Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15-08-2016 01 Ran by [removed] (17-08-2016 11:01:13) Running from C:\Users\[removed]\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LC24TP3V Windows 7 Professional Service Pack 1 (X64) (2011-06-02 20:54:53) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= 4BD72D2CC7C249789715 (S-1-5-21-660726629-327130963-595889159-1005 - Limited - Enabled) Administrator (S-1-5-21-660726629-327130963-595889159-500 - Administrator - Disabled) Guest (S-1-5-21-660726629-327130963-595889159-501 - Limited - Disabled) liz (S-1-5-21-660726629-327130963-595889159-1002 - Administrator - Enabled) => C:\Users\liz Peter (S-1-5-21-660726629-327130963-595889159-1006 - Administrator - Enabled) => C:\Users\Peter Tim_v (S-1-5-21-660726629-327130963-595889159-1004 - Limited - Enabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: McAfee VirusScan Enterprise (Enabled - Out of date) {86355677-4064-3EA7-ABB3-1B136EB04637} AV: Lavasoft Ad-Aware (Disabled - Out of date) {E0D97DD4-42BA-B3F2-A5A7-22E9ACE81FC7} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Lavasoft Ad-Aware (Disabled - Out of date) {5BB89C30-6480-BC7C-9F17-199BD76F557A} AS: McAfee VirusScan Enterprise Antispyware Module (Enabled - Out of date) {3D54B793-665E-3129-9103-206115370C8A} FW: Lavasoft Ad-Aware (Disabled) {D8E2FCF1-08D5-B2AA-8EF8-8BDC523B58BC} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 123 Free Solitaire 2009 v7.2 (HKLM-x32\...\123 Free Solitaire_is1) (Version: - TreeCardGames.com) 35mm Film Scanner X64 (HKLM-x32\...\{A90C9F22-68A4-4704-BB4F-FE205F416B9C}) (Version: 1.00.0000 - 35mm Film Scanner) 64 Bit HP CIO Components Installer (Version: 6.2.1 - Hewlett-Packard) Hidden Ad-Aware Antivirus (HKLM-x32\...\{2819e172-81d5-4113-88bd-4605b02344e0}) (Version: 10.4.49.4168 - Lavasoft) Ad-Aware Browsing Protection (HKLM-x32\...\Ad-Aware Browsing Protection) (Version: 1.0.1.82 - Lavasoft) Adblock Plus for IE (32-bit and 64-bit) (HKLM\...\{77588F59-3C58-4675-8EEE-998E5BC33CF4}) (Version: 1.4 - Eyeo GmbH) Adblock Plus for IE (HKLM-x32\...\{fd97d1e2-368a-4cd9-af63-8eeff938044a}) (Version: 1.1 - ) Adobe Acrobat X Pro - English, Français, Deutsch (HKLM-x32\...\{AC76BA86-1033-F400-7760-000000000005}) (Version: 10.1.6 - Adobe Systems) Adobe Community Help (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 3.4.980 - Adobe Systems Incorporated.) Adobe Flash Player 22 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 22.0.0.210 - Adobe Systems Incorporated) Adobe Reader XI (11.0.11) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.11 - Adobe Systems Incorporated) Apple Application Support (32-bit) (HKLM-x32\...\{7FA9ECCF-A2DE-4DA1-BFF3-81260DBDA68F}) (Version: 4.1.2 - Apple Inc.) Apple Application Support (64-bit) (HKLM\...\{691F30EB-9009-475A-B8A9-E1BF39598FD5}) (Version: 4.1.2 - Apple Inc.) Apple Application Support (HKLM-x32\...\{78002155-F025-4070-85B3-7C0453561701}) (Version: 3.0.6 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{3540181E-340A-4E7A-B409-31663472B2F7}) (Version: 9.1.0.6 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{6AF2AC2A-3532-43FD-9F4D-BDC9C0D724C7}) (Version: 7.1.2.6 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Apple Software Update (HKLM-x32\...\{FFD1F7F1-1AC9-4BC4-A908-0686D635ABAF}) (Version: 2.1.4.131 - Apple Inc.) ArcSoft Panorama Maker 6 (HKLM-x32\...\{DABFD34E-BE68-4BC6-9254-5D7A7FF76B99}) (Version: 6.0.8.85 - ArcSoft) ArcSoft PhotoStudio 5.5 (HKLM-x32\...\{63B8997E-EB2D-41D3-984C-C44D6D67A571}) (Version: - ArcSoft) ASIO4ALL (HKLM-x32\...\ASIO4ALL) (Version: 2.10 - Michael Tippach) Autodesk Pixlr (HKLM-x32\...\Autodesk Pixlr) (Version: 1.1.1.0 - Autodesk) Autodesk Pixlr (x32 Version: 1.1.1.0 - Autodesk) Hidden Avid Pro Tools SE 8.0.3 (HKLM-x32\...\{371F27A1-9502-4762-AE97-1C1938B21055}) (Version: 8.0.3 - Digidesign, A Division of Avid Technology, Inc.) AviSynth 2.5 (HKLM-x32\...\AviSynth) (Version: - ) BioAPI Framework (Version: 1.0.2 - Dell Inc.) Hidden BlackBerry Desktop Software 7.1 (HKLM-x32\...\BlackBerry_Desktop) (Version: 7.1.0.41 - Research In Motion Ltd.) BlackBerry Desktop Software 7.1 (x32 Version: 7.1.0.41 - Research In Motion Ltd.) Hidden Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Camera Support Core Library (x32 Version: 7.3.0.4 - Canon) Hidden Camera Window DS (x32 Version: 5.2 - Canon) Hidden Camera Window DVC (x32 Version: 5.4 - Canon) Hidden Camera Window MC (x32 Version: 5.4 - Canon) Hidden CamfrogWEB Advanced ActiveX Plugin (remove only) (HKLM-x32\...\CFWebAdvancedU) (Version: - ) Canon Camera Support Core Library (HKLM-x32\...\InstallShield_{A1D0D14A-B776-4907-BC00-5149F2298086}) (Version: 7.3.0.4 - Canon) Canon Camera Window DC_DV 5 for ZoomBrowser EX (HKLM-x32\...\InstallShield_{001AB29C-5468-4972-8D24-2EBDB2B12133}) (Version: 5.4 - Canon) Canon Camera Window DS for ZoomBrowser EX (HKLM-x32\...\InstallShield_{6B8BDABA-6737-4998-AEE4-E218EDE5FC7A}) (Version: 5.2 - Canon) Canon Camera Window MC 5 for ZoomBrowser EX (HKLM-x32\...\InstallShield_{89EB3ED7-225A-412E-B048-623D502C000F}) (Version: 5.4 - Canon) Canon MovieEdit Task for ZoomBrowser EX (HKLM-x32\...\InstallShield_{68D27126-BF6A-457D-8DD0-5F35E8D41310}) (Version: 1.3.1.21 - Canon) Canon PhotoRecord (HKLM-x32\...\{6693BD7C-CB4E-43AC-A0D6-10D1A1B88DCF}) (Version: 02.02.02000 - Cisra) Canon RAW Image Task for ZoomBrowser EX (HKLM-x32\...\InstallShield_{001EB665-D9EC-415E-9E13-AD2125B2B992}) (Version: 2.1 - Canon) Canon Utilities PhotoStitch 3.1 (HKLM-x32\...\InstallShield_{218BBBE3-FE63-4BB2-81A8-7435575A84FA}) (Version: 3.1.14 - Canon) Canon ZoomBrowser EX (HKLM-x32\...\{C1D76D7A-F3BB-47EA-A746-5B1E2FFC1DF2}) (Version: 5.02.0100 - Canon) Citrix Receiver (HKLM-x32\...\CitrixOnlinePluginPackWeb) (Version: 14.3.0.5014 - Citrix Systems, Inc.) Custom (Version: 12.34.56.789 - Wave Systems Corp.) Hidden CyberLink PowerDVD 9.5 (HKLM-x32\...\InstallShield_{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}) (Version: 9.5.1.3225 - CyberLink Corp.) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Dell Backup and Recovery Manager (HKLM\...\{50B4B603-A4C6-4739-AE96-6C76A0F8A388}) (Version: 1.3.1 - Dell Inc.) Dell ControlVault Host Components Installer 64 bit (Version: 2.0.20.159 - Broadcom Corporation) Hidden Dell Data Protection | Access (HKLM-x32\...\{A7D91856-258D-4C87-8041-B170851CE432}) (Version: 2.0.00000.085 - Dell Inc.) Dell Data Protection | Access (Version: 01.01.00.085 - Wave Systems Corp) Hidden Dell Data Protection | Access | Drivers (HKLM-x32\...\{4E4E65EE-C456-45AC-B5AD-C62C3A325BD0}) (Version: 1.00.011 - Dell Inc.) Dell Data Protection | Access | Middleware (HKLM-x32\...\{841CBDD5-4BB5-403E-AEE3-2FADC3890BE8}) (Version: 1.00.005 - Dell Inc.) Dell Edoc Viewer (HKLM\...\{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}) (Version: 1.0.0 - Dell Inc) Dell System Detect (HKU\S-1-5-21-660726629-327130963-595889159-1006\...\58d94f3ce2c27db0) (Version: 7.3.0.6 - Dell) Dell System Manager (HKLM\...