Additional scan result of Farbar Recovery Scan Tool (x64) Version:17-01-2015 Ran by [removed] (2016-01-17 11:51:52) Running from E:\Users\[removed]\Downloads Windows 7 Professional Service Pack 1 (X64) (2012-02-11 15:21:20) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-3780434946-300326871-666920331-500 - Administrator - Disabled) Guest (S-1-5-21-3780434946-300326871-666920331-501 - Limited - Enabled) HomeGroupUser$ (S-1-5-21-3780434946-300326871-666920331-1011 - Limited - Enabled) Michel (S-1-5-21-3780434946-300326871-666920331-1001 - Administrator - Enabled) => C:\Users\Michel ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: McAfee Anti-Virus and Anti-Spyware (Enabled - Out of date) {DA9F8ED0-D0DE-39CC-F55A-51AB4CC1B556} AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: McAfee Anti-Virus and Anti-Spyware (Enabled - Out of date) {61FE6F34-F6E4-3642-CFEA-6AD93746FFEB} FW: McAfee Firewall (Enabled) {E2A40FF5-9AB1-3894-DE05-F89EB212F22D} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.010.20056 - Adobe Systems Incorporated) Adobe Flash Player 20 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 20.0.0.270 - Adobe Systems Incorporated) Adobe Flash Player 20 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 20.0.0.267 - Adobe Systems Incorporated) Adobe Flash Player 20 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 20.0.0.267 - Adobe Systems Incorporated) Apple Application Support (32-bit) (HKLM-x32\...\{7FA9ECCF-A2DE-4DA1-BFF3-81260DBDA68F}) (Version: 4.1.2 - Apple Inc.) Apple Application Support (64-bit) (HKLM\...\{691F30EB-9009-475A-B8A9-E1BF39598FD5}) (Version: 4.1.2 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{3540181E-340A-4E7A-B409-31663472B2F7}) (Version: 9.1.0.6 - Apple Inc.) Apple Software Update (HKLM-x32\...\{FFD1F7F1-1AC9-4BC4-A908-0686D635ABAF}) (Version: 2.1.4.131 - Apple Inc.) Assassin's Creed Syndicate (HKLM-x32\...\Uplay Install 1875) (Version: 1.31 - Ubisoft) ASUS PC Diagnostics (HKLM-x32\...\{D709005F-D8DC-42A8-8435-5AE880ECAF82}) (Version: 1.4.1 - ASUSTeK Computer Inc.) Big Pharma (HKLM-x32\...\1440407371_is1) (Version: 2.3.0.4 - GOG.com) BOINC (HKLM\...\{085CC3D7-09D0-4488-BAD2-A57E909EE1EC}) (Version: 7.6.9 - Space Sciences Laboratory, U.C. Berkeley) Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.) CCleaner (HKLM\...\CCleaner) (Version: 5.10 - Piriform) CutePDF Writer 2.8 (HKLM\...\CutePDF Writer Installation) (Version: - ) Dropbox (HKU\S-1-5-21-3780434946-300326871-666920331-1001\...\Dropbox) (Version: 3.12.5 - Dropbox, Inc.) Elite Dangerous Launcher version 0.4.4347.0 (HKLM-x32\...\{696F8871-C91D-4CB1-825D-36BE18065575}_is1) (Version: 0.4.4347.0 - Frontier Developments) Evernote v. 5.9.6 (HKLM-x32\...\{A542D366-9877-11E5-B101-005056951CAD}) (Version: 5.9.6.9494 - Evernote Corp.) FireStorm version V1.0.45.000 (HKLM-x32\...\FireStorm_is1) (Version: V1.0.45.000 - ) Galactic Civilizations III (HKLM-x32\...\Steam App 226860) (Version: - Stardock Entertainment) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 47.0.2526.111 - Google Inc.) Google Drive (HKLM-x32\...\{1C3D2F92-D25E-4D98-B810-3F3B0857BF26}) (Version: 1.26.0707.2863 - Google, Inc.) Google Earth (HKLM-x32\...\{817750FA-EC6A-485D-9901-0683AE6FFDF1}) (Version: 7.1.5.1557 - Google) Google Update Helper (x32 Version: 1.3.29.1 - Google Inc.) Hidden Grand Theft Auto V (HKLM-x32\...\Steam App 271590) (Version: - Rockstar North) HP FWUpdateEDO2 (HKLM-x32\...\{415FA9AD-DA10-4ABE-97B6-5051D4795C90}) (Version: 1.2.0.0 - Hewlett-Packard) HP Officejet Pro 8610 Basic Device Software (HKLM\...\{DAE3B13B-5097-4EAE-BC26-C463377BD80E}) (Version: 32.2.188.47710 - Hewlett-Packard Co.) HP Officejet Pro 8610 Help (HKLM-x32\...\{F9569D00-4576-46C8-B6C7-207A4FD39745}) (Version: 32.0.0 - Hewlett Packard) HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard) HPDiagnosticAlert (x32 Version: 1.00.0001 - Microsoft) Hidden I.R.I.S. OCR (HKLM-x32\...\{CA6BCA2F-EDEB-408F-850B-31404BE16A61}) (Version: 12.3.4.0 - HP) iCloud (HKLM\...\{4B48E22A-2FB0-4EFA-B99E-954B1E50CD69}) (Version: 5.1.0.34 - Apple Inc.) Image Resizer for Windows (64 bit) (Version: 3.0.4802.35565 - Brice Lambson) Hidden Image Resizer for Windows (HKLM-x32\...\{69d72156-6582-4556-8637-06f40aa7f85b}) (Version: 3.0.4802.35565 - Brice Lambson) iTunes (HKLM\...\{FBEB98F8-64E4-4FA3-A15E-4A9F42FF962E}) (Version: 12.3.2.35 - Apple Inc.) Java 8 Update 66 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218066F0}) (Version: 8.0.660.18 - Oracle Corporation) Kerbal Space Program (HKLM-x32\...\Steam App 220200) (Version: - Squad) Logitech GamePanel Software 3.06.109 (HKLM\...\{A1E85B9A-AFAD-4D38-AF01-6B020DD5213A}) (Version: 3.06.109 - Logitech Inc.) Malwarebytes Anti-Exploit version 1.8.1.1045 (HKLM\...\Malwarebytes Anti-Exploit_is1) (Version: 1.8.1.1045 - Malwarebytes) Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes) McAfee Internet Security (HKLM-x32\...\MSC) (Version: 14.0.6136 - McAfee, Inc.) McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.11.266.3 - McAfee, Inc.) McAfee WebAdvisor (HKLM-x32\...\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}) (Version: 4.0.207 - McAfee, Inc.) Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation) Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation) Microsoft Mouse and Keyboard Center (HKLM\...\Microsoft Mouse and Keyboard Center) (Version: 2.3.188.0 - Microsoft Corporation) Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-3780434946-300326871-666920331-1001\...\OneDriveSetup.exe) (Version: 17.3.6281.1202 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable - KB2467175 (HKLM-x32\...\{a0fe116e-9a8a-466f-aee0-625cb7c207e3}) (Version: 8.0.51011 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}) (Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: - ) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: - ) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Microsoft Xbox 360 Accessories 1.2 (HKLM\...\{D9C50188-12D5-4D3E-8F00-682346C2AA5F}) (Version: 1.20.146.0 - Microsoft) Mozilla Firefox 43.0.4 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 43.0.4 (x86 en-US)) (Version: 43.0.4 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 43.0.4 - Mozilla) MySQL Connector/ODBC 3.51 (HKLM-x32\...