Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02.08.2018 Ran by [removed] (10-08-2018 13:58:09) Running from C:\Users\[removed]\Downloads Windows 8.1 (Update) (X64) (2014-05-16 09:06:20) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-28108215-2538129268-678420320-500 - Administrator - Disabled) CrisYouSasyMedic (S-1-5-21-28108215-2538129268-678420320-1002 - Administrator - Enabled) => C:\Users\CrisYouSasyMedic CrisY_000 (S-1-5-21-28108215-2538129268-678420320-1003 - Limited - Enabled) Guest (S-1-5-21-28108215-2538129268-678420320-501 - Limited - Disabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Kaspersky Anti-Virus (Enabled - Up to date) {86367591-4BE4-AE08-2FD9-7FCB8259CD98} AV: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Kaspersky Anti-Virus (Enabled - Up to date) {3D579475-6DDE-A186-1569-44B9F9DE8725} AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 4 Elements II (HKLM-x32\...\WTA-545aa1e8-471e-4efc-9132-05ed45152c29) (Version: 2.2.0.98 - WildTangent) Hidden 7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov) Adobe Flash Player 30 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 30.0.0.134 - Adobe Systems Incorporated) Adobe Shockwave Player 12.0 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.0.4.144 - Adobe Systems, Inc.) Airport Mania (HKLM-x32\...\WTA-1e350cce-7b1c-4aba-800c-48716cc60bcc) (Version: 2.2.0.95 - WildTangent) Hidden AMD Software (HKLM\...\AMD Catalyst Install Manager) (Version: 9.0.000.8 - Advanced Micro Devices, Inc.) Amnesia - The Dark Descent (HKLM-x32\...\{759FC370-E77F-4FB0-A1E4-C0628A44BA44}) (Version: 1.00.0000 - Valusoft) Azkend 2: The World Beneath (HKLM-x32\...\WTA-31e4b974-5ded-4ae1-b46b-5ff648b1c47f) (Version: 2.2.0.98 - WildTangent) Hidden Bejeweled 3 (HKLM-x32\...\WTA-e7e48931-095a-4f37-8a4f-5cec7d34907d) (Version: 2.2.0.98 - WildTangent) Hidden Big Fish: Game Manager (HKLM-x32\...\BFGC) (Version: 3.3.0.2 - ) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Bounce Symphony (HKLM-x32\...\WTA-8c19759a-cabd-43b3-bd5d-b7053214531c) (Version: 2.2.0.97 - WildTangent) Hidden Britannica World's Best Solitaire (HKLM-x32\...\World's Best Solitaire) (Version: 2.00.07.01.23 - Selectsoft Publishing) Build-a-lot (HKLM-x32\...\WTA-0c411bb9-99b4-41e0-87f8-cf5a0fdcaeb7) (Version: 2.2.0.98 - WildTangent) Hidden Catalyst Control Center Next Localization BR (HKLM\...\{B3404CFD-64B2-138C-22EC-64EBAF2DF5D7}) (Version: 2016.1223.1240.22785 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CHS (HKLM\...\{4F374250-3B97-160A-5D2A-452AE7E70ED7}) (Version: 2016.1223.1240.22785 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CHT (HKLM\...\{DBFEE72E-7001-28DC-88FF-777621EA148E}) (Version: 2016.1223.1240.22785 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CS (HKLM\...\{AB77F5E4-CDCF-F6FA-4D3E-36A6BB9EEF50}) (Version: 2016.1223.1240.22785 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization DA (HKLM\...\{8193166C-B615-0D56-70D1-F908F34C4E5B}) (Version: 2016.1223.1240.22785 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization DE (HKLM\...\{C52624B1-12DB-AA8B-449E-08CA0FD2E50E}) (Version: 2016.1223.1240.22785 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization EL (HKLM\...\{8EB916C5-A52A-8A98-BDC5-8856A19AAA3A}) (Version: 2016.1223.1240.22785 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization ES (HKLM\...\{228882CB-19B2-EE92-C820-03D8E2BF101B}) (Version: 2016.1223.1240.22785 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization FI (HKLM\...\{CB6E1114-058D-D311-FC1A-D98C003328C8}) (Version: 2016.1223.1240.22785 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization FR (HKLM\...\{AD0AA617-CCDA-8FA5-9A82-1F6FFB8F7660}) (Version: 2016.1223.1240.22785 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization HU (HKLM\...\{E65DD8F5-F185-362F-5FE7-00627C73ED7C}) (Version: 2016.1223.1240.22785 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization IT (HKLM\...\{88D3DDCC-8BB4-3228-D407-7A04B9B8A6E6}) (Version: 2016.1223.1240.22785 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization JA (HKLM\...\{539FE6EE-0BD2-6F1F-A48B-78D2CCAFD9BD}) (Version: 2016.1223.1240.22785 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization KO (HKLM\...\{C617CA3A-1296-7DFD-990F-F27A00E5FCA1}) (Version: 2016.1223.1240.22785 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization NL (HKLM\...\{91548629-F93E-5E9A-2F3B-C226488F8805}) (Version: 2016.1223.1240.22785 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization NO (HKLM\...\{8A112EC0-D20F-1545-5F13-BBA0006FB3BD}) (Version: 2016.1223.1240.22785 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization PL (HKLM\...\{F1E1C881-6A24-CA60-58BF-6005B654CBEC}) (Version: 2016.1223.1240.22785 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization RU (HKLM\...\{1A4779F8-961C-9FEF-4056-30B9A393F292}) (Version: 2016.1223.1240.22785 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization SV (HKLM\...