S Sezneg Member Joined May 7, 2016 Posts 19 May 7, 2016 #1 I cleared a malware/trojan infection that has left corrupt files behind. Here is the SFCfix log: SFCFix version 3.0.0.0 by niemiro. Start time: 2016-05-01 21:36:44.875 Microsoft Windows 10 Build 10586 - amd64 Not using a script file. AutoAnalysis:: WARNING: Failed to get store name from identity name with return code 2 for component Microsoft-Windows-iSCSI_Initiator_UI and file iSCSI Initiator.lnk. File is reported as corrupt by SFC. CORRUPT: iSCSI Initiator.lnk of component Microsoft-Windows-iSCSI_Initiator_UI. WARNING: Failed to get store name from identity name with return code 2 for component Microsoft-Windows-Microsoft-Data-Access-Components-(MDAC)-ODBC-Administrator and file ODBC Data Sources (64-bit).lnk. File is reported as corrupt by SFC. CORRUPT: ODBC Data Sources (64-bit).lnk of component Microsoft-Windows-Microsoft-Data-Access-Components-(MDAC)-ODBC-Administrator. WARNING: Failed to get store name from identity name with return code 2 for component Microsoft-Windows-Microsoft-Data-Access-Components-(MDAC)-ODBC-Administrator and file ODBC Data Sources (32-bit).lnk. File is reported as corrupt by SFC. CORRUPT: ODBC Data Sources (32-bit).lnk of component Microsoft-Windows-Microsoft-Data-Access-Components-(MDAC)-ODBC-Administrator. SUMMARY: Some corruptions could not be fixed automatically. Seek advice from helper or sysnative.com. CBS & SFC total detected corruption count: 3 CBS & SFC total unimportant corruption count: 0 CBS & SFC total fixed corruption count: 0 SURT total detected corruption count: 0 SURT total unimportant corruption count: 0 SURT total fixed corruption count: 0 AutoAnalysis:: directive completed successfully. Successfully processed all directives. SFCFix version 3.0.0.0 by niemiro has completed. Currently storing 0 datablocks. Finish time: 2016-05-01 21:42:23.685 ----------------------EOF-----------------------
I cleared a malware/trojan infection that has left corrupt files behind. Here is the SFCfix log: SFCFix version 3.0.0.0 by niemiro. Start time: 2016-05-01 21:36:44.875 Microsoft Windows 10 Build 10586 - amd64 Not using a script file. AutoAnalysis:: WARNING: Failed to get store name from identity name with return code 2 for component Microsoft-Windows-iSCSI_Initiator_UI and file iSCSI Initiator.lnk. File is reported as corrupt by SFC. CORRUPT: iSCSI Initiator.lnk of component Microsoft-Windows-iSCSI_Initiator_UI. WARNING: Failed to get store name from identity name with return code 2 for component Microsoft-Windows-Microsoft-Data-Access-Components-(MDAC)-ODBC-Administrator and file ODBC Data Sources (64-bit).lnk. File is reported as corrupt by SFC. CORRUPT: ODBC Data Sources (64-bit).lnk of component Microsoft-Windows-Microsoft-Data-Access-Components-(MDAC)-ODBC-Administrator. WARNING: Failed to get store name from identity name with return code 2 for component Microsoft-Windows-Microsoft-Data-Access-Components-(MDAC)-ODBC-Administrator and file ODBC Data Sources (32-bit).lnk. File is reported as corrupt by SFC. CORRUPT: ODBC Data Sources (32-bit).lnk of component Microsoft-Windows-Microsoft-Data-Access-Components-(MDAC)-ODBC-Administrator. SUMMARY: Some corruptions could not be fixed automatically. Seek advice from helper or sysnative.com. CBS & SFC total detected corruption count: 3 CBS & SFC total unimportant corruption count: 0 CBS & SFC total fixed corruption count: 0 SURT total detected corruption count: 0 SURT total unimportant corruption count: 0 SURT total fixed corruption count: 0 AutoAnalysis:: directive completed successfully. Successfully processed all directives. SFCFix version 3.0.0.0 by niemiro has completed. Currently storing 0 datablocks. Finish time: 2016-05-01 21:42:23.685 ----------------------EOF-----------------------
Aura Sysnative Staff, Security Analyst Staff member Joined Mar 16, 2015 Posts 8,061 May 7, 2016 #2 Hi again Sezneg :) Looks like I'll need a full CBS.log to see which files are needed to replace the corrupt ones. Follow the instructions below please. System File Checker (SFC) Follow the instructions below to run a SFC scan on your system and to provide the CBS log in your next reply; On Windows Vista & 7, click on the Windows Start Menu, then enter cmd in the search box, right-click on the cmd icon and select Run as Administrator On Windows 8, drag your cursor in the bottom-left corner, and right-click on the metro menu preview, then select Command Prompt (Admin); On Windows 8.1, right click on the Windows logo in the bottom-left corner and select Command Prompt (Admin); Enter the command below and press on Enter; Code: sfc /scannow Note: There's a space between "sfc" and "/scannow"; Once the scan is complete, enter the command below and press on Enter Code: copy %windir%\logs\cbs\cbs.log "%userprofile%\Desktop\cbs.txt" A file called cbs.txt will have appeared on your Desktop. Upload the file on Dropbox, Google Drive or OneDrive and post the download URL for it here; Note: Please note that the CBS.log is volatile, which means that if you don't upload it after the SFC scan is completed, it won't have the information from the scan anymore. So archive it and upload it as soon as you can.
Hi again Sezneg :) Looks like I'll need a full CBS.log to see which files are needed to replace the corrupt ones. Follow the instructions below please. System File Checker (SFC) Follow the instructions below to run a SFC scan on your system and to provide the CBS log in your next reply; On Windows Vista & 7, click on the Windows Start Menu, then enter cmd in the search box, right-click on the cmd icon and select Run as Administrator On Windows 8, drag your cursor in the bottom-left corner, and right-click on the metro menu preview, then select Command Prompt (Admin); On Windows 8.1, right click on the Windows logo in the bottom-left corner and select Command Prompt (Admin); Enter the command below and press on Enter; Code: sfc /scannow Note: There's a space between "sfc" and "/scannow"; Once the scan is complete, enter the command below and press on Enter Code: copy %windir%\logs\cbs\cbs.log "%userprofile%\Desktop\cbs.txt" A file called cbs.txt will have appeared on your Desktop. Upload the file on Dropbox, Google Drive or OneDrive and post the download URL for it here; Note: Please note that the CBS.log is volatile, which means that if you don't upload it after the SFC scan is completed, it won't have the information from the scan anymore. So archive it and upload it as soon as you can.
Aura Sysnative Staff, Security Analyst Staff member Joined Mar 16, 2015 Posts 8,061 May 7, 2016 #4 That's a lot of corrupt file, way more than the 3 originally reported by SFCFix. Let's run a DISM scan to get a clean output, it'll make sourcing them way easier. DISM - Fixing Component Store Corruption Follow the instructions below to run a DISM operation on your system. On Windows 8, drag your cursor in the bottom-left corner, and right-click on the metro menu preview, then select Command Prompt (Admin); On Windows 8.1, right click on the Windows logo in the bottom-left corner and select Command Prompt (Admin); Enter the command below and press on Enter; Code: DISM /Online /Cleanup-Image /RestoreHealth Let the scan run until the end (100%). Depending on your system, it can take some time; Copy the C:\Windows\Logs\DISM folder and C:\Windows\Logs\CBS\CBS.log file on your Desktop, then right-click on it, go to Send to... and select Compressed .zip archive; Upload the file on Dropbox, Google Drive or OneDrive and post the download URL for it here; Note: Please note that the CBS.log is volatile, which means that if you don't upload it after the DISM scan is completed, it won't contains the information from the scan anymore. So archive it and upload it as soon as you can.
That's a lot of corrupt file, way more than the 3 originally reported by SFCFix. Let's run a DISM scan to get a clean output, it'll make sourcing them way easier. DISM - Fixing Component Store Corruption Follow the instructions below to run a DISM operation on your system. On Windows 8, drag your cursor in the bottom-left corner, and right-click on the metro menu preview, then select Command Prompt (Admin); On Windows 8.1, right click on the Windows logo in the bottom-left corner and select Command Prompt (Admin); Enter the command below and press on Enter; Code: DISM /Online /Cleanup-Image /RestoreHealth Let the scan run until the end (100%). Depending on your system, it can take some time; Copy the C:\Windows\Logs\DISM folder and C:\Windows\Logs\CBS\CBS.log file on your Desktop, then right-click on it, go to Send to... and select Compressed .zip archive; Upload the file on Dropbox, Google Drive or OneDrive and post the download URL for it here; Note: Please note that the CBS.log is volatile, which means that if you don't upload it after the DISM scan is completed, it won't contains the information from the scan anymore. So archive it and upload it as soon as you can.
