Additional scan result of Farbar Recovery Scan Tool (x64) Version: 14-01-2017
Ran by Mohamed Elkheir (14-01-2017 12:29:58)
Running from C:\Users\Mohamed Elkheir\Desktop\SWF
Windows 10 Home Version 1607 (X64) (2016-10-07 11:27:48)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-2903169055-2215062143-4039091648-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-2903169055-2215062143-4039091648-503 - Limited - Disabled)
Gæst (S-1-5-21-2903169055-2215062143-4039091648-501 - Limited - Disabled)
Mohamed Elkheir (S-1-5-21-2903169055-2215062143-4039091648-1000 - Administrator - Enabled) => C:\Users\Mohamed Elkheir
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Avast Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
FW: avast! Antivirus (Disabled) {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
64 Bit HP CIO Components Installer (Version: 6.2.2 - Hewlett-Packard) Hidden
Acer Backup Manager (HKLM-x32...\InstallShield_{0B61BBD5-DA3C-409A-8730-0C3DC3B0F270}) (Version: 3.0.0.100 - NTI Corporation)
Acer Crystal Eye Webcam (HKLM-x32...\InstallShield_{A0382E3C-7384-429A-9BFA-AF5888E5A193}) (Version: 1.5.2728.00 - CyberLink Corp.)
Acer Crystal Eye Webcam (x32 Version: 1.5.2728.00 - CyberLink Corp.) Hidden
Acer ePower Management (HKLM-x32...{3DB0448D-AD82-4923-B305-D001E521A964}) (Version: 6.00.3010 - Acer Incorporated)
Acer eRecovery Management (HKLM-x32...{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 5.00.3507 - Acer Incorporated)
Acer Instant Update Service (HKLM...{2AC88B17-0D33-435D-BC19-99C313B4E622}) (Version: 1.00.3001 - Acer Incorporated)
Acer ScreenSaver (HKLM-x32...\Acer Screensaver) (Version: 20.12.0307.1154 - Acer Incorporated)
Acer Theft Shield (HKLM...{8ADB0CD2-4E5A-452F-BB3B-3A2984CAC749}) (Version: 1.01.3006 - Acer Incorporated)
Acer VCM (HKLM-x32...{047F790A-7A2A-4B6A-AD02-38092BA63DAC}) (Version: 4.05.3501 - Acer Incorporated)
Adobe Acrobat Reader DC - Dansk (HKLM-x32...{AC76BA86-7AD7-1030-7B44-AC0F074E4100}) (Version: 15.023.20053 - Adobe Systems Incorporated)
Adobe Connect 9 Add-in (HKU\S-1-5-21-2903169055-2215062143-4039091648-1000...\Adobe Connect 9 Add-in) (Version: 11.9.976.299 - Adobe Systems Incorporated)
Adobe Flash Player 24 NPAPI (HKLM-x32...\Adobe Flash Player NPAPI) (Version: 24.0.0.194 - Adobe Systems Incorporated)
Apple Mobile Device Support (HKLM...{55BB2110-FB43-49B3-93F4-945A0CFB0A6C}) (Version: 10.0.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32...{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.)
Apple-programunderstøttelse (64 bit) (HKLM...{64E6007B-1DA9-42CD-BBE4-D5FA67A7C71D}) (Version: 5.2 - Apple Inc.)
Atheros Bluetooth Suite (64) (HKLM...{230D1595-57DA-4933-8C4E-375797EBB7E1}) (Version: 7.4.0.126 - Atheros)
Avast Free Antivirus (HKLM-x32...\Avast) (Version: 12.3.2280 - AVAST Software)
AX88772B Windows 7 Drivers (HKLM-x32...\InstallShield_{54A168C9-2250-4058-80EB-1F4A4192548A}) (Version: 1.0.1.1 - ASIX Electronics Corporation)
AX88772B Windows 7 Drivers (x32 Version: 1.0.1.1 - ASIX Electronics Corporation) Hidden
Backup Manager V3 (x32 Version: 3.0.0.100 - NTI Corporation) Hidden
Bing Bar (HKLM-x32...{C28D96C0-6A90-459E-A077-A6706F4EC0FC}) (Version: 7.0.765.0 - Microsoft Corporation)
Bonjour (HKLM...{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
CCleaner (HKLM...\CCleaner) (Version: 5.25 - Piriform)
clear.fi Media (HKLM-x32...{E9AF1707-3F3A-49E2-8345-4F2D629D0876}) (Version: 2.00.3004 - Acer Incorporated)
clear.fi Photo (HKLM-x32...{B5AD89F2-03D3-4206-8487-018298007DD0}) (Version: 2.00.3004 - Acer Incorporated)
clear.fi SDK - MVP 2 (x32 Version: 2.0.1505 - CyberLink Corp.) Hidden
clear.fi SDK- Movie 2 (x32 Version: 2.0.1502 - CyberLink Corp.) Hidden
CyberLink MediaEspresso (HKLM-x32...\InstallShield_{E3739848-5329-48E3-8D28-5BBD6E8BE384}) (Version: 6.5.1720_38230 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Dolby Home Theater v4 (HKLM-x32...{B26438B4-BF51-49C3-9567-7F14A5E40CB9}) (Version: 7.2.7000.7 - Dolby Laboratories Inc)
Dropbox (HKLM-x32...\Dropbox) (Version: 17.4.33 - Dropbox, Inc.)
Dropbox Update Helper (x32 Version: 1.3.59.1 - Dropbox, Inc.) Hidden
ELAN Touchpad 11.15.0.18_X64 (HKLM...\Elantech) (Version: 11.15.0.18 - ELAN Microelectronic Corp.)
EPSON XP-235 Series Printer Uninstall (HKLM...\EPSON XP-235 Series) (Version: - Seiko Epson Corporation)
EPSON-manualer (HKLM-x32...{84CECC1B-21EF-41B1-9A91-3E724E5D99D3}) (Version: 1.50.0.0 - SEIKO EPSON CORPORATION)
Evernote v. 4.5.2 (HKLM-x32...{F77EF646-19EB-11E1-9A9E-984BE15F174E}) (Version: 4.5.2.5866 - Evernote Corp.)
