Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15-07-2017 Ran by [removed] (16-07-2017 13:51:43) Running from C:\Users\[removed]\Desktop Windows 10 Pro Version 1703 (X64) (2017-06-14 23:53:36) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Admin (S-1-5-21-3349261695-2154521845-2584642868-1001 - Administrator - Enabled) => C:\Users\Uporabnik Administrator (S-1-5-21-3349261695-2154521845-2584642868-500 - Administrator - Disabled) => C:\Users\Administrator DefaultAccount (S-1-5-21-3349261695-2154521845-2584642868-503 - Limited - Disabled) Guest (S-1-5-21-3349261695-2154521845-2584642868-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-3349261695-2154521845-2584642868-1003 - Limited - Enabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: Norton Internet Security (Disabled - Out of date) {30744133-1E94-7B35-F4A3-82A5AEF1CBAA} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Norton Internet Security (Disabled - Out of date) {8B15A0D7-38AE-74BB-CE13-B9D7D5768117} FW: Norton Internet Security (Disabled) {084FC016-54FB-7A6D-DFFC-2B9050228CD1} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 64 Bit HP CIO Components Installer (HKLM\...\{FF21C3E6-97FD-474F-9518-8DCBE94C2854}) (Version: 7.2.8 - Hewlett-Packard) Hidden ACS Unified PC/SC Driver 4.0.0.7 (HKLM\...\{ED615C09-BB80-4A1A-ACD2-09B7B4577827}) (Version: 4.0.7.1 - Advanced Card Systems Ltd.) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 21.0.0.198 - Adobe Systems Incorporated) Adobe Flash Player 26 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 26.0.0.131 - Adobe Systems Incorporated) Adobe Media Player (HKLM-x32\...\com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.8 - Adobe Systems Incorporated) Adobe Photoshop CC 2015 (HKLM-x32\...\{2D99B50E-431D-4AA8-85C1-172A6F8BCF01}) (Version: 16.0 - Adobe Systems Incorporated) Adobe Shockwave Player 12.2 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.2.4.194 - Adobe Systems, Inc.) Adobe Update Management Tool (HKLM-x32\...\{534A7A1A-7102-4AF6-23EA-7CD279C7B625}_is1) (Version: 8.0 - PainteR) ASP32 slovarji 29in1 (HKLM-x32\...\ASP32 slovarji 29in1_is1) (Version: - Bushy) ASUS GPU Tweak (HKLM-x32\...\{532F6E8A-AF97-41C3-915F-39F718EC07D1}) (Version: 2.5.3.7 - ASUSTek COMPUTER INC.) Hidden ASUS GPU Tweak (HKLM-x32\...\InstallShield_{532F6E8A-AF97-41C3-915F-39F718EC07D1}) (Version: 2.5.3.7 - ASUSTek COMPUTER INC.) ASUS Product Register Program (HKLM-x32\...\{C87D79F6-F813-4812-B7A9-CCCAAB8B1188}) (Version: 1.0.025 - ASUSTek Computer Inc.) AV Voice Changer Software DIAMOND 7.0 (HKLM-x32\...\AV Voice Changer Software DIAMOND 7.0) (Version: 7.0.29 - Avnex Ltd.) BufferChm (HKLM-x32\...\{FA0FF682-CC70-4C57-93CD-E276F3E7537E}) (Version: 140.0.298.000 - Hewlett-Packard) Hidden Cardpeek version 0.8.4 (HKLM-x32\...\{C65CF493-F496-46DA-923C-98A007914CD9}_is1) (Version: 0.8.4 - Alain Pannetrat <[removed]>) CCleaner (HKLM\...\CCleaner) (Version: 5.25 - Piriform) ChequeSystem v3.3.1 (HKLM-x32\...\ChequeSystem_is1) (Version: - Evinco Solutions Limited) Copy (HKLM-x32\...\{9BE466FF-70B7-4DA8-807C-DB4C3610FDAA}) (Version: 140.0.298.000 - Hewlett-Packard) Hidden DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 10.5.0.0222 - Disc Soft Ltd) Dependency Package Update (HKLM\...\{0788641D-D31A-478D-BB34-C41564AE9F93}) (Version: 1.6.38.00 - Lenovo Inc.) Hidden Dependency Package Update (HKLM\...\{5252431C-288E-409D-ADCF-24407E0E6F70}) (Version: 1.6.36.00 - Lenovo Inc.) Hidden Dependency Package Update (HKLM\...\{FFED38DF-94DC-4FF9-96C1-A6990EDA6B03}) (Version: 1.6.29.00 - Lenovo Inc.) Hidden Dependency Package Update (HKLM-x32\...\{1D2682EA-75DD-44B6-BF2D-CD3C49EAD012}) (Version: 1.6.38.01 - Lenovo Group Limited) Hidden Dependency Package Update (HKLM-x32\...\{3117B53D-A409-4D99-A0DE-11A1A40696FA}) (Version: 1.6.32.00 - Lenovo Group Limited) Hidden Dependency Package Update (HKLM-x32\...\{4430150F-61B3-4142-BE04-EAC68C8DDA18}) (Version: 1.6.32.00 - Lenovo Group Limited) Hidden Dependency Package Update (HKLM-x32\...\{4AF6C9BC-D8DB-4286-94D9-474CE54ADAA2}) (Version: 1.6.38.00 - Lenovo Group Limited) Hidden Dependency Package Update (HKLM-x32\...\{503B47A9-E34A-4841-ADD7-417191D5DB5E}) (Version: 1.6.32.00 - Lenovo Group Limited) Hidden Dependency Package Update (HKLM-x32\...\{546FF45D-2467-4950-AAFB-0A06ACBB6B2C}) (Version: 1.6.32.00 - Lenovo Group Limited) Hidden Dependency Package Update (HKLM-x32\...\{5B2190E9-199D-450A-94B3-4D6826C770C2}) (Version: 1.6.32.00 - Lenovo Group Limited) Hidden Dependency Package Update (HKLM-x32\...\{5BEFE1E1-F597-4B79-913B-15FFDB25B744}) (Version: 1.6.32.00 - Lenovo Group Limited) Hidden Dependency Package Update (HKLM-x32\...\{63DE35C9-B080-4D03-B110-99E14FD35BCE}) (Version: 1.6.32.00 - Lenovo Group Limited) Hidden Dependency Package Update (HKLM-x32\...\{65316098-0220-4D5C-B37A-6136083A0897}) (Version: 1.6.32.00 - Lenovo Group Limited) Hidden Dependency Package Update (HKLM-x32\...\{E966DBE4-5075-465E-BA81-BC9A3A3204B3}) (Version: 1.6.32.00 - Lenovo Group Limited) Hidden Destinations (HKLM-x32\...\{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}) (Version: 140.0.253.000 - Hewlett-Packard) Hidden DeviceDiscovery (HKLM-x32\...\{1458BB78-1DC5-4BC0-B9A3-2B644F5A8105}) (Version: 140.0.298.000 - Hewlett-Packard) Hidden DJ_AIO_06_F2400_SW_Min (HKLM-x32\...\{D1E8CEBA-EC2B-4B37-97B8-C87AF6302601}) (Version: 140.0.851.000 - Hewlett-Packard) Hidden Electrum (HKU\S-1-5-21-3349261695-2154521845-2584642868-1001\...\Electrum) (Version: 2.8.2 - Electrum Technologies GmbH) EVEREST Home Edition v2.20 (HKLM-x32\...\EVEREST Home Edition_is1) (Version: 2.20 - Lavalys Inc) F2400 (HKLM-x32\...\{60F0F139-0C04-4D9C-9C6C-DEF35766BAB3}) (Version: 140.0.851.000 - Hewlett-Packard) Hidden Female Voices (HKLM-x32\...\{657015B4-C933-455B-938E-D4CFCE91148D}) (Version: 4.4.21 - Screaming Bee Inc.) Hidden Female Voices for MorphVOX (HKLM-x32\...\{6502eaff-6343-46f3-9c22-6ccca6ee1f86}) (Version: 4.4.21 - Screaming Bee Inc.) Flash Cookie Cleaner (HKLM-x32\...\{E4E1D7C7-6561-4462-96B5-E6439488ED41}) (Version: 2.0 - ConsumerSoft) ForTrade MetaTrader 4 (HKLM-x32\...\ForTrade MetaTrader 4) (Version: 4.00 - MetaQuotes Software Corp.) Foxit PhantomPDF (HKLM-x32\...\{FD617DA4-2048-11E7-B4E6-000C2992F709}) (Version: 8.3.0.14878 - Foxit Software Inc.) GoTo Opener (HKLM-x32\...\{C0A5FA19-686C-490A-91CF-513FE6832187}) (Version: 1.0.459 - LogMeIn, Inc.) GPBaseService2 (HKLM-x32\...\{BB3447F6-9553-4AA9-960E-0DB5310C5779}) (Version: 140.0.297.000 - Hewlett-Packard) Hidden Gpg4win (2.3.0) (HKLM-x32\...\GPG4Win) (Version: 2.3.0 - The Gpg4win Project) GPUTweakStreaming (HKLM-x32\...\{D2A41AA7-4313-43D5-AA39-7E3FBBE0556D}) (Version: 1.0.3.5 - ASUS) Hidden GPUTweakStreaming (HKLM-x32\...\InstallShield_{D2A41AA7-4313-43D5-AA39-7E3FBBE0556D}) (Version: 1.0.3.5 - ASUS) HP Customer Participation Program 14.0 (HKLM\...\HPExtendedCapabilities) (Version: 14.0 - HP) HP Deskjet F2400 All-in-One Driver Software 14.0 Rel. 6 (HKLM\...\{BCDD692B-172D-440A-9A1B-501C71D72CC8}) (Version: 14.0 - HP) HP Imaging Device Functions 14.0 (HKLM\...\HP Imaging Device Functions) (Version: 14.0 - HP) HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.2024 - HP Photo Creations Powered by RocketLife) HP Solution Center 14.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 14.0 - HP) HP Support Solutions Framework (HKLM-x32\...\{44157EB3-D8D0-4BB1-B0F5-AD2C38814ED1}) (Version: 11.51.0027 - Hewlett-Packard Company) HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard) HPPhotoGadget (HKLM-x32\...\{CAE4213F-F797-439D-BD9E-79B71D115BE3}) (Version: 140.0.524.000 - Hewlett-Packard) Hidden HPProductAssistant (HKLM-x32\...\{150B6201-E9E6-4DFB-960E-CCBD53FBDDED}) (Version: 140.0.298.000 - Hewlett-Packard) Hidden HPSSupply (HKLM-x32\...