Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15-03-2017 Ran by [removed] (24-03-2017 19:07:31) Running from C:\Users\[removed]\Downloads Windows 8.1 Pro (Update) (X64) (2014-12-10 19:47:59) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-1863226909-815411734-1163765807-500 - Administrator - Disabled) Guest (S-1-5-21-1863226909-815411734-1163765807-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-1863226909-815411734-1163765807-1016 - Limited - Enabled) Nemo (S-1-5-21-1863226909-815411734-1163765807-1001 - Administrator - Enabled) => C:\Users\anton_000 ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 7-Zip 16.04 (x64 edition) (HKLM\...\{23170F69-40C1-2702-1604-000001000000}) (Version: 16.04.00.0 - Igor Pavlov) Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.023.20070 - Adobe Systems Incorporated) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 25.0.0.134 - Adobe Systems Incorporated) Adobe Creative Suite 6 Master Collection (HKLM-x32\...\{E8AD3069-9EB7-4BA8-8BFE-83F4E69355C0}) (Version: 6 - Adobe Systems Incorporated) Adobe Flash Player 25 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 25.0.0.127 - Adobe Systems Incorporated) Adobe Help Manager (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 4.0.244 - Adobe Systems Incorporated) Adobe Photoshop Lightroom 4.4 64-bit (HKLM\...\{11A955CD-4398-405A-886D-E464C3618FBF}) (Version: 4.4.1 - Adobe) Adobe Widget Browser (HKLM-x32\...\com.adobe.WidgetBrowser) (Version: 2.0 Build 348 - Adobe Systems Incorporated.) AMD Software (HKLM\...\AMD Catalyst Install Manager) (Version: 9.0.000.8 - Advanced Micro Devices, Inc.) Assassin's Creed Rogue (HKLM-x32\...\Uplay Install 895) (Version: - Ubisoft) Assassins Creed Unity Gold Edition version 1.5.0 (HKLM-x32\...\Assassins Creed Unity Gold Edition_is1) (Version: 1.5.0 - GMT-MAX.ORG) Astroburn Lite (HKLM-x32\...\Astroburn Lite) (Version: 1.8.0.0183 - Disc Soft Ltd) Autodesk 3ds Max 2015 (HKLM\...\Autodesk 3ds Max 2015) (Version: 17.0.630.0 - Autodesk) Autodesk 3ds Max 2015 (Version: 17.0.630.0 - Autodesk) Hidden Autodesk 3ds Max 2015 Populate Data (HKLM\...\{57E92DED-DC6C-41E5-B9E1-76D83BD2EABE}) (Version: 17.0.0.0 - Autodesk) Autodesk Application Manager (HKLM-x32\...\Autodesk Application Manager) (Version: 5.0.142.14 - Autodesk) Autodesk Backburner 2015 (HKLM-x32\...\{8C5F38D2-8EFE-49A4-B3F5-BF3210FED168}) (Version: 15.0.0.0 - Autodesk) Autodesk DirectConnect 2015 64-bit (HKLM\...\Autodesk DirectConnect 2015 64-bit) (Version: 9.0.56.4 - Autodesk) Autodesk DirectConnect 2015 64-bit (Version: 9.0.56.4 - Autodesk) Hidden Autodesk Inventor Server Engine for 3ds Max 2015 (HKLM\...\{9167CA34-4E48-49E3-8892-3C439739D2D3}) (Version: 17.0 - Autodesk) Autodesk Material Library 2015 (HKLM-x32\...\{427F733F-4D6C-45BC-9324-EB743104C321}) (Version: 5.2.9.100 - Autodesk) Autodesk Material Library Base Resolution Image Library 2015 (HKLM-x32\...\{ABE2F70B-8D94-44E9-AA04-F0DB35063D62}) (Version: 5.2.9.100 - Autodesk) Autodesk Material Library Medium Resolution Image Library 2015 (HKLM-x32\...\{9F6466D9-6EFC-4A10-B931-C72D1A3F1763}) (Version: 5.2.9.100 - Autodesk) Autodesk Revit Interoperability for 3ds Max 2015 (HKLM\...\Autodesk Revit Interoperability for 3ds Max 2015) (Version: 15.0.107.0 - Autodesk) Autodesk Revit Interoperability for 3ds Max 2015 (Version: 15.0.107.0 - Autodesk) Hidden Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 12.1.2272 - AVAST Software) Baldur's Gate - Enhanced Edition (HKLM-x32\...\1207666353_is1) (Version: 2.0.0.1 - GOG.com) Baldur's Gate II - Enhanced Edition (HKLM-x32\...\1207666373_is1) (Version: 2.0.0.1 - GOG.com) Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) bl (x32 Version: 1.0.0 - Your Company Name) Hidden Catalyst Control Center Next Localization BR (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization BR (Version: 2017.0210.908.16431 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CHS (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CHS (Version: 2017.0210.908.16431 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CHT (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CHT (Version: 2017.0210.908.16431 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CS (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CS (Version: 2017.0210.908.16431 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization DA (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization DA (Version: 2017.0210.908.16431 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization DE (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization DE (Version: 2017.0210.908.16431 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization EL (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization EL (Version: 2017.0210.908.16431 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization ES (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization ES (Version: 2017.0210.908.16431 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization FI (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization FI (Version: 2017.0210.908.16431 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization FR (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization FR (Version: 2017.0210.908.16431 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization HU (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization HU (Version: 2017.0210.908.16431 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization IT (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization IT (Version: 2017.0210.908.16431 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization JA (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization JA (Version: 2017.0210.908.16431 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization KO (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization KO (Version: 2017.0210.908.16431 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization NL (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization NL (Version: 2017.0210.908.16431 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization NO (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization NO (Version: 2017.0210.908.16431 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization PL (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization PL (Version: 2017.0210.908.16431 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization RU (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization RU (Version: 2017.0210.908.16431 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization SV (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization SV (Version: 2017.0210.908.16431 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization TH (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization TH (Version: 2017.0210.908.16431 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization TR (Version: 2016.0321.1015.16463 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization TR (Version: 2017.0210.908.16431 - Advanced Micro Devices, Inc.) Hidden CCleaner (HKLM\...