ExpressCache (HKLM...{1E084588-8CC6-4D1B-B904-B1A09DA22A52}) (Version: 1.0.82 - Diskeeper Corporation)
Fotogalerija Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galeria fotogràfica del Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galeria fotografii us?ugi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galerie foto Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Google Chrome (HKLM-x32...\Google Chrome) (Version: 55.0.2883.87 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.32.7 - Google Inc.) Hidden
Graph 4.4.2 (HKLM-x32...\Graph_is1) (Version: - Ivan Johansen)
Identity Card (HKLM-x32...\Identity Card) (Version: 1.00.3501 - Acer Incorporated)
Intel(R) Manageability Engine Firmware Recovery Agent (HKLM-x32...{A6C48A9F-694A-4234-B3AA-62590B668927}) (Version: 1.0.0.36279 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32...{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.0.10.1464 - Intel Corporation)
Intel(R) OpenCL CPU Runtime (HKLM-x32...{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32...{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.4276 - Intel Corporation)
Intel(R) Rapid Start Technology (HKLM-x32...\3D073343-CEEB-4ce7-85AC-A69A7631B5D6) (Version: 1.0.0.1024 - Intel Corporation)
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32...{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.4.220 - Intel Corporation)
Intel® Turbo Boost Teknologi Monitor 2.5 (HKLM...{6C9365EB-1F9E-4893-9196-3EC77C88D0C5}) (Version: 2.5.1.0 - Intel)
iTunes (HKLM...{554C62C7-E6BB-40F1-892B-F0AE02D3C135}) (Version: 12.5.3.17 - Apple Inc.)
Java 8 Update 101 (64-bit) (HKLM...{26A24AE4-039D-4CA4-87B4-2F64180101F0}) (Version: 8.0.1010.13 - Oracle Corporation)
Java 8 Update 101 (HKLM-x32...{26A24AE4-039D-4CA4-87B4-2F32180101F0}) (Version: 8.0.1010.13 - Oracle Corporation)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Launch Manager (HKLM-x32...\LManager) (Version: 5.1.15 - Acer Inc.)
Malwarebytes version 3.0.5.1299 (HKLM...{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.0.5.1299 - Malwarebytes)
Maple 18 (HKLM...\Maple 18) (Version: 18 - Maplesoft)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft ASP.NET MVC 2 (HKLM-x32...{DD8FF2F3-0D97-4CF3-AF78-FA0E1B242244}) (Version: 2.0.60926.0 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-2903169055-2215062143-4039091648-1000...\OneDriveSetup.exe) (Version: 17.3.6743.1212 - Microsoft Corporation)
Microsoft Silverlight (HKLM...{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50901.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition ENU (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32...{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32...{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32...{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM...{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM...{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM...{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32...{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32...{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32...{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32...{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32...{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM...{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32...{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DAN (HKLM...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DAN) (Version: 10.0.50903 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM-x32...{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32...{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MyWinLocker (Version: 4.0.14.27 - Egis Technology Inc.) Hidden
MyWinLocker 4 (x32 Version: 4.0.14.27 - Egis Technology Inc.) Hidden
MyWinLocker Suite (HKLM-x32...\InstallShield_{17DF9714-60C9-43C9-A9C2-32BCAED44CBE}) (Version: 4.0.14.19 - Egis Technology Inc.)
MyWinLocker Suite (x32 Version: 4.0.14.19 - Egis Technology Inc.) Hidden
Nero Prerequisite Installer 2.0 (HKLM-x32...{0DBC021C-95D9-435A-A4B0-E6515AFD1A71}) (Version: 12.0.01000 - Nero AG)
Nero12EssTSST (HKLM-x32...{1DEC64C1-7F34-44CD-BC35-8E0A096300CF}) (Version: 12.0.01100 - Nero AG)
newsXpresso (HKLM-x32...\InstallShield_{613C0AC5-3A67-4B94-8B13-9176AD83F5BF}) (Version: 1.0.0.40 - esobi Inc.)
newsXpresso (x32 Version: 1.0.0.40 - esobi Inc.) Hidden
Poczta us?ugi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Podstawowe programy Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Po?ta Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Prerequisite installer (x32 Version: 12.0.0003 - Nero AG) Hidden
Qualcomm Atheros WiFi Driver Installation (HKLM-x32...{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 3.1 - Qualcomm Atheros)
Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Realtek High Definition Audio Driver (HKLM-x32...{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7535 - Realtek Semiconductor Corp.)
Realtek USB 2.0 Card Reader (HKLM-x32...{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7601.39025 - Realtek Semiconductor Corp.)
SafeZone Stable 1.51.2220.62 (x32 Version: 1.51.2220.62 - Avast Software) Hidden
Samsung Kies (HKLM-x32...\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.6.0.13064_2 - Samsung Electronics Co., Ltd.)
Samsung Kies (x32 Version: 2.6.0.13064_2 - Samsung Electronics Co., Ltd.) Hidden
SAMSUNG USB Driver for Mobile Phones (HKLM...{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.27.0 - SAMSUNG Electronics Co., Ltd.)
Secunia PSI (3.0.0.11005) (HKLM-x32...\Secunia PSI) (Version: 3.0.0.11005 - Secunia)
Shared C Run-time for x64 (HKLM...{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee)
Shredder (Version: 2.0.8.9 - Egis Technology Inc.) Hidden
Shredder (x32 Version: 2.0.8.9 - Egis Technology Inc.) Hidden
Sleep Memory Optimizer (HKLM-x32...{34BE2594-1D20-4A2E-97A0-B9E2837520AE}) (Version: 1.00.3004 - Acer Incorporated)
Smart Timer (HKLM-x32...{89DB52FC-EA72-468F-A0C7-150AF8B7AB74}) (Version: 1.00.3004 - Acer Incorporated)
Welcome Center (HKLM-x32...\Acer Welcome Center) (Version: 1.02.3507 - Acer Incorporated)
Windows Live Essentials (HKLM-x32...\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation)
WinZip 20.5 (HKLM...{CD95F661-A5C4-44F5-A6AA-ECDD91C24105}) (Version: 20.5.12118 - WinZip Computing, S.L. )
WordMat v. 1.03 (HKLM-x32...{301A8257-D5EF-48B4-AAC2-E86700DDA6FE}_is1) (Version: - Eduap)
??????? ??????????? ??? Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
???????? ?????????? Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
????? Windows Live (x32 Version: 15.4.3502.0922 - ?????????? ??????????) Hidden
?????????? Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
??????????? ?? Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
?????? ??????? ?? Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
???? Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
???? ??? Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-2903169055-2215062143-4039091648-1000_Classes\CLSID{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\WINDOWS\system32\igfxEM.exe (Intel Corporation)
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {0A017648-1032-4AB4-9BAE-C2ECFB86EF25} - System32\Tasks\EPSON XP-235 Series Update {77C184EF-EF91-4AC7-B7E3-B07188599FAF} => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSPFE.EXE [2013-11-22] (SEIKO EPSON CORPORATION)
Task: {0B3BC962-8955-4234-BDD3-5CBAA348F2F7} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\WINDOWS\ehome\ehrec.exe
Task: {0FD1BA23-DF5F-448A-BB6D-1F6F25FD9F03} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {12AB0D91-4E49-42AD-8D55-E81AA9C3579A} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\WINDOWS\ehome\mcupdate.exe
Task: {13E90765-0666-4E5A-852F-E37A39E11872} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-12-06] (Piriform Ltd)
Task: {1C14F846-94E8-42C5-BA57-F3F6C7890CCC} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {20A667A0-5E04-4E44-BB8A-794428D62603} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {219AE867-7495-488A-B9AA-20920B74BE08} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-06-14] (Dropbox, Inc.)
