-4235-b2ca-c2c2d8161710 Faulting package full name: microsoft.windowscommunicationsapps_16005.13426.20316.0_x64__8wekyb3d8bbwe Faulting package-relative application ID: microsoft.windowslive.mail Error: (12/14/2020 03:20:05 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: HxOutlook.exe, version: 16.0.13426.20310, time stamp: 0x5fc801df Faulting module name: Windows.UI.Xaml.dll, version: 10.0.18362.1171, time stamp: 0x3065fca2 Exception code: 0xc000027b Fault offset: 0x0000000000712c96 Faulting process id: 0x3128 Faulting application start time: 0x01d6d256826f555b Faulting application path: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.13426.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exe Faulting module path: C:\Windows\System32\Windows.UI.Xaml.dll Report Id: f7658e35-6aca-4b06-84e4-107fed9045c9 Faulting package full name: microsoft.windowscommunicationsapps_16005.13426.20316.0_x64__8wekyb3d8bbwe Faulting package-relative application ID: microsoft.windowslive.mail Error: (12/14/2020 02:04:15 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: HxOutlook.exe, version: 16.0.13426.20310, time stamp: 0x5fc801df Faulting module name: Windows.UI.Xaml.dll, version: 10.0.18362.1171, time stamp: 0x3065fca2 Exception code: 0xc000027b Fault offset: 0x0000000000712c96 Faulting process id: 0x21fc Faulting application start time: 0x01d6d24bea30590f Faulting application path: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.13426.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exe Faulting module path: C:\Windows\System32\Windows.UI.Xaml.dll Report Id: a97662f1-3c40-4203-9543-8adca48fd528 Faulting package full name: microsoft.windowscommunicationsapps_16005.13426.20316.0_x64__8wekyb3d8bbwe Faulting package-relative application ID: microsoft.windowslive.mail Error: (12/14/2020 01:17:34 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: HxOutlook.exe, version: 16.0.13426.20310, time stamp: 0x5fc801df Faulting module name: Windows.UI.Xaml.dll, version: 10.0.18362.1171, time stamp: 0x3065fca2 Exception code: 0xc000027b Fault offset: 0x0000000000712c96 Faulting process id: 0x684 Faulting application start time: 0x01d6d245649da31e Faulting application path: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.13426.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exe Faulting module path: C:\Windows\System32\Windows.UI.Xaml.dll Report Id: b9f6d498-f071-4087-a0b2-24d4d2070f21 Faulting package full name: microsoft.windowscommunicationsapps_16005.13426.20316.0_x64__8wekyb3d8bbwe Faulting package-relative application ID: microsoft.windowslive.mail Error: (12/14/2020 11:29:40 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: HxOutlook.exe, version: 16.0.13426.20310, time stamp: 0x5fc801df Faulting module name: Windows.UI.Xaml.dll, version: 10.0.18362.1171, time stamp: 0x3065fca2 Exception code: 0xc000027b Fault offset: 0x0000000000712c96 Faulting process id: 0x128c Faulting application start time: 0x01d6d236522b7744 Faulting application path: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.13426.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exe Faulting module path: C:\Windows\System32\Windows.UI.Xaml.dll Report Id: d4ec1ab5-0b39-46a8-a54f-62528621b7d5 Faulting package full name: microsoft.windowscommunicationsapps_16005.13426.20316.0_x64__8wekyb3d8bbwe Faulting package-relative application ID: microsoft.windowslive.mail Error: (12/14/2020 10:15:47 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: backgroundTaskHost.exe, version: 10.0.18362.1, time stamp: 0x533f8404 Faulting module name: twinapi.appcore.dll, version: 10.0.18362.1171, time stamp: 0x3e66f34f Exception code: 0xc000027b Fault offset: 0x00000000000d65d8 Faulting process id: 0x29a8 Faulting application start time: 0x01d6d22c0027d53c Faulting application path: C:\WINDOWS\system32\backgroundTaskHost.exe Faulting module path: C:\Windows\System32\twinapi.appcore.dll Report Id: 4ebaec2b-8ead-4386-a0c7-326c0cbf00c5 Faulting package full name: DellInc.DellSupportAssistforPCs_3.8.8.0_x64__htrsf667h5kn2 Faulting package-relative application ID: App Error: (12/14/2020 10:14:39 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: HxOutlook.exe, version: 16.0.13426.20310, time stamp: 0x5fc801df Faulting module name: Windows.UI.Xaml.dll, version: 10.0.18362.1171, time stamp: 0x3065fca2 Exception code: 0xc000027b Fault offset: 0x0000000000712c96 Faulting process id: 0x1f84 Faulting application start time: 0x01d6d22bd6dacae3 Faulting application path: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.13426.