Additional scan result of Farbar Recovery Scan Tool (x64) Version: 09-12-2017 Ran by [removed] (10-12-2017 22:44:16) Running from C:\Users\[removed]\Desktop Windows 7 Home Premium Service Pack 1 (X64) (2012-04-11 13:23:37) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-298761936-1198288888-1608458099-500 - Administrator - Disabled) Comet (S-1-5-21-298761936-1198288888-1608458099-1000 - Administrator - Enabled) => C:\Users\Comet Guest (S-1-5-21-298761936-1198288888-1608458099-501 - Limited - Enabled) Paul (S-1-5-21-298761936-1198288888-1608458099-1005 - Administrator - Enabled) => C:\Users\Paul ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF} AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B} AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Acronis True Image Home 2012 (HKLM-x32\...\{DE9DDE76-B62E-49E9-B41F-510F83D7706D}) (Version: 15.0.7133 - Acronis) Hidden Acronis True Image Home 2012 (HKLM-x32\...\{DE9DDE76-B62E-49E9-B41F-510F83D7706D}Visible) (Version: 15.0.7133 - Acronis) Audacity 2.0.2 (HKLM-x32\...\Audacity_is1) (Version: 2.0.2 - Audacity Team) Avast Free Antivirus (HKLM-x32\...\Avast Antivirus) (Version: 17.8.2318 - AVAST Software) CCleaner (HKLM\...\CCleaner) (Version: 5.37 - Piriform) D3DX10 (HKLM-x32\...\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden Defraggler (HKLM\...\Defraggler) (Version: 2.21 - Piriform) DeskUpdate 4.11 (HKLM-x32\...\DeskUpdate_is1) (Version: 4.11.0074 - Fujitsu Technology Solutions) ImagXpress (HKLM-x32\...\{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}) (Version: 7.0.74.0 - Nero AG) Hidden Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.2932 - Intel Corporation) Junk Mail filter update (HKLM-x32\...\{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}) (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden LAME v3.99.3 (for Windows) (HKLM-x32\...\LAME_is1) (Version: - ) Malwarebytes version 3.3.1.2183 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.3.1.2183 - Malwarebytes) Mesh Runtime (HKLM-x32\...\{8C6D6116-B724-4810-8F2D-D047E6B7D68E}) (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.7 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.02053 - Microsoft Corporation) Microsoft Office Click-to-Run 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Starter 2010 - English (HKLM-x32\...\{90140011-0066-0409-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM-x32\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 4.1.10329.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Mozilla Firefox 57.0.2 (x64 en-US) (HKLM\...\Mozilla Firefox 57.0.2 (x64 en-US)) (Version: 57.0.2 - Mozilla) MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6278 - Realtek Semiconductor Corp.) Revo Uninstaller 1.94 (HKLM-x32\...\Revo Uninstaller) (Version: 1.94 - VS Revo Group) SpywareBlaster 5.5 (HKLM-x32\...\SpywareBlaster_is1) (Version: 5.5.0 - BrightFort LLC) System Requirements Lab for Intel (HKLM-x32\...\{C7CA731B-BF9A-46D9-92CF-8A8737AE9240}) (Version: 4.5.13.0 - Husdawg, LLC) Winamp (HKLM-x32\...\Winamp) (Version: 5.63 - Nullsoft, Inc) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-11-22] (AVAST Software) ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-11-22] (AVAST Software) ContextMenuHandlers1: [VersionsPageShellExt] -> {9E42900A-85F9-4E67-9778-575FBBA0A81C} => C:\Program Files (x86)\Acronis\TrueImageHome\x64\versions_page.dll [2012-06-28] (Acronis) ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-11-22] (AVAST Software) ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-11-01] (Malwarebytes) ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\Windows\system32\igfxpph.dll [2012-12-12] (Intel Corporation) ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-11-22] (AVAST Software) ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-11-01] (Malwarebytes) ContextMenuHandlers6: [VersionsPageShellExt] -> {9E42900A-85F9-4E67-9778-575FBBA0A81C} => C:\Program Files (x86)\Acronis\TrueImageHome\x64\versions_page.dll [2012-06-28] (Acronis) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {12AC1987-3650-4372-8340-E7B84A8A816A} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2017-11-08] (Piriform Ltd) Task: {32BB29C1-B8F4-4259-95CB-5343B861AF42} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2017-11-22] (AVAST Software) Task: {E7B8538C-BA16-4E60-8C77-9778584760FD} - System32\Tasks\{13A80A86-065B-441C-A635-6DAFE9158DE9} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\VS Revo Group\Revo Uninstaller\Revouninstaller.exe" -d "C:\Program Files (x86)\VS Revo Group\Revo Uninstaller" Task: {EF57C6F4-6700-4E7D-8F20-6ABD45C3EEBE} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [2017-11-08] (Piriform Ltd) Task: {FC3AA75B-380A-49F9-B6BF-06955E4AE923} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [2017-12-07] (AVAST Software) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) ==================== Shortcuts & WMI ======================== (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== 2017-11-22 04:36 - 2017-11-01 08:55 - 002299344 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\SelfProtectionSdk.dll 2017-11-22 04:36 - 2017-11-01 08:54 - 002358736 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll 2017-11-22 05:28 - 2017-11-22 05:28 - 000067408 _____ () C:\Program Files\AVAST Software\Avast\x64\module_lifetime.dll 2017-11-22 05:28 - 2017-11-22 05:28 - 000169832 _____ () c:\Program Files\AVAST Software\Avast\x64\vaarclient.dll 2017-11-22 05:28 - 2017-11-22 05:28 - 000859216 _____ () C:\Program Files\AVAST Software\Avast\x64\ffl2.dll 2017-11-22 05:28 - 2017-11-22 05:28 - 000292408 _____ () c:\Program Files\AVAST Software\Avast\x64\StreamBack.dll 2017-11-22 05:28 - 2017-11-22 05:28 - 000281536 _____ () C:\Program Files\AVAST Software\Avast\x64\tasks_core.dll 2017-11-22 05:28 - 2017-11-22 05:28 - 000059040 _____ () C:\Program Files\AVAST Software\Avast\module_lifetime.dll 2017-11-22 05:28 - 2017-11-22 05:28 - 000167096 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll 2017-11-22 05:28 - 2017-11-22 05:28 - 000237808 _____ () C:\Program Files\AVAST Software\Avast\event_routing_rpc.dll 2017-11-22 05:28 - 2017-11-22 05:28 - 000244584 _____ () C:\Program Files\AVAST Software\Avast\tasks_core.dll 2017-11-22 05:28 - 2017-11-22 05:28 - 000151104 _____ () C:\Program Files\AVAST Software\Avast\network_notifications.dll 2017-12-09 14:14 - 2017-12-09 14:14 - 005892848 _____ () C:\Program Files\AVAST Software\Avast\defs\17120900\algo.dll 2017-11-22 05:28 - 2017-11-22 05:28 - 000710056 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll 2017-12-10 14:07 - 2017-12-10 14:07 - 005892848 _____ () C:\Program Files\AVAST Software\Avast\defs\17121002\algo.dll 2017-11-22 05:28 - 2017-11-22 05:28 - 067109376 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2012-06-28 15:42 - 2012-12-27 12:07 - 000417280 _____ () C:\Program Files (x86)\Winamp\nsutil.dll 2012-06-28 15:42 - 2012-12-27 12:07 - 000078848 _____ () C:\Program Files (x86)\Winamp\nde.dll 2012-06-28 15:42 - 2012-12-27 12:07 - 000023552 _____ () C:\Program Files (x86)\Winamp\System\albumart.w5s 2012-06-28 15:42 - 2012-12-27 12:07 - 000019456 _____ () C:\Program Files (x86)\Winamp\System\bmp.w5s 2012-06-28 15:42 - 2012-12-27 12:07 - 000064512 _____ () C:\Program Files (x86)\Winamp\zlib.dll 2012-06-28 15:42 - 2012-12-27 12:07 - 000044544 _____ () C:\Program Files (x86)\Winamp\System\devices.w5s 2012-06-28 15:42 - 2012-12-27 12:07 - 000016896 _____ () C:\Program Files (x86)\Winamp\System\dlmgr.w5s 2012-06-28 15:42 - 2012-12-27 12:07 - 000014336 _____ () C:\Program Files (x86)\Winamp\System\filereader.w5s 2012-06-28 15:42 - 2012-12-27 12:07 - 000019456 _____ () C:\Program Files (x86)\Winamp\System\gif.w5s 