Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15-03-2017 Ran by Owner (24-03-2017 02:40:06) Running from C:\Users\Owner\Desktop Windows 10 Home Version 1607 (X64) (2017-03-08 21:08:52) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-3212692151-809831644-2900379575-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-3212692151-809831644-2900379575-503 - Limited - Disabled) defaultuser0 (S-1-5-21-3212692151-809831644-2900379575-1000 - Limited - Disabled) => C:\Users\defaultuser0 Guest (S-1-5-21-3212692151-809831644-2900379575-501 - Limited - Disabled) Owner (S-1-5-21-3212692151-809831644-2900379575-1001 - Administrator - Enabled) => C:\Users\Owner ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Webroot SecureAnywhere (Enabled - Up to date) {4646A877-74EB-CD3B-8FDB-210DB94FA61A} AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Webroot SecureAnywhere (Enabled - Up to date) {FD274993-52D1-C2B5-B56B-1A7FC2C8ECA7} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.023.20070 - Adobe Systems Incorporated) CCleaner (HKLM\...\CCleaner) (Version: 5.28 - Piriform) Dashlane (HKU\S-1-5-21-3212692151-809831644-2900379575-1001\...\Dashlane) (Version: 4.6.8.26847 - Dashlane, Inc.) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 57.0.2987.110 - Google Inc.) Google Update Helper (x32 Version: 1.3.32.7 - Google Inc.) Hidden HP Support Assistant (HKLM-x32\...\{4780AF24-213D-4187-86F2-0014A6D6077B}) (Version: 8.3.50.9 - HP Inc.) HP Support Solutions Framework (HKLM-x32\...\{00612F78-52C4-46C0-97F0-F50B6036B5E2}) (Version: 12.5.32.203 - HP Inc.) Intel(R) Chipset Device Software (x32 Version: 10.1.1.32 - Intel(R) Corporation) Hidden Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 21.20.16.4542 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 15.0.0.1039 - Intel Corporation) Java 8 Update 121 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180121F0}) (Version: 8.0.1210.13 - Oracle Corporation) Microsoft Office 365 - en-us (HKLM\...\O365HomePremRetail - en-us) (Version: 16.0.7766.2060 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-3212692151-809831644-2900379575-1001\...\OneDriveSetup.exe) (Version: 17.3.6798.0207 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Office 16 Click-to-Run Extensibility Component (x32 Version: 16.0.7766.2047 - Microsoft Corporation) Hidden Office 16 Click-to-Run Extensibility Component 64-bit Registration (Version: 16.0.7766.2047 - Microsoft Corporation) Hidden Office 16 Click-to-Run Licensing Component (Version: 16.0.7766.2047 - Microsoft Corporation) Hidden Office 16 Click-to-Run Localization Component (x32 Version: 16.0.7668.2066 - Microsoft Corporation) Hidden Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.10.714.2016 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7993 - Realtek Semiconductor Corp.) REALTEK Wireless LAN Driver (HKLM-x32\...\{A5107464-AA9B-4177-8129-5FF2F42DD322}) (Version: 1.0.0.72 - REALTEK Semiconductor Corp.) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 19.3.11.37 - Synaptics Incorporated) Webroot SecureAnywhere (HKLM-x32\...\WRUNINST) (Version: 9.0.15.40 - Webroot) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {14182D98-A1EA-4808-BF67-3F26B700939C} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2017-03-03] (Piriform Ltd) Task: {209966EB-86F8-483E-B0FA-13DB3BA1CAE9} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-03-24] (Google Inc.) Task: {34D1422F-EBAD-445D-B37E-A46247BD813C} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Product Configurator => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\ProductConfig.exe [2017-03-02] (HP Inc.) Task: {37F4DDA9-7335-4A8F-A523-5BD95F7F5394} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2017-03-10] (HP Inc.) Task: {3A34E6EE-6BD8-4FB8-A27E-2ADF2C6B6D93} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_TH67J321C2 => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2017-03-10] (HP Inc.) Task: {403CF5A3-D313-4C9C-A59F-B90D6C4EDC4F} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2017-02-19] (Microsoft Corporation) Task: {475C5586-1BAB-4873-A416-2892E87FEABC} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [2016-12-21] (HP Inc.) Task: {4B15BFF5-5BCB-49AC-9420-97A7FEF60F33} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Opt-in For HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF_Utils.exe [2016-12-07] (HP Inc.) Task: {613B73A7-99D7-4B96-B139-59082C874B21} - System32\Tasks\Hewlett-Packard\HP Active Health\HP Active Health Scan (HPSA) => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.exe [2016-11-07] (HP Inc.) Task: {6BB1654A-7D5A-4850-A2F4-CE13D3C33BEB} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2017-03-10] (HP Inc.) Task: {79DC4E5C-5717-4944-ADDA-3725F4648A3F} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2016-12-06] (HP Inc.) Task: {90BA60EB-63CA-429F-892D-B2ED5DD79A0F} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-02-18] (Microsoft Corporation) Task: {91F597AB-7824-4839-89E7-2477C5E39BB4} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-12-19] (Adobe Systems Incorporated) Task: {9E067C0D-DA67-4F7E-A412-EB8BEA1CD6EB} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater - Resources => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2016-12-06] (HP Inc.) Task: {A069B16C-CA4A-43D6-BDA9-6EFAA5F25BA6} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-02-18] (Microsoft Corporation) Task: {B12671FA-D480-4400-AF45-1CA4C3246270} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2016-12-07] (HP Inc.) Task: {D52ECC44-7E9C-4A20-A255-E8970E1F8DE7} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2016-12-07] (HP Inc.) Task: {E415CF32-4E56-405B-B907-A39252E0A651} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-03-24] (Google Inc.) Task: {FAF6E86D-AB6B-4E76-BA2C-3259D02F7D4F} - System32\Tasks\HPCeeScheduleForOwner => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2016-05-12] (HP Development Company, L.P.) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\HPCeeScheduleForOwner.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== 2016-07-16 05:42 - 2016-07-16 05:42 - 00231424 _____ () C:\Windows\SYSTEM32\ism32k.dll 2017-03-15 02:02 - 2017-03-04 01:19 - 02681200 _____ () C:\Windows\system32\CoreUIComponents.dll 2017-03-15 02:02 - 2017-03-04 01:19 - 02681200 _____ () C:\Windows\SYSTEM32\CoreUIComponents.dll 2017-03-08 17:51 - 2017-01-29 07:55 - 08930504 _____ () C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\1033\GrooveIntlResource.dll 2017-03-08 16:32 - 2016-09-06 22:56 - 00134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll 2017-03-15 02:01 - 2017-03-04 00:31 - 00474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll 2017-03-15 02:02 - 2017-03-04 00:12 - 09760768 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2017-03-15 02:02 - 2017-03-04 00:05 - 01401856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2017-03-15 02:02 - 2017-03-04 00:05 - 00757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll 2017-03-15 02:02 - 2017-03-04 00:05 - 01033216 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll 2017-03-15 02:02 - 2017-03-04 00:05 - 02424320 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll 2017-03-15 02:02 - 2017-03-04 00:08 - 04853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll 2017-03-10 02:03 - 2017-03-17 09:48 - 00544208 _____ () C:\Users\Owner\AppData\Roaming\Dashlane\DashlanePlugin.exe 2017-03-13 02:16 - 2017-03-13 02:17 - 00077312 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.12.112.0_x64__kzf8qxf38zg5c\SkypeHost.exe 2017-03-13 02:16 - 2017-03-13 02:17 - 00182784 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.12.112.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll 2017-03-13 02:16 - 2017-03-13 02:17 - 41048064 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.12.112.0_x64__kzf8qxf38zg5c\SkyWrap.dll 2017-03-13 02:16 - 2017-03-13 02:17 - 02236896 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.12.112.0_x64__kzf8qxf38zg5c\roottools.dll 2017-03-08 15:51 - 2017-03-08 15:51 - 00019456 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.214.10010.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe 2017-03-08 15:51 - 2017-03-08 15:51 - 21149696 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.214.10010.