Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Additional scan result of Farbar Recovery Scan Tool (x64) Version: 21-08-2016 01
- Ran by Josh_x (27-08-2016 05:37:10)
- Running from C:\Users\Josh_x\Desktop
- Windows 10 Home Version 1511 (X64) (2016-04-17 18:54:30)
- Boot Mode: Normal
- ==========================================================
- ==================== Accounts: =============================
- Administrator (S-1-5-21-2876923373-2406336335-375998269-500 - Administrator - Disabled)
- DefaultAccount (S-1-5-21-2876923373-2406336335-375998269-503 - Limited - Disabled)
- Guest (S-1-5-21-2876923373-2406336335-375998269-501 - Limited - Disabled)
- HomeGroupUser$ (S-1-5-21-2876923373-2406336335-375998269-1003 - Limited - Enabled)
- Josh_x (S-1-5-21-2876923373-2406336335-375998269-1001 - Administrator - Enabled) => C:\Users\Josh_x
- ==================== Security Center ========================
- (If an entry is included in the fixlist, it will be removed.)
- AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
- AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
- ==================== Installed Programs ======================
- (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
- µTorrent (HKU\S-1-5-21-2876923373-2406336335-375998269-1001\...\uTorrent) (Version: 3.4.7.42330 - BitTorrent Inc.)
- Absolute Uninstaller 5.3.1.20 (HKLM-x32\...\Absolute Uninstaller) (Version: 5.3.1.20 - Glarysoft Ltd)
- Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.1.0.4880 - Adobe Systems Incorporated)
- Adobe Premiere Pro CS6 (HKLM-x32\...\{7176B973-6011-43C1-AEBC-2D73FE7C6982}) (Version: 6.0 - Adobe Systems Incorporated)
- AMD Catalyst Install Manager (HKLM\...\{69ECE411-BF4A-2984-AFD5-8EEB829C5B2C}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.)
- AMD Quick Stream (HKLM\...\{E9EED4AE-682B-4501-9574-D09A21717599}_is1) (Version: 3.10.4.1 - AppEx Networks)
- AVerMedia GL710 Live Gamer Portable 3.7.0.37 (HKLM-x32\...\AVerMedia GL710 Live Gamer Portable) (Version: 3.7.0.37 - AVerMedia TECHNOLOGIES, Inc.)
- AVerMedia Live Gamer Portable Stream Engine 1.3.0.13 (HKLM-x32\...\AVerMedia Live Gamer Portable Stream Engine) (Version: 1.3.0.13 - AVerMedia TECHNOLOGIES, Inc.)
- AVerMedia RECentral (HKLM-x32\...\InstallShield_{30D6B6ED-E039-4D62-8E07-E058D17A9372}) (Version: 1.3.0.96.2015111701 - AVerMedia Technologies, Inc.)
- AVerMedia RECentral (x32 Version: 1.3.0.96.2015111701 - AVerMedia Technologies, Inc.) Hidden
- bl (x32 Version: 1.0.0 - Your Company Name) Hidden
- Black Ops 2 - GSC Studio (HKLM-x32\...\{909C0DF9-6BBE-42BD-8FB2-0ADEBA3459B6}_is1) (Version: 16.2.15.0 - iMCS Productions)
- Broadcom 802.11 Network Adapter (HKLM\...\Broadcom 802.11 Network Adapter) (Version: 6.30.223.227 - Broadcom Corporation)
- Chroma Sync (HKLM-x32\...\{BC8D681E-1F5D-4C68-8E3E-A9A614D66C14}) (Version: 1.1.1 - Ultrabox Entertainment Limited)
- Consumer Input Update Helper (x32 Version: 1.3.25.309 - Compete Inc.) Hidden <==== ATTENTION
- ControlConsole API version 2.60 (HKLM-x32\...\{E6C0F5ED-B5EA-451D-8CB1-57902AA188DE}_is1) (Version: 2.60 - Enstone)
- Counter-Strike: Global Offensive (HKLM\...\Steam App 730) (Version: - Valve)
- CyberGhost 5 (HKLM\...\CyberGhost 5_is1) (Version: - CyberGhost S.R.L.)
- D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
- Discord (HKU\S-1-5-21-2876923373-2406336335-375998269-1001\...\Discord) (Version: 0.0.296 - Hammer & Chisel, Inc.)
- DisplayLink Core Software (HKLM\...\{22ED06F1-2432-4D16-B4DC-2DF4A7ACD54A}) (Version: 7.9.1488.0 - DisplayLink Corp.)
- FileZilla Client 3.19.0 (HKLM-x32\...\FileZilla Client) (Version: 3.19.0 - Tim Kosse)
- FLV-Media-Player (HKLM-x32\...\{AB7A5DBA-BC45-489A-B4D2-2E8F8CABB9EA}) (Version: 2.0.3.2532 - HYBRIDWEB.de)
- Game Capture HD v2.3.3.40 (HKLM-x32\...\Software_Elgato_Game Capture HD) (Version: 2.3.3.40 - Elgato Systems)
- Game Capture HD60 Pro v1.1.0.149 (HKLM-x32\...\Software_Elgato_Game Capture HD60 Pro) (Version: 1.1.0.149 - Elgato Systems)
- Game Capture HD60 S v1.1.0.160 (HKLM-x32\...\Software_Elgato_Game Capture HD60 S) (Version: 1.1.0.160 - Elgato Systems)
- Game Capture HD60 v2.1.1.4 (HKLM-x32\...\Software_Elgato_Game Capture HD60) (Version: 2.1.1.4 - Elgato Systems)
- Google Chrome (HKLM-x32\...\Google Chrome) (Version: 52.0.2743.116 - Google Inc.)