\CCleaner) (Version: 5.09 - Piriform) CDex extraction audio (HKLM-x32\...\CDex) (Version: - ) Combined Community Codec Pack 2014-07-13 (HKLM-x32\...\Combined Community Codec Pack_is1) (Version: 2014.07.13.0 - CCCP Project) DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd) Dreamfall Chapters (HKLM-x32\...\Dreamfall Chapters_is1) (Version: - Red Thread Games) Dropbox (HKU\S-1-5-21-1863226909-815411734-1163765807-1001\...\Dropbox) (Version: 21.4.25 - Dropbox, Inc.) East West EWQLSO Silver Edition (HKLM-x32\...\East West EWQLSO Silver Edition) (Version: - ) eLicenser Control (HKLM-x32\...\eLicenser Control) (Version: 6.6.6.2133 - Steinberg Media Technologies GmbH) FileZilla Client 3.25.0 (HKLM-x32\...\FileZilla Client) (Version: 3.25.0 - Tim Kosse) FLAC to MP3 Converter 6.1.9.a (HKLM-x32\...\DD4F47DF-6540-4BDA-BEAD-2B19250B0C48_is1) (Version: - Accmeware Corporation) Fran Bow (HKLM-x32\...\1438948561_is1) (Version: 2.5.0.6 - GOG.com) GOG Galaxy (HKLM-x32\...\{7258BA11-600C-430E-A759-27E2C691A335}_is1) (Version: - GOG.com) GOG.com The Longest Journey (HKLM\...\{1421ef36-3d77-4de9-aad4-c6f2f95e304f}.sdb) (Version: - ) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 56.0.2924.87 - Google Inc.) Google Drive (HKLM-x32\...\{07A12123-B717-496B-B471-48AF6407B433}) (Version: 1.32.4066.7445 - Google, Inc.) Google Earth Plug-in (HKLM-x32\...\{4AB54F11-2F8C-11E3-B09F-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.32.7 - Google Inc.) Hidden Guitar Pro 5.1 (HKLM-x32\...\Guitar Pro 5_is1) (Version: - Arobas Music) Heroes of Might and Magic 3 Complete (HKLM-x32\...\Heroes of Might and Magic 3 Complete_is1) (Version: - GOG.com) Icewind Dale II (HKLM-x32\...\GOGPACKICEWINDDALE2_is1) (Version: 2.0.0.11 - GOG.com) Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 10.0.25.1048 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.4226 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.9.0.1001 - Intel Corporation) Java 8 Update 121 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180121F0}) (Version: 8.0.1210.13 - Oracle Corporation) Java 8 Update 121 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180121F0}) (Version: 8.0.1210.13 - Oracle Corporation) LG Mobile Drivers (HKLM-x32\...\{D8D0327A-72B4-4C79-9883-1B6B6C20ED2B}) (Version: 4.0.3 - LG Electronics) LG USB WML Modem Driver (HKLM-x32\...\{FBA0CA60-8BF2-4381-B819-74F020E165A9}) (Version: 1.0 - LG Electronics) Malwarebytes version 3.0.6.1469 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.0.6.1469 - Malwarebytes) Microsoft Mouse and Keyboard Center (HKLM\...\Microsoft Mouse and Keyboard Center) (Version: 2.3.188.0 - Microsoft Corporation) Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.4518.1014 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24123 (HKLM-x32\...\{2cbcedbb-f38c-48a3-a3e1-6c6fd821a7f4}) (Version: 14.0.24123.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation) Mozilla Firefox 52.0.1 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 52.0.1 (x86 en-US)) (Version: 52.0.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 52.0.0.6270 - Mozilla) MSI Afterburner 2.3.1 (HKLM-x32\...\Afterburner) (Version: 2.3.1 - MSI Co., LTD) Mumble 1.2.19 (HKLM-x32\...\{F62A874F-2354-49B1-87BE-CAAD7C8FA084}) (Version: 1.2.19 - Thorvald Natvig) Native Instruments Controller Editor (HKLM-x32\...\Native Instruments Controller Editor) (Version: - Native Instruments) Native Instruments Guitar Rig 4 (HKLM-x32\...\Native Instruments Guitar Rig 4) (Version: - Native Instruments) Native Instruments Rig Kontrol 3 Driver (HKLM-x32\...\Native Instruments Rig Kontrol 3 Driver) (Version: - Native Instruments) Native Instruments Service Center (HKLM-x32\...\Native Instruments Service Center) (Version: - Native Instruments) NiBiRu (HKLM-x32\...\NiBiRu_is1) (Version: - The Adventure Company) OpenAL (HKLM-x32\...\OpenAL) (Version: - ) OpenOffice 4.1.1 (HKLM-x32\...\{9395F41D-0F80-432E-9A59-B8E477E7E163}) (Version: 4.11.9775 - Apache Software Foundation) Oxford Advanced Learner's Dictionary - 8th Edition (HKLM-x32\...\NSIS_oald8) (Version: - ) PDF Settings CS6 (x32 Version: 11.0 - Adobe Systems Incorporated) Hidden PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 2.3.1 - pdfforge GmbH) ph (x32 Version: 1.0.0 - Your Company Name) Hidden Pillars of Eternity (HKLM-x32\...\1207666813_is1) (Version: 2.0.0.1 - GOG.com) Planescape Torment (HKLM-x32\...\1207658887_is1) (Version: 2.1.0.9 - GOG.com) PxMergeModule (x32 Version: 1.00.0000 - Your Company Name) Hidden qBittorrent 3.3.6 (HKLM-x32\...\qBittorrent) (Version: 3.3.6 - The qBittorrent project) QUICKfind server v1.1 (HKLM-x32\...\QUICKfind) (Version: - IDM) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.38.115.2015 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7503 - Realtek Semiconductor Corp.) SafeZone Stable 1.51.2220.62 (x32 Version: 1.51.2220.62 - Avast Software) Hidden Skype Click to Call (HKLM-x32\...\{873F8E7C-10E6-449F-BD7E-5FBA7C8E1C9B}) (Version: 8.5.0.9167 - Microsoft Corporation) Skype™ 7.33 (HKLM-x32\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.33.105 - Skype Technologies S.A.) Sony PC Companion 2.10.236 (HKLM-x32\...\{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}) (Version: 2.10.236 - Sony) Steinberg Cubase LE AI Elements 7 64bit (HKLM\...\{67E7C608-D0EA-4273-B374-50ABE42FBE08}) (Version: 7.0.7 - Steinberg Media Technologies GmbH) Steinberg Drum Loop Expansion 01 (HKLM-x32\...