\{FDF509ED-9624-4FDE-9BAA-9566C186AB96}) (Version: 1.6.00000 - Dell Inc.) Dell Touchpad (HKLM\...\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version: 8.1200.101.134 - ALPS ELECTRIC CO., LTD.) Dell Webcam Central (HKLM-x32\...\Dell Webcam Central) (Version: 1.40.28 - Creative Technology Ltd) DellAccess (Version: 01.01.00.053 - Wave Systems Corp.) Hidden DigiTech X-Edit 2.4.1 (HKLM-x32\...\{02DC3C69-02AF-47C2-9B68-AA2A69631CF8}) (Version: 2.4.1.2 - DigiTech) DirectX 9 Runtime (x32 Version: 1.00.0000 - Sonic Solutions) Hidden Dropbox (HKU\S-1-5-21-660726629-327130963-595889159-1006\...\Dropbox) (Version: 7.4.30 - Dropbox, Inc.) EMBASSY Security Center (Version: 04.03.00.067 - Wave Systems Corp.) Hidden Eraser 6.2.0.2969 (HKLM\...\{66AB13EA-E7D2-4CFC-9B66-8E9EE44C89EE}) (Version: 6.2.2969 - The Eraser Project) Forté Agent (HKLM-x32\...\{9B867430-CF67-4989-A414-68DF625D5D15}) (Version: 8.00.1272 - Forté Internet Software, Inc.) FortiClient SSLVPN v4.0.2300 (HKLM-x32\...\{A34DCE59-0004-0000-2300-3F8A9926B752}) (Version: 4.0.2300 - Fortinet Inc.) Free Studio (HKLM-x32\...\Free Studio_is1) (Version: 6.6.7.426 - DVDVideoSoft Ltd.) Free Video Flip and Rotate (HKLM-x32\...\Free Video Flip and Rotate_is1) (Version: 2.2.18.323 - DVDVideoSoft Ltd.) Free Video to JPG Converter version 1.4 (HKLM-x32\...\Free Video to JPG Converter_is1) (Version: - DVD Video Soft Limited.) Gemalto (Version: 01.64.01.0010 - Wave Systems Corp) Hidden Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.5111.1712 - Google Inc.) Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden Guitar Pro 5.2 (HKLM-x32\...\Guitar Pro 5_is1) (Version: - Arobas Music) HP Deskjet 3050A J611 series Basic Device Software (HKLM\...\{B6A3EAE4-3727-46A4-A659-8576BF7C8C8D}) (Version: 23.0.504.0 - Hewlett-Packard Co.) HP Deskjet 3050A J611 series Help (HKLM-x32\...\{97DDCAB8-B770-4089-A10F-67568069D78A}) (Version: 140.0.2.2 - Hewlett Packard) HP Deskjet 3050A J611 series Product Improvement Study (HKLM\...\{F638F65B-B435-44E0-9382-7F90BDB003E2}) (Version: 23.0.504.0 - Hewlett-Packard Co.) HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.12262 - HP Photo Creations) HP Update (HKLM-x32\...\{DDD5104F-1C44-49EB-9E6B-29EC5D27658B}) (Version: 5.002.007.004 - Hewlett-Packard) Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1010 - Intel Corporation) Intel(R) Identity Protection Technology 1.0.71.0 (HKLM-x32\...\{2C43790E-8470-1027-82D3-DF319F3C410F}) (Version: 1.0.71.0 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.1.70.1205 - Intel Corporation) Intel(R) Network Connections 15.7.176.1 (HKLM\...\PROSetDX) (Version: 15.7.176.1 - Dell) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2347 - Intel Corporation) Intel(R) PROSet/Wireless WiFi Software (HKLM\...\{4C1CCA11-0D08-4D5E-8444-2D9FB48BCABF}) (Version: 14.00.20110 - Intel Corporation) Interlok driver setup x64 (HKLM\...\{25613C10-27D2-410B-942B-D922D5C3A7BE}) (Version: 5.8.13 - PACE Anti-Piracy) iTunes (HKLM\...\{77DE5105-D05E-448C-96CB-7FA381903753}) (Version: 11.3.1.2 - Apple Inc.) iTunes (HKLM\...\{FBEB98F8-64E4-4FA3-A15E-4A9F42FF962E}) (Version: 12.3.2.35 - Apple Inc.) Java(TM) 6 Update 24 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86416024FF}) (Version: 6.0.240 - Oracle) Java(TM) 6 Update 31 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216031FF}) (Version: 6.0.310 - Oracle) Java(TM) 7 Update 5 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217005FF}) (Version: 7.0.50 - Oracle) JavaFX 2.1.1 (HKLM-x32\...\{1111706F-666A-4037-7777-211328764D10}) (Version: 2.1.1 - Oracle Corporation) Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden MAGIX PC Check & Tuning 2012 Download Version (HKLM-x32\...\MAGIX_MSI_PC_Check_Tuning_2012) (Version: 7.0.401.3 - MAGIX AG) MAGIX PC Check & Tuning 2012 Download Version (x32 Version: 7.0.401.3 - MAGIX AG) Hidden MAGIX PC Live (HKLM-x32\...\MAGIX_MSI_PC_Live) (Version: 1.0.4.9 - MAGIX AG) MAGIX PC Live (x32 Version: 1.0.4.9 - MAGIX AG) Hidden MAGIX Screenshare (HKLM-x32\...\MAGIX_MSI_PCVisit) (Version: 4.3.6.1987 - MAGIX AG) MAGIX Screenshare (x32 Version: 4.3.6.1987 - MAGIX AG) Hidden Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes) M-Audio FastTrack Driver 6.0.2 (x64) (HKLM\...\{C874B99C-8480-4AFB-A646-4B1DCAB185B2}) (Version: 6.0.2 - M-Audio) McAfee Agent (HKLM-x32\...\{2AAB21C2-4CDA-4189-A0EC-5ED666113F84}) (Version: 4.5.0.1810 - McAfee, Inc.) McAfee VirusScan Enterprise (HKLM-x32\...\{CE15D1B6-19B6-4D4D-8F43-CF5D2C3356FF}) (Version: 8.8.00000 - McAfee, Inc.) MediaHuman Audio Converter version 1.9.5.2 (HKLM-x32\...\MHAudioConverter_is1) (Version: 1.9.5.2 - MediaHuman) Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.6.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation) Microsoft Office Professional Plus 2010 (HKLM\...\Office14.PROPLUS) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.) MovieEdit Task (x32 Version: 1.3.1.21 - Canon) Hidden MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2721691) (HKLM-x32\...\{355B5AC0-CEEE-42C5-AD4D-7F3CFD806C36}) (Version: 4.30.2114.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB973685) (HKLM-x32\...\{859DFA95-E4A6-48CD-B88E-A3E483E89B44}) (Version: 4.30.2107.0 - Microsoft Corporation) Musicnotes Software Suite 1.6.0 (HKLM-x32\...\Musicnotes Combined Installer_is1) (Version: 1.6.0 - Musicnotes Inc.) Native Instruments Guitar Rig 3 (HKLM-x32\...\Native Instruments Guitar Rig 3) (Version: - ) Native Instruments Service Center (HKLM-x32\...\Native Instruments Service Center) (Version: - ) Nikon Movie Editor (HKLM-x32\...\{5CAD3393-EEC0-44CE-9F93-BCAA365B77FB}) (Version: 2.3.1 - Nikon) NTRU TCG Software Stack (Version: 2.1.34 - Security Innovation) Hidden NVIDIA 3D Vision Driver 296.79 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 296.79 - NVIDIA Corporation) NVIDIA GAME System Software 2.8.1 (HKLM-x32\...\{4F0C7CCF-5666-474B-B02E-AC514A95EC93}) (Version: 2.8.1 - NVIDIA Corporation) NVIDIA Graphics Driver 296.79 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 296.79 - NVIDIA Corporation) NVIDIA HD Audio Driver 1.3.12.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.12.0 - NVIDIA Corporation) NVIDIA nView 136.28 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NView) (Version: 136.28 - NVIDIA Corporation) O2Micro Flash Memory Card Windows Driver (HKLM-x32\...\InstallShield_{0CB3B7EE-52C7-4136-AF40-605567D90318}) (Version: 3.0.07.23 - O2Micro International LTD.) O2Micro Flash Memory Card Windows Driver (x32 Version: 3.0.07.23 - O2Micro International LTD.) Hidden Online Plug-in (x32 Version: 14.3.0.5014 - Citrix Systems, Inc.) Hidden OpenOffice 4.1.2 (HKLM-x32\...\{E6AD67BB-1C33-4AB3-A387-E0D48137AB70}) (Version: 4.12.9782 - Apache Software Foundation) PC-CCID (Version: 2.0.0 - Gemalto) Hidden PDFCreator (HKLM-x32\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.2.3 - Frank Heindörfer, Philip Chinery) PhotoShowExpress (x32 Version: 2.0.063 - Sonic Solutions) Hidden PhotoStitch (x32 Version: 3.1.14 - Canon) Hidden Picture Control Utility x64 (HKLM\...