- Google Update Helper (x32 Version: 1.3.31.5 - Google Inc.) Hidden
- Java 8 Update 101 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180101F0}) (Version: 8.0.1010.13 - Oracle Corporation)
- KeyScrambler (HKLM-x32\...\KeyScrambler) (Version: 3.9.0.3 - QFX Software Corporation)
- Lightshot-5.4.0.1 (HKLM-x32\...\{30A5B3C9-2084-4063-A32A-628A98DE512B}_is1) (Version: 5.4.0.1 - Skillbrains)
- Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
- Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
- Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
- Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
- Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
- Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
- Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
- Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
- Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
- Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
- Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
- Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
- Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
- Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
- Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
- Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23918 (HKLM-x32\...\{dab68466-3a7d-41a8-a5cf-415e3ff8ef71}) (Version: 14.0.23918.0 - Microsoft Corporation)
- Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23918 (HKLM-x32\...\{2e085fd2-a3e4-4b39-8e10-6b8d35f55244}) (Version: 14.0.23918.0 - Microsoft Corporation)
- Microsoft XNA Framework Redistributable 2.0 (HKLM-x32\...\{245F6C7A-0C22-4DE0-8202-2AAA620A1D3A}) (Version: 2.0.11128.1 - Microsoft Corporation)
- Microsoft XNA Framework Redistributable 4.0 (HKLM-x32\...\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation)
- MiniAide Fat32 Formatter Home Edition version 1.05 (HKLM-x32\...\{C206CD7D-7CFE-4F0C-BC68-8873CDE3A5F5}_is1) (Version: 1.05 - MiniAide Tech Development Co., Ltd.)
- Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
- Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.9.2 - Notepad++ Team)
- NVIDIA PhysX (HKLM-x32\...\{DEA314C4-0929-4250-BC92-98E4C105F28D}) (Version: 9.10.0129 - NVIDIA Corporation)
- Open Broadcaster Software (HKLM-x32\...\Open Broadcaster Software) (Version: - )
- paint.net (HKLM\...\{DADC2AF6-DC9F-4BCF-BFCE-DCEC16EF507C}) (Version: 4.0.9 - dotPDN LLC)
- ph (x32 Version: 1.0.0 - Your Company Name) Hidden
- Razer Chroma SDK Core Components (HKLM-x32\...\Razer Chroma SDK) (Version: 1.7.8 - Razer Inc.)
- Razer Synapse (HKLM-x32\...\{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}) (Version: 2.20.15.707 - Razer Inc.)
- Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.3.9600.29077 - Realtek Semiconductor Corp.)
- Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.24.1218.2013 - Realtek)
- Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7173 - Realtek Semiconductor Corp.)
- ROBLOX Player for Josh_x (HKU\S-1-5-21-2876923373-2406336335-375998269-1001\...\{373B1718-8CC5-4567-8EE2-9033AD08A680}) (Version: - ROBLOX Corporation)
- ROBLOX Studio for Josh_x (HKU\S-1-5-21-2876923373-2406336335-375998269-1001\...\{2922D6F1-2865-4EFA-97A9-94EEAB3AFA14}) (Version: - ROBLOX Corporation)
- Skype Tool Pack (HKU\S-1-5-21-2876923373-2406336335-375998269-1001\...\Skype Tool Pack 1.0.0) (Version: 1.0.0 - HGCommunity)
- Skype Tool Pack (x32 Version: 1.0.0 - HGCommunity) Hidden
- Skype Web Plugin (HKLM-x32\...\{0A95D1F2-BF33-43E7-A32B-E8089182EAE7}) (Version: 7.23.0.54 - Skype Technologies S.A.)
- Skype™ 7.26 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.26.101 - Skype Technologies S.A.)
- Source SDK Base 2006 (HKLM\...\Steam App 215) (Version: - Valve)
- Spotify (HKU\S-1-5-21-2876923373-2406336335-375998269-1001\...\Spotify) (Version: 1.0.33.106.g60b5d1f0 - Spotify AB)
- Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
- Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 19.0.16.3 - Synaptics Incorporated)
- TeamViewer 11 (HKLM-x32\...\TeamViewer) (Version: 11.0.63017 - TeamViewer)
- TOSHIBA Application Installer (HKLM\...\{21A63CA3-75C0-4E56-B602-B7CD2EF6B621}) (Version: 9.0.2.6 - Toshiba Corporation)
- TOSHIBA Audio Enhancement (HKLM\...\{1515F5E3-29EA-4CD1-A981-032D88880F09}) (Version: 2.0.18.0 - Toshiba Corporation)
- TOSHIBA Battery Check Utility (HKLM-x32\...\{5468E297-7EF8-4CB3-A091-F8714147793F}) (Version: 1.00.01.01 - Toshiba Corporation)
- TOSHIBA Display Utility (HKLM\...\{0B39C39A-3ECE-4582-9C91-842D22819A24}) (Version: 2.0.1.0 - Toshiba Corporation)
- TOSHIBA eco Utility (HKLM\...\{94D2A899-0C34-4420-880E-AE337E635AB0}) (Version: 2.5.0.6404 - Toshiba Corporation)
- TOSHIBA Function Key (HKLM\...\{1844CFE2-EBA3-490A-8A5E-9BFC646342FD}) (Version: 1.1.5.6402 - Toshiba Corporation)
- TOSHIBA Password Utility (HKLM-x32\...\{2DB90351-FBAA-472B-9F12-6E1EBBB354DE}) (Version: v2.1.0.22 - Toshiba Corporation)
- TOSHIBA Recovery Media Creator (HKLM-x32\...\{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}) (Version: 3.2.00.56006005 - Toshiba Corporation)
- TOSHIBA Service Station (HKLM\...\{B1F241E1-90BF-4201-8977-A0DF85A38EBB}) (Version: 2.6.16.0 - Toshiba Corporation)
- TOSHIBA System Driver (HKLM-x32\...\{1E6A96A1-2BAB-43EF-8087-30437593C66C}) (Version: 1.00.0033 - Toshiba Corporation)
- TOSHIBA System Settings (HKLM-x32\...\{4D57ED72-6B01-40BD-9CA9-012B8FC09CEB}) (Version: 2.0.1.32003 - Toshiba Corporation)
- TOSHIBA User's Guide (HKLM-x32\...\{3384E1D9-3F18-4A98-8655-180FEF0DFC02}) (Version: 1.00.02 - TOSHIBA)
- TOSHIBARegistration (HKLM-x32\...\{5AF550B4-BB67-4E7E-82F1-2C4300279050}) (Version: 1.1.6 - TOSHIBA)
- Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
- WinRAR 5.31 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.31.0 - win.rar GmbH)
- ==================== Custom CLSID (Whitelisted): ==========================
- (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
- CustomCLSID: HKU\S-1-5-21-2876923373-2406336335-375998269-1001_Classes\CLSID\{49ACECA8-A1DF-467E-8FED-CCC810B1434E}\localserver32 -> C:\Users\Josh_x\AppData\Local\SkypePlugin\7.23.0.54\GatewayVersion-x64.exe (Skype Technologies S.A.)
