Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Additional scan result of Farbar Recovery Scan Tool (x64) Version: 20.01.2019
- Ran by Justin (23-01-2019 00:36:23)
- Running from C:\Users\Justin\Desktop
- Windows 10 Home Version 1803 17134.523 (X64) (2018-07-14 03:13:17)
- Boot Mode: Normal
- ==========================================================
- ==================== Accounts: =============================
- Administrator (S-1-5-21-714140578-3863512547-176017840-500 - Administrator - Enabled) => C:\Users\Administrator
- DefaultAccount (S-1-5-21-714140578-3863512547-176017840-503 - Limited - Disabled)
- Guest (S-1-5-21-714140578-3863512547-176017840-501 - Limited - Disabled)
- Justin (S-1-5-21-714140578-3863512547-176017840-1001 - Administrator - Enabled) => C:\Users\Justin
- WDAGUtilityAccount (S-1-5-21-714140578-3863512547-176017840-504 - Limited - Disabled)
- ==================== Security Center ========================
- (If an entry is included in the fixlist, it will be removed.)
- AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
- AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
- ==================== Installed Programs ======================
- (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
- AMD Install Manager (HKLM\...\AMD Catalyst Install Manager) (Version: 9.0.000.4 - Advanced Micro Devices, Inc.)
- Catalyst Control Center Next Localization BR (HKLM\...\{23CBDD30-CA0C-E6B9-4EC8-63B78961132F}) (Version: 2016.0628.2138.37120 - Advanced Micro Devices, Inc.) Hidden
- Catalyst Control Center Next Localization CHS (HKLM\...\{2DABEA95-389F-30CB-F240-19C3FEA03F0F}) (Version: 2016.0628.2138.37120 - Advanced Micro Devices, Inc.) Hidden
- Catalyst Control Center Next Localization CHT (HKLM\...\{73E43AAD-ECAD-2241-0BF9-D6BAAAAE2F12}) (Version: 2016.0628.2138.37120 - Advanced Micro Devices, Inc.) Hidden
- Catalyst Control Center Next Localization CS (HKLM\...\{0DD0D348-1187-9D6B-E70F-4F02DF59D79B}) (Version: 2016.0628.2138.37120 - Advanced Micro Devices, Inc.) Hidden
- Catalyst Control Center Next Localization DA (HKLM\...\{FE563F5D-9C9D-204B-40A8-25EC8A9612BD}) (Version: 2016.0628.2138.37120 - Advanced Micro Devices, Inc.) Hidden
- Catalyst Control Center Next Localization DE (HKLM\...\{CE49BC19-F4A1-19E1-97D3-E8378EFEEFDC}) (Version: 2016.0628.2138.37120 - Advanced Micro Devices, Inc.) Hidden
- Catalyst Control Center Next Localization EL (HKLM\...\{6855CB75-AEDC-D2F3-01FF-4388B0331619}) (Version: 2016.0628.2138.37120 - Advanced Micro Devices, Inc.) Hidden
- Catalyst Control Center Next Localization ES (HKLM\...\{EB603F1D-F8B1-504A-C51B-E04EAF0FC38D}) (Version: 2016.0628.2138.37120 - Advanced Micro Devices, Inc.) Hidden
- Catalyst Control Center Next Localization FI (HKLM\...\{051EFF0D-DBA9-77EE-BAB4-D7D8E782A62F}) (Version: 2016.0628.2138.37120 - Advanced Micro Devices, Inc.) Hidden
- Catalyst Control Center Next Localization FR (HKLM\...\{6B1A268A-DE57-932E-0D0A-5F64CAD31B08}) (Version: 2016.0628.2138.37120 - Advanced Micro Devices, Inc.) Hidden
- Catalyst Control Center Next Localization HU (HKLM\...\{60EBA0A2-5B9B-6E1B-B930-C402985733FF}) (Version: 2016.0628.2138.37120 - Advanced Micro Devices, Inc.) Hidden
- Catalyst Control Center Next Localization IT (HKLM\...\{38967EFC-98E7-C9CD-B954-30346697B984}) (Version: 2016.0628.2138.37120 - Advanced Micro Devices, Inc.) Hidden
- Catalyst Control Center Next Localization JA (HKLM\...\{2DFC817D-5042-2BC1-D04C-ED4CA1734E35}) (Version: 2016.0628.2138.37120 - Advanced Micro Devices, Inc.) Hidden
- Catalyst Control Center Next Localization KO (HKLM\...\{9D6ADD8A-63AB-A5FC-2AE1-E33D70664363}) (Version: 2016.0628.2138.37120 - Advanced Micro Devices, Inc.) Hidden
- Catalyst Control Center Next Localization NL (HKLM\...\{49E7BF58-4A38-6664-75F2-96F9675B1EE1}) (Version: 2016.0628.2138.37120 - Advanced Micro Devices, Inc.) Hidden
- Catalyst Control Center Next Localization NO (HKLM\...\{35AE455A-2D66-3310-A49C-22E4E943EED7}) (Version: 2016.0628.2138.37120 - Advanced Micro Devices, Inc.) Hidden
- Catalyst Control Center Next Localization PL (HKLM\...\{37E7E737-3BC3-6E3A-214B-27194706CCE7}) (Version: 2016.0628.2138.37120 - Advanced Micro Devices, Inc.) Hidden
- Catalyst Control Center Next Localization RU (HKLM\...\{005D91E4-17FA-720F-BEFF-DF645EF8E959}) (Version: 2016.0628.2138.37120 - Advanced Micro Devices, Inc.) Hidden
- Catalyst Control Center Next Localization SV (HKLM\...\{CFD4B8F3-496D-1060-5E59-AA8DE07A6074}) (Version: 2016.0628.2138.37120 - Advanced Micro Devices, Inc.) Hidden
- Catalyst Control Center Next Localization TH (HKLM\...\{2B562D67-CC1D-2F21-9D1D-2889D50A45F0}) (Version: 2016.0628.2138.37120 - Advanced Micro Devices, Inc.) Hidden
- Catalyst Control Center Next Localization TR (HKLM\...\{8A0D2844-DB1C-0D54-2413-727D6D857C3D}) (Version: 2016.0628.2138.37120 - Advanced Micro Devices, Inc.) Hidden
- Chrome (HKLM-x32\...\Google Chrome) (Version: 71.0.3578.98 - Google Inc.)
- Dell Customer Connect (HKLM-x32\...\{2BFA1207-9A98-4D55-9182-5C433ED6A55A}) (Version: 1.4.3.0 - Dell Inc.)
- Dell Digital Delivery (HKLM-x32\...\{AB7F2792-2ED1-4C5C-9F28-680E5110BF72}) (Version: 3.1.1018.0 - Dell Products, LP)
- Dell Help & Support (HKLM\...\{457EFE69-8F49-43E0-80F9-1DEF4F7690C2}) (Version: 2.5.23.0 - Dell Inc.) Hidden
- Dell Help & Support (HKLM-x32\...\InstallShield_{457EFE69-8F49-43E0-80F9-1DEF4F7690C2}) (Version: 2.5.23.0 - Dell Inc.)
- Dell Product Registration (HKLM-x32\...\InstallShield_{48114909-3C3B-43E6-BF98-AE9C396500A3}) (Version: 3.0.127.0 - Dell Inc.)