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exe Faulting module path: C:\Windows\System32\Windows.UI.Xaml.dll Report Id: b735b6c6-9626-4e9c-8abe-865d0d528205 Faulting package full name: microsoft.windowscommunicationsapps_16005.13426.20316.0_x64__8wekyb3d8bbwe Faulting package-relative application ID: microsoft.windowslive.mail System errors: ============= Error: (12/13/2020 10:15:34 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The McAfee CSP Service service failed to start due to the following error: The system cannot find the file specified. Error: (12/13/2020 10:13:23 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The PEFService service failed to start due to the following error: The system cannot find the file specified. Error: (12/13/2020 10:13:23 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The ModuleCoreService service failed to start due to the following error: The system cannot find the file specified. Error: (12/13/2020 10:13:23 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The mfemms service failed to start due to the following error: The system cannot find the file specified. Error: (12/13/2020 06:33:37 PM) (Source: disk) (EventID: 11) (User: ) Description: The driver detected a controller error on \Device\Harddisk1\DR18. Error: (12/13/2020 05:49:01 PM) (Source: disk) (EventID: 11) (User: ) Description: The driver detected a controller error on \Device\Harddisk1\DR18. Error: (12/10/2020 04:49:53 PM) (Source: ACPI) (EventID: 13) (User: ) Description: : The embedded controller (EC) did not respond within the specified timeout period. This may indicate that there is an error in the EC hardware or firmware or that the BIOS is accessing the EC incorrectly. You should check with your computer manufacturer for an upgraded BIOS. In some situations, this error may cause the computer to function incorrectly. Error: (12/09/2020 07:54:28 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The McAfee CSP Service service failed to start due to the following error: The system cannot find the file specified. Windows Defender: =================================== Date: 2020-12-13 12:13:34.424 Description: Windows Defender Antivirus scan has been stopped before completion. Scan ID: {80A8F19C-BF2D-44BD-AE1D-18F679377550} Scan Type: Antimalware Scan Parameters: Quick Scan Date: 2020-12-12 07:52:27.700 Description: Windows Defender Antivirus scan has been stopped before completion. Scan ID: {840DC9BB-F947-4F31-93D5-7085EFE42737} Scan Type: Antimalware Scan Parameters: Quick Scan Date: 2020-12-11 01:52:31.117 Description: Windows Defender Antivirus scan has been stopped before completion. Scan ID: {090F75F7-92C6-4722-B3C8-866405F6CFD5} Scan Type: Antimalware Scan Parameters: Quick Scan Date: 2020-12-08 23:10:48.683 Description: Windows Defender Antivirus scan has been stopped before completion. Scan ID: {A1253CBB-04F2-4478-B0BE-A1501A3EEAB1} Scan Type: Antimalware Scan Parameters: Quick Scan Date: 2020-12-06 19:13:55.969 Description: Windows Defender Antivirus scan has been stopped before completion. Scan ID: {F8F10168-2780-4686-8CA1-6E01AB22A301} Scan Type: Antimalware Scan Parameters: Quick Scan CodeIntegrity: =================================== Date: 2019-07-19 18:28:46.700 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Program Files\McAfee\MfeAV\AMSIExt.dll that did not meet the Windows signing level requirements. ==================== Memory info =========================== BIOS: Dell Inc. 1.8.0 02/12/2020 Motherboard: Dell Inc. 0WHCP7 Processor: Intel(R) Core(TM) i5-8265U CPU @ 1.60GHz Percentage of memory in use: 72% Total physical RAM: 8054.11 MB Available physical RAM: 2228.81 MB Total Virtual: 17270.11 MB Available Virtual: 9690.84 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:223.69 GB) (Free:119.55 GB) NTFS \\?\Volume{97fad206-271d-4b9b-ae90-41e1706b606c}\ (WINRETOOLS) (Fixed) (Total:0.47 GB) (Free:0.08 GB) NTFS \\?\Volume{129ebef3-0012-4623-ba58-fca6239c4228}\ (Image) (Fixed) (Total:12.22 GB) (Free:0.94 GB) NTFS \\?\Volume{26947bac-c280-4f5c-950d-18145d0c06f2}\ (DELLSUPPORT) (Fixed) (Total:1.21 GB) (Free:0.48 GB) NTFS \\?\Volume{091e8743-4376-4767-a10e-f5cc9983acf8}\ (ESP) (Fixed) (Total:0.73 GB) (Free:0.66 GB) FAT32 ==================== MBR & Partition Table ==================== ========================================================== Disk: 0 (Size: 238.5 GB) (Disk ID: 96E1E7EF) Partition: GPT. ==================== End of Addition.txt =======================