- CustomCLSID: HKU\S-1-5-21-2876923373-2406336335-375998269-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Josh_x\AppData\Local\Microsoft\OneDrive\17.3.6386.0412\FileCoAuth.exe (Microsoft Corporation)
- CustomCLSID: HKU\S-1-5-21-2876923373-2406336335-375998269-1001_Classes\CLSID\{7E3A041F-59E4-45ED-85BB-0DC57685CC7B}\InprocServer32 -> C:\Users\Josh_x\AppData\Local\SkypePlugin\7.23.0.54\GatewayActiveX-x64.dll (Skype Technologies S.A.)
- CustomCLSID: HKU\S-1-5-21-2876923373-2406336335-375998269-1001_Classes\CLSID\{CBF9CD8C-2714-4F36-B76A-43E6C7547BC2}\localserver32 -> C:\Users\Josh_x\AppData\Local\SkypePlugin\7.23.0.54\EdgeCalling.exe (Skype Technologies S.A.)
- CustomCLSID: HKU\S-1-5-21-2876923373-2406336335-375998269-1001_Classes\CLSID\{DEE03C2B-0C0C-41A9-9877-FD4B4D7B6EA3}\InprocServer32 -> C:\Users\Josh_x\AppData\Local\Roblox\Versions\version-e6d872d544b64cd9\RobloxProxy64.dll (ROBLOX Corporation)
- ==================== Scheduled Tasks (Whitelisted) =============
- (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
- Task: {05949630-EE2E-4E9F-BB1F-A89BC72B15C1} - System32\Tasks\update-sys => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe [2014-11-29] ()
- Task: {0B545118-B563-42FC-8D07-B78F602FCF34} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList
- Task: {11CE7E58-E0FD-44D7-A699-5F3699BA2C7C} - System32\Tasks\update-S-1-5-21-2876923373-2406336335-375998269-1001 => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe [2014-11-29] ()
- Task: {14637FB5-777F-4744-A4EC-1FE58F635E29} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime -> No File <==== ATTENTION
- Task: {1E67996C-DF6B-44E7-934B-84EAF5ABA884} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
- Task: {29803F7B-1B8C-42E8-8FF4-270FBC3E6C5A} - System32\Tasks\{CB64F256-07D1-4DE6-8B17-CBF8A3A2BDF1} => Chrome.exe hxxp://ui.skype.com/ui/0/7.25.0.106/en/abandoninstall?page=tsProgressBar
- Task: {2D72D345-50E9-474F-8849-0BBFDBD251D3} - System32\Tasks\CIMT_daily_S-1-5-21-2876923373-2406336335-375998269-1001 => C:\Program Files (x86)\Consumer Input\Monitoring\dca-monitoring.exe <==== ATTENTION
- Task: {335C745F-40F2-4C16-B611-0E40492386BC} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
- Task: {6B466DE8-54F6-4232-A44A-CC731D383FA7} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
- Task: {6F0B4E84-37B8-4EB4-9674-21E527D9770D} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
- Task: {71A7E7DF-6341-4E07-9EB2-0EED1C889102} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
- Task: {76105D99-59CE-48A3-8B0B-8F297F6E7720} - System32\Tasks\CIMT_S-1-5-21-2876923373-2406336335-375998269-1001 => C:\Program Files (x86)\Consumer Input\Monitoring\dca-monitoring.exe <==== ATTENTION
- Task: {7A23CE40-3F2F-42E7-8F01-3BB766016D19} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-03-29] (Google Inc.)
- Task: {7A257C24-1FA1-481D-924B-44BE7F8162C8} - System32\Tasks\Synaptics TouchPad Enhancements => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2015-10-09] (Synaptics Incorporated)
- Task: {7BA7DCDE-1B65-4117-9392-2031712DCC18} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
- Task: {800E14F9-34DF-4F8D-B3E9-ED43B248B3E3} - \Microsoft\Windows\Setup\GWXTriggers\OnIdle-5d -> No File <==== ATTENTION
- Task: {9EC18431-278D-41A6-9814-46E485379D41} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime -> No File <==== ATTENTION
- Task: {A6C58CBF-03F0-4A87-BD3A-C2B8BB97D456} - System32\Tasks\{3B12FE2D-2824-40AF-BA57-B5E7D3C87A14} => pcalua.exe -a C:\Users\Josh_x\AppData\Local\Roblox\Versions\version-fe7696f13e4e4f07\RobloxPlayerLauncher.exe -c -uninstall
- Task: {BDF28546-B4E5-44BE-B4FE-D50534453E0E} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
- Task: {CA808170-E7A9-4B8A-A261-A63129E9E74F} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
- Task: {CF8A0D65-EEAE-43D5-8695-AD8679E2A66F} - System32\Tasks\TOSHIBA\Service Station => C:\Program Files\TOSHIBA\Toshiba Service Station\ToshibaServiceStation.exe [2014-04-04] (TOSHIBA Corporation)
- Task: {DC6AFAC3-B3C8-4CA1-81F7-D0447907FF77} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-03-29] (Google Inc.)
