Additional scan result of Farbar Recovery Scan Tool (x64) Version: 24-05-2017 Ran by [removed] (27-05-2017 20:26:25) Running from C:\Users\[removed]\Downloads\Desktop\Rold's\VIRUSES Windows 10 Home Version 1607 (X64) (2016-08-21 20:50:13) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-964481591-2532791391-1458198129-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-964481591-2532791391-1458198129-503 - Limited - Disabled) Guest (S-1-5-21-964481591-2532791391-1458198129-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-964481591-2532791391-1458198129-1003 - Limited - Enabled) Rold (S-1-5-21-964481591-2532791391-1458198129-1002 - Administrator - Enabled) => C:\Users\Rold ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) . . . (Version: 2.1.28.3 - Intel) Hidden . . . (x32 Version: 2.6.2.4 - Intel) Hidden «Tales of Zestiria» 1.4.0.0 (HKLM-x32\...\«Tales of Zestiria»_is1) (Version: 1.4.0.0 - BANDAI NAMCO Entertainment) µTorrent (HKU\S-1-5-21-964481591-2532791391-1458198129-1002\...\uTorrent) (Version: 3.5.0.43804 - BitTorrent Inc.) 1500 (x32 Version: 140.0.425.000 - Hewlett-Packard) Hidden 1500_Help (x32 Version: 82.0.242.000 - Hewlett-Packard) Hidden 1500Trb (x32 Version: 82.0.242.000 - Hewlett-Packard) Hidden 64 Bit HP CIO Components Installer (Version: 7.2.8 - Hewlett-Packard) Hidden 7-Zip 16.04 (x64) (HKLM\...\7-Zip) (Version: 16.04 - Igor Pavlov) Adobe Audition CC 2015 (HKLM-x32\...\{839A3566-AED6-4787-A849-5CBE2B1DC6AE}) (Version: 8.0 - Adobe Systems Incorporated) Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 3.7.5.291 - Adobe Systems Incorporated) Adobe Flash Player 25 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 25.0.0.171 - Adobe Systems Incorporated) Adobe Photoshop CC 2014 (HKLM-x32\...\{D7A4F897-B20A-42D0-862D-CB5F6DB7391D}) (Version: 15.0 - Adobe Systems Incorporated) Adobe Reader X (10.1.9) MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.1.9 - Adobe Systems Incorporated) Advanced Audio FX Engine (HKLM-x32\...\Advanced Audio FX Engine) (Version: 1.12.05 - Creative Technology Ltd) Advanced SystemCare 9 (HKLM-x32\...\Advanced SystemCare_is1) (Version: 9.4.0 - IObit) AIO_CDB_ProductContext (x32 Version: 140.0.425.000 - Hewlett-Packard) Hidden AIO_CDB_Software (x32 Version: 140.0.428.000 - Hewlett-Packard) Hidden AIO_Scan (x32 Version: 130.0.421.000 - Hewlett-Packard) Hidden Akamai NetSession Interface (HKU\S-1-5-21-964481591-2532791391-1458198129-1002\...\Akamai) (Version: - Akamai Technologies, Inc) Akaneiro Launcher (HKLM-x32\...\AkaneiroLauncher) (Version: - ) Alarm Clock v1.0 (HKLM-x32\...\Alarm Clock_is1) (Version: - Moore Design Lmt.) AlienRespawn - Support Software (HKLM-x32\...\{A9668246-FB70-4103-A1E3-66C9BC2EFB49}) (Version: 9.4.57 - Alienware) AlienRespawn (HKLM-x32\...\{0ED7EE95-6A97-47AA-AD73-152C08A15B04}) (Version: 9.4.57 - Alienware) Alienware Command Center (HKLM-x32\...\InstallShield_{FD1AE10F-163C-4D4B-9FCE-AC667AF1DC6E}) (Version: 2.8.8.0 - Alienware Corp.) Alienware Command Center (Version: 2.8.8.0 - Alienware Corp.) Hidden Alienware M14x Manual (HKLM-x32\...\InstallShield_{B90A9452-2233-4B2A-8277-5DC4FEC239CB}) (Version: 1.0.1.0 - Alienware Corp.) Alienware M14x Manual (Version: 1.0.1.0 - Alienware Corp.) Hidden Alienware On-Screen Display (HKLM-x32\...\InstallShield_{0D69462F-99CC-4F8D-942E-666E21CE59F8}) (Version: 0.31.1.8C - ) Alienware On-Screen Display (x32 Version: 0.31.1.8C - ) Hidden AlphaGo (HKLM-x32\...\{97D2FBF4-72CF-4DD6-8DA8-26710BC7BE71}) (Version: 1.1.0 - Default Company Name) <==== ATTENTION AlphaGo (HKLM-x32\...\{B7CB7055-EFAE-4CD2-928A-15DB5F4FF7C7}) (Version: 1.2.5 - AlphaGo) <==== ATTENTION Android Studio (HKLM\...\Android Studio) (Version: 1.0 - Google Inc.) Ansel (Version: 378.92 - NVIDIA Corporation) Hidden Apple Application Support (32 bits) (HKLM-x32\...\{D079CAAD-0C31-47A2-9AF5-A82F9CD9B221}) (Version: 5.2 - Apple Inc.) Apple Application Support (64 bits) (HKLM\...\{64E6007B-1DA9-42CD-BBE4-D5FA67A7C71D}) (Version: 5.2 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{55BB2110-FB43-49B3-93F4-945A0CFB0A6C}) (Version: 10.0.1.3 - Apple Inc.) Apple Software Update (HKLM-x32\...\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.) AtlantisRO Updater [v157] (HKLM-x32\...\{FD74BD2F-20CC-438D-B16E-EC9057A3D63C}_is1) (Version: v157 - AtlantisRO) Audacity 2.0.5 (HKLM-x32\...\Audacity_is1) (Version: 2.0.5 - Audacity Team) Auto Clicker by Shocker (HKLM-x32\...\Auto Clicker by Shocker_is1) (Version: V3.0 - shockingsoft.com) AV Voice Changer Software DIAMOND 7.0 (HKLM-x32\...\AV Voice Changer Software DIAMOND 7.0) (Version: 7.0.51 - AVSOFT Corp.) Avidemux 2.6 - 64bits (HKLM-x32\...\Avidemux 2.6 - 64bits (64-bit)) (Version: 2.6.5.8897 - ) Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) bl (x32 Version: 1.0.0 - Your Company Name) Hidden Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.) BufferChm (x32 Version: 140.0.298.000 - Hewlett-Packard) Hidden CamStudio Lossless Codec (HKLM\...\camcodec) (Version: - ) CamStudio OSS Desktop Recorder (HKLM-x32\...\{FD9C31B6-F572-414D-81E3-89368C97A125}_is1) (Version: 2.6 Beta r294 - CamStudio Open Source Dev Team) CodeBlocks (HKU\S-1-5-21-964481591-2532791391-1458198129-1002\...\CodeBlocks) (Version: 13.12 - The Code::Blocks Team) Copy (x32 Version: 140.0.298.000 - Hewlett-Packard) Hidden Cubetractor version 1.0 (HKLM-x32\...\{3D863D86-14DA-4453-96F4-043E5E9F6A43}_is1) (Version: 1.0 - ) CyberLink PowerDirector (HKLM-x32\...\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 9.0.0.2330a - CyberLink Corp.) CyberLink PowerDirector (Version: 9.0.0.2330a - CyberLink Corp.) Hidden CyberLink WaveEditor (HKLM-x32\...\InstallShield_{324F76CC-D8DD-4D87-B77D-D4AF5E1AA7B3}) (Version: 1.0.1.2318 - CyberLink Corp.) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 10.2.0.0115 - Disc Soft Ltd) DAEMON Tools Pro (HKLM-x32\...\DAEMON Tools Pro) (Version: 6.0.0.0444 - Disc Soft Ltd) Dell DataSafe Online (HKLM-x32\...\{7EC66A95-AC2D-4127-940B-0445A526AB2F}) (Version: 2.1.19634 - Dell) Dell System Detect (HKU\S-1-5-21-964481591-2532791391-1458198129-1002\...\58d94f3ce2c27db0) (Version: 7.4.0.3 - Dell) Destinations (x32 Version: 140.0.253.000 - Hewlett-Packard) Hidden DeviceDiscovery (x32 Version: 140.0.298.000 - Hewlett-Packard) Hidden DirectX 9 Runtime (x32 Version: 1.00.0000 - Sonic Solutions) Hidden DnaSP v5 (HKLM-x32\...\{C940408E-6DC5-454B-9727-2CAB0E4A7B12}) (Version: 5.10.0.1 - UB) DocProc (x32 Version: 140.0.185.000 - Hewlett-Packard) Hidden Dolby Axon - 1.5.1.1 (HKLM-x32\...\{17936630-5344-4F18-9970-616129E2A114}_is1) (Version: 1.5.1.1 - Dolby Laboratories) Driver Booster 3.3 (HKLM-x32\...\Driver Booster_is1) (Version: 3.3 - IObit) Dust: An Elysian Tail (HKLM\...\Steam App 236090) (Version: - Humble Hearts LLC) EMSC (x32 Version: 0.0.0.22C - Compal Electronics, Inc.) Hidden Enthought Canopy (64-bit) (HKLM\...\{93D7DF53-FDD4-4270-B83C-1EBC15FA1A87}) (Version: 1.7.3.3335 - Enthought, Inc.) EVEMon (HKLM-x32\...\EVEMon) (Version: 1.8.0.3987 - battleclinic.com) Evoland 1.0 (HKLM-x32\...\Evoland 1.0) (Version: 1.0 - Cat-A-Cat) f.lux (HKU\S-1-5-21-964481591-2532791391-1458198129-1002\...\Flux) (Version: - ) Facebook Video Calling 3.1.0.521 (HKLM-x32\...\{2091F234-EB58-4B80-8C96-8EB78C808CF7}) (Version: 3.1.521 - Skype Limited) Fax (x32 Version: 140.0.307.000 - Hewlett-Packard) Hidden Final Fantasy X X-2 HD Remaster (HKLM-x32\...\Final Fantasy X X-2 HD Remaster_is1) (Version: - ) Foldit (HKLM-x32\...\Foldit) (Version: - ) Fraps (remove only) (HKLM-x32\...\Fraps) (Version: - ) Free Alarm Clock 3.0.3 (HKLM-x32\...\{8ED5A2F1-338F-4608-8AF7-BCD1ADC1E1F7}_is1) (Version: 3.0 - Comfort Software Group) Free WMA to MP3 Converter 1.16 (HKLM-x32\...\Free WMA to MP3 Converter_is1) (Version: - Jodix Technologies Ltd.) Freemake Video Converter version 4.0.2 (HKLM-x32\...\Freemake Video Converter_is1) (Version: 4.0.2 - Ellora Assets Corporation) GitHub (HKU\S-1-5-21-964481591-2532791391-1458198129-1002\...\5f7eb300e2ea4ebf) (Version: 3.3.4.0 - GitHub, Inc.) Go Programming Language amd64 go1.8 (HKLM\...\{E2EACBDF-D16C-4C31-A9DF-76D430959226}) (Version: 1.8 - hxxps://golang.org) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 58.0.3029.110 - Google Inc.) Google Earth Plug-in (HKLM-x32\...\{57BB4801-61C8-4E74-9672-2160728A461E}) (Version: 7.1.5.1557 - Google) Google Gmail Notifier (HKLM-x32\...\{0228e555-4f9c-4e35-a3ec-b109a192b4c2}) (Version: - Google Inc.) Google Talk Plugin (HKLM-x32\...\{F9B579C2-D854-300A-BE62-A09EB9D722E4}) (Version: 5.41.3.0 - Google) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.33.5 - Google Inc.) Hidden GPBaseService2 (x32 Version: 140.0.297.000 - Hewlett-Packard) Hidden gpedt.msc 1.0 (HKLM-x32\...\{10B9C608-BF7C-4CCF-A658-C01D969DCA21}_is1) (Version: - Richard) GTK2-Runtime (HKLM-x32\...\GTK2-Runtime) (Version: 2.24.10-2012-10-10-ash - Alexander Shaduri) Guitar Pro 5.2 (HKLM-x32\...\Guitar Pro 5_is1) (Version: - Arobas Music) Haste Esports Accelerator (HKLM\...\{0CE25888-B1A7-425C-8782-EE25F5D03430}) (Version: 0.99.2300 - Haste) Hextech Repair Tool (HKLM-x32\...\{7F9A97E6-E666-11E5-B582-B88687E82322}) (Version: 1.0.16 - Riot Games, Inc.) HP Customer Participation Program 14.0 (HKLM\...\HPExtendedCapabilities) (Version: 14.0 - HP) HP Imaging Device Functions 14.0 (HKLM\...\HP Imaging Device Functions) (Version: 14.0 - HP) HP Photosmart Officejet and Deskjet All-In-One Driver Software (HKLM\...\{6F5B70F0-EA6C-4A5B-BB16-8390BD66B251}) (Version: 14.0 - HP) HP Solution Center 14.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 14.0 - HP) HPPhotoGadget (x32 Version: 140.0.524.000 - Hewlett-Packard) Hidden HPProductAssistant (x32 Version: 140.0.298.000 - Hewlett-Packard) Hidden ImageMagick 6.7.5-7 Q16 (2012-03-01) (HKLM-x32\...\ImageMagick 6.7.5 Q16_is1) (Version: 6.7.5 - ImageMagick Studio LLC) Integrated Webcam Live! Central (HKLM-x32\...\Integrated Webcam Live! Central) (Version: 2.01.17 - Creative Technology Ltd) Intel XDK (HKU\S-1-5-21-964481591-2532791391-1458198129-1002\...\ARP_for_prd_xdk_0.0.3400) (Version: 0.0.3400 - Intel Corporation) Intel(R) Chipset Device Software (x32 Version: 10.1.1.14 - Intel(R) Corporation) Hidden Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.3347 - Intel Corporation) Intel(R) Wireless Display (HKLM\...\{28EF7372-9087-4AC3-9B9F-D9751FCDF830}) (Version: - ) Intel(R) Wireless Display (HKLM-x32\...\{F84906ED-BB54-4889-B131-FED9C9056FC8}) (Version: 2.0.27.0 - Intel Corporation) Intel® Driver Update Utility (HKLM-x32\...\{66307462-7d19-4f1a-af82-aa04b6017f05}) (Version: 2.6.2.4 - Intel) Intel® Hardware Accelerated Execution Manager (HKLM\...\{ECCB31F5-435D-4F37-A98D-5854D3C62718}) (Version: 1.1.1 - Intel Corporation) IObit Uninstaller (HKLM-x32\...\IObitUninstall) (Version: 5.4.0.125 - IObit) iTunes (HKLM\...\{81C96689-EA5B-4B7D-A04F-16326EC51BC2}) (Version: 12.5.4.42 - Apple Inc.) Java 8 Update 111 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180111F0}) (Version: 8.0.1110.14 - Oracle Corporation) Java 8 Update 112 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180112F0}) (Version: 8.0.1120.15 - Oracle Corporation) Java 8 Update 121 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180121F0}) (Version: 8.0.1210.13 - Oracle Corporation) Java 8 Update 131 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180131F0}) (Version: 8.0.1310.11 - Oracle Corporation) Java SE Development Kit 7 Update 51 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0170510}) (Version: 1.7.0.510 - Oracle) Java SE Development Kit 8 Update 25 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0180250}) (Version: 8.0.250.18 - Oracle Corporation) Java SE Development Kit 8 Update 65 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0180650}) (Version: 8.0.650.17 - Oracle Corporation) JDownloader 0.9 (HKLM-x32\...\5513-1208-7298-9440) (Version: 0.9 - AppWork GmbH) JDownloader 2 (HKLM\...\jdownloader2) (Version: 2.0 - AppWork GmbH) JetBrains WebStorm 2016.3.3 (HKLM-x32\...\WebStorm 2016.3.3) (Version: 163.12024.17 - JetBrains s.r.o.) join.me (HKU\S-1-5-21-964481591-2532791391-1458198129-1002\...\JoinMe) (Version: 1.15.0.136 - LogMeIn, Inc.) KMPFaster (HKLM-x32\...\simplitec POWER SUITE_is1) (Version: 2.3.2.902 - simplitec GmbH) <==== ATTENTION KMPlayer (remove only) (HKLM-x32\...\The KMPlayer) (Version: 4.0.1.5 - PandoraTV) Lasergene 7 v7.1.0 (HKLM-x32\...\Lasergene 7) (Version: - ) LAV Filters 0.67 (HKLM-x32\...\lavfilters_is1) (Version: 0.67 - Hendrik Leppkes) League of Legends (HKLM-x32\...\League of Legends 4.1.2) (Version: 4.1.2 - Riot Games) League of Legends (x32 Version: 4.1.2 - Riot Games) Hidden Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes) ManageMyMobile (HKLM-x32\...\ManageMyMobile_is1) (Version: 1.0 - IObit) MarketResearch (x32 Version: 140.0.299.000 - Hewlett-Packard) Hidden MEGA5 (HKLM-x32\...\{82808A16-D448-4FBF-9AE9-75AF3FC240DC}_is1) (Version: - Arizona State University) MEGA6 .06 (HKLM-x32\...\{EE7E4984-0208-48E7-959C-A5F5F06F0DE0}_is1) (Version: .06 - Center for Evolutionary Medicine and Informatics) MEGAsync (HKLM-x32\...\MEGAsync) (Version: - Mega Limited) Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation) Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{F2508213-9989-4E85-A078-72BE483917EF}) (Version: 3.5.88.0 - Microsoft Corporation) Microsoft Games for Windows Marketplace (HKLM-x32\...\{4CB0307C-565E-4441-86BE-0DF2E4FB828C}) (Version: 3.5.50.0 - Microsoft Corporation) Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUS) (Version: 14.0.4734.1000 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411 (HKLM-x32\...\{5DA8F6CD-C70E-39D8-8430-3D9808D6BD17}) (Version: 9.0.30411 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{820B6609-4C97-3A2B-B644-573B06A0F0CC}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Microsoft XNA Framework Redistributable 3.1 (HKLM-x32\...\{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}) (Version: 3.1.10527.0 - Microsoft Corporation) Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation) MiniTool Partition Wizard Free 10 (HKLM\...\{05D996FA-ADCB-4D23-BA3C-A7C184A8FAC6}_is1) (Version: - MiniTool Solution Ltd.) Monitor Off Utility 1.0 (HKLM-x32\...\{10F0131F-1CA2-4433-8473-7C890C769581}_is1) (Version: - Dekisoft) Mozilla Thunderbird 45.8.0 (x86 es-ES) (HKLM-x32\...\Mozilla Thunderbird 45.8.0 (x86 es-ES)) (Version: 45.8.0 - Mozilla) MSI Afterburner 4.3.0 (HKLM-x32\...\Afterburner) (Version: 4.3.0 - MSI Co., LTD) MSI Kombustor 3.5.2.1 (64-bit) (HKLM\...\{9598DA62-2AE8-426D-9C86-BEA96AC6721E}_is1) (Version: - MSI Co., LTD) MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) NCSOFT Game Launcher (HKLM-x32\...\NCLauncher_NCWest) (Version: - NCSOFT) Nero 2015 (HKLM-x32\...\{763EF8DC-4CC0-47CA-BE1C-BDE731462250}) (Version: 16.0.02900 - Nero AG) Nero Info (HKLM-x32\...\{B791E0AB-87A9-41A4-8D98-D13C2E37D928}) (Version: 16.0.1003 - Nero AG) NetLimiter 3 (HKLM\...\{913923AB-3AAB-4870-8910-627C4CD82789}) (Version: 3.0.0.11 - Locktime Software s.r.o.) Network64 (Version: 140.0.306.000 - Hewlett-Packard) Hidden NVIDIA 3D Vision Driver 378.92 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 378.92 - NVIDIA Corporation) NVIDIA 3D Vision Video Player (HKLM-x32\...\{244FB715-13C4-4C85-BEB6-6C1ABB29D8B1}) (Version: 1.7.5 - NVIDIA Corporation) NVIDIA Graphics Driver 378.92 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 378.92 - NVIDIA Corporation) NVIDIA PhysX System Software 9.16.0318 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.16.0318 - NVIDIA Corporation) OCR Software by I.R.I.S. 14.0 (HKLM\...\HPOCR) (Version: 14.0 - HP) Owlboy (HKLM-x32\...\1159880091_is1) (Version: 2.0.0.3 - GOG.com) PakkISO 0.4 (HKLM-x32\...\PakkISO_is1) (Version: PakkISO 0.4 by zorted, installer by BitLooter - ) PDF-Viewer (HKLM\...\{A278382D-4F1B-4D47-9885-8523F7261E8D}_is1) (Version: 2.5.198.0 - Tracker Software Products Ltd) ph (x32 Version: 1.0.0 - Your Company Name) Hidden PhotoShowExpress (x32 Version: 2.0.063 - Sonic Solutions) Hidden Populus (HKLM-x32\...\Populus) (Version: - ) Prerequisite installer (x32 Version: 16.0.0000 - Nero AG) Hidden Project64 1.6 (HKLM-x32\...\{9559F7CA-5E34-4237-A2D9-D856464AD727}) (Version: 1.6 - Project64) Python 3.5.2 (64-bit) (HKU\S-1-5-21-964481591-2532791391-1458198129-1002\...\{d46281ac-f66b-4246-8cfe-34f61512982f}) (Version: 3.5.2150.0 - Python Software Foundation) Python 3.5.2 Core Interpreter (64-bit) (Version: 3.5.2150.0 - Python Software Foundation) Hidden Python 3.5.2 Development Libraries (64-bit) (Version: 3.5.2150.0 - Python Software Foundation) Hidden Python 3.5.2 Documentation (64-bit) (Version: 3.5.2150.0 - Python Software Foundation) Hidden Python 3.5.2 Executables (64-bit) (Version: 3.5.2150.0 - Python Software Foundation) Hidden Python 3.5.2 pip Bootstrap (64-bit) (Version: 3.5.2150.0 - Python Software Foundation) Hidden Python 3.5.2 Standard Library (64-bit) (Version: 3.5.2150.0 - Python Software Foundation) Hidden Python 3.5.2 Tcl/Tk Support (64-bit) (Version: 3.5.2150.0 - Python Software Foundation) Hidden Python 3.5.2 Test Suite (64-bit) (Version: 3.5.2150.0 - Python Software Foundation) Hidden Python 3.5.2 Utility Scripts (64-bit) (Version: 3.5.2150.0 - Python Software Foundation) Hidden Python Launcher (HKLM-x32\...\{0276F61C-30FC-46D4-BEFE-0EA959C4D691}) (Version: 3.5.2121.0 - Python Software Foundation) QuickTime (HKLM-x32\...\{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}) (Version: 7.66.71.0 - Apple Inc.) R for Windows 2.13.2 (HKLM\...\R for Windows 2.13.2_is1) (Version: 2.13.2 - R Development Core Team) R for Windows 2.15.2 (HKLM\...\R for Windows 2.15.2_is1) (Version: 2.15.2 - R Core Team) Rainmeter (HKLM-x32\...\Rainmeter) (Version: 2.5 r1842 - ) RAR Password Unlocker 4.2.0.0 (HKLM-x32\...\{B789FA51-6A71-408F-92DE-EDE4A517B8F9}_is1) (Version: - Password Unlocker Studio) RBVirtualFolder64Inst (Version: 1.00.0000 - Roxio, Inc.) Hidden ReadCube (HKU\S-1-5-21-964481591-2532791391-1458198129-1002\...\ReadCube) (Version: - Labtiva, Inc.) Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.14393.28161 - Realtek Semiconduct Corp.) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8036 - Realtek Semiconductor Corp.) Revo Uninstaller Pro 3.1.4 (HKLM\...