\{014A1FFF-4B25-00C0-D744-434AE84E842B}) (Version: 2016.1223.1240.22785 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization TH (HKLM\...\{BF020F1B-4402-A4FD-2C8D-5B09561E113A}) (Version: 2016.1223.1240.22785 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization TR (HKLM\...\{24ECF4ED-85F7-F6D1-A82D-567187220178}) (Version: 2016.1223.1240.22785 - Advanced Micro Devices, Inc.) Hidden Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.) Cisco LEAP Module (HKLM-x32\...\{AF312B06-5C5C-468E-89B3-BE6DE2645722}) (Version: 1.0.19 - Cisco Systems, Inc.) Cisco PEAP Module (HKLM-x32\...\{0A4EF0E6-A912-4CDE-A7F3-6E56E7C13A2F}) (Version: 1.1.6 - Cisco Systems, Inc.) Cobian Backup 11 Gravity (HKLM-x32\...\CobBackup11) (Version: - ) Cradle Of Egypt Collector's Edition (HKLM-x32\...\WTA-a7a7a624-9c9a-4a09-b37e-5018aac5e0ca) (Version: 2.2.0.110 - WildTangent) Hidden Cradle of Rome 2 (HKLM-x32\...\WTA-5ce6c8ea-49a4-49ae-a2a0-63135c500875) (Version: 2.2.0.98 - WildTangent) Hidden Curse at Twilight (HKLM-x32\...\WTA-1c705dda-d638-41bc-a916-f43c491cb09a) (Version: 3.0.2.32 - WildTangent) Hidden Cursed Fates - The Headless Horseman (HKLM-x32\...\Cursed Fates - The Headless Horseman) (Version: - ) CyberLink LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.5.6902 - CyberLink Corp.) CyberLink Media Suite 10 (HKLM-x32\...\InstallShield_{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}) (Version: 10.0.9.4928 - CyberLink Corp.) CyberLink Power Media Player 12 (HKLM-x32\...\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}) (Version: 12.0.6.5104 - CyberLink Corp.) CyberLink Power2Go 8 (HKLM-x32\...\InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}) (Version: 8.0.10.5422 - CyberLink Corp.) CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 5.0.6.5011 - CyberLink Corp.) D3DX10 (HKLM-x32\...\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden Dark Dimensions: City of Fog (HKLM-x32\...\BFG-Dark Dimensions - City of Fog) (Version: - ) Dark Mysteries - The Soul Keeper (HKLM-x32\...\Dark Mysteries - The Soul Keeper) (Version: - ) Dark Tales: Edgar Allan Poes The Premature Burial (HKLM-x32\...\BFG-Dark Tales - Edgar Allan Poes The Premature Burial) (Version: - ) Dark Tales: ™ Edgar Allan Poe's The Black Cat (HKLM-x32\...\BFG-Dark Tales - Edgar Allan Poe's The Black Cat) (Version: - ) Delicious: Emily's Childhood Memories Premium Edition (HKLM-x32\...\WTA-d6fcbbb6-022d-4052-abfb-445d19c7578d) (Version: 3.0.2.32 - WildTangent) Hidden DisableMSDefender (HKLM\...\{74FE39A0-FB76-47CD-84BA-91E2BBB17EF2}) (Version: 1.0.0 - Hewlett-Packard Company) Hidden Echoes of Sorrow (HKLM-x32\...\Echoes of Sorrow) (Version: 1.0 - Alawar Entertainment Inc.) Energy Star (HKLM-x32\...\{FC0ADA4D-8FA5-4452-8AFF-F0A0BAC97EF7}) (Version: 1.0.9 - Hewlett-Packard Company) F.A.C.E.S. Collector's Edition (HKLM-x32\...\BFG-F.A.C.E.S. Collector's Edition) (Version: - ) Farm Frenzy (HKLM-x32\...\WTA-c878aac2-8d29-448a-b55c-6ced49637f6d) (Version: 2.2.0.98 - WildTangent) Hidden Fishdom 3: Collector's Edition (HKLM-x32\...\WTA-22115ff0-9e95-4430-83e0-8c15907f00ed) (Version: 3.0.2.38 - WildTangent) Hidden Google Chrome (HKLM-x32\...\Google Chrome) (Version: 68.0.3440.106 - Google Inc.) Google Earth Pro (HKLM\...\{F914BC59-918A-498F-B2E3-B274C9CB48A8}) (Version: 7.3.2.5491 - Google) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.17 - Google Inc.) Hidden Governor of Poker 2 Premium Edition (HKLM-x32\...\WTA-a6e76048-f70e-40a5-82eb-84d2c73ebbda) (Version: 2.2.0.110 - WildTangent) Hidden Gravely Silent: House of Deadlock Collector's Edition (HKLM-x32\...\BFG-Gravely Silent - House of Deadlock Collector's Edition) (Version: - ) Grim Tales: The Bride (HKLM-x32\...\BFG-Grim Tales - The Bride) (Version: - ) Grim Tales: The Legacy (HKLM-x32\...\BFG-Grim Tales - The Legacy) (Version: - ) Haunted Halls: Green Hills Sanitarium (HKLM-x32\...\BFG-Haunted Halls - Green Hills Sanitarium) (Version: - ) Haunted Halls: Green Hills Sanitarium Strategy Guide (HKLM-x32\...\BFG-Haunted Halls - Green Hills Sanitarium Strategy Guide) (Version: - ) Haunted Legends: The Bronze Horseman Collectors Edition (HKLM-x32\...\BFG-Haunted Legends - The Bronze Horseman Collectors Edition) (Version: - ) Haunted Legends: The Queen of Spades (HKLM-x32\...\BFG-Haunted Legends - The Queen of Spades) (Version: - ) Haunted Manor: Lord of Mirrors (HKLM-x32\...\BFG-Haunted Manor - Lord of Mirrors) (Version: - ) Hewlett-Packard ACLM.NET v1.2.2.3 (HKLM-x32\...\{6F340107-F9AA-47C6-B54C-C3A19F11553F}) (Version: 1.00.0000 - Hewlett-Packard Company) Hidden House of 1000 Doors: Family Secrets (HKLM-x32\...\WTA-3eb54275-1f3d-47ab-8e8c-6b37c2d659be) (Version: 2.2.0.98 - WildTangent) Hidden HP Documentation (HKLM-x32\...\{D82B396E-A647-4C81-9DA4-C61F7BB620EC}) (Version: 1.1.0.0 - Hewlett-Packard) HP Registration Service (HKLM\...\{D1E8F2D7-7794-4245-B286-87ED86C1893C}) (Version: 1.2.7127.4628 - Hewlett-Packard) HP SimplePass (HKLM-x32\...\InstallShield_{314FAD12-F785-4471-BCE8-AB506642B9A1}) (Version: 8.00.57 - Hewlett-Packard) HP Support Assistant (HKLM-x32\...