\{AC35A885-0F8F-4857-B7DA-6E8DFB43E6B3}) (Version: 140.0.297.000 - Hewlett-Packard) Hidden ICQ (version 10.0.12180) (HKU\S-1-5-21-3349261695-2154521845-2584642868-1001\...\icq.desktop) (Version: 10.0.12180 - ICQ) Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1010 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.0.0.1310 - Intel Corporation) Intel(R) Network Connections Drivers (HKLM\...\PROSet) (Version: 19.1 - Intel) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.18.10.3220 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.5.0.1066 - Intel Corporation) Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 3.0.0.66956 - Intel Corporation) Intel(R) Update Manager (HKLM-x32\...\{608E1B9B-A2E8-4A1F-8BAB-874EB0DD25E3}) (Version: 1.0.0.36888 - Intel Corporation) Hidden IQ Option (HKLM-x32\...\IQ Option) (Version: 1.0 - IQOption) Java 8 Update 121 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180121F0}) (Version: 8.0.1210.13 - Oracle Corporation) LBAI (HKLM-x32\...\{C5C91B7B-38A6-40B7-84D6-E44885E44B13}_is1) (Version: 1.0.0.8 - Lenovo Group Limited) Lenovo Dependency Package (HKLM\...\Lenovo Dependency Package_is1) (Version: 1.6.38.00 - Lenovo Group Limited) Lenovo Solution Center (HKLM\...\{C1FC707B-AE6B-4DC4-89A5-6628A01F8103}) (Version: 3.3.003.00 - Lenovo) Lenovo Solutions for Small Business (HKLM-x32\...\{6A6D86CD-B004-46b7-8951-7BB75A776F8C}) (Version: 2.0.32.7350 - Intel(R) Corporation) Lenovo Solutions for Small Business Customizations (HKLM-x32\...\{AFD7B869-3B70-40C7-8983-769256BA3BD2}) (Version: 2.0.0004.00 - Lenovo Group Limited) Lenovo System Update (HKLM-x32\...\{25C64847-B900-48AD-A164-1B4F9B774650}) (Version: 5.07.0037 - Lenovo) Lenovo User Guide (HKLM-x32\...\{13F59938-C595-479C-B479-F171AB9AF64F}) (Version: 1.0.0012.00 - Lenovo Group Limited) Lenovo Warranty Information (HKLM-x32\...\{FD4EC278-C1B1-4496-99ED-C0BE1B0AA521}) (Version: 1.0.0007.00 - Lenovo) Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes) MarketResearch (HKLM-x32\...\{D360FA88-17C8-4F14-B67F-13AAF9607B12}) (Version: 140.0.212.000 - Hewlett-Packard) Hidden McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.11.584.4 - McAfee, Inc.) Metric Collection SDK (HKLM-x32\...\{DDAA788F-52E6-44EA-ADB8-92837B11BF26}) (Version: 1.1.0005.00 - Lenovo Group Limited) Hidden Microsoft Access database engine 2010 (English) (HKLM-x32\...\{90140000-00D1-0409-0000-0000000FF1CE}) (Version: 14.0.6029.1000 - Microsoft Corporation) Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation) Microsoft Office Professional Plus 2013 - sl-si (HKLM\...\ProPlusRetail - sl-si) (Version: 15.0.4867.1003 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-3349261695-2154521845-2584642868-1001\...\OneDriveSetup.exe) (Version: 17.3.6917.0607 - Microsoft Corporation) Microsoft redistributable runtime DLLs VS2005 SP1(x86) (HKLM-x32\...\{CEC7A786-A9C8-4EF7-BB59-6518E3B3C878}) (Version: 8.0.50727.4053 - SAP) Microsoft redistributable runtime DLLs VS2008 SP1(x86) (HKLM-x32\...\{A47A9101-6EB5-4314-BDA1-297880FBB908}) (Version: 9.0 - SAP AG) Microsoft redistributable runtime DLLs VS2010 SP1 (x86) (HKLM-x32\...\{2385C070-EC26-4AB9-8718-E605C977C0ED}) (Version: 10.0.40219.1 - SAP) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{4FFA2088-8317-3B14-93CD-4C699DB37843}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) MorphVOX Pro (HKLM-x32\...\{75B956F9-D72D-4929-B695-120D70E8AEE1}) (Version: 4.4.7 - Screaming Bee) MSR606 (HKLM-x32\...\MSR606v2.01) (Version: v2.01 - ) Norton Internet Security (HKLM-x32\...\NIS) (Version: 22.9.4.8 - Symantec Corporation) NVIDIA 3D Vision gonilnik za krmilnik 352.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 352.65 - NVIDIA Corporation) NVIDIA GeForce Experience 2.1.4 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.1.4 - NVIDIA Corporation) NVIDIA Gonilnika 3D Vision 376.53 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 376.53 - NVIDIA Corporation) NVIDIA Grafični gonilnik 376.53 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 376.53 - NVIDIA Corporation) NVIDIA HD avdio gonilnika 1.3.34.17 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.17 - NVIDIA Corporation) NVIDIA Miracast navidezni avdio 355.82 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Miracast.VirtualAudio) (Version: 355.82 - NVIDIA Corporation) NVIDIA Sistemske opreme PhysX 9.15.0428 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation) Office 15 Click-to-Run Extensibility Component (HKLM-x32\...\{90150000-008C-0000-0000-0000000FF1CE}) (Version: 15.0.4867.1003 - Microsoft Corporation) Hidden Office 15 Click-to-Run Licensing Component (HKLM\...\{90150000-008F-0000-1000-0000000FF1CE}) (Version: 15.0.4867.1003 - Microsoft Corporation) Hidden Personality Voices (HKLM-x32\...\{DCF84BE6-76B2-452F-A4DF-DC01DA0D25E4}) (Version: 4.4.21 - Screaming Bee Inc.) Hidden Personality Voices for MorphVOX (HKLM-x32\...\{da9b1e64-24d5-4c4c-b687-270ea6065b14}) (Version: 4.4.21 - Screaming Bee Inc.) Pidgin (HKLM-x32\...\Pidgin) (Version: 2.10.6 - ) pidgin-otr 4.0.0-1 (HKLM-x32\...\pidgin-otr) (Version: 4.0.0-1 - Cypherpunks CA) PL-2303 USB-to-Serial (HKLM-x32\...\{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}) (Version: 1.8.0 - Prolific Technology INC) Power Manager (HKLM-x32\...\{DAC01CEE-5BAE-42D5-81FC-B687E84E8405}_is1) (Version: 3.40.0001 - Lenovo Group Limited) PrintBoss (HKLM-x32\...\PrintBoss) (Version: - ) Python 2.6.1 (HKLM-x32\...\{9cc89170-000b-457d-91f1-53691f85b223}) (Version: 2.6.1150 - Python Software Foundation) QuickBooks (HKLM-x32\...\{2B0E1E07-2F3D-4E7D-AD0A-1C74A8881B9B}) (Version: 26.0.4006.2607 - Intuit Inc.) Hidden QuickBooks Pro 2016 (HKLM-x32\...\{4338BDE2-0035-41BC-87BE-EE0AD5D48042}) (Version: 26.0.4006.2607 - Intuit Inc.) QuickBooks Runtime Redistributable (HKLM\...\{F2A4F809-2DE6-4D27-888B-4D2BB8DAF20E}) (Version: 1.00.0000 - Intuit Inc.) QuickTransfer (HKLM-x32\...\{E517094C-06B6-419F-8FFD-EF4F57972130}) (Version: 140.0.98.000 - Hewlett-Packard) Hidden Realtek Card Reader (HKLM-x32\...\{F0A8BF4A-972F-41E0-9800-1EFE3BF28266}) (Version: 6.2.9200.30158 - Realtek Semiconductor Corp.) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6844 - Realtek Semiconductor Corp.) Remo Recover 4.0 (HKLM\...\{A573D759-F894-448D-A420-3A9C31879F88}_is1) (Version: 4.0.0.34 - Remo Software) SAP GUI for Windows 7.30 (HKLM-x32\...\SAPGUI710) (Version: 7.30 Compilation 1 - SAP) Scan (HKLM-x32\...\{06A1D88C-E102-4527-AF70-29FFD7AF215A}) (Version: 140.0.253.000 - Hewlett-Packard) Hidden SHIELD Streaming (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.NvStreamSrv) (Version: 3.1.2000 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShieldWirelessController) (Version: 16.13.65 - NVIDIA Corporation) Hidden Shop for HP Supplies (HKLM\...\Shop for HP Supplies) (Version: 14.0 - HP) Skype™ 7.37 (HKLM-x32\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.37.103 - Skype Technologies S.A.) SolutionCenter (HKLM-x32\...\{BC5DD87B-0143-4D14-AAE6-97109614DC6B}) (Version: 140.0.299.000 - Hewlett-Packard) Hidden StarMoney (HKLM-x32\...\{1A357B9B-763D-4346-A01C-F30767E27266}) (Version: 4.0.6.107 - StarFinanz) Hidden StarMoney (HKLM-x32\...\{6EAB5DC3-BBFE-4B34-AF33-E0C1D1626346}) (Version: 4.0.6.107 - StarFinanz) Hidden Status (HKLM-x32\...\{5B025634-7D5B-4B8D-BE2A-7943C1CF2D5D}) (Version: 140.0.342.000 - Hewlett-Packard) Hidden Sure Delete 5.1.1 (HKLM-x32\...\Sure Delete_is1) (Version: - Wizard Industries LLC) swMSM (HKLM-x32\...\{612C34C7-5E90-47D8-9B5C-0F717DD82726}) (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden Toolbox (HKLM-x32\...\{292F0F52-B62D-4E71-921B-89A682402201}) (Version: 140.0.596.000 - Hewlett-Packard) Hidden Trading Central Indicator for MetaTrader (HKLM-x32\...