Task: {2BD77854-074A-467B-BDE1-BB76D2EA2F96} - System32\Tasks\Theft Shield\AcerTheftShieldTask => C:\Program Files\Acer\Acer Theft Shield\USecuAppLauncher.exe [2012-11-12] (Acer Incorporated)
Task: {2C679002-D1C5-4DD2-84B1-04D3CBAF3477} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2012-03-26] (Intel Corporation)
Task: {2D9EF5CD-CA04-4D75-B24D-CDBFC9CB4623} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {32B1486D-FDDD-4672-BC2E-442EEF86CB44} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2012-03-26] (Intel Corporation)
Task: {3AD0842F-3087-4B65-B52E-0B05ED4E1172} - System32\Tasks\DeviceDetector => C:\Program Files (x86)\Cyberlink\MediaEspresso\DeviceDetector\DeviceDetector.exe 2011-05-20
Task: {4073F259-D333-4F33-9372-7DF1AD7FF8E3} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {45FEB2DD-5BCF-4B95-88F0-3575B4AE31E4} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2017-01-12] (Microsoft Corporation)
Task: {49633FC9-7372-4B6F-BF6E-D0190588823C} - System32\Tasks\EgisUpdate => C:\Program Files\EgisTec IPS\EgisUpdate.exe [2011-03-28] (Egis Technology Inc.)
Task: {4F61A91C-6295-4E66-B7A7-6D274C00CB93} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\WINDOWS\ehome\MCUpdate.exe
Task: {55D6B254-A5D5-4EC1-BD4E-32B6A686A03B} - System32\Tasks\Smart Timer Task Scheduler => Smart_Timer.exe
Task: {56F06DD2-E015-43AD-B2FD-69C6114A441C} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-01-12] (Adobe Systems Incorporated)
Task: {6001A8B4-BDBF-41D7-8F7D-1C3B80918CDE} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {6462446B-284F-4AD6-AD67-44D0C9EAB83B} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {6E86E924-88DC-49C7-BAEC-BBBE32C1B084} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {71DEA2DD-7EBD-4D8D-BED5-5AED5BEE4E21} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {75EECB8E-A5D1-416B-8271-BDCA1C11CFD9} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {7B62F6EC-62B1-468F-9639-B92D6774FCB3} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {873BEB94-133A-4920-B22F-8CEDE950A696} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {8E211345-74E5-4FA4-9029-A364E3385FEC} - System32\Tasks\avastBCLRestart_chrome.exe => Chrome.exe
Task: {8ED1D13D-D985-4255-9595-F4E99FFB8CC3} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-01] (Google Inc.)
Task: {9A9B6FE7-02B6-47CB-9741-C1FFDAA1AA16} - System32\Tasks\OneDrive Standalone Update Task => C:\Users\Mohamed Elkheir\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\OneDriveStandaloneUpdater.exe
Task: {9DD18444-D74F-4CA9-BD78-D690952FE799} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-06-14] (Dropbox, Inc.)
Task: {9FE999C3-D98D-4611-B44F-FEBE54D858A5} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {A688FF71-7B1D-4E64-ABC7-DE91525ED4AF} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-01] (Google Inc.)
Task: {A6B5B866-6158-4668-B495-7C048D3BCD3A} - System32\Tasks\EPSON XP-235 Series Update {54415D97-ACA6-4D8A-B18B-078990DF8BED} => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSPFE.EXE [2013-11-22] (SEIKO EPSON CORPORATION)
Task: {AE5D805D-C4E7-4C73-BA8F-93A920EE8CDC} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\WINDOWS\ehome\mcupdate.exe
Task: {B398C832-18CD-4F61-BBB2-4DF732F24FFF} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {B49E886D-6AD3-418C-BEBC-7D1EFEE7144A} - System32\Tasks\SafeZone scheduled Autoupdate 1474899492 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2016-09-06] (Avast Software)
Task: {B5DAAA18-0BCC-4308-B968-F78F21F4D7B9} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2016-09-26] (AVAST Software)
Task: {BAD0D59E-37BC-4EE5-A2CD-44241ADDA197} - System32\Tasks\EPSON XP-235 Series Update {2221F19E-8437-44C1-8BCB-65320C498667} => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSPFE.EXE [2013-11-22] (SEIKO EPSON CORPORATION)
Task: {C96869C3-A8E2-40FF-A846-73F6878AA7EC} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {D66F1723-2869-431C-BC6F-7D75F592B0C2} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-12-19] (Adobe Systems Incorporated)
Task: {E53CA6A8-0CC2-48B2-8F7E-82AE95F18C8B} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {EA1E36F0-DD88-423F-A651-B4D9F2D504EF} - System32\Tasks\UALU notificatin => C:\Program Files\Acer\Acer Updater\UALU.exe [2012-02-07] (Acer Incorporated)
Task: {EDECB718-616A-4B95-8C3E-53880B736735} - \OfficeSoftwareProtectionPlatform\SvcRestartTask -> No File <==== ATTENTION
Task: {EF35A17A-C9A2-419A-840D-E80E50E53CAE} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {F1464D62-56C3-4242-B6BE-8E0912F0F3AB} - System32\Tasks\ROC_JAN2013_TB_rmv => C:\Program Files (x86)\AVG Secure Search\PostInstall\ROC.exe
Task: {F5926445-EB34-42F5-9BED-3A1563412C32} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\WINDOWS\ehome\ehrec.exe
Task: {FCC6017B-8687-4B69-B61E-262D2A1DD63E} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {FD50F2C5-F325-49A1-B482-9595CA63607C} - System32\Tasks\PMMUpdate => C:\Program Files\EgisTec IPS\PMMUpdate.exe [2011-03-28] (Egis Technology Inc.)
