Additional scan result of Farbar Recovery Scan Tool (x64) Version: 25-09-2017 01 Ran by [removed] (25-09-2017 19:56:17) Running from C:\Users\[removed]\Downloads Windows 10 Home Version 1703 (X64) (2017-05-13 10:47:29) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-2082031664-807437708-106104952-500 - Administrator - Disabled) ASPNET (S-1-5-21-2082031664-807437708-106104952-1007 - Limited - Enabled) DefaultAccount (S-1-5-21-2082031664-807437708-106104952-503 - Limited - Disabled) Guest (S-1-5-21-2082031664-807437708-106104952-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-2082031664-807437708-106104952-1006 - Limited - Enabled) Joshua (S-1-5-21-2082031664-807437708-106104952-1002 - Administrator - Enabled) => C:\Users\Joshua ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: Panda Antivirus Pro (Disabled - Up to date) {46AEFD02-ACA3-E038-1FA5-4A15EFD361E0} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Panda Antivirus Pro (Disabled - Up to date) {FDCF1CE6-8A99-EFB6-2515-716794542B5D} FW: Panda Firewall (Disabled) {7E957C27-E6CC-E160-34FA-E3201100269B} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 7-Zip 16.02 (x64) (HKLM\...\7-Zip) (Version: 16.02 - Igor Pavlov) 7-Zip 16.04 (x64 edition) (HKLM\...\{23170F69-40C1-2702-1604-000001000000}) (Version: 16.04.00.0 - Igor Pavlov) Ablebits.com Ultimate Suite for Microsoft Excel (HKLM-x32\...\{F2A020E7-840B-4895-9500-FCD14C5D6BEF}) (Version: 16.4.484 - Add-in Express Ltd) Adobe Shockwave Player 11.6 (HKLM-x32\...\Adobe Shockwave Player) (Version: 11.6.5.635 - Adobe Systems, Inc.) Adobe Shockwave Player 12.2 (HKLM-x32\...\{52B66F1A-E977-41EE-8359-3C4040BE72F5}) (Version: 12.2.8.198 - Adobe Systems, Inc) Aegisub 3.2.2 (HKLM\...\{24BC8B57-716C-444F-B46B-A3349B9164C5}_is1) (Version: 3.2.2 - Aegisub Team) AMD Catalyst Install Manager (HKLM\...\{D01E0B82-7D6E-F9AC-9A7D-C6076264F419}) (Version: 8.0.881.0 - Advanced Micro Devices, Inc.) AMD Quick Stream (HKLM\...\{E9EED4AE-682B-4501-9574-D09A21717599}_is1) (Version: 3.3.26.0 - AppEx Networks) AstroGrep (HKLM-x32\...\AstroGrep) (Version: 4.4.6 - AstroComma, Inc.) AuthenTec TrueAPI 64-bit (HKLM\...\{EBC0CC3F-B7A1-4FC8-8014-4C7BFD3925E8}) (Version: 1.6.0.86 - AuthenTec, Inc.) Hidden Backup and Sync from Google (HKLM-x32\...\{9AC75ED0-A54A-4AEA-9563-87572879D91C}) (Version: 3.36.6721.3394 - Google, Inc.) Belarc Advisor 8.5c (HKLM-x32\...\Belarc Advisor) (Version: 8.5.3.0 - Belarc Inc.) Blizzard App (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) BorderlessBrowser (HKLM-x32\...\{22530547-85B3-467D-94DC-90228C58E387}) (Version: 1.1.0 - Clement Lorteau) Brave (HKU\S-1-5-21-2082031664-807437708-106104952-1002\...\Brave) (Version: 0.18.36 - Brave Software) calibre (HKLM-x32\...\{00F91371-9FE2-4F75-9B49-8F7D1C135214}) (Version: 3.7.0 - Kovid Goyal) CDBurnerXP (HKLM-x32\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.7.6623 - CDBurnerXP) Connect (HKLM-x32\...\MAGIX_connector_is1) (Version: 2.5.1.84 - MAGIX Software GmbH) Cybereason RansomFree 2.4.0.0 (HKLM-x32\...\{E5187076-2C8E-4062-88D2-E29DC4F4962C}) (Version: 2.4.0.0 - Cybereason Inc.) CyberLink LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.1.5407 - CyberLink Corp.) CyberLink Media Suite 10 (HKLM-x32\...\InstallShield_{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}) (Version: 10.0.1.1916 - CyberLink Corp.) CyberLink PhotoDirector (HKLM-x32\...\InstallShield_{4862344A-A39C-4897-ACD4-A1BED5163C5A}) (Version: 2.0.1.3119 - CyberLink Corp.) CyberLink Power2Go 8 (HKLM-x32\...\InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}) (Version: 8.0.1.1926 - CyberLink Corp.) CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.1.1925 - CyberLink Corp.) CyberLink PowerDVD (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.6.4319 - CyberLink Corp.) CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.5.4.5527 - CyberLink Corp.) D3DX10 (HKLM-x32\...\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden Dead in Bermuda (HKLM-x32\...\{FA6BAE37-E751-46A2-A26D-C6090ECCEBD3}) (Version: 1.1.0.0 - Plug In Digital) DisplayLink Core Software (HKLM\...\{F3B9FCD6-4E63-40B6-A38F-A38644E70629}) (Version: 7.9.1589.0 - DisplayLink Corp.) DisplayLink Graphics (HKLM\...\{291A3AE0-D946-4F8A-9F7C-A083B5C0CCD2}) (Version: 7.9.1591.0 - DisplayLink Corp.) Dolphin (HKLM-x32\...\Dolphin) (Version: 5.0 - Dolphin Team) Dragon Age: Origins (HKLM-x32\...\{AEC81925-9C76-4707-84A9-40696C613ED3}) (Version: 1.05.13263.0 - Electronic Arts) Dropbox (HKLM-x32\...\Dropbox) (Version: 35.4.20 - Dropbox, Inc.) Dropbox Update Helper (HKLM-x32\...\{099218A5-A723-43DC-8DB5-6173656A1E94}) (Version: 1.3.59.1 - Dropbox, Inc.) Hidden Dungeons & Dragons Online® (HKLM\...\Steam App 206480) (Version: - Turbine, Inc.) Energy Star (HKLM\...\{0FA995CC-C849-4755-B14B-5404CC75DC24}) (Version: 1.0.8 - Hewlett-Packard) FairStars CD Ripper 1.90 (HKLM-x32\...\FairStars CD Ripper_is1) (Version: - FairStars Soft) FossaMail 25.2.4 (x64 en-US) (HKLM\...\FossaMail 25.2.4 (x64 en-US)) (Version: 25.2.4 - Mozilla) Freemake Audio Converter version 1.1.8 (HKLM-x32\...\Freemake Audio Converter_is1) (Version: 1.1.8 - Ellora Assets Corporation) FreeStyle2: Street Basketball (HKLM\...\Steam App 339610) (Version: - Joycity) Git version 2.13.0 (HKLM\...\Git_is1) (Version: 2.13.0 - The Git Development Community) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 61.0.3163.100 - Google Inc.) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.5 - Google Inc.) Hidden Greenshot 1.2.8.12 (HKLM\...\Greenshot_is1) (Version: 1.2.8.12 - Greenshot) HandBrake 0.10.5 (HKLM-x32\...\HandBrake) (Version: 0.10.5 - ) HD Video Converter Factory Pro 12.0 (HKLM-x32\...\HD Video Converter Factory Pro) (Version: 12.0 - WonderFox Soft, Inc.) Hewlett-Packard ACLM.NET v1.2.0.0 (HKLM-x32\...\{6F340107-F9AA-47C6-B54C-C3A19F11553F}) (Version: 1.00.0000 - Hewlett-Packard Company) Hidden HP 3D DriveGuard (HKLM\...\{F244D07D-1876-4CDD-914D-214E15A8D327}) (Version: 4.2.5.1 - Hewlett-Packard Company) HP CoolSense (HKLM-x32\...\{16B7BDA1-B967-4D2D-8B27-E12727C28350}) (Version: 2.10.3 - Hewlett-Packard Company) HP Documentation (HKLM-x32\...\{7DE5085A-3665-40BC-9595-A1A209699137}) (Version: 1.1.0.0 - Hewlett-Packard) HP Games (HKLM-x32\...\WildTangent hp Master Uninstall) (Version: 1.0.3.0 - WildTangent) HP MyRoom (HKLM-x32\...\{9C35EDE5-4B0F-45E7-A438-314BA889948E}) (Version: 9.0.0.0 - Hewlett-Packard Company) HP Quick Launch (HKLM-x32\...\{609B11CC-8CED-4116-AD8A-A72168894D39}) (Version: 3.0.4 - Hewlett-Packard Company) HP Registration Service (HKLM\...\{E4D6CCF2-0AAF-4B9C-9DE5-893EDC9B4BAA}) (Version: 1.0.5976.4186 - Hewlett-Packard) HP Software Framework (HKLM-x32\...\{835B275B-F29B-464B-BD4B-097FD55FAB0A}) (Version: 4.6.8.1 - Hewlett-Packard Company) HP Support Assistant (HKLM-x32\...\{B8019B54-F9BE-490A-9619-6D06F18F129F}) (Version: 7.0.32.44 - Hewlett-Packard Company) HP Utility Center (HKLM-x32\...\{0C57987A-A03A-4B95-A309-D23F78F406CA}) (Version: 1.0.7 - Hewlett-Packard) HP Wireless Button Driver (HKLM-x32\...\{941DE69D-6CEE-4171-8F1F-3D7E352AA498}) (Version: 1.0.5.1 - Hewlett-Packard Company) IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6425.0 - IDT) IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.42 - Irfan Skiljan) IrfanView 4.44 (64-bit) (HKLM\...\IrfanView64) (Version: 4.44 - Irfan Skiljan) ISO to USB (HKLM-x32\...\{D08A30AC-A663-4EA8-8D81-B98E17F19F1C}_is1) (Version: - isotousb.com) Java 8 Update 131 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180131F0}) (Version: 8.0.1310.11 - Oracle Corporation) Java 8 Update 131 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180131F0}) (Version: 8.0.1310.11 - Oracle Corporation) Java SE Development Kit 8 Update 121 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0180121}) (Version: 8.0.1210.13 - Oracle Corporation) KeePass Password Safe 2.34 (HKLM-x32\...\KeePassPasswordSafe2_is1) (Version: 2.34 - Dominik Reichl) Kodi (HKU\S-1-5-21-2082031664-807437708-106104952-1002\...\Kodi) (Version: - XBMC-Foundation) Kutools for Word version 8.6.0.125 (HKLM-x32\...\{E9A0AD37-5BA2-4E60-85F1-8B785CF2FBF5}_is1) (Version: 8.6.0.125 - ExtendOffice) LastPass (uninstall only) (HKLM-x32\...\LastPass) (Version: - LastPass) League of Legends (HKLM-x32\...\{E80C09B5-A296-47E9-BD4B-BCCF2FDCA13E}) (Version: 4.1.2 - Riot Games) Hidden League of Legends (HKLM-x32\...\League of Legends 4.1.2) (Version: 4.1.2 - Riot Games) MAGIX Content and Soundpools (HKLM-x32\...\MAGIX_GlobalContent) (Version: 1.0.0.0 - MAGIX Software GmbH) MAGIX Soundpool Music Maker - Feel good (HKLM\...\{1DD15EDF-7474-4F65-B459-2E5233F583F6}) (Version: 1.0.0.0 - MAGIX Software GmbH) Hidden Malwarebytes version 3.2.2.2029 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.2.2.2029 - Malwarebytes) Marvel Heroes 2016 (HKLM\...\Steam App 226320) (Version: - Gazillion Entertainment) Mass Effect™ 2 (HKLM-x32\...\{75D84EF7-0D8C-4e70-B3FA-7B42A5D4E0EB}) (Version: 1.2.1604.0 - Electronic Arts) Medal of Honor: Pacific Assault™ (HKLM-x32\...\{56CFA833-F44F-4199-8C58-7F8B38F2BC7B}) (Version: 1.2.1.281 - Electronic Arts) Meld (HKLM-x32\...\{790FF9F0-3503-4E4D-A50D-6B85749C8651}) (Version: 3.16.2 - The Meld project) Messenger for Desktop (HKU\S-1-5-21-2082031664-807437708-106104952-1002\...\messengerfordesktop) (Version: 2.0.9 - MessengerForDesktop.com) Microsoft .NET Framework 1.1 (HKLM-x32\...\{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}) (Version: 1.1.4322 - Microsoft) Microsoft Office Professional Plus 2016 - en-us (HKLM\...\ProPlusRetail - en-us) (Version: 16.0.8431.2079 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-2082031664-807437708-106104952-1002\...\OneDriveSetup.exe) (Version: 17.3.6917.0607 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23918 (HKLM-x32\...\{dab68466-3a7d-41a8-a5cf-415e3ff8ef71}) (Version: 14.0.23918.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23506 (HKLM-x32\...\{23daf363-3020-4059-b3ae-dc4ad39fed19}) (Version: 14.0.23506.0 - Microsoft Corporation) Microsoft Visual Studio Code (HKLM\...\{EA457B21-F73E-494C-ACAB-524FDE069978}_is1) (Version: 1.16.1 - Microsoft Corporation) MOBIUS FINAL FANTASY (HKLM\...\Steam App 536930) (Version: - SQUARE ENIX CO., LTD.) Mp3tag v2.80 (HKLM-x32\...\Mp3tag) (Version: v2.80 - Florian Heidenreich) Music Maker (HKLM\...\{D5FF45D3-3AE3-4490-85DE-04D059606382}) (Version: 25.0.1.33 - MAGIX Software GmbH) Hidden Music Maker (HKLM-x32\...\MX.{D5FF45D3-3AE3-4490-85DE-04D059606382}) (Version: 25.0.1.33 - MAGIX Software GmbH) Need for Speed™ Most Wanted (HKLM-x32\...