\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 3.1.4 - VS Revo Group, Ltd.) Roxio Creator Starter (HKLM-x32\...\{6F0BBEFE-BE1C-419B-BA1F-D36C9E7915BC}) (Version: 12.1.77.0 - Roxio) Roxio File Backup (Version: 1.3.2 - Roxio) Hidden Samsung USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.63.0 - Samsung Electronics Co., Ltd.) Scan (x32 Version: 140.0.253.000 - Hewlett-Packard) Hidden SDFormatter (HKLM-x32\...\{179324FF-7B16-4BA8-9836-055CAAEE4F08}) (Version: 4.0.0 - SD Association) Skype Click to Call (HKLM-x32\...\{873F8E7C-10E6-449F-BD7E-5FBA7C8E1C9B}) (Version: 8.5.0.9167 - Microsoft Corporation) Skype™ 7.18 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.18.112 - Skype Technologies S.A.) Smart Defrag 3 (HKLM-x32\...\Smart Defrag 3_is1) (Version: 3.2 - IObit) Smart Game Booster 4 (HKLM-x32\...\Smart Game Booster_is1) (Version: 4.0.0 - Smart Game Booster) Smart Switch (HKLM-x32\...\InstallShield_{74FA5314-85C8-4E2A-907D-D9ECCCB770A7}) (Version: 4.1.17022.20 - Samsung Electronics Co., Ltd.) Smart Switch (x32 Version: 4.1.17022.20 - Samsung Electronics Co., Ltd.) Hidden SmartDraw 2012 (HKLM-x32\...\SmartDraw 2012) (Version: - SmartDraw.com) SmartSound Quicktracks 5 (HKLM-x32\...\InstallShield_{2F8BA3FD-1FA9-4279-B696-712ABB12F09F}) (Version: 5.1.7 - SmartSound Software Inc.) SmartSound Quicktracks 5 (x32 Version: 5.1.7 - SmartSound Software Inc.) Hidden SoftEther VPN Client (HKLM\...\softether_sevpnclient) (Version: 4.22.9634 - SoftEther VPN Project) SolutionCenter (x32 Version: 140.0.299.000 - Hewlett-Packard) Hidden Sonic CinePlayer Decoder Pack (x32 Version: 4.3.0 - Sonic Solutions) Hidden SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version: - ) Spotify (HKU\S-1-5-21-964481591-2532791391-1458198129-1002\...\Spotify) (Version: 1.0.31.56.g526cfefe - Spotify AB) SPSS Statistics 17.0 (HKLM-x32\...\{46B65150-F8AA-42F2-94FB-2729A8AE5F7E}) (Version: 17.0.0 - SPSS Inc.) Stardew Valley (HKLM\...\Steam App 413150) (Version: - ConcernedApe) Status (x32 Version: 140.0.342.000 - Hewlett-Packard) Hidden Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) Surfing Protection (HKLM-x32\...\IObit Surfing Protection_is1) (Version: 1.2 - IObit) Swiff Player 1.7.2 (HKLM-x32\...\Swiff Player_is1) (Version: 1.7.2 - GlobFX Technologies) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.1.19.0 - Synaptics Incorporated) TextPad 6 (HKLM-x32\...\{3F04067F-0DA5-4F48-9A89-6FCFD2A9E040}) (Version: 6.1.3 - Helios) The Legend of Heroes Trails in the Sky the 3rd (HKLM-x32\...\The Legend of Heroes Trails in the Sky the 3rd_is1) (Version: - ) TimeLeft (HKLM-x32\...\TIMELEFT3_is1) (Version: 3.57 - NesterSoft Inc.) Toolbox (x32 Version: 140.0.596.000 - Hewlett-Packard) Hidden Torchlight 2 (HKLM-x32\...\1958228073_is1) (Version: 2.0.0.2 - GOG.com) TrayApp (x32 Version: 140.0.297.000 - Hewlett-Packard) Hidden Tree of Savior (English Ver.) (HKLM\...\Steam App 372000) (Version: - IMCGAMES Co.,Ltd.) Ubisoft Game Launcher (HKLM-x32\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT) Unity Web Player (HKU\S-1-5-21-964481591-2532791391-1458198129-1002\...\UnityWebPlayer) (Version: - Unity Technologies ApS) Update_msi (HKLM-x32\...\{59B5A9CD-253D-4C41-A073-B387D4C9672D}) (Version: 1.0.0 - Default Company Name) UsbFix (HKLM-x32\...\Usbfix) (Version: 7.181 - El Desaparecido - www.usbfix.net - www.sosvirus.net) uTorrentBar_ES Toolbar (HKLM-x32\...\uTorrentBar_ES Toolbar) (Version: 6.9.0.16 - uTorrentBar_ES) <==== ATTENTION Vegas Pro 12.0 (64-bit) (HKLM\...\{A7500970-FE98-11E1-B560-F04DA23A5C58}) (Version: 12.0.367 - Sony) Ventrilo Client for Windows x64 (HKLM\...\{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}) (Version: 3.0.8.0 - Flagship Industries, Inc.) VLC media player 1.1.5 (HKLM-x32\...\VLC media player) (Version: 1.1.5 - VideoLAN) VMD 1.9.1 (HKLM-x32\...\{AC0F06C8-865D-4EC4-99CB-0714E2800880}) (Version: 1.9.1 - University of Illinois) Vulkan Run Time Libraries 1.0.39.1 (HKLM\...\VulkanRT1.0.39.1) (Version: 1.0.39.1 - LunarG, Inc.) Wakfu (HKU\S-1-5-21-964481591-2532791391-1458198129-1002\...\1F4715F1-86E7-4450-AA9A-13ADBF14BED1-2) (Version: - Ankama) WebReg (x32 Version: 140.0.297.017 - Hewlett-Packard) Hidden WIDCOMM Bluetooth Software (HKLM\...\{436E0B79-2CFB-4E5F-9380-E17C1B25D0C5}) (Version: 6.3.0.6300 - Broadcom Corporation) Windows 10 Update and Privacy Settings (HKLM\...\{293F2009-0145-450B-B4AA-063D43FB368C}) (Version: 1.0.13.0 - Microsoft Corporation) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation) WinRAR 4.01 (64-bit) (HKLM\...\WinRAR archiver) (Version: 4.01.0 - win.rar GmbH) Xilisoft Video Convertidor Ultimate (HKLM-x32\...\Xilisoft Video Convertidor Ultimate) (Version: 7.7.2.20130217 - Xilisoft) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-964481591-2532791391-1458198129-1002_Classes\CLSID\{144DF3B2-2402-47AE-9583-5A045929A8D4}\InprocServer32 -> C:\Users\Rold\AppData\Local\Google\Update\1.3.33.5\psuser_64.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-964481591-2532791391-1458198129-1002_Classes\CLSID\{e8c77137-e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems) CustomCLSID: HKU\S-1-5-21-964481591-2532791391-1458198129-1002_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Rold\AppData\Local\Google\Update\1.3.33.5\psuser_64.dll (Google Inc.) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {04ACFFB6-810F-4359-91F8-DEDB34F7EF1E} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => %SystemRoot%\ehome\ehPrivJob.exe Task: {0DFFE546-18C8-46A7-BD70-92C49427B746} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION Task: {0ED9915E-79BE-4449-84FF-0E50C127D231} - System32\Tasks\ASC9_PerformanceMonitor => C:\Program Files (x86)\IObit\Advanced SystemCare\Monitor.exe [2016-07-20] (IObit) Task: {118F87EE-F1EE-4F3D-976F-78460D2CCC47} - System32\Tasks\Game_Booster_AutoUpdate => C:\Program Files (x86)\IObit\Game Booster 3\AutoUpdate.exe Task: {13AD7B0E-473D-4A79-9461-C04516129277} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2017-05-22] (Microsoft Corporation) Task: {163AAD54-DE59-4CCD-8527-60D33CBF1B84} - System32\Tasks\ASC9_SkipUac_Rold => C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe [2016-08-16] (IObit) Task: {176711FD-45AC-45F6-AC0A-A6DF717BE2AA} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-964481591-2532791391-1458198129-1002UA => C:\Users\Rold\AppData\Local\Google\Update\GoogleUpdate.exe [2016-11-27] (Google Inc.) Task: {20CC4CAC-A5F1-462B-9303-B826ABE007D7} - System32\Tasks\SDMsgUpdate (TE) => C:\PROGRA~2\SMARTD~1\Messages\SDNotify.exe Task: {25D9C75E-5407-41D1-AB0D-E77CF131168B} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => %SystemRoot%\ehome\mcupdate.exe Task: {26A5E551-6E87-415B-A5BB-8C5FA11BCA4D} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => %SystemRoot%\ehome\ehPrivJob.exe Task: {27A239DF-A4CA-4C43-969A-5B6BF8150638} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION Task: {29232D3F-AC9E-4D8C-91F5-A0390A9E9458} - \Microsoft\Windows\Media Center\VCore -> No File <==== ATTENTION Task: {2939AADA-49A5-4047-8E14-7558C847A34D} - System32\Tasks\{209525A1-571A-43F6-981F-96BC6F119443} => pcalua.exe -a C:\Users\Rold\Downloads\planner-0.14.2.exe -d C:\Users\Rold\Downloads Task: {30AEFC67-F451-41D0-9107-9E3C062295CE} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => %windir%\ehome\MCUpdate.exe Task: {32D77F39-AAE6-4DDC-9384-CBE35AD873F5} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-05-25] (Google Inc.) Task: {3D1B8B0E-6642-4134-B72D-F76D88BE4544} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => %SystemRoot%\ehome\ehPrivJob.exe Task: {3EA77021-EEDE-4A49-B6B1-962CE0947A81} - System32\Tasks\{62944DE0-FCA9-4DF9-9EAB-0E2AB408253B} => pcalua.exe -a "C:\GOG Games\Pillars of Eternity\unins000.exe" Task: {480CF2AD-C93B-49A0-9C1B-2A61B0D697F0} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2017-03-16] (NVIDIA Corporation) Task: {485FC5D4-C7E3-44E7-B415-BBC350978BCE} - \{86BBC30A-0B06-49E4-9F62-EC046E7E1457} -> No File <==== ATTENTION Task: {4AB56719-9F93-4AAE-8154-6F7CF421974D} - System32\Tasks\Nero\Nero Info => C:\Program Files (x86)\Common Files\Nero\Nero Info\NeroInfo.exe [2014-07-21] (Nero AG) Task: {4B4A0EF9-F50C-4FA3-A6F4-20B911B80A87} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-05-09] (Adobe Systems Incorporated) Task: {4CE4033A-BEB9-45F8-9ACE-085A50C2E917} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => %SystemRoot%\ehome\ehPrivJob.exe Task: {61F655F8-95BD-4DB3-8ED4-1E46AFDA3A7B} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => %SystemRoot%\ehome\mcupdate.exe Task: {62340125-076E-4825-A77C-83A87BD9725F} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-964481591-2532791391-1458198129-1002Core => C:\Users\Rold\AppData\Local\Google\Update\GoogleUpdate.exe [2016-11-27] (Google Inc.) Task: {62CD5F12-2156-440D-BE8B-E128153E58A2} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => %SystemRoot%\ehome\ehPrivJob.exe Task: {65E57913-C6C9-49C1-AF99-00CE47CF669B} - System32\Tasks\Driver Booster SkipUAC (Rold) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe [2016-03-23] (IObit) Task: {674F76FF-56FF-4321-BA2F-95A513CCB65F} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-03-16] (NVIDIA Corporation) Task: {69414B1E-C30A-4EE2-BCC9-D6F2D47DC905} - \{70140A8E-099F-45EA-9B3A-37AA33DE9629} -> No File <==== ATTENTION Task: {70FCB84C-3F3A-4C50-81A5-48B98FF29C0D} - System32\Tasks\SmartDefrag3_Startup => C:\Program Files (x86)\IObit\Smart Defrag 3\SmartDefrag.exe [2014-07-02] (IObit) Task: {710C6D31-48CC-4391-AA72-010DAD8154A0} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.) Task: {76DC1DC0-8C08-42E4-A879-BD7A5F468BD6} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-964481591-2532791391-1458198129-1002UA => C:\Users\Rold\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-05-12] (Facebook Inc.) Task: {7A14CA65-B2A2-4788-B4F3-D25BEFE56933} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => %SystemRoot%\ehome\mcupdate.exe Task: {7C5EF484-A4D1-4877-9765-F6BE8846A706} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION Task: {83AC1D38-169D-4F3C-A414-96DC5458212D} - System32\Tasks\SmartDefrag3_Update => C:\Program Files (x86)\IObit\Smart Defrag 3\AutoUpdate.exe [2014-07-03] (IObit) Task: {873811C2-7906-47C3-B6EB-4AFF4E178ABD} - System32\Tasks\{9EB174FC-E133-4A07-8FE3-CE2297963144} => pcalua.exe -a "C:\Program Files (x86)\IObit\Advanced SystemCare 5\SecurityHole_Backup\KB2467173.exe" -d C:\Windows\system32 -c /quiet /norestart Task: {882CE2C7-B6DB-488E-BD17-A5B0B8FE4BAA} - System32\Tasks\simplitec Power Suite => C:\Program Files (x86)\simplitec\KMPFaster\PowerSuite.exe <==== ATTENTION Task: {8B3454B0-E5CB-4BEA-9D5F-DC36E6E6A619} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => %SystemRoot%\ehome\ehPrivJob.exe Task: {8CC764A0-B47D-4174-9FED-261CA4736C55} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => %SystemRoot%\ehome\ehPrivJob.exe Task: {914CDD65-2169-4B24-9B3B-C32CF79AFEBC} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-03-16] (NVIDIA Corporation) Task: {970FDDDD-844C-4DAB-B995-9509055C96C1} - System32\Tasks\Driver Booster Scheduler => C:\Program Files (x86)\IObit\Driver Booster\Scheduler.exe [2016-03-23] (IObit) Task: {9E7C479B-26CB-4960-907A-CE0A6D7F8960} - System32\Tasks\USER_ESRV_SVC_QUEENCREEK => Wscript.exe //B //NoLogo "C:\Program Files\Intel\SUR\QUEENCREEK\task.vbs" Task: {A391FC97-8A03-4F97-B06E-7ECB787DD036} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-964481591-2532791391-1458198129-1002Core => C:\Users\Rold\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-05-12] (Facebook Inc.) Task: {A45031B4-CE64-45E6-A290-E46EE19ED9FE} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => %SystemRoot%\ehome\ehPrivJob.exe Task: {A7C97C6F-A1C9-4C87-8829-D0850AF7B1E7} - \OfficeSoftwareProtectionPlatform\SvcRestartTask -> No File <==== ATTENTION Task: {A937D392-4F6E-4AED-B09F-7D7B77CDDF1F} - System32\Tasks\Uninstaller_SkipUac_Rold => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [2016-06-24] (IObit) Task: {B80B82BB-EF32-41FC-82B7-78EA124485F8} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => %SystemRoot%\ehome\mcupdate.exe Task: {B8541BDC-C229-498C-9F4F-02E7897007D0} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => %SystemRoot%\ehome\ehPrivJob.exe Task: {B91037F8-16FF-4386-A4C7-6AEE26BB2C1B} - System32\Tasks\SmartGameBooster SkipUAC (Rold) => C:\Program Files (x86)\PCGameBoost\Smart Game Booster\SgbMain.exe [2016-12-20] () Task: {BAEE117B-20B4-49EA-94A2-D757CE74E18B} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => %SystemRoot%\ehome\mcupdate.exe Task: {BD17E5F9-75C4-4C5C-9F91-ADDF53FAAD35} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\WINDOWS\explorer.exe /NOUACCHECK Task: {C0489DAE-6B7A-446F-8BB4-3D21EB31318E} - System32\Tasks\Intel\Intel Telemetry 2 => C:\Program Files\Intel\Telemetry 2.0\lrio.exe [2016-03-17] (Intel Corporation) Task: {C3CEC8B6-F3AD-4506-8117-16C28155D67A} - System32\Tasks\{07AEDE28-2F1C-4DF2-9033-527BE4C94D75} => pcalua.exe -a "C:\Users\Rold\Desktop\Rold's\Programas\AdobeAudition 3.0\Audition3__.sfx.exe" -d "C:\Users\Rold\Desktop\Rold's\Programas\AdobeAudition 3.0" Task: {CA209243-FFD3-4C33-8101-CF53D720C344} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => %SystemRoot%\ehome\ehPrivJob.exe Task: {D019F422-AE8B-492A-9630-D2D40C211A06} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => c:\Program Files\Microsoft Security Client\MpCmdRun.exe Task: {D06A6427-B243-4C81-8291-C476137F0C43} - System32\Tasks\SmartGameBooster Update => C:\Program Files (x86)\PCGameBoost\Smart Game Booster\SgbUpdater.exe [2016-12-19] () Task: {D1BF1D74-2BA7-46E6-ADB1-A5A6A8E18D3D} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION Task: {D33852CA-C423-4FD3-AC01-697759769829} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => %SystemRoot%\ehome\ehPrivJob.exe Task: {E7CE2F71-A981-4344-A9D2-3CF6FE79E734} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => %SystemRoot%\ehome\ehrec.exe Task: {E9DB672A-CACC-4BED-98AA-9AF40C9C5975} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-03-16] (NVIDIA Corporation) Task: {ECB6050B-1EED-402B-8686-244B9ACDCB1D} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => %SystemRoot%\ehome\ehPrivJob.exe Task: {EF62269D-A795-4E81-B886-6C8C9588251C} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => %SystemRoot%\ehome\ehPrivJob.exe Task: {F2791032-D843-428C-B8CD-FC3F87E5FCF3} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-03-16] (NVIDIA Corporation) Task: {F32800E6-2484-4249-B5AF-0A49C600CD90} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => %SystemRoot%\ehome\mcupdate.exe Task: {F365DE6C-571F-4B97-B178-88BE6EF6442A} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => %SystemRoot%\ehome\mcupdate.exe Task: {F5E84058-3189-4302-85DA-F94DC7BEBB78} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-05-25] (Google Inc.) Task: {FC765D34-B222-4F51-8822-DC35B345FF5F} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => %SystemRoot%\ehome\ehrec.exe Task: {FDF6F0F4-B97A-43C4-A3B7-C610E87B9EB1} - System32\Tasks\{0218FD06-142A-49A8-9A1D-F1AC779E29AF} => pcalua.exe -a F:\SETUP.EXE -d F:\ Task: {FE6F2E4D-2BF1-4FD3-8EB5-FC12E96A58C5} - System32\Tasks\Uninstaller_SkipUac_Administrator => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [2016-06-24] (IObit) Task: {FF221CA5-1E98-41EF-A6D5-2A34FEFC2BA8} - System32\Tasks\simplitec Power Suite (Tray) => C:\Program Files (x86)\simplitec\KMPFaster\ServiceProvider.exe <==== ATTENTION (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\ASC9_SkipUac_Rold.job => C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe Task: C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-964481591-2532791391-1458198129-1002Core.job => C:\Users\Rold\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-964481591-2532791391-1458198129-1002UA.job => C:\Users\Rold\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\WINDOWS\Tasks\SDMsgUpdate (TE).job => C:\PROGRA~2\SMARTD~1\Messages\SDNotify.exe\-PTE -V20000102 -SSDU.ini -A -Mhxxp:/www.smartdraw.com/msgs/messagecheck.asp Task: C:\WINDOWS\Tasks\simplitec Power Suite (Tray).job => C:\Program Files (x86)\simplitec\KMPFaster\ServiceProvider.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\simplitec Power Suite.job => C:\Program Files (x86)\simplitec\KMPFaster\PowerSuite.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\Uninstaller_SkipUac_Rold.job => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) Shortcut: C:\Users\Rold\Downloads\Desktop\Rold's\FCB - Lic. en Biotecnología Genómica\Mesa Directiva\Archivos Mesa 2010 - 2011\respaldo\Mesa\Entorno de red\Mis sitios Web en MSN\target.lnk -> hxxp://www.msnusers.co Shortcut: C:\Users\Rold\Downloads\Desktop\Rold's\FCB - Lic. en Biotecnología Genómica\5to. Semestre\5to. USB\Mesa\Archivos Mesa 2010 - 2011\respaldo\Mesa\Entorno de red\Mis sitios Web en MSN\target.lnk -> hxxp://www.msnusers.co Shortcut: C:\Users\Rold\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome\Menú de aplicaciones de Chrome.lnk -> C:\Users\Rold\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome () ShortcutWithArgument: C:\Users\Rold\AppData\Local\Google\Chrome\User Data Default\Menú de aplicaciones de Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --show-app-list ShortcutWithArgument: C:\Users\Rold\AppData\Local\Google\Chrome\User Data\Menú de aplicaciones de Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --show-app-list ShortcutWithArgument: C:\Users\Rold\AppData\Local\Bangtony\User Data\Menú de aplicaciones de Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --show-app-list ShortcutWithArgument: C:\Users\Rold\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Enthought Canopy (64-bit)\Canopy 64-bit command prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) -> /k C:\Users\Rold\AppData\Local\Enthought\Canopy\User\Scripts\activate.bat ==================== Loaded Modules (Whitelisted) ============== 2016-07-16 06:42 - 2016-07-16 06:42 - 00231424 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll 2017-05-09 17:14 - 2017-04-27 19:49 - 02681200 _____ () C:\WINDOWS\system32\CoreUIComponents.dll 2017-03-28 15:21 - 2017-03-16 18:16 - 00133056 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2016-10-05 19:17 - 2016-10-05 19:17 - 00092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2016-11-17 02:28 - 2016-11-17 02:28 - 01353528 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2012-02-07 17:33 - 2010-08-19 18:43 - 00386344 _____ () C:\Program Files\CyberLink\Shared files\RichVideo64.exe 2011-08-28 09:34 - 2011-07-08 10:12 - 02749248 ____N () C:\Program Files (x86)\AlienRespawn\COMPONENTS\SCHEDULER\STSERVICE.EXE 2017-05-09 17:14 - 2017-04-27 19:49 - 02681200 _____ () C:\WINDOWS\SYSTEM32\CoreUIComponents.dll 2017-04-26 11:32 - 2017-04-26 11:32 - 00598528 _____ () C:\Users\Rold\AppData\Local\MEGAsync\ShellExtX64.dll 2016-05-22 19:33 - 2016-05-22 19:33 - 00491184 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll 2016-08-21 15:55 - 2016-08-21 15:55 - 00959168 _____ () C:\Users\Rold\AppData\Local\Microsoft\OneDrive\17.3.6381.0405\amd64\ClientTelemetry.dll 2010-01-09 21:17 - 2010-01-09 21:17 - 04254560 _____ () C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF 2010-01-21 02:40 - 2010-01-21 02:40 - 08794464 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll 2012-01-06 03:05 - 2011-05-28 23:05 - 00164864 _____ () C:\Program Files\WinRAR\rarext.dll 2016-12-27 14:31 - 2016-12-06 16:05 - 00133296 _____ () C:\Program Files (x86)\PCGameBoost\Smart Game Booster\MenuExt64.dll 2016-09-16 22:46 - 2016-09-06 23:56 - 00134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll 2017-03-14 20:15 - 2017-03-04 01:31 - 00474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll 2017-03-14 20:15 - 2017-03-04 01:30 - 00693248 _____ () C:\Windows\ShellExperiences\MtcUvc.dll 2017-03-14 20:16 - 2017-03-04 01:12 - 09760768 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2017-03-14 20:16 - 2017-03-04 01:05 - 01401856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2017-03-14 20:16 - 2017-03-04 01:05 - 00757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll 2017-05-09 17:14 - 2017-04-27 18:36 - 02424320 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll 2017-05-09 17:14 - 2017-04-27 18:37 - 04853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll 2017-05-08 22:19 - 2017-05-08 22:21 - 00074752 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.15.597.0_x64__kzf8qxf38zg5c\SkypeHost.exe 2017-05-08 22:19 - 2017-05-08 22:21 - 00201728 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.15.597.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll 2017-05-08 22:19 - 2017-05-08 22:21 - 43195904 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.15.597.0_x64__kzf8qxf38zg5c\SkyWrap.dll 2017-05-08 22:19 - 2017-05-08 22:21 - 02457088 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.15.597.0_x64__kzf8qxf38zg5c\skypert.dll 2011-01-10 16:16 - 2011-01-10 16:16 - 01545584 _____ () C:\Program Files (x86)\Alienware On-Screen Display\AlienwareOn-ScreenDisplay.exe 2017-03-09 02:16 - 2017-03-09 02:16 - 00112264 _____ () C:\Windows\System32\IccLibDll_x64.dll 2016-10-24 05:03 - 2016-10-24 05:03 - 00589512 _____ () C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe 2017-05-25 17:19 - 2017-05-09 04:13 - 03767640 _____ () C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.110\libglesv2.dll 2017-05-25 17:19 - 2017-05-09 04:13 - 00100696 _____ () C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.110\libegl.dll 2013-12-20 12:57 - 2014-10-16 10:26 - 00622880 _____ () C:\Program Files (x86)\IObit\LiveUpdate\ProductStatistics.dll 2014-09-04 13:56 - 2014-06-04 15:17 - 00892288 _____ () C:\Program Files (x86)\IObit\Smart Defrag 3\webres.dll 2017-05-22 14:51 - 2015-12-23 18:32 - 00355616 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare\madExcept_.bpl 2017-05-22 14:51 - 2015-12-23 18:32 - 00190240 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare\madBasic_.bpl 2017-05-22 14:51 - 2015-12-23 18:32 - 00057632 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare\madDisAsm_.bpl 2009-12-18 11:07 - 2009-12-18 11:07 - 00577536 _____ () C:\Program Files (x86)\Alienware On-Screen Display\EMSC.dll 2017-05-22 14:51 - 2015-12-23 18:32 - 00190240 _____ () C:\Program Files (x86)\IObit\IObit Uninstaller\madBasic_.bpl 2017-05-22 14:51 - 2015-12-23 18:32 - 00057632 _____ () C:\Program Files (x86)\IObit\IObit Uninstaller\madDisAsm_.bpl 2016-10-10 11:46 - 2016-10-10 11:46 - 00228864 _____ () C:\Program Files (x86)\MSI Afterburner\RTCore.dll 2016-10-10 11:46 - 2016-10-10 11:46 - 00056832 _____ () C:\Program Files (x86)\MSI Afterburner\RTFC.dll 2016-10-10 11:46 - 2016-10-10 11:46 - 00071680 _____ () C:\Program Files (x86)\MSI Afterburner\RTMUI.dll 2016-10-10 11:46 - 2016-10-10 11:46 - 00357888 _____ () C:\Program Files (x86)\MSI Afterburner\RTUI.dll 2016-10-10 11:46 - 2016-10-10 11:46 - 00526848 _____ () C:\Program Files (x86)\MSI Afterburner\RTHAL.dll 2017-05-04 21:27 - 2016-02-01 16:40 - 00002048 _____ () C:\Program Files (x86)\DAEMON Tools Pro\MSIMG32.dll 2017-05-22 14:51 - 2015-12-28 13:50 - 00899872 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare\webres.dll 2017-05-22 14:51 - 2015-12-28 13:50 - 01293088 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare\Scan.dll 2017-05-22 14:51 - 2015-12-28 13:49 - 00629536 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare\ProductStatistics.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer => ""="Server" ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) IE trusted site: HKU\S-1-5-21-964481591-2532791391-1458198129-1002\...\clonewarsadventures.com -> clonewarsadventures.com IE trusted site: HKU\S-1-5-21-964481591-2532791391-1458198129-1002\...\freerealms.com -> freerealms.com IE trusted site: HKU\S-1-5-21-964481591-2532791391-1458198129-1002\...\soe.com -> soe.com IE trusted site: HKU\S-1-5-21-964481591-2532791391-1458198129-1002\...\sony.com -> sony.com IE restricted site: HKU\S-1-5-21-964481591-2532791391-1458198129-1002\...\008i.com -> 008i.com IE restricted site: HKU\S-1-5-21-964481591-2532791391-1458198129-1002\...\008k.com -> 008k.com IE restricted site: HKU\S-1-5-21-964481591-2532791391-1458198129-1002\...\00hq.com -> 00hq.com IE restricted site: HKU\S-1-5-21-964481591-2532791391-1458198129-1002\...\0190-dialers.com -> 0190-dialers.com IE restricted site: HKU\S-1-5-21-964481591-2532791391-1458198129-1002\...\01i.info -> 01i.info IE restricted site: HKU\S-1-5-21-964481591-2532791391-1458198129-1002\...\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com IE restricted site: HKU\S-1-5-21-964481591-2532791391-1458198129-1002\...\05p.com -> 05p.com IE restricted site: HKU\S-1-5-21-964481591-2532791391-1458198129-1002\...\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com IE restricted site: HKU\S-1-5-21-964481591-2532791391-1458198129-1002\...\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com IE restricted site: HKU\S-1-5-21-964481591-2532791391-1458198129-1002\...\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com IE restricted site: HKU\S-1-5-21-964481591-2532791391-1458198129-1002\...\0calories.net -> 0calories.net IE restricted site: HKU\S-1-5-21-964481591-2532791391-1458198129-1002\...\0cj.net -> 0cj.net IE restricted site: HKU\S-1-5-21-964481591-2532791391-1458198129-1002\...\0scan.com -> 0scan.com IE restricted site: HKU\S-1-5-21-964481591-2532791391-1458198129-1002\...\1-britney-spears-nude.com -> 1-britney-spears-nude.com IE restricted site: HKU\S-1-5-21-964481591-2532791391-1458198129-1002\...\1-domains-registrations.com -> 1-domains-registrations.com IE restricted site: HKU\S-1-5-21-964481591-2532791391-1458198129-1002\...\1-se.com -> 1-se.com IE restricted site: HKU\S-1-5-21-964481591-2532791391-1458198129-1002\...\1001movie.com -> 1001movie.com IE restricted site: HKU\S-1-5-21-964481591-2532791391-1458198129-1002\...\1001night.biz -> 1001night.biz IE restricted site: HKU\S-1-5-21-964481591-2532791391-1458198129-1002\...\100gal.net -> 100gal.net IE restricted site: HKU\S-1-5-21-964481591-2532791391-1458198129-1002\...\100sexlinks.com -> 100sexlinks.com There are 4791 more sites. ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-964481591-2532791391-1458198129-1002\Control Panel\Desktop\\Wallpaper -> C:\Users\Rold\Downloads\Desktop\Rold's\Fotos\wallpaper\gabriel_the_seventh_angel WALLPAPER 2.jpg DNS Servers: 192.168.1.254 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is disabled. ==================== MSCONFIG/TASK MANAGER disabled items == MSCONFIG\Services: NAUpdate => 2 MSCONFIG\Services: NvStreamNetworkSvc => 3 MSCONFIG\Services: NvStreamSvc => 2 MSCONFIG\Services: Update service => 2 MSCONFIG\startupfolder: C:^Users^Rold^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2010 Screen Clipper and Launcher.lnk => C:\Windows\pss\OneNote 2010 Screen Clipper and Launcher.lnk.Startup MSCONFIG\startupfolder: C:^Users^Rold^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^TimeLeft.lnk => C:\Windows\pss\TimeLeft.lnk.Startup MSCONFIG\startupreg: Adobe ARM => c:\program files (x86)\common files\adobe\arm\1.0\adobearm.exe MSCONFIG\startupreg: Adobe Reader Speed Launcher => "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" MSCONFIG\startupreg: Akamai NetSession Interface => c:\users\rold\appdata\local\akamai\netsession_win.exe MSCONFIG\startupreg: ApnUpdater => MSCONFIG\startupreg: APSDaemon => c:\program files (x86)\common files\apple\apple application support\apsdaemon.exe MSCONFIG\startupreg: BCSSync => "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices MSCONFIG\startupreg: Command Center Controllers => MSCONFIG\startupreg: Dekisoft Monitor Off Utility => MSCONFIG\startupreg: Dell DataSafe Online => c:\program files (x86)\dell\dell datasafe online\nobuclient.exe MSCONFIG\startupreg: Desktop Disc Tool => "C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe" MSCONFIG\startupreg: Facebook Update => "c:\users\rold\appdata\local\facebook\update\facebookupdate.exe" /c /nocrashserver MSCONFIG\startupreg: FreeAC => c:\program files (x86)\freealarmclock\freealarmclock.exe -autorun MSCONFIG\startupreg: FreeFallProtection => MSCONFIG\startupreg: GeDoSaToTool => c:\gedosato\gedosatotool.exe -m MSCONFIG\startupreg: Google Update => "C:\Users\Rold\AppData\Local\Google\Update\GoogleUpdate.exe" /c MSCONFIG\startupreg: HotKeysCmds => c:\windows\system32\hkcmd.exe MSCONFIG\startupreg: IAStorIcon => MSCONFIG\startupreg: Iminent => MSCONFIG\startupreg: IminentMessenger => MSCONFIG\startupreg: Integrated Webcam Live! Central => "c:\program files (x86)\integrated webcam\live! central\webcamint.exe" /mode2 MSCONFIG\startupreg: IntelWireless => MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe" MSCONFIG\startupreg: kakita => wscript.exe //B "C:\Users\Rold\AppData\Local\Temp\kakita.vbs" MSCONFIG\startupreg: MKLOL => "c:\program files (x86)\mkjogo\mklol\mk.exe" -auto MSCONFIG\startupreg: NetLimiter => C:\Program Files\NetLimiter 3\NLClientApp.exe /tray MSCONFIG\startupreg: NvBackend => c:\program files (x86)\nvidia corporation\update core\nvbackend.exe MSCONFIG\startupreg: Nvtmru => MSCONFIG\startupreg: PC Auto Shutdown => "C:\Program Files (x86)\PC Auto Shutdown\AutoShutdown.exe" MSCONFIG\startupreg: Persistence => c:\windows\system32\igfxpers.exe MSCONFIG\startupreg: PriceMeterW => c:\users\rold\appdata\local\pricemeter\pricemeterw.exe MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime MSCONFIG\startupreg: RoxWatchTray => c:\program files (x86)\common files\roxio shared\oem\12.0\sharedcom\roxwatchtray12oem.exe MSCONFIG\startupreg: RtHDVBg => MSCONFIG\startupreg: RTHDVCPL => MSCONFIG\startupreg: ShadowPlay => c:\windows\system32\rundll32.exe c:\windows\system32\nvspcap64.dll,shadowplayonsystemstart MSCONFIG\startupreg: SmartRAM => "c:\program files (x86)\iobit\advanced systemcare 7\suo10_smartram.exe" /m MSCONFIG\startupreg: Spotify => "c:\users\rold\appdata\roaming\spotify\spotify.exe" -autostart -minimized MSCONFIG\startupreg: Spotify Web Helper => c:\users\rold\appdata\roaming\spotify\spotifywebhelper.exe MSCONFIG\startupreg: Steam => "c:\program files (x86)\steam\steam.exe" -silent MSCONFIG\startupreg: SynTPEnh => MSCONFIG\startupreg: WTFast Tray => "c:\program files (x86)\wtfast\wtfast.exe" trayonly MSCONFIG\startupreg: Zune Launcher => "C:\Program Files\Zune\ZuneLauncher.exe" MSCONFIG\startupreg: {0228e555-4f9c-4e35-a3ec-b109a192b4c2} => c:\program files (x86)\google\gmail notifier\gnotify.exe HKLM\...\StartupApproved\Run: => "iTunesHelper" HKLM\...\StartupApproved\Run32: => "IObit Malware Fighter" HKU\S-1-5-21-964481591-2532791391-1458198129-1002\...\StartupApproved\Run: => "GeDoSaToTool" HKU\S-1-5-21-964481591-2532791391-1458198129-1002\...\StartupApproved\Run: => "Spotify Web Helper" HKU\S-1-5-21-964481591-2532791391-1458198129-1002\...\StartupApproved\Run: => "DAEMON Tools Lite Automount" HKU\S-1-5-21-964481591-2532791391-1458198129-1002\...\StartupApproved\Run: => "DAEMON Tools Pro Agent" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{32EBE6A2-BFAF-4C96-8E67-BE457E57C967}] => (Allow) C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe FirewallRules: [{5B3B6A0B-A547-4560-A9B2-BCA29066B310}] => (Allow) C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe FirewallRules: [{C3E50B6F-35E4-4E58-B498-A7C19061448D}] => (Allow) C:\Riot Games\League of Legends\lol.launcher.exe FirewallRules: [{32D19403-D3AA-44A6-9C21-472BB8CC1B44}] => (Allow) C:\Riot Games\League of Legends\lol.launcher.exe FirewallRules: [{B5913172-0420-4EB0-ABF5-979235A9828F}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\AutoUpdate.exe FirewallRules: [{2535E70C-C1B2-4E9D-941B-2BA5B8F2609A}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\AutoUpdate.exe FirewallRules: [{C4D0FACD-3918-417A-BFCD-FD981A17B5E4}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\DBDownloader.exe FirewallRules: [{FE7F8F0D-A1D1-4035-A5D1-2693F6E372EC}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\DBDownloader.exe FirewallRules: [{EA74C264-7FE5-42DE-B02D-DEDED678D982}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe FirewallRules: [{03132E50-62BF-499A-A09A-A7D5242C8924}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe FirewallRules: [{E129AEB3-BE15-4151-89EC-91582937201F}] => (Allow) C:\Program Files (x86)\DolbyAxon\Axon.exe FirewallRules: [{FE7B3EF8-391C-4C9E-A97D-F5A077A0AF35}] => (Allow) C:\Program Files (x86)\DolbyAxon\Axon.exe FirewallRules: [{99AFCD37-3ABA-4D53-9878-62CEF8F49A8D}] => (Allow) C:\Users\Rold\AppData\Local\Facebook\Video\Skype\FacebookVideoCalling.exe FirewallRules: [UDP Query User{1E6EDBFF-3B52-48D5-8B16-170289263533}C:\users\rold\downloads\av voice changer software diamond 7.0.51 [chingliu]\activator\hfs279.exe] => (Allow) C:\users\rold\downloads\av voice changer software diamond 7.0.51 [chingliu]\activator\hfs279.exe FirewallRules: [TCP Query User{DF1E38DC-1A42-41F6-BAC9-FE80AEF69855}C:\users\rold\downloads\av voice changer software diamond 7.0.51 [chingliu]\activator\hfs279.exe] => (Allow) C:\users\rold\downloads\av voice changer software diamond 7.0.51 [chingliu]\activator\hfs279.exe FirewallRules: [UDP Query User{CC1517E1-931E-491A-BA41-8A7970ED1F57}C:\program files (x86)\java\jre7\bin\java.exe] => (Allow) C:\program files (x86)\java\jre7\bin\java.exe FirewallRules: [TCP Query User{32A3D9E4-9C19-4F69-BB81-2FA60A98EBA3}C:\program files (x86)\java\jre7\bin\java.exe] => (Allow) C:\program files (x86)\java\jre7\bin\java.exe FirewallRules: [UDP Query User{04A36610-5BCA-41EE-8E8B-8BFD138BA6E2}C:\users\rold\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\rold\appdata\local\akamai\netsession_win.exe FirewallRules: [TCP Query User{09403399-DCA4-488F-9231-823A80B63313}C:\users\rold\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\rold\appdata\local\akamai\netsession_win.exe FirewallRules: [{99F94364-7816-4701-9698-7A89E644EFC4}] => (Allow) C:\Users\Rold\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{E12618B7-C7FD-433D-86E0-222B4F22A7D3}] => (Allow) C:\Users\Rold\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{D19FF9BE-A4F8-40D1-85DB-94A97ACDB775}] => (Allow) C:\Users\Rold\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{EA403685-CB88-4910-BC4E-59B9A317EA3D}] => (Allow) C:\Users\Rold\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{3728B18E-2510-4093-85D2-EBA64FB6D30A}] => (Allow) C:\Users\Rold\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe FirewallRules: [{C97A6579-479E-4684-B00F-8EF1D401186A}] => (Allow) C:\Users\Rold\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe FirewallRules: [{D48D1E29-3006-4819-B6DE-88E8602E62ED}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{BEACB5EB-B480-4AFD-AC02-5B03EE14FCCF}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{BC6B95A6-D6EE-40B2-BC46-3F4EFD7D69B4}] => (Allow) C:\Program Files (x86)\SPSSInc\Statistics17\statistics.com FirewallRules: [{DF9F3A5F-A1B7-4DD7-B3D7-F323DD543EC0}] => (Allow) C:\Program Files (x86)\SPSSInc\Statistics17\statistics.com FirewallRules: [{D4A2D418-35D5-4D56-86AE-54B2547FFC81}] => (Allow) C:\Program Files (x86)\SPSSInc\Statistics17\statistics.exe FirewallRules: [{F77798EA-AC65-4EB8-A93D-27D71FECAB61}] => (Allow) C:\Program Files (x86)\SPSSInc\Statistics17\SPSSWinWrapIDE.exe FirewallRules: [{EC1972F2-CF7C-45C5-9176-BDBFF7F0396E}] => (Allow) C:\Program Files (x86)\SPSSInc\Statistics17\statistics.exe FirewallRules: [{BB81C2D8-B8BE-4BF8-BAA9-6956111F6312}] => (Allow) C:\Program Files (x86)\SPSSInc\Statistics17\SPSSWinWrapIDE.exe FirewallRules: [{FDA53C62-7977-4D28-BD3D-B52FEF30F7FF}] => (Allow) C:\Program Files\Ventrilo\Ventrilo.exe FirewallRules: [{E97D30F8-BC21-40F9-B131-6D71132CF4EF}] => (Allow) C:\Program Files\Ventrilo\Ventrilo.exe FirewallRules: [{A6618917-A960-4FCD-9575-6705CCE9CA48}] => (Allow) C:\Program Files\CyberLink\PowerDirector\PDR9.EXE FirewallRules: [{FACF3A74-F954-425A-BC78-061576795C4C}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{5E4F1ABA-E20E-4302-B8A1-177AEEFCDD3F}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe FirewallRules: [{B67CB7EE-A7ED-467F-9FB2-535692086602}] => (Allow) LPort=1900 FirewallRules: [{59F13993-B15C-4963-91F7-C3BA6829DCC7}] => (Allow) LPort=2869 FirewallRules: [{CDC636C7-ED0C-41FD-9E02-5AAF4DD11FBE}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe FirewallRules: [{F7448DAB-DFB9-48F2-BAB2-FE090517367C}] => (Allow) C:\Users\Rold\AppData\Local\Akamai\netsession_win.exe FirewallRules: [{CA260BB8-94E8-4E69-AF84-827566D99572}] => (Allow) C:\Users\Rold\AppData\Local\Akamai\netsession_win.exe FirewallRules: [{C5078C59-DDBF-43B3-95A4-78EC61903892}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{FBDAC67D-F211-4C4C-8B15-29360C9FFA1D}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{B5C595A3-E86F-4C90-82A3-A9A3FE383C0F}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{3540EB31-DD3E-4CA8-A284-2394C86449A5}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{2AA2AA44-35B8-480F-A451-3FEC6D78886D}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe FirewallRules: [{FE9D0E17-D691-42B9-937C-AAB21E3802C7}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe FirewallRules: [{51A51C88-D504-4A7F-A066-4F0E9792A955}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe FirewallRules: [TCP Query User{8A1F21A1-40E6-4405-999B-F40832AE291F}C:\users\rold\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\rold\appdata\roaming\spotify\spotify.exe FirewallRules: [UDP Query User{A6FA1A6F-B68A-4BBB-B162-B2B823C0AA11}C:\users\rold\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\rold\appdata\roaming\spotify\spotify.exe FirewallRules: [{FCBE745F-381C-49CC-A15B-4D5FB3319A70}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe FirewallRules: [{7FE77F8E-DEE8-49C4-BDD6-FD930C74843A}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe FirewallRules: [{0772AD68-F152-41BB-BCAD-111BAE4A995C}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpofxm08.exe FirewallRules: [{26A41385-CFD4-4115-9FAC-261B03CF8F23}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposfx08.exe FirewallRules: [{20056809-DC33-4806-A7E4-911B90A3614D}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposid01.exe FirewallRules: [{446EE410-14C3-4509-A9C4-D43BE1FCD74A}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqkygrp.exe FirewallRules: [{50607CE5-225B-4E2B-8F4D-662BB596F6E4}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcopy2.exe FirewallRules: [{6A3433DB-D71E-45A7-9D95-15587BB6262C}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpfccopy.exe FirewallRules: [{CD31F135-AE8E-4740-BA25-63D9EA6F82AE}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpzwiz01.exe FirewallRules: [{F664BD15-582A-428C-9521-0C69AD4818C5}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpoews01.exe FirewallRules: [{7BABA381-6662-4C6E-BB4A-FA5E0FF30C41}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqnrs08.exe FirewallRules: [{BC3E709E-046D-430A-ABC1-A0D5A7024DAB}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpiscnapp.exe FirewallRules: [{EC253563-B265-4BB1-9E16-AB455CA44D1C}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpofxs08.exe FirewallRules: [{BD3E2919-99AD-411C-8502-FE7375834305}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqfxt08.exe FirewallRules: [{9B337AD0-96C4-4C59-BD76-61611A7E3384}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgplgtupl.exe FirewallRules: [{32CCCBD6-08B6-4474-885D-F56FA3AFF5A3}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe FirewallRules: [{0CBD5A43-E80D-43E1-836F-A46104D64626}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgm.exe FirewallRules: [{8318B55F-5D2B-427A-B7C1-19D3463FB5E2}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgh.exe FirewallRules: [{46E4FDD7-BDB8-4171-A9D3-FBDCD66E055B}] => (Allow) C:\Program Files (x86)\Nero\Nero Blu-ray Player\Blu-rayPlayer.exe FirewallRules: [{A957AB4A-C05E-4E01-AA7A-011E9EBE5953}] => (Allow) C:\Program Files (x86)\Nero\Nero Blu-ray Player\Blu-rayPlayer.exe FirewallRules: [{97AD226D-C0A8-45ED-A493-F52923B9CA3E}] => (Allow) C:\Program Files (x86)\Nero\Nero 2015\Nero Burning ROM\StartNBR.exe FirewallRules: [{2C026D82-2D52-44D2-9BE2-3F38C77380E5}] => (Allow) C:\Program Files (x86)\Nero\KM\NMDllHost.exe FirewallRules: [{D163908F-3109-4EBA-8B17-CAA8C10C727C}] => (Allow) C:\Program Files (x86)\Nero\Nero 2015\Nero Burning ROM\nero.exe FirewallRules: [{EF3087CD-CAEF-4D46-B252-241184C748DA}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{F735B2E9-C7AE-4BFA-9C5E-3FEA8794C277}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{0639CAD1-9ED3-4403-81E0-6F8EF02F2EA1}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{C8E01039-67B9-4D54-B665-E87023ECC30F}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{E0236BAC-4CEA-4BD6-83B1-1EA9E1D1D2B4}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{297240DF-B028-4C10-AEA2-B5D838BD23A6}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{7B0295B5-7C46-47B5-AD69-F2C359D183C5}] => (Allow) C:\Program Files (x86)\Popcorn Time\Updater.exe FirewallRules: [{74BE2620-C728-46B1-908A-0CC72CF60191}] => (Allow) C:\Program Files (x86)\Popcorn Time\Updater.exe FirewallRules: [{97D3913F-005C-48A6-A2EE-B7703C5CDFED}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dust An Elysian Tail\DustAET.exe FirewallRules: [{3A83BC54-B801-4A22-A105-17833576AD50}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dust An Elysian Tail\DustAET.exe FirewallRules: [{C0C1B375-9F3C-4E4A-A6A8-7B38FA97B649}] => (Allow) C:\Program Files\iTunes\iTunes.exe FirewallRules: [{C3C85679-8928-4006-AB71-8B1BB8FB6B99}] => (Allow) C:\Program Files (x86)\Popcorn Time\Updater.exe FirewallRules: [{31B57991-0AD5-4741-856D-816EC74B22D3}] => (Allow) C:\Program Files (x86)\Popcorn Time\Updater.exe FirewallRules: [{67F64BDF-EBEF-4408-B0B9-0112A2FF5C2D}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{37D8BFC7-E206-4D58-8423-56B8F782311C}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{97BD46F0-244A-4C14-8E12-AFDE1F17F547}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Stardew Valley\Stardew Valley.exe FirewallRules: [{DC59AA02-A33D-467F-9AA6-9FE22839A3B0}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Stardew Valley\Stardew Valley.exe FirewallRules: [{3D7B5FAE-CD07-47A2-B741-0BF665692ACB}] => (Allow) C:\Program Files\SoftEther VPN Client\vpnclient_x64.exe FirewallRules: [{640E1086-512F-4BE9-BACA-591D69005986}] => (Allow) C:\Program Files\SoftEther VPN Client\vpncmgr.exe FirewallRules: [{9D2E3E1B-50EE-48BE-A902-D9DD7D5D2BC1}] => (Allow) C:\Program Files\SoftEther VPN Client\vpncmd.exe FirewallRules: [{3465EE69-FBA9-45C6-A436-51999C56BEC6}] => (Allow) C:\Program Files\SoftEther VPN Client\vpncmgr_x64.exe FirewallRules: [{B8058E13-BE21-46FB-B163-3F559E45015B}] => (Allow) C:\Program Files\SoftEther VPN Client\vpncmd_x64.exe FirewallRules: [{89C7C72C-1124-4393-9643-C4D0DAFF501A}] => (Allow) C:\Program Files\SoftEther VPN Client\vpnclient.exe FirewallRules: [{D8585C2D-FADB-4E5A-99F0-4B5CC8D5D583}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{0D6CC5A0-9CD6-4B22-8EA3-8F60BC16B313}] => (Allow) C:\Program Files (x86)\The Legend of Heroes Trails in the Sky the 3rd\ed6_win3.exe FirewallRules: [{CED8F7F4-96FD-4E5F-907B-7AC64CF1CEE7}] => (Allow) C:\Program Files (x86)\The Legend of Heroes Trails in the Sky the 3rd\ed6_win3.exe FirewallRules: [{B0262BBE-7EFA-43FC-BEC7-79F58345AC25}] => (Allow) C:\Program Files (x86)\The Legend of Heroes Trails in the Sky the 3rd\ed6_win3.exe FirewallRules: [{24985EE3-02E2-41D1-BCF7-74D3530A83AF}] => (Allow) C:\Program Files (x86)\The Legend of Heroes Trails in the Sky the 3rd\ed6_win3.exe FirewallRules: [{C3963DF4-D29C-46E4-9136-65527649AF26}] => (Allow) C:\Program Files (x86)\The Legend of Heroes Trails in the Sky the 3rd\Config3.exe FirewallRules: [{EE5A66CE-5303-4702-B87F-87E5B6DC3422}] => (Allow) C:\Program Files (x86)\The Legend of Heroes Trails in the Sky the 3rd\Config3.exe FirewallRules: [{D09A5A34-4A43-4704-824F-A574A24E0C45}] => (Allow) C:\Program Files (x86)\The Legend of Heroes Trails in the Sky the 3rd\Config3.exe FirewallRules: [{3407675B-E112-41B4-AC56-3884B559E41B}] => (Allow) C:\Program Files (x86)\The Legend of Heroes Trails in the Sky the 3rd\Config3.exe FirewallRules: [{4E25A3DB-0CCA-4108-8D06-0AE1E24A9E9A}] => (Allow) C:\Program Files (x86)\The Legend of Heroes Trails in the Sky the 3rd\unins000.exe FirewallRules: [{5B180B4A-2B32-4391-9849-1E6A78F5D83B}] => (Allow) C:\Program Files (x86)\The Legend of Heroes Trails in the Sky the 3rd\unins000.exe FirewallRules: [{34D933FD-18CE-466C-A8C9-0B3B874B5F54}] => (Allow) C:\Program Files (x86)\The Legend of Heroes Trails in the Sky the 3rd\unins000.exe FirewallRules: [{36C12734-3BD6-410F-AFF5-94A97078242E}] => (Allow) C:\Program Files (x86)\The Legend of Heroes Trails in the Sky the 3rd\unins000.exe FirewallRules: [{9EA99B44-7805-4686-9E9F-483CD1045E09}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\TreeOfSavior\release\patch\tos.exe FirewallRules: [{B7172161-1ECD-495C-9A72-44C8CFDFEEC3}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\TreeOfSavior\release\patch\tos.exe FirewallRules: [{7700548D-A81E-474E-BE2D-5D9B3DBA86BD}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{FA1FE474-60D5-4B28-B678-BE2D3E670953}] => (Allow) C:\Program Files (x86)\Bangtony\Application\chrome.exe FirewallRules: [{9513E5CD-2AAC-42AC-85B1-2026DD6D77FB}] => (Allow) C:\Program Files (x86)\Firefox\Firefox.exe ==================== Restore Points ========================= 16-05-2017 13:06:23 Windows Update 19-05-2017 16:40:42 Windows Update ==================== Faulty Device Manager Devices ============= Name: Android Gadget VCOM Driver (COM3) Description: Android Gadget VCOM Driver Class Guid: {4d36e978-e325-11ce-bfc1-08002be10318} Manufacturer: MediaTek Inc. Service: usbser Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (05/27/2017 02:08:48 PM) (Source: TOASTER.EXE) (EventID: 0) (User: ) Description: An Unhandled Exception occured. The process cannot access the file 'C:\Users\Rold\AppData\local\softthinks\scheduler.xml' because it is being used by another process. at System.IO.