Task: {FF27ABA1-676A-4A66-B94C-4BC6B12C2072} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\EPSON XP-235 Series Update {2221F19E-8437-44C1-8BCB-65320C498667}.job => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSPFE.EXE :/EXE:{2221F19E-8437-44C1-8BCB-65320C498667} /F:Update WORKGROUP\MOHAMEDELKHEIR$ ?Searches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi
Task: C:\WINDOWS\Tasks\EPSON XP-235 Series Update {54415D97-ACA6-4D8A-B18B-078990DF8BED}.job => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSPFE.EXE :/EXE:{54415D97-ACA6-4D8A-B18B-078990DF8BED} /F:Update WORKGROUP\MOHAMEDELKHEIR$ ?Searches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi
Task: C:\WINDOWS\Tasks\EPSON XP-235 Series Update {77C184EF-EF91-4AC7-B7E3-B07188599FAF}.job => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSPFE.EXE :/EXE:{77C184EF-EF91-4AC7-B7E3-B07188599FAF} /F:Update WORKGROUP\MOHAMEDELKHEIR$ ?Searches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi
Task: C:\WINDOWS\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe
Task: C:\WINDOWS\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe
==================== Shortcuts =============================
(The entries could be listed to be restored or removed.)
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Anti-Theft.lnk -> C:\Program Files\Preload\McAfee Anti-Theft\StartURL.exe () ->
hxxp://home.mcafee.com/root/campaign.aspx?cid=103626==================== Loaded Modules (Whitelisted) ==============
2016-07-16 12:42 - 2016-07-16 12:42 - 00231424 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2016-12-14 18:42 - 2016-12-09 11:29 - 02681200 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2017-01-13 18:50 - 2016-12-14 12:55 - 02259232 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\PoliciesControllerImpl.dll
2017-01-13 18:50 - 2016-12-14 12:55 - 02813904 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\arwlib.dll
2016-12-14 18:42 - 2016-12-09 11:29 - 02681200 _____ () C:\WINDOWS\SYSTEM32\CoreUIComponents.dll
2009-01-21 16:45 - 2009-01-21 16:45 - 01401856 _____ () C:\Program Files (x86)\EgisTec MyWinLocker\x64\LIBEAY32.dll
2016-10-07 10:56 - 2016-10-07 10:56 - 00134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll
2016-12-14 18:41 - 2016-12-09 10:41 - 00474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll
2016-11-09 15:53 - 2016-11-02 11:21 - 09760768 ____ () C:\Windows\SystemApps\Microsoft.Windows.Cortanacw5n1h2txyewy\CortanaApi.dll
2016-11-09 15:54 - 2016-11-02 11:15 - 01401856 ____ () C:\Windows\SystemApps\Microsoft.Windows.Cortanacw5n1h2txyewy\Cortana.Core.dll
2016-11-09 15:53 - 2016-11-02 11:14 - 00757248 ____ () C:\Windows\SystemApps\Microsoft.Windows.Cortanacw5n1h2txyewy\CSGSuggestLib.dll
2016-11-09 15:53 - 2016-11-02 11:16 - 02424320 ____ () C:\Windows\SystemApps\Microsoft.Windows.Cortanacw5n1h2txyewy\Cortana.BackgroundTask.dll
2016-11-09 15:53 - 2016-11-02 11:17 - 04853760 ____ () C:\Windows\SystemApps\Microsoft.Windows.Cortanacw5n1h2txyewy\RemindersUI.dll
2016-12-14 10:40 - 2016-12-14 10:41 - 00072192 ____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp11.10.145.0_x64__kzf8qxf38zg5c\SkypeHost.exe
2016-12-14 10:40 - 2016-12-14 10:41 - 00179712 ____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp11.10.145.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll
2016-12-14 10:40 - 2016-12-14 10:41 - 42130432 ____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp11.10.145.0_x64__kzf8qxf38zg5c\SkyWrap.dll
2016-12-14 10:40 - 2016-12-14 10:41 - 02216448 ____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp11.10.145.0_x64__kzf8qxf38zg5c\roottools.dll
2012-02-20 15:34 - 2012-02-20 15:34 - 00040552 _____ () C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe
2012-02-20 15:34 - 2012-02-20 15:34 - 00022632 _____ () C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe
2012-11-07 19:41 - 2012-03-29 07:36 - 00128280 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
2016-11-17 01:28 - 2016-11-17 01:28 - 00092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2016-11-17 01:28 - 2016-11-17 01:28 - 01353528 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2016-09-26 14:16 - 2016-09-26 14:16 - 00169064 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2016-09-26 14:16 - 2016-09-26 14:16 - 00482928 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll
2017-01-14 12:13 - 2017-01-14 12:13 - 04444072 _____ () C:\Program Files\AVAST Software\Avast\defs\17011301\algo.dll
2012-01-05 22:22 - 2012-01-05 22:22 - 00465344 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\sqlite3.dll
2012-01-05 22:22 - 2012-01-05 22:22 - 00125464 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\MailConverter32.dll
2012-01-05 22:22 - 2012-01-05 22:22 - 01081368 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\ACE.dll
2016-09-26 14:17 - 2016-09-26 14:17 - 48936448 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2017-01-12 16:08 - 2016-12-08 02:00 - 00035792 _____ () C:\Program Files (x86)\Dropbox\Client_multiprocessing.pyd
2017-01-12 16:07 - 2016-12-08 02:00 - 00145864 _____ () C:\Program Files (x86)\Dropbox\Client\pyexpat.pyd
2017-01-12 16:07 - 2016-12-08 02:01 - 00019408 _____ () C:\Program Files (x86)\Dropbox\Client\faulthandler.pyd