\{FB0127F3-985B-44CE-AE29-378CAF60B361}) (Version: 1.5.0.0 - Electronic Arts) NexusFile (5.3.3.5532) (HKLM-x32\...\{ED0FB0C1-CD06-4C29-B903-8A91D4BF5B61}_is1) (Version: - xiles) Nox APP Player (HKLM-x32\...\Nox) (Version: 3.8.3.1 - Duodian Technology Co. Ltd.) NVIDIA PhysX (HKLM-x32\...\{80407BA7-7763-4395-AB98-5233F1B34E65}) (Version: 9.13.1220 - NVIDIA Corporation) Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.8431.2079 - Microsoft Corporation) Hidden Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.8431.2079 - Microsoft Corporation) Hidden Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0409-1000-0000000FF1CE}) (Version: 16.0.8326.2107 - Microsoft Corporation) Hidden Oracle VM VirtualBox 5.1.22 (HKLM\...\{8D5E4D4D-5E0C-4448-B018-5DDEF1E208D9}) (Version: 5.1.22 - Oracle Corporation) Origin (HKLM-x32\...\Origin) (Version: 10.5.2.49155 - Electronic Arts, Inc.) Outlast (HKLM\...\Steam App 238320) (Version: - Red Barrels) paint.net (HKLM\...\{6AC1101E-7561-43C9-BEEA-4AB1D220D8FF}) (Version: 4.0.13 - dotPDN LLC) Panda Antivirus Pro (HKLM\...\{456A8117-2915-414D-8435-AC57447C4E2D}) (Version: 8.31.10 - Panda Security) Hidden Panda Antivirus Pro (HKLM-x32\...\Panda Universal Agent Endpoint) (Version: 17.00.01.0000 - Panda Security) Panda Devices Agent (HKLM-x32\...\{3F9548B2-0B34-4453-A92E-35056B053F19}) (Version: 1.08.00 - Panda Security) Hidden Panda Devices Agent (HKLM-x32\...\Panda Devices Agent) (Version: 1.03.08 - Panda Security) Hidden Panda Safe Web (HKLM-x32\...\pandasecuritytb) (Version: 4.3.1.20 - Panda Security and Visicom Media Inc.) PCSX2 - Playstation 2 Emulator (HKLM-x32\...\pcsx2) (Version: - ) PhraseExpress v12.0.137 (HKLM-x32\...\PhraseExpress_is1) (Version: 12.0.137 - Bartels Media GmbH) Process Hacker 2.39 (r124) (HKLM\...\Process_Hacker2_is1) (Version: 2.39.0.124 - wj32) Psychonauts (HKLM\...\Steam App 3830) (Version: - Double Fine Productions) Python 2.7.13 (64-bit) (HKLM\...\{4A656C6C-D24A-473F-9747-3A8D00907A04}) (Version: 2.7.13150 - Python Software Foundation) Qcma (HKLM\...\Qcma) (Version: 0.3.13 - codestation) Qualcomm Atheros Driver Installation Program (HKLM-x32\...\{C3A32068-8AB1-4327-BB16-BED9C6219DC7}) (Version: 10.0 - Qualcomm Atheros) Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.14393.29093 - Realtek Semiconductor Corp.) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.2.612.2012 - Realtek) Realtek PC Camera (HKLM-x32\...\{E0A7ED39-8CD6-4351-93C3-69CCA00D12B4}) (Version: 6.2.8400.10189 - Realtek Semiconductor Corp.) Realtek PCIE Card Reader (HKLM-x32\...\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.1.8400.29025 - Realtek Semiconductor Corp.) Samsung SideSync (HKLM-x32\...\Samsung SideSync) (Version: 4.7.5.181 - Samsung Electronics Co., Ltd.) Samsung USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.63.0 - Samsung Electronics Co., Ltd.) SimCity 2000 Special Edition (HKLM-x32\...\{59D2C751-F7BE-4E9F-9C8C-1F16013802C7}) (Version: 2.0.0.1 - Electronic Arts) Smart Switch (HKLM-x32\...\{74FA5314-85C8-4E2A-907D-D9ECCCB770A7}) (Version: 4.1.17022.20 - Samsung Electronics Co., Ltd.) Hidden Smart Switch (HKLM-x32\...\InstallShield_{74FA5314-85C8-4E2A-907D-D9ECCCB770A7}) (Version: 4.1.17022.20 - Samsung Electronics Co., Ltd.) Soda PDF Desktop (HKLM-x32\...\SodaDesktop) (Version: 9.1.17.32870 - LULU Software) Soda PDF Desktop Asian Fonts Pack (HKLM\...\{CBFF9D21-FBBB-48D7-9F84-C24370992AA4}) (Version: 9.2.12.34356 - LULU Software) Hidden Soda PDF Desktop Convert Module (HKLM\...\{8FC1C3BD-A694-4E9E-B51F-207BCD6A2133}) (Version: 9.2.12.34356 - LULU Software) Hidden Soda PDF Desktop Create Module (HKLM\...\{83A67DAD-E51A-4A3A-AD6A-49A5853F6D9A}) (Version: 9.2.12.34356 - LULU Software) Hidden Soda PDF Desktop Edit Module (HKLM\...\{1F974010-6C8B-42B6-A669-B0A696FAFB29}) (Version: 9.2.12.34356 - LULU Software) Hidden Soda PDF Desktop Forms Module (HKLM\...\{981FAAEC-D9AB-475A-985D-EF74A046A372}) (Version: 9.2.12.34356 - LULU Software) Hidden Soda PDF Desktop Insert Module (HKLM\...\{511A21D3-BB6E-4336-80C8-E63CDF6A307C}) (Version: 9.2.12.34356 - LULU Software) Hidden Soda PDF Desktop OCR Module (HKLM\...\{438CF57D-B860-4A6F-95ED-7B6FD267040D}) (Version: 9.2.12.34356 - LULU Software) Hidden Soda PDF Desktop Review Module (HKLM\...\{1368EEAD-7B14-47E1-BF26-4CD49C5B7BCF}) (Version: 9.2.12.34356 - LULU Software) Hidden Soda PDF Desktop Secure Module (HKLM\...\{B094A0C4-2225-4F9C-A3D6-50700AAFCA80}) (Version: 9.2.12.34356 - LULU Software) Hidden Soda PDF Desktop View Module (HKLM\...\{165B875F-9B74-4434-97F9-1FCB926504F8}) (Version: 9.2.12.34356 - LULU Software) Hidden SoftMaker FreeOffice 2016 (HKLM-x32\...\{8EBB8452-274B-465D-8324-00B0832FBB05}) (Version: 1.0.3815 - SoftMaker Software GmbH) Sound Forge Audio Studio 10.0 (HKLM-x32\...\{10255740-2BBF-11E7-BEA5-91D6B83C4E18}) (Version: 10.0.319 - MAGIX) Spotify (HKU\S-1-5-21-2082031664-807437708-106104952-1002\...\Spotify) (Version: 1.0.54.1079.g3809528e - Spotify AB) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) Sublime Text Build 3114 (HKLM\...\Sublime Text 3_is1) (Version: - Sublime HQ Pty Ltd) SumatraPDF (HKLM\...\SumatraPDF) (Version: 3.1.2 - Krzysztof Kowalczyk) swMSM (HKLM-x32\...\{612C34C7-5E90-47D8-9B5C-0F717DD82726}) (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 19.0.12.98 - Synaptics Incorporated) TeamViewer 12 (HKLM-x32\...\TeamViewer) (Version: 12.0.83369 - TeamViewer) Tenable Nessus (x64) (HKLM\...\{C907E3FA-B1E2-4549-BDBF-059B94FE84BB}) (Version: 6.10.6.20091 - Tenable Network Security, Inc.) TeraCopy version 3.1 (HKLM\...\TeraCopy_is1) (Version: 3.1 - Code Sector) The Binding of Isaac: Rebirth (HKLM\...\Steam App 250900) (Version: - Nicalis, Inc.) The Walking Dead (HKLM\...\Steam App 207610) (Version: - Telltale Games) Tixati (HKLM-x32\...\tixati) (Version: - ) TuxGuitar (HKLM-x32\...\TuxGuitar 1.4) (Version: 1.4 - TuxGuitar) Unlocker 1.9.2 (HKLM\...\Unlocker) (Version: 1.9.2 - Cedrick Collomb) Validity WBF DDK (HKLM\...\{1F91C200-8F0F-4009-A75E-DB6CE151BD4E}) (Version: 4.4.234.0 - Validity Sensors, Inc.) Vita Concert Grand LE (HKLM\...\{172973DF-3972-43CB-9D6D-984C1AE79364}) (Version: 2.4.0.95 - MAGIX Software GmbH) Hidden VLC media player (HKLM\...\VLC media player) (Version: 3.0.0-git - VideoLAN) WebCamViewer 1.0.6258.7039 (HKLM-x32\...\WebCamViewer) (Version: 1.0.6258.7039 - ) Windows 10 Update and Privacy Settings (HKLM\...\{293F2009-0145-450B-B4AA-063D43FB368C}) (Version: 1.0.13.0 - Microsoft Corporation) Windows 7 USB/DVD Download Tool (HKLM-x32\...\{CCF298AF-9CE1-4B26-B251-486E98A34789}) (Version: 1.0.30 - Microsoft Corporation) Windows Driver Package - Advanced Micro Devices (AtiHDAudioService) MEDIA (07/26/2016 9.0.0.9910) (HKLM\...\52CF107E7D2BCC320ADE14A51479DD758FAECD98) (Version: 07/26/2016 9.0.0.9910 - Advanced Micro Devices) Windows Driver Package - AMD (amdkmafd) System (08/15/2016 16.40.0.0000) (HKLM\...\CAC7BB461C69F6A312C90B1B8BCE0FBD1EF8141A) (Version: 08/15/2016 16.40.0.0000 - AMD) Windows Driver Package - BigNox Corporation (VBoxUSB) USB (09/16/2015 4.3.12) (HKLM\...\76B144D15273552931249392EDB13C0BBD52C84E) (Version: 09/16/2015 4.3.12 - BigNox Corporation) Windows Driver Package - BigNox Corporation VBoxUSBMon System (09/16/2015 4.3.12) (HKLM\...\39F54A37125643D2E1E90FA7D81F36ACC9441510) (Version: 09/16/2015 4.3.12 - BigNox Corporation) Windows Driver Package - BigNox Corporation XQHDrv System (09/16/2015 4.3.12) (HKLM\...\0147813640F7AF69F569581EE672B6BE1E71798E) (Version: 09/16/2015 4.3.12 - BigNox Corporation) Windows Driver Package - Compal Electronics, INC. (LPCFilter) System (07/09/2015 1.0.64.8) (HKLM\...\842031008B16B0F5F6589CACF189217BC15111A0) (Version: 07/09/2015 1.0.64.8 - Compal Electronics, INC.) Windows Driver Package - Hewlett-Packard Development Company, L.P. (HpqKbFiltr) Keyboard (04/25/2014 7.0.13.1) (HKLM\...\76B58A5F2A5BDE0C3DB4CE26DF62D5358942BAAB) (Version: 04/25/2014 7.0.13.1 - Hewlett-Packard Development Company, L.P.) Windows Driver Package - Hewlett-Packard Development Company, L.P. HP Mobile Data Protection Sensor (08/16/2012 4.2.8.1) (HKLM\...\373FF7A2AB9CC1F568F3DB5D3EF1CD12FA3ECE2D) (Version: 08/16/2012 4.2.8.1 - Hewlett-Packard Development Company, L.P.) Windows Driver Package - HP (WirelessButtonDriver64) HIDClass (04/11/2016 1.1.17.1) (HKLM\...\372A51DF092FB48F03BB545F022B1B6E6AD65A5D) (Version: 04/11/2016 1.1.17.1 - HP) Windows Driver Package - IDT (STHDA) MEDIA (12/05/2013 6.10.6498.0) (HKLM\...\A67075A423A287A24D0814A22BE11224E84E29FB) (Version: 12/05/2013 6.10.6498.0 - IDT) Windows Driver Package - libusbK PS Vita Type B (04/27/2014 3.0.7.0) (HKLM\...\A4993408B35BE65CEBE1D6DFDE92F1262C6D9134) (Version: 04/27/2014 3.0.7.0 - libusbK) Windows Driver Package - Logitech (LEqdUsb) HIDClass (06/09/2015 5.90.38) (HKLM\...\3D88081D327A12E9348E1EADDE35513319822FE0) (Version: 06/09/2015 5.90.38 - Logitech) Windows Driver Package - Logitech (LHidFilt) Keyboard (06/09/2015 5.90.38) (HKLM\...\ECB9A872456DA502A6B195D7AEEF6FEB7355ECB6) (Version: 06/09/2015 5.90.38 - Logitech) Windows Driver Package - Logitech (LHidFilt) Mouse (06/09/2015 5.90.38) (HKLM\...\3A23CE434CCC10D23CD098DBBFD5A4C5D855E356) (Version: 06/09/2015 5.90.38 - Logitech) Windows Driver Package - Logitech (usbccgp) USB (11/04/2010 1.0.2.11) (HKLM\...\8A87028F68EFC3B6D4F26F7EF2DDB31C8F6767EF) (Version: 11/04/2010 1.0.2.11 - Logitech) Windows Driver Package - Microsoft Battery (11/13/2015 1.2.0.2) (HKLM\...\D94A6ADF78DC5F14DEE64147DCDF230ED63FD734) (Version: 11/13/2015 1.2.0.2 - Microsoft) Windows Driver Package - Qualcomm Atheros Communications Inc. (athr) Net (08/16/2016 10.0.0.345) (HKLM\...\31077EE1027642EAD54D8B7AA8B67C5C9A25A15F) (Version: 08/16/2016 10.0.0.345 - Qualcomm Atheros Communications Inc.) Windows Driver Package - Realtek (rt640x64) Net (07/14/2016 10.010.0714.2016) (HKLM\...\A0F2F1AF5B44FBF0075F603FD6284C940350A95C) (Version: 07/14/2016 10.010.0714.2016 - Realtek) Windows Driver Package - Realtek (rtsuvc) Image (09/28/2012 6.2.8400.10189) (HKLM\...\E698172B3456957E5EA39096880F341504FB40D1) (Version: 09/28/2012 6.2.8400.10189 - Realtek) Windows Driver Package - Realtek Semiconductor Corp. (RSP2STOR) MTD (09/02/2016 10.0.14393.29093) (HKLM\...\5AE4A5ED2354BC5E0C463B1F3E8DE1DCBDFCBB23) (Version: 09/02/2016 10.0.14393.29093 - Realtek Semiconductor Corp.) Windows Driver Package - Screenovate Technologies Ltd. (WidockVhid) Screenovate (02/29/2016 5.0.0.501) (HKLM\...\2DF704FFC8BE30DEDE37DC61848EFD4166CF26E9) (Version: 02/29/2016 5.0.0.501 - Screenovate Technologies Ltd.) Windows Driver Package - Synaptics (SmbDrv) System (08/25/2016 19.2.4.10) (HKLM\...