\{E959FD01-BD01-4CC4-9BB8-4EBE8309BF37}) (Version: 8.6.18.11 - HP) HP Support Solutions Framework (HKLM-x32\...\{E2CB09C1-3C76-4395-BB47-50C066535CF8}) (Version: 12.9.24.3 - HP) HP System Event Utility (HKLM-x32\...\{09D0DB68-90EA-4015-983E-A0BD777D5A02}) (Version: 1.4.10 - HP Inc.) HP Touchpoint Analytics Client (HKLM\...\{E5FB98E0-0784-44F0-8CEC-95CD4690C43F}) (Version: 4.0.2.1439 - HP Inc.) HP Utility Center (HKLM\...\{1D7EB7E7-0B5D-4A23-A383-7EF133090026}) (Version: 2.3.2 - Hewlett-Packard Company) HP Wireless Button Driver (HKLM-x32\...\{EFA01423-3857-468C-B7B6-F30AA08E50BC}) (Version: 1.1.5.1 - Hewlett-Packard) Inst5675 (HKLM\...\{2DE6247C-7077-451B-8BA7-FFD1A2ABBB47}) (Version: 8.00.57 - Softex Inc.) Hidden Inst5676 (HKLM\...\{878F6913-7421-4713-97F7-0A736EE2A188}) (Version: 8.00.57 - Softex Inc.) Hidden Jewel Match 3 (HKLM-x32\...\WTA-53496468-739f-4daf-9999-b9823f027c89) (Version: 2.2.0.98 - WildTangent) Hidden John Deere Drive Green (HKLM-x32\...\WTA-a2762c91-c502-413d-b757-56b815bdf8e7) (Version: 2.2.0.95 - WildTangent) Hidden Kaspersky Anti-Virus (HKLM-x32\...\{5AAE61FF-858E-453E-B8F3-944618149975}) (Version: 18.0.0.405 - Kaspersky Lab) Hidden Kaspersky Anti-Virus (HKLM-x32\...\InstallWIX_{5AAE61FF-858E-453E-B8F3-944618149975}) (Version: 18.0.0.405 - Kaspersky Lab) Kaspersky Secure Connection (HKLM-x32\...\{F33C0717-8E04-4EB5-90C8-47221287DB4F}) (Version: 18.0.0.405 - Kaspersky Lab) Hidden Kaspersky Secure Connection (HKLM-x32\...\InstallWIX_{F33C0717-8E04-4EB5-90C8-47221287DB4F}) (Version: 18.0.0.405 - Kaspersky Lab) King Oddball (HKLM-x32\...\WTA-907c9196-a16f-45e5-a836-05147a403026) (Version: 3.0.2.48 - WildTangent) Hidden Lost Souls - Enchanted Paintings (HKLM-x32\...\Lost Souls - Enchanted Paintings) (Version: - ) Luxor Evolved (HKLM-x32\...\WTA-9eb69b18-6608-4ff1-8350-e995d8ababd0) (Version: 2.2.0.98 - WildTangent) Hidden Mahjongg Dimensions Deluxe (HKLM-x32\...\WTA-23824612-adb6-4c7f-82f1-9dd8c09a2271) (Version: 2.2.0.95 - WildTangent) Hidden Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4454.1510 - Microsoft Corporation) Microsoft Office Professional Edition 2003 (HKLM-x32\...\{90110409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Movie Maker (HKLM-x32\...\{45898170-E68C-4F02-AA35-C2186BF347A3}) (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Movie Maker (HKLM-x32\...\{B39A6825-EA20-43EA-AB2D-A6BC0298D9A1}) (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Mozilla Firefox 61.0.2 (x64 en-US) (HKLM\...\Mozilla Firefox 61.0.2 (x64 en-US)) (Version: 61.0.2 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 56.0.2 - Mozilla) Muvic Smartbar (HKLM-x32\...\{1EB8010A-F431-4F8F-874A-506B2B51F3D2}) (Version: 11.51.58.16919 - PinWid Ltd.) <==== ATTENTION Muvic Smartbar Engine (HKU\S-1-5-21-28108215-2538129268-678420320-1002\...\{08998c2c-b970-4110-8c1f-7a405e284254}) (Version: 11.51.58.16919 - PinWid Ltd.) <==== ATTENTION Mystery Case Files: Escape from Ravenhearst (HKLM-x32\...\BFG-Mystery Case Files - Escape from Ravenhearst) (Version: - ) Mystery Case Files: Return to Ravenhearst ™ (HKLM-x32\...\BFG-Mystery Case Files - Return to Ravenhearst) (Version: - ) Mystery Legends: Beauty and the Beast (HKLM-x32\...\BFG-Mystery Legends - Beauty and the Beast) (Version: - ) Mystery P.I. - Curious Case of Counterfeit Cove (HKLM-x32\...\WTA-50c81989-bd06-4041-8bdb-eda6e3d4d7c6) (Version: 2.2.0.98 - WildTangent) Hidden Mystery Stories - Mountains of Madness (HKLM-x32\...\Mystery Stories - Mountains of Madness) (Version: - ) OEM Application Profile (HKLM-x32\...\{70D5F822-F4C4-33D9-7EEC-2A4AF4EA7BDC}) (Version: 1.00.0000 - Advanced Micro Devices, Inc.) OEM Application Profile (HKLM-x32\...\{8F92E0CF-620B-5C20-F292-59C93567B06D}) (Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden Peggle Nights (HKLM-x32\...\WTA-0e60c1aa-64c9-4531-9872-3a621c04d3ad) (Version: 2.2.0.98 - WildTangent) Hidden Penguins! (HKLM-x32\...\WTA-d3d51d38-13a3-439b-bae0-0bed6cb0d74c) (Version: 2.2.0.98 - WildTangent) Hidden Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9.141.259 - Google, Inc.) Pinger (HKLM-x32\...\{9B56B031-A6C0-4BB7-8F61-938548C1B759}) (Version: 1.4.0.1 - Pinger Inc.) Hidden Pinger (HKLM-x32\...\Pinger 1.4.0.1) (Version: 1.4.0.1 - Pinger Inc.) Plants vs. Zombies - Game of the Year (HKLM-x32\...\WTA-d59a1ddd-8827-4478-848e-257c8f7479e0) (Version: 2.2.0.98 - WildTangent) Hidden Polar Bowler (HKLM-x32\...\WTA-f8868715-8d23-4c71-af13-b5a6c2175bd3) (Version: 2.2.0.97 - WildTangent) Hidden Punch! Home and Landscape (HKLM-x32\...\{5AB52F3C-23C7-4FB2-9285-C0C0635CABCC}) (Version: 15.0.2 - Punch! Software, LLC) Puran File Recovery 1.2.1 (HKLM\...\Puran File Recovery_is1) (Version: - Puran Software) Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.3.9600.29082 - Realtek Semiconductor Corp.) Realtek Ethernet Controller All-In-One Windows Driver (HKLM-x32\...\{F7E7F0CB-AA41-4D5A-B6F2-8E6738EB063F}) (Version: 8.35.716.2014 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7730 - Realtek Semiconductor Corp.) REALTEK Wireless LAN Driver (HKLM-x32\...