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll 2017-03-08 15:51 - 2017-03-08 15:51 - 05380096 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.214.10010.0_x64__8wekyb3d8bbwe\MediaEngine.dll 2017-03-08 15:51 - 2017-03-08 15:51 - 00680448 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.214.10010.0_x64__8wekyb3d8bbwe\Microsoft.DesignCore.dll 2017-03-08 15:51 - 2017-03-08 15:51 - 00387584 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.214.10010.0_x64__8wekyb3d8bbwe\Microsoft.RichMedia.Ink.Controls.dll 2017-03-08 15:51 - 2017-03-08 15:51 - 01047552 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.214.10010.0_x64__8wekyb3d8bbwe\Microsoft.Sharing.dll 2016-07-16 08:34 - 2016-07-16 08:34 - 00291328 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.214.10010.0_x64__8wekyb3d8bbwe\StoreRatingPromotion.dll 2017-03-09 21:47 - 2017-03-09 21:49 - 10650112 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_11701.1001.79.0_x64__8wekyb3d8bbwe\WinStore.Entertainment.Mobile.dll 2017-03-09 21:47 - 2017-03-09 21:47 - 02653184 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_11701.1001.79.0_x64__8wekyb3d8bbwe\MS.Entertainment.Common.Mobile.dll 2017-03-09 21:47 - 2017-03-09 21:49 - 00761344 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_11701.1001.79.0_x64__8wekyb3d8bbwe\WinStore.Vui.dll 2017-03-14 13:47 - 2017-03-03 12:31 - 31099992 _____ () C:\Users\Owner\AppData\Local\Google\Chrome\User Data\PepperFlash\25.0.0.127\pepflashplayer.dll 2017-03-21 18:20 - 2017-03-17 09:48 - 00338896 _____ () C:\Users\Owner\AppData\Roaming\Dashlane\4.6.8.26847\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWDebugDll_win32.4.6.8.26847.dll 2017-03-21 18:20 - 2017-03-17 09:48 - 00441808 _____ () C:\Users\Owner\AppData\Roaming\Dashlane\4.6.8.26847\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWDebug.4.6.8.26847.dll 2017-03-21 18:20 - 2017-03-17 09:48 - 00464848 _____ () C:\Users\Owner\AppData\Roaming\Dashlane\4.6.8.26847\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWUtils.4.6.8.26847.dll 2017-03-21 18:20 - 2017-03-17 09:48 - 62708176 _____ () C:\Users\Owner\AppData\Roaming\Dashlane\4.6.8.26847\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWExternLib.4.6.8.26847.dll 2017-03-21 18:20 - 2017-03-17 09:48 - 00285648 _____ () C:\Users\Owner\AppData\Roaming\Dashlane\4.6.8.26847\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWMainLib_win.4.6.8.26847.dll 2017-03-21 18:20 - 2017-03-17 09:48 - 06183888 _____ () C:\Users\Owner\AppData\Roaming\Dashlane\4.6.8.26847\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWData.4.6.8.26847.dll 2017-03-21 18:20 - 2017-03-17 09:48 - 07271888 _____ () C:\Users\Owner\AppData\Roaming\Dashlane\4.6.8.26847\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWApplication.4.6.8.26847.dll 2017-03-21 18:20 - 2017-03-17 09:48 - 13684176 _____ () C:\Users\Owner\AppData\Roaming\Dashlane\4.6.8.26847\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWMainLib.4.6.8.26847.dll 2017-03-21 18:20 - 2017-03-17 09:48 - 02215888 _____ () C:\Users\Owner\AppData\Roaming\Dashlane\4.6.8.26847\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWMainLibData.4.6.8.26847.dll 2017-03-21 18:20 - 2017-03-17 09:48 - 00334288 _____ () C:\Users\Owner\AppData\Roaming\Dashlane\4.6.8.26847\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\Kwift_DP.4.6.8.26847.dll 2017-03-08 17:48 - 2017-03-15 03:59 - 00252608 _____ () C:\Program Files (x86)\Microsoft Office\root\Office16\IEAWSDC.DLL ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WRkrn => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WRSVC => ""="Service" ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2016-07-16 05:47 - 2016-07-16 05:45 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-3212692151-809831644-2900379575-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Windows\img0.jpg DNS Servers: 75.75.75.75 - 75.75.76.76 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == HKLM\...\StartupApproved\Run: => "RtHDVBg_Session" HKLM\...\StartupApproved\Run: => "RTHDVCPL" HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched" HKU\S-1-5-21-3212692151-809831644-2900379575-1001\...\StartupApproved\Run: => "OneDrive" HKU\S-1-5-21-3212692151-809831644-2900379575-1001\...