- Dell SupportAssist (HKLM\...\{E98E94E2-12D1-48E5-AC69-2C312F466136}) (Version: 3.1.0.142 - Dell Inc.)
- Dell SupportAssist (HKLM\...\PC-Doctor for Windows) (Version: 1.2.6793.01 - Dell)
- Dell SupportAssist Remediation (HKLM\...\{5832D99C-C9C6-437F-861C-43ED6333956F}) (Version: 4.1.0.6828 - Dell Inc.) Hidden
- Dell SupportAssist Remediation (HKLM-x32\...\{48253a97-70d4-4166-9a2b-80b3bb2fcc75}) (Version: 4.1.0.6828 - Dell Inc.)
- Dell Update - SupportAssist Update Plugin (HKLM\...\{6DE68941-66DE-48DE-9C80-FE60C9DE0AD4}) (Version: 4.0.1.5857 - Dell Inc.) Hidden
- Dell Update - SupportAssist Update Plugin (HKLM-x32\...\{1dbe752f-b00e-4567-9276-141812b20d28}) (Version: 4.0.1.5857 - Dell Inc.)
- Dell Update (HKLM-x32\...\{D8AE5F9D-647C-49B4-A666-1C20B44EC0E1}) (Version: 2.1.3.0 - Dell Inc.)
- Discord (HKU\S-1-5-21-714140578-3863512547-176017840-1001\...\Discord) (Version: 0.0.304 - Discord Inc.)
- Dropbox 20 GB (HKLM-x32\...\{84D8451D-2ED6-3A59-ABA5-2A447F7C6310}) (Version: 4.1.2.0 - Dropbox, Inc.)
- Dropbox Update Helper (HKLM-x32\...\{099218A5-A723-43DC-8DB5-6173656A1E94}) (Version: 1.3.141.1 - Dropbox, Inc.) Hidden
- DSC/AA Factory Installer (HKLM\...\{F7A70D00-F283-45C8-B163-49EC365D7E27}) (Version: 1.2.6793.01 - PC-Doctor, Inc.) Hidden
- FileZilla Client 3.37.4 (HKLM-x32\...\FileZilla Client) (Version: 3.37.4 - Tim Kosse)
- Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.23 - Google Inc.) Hidden
- Intel(R) Chipset Device Software (HKLM-x32\...\{aaa7f0fb-02dc-4576-beef-7d24842c5fbe}) (Version: 10.1.1.32 - Intel(R) Corporation) Hidden
- Intel(R) Dynamic Platform and Thermal Framework (HKLM-x32\...\{654EE65D-FAA4-4EA6-8C07-DC94E6A304D4}) (Version: 8.2.10900.330 - Intel Corporation)
- Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 21.20.16.4492 - Intel Corporation)
- Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 15.0.1.1040 - Intel Corporation)
- Intel(R) Wireless Bluetooth(R) (HKLM-x32\...\{00000010-0200-1033-84C8-B8D95FA3C8C3}) (Version: 20.10.0 - Intel Corporation)
- Intel® PROSet/Wireless Software (HKLM-x32\...\{8c595286-0f9e-42de-a0d4-969aba282637}) (Version: 20.50.0 - Intel Corporation)
- Intel® Security Assist (HKLM-x32\...\{8B08DDA1-FDE7-4897-8EB6-E0B048A6D88B}) (Version: 1.0.1.618 - Intel Corporation)
- Java 10.0.2 (64-bit) (HKLM\...\{EECB2736-D013-5AC5-9917-7656712F6931}) (Version: 10.0.2.0 - Oracle Corporation)
- Java(TM) SE Development Kit 10.0.2 (64-bit) (HKLM\...\{71307D56-8005-5F5E-9227-BFA2754D6E54}) (Version: 10.0.2.0 - Oracle Corporation)
- LogMeIn Hamachi (HKLM-x32\...\{892DB406-ADF8-4C30-9840-8438AF5B8763}) (Version: 2.2.0.607 - LogMeIn, Inc.) Hidden
- LogMeIn Hamachi (HKLM-x32\...\LogMeIn Hamachi) (Version: 2.2.0.607 - LogMeIn, Inc.)
- Maxx Audio Installer (x64) (HKLM\...\{307032B2-6AF2-46D7-B933-62438DEB2B9A}) (Version: 2.7.9434.5 - Waves Audio Ltd.) Hidden
- McAfee WebAdvisor (HKLM-x32\...\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}) (Version: 4.0.8.17336 - McAfee, Inc.)
- Microsoft Office 365 - en-us (HKLM\...\O365HomePremRetail - en-us) (Version: 16.0.11126.20266 - Microsoft Corporation)
- Microsoft OneDrive (HKU\.DEFAULT\...\OneDriveSetup.exe) (Version: 17.3.6743.1212 - Microsoft Corporation)
- Microsoft OneDrive (HKU\S-1-5-21-714140578-3863512547-176017840-1001\...\OneDriveSetup.exe) (Version: 18.222.1104.0007 - Microsoft Corporation)
- Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
- Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
- Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
- Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
- Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation)
- Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23506 (HKLM-x32\...\{23daf363-3020-4059-b3ae-dc4ad39fed19}) (Version: 14.0.23506.0 - Microsoft Corporation)
- Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation)
- Minecraft (HKLM-x32\...\{756E195A-CB58-4B99-917F-0DDA0D881204}) (Version: 1.0.4.0 - Mojang)
- MuseScore 2 (HKLM-x32\...\{6088F9C1-491A-431F-94D1-81FA26AF7620}) (Version: 2.3.1 - Werner Schweer and Others)
- Nexon Launcher (HKLM-x32\...\Nexon Nexon Launcher) (Version: 2.0.0 - Nexon)
- OEM Application Profile (HKLM-x32\...\{B4B7FD8F-06FC-E277-4F29-8F75F8281D8F}) (Version: 1.00.0000 - Advanced Micro Devices, Inc.)
- Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.11126.20266 - Microsoft Corporation) Hidden
- Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.11126.20266 - Microsoft Corporation) Hidden
- Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.11126.20266 - Microsoft Corporation) Hidden
- Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0409-0000-0000000FF1CE}) (Version: 16.0.11126.20266 - Microsoft Corporation) Hidden
- ÖÕ½áÕß2£ºÉóÅÐÈÕ °æ±¾ 1.0.0 (HKLM-x32\...\{B02F854B-BDB1-4904-A487-880DD0CF1166}_is1) (Version: 1.0.0 - NetEase(Hangzhou) Network Co.Ltd.)
- osu! (HKLM-x32\...\{8235b4fc-a436-4ab8-9b08-b57e8081945e}) (Version: latest - ppy Pty Ltd)
- Product Registration (HKLM\...\{48114909-3C3B-43E6-BF98-AE9C396500A3}) (Version: 3.0.127.0 - Dell Inc.) Hidden
- PX Profile Update (HKLM-x32\...\{AE6AD6F1-2A13-0DFD-D3A6-E099323E361F}) (Version: 1.00.1. - AMD) Hidden
- Quickset64 (HKLM\...\{87CF757E-C1F1-4D22-865C-00C6950B5258}) (Version: 10.17.016 - Dell Inc.)
- Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.14393.31228 - Realtek Semiconductor Corp.)
- Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8555 - Realtek Semiconductor Corp.)
- Realtek PC Camera (HKLM-x32\...\{E399A5B3-ED53-4DEA-AF04-8011E1EB1EAC}) (Version: 10.0.10586.11188 - Realtek Semiconductor Corp.)
- Roblox Player for Justin (HKU\S-1-5-21-714140578-3863512547-176017840-1001\...\{373B1718-8CC5-4567-8EE2-9033AD08A680}) (Version: - Roblox Corporation)
- Roblox Player for Justin (HKU\S-1-5-21-714140578-3863512547-176017840-1001\...\roblox-player) (Version: - Roblox Corporation)
- Rules of Survival version 1.147074.149250 (HKLM-x32\...\{F560482D-4378-4FB8-8EB7-4F017FDBCC90}_is1) (Version: 1.147074.149250 - Hong Kong Netease Interactive Entertainment Limited)
- SmartByte Drivers and Services (HKLM\...\{01F01829-4C5A-41B0-8198-0BDD02B34C47}) (Version: 2.0.643 - Rivet Networks)
- Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
- Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 19.0.14.1 - Synaptics Incorporated)
- True Color (HKLM\...\{EC35CD40-7798-46D0-BF77-993DA07BE79C}) (Version: 7.2.0.0 - Entertainment Experience LLC) Hidden
- True Color (HKLM-x32\...\{00c310e1-4968-4759-8f7c-11720df47b4f}) (Version: 7.2.0.0 - Entertainment Experience)
- True Color XML Tables (HKLM\...\{058DB015-6603-466E-AA45-1601384B96FF}) (Version: 7.4.0.0 - Entertainment Experience LLC) Hidden
- TrueColorXMLTables (HKLM-x32\...\{acf31853-f5c0-4795-9896-f7b4d69b5edb}) (Version: 7.4.0.0 - Entertainment Experience)
- Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{F814D094-197F-43C8-87FA-3210BB780486}) (Version: 2.53.0.0 - Microsoft Corporation)
- VideoPad Video Editor (HKLM-x32\...\VideoPad) (Version: 6.01 - NCH Software)
- Vulkan Run Time Libraries 1.0.17.0 (HKLM\...\VulkanRT1.0.17.0) (Version: 1.0.17.0 - LunarG, Inc.)
- Vulkan Run Time Libraries 1.0.54.1 (HKLM\...\VulkanRT1.0.54.1) (Version: 1.0.54.1 - Intel Corporation Inc.) Hidden
- Vulkan Run Time Libraries 1.0.54.1 (HKLM\...\VulkanRT1.0.54.1-2) (Version: 1.0.54.1 - Intel Corporation Inc.)
- WinRAR 5.60 beta 3 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 5.60.3 - win.rar GmbH)
- ==================== Custom CLSID (Whitelisted): ==========================
- (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
- CustomCLSID: HKU\S-1-5-21-714140578-3863512547-176017840-1001_Classes\CLSID\{a9872fee-5a55-4ecb-9b0f-b06fedcf14d1}\localserver32 -> C:\Program Files\Waves\MaxxAudio\MaxxAudioPro.exe (Waves Audio Ltd)
- ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2018-04-24] (Alexander Roshal)
- ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext.dll [2018-04-24] (Alexander Roshal)
- ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
- ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\System32\DriverStore\FileRepository\ki125183.inf_amd64_cb49708b33bad074\igfxDTCM.dll [2017-11-07] (Intel Corporation)
- ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2018-04-24] (Alexander Roshal)
- ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext.dll [2018-04-24] (Alexander Roshal)
- ==================== Scheduled Tasks (Whitelisted) =============
- (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
- Task: {09815CBA-1C58-4851-A910-3AB9D9A6EE56} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2018-04-11] (Dropbox, Inc.)
- Task: {0D6ED4E7-766C-4D11-B576-CAAA74E33C1F} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1812.3-0\MpCmdRun.exe [2018-12-11] (Microsoft Corporation)
- Task: {25610452-C63E-474E-BBBE-56D3EDA2FFAC} - System32\Tasks\Intel PTT EK Recertification => C:\Program Files\Intel\iCLS Client\IntelPTTEKRecertification.exe [2016-02-20] (Intel(R) Corporation)
- Task: {2968DB3A-AB22-44D2-992C-24D9A2AC66EC} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1812.3-0\MpCmdRun.exe [2018-12-11] (Microsoft Corporation)
- Task: {43C9926E-4CE3-4871-9D23-EF52242F7006} - System32\Tasks\JavaUpdateSched => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2018-06-27] (Oracle Corporation)
- Task: {57E846ED-371B-4701-B3E8-5CD261912284} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2019-01-02] (Microsoft Corporation)
- Task: {593F6E3B-DCDD-43DB-9357-70420582B5AF} - System32\Tasks\PCDDataUploadTask => uaclauncher.exe
- Task: {59A3D749-6B8C-4F51-BF4B-3AB518D6AA8E} - System32\Tasks\SystemToolsDailyTest => uaclauncher.exe
- Task: {5ACCD32D-E324-479F-9BD5-B7C320B7335F} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2018-04-11] (Dropbox, Inc.)
- Task: {65B85F6F-35B3-4459-A179-28255D5B7B25} - System32\Tasks\Microsoft\Windows\HelloFace\FODCleanupTask => C:\WINDOWS\System32\WinBioPlugIns\FaceFodUninstaller.exe [2018-04-12] ()
- Task: {77885972-997A-4EF5-9FEC-0BB4ED844761} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2019-01-02] (Microsoft Corporation)
- Task: {80134CF7-A36A-4FB8-A701-43EE0C599470} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\sdxhelper.exe [2019-01-19] (Microsoft Corporation)
- Task: {89276F04-5D46-4793-805F-CDF3AAFFAE29} - System32\Tasks\DropboxOEM => C:\Program Files (x86)\Dropbox\DropboxOEM\DropboxOEM.exe [2016-12-01] (DropboxOEM)
- Task: {91512961-AE14-45EB-BD21-DE6B7FA02AF2} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\sdxhelper.exe [2019-01-19] (Microsoft Corporation)
- Task: {92AE119D-CA11-45F1-B21B-3CA892C208D4} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-04-11] (Google Inc.)
- Task: {97411830-7321-493E-8726-00D6440BE59A} - System32\Tasks\PCDoctorBackgroundMonitorTask => C:\Program Files\Dell\SupportAssist\uaclauncher.exe [2016-03-25] (PC-Doctor, Inc.)
- Task: {A567150D-D316-44B5-AD11-5798BE000675} - System32\Tasks\RtHDVBg_PushButton => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2018-10-18] (Realtek Semiconductor)
- Task: {AE7385F1-33E6-46D4-B4ED-90FEFE690B67} - System32\Tasks\PCDEventLauncherTask => C:\Program Files\Dell\SupportAssist\sessionchecker.exe [2016-03-25] (PC-Doctor, Inc.)
- Task: {B4ED03B5-388D-4776-A73E-65FB3836EFA3} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1812.3-0\MpCmdRun.exe [2018-12-11] (Microsoft Corporation)
- Task: {BA2DD833-C453-4132-B1D0-BC76C5D292CF} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1812.3-0\MpCmdRun.exe [2018-12-11] (Microsoft Corporation)
- Task: {BC871E8A-BA5C-4FC1-B327-38525E021595} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-04-11] (Google Inc.)