- Task: {DDABEB25-4F56-4443-811A-D434BF369AC7} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
- Task: {E5334FE7-A758-4C58-87D3-778BED5F0FDB} - System32\Tasks\{972459AB-D61E-4D54-A2D8-2E96C89F9087} => pcalua.exe -a C:\Users\Josh_x\AppData\Local\Roblox\Versions\version-ee338271909542da\RobloxPlayerLauncher.exe -c -uninstall
- Task: {E5D0EF01-435D-4504-A0CA-947A0BC38CFD} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
- (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
- Task: C:\WINDOWS\Tasks\CIMT_daily_S-1-5-21-2876923373-2406336335-375998269-1001.job => C:\Program Files (x86)\Consumer Input\Monitoring\dca-monitoring.exe <==== ATTENTION
- Task: C:\WINDOWS\Tasks\CIMT_S-1-5-21-2876923373-2406336335-375998269-1001.job => C:\Program Files (x86)\Consumer Input\Monitoring\dca-monitoring.exe <==== ATTENTION
- Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
- Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
- Task: C:\WINDOWS\Tasks\update-S-1-5-21-2876923373-2406336335-375998269-1001.job => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe
- Task: C:\WINDOWS\Tasks\update-sys.job => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe
- ==================== Shortcuts =============================
- (The entries could be listed to be restored or removed.)
- ShortcutWithArgument: C:\Users\Josh_x\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\FLV Player.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=dhogabmliblgpadclikpkjfnnipeebjm
- ==================== Loaded Modules (Whitelisted) ==============
- 2015-10-30 17:18 - 2015-10-30 17:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
- 2015-02-15 16:44 - 2015-02-15 16:44 - 00140288 _____ () C:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe
- 2015-11-05 09:11 - 2015-11-05 09:12 - 00188072 _____ () C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
- 2016-07-13 09:48 - 2016-07-01 14:48 - 02656408 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
- 2016-02-13 01:20 - 2016-02-13 01:20 - 01652456 _____ () C:\Program Files\DisplayLink Core Software\AddOnApi64.dll
- 2016-07-13 09:48 - 2016-07-01 14:48 - 02656408 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
- 2016-04-26 09:38 - 2016-04-26 09:38 - 00959176 _____ () C:\Users\Josh_x\AppData\Local\Microsoft\OneDrive\17.3.6386.0412\amd64\ClientTelemetry.dll
- 2016-07-13 09:48 - 2016-07-01 13:21 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
- 2016-07-13 09:48 - 2016-07-01 13:22 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
- 2016-04-20 07:08 - 2016-04-20 07:08 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe
- 2016-02-13 22:54 - 2016-02-13 22:54 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll
- 2016-07-13 09:49 - 2016-07-01 13:48 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
- 2012-07-19 11:38 - 2012-07-19 11:38 - 00020904 _____ () C:\Program Files\TOSHIBA\Hotkey\SmoothView.dll
- 2016-06-15 12:39 - 2016-06-15 12:39 - 00298448 _____ () C:\ProgramData\Razer\Synapse\RzStats\RzStats.Manager.exe
- 2015-02-15 16:44 - 2015-02-15 16:44 - 00016896 _____ () C:\Program Files\ATI Technologies\ATI.ACE\a4\AS4.NativeProxy.dll
- 2016-07-13 09:48 - 2016-07-01 13:27 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
- 2016-07-13 09:48 - 2016-07-01 13:22 - 00936960 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll
- 2016-07-13 09:48 - 2016-07-01 13:24 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
- 2016-04-20 07:08 - 2016-04-20 07:08 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll
- 2016-04-20 07:08 - 2016-04-20 07:08 - 22284800 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkyWrap.dll
- 2016-08-26 06:39 - 2016-08-24 17:49 - 01950392 _____ () C:\Users\Josh_x\AppData\Local\Discord\app-0.0.296\ffmpeg.dll
- 2016-08-26 06:39 - 2016-08-26 06:39 - 01050296 _____ () \\?\C:\Users\Josh_x\AppData\Roaming\discord\0.0.296\modules\discord_voice\discord_voice.node
- 2016-08-26 06:39 - 2016-08-26 06:39 - 03793080 _____ () \\?\C:\Users\Josh_x\AppData\Roaming\discord\0.0.296\modules\discord_voice\libdiscord.dll
- 2016-08-26 06:39 - 2016-08-26 06:39 - 00894136 _____ () \\?\C:\Users\Josh_x\AppData\Roaming\discord\0.0.296\modules\discord_utils\discord_utils.node
- 2016-06-01 14:01 - 2016-08-27 05:19 - 00619840 _____ () C:\Users\Josh_x\AppData\Local\Temp\0Kraken71ChromaDevProps.dll
- 2016-08-26 06:39 - 2016-08-26 06:39 - 01119416 _____ () \\?\C:\Users\Josh_x\AppData\Roaming\discord\0.0.296\modules\discord_toaster\discord_toaster.node
