Additional scan result of Farbar Recovery Scan Tool (x64) Version: 06.10.2018 Ran by [removed] (08-10-2018 16:35:14) Running from C:\Users\[removed]\Downloads Windows 10 Pro Version 1803 17134.320 (X64) (2018-07-03 08:11:41) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-886221053-1638992907-3193777533-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-886221053-1638992907-3193777533-503 - Limited - Disabled) Guest (S-1-5-21-886221053-1638992907-3193777533-501 - Limited - Enabled) JeraldPunx (S-1-5-21-886221053-1638992907-3193777533-1002 - Administrator - Enabled) => C:\Users\JeraldPunx WDAGUtilityAccount (S-1-5-21-886221053-1638992907-3193777533-504 - Limited - Disabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF} AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) µTorrent (HKU\S-1-5-21-886221053-1638992907-3193777533-1002\...\uTorrent) (Version: 3.5.4.44632 - BitTorrent Inc.) Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 4.6.0.384 - Adobe Systems Incorporated) Adobe Flash Player 31 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 31.0.0.108 - Adobe Systems Incorporated) Adobe Photoshop CC 2014 (HKLM-x32\...\{D7A4F897-B20A-42D0-862D-CB5F6DB7391D}) (Version: 15.0 - Adobe Systems Incorporated) Adobe Premiere (HKLM\...\{C1CB876C-A08E-4692-B525-42848BD154D7}) (Version: 1.0.0000 - Adobe Systems Incorporated) Hidden Adobe Premiere Pro CC 2017 (HKLM-x32\...\PPRO_11_0_1) (Version: 11.0.1 - Adobe Systems Incorporated) Adobe Reader XI (11.0.20) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.20 - Adobe Systems Incorporated) Adobe Shockwave Player 12.3 (HKLM-x32\...\{49CD151E-5BE3-4A32-B9C3-687AD5B579B1}) (Version: 12.3.2.202 - Adobe Systems, Inc) Advanced IP Scanner 2.5 (HKLM-x32\...\{713B5DE9-77B2-4F75-B597-40A4065FB1D1}) (Version: 2.5.3646 - Famatech) Allgemeine Runtime Files (x86) (HKLM\...\{1F6D1DB5-82B5-41A4-85A2-0A382C142A35}_is1) (Version: 1.0.5.1 - Sereby Corporation) Apple Application Support (32-bit) (HKLM-x32\...\{308F2F8C-9D33-4B22-8A6C-D9C13DBEF8C6}) (Version: 7.0.2 - Apple Inc.) Apple Application Support (64-bit) (HKLM\...\{0CB84A7D-9697-4526-A819-60FB050E8F05}) (Version: 7.0.2 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{77F8C879-88CD-4145-945A-541C35285285}) (Version: 12.0.0.1039 - Apple Inc.) Apple Software Update (HKLM-x32\...\{A30EA700-5515-48F0-88B0-9E99DC356B88}) (Version: 2.6.0.1 - Apple Inc.) Avast Cleanup Premium (HKLM-x32\...\{075CC190-59EE-499F-828B-0B5C098C8C15}_is1) (Version: 18.2.5796 - AVAST Software) Avast Free Antivirus (HKLM-x32\...\Avast Antivirus) (Version: 18.6.2349 - AVAST Software) Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) Battlefield 4™ (HKLM-x32\...\{ABADE36E-EC37-413B-8179-B432AD3FACE7}) (Version: 1.8.2.48475 - Electronic Arts) Battlelog Web Plugins (HKLM-x32\...\Battlelog Web Plugins) (Version: 2.3.0 - EA Digital Illusions CE AB) BlueJeans (HKLM\...\{EF144075-4098-4DCB-99D5-D355AC110488}) (Version: 2.7.523 - BlueJeans Network, Inc.) Hidden BlueJeans (HKU\S-1-5-21-886221053-1638992907-3193777533-1002\...\{10a7968c-71f9-4752-8a30-3be57cf70027}) (Version: 2.7.523 - BlueJeans Network, Inc.) Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.) CCleaner (HKLM\...\CCleaner) (Version: 5.47 - Piriform) Composer - Php Dependency Manager (HKLM-x32\...\{7315AF68-E777-496A-A6A2-4763A98ED35A}_is1) (Version: - getcomposer.org) DB Browser for SQLite (HKLM-x32\...\DB Browser for SQLite) (Version: 3.10.1 - DB Browser for SQLite Team) Destiny 2 (HKLM-x32\...\Destiny 2) (Version: - Blizzard Entertainment) DirectX 9.0c Extra Files (x86, x64) (HKLM\...\{8729E65B-8C12-4A42-B1FE-E4DA7ED52855}_is1) (Version: 1.10.06.0 - Sereby Corporation) Discord (HKU\S-1-5-21-886221053-1638992907-3193777533-1002\...\Discord) (Version: 0.0.301 - Discord Inc.) DisplayDriverAnalyzer (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_DisplayDriverAnalyzer) (Version: 398.82 - NVIDIA Corporation) Hidden Driver Booster 6 (HKLM-x32\...\Driver Booster_is1) (Version: 6.0.2 - IObit) Epic Games Launcher (HKLM-x32\...\{93BFE5DF-776E-436F-8693-DF1F72C0E3C1}) (Version: 1.1.151.0 - Epic Games, Inc.) Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden ESN Sonar (HKLM-x32\...\ESN Sonar-0.70.4) (Version: 0.70.4 - ESN Social Software AB) f.lux (HKU\S-1-5-21-886221053-1638992907-3193777533-1002\...\Flux) (Version: - f.lux Software LLC) Forza Horizon 3 (HKLM-x32\...\Forza Horizon 3_is1) (Version: - ) GameClub Launcher PH (Remove only) (HKLM-x32\...\{BBD9FAD7-F782-4548-B00F-E612322950F6}) (Version: 20111202 - GameClub) GitHub Desktop (HKU\S-1-5-21-886221053-1638992907-3193777533-1002\...\GitHubDesktop) (Version: 1.4.0 - GitHub, Inc.) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 69.0.3497.100 - Google Inc.) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.17 - Google Inc.) Hidden Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.21.169 - Google Inc.) Hidden GoPro Quik (HKLM\...\{8B7D1DD1-5CA4-4B6E-9A86-3EA9E3601DF3}) (Version: 0.1.841 - GoPro, Inc.) Hidden GoPro Quik (HKLM-x32\...\{f1aab631-23ee-456b-a5ef-6e4d9d638068}) (Version: 2.6.2.841 - GoPro, Inc.) Herramientas de corrección de Microsoft Office 2016: español (HKLM\...\{90160000-001F-0C0A-1000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden HP Deskjet Ink Adv 2060 K110 Basic Device Software (HKLM\...\{8A3C3FD1-25E6-45D5-B1A6-6A5174A2D012}) (Version: 28.0.1313.0 - Hewlett-Packard Co.) HP Deskjet Ink Adv 2060 K110 Help (HKLM-x32\...\{261A4762-744B-4C71-81D2-57FA5038DC7B}) (Version: 140.0.2.2 - Hewlett Packard) HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard) Inno Setup version 5.6.1 (HKLM-x32\...\Inno Setup 5_is1) (Version: 5.6.1 - jrsoftware.org) Internet Download Manager version 7.1 (HKLM-x32\...\{15249A89-18CC-47CC-8D4A-C08B4DA17698}_is1) (Version: 7.1 - Tonec, Inc.) iTunes (HKLM\...\{645877C4-2AB6-46B6-BD32-B251B0666F63}) (Version: 12.9.0.167 - Apple Inc.) Java 10.0.1 (64-bit) (HKLM\...\{D33DF729-38BB-5651-9D40-93BFEFB5DCED}) (Version: 10.0.1.0 - Oracle Corporation) Java 10.0.2 (64-bit) (HKLM\...\{EECB2736-D013-5AC5-9917-7656712F6931}) (Version: 10.0.2.0 - Oracle Corporation) Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden Leonflix 0.4.7 (only current user) (HKU\S-1-5-21-886221053-1638992907-3193777533-1002\...\8751db29-a017-5240-bf08-2c23a7d362b0) (Version: 0.4.7 - Leonflix) Malwarebytes version 3.6.1.2711 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.6.1.2711 - Malwarebytes) MEGAsync (HKLM-x32\...\MEGAsync) (Version: - Mega Limited) Metal Gear Solid V: TPP (HKLM-x32\...\Metal Gear Solid V: TPP_is1) (Version: - ) Microsoft Office Professional Plus 2016 (HKLM\...\Office16.PROPLUS) (Version: 16.0.4266.1001 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61187 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61186 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.7523 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.7523 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.7523 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.7523 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61135 (HKLM\...\{37B8F9C7-03FB-3253-8781-2517C99D7C00}) (Version: 11.0.61135 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61135 (HKLM\...\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}) (Version: 11.0.61135 - Microsoft Corporation) Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61135 (HKLM-x32\...\{B175520C-86A2-35A7-8619-86DC379688B9}) (Version: 11.0.61135 - Microsoft Corporation) Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61135 (HKLM-x32\...\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}) (Version: 11.0.61135 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40649 (HKLM-x32\...\{5d0723d3-cff7-4e07-8d0b-ada737deb5e6}) (Version: 12.0.40649.5 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40664 (HKLM-x32\...\{4ffaf7b8-a84a-4813-840c-8b1f1343ae54}) (Version: 12.0.40664.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40664 (HKLM-x32\...