\{6A85286D-BA0F-4318-8C30-AD74A33AAD36}) (Version: - ) MySQL Connector/ODBC 5.2(a) (HKLM-x32\...\{6BAA9A62-1520-4063-A5B4-FFB3D6EC62BB}) (Version: - ) Nero Update (HKLM-x32\...\{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}) (Version: - ) Nikon Message Center 2 (HKLM-x32\...\{B014EE44-9197-4513-9613-71E6EB1B514E}) (Version: - ) Nikon Movie Editor (HKLM-x32\...\{5CAD3393-EEC0-44CE-9F93-BCAA365B77FB}) (Version: 2.9.2 - Nikon) NVIDIA 3D Vision Controller Driver 352.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 352.65 - NVIDIA Corporation) NVIDIA 3D Vision Driver 361.43 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 361.43 - NVIDIA Corporation) NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.7 - NVIDIA Corporation) NVIDIA GeForce Experience 2.8.1.21 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.8.1.21 - NVIDIA Corporation) NVIDIA Graphics Driver 361.43 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 361.43 - NVIDIA Corporation) NVIDIA HD Audio Driver 1.3.34.4 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.4 - NVIDIA Corporation) NVIDIA PhysX System Software 9.15.0428 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation) Oracle VM VirtualBox 4.3.12 (HKLM\...\{B5121457-0126-4E62-BCBF-6DC7C73D9E4A}) (Version: 4.3.12 - Oracle Corporation) PeerBlock 1.2 (r693) (HKLM\...\{015C5B35-B678-451C-9AEE-821E8D69621C}_is1) (Version: 1.2.0.693 - PeerBlock, LLC) Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9 - Google, Inc.) Picture Control Utility x64 (HKLM\...\{11953C65-BB4E-4CA4-B0F0-2600A4B20040}) (Version: 1.5.1 - Nikon) Pinnacle Game Profiler (HKLM-x32\...\{49BF48CC-ABB6-4795-9B35-B5DE005D8612}) (Version: 7.6.9 - PowerUp Software) Plex Media Server (HKLM-x32\...\{24f6f734-f790-479b-bd0f-38409a456508}) (Version: 0.9.1219 - Plex, Inc.) Plex Media Server (x32 Version: 0.9.1219 - Plex, Inc.) Hidden Portal 2 (HKLM-x32\...\Steam App 620) (Version: - Valve) Portal Stories: Mel (HKLM-x32\...\Steam App 317400) (Version: - Prism Studios) Product Improvement Study for HP Officejet Pro 8610 (HKLM\...\{710F7B0F-A679-4314-8E69-E868B660FAEA}) (Version: 32.2.188.47710 - Hewlett-Packard Co.) QuickTime 7 (HKLM-x32\...\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}) (Version: 7.79.80.95 - Apple Inc.) Recuva (HKLM\...\Recuva) (Version: 1.47 - Piriform) ROCCAT Power-Grid version 0.461 (HKLM-x32\...\{953CF6E6-4EC8-4E55-A263-720CEBD591FE}_is1) (Version: 0.461 - ROCCAT GmbH) Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.1.6.5 - Rockstar Games) Sage 50 Accounting (x32 Version: 22.20.1001 - Sage Software) Hidden Sage 50 Accounting Version 2015 (HKLM-x32\...\InstallShield_{1585982E-766D-476A-BF0D-5FE4A1C1BE9F}) (Version: 22.20.1001 - Sage Software) Shared C Run-time for x64 (HKLM\...\{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee) SHIELD Streaming (Version: 4.1.0250 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: 2.8.1.21 - NVIDIA Corporation) Hidden Should I Remove It (HKU\S-1-5-21-3780434946-300326871-666920331-1001\...\Should I Remove It 1.0.4) (Version: 1.0.4 - Reason Software Company Inc.) Should I Remove It (x32 Version: 1.0.4 - Reason Software Company Inc.) Hidden Sid Meier's Civilization V (HKLM-x32\...\Steam App 8930) (Version: - 2K Games, Inc.) Silent Hunter: Wolves of the Pacific (HKLM-x32\...\Steam App 15200) (Version: - Ubisoft Romania) Snagit 11 (HKLM-x32\...\{68723B04-57EC-11E1-A6A8-9E2D4824019B}) (Version: - ) Sniper Elite 3 (HKLM-x32\...\Steam App 238090) (Version: - Rebellion) Splinter Cell Blacklist (HKLM-x32\...\Uplay Install 91) (Version: - Ubisoft) Take On Mars (HKLM-x32\...\Steam App 244030) (Version: - Bohemia Interactive) TurboTax 2014 (HKLM-x32\...\{0B69B187-4F9F-41C2-B850-735D1A323571}) (Version: 1.00.0000 - Intuit Canada) UnionCam Player 1.1 (HKLM-x32\...\UnionCam Player_is1) (Version: 1.1 - UnionCam Software) Unreal Development Kit: 2012-10 (HKLM\...\UDK-75d44512-c0ed-4247-8eb4-652d9fd8ccea) (Version: - Epic Games, Inc.) Uplay (HKLM-x32\...\Uplay) (Version: 13.0 - Ubisoft) Uplink (HKLM-x32\...\GOGPACKUPLINK_is1) (Version: 2.0.0.5 - GOG.com) ViewNX 2 (HKLM\...\{635BE602-BB9C-4C59-8CC5-93F9366E8A21}) (Version: 2.9.2 - Nikon) VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN) WATCH_DOGS (HKLM-x32\...\Uplay Install 274) (Version: - Ubisoft) WinSCP 5.5.6 (HKLM-x32\...\winscp3_is1) (Version: 5.5.6 - Martin Prikryl) World of Warplanes (HKLM-x32\...\{1EAC1D02-C6AC-4FA6-9A44-96258C37C813NA}_is1) (Version: - Wargaming.net) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-3780434946-300326871-666920331-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Michel\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3780434946-300326871-666920331-1001_Classes\CLSID\{162C6FB5-44D3-435B-903D-E613FA093FB5}\InprocServer32 -> C:\Users\Michel\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64\FileCoAuthLib64.dll () CustomCLSID: HKU\S-1-5-21-3780434946-300326871-666920331-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Michel\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\FileCoAuth.exe (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3780434946-300326871-666920331-1001_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Michel\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3780434946-300326871-666920331-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Michel\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3780434946-300326871-666920331-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Michel\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3780434946-300326871-666920331-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Michel\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3780434946-300326871-666920331-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Michel\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3780434946-300326871-666920331-1001_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Michel\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3780434946-300326871-666920331-1001_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Michel\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3780434946-300326871-666920331-1001_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Michel\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3780434946-300326871-666920331-1001_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Michel\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3780434946-300326871-666920331-1001_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\Michel\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll (Dropbox, Inc.) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {0A359771-6CEF-4239-B287-7D9FE4A9C81C} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation) Task: {144A867C-987A-42F0-A5A4-FE1950474403} - \5ycytivy -> No File <==== ATTENTION Task: {1A11919C-6214-48D0-9698-3D03058E0FBC} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime => C:\Windows\system32\GWX\GWXUXWorker.exe [2015-12-05] (Microsoft Corporation) Task: {29DFF902-8490-4CD1-B7DA-A649231D3DB2} - \LaunchPreSignup -> No File <==== ATTENTION Task: {2D64FAB4-2E8C-43D1-9758-036621873753} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-01-02] (Adobe Systems Incorporated) Task: {2EFD59B4-379B-41ED-B2CB-655F5FBC91E7} - System32\Tasks\HPCustParticipation HP Officejet Pro 8610 => C:\Program Files\HP\HP Officejet Pro 8610\Bin\HPCustPartic.exe [2014-03-06] (Hewlett-Packard Co.) Task: {37A949A7-F16A-41DF-BE4B-E05A54ECEF0D} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation) Task: {44623DED-2121-4BDF-BB0A-8D9200C0791F} - System32\Tasks\Start Evernote Client => C:\Program Files (x86)\Evernote\Evernote\Evernote.exe [2015-12-01] (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) Task: {4B7E415F-9F2B-4FD9-A672-C7938290A981} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-12-13] (Adobe Systems Incorporated) Task: {526AA955-7E61-4995-9888-B3EE8C1FDC43} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2015-08-26] (Apple Inc.) Task: {56ADE151-F986-413B-9DFC-BE31BD86BC74} - System32\Tasks\McAfeeLogon => C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe [2015-11-02] (McAfee, Inc.) Task: {58F91133-FD71-4838-95F6-04264337FAD8} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation) Task: {5A40E926-9E86-4B89-9CFD-B12311724371} - System32\Tasks\Microsoft\Windows\UPnP\UPnPHostConfig => config upnphost start= auto Task: {69E5B344-72B7-4880-8B91-785E5B38AC7E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.) Task: {6B5E9620-CB20-4928-A167-D8C5A7749E3B} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation) Task: {73E60C7B-396E-4293-BB07-6E4ADCF7B2FF} - System32\Tasks\Intel Security DAT Reputation (AMCore) periodic endpoint safety pulse => C:\Program Files\Common Files\McAfee\AMContent\scanners\x86_64\datrep\21.0\mcdatrep.exe [2016-01-07] (McAfee, Inc.) Task: {82E0291F-8077-450F-AFF1-674CD9C97DF0} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.) Task: {875FDFE6-783B-44D1-B2B5-E55C2F45840B} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2014-03-19] (Microsoft) Task: {882C29BE-3903-4E8B-B7EF-FE676D21D875} - System32\Tasks\McAfee Remediation (Prepare) => C:\Program Files\Common Files\AV\McAfee Anti-Virus And Anti-Spyware\upgrade.exe [2015-11-03] (McAfee, Inc.) Task: {95745FE8-2990-4E33-A207-EFBAEE74D6BE} - \SaferUpdateTaskSCUD -> No File <==== ATTENTION Task: {AA15B9C4-6D54-410F-AAD2-CB4E43499567} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-09-16] (Piriform Ltd) Task: {B5BA10D2-395E-4165-932A-F459797140EC} - System32\Tasks\ASUS\ASUS RegRun Loader => C:\Program Files (x86)\ASUS\AASP\1.00.91\AsLoader.exe [2008-07-02] () Task: {B90008D1-9452-47B2-B4DC-83FE9174E55D} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime => C:\Windows\system32\GWX\GWXUXWorker.exe [2015-12-05] (Microsoft Corporation) Task: {C2EA4A50-6A42-421E-91D0-B0B3B2CCE98F} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-3780434946-300326871-666920331-1001Core => C:\Users\Michel\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-18] (Dropbox, Inc.) Task: {D95D2D00-2A80-464F-9A22-EB37127CE53F} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-3780434946-300326871-666920331-1001UA => C:\Users\Michel\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-18] (Dropbox, Inc.) Task: {DD9F510C-95F4-499A-90C8-BAC5BC372FF4} - System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask => start sppsvc Task: {ECA5A0EA-57DD-447B-9B34-A62FC6FC92EB} - System32\Tasks\McAfee\McAfee Idle Detection Task Task: {EFC7EC5B-53C8-4959-AA61-574B3D61B527} - \LaunchPreSignup -> No File <==== ATTENTION Task: {F18FB285-0466-4A55-B4A2-A95CC8A1FB89} - System32\Tasks\dqwuloadio => C:\Windows\system32\config\systemprofile\AppData\Local\Trust <==== ATTENTION (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-3780434946-300326871-666920331-1001Core.job => C:\Users\Michel\AppData\Local\Dropbox\Update\DropboxUpdate.exe Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-3780434946-300326871-666920331-1001UA.job => C:\Users\Michel\AppData\Local\Dropbox\Update\DropboxUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== 2012-03-08 11:32 - 2009-11-05 08:40 - 00085504 _____ () C:\Windows\System32\cpwmon64.dll 2015-01-20 22:35 - 2015-01-20 22:35 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2015-10-13 04:45 - 2015-10-13 04:45 - 01328912 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2015-12-21 16:10 - 2015-12-16 12:34 - 00217720 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamBase.dll 2015-10-13 04:46 - 2015-10-13 04:46 - 01040144 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2014-01-20 13:17 - 2014-01-20 13:17 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2015-10-13 04:45 - 2015-10-13 04:45 - 00237328 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxslt.dll 2015-03-30 18:46 - 2015-12-16 12:34 - 00011896 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll 2015-11-16 04:47 - 2015-11-16 04:47 - 50648576 _____ () I:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\libcef.dll 2015-12-11 02:33 - 2015-10-30 19:59 - 00034768 _____ () C:\Users\Michel\AppData\Roaming\Dropbox\bin\_multiprocessing.pyd 2015-12-11 02:33 - 2015-10-30 20:00 - 