2017-01-12 16:08 - 2016-12-08 02:00 - 00116688 _____ () C:\Program Files (x86)\Dropbox\Client\pywintypes27.dll
2017-01-12 16:08 - 2016-12-08 02:04 - 00024528 _____ () C:\Program Files (x86)\Dropbox\Client\win32event.pyd
2017-01-12 16:08 - 2016-12-08 02:00 - 00100296 _____ () C:\Program Files (x86)\Dropbox\Client_ctypes.pyd
2017-01-12 16:08 - 2016-12-08 02:04 - 00105928 _____ () C:\Program Files (x86)\Dropbox\Client\win32api.pyd
2017-01-12 16:08 - 2016-12-08 02:00 - 00018888 _____ () C:\Program Files (x86)\Dropbox\Client\select.pyd
2017-01-12 16:08 - 2017-01-06 01:04 - 00019776 _____ () C:\Program Files (x86)\Dropbox\Client\tornado.speedups.pyd
2017-01-12 16:08 - 2016-12-08 02:00 - 00694224 _____ () C:\Program Files (x86)\Dropbox\Client\unicodedata.pyd
2017-01-12 16:07 - 2017-01-06 01:03 - 00020824 ____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings.constant_time.pyd
2017-01-12 16:08 - 2016-12-08 02:01 - 00123856 ____ () C:\Program Files (x86)\Dropbox\Client_cffibackend.pyd
2017-01-12 16:07 - 2017-01-06 01:03 - 01682768 ____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings.openssl.pyd
2017-01-12 16:07 - 2017-01-06 01:03 - 00020816 ____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings.padding.pyd
2017-01-12 16:08 - 2017-01-06 01:04 - 00021328 ____ () C:\Program Files (x86)\Dropbox\Client\winffi.crt.compiled.winffi_crt.pyd
2017-01-12 16:07 - 2017-01-06 01:04 - 00052032 ____ () C:\Program Files (x86)\Dropbox\Client\psutil.psutil_windows.pyd
2017-01-12 16:07 - 2017-01-06 01:04 - 00038712 _____ () C:\Program Files (x86)\Dropbox\Client\fastpath.pyd
2017-01-12 16:08 - 2016-12-08 02:00 - 00392144 _____ () C:\Program Files (x86)\Dropbox\Client\pythoncom27.dll
2017-01-12 16:07 - 2016-12-08 02:04 - 00020936 _____ () C:\Program Files (x86)\Dropbox\Client\mmapfile.pyd
2017-01-12 16:08 - 2016-12-08 02:04 - 00116176 _____ () C:\Program Files (x86)\Dropbox\Client\win32security.pyd
2017-01-12 16:08 - 2017-01-06 01:04 - 00381760 _____ () C:\Program Files (x86)\Dropbox\Client\win32com.shell.shell.pyd
2017-01-12 16:08 - 2016-12-08 02:04 - 00124880 _____ () C:\Program Files (x86)\Dropbox\Client\win32file.pyd
2017-01-12 16:08 - 2017-01-06 01:04 - 00025432 ____ () C:\Program Files (x86)\Dropbox\Client\winffi.kernel32.compiled.winffi_kernel32.pyd
2017-01-12 16:08 - 2016-12-08 02:04 - 00024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32clipboard.pyd
2017-01-12 16:08 - 2016-12-08 02:04 - 00175560 _____ () C:\Program Files (x86)\Dropbox\Client\win32gui.pyd
2017-01-12 16:08 - 2016-12-08 02:04 - 00030160 _____ () C:\Program Files (x86)\Dropbox\Client\win32pipe.pyd
2017-01-12 16:08 - 2016-12-08 02:04 - 00043472 _____ () C:\Program Files (x86)\Dropbox\Client\win32process.pyd
2017-01-12 16:08 - 2016-12-08 02:04 - 00048592 _____ () C:\Program Files (x86)\Dropbox\Client\win32service.pyd
2017-01-12 16:08 - 2016-12-08 02:04 - 00057808 _____ () C:\Program Files (x86)\Dropbox\Client\win32evtlog.pyd
2017-01-12 16:08 - 2016-12-08 02:04 - 00024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32profile.pyd
2017-01-12 16:07 - 2017-01-06 01:03 - 00246608 _____ () C:\Program Files (x86)\Dropbox\Client\breakpad.client.windows.handler.pyd
2017-01-12 16:07 - 2017-01-06 01:03 - 00026464 ____ () C:\Program Files (x86)\Dropbox\Client\dropbox.infinite.win.compiled.driverinstallation.pyd
2017-01-12 16:08 - 2016-12-08 02:02 - 00241104 _____ () C:\Program Files (x86)\Dropbox\Client_jpegtran.pyd
2017-01-12 16:07 - 2017-01-06 01:03 - 00020288 ____ () C:\Program Files (x86)\Dropbox\Client\cpuid.compiled.cpuid.pyd
2017-01-12 16:08 - 2016-12-08 02:04 - 00028616 _____ () C:\Program Files (x86)\Dropbox\Client\win32ts.pyd
2017-01-12 16:08 - 2017-01-06 01:04 - 00023384 ____ () C:\Program Files (x86)\Dropbox\Client\winscreenshot.compiled.CaptureScreenshot.pyd
2017-01-12 16:08 - 2017-01-06 01:04 - 00020816 ____ () C:\Program Files (x86)\Dropbox\Client\winffi.iphlpapi.winffi_iphlpapi.pyd
2017-01-12 16:08 - 2017-01-06 01:04 - 00019792 ____ () C:\Program Files (x86)\Dropbox\Client\winffi.winerror.winffi_winerror.pyd
2017-01-12 16:08 - 2017-01-06 01:04 - 00020808 ____ () C:\Program Files (x86)\Dropbox\Client\winffi.wininet.winffi_wininet.pyd
2017-01-12 16:08 - 2016-12-08 02:04 - 00350152 _____ () C:\Program Files (x86)\Dropbox\Client\winxpgui.pyd
2017-01-12 16:08 - 2017-01-06 01:04 - 00022360 ____ () C:\Program Files (x86)\Dropbox\Client\winverifysignature.compiled.VerifySignature.pyd
2017-01-12 16:07 - 2017-01-06 01:04 - 00024400 ____ () C:\Program Files (x86)\Dropbox\Client\librsyncffi.compiled.librsyncffi.pyd
2017-01-12 16:07 - 2016-12-08 01:57 - 00036296 _____ () C:\Program Files (x86)\Dropbox\Client\librsync.dll
2017-01-12 16:07 - 2017-01-06 01:04 - 00031576 ____ () C:\Program Files (x86)\Dropbox\Client\enterprisedata.compiled.enterprisedata.pyd
2017-01-12 16:07 - 2016-12-22 03:04 - 00293392 _____ () C:\Program Files (x86)\Dropbox\Client\EnterpriseDataAdapter.dll
2017-01-12 16:07 - 2017-01-06 01:03 - 00084288 ____ () C:\Program Files (x86)\Dropbox\Client\dropboxsqlite_ext.DLL
2017-01-12 16:07 - 2017-01-06 01:04 - 01826104 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtCore.pyd
2017-01-12 16:08 - 2016-12-08 02:01 - 00083912 _____ () C:\Program Files (x86)\Dropbox\Client\sip.pyd