\StartupApproved\Run: => "CCleaner Monitoring" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [{6048632D-AD3E-4726-AFB6-CE9E4B6BB3C1}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe FirewallRules: [{558C3436-79B9-48E0-848D-2965260CBB23}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Restore Points ========================= 15-03-2017 05:37:02 Windows Update 15-03-2017 05:37:45 Windows Update 21-03-2017 00:10:56 3/21/17 ==================== Faulty Device Manager Devices ============= Name: Realtek PCIe FE Family Controller Description: Realtek PCIe FE Family Controller Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Realtek Service: rt640x64 Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (03/24/2017 01:31:51 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: MiracastView.exe, version: 10.0.14393.0, time stamp: 0x57899be7 Faulting module name: Windows.UI.Xaml.dll, version: 10.0.14393.953, time stamp: 0x58ba5c3d Exception code: 0xc0000409 Fault offset: 0x00000000000521d0 Faulting process id: 0x1ecc Faulting application start time: 0x01d2a470b46d20ea Faulting application path: C:\Windows\MiracastView\MiracastView.exe Faulting module path: C:\Windows\System32\Windows.UI.Xaml.dll Report Id: 582ddc58-6325-4178-bc1f-61d660dcf827 Faulting package full name: Faulting package-relative application ID: Error: (03/24/2017 01:31:33 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: MiracastView.exe, version: 10.0.14393.0, time stamp: 0x57899be7 Faulting module name: Windows.UI.Xaml.dll, version: 10.0.14393.953, time stamp: 0x58ba5c3d Exception code: 0xc0000409 Fault offset: 0x00000000000521d0 Faulting process id: 0xc78 Faulting application start time: 0x01d2a470a95d0416 Faulting application path: C:\Windows\MiracastView\MiracastView.exe Faulting module path: C:\Windows\System32\Windows.UI.Xaml.dll Report Id: 9ee9603e-9bd2-40a5-9406-32a3d39b6abb Faulting package full name: Faulting package-relative application ID: Error: (03/24/2017 01:31:31 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: MiracastView.exe, version: 10.0.14393.0, time stamp: 0x57899be7 Faulting module name: Windows.UI.Xaml.dll, version: 10.0.14393.953, time stamp: 0x58ba5c3d Exception code: 0xc0000409 Fault offset: 0x00000000000521d0 Faulting process id: 0x1898 Faulting application start time: 0x01d2a470a81dd650 Faulting application path: C:\Windows\MiracastView\MiracastView.exe Faulting module path: C:\Windows\System32\Windows.UI.Xaml.dll Report Id: f3830d49-ce55-41a8-a444-e5f9da8004d7 Faulting package full name: Faulting package-relative application ID: Error: (03/24/2017 01:31:29 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: MiracastView.exe, version: 10.0.14393.0, time stamp: 0x57899be7 Faulting module name: Windows.UI.Xaml.dll, version: 10.0.14393.953, time stamp: 0x58ba5c3d Exception code: 0xc0000409 Fault offset: 0x00000000000521d0 Faulting process id: 0x484 Faulting application start time: 0x01d2a470a76c61b1 Faulting application path: C:\Windows\MiracastView\MiracastView.exe Faulting module path: C:\Windows\System32\Windows.UI.Xaml.dll Report Id: 0be0148b-6d76-4f9f-88db-7d6656ed1a46 Faulting package full name: Faulting package-relative application ID: Error: (03/24/2017 01:31:27 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: MiracastView.exe, version: 10.0.14393.0, time stamp: 0x57899be7 Faulting module name: Windows.UI.Xaml.dll, version: 10.0.14393.953, time stamp: 0x58ba5c3d Exception code: 0xc0000409 Fault offset: 0x00000000000521d0 Faulting process id: 0x171c Faulting application start time: 0x01d2a470a603e608 Faulting application path: C:\Windows\MiracastView\MiracastView.exe Faulting module path: C:\Windows\System32\Windows.UI.Xaml.dll Report Id: 74b88a72-39aa-45ac-8fe3-bb2c8851bc68 Faulting package full name: Faulting package-relative application ID: Error: (03/24/2017 01:22:45 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: MiracastView.exe, version: 10.0.14393.0, time stamp: 0x57899be7 Faulting module name: Windows.UI.Xaml.dll, version: 10.0.14393.953, time stamp: 0x58ba5c3d Exception code: 0xc0000409 Fault offset: 0x00000000000521d0 Faulting process id: 0x1bc4 Faulting application start time: 0x01d2a46f6ed57b63 Faulting application path: C:\Windows\MiracastView\MiracastView.exe Faulting module path: C:\Windows\System32\Windows.UI.Xaml.dll Report Id: 81cb1687-5bc6-45a2-adf3-beee953f9eb5 Faulting package full name: Faulting package-relative application ID: Error: (03/24/2017 12:09:28 AM) (Source: DPTF) (EventID: 256) (User: ) Description: Intel(R) Dynamic Platform and Thermal Framework : ESIF(8.2.11000.2996) TYPE: ERROR MODULE: DPTF TIME 21923 ms DPTF Build Version: 8.2.11000.2996 DPTF Build Date: Aug 10 2016 11:44:33 Source File: ..