\7DDCFF7E96357D63DF7030FFC3FF5E06981D159C) (Version: 08/25/2016 19.2.4.10 - Synaptics) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation) Windscribe version 1.70 build 4 (HKLM-x32\...\{fa690e90-ddb0-4f0c-b3f1-136c084e5fc7}_is1) (Version: 1.70 build 4 - Windscribe) WinHTTrack Website Copier 3.49-2 (x64) (HKLM\...\WinHTTrack Website Copier_is1) (Version: 3.49.2 - HTTrack) WinPcap 4.1.3 (HKLM-x32\...\WinPcapInst) (Version: 4.1.0.2980 - Riverbed Technology, Inc.) WinToUSB version 3.5 (HKLM\...\WinToUSB_is1) (Version: 3.5 - The EasyUEFI Development Team.) Zemana AntiMalware (HKLM-x32\...\{8F0CD7D1-42F3-4195-95CD-833578D45057}_is1) (Version: 2.74.0.150 - Zemana Ltd.) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{00020420-0000-0000-C000-000000000046}\InprocServer32 -> C:\WINDOWS\system32\oleaut32.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{00020421-0000-0000-C000-000000000046}\InprocServer32 -> C:\WINDOWS\system32\oleaut32.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{00020422-0000-0000-C000-000000000046}\InprocServer32 -> C:\WINDOWS\system32\oleaut32.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{00020423-0000-0000-C000-000000000046}\InprocServer32 -> C:\WINDOWS\system32\oleaut32.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{00020424-0000-0000-C000-000000000046}\InprocServer32 -> C:\WINDOWS\system32\oleaut32.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{00020425-0000-0000-C000-000000000046}\InprocServer32 -> C:\WINDOWS\system32\oleaut32.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{0045B4D9-BA8C-3069-8559-866EFAAC2E41}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{03FD2EFF-E668-3B9B-8116-EBC8BE84C99B}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{07E2883A-7DD3-354F-A731-B91320F64F09}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{0FCEC664-F780-3AF4-AF67-55F906234790}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{11A1A093-EF58-3778-8BF2-A51259BED415}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{12877337-5FC2-3BC7-935B-681516BB6314}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{1FC22A66-FE7F-35A6-9388-00BCA9D73EA3}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{20DE22E0-135C-333A-ADFF-7DCC932CC253}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{26D9CC59-FFE5-36F2-919F-D5BEDABB71A8}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{287C39FC-2B1C-3076-936F-C2B0BD08D70E}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{2D1482DE-1144-3129-8A4E-2EBF1E0C3CD1}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{2D3DC66B-1614-39EF-AE06-30A32BC2DC87}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{2FFDF364-EF38-3916-9CDB-3E2DE5AC7DC3}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{300216E5-D02D-3B66-BD6D-3BE785ADB217}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{31F7619D-F1EF-30A5-BF69-8854E4FB067E}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{321D4458-053A-3E6A-BAFA-C1F789C4153D}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{3D617CE6-C7CF-4B1D-86B4-BF8C8C530210}\InprocServer32 -> C:\Users\Joshua\AppData\Roaming\Add-in Express\Ultimate Suite for Microsoft Excel\adxloader64.dll () CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{3DC8D899-5909-34E2-8A76-13E718968495}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{43BA05C6-983D-3935-8E0D-0FFD96A26BE4}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{488E398F-7846-3D35-B4ED-1C4DC5D67AA8}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{4F02CEAC-0647-3A4F-BEFA-C6B150A480F7}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{4FC22687-8B8F-322B-9B46-1F577D781EA1}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{51177181-08ED-3D2C-B38E-2394C70160AA}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{54ACD037-3855-3542-BBB9-A8965D7303EC}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{56A936DE-8A07-32F5-BB00-E19FF7131FF3}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{5715FBBA-BC61-3D39-BBD7-52B76F03313C}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{5823CA10-6302-33FB-83F7-F1B6328C192F}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{590C4387-5EBD-4D46-8A84-CD0BA2EF2856}\InprocServer32 -> C:\Users\Joshua\AppData\Local\Google\Update\1.3.30.3\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{59B55F04-DE14-4BB8-92FF-C4A22EF2E5F4}\InprocServer32 -> C:\Users\Joshua\AppData\Local\Google\Update\1.3.31.5\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{5ADCB1B8-27E4-3E19-BB1F-CBB1B0550D7F}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{5BFAB51E-41AD-3D59-BF5A-91BEF3B4E4C4}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{625CBB1D-2D57-34D8-939B-2275C0988447}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{63BDDF6C-C557-3096-B598-3037A19C4FE3}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{6599765C-9878-3CF0-80C6-D2D138390AE5}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{67038E65-0574-3CC6-94C0-58638350873A}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{6A80A88B-8001-3015-AE16-2A5F29AC87B0}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{6BE0C6A4-2E70-341A-AD1B-795CFA32135F}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{6FD58A90-A24C-38A2-A23F-FE56D71FD92D}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{7254EF86-4DB6-34DF-B306-7F8047079464}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{79280FD0-7017-3F54-9844-1073B710C63D}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{793EE463-1304-471C-ADF1-68C2FFB01247}\InprocServer32 -> C:\Users\Joshua\AppData\Local\Google\Update\1.3.29.5\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{7AC6AF8A-B2E0-31BA-B859-4FB2E66ECFCC}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{7C12DF8F-DA41-33E2-84E1-294661D3A7E6}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{81705503-007F-3CA8-BB65-579B86791E69}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{8670DE5A-CF8D-3BCA-A913-983BF9CB4971}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{88C7C9D0-9FE0-3EC8-85AA-2BC76F6597E7}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{8C46158B-D978-483C-A312-16EE5013BE04}\InprocServer32 -> C:\Users\Joshua\AppData\Local\Google\Update\1.3.33.3\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{900363DB-A42F-3E75-A921-74ED66763760}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{9C6FA6EC-6F73-348D-BC74-A09F7C94F7AC}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{A7438874-7DA0-326B-96C0-63C449862C18}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{A93BAA34-0843-3DE3-9F5A-FF249E41C885}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{A9AE6EB5-DFF4-3988-9500-453775F5B3E2}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{AFB6E014-63BA-35F6-B11D-395F5FB71D1F}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{B0474813-C7CA-365C-8E96-002D9AE85937}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{B4806774-0413-33D2-BA4D-E963C3B3EBA9}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{B8F9AA9C-776E-3F96-A693-151F9BD803B0}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{BAAFD54E-3E00-37C0-9A86-A6482A732769}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{BDCCF4A5-DFC1-3F84-AB98-651F6D77F159}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{BE6C206B-6AD0-33D4-A408-35B9EFE262E6}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{BE71CB61-AD24-30EB-9945-0F9EB76EF53C}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{C496C6DC-4063-3053-818A-6B944CB796C1}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{C6614F8B-EEBA-383D-8E01-D930D3C98650}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{C6767C2E-5B93-3563-8B4E-D5AA281DECA1}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{C73A9005-C966-34C2-95A7-5DBF43E18572}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{CA027201-87F5-3F1F-B5D6-7A24C1E30A9D}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{CB492AF1-2CEF-4E58-BE47-471C77D0C8BA}\InprocServer32 -> C:\Users\Joshua\AppData\Local\Google\Update\1.3.32.7\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{CC66D6CF-4B79-38C7-8D00-F00A758BEDEA}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{D1DDAEC2-A75B-3E15-AE90-4743065AC9D3}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{D59753C8-4694-3FDF-A243-4F1A81B98537}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{D63AE62B-67CD-31B4-9C39-2326F05FB4F8}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{D88F7D12-10D2-3C5D-96E2-06CCB6530134}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{D8EF93AE-8D53-31BC-8FF5-A25A2B4C4E6A}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{D93BFA3C-F751-31A7-829C-9D61A97AD5C3}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{D97EF3DF-48DF-3BF6-9E67-8A02F1542179}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{DAF07FB7-5F64-35A9-8040-47B5ACA24E03}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{DBE95724-C5BD-31F0-BEA4-F871CE7EBE09}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{DFC09CFC-05C7-3032-9033-FA9C3B5D4EE9}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{E1D71666-5D26-32D6-B552-C11AB4C7A0C4}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{E2DCF7AF-22C1-3B6E-BAD7-77A858AFE1D9}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{E3F6F520-9CF0-39B6-A4AA-C7CE23385DD2}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{E6AC0222-1899-3EBA-A0F6-C680DD21F749}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{E962C5AF-7877-3EFA-89DF-E5FEEC1E0862}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{EDBA4B67-A29D-342F-8E45-26A74F758AF4}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{F024FA55-9770-32A7-AADA-52B73794E898}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{F2D6B43E-6C7E-3318-9CAA-F1D5BB747F17}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{F62A453E-6CCB-34F3-A32A-357D9575BBE8}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{F948488C-EEA6-3FA1-A188-3C5FF02F646D}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{F9618249-0285-32D0-BA62-0EEE7E97333E}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{F9E5A74D-8E71-37D3-BECE-9169C49DF54E}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{FAD484FA-DEE7-346D-8FF9-AEBCA34660BE}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{FCA5262F-51F3-3BA6-B3E4-92C5839EF36B}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2082031664-807437708-106104952-1002_Classes\CLSID\{FE490DC0-ECB2-30F3-B1E3-8EF12DEA835B}\InprocServer32 -> C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) ShellIconOverlayIdentifiers: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.18.0.dll [2017-09-20] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.18.0.dll [2017-09-20] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.18.0.dll [2017-09-20] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.18.0.dll [2017-09-20] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.18.0.dll [2017-09-20] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.18.0.dll [2017-09-20] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.18.0.dll [2017-09-20] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.18.0.dll [2017-09-20] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.18.0.dll [2017-09-20] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.18.0.dll [2017-09-20] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2017-08-31] (Google) ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2017-08-31] (Google) ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2017-08-31] (Google) ShellIconOverlayIdentifiers-x32: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.18.0.dll [2017-09-20] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.18.0.dll [2017-09-20] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.18.0.dll [2017-09-20] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.18.0.dll [2017-09-20] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.18.0.dll [2017-09-20] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.18.0.dll [2017-09-20] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.18.0.dll [2017-09-20] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.18.0.dll [2017-09-20] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.18.0.dll [2017-09-20] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.18.0.dll [2017-09-20] (Dropbox, Inc.) ContextMenuHandlers1: [2.0 Zemana AntiMalware] -> {6ABB1C11-E261-4CEA-BBB5-3836225689DD} => C:\Program Files (x86)\Zemana AntiMalware\ZAMShellExt64.dll [2017-09-21] () ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov) ContextMenuHandlers1: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} => C:\Program Files (x86)\Common Files\CyberLink\ShellExtComponent\CLVDShellExt.dll [2012-07-27] (Cyberlink) ContextMenuHandlers1: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.18.0.dll [2017-09-20] (Dropbox, Inc.) ContextMenuHandlers1: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files (x86)\Google\Drive\contextmenu64.dll [2017-08-31] (Google) ContextMenuHandlers1: [Mp3tagShell] -> {6351E20C-35FA-4BE3-98FB-4CABF1363E12} => C:\Program Files (x86)\Mp3tag\Mp3tagShell64.dll [2016-11-25] (Florian Heidenreich) ContextMenuHandlers1: [SodaPDFDesktop_ManagerExt] -> {526A2ADD-BD9B-40E5-9D45-75EF6313FCE4} => C:\Program Files\Soda PDF Desktop\context-menu.dll [2017-08-02] (LULU Software) ContextMenuHandlers1: [TeraCopy] -> {A8005AF0-D6E8-48AF-8DFA-023B1CF660A7} => C:\Program Files\TeraCopy\TeraCopyExt.dll [2016-12-07] () ContextMenuHandlers1: [UAContextMenu] -> {A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} => C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAShell.dll [2016-08-04] (Panda Security, S.L.) ContextMenuHandlers2: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} => C:\Program Files (x86)\Common Files\CyberLink\ShellExtComponent\CLVDShellExt.dll [2012-07-27] (Cyberlink) ContextMenuHandlers2: [Mp3tagShell] -> {6351E20C-35FA-4BE3-98FB-4CABF1363E12} => C:\Program Files (x86)\Mp3tag\Mp3tagShell64.dll [2016-11-25] (Florian Heidenreich) ContextMenuHandlers2: [TeraCopy] -> {A8005AF0-D6E8-48AF-8DFA-023B1CF660A7} => C:\Program Files\TeraCopy\TeraCopyExt.dll [2016-12-07] () ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-08-30] (Malwarebytes) ContextMenuHandlers3: [UnlockerShellExtension] -> {DDE4BEEB-DDE6-48fd-8EB5-035C09923F83} => C:\Program Files\Unlocker\UnlockerCOM.dll [2010-07-15] () ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov) ContextMenuHandlers4: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.18.0.dll [2017-09-20] (Dropbox, Inc.) ContextMenuHandlers4: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files (x86)\Google\Drive\contextmenu64.dll [2017-08-31] (Google) ContextMenuHandlers4: [Mp3tagShell] -> {6351E20C-35FA-4BE3-98FB-4CABF1363E12} => C:\Program Files (x86)\Mp3tag\Mp3tagShell64.dll [2016-11-25] (Florian Heidenreich) ContextMenuHandlers4: [TeraCopy] -> {A8005AF0-D6E8-48AF-8DFA-023B1CF660A7} => C:\Program Files\TeraCopy\TeraCopyExt.dll [2016-12-07] () ContextMenuHandlers5: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.18.0.dll [2017-09-20] (Dropbox, Inc.) ContextMenuHandlers5: [UAContextMenu] -> {A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} => C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAShell.dll [2016-08-04] (Panda Security, S.L.) ContextMenuHandlers6: [2.0 Zemana AntiMalware] -> {6ABB1C11-E261-4CEA-BBB5-3836225689DD} => C:\Program Files (x86)\Zemana AntiMalware\ZAMShellExt64.dll [2017-09-21] () ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov) ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-08-30] (Malwarebytes) ContextMenuHandlers6: [TeraCopy] -> {A8005AF0-D6E8-48AF-8DFA-023B1CF660A7} => C:\Program Files\TeraCopy\TeraCopyExt.dll [2016-12-07] () ContextMenuHandlers6: [UAContextMenu] -> {A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} => C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAShell.dll [2016-08-04] (Panda Security, S.L.) ContextMenuHandlers6: [UnlockerShellExtension] -> {DDE4BEEB-DDE6-48fd-8EB5-035C09923F83} => C:\Program Files\Unlocker\UnlockerCOM.dll [2010-07-15] () ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {0C0093CE-6E30-4F9F-8773-3909E3941A06} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2017-09-22] () Task: {10AAB0B8-8053-4415-B0BB-07355ECBAB43} - \Optimize Start Menu Cache Files-S-1-5-21-2082031664-807437708-106104952-1002 -> No File <==== ATTENTION Task: {207FA1FA-DF26-4543-948D-A890F04A78A1} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-09-08] (Microsoft Corporation) Task: {21807721-3FE4-418A-A69E-267D302A2D64} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2012-08-07] (Hewlett-Packard Company) Task: {227C3567-7D70-4A56-BB81-C255A763C8F6} - System32\Tasks\{55D1E5D4-EECD-4656-9213-F5489302A408} => C:\WINDOWS\system32\pcalua.exe -a "C:\Program Files (x86)\Lionhead Studios Ltd\Black & White\runblack.exe" -d "C:\Program Files (x86)\Lionhead Studios Ltd\Black & White" Task: {235842F3-9551-46D7-BBD7-59A70D3F3E5F} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-08-10] (Hewlett-Packard Company) Task: {32A5F5BF-C25D-4B47-89C1-3C6F2FB289D1} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [2017-09-22] (Microsoft Corporation) Task: {3ADC8A78-272E-4603-8217-07B1961B3104} - System32\Tasks\CLMLSvc_P2G8 => C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [2012-06-07] (CyberLink) Task: {3E4D7809-EA5E-4915-AAE9-420EAA690FD5} - System32\Tasks\Desktopcleaner => C:\Program Files (x86)\Desktop Cleaner\\dcservice.exe Task: {439E4808-DBE1-48C5-8A48-C88E593404CF} - no filepath Task: {46233DD6-E835-45CE-8149-38F6E4BCC9D4} - no filepath Task: {472081FC-2DAC-4C34-AE62-8E18E4B2AF84} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2017-09-22] () Task: {5331585B-02C2-49D7-9E89-1C4393D2F580} - System32\Tasks\Connect => C:\Program Files (x86)\MAGIX\Connect\connect.exe [2017-05-10] (MAGIX Software GmbH) Task: {5D9F550A-A85C-4EE5-AFE1-31DBCE933562} - System32\Tasks\Cybereason RansomFree Keepalive => C:\Program Files (x86)\Cybereason\RansomFree\CybereasonRansomFree.exe [2017-08-07] (Cybereason) Task: {5DE97767-0536-4599-91CF-542195972C57} - System32\Tasks\Norton Internet Security\Norton Error Analyzer => C:\Program Files (x86)\Norton Internet Security\Engine\20.0.0.136\SymErr.exe Task: {60828546-5278-4EEE-9885-BFB500AF2EC6} - System32\Tasks\Cybereason RansomFree Autostart => C:\Program Files (x86)\Cybereason\RansomFree\CybereasonRansomFree.exe [2017-08-07] (Cybereason) Task: {798F1D67-C137-4C2D-A063-096C2955D370} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-06-18] (Dropbox, Inc.) Task: {8187D504-778E-4C56-B685-F3C9606E9013} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-09-08] (Microsoft Corporation) Task: {97A35A0F-710A-493A-B4E2-4BA4AEAF07E4} - no filepath Task: {9D67414F-B623-4A93-BCC9-E1C9013240D5} - System32\Tasks\Norton Internet Security\Norton Error Processor => C:\Program Files (x86)\Norton Internet Security\Engine\20.0.0.136\SymErr.exe Task: {A2F01371-0674-40FB-87C3-C8765885F88A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-02-28] (Google Inc.) Task: {A6684573-A583-42B6-9A3B-1A51B6A68B62} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-02-28] (Google Inc.) Task: {C5F605D0-44E1-42D8-906C-52641B09B51B} - System32\Tasks\MirageAgent => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [2012-07-27] (CyberLink) Task: {D0EA334A-B67C-4A54-A57A-600635E936DF} - no filepath Task: {D58C7644-87EE-4BE2-BE0E-DE8EC499B6AD} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-06-18] (Dropbox, Inc.) Task: {E5147A8E-6BD8-4A04-BB84-1467BCEB42C9} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [2017-09-22] (Microsoft Corporation) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\Connect.job => C:\Program Files (x86)\MAGIX\Connect\connect.exe Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Task: C:\WINDOWS\Tasks\Synaptics TouchPad Enhancements.job => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe ==================== Shortcuts & WMI ======================== (The entries could be listed to be restored or removed.) ShortcutWithArgument: C:\Users\Joshua\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Floating for YouTube™.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=jjphmlaoffndcnecccgemfdaaoighkel ShortcutWithArgument: C:\Users\Joshua\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Super Nintendo Emulator (snes9x).lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=ckpjobcmemfpfeaeolhhjkjdpfnkngnd ==================== Loaded Modules (Whitelisted) ============== 2012-08-08 13:36 - 2012-08-08 13:36 - 000073728 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.Wlan.dll 2017-03-18 16:58 - 2017-03-18 16:58 - 000138000 _____ () C:\WINDOWS\SYSTEM32\inputhost.dll 2010-07-15 00:44 - 2010-07-15 00:44 - 000020032 _____ () C:\Program Files\Unlocker\UnlockerCOM.dll 2016-06-18 14:50 - 2016-12-07 15:40 - 003681104 _____ () C:\Program Files\TeraCopy\TeraCopyExt.dll 2017-09-21 20:08 - 2017-09-21 20:08 - 000155504 _____ () C:\Program Files (x86)\Zemana AntiMalware\ZAMShellExt64.dll 2017-03-18 16:59 - 2017-03-18 22:31 - 001731072 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2017-09-24 09:35 - 2017-09-24 09:35 - 000346624 _____ () \\?\C:\Users\Joshua\AppData\Local\Temp\7898deb7-f01d-41fc-9bbd-5f60dc3bfdf8.tmp.node 2017-09-24 09:35 - 2017-09-24 09:35 - 000177152 _____ () \\?\C:\Users\Joshua\AppData\Local\Temp\fb7937cd-d88c-46dc-8af6-62c260d0d31e.tmp.node 2017-09-24 09:36 - 2017-09-24 09:36 - 000105984 _____ () \\?\C:\Users\Joshua\AppData\Local\Temp\7eb21cdd-dc67-496f-a5ec-dad413ab06cd.tmp.node 2017-09-24 09:36 - 2017-09-24 09:36 - 000521728 _____ () \\?\C:\Users\Joshua\AppData\Local\Temp\25c3dbd8-a06f-4ad0-b65b-04c1c394ef2a.tmp.node 2017-06-26 19:40 - 2017-09-22 22:31 - 008929480 _____ () C:\Program Files\Microsoft Office\root\Office16\1033\GrooveIntlResource.dll 2017-09-20 16:17 - 2017-09-20 16:18 - 003935040 _____ () C:\Users\Joshua\AppData\Local\brave\app-0.18.36\libglesv2.dll 2017-09-20 16:17 - 2017-09-20 16:17 - 000096064 _____ () C:\Users\Joshua\AppData\Local\brave\app-0.18.36\libegl.dll 2017-08-29 21:07 - 2017-08-29 21:08 - 000074752 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.19.856.0_x64__kzf8qxf38zg5c\SkypeHost.exe 2017-08-29 21:07 - 2017-08-29 21:08 - 000203264 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.19.856.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll 2017-08-29 21:07 - 2017-08-29 21:08 - 036162048 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.19.856.0_x64__kzf8qxf38zg5c\SkyWrap.dll 2017-08-29 21:07 - 2017-08-29 21:08 - 002237952 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.19.856.0_x64__kzf8qxf38zg5c\skypert.dll 2017-09-20 10:04 - 2017-09-20 10:04 - 000914944 ____N () C:\Users\Joshua\AppData\Local\nvnkdes\nvnkdes.exe 2017-08-20 12:38 - 2017-08-20 12:38 - 001087488 _____ () C:\Users\Joshua\AppData\Local\nvnkdes\scbglnu.exe 2017-08-28 15:08 - 2017-08-23 04:48 - 003824472 _____ () C:\Program Files (x86)\Google\Chrome\Application\60.0.3112.113\libglesv2.dll 2017-08-28 15:08 - 2017-08-23 04:48 - 000100184 _____ () C:\Program Files (x86)\Google\Chrome\Application\60.0.3112.113\libegl.dll 2016-07-25 21:23 - 2016-10-25 18:03 - 004125696 _____ () C:\Program Files\FossaMail\mozjs.dll 2016-07-25 21:23 - 2016-10-25 18:05 - 000219136 _____ () C:\Program Files\FossaMail\NSLDAP32V60.dll 2016-07-25 21:23 - 2016-10-25 18:05 - 000017920 _____ () C:\Program Files\FossaMail\NSLDAPPR32V60.dll 2016-07-25 21:59 - 2012-11-21 07:26 - 000010240 _____ () C:\Users\Joshua\AppData\Roaming\FossaMail\Profiles\9kp9z46k.default\extensions\[removed]\lib\tray_x86_64-msvc.dll 2017-09-01 15:20 - 2017-09-01 15:20 - 004345856 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1706.2271.0_x64__8wekyb3d8bbwe\Calculator.exe 2017-08-29 21:22 - 2017-08-29 21:22 - 003553704 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1706.2271.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll 2017-09-20 16:37 - 2017-09-14 16:43 - 001208976 _____ () C:\Program Files\Microsoft VS Code\ffmpeg.dll 2017-09-20 16:38 - 2017-09-14 16:42 - 000129168 _____ () \\?\C:\Program Files\Microsoft VS Code\resources\app\node_modules\keytar\build\Release\keytar.node 2017-09-20 16:38 - 2017-09-14 16:42 - 000139920 _____ () \\?\C:\Program Files\Microsoft VS Code\resources\app\node_modules\native-keymap\build\Release\keymapping.node 2017-09-20 16:37 - 2017-09-14 16:48 - 003957392 _____ () C:\Program Files\Microsoft VS Code\libglesv2.dll 2017-09-20 16:37 - 2017-09-14 16:48 - 000109712 _____ () C:\Program Files\Microsoft VS Code\libegl.dll 2017-09-20 16:38 - 2017-09-14 16:42 - 000139920 _____ () \\?\C:\Program Files\Microsoft VS Code\resources\app\node_modules\gc-signals\build\Release\gcsignals.node 2017-09-20 16:38 - 2017-09-14 16:42 - 000106128 _____ () \\?\c:\Program Files\Microsoft VS Code\resources\app\node_modules\native-watchdog\build\Release\watchdog.node 2016-06-22 13:03 - 2012-12-09 00:03 - 001763328 _____ () C:\Program Files (x86)\NexusFile\NexusFile.exe 2017-05-14 08:35 - 2011-12-05 16:27 - 000158536 _____ () C:\WINDOWS\System32\SRSLabs\{176F4E15-8F7C-4833-ADED-81FAE8CCD186}\slcc3d64.dll 2014-04-07 18:41 - 2012-06-07 23:34 - 000627216 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMediaLibrary.dll 2012-06-08 14:34 - 2012-06-08 14:34 - 000016400 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvcPS.dll 2017-08-24 16:24 - 2017-08-24 16:24 - 000007168 _____ () C:\MUSHclient\lua5.1.dll 2017-08-24 16:24 - 2017-08-24 16:24 - 000364544 _____ () C:\MUSHclient\lua51.DLL 2017-08-24 16:24 - 2017-08-24 16:24 - 001470464 _____ () C:\MUSHclient\locale\EN.dll 2017-08-24 16:24 - 2017-08-24 16:24 - 000013312 _____ () C:\MUSHclient\llthreads.dll 2017-08-24 16:24 - 2017-08-24 16:24 - 000032768 _____ () C:\MUSHclient\socket\core.dll 2017-08-24 16:24 - 2017-08-24 16:24 - 000024576 _____ () C:\MUSHclient\mime\core.dll 2017-08-24 16:24 - 2017-08-24 16:24 - 000182272 _____ () C:\MUSHclient\openssl.dll 2017-09-21 16:24 - 2017-09-20 12:48 - 000771904 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_watchdog.dll 2017-09-21 16:24 - 2017-09-20 12:48 - 001804608 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_crashpad.dll 2017-09-21 16:24 - 2017-09-20 12:49 - 000023872 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_bootstrap.dll 2017-09-15 13:25 - 2017-09-20 12:48 - 000100296 _____ () C:\Program Files (x86)\Dropbox\Client\_ctypes.pyd 2017-09-15 13:25 - 2017-09-20 12:48 - 000018888 _____ () C:\Program Files (x86)\Dropbox\Client\select.pyd 2017-09-15 13:25 - 2017-09-20 12:50 - 000020800 _____ () C:\Program Files (x86)\Dropbox\Client\tornado.speedups.pyd 2017-09-15 13:25 - 2017-09-20 12:48 - 000035792 _____ () C:\Program Files (x86)\Dropbox\Client\_multiprocessing.pyd 2017-09-21 16:24 - 2017-09-20 12:49 - 000021848 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._constant_time.pyd 2017-09-15 13:25 - 2017-09-20 12:48 - 000125904 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_backend.pyd 2017-09-15 13:25 - 2017-09-20 12:48 - 000694224 _____ () C:\Program Files (x86)\Dropbox\Client\unicodedata.pyd 2017-09-21 16:24 - 2017-09-20 12:49 - 001862992 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._openssl.pyd 2017-09-21 16:24 - 2017-09-20 12:49 - 000022864 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._padding.pyd 2017-09-21 16:24 - 2017-09-20 12:48 - 000145864 _____ () C:\Program Files (x86)\Dropbox\Client\pyexpat.pyd 2017-09-21 16:24 - 2017-09-20 12:48 - 000116688 _____ () C:\Program Files (x86)\Dropbox\Client\pywintypes27.dll 2017-09-15 13:25 - 2017-09-20 12:48 - 000105928 _____ () C:\Program Files (x86)\Dropbox\Client\win32api.pyd 2017-09-15 13:25 - 2017-09-20 12:50 - 000022864 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.crt.compiled._winffi_crt.pyd 2017-09-21 16:24 - 2017-09-20 12:49 - 000062784 _____ () C:\Program Files (x86)\Dropbox\Client\psutil._psutil_windows.pyd 2017-09-15 13:25 - 2017-09-20 12:48 - 000024528 _____ () C:\Program Files (x86)\Dropbox\Client\win32event.pyd 2017-09-21 16:24 - 2017-09-20 12:49 - 000040248 _____ () C:\Program Files (x86)\Dropbox\Client\fastpath.pyd 2017-09-21 16:24 - 2017-09-20 12:48 - 000020936 _____ () C:\Program Files (x86)\Dropbox\Client\mmapfile.pyd 2017-09-15 13:25 - 2017-09-20 12:48 - 000124880 _____ () C:\Program Files (x86)\Dropbox\Client\win32file.pyd 2017-09-15 13:25 - 2017-09-20 12:48 - 000116176 _____ () C:\Program Files (x86)\Dropbox\Client\win32security.pyd 2017-09-21 16:24 - 2017-09-20 12:48 - 000392656 _____ () C:\Program Files (x86)\Dropbox\Client\pythoncom27.dll 2017-09-15 13:25 - 2017-09-20 12:50 - 000392512 _____ () C:\Program Files (x86)\Dropbox\Client\win32com.shell.shell.pyd 2017-09-15 13:25 - 2017-09-20 12:50 - 000026456 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.kernel32.compiled._winffi_kernel32.pyd 2017-09-15 13:25 - 2017-09-20 12:48 - 000024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32clipboard.pyd 2017-09-15 13:25 - 2017-09-20 12:48 - 000175560 _____ () C:\Program Files (x86)\Dropbox\Client\win32gui.pyd 2017-09-15 13:25 - 2017-09-20 12:48 - 000030160 _____ () C:\Program Files (x86)\Dropbox\Client\win32pipe.pyd 2017-09-15 13:25 - 2017-09-20 12:48 - 000043472 _____ () C:\Program Files (x86)\Dropbox\Client\win32process.pyd 2017-09-21 16:24 - 2017-09-20 12:48 - 000026056 _____ () C:\Program Files (x86)\Dropbox\Client\win32job.pyd 2017-09-15 13:25 - 2017-09-20 12:48 - 000048592 _____ () C:\Program Files (x86)\Dropbox\Client\win32service.pyd 2017-09-15 13:25 - 2017-09-20 12:48 - 000057808 _____ () C:\Program Files (x86)\Dropbox\Client\win32evtlog.pyd 2017-09-21 16:24 - 2017-09-20 12:49 - 000022336 _____ () C:\Program Files (x86)\Dropbox\Client\cpuid.compiled._cpuid.pyd 2017-09-15 13:25 - 2017-09-20 12:50 - 000023368 _____ () C:\Program Files (x86)\Dropbox\Client\winshell.compiled._winshell.pyd 2017-09-21 16:24 - 2017-09-20 12:49 - 000023368 _____ () C:\Program Files (x86)\Dropbox\Client\crashpad.compiled._Crashpad.pyd 2017-09-15 13:25 - 2017-09-20 12:50 - 000082264 _____ () C:\Program Files (x86)\Dropbox\Client\winenumhandles.compiled._WinEnumHandles.pyd 2017-09-15 13:25 - 2017-09-20 12:50 - 000025432 _____ () C:\Program Files (x86)\Dropbox\Client\winscreenshot.compiled._CaptureScreenshot.pyd 2017-09-15 13:25 - 2017-09-20 12:48 - 000028616 _____ () C:\Program Files (x86)\Dropbox\Client\win32ts.pyd 2017-09-15 13:25 - 2017-09-20 12:48 - 000024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32profile.pyd 2017-09-21 16:24 - 2017-09-20 12:49 - 001796920 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtCore.pyd 2017-09-15 13:25 - 2017-09-20 12:48 - 000084424 _____ () C:\Program Files (x86)\Dropbox\Client\sip.pyd 2017-09-21 16:24 - 2017-09-20 12:49 - 001956152 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtGui.pyd 2017-09-21 16:24 - 2017-09-20 12:50 - 003859264 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWidgets.pyd 2017-09-21 16:24 - 2017-09-20 12:50 - 000154440 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebEngineWidgets.pyd 2017-09-21 16:24 - 2017-09-20 12:49 - 000521024 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtNetwork.pyd 2017-09-21 16:24 - 2017-09-20 12:50 - 000045888 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebEngineCore.pyd 2017-09-21 16:24 - 2017-09-20 12:50 - 000042304 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebChannel.pyd 2017-09-21 16:24 - 2017-09-20 12:50 - 000131384 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKit.pyd 2017-09-21 16:24 - 2017-09-20 12:50 - 000218944 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKitWidgets.pyd 2017-09-21 16:24 - 2017-09-20 12:49 - 000204096 