\{dd1e9bde-2ad6-4e92-8c07-7d4723eab8b8}) (Version: 12.0.40664.0 - Microsoft Corporation) Microsoft Visual C++ 2017 Redistributable (x64) - 14.14.26405 (HKLM-x32\...\{5b295ba9-ef89-4aeb-8acc-b61adb0b9b5f}) (Version: 14.14.26405.0 - Microsoft Corporation) Microsoft Visual C++ 2017 Redistributable (x86) - 14.14.26405 (HKLM-x32\...\{ec9c2282-a836-48a6-9e41-c2f0bf8d678b}) (Version: 14.14.26405.0 - Microsoft Corporation) Microsoft XNA Framework Redistributable 4.0 (HKLM-x32\...\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation) Mozilla Firefox 62.0.3 (x64 en-US) (HKLM\...\Mozilla Firefox 62.0.3 (x64 en-US)) (Version: 62.0.3 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 60.0.2 - Mozilla) MyImgur (HKLM-x32\...\{2C08A2AE-BF6F-4100-95AF-8A6CCF379EF1}_is1) (Version: 3.93 - Eden.fm) Node.js (HKLM\...\{C4BE807E-A066-4B2C-9AC2-B12F64192054}) (Version: 8.12.0 - Node.js Foundation) NVAPI Monitor plugin for NvContainer (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.NvapiMonitor) (Version: 1.11 - NVIDIA Corporation) Hidden NVIDIA 3D Vision Controller Driver 390.41 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 390.41 - NVIDIA Corporation) NVIDIA GeForce Experience 3.15.0.164 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.15.0.164 - NVIDIA Corporation) NVIDIA PhysX System Software 9.17.0524 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.17.0524 - NVIDIA Corporation) OBS Studio (HKLM-x32\...\OBS Studio) (Version: 21.1.2 - OBS Project) OneClickFirewall (HKLM\...\OneClickFirewall) (Version: 1.0.0.2 - hxxp://winaero.com) OpenAL (HKLM-x32\...\OpenAL) (Version: - ) OpenIV (HKU\S-1-5-21-886221053-1638992907-3193777533-1002\...\OpenIV) (Version: 3.0.1006 - .black/OpenIV Team) Outils de vérification linguistique 2016 de Microsoft Office - Français (HKLM\...\{90160000-001F-040C-1000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8485 - Realtek Semiconductor Corp.) Resident Evil 7: Biohazard (HKLM-x32\...\Resident Evil 7: Biohazard_is1) (Version: - ) Roblox Player for JeraldPunx (HKU\S-1-5-21-886221053-1638992907-3193777533-1002\...\{373B1718-8CC5-4567-8EE2-9033AD08A680}) (Version: - Roblox Corporation) Roblox Player for JeraldPunx (HKU\S-1-5-21-886221053-1638992907-3193777533-1002\...\roblox-player) (Version: - Roblox Corporation) Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.2.2.0 - Rockstar Games) SHAREit (HKLM-x32\...\www.ushareit.com_is1) (Version: 4.0.6.177 - SHAREit Technologies Co.Ltd) Stremio (HKU\S-1-5-21-886221053-1638992907-3193777533-1002\...\Stremio) (Version: 4.4.10 - Smart Code Ltd.) Sublime Text Build 3176 (HKLM\...\Sublime Text 3_is1) (Version: - Sublime HQ Pty Ltd) TeamViewer 13 (HKLM-x32\...\TeamViewer) (Version: 13.2.5287 - TeamViewer) Tencent Gaming Buddy (HKLM-x32\...\MobileGamePC) (Version: 1.0.0.1 - Tencent Technology Company) Update for Skype for Business 2016 (KB4092445) 64-Bit Edition (HKLM\...\{90160000-0011-0000-1000-0000000FF1CE}_Office16.PROPLUS_{1D3EBE92-8BB5-4F75-B272-4AE736882A7D}) (Version: - Microsoft) Update for Skype for Business 2016 (KB4092445) 64-Bit Edition (HKLM\...\{90160000-00C1-0000-1000-0000000FF1CE}_Office16.PROPLUS_{1D3EBE92-8BB5-4F75-B272-4AE736882A7D}) (Version: - Microsoft) Update for Skype for Business 2016 (KB4092445) 64-Bit Edition (HKLM\...\{90160000-012B-0409-1000-0000000FF1CE}_Office16.PROPLUS_{1D3EBE92-8BB5-4F75-B272-4AE736882A7D}) (Version: - Microsoft) uTorrent Web (HKU\S-1-5-21-886221053-1638992907-3193777533-1002\...\utweb) (Version: 0.18.2 - BitTorrent, Inc.) VirtualCloneDrive (HKLM-x32\...\VirtualCloneDrive) (Version: 5.5.0.0 - Elaborate Bytes) VLC media player (HKLM-x32\...\VLC media player) (Version: 3.0.4 - VideoLAN) Voicemod (HKLM\...\{8435A407-F778-4647-9CDB-46E5EC50BAD0}_is1) (Version: 1.0.8.1 - Voicemod S.L.) Wampserver64 3.1.3 (HKLM\...\{wampserver64}_is1) (Version: 3.1.3 - Dominique Ottello aka Otomatic) WinRAR 5.50 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.50.0 - win.rar GmbH) WinRAR Universal Crack (HKLM-x32\...\WinRAR Universal Crack) (Version: 5.50 - Crackingpatching.com Team) World oƒ Tantra Philippines (HKU\S-1-5-21-886221053-1638992907-3193777533-1002\...\World oƒ Tantra Philippines) (Version: - ) ZLOrigin (HKLM-x32\...\ZLOrigin_is1) (Version: ZLOrigin - ZLOFENIX) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-886221053-1638992907-3193777533-1002_Classes\CLSID\{0E270DAA-1BE6-48F2-AC49-5286CA37832A}\InprocServer32 -> %%systemroot%%\system32\shell32.dll => No File CustomCLSID: HKU\S-1-5-21-886221053-1638992907-3193777533-1002_Classes\CLSID\{e8c77137-e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems) ShellIconOverlayIdentifiers: [ MEGA (Pending)] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\ProgramData\MEGAsync\ShellExtX64.dll [2017-10-19] () ShellIconOverlayIdentifiers: [ MEGA (Synced)] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\ProgramData\MEGAsync\ShellExtX64.dll [2017-10-19] () ShellIconOverlayIdentifiers: [ MEGA (Syncing)] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\ProgramData\MEGAsync\ShellExtX64.dll [2017-10-19] () ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-02-27] () ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-02-27] () ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-02-27] () ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-08-24] (AVAST Software) ShellIconOverlayIdentifiers: [IDM Shell Extension] -> {CDC95B92-E27C-4745-A8C5-64A52A78855D} => C:\Program Files (x86)\Tonec\IDMShellExt64.dll [2011-05-30] (Tonec Inc.) ShellIconOverlayIdentifiers-x32: [ MEGA (Pending)] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\ProgramData\MEGAsync\ShellExtX64.dll [2017-10-19] () ShellIconOverlayIdentifiers-x32: [ MEGA (Synced)] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\ProgramData\MEGAsync\ShellExtX64.dll [2017-10-19] () ShellIconOverlayIdentifiers-x32: [ MEGA (Syncing)] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\ProgramData\MEGAsync\ShellExtX64.dll [2017-10-19] () ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File ContextMenuHandlers1: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-02-27] () ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-08-24] (AVAST Software) ContextMenuHandlers1: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\ProgramData\MEGAsync\ShellExtX64.dll [2017-10-19] () ContextMenuHandlers1: [MyImgur] -> {F3026062-4D7E-4638-9A6B-382CCAC3FC0A} => c:\MyImgur\CTXMEN~1.DLL [2017-04-24] () ContextMenuHandlers1: [VirtualCloneDrive] -> {B7056B8E-4F99-44f8-8CBD-282390FE5428} => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\ElbyVCDShell.dll [2009-12-15] (Elaborate Bytes AG) ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2017-08-11] (Alexander Roshal) ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2017-08-11] (Alexander Roshal) ContextMenuHandlers2: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\ProgramData\MEGAsync\ShellExtX64.dll [2017-10-19] () ContextMenuHandlers2: [VirtualCloneDrive] -> {B7056B8E-4F99-44f8-8CBD-282390FE5428} => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\ElbyVCDShell.dll [2009-12-15] (Elaborate Bytes AG) ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-08-24] (AVAST Software) ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-09-19] (Malwarebytes) ContextMenuHandlers3: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\ProgramData\MEGAsync\ShellExtX64.dll [2017-10-19] () ContextMenuHandlers4: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\ProgramData\MEGAsync\ShellExtX64.dll [2017-10-19] () ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2018-09-18] (NVIDIA Corporation) ContextMenuHandlers6: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-02-27] () ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-08-24] (AVAST Software) ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-09-19] (Malwarebytes) ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2017-08-11] (Alexander Roshal) ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2017-08-11] (Alexander