S Sezneg Member Joined May 7, 2016 Posts 19 May 7, 2016 #5 DISM failed with Error: 0x800f081f Here are the logs: dism.log - Google Drive CBS.log - Google Drive
Aura Sysnative Staff, Security Analyst Staff member Joined Mar 16, 2015 Posts 8,061 May 7, 2016 #6 Alright, it took me a bit to put a fix together, but here goes. SFCFix - Fix Time WARNING! The following fix is specific to the user's system in this thread. No one else should follow the instructions below to apply that fix, as it could damage your system. If you need assistance with an issue, please start a new thread and someone will assist you shortly. Follow the instructions below to download and execute a SFCFix fix, and provide the log. Download SFCFix and move the executable on your Desktop; Download the attached SFCFix.zip and move the archive to your Desktop; Note: Make sure that the file is named SFCFix.zip, do not rename it. Save any work you have open, and close every programs; Drag the SFCFix.zip archive file over the SFCFix.exe executable and release it; SFCFix will launch, let it complete; Once done, a file will appear on your Desktop, called SFCFix.txt; Open the file, then copy and paste its content in your next reply; SFCFix.zip
Alright, it took me a bit to put a fix together, but here goes. SFCFix - Fix Time WARNING! The following fix is specific to the user's system in this thread. No one else should follow the instructions below to apply that fix, as it could damage your system. If you need assistance with an issue, please start a new thread and someone will assist you shortly. Follow the instructions below to download and execute a SFCFix fix, and provide the log. Download SFCFix and move the executable on your Desktop; Download the attached SFCFix.zip and move the archive to your Desktop; Note: Make sure that the file is named SFCFix.zip, do not rename it. Save any work you have open, and close every programs; Drag the SFCFix.zip archive file over the SFCFix.exe executable and release it; SFCFix will launch, let it complete; Once done, a file will appear on your Desktop, called SFCFix.txt; Open the file, then copy and paste its content in your next reply; SFCFix.zip
S Sezneg Member Joined May 7, 2016 Posts 19 May 7, 2016 #7 Here it is: SFCFix version 3.0.0.0 by niemiro. Start time: 2016-05-07 22:18:50.769 Microsoft Windows 10 Build 10586 - amd64 Using .zip script file at C:\Users\Matthew\Desktop\SFCFix.zip [0] PowerCopy:: Successfully took permissions for file or folder C:\WINDOWS\winsxs\wow64_microsoft-windows-m..-odbc-administrator_31bf3856ad364e35_10.0.10586.0_none_db2a2a091c6f0159\ODBC Data Sources (32-bit).lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_windows-defender-ui_31bf3856ad364e35_10.0.10586.0_none_a28eb67a8a54ab2a\Windows Defender.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_taskschedulersettings_31bf3856ad364e35_10.0.10586.0_none_d7709c22aeb417b7\Task Scheduler.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_networking-mpssvc-shortcut_31bf3856ad364e35_10.0.10586.0_none_11dc8d62b71c6074\Windows Firewall with Advanced Security.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_microsoft-windows-xpsreachviewer_31bf3856ad364e35_10.0.10586.0_none_a1a0ebd8f88eb4bf\XPS Viewer.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_microsoft-windows-wordpad_31bf3856ad364e35_10.0.10586.0_none_ba40118c173cb7f2\Wordpad.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_microsoft-windows-t..minalservicesclient_31bf3856ad364e35_10.0.10586.0_none_da61e5edcb6ec32f\Remote Desktop Connection.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_microsoft-windows-t..etpc-mathinputpanel_31bf3856ad364e35_10.0.10586.0_none_57271b70fb42a4a1\Math Input Panel.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_microsoft-windows-sud-link_31bf3856ad364e35_10.0.10586.0_none_5bb3b3b77727a42e\Default Programs.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_microsoft-windows-stickynotes-app_31bf3856ad364e35_10.0.10586.0_none_79cc4f5663a2c321\Sticky Notes.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_microsoft-windows-speech-userexperience_31bf3856ad364e35_10.0.10586.0_none_a88f8863f623d2ed\Speech Recognition.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_microsoft-windows-snippingtool-app_31bf3856ad364e35_10.0.10586.0_none_26499a8833fa2713\Snipping Tool.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_10.0.10586.0_none_5be97afcf0121814\services.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_microsoft-windows-s..ment-policytools-ex_31bf3856ad364e35_10.0.10586.0_none_e5e4edf6eb6cd204\Security Configuration Management.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_microsoft-windows-performancetoolsgui_31bf3856ad364e35_10.0.10586.0_none_288f56844b4b2341\Performance Monitor.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_microsoft-windows-performancetoolsgui_31bf3856ad364e35_10.0.10586.0_none_288f56844b4b2341\Resource Monitor.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_microsoft-windows-p..erandprintui-pmcppc_31bf3856ad364e35_10.0.10586.0_none_97edda452b08d8b9\Print Management.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_microsoft-windows-mspaint_31bf3856ad364e35_10.0.10586.0_none_1aa31efd98e8ec4b\Paint.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_microsoft-windows-msinfo32-exe_31bf3856ad364e35_10.0.10586.0_none_3861ff2fa4057c69\System Information.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_microsoft-windows-msconfig-exe_31bf3856ad364e35_10.0.10586.0_none_66ffd6dc481743c2\System Configuration.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_microsoft-windows-mediaplayer-shortcut_31bf3856ad364e35_10.0.10586.0_none_3b570a9cf80c90b7\Windows Media Player.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_microsoft-windows-m..diagnostic-schedule_31bf3856ad364e35_10.0.10586.0_none_205c3495240eb77a\Memory Diagnostics Tool.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_microsoft-windows-m..-odbc-administrator_31bf3856ad364e35_10.0.10586.0_none_d0d57fb6e80e3f5e\ODBC Data Sources (64-bit).lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_microsoft-windows-iscsi_initiator_ui_31bf3856ad364e35_10.0.10586.0_none_6470c30a06691255\iSCSI Initiator.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_microsoft-windows-f..client-applications_31bf3856ad364e35_10.0.10586.0_none_057f44bfd2bd9812\Windows Fax and Scan.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_microsoft-windows-defrag-adminui_31bf3856ad364e35_10.0.10586.0_none_259ba7173a9c269a\dfrgui.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_microsoft-windows-cleanmgr_31bf3856ad364e35_10.0.10586.0_none_f9c9ceba07e30464\Disk Cleanup.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_microsoft-windows-charmap_31bf3856ad364e35_10.0.10586.0_none_7edf55b74eb25a19\Character Map.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_microsoft-windows-c..termanagementsnapin_31bf3856ad364e35_10.0.10586.0_none_d79bb88420ae2d66\Computer Management.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_microsoft-windows-c..s-admin-compsvclink_31bf3856ad364e35_10.0.10586.0_none_5f17ea2284d04ef8\Component Services.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_microsoft-windows-advancedtaskmanager_31bf3856ad364e35_10.0.10586.0_none_3b6c733895d68477\Task Manager.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_microsoft-windows-a..roblemstepsrecorder_31bf3856ad364e35_10.0.10586.0_none_67772984f550f61f\Steps Recorder.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_eventviewersettings_31bf3856ad364e35_10.0.10586.0_none_817d705fae0a5733\Event Viewer.lnk Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\wow64_microsoft-windows-m..-odbc-administrator_31bf3856ad364e35_10.0.10586.0_none_db2a2a091c6f0159\ODBC Data Sources (32-bit).lnk to C:\WINDOWS\winsxs\wow64_microsoft-windows-m..-odbc-administrator_31bf3856ad364e35_10.0.10586.0_none_db2a2a091c6f0159\ODBC Data Sources (32-bit).lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_windows-defender-ui_31bf3856ad364e35_10.0.10586.0_none_a28eb67a8a54ab2a\Windows Defender.lnk to C:\WINDOWS\winsxs\amd64_windows-defender-ui_31bf3856ad364e35_10.0.10586.0_none_a28eb67a8a54ab2a\Windows Defender.