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtPrintSupport.pyd 2017-09-15 13:25 - 2017-09-20 12:48 - 000060880 _____ () C:\Program Files (x86)\Dropbox\Client\win32print.pyd 2017-09-15 13:25 - 2017-09-20 12:50 - 000054608 _____ () C:\Program Files (x86)\Dropbox\Client\winrpcserver.compiled._RPCServer.pyd 2017-09-15 13:25 - 2017-09-20 12:50 - 000022864 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.user32.compiled._winffi_user32.pyd 2017-09-15 13:25 - 2017-09-20 12:50 - 000069968 _____ () C:\Program Files (x86)\Dropbox\Client\windisplaytoast.compiled._DisplayToast.pyd 2017-09-15 13:25 - 2017-09-20 12:50 - 000022872 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.iphlpapi.compiled._winffi_iphlpapi.pyd 2017-09-15 13:25 - 2017-09-20 12:50 - 000021848 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winerror.compiled._winffi_winerror.pyd 2017-09-15 13:25 - 2017-09-20 12:50 - 000022872 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.wininet.compiled._winffi_wininet.pyd 2017-09-21 16:24 - 2017-09-20 12:49 - 000027488 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox.infinite.win.compiled._driverinstallation.pyd 2017-09-15 13:25 - 2017-09-20 12:48 - 000349128 _____ () C:\Program Files (x86)\Dropbox\Client\winxpgui.pyd 2017-09-21 16:24 - 2017-09-20 12:50 - 000101184 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWinExtras.pyd 2017-09-15 13:25 - 2017-09-20 12:50 - 000023896 _____ () C:\Program Files (x86)\Dropbox\Client\winverifysignature.compiled._VerifySignature.pyd 2017-09-21 16:24 - 2017-09-20 12:49 - 000025936 _____ () C:\Program Files (x86)\Dropbox\Client\librsyncffi.compiled._librsyncffi.pyd 2017-09-21 16:24 - 2017-09-20 12:48 - 000036296 _____ () C:\Program Files (x86)\Dropbox\Client\librsync.dll 2017-09-21 16:24 - 2017-09-20 12:49 - 000033112 _____ () C:\Program Files (x86)\Dropbox\Client\enterprise_data.compiled._enterprise_data.pyd 2017-09-21 16:24 - 2017-09-20 12:48 - 000293392 _____ () C:\Program Files (x86)\Dropbox\Client\EnterpriseDataAdapter.dll 2017-09-21 16:24 - 2017-09-20 12:49 - 000181056 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_sqlite_ext.DLL 2017-09-15 13:25 - 2017-09-20 12:50 - 000030536 _____ () C:\Program Files (x86)\Dropbox\Client\wind3d11.compiled._wind3d11.pyd 2017-09-21 16:24 - 2017-09-20 12:49 - 000024368 _____ () C:\Program Files (x86)\Dropbox\Client\libEGL.DLL 2017-09-21 16:24 - 2017-09-20 12:49 - 001638200 _____ () C:\Program Files (x86)\Dropbox\Client\libGLESv2.dll 2017-09-15 13:25 - 2017-09-20 12:50 - 000026456 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winhttp.compiled._winffi_winhttp.pyd 2017-09-21 16:24 - 2017-09-20 12:50 - 000545080 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQuick.pyd 2017-09-21 16:24 - 2017-09-20 12:50 - 000359224 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQml.pyd 2017-09-21 16:24 - 2017-09-20 12:50 - 000038208 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebEngine.pyd 2017-08-02 21:40 - 2017-08-02 21:40 - 053460480 _____ () C:\Users\Joshua\AppData\Local\nvnkdes\libcef.dll 2016-05-31 11:43 - 2016-05-31 11:43 - 001976832 _____ () C:\Users\Joshua\AppData\Local\nvnkdes\libglesv2.dll 2016-05-31 11:44 - 2016-05-31 11:44 - 000075264 _____ () C:\Users\Joshua\AppData\Local\nvnkdes\libegl.dll 2017-05-13 21:28 - 2017-05-13 21:28 - 001943040 _____ () C:\Users\Joshua\AppData\Local\messengerfordesktop\app-2.0.9\ffmpeg.dll 2017-09-24 09:51 - 2017-09-24 09:51 - 000402944 _____ () \\?\C:\Users\Joshua\AppData\Local\Temp\F69.tmp.node 2017-09-24 09:51 - 2017-09-24 09:51 - 000402944 _____ () \\?\C:\Users\Joshua\AppData\Local\Temp\2236.tmp.node 2016-06-15 17:15 - 2016-06-15 17:15 - 017599640 _____ () C:\Users\Joshua\AppData\Local\nvnkdes\pepflashplayer.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\WINDOWS\system32\Drivers\lyykbyxk.sys:changelist [1094] ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NanoServiceMain => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PSUAService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NanoServiceMain => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PSUAService => ""="Service" ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2012-07-26 01:26 - 2017-09-20 21:12 - 000001024 _____ C:\WINDOWS\system32\Drivers\etc\hosts 127.0.0.1 localhost 127.0.0.1 lmlicenses.wip4.adobe.com 127.0.0.1 lm.licenses.adobe.com 127.0.0.1 na1r.services.adobe.com 127.0.0.1 hlrcv.stage.adobe.com 127.0.0.1 practivate.adobe.com 127.0.0.1 activate.adobe.com ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-2082031664-807437708-106104952-1002\Control Panel\Desktop\\Wallpaper -> DNS Servers: [removed] - [removed] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == MSCONFIG\Services: MB3Service => 2 HKLM\...\StartupApproved\StartupFolder: => "Install LastPass IE RunOnce.lnk" HKLM\...\StartupApproved\Run: => "ClipX" HKLM\...\StartupApproved\Run32: => "CLVirtualDrive" HKLM\...\StartupApproved\Run32: => "BDRegion" HKLM\...\StartupApproved\Run32: => "KeePass 2 PreLoad" HKLM\...\StartupApproved\Run32: => "ProductUpdater" HKU\S-1-5-21-2082031664-807437708-106104952-1002\...\StartupApproved\StartupFolder: => "Trillian.lnk" HKU\S-1-5-21-2082031664-807437708-106104952-1002\...\StartupApproved\Run: => "GoogleChromeAutoLaunch_7AF03CD55FBE5121416D410588C61404" HKU\S-1-5-21-2082031664-807437708-106104952-1002\...\StartupApproved\Run: => "BlueStacks Agent" HKU\S-1-5-21-2082031664-807437708-106104952-1002\...\StartupApproved\Run: => "EADM" HKU\S-1-5-21-2082031664-807437708-106104952-1002\...\StartupApproved\Run: => "Steam" HKU\S-1-5-21-2082031664-807437708-106104952-1002\...\StartupApproved\Run: => "Windscribe" HKU\S-1-5-21-2082031664-807437708-106104952-1002\...\StartupApproved\Run: => "GoogleDriveSync" HKU\S-1-5-21-2082031664-807437708-106104952-1002\...\StartupApproved\Run: => "WordExpander" HKU\S-1-5-21-2082031664-807437708-106104952-1002\...\StartupApproved\Run: => "AirDroid 3" HKU\S-1-5-21-2082031664-807437708-106104952-1002\...\StartupApproved\Run: => "SideSync" HKU\S-1-5-21-2082031664-807437708-106104952-1002\...\StartupApproved\Run: => "Spotify" HKU\S-1-5-21-2082031664-807437708-106104952-1002\...\StartupApproved\Run: => "Spotify Web Helper" HKU\S-1-5-21-2082031664-807437708-106104952-1002\...\StartupApproved\Run: => "Messenger for Desktop" HKU\S-1-5-21-2082031664-807437708-106104952-1002\...\StartupApproved\Run: => "70U5LJ2Y6XGYE12" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [UDP Query User{CA27810B-E4CD-48C3-B395-194582654F7E}C:\program files (x86)\diablo iii\x64\diablo iii64.exe] => (Allow) C:\program files (x86)\diablo iii\x64\diablo iii64.exe FirewallRules: [TCP Query User{AA12DB67-5C80-42F6-A9BA-54DCDAA07D77}C:\program files (x86)\diablo iii\x64\diablo iii64.exe] => (Allow) C:\program files (x86)\diablo iii\x64\diablo iii64.exe FirewallRules: [{01CF1644-8760-47B5-96C5-45893123E45D}] => (Allow) C:\Program Files (x86)\Origin Games\Dragon Age\bin_ship\daorigins.exe FirewallRules: [{E1478309-CB04-4C6A-9E0B-BF49BE658732}] => (Allow) C:\Program Files (x86)\Origin Games\Dragon Age\bin_ship\daorigins.exe FirewallRules: [UDP Query User{793D1904-9064-4F0A-AF8F-699277B37F8C}C:\users\joshua\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\joshua\appdata\roaming\spotify\spotify.exe FirewallRules: [TCP Query User{636CD6FD-32B8-4D0F-B7D4-C63976242D58}C:\users\joshua\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\joshua\appdata\roaming\spotify\spotify.exe FirewallRules: [UDP Query User{691201F7-15E0-411B-AFB3-C4623F975BCD}C:\program files (x86)\steam\steamapps\common\freestyle2\freestyle2.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\freestyle2\freestyle2.exe FirewallRules: [TCP Query User{3CB1892B-CDA2-4B7A-AE45-83F8E1FBBB75}C:\program files (x86)\steam\steamapps\common\freestyle2\freestyle2.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\freestyle2\freestyle2.exe FirewallRules: [{602E3ED9-CD4A-4D94-88E6-9560C8FB0B65}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\FreeStyle2\LauncherSteam.exe FirewallRules: [{146FB4FD-5BAA-46B4-B15B-B7F10DB30AE0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\FreeStyle2\LauncherSteam.exe FirewallRules: [{5A87F8B2-50B9-42E0-9847-E206CB41F006}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\MOBIUS FINAL FANTASY\mobiusff.exe FirewallRules: [{D5DD2A1E-1C05-4EDD-8638-2C6EE1B4E380}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\MOBIUS FINAL FANTASY\mobiusff.exe FirewallRules: [{CFEB4CFB-E9FF-4379-A128-5B558FD3A37D}] => (Allow) C:\Program Files (x86)\Origin Games\Need for Speed(TM) Most Wanted\NFS13.exe FirewallRules: [{8EB7D157-46E5-4FE1-A8F4-97596CD054F4}] => (Allow) C:\Program Files (x86)\Origin Games\Need for Speed(TM) Most Wanted\NFS13.exe FirewallRules: [{45E58370-1225-4E39-A6F5-B6D672C74A27}] => (Allow) C:\Program Files (x86)\PhraseExpress\PhraseExpress.exe FirewallRules: [UDP Query User{82AFD0A8-A2FC-4474-A2A2-DB1FEF814929}C:\users\joshua\appdata\local\google\chrome\application\chrome.exe] => (Allow) C:\users\joshua\appdata\local\google\chrome\application\chrome.exe FirewallRules: [TCP Query User{F98FF4C3-9AF3-4890-B5A9-CB84F5101DFC}C:\users\joshua\appdata\local\google\chrome\application\chrome.exe] => (Allow) C:\users\joshua\appdata\local\google\chrome\application\chrome.exe FirewallRules: [{98A904F5-E116-4838-BCD7-B578921E9D18}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect 2\Binaries\MassEffect2.exe FirewallRules: [{05C1735E-B4D4-4073-8589-23976A6E4B31}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect 2\Binaries\MassEffect2.exe FirewallRules: [UDP Query User{5FD11B05-54DF-4690-B8F7-732E2EF6B151}C:\program files (x86)\airdroid\airdroid.exe] => (Allow) C:\program files (x86)\airdroid\airdroid.exe FirewallRules: [TCP Query User{EDA7822B-7E84-485A-BFB1-AE258E363097}C:\program files (x86)\airdroid\airdroid.exe] => (Allow) C:\program files (x86)\airdroid\airdroid.exe FirewallRules: [{DB276319-1DB1-4F4A-97F2-5C9B3F673E7F}] => (Allow) C:\Program Files (x86)\Apowersoft\ApowerMirror\ApowerMirror.exe FirewallRules: [{B628C9A0-C850-4267-95AD-1DA0B16FFF9A}] => (Allow) C:\Program Files (x86)\Apowersoft\ApowerMirror\ApowerMirror.exe FirewallRules: [UDP Query User{76BE0C52-8DF2-4F8A-8A53-4AB5C84EB638}C:\program files\tixati\tixati.exe] => (Allow) C:\program files\tixati\tixati.exe FirewallRules: [TCP Query User{C06BFFB0-5B5E-4E98-B3D8-2FAF547D3291}C:\program files\tixati\tixati.exe] => (Allow) C:\program files\tixati\tixati.exe FirewallRules: [{F16106F5-E2AB-4BB5-A73E-5B5975F6CE9A}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{A980D5FF-FAD4-4D8C-AC9F-A2414FE969DD}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{E619ECFD-6BFC-4E2B-8B64-2F5034AFE737}] => (Block) %ProgramFiles%\Adobe\Adobe Photoshop CC 2015\Photoshop.exe FirewallRules: [{B45CDCA9-9F48-4F75-B34F-3B009D873917}] => (Allow) C:\Program Files (x86)\PhraseExpress\PhraseExpress.exe FirewallRules: [UDP Query User{FC3707D0-F8F9-48D3-BED0-69B22E398C2D}C:\program files\qcma\qcma.exe] => (Allow) C:\program files\qcma\qcma.exe FirewallRules: [TCP Query User{78A474AC-6B00-4462-8AE5-B4B10DAC11BA}C:\program files\qcma\qcma.exe] => (Allow) C:\program files\qcma\qcma.exe FirewallRules: [{4A3C36C7-48A8-48AF-AB66-7D3A1915B261}] => (Allow) C:\Users\Joshua\AppData\Roaming\Nox\bin\Nox.exe FirewallRules: [UDP Query User{696DA7E6-3D61-45A3-B614-76FB23BAB10A}C:\program files (x86)\lionhead studios ltd\black & white\runblack.exe] => (Allow) C:\program files (x86)\lionhead studios ltd\black & white\runblack.exe FirewallRules: [TCP Query User{D3D4FCEA-80D8-404F-84D6-8309565E12C0}C:\program files (x86)\lionhead studios ltd\black & white\runblack.exe] => (Allow) C:\program files (x86)\lionhead studios ltd\black & white\runblack.exe FirewallRules: [UDP Query User{57CB2503-E52C-4B4A-BB60-09005EF2C48B}C:\program files (x86)\steam\steamapps\common\dungeons and dragons online\dndclient.