2017-01-12 16:07 - 2017-01-06 01:04 - 00531264 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtNetwork.pyd
2017-01-12 16:08 - 2017-01-06 01:04 - 03928896 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWidgets.pyd
2017-01-12 16:07 - 2017-01-06 01:04 - 01972536 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtGui.pyd
2017-01-12 16:08 - 2017-01-06 01:04 - 00133432 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKit.pyd
2017-01-12 16:08 - 2017-01-06 01:04 - 00224064 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKitWidgets.pyd
2017-01-12 16:07 - 2017-01-06 01:04 - 00207680 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtPrintSupport.pyd
2017-01-12 16:08 - 2017-01-06 01:04 - 00020296 ____ () C:\Program Files (x86)\Dropbox\Client\winffi.user32.winffi_user32.pyd
2017-01-12 16:07 - 2016-12-08 02:08 - 00017864 _____ () C:\Program Files (x86)\Dropbox\Client\libEGL.dll
2017-01-12 16:07 - 2016-12-08 02:08 - 01631184 _____ () C:\Program Files (x86)\Dropbox\Client\libGLESv2.dll
2017-01-12 16:07 - 2017-01-06 01:04 - 00042816 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebChannel.pyd
2017-01-12 16:07 - 2017-01-06 01:04 - 00171336 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebEngineWidgets.pyd
2017-01-12 16:07 - 2017-01-06 01:04 - 00357688 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQml.pyd
2017-01-12 16:08 - 2016-12-08 02:04 - 00060880 _____ () C:\Program Files (x86)\Dropbox\Client\win32print.pyd
2017-01-12 16:08 - 2017-01-06 01:04 - 00037200 ____ () C:\Program Files (x86)\Dropbox\Client\windisplaytoast.compiled.DisplayToast.pyd
2017-01-12 16:08 - 2017-01-06 01:04 - 00024920 ____ () C:\Program Files (x86)\Dropbox\Client\winffi.winhttp.compiled.winffi_winhttp.pyd
2017-01-12 16:07 - 2017-01-06 01:04 - 00546104 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQuick.pyd
2012-11-07 19:41 - 2012-03-29 07:18 - 01198872 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
AlternateDataStreams: C:\Users\Mohamed Elkheir\Desktop\2 Jurisdiktion & international beskyttelse af grundæggende rettigheder.doc:com.dropbox.attributes [168]
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
IE trusted site: HKU\S-1-5-21-2903169055-2215062143-4039091648-1000...\amazon.com ->
hxxps://amazon.comIE trusted site: HKU\S-1-5-21-2903169055-2215062143-4039091648-1000...\sharepoint.com ->
hxxps://studentsdudk.sharepoint.com==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 03:34 - 2016-04-13 06:45 - 00000035 ____A C:\WINDOWS\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-2903169055-2215062143-4039091648-1000\Control Panel\Desktop\Wallpaper -> c:\windows\web\wallpaper\acer01.jpg
DNS Servers: 10.0.0.1 - 212.242.40.3
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
HKLM...\StartupApproved\Run: => "RtHDVCpl"
HKLM...\StartupApproved\Run: => "RtHDVBg_Dolby"
HKLM...\StartupApproved\Run: => "Power Management"
HKLM...\StartupApproved\Run32: => "APSDaemon"
HKLM...\StartupApproved\Run32: => "HP Software Update"
HKLM...\StartupApproved\Run32: => "iTunesHelper"
HKLM...\StartupApproved\Run32: => "KiesTrayAgent"
HKLM...\StartupApproved\Run32: => "LManager"
HKU\S-1-5-21-2903169055-2215062143-4039091648-1000...\StartupApproved\StartupFolder: => "Send til OneNote.lnk"
HKU\S-1-5-21-2903169055-2215062143-4039091648-1000...\StartupApproved\Run: => "Dropbox Update"
HKU\S-1-5-21-2903169055-2215062143-4039091648-1000...\StartupApproved\Run: => "KiesPreload"
HKU\S-1-5-21-2903169055-2215062143-4039091648-1000...\StartupApproved\Run: => ""
HKU\S-1-5-21-2903169055-2215062143-4039091648-1000...\StartupApproved\Run: => "Spotify Web Helper"
HKU\S-1-5-21-2903169055-2215062143-4039091648-1000...\StartupApproved\Run: => "EPLTarget\P0000000000000000"
HKU\S-1-5-21-2903169055-2215062143-4039091648-1000...\StartupApproved\Run: => "EPLTarget\P0000000000000001"
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [vm-monitoring-nb-session] => LPort=139
FirewallRules: [UDP Query User{71187F35-94A2-42CD-B936-9A135E48B9E4}C:\program files (x86)\java\jre1.8.0_101\bin\jp2launcher.exe] => C:\program files (x86)\java\jre1.8.0_101\bin\jp2launcher.exe
FirewallRules: [TCP Query User{BA9D0E11-5D50-4EBF-9795-E8C29595C4F9}C:\program files (x86)\java\jre1.8.0_101\bin\jp2launcher.exe] => C:\program files (x86)\java\jre1.8.0_101\bin\jp2launcher.exe
FirewallRules: [{79B2B3C1-A561-4EFE-A11C-C1F54AF18C74}] => C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{DE06BD39-5B9D-4711-B76F-B65A08FA5469}] => C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{DB61FEE3-7DFC-4313-8BC0-CCBBE9D8B49D}] => C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{AA4F6372-98DD-46CC-9061-9B519769A422}] => C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [UDP Query User{507E2A3E-00EB-4F0C-AFF3-BECA73DAA719}C:\program files (x86)\java\jre1.8.0_91\bin\jp2launcher.exe] => C:\program files (x86)\java\jre1.8.0_91\bin\jp2launcher.exe
FirewallRules: [TCP Query User{0D4226D2-34C9-48EB-B3F0-BE7845F9BF69}C:\program files (x86)\java\jre1.8.0_91\bin\jp2launcher.exe] => C:\program files (x86)\java\jre1.8.0_91\bin\jp2launcher.exe
FirewallRules: [{D753266C-CAAE-4023-94A6-60529C1A9D66}] => C:\Users\Mohamed Elkheir\AppData\Local\Temp\EpInsNav\DL\3013\Network\EpsonNetSetup\EpsonNetSetup\Data\ENEasyApp.exe