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_taskschedulersettings_31bf3856ad364e35_10.0.10586.0_none_d7709c22aeb417b7\Task Scheduler.lnk to C:\WINDOWS\winsxs\amd64_taskschedulersettings_31bf3856ad364e35_10.0.10586.0_none_d7709c22aeb417b7\Task Scheduler.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_networking-mpssvc-shortcut_31bf3856ad364e35_10.0.10586.0_none_11dc8d62b71c6074\Windows Firewall with Advanced Security.lnk to C:\WINDOWS\winsxs\amd64_networking-mpssvc-shortcut_31bf3856ad364e35_10.0.10586.0_none_11dc8d62b71c6074\Windows Firewall with Advanced Security.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_microsoft-windows-xpsreachviewer_31bf3856ad364e35_10.0.10586.0_none_a1a0ebd8f88eb4bf\XPS Viewer.lnk to C:\WINDOWS\winsxs\amd64_microsoft-windows-xpsreachviewer_31bf3856ad364e35_10.0.10586.0_none_a1a0ebd8f88eb4bf\XPS Viewer.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_microsoft-windows-wordpad_31bf3856ad364e35_10.0.10586.0_none_ba40118c173cb7f2\Wordpad.lnk to C:\WINDOWS\winsxs\amd64_microsoft-windows-wordpad_31bf3856ad364e35_10.0.10586.0_none_ba40118c173cb7f2\Wordpad.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_microsoft-windows-t..minalservicesclient_31bf3856ad364e35_10.0.10586.0_none_da61e5edcb6ec32f\Remote Desktop Connection.lnk to C:\WINDOWS\winsxs\amd64_microsoft-windows-t..minalservicesclient_31bf3856ad364e35_10.0.10586.0_none_da61e5edcb6ec32f\Remote Desktop Connection.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_microsoft-windows-t..etpc-mathinputpanel_31bf3856ad364e35_10.0.10586.0_none_57271b70fb42a4a1\Math Input Panel.lnk to C:\WINDOWS\winsxs\amd64_microsoft-windows-t..etpc-mathinputpanel_31bf3856ad364e35_10.0.10586.0_none_57271b70fb42a4a1\Math Input Panel.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_microsoft-windows-sud-link_31bf3856ad364e35_10.0.10586.0_none_5bb3b3b77727a42e\Default Programs.lnk to C:\WINDOWS\winsxs\amd64_microsoft-windows-sud-link_31bf3856ad364e35_10.0.10586.0_none_5bb3b3b77727a42e\Default Programs.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_microsoft-windows-stickynotes-app_31bf3856ad364e35_10.0.10586.0_none_79cc4f5663a2c321\Sticky Notes.lnk to C:\WINDOWS\winsxs\amd64_microsoft-windows-stickynotes-app_31bf3856ad364e35_10.0.10586.0_none_79cc4f5663a2c321\Sticky Notes.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_microsoft-windows-speech-userexperience_31bf3856ad364e35_10.0.10586.0_none_a88f8863f623d2ed\Speech Recognition.lnk to C:\WINDOWS\winsxs\amd64_microsoft-windows-speech-userexperience_31bf3856ad364e35_10.0.10586.0_none_a88f8863f623d2ed\Speech Recognition.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_microsoft-windows-snippingtool-app_31bf3856ad364e35_10.0.10586.0_none_26499a8833fa2713\Snipping Tool.lnk to C:\WINDOWS\winsxs\amd64_microsoft-windows-snippingtool-app_31bf3856ad364e35_10.0.10586.0_none_26499a8833fa2713\Snipping Tool.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_10.0.10586.0_none_5be97afcf0121814\services.lnk to C:\WINDOWS\winsxs\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_10.0.10586.0_none_5be97afcf0121814\services.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_microsoft-windows-s..ment-policytools-ex_31bf3856ad364e35_10.0.10586.0_none_e5e4edf6eb6cd204\Security Configuration Management.lnk to C:\WINDOWS\winsxs\amd64_microsoft-windows-s..ment-policytools-ex_31bf3856ad364e35_10.0.10586.0_none_e5e4edf6eb6cd204\Security Configuration Management.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_microsoft-windows-performancetoolsgui_31bf3856ad364e35_10.0.10586.0_none_288f56844b4b2341\Performance Monitor.lnk to C:\WINDOWS\winsxs\amd64_microsoft-windows-performancetoolsgui_31bf3856ad364e35_10.0.10586.0_none_288f56844b4b2341\Performance Monitor.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_microsoft-windows-performancetoolsgui_31bf3856ad364e35_10.0.10586.0_none_288f56844b4b2341\Resource Monitor.lnk to C:\WINDOWS\winsxs\amd64_microsoft-windows-performancetoolsgui_31bf3856ad364e35_10.0.10586.0_none_288f56844b4b2341\Resource Monitor.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_microsoft-windows-p..erandprintui-pmcppc_31bf3856ad364e35_10.0.10586.0_none_97edda452b08d8b9\Print Management.lnk to C:\WINDOWS\winsxs\amd64_microsoft-windows-p..erandprintui-pmcppc_31bf3856ad364e35_10.0.10586.0_none_97edda452b08d8b9\Print Management.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_microsoft-windows-mspaint_31bf3856ad364e35_10.0.10586.0_none_1aa31efd98e8ec4b\Paint.lnk to C:\WINDOWS\winsxs\amd64_microsoft-windows-mspaint_31bf3856ad364e35_10.0.10586.0_none_1aa31efd98e8ec4b\Paint.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_microsoft-windows-msinfo32-exe_31bf3856ad364e35_10.0.10586.0_none_3861ff2fa4057c69\System Information.lnk to C:\WINDOWS\winsxs\amd64_microsoft-windows-msinfo32-exe_31bf3856ad364e35_10.0.10586.0_none_3861ff2fa4057c69\System Information.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_microsoft-windows-msconfig-exe_31bf3856ad364e35_10.0.10586.0_none_66ffd6dc481743c2\System Configuration.lnk to C:\WINDOWS\winsxs\amd64_microsoft-windows-msconfig-exe_31bf3856ad364e35_10.0.10586.0_none_66ffd6dc481743c2\System Configuration.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_microsoft-windows-mediaplayer-shortcut_31bf3856ad364e35_10.0.10586.0_none_3b570a9cf80c90b7\Windows Media Player.lnk to C:\WINDOWS\winsxs\amd64_microsoft-windows-mediaplayer-shortcut_31bf3856ad364e35_10.0.10586.0_none_3b570a9cf80c90b7\Windows Media Player.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_microsoft-windows-m..diagnostic-schedule_31bf3856ad364e35_10.0.10586.0_none_205c3495240eb77a\Memory Diagnostics Tool.lnk to C:\WINDOWS\winsxs\amd64_microsoft-windows-m..diagnostic-schedule_31bf3856ad364e35_10.0.10586.0_none_205c3495240eb77a\Memory Diagnostics Tool.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_microsoft-windows-m..-odbc-administrator_31bf3856ad364e35_10.0.10586.0_none_d0d57fb6e80e3f5e\ODBC Data Sources (64-bit).lnk to C:\WINDOWS\winsxs\amd64_microsoft-windows-m..-odbc-administrator_31bf3856ad364e35_10.0.10586.0_none_d0d57fb6e80e3f5e\ODBC Data Sources (64-bit).lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_microsoft-windows-iscsi_initiator_ui_31bf3856ad364e35_10.0.10586.0_none_6470c30a06691255\iSCSI Initiator.lnk to C:\WINDOWS\winsxs\amd64_microsoft-windows-iscsi_initiator_ui_31bf3856ad364e35_10.0.10586.0_none_6470c30a06691255\iSCSI Initiator.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_microsoft-windows-f..client-applications_31bf3856ad364e35_10.0.10586.0_none_057f44bfd2bd9812\Windows Fax and Scan.lnk to C:\WINDOWS\winsxs\amd64_microsoft-windows-f..client-applications_31bf3856ad364e35_10.0.10586.0_none_057f44bfd2bd9812\Windows Fax and Scan.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_microsoft-windows-defrag-adminui_31bf3856ad364e35_10.0.10586.0_none_259ba7173a9c269a\dfrgui.lnk to C:\WINDOWS\winsxs\amd64_microsoft-windows-defrag-adminui_31bf3856ad364e35_10.0.10586.0_none_259ba7173a9c269a\dfrgui.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_microsoft-windows-cleanmgr_31bf3856ad364e35_10.0.10586.0_none_f9c9ceba07e30464\Disk Cleanup.lnk to C:\WINDOWS\winsxs\amd64_microsoft-windows-cleanmgr_31bf3856ad364e35_10.0.10586.0_none_f9c9ceba07e30464\Disk Cleanup.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_microsoft-windows-charmap_31bf3856ad364e35_10.0.10586.0_none_7edf55b74eb25a19\Character Map.lnk to C:\WINDOWS\winsxs\amd64_microsoft-windows-charmap_31bf3856ad364e35_10.0.10586.0_none_7edf55b74eb25a19\Character Map.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_microsoft-windows-c..termanagementsnapin_31bf3856ad364e35_10.0.10586.0_none_d79bb88420ae2d66\Computer Management.lnk to C:\WINDOWS\winsxs\amd64_microsoft-windows-c..termanagementsnapin_31bf3856ad364e35_10.0.10586.0_none_d79bb88420ae2d66\Computer Management.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_microsoft-windows-c..s-admin-compsvclink_31bf3856ad364e35_10.0.10586.0_none_5f17ea2284d04ef8\Component Services.lnk to C:\WINDOWS\winsxs\amd64_microsoft-windows-c..s-admin-compsvclink_31bf3856ad364e35_10.0.10586.0_none_5f17ea2284d04ef8\Component Services.