Additional scan result of Farbar Recovery Scan Tool (x64) Version: 29-08-2016 Ran by [removed] (30-08-2016 10:37:14) Running from C:\Users\[removed]\Desktop Windows 8.1 (Update) (X64) (2015-04-16 02:42:29) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-3268202683-2675470380-2750706328-500 - Administrator - Disabled) Guest (S-1-5-21-3268202683-2675470380-2750706328-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-3268202683-2675470380-2750706328-1003 - Limited - Enabled) user1 (S-1-5-21-3268202683-2675470380-2750706328-1001 - Administrator - Enabled) => C:\Users\user1 ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) µTorrent (HKU\S-1-5-21-3268202683-2675470380-2750706328-1001\...\uTorrent) (Version: 3.4.8.42449 - BitTorrent Inc.) Adobe Flash Player 23 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 23.0.0.151 - Adobe Systems Incorporated) Adobe Reader XI (11.0.17) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.17 - Adobe Systems Incorporated) Apple Application Support (32-bit) (HKLM-x32\...\{649A1FD9-5892-46AD-8DF0-C4A43FF61CB7}) (Version: 4.1 - Apple Inc.) Apple Application Support (64-bit) (HKLM\...\{0DE0A178-AC7B-4650-806C-CF226DE03766}) (Version: 4.1 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{3540181E-340A-4E7A-B409-31663472B2F7}) (Version: 9.1.0.6 - Apple Inc.) Apple Software Update (HKLM-x32\...\{FFD1F7F1-1AC9-4BC4-A908-0686D635ABAF}) (Version: 2.1.4.131 - Apple Inc.) Application Insights Tools for Visual Studio 2013 (x32 Version: 2.1 - Microsoft Corporation) Hidden Assembly Windows Phone SDK 8.0 - ita (x32 Version: 11.0.60610 - Microsoft Corporation) Hidden AzureTools.Notifications (x32 Version: 2.1.10731.1602 - Microsoft Corporation) Hidden Behaviors SDK (Windows Phone) for Visual Studio 2013 (x32 Version: 12.0.50716.0 - Microsoft Corporation) Hidden Behaviors SDK (Windows) for Visual Studio 2013 (x32 Version: 12.0.50429.0 - Microsoft Corporation) Hidden Blend for Visual Studio 2013 (x32 Version: 12.0.41002.1 - Microsoft Corporation) Hidden Blend for Visual Studio 2013 ITA resources (x32 Version: 12.0.41002.1 - Microsoft Corporation) Hidden Blend for Visual Studio SDK for .NET 4.5 (x32 Version: 3.0.40218.0 - Microsoft Corporation) Hidden Blend for Visual Studio SDK for Silverlight 5 (x32 Version: 3.0.40218.0 - Microsoft Corporation) Hidden Blend for Visual Studio SDK for Windows Phone 8.0 (x32 Version: 3.0.30924.0 - Microsoft Corporation) Hidden Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.) Build Tools - amd64 (Version: 12.0.30723 - Microsoft Corporation) Hidden Build Tools - x86 (x32 Version: 12.0.30723 - Microsoft Corporation) Hidden Build Tools Language Resources - amd64 (Version: 12.0.30723 - Microsoft Corporation) Hidden Build Tools Language Resources - x86 (x32 Version: 12.0.30723 - Microsoft Corporation) Hidden Chrome Remote Desktop Host (HKLM-x32\...\{159AA592-31AA-4EAC-A6CB-B47AB2CB1476}) (Version: 52.0.2743.48 - Google Inc.) Compon. agg. Microsoft Report Viewer per Visual Studio 2013 (x32 Version: 11.1.3442.2 - Microsoft Corporation) Hidden Componente aggiuntivo Microsoft Visual Studio 2013 per Windows Phone - ITA Language Pack (x32 Version: 12.0.30723 - Microsoft Corporation) Hidden Configuratore emulatore Windows Phone 8.0 - ita (x32 Version: 11.0.60830 - Microsoft Corporation) Hidden Dotfuscator and Analytics Community Edition (x32 Version: 5.5.4954.46574 - PreEmptive Solutions) Hidden Dotfuscator and Analytics Community Edition Language Pack (x32 Version: 5.5.4954.46574 - PreEmptive Solutions) Hidden Entity Framework 6.1.1 Tools for Visual Studio 2013 (HKLM-x32\...\{85253F13-EE42-4850-A3A5-79B90E92D7AC}) (Version: 12.0.30610.0 - Microsoft Corporation) FEP2010 Security MP (HKLM-x32\...\{417E6B63-96F7-40BA-9877-A3C433CA55B2}) (Version: 2.1.1116.111 - Microsoft) Finalizzatore strumenti Windows Phone - ita (Version: 11.0.60610 - Microsoft Corporation) Hidden Framework applicazione livello dati Microsoft SQL Server 2012 (HKLM-x32\...\{6EEAE8E0-4899-4657-870B-EEDF36FC3369}) (Version: 11.1.2902.0 - Microsoft Corporation) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 52.0.2743.116 - Google Inc.) Google Photos Backup (HKU\S-1-5-21-3268202683-2675470380-2750706328-1001\...\Google Photos Backup) (Version: 1.1.2.13 - Google, Inc.) Google Update Helper (x32 Version: 1.3.31.5 - Google Inc.) Hidden Hewlett-Packard ACLM.NET v1.2.2.3 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden HP CoolSense (HKLM-x32\...\{E2C8D0C2-1C97-4C05-939A-5B13A0FE655C}) (Version: 2.20.31 - Hewlett-Packard Company) HP Port Replicator Software Installer (HKLM-x32\...\{6313BCDF-1109-4682-A19D-413189817787}) (Version: 1.3.38 - HP) HP Support Assistant (HKLM-x32\...\{78E2C850-ADA6-420D-BA35-2F4A9BE733CC}) (Version: 8.3.27.17 - HP) HP Support Solutions Framework (HKLM-x32\...\{5F084DD8-AF2C-4004-9C92-820C32E4BD55}) (Version: 12.5.26.37 - HP) HP Utility Center (HKLM\...\{DCD5C599-5CCC-4E37-8938-FBB548D780C6}) (Version: 2.5.3 - Hewlett-Packard Company) HP Wireless Button Driver (HKLM-x32\...\{EFA01423-3857-468C-B7B6-F30AA08E50BC}) (Version: 1.1.5.1 - Hewlett-Packard) HPDetect (HKLM-x32\...\{CCCDD476-98F9-4B06-91DB-23F27CEC3BE1}) (Version: 1.0.0.0 - HP) iCloud (HKLM\...\{709A2D23-C25E-47B5-9268-CB6FEE648504}) (Version: 4.1.1.53 - Apple Inc.) IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6425.0 - IDT) IIS 8.0 Express (HKLM\...\{7BF61FA9-BDFB-4563-98AD-FCB0DA28CCC7}) (Version: 8.0.1557 - Microsoft Corporation) Immagini emulatore Windows Phone 8.0 - ita (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.30.1349 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3958 - Intel Corporation) iTunes (HKLM\...\{E690A491-702F-4DEC-9977-C015D1DBB57C}) (Version: 12.3.1.23 - Apple Inc.) Kit SDK de vérification de Visual Studio 2012 - fra (x32 Version: 12.0.30501 - Microsoft Corporation) Hidden KMPlayer (remove only) (HKLM-x32\...