FirewallRules: [{603A69DE-F061-46D3-B217-E7A769DC263E}] => C:\Users\Mohamed Elkheir\AppData\Local\Temp\EpInsNav\DL\3013\Network\EpsonNetSetup\EpsonNetSetup\Data\ENEasyApp.exe
FirewallRules: [TCP Query User{AF3D4CA1-0657-420B-8FB0-BB6155C5E17E}C:\program files\hp\hp deskjet 3520 series\bin\hpnetworkcommunicator.exe] => C:\program files\hp\hp deskjet 3520 series\bin\hpnetworkcommunicator.exe
FirewallRules: [UDP Query User{0035E19D-B620-4648-AA57-B26F3EA055A6}C:\program files\hp\hp deskjet 3520 series\bin\hpnetworkcommunicator.exe] => C:\program files\hp\hp deskjet 3520 series\bin\hpnetworkcommunicator.exe
FirewallRules: [TCP Query User{A9B1583F-024E-41D8-BDF4-3C13CC876025}C:\program files\acer\acer theft shield\usecuappclient.exe] => C:\program files\acer\acer theft shield\usecuappclient.exe
FirewallRules: [UDP Query User{D7DB3C6D-720E-4353-A7C6-5CDAE325AC44}C:\program files\acer\acer theft shield\usecuappclient.exe] => C:\program files\acer\acer theft shield\usecuappclient.exe
FirewallRules: [TCP Query User{A2FCEF23-61BE-418D-AD22-E6DEF700AEF6}C:\program files\hp\hp deskjet 3520 series\bin\hpnetworkcommunicator.exe] => C:\program files\hp\hp deskjet 3520 series\bin\hpnetworkcommunicator.exe
FirewallRules: [UDP Query User{63216E2A-2E36-42FF-A981-A6D442CD37E9}C:\program files\hp\hp deskjet 3520 series\bin\hpnetworkcommunicator.exe] => C:\program files\hp\hp deskjet 3520 series\bin\hpnetworkcommunicator.exe
FirewallRules: [TCP Query User{B72CC1D4-F5CC-4460-90FC-268498D8FC1E}C:\program files\acer\acer theft shield\usecuappclient.exe] => C:\program files\acer\acer theft shield\usecuappclient.exe
FirewallRules: [UDP Query User{88A1B07A-80A3-46EF-A539-889C734513FA}C:\program files\acer\acer theft shield\usecuappclient.exe] => C:\program files\acer\acer theft shield\usecuappclient.exe
FirewallRules: [TCP Query User{7029674F-335D-4469-99E8-EFB917976003}C:\program files\java\jre1.8.0_66\bin\jp2launcher.exe] => C:\program files\java\jre1.8.0_66\bin\jp2launcher.exe
FirewallRules: [UDP Query User{A009ACA9-2F7A-48FE-B1B7-7A4810531A58}C:\program files\java\jre1.8.0_66\bin\jp2launcher.exe] => C:\program files\java\jre1.8.0_66\bin\jp2launcher.exe
FirewallRules: [TCP Query User{6E49D5FD-F2F3-4861-BD9D-FBCB09D3F588}C:\program files\maple 18\jre\bin\maple.exe] => C:\program files\maple 18\jre\bin\maple.exe
FirewallRules: [UDP Query User{AB62175E-49BF-4164-8293-3F37D8C2BDA3}C:\program files\maple 18\jre\bin\maple.exe] => C:\program files\maple 18\jre\bin\maple.exe
FirewallRules: [TCP Query User{662FF917-56F3-46D5-B7F9-A3160A0D76B5}C:\program files\maple 18\jre\bin\maple.exe] => C:\program files\maple 18\jre\bin\maple.exe
FirewallRules: [UDP Query User{A6C8A617-FDE5-4C09-9140-97D3E71496E6}C:\program files\maple 18\jre\bin\maple.exe] => C:\program files\maple 18\jre\bin\maple.exe
FirewallRules: [{5FBC05EB-DA6A-4FD7-8731-F296B6D04E41}] => C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{679D7455-0750-4E65-A888-AA599F5E736C}] => C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [{6376EFC3-E387-487F-B724-CD518A9214A7}] => C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{E2FE4CF3-286A-4B0A-89A8-FFA5B5DF33D0}] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{0E124B17-C09F-470C-8A97-BB2AFB1CE062}] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
==================== Restore Points =========================
30-12-2016 12:05:05 Windows Update
02-01-2017 19:01:48 Windows Update
05-01-2017 19:25:52 Windows Update
12-01-2017 16:30:44 Windows Update
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
Error: (01/14/2017 12:18:27 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Aktiveringskontekstgenereringen mislykkedes for "c:\program files (x86)\nero\nero 12\nero backitup\NBCore.exe".
Afhængig samling Nfx.SmmContracts,processorArchitecture="msil",publicKeyToken="160f5391b5b5d5d4",version="11.1.0.0" blev ikke fundet.
Anvend sxstrace.exe til detaljeret diagnose.
Error: (01/14/2017 12:17:56 PM) (Source: ESENT) (EventID: 490) (User: )
Description: taskhostw (4576) WebCacheLocal: An attempt to open the file "C:\Users\Mohamed Elkheir\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.jfm" for read / write access failed with system error 32 (0x00000020): "Processen kan ikke få adgang til filen, da den bruges af en anden proces. ". The open file operation will fail with error -1032 (0xfffffbf8).
Error: (01/14/2017 12:17:31 PM) (Source: SideBySide) (EventID: 9) (User: )
Description: Aktiveringskontekstgenereringen mislykkedes for "C:\Program Files\WinZip\adxloader.dll.Manifest". Der er en fejl i manifestet eller politikfilen "C:\Program Files\WinZip\adxloader.dll.Manifest" i linje 2.
Manifestfilens rodelement skal være assembly.
Error: (01/14/2017 12:17:27 PM) (Source: ESENT) (EventID: 490) (User: )
Description: DllHost (8700) WebCacheLocal: An attempt to open the file "C:\Users\Mohamed Elkheir\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.jfm" for read / write access failed with system error 32 (0x00000020): "Processen kan ikke få adgang til filen, da den bruges af en anden proces. ". The open file operation will fail with error -1032 (0xfffffbf8).
Error: (01/14/2017 12:17:17 PM) (Source: ESENT) (EventID: 454) (User: )
Description: DllHost (8700) WebCacheLocal: Database recovery/restore failed with unexpected error -1032.