\{AA7F1135-3AAA-4F08-8144-99B8C6384543}) (Version: 1.4.2 - Trading Central) TrayApp (HKLM-x32\...\{CD31E63D-47FD-491C-8117-CF201D0AFAB5}) (Version: 140.0.297.000 - Hewlett-Packard) Hidden Unlocker 1.9.2 (HKLM\...\Unlocker) (Version: 1.9.2 - Cedrick Collomb) VC80CRTRedist - 8.0.50727.6195 (HKLM-x32\...\{933B4015-4618-4716-A828-5289FC03165F}) (Version: 1.2.0 - DivX, Inc) Hidden View Management Utility (HKLM\...\View Management Utility_is1) (Version: 3.0.1.20121226 - Lenovo Inc.) Visual Studio Tools for the Office system 3.0 Runtime (HKLM-x32\...\Visual Studio Tools for the Office system 3.0 Runtime) (Version: - Microsoft Corporation) Visual Studio Tools for the Office system 3.0 Runtime Service Pack 1 (KB949258) (HKLM-x32\...\{8FB53850-246A-3507-8ADE-0060093FFEA6}.KB949258) (Version: 1 - Microsoft Corporation) VLC media player (HKLM-x32\...\VLC media player) (Version: 2.1.5 - VideoLAN) WebReg (HKLM-x32\...\{8EE94FD8-5F52-4463-A340-185D16328158}) (Version: 140.0.297.017 - Hewlett-Packard) Hidden WhatsApp (HKU\S-1-5-21-3349261695-2154521845-2584642868-1001\...\WhatsApp) (Version: 0.2.1880 - WhatsApp) Windows 10 Update and Privacy Settings (HKLM\...\{293F2009-0145-450B-B4AA-063D43FB368C}) (Version: 1.0.13.0 - Microsoft Corporation) Windows Driver Package - Advanced Card Systems Ltd. Unified PC/SC Driver (05/30/2015 4.0.0.7) (HKLM\...\1955D686C48CCCD0F157D8D8170D36D03D484A51) (Version: 05/30/2015 4.0.0.7 - Advanced Card Systems Ltd.) WinRAR 5.11 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 5.11.0 - win.rar GmbH) X-Lite 3.0 (HKLM-x32\...\X-Lite 1.5_is1) (Version: - CounterPath Solutions Inc.) Xvid MPEG-4 Video Codec (HKLM-x32\...\xvid) (Version: - Xvid Development Team) Yahoo! Messenger (HKLM-x32\...\Yahoo! Messenger) (Version: - Yahoo! Inc.) YoutubeAdBlock (HKLM-x32\...\E3605470-291B-44EB-8648-745EE356599A) (Version: 2.0.0.279 - Company Inc.) <==== ATTENTION Zoiper (HKLM-x32\...\Zoiper) (Version: 3.9 - Securax LTD) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ShellIconOverlayIdentifiers: [ OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files (x86)\Norton Internet Security\Engine\22.9.4.8\buShell.dll [2017-05-11] (Symantec Corporation) ShellIconOverlayIdentifiers: [ OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files (x86)\Norton Internet Security\Engine\22.9.4.8\buShell.dll [2017-05-11] (Symantec Corporation) ShellIconOverlayIdentifiers: [ OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files (x86)\Norton Internet Security\Engine\22.9.4.8\buShell.dll [2017-05-11] (Symantec Corporation) ShellIconOverlayIdentifiers: [SugarSyncBackedUp] -> {0C4A258A-3F3B-4FFF-80A7-9B3BEC139472} => -> No File ShellIconOverlayIdentifiers: [SugarSyncPending] -> {62CCD8E3-9C21-41E1-B55E-1E26DFC68511} => -> No File ShellIconOverlayIdentifiers: [SugarSyncRoot] -> {A759AFF6-5851-457D-A540-F4ECED148351} => -> No File ShellIconOverlayIdentifiers: [SugarSyncShared] -> {1574C9EF-7D58-488F-B358-8B78C1538F51} => -> No File ShellIconOverlayIdentifiers-x32: [ OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files (x86)\Norton Internet Security\Engine32\22.9.4.8\buShell.dll [2017-05-11] (Symantec Corporation) ShellIconOverlayIdentifiers-x32: [ OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files (x86)\Norton Internet Security\Engine32\22.9.4.8\buShell.dll [2017-05-11] (Symantec Corporation) ShellIconOverlayIdentifiers-x32: [ OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files (x86)\Norton Internet Security\Engine32\22.9.4.8\buShell.dll [2017-05-11] (Symantec Corporation) ShellIconOverlayIdentifiers-x32: [ SkyDrivePro1 (ErrorConflict)] -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2016-09-06] (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ SkyDrivePro2 (SyncInProgress)] -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2016-09-06] (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ SkyDrivePro3 (InSync)] -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2016-09-06] (Microsoft Corporation) ContextMenuHandlers01: [BUContextMenu] -> {F7CAA2A1-67A2-44BB-B20F-202FD8EB1DAB} => C:\Program Files (x86)\Norton Internet Security\Engine\22.9.4.8\buShell.dll [2017-05-11] (Symantec Corporation) ContextMenuHandlers01: [Foxit_ConvertToPDF] -> {C5269811-4A29-4818-A4BB-111F9FC63A5F} => C:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\ConvertToPDFShellExtension_x64.dll [2017-03-31] (Foxit Software Inc.) ContextMenuHandlers01: [SugarSync] -> {305BC11B-5175-492B-B569-866547FCDA40} => -> No File ContextMenuHandlers01: [Symantec.Norton.Antivirus.IEContextMenu] -> {FAD61B3D-699D-49B2-BE16-7F82CB4C59CA} => C:\Program Files (x86)\Norton Internet Security\Engine\22.9.4.8\NavShExt.dll [2017-05-27] (Symantec Corporation) ContextMenuHandlers01: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2014-08-27] (Alexander Roshal) ContextMenuHandlers01: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => -> No File ContextMenuHandlers02: [Symantec.Norton.Antivirus.IEContextMenu] -> {FAD61B3D-699D-49B2-BE16-7F82CB4C59CA} => C:\Program Files (x86)\Norton Internet Security\Engine\22.9.4.8\NavShExt.dll [2017-05-27] (Symantec Corporation) ContextMenuHandlers03: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamext.dll [2016-03-10] (Malwarebytes) ContextMenuHandlers05: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File ContextMenuHandlers05: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2017-05-01] (NVIDIA Corporation) ContextMenuHandlers06: [BUContextMenu] -> {F7CAA2A1-67A2-44BB-B20F-202FD8EB1DAB} => C:\Program Files (x86)\Norton Internet Security\Engine\22.9.4.8\buShell.dll [2017-05-11] (Symantec Corporation) ContextMenuHandlers06: [Foxit_ConvertToPDF] -> {C5269811-4A29-4818-A4BB-111F9FC63A5F} => C:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\ConvertToPDFShellExtension_x64.dll [2017-03-31] (Foxit Software Inc.) ContextMenuHandlers06: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamext.dll [2016-03-10] (Malwarebytes) ContextMenuHandlers06: [SugarSync] -> {305BC11B-5175-492B-B569-866547FCDA40} => -> No File ContextMenuHandlers06: [Symantec.Norton.Antivirus.IEContextMenu] -> {FAD61B3D-699D-49B2-BE16-7F82CB4C59CA} => C:\Program Files (x86)\Norton Internet Security\Engine\22.9.4.8\NavShExt.dll [2017-05-27] (Symantec Corporation) ContextMenuHandlers06: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2014-08-27] (Alexander Roshal) ContextMenuHandlers06: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => -> No File ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {0779B6BD-E784-46E1-A7E0-B4612BB01073} - \Norton Security Scan for Levak -> No File <==== ATTENTION Task: {0831083B-8E41-4F2F-870E-FA3E76BC4302} - \Lenovo\LSC\LSCHardwareScanPostpone -> No File <==== ATTENTION Task: {094CD275-5C71-4753-B57E-5566CA859498} - \Microsoft\Windows\SideShow\AutoWake -> No File <==== ATTENTION Task: {0AD02914-2CC4-4B4C-AB09-F8716EA74C43} - \Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_Display -> No File <==== ATTENTION Task: {0DF8F528-D4A6-4FDF-8B65-61C4FFDF019E} - System32\Tasks\Norton Internet Security\Norton Internet Security Autofix => C:\Program Files (x86)\Norton Internet Security\Engine\22.9.4.8\SymErr.exe [2017-05-11] (Symantec Corporation) Task: {0F533730-4C72-4034-807A-8EDA1FA09F8D} - \Lenovo\Lenovo Solution Center Launcher -> No File <==== ATTENTION Task: {0F6DBBD1-1FA5-490B-A482-1F43FCC689E6} - \Microsoft\Windows\SideShow\SystemDataProviders -> No File <==== ATTENTION Task: {17C1D4B4-C305-40ED-95F0-31039E1ED99D} - System32\Tasks\Microsoft\Windows\Multimedia\Driver => C:\WINDOWS\SysWOW64\Easeware.Driver.exe Task: {19295C7D-C8A1-4B56-B44A-6582A1CC753A} - \ParetoLogic Registration3 -> No File <==== ATTENTION Task: {19A3017D-AEDC-4BC3-A4BD-DA532FAF3E49} - \Microsoft\Windows\PLA\LSC Memory -> No File <==== ATTENTION