\{490BF87E-1F75-4453-BF55-9F540543A3CA}) (Version: 2.0.0.0 - Steinberg Media Technologies GmbH) Steinberg Groove Agent ONE Content (HKLM-x32\...\{BD86F1AC-B594-46E4-85DC-1258AC9E2232}) (Version: 1.0.0.003 - Steinberg Media Technologies GmbH) Steinberg Groove Agent ONE Vintage Beatboxes (HKLM-x32\...\{DBF4BC99-53F1-4C97-84C3-7557D103E182}) (Version: 1.0.0.000 - Steinberg Media Technologies GmbH) Steinberg HALion Sonic SE 64bit (HKLM\...\{B99C316B-C135-43B5-8E77-2BC5E241F964}) (Version: 1.6.3 - Steinberg Media Technologies GmbH) Steinberg HALion Sonic SE Content for Cubase LE AI Elements (HKLM-x32\...\{CF45002F-2205-4116-BB51-2D015F436CAC}) (Version: 1.6.3 - Steinberg Media Technologies GmbH) Steinberg Midi Loop Library (HKLM-x32\...\{89DE2651-6DD9-4C15-AC94-8348362D456C}) (Version: 1.0.0 - Steinberg Media Technologies GmbH) Steinberg REVerence Content 01 (HKLM-x32\...\{532B917B-8235-4FA5-BE36-643A8BB053A5}) (Version: 2.0.1.000 - Steinberg Media Technologies GmbH) Steinberg Upload Manager (HKLM-x32\...\{88BBBD8F-4C19-4809-B84B-7A8F8238B48D}) (Version: 1.0.1 - Steinberg Media Technologies GmbH) Steinberg VST Amp Rack Content 01 (HKLM-x32\...\{8CBA7E47-48DA-47DC-8E98-6984BA830295}) (Version: 1.0.1 - Steinberg Media Technologies GmbH) Sublime Text Build 3126 (HKLM\...\Sublime Text 3_is1) (Version: - Sublime HQ Pty Ltd) TeamViewer 10 (HKLM-x32\...\TeamViewer) (Version: 10.0.36897 - TeamViewer) The Dark Eye - Chains of Satinav (HKLM-x32\...\The Dark Eye - Chains of Satinav_R.G. Mechanics_is1) (Version: - R.G. Mechanics, markfiter) The Longest Journey (HKLM-x32\...\GOGPACKTLJ_is1) (Version: 2.0.0.12 - GOG.com) The Witcher 3 - Wild Hunt (HKLM-x32\...\1207664643_is1) (Version: 1.31.0.0 - GOG.com) The Witcher 3: Wild Hunt - Blood and Wine (HKLM-x32\...\Blood and Wine_is1) (Version: 1.24.0.0 - GOG.com) The Witcher 3: Wild Hunt - Free DLC program (16 DLC) (HKLM-x32\...\Free DLC program (16 DLC)_is1) (Version: 1.24.0.0 - GOG.com) The Witcher 3: Wild Hunt - Hearts of Stone (HKLM-x32\...\Hearts of Stone_is1) (Version: 1.24.0.0 - GOG.com) Uplay (HKLM-x32\...\Uplay) (Version: 4.9 - Ubisoft) Vampire - The Masquerade - Bloodlines (HKLM-x32\...\1207659240_is1) (Version: 2.0.0.7 - GOG.com) VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.4 - VideoLAN) Vulkan Run Time Libraries 1.0.11.0 (HKLM\...\VulkanRT1.0.11.0-2) (Version: 1.0.11.0 - LunarG, Inc.) Vulkan Run Time Libraries 1.0.11.0 (Version: 1.0.11.0 - LunarG, Inc.) Hidden Vulkan Run Time Libraries 1.0.17.0 (HKLM\...\VulkanRT1.0.17.0-2) (Version: 1.0.17.0 - LunarG, Inc.) Vulkan Run Time Libraries 1.0.17.0 (Version: 1.0.17.0 - LunarG, Inc.) Hidden Vulkan Run Time Libraries 1.0.26.0 (HKLM\...\VulkanRT1.0.26.0-3) (Version: 1.0.26.0 - LunarG, Inc.) Vulkan Run Time Libraries 1.0.26.0 (Version: 1.0.26.0 - LunarG, Inc.) Hidden Vulkan Run Time Libraries 1.0.3.1 (HKLM\...\VulkanRT1.0.3.1) (Version: 1.0.3.1 - LunarG, Inc.) Vulkan Run Time Libraries 1.0.37.0 (HKLM\...\VulkanRT1.0.37.0) (Version: 1.0.37.0 - LunarG, Inc.) WhatsApp (HKU\S-1-5-21-1863226909-815411734-1163765807-1001\...\WhatsApp) (Version: 0.2.3699 - WhatsApp) Winamp (HKLM-x32\...\Winamp) (Version: 5.666 - Nullsoft, Inc) WinRAR 5.40 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.40.0 - win.rar GmbH) World of Warcraft (HKLM-x32\...\World of Warcraft) (Version: - Blizzard Entertainment) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-1863226909-815411734-1163765807-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\anton_000\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1863226909-815411734-1163765807-1001_Classes\CLSID\{073CB204-6B29-46FC-AB98-451F1D068741}\InprocServer32 -> C:\Program Files\Autodesk\3ds Max 2015\Inventor Server\Bin\TestServer.dll => No File CustomCLSID: HKU\S-1-5-21-1863226909-815411734-1163765807-1001_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\Windows\system32\igfxEM.exe (Intel Corporation) CustomCLSID: HKU\S-1-5-21-1863226909-815411734-1163765807-1001_Classes\CLSID\{8C23B656-4E6E-4B45-9920-9617168D39A3}\InprocServer32 -> C:\Program Files\Autodesk\3ds Max 2015\Inventor Server\Bin\TestServer.dll => No File CustomCLSID: HKU\S-1-5-21-1863226909-815411734-1163765807-1001_Classes\CLSID\{E5B0515D-48D2-4F04-906D-0192ED65A2DD}\InprocServer32 -> C:\Program Files\Autodesk\3ds Max 2015\Inventor Server\Bin\TestServer.dll => No File CustomCLSID: HKU\S-1-5-21-1863226909-815411734-1163765807-1001_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\anton_000\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1863226909-815411734-1163765807-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\anton_000\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1863226909-815411734-1163765807-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\anton_000\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1863226909-815411734-1163765807-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\anton_000\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1863226909-815411734-1163765807-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\anton_000\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1863226909-815411734-1163765807-1001_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\anton_000\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1863226909-815411734-1163765807-1001_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\anton_000\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1863226909-815411734-1163765807-1001_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\anton_000\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1863226909-815411734-1163765807-1001_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\anton_000\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1863226909-815411734-1163765807-1001_Classes\CLSID\{FB314EE1-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\anton_000\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1863226909-815411734-1163765807-1001_Classes\CLSID\{FB314EE2-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\anton_000\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1863226909-815411734-1163765807-1001_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\anton_000\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {0614D93A-63D5-444F-A119-AFFAF1079226} - System32\Tasks\{C53205DF-9C7C-4247-A9F7-B070F6D9B62B} => pcalua.exe -a "C:\Program Files (x86)\Activision\Vampire - Bloodlines\vampire.exe" -d "C:\Program Files (x86)\Activision\Vampire - Bloodlines\" Task: {113EC9CA-CDA5-4758-9431-44F5F4CA07EF} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-12-19] (Adobe Systems Incorporated) Task: {141E2C6C-81BF-4B8E-9BBB-FB5CB214B90E} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-03-15] (Adobe Systems Incorporated) Task: {18BA6DC2-9266-4B7A-A836-083C04F2745D} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-08-20] (Piriform Ltd) Task: {20A7C862-8DE9-4A6B-AADE-1CA36F63BAB5} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.) Task: {2C8A90F8-5178-49F3-8545-B686EDE4BC6B} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2016-07-11] (AVAST Software) Task: {3779AFA1-B13B-4BEE-AB1C-346A523F4CA3} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation) Task: {3BCC0D6A-2BFA-4EBB-B3F6-1BACA8FFF5D2} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-1863226909-815411734-1163765807-1001UA => C:\Users\anton_000\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2016-11-05] (Dropbox, Inc.) Task: {3E77AC68-6B1B-485B-9663-3A5D5459F7D3} - System32\Tasks\SafeZone scheduled Autoupdate 1478289621 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2016-09-06] (Avast Software) Task: {5153A4FB-FC98-4FBC-89C1-B7CB250599FA} - System32\Tasks\AMD ThankingURL => C:\Program Files\AMD\CIM\Bin64\Setup.exe [2017-02-10] (Advanced Micro Devices, Inc.) Task: {5689BCC1-13EC-4D45-A865-7F9034CC3310} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2014-03-19] (Microsoft) Task: {70D3236E-962E-4C3E-BB38-922AA2E59978} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation) Task: {80142721-5442-418F-A282-536FF566F042} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation) Task: {A83C6CFC-7D4C-4006-9E78-559A4E5A1049} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation) Task: {AD39E887-89AD-4069-9BEA-93FF21D72B19} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe [2017-02-10] (Advanced Micro Devices, Inc.) Task: {B5FDA5D0-055A-49E1-9033-507C188DC815} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-1863226909-815411734-1163765807-1001Core => C:\Users\anton_000\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2016-11-05] (Dropbox, Inc.) Task: {B613AFFC-EE57-4844-BDC4-A28003778AEC} - System32\Tasks\{DF5D6FCD-138F-47F8-9EBA-047A5AD2FDCF} => pcalua.exe -a D:\Dorky\Vampire\vampire.exe -d D:\Dorky\Vampire Task: {C5115726-A331-4987-A1FF-E3C67567C2E1} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.) Task: {D0EB85BA-3B5A-4167-9600-064A2BADA187} - System32\Tasks\AMD Updater => C:\Program Files\AMD\CIM\\Bin64\RadeonInstaller.exe [2017-02-10] (Advanced Micro Devices, Inc.) Task: {EED7923B-7541-4E74-A7D1-27BBF224D9E4} - System32\Tasks\{AF057989-617B-474F-8C79-DEC870598D31} => pcalua.exe -a "C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\Uplay.exe" -c uplay://uninstall/895 Task: {FB79D0C2-59FA-40B4-AA62-A59E49485DEC} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2017-01-27] (AVAST Software) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-1863226909-815411734-1163765807-1001Core.job => C:\Users\anton_000\AppData\Local\Dropbox\Update\DropboxUpdate.exe Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-1863226909-815411734-1163765807-1001UA.job => C:\Users\anton_000\AppData\Local\Dropbox\Update\DropboxUpdate.exe ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== 2017-03-22 16:01 - 2017-02-24 06:23 - 02264352 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\PoliciesControllerImpl.dll 2017-03-13 16:11 - 2017-03-13 16:11 - 00052392 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll 2006-09-19 09:07 - 2006-09-19 09:07 - 00827392 _____ () C:\Windows\vsnpstd3.exe 2016-02-15 15:44 - 2016-02-15 15:59 - 00253952 _____ () G:\Games\GalaxyClient\Games\The Witcher 3 Wild Hunt\bin\x64\d3d11.dll 2016-02-15 15:44 - 2016-02-15 17:19 - 00991232 _____ () G:\Games\GalaxyClient\Games\The Witcher 3 Wild Hunt\bin\x64\dxgi.dll 2016-10-17 15:24 - 2016-09-07 07:56 - 00013824 _____ () G:\Games\GalaxyClient\Games\The Witcher 3 Wild Hunt\bin\x64\NvCameraSDK64.dll 2016-02-15 15:44 - 2016-02-15 17:28 - 00918016 _____ () G:\Games\GalaxyClient\Games\The Witcher 3 Wild Hunt\bin\x64\GFSDK_SSAO.win64.dll 2016-02-15 15:44 - 2016-02-15 17:21 - 00025600 _____ () G:\Games\GalaxyClient\Games\The Witcher 3 Wild Hunt\bin\x64\XINPUT1_3.dll 2016-02-15 15:44 - 2016-02-15 17:22 - 00366080 _____ () G:\Games\GalaxyClient\Games\The Witcher 3 Wild Hunt\bin\x64\DINPUT8.dll 2016-02-15 15:44 - 2016-02-15 17:05 - 05023744 _____ () G:\Games\GalaxyClient\Games\The Witcher 3 Wild Hunt\bin\x64\Galaxy.dll 2015-06-08 10:45 - 2017-03-20 17:36 - 12165696 _____ () C:\ProgramData\GOG.com\Galaxy\redists\peer\msvc-17\GalaxyPeer64.dll 2016-02-15 15:44 - 2016-02-15 15:44 - 01422336 _____ () G:\Games\GalaxyClient\Games\The Witcher 3 Wild Hunt\bin\x64\GFSDK_HairWorks.win64.dll 2016-02-15 15:44 - 2016-02-15 15:58 - 00105984 _____ () G:\Games\GalaxyClient\Games\The Witcher 3 Wild Hunt\bin\x64\GogGalaxyHooks.dll 2017-03-13 12:58 - 2017-03-13 12:58 - 02259968 _____ () C:\Users\anton_000\AppData\Local\WhatsApp\app-0.2.3699\ffmpeg.dll 2017-03-13 12:58 - 2017-03-13 12:58 - 02917376 _____ () C:\Users\anton_000\AppData\Local\WhatsApp\app-0.2.3699\libglesv2.dll 2017-03-13 12:58 - 2017-03-13 12:58 - 00095232 _____ () C:\Users\anton_000\AppData\Local\WhatsApp\app-0.2.3699\libegl.dll 2017-03-24 15:08 - 2017-03-24 15:08 - 00486912 _____ () \\?\C:\Users\anton_000\AppData\Local\Temp\F165.tmp.node 2017-03-24 15:56 - 2017-03-24 15:56 - 00221184 _____ () \\?