Additional scan result of Farbar Recovery Scan Tool (x64) Version:01-06-2016 Ran by [removed] (2016-06-02 23:13:34) Running from C:\Users\[removed]\Downloads Windows 10 Home Version 1511 (X64) (2015-12-07 03:21:24) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-347070757-4124586549-2319610994-500 - Administrator - Enabled) => C:\Users\Administrator cloud (S-1-5-21-347070757-4124586549-2319610994-1001 - Administrator - Enabled) => C:\Users\cloud DefaultAccount (S-1-5-21-347070757-4124586549-2319610994-503 - Limited - Disabled) Guest (S-1-5-21-347070757-4124586549-2319610994-501 - Limited - Disabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Spybot - Search and Destroy (Enabled - Out of date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Acrobat Reader DC - Italiano (HKLM-x32\...\{AC76BA86-7AD7-1040-7B44-AC0F074E4100}) (Version: 15.016.20041 - Adobe Systems Incorporated) Amazon Kindle (HKU\S-1-5-21-347070757-4124586549-2319610994-1001\...\Amazon Kindle) (Version: - Amazon) AMD Catalyst Control Center (HKLM-x32\...\WUCCCApp) (Version: 1.00.0000 - AMD) Audacity 2.1.2 (HKLM-x32\...\Audacity®_is1) (Version: 2.1.2 - Audacity Team) CCleaner (HKLM\...\CCleaner) (Version: 5.14 - Piriform) CDisplayEx 1.10.29 (HKLM\...\CDisplayEx_is1) (Version: - Progdigy Software S.A.R.L.) Celtx (2.9.7) (HKLM-x32\...\Celtx (2.9.7)) (Version: 2.9.7 (it) - Greyfirst) CPUID HWMonitor 1.28 (HKLM\...\CPUID HWMonitor_is1) (Version: - ) Dropbox (HKLM-x32\...\Dropbox) (Version: 3.20.1 - Dropbox, Inc.) Dropbox Update Helper (x32 Version: 1.3.27.37 - Dropbox, Inc.) Hidden Google Chrome (HKLM-x32\...\Google Chrome) (Version: 51.0.2704.63 - Google Inc.) Google Update Helper (x32 Version: 1.3.30.3 - Google Inc.) Hidden HexChat (HKLM\...\HexChat_is1) (Version: 2.10.2 - HexChat) IObit Uninstaller (HKLM-x32\...\IObitUninstall) (Version: 5.4.0.119 - IObit) League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games) League of Legends (x32 Version: 3.0.1 - Riot Games) Hidden McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.11.292.3 - McAfee, Inc.) Memory Cleaner 2.20 (HKLM-x32\...\MemClean) (Version: 2.20 - KoshyJohn.com) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools per Office Runtime (x64) - Language Pack - ITA (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - ITA) (Version: 10.0.50903 - Microsoft Corporation) Microsoft XNA Framework Redistributable 4.0 (HKLM-x32\...\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7535 - Realtek Semiconductor Corp.) Skype™ 7.17 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.17.105 - Skype Technologies S.A.) Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.4.40 - Safer-Networking Ltd.) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 6.0.1216 - SUPERAntiSpyware.com) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 19.0.13.0 - Synaptics Incorporated) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.17 - TeamSpeak Systems GmbH) VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN) WinRAR 5.21 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-347070757-4124586549-2319610994-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\cloud\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\FileCoAuth.exe (Microsoft Corporation) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {175F5F2A-5A25-4C15-AFEE-0F8D9FBCFE85} - System32\Tasks\Uninstaller_SkipUac_cloud => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [2016-06-01] (IObit) Task: {3F1B3010-BF37-41A1-92DA-D228B103FA9B} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2015-10-13] (Dropbox, Inc.) Task: {5104961B-699D-4DF7-A1A9-6714C442EC89} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-01-15] (Piriform Ltd) Task: {7851DECF-8D05-4152-98FF-D147771430CD} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe [2014-06-27] (Safer-Networking Ltd.) Task: {7BBEE612-FFF0-47CE-BDE8-7600D9CFB43D} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-04-22] (Adobe Systems Incorporated) Task: {7C26C938-A047-41C6-8D6F-6E0361574F45} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-05-30] (Google Inc.) Task: {866918E4-C230-4067-877E-7675748066C1} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe [2014-06-24] (Safer-Networking Ltd.) Task: {B2D00253-F075-434E-BC31-F6B88469A928} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-05-11] (Microsoft Corporation) Task: {CF3CA228-3D88-40FE-9063-0F1CCA853E63} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-05-30] (Google Inc.) Task: {D019A17E-0F50-40C0-8E09-7FEDDD8A74C6} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe [2014-06-24] (Safer-Networking Ltd.) Task: {F3A5C219-F85C-416E-AD63-FD40B0D4CBA2} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2015-10-13] (Dropbox, Inc.) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\Uninstaller_SkipUac_cloud.job => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== 2015-10-30 09:18 - 2015-10-30 09:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll 2016-04-13 18:23 - 2016-03-29 12:20 - 02656952 _____ () C:\WINDOWS\system32\CoreUIComponents.dll 2016-04-13 18:23 - 2016-03-29 12:20 - 02656952 _____ () C:\WINDOWS\System32\CoreUIComponents.dll 2016-04-19 12:10 - 2016-04-19 12:10 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe 2015-12-18 10:28 - 2015-12-07 06:14 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll 2016-05-11 17:11 - 2016-04-23 06:25 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll 2016-05-11 17:11 - 2016-04-23 06:25 - 00674816 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\MtcUvc.dll 2016-05-30 22:27 - 2016-05-25 01:24 - 02334360 _____ () C:\Program Files (x86)\Google\Chrome\Application\51.0.2704.63\libglesv2.dll 2016-05-30 22:27 - 2016-05-25 01:24 - 00105112 _____ () C:\Program Files (x86)\Google\Chrome\Application\51.0.2704.63\libegl.dll 2016-03-29 15:46 - 2016-03-29 15:47 - 00016896 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.325.12390.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe 2016-03-29 15:46 - 2016-03-29 15:47 - 17535488 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.325.12390.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll 2016-03-04 15:24 - 2016-03-04 15:24 - 00291328 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.325.12390.0_x64__8wekyb3d8bbwe\StoreRatingPromotion.dll 2016-05-18 09:21 - 2016-05-18 09:22 - 00933576 _____ () C:\Program Files\WindowsApps\Microsoft.Office.OneNote_17.6965.57741.0_x64__8wekyb3d8bbwe\Microsoft.Applications.Telemetry.Windows.dll 2016-05-24 21:13 - 2016-05-24 21:14 - 00138432 _____ () C:\Program Files\WindowsApps\Microsoft.Office.OneNote_17.6965.57741.0_x64__8wekyb3d8bbwe\textinputdriver.dll 2016-05-24 21:13 - 2016-05-24 21:14 - 00634560 _____ () C:\Program Files\WindowsApps\Microsoft.Office.OneNote_17.6965.57741.0_x64__8wekyb3d8bbwe\SignalRClient_winapp.dll 2016-05-11 17:12 - 2016-04-23 06:02 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2016-05-11 17:12 - 2016-04-23 05:58 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2016-05-11 17:12 - 2016-04-23 05:58 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll 2016-05-11 17:12 - 2016-04-23 06:01 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll 2016-03-13 10:12 - 2014-05-13 13:04 - 00109400 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl 2016-03-13 10:12 - 2014-05-13 13:04 - 00167768 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl 2016-03-13 10:12 - 2014-05-13 13:04 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl 2016-03-13 10:12 - 2012-08-23 11:38 - 00574840 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll 2016-03-13 10:12 - 2012-04-03 18:06 - 00565640 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\av\BDSmartDB.dll 2016-04-19 12:10 - 2016-04-19 12:10 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll 2016-04-19 12:10 - 2016-04-19 12:10 - 22284800 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkyWrap.dll 2016-06-02 23:03 - 2015-12-23 16:27 - 00355616 _____ () C:\Program Files (x86)\IObit\IObit Uninstaller\madExcept_.bpl 2016-06-02 23:03 - 2015-12-23 16:27 - 00190240 _____ () C:\Program Files (x86)\IObit\IObit Uninstaller\madBasic_.bpl 2016-06-02 23:03 - 2015-12-23 16:27 - 00057632 _____ () C:\Program Files (x86)\IObit\IObit Uninstaller\madDisAsm_.bpl 2016-06-02 23:03 - 2015-12-23 16:27 - 00629536 _____ () C:\Program Files (x86)\IObit\LiveUpdate\ProductStatistics.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) IE restricted site: HKU\.DEFAULT\...\007guard.com -> install.007guard.com IE restricted site: HKU\.DEFAULT\...\008i.com -> 008i.com IE restricted site: HKU\.DEFAULT\...\008k.com -> www.008k.com IE restricted site: HKU\.DEFAULT\...\00hq.com -> www.00hq.com IE restricted site: HKU\.DEFAULT\...\010402.com -> 010402.com IE restricted site: HKU\.DEFAULT\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com IE restricted site: HKU\.DEFAULT\...\0scan.com -> www.0scan.com IE restricted site: HKU\.DEFAULT\...\1-2005-search.com -> www.1-2005-search.com IE restricted site: HKU\.DEFAULT\...\1-domains-registrations.com -> www.1-domains-registrations.com IE restricted site: HKU\.DEFAULT\...\1000gratisproben.com -> www.1000gratisproben.com IE restricted site: HKU\.DEFAULT\...\1001namen.com -> www.1001namen.com IE restricted site: HKU\.DEFAULT\...\100888290cs.com -> mir.100888290cs.com IE restricted site: HKU\.DEFAULT\...\100sexlinks.com -> www.100sexlinks.com IE restricted site: HKU\.DEFAULT\...\10sek.com -> www.10sek.com IE restricted site: HKU\.DEFAULT\...\12-26.net -> user1.12-26.net IE restricted site: HKU\.DEFAULT\...\12-27.net -> user1.12-27.net IE restricted site: HKU\.DEFAULT\...\123fporn.info -> www.123fporn.info IE restricted site: HKU\.DEFAULT\...\123haustiereundmehr.com -> www.123haustiereundmehr.com IE restricted site: HKU\.DEFAULT\...\123moviedownload.com -> www.123moviedownload.com IE restricted site: HKU\.DEFAULT\...\123simsen.com -> www.123simsen.com There are 7873 more sites. IE restricted site: HKU\S-1-5-21-347070757-4124586549-2319610994-1001\...\007guard.com -> install.007guard.com IE restricted site: HKU\S-1-5-21-347070757-4124586549-2319610994-1001\...\008i.com -> 008i.com IE restricted site: HKU\S-1-5-21-347070757-4124586549-2319610994-1001\...\008k.com -> www.008k.com IE restricted site: HKU\S-1-5-21-347070757-4124586549-2319610994-1001\...\00hq.com -> www.00hq.com IE restricted site: HKU\S-1-5-21-347070757-4124586549-2319610994-1001\...\010402.com -> 010402.com IE restricted site: HKU\S-1-5-21-347070757-4124586549-2319610994-1001\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com IE restricted site: HKU\S-1-5-21-347070757-4124586549-2319610994-1001\...\0scan.com -> www.0scan.com IE restricted site: HKU\S-1-5-21-347070757-4124586549-2319610994-1001\...\1-2005-search.com -> www.1-2005-search.com IE restricted site: HKU\S-1-5-21-347070757-4124586549-2319610994-1001\...\1-domains-registrations.com -> www.1-domains-registrations.com IE restricted site: HKU\S-1-5-21-347070757-4124586549-2319610994-1001\...\1000gratisproben.com -> www.1000gratisproben.com IE restricted site: HKU\S-1-5-21-347070757-4124586549-2319610994-1001\...\1001namen.com -> www.1001namen.com IE restricted site: HKU\S-1-5-21-347070757-4124586549-2319610994-1001\...\100888290cs.com -> mir.100888290cs.com IE restricted site: HKU\S-1-5-21-347070757-4124586549-2319610994-1001\...\100sexlinks.com -> www.100sexlinks.com IE restricted site: HKU\S-1-5-21-347070757-4124586549-2319610994-1001\...\10sek.com -> www.10sek.com IE restricted site: HKU\S-1-5-21-347070757-4124586549-2319610994-1001\...\12-26.net -> user1.12-26.net IE restricted site: HKU\S-1-5-21-347070757-4124586549-2319610994-1001\...\12-27.net -> user1.12-27.net IE restricted site: HKU\S-1-5-21-347070757-4124586549-2319610994-1001\...\123fporn.info -> www.123fporn.info IE restricted site: HKU\S-1-5-21-347070757-4124586549-2319610994-1001\...\123haustiereundmehr.com -> www.123haustiereundmehr.com IE restricted site: HKU\S-1-5-21-347070757-4124586549-2319610994-1001\...\123moviedownload.com -> www.123moviedownload.com IE restricted site: HKU\S-1-5-21-347070757-4124586549-2319610994-1001\...\123simsen.com -> www.123simsen.com There are 7874 more sites. ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2015-07-10 13:04 - 2016-05-30 21:22 - 00451294 ____R C:\WINDOWS\system32\Drivers\etc\hosts 127.0.0.1 www.fakku.net 127.0.0.1 www.exhentai.org 127.0.0.1 e-hentai.org 127.0.0.1 www.youporn.com 127.0.0.1 www.xvideos.com 127.0.0.1 http://g.e-hentai.org/ 127.0.0.1 http://forums.e-hentai.org/ 127.0.0.1 http://nhentai.net/ 0.0.0.1 mssplus.mcafee.com127.0.0.1 www.007guard.com 127.0.0.1 007guard.com 127.0.0.1 008i.com 127.0.0.1 www.008k.com 127.0.0.1 008k.com 127.0.0.1 www.00hq.com 127.0.0.1 00hq.com 127.0.0.1 010402.com 127.0.0.1 www.032439.com 127.0.0.1 032439.com 127.0.0.1 www.0scan.com 127.0.0.1 0scan.com 127.0.0.1 1000gratisproben.com 127.0.0.1 www.1000gratisproben.com 127.0.0.1 1001namen.com 127.0.0.1 www.1001namen.com 127.0.0.1 100888290cs.com 127.0.0.1 www.100888290cs.com 127.0.0.1 www.100sexlinks.com 127.0.0.1 100sexlinks.com 127.0.0.1 10sek.com 127.0.0.1 www.10sek.com There are 15481 more lines. ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-347070757-4124586549-2319610994-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\cloud\Pictures\xenobladewallpaper.jpg DNS Servers: 192.168.1.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) HKLM\...\StartupApproved\StartupFolder: => "McAfee Security Scan Plus.lnk" HKLM\...\StartupApproved\Run32: => "StartCCC" HKLM\...\StartupApproved\Run32: => "LogMeIn Hamachi Ui" HKLM\...\StartupApproved\Run32: => "Dropbox" HKU\S-1-5-21-347070757-4124586549-2319610994-1001\...\StartupApproved\StartupFolder: => "Send to OneNote.lnk" HKU\S-1-5-21-347070757-4124586549-2319610994-1001\...\StartupApproved\Run: => "OneDrive" HKU\S-1-5-21-347070757-4124586549-2319610994-1001\...\StartupApproved\Run: => "CCleaner Monitoring" HKU\S-1-5-21-347070757-4124586549-2319610994-1001\...\StartupApproved\Run: => "WTFast Tray" HKU\S-1-5-21-347070757-4124586549-2319610994-1001\...\StartupApproved\Run: => "Steam" HKU\S-1-5-21-347070757-4124586549-2319610994-1001\...\StartupApproved\Run: => "SUPERAntiSpyware" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [{8E02FE9F-B768-4868-9F2B-61CE3F1610A3}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{A4365DFC-9E7A-4741-89A1-D23DFDE08184}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{7C7F8C9F-7F44-4A0A-8573-4C520E2E7FE1}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{E787B24C-86D7-4EEC-A579-6C5F6BEF8AD2}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{ACD07CED-1EDF-43CD-AA86-733E2A35AB66}] => (Allow) LPort=1689 FirewallRules: [{DFB96A8E-7B82-4DE1-AD84-BC2B0DC6ADB6}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe FirewallRules: [{E6E271CB-528C-4E08-AE69-2533B6655BD6}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe FirewallRules: [{B359C1FA-D269-4E7B-8E82-D20220581FBC}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe FirewallRules: [{AC6DC16A-4B12-4F3A-A16E-E5616FB62451}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe FirewallRules: [{F05C21D8-9428-4335-AC5A-194582C690F7}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe FirewallRules: [{0C619AD8-24DD-45A8-AA03-9ADE561A9075}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe FirewallRules: [{A6D26ECC-CAF2-4F17-89A5-EC822D91593A}] => (Allow) C:\Program Files\KMSpico\KMSELDI.exe FirewallRules: [{E1B14F0A-D092-454F-9DE1-2D6386B94CC3}] => (Allow) C:\Program Files\KMSpico\KMSELDI.exe FirewallRules: [{5D1B7651-E74A-4DA8-AEBA-A758DD5D17FA}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe FirewallRules: [{12562C29-6374-4EA6-A6E8-1180B9901561}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe FirewallRules: [{D7E1E49B-71E3-4E4B-AFFD-CEBA092A26A5}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe FirewallRules: [{6BA1BC8D-E7A1-457E-A96F-0EAB8B9C08C4}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe FirewallRules: [{75199C2D-A06C-4952-8C5B-30568FABFD74}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [TCP Query User{7979DC3F-DAE4-414B-9A4C-5EF9258338F7}C:\program files\hexchat\hexchat.exe] => (Allow) C:\program files\hexchat\hexchat.exe FirewallRules: [UDP Query User{A3482201-D154-490C-81B0-A734E977D893}C:\program files\hexchat\hexchat.exe] => (Allow) C:\program files\hexchat\hexchat.exe FirewallRules: [{E4CA35B1-B8CC-4A8A-83BC-B2FF4E39C625}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe FirewallRules: [{FDFEA7D0-D935-448E-AFB9-2728A2D933EC}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe FirewallRules: [{CDF40FFB-BF4E-4D37-B2B3-64B9C6E68250}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe FirewallRules: [TCP Query User{93BE1148-629E-487C-BF26-F5E3AC7A80FD}C:\program files\hexchat\hexchat.exe] => (Allow) C:\program files\hexchat\hexchat.exe FirewallRules: [UDP Query User{26AA9162-EF7E-46FF-B077-8AA799E0E6C5}C:\program files\hexchat\hexchat.exe] => (Allow) C:\program files\hexchat\hexchat.exe FirewallRules: [{2086911C-7183-4BA8-ACE4-1F4786D87088}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe] => Enabled:Spybot - Search & Destroy tray access StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe] => Enabled:Spybot-S&D 2 Scanner Service StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe] => Enabled:Spybot-S&D 2 Updater StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe] => Enabled:Spybot-S&D 2 Background update service ==================== Restore Points ========================= 15-05-2016 13:08:28 Windows Update 23-05-2016 07:58:48 Punto di controllo pianificato 01-06-2016 08:44:00 Punto di controllo pianificato 02-06-2016 22:31:48 Removed Microsoft Office Professional Plus 2013 ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (06/02/2016 10:32:04 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Servizi di crittografia: impossibile elaborare la chiamata OnIdentity() nell'oggetto writer del sistema. Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol. System Error: Accesso negato. . Error: (06/02/2016 05:53:04 PM) (Source: ATIeRecord) (EventID: 16391) (User: ) Description: ATI EEU maximum number of session has been surpassed Error: (06/02/2016 12:43:10 PM) (Source: ATIeRecord) (EventID: 16391) (User: ) Description: ATI EEU maximum number of session has been surpassed Error: (06/02/2016 12:43:09 PM) (Source: ATIeRecord) (EventID: 16391) (User: ) Description: ATI EEU maximum number of session has been surpassed Error: (06/02/2016 12:43:08 PM) (Source: ATIeRecord) (EventID: 16391) (User: ) Description: ATI EEU maximum number of session has been surpassed Error: (06/02/2016 12:43:08 PM) (Source: ATIeRecord) (EventID: 16391) (User: ) Description: ATI EEU maximum number of session has been surpassed Error: (06/02/2016 12:43:03 PM) (Source: ATIeRecord) (EventID: 16391) (User: ) Description: ATI EEU maximum number of session has been surpassed Error: (06/02/2016 11:59:08 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nome dell'applicazione che ha generato l'errore: AutoPico.exe, versione: 12.3.0.0, timestamp: 0x53b06ef5 Nome del modulo che ha generato l'errore: KERNELBASE.dll, versione: 10.0.10586.306, timestamp: 0x571af331 Codice eccezione: 0xe0434352 Offset errore 0x0000000000071f28 ID processo che ha generato l'errore: 0xd50 Ora di avvio dell'applicazione che ha generato l'errore: 0xAutoPico.exe0 Percorso dell'applicazione che ha generato l'errore: AutoPico.exe1 Percorso del modulo che ha generato l'errore: AutoPico.exe2 ID segnalazione: AutoPico.exe3 Nome completo pacchetto che ha generato l'errore: AutoPico.exe4 ID applicazione relativo al pacchetto che ha generato l'errore: AutoPico.exe5 Error: (06/02/2016 11:59:07 AM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Applicazione: AutoPico.exe Versione framework: v4.0.30319 Descrizione: il processo è stato terminato a causa di un'eccezione non gestita. Informazioni sull'eccezione: System.ArgumentOutOfRangeException in System.ThrowHelper.ThrowArgumentOutOfRangeException(System.ExceptionArgument, System.ExceptionResource) in System.Collections.Generic.List`1[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]].RemoveAt(Int32) in AutoPico.Logging.FileLogger.WriteMessage(System.String ByRef) in System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) in System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) in System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object) in System.Threading.ThreadHelper.ThreadStart() Error: (06/02/2016 08:24:06 AM) (Source: ATIeRecord) (EventID: 16391) (User: ) Description: ATI EEU maximum number of session has been surpassed System errors: ============= Error: (06/02/2016 10:27:46 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: impostazioni specifiche dell'applicazioneLocaleAttivazione{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYSYSTEMS-1-5-18LocalHost (tramite LRPC)Non disponibileNon disponibile Error: (06/02/2016 12:43:04 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Il servizio Accesso dati utente_535dd462 è stato arrestato in modo imprevisto. Questo problema si è verificato 1 volta/e. Le seguenti azioni di correzione saranno eseguite tra 10000 millisecondi: Riavvia il servizio. Error: (06/02/2016 12:43:04 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Il servizio Archiviazione dati utente_535dd462 è stato arrestato in modo imprevisto. Questo problema si è verificato 1 volta/e. Le seguenti azioni di correzione saranno eseguite tra 10000 millisecondi: Riavvia il servizio. Error: (06/02/2016 12:43:04 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Il servizio Dati contatti_535dd462 è stato arrestato in modo imprevisto. Questo problema si è verificato 1 volta/e. Le seguenti azioni di correzione saranno eseguite tra 10000 millisecondi: Riavvia il servizio. Error: (06/02/2016 12:43:04 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Il servizio Sincronizza host_535dd462 è stato arrestato in modo imprevisto. Questo problema si è verificato 1 volta/e. Le seguenti azioni di correzione saranno eseguite tra 10000 millisecondi: Riavvia il servizio. Error: (06/02/2016 12:43:03 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: impostazioni specifiche dell'applicazioneLocaleAttivazione{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYSYSTEMS-1-5-18LocalHost (tramite LRPC)Non disponibileNon disponibile Error: (06/02/2016 01:10:26 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Il servizio Accesso dati utente_4c7092b0 è stato arrestato in modo imprevisto. Questo problema si è verificato 1 volta/e. Le seguenti azioni di correzione saranno eseguite tra 10000 millisecondi: Riavvia il servizio. Error: (06/02/2016 01:10:26 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Il servizio Archiviazione dati utente_4c7092b0 è stato arrestato in modo imprevisto. Questo problema si è verificato 1 volta/e. Le seguenti azioni di correzione saranno eseguite tra 10000 millisecondi: Riavvia il servizio. Error: (06/02/2016 01:10:26 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Il servizio Dati contatti_4c7092b0 è stato arrestato in modo imprevisto. Questo problema si è verificato 1 volta/e. Le seguenti azioni di correzione saranno eseguite tra 10000 millisecondi: Riavvia il servizio. Error: (06/02/2016 01:10:26 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Il servizio Sincronizza host_4c7092b0 è stato arrestato in modo imprevisto. Questo problema si è verificato 1 volta/e. Le seguenti azioni di correzione saranno eseguite tra 10000 millisecondi: Riavvia il servizio. CodeIntegrity: =================================== Date: 2016-05-15 14:23:01.194 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-05-13 11:59:26.023 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-05-12 16:52:56.287 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-05-11 22:59:39.494 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-04-15 11:57:23.450 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-04-14 18:42:46.484 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-04-13 22:59:36.764 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-03-24 10:12:05.971 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-03-13 11:59:22.648 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-03-12 22:59:28.664 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i5 CPU M 430 @ 2.27GHz Percentage of memory in use: 63% Total physical RAM: 3958.71 MB Available physical RAM: 1447.48 MB Total Virtual: 5501.74 MB Available Virtual: 1554.93 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:464.75 GB) (Free:272.16 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: C20ADB7D) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=464.8 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=480 MB) - (Type=27) Partition 4: (Not Active) - (Size=450 MB) - (Type=27) ==================== End of Addition.txt ============================