\{11953C65-BB4E-4CA4-B0F0-2600A4B20040}) (Version: 1.4.3 - Nikon) Preboot Manager (Version: 03.03.00.049 - Wave Systems Corp.) Hidden Private Information Manager (Version: 07.01.00.007 - Wave Systems Corp.) Hidden PxMergeModule (x32 Version: 1.00.0000 - Your Company Name) Hidden QuickTime 7 (HKLM-x32\...\{627FFC10-CE0A-497F-BA2B-208CAC638010}) (Version: 7.77.80.95 - Apple Inc.) RAW Image Task 2.1 (x32 Version: 2.1 - Canon) Hidden RBVirtualFolder64Inst (Version: 1.00.0000 - Roxio, Inc.) Hidden Reader for PC (HKLM-x32\...\{38FB32F7-5A2A-40E4-B106-4C35F75725CD}) (Version: 2.4.00.05230 - Sony Corporation) Roxio Creator Starter (HKLM-x32\...\{6F0BBEFE-BE1C-419B-BA1F-D36C9E7915BC}) (Version: 12.1.77.0 - Roxio) Roxio Easy VHS to DVD 3 (HKLM-x32\...\{01EA1B5D-04A2-45BD-83BD-488D6EB7B942}) (Version: 3.0 - Roxio) Roxio File Backup (Version: 1.3.2 - Roxio) Hidden SecondLifeViewer (HKLM-x32\...\SecondLifeViewer) (Version: 4.0.6.315555 - Linden Research, Inc.) Self-service Plug-in (x32 Version: 4.3.0.8352 - Citrix Systems, Inc.) Hidden Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{A3364707-2F53-4C83-8F68-C9877A9080C7}) (Version: - Microsoft) Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (Version: - Microsoft) Hidden SlimDX Redistributable (March 2009) (HKLM-x32\...\{D5395E5F-4D45-4665-8F00-234FA33678AF}) (Version: 2.0.7.41 - SlimDX Group) SONAR 8.0 Producer Edition (HKLM-x32\...\SONAR8Producer_x64_is1) (Version: 17.0 - Cakewalk Music Software) Sonic CinePlayer Decoder Pack (x32 Version: 4.3.0 - Sonic Solutions) Hidden Sothink Movie DVD Maker (HKLM-x32\...\{4F94119D-1B71-400e-9F04-B4E5CEAE71F8}_is1) (Version: 3.7 - SourceTec Software Co., LTD) SPBA 5.9 (Version: 5.9.4.6686 - UPEK Inc.) Hidden Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1) (Version: 1.6.2 - Safer Networking Limited) Super nude patch II 2.8 (HKLM-x32\...\Super_nude_patch_II_1.0) (Version: 2.0.2 - Pandora sims) Switch Sound File Converter (HKLM-x32\...\Switch) (Version: - NCH Software) TouchFreeze (HKLM-x32\...\{9C9744E5-2BB7-4042-BD1C-8A339480A08C}) (Version: 1.1.0 - Ivan Zhakov) Trusted Drive Manager (Version: 4.0.0.512 - Wave Systems Corp.) Hidden TuneUp Utilities 2014 (en-US) (x32 Version: 14.0.1000.88 - TuneUp Software) Hidden TurboTax 2011 (HKLM-x32\...\{12CAA28E-56CA-4C3D-B3F2-7311540DD410}) (Version: 1.00.0000 - Intuit Canada) TurboTax 2012 (HKLM-x32\...\{726DDC29-79B3-41B4-BDBF-97DF25BF1EA8}) (Version: 1.00.0000 - Intuit Canada) TurboTax 2013 (HKLM-x32\...\{1E0FF98D-4AE4-46CC-B624-E771ABD5EA11}) (Version: 1.00.0000 - Intuit Canada) TurboTax 2014 (HKLM-x32\...\{0B69B187-4F9F-41C2-B850-735D1A323571}) (Version: 1.00.0000 - Intuit Canada) TurboTax 2015 (HKLM-x32\...\{2A42456E-B15D-492F-B99A-53C5ABD77EC0}) (Version: 1.00.0000 - Intuit Canada) TweakBit Driver Updater (HKLM-x32\...\{62D64B30-6E10-4C49-95FE-EDD8F8165DED}_is1) (Version: 1.7.2.2 - Auslogics Labs Pty Ltd) U3Launcher (HKLM-x32\...\{D8E363A7-88B7-446D-B2C0-E26CE4DC8E54}) (Version: 1.0.0 - U3) Uninstall 1.0.0.1 (HKLM-x32\...\Uninstall_is1) (Version: - ) Upek Touchchip Fingerprint Reader (Version: 1.2.004 - Dell Inc.) Hidden Usenet.nl (HKLM-x32\...\Usenet.nl_is1) (Version: - ) Vegas Pro 13.0 (64-bit) (HKLM\...\{CDA02BF0-BFBC-11E3-AFA0-F04DA23A5C58}) (Version: 13.0.290 - Sony) VideoPad Video Editor (HKLM-x32\...\VideoPad) (Version: 4.33 - NCH Software) ViewNX 2 (HKLM\...\{635BE602-BB9C-4C59-8CC5-93F9366E8A21}) (Version: 2.3.2 - Nikon) Wave Infrastructure Installer (Version: 07.66.40.0008 - Wave Systems Corp) Hidden Wave Support Software Installer (Version: 05.13.00.014 - Wave Systems Corp) Hidden WavePad Sound Editor (HKLM-x32\...\WavePad) (Version: - NCH Software) WIDCOMM Bluetooth Software (HKLM\...\{436E0B79-2CFB-4E5F-9380-E17C1B25D0C5}) (Version: 6.3.0.7900 - Broadcom Corporation) Windows 7 USB/DVD Download Tool (HKLM-x32\...\{CCF298AF-9CE1-4B26-B251-486E98A34789}) (Version: 1.0.30 - Microsoft Corporation) Windows Driver Package - Dell Inc. PBADRV System (09/11/2009 1.0.1.6) (HKLM\...\9512AA21B791B05A54E27065C45BBC417AB282DF) (Version: 09/11/2009 1.0.1.6 - Dell Inc.) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation) Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation) WinPcap 4.1.2 (HKLM-x32\...\WinPcapInst) (Version: 4.1.0.2001 - CACE Technologies) WinRAR 4.01 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 4.01.0 - win.rar GmbH) WinZip 15.0 (HKLM-x32\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240BE}) (Version: 15.0.9302 - WinZip Computing, S.L. ) Wondershare Video Converter Ultimate(Build 8.5.6.0) (HKLM-x32\...\Wondershare Video Converter Ultimate_is1) (Version: 8.5.6.0 - Wondershare Software) Write Your Legal Will in 3 Easy Steps (HKLM-x32\...\Write Your Legal Will in 3 Easy Steps08-1) (Version: 08-1 - Self-Counsel Press) ZOOM Edit&Share for Windows (HKLM-x32\...\{E99B8E1C-262D-49E6-9A84-D2AC486B2648}) (Version: 5.00.0000 - ZOOM Corporation) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-660726629-327130963-595889159-1006_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Peter\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-660726629-327130963-595889159-1006_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Peter\AppData\Roaming\Dropbox\bin\DropboxExt64.38.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-660726629-327130963-595889159-1006_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Peter\AppData\Roaming\Dropbox\bin\DropboxExt64.38.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-660726629-327130963-595889159-1006_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Peter\AppData\Roaming\Dropbox\bin\DropboxExt64.38.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-660726629-327130963-595889159-1006_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Peter\AppData\Roaming\Dropbox\bin\DropboxExt64.38.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-660726629-327130963-595889159-1006_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Peter\AppData\Roaming\Dropbox\bin\DropboxExt64.38.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-660726629-327130963-595889159-1006_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Peter\AppData\Roaming\Dropbox\bin\DropboxExt64.38.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-660726629-327130963-595889159-1006_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Peter\AppData\Roaming\Dropbox\bin\DropboxExt64.38.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-660726629-327130963-595889159-1006_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Peter\AppData\Roaming\Dropbox\bin\DropboxExt64.38.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-660726629-327130963-595889159-1006_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Peter\AppData\Roaming\Dropbox\bin\DropboxExt64.38.