__Error.WinIOError(Int32 errorCode, String maybeFullPath) at System.IO.FileStream.Init(String path, FileMode mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32 bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath, Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode mode, FileAccess access, FileShare share, Int32 bufferSize) at System.Xml.XmlDownloadManager.GetStream(Uri uri, ICredentials credentials) at System.Xml.XmlUrlResolver.GetEntity(Uri absoluteUri, String role, Type ofObjectToReturn) at System.Xml.XmlTextReaderImpl.OpenUrlDelegate(Object xmlResolver) at System.Threading.CompressedStack.runTryCode(Object userData) at System.Runtime.CompilerServices.RuntimeHelpers.ExecuteCodeWithGuaranteedCleanup(TryCode code, CleanupCode backoutCode, Object userData) at System.Threading.CompressedStack.Run(CompressedStack compressedStack, ContextCallback callback, Object state) at System.Xml.XmlTextReaderImpl.OpenUrl() at System.Xml.XmlTextReaderImpl.Read() at System.Xml.XmlLoader.Load(XmlDocument doc, XmlReader reader, Boolean preserveWhitespace) at System.Xml.XmlDocument.Load(XmlReader reader) at System.Xml.XmlDocument.Load(String filename) at Toaster.SchedulerReader.read() at Toaster.Notifications.FullSystemBackup.FsbHelper.IsFsbScheduledNow() at Toaster.Notifications.FullSystemBackup.FsbHelper.CheckReminder() at Toaster.Helper.CheckReminders(ObservableCollection`1 notificationHelpers) at Toaster.MainWindowViewModel.NotificationsTimerTick(Object sender, EventArgs e) at System.Windows.Threading.DispatcherTimer.FireTick(Object unused) at System.Windows.Threading.ExceptionWrapper.InternalRealCall(Delegate callback, Object args, Boolean isSingleParameter) at System.Windows.Threading.ExceptionWrapper.TryCatchWhen(Object source, Delegate callback, Object args, Boolean isSingleParameter, Delegate catchHandler) Error: (05/27/2017 02:02:12 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: svchost.exe, version: 10.0.14393.0, time stamp: 0x57899b1c Faulting module name: LicenseManager.dll, version: 10.0.14393.953, time stamp: 0x58ba5dd7 Exception code: 0xc0000005 Fault offset: 0x0000000000023b6b Faulting process id: 0x534 Faulting application start time: 0x01d2d71b6e149c01 Faulting application path: C:\WINDOWS\system32\svchost.exe Faulting module path: c:\windows\system32\LicenseManager.dll Report Id: b9f7ac4e-268e-43a3-9431-42668e17e8cb Faulting package full name: Faulting package-relative application ID: Error: (05/27/2017 02:02:04 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Rold-PC) Description: Activation of app Microsoft.MicrosoftStickyNotes_8wekyb3d8bbwe!App failed with error: -2144927142 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (05/27/2017 02:02:03 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2486) (User: Rold-PC) Description: App Microsoft.MicrosoftStickyNotes_1.8.0.0_x64__8wekyb3d8bbwe+App did not launch within its allotted time. Error: (05/27/2017 03:34:08 AM) (Source: SideBySide) (EventID: 78) (User: ) Description: Activation context generation failed for "c:\program files (x86)\adobe\adobe creative cloud\utils\Creative Cloud Uninstaller.exe".Error in manifest or policy file "" on line . A component version required by the application conflicts with another component version already active. Conflicting components are:. Component 1: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171.manifest. Component 2: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b.manifest. Error: (05/27/2017 03:31:52 AM) (Source: SideBySide) (EventID: 63) (User: ) Description: Activation context generation failed for "c:\program files\r\r-2.15.2\tcl\bin64\tk85.dll".Error in manifest or policy file "c:\program files\r\r-2.15.2\tcl\bin64\tk85.dll" on line 9. The value "x64" of attribute "processorArchitecture" in element "assemblyIdentity" is invalid. Error: (05/27/2017 03:31:36 AM) (Source: SideBySide) (EventID: 63) (User: ) Description: Activation context generation failed for "c:\program files\r\r-2.13.2\tcl\bin64\tk85.dll".Error in manifest or policy file "c:\program files\r\r-2.13.2\tcl\bin64\tk85.dll" on line 9. The value "x64" of attribute "processorArchitecture" in element "assemblyIdentity" is invalid. Error: (05/26/2017 08:37:26 AM) (Source: SideBySide) (EventID: 78) (User: ) Description: Activation context generation failed for "c:\program files (x86)\adobe\adobe creative cloud\utils\Creative Cloud Uninstaller.exe".Error in manifest or policy file "" on line . A component version required by the application conflicts with another component version already active. Conflicting components are:. Component 1: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171.manifest. Component 2: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b.manifest. Error: (05/26/2017 08:34:26 AM) (Source: SideBySide) (EventID: 63) (User: ) Description: Activation context generation failed for "c:\program files\r\r-2.15.2\tcl\bin64\tk85.dll".Error in manifest or policy file "c:\program files\r\r-2.15.2\tcl\bin64\tk85.dll" on line 9. The value "x64" of attribute "processorArchitecture" in element "assemblyIdentity" is invalid. Error: (05/26/2017 08:34:05 AM) (Source: SideBySide) (EventID: 63) (User: ) Description: Activation context generation failed for "c:\program files\r\r-2.13.2\tcl\bin64\tk85.dll".Error in manifest or policy file "c:\program files\r\r-2.13.2\tcl\bin64\tk85.dll" on line 9. The value "x64" of attribute "processorArchitecture" in element "assemblyIdentity" is invalid. System errors: ============= Error: (05/27/2017 02:18:27 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The snare service terminated unexpectedly. It has done this 1 time(s). Error: (05/27/2017 02:04:21 PM) (Source: Service Control Manager) (EventID: 7032) (User: ) Description: The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Network Store Interface Service service, but this action failed with the following error: An instance of the service is already running. Error: (05/27/2017 02:03:59 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: The Connected Devices Platform Service service terminated with the following error: Unspecified error Error: (05/27/2017 02:03:21 PM) (Source: Service Control Manager) (EventID: 7032) (User: ) Description: The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Font Cache Service service, but this action failed with the following error: An instance of the service is already running. Error: (05/27/2017 02:03:08 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: The Microsoft IdentityCRL Service service terminated with the following error: The specified module could not be found. Error: (05/27/2017 02:02:22 PM) (Source: Service Control Manager) (EventID: 7032) (User: ) Description: The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the COM+ Event System service, but this action failed with the following error: An instance of the service is already running. Error: (05/27/2017 02:02:21 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The WinHTTP Web Proxy Auto-Discovery Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. Error: (05/27/2017 02:02:21 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The Diagnostic Service Host service terminated unexpectedly. It has done this 1 time(s). Error: (05/27/2017 02:02:21 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The Network Store Interface Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service. Error: (05/27/2017 02:02:21 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The Network List Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 100 milliseconds: Restart the service. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i7-2630QM CPU @ 2.00GHz Percentage of memory in use: 50% Total physical RAM: 8139.86 MB Available physical RAM: 4060.34 MB Total Virtual: 8139.86 MB Available Virtual: 4157.14 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:570.95 GB) (Free:34.99 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 698.6 GB) (Disk ID: 871E0ED4) Partition 1: (Not Active) - (Size=39 MB) - (Type=DE) Partition 2: (Active) - (Size=6.9 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=571 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=107.4 GB) - (Type=05) ==================== End of Addition.txt ============================