\..\..\..\Sources\Policies\PolicyLib\PolicyBase.cpp @ line 989 Executing Function: PolicyBase::takeControlOfOsc Message: Passive Policy 2: Failed to acquire OSC: Failure during execution of _OSC: DPTF Build Version: 8.2.11000.2996 DPTF Build Date: Aug 10 2016 11:44:33 Source File: ..\..\..\Sources\Manager\EsifServices.cpp @ line 472 Executing Function: EsifServices::primitiveExecuteSet Message: Error returned from ESIF services interface function call Participant: NoParticipant Domain: NoDomain ESIF Primitive: SET_OPERATING_SYSTEM_CAPABILITIES [93] ESIF Instance: 255 ESIF Return Code: ESIF_E_UNSUPPORTED_ACTION_TYPE [1202] Policy: Passive Policy 2 [1] Error: (03/23/2017 06:28:09 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: HPSF.exe, version: 8.3.50.9, time stamp: 0x58472b92 Faulting module name: KERNELBASE.dll, version: 10.0.14393.953, time stamp: 0x58ba59e1 Exception code: 0xe0434352 Fault offset: 0x0000000000017788 Faulting process id: 0x1114 Faulting application start time: 0x01d2a435563e2282 Faulting application path: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe Faulting module path: C:\Windows\System32\KERNELBASE.dll Report Id: 214e1a3c-b902-434a-b6fd-d68f7a4afb07 Faulting package full name: Faulting package-relative application ID: Error: (03/23/2017 06:28:09 PM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Application: HPSF.exe Framework Version: v4.0.30319 Description: The process was terminated due to an unhandled exception. Exception Info: System.Exception at HP.SupportFramework.Common.Config.Configuration.() at HP.SupportAssistant.Engine.HPSAContext.get_Configuration() at HP.SupportAssistant.UIController.ActiveCheck.AnalyzingVM.() at HP.SupportAssistant.UIController.ActiveCheck.AnalyzingVM.(System.Object, System.EventArgs) at HP.SupportAssistant.Engine.DeviceDetect.DeviceDetection.(System.Object, System.ComponentModel.RunWorkerCompletedEventArgs) at System.ComponentModel.BackgroundWorker.OnRunWorkerCompleted(System.ComponentModel.RunWorkerCompletedEventArgs) at System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) at System.Threading.QueueUserWorkItemCallback.System.Threading.IThreadPoolWorkItem.ExecuteWorkItem() at System.Threading.ThreadPoolWorkQueue.Dispatch() Error: (03/22/2017 04:18:23 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: The Open Procedure for service "BITS" in DLL "C:\Windows\System32\bitsperf.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code. System errors: ============= Error: (03/24/2017 12:34:31 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (03/24/2017 12:33:39 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (03/24/2017 12:09:53 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {8D8F4F83-3594-4F07-8369-FC3C3CAE4919} and APPID {F72671A9-012C-4725-9D2F-2A4D32D65169} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (03/24/2017 12:08:42 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (03/23/2017 09:04:01 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (03/23/2017 07:25:34 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (03/23/2017 03:14:02 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (03/23/2017 02:22:03 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (03/23/2017 11:59:47 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (03/23/2017 11:34:19 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i7-7500U CPU @ 2.70GHz Percentage of memory in use: 44% Total physical RAM: 8064.57 MB Available physical RAM: 4441.58 MB Total Virtual: 9344.57 MB Available Virtual: 5620.65 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:930.96 GB) (Free:896.09 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 00000000) Partition: GPT. ==================== End of Addition.txt ============================