- 2013-05-15 11:57 - 2013-05-15 11:57 - 00626688 _____ () C:\Program Files (x86)\AVerMedia\AVerMedia Stream Engine\Filter\sptlib21.dll
- 2016-08-26 06:39 - 2016-08-24 17:49 - 02230456 _____ () C:\Users\Josh_x\AppData\Local\Discord\app-0.0.296\libglesv2.dll
- 2016-08-26 06:39 - 2016-08-24 17:49 - 00088760 _____ () C:\Users\Josh_x\AppData\Local\Discord\app-0.0.296\libegl.dll
- 2016-07-22 20:14 - 2016-07-22 20:14 - 00143824 _____ () C:\ProgramData\Razer\Synapse\CrashReporter\CrashRpt1402.dll
- 2016-08-27 05:19 - 2016-08-27 05:19 - 00170496 _____ () \\?\C:\Users\Josh_x\AppData\Local\Temp\1A49.tmp.node
- 2015-10-30 17:17 - 2015-10-30 17:17 - 01021792 _____ () C:\Windows\SYSTEM32\speech\engines\tts\MSTTSEngine.dll
- 2015-10-30 17:17 - 2015-10-30 17:17 - 00528384 _____ () C:\Windows\SYSTEM32\speech\engines\tts\MSTTSLoc.DLL
- 2016-08-05 09:14 - 2016-08-03 10:24 - 01771336 _____ () C:\Program Files (x86)\Google\Chrome\Application\52.0.2743.116\libglesv2.dll
- 2016-08-05 09:14 - 2016-08-03 10:23 - 00094024 _____ () C:\Program Files (x86)\Google\Chrome\Application\52.0.2743.116\libegl.dll
- 2016-04-19 08:13 - 2015-10-07 05:26 - 50656768 _____ () C:\Users\Josh_x\AppData\Local\razer\InGameEngine\cache\RzStats.Manager\cef\libcef.dll
- 2016-04-19 08:13 - 2015-10-07 05:26 - 01874944 _____ () C:\Users\Josh_x\AppData\Local\razer\InGameEngine\cache\RzStats.Manager\cef\libglesv2.dll
- 2016-04-19 08:13 - 2015-10-07 05:26 - 00075264 _____ () C:\Users\Josh_x\AppData\Local\razer\InGameEngine\cache\RzStats.Manager\cef\libegl.dll
- 2016-06-12 11:41 - 2016-08-09 09:27 - 00785920 _____ () C:\Program Files (x86)\Steam\SDL2.dll
- 2016-06-12 11:41 - 2015-07-02 08:06 - 04962816 _____ () C:\Program Files (x86)\Steam\v8.dll
- 2016-06-12 11:41 - 2016-08-24 05:33 - 02321184 _____ () C:\Program Files (x86)\Steam\video.dll
- 2016-06-12 11:41 - 2016-01-27 17:49 - 02549760 _____ () C:\Program Files (x86)\Steam\libavcodec-56.dll
- 2016-06-12 11:41 - 2016-01-27 17:49 - 00491008 _____ () C:\Program Files (x86)\Steam\libavformat-56.dll
- 2016-06-12 11:41 - 2016-01-27 17:49 - 00332800 _____ () C:\Program Files (x86)\Steam\libavresample-2.dll
- 2016-06-12 11:41 - 2016-01-27 17:49 - 00442880 _____ () C:\Program Files (x86)\Steam\libavutil-54.dll
- 2016-06-12 11:41 - 2016-01-27 17:49 - 00485888 _____ () C:\Program Files (x86)\Steam\libswscale-3.dll
- 2016-06-12 11:41 - 2015-07-02 08:06 - 01187840 _____ () C:\Program Files (x86)\Steam\icuuc.dll
- 2016-06-12 11:41 - 2015-07-02 08:06 - 01556992 _____ () C:\Program Files (x86)\Steam\icui18n.dll
- 2016-06-12 11:41 - 2016-08-24 05:33 - 00835360 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL
- 2016-06-12 11:41 - 2016-07-05 08:17 - 00266560 _____ () C:\Program Files (x86)\Steam\openvr_api.dll
- 2016-06-12 11:41 - 2016-08-05 06:56 - 49825056 _____ () C:\Program Files (x86)\Steam\bin\libcef.dll
- ==================== Alternate Data Streams (Whitelisted) =========
- (If an entry is included in the fixlist, only the ADS will be removed.)
- AlternateDataStreams: C:\Users\Josh_x\AppData\Local\AdeJ5eQLk3f:Q4oEra6uG3sTyAbCQknn [2226]
- AlternateDataStreams: C:\Users\Josh_x\AppData\Local\Temp:JM7h1JyYY148D3liJKAdX9sM00u4 [1830]
- ==================== Safe Mode (Whitelisted) ===================
- (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
- ==================== Association (Whitelisted) ===============
- (If an entry is included in the fixlist, the registry item will be restored to default or removed.)
- ==================== Internet Explorer trusted/restricted ===============
- (If an entry is included in the fixlist, it will be removed from the registry.)
- ==================== Hosts content: ==========================
- (If needed Hosts: directive could be included in the fixlist to reset Hosts.)
- 2013-08-22 23:25 - 2016-07-08 15:54 - 00001006 ____A C:\WINDOWS\system32\Drivers\etc\hosts
- 127.0.0.1 down.baidu2016.com
- 127.0.0.1 123.sogou.com
- 127.0.0.1 www.czzsyzgm.com
- 127.0.0.1 www.czzsyzxl.com
- 127.0.0.1 union.baidu2019.com
- ==================== Other Areas ============================
- (Currently there is no automatic fix for this section.)
- HKU\S-1-5-21-2876923373-2406336335-375998269-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Innovation\String Lake - Grand Tetons.jpg
- DNS Servers: 192.168.1.254
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
- Windows Firewall is enabled.
- ==================== MSCONFIG/TASK MANAGER disabled items ==
- (Currently there is no automatic fix for this section.)