Roshal) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {02B5338C-60ED-4B1B-A113-56BD70A66569} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2018-01-08] (Apple Inc.) Task: {032314EB-DCDE-41D7-9B68-28E61D82D810} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2018-09-19] (Piriform Ltd) Task: {04BFC897-391F-4CD3-8424-A5DBE5136A13} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1807.18075-0\MpCmdRun.exe [2018-09-04] (Microsoft Corporation) Task: {088D123E-E2D1-46B7-A6DD-270BBD9CE4BA} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2018-09-12] (NVIDIA Corporation) Task: {1391EBE9-7B1C-4350-9EDF-086CD61A275E} - System32\Tasks\Driver Booster Scheduler => C:\Program Files (x86)\IObit\Driver Booster\6.0.2\Scheduler.exe [2018-09-13] (IObit) Task: {1E6EB7DE-4A0E-408E-B978-14ED78878B33} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2018-09-12] (NVIDIA Corporation) Task: {2073A001-5B35-45FC-A688-3FF5D36DBB03} - System32\Tasks\NvTmRepCR2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2018-09-12] (NVIDIA Corporation) Task: {262EDD24-49C1-43BB-B4E7-819D61912445} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [2018-09-12] (NVIDIA Corporation) Task: {34D23089-A65C-4048-93AF-37CB4A814A7D} - System32\Tasks\Microsoft\Windows\Setup\Notifier => C:\WINDOWS\system32\Notifier.exe Task: {3725C6A1-C068-4CFE-96AC-E9B5A4C773F5} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2018-09-12] (NVIDIA Corporation) Task: {3D57A5B9-AD16-4303-9BEE-E3F2EDD00767} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2018-09-12] (NVIDIA Corporation) Task: {475A962B-B500-4DC0-B5C9-86CEC2C44FA2} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe [2018-09-15] (AVAST Software) Task: {4916EC2B-E22F-408C-B0CE-858DA057DB20} - System32\Tasks\Open Hardware Monitor\Startup => C:\Users\JeraldPunx\Desktop\OpenHardwareMonitor\OpenHardwareMonitor.exe Task: {49387026-7E96-4F33-9EA5-4A1EDC019AAC} - System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcTrigger Task: {4FC9CE65-D0A9-4A5C-8EE1-7E9FE56D47CD} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1807.18075-0\MpCmdRun.exe [2018-09-04] (Microsoft Corporation) Task: {50BF6688-E198-4C9B-8E86-9A437AE30E3D} - System32\Tasks\Driver Booster SkipUAC (JeraldPunx) => C:\Program Files (x86)\IObit\Driver Booster\6.0.2\DriverBooster.exe [2018-09-19] (IObit) Task: {574B63D2-2C80-4A1D-9B1A-30AF5C161143} - System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-886221053-1638992907-3193777533-500 => C:\Users\JeraldPunx\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe Task: {5B9FEBC4-DA7C-47EE-A311-4B5CBA460BF6} - System32\Tasks\NvTmRepCR1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2018-09-12] (NVIDIA Corporation) Task: {65B85F6F-35B3-4459-A179-28255D5B7B25} - System32\Tasks\Microsoft\Windows\HelloFace\FODCleanupTask => C:\WINDOWS\System32\WinBioPlugIns\FaceFodUninstaller.exe [2018-04-12] () Task: {6FE97A6A-473E-431A-A6D1-65BC1810D366} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-09-20] (Adobe Systems Incorporated) Task: {79E13F74-61F3-4AE6-A79F-FF3C0C523B8D} - System32\Tasks\Avast TUNEUP Update => C:\Program Files (x86)\AVAST Software\Avast Cleanup\TUNEUpdate.exe [2018-09-25] (AVAST Software) Task: {7A091F8A-B519-45DF-B4C1-01E967A22A4A} - System32\Tasks\MSIAfterburner => C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe Task: {7D2AC4F5-6D3E-4AD6-9167-C9891949EC3A} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2018-08-24] (AVAST Software) Task: {810FCA9D-9314-407F-9C82-CABA417A3B8C} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [2018-09-19] (Piriform Ltd) Task: {8276FE2C-E10E-4E14-B832-4E79D38494C1} - System32\Tasks\MEGA\MEGAsync Update Task S-1-5-21-886221053-1638992907-3193777533-1002 => C:\ProgramData\MEGAsync\MEGAupdater.exe [2018-01-16] (Mega Limited) Task: {8381088C-F4E4-4265-AFA5-6C27973F108E} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\Office16\msoia.exe [2015-07-31] (Microsoft Corporation) Task: {877BBFB2-5C4D-4C2A-B22E-9BC82C3616E0} - System32\Tasks\AdobeGCInvoker-1.0-DESKTOP-HKGFUOP-JeraldPunx => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [2018-09-10] (Adobe Systems, Incorporated) Task: {8901507F-2411-4C90-8BB2-67A9F6F19BF1} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2018-09-12] (NVIDIA Corporation) Task: {8B0B6D4D-C895-4575-940E-FE8BB1ACCA72} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\Office16\msoia.exe [2015-07-31] (Microsoft Corporation) Task: {8B647D0E-B6F0-48B9-8027-A23AD25A1147} - System32\Tasks\NvTmRepCR3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2018-09-12] (NVIDIA Corporation) Task: {99E89A8B-C7FA-461B-9C5F-BA59A8764C46} - System32\Tasks\JavaUpdateSched => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2018-06-27] (Oracle Corporation) Task: {9AD23FE3-C0CC-465E-A1D9-035A0D992052} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\WINDOWS\explorer.exe /NOUACCHECK Task: {9C5F41B0-AFD6-444E-93EA-4FBE84278743} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-06-25] (Google Inc.) Task: {9D3F3AAD-3A6B-445F-AC67-FFBCBDF41CB2} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_31_0_0_108_Plugin.exe [2018-09-20] (Adobe Systems Incorporated) Task: {9E60840D-4FBF-4CFD-B610-1B0EF41C0E45} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2018-09-12] (NVIDIA Corporation) Task: {AC81BBF1-1D42-49FD-9A58-1148687BAB95} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2018-09-12] (NVIDIA Corporation) Task: {C0B83875-D9A4-4913-B386-39E56A2360E7} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2015-07-31] (Microsoft Corporation) Task: {E35DFECD-0B39-4C2A-A0C3-C5A2E0FC0FED} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-06-25] (Google Inc.) Task: {EC0FE8AE-7D40-4B19-822B-038B08EDFAAA} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1807.18075-0\MpCmdRun.exe [2018-09-04] (Microsoft Corporation) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) ==================== Shortcuts & WMI ======================== (The entries could be listed to be restored or removed.) Shortcut: C:\Users\Public\Desktop\Forza Horizon 3 (Install Crack).lnk -> E:\Offline\Forza Horizon 3\Install Crack.bat () ShortcutWithArgument: C:\Users\JeraldPunx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Chrome Remote Desktop.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=gbchcmhmhahfdphkhkmpfmihenigjmpp ShortcutWithArgument: C:\Users\JeraldPunx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Postman.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=fhbjgbiflinjbdggehcddcbncdddomop ShortcutWithArgument: C:\Users\JeraldPunx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\SoundIt.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=jpmlghikapcebilgkglhelbdipdibmgd ShortcutWithArgument: C:\Users\JeraldPunx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Subtitle Videoplayer.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=naikohapihpbhficdpbddmgbhiccijca ==================== Loaded Modules (Whitelisted) ============== 2018-04-12 07:34 - 2018-04-12 07:34 - 000444416 _____ () c:\windows\system32\SSDM.dll 2018-06-25 16:40 - 2013-07-03 20:32 - 000936728 _____ () C:\Program Files (x86)\ASUS\AXSP\1.01.02\atkexComSvc.exe 2018-06-23 06:56 - 2018-06-23 06:56 - 000088888 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2018-08-22 22:18 - 2018-08-22 22:18 - 001356088 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2018-10-04 20:14 - 2018-09-12 11:35 - 002701064 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\SelfProtectionSdk.dll 2018-07-26 23:06 - 2018-09-12 19:45 - 001315024 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll 2018-04-12 07:34 - 2018-04-12 07:34 - 000491744 _____ () C:\WINDOWS\SYSTEM32\inputhost.dll 2018-04-12 07:34 - 2018-04-12 07:34 - 000472064 _____ () C:\Windows\ShellExperiences\TileControl.dll 2018-04-12 07:34 - 2018-04-12 07:34 - 002759168 _____ () C:\Windows\ShellComponents\TaskFlowUI.dll 2017-10-19 05:51 - 2017-10-19 05:51 - 000598528 _____ () C:\ProgramData\MEGAsync\ShellExtX64.dll 2018-02-27 20:08 - 2018-02-27 20:08 - 000614856 _____ () C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll 2017-07-11 21:03 - 2017-07-11 21:03 - 008911560 _____ () C:\Program Files\Microsoft Office\Office16\1033\GrooveIntlResource.dll 2018-07-26 23:06 - 2018-09-12 19:45 - 101252304 _____ () C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\libcef.dll 2018-07-26 23:06 - 2018-09-12 19:45 - 004619984 _____ () C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\libglesv2.dll 2018-07-26 23:06 - 2018-09-12 19:45 - 000108752 _____ () C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\libegl.dll 2018-10-01 23:41 - 2018-09-21 11:38 - 002185728 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2018-08-28 10:46 - 2018-08-28 10:46 - 000088888 _____ () C:\Program Files\iTunes\zlib1.dll 2018-08-28 10:46 - 2018-08-28 10:46 - 001356088 _____ () C:\Program Files\iTunes\libxml2.dll 2018-09-12 18:07 - 2018-09-06 04:14 - 001055520 _____ () D:\Online Games\Steam\bin\cef\cef.win7x64\SDL2.dll 2018-08-29 08:10 - 2018-08-28 04:52 - 098006816 _____ () D:\Online Games\Steam\bin\cef\cef.win7x64\libcef.dll 2018-08-29 08:10 - 2018-08-28 04:53 - 002680608 _____ () D:\Online Games\Steam\bin\cef\cef.win7x64\swiftshader\libglesv2.dll 2018-08-29 08:10 - 2018-08-28 04:53 - 000129312 _____ () D:\Online Games\Steam\bin\cef\cef.win7x64\swiftshader\libegl.dll 2018-06-25 16:41 - 2018-10-08 11:36 - 000033936 _____ () C:\Program Files (x86)\ASUS\AXSP\1.01.02\PEbiosinterface32.dll 2018-06-25 16:41 - 2013-07-03 20:32 - 000104448 _____ () C:\Program Files (x86)\ASUS\AXSP\1.01.02\ATKEX.dll 2018-07-26 23:06 - 2018-09-12 19:45 - 001032912 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\libprotobuf.dll 2018-06-25 17:40 - 2018-06-25 17:40 - 067126928 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2018-08-24 21:10 - 2018-08-24 21:10 - 000575704 _____ () C:\Program Files\AVAST Software\Avast\streamback.dll 2018-07-23 09:40 - 2016-09-12 15:53 - 048936448 _____ () C:\Program Files (x86)\AVAST Software\Avast Cleanup\libcef.dll 2017-09-11 04:51 - 2017-09-11 04:51 - 000798208 _____ () C:\ProgramData\MEGAsync\libsodium.dll 2018-09-12 18:07 - 2018-09-06 04:14 - 000876320 _____ () D:\Online Games\Steam\SDL2.dll 2018-09-12 18:07 - 2018-09-09 04:31 - 002646304 _____ () D:\Online Games\Steam\video.dll 2018-07-25 06:48 - 2016-09-01 09:02 - 004969248 _____ () D:\Online Games\Steam\v8.dll 2018-07-25 06:48 - 2017-12-20 09:43 - 000351520 _____ () D:\Online Games\Steam\libavresample-3.dll 2018-07-25 06:48 - 2017-12-20 09:43 - 000695584 _____ () D:\Online Games\Steam\libavformat-57.dll 2018-07-25 06:48 - 2017-12-20 09:43 - 000847136 _____ () D:\Online Games\Steam\libavutil-55.dll 2018-07-25 06:48 - 2017-12-20 09:43 - 000783648 _____ () D:\Online Games\Steam\libswscale-4.dll 2018-07-25 06:48 - 2016-09-01 09:02 - 001195296 _____ () D:\Online Games\Steam\icuuc.dll 2018-07-25 06:48 - 2016-09-01 09:02 - 001563936 _____ () D:\Online Games\Steam\icui18n.dll 2018-07-25 06:48 - 2017-12-20 09:43 - 005137696 _____ () D:\Online Games\Steam\libavcodec-57.dll 2018-09-12 18:07 - 2018-09-09 04:31 - 001015584 _____ () D:\Online Games\Steam\bin\chromehtml.DLL 2018-07-25 06:48 - 2016-07-05 06:17 - 000266560 _____ () D:\Online Games\Steam\openvr_api.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\Users\JeraldPunx\AppData\Local\Temp:$DATA​ [16] AlternateDataStreams: C:\Users\Public\AppData:CSM [452] AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [470] ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) HKU\S-1-5-21-886221053-1638992907-3193777533-1002\Software\Classes\.exe: exefile => <==== ATTENTION ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2017-09-29 21:46 - 2018-09-24 14:01 - 000001158 _____ C:\WINDOWS\system32\Drivers\etc\hosts 127.0.0.1 activate.adobe.com 127.0.0.1 practivate.adobe.com 127.0.0.1 lmlicenses.wip4.adobe.com 127.0.0.1 lm.licenses.adobe.com 127.0.0.1 na1r.services.adobe.com 127.0.0.1 hlrcv.stage.adobe.com 127.0.0.1 www.easeus.com 127.0.0.1 activation.easeus.com 127.0.0.1 track.easeus.com 127.0.0.1 localhost 127.0.0.1 www.sublimetext.com 127.0.0.1 license.sublimehq.com ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-886221053-1638992907-3193777533-1002\Control Panel\Desktop\\Wallpaper -> C:\Users\JeraldPunx\AppData\Local\Microsoft\Windows\Themes\McLaren S\DesktopBackground\09_mclaren_senna_black_livery_6_resized.jpg DNS Servers: 1.1.1.1 - 1.0.0.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: ) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == If an entry is included in the fixlist, it will be removed. HKLM\...\StartupApproved\Run: => "AdobeAAMUpdater-1.0" HKLM\...\StartupApproved\Run: => "AdobeGCInvoker-1.0" HKLM\...\StartupApproved\Run: => "WindowsDefender" HKLM\...\StartupApproved\Run: => "SoftEther VPN Client UI Helper" HKLM\...\StartupApproved\Run32: => "Adobe Creative Cloud" HKLM\...\StartupApproved\Run32: => "Adobe ARM" HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched" HKLM\...\StartupApproved\Run32: => "EaseUS EPM Tray Agent" HKLM\...\StartupApproved\Run32: => "VirtualCloneDrive" HKU\S-1-5-21-886221053-1638992907-3193777533-1002\...\StartupApproved\Run: => "CCleaner Monitoring" HKU\S-1-5-21-886221053-1638992907-3193777533-1002\...\StartupApproved\Run: => "OneDriveSetup" HKU\S-1-5-21-886221053-1638992907-3193777533-1002\...\StartupApproved\Run: => "utweb" HKU\S-1-5-21-886221053-1638992907-3193777533-1002\...\StartupApproved\Run: => "Gaijin.Net Agent" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [UDP Query User{1038E978-3027-4440-B00C-2470B825550D}C:\users\jeraldpunx\appdata\local\programs\lnv\stremio-4\node.exe] => (Allow) C:\users\jeraldpunx\appdata\local\programs\lnv\stremio-4\node.exe FirewallRules: [TCP Query User{517EB55A-7E61-40AE-B98B-F0A00BA0A12D}C:\users\jeraldpunx\appdata\local\programs\lnv\stremio-4\node.exe] => (Allow) C:\users\jeraldpunx\appdata\local\programs\lnv\stremio-4\node.exe FirewallRules: [UDP Query User{C9E94BF6-66E5-4EE1-AB94-1AE7B261E925}D:\online games\steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe] => (Allow) D:\online games\steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe FirewallRules: [TCP Query User{B5A32F36-3CB0-43EE-802D-D9F172CF2F90}D:\online games\steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe] => (Allow) D:\online games\steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe FirewallRules: [UDP Query User{4887CC32-E09F-44FD-B254-2E08C6B58AD6}D:\online games\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) D:\online games\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe FirewallRules: [TCP Query User{B324B75C-C2A0-4A22-A70A-2CB5E90A62A4}D:\online games\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) D:\online games\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe FirewallRules: [{958C00A4-27EB-4921-AD10-0B974FDBB588}] => (Allow) D:\Online Games\Steam\SteamApps\common\Realm Royale\Binaries\Win64\RealmEAC.exe FirewallRules: [{A3B161E2-B12B-4324-B5CC-37A16F43616A}] => (Allow) D:\Online Games\Steam\SteamApps\common\Realm Royale\Binaries\Win64\RealmEAC.exe FirewallRules: [{AE74CF77-15C5-4460-AE2E-D0BF96AEEF27}] => (Allow) D:\Online Games\Steam\SteamApps\common\PUBG\TslGame\Binaries\Win64\TslGame_BE.exe FirewallRules: [{3DB62FA9-22F0-4255-9BAC-A6F43E9E0D57}] => (Allow) D:\Online Games\Steam\SteamApps\common\PUBG\TslGame\Binaries\Win64\TslGame_BE.exe FirewallRules: [{961853C2-FB38-453A-A751-3E23A79C5378}] => (Allow) D:\Online Games\Steam\Steam.exe FirewallRules: [{AD53E160-A204-4887-A320-BED97C6C220D}] => (Allow) D:\Online Games\Steam\Steam.exe FirewallRules: [UDP Query User{08D69823-5E88-4D74-BA14-35CC97F919BF}I:\online games\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) I:\online games\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe FirewallRules: [TCP Query User{B962239E-8834-44CB-9B35-85BACB10017E}I:\online games\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) I:\online games\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe FirewallRules: [UDP Query User{F9BDE161-484D-4DA6-A99C-10D06DC49BC9}D:\online