Task: {1A4230A2-E136-4936-9B22-DDF624BB8332} - \Microsoft\Windows\IME\SQM data sender -> No File <==== ATTENTION Task: {1B9AF3D3-97BD-4E67-933F-3A1BB5D1EC79} - \Microsoft\Windows\UpdateOrchestrator\Policy Install -> No File <==== ATTENTION Task: {1C12F6D5-B6F4-4438-B68B-F46A42570BA9} - \Microsoft\Windows\WindowsUpdate\AUFirmwareInstall -> No File <==== ATTENTION Task: {1DE5E957-3617-41FD-85F6-AF5EC7E47577} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2015-10-29] (Microsoft Corporation) Task: {29ED74FC-2A29-4B43-AAC3-7B3584A8C2F4} - \Microsoft\Windows\WindowsUpdate\AUSessionConnect -> No File <==== ATTENTION Task: {2A767A1A-6DF2-4490-89AF-EE64AFADC9AF} - \Microsoft\Windows\MUI\Lpksetup -> No File <==== ATTENTION Task: {2CA3CC00-5B78-4565-B045-E71AC1107269} - \Microsoft\Windows\WindowsUpdate\AUScheduledInstall -> No File <==== ATTENTION Task: {2F6C8A3F-3EEB-481B-9EF3-4E6D93703C3E} - \Lenovo\LSC\Time72Task -> No File <==== ATTENTION Task: {3E49052A-4BE6-40C6-828E-8A29B03C0528} - \ParetoLogic Update Version3 -> No File <==== ATTENTION Task: {4520E8A9-AF06-4122-859B-E4B655B29B36} - \Microsoft\Windows\AppID\SmartScreenSpecific -> No File <==== ATTENTION Task: {47828933-3978-4CB6-8014-9030BC0ED618} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION Task: {4F2AFA0C-1D66-450F-BA90-8E5C2E0FD59C} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION Task: {505D08C3-3C9C-420B-8EF0-1DA30EDD8885} - \Microsoft\Windows\MUI\Mcbuilder -> No File <==== ATTENTION Task: {51B7FB15-4DCB-400E-9A98-10E802F21FB3} - \Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceScreenOnOff -> No File <==== ATTENTION Task: {5A3FB241-0B11-4EA5-BC66-0D9F1B406040} - \Microsoft\Windows\Customer Experience Improvement Program\BthSQM -> No File <==== ATTENTION Task: {62C47028-7886-43DE-BAA1-7EFC83DBF85C} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION Task: {62CF6675-6B84-4827-B131-F11BFC05E6CD} - System32\Tasks\Microsoft\Windows\Multimedia\Manager => C:\Windows\Manager.exe [2017-07-12] () Task: {63387002-B60F-4EA2-BA38-92BC3889A7AC} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION Task: {6C129B53-A416-4EA8-BFB6-543F1C5760B1} - \Microsoft\Windows\Shell\FamilySafetyUpload -> No File <==== ATTENTION Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - \Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task -> No File <==== ATTENTION Task: {6FE80F2D-6B1B-4FD0-86EF-4B9AD6855D21} - System32\Tasks\Norton Internet Security\Norton Internet Security Error Analyzer => C:\Program Files (x86)\Norton Internet Security\Engine\22.9.4.8\SymErr.exe [2017-05-11] (Symantec Corporation) Task: {72319288-85B2-481C-833C-775FB5EE5E6B} - \Lenovo\LSC\LSCHardwareScan -> No File <==== ATTENTION Task: {75D7510F-DDC7-48E4-9BF7-5AE620EB896B} - \Microsoft\XblGameSave\XblGameSaveTaskLogon -> No File <==== ATTENTION Task: {7764BD06-8580-4CCC-931E-78E47D15AF10} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2015-10-29] (Microsoft Corporation) Task: {7E882950-1225-4D67-A702-DE7168DAE9D9} - \Lenovo\Lenovo Customer Feedback Program 64 -> No File <==== ATTENTION Task: {847F1BAD-23DF-4026-AFFF-C5F9E7DC6BC9} - \Intel(R) Small Business Advantage\Notifier -> No File <==== ATTENTION Task: {865C0EE0-DF6A-4717-8266-343E6B6B9468} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - \Microsoft\Windows\SkyDrive\Routine Maintenance Task -> No File <==== ATTENTION Task: {8B6759EE-1C08-4B8F-955C-774AB5A6544E} - \Microsoft\Windows\SideShow\SessionAgent -> No File <==== ATTENTION Task: {91DF7AF0-8EA6-4E07-84CA-465A2E3AF462} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION Task: {A0EDFF74-0BF1-4DC7-9D44-2C756450EBBA} - System32\Tasks\Remediation\AntimalwareMigrationTask => C:\Program Files\Common Files\AV\Norton Internet Security\Upgrade.exe [2017-05-27] (Symantec Corporation) Task: {A1F64D6A-4069-47DF-BAFC-A44DF929DBA3} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION Task: {A480128A-D30A-4758-9357-B387C6F7A448} - \Microsoft\Windows\ErrorDetails\EnableErrorDetailsUpdate -> No File <==== ATTENTION Task: {AEE87E78-DAA1-424D-9BAE-64FE74D816E7} - \System\SystemCheck -> No File <==== ATTENTION Task: {B0A7ED8D-F4F4-4F07-B68E-E05F6579873C} - \Microsoft\Windows\ErrorDetails\ErrorDetailsUpdate -> No File <==== ATTENTION Task: {B320E058-C6FA-413F-876B-0C9B4428AE66} - \Microsoft\Windows\DeviceDirectoryClient\RegisterDevicePeriodic6 -> No File <==== ATTENTION Task: {BFC818AC-70B2-482F-8A42-1A14A542B20A} - \Lenovo\Dependency Package Auto Update -> No File <==== ATTENTION Task: {C4AE3C3E-C327-4689-B6FD-C11FB31AE88B} - \Microsoft\Windows\NetCfg\BindingWorkItemQueueHandler -> No File <==== ATTENTION Task: {C6B2579B-4962-4D12-883D-BBD420573A6C} - \Microsoft\Windows\DeviceDirectoryClient\RegisterDevicePeriodic1 -> No File <==== ATTENTION Task: {C8AB6BAB-3F8C-4169-B001-9A964BDADB66} - \ParetoLogic Update Version3 Startup Task -> No File <==== ATTENTION Task: {C9ACBFD2-20AA-4A3F-BE1A-A3D5279BB1BB} - \Microsoft\Windows\Plug and Play\Plug and Play Cleanup -> No File <==== ATTENTION Task: {C9DCF59E-6B97-4C0C-8641-B8261089C8CA} - \Microsoft\Windows\MobilePC\HotStart -> No File <==== ATTENTION Task: {CB4B526E-29ED-4FA6-9DE0-8E7CAE577CE9} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION Task: {CE2DE968-E342-40D7-9566-427D45E4A886} - \Microsoft\Windows\PerfTrack\BackgroundConfigSurveyor -> No File <==== ATTENTION Task: {D19A2726-897E-4F7D-9CE4-0773B449CE9E} - \Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceConnectedToNetwork -> No File <==== ATTENTION Task: {D1B81547-C7EC-4CE5-BF4A-C11684F8569D} - \Lenovo\LSC\Lenovo Solution Center Notifications -> No File <==== ATTENTION Task: {D30A18DA-1853-4AEC-8BFC-52EA5B06A4E3} - \Microsoft\Windows\WindowsUpdate\Scheduled Start With Network -> No File <==== ATTENTION Task: {D407E6A8-1483-4F01-94FE-0915C7ADA0FB} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION Task: {D4F84DA4-DAFD-407F-BBDB-7C4B40131AA7} - System32\Tasks\Norton Internet Security\Norton Internet Security Error Processor => C:\Program Files (x86)\Norton Internet Security\Engine\22.9.4.8\SymErr.exe [2017-05-11] (Symantec Corporation) Task: {DB21EF32-6BA9-4118-BBC1-BC4FF48961E5} - \Microsoft\Windows\SideShow\GadgetManager -> No File <==== ATTENTION Task: {DBA09BB9-6440-412A-834A-2BDBB9D685D4} - \Lenovo\Lenovo Customer Feedback Program 64 35 -> No File <==== ATTENTION Task: {DBB6A085-16B7-49FC-85A9-584612C68F2B} - \Lenovo\LSC\RebootCountTask -> No File <==== ATTENTION Task: {DFE80F9F-D11E-486B-BAA6-1AC9BBE4E14E} - \ASUS\ASUS Product Register Service -> No File <==== ATTENTION Task: {E465E548-DD4E-4B53-8578-58617638BE0E} - \Microsoft\Windows\RemovalTools\MRT_HB -> No File <==== ATTENTION Task: {E6208CC9-A451-4509-B375-483CA9781251} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION Task: {E8BBD14B-57E4-4B9C-BA2B-BC64BF4F4C08} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton Internet Security\Engine\22.9.4.8\WSCStub.exe [2017-05-27] (Symantec Corporation) Task: {E9BB7B3D-01B2-4C6F-8B39-91FB35FF1C5B} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION Task: {F24FDA55-6D75-4ACF-AF1F-5EC68CD97277} - \Lenovo\Lenovo Customer Feedback Program -> No File <==== ATTENTION Task: {F6309E66-8415-4641-A250-40C2F9857251} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION Task: {FD303B05-6B84-49C8-BC65-819141CF7194} - \Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_ReadyToReboot -> No File <==== ATTENTION (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\Norton Security Scan for Levak.job => C:\PROGRA~2\NORTON~3\Engine\410~1.28\Nss.exe Task: C:\WINDOWS\Tasks\ParetoLogic Registration3.job => rundll32.exe C:\Program Files (x86)\Common Files\ParetoLogic\UUS3\UUS3.dll <==== ATTENTION Task: C:\WINDOWS\Tasks\ParetoLogic Update Version3 Startup Task.job => C:\Program Files (x86)\Common Files\ParetoLogic\UUS3\Pareto_Update3.