2012-06-28 15:42 - 2012-12-27 12:07 - 000016384 _____ () C:\Program Files (x86)\Winamp\System\gracenote.w5s 2012-06-28 15:42 - 2012-12-27 12:07 - 000623616 _____ () C:\Program Files (x86)\Winamp\System\jnetlib.w5s 2012-06-28 15:42 - 2012-12-27 12:07 - 000154624 _____ () C:\Program Files (x86)\Winamp\System\jpeg.w5s 2012-06-28 15:42 - 2012-12-27 12:07 - 000084480 _____ () C:\Program Files (x86)\Winamp\System\playlist.w5s 2012-06-28 15:42 - 2012-12-27 12:07 - 000087552 _____ () C:\Program Files (x86)\Winamp\System\png.w5s 2012-06-28 15:42 - 2012-12-27 12:07 - 000013824 _____ () C:\Program Files (x86)\Winamp\System\primo.w5s 2012-06-28 15:42 - 2012-12-27 12:07 - 000021504 _____ () C:\Program Files (x86)\Winamp\System\tagz.w5s 2012-06-28 15:42 - 2012-12-27 12:07 - 000035328 _____ () C:\Program Files (x86)\Winamp\System\timer.w5s 2012-06-28 15:42 - 2012-12-27 12:07 - 000091136 _____ () C:\Program Files (x86)\Winamp\System\xml.w5s 2012-06-28 15:42 - 2012-12-27 12:07 - 000068608 _____ () C:\Program Files (x86)\Winamp\Plugins\in_avi.dll 2012-06-28 15:42 - 2012-12-27 12:07 - 000102400 _____ () C:\Program Files (x86)\Winamp\Plugins\in_cdda.dll 2012-06-28 15:42 - 2012-12-27 12:07 - 000072192 _____ () C:\Program Files (x86)\Winamp\Plugins\in_dshow.dll 2012-06-28 15:42 - 2012-12-27 12:07 - 000061440 _____ () C:\Program Files (x86)\Winamp\Plugins\in_flac.dll 2012-06-28 15:42 - 2012-12-27 12:07 - 000043008 _____ () C:\Program Files (x86)\Winamp\Plugins\in_flv.dll 2012-06-28 15:42 - 2012-12-27 12:07 - 000109568 _____ () C:\Program Files (x86)\Winamp\Plugins\in_midi.dll 2012-06-28 15:42 - 2012-12-27 12:07 - 000049152 _____ () C:\Program Files (x86)\Winamp\Plugins\in_mkv.dll 2012-06-28 15:42 - 2012-12-27 12:07 - 000164864 _____ () C:\Program Files (x86)\Winamp\Plugins\in_mod.dll 2012-06-28 15:42 - 2012-12-27 12:07 - 000290816 _____ () C:\Program Files (x86)\Winamp\Plugins\in_mp3.dll 2012-06-28 15:42 - 2012-12-27 12:07 - 000052736 _____ () C:\Program Files (x86)\Winamp\Plugins\in_mp4.dll 2012-06-28 15:42 - 2012-12-27 12:07 - 000075264 _____ () C:\Program Files (x86)\Winamp\Plugins\in_nsv.dll 2012-06-28 15:42 - 2012-12-27 12:07 - 000253440 _____ () C:\Program Files (x86)\Winamp\Plugins\in_vorbis.dll 2012-06-28 15:42 - 2012-12-27 12:07 - 000016896 _____ () C:\Program Files (x86)\Winamp\Plugins\in_wave.dll 2012-06-28 15:42 - 2012-12-27 12:07 - 000253440 _____ () C:\Program Files (x86)\Winamp\libsndfile.dll 2012-06-28 15:42 - 2012-12-27 12:07 - 000313344 _____ () C:\Program Files (x86)\Winamp\Plugins\in_wm.dll 2012-06-28 15:42 - 2012-12-27 12:07 - 000022528 _____ () C:\Program Files (x86)\Winamp\Plugins\out_disk.dll 2012-06-28 15:42 - 2012-12-27 12:07 - 000052224 _____ () C:\Program Files (x86)\Winamp\Plugins\out_ds.dll 2012-06-28 15:42 - 2012-12-27 12:07 - 000018432 _____ () C:\Program Files (x86)\Winamp\Plugins\out_wave.dll 2012-06-28 15:42 - 2012-12-27 12:07 - 001737728 _____ () C:\Program Files (x86)\Winamp\Plugins\gen_ff.dll 2012-06-28 15:42 - 2012-12-27 12:07 - 000083968 _____ () C:\Program Files (x86)\Winamp\tataki.dll 2012-06-28 15:42 - 2012-12-27 12:07 - 000340992 _____ () C:\Program Files (x86)\Winamp\Plugins\freeform\wacs\freetype\freetype.wac 2012-06-28 15:42 - 2012-12-27 12:07 - 000028160 _____ () C:\Program Files (x86)\Winamp\Plugins\gen_hotkeys.dll 2011-11-10 22:10 - 2012-12-27 12:07 - 000185344 _____ () C:\Program Files (x86)\Winamp\Plugins\gen_jumpex.dll 2012-06-28 15:42 - 2012-12-27 12:07 - 000318976 _____ () C:\Program Files (x86)\Winamp\Plugins\gen_ml.dll 2012-06-28 15:42 - 2012-12-27 12:07 - 000294912 _____ () C:\Program Files (x86)\Winamp\Plugins\ml_local.dll 2012-06-28 15:42 - 2012-12-27 12:07 - 000084480 _____ () C:\Program Files (x86)\Winamp\Plugins\ml_playlists.dll 2012-06-28 15:42 - 2012-12-27 12:07 - 000249856 _____ () C:\Program Files (x86)\Winamp\Plugins\ml_devices.dll 2012-06-28 15:42 - 2012-12-27 12:07 - 000240640 _____ () C:\Program Files (x86)\Winamp\Plugins\ml_pmp.dll 2012-06-28 15:42 - 2012-12-27 12:07 - 000170496 _____ () C:\Program Files (x86)\Winamp\Plugins\pmp_ipod.dll 2012-06-28 15:42 - 2012-12-27 12:07 - 000113664 _____ () C:\Program Files (x86)\Winamp\Plugins\pmp_wifi.dll 2012-06-28 15:42 - 2012-12-27 12:07 - 000028672 _____ () C:\Program Files (x86)\Winamp\Plugins\ml_autotag.dll 2012-06-28 15:42 - 2012-12-27 12:07 - 000033792 _____ () C:\Program Files (x86)\Winamp\Plugins\ml_rg.dll 2012-06-28 15:42 - 2012-12-27 12:07 - 000032256 _____ () C:\Program Files (x86)\Winamp\Plugins\ml_transcode.dll 2012-06-28 15:42 - 2012-12-27 12:07 - 000025600 _____ () C:\Program Files (x86)\Winamp\Plugins\gen_tray.dll 2012-06-28 22:07 - 2012-06-28 22:07 - 012985824 _____ () C:\Program Files (x86)\Acronis\TrueImageHome\Common\ti_managers.dll 2012-06-28 17:34 - 2012-06-28 17:34 - 000018816 _____ () C:\Program Files (x86)\Acronis\TrueImageHome\ti_managers_proxy_stub.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\ProgramData\TEMP:5C321E34 [62] ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) IE trusted site: HKU\S-1-5-21-298761936-1198288888-1608458099-1005\...\localhost -> localhost IE restricted site: HKU\S-1-5-21-298761936-1198288888-1608458099-1005\...\008i.com -> 008i.com IE restricted site: HKU\S-1-5-21-298761936-1198288888-1608458099-1005\...\008k.com -> 008k.com IE restricted site: HKU\S-1-5-21-298761936-1198288888-1608458099-1005\...\00hq.com -> 00hq.com IE restricted site: HKU\S-1-5-21-298761936-1198288888-1608458099-1005\...\0190-dialers.com -> 0190-dialers.com IE restricted site: HKU\S-1-5-21-298761936-1198288888-1608458099-1005\...\01i.info -> 01i.info IE restricted site: HKU\S-1-5-21-298761936-1198288888-1608458099-1005\...\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com IE restricted site: HKU\S-1-5-21-298761936-1198288888-1608458099-1005\...\0411dd.com -> 0411dd.com IE restricted site: HKU\S-1-5-21-298761936-1198288888-1608458099-1005\...\0511zfhl.com -> 0511zfhl.com IE restricted site: HKU\S-1-5-21-298761936-1198288888-1608458099-1005\...\05p.com -> 05p.com IE restricted site: HKU\S-1-5-21-298761936-1198288888-1608458099-1005\...\0632qyw.com -> 0632qyw.com IE restricted site: HKU\S-1-5-21-298761936-1198288888-1608458099-1005\...\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com IE restricted site: HKU\S-1-5-21-298761936-1198288888-1608458099-1005\...\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com IE restricted site: HKU\S-1-5-21-298761936-1198288888-1608458099-1005\...\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com IE restricted site: HKU\S-1-5-21-298761936-1198288888-1608458099-1005\...\0calories.net -> 0calories.net IE restricted site: HKU\S-1-5-21-298761936-1198288888-1608458099-1005\...\0cj.net -> 0cj.net IE restricted site: HKU\S-1-5-21-298761936-1198288888-1608458099-1005\...\0scan.com -> 0scan.com IE restricted site: HKU\S-1-5-21-298761936-1198288888-1608458099-1005\...\1-britney-spears-nude.com -> 1-britney-spears-nude.com IE restricted site: HKU\S-1-5-21-298761936-1198288888-1608458099-1005\...\1-domains-registrations.com -> 1-domains-registrations.com IE restricted site: HKU\S-1-5-21-298761936-1198288888-1608458099-1005\...\1-se.com -> 1-se.com IE restricted site: HKU\S-1-5-21-298761936-1198288888-1608458099-1005\...\1001movie.com -> 1001movie.com There are 6091 more sites. ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 02:34 - 2017-11-30 22:27 - 000493130 _____ C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost 0.0.0.0 fr.a2dfp.net 0.0.0.0 m.fr.a2dfp.net 0.0.0.0 mfr.a2dfp.net 0.0.0.0 ad.a8.net 0.0.0.0 asy.a8ww.net 0.0.0.0 static.a-ads.com 0.0.0.0 abcstats.com 0.0.0.0 a.abv.bg 0.0.0.0 adserver.abv.bg 0.0.0.0 adv.abv.bg 0.0.0.0 bimg.abv.bg 0.0.0.0 ca.abv.bg 0.0.0.0 track.acclaimnetwork.com 0.0.0.0 accuserveadsystem.com 0.0.0.0 www.accuserveadsystem.com 0.0.0.0 achmedia.com 0.0.0.0 csh.actiondesk.com 0.0.0.0 ads.activepower.net 0.0.0.0 ad.activesolutions.cz 0.0.0.0 app.activetrail.com 0.0.0.0 traffic.acwebconnecting.com 0.0.0.0 office.ad1.ru 0.0.0.0 cms.ad2click.nl 0.0.0.0 ad2games.com 0.0.0.0 content.ad20.net 0.0.0.0 core.ad20.net 0.0.0.0 banner.ad.nu 0.0.0.0 adadvisor.net 0.0.0.0 tag1.adaptiveads.com There are 12989 more lines. ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-298761936-1198288888-1608458099-1005\Control Panel\Desktop\\Wallpaper -> C:\Users\Paul\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: [removed] - [removed] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == MSCONFIG\startupfolder: C:^Users^Comet^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^LaunchCenter.lnk => C:\Windows\pss\LaunchCenter.lnk.Startup MSCONFIG\startupreg: Acronis Scheduler2 Service => "C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe" MSCONFIG\startupreg: AcronisTimounterMonitor => C:\Program Files (x86)\Acronis\TrueImageHome\TimounterMonitor.exe MSCONFIG\startupreg: HotKeysCmds => C:\Windows\system32\hkcmd.exe MSCONFIG\startupreg: IgfxTray => C:\Windows\system32\igfxtray.exe MSCONFIG\startupreg: Persistence => C:\Windows\system32\igfxpers.exe MSCONFIG\startupreg: RtHDVCpl => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s MSCONFIG\startupreg: TrueImageMonitor.exe => "C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [TCP Query User{BC118BB8-332E-47F0-B6FC-884BE8E45FB6}C:\program files (x86)\winamp\winamp.exe] => (Allow) C:\program files (x86)\winamp\winamp.exe FirewallRules: [UDP Query User{63F8E841-9993-400A-AE3C-0FB3BA317E89}C:\program files (x86)\winamp\winamp.exe] => (Allow) C:\program files (x86)\winamp\winamp.exe ==================== Restore Points ========================= 10-12-2017 22:28:22 Manual Restore Point ==================== Faulty Device Manager Devices ============= Name: Microsoft PS/2 Mouse Description: Microsoft PS/2 Mouse Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: i8042prt Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. ==================== Event log errors: ========================= Application errors: ================== Error: (12/09/2017 10:42:44 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Error: (12/09/2017 06:16:59 PM) (Source: Windows Search Service) (EventID: 7010) (User: ) Description: The index cannot be initialized. Details: The content index catalog is corrupt. (HRESULT : 0xc0041801) (0xc0041801) Error: (12/09/2017 06:16:59 PM) (Source: Windows Search Service) (EventID: 3058) (User: ) Description: The application cannot be initialized. Context: Windows Application Details: The content index catalog is corrupt. (HRESULT : 0xc0041801) (0xc0041801) Error: (12/09/2017 06:16:59 PM) (Source: Windows Search Service) (EventID: 3028) (User: ) Description: The gatherer object cannot be initialized. Context: Windows Application, SystemIndex Catalog Details: The content index catalog is corrupt. (HRESULT : 0xc0041801) (0xc0041801) Error: (12/09/2017 06:16:59 PM) (Source: Windows Search Service) (EventID: 3029) (User: ) Description: The plug-in in cannot be initialized. Context: Windows Application, SystemIndex Catalog Details: Element not found. (HRESULT : 0x80070490) (0x80070490) Error: (12/09/2017 06:16:59 PM) (Source: Windows Search Service) (EventID: 3029) (User: ) Description: The plug-in in cannot be initialized. Context: Windows Application, SystemIndex Catalog Details: The content index catalog is corrupt. (HRESULT : 0xc0041801) (0xc0041801) Error: (12/09/2017 06:16:59 PM) (Source: Windows Search Service) (EventID: 9002) (User: ) Description: The Windows Search Service cannot load the property store information. Context: Windows Application, SystemIndex Catalog Details: The content