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\dungeons and dragons online\dndclient.exe FirewallRules: [TCP Query User{237C2306-5C22-47E1-88AE-FFFF21550E54}C:\program files (x86)\steam\steamapps\common\dungeons and dragons online\dndclient.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\dungeons and dragons online\dndclient.exe FirewallRules: [{B6883FE1-D8B7-4AAB-96C2-53912E919DFF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Dungeons and Dragons Online\TurbineInvoker.exe FirewallRules: [{B26307F6-D4EC-4F3A-8682-5D7E79163336}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Dungeons and Dragons Online\TurbineInvoker.exe FirewallRules: [{F3E10CBC-8E7C-4F88-BF04-0A0435E1561E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Marvel Heroes\UnrealEngine3\Binaries\Win64\MarvelHeroes2016.exe FirewallRules: [{E932F27D-80A2-4BAC-AE24-5EB1690A2A2E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Marvel Heroes\UnrealEngine3\Binaries\Win64\MarvelHeroes2016.exe FirewallRules: [{EBA6BBDC-C3DF-4046-AF5C-57CC35D03888}] => (Allow) C:\Program Files (x86)\PhraseExpress\PhraseExpress.exe FirewallRules: [UDP Query User{1C68A9A5-DC13-4297-8D3B-E2A4422C0DC7}C:\program files\tixati\tixati.exe] => (Allow) C:\program files\tixati\tixati.exe FirewallRules: [TCP Query User{6DB56666-E68D-41C2-95CE-C44EAA40A772}C:\program files\tixati\tixati.exe] => (Allow) C:\program files\tixati\tixati.exe FirewallRules: [{280330AF-0362-4A4F-909A-45777004C47A}] => (Allow) C:\Program Files (x86)\Origin Games\SimCity 2000 SE\Game\Game\DOSBox\DOSBox.exe FirewallRules: [{201C525E-462A-452D-AB69-0B68178BA7D2}] => (Allow) C:\Program Files (x86)\Origin Games\SimCity 2000 SE\Game\Game\DOSBox\DOSBox.exe FirewallRules: [{9918616D-F624-4CEC-9B6F-7AA883910D7F}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{D47E84EE-F22E-4D92-89F1-88356C85F617}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{7154FC60-FF10-486B-ADA9-121147D5BFC8}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{8EF913EE-A48B-4EF1-B4FA-AAD1AC0D7607}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [UDP Query User{0C4C3C6A-C194-41AC-8D30-EE8602E2002F}C:\mushclient\mushclient.exe] => (Allow) C:\mushclient\mushclient.exe FirewallRules: [TCP Query User{A418DE3F-FC0F-4578-AB31-26FC07FD29AA}C:\mushclient\mushclient.exe] => (Allow) C:\mushclient\mushclient.exe FirewallRules: [{2A320EBE-AA54-433C-BC57-C7E54B277DD5}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe FirewallRules: [{472BA37A-37A1-424C-AABB-AA7E1C0016F3}] => (Allow) LPort=2869 FirewallRules: [{CED499B8-2A16-423B-BF2E-2802CBC56CCA}] => (Allow) LPort=1900 FirewallRules: [{F5733B9B-C407-4D8C-BCFF-B4AC10CE805D}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD10.EXE FirewallRules: [{6F255C95-4012-4ACB-BAD9-21C4410658B1}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDirector10\PDR10.EXE FirewallRules: [{6436216F-E0F0-49DA-B877-866D81FDC2E7}] => (Allow) C:\Program Files (x86)\Origin Games\Dead in Bermuda\Dead In Bermuda.exe FirewallRules: [{7D02B981-7B93-4170-838E-D0565159249B}] => (Allow) C:\Program Files (x86)\Origin Games\Dead in Bermuda\Dead In Bermuda.exe FirewallRules: [{54CF0C8E-546D-40D9-99F6-EA507DCC7941}] => (Allow) C:\Program Files (x86)\WordExpander\WordExpander.exe FirewallRules: [TCP Query User{F2ECEFBE-D471-488A-91EA-036E5BF0BE25}C:\users\joshua\downloads\anydesk.exe] => (Allow) C:\users\joshua\downloads\anydesk.exe FirewallRules: [UDP Query User{5B749883-6DA3-4E15-9CC2-CDFDE9EBC96C}C:\users\joshua\downloads\anydesk.exe] => (Allow) C:\users\joshua\downloads\anydesk.exe FirewallRules: [{58D4EDA3-2295-4CF4-B0EF-3E13A9F8E631}] => (Allow) C:\Users\Joshua\Downloads\Tech tool store tools\TechToolStore64.exe FirewallRules: [TCP Query User{D61173B3-FE8F-4005-880D-61398FC38CE2}C:\users\joshua\downloads\tech tool store tools\snappydriverinstaller\sdi_x64_r1751.exe] => (Allow) C:\users\joshua\downloads\tech tool store tools\snappydriverinstaller\sdi_x64_r1751.exe FirewallRules: [UDP Query User{C049C6BF-A636-4868-9C8F-FC4A699ABD8D}C:\users\joshua\downloads\tech tool store tools\snappydriverinstaller\sdi_x64_r1751.exe] => (Allow) C:\users\joshua\downloads\tech tool store tools\snappydriverinstaller\sdi_x64_r1751.exe FirewallRules: [{CA583B67-EED0-4142-8067-17A1943FF232}] => (Allow) C:\Users\Joshua\Downloads\Tech tool store tools\TechToolStore (1)64.exe FirewallRules: [{D4473379-E2B8-4478-9AB8-57615788ABBC}] => (Allow) C:\Users\Joshua\Downloads\Tech tool store tools\TechToolStore (1)64.exe FirewallRules: [TCP Query User{17CE862E-55FC-4D53-B94F-A46A0B3F6D97}C:\python27\python.exe] => (Allow) C:\python27\python.exe FirewallRules: [UDP Query User{24B07EF3-FBEE-4F28-85CD-884FB754362E}C:\python27\python.exe] => (Allow) C:\python27\python.exe FirewallRules: [{82FBA4BD-A023-495C-9DED-E2B003219085}] => (Allow) C:\Program Files (x86)\Samsung\SideSync4\SideSync.exe FirewallRules: [{AD4F7CF1-6E6D-4738-BF8E-09A15ED28A5C}] => (Allow) C:\Program Files (x86)\Samsung\SideSync4\SideSync.exe FirewallRules: [{C8F4E063-B736-483E-AE12-8BAE298FD082}] => (Allow) C:\Program Files (x86)\Origin Games\Medal of Honor Pacific Assault\mohpa_setup.exe FirewallRules: [{EAC4691F-953E-47B5-AB37-045601E6EAD3}] => (Allow) C:\Program Files (x86)\Origin Games\Medal of Honor Pacific Assault\mohpa_setup.exe FirewallRules: [{240733AD-CFC4-4938-946E-BEA778D01BFB}] => (Allow) C:\Program Files (x86)\Origin Games\Medal of Honor Pacific Assault\mohpa.exe FirewallRules: [{4597CC7C-7D80-43C3-8811-96D2EE587E4F}] => (Allow) C:\Program Files (x86)\Origin Games\Medal of Honor Pacific Assault\mohpa.exe FirewallRules: [{E2FB848B-093F-4002-A840-FAE5E991038C}] => (Allow) C:\Program Files (x86)\MAGIX\Music Maker\25\MusicMaker.exe FirewallRules: [{645F2E01-844B-46A1-8751-9BFE9316258A}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe FirewallRules: [{35220437-31F5-470F-A084-EF935044575F}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe FirewallRules: [{142AA214-DC1E-4395-A47C-2AF9EBD8FBC7}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe FirewallRules: [{0BCD47EB-BABD-47BC-9D38-A014A981892F}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe FirewallRules: [{455E0276-6304-47EB-A416-93B8A8890B3E}] => (Allow) C:\Program Files (x86)\Samsung\SideSync4\SideSync.exe FirewallRules: [{FBA6ABB0-E49A-4874-BB43-EFBF50BFD30E}] => (Allow) C:\Program Files (x86)\Samsung\SideSync4\SideSync.exe FirewallRules: [{F4E51E6D-146C-4EB1-B57B-4F3BB81AA3DB}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{7F840F0D-1961-420D-A494-56E658E288EC}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{A2B290BB-9B70-41DA-9075-4425F15BE26B}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{986CEAA2-8EBA-4B3A-82C3-3B2139F5EAA6}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{2B0EF403-F3D5-4CB9-B9AF-9A1082D3E2A7}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe FirewallRules: [{C407B289-9AA4-49B6-A62C-8D6D6D238E00}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{A91AB120-C82A-425E-92A3-A77BBAB6FD50}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{CAC62679-0CC4-442D-BE12-80D165DDBC1B}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{87D98CAB-9585-47AA-8259-1BF3D3BCC246}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{DC9873C6-A0F9-491E-AFFA-75DFBADA763B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Walking Dead\WalkingDead101.exe FirewallRules: [{32BD6E0D-9241-4B97-9F6C-90ACC413B88F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Walking Dead\WalkingDead101.exe FirewallRules: [{BA3EFD84-FBBD-4038-9D5A-1A37A8BB0EBB}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Psychonauts\Psychonauts.exe FirewallRules: [{AF5AC526-905A-4092-A1B7-3FF1FDE56AC9}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Psychonauts\Psychonauts.exe FirewallRules: [{C43CA5C8-3C08-413C-A1D8-48EF8625283D}] => (Allow) 㩃停潲牧浡䘠汩獥⠠㡸⤶啜浮汥整杤敲湯屹湕敭瑬摥牧潥祮攮數 FirewallRules: [{78494321-B3D8-45D1-9592-4D1E910EB566}] => (Allow) 㩃停潲牧浡䘠汩獥⠠㡸⤶啜浮汥整杤敲湯屹湕敭瑬摥牧潥祮⹟硥e FirewallRules: [{2D1D5931-CE92-48A7-86BE-0CB89B6CF2E5}] => (Allow) C:\Users\Joshua\Downloads\Tech tool store tools\TechToolStore64.exe FirewallRules: [{F238ED0B-51D1-4D19-8846-92416DF0BFE2}] => (Allow) C:\Users\Joshua\Downloads\Tech tool store tools\TechToolStore64.exe FirewallRules: [{B83B7FD8-B23C-40FC-8049-FF3A3707D540}] => (Allow) C:\Users\Joshua\Downloads\Tech tool store tools\TechToolStore64.exe FirewallRules: [{A532C43B-65E2-4936-B987-C10E2A6B926B}] => (Allow) C:\Users\Joshua\Downloads\Tech tool store tools\TechToolStore64.exe FirewallRules: [TCP Query User{00446B03-7091-467F-AC1B-C599AE644ADD}C:\users\joshua\appdata\local\brave\app-0.18.36\brave.exe] => (Allow) C:\users\joshua\appdata\local\brave\app-0.18.36\brave.exe FirewallRules: [UDP Query User{E1B92D61-1FEA-4EC1-8ACA-879755C69C85}C:\users\joshua\appdata\local\brave\app-0.18.36\brave.exe] => (Allow) C:\users\joshua\appdata\local\brave\app-0.18.36\brave.exe FirewallRules: [{59CD10FF-BD4D-4C10-A0CD-D01395FE9C02}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe FirewallRules: [TCP Query User{69E863F1-2DC0-4684-91F2-9ED34E70E268}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe FirewallRules: [UDP Query User{E017F129-A91B-4D94-85A8-569AB4B01617}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe FirewallRules: [{E21A24AF-E97E-4FB7-BB08-7A9EF21C7105}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Outlast\OutlastLauncher.exe FirewallRules: [{BEE1C217-DA6D-460F-80A6-2B7F3317576D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Outlast\OutlastLauncher.exe FirewallRules: [TCP Query User{F05FEC31-2F90-4725-B7A2-AD49D1C14C07}C:\program files (x86)\steam\steamapps\common\outlast\binaries\win64\olgame.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\outlast\binaries\win64\olgame.exe FirewallRules: [UDP Query User{00F7656D-1B31-4996-8F29-FE8D548FBC63}C:\program files (x86)\steam\steamapps\common\outlast\binaries\win64\olgame.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\outlast\binaries\win64\olgame.exe FirewallRules: [{7060355C-930E-4F44-83A9-013CBF0A88AA}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Restore Points ========================= 24-09-2017 20:54:09 Scheduled Checkpoint ==================== Faulty Device Manager Devices ============= Name: Logitech Cordless Device Description: Logitech Cordless Device Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Logitech Cordless Device Description: Logitech Cordless Device Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Logitech Cordless Device Description: Logitech Cordless Device Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (09/25/2017 07:51:08 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Activation context generation failed for "C:\Program Files (x86)\Samsung\SideSync4\SideSync.exe".Error in manifest or policy file "" on line . A component version required by the application conflicts with another component version already active. Conflicting components are:. Component 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.483_none_26002d27e7c744a2.manifest. Component 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.483_none_6dad63fefc436da8.manifest. Error: (09/25/2017 07:51:08 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Activation context generation failed for "C:\Program Files (x86)\Samsung\SideSync4\SideSync.exe".Error in manifest or policy file "" on line . A component version required by the application conflicts with another component version already active. Conflicting components are:. Component 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.483_none_26002d27e7c744a2.manifest. Component 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.483_none_6dad63fefc436da8.manifest. Error: (09/25/2017 07:26:47 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Activation context generation failed for "C:\Program Files (x86)\Samsung\SideSync4\SideSync.exe".Error in manifest or policy file "" on line . A component version required by the application conflicts with another component version already active. Conflicting components are:. Component 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.483_none_26002d27e7c744a2.manifest. Component 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.483_none_6dad63fefc436da8.manifest. Error: (09/25/2017 07:26:47 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Activation context generation failed for "C:\Program Files (x86)\Samsung\SideSync4\SideSync.exe".Error in manifest or policy file "" on line . A component version required by the application conflicts with another component version already active. Conflicting components are:. Component 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.483_none_26002d27e7c744a2.manifest. Component 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.483_none_6dad63fefc436da8.manifest. Error: (09/25/2017 07:25:44 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Activation context generation failed for "C:\Program Files (x86)\Samsung\SideSync4\SideSync.exe".Error in manifest or policy file "" on line . A component version required by the application conflicts with another component version already active. Conflicting components are:. Component 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.483_none_26002d27e7c744a2.manifest. Component 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.483_none_6dad63fefc436da8.manifest. Error: (09/25/2017 07:25:44 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Activation context generation failed for "C:\Program Files (x86)\Samsung\SideSync4\SideSync.exe".Error in manifest or policy file "" on line . A component version required by the application conflicts with another component version already active. Conflicting components are:. Component 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.483_none_26002d27e7c744a2.manifest. Component 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.483_none_6dad63fefc436da8.manifest. Error: (09/25/2017 06:00:59 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: scbglnu.exe, version: 1.0.1.5, time stamp: 0x59991256 Faulting module name: libcef.dll, version: 3.2526.1373.0, time stamp: 0x587a0d9a Exception code: 0xc0000005 Fault offset: 0x011fae1b Faulting process id: 0x3790 Faulting application start time: 0x01d33649876accbb Faulting application path: C:\Users\Joshua\AppData\Local\nvnkdes\scbglnu.exe Faulting module path: C:\Users\Joshua\AppData\Local\nvnkdes\libcef.dll Report Id: 6d839fb1-af8d-4717-978f-7637c0a2959b Faulting package full name: Faulting package-relative application ID: Error: (09/25/2017 04:21:19 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: scbglnu.exe, version: 1.0.1.5, time stamp: 0x59991256 Faulting module name: libcef.dll, version: 3.2526.1373.0, time stamp: 0x587a0d9a Exception code: 0xc0000005 Fault offset: 0x01eed9f0 Faulting process id: 0x33e0 Faulting application start time: 0x01d3363bc1be1045 Faulting application path: C:\Users\Joshua\AppData\Local\nvnkdes\scbglnu.exe Faulting module path: C:\Users\Joshua\AppData\Local\nvnkdes\libcef.dll Report Id: 1b9b97e3-ac0d-4a1e-b759-a9da7453a756 Faulting package full name: Faulting package-relative application ID: Error: (09/25/2017 03:53:20 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: scbglnu.exe, version: 1.0.1.5, time stamp: 0x59991256 Faulting module name: libcef.dll, version: 3.2526.1373.0, time stamp: 0x587a0d9a Exception code: 0xc0000005 Fault offset: 0x00180814 Faulting process id: 0x2da8 Faulting application start time: 0x01d33637dc45b3ac Faulting application path: C:\Users\Joshua\AppData\Local\nvnkdes\scbglnu.exe Faulting module path: C:\Users\Joshua\AppData\Local\nvnkdes\libcef.dll Report Id: 1896efc8-8fea-4be1-96ca-4c05011d918e Faulting package full name: Faulting package-relative application ID: Error: (09/25/2017 02:59:35 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: scbglnu.exe, version: 1.0.1.5, time stamp: 0x59991256 Faulting module name: libcef.dll, version: 3.2526.1373.0, time stamp: 0x587a0d9a Exception code: 0xc0000005 Fault offset: 0x01eed9f0 Faulting process id: 0x42c0 Faulting application start time: 0x01d336304279781b Faulting application path: C:\Users\Joshua\AppData\Local\nvnkdes\scbglnu.exe Faulting module path: C:\Users\Joshua\AppData\Local\nvnkdes\libcef.dll Report Id: af55d661-fc26-4ce6-a4fd-ab41d58d5253 Faulting package full name: Faulting package-relative application ID: System errors: ============= Error: (09/24/2017 08:12:48 PM) (Source: volsnap) (EventID: 36) (User: ) Description: The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit. Error: (09/24/2017 07:01:52 PM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY) Description: The server {F3B4E234-7A68-4E43-B813-E4BA55A065F6} did not register with DCOM within the required timeout. Error: (09/24/2017 02:27:52 PM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY) Description: The server {F3B4E234-7A68-4E43-B813-E4BA55A065F6} did not register with DCOM within the required timeout. Error: (09/24/2017 01:47:03 PM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY) Description: The server {F3B4E234-7A68-4E43-B813-E4BA55A065F6} did not register with DCOM within the required timeout. Error: (09/24/2017 10:28:10 AM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the CybereasonRansomFree service. Error: (09/24/2017 09:41:48 AM) (Source: Service Control Manager) (EventID: 7022) (User: ) Description: The Downloaded Maps Manager service hung on starting. Error: (09/24/2017 09:39:47 AM) (Source: Service Control Manager) (EventID: 7022) (User: ) Description: The HP Support Assistant Service service hung on starting. Error: (09/24/2017 09:37:40 AM) (Source: Service Control Manager) (EventID: 7022) (User: ) Description: The Delivery Optimization service hung on starting. Error: (09/24/2017 09:33:07 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The Origin Web Helper Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. Error: (09/24/2017 09:33:07 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: A timeout was reached (30000 milliseconds) while waiting for the Origin Web Helper Service service to connect. CodeIntegrity: =================================== Date: 2017-09-22 21:52:22.438 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-09-22 21:52:22.394 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-09-22 17:10:43.177 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-09-22 17:10:43.173 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-09-21 23:22:15.391 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-09-21 23:22:15.376 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-09-21 19:48:06.124 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-09-21 19:48:06.121 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-09-21 19:30:14.931 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Users\Joshua\AppData\Local\Temp\HBCD\REGSYS701.SYS because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2017-09-21 19:30:14.895 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\SysWOW64\drivers\REGSYS701.SYS because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. ==================== Memory info =========================== Processor: AMD A8-4500M APU with Radeon(tm) HD Graphics Percentage of memory in use: 71% Total physical RAM: 5596.26 MB Available physical RAM: 1597.37 MB Total Virtual: 10204.26 MB Available Virtual: 3613.07 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:565.26 GB) (Free:262.74 GB) NTFS ==>[system with boot components (obtained from drive)] Drive d: (RECOVERY) (Fixed) (Total:27.26 GB) (Free:3.21 GB) NTFS ==>[system with boot components (obtained from drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 596.2 GB) (Disk ID: 9DCF5BF6) Partition: GPT. ==================== End of Addition.txt ============================