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_microsoft-windows-advancedtaskmanager_31bf3856ad364e35_10.0.10586.0_none_3b6c733895d68477\Task Manager.lnk to C:\WINDOWS\winsxs\amd64_microsoft-windows-advancedtaskmanager_31bf3856ad364e35_10.0.10586.0_none_3b6c733895d68477\Task Manager.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_microsoft-windows-a..roblemstepsrecorder_31bf3856ad364e35_10.0.10586.0_none_67772984f550f61f\Steps Recorder.lnk to C:\WINDOWS\winsxs\amd64_microsoft-windows-a..roblemstepsrecorder_31bf3856ad364e35_10.0.10586.0_none_67772984f550f61f\Steps Recorder.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_eventviewersettings_31bf3856ad364e35_10.0.10586.0_none_817d705fae0a5733\Event Viewer.lnk to C:\WINDOWS\winsxs\amd64_eventviewersettings_31bf3856ad364e35_10.0.10586.0_none_817d705fae0a5733\Event Viewer.lnk. Successfully restored ownership for C:\WINDOWS\winsxs\wow64_microsoft-windows-m..-odbc-administrator_31bf3856ad364e35_10.0.10586.0_none_db2a2a091c6f0159\ODBC Data Sources (32-bit).lnk Successfully restored permissions on C:\WINDOWS\winsxs\wow64_microsoft-windows-m..-odbc-administrator_31bf3856ad364e35_10.0.10586.0_none_db2a2a091c6f0159\ODBC Data Sources (32-bit).lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_windows-defender-ui_31bf3856ad364e35_10.0.10586.0_none_a28eb67a8a54ab2a\Windows Defender.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_windows-defender-ui_31bf3856ad364e35_10.0.10586.0_none_a28eb67a8a54ab2a\Windows Defender.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_taskschedulersettings_31bf3856ad364e35_10.0.10586.0_none_d7709c22aeb417b7\Task Scheduler.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_taskschedulersettings_31bf3856ad364e35_10.0.10586.0_none_d7709c22aeb417b7\Task Scheduler.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_networking-mpssvc-shortcut_31bf3856ad364e35_10.0.10586.0_none_11dc8d62b71c6074\Windows Firewall with Advanced Security.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_networking-mpssvc-shortcut_31bf3856ad364e35_10.0.10586.0_none_11dc8d62b71c6074\Windows Firewall with Advanced Security.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_microsoft-windows-xpsreachviewer_31bf3856ad364e35_10.0.10586.0_none_a1a0ebd8f88eb4bf\XPS Viewer.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_microsoft-windows-xpsreachviewer_31bf3856ad364e35_10.0.10586.0_none_a1a0ebd8f88eb4bf\XPS Viewer.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_microsoft-windows-wordpad_31bf3856ad364e35_10.0.10586.0_none_ba40118c173cb7f2\Wordpad.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_microsoft-windows-wordpad_31bf3856ad364e35_10.0.10586.0_none_ba40118c173cb7f2\Wordpad.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_microsoft-windows-t..minalservicesclient_31bf3856ad364e35_10.0.10586.0_none_da61e5edcb6ec32f\Remote Desktop Connection.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_microsoft-windows-t..minalservicesclient_31bf3856ad364e35_10.0.10586.0_none_da61e5edcb6ec32f\Remote Desktop Connection.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_microsoft-windows-t..etpc-mathinputpanel_31bf3856ad364e35_10.0.10586.0_none_57271b70fb42a4a1\Math Input Panel.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_microsoft-windows-t..etpc-mathinputpanel_31bf3856ad364e35_10.0.10586.0_none_57271b70fb42a4a1\Math Input Panel.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_microsoft-windows-sud-link_31bf3856ad364e35_10.0.10586.0_none_5bb3b3b77727a42e\Default Programs.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_microsoft-windows-sud-link_31bf3856ad364e35_10.0.10586.0_none_5bb3b3b77727a42e\Default Programs.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_microsoft-windows-stickynotes-app_31bf3856ad364e35_10.0.10586.0_none_79cc4f5663a2c321\Sticky Notes.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_microsoft-windows-stickynotes-app_31bf3856ad364e35_10.0.10586.0_none_79cc4f5663a2c321\Sticky Notes.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_microsoft-windows-speech-userexperience_31bf3856ad364e35_10.0.10586.0_none_a88f8863f623d2ed\Speech Recognition.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_microsoft-windows-speech-userexperience_31bf3856ad364e35_10.0.10586.0_none_a88f8863f623d2ed\Speech Recognition.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_microsoft-windows-snippingtool-app_31bf3856ad364e35_10.0.10586.0_none_26499a8833fa2713\Snipping Tool.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_microsoft-windows-snippingtool-app_31bf3856ad364e35_10.0.10586.0_none_26499a8833fa2713\Snipping Tool.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_10.0.10586.0_none_5be97afcf0121814\services.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_10.0.10586.0_none_5be97afcf0121814\services.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_microsoft-windows-s..ment-policytools-ex_31bf3856ad364e35_10.0.10586.0_none_e5e4edf6eb6cd204\Security Configuration Management.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_microsoft-windows-s..ment-policytools-ex_31bf3856ad364e35_10.0.10586.0_none_e5e4edf6eb6cd204\Security Configuration Management.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_microsoft-windows-performancetoolsgui_31bf3856ad364e35_10.0.10586.0_none_288f56844b4b2341\Performance Monitor.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_microsoft-windows-performancetoolsgui_31bf3856ad364e35_10.0.10586.0_none_288f56844b4b2341\Performance Monitor.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_microsoft-windows-performancetoolsgui_31bf3856ad364e35_10.0.10586.0_none_288f56844b4b2341\Resource Monitor.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_microsoft-windows-performancetoolsgui_31bf3856ad364e35_10.0.10586.0_none_288f56844b4b2341\Resource Monitor.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_microsoft-windows-p..erandprintui-pmcppc_31bf3856ad364e35_10.0.10586.0_none_97edda452b08d8b9\Print Management.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_microsoft-windows-p..erandprintui-pmcppc_31bf3856ad364e35_10.0.10586.0_none_97edda452b08d8b9\Print Management.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_microsoft-windows-mspaint_31bf3856ad364e35_10.0.10586.0_none_1aa31efd98e8ec4b\Paint.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_microsoft-windows-mspaint_31bf3856ad364e35_10.0.10586.0_none_1aa31efd98e8ec4b\Paint.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_microsoft-windows-msinfo32-exe_31bf3856ad364e35_10.0.10586.0_none_3861ff2fa4057c69\System Information.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_microsoft-windows-msinfo32-exe_31bf3856ad364e35_10.0.10586.0_none_3861ff2fa4057c69\System Information.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_microsoft-windows-msconfig-exe_31bf3856ad364e35_10.0.10586.0_none_66ffd6dc481743c2\System Configuration.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_microsoft-windows-msconfig-exe_31bf3856ad364e35_10.0.10586.0_none_66ffd6dc481743c2\System Configuration.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_microsoft-windows-mediaplayer-shortcut_31bf3856ad364e35_10.0.10586.0_none_3b570a9cf80c90b7\Windows Media Player.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_microsoft-windows-mediaplayer-shortcut_31bf3856ad364e35_10.0.10586.0_none_3b570a9cf80c90b7\Windows Media Player.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_microsoft-windows-m..diagnostic-schedule_31bf3856ad364e35_10.0.10586.0_none_205c3495240eb77a\Memory Diagnostics Tool.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_microsoft-windows-m..diagnostic-schedule_31bf3856ad364e35_10.0.10586.0_none_205c3495240eb77a\Memory Diagnostics Tool.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_microsoft-windows-m..-odbc-administrator_31bf3856ad364e35_10.0.10586.0_none_d0d57fb6e80e3f5e\ODBC Data Sources (64-bit).lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_microsoft-windows-m..-odbc-administrator_31bf3856ad364e35_10.0.10586.0_none_d0d57fb6e80e3f5e\ODBC Data Sources (64-bit).lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_microsoft-windows-iscsi_initiator_ui_31bf3856ad364e35_10.0.10586.0_none_6470c30a06691255\iSCSI Initiator.