00019408 _____ () C:\Users\Michel\AppData\Roaming\Dropbox\bin\faulthandler.pyd 2015-12-11 02:33 - 2015-12-08 16:36 - 00022848 _____ () C:\Users\Michel\AppData\Roaming\Dropbox\bin\Crypto.Random.OSRNG.winrandom.pyd 2015-12-11 02:33 - 2015-12-08 16:36 - 00023352 _____ () C:\Users\Michel\AppData\Roaming\Dropbox\bin\Crypto.Util._counter.pyd 2015-12-11 02:33 - 2015-12-08 16:36 - 00042296 _____ () C:\Users\Michel\AppData\Roaming\Dropbox\bin\Crypto.Cipher._AES.pyd 2015-12-11 02:33 - 2015-10-30 19:59 - 00116688 _____ () C:\Users\Michel\AppData\Roaming\Dropbox\bin\pywintypes27.dll 2015-12-11 02:33 - 2015-10-30 19:59 - 00093640 _____ () C:\Users\Michel\AppData\Roaming\Dropbox\bin\_ctypes.pyd 2015-12-11 02:33 - 2015-10-30 19:59 - 00018376 _____ () C:\Users\Michel\AppData\Roaming\Dropbox\bin\select.pyd 2015-12-11 02:33 - 2015-12-08 16:36 - 00019760 _____ () C:\Users\Michel\AppData\Roaming\Dropbox\bin\tornado.speedups.pyd 2015-12-11 02:33 - 2015-10-30 20:00 - 00105928 _____ () C:\Users\Michel\AppData\Roaming\Dropbox\bin\win32api.pyd 2015-12-11 02:33 - 2015-10-30 19:59 - 00392144 _____ () C:\Users\Michel\AppData\Roaming\Dropbox\bin\pythoncom27.dll 2015-12-11 02:33 - 2015-12-08 16:36 - 00381752 _____ () C:\Users\Michel\AppData\Roaming\Dropbox\bin\win32com.shell.shell.pyd 2015-12-11 02:33 - 2015-10-30 19:59 - 00692688 _____ () C:\Users\Michel\AppData\Roaming\Dropbox\bin\unicodedata.pyd 2015-12-11 02:33 - 2015-12-08 16:36 - 00020816 _____ () C:\Users\Michel\AppData\Roaming\Dropbox\bin\cryptography.hazmat.bindings._constant_time.pyd 2015-12-11 02:33 - 2015-10-30 20:00 - 00109520 _____ () C:\Users\Michel\AppData\Roaming\Dropbox\bin\_cffi_backend.pyd 2015-12-11 02:33 - 2015-12-08 16:36 - 01737032 _____ () C:\Users\Michel\AppData\Roaming\Dropbox\bin\cryptography.hazmat.bindings._openssl.pyd 2015-12-11 02:33 - 2015-12-08 16:36 - 00020808 _____ () C:\Users\Michel\AppData\Roaming\Dropbox\bin\cryptography.hazmat.bindings._padding.pyd 2015-12-11 02:33 - 2015-12-08 16:36 - 00020800 _____ () C:\Users\Michel\AppData\Roaming\Dropbox\bin\_cffi_python_x66cf7a7cx17a72769.pyd 2015-12-11 02:33 - 2015-12-08 16:36 - 00021840 _____ () C:\Users\Michel\AppData\Roaming\Dropbox\bin\_cffi_unicode_environ_win32_x8bf8e68bx9968e850.pyd 2015-12-11 02:33 - 2015-12-08 16:36 - 00038696 _____ () C:\Users\Michel\AppData\Roaming\Dropbox\bin\fastpath.pyd 2015-12-11 02:33 - 2015-10-30 20:00 - 00024528 _____ () C:\Users\Michel\AppData\Roaming\Dropbox\bin\win32event.pyd 2015-12-11 02:33 - 2015-10-30 20:00 - 00020936 _____ () C:\Users\Michel\AppData\Roaming\Dropbox\bin\mmapfile.pyd 2015-12-11 02:33 - 2015-10-30 20:00 - 00114640 _____ () C:\Users\Michel\AppData\Roaming\Dropbox\bin\win32security.pyd 2015-12-11 02:33 - 2015-12-08 16:36 - 00021320 _____ () C:\Users\Michel\AppData\Roaming\Dropbox\bin\_cffi_pywin_kernel32_xde9e4433x360333f0.pyd 2015-12-11 02:33 - 2015-10-30 20:00 - 00124880 _____ () C:\Users\Michel\AppData\Roaming\Dropbox\bin\win32file.pyd 2015-12-11 02:33 - 2015-10-30 20:00 - 00030160 _____ () C:\Users\Michel\AppData\Roaming\Dropbox\bin\win32pipe.pyd 2015-12-11 02:33 - 2015-10-30 20:00 - 00043472 _____ () C:\Users\Michel\AppData\Roaming\Dropbox\bin\win32process.pyd 2015-12-11 02:33 - 2015-10-30 20:00 - 00175560 _____ () C:\Users\Michel\AppData\Roaming\Dropbox\bin\win32gui.pyd 2015-12-11 02:33 - 2015-10-30 20:00 - 00028616 _____ () C:\Users\Michel\AppData\Roaming\Dropbox\bin\win32ts.pyd 2015-12-11 02:33 - 2015-10-30 20:00 - 00024016 _____ () C:\Users\Michel\AppData\Roaming\Dropbox\bin\win32clipboard.pyd 2015-12-11 02:33 - 2015-10-30 20:00 - 00048592 _____ () C:\Users\Michel\AppData\Roaming\Dropbox\bin\win32service.pyd 2015-12-11 02:33 - 2015-12-08 16:36 - 00024392 _____ () C:\Users\Michel\AppData\Roaming\Dropbox\bin\librsyncffi.compiled._librsyncffi.pyd 2015-12-11 02:33 - 2015-10-30 20:00 - 00036296 _____ () C:\Users\Michel\AppData\Roaming\Dropbox\bin\librsync.dll 2015-12-11 02:33 - 2015-10-30 20:00 - 00024016 _____ () C:\Users\Michel\AppData\Roaming\Dropbox\bin\win32profile.pyd 2015-12-11 02:33 - 2015-12-08 16:36 - 00117056 _____ () C:\Users\Michel\AppData\Roaming\Dropbox\bin\breakpad.client.windows.handler.pyd 2015-12-11 02:33 - 2015-12-08 16:36 - 00023376 _____ () C:\Users\Michel\AppData\Roaming\Dropbox\bin\winscreenshot.compiled._CaptureScreenshot.pyd 2015-12-11 02:33 - 2015-10-30 19:59 - 00134608 _____ () C:\Users\Michel\AppData\Roaming\Dropbox\bin\_elementtree.pyd 2015-12-11 02:33 - 2015-10-30 19:59 - 00134088 _____ () C:\Users\Michel\AppData\Roaming\Dropbox\bin\pyexpat.pyd 2015-12-11 02:33 - 2015-10-30 20:00 - 00240584 _____ () C:\Users\Michel\AppData\Roaming\Dropbox\bin\jpegtran.pyd 2015-12-11 02:33 - 2015-12-08 16:36 - 00020280 _____ () C:\Users\Michel\AppData\Roaming\Dropbox\bin\cpuid.compiled._cpuid.pyd 2015-12-11 02:33 - 2015-12-08 16:36 - 00052024 _____ () C:\Users\Michel\AppData\Roaming\Dropbox\bin\psutil._psutil_windows.pyd 2015-12-11 02:33 - 2015-12-08 16:36 - 00021304 _____ () C:\Users\Michel\AppData\Roaming\Dropbox\bin\Crypto.Util.strxor.pyd 2015-12-11 02:33 - 2015-10-30 20:00 - 00350152 _____ () C:\Users\Michel\AppData\Roaming\Dropbox\bin\winxpgui.pyd 2015-12-11 02:33 - 2015-12-08 16:36 - 00084792 _____ () C:\Users\Michel\AppData\Roaming\Dropbox\bin\dropbox_sqlite_ext.DLL 2015-12-11 02:33 - 2015-12-08 16:36 - 01826608 _____ () C:\Users\Michel\AppData\Roaming\Dropbox\bin\PyQt5.QtCore.pyd 2015-12-11 02:33 - 2015-10-30 20:00 - 00083912 _____ () C:\Users\Michel\AppData\Roaming\Dropbox\bin\sip.pyd 2015-12-11 02:33 - 2015-12-08 16:36 - 03891504 _____ () C:\Users\Michel\AppData\Roaming\Dropbox\bin\PyQt5.QtWidgets.pyd 2015-12-11 02:33 - 2015-12-08 16:36 - 01950000 _____ () C:\Users\Michel\AppData\Roaming\Dropbox\bin\PyQt5.QtGui.pyd 2015-12-11 02:33 - 2015-12-08 16:36 - 00519984 _____ () C:\Users\Michel\AppData\Roaming\Dropbox\bin\PyQt5.QtNetwork.pyd 2015-12-11 02:33 - 2015-12-08 16:36 - 00133936 _____ () C:\Users\Michel\AppData\Roaming\Dropbox\bin\PyQt5.QtWebKit.pyd 2015-12-11 02:33 - 2015-12-08 16:36 - 00225080 _____ () C:\Users\Michel\AppData\Roaming\Dropbox\bin\PyQt5.QtWebKitWidgets.pyd 2015-12-11 02:33 - 2015-12-08 16:36 - 00207672 _____ () C:\Users\Michel\AppData\Roaming\Dropbox\bin\PyQt5.QtPrintSupport.pyd 