games\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) D:\online games\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe FirewallRules: [TCP Query User{63A7E4CF-94A6-438B-B400-FCFD6F011629}D:\online games\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) D:\online games\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe FirewallRules: [UDP Query User{7C248E60-2F9A-4F6C-B488-9731DC73B6B7}C:\program files\mozilla firefox\firefox.exe] => (Allow) C:\program files\mozilla firefox\firefox.exe FirewallRules: [TCP Query User{771CF0A4-ADFB-4887-9E9C-47D5A44EFC90}C:\program files\mozilla firefox\firefox.exe] => (Allow) C:\program files\mozilla firefox\firefox.exe FirewallRules: [{BBD4BB4E-4DF0-4BF6-8B02-14A9FAED90C0}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [{793F7BF2-B75C-48FE-9624-A06004C545EF}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [{498A0C40-F095-44E5-9E08-469E36565E0A}] => (Allow) C:\Program Files\Microsoft Office\Office16\UcMapi.exe FirewallRules: [{5E37FE4A-9D91-4ADA-AE41-87A89EA9448B}] => (Allow) C:\Program Files\Microsoft Office\Office16\UcMapi.exe FirewallRules: [{2AA5F08E-EACB-4432-81C9-71B13939EE68}] => (Allow) C:\Program Files\Microsoft Office\Office16\lync.exe FirewallRules: [{E446C4AE-AD39-460B-9B00-FE3435906216}] => (Allow) C:\Program Files\Microsoft Office\Office16\lync.exe FirewallRules: [TCP Query User{5AE0A764-947F-4ABC-A282-70B076C45C83}F:\online\ros\ros.exe] => (Allow) F:\online\ros\ros.exe FirewallRules: [UDP Query User{C2737542-8298-4AA5-9FB7-E50F0E920D44}F:\online\ros\ros.exe] => (Allow) F:\online\ros\ros.exe FirewallRules: [TCP Query User{80CBA85D-7621-4A3D-BF8F-741DEEC1A33C}F:\online\ros\ccmini\ccmini.exe] => (Allow) F:\online\ros\ccmini\ccmini.exe FirewallRules: [UDP Query User{A7D76AAE-6360-41A3-A7BC-1AB70BE5E035}F:\online\ros\ccmini\ccmini.exe] => (Allow) F:\online\ros\ccmini\ccmini.exe FirewallRules: [TCP Query User{AE7B2FEC-EE04-41FC-A742-D786BFC90AEB}D:\online games\steam\steamapps\common\realm royale\binaries\win64\realm.exe] => (Allow) D:\online games\steam\steamapps\common\realm royale\binaries\win64\realm.exe FirewallRules: [UDP Query User{795D4273-1A39-44CB-8598-87FAC7121884}D:\online games\steam\steamapps\common\realm royale\binaries\win64\realm.exe] => (Allow) D:\online games\steam\steamapps\common\realm royale\binaries\win64\realm.exe FirewallRules: [TCP Query User{F95BC182-CF1A-475A-BCF8-874DE3E37943}C:\wamp64\bin\apache\apache2.4.33\bin\httpd.exe] => (Allow) C:\wamp64\bin\apache\apache2.4.33\bin\httpd.exe FirewallRules: [UDP Query User{C7EF6F94-D90E-436B-875C-FF09662C10B1}C:\wamp64\bin\apache\apache2.4.33\bin\httpd.exe] => (Allow) C:\wamp64\bin\apache\apache2.4.33\bin\httpd.exe FirewallRules: [{67C71B46-2FC4-4923-B45D-90BCD00E2D41}] => (Allow) C:\Users\JeraldPunx\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{D5DE89D2-A273-4E03-8345-735E60F6624C}] => (Allow) C:\Users\JeraldPunx\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{EABE09F1-8839-4C84-9815-6402AB06A271}] => (Allow) D:\Online Games\Steam\SteamApps\common\Counter-Strike Global Offensive\csgo.exe FirewallRules: [{D2D7C16A-8B09-4828-877C-C513181DB84D}] => (Allow) D:\Online Games\Steam\SteamApps\common\Counter-Strike Global Offensive\csgo.exe FirewallRules: [{33173500-5A0D-4127-9B4B-6D848AFBC8B5}] => (Allow) C:\Program Files\GoPro\GoPro Desktop App\GoPro Quik.exe FirewallRules: [{DD1A4EB2-6153-455B-800A-73E0F31701A6}] => (Allow) C:\Program Files\GoPro\GoPro Desktop App\GoProMsgBus.exe FirewallRules: [{C4F31033-C0A2-47A4-A17A-2C01DCAE0D54}] => (Allow) C:\Program Files\GoPro\GoPro Desktop App\GoProIDService.exe FirewallRules: [{0F2B04B4-A262-4731-BC9D-6C927B8E57EA}] => (Allow) C:\Program Files\GoPro\GoPro Desktop App\GoProLauncher.exe FirewallRules: [{A979E948-CA40-4207-90E8-FE19E65649E0}] => (Allow) D:\Online Games\TxGameAssistant\AppMarket\AppMarket.exe FirewallRules: [{B3614DCF-4E62-49C9-A95F-0CA4753DDA44}] => (Allow) D:\Online Games\TxGameAssistant\AppMarket\TInst.exe FirewallRules: [{AE28900A-5E6F-452F-849A-64612842F02C}] => (Allow) D:\Online Games\TxGameAssistant\AppMarket\bugreport.exe FirewallRules: [{4B07E174-FA8F-441B-B85D-D3BB2FA3758C}] => (Allow) D:\Online Games\TxGameAssistant\AppMarket\QQExternal.exe FirewallRules: [{FDBDBD75-2F65-4FF1-8460-E79024C24FC3}] => (Allow) D:\Online Games\TxGameAssistant\AppMarket\GameDownload.exe FirewallRules: [{3C9C1A21-E090-449A-94F7-E4252F459396}] => (Allow) D:\Online Games\TxGameAssistant\AppMarket\GF186\TUpdate.exe FirewallRules: [{E128CC88-7CBE-48AF-AAA8-D619ECD21B0E}] => (Allow) C:\Users\JeraldPunx\AppData\Roaming\Tencent\TxGameAssistant\GameDownload\TenioDL.exe FirewallRules: [{A18EE083-FEC7-459A-95CF-B1270C073602}] => (Allow) C:\Users\JeraldPunx\AppData\Roaming\Tencent\TxGameAssistant\GameDownload\TenioDL.exe FirewallRules: [{CDF13891-1BB2-4711-A2BA-608684822813}] => (Allow) C:\Users\JeraldPunx\AppData\Roaming\Tencent\TxGameAssistant\GameDownload\TenioDL.exe FirewallRules: [{D63937DA-EBF1-4783-900A-1B6CE679ABD1}] => (Allow) C:\Users\JeraldPunx\AppData\Roaming\Tencent\TxGameAssistant\GameDownload\TenioDL.exe FirewallRules: [{C2BEBFCD-75B7-4E3A-A32A-DCF2D4C6A70F}] => (Allow) C:\Users\JeraldPunx\AppData\Roaming\Tencent\TxGameAssistant\GameDownload\TenioDL.exe FirewallRules: [{D62D9AD5-9A28-4EC9-A708-2AC2D1969726}] => (Allow) C:\Users\JeraldPunx\AppData\Roaming\Tencent\TxGameAssistant\GameDownload\TenioDL.exe FirewallRules: [{619EA7FA-B272-43CE-AEB5-5D0073E0DF12}] => (Allow) D:\Online Games\TxGameAssistant\UI\AndroidEmulator.exe FirewallRules: [{862E5713-E16F-477C-8C66-1E1D7B7DE7EE}] => (Allow) D:\Online Games\TxGameAssistant\UI\adb.exe FirewallRules: [{1FA1F32F-22B0-442C-BACE-A043CF1FB63B}] => (Allow) D:\Online Games\TxGameAssistant\UI\TInst.exe FirewallRules: [{3932E801-6517-4A38-BA09-975831F25714}] => (Allow) D:\Online Games\TxGameAssistant\UI\bugreport.exe FirewallRules: [{79D97CCC-32C3-4631-9459-D90CEC5ECE47}] => (Allow) D:\Online Games\TxGameAssistant\UI\TxGaDcc.exe FirewallRules: [TCP Query User{6CA4FD57-38ED-43D9-B1FB-D4D982ACA4AA}E:\offline\farcry 3\bin\farcry3.exe] => (Allow) E:\offline\farcry 3\bin\farcry3.exe FirewallRules: [UDP Query User{319F65F9-3916-4900-84E3-4F6FDA488E3E}E:\offline\farcry 3\bin\farcry3.exe] => (Allow) E:\offline\farcry 3\bin\farcry3.exe FirewallRules: [TCP Query User{0355A3DE-D195-4B29-BBA1-B714F4A03128}E:\offline\prototype 2\prototype2.exe] => (Block) E:\offline\prototype 2\prototype2.exe FirewallRules: [UDP Query User{CA6431B6-A542-4D2F-9BC5-2F1E85BC41BB}E:\offline\prototype 2\prototype2.exe] => (Block) E:\offline\prototype 2\prototype2.exe FirewallRules: [{68D9E27C-A325-4DE5-AD65-909E96B3BEDF}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe FirewallRules: [{CC5EB0F8-3852-4C2C-9772-77E90A9BCE35}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{AFB7890D-38B9-45A0-B64A-74D1F7BF0102}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{C79FCDC5-7459-427C-B2B5-DE8503ADC515}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{F0CB64C9-F979-41EA-88ED-E3199FF26154}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{B40BA83C-2626-454C-8621-4E201D9D790D}] => (Allow) D:\Online Games\TxGameAssistant\UI\AndroidEmulator.exe FirewallRules: [{0DCD44EA-75BE-43BB-A45D-15C31FBDE2BF}] => (Allow) D:\Online Games\TxGameAssistant\UI\adb.exe FirewallRules: [{76E6CAD1-370F-41C3-84F6-CDEB4D74F024}] => (Allow) D:\Online Games\TxGameAssistant\UI\TInst.exe FirewallRules: [{9312C46C-2F36-4855-BE42-0364BF5CB99A}] => (Allow) D:\Online Games\TxGameAssistant\UI\bugreport.exe FirewallRules: [{EA3ECA12-AD52-4978-BFAB-D0A042415E2C}] => (Allow) D:\Online Games\TxGameAssistant\UI\TxGaDcc.exe FirewallRules: [TCP Query User{CB93E536-CF3C-4646-A355-1E726227A8BB}D:\offline games\grand theft auto v\gta5.exe] => (Block) D:\offline games\grand theft auto v\gta5.exe FirewallRules: [UDP Query User{09797146-2B8C-4BF7-BE6C-2A8B324DF3E3}D:\offline games\grand theft auto v\gta5.exe] => (Block) D:\offline games\grand theft auto v\gta5.exe FirewallRules: [{1A5C8B83-CC16-4026-AA30-D27D0CFC0370}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe FirewallRules: [{6C0FDF74-7CED-4CB5-BD61-E4F00033C54D}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe FirewallRules: [{3D07ED5D-ADC1-46F5-9D04-A386FD762234}] => (Block) D:\Offline Games\Grand Theft Auto V\GTA5.exe FirewallRules: [{B9D24EF8-B22C-487B-AF7E-8F500E5CD316}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{CB596A9E-2695-47F6-A199-A59D7387873D}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{5647BA26-80F0-44F9-B3E5-887A5208CCD0}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{34EA2354-7AB2-461A-99CF-894ADF3AD3C3}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{5CC8435F-23A7-4CAB-8F43-F1342D00D965}] => (Allow) D:\Online Games\Steam\SteamApps\common\Cuisine Royale\slauncher.exe FirewallRules: [{2E88AEAE-CFDF-4ED7-AA57-C8B607370C5F}] => (Allow) D:\Online Games\Steam\SteamApps\common\Cuisine Royale\slauncher.exe FirewallRules: [{36459BE7-AA6C-45F1-A89C-08B79A1184AC}] => (Allow) C:\Program Files (x86)\SHAREit Technologies\SHAREit\SHAREit.exe FirewallRules: [{2FDF5026-170A-4DA8-95AD-92CD6EF7BFB4}] => (Allow) C:\Program Files (x86)\SHAREit Technologies\SHAREit\SHAREit.exe FirewallRules: [TCP Query User{9F75922D-F942-4443-966B-57803222C4A6}D:\offline games\grand theft auto v - copy\gta5.exe] => (Block) D:\offline games\grand theft auto v - copy\gta5.exe FirewallRules: [UDP Query User{BCEAAE3D-8A1E-48D2-B8D0-16CC3C978FE6}D:\offline games\grand theft auto v - copy\gta5.exe] => (Block) D:\offline games\grand theft auto v - copy\gta5.exe FirewallRules: [{B0F8D262-8176-45D6-887F-6DADFC4F2B59}] => (Allow) D:\Online Games\Steam\SteamApps\common\Deceit\bin\win_x64\Deceit.exe FirewallRules: [{6CD9AAB6-B318-4B24-AEBC-9DCBCCFE7D61}] => (Allow) D:\Online Games\Steam\SteamApps\common\Deceit\bin\win_x64\Deceit.exe FirewallRules: [{D4D88D23-562D-4620-9EA6-D7F23A77ADF9}] => (Allow) D:\Online Games\Steam\bin\cef\cef.win7x64\steamwebhelper.exe FirewallRules: [{0585AB15-5EA1-42B0-985C-514C7434BA50}] => (Allow) D:\Online Games\Steam\bin\cef\cef.win7x64\steamwebhelper.exe FirewallRules: [{D00DCB4B-9CEB-4F8D-AA38-7617E1CB44CD}] => (Allow) C:\Program Files\HP\HP Deskjet Ink Adv 2060 K110\Bin\USBSetup.exe FirewallRules: [{8A3B2A5E-DF0C-4AD8-BE56-AB5551818232}] => (Allow) D:\Online Games\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{22D50773-08B1-41BD-99B6-00724E88C978}] => (Allow) D:\Online Games\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe FirewallRules: [{528945BD-FB65-4D92-A847-76341289F324}] => (Allow) C:\Program Files\AndroidTbox\THypervBox.exe FirewallRules: [{3F422A5B-633E-42ED-882A-8C32F92246E2}] => (Allow) C:\Program Files\AndroidTbox\TBoxHeadless.exe FirewallRules: [{CB555CDD-A5D5-4A30-B016-B484917954A6}] => (Allow) C:\Program Files\AndroidTbox\TBoxNetNAT.exe FirewallRules: [{F29E7500-DCD5-4327-9F07-9F2B1DFBBDDA}] => (Allow) C:\Program Files\AndroidTbox\TBoxSDL.exe FirewallRules: [{E9CAF592-CD52-466B-AD14-274D3F4CEE44}] => (Allow) C:\Program Files\AndroidTbox\TBoxExtPackHelperApp.exe FirewallRules: [{D26305AD-A113-4DB3-A7D8-7770DDE525C0}] => (Allow) C:\Program Files\AndroidTbox\USBInstall.exe FirewallRules: [{30095332-24D8-4FD8-9E82-8D85907E40EC}] => (Allow) C:\Program Files\AndroidTbox\TBoxNetDHCP.exe FirewallRules: [{A37725BC-E975-4331-A2AD-70E81DA85B21}] => (Allow) C:\Program Files\AndroidTbox\TBoxManage.exe FirewallRules: [{C8AF13CE-AC7A-4B0D-BBE5-BD916112E24D}] => (Allow) C:\Program Files\AndroidTbox\USBUninstall.exe FirewallRules: [{EB3F091F-5837-42B0-9587-ED5F9F561F94}] => (Allow) C:\Program Files\AndroidTbox\TInst.exe FirewallRules: [{18AAACDD-FE29-4056-81CC-31C80CF59C08}] => (Allow) C:\Program Files\AndroidTbox\SUPLoggerCtl.exe FirewallRules: [{864F18C4-EBF9-48EA-93EF-735DC9EAB97F}] => (Allow) C:\Program Files\AndroidTbox\NetFltUninstall.exe FirewallRules: [{0C9171BC-06FC-4B96-A174-53A7ED3BD726}] => (Allow) C:\Program Files\AndroidTbox\NetFltInstall.exe FirewallRules: [{8C91E925-CE2D-4D10-9172-32DDC7BE9E11}] => (Allow) C:\Program Files\AndroidTbox\SUPUninstall.exe FirewallRules: [{37AE8927-7E11-4B5C-B3E9-BCD8211511E1}] => (Allow) C:\Program Files\AndroidTbox\TBoxBalloonCtrl.exe FirewallRules: [{2B856237-A3CF-465B-A573-D070E9254183}] => (Allow) C:\Program Files\AndroidTbox\SUPInstall.exe FirewallRules: [{38FFC212-1BB4-4ED8-97A5-B1B9E723E3BA}] => (Allow) C:\Program Files\AndroidTbox\TBoxSVC.exe FirewallRules: [{8E5A33C9-FA75-49CC-B249-5D4AA9AE13B5}] => (Allow) D:\Online Games\TxGameAssistant\UI\AndroidEmulator.exe FirewallRules: [{B83B0A55-BC18-478C-922F-0EEDF1730D0F}] => (Allow) D:\Online Games\TxGameAssistant\UI\adb.exe FirewallRules: [{B9219887-F863-4774-BA16-FD6ADFCB28A0}] => (Allow) D:\Online Games\TxGameAssistant\UI\TInst.exe FirewallRules: [{B6B65821-8B58-4CC9-A167-90254E823A04}] => (Allow) D:\Online Games\TxGameAssistant\UI\bugreport.exe FirewallRules: [{C932A741-77E8-4180-A7B2-31287DCECAEA}] => (Allow) D:\Online Games\TxGameAssistant\UI\TxGaDcc.exe FirewallRules: [{3F637344-1D2E-43D7-9724-89D630B81F9A}] => (Allow) D:\Online Games\Steam\SteamApps\common\Team Fortress 2\hl2.exe FirewallRules: [{48E12FBF-879C-4AA0-BCAC-53E48D10521B}] => (Allow) D:\Online Games\Steam\SteamApps\common\Team Fortress 2\hl2.exe FirewallRules: [{D9462DD0-0576-40B9-873C-6146D2F26BF4}] => (Allow) D:\Online Games\TxGameAssistant\UI\AndroidEmulator.exe FirewallRules: [{4DB07537-7988-4B18-A5FD-A65B198DD9B5}] => (Allow) D:\Online Games\TxGameAssistant\UI\adb.exe FirewallRules: [{1E75D101-1252-472F-B4DC-3E6113C430B4}] => (Allow) D:\Online Games\TxGameAssistant\UI\TInst.exe FirewallRules: [{911FC731-1E90-4237-B3F6-8970227C9519}] => (Allow) D:\Online Games\TxGameAssistant\UI\bugreport.exe FirewallRules: [{456177AF-34E2-427A-A5C6-9078D1762F05}] => (Allow) D:\Online Games\TxGameAssistant\UI\TxGaDcc.exe FirewallRules: [{7094533B-79AC-41DF-A1A5-1A1A10A855B2}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{3276E569-D2B9-4969-896D-1F714FB9FE18}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.0.2\DriverBooster.exe FirewallRules: [{E6E666D2-ACC2-49FD-8ACB-EED4035D0E19}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.0.2\DriverBooster.exe FirewallRules: [{7A7F477F-E28D-4B9A-A253-B39D4D68390D}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.0.2\DBDownloader.exe FirewallRules: [{19F4EF67-F9C8-4957-8E9F-43836580B101}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.0.2\DBDownloader.exe FirewallRules: [{220DFE01-5FAC-43FB-A253-68AB60DEB27A}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.0.2\AutoUpdate.exe FirewallRules: [{042EF991-9EB9-4EDA-943F-147BBD125470}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.0.2\AutoUpdate.exe FirewallRules: [{CA9A2692-41A6-4E26-8B56-E0C98D37E3F2}] => (Allow) D:\Online Games\Steam\SteamApps\common\Cuisine Royale\eac_launcher.exe FirewallRules: [{42A7B025-7585-4241-AC9B-C4FC7F4DA9B4}] => (Allow) D:\Online Games\Steam\SteamApps\common\Cuisine Royale\eac_launcher.exe FirewallRules: [{E9EB12E5-A78F-44C3-8A24-ED059647DB99}] => (Allow) D:\Online Games\Steam\SteamApps\common\Cuisine Royale\bpreport.exe FirewallRules: [{602600D4-24EE-48A2-9A3F-6B4B95A891D8}] => (Allow) D:\Online Games\Steam\SteamApps\common\Cuisine Royale\bpreport.exe FirewallRules: [{7DE497D3-A405-480A-91D7-324CCCA816D8}] => (Allow) D:\Online Games\Steam\SteamApps\common\Cuisine Royale\win32\bpreport.exe FirewallRules: [{73E1B8A0-C091-4753-A24B-BAD3C7E625DD}] => (Allow) D:\Online Games\Steam\SteamApps\common\Cuisine Royale\win32\bpreport.exe FirewallRules: [{72A96225-0052-45DE-888B-C7F828198D9A}] => (Allow) D:\Online Games\Steam\SteamApps\common\Cuisine Royale\gaijin_downloader.exe FirewallRules: [{D2E99C4A-32F1-4992-A2D7-56FD5961D75B}] => (Allow) D:\Online Games\Steam\SteamApps\common\Cuisine Royale\gaijin_downloader.exe FirewallRules: [{2338B2A8-F53C-4700-BEF1-25081BC328DD}] => (Allow) D:\Online Games\Steam\SteamApps\common\Cuisine Royale\win64\enlisted.exe FirewallRules: [{5893044E-6664-485A-9160-448B0DDF8C61}] => (Allow) D:\Online Games\Steam\SteamApps\common\Cuisine Royale\win64\enlisted.exe FirewallRules: [{A3B1D24D-F52A-495A-B9BC-BCC256E7BB81}] => (Allow) C:\Users\JeraldPunx\AppData\Roaming\uTorrent Web\utweb.exe FirewallRules: [{9F0E1340-EEC9-47E0-873E-9B06AD258074}] => (Allow) C:\Users\JeraldPunx\AppData\Roaming\uTorrent Web\utweb.exe FirewallRules: [{812BAC8E-76FD-4244-9A02-0827CFD5FC76}] => (Allow) C:\Program Files\iTunes\iTunes.exe FirewallRules: [TCP Query User{FF48D2E8-70A4-4B2E-8C6E-E41EE15FE49B}C:\program files\nodejs\node.exe] => (Allow) C:\program files\nodejs\node.exe FirewallRules: [UDP Query User{6196A0A4-21DC-4B91-BFBA-5D41183F1289}C:\program files\nodejs\node.exe] => (Allow) C:\program files\nodejs\node.exe FirewallRules: [{F6559EBA-34ED-4C45-92BE-212CD4215FD1}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe FirewallRules: [{23002CD8-F18B-470B-B40E-B9A6908AC4A9}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe FirewallRules: [{45A8D714-AA98-4E34-B6A5-D91A908615F3}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{286DFC17-F6A0-432A-A1B5-07D268419C3C}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{69BD07BE-376D-42BB-A1B0-40F371711BD0}] => (Allow) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe FirewallRules: [{0E35F9F2-69E4-4311-9840-E757173D98C5}] => (Allow) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe FirewallRules: [{389742C9-60CF-440C-A051-5CC179565B03}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe FirewallRules: [{1E839663-4D25-478F-98E3-B13C743F02FA}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe FirewallRules: [{8133D7E2-8EC0-4512-B350-60AC24EBCD1F}] => (Allow) C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\SonarHost.exe FirewallRules: [{86D57101-BC4C-44EE-A290-8FE42EC8125B}] => (Allow) C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\SonarHost.exe FirewallRules: [{619F271F-E7BA-4F9E-A7CD-5E020CDFCE6E}] => (Allow) E:\Offline\Battlefield 4\BFLauncher.exe FirewallRules: [{B0462642-D84B-4597-BDA4-34DB419D052A}] => (Allow) E:\Offline\Battlefield 4\BFLauncher.exe FirewallRules: [{3B7F47E1-5B16-4002-BE4F-F125A173EF2B}] => (Allow) E:\Offline\Battlefield 4\BFLauncher_x86.exe FirewallRules: [{3A9B2273-8DB0-43EC-8FC5-F76383B96DF7}] => (Allow) E:\Offline\Battlefield 4\BFLauncher_x86.exe FirewallRules: [{E80C201B-8CFF-4CF2-ACB4-78DAB554158A}] => (Allow) D:\Online Games\Steam\SteamApps\common\PUBG\TslGame\Binaries\Win64\ExecPubg.exe FirewallRules: [{52F06AB1-3A01-4838-990F-A44E22E0AAB3}] => (Allow) D:\Online Games\Steam\SteamApps\common\PUBG\TslGame\Binaries\Win64\ExecPubg.exe FirewallRules: [{2E14DE7E-1D2E-42FD-A154-1A9EEB45C48A}] => (Allow) D:\Online Games\Steam\SteamApps\common\SMITE\Binaries\Win32\HirezBridge.exe FirewallRules: [{EA35D925-AA03-40CE-8BC0-61ADB79CB06E}] => (Allow) D:\Online Games\Steam\SteamApps\common\SMITE\Binaries\Win32\HirezBridge.exe FirewallRules: [{290FDE15-2D54-4BBE-B4E2-F89D8E20AB1A}] => (Allow) D:\Online Games\TxGameAssistant\UI\AndroidEmulator.exe FirewallRules: [{1D665A50-4021-4AB3-9A1B-2D586857F95D}] => (Allow) D:\Online Games\TxGameAssistant\UI\adb.exe FirewallRules: [{B3E945BD-A92B-4B32-830A-767740B4DB65}] => (Allow) D:\Online Games\TxGameAssistant\UI\TInst.exe FirewallRules: [{E8411EEF-280C-457F-858C-DBBE1961218A}] => (Allow) D:\Online Games\TxGameAssistant\UI\bugreport.exe FirewallRules: [{7481266C-F3DB-4248-A4F9-AF95EBF67F64}] => (Allow) D:\Online Games\TxGameAssistant\UI\TxGaDcc.exe FirewallRules: [TCP Query User{49B5B9B7-99F9-49D7-9FDC-4D3860425ECB}C:\users\jeraldpunx\appdata\local\bluejeans\current\bluejeans.exe] => (Allow) C:\users\jeraldpunx\appdata\local\bluejeans\current\bluejeans.exe FirewallRules: [UDP Query User{E201732C-F988-4B88-8641-240BC9484EF3}C:\users\jeraldpunx\appdata\local\bluejeans\current\bluejeans.exe] => (Allow) C:\users\jeraldpunx\appdata\local\bluejeans\current\bluejeans.exe FirewallRules: [TCP Query User{786EF200-A4F7-40DD-A560-7416578D58E2}D:\online games\destiny 2\destiny2.exe] => (Allow) D:\online games\destiny 2\destiny2.exe FirewallRules: [UDP Query User{C028FAEB-9A38-4303-ABB2-285A5C86D436}D:\online games\destiny 2\destiny2.exe] => (Allow) D:\online games\destiny 2\destiny2.exe FirewallRules: [OpenSSH-Server-In-TCP] => (Allow) %SystemRoot%\system32\OpenSSH\sshd.exe FirewallRules: [{C0879EBD-E446-4DA9-BCCE-450E9E306C26}] => (Block) c:\program files\voicemod desktop\voicemoddesktop.exe ==================== Restore Points ========================= 07-10-2018 21:05:34 Microsoft Visual C++ 2017 Redistributable (x64) - 14.13.26020 ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (10/08/2018 10:57:19 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: svchost.exe_WpnUserService, version: 10.0.17134.1, time stamp: 0xa38b9ab2 Faulting module name: NotificationController.dll, version: 10.0.17134.165, time stamp: 0xe0385185 Exception code: 0xc0000005 Fault offset: 0x000000000007c686 Faulting process id: 0x1344 Faulting application start time: 0x01d45eabe3d91d16 Faulting application path: C:\WINDOWS\system32\svchost.exe Faulting module path: C:\Windows\System32\NotificationController.dll Report Id: d6e642e7-29ec-457c-817c-7081a4523726 Faulting package full name: Faulting package-relative application ID: Error: (10/08/2018 08:22:55 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: svchost.exe_WpnUserService, version: 10.0.17134.1, time stamp: 0xa38b9ab2 Faulting module name: NotificationController.dll, version: 10.0.17134.165, time stamp: 0xe0385185 Exception code: 0xc0000005 Fault offset: 0x000000000007c686 Faulting process id: 0x4f0 Faulting application start time: 0x01d45e6ad19bda97 Faulting application path: C:\WINDOWS\system32\svchost.exe Faulting module path: C:\Windows\System32\NotificationController.dll Report Id: f3c06395-584f-46cb-a5d9-fcfd1655cf53 Faulting package full name: Faulting package-relative application ID: Error: (10/07/2018 09:08:17 PM) (Source: VSS) (EventID: 8193) (User: ) Description: Volume Shadow Copy Service error: Unexpected error calling routine QueryFullProcessImageNameW. hr = 0x80070006, The handle is invalid. . Operation: Executing Asynchronous Operation Context: Current State: DoSnapshotSet Error: (10/07/2018 09:05:34 PM) (Source: VSS) (EventID: 8193) (User: ) Description: Volume Shadow Copy Service error: Unexpected error calling routine QueryFullProcessImageNameW. hr = 0x80070006, The handle is invalid. . Operation: Executing Asynchronous Operation Context: Current State: DoSnapshotSet Error: (10/07/2018 08:23:21 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program explorer.exe version 10.0.17134.165 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel. Process ID: 1630 Start Time: 01d45e3869fe80e0 Termination Time: 0 Application Path: C:\Windows\explorer.exe Report Id: b7689056-2036-4aff-870c-68f5cd3b4d97 Faulting package full name: Faulting package-relative application ID: Error: (10/07/2018 08:22:29 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program explorer.exe version 10.0.17134.165 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel. Process ID: 15c8 Start Time: 01d45e382c37e364 Termination Time: 0 Application Path: C:\Windows\explorer.exe Report Id: d2bccb11-c9da-4530-81cc-c34781ddbdd6 Faulting package full name: Faulting package-relative application ID: Error: (10/07/2018 07:28:12 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: svchost.exe_WpnUserService, version: 10.0.17134.1, time stamp: 0xa38b9ab2 Faulting module name: NotificationController.dll, version: 10.0.17134.165, time stamp: 0xe0385185 Exception code: 0xc0000005 Fault offset: 0x000000000007c686 Faulting process id: 0x11d0 Faulting application start time: 0x01d45e29df26ef9a Faulting application path: C:\WINDOWS\system32\svchost.exe Faulting module path: C:\Windows\System32\NotificationController.dll Report Id: e96cd1ed-ca34-424b-bfdf-622ef6771977 Faulting package full name: Faulting package-relative application ID: Error: (10/07/2018 06:32:02 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: svchost.exe_WpnUserService, version: 10.0.17134.1, time stamp: 0xa38b9ab2 Faulting module name: NotificationController.dll, version: 10.0.17134.165, time stamp: 0xe0385185 Exception code: 0xc0000005 Fault offset: 0x000000000007c686 Faulting process id: 0x2c70 Faulting application start time: 0x01d45e20374f07dc Faulting application path: C:\WINDOWS\system32\svchost.exe Faulting module path: C:\Windows\System32\NotificationController.dll Report Id: 8731e92f-c84e-42c7-85b1-76966e1079de Faulting package full name: Faulting package-relative application ID: System errors: ============= Error: (10/08/2018 03:48:13 PM) (Source: DCOM) (EventID: 10016) (User: JERALDPUNX-PC) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the user JERALDPUNX-PC\JeraldPunx SID (S-1-5-21-886221053-1638992907-3193777533-1002) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (10/08/2018 11:44:22 AM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY) Description: The server {B91D5831-B1BD-4608-8198-D72E155020F7} did not register with DCOM within the required timeout. Error: (10/08/2018 11:44:02 AM) (Source: Service Control Manager) (EventID: 7022) (User: ) Description: The Update Orchestrator Service service hung on starting. Error: (10/08/2018 11:41:07 AM) (Source: Service Control Manager) (EventID: 7022) (User: ) Description: The Downloaded Maps Manager service hung on starting. Error: (10/08/2018 11:39:03 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The GoPro Device Detection Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. Error: (10/08/2018 11:39:03 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: A timeout was reached (30000 milliseconds) while waiting for the GoPro Device Detection Service service to connect. Error: (10/08/2018 11:34:42 AM) (Source: Microsoft-Windows-Ntfs) (EventID: 98) (User: NT AUTHORITY) Description: C:\Device\HarddiskVolume23 Error: (10/08/2018 11:34:42 AM) (Source: Ntfs) (EventID: 55) (User: NT AUTHORITY) Description: A corruption was discovered in the file system structure on volume C:. The exact nature of the corruption is unknown. The file system structures need to be scanned and fixed offline. Windows Defender: =================================== Date: 2018-09-05 00:15:11.385 Description: Windows Defender Antivirus has detected malware or other potentially unwanted software. For more information please see the following: https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/Fuerboos.E!cl&threatid=2147723656&enterprise=0 Name: Trojan:Win32/Fuerboos.E!cl ID: 2147723656 Severity: Severe Category: Trojan Path: file:_F:\GR11\autorun.inf.exe; file:_F:\GR11\RECYCLER.exe Detection Origin: Local machine Detection Type: FastPath Detection Source: Real-Time Protection Process Name: C:\Windows\explorer.exe Signature Version: AV: 1.275.718.0, AS: 1.275.718.0, NIS: 1.275.718.0 Engine Version: AM: 1.1.15200.1, NIS: 1.1.15200.1 Date: 2018-09-05 00:15:11.203 Description: Windows Defender Antivirus has detected malware or other potentially unwanted software. For more information please see the following: https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/Fuerboos.E!cl&threatid=2147723656&enterprise=0 Name: Trojan:Win32/Fuerboos.E!cl ID: 2147723656 Severity: Severe Category: Trojan Path: file:_F:\GR11\autorun.inf.exe Detection Origin: Local machine Detection Type: FastPath Detection Source: Real-Time Protection Process Name: C:\Windows\explorer.exe Signature Version: AV: 1.275.718.0, AS: 1.275.718.0, NIS: 1.275.718.0 Engine Version: AM: 1.1.15200.1, NIS: 1.1.15200.1 Date: 2018-07-26 03:21:42.090 Description: Windows Defender Antivirus has detected malware or other potentially unwanted software. For more information please see the following: https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/Occamy.C&threatid=2147726780&enterprise=0 Name: Trojan:Win32/Occamy.C ID: 2147726780 Severity: Severe Category: Trojan Path: file:_C:\Users\JeraldPunx\AppData\Local\Temp\rld-gtav141.7z;file:_C:\Users\JERALD~1\AppData\Local\Temp\rld-gtav141.7z Detection Origin: Local machine Detection Type: FastPath Detection Source: Real-Time Protection Process Name: C:\Program Files\WinRAR\WinRAR.exe Signature Version: AV: 1.273.337.0, AS: 1.273.337.0, NIS: 1.273.337.0 Engine Version: AM: 1.1.15100.1, NIS: 1.1.15100.1 Date: 2018-07-26 03:21:37.028 Description: Windows Defender Antivirus has detected malware or other potentially unwanted software. For more information please see the following: https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/Occamy.C&threatid=2147726780&enterprise=0 Name: Trojan:Win32/Occamy.C ID: 2147726780 Severity: Severe Category: Trojan Path: file:_C:\Users\JERALD~1\AppData\Local\Temp\rld-gtav141.7z Detection Origin: Local machine Detection Type: FastPath Detection Source: Real-Time Protection Process Name: C:\Program Files\WinRAR\WinRAR.exe Signature Version: AV: 1.273.337.0, AS: 1.273.337.0, NIS: 1.273.337.0 Engine Version: AM: 1.1.15100.1, NIS: 1.1.15100.1 Date: 2018-07-13 10:14:36.635 Description: Windows Defender Antivirus has detected malware or other potentially unwanted software. For more information please see the following: https://go.microsoft.com/fwlink/?linkid=37020&name=HackTool:Win32/Gendows&threatid=2147646077&enterprise=0 Name: HackTool:Win32/Gendows ID: 2147646077 Severity: High Category: Tool Path: containerfile:_H:\Windows 7 ACTIVATION.zip;file:_H:\Windows 7 ACTIVATION.zip;file:_H:\Windows 7 ACTIVATION.zip->Windows 7 Activation.exe Detection Origin: Local machine Detection Type: FastPath Detection Source: System Process Name: Unknown Signature Version: AV: 1.271.913.0, AS: 1.271.913.0, NIS: 1.271.913.0 Engine Version: AM: 1.1.15000.2, NIS: 1.1.15000.2 Date: 2018-09-05 14:20:39.694 Description: Windows Defender Antivirus has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.275.727.0 Update Source: Microsoft Update Server Signature Type: AntiVirus Update Type: Full Current Engine Version: Previous Engine Version: 1.1.15200.1 Error code: 0x8024402f Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support. CodeIntegrity: =================================== Date: 2018-10-08 16:21:41.424 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Microsoft signing level requirements. Date: 2018-10-08 16:21:41.423 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Microsoft signing level requirements. Date: 2018-10-08 15:54:45.804 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Microsoft signing level requirements. Date: 2018-10-08 15:54:45.802 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Microsoft signing level requirements. Date: 2018-10-08 15:51:41.430 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Microsoft signing level requirements. Date: 2018-10-08 15:51:41.429 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Microsoft signing level requirements. Date: 2018-10-08 15:39:44.698 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Microsoft signing level requirements. Date: 2018-10-08 15:39:44.696 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Microsoft signing level requirements. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i5-4460 CPU @ 3.20GHz Percentage of memory in use: 64% Total physical RAM: 8130.41 MB Available physical RAM: 2856.12 MB Total Virtual: 13762.41 MB Available Virtual: 7240.84 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:330.98 GB) (Free:156.99 GB) NTFS Drive d: (New Volume) (Fixed) (Total:600 GB) (Free:21.77 GB) NTFS Drive e: (New Volume) (Fixed) (Total:298.09 GB) (Free:66.24 GB) NTFS \\?\Volume{6b737ca8-0000-0000-0000-100000000000}\ (System Reserved) (Fixed) (Total:0.54 GB) (Free:0.14 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7/8/10) (Size: 931.5 GB) (Disk ID: 6B737CA8) Partition 1: (Active) - (Size=549 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=331 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=600 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7/8/10) (Size: 298.1 GB) (Disk ID: A2CEEF95) Partition 1: (Not Active) - (Size=298.1 GB) - (Type=07 NTFS) ==================== End of Addition.txt ============================