Error: (01/14/2017 12:17:17 PM) (Source: ESENT) (EventID: 490) (User: )
Description: DllHost (8700) WebCacheLocal: An attempt to open the file "C:\Users\Mohamed Elkheir\AppData\Local\Microsoft\Windows\WebCache\V01.log" for read / write access failed with system error 32 (0x00000020): "Processen kan ikke få adgang til filen, da den bruges af en anden proces. ". The open file operation will fail with error -1032 (0xfffffbf8).
Error: (01/14/2017 12:17:06 PM) (Source: ESENT) (EventID: 490) (User: )
Description: DllHost (8700) WebCacheLocal: An attempt to open the file "C:\Users\Mohamed Elkheir\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat" for read / write access failed with system error 32 (0x00000020): "Processen kan ikke få adgang til filen, da den bruges af en anden proces. ". The open file operation will fail with error -1032 (0xfffffbf8).
Error: (01/14/2017 12:16:56 PM) (Source: ESENT) (EventID: 454) (User: )
Description: taskhostw (4576) WebCacheLocal: Database recovery/restore failed with unexpected error -1032.
Error: (01/14/2017 12:16:56 PM) (Source: ESENT) (EventID: 490) (User: )
Description: taskhostw (4576) WebCacheLocal: An attempt to open the file "C:\Users\Mohamed Elkheir\AppData\Local\Microsoft\Windows\WebCache\V01.log" for read / write access failed with system error 32 (0x00000020): "Processen kan ikke få adgang til filen, da den bruges af en anden proces. ". The open file operation will fail with error -1032 (0xfffffbf8).
Error: (01/14/2017 12:10:17 PM) (Source: DbxSvc) (EventID: 320) (User: )
Description: Failed to connect to the driver: (-2147024894) Den angivne fil blev ikke fundet.
System errors:
Error: (01/14/2017 12:10:32 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Adgangsindstillingerne programspecifikke giver ikke Lokal Aktivering adgang til COM-serverprogrammet med CLSID
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
og APPID
{F72671A9-012C-4725-9D2F-2A4D32D65169}
for brugeren NT AUTHORITY\SYSTEM SID (S-1-5-18) fra adressen LocalHost (via LRPC), der kører i programbeholderen Ikke tilgængelig SID (Ikke tilgængelig). Denne sikkerhedstilladelse kan redigeres ved hjælp af administrationsværktøjet til komponenttjenester.
Error: (01/14/2017 12:09:51 PM) (Source: Microsoft-Windows-HAL) (EventID: 13) (User: NT AUTHORITY)
Description: Systemets watchdog-timer blev udløst.
Error: (01/14/2017 12:10:11 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: Den foregående systemlukning kl. 12:05:55 d. ?14-?01-?2017 var uventet.
Error: (01/14/2017 12:00:04 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Der opstod en timeout (30000 millisekunder), mens der ventedes på et transaktionssvar fra tjenesten iphlpsvc.
Error: (01/14/2017 12:12:00 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Der opstod en timeout (30000 millisekunder), mens der ventedes på et transaktionssvar fra tjenesten DsiWMIService.
Error: (01/14/2017 12:10:56 AM) (Source: DCOM) (EventID: 10010) (User: MOHAMEDELKHEIR)
Description: Serveren {4AA0A5C4-1B9B-4F2E-99D7-99C6AEC83474} blev ikke registreret af DCOM inden for det specificerede tidsrum.
Error: (01/13/2017 08:14:03 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installationsfejl: Der opstod en fejl, da Windows skulle installere følgende opdatering 0x800f020b: Hewlett-Packard - Imaging - Null Print - HP Deskjet 3520 series.
Error: (01/13/2017 07:08:57 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installationsfejl: Der opstod en fejl, da Windows skulle installere følgende opdatering 0x800f020b: Hewlett-Packard - Imaging - Null Print - HP Deskjet 3520 series.
Error: (01/13/2017 06:41:11 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Adgangsindstillingerne programspecifikke giver ikke Lokal Aktivering adgang til COM-serverprogrammet med CLSID
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
og APPID
{F72671A9-012C-4725-9D2F-2A4D32D65169}
for brugeren NT AUTHORITY\SYSTEM SID (S-1-5-18) fra adressen LocalHost (via LRPC), der kører i programbeholderen Ikke tilgængelig SID (Ikke tilgængelig). Denne sikkerhedstilladelse kan redigeres ved hjælp af administrationsværktøjet til komponenttjenester.
Error: (01/13/2017 12:23:07 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Adgangsindstillingerne programspecifikke giver ikke Lokal Aktivering adgang til COM-serverprogrammet med CLSID
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
og APPID
{F72671A9-012C-4725-9D2F-2A4D32D65169}
for brugeren NT AUTHORITY\SYSTEM SID (S-1-5-18) fra adressen LocalHost (via LRPC), der kører i programbeholderen Ikke tilgængelig SID (Ikke tilgængelig). Denne sikkerhedstilladelse kan redigeres ved hjælp af administrationsværktøjet til komponenttjenester.
CodeIntegrity:
Date: 2016-12-08 14:23:31.419
Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files (x86)\Dropbox\Client\DropboxExt64.3.0.dll that did not meet the Store signing level requirements.
Date: 2016-12-08 14:23:31.419
Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files (x86)\Dropbox\Client\DropboxExt64.3.0.dll that did not meet the Store signing level requirements.
Date: 2016-12-08 14:23:31.419
Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files (x86)\Dropbox\Client\DropboxExt64.3.0.dll that did not meet the Store signing level requirements.
Date: 2016-12-08 14:23:31.144
Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files (x86)\Bluetooth Suite\AthCopyHook.dll that did not meet the Store signing level requirements.
Date: 2016-12-08 14:23:31.144
Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files (x86)\Bluetooth Suite\AthCopyHook.dll that did not meet the Store signing level requirements.
Date: 2016-12-08 14:23:31.144
Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files (x86)\Bluetooth Suite\AthCopyHook.dll that did not meet the Store signing level requirements.
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i5-3317U CPU @ 1.70GHz
Percentage of memory in use: 50%
Total physical RAM: 3934.35 MB
Available physical RAM: 1951.14 MB
Total Virtual: 7902.35 MB
Available Virtual: 5666.94 MB
==================== Drives ================================
Drive c: (ACER) (Fixed) (Total:449.74 GB) (Free:340.26 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: BE0BFCB2)
Partition 1: (Not Active) - (Size=15.1 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=449.7 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=802 MB) - (Type=27)
========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 18.6 GB) (Disk ID: 3E21AACB)
Partition 1: (Not Active) - (Size=4 GB) - (Type=84)
Partition 2: (Not Active) - (Size=14.6 GB) - (Type=73)
==================== End of Addition.txt ============================