2015-12-11 02:33 - 2015-12-08 16:36 - 00024904 _____ () C:\Users\Michel\AppData\Roaming\Dropbox\bin\_cffi_wpad_proxy_win_x752e3d61xdcfdcc84.pyd 2015-12-11 02:33 - 2015-12-08 16:36 - 00486704 _____ () C:\Users\Michel\AppData\Roaming\Dropbox\bin\PyQt5.QtQuick.pyd 2015-12-11 02:33 - 2015-12-08 16:36 - 00357680 _____ () C:\Users\Michel\AppData\Roaming\Dropbox\bin\PyQt5.QtQml.pyd 2015-03-04 16:45 - 2015-10-30 20:01 - 00019920 _____ () C:\Users\Michel\AppData\Roaming\Dropbox\bin\QtQuick.2\qtquick2plugin.dll 2015-03-04 16:45 - 2015-10-30 20:00 - 00786904 _____ () C:\Users\Michel\AppData\Roaming\Dropbox\bin\QtQuick\Controls\qtquickcontrolsplugin.dll 2015-08-04 08:55 - 2015-10-30 20:00 - 00063448 _____ () C:\Users\Michel\AppData\Roaming\Dropbox\bin\QtQuick\Layouts\qquicklayoutsplugin.dll 2015-03-04 16:45 - 2015-10-30 20:00 - 00019408 _____ () C:\Users\Michel\AppData\Roaming\Dropbox\bin\QtQuick\Window.2\windowplugin.dll 2013-03-12 16:10 - 2015-11-10 14:55 - 00778752 _____ () E:\Program Files (x86)\Steam\SDL2.dll 2015-02-07 10:53 - 2015-07-03 11:12 - 04962816 _____ () E:\Program Files (x86)\Steam\v8.dll 2015-02-07 10:53 - 2015-07-03 11:12 - 01556992 _____ () E:\Program Files (x86)\Steam\icui18n.dll 2015-02-07 10:53 - 2015-07-03 11:12 - 01187840 _____ () E:\Program Files (x86)\Steam\icuuc.dll 2014-05-23 13:14 - 2015-12-14 15:01 - 02547280 _____ () E:\Program Files (x86)\Steam\video.dll 2014-09-10 06:51 - 2015-09-23 19:33 - 02549248 _____ () E:\Program Files (x86)\Steam\libavcodec-56.dll 2014-09-10 06:51 - 2015-09-23 19:33 - 00442880 _____ () E:\Program Files (x86)\Steam\libavutil-54.dll 2014-09-10 06:51 - 2015-09-23 19:33 - 00491008 _____ () E:\Program Files (x86)\Steam\libavformat-56.dll 2014-09-10 06:51 - 2015-09-23 19:33 - 00332800 _____ () E:\Program Files (x86)\Steam\libavresample-2.dll 2014-09-10 06:51 - 2015-09-23 19:33 - 00485888 _____ () E:\Program Files (x86)\Steam\libswscale-3.dll 2011-07-13 07:58 - 2015-12-14 15:01 - 00804432 _____ () E:\Program Files (x86)\Steam\bin\chromehtml.DLL 2015-07-24 14:56 - 2015-11-03 17:00 - 00201728 _____ () E:\Program Files (x86)\Steam\bin\openvr_api.dll 2010-05-02 11:10 - 2015-11-16 19:31 - 47846176 _____ () E:\Program Files (x86)\Steam\bin\libcef.dll 2016-01-14 18:45 - 2016-01-12 11:35 - 01590088 _____ () C:\Program Files (x86)\Google\Chrome\Application\47.0.2526.111\libglesv2.dll 2016-01-14 18:45 - 2016-01-12 11:35 - 00087880 _____ () C:\Program Files (x86)\Google\Chrome\Application\47.0.2526.111\libegl.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\Windows\SysWOW64\zlib.dll:DocumentSummaryInformation AlternateDataStreams: C:\Windows\SysWOW64\zlib.dll:SummaryInformation AlternateDataStreams: C:\Windows\SysWOW64\zlib.dll:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\82357907.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\82357907.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\atashost => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McNaiAnn => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfemms => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver" ==================== EXE Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-13 21:34 - 2015-12-16 13:34 - 00000057 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost 0.0.0.1 mssplus.mcafee.com ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-3780434946-300326871-666920331-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Michel\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: [removed] - [removed] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 0) Windows Firewall is disabled. ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) MSCONFIG\Services: Fitbit Connect => 2 MSCONFIG\Services: ForceWare Intelligent Application Manager (IAM) => 2 MSCONFIG\Services: MediaMall Server => 2 MSCONFIG\Services: nSvcIp => 2 MSCONFIG\Services: Sage 50 Transaction Manager 2014 - CDN => 3 ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe FirewallRules: [{2FC5E816-3EC5-4C96-8F50-5BB14CFD4B6A}] => (Allow) E:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{8731132B-D03F-4AE9-AEF1-FC40BF793218}] => (Allow) E:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{7D3F6CB9-EFC0-4021-A074-372F0277833D}] => (Allow) C:\Users\Michel\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [{B2E9AF83-C40C-4BCB-9195-E637306BE558}] => (Allow) C:\Users\Michel\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [{3013EC6C-6FFC-4094-84D9-861A529C6F7C}] => (Allow) LPort=5353 FirewallRules: [{83B86A85-374F-49CB-A0C1-D54B1F7F69EE}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{BD3F616E-313D-4F1F-9AA3-49129F6D90B1}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{5934DAC4-79F1-454E-8262-A1E26DA917D0}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{FA086B76-BF9B-4EB8-8070-7F1AC2507DA3}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{CC105E72-7A46-4A48-A267-009E963BE30D}] => (Allow) LPort=9322 FirewallRules: [{62069951-76FE-410D-81AC-F20463F5591A}] => (Allow) LPort=5353 FirewallRules: [{24AE63F6-7EB7-4DB4-8976-7463D1D3CAC3}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe FirewallRules: [{F843240C-AAC9-4DC1-A294-704B6F7367A0}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe FirewallRules: [{1D3450C7-B1C5-4322-94D1-A88ADE31E31E}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe FirewallRules: [{2373A71F-E3C6-49D4-9F8F-22C685A6ACB4}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe FirewallRules: [{19428017-1E1C-4FD2-9316-F56CB38411BB}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\Railroad Tycoon 2 Platinum\RT2_PLAT.EXE FirewallRules: [{A7F51A3D-23E7-4D25-9B8F-568842AAC919}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\Railroad Tycoon 2 Platinum\RT2_PLAT.EXE FirewallRules: [{D397FA4B-1ED8-4BAC-B63C-F588544B29F6}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.524\Agent.exe FirewallRules: [{C89AE11A-08B3-4D5E-A317-68FA370976A5}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.524\Agent.exe FirewallRules: [{80870918-3A87-48CE-8280-EDB08E0838CA}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1225\Agent.exe FirewallRules: [{80D07129-BA34-486C-B3FB-DAE67492ED6F}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1225\Agent.exe FirewallRules: [{4998F4C5-A321-4843-B227-2A9E80FC5478}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1267\Agent.exe FirewallRules: [{3FEF42F7-4A47-423E-87A9-34E7E4952013}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1267\Agent.exe FirewallRules: [{DA3C98D8-B049-4FCD-8C27-DD275A9569D0}] => (Allow) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe FirewallRules: [{81DB63EA-AAC0-4765-A855-2BC697A3F1CC}] => (Allow) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe FirewallRules: [{0FFC4631-2016-47B7-9A33-799CC4C27361}] => (Allow) E:\UDK\Custom\Binaries\Win32\UDK.exe FirewallRules: [{B9DCE0CE-279A-43D9-808D-C2450CA8DF18}] => (Allow) E:\UDK\Custom\Binaries\Win32\UDK.exe FirewallRules: [{9F7DD58A-4221-43A5-80B2-DB4ABEB32BCD}] => (Allow) E:\UDK\Custom\Binaries\Win64\UDK.exe FirewallRules: [{755DD51F-204B-4899-BCF3-3C01F74B9939}] => (Allow) E:\UDK\Custom\Binaries\Win64\UDK.exe FirewallRules: [{5C523C81-D5CB-407F-A411-ED6F68929341}] => (Allow) C:\Program Files (x86)\Nero\KM\KwikMedia.exe FirewallRules: [{16CF7A2D-6A52-401C-BA91-2B61BF5DB1FD}] => (Allow) C:\Program Files (x86)\Nero\KM\KwikMedia.exe FirewallRules: [{5E951ACA-7DE2-4CCA-83FB-8BC5A7707B09}] => (Allow) C:\Program Files (x86)\Nero\Nero 12\Nero BackItUp\BackItUp.exe FirewallRules: [{62688DD9-9CEA-4E2E-8738-540D109D9241}] => (Allow) C:\Program Files (x86)\Nero\Nero 12\Nero BackItUp\BackItUp.exe FirewallRules: [{607113D7-E7D6-43D1-86EA-6E3760817230}] => (Allow) C:\Program Files (x86)\Nero\Nero Blu-ray Player\Blu-rayPlayer.exe FirewallRules: [{989BE24A-EB9E-4503-9F52-EE157D2575C7}] => (Allow) C:\Program Files (x86)\Nero\Nero Blu-ray Player\Blu-rayPlayer.exe FirewallRules: [{78559CA3-B3BB-44AD-A1E5-0C15BEC58821}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\sid meier's civilization v\Launcher.exe FirewallRules: [{27B6FAD4-6251-4073-94AD-B4B27A9F3AC9}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\sid meier's civilization v\Launcher.exe FirewallRules: [{BBDB8F04-D7CF-4676-8D9A-F715124B5E3D}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe FirewallRules: [{4DB56BC5-2901-477B-9BD0-6CA368B388C9}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe FirewallRules: [{3BA3EA05-5F5D-4483-8F78-55FB3DF6F187}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{108710A1-C221-47CC-8992-E2B593E0AD5E}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{005336F8-C82F-4905-A25B-13CB7E51FA87}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{90FB2942-20CB-4868-BE6F-D89BD568B8F5}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{D569F963-84E0-4D8A-9020-E8040F7B4596}] => (Allow) C:\Program Files\Ubisoft\WATCH_DOGS\bin\Watch_Dogs.exe FirewallRules: [{5EBDDD44-4D7A-4654-B02D-9644C7FE24FA}] => (Allow) C:\Program Files\Ubisoft\WATCH_DOGS\bin\Watch_Dogs.exe FirewallRules: [{C3EE95F6-09D6-4E63-99CF-B0AA7CADDBB1}] => (Allow) E:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{463E41DE-8437-4357-95D0-6A8F6D2D66BE}] => (Allow) E:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{D44EFBB7-4D26-44DF-8B1C-AF1F5409F721}] => (Allow) C:\Program Files\HP\HP Officejet Pro 8610\bin\FaxApplications.exe FirewallRules: [{6B271321-2AE8-4F9F-AA54-15FA11E88C40}] => (Allow) C:\Program Files\HP\HP Officejet Pro 8610\bin\DigitalWizards.exe FirewallRules: [{15417957-B456-4AE8-9360-E0F66F0F2349}] => (Allow) C:\Program Files\HP\HP Officejet Pro 8610\bin\SendAFax.exe FirewallRules: [{0DE9F518-F563-468B-99ED-DC1C6E27E482}] => (Allow) C:\Program Files\HP\HP Officejet Pro 8610\Bin\DeviceSetup.exe FirewallRules: [{4224E777-68C9-4429-99AC-089B701DBF46}] => (Allow) LPort=5357 FirewallRules: [{60FB2192-6D63-4AD6-99E5-ED21F7A757C4}] => (Allow) C:\Program Files\HP\HP Officejet Pro 8610\Bin\HPNetworkCommunicatorCom.exe FirewallRules: [{288B1071-9836-426A-B462-3E71B0FA67B4}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{DB189879-DC4D-4516-BB12-A9E0DFCF3E00}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{6B2659D4-6264-4DCC-91E6-E13B56B6E38E}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\portal 2\portal2.exe FirewallRules: [{F794DDBE-F5B9-4886-8DA0-B6C13070F363}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\portal 2\portal2.exe FirewallRules: [{80AFA89A-784F-4C73-A85A-8B48AABAB27F}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\Portal Stories Mel\portal2.exe FirewallRules: [{1628511B-70C7-48F6-A640-9A8943B96ABA}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\Portal Stories Mel\portal2.exe FirewallRules: [{CAB8CFD0-33EB-4CCF-A673-25C06C0CECCA}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{5C25878D-2783-45F5-99C2-B6FA00634942}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{BE698519-89C1-46C1-9531-F7574E9517C8}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe FirewallRules: [{4B7E289F-C98F-41B5-A89B-65099155511D}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{00872599-4BD0-4EF6-9178-9552FA3EC354}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{F656D896-C731-4AEF-8952-0BCF84979214}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\Grand Theft Auto V\GTAVLauncher.exe FirewallRules: [{C432A565-E2D4-4F9C-86E4-E7C27AE8E8F0}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\Grand Theft Auto V\GTAVLauncher.exe FirewallRules: [{1E5A924C-2753-457C-BEA0-5E8DBD9BF25B}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\Grand Theft Auto V\GTA5.exe FirewallRules: [{93123B24-E44B-4B7F-A181-B9EA4E52BF98}] => (Allow) E:\Program Files (x86)\Steam\steamapps\common\Grand Theft Auto V\GTA5.exe FirewallRules: [{BA98CF37-EEF1-4409-B682-6D2287E1F36B}] => (Allow) I:\SteamLibrary\steamapps\common\Galactic Civilizations III\GalCiv3.exe FirewallRules: [{76C196A2-486F-4976-AE5F-411C1D8EC3AE}] => (Allow) I:\SteamLibrary\steamapps\common\Galactic Civilizations III\GalCiv3.exe FirewallRules: [{0AE0187A-FF91-4310-BB7D-93FA6438233B}] => (Allow) I:\SteamLibrary\steamapps\common\Sniper Elite 3\Launcher\Sniper3Launcher.exe FirewallRules: [{DB4094CB-256D-40C2-8B0F-801C851690C1}] => (Allow) I:\SteamLibrary\steamapps\common\Sniper Elite 3\Launcher\Sniper3Launcher.exe FirewallRules: [{FBFA6004-3CE8-4917-B658-56873D1B8DE7}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{96FD49FC-00E4-4C55-A3D9-40A4D9795DCA}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{C2DD6561-B9A0-4DAF-B262-8954ABA11A65}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{E8B7D2DB-7DA1-4FBA-BB6E-1ED6AD78C477}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{DC477C8B-FE58-445F-80F5-F8DFFE1C814A}] => (Allow) I:\SteamLibrary\steamapps\common\Silent Hunters Wolves of the Pacific\sh4.exe FirewallRules: [{88C69BD0-DFCF-4953-99FB-F15DEDF69E34}] => (Allow) I:\SteamLibrary\steamapps\common\Silent Hunters Wolves of the Pacific\sh4.exe FirewallRules: [{B1864A23-F115-4441-8E83-E8FA230FB98E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{07673D57-6B5B-4D70-BDFC-34829E387D71}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{7D555FE8-4F4C-4B3C-986B-C30C85B100C3}] => (Allow) I:\Program Files (x86)\Ubisoft\Splinter Cell Blacklist\src\SYSTEM\Blacklist_game.exe FirewallRules: [{B624FF29-FBE0-46C5-AADE-428F2E5640FE}] => (Allow) I:\Program Files (x86)\Ubisoft\Splinter Cell Blacklist\src\SYSTEM\Blacklist_game.exe FirewallRules: [{BC2DAD60-DCDC-4551-B3BA-5BBF96B68C86}] => (Allow) I:\Program Files (x86)\Ubisoft\Splinter Cell Blacklist\src\SYSTEM\Blacklist_DX11_game.exe FirewallRules: [{3E8498B2-D253-47F8-9D79-09243117590C}] => (Allow) I:\Program Files (x86)\Ubisoft\Splinter Cell Blacklist\src\SYSTEM\Blacklist_DX11_game.exe FirewallRules: [{2A74FF34-F755-4662-8C0B-2B665FD7B82D}] => (Allow) I:\Program Files (x86)\Ubisoft\Assassin's Creed Syndicate\ACS.exe FirewallRules: [{3575EA43-4275-45B7-9D19-8607793C5CCD}] => (Allow) I:\SteamLibrary\steamapps\common\Take On Mars\TKOM.exe FirewallRules: [{7F15CA85-8FB0-418F-9C26-124C98973205}] => (Allow) I:\SteamLibrary\steamapps\common\Take On Mars\TKOM.exe FirewallRules: [{B7B94689-4E7B-4C38-B040-3C8CE1048A58}] => (Allow) I:\SteamLibrary\steamapps\common\Take On Mars\TKOM_dev.exe FirewallRules: [{F42289A8-CF86-4363-97F5-969E96773C43}] => (Allow) I:\SteamLibrary\steamapps\common\Take On Mars\TKOM_dev.exe FirewallRules: [{1EB67790-3374-4583-9B5D-CA7CCB3A2F07}] => (Allow) I:\SteamLibrary\steamapps\common\Take On Mars\TKOM_loader.exe FirewallRules: [{B5206614-5817-48C9-A33F-93D907A496D7}] => (Allow) I:\SteamLibrary\steamapps\common\Take On Mars\TKOM_loader.exe FirewallRules: [{CB6BE8DD-2C37-4E3A-A46B-171593195CF4}] => (Allow) C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe FirewallRules: [{772012CC-8C85-4818-904D-4547AB9E16EE}] => (Allow) C:\Program Files (x86)\Plex\Plex Media Server\PlexScriptHost.exe FirewallRules: [{9D5FAD24-E2F5-4997-8CA6-5D56B00C044F}] => (Allow) C:\Program Files (x86)\Plex\Plex Media Server\PlexDlnaServer.exe FirewallRules: [{6D56688F-21BA-4E56-81CA-E57A002C1CAC}] => (Allow) C:\Program Files\iTunes\iTunes.exe FirewallRules: [{E787C6D6-0455-46A9-84B7-91965D157A0D}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{3137F120-7C3B-4F47-A401-697739B06C27}] => (Allow) I:\SteamLibrary\steamapps\common\Kerbal Space Program\KSP.exe FirewallRules: [{B5BDC957-885E-4023-8DC9-EBF847F3A43B}] => (Allow) I:\SteamLibrary\steamapps\common\Kerbal Space Program\KSP.exe ==================== Restore Points ========================= 15-12-2015 21:32:30 Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 15-12-2015 21:34:36 Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 18-12-2015 03:00:15 Windows Update 22-12-2015 11:50:30 muvee on roll 22-12-2015 11:58:15 muvee on roll 26-12-2015 14:05:52 Installed DirectX 26-12-2015 14:09:12 Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 01-01-2016 11:17:27 McAfee Vulnerability Scanner 01-01-2016 15:04:30 Plex Media Server 01-01-2016 15:08:53 Plex Media Server 09-01-2016 00:00:07 Scheduled Checkpoint 11-01-2016 15:46:41 JRT Pre-Junkware Removal 13-01-2016 10:45:48 JRT Pre-Junkware Removal 14-01-2016 03:02:14 Windows Update 15-01-2016 06:54:22 McAfee Vulnerability Scanner 16-01-2016 14:36:50 JRT Pre-Junkware Removal 17-01-2016 09:12:32 Removed PlayOn ==================== Faulty Device Manager Devices ============= Name: NVIDIA nForce 10/100/1000 Mbps Ethernet Description: NVIDIA nForce Networking Controller Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: NVIDIA Service: NVNET Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: ASInsHelp Description: ASInsHelp Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1} Manufacturer: Service: ASInsHelp Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. Name: Teredo Tunneling Pseudo-Interface Description: Microsoft Teredo Tunneling Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (01/15/2016 10:25:14 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: ACS.exe, version: 0.0.0.0, time stamp: 0x56715761 Faulting module name: ACS.exe, version: 0.0.0.0, time stamp: 0x56715761 Exception code: 0xc0000005 Fault offset: 0x000000000000b927 Faulting process id: 0x2d00 Faulting application start time: 0xACS.exe0 Faulting application path: ACS.exe1 Faulting module path: ACS.exe2 Report Id: ACS.exe3 Error: (01/15/2016 06:57:07 AM) (Source: MsiInstaller) (EventID: 1023) (User: Rosebud) Description: Product: Adobe Reader XI (11.0.10) - Update 'Adobe Reader XI (11.0.10)' could not be installed. Error code 1603. Additional information is available in the log file C:\Users\Michel\AppData\Local\Temp\MSI7843a.LOG. Error: (01/15/2016 06:57:07 AM) (Source: MsiInstaller) (EventID: 1013) (User: Rosebud) Description: Product: Adobe Reader XI (11.0.10) -- Setup has detected that you already have a more functional product installed. Setup will now terminate. Error: (01/13/2016 11:12:36 AM) (Source: ESENT) (EventID: 455) (User: ) Description: taskhost (2064) WebCacheLocal: Error -1811 occurred while opening logfile C:\Users\Michel\AppData\Local\Microsoft\Windows\WebCache\V0100039.log. Error: (01/11/2016 02:31:07 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: ACS.exe, version: 0.0.0.0, time stamp: 0x56715761 Faulting module name: ACS.exe, version: 0.0.0.0, time stamp: 0x56715761 Exception code: 0xc0000005 Fault offset: 0x000000000000b927 Faulting process id: 0x25d0 Faulting application start time: 0xACS.exe0 Faulting application path: ACS.exe1 Faulting module path: ACS.exe2 Report Id: ACS.exe3 Error: (01/11/2016 01:06:16 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: ACS.exe, version: 0.0.0.0, time stamp: 0x56715761 Faulting module name: ACS.exe, version: 0.0.0.0, time stamp: 0x56715761 Exception code: 0xc0000005 Fault offset: 0x0000000001d64a70 Faulting process id: 0x2798 Faulting application start time: 0xACS.exe0 Faulting application path: ACS.exe1 Faulting module path: ACS.exe2 Report Id: ACS.exe3 Error: (01/11/2016 01:00:59 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program ACS.exe version 0.0.0.