\{A5107464-AA9B-4177-8129-5FF2F42DD322}) (Version: 1.0.0.38 - REALTEK Semiconductor Corp.) Recuva (HKLM\...\Recuva) (Version: 1.53 - Piriform) Redemption Cemetery: Curse of the Raven (HKLM-x32\...\BFG-Redemption Cemetery - Curse of the Raven) (Version: - ) Redemption Cemetery: Grave Testimony (HKLM-x32\...\BFG-Redemption Cemetery - Grave Testimony) (Version: - ) Redemption Cemetery: Salvation of the Lost (HKLM-x32\...\BFG-Redemption Cemetery - Salvation of the Lost) (Version: - ) RGMUpdater Monetization Control (HKLM-x32\...\RGMUpdater Monetization Controlcc56729e-9fc2-4c79-a5a8-77edc7087390) (Version: 2.2.0322.1140 - ) Roads of Rome 3 (HKLM-x32\...\WTA-70ef15d1-43a2-4071-8a27-85587e95d13e) (Version: 2.2.0.98 - WildTangent) Hidden Save Our Spirit (HKLM-x32\...\Save Our Spirit) (Version: - ) Shadow Wolf Mysteries: Bane of the Family (HKLM-x32\...\BFG-Shadow Wolf Mysteries - Bane of the Family) (Version: - ) Shadow Wolf Mysteries: Curse of the Full Moon (HKLM-x32\...\BFG-Shadow Wolf Mysteries - Curse of the Full Moon) (Version: - ) Shockwave (HKLM-x32\...\Shockwave) (Version: - ) Spirits of Mystery: Amber Maiden (HKLM-x32\...\BFG-Spirits of Mystery - Amber Maiden) (Version: - ) Spirits of Mystery: Song of the Phoenix (HKLM-x32\...\BFG-Spirits of Mystery - Song of the Phoenix) (Version: - ) Spirits of Mystery: The Dark Minotaur (HKLM-x32\...\BFG-Spirits of Mystery - The Dark Minotaur) (Version: - ) Stray Souls: Dollhouse Story (HKLM-x32\...\Stray Souls: Dollhouse Story) (Version: 1.0 - Alawar Entertainment Inc.) swMSM (HKLM-x32\...\{612C34C7-5E90-47D8-9B5C-0F717DD82726}) (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 18.1.7.20 - Synaptics Incorporated) Tales of Lagoona (HKLM-x32\...\WTA-872c36de-ad44-4735-9234-d2cb8c4438f9) (Version: 2.2.0.110 - WildTangent) Hidden The Stanwick Mystery (HKLM-x32\...\The Stanwick Mystery) (Version: - ) The Treasures of Mystery Island: The Ghost Ship (HKLM-x32\...\The Treasures of Mystery Island: The Ghost Ship) (Version: 1.0 - Alawar Entertainment Inc.) Theatre of the Absurd (HKLM-x32\...\Theatre of the Absurd) (Version: - ) Tweaking.com - Registry Backup (HKLM-x32\...\Tweaking.com - Registry Backup) (Version: 3.5.3 - Tweaking.com) Twisted Lands: Shadow Town (HKLM-x32\...\Twisted Lands: Shadow Town) (Version: - Alawar Entertainment Inc.) Vacation Quest™ - Australia (HKLM-x32\...\WTA-042253bf-b369-4a76-8a8d-34385b3a27fe) (Version: 3.0.2.32 - WildTangent) Hidden VIVA MEDIA GAME CENTER (HKLM-x32\...\VIVAGplayer) (Version: 1.2010.6.23 - INTENIUM GmbH) VLC media player (HKLM-x32\...\VLC media player) (Version: 3.0.3 - VideoLAN) Vulkan Run Time Libraries 1.0.26.0 (HKLM\...\VulkanRT1.0.26.0) (Version: 1.0.26.0 - LunarG, Inc.) WildTangent Games (HKLM-x32\...\WildTangent wildgames Master Uninstall) (Version: 1.0.4.0 - WildTangent) WildTangent Games App (HP Games) (HKLM-x32\...\{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-hp) (Version: 4.0.10.15 - WildTangent) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3508.0205 - Microsoft Corporation) Windows Media Player and Options (HKLM\...\Windows_Media_Player_and_Options) (Version: 1.0 - Windows Media Player) Youda Jewel Shop (HKLM-x32\...\WTA-6e9486f2-21c3-4e1b-9e8e-05e37eae6809) (Version: 3.0.2.32 - WildTangent) Hidden Zuma's Revenge (HKLM-x32\...\WTA-b45c4bdc-7269-49b7-9ac0-6eec63e53b26) (Version: 2.2.0.98 - WildTangent) Hidden ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2010-11-18] (Igor Pavlov) ContextMenuHandlers1: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} => C:\Program Files (x86)\Common Files\CyberLink\ShellExtComponent\CLVDShellExt_20160726_23_29_18.dll [2016-07-26] (Cyberlink) ContextMenuHandlers1: [Kaspersky Anti-Virus 18.0.0] -> {FF48AD48-74C7-4260-B385-FAEB80947450} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 18.0.0\x64\ShellEx.dll [2018-05-04] (AO Kaspersky Lab) ContextMenuHandlers2: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} => C:\Program Files (x86)\Common Files\CyberLink\ShellExtComponent\CLVDShellExt_20160726_23_29_18.dll [2016-07-26] (Cyberlink) ContextMenuHandlers2: [Kaspersky Anti-Virus 18.0.0] -> {FF48AD48-74C7-4260-B385-FAEB80947450} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 18.0.0\x64\ShellEx.dll [2018-05-04] (AO Kaspersky Lab) ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2010-11-18] (Igor Pavlov) ContextMenuHandlers4: [Kaspersky Anti-Virus 18.0.0] -> {FF48AD48-74C7-4260-B385-FAEB80947450} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 18.0.0\x64\ShellEx.dll [2018-05-04] (AO Kaspersky Lab) ContextMenuHandlers4: [RecuvaShellExt] -> {435E5DF5-2510-463C-B223-BDA47006D002} => C:\Program Files\Recuva\RecuvaShell64.dll [2016-06-06] (Piriform Ltd) ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Program Files\AMD\CNext\CNext\atiacm64.dll [2016-12-23] (Advanced Micro Devices, Inc.) ContextMenuHandlers6: [Kaspersky Anti-Virus 18.0.0] -> {FF48AD48-74C7-4260-B385-FAEB80947450} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 18.0.0\x64\ShellEx.dll [2018-05-04] (AO Kaspersky Lab) ContextMenuHandlers6: [RecuvaShellExt] -> {435E5DF5-2510-463C-B223-BDA47006D002} => C:\Program Files\Recuva\RecuvaShell64.dll [2016-06-06] (Piriform Ltd) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {157C072F-ADE3-40C5-8DDD-BAC608569C41} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Product Configurator => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\ProductConfig.exe [2018-06-27] (HP Inc.) Task: {25940008-B69A-46C8-A4FE-E19A35CAA1B5} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-07-10] (Adobe Systems Incorporated) Task: {49C6ADC9-64BF-4BA0-BBED-3B1D38F030C6} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-03-05] (Google Inc.) Task: {5F8FDCCD-D512-4A42-9A90-AED8B8297044} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2018-06-28] (HP Inc.) Task: {698ABD70-AA44-4AAD-87E0-FEB0F98BFD31} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater - Resources => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2017-09-20] (HP Inc.) Task: {84B69169-74D2-4D2F-B612-4FBB73350FB4} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-03-05] (Google Inc.) Task: {87718BE5-2B95-45CA-982D-D19DE708AE26} - System32\Tasks\Hewlett-Packard\HP Active Health\HP Active Health Scan (HPSA) => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.exe [2017-11-17] () Task: {8844EE5A-F9EE-4058-A422-0A365F466695} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_30_0_0_134_Plugin.exe [2018-07-10] (Adobe Systems Incorporated) Task: {8B3E53B9-12C4-4EB2-994F-B00E1CAC9C2E} - System32\Tasks\YCMServiceAgent => C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe [2015-02-11] (CyberLink Corp.) Task: {8DBBF1B1-72E2-4AC3-8A32-F2BC7CFC3C54} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [2017-06-22] (HP Inc.) Task: {8FE2DA95-8D83-4D96-BE2D-FEB3868BAF6C} - System32\Tasks\AdwCleaner_onReboot => C:\Users\CrisYouSasyMedic\Downloads\AdwCleaner.exe [2018-08-10] (Malwarebytes) Task: {A9A19964-88D2-400B-B24C-38354CA2CFA6} - System32\Tasks\Synaptics TouchPad Enhancements => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2015-07-11] (Synaptics Incorporated) Task: {AC455EC3-D9E1-436B-95D0-A3408D1EE9E4} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2018-05-04] (HP Inc.) Task: {BA19CE9A-AFD5-4F8E-8375-E57FCE9BA91B} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis Restart => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2018-05-04] (HP Inc.) Task: {BB3451E7-B4B6-4DBB-9196-BA968BE31E75} - System32\Tasks\HPCeeScheduleForCrisYouSasyMedic => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2015-06-16] (Hewlett-Packard) Task: {C646E56B-43EE-408F-8652-409E45EEC921} - System32\Tasks\Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901} => C:\Program Files\Common Files\AV\Kaspersky Lab\upgrade_launcher.exe [2018-01-19] (AO Kaspersky Lab) Task: {C6ACC884-109C-43C5-86BA-2D209CA88B41} - System32\Tasks\SnoopRun => C:\ProgramData\Snoop\Snoop.exe [2015-05-20] () <==== ATTENTION Task: {EC3BE2BC-4F14-454A-9A88-DB88B654BB61} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2018-05-04] (HP Inc.) Task: {EC5F3C92-7B21-47A4-831F-2357E638FAC5} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe [2016-12-23] (Advanced Micro Devices, Inc.) Task: {F31F0122-E83C-4FF7-81C1-05B3CF6A59CA} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2017-09-20] (HP Inc.) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\HPCeeScheduleForCrisYouSasyMedic.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe ==================== Shortcuts & WMI ======================== (The entries could be listed to be restored or removed.) Shortcut: C:\Users\CrisYouSasyMedic\AppData\Roaming\Microsoft\Windows\Network Shortcuts\My Web Sites on MSN\target.lnk -> hxxp://www.msnusers.co ==================== Loaded Modules (Whitelisted) ============== 2018-01-19 00:15 - 2018-01-19 00:15 - 000836968 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 18.0.0\kpcengine.2.3.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\ProgramData\Temp:11590865 [177] AlternateDataStreams: C:\ProgramData\Temp:1416AAA6 [330] AlternateDataStreams: C:\ProgramData\Temp:2AD33723 [162] AlternateDataStreams: C:\ProgramData\Temp:2AF322BF [312] AlternateDataStreams: C:\ProgramData\Temp:2CB9631F [134] AlternateDataStreams: C:\ProgramData\Temp:363E775E [182] AlternateDataStreams: C:\ProgramData\Temp:3EC5BC08 [344] AlternateDataStreams: C:\ProgramData\Temp:491270B8 [314] AlternateDataStreams: C:\ProgramData\Temp:5E73E1C2 [182] AlternateDataStreams: C:\ProgramData\Temp:6B709AD7 [346] AlternateDataStreams: C:\ProgramData\Temp:7687A3E3 [382] AlternateDataStreams: C:\ProgramData\Temp:98CF1A39 [189] AlternateDataStreams: C:\ProgramData\Temp:9DBE6481 [130] AlternateDataStreams: C:\ProgramData\Temp:A4AF8D0D [165] AlternateDataStreams: C:\ProgramData\Temp:A6D6E537 [177] AlternateDataStreams: C:\ProgramData\Temp:A7DA2BCD [334] AlternateDataStreams: C:\ProgramData\Temp:A88BE334 [316] AlternateDataStreams: C:\ProgramData\Temp:B54E4B5A [342] AlternateDataStreams: C:\ProgramData\Temp:B6E6C4EA [179] AlternateDataStreams: C:\ProgramData\Temp:BEE39E9B [364] AlternateDataStreams: C:\ProgramData\Temp:C22674B6 [294] AlternateDataStreams: C:\ProgramData\Temp:C3899C0B [171] AlternateDataStreams: C:\ProgramData\Temp:C78DADEA [178] AlternateDataStreams: C:\ProgramData\Temp:CAC06C34 [177] AlternateDataStreams: C:\ProgramData\Temp:CBAF0C30 [183] AlternateDataStreams: C:\ProgramData\Temp:F5D01D7C [384] AlternateDataStreams: C:\ProgramData\Temp:F84B8DB5 [155] AlternateDataStreams: C:\ProgramData\Temp:F9F58B80 [180] AlternateDataStreams: C:\ProgramData\Temp:FAB64002 [146] AlternateDataStreams: C:\ProgramData\Temp:FBD274CF [171] AlternateDataStreams: C:\ProgramData\Temp:FC70A22A [370] ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""="" ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2013-08-22 06:25 - 2017-12-21 15:49 - 000000828 _____ C:\Windows\system32\Drivers\etc\hosts ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-28108215-2538129268-678420320-1002\Control Panel\Desktop\\Wallpaper -> C:\Users\CrisYouSasyMedic\AppData\Roaming\Microsoft\Windows Photo Viewer\Windows Photo Viewer Wallpaper.jpg DNS Servers: 192.168.0.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == MSCONFIG\Services: gupdate => 2 MSCONFIG\Services: gupdatem => 3 MSCONFIG\Services: gusvc => 3 HKLM\...\StartupApproved\StartupFolder: => "McAfee Security Scan Plus.lnk" HKLM\...\StartupApproved\Run32: => "YouCam Service" HKU\S-1-5-21-28108215-2538129268-678420320-1002\...\StartupApproved\Run: => "Google+ Auto Backup" HKU\S-1-5-21-28108215-2538129268-678420320-1002\...\StartupApproved\Run: => "Power2GoExpress8" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{24923E29-0F7A-421E-A76A-767933901AB8}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe FirewallRules: [{CC0F9C4B-D164-4F83-A55D-D87127AFD8BA}] => (Allow) LPort=2869 FirewallRules: [{363FA916-6FDD-4C77-ABC1-526528DEDAB9}] => (Allow) LPort=1900 FirewallRules: [{D748616C-2F0C-4249-A544-784F5E97AFEA}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{12978DEF-9119-451A-83B3-B7D82A72B9E2}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{7493C0AD-1994-4336-9041-B01F30BF2E39}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{A8574F11-9CBB-442E-B9EC-DCD8397DBCEE}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{F57B076A-6497-45EA-B125-62955C24C2AD}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe FirewallRules: [{EE6C99D9-22CF-4C29-AB3E-38DECFA38F28}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe FirewallRules: [{E12649A7-5D39-4027-84B7-B7F4BEDDA31E}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe FirewallRules: [{BA62EBB9-D39B-4E33-833F-3494D2094622}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe FirewallRules: [{1A204196-7661-4019-86E4-55A50EB63ED7}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12.exe FirewallRules: [{E4D15090-59F4-409B-A3EF-BDD0ACB30DC4}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe FirewallRules: [{80AB0DE4-E7E6-404B-9A82-83EEF8667756}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12ML.exe FirewallRules: [{A8122D55-EF7B-424B-911B-1E084CC80487}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Movie\PowerDVD.exe FirewallRules: [{DAA686F6-88E4-49A6-B734-2BE10C02B610}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{8B470643-88E6-41FC-9535-0BA4EBD9447E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{BE72A120-555C-4C9F-A54D-AD2B59379358}] => (Block) LPort=445 FirewallRules: [{064D5996-D9F7-4DDE-B27A-02F58499BAD2}] => (Block) LPort=445 FirewallRules: [{5D9326FC-0BFA-4454-8E6C-1653F636B35C}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [TCP Query User{A012EE80-1EA2-45CF-9FF4-88E1D5F6EE02}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe FirewallRules: [UDP Query User{12A36C46-086A-44EF-8C0F-31E8ED13B0B6}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe FirewallRules: [{B88F800C-2C14-4D9D-976F-99277680BBE1}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Restore Points ========================= 24-07-2018 22:58:07 Scheduled Checkpoint 03-08-2018 12:08:13 Scheduled Checkpoint ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (08/10/2018 12:48:17 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: RadeonSettings.exe, version: 10.1.1.1666, time stamp: 0x585d6113 Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000 Exception code: 0xc0000005 Fault offset: 0x0000000000000000 Faulting process id: 0x22c8 Faulting application start time: 0x01d430e1da8d1b34 Faulting application path: C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe Faulting module path: unknown Report Id: 5321e4f1-9cd6-11e8-840d-a01d4808520a Faulting package full name: Faulting package-relative application ID: Error: (08/09/2018 04:30:44 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: PHOEBE) Description: Activation of app microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 failed with error: -2144927141 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (08/09/2018 01:56:41 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: RadeonSettings.exe, version: 10.1.1.1666, time stamp: 0x585d6113 Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000 Exception code: 0xc0000005 Fault offset: 0x0000000000000000 Faulting process id: 0x3248 Faulting application start time: 0x01d43022771eff79 Faulting application path: C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe Faulting module path: unknown Report Id: b6b17c43-9c16-11e8-840d-a01d4808520a Faulting package full name: Faulting package-relative application ID: Error: (08/07/2018 09:43:19 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: RadeonSettings.exe, version: 10.1.1.1666, time stamp: 0x585d6113 Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000 Exception code: 0xc0000005 Fault offset: 0x0000000000000000 Faulting process id: 0x3618 Faulting application start time: 0x01d42ed128031f71 Faulting application path: C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe Faulting module path: unknown Report Id: 92421da9-9ac5-11e8-840d-a01d4808520a Faulting package full name: Faulting package-relative application ID: Error: (08/07/2018 02:54:28 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: FileManager.exe, version: 6.3.9600.17418, time stamp: 0x5458237f Faulting module name: ntdll.dll, version: 6.3.9600.18895, time stamp: 0x5a4b1b67 Exception code: 0xc000000d Fault offset: 0x0000000000102c10 Faulting process id: 0x2664 Faulting application start time: 0x01d42e992577fa01 Faulting application path: C:\Windows\FileManager\FileManager.exe Faulting module path: C:\Windows\SYSTEM32\ntdll.dll Report Id: 74976db4-9a8c-11e8-840d-a01d4808520a Faulting package full name: FileManager_6.3.9600.16384_neutral_neutral_cw5n1h2txyewy Faulting package-relative application ID: Microsoft.Windows.FileManager Error: (08/07/2018 02:05:32 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: RadeonSettings.exe, version: 10.1.1.1666, time stamp: 0x585d6113 Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000 Exception code: 0xc0000005 Fault offset: 0x0000000000000000 Faulting process id: 0x2dec Faulting application start time: 0x01d42e91967aae8e Faulting application path: C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe Faulting module path: unknown Report Id: 9e9d8ad8-9a85-11e8-840d-a01d4808520a Faulting package full name: Faulting package-relative application ID: Error: (08/07/2018 11:36:23 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: RadeonSettings.exe, version: 10.1.1.1666, time stamp: 0x585d6113 Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000 Exception code: 0xc0000005 Fault offset: 0x0000000000000000 Faulting process id: 0x2454 Faulting application start time: 0x01d42e7cac0fb68f Faulting application path: C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe Faulting module path: unknown Report Id: c87c6c69-9a70-11e8-840d-a01d4808520a Faulting package full name: Faulting package-relative application ID: Error: (08/06/2018 10:30:36 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program Picasa3.exe version 3.9.141.259 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: 2b70 Start Time: 01d42e0f82407ec8 Termination Time: 62 Application Path: C:\Program Files (x86)\Google\Picasa3\Picasa3.exe Report Id: 002d603c-9a03-11e8-840d-a01d4808520a Faulting package full name: Faulting package-relative application ID: System errors: ============= Error: (08/10/2018 01:53:57 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The HP Touchpoint Analytics service terminated unexpectedly. It has done this 1 time(s). Error: (08/10/2018 01:53:56 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The Kaspersky Secure Connection Service 2.0.0 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service. Error: (08/10/2018 01:53:55 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The Cobian Backup 11 Volume Shadow Copy Requester service terminated unexpectedly. It has done this 1 time(s). Error: (08/10/2018 01:53:55 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The HP SimplePass Service service terminated unexpectedly. It has done this 1 time(s). Error: (08/10/2018 01:53:55 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The AdaptiveSleepService service terminated unexpectedly. It has done this 1 time(s). Error: (08/10/2018 01:53:54 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The DbxSvc service terminated unexpectedly. It has done this 1 time(s). Error: (08/10/2018 01:53:54 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The HP Software Framework Service service terminated unexpectedly. It has done this 1 time(s). Error: (08/10/2018 01:53:54 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The HPWMISVC service terminated unexpectedly. It has done this 1 time(s). Windows Defender: =================================== Date: 2018-05-02 15:19:59.563 Description: Windows Defender scan has been stopped before completion. Scan ID: {6D4C2D02-5EC0-40B9-A4FD-1707828ACE62} Scan Type: Antimalware Scan Parameters: Quick Scan Date: 2018-05-01 20:21:17.470 Description: Windows Defender scan has been stopped before completion. Scan ID: {5A7AA1A2-A5BB-43F3-91E0-47C0BE9965C4} Scan Type: Antimalware Scan Parameters: Quick Scan Date: 2018-04-29 16:04:04.475 Description: Windows Defender scan has been stopped before completion. Scan ID: {3B6FD8F9-E5A2-4E95-BC37-89B41D3E9A94} Scan Type: Antimalware Scan Parameters: Quick Scan Date: 2018-04-29 14:30:03.992 Description: Windows Defender scan has been stopped before completion. Scan ID: {F024011E-C5CB-42AA-8BC3-D284337BB126} Scan Type: Antimalware Scan Parameters: Quick Scan Date: 2018-04-27 16:22:21.135 Description: Windows Defender scan has been stopped before completion. Scan ID: {2CED1371-CFA7-472B-807B-51E8F6595D6E} Scan Type: Antimalware Scan Parameters: Quick Scan Date: 2018-04-25 18:02:37.288 Description: Windows Defender has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.259.1806.0 Update Source: Microsoft Update Server Signature Type: AntiVirus Update Type: Full Current Engine Version: Previous Engine Version: 1.1.14405.2 Error code: 0x800704c7 Error description: The operation was canceled by the user. Date: 2018-01-18 12:34:13.895 Description: Windows Defender has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 113.77.0.0 Update Source: Microsoft Malware Protection Center Signature Type: Network Inspection System Update Type: Full Current Engine Version: Previous Engine Version: 2.1.11005.0 Error code: 0x80072ee7 Error description: The server name or address could not be resolved Date: 2018-01-18 12:34:13.880 Description: Windows Defender has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.233.3748.0 Update Source: Microsoft Malware Protection Center Signature Type: AntiSpyware Update Type: Full Current Engine Version: Previous Engine Version: 1.1.13303.0 Error code: 0x80072ee7 Error description: The server name or address could not be resolved Date: 2018-01-18 12:34:13.880 Description: Windows Defender has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.233.3748.0 Update Source: Microsoft Malware Protection Center Signature Type: AntiVirus Update Type: Full Current Engine Version: Previous Engine Version: 1.1.13303.0 Error code: 0x80072ee7 Error description: The server name or address could not be resolved Date: 2018-01-18 12:34:13.708 Description: Windows Defender has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.233.3748.0 Update Source: Microsoft Update Server Signature Type: AntiVirus Update Type: Full Current Engine Version: Previous Engine Version: 1.1.13303.0 Error code: 0x8024402c Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support. CodeIntegrity: =================================== Date: 2018-01-18 12:30:06.251 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\wow64.dll because the set of per-page image hashes could not be found on the system. Date: 2018-01-18 12:30:04.907 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\wow64.dll because the set of per-page image hashes could not be found on the system. Date: 2018-01-18 12:30:03.719 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\wow64.dll because the set of per-page image hashes could not be found on the system. Date: 2018-01-18 12:30:02.563 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\wow64.dll because the set of per-page image hashes could not be found on the system. Date: 2018-01-18 12:30:01.188 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\wow64.dll because the set of per-page image hashes could not be found on the system. Date: 2018-01-18 12:29:59.813 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\wow64.dll because the set of per-page image hashes could not be found on the system. Date: 2018-01-18 12:29:58.641 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\wow64.dll because the set of per-page image hashes could not be found on the system. Date: 2018-01-18 12:29:57.548 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\wow64.dll because the set of per-page image hashes could not be found on the system. ==================== Memory info =========================== Processor: AMD A4-5000 APU with Radeon(TM) HD Graphics Percentage of memory in use: 55% Total physical RAM: 3537.01 MB Available physical RAM: 1584.76 MB Total Virtual: 7121.01 MB Available Virtual: 4653.22 MB ==================== Drives ================================ Drive c: (Windows) (Fixed) (Total:446.77 GB) (Free:341.83 GB) NTFS Drive d: (RECOVERY) (Fixed) (Total:18.22 GB) (Free:1.85 GB) NTFS ==>[system with boot components (obtained from drive)] \\?\Volume{62b1e414-cc10-4ad9-9097-d18965972007}\ (WINRE) (Fixed) (Total:0.39 GB) (Free:0.13 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 465.8 GB) (Disk ID: 179F6E94) Partition: GPT. ==================== End of Addition.txt ============================