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\ParetoLogic Update Version3.job => C:\Program Files (x86)\Common Files\ParetoLogic\UUS3\Pareto_Update3.exe <==== ATTENTION ==================== Shortcuts & WMI ======================== (The entries could be listed to be restored or removed.) Shortcut: C:\Users\Uporabnik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ICQ\icq.com.lnk -> hxxp://www.icq.com ShortcutWithArgument: C:\Users\Uporabnik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www%2dsearching.com/?prd=set_epf&s=h7czltpbl1bu,0e29e4d6-d214-4113-bce3-e9c5e901b2f9, ==================== Loaded Modules (Whitelisted) ============== 2014-09-25 22:24 - 2016-05-24 09:51 - 00116416 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll 2012-01-17 20:24 - 2012-01-17 20:24 - 00055296 _____ () C:\Windows\SysWOW64\ASGT.exe 2015-11-24 20:32 - 2015-11-24 20:32 - 00216576 _____ () C:\Program Files (x86)\GNU\GnuPG\dirmngr.exe 2017-06-15 01:23 - 2017-05-01 22:51 - 00133752 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2017-03-18 22:58 - 2017-03-18 22:58 - 00138000 _____ () C:\WINDOWS\SYSTEM32\inputhost.dll 2017-03-18 22:59 - 2017-03-20 06:09 - 01731072 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2017-07-12 10:28 - 2017-06-28 12:24 - 03184128 _____ () C:\Users\Uporabnik\AppData\Roaming\Microsoft\Windows\Helper.exe 2017-06-21 19:27 - 2017-06-21 19:28 - 00074752 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.18.614.0_x64__kzf8qxf38zg5c\SkypeHost.exe 2017-06-21 19:27 - 2017-06-21 19:28 - 00203264 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.18.614.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll 2017-06-21 19:27 - 2017-06-21 19:28 - 43454464 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.18.614.0_x64__kzf8qxf38zg5c\SkyWrap.dll 2017-06-21 19:27 - 2017-06-21 19:28 - 02437120 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.18.614.0_x64__kzf8qxf38zg5c\skypert.dll 2017-06-04 20:21 - 2017-06-04 20:21 - 26874504 _____ () C:\Users\Uporabnik\AppData\Roaming\ICQ\bin\icq.exe 2015-11-24 20:20 - 2015-11-24 20:20 - 00221696 _____ () C:\Program Files (x86)\GNU\GnuPG\libksba-8.dll 2015-11-24 20:20 - 2015-11-24 20:20 - 00073728 _____ () C:\Program Files (x86)\GNU\GnuPG\libassuan-0.dll 2015-11-24 20:09 - 2015-11-24 20:09 - 00050176 _____ () C:\Program Files (x86)\GNU\GnuPG\libw32pth-0.dll 2015-11-24 20:22 - 2015-11-24 20:22 - 00751104 _____ () C:\Program Files (x86)\GNU\GnuPG\libgcrypt-20.dll 2015-11-24 20:14 - 2015-11-24 20:14 - 00087552 _____ () C:\Program Files (x86)\GNU\GnuPG\libgpg-error-0.dll 2014-08-13 21:33 - 2013-01-24 01:57 - 01199576 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll 2017-05-31 11:41 - 2017-05-31 11:41 - 01982976 ____R () C:\Program Files (x86)\Skype\Phone\skypert.dll 2016-03-08 00:42 - 2016-03-08 00:42 - 00031512 _____ () C:\Program Files (x86)\Intuit\QuickBooks 2016\QBCompressor.dll 2016-03-08 00:43 - 2016-03-08 00:43 - 00084248 _____ () C:\Program Files (x86)\Intuit\QuickBooks 2016\QBProActiveCore.dll 2016-03-08 00:41 - 2016-03-08 00:41 - 00655640 _____ () C:\Program Files (x86)\Intuit\QuickBooks 2016\FtuEngine.dll 2016-03-08 00:43 - 2016-03-08 00:43 - 00102168 _____ () C:\Program Files (x86)\Intuit\QuickBooks 2016\QBMAPILibrary.dll 2016-03-07 23:32 - 2016-03-07 23:32 - 00630784 _____ () C:\Program Files (x86)\Intuit\QuickBooks 2016\boost_regex-vc120-mt-1_55.dll 2016-03-08 00:40 - 2016-03-08 00:40 - 00245528 _____ () C:\Program Files (x86)\Intuit\QuickBooks 2016\boost_serialization-vc120-mt-1_55.dll 2016-03-08 00:40 - 2016-03-08 00:40 - 00688408 _____ () C:\Program Files (x86)\Intuit\QuickBooks 2016\BackupLib.dll 2016-03-07 23:33 - 2016-03-07 23:33 - 00059904 _____ () C:\Program Files (x86)\Intuit\QuickBooks 2016\zlib1.dll 2016-03-07 23:31 - 2016-03-07 23:31 - 38715904 _____ () C:\Program Files (x86)\Intuit\QuickBooks 2016\libcef.dll 2016-03-08 00:41 - 2016-03-08 00:41 - 01235736 _____ () C:\Program Files (x86)\Intuit\QuickBooks 2016\FeaturesBridge.dll 2016-03-08 00:42 - 2016-03-08 00:42 - 00067864 _____ () C:\Program Files (x86)\Intuit\QuickBooks 2016\mbpopup.dll 2012-07-06 18:22 - 2012-07-06 18:22 - 00582656 _____ () C:\Program Files (x86)\Pidgin\exchndl.dll 2014-09-21 01:30 - 2014-09-21 01:30 - 00904525 _____ () C:\Program Files (x86)\Pidgin\Gtk\bin\libcairo-2.dll 2014-09-21 01:30 - 2014-09-21 01:30 - 00055808 _____ () C:\Program Files (x86)\Pidgin\Gtk\bin\zlib1.dll 2014-09-21 01:30 - 2014-09-21 01:30 - 00279059 _____ () C:\Program Files (x86)\Pidgin\Gtk\bin\libfontconfig-1.dll 2014-09-21 01:30 - 2014-09-21 01:30 - 00535264 _____ () C:\Program Files (x86)\Pidgin\Gtk\bin\freetype6.dll 2014-09-21 01:30 - 2014-09-21 01:30 - 00482872 _____ () C:\Program Files (x86)\Pidgin\Gtk\bin\libgio-2.0-0.dll 2014-09-21 01:30 - 2014-09-21 01:30 - 00143096 _____ () C:\Program Files (x86)\Pidgin\Gtk\bin\libexpat-1.dll 2014-09-21 01:30 - 2014-09-21 01:30 - 00095189 _____ () C:\Program Files (x86)\Pidgin\Gtk\bin\libpangocairo-1.0-0.dll 2012-07-06 18:21 - 2012-07-06 18:21 - 01213633 _____ () C:\Program Files (x86)\Pidgin\libxml2-2.dll 2014-09-21 01:30 - 2014-09-21 01:30 - 00219305 _____ () C:\Program Files (x86)\Pidgin\Gtk\bin\libpng14-14.dll 2012-07-06 18:22 - 2012-07-06 18:22 - 00475580 _____ () C:\Program Files (x86)\Pidgin\spellcheck\libgtkspell-0.dll 2012-07-06 18:22 - 2012-07-06 18:22 - 00015260 _____ () C:\Program Files (x86)\Pidgin\plugins\autoaccept.dll 2012-07-06 18:22 - 2012-07-06 18:22 - 00009052 _____ () C:\Program Files (x86)\Pidgin\plugins\buddynote.dll 2012-07-06 18:22 - 2012-07-06 18:22 - 00019699 _____ () C:\Program Files (x86)\Pidgin\plugins\convcolors.dll 2012-07-06 18:22 - 2012-07-06 18:22 - 00011501 _____ () C:\Program Files (x86)\Pidgin\plugins\extplacement.dll 2012-07-06 18:22 - 2012-07-06 18:22 - 00009946 _____ () C:\Program Files (x86)\Pidgin\plugins\gtkbuddynote.dll 2012-07-06 18:22 - 2012-07-06 18:22 - 00014681 _____ () C:\Program Files (x86)\Pidgin\plugins\history.dll 2012-07-06 18:22 - 2012-07-06 18:22 - 00008664 _____ () C:\Program Files (x86)\Pidgin\plugins\iconaway.dll 2012-07-06 18:22 - 2012-07-06 18:22 - 00012794 _____ () C:\Program Files (x86)\Pidgin\plugins\idle.dll 2012-07-06 18:22 - 2012-07-06 18:22 - 00012818 _____ () C:\Program Files (x86)\Pidgin\plugins\joinpart.dll 2012-07-06 18:22 - 2012-07-06 18:22 - 00010873 _____ () C:\Program Files (x86)\Pidgin\plugins\libaim.dll 2012-07-06 18:22 - 2012-07-06 18:22 - 00248914 _____ () C:\Program Files (x86)\Pidgin\liboscar.dll 2012-07-06 18:22 - 2012-07-06 18:22 - 00071089 _____ () C:\Program Files (x86)\Pidgin\plugins\libbonjour.dll 2012-07-06 18:22 - 2012-07-06 18:22 - 00178081 _____ () C:\Program Files (x86)\Pidgin\plugins\libgg.dll 2012-07-06 18:22 - 2012-07-06 18:22 - 00011804 _____ () C:\Program Files (x86)\Pidgin\plugins\libicq.dll 2012-07-06 18:22 - 2012-07-06 18:22 - 00075639 _____ () C:\Program Files (x86)\Pidgin\plugins\libirc.dll 2012-07-06 18:22 - 2012-07-06 18:22 - 00284936 _____ () C:\Program Files (x86)\Pidgin\plugins\libmsn.dll 2012-07-06 18:22 - 2012-07-06 18:22 - 00117957 _____ () C:\Program Files (x86)\Pidgin\plugins\libmxit.dll 2012-07-06 18:22 - 2012-07-06 18:22 - 00087621 _____ () C:\Program Files (x86)\Pidgin\plugins\libmyspace.dll 2012-07-06 18:22 - 2012-07-06 18:22 - 00087595 _____ () C:\Program Files (x86)\Pidgin\plugins\libnovell.dll 2012-07-06 18:22 - 2012-07-06 18:22 - 00093436 _____ () C:\Program Files (x86)\Pidgin\plugins\libsametime.dll 2012-07-06 18:21 - 2012-07-06 18:21 - 00173805 _____ () C:\Program Files (x86)\Pidgin\libmeanwhile-1.dll 2012-07-06 18:22 - 2012-07-06 18:22 - 00145897 _____ () C:\Program Files (x86)\Pidgin\plugins\libsilc.dll 2012-07-06 18:21 - 2012-07-06 18:21 - 02719062 _____ () C:\Program Files (x86)\Pidgin\libsilc-1-1-2.dll 2012-07-06 18:21 - 2012-07-06 18:21 - 01206642 _____ () C:\Program Files (x86)\Pidgin\libsilcclient-1-1-2.dll 2012-07-06 18:22 - 2012-07-06 18:22 - 00044389 _____ () C:\Program Files (x86)\Pidgin\plugins\libsimple.dll 2012-07-06 18:22 - 2012-07-06 18:22 - 00017648 _____ () C:\Program Files (x86)\Pidgin\plugins\libxmpp.dll 2012-07-06 18:22 - 2012-07-06 18:22 - 00323801 _____ () C:\Program Files (x86)\Pidgin\libjabber.dll 2012-07-06 18:22 - 2012-07-06 18:22 - 00018119 _____ () C:\Program Files (x86)\Pidgin\plugins\libyahoo.dll 2012-07-06 18:22 - 2012-07-06 18:22 - 00190403 _____ () C:\Program Files (x86)\Pidgin\libymsg.dll 2012-07-06 18:22 - 2012-07-06 18:22 - 00015592 _____ () C:\Program Files (x86)\Pidgin\plugins\libyahoojp.dll 2012-07-06 18:22 - 2012-07-06 18:22 - 00040118 _____ () C:\Program Files (x86)\Pidgin\plugins\log_reader.dll 2012-07-06 18:22 - 2012-07-06 18:22 - 00015546 _____ () C:\Program Files (x86)\Pidgin\plugins\markerline.dll 2012-07-06 18:22 - 2012-07-06 18:22 - 00009767 _____ () C:\Program Files (x86)\Pidgin\plugins\newline.dll 2012-07-06 18:22 - 2012-07-06 18:22 - 00022976 _____ () C:\Program Files (x86)\Pidgin\plugins\notify.dll 2012-07-06 18:22 - 2012-07-06 18:22 - 00012822 _____ () C:\Program Files (x86)\Pidgin\plugins\offlinemsg.dll 2012-09-09 15:17 - 2012-09-09 15:17 - 00472576 _____ () C:\Program Files (x86)\Pidgin\plugins\pidgin-otr.dll 2012-07-06 18:22 - 2012-07-06 18:22 - 00024031 _____ () C:\Program Files (x86)\Pidgin\plugins\pidginrc.dll 2012-07-06 18:22 - 2012-07-06 18:22 - 00010667 _____ () C:\Program Files (x86)\Pidgin\plugins\psychic.dll 2012-07-06 18:22 - 2012-07-06 18:22 - 00010716 _____ () C:\Program Files (x86)\Pidgin\plugins\relnot.dll 2012-07-06 18:22 - 2012-07-06 18:22 - 00011356 _____ () C:\Program Files (x86)\Pidgin\plugins\sendbutton.dll 2012-07-06 18:22 - 2012-07-06 18:22 - 00063326 _____ () C:\Program Files (x86)\Pidgin\plugins\spellchk.dll 2012-07-06 18:22 - 2012-07-06 18:22 - 00020495 _____ () C:\Program Files (x86)\Pidgin\plugins\ssl-nss.dll 2012-07-06 18:22 - 2012-07-06 18:22 - 00007803 _____ () C:\Program Files (x86)\Pidgin\plugins\ssl.dll 2012-07-06 18:22 - 2012-07-06 18:22 - 00010753 _____ () C:\Program Files (x86)\Pidgin\plugins\statenotify.dll 2012-07-06 18:22 - 2012-07-06 18:22 - 00024616 _____ () C:\Program Files (x86)\Pidgin\plugins\themeedit.dll 2012-07-06 18:22 - 2012-07-06 18:22 - 00024235 _____ () C:\Program Files (x86)\Pidgin\plugins\ticker.dll 2012-07-06 18:22 - 2012-07-06 18:22 - 00014710 _____ () C:\Program Files (x86)\Pidgin\plugins\timestamp.dll 2012-07-06 18:22 - 2012-07-06 18:22 - 00018592 _____ () C:\Program Files (x86)\Pidgin\plugins\timestamp_format.dll 2012-07-06 18:22 - 2012-07-06 18:22 - 00023542 _____ () C:\Program Files (x86)\Pidgin\plugins\win2ktrans.dll 2012-07-06 18:22 - 2012-07-06 18:22 - 00023498 _____ () C:\Program Files (x86)\Pidgin\plugins\winprefs.dll 2012-07-06 18:22 - 2012-07-06 18:22 - 00030942 _____ () C:\Program Files (x86)\Pidgin\plugins\xmppconsole.dll 2012-07-06 18:22 - 2012-07-06 18:22 - 00036197 _____ () C:\Program Files (x86)\Pidgin\plugins\xmppdisco.dll 2012-07-06 18:21 - 2012-07-06 18:21 - 00417501 _____ () C:\Program Files (x86)\Pidgin\sqlite3.dll 2014-09-21 01:30 - 2014-09-21 01:30 - 00090496 _____ () C:\Program Files (x86)\Pidgin\Gtk\lib\gtk-2.0\2.10.0\engines\libwimp.dll 2017-06-04 20:21 - 2017-06-04 20:21 - 04556424 _____ () C:\Users\Uporabnik\AppData\Roaming\ICQ\bin\corelib.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\WINDOWS\system32\Drivers\rvvhjhog.sys:changelist [1050] ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\QQPCRTP => ""="service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\QQPCRTP => ""="service" ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2016-07-16 13:47 - 2017-07-12 12:09 - 00001781 _____ C:\WINDOWS\system32\Drivers\etc\hosts 127.0.0.1 plugpackdownload.net 127.0.0.1 dscdn.pw 127.0.0.1 wemsofts.com 127.0.0.1 bongadoom.com 127.0.0.1 wepcmainsystem.com 127.0.0.1 internalcampaigntargets.com 127.0.0.1 bongadoom.com 127.0.0.1 getthefilenow.com 127.0.0.1 bigpicturepop.com 127.0.0.1 wizzcaster.com 127.0.0.1 bestoffersfortoday.com 127.0.0.1 wepcmainsystem.com 127.0.0.1 agent.wizztrakys.com 127.0.0.1 csdimonetize.com 127.0.0.1 dl.azalee.site 127.0.0.1 titiaredh.com 127.0.0.1 wepcdisplaysystem.com 127.0.0.1 wepcanalyticsystem.com 127.0.0.1 healthydownload.com 127.0.0.1 leading2download.com 127.0.0.1 dwl0.wizzlabs.com 127.0.0.1 dwl1.wizzlabs.com 127.0.0.1 installpixel.com 127.0.0.1 burningcube.ru 127.0.0.1 mess1.wizzmonetize.com 127.0.0.1 dl.azalee.site 127.0.0.1 dl.smashdl.com 127.0.0.1 downloadmyhost.com 127.0.0.1 lapapahoster.com ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-3349261695-2154521845-2584642868-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Lenovo\LUX-Maldives-01.jpg DNS Servers: 192.168.1.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == HKLM\...\StartupApproved\StartupFolder: => "V-Gear WebCam Pro2 Still Image.lnk" HKLM\...\StartupApproved\StartupFolder: => "HP Digital Imaging Monitor.lnk" HKLM\...\StartupApproved\Run32: => "Acrobat Assistant 8.0" HKLM\...\StartupApproved\Run32: => "Power Manager Startup Utility" HKLM\...\StartupApproved\Run32: => "TkBellExe" HKLM\...\StartupApproved\Run32: => "HP Software Update" HKU\S-1-5-21-3349261695-2154521845-2584642868-1001\...\StartupApproved\StartupFolder: => "Pošiljanje v OneNote.lnk" HKU\S-1-5-21-3349261695-2154521845-2584642868-1001\...\StartupApproved\Run: => "DAEMON Tools Lite" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [UDP Query User{BCECD1AC-1A85-4B72-8C72-6461B69F1FC7}C:\program files (x86)\vip72 socks\vip72socks.exe] => (Block) C:\program files (x86)\vip72 socks\vip72socks.exe FirewallRules: [TCP Query User{42BFA2B4-F07F-4398-BE96-8D02148E3D15}C:\program files (x86)\vip72 socks\vip72socks.exe] => (Block) C:\program files (x86)\vip72 socks\vip72socks.exe FirewallRules: [UDP Query User{EF0ABCE7-0913-4D15-B374-93CCFC8EB801}C:\users\uporabnik\appdata\roaming\icq\bin\icq.exe] => (Allow) C:\users\uporabnik\appdata\roaming\icq\bin\icq.exe FirewallRules: [TCP Query User{B6538AEA-EE64-47CF-AFF5-B823F5818B86}C:\users\uporabnik\appdata\roaming\icq\bin\icq.exe] => (Allow) C:\users\uporabnik\appdata\roaming\icq\bin\icq.exe FirewallRules: [{965BC79F-44C0-4F7E-9F13-636CF0F9F5D3}] => (Allow) C:\Program Files (x86)\Lenovo\System Update\uncserver.exe FirewallRules: [{6DA0FFC6-BCA8-41A2-AC92-1CCDC1E45DE7}] => (Allow) C:\Program Files (x86)\Lenovo\System Update\uncserver.exe FirewallRules: [{FAF0AE6E-AE5C-44E4-91BF-AA513444E644}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\UcMapi.exe FirewallRules: [{7A4A140E-F5F6-40B2-9854-1346E4DCFA0D}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\UcMapi.exe FirewallRules: [{A1B0CB56-D4A6-41D4-9115-152D751DA18A}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\Lync.exe FirewallRules: [{4E3C4E20-D256-4682-96E8-5D82B143DD65}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\Lync.exe FirewallRules: [{6E747BBC-78AA-4F07-8386-62EC4ADFA1AD}] => (Allow) C:\Program Files (x86)\X-Lite\x-lite.exe FirewallRules: [{AF348D39-7E51-4984-91EF-FB2F69F6359B}] => (Allow) C:\Program Files (x86)\X-Lite\x-lite.exe FirewallRules: [{65FBC154-0D94-4F9D-86D1-85CE4C93AA56}] => (Allow) C:\Program Files (x86)\X-Lite\x-lite.exe FirewallRules: [{86342BAC-A453-4BDC-AA70-D17D3D34D768}] => (Allow) C:\Program Files (x86)\X-Lite\x-lite.exe FirewallRules: [{F3DA6C7F-6196-48CF-A60D-B6A6A2BD5D20}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{9E504C23-E504-465A-8A3A-275D1B736A4B}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{5055C19C-33D0-4AC9-A900-BF18B9F49600}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe FirewallRules: [{1CA01F57-191E-42DA-A430-4CE0E2522CA0}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe FirewallRules: [{2FFBD2FE-17B5-423F-81A9-43237449E9DA}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{A3EBD962-858E-47C5-BF7C-4EDFC93319A1}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{911DE18C-BE07-463A-A46E-A0C7EB08AD64}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{D2230FE9-74FB-429C-9C9C-C13A6BDCEE75}] => (Allow) C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe FirewallRules: [{F48C72C6-8A31-49FD-A800-D98E4B675450}] => (Allow) C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe FirewallRules: [{A6668F33-CB77-4727-80FE-6D0399827F3A}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe FirewallRules: [{AEFD3B30-19B0-48BD-9672-EFE891019699}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe FirewallRules: [{BA1F97DE-DFF9-40E8-A06E-75A0AFE04A32}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposid01.exe FirewallRules: [{30B2BC6A-345D-4050-9639-597F2D37D082}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqkygrp.exe FirewallRules: [{20EE71F2-733D-4BD0-A341-2C0A045B1CD7}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcopy2.exe FirewallRules: [{DD544F91-9140-4A27-B47F-6F2319641BEF}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpfccopy.exe FirewallRules: [{9D67B051-2386-4DE1-AB73-B8517A89407B}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpoews01.exe FirewallRules: [{238FEA46-BBD4-4B98-84D6-4B6CCF159791}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpiscnapp.exe FirewallRules: [{A96437DF-10DA-4526-865E-AAB3316AA812}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgplgtupl.exe FirewallRules: [{33C58F22-2FFA-4077-9475-1FAA9DFFFABD}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe FirewallRules: [{E844E5FF-AA59-4DBD-AA17-2992718F4A0C}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgm.exe FirewallRules: [{7149F575-891C-4794-AAC8-526DFFB2DBB5}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgh.exe FirewallRules: [{CD9432C7-12AA-4944-B4C7-999EBB3B0FD2}] => (Allow) C:\Program Files (x86)\HP\hp software update\hpwucli.exe FirewallRules: [{645B4085-6E71-4516-BE7F-5B6394559A95}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\outlook.exe FirewallRules: [TCP Query User{CAEFFD99-57F3-4C37-AD8A-89A3629574F3}C:\program files (x86)\zoiper\zoiper.exe] => (Allow) C:\program files (x86)\zoiper\zoiper.exe FirewallRules: [UDP Query User{40DC8934-683A-4DA7-98AC-6DA1F9A00EF5}C:\program files (x86)\zoiper\zoiper.exe] => (Allow) C:\program files (x86)\zoiper\zoiper.exe FirewallRules: [TCP Query User{56A1F4EB-7FF4-451A-BA13-1789E5F7808E}C:\program files (x86)\pidgin\pidgin.exe] => (Allow) C:\program files (x86)\pidgin\pidgin.exe FirewallRules: [UDP Query User{7D7B2418-0341-4216-A254-366EDB6B3B74}C:\program files (x86)\pidgin\pidgin.exe] => (Allow) C:\program files (x86)\pidgin\pidgin.exe FirewallRules: [{01DBE6C2-78AD-46F3-9125-DDB1EB07603C}] => (Allow) C:\WINDOWS\system32\rundll32.exe FirewallRules: [{17C62F9F-5D7B-44D6-852B-122498FA559B}] => (Allow) C:\Windows\System32\rundll32.exe FirewallRules: [{FC3660DA-756F-4039-A990-0D351B5090B4}] => (Allow) C:\Windows\System32\rundll32.exe ==================== Restore Points ========================= 01-07-2017 12:43:18 Scheduled Checkpoint 10-07-2017 11:30:42 Scheduled Checkpoint 12-07-2017 10:32:22 Installed ezPaycheck ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (07/16/2017 11:30:48 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Napačno ime programa: attrib.exe, različica: 10.0.15063.0, časovni žig: 0xf8d2fac2 Napačno ime modula: libcrypto-1.0.0.dll, različica: 0.0.0.0, časovni žig: 0xa478a468 Koda izjeme: 0xc0000005 Napačen odmik: 0x0000000000000000 Napačen id procesa: 0x2b30 Napačen začetni čas programa: 0x01d2fe120224ab8f Napačna programska pot: c:\Windows\System32\attrib.exe Napačna pot modula: C:\Users\Uporabnik\AppData\Roaming\Microsoft\Windows\libcrypto-1.0.0.dll Id poročila: ee7acb65-04d5-49b7-9dcd-631c24e82aa0 Napačno polno ime paketa: Napačen ID programa, sorodnega paketu: Error: (07/16/2017 11:30:48 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Napačno ime programa: attrib.exe, različica: 10.0.15063.0, časovni žig: 0xf8d2fac2 Napačno ime modula: libssl-1.0.0.dll, različica: 0.0.0.0, časovni žig: 0x6af5c060 Koda izjeme: 0xc0000005 Napačen odmik: 0x0000000000000000 Napačen id procesa: 0x2b30 Napačen začetni čas programa: 0x01d2fe120224ab8f Napačna programska pot: c:\Windows\System32\attrib.exe Napačna pot modula: C:\Users\Uporabnik\AppData\Roaming\Microsoft\Windows\libssl-1.0.0.dll Id poročila: a96c1794-003a-4239-9bd9-db2482d26542 Napačno polno ime paketa: Napačen ID programa, sorodnega paketu: Error: (07/16/2017 11:30:47 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Napačno ime programa: attrib.exe, različica: 10.0.15063.0, časovni žig: 0xf8d2fac2 Napačno ime modula: libz-1.dll, različica: 0.0.0.0, časovni žig: 0x00000000 Koda izjeme: 0xc0000005 Napačen odmik: 0x0000000000000000 Napačen id procesa: 0x2b30 Napačen začetni čas programa: 0x01d2fe120224ab8f Napačna programska pot: c:\Windows\System32\attrib.exe Napačna pot modula: C:\Users\Uporabnik\AppData\Roaming\Microsoft\Windows\libz-1.dll Id poročila: e5d17a1e-4626-4bf1-8c2c-d6bbd0fab3a1 Napačno polno ime paketa: Napačen ID programa, sorodnega paketu: Error: (07/16/2017 11:30:47 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Napačno ime programa: attrib.exe, različica: 10.0.15063.0, časovni žig: 0xf8d2fac2 Napačno ime modula: libcurl-4.dll, različica: 0.0.0.0, časovni žig: 0x0005951a Koda izjeme: 0xc0000005 Napačen odmik: 0x0000000000000000 Napačen id procesa: 0x2b30 Napačen začetni čas programa: 0x01d2fe120224ab8f Napačna programska pot: c:\Windows\System32\attrib.exe Napačna pot modula: C:\Users\Uporabnik\AppData\Roaming\Microsoft\Windows\libcurl-4.dll Id poročila: 27ed20ed-5207-451e-9e43-e8251cb5fe96 Napačno polno ime paketa: Napačen ID programa, sorodnega paketu: Error: (07/16/2017 11:30:47 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Napačno ime programa: attrib.exe, različica: 10.0.15063.0, časovni žig: 0xf8d2fac2 Napačno ime modula: libwinpthread-1.dll, različica: 0.0.0.0, časovni žig: 0x89c085ff Koda izjeme: 0xc0000005 Napačen odmik: 0x0000000000000000 Napačen id procesa: 0x2b30 Napačen začetni čas programa: 0x01d2fe120224ab8f Napačna programska pot: c:\Windows\System32\attrib.exe Napačna pot modula: C:\Users\Uporabnik\AppData\Roaming\Microsoft\Windows\libwinpthread-1.dll Id poročila: d29dbd1c-47d5-4c1a-a06a-4a9b0f9efd89 Napačno polno ime paketa: Napačen ID programa, sorodnega paketu: Error: (07/16/2017 11:30:47 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Napačno ime programa: attrib.exe, različica: 10.0.15063.0, časovni žig: 0xf8d2fac2 Napačno ime modula: libgcc_s_seh-1.dll, različica: 0.0.0.0, časovni žig: 0x022cba38 Koda izjeme: 0xc0000005 Napačen odmik: 0x0000000000000000 Napačen id procesa: 0x2b30 Napačen začetni čas programa: 0x01d2fe120224ab8f Napačna programska pot: c:\Windows\System32\attrib.exe Napačna pot modula: C:\Users\Uporabnik\AppData\Roaming\Microsoft\Windows\libgcc_s_seh-1.dll Id poročila: ae17076b-16f4-4d30-8ea1-b9f94107d95d Napačno polno ime paketa: Napačen ID programa, sorodnega paketu: Error: (07/16/2017 11:30:47 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Napačno ime programa: attrib.exe, različica: 10.0.15063.0, časovni žig: 0xf8d2fac2 Napačno ime modula: libjansson-4.dll, različica: 0.0.0.0, časovni žig: 0x000157d0 Koda izjeme: 0xc0000005 Napačen odmik: 0x0000000000000000 Napačen id procesa: 0x2b30 Napačen začetni čas programa: 0x01d2fe120224ab8f Napačna programska pot: c:\Windows\System32\attrib.exe Napačna pot modula: C:\Users\Uporabnik\AppData\Roaming\Microsoft\Windows\libjansson-4.dll Id poročila: 50f32bfe-71b8-486c-873e-c1a050caa3b1 Napačno polno ime paketa: Napačen ID programa, sorodnega paketu: Error: (07/16/2017 11:30:46 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Napačno ime programa: attrib.exe, različica: 10.0.15063.0, časovni žig: 0xf8d2fac2 Napačno ime modula: libstdc++-6.dll, različica: 0.0.0.0, časovni žig: 0x00000000 Koda izjeme: 0xc0000005 Napačen odmik: 0x0000000000000000 Napačen id procesa: 0x2b30 Napačen začetni čas programa: 0x01d2fe120224ab8f Napačna programska pot: c:\Windows\System32\attrib.exe Napačna pot modula: C:\Users\Uporabnik\AppData\Roaming\Microsoft\Windows\libstdc++-6.dll Id poročila: 1e64c077-bb3b-4533-9311-42d3b795dc68 Napačno polno ime paketa: Napačen ID programa, sorodnega paketu: Error: (07/16/2017 11:30:46 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Napačno ime programa: attrib.exe, različica: 10.0.15063.0, časovni žig: 0xf8d2fac2 Napačno ime modula: libcrypto-1.0.0.dll, različica: 0.0.0.0, časovni žig: 0xa478a468 Koda izjeme: 0xc0000005 Napačen odmik: 0x0000000000000000 Napačen id procesa: 0x2b30 Napačen začetni čas programa: 0x01d2fe120224ab8f Napačna programska pot: c:\Windows\System32\attrib.exe Napačna pot modula: C:\Users\Uporabnik\AppData\Roaming\Microsoft\Windows\libcrypto-1.0.0.dll Id poročila: 1fcbf2dc-4d8a-4c98-8e86-17146ab2e94d Napačno polno ime paketa: Napačen ID programa, sorodnega paketu: Error: (07/16/2017 11:30:46 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Napačno ime programa: attrib.exe, različica: 10.0.15063.0, časovni žig: 0xf8d2fac2 Napačno ime modula: libssl-1.0.0.dll, različica: 0.0.0.0, časovni žig: 0x6af5c060 Koda izjeme: 0xc0000005 Napačen odmik: 0x0000000000000000 Napačen id procesa: 0x2b30 Napačen začetni čas programa: 0x01d2fe120224ab8f Napačna programska pot: c:\Windows\System32\attrib.exe Napačna pot modula: C:\Users\Uporabnik\AppData\Roaming\Microsoft\Windows\libssl-1.0.0.dll Id poročila: e4c5b2a1-29b4-412a-ba6b-24c0d895b082 Napačno polno ime paketa: Napačen ID programa, sorodnega paketu: System errors: ============= Error: (07/16/2017 12:43:12 PM) (Source: Ntfs) (EventID: 55) (User: NT AUTHORITY) Description: A corruption was discovered in the file system structure on volume Windows8_OS. The exact nature of the corruption is unknown. The file system structures need to be scanned online. Error: (07/16/2017 12:43:09 PM) (Source: Ntfs) (EventID: 55) (User: NT AUTHORITY) Description: A corruption was discovered in the file system structure on volume Windows8_OS. The exact nature of the corruption is unknown. The file system structures need to be scanned online. Error: (07/16/2017 12:43:07 PM) (Source: Ntfs) (EventID: 55) (User: NT AUTHORITY) Description: A corruption was discovered in the file system structure on volume Windows8_OS. A corruption was found in a file system index structure. The file reference number is 0x10000000194ca. The name of the file is "\System Volume Information". The corrupted index attribute is ":$I30:$INDEX_ALLOCATION". Error: (07/16/2017 01:41:39 AM) (Source: DCOM) (EventID: 10010) (User: PC) Description: The server Microsoft.Windows.Cortana_1.8.12.15063_neutral_neutral_cw5n1h2txyewy!CortanaUI.AppX6jbm6fjqte5wzzrf5807m7eq0z44q5gf.mca did not register with DCOM within the required timeout. Error: (07/15/2017 05:55:22 PM) (Source: Schannel) (EventID: 4114) (User: PC) Description: The certificate received from the remote server was issued by an untrusted certificate authority. Because of this, none of the data contained in the certificate can be validated. The TLS connection request has failed. The attached data contains the server certificate. Error: (07/15/2017 05:54:21 PM) (Source: Schannel) (EventID: 4114) (User: PC) Description: The certificate received from the remote server was issued by an untrusted certificate authority. Because of this, none of the data contained in the certificate can be validated. The TLS connection request has failed. The attached data contains the server certificate. Error: (07/15/2017 05:54:19 PM) (Source: Schannel) (EventID: 4114) (User: PC) Description: The certificate received from the remote server was issued by an untrusted certificate authority. Because of this, none of the data contained in the certificate can be validated. The TLS connection request has failed. The attached data contains the server certificate. Error: (07/15/2017 05:53:19 PM) (Source: Schannel) (EventID: 4114) (User: PC) Description: The certificate received from the remote server was issued by an untrusted certificate authority. Because of this, none of the data contained in the certificate can be validated. The TLS connection request has failed. The attached data contains the server certificate. Error: (07/15/2017 05:52:18 PM) (Source: Schannel) (EventID: 4114) (User: PC) Description: The certificate received from the remote server was issued by an untrusted certificate authority. Because of this, none of the data contained in the certificate can be validated. The TLS connection request has failed. The attached data contains the server certificate. Error: (07/15/2017 05:51:17 PM) (Source: Schannel) (EventID: 4114) (User: PC) Description: The certificate received from the remote server was issued by an untrusted certificate authority. Because of this, none of the data contained in the certificate can be validated. The TLS connection request has failed. The attached data contains the server certificate. CodeIntegrity: =================================== Date: 2017-07-14 13:24:33.116 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files (x86)\Common Files\Avnex\vcs64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2017-07-13 14:18:19.274 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files (x86)\Common Files\Avnex\vcs64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2017-07-13 14:00:59.058 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files (x86)\Common Files\Avnex\vcs64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2017-07-13 08:22:17.932 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files (x86)\Common Files\Avnex\vcs64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2017-07-12 18:55:16.161 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files (x86)\Common Files\Avnex\vcs64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2017-07-12 14:02:55.894 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files (x86)\Common Files\Avnex\vcs64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2017-07-12 13:41:37.002 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files (x86)\Common Files\Avnex\vcs64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2017-07-12 12:42:06.921 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Tencent\QQPCMgr\12.2.18347.225\TSVulFWX64.DAT that did not meet the Store signing level requirements. Date: 2017-07-12 12:42:06.785 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Tencent\QQPCMgr\12.2.18347.225\TSVulFWX64.DAT that did not meet the Store signing level requirements. Date: 2017-07-12 12:24:14.250 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files (x86)\Common Files\Avnex\vcs64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i7-4770 CPU @ 3.40GHz Percentage of memory in use: 10% Total physical RAM: 32692.04 MB Available physical RAM: 29148.26 MB Total Virtual: 37556.04 MB Available Virtual: 34096.3 MB ==================== Drives ================================ Drive c: (Windows8_OS) (Fixed) (Total:450.02 GB) (Free:384.8 GB) NTFS ==>[system with boot components (obtained from drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 465.8 GB) (Disk ID: 0624874C) Partition: GPT. ==================== End of Addition.txt ============================