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: 2874 Start Time: 01d14c9979898d20 Termination Time: 528 Application Path: I:\Program Files (x86)\Ubisoft\Assassin's Creed Syndicate\ACS.exe Report Id: Error: (01/11/2016 10:55:24 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: ACS.exe, version: 0.0.0.0, time stamp: 0x56715761 Faulting module name: ACS.exe, version: 0.0.0.0, time stamp: 0x56715761 Exception code: 0xc0000005 Fault offset: 0x000000000000b927 Faulting process id: 0xdf4 Faulting application start time: 0xACS.exe0 Faulting application path: ACS.exe1 Faulting module path: ACS.exe2 Report Id: ACS.exe3 Error: (01/09/2016 10:57:04 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: ACS.exe, version: 0.0.0.0, time stamp: 0x56715761 Faulting module name: ACS.exe, version: 0.0.0.0, time stamp: 0x56715761 Exception code: 0xc0000005 Fault offset: 0x000000000000b927 Faulting process id: 0x1dc0 Faulting application start time: 0xACS.exe0 Faulting application path: ACS.exe1 Faulting module path: ACS.exe2 Report Id: ACS.exe3 Error: (01/09/2016 10:48:34 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: ACS.exe, version: 0.0.0.0, time stamp: 0x56715761 Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000 Exception code: 0xc0000005 Fault offset: 0x0000007463656a62 Faulting process id: 0x2b4c Faulting application start time: 0xACS.exe0 Faulting application path: ACS.exe1 Faulting module path: ACS.exe2 Report Id: ACS.exe3 System errors: ============= Error: (01/16/2016 02:37:21 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The NVIDIA Display Driver Service service terminated unexpectedly. It has done this 1 time(s). Error: (01/16/2016 02:35:11 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The PinnacleUpdate Service service terminated unexpectedly. It has done this 1 time(s). Error: (01/16/2016 02:33:22 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The ASInsHelp service failed to start due to the following error: %%2 Error: (01/16/2016 02:31:10 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The Windows Modules Installer service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service. Error: (01/16/2016 02:31:10 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The Nero Update service terminated unexpectedly. It has done this 1 time(s). Error: (01/16/2016 02:31:10 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The Windows Presentation Foundation Font Cache 3.0.0.0 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. Error: (01/16/2016 02:31:09 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The Windows Media Player Network Sharing Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service. Error: (01/16/2016 02:31:09 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The iPod Service service terminated unexpectedly. It has done this 1 time(s). Error: (01/16/2016 02:31:09 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The Windows Search service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service. Error: (01/16/2016 02:31:08 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The Sage 50 Database Connection Manager service terminated unexpectedly. It has done this 1 time(s). CodeIntegrity: =================================== Date: 2015-12-12 12:40:32.873 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume1\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2015-12-12 12:40:32.763 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume1\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2015-08-21 14:45:07.421 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system. Date: 2015-08-21 14:43:38.320 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system. Date: 2015-08-21 14:43:12.213 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system. Date: 2015-08-21 14:43:12.118 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system. Date: 2015-08-21 14:42:00.437 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system. Date: 2015-08-21 14:42:00.281 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system. Date: 2015-08-21 14:41:36.334 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system. Date: 2015-08-21 14:41:36.242 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system. ==================== Memory info =========================== Processor: Intel(R) Core(TM)2 Quad CPU Q9650 @ 3.00GHz Percentage of memory in use: 38% Total physical RAM: 8190.55 MB Available physical RAM: 5052.51 MB Total Virtual: 16379.32 MB Available Virtual: 12880.11 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:279.46 GB) (Free:74.38 GB) NTFS ==>[drive with boot components (obtained from BCD)] Drive e: () (Fixed) (Total:596.17 GB) (Free:122.51 GB) NTFS Drive g: (WD SmartWare) (CDROM) (Total:0.44 GB) (Free:0 GB) UDF Drive h: (My Book) (Fixed) (Total:930.86 GB) (Free:452.4 GB) NTFS Drive i: (New Volume) (Fixed) (Total:2794.39 GB) (Free:2537.53 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 279.5 GB) (Disk ID: 71FB6BD8) Partition 1: (Active) - (Size=279.5 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or Vista) (Size: 596.2 GB) (Disk ID: 73EA7A88) Partition 1: (Not Active) - (Size=596.2 GB) - (Type=07 NTFS) ======================================================== Disk: 2 (MBR Code: Windows 7 or 8) (Size: 2794.5 GB) (Disk ID: 00000000) Partition: GPT. ======================================================== Disk: 3 (Size: 930.9 GB) (Disk ID: D7D8348F) Partition 1: (Not Active) - (Size=930.9 GB) - (Type=07 NTFS) ==================== End of Addition.txt ============================