Additional scan result of Farbar Recovery Scan Tool (x64) Version:06-06-2016 Ran by [removed] (2016-06-07 09:51:22) Running from C:\Users\[removed]\Downloads Windows 10 Pro Version 1511 (X64) (2016-01-16 04:36:39) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= admin (S-1-5-21-3515164915-2860861682-270758949-1000 - Administrator - Enabled) => C:\Users\admin Administrator (S-1-5-21-3515164915-2860861682-270758949-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-3515164915-2860861682-270758949-503 - Limited - Disabled) Guest (S-1-5-21-3515164915-2860861682-270758949-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-3515164915-2860861682-270758949-1002 - Limited - Enabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) µTorrent (HKU\S-1-5-21-3515164915-2860861682-270758949-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\uTorrent) (Version: 3.4.7.42330 - BitTorrent Inc.) Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.016.20045 - Adobe Systems Incorporated) Adobe Digital Editions 4.0 (HKLM-x32\...\Adobe Digital Editions 4.0) (Version: 4.0.3 - Adobe Systems Incorporated) Adobe Flash Player 21 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 21.0.0.242 - Adobe Systems Incorporated) AMD Catalyst Control Center (HKLM-x32\...\WUCCCApp) (Version: 1.00.0000 - AMD) AMD Catalyst Install Manager (HKLM\...\{935D195D-0E7A-3D63-5B66-70E6D13E6C03}) (Version: 8.0.911.0 - Advanced Micro Devices, Inc.) Apple Application Support (32-bit) (HKLM-x32\...\{26356515-5821-40FA-9C3D-9785052A1062}) (Version: 4.3.1 - Apple Inc.) Apple Application Support (64-bit) (HKLM\...\{C2651553-6CA3-4822-B2E6-BC4ACA6E0EA2}) (Version: 4.3.1 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{2E4AF2A6-50EA-4260-9BA4-5E582D11879A}) (Version: 9.3.0.15 - Apple Inc.) Apple Software Update (HKLM-x32\...\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.) Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 11.2.2262 - AVAST Software) AVS Audio Editor 7.2 (HKLM-x32\...\AVS Audio Editor_is1) (Version: 7.2.2.488 - Online Media Technologies Ltd.) Ballistic Measurement System (HKLM-x32\...\Ballistic Measurement System_is1) (Version: 2015.0.0 - Innervations) BitTorrent (HKU\S-1-5-21-3515164915-2860861682-270758949-1000\...\BitTorrent) (Version: 7.9.5.41373 - BitTorrent Inc.) BitTorrent (HKU\S-1-5-21-3515164915-2860861682-270758949-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\BitTorrent) (Version: 7.9.5.41373 - BitTorrent Inc.) Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.) Canon MG3100 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG3100_series) (Version: - ) Chromodo (HKLM-x32\...\Chromodo) (Version: 48.12.18.254 - Comodo) Crystal Reports Basic Runtime for Visual Studio 2008 (HKLM-x32\...\{CE26F10F-C80F-4377-908B-1B7882AE2CE3}) (Version: 10.5.2.0 - Business Objects) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden DriverIdentifier 4.2.7 (HKLM-x32\...\{40A3E5DB-5EF8-4F04-BF3E-7AB87C4AE85A}_is1) (Version: - DriverIdentifier) Dropbox (HKLM-x32\...\Dropbox) (Version: 4.4.29 - Dropbox, Inc.) Dropbox Update Helper (x32 Version: 1.3.41.1 - Dropbox, Inc.) Hidden EndNote X7 (HKLM-x32\...\{86B3F2D6-AC2B-0017-8AE1-F2F77F781B0C}) (Version: 17.0.1.7212 - Thomson Reuters) G*Power 3.1.9.2 (HKLM-x32\...\{F9C59D86-6F65-4EDB-89A2-FBA1F78762D2}) (Version: 3.1.92 - Franz Faul, Uni Kiel, Germany) Google Drive (HKLM-x32\...\{709316AD-161C-4D5C-9AE7-0B3A822DA271}) (Version: 1.30.2170.0459 - Google, Inc.) Google Drive (HKLM-x32\...\{9C350701-AC04-48BA-A435-BD5E0D82897E}) (Version: 1.25.0523.2491 - Google, Inc.) Google Talk Plugin (HKLM-x32\...\{F9B579C2-D854-300A-BE62-A09EB9D722E4}) (Version: 5.41.3.0 - Google) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.30.3 - Google Inc.) Hidden HP Support Solutions Framework (HKLM-x32\...\{A772EA32-AE5B-4474-BFC0-4C69C04AFF6A}) (Version: 12.4.18.7 - Hewlett-Packard Company) HP Webcam (HKLM-x32\...\{1D61E881-43CD-447B-9E6B-D2C6138B2862}) (Version: 1.0.26.3 - Roxio) iCloud (HKLM\...\{ADFDB647-35C0-4254-9EE6-2D9C3B7104BD}) (Version: 5.2.1.69 - Apple Inc.) iTunes (HKLM\...\{58D7E5F7-BAD1-49C5-93C8-B655736EDA00}) (Version: 12.4.0.119 - Apple Inc.) Java 8 Update 73 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218073F0}) (Version: 8.0.730.2 - Oracle Corporation) Java 8 Update 91 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218091F0}) (Version: 8.0.910.14 - Oracle Corporation) Kinovea (HKLM-x32\...\Kinovea) (Version: 0.8.15 - Kinovea) Kistler BioWare (HKLM-x32\...\{DABF95C0-16FB-4493-BBB2-B050B4E6C982}) (Version: 5.1.1.0 - Kistler Instrument Group) Kistler DataServer (HKLM-x32\...\{0479EFA6-278B-4031-9004-BFEF8EEE3415}) (Version: 1.3.0.2002 - Kistler Instrument Group) Kodi (HKU\S-1-5-21-3515164915-2860861682-270758949-1000\...\Kodi) (Version: - XBMC-Foundation) Kodi (HKU\S-1-5-21-3515164915-2860861682-270758949-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Kodi) (Version: - XBMC-Foundation) Malwarebytes Anti-Exploit version 1.8.1.1196 (HKLM\...\Malwarebytes Anti-Exploit_is1) (Version: 1.8.1.1196 - Malwarebytes) Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes) MCShield ::Anti-Malware Tool:: (HKLM-x32\...\MCShield) (Version: 3.0.5.28 - MyCity) Microsoft Forefront UAG endpoint components v4.0.0 (HKLM-x32\...\Microsoft Forefront UAG endpoint components 3.1.0) (Version: - Microsoft Corporation) Microsoft LifeCam (HKLM\...\{6965A8D2-465D-4F98-9FAA-0E9E2348F329}) (Version: 3.22.270.0 - Microsoft Corporation) Microsoft Office 365 - en-us (HKLM\...\O365HomePremRetail - en-us) (Version: 16.0.6868.2067 - Microsoft Corporation) Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft SQL Server Compact 3.5 SP1 English (HKLM-x32\...\{E59113EB-0285-4BFD-A37A-B79EAC6B8F4B}) (Version: 3.5.5692.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Office 16 Click-to-Run Extensibility Component (x32 Version: 16.0.6828.1019 - Microsoft Corporation) Hidden Office 16 Click-to-Run Licensing Component (Version: 16.0.6828.1019 - Microsoft Corporation) Hidden Office 16 Click-to-Run Localization Component (x32 Version: 16.0.6828.1019 - Microsoft Corporation) Hidden Qualys BrowserCheck (HKLM-x32\...\{80112B33-B9C0-424C-8C9C-7684C238325E}) (Version: 1.1.1 - Qualys) Recuva (HKLM\...\Recuva) (Version: 1.52 - Piriform) Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.32.0 - Renesas Electronics Corporation) Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.32.0 - Renesas Electronics Corporation) Hidden ResearchSoft Direct Export Helper (HKLM-x32\...\ResearchSoft Direct Export Helper) (Version: - Thomson Reuters) SafeZone Stable 1.48.2066.101 (x32 Version: 1.48.2066.101 - Avast Software) Hidden ShadowExplorer 0.9 (HKLM-x32\...\ShadowExplorer_is1) (Version: 0.9.462.0 - ShadowExplorer.com) Spotify (HKU\S-1-5-21-3515164915-2860861682-270758949-1000\...\Spotify) (Version: 1.0.20.94.g8f8543b3 - Spotify AB) Spotify (HKU\S-1-5-21-3515164915-2860861682-270758949-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Spotify) (Version: 1.0.20.94.g8f8543b3 - Spotify AB) SPSS 17 (HKLM-x32\...\SPSS 17) (Version: - Rainbow Hacks) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 19.0.12.0 - Synaptics Incorporated) Unchecky v0.4.3 (HKLM-x32\...\Unchecky) (Version: 0.4.3 - RaMMicHaeL) <==== ATTENTION Visual3D v5 Educational Textbook Version (HKLM-x32\...\{C27B0E0C-87A7-4723-94A3-0C43F79F1582}_is1) (Version: 5.00.26 - C-Motion, Inc.) Windows Driver Package - FTDI CDM Driver Package - Bus/D2XX Driver (01/18/2013 2.08.28) (HKLM\...\9E24492CE9279512BD465F61DB8523641BB7BBFC) (Version: 01/18/2013 2.08.28 - FTDI) Windows Driver Package - FTDI CDM Driver Package - VCP Driver (01/18/2013 2.08.28) (HKLM\...\E61B77ECE57113AE1CA028BC7A8AD6C137BD13DD) (Version: 01/18/2013 2.08.28 - FTDI) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-3515164915-2860861682-270758949-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0_Classes\CLSID\{590C4387-5EBD-4D46-8A84-CD0BA2EF2856}\InprocServer32 -> C:\Users\admin\AppData\Local\Google\Update\1.3.30.3\psuser_64.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-3515164915-2860861682-270758949-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\admin\AppData\Local\Microsoft\OneDrive\17.3.6281.1202_2\FileCoAuth.exe (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3515164915-2860861682-270758949-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0_Classes\CLSID\{793EE463-1304-471C-ADF1-68C2FFB01247}\InprocServer32 -> C:\Users\admin\AppData\Local\Google\Update\1.3.29.5\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-3515164915-2860861682-270758949-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\admin\AppData\Local\Google\Update\1.3.30.3\psuser_64.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-3515164915-2860861682-270758949-1000_Classes\CLSID\{590C4387-5EBD-4D46-8A84-CD0BA2EF2856}\InprocServer32 -> C:\Users\admin\AppData\Local\Google\Update\1.3.30.3\psuser_64.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-3515164915-2860861682-270758949-1000_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\admin\AppData\Local\Microsoft\OneDrive\17.3.6281.1202_2\FileCoAuth.exe (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3515164915-2860861682-270758949-1000_Classes\CLSID\{793EE463-1304-471C-ADF1-68C2FFB01247}\InprocServer32 -> C:\Users\admin\AppData\Local\Google\Update\1.3.29.5\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-3515164915-2860861682-270758949-1000_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\admin\AppData\Local\Google\Update\1.3.30.3\psuser_64.dll (Google Inc.) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {087F68F7-C132-4310-9EE9-27D24CFE8ED1} - System32\Tasks\CreateExplorerShellUnelevatedTask => /NOUACCHECK Task: {0B2E76BB-2016-4B03-91C0-6C42D954A6F5} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-05-17] (Dropbox, Inc.) Task: {0B7B3ED7-513A-432C-AD71-BC07C9C32A97} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-05-17] (Dropbox, Inc.) Task: {0C65352E-53D8-4B7D-A441-CE3712B05573} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-01] (Google Inc.) Task: {12BC0AE8-37EE-46F1-9C0A-A9BEE258CC28} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2016-05-04] (Hewlett-Packard) Task: {13D863AB-3093-472C-B0AD-0E5B77DD7A0B} - System32\Tasks\COMODO\COMODO Signature Update {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe Task: {180F77A3-E0A4-4368-AA86-678BD55A5374} - System32\Tasks\SafeZone scheduled Autoupdate 1462889571 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2016-04-15] (Avast Software) Task: {191C4972-F4DE-4FED-A12C-BB5121E8C9D8} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\Windows\ehome\ehrec.exe Task: {1F6808B2-08FD-4392-B127-5DDEF786A890} - System32\Tasks\{063A0F41-9B35-450D-A49B-B89A237A427F} => C:\Users\admin\AppData\Roaming\Dropbox\bin\Dropbox.exe Task: {24AF0F45-0C06-4A68-A941-81F1212CAE9A} - System32\Tasks\{3E6BB2CE-BD98-4E94-B6C5-116FE3E6625C} => C:\Users\admin\AppData\Roaming\Dropbox\bin\Dropbox.exe Task: {26525853-27B4-4655-9285-735162100E05} - System32\Tasks\{D4F5AE6C-9830-4EC0-9E37-1A36ABAE145F} => C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.exe [2014-03-31] (Microsoft Corporation) Task: {398AC8BC-6256-4C71-99EE-1E4A8D4A056A} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2016-05-15] (Microsoft Corporation) Task: {4C03A10C-7CC8-4093-A9AF-B437294EABA1} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2016-05-17] (Microsoft Corporation) Task: {598CED29-90D8-4796-AF92-FB127159CFD8} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2016-05-15] (Microsoft Corporation) Task: {8D5EEB58-929C-4081-AEFE-E8DF4980F972} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3515164915-2860861682-270758949-1000Core => C:\Users\admin\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.) Task: {92057438-2CF3-4F54-B75B-D1D3920F4535} - System32\Tasks\COMODO\COMODO Autostart {D5EFF3B3-E126-4AF6-BCE9-852A72129E10} => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe Task: {9AA6BC5F-CC27-4F32-9C23-92C17CC1F737} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [2016-05-09] (Hewlett-Packard) Task: {9E51DD61-2299-4564-B918-1DBB6AEAC8C4} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3515164915-2860861682-270758949-1000UA => C:\Users\admin\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.) Task: {C01DB616-D3B8-4B22-BD54-E290AE6CB6A6} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2016-05-10] (AVAST Software) Task: {C3543460-945B-4E23-9EED-FF31D9C4DC72} - System32\Tasks\{E35AD483-8B30-4C79-B0F9-5EA57C5A57E3} => C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.exe [2014-03-31] (Microsoft Corporation) Task: {D05BC672-A2EB-4B52-BA71-E326BD7F76C8} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-05-12] (Microsoft Corporation) Task: {DCACE629-14B6-470E-ACEF-33FA4D4C97C8} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-05-13] (Adobe Systems Incorporated) Task: {E09A24CF-42FB-4202-A728-DD2D1A7EDE60} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-01] (Google Inc.) Task: {E7774606-2E3C-4D5E-BD6C-9EFE5231C110} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe Task: {EA028372-9F41-426E-8095-E43CF7D39A29} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.) Task: {EEC8E1CC-F031-460B-BB54-A190AE029F52} - System32\Tasks\COMODO\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe Task: {F7C9EE6D-2391-4690-87BA-57C28844299E} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-04-22] (Adobe Systems Incorporated) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-3515164915-2860861682-270758949-1000Core.job => C:\Users\admin\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-3515164915-2860861682-270758949-1000UA.job => C:\Users\admin\AppData\Local\Google\Update\GoogleUpdate.exe ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== 2016-03-18 22:56 - 2016-03-18 22:56 - 00092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2016-04-22 01:07 - 2016-04-22 01:07 - 01337144 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2015-10-30 08:18 - 2015-10-30 08:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll 2016-04-13 06:29 - 2016-03-29 11:20 - 02656952 _____ () C:\WINDOWS\system32\CoreUIComponents.dll 2016-04-13 06:29 - 2016-03-29 11:20 - 02656952 _____ () C:\WINDOWS\System32\CoreUIComponents.dll 2013-12-04 14:08 - 2013-08-23 14:36 - 00721263 _____ () C:\Windows\SysWOW64\ISCM64.dll 2016-04-19 09:33 - 2016-04-19 09:33 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe 2016-01-16 12:56 - 2016-01-16 12:56 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll 2016-05-11 22:03 - 2016-04-23 05:25 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll 2016-03-20 11:58 - 2016-05-15 11:51 - 00417480 _____ () C:\Program Files\Common Files\Microsoft Shared\ClickToRun\ApiClient.dll 2016-06-03 08:36 - 2016-06-03 08:37 - 00017920 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.526.11220.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe 2016-06-03 08:36 - 2016-06-03 08:37 - 13105152 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.526.11220.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll 2016-06-03 08:36 - 2016-06-03 08:37 - 00680448 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.526.11220.0_x64__8wekyb3d8bbwe\Microsoft.DesignCore.dll 2016-03-04 10:46 - 2016-03-04 10:47 - 00291328 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.526.11220.0_x64__8wekyb3d8bbwe\StoreRatingPromotion.dll 2016-01-21 09:15 - 2016-01-21 09:15 - 03746816 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1601.49020.0_x64__8wekyb3d8bbwe\Calculator.exe 2015-12-15 07:20 - 2015-12-15 07:20 - 00258560 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1601.49020.0_x64__8wekyb3d8bbwe\StoreRatingPromotion.dll 2016-05-11 22:05 - 2016-04-23 05:02 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2016-05-11 22:05 - 2016-04-23 04:58 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2016-05-11 22:06 - 2016-04-23 04:58 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll 2016-05-11 22:06 - 2016-04-23 05:01 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll 2016-05-10 14:19 - 2016-05-10 14:19 - 00123344 _____ () C:\Program Files\AVAST Software\Avast\log.dll 2016-05-10 14:18 - 2016-05-10 14:18 - 00135816 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll 2016-06-03 21:58 - 2016-06-03 21:58 - 02923008 _____ () C:\Program Files\AVAST Software\Avast\defs\16060301\algo.dll 2016-05-10 14:18 - 2016-05-10 14:18 - 00309912 _____ () C:\Program Files\AVAST Software\Avast\browser_pass.dll 2016-05-10 14:19 - 2016-05-10 14:19 - 00479680 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll 2016-06-06 19:26 - 2016-06-06 19:26 - 02923008 _____ () C:\Program Files\AVAST Software\Avast\defs\16060601\algo.dll 2016-04-19 09:33 - 2016-04-19 09:33 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll 2016-04-19 09:33 - 2016-04-19 09:33 - 22284800 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkyWrap.dll 2016-04-22 01:08 - 2016-04-22 01:08 - 01047864 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2016-03-18 22:56 - 2016-03-18 22:56 - 00080184 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2016-04-22 01:07 - 2016-04-22 01:07 - 00244024 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxslt.dll 2016-06-04 09:24 - 2016-05-05 11:09 - 00034768 _____ () C:\Program Files (x86)\Dropbox\Client\_multiprocessing.pyd 2016-06-04 09:23 - 2016-05-05 11:10 - 00019408 _____ () C:\Program Files (x86)\Dropbox\Client\faulthandler.pyd 2016-06-04 09:23 - 2016-05-05 11:09 - 00116688 _____ () C:\Program Files (x86)\Dropbox\Client\pywintypes27.dll 2016-06-04 09:24 - 2016-05-05 11:09 - 00093640 _____ () C:\Program Files (x86)\Dropbox\Client\_ctypes.pyd 2016-06-04 09:24 - 2016-05-05 11:09 - 00018376 _____ () C:\Program Files (x86)\Dropbox\Client\select.pyd 2016-06-04 09:24 - 2016-05-31 19:34 - 00019760 _____ () C:\Program Files (x86)\Dropbox\Client\tornado.speedups.pyd 2016-06-04 09:24 - 2016-05-05 11:11 - 00105928 _____ () C:\Program Files (x86)\Dropbox\Client\win32api.pyd 2016-06-04 09:23 - 2016-05-05 11:09 - 00392144 _____ () C:\Program Files (x86)\Dropbox\Client\pythoncom27.dll 2016-06-04 09:24 - 2016-05-31 19:34 - 00381752 _____ () C:\Program Files (x86)\Dropbox\Client\win32com.shell.shell.pyd 2016-06-04 09:24 - 2016-05-05 11:09 - 00692688 _____ () C:\Program Files (x86)\Dropbox\Client\unicodedata.pyd 2016-06-04 09:23 - 2016-05-31 19:34 - 00020816 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._constant_time.pyd 2016-06-04 09:24 - 2016-05-05 11:10 - 00123856 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_backend.pyd 2016-06-04 09:23 - 2016-05-31 19:34 - 01682760 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._openssl.pyd 2016-06-04 09:23 - 2016-05-31 19:34 - 00020808 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._padding.pyd 2016-06-04 09:24 - 2016-05-31 19:34 - 00021840 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_unicode_environ_win32_x8bf8e68bx9968e850.pyd 2016-06-04 09:23 - 2016-05-31 19:34 - 00038696 _____ () C:\Program Files (x86)\Dropbox\Client\fastpath.pyd 2016-06-04 09:23 - 2016-05-05 11:11 - 00020936 _____ () C:\Program Files (x86)\Dropbox\Client\mmapfile.pyd 2016-06-04 09:24 - 2016-05-05 11:11 - 00024528 _____ () C:\Program Files (x86)\Dropbox\Client\win32event.pyd 2016-06-04 09:24 - 2016-05-05 11:11 - 00114640 _____ () C:\Program Files (x86)\Dropbox\Client\win32security.pyd 2016-06-04 09:24 - 2016-05-05 11:11 - 00124880 _____ () C:\Program Files (x86)\Dropbox\Client\win32file.pyd 2016-06-04 09:24 - 2016-05-31 19:34 - 00021832 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_pywin_kernel32_x64d8f881xc8c369be.pyd 2016-06-04 09:24 - 2016-05-05 11:11 - 00024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32clipboard.pyd 2016-06-04 09:24 - 2016-05-05 11:11 - 00175560 _____ () C:\Program Files (x86)\Dropbox\Client\win32gui.pyd 2016-06-04 09:24 - 2016-05-05 11:11 - 00030160 _____ () C:\Program Files (x86)\Dropbox\Client\win32pipe.pyd 2016-06-04 09:24 - 2016-05-05 11:11 - 00043472 _____ () C:\Program Files (x86)\Dropbox\Client\win32process.pyd 2016-06-04 09:24 - 2016-05-05 11:11 - 00048592 _____ () C:\Program Files (x86)\Dropbox\Client\win32service.pyd 2016-06-04 09:24 - 2016-05-31 19:34 - 00023872 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.kernel32._winffi_kernel32.pyd 2016-06-04 09:23 - 2016-05-05 11:09 - 00134088 _____ () C:\Program Files (x86)\Dropbox\Client\pyexpat.pyd 2016-06-04 09:23 - 2016-05-31 19:34 - 00026456 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox.infinite.win.compiled._driverinstallation.pyd 2016-06-04 09:24 - 2016-05-05 11:11 - 00057808 _____ () C:\Program Files (x86)\Dropbox\Client\win32evtlog.pyd 2016-06-04 09:24 - 2016-05-05 11:11 - 00024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32profile.pyd 2016-06-04 09:23 - 2016-05-31 19:33 - 00246592 _____ () C:\Program Files (x86)\Dropbox\Client\breakpad.client.windows.handler.pyd 2016-06-04 09:24 - 2016-05-05 11:11 - 00028616 _____ () C:\Program Files (x86)\Dropbox\Client\win32ts.pyd 2016-06-04 09:23 - 2016-05-31 19:34 - 00052024 _____ () C:\Program Files (x86)\Dropbox\Client\psutil._psutil_windows.pyd 2016-06-04 09:24 - 2016-05-05 11:09 - 00134608 _____ () C:\Program Files (x86)\Dropbox\Client\_elementtree.pyd 2016-06-04 09:23 - 2016-05-05 11:10 - 00240584 _____ () C:\Program Files (x86)\Dropbox\Client\jpegtran.pyd 2016-06-04 09:24 - 2016-05-31 19:34 - 00020800 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.iphlpapi._winffi_iphlpapi.pyd 2016-06-04 09:24 - 2016-05-31 19:34 - 00019776 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winerror._winffi_winerror.pyd 2016-06-04 09:24 - 2016-05-31 19:34 - 00020800 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.wininet._winffi_wininet.pyd 2016-06-04 09:23 - 2016-05-31 19:34 - 00020280 _____ () C:\Program Files (x86)\Dropbox\Client\cpuid.compiled._cpuid.pyd 2016-06-04 09:24 - 2016-05-31 19:34 - 00023376 _____ () C:\Program Files (x86)\Dropbox\Client\winscreenshot.compiled._CaptureScreenshot.pyd 2016-06-04 09:24 - 2016-05-05 11:11 - 00350152 _____ () C:\Program Files (x86)\Dropbox\Client\winxpgui.pyd 2016-06-04 09:24 - 2016-05-31 19:34 - 00022352 _____ () C:\Program Files (x86)\Dropbox\Client\winverifysignature.compiled._VerifySignature.pyd 2016-06-04 09:23 - 2016-05-31 19:34 - 00024392 _____ () C:\Program Files (x86)\Dropbox\Client\librsyncffi.compiled._librsyncffi.pyd 2016-06-04 09:23 - 2016-05-05 11:12 - 00036296 _____ () C:\Program Files (x86)\Dropbox\Client\librsync.dll 2016-06-04 09:23 - 2016-05-31 19:34 - 00031568 _____ () C:\Program Files (x86)\Dropbox\Client\enterprise_data.compiled._enterprise_data.pyd 2016-06-04 09:23 - 2016-03-12 01:46 - 00293392 _____ () C:\Program Files (x86)\Dropbox\Client\EnterpriseDataAdapter.dll 2016-06-04 09:23 - 2016-05-31 19:34 - 00084280 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_sqlite_ext.DLL 2016-06-04 09:23 - 2016-05-31 19:34 - 01826096 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtCore.pyd 2016-06-04 09:24 - 2016-05-05 11:10 - 00083912 _____ () C:\Program Files (x86)\Dropbox\Client\sip.pyd 2016-06-04 09:23 - 2016-05-31 19:34 - 03928880 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWidgets.pyd 2016-06-04 09:23 - 2016-05-31 19:34 - 01971504 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtGui.pyd 2016-06-04 09:23 - 2016-05-31 19:34 - 00531248 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtNetwork.pyd 2016-06-04 09:23 - 2016-05-31 19:34 - 00132912 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKit.pyd 2016-06-04 09:23 - 2016-05-31 19:34 - 00223544 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKitWidgets.pyd 2016-06-04 09:23 - 2016-05-31 19:34 - 00207672 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtPrintSupport.pyd 2016-06-04 09:24 - 2016-05-05 11:11 - 00060880 _____ () C:\Program Files (x86)\Dropbox\Client\win32print.pyd 2016-06-04 09:24 - 2016-05-31 19:34 - 00025928 _____ () C:\Program Files (x86)\Dropbox\Client\windisplaytoast.compiled._DisplayToast.pyd 2016-06-04 09:24 - 2016-05-31 19:34 - 00024904 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_wpad_proxy_win_x752e3d61xdcfdcc84.pyd 2016-06-04 09:23 - 2016-05-31 19:34 - 00546096 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQuick.pyd 2016-06-04 09:23 - 2016-05-31 19:34 - 00357680 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQml.pyd 2016-06-04 09:23 - 2016-05-05 11:13 - 00017864 _____ () C:\Program Files (x86)\Dropbox\Client\libEGL.dll 2016-06-04 09:23 - 2016-05-05 11:13 - 01631184 _____ () C:\Program Files (x86)\Dropbox\Client\libGLESv2.dll 2016-06-04 09:24 - 2016-05-05 11:15 - 00697304 _____ () C:\Program Files (x86)\Dropbox\Client\QtQuick\Controls\qtquickcontrolsplugin.dll 2016-03-09 10:20 - 2016-03-09 10:20 - 40539648 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2016-05-08 08:51 - 2016-06-03 09:05 - 03592392 _____ () C:\Program Files (x86)\Microsoft Office\root\Office16\gfx.dll 2016-03-20 12:11 - 2016-06-03 09:04 - 00157384 _____ () C:\Program Files (x86)\Microsoft Office\root\Office16\JitV.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\Users\admin\Desktop\Loreto Hops, Sprints, and CODS 13-4-16.xlsx:com.dropbox.attributes [168] ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) IE trusted site: HKU\S-1-5-21-3515164915-2860861682-270758949-1000\...\google.com -> hxxps://accounts.google.com IE trusted site: HKU\S-1-5-21-3515164915-2860861682-270758949-1000\...\sharepoint.com -> hxxps://testlivesalfordac.sharepoint.com IE trusted site: HKU\S-1-5-21-3515164915-2860861682-270758949-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\google.com -> hxxps://accounts.google.com IE trusted site: HKU\S-1-5-21-3515164915-2860861682-270758949-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\sharepoint.com -> hxxps://testlivesalfordac.sharepoint.com ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 03:34 - 2016-06-04 11:23 - 00001227 ____A C:\WINDOWS\system32\Drivers\etc\hosts 127.0.0.1 localhost0.0.0.0 0.0.0.0 # fix for traceroute and netstat display anomaly 0.0.0.0 tracking.opencandy.com.s3.amazonaws.com 0.0.0.0 media.opencandy.com 0.0.0.0 cdn.opencandy.com 0.0.0.0 tracking.opencandy.com 0.0.0.0 api.opencandy.com 0.0.0.0 api.recommendedsw.com 0.0.0.0 installer.betterinstaller.com 0.0.0.0 installer.filebulldog.com 0.0.0.0 d3oxtn1x3b8d7i.cloudfront.net 0.0.0.0 inno.bisrv.com 0.0.0.0 nsis.bisrv.com 0.0.0.0 cdn.file2desktop.com 0.0.0.0 cdn.goateastcach.us 0.0.0.0 cdn.guttastatdk.us 0.0.0.0 cdn.inskinmedia.com 0.0.0.0 cdn.insta.oibundles2.com 0.0.0.0 cdn.insta.playbryte.com 0.0.0.0 cdn.llogetfastcach.us 0.0.0.0 cdn.montiera.com 0.0.0.0 cdn.msdwnld.com 0.0.0.0 cdn.mypcbackup.com 0.0.0.0 cdn.ppdownload.com 0.0.0.0 cdn.riceateastcach.us 0.0.0.0 cdn.shyapotato.us 0.0.0.0 cdn.solimba.com 0.0.0.0 cdn.tuto4pc.com 0.0.0.0 cdn.appround.biz 0.0.0.0 cdn.bigspeedpro.com 0.0.0.0 cdn.bispd.com There are 4 more lines. ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-3515164915-2860861682-270758949-1000\Control Panel\Desktop\\Wallpaper -> HKU\S-1-5-21-3515164915-2860861682-270758949-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\Wallpaper -> HKU\S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\Wallpaper -> DNS Servers: 8.8.8.8 - 8.8.4.4 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) HKLM\...\StartupApproved\Run: => "iTunesHelper" HKLM\...\StartupApproved\Run32: => "APSDaemon" HKU\S-1-5-21-3515164915-2860861682-270758949-1000\...\StartupApproved\Run: => "BitTorrent" HKU\S-1-5-21-3515164915-2860861682-270758949-1000\...\StartupApproved\Run: => "Google Update" HKU\S-1-5-21-3515164915-2860861682-270758949-1000\...\StartupApproved\Run: => "GoogleChromeAutoLaunch_A822CA3D40D4B8944864CFEA751D8D57" HKU\S-1-5-21-3515164915-2860861682-270758949-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\StartupApproved\Run: => "BitTorrent" HKU\S-1-5-21-3515164915-2860861682-270758949-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\StartupApproved\Run: => "Google Update" HKU\S-1-5-21-3515164915-2860861682-270758949-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\StartupApproved\Run: => "GoogleChromeAutoLaunch_A822CA3D40D4B8944864CFEA751D8D57" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [MSMQ-In-TCP] => (Allow) %systemroot%\system32\mqsvc.exe FirewallRules: [MSMQ-Out-TCP] => (Allow) %systemroot%\system32\mqsvc.exe FirewallRules: [MSMQ-In-UDP] => (Allow) %systemroot%\system32\mqsvc.exe FirewallRules: [MSMQ-Out-UDP] => (Allow) %systemroot%\system32\mqsvc.exe FirewallRules: [WCF-NetTcpActivator-In-TCP-64bit] => (Allow) LPort=808 FirewallRules: [UDP Query User{52288698-5AF7-47A1-8E0A-198A76EF9335}C:\program files (x86)\ibm\spss\statistics\20\jre\bin\javaw.exe] => (Block) C:\program files (x86)\ibm\spss\statistics\20\jre\bin\javaw.exe FirewallRules: [TCP Query User{8894236E-F9DE-40BB-A439-BAD8ED37E334}C:\program files (x86)\ibm\spss\statistics\20\jre\bin\javaw.exe] => (Block) C:\program files (x86)\ibm\spss\statistics\20\jre\bin\javaw.exe FirewallRules: [UDP Query User{32D14826-74EB-4A47-9150-6C05846D59C8}C:\program files (x86)\spss 17\statistics.exe] => (Allow) C:\program files (x86)\spss 17\statistics.exe FirewallRules: [TCP Query User{827FE4FA-D5FC-4B40-A45C-3DC61D91D1C0}C:\program files (x86)\spss 17\statistics.exe] => (Allow) C:\program files (x86)\spss 17\statistics.exe FirewallRules: [UDP Query User{40FDBA4C-191A-443B-8C52-9D92AA7C10EE}C:\users\admin\appdata\roaming\bittorrent\bittorrent.exe] => (Block) C:\users\admin\appdata\roaming\bittorrent\bittorrent.exe FirewallRules: [TCP Query User{C202D075-A98D-4505-82ED-3D1B88FE1EFF}C:\users\admin\appdata\roaming\bittorrent\bittorrent.exe] => (Block) C:\users\admin\appdata\roaming\bittorrent\bittorrent.exe FirewallRules: [{FE7968EC-ED7E-4B94-A254-BB3C579E55BC}] => (Allow) LPort=139 FirewallRules: [TCP Query User{559F5A6D-B143-4C85-99CB-468057135901}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe FirewallRules: [UDP Query User{F12CFC3D-6CDC-4F3B-B7B4-1D69B6723885}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe FirewallRules: [TCP Query User{E7DAC4B4-A4A5-4D64-9C82-DD941F6D9719}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe FirewallRules: [UDP Query User{8BF7801A-7790-4A0F-9B58-658CD371A279}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe FirewallRules: [TCP Query User{EB47B5F2-BEBC-42F1-9034-ED9F932E94A3}C:\users\admin\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\admin\appdata\roaming\spotify\spotify.exe FirewallRules: [UDP Query User{2B2C2FC8-160F-4443-B4B0-E0A3221342D7}C:\users\admin\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\admin\appdata\roaming\spotify\spotify.exe FirewallRules: [TCP Query User{F83C5337-0457-452A-A24D-4812009FA5FF}C:\users\admin\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\admin\appdata\roaming\spotify\spotify.exe FirewallRules: [UDP Query User{1668F5F6-0978-4A8A-A754-6FE43EE6657F}C:\users\admin\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\admin\appdata\roaming\spotify\spotify.exe FirewallRules: [{CDAAF369-D93D-4915-BD0A-FB4109175D23}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeCam.exe FirewallRules: [{CCFCAAC0-340A-42B9-A669-4E704BB4EF8B}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeCam.exe FirewallRules: [{F9C6B979-F9F9-4736-9891-82FF67832E87}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeEnC2.exe FirewallRules: [{D9D7880B-6CE3-474C-9A55-297D5E6123DF}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeEnC2.exe FirewallRules: [{EAC9C857-E2E6-412F-9503-90A3F855B738}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe FirewallRules: [{616C30D4-AD21-4853-ADF5-8D735ABA2A8C}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe FirewallRules: [{0C5FA3AD-D205-469B-82C8-6E8CB1EF0492}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeTray.exe FirewallRules: [{E81A3D57-1911-4942-B595-2481BF14B613}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeTray.exe FirewallRules: [{D86B63CE-5FEA-4B3F-A070-BB3CDDA45E75}] => (Allow) C:\Users\admin\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe FirewallRules: [{566AE3BC-650D-4F36-B3F2-E45E10648303}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{242ADDA0-69C1-4882-AB7D-1003F0BEFA92}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{B33E406F-E833-4E06-A488-BCF0923A1284}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{CE4CAE57-0DFB-4D07-B6AF-C5CB244D4F0B}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{1F3CFD3E-C3AC-40F8-8D6F-452699C360B5}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe FirewallRules: [{87B7C276-6209-4EAE-90F5-8C036B000673}] => (Allow) LPort=2869 FirewallRules: [{E3031186-17B1-4FAA-89F3-8B0798B66089}] => (Allow) LPort=1900 FirewallRules: [TCP Query User{3064164E-A20D-41EE-8D6E-3B3BBED8EC5C}C:\users\admin\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\admin\appdata\roaming\dropbox\bin\dropbox.exe FirewallRules: [UDP Query User{41182754-764E-42F7-B038-C349BA3BC621}C:\users\admin\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\admin\appdata\roaming\dropbox\bin\dropbox.exe FirewallRules: [{7EEE148F-428C-420C-923B-4647CD2F8B06}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{EC5B5E21-EEA4-4B13-9A0F-982C3DAE6035}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{02D3633F-245A-460F-A12F-66477E2B407E}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{F27E1DFA-AC39-48A2-90DD-C70AD91932CD}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [TCP Query User{EB9CCC71-30D4-4D32-A7F3-6B5432A619DF}C:\users\admin\appdata\roaming\bittorrent\updates\7.9.5_41713.exe] => (Block) C:\users\admin\appdata\roaming\bittorrent\updates\7.9.5_41713.exe FirewallRules: [UDP Query User{3B2D19C3-950D-4BC3-A974-20A4A34896DE}C:\users\admin\appdata\roaming\bittorrent\updates\7.9.5_41713.exe] => (Block) C:\users\admin\appdata\roaming\bittorrent\updates\7.9.5_41713.exe FirewallRules: [{021D5901-FA7B-4AA5-BD0B-6C359E9B8A2D}] => (Allow) C:\Users\admin\AppData\Roaming\BitTorrent\updates\7.9.5_41713.exe FirewallRules: [{5DC0FCAD-0A60-42A5-B39E-EDB4544059BC}] => (Allow) C:\Users\admin\AppData\Roaming\BitTorrent\updates\7.9.5_41713.exe FirewallRules: [TCP Query User{7E8EABF0-44DE-4A64-BD1E-15436BEEC81A}C:\users\admin\appdata\roaming\bittorrent\updates\7.9.5_41866.exe] => (Block) C:\users\admin\appdata\roaming\bittorrent\updates\7.9.5_41866.exe FirewallRules: [UDP Query User{28F5C1B4-9575-4299-88E2-FECEBFC6E8E3}C:\users\admin\appdata\roaming\bittorrent\updates\7.9.5_41866.exe] => (Block) C:\users\admin\appdata\roaming\bittorrent\updates\7.9.5_41866.exe FirewallRules: [{EAD485FA-B4F6-408A-8DB5-08EF236551BA}] => (Allow) C:\Users\admin\AppData\Roaming\BitTorrent\updates\7.9.5_41713.exe FirewallRules: [{CB4A7B37-54B7-47AB-9B0C-CEE763110001}] => (Allow) C:\Users\admin\AppData\Roaming\BitTorrent\updates\7.9.5_41713.exe FirewallRules: [{DA3B0383-CD8F-477F-89F1-88A871CAEC38}] => (Allow) C:\Users\admin\AppData\Roaming\BitTorrent\updates\7.9.5_41713.exe FirewallRules: [{3B9992A0-C530-4BB2-A1C8-7F90A44D4281}] => (Allow) C:\Users\admin\AppData\Roaming\BitTorrent\updates\7.9.5_41713.exe FirewallRules: [TCP Query User{E82D9737-447E-45D5-A581-ADCBAA1259AE}C:\users\admin\appdata\local\temp\temp2_u.zip\u1504.exe] => (Allow) C:\users\admin\appdata\local\temp\temp2_u.zip\u1504.exe FirewallRules: [UDP Query User{37A4A774-46C8-4CC5-8E26-98C86989899B}C:\users\admin\appdata\local\temp\temp2_u.zip\u1504.exe] => (Allow) C:\users\admin\appdata\local\temp\temp2_u.zip\u1504.exe FirewallRules: [TCP Query User{C5C9E84A-0846-4ABA-AEDD-17FF58F9FBA9}C:\users\admin\desktop\u1504.exe] => (Allow) C:\users\admin\desktop\u1504.exe FirewallRules: [UDP Query User{D99A8C58-832C-4E40-BF4E-F80161780F4C}C:\users\admin\desktop\u1504.exe] => (Allow) C:\users\admin\desktop\u1504.exe FirewallRules: [TCP Query User{3E208042-7CC4-4C3B-9C4F-F38C423A3CDD}C:\program files (x86)\kodi\kodi.exe] => (Allow) C:\program files (x86)\kodi\kodi.exe FirewallRules: [UDP Query User{8FDDF88C-0C1B-4FBB-A5DF-3912C0DFF9BE}C:\program files (x86)\kodi\kodi.exe] => (Allow) C:\program files (x86)\kodi\kodi.exe FirewallRules: [TCP Query User{B69278D0-BAAF-4D01-B748-BCA9B20A4627}C:\users\admin\appdata\roaming\bittorrent\updates\7.9.6_42095.exe] => (Allow) C:\users\admin\appdata\roaming\bittorrent\updates\7.9.6_42095.exe FirewallRules: [UDP Query User{90C1C6F7-8E18-4CB9-B168-F6FC71700F52}C:\users\admin\appdata\roaming\bittorrent\updates\7.9.6_42095.exe] => (Allow) C:\users\admin\appdata\roaming\bittorrent\updates\7.9.6_42095.exe FirewallRules: [{A5919993-B357-4D8B-BF72-0065176EA87E}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe FirewallRules: [{6BD64261-4537-4180-9188-8D52D25766AE}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{A6784AE0-0758-4B7D-A0CC-DF3F9533C4E6}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{B4E7D1B2-64A5-42DD-8E2D-5833C3369F69}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{9FDA8C43-2359-4D21-B179-C7DE8809DAD2}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{B1BFA0A3-955D-45B3-BD5E-78CBC2A16104}] => (Allow) C:\Program Files\iTunes\iTunes.exe FirewallRules: [{4CE9640C-5ECF-4AED-A387-3BC442906E52}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe ==================== Restore Points ========================= 15-05-2016 10:21:23 Windows Update 27-05-2016 08:19:57 Scheduled Checkpoint ==================== Faulty Device Manager Devices ============= Name: Base System Device Description: Base System Device Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (06/06/2016 05:53:11 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 5344 Error: (06/06/2016 05:53:11 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 5344 Error: (06/06/2016 05:53:11 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (06/06/2016 05:13:02 PM) (Source: COM) (EventID: 10031) (User: ) Description: {CDC82860-468D-4D4E-B7E7-C298FF23AB2C} Error: (06/06/2016 05:13:02 PM) (Source: COM) (EventID: 10031) (User: ) Description: {CDC82860-468D-4D4E-B7E7-C298FF23AB2C} Error: (06/06/2016 04:43:31 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: CHRISTHOMAS) Description: Activation of app Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy!App failed with error: -2144927142 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (06/06/2016 04:43:31 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: CHRISTHOMAS) Description: Activation of app Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy!App failed with error: -2147023170 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (06/06/2016 04:43:25 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: CHRISTHOMAS) Description: Activation of app Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy!App failed with error: -2144927142 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (06/06/2016 03:52:35 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 6141 Error: (06/06/2016 03:52:35 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 6141 System errors: ============= Error: (06/06/2016 03:27:53 PM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY) Description: {B91D5831-B1BD-4608-8198-D72E155020F7} Error: (06/06/2016 03:25:53 PM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY) Description: {B91D5831-B1BD-4608-8198-D72E155020F7} Error: (06/06/2016 06:48:21 AM) (Source: DCOM) (EventID: 10010) (User: CHRISTHOMAS) Description: App.AppXy9rh3t8m2jfpvhhxp6y2ksgeq77vymbq.mca Error: (06/05/2016 07:54:45 AM) (Source: WudfUsbccidDriver) (EventID: 1) (User: NT AUTHORITY) Description: ScReadWrite: Failed to write request.-8053063540xa0x00x00x0 Error: (06/04/2016 11:23:48 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The uagqecsvc service failed to start due to the following error: %%1053 Error: (06/04/2016 11:23:48 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: A timeout was reached (30000 milliseconds) while waiting for the uagqecsvc service to connect. Error: (06/04/2016 11:23:47 AM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The NetTcpActivator service depends on the NetTcpPortSharing service which failed to start because of the following error: %%1058 Error: (06/04/2016 11:22:05 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: A timeout was reached (30000 milliseconds) while waiting for the Sync Host_45136 service to connect. Error: (06/04/2016 11:22:05 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: A timeout was reached (30000 milliseconds) while waiting for the User Data Storage_45136 service to connect. Error: (06/04/2016 11:21:55 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The User Data Access_45136 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service. CodeIntegrity: =================================== Date: 2016-06-06 17:05:52.190 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-06-06 17:05:51.965 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-06-06 17:05:50.641 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-06-06 17:05:50.492 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-06-06 17:05:50.186 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-06-06 15:46:52.462 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-06-06 15:46:50.640 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-06-06 15:46:48.953 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-06-06 15:46:48.561 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-06-06 15:46:47.431 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i7-2620M CPU @ 2.70GHz Percentage of memory in use: 72% Total physical RAM: 4046.35 MB Available physical RAM: 1131.55 MB Total Virtual: 8142.35 MB Available Virtual: 3840.86 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:297.5 GB) (Free:166.54 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: 6A6731BE) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=297.5 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=507 MB) - (Type=27) ==================== End of Addition.txt ============================