- Task: {CD720D6B-495A-4416-B6B9-EB4EA33D608F} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2019-01-19] (Microsoft Corporation)
- Task: {D30E6210-94D7-4FC8-B4A3-3CC76A935E54} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2019-01-19] (Microsoft Corporation)
- Task: {F531726D-4042-4916-83FA-A1F16BB32757} - System32\Tasks\SmartByte Telemetry => C:\Program Files\Rivet Networks\SmartByte\SmartByteTelemetry.exe [2018-12-04] (DELL)
- Task: {FB8DEEEB-6B9D-4FAA-A52D-6326C5542CC9} - System32\Tasks\Dell SupportAssistAgent AutoUpdate => C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistInstaller.exe [2018-12-12] (Dell Inc.)
- (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
- Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
- Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
- Task: C:\WINDOWS\Tasks\RunDLC.job => cmd c sc start Dell Help SupportWORKGROUP DESKTOP 0C1MC7G
- ==================== Shortcuts & WMI ========================
- (The entries could be listed to be restored or removed.)
- Shortcut: C:\Users\Justin\Favorites\NCH Software Download Site.lnk -> hxxp://www.nchsoftware.com/index.htm
- ==================== Loaded Modules (Whitelisted) ==============
- 2016-05-18 13:31 - 2016-05-18 13:31 - 000140288 _____ () C:\WINDOWS\system32\DPPPlugin.dll
- 2016-05-19 04:57 - 2016-05-19 04:57 - 000087040 _____ () C:\Program Files\TrueColor\TrueColorALS.exe
- 2018-04-12 07:34 - 2018-04-12 07:34 - 000491744 _____ () C:\WINDOWS\SYSTEM32\inputhost.dll
- 2018-04-12 07:34 - 2018-04-12 07:34 - 000472064 _____ () C:\Windows\ShellExperiences\TileControl.dll
- 2018-12-13 08:52 - 2018-11-09 10:17 - 002759680 _____ () C:\Windows\ShellComponents\TaskFlowUI.dll
- 2018-10-04 22:50 - 2018-10-04 22:50 - 000054440 _____ () C:\Program Files\FileZilla FTP Client\fzshellext_64.dll
- 2019-01-09 19:33 - 2019-01-01 14:42 - 002185728 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
- 2018-07-11 21:00 - 2018-07-11 21:00 - 001922224 _____ () C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_17.10314.31700.1000_x64__8wekyb3d8bbwe\Microsoft.Applications.Telemetry.Windows.dll
- 2018-10-16 22:46 - 2018-10-16 22:46 - 000009216 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.36.52.0_x64__kzf8qxf38zg5c\ImagePipelineNative.dll
- 2018-12-14 17:21 - 2018-12-14 17:21 - 000060416 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.36.52.0_x64__kzf8qxf38zg5c\ChakraBridge.dll
- 2018-12-14 17:21 - 2018-12-14 17:22 - 000182272 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.36.52.0_x64__kzf8qxf38zg5c\SkypeBackgroundHost.exe
- 2018-12-11 22:49 - 2018-12-11 22:49 - 034870272 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18102.12011.0_x64__8wekyb3d8bbwe\Video.UI.exe
- 2018-12-11 22:49 - 2018-12-11 22:49 - 000292352 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18102.12011.0_x64__8wekyb3d8bbwe\SharedUI.dll
- 2018-04-12 19:12 - 2018-04-12 19:12 - 000902656 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18102.12011.0_x64__8wekyb3d8bbwe\Microsoft.Membership.MeControl.UI.Xaml.dll
- 2018-11-29 23:41 - 2018-11-29 23:41 - 004202208 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18102.12011.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll
- 2018-12-11 22:49 - 2018-12-11 22:49 - 005967872 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18102.12011.0_x64__8wekyb3d8bbwe\EntCommon.dll
- 2018-12-11 22:49 - 2018-12-11 22:49 - 009072128 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18102.12011.0_x64__8wekyb3d8bbwe\EntPlat.dll
- 2015-06-26 08:34 - 2015-06-26 08:34 - 000014336 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick.2\qtquick2plugin.dll
- 2015-06-26 08:37 - 2015-06-26 08:37 - 000739840 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Controls\qtquickcontrolsplugin.dll
- 2015-06-26 08:35 - 2015-06-26 08:35 - 000014336 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Window.2\windowplugin.dll
- 2015-06-26 08:38 - 2015-06-26 08:38 - 000071168 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Layouts\qquicklayoutsplugin.dll
- 2015-06-26 07:53 - 2015-06-26 07:53 - 000011776 _____ () C:\Program Files\AMD\CNext\CNext\libEGL.dll
- 2015-06-26 07:51 - 2015-06-26 07:51 - 002013696 _____ () C:\Program Files\AMD\CNext\CNext\libGLESv2.dll
- 2019-01-01 12:55 - 2018-10-31 02:06 - 001057056 _____ () C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\SDL2.dll
- 2019-01-01 12:55 - 2018-09-23 08:00 - 102804768 _____ () C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\libcef.dll
- 2019-01-01 12:55 - 2018-09-23 08:00 - 004866336 _____ () C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\libglesv2.dll
- 2019-01-01 12:55 - 2018-09-23 08:00 - 000116000 _____ () C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\libegl.dll
- 2019-01-08 17:55 - 2019-01-08 17:55 - 002587968 _____ () C:\Program Files\Dell\SupportAssistAgent\PCDr\SupportAssist\6.0.6992.1466\libprotobuf.dll
- 2019-01-17 07:11 - 2019-01-17 07:11 - 000478720 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2019.18112.20010.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
- 2019-01-17 07:11 - 2019-01-17 07:11 - 065903104 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2019.18112.20010.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll
- 2019-01-17 07:11 - 2019-01-17 07:11 - 000012288 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2019.18112.20010.0_x64__8wekyb3d8bbwe\RenderingPlugin.dll
- 2018-04-12 19:15 - 2018-04-12 19:18 - 002523136 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2019.18112.20010.0_x64__8wekyb3d8bbwe\UnityEngineDelegates.dll
- 2018-11-16 19:45 - 2018-11-16 19:46 - 003715072 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2019.18112.20010.0_x64__8wekyb3d8bbwe\MediaEngineCSWrapper.dll
- 2018-11-16 19:45 - 2018-11-16 19:47 - 000036352 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2019.18112.20010.0_x64__8wekyb3d8bbwe\WinMLWrapper.UWP.dll
- 2018-08-18 14:05 - 2018-08-18 14:06 - 002480640 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2019.18112.20010.0_x64__8wekyb3d8bbwe\opencv_imgproc320.dll
- 2018-08-18 14:05 - 2018-08-18 14:06 - 002280960 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2019.18112.20010.0_x64__8wekyb3d8bbwe\opencv_core320.dll