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_microsoft-windows-iscsi_initiator_ui_31bf3856ad364e35_10.0.10586.0_none_6470c30a06691255\iSCSI Initiator.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_microsoft-windows-f..client-applications_31bf3856ad364e35_10.0.10586.0_none_057f44bfd2bd9812\Windows Fax and Scan.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_microsoft-windows-f..client-applications_31bf3856ad364e35_10.0.10586.0_none_057f44bfd2bd9812\Windows Fax and Scan.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_microsoft-windows-defrag-adminui_31bf3856ad364e35_10.0.10586.0_none_259ba7173a9c269a\dfrgui.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_microsoft-windows-defrag-adminui_31bf3856ad364e35_10.0.10586.0_none_259ba7173a9c269a\dfrgui.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_microsoft-windows-cleanmgr_31bf3856ad364e35_10.0.10586.0_none_f9c9ceba07e30464\Disk Cleanup.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_microsoft-windows-cleanmgr_31bf3856ad364e35_10.0.10586.0_none_f9c9ceba07e30464\Disk Cleanup.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_microsoft-windows-charmap_31bf3856ad364e35_10.0.10586.0_none_7edf55b74eb25a19\Character Map.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_microsoft-windows-charmap_31bf3856ad364e35_10.0.10586.0_none_7edf55b74eb25a19\Character Map.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_microsoft-windows-c..termanagementsnapin_31bf3856ad364e35_10.0.10586.0_none_d79bb88420ae2d66\Computer Management.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_microsoft-windows-c..termanagementsnapin_31bf3856ad364e35_10.0.10586.0_none_d79bb88420ae2d66\Computer Management.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_microsoft-windows-c..s-admin-compsvclink_31bf3856ad364e35_10.0.10586.0_none_5f17ea2284d04ef8\Component Services.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_microsoft-windows-c..s-admin-compsvclink_31bf3856ad364e35_10.0.10586.0_none_5f17ea2284d04ef8\Component Services.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_microsoft-windows-advancedtaskmanager_31bf3856ad364e35_10.0.10586.0_none_3b6c733895d68477\Task Manager.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_microsoft-windows-advancedtaskmanager_31bf3856ad364e35_10.0.10586.0_none_3b6c733895d68477\Task Manager.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_microsoft-windows-a..roblemstepsrecorder_31bf3856ad364e35_10.0.10586.0_none_67772984f550f61f\Steps Recorder.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_microsoft-windows-a..roblemstepsrecorder_31bf3856ad364e35_10.0.10586.0_none_67772984f550f61f\Steps Recorder.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_eventviewersettings_31bf3856ad364e35_10.0.10586.0_none_817d705fae0a5733\Event Viewer.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_eventviewersettings_31bf3856ad364e35_10.0.10586.0_none_817d705fae0a5733\Event Viewer.lnk PowerCopy:: directive completed successfully. Successfully processed all directives. SFCFix version 3.0.0.0 by niemiro has completed. Currently storing 33 datablocks. Finish time: 2016-05-07 22:18:52.745 Script hash: Q5YCoCYYZdlHkCKdU5GP0iJTthbZPNDHp8GS1R3CQUg= ----------------------EOF-----------------------
Here it is: SFCFix version 3.0.0.0 by niemiro. Start time: 2016-05-07 22:18:50.769 Microsoft Windows 10 Build 10586 - amd64 Using .zip script file at C:\Users\Matthew\Desktop\SFCFix.zip [0] PowerCopy:: Successfully took permissions for file or folder C:\WINDOWS\winsxs\wow64_microsoft-windows-m..-odbc-administrator_31bf3856ad364e35_10.0.10586.0_none_db2a2a091c6f0159\ODBC Data Sources (32-bit).lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_windows-defender-ui_31bf3856ad364e35_10.0.10586.0_none_a28eb67a8a54ab2a\Windows Defender.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_taskschedulersettings_31bf3856ad364e35_10.0.10586.0_none_d7709c22aeb417b7\Task Scheduler.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_networking-mpssvc-shortcut_31bf3856ad364e35_10.0.10586.0_none_11dc8d62b71c6074\Windows Firewall with Advanced Security.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_microsoft-windows-xpsreachviewer_31bf3856ad364e35_10.0.10586.0_none_a1a0ebd8f88eb4bf\XPS Viewer.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_microsoft-windows-wordpad_31bf3856ad364e35_10.0.10586.0_none_ba40118c173cb7f2\Wordpad.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_microsoft-windows-t..minalservicesclient_31bf3856ad364e35_10.0.10586.0_none_da61e5edcb6ec32f\Remote Desktop Connection.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_microsoft-windows-t..etpc-mathinputpanel_31bf3856ad364e35_10.0.10586.0_none_57271b70fb42a4a1\Math Input Panel.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_microsoft-windows-sud-link_31bf3856ad364e35_10.0.10586.0_none_5bb3b3b77727a42e\Default Programs.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_microsoft-windows-stickynotes-app_31bf3856ad364e35_10.0.10586.0_none_79cc4f5663a2c321\Sticky Notes.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_microsoft-windows-speech-userexperience_31bf3856ad364e35_10.0.10586.0_none_a88f8863f623d2ed\Speech Recognition.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_microsoft-windows-snippingtool-app_31bf3856ad364e35_10.0.10586.0_none_26499a8833fa2713\Snipping Tool.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_10.0.10586.0_none_5be97afcf0121814\services.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_microsoft-windows-s..ment-policytools-ex_31bf3856ad364e35_10.0.10586.0_none_e5e4edf6eb6cd204\Security Configuration Management.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_microsoft-windows-performancetoolsgui_31bf3856ad364e35_10.0.10586.0_none_288f56844b4b2341\Performance Monitor.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_microsoft-windows-performancetoolsgui_31bf3856ad364e35_10.0.10586.0_none_288f56844b4b2341\Resource Monitor.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_microsoft-windows-p..erandprintui-pmcppc_31bf3856ad364e35_10.0.10586.0_none_97edda452b08d8b9\Print Management.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_microsoft-windows-mspaint_31bf3856ad364e35_10.0.10586.0_none_1aa31efd98e8ec4b\Paint.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_microsoft-windows-msinfo32-exe_31bf3856ad364e35_10.0.10586.0_none_3861ff2fa4057c69\System Information.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_microsoft-windows-msconfig-exe_31bf3856ad364e35_10.0.10586.0_none_66ffd6dc481743c2\System Configuration.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_microsoft-windows-mediaplayer-shortcut_31bf3856ad364e35_10.0.10586.0_none_3b570a9cf80c90b7\Windows Media Player.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_microsoft-windows-m..diagnostic-schedule_31bf3856ad364e35_10.0.10586.0_none_205c3495240eb77a\Memory Diagnostics Tool.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_microsoft-windows-m..-odbc-administrator_31bf3856ad364e35_10.0.10586.0_none_d0d57fb6e80e3f5e\ODBC Data Sources (64-bit).lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_microsoft-windows-iscsi_initiator_ui_31bf3856ad364e35_10.0.10586.0_none_6470c30a06691255\iSCSI Initiator.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_microsoft-windows-f..client-applications_31bf3856ad364e35_10.0.10586.0_none_057f44bfd2bd9812\Windows Fax and Scan.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_microsoft-windows-defrag-adminui_31bf3856ad364e35_10.0.10586.0_none_259ba7173a9c269a\dfrgui.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_microsoft-windows-cleanmgr_31bf3856ad364e35_10.0.10586.0_none_f9c9ceba07e30464\Disk Cleanup.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_microsoft-windows-charmap_31bf3856ad364e35_10.0.10586.0_none_7edf55b74eb25a19\Character Map.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_microsoft-windows-c..termanagementsnapin_31bf3856ad364e35_10.0.10586.0_none_d79bb88420ae2d66\Computer Management.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_microsoft-windows-c..s-admin-compsvclink_31bf3856ad364e35_10.0.10586.0_none_5f17ea2284d04ef8\Component Services.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_microsoft-windows-advancedtaskmanager_31bf3856ad364e35_10.0.10586.0_none_3b6c733895d68477\Task Manager.