index database is corrupt. (HRESULT : 0xc0041800) (0xc0041800) Error: (12/09/2017 06:16:59 PM) (Source: Windows Search Service) (EventID: 7042) (User: ) Description: The Windows Search Service is being stopped because there is a problem with the indexer: The catalog is corrupt. Details: The content index catalog is corrupt. (HRESULT : 0xc0041801) (0xc0041801) Error: (12/09/2017 06:16:59 PM) (Source: Windows Search Service) (EventID: 7040) (User: ) Description: The search service has detected corrupted data files in the index {id=4700}. The service will attempt to automatically correct this problem by rebuilding the index. Details: The content index catalog is corrupt. (HRESULT : 0xc0041801) (0xc0041801) Error: (12/09/2017 06:16:59 PM) (Source: Windows Search Service) (EventID: 9000) (User: ) Description: The Windows Search Service cannot open the Jet property store. Details: 0x%08x (0xc0041800 - The content index database is corrupt. (HRESULT : 0xc0041800)) System errors: ============= Error: (12/10/2017 09:27:40 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The eapihdrv service failed to start due to the following error: This driver has been blocked from loading Error: (12/10/2017 09:27:40 PM) (Source: Application Popup) (EventID: 1060) (User: ) Description: \??\C:\Users\Paul\AppData\Local\Temp\ehdrv.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver. Error: (12/10/2017 09:27:40 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The eapihdrv service failed to start due to the following error: This driver has been blocked from loading Error: (12/10/2017 09:27:40 PM) (Source: Application Popup) (EventID: 1060) (User: ) Description: \??\C:\Users\Paul\AppData\Local\Temp\ehdrv.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver. Error: (12/10/2017 09:27:40 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The eapihdrv service failed to start due to the following error: This driver has been blocked from loading Error: (12/10/2017 09:27:40 PM) (Source: Application Popup) (EventID: 1060) (User: ) Description: \??\C:\Users\Paul\AppData\Local\Temp\ehdrv.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver. Error: (12/10/2017 09:27:39 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The eapihdrv service failed to start due to the following error: This driver has been blocked from loading Error: (12/10/2017 09:27:39 PM) (Source: Application Popup) (EventID: 1060) (User: ) Description: \??\C:\Users\Paul\AppData\Local\Temp\ehdrv.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver. Error: (12/10/2017 09:27:39 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The eapihdrv service failed to start due to the following error: This driver has been blocked from loading Error: (12/10/2017 09:27:39 PM) (Source: Application Popup) (EventID: 1060) (User: ) Description: \??\C:\Users\Paul\AppData\Local\Temp\ehdrv.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver. CodeIntegrity: =================================== Date: 2017-11-22 01:47:03.677 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\wdcsam64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2017-11-22 01:47:03.677 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\wdcsam64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i3-2120 CPU @ 3.30GHz Percentage of memory in use: 64% Total physical RAM: 4000.38 MB Available physical RAM: 1412.12 MB Total Virtual: 7998.95 MB Available Virtual: 5065.03 MB ==================== Drives ================================ Drive c: (System) (Fixed) (Total:913.85 GB) (Free:854.78 GB) NTFS ==>[system with boot components (obtained from drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: B477DB1C) Partition 1: (Active) - (Size=2 GB) - (Type=27) Partition 3: (Not Active) - (Size=929.5 GB) - (Type=05) ==================== End of Addition.txt ============================