Additional scan result of Farbar Recovery Scan Tool (x64) Version:07-05-2016 Ran by [removed] (2016-05-07 10:36:30) Running from C:\Users\[removed]\Desktop Windows 7 Home Premium Service Pack 1 (X64) (2012-09-25 18:19:21) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-3640800009-1063320712-4824981-500 - Administrator - Disabled) Guest (S-1-5-21-3640800009-1063320712-4824981-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-3640800009-1063320712-4824981-1003 - Limited - Enabled) mark (S-1-5-21-3640800009-1063320712-4824981-1002 - Administrator - Enabled) => C:\Users\mark ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Flash Player 21 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 21.0.0.213 - Adobe Systems Incorporated) Adobe Flash Player 21 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 21.0.0.213 - Adobe Systems Incorporated) Adobe Reader XI (11.0.15) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.15 - Adobe Systems Incorporated) Age of Empires II: HD Edition (HKLM-x32\...\Steam App 221380) (Version: - Hidden Path Entertainment, Ensemble Studios) Apple Application Support (32-bit) (HKLM-x32\...\{FE5C2FAA-118D-4509-B51D-3F71CC9E1B3E}) (Version: 4.3 - Apple Inc.) Apple Application Support (64-bit) (HKLM\...\{2937FD88-C9D6-4B82-B539-37CD0A572F42}) (Version: 4.3 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{2E4AF2A6-50EA-4260-9BA4-5E582D11879A}) (Version: 9.3.0.15 - Apple Inc.) Apple Software Update (HKLM-x32\...\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.) ARK: Survival Evolved (HKLM\...\Steam App 346110) (Version: - Studio Wildcard) Arma 3 (HKLM-x32\...\Steam App 107410) (Version: - Bohemia Interactive) Assassins Creed IV Black Flag (HKLM-x32\...\QXNzYXNzaW5zQ3JlZWRJVkJsYWNrRmxhZw==_is1) (Version: 1 - ) Assassin's Creed Syndicate (HKLM-x32\...\Uplay Install 1875) (Version: 1.40 - Ubisoft) Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 2.0.4.4 - Atheros Communications Inc.) Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) BitTorrent (HKLM-x32\...\BitTorrent) (Version: 7.8.0.29626 - BitTorrent Inc.) BitTorrent (HKU\S-1-5-21-3640800009-1063320712-4824981-1002\...\BitTorrent) (Version: 7.9.3.40299 - BitTorrent Inc.) Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.) Borderlands (HKLM-x32\...\Steam App 8980) (Version: - Gearbox Software) Borderlands 2 (HKLM-x32\...\Steam App 49520) (Version: - Gearbox Software) Borderlands: The Pre-Sequel (HKLM-x32\...\Steam App 261640) (Version: - 2K Australia) Callouts V (HKLM-x32\...\CalloutsV) (Version: - Official LukeD) CCleaner (HKLM\...\CCleaner) (Version: 5.15 - Piriform) CPUID CPU-Z 1.64.0 (HKLM\...\CPUID CPU-Z_is1) (Version: - ) CPUID HWMonitor 1.20 (HKLM\...\CPUID HWMonitor_is1) (Version: - ) DB Browser for SQLite (HKLM-x32\...\SqliteBrowser3) (Version: 3.7.0 - oldsch00l) Dual-Core Optimizer (HKLM-x32\...\{9FD6F1A8-5550-46AF-8509-271DF0E768B5}) (Version: 1.1.4.0169 - AMD) ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - ) Far Cry Primal (HKLM-x32\...\Uplay Install 2010) (Version: - Ubisoft) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 50.0.2661.94 - Google Inc.) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.29.5 - Google Inc.) Hidden Grand Theft Auto V (HKLM-x32\...\Steam App 271590) (Version: - Rockstar North) Hearthstone (HKLM-x32\...\Hearthstone) (Version: - Blizzard Entertainment) iFunbox (v3.0.3109.1352) (HKLM-x32\...\iFunbox_is1) (Version: v3.0.3109.1352 - iFunbox DevTeam) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.0.0.1351 - Intel Corporation) Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.3.214 - Intel Corporation) Intel® Trusted Connect Service Client (HKLM\...\{6199B534-A1B6-46ED-873B-97B0ECF8F81E}) (Version: 1.23.216.0 - Intel Corporation) iPhone Data Recovery (HKLM-x32\...\iPhone Data Recovery) (Version: - Tenorshare, Inc.) iTunes (HKLM\...\{A31C5565-90D9-4615-AE13-94D86C3836C7}) (Version: 12.3.3.17 - Apple Inc.) Java 8 Update 91 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218091F0}) (Version: 8.0.910.14 - Oracle Corporation) Magic ISO Maker v5.5 (build 0281) (HKLM-x32\...\Magic ISO Maker v5.5 (build 0281)) (Version: - ) Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes) marvell 91xx driver (HKLM-x32\...\MagniDriver) (Version: 1.2.0.1010 - Marvell) Microsoft .NET Framework 4.5.1 RC (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50861 - Microsoft Corporation) Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation) Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}) (Version: 3.5.92.0 - Microsoft Corporation) Microsoft Games for Windows Marketplace (HKLM-x32\...\{4CB0307C-565E-4441-86BE-0DF2E4FB828C}) (Version: 3.5.50.0 - Microsoft Corporation) Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUS) (Version: 14.0.4734.1000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23026 (HKLM-x32\...\{e46eca4f-393b-40df-9f49-076faf788d83}) (Version: 14.0.23026.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23026 (HKLM-x32\...\{74d0e5db-b326-4dae-a6b2-445b9de1836e}) (Version: 14.0.23026.0 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.) Minecraft (HKLM-x32\...\{1C16BCA3-EBC1-49F6-8623-8FBFB9CCC872}) (Version: 1.0.3.0 - Mojang) MSI Afterburner 3.0.0 (HKLM-x32\...\Afterburner) (Version: 3.0.0 - MSI Co., LTD) MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MSXML 4.0 SP2 Parser and SDK (HKLM-x32\...\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation) Nero Video 12 (HKLM-x32\...\{D7D28084-C2F5-48BA-916D-52A14E71D9F5}) (Version: 12.5.01200 - Nero AG) NVIDIA 3D Vision Controller Driver 364.44 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 364.44 - NVIDIA Corporation) NVIDIA 3D Vision Driver 364.51 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 364.51 - NVIDIA Corporation) NVIDIA GeForce Experience 2.10.2.40 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.10.2.40 - NVIDIA Corporation) NVIDIA Graphics Driver 364.51 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 364.51 - NVIDIA Corporation) NVIDIA HD Audio Driver 1.3.34.4 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.4 - NVIDIA Corporation) NVIDIA PhysX System Software 9.15.0428 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation) ON_OFF Charge B11.1102.1 (HKLM-x32\...\{3DECD372-76A1-4483-BF10-B547790A3261}) (Version: 1.00.0001 - GIGABYTE) Open Broadcaster Software (HKLM-x32\...\Open Broadcaster Software) (Version: - ) OpenAL (HKLM-x32\...\OpenAL) (Version: - ) Origin (HKLM-x32\...\Origin) (Version: 9.5.3.636 - Electronic Arts, Inc.) Platform (x32 Version: 1.38 - VIA Technologies, Inc.) Hidden PremiumSoft Navicat Premium 11.2 (HKLM\...\PremiumSoft Navicat Premium_is1) (Version: 11.2.5 - PremiumSoft CyberTech Ltd.) PremiumSoft Navicat Premium 9.1 (HKLM-x32\...\PremiumSoft Navicat Premium_is1) (Version: - PremiumSoft CyberTech Ltd.) Prerequisite installer (x32 Version: 12.0.0003 - Nero AG) Hidden Prison Architect (HKLM-x32\...\Steam App 233450) (Version: - Introversion Software) RaidCall (HKLM-x32\...\RaidCall) (Version: 7.0.2-1.0.1512.31 - raidcall.com) Razer Chroma SDK Core Components (HKLM-x32\...\Razer Chroma SDK) (Version: 1.6.1 - Razer Inc.) Razer Core (HKLM-x32\...\Razer Core) (Version: 1.0.1.66 - Razer Inc) Razer Synapse (HKLM-x32\...\{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}) (Version: 1.20.15.29092 - Razer Inc.) RivaTuner Statistics Server 6.1.1 (HKLM-x32\...\RTSS) (Version: 6.1.1 - Unwinder) Rocket League (HKLM-x32\...\Steam App 252950) (Version: - Psyonix) Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.1.6.9 - Rockstar Games) SHIELD Streaming (Version: 5.1.0270 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: 2.10.2.40 - NVIDIA Corporation) Hidden Sid Meier's Civilization V (HKLM-x32\...\Steam App 8930) (Version: - 2K Games, Inc.) Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1) (Version: 1.6.2 - Safer Networking Limited) Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.15 - TeamSpeak Systems GmbH) Tom Clancy's The Division (HKLM\...\Steam App 365590) (Version: - Massive Entertainment) TreeSize Free V3.2 (HKLM-x32\...\TreeSize Free_is1) (Version: 3.2 - JAM Software) Tropico 5 (HKLM-x32\...\Tropico 5_is1) (Version: - ) Uplay (HKLM-x32\...\Uplay) (Version: 4.3 - Ubisoft) VIA Platform Device Manager (HKLM-x32\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.38 - VIA Technologies, Inc.) VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN) WhoCrashed 3.06 (HKLM\...\WhoCrashed_is1) (Version: - Resplendence Software Projects Sp.) Windows Live ID Sign-in Assistant (HKLM\...\{9B48B0AC-C813-4174-9042-476A887592C7}) (Version: 6.500.3165.0 - Microsoft Corporation) WinRAR 5.30 beta 5 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 5.30.5 - win.rar GmbH) World of Warcraft (HKLM-x32\...\World of Warcraft) (Version: - Blizzard Entertainment) XCOM: Enemy Unknown (HKLM-x32\...\Steam App 200510) (Version: - Firaxis Games) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {125D2D2B-73A9-41F0-B947-01507AB0646F} - System32\Tasks\{02B90DA8-50E1-4888-9C8C-9562E492A0E3} => pcalua.exe -a "C:\Users\mark\AppData\Roaming\Reincubate\iPhone Backup Extractor\iPhoneBackupExtractor.Uninstall.exe" -c "iPhone Backup Extractor" {AA0ADAF3-293D-4FE6-826A-819ACD4584E5} Task: {48C59AF7-94A3-4F58-A145-31947724DE27} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.) Task: {52C4C97E-93C5-4349-9950-95D3992000C1} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-04-08] (Adobe Systems Incorporated) Task: {6635FAB0-9ED1-4DFE-8B01-53CC958436E9} - System32\Tasks\CCleanerSkipUAC => E:\CCleaner\CCleaner.exe [2016-02-12] (Piriform Ltd) Task: {9D0A22ED-0AB2-40B4-9361-9A2341B92437} - System32\Tasks\{310056FC-93FD-425E-BA83-1078F01AAB91} => pcalua.exe -a C:\Users\mark\Desktop\svencoop47.exe -d C:\Users\mark\Desktop Task: {ABEA203E-5B3D-4AD6-BB80-937224F4F37D} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-12-14] (Adobe Systems Incorporated) Task: {DD3DD74B-978E-4FE8-B88E-6D715AF038AE} - System32\Tasks\Games\UpdateCheck_S-1-5-21-3640800009-1063320712-4824981-1002 Task: {DD743F3D-40F3-4466-A842-ED110764B03D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.) Task: {E1735C00-56DE-472C-ABF0-7A8A690C4CAB} - System32\Tasks\{851480D3-A138-4588-8C84-43AF853A4A51} => pcalua.exe -a E:\Steam\steam.exe -c steam://uninstall/220620 Task: {F9B0220C-971D-4E57-90AF-A74417DBDE44} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== 2016-03-22 12:57 - 2016-03-08 07:27 - 00134712 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2014-05-16 17:39 - 2014-05-16 17:39 - 00399360 _____ () E:\RivaTuner Statistics Server\RTSSHooks64.dll 2010-01-09 21:17 - 2010-01-09 21:17 - 04254560 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF 2010-01-21 02:40 - 2010-01-21 02:40 - 08794464 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll 2016-03-18 22:56 - 2016-03-18 22:56 - 00092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2016-03-18 22:56 - 2016-03-18 22:56 - 01329936 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2015-11-16 16:16 - 2015-11-05 19:19 - 00457808 _____ () C:\Program Files (x86)\Common Files\aunhelper\aunhelper.exe 2015-11-16 16:16 - 2015-11-05 19:19 - 00064592 _____ () C:\Program Files (x86)\Common Files\aunhelper\worker.exe 2016-03-22 12:57 - 2016-03-08 11:07 - 01416064 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\MessageBus.dll 2016-03-22 12:57 - 2016-03-08 11:07 - 03613056 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\Poco.dll 2016-03-22 12:57 - 2016-03-08 11:07 - 00299392 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamBase.dll 2013-07-05 02:06 - 2015-03-22 23:13 - 00076152 _____ () C:\Windows\SysWOW64\PnkBstrA.exe 2015-11-05 01:11 - 2015-11-05 01:12 - 00188072 _____ () C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe 2014-02-28 10:14 - 2016-04-27 14:39 - 00174872 _____ () E:\TS3\quazip.dll 2014-06-20 08:48 - 2016-04-27 14:39 - 00103192 _____ () E:\TS3\soundbackends\directsound_win64.dll 2014-06-20 08:49 - 2016-04-27 14:39 - 00107800 _____ () E:\TS3\soundbackends\windowsaudiosession_win64.dll 2014-06-26 07:38 - 2016-04-27 14:39 - 00312088 _____ () E:\TS3\plugins\clientquery_plugin.dll 2014-07-14 09:22 - 2016-04-27 14:39 - 00485656 _____ () E:\TS3\plugins\teamspeak_control_plugin.dll 2014-05-19 11:46 - 2014-05-19 11:46 - 00465064 _____ () E:\MSI Afterburner\MSIAfterburner.exe 2014-05-16 17:39 - 2014-05-16 17:39 - 00188928 _____ () E:\RivaTuner Statistics Server\RTSS.exe 2014-05-16 17:38 - 2014-05-16 17:38 - 00026112 _____ () E:\RivaTuner Statistics Server\EncoderServer.exe 2014-05-16 17:39 - 2014-05-16 17:39 - 00088576 _____ () E:\RivaTuner Statistics Server\RTSSHooksLoader64.exe 2015-11-16 16:16 - 2015-10-30 11:22 - 00229376 _____ () C:\Program Files (x86)\Common Files\aunhelper\logger.job 2015-11-16 16:16 - 2015-10-30 11:22 - 00241664 _____ () C:\Program Files (x86)\Common Files\aunhelper\update.job 2014-05-16 17:38 - 2014-05-16 17:38 - 00354816 _____ () E:\RivaTuner Statistics Server\RTSSHooks.dll 2016-03-22 12:57 - 2016-03-08 11:07 - 00020352 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll 2013-07-11 22:47 - 2016-04-29 21:10 - 00785920 _____ () E:\Steam\SDL2.dll 2015-01-22 14:15 - 2015-07-03 17:12 - 04962816 _____ () E:\Steam\v8.dll 2015-01-22 14:15 - 2015-07-03 17:12 - 01556992 _____ () E:\Steam\icui18n.dll 2015-01-22 14:15 - 2015-07-03 17:12 - 01187840 _____ () E:\Steam\icuuc.dll 2014-05-22 14:32 - 2016-04-30 01:10 - 02549840 _____ () E:\Steam\video.dll 2014-08-29 15:46 - 2016-02-09 00:14 - 02549760 _____ () E:\Steam\libavcodec-56.dll 2014-08-29 15:46 - 2016-02-09 00:14 - 00442880 _____ () E:\Steam\libavutil-54.dll 2014-08-29 15:46 - 2016-02-09 00:14 - 00491008 _____ () E:\Steam\libavformat-56.dll 2014-08-29 15:46 - 2016-02-09 00:14 - 00332800 _____ () E:\Steam\libavresample-2.dll 2014-08-29 15:46 - 2016-02-09 00:14 - 00485888 _____ () E:\Steam\libswscale-3.dll 2013-07-11 22:47 - 2016-04-30 01:10 - 00829008 _____ () E:\Steam\bin\chromehtml.DLL 2016-03-09 11:07 - 2016-02-17 23:25 - 00281088 _____ () E:\Steam\openvr_api.dll 2016-04-26 11:05 - 2016-04-26 11:05 - 00143824 _____ () C:\ProgramData\Razer\Synapse\CrashReporter\CrashRpt1402.dll 2015-07-25 23:27 - 2015-08-27 22:30 - 40622592 _____ () C:\Users\mark\AppData\Local\razer\InGameEngine\cache\RzSynapse\cef\libcef.dll 2013-07-11 22:47 - 2016-04-28 02:00 - 49825056 _____ () E:\Steam\bin\libcef.dll 2015-07-25 23:27 - 2015-08-27 22:30 - 00911360 _____ () C:\Users\mark\AppData\Local\razer\InGameEngine\cache\RzSynapse\cef\libglesv2.dll 2015-07-25 23:27 - 2015-08-27 22:30 - 00134144 _____ () C:\Users\mark\AppData\Local\razer\InGameEngine\cache\RzSynapse\cef\libegl.dll 2014-04-15 14:31 - 2014-04-15 14:31 - 00071680 _____ () E:\MSI Afterburner\RTMUI.dll 2014-04-15 14:31 - 2014-04-15 14:31 - 00056832 _____ () E:\MSI Afterburner\RTFC.dll 2014-04-15 14:31 - 2014-04-15 14:31 - 00216064 _____ () E:\MSI Afterburner\RTCore.dll 2014-04-15 14:31 - 2014-04-15 14:31 - 00127488 _____ () E:\MSI Afterburner\RTUI.dll 2014-04-15 14:31 - 2014-04-15 14:31 - 00638976 _____ () E:\MSI Afterburner\RTHAL.dll 2014-05-16 17:38 - 2014-05-16 17:38 - 00056320 _____ () E:\RivaTuner Statistics Server\RTFC.dll 2014-05-16 17:38 - 2014-05-16 17:38 - 00127488 _____ () E:\RivaTuner Statistics Server\RTUI.dll 2014-05-16 17:39 - 2014-05-16 17:39 - 00071680 _____ () E:\RivaTuner Statistics Server\RTMUI.dll 2015-01-22 14:15 - 2015-09-25 00:56 - 00119208 _____ () E:\Steam\winh264.dll 2012-09-22 00:39 - 2011-12-16 18:39 - 01198872 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll 2010-01-09 21:18 - 2010-01-09 21:18 - 04254560 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF 2010-01-21 02:34 - 2010-01-21 02:34 - 08793952 _____ () C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll 2016-04-28 21:10 - 2016-04-28 00:25 - 01738904 _____ () C:\Program Files (x86)\Google\Chrome\Application\50.0.2661.94\libglesv2.dll 2016-04-28 21:10 - 2016-04-28 00:25 - 00086168 _____ () C:\Program Files (x86)\Google\Chrome\Application\50.0.2661.94\libegl.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PAexec => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PAexec => ""="Service" ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 03:34 - 2013-08-17 00:01 - 00000027 ____N C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-3640800009-1063320712-4824981-1002\Control Panel\Desktop\\Wallpaper -> C:\Users\mark\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.0.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) MSCONFIG\Services: AdobeFlashPlayerUpdateSvc => 3 MSCONFIG\Services: Apple Mobile Device => 2 MSCONFIG\Services: Bonjour Service => 2 MSCONFIG\Services: gupdate => 2 MSCONFIG\Services: gupdatem => 3 MSCONFIG\Services: iPod Service => 3 MSCONFIG\Services: MBAMScheduler => 2 MSCONFIG\Services: MBAMService => 2 MSCONFIG\Services: NAUpdate => 2 MSCONFIG\Services: RzOvlMon => 2 MSCONFIG\Services: vToolbarUpdater15.5.0 => 2 MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^ResultsHubDesktopSearch.lnk => C:\Windows\pss\ResultsHubDesktopSearch.lnk.CommonStartup MSCONFIG\startupreg: AdAwareTray => "F:\ada\Ad-Aware Antivirus\11.10.767.8917\AdAwareTray.exe" MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" MSCONFIG\startupreg: EADM => "E:\Origin\Origin.exe" -AutoStart MSCONFIG\startupreg: iFunBox => C:\Program Files (x86)\i-Funbox DevTeam\iFunBox_x64.exe /tray MSCONFIG\startupreg: irang => "C:\Windows\System32\rundll32.exe" "C:\Users\mark\AppData\Roaming\irang.dll",SimpleParseFile MSCONFIG\startupreg: iTunesHelper => "E:\Itunes\iTunesHelper.exe" MSCONFIG\startupreg: NvBackend => "C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" MSCONFIG\startupreg: ocrdv => rundll32.exe "C:\Users\mark\AppData\Roaming\ocrdv.dll",SetColumns MSCONFIG\startupreg: RaidCall => E:\RaidCall\raidcall.exe MSCONFIG\startupreg: sacpie => "C:\Windows\System32\rundll32.exe" "C:\Users\mark\AppData\Roaming\sacpie.dll",Node_ListTree MSCONFIG\startupreg: ShadowPlay => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [TCP Query User{1F93378D-2666-4A9D-98D6-6DD3E4B7A3E4}E:\bit\bittorrent.exe] => (Allow) E:\bit\bittorrent.exe FirewallRules: [UDP Query User{B78B2613-7C1F-4214-AB3F-0E46CF6CEDD9}E:\bit\bittorrent.exe] => (Allow) E:\bit\bittorrent.exe FirewallRules: [TCP Query User{C5866978-F2B9-4549-A1E6-91B09C502263}E:\steam\steam.exe] => (Allow) E:\steam\steam.exe FirewallRules: [UDP Query User{76169D92-43F1-446F-BCFD-D9C0FDCF643E}E:\steam\steam.exe] => (Allow) E:\steam\steam.exe FirewallRules: [{E9E88D8E-2AC4-460C-9C47-0FE58633313E}] => (Allow) E:\Steam\steamapps\common\Borderlands 2\Binaries\Win32\Launcher.exe FirewallRules: [{25B4FCAD-FB24-4197-9810-807A73A75654}] => (Allow) E:\Steam\steamapps\common\Borderlands 2\Binaries\Win32\Launcher.exe FirewallRules: [TCP Query User{E4507524-134C-412A-A1E4-D460A9D014D4}E:\steam\steamapps\common\borderlands 2\binaries\win32\borderlands2.exe] => (Allow) E:\steam\steamapps\common\borderlands 2\binaries\win32\borderlands2.exe FirewallRules: [UDP Query User{B7C540CB-08A9-4DDE-B4D6-8FDD8F16BA54}E:\steam\steamapps\common\borderlands 2\binaries\win32\borderlands2.exe] => (Allow) E:\steam\steamapps\common\borderlands 2\binaries\win32\borderlands2.exe FirewallRules: [{DCB92140-3E60-481C-B781-B1F913771265}] => (Allow) E:\Steam\steamapps\common\Sid Meier's Civilization V\Launcher.exe FirewallRules: [{03816FAF-2B0F-48F8-84D5-D83A1202F857}] => (Allow) E:\Steam\steamapps\common\Sid Meier's Civilization V\Launcher.exe FirewallRules: [{E546C21A-FAE1-4DC7-A6FD-B8E08B172B45}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2737\Agent.exe FirewallRules: [{CF503FD6-21C9-4C97-B39B-23BB78B185B0}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2737\Agent.exe FirewallRules: [{F5FF35F1-8F57-43E8-B4B4-4922B37598F1}] => (Allow) E:\Battle.net\Battle.net.exe FirewallRules: [{ACE658BC-D095-478D-B810-12E21067B98C}] => (Allow) E:\Battle.net\Battle.net.exe FirewallRules: [{F325AE63-BE07-4D63-A53F-0861D748D00C}] => (Allow) E:\Hearthstone\Hearthstone.exe FirewallRules: [{DFCDBDED-1BBA-4873-AABC-D00456088D6E}] => (Allow) E:\Hearthstone\Hearthstone.exe FirewallRules: [{73032690-DF68-4651-8558-1D0130CB5521}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2753\Agent.exe FirewallRules: [{DBCA2201-8D86-4063-A23B-D68970C8A8A6}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2753\Agent.exe FirewallRules: [{DCF1E09A-C55D-451B-8AE8-C5D4270B9B34}] => (Allow) E:\nero\Nero Blu-ray Player\Blu-rayPlayer.exe FirewallRules: [{78B60B80-4C10-4FCF-B256-A7ABCCACE186}] => (Allow) E:\nero\Nero Blu-ray Player\Blu-rayPlayer.exe FirewallRules: [{C2302F03-042B-4056-A19A-CAFC9416ECA9}] => (Allow) E:\nero\KM\KwikMedia.exe FirewallRules: [{593CCC9E-41D5-4D57-9F28-15D11933DAD3}] => (Allow) E:\nero\KM\KwikMedia.exe FirewallRules: [{6C319226-F51E-4908-9F73-201433E1A085}] => (Allow) E:\Steam\steamapps\common\Arma 3\arma3.exe FirewallRules: [{BA43AF12-C3D6-4E96-80D9-50411EC76EB3}] => (Allow) E:\Steam\steamapps\common\Arma 3\arma3.exe FirewallRules: [{A31E11B1-455C-4FC6-A369-D2096F080DB0}] => (Allow) E:\Steam\steamapps\common\Arma 3\arma3launcher.exe FirewallRules: [{34EB8187-8DB9-4F5D-8A46-DFF9250FDB46}] => (Allow) E:\Steam\steamapps\common\Arma 3\arma3launcher.exe FirewallRules: [{69E7314F-25CD-4058-B67A-E378BD0BB09C}] => (Allow) E:\Steam\steamapps\common\Borderlands\Binaries\Borderlands.exe FirewallRules: [{7C13DAC1-0C65-4AC7-B1A4-EC064D54ABE8}] => (Allow) E:\Steam\steamapps\common\Borderlands\Binaries\Borderlands.exe FirewallRules: [{4446FE25-169B-44FA-BFAD-20260D33FBD7}] => (Allow) E:\Steam\bin\steamwebhelper.exe FirewallRules: [{EFC57FF6-F3E8-41B6-A709-34CF7D98A25A}] => (Allow) E:\Steam\bin\steamwebhelper.exe FirewallRules: [{7F042331-0343-4966-820C-ED3A8F3831AC}] => (Allow) E:\Steam\steamapps\common\Prison Architect\Prison Architect.exe FirewallRules: [{09FC61A9-5930-4245-961E-FC54386FE78E}] => (Allow) E:\Steam\steamapps\common\Prison Architect\Prison Architect.exe FirewallRules: [{A430C24D-FE60-4B1A-8CD3-5A2333E5EDA0}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{7BC93ED0-D5D0-4E5D-A4B7-6A38BAADB106}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{8561A5EA-92D8-4727-AF6F-C0A59825137A}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{8995D690-E797-4878-9CE0-064ED59CBCFC}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [TCP Query User{68C51D8B-57DC-41B9-AF50-265986DB2C31}E:\hearthstone\hearthstone.exe] => (Allow) E:\hearthstone\hearthstone.exe FirewallRules: [UDP Query User{E915D1E0-84C4-407A-B773-43BC818864C6}E:\hearthstone\hearthstone.exe] => (Allow) E:\hearthstone\hearthstone.exe FirewallRules: [TCP Query User{32C8EEA8-8B1B-40FB-960F-5656324FC44D}E:\bit\bittorrent.exe] => (Allow) E:\bit\bittorrent.exe FirewallRules: [UDP Query User{9B2E0477-A884-4AFD-8CF9-B5A0F9BF5BBF}E:\bit\bittorrent.exe] => (Allow) E:\bit\bittorrent.exe FirewallRules: [{99337D6F-622B-4494-8434-3DCD47BA41E7}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{23F5FB2D-97D4-4C1C-9E97-FDA0D7C0B487}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{16D9A462-E5E6-4485-8BE4-3E997363F136}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{5E74D050-B0B5-488E-8C38-78E274BF7AAE}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [TCP Query User{033105C2-377F-410C-BECC-6F779C71B581}E:\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) E:\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe FirewallRules: [UDP Query User{DFAA7B89-FC94-4BAE-984A-8594B804DF1D}E:\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) E:\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe FirewallRules: [{6B861669-025C-4D0D-ADC7-828E8D92DCC1}] => (Allow) E:\Steam\steamapps\common\Grand Theft Auto V\GTAVLauncher.exe FirewallRules: [{DB835744-7DBC-4CA4-A10D-9EC8A0FEB84D}] => (Allow) E:\Steam\steamapps\common\Grand Theft Auto V\GTAVLauncher.exe FirewallRules: [TCP Query User{2E3740B9-40DE-4C59-88E4-EE4DA21365DC}E:\steam\steamapps\common\grand theft auto v\gta5.exe] => (Allow) E:\steam\steamapps\common\grand theft auto v\gta5.exe FirewallRules: [UDP Query User{A63F0106-938C-4160-836C-5016E9805362}E:\steam\steamapps\common\grand theft auto v\gta5.exe] => (Allow) E:\steam\steamapps\common\grand theft auto v\gta5.exe FirewallRules: [{CF124EA5-B6B0-4CD4-A35A-00762B34743B}] => (Allow) E:\Steam\steamapps\common\BorderlandsPreSequel\Binaries\Win32\Launcher.exe FirewallRules: [{6225B47C-E9CB-449F-9166-91EBBC93E67C}] => (Allow) E:\Steam\steamapps\common\BorderlandsPreSequel\Binaries\Win32\Launcher.exe FirewallRules: [{92B32A09-9A52-46B8-8873-8843C4941973}] => (Allow) E:\Steam\steamapps\common\Age2HD\Launcher.exe FirewallRules: [{DE300D4D-4A9A-41FD-A4F4-F49A9F9A71E3}] => (Allow) E:\Steam\steamapps\common\Age2HD\Launcher.exe FirewallRules: [{26FF2C9D-CB30-4935-8F17-1CF4D4239A1D}] => (Allow) E:\Steam\steamapps\common\Half-Life\hl.exe FirewallRules: [{0E42A939-7E73-42C6-ADC6-C629C0126D0C}] => (Allow) E:\Steam\steamapps\common\Half-Life\hl.exe FirewallRules: [{63F87D35-9C77-4B4F-BC76-0BF723D4B6F8}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{9BF12114-44EE-425F-AE70-413A796FB740}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{14499277-D0FD-4BF6-B947-549AC27BEFFE}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{546E0973-121C-424F-A44B-D0BF83D6DD18}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{C308A221-EC37-4090-AC94-9BE69F7834D2}] => (Allow) E:\Assassin's Creed Syndicate\ACS.exe FirewallRules: [{DD18B697-0131-4715-B374-31BDE72FA1A9}] => (Allow) E:\Steam\steamapps\common\XCom-Enemy-Unknown\Binaries\Win32\XComGame.exe FirewallRules: [{22B4782F-3DAA-4857-96E2-F78CCF1399DC}] => (Allow) E:\Steam\steamapps\common\XCom-Enemy-Unknown\Binaries\Win32\XComGame.exe FirewallRules: [TCP Query User{7A8C954D-7361-4BA8-B7F2-0AE9C448B22E}E:\steam\steamapps\common\xcom-enemy-unknown\xew\binaries\win32\xcomew.exe] => (Allow) E:\steam\steamapps\common\xcom-enemy-unknown\xew\binaries\win32\xcomew.exe FirewallRules: [UDP Query User{3E92126E-41A1-4277-BC18-6E64EC2DEAD2}E:\steam\steamapps\common\xcom-enemy-unknown\xew\binaries\win32\xcomew.exe] => (Allow) E:\steam\steamapps\common\xcom-enemy-unknown\xew\binaries\win32\xcomew.exe FirewallRules: [{AFAFF299-1F64-4683-A8CA-90BE54A73E45}] => (Allow) E:\Far Cry Primal\bin\FCPrimal.exe FirewallRules: [{64EBCBEB-E493-4ABE-85F8-4A8EDB542A54}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{E68CB7C7-BF48-4B61-8B72-714A730E5667}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{735CE996-09A8-42AD-8703-7B7175155AEF}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{20543E9D-DFB6-4CD1-9B38-0DBFDA017595}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{D2264650-9E1F-40EC-9B56-8E915D99A7A2}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe FirewallRules: [{ACDA0EFF-40ED-434F-9BA9-F65567C25E9A}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{2CB1C1AD-56B3-4AE8-A0B6-648D0914D23A}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{953E1D43-04A2-4186-8C62-D772CF3834B2}] => (Allow) E:\Steam\steamapps\common\Tom Clancy's The Division\thedivision.exe FirewallRules: [{BD0F4C30-4BD9-4519-B150-0F35CDF3342D}] => (Allow) E:\Steam\steamapps\common\Tom Clancy's The Division\thedivision.exe FirewallRules: [{256E5409-639F-4FCD-A886-CA948BF9B482}] => (Allow) E:\Steam\steamapps\common\Prison Architect\Prison Architect Safe Mode.exe FirewallRules: [{6379DC4C-3E24-4ACC-AA40-3FE4CF209333}] => (Allow) E:\Steam\steamapps\common\Prison Architect\Prison Architect Safe Mode.exe FirewallRules: [{9D88426F-B773-4409-A519-AD827BC2D4D6}] => (Allow) C:\Program Files\iTunes\iTunes.exe FirewallRules: [{C10890CE-FB41-4AD3-B19F-A45E08E977C1}] => (Allow) E:\Steam\steamapps\common\ARK\ShooterGame\Binaries\Win64\ShooterGame_BE.exe FirewallRules: [{B692BC2A-A182-48A3-B7CF-05A9DDC3B9E4}] => (Allow) E:\Steam\steamapps\common\ARK\ShooterGame\Binaries\Win64\ShooterGame_BE.exe FirewallRules: [{110A3E1E-814C-4271-923C-F265A2D0C1CA}] => (Allow) E:\Steam\steamapps\common\ARK\ShooterGame\Binaries\Win64\ShooterGame.exe FirewallRules: [{B16297E3-68CB-41AA-ADC6-135B834497E0}] => (Allow) E:\Steam\steamapps\common\ARK\ShooterGame\Binaries\Win64\ShooterGame.exe FirewallRules: [{4EA17FBE-C593-47BA-8B85-5DAC77854D83}] => (Allow) E:\Steam\steamapps\common\rocketleague\Binaries\Win32\RocketLeague.exe FirewallRules: [{BD779D7B-2290-4C65-9DED-57643A66A7D4}] => (Allow) E:\Steam\steamapps\common\rocketleague\Binaries\Win32\RocketLeague.exe FirewallRules: [{4B6C9EB8-1109-46C3-9C45-60BCD94E7FDD}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Restore Points ========================= 06-05-2016 17:19:25 Windows Update 06-05-2016 17:36:37 Installed Microsoft Fix it 50123 06-05-2016 17:44:51 Installed Microsoft Fix it 50123 07-05-2016 03:05:17 AA11 07-05-2016 07:48:14 AA11 ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (05/07/2016 10:20:39 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/07/2016 10:15:35 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/07/2016 07:51:29 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/07/2016 04:25:47 AM) (Source: SideBySide) (EventID: 80) (User: ) Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest3. A component version required by the application conflicts with another component version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest. Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest. Error: (05/07/2016 03:14:28 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/07/2016 03:11:48 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: ERROR: handle_resolve_request bad interfaceIndex 24 Error: (05/07/2016 03:11:48 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: ERROR: handle_resolve_request bad interfaceIndex 23 Error: (05/07/2016 03:11:48 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: ERROR: handle_resolve_request bad interfaceIndex 22 Error: (05/07/2016 03:11:48 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: ERROR: handle_resolve_request bad interfaceIndex 21 Error: (05/07/2016 03:11:48 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: ERROR: handle_resolve_request bad interfaceIndex 20 System errors: ============= Error: (05/06/2016 05:56:05 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The eapihdrv service failed to start due to the following error: %%1275 Error: (05/06/2016 05:56:05 PM) (Source: Application Popup) (EventID: 1060) (User: ) Description: \??\C:\Users\mark\AppData\Local\Temp\ehdrv.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver. Error: (05/06/2016 05:56:05 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The eapihdrv service failed to start due to the following error: %%1275 Error: (05/06/2016 05:56:05 PM) (Source: Application Popup) (EventID: 1060) (User: ) Description: \??\C:\Users\mark\AppData\Local\Temp\ehdrv.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver. Error: (05/06/2016 05:56:05 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The eapihdrv service failed to start due to the following error: %%1275 Error: (05/06/2016 05:56:05 PM) (Source: Application Popup) (EventID: 1060) (User: ) Description: \??\C:\Users\mark\AppData\Local\Temp\ehdrv.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver. Error: (05/06/2016 05:54:16 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The eapihdrv service failed to start due to the following error: %%1275 Error: (05/06/2016 05:54:16 PM) (Source: Application Popup) (EventID: 1060) (User: ) Description: \??\C:\Users\mark\AppData\Local\Temp\ehdrv.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver. Error: (05/06/2016 05:54:15 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The eapihdrv service failed to start due to the following error: %%1275 Error: (05/06/2016 05:54:15 PM) (Source: Application Popup) (EventID: 1060) (User: ) Description: \??\C:\Users\mark\AppData\Local\Temp\ehdrv.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver. CodeIntegrity: =================================== Date: 2013-08-17 00:00:55.902 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2013-08-17 00:00:55.887 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i5-3570K CPU @ 3.40GHz Percentage of memory in use: 17% Total physical RAM: 16344.07 MB Available physical RAM: 13477.64 MB Total Virtual: 32686.35 MB Available Virtual: 29431.8 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:111.79 GB) (Free:19.92 GB) NTFS Drive e: (New Volume) (Fixed) (Total:931.41 GB) (Free:562.52 GB) NTFS Drive f: (New Volume) (Fixed) (Total:223.57 GB) (Free:223.38 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 828D97A8) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=931.4 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 111.8 GB) (Disk ID: 828D97A0) Partition 1: (Not Active) - (Size=111.8 GB) - (Type=07 NTFS) ======================================================== Disk: 2 (MBR Code: Windows 7 or 8) (Size: 223.6 GB) (Disk ID: 6EF8A041) Partition 1: (Not Active) - (Size=223.6 GB) - (Type=07 NTFS) ==================== End of Addition.txt ============================