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-660726629-327130963-595889159-1006_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\Peter\AppData\Roaming\Dropbox\bin\DropboxExt64.38.dll (Dropbox, Inc.) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {04D5BBC7-B216-48D1-AF52-2D398994529C} - System32\Tasks\RPJDMDJF => Rundll32.exe "C:\Windows\SysWOW64\EhStorAPIR.dll",bfjjncyw Task: {2F7EC016-EEB2-4BD5-9410-FC5EC9F1862B} - System32\Tasks\{5EFE98F3-F302-4706-B831-E0601D13B031} => pcalua.exe -a C:\Windows\iun6002.exe -c "C:\Users\peter_m\Documents\EA Games\The Sims 2\irunin.ini" <==== ATTENTION Task: {32D072FF-A3B7-4BB3-AAD7-343C8CD6EE01} - \GPUpdateCheck -> No File <==== ATTENTION Task: {3AF7D6B8-F0DF-4916-8F56-80938E3F1B93} - System32\Tasks\Ad-Aware Update (Weekly) => C:\Program Files (x86)\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe Task: {40AE45B2-A40F-48EA-9E3F-0DC58153107D} - System32\Tasks\{2E0C17C9-332E-4E52-BEA3-9EADB81373D3} => pcalua.exe -a "C:\Remote Programs\7 Wonders 2\GPlrLanc.exe" -c -LOpCode 2 /RemoveContent cid=586350;name=7 Wonders II;dir=C:\Remote Programs\7 Wonders 2\;prvid=143;cmdid=1;prvdir=Default Task: {52BA27AB-474F-4663-B7C5-02A76B51928D} - System32\Tasks\{F2ACA42B-2C3A-4163-8877-C47A0C2B0FA6} => pcalua.exe -a D:\Setup.exe -d D:\ Task: {5BAACA48-D86F-4CB0-89E5-FA84D1FA1E08} - System32\Tasks\Adobe Reader and Acrobat Manager MAGIX PCCT => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-07-07] (Adobe Systems Incorporated) Task: {5C3F9962-B7A1-43AC-9580-07FC2CA6FF97} - System32\Tasks\{DE770AFA-4ADA-44D6-BB80-E763A03CF7F1} => pcalua.exe -a "C:\Users\Peter\Documents\Office 2010\setup.exe" -d "C:\Users\Peter\Documents\Office 2010" Task: {61B92FDA-E562-4C1B-A87D-790A678F77CF} - System32\Tasks\{A9C46FAA-DC81-4F80-BF59-04C64C78ECAC} => pcalua.exe -a D:\setup.exe -d D:\ Task: {65874B8F-BA2B-4F02-BC01-88E301E7BD30} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2015-08-27] (Apple Inc.) Task: {6AEA604D-FA6E-4C52-B773-19AD208AF7D3} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-07-07] (Adobe Systems Incorporated) Task: {6D99C160-68CB-47BE-989B-7D6CB175013E} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: {729C7572-5338-40CD-8385-8303118D3E62} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-07-15] (Adobe Systems Incorporated) Task: {7FD4319D-B9E3-4EB5-B657-382CC7576EB8} - System32\Tasks\Ad-Aware Antivirus Scheduled Scan => C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareLauncher.exe [2012-12-14] (Lavasoft Limited) Task: {80BD6481-ADC6-4C0D-85EA-4FB735DDBE34} - System32\Tasks\{AEA1D9EE-8885-4E77-B5A5-BE8869B1ACCE} => pcalua.exe -a "C:\ProgramData\Citrix\Citrix Receiver\TrolleyExpress.exe" -c /uninstall /cleanup Task: {8C62C8F6-B15B-4D2C-B362-B87A73F83125} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: {AD187006-35A3-4CAC-B8E2-94A83D2AC9E2} - System32\Tasks\{025CE0C7-FD46-4A6B-842A-0CB534D52420} => pcalua.exe -a C:\Users\peter_m\Documents\videorepair\gs.exe -d C:\Users\peter_m\Documents\videorepair Task: {D289A1B2-6963-42FF-AAB1-DC16757F37D8} - System32\Tasks\Software Manager MAGIX PCCT => C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [2010-05-21] (Flexera Software, Inc.) Task: {D8B9898A-4EC2-46E3-ACF2-74E1148D2C21} - System32\Tasks\HP Photo Creations Communicator => C:\ProgramData\HP Photo Creations\Communicator.exe [2013-09-08] () Task: {DD38D63C-D1B5-4566-A892-DFCADFB921ED} - System32\Tasks\{72658F51-728B-4975-BBA5-4D9BC0F68EA3} => pcalua.exe -a "C:\Program Files (x86)\Research In Motion\BlackBerry Desktop\InstallerUtils\InstallerUtils.exe" -c /UninstallDesktop Task: {E768155D-C4DD-4598-8682-98B6242366FA} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-660726629-327130963-595889159-1006Core => C:\Users\Peter\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-07-12] (Dropbox, Inc.) Task: {EE062578-D107-4128-942C-2FB53BDF261A} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-660726629-327130963-595889159-1006UA => C:\Users\Peter\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-07-12] (Dropbox, Inc.) Task: {F389DB12-4D83-4D6C-B04A-0105D8281F80} - System32\Tasks\HPCustParticipation HP Deskjet 3050A J611 series => C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\HPCustPartic.exe [2011-03-30] (Hewlett-Packard Co.) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\Ad-Aware Update (Weekly).job => C:\Program Files (x86)\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\Adobe Reader and Acrobat Manager MAGIX PCCT.job => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-660726629-327130963-595889159-1006Core.job => C:\Users\Peter\AppData\Local\Dropbox\Update\DropboxUpdate.exe Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-660726629-327130963-595889159-1006UA.job => C:\Users\Peter\AppData\Local\Dropbox\Update\DropboxUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\HP Photo Creations Communicator.job => C:\ProgramData\HP Photo Creations\Communicator.exe Task: C:\Windows\Tasks\RPJDMDJF.job => rundll32.exe C:\Windows\SysWOW64\EhStorAPIR.dll Task: C:\Windows\Tasks\Software Manager MAGIX PCCT.job => C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) Shortcut: C:\Users\Peter\Favorites\NCH Software Download Site.lnk -> hxxp://www.nchsoftware.com/index.html ==================== Loaded Modules (Whitelisted) ============== 2010-12-23 15:33 - 2010-12-23 15:33 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\Libeay32.dll 2014-03-10 11:58 - 2005-03-12 01:07 - 00087040 _____ () C:\Windows\System32\pdfcmnnt.dll 2013-09-05 01:17 - 2013-09-05 01:17 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF 2010-10-20 15:23 - 2010-10-20 15:23 - 08801632 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll 2016-08-17 08:01 - 2016-08-17 08:01 - 21076552 _____ () C:\Users\Peter\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IGXF92R6\RogueKiller.exe 2014-02-12 20:58 - 2014-02-12 20:58 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2015-12-17 19:39 - 2015-12-17 19:39 - 01040144 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2007-04-18 20:30 - 2007-04-18 20:30 - 00393216 _____ () C:\Program Files (x86)\McAfee\Common Framework\cryptocme2.dll 2007-04-18 20:30 - 2007-04-18 20:30 - 00471040 _____ () C:\Program Files (x86)\McAfee\Common Framework\ccme_base.dll 2011-01-12 17:05 - 2011-01-12 17:05 - 00065536 _____ () C:\Program Files (x86)\McAfee\Common Framework\boost_thread-vc80-mt-1_32.dll 2011-01-12 09:08 - 2011-01-12 09:08 - 00150032 _____ () C:\Program Files (x86)\McAfee\VirusScan Enterprise\WscAv.dll 2013-09-05 01:14 - 2013-09-05 01:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF 2010-10-20 15:45 - 2010-10-20 15:45 - 08801120 _____ () C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll 2013-02-09 13:04 - 2014-06-20 06:08 - 00192376 _____ () C:\Program Files (x86)\Ad-Aware Antivirus\Definitions\libBase64.dll 2013-02-09 13:04 - 2014-06-20 06:08 - 00180088 _____ () C:\Program Files (x86)\Ad-Aware Antivirus\Definitions\libMachoUniv.