Additional scan result of Farbar Recovery Scan Tool (x64) Version:29-05-2016 02 Ran by [removed] (2016-05-31 17:53:31) Running from C:\Users\[removed]\Downloads Windows 10 Home Version 1511 (X64) (2015-12-07 03:21:24) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-347070757-4124586549-2319610994-500 - Administrator - Enabled) => C:\Users\Administrator cloud (S-1-5-21-347070757-4124586549-2319610994-1001 - Administrator - Enabled) => C:\Users\cloud DefaultAccount (S-1-5-21-347070757-4124586549-2319610994-503 - Limited - Disabled) Guest (S-1-5-21-347070757-4124586549-2319610994-501 - Limited - Disabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Spybot - Search and Destroy (Enabled - Out of date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Acrobat Reader DC - Italiano (HKLM-x32\...\{AC76BA86-7AD7-1040-7B44-AC0F074E4100}) (Version: 15.016.20041 - Adobe Systems Incorporated) Amazon Kindle (HKU\S-1-5-21-347070757-4124586549-2319610994-1001\...\Amazon Kindle) (Version: - Amazon) AMD Catalyst Control Center (HKLM-x32\...\WUCCCApp) (Version: 1.00.0000 - AMD) Audacity 2.1.2 (HKLM-x32\...\Audacity®_is1) (Version: 2.1.2 - Audacity Team) CCleaner (HKLM\...\CCleaner) (Version: 5.14 - Piriform) CDisplayEx 1.10.29 (HKLM\...\CDisplayEx_is1) (Version: - Progdigy Software S.A.R.L.) Celtx (2.9.7) (HKLM-x32\...\Celtx (2.9.7)) (Version: 2.9.7 (it) - Greyfirst) CPUID HWMonitor 1.28 (HKLM\...\CPUID HWMonitor_is1) (Version: - ) Dropbox (HKLM-x32\...\Dropbox) (Version: 3.20.1 - Dropbox, Inc.) Dropbox Update Helper (x32 Version: 1.3.27.37 - Dropbox, Inc.) Hidden GIMP 2.8.14 (HKLM\...\GIMP-2_is1) (Version: 2.8.14 - The GIMP Team) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 51.0.2704.63 - Google Inc.) Google Update Helper (x32 Version: 1.3.30.3 - Google Inc.) Hidden HexChat (HKLM\...\HexChat_is1) (Version: 2.10.2 - HexChat) KMSpico v9.3.1 (HKLM\...\KMSpico_is1) (Version: 9.3.1 - ) League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games) League of Legends (x32 Version: 3.0.1 - Riot Games) Hidden McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.11.292.3 - McAfee, Inc.) Memory Cleaner 2.20 (HKLM-x32\...\MemClean) (Version: 2.20 - KoshyJohn.com) Microsoft Office Professional Plus 2013 (HKLM\...\Office15.PROPLUSR) (Version: 15.0.4569.1506 - Microsoft Corporation) Microsoft Office Proofing Tools 2013 - Italiano (HKLM\...\{90150000-001F-0410-1000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools per Office Runtime (x64) - Language Pack - ITA (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - ITA) (Version: 10.0.50903 - Microsoft Corporation) Microsoft XNA Framework Redistributable 4.0 (HKLM-x32\...\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation) Outils de vérification linguistique 2013 de Microsoft Office - Français (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7535 - Realtek Semiconductor Corp.) Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (HKLM\...\{91150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUSR_{D82063A8-7C8C-4C3B-A9BB-95138CA55D26}) (Version: - Microsoft) Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (Version: - Microsoft) Hidden Skype™ 7.17 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.17.105 - Skype Technologies S.A.) Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.4.40 - Safer-Networking Ltd.) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 6.0.1216 - SUPERAntiSpyware.com) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 19.0.13.0 - Synaptics Incorporated) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.17 - TeamSpeak Systems GmbH) Update for Skype for Business 2015 (KB3039776) 64-Bit Edition (HKLM\...\{90150000-012B-0409-1000-0000000FF1CE}_Office15.PROPLUSR_{0FA8AE0C-69AE-4F60-A1AB-F79C6BA5A999}) (Version: - Microsoft) VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN) WinRAR 5.21 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-347070757-4124586549-2319610994-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\cloud\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\FileCoAuth.exe (Microsoft Corporation) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {0CADA19D-34E1-4F4C-948C-7039372A2C69} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation) Task: {3F1B3010-BF37-41A1-92DA-D228B103FA9B} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2015-10-13] (Dropbox, Inc.) Task: {5104961B-699D-4DF7-A1A9-6714C442EC89} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-01-15] (Piriform Ltd) Task: {7851DECF-8D05-4152-98FF-D147771430CD} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe [2014-06-27] (Safer-Networking Ltd.) Task: {7BBEE612-FFF0-47CE-BDE8-7600D9CFB43D} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-04-22] (Adobe Systems Incorporated) Task: {7C26C938-A047-41C6-8D6F-6E0361574F45} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-05-30] (Google Inc.) Task: {866918E4-C230-4067-877E-7675748066C1} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe [2014-06-24] (Safer-Networking Ltd.) Task: {97EA5E53-B813-4108-B305-EF2481C97F7E} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation) Task: {9990449E-B6FA-4925-887D-254C49EF59C5} - System32\Tasks\AutoPico Daily Restart => C:\Program Files\KMSpico\AutoPico.exe [2014-06-29] (@ByELDI) Task: {9C284D86-F751-48B7-AF9A-9E64F5485969} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2014-01-23] (Microsoft Corporation) Task: {B2D00253-F075-434E-BC31-F6B88469A928} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-05-11] (Microsoft Corporation) Task: {CF3CA228-3D88-40FE-9063-0F1CCA853E63} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-05-30] (Google Inc.) Task: {D019A17E-0F50-40C0-8E09-7FEDDD8A74C6} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe [2014-06-24] (Safer-Networking Ltd.) Task: {F3A5C219-F85C-416E-AD63-FD40B0D4CBA2} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2015-10-13] (Dropbox, Inc.) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== 2015-10-30 09:18 - 2015-10-30 09:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll 2016-04-13 18:23 - 2016-03-29 12:20 - 02656952 _____ () C:\WINDOWS\system32\CoreUIComponents.dll 2016-04-13 18:23 - 2016-03-29 12:20 - 02656952 _____ () C:\WINDOWS\System32\CoreUIComponents.dll 2015-12-18 10:28 - 2015-12-07 06:14 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll 2016-05-11 17:11 - 2016-04-23 06:25 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll 2016-04-19 12:10 - 2016-04-19 12:10 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe 2016-03-29 15:46 - 2016-03-29 15:47 - 00016896 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.325.12390.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe 2016-03-29 15:46 - 2016-03-29 15:47 - 17535488 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.325.12390.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll 2016-03-04 15:24 - 2016-03-04 15:24 - 00291328 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.325.12390.0_x64__8wekyb3d8bbwe\StoreRatingPromotion.dll 2016-05-18 09:21 - 2016-05-18 09:22 - 00933576 _____ () C:\Program Files\WindowsApps\Microsoft.Office.OneNote_17.6965.57741.0_x64__8wekyb3d8bbwe\Microsoft.Applications.Telemetry.Windows.dll 2016-05-24 21:13 - 2016-05-24 21:14 - 00138432 _____ () C:\Program Files\WindowsApps\Microsoft.Office.OneNote_17.6965.57741.0_x64__8wekyb3d8bbwe\textinputdriver.dll 2016-05-24 21:13 - 2016-05-24 21:14 - 00634560 _____ () C:\Program Files\WindowsApps\Microsoft.Office.OneNote_17.6965.57741.0_x64__8wekyb3d8bbwe\SignalRClient_winapp.dll 2015-09-15 14:58 - 2015-09-15 14:58 - 08901184 _____ () C:\Program Files\Microsoft Office\Office15\1033\GrooveIntlResource.dll 2016-05-30 22:27 - 2016-05-25 01:24 - 02334360 _____ () C:\Program Files (x86)\Google\Chrome\Application\51.0.2704.63\libglesv2.dll 2016-05-30 22:27 - 2016-05-25 01:24 - 00105112 _____ () C:\Program Files (x86)\Google\Chrome\Application\51.0.2704.63\libegl.dll 2016-05-11 17:12 - 2016-04-23 06:02 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2016-05-11 17:12 - 2016-04-23 05:58 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2016-05-11 17:12 - 2016-04-23 05:58 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll 2016-05-11 17:12 - 2016-04-23 06:01 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll 2016-03-13 10:12 - 2014-05-13 13:04 - 00109400 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl 2016-03-13 10:12 - 2014-05-13 13:04 - 00167768 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl 2016-03-13 10:12 - 2014-05-13 13:04 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl 2016-03-13 10:12 - 2012-08-23 11:38 - 00574840 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll 2016-03-13 10:12 - 2012-04-03 18:06 - 00565640 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\av\BDSmartDB.dll 2016-04-19 12:10 - 2016-04-19 12:10 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll 2016-04-19 12:10 - 2016-04-19 12:10 - 22284800 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkyWrap.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) IE restricted site: HKU\.DEFAULT\...\007guard.com -> install.007guard.com IE restricted site: HKU\.DEFAULT\...\008i.com -> 008i.com IE restricted site: HKU\.DEFAULT\...\008k.com -> www.008k.com IE restricted site: HKU\.DEFAULT\...\00hq.com -> www.00hq.com IE restricted site: HKU\.DEFAULT\...\010402.com -> 010402.com IE restricted site: HKU\.DEFAULT\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com IE restricted site: HKU\.DEFAULT\...\0scan.com -> www.0scan.com IE restricted site: HKU\.DEFAULT\...\1-2005-search.com -> www.1-2005-search.com IE restricted site: HKU\.DEFAULT\...\1-domains-registrations.com -> www.1-domains-registrations.com IE restricted site: HKU\.DEFAULT\...\1000gratisproben.com -> www.1000gratisproben.com IE restricted site: HKU\.DEFAULT\...\1001namen.com -> www.1001namen.com IE restricted site: HKU\.DEFAULT\...\100888290cs.com -> mir.100888290cs.com IE restricted site: HKU\.DEFAULT\...\100sexlinks.com -> www.100sexlinks.com IE restricted site: HKU\.DEFAULT\...\10sek.com -> www.10sek.com IE restricted site: HKU\.DEFAULT\...\12-26.net -> user1.12-26.net IE restricted site: HKU\.DEFAULT\...\12-27.net -> user1.12-27.net IE restricted site: HKU\.DEFAULT\...\123fporn.info -> www.123fporn.info IE restricted site: HKU\.DEFAULT\...\123haustiereundmehr.com -> www.123haustiereundmehr.com IE restricted site: HKU\.DEFAULT\...\123moviedownload.com -> www.123moviedownload.com IE restricted site: HKU\.DEFAULT\...\123simsen.com -> www.123simsen.com There are 7873 more sites. IE restricted site: HKU\S-1-5-21-347070757-4124586549-2319610994-1001\...\007guard.com -> install.007guard.com IE restricted site: HKU\S-1-5-21-347070757-4124586549-2319610994-1001\...\008i.com -> 008i.com IE restricted site: HKU\S-1-5-21-347070757-4124586549-2319610994-1001\...\008k.com -> www.008k.com IE restricted site: HKU\S-1-5-21-347070757-4124586549-2319610994-1001\...\00hq.com -> www.00hq.com IE restricted site: HKU\S-1-5-21-347070757-4124586549-2319610994-1001\...\010402.com -> 010402.com IE restricted site: HKU\S-1-5-21-347070757-4124586549-2319610994-1001\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com IE restricted site: HKU\S-1-5-21-347070757-4124586549-2319610994-1001\...\0scan.com -> www.0scan.com IE restricted site: HKU\S-1-5-21-347070757-4124586549-2319610994-1001\...\1-2005-search.com -> www.1-2005-search.com IE restricted site: HKU\S-1-5-21-347070757-4124586549-2319610994-1001\...\1-domains-registrations.com -> www.1-domains-registrations.com IE restricted site: HKU\S-1-5-21-347070757-4124586549-2319610994-1001\...\1000gratisproben.com -> www.1000gratisproben.com IE restricted site: HKU\S-1-5-21-347070757-4124586549-2319610994-1001\...\1001namen.com -> www.1001namen.com IE restricted site: HKU\S-1-5-21-347070757-4124586549-2319610994-1001\...\100888290cs.com -> mir.100888290cs.com IE restricted site: HKU\S-1-5-21-347070757-4124586549-2319610994-1001\...\100sexlinks.com -> www.100sexlinks.com IE restricted site: HKU\S-1-5-21-347070757-4124586549-2319610994-1001\...\10sek.com -> www.10sek.com IE restricted site: HKU\S-1-5-21-347070757-4124586549-2319610994-1001\...\12-26.net -> user1.12-26.net IE restricted site: HKU\S-1-5-21-347070757-4124586549-2319610994-1001\...\12-27.net -> user1.12-27.net IE restricted site: HKU\S-1-5-21-347070757-4124586549-2319610994-1001\...\123fporn.info -> www.123fporn.info IE restricted site: HKU\S-1-5-21-347070757-4124586549-2319610994-1001\...\123haustiereundmehr.com -> www.123haustiereundmehr.com IE restricted site: HKU\S-1-5-21-347070757-4124586549-2319610994-1001\...\123moviedownload.com -> www.123moviedownload.com IE restricted site: HKU\S-1-5-21-347070757-4124586549-2319610994-1001\...\123simsen.com -> www.123simsen.com There are 7874 more sites. ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2015-07-10 13:04 - 2016-05-30 21:22 - 00451294 ____R C:\WINDOWS\system32\Drivers\etc\hosts 127.0.0.1 www.fakku.net 127.0.0.1 www.exhentai.org 127.0.0.1 e-hentai.org 127.0.0.1 www.youporn.com 127.0.0.1 www.xvideos.com 127.0.0.1 http://g.e-hentai.org/ 127.0.0.1 http://forums.e-hentai.org/ 127.0.0.1 http://nhentai.net/ 0.0.0.1 mssplus.mcafee.com127.0.0.1 www.007guard.com 127.0.0.1 007guard.com 127.0.0.1 008i.com 127.0.0.1 www.008k.com 127.0.0.1 008k.com 127.0.0.1 www.00hq.com 127.0.0.1 00hq.com 127.0.0.1 010402.com 127.0.0.1 www.032439.com 127.0.0.1 032439.com 127.0.0.1 www.0scan.com 127.0.0.1 0scan.com 127.0.0.1 1000gratisproben.com 127.0.0.1 www.1000gratisproben.com 127.0.0.1 1001namen.com 127.0.0.1 www.1001namen.com 127.0.0.1 100888290cs.com 127.0.0.1 www.100888290cs.com 127.0.0.1 www.100sexlinks.com 127.0.0.1 100sexlinks.com 127.0.0.1 10sek.com 127.0.0.1 www.10sek.com There are 15481 more lines. ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-347070757-4124586549-2319610994-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\cloud\Pictures\xenobladewallpaper.jpg DNS Servers: 192.168.1.254 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) HKLM\...\StartupApproved\StartupFolder: => "McAfee Security Scan Plus.lnk" HKLM\...\StartupApproved\Run32: => "StartCCC" HKLM\...\StartupApproved\Run32: => "LogMeIn Hamachi Ui" HKLM\...\StartupApproved\Run32: => "Dropbox" HKU\S-1-5-21-347070757-4124586549-2319610994-1001\...\StartupApproved\StartupFolder: => "Send to OneNote.lnk" HKU\S-1-5-21-347070757-4124586549-2319610994-1001\...\StartupApproved\Run: => "OneDrive" HKU\S-1-5-21-347070757-4124586549-2319610994-1001\...\StartupApproved\Run: => "CCleaner Monitoring" HKU\S-1-5-21-347070757-4124586549-2319610994-1001\...\StartupApproved\Run: => "WTFast Tray" HKU\S-1-5-21-347070757-4124586549-2319610994-1001\...\StartupApproved\Run: => "Steam" HKU\S-1-5-21-347070757-4124586549-2319610994-1001\...\StartupApproved\Run: => "SUPERAntiSpyware" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [{8E02FE9F-B768-4868-9F2B-61CE3F1610A3}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{A4365DFC-9E7A-4741-89A1-D23DFDE08184}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{7C7F8C9F-7F44-4A0A-8573-4C520E2E7FE1}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{E787B24C-86D7-4EEC-A579-6C5F6BEF8AD2}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{ACD07CED-1EDF-43CD-AA86-733E2A35AB66}] => (Allow) LPort=1689 FirewallRules: [{DFB96A8E-7B82-4DE1-AD84-BC2B0DC6ADB6}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe FirewallRules: [{E6E271CB-528C-4E08-AE69-2533B6655BD6}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe FirewallRules: [{B359C1FA-D269-4E7B-8E82-D20220581FBC}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe FirewallRules: [{AC6DC16A-4B12-4F3A-A16E-E5616FB62451}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe FirewallRules: [{F05C21D8-9428-4335-AC5A-194582C690F7}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe FirewallRules: [{0C619AD8-24DD-45A8-AA03-9ADE561A9075}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe FirewallRules: [{A6D26ECC-CAF2-4F17-89A5-EC822D91593A}] => (Allow) C:\Program Files\KMSpico\KMSELDI.exe FirewallRules: [{E1B14F0A-D092-454F-9DE1-2D6386B94CC3}] => (Allow) C:\Program Files\KMSpico\KMSELDI.exe FirewallRules: [{5D1B7651-E74A-4DA8-AEBA-A758DD5D17FA}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe FirewallRules: [{12562C29-6374-4EA6-A6E8-1180B9901561}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe FirewallRules: [{D7E1E49B-71E3-4E4B-AFFD-CEBA092A26A5}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe FirewallRules: [{6BA1BC8D-E7A1-457E-A96F-0EAB8B9C08C4}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe FirewallRules: [{75199C2D-A06C-4952-8C5B-30568FABFD74}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [TCP Query User{7979DC3F-DAE4-414B-9A4C-5EF9258338F7}C:\program files\hexchat\hexchat.exe] => (Allow) C:\program files\hexchat\hexchat.exe FirewallRules: [UDP Query User{A3482201-D154-490C-81B0-A734E977D893}C:\program files\hexchat\hexchat.exe] => (Allow) C:\program files\hexchat\hexchat.exe FirewallRules: [{E4CA35B1-B8CC-4A8A-83BC-B2FF4E39C625}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe FirewallRules: [{FDFEA7D0-D935-448E-AFB9-2728A2D933EC}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe FirewallRules: [{CDF40FFB-BF4E-4D37-B2B3-64B9C6E68250}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe FirewallRules: [TCP Query User{93BE1148-629E-487C-BF26-F5E3AC7A80FD}C:\program files\hexchat\hexchat.exe] => (Allow) C:\program files\hexchat\hexchat.exe FirewallRules: [UDP Query User{26AA9162-EF7E-46FF-B077-8AA799E0E6C5}C:\program files\hexchat\hexchat.exe] => (Allow) C:\program files\hexchat\hexchat.exe FirewallRules: [{2086911C-7183-4BA8-ACE4-1F4786D87088}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{5ADFADEC-A382-4FA0-B3BB-334EE97C0569}] => (Allow) LPort=1688 StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe] => Enabled:Spybot - Search & Destroy tray access StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe] => Enabled:Spybot-S&D 2 Scanner Service StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe] => Enabled:Spybot-S&D 2 Updater StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe] => Enabled:Spybot-S&D 2 Background update service ==================== Restore Points ========================= 10-05-2016 16:36:36 Windows Update 15-05-2016 13:08:28 Windows Update 23-05-2016 07:58:48 Punto di controllo pianificato ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (05/31/2016 05:29:05 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nome dell'applicazione che ha generato l'errore: AutoPico.exe, versione: 12.3.0.0, timestamp: 0x53b06ef5 Nome del modulo che ha generato l'errore: KERNELBASE.dll, versione: 10.0.10586.306, timestamp: 0x571af331 Codice eccezione: 0xe0434352 Offset errore 0x0000000000071f28 ID processo che ha generato l'errore: 0x1f20 Ora di avvio dell'applicazione che ha generato l'errore: 0xAutoPico.exe0 Percorso dell'applicazione che ha generato l'errore: AutoPico.exe1 Percorso del modulo che ha generato l'errore: AutoPico.exe2 ID segnalazione: AutoPico.exe3 Nome completo pacchetto che ha generato l'errore: AutoPico.exe4 ID applicazione relativo al pacchetto che ha generato l'errore: AutoPico.exe5 Error: (05/31/2016 05:29:04 PM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Applicazione: AutoPico.exe Versione framework: v4.0.30319 Descrizione: il processo è stato terminato a causa di un'eccezione non gestita. Informazioni sull'eccezione: System.Net.Sockets.SocketException in System.Net.Sockets.Socket.BeginReceive(Byte[], Int32, Int32, System.Net.Sockets.SocketFlags, System.AsyncCallback, System.Object) in System.Net.Sockets.NetworkStream.BeginRead(Byte[], Int32, Int32, System.AsyncCallback, System.Object) Informazioni sull'eccezione: System.IO.IOException in System.Net.Sockets.NetworkStream.BeginRead(Byte[], Int32, Int32, System.AsyncCallback, System.Object) in AutoPico.KMSEmulator.TCPServer.AcceptTcpClientCallbackTask(Client ByRef) in System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) in System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) in System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object) in System.Threading.ThreadHelper.ThreadStart() Error: (05/31/2016 04:24:40 PM) (Source: ATIeRecord) (EventID: 16391) (User: ) Description: ATI EEU maximum number of session has been surpassed Error: (05/30/2016 11:09:35 PM) (Source: ATIeRecord) (EventID: 16391) (User: ) Description: ATI EEU maximum number of session has been surpassed Error: (05/30/2016 11:09:34 PM) (Source: ATIeRecord) (EventID: 16391) (User: ) Description: ATI EEU maximum number of session has been surpassed Error: (05/30/2016 11:09:34 PM) (Source: ATIeRecord) (EventID: 16391) (User: ) Description: ATI EEU maximum number of session has been surpassed Error: (05/30/2016 11:09:34 PM) (Source: ATIeRecord) (EventID: 16391) (User: ) Description: ATI EEU maximum number of session has been surpassed Error: (05/30/2016 11:09:33 PM) (Source: ATIeRecord) (EventID: 16391) (User: ) Description: ATI EEU maximum number of session has been surpassed Error: (05/30/2016 10:59:11 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nome dell'applicazione che ha generato l'errore: AutoPico.exe, versione: 12.3.0.0, timestamp: 0x53b06ef5 Nome del modulo che ha generato l'errore: KERNELBASE.dll, versione: 10.0.10586.306, timestamp: 0x571af331 Codice eccezione: 0xe0434352 Offset errore 0x0000000000071f28 ID processo che ha generato l'errore: 0x1564 Ora di avvio dell'applicazione che ha generato l'errore: 0xAutoPico.exe0 Percorso dell'applicazione che ha generato l'errore: AutoPico.exe1 Percorso del modulo che ha generato l'errore: AutoPico.exe2 ID segnalazione: AutoPico.exe3 Nome completo pacchetto che ha generato l'errore: AutoPico.exe4 ID applicazione relativo al pacchetto che ha generato l'errore: AutoPico.exe5 Error: (05/30/2016 10:59:10 PM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Applicazione: AutoPico.exe Versione framework: v4.0.30319 Descrizione: il processo è stato terminato a causa di un'eccezione non gestita. Informazioni sull'eccezione: System.Net.Sockets.SocketException in System.Net.Sockets.Socket.EndReceive(System.IAsyncResult) in System.Net.Sockets.NetworkStream.EndRead(System.IAsyncResult) Informazioni sull'eccezione: System.IO.IOException in System.Net.Sockets.NetworkStream.EndRead(System.IAsyncResult) in AutoPico.KMSEmulator.TCPServer.ReadCallback(System.IAsyncResult) in System.Net.LazyAsyncResult.Complete(IntPtr) in System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) in System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) in System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object) in System.Net.ContextAwareResult.Complete(IntPtr) in System.Net.LazyAsyncResult.ProtectedInvokeCallback(System.Object, IntPtr) in System.Net.Sockets.BaseOverlappedAsyncResult.CompletionPortCallback(UInt32, UInt32, System.Threading.NativeOverlapped*) in System.Threading._IOCompletionCallback.PerformIOCompletionCallback(UInt32, UInt32, System.Threading.NativeOverlapped*) System errors: ============= Error: (05/30/2016 11:09:33 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Il servizio Accesso dati utente_468f5dce è stato arrestato in modo imprevisto. Questo problema si è verificato 1 volta/e. Le seguenti azioni di correzione saranno eseguite tra 10000 millisecondi: Riavvia il servizio. Error: (05/30/2016 11:09:33 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Il servizio Archiviazione dati utente_468f5dce è stato arrestato in modo imprevisto. Questo problema si è verificato 1 volta/e. Le seguenti azioni di correzione saranno eseguite tra 10000 millisecondi: Riavvia il servizio. Error: (05/30/2016 11:09:33 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Il servizio Dati contatti_468f5dce è stato arrestato in modo imprevisto. Questo problema si è verificato 1 volta/e. Le seguenti azioni di correzione saranno eseguite tra 10000 millisecondi: Riavvia il servizio. Error: (05/30/2016 11:09:33 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Il servizio Sincronizza host_468f5dce è stato arrestato in modo imprevisto. Questo problema si è verificato 1 volta/e. Le seguenti azioni di correzione saranno eseguite tra 10000 millisecondi: Riavvia il servizio. Error: (05/30/2016 11:09:32 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: impostazioni specifiche dell'applicazioneLocaleAttivazione{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYSYSTEMS-1-5-18LocalHost (tramite LRPC)Non disponibileNon disponibile Error: (05/30/2016 02:04:32 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Il servizio Accesso dati utente_45b091a8 è stato arrestato in modo imprevisto. Questo problema si è verificato 1 volta/e. Le seguenti azioni di correzione saranno eseguite tra 10000 millisecondi: Riavvia il servizio. Error: (05/30/2016 02:04:32 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Il servizio Archiviazione dati utente_45b091a8 è stato arrestato in modo imprevisto. Questo problema si è verificato 1 volta/e. Le seguenti azioni di correzione saranno eseguite tra 10000 millisecondi: Riavvia il servizio. Error: (05/30/2016 02:04:32 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Il servizio Dati contatti_45b091a8 è stato arrestato in modo imprevisto. Questo problema si è verificato 1 volta/e. Le seguenti azioni di correzione saranno eseguite tra 10000 millisecondi: Riavvia il servizio. Error: (05/30/2016 02:04:32 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Il servizio Sincronizza host_45b091a8 è stato arrestato in modo imprevisto. Questo problema si è verificato 1 volta/e. Le seguenti azioni di correzione saranno eseguite tra 10000 millisecondi: Riavvia il servizio. Error: (05/30/2016 02:04:32 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: impostazioni specifiche dell'applicazioneLocaleAttivazione{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYSYSTEMS-1-5-18LocalHost (tramite LRPC)Non disponibileNon disponibile CodeIntegrity: =================================== Date: 2016-05-15 14:23:01.194 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-05-13 11:59:26.023 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-05-12 16:52:56.287 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-05-11 22:59:39.494 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-04-15 11:57:23.450 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-04-14 18:42:46.484 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-04-13 22:59:36.764 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-03-24 10:12:05.971 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-03-13 11:59:22.648 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-03-12 22:59:28.664 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i5 CPU M 430 @ 2.27GHz Percentage of memory in use: 63% Total physical RAM: 3958.71 MB Available physical RAM: 1463.59 MB Total Virtual: 5501.74 MB Available Virtual: 2073.49 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:464.75 GB) (Free:243.19 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: C20ADB7D) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=464.8 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=480 MB) - (Type=27) Partition 4: (Not Active) - (Size=450 MB) - (Type=27) ==================== End of Addition.txt ============================