- 2018-04-12 19:15 - 2018-04-12 19:18 - 002283008 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2019.18112.20010.0_x64__8wekyb3d8bbwe\TrackingDLLUWP.dll
- 2019-01-17 07:11 - 2019-01-17 07:11 - 014186496 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2019.18112.20010.0_x64__8wekyb3d8bbwe\PhotosApp.Windows.dll
- 2018-11-16 19:45 - 2018-11-16 19:46 - 003569152 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2019.18112.20010.0_x64__8wekyb3d8bbwe\MediaEngine.dll
- 2019-01-17 07:11 - 2019-01-17 07:11 - 002871296 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2019.18112.20010.0_x64__8wekyb3d8bbwe\AppCore.Windows.dll
- 2018-08-30 00:40 - 2018-08-30 00:42 - 000973312 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2019.18112.20010.0_x64__8wekyb3d8bbwe\RuntimeConfiguration.dll
- 2018-07-27 13:02 - 2018-07-27 13:02 - 004584960 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2019.18112.20010.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll
- 2019-01-08 17:55 - 2019-01-08 17:56 - 017134080 _____ () C:\Program Files\WindowsApps\DellInc.DellSupportAssistforPCs_3.1.30.0_x64__htrsf667h5kn2\SupportAssistClientUI.dll
- 2019-01-08 17:55 - 2019-01-08 17:56 - 000057200 _____ () C:\Program Files\WindowsApps\DellInc.DellSupportAssistforPCs_3.1.30.0_x64__htrsf667h5kn2\win32\SupportAssistAppWire.exe
- 2018-12-14 10:10 - 2018-12-12 13:11 - 005237216 _____ () C:\Program Files (x86)\Google\Chrome\Application\71.0.3578.98\libglesv2.dll
- 2018-12-14 10:10 - 2018-12-12 13:11 - 000117216 _____ () C:\Program Files (x86)\Google\Chrome\Application\71.0.3578.98\libegl.dll
- 2018-10-24 22:00 - 2018-10-31 02:06 - 000879904 _____ () C:\Program Files (x86)\Steam\SDL2.dll
- 2018-10-24 22:00 - 2016-09-01 09:02 - 004969248 _____ () C:\Program Files (x86)\Steam\v8.dll
- 2018-10-24 22:00 - 2019-01-05 07:33 - 002650400 _____ () C:\Program Files (x86)\Steam\video.dll
- 2018-10-24 22:00 - 2017-12-20 09:43 - 000695584 _____ () C:\Program Files (x86)\Steam\libavformat-57.dll
- 2018-10-24 22:00 - 2017-12-20 09:43 - 000351520 _____ () C:\Program Files (x86)\Steam\libavresample-3.dll
- 2018-10-24 22:00 - 2017-12-20 09:43 - 000847136 _____ () C:\Program Files (x86)\Steam\libavutil-55.dll
- 2018-10-24 22:00 - 2017-12-20 09:43 - 005137696 _____ () C:\Program Files (x86)\Steam\libavcodec-57.dll
- 2018-10-24 22:00 - 2017-12-20 09:43 - 000783648 _____ () C:\Program Files (x86)\Steam\libswscale-4.dll
- 2018-10-24 22:00 - 2016-09-01 09:02 - 001195296 _____ () C:\Program Files (x86)\Steam\icuuc.dll
- 2018-10-24 22:00 - 2016-09-01 09:02 - 001563936 _____ () C:\Program Files (x86)\Steam\icui18n.dll
- 2018-10-24 22:00 - 2019-01-05 07:33 - 001028384 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL
- 2018-10-24 22:00 - 2016-07-05 06:17 - 000266560 _____ () C:\Program Files (x86)\Steam\openvr_api.dll
- 2018-03-27 13:41 - 2018-03-27 13:41 - 000134616 _____ () C:\Program Files (x86)\Dell Update\ServiceTagPlusPlus.dll
- 2016-05-17 12:50 - 2016-05-17 12:50 - 001243936 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
- 2019-01-21 20:49 - 2019-01-15 16:32 - 002000216 _____ () C:\Users\Justin\AppData\Local\Discord\app-0.0.304\ffmpeg.dll
- 2019-01-21 20:49 - 2019-01-15 16:32 - 004332376 _____ () C:\Users\Justin\AppData\Local\Discord\app-0.0.304\libglesv2.dll
- 2019-01-21 20:49 - 2019-01-15 16:32 - 000106328 _____ () C:\Users\Justin\AppData\Local\Discord\app-0.0.304\libegl.dll
- 2019-01-21 20:50 - 2019-01-21 20:50 - 011344728 _____ () \\?\C:\Users\Justin\AppData\Roaming\discord\0.0.304\modules\discord_voice\discord_voice.node
- 2019-01-21 20:50 - 2019-01-21 20:50 - 001723224 _____ () \\?\C:\Users\Justin\AppData\Roaming\discord\0.0.304\modules\discord_utils\discord_utils.node
- 2019-01-21 20:50 - 2019-01-21 20:50 - 001762648 _____ () \\?\C:\Users\Justin\AppData\Roaming\discord\0.0.304\modules\discord_game_utils\discord_game_utils.node
- 2019-01-21 20:50 - 2019-01-21 20:50 - 002672984 _____ () \\?\C:\Users\Justin\AppData\Roaming\discord\0.0.304\modules\discord_spellcheck\node_modules\cld\build\Release\cld.node
- 2019-01-21 20:50 - 2019-01-21 20:50 - 000837464 _____ () \\?\C:\Users\Justin\AppData\Roaming\discord\0.0.304\modules\discord_spellcheck\node_modules\spellchecker\build\Release\spellchecker.node
- 2019-01-21 20:50 - 2019-01-21 20:50 - 000479064 _____ () \\?\C:\Users\Justin\AppData\Roaming\discord\0.0.304\modules\discord_spellcheck\node_modules\keyboard-layout\build\Release\keyboard-layout-manager.node
- 2019-01-21 20:50 - 2019-01-21 20:50 - 000553816 _____ () \\?\C:\Users\Justin\AppData\Roaming\discord\0.0.304\modules\discord_erlpack\discord_erlpack.node
- 2019-01-21 20:51 - 2019-01-21 20:51 - 009914712 _____ () \\?\C:\Users\Justin\AppData\Roaming\discord\0.0.304\modules\discord_cloudsync\discord_cloudsync.node
- 2019-01-21 20:51 - 2019-01-21 20:51 - 002909016 _____ () \\?\C:\Users\Justin\AppData\Roaming\discord\0.0.304\modules\discord_rpc\discord_rpc.node
- 2019-01-21 20:51 - 2019-01-21 20:51 - 001726296 _____ () \\?\C:\Users\Justin\AppData\Roaming\discord\0.0.304\modules\discord_overlay2\discord_overlay2.node
- 2019-01-21 20:51 - 2019-01-21 20:51 - 001266008 _____ () \\?\C:\Users\Justin\AppData\Roaming\discord\0.0.304\modules\discord_modules\discord_modules.node
- 2019-01-21 20:51 - 2019-01-21 20:51 - 022327128 _____ () \\?\C:\Users\Justin\AppData\Roaming\discord\0.0.304\modules\discord_dispatch\discord_dispatch.node
- 2019-01-21 20:51 - 2019-01-21 20:51 - 002947416 _____ () \\?\C:\Users\Justin\AppData\Roaming\discord\0.0.304\modules\discord_contact_import\discord_contact_import.node
- 2019-01-21 20:51 - 2019-01-21 20:51 - 001297752 _____ () \\?\C:\Users\Justin\AppData\Roaming\discord\0.0.304\modules\discord_vigilante\discord_vigilante.node
- 2019-01-21 23:54 - 2019-01-21 23:54 - 001646936 _____ () \\?\C:\Users\Justin\AppData\Roaming\discord\0.0.304\modules\discord_hook\discord_hook.node
- 2019-01-21 20:49 - 2019-01-15 16:32 - 002269528 _____ () C:\Users\Justin\AppData\Local\Discord\app-0.0.304\swiftshader\libglesv2.dll
- 2019-01-21 20:49 - 2019-01-15 16:32 - 000132952 _____ () C:\Users\Justin\AppData\Local\Discord\app-0.0.304\swiftshader\libegl.dll
- ==================== Alternate Data Streams (Whitelisted) =========
- (If an entry is included in the fixlist, only the ADS will be removed.)
- ==================== Safe Mode (Whitelisted) ===================
- (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
- ==================== Association (Whitelisted) ===============
- (If an entry is included in the fixlist, the registry item will be restored to default or removed.)
- ==================== Internet Explorer trusted/restricted ===============
- (If an entry is included in the fixlist, it will be removed from the registry.)
- ==================== Hosts content: ==========================
- (If needed Hosts: directive could be included in the fixlist to reset Hosts.)
- 2015-10-30 15:24 - 2018-12-20 01:18 - 000001768 __RSH C:\WINDOWS\system32\drivers\etc\hosts
- 0.0.0.0 www.hileliadam.co
- 0.0.0.0 hileliadam.co
- 0.0.0.0 www.hilenbizde.com
- 0.0.0.0 hilenbizde.com
- 0.0.0.0 www.wolfteamhacker.com
- 0.0.0.0 wolfteamhacker.com
- 0.0.0.0 wolfteam-hile.com
- 0.0.0.0 www.wolfteam-hile.com
- 0.0.0.0 www.zulahile.com
- 0.0.0.0 zulahile.com
- 0.0.0.0 frmturk.org
- 0.0.0.0 www.frmturk.org
- 0.0.0.0 badeshan.biz
- 0.0.0.0 www.badeshan.biz
- 0.0.0.0 www.mrsnapz.net
- 0.0.0.0 mrsnapz.net
- 0.0.0.0 www.mrsnapznet.us
- 0.0.0.0 mrsnapznet.us
- 0.0.0.0 www.badeshan.com
- 0.0.0.0 www.thefrm.net
- 0.0.0.0 www.plathelper.net
- 0.0.0.0 www.thefrmonline.com
- 0.0.0.0 www.pro-hile.com
- 0.0.0.0 www.pro-hile.net
- 0.0.0.0 www.hileliadam.com
- 0.0.0.0 www.hilelikafa.com
- 0.0.0.0 www.gamehileleri.com
- 0.0.0.0 www.hilemekani.com
- 0.0.0.0 www.frmbull.com
- 0.0.0.0 www.turkfrm.net
- ==================== Other Areas ============================
- (Currently there is no automatic fix for this section.)
- HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path: C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\Program Files (x86)\Intel\iCLS Client\;C:\Program Files\Intel\iCLS Client\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files\Intel\Intel(R) Management Engine Components\IPT;%SYSTEMROOT%\System32\OpenSSH\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\
- HKU\S-1-5-21-714140578-3863512547-176017840-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Justin\Downloads\moonlight.jpg
- DNS Servers: 8.8.8.8 - 8.8.8.4
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Warn)
- Windows Firewall is enabled.
- ==================== MSCONFIG/TASK MANAGER disabled items ==
- If an entry is included in the fixlist, it will be removed.
- ==================== FirewallRules (Whitelisted) ===============
- (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
- FirewallRules: [{959CCEE2-4595-4EC9-BF8C-A8A4B7642F52}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
- FirewallRules: [{9FF787F1-888E-4541-B5EC-69E6C7CD1A8A}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
- FirewallRules: [{48B522E1-1C74-4258-AA80-7E8B2A25C30C}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corporation)
- FirewallRules: [{FAC16255-6FA7-485E-B805-AB80EE386F0B}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corporation)
- FirewallRules: [TCP Query User{DA5402A6-264B-4845-B425-19781E35567A}C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_51\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_51\bin\javaw.exe (Oracle Corporation)
- FirewallRules: [UDP Query User{5568E399-2D2E-46DE-81CD-8DCD9F28FF86}C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_51\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_51\bin\javaw.exe (Oracle Corporation)
- FirewallRules: [TCP Query User{AB13B60F-3620-49FF-A1EA-229B4ECA8A70}C:\ros\ros.exe] => (Allow) C:\ros\ros.exe ()
- FirewallRules: [UDP Query User{921037A3-4306-47CA-BBF4-6AF7A635466D}C:\ros\ros.exe] => (Allow) C:\ros\ros.exe ()
- FirewallRules: [TCP Query User{4813E4B1-C20E-4C75-BABB-0A4B770FE2E6}C:\ros\ccmini\ccmini.exe] => (Allow) C:\ros\ccmini\ccmini.exe (网易公司)
- FirewallRules: [UDP Query User{82B24E56-40E1-434C-B4CD-D8802F148F08}C:\ros\ccmini\ccmini.exe] => (Allow) C:\ros\ccmini\ccmini.exe (网易公司)
- ==================== Restore Points =========================
- 09-01-2019 19:32:28 Windows Update
- 16-01-2019 20:38:44 Scheduled Checkpoint
- ==================== Faulty Device Manager Devices =============
- ==================== Event log errors: =========================
- Application errors:
- ==================
- Error: (01/21/2019 11:29:04 PM) (Source: Application Hang) (EventID: 1002) (User: )
- Description: The program ros.exe version 0.0.0.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.
- Process ID: 19ac
- Start Time: 01d4b19973b2b5af
- Termination Time: 4294967295
- Application Path: C:\ros\ros.exe
- Report Id: a9a8b633-f2b3-47d6-a4ec-8ecdb93d5860
- Faulting package full name:
- Faulting package-relative application ID:
- Error: (01/20/2019 01:12:44 AM) (Source: ESENT) (EventID: 522) (User: )
- Description: ShellExperienceHost (1684,P,98) TILEREPOSITORYS-1-5-21-714140578-3863512547-176017840-500: An attempt to open the device with name "\\.\C:" containing "C:\" failed with system error 5 (0x00000005): "Access is denied. ". The operation will fail with error -1032 (0xfffffbf8).
- Error: (01/17/2019 07:10:32 AM) (Source: MsiInstaller) (EventID: 10005) (User: NT AUTHORITY)
- Description: Product: Update for Windows 10 for x64-based Systems (KB4023057) -- A later version of Update for Windows 10 for x64-based Systems (KB4023057) is already installed. Setup will now exit.
- Error: (01/11/2019 01:11:10 AM) (Source: Application Error) (EventID: 1000) (User: )
- Description: Faulting application name: RadeonSettings.exe, version: 10.1.1.1641, time stamp: 0x57732628
- Faulting module name: Qt5Qml.dll, version: 5.5.0.0, time stamp: 0x558c716c
- Exception code: 0xc0000005
- Fault offset: 0x0000000000144b55
- Faulting process id: 0x2788
- Faulting application start time: 0x01d4a8dd08962b3d
- Faulting application path: C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe
- Faulting module path: C:\Program Files\AMD\CNext\CNext\Qt5Qml.dll
- Report Id: f80aa545-379f-4823-b462-0da128ecbc82
- Faulting package full name:
- Faulting package-relative application ID:
- Error: (01/08/2019 05:58:03 PM) (Source: Application Error) (EventID: 1000) (User: )
- Description: Faulting application name: SupportAssistInstaller.exe, version: 3.1.0.142, time stamp: 0x5bd20eb7
- Faulting module name: KERNELBASE.dll, version: 10.0.17134.441, time stamp: 0x428de48c
- Exception code: 0xe0434352
- Fault offset: 0x000000000003a388
- Faulting process id: 0x11c0
- Faulting application start time: 0x01d4a737508ab55a
- Faulting application path: C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistInstaller.exe
- Faulting module path: C:\WINDOWS\System32\KERNELBASE.dll
- Report Id: fce5a486-1a7f-48e5-8d19-8b6fdd67559e
- Faulting package full name:
- Faulting package-relative application ID:
- Error: (01/08/2019 05:58:02 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
- Description: Application: SupportAssistInstaller.exe
- Framework Version: v4.0.30319
- Description: The process was terminated due to an unhandled exception.
- Exception Info: System.IO.FileNotFoundException
- at Dell.Services.SupportAssist.SupportAssistInstaller.MainWindow.ChangeTaskSchedulerTriggerTime(Int32)
- at Dell.Services.SupportAssist.SupportAssistInstaller.MainWindow.<SupportAssistInstallerPackage_OnDownload>b__36_0()
- Exception Info: System.Reflection.TargetInvocationException
- at System.RuntimeMethodHandle.InvokeMethod(System.Object, System.Object[], System.Signature, Boolean)
- at System.Reflection.RuntimeMethodInfo.UnsafeInvokeInternal(System.Object, System.Object[], System.Object[])
- at System.Delegate.DynamicInvokeImpl(System.Object[])
- at System.Windows.Threading.ExceptionWrapper.InternalRealCall(System.Delegate, System.Object, Int32)
- at System.Windows.Threading.ExceptionWrapper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate)
- at System.Windows.Threading.DispatcherOperation.InvokeImpl()
- at System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
- at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
- at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object)
- at MS.Internal.CulturePreservingExecutionContext.Run(MS.Internal.CulturePreservingExecutionContext, System.Threading.ContextCallback, System.Object)
- at System.Windows.Threading.DispatcherOperation.Invoke()
- at System.Windows.Threading.Dispatcher.ProcessQueue()
- at System.Windows.Threading.Dispatcher.WndProcHook(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef)
- at MS.Win32.HwndWrapper.WndProc(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef)
- at MS.Win32.HwndSubclass.DispatcherCallbackOperation(System.Object)
- at System.Windows.Threading.ExceptionWrapper.InternalRealCall(System.Delegate, System.Object, Int32)
- at System.Windows.Threading.ExceptionWrapper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate)
- at System.Windows.Threading.Dispatcher.LegacyInvokeImpl(System.Windows.Threading.DispatcherPriority, System.TimeSpan, System.Delegate, System.Object, Int32)
- at MS.Win32.HwndSubclass.SubclassWndProc(IntPtr, Int32, IntPtr, IntPtr)
- at MS.Win32.UnsafeNativeMethods.DispatchMessage(System.Windows.Interop.MSG ByRef)
- at System.Windows.Threading.Dispatcher.PushFrameImpl(System.Windows.Threading.DispatcherFrame)
- at System.Windows.Application.RunDispatcher(System.Object)
- at System.Windows.Application.RunInternal(System.Windows.Window)
- at Dell.Services.SupportAssist.SupportAssistInstaller.App.Main()
- Error: (01/08/2019 05:57:22 PM) (Source: Application Hang) (EventID: 1002) (User: )
- Description: The program SupportAssistAppWire.exe version 3.0.2.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.
- Process ID: 22d0
- Start Time: 01d4a4ad4c9133dc
- Termination Time: 4294967295
- Application Path: C:\Program Files\WindowsApps\DellInc.DellSupportAssistforPCs_3.1.15.0_x64__htrsf667h5kn2\win32\SupportAssistAppWire.exe
- Report Id: b16a93f0-1d8e-4663-90a4-394aebd41833
- Faulting package full name: DellInc.DellSupportAssistforPCs_3.1.15.0_x64__htrsf667h5kn2
- Faulting package-relative application ID: App
- Error: (01/05/2019 12:22:10 PM) (Source: Application Error) (EventID: 1000) (User: )
- Description: Faulting application name: MapleStory.exe, version: 8.162.4.0, time stamp: 0x55924f1b
- Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
- Exception code: 0xc0000005
- Fault offset: 0x00000000
- Faulting process id: 0x4358
- Faulting application start time: 0x01d4a4ae26c636d7
- Faulting application path: C:\Users\Justin\Desktop\Ellinia v162.4\MapleStory.exe
- Faulting module path: unknown
- Report Id: bb7b1c50-cac1-4358-8989-ce5a6dc5fcc3
- Faulting package full name:
- Faulting package-relative application ID:
- System errors:
- =============
- Error: (01/23/2019 12:19:01 AM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-0C1MC7G)
- Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
- {D63B10C5-BB46-4990-A94F-E40B9D520160}
- and APPID
- {9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
- to the user DESKTOP-0C1MC7G\Justin SID (S-1-5-21-714140578-3863512547-176017840-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
- Error: (01/22/2019 06:57:35 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
- Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
- {D63B10C5-BB46-4990-A94F-E40B9D520160}
- and APPID
- {9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
- to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
- Error: (01/22/2019 06:55:14 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-0C1MC7G)
- Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
- {8BC3F05E-D86B-11D0-A075-00C04FB68820}
- and APPID
- {8BC3F05E-D86B-11D0-A075-00C04FB68820}
- to the user DESKTOP-0C1MC7G\Justin SID (S-1-5-21-714140578-3863512547-176017840-1001) from address LocalHost (Using LRPC) running in the application container Microsoft.Windows.ContentDeliveryManager_10.0.17134.1_neutral_neutral_cw5n1h2txyewy SID (S-1-15-2-350187224-1905355452-1037786396-3028148496-2624191407-3283318427-1255436723). This security permission can be modified using the Component Services administrative tool.
- Error: (01/21/2019 11:56:16 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
- Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
- {D63B10C5-BB46-4990-A94F-E40B9D520160}
- and APPID
- {9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
- to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
- Error: (01/21/2019 08:48:02 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-0C1MC7G)
- Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
- {D63B10C5-BB46-4990-A94F-E40B9D520160}
- and APPID
- {9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
- to the user DESKTOP-0C1MC7G\Justin SID (S-1-5-21-714140578-3863512547-176017840-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
- Error: (01/21/2019 08:47:23 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
- Description: The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID
- Windows.SecurityCenter.WscBrokerManager
- and APPID
- Unavailable
- to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
- Error: (01/21/2019 08:47:23 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
- Description: The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID
- Windows.SecurityCenter.WscDataProtection
- and APPID
- Unavailable
- to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
- Error: (01/21/2019 08:45:59 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-0C1MC7G)
- Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
- {D63B10C5-BB46-4990-A94F-E40B9D520160}
- and APPID
- {9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
- to the user DESKTOP-0C1MC7G\Justin SID (S-1-5-21-714140578-3863512547-176017840-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
- Windows Defender:
- ===================================
- Date: 2019-01-23 00:26:06.828
- Description:
- Windows Defender Antivirus has detected malware or other potentially unwanted software.
- For more information please see the following:
- https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/Fuerboos.E!cl&threatid=2147723656&enterprise=0
- Name: Trojan:Win32/Fuerboos.E!cl
- ID: 2147723656
- Severity: Severe
- Category: Trojan
- Path: file:_C:\Users\Justin\Downloads\Zakum.exe
- Detection Origin: Local machine
- Detection Type: FastPath
- Detection Source: Real-Time Protection
- Process Name: C:\Users\Justin\Downloads\FRST64.exe
- Signature Version: AV: 1.283.3486.0, AS: 1.283.3486.0, NIS: 1.283.3486.0
- Engine Version: AM: 1.1.15500.2, NIS: 1.1.15500.2
- Date: 2019-01-21 18:44:44.973
- Description:
- Windows Defender Antivirus has detected malware or other potentially unwanted software.
- For more information please see the following:
- https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/Vigorf.A&threatid=2147714384&enterprise=0
- Name: Trojan:Win32/Vigorf.A
- ID: 2147714384
- Severity: Severe
- Category: Trojan
- Path: file:_C:\Users\Justin\Downloads\EV31.zip; webfile:_C:\Users\Justin\Downloads\EV31.zip|https://storagevipshare-01.sfo2.digitaloceanspaces.com/2019-01-16/15c3ee05ad395c.zip|pid:4600,ProcessStart:131925025221058189
- Detection Origin: Internet
- Detection Type: FastPath
- Detection Source: Downloads and attachments
- Process Name: Unknown
- Signature Version: AV: 1.283.3361.0, AS: 1.283.3361.0, NIS: 1.283.3361.0
- Engine Version: AM: 1.1.15500.2, NIS: 1.1.15500.2
- Date: 2019-01-06 13:14:14.567
- Description:
- Windows Defender Antivirus scan has been stopped before completion.
- Scan ID: {C8CBE433-E654-4D69-BF85-DA7FDC0EAD5A}
- Scan Type: Antimalware
- Scan Parameters: Quick Scan
- Date: 2019-01-06 13:13:48.901
- Description:
- Windows Defender Antivirus has detected malware or other potentially unwanted software.
- For more information please see the following:
- https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/Occamy.C&threatid=2147726780&enterprise=0
- Name: Trojan:Win32/Occamy.C
- ID: 2147726780
- Severity: Severe
- Category: Trojan
- Path: file:_C:\Users\Justin\Desktop\qTw5yENg.exe
- Detection Origin: Local machine
- Detection Type: FastPath
- Detection Source: Real-Time Protection
- Process Name: C:\Windows\explorer.exe
- Signature Version: AV: 1.283.2341.0, AS: 1.283.2341.0, NIS: 1.283.2341.0
- Engine Version: AM: 1.1.15500.2, NIS: 1.1.15500.2
- Date: 2019-01-03 21:15:09.339
- Description:
- Windows Defender Antivirus has detected malware or other potentially unwanted software.
- For more information please see the following:
- https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/Occamy.C&threatid=2147726780&enterprise=0
- Name: Trojan:Win32/Occamy.C
- ID: 2147726780
- Severity: Severe
- Category: Trojan
- Path: file:_C:\Users\Justin\AppData\Local\Temp\Rar$DRa14176.29821\qTw5yENg.exe
- Detection Origin: Local machine
- Detection Type: FastPath
- Detection Source: Real-Time Protection
- Process Name: C:\Program Files (x86)\WinRAR\WinRAR.exe
- Signature Version: AV: 1.283.2134.0, AS: 1.283.2134.0, NIS: 1.283.2134.0
- Engine Version: AM: 1.1.15500.2, NIS: 1.1.15500.2
- Date: 2018-12-14 18:23:26.417
- Description:
- Windows Defender Antivirus has encountered an error trying to update signatures.
- New Signature Version:
- Previous Signature Version: 1.283.532.0
- Update Source: Microsoft Update Server
- Signature Type: AntiVirus
- Update Type: Full
- Current Engine Version:
- Previous Engine Version: 1.1.15500.2
- Error code: 0x8024402c
- Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
- Date: 2018-12-14 18:10:35.903
- Description:
- Windows Defender Antivirus has encountered an error trying to update signatures.
- New Signature Version: 1.283.574.0
- Previous Signature Version: 1.283.532.0
- Update Source: User
- Signature Type: AntiSpyware
- Update Type: Delta
- Current Engine Version: 1.1.15500.2
- Previous Engine Version: 1.1.15500.2
- Error code: 0x80509004
- Error description: An unexpected problem occurred. Install any available updates, and then try to start the program again. For information on installing updates, see Help and Support.
- Date: 2018-12-14 18:10:35.903
- Description:
- Windows Defender Antivirus has encountered an error trying to update signatures.
- New Signature Version: 1.283.574.0
- Previous Signature Version: 1.283.532.0
- Update Source: User
- Signature Type: AntiVirus
- Update Type: Delta
- Current Engine Version: 1.1.15500.2
- Previous Engine Version: 1.1.15500.2
- Error code: 0x80509004
- Error description: An unexpected problem occurred. Install any available updates, and then try to start the program again. For information on installing updates, see Help and Support.
- ==================== Memory info ===========================
- Processor: Intel(R) Core(TM) i7-7500U CPU @ 2.70GHz
- Percentage of memory in use: 56%
- Total physical RAM: 8089.64 MB
- Available physical RAM: 3550.73 MB
- Total Virtual: 10671.36 MB
- Available Virtual: 4312.13 MB
- ==================== Drives ================================
- Drive c: (OS) (Fixed) (Total:917.36 GB) (Free:811.25 GB) NTFS
- Drive e: (CHAMPION'S) (Removable) (Total:7.47 GB) (Free:6.43 GB) FAT32
- \\?\Volume{5ba7b080-8980-4383-ad71-0f3b7366ff1b}\ () (Fixed) (Total:0.86 GB) (Free:0.47 GB) NTFS
- \\?\Volume{ac3c5012-518d-4305-be25-0654cf784518}\ (Image) (Fixed) (Total:11.66 GB) (Free:0.64 GB) NTFS
- \\?\Volume{a9afaed7-194e-42c8-a444-26a85e04a91b}\ (DELLSUPPORT) (Fixed) (Total:1.02 GB) (Free:0.45 GB) NTFS
- \\?\Volume{2be48832-92a5-46b1-961c-b7e8a4355a13}\ (ESP) (Fixed) (Total:0.48 GB) (Free:0.43 GB) FAT32
- ==================== MBR & Partition Table ==================
- ========================================================
- Disk: 0 (Size: 931.5 GB) (Disk ID: 0832C9DA)
- Partition: GPT.
- ========================================================
- Disk: 1 (Protective MBR) (Size: 7.5 GB) (Disk ID: 00000000)
- Partition: GPT.
- ==================== End of Addition.txt ============================
Add Comment
Please, Sign In to add comment