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\ProgramData\Microsoft:mEjDsL0uMgEwM7GRo4PIoaJih [2368] AlternateDataStreams: C:\ProgramData\Microsoft:sG0dOEUFENODBXNBM9APD5IeanG [2174] AlternateDataStreams: C:\ProgramData\Temp:890CC2F3 [127] AlternateDataStreams: C:\Users\Peter\Cookies:49ChnLA3T7ad366VE2V [2066] AlternateDataStreams: C:\Users\Peter\Cookies:4Pwp27sRecEe4GmyPiuMiqwaeg [2104] AlternateDataStreams: C:\Users\Peter\AppData\Local\Temp:3S2ZpMP3tB5KOhQrA9sx2 [2328] AlternateDataStreams: C:\Users\peter_m\Cookies:49ChnLA3T7ad366VE2V [2420] AlternateDataStreams: C:\Users\peter_m\Cookies:4Pwp27sRecEe4GmyPiuMiqwaeg [2312] AlternateDataStreams: C:\Users\peter_m\Local Settings:hAp8Qvx27Nnf9W6pq1IzJsZ4MB [2208] AlternateDataStreams: C:\Users\peter_m\AppData\Local:hAp8Qvx27Nnf9W6pq1IzJsZ4MB [2208] AlternateDataStreams: C:\Users\peter_m\AppData\Local\2fARNf39WQxb3vI:do74RPQ0DR3UmOR3IFkGx4o [2120] AlternateDataStreams: C:\Users\peter_m\AppData\Local\Application Data:hAp8Qvx27Nnf9W6pq1IzJsZ4MB [2208] AlternateDataStreams: C:\Users\peter_m\AppData\Local\Temp:3S2ZpMP3tB5KOhQrA9sx2 [2000] AlternateDataStreams: C:\Users\peter_m\AppData\Local\Temporary Internet Files:5NBvyQjjA178oWmzgCOYVUVwA1 [2398] AlternateDataStreams: C:\Users\peter_m\AppData\Local\Temporary Internet Files:v6RxbrdO3U1tUiMVq4QLlEfpNhx [2300] ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\15206930.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ad-Aware Service => ""="Ad-Aware Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\15206930.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Ad-Aware Service => ""="Ad-Aware Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MSIServer => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SBAMSvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver" ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) IE trusted site: HKU\S-1-5-21-660726629-327130963-595889159-1006\...\dell.com -> dell.com ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2012-03-16 20:41 - 2015-08-13 10:03 - 00001213 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost127.0.0.1 3dns.adobe.com 3dns-1.adobe.com 3dns-2.adobe.com 3dns-3.adobe.com 3dns-4.adobe.com activate.adobe.com activate-sea.adobe.com activate-sjc0.adobe.com activate.wip.adobe.com 127.0.0.1 activate.wip1.adobe.com activate.wip2.adobe.com activate.wip3.adobe.com activate.wip4.adobe.com adobe-dns.adobe.com adobe-dns-1.adobe.com adobe-dns-2.adobe.com adobe-dns-3.adobe.com adobe-dns-4.adobe.com 127.0.0.1 adobeereg.com practivate.adobe practivate.adobe.com practivate.adobe.newoa practivate.adobe.ntp practivate.adobe.ipp ereg.adobe.com ereg.wip.adobe.com ereg.wip1.adobe.com 127.0.0.1 ereg.wip2.adobe.com ereg.wip3.adobe.com ereg.wip4.adobe.com hl2rcv.adobe.com wip.adobe.com wip1.adobe.com wip2.adobe.com wip3.adobe.com wip4.adobe.com 127.0.0.1 www.adobeereg.com wwis-dubc1-vip60.adobe.com www.wip.adobe.com www.wip1.adobe.com 127.0.0.1 www.wip2.adobe.com www.wip3.adobe.com www.wip4.adobe.com wwis-dubc1-vip60.adobe.com crl.verisign.net CRL.VERISIGN.NET ood.opsource.net ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-660726629-327130963-595889159-1006\Control Panel\Desktop\\Wallpaper -> C:\Users\Peter\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.2.1 - [removed] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) MSCONFIG\Services: NVSvc => 2 MSCONFIG\Services: nvUpdatusService => 3 MSCONFIG\Services: O2FLASH => 2 MSCONFIG\Services: O2SDIOAssist => 2 MSCONFIG\Services: RoxMediaDB12OEM => 3 MSCONFIG\Services: RoxMediaDBVHS => 3 MSCONFIG\Services: RoxWatch12 => 2 MSCONFIG\Services: SBAMSvc => 2 MSCONFIG\Services: SBSDWSCService => 2 MSCONFIG\Services: SecureStorageService => 3 MSCONFIG\Services: Sony SCSI Helper Service => 3 MSCONFIG\Services: STacSV => 2 MSCONFIG\Services: Steam Client Service => 3 MSCONFIG\Services: Stereo Service => 3 MSCONFIG\Services: stllssvr => 3 MSCONFIG\Services: tcsd_win32.exe => 2 MSCONFIG\Services: TdmService => 2 MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk => C:\Windows\pss\Bluetooth.lnk.CommonStartup MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Dell System Manager.lnk => C:\Windows\pss\Dell System Manager.lnk.CommonStartup MSCONFIG\startupfolder: C:^Users^peter_m^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^LaunchU3.exe.lnk => C:\Windows\pss\LaunchU3.exe.lnk.Startup MSCONFIG\startupfolder: C:^Users^peter_m^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2010 Screen Clipper and Launcher.lnk => C:\Windows\pss\OneNote 2010 Screen Clipper and Launcher.lnk.Startup MSCONFIG\startupfolder: C:^Users^peter_m^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^PowerReg Scheduler V3.exe => C:\Windows\pss\PowerReg Scheduler V3.exe.Startup MSCONFIG\startupreg: Acrobat Assistant 8.0 => "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe" MSCONFIG\startupreg: Ad-Aware Antivirus => "C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareLauncher" --windows-run MSCONFIG\startupreg: Ad-Aware Browsing Protection => "C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe" MSCONFIG\startupreg: Adobe Acrobat Speed Launcher => "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe" MSCONFIG\startupreg: AdobeAAMUpdater-1.0 => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe MSCONFIG\startupreg: Apoint => C:\Program Files\DellTPad\Apoint.exe MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" MSCONFIG\startupreg: BCSSync => "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices MSCONFIG\startupreg: ConnectionCenter => "C:\Program Files (x86)\Citrix\ICA Client\concentr.exe" /startup MSCONFIG\startupreg: DBRMTray => C:\Dell\DBRM\Reminder\DbrmTrayIcon.exe MSCONFIG\startupreg: Dell Webcam Central => "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2 MSCONFIG\startupreg: Desktop Disc Tool => "C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe" MSCONFIG\startupreg: DigidesignMMERefresh => C:\Program Files (x86)\Digidesign\Drivers\MMERefresh.exe MSCONFIG\startupreg: EA Core => "C:\Program Files (x86)\Electronic Arts\EADM\Core.exe" -silent MSCONFIG\startupreg: Freecorder FLV Service => "C:\Program Files (x86)\Freecorder\FLVSrvc.exe" /run MSCONFIG\startupreg: HF_G_Jul => "C:\Program Files (x86)\AVG Secure Search\HF_G_Jul.exe" /DoAction MSCONFIG\startupreg: HotKeysCmds => C:\Windows\system32\hkcmd.exe MSCONFIG\startupreg: HP Deskjet 3050A J611 series (NET) => "C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN1674B3N405PJ:NW" -scfn "HP Deskjet 3050A J611 series (NET)" -AutoStart 1 MSCONFIG\startupreg: IgfxTray => C:\Windows\system32\igfxtray.exe MSCONFIG\startupreg: IMSS => "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe" MSCONFIG\startupreg: IntelPROSet => "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel PROSet/Wireless MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe" MSCONFIG\startupreg: LifeCam => "C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe" MSCONFIG\startupreg: M-Audio Taskbar Icon => C:\Windows\system32\M-AudioTaskBarIcon.exe MSCONFIG\startupreg: McAfeeUpdaterUI => "C:\Program Files (x86)\McAfee\Common Framework\udaterui.exe" /StartedFromRunKey MSCONFIG\startupreg: NVHotkey => rundll32.exe C:\Windows\system32\nvHotkey.dll,Start MSCONFIG\startupreg: Path => "C:\Program Files (x86)\ZOOM\Edit_Share\bin\ZOOM Edit&Share startup.exe" MSCONFIG\startupreg: Persistence => C:\Windows\system32\igfxpers.exe MSCONFIG\startupreg: Reader Application Helper => C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\ReaderAppHelper.exe MSCONFIG\startupreg: RemoteControl9 => "C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe" MSCONFIG\startupreg: RESTART_STICKY_NOTES => C:\Windows\System32\StikyNot.exe MSCONFIG\startupreg: ROC_ROC_JULY_P1 => "C:\Program Files (x86)\AVG Secure Search\ROC_ROC_JULY_P1.exe" / /PROMPT /CMPID=ROC_JULY_P1 MSCONFIG\startupreg: RoxWatchTray => "C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe" MSCONFIG\startupreg: ShStatEXE => "C:\Program Files (x86)\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE MSCONFIG\startupreg: Sidebar => C:\Program Files\Windows Sidebar\sidebar.exe /autoRun MSCONFIG\startupreg: SysTrayApp => C:\Program Files\IDT\WDM\sttray64.exe MSCONFIG\startupreg: VX1000 => C:\Windows\vVX1000.exe ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe FirewallRules: [TCP Query User{3FFBE3D4-7E6D-48BA-9E84-30125F450FA4}C:\program files\hp\hp deskjet 3050a j611 series\bin\hpnetworkcommunicator.exe] => (Allow) C:\program files\hp\hp deskjet 3050a j611 series\bin\hpnetworkcommunicator.exe FirewallRules: [UDP Query User{C92688A7-A562-4A51-8C13-B11FB59D9870}C:\program files\hp\hp deskjet 3050a j611 series\bin\hpnetworkcommunicator.exe] => (Allow) C:\program files\hp\hp deskjet 3050a j611 series\bin\hpnetworkcommunicator.exe FirewallRules: [TCP Query User{CC08221B-39CB-49CA-947F-2BBC5E855361}C:\program files\hp\hp deskjet 3050a j611 series\bin\hpnetworkcommunicator.exe] => (Allow) C:\program files\hp\hp deskjet 3050a j611 series\bin\hpnetworkcommunicator.exe FirewallRules: [UDP Query User{7BF3F08A-55D2-4858-94A5-BC95AFB9EB01}C:\program files\hp\hp deskjet 3050a j611 series\bin\hpnetworkcommunicator.exe] => (Allow) C:\program files\hp\hp deskjet 3050a j611 series\bin\hpnetworkcommunicator.exe FirewallRules: [{12657F7F-EB17-4FDE-BDCD-3D5060967721}] => (Allow) C:\Program Files (x86)\McAfee\Common Framework\FrameworkService.exe FirewallRules: [{6B1FA960-A977-4C2A-AA3D-A9624DA152A3}] => (Allow) C:\Program Files (x86)\McAfee\Common Framework\FrameworkService.exe FirewallRules: [{3842A35F-DE4A-490E-ABE5-F377757C05E4}] => (Allow) C:\Program Files (x86)\McAfee\Common Framework\FrameworkService.exe FirewallRules: [{6756B1D7-9F16-4DCF-838B-EAC2567E1D6F}] => (Allow) C:\Program Files (x86)\McAfee\Common Framework\FrameworkService.exe FirewallRules: [{4FB94588-4F4E-473A-91C6-5EE1CE0A88DA}] => (Allow) C:\Program Files (x86)\McAfee\Common Framework\FrameworkService.exe FirewallRules: [{CC7A8D19-4558-484C-8B8C-4A6DB56A3E84}] => (Allow) C:\Program Files (x86)\McAfee\Common Framework\FrameworkService.exe FirewallRules: [TCP Query User{0ED22F75-8299-4146-A127-9CCCE90080EB}C:\program files (x86)\secondlifeviewer\slvoice.exe] => (Allow) C:\program files (x86)\secondlifeviewer\slvoice.exe FirewallRules: [UDP Query User{AFF1FCE0-7F69-4CF8-8A5F-0C5B521848AF}C:\program files (x86)\secondlifeviewer\slvoice.exe] => (Allow) C:\program files (x86)\secondlifeviewer\slvoice.exe FirewallRules: [{6D5861B8-1E87-4A5D-8737-4BD60D80153F}] => (Allow) C:\Program Files\Internet Explorer\iexplore.exe FirewallRules: [{6A1E6E2E-098B-4EC3-AF2B-7DF24A97E6A7}] => (Allow) C:\Program Files\Internet Explorer\iexplore.exe FirewallRules: [TCP Query User{B205792B-1D38-4BED-8249-9809410D1802}C:\program files (x86)\frostwire 5\frostwire.exe] => (Block) C:\program files (x86)\frostwire 5\frostwire.exe FirewallRules: [UDP Query User{7CF19403-1D20-4FDD-B5CC-47D558E6EF37}C:\program files (x86)\frostwire 5\frostwire.exe] => (Block) C:\program files (x86)\frostwire 5\frostwire.exe FirewallRules: [{D197E854-0D87-496D-AC2B-51E594B4B0BC}] => (Allow) C:\Program Files (x86)\FrostWire 5\FrostWire.exe FirewallRules: [{F0D7D1B9-ACBA-4853-97D2-F93F3EA7A36D}] => (Allow) C:\Program Files (x86)\FrostWire 5\FrostWire.exe FirewallRules: [{6630C9F2-D4CD-4C3E-9DDB-971BE7CC66DB}] => (Allow) C:\Users\peter_m\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [{96BFF04F-6E5D-4D7A-979D-DF6F242A1E86}] => (Allow) C:\Users\peter_m\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [{79C950F0-DA4F-419C-8742-9A1905E20054}] => (Allow) C:\Users\peter_m\AppData\Roaming\BitTorrent\BitTorrent.exe FirewallRules: [{83F35B80-2657-4AD6-8A80-54233C8974E3}] => (Allow) C:\Users\peter_m\AppData\Roaming\BitTorrent\BitTorrent.exe FirewallRules: [TCP Query User{7D8B3DBF-EC96-44AE-BFF5-0E3C5308006B}C:\program files (x86)\java\jre7\launch4j-tmp\mimo.exe] => (Allow) C:\program files (x86)\java\jre7\launch4j-tmp\mimo.exe FirewallRules: [UDP Query User{11DB4BEA-F030-44DF-A34B-261777D9D9E9}C:\program files (x86)\java\jre7\launch4j-tmp\mimo.exe] => (Allow) C:\program files (x86)\java\jre7\launch4j-tmp\mimo.exe FirewallRules: [TCP Query User{D8D7AEB9-DA68-4CEA-8656-6304B09ECEE1}C:\program files (x86)\java\jre7\launch4j-tmp\mimo.exe] => (Allow) C:\program files (x86)\java\jre7\launch4j-tmp\mimo.exe FirewallRules: [UDP Query User{81049102-FA7C-4BAB-808A-8ADFE76A3F1F}C:\program files (x86)\java\jre7\launch4j-tmp\mimo.exe] => (Allow) C:\program files (x86)\java\jre7\launch4j-tmp\mimo.exe FirewallRules: [{770860E6-BD78-481C-B0D6-13BF1DF24A8A}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{073B194C-3C4A-4C0B-A05A-4EA901824B15}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{82CE8558-61C2-4BFC-962A-782B72FF9846}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\RollerCoaster Tycoon Deluxe\RCT.EXE FirewallRules: [{779A55AD-B4EF-4C65-B246-D53D8CFF3F5B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\RollerCoaster Tycoon Deluxe\RCT.EXE FirewallRules: [{C27583F9-1C69-490F-A218-B48026822D4E}] => (Allow) C:\Program Files (x86)\Research In Motion\BlackBerry Desktop\Rim.Desktop.exe FirewallRules: [{723473DF-A227-471E-A9C3-D3231E9FB1B5}] => (Allow) C:\Program Files (x86)\Research In Motion\BlackBerry Desktop\Rim.Desktop.exe FirewallRules: [{E6AE8CAB-FFB1-41A8-B912-B90710EC5871}] => (Allow) LPort=4481 FirewallRules: [{A8FCAA2F-8DAA-4249-AE5A-FE9385318364}] => (Allow) LPort=4481 FirewallRules: [{6954DC26-FF25-42A5-AD2A-EAD6E2FC5B0D}] => (Allow) LPort=4482 FirewallRules: [{7B5C3D8E-B2EF-499D-98DB-76BDD2D62710}] => (Allow) LPort=4482 FirewallRules: [{91BFEA63-2EAE-4962-B318-E0D0316A9863}] => (Allow) C:\Program Files (x86)\iTunes\iTunes.exe FirewallRules: [TCP Query User{7910A946-A4A1-4A8D-8E91-F3D95C5D2F9D}C:\program files (x86)\citrix\ica client\wfica32.exe] => (Allow) C:\program files (x86)\citrix\ica client\wfica32.exe FirewallRules: [UDP Query User{9C3AF545-4F25-432B-9C1E-F596E5C6724B}C:\program files (x86)\citrix\ica client\wfica32.exe] => (Allow) C:\program files (x86)\citrix\ica client\wfica32.exe FirewallRules: [{3C37C116-2163-4919-829D-1F7BAA576D64}] => (Allow) C:\Program Files (x86)\FrostWire 6\FrostWire.exe FirewallRules: [{EF1CB827-7CF8-4377-8124-2753EB0B4BED}] => (Allow) C:\Program Files (x86)\FrostWire 6\FrostWire.exe FirewallRules: [{B75313C8-99A0-4AEA-A711-20ACF5888D86}] => (Allow) C:\Program Files (x86)\FrostWire\FrostWire.exe FirewallRules: [{D00CED12-B760-4C2A-86A5-4A67E72F994E}] => (Allow) C:\Program Files (x86)\FrostWire\FrostWire.exe FirewallRules: [{C04B20B3-006C-4367-852F-8DB7E8E897B0}] => (Allow) C:\Windows\SysWOW64\rundll32.exe FirewallRules: [{1F60EBBB-8CFA-4EA7-9A01-AB89A02FF767}] => (Allow) C:\Windows\SysWOW64\rundll32.exe FirewallRules: [{0E1C73A9-C257-409A-9DF2-FAACEF86E44C}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{5F81A90F-7B92-4DE8-B531-0A39920B9107}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{14171879-579C-4E0B-A226-B92B2D50F813}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{80C6EDE1-16B4-4774-B59D-39ED7E3C82A4}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{0AE82A46-BD59-497F-9C2A-799D44BB4101}] => (Allow) C:\Program Files (x86)\DVDVideoSoft\Free Torrent Download\FreeTorrentDownload.exe FirewallRules: [{CAF23D18-272B-4717-AA9A-0223BCC8F0AB}] => (Allow) C:\Program Files (x86)\DVDVideoSoft\Free Torrent Download\FreeTorrentDownload.exe FirewallRules: [{0B9652D5-2687-4BA5-BA84-61FE09916DF0}] => (Allow) C:\Windows\SysWOW64\rundll32.exe FirewallRules: [{EE3AEB16-3161-4838-AD75-2CECD6C5B083}] => (Allow) C:\Windows\SysWOW64\rundll32.exe ==================== Restore Points ========================= ==================== Faulty Device Manager Devices ============= Name: Integrated Webcam Description: USB Video Device Class Guid: {6bdd1fc6-810f-11d0-bec7-08002be2092f} Manufacturer: Microsoft Service: usbvideo Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Dell Wireless 375 Bluetooth Module Description: Dell Wireless 375 Bluetooth Module Class Guid: {e0cbf06c-cd8b-4647-bb8a-263b43f0f974} Manufacturer: Broadcom Service: BTHUSB Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (08/17/2016 10:46:51 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: rundll32.exe, version: 6.1.7600.16385, time stamp: 0x4a5bc637 Faulting module name: Flash32_22_0_0_210.ocx, version: 22.0.0.210, time stamp: 0x57858ce4 Exception code: 0xc0000005 Fault offset: 0x00230050 Faulting process id: 0xd78 Faulting application start time: 0xrundll32.exe0 Faulting application path: rundll32.exe1 Faulting module path: rundll32.exe2 Report Id: rundll32.exe3 Error: (08/17/2016 09:11:57 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: AdblockPlusEngine.exe, version: 1.4.0.0, time stamp: 0x54edf945 Faulting module name: ntdll.dll, version: 6.1.7601.23418, time stamp: 0x5708a857 Exception code: 0xc0000374 Fault offset: 0x00000000000bf262 Faulting process id: 0x1478 Faulting application start time: 0xAdblockPlusEngine.exe0 Faulting application path: AdblockPlusEngine.exe1 Faulting module path: AdblockPlusEngine.exe2 Report Id: AdblockPlusEngine.exe3 Error: (08/16/2016 12:33:33 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: rundll32.exe, version: 6.1.7600.16385, time stamp: 0x4a5bc637 Faulting module name: Flash32_22_0_0_210.ocx, version: 22.0.0.210, time stamp: 0x57858ce4 Exception code: 0xc0000005 Fault offset: 0x0079e5bc Faulting process id: 0x1ab4 Faulting application start time: 0xrundll32.exe0 Faulting application path: rundll32.exe1 Faulting module path: rundll32.exe2 Report Id: rundll32.exe3 Error: (08/16/2016 09:29:47 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: rundll32.exe, version: 6.1.7600.16385, time stamp: 0x4a5bc637 Faulting module name: Flash32_22_0_0_210.ocx, version: 22.0.0.210, time stamp: 0x57858ce4 Exception code: 0xc0000005 Fault offset: 0x001501a3 Faulting process id: 0x18e4 Faulting application start time: 0xrundll32.exe0 Faulting application path: rundll32.exe1 Faulting module path: rundll32.exe2 Report Id: rundll32.exe3 Error: (08/16/2016 02:09:03 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: rundll32.exe, version: 6.1.7600.16385, time stamp: 0x4a5bc637 Faulting module name: jscript9.dll, version: 11.0.9600.18427, time stamp: 0x57a02dab Exception code: 0xc0000005 Fault offset: 0x00157731 Faulting process id: 0xeec Faulting application start time: 0xrundll32.exe0 Faulting application path: rundll32.exe1 Faulting module path: rundll32.exe2 Report Id: rundll32.exe3 Error: (08/15/2016 05:06:15 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: IEXPLORE.EXE, version: 11.0.9600.18427, time stamp: 0x57a02609 Faulting module name: AdblockPlus32.dll, version: 1.4.0.0, time stamp: 0x54edf8a0 Exception code: 0xc0000005 Fault offset: 0x0001c9d3 Faulting process id: 0x1c50 Faulting application start time: 0xIEXPLORE.EXE0 Faulting application path: IEXPLORE.EXE1 Faulting module path: IEXPLORE.EXE2 Report Id: IEXPLORE.EXE3 Error: (08/15/2016 05:06:14 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: IEXPLORE.EXE, version: 11.0.9600.18427, time stamp: 0x57a02609 Faulting module name: AdblockPlus32.dll, version: 1.4.0.0, time stamp: 0x54edf8a0 Exception code: 0xc000041d Fault offset: 0x0000fb9c Faulting process id: 0x1c50 Faulting application start time: 0xIEXPLORE.EXE0 Faulting application path: IEXPLORE.EXE1 Faulting module path: IEXPLORE.EXE2 Report Id: IEXPLORE.EXE3 Error: (08/15/2016 05:06:04 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: IEXPLORE.EXE, version: 11.0.9600.18427, time stamp: 0x57a02609 Faulting module name: AdblockPlus32.dll, version: 1.4.0.0, time stamp: 0x54edf8a0 Exception code: 0xc0000005 Fault offset: 0x0000fb9c Faulting process id: 0x1c50 Faulting application start time: 0xIEXPLORE.EXE0 Faulting application path: IEXPLORE.EXE1 Faulting module path: IEXPLORE.EXE2 Report Id: IEXPLORE.EXE3 Error: (08/14/2016 08:29:57 AM) (Source: System Restore) (EventID: 8193) (User: ) Description: Failed to create restore point (Process = C:\Program Files (x86)\MAGIX\PC_Check_Tuning_2012_Download_Version\TuningStart.exe Files (x86)\MAGIX\PC_Check_Tuning_2012_Download_Version\TuningStart.exe" ; Description = MAGIX PC Check & Tuning 2012 (PC Check); Error = 0x8007043c). Error: (08/12/2016 10:41:33 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: rundll32.exe, version: 6.1.7600.16385, time stamp: 0x4a5bc637 Faulting module name: jscript9.dll, version: 11.0.9600.18427, time stamp: 0x57a02dab Exception code: 0xc0000005 Fault offset: 0x001575b6 Faulting process id: 0x1404 Faulting application start time: 0xrundll32.exe0 Faulting application path: rundll32.exe1 Faulting module path: rundll32.exe2 Report Id: rundll32.exe3 System errors: ============= Error: (08/17/2016 09:15:21 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The Digital Wave Update Service service terminated unexpectedly. It has done this 1 time(s). Error: (08/17/2016 09:03:57 AM) (Source: Microsoft-Windows-GroupPolicy) (EventID: 1129) (User: NT AUTHORITY) Description: The processing of Group Policy failed because of lack of network connectivity to a domain controller. This may be a transient condition. A success message would be generated once the machine gets connected to the domain controller and Group Policy has succesfully processed. If you do not see a success message for several hours, then contact your administrator. Error: (08/17/2016 08:02:03 AM) (Source: Application Popup) (EventID: 1060) (User: ) Description: \??\C:\Windows\System32\drivers\TrueSight.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver. Error: (08/17/2016 07:38:39 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY) Description: Installation Failure: Windows failed to install the following update with error 0x80070643: Security Update for Microsoft Visual C++ 2008 Service Pack 1 Redistributable Package (KB2538243). Error: (08/17/2016 07:33:52 AM) (Source: volsnap) (EventID: 14) (User: ) Description: The shadow copies of volume C: were aborted because of an IO failure on volume C:. Error: (08/17/2016 07:25:52 AM) (Source: Microsoft-Windows-GroupPolicy) (EventID: 1055) (User: NT AUTHORITY) Description: The processing of Group Policy failed. Windows could not resolve the computer name. This could be caused by one of more of the following: a) Name Resolution failure on the current domain controller. b) Active Directory Replication Latency (an account created on another domain controller has not replicated to the current domain controller). Error: (08/17/2016 07:25:41 AM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: The Windows Time service terminated with the following error: %%1792 = An attempt was made to logon, but the network logon service was not started. Error: (08/17/2016 07:25:41 AM) (Source: Microsoft-Windows-Time-Service) (EventID: 46) (User: NT AUTHORITY) Description: The time service encountered an error and was forced to shut down. The error was: 0x80070700: An attempt was made to logon, but the network logon service was not started. Error: (08/17/2016 07:25:35 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The MSCamSvc service failed to start due to the following error: %%2 = The system cannot find the file specified. Error: (08/17/2016 07:25:21 AM) (Source: EventLog) (EventID: 6008) (User: ) Description: The previous system shutdown at 6:49:38 PM on ‎16/‎08/‎2016 was unexpected. CodeIntegrity: =================================== Date: 2016-08-15 19:13:46.009 Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume3\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\amd64_microsoft-windows-errorreportingfaults_31bf3856ad364e35_10.0.10074.1_none_f3153036f55ab3f5\werfault.exe because the signing certificate has been revoked. Check with the publisher to see if a new signed version of the kernel module is available. Date: 2016-08-15 19:13:46.009 Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume3\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\amd64_microsoft-windows-errorreportingfaults_31bf3856ad364e35_10.0.10074.1_none_f3153036f55ab3f5\werfault.exe because the signing certificate has been revoked. Check with the publisher to see if a new signed version of the kernel module is available. Date: 2016-08-15 19:13:46.009 Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume3\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\amd64_microsoft-windows-errorreportingfaults_31bf3856ad364e35_10.0.10074.1_none_f3153036f55ab3f5\werfault.exe because the signing certificate has been revoked. Check with the publisher to see if a new signed version of the kernel module is available. Date: 2016-08-15 19:13:45.993 Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume3\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\amd64_microsoft-windows-errorreportingfaults_31bf3856ad364e35_10.0.10074.1_none_f3153036f55ab3f5\werfault.exe because the signing certificate has been revoked. Check with the publisher to see if a new signed version of the kernel module is available. Date: 2016-08-15 19:13:45.978 Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume3\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\amd64_microsoft-windows-errorreportingfaults_31bf3856ad364e35_10.0.10074.1_none_f3153036f55ab3f5\werfault.exe because the signing certificate has been revoked. Check with the publisher to see if a new signed version of the kernel module is available. Date: 2016-08-15 19:13:45.978 Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume3\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\amd64_microsoft-windows-errorreportingfaults_31bf3856ad364e35_10.0.10074.1_none_f3153036f55ab3f5\werfault.exe because the signing certificate has been revoked. Check with the publisher to see if a new signed version of the kernel module is available. Date: 2016-08-15 19:13:45.572 Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume3\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\x86_microsoft-windows-errorreportingfaults_31bf3856ad364e35_10.0.10074.1_none_96f694b33cfd42bf\werfault.exe because the signing certificate has been revoked. Check with the publisher to see if a new signed version of the kernel module is available. Date: 2016-08-15 19:13:45.557 Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume3\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\x86_microsoft-windows-errorreportingfaults_31bf3856ad364e35_10.0.10074.1_none_96f694b33cfd42bf\werfault.exe because the signing certificate has been revoked. Check with the publisher to see if a new signed version of the kernel module is available. Date: 2016-08-15 19:13:45.557 Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume3\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\x86_microsoft-windows-errorreportingfaults_31bf3856ad364e35_10.0.10074.1_none_96f694b33cfd42bf\werfault.exe because the signing certificate has been revoked. Check with the publisher to see if a new signed version of the kernel module is available. Date: 2016-08-15 19:13:45.541 Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume3\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\x86_microsoft-windows-errorreportingfaults_31bf3856ad364e35_10.0.10074.1_none_96f694b33cfd42bf\werfault.exe because the signing certificate has been revoked. Check with the publisher to see if a new signed version of the kernel module is available. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i7-2620M CPU @ 2.70GHz Percentage of memory in use: 67% Total physical RAM: 4052.9 MB Available physical RAM: 1336.57 MB Total Virtual: 8103.98 MB Available Virtual: 4625.84 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:287.75 GB) (Free:64.04 GB) NTFS Drive e: () (Removable) (Total:29.82 GB) (Free:14.7 GB) FAT32 ==================== MBR & Partition Table ================== ==================== End of Addition.txt ============================