Additional scan result of Farbar Recovery Scan Tool (x64) Version: 17.03.2019 Ran by [removed] (02-04-2019 17:56:11) Running from C:\Users\[removed]\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\TempState\Downloads Windows 10 Pro Version 1803 17134.648 (X64) (2019-02-24 17:46:21) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-3843450261-267223717-1376901193-500 - Administrator - Disabled) Dean Miles (S-1-5-21-3843450261-267223717-1376901193-1001 - Administrator - Enabled) => C:\Users\Dean Miles DefaultAccount (S-1-5-21-3843450261-267223717-1376901193-503 - Limited - Disabled) defaultuser0 (S-1-5-21-3843450261-267223717-1376901193-1000 - Administrator - Disabled) Guest (S-1-5-21-3843450261-267223717-1376901193-501 - Limited - Disabled) WDAGUtilityAccount (S-1-5-21-3843450261-267223717-1376901193-504 - Limited - Disabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: Kaspersky Free (Enabled - Up to date) {0AB30972-4BAC-7BEE-CBCA-B8F9E68797D8} AS: Kaspersky Free (Enabled - Up to date) {B1D2E896-6D96-7460-F17A-838B9D00DD65} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 7-Zip 19.00 (x64) (HKLM\...\7-Zip) (Version: 19.00 - Igor Pavlov) AMD Settings (HKLM\...\WUCCCApp) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Avira Phantom VPN (HKLM-x32\...\Avira Phantom VPN) (Version: 2.21.2.30481 - Avira Operations GmbH & Co. KG) BitLord 2.4 (HKLM-x32\...\BitLord) (Version: 2.4.6-336 - House of Life) BlueStacks App Player (HKLM\...\BlueStacks) (Version: 4.50.5.1003 - BlueStack Systems, Inc.) Brackets (HKLM-x32\...\{0AE22FBF-578D-45D9-9E2D-9678512154AC}) (Version: 1.13.17699 - brackets.io) Catalyst Control Center Next Localization BR (HKLM\...\{A16E186C-58C4-3BDC-5CCE-714EFEF5F27F}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization BR (HKLM\...\{E7AA1A02-575C-14C6-FBEF-4BE6D46A5B74}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CHS (HKLM\...\{E42911E5-48F8-8557-ED20-D72AD1907D25}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CHS (HKLM\...\{EB6C44F1-0F78-FE10-BC63-90BA50AB0CE9}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CHT (HKLM\...\{B26D75B8-FAB7-6F8B-767F-BAF975383D91}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CHT (HKLM\...\{B4C30EF4-B2C5-1395-B534-7B63BCB6E8E4}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CS (HKLM\...\{36EDC500-E4C0-371C-9865-08450415C1E9}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CS (HKLM\...\{62098A5F-E03B-31A3-5F9C-51A7F7D25744}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization DA (HKLM\...\{1757AD9B-0E3C-05F9-FE43-4343BED7DA85}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization DA (HKLM\...\{4C2FB7FD-89FD-BA5C-585A-3811F326AD34}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization DE (HKLM\...\{66B06F29-EE4F-9130-D96A-754826093FEA}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization DE (HKLM\...\{D74218A3-C503-57EF-AC9F-2220082E7ADE}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization EL (HKLM\...\{821D0A0E-F246-BE40-0D68-93883C14C410}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization EL (HKLM\...\{DA433FCF-90A1-19A5-65A7-FDF82DE4826D}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization ES (HKLM\...\{88BD74C4-23AB-4554-915C-6E1F0C81F6CD}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization ES (HKLM\...\{949F125B-A6CC-5A5E-EEE7-4AC50305C1FA}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization FI (HKLM\...\{20D46801-147B-30AD-7C5A-AC4560A79096}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization FI (HKLM\...\{A48E2AB0-0866-7783-9657-E1709EB18D02}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization FR (HKLM\...\{22C39711-2747-D264-319A-1550BEEAAEC6}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization FR (HKLM\...\{E61CEF9A-BAC3-EAEE-F735-E257D2354DF2}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization HU (HKLM\...\{1DBACFDB-5E43-7882-36BD-53526D34BD22}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization HU (HKLM\...\{DA0326BB-657D-AAFC-752C-363E8FA33755}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization IT (HKLM\...\{A91FC4BF-C1EC-ADCA-79D1-F4F0671F1D60}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization IT (HKLM\...\{B873A1FB-5EA0-EE5F-A861-1E38880AD08E}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization JA (HKLM\...\{EC9DF9FF-9D75-4CDD-1D58-A2E887B0A42E}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization JA (HKLM\...\{ED75A775-03A7-F214-868D-497748707968}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization KO (HKLM\...\{07BFBD5C-2F63-6828-1B61-B41A44113F3B}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization KO (HKLM\...\{7ABACA7E-6E59-0EF9-8FA3-6B32E5F58127}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization NL (HKLM\...\{3E196AAF-F81C-B384-E2AB-28EE2398FE5F}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization NL (HKLM\...\{E6038D3E-5D87-8DF7-6D05-BE7532C3E73E}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization NO (HKLM\...\{DAEFFE0C-CD05-1355-6AFC-7B3D4106A820}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization NO (HKLM\...\{DFAD9DAC-4768-C8BB-4E0E-5239605A9BEA}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization PL (HKLM\...\{E392A425-53A7-DF90-96A0-E287A75DD3B2}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization PL (HKLM\...\{FFBFBD1F-B160-A119-7C43-8584FA2E5665}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization RU (HKLM\...\{4D1D5407-9B69-6422-629C-8518A26004A4}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization RU (HKLM\...\{D6F47BB4-700A-F612-0671-5F69EA311BB7}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization SV (HKLM\...