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_microsoft-windows-a..roblemstepsrecorder_31bf3856ad364e35_10.0.10586.0_none_67772984f550f61f\Steps Recorder.lnk Successfully took permissions for file or folder C:\WINDOWS\winsxs\amd64_eventviewersettings_31bf3856ad364e35_10.0.10586.0_none_817d705fae0a5733\Event Viewer.lnk Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\wow64_microsoft-windows-m..-odbc-administrator_31bf3856ad364e35_10.0.10586.0_none_db2a2a091c6f0159\ODBC Data Sources (32-bit).lnk to C:\WINDOWS\winsxs\wow64_microsoft-windows-m..-odbc-administrator_31bf3856ad364e35_10.0.10586.0_none_db2a2a091c6f0159\ODBC Data Sources (32-bit).lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_windows-defender-ui_31bf3856ad364e35_10.0.10586.0_none_a28eb67a8a54ab2a\Windows Defender.lnk to C:\WINDOWS\winsxs\amd64_windows-defender-ui_31bf3856ad364e35_10.0.10586.0_none_a28eb67a8a54ab2a\Windows Defender.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_taskschedulersettings_31bf3856ad364e35_10.0.10586.0_none_d7709c22aeb417b7\Task Scheduler.lnk to C:\WINDOWS\winsxs\amd64_taskschedulersettings_31bf3856ad364e35_10.0.10586.0_none_d7709c22aeb417b7\Task Scheduler.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_networking-mpssvc-shortcut_31bf3856ad364e35_10.0.10586.0_none_11dc8d62b71c6074\Windows Firewall with Advanced Security.lnk to C:\WINDOWS\winsxs\amd64_networking-mpssvc-shortcut_31bf3856ad364e35_10.0.10586.0_none_11dc8d62b71c6074\Windows Firewall with Advanced Security.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_microsoft-windows-xpsreachviewer_31bf3856ad364e35_10.0.10586.0_none_a1a0ebd8f88eb4bf\XPS Viewer.lnk to C:\WINDOWS\winsxs\amd64_microsoft-windows-xpsreachviewer_31bf3856ad364e35_10.0.10586.0_none_a1a0ebd8f88eb4bf\XPS Viewer.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_microsoft-windows-wordpad_31bf3856ad364e35_10.0.10586.0_none_ba40118c173cb7f2\Wordpad.lnk to C:\WINDOWS\winsxs\amd64_microsoft-windows-wordpad_31bf3856ad364e35_10.0.10586.0_none_ba40118c173cb7f2\Wordpad.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_microsoft-windows-t..minalservicesclient_31bf3856ad364e35_10.0.10586.0_none_da61e5edcb6ec32f\Remote Desktop Connection.lnk to C:\WINDOWS\winsxs\amd64_microsoft-windows-t..minalservicesclient_31bf3856ad364e35_10.0.10586.0_none_da61e5edcb6ec32f\Remote Desktop Connection.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_microsoft-windows-t..etpc-mathinputpanel_31bf3856ad364e35_10.0.10586.0_none_57271b70fb42a4a1\Math Input Panel.lnk to C:\WINDOWS\winsxs\amd64_microsoft-windows-t..etpc-mathinputpanel_31bf3856ad364e35_10.0.10586.0_none_57271b70fb42a4a1\Math Input Panel.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_microsoft-windows-sud-link_31bf3856ad364e35_10.0.10586.0_none_5bb3b3b77727a42e\Default Programs.lnk to C:\WINDOWS\winsxs\amd64_microsoft-windows-sud-link_31bf3856ad364e35_10.0.10586.0_none_5bb3b3b77727a42e\Default Programs.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_microsoft-windows-stickynotes-app_31bf3856ad364e35_10.0.10586.0_none_79cc4f5663a2c321\Sticky Notes.lnk to C:\WINDOWS\winsxs\amd64_microsoft-windows-stickynotes-app_31bf3856ad364e35_10.0.10586.0_none_79cc4f5663a2c321\Sticky Notes.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_microsoft-windows-speech-userexperience_31bf3856ad364e35_10.0.10586.0_none_a88f8863f623d2ed\Speech Recognition.lnk to C:\WINDOWS\winsxs\amd64_microsoft-windows-speech-userexperience_31bf3856ad364e35_10.0.10586.0_none_a88f8863f623d2ed\Speech Recognition.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_microsoft-windows-snippingtool-app_31bf3856ad364e35_10.0.10586.0_none_26499a8833fa2713\Snipping Tool.lnk to C:\WINDOWS\winsxs\amd64_microsoft-windows-snippingtool-app_31bf3856ad364e35_10.0.10586.0_none_26499a8833fa2713\Snipping Tool.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_10.0.10586.0_none_5be97afcf0121814\services.lnk to C:\WINDOWS\winsxs\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_10.0.10586.0_none_5be97afcf0121814\services.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_microsoft-windows-s..ment-policytools-ex_31bf3856ad364e35_10.0.10586.0_none_e5e4edf6eb6cd204\Security Configuration Management.lnk to C:\WINDOWS\winsxs\amd64_microsoft-windows-s..ment-policytools-ex_31bf3856ad364e35_10.0.10586.0_none_e5e4edf6eb6cd204\Security Configuration Management.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_microsoft-windows-performancetoolsgui_31bf3856ad364e35_10.0.10586.0_none_288f56844b4b2341\Performance Monitor.lnk to C:\WINDOWS\winsxs\amd64_microsoft-windows-performancetoolsgui_31bf3856ad364e35_10.0.10586.0_none_288f56844b4b2341\Performance Monitor.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_microsoft-windows-performancetoolsgui_31bf3856ad364e35_10.0.10586.0_none_288f56844b4b2341\Resource Monitor.lnk to C:\WINDOWS\winsxs\amd64_microsoft-windows-performancetoolsgui_31bf3856ad364e35_10.0.10586.0_none_288f56844b4b2341\Resource Monitor.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_microsoft-windows-p..erandprintui-pmcppc_31bf3856ad364e35_10.0.10586.0_none_97edda452b08d8b9\Print Management.lnk to C:\WINDOWS\winsxs\amd64_microsoft-windows-p..erandprintui-pmcppc_31bf3856ad364e35_10.0.10586.0_none_97edda452b08d8b9\Print Management.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_microsoft-windows-mspaint_31bf3856ad364e35_10.0.10586.0_none_1aa31efd98e8ec4b\Paint.lnk to C:\WINDOWS\winsxs\amd64_microsoft-windows-mspaint_31bf3856ad364e35_10.0.10586.0_none_1aa31efd98e8ec4b\Paint.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_microsoft-windows-msinfo32-exe_31bf3856ad364e35_10.0.10586.0_none_3861ff2fa4057c69\System Information.lnk to C:\WINDOWS\winsxs\amd64_microsoft-windows-msinfo32-exe_31bf3856ad364e35_10.0.10586.0_none_3861ff2fa4057c69\System Information.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_microsoft-windows-msconfig-exe_31bf3856ad364e35_10.0.10586.0_none_66ffd6dc481743c2\System Configuration.lnk to C:\WINDOWS\winsxs\amd64_microsoft-windows-msconfig-exe_31bf3856ad364e35_10.0.10586.0_none_66ffd6dc481743c2\System Configuration.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_microsoft-windows-mediaplayer-shortcut_31bf3856ad364e35_10.0.10586.0_none_3b570a9cf80c90b7\Windows Media Player.lnk to C:\WINDOWS\winsxs\amd64_microsoft-windows-mediaplayer-shortcut_31bf3856ad364e35_10.0.10586.0_none_3b570a9cf80c90b7\Windows Media Player.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_microsoft-windows-m..diagnostic-schedule_31bf3856ad364e35_10.0.10586.0_none_205c3495240eb77a\Memory Diagnostics Tool.lnk to C:\WINDOWS\winsxs\amd64_microsoft-windows-m..diagnostic-schedule_31bf3856ad364e35_10.0.10586.0_none_205c3495240eb77a\Memory Diagnostics Tool.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_microsoft-windows-m..-odbc-administrator_31bf3856ad364e35_10.0.10586.0_none_d0d57fb6e80e3f5e\ODBC Data Sources (64-bit).lnk to C:\WINDOWS\winsxs\amd64_microsoft-windows-m..-odbc-administrator_31bf3856ad364e35_10.0.10586.0_none_d0d57fb6e80e3f5e\ODBC Data Sources (64-bit).lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_microsoft-windows-iscsi_initiator_ui_31bf3856ad364e35_10.0.10586.0_none_6470c30a06691255\iSCSI Initiator.lnk to C:\WINDOWS\winsxs\amd64_microsoft-windows-iscsi_initiator_ui_31bf3856ad364e35_10.0.10586.0_none_6470c30a06691255\iSCSI Initiator.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_microsoft-windows-f..client-applications_31bf3856ad364e35_10.0.10586.0_none_057f44bfd2bd9812\Windows Fax and Scan.lnk to C:\WINDOWS\winsxs\amd64_microsoft-windows-f..client-applications_31bf3856ad364e35_10.0.10586.0_none_057f44bfd2bd9812\Windows Fax and Scan.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_microsoft-windows-defrag-adminui_31bf3856ad364e35_10.0.10586.0_none_259ba7173a9c269a\dfrgui.lnk to C:\WINDOWS\winsxs\amd64_microsoft-windows-defrag-adminui_31bf3856ad364e35_10.0.10586.0_none_259ba7173a9c269a\dfrgui.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_microsoft-windows-cleanmgr_31bf3856ad364e35_10.0.10586.0_none_f9c9ceba07e30464\Disk Cleanup.lnk to C:\WINDOWS\winsxs\amd64_microsoft-windows-cleanmgr_31bf3856ad364e35_10.0.10586.0_none_f9c9ceba07e30464\Disk Cleanup.