\C:\Users\anton_000\AppData\Local\Temp\9074.tmp.node 2016-07-11 19:42 - 2016-07-11 19:42 - 00146232 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll 2016-07-11 19:42 - 2016-07-11 19:42 - 00479288 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll 2017-03-24 13:19 - 2017-03-24 13:19 - 05889024 _____ () C:\Program Files\AVAST Software\Avast\defs\17032301\algo.dll 2016-01-20 21:39 - 2016-02-24 06:48 - 00062024 _____ () C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\QtSolutions_Service-head.dll 2016-01-20 21:39 - 2016-02-24 06:47 - 00110664 _____ () C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\qjson0.dll 2014-06-24 15:08 - 2014-06-24 15:08 - 01241560 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll 2016-07-11 19:42 - 2016-07-11 19:42 - 48936448 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2016-10-17 11:24 - 2016-10-17 11:23 - 53018112 _____ () G:\Games\GalaxyClient\libcef.dll 2017-03-20 17:37 - 2017-03-20 17:37 - 00507968 _____ () G:\Games\GalaxyClient\PocoUtil.dll 2017-03-20 17:37 - 2017-03-20 17:37 - 01076800 _____ () G:\Games\GalaxyClient\PocoNet.dll 2017-03-20 17:37 - 2017-03-20 17:36 - 01854528 _____ () G:\Games\GalaxyClient\PocoData.dll 2017-03-20 17:37 - 2017-03-20 17:36 - 00393280 _____ () G:\Games\GalaxyClient\PocoDataSQLite.dll 2017-03-20 17:37 - 2017-03-20 17:36 - 01589312 _____ () G:\Games\GalaxyClient\PocoFoundation.dll 2017-03-20 17:37 - 2017-03-20 17:37 - 00307776 _____ () G:\Games\GalaxyClient\PocoNetSSL.dll 2017-03-20 17:37 - 2017-03-20 17:36 - 00330816 _____ () G:\Games\GalaxyClient\PocoJSON.dll 2017-03-20 17:37 - 2017-03-20 17:37 - 00104000 _____ () G:\Games\GalaxyClient\zlib.dll 2017-03-20 17:37 - 2017-03-20 17:37 - 00520768 _____ () G:\Games\GalaxyClient\PocoXML.dll 2017-03-20 17:37 - 2017-03-20 17:37 - 00272448 _____ () G:\Games\GalaxyClient\PocoZip.dll 2017-03-20 17:37 - 2017-03-20 17:37 - 00680000 _____ () G:\Games\GalaxyClient\sqlite.dll 2017-03-20 17:37 - 2017-03-20 17:36 - 00425536 _____ () G:\Games\GalaxyClient\pcre.dll 2017-03-20 17:37 - 2017-03-20 17:36 - 00157760 _____ () G:\Games\GalaxyClient\PocoCrypto.dll 2017-03-20 17:37 - 2017-03-20 17:36 - 00152128 _____ () G:\Games\GalaxyClient\expat.dll 2016-10-17 11:24 - 2016-10-17 11:23 - 01738752 _____ () G:\Games\GalaxyClient\libglesv2.dll 2016-10-17 11:24 - 2016-10-17 11:23 - 00078848 _____ () G:\Games\GalaxyClient\libegl.dll 2012-03-09 16:26 - 2012-03-09 16:26 - 00100352 _____ () C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\zlib1.dll 2017-02-07 11:48 - 2017-02-01 11:01 - 01870168 _____ () C:\Program Files (x86)\Google\Chrome\Application\56.0.2924.87\libglesv2.dll 2017-02-07 11:48 - 2017-02-01 11:01 - 00085848 _____ () C:\Program Files (x86)\Google\Chrome\Application\56.0.2924.87\libegl.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\Users\anton_000\AppData\Local\Temp:Inm2kcFVSsS3ylnFigURHPUZ0os0 [542] AlternateDataStreams: C:\Users\anton_000\AppData\Local\Temporary Internet Files:lXMQ91fsX1FdXoEUqyHbmA [1916] ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) IE restricted site: HKU\S-1-5-21-1863226909-815411734-1163765807-1001\...\skype.com -> hxxps://apps.skype.com ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2014-12-15 20:54 - 2017-03-22 14:05 - 00001453 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost 127.0.0.1 3dns.adobe.com 127.0.0.1 3dns-1.adobe.com 127.0.0.1 3dns-2.adobe.com 127.0.0.1 3dns-3.adobe.com 127.0.0.1 3dns-4.adobe.com 127.0.0.1 activate.adobe.com 127.0.0.1 activate-sea.adobe.com 127.0.0.1 activate-sjc0.adobe.com 127.0.0.1 activate.wip.adobe.com 127.0.0.1 activate.wip1.adobe.com 127.0.0.1 activate.wip2.adobe.com 127.0.0.1 activate.wip3.adobe.com 127.0.0.1 activate.wip4.adobe.com 127.0.0.1 adobe-dns.adobe.com 127.0.0.1 adobe-dns-1.adobe.com 127.0.0.1 adobe-dns-2.adobe.com 127.0.0.1 adobe-dns-3.adobe.com 127.0.0.1 adobe-dns-4.adobe.com 127.0.0.1 adobeereg.com 127.0.0.1 practivate.adobe 127.0.0.1 practivate.adobe.com 127.0.0.1 practivate.adobe.newoa 127.0.0.1 practivate.adobe.ntp 127.0.0.1 practivate.adobe.ipp 127.0.0.1 ereg.adobe.com 127.0.0.1 ereg.wip.adobe.com 127.0.0.1 ereg.wip1.adobe.com 127.0.0.1 ereg.wip2.adobe.com 127.0.0.1 ereg.wip3.adobe.com There are 17 more lines. ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-1863226909-815411734-1163765807-1001\Control Panel\Desktop\\Wallpaper -> I:\wallpapers\Witcher\yennefer_the_witcher_3_wild_hunt-wallpaper-1920x1080.jpg DNS Servers: 192.168.1.254 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == HKLM\...\StartupApproved\Run: => "AdobeAAMUpdater-1.0" HKLM\...\StartupApproved\Run: => "IAStorIcon" HKLM\...\StartupApproved\Run32: => "Acrobat Assistant 8.0" HKLM\...\StartupApproved\Run32: => "Adobe Acrobat Speed Launcher" HKLM\...\StartupApproved\Run32: => "AdobeCS5.5ServiceManager" HKLM\...\StartupApproved\Run32: => "SwitchBoard" HKLM\...\StartupApproved\Run32: => "ADSKAppManager" HKLM\...\StartupApproved\Run32: => "GrooveMonitor" HKLM\...\StartupApproved\Run32: => "AdobeCS6ServiceManager" HKU\S-1-5-21-1863226909-815411734-1163765807-1001\...\StartupApproved\StartupFolder: => "Dropbox.lnk" HKU\S-1-5-21-1863226909-815411734-1163765807-1001\...\StartupApproved\Run: => "Skype" HKU\S-1-5-21-1863226909-815411734-1163765807-1001\...\StartupApproved\Run: => "CCleaner Monitoring" HKU\S-1-5-21-1863226909-815411734-1163765807-1001\...\StartupApproved\Run: => "DAEMON Tools Lite" HKU\S-1-5-21-1863226909-815411734-1163765807-1001\...\StartupApproved\Run: => "Dropbox Update" HKU\S-1-5-21-1863226909-815411734-1163765807-1001\...\StartupApproved\Run: => "GalaxyClient" HKU\S-1-5-21-1863226909-815411734-1163765807-1001\...\StartupApproved\Run: => "Sony PC Companion" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [{96BB3514-D3EF-45BB-B152-D3DEAC17F352}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe FirewallRules: [{AE03525D-B879-4025-9583-9B2EAFBC4A6E}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe FirewallRules: [{0CD32B0B-D2FE-416C-83DD-65218309C46E}] => (Allow) C:\Users\anton_000\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{8FAA30F3-D876-4623-B6A1-60873102760D}] => (Allow) C:\Users\anton_000\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{4623064E-E9B5-4339-B164-B22DF62764CA}] => (Allow) C:\Program Files (x86)\Adobe\Adobe Flash Builder 4.5\FlashBuilder.exe FirewallRules: [{9E06BA0E-A43A-4E4A-B437-9F992C7A1181}] => (Allow) C:\Program Files (x86)\Adobe\Adobe Flash Builder 4.5\FlashBuilder.exe FirewallRules: [{1C8984C6-40F8-4E89-A882-7BBE082C9BFE}] => (Allow) LPort=7935 FirewallRules: [{561B293B-0A22-4CFC-8C47-82746D6D7F4D}] => (Allow) C:\Users\anton_000\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [{F21A73DC-A048-4AF1-99A3-9E1F6DDE9DEC}] => (Allow) C:\Users\anton_000\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [TCP Query User{CDCF0A47-62FF-4E71-B9FE-FA2B0F1E0DE3}C:\program files\steinberg\cubase le ai elements 7\cubase le ai elements 7.exe] => (Allow) C:\program files\steinberg\cubase le ai elements 7\cubase le ai elements 7.exe FirewallRules: [UDP Query User{6FCADA47-FEB9-49BF-A4AB-E8CD3F1ABF20}C:\program files\steinberg\cubase le ai elements 7\cubase le ai elements 7.exe] => (Allow) C:\program files\steinberg\cubase le ai elements 7\cubase le ai elements 7.exe FirewallRules: [TCP Query User{9C741D61-6847-4169-887E-A101BAC7123B}C:\program files\steinberg\cubase le ai elements 7\components\vstbridgeapp.exe] => (Allow) C:\program files\steinberg\cubase le ai elements 7\components\vstbridgeapp.exe FirewallRules: [UDP Query User{183E5C6D-22DB-47B7-8883-2FC758FDD63B}C:\program files\steinberg\cubase le ai elements 7\components\vstbridgeapp.exe] => (Allow) C:\program files\steinberg\cubase le ai elements 7\components\vstbridgeapp.exe FirewallRules: [TCP Query User{04A40B58-A8A0-4539-9586-27FBE078DD8D}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe FirewallRules: [UDP Query User{C0DAE8BC-514E-4F98-B68E-F3C02A2A4A3C}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe FirewallRules: [{9F710B40-561D-46D3-8812-5525532E1984}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{B642A260-27D8-4A13-BDA2-3EC7F9310881}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{DA4FA91A-70D4-4291-9738-78CEFB654C05}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{47FF98E1-1E74-4056-87FE-7A789C158A91}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{BBB1C9FB-A9D2-4CC4-ABD3-5803C66CF50C}] => (Allow) C:\Users\anton_000\AppData\Local\Temp\7zS49F8\hppiw.exe FirewallRules: [{5080B8BF-7C9C-4BC6-964F-79840716A67B}] => (Allow) C:\Users\anton_000\AppData\Local\Temp\7zS49F8\hppiw.exe FirewallRules: [{A07F1E89-9B0B-4F24-8A28-7998A285B961}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{3BBB137E-1B95-418B-9EE3-563C040005F4}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [TCP Query User{5310BE15-7D2A-4594-B1B8-2DF25D2E4D71}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe FirewallRules: [UDP Query User{C32293E7-DF0E-426F-BFEB-B521F08CD654}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe FirewallRules: [TCP Query User{34A73C87-4457-43B3-AB63-E8E27C10C3D6}C:\program files (x86)\skype\phone\skype.exe] => (Block) C:\program files (x86)\skype\phone\skype.exe FirewallRules: [UDP Query User{518FFD55-545B-4380-B1F2-3199F45E3576}C:\program files (x86)\skype\phone\skype.exe] => (Block) C:\program files (x86)\skype\phone\skype.exe FirewallRules: [TCP Query User{37AB0DC7-DA51-4109-BD00-4D29ED60D7DB}C:\program files\steinberg\cubase le ai elements 7\cubase le ai elements 7.exe] => (Allow) C:\program files\steinberg\cubase le ai elements 7\cubase le ai elements 7.exe FirewallRules: [UDP Query User{1E701F69-62C5-4A39-BF64-2967BD7C2598}C:\program files\steinberg\cubase le ai elements 7\cubase le ai elements 7.exe] => (Allow) C:\program files\steinberg\cubase le ai elements 7\cubase le ai elements 7.exe FirewallRules: [TCP Query User{9CFDE4DA-3864-4DE0-BD38-CDC5F31B0C72}C:\program files\steinberg\cubase le ai elements 7\components\vstbridgeapp.exe] => (Allow) C:\program files\steinberg\cubase le ai elements 7\components\vstbridgeapp.exe FirewallRules: [UDP Query User{48A9AA2B-BE4E-413F-9562-E20D8F65393F}C:\program files\steinberg\cubase le ai elements 7\components\vstbridgeapp.exe] => (Allow) C:\program files\steinberg\cubase le ai elements 7\components\vstbridgeapp.exe FirewallRules: [{CC753E7C-72E4-43C5-84F1-D4795A2BDEFC}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe FirewallRules: [{3CE2239B-3CA4-4D52-B768-93279EF0B28A}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe FirewallRules: [TCP Query User{B57554E0-18A9-404B-98D6-4BD36BCFB304}C:\program files (x86)\might and magic heroes vii\binaries\win64\mmh7game-win64-shipping.exe] => (Block) C:\program files (x86)\might and magic heroes vii\binaries\win64\mmh7game-win64-shipping.exe FirewallRules: [UDP Query User{70753148-EE99-4C60-A91A-87556B16AE1A}C:\program files (x86)\might and magic heroes vii\binaries\win64\mmh7game-win64-shipping.exe] => (Block) C:\program files (x86)\might and magic heroes vii\binaries\win64\mmh7game-win64-shipping.exe FirewallRules: [TCP Query User{134BE0C5-BE34-4A99-9E34-5FAE57AADCC3}C:\program files (x86)\might and magic heroes vii\binaries\win32\mmh7game-win32-shipping.exe] => (Block) C:\program files (x86)\might and magic heroes vii\binaries\win32\mmh7game-win32-shipping.exe FirewallRules: [UDP Query User{D2FBE872-929E-4E00-8C4E-26E9B5E48AE2}C:\program files (x86)\might and magic heroes vii\binaries\win32\mmh7game-win32-shipping.exe] => (Block) C:\program files (x86)\might and magic heroes vii\binaries\win32\mmh7game-win32-shipping.exe FirewallRules: [TCP Query User{DA8CEA02-FC1F-4FD3-9861-4751B82589C7}C:\program files (x86)\might and magic heroes vii\binaries\win64\mmh7game-win64-shipping.exe] => (Block) C:\program files (x86)\might and magic heroes vii\binaries\win64\mmh7game-win64-shipping.exe FirewallRules: [UDP Query User{F80E2146-B696-486A-B89D-003A523CA048}C:\program files (x86)\might and magic heroes vii\binaries\win64\mmh7game-win64-shipping.exe] => (Block) C:\program files (x86)\might and magic heroes vii\binaries\win64\mmh7game-win64-shipping.exe FirewallRules: [{DC723104-459D-4AC2-8E2E-4CE03A3EBE09}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe FirewallRules: [{C56CACFB-41AB-4FD9-BBA4-CAA04BF4C58E}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe FirewallRules: [{E4E116A6-E377-467D-9D51-DE34C43C5CD4}] => (Allow) C:\Program Files\Autodesk\3ds Max 2015\NVIDIA\Satellite\raysat_3dsmax2015_64server.exe FirewallRules: [{B2B84216-D842-4898-A6F8-77DFC9555E97}] => (Allow) C:\Program Files\Autodesk\3ds Max 2015\NVIDIA\Satellite\raysat_3dsmax2015_64server.exe FirewallRules: [{8A96F456-EE05-492F-ADBC-C7F69A3E52F0}] => (Allow) C:\Program Files\Autodesk\3ds Max 2015\NVIDIA\Satellite\raysat_3dsmax2015_64.exe FirewallRules: [{2D6AF1AA-2110-45B5-8631-B131A0DA4573}] => (Allow) C:\Program Files\Autodesk\3ds Max 2015\NVIDIA\Satellite\raysat_3dsmax2015_64.exe FirewallRules: [{2FED3AE1-47F9-4DE0-BD8E-2B62D5FF4931}] => (Allow) C:\Program Files (x86)\Adobe\Adobe Flash Builder 4.6\FlashBuilder.exe FirewallRules: [{7D9EFEAF-B2C6-4120-9679-3EAFCDAB62F7}] => (Allow) C:\Program Files (x86)\Adobe\Adobe Flash Builder 4.6\FlashBuilder.exe FirewallRules: [TCP Query User{83FE97B2-4078-4A90-946B-6EDF18C01ACC}C:\program files (x86)\ubisoft\assassin's creed iii\ac3sp.exe] => (Block) C:\program files (x86)\ubisoft\assassin's creed iii\ac3sp.exe FirewallRules: [UDP Query User{8D696A45-00BB-4630-9ACB-930FF1884680}C:\program files (x86)\ubisoft\assassin's creed iii\ac3sp.exe] => (Block) C:\program files (x86)\ubisoft\assassin's creed iii\ac3sp.exe FirewallRules: [{64D94903-494E-469B-A083-E29E6BCC0CF5}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe FirewallRules: [{68844869-9EC9-4226-AD4E-045589A3FE59}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe FirewallRules: [{14FAF668-CB35-46D4-9BA9-77F9267D7BDA}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe FirewallRules: [{14A84CF5-7009-4C2E-8339-3A579D6E66D4}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe FirewallRules: [{E70CCAC8-C10E-4EEF-90BF-634EA8CF59F4}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{534E5655-E9D1-418B-BC63-4254D80BA081}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{9CD8A241-98BA-41ED-938A-A0B60C943C24}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr.exe FirewallRules: [{3F2EECA7-420D-458D-A2D1-F873ED0B86B3}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr.exe FirewallRules: [{0A776744-500F-4FC0-8894-29D48F5AE6FF}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr_im.exe FirewallRules: [{0C2A3211-C5C8-447F-A9E3-002C0D630F11}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr_im.exe FirewallRules: [{93CFCDEC-4F89-4A87-8908-B93F72DC09F5}] => (Allow) C:\Program Files (x86)\qBittorrent\qbittorrent.exe FirewallRules: [{838899A2-3ABA-4D53-A945-5D95BAF9A12C}] => (Allow) C:\Program Files (x86)\qBittorrent\qbittorrent.exe FirewallRules: [{4C76292E-C8EC-4930-864B-6DFF2AF1DC22}] => (Allow) C:\Program Files (x86)\Raptr Inc\PlaysTV\playstv.exe FirewallRules: [{03D54262-6DE0-4C16-8759-3DB13C74EFA6}] => (Allow) C:\Program Files (x86)\Raptr Inc\PlaysTV\playstv.exe FirewallRules: [TCP Query User{7B0B3370-64A5-455A-9905-B375ECBBB3E3}C:\program files (x86)\battle.net\battle.net.8265\battle.net.exe] => (Allow) C:\program files (x86)\battle.net\battle.net.8265\battle.net.exe FirewallRules: [UDP Query User{2CAC3722-A038-4EA0-8019-93707B9DC0E9}C:\program files (x86)\battle.net\battle.net.8265\battle.net.exe] => (Allow) C:\program files (x86)\battle.net\battle.net.8265\battle.net.exe FirewallRules: [{94D541E0-0E32-41D4-B284-28EC18DC1A6C}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Restore Points ========================= 21-03-2017 15:55:54 Removed Safari ==================== Faulty Device Manager Devices ============= Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (03/24/2017 06:03:14 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: GalaxyCommunication.exe, version: 1.1.21.2, time stamp: 0x5824657b Faulting module name: GalaxyCommunication.exe, version: 1.1.21.2, time stamp: 0x5824657b Exception code: 0xc0000005 Fault offset: 0x000400ce Faulting process id: 0x1010 Faulting application start time: 0x01d2a49f2b197395 Faulting application path: C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe Faulting module path: C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe Report Id: 6259f36a-10ab-11e7-8311-74d43585e708 Faulting package full name: Faulting package-relative application ID: Error: (03/24/2017 02:38:17 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program chrome.exe version 56.0.2924.87 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: 1668 Start Time: 01d2a49aae9f5d63 Termination Time: 4294967295 Application Path: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Report Id: bf0e0d12-108e-11e7-8311-74d43585e708 Faulting package full name: Faulting package-relative application ID: Error: (03/24/2017 02:36:03 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: RadeonSettings.exe, version: 10.1.1.1674, time stamp: 0x589dc8f2 Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000 Exception code: 0xc0000005 Fault offset: 0x0000000000000000 Faulting process id: 0xd28 Faulting application start time: 0x01d2a49a7f173434 Faulting application path: C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe Faulting module path: unknown Report Id: 70f6e600-108e-11e7-8311-74d43585e708 Faulting package full name: Faulting package-relative application ID: Error: (03/24/2017 01:37:36 PM) (Source: Microsoft-Windows-Defrag) (EventID: 257) (User: ) Description: The volume Recovery was not optimized because an error was encountered: The parameter is incorrect. (0x80070057) Error: (03/23/2017 09:59:26 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: RadeonSettings.exe, version: 10.1.1.1674, time stamp: 0x589dc8f2 Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000 Exception code: 0xc0000005 Fault offset: 0x0000000000000000 Faulting process id: 0x186c Faulting application start time: 0x01d2a40f44dc20c0 Faulting application path: C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe Faulting module path: unknown Report Id: 372689e5-1003-11e7-8311-74d43585e708 Faulting package full name: Faulting package-relative application ID: Error: (03/23/2017 03:16:46 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: RadeonSettings.exe, version: 10.1.1.1674, time stamp: 0x589dc8f2 Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000 Exception code: 0xc0000005 Fault offset: 0x0000000000000000 Faulting process id: 0x1814 Faulting application start time: 0x01d2a3d703eb08f0 Faulting application path: C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe Faulting module path: unknown Report Id: f6e97f2a-0fca-11e7-8311-74d43585e708 Faulting package full name: Faulting package-relative application ID: Error: (03/22/2017 04:38:10 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: RadeonSettings.exe, version: 10.1.1.1674, time stamp: 0x589dc8f2 Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000 Exception code: 0xc0000005 Fault offset: 0x0000000000000000 Faulting process id: 0x11f8 Faulting application start time: 0x01d2a31935047ccd Faulting application path: C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe Faulting module path: unknown Report Id: 2b63642f-0f0d-11e7-8311-74d43585e708 Faulting package full name: Faulting package-relative application ID: Error: (03/22/2017 03:27:39 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program chrome.exe version 56.0.2924.87 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: 1008 Start Time: 01d2a308709951af Termination Time: 4294967295 Application Path: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Report Id: 4fe1a829-0f03-11e7-8310-74d43585e708 Faulting package full name: Faulting package-relative application ID: Error: (03/22/2017 02:27:37 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: RadeonSettings.exe, version: 10.1.1.1674, time stamp: 0x589dc8f2 Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000 Exception code: 0xc0000005 Fault offset: 0x0000000000000000 Faulting process id: 0x1050 Faulting application start time: 0x01d2a306f7e99ffc Faulting application path: C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe Faulting module path: unknown Report Id: eeb7b0de-0efa-11e7-8310-74d43585e708 Faulting package full name: Faulting package-relative application ID: Error: (03/22/2017 12:51:00 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: rsUI.exe, version: 2.0.0.0, time stamp: 0x58aa6f9d Faulting module name: LSASRV.dll, version: 6.3.9600.17918, time stamp: 0x558e04d1 Exception code: 0xc0000005 Fault offset: 0x000000000005036a Faulting process id: 0xb34 Faulting application start time: 0x01d2a2f9d25ef33c Faulting application path: C:\Program Files\Reason\Security\rsUI.exe Faulting module path: C:\Windows\SYSTEM32\LSASRV.dll Report Id: 6f75faa1-0eed-11e7-830b-74d43585e708 Faulting package full name: Faulting package-relative application ID: System errors: ============= Error: (03/23/2017 03:43:14 PM) (Source: DCOM) (EventID: 10010) (User: MYRI-PC) Description: The server {1B1F472E-3221-4826-97DB-2C2324D389AE} did not register with DCOM within the required timeout. Error: (03/23/2017 03:42:44 PM) (Source: DCOM) (EventID: 10010) (User: MYRI-PC) Description: The server {BF6C1E47-86EC-4194-9CE5-13C15DCB2001} did not register with DCOM within the required timeout. Error: (03/22/2017 05:14:15 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {135FD325-45B7-4C30-89F8-4386961669F0} and APPID {135FD325-45B7-4C30-89F8-4386961669F0} to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (03/22/2017 04:32:52 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The Security Driver service failed to start due to the following error: This driver has been blocked from loading Error: (03/22/2017 04:32:52 PM) (Source: Application Popup) (EventID: 1060) (User: ) Description: \SystemRoot\System32\Drivers\secdrv.SYS Error: (03/22/2017 04:24:33 PM) (Source: DCOM) (EventID: 10010) (User: MYRI-PC) Description: The server {BF6C1E47-86EC-4194-9CE5-13C15DCB2001} did not register with DCOM within the required timeout. Error: (03/22/2017 04:24:03 PM) (Source: DCOM) (EventID: 10010) (User: MYRI-PC) Description: The server {1B1F472E-3221-4826-97DB-2C2324D389AE} did not register with DCOM within the required timeout. Error: (03/22/2017 02:22:20 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The Security Driver service failed to start due to the following error: %%1275 = This driver has been blocked from loading Error: (03/22/2017 02:22:20 PM) (Source: Application Popup) (EventID: 1060) (User: ) Description: \SystemRoot\System32\Drivers\secdrv.SYS Error: (03/22/2017 02:21:50 PM) (Source: DCOM) (EventID: 10005) (User: MYRI-PC) Description: DCOM got error "1084" attempting to start the service WSearch with arguments "Unavailable" in order to run the server: {9E175B68-F52A-11D8-B9A5-505054503030} CodeIntegrity: =================================== Date: 2017-03-22 16:32:52.883 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\drivers\secdrv.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2017-03-22 14:22:20.712 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\drivers\secdrv.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2017-03-22 14:11:00.764 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\drivers\secdrv.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2017-03-22 14:09:46.242 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\drivers\secdrv.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2017-03-21 16:17:34.763 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\drivers\secdrv.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2017-03-21 16:04:13.140 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\drivers\secdrv.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2017-03-19 20:51:30.058 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\drivers\secdrv.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2017-03-19 10:42:15.499 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\drivers\secdrv.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2017-02-25 14:40:03.540 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\drivers\secdrv.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2017-02-25 00:37:12.532 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\drivers\secdrv.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i5-4460 CPU @ 3.20GHz Percentage of memory in use: 85% Total physical RAM: 8079.16 MB Available physical RAM: 1138.24 MB Total Virtual: 12431.16 MB Available Virtual: 1419.2 MB ==================== Drives ================================ Drive c: (Windows SSD) (Fixed) (Total:232.37 GB) (Free:77.49 GB) NTFS Drive d: (System Reserve) (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS ==>[system with boot components (obtained from drive)] Drive g: (Myri 1) (Fixed) (Total:146.38 GB) (Free:65.52 GB) NTFS Drive h: (My thingys) (Fixed) (Total:151.6 GB) (Free:79.52 GB) NTFS Drive i: (Games!) (Fixed) (Total:465.76 GB) (Free:357.44 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 232.9 GB) (Disk ID: 00000000) Partition: GPT. ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: AEFDAEFD) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=146.4 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=151.6 GB) - (Type=OF Extended) ======================================================== Disk: 2 (MBR Code: Windows 7 or Vista) (Size: 465.8 GB) (Disk ID: 98EA9D95) Partition 1: (Active) - (Size=465.8 GB) - (Type=07 NTFS) ==================== End of Addition.txt ============================