- HKLM\...\StartupApproved\Run: => "Logitech Download Assistant"
- HKLM\...\StartupApproved\Run: => "AdobeAAMUpdater-1.0"
- HKU\S-1-5-21-2876923373-2406336335-375998269-1001\...\StartupApproved\StartupFolder: => "PdaNet Desktop.lnk"
- HKU\S-1-5-21-2876923373-2406336335-375998269-1001\...\StartupApproved\StartupFolder: => "SUUdULXDRYGTUaXZ.cmd.lnk"
- HKU\S-1-5-21-2876923373-2406336335-375998269-1001\...\StartupApproved\StartupFolder: => "KUUKBCbHRXBRUDPC.cmd.lnk"
- HKU\S-1-5-21-2876923373-2406336335-375998269-1001\...\StartupApproved\StartupFolder: => "XJfMWDhiZXFKHECK.cmd.lnk"
- HKU\S-1-5-21-2876923373-2406336335-375998269-1001\...\StartupApproved\Run: => "Skype"
- HKU\S-1-5-21-2876923373-2406336335-375998269-1001\...\StartupApproved\Run: => "OneDrive"
- HKU\S-1-5-21-2876923373-2406336335-375998269-1001\...\StartupApproved\Run: => "SkypeToolPack"
- HKU\S-1-5-21-2876923373-2406336335-375998269-1001\...\StartupApproved\Run: => "fastweb"
- HKU\S-1-5-21-2876923373-2406336335-375998269-1001\...\StartupApproved\Run: => "Spotify"
- HKU\S-1-5-21-2876923373-2406336335-375998269-1001\...\StartupApproved\Run: => "Spotify Web Helper"
- HKU\S-1-5-21-2876923373-2406336335-375998269-1001\...\StartupApproved\Run: => "CyberGhost"
- HKU\S-1-5-21-2876923373-2406336335-375998269-1001\...\StartupApproved\Run: => "Discord"
- HKU\S-1-5-21-2876923373-2406336335-375998269-1001\...\StartupApproved\Run: => "Steam"
- ==================== FirewallRules (Whitelisted) ===============
- (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
- FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
- FirewallRules: [UDP Query User{FDC2F5F2-62E6-455E-B1CD-59E5B7582178}C:\program files\filezilla ftp client\filezilla.exe] => (Allow) C:\program files\filezilla ftp client\filezilla.exe
- FirewallRules: [TCP Query User{4410106A-D3DE-4E96-B3B5-713993205D8D}C:\program files\filezilla ftp client\filezilla.exe] => (Allow) C:\program files\filezilla ftp client\filezilla.exe
- FirewallRules: [{B732ADB5-C9F5-4965-ADD8-4F23F477B163}] => (Allow) C:\Users\Josh_x\AppData\Roaming\uTorrent\uTorrent.exe
- FirewallRules: [{10F6AC50-0434-4AEC-B2ED-C318AEC0592B}] => (Allow) C:\Users\Josh_x\AppData\Roaming\uTorrent\uTorrent.exe
- FirewallRules: [{7AE41F66-2E7E-439A-A574-2A45FAAD39AA}] => (Allow) C:\Users\Josh_x\AppData\Roaming\uTorrent\uTorrent.exe
- FirewallRules: [{96516B57-9C44-492B-B99C-82E07AD9590A}] => (Allow) C:\Users\Josh_x\AppData\Roaming\uTorrent\uTorrent.exe
- FirewallRules: [{0BCBFED2-84C4-49DD-BA31-8FC864694F42}] => (Allow) C:\Users\Josh_x\AppData\Roaming\uTorrent\uTorrent.exe
- FirewallRules: [{FE5B60BD-A56E-4C6C-B5A2-C96116EDB03A}] => (Allow) C:\Users\Josh_x\AppData\Roaming\uTorrent\uTorrent.exe
- FirewallRules: [UDP Query User{7FF68D83-10B5-458B-AE9F-81834ED80F47}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
- FirewallRules: [TCP Query User{C068AAD5-4B9A-462B-816D-586177CFA3DF}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
- FirewallRules: [{264B3063-326B-4E74-9442-F6D79A1076FC}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
- FirewallRules: [{CAB52957-367D-462D-9618-D271583C6E87}] => (Allow) LPort=2869
- FirewallRules: [{B8D15B9E-D614-4210-93CB-8093CC2F4313}] => (Allow) LPort=1900
- FirewallRules: [{253DE1E7-F029-4329-9459-5BB596DF5DBB}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
- FirewallRules: [{7722F01F-3659-4F58-B278-9B301969976B}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
- FirewallRules: [{7E930BA7-259A-4239-A94B-7E90D7CBC579}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
- FirewallRules: [{501076F1-FE51-484F-940A-5996F7858888}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
- FirewallRules: [TCP Query User{7A2419E6-EC37-4035-AD89-12B0BE8B3821}C:\users\josh_x\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\josh_x\appdata\roaming\spotify\spotify.exe
- FirewallRules: [UDP Query User{2F69E470-AA2D-418F-A96D-38AF9E2D3955}C:\users\josh_x\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\josh_x\appdata\roaming\spotify\spotify.exe
- FirewallRules: [TCP Query User{228C192E-D114-434D-AC9D-1BB1F16B79F6}C:\users\josh_x\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\josh_x\appdata\roaming\spotify\spotify.exe
- FirewallRules: [UDP Query User{C63815DF-0BE5-4CE6-ABD3-AA6941C8A826}C:\users\josh_x\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\josh_x\appdata\roaming\spotify\spotify.exe
- FirewallRules: [TCP Query User{04303596-B66F-4F4C-8DE0-E7A48D220F1A}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe
- FirewallRules: [UDP Query User{47BD8208-A622-4692-B899-B37D6EBDCEBA}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe
- FirewallRules: [TCP Query User{3D25F3C3-2918-43E5-9D4B-47979A2FB6A4}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe
- FirewallRules: [UDP Query User{6FFA9896-2EA7-4FD5-870B-D0FB2905F323}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe
- FirewallRules: [{3D181854-8C0C-488F-B122-1730DAFEFFB3}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Source SDK Base\hl2.exe
- FirewallRules: [{4C096208-371B-408D-AD0F-F43113765503}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Source SDK Base\hl2.exe
- FirewallRules: [{8A08EE83-D4DE-4801-A9B5-5A624F152F33}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\theHunter\launcher\launcher.exe
- FirewallRules: [{04501133-6CD5-44C7-BD8E-5810DAA07BE4}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\theHunter\launcher\launcher.exe
- FirewallRules: [TCP Query User{81D32C90-7F05-4D19-8466-00ACA8D48162}C:\program files (x86)\steam\steamapps\common\thehunter\game\thehunter.exe] => (Block) C:\program files (x86)\steam\steamapps\common\thehunter\game\thehunter.exe
- FirewallRules: [UDP Query User{A4639EEC-EA4D-4722-81C7-62D530269F77}C:\program files (x86)\steam\steamapps\common\thehunter\game\thehunter.exe] => (Block) C:\program files (x86)\steam\steamapps\common\thehunter\game\thehunter.exe
- FirewallRules: [{9AED91EC-28E9-40FC-9B51-4CA2F36C0D9A}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
- FirewallRules: [{7D060140-95CE-4EEE-ABBB-420218852583}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
- FirewallRules: [{C983EA61-E87E-4257-8EC6-EE51F0B46869}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
- FirewallRules: [{A93ABCB0-878D-4282-AB03-CEB3FCF255B7}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
- FirewallRules: [{366E913E-E9FA-49C2-A750-B389F566BCD3}] => (Allow) C:\Program Files (x86)\GamersFirst\APB Reloaded\Binaries\APB.exe
- FirewallRules: [{A3AB5C6D-7FE3-4CCB-8810-0D62EDB6766A}] => (Allow) C:\Program Files (x86)\GamersFirst\APB Reloaded\Binaries\APB.exe
- FirewallRules: [{7E3AEE3D-718B-434E-AEF2-57868B2D426A}] => (Allow) C:\Program Files (x86)\GamersFirst\APB Reloaded\Binaries\VivoxVoiceService.exe
- FirewallRules: [{03B2B2AC-6D09-4D03-95D1-FBD9C708EB7C}] => (Allow) C:\Program Files (x86)\GamersFirst\APB Reloaded\Binaries\VivoxVoiceService.exe
- FirewallRules: [{0B61FBC8-D260-4BA9-89B3-FD105E3ECDE7}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\APB Reloaded\Binaries\APB.exe
- FirewallRules: [{EC8DDFD1-A945-4A70-8CCD-403B0F3F94DF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\APB Reloaded\Binaries\APB.exe
- FirewallRules: [{851D387C-C9A9-44B1-AD36-DE095CA4A04E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\APB Reloaded\Binaries\VivoxVoiceService.exe
- FirewallRules: [{35283B54-E101-42DE-BA82-264A3BD091DA}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\APB Reloaded\Binaries\VivoxVoiceService.exe
- FirewallRules: [TCP Query User{796E41A7-74ED-4E5B-9082-17C5EC36AF91}C:\program files (x86)\ultrabox entertainment\chroma sync\chroma sync.exe] => (Allow) C:\program files (x86)\ultrabox entertainment\chroma sync\chroma sync.exe
- FirewallRules: [UDP Query User{6F7CF1DB-5650-4A30-AD14-6259D273FD92}C:\program files (x86)\ultrabox entertainment\chroma sync\chroma sync.exe] => (Allow) C:\program files (x86)\ultrabox entertainment\chroma sync\chroma sync.exe
- FirewallRules: [{CAE63CCE-FEA0-4872-B791-CFD90024FBA6}] => (Block) C:\program files (x86)\ultrabox entertainment\chroma sync\chroma sync.exe
- FirewallRules: [{EF0A02DD-0EA8-4A7D-A461-03C3CAC9250A}] => (Block) C:\program files (x86)\ultrabox entertainment\chroma sync\chroma sync.exe
- FirewallRules: [TCP Query User{A6F8B0DD-1085-40B4-947E-F220F3771166}C:\users\josh_x\desktop\arcinstaller\chroma android.exe] => (Allow) C:\users\josh_x\desktop\arcinstaller\chroma android.exe
- FirewallRules: [UDP Query User{52F6C1B8-BB13-462C-B2A4-A05024396649}C:\users\josh_x\desktop\arcinstaller\chroma android.exe] => (Allow) C:\users\josh_x\desktop\arcinstaller\chroma android.exe
- FirewallRules: [{352E074D-06A1-4E9A-8611-54DFFE4CE907}] => (Block) C:\users\josh_x\desktop\arcinstaller\chroma android.exe
- FirewallRules: [{0933A82F-F8E8-4AE8-B1B9-65BABAC1A7C8}] => (Block) C:\users\josh_x\desktop\arcinstaller\chroma android.exe
- FirewallRules: [{59337FBB-6AC6-4774-923F-F3C3156F4F87}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
- FirewallRules: [{CAC643AB-534D-4E99-AAA0-5AD3AF6B1288}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
- FirewallRules: [{BC0AA7D4-B8F1-4E85-9CA8-36ED2F5F8842}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
- FirewallRules: [{D8ED7B27-A093-4E91-B9A7-A8376EA1EB92}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
- FirewallRules: [{33597D2E-2BA6-4319-8AC8-EE923EFF76A6}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
- FirewallRules: [{BE107151-4E01-41A0-91B1-2ED34F6412EA}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
- FirewallRules: [{116B57D8-3DE9-4473-ADF6-009C8E6BC747}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- FirewallRules: [TCP Query User{FF05B60F-0B69-4926-8FED-374A1F5E70DE}C:\users\josh_x\appdata\local\skypeplugin\pluginhost.exe] => (Allow) C:\users\josh_x\appdata\local\skypeplugin\pluginhost.exe
- FirewallRules: [UDP Query User{A195B504-1DC9-48F3-92DE-2F756B76BA4A}C:\users\josh_x\appdata\local\skypeplugin\pluginhost.exe] => (Allow) C:\users\josh_x\appdata\local\skypeplugin\pluginhost.exe
- ==================== Restore Points =========================
- 01-08-2016 17:13:27 Removed Adobe Reader XI (11.0.03) MUI.
- 08-08-2016 23:25:52 Scheduled Checkpoint
- 22-08-2016 04:57:29 Scheduled Checkpoint
- 26-08-2016 07:45:46 Removed Elgato Game Capture HD
- ==================== Faulty Device Manager Devices =============
- Name: AMD PSP 1.0 Device
- Description: AMD PSP 1.0 Device
- Class Guid: {d94ee5d8-d189-4994-83d2-f68d7d41b0e6}
- Manufacturer: Advanced Micro Devices, Inc.
- Service: amdpsp
- Problem: : Windows cannot start this hardware device because its configuration information (in the registry) is incomplete or damaged. (Code 19)
- Resolution: A registry problem was detected.
- This can occur when more than one service is defined for a device, if there is a failure opening the service subkey, or if the driver name cannot be obtained from the service subkey. Try these options:
- On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
- Click "Uninstall", and then click "Scan for hardware changes" to load a usable driver.
- ==================== Event log errors: =========================
- Application errors:
- ==================
- Error: (08/26/2016 12:28:35 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: EDMLIFE)
- Description: Activation of app Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI failed with error: -2144927141 See the Microsoft-Windows-TWinUI/Operational log for additional information.
- Error: (08/26/2016 07:45:55 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
- Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.
- Details:
- AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.
- System Error:
- Access is denied.
- .
- Error: (08/26/2016 07:45:31 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: EDMLIFE)
- Description: Activation of app Microsoft.Windows.Photos_8wekyb3d8bbwe!App failed with error: -2147023170 See the Microsoft-Windows-TWinUI/Operational log for additional information.
- Error: (08/23/2016 07:47:47 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: EDMLIFE)
- Description: Activation of app Microsoft.BingWeather_8wekyb3d8bbwe!App failed with error: -2144927148 See the Microsoft-Windows-TWinUI/Operational log for additional information.
- Error: (08/23/2016 07:46:58 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: EDMLIFE)
- Description: Activation of app Microsoft.WindowsMaps_8wekyb3d8bbwe!App failed with error: -2144927148 See the Microsoft-Windows-TWinUI/Operational log for additional information.
- Error: (08/23/2016 07:41:52 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: EDMLIFE)
- Description: Package Microsoft.Windows.ShellExperienceHost_10.0.10586.0_neutral_neutral_cw5n1h2txyewy+App was terminated because it took too long to suspend.
- Error: (08/22/2016 04:57:33 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
- Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.
- Details:
- AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.
- System Error:
- Access is denied.
- .
- Error: (08/21/2016 02:07:29 PM) (Source: Application Error) (EventID: 1000) (User: )
- Description: Faulting application name: csrss.exe, version: 0.0.0.0, time stamp: 0x57956391
- Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
- Exception code: 0xc0000005
- Fault offset: 0x0244183f
- Faulting process id: 0x5d8
- Faulting application start time: 0xcsrss.exe0
- Faulting application path: csrss.exe1
- Faulting module path: csrss.exe2
- Report Id: csrss.exe3
- Faulting package full name: csrss.exe4
- Faulting package-relative application ID: csrss.exe5
- Error: (08/21/2016 02:07:12 PM) (Source: Application Error) (EventID: 1000) (User: )
- Description: Faulting application name: services.exe, version: 0.0.0.0, time stamp: 0x57956391
- Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
- Exception code: 0xc0000005
- Fault offset: 0x0070183f
- Faulting process id: 0x1bd0
- Faulting application start time: 0xservices.exe0
- Faulting application path: services.exe1
- Faulting module path: services.exe2
- Report Id: services.exe3
- Faulting package full name: services.exe4
- Faulting package-relative application ID: services.exe5
- Error: (08/21/2016 02:07:12 PM) (Source: Application Error) (EventID: 1000) (User: )
- Description: Faulting application name: chrome.exe, version: 0.0.0.0, time stamp: 0x57956391
- Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
- Exception code: 0xc0000005
- Fault offset: 0x0077183f
- Faulting process id: 0x2dc0
- Faulting application start time: 0xchrome.exe0
- Faulting application path: chrome.exe1
- Faulting module path: chrome.exe2
- Report Id: chrome.exe3
- Faulting package full name: chrome.exe4
- Faulting package-relative application ID: chrome.exe5
- System errors:
- =============
- Error: (08/27/2016 05:20:52 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
- Description: The Steam Client Service service failed to start due to the following error:
- %%1053 = The service did not respond to the start or control request in a timely fashion.
- Error: (08/27/2016 05:20:52 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
- Description: A timeout was reached (30000 milliseconds) while waiting for the Steam Client Service service to connect.
- Error: (08/27/2016 05:18:55 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
- Description: The WeatherChiknSrvr service failed to start due to the following error:
- %%2 = The system cannot find the file specified.
- Error: (08/27/2016 05:18:24 AM) (Source: DCOM) (EventID: 10010) (User: EDMLIFE)
- Description: NLInternal.SharedRecoActivation
- Error: (08/27/2016 05:18:19 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
- Description: The User Data Access_12b28c25 service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service.
- Error: (08/27/2016 05:18:19 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
- Description: The User Data Storage_12b28c25 service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service.
- Error: (08/27/2016 05:18:19 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
- Description: The Contact Data_12b28c25 service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service.
- Error: (08/26/2016 12:28:35 PM) (Source: DCOM) (EventID: 10010) (User: EDMLIFE)
- Description: CortanaUI.AppXtpp90jhw9p0njjb85kvhxpppgrqfp117.mca
- Error: (08/26/2016 12:28:22 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
- Description: A timeout was reached (30000 milliseconds) while waiting for the Sync Host_12b28c25 service to connect.
- Error: (08/26/2016 12:28:22 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
- Description: A timeout was reached (30000 milliseconds) while waiting for the User Data Storage_12b28c25 service to connect.
- CodeIntegrity:
- ===================================
- Date: 2016-08-12 09:07:17.181
- Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
- Date: 2016-07-15 04:22:11.770
- Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
- Date: 2016-07-13 14:42:35.920
- Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
- Date: 2016-07-08 18:26:47.820
- Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
- Date: 2016-06-28 05:20:25.460
- Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
- Date: 2016-06-26 17:34:35.950
- Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
- Date: 2016-06-23 11:31:02.738
- Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
- Date: 2016-06-18 02:19:19.937
- Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
- Date: 2016-06-15 10:28:15.242
- Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
- Date: 2016-06-14 04:49:50.822
- Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
- ==================== Memory info ===========================
- Processor: AMD A8-6410 APU with AMD Radeon R5 Graphics
- Percentage of memory in use: 46%
- Total physical RAM: 7129.26 MB
- Available physical RAM: 3841.97 MB
- Total Virtual: 8281.26 MB
- Available Virtual: 4339.24 MB
- ==================== Drives ================================
- Drive c: (TI10700500A) (Fixed) (Total:212.43 GB) (Free:83.82 GB) NTFS
- Drive d: (Mar 16 2016) (CDROM) (Total:0.69 GB) (Free:0.52 GB) UDF
- ==================== MBR & Partition Table ==================
- ========================================================
- Disk: 0 (Size: 223.6 GB) (Disk ID: 07899F12)
- Partition: GPT.
- ==================== End of Addition.txt ============================
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement