This is my original post. https://www.sysnative.com/forums/wi...n-windows-contains-error-help.html#post224051
softwaremaniac instructed me to post these logs here and have a malware specialist take a look cause he saw some trojans in the past that were caught by windows defender.
Thank you ahead of time for you help.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 20.06.2018
Ran by Wr3ckage (administrator) on WR3CKAGE-PC (30-06-2018 18:56:28)
Running from C:\Users\Wr3ckage\Desktop
Loaded Profiles: Wr3ckage & rmarc (Available Profiles: Wr3ckage & rmarc & DefaultAppPool)
Platform: Windows 10 Pro Version 1703 15063.726 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Edge)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.209.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDCountdown.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDClock.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDPOP3.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDRSS.exe
() C:\Program Files\Elgato\SoundCapture\SoundCapture.exe
() C:\Program Files\YoloMouse\YoloMouse.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
() C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18041.15530.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
(Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1806.18062-0\MsMpEng.exe
(Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1806.18062-0\NisSrv.exe
(Microsoft Corporation) C:\Windows\System32\UI0Detect.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Elgato Systems GmbH) C:\Program Files\Elgato\GameCapture\GameCapture.exe
(Microsoft Corporation) C:\Windows\System32\InputMethod\CHT\ChtIME.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Microsoft Corporation) C:\Windows\System32\InputMethod\CHT\ChtIME.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
() C:\Program Files\Elgato\SoundCapture\SoundCapture.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDClock.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDCountdown.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDPOP3.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDRSS.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.209.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(MediaMall Technologies, Inc.) C:\Program Files (x86)\MediaMall\MediaMallServer.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUI.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-18] (Microsoft Corporation)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7156296 2013-03-05] (Realtek Semiconductor)
HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [13318424 2015-03-12] (Logitech Inc.)
HKLM\...\Run: [ShadowPlay] => "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [Elgato Sound Capture] => C:\Program Files\Elgato\SoundCapture\SoundCapture.exe [1234944 2017-04-19] ()
HKLM-x32\...\Run: [LWS] => C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe [204136 2012-09-13] (Logitech Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [3567928 2017-12-04] (Dropbox, Inc.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
HKU\S-1-5-21-2206024096-2261513051-2171788053-1000\...\Run: [BitTorrent] => C:\Users\Wr3ckage\AppData\Roaming\BitTorrent\BitTorrent.exe [2153928 2017-08-19] (BitTorrent Inc.)
HKU\S-1-5-21-2206024096-2261513051-2171788053-1000\...\Run: [Chromium] => c:\users\wr3ckage\appdata\local\chromium\application\chrome.exe [1068544 2016-03-18] (The Chromium Authors)
HKU\S-1-5-21-2206024096-2261513051-2171788053-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [9773272 2017-05-19] (Piriform Ltd)
HKU\S-1-5-21-2206024096-2261513051-2171788053-1000\...\Run: [Discord] => C:\Users\Wr3ckage\AppData\Local\Discord\app-0.0.298\Discord.exe [57477112 2017-08-08] (Discord Inc.)
HKU\S-1-5-21-2206024096-2261513051-2171788053-1000\...\Run: [YoloMouse] => C:\Program Files\YoloMouse\YoloMouse.exe [222208 2017-02-08] ()
HKU\S-1-5-21-2206024096-2261513051-2171788053-1000\...\Run: [uTorrent] => C:\Users\Wr3ckage\AppData\Roaming\uTorrent\uTorrent.exe [1981624 2017-11-28] (BitTorrent Inc.)
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - %SystemRoot%\system32\wpdshserviceobj.dll (Microsoft Corporation)
BootExecute: autocheck autochk /r \??\C:autocheck autochk *
GroupPolicy: Restriction ? <==== ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
CHR HKU\S-1-5-21-2206024096-2261513051-2171788053-1000\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings: [ProxySettingsPerUser] 0 <==== ATTENTION (Restriction - ProxySettings)
Winsock: Catalog5 07 c:\Windows\SysWOW64\wlidnsp.dll [43008 2017-03-18] (Microsoft Corporation)
Winsock: Catalog5 08 c:\Windows\SysWOW64\wlidnsp.dll [43008 2017-03-18] (Microsoft Corporation)
Winsock: Catalog5-x64 07 c:\Windows\System32\wlidnsp.dll [65536 2017-03-18] (Microsoft Corporation)
Winsock: Catalog5-x64 08 c:\Windows\System32\wlidnsp.dll [65536 2017-03-18] (Microsoft Corporation)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 208.59.247.45 208.59.247.46 192.168.1.1
Tcpip\..\Interfaces\{0d37b7da-92f5-4a28-8cfa-834fc3f410d3}: [DhcpNameServer] 198.18.0.1 198.18.0.2
Tcpip\..\Interfaces\{72814d51-9887-445a-a1de-cc798b9d1398}: [DhcpNameServer] 208.59.247.45 208.59.247.46 192.168.1.1
Internet Explorer:
==================
SearchScopes: HKU\S-1-5-21-2206024096-2261513051-2171788053-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://us.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_fs_16_35¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzuyByE0DtDtB0BtB0C0Azy0ByC0Ezz0A0FtN0D0Tzu0StCyBtDyCtN1L2XzutAtFtByEtFyCtFzytN1L1Czu1BtBtN1L1G1B1V1N2Y1L1Qzu2SyDzz0EyB0C0D0FyCtGyB0F0DtAtGzyzztBzztGyB0DyC0DtGtB0A0F0EtCtCyEzyzyyE0F0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0C0EtDzzyEzyyB0AtG0DyD0EzztGyE0EyE0BtG0BtD0C0DtGyE0DtD0A0FzzyDyB0Bzy0Bzz2QtN0A0LzuyE%26cr%3D1500848655%26a%3Dwbf_fs_16_35%26os_ver%3D10.0%26os%3DWindows%2B10%2BPro&p={searchTerms}
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2018-06-29] (Microsoft Corporation)
BHO: No Name -> {3706EE7C-3CAD-445D-8A43-03EBC3B75908} -> No File
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-04-23] (Google Inc.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\ssv.dll [2015-07-28] (Oracle Corporation)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-04-23] (Google Inc.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\jp2ssv.dll [2015-07-28] (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-04-23] (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-04-23] (Google Inc.)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-06-29] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-06-29] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-06-29] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-06-29] (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
FireFox:
========
FF ProfilePath: C:\Users\Wr3ckage\AppData\Roaming\Mozilla\Firefox\Profiles\mpsryc5m.default [2018-06-30]
FF user.js: detected! => C:\Users\Wr3ckage\AppData\Roaming\Mozilla\Firefox\Profiles\mpsryc5m.default\user.js [2014-08-10]
FF Homepage: Mozilla\Firefox\Profiles\mpsryc5m.default -> hxxps://us.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_fs_16_35¶m1=1¶m2=f%3D1%26b%3DFirefox%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzuyByE0DtDtB0BtB0C0Azy0ByC0Ezz0A0FtN0D0Tzu0StCyBtDyCtN1L2XzutAtFtByEtFyCtFzytN1L1Czu1BtBtN1L1G1B1V1N2Y1L1Qzu2SyDzz0EyB0C0D0FyCtGyB0F0DtAtGzyzztBzztGyB0DyC0DtGtB0A0F0EtCtCyEzyzyyE0F0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0C0EtDzzyEzyyB0AtG0DyD0EzztGyE0EyE0BtG0BtD0C0DtGyE0DtD0A0FzzyDyB0Bzy0Bzz2QtN0A0LzuyE%26cr%3D1500848655%26a%3Dwbf_fs_16_35%26os_ver%3D10.0%26os%3DWindows%2B10%2BPro
FF NewTab: Mozilla\Firefox\Profiles\mpsryc5m.default -> about:newtab
FF Extension: (Bluhell Firewall) - C:\Users\Wr3ckage\AppData\Roaming\Mozilla\Firefox\Profiles\mpsryc5m.default\Extensions\{6BB5760D-F97E-421B-AF5B-8457A90C3CED}.xpi [2018-01-13] [Legacy]
FF SearchPlugin: C:\Users\Wr3ckage\AppData\Roaming\Mozilla\Firefox\Profiles\mpsryc5m.default\searchplugins\Search Provided by Yahoo.xml [2016-03-14]
FF SearchPlugin: C:\Users\Wr3ckage\AppData\Roaming\Mozilla\Firefox\Profiles\mpsryc5m.default\searchplugins\yahoo! powered.xml [2016-09-02]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_27_0_0_187.dll [2017-11-14] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_27_0_0_187.dll [2017-11-14] ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2016-10-06] (Google)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.0.72 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-03-12] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-03-12] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.51.2 -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\dtplugin\npDeployJava1.dll [2015-07-28] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.51.2 -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\plugin2\npjp2.dll [2015-07-28] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2018-03-08] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2017-10-27] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2017-10-27] (NVIDIA Corporation)
FF Plugin-x32: @playon.tv/PlayOnToolbar -> C:\Program Files (x86)\MediaMall\toolbar\npVT.dll [2017-04-18] (MediaMall Technologies, Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-15] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-15] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2013-07-30] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2013-05-11] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2206024096-2261513051-2171788053-1000: @my.com/Games -> C:\Users\Wr3ckage\AppData\Local\MyComGames\NPMyComDetector.dll [2016-02-06] (MY.COM B.V.)
FF Plugin HKU\S-1-5-21-2206024096-2261513051-2171788053-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Wr3ckage\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-08-28] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-2206024096-2261513051-2171788053-1000: jpl.nasa.gov/NASAEyes -> C:\Users\Wr3ckage\AppData\Roaming\JPL-NASA-Caltech\NASA's Eyes\npNASAEyes.dll [2014-12-16] (Jet Propulsion Laboratory)
StartMenuInternet: FIREFOX.EXE - firefox.exe
Chrome:
=======
CHR HomePage: Default -> hxxps://us.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_mdaffmarmarie_16_09¶m1=1¶m2=f%3D1%26b%3DChrome%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzuyByE0DtDtB0BtB0C0Azy0ByC0Ezz0A0FtN0D0Tzu0StCyDtByCtN1L2XzutAtFtCzytFtCtFtDtN1L1Czu1BtBtN1L1G1B1V1N2Y1L1Qzu2StCtC0FtAzyyEzztCtGtBtAtC0BtGyEyCzy0FtGyDyEtCzytGyBtAyBtAtDtA0A0ByDtAyEyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0C0EtDzzyEzyyB0AtG0DyD0EzztGyE0EyE0BtG0BtD0C0DtGyE0DtD0A0FzzyDyB0Bzy0Bzz2QtN0A0LzuyE%26cr%3D511454156%26a%3Dwncy_mdaffmarmarie_16_09%26os_ver%3D6.1%26os%3DWindows%2B7%2BUltimate
CHR DefaultSearchURL: Default -> hxxps://us.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_mdaffmarmarie_16_09¶m1=1¶m2=f%3D4%26b%3DChrome%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzuyByE0DtDtB0BtB0C0Azy0ByC0Ezz0A0FtN0D0Tzu0StCyDtByCtN1L2XzutAtFtCzytFtCtFtDtN1L1Czu1BtBtN1L1G1B1V1N2Y1L1Qzu2StCtC0FtAzyyEzztCtGtBtAtC0BtGyEyCzy0FtGyDyEtCzytGyBtAyBtAtDtA0A0ByDtAyEyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0C0EtDzzyEzyyB0AtG0DyD0EzztGyE0EyE0BtG0BtD0C0DtGyE0DtD0A0FzzyDyB0Bzy0Bzz2QtN0A0LzuyE%26cr%3D511454156%26a%3Dwncy_mdaffmarmarie_16_09%26os_ver%3D6.1%26os%3DWindows%2B7%2BUltimate&p={searchTerms}
CHR DefaultSearchKeyword: Default -> search provided by yahoo.com
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?client=chrome&hl={language}&q={searchTerms}
CHR Profile: C:\Users\Wr3ckage\AppData\Local\Google\Chrome\User Data\Default [2018-06-30]
CHR Extension: (Google Docs Offline) - C:\Users\Wr3ckage\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-03-31]
CHR Extension: (AdBlock) - C:\Users\Wr3ckage\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2018-06-16]
CHR Extension: (TwitchAlerts Stream Labels) - C:\Users\Wr3ckage\AppData\Local\Google\Chrome\User Data\Default\Extensions\kgmggmdngboajiakmbpdknfpdelbjbcg [2016-12-07]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Wr3ckage\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-04]
CHR Extension: (Chrome Media Router) - C:\Users\Wr3ckage\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-11-16]
CHR HKLM\...\Chrome\Extension: [ajcmdlkeklfmbjffnlofgfkjcnpfckab] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-2206024096-2261513051-2171788053-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [ajcmdlkeklfmbjffnlofgfkjcnpfckab] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [ajcmdlkeklfmbjffnlofgfkjcnpfckab] - hxxps://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S2 AppApcVerifier; C:\ProgramData\AppApcVerifier\AppVerifierapc.exe [47104 2016-06-30] (AppApcVerifier) [File not signed]
S2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.01.02\atkexComSvc.exe [936728 2013-07-04] ()
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1522184 2017-06-10] ()
S2 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [409304 2014-10-08] (BlueStack Systems, Inc.)
S2 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [388824 2014-10-08] (BlueStack Systems, Inc.)
S2 BstHdUpdaterSvc; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe [782040 2014-10-08] (BlueStack Systems, Inc.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [8765104 2018-06-20] (Microsoft Corporation)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2017-05-03] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2017-05-03] (Dropbox, Inc.)
R2 DbxSvc; C:\WINDOWS\system32\DbxSvc.exe [51016 2017-12-04] (Dropbox, Inc.)
S2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15344 2013-01-31] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [731648 2013-02-13] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [820184 2013-02-13] (Intel(R) Corporation)
S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [177376 2016-08-12] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-03-12] (Intel Corporation)
R2 MediaMall Server; C:\Program Files (x86)\MediaMall\MediaMallServer.exe [8326408 2018-01-09] (MediaMall Technologies, Inc.)
S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [3758336 2015-11-29] (INCA Internet Co., Ltd.)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2078216 2015-10-08] (Electronic Arts)
R2 osrss; C:\WINDOWS\system32\osrss.dll [131288 2018-06-27] (Microsoft Corporation)
S3 PAExec; C:\WINDOWS\PAExec.exe [189112 2017-02-15] (Power Admin LLC)
S3 PrintNotify; c:\Windows\System32\spool\drivers\x64\{2C4EE6E4-1857-4293-96A1-60E4D8EC3A69}\PrintConfig.dll [2899968 2017-03-18] (Microsoft Corporation)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [3913064 2017-03-18] (Microsoft Corporation)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1806.18062-0\NisSrv.exe [3925648 2018-06-26] (Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1806.18062-0\MsMpEng.exe [100080 2018-06-26] (Microsoft Corporation)
R2 NvContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe" -s NvContainerLocalSystem -f "C:\ProgramData\NVIDIA\NvContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\LocalSystem" -r -p 30000
S3 NvContainerNetworkService; "C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe" -s NvContainerNetworkService -f "C:\ProgramData\NVIDIA\NvContainerNetworkService.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\NetworkService" -r -p 30000
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
R2 NvTelemetryContainer; "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\plugin"
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 asahci64; C:\WINDOWS\System32\drivers\asahci64.sys [47512 2013-01-10] (Asmedia Technology)
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2013-07-04] ()
R3 bcgame; C:\WINDOWS\system32\drivers\bcgame.sys [35328 2007-08-14] (Belkin Corporation)
S2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [122072 2014-10-08] (BlueStack Systems)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [130688 2016-07-22] (Samsung Electronics Co., Ltd.)
S3 ElgatoGC658Y; C:\WINDOWS\System32\Drivers\ElgatoGC658.sys [50288 2012-11-12] (UB658)
R3 ElgatoVAD; C:\WINDOWS\system32\DRIVERS\ElgatoVAD.sys [38152 2016-08-16] (Elgato Systems GmbH)
R2 ISOMount; C:\Program Files (x86)\Free ISO Mount\FIMx64.sys [33896 2014-08-10] ()
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [192216 2018-06-30] (Malwarebytes)
R1 MpKsl6e22bb12; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C11889C0-CB94-4601-BCA7-336BEE2F8551}\MpKsl6e22bb12.sys [58120 2018-06-30] (Microsoft Corporation)
R3 msvad_simple; C:\WINDOWS\system32\drivers\povrtdev.sys [28528 2015-10-29] (MediaMall Technologies, Inc.)
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nv_ref_pubwu.inf_amd64_2e7fa54192fe16d0\nvlddmkm.sys [16936048 2017-11-09] (NVIDIA Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30144 2017-03-27] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [47552 2017-03-27] (NVIDIA Corporation)
R3 nvvhci; C:\WINDOWS\System32\drivers\nvvhci.sys [57792 2017-03-27] (NVIDIA Corporation)
S3 SDFRd; C:\WINDOWS\System32\drivers\SDFRd.sys [31128 2017-03-18] ()
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [164992 2016-07-22] (Samsung Electronics Co., Ltd.)
S3 taphss6; C:\WINDOWS\System32\DRIVERS\taphss6.sys [42184 2014-01-14] (Anchorfree Inc.)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [46592 2018-06-26] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [340008 2018-06-26] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [59944 2018-06-26] (Microsoft Corporation)
S3 WinRing0_1_2_0; C:\Program Files (x86)\EVGA\Precision XOC\WinRing0\WinRing0x64.sys [14536 2015-10-20] (OpenLibSys.org)
R3 XSplit_Dummy; C:\WINDOWS\system32\drivers\xspltspk.sys [26200 2015-05-26] (SplitmediaLabs Limited)
U3 idsvc; no ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-06-30 18:56 - 2018-06-30 18:56 - 000028486 _____ C:\Users\Wr3ckage\Desktop\FRST.txt
2018-06-30 18:55 - 2018-06-30 18:55 - 002412544 _____ (Farbar) C:\Users\Wr3ckage\Desktop\FRST64.exe
2018-06-30 18:47 - 2018-06-30 18:47 - 007765399 _____ C:\Users\Wr3ckage\Desktop\gsmartcontrol-1.1.1-win32.exe
2018-06-30 18:35 - 2018-06-30 18:35 - 001371677 _____ C:\Users\Wr3ckage\Desktop\Fixlog.txt
2018-06-30 18:32 - 2018-06-30 18:56 - 000000000 ____D C:\FRST
2018-06-30 18:16 - 2018-06-30 18:16 - 011262890 _____ C:\Users\Wr3ckage\Desktop\cbs.txt
2018-06-30 18:16 - 2018-06-30 18:16 - 000712022 _____ C:\Users\Wr3ckage\Desktop\cbs (3).zip
2018-06-30 18:16 - 2018-06-30 18:16 - 000712022 _____ C:\Users\Wr3ckage\Desktop\cbs (2).zip
2018-06-30 18:02 - 2018-06-30 18:02 - 006430316 _____ C:\Users\Wr3ckage\Downloads\CBS.zip
2018-06-30 18:01 - 2018-06-30 18:01 - 006430316 _____ C:\Users\Wr3ckage\Desktop\CBS.zip
2018-06-30 18:01 - 2018-06-30 18:01 - 000000000 ____D C:\Users\Wr3ckage\Desktop\CBS
2018-06-30 17:59 - 2018-06-30 17:59 - 002884096 _____ (niemiro) C:\Users\Wr3ckage\Downloads\SFCFix.exe
2018-06-30 15:20 - 2018-06-30 15:20 - 042400128 _____ (EaseUS ) C:\Users\Wr3ckage\Downloads\drw_setup.exe
2018-06-30 04:54 - 2018-06-30 04:54 - 000286158 _____ C:\Users\Wr3ckage\Desktop\SFCFix.zip
2018-06-30 04:52 - 2018-06-30 04:52 - 002884096 _____ (niemiro) C:\Users\Wr3ckage\Desktop\SFCFix.exe
2018-06-30 04:11 - 2018-06-30 04:11 - 000195346 _____ C:\Users\Wr3ckage\Downloads\wu170509.diagcab
2018-06-30 03:02 - 2018-06-30 03:02 - 000000000 ____D C:\Users\rmarc\AppData\Local\NVIDIA Corporation
2018-06-30 03:02 - 2018-06-30 03:02 - 000000000 ____D C:\Users\rmarc\AppData\Local\Comms
2018-06-30 03:01 - 2018-06-30 03:01 - 001573568 _____ C:\Users\rmarc\Downloads\SteamSetup.exe
2018-06-30 03:00 - 2018-06-30 04:05 - 000000000 ____D C:\Users\rmarc\AppData\Local\Publishers
2018-06-30 03:00 - 2018-06-30 04:05 - 000000000 ____D C:\Users\rmarc\AppData\Local\Packages
2018-06-30 03:00 - 2018-06-30 03:00 - 000002336 _____ C:\Users\rmarc\Desktop\Google Chrome.lnk
2018-06-30 03:00 - 2018-06-30 03:00 - 000000258 __RSH C:\Users\rmarc\ntuser.pol
2018-06-30 03:00 - 2018-06-30 03:00 - 000000020 ___SH C:\Users\rmarc\ntuser.ini
2018-06-30 03:00 - 2018-06-30 03:00 - 000000000 ____D C:\Users\rmarc\AppData\Roaming\Elgato
2018-06-30 03:00 - 2018-06-30 03:00 - 000000000 ____D C:\Users\rmarc\AppData\Roaming\Adobe
2018-06-30 03:00 - 2018-06-30 03:00 - 000000000 ____D C:\Users\rmarc\AppData\Local\VirtualStore
2018-06-30 03:00 - 2018-06-30 03:00 - 000000000 ____D C:\Users\rmarc\AppData\Local\TileDataLayer
2018-06-30 03:00 - 2018-06-30 03:00 - 000000000 ____D C:\Users\rmarc\AppData\Local\NVIDIA
2018-06-30 03:00 - 2018-06-30 03:00 - 000000000 ____D C:\Users\rmarc\AppData\Local\Logitech
2018-06-30 03:00 - 2018-06-30 03:00 - 000000000 ____D C:\Users\rmarc\AppData\Local\IsolatedStorage
2018-06-30 03:00 - 2018-06-30 03:00 - 000000000 ____D C:\Users\rmarc\AppData\Local\Google
2018-06-30 03:00 - 2018-06-30 03:00 - 000000000 ____D C:\Users\rmarc\AppData\Local\DBG
2018-06-30 03:00 - 2018-06-30 03:00 - 000000000 ____D C:\Users\rmarc\AppData\Local\ConnectedDevicesPlatform
2018-06-30 03:00 - 2018-06-30 03:00 - 000000000 ____D C:\Users\rmarc
2018-06-30 03:00 - 2016-10-19 21:15 - 000000000 ____D C:\Users\rmarc\AppData\Roaming\Media Center Programs
2018-06-30 03:00 - 2016-10-19 21:15 - 000000000 ____D C:\Users\rmarc\AppData\Roaming\Macromedia
2018-06-30 02:43 - 2018-06-30 02:43 - 037993920 _____ (EaseUS ) C:\Users\Wr3ckage\Downloads\epm.exe
2018-06-30 02:16 - 2018-06-30 02:21 - 000824139 _____ C:\Users\Wr3ckage\Desktop\regdll.bat
2018-06-30 02:15 - 2018-06-30 02:15 - 002301216 _____ C:\regdll.bat
2018-06-30 00:30 - 2018-06-30 00:31 - 131354336 _____ (Microsoft Corporation) C:\Users\Wr3ckage\Downloads\msert (1).exe
2018-06-29 13:38 - 2018-06-29 13:38 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools
2018-06-29 09:45 - 2018-06-29 09:45 - 000918104 _____ C:\Users\Wr3ckage\Downloads\628925049244_Mar_2018.pdf
2018-06-29 09:44 - 2018-06-29 09:44 - 000918421 _____ C:\Users\Wr3ckage\Downloads\628925049244_May_2018.pdf
2018-06-29 09:44 - 2018-06-29 09:44 - 000918421 _____ C:\Users\Wr3ckage\Downloads\628925049244_May_2018 (1).pdf
2018-06-29 09:44 - 2018-06-29 09:44 - 000918158 _____ C:\Users\Wr3ckage\Downloads\628925049244_Apr_2018.pdf
2018-06-27 04:17 - 2018-06-27 04:20 - 000000000 ___HD C:\$WINDOWS.~BT
2018-06-27 01:30 - 2018-06-27 01:30 - 000000000 ____D C:\WINDOWS\UpdateAssistant
2018-06-22 23:03 - 2018-06-22 23:03 - 000135252 _____ C:\Users\Wr3ckage\Downloads\SamanthaDym-MarcianoResume.pdf
2018-06-06 16:37 - 2018-06-06 16:37 - 000010478 _____ C:\Users\Wr3ckage\Downloads\test.odt
2018-06-06 16:36 - 2018-06-06 16:36 - 000355200 _____ C:\Users\Wr3ckage\Downloads\test.pdf
2018-06-06 16:22 - 2018-06-06 16:22 - 000078569 _____ C:\Users\Wr3ckage\Desktop\RichardMarcianoResume.PDF.pdf
2018-06-06 16:19 - 2018-06-06 16:19 - 000006664 _____ C:\Users\Wr3ckage\Desktop\test2.odt
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-06-30 18:10 - 2017-08-24 16:28 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2018-06-30 17:23 - 2017-08-24 16:34 - 000004166 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{3FDA6D8E-70CD-417D-A75A-C73BEBB6E755}
2018-06-30 15:28 - 2017-03-18 17:01 - 000000000 ____D C:\WINDOWS\INF
2018-06-30 11:29 - 2017-03-18 17:03 - 000000000 ____D C:\WINDOWS\AppReadiness
2018-06-30 04:28 - 2017-03-18 17:03 - 000000000 ____D C:\WINDOWS\system32\NDF
2018-06-30 04:23 - 2015-10-27 03:11 - 000192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2018-06-30 04:13 - 2017-05-13 01:26 - 000000000 ____D C:\ProgramData\MediaMall
2018-06-30 04:05 - 2016-07-19 16:07 - 000000000 ____D C:\Users\Wr3ckage\AppData\Local\ElevatedDiagnostics
2018-06-30 04:01 - 2017-03-18 17:03 - 000000000 ___HD C:\Program Files\WindowsApps
2018-06-30 03:54 - 2017-04-16 00:46 - 000000000 ____D C:\Users\Wr3ckage\AppData\Local\YoloMouse
2018-06-30 03:16 - 2017-03-18 17:03 - 000000000 ___RD C:\WINDOWS\PrintDialog
2018-06-30 03:16 - 2017-03-18 17:03 - 000000000 ___RD C:\WINDOWS\MiracastView
2018-06-30 03:02 - 2017-08-24 16:29 - 000000000 ____D C:\ProgramData\NVIDIA
2018-06-30 03:00 - 2016-04-27 02:42 - 000000000 __RHD C:\Users\Public\AccountPictures
2018-06-30 02:27 - 2017-08-24 16:29 - 003296422 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI
2018-06-30 02:25 - 2017-08-24 16:29 - 003295974 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2018-06-30 02:24 - 2017-08-24 16:29 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2018-06-29 13:38 - 2017-03-18 17:03 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2018-06-29 13:38 - 2016-11-03 00:59 - 000002493 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk
2018-06-29 13:38 - 2016-11-03 00:59 - 000002492 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk
2018-06-29 13:38 - 2016-11-03 00:59 - 000002456 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access.lnk
2018-06-29 13:38 - 2016-11-03 00:59 - 000002455 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk
2018-06-29 13:38 - 2016-11-03 00:59 - 000002449 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook.lnk
2018-06-29 13:38 - 2016-11-03 00:59 - 000002443 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher.lnk
2018-06-29 13:38 - 2016-11-03 00:59 - 000002435 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk
2018-06-29 13:38 - 2014-02-12 00:14 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2018-06-27 12:10 - 2018-02-14 13:29 - 000131288 _____ (Microsoft Corporation) C:\WINDOWS\system32\osrss.dll
2018-06-27 04:20 - 2018-03-09 06:08 - 000000000 ____D C:\WINDOWS\Panther
2018-06-27 04:20 - 2017-08-24 16:35 - 000001908 _____ C:\WINDOWS\diagwrn.xml
2018-06-27 04:20 - 2017-08-24 16:35 - 000001908 _____ C:\WINDOWS\diagerr.xml
2018-06-27 04:20 - 2016-07-29 20:38 - 000000000 ___HD C:\$GetCurrent
2018-06-27 04:17 - 2018-03-09 06:06 - 000000036 _____ C:\WINDOWS\progress.ini
2018-06-27 04:15 - 2017-08-24 16:36 - 000000258 __RSH C:\Users\Wr3ckage\ntuser.pol
2018-06-27 04:15 - 2017-08-24 16:30 - 000000000 ____D C:\Users\Wr3ckage
2018-06-27 04:15 - 2016-07-29 20:38 - 000000000 ____D C:\Windows10Upgrade
2018-06-27 04:15 - 2016-03-06 04:47 - 000000344 __RSH C:\ProgramData\ntuser.pol
2018-06-26 01:05 - 2018-02-21 16:03 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2018-06-19 00:39 - 2017-08-24 16:34 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2018-06-19 00:39 - 2017-08-24 16:28 - 000391736 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2018-06-16 21:19 - 2017-05-24 14:48 - 000000000 ____D C:\Program Files\Opera
2018-06-12 17:51 - 2013-08-11 21:03 - 000000000 ____D C:\WINDOWS\system32\MRT
2018-06-12 17:50 - 2017-10-11 05:09 - 133315992 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT-KB890830.exe
2018-06-12 17:50 - 2013-08-11 18:53 - 133315992 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
==================== Files in the root of some directories =======
2015-06-12 11:43 - 2015-06-15 04:33 - 004427564 _____ () C:\ProgramData\4j4BNPi59zb3hp1JI2fi3sH4ty68b.exe
2015-06-11 13:15 - 2015-06-11 13:15 - 000549820 _____ () C:\ProgramData\rmA8qT4D.exe
2015-09-24 23:11 - 2015-09-24 23:11 - 000000000 _____ () C:\Users\Wr3ckage\AppData\Roaming\REN_winlogon.exe.vir
2014-06-01 18:47 - 2015-09-24 23:07 - 000266752 _____ (BabaTools.com | Next Generation Tools. (3132333)) C:\Users\Wr3ckage\AppData\Roaming\Twitch God 2014 (VIP Edition) v7.exe
2016-03-06 05:48 - 2016-09-04 22:03 - 000000195 _____ () C:\Users\Wr3ckage\AppData\Roaming\WB.CFG
2015-09-24 23:07 - 2015-09-24 23:11 - 000000000 _____ () C:\Users\Wr3ckage\AppData\Roaming\winlogon.exe.vir
2014-12-28 21:50 - 2014-12-28 21:50 - 000000064 _____ () C:\Users\Wr3ckage\AppData\Local\dc2edefb345698374a259f7e89115294
2017-02-15 18:09 - 2017-02-15 18:11 - 001307648 _____ () C:\Users\Wr3ckage\AppData\Local\file__0.localstorage
2017-06-08 05:17 - 2017-06-08 05:17 - 000019428 _____ () C:\Users\Wr3ckage\AppData\Local\recently-used.xbel
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2018-06-26 17:02
==================== End of FRST.txt ============================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 20.06.2018
Ran by Wr3ckage (30-06-2018 18:56:57)
Running from C:\Users\Wr3ckage\Desktop
Windows 10 Pro Version 1703 15063.726 (X64) (2017-08-24 20:36:50)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-2206024096-2261513051-2171788053-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-2206024096-2261513051-2171788053-503 - Limited - Disabled)
Guest (S-1-5-21-2206024096-2261513051-2171788053-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2206024096-2261513051-2171788053-1002 - Limited - Enabled)
rmarc (S-1-5-21-2206024096-2261513051-2171788053-1004 - Administrator - Enabled) => C:\Users\rmarc
Wr3ckage (S-1-5-21-2206024096-2261513051-2171788053-1000 - Administrator - Enabled) => C:\Users\Wr3ckage
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
µTorrent (HKU\S-1-5-21-2206024096-2261513051-2171788053-1000\...\uTorrent) (Version: 3.5.0.44294 - BitTorrent Inc.)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 19.0.0.213 - Adobe Systems Incorporated)
Adobe Flash Player 27 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 27.0.0.187 - Adobe Systems Incorporated)
Adobe Flash Player 27 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 27.0.0.187 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.03) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.03 - Adobe Systems Incorporated)
Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Ascella Fullscreen Timer (HKLM-x32\...\Ascella Fullscreen Timer_is1) (Version: 1.4.2.0 - AAR Innovations)
Asmedia ASM106x SATA Host Controller Driver (HKLM-x32\...\{61942EF5-2CD8-47D4-869C-2E9A8BB085F1}) (Version: 1.3.4.001 - Asmedia Technology)
ASUS Product Register Program (HKLM-x32\...\{C87D79F6-F813-4812-B7A9-CCCAAB8B1188}) (Version: 1.0.020 - ASUSTek Computer Inc.)
Audacity 2.1.0 (HKLM-x32\...\Audacity_is1) (Version: 2.1.0 - Audacity Team)
AVG 2016 (HKLM\...\{C95CF442-7229-4025-A4F0-E970BF801432}) (Version: 16.0.4450 - AVG Technologies) Hidden
Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment)
BitTorrent (HKU\S-1-5-21-2206024096-2261513051-2171788053-1000\...\BitTorrent) (Version: 7.10.0.43917 - BitTorrent Inc.)
Blender (HKLM\...\{437221A8-91D1-42A0-9E04-0AD64B502374}) (Version: 2.78.1 - Blender Foundation)
BlueStacks App Player (HKLM-x32\...\BlueStacks App Player) (Version: 0.9.4.4079 - BlueStack Systems, Inc.)
BlueStacks Notification Center (HKLM-x32\...\{8DCCC556-265B-478A-8B32-C12DA988BA74}) (Version: 0.9.4.4079 - BlueStack Systems, Inc.)
CameraHelperMsi (HKLM-x32\...\{15634701-BACE-4449-8B25-1567DA8C9FD3}) (Version: 13.51.815.0 - Logitech) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 5.30 - Piriform)
CMUD 3.34 (HKLM-x32\...\CMUD) (Version: 3.34 - Zugg Software)
Combined Community Codec Pack 64bit 2015-10-18 (HKLM\...\Combined Community Codec Pack 64bit_is1) (Version: 2015.10.19.0 - CCCP Project)
Compatibility Pack for the 2007 Office system (HKLM-x32\...\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Core Temp 1.0 RC5 (HKLM\...\{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1) (Version: 1.0 - Alcpu)
CPUID CPU-Z 1.65.1 (HKLM\...\CPUID CPU-Z_is1) (Version: - ) <==== ATTENTION
D3DX10 (HKLM-x32\...\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden
Diablo III (HKLM-x32\...\Diablo III) (Version: - Blizzard Entertainment)
Discord (HKU\S-1-5-21-2206024096-2261513051-2171788053-1000\...\Discord) (Version: 0.0.298 - Discord Inc.)
Dropbox (HKLM-x32\...\Dropbox) (Version: 40.4.46 - Dropbox, Inc.)
Dropbox Update Helper (HKLM-x32\...\{099218A5-A723-43DC-8DB5-6173656A1E94}) (Version: 1.3.65.1 - Dropbox, Inc.) Hidden
Elgato Game Capture HD (HKLM\...\{21F4E9A1-CB52-49EC-997F-4C7F29306252}) (Version: 3.50.125.2125 - Elgato Systems GmbH)
Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
erLT (HKLM-x32\...\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}) (Version: 1.20.138.34 - Logitech, Inc.) Hidden
EVGA OC Scanner X 3.6.1.2 (64-bit) (HKLM\...\{CC520CF6-B02E-49AA-8192-C1DDC159E0AA}}_is1) (Version: - EVGA)
EVGA Precision XOC (HKLM-x32\...\{D705C0CA-D900-45AB-85A7-AD651F7055A6}) (Version: 6.0.9 - EVGA Corporation)
Fox Searchlight Digital Screeners (HKU\S-1-5-21-2206024096-2261513051-2171788053-1000\...\209253121.IIS Windows Server) (Version: - IIS Windows Server)
Free ISO Mount (HKLM-x32\...\FreeISOMount) (Version: 1.0 - Media Freeware)
Game Capture HD v1.0.0.1 (HKLM-x32\...\Software_Elgato_Game Capture HD) (Version: 1.0.0.1 - Elgato Systems)
Game Capture HD60 Pro v1.1.0.149 (HKLM-x32\...\Software_Elgato_Game Capture HD60 Pro) (Version: 1.1.0.149 - Elgato Systems)
Game Capture HD60 S v1.1.0.160 (HKLM-x32\...\Software_Elgato_Game Capture HD60 S) (Version: 1.1.0.160 - Elgato Systems)
Game Capture HD60 v2.1.1.4 (HKLM-x32\...\Software_Elgato_Game Capture HD60) (Version: 2.1.1.4 - Elgato Systems)
GIMP 2.8.20 (HKLM\...\GIMP-2_is1) (Version: 2.8.20 - The GIMP Team)
GoldWave v6.21 (HKLM\...\GoldWave v6.21) (Version: 6.21 - GoldWave Inc.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 62.0.3202.94 - Google Inc.)
Google Earth Plug-in (HKLM-x32\...\{57BB4801-61C8-4E74-9672-2160728A461E}) (Version: 7.1.5.1557 - Google)
Google Earth Pro (HKLM-x32\...\{ECF2E224-42F5-4E50-B58E-94CA70E85697}) (Version: 7.3.0.3832 - Google)
Google Toolbar for Internet Explorer (HKLM-x32\...\{18455581-E099-4BA8-BC6B-F34B2F06600C}) (Version: 1.0.0 - Google Inc.) Hidden
Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.8231.2252 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.7 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden
HandBrake 0.10.5 (HKLM-x32\...\HandBrake) (Version: 0.10.5 - )
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.0.0.1323 - Intel Corporation)
Intel(R) Network Connections 18.1.59.0 (HKLM\...\PROSetDX) (Version: 18.1.59.0 - Intel)
Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.0.0.1083 - Intel Corporation)
Intel(R) Update Manager (HKLM-x32\...\{7224B7CE-196C-4E2A-A1AE-1D7BF259FD36}) (Version: 3.4.1942 - Intel Corporation)
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 2.0.0.100 - Intel Corporation)
Intel® SSD Toolbox (HKLM-x32\...\{06D085C8-1F00-11B2-96A7-8f0CE39193ED}) (Version: 3.2.0.400 - Intel Corporation)
IPVanish (HKLM\...\{37C6D801-BF83-4EA4-9859-109E92625352}) (Version: 3.1.0.0 - IPVanish) Hidden
IPVanish (HKLM-x32\...\IPVanish 3.1.0.0) (Version: 3.1.0.0 - IPVanish)
Java 8 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218051F0}) (Version: 8.0.510 - Oracle Corporation)
Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
Logitech Gaming Software 8.58 (HKLM\...\Logitech Gaming Software) (Version: 8.58.183 - Logitech Inc.)
Logitech Webcam Software (HKLM-x32\...\{D40EB009-0499-459c-A8AF-C9C110766215}) (Version: 2.51 - Logitech Inc.)
Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Office 365 - en-us (HKLM\...\O365HomePremRetail - en-us) (Version: 16.0.10228.20080 - Microsoft Corporation)
Microsoft Office Word Viewer 2003 (HKLM-x32\...\{90850409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-2206024096-2261513051-2171788053-1000\...\OneDriveSetup.exe) (Version: 17.3.7076.1026 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Xbox One Controller for Windows (HKLM\...\{DC2CB48C-FD96-48EB-A36A-7D995BB587EB}) (Version: 1.0.2 - Microsoft Corporation)
Movie Maker (HKLM-x32\...\{38F03569-A636-4CF3-BDDE-032C8C251304}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Movie Maker (HKLM-x32\...\{DD67BE4B-7E62-4215-AFA3-F123A800A389}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 56.0.0.6478 - Mozilla)
MSI Afterburner 2.3.1 (HKLM-x32\...\Afterburner) (Version: 2.3.1 - MSI Co., LTD)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
My.com Game Center (HKU\S-1-5-21-2206024096-2261513051-2171788053-1000\...\MyComGames) (Version: 3.170 - My.com B.V.)
NCSOFT Game Launcher (HKLM-x32\...\NCLauncher_NCWest) (Version: - NCSOFT)
Nostromo (HKLM-x32\...\{548C7B77-8B04-427E-ACD0-D0E6E6E59BCF}) (Version: 3.2.4 - Belkin International)
NVIDIA 3D Vision Driver 388.13 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 388.13 - NVIDIA Corporation)
NVIDIA GeForce Experience 3.5.0.70 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.5.0.70 - NVIDIA Corporation)
NVIDIA Graphics Driver 388.13 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 388.13 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.35.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.35.1 - NVIDIA Corporation)
NvNodejs (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvNodejs) (Version: 3.5.0.70 - NVIDIA Corporation) Hidden
NvTelemetry (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvTelemetry) (Version: 2.4.5.0 - NVIDIA Corporation) Hidden
NvvHci (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvvHci) (Version: 2.02.0.5 - NVIDIA Corporation) Hidden
OBS Studio (HKLM-x32\...\OBS Studio) (Version: 19.0.2 - OBS Project)
Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.10228.20080 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.10228.20080 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.10228.20080 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0409-0000-0000000FF1CE}) (Version: 16.0.10228.20080 - Microsoft Corporation) Hidden
OpenAL (HKLM-x32\...\OpenAL) (Version: - )
Opera Stable 49.0.2725.47 (HKLM-x32\...\Opera 49.0.2725.47) (Version: 49.0.2725.47 - Opera Software)
Origin (HKLM-x32\...\Origin) (Version: 9.7.2.53208 - Electronic Arts, Inc.)
PlayOn (HKLM-x32\...\{7D147000-343B-4202-88BD-7715A4EE93A7}) (Version: 4.3.9 - MediaMall Technologies, Inc.) Hidden
PlayOn (HKLM-x32\...\{9eaa2820-362d-46bd-a7ab-a9244ccd41db}) (Version: 4.3.9.18619 - MediaMall Technologies, Inc.)
PlayOn Dependencies (HKLM-x32\...\{0E100B2E-D56C-4BFB-9FD6-894FDEDC10E6}) (Version: 1.0.0.0 - MediaMall Technologies, Inc.) Hidden
QuickTime 7 (HKLM-x32\...\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}) (Version: 7.79.80.95 - Apple Inc.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6853 - Realtek Semiconductor Corp.)
RivaTuner Statistics Server 5.2.0 (HKLM-x32\...\RTSS) (Version: 5.2.0 - Unwinder)
Rosetta Stone Version 3 (HKLM-x32\...\{80F7CA44-F3A5-4853-8BA6-DDF57CD4F078}) (Version: 3.4.7.0 - Rosetta Stone Ltd.)
SHIELD Streaming (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.NvStreamSrv) (Version: 7.1.0360 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShieldWirelessController) (Version: 3.5.0.70 - NVIDIA Corporation) Hidden
Skypeâ„¢ 7.6 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.6.105 - Skype Technologies S.A.)
SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version: - )
SpeedTest (HKLM-x32\...\{E27EA56C-7123-42AA-950C-3F2A984A0B30}_is1) (Version: - )
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
System Requirements Lab for Intel (HKLM-x32\...\{53C63F43-B827-42D9-8886-4698D91EA33B}) (Version: 4.5.15.0 - Husdawg, LLC)
TeamSpeak 3 Client (HKLM-x32\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH)
TechPowerUp GPU-Z (HKLM-x32\...\TechPowerUp GPU-Z) (Version: - TechPowerUp)
Unigine Valley Benchmark version 1.0 (HKLM-x32\...\Unigine Valley Benchmark_is1) (Version: 1.0 - Unigine Corp.)
Unity Web Player (HKU\S-1-5-21-2206024096-2261513051-2171788053-1000\...\UnityWebPlayer) (Version: 5.2.0f3 - Unity Technologies ApS)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{5009B7EE-8A15-4A23-B404-15E31D02DA67}) (Version: 2.43.0.0 - Microsoft Corporation)
UpdateAssistant (HKLM\...\{A7B60FC9-A750-43C7-B7EC-892CD09147C7}) (Version: 1.18.0.0 - Microsoft Corporation) Hidden
Uplay (HKLM-x32\...\Uplay) (Version: 37.0 - Ubisoft)
VC_CRT_x64 (HKLM\...\{54F2237F-018C-483B-8884-9FC0D88840C3}) (Version: 1.02.0000 - Intel Corporation) Hidden
Ventrilo Client for Windows x64 (HKLM\...\{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}) (Version: 3.0.8.0 - Flagship Industries, Inc.)
VideoPad Video Editor (HKLM-x32\...\VideoPad) (Version: 5.03 - NCH Software)
Virtual Audio Cable 4.14 (HKLM\...\Virtual Audio Cable 4.14) (Version: - )
VirtualCloneDrive (HKLM-x32\...\VirtualCloneDrive) (Version: 5.4.7.0 - Elaborate Bytes)
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
VLC media player 2.0.8 (HKLM-x32\...\VLC media player) (Version: 2.0.8 - VideoLAN)
VSDC Free Video Editor version 5.5.0.601 (HKLM-x32\...\VSDC Free Video Editor_is1) (Version: 5.5.0.601 - Flash-Integro LLC)
Vulkan Run Time Libraries 1.0.61.0 (HKLM\...\VulkanRT1.0.61.0) (Version: 1.0.61.0 - LunarG, Inc.) Hidden
Wargaming.net Game Center (HKU\S-1-5-21-2206024096-2261513051-2171788053-1000\...\Wargaming.net Game Center) (Version: 17.9.0.6629 - Wargaming.net)
Windows 10 Update and Privacy Settings (HKLM\...\{4DFCD818-036A-4229-A67D-CF17DC461D92}) (Version: 1.0.14.0 - Microsoft Corporation)
Windows 10 Update Assistant (HKLM-x32\...\{D5C69738-B486-402E-85AC-2456D98A64E4}) (Version: 1.4.9200.22452 - Microsoft Corporation)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
Windows Setup Remediations (x64) (KB4023057) (HKLM\...\{5534e02f-0f5d-40dd-ba92-bea38d22384d}.sdb) (Version: - )
WinRAR 5.01 beta 1 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.01.1 - win.rar GmbH)
World of Warships (HKU\S-1-5-21-2206024096-2261513051-2171788053-1000\...\WOWS.NA.PRODUCTION) (Version: - Wargaming.net)
XSplit Broadcaster (HKLM-x32\...\{6459F338-FE52-4034-BCA7-74772DA0F24D}) (Version: 1.3.1403.1202 - SplitMediaLabs)
XSplit Gamecaster (HKLM-x32\...\{02297800-E109-4A50-8F82-AACD0844A051}) (Version: 2.5.1507.3024 - SplitmediaLabs)
YoloMouse (HKLM\...\{AD023FBA-862C-4342-9E9C-FBB9870412B5}) (Version: 0.8.2.0 - HaPpY)
zMUD 7.21.0.0 (HKLM-x32\...\zMUD) (Version: 7.21.0.0 - Zugg Software)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
HKU\S-1-5-21-2206024096-2261513051-2171788053-1000\...\ChromeHTML: -> <==== ATTENTION
ShellIconOverlayIdentifiers: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-12-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-12-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-12-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-12-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-12-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-12-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-12-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-12-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-12-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-12-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-12-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-12-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-12-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-12-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-12-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-12-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-12-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-12-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-12-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-12-04] (Dropbox, Inc.)
ContextMenuHandlers1: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-12-04] (Dropbox, Inc.)
ContextMenuHandlers1: [VirtualCloneDrive] -> {B7056B8E-4F99-44f8-8CBD-282390FE5428} => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\ElbyVCDShell.dll [2009-12-14] (Elaborate Bytes AG)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2013-11-27] (Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2013-11-27] (Alexander Roshal)
ContextMenuHandlers2: [VirtualCloneDrive] -> {B7056B8E-4F99-44f8-8CBD-282390FE5428} => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\ElbyVCDShell.dll [2009-12-14] (Elaborate Bytes AG)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamext.dll [2016-03-10] (Malwarebytes)
ContextMenuHandlers4: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-12-04] (Dropbox, Inc.)
ContextMenuHandlers5: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-12-04] (Dropbox, Inc.)
ContextMenuHandlers5: [Gadgets] -> {6B9228DA-9C15-419e-856C-19E768A13BDC} => -> No File
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\System32\nvshext.dll [2017-10-27] (NVIDIA Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamext.dll [2016-03-10] (Malwarebytes)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2013-11-27] (Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2013-11-27] (Alexander Roshal)
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {01B0DEF9-7F56-475D-B8C2-E6F4050B14CA} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2017-05-03] (Dropbox, Inc.)
Task: {0322CE59-05E8-4FD0-A25D-544AE9430569} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\WINDOWS\ehome\ehrec.exe
Task: {05F56212-DD7E-4DC2-9C46-DBC308315334} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-03-27] (NVIDIA Corporation)
Task: {08A0D656-BFBB-434A-AF9A-C95801E614B8} - System32\Tasks\EVGAPrecisionX => C:\Program Files (x86)\EVGA\PrecisionX 16\PrecisionX_x64.exe
Task: {10A4FFA9-C662-449B-81DD-75E3FD5A75BB} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {1172B2B2-8144-47CF-8DA2-06EEECD4AD35} - System32\Tasks\EVGAPrecision => C:\Program Files (x86)\EVGA Precision X\EVGAPrecision.exe
Task: {14ABAAC8-BB0C-46C9-B938-8C208E2D9312} - System32\Tasks\GridinSoft Anti-Malware => C:\Program Files\GridinSoft Anti-Malware\gsam.exe
Task: {1AA9D6D2-9C0E-4C2A-BAE2-F82D57351469} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {1D28F87B-7958-48E3-8D9E-BE734E2EF6A8} - System32\Tasks\{8DB225DA-401B-4324-B9D2-CAEECC6714E3} => C:\Windows\system32\pcalua.exe -a C:\Users\Wr3ckage\Downloads\Haardvuur.exe -d C:\Users\Wr3ckage\Downloads
Task: {1E27A1E5-E788-41A3-A07E-9761AF2E3788} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {21BEE89E-7A5A-46E7-A884-E9E72C370123} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-03-27] (NVIDIA Corporation)
Task: {2550273A-3A52-4D7E-8C8A-5F9AA4439B87} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime -> No File <==== ATTENTION
Task: {313A60CE-3734-4FF0-BD81-15B5735CEDF3} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-03-27] (NVIDIA Corporation)
Task: {34D121B2-4042-4D93-BF9A-14C40F0A5761} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_27_0_0_187_pepper.exe [2017-11-14] (Adobe Systems Incorporated)
Task: {3A5C1EA4-412F-4F79-8A95-D087F488B243} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2018-06-29] (Microsoft Corporation)
Task: {3DD46BF8-4E74-47FA-AD12-A858F1001799} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2018-06-20] (Microsoft Corporation)
Task: {45036761-A47B-460A-B65C-388CA89D794C} - System32\Tasks\{425B38BA-4249-4B92-972E-A9DCACA26066} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\InstallShield Installation Information\{2B41E132-07DF-4925-A3D3-F2D1765CCDFE}\setup.exe" -c -runfromtemp -l0x0009 -removeonly
Task: {4F7E9E38-C6E8-47A8-A994-0665E2B5044C} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-11-14] (Adobe Systems Incorporated)
Task: {50ADA210-8F62-4515-90BD-F9DF48DB3672} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2017-03-27] (NVIDIA Corporation)
Task: {5250DD9F-FEF9-4C70-AF21-6205EE398C8D} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1806.18062-0\MpCmdRun.exe [2018-06-26] (Microsoft Corporation)
Task: {537E0268-30A4-419A-AD05-FE3A631E08E6} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {56057729-3885-45C4-B32F-EBF0301C64DD} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {56367BD5-B69B-4904-8A5E-AF35CB6FA3A8} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {59CF72E4-4C3F-4929-B8FE-A8B1F54232B4} - \PastaQuotes -> No File <==== ATTENTION
Task: {6181CE75-6CDC-4985-B826-91139BE24F53} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2016-08-12] (Intel Corporation)
Task: {62726965-9661-4725-BA45-A6B3720E96CC} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1806.18062-0\MpCmdRun.exe [2018-06-26] (Microsoft Corporation)
Task: {64BEC3E6-B3A4-4ED4-ACCE-013834FB5233} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {6B4E5B16-B84D-4C2D-B543-C0D53FF9D7BE} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2018-06-29] (Microsoft Corporation)
Task: {762DDC4D-8645-4871-A0FC-0DF9738D1C2D} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {7AF5BB6F-7881-4A8C-B61D-71099FDEAD1D} - \Microsoft\Windows\Setup\EOONotify -> No File <==== ATTENTION
Task: {7F4CC302-F7E9-4DD9-979C-D6A352FB6DBC} - \Microsoft\Windows\Setup\gwx\rundetector -> No File <==== ATTENTION
Task: {8131BB14-7FC8-4964-A4A5-E3D89C12AC23} - \LaunchSignup -> No File <==== ATTENTION
Task: {844BC227-11FA-4E17-88A6-D6B3C6343C37} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\WINDOWS\ehome\mcupdate.exe
Task: {8467252C-E66A-4E1B-BE56-05CF87EA4EE3} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\WINDOWS\ehome\mcupdate.exe
Task: {8826475F-15C0-4A16-B4D7-B64AE15EF953} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2017-03-27] (NVIDIA Corporation)
Task: {887F0DF0-A490-46AE-97DC-B6FC9F1C36B9} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {898D3B10-6742-496E-9AB4-91109A33D79C} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {9D667347-2184-4C59-BC1F-BB07F329DD16} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {9E9388D8-1188-4CD9-A682-8551F27EEC88} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-03-27] (NVIDIA Corporation)
Task: {A2E7844B-D058-40AA-BF49-4E1494D59BAC} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {A45AFBEE-4481-4905-9A1D-06FB153EDF89} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {A906D588-606F-4319-AA82-97F62A29DF22} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\WINDOWS\ehome\MCUpdate.exe
Task: {AB978A6C-A494-4780-BCF0-5CED6850F31F} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {AF3DDA01-9A54-440D-B4CA-A739F51711BB} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {B1D9E5F1-5799-4314-9044-FDD9B0C2E7EC} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2018-06-29] (Microsoft Corporation)
Task: {B3B12495-7EA8-4381-AD14-1EEAEF621531} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {B60DAFAE-434F-4EB4-AFF8-6888E33F6C49} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {BD41F101-356F-445E-BF74-5C1E70A295DE} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1806.18062-0\MpCmdRun.exe [2018-06-26] (Microsoft Corporation)
Task: {BED1E8DC-1AAA-47B3-8627-9097B5413F9B} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\WINDOWS\ehome\ehrec.exe
Task: {C4D5822C-5219-4EAE-AC85-22FD064B82D4} - System32\Tasks\Trojan Remover => C:\Program Files\Loaris\Trojan Remover\ltr.exe
Task: {C4F1AEAD-328A-48E0-B257-2A18032AA998} - System32\Tasks\Microsoft\Office\OfficeOsfInstaller => C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\osfinstaller.exe [2018-06-29] (Microsoft Corporation)
Task: {C9EAA4EE-3A05-455F-BB8D-67ED71D8BEE2} - System32\Tasks\Opera scheduled Autoupdate 1495651710 => C:\Program Files\Opera\launcher.exe [2017-11-23] (Opera Software)
Task: {CE1C063E-8D6A-4357-AD29-EE3FF09DF4D3} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime -> No File <==== ATTENTION
Task: {D18B8EDE-1419-4A6D-802F-4C30E9029F51} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {D47FDD49-4CF3-4D5C-878B-6CE0C371C91F} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {E313CD67-A3ED-4DD8-B25D-D6DB85B3C2FD} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2017-05-19] (Piriform Ltd)
Task: {E3AC54D9-AABD-4215-BEE2-0262115F8236} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {E59E241D-BA23-4152-9793-57B7EA9A1E06} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2018-06-20] (Microsoft Corporation)
Task: {EB42E748-1606-4C3B-9025-21294AD33DFA} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {EC025D43-A002-4D7B-8618-AEA78DCB6C0B} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {EF83EAEE-4117-446D-B38B-05C274E5D354} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2017-05-03] (Dropbox, Inc.)
Task: {F28D3CCA-DA9C-4CDD-9B82-952A59DC41AA} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1806.18062-0\MpCmdRun.exe [2018-06-26] (Microsoft Corporation)
Task: {F5384768-C412-47D1-B8F6-92443F06A89A} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {F6733661-63A1-4A55-BA18-916C5EA53F61} - System32\Tasks\ASUS\ASUS Product Register Service => C:\Program Files (x86)\ASUS\APRP\aprp.exe
Task: {F684C460-AE34-4023-A6F3-DE63CF68C901} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2016-08-12] (Intel Corporation)
Task: {FF3F3BCF-472B-4674-9A86-0D387519578F} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {FF5AF123-FE7E-4165-AA42-694A326A4217} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-03-27] (NVIDIA Corporation)
Task: {FFB45B12-5A62-437E-94BF-E2E348DD32BB} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
==================== Shortcuts & WMI ========================
(The entries could be listed to be restored or removed.)
Shortcut: C:\Users\Wr3ckage\Favorites\NCH Software Download Site.lnk -> hxxp://www.nchsoftware.com/index.htm
ShortcutWithArgument: C:\Users\Wr3ckage\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Fox Searchlight Digital Scr....lnk -> C:\Program Files (x86)\Microsoft Silverlight\sllauncher.exe (Microsoft Corporation) -> 209253121.IIS Windows Server
ShortcutWithArgument: C:\Users\Wr3ckage\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\TwitchAlerts Stream Labels.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=kgmggmdngboajiakmbpdknfpdelbjbcg
==================== Loaded Modules (Whitelisted) ==============
2017-08-24 16:29 - 2017-10-27 12:12 - 000133752 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2017-02-15 05:30 - 2017-03-27 23:32 - 001147328 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll
2017-02-08 17:14 - 2017-02-08 17:14 - 000180736 _____ () C:\Program Files\YoloMouse\Yolo64.dll
2017-03-18 16:58 - 2017-03-18 16:58 - 000138000 _____ () C:\WINDOWS\SYSTEM32\inputhost.dll
2018-05-22 15:04 - 2018-05-22 15:04 - 000086528 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.209.0_x64__kzf8qxf38zg5c\SkypeHost.exe
2018-05-22 15:04 - 2018-05-22 15:04 - 000195072 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.209.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll
2018-05-22 15:04 - 2018-05-22 15:04 - 022374400 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.209.0_x64__kzf8qxf38zg5c\SkyWrap.dll
2018-05-22 15:04 - 2018-05-22 15:04 - 002610176 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.209.0_x64__kzf8qxf38zg5c\skypert.dll
2018-05-22 15:04 - 2018-05-22 15:04 - 000654848 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.209.0_x64__kzf8qxf38zg5c\RtmMvrUap.dll
2018-05-22 15:04 - 2018-05-22 15:04 - 000146432 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.209.0_x64__kzf8qxf38zg5c\SkypeHost.Proxies.dll
2014-09-18 03:23 - 2014-09-18 03:23 - 000866584 _____ () C:\Program Files\Logitech Gaming Software\libGLESv2.dll
2015-03-12 14:23 - 2015-03-12 14:23 - 001050904 _____ () C:\Program Files\Logitech Gaming Software\platforms\qwindows.dll
2014-09-18 03:23 - 2014-09-18 03:23 - 000059160 _____ () C:\Program Files\Logitech Gaming Software\libEGL.dll
2015-03-12 14:23 - 2015-03-12 14:23 - 000242456 _____ () C:\Program Files\Logitech Gaming Software\imageformats\qjpeg.dll
2017-04-19 08:43 - 2017-04-19 08:43 - 001234944 _____ () C:\Program Files\Elgato\SoundCapture\SoundCapture.exe
2017-02-08 17:14 - 2017-02-08 17:14 - 000222208 _____ () C:\Program Files\YoloMouse\YoloMouse.exe
2017-11-14 16:13 - 2017-11-10 05:57 - 004135768 _____ () C:\Program Files (x86)\Google\Chrome\Application\62.0.3202.94\libglesv2.dll
2017-11-14 16:13 - 2017-11-10 05:57 - 000100184 _____ () C:\Program Files (x86)\Google\Chrome\Application\62.0.3202.94\libegl.dll
2018-06-08 13:27 - 2018-06-08 13:27 - 000478720 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18041.15530.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
2018-06-08 13:27 - 2018-06-08 13:27 - 067232256 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18041.15530.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll
2017-10-07 13:56 - 2017-10-07 13:56 - 002523136 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18041.15530.0_x64__8wekyb3d8bbwe\UnityEngineDelegates.dll
2018-05-30 06:18 - 2018-05-30 06:19 - 000010752 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18041.15530.0_x64__8wekyb3d8bbwe\RenderingPlugin.dll
2018-05-30 06:18 - 2018-05-30 06:19 - 004214784 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18041.15530.0_x64__8wekyb3d8bbwe\MediaEngineCSWrapper.dll
2018-05-04 09:33 - 2018-05-04 09:33 - 000009216 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18041.15530.0_x64__8wekyb3d8bbwe\ImagePipelineNative.dll
2018-05-30 06:18 - 2018-05-30 06:19 - 000035840 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18041.15530.0_x64__8wekyb3d8bbwe\WinMLWrapper.UWP.dll
2018-04-05 02:44 - 2018-04-05 02:44 - 002283008 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18041.15530.0_x64__8wekyb3d8bbwe\TrackingDLLUWP.dll
2018-06-08 13:27 - 2018-06-08 13:27 - 014851072 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18041.15530.0_x64__8wekyb3d8bbwe\PhotosApp.Windows.dll
2018-05-30 06:18 - 2018-05-30 06:19 - 004058624 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18041.15530.0_x64__8wekyb3d8bbwe\MediaEngine.dll
2018-06-08 13:27 - 2018-06-08 13:27 - 003266048 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18041.15530.0_x64__8wekyb3d8bbwe\AppCore.Windows.dll
2018-05-30 06:18 - 2018-05-30 06:19 - 001393664 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18041.15530.0_x64__8wekyb3d8bbwe\Microsoft.RichMedia.Ink.Controls.dll
2018-05-30 06:18 - 2018-05-30 06:19 - 004218080 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18041.15530.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll
2018-05-30 06:18 - 2018-05-30 06:19 - 000103424 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18041.15530.0_x64__8wekyb3d8bbwe\BendRealityNode.dll
2018-05-30 06:18 - 2018-05-30 06:19 - 000872448 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18041.15530.0_x64__8wekyb3d8bbwe\RuntimeConfiguration.dll
2018-04-05 02:44 - 2018-04-05 02:44 - 000043008 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18041.15530.0_x64__8wekyb3d8bbwe\Microsoft.Photos.Edit.Services.dll
2018-06-08 13:27 - 2018-06-08 13:27 - 000165376 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18041.15530.0_x64__8wekyb3d8bbwe\SKU.dll
2017-04-18 16:10 - 2017-04-18 16:10 - 000817152 _____ () C:\Program Files\Elgato\GameCapture\CFLite.dll
2017-04-18 16:11 - 2017-04-18 16:11 - 074678272 _____ () C:\Program Files\Elgato\GameCapture\libcef.dll
2017-03-18 16:59 - 2017-03-18 22:30 - 001731072 ____N () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2017-03-18 16:58 - 2017-03-18 16:58 - 000047616 ____N () C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUITelemetry.dll
2017-07-11 01:41 - 2017-07-11 01:41 - 002331136 ____N () C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUIViewModels.dll
2017-07-11 01:41 - 2017-07-11 01:41 - 002836480 ____N () C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUIDataModel.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
AlternateDataStreams: C:\ProgramData\TEMP:27D40D6F [390]
AlternateDataStreams: C:\ProgramData\TEMP:56E2E879 [118]
AlternateDataStreams: C:\ProgramData\TEMP:CB0AACC9 [148]
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
IE trusted site: HKU\S-1-5-21-2206024096-2261513051-2171788053-1000\...\foxtv.com -> hxxps://ftsaccess.foxtv.com
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-13 22:34 - 2017-07-06 05:16 - 000001484 _____ C:\WINDOWS\system32\Drivers\etc\hosts
161.202.84.165 gs001.pso2gs.net #PSO2Proxy Public Server Ship 01
161.202.84.165 gs016.pso2gs.net #PSO2Proxy Public Server Ship 02
161.202.84.165 gs031.pso2gs.net #PSO2Proxy Public Server Ship 03
161.202.84.165 gs046.pso2gs.net #PSO2Proxy Public Server Ship 04
161.202.84.165 gs061.pso2gs.net #PSO2Proxy Public Server Ship 05
161.202.84.165 gs076.pso2gs.net #PSO2Proxy Public Server Ship 06
161.202.84.165 gs091.pso2gs.net #PSO2Proxy Public Server Ship 07
161.202.84.165 gs106.pso2gs.net #PSO2Proxy Public Server Ship 08
161.202.84.165 gs121.pso2gs.net #PSO2Proxy Public Server Ship 09
161.202.84.165 gs136.pso2gs.net #PSO2Proxy Public Server Ship 10
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-2206024096-2261513051-2171788053-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Wr3ckage\Desktop\newvegfinal.jpg
HKU\S-1-5-21-2206024096-2261513051-2171788053-1004\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\web\wallpaper\Windows\img0.jpg
DNS Servers: 208.59.247.45 - 208.59.247.46
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Nostromo Loadout Manager.lnk => C:\Windows\pss\Nostromo Loadout Manager.lnk.CommonStartup
MSCONFIG\startupfolder: C:^Users^Wr3ckage^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^MagicDisc.lnk => C:\Windows\pss\MagicDisc.lnk.Startup
MSCONFIG\startupfolder: C:^Users^Wr3ckage^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Wr3ckage.exe => C:\Windows\pss\Wr3ckage.exe.Startup
MSCONFIG\startupreg: AvgUi => "C:\Program Files (x86)\AVG\Framework\Common\avguirnx.exe" /lps=fmw
MSCONFIG\startupreg: BitTorrent => "C:\Users\Wr3ckage\AppData\Roaming\BitTorrent\BitTorrent.exe" /MINIMIZED
MSCONFIG\startupreg: BlueStacks Agent => C:\Program Files (x86)\BlueStacks\HD-Agent.exe
MSCONFIG\startupreg: BrowserSafeguard => "C:\Program Files (x86)\Browsersafeguard\BrowserSafeguard.exe"
MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
MSCONFIG\startupreg: cpx => "C:\Program Files (x86)\cpx\cpx.exe" -starup
MSCONFIG\startupreg: Discord => C:\Users\Wr3ckage\AppData\Local\Discord\app-0.0.277\Discord.exe
MSCONFIG\startupreg: IAStorIcon => "C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe" "C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" 60
MSCONFIG\startupreg: msrtn32 => "C:\Program Files (x86)\msrtn32\msrtn32.exe" -startup=smartcpx -check=60
MSCONFIG\startupreg: MyComGames => "C:\Users\Wr3ckage\AppData\Local\MyComGames\MyComGames.exe" -autostart
MSCONFIG\startupreg: Nvtmru => "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe"
MSCONFIG\startupreg: Overwolf => C:\Program Files (x86)\Overwolf\Overwolf.exe -silent
MSCONFIG\startupreg: ShadowPlay => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
MSCONFIG\startupreg: Steam => "C:\Program Files (x86)\Steam\Steam.exe" -silent
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
MSCONFIG\startupreg: TrojanScanner => C:\Program Files (x86)\Trojan Remover\Trjscan.exe /boot
MSCONFIG\startupreg: tsiVideo => C:\Windows\SysWOW64\rundll32.exe C:\Users\Wr3ckage\AppData\Local\Temp\mdi064.dll,quardin
MSCONFIG\startupreg: UserCheck => C:\ProgramData\UserCheck.exe
MSCONFIG\startupreg: VirtualCloneDrive => "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
MSCONFIG\startupreg: Winlogon => C:\Users\Wr3ckage\AppData\Roaming\winlogon.exe
HKLM\...\StartupApproved\Run: => "WindowsDefender"
HKLM\...\StartupApproved\Run32: => "Adobe ARM"
HKLM\...\StartupApproved\Run32: => "Dropbox"
HKLM\...\StartupApproved\Run32: => "APSDaemon"
HKU\S-1-5-21-2206024096-2261513051-2171788053-1000\...\StartupApproved\Run: => "BitTorrent"
HKU\S-1-5-21-2206024096-2261513051-2171788053-1000\...\StartupApproved\Run: => "Chromium"
HKU\S-1-5-21-2206024096-2261513051-2171788053-1000\...\StartupApproved\Run: => "Discord"
HKU\S-1-5-21-2206024096-2261513051-2171788053-1000\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-2206024096-2261513051-2171788053-1000\...\StartupApproved\Run: => "uTorrent"
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{E206A2EC-AE47-4943-81BF-8839B44ABD6D}] => (Allow) C:\Users\Wr3ckage\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{544E391F-0661-4463-8F80-5F3B883E377C}] => (Allow) C:\Users\Wr3ckage\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{608F7ED1-FBB7-429D-8750-B3F8DEA73B7D}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe
FirewallRules: [{E47C765C-6FDC-4EF8-AA99-41362CFC4F71}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Project Highrise\Game.exe
FirewallRules: [{1876ECFF-8541-4DBD-8AFB-19097D81871F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Project Highrise\Game.exe
FirewallRules: [{FF510C99-2CB1-41B2-8EA9-394CF74DCD6E}] => (Allow) C:\Program Files (x86)\MediaMall\Surfer.exe
FirewallRules: [{3677F5AA-463C-4884-A349-85D516697DC6}] => (Allow) C:\Program Files (x86)\MediaMall\PlayMark.exe
FirewallRules: [{CDAD1FB1-E628-4934-B3B4-FB8AD6D587DF}] => (Allow) C:\Program Files (x86)\MediaMall\PlayOn.exe
FirewallRules: [{F176C550-43C8-432E-8B09-A76524832AE6}] => (Allow) C:\Program Files (x86)\MediaMall\SettingsManager.exe
FirewallRules: [{93CECC06-64E3-4915-B533-AD65BC96FFBD}] => (Allow) C:\Program Files (x86)\MediaMall\MediaMallServerLauncher.exe
FirewallRules: [{095151F2-4383-43B1-8E86-AEB68A98643A}] => (Allow) C:\Program Files (x86)\MediaMall\MediaMallServer.exe
FirewallRules: [{94428C46-FD11-485A-AF0A-2A344ED45D66}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{A709DD6E-E5AB-4591-8137-1D729A922F65}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{E9124850-004C-4B29-B3A7-D074BE9435E5}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
FirewallRules: [{25CB5D37-C122-4BA8-AE91-D4243B8E1BA1}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [{A909610D-74F4-4857-819B-0985A56ED49F}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [{F744D64B-B0D7-41FB-8BE8-6CF819E95520}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{3E6466AA-A9EF-41D0-9937-EBE1421D89A5}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [UDP Query User{D6D51F59-1CEF-47BD-8F83-B4C50F7DAFFE}C:\program files (x86)\diablo iii\x64\diablo iii64.exe] => (Allow) C:\program files (x86)\diablo iii\x64\diablo iii64.exe
FirewallRules: [TCP Query User{92BDBB9C-7892-4F29-A8A8-0C68B44CE40C}C:\program files (x86)\diablo iii\x64\diablo iii64.exe] => (Allow) C:\program files (x86)\diablo iii\x64\diablo iii64.exe
FirewallRules: [{93233250-AEF5-4266-A744-8640BF0351AE}] => (Allow) C:\Program Files (x86)\FlashIntegro\VideoEditor\Updater.exe
FirewallRules: [{02D7516E-3CA7-44BD-83B9-A85E505472D7}] => (Allow) C:\Program Files (x86)\FlashIntegro\VideoEditor\Updater.exe
FirewallRules: [{69E66EA3-CCBA-4DAF-87F9-3994443A286A}] => (Allow) C:\Program Files (x86)\FlashIntegro\VideoEditor\Activation.exe
FirewallRules: [{801CC622-9815-4EB3-BB3F-594009D0BDB6}] => (Allow) C:\Program Files (x86)\FlashIntegro\VideoEditor\Activation.exe
FirewallRules: [{FC9F100D-74E2-4EA9-97EE-133DB21B2472}] => (Allow) C:\Program Files (x86)\FlashIntegro\VideoEditor\VideoEditor.exe
FirewallRules: [{09294686-B832-476F-91FD-FA09B37971A4}] => (Allow) C:\Program Files (x86)\FlashIntegro\VideoEditor\VideoEditor.exe
FirewallRules: [{A6BD5E16-140C-4F35-8622-37CB9B88F5F1}] => (Allow) LPort=1900
FirewallRules: [{29CB68C6-CBB1-405A-99D2-9BD08006ADC9}] => (Allow) LPort=2869
FirewallRules: [{5945C811-53F7-45FD-9AAB-AFB2C4DCD181}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [UDP Query User{2FC6A050-9F37-4FED-B964-40A9B469B103}C:\users\wr3ckage\appdata\local\mycomgames\mycomgames.exe] => (Allow) C:\users\wr3ckage\appdata\local\mycomgames\mycomgames.exe
FirewallRules: [TCP Query User{81987451-11DC-46DA-9F21-1D69133B471B}C:\users\wr3ckage\appdata\local\mycomgames\mycomgames.exe] => (Allow) C:\users\wr3ckage\appdata\local\mycomgames\mycomgames.exe
FirewallRules: [{73C0FAC1-2D61-4891-9FC8-810042CB0600}] => (Allow) C:\Users\Wr3ckage\AppData\Local\MyComGames\MyComGames.exe
FirewallRules: [{468D7AD5-53C5-4053-9B14-764CE07127B8}] => (Allow) C:\Users\Wr3ckage\AppData\Local\MyComGames\MyComGames.exe
FirewallRules: [{38D02012-249B-4B8F-A949-75D085AB55E2}] => (Allow) C:\Program Files\Logitech Gaming Software\LCore.exe
FirewallRules: [{57686B6D-D79B-4408-B226-3B0205AD057D}] => (Allow) C:\Program Files\Logitech Gaming Software\LCore.exe
FirewallRules: [{AFBB460D-3037-4F1C-9DB1-57CB8D580236}] => (Allow) C:\Program Files (x86)\Rosetta Stone\Rosetta Stone Version 3\support\bin\win\RosettaStoneLtdServices.exe
FirewallRules: [{8A6CA56C-1974-4D20-BA0C-631DC2EE4097}] => (Allow) C:\Program Files (x86)\Rosetta Stone\Rosetta Stone Version 3\support\bin\win\RosettaStoneLtdServices.exe
FirewallRules: [{6143A5D2-7B5F-4936-AEE3-E1FEB35704BF}] => (Allow) C:\Program Files (x86)\Rosetta Stone\Rosetta Stone Version 3\RosettaStoneVersion3.exe
FirewallRules: [{4B0506F3-01B7-4CBC-8DD9-7EEC02CC84DF}] => (Allow) C:\Program Files (x86)\Rosetta Stone\Rosetta Stone Version 3\RosettaStoneVersion3.exe
FirewallRules: [{7E6BAA8C-5DC1-4B0A-90F3-46044189F012}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2753\Agent.exe
FirewallRules: [{AE50D218-4A65-4640-AC11-7951CB521C7C}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2753\Agent.exe
FirewallRules: [{0B2F61CF-8BEF-43B0-BE51-14A0EC005FFE}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2737\Agent.exe
FirewallRules: [{A3FDC6A8-F669-4E01-B5BE-11461622E68C}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2737\Agent.exe
FirewallRules: [{9A273C0E-4276-4BF0-8458-FCC3384FE846}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{E33E2A17-67EB-4F89-AC40-6554914DF53F}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{EE5E8C22-ADBD-46DA-8381-8672BC56B4CE}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{78333F96-3E6A-46A2-A858-1AA2E8CFF5F9}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{1042FB8A-8DFA-4D87-9E19-3928EE8174CE}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{1E75FD1F-580B-4931-83A9-3A11CAC06105}] => (Allow) C:\Program Files\Ventrilo\Ventrilo.exe
FirewallRules: [{362736EE-1791-4AFC-A949-4AE5D8958285}] => (Allow) C:\Program Files\Ventrilo\Ventrilo.exe
FirewallRules: [{B1854FBA-2A0B-41D8-B496-96FBC2A177A7}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{D2D93F62-44FD-46EC-9805-12838C5799A9}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{770D9BCF-483F-4248-8B52-EFED5DB023A8}] => (Allow) C:\Users\Wr3ckage\AppData\Roaming\BitTorrent\BitTorrent.exe
FirewallRules: [{C2597128-FFA5-4C5A-9820-D81898D9E790}] => (Allow) C:\Users\Wr3ckage\AppData\Roaming\BitTorrent\BitTorrent.exe
FirewallRules: [{23C60FE2-6631-434E-B02D-9FD5DE5D06B1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\South Park The Fractured But Whole\SouthPark_TFBW.exe
FirewallRules: [{25E4EACE-5D44-487E-9156-9DB008597F49}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\South Park The Fractured But Whole\SouthPark_TFBW.exe
FirewallRules: [{2E953464-BB92-415D-A0CD-D68DD876421B}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{3693DC32-587F-4B31-8FA7-1219C3A00E61}] => (Allow) C:\Program Files\Opera\49.0.2725.39\opera.exe
FirewallRules: [{48117B84-206C-42DF-8A80-0CCAF0E564ED}] => (Allow) C:\Program Files\Opera\49.0.2725.47\opera.exe
FirewallRules: [{F99718CF-DEE3-499B-B426-B5FA517D9DEC}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
FirewallRules: [TCP Query User{FEA40C4B-B121-46E1-BDB5-BC3AA20C139D}C:\programdata\wargaming.net\gamecenter\wgc.exe] => (Allow) C:\programdata\wargaming.net\gamecenter\wgc.exe
FirewallRules: [UDP Query User{11ED596C-3CAA-412C-973F-398FB8290B8A}C:\programdata\wargaming.net\gamecenter\wgc.exe] => (Allow) C:\programdata\wargaming.net\gamecenter\wgc.exe
FirewallRules: [{212DA6DE-42C0-4EC9-AF8E-75844ECD740E}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe
==================== Restore Points =========================
19-06-2018 20:17:21 Scheduled Checkpoint
27-06-2018 01:30:22 Windows Update
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (06/30/2018 06:47:24 PM) (Source: SideBySide) (EventID: 59) (User: )
Description: Activation context generation failed for "C:\Users\Wr3ckage\Downloads\SFCFix.exe".Error in manifest or policy file "C:\WINDOWS\WinSxS\manifests\x86_policy.8.0.microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.9307_none_5168dae10f4d982d.manifest" on line 0.
Invalid Xml syntax.
Error: (06/30/2018 06:00:08 PM) (Source: SideBySide) (EventID: 59) (User: )
Description: Activation context generation failed for "C:\Users\Wr3ckage\Downloads\SFCFix.exe".Error in manifest or policy file "C:\WINDOWS\WinSxS\manifests\x86_policy.8.0.microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.9307_none_5168dae10f4d982d.manifest" on line 0.
Invalid Xml syntax.
Error: (06/30/2018 06:00:01 PM) (Source: SideBySide) (EventID: 59) (User: )
Description: Activation context generation failed for "C:\Users\Wr3ckage\Downloads\SFCFix.exe".Error in manifest or policy file "C:\WINDOWS\WinSxS\manifests\x86_policy.8.0.microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.9307_none_5168dae10f4d982d.manifest" on line 0.
Invalid Xml syntax.
Error: (06/30/2018 05:59:44 PM) (Source: SideBySide) (EventID: 59) (User: )
Description: Activation context generation failed for "C:\Users\Wr3ckage\Desktop\SFCFix.exe".Error in manifest or policy file "C:\WINDOWS\WinSxS\manifests\x86_policy.8.0.microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.9307_none_5168dae10f4d982d.manifest" on line 0.
Invalid Xml syntax.
Error: (06/30/2018 05:26:45 PM) (Source: SideBySide) (EventID: 59) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\Intel\Intel(R) SSD Toolbox\Intel SSD Toolbox.exe".Error in manifest or policy file "C:\WINDOWS\WinSxS\manifests\x86_policy.9.0.microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9279_none_f4810f46f6546fca.manifest" on line 0.
Invalid Xml syntax.
Error: (06/30/2018 05:26:45 PM) (Source: SideBySide) (EventID: 59) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\Intel\Intel(R) SSD Toolbox\Intel SSD Toolbox.exe".Error in manifest or policy file "C:\WINDOWS\WinSxS\manifests\x86_policy.9.0.microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9279_none_f4810f46f6546fca.manifest" on line 0.
Invalid Xml syntax.
Error: (06/30/2018 05:26:44 PM) (Source: SideBySide) (EventID: 59) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe".Error in manifest or policy file "C:\WINDOWS\WinSxS\manifests\x86_policy.9.0.microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9279_none_f4810f46f6546fca.manifest" on line 0.
Invalid Xml syntax.
Error: (06/30/2018 04:33:41 PM) (Source: SideBySide) (EventID: 59) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe".Error in manifest or policy file "C:\WINDOWS\WinSxS\manifests\x86_policy.9.0.microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9279_none_f4810f46f6546fca.manifest" on line 0.
Invalid Xml syntax.
System errors:
=============
Error: (06/30/2018 03:28:01 PM) (Source: DCOM) (EventID: 10010) (User: Wr3ckage-PC)
Description: The server Microsoft.MicrosoftEdge_40.15063.674.0_neutral__8wekyb3d8bbwe!ContentProcess did not register with DCOM within the required timeout.
Error: (06/30/2018 03:16:19 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID
{C2F03A33-21F5-47FA-B4BB-156362A2F239}
and APPID
{316CDED5-E4AE-4B15-9113-7055D84DCC97}
to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (06/30/2018 03:16:19 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
and APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (06/30/2018 03:16:19 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID
{C2F03A33-21F5-47FA-B4BB-156362A2F239}
and APPID
{316CDED5-E4AE-4B15-9113-7055D84DCC97}
to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (06/30/2018 03:16:19 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
and APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (06/30/2018 03:16:19 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID
{C2F03A33-21F5-47FA-B4BB-156362A2F239}
and APPID
{316CDED5-E4AE-4B15-9113-7055D84DCC97}
to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (06/30/2018 03:16:19 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
and APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (06/30/2018 03:16:19 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID
{C2F03A33-21F5-47FA-B4BB-156362A2F239}
and APPID
{316CDED5-E4AE-4B15-9113-7055D84DCC97}
to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Windows Defender:
===================================
Date: 2018-06-30 15:35:09.296
Description:
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {56EC89F5-33D7-4F8F-9243-44A952D2808E}
Scan Type: Antimalware
Scan Parameters: Full Scan
Date: 2018-06-30 01:03:42.800
Description:
Windows Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?li...n32/Bitrep.B&threatid=2147723143&enterprise=0
Name: Trojan:Win32/Bitrep.B
ID: 2147723143
Severity: Severe
Category: Trojan
Path: file:_C:\Users\Wr3ckage\Downloads\Rosetta Stone JP1-3+App\Rosetta Stone V3.2\Rosetta Stone v3.2 - Patch.exe
Detection Origin: Local machine
Detection Type: FastPath
Detection Source: System
Process Name: Unknown
Signature Version: AV: 1.271.213.0, AS: 1.271.213.0, NIS: 1.271.213.0
Engine Version: AM: 1.1.15000.2, NIS: 1.1.15000.2
Date: 2018-06-30 01:03:24.001
Description:
Windows Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?li...n32/Bitrep.B&threatid=2147723143&enterprise=0
Name: Trojan:Win32/Bitrep.B
ID: 2147723143
Severity: Severe
Category: Trojan
Path: file:_C:\Users\Wr3ckage\Downloads\Rosetta Stone JP1-3+App\Rosetta Stone V3.2\Rosetta Stone v3.2 - Patch.exe
Detection Origin: Local machine
Detection Type: FastPath
Detection Source: System
Process Name: Unknown
Signature Version: AV: 1.271.213.0, AS: 1.271.213.0, NIS: 1.271.213.0
Engine Version: AM: 1.1.15000.2, NIS: 1.1.15000.2
Date: 2018-06-30 00:49:47.827
Description:
Windows Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?li...n32/Bitrep.B&threatid=2147723143&enterprise=0
Name: Trojan:Win32/Bitrep.B
ID: 2147723143
Severity: Severe
Category: Trojan
Path: file:_C:\Users\Wr3ckage\Downloads\Rosetta Stone JP1-3+App\Rosetta Stone V3.2\Rosetta Stone v3.2 - Patch.exe
Detection Origin: Local machine
Detection Type: FastPath
Detection Source: System
Process Name: Unknown
Signature Version: AV: 1.271.213.0, AS: 1.271.213.0, NIS: 1.271.213.0
Engine Version: AM: 1.1.15000.2, NIS: 1.1.15000.2
Date: 2018-06-26 01:39:12.541
Description:
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {C4807C59-8460-4E65-99E0-4A836B31BD1F}
Scan Type: Antimalware
Scan Parameters: Quick Scan
CodeIntegrity:
===================================
Date: 2018-06-26 01:26:50.891
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\ProgramData\Microsoft\Windows Defender\Platform\4.18.1806.18062-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2018-06-26 01:05:11.653
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ProgramData\Microsoft\Windows Defender\Platform\4.18.1806.18062-0\Drivers\WdBoot.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2018-06-26 01:05:11.652
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ProgramData\Microsoft\Windows Defender\Platform\4.18.1806.18062-0\Drivers\WdBoot.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2018-06-19 00:50:14.580
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\ProgramData\Microsoft\Windows Defender\Platform\4.16.17656.18052-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2018-06-16 21:26:45.941
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\ProgramData\Microsoft\Windows Defender\Platform\4.16.17656.18052-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2018-05-30 19:37:08.321
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\ProgramData\Microsoft\Windows Defender\Platform\4.16.17656.18052-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2018-05-30 18:39:44.515
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ProgramData\Microsoft\Windows Defender\Platform\4.16.17656.18052-0\Drivers\WdBoot.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2018-05-30 18:39:44.513
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ProgramData\Microsoft\Windows Defender\Platform\4.16.17656.18052-0\Drivers\WdBoot.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i7-4770K CPU @ 3.50GHz
Percentage of memory in use: 47%
Total physical RAM: 16321.32 MB
Available physical RAM: 8625.3 MB
Total Virtual: 32705.32 MB
Available Virtual: 19990.32 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:222.63 GB) (Free:7.67 GB) NTFS
\\?\Volume{58414428-01dc-11e3-8dc2-806e6f6e6963}\ (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS
\\?\Volume{45cae16c-0000-0000-0000-f0ae37000000}\ () (Fixed) (Total:0.84 GB) (Free:0.34 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 223.6 GB) (Disk ID: 45CAE16C)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=222.6 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=856 MB) - (Type=27)
==================== End of Addition.txt ============================
softwaremaniac instructed me to post these logs here and have a malware specialist take a look cause he saw some trojans in the past that were caught by windows defender.
Thank you ahead of time for you help.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 20.06.2018
Ran by Wr3ckage (administrator) on WR3CKAGE-PC (30-06-2018 18:56:28)
Running from C:\Users\Wr3ckage\Desktop
Loaded Profiles: Wr3ckage & rmarc (Available Profiles: Wr3ckage & rmarc & DefaultAppPool)
Platform: Windows 10 Pro Version 1703 15063.726 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Edge)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.209.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDCountdown.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDClock.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDPOP3.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDRSS.exe
() C:\Program Files\Elgato\SoundCapture\SoundCapture.exe
() C:\Program Files\YoloMouse\YoloMouse.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
() C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18041.15530.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
(Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1806.18062-0\MsMpEng.exe
(Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1806.18062-0\NisSrv.exe
(Microsoft Corporation) C:\Windows\System32\UI0Detect.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Elgato Systems GmbH) C:\Program Files\Elgato\GameCapture\GameCapture.exe
(Microsoft Corporation) C:\Windows\System32\InputMethod\CHT\ChtIME.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Microsoft Corporation) C:\Windows\System32\InputMethod\CHT\ChtIME.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
() C:\Program Files\Elgato\SoundCapture\SoundCapture.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDClock.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDCountdown.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDPOP3.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDRSS.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.209.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(MediaMall Technologies, Inc.) C:\Program Files (x86)\MediaMall\MediaMallServer.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUI.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-18] (Microsoft Corporation)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7156296 2013-03-05] (Realtek Semiconductor)
HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [13318424 2015-03-12] (Logitech Inc.)
HKLM\...\Run: [ShadowPlay] => "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [Elgato Sound Capture] => C:\Program Files\Elgato\SoundCapture\SoundCapture.exe [1234944 2017-04-19] ()
HKLM-x32\...\Run: [LWS] => C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe [204136 2012-09-13] (Logitech Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [3567928 2017-12-04] (Dropbox, Inc.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
HKU\S-1-5-21-2206024096-2261513051-2171788053-1000\...\Run: [BitTorrent] => C:\Users\Wr3ckage\AppData\Roaming\BitTorrent\BitTorrent.exe [2153928 2017-08-19] (BitTorrent Inc.)
HKU\S-1-5-21-2206024096-2261513051-2171788053-1000\...\Run: [Chromium] => c:\users\wr3ckage\appdata\local\chromium\application\chrome.exe [1068544 2016-03-18] (The Chromium Authors)
HKU\S-1-5-21-2206024096-2261513051-2171788053-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [9773272 2017-05-19] (Piriform Ltd)
HKU\S-1-5-21-2206024096-2261513051-2171788053-1000\...\Run: [Discord] => C:\Users\Wr3ckage\AppData\Local\Discord\app-0.0.298\Discord.exe [57477112 2017-08-08] (Discord Inc.)
HKU\S-1-5-21-2206024096-2261513051-2171788053-1000\...\Run: [YoloMouse] => C:\Program Files\YoloMouse\YoloMouse.exe [222208 2017-02-08] ()
HKU\S-1-5-21-2206024096-2261513051-2171788053-1000\...\Run: [uTorrent] => C:\Users\Wr3ckage\AppData\Roaming\uTorrent\uTorrent.exe [1981624 2017-11-28] (BitTorrent Inc.)
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - %SystemRoot%\system32\wpdshserviceobj.dll (Microsoft Corporation)
BootExecute: autocheck autochk /r \??\C:autocheck autochk *
GroupPolicy: Restriction ? <==== ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
CHR HKU\S-1-5-21-2206024096-2261513051-2171788053-1000\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings: [ProxySettingsPerUser] 0 <==== ATTENTION (Restriction - ProxySettings)
Winsock: Catalog5 07 c:\Windows\SysWOW64\wlidnsp.dll [43008 2017-03-18] (Microsoft Corporation)
Winsock: Catalog5 08 c:\Windows\SysWOW64\wlidnsp.dll [43008 2017-03-18] (Microsoft Corporation)
Winsock: Catalog5-x64 07 c:\Windows\System32\wlidnsp.dll [65536 2017-03-18] (Microsoft Corporation)
Winsock: Catalog5-x64 08 c:\Windows\System32\wlidnsp.dll [65536 2017-03-18] (Microsoft Corporation)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 208.59.247.45 208.59.247.46 192.168.1.1
Tcpip\..\Interfaces\{0d37b7da-92f5-4a28-8cfa-834fc3f410d3}: [DhcpNameServer] 198.18.0.1 198.18.0.2
Tcpip\..\Interfaces\{72814d51-9887-445a-a1de-cc798b9d1398}: [DhcpNameServer] 208.59.247.45 208.59.247.46 192.168.1.1
Internet Explorer:
==================
SearchScopes: HKU\S-1-5-21-2206024096-2261513051-2171788053-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://us.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_fs_16_35¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzuyByE0DtDtB0BtB0C0Azy0ByC0Ezz0A0FtN0D0Tzu0StCyBtDyCtN1L2XzutAtFtByEtFyCtFzytN1L1Czu1BtBtN1L1G1B1V1N2Y1L1Qzu2SyDzz0EyB0C0D0FyCtGyB0F0DtAtGzyzztBzztGyB0DyC0DtGtB0A0F0EtCtCyEzyzyyE0F0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0C0EtDzzyEzyyB0AtG0DyD0EzztGyE0EyE0BtG0BtD0C0DtGyE0DtD0A0FzzyDyB0Bzy0Bzz2QtN0A0LzuyE%26cr%3D1500848655%26a%3Dwbf_fs_16_35%26os_ver%3D10.0%26os%3DWindows%2B10%2BPro&p={searchTerms}
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2018-06-29] