Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02-07-2016 Ran by [removed] (2016-07-04 18:17:04) Running from C:\Users\[removed]\Downloads Windows 10 Home Version 1511 (X64) (2016-06-02 12:58:52) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-1000113554-1559343911-2160561676-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-1000113554-1559343911-2160561676-503 - Limited - Disabled) Guest (S-1-5-21-1000113554-1559343911-2160561676-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-1000113554-1559343911-2160561676-1004 - Limited - Enabled) Jacob (S-1-5-21-1000113554-1559343911-2160561676-1001 - Administrator - Enabled) => C:\Users\Jacob ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Spybot - Search and Destroy (Enabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 80 Days (HKLM\...\Steam App 381780) (Version: - inkle Ltd) Amnesia: The Dark Descent (HKLM\...\Steam App 57300) (Version: - Frictional Games) And Yet It Moves (HKLM\...\Steam App 18700) (Version: - Broken Rules) Aquaria (HKLM\...\Steam App 24420) (Version: - Bit Blot, LLC) Arduino (HKLM-x32\...\Arduino) (Version: 1.6.9 - Arduino LLC) ASUS Live Update (HKLM-x32\...\{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}) (Version: 3.4.1 - ASUS) ASUS Smart Gesture (HKLM-x32\...\{4D3286A6-F6AB-498A-82A4-E4F040529F3D}) (Version: 4.0.9 - ASUS) ASUS Splendid Video Enhancement Technology (HKLM-x32\...\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 3.13.0004 - ASUS) ASUS USB Charger Plus (HKLM-x32\...\{A859E3E5-C62F-4BFA-AF1D-2B95E03166AF}) (Version: 4.1.6 - ASUS) ATK Package (HKLM-x32\...\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0040 - ASUS) Atom Zombie Smasher (HKLM\...\Steam App 55040) (Version: - Blendo Games) AudioWizard (HKLM-x32\...\{57E770A2-2BAF-4CAA-BAA3-BD896E2254D3}) (Version: 1.0.0.101 - ICEpower a/s) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Braid (HKLM\...\Steam App 26800) (Version: - Number None) Broken Age (HKLM\...\Steam App 232790) (Version: - Double Fine Productions) CDisplayEx 1.10.29 (HKLM\...\CDisplayEx_is1) (Version: - Progdigy Software S.A.R.L.) Cibele (HKLM\...\Steam App 408120) (Version: - Star Maid Games) Cogs (HKLM\...\Steam App 26500) (Version: - Lazy 8 Studios) Cortex Command (HKLM\...\Steam App 209670) (Version: - Data Realms) Crayon Physics Deluxe (HKLM\...\Steam App 26900) (Version: - Kloonigames) CyberLink PhotoDirector 5 (HKLM-x32\...\InstallShield_{5A454EC5-217A-42a5-8CE1-2DDEC4E70E01}) (Version: 5.0.5.6515 - CyberLink Corp.) CyberLink PhotoDirector 5 (Version: 5.0.5.6515 - CyberLink Corp.) Hidden CyberLink PowerDirector 12 (HKLM-x32\...\InstallShield_{E1646825-D391-42A0-93AA-27FA810DA093}) (Version: 12.0.4010.0 - CyberLink Corp.) CyberLink PowerDirector 12 (Version: 12.0.4010.0 - CyberLink Corp.) Hidden Device Setup (HKLM-x32\...\{8D6B05E0-F457-408C-9D13-549334D8FAE1}) (Version: 2.0.2 - ASUSTek Computer Inc.) DiskInternals Linux Reader (HKLM-x32\...\DiskInternals Linux Reader) (Version: 2.3.0.3 - DiskInternals Research) Dropbox (HKLM-x32\...\Dropbox) (Version: 5.4.24 - Dropbox, Inc.) Dropbox 25 GB (HKLM-x32\...\{597A58EC-42D6-4940-8739-FB94491B013C}) (Version: 1.0.8.0 - Dropbox, Inc.) Dropbox Update Helper (x32 Version: 1.3.43.1 - Dropbox, Inc.) Hidden EitherMouse 0.64 (HKLM-x32\...\EitherMouse) (Version: 0.64 - Steffen Software) Evernote v. 5.8.6 (HKLM-x32\...\{FEDC7C10-EF67-11E4-9B07-00505695D7B0}) (Version: 5.8.6.7519 - Evernote Corp.) f.lux (HKU\S-1-5-21-1000113554-1559343911-2160561676-1001\...\Flux) (Version: - ) Foxit Reader (HKLM-x32\...\Foxit Reader_is1) (Version: 7.3.4.311 - Foxit Software Inc.) Gish (HKLM\...\Steam App 9500) (Version: - Cryptic Sea) Hammerfight (HKLM\...\Steam App 41100) (Version: - Konstantin Koshutin) Her Story (HKLM\...\Steam App 368370) (Version: - Sam Barlow) Intel(R) Chipset Device Software (x32 Version: 10.1.1.9 - Intel(R) Corporation) Hidden Intel(R) Driver Update Utility 2.5 (x32 Version: 2.5.0.22 - Intel) Hidden Intel(R) Dynamic Platform and Thermal Framework (HKLM-x32\...\{654EE65D-FAA4-4EA6-8C07-DC94E6A304D4}) (Version: 8.1.10603.192 - Intel Corporation) Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.0.0.1162 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 20.19.15.4463 - Intel Corporation) Intel(R) Product Improvement Program (x32 Version: 2.1.27.3 - Intel) Hidden Intel(R) Serial IO (HKLM\...\{9FD91C5C-44AE-4D9D-85BE-AE52816B0294}) (Version: 30.100.1519.7 - Intel Corporation) Intel(R) Wireless Bluetooth(R) (HKLM-x32\...\{64FD4757-7186-4F12-9AA8-5EE809CAB282}) (Version: 17.1.1532.1814 - Intel Corporation) Intel® Driver Update Utility (HKLM-x32\...\{aa1dec3b-dc4b-4db0-8c18-9157457eff1f}) (Version: 2.5.0.22 - Intel) Intel® PROSet/Wireless Software (HKLM-x32\...\{d5572863-793c-4ec8-872a-43cccc68b948}) (Version: 18.40.0 - Intel Corporation) Intel® Security Assist (HKLM-x32\...\{4B230374-6475-4A73-BA6E-41015E9C5013}) (Version: 1.0.0.532 - Intel Corporation) Intel® Watchdog Timer Driver (Intel® WDT) (HKLM-x32\...\{3FD0C489-0F02-481a-A3E1-9754CD396761}) (Version: - Intel Corporation) Intel® Watchdog Timer Driver (Intel® WDT) (HKLM-x32\...\3FD0C489-0F02-481a-A3E1-9754CD396761) (Version: - Intel Corporation) LIMBO (HKLM\...\Steam App 48000) (Version: - Playdead) Lone Survivor: The Director's Cut (HKLM\...\Steam App 209830) (Version: - Jasper Byrne) Lugaru HD (HKLM\...\Steam App 25010) (Version: - Wolfire Games) Microsoft Office 2003 Web Components (HKLM-x32\...\{90120000-00A4-0409-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation) Microsoft Office 365 - en-us (HKLM\...\O365HomePremRetail - en-us) (Version: 16.0.6965.2058 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23918 (HKLM-x32\...\{dab68466-3a7d-41a8-a5cf-415e3ff8ef71}) (Version: 14.0.23918.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23918 (HKLM-x32\...\{2e085fd2-a3e4-4b39-8e10-6b8d35f55244}) (Version: 14.0.23918.0 - Microsoft Corporation) Microsoft Visual Studio 2005 Remote Debugger Light (x64) - ENU (HKLM\...\Microsoft Visual Studio 2005 Remote Debugger Light (x64) - ENU) (Version: - Microsoft Corporation) Mozilla Firefox 47.0 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 47.0 (x86 en-US)) (Version: 47.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 47.0.0.5999 - Mozilla) MPC-HC 1.7.10 (64-bit) (HKLM\...\{2ACBF1FA-F5C3-4B19-A774-B22A31F231B9}_is1) (Version: 1.7.10 - MPC-HC Team) NVIDIA GeForce Experience 2.11.4.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.11.4.0 - NVIDIA Corporation) NVIDIA Graphics Driver 368.39 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 368.39 - NVIDIA Corporation) NVIDIA PhysX System Software 9.16.0318 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.16.0318 - NVIDIA Corporation) Office 16 Click-to-Run Extensibility Component (x32 Version: 16.0.6925.1018 - Microsoft Corporation) Hidden Office 16 Click-to-Run Licensing Component (Version: 16.0.6925.1018 - Microsoft Corporation) Hidden Office 16 Click-to-Run Localization Component (x32 Version: 16.0.6925.1018 - Microsoft Corporation) Hidden OpenAL (HKLM-x32\...\OpenAL) (Version: - ) Penumbra: Overture (HKLM\...\Steam App 22180) (Version: - Frictional Games) Portal (HKLM\...\Steam App 400) (Version: - Valve) Psychonauts (HKLM\...\Steam App 3830) (Version: - Double Fine Productions) Read Only Memories (HKLM\...\Steam App 330820) (Version: - MidBoss, LLC.) Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.10143.21278 - Realtek Semiconductor Corp.) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.2.703.2015 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7599 - Realtek Semiconductor Corp.) ROG Game First III (HKLM-x32\...\{0C6E32E1-31D9-49F1-B67F-2941994002D5}) (Version: 1.00.27 - ASUSTeK Computer Inc.) ROG Gaming Center (HKLM-x32\...\{CC182DBF-FC67-4F79-9930-6A2682E60BDD}) (Version: 1.0.1 - ASUS) Samorost 2 (HKLM\...\Steam App 40720) (Version: - Amanita Design) Samorost 3 (HKLM\...\Steam App 421120) (Version: - Amanita Design) SHIELD Streaming (Version: 7.1.0280 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: 2.11.4.0 - NVIDIA Corporation) Hidden SolidWorks 2014 x64 Edition SP03 (HKLM-x32\...\SolidWorks Installation Manager 20140-40300-1100-100) (Version: 22.3.0.56 - SolidWorks Corporation) SolidWorks 2014 x64 Edition SP03 (Version: 22.130.56 - SolidWorks) Hidden SolidWorks Composer Player 2014 SP03 x64 Edition (Version: 22.30.56 - Dassault Systemes SolidWorks) Hidden SolidWorks eDrawings 2014 x64 Edition SP03 (Version: 14.3.107 - Dassault Systèmes SolidWorks Corp) Hidden SolidWorks Explorer 2014 SP03 x64 Edition (Version: 22.30.56 - SolidWorks Corporation) Hidden SolidWorks Plastics 2014 SP03 x64 Edition (Version: 22.30.56 - SolidWorks Corporation) Hidden Sorcery! Parts 1 & 2 (HKLM\...\Steam App 411000) (Version: - inkle Ltd) Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.4.40 - Safer-Networking Ltd.) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) Steel Storm: Burning Retribution (HKLM\...\Steam App 96200) (Version: - Kot in Action Creative Artel) Super Meat Boy (HKLM\...\Steam App 40800) (Version: - Team Meat) Superbrothers: Sword & Sworcery EP (HKLM\...\Steam App 204060) (Version: - Capybara) VMware Workstation (HKLM\...\{4B855F64-CB51-4FC3-935F-5AF7D3372BDE}) (Version: 12.0.1 - VMware, Inc.) Vulkan Run Time Libraries 1.0.11.1 (HKLM\...\VulkanRT1.0.11.1) (Version: 1.0.11.1 - LunarG, Inc.) VVVVVV (HKLM\...\Steam App 70300) (Version: - Terry Cavanagh) WebStorage (HKLM-x32\...\WebStorage) (Version: 2.2.8.559 - ASUS Cloud Corporation) Windows Driver Package - ASUS (AsusSGDrv) Mouse (08/06/2015 8.0.0.19) (HKLM\...\149F37A1996406108DA0EB71D7EBC48895119059) (Version: 08/06/2015 8.0.0.19 - ASUS) WinFlash (HKLM-x32\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 3.0.1 - ASUS) WinRAR 5.20 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.20.0 - win.rar GmbH) WinSCP 5.7.7 (HKLM-x32\...\winscp3_is1) (Version: 5.7.7 - Martin Prikryl) WinWget version 0.20 beta (HKLM-x32\...\WinWget_is1) (Version: 0.20 - WinWget Team) World of Goo (HKLM\...\Steam App 22000) (Version: - 2D BOY) XSplit Gamecaster (HKLM-x32\...\{0E12BEC0-F2EE-43FA-AEA0-24B5E9F80167}) (Version: 2.5.1507.3011 - SplitmediaLabs) Zaccaria Pinball (HKLM\...\Steam App 444930) (Version: - Magic Pixel Kft.) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-1000113554-1559343911-2160561676-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Jacob\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_1\FileCoAuth.exe (Microsoft Corporation) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {00876D94-79B2-4059-9E8E-FC0818FC06CD} - System32\Tasks\ASUS\ASUS Product Register Service => C:\Program Files (x86)\ASUS\APRP\aprp.exe [2015-05-15] (ASUSTek Computer Inc.) Task: {08DD0904-43E7-4A62-851C-1E10B1F0B066} - System32\Tasks\ASUS Splendid ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2015-08-26] (ASUS) Task: {10248DA9-AE45-4D49-9CA0-DE671CBCFCAF} - System32\Tasks\ASUS Live Update2 => C:\Program Files (x86)\ASUS\ASUS Live Update\UpdateChecker.exe [2016-06-03] () Task: {1A4765AD-4610-4F71-B6ED-992F88728E9E} - System32\Tasks\ROG Gaming Center => C:\Program Files (x86)\ASUS\ROG Gaming Center\ROGGamingKey.exe [2015-08-13] (ASUSTek Computer Inc.) Task: {1B343378-2ECC-4830-A3C6-154D2E574A6B} - System32\Tasks\Intel\Intel Telemetry 2 => C:\Program Files\Intel\Telemetry 2.0\lrio.exe [2015-06-05] (Intel Corporation) Task: {249CB101-837F-4913-897D-5E2A7467A444} - System32\Tasks\ATK Package 36D18D69AFC3 => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SimAppExec.exe [2015-03-11] (ASUSTek Computer Inc.) Task: {298A4C21-DE92-4438-A5D2-8B43C67B5095} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2015-09-03] (Realtek Semiconductor) Task: {3527C467-B677-44B3-8BF8-0C68DEEE4593} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe [2016-03-21] (Safer-Networking Ltd.) Task: {3ACB3852-449F-45C1-935E-99A320DA52D1} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2016-06-10] (Microsoft Corporation) Task: {3CBD6324-5812-46AE-86C0-90DD712A6815} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2016-06-11] (Microsoft Corporation) Task: {4B100C36-F2E1-4156-B567-EF8C9FCF89F7} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2016-06-10] (Microsoft Corporation) Task: {5951DFD1-C8F9-497E-9390-F648DA51A4EA} - System32\Tasks\RtHDVBg_ListenToDevice => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2015-09-03] (Realtek Semiconductor) Task: {6D65893C-62BA-47B7-A307-36FBD05281E0} - System32\Tasks\USER_ESRV_SVC_WILLAMETTE => Wscript.exe //B //NoLogo "C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\task.vbs" Task: {96DBF111-AB4D-4A89-8859-15D8DC7022E6} - System32\Tasks\ASUS USB Charger Plus => C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [2015-05-26] (ASUSTek Computer Inc.) Task: {9CF72F14-2B73-414E-B313-5092E9E2A6A2} - System32\Tasks\ASUS Smart Gesture Launcher => C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLauncher.exe [2015-08-18] (AsusTek) Task: {AD3F2BE5-66AA-486A-AE73-1AE3CBFBDD54} - System32\Tasks\ASUS Live Update1 => C:\Program Files (x86)\ASUS\ASUS Live Update\UpdateChecker.exe [2016-06-03] () Task: {ADEAA690-A594-48E8-AD74-D0117110C6E5} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe [2016-03-21] (Safer-Networking Ltd.) Task: {BA766FB0-83D0-4CAD-9908-326EFF744DF3} - System32\Tasks\Intel\Intel Telemetry 2 (x86) => C:\Program Files (x86)\Intel\Telemetry 2.0\lrio.exe [2016-03-17] (Intel Corporation) Task: {BB3F02A9-B320-487D-ACD5-94828AB46621} - System32\Tasks\Update Checker => C:\Program Files (x86)\ASUS\ASUS Live Update\UpdateChecker.exe [2016-06-03] () Task: {BE5C4A16-EA43-47A9-B395-F3F90A960D5E} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe [2014-06-27] (Safer-Networking Ltd.) Task: {C8D22562-8839-49FE-ABA7-B8B12964880E} - System32\Tasks\ATK Package A22126881260 => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SimAppExec.exe [2015-03-11] (ASUSTek Computer Inc.) Task: {D600C82A-4433-4357-819A-342D6C3C7BF2} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-06-02] (Dropbox, Inc.) Task: {DF73588D-4584-487E-8FFD-0134127B8EEC} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-06-02] (Dropbox, Inc.) Task: {E9AD3EFA-E520-40BC-8BF3-E0A5CD989E2F} - System32\Tasks\DropboxOEM => C:\Program Files (x86)\Dropbox\DropboxOEM\DropboxOEM.exe [2015-05-30] () Task: {FECEF549-4C32-465A-BBC0-DED2477A0C3C} - System32\Tasks\{10DF89F9-96D3-4335-A085-74D59C6064D6} => pcalua.exe -a "C:\Program Files (x86)\Spybot - Search & Destroy 2\unins000.exe" (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) Shortcut: C:\Users\Jacob\Desktop\DiskInternals Research.lnk -> hxxp://www.diskinternals.com/go/ (No File) Shortcut: C:\Users\Jacob\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DiskInternals\Linux Reader\DiskInternals Research.lnk -> hxxp://www.diskinternals.com/go/ (No File) ==================== Loaded Modules (Whitelisted) ============== 2015-10-30 17:17 - 2015-10-30 17:17 - 00028672 _____ () C:\WINDOWS\SYSTEM32\efsext.dll 2015-10-30 17:18 - 2015-10-30 17:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll 2015-11-29 17:53 - 2014-04-15 12:59 - 00389896 _____ () C:\Program Files\CyberLink\Shared files\RichVideo64.exe 2016-06-03 16:24 - 2016-06-03 16:24 - 02656952 _____ () C:\WINDOWS\system32\CoreUIComponents.dll 2016-06-15 11:42 - 2016-05-28 13:53 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2016-06-15 11:43 - 2016-05-28 13:54 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll 2016-06-03 16:24 - 2016-06-03 16:24 - 02656952 _____ () C:\WINDOWS\System32\CoreUIComponents.dll 2016-06-02 23:08 - 2016-06-02 23:08 - 00959168 _____ () C:\Users\Jacob\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_1\amd64\ClientTelemetry.dll 2016-04-27 16:10 - 2016-04-27 16:10 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll 2016-06-03 16:24 - 2016-06-03 16:24 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll 2016-06-15 11:43 - 2016-05-28 13:59 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2016-06-15 11:43 - 2016-05-28 13:55 - 00936960 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll 2016-06-15 11:43 - 2016-05-28 13:56 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll 2016-06-15 11:43 - 2016-05-28 13:53 - 00529408 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.NodeWinrtWrap.dll 2015-10-30 17:18 - 2016-04-27 16:20 - 00037888 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\dss_service\node_modules\winrt-projections\bin\Winrt_Projections.node 2015-10-30 17:18 - 2016-04-27 16:19 - 00796160 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\dss_service\node_modules\windows.web.http\bin\NodeRT_Windows_Web_Http.node 2015-10-30 17:18 - 2016-04-27 16:20 - 00961024 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\dss_service\node_modules\windows.web.http.headers\bin\NodeRT_Windows_Web_Http_Headers.node 2015-10-30 17:18 - 2016-04-27 16:19 - 00206336 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\dss_service\node_modules\windows.web.http.filters\bin\NodeRT_Windows_Web_Http_Filters.node 2015-10-30 17:18 - 2016-04-27 16:19 - 00558592 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\dss_service\node_modules\windows.storage.streams\bin\NodeRT_Windows_Storage_Streams.node 2015-10-30 17:18 - 2016-04-27 16:20 - 00397824 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\dss_service\node_modules\windows.foundation\bin\NodeRT_Windows_Foundation.node 2015-10-30 17:18 - 2016-04-27 16:19 - 00181248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\dss_service\node_modules\nodert-buffer-utils\bin\NodeRT_Buffer_Utils.node 2015-10-30 17:18 - 2016-04-27 16:19 - 00093696 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\dss_service\node_modules\windows.security.cryptography\bin\NodeRT_Windows_Security_Cryptography.node 2015-10-30 17:18 - 2016-04-27 16:19 - 00200192 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\dss_service\node_modules\windows.cortana.pal\bin\NodeRT_Windows_Cortana_PAL.node 2015-09-10 17:42 - 2016-06-17 00:23 - 00384496 _____ () C:\WINDOWS\system32\igfxTray.exe 2016-06-19 21:38 - 2016-06-19 21:38 - 01560576 _____ () C:\Program Files (x86)\EitherMouse\EitherMouse.exe 2016-05-04 15:23 - 2016-05-04 15:23 - 01382368 _____ () C:\Program Files (x86)\ASUS\WebStorage\2.2.8.559\AsusWSService.exe 2016-06-03 08:16 - 2016-06-03 08:18 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe 2016-06-05 11:03 - 2014-05-13 12:04 - 00109400 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl 2016-06-05 11:03 - 2014-05-13 12:04 - 00167768 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl 2016-06-05 11:03 - 2014-05-13 12:04 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl 2016-06-05 11:03 - 2012-08-23 10:38 - 00574840 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll 2015-10-18 18:32 - 2015-10-18 18:32 - 01301696 _____ () C:\Program Files (x86)\VMware\VMware Workstation\libxml2.dll 2016-06-02 23:08 - 2016-06-02 23:08 - 00679624 _____ () C:\Users\Jacob\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_1\ClientTelemetry.dll 2015-11-29 17:21 - 2016-06-15 06:03 - 00018880 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll 2016-06-22 18:38 - 2016-04-30 06:10 - 00785920 _____ () C:\Program Files (x86)\Steam\SDL2.dll 2016-06-22 18:38 - 2015-07-04 02:12 - 04962816 _____ () C:\Program Files (x86)\Steam\v8.dll 2016-06-22 18:38 - 2016-06-15 10:47 - 02387024 _____ () C:\Program Files (x86)\Steam\video.dll 2016-06-22 18:38 - 2015-07-04 02:12 - 01556992 _____ () C:\Program Files (x86)\Steam\icui18n.dll 2016-06-22 18:38 - 2015-07-04 02:12 - 01187840 _____ () C:\Program Files (x86)\Steam\icuuc.dll 2016-06-22 18:38 - 2016-02-09 09:14 - 02549760 _____ () C:\Program Files (x86)\Steam\libavcodec-56.dll 2016-06-22 18:38 - 2016-02-09 09:14 - 00491008 _____ () C:\Program Files (x86)\Steam\libavformat-56.dll 2016-06-22 18:38 - 2016-02-09 09:14 - 00332800 _____ () C:\Program Files (x86)\Steam\libavresample-2.dll 2016-06-22 18:38 - 2016-02-09 09:14 - 00442880 _____ () C:\Program Files (x86)\Steam\libavutil-54.dll 2016-06-22 18:38 - 2016-02-09 09:14 - 00485888 _____ () C:\Program Files (x86)\Steam\libswscale-3.dll 2016-06-22 18:38 - 2016-06-15 10:47 - 00829008 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL 2016-06-22 18:38 - 2016-02-18 08:25 - 00281088 _____ () C:\Program Files (x86)\Steam\openvr_api.dll 2016-06-02 16:00 - 2016-05-26 03:03 - 00034768 _____ () C:\Program Files (x86)\Dropbox\Client\_multiprocessing.pyd 2016-06-25 07:22 - 2016-05-26 03:03 - 00134088 _____ () C:\Program Files (x86)\Dropbox\Client\pyexpat.pyd 2016-06-25 07:22 - 2016-05-26 03:04 - 00019408 _____ () C:\Program Files (x86)\Dropbox\Client\faulthandler.pyd 2016-06-25 07:22 - 2016-05-26 03:03 - 00116688 _____ () C:\Program Files (x86)\Dropbox\Client\pywintypes27.dll 2016-06-02 16:00 - 2016-05-26 03:03 - 00093640 _____ () C:\Program Files (x86)\Dropbox\Client\_ctypes.pyd 2016-06-02 16:00 - 2016-05-26 03:03 - 00018376 _____ () C:\Program Files (x86)\Dropbox\Client\select.pyd 2016-06-02 16:00 - 2016-06-14 06:13 - 00019760 _____ () C:\Program Files (x86)\Dropbox\Client\tornado.speedups.pyd 2016-06-02 16:00 - 2016-05-26 03:05 - 00105928 _____ () C:\Program Files (x86)\Dropbox\Client\win32api.pyd 2016-06-25 07:22 - 2016-05-26 03:03 - 00392144 _____ () C:\Program Files (x86)\Dropbox\Client\pythoncom27.dll 2016-06-02 16:00 - 2016-06-14 06:13 - 00381752 _____ () C:\Program Files (x86)\Dropbox\Client\win32com.shell.shell.pyd 2016-06-02 16:00 - 2016-05-26 03:03 - 00692688 _____ () C:\Program Files (x86)\Dropbox\Client\unicodedata.pyd 2016-06-25 07:22 - 2016-06-14 06:13 - 00020816 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._constant_time.pyd 2016-06-02 16:00 - 2016-05-26 03:04 - 00123856 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_backend.pyd 2016-06-25 07:22 - 2016-06-14 06:13 - 01682760 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._openssl.pyd 2016-06-25 07:22 - 2016-06-14 06:13 - 00020808 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._padding.pyd 2016-06-02 16:00 - 2016-06-14 06:13 - 00021840 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_unicode_environ_win32_x8bf8e68bx9968e850.pyd 2016-06-25 07:22 - 2016-06-14 06:13 - 00052024 _____ () C:\Program Files (x86)\Dropbox\Client\psutil._psutil_windows.pyd 2016-06-25 07:22 - 2016-06-14 06:13 - 00038696 _____ () C:\Program Files (x86)\Dropbox\Client\fastpath.pyd 2016-06-25 07:22 - 2016-05-26 03:05 - 00020936 _____ () C:\Program Files (x86)\Dropbox\Client\mmapfile.pyd 2016-06-02 16:00 - 2016-05-26 03:05 - 00024528 _____ () C:\Program Files (x86)\Dropbox\Client\win32event.pyd 2016-06-02 16:00 - 2016-05-26 03:05 - 00114640 _____ () C:\Program Files (x86)\Dropbox\Client\win32security.pyd 2016-06-02 16:00 - 2016-05-26 03:05 - 00124880 _____ () C:\Program Files (x86)\Dropbox\Client\win32file.pyd 2016-06-02 16:00 - 2016-06-14 06:13 - 00021832 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_pywin_kernel32_x64d8f881xc8c369be.pyd 2016-06-02 16:00 - 2016-05-26 03:05 - 00024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32clipboard.pyd 2016-06-02 16:00 - 2016-05-26 03:05 - 00175560 _____ () C:\Program Files (x86)\Dropbox\Client\win32gui.pyd 2016-06-02 16:00 - 2016-05-26 03:05 - 00030160 _____ () C:\Program Files (x86)\Dropbox\Client\win32pipe.pyd 2016-06-02 16:00 - 2016-05-26 03:05 - 00043472 _____ () C:\Program Files (x86)\Dropbox\Client\win32process.pyd 2016-06-02 16:00 - 2016-05-26 03:05 - 00048592 _____ () C:\Program Files (x86)\Dropbox\Client\win32service.pyd 2016-06-02 16:00 - 2016-06-14 06:13 - 00023872 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.kernel32._winffi_kernel32.pyd 2016-06-25 07:22 - 2016-06-14 06:13 - 00026456 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox.infinite.win.compiled._driverinstallation.pyd 2016-06-02 16:00 - 2016-05-26 03:05 - 00057808 _____ () C:\Program Files (x86)\Dropbox\Client\win32evtlog.pyd 2016-06-02 16:00 - 2016-05-26 03:05 - 00024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32profile.pyd 2016-06-25 07:22 - 2016-06-14 06:13 - 00246592 _____ () C:\Program Files (x86)\Dropbox\Client\breakpad.client.windows.handler.pyd 2016-06-02 16:00 - 2016-05-26 03:05 - 00028616 _____ () C:\Program Files (x86)\Dropbox\Client\win32ts.pyd 2016-06-02 16:00 - 2016-06-14 06:13 - 00020800 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.iphlpapi._winffi_iphlpapi.pyd 2016-06-02 16:00 - 2016-06-14 06:13 - 00019776 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winerror._winffi_winerror.pyd 2016-06-02 16:00 - 2016-06-14 06:13 - 00020800 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.wininet._winffi_wininet.pyd 2016-06-02 16:00 - 2016-05-26 03:03 - 00134608 _____ () C:\Program Files (x86)\Dropbox\Client\_elementtree.pyd 2016-06-25 07:22 - 2016-05-26 03:04 - 00240584 _____ () C:\Program Files (x86)\Dropbox\Client\jpegtran.pyd 2016-06-25 07:22 - 2016-06-14 06:13 - 00020280 _____ () C:\Program Files (x86)\Dropbox\Client\cpuid.compiled._cpuid.pyd 2016-06-02 16:00 - 2016-06-14 06:13 - 00023376 _____ () C:\Program Files (x86)\Dropbox\Client\winscreenshot.compiled._CaptureScreenshot.pyd 2016-06-02 16:00 - 2016-05-26 03:05 - 00350152 _____ () C:\Program Files (x86)\Dropbox\Client\winxpgui.pyd 2016-06-02 16:00 - 2016-06-14 06:13 - 00022352 _____ () C:\Program Files (x86)\Dropbox\Client\winverifysignature.compiled._VerifySignature.pyd 2016-06-25 07:22 - 2016-06-14 06:13 - 00024392 _____ () C:\Program Files (x86)\Dropbox\Client\librsyncffi.compiled._librsyncffi.pyd 2016-06-25 07:22 - 2016-05-26 03:05 - 00036296 _____ () C:\Program Files (x86)\Dropbox\Client\librsync.dll 2016-06-25 07:22 - 2016-06-14 06:13 - 00031568 _____ () C:\Program Files (x86)\Dropbox\Client\enterprise_data.compiled._enterprise_data.pyd 2016-06-25 07:22 - 2016-03-12 10:46 - 00293392 _____ () C:\Program Files (x86)\Dropbox\Client\EnterpriseDataAdapter.dll 2016-06-25 07:22 - 2016-06-14 06:13 - 00084280 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_sqlite_ext.DLL 2016-06-25 07:22 - 2016-06-14 06:13 - 01826096 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtCore.pyd 2016-06-02 16:00 - 2016-05-26 03:04 - 00083912 _____ () C:\Program Files (x86)\Dropbox\Client\sip.pyd 2016-06-25 07:22 - 2016-06-14 06:13 - 03928880 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWidgets.pyd 2016-06-25 07:22 - 2016-06-14 06:13 - 01971504 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtGui.pyd 2016-06-25 07:22 - 2016-06-14 06:13 - 00531248 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtNetwork.pyd 2016-06-25 07:22 - 2016-06-14 06:13 - 00132912 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKit.pyd 2016-06-25 07:22 - 2016-06-14 06:13 - 00223544 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKitWidgets.pyd 2016-06-25 07:22 - 2016-06-14 06:13 - 00207672 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtPrintSupport.pyd 2016-06-02 16:00 - 2016-05-26 03:05 - 00060880 _____ () C:\Program Files (x86)\Dropbox\Client\win32print.pyd 2016-06-02 16:00 - 2016-06-14 06:13 - 00025928 _____ () C:\Program Files (x86)\Dropbox\Client\windisplaytoast.compiled._DisplayToast.pyd 2016-06-02 16:00 - 2016-06-14 06:13 - 00024904 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_wpad_proxy_win_x752e3d61xdcfdcc84.pyd 2016-06-25 07:22 - 2016-06-14 06:13 - 00546096 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQuick.pyd 2016-06-25 07:22 - 2016-06-14 06:13 - 00357680 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQml.pyd 2016-06-22 18:38 - 2016-06-15 05:14 - 49826080 _____ () C:\Program Files (x86)\Steam\bin\libcef.dll 2015-08-07 19:09 - 2015-08-07 19:09 - 01243936 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll 2015-08-26 03:40 - 2015-08-26 03:40 - 00027648 _____ () C:\Program Files (x86)\ASUS\Splendid\DetectDisplayDC.dll 2015-08-26 03:40 - 2015-08-26 03:40 - 00124928 _____ () C:\Program Files (x86)\ASUS\Splendid\CCTAdjust.dll 2016-06-03 08:16 - 2016-06-03 08:18 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll 2016-06-03 08:16 - 2016-06-03 08:20 - 22284800 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkyWrap.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service" ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) IE restricted site: HKU\.DEFAULT\...\007guard.com -> install.007guard.com IE restricted site: HKU\.DEFAULT\...\008i.com -> 008i.com IE restricted site: HKU\.DEFAULT\...\008k.com -> www.008k.com IE restricted site: HKU\.DEFAULT\...\00hq.com -> www.00hq.com IE restricted site: HKU\.DEFAULT\...\010402.com -> 010402.com IE restricted site: HKU\.DEFAULT\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com IE restricted site: HKU\.DEFAULT\...\0scan.com -> www.0scan.com IE restricted site: HKU\.DEFAULT\...\1-2005-search.com -> www.1-2005-search.com IE restricted site: HKU\.DEFAULT\...\1-domains-registrations.com -> www.1-domains-registrations.com IE restricted site: HKU\.DEFAULT\...\1000gratisproben.com -> www.1000gratisproben.com IE restricted site: HKU\.DEFAULT\...\1001namen.com -> www.1001namen.com IE restricted site: HKU\.DEFAULT\...\100888290cs.com -> mir.100888290cs.com IE restricted site: HKU\.DEFAULT\...\100sexlinks.com -> www.100sexlinks.com IE restricted site: HKU\.DEFAULT\...\10sek.com -> www.10sek.com IE restricted site: HKU\.DEFAULT\...\12-26.net -> user1.12-26.net IE restricted site: HKU\.DEFAULT\...\12-27.net -> user1.12-27.net IE restricted site: HKU\.DEFAULT\...\123fporn.info -> www.123fporn.info IE restricted site: HKU\.DEFAULT\...\123haustiereundmehr.com -> www.123haustiereundmehr.com IE restricted site: HKU\.DEFAULT\...\123moviedownload.com -> www.123moviedownload.com IE restricted site: HKU\.DEFAULT\...\123simsen.com -> www.123simsen.com There are 7908 more sites. IE restricted site: HKU\S-1-5-21-1000113554-1559343911-2160561676-1001\...\007guard.com -> install.007guard.com IE restricted site: HKU\S-1-5-21-1000113554-1559343911-2160561676-1001\...\008i.com -> 008i.com IE restricted site: HKU\S-1-5-21-1000113554-1559343911-2160561676-1001\...\008k.com -> www.008k.com IE restricted site: HKU\S-1-5-21-1000113554-1559343911-2160561676-1001\...\00hq.com -> www.00hq.com IE restricted site: HKU\S-1-5-21-1000113554-1559343911-2160561676-1001\...\010402.com -> 010402.com IE restricted site: HKU\S-1-5-21-1000113554-1559343911-2160561676-1001\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com IE restricted site: HKU\S-1-5-21-1000113554-1559343911-2160561676-1001\...\0scan.com -> www.0scan.com IE restricted site: HKU\S-1-5-21-1000113554-1559343911-2160561676-1001\...\1-2005-search.com -> www.1-2005-search.com IE restricted site: HKU\S-1-5-21-1000113554-1559343911-2160561676-1001\...\1-domains-registrations.com -> www.1-domains-registrations.com IE restricted site: HKU\S-1-5-21-1000113554-1559343911-2160561676-1001\...\1000gratisproben.com -> www.1000gratisproben.com IE restricted site: HKU\S-1-5-21-1000113554-1559343911-2160561676-1001\...\1001namen.com -> www.1001namen.com IE restricted site: HKU\S-1-5-21-1000113554-1559343911-2160561676-1001\...\100888290cs.com -> mir.100888290cs.com IE restricted site: HKU\S-1-5-21-1000113554-1559343911-2160561676-1001\...\100sexlinks.com -> www.100sexlinks.com IE restricted site: HKU\S-1-5-21-1000113554-1559343911-2160561676-1001\...\10sek.com -> www.10sek.com IE restricted site: HKU\S-1-5-21-1000113554-1559343911-2160561676-1001\...\12-26.net -> user1.12-26.net IE restricted site: HKU\S-1-5-21-1000113554-1559343911-2160561676-1001\...\12-27.net -> user1.12-27.net IE restricted site: HKU\S-1-5-21-1000113554-1559343911-2160561676-1001\...\123fporn.info -> www.123fporn.info IE restricted site: HKU\S-1-5-21-1000113554-1559343911-2160561676-1001\...\123haustiereundmehr.com -> www.123haustiereundmehr.com IE restricted site: HKU\S-1-5-21-1000113554-1559343911-2160561676-1001\...\123moviedownload.com -> www.123moviedownload.com IE restricted site: HKU\S-1-5-21-1000113554-1559343911-2160561676-1001\...\123simsen.com -> www.123simsen.com There are 7908 more sites. ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2015-07-10 21:04 - 2016-07-01 20:25 - 00452958 ____R C:\WINDOWS\system32\Drivers\etc\hosts 127.0.0.1 www.007guard.com 127.0.0.1 007guard.com 127.0.0.1 008i.com 127.0.0.1 www.008k.com 127.0.0.1 008k.com 127.0.0.1 www.00hq.com 127.0.0.1 00hq.com 127.0.0.1 010402.com 127.0.0.1 www.032439.com 127.0.0.1 032439.com 127.0.0.1 www.0scan.com 127.0.0.1 0scan.com 127.0.0.1 1000gratisproben.com 127.0.0.1 www.1000gratisproben.com 127.0.0.1 1001namen.com 127.0.0.1 www.1001namen.com 127.0.0.1 100888290cs.com 127.0.0.1 www.100888290cs.com 127.0.0.1 www.100sexlinks.com 127.0.0.1 100sexlinks.com 127.0.0.1 10sek.com 127.0.0.1 www.10sek.com 127.0.0.1 www.1-2005-search.com 127.0.0.1 1-2005-search.com 127.0.0.1 123fporn.info 127.0.0.1 www.123fporn.info 127.0.0.1 www.123haustiereundmehr.com 127.0.0.1 123haustiereundmehr.com 127.0.0.1 123moviedownload.com 127.0.0.1 www.123moviedownload.com There are 15541 more lines. ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-1000113554-1559343911-2160561676-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Jacob\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper DNS Servers: 8.8.8.8 - 8.8.4.4 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) HKLM\...\StartupApproved\StartupFolder: => "Heimdal.lnk" HKLM\...\StartupApproved\StartupFolder: => "SolidWorks 2014 Fast Start.lnk" HKLM\...\StartupApproved\StartupFolder: => "SolidWorks Background Downloader.lnk" HKU\S-1-5-21-1000113554-1559343911-2160561676-1001\...\StartupApproved\Run: => "OneDrive" HKU\S-1-5-21-1000113554-1559343911-2160561676-1001\...\StartupApproved\Run: => "SpybotPostWindows10UpgradeReInstall" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [{24BE7522-12FC-4E1A-BCD8-1EC9BECFBB35}] => (Allow) C:\Program Files\CyberLink\PowerDirector12\PDR10.EXE FirewallRules: [{68225EB6-14EE-4F22-AD31-2710606EB920}] => (Allow) C:\Windows\SysWOW64\ftp.exe FirewallRules: [{DD27DE23-9144-47B5-8956-8D4AC7083729}] => (Allow) C:\Windows\SysWOW64\ftp.exe FirewallRules: [{B2680CE9-0A29-42AC-8F2E-DB1E7E50939F}] => (Allow) C:\Windows\system32\ftp.exe FirewallRules: [{D5D3BDB9-5930-42AD-AF6B-FE2708E0B7B6}] => (Allow) C:\Windows\system32\ftp.exe FirewallRules: [{C4A83968-BAE3-4E04-879D-5E314E51BA76}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{E19912B7-D3E4-43BB-8C9B-C2DD1B508348}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{2CA7EF8A-A3B6-47FE-9DB3-D7FACA7F3864}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe FirewallRules: [{7695977E-6AAD-4A5D-8D30-33C7943E6E99}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{C169AC4D-9DB7-472D-AFD3-A2477223C2F3}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{A26C3882-1017-415F-A0C0-5C21D435BA62}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{16A680A8-16BB-4553-B885-D8DB05430C63}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{6BEF936D-8AB8-4E43-8D0A-D0AB0BCC9070}] => (Allow) C:\Program Files (x86)\ASUS\ROG Game First III\gameFirst3.exe FirewallRules: [{56179076-524B-4B27-8145-3A460ED2CC6C}] => (Allow) C:\Program Files (x86)\ASUS\ROG Game First III\gameFirst3.exe FirewallRules: [{83259501-515F-41C7-8A15-0FBBF9C392A1}] => (Allow) C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe FirewallRules: [{F96B8697-647F-4445-B740-18FAC5FC67E5}] => (Allow) C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe FirewallRules: [{C3346573-BE89-4B8C-BBB5-E25B6ABFA0A2}] => (Allow) C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe FirewallRules: [{255BF8B0-C390-422D-9CDE-28A240254AB6}] => (Allow) C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe FirewallRules: [{CFCAE2EB-88CB-4A4F-9B07-71CDD09583A4}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{8D596406-EEC2-4FBA-A50B-E5ACB1ED68D7}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{104E7109-F84E-4B3F-AC50-BE1CD1DC87B7}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe FirewallRules: [{286CE0BA-0BAE-4B2A-A36B-73D5BD88E1DC}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe FirewallRules: [{751795B0-4354-4279-89B6-3EAAFB047BA7}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{C0DA2B7E-D75A-4BAA-98D7-3E4974A8ECFD}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{CF6939E5-55B8-439D-8509-C4AD71FD6DA2}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{EB218FBD-D36D-4953-A6E2-8F54E651BB97}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{3AE042D6-C6B5-415F-9725-1FF7B7C9564E}] => (Allow) C:\Program Files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe FirewallRules: [{221A79AF-F1E4-4DB2-A12A-668D8DEE5CE4}] => (Allow) C:\Program Files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe FirewallRules: [{D94511B0-CC9D-4E3C-A665-06E4F96B0D81}] => (Allow) C:\Program Files\SolidWorks Corp\SolidWorks\photoview\photoview360.exe FirewallRules: [{EF6A5C39-6558-418B-9F43-7E3C44CD972F}] => (Allow) C:\Program Files\SolidWorks Corp\SolidWorks\photoview\photoview360.exe FirewallRules: [{23A7B8A1-D489-4445-AD50-2B75A70B2831}] => (Allow) C:\Program Files\SolidWorks Corp\SolidWorks\photoview\photoview360_cl.exe FirewallRules: [{953A63ED-4130-45E7-B1F4-9C0F672892E7}] => (Allow) C:\Program Files\SolidWorks Corp\SolidWorks\photoview\photoview360_cl.exe FirewallRules: [{3B9C1CA6-DFA7-4903-9921-7F0ADB042FD6}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{C1359E85-5CC8-4FF2-84F4-A749ECFCD1F0}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{5E82C78E-D174-40B0-82E5-40EB173375C3}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{5278E403-B100-48BF-9CE5-DB87B8500BD9}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{F0ADCABA-C88B-4A1E-BE8D-39D95E813ED8}] => (Allow) D:\SteamLibrary\steamapps\common\Portal\hl2.exe FirewallRules: [{B8C40F27-5D70-46D9-A314-78C4FDABE68F}] => (Allow) D:\SteamLibrary\steamapps\common\Portal\hl2.exe FirewallRules: [{35008737-F52A-4E19-BC0A-54D6AAB31A60}] => (Allow) D:\SteamLibrary\steamapps\common\Zaccaria Pinball\ZaccariaPinball.exe FirewallRules: [{1661616F-3104-42A7-8A20-BAF9C731D59B}] => (Allow) D:\SteamLibrary\steamapps\common\Zaccaria Pinball\ZaccariaPinball.exe FirewallRules: [{448CA2D1-4806-48D0-BF84-E7D112DCB061}] => (Allow) D:\SteamLibrary\steamapps\common\World of Goo\WorldOfGoo.exe FirewallRules: [{E47C103E-6E43-44C8-8DD1-30ED1A284CBA}] => (Allow) D:\SteamLibrary\steamapps\common\World of Goo\WorldOfGoo.exe FirewallRules: [{41818F5D-E7F2-422A-983D-32AB215F8541}] => (Allow) D:\SteamLibrary\steamapps\common\Braid\braid.exe FirewallRules: [{AEE737A5-0FC4-48D0-B7B8-6604D4847467}] => (Allow) D:\SteamLibrary\steamapps\common\Braid\braid.exe FirewallRules: [{1A31BDD2-9A51-4F69-B98F-32A52C2BA76D}] => (Allow) D:\SteamLibrary\steamapps\common\Crayon Physics Deluxe\launcher.exe FirewallRules: [{B0C01730-6054-4AEC-AC9F-D47F9C4B3E5E}] => (Allow) D:\SteamLibrary\steamapps\common\Crayon Physics Deluxe\launcher.exe FirewallRules: [{0DDF7BF9-5DD2-48EE-B100-DD38DE8EA3D2}] => (Allow) D:\SteamLibrary\steamapps\common\Bastion\Bastion.exe FirewallRules: [{5B6F326F-2F55-48B1-AB15-1244E743FD02}] => (Allow) D:\SteamLibrary\steamapps\common\Bastion\Bastion.exe FirewallRules: [{557EC1ED-CD9D-48D3-8656-E2F8CD4314CE}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe FirewallRules: [{BC6A4BF0-DC62-439F-BEA8-07056949365C}] => (Allow) D:\SteamLibrary\steamapps\common\And Yet It Moves\And Yet It Moves.exe FirewallRules: [{E7DB3BD1-6347-4383-A84F-4BE3088F8122}] => (Allow) D:\SteamLibrary\steamapps\common\And Yet It Moves\And Yet It Moves.exe FirewallRules: [{8256924C-42CB-4CCB-B4FF-8D726B856074}] => (Allow) D:\SteamLibrary\steamapps\common\Psychonauts\Psychonauts.exe FirewallRules: [{C49B2A1D-9906-4F9C-85BC-5BFE51FF3815}] => (Allow) D:\SteamLibrary\steamapps\common\Psychonauts\Psychonauts.exe FirewallRules: [{0C048CB6-1A39-46F3-AF23-7C3F36208FEC}] => (Allow) D:\SteamLibrary\steamapps\common\Limbo\limbo.exe FirewallRules: [{C2848CE3-CE4B-4F5D-BD95-A9C220BC3E1B}] => (Allow) D:\SteamLibrary\steamapps\common\Limbo\limbo.exe FirewallRules: [{3693CB8E-0D2F-4B54-B2D0-AD60B9A34359}] => (Allow) D:\SteamLibrary\steamapps\common\Sorcery!\Sorcery!.exe FirewallRules: [{36D77956-E308-4E71-B45B-13AE9972177C}] => (Allow) D:\SteamLibrary\steamapps\common\Sorcery!\Sorcery!.exe FirewallRules: [{B6173E88-93EE-4694-8AA3-B482672C72A9}] => (Allow) D:\SteamLibrary\steamapps\common\Aquaria\Aquaria.exe FirewallRules: [{32C895CF-982B-4250-A652-3CFF77925435}] => (Allow) D:\SteamLibrary\steamapps\common\Aquaria\Aquaria.exe FirewallRules: [{45B7BB18-8708-4DFA-B3FB-3C34563306FD}] => (Allow) D:\SteamLibrary\steamapps\common\Broken Age\BrokenAge.exe FirewallRules: [{5051C22D-A32A-4498-8BFC-C192DF4A5560}] => (Allow) D:\SteamLibrary\steamapps\common\Broken Age\BrokenAge.exe FirewallRules: [{26DA73BC-4C59-4C57-9DBB-B1D11302ABD1}] => (Allow) D:\SteamLibrary\steamapps\common\Cibele\Cibele\Cibele.exe FirewallRules: [{E1B8F9CF-56B8-42E0-A0CF-AF2BAF404FA6}] => (Allow) D:\SteamLibrary\steamapps\common\Cibele\Cibele\Cibele.exe FirewallRules: [{44B28584-0D73-4584-BBFD-D3373B0F136D}] => (Allow) D:\SteamLibrary\steamapps\common\Cogs\cogs.exe FirewallRules: [{4010464B-2549-41DC-9413-8864DEE1D66F}] => (Allow) D:\SteamLibrary\steamapps\common\Cogs\cogs.exe FirewallRules: [{78ACB624-DCB0-475E-82E2-465170706FA3}] => (Allow) D:\SteamLibrary\steamapps\common\Gish\gish.exe FirewallRules: [{4DF6F686-4FB6-428C-9137-A7159B6B1436}] => (Allow) D:\SteamLibrary\steamapps\common\Gish\gish.exe FirewallRules: [{F909613C-388E-4D72-95F6-B3F89B919292}] => (Allow) D:\SteamLibrary\steamapps\common\Lugaru HD\Lugaru.exe FirewallRules: [{7C0CC3E8-494F-41F4-B17E-91EB6A20FBAC}] => (Allow) D:\SteamLibrary\steamapps\common\Lugaru HD\Lugaru.exe FirewallRules: [{389EB0C2-D43C-4951-A714-5D5899B55B67}] => (Allow) D:\SteamLibrary\steamapps\common\Penumbra Overture\redist\Penumbra.exe FirewallRules: [{30953ED9-7EE0-420C-9F67-CF1253A620B3}] => (Allow) D:\SteamLibrary\steamapps\common\Penumbra Overture\redist\Penumbra.exe FirewallRules: [{686F74A2-9BA0-4BED-BCE5-537145EB8B19}] => (Allow) D:\SteamLibrary\steamapps\common\Samorost 2\Samorost2.exe FirewallRules: [{6381BAD7-1C41-461D-998C-209869F7F8CF}] => (Allow) D:\SteamLibrary\steamapps\common\Samorost 2\Samorost2.exe FirewallRules: [{82B4A709-C287-4BF3-8931-24A75FBE7D4E}] => (Allow) D:\SteamLibrary\steamapps\common\Samorost 3\Samorost3.exe FirewallRules: [{8048E852-6C41-40AA-B60D-64EF423D6309}] => (Allow) D:\SteamLibrary\steamapps\common\Samorost 3\Samorost3.exe FirewallRules: [{D1E3041C-0537-47F4-AB8C-555CF2921657}] => (Allow) D:\SteamLibrary\steamapps\common\Read Only Memories\ROM.exe FirewallRules: [{658B17EB-31D2-4716-A71F-85281606A0E8}] => (Allow) D:\SteamLibrary\steamapps\common\Read Only Memories\ROM.exe FirewallRules: [{BAA7C959-48B3-4034-873E-FB5EC9A30D35}] => (Allow) D:\SteamLibrary\steamapps\common\steelstorm\steelstorm.exe FirewallRules: [{EE02E1CB-8D74-4F70-8422-E4699ADC9051}] => (Allow) D:\SteamLibrary\steamapps\common\steelstorm\steelstorm.exe FirewallRules: [{62F5BA36-0BF3-405D-B922-6471BF009CB3}] => (Allow) D:\SteamLibrary\steamapps\common\steelstorm\netradiant_win32\radiant.exe FirewallRules: [{0A7111AD-AB0D-4C37-9A60-715F89158999}] => (Allow) D:\SteamLibrary\steamapps\common\steelstorm\netradiant_win32\radiant.exe FirewallRules: [{E1F0B57F-279E-4D5C-8652-A68AFC55505C}] => (Allow) D:\SteamLibrary\steamapps\common\80 Days\80 Days.exe FirewallRules: [{BADDAD11-4B62-4686-99C2-2539170C48C2}] => (Allow) D:\SteamLibrary\steamapps\common\80 Days\80 Days.exe FirewallRules: [{3C8AD5E8-F689-4D1C-9C66-47F6CE9E5A0C}] => (Allow) D:\SteamLibrary\steamapps\common\Lone Survivor\LoneSurvivor\LoneSurvivor.exe FirewallRules: [{4FD88BD1-AD8C-4A64-BEB6-9C9AF3A13F10}] => (Allow) D:\SteamLibrary\steamapps\common\Lone Survivor\LoneSurvivor\LoneSurvivor.exe FirewallRules: [{D47CF01F-034F-41DB-B43F-B7B2CD1924E5}] => (Allow) D:\SteamLibrary\steamapps\common\Cortex Command\Cortex Command.exe FirewallRules: [{A5B9FE62-EE93-42B3-8339-2CBD04E20694}] => (Allow) D:\SteamLibrary\steamapps\common\Cortex Command\Cortex Command.exe FirewallRules: [{70EFBAB2-E3E8-45F9-9597-B0293DCC7B74}] => (Allow) D:\SteamLibrary\steamapps\common\atomzombiesmasher\data\atomzombiesmasher.exe FirewallRules: [{A53F6411-18A7-4022-A8EA-35FEADA94772}] => (Allow) D:\SteamLibrary\steamapps\common\atomzombiesmasher\data\atomzombiesmasher.exe FirewallRules: [{7338C728-041D-46A1-8FED-298FCF8D90B2}] => (Allow) D:\SteamLibrary\steamapps\common\Super Meat Boy\SuperMeatBoy.exe FirewallRules: [{5202E7F7-03C0-481A-8EA7-7B04ACD42F08}] => (Allow) D:\SteamLibrary\steamapps\common\Super Meat Boy\SuperMeatBoy.exe FirewallRules: [{5F8BC044-353D-4380-9A77-D9CEFD18FDF1}] => (Allow) D:\SteamLibrary\steamapps\common\vvvvvv\VVVVVV.exe FirewallRules: [{5F25331C-9679-4B49-818F-B5A78A2C3B13}] => (Allow) D:\SteamLibrary\steamapps\common\vvvvvv\VVVVVV.exe FirewallRules: [{31AA7966-6A7C-44BA-9259-374579494490}] => (Allow) D:\SteamLibrary\steamapps\common\Hammerfight\Hammerfight.exe FirewallRules: [{3211B2AE-9B95-465D-A485-2E2A9B4A94F2}] => (Allow) D:\SteamLibrary\steamapps\common\Hammerfight\Hammerfight.exe FirewallRules: [{D27CCBFF-FC1B-402C-86C8-2FDAF6E81690}] => (Allow) D:\SteamLibrary\steamapps\common\Amnesia The Dark Descent\Amnesia.exe FirewallRules: [{5F48685A-4013-4F86-AFC8-5ECF6CD7ED14}] => (Allow) D:\SteamLibrary\steamapps\common\Amnesia The Dark Descent\Amnesia.exe FirewallRules: [{07325787-F071-45C3-923C-576094D16596}] => (Allow) D:\SteamLibrary\steamapps\common\Amnesia The Dark Descent\Launcher.exe FirewallRules: [{08F46B5C-1548-41C1-8531-206DB36602E3}] => (Allow) D:\SteamLibrary\steamapps\common\Amnesia The Dark Descent\Launcher.exe FirewallRules: [{E593F06A-6F59-487F-B6C9-407559EBF8C4}] => (Allow) D:\SteamLibrary\steamapps\common\Superbrothers Sword & Sworcery EP\swordandsworcery_pc.exe FirewallRules: [{38EF1588-EBEA-4B63-B55C-E414E6BC9563}] => (Allow) D:\SteamLibrary\steamapps\common\Superbrothers Sword & Sworcery EP\swordandsworcery_pc.exe FirewallRules: [{369E65A8-EC76-4E43-A113-00D295F0E3B1}] => (Allow) D:\SteamLibrary\steamapps\common\HER STORY\HerStory.exe FirewallRules: [{45B7E9CE-42E4-41AE-9993-4785220339D9}] => (Allow) D:\SteamLibrary\steamapps\common\HER STORY\HerStory.exe FirewallRules: [{2C373972-B3AC-47BB-BE5A-D9507CD2765A}] => (Allow) C:\Program Files\Windows Defender\MsMpEng.exe FirewallRules: [{EE94B7ED-1352-4CA7-9E45-AAD7F6767123}] => (Allow) C:\Program Files\Windows Defender\MsMpEng.exe FirewallRules: [{26C1DFA1-54F0-4E1F-AB74-78DCDCBA9B78}] => (Allow) C:\Program Files\Windows Defender\MsMpEng.exe FirewallRules: [{233F595B-012B-4372-8AC3-A1AA255B816A}] => (Allow) C:\Program Files\Windows Defender\MsMpEng.exe StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe] => Enabled:Spybot - Search & Destroy tray access StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe] => Enabled:Spybot-S&D 2 Scanner Service StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe] => Enabled:Spybot-S&D 2 Updater StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe] => Enabled:Spybot-S&D 2 Background update service ==================== Restore Points ========================= 22-06-2016 22:13:04 Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23918 22-06-2016 22:14:01 Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23918 26-06-2016 00:10:35 Installed DirectX 04-07-2016 16:41:17 Scheduled Checkpoint ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (07/04/2016 04:41:34 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol. System Error: Access is denied. . Error: (07/04/2016 02:47:51 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: SearchUI.exe, version: 10.0.10586.420, time stamp: 0x57491ba1 Faulting module name: Windows.UI.Xaml.dll, version: 10.0.10586.306, time stamp: 0x571af9f6 Exception code: 0xc000027b Fault offset: 0x0000000000281f52 Faulting process id: 0x2204 Faulting application start time: 0xSearchUI.exe0 Faulting application path: SearchUI.exe1 Faulting module path: SearchUI.exe2 Report Id: SearchUI.exe3 Faulting package full name: SearchUI.exe4 Faulting package-relative application ID: SearchUI.exe5 Error: (07/04/2016 02:47:38 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: MOBILELABMAX) Description: Activation of app Microsoft.Windows.Photos_8wekyb3d8bbwe!App failed with error: -2147023170 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (07/04/2016 02:47:32 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: Microsoft.Photos.exe, version: 16.526.11240.0, time stamp: 0x574744f3 Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000 Exception code: 0xe0464645 Fault offset: 0x0000000000000000 Faulting process id: 0x2cbc Faulting application start time: 0xMicrosoft.Photos.exe0 Faulting application path: Microsoft.Photos.exe1 Faulting module path: Microsoft.Photos.exe2 Report Id: Microsoft.Photos.exe3 Faulting package full name: Microsoft.Photos.exe4 Faulting package-relative application ID: Microsoft.Photos.exe5 Error: (07/03/2016 01:08:18 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: SearchUI.exe, version: 10.0.10586.420, time stamp: 0x57491ba1 Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000 Exception code: 0xe0464645 Fault offset: 0x0000000000000000 Faulting process id: 0x2e28 Faulting application start time: 0xSearchUI.exe0 Faulting application path: SearchUI.exe1 Faulting module path: SearchUI.exe2 Report Id: SearchUI.exe3 Faulting package full name: SearchUI.exe4 Faulting package-relative application ID: SearchUI.exe5 Error: (07/03/2016 09:06:02 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: SearchUI.exe, version: 10.0.10586.420, time stamp: 0x57491ba1 Faulting module name: Windows.UI.Xaml.dll, version: 10.0.10586.306, time stamp: 0x571af9f6 Exception code: 0xc000027b Fault offset: 0x0000000000281f52 Faulting process id: 0x2ee4 Faulting application start time: 0xSearchUI.exe0 Faulting application path: SearchUI.exe1 Faulting module path: SearchUI.exe2 Report Id: SearchUI.exe3 Faulting package full name: SearchUI.exe4 Faulting package-relative application ID: SearchUI.exe5 Error: (07/03/2016 06:37:54 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: MOBILELABMAX) Description: Activation of app Microsoft.WindowsMaps_8wekyb3d8bbwe!App failed with error: -2144927148 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (07/03/2016 06:37:41 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: MOBILELABMAX) Description: Activation of app Microsoft.WindowsMaps_8wekyb3d8bbwe!App failed with error: -2144927148 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (07/03/2016 06:31:57 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: MOBILELABMAX) Description: Activation of app Microsoft.WindowsMaps_8wekyb3d8bbwe!App failed with error: -2144927148 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (07/03/2016 06:26:53 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: MOBILELABMAX) Description: Activation of app Microsoft.WindowsMaps_8wekyb3d8bbwe!App failed with error: -2144927148 See the Microsoft-Windows-TWinUI/Operational log for additional information. System errors: ============= Error: (07/04/2016 05:50:24 PM) (Source: DCOM) (EventID: 10016) (User: MOBILELABMAX) Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}MOBILELABMAXJacobS-1-5-21-1000113554-1559343911-2160561676-1001LocalHost (Using LRPC)Microsoft.Windows.FeatureOnDemand.InsiderHub_10.0.10586.0_neutral_neutral_cw5n1h2txyewyS-1-15-2-4016783169-893401051-2237370320-274899566-412088533-2398988950-2155762795 Error: (07/04/2016 05:46:52 PM) (Source: Service Control Manager) (EventID: 7022) (User: ) Description: The Intel(R) Management and Security Application Local Management Service service hung on starting. Error: (07/04/2016 05:46:48 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: application-specificLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)UnavailableUnavailable Error: (07/04/2016 05:43:58 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The VMware Workstation Server service failed to start due to the following error: %%1053 = The service did not respond to the start or control request in a timely fashion. Error: (07/04/2016 05:43:58 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: A timeout was reached (30000 milliseconds) while waiting for the VMwareHostd service to connect. Error: (07/04/2016 05:43:19 PM) (Source: Service Control Manager) (EventID: 7022) (User: ) Description: The Delivery Optimization service hung on starting. Error: (07/04/2016 05:40:23 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The Windows Presentation Foundation Font Cache 3.0.0.0 service failed to start due to the following error: %%1053 = The service did not respond to the start or control request in a timely fashion. Error: (07/04/2016 05:40:07 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: A timeout was reached (30000 milliseconds) while waiting for the FontCache3.0.0.0 service to connect. Error: (07/04/2016 05:39:07 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The SystemUsageReportSvc_WILLAMETTE service failed to start due to the following error: %%1053 = The service did not respond to the start or control request in a timely fashion. Error: (07/04/2016 05:39:07 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: A timeout was reached (30000 milliseconds) while waiting for the SystemUsageReportSvc_WILLAMETTE service to connect. CodeIntegrity: =================================== Date: 2016-07-02 13:31:12.777 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\nvinitx.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-06-22 18:36:46.227 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-06-18 03:49:06.750 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-06-16 03:37:19.500 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-06-12 11:47:50.174 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-06-09 23:33:29.210 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-06-09 15:44:01.652 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-06-08 21:31:37.293 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-06-08 20:24:37.027 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. Date: 2016-06-06 02:44:45.047 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i7-6700HQ CPU @ 2.60GHz Percentage of memory in use: 41% Total physical RAM: 8090.55 MB Available physical RAM: 4742.59 MB Total Virtual: 10778.55 MB Available Virtual: 7488.2 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:371.85 GB) (Free:142.34 GB) NTFS ==>[system with boot components (obtained from drive)] Drive d: (DATA) (Fixed) (Total:558.91 GB) (Free:233.39 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 931.5 GB) (Disk ID: D1E086BE) Partition: GPT. ==================== End of Addition.txt ============================