Additional scan result of Farbar Recovery Scan Tool (x64) Version:10-01-2015 01 Ran by [removed] (2016-01-11 23:41:36) Running from C:\Users\[removed]\Downloads Windows 10 Home (X64) (2015-12-10 04:06:31) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-3488279127-63086370-3813774398-500 - Administrator - Disabled) cmcga_000 (S-1-5-21-3488279127-63086370-3813774398-1005 - Limited - Enabled) => C:\Users\cmcga_000 DefaultAccount (S-1-5-21-3488279127-63086370-3813774398-503 - Limited - Disabled) Guest (S-1-5-21-3488279127-63086370-3813774398-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-3488279127-63086370-3813774398-1003 - Limited - Enabled) maggi_000 (S-1-5-21-3488279127-63086370-3813774398-1004 - Limited - Enabled) => C:\Users\maggi_000 stephen (S-1-5-21-3488279127-63086370-3813774398-1001 - Administrator - Enabled) => C:\Users\stephen ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: AVG AntiVirus Free Edition (Enabled - Out of date) {4D41356F-32AD-7C42-C820-63775EE4F413} AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Spybot - Search and Destroy (Enabled - Out of date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0} AS: AVG AntiVirus Free Edition (Enabled - Out of date) {F620D48B-1497-73CC-F290-58052563BEAE} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) µTorrent (HKU\S-1-5-21-3488279127-63086370-3813774398-1004\...\uTorrent) (Version: 3.4.3.40298 - BitTorrent Inc.) µTorrent (HKU\S-1-5-21-3488279127-63086370-3813774398-1005\...\uTorrent) (Version: 3.4.3.40298 - BitTorrent Inc.) 7-Zip 9.38 beta (HKLM-x32\...\7-Zip) (Version: - ) A360 Desktop (HKLM\...\{B209E611-5511-4AD6-B4B3-9D36F93DBCD4}) (Version: 6.0.3.1100 - Autodesk) ACA & MEP 2016 Object Enabler (Version: 7.8.41.0 - Autodesk) Hidden ACAD Private (Version: 20.1.49.0 - Autodesk) Hidden Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.009.20079 - Adobe Systems Incorporated) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 14.0.0.178 - Adobe Systems Incorporated) Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 3.3.0.151 - Adobe Systems Incorporated) Adobe CSI CS4 x64 (Version: 1 - Adobe Systems Incorporated) Hidden Adobe Download Assistant (HKLM-x32\...\com.adobe.downloadassistant.AdobeDownloadAssistant) (Version: 1.2.9 - Adobe Systems Incorporated) Adobe Drive CS4 x64 (Version: 1 - Adobe Systems Incorporated) Hidden Adobe Flash Player 20 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 20.0.0.267 - Adobe Systems Incorporated) Adobe InDesign CS4 (HKLM-x32\...\Adobe_1710d324011afc3e7658e969025f4ba) (Version: 6.0 - Adobe Systems Incorporated) Adobe InDesign CS4 Icon Handler x64 (Version: 6.0 - Adobe Systems Incorporated) Hidden Adobe Media Player (HKLM-x32\...\com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.1 - Adobe Systems Incorporated) Adobe PDF iFilter 11 for 64-bit platforms (HKLM\...\{BA5C0CC3-421B-4AE5-9370-1650D1941F30}) (Version: 11.0.00 - Adobe) Adobe Photoshop CC 2015 (HKLM-x32\...\{793C2BF7-A4FE-4608-91C9-9282C5801C21}) (Version: 16.0.1 - Adobe Systems Incorporated) AdVPN (HKLM-x32\...\AdVPN) (Version: v1.1 - Alto Cloud Media Ltd.) Akamai NetSession Interface (HKU\S-1-5-21-3488279127-63086370-3813774398-1001\...\Akamai) (Version: - Akamai Technologies, Inc) Akamai NetSession Interface (HKU\S-1-5-21-3488279127-63086370-3813774398-1004\...\Akamai) (Version: - Akamai Technologies, Inc) Akamai NetSession Interface (HKU\S-1-5-21-3488279127-63086370-3813774398-1005\...\Akamai) (Version: - Akamai Technologies, Inc) Amazon Kindle (HKU\S-1-5-21-3488279127-63086370-3813774398-1004\...\Amazon Kindle) (Version: 1.14.0.43019 - Amazon) Aslain's XVM WoT Modpack version 9.13.07 (HKLM-x32\...\ZRwTINhSZfduKONYrSCTiCiGPggQZdcLRvoAVxyCOXXpkHeC~1DC3968F_is1) (Version: 9.13.07 - Aslain) AutoCAD 2014 - English (Version: 19.1.108.1 - Autodesk) Hidden AutoCAD 2014 - English (Version: 19.1.42.0 - Autodesk) Hidden AutoCAD 2014 Language Pack - English (Version: 19.1.42.0 - Autodesk) Hidden AutoCAD 2016 - English (Version: 20.1.49.0 - Autodesk) Hidden AutoCAD 2016 (Version: 20.1.107.0 - Autodesk) Hidden AutoCAD 2016 Language Pack - English (Version: 20.1.49.0 - Autodesk) Hidden Autodesk Advanced Material Library Image Library 2016 (HKLM-x32\...\{94AD53E7-493B-4291-8714-7A3B761D2783}) (Version: 6.3.0.15 - Autodesk) Autodesk App Manager (HKLM-x32\...\{C070121A-C8C5-4D52-9A7D-D240631BD433}) (Version: 1.1.0 - Autodesk) Autodesk App Manager 2016 (HKLM-x32\...\{4ECF9E00-2978-46AF-BD80-455EFEAB7A93}) (Version: 2.0.0 - Autodesk) Autodesk Application Manager (HKLM-x32\...\Autodesk Application Manager) (Version: 5.0.142.9 - Autodesk) Autodesk AutoCAD 2014 - English SP1 (HKLM\...\AutoCAD 2014 - English SP1) (Version: 1 - Autodesk) Autodesk AutoCAD 2016 - English (HKLM\...\AutoCAD 2016 - English) (Version: 20.1.49.0 - Autodesk) Autodesk AutoCAD 2016 SP 1 (HKLM\...\AutoCAD 2016 SP1) (Version: 20.1.107.0 - Autodesk) Autodesk AutoCAD Performance Feedback Tool 1.2.4 (HKLM-x32\...\{4E20873D-BC20-495C-AFD9-B18877B7F9BB}) (Version: 1.2.4.0 - Autodesk) Autodesk BIM 360 Glue AutoCAD 2016 Add-in 64 bit (HKLM\...\{4BEE127E-95C4-434D-ABAC-65155192BB24}) (Version: 4.35.1742 - Autodesk) Autodesk Content Service (HKLM\...\Autodesk Content Service) (Version: 3.2.0.0 - Autodesk) Autodesk Content Service (Version: 3.2.0.0 - Autodesk) Hidden Autodesk Content Service Language Pack (Version: 3.2.0.0 - Autodesk) Hidden Autodesk Featured Apps (HKLM-x32\...\{F732FEDA-7713-4428-934B-EF83B8DD65D0}) (Version: 1.1.0 - Autodesk) Autodesk Featured Apps 2016 (HKLM-x32\...\{D42F37CD-9AF9-4435-A474-B387C5BB6B47}) (Version: 2.0.0 - Autodesk) Autodesk Material Library 2016 (HKLM-x32\...\{29A7D6EC-63C2-42FD-8143-5812ABD2923F}) (Version: 6.3.0.15 - Autodesk) Autodesk Material Library Base Resolution Image Library 2016 (HKLM-x32\...\{6B4CFC6E-ECB0-47FE-95D3-65C680ED0687}) (Version: 6.3.0.15 - Autodesk) Autodesk ReCap (Version: 1.0.43.13 - Autodesk) Hidden Autodesk ReCap 2016 (HKLM\...\Autodesk ReCap 2016) (Version: 1.5.0.33 - Autodesk) Autodesk ReCap 2016 (Version: 1.5.0.33 - Autodesk) Hidden Autodesk ReCap Language Pack-English (Version: 1.0.43.13 - Autodesk) Hidden AVG (HKLM\...\AvgZen) (Version: 1.31.1.48846 - AVG Technologies) AVG (Version: 16.31.7356 - AVG Technologies) Hidden AVG 2016 (Version: 16.0.4492 - AVG Technologies) Hidden AVG PC TuneUp (HKLM-x32\...\AVG PC TuneUp) (Version: 16.13.1.47453 - AVG Technologies) AVG PC TuneUp (x32 Version: 16.13.3 - AVG Technologies) Hidden AVG Protection (HKLM\...\AVG) (Version: 2016.31.7356 - AVG Technologies) AVG Web TuneUp (HKLM-x32\...\AVG Web TuneUp) (Version: 4.2.4.155 - AVG Technologies) AVG Zen (Version: 1.31.9 - AVG Technologies) Hidden Call of Duty: Modern Warfare 2 (HKLM-x32\...\Steam App 10180) (Version: - Infinity Ward) CCleaner (HKLM\...\CCleaner) (Version: 5.13 - Piriform) Compatibility Pack for the 2007 Office system (HKLM-x32\...\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Connect (x32 Version: 1.0.0.1 - Adobe Systems Incorporated) Hidden Counter-Strike: Source (HKLM-x32\...\Steam App 240) (Version: - Valve) eLicenser Control (HKLM-x32\...\eLicenser Control) (Version: 6.9.1.1175 - Steinberg Media Technologies GmbH) Fallout 3 - Game of the Year Edition (HKLM-x32\...\Steam App 22370) (Version: - Bethesda Game Studios) Fallout 3 (HKU\S-1-5-21-3488279127-63086370-3813774398-1001\...\{974C4B12-4D02-4879-85E0-61C95CC63E9E}) (Version: 1.00.0000 - Bethesda Softworks) Fallout 3 (HKU\S-1-5-21-3488279127-63086370-3813774398-1004\...\{974C4B12-4D02-4879-85E0-61C95CC63E9E}) (Version: 1.00.0000 - Bethesda Softworks) Fallout 3 (HKU\S-1-5-21-3488279127-63086370-3813774398-1005\...\{974C4B12-4D02-4879-85E0-61C95CC63E9E}) (Version: 1.00.0000 - Bethesda Softworks) FARO LS 1.1.406.58 (HKLM-x32\...\{951B0F30-9F1A-4BF6-B3DA-99EB0E917B1C}) (Version: 4.6.58.2 - FARO Scanner Production) FARO LS 1.1.501.0 (64bit) (HKLM-x32\...\{8A470330-70B2-49AD-86AF-79885EF9898A}) (Version: 5.1.0.30630 - FARO Scanner Production) FARO LS 1.1.502.0 (64bit) (HKLM-x32\...\{66D83FE0-D798-4B38-86FE-FB48151E5AEF}) (Version: 5.2.0.35213 - FARO Scanner Production) FARO LS 1.1.503.3 (64bit) (HKLM-x32\...\{1C05E654-FB81-4274-BF32-292E3707701D}) (Version: 5.3.3.38662 - FARO Scanner Production) FMW 1 (Version: 1.42.1 - AVG Technologies) Hidden GanttProject (HKLM-x32\...\GanttProject) (Version: - ) Google Earth (HKLM-x32\...\{817750FA-EC6A-485D-9901-0683AE6FFDF1}) (Version: 7.1.5.1557 - Google) Google Update Helper (x32 Version: 1.3.29.1 - Google Inc.) Hidden Half-Life 2 (HKLM-x32\...\Steam App 220) (Version: - Valve) Homeworld Remastered Collection (HKLM-x32\...\Steam App 244160) (Version: - Gearbox Software) Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 10.0.0.1204 - Intel Corporation) Java 8 Update 66 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418066F0}) (Version: 8.0.660.18 - Oracle Corporation) Java 8 Update 66 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218066F0}) (Version: 8.0.660.18 - Oracle Corporation) kuler (x32 Version: 2.0 - Adobe Systems Incorporated) Hidden leafdigital leafDrums 2.1 (HKLM-x32\...\leafDrums2) (Version: - ) Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes) McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.8.150.1 - McAfee, Inc.) Media Go (HKLM-x32\...\{65256C0D-3FE7-4D2E-BB3E-53F1175481C8}) (Version: 3.0.403 - Sony) Media Go Network Downloader (HKLM-x32\...\{C52148B9-19E0-433A-9422-3451B1BEE20F}) (Version: 1.6.01.0 - Sony) Media Go Video Playback Engine 2.20.107.05220 (HKLM-x32\...\{7348D0F2-3DAC-0BE7-4E7C-64844D2E3CA9}) (Version: 2.20.107.05220 - Sony) Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation) Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}) (Version: 3.5.92.0 - Microsoft Corporation) Microsoft Games for Windows Marketplace (HKLM-x32\...\{67F42018-F647-4D3C-BE62-F8CB4FE2FCD5}) (Version: 3.5.67.0 - Microsoft Corporation) Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office Professional Edition 2003 (HKLM-x32\...\{90110409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation) Microsoft Office Project 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-003B-0000-0000-0000000FF1CE}_PRJPRO_{8446EB22-A746-46DC-B1BD-E0DFA1F3CDDA}) (Version: - Microsoft) Microsoft Office Project Professional 2007 (HKLM-x32\...\PRJPRO) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-3488279127-63086370-3813774398-1005\...\OneDriveSetup.exe) (Version: 17.3.5907.0716 - Microsoft Corporation) Microsoft OneNote 2013 - en-us (HKLM\...\OneNoteFreeRetail - en-us) (Version: 15.0.4779.1002 - Microsoft Corporation) Microsoft Project Professional 2013 (HKLM-x32\...\Office15.PRJPRO) (Version: 15.0.4569.1506 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41105.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.) Mozilla Firefox 43.0.4 (x86 en-GB) (HKLM-x32\...\Mozilla Firefox 43.0.4 (x86 en-GB)) (Version: 43.0.4 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 43.0.4 - Mozilla) MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation) NBS Create (HKLM-x32\...\{A0AF8432-76A3-4269-86A8-15E2CA9ACC5C}) (Version: 1.05.0003 - NBS) NVIDIA 3D Vision Controller Driver 352.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 352.65 - NVIDIA Corporation) NVIDIA 3D Vision Driver 352.86 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 352.86 - NVIDIA Corporation) NVIDIA GeForce Experience 2.7.4.10 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.7.4.10 - NVIDIA Corporation) NVIDIA Graphics Driver 352.86 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 352.86 - NVIDIA Corporation) NVIDIA HD Audio Driver 1.3.34.3 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.3 - NVIDIA Corporation) NVIDIA Miracast Virtual Audio 352.86 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Miracast.VirtualAudio) (Version: 352.86 - NVIDIA Corporation) NVIDIA PhysX System Software 9.15.0428 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation) Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4779.1002 - Microsoft Corporation) Hidden Office 15 Click-to-Run Licensing Component (Version: 15.0.4779.1002 - Microsoft Corporation) Hidden Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4779.1002 - Microsoft Corporation) Hidden Opera Stable 34.0.2036.25 (HKLM-x32\...\Opera 34.0.2036.25) (Version: 34.0.2036.25 - Opera Software) Outils de vérification linguistique 2013 de Microsoft Office - Français (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden PDF Settings CS4 (x32 Version: 9.0 - Adobe Systems Incorporated) Hidden Photoshop Camera Raw (x32 Version: 5.0 - Adobe Systems Incorporated) Hidden Portal (HKLM-x32\...\Steam App 400) (Version: - Valve) Portal 2 (HKLM-x32\...\Steam App 620) (Version: - Valve) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7535 - Realtek Semiconductor Corp.) Recuva (HKLM\...\Recuva) (Version: 1.52 - Piriform) Samsung USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.55.0 - Samsung Electronics Co., Ltd.) SHIELD Streaming (Version: 4.1.0240 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: 2.7.4.10 - NVIDIA Corporation) Hidden Shockwave (HKLM-x32\...\Shockwave) (Version: - ) Should I Remove It (HKU\S-1-5-21-3488279127-63086370-3813774398-1001\...\Should I Remove It 1.0.4) (Version: 1.0.4 - Reason Software Company Inc.) Should I Remove It (HKU\S-1-5-21-3488279127-63086370-3813774398-1004\...\Should I Remove It 1.0.4) (Version: 1.0.4 - Reason Software Company Inc.) Should I Remove It (HKU\S-1-5-21-3488279127-63086370-3813774398-1005\...\Should I Remove It 1.0.4) (Version: 1.0.4 - Reason Software Company Inc.) Should I Remove It (x32 Version: 1.0.4 - Reason Software Company Inc.) Hidden SketchUp 2015 (HKLM\...\{350488A4-1540-4103-8F01-B27503891EB0}) (Version: 15.3.331 - Trimble Navigation Limited) SketchUp Import (HKLM-x32\...\{C403E867-FCF1-432B-BCC1-8FFD40A10A6E}) (Version: 1.2.0 - Autodesk) SketchUp Import 2016 (HKLM-x32\...\{C769FB7C-1F55-4B31-9A2A-21CEC50F4F92}) (Version: 2.0.0 - Autodesk) Skype™ 7.5 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.5.101 - Skype Technologies S.A.) SmartDraw 2010 (HKU\S-1-5-21-3488279127-63086370-3813774398-1001\...\SmartDraw 2010) (Version: - ) SmartDraw 2010 (HKU\S-1-5-21-3488279127-63086370-3813774398-1004\...\SmartDraw 2010) (Version: - ) SmartDraw 2010 (HKU\S-1-5-21-3488279127-63086370-3813774398-1005\...\SmartDraw 2010) (Version: - ) Sony Mobile Update Engine (HKLM-x32\...\Update Engine) (Version: 2.15.16.201511171525 - Sony Mobile Communications Inc.) Sony PC Companion 2.10.297 (HKLM-x32\...\{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}) (Version: 2.10.297 - Sony) Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.4.40 - Safer-Networking Ltd.) Steam (HKLM-x32\...\Steam) (Version: - Valve Corporation) Steinberg Cubase LE AI Elements 6 64bit (HKLM\...\{8EEEB23E-A3EB-44A4-AEE9-D2FD6F96E4A0}) (Version: 6.0.3 - Steinberg Media Technologies GmbH) Steinberg Drum Loop Expansion 01 (HKLM-x32\...\{490BF87E-1F75-4453-BF55-9F540543A3CA}) (Version: 2.0.0.0 - Steinberg Media Technologies GmbH) Steinberg Groove Agent ONE Content (HKLM-x32\...\{BD86F1AC-B594-46E4-85DC-1258AC9E2232}) (Version: 1.0.0.003 - Steinberg Media Technologies GmbH) Steinberg Groove Agent ONE Vintage Beatboxes (HKLM-x32\...\{DBF4BC99-53F1-4C97-84C3-7557D103E182}) (Version: 1.0.0.000 - Steinberg Media Technologies GmbH) Steinberg HALion Sonic SE 64bit (HKLM\...\{B99C316B-C135-43B5-8E77-2BC5E241F964}) (Version: 1.5.2 - Steinberg Media Technologies GmbH) Steinberg HALion Sonic SE Content for Cubase LE AI Elements (HKLM-x32\...\{CF45002F-2205-4116-BB51-2D015F436CAC}) (Version: 1.5.2.000 - Steinberg Media Technologies GmbH) Suite Shared Configuration CS4 (x32 Version: 1.0 - Adobe Systems Incorporated) Hidden TeamSpeak 3 Client (HKU\S-1-5-21-3488279127-63086370-3813774398-1001\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH) TeamSpeak 3 Client (HKU\S-1-5-21-3488279127-63086370-3813774398-1004\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH) TeamSpeak 3 Client (HKU\S-1-5-21-3488279127-63086370-3813774398-1005\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH) Text-To-Speech-Runtime (HKLM-x32\...\{7B3F0113-E63C-4D6D-AF19-111A3165CCA2}) (Version: 1.0.0.0 - Magix Development GmbH) Thunder Master v2.4 (HKLM-x32\...\{EE04522C-0814-4B63-AE57-0B63E5A355BB}_is1) (Version: 2.4.0.0 - Palit Microsystems Ltd.) Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-003B-0000-0000-0000000FF1CE}_PRJPRO_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Uplay (HKLM-x32\...\Uplay) (Version: 4.6 - Ubisoft) Visual C++ 2008 - x64 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{6DA2B636-698A-3294-BF4A-B5E11B238CDD}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation) Visual C++ 2008 - x64 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{8CCEA24C-51AE-3B71-9092-7D0C44DDA2DF}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation) Visual C++ 2008 - x64 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{C3A57BB3-9AA6-3F6F-9395-6C062BDD5FC4}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation) Visual C++ 2008 - x64 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{F6F09DD8-F39B-3A16-ADB9-C9E6B56903F9}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation) Visual C++ 2008 - x86 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{04B34E21-5BEE-3D2B-8D3D-E3E80D253F64}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation) Visual C++ 2008 - x86 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{14866AAD-1F23-39AC-A62B-7091ED1ADE64}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation) Visual C++ 2008 - x86 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{4B90093A-5D9C-3956-8ABB-95848BE6EFAD}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation) Visual C++ 2008 - x86 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{B42E259C-E4D4-37F1-A1B2-EB9C4FC5A04D}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation) Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies) Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.) VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN) Watch_Dogs (HKLM-x32\...\Uplay Install 274) (Version: - Ubisoft) WinCalendar V4 (HKLM-x32\...\WinCalendar V4) (Version: 4.31 - Sapro Systems) WinRAR 5.11 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.11.0 - win.rar GmbH) WinZip 18.5 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240E3}) (Version: 18.5.11111 - WinZip Computing, S.L. ) World of Tanks (HKU\S-1-5-21-3488279127-63086370-3813774398-1001\...\{1EAC1D02-C6AC-4FA6-9A44-96258C37C812EU}_is1) (Version: - Wargaming.net) World of Tanks (HKU\S-1-5-21-3488279127-63086370-3813774398-1004\...\{1EAC1D02-C6AC-4FA6-9A44-96258C37C812EU}_is1) (Version: - Wargaming.net) World of Tanks (HKU\S-1-5-21-3488279127-63086370-3813774398-1005\...\{1EAC1D02-C6AC-4FA6-9A44-96258C37C812EU}_is1) (Version: - Wargaming.net) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-3488279127-63086370-3813774398-1001_Classes\CLSID\{0E270DAA-1BE6-48F2-AC49-3E48168F0BF5}\InprocServer32 -> %%systemroot%%\system32\shell32.dll => No File CustomCLSID: HKU\S-1-5-21-3488279127-63086370-3813774398-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\stephen\AppData\Local\Microsoft\OneDrive\17.3.6201.1019_1\FileCoAuth.exe (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3488279127-63086370-3813774398-1001_Classes\CLSID\{7DE1BE5C-CEBA-4F1D-ACBC-9CE11EE9A2A1}\localserver32 -> D:\Program Files\Autodesk\AutoCAD 2014\acad.exe (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-3488279127-63086370-3813774398-1001_Classes\CLSID\{e8c77137-e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {05D59D87-96D4-4809-B3E3-97F234952844} - \One System Care Monitor -> No File <==== ATTENTION Task: {07A4BA73-6E2C-4CC0-9C90-4582C0784378} - \APSnotifierPP2 -> No File <==== ATTENTION Task: {0CFE2E40-6A97-48C5-9F38-DE82315CF1B0} - System32\Tasks\Microsoft\Windows\UPnP\UPnPHostConfig => config upnphost start= auto Task: {0D0D7F5F-415F-4BA5-BDDE-E9795793B0CF} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION Task: {0E8CBF72-BACF-456C-B418-0BC1D825D58F} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION Task: {0FBB4C60-A94D-48A5-BAD7-5625DDF2A7D0} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe Task: {10B3EDC6-37ED-466C-A117-CDB1E3012531} - System32\Tasks\AVGPCTuneUp_Task_BkGndMaintenance => C:\Program Files (x86)\AVG\AVG PC TuneUp\tuscanx.exe [2015-12-11] (AVG Technologies CZ, s.r.o.) Task: {18FCD4A7-8F8B-463C-93F0-201D321FE4D3} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-10-05] (Google Inc.) Task: {25A68E46-C579-4EC3-8EF5-E063E0307D1B} - \IBUpd -> No File <==== ATTENTION Task: {2E599E7B-8934-48F7-BE8F-E50B24D2FBD1} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-12-29] (Adobe Systems Incorporated) Task: {30DF0F10-D2C7-4F42-A8B6-1BE45573F78E} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-21] (Microsoft Corporation) Task: {35EC7C55-529C-482B-8014-350520EF20DF} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION Task: {452BD620-F945-4718-A8D1-2F1028AF411C} - System32\Tasks\Opera scheduled Autoupdate 1432733584 => C:\Program Files (x86)\Opera\launcher.exe [2015-12-04] (Opera Software) Task: {46FAD34F-36A4-4CD0-8BCA-651D7306173F} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION Task: {49811A13-6A52-49A6-A86C-242A54738A18} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION Task: {4C503F55-2E5F-4B0B-AC2B-B07C9919555F} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2015-10-13] (Microsoft Corporation) Task: {515957AE-8084-4613-AAB3-7CCAA5426F5D} - System32\Tasks\{3B00E05A-55A2-420D-AB18-BDBC1D5086E0} => pcalua.exe -a E:\Setup.now.exe -d E:\ Task: {58892ADB-3640-4938-AFFD-DB5BE0C864EB} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION Task: {5967A2A6-BDEB-4BF2-8968-85D6DD93ECB2} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-12-11] (Microsoft Corporation) Task: {5B8D9BE7-190D-4AAA-B0CE-5599D6DD766A} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION Task: {5D6C13FC-A0E0-4F32-A275-A13FD1632A7A} - \One System CarePeriod -> No File <==== ATTENTION Task: {61278F75-ACB1-49D1-9937-E27748F0BCB1} - System32\Tasks\{7BEE6A47-035C-4DE7-819A-FF8321383B81} => pcalua.exe -a "C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe" -c scenario=install baseurl="C:\Program Files\Microsoft Office 15" platform=x86 version=15.0.4641.1003 culture=en-us productstoremove=ProPlusRetail_en-us_x-none Task: {6C901A03-B728-48FD-8253-09345D462AF3} - \APSnotifierPP1 -> No File <==== ATTENTION Task: {71FDBB6F-0FAC-4CF6-80D6-91C47D61A6F0} - \APSnotifierPP3 -> No File <==== ATTENTION Task: {7E05E333-440E-4A41-A615-CDD8579B0F5E} - \SmartWeb Upgrade Trigger Task -> No File <==== ATTENTION Task: {825922FE-84C7-4A48-B4A0-C31E3E76926F} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-10-28] (Adobe Systems Incorporated) Task: {8AEDF436-33EE-442E-A1FD-C28DFCCEFF25} - \SwiftSearch Auto Updater 1.10.0.25 Core -> No File <==== ATTENTION Task: {8D435A42-F6A4-452D-B01A-E8AB4CA713C0} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe [2014-06-24] (Safer-Networking Ltd.) Task: {8D469930-866F-4944-B9D7-40DEA54E9A91} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-21] (Microsoft Corporation) Task: {8DFBE616-7074-45BE-ABA7-925981AC24F3} - System32\Tasks\ShouldIRemoveIt_Notifications => D:\Program Files (x86)\Reason\Should I Remove It\ShouldIRemoveIt.exe [2014-09-03] (Reason Software Company Inc.) Task: {8E34CD63-AA22-4525-8DEC-5CB797FCAC93} - System32\Tasks\[removed] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2015-09-04] (Adobe Systems Incorporated) Task: {8E8068C7-557E-4208-99E6-29427EDFE4BE} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe [2014-06-24] (Safer-Networking Ltd.) Task: {9027744C-BC63-42FB-9581-8CE3CDCB06A5} - \One System Care Run Delay -> No File <==== ATTENTION Task: {908DF050-EC73-490D-A3CC-FABDA32F6478} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-12-08] (Piriform Ltd) Task: {944B75A4-B30B-451B-914F-0F05E7C19F46} - \SwiftSearch Auto Updater 1.10.0.25 Pending Update -> No File <==== ATTENTION Task: {9A2CAD55-E9F0-4E2B-996D-9E5B38367C48} - System32\Tasks\Java Platform SE Auto Updater => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2015-11-09] (Oracle Corporation) Task: {A82CF6DE-22FC-4106-B744-E1011BE2AD50} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION Task: {B11FD346-80A8-494A-B4D9-5D7D5E80E52B} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-10-05] (Google Inc.) Task: {CF01CF38-7BB2-44AC-B841-4B43F49DED1B} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2015-10-13] (Microsoft Corporation) Task: {CF3CF60B-F2E7-4DFE-9DAE-D666E7D3E908} - System32\Tasks\{F2FF3EB3-E05D-4702-BE9E-403B588482E6} => pcalua.exe -a D:\leafDrums233.exe -d D:\ Task: {D2794EA9-DE59-4E4C-A896-369704F28B51} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION Task: {D4F4507B-BAE8-438E-A3DD-E735401AC9E0} - System32\Tasks\SDMsgUpdate (TE) => C:\Program Files (x86)\SmartDraw 2010\Messages\SDNotify.exe [2009-07-08] () Task: {D7D1F4A3-AEC0-46E2-8941-FCCEBE89056D} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION Task: {EB8FBA59-4982-4D21-8793-EDB8B55056E8} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION Task: {FB5EB42F-2D5B-49C4-B8D7-829794D7B939} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe [2014-06-27] (Safer-Networking Ltd.) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\SDMsgUpdate (TE).job => C:\PROGRA~2\SMARTD~1\Messages\SDNotify.exeX-PTE -V1812 -SSDU.ini -A -Mhxxp:/www.smartdraw.com/msgs/messagecheck.asp ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== 2015-10-30 07:17 - 2015-10-30 07:17 - 00028672 _____ () C:\WINDOWS\SYSTEM32\efsext.dll 2015-05-02 12:56 - 2015-12-18 12:04 - 01164688 _____ () C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe 2015-12-10 03:56 - 2014-01-28 03:16 - 00936728 _____ () C:\Program Files (x86)\ASUS\AXSP\1.02.00\atkexComSvc.exe 2015-02-01 02:03 - 2015-10-13 04:34 - 00105640 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll 2015-11-26 20:00 - 2015-11-26 20:00 - 00035328 _____ () C:\Program Files (x86)\AdVPN\AdVpnService.exe 2015-12-18 12:04 - 2015-12-18 12:04 - 00192912 _____ () C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\40.2.4\loggingserver.exe 2015-10-30 07:18 - 2015-10-30 07:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll 2015-12-10 03:53 - 2015-12-10 03:53 - 02653816 _____ () C:\WINDOWS\system32\CoreUIComponents.dll 2015-12-10 03:53 - 2015-12-10 03:53 - 02653816 _____ () C:\WINDOWS\System32\CoreUIComponents.dll 2015-09-11 18:02 - 2015-09-11 18:02 - 00803488 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll 2015-10-28 10:09 - 2015-09-01 16:04 - 08901184 _____ () C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\1033\GrooveIntlResource.dll 2015-12-18 10:50 - 2015-12-07 03:33 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2015-12-18 10:50 - 2015-12-07 03:34 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll 2015-12-18 10:50 - 2015-12-07 04:14 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll 2015-12-18 10:50 - 2015-12-07 04:00 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll 2015-12-18 10:50 - 2015-12-07 03:37 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2015-12-18 10:50 - 2015-12-07 03:34 - 00936448 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll 2015-12-18 10:50 - 2015-12-07 03:36 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll 2015-12-10 03:56 - 2015-08-07 00:24 - 00116344 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2015-12-10 08:49 - 2015-12-10 08:49 - 00012800 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.1208.10480.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe 2015-12-10 08:49 - 2015-12-10 08:49 - 11542016 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.1208.10480.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll 2015-11-20 08:12 - 2015-11-20 08:12 - 00258560 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.1208.10480.0_x64__8wekyb3d8bbwe\StoreRatingPromotion.dll 2015-12-21 15:12 - 2015-11-17 02:33 - 00055328 _____ () C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\QtSolutions_Service-head.dll 2015-12-21 15:12 - 2015-11-17 02:33 - 00103968 _____ () C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\qjson0.dll 2016-01-11 13:52 - 2014-05-13 12:04 - 00109400 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl 2016-01-11 13:52 - 2014-05-13 12:04 - 00167768 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl 2016-01-11 13:52 - 2014-05-13 12:04 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl 2016-01-11 13:52 - 2012-08-23 10:38 - 00574840 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll 2016-01-11 13:52 - 2012-04-03 17:06 - 00565640 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\av\BDSmartDB.dll 2015-12-10 03:56 - 2016-01-11 15:48 - 00032768 _____ () C:\Program Files (x86)\ASUS\AXSP\1.02.00\PEbiosinterface32.dll 2015-12-10 03:56 - 2014-01-28 03:16 - 00104448 _____ () C:\Program Files (x86)\ASUS\AXSP\1.02.00\ATKEX.dll 2015-12-18 12:04 - 2015-12-18 12:04 - 00533904 _____ () C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\40.2.4\log4cplusU.dll 2014-03-20 10:43 - 2014-03-20 10:43 - 01241560 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll 2015-02-25 15:02 - 2015-11-12 18:39 - 00012080 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll 2015-12-08 02:41 - 2015-12-08 02:41 - 40500224 _____ () C:\Program Files (x86)\AVG\UiDll\2171\libcef.dll 2009-02-26 09:45 - 2009-02-26 09:45 - 00024912 _____ () C:\Program Files (x86)\Microsoft Office\Office12\Wordcnvpxy.cnv ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxldtlfudivq`qsp`26hfm ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) IE trusted site: HKU\S-1-5-21-3488279127-63086370-3813774398-1001\...\localhost -> localhost IE trusted site: HKU\S-1-5-21-3488279127-63086370-3813774398-1001\...\webcompanion.com -> hxxp://webcompanion.com IE trusted site: HKU\S-1-5-21-3488279127-63086370-3813774398-1004\...\localhost -> localhost IE trusted site: HKU\S-1-5-21-3488279127-63086370-3813774398-1004\...\webcompanion.com -> hxxp://webcompanion.com ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2013-08-22 13:25 - 2013-08-22 13:25 - 00000824 ____N C:\WINDOWS\system32\Drivers\etc\hosts ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-3488279127-63086370-3813774398-1001\Control Panel\Desktop\\Wallpaper -> HKU\S-1-5-21-3488279127-63086370-3813774398-1004\Control Panel\Desktop\\Wallpaper -> C:\Users\maggi_000\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper HKU\S-1-5-21-3488279127-63086370-3813774398-1005\Control Panel\Desktop\\Wallpaper -> C:\Users\cmcga_000\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\img2.jpg DNS Servers: [removed] - [removed] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) HKLM\...\StartupApproved\StartupFolder: => "McAfee Security Scan Plus.lnk" HKLM\...\StartupApproved\Run: => "MouseDriver" HKLM\...\StartupApproved\Run: => "ShadowPlay" HKLM\...\StartupApproved\Run: => "NvBackend" HKLM\...\StartupApproved\Run: => "AdobeAAMUpdater-1.0" HKLM\...\StartupApproved\Run: => "Autodesk Sync" HKLM\...\StartupApproved\Run: => "XMouseButtonControl" HKLM\...\StartupApproved\Run32: => "KiesTrayAgent" HKLM\...\StartupApproved\Run32: => "Adobe Creative Cloud" HKLM\...\StartupApproved\Run32: => "AdobeCS4ServiceManager" HKLM\...\StartupApproved\Run32: => "vProt" HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched" HKLM\...\StartupApproved\Run32: => "ADSKAppManager" HKLM\...\StartupApproved\Run32: => "WinCalendar V4" HKLM\...\StartupApproved\Run32: => "AdVPN" HKLM\...\StartupApproved\Run32: => "AdobeAAMUpdater-1.0" HKU\S-1-5-21-3488279127-63086370-3813774398-1001\...\StartupApproved\StartupFolder: => "OpenOffice.org 3.1.lnk" HKU\S-1-5-21-3488279127-63086370-3813774398-1001\...\StartupApproved\StartupFolder: => "Send to OneNote.lnk" HKU\S-1-5-21-3488279127-63086370-3813774398-1001\...\StartupApproved\Run: => "KiesAirMessage" HKU\S-1-5-21-3488279127-63086370-3813774398-1001\...\StartupApproved\Run: => "Akamai NetSession Interface" HKU\S-1-5-21-3488279127-63086370-3813774398-1001\...\StartupApproved\Run: => "Autodesk Sync" HKU\S-1-5-21-3488279127-63086370-3813774398-1001\...\StartupApproved\Run: => "Sony PC Companion" HKU\S-1-5-21-3488279127-63086370-3813774398-1001\...\StartupApproved\Run: => "Browser Extensions" HKU\S-1-5-21-3488279127-63086370-3813774398-1001\...\StartupApproved\Run: => "Search Protection" HKU\S-1-5-21-3488279127-63086370-3813774398-1001\...\StartupApproved\Run: => "WinCalendar V4" HKU\S-1-5-21-3488279127-63086370-3813774398-1001\...\StartupApproved\Run: => "NvLedServiceHost" HKU\S-1-5-21-3488279127-63086370-3813774398-1001\...\StartupApproved\Run: => "Skype" HKU\S-1-5-21-3488279127-63086370-3813774398-1001\...\StartupApproved\Run: => "Web Companion" HKU\S-1-5-21-3488279127-63086370-3813774398-1001\...\StartupApproved\Run: => "OneDrive" HKU\S-1-5-21-3488279127-63086370-3813774398-1001\...\StartupApproved\Run: => "AdobeBridge" HKU\S-1-5-21-3488279127-63086370-3813774398-1001\...\StartupApproved\Run: => "CCleaner Monitoring" HKU\S-1-5-21-3488279127-63086370-3813774398-1001\...\StartupApproved\Run: => "uTorrent" HKU\S-1-5-21-3488279127-63086370-3813774398-1004\...\StartupApproved\StartupFolder: => "OpenOffice.org 3.1.lnk" HKU\S-1-5-21-3488279127-63086370-3813774398-1004\...\StartupApproved\StartupFolder: => "Send to OneNote.lnk" HKU\S-1-5-21-3488279127-63086370-3813774398-1004\...\StartupApproved\Run: => "Jenkat Games Arcade App" HKU\S-1-5-21-3488279127-63086370-3813774398-1004\...\StartupApproved\Run: => "KiesAirMessage" HKU\S-1-5-21-3488279127-63086370-3813774398-1004\...\StartupApproved\Run: => "Autodesk Sync" HKU\S-1-5-21-3488279127-63086370-3813774398-1004\...\StartupApproved\Run: => "Sony PC Companion" HKU\S-1-5-21-3488279127-63086370-3813774398-1004\...\StartupApproved\Run: => "Browser Extensions" HKU\S-1-5-21-3488279127-63086370-3813774398-1004\...\StartupApproved\Run: => "Search Protection" HKU\S-1-5-21-3488279127-63086370-3813774398-1004\...\StartupApproved\Run: => "WinCalendar V4" HKU\S-1-5-21-3488279127-63086370-3813774398-1004\...\StartupApproved\Run: => "NvLedServiceHost" HKU\S-1-5-21-3488279127-63086370-3813774398-1004\...\StartupApproved\Run: => "Skype" HKU\S-1-5-21-3488279127-63086370-3813774398-1004\...\StartupApproved\Run: => "Web Companion" HKU\S-1-5-21-3488279127-63086370-3813774398-1005\...\StartupApproved\StartupFolder: => "OpenOffice.org 3.1.lnk" HKU\S-1-5-21-3488279127-63086370-3813774398-1005\...\StartupApproved\StartupFolder: => "Send to OneNote.lnk" HKU\S-1-5-21-3488279127-63086370-3813774398-1005\...\StartupApproved\Run: => "KiesAirMessage" HKU\S-1-5-21-3488279127-63086370-3813774398-1005\...\StartupApproved\Run: => "Autodesk Sync" HKU\S-1-5-21-3488279127-63086370-3813774398-1005\...\StartupApproved\Run: => "Sony PC Companion" HKU\S-1-5-21-3488279127-63086370-3813774398-1005\...\StartupApproved\Run: => "Browser Extensions" HKU\S-1-5-21-3488279127-63086370-3813774398-1005\...\StartupApproved\Run: => "Search Protection" HKU\S-1-5-21-3488279127-63086370-3813774398-1005\...\StartupApproved\Run: => "WinCalendar V4" HKU\S-1-5-21-3488279127-63086370-3813774398-1005\...\StartupApproved\Run: => "NvLedServiceHost" HKU\S-1-5-21-3488279127-63086370-3813774398-1005\...\StartupApproved\Run: => "Skype" HKU\S-1-5-21-3488279127-63086370-3813774398-1005\...\StartupApproved\Run: => "Web Companion" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [{7CBC7956-1BA8-43BB-A74E-EB6172252448}] => (Allow) C:\Users\stephen\Desktop\Microsoft Toolkit.exe FirewallRules: [{E553DA61-5AD2-4E9F-B418-F72D4E4B83D4}] => (Allow) C:\Users\stephen\Desktop\Microsoft Toolkit.exe FirewallRules: [{6F4B3880-2897-4AEA-A358-46E07766FA8E}] => (Allow) C:\Program Files (x86)\Sony Mobile\Update Engine\Sony Mobile Update Engine.exe FirewallRules: [{B38FB37B-D48E-40AA-AA53-48B4041F7265}] => (Allow) C:\Program Files (x86)\Sony Mobile\Update Engine\Sony Mobile Update Engine.exe FirewallRules: [{2EF60B3C-ACC3-404A-A9EC-E7989FC61FFE}] => (Allow) C:\Windows\SysWOW64\muzapp.exe FirewallRules: [{1CB05E20-B104-4166-B71C-AC6B936C1D08}] => (Allow) C:\Windows\SysWOW64\muzapp.exe FirewallRules: [{9374BA96-BE7D-4883-AFBF-8C441F8D79D5}] => (Allow) C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe FirewallRules: [{91DD439C-6FA0-4000-8DA5-59D42FCCAC3F}] => (Allow) C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe FirewallRules: [{24125DD9-AA1F-49BE-A6A0-FFBF6CC28DD2}] => (Allow) LPort=5353 FirewallRules: [{9AC77051-544D-4777-BE1E-98353290DB15}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{E001E44F-22D6-47DF-A714-A062EB080BE0}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{068EF7EC-734F-4A69-9BBD-15CC692D546B}] => (Allow) D:\SteamLibrary\SteamApps\common\Counter-Strike Source\hl2.exe FirewallRules: [{EF024DDE-6383-4686-B215-85076290742A}] => (Allow) D:\SteamLibrary\SteamApps\common\Counter-Strike Source\hl2.exe FirewallRules: [{BA69AFF2-69F8-46E5-9BE5-F03AF5825338}] => (Allow) D:\SteamLibrary\SteamApps\common\Call of Duty Modern Warfare 2\iw4sp.exe FirewallRules: [{557B27C5-7826-46B4-95FE-8BD57B9EE0EE}] => (Allow) D:\SteamLibrary\SteamApps\common\Call of Duty Modern Warfare 2\iw4sp.exe FirewallRules: [{6394831C-02BF-4287-930B-FC4D275A7934}] => (Allow) D:\Steam\SteamApps\common\Counter-Strike Source\hl2.exe FirewallRules: [{098645C1-557F-44BB-B643-751CCFCAFD17}] => (Allow) D:\Steam\SteamApps\common\Counter-Strike Source\hl2.exe FirewallRules: [TCP Query User{C2FC2D3A-4262-4D1E-BA2E-DC1B429550B0}C:\users\maggi_000\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\maggi_000\appdata\local\akamai\netsession_win.exe FirewallRules: [UDP Query User{8FB2C83A-E066-43BA-8787-362A7378B086}C:\users\maggi_000\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\maggi_000\appdata\local\akamai\netsession_win.exe FirewallRules: [TCP Query User{4D9CD4CE-45CD-46B5-B923-44C8157241BB}C:\users\maggi_000\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\maggi_000\appdata\local\akamai\netsession_win.exe FirewallRules: [UDP Query User{B9A97A59-FD91-4C84-80AD-ED932079DE84}C:\users\maggi_000\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\maggi_000\appdata\local\akamai\netsession_win.exe FirewallRules: [TCP Query User{2255D6C3-EE6E-437E-82AD-A6D7ABCD5EAB}D:\games\world_of_tanks\worldoftanks.exe] => (Allow) D:\games\world_of_tanks\worldoftanks.exe FirewallRules: [UDP Query User{890ADF07-6BCD-414F-89AA-63D1A3008C4C}D:\games\world_of_tanks\worldoftanks.exe] => (Allow) D:\games\world_of_tanks\worldoftanks.exe FirewallRules: [TCP Query User{E2230686-AB58-4AA0-B085-9DC67919B8DD}D:\program files (x86)\ubisoft\ubisoft game launcher\games\watch_dogs\bin\watch_dogs.exe] => (Allow) D:\program files (x86)\ubisoft\ubisoft game launcher\games\watch_dogs\bin\watch_dogs.exe FirewallRules: [UDP Query User{E1E613BE-AE79-4F84-BC01-56C5CE0F67CF}D:\program files (x86)\ubisoft\ubisoft game launcher\games\watch_dogs\bin\watch_dogs.exe] => (Allow) D:\program files (x86)\ubisoft\ubisoft game launcher\games\watch_dogs\bin\watch_dogs.exe FirewallRules: [TCP Query User{93384D67-8F48-4BFB-A704-A16D6EC6F66C}D:\games\world_of_tanks\wotlauncher.exe] => (Allow) D:\games\world_of_tanks\wotlauncher.exe FirewallRules: [UDP Query User{8D9A6708-CA59-4240-9954-1CC8F326C7D6}D:\games\world_of_tanks\wotlauncher.exe] => (Allow) D:\games\world_of_tanks\wotlauncher.exe FirewallRules: [{5315D542-B684-40BC-9455-D99A1B928CA6}] => (Allow) D:\Steam\Steam.exe FirewallRules: [{5031D340-6BB7-4737-B461-6C2244AB1B17}] => (Allow) D:\Steam\Steam.exe FirewallRules: [{A076CE23-C7DB-42B6-9F7B-5A7173877963}] => (Allow) D:\Steam\bin\steamwebhelper.exe FirewallRules: [{DBE3E056-EADD-488D-BB1D-1779A7F628AE}] => (Allow) D:\Steam\bin\steamwebhelper.exe FirewallRules: [{3F21404F-EC71-4D57-AD52-299FDEA0EA71}] => (Allow) D:\Steam\SteamApps\common\Call of Duty Modern Warfare 2\iw4sp.exe FirewallRules: [{7486BC65-D078-4038-AFBE-402256FBEE28}] => (Allow) D:\Steam\SteamApps\common\Call of Duty Modern Warfare 2\iw4sp.exe FirewallRules: [{632DC639-2249-4DD6-B372-490DF9B3E189}] => (Allow) D:\Steam\SteamApps\common\Portal\hl2.exe FirewallRules: [{43B37AC3-22C7-475D-9053-7605FA86C0E0}] => (Allow) D:\Steam\SteamApps\common\Portal\hl2.exe FirewallRules: [{CC41A8E8-3954-403D-B394-4C5F427EEDAF}] => (Allow) D:\Steam\SteamApps\common\Portal 2\portal2.exe FirewallRules: [{A84A0001-59E7-4CA7-AC90-096ED32B26EB}] => (Allow) D:\Steam\SteamApps\common\Portal 2\portal2.exe FirewallRules: [TCP Query User{639B8B9F-5FAB-4E9B-9A1C-0A1CFA28042C}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe FirewallRules: [UDP Query User{209E4CB4-1A55-46F0-8424-408605D10BEF}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe FirewallRules: [{F2321D11-B5D4-47DE-BAD4-216E489A1267}] => (Allow) D:\Steam\SteamApps\common\Homeworld\HWLauncher\Launcher.exe FirewallRules: [{FC0A709D-5515-4E38-B0E8-969E75B285A4}] => (Allow) D:\Steam\SteamApps\common\Homeworld\HWLauncher\Launcher.exe FirewallRules: [{A361AE83-6FDB-4802-98B9-7CE0AD3F71F2}] => (Allow) D:\Steam\SteamApps\common\Half-Life 2\hl2.exe FirewallRules: [{DE470DEB-2C15-4ABE-A21C-105595FC022E}] => (Allow) D:\Steam\SteamApps\common\Half-Life 2\hl2.exe FirewallRules: [{5ED036ED-F5AB-4048-BDFC-E8B47D75749A}] => (Allow) D:\Program Files (x86)\FrostWire 6\FrostWire.exe FirewallRules: [{D17527EF-2462-4A78-9F98-2A7798A0EAC5}] => (Allow) D:\Program Files (x86)\FrostWire 6\FrostWire.exe FirewallRules: [{2A71F814-A5F1-430C-8D2B-AA8597A0366D}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{F764B9C8-2AD1-464C-8493-59B009595829}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{99FD8412-B44E-4C94-A701-01D404AFE09B}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe FirewallRules: [{7210F895-BB87-4A53-BBB4-8C64AA5EA79B}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{8DC7D9E8-38AC-4A62-A46B-1E522DE7B3AB}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{C2CE4B41-79A2-4B83-A8A0-BBD76D892A90}] => (Allow) D:\Steam\SteamApps\common\Fallout 3 goty\FalloutLauncher.exe FirewallRules: [{6387A010-1852-4255-8AC7-353FA14720C1}] => (Allow) D:\Steam\SteamApps\common\Fallout 3 goty\FalloutLauncher.exe FirewallRules: [TCP Query User{FCB16392-02A0-4C5E-893D-DE942B3B38F6}C:\users\stephen\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\stephen\appdata\local\akamai\netsession_win.exe FirewallRules: [UDP Query User{1BC21281-8C6D-467E-91EA-6399F4687AA3}C:\users\stephen\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\stephen\appdata\local\akamai\netsession_win.exe FirewallRules: [{5C259770-F980-4729-AC51-D6F946DBA4F7}] => (Allow) LPort=50248 FirewallRules: [{8C209DAE-C769-4D16-A8CA-04247FDF68EE}] => (Allow) C:\Program Files (x86)\AVG\Av\avgnsa.exe FirewallRules: [{563ACA44-5FBF-47FD-A368-945205C57BE6}] => (Allow) C:\Program Files (x86)\AVG\Av\avgnsa.exe FirewallRules: [{06CADD38-A975-479C-801F-433E8AA7ACEF}] => (Allow) C:\Program Files (x86)\AVG\Av\avgdiagex.exe FirewallRules: [{62E09C26-A72C-4760-993C-DB48D3A0D308}] => (Allow) C:\Program Files (x86)\AVG\Av\avgdiagex.exe FirewallRules: [{B978696B-8CD5-4D29-B5C9-0F471F7397AF}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{209C0677-1645-49D1-A58C-329A60652A50}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe] => Enabled:Spybot - Search & Destroy tray access StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe] => Enabled:Spybot-S&D 2 Scanner Service StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe] => Enabled:Spybot-S&D 2 Updater StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe] => Enabled:Spybot-S&D 2 Background update service ==================== Restore Points ========================= ATTENTION: System Restore is disabled ==================== Faulty Device Manager Devices ============= Name: NVIDIA High Definition Audio Description: NVIDIA High Definition Audio Class Guid: {4d36e96c-e325-11ce-bfc1-08002be10318} Manufacturer: NVIDIA Service: NVHDA Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: Turtle Beach PX11 Chat Description: USB Audio Device Class Guid: {4d36e96c-e325-11ce-bfc1-08002be10318} Manufacturer: (Generic USB Audio) Service: usbaudio Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: NVIDIA Virtual Audio Device (Wave Extensible) (WDM) Description: NVIDIA Virtual Audio Device (Wave Extensible) (WDM) Class Guid: {4d36e96c-e325-11ce-bfc1-08002be10318} Manufacturer: NVIDIA Service: nvvad_WaveExtensible Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (01/11/2016 03:40:51 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: IEXPLORE.EXE, version: 11.0.10586.20, time stamp: 0x56541caa Faulting module name: Flash.ocx, version: 20.0.0.272, time stamp: 0x56870c97 Exception code: 0xc0000005 Fault offset: 0x00356e71 Faulting process ID: 0x1750 Faulting application start time: 0xIEXPLORE.EXE0 Faulting application path: IEXPLORE.EXE1 Faulting module path: IEXPLORE.EXE2 Report ID: IEXPLORE.EXE3 Faulting package full name: IEXPLORE.EXE4 Faulting package-relative application ID: IEXPLORE.EXE5 Error: (01/11/2016 01:44:09 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: MAGGIE) Description: Activation of application Microsoft.Windows.Photos_8wekyb3d8bbwe!App failed with error: -2144927142 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (01/11/2016 07:40:52 AM) (Source: Perflib) (EventID: 1008) (User: ) Description: BITSC:\Windows\System32\bitsperf.dll8 Error: (01/10/2016 12:19:44 AM) (Source: Perflib) (EventID: 1008) (User: ) Description: BITSC:\Windows\System32\bitsperf.dll8 Error: (01/07/2016 09:47:16 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: MAGGIE) Description: Activation of application Microsoft.Windows.Photos_8wekyb3d8bbwe!App failed with error: -2147024891 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (01/07/2016 09:15:08 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: MAGGIE) Description: Activation of application Microsoft.Windows.Photos_8wekyb3d8bbwe!App failed with error: -2147024891 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (01/07/2016 08:17:59 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Maggie) Description: Activation of application Microsoft.Windows.Photos_8wekyb3d8bbwe!App failed with error: -2147024891 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (01/07/2016 12:03:21 AM) (Source: MsiInstaller) (EventID: 11706) (User: NT AUTHORITY) Description: SA_Error1709: StandardAction(0xC00706AD): Product: AVG -- Error 1706. SA_Error1706: StandardAction(0xC00706AA): An installation package for the product AVG cannot be found. Try the installation again using a valid copy of the installation package 'Avgx64.msi'. Error: (01/06/2016 10:00:44 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: MAGGIE) Description: Activation of application Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI failed with error: -2144927141 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (01/06/2016 10:00:44 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: MAGGIE) Description: Activation of application Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI failed with error: -2144927141 See the Microsoft-Windows-TWinUI/Operational log for additional information. System errors: ============= Error: (01/11/2016 09:29:14 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The User Data Access_a77c9c service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service. Error: (01/11/2016 09:29:14 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The User Data Storage_a77c9c service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service. Error: (01/11/2016 09:29:14 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The Contact Data_a77c9c service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service. Error: (01/11/2016 09:29:14 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The Sync Host_a77c9c service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service. Error: (01/11/2016 09:29:14 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: application-specificLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)UnavailableUnavailable Error: (01/11/2016 09:29:09 PM) (Source: DCOM) (EventID: 10016) (User: MAGGIE) Description: application-specificLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}MaggiestephenS-1-5-21-3488279127-63086370-3813774398-1001LocalHost (Using LRPC)UnavailableUnavailable Error: (01/11/2016 09:08:57 PM) (Source: DCOM) (EventID: 10016) (User: MAGGIE) Description: application-specificLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}MaggiestephenS-1-5-21-3488279127-63086370-3813774398-1001LocalHost (Using LRPC)UnavailableUnavailable Error: (01/11/2016 08:39:47 PM) (Source: DCOM) (EventID: 10016) (User: MAGGIE) Description: application-specificLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}MaggiestephenS-1-5-21-3488279127-63086370-3813774398-1001LocalHost (Using LRPC)UnavailableUnavailable Error: (01/11/2016 08:32:48 PM) (Source: DCOM) (EventID: 10016) (User: MAGGIE) Description: application-specificLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}MaggiestephenS-1-5-21-3488279127-63086370-3813774398-1001LocalHost (Using LRPC)UnavailableUnavailable Error: (01/11/2016 08:27:07 PM) (Source: DCOM) (EventID: 10016) (User: MAGGIE) Description: application-specificLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}MaggiestephenS-1-5-21-3488279127-63086370-3813774398-1001LocalHost (Using LRPC)UnavailableUnavailable CodeIntegrity: =================================== Date: 2016-01-07 06:03:29.732 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-01-06 12:05:05.684 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-01-01 06:33:13.012 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2015-12-30 09:09:18.138 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2015-12-21 15:18:30.918 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2015-12-21 03:38:26.138 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\winhttp.dll because the set of per-page image hashes could not be found on the system. Date: 2015-12-21 03:38:26.133 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\winhttp.dll because the set of per-page image hashes could not be found on the system. Date: 2015-12-21 03:38:26.076 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\winhttp.dll because the set of per-page image hashes could not be found on the system. Date: 2015-12-21 03:38:26.068 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\winhttp.dll because the set of per-page image hashes could not be found on the system. Date: 2015-12-21 03:38:26.060 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\winhttp.dll because the set of per-page image hashes could not be found on the system. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i7-4790 CPU @ 3.60GHz Percentage of memory in use: 17% Total physical RAM: 16326.05 MB Available physical RAM: 13432.3 MB Total Virtual: 18758.05 MB Available Virtual: 14653.44 MB ==================== Drives ================================ Drive c: (Windows) (Fixed) (Total:104.33 GB) (Free:19.04 GB) NTFS Drive d: () (Fixed) (Total:931.39 GB) (Free:752.04 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 111.8 GB) (Disk ID: 4BFB80C9) Partition: GPT. ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 00000000) Partition: GPT. ==================== End of Addition.txt ============================