\The KMPlayer) (Version: 3.9.1.135 - PandoraTV) Language Pack degli strumenti dei servizi mobili di Microsoft Azure per Visual Studio - v1.2 (x32 Version: 1.2.20710.1601 - Microsoft Corporation) Hidden Language Pack degli strumenti di sviluppo di Microsoft Office 2013 per Microsoft Visual Studio (x64) - ITA (Version: 12.0.30626 - Microsoft Corporation) Hidden Language Pack del Visualizzatore della Guida Microsoft 2.1 - ITA (HKLM-x32\...\Language Pack del Visualizzatore della Guida Microsoft 2.1 - ITA) (Version: 2.1.21005 - Microsoft Corporation) Language Pack del Visualizzatore della Guida Microsoft 2.1 - ITA (x32 Version: 2.1.21005 - Microsoft Corporation) Hidden LocalESPC (x32 Version: 8.59.29989 - Microsoft Corporation) Hidden LocalESPC Dev12 (x32 Version: 8.100.25984 - Microsoft Corporation) Hidden LocalESPCui for it-it (x32 Version: 8.59.29989 - Microsoft) Hidden LocalESPCui for it-it Dev12 (x32 Version: 8.100.25984 - Microsoft) Hidden Memory Profiler (x32 Version: 12.0.30723 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5 Multi-Targeting Pack (HKLM-x32\...\{56E962F0-4FB0-3C67-88DB-9EAA6EEFC493}) (Version: 4.5.50710 - Microsoft Corporation) Microsoft .NET Framework 4.5 SDK - ITA Lang Pack (HKLM-x32\...\{CC85795B-9AB3-4AAE-8BEA-9041178DF6E9}) (Version: 4.5.50710 - Microsoft Corporation) Microsoft .NET Framework 4.5 SDK (HKLM-x32\...\{4AE57014-05C4-4864-A13D-86517A7E1BA4}) (Version: 4.5.50710 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (HKLM-x32\...\{6A0C6700-EA93-372C-8871-DCCF13D160A4}) (Version: 4.5.50932 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (Italiano) (HKLM-x32\...\{079CDB66-D3E9-31C8-A597-93382A9A7402}) (Version: 4.5.50932 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 SDK (HKLM-x32\...\{19A5926D-66E1-46FC-854D-163AA10A52D3}) (Version: 4.5.51641 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 SDK (Italiano) (HKLM-x32\...\{46539A2C-DCEB-4BB1-BBBF-CAA06967E509}) (Version: 4.5.51641 - Microsoft Corporation) Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}) (Version: 3.5.92.0 - Microsoft Corporation) Microsoft Games for Windows Marketplace (HKLM-x32\...\{67F42018-F647-4D3C-BE62-F8CB4FE2FCD5}) (Version: 3.5.67.0 - Microsoft Corporation) Microsoft Help Viewer 2.1 (HKLM-x32\...\Microsoft Help Viewer 2.1) (Version: 2.1.21005 - Microsoft Corporation) Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.4518.1014 - Microsoft Corporation) Microsoft Silverlight (HKLM-x32\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.20513.0 - Microsoft Corporation) Microsoft Silverlight 5 SDK - ITA (HKLM-x32\...\{F9859759-079A-44EB-B5BD-638733F76BA0}) (Version: 5.0.61118.0 - Microsoft Corporation) Microsoft SQL Server 2012 Command Line Utilities (HKLM\...\{61AB8577-B46C-492A-882E-C0F7AA6F49FB}) (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2012 Data-Tier App Framework (x64) (HKLM\...\{35467A25-F30D-43AB-BDF1-77869DBC6F39}) (Version: 11.1.2902.0 - Microsoft Corporation) Microsoft SQL Server 2012 Express LocalDB (HKLM\...\{16A550C4-1D4A-4AAF-9D26-3FA37E49D3AF}) (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2012 Management Objects (HKLM-x32\...\{99F9DB22-1D83-4A41-BB6E-8DD58EFC9E8E}) (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2012 Management Objects (x64) (HKLM\...\{407F5EC7-B580-4C69-A233-D853C926869D}) (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2012 Native Client (HKLM\...\{E672485C-E457-4E07-A813-9C78584076CB}) (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2012 System CLR Types (HKLM-x32\...\{6E1B40C0-130A-4D3E-90D2-B7AD107A1575}) (Version: 11.1.3366.16 - Microsoft Corporation) Microsoft SQL Server 2012 System CLR Types (x64) (HKLM\...\{035A5DBB-6799-412B-AD1A-AE1D50ECD5D0}) (Version: 11.1.3366.16 - Microsoft Corporation) Microsoft SQL Server 2012 Transact-SQL ScriptDom (HKLM\...\{EFCB3339-A7BA-4CB4-B4D8-97BCA0FC2AC5}) (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server Compact 4.0 SP1 x64 ITA (HKLM\...\{E7BFD3A1-2152-4DE1-9F82-A478DD6097C9}) (Version: 4.0.8876.1 - Microsoft Corporation) Microsoft SQL Server Data Tools - ITA (12.0.30919.1) (HKLM-x32\...\{10EBF1CD-4D7C-4961-8AA9-D7D2EC4E5413}) (Version: 12.0.30919.1 - Microsoft Corporation) Microsoft SQL Server Data Tools Build Utilities - ITA (12.0.30919.1) (HKLM-x32\...\{F5675659-3A73-4F35-8673-0D39EB84F093}) (Version: 12.0.30919.1 - Microsoft Corporation) Microsoft SQL Server System CLR Types (HKLM-x32\...\{DE2A5709-8CFB-4A5C-87A7-08E7662734A4}) (Version: 10.50.1600.1 - Microsoft Corporation) Microsoft SQL Server System CLR Types (x64) (HKLM\...\{200EC2DF-EFBE-4631-B6FF-94FEC64E64E7}) (Version: 10.50.1600.1 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{d20fc4cc-15ff-47e6-ac8b-6956f30dbe0a}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{abea410c-010f-4790-ac28-20f51b60f339}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.40820 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools per Office Runtime (x64) - Language Pack - ITA (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - ITA) (Version: 10.0.40820 - Microsoft Corporation) Microsoft Visual Studio Ultimate 2013 con Update 3 (HKLM-x32\...\{c9211b86-1d50-4ecf-86de-296670ec1baf}) (Version: 12.0.30723 - Microsoft Corporation) Microsoft Xbox 360 Accessories 1.2 (HKLM\...\{D9C50188-12D5-4D3E-8F00-682346C2AA5F}) (Version: 1.20.146.0 - Microsoft) Modello a oggetti di Microsoft Team Foundation Server 2013 Update 3 Language Pack (x64) - ITA (Version: 12.0.30723 - Microsoft Corporation) Hidden Modello di reindirizzamento di Python Tools (x32 Version: 1.2 - Microsoft Corporation) Hidden Mozilla Firefox 27.0 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 27.0 (x86 en-US)) (Version: 27.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 27.0 - Mozilla) My WIFI Router (HKLM-x32\...\My WIFI Router) (Version: 3.0.064-1201-001 - TxNetwork, Inc.) MyPublicWiFi 5.1 (HKLM-x32\...\{C08D782B-9281-406B-ABCE-326DA70B8A1F}_is1) (Version: - TRUE Software) NVIDIA PhysX (HKLM-x32\...\{B455E95A-B804-439F-B533-336B1635AE97}) (Version: 9.14.0702 - NVIDIA Corporation) Open XML SDK 2.5 for Microsoft Office (x32 Version: 2.5.5631 - Microsoft Corporation) Hidden Photon (HKLM-x32\...\Huawei Photon) (Version: 23.009.17.18.628 - Huawei Technologies Co.,Ltd) Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9.141.259 - Google, Inc.) PreEmptive Analytics Client Italian Language Pack (x32 Version: 1.2.3197.1 - PreEmptive Solutions) Hidden PreEmptive Analytics Visual Studio Components (x32 Version: 1.2.3197.1 - PreEmptive Solutions) Hidden Preparazione di Microsoft Visual Studio 2013 (x32 Version: 12.0.21005 - Microsoft Corporation) Hidden Prerequisiti per SSDT (HKLM-x32\...\{038D0EF0-B10C-4ED3-8E0E-A9513B6E86F2}) (Version: 11.1.3000.0 - Microsoft Corporation) Progettazione interfaccia utente XAML di Microsoft Visual Studio 2013 - ITA (x32 Version: 12.0.30723 - Microsoft Corporation) Hidden Qualcomm Atheros Driver Installation Program (HKLM-x32\...\{C3A32068-8AB1-4327-BB16-BED9C6219DC7}) (Version: 10.0 - Qualcomm Atheros) Realtek PCIE Card Reader (HKLM-x32\...\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.2.8400.29029 - Realtek Semiconductor Corp.) Risorse di Microsoft Visual Studio 2013 IntelliTrace (x64) - ITA (Version: 12.0.30723 - Microsoft Corporation) Hidden Risorse di Microsoft Visual Studio 2013 IntelliTrace (x86) - ITA (x32 Version: 12.0.30723 - Microsoft Corporation) Hidden Risorse di Microsoft Visual Studio 2013 Shell (minime) (x32 Version: 12.0.21005 - Microsoft Corporation) Hidden Risorse Microsoft Visual Studio 2013 IntelliTrace Front End - ITA (x32 Version: 12.0.30723 - Microsoft Corporation) Hidden SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.51.0 - SAMSUNG Electronics Co., Ltd.) SDK de comprobación de Visual Studio 2012 - esn (x32 Version: 12.0.30501 - Microsoft Corporation) Hidden Servizio linguaggio T-SQL Microsoft SQL Server 2012 (HKLM-x32\...\{EB7B7148-F739-4AD8-8FE2-6347034E518B}) (Version: 11.1.3000.0 - Microsoft Corporation) SharePoint Client Components (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden SharePoint Client Components (Version: 16.0.2617.1200 - Microsoft Corporation) Hidden Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation) Storyboard di Microsoft Visual Studio Team Foundation Server 2013 Language Pack (x64) - ITA (Version: 12.0.21005 - Microsoft Corporation) Hidden Strumenti di diagnostica Microsoft Visual Studio 2013 - ITA (x32 Version: 12.0.30723 - Microsoft Corporation) Hidden Strumenti di Windows Azure per LightSwitch per Visual Studio 2013 - $(var.OOBPublishVersion) (ITA) (x32 Version: 2.1.10909.1601 - Microsoft) Hidden Strumenti di Windows Phone 8.1 per Visual Studio 2013 - ITA (x32 Version: 12.0.30723 - Microsoft Corporation) Hidden Strumenti di Windows Phone 8.1 per Visual Studio Professional 2013 - ITA (x32 Version: 12.0.30723 - Microsoft Corporation) Hidden Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 16.6.1.3 - Synaptics Incorporated) Team Explorer for Microsoft Visual Studio 2013 (x32 Version: 12.0.21005 - Microsoft Corporation) Hidden TypeScript Power Tool (x32 Version: 1.0.3.1 - Microsoft Corporation) Hidden TypeScript Tools for Microsoft Visual Studio 2013 (x32 Version: 1.0.3.1 - Microsoft Corporation) Hidden Unlocker 1.9.2 (HKLM\...\Unlocker) (Version: 1.9.2 - Cedrick Collomb) Update for (KB2504637) (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}.KB2504637) (Version: 1 - Microsoft Corporation) Visual Studio 2013 Update 3 (KB2829760) (HKLM-x32\...\{86438e3d-7f83-4dd2-94aa-047e7c3974cb}) (Version: 12.0.30723 - Microsoft Corporation) VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN) VS Update core components (x32 Version: 12.0.30723 - Microsoft Corporation) Hidden WCF Data Services 5.6.0 ITA Language Pack (x32 Version: 5.6.61587.0 - Microsoft Corporation) Hidden WCF Data Services 5.6.0 Runtime (x32 Version: 5.6.61587.0 - Microsoft Corporation) Hidden WCF Data Services Tools for Microsoft Visual Studio 2013 (x32 Version: 5.6.61587.0 - Microsoft Corporation) Hidden WCF Data Services Tools for Microsoft Visual Studio 2013 ITA Language Pack (x32 Version: 5.6.61587.0 - Microsoft Corporation) Hidden WD Drive Utilities (HKLM-x32\...\{E61CFDDA-40DD-4400-95CA-12819C50B5C2}) (Version: 1.1.0.51 - Western Digital Technologies, Inc.) WD Quick View (HKLM-x32\...\{965D28B5-3C86-41FD-994E-D6376815C9B3}) (Version: 2.4.10.17 - Western Digital Technologies, Inc.) WD Security (HKLM-x32\...\{919ADA61-13BF-43C4-A2DD-8BA49A244FC8}) (Version: 1.1.0.51 - Western Digital Technologies, Inc.) WD SES Driver Setup (x32 Version: 1.1.0.51 - Western Digital) Hidden WD SmartWare (HKLM\...\{F6FE3205-7737-4772-9017-C7ACD8A5561C}) (Version: 2.4.10.17 - Western Digital Technologies, Inc.) WD SmartWare Installer (HKLM-x32\...\{647175e1-9944-4a82-bac1-102c95f0a99a}) (Version: 2.4.10.17 - Western Digital Technologies, Inc.) WinRAR 4.00 (64-bit) (HKLM\...\WinRAR archiver) (Version: 4.00.0 - win.rar GmbH) WinRAR 4.20 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH) Workflow Manager Client 1.0 (Version: 2.0.40131.0 - Microsoft Corporation) Hidden Workflow Manager Tools 1.0 for Visual Studio (Version: 2.0.40326.0 - Microsoft Corporation) Hidden Пакет Visual Studio 2012 Verification SDK - rus (x32 Version: 12.0.30501 - Microsoft Corporation) Hidden ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-3268202683-2675470380-2750706328-1001_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\user1\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-3268202683-2675470380-2750706328-1001_Classes\CLSID\{590C4387-5EBD-4D46-8A84-CD0BA2EF2856}\InprocServer32 -> C:\Users\user1\AppData\Local\Google\Update\1.3.30.3\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-3268202683-2675470380-2750706328-1001_Classes\CLSID\{59B55F04-DE14-4BB8-92FF-C4A22EF2E5F4}\InprocServer32 -> C:\Users\user1\AppData\Local\Google\Update\1.3.31.5\psuser_64.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-3268202683-2675470380-2750706328-1001_Classes\CLSID\{5C8C2A98-6133-4EBA-BBCC-34D9EA01FC2E}\InprocServer32 -> C:\Users\user1\AppData\Local\Google\Update\1.3.28.1\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-3268202683-2675470380-2750706328-1001_Classes\CLSID\{78550997-5DEF-4A8A-BAF9-D5774E87AC98}\InprocServer32 -> C:\Users\user1\AppData\Local\Google\Update\1.3.28.13\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-3268202683-2675470380-2750706328-1001_Classes\CLSID\{793EE463-1304-471C-ADF1-68C2FFB01247}\InprocServer32 -> C:\Users\user1\AppData\Local\Google\Update\1.3.29.5\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-3268202683-2675470380-2750706328-1001_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\Windows\system32\igfxEM.exe (Intel Corporation) CustomCLSID: HKU\S-1-5-21-3268202683-2675470380-2750706328-1001_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\user1\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-3268202683-2675470380-2750706328-1001_Classes\CLSID\{CC182BE1-84CE-4A57-B85C-FD4BBDF78CB2}\InprocServer32 -> C:\Users\user1\AppData\Local\Google\Update\1.3.29.1\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-3268202683-2675470380-2750706328-1001_Classes\CLSID\{D1EDC4F5-7F4D-4B12-906A-614ECF66DDAF}\InprocServer32 -> C:\Users\user1\AppData\Local\Google\Update\1.3.28.15\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-3268202683-2675470380-2750706328-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\user1\AppData\Local\Google\Update\1.3.31.5\psuser_64.dll (Google Inc.) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {0826ED85-DB2C-49F0-8990-010E012A72BD} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-04-16] (Google Inc.) Task: {0B545118-B563-42FC-8D07-B78F602FCF34} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList Task: {1B2B0DE0-B3FC-4F00-ABBD-19430E6AB0DD} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2016-07-04] (HP Inc.) Task: {254D4DA2-DD5C-445E-BFDF-79041C84041D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2016-08-08] (HP Inc.) Task: {2D7993EF-EB9F-4069-945D-D809DCF75A74} - System32\Tasks\Hewlett-Packard\HP Active Health\HP Active Health Scan (HPSA) => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.exe [2016-06-15] (HP Inc.) Task: {31F356E6-06FD-4B06-AF68-03FEFCCA1953} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-06-25] (Adobe Systems Incorporated) Task: {5A082399-F932-4394-B55F-A8A794EA05B1} - System32\Tasks\HPCeeScheduleForuser1 => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2016-01-22] (Hewlett-Packard) Task: {6CD875CA-2095-430C-9F33-E59B71713F04} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [2016-05-09] (Hewlett-Packard) Task: {756F7D4F-F948-4716-9056-25D72DFEA3F4} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3268202683-2675470380-2750706328-1001UA => C:\Users\user1\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.) Task: {78FDDCF2-FD1D-4474-BAFB-901E81FB520A} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3268202683-2675470380-2750706328-1001Core => C:\Users\user1\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.) Task: {8A899A0F-CEE3-41F1-9232-DF14EDCEFBAB} - System32\Tasks\Synaptics TouchPad Enhancements => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2013-05-07] (Synaptics Incorporated) Task: {9519960B-FEF4-447F-987E-873100A38434} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-08-24] (Adobe Systems Incorporated) Task: {BD7EA55F-6F14-4FB7-958F-2B3F7B79DBCE} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2016-07-04] (HP Inc.) Task: {C8E1116F-927A-4148-9520-72C7511143A9} - System32\Tasks\Hewlett-Packard\HP CoolSense\HP CoolSense Start at Logon => C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe [2013-11-01] (Hewlett-Packard Development Company, L.P.) Task: {CF63FDA2-571F-4E43-9F5E-37B98BC5E28E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-04-16] (Google Inc.) Task: {DF72A473-0A3A-44C4-B6C9-744247CFF505} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2016-08-03] (HP Inc.) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3268202683-2675470380-2750706328-1001Core.job => C:\Users\user1\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3268202683-2675470380-2750706328-1001UA.job => C:\Users\user1\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\HPCeeScheduleForuser1.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== 2015-03-20 18:12 - 2015-03-20 18:12 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2015-10-13 05:45 - 2015-10-13 05:45 - 01328912 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2014-01-15 09:12 - 2014-01-15 09:12 - 00351824 _____ () C:\ProgramData\DatacardService\HWDeviceService64.exe 2014-11-18 08:29 - 2014-11-18 08:29 - 00047464 _____ () C:\Program Files (x86)\Wi-Fi\WiFiGxSvc.exe 2016-05-07 21:53 - 2013-10-26 15:15 - 00651856 _____ () C:\ProgramData\Photon\Huawei\EC306-1\OnlineUpdate\ouc.exe 2016-05-30 12:20 - 2016-05-28 16:33 - 184515319 ___SH () C:\ProgramData\cu\cu.exe 2016-06-01 18:25 - 2014-07-09 16:34 - 00190464 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\Photon.exe 2016-05-07 21:53 - 2012-10-31 14:41 - 02417152 _____ () C:\ProgramData\Photon\Huawei\EC306-1\OnlineUpdate\QtCore4.dll 2016-05-07 21:53 - 2012-10-31 14:44 - 01148416 _____ () C:\ProgramData\Photon\Huawei\EC306-1\OnlineUpdate\QtNetwork4.dll 2016-05-07 21:53 - 2009-01-11 00:02 - 00011362 _____ () C:\ProgramData\Photon\Huawei\EC306-1\OnlineUpdate\mingwm10.dll 2016-05-07 21:53 - 2009-06-23 08:12 - 00043008 _____ () C:\ProgramData\Photon\Huawei\EC306-1\OnlineUpdate\libgcc_s_dw2-1.dll 2016-06-01 18:25 - 2014-11-21 12:15 - 00586752 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\core.dll 2016-06-01 18:25 - 2014-11-21 12:15 - 00294400 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\sdk.dll 2016-06-01 18:25 - 2009-01-11 00:02 - 00011362 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\mingwm10.dll 2016-06-01 18:25 - 2009-06-23 08:12 - 00043008 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\libgcc_s_dw2-1.dll 2016-06-01 18:25 - 2012-10-31 14:41 - 02417152 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\QtCore4.dll 2016-06-01 18:25 - 2012-10-31 15:03 - 09562624 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\QtGui4.dll 2016-06-01 18:25 - 2010-02-10 23:11 - 15675904 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\QtWebKit4.DLL 2016-06-01 18:25 - 2012-10-31 14:44 - 01148416 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\QtNetwork4.dll 2016-06-01 18:25 - 2012-10-31 17:53 - 03962368 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\QtXmlPatterns4.dll 2016-06-01 18:25 - 2012-10-31 17:54 - 00306176 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\phonon4.dll 2016-06-01 18:25 - 2014-11-21 12:15 - 00413696 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\Proxy.DLL 2016-06-01 18:25 - 2014-11-21 12:15 - 00628224 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\Common.dll 2016-06-01 18:25 - 2014-11-21 12:15 - 00158208 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\Trace.dll 2016-06-01 18:25 - 2014-11-21 12:15 - 00583168 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\PluginContainer.dll 2016-06-01 18:25 - 2014-11-21 12:15 - 00646144 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\AtCodec.dll 2016-06-01 18:25 - 2014-11-21 12:15 - 00747008 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\DeviceSrvPlugin.dll 2016-06-01 18:25 - 2014-11-21 12:15 - 00195584 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\XCodec.dll 2016-06-01 18:25 - 2014-11-21 12:15 - 00253952 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\NetSrvPlugin.dll 2016-06-01 18:25 - 2014-11-21 12:15 - 00166912 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\OSDialup.dll 2016-06-01 18:25 - 2014-11-21 12:15 - 00155136 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\DataServicePlugin.dll 2016-06-01 18:25 - 2014-11-21 12:15 - 00177152 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\CallSrvPlugin.dll 2016-06-01 18:25 - 2014-11-21 12:15 - 00672768 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\AddrBookSrvPlugin.dll 2016-06-01 18:25 - 2014-11-21 12:15 - 00220160 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\SmsSrvPlugin.dll 2016-06-01 18:25 - 2014-11-21 12:15 - 00142336 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\USSDSrvPlugin.dll 2016-06-01 18:25 - 2014-11-21 12:15 - 00157184 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\STKSrvPlugin.dll 2016-06-01 18:25 - 2014-11-21 12:15 - 00781824 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\DeviceAppPlugin.dll 2016-06-01 18:25 - 2014-11-21 12:15 - 00065536 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\OSPowerMgr.dll 2016-06-01 18:25 - 2013-05-21 14:14 - 00155648 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\Win7Support.dll 2016-06-01 18:25 - 2014-11-21 12:15 - 01124352 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\AddrBookPlugin.dll 2016-06-01 18:25 - 2014-11-21 12:15 - 00704000 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\SmsAppPlugin.dll 2016-06-01 18:25 - 2014-11-21 12:15 - 00187392 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\CallAppPlugin.dll 2016-06-01 18:25 - 2014-11-21 12:15 - 00569344 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\CallLogSrvPlugin.dll 2016-06-01 18:25 - 2014-11-21 12:15 - 00158720 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\NetConnectSrvPlugin.dll 2016-06-01 18:25 - 2014-11-21 12:15 - 00236544 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\DialUpPlugin.dll 2016-06-01 18:25 - 2014-11-21 12:15 - 00123392 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\OSAdapt.dll 2016-06-01 18:25 - 2014-11-21 12:15 - 00201216 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\NDISPlugin.dll 2016-06-01 18:25 - 2014-11-21 12:15 - 00131584 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\OSNDIS.dll 2016-06-01 18:25 - 2014-01-09 11:08 - 01134592 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\NDISAPI.dll 2016-06-01 18:25 - 2014-11-21 12:15 - 00702464 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\NetInfoSrvPlugin.dll 2016-06-01 18:25 - 2014-11-21 12:15 - 00062976 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\OSCall.dll 2016-06-01 18:25 - 2013-05-21 14:14 - 00224256 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\tdpcvoice.dll 2016-06-01 18:25 - 2014-11-21 12:15 - 00617984 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\DeviceMgrUIPlugin.dll 2016-06-01 18:25 - 2012-10-31 14:41 - 00398336 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\QtXml4.dll 2016-06-01 18:25 - 2014-11-21 12:15 - 00172032 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\ATR2SMgr.dll 2016-06-01 18:25 - 2014-11-21 12:15 - 00283648 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\XFramePlugin.dll 2016-06-01 18:25 - 2014-11-21 12:15 - 00779264 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\CallUIPlugin.dll 2016-06-01 18:25 - 2014-11-21 12:15 - 00097792 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\NotifyServicePlugin.dll 2016-06-01 18:25 - 2014-11-21 12:15 - 00374272 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\StatusBarMgrPlugin.dll 2016-06-01 18:25 - 2014-11-21 12:15 - 00404480 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\NetConnectPlugin.dll 2016-06-01 18:25 - 2014-11-21 12:15 - 00619008 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\DialupUIPlugin.dll 2016-06-01 18:25 - 2014-11-21 12:15 - 00130048 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\LayoutPlugin.dll 2016-06-01 18:25 - 2014-11-21 12:15 - 00121344 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\ConnectMgrUIPlugin.dll 2016-06-01 18:25 - 2014-11-21 12:15 - 00122880 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\LeftWebPlugin.dll 2016-06-01 18:25 - 2014-11-21 12:15 - 00254976 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\ToolBarMgrPlugin.dll 2016-06-01 18:25 - 2014-11-21 12:15 - 00124416 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\HelpUIPlugin.dll 2016-06-01 18:25 - 2014-11-21 12:15 - 00493568 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\NetInfoUIExPlugin.dll 2016-06-01 18:25 - 2014-11-21 12:15 - 00924672 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\SMSUIPlugin.dll 2016-06-01 18:25 - 2014-11-21 12:15 - 00836608 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\AddrBookUIPlugin.dll 2016-06-01 18:25 - 2014-11-21 12:15 - 00110592 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\TATASettingsPlugin.dll 2016-06-01 18:25 - 2014-11-21 12:15 - 00107008 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\ServicesPlugin.dll 2016-06-01 18:25 - 2014-11-21 12:15 - 00340480 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\MenuMgrPlugin.dll 2016-06-01 18:25 - 2014-11-21 12:15 - 00315904 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\DiagnosisPlugin.dll 2016-06-01 18:25 - 2013-05-21 12:50 - 00691200 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\LiveUpdateInterface.DLL 2016-06-01 18:25 - 2013-05-21 14:12 - 00082944 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\plugins\imageformats\qgif4.dll 2016-06-01 18:25 - 2013-05-21 14:12 - 00081920 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\plugins\imageformats\qico4.dll 2016-06-01 18:25 - 2013-05-21 14:12 - 00192000 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\plugins\imageformats\qjpeg4.dll 2016-06-01 18:25 - 2013-05-21 14:12 - 00350720 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\plugins\imageformats\qmng4.dll 2016-06-01 18:25 - 2013-05-21 14:12 - 00370176 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\plugins\imageformats\qtiff4.dll 2016-06-01 18:25 - 2014-11-21 12:15 - 00154624 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\SettingUIPlugin.dll 2016-06-01 18:25 - 2014-11-21 12:15 - 00150016 _____ () C:\Program Files (x86)\Photon\Huawei\EC306-1\DownLoadAndCache.dll 2015-04-17 11:25 - 2013-01-14 10:25 - 01200088 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll 2016-08-09 10:20 - 2016-08-03 05:54 - 01771336 _____ () C:\Program Files (x86)\Google\Chrome\Application\52.0.2743.116\libglesv2.dll 2016-08-09 10:20 - 2016-08-03 05:53 - 00094024 _____ () C:\Program Files (x86)\Google\Chrome\Application\52.0.2743.116\libegl.dll 2014-12-01 14:17 - 2014-12-01 14:17 - 00044560 _____ () C:\Program Files (x86)\Wi-Fi\plugins\txn.controller_0.1.0.dll 2014-11-20 12:07 - 2014-11-20 12:07 - 00367632 _____ () C:\Program Files (x86)\Wi-Fi\CTKPluginFramework.dll 2014-11-20 12:07 - 2014-11-20 12:07 - 00144400 _____ () C:\Program Files (x86)\Wi-Fi\libqjson.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2013-08-22 18:55 - 2013-08-22 18:55 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-3268202683-2675470380-2750706328-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\user1\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper DNS Servers: [removed] - [removed] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) HKU\S-1-5-21-3268202683-2675470380-2750706328-1001\...\StartupApproved\Run: => "Google+ Auto Backup" HKU\S-1-5-21-3268202683-2675470380-2750706328-1001\...\StartupApproved\Run: => "Steam" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [{AFE7992B-54FF-4C81-9752-F704ED8AF369}] => (Allow) C:\Users\user1\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{3B83FC26-900B-431B-8573-A3F6B9D0BF6E}] => (Allow) C:\Users\user1\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{D86681DE-F3F2-46AD-8331-EDB6AA8464BD}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{60F9E5E9-19CD-4080-8ED6-7B80EC397DED}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{671B871D-F134-4FB6-B4F8-F593581D2A54}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{189ECE21-2794-4C5C-BB74-EE9A3A666473}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{3756410C-A441-4925-BE92-AAA7C00AA809}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 12.0\Common7\IDE\devenv.exe FirewallRules: [{0FEFFE76-80BE-4A84-B467-F12F75E023B2}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 12.0\Common7\IDE\devenv.exe FirewallRules: [{7F46E536-F030-43F4-9358-EB0FCE960946}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 12.0\Common7\IDE\devenv.exe FirewallRules: [{BC2F9B4F-BC66-40B4-97B1-75B8D43D8008}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 12.0\Common7\IDE\devenv.exe FirewallRules: [{E4180ACD-C943-4F61-A502-DD817802D149}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 12.0\Common7\IDE\devenv.exe FirewallRules: [{1C31E3BB-D424-4AFB-A4CA-6559A1FE0493}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 12.0\Common7\IDE\devenv.exe FirewallRules: [{6E0B7C82-0846-4895-8597-059052D618EF}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 12.0\Common7\IDE\devenv.exe FirewallRules: [{6365455A-5E2F-4273-9D83-F8AB6DA1AABD}] => (Allow) LPort=12292 FirewallRules: [{AEF6425A-A91A-4BC7-980C-FDFEBD413C7B}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPDeviceDetection3.exe FirewallRules: [{676CA8A0-0582-4059-8568-210C95279DD0}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{DE3D0BAD-0087-4221-97E0-CBCE422D00FE}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [TCP Query User{45505565-F0ED-4EAD-B461-4E72BBBC1FB5}D:\fifa 14\game\fifa14.exe] => (Allow) D:\fifa 14\game\fifa14.exe FirewallRules: [UDP Query User{8AA88709-8870-4282-B229-D8C904BCE874}D:\fifa 14\game\fifa14.exe] => (Allow) D:\fifa 14\game\fifa14.exe FirewallRules: [{E0E0AF2A-0E98-42CB-890B-0CDC9E033F59}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe FirewallRules: [{2EA8C557-8E89-4B1C-87D4-805C5E67F60B}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe FirewallRules: [{C9B8840B-6363-4ACE-885C-F621A51E188D}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe FirewallRules: [{A4DD1005-4B18-41DB-9071-572B8814FA47}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe FirewallRules: [{A6C83FFC-4C39-4A20-8C93-250DACED736E}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe FirewallRules: [{404673C5-97BC-410F-8D2E-FFAA2C308F62}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe FirewallRules: [{AA188EAA-8B7B-49BB-91ED-B6D0D1165468}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe FirewallRules: [{F4CC5EB0-2887-4FF5-B654-CE3162C77697}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe FirewallRules: [{B2D6FF32-D3AE-4E95-B0FC-089D83DEA5DE}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe FirewallRules: [{8E19B543-6E28-4BC5-B6A4-71D4ECDDF6FF}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe FirewallRules: [TCP Query User{632204D8-94C3-400F-B559-C6ABBBF30769}C:\users\user1\desktop\fifa 14\game\fifa14.exe] => (Allow) C:\users\user1\desktop\fifa 14\game\fifa14.exe FirewallRules: [UDP Query