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_microsoft-windows-charmap_31bf3856ad364e35_10.0.10586.0_none_7edf55b74eb25a19\Character Map.lnk to C:\WINDOWS\winsxs\amd64_microsoft-windows-charmap_31bf3856ad364e35_10.0.10586.0_none_7edf55b74eb25a19\Character Map.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_microsoft-windows-c..termanagementsnapin_31bf3856ad364e35_10.0.10586.0_none_d79bb88420ae2d66\Computer Management.lnk to C:\WINDOWS\winsxs\amd64_microsoft-windows-c..termanagementsnapin_31bf3856ad364e35_10.0.10586.0_none_d79bb88420ae2d66\Computer Management.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_microsoft-windows-c..s-admin-compsvclink_31bf3856ad364e35_10.0.10586.0_none_5f17ea2284d04ef8\Component Services.lnk to C:\WINDOWS\winsxs\amd64_microsoft-windows-c..s-admin-compsvclink_31bf3856ad364e35_10.0.10586.0_none_5f17ea2284d04ef8\Component Services.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_microsoft-windows-advancedtaskmanager_31bf3856ad364e35_10.0.10586.0_none_3b6c733895d68477\Task Manager.lnk to C:\WINDOWS\winsxs\amd64_microsoft-windows-advancedtaskmanager_31bf3856ad364e35_10.0.10586.0_none_3b6c733895d68477\Task Manager.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_microsoft-windows-a..roblemstepsrecorder_31bf3856ad364e35_10.0.10586.0_none_67772984f550f61f\Steps Recorder.lnk to C:\WINDOWS\winsxs\amd64_microsoft-windows-a..roblemstepsrecorder_31bf3856ad364e35_10.0.10586.0_none_67772984f550f61f\Steps Recorder.lnk. Successfully copied file C:\Users\Matthew\AppData\Local\niemiro\Archive\winsxs\amd64_eventviewersettings_31bf3856ad364e35_10.0.10586.0_none_817d705fae0a5733\Event Viewer.lnk to C:\WINDOWS\winsxs\amd64_eventviewersettings_31bf3856ad364e35_10.0.10586.0_none_817d705fae0a5733\Event Viewer.lnk. Successfully restored ownership for C:\WINDOWS\winsxs\wow64_microsoft-windows-m..-odbc-administrator_31bf3856ad364e35_10.0.10586.0_none_db2a2a091c6f0159\ODBC Data Sources (32-bit).lnk Successfully restored permissions on C:\WINDOWS\winsxs\wow64_microsoft-windows-m..-odbc-administrator_31bf3856ad364e35_10.0.10586.0_none_db2a2a091c6f0159\ODBC Data Sources (32-bit).lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_windows-defender-ui_31bf3856ad364e35_10.0.10586.0_none_a28eb67a8a54ab2a\Windows Defender.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_windows-defender-ui_31bf3856ad364e35_10.0.10586.0_none_a28eb67a8a54ab2a\Windows Defender.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_taskschedulersettings_31bf3856ad364e35_10.0.10586.0_none_d7709c22aeb417b7\Task Scheduler.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_taskschedulersettings_31bf3856ad364e35_10.0.10586.0_none_d7709c22aeb417b7\Task Scheduler.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_networking-mpssvc-shortcut_31bf3856ad364e35_10.0.10586.0_none_11dc8d62b71c6074\Windows Firewall with Advanced Security.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_networking-mpssvc-shortcut_31bf3856ad364e35_10.0.10586.0_none_11dc8d62b71c6074\Windows Firewall with Advanced Security.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_microsoft-windows-xpsreachviewer_31bf3856ad364e35_10.0.10586.0_none_a1a0ebd8f88eb4bf\XPS Viewer.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_microsoft-windows-xpsreachviewer_31bf3856ad364e35_10.0.10586.0_none_a1a0ebd8f88eb4bf\XPS Viewer.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_microsoft-windows-wordpad_31bf3856ad364e35_10.0.10586.0_none_ba40118c173cb7f2\Wordpad.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_microsoft-windows-wordpad_31bf3856ad364e35_10.0.10586.0_none_ba40118c173cb7f2\Wordpad.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_microsoft-windows-t..minalservicesclient_31bf3856ad364e35_10.0.10586.0_none_da61e5edcb6ec32f\Remote Desktop Connection.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_microsoft-windows-t..minalservicesclient_31bf3856ad364e35_10.0.10586.0_none_da61e5edcb6ec32f\Remote Desktop Connection.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_microsoft-windows-t..etpc-mathinputpanel_31bf3856ad364e35_10.0.10586.0_none_57271b70fb42a4a1\Math Input Panel.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_microsoft-windows-t..etpc-mathinputpanel_31bf3856ad364e35_10.0.10586.0_none_57271b70fb42a4a1\Math Input Panel.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_microsoft-windows-sud-link_31bf3856ad364e35_10.0.10586.0_none_5bb3b3b77727a42e\Default Programs.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_microsoft-windows-sud-link_31bf3856ad364e35_10.0.10586.0_none_5bb3b3b77727a42e\Default Programs.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_microsoft-windows-stickynotes-app_31bf3856ad364e35_10.0.10586.0_none_79cc4f5663a2c321\Sticky Notes.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_microsoft-windows-stickynotes-app_31bf3856ad364e35_10.0.10586.0_none_79cc4f5663a2c321\Sticky Notes.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_microsoft-windows-speech-userexperience_31bf3856ad364e35_10.0.10586.0_none_a88f8863f623d2ed\Speech Recognition.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_microsoft-windows-speech-userexperience_31bf3856ad364e35_10.0.10586.0_none_a88f8863f623d2ed\Speech Recognition.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_microsoft-windows-snippingtool-app_31bf3856ad364e35_10.0.10586.0_none_26499a8833fa2713\Snipping Tool.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_microsoft-windows-snippingtool-app_31bf3856ad364e35_10.0.10586.0_none_26499a8833fa2713\Snipping Tool.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_10.0.10586.0_none_5be97afcf0121814\services.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_10.0.10586.0_none_5be97afcf0121814\services.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_microsoft-windows-s..ment-policytools-ex_31bf3856ad364e35_10.0.10586.0_none_e5e4edf6eb6cd204\Security Configuration Management.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_microsoft-windows-s..ment-policytools-ex_31bf3856ad364e35_10.0.10586.0_none_e5e4edf6eb6cd204\Security Configuration Management.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_microsoft-windows-performancetoolsgui_31bf3856ad364e35_10.0.10586.0_none_288f56844b4b2341\Performance Monitor.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_microsoft-windows-performancetoolsgui_31bf3856ad364e35_10.0.10586.0_none_288f56844b4b2341\Performance Monitor.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_microsoft-windows-performancetoolsgui_31bf3856ad364e35_10.0.10586.0_none_288f56844b4b2341\Resource Monitor.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_microsoft-windows-performancetoolsgui_31bf3856ad364e35_10.0.10586.0_none_288f56844b4b2341\Resource Monitor.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_microsoft-windows-p..erandprintui-pmcppc_31bf3856ad364e35_10.0.10586.0_none_97edda452b08d8b9\Print Management.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_microsoft-windows-p..erandprintui-pmcppc_31bf3856ad364e35_10.0.10586.0_none_97edda452b08d8b9\Print Management.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_microsoft-windows-mspaint_31bf3856ad364e35_10.0.10586.0_none_1aa31efd98e8ec4b\Paint.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_microsoft-windows-mspaint_31bf3856ad364e35_10.0.10586.0_none_1aa31efd98e8ec4b\Paint.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_microsoft-windows-msinfo32-exe_31bf3856ad364e35_10.0.10586.0_none_3861ff2fa4057c69\System Information.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_microsoft-windows-msinfo32-exe_31bf3856ad364e35_10.0.10586.0_none_3861ff2fa4057c69\System Information.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_microsoft-windows-msconfig-exe_31bf3856ad364e35_10.0.10586.0_none_66ffd6dc481743c2\System Configuration.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_microsoft-windows-msconfig-exe_31bf3856ad364e35_10.0.10586.0_none_66ffd6dc481743c2\System Configuration.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_microsoft-windows-mediaplayer-shortcut_31bf3856ad364e35_10.0.10586.0_none_3b570a9cf80c90b7\Windows Media Player.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_microsoft-windows-mediaplayer-shortcut_31bf3856ad364e35_10.0.10586.0_none_3b570a9cf80c90b7\Windows Media Player.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_microsoft-windows-m..diagnostic-schedule_31bf3856ad364e35_10.0.10586.0_none_205c3495240eb77a\Memory Diagnostics Tool.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_microsoft-windows-m..diagnostic-schedule_31bf3856ad364e35_10.0.10586.0_none_205c3495240eb77a\Memory Diagnostics Tool.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_microsoft-windows-m..-odbc-administrator_31bf3856ad364e35_10.0.10586.0_none_d0d57fb6e80e3f5e\ODBC Data Sources (64-bit).lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_microsoft-windows-m..-odbc-administrator_31bf3856ad364e35_10.0.10586.0_none_d0d57fb6e80e3f5e\ODBC Data Sources (64-bit).lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_microsoft-windows-iscsi_initiator_ui_31bf3856ad364e35_10.0.10586.0_none_6470c30a06691255\iSCSI Initiator.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_microsoft-windows-iscsi_initiator_ui_31bf3856ad364e35_10.0.10586.0_none_6470c30a06691255\iSCSI Initiator.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_microsoft-windows-f..client-applications_31bf3856ad364e35_10.0.10586.0_none_057f44bfd2bd9812\Windows Fax and Scan.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_microsoft-windows-f..client-applications_31bf3856ad364e35_10.0.10586.0_none_057f44bfd2bd9812\Windows Fax and Scan.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_microsoft-windows-defrag-adminui_31bf3856ad364e35_10.0.10586.0_none_259ba7173a9c269a\dfrgui.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_microsoft-windows-defrag-adminui_31bf3856ad364e35_10.0.10586.0_none_259ba7173a9c269a\dfrgui.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_microsoft-windows-cleanmgr_31bf3856ad364e35_10.0.10586.0_none_f9c9ceba07e30464\Disk Cleanup.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_microsoft-windows-cleanmgr_31bf3856ad364e35_10.0.10586.0_none_f9c9ceba07e30464\Disk Cleanup.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_microsoft-windows-charmap_31bf3856ad364e35_10.0.10586.0_none_7edf55b74eb25a19\Character Map.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_microsoft-windows-charmap_31bf3856ad364e35_10.0.10586.0_none_7edf55b74eb25a19\Character Map.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_microsoft-windows-c..termanagementsnapin_31bf3856ad364e35_10.0.10586.0_none_d79bb88420ae2d66\Computer Management.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_microsoft-windows-c..termanagementsnapin_31bf3856ad364e35_10.0.10586.0_none_d79bb88420ae2d66\Computer Management.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_microsoft-windows-c..s-admin-compsvclink_31bf3856ad364e35_10.0.10586.0_none_5f17ea2284d04ef8\Component Services.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_microsoft-windows-c..s-admin-compsvclink_31bf3856ad364e35_10.0.10586.0_none_5f17ea2284d04ef8\Component Services.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_microsoft-windows-advancedtaskmanager_31bf3856ad364e35_10.0.10586.0_none_3b6c733895d68477\Task Manager.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_microsoft-windows-advancedtaskmanager_31bf3856ad364e35_10.0.10586.0_none_3b6c733895d68477\Task Manager.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_microsoft-windows-a..roblemstepsrecorder_31bf3856ad364e35_10.0.10586.0_none_67772984f550f61f\Steps Recorder.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_microsoft-windows-a..roblemstepsrecorder_31bf3856ad364e35_10.0.10586.0_none_67772984f550f61f\Steps Recorder.lnk Successfully restored ownership for C:\WINDOWS\winsxs\amd64_eventviewersettings_31bf3856ad364e35_10.0.10586.0_none_817d705fae0a5733\Event Viewer.lnk Successfully restored permissions on C:\WINDOWS\winsxs\amd64_eventviewersettings_31bf3856ad364e35_10.0.10586.0_none_817d705fae0a5733\Event Viewer.lnk PowerCopy:: directive completed successfully. Successfully processed all directives. SFCFix version 3.0.0.0 by niemiro has completed. Currently storing 33 datablocks. Finish time: 2016-05-07 22:18:52.745 Script hash: Q5YCoCYYZdlHkCKdU5GP0iJTthbZPNDHp8GS1R3CQUg= ----------------------EOF-----------------------
Aura Sysnative Staff, Security Analyst Staff member Joined Mar 16, 2015 Posts 8,061 May 7, 2016 #8 Good :) Run a new SFC scan and provide me the CBS.log after please.
S Sezneg Member Joined May 7, 2016 Posts 19 May 7, 2016 #9 I may have copied the stuff into this text twice... "Windows Resource Protection did not find any integrity violations" cbs.txt - Google Drive
I may have copied the stuff into this text twice... "Windows Resource Protection did not find any integrity violations" cbs.txt - Google Drive
Aura Sysnative Staff, Security Analyst Staff member Joined Mar 16, 2015 Posts 8,061 May 7, 2016 #10 Awesome :) Please run DISM again and provide the CBS and DISM logs after.
S Sezneg Member Joined May 7, 2016 Posts 19 May 8, 2016 #11 Completed without errors in the cmd window. dism.log - Google Drive CBS.log - Google Drive
Aura Sysnative Staff, Security Analyst Staff member Joined Mar 16, 2015 Posts 8,061 May 8, 2016 #12 Awesome! :) Was there anything else that needed to be addressed, system file-wise?
S Sezneg Member Joined May 7, 2016 Posts 19 May 8, 2016 #13 It looks like Microsoft Edge is still not functional - it will load, but not render or attempt to load any pages. I have to say the malware this machine got hit with was pretty diabolical. First time in years I've had to clean my own system...
It looks like Microsoft Edge is still not functional - it will load, but not render or attempt to load any pages. I have to say the malware this machine got hit with was pretty diabolical. First time in years I've had to clean my own system...
Aura Sysnative Staff, Security Analyst Staff member Joined Mar 16, 2015 Posts 8,061 May 8, 2016 #14 When you enter an URL, what happens? Does the URL still shows in the address bar, but Edge doesn't do anything?
When you enter an URL, what happens? Does the URL still shows in the address bar, but Edge doesn't do anything?
Aura Sysnative Staff, Security Analyst Staff member Joined Mar 16, 2015 Posts 8,061 May 9, 2016 #16 Do you have any extensions/add-ons yet in Edge?
S Sezneg Member Joined May 7, 2016 Posts 19 May 9, 2016 #17 Not intentionally. I honestly don't even know where the UI to check that is. I only use edge for a few work items at home.
Not intentionally. I honestly don't even know where the UI to check that is. I only use edge for a few work items at home.
Aura Sysnative Staff, Security Analyst Staff member Joined Mar 16, 2015 Posts 8,061 May 9, 2016 #18 You can always try to "reset" Microsoft Edge the hard way (seems to be the only way to reset it anyway) and see what it gives. How to reset Microsoft Edge in Windows 1 when things are broken | Windows Central I would create a Restore Point beforehand.
You can always try to "reset" Microsoft Edge the hard way (seems to be the only way to reset it anyway) and see what it gives. How to reset Microsoft Edge in Windows 1 when things are broken | Windows Central I would create a Restore Point beforehand.
S Sezneg Member Joined May 7, 2016 Posts 19 May 13, 2016 #19 Ok, there is something more going on here. I followed the steps as presented. When I completed them, I went to test it and the problem persisted AND windows defender triggered on something. Malwarebytes also found stuff after. Looks like whatever broke edge is still bad news.
Ok, there is something more going on here. I followed the steps as presented. When I completed them, I went to test it and the problem persisted AND windows defender triggered on something. Malwarebytes also found stuff after. Looks like whatever broke edge is still bad news.
Aura Sysnative Staff, Security Analyst Staff member Joined Mar 16, 2015 Posts 8,061 May 13, 2016 #20 If you need a more in-depth malware clean-up, I suggest you to head over the Security Arena here to receive assistance :) https://www.sysnative.com/forums/security-arena/
If you need a more in-depth malware clean-up, I suggest you to head over the Security Arena here to receive assistance :) https://www.sysnative.com/forums/security-arena/