\{01FD9A26-3F61-9236-B360-BE5D043D82C0}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization SV (HKLM\...\{A8379BAB-59A9-C0A3-8BCC-4852EA403692}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization TH (HKLM\...\{24DF617A-CD23-6E6A-126B-23630D2781CE}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization TH (HKLM\...\{64D4CCC3-63DF-252D-D29D-03491670225D}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization TR (HKLM\...\{83DDDFD8-AD42-72F9-E4F1-5456FDB304C9}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization TR (HKLM\...\{8DF90937-B869-9F76-5D45-5A8BDA0A33B6}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden CCleaner (HKLM\...\CCleaner) (Version: 5.55 - Piriform) CursorFX (HKLM-x32\...\{C1080852-065E-4991-9260-F3756E3CC182}) (Version: 2.00 - Stardock Corporation) Hidden CursorFX Plus (HKLM-x32\...\CursorFX Plus) (Version: - Stardock Corporation) Defraggler (HKLM\...\Defraggler) (Version: 2.22 - Piriform) Discord (HKU\S-1-5-21-3843450261-267223717-1376901193-1001\...\Discord) (Version: 0.0.305 - Discord Inc.) Download Accelerator Plus (DAP) (HKLM-x32\...\Download Accelerator Plus (DAP)) (Version: 10060 (Build 2599) - Speedbit Ltd.) GIMP 2.10.8 (HKLM\...\GIMP-2_is1) (Version: 2.10.8 - The GIMP Team) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.34.7 - Google LLC) Hidden Gyazo 3.5.4.0 (HKLM-x32\...\{6DB8C365-E719-4BA5-9594-10DFC244D3FD}_is1) (Version: - Nota Inc.) HitmanPro 3.8 (HKLM\...\HitmanPro38) (Version: 3.8.11.300 - SurfRight B.V.) IObit Uninstaller 8 (HKLM-x32\...\IObitUninstall) (Version: 8.4.0.7 - IObit) Java 8 Update 201 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180201F0}) (Version: 8.0.2010.9 - Oracle Corporation) Kaspersky Free (HKLM-x32\...\{718613F4-492D-4272-ACC3-D04A8EF0F883}) (Version: 19.0.0.1088 - Kaspersky Lab) Hidden Kaspersky Free (HKLM-x32\...\InstallWIX_{718613F4-492D-4272-ACC3-D04A8EF0F883}) (Version: 19.0.0.1088 - Kaspersky Lab) Kaspersky Secure Connection (HKLM-x32\...\{F10AA188-7166-430E-8810-FEAB2AD73DE3}) (Version: 19.0.0.1088 - Kaspersky Lab) Hidden Kaspersky Secure Connection (HKLM-x32\...\InstallWIX_{F10AA188-7166-430E-8810-FEAB2AD73DE3}) (Version: 19.0.0.1088 - Kaspersky Lab) Lightshot-5.4.0.35 (HKLM-x32\...\{30A5B3C9-2084-4063-A32A-628A98DE512B}_is1) (Version: 5.4.0.35 - Skillbrains) Malwarebytes version 3.7.1.2839 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.7.1.2839 - Malwarebytes) Microsoft .NET Core 2.2.3 - Windows Server Hosting (HKLM-x32\...\{b47538b1-1581-4d1a-81e3-87858a9366a6}) (Version: 2.2.3.0 - Microsoft Corporation) Microsoft .NET Core Runtime - 2.2.3 (x64) (HKLM-x32\...\{348148f5-5b02-46e8-ac6e-93e7329a2e5a}) (Version: 2.2.3.27414 - Microsoft Corporation) Microsoft .NET Core Runtime - 2.2.3 (x86) (HKLM-x32\...\{0dda4081-adec-41dc-bf10-5ffb0e11efce}) (Version: 2.2.3.27414 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-3843450261-267223717-1376901193-1001\...\OneDriveSetup.exe) (Version: 19.033.0218.0011 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2017 Redistributable (x64) - 14.10.25008 (HKLM-x32\...\{f1e7e313-06df-4c56-96a9-99fdfd149c51}) (Version: 14.10.25008.0 - Microsoft Corporation) Microsoft Visual C++ 2017 Redistributable (x86) - 14.10.25008 (HKLM-x32\...\{c239cea1-d49e-4e16-8e87-8c055765f7ec}) (Version: 14.10.25008.0 - Microsoft Corporation) Minecraft Launcher (HKLM-x32\...\{54AFFE31-F012-4585-939B-B8D6CA77E022}) (Version: 1.0.0.0 - Mojang) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 60.6.0 - Mozilla) Mozilla Thunderbird 60.6.0 (x86 en-GB) (HKLM-x32\...\Mozilla Thunderbird 60.6.0 (x86 en-GB)) (Version: 60.6.0 - Mozilla) Opera Stable 58.0.3135.127 (HKU\S-1-5-21-3843450261-267223717-1376901193-1001\...\Opera 58.0.3135.127) (Version: 58.0.3135.127 - Opera Software) Origin (HKLM-x32\...\Origin) (Version: 10.5.35.22222 - Electronic Arts, Inc.) osrss (HKLM-x32\...\{1BA1133B-1C7A-41A0-8CBF-9B993E63D296}) (Version: 1.0.0 - Microsoft Corporation) Hidden paint.net (HKLM\...\{B998B716-4001-4919-BA90-BA14B51DFEB5}) (Version: 4.1.6 - dotPDN LLC) PCSX2 - Playstation 2 Emulator (HKLM-x32\...\pcsx2) (Version: - ) Rainmeter (HKLM-x32\...\Rainmeter) (Version: 4.3 r3298 - Rainmeter) Remotr version 1.3.1438 (HKLM-x32\...\Remotr_is1) (Version: 1.3.1438 - RemoteMyApp sp. z o.o.) Roblox Player for Dean Miles (HKU\S-1-5-21-3843450261-267223717-1376901193-1001\...\roblox-player) (Version: - Roblox Corporation) Stardock Fences 3 (HKLM-x32\...\Stardock Fences 3) (Version: 3.03 - Stardock Software, Inc.) Stardock WindowBlinds (HKLM-x32\...\Stardock WindowBlinds) (Version: 10.74 - Stardock Software, Inc.) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) The Sims™ 4 (HKLM-x32\...\{48EBEBBF-B9F8-4520-A3CF-89A730721917}) (Version: 1.49.65.1020 - Electronic Arts Inc.) The Walking Dead The Final Season Episode 1 (HKLM-x32\...\The Walking Dead The Final Season Episode 1_is1) (Version: - ) Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{FBA3961B-D1DF-493C-BC1F-E67D3B832895}) (Version: 2.56.0.0 - Microsoft Corporation) Update for Windows 10 for x64-based Systems (KB4480730) (HKLM\...\{13668B9F-F140-4BAB-AB06-08E0D43564F4}) (Version: 2.51.0.0 - Microsoft Corporation) Winamp (HKLM-x32\...\Winamp) (Version: 5.8 - Winamp SA) Windows Driver Package - Microsoft PS VR Control (Interface 5) (02/22/2013 6.1.7600.16385) (HKLM\...\7664041C62AE68D4B2EB4627167336BB2D4D7C46) (Version: 02/22/2013 6.1.7600.16385 - Microsoft) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-3843450261-267223717-1376901193-1001_Classes\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6} -> [OneDrive] => {a52bba46-e9e1-435f-b3d9-28daa648c0f6} ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2019-02-21] (Igor Pavlov) [File not signed] ContextMenuHandlers1: [DefragglerShellExtension] -> {4380C993-0C43-4E02-9A7A-0D40B6EA7590} => C:\Program Files\Defraggler\DefragglerShell64.dll [2018-05-02] (Piriform Ltd -> Piriform Ltd) ContextMenuHandlers1: [FencesShellExt] -> {1984DD45-52CF-49cd-AB77-18F378FEA264} => C:\Program Files (x86)\Stardock\Fences\FencesMenu64.dll [2016-09-16] (Stardock Corporation -> Stardock) ContextMenuHandlers1: [IObitUnstaler] -> {836AB26C-2DE4-41D3-AC24-4C6C2699B960} => C:\Program Files (x86)\IObit\IObit Uninstaller\IUMenuRight.dll [2018-07-21] (IObit Information Technology -> IObit) ContextMenuHandlers1: [Kaspersky Anti-Virus 19.0.0] -> {755D388B-420B-4692-A974-84AAF0E577D3} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 19.0.0\x64\ShellEx.dll [2019-03-31] (Kaspersky Lab -> AO Kaspersky Lab) ContextMenuHandlers2: [Kaspersky Anti-Virus 19.0.0] -> {755D388B-420B-4692-A974-84AAF0E577D3} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 19.0.0\x64\ShellEx.dll [2019-03-31] (Kaspersky Lab -> AO Kaspersky Lab) ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-02-01] (Malwarebytes Corporation -> Malwarebytes) ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2019-02-21] (Igor Pavlov) [File not signed] ContextMenuHandlers4: [FencesShellExt] -> {1984DD45-52CF-49cd-AB77-18F378FEA264} => C:\Program Files (x86)\Stardock\Fences\FencesMenu64.dll [2016-09-16] (Stardock Corporation -> Stardock) ContextMenuHandlers4: [IObitUnstaler] -> {836AB26C-2DE4-41D3-AC24-4C6C2699B960} => C:\Program Files (x86)\IObit\IObit Uninstaller\IUMenuRight.dll [2018-07-21] (IObit Information Technology -> IObit) ContextMenuHandlers4: [Kaspersky Anti-Virus 19.0.0] -> {755D388B-420B-4692-A974-84AAF0E577D3} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 19.0.0\x64\ShellEx.dll [2019-03-31] (Kaspersky Lab -> AO Kaspersky Lab) ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Program Files\AMD\CNext\CNext\atiacm64.dll [2017-09-22] (Advanced Micro Devices, Inc.) [File not signed] ContextMenuHandlers5: [FencesShellExt] -> {1984DD45-52CF-49cd-AB77-18F378FEA264} => C:\Program Files (x86)\Stardock\Fences\FencesMenu64.dll [2016-09-16] (Stardock Corporation -> Stardock) ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2019-02-21] (Igor Pavlov) [File not signed] ContextMenuHandlers6: [DefragglerShellExtension] -> {4380C993-0C43-4E02-9A7A-0D40B6EA7590} => C:\Program Files\Defraggler\DefragglerShell64.dll [2018-05-02] (Piriform Ltd -> Piriform Ltd) ContextMenuHandlers6: [FencesShellExt] -> {1984DD45-52CF-49cd-AB77-18F378FEA264} => C:\Program Files (x86)\Stardock\Fences\FencesMenu64.dll [2016-09-16] (Stardock Corporation -> Stardock) ContextMenuHandlers6: [IObitUnstaler] -> {836AB26C-2DE4-41D3-AC24-4C6C2699B960} => C:\Program Files (x86)\IObit\IObit Uninstaller\IUMenuRight.dll [2018-07-21] (IObit Information Technology -> IObit) ContextMenuHandlers6: [Kaspersky Anti-Virus 19.0.0] -> {755D388B-420B-4692-A974-84AAF0E577D3} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 19.0.0\x64\ShellEx.dll [2019-03-31] (Kaspersky Lab -> AO Kaspersky Lab) ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-02-01] (Malwarebytes Corporation -> Malwarebytes) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {106435B2-D95F-4824-8485-C6B4FBC4117F} - System32\Tasks\BlueStacksHelper => C:\ProgramData\BlueStacks\Client\Helper\BlueStacksHelper.exe (BlueStack Systems, Inc. -> BlueStack Systems, Inc.) Task: {1BA23B59-5BBC-42D9-AB70-3CC71EC5C9D9} - System32\Tasks\GyazoUpdateTaskMachine => C:\Program Files (x86)\Gyazo\GyazoUpdate.exe (Nota Inc. -> Nota Inc.) Task: {1BC71D07-9813-43A0-AEDE-173731F2AD91} - System32\Tasks\Uninstaller_SkipUac_Dean_Miles => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe (IObit Information Technology -> IObit) Task: {2B7AEFE3-E114-40C1-9FAD-6110747FFE90} - System32\Tasks\S-1-5-21-3843450261-267223717-1376901193-1001\DataSenseLiveTileTask => C:\WINDOWS\System32\DataUsageLiveTileTask.exe (Microsoft Windows -> Microsoft Corporation) Task: {3CB787BF-D5F7-4CF8-9F7A-0AE44F0063D9} - System32\Tasks\Opera scheduled assistant Autoupdate 1550663977 => C:\Users\Dean Miles\AppData\Local\Programs\Opera\launcher.exe (Opera Software AS -> Opera Software) Task: {7406FC63-F118-45E5-BC3E-6F6BD1B7E405} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe (Piriform Software Ltd -> Piriform Software Ltd) Task: {7B9B2F67-05C7-4421-B8B1-39B7F29CE9A6} - System32\Tasks\Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901} => C:\Program Files\Common Files\AV\Kaspersky Lab\upgrade_launcher.exe (Kaspersky Lab -> AO Kaspersky Lab) Task: {7D96E7EA-BE5C-4D55-9769-07B2D795E16F} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: {7F49A5C5-852F-4647-A180-7BE4D8312099} - System32\Tasks\Opera scheduled Autoupdate 1550663975 => C:\Users\Dean Miles\AppData\Local\Programs\Opera\launcher.exe (Opera Software AS -> Opera Software) Task: {82A302F6-4D75-4D8F-BBF5-C28F58B780E4} - System32\Tasks\update-S-1-5-21-3843450261-267223717-1376901193-1001 => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe (OOO Lightshot -> TODO: ) Task: {93CB5624-332F-4DD2-8C2A-7AD0B2C927A9} - System32\Tasks\Microsoft\Windows\Flighting\FeatureConfig\ReconcileFeatures Task: {AC20854C-C03C-476E-A75E-CE3D4A4A91E3} - System32\Tasks\update-sys => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe (OOO Lightshot -> TODO: ) Task: {B067F938-1FC0-4E7D-8729-D1107EDF20A3} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) Task: {BA20B270-4DC5-4FE6-AF3B-3B0A6BE10CFE} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe (Piriform Software Ltd -> Piriform Software Ltd) Task: {BB0E3A3C-96F6-4612-9A55-4D41837E658B} - System32\Tasks\Microsoft\Windows\CUAssistant\CULauncher => C:\Program Files\CUAssistant\culauncher.exe (Microsoft Windows -> Microsoft Corporation) Task: {E731E50D-5B66-4489-9622-DB3BBEE825B6} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: {EA036489-5697-43E0-8C1B-DDC6CB3FDD63} - System32\Tasks\Opera scheduled Autoupdate 1554148284 => C:\Users\Dean Miles\AppData\Local\Programs\Opera\launcher.exe (Opera Software AS -> Opera Software) Task: {FA28BF1D-46B3-421C-A65F-8A701C645A73} - System32\Tasks\GyazoUpdateTaskMachineDaily => C:\Program Files (x86)\Gyazo\GyazoUpdate.exe (Nota Inc. -> Nota Inc.) Task: {FAD7383C-8CF3-4B00-8691-2ED7C880D72E} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\WINDOWS\explorer.exe /NOUACCHECK (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\update-S-1-5-21-3843450261-267223717-1376901193-1001.job => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe Task: C:\WINDOWS\Tasks\update-sys.job => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe ==================== Shortcuts & WMI ======================== (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== 2017-03-16 19:16 - 2017-03-16 19:16 - 001180400 _____ (Stardock Corporation -> Stardock Software, Inc) [File not signed] C:\Program Files (x86)\Stardock\WindowBlinds\WBSrv.dll 2016-10-10 14:43 - 2016-10-10 14:43 - 001003216 _____ (Stardock Corporation -> Stardock Software, Inc) [File not signed] C:\Program Files (x86)\Stardock\WindowBlinds\tray64.dll 2016-09-16 21:38 - 2016-09-16 21:38 - 001018840 _____ (Stardock Corporation -> Stardock) [File not signed] c:\program files (x86)\stardock\fences\DesktopDock64.dll 2015-09-01 14:19 - 2015-09-01 14:19 - 001257480 _____ (Stardock Corporation -> Stardock Corporation) [File not signed] c:\program files (x86)\stardock\fences\SdAppServices_x64.dll 2019-03-16 23:18 - 2019-03-16 23:31 - 000095744 ____N () [File not signed] C:\WINDOWS\Womtrust.dll 2019-03-31 12:32 - 2019-02-21 17:00 - 000078336 _____ (Igor Pavlov) [File not signed] C:\Program Files\7-Zip\7-zip.dll 2017-09-22 17:57 - 2017-09-22 17:57 - 000979456 _____ (Advanced Micro Devices, Inc.) [File not signed] C:\Program Files\AMD\CNext\CNext\atiacm64.dll 2019-03-18 16:02 - 2019-03-18 16:02 - 000315392 _____ () [File not signed] C:\Program Files\Rainmeter\Plugins\ActionTimer.DLL 2019-03-20 21:06 - 2019-03-20 21:06 - 000108544 _____ () [File not signed] C:\Users\Dean Miles\AppData\Roaming\Rainmeter\Plugins\ConfigActive.DLL 2019-03-20 21:06 - 2019-03-20 21:06 - 000026112 _____ () [File not signed] C:\Users\Dean Miles\AppData\Roaming\Rainmeter\Plugins\NXTInput.DLL 2019-03-18 16:02 - 2019-03-18 16:02 - 000110592 _____ () [File not signed] C:\Program Files\Rainmeter\Plugins\PowerPlugin.DLL 2019-03-18 16:02 - 2019-03-18 16:02 - 000096768 _____ () [File not signed] C:\Program Files\Rainmeter\Plugins\Perfmon.dll 2019-03-18 16:02 - 2019-03-18 16:02 - 000130048 _____ () [File not signed] C:\Program Files\Rainmeter\Plugins\SysInfo.DLL 2019-03-20 21:06 - 2019-03-20 21:06 - 000143360 _____ () [File not signed] C:\Users\Dean Miles\AppData\Roaming\Rainmeter\Plugins\HotKey.DLL 2019-03-18 16:02 - 2019-03-18 16:02 - 000323584 _____ () [File not signed] C:\Program Files\Rainmeter\Plugins\RunCommand.DLL 2019-03-20 21:06 - 2019-03-20 21:06 - 000012288 _____ () [File not signed] C:\Users\Dean Miles\AppData\Roaming\Rainmeter\Plugins\PluginClipboard.dll 2019-03-18 16:02 - 2019-03-18 16:02 - 000173568 _____ () [File not signed] C:\Program Files\Rainmeter\Plugins\AudioLevel.DLL 2019-03-18 16:02 - 2019-03-18 16:02 - 000135168 _____ () [File not signed] C:\Program Files\Rainmeter\Plugins\Win7AudioPlugin.DLL 2019-03-18 16:03 - 2019-03-18 16:03 - 000026624 _____ () [File not signed] C:\Program Files\Rainmeter\Plugins\UsageMonitor.DLL 2019-03-23 15:20 - 2017-05-23 15:59 - 000478208 _____ (Skillbrains) [File not signed] C:\Program Files (x86)\Skillbrains\lightshot\5.4.0.35\Lightshot.exe 2016-09-13 03:00 - 2016-09-13 03:00 - 000912384 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Charts.dll 2016-09-13 03:00 - 2016-09-13 03:00 - 002924544 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Quick.dll 2016-09-13 03:00 - 2016-09-13 03:00 - 005496320 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Core.dll 2016-09-13 03:00 - 2016-09-13 03:00 - 005444608 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Widgets.dll 2016-09-13 03:01 - 2016-09-13 03:01 - 000277504 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5WinExtras.dll 2016-09-13 03:00 - 2016-09-13 03:00 - 005804544 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Gui.dll 2016-09-13 03:01 - 2016-09-13 03:01 - 000193024 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Xml.dll 2016-09-13 03:00 - 2016-09-13 03:00 - 003187712 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Qml.dll 2016-09-13 03:00 - 2016-09-13 03:00 - 001061376 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Network.dll 2016-09-13 03:01 - 2016-09-13 03:01 - 001212416 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\platforms\qwindows.dll 2016-09-13 03:01 - 2016-09-13 03:01 - 000014336 _____ () [File not signed] C:\Program Files\AMD\CNext\CNext\QtQuick.2\qtquick2plugin.dll 2016-09-13 03:01 - 2016-09-13 03:01 - 000739840 _____ () [File not signed] C:\Program Files\AMD\CNext\CNext\QtQuick\Controls\qtquickcontrolsplugin.dll 2016-09-13 03:01 - 2016-09-13 03:01 - 000014336 _____ () [File not signed] C:\Program Files\AMD\CNext\CNext\QtQuick\Window.2\windowplugin.dll 2016-09-13 03:01 - 2016-09-13 03:01 - 000071168 _____ () [File not signed] C:\Program Files\AMD\CNext\CNext\QtQuick\Layouts\qquicklayoutsplugin.dll 2016-09-13 03:01 - 2016-09-13 03:01 - 000011776 _____ () [File not signed] C:\Program Files\AMD\CNext\CNext\libEGL.dll 2016-09-13 03:01 - 2016-09-13 03:01 - 002013696 _____ () [File not signed] C:\Program Files\AMD\CNext\CNext\libGLESv2.dll 2016-09-13 03:01 - 2016-09-13 03:01 - 000049664 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\imageformats\qdds.dll 2016-09-13 03:01 - 2016-09-13 03:01 - 000029696 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\imageformats\qgif.dll 2016-09-13 03:01 - 2016-09-13 03:01 - 000037376 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\imageformats\qicns.dll 2016-09-13 03:01 - 2016-09-13 03:01 - 000030208 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\imageformats\qico.dll 2016-09-13 03:01 - 2016-09-13 03:01 - 000459776 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\imageformats\qjp2.dll 2016-09-13 03:01 - 2016-09-13 03:01 - 000236544 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\imageformats\qjpeg.dll 2016-09-13 03:01 - 2016-09-13 03:01 - 000275456 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\imageformats\qmng.dll 2016-09-13 03:01 - 2016-09-13 03:01 - 000023552 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\imageformats\qsvg.dll 2016-09-13 03:00 - 2016-09-13 03:00 - 000310784 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\Qt5Svg.dll 2016-09-13 03:01 - 2016-09-13 03:01 - 000022528 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\imageformats\qtga.dll 2016-09-13 03:01 - 2016-09-13 03:01 - 000351744 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\imageformats\qtiff.dll 2016-09-13 03:01 - 2016-09-13 03:01 - 000021504 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\imageformats\qwbmp.dll 2016-09-13 03:01 - 2016-09-13 03:01 - 000374784 _____ (The Qt Company Ltd) [File not signed] C:\Program Files\AMD\CNext\CNext\imageformats\qwebp.dll 2016-09-13 03:01 - 2016-09-13 03:01 - 000191488 _____ () [File not signed] C:\Program Files\AMD\CNext\CNext\QtQuick\Dialogs\dialogplugin.dll 2019-02-19 15:47 - 2019-03-05 17:51 - 005089792 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Widgets.dll 2019-02-19 15:47 - 2019-03-05 17:51 - 001177600 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Network.dll 2019-02-19 15:47 - 2019-03-05 17:51 - 005487104 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Core.dll 2019-02-19 15:47 - 2019-03-05 17:51 - 000184832 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Xml.dll 2019-02-19 15:47 - 2019-03-05 17:51 - 005841920 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Gui.dll 2019-02-19 15:29 - 2019-03-05 17:51 - 001548288 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files (x86)\Origin\LIBEAY32.dll 2019-02-19 15:29 - 2019-03-05 17:51 - 001611264 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\platforms\qwindows.dll 2019-02-19 15:29 - 2019-03-05 17:51 - 000395776 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files (x86)\Origin\ssleay32.dll 2019-03-23 15:20 - 2017-05-23 15:59 - 000494080 _____ (Skillbrains) [File not signed] C:\Program Files (x86)\Skillbrains\lightshot\5.4.0.35\Lightshot.dll 2019-03-23 15:20 - 2017-05-23 15:59 - 000256000 _____ (Skillbrains) [File not signed] C:\Program Files (x86)\Skillbrains\lightshot\5.4.0.35\uploader.dll 2019-02-19 15:47 - 2019-03-05 17:51 - 000068096 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5QuickWidgets.dll 2019-02-19 15:47 - 2019-03-05 17:51 - 000146432 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5WebSockets.dll 2019-02-19 15:47 - 2019-03-05 17:51 - 000211456 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5WebEngineWidgets.dll 2019-02-19 15:47 - 2019-03-05 17:51 - 000310272 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5PrintSupport.dll 2019-02-19 15:47 - 2019-03-05 17:51 - 003390976 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Quick.dll 2019-02-19 15:47 - 2019-03-05 17:51 - 003515904 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Qml.dll 2019-02-19 15:47 - 2019-03-05 17:51 - 054063616 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5WebEngineCore.dll 2019-02-19 15:47 - 2019-03-05 17:51 - 000116224 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5WebChannel.dll 2019-02-19 15:47 - 2019-03-05 17:51 - 000207360 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Positioning.dll 2019-02-19 15:47 - 2019-03-05 17:51 - 000015360 _____ () [File not signed] C:\Program Files (x86)\Origin\libEGL.DLL 2019-02-19 15:47 - 2019-03-05 17:51 - 003090944 _____ () [File not signed] C:\Program Files (x86)\Origin\libGLESv2.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\ProgramData\TEMP:56E2E879 [135] ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LMIRescue_c9611d5e-6bc3-1822-acbb-0c07fbfd21b0 => ""="Service" ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2015-07-10 12:04 - 2015-07-10 12:02 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path: C:\Program Files (x86)\Common Files\Oracle\Java\javapath;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\;C:\Program Files (x86)\Brackets\command;C:\Program Files\dotnet\;C:\Program Files (x86)\dotnet\ HKU\S-1-5-21-3843450261-267223717-1376901193-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Dean Miles\AppData\Roaming\Mozilla\Firefox\Desktop Background.bmp DNS Servers: 1.1.1.1 - 1.0.0.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == If an entry is included in the fixlist, it will be removed. HKLM\...\StartupApproved\Run: => "Fences" HKU\S-1-5-21-3843450261-267223717-1376901193-1001\...\StartupApproved\Run: => "EADM" HKU\S-1-5-21-3843450261-267223717-1376901193-1001\...\StartupApproved\Run: => "Opera Browser Assistant" HKU\S-1-5-21-3843450261-267223717-1376901193-1001\...\StartupApproved\Run: => "utweb" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{1A1F1B67-BBF1-4D7B-AD86-46E02DCA36A9}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Scribblenauts\Scribble.exe () [File not signed] FirewallRules: [{2AC9E180-0BE9-4792-8972-85C11319B329}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Scribblenauts\Scribble.exe () [File not signed] FirewallRules: [{68EABA11-E2AF-4F7E-9E96-86A8CADA56DE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Left 4 Dead 2\left4dead2.exe () [File not signed] FirewallRules: [{91D83B61-F681-4BCA-902C-2A44B5CD52BB}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Left 4 Dead 2\left4dead2.exe () [File not signed] FirewallRules: [{DE1B9340-9688-4082-B195-8F250B4D401C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Team Fortress 2\hl2.exe (Valve -> ) FirewallRules: [{D477544D-BE6B-488C-8318-120F6024CDAF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Team Fortress 2\hl2.exe (Valve -> ) FirewallRules: [{630B42BE-7479-4357-8BB6-4C277ED3A6F5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\wallpaper_engine\launcher.exe (Kristjan Skutta -> ) FirewallRules: [{8AC03486-A3D1-4C18-8416-53ACE3D51D46}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\wallpaper_engine\launcher.exe (Kristjan Skutta -> ) FirewallRules: [{26AAAD9D-1978-49D3-8CD6-90E04C99FAD1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\AdventureQuest3D\aq3d\AQ3D.exe () [File not signed] FirewallRules: [{92435B6D-BF9F-415D-A0CC-E5236FF4E0F8}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\AdventureQuest3D\aq3d\AQ3D.exe () [File not signed] FirewallRules: [{63C92622-B255-4E97-B029-44C31824F97E}] => (Allow) C:\Users\Dean Miles\AppData\Roaming\uTorrent Web\utweb.exe No File FirewallRules: [{37A58E8D-59F5-4289-B3DB-64B8EC106BBC}] => (Allow) C:\Users\Dean Miles\AppData\Roaming\uTorrent Web\utweb.exe No File FirewallRules: [{CF7B6625-15D7-4ABA-B03C-4E07D82EF2A0}] => (Allow) C:\Program Files (x86)\BitLord\BitLord.exe (House of Life) [File not signed] FirewallRules: [{2288C578-4BA3-4C2B-A59A-33D2303BBA77}] => (Allow) C:\Program Files (x86)\BitLord\BitLord.exe (House of Life) [File not signed] FirewallRules: [{F467640B-824E-4663-8E4D-53839F5FA55C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Terraria\Terraria.exe (Re-Logic) [File not signed] FirewallRules: [{17BB3389-92FE-40F8-A50F-67C16E539A95}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Terraria\Terraria.exe (Re-Logic) [File not signed] FirewallRules: [{842D6400-1E43-4603-AE16-26A108DEBD7B}] => (Allow) C:\Program Files (x86)\Origin Games\The Sims 4\Game\Bin\TS4_x64.exe (Electronic Arts, Inc. -> Electronic Arts Inc.) FirewallRules: [{B93D3FB4-3847-4953-949F-0BA0CC1CF5B4}] => (Allow) C:\Program Files (x86)\Origin Games\The Sims 4\Game\Bin\TS4_x64.exe (Electronic Arts, Inc. -> Electronic Arts Inc.) FirewallRules: [{F97FC698-3BA3-446C-A252-AA7F4B2F90D1}] => (Allow) C:\Program Files (x86)\Origin Games\The Sims 4\Game\Bin\TS4.exe (Electronic Arts, Inc. -> Electronic Arts Inc.) FirewallRules: [{E693A190-19EA-4F82-98CD-74E97105D441}] => (Allow) C:\Program Files (x86)\Origin Games\The Sims 4\Game\Bin\TS4.exe (Electronic Arts, Inc. -> Electronic Arts Inc.) FirewallRules: [{E6492AE8-8DD5-4B1E-9EBD-FBD7D31EFBEA}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Blockland\Blockland.exe () [File not signed] FirewallRules: [{A12067E2-E02C-4C2D-BA44-60DBB1B9DA39}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Blockland\Blockland.exe () [File not signed] FirewallRules: [{58C12D55-5640-4020-A341-2D68CA9E4F1B}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation) FirewallRules: [{5C6CF449-D43D-405E-B0F4-294ED5A73B59}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation) FirewallRules: [{1BD39BFB-F192-464A-8871-2473471C90B7}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation) FirewallRules: [{70D37587-9BEF-454C-8815-2CF89F3AA16B}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation) FirewallRules: [UDP Query User{0F300C7C-682E-4E69-8A10-6A80A7EAC7DA}C:\program files (x86)\minecraft launcher\runtime\jre-x64\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft launcher\runtime\jre-x64\bin\javaw.exe FirewallRules: [TCP Query User{898971DD-C1BE-4CD9-99E3-BDD3E6D25FA7}C:\program files (x86)\minecraft launcher\runtime\jre-x64\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft launcher\runtime\jre-x64\bin\javaw.exe FirewallRules: [{06D8F750-2DC2-43C0-ABD4-2FD5F87D74A3}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe No File FirewallRules: [{FFA7BE35-1FCD-4423-87BD-34587D3EA059}] => (Allow) C:\Users\Dean Miles\AppData\Local\Programs\Opera\58.0.3135.79\opera.exe No File FirewallRules: [TCP Query User{B4D75202-5D2A-4D7B-A73F-309877EB71DD}C:\program files\java\jre1.8.0_201\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_201\bin\javaw.exe FirewallRules: [UDP Query User{FB4CF490-5459-4CEF-B19B-650DF3C3BB26}C:\program files\java\jre1.8.0_201\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_201\bin\javaw.exe FirewallRules: [TCP Query User{64C4D262-C43C-4ABD-A316-6FB755E93C65}C:\program files (x86)\brackets\node.exe] => (Allow) C:\program files (x86)\brackets\node.exe (Adobe Systems Incorporated -> Node.js) FirewallRules: [UDP Query User{E02850F4-F0BD-428F-BD46-FFBF1DAA5886}C:\program files (x86)\brackets\node.exe] => (Allow) C:\program files (x86)\brackets\node.exe (Adobe Systems Incorporated -> Node.js) FirewallRules: [{DC35B36A-E5B6-4DB2-9EC6-81591B88DF33}] => (Allow) C:\Program Files\BlueStacks\HD-Player.exe (BlueStack Systems, Inc. -> BlueStack Systems, Inc.) FirewallRules: [{26C46169-E07B-4EA1-9380-50939D8E91D2}] => (Allow) C:\Users\Dean Miles\AppData\Local\Programs\Opera\58.0.3135.107\opera.exe No File FirewallRules: [{62A493D6-DB78-4732-965C-01AD6A29635C}] => (Allow) C:\Program Files (x86)\Remotr\RemotrServer.exe (RemoteMyApp sp. z o.o. -> RemoteMyApp sp. z o.o.) FirewallRules: [{3DAAB37F-8D6B-4F9A-A718-EE93AA660E3D}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe (Winamp SA -> Winamp SA) FirewallRules: [{71616A32-B444-415C-8890-E6ACAED2DC53}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe (Winamp SA -> Winamp SA) FirewallRules: [{40720247-0B4C-497E-AC06-FA950D9F3809}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\grid 2\grid2.exe (Valve Corp. -> Codemasters Software Company Limited) FirewallRules: [{94D70991-F2F1-42E6-8BDD-94F3D28D625A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\grid 2\grid2.exe (Valve Corp. -> Codemasters Software Company Limited) FirewallRules: [{7B28513A-A492-4BBE-9C97-AB98EA52C830}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\A Story About My Uncle\Binaries\Win32\ASAMU-Win32-Shipping.exe (Epic Games, Inc.) [File not signed] FirewallRules: [{5EDE8B73-34D6-49EB-9FD9-9E2C1A19FA69}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\A Story About My Uncle\Binaries\Win32\ASAMU-Win32-Shipping.exe (Epic Games, Inc.) [File not signed] FirewallRules: [{F727E0F3-18E3-42A8-A1AB-60183195EC93}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Floor Is Really Cheap Lava\The Floor Is Really Cheap Lava.exe () [File not signed] FirewallRules: [{A16DEFC8-DF73-4C81-AE90-DD73230D2124}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Floor Is Really Cheap Lava\The Floor Is Really Cheap Lava.exe () [File not signed] FirewallRules: [{855EB254-654C-405E-964C-1E8B9FC6A5ED}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Struckd - 3D Game Creator\Struckd.exe () [File not signed] FirewallRules: [{01CDE2B7-9B7B-49AB-804C-B91EC6FBC058}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Struckd - 3D Game Creator\Struckd.exe () [File not signed] FirewallRules: [{132E3383-F290-4EA1-811B-A866E4414A2E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\wallpaper_engine\bin\diagnostics32.exe (Kristjan Skutta -> ) FirewallRules: [{B5BC15BC-BBAB-46B9-A381-035A408A7CFF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\wallpaper_engine\bin\diagnostics32.exe (Kristjan Skutta -> ) FirewallRules: [{62750A00-E3BB-4B62-9592-ADF4FB5D4C31}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\LOOT BOX ACHIEVEMENT SIMULATOR\LOOTBOX_WIN.exe () [File not signed] FirewallRules: [{0DB10F3D-68C4-4E7D-B621-F56077602EFD}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\LOOT BOX ACHIEVEMENT SIMULATOR\LOOTBOX_WIN.exe () [File not signed] ==================== Restore Points ========================= Check "winmgmt" service or repair WMI. ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (04/02/2019 05:12:42 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program chrome.exe version 73.0.3683.86 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel. Process ID: 194 Start Time: 01d4e96ed403f4c1 Termination Time: 6 Application Path: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Report Id: ea6be42c-9015-432a-91d4-5bc683e48e46 Faulting package full name: Faulting package-relative application ID: Error: (04/02/2019 05:11:48 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program opera.exe version 58.0.3135.127 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel. Process ID: 1c74 Start Time: 01d4e96e4086d33b Termination Time: 4294967295 Application Path: C:\Users\Dean Miles\AppData\Local\Programs\Opera\58.0.3135.127\opera.exe Report Id: 1f113cf5-13fa-4077-92c9-ba8c37b316d5 Faulting package full name: Faulting package-relative application ID: Error: (04/02/2019 05:05:40 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program opera.exe version 58.0.3135.127 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel. Process ID: 1f80 Start Time: 01d4e96cb8334e4a Termination Time: 4294967295 Application Path: C:\Users\Dean Miles\AppData\Local\Programs\Opera\58.0.3135.127\opera.exe Report Id: 156ac69e-4736-46b5-a8f4-d8bb3f2ffa68 Faulting package full name: Faulting package-relative application ID: Error: (04/02/2019 05:02:50 PM) (Source: VSS) (EventID: 8193) (User: ) Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x000003d4,SYSTEM\CurrentControlSet\Services\VSS\Diag\VssvcPublisher,0,REG_BINARY,0000009B7977E860.72). hr = 0x80070005, Access is denied. . Error: (04/02/2019 05:02:50 PM) (Source: VSS) (EventID: 8193) (User: ) Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x00000274,(null),0,REG_BINARY,000000F3036FD2A0.72). hr = 0x80070005, Access is denied. . Operation: BackupShutdown Event Context: Execution Context: Writer Writer Class Id: {a6ad56c2-b509-4e6c-bb19-49d8f43532f0} Writer Name: WMI Writer Writer Instance ID: {b9a100bd-fd62-4058-809b-c4c7877fd3d8} Error: (04/02/2019 05:02:50 PM) (Source: VSS) (EventID: 8193) (User: ) Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x0000020c,(null),0,REG_BINARY,000000A1CFDFD0C0.72). hr = 0x80070005, Access is denied. . Operation: BackupShutdown Event Context: Execution Context: Writer Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220} Writer Name: System Writer Writer Instance ID: {ce71142c-36c6-462c-a70f-d5d08cb6356e} Error: (04/02/2019 05:02:50 PM) (Source: VSS) (EventID: 8193) (User: ) Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x000001ec,(null),0,REG_BINARY,0000009B798FF1F0.72). hr = 0x80070005, Access is denied. . Operation: BackupShutdown Event Context: Execution Context: Writer Writer Class Id: {542da469-d3e1-473c-9f4f-7847f01fc64f} Writer Name: COM+ REGDB Writer Writer Instance ID: {4c55dc07-7529-4c07-9ccc-eb80276e2119} Error: (04/02/2019 05:02:50 PM) (Source: VSS) (EventID: 8193) (User: ) Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x0000027c,(null),0,REG_BINARY,0000009B797FE6F0.72). hr = 0x80070005, Access is denied. . Operation: BackupShutdown Event Context: Execution Context: Writer Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f} Writer Name: Shadow Copy Optimization Writer Writer Instance ID: {4bbaf891-1d5d-49b8-af1f-984ecee7c1dc} System errors: ============= Error: (04/02/2019 05:56:29 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-7DUR10C) Description: The server {9E175B6D-F52A-11D8-B9A5-505054503030} did not register with DCOM within the required timeout. Error: (04/02/2019 05:54:29 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-7DUR10C) Description: The server {9E175B6D-F52A-11D8-B9A5-505054503030} did not register with DCOM within the required timeout. Error: (04/02/2019 05:52:29 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-7DUR10C) Description: The server {9E175B6D-F52A-11D8-B9A5-505054503030} did not register with DCOM within the required timeout. Error: (04/02/2019 05:50:29 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-7DUR10C) Description: The server {9E175B6D-F52A-11D8-B9A5-505054503030} did not register with DCOM within the required timeout. Error: (04/02/2019 05:48:29 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-7DUR10C) Description: The server {9E175B6D-F52A-11D8-B9A5-505054503030} did not register with DCOM within the required timeout. Error: (04/02/2019 05:46:29 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-7DUR10C) Description: The server {9E175B6D-F52A-11D8-B9A5-505054503030} did not register with DCOM within the required timeout. Error: (04/02/2019 05:44:29 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-7DUR10C) Description: The server {9E175B6D-F52A-11D8-B9A5-505054503030} did not register with DCOM within the required timeout. Error: (04/02/2019 05:42:29 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-7DUR10C) Description: The server {9E175B6D-F52A-11D8-B9A5-505054503030} did not register with DCOM within the required timeout. Windows Defender: =================================== Date: 2019-03-31 21:12:40.759 Description: Windows Defender Antivirus scan has been stopped before completion. Scan ID: {F7B74336-8050-481D-B134-672CE726678B} Scan Type: Antimalware Scan Parameters: Quick Scan Date: 2019-04-01 20:46:23.205 Description: Windows Defender Antivirus has encountered an error trying to update the engine. New Engine Version: 1.1.15800.1 Previous Engine Version: 1.1.15700.8 Error Code: 0x80004004 Error description: Operation aborted CodeIntegrity: =================================== Date: 2019-04-02 17:54:38.325 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\browser_broker.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\wbload.dll that did not meet the Microsoft signing level requirements. Date: 2019-04-02 17:54:38.319 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\browser_broker.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\wbload.dll that did not meet the Microsoft signing level requirements. Date: 2019-04-02 17:54:38.314 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\browser_broker.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\wbload.dll that did not meet the Microsoft signing level requirements. Date: 2019-04-02 17:54:38.308 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\browser_broker.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\wbload.dll that did not meet the Microsoft signing level requirements. Date: 2019-04-02 17:54:38.303 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\browser_broker.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\wbload.dll that did not meet the Microsoft signing level requirements. Date: 2019-04-02 17:54:08.296 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\browser_broker.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\wbload.dll that did not meet the Microsoft signing level requirements. Date: 2019-04-02 17:54:08.288 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\browser_broker.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\wbload.dll that did not meet the Microsoft signing level requirements. Date: 2019-04-02 17:54:08.278 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\browser_broker.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\wbload.dll that did not meet the Microsoft signing level requirements. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i7-3770 CPU @ 3.40GHz Percentage of memory in use: 25% Total physical RAM: 16338.89 MB Available physical RAM: 12092.62 MB Total Virtual: 18770.89 MB Available Virtual: 14594.43 MB ==================== Drives ================================ Drive c: (Primary) (Fixed) (Total:1861.61 GB) (Free:1621.06 GB) NTFS ==>[drive with boot components (obtained from BCD)] Drive d: () (Removable) (Total:29.25 GB) (Free:23.99 GB) NTFS \\?\Volume{353ea041-0000-0000-0000-a0a3d1010000}\ (System Reserved) (Fixed) (Total:0.46 GB) (Free:0.44 GB) NTFS \\?\Volume{353ea041-0000-0000-0000-100000000000}\ (System Reserved) (Fixed) (Total:0.49 GB) (Free:0.45 GB) NTFS \\?\Volume{353ea041-0000-0000-0000-3086d1010000}\ () (Fixed) (Total:0.46 GB) (Free:0.08 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7/8/10) (Size: 1863 GB) (Disk ID: 353EA041) Partition 1: (Not Active) - (Size=500 MB) - (Type=07 NTFS) Partition 2: (Active) - (Size=1861.6 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=470 MB) - (Type=27) Partition 4: (Not Active) - (Size=469 MB) - (Type=0F Extended) ======================================================== Disk: 1 (Protective MBR) (Size: 29.3 GB) (Disk ID: 00000000) Partition: GPT. ==================== End of Addition.txt ============================