User{13AB8A82-75DE-4F24-9E9D-ADAA18A19492}C:\users\user1\desktop\fifa 14\game\fifa14.exe] => (Allow) C:\users\user1\desktop\fifa 14\game\fifa14.exe FirewallRules: [TCP Query User{0D54F27A-31FA-46CC-9856-060A523679A1}C:\program files (x86)\who wants to be a millionaire special editions\binaries\win32\shippingpc-wwtbamgame.exe] => (Allow) C:\program files (x86)\who wants to be a millionaire special editions\binaries\win32\shippingpc-wwtbamgame.exe FirewallRules: [UDP Query User{3CF35BFE-0B38-448D-893C-30ED76DBE54B}C:\program files (x86)\who wants to be a millionaire special editions\binaries\win32\shippingpc-wwtbamgame.exe] => (Allow) C:\program files (x86)\who wants to be a millionaire special editions\binaries\win32\shippingpc-wwtbamgame.exe FirewallRules: [{D754A7F3-5313-4D36-B548-9412C5ECDA67}] => (Allow) C:\Program Files (x86)\2K Sports\NBA 2K14\nba2k14.exe FirewallRules: [{E6B08E56-7080-4A6A-B911-7CF9A46EA508}] => (Allow) C:\Program Files (x86)\2K Sports\NBA 2K14\nba2k14.exe FirewallRules: [{D24937D6-7F82-4B6C-A0FA-F04426DBC485}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{1F5B0E4F-4405-449F-8C25-990FCB303DDE}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{761A5402-E33A-46DB-896D-AEE87A32B6DC}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{731EDDFF-AA01-48B4-94B3-36245D3C1954}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{160DF5D6-FC55-4C74-BE97-CB77549E6BDD}] => (Allow) C:\Program Files\iTunes\iTunes.exe FirewallRules: [TCP Query User{BFCFD8F0-DB35-4023-BB52-225CA85B4B71}C:\users\user1\desktop\new folder\123141dish0ned\dishonored\binaries\win32\dishonored.exe] => (Allow) C:\users\user1\desktop\new folder\123141dish0ned\dishonored\binaries\win32\dishonored.exe FirewallRules: [UDP Query User{46E46873-E8C6-4573-A6AC-251858136F47}C:\users\user1\desktop\new folder\123141dish0ned\dishonored\binaries\win32\dishonored.exe] => (Allow) C:\users\user1\desktop\new folder\123141dish0ned\dishonored\binaries\win32\dishonored.exe FirewallRules: [TCP Query User{199434F8-2E51-45F8-9DAD-C738F0EEF0BA}C:\program files (x86)\who wants to be a millionaire special editions\binaries\win32\shippingpc-wwtbamgame.exe] => (Allow) C:\program files (x86)\who wants to be a millionaire special editions\binaries\win32\shippingpc-wwtbamgame.exe FirewallRules: [UDP Query User{043D9438-8546-4E05-AB90-525B5714D318}C:\program files (x86)\who wants to be a millionaire special editions\binaries\win32\shippingpc-wwtbamgame.exe] => (Allow) C:\program files (x86)\who wants to be a millionaire special editions\binaries\win32\shippingpc-wwtbamgame.exe FirewallRules: [TCP Query User{6156623F-B848-44BC-BDB4-25C1BDD81CAC}C:\users\user1\desktop\games\new folder\123141dish0ned\dishonored\binaries\win32\dishonored.exe] => (Allow) C:\users\user1\desktop\games\new folder\123141dish0ned\dishonored\binaries\win32\dishonored.exe FirewallRules: [UDP Query User{371D843C-1889-4AE4-AAD8-9AA5A68D20C6}C:\users\user1\desktop\games\new folder\123141dish0ned\dishonored\binaries\win32\dishonored.exe] => (Allow) C:\users\user1\desktop\games\new folder\123141dish0ned\dishonored\binaries\win32\dishonored.exe FirewallRules: [TCP Query User{FB13127C-3C6B-4F24-B551-D3A95DDC457D}C:\program files (x86)\r.g. catalyst\a game of thrones - genesis\agot.exe] => (Allow) C:\program files (x86)\r.g. catalyst\a game of thrones - genesis\agot.exe FirewallRules: [UDP Query User{FE2FC70D-3AB6-4AB6-9EA6-0FAABE51C0CE}C:\program files (x86)\r.g. catalyst\a game of thrones - genesis\agot.exe] => (Allow) C:\program files (x86)\r.g. catalyst\a game of thrones - genesis\agot.exe FirewallRules: [TCP Query User{A8F27BB4-C47F-45EE-863C-C478D6852B3B}C:\users\user1\downloads\images\crack.exe] => (Allow) C:\users\user1\downloads\images\crack.exe FirewallRules: [UDP Query User{95330B5F-6789-46EE-8AB4-BD34147B59EB}C:\users\user1\downloads\images\crack.exe] => (Allow) C:\users\user1\downloads\images\crack.exe FirewallRules: [TCP Query User{2CEF6260-1809-40EE-B7E7-FA3086285966}D:\a game of thrones - genesis\agot.exe] => (Block) D:\a game of thrones - genesis\agot.exe FirewallRules: [UDP Query User{5896EA49-5E5C-4668-BB4E-DBE6C8D15A68}D:\a game of thrones - genesis\agot.exe] => (Block) D:\a game of thrones - genesis\agot.exe FirewallRules: [TCP Query User{14E3E3D5-3732-4690-939E-A6B0B6DA9243}C:\program files (x86)\r.g. mechanics\game of thrones\binaries\win32\shippingpc-agotgame.exe] => (Block) C:\program files (x86)\r.g. mechanics\game of thrones\binaries\win32\shippingpc-agotgame.exe FirewallRules: [UDP Query User{AB24EC34-AB0D-4C32-8D56-77ADB0C986E8}C:\program files (x86)\r.g. mechanics\game of thrones\binaries\win32\shippingpc-agotgame.exe] => (Block) C:\program files (x86)\r.g. mechanics\game of thrones\binaries\win32\shippingpc-agotgame.exe FirewallRules: [TCP Query User{BE2C7850-37CB-44CD-B4CF-33A0F66BFD47}C:\program files (x86)\connectify\connectify.exe] => (Allow) C:\program files (x86)\connectify\connectify.exe FirewallRules: [UDP Query User{3D8827FF-28DD-483E-B9CA-2F0D9F34C417}C:\program files (x86)\connectify\connectify.exe] => (Allow) C:\program files (x86)\connectify\connectify.exe FirewallRules: [{D7A7DBC1-93CB-43D4-BA8A-C9EFA8D498F6}] => (Allow) D:\New folder (2)\mHotspot\mHotspot.exe FirewallRules: [{CD2EFDC2-70D7-498E-A18B-B8453806E644}] => (Allow) D:\New folder (2)\mHotspot\mHotspot.exe FirewallRules: [{84E4883F-DFD0-4E1F-A60F-179A1473430B}] => (Allow) C:\Program Files (x86)\mHotspot\mHotspot.exe FirewallRules: [{91695A52-4D3B-493F-A171-6FF8D601623F}] => (Allow) C:\Program Files (x86)\mHotspot\mHotspot.exe FirewallRules: [{4593326F-8C37-4850-92C7-BA2306167EB5}] => (Allow) C:\Program Files (x86)\MyPublicWiFi\MyPublicWiFi.exe FirewallRules: [{4E9F09D5-9164-48A7-B57C-8E81F576DBDA}] => (Allow) C:\Program Files (x86)\MyPublicWiFi\MyPublicWiFi.exe FirewallRules: [{0D611CB4-4C52-4888-9E5B-725036D5BE5F}] => (Allow) C:\Program Files (x86)\Wi-Fi\Wi-Fi.exe FirewallRules: [{8FE2BD2A-1E1A-4FBC-B35D-43B87596210B}] => (Allow) C:\Program Files (x86)\Google\Chrome Remote Desktop\52.0.2743.48\remoting_host.exe FirewallRules: [{CD154C41-48B7-449E-8EB1-C580A561D71D}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{60822189-DE54-4A99-BE74-F9E35B175430}] => (Allow) C:\Program Files (x86)\Wi-Fi\TX_Httpd.exe ==================== Restore Points ========================= 16-08-2016 11:50:40 Scheduled Checkpoint 24-08-2016 13:28:33 Scheduled Checkpoint 27-08-2016 16:52:52 Windows Defender Checkpoint 29-08-2016 09:20:03 Windows Defender Checkpoint 30-08-2016 10:19:11 JRT Pre-Junkware Removal ==================== Faulty Device Manager Devices ============= Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: HUAWEI Mass Storage USB Device Description: CD-ROM Drive Class Guid: {4d36e965-e325-11ce-bfc1-08002be10318} Manufacturer: (Standard CD-ROM drives) Service: cdrom Problem: : Windows cannot start this hardware device because its configuration information (in the registry) is incomplete or damaged. (Code 19) Resolution: A registry problem was detected. This can occur when more than one service is defined for a device, if there is a failure opening the service subkey, or if the driver name cannot be obtained from the service subkey. Try these options: On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Click "Uninstall", and then click "Scan for hardware changes" to load a usable driver. ==================== Event log errors: ========================= Application errors: ================== Error: (08/30/2016 10:14:31 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY) Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code. Error: (08/30/2016 10:14:31 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY) Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section. Error: (08/30/2016 09:57:34 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY) Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code. Error: (08/30/2016 09:57:34 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY) Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section. Error: (08/30/2016 09:19:41 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY) Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code. Error: (08/30/2016 09:19:41 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY) Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section. Error: (08/30/2016 09:12:25 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY) Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code. Error: (08/30/2016 09:12:25 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY) Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section. Error: (08/29/2016 11:02:35 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: USER) Description: Activation of app microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 failed with error: -2144927141 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (08/29/2016 06:30:58 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY) Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code. System errors: ============= Error: (08/30/2016 10:35:53 AM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The HomeGroup Provider service depends on the Function Discovery Resource Publication service which failed to start because of the following error: %%2147952449 = The requested address is not valid in its context. Error: (08/30/2016 10:35:53 AM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: The Function Discovery Resource Publication service terminated with the following error: %%2147952449 = The requested address is not valid in its context. Error: (08/30/2016 10:35:53 AM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The HomeGroup Provider service depends on the Function Discovery Resource Publication service which failed to start because of the following error: %%2147952449 = The requested address is not valid in its context. Error: (08/30/2016 10:35:53 AM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: The Function Discovery Resource Publication service terminated with the following error: %%2147952449 = The requested address is not valid in its context. Error: (08/30/2016 10:35:53 AM) (Source: ipnathlp) (EventID: 1233) (User: ) Description: The ICS_IPV6 failed to configure IPv6 stack. Error: (08/30/2016 10:35:53 AM) (Source: ipnathlp) (EventID: 1233) (User: ) Description: The ICS_IPV6 failed to configure IPv6 stack. Error: (08/30/2016 10:35:52 AM) (Source: ipnathlp) (EventID: 1233) (User: ) Description: The ICS_IPV6 failed to configure IPv6 stack. Error: (08/30/2016 10:35:52 AM) (Source: ipnathlp) (EventID: 1233) (User: ) Description: The ICS_IPV6 failed to configure IPv6 stack. Error: (08/30/2016 10:27:20 AM) (Source: ipnathlp) (EventID: 1233) (User: ) Description: The ICS_IPV6 failed to configure IPv6 stack. Error: (08/30/2016 10:27:20 AM) (Source: ipnathlp) (EventID: 1233) (User: ) Description: The ICS_IPV6 failed to configure IPv6 stack. CodeIntegrity: =================================== Date: 2016-08-30 10:23:41.754 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-08-30 10:23:41.551 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-08-28 14:17:16.155 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-08-28 14:17:15.812 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-08-28 14:00:42.127 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-08-28 14:00:41.765 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-08-25 11:16:17.787 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-08-25 11:16:17.386 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-08-24 16:37:25.006 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-08-17 13:35:05.705 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i5-3317U CPU @ 1.70GHz Percentage of memory in use: 34% Total physical RAM: 6043.27 MB Available physical RAM: 3977.44 MB Total Virtual: 7003.27 MB Available Virtual: 4996.41 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:171.89 GB) (Free:83.42 GB) NTFS Drive d: (Local Disk) (Fixed) (Total:292.97 GB) (Free:259.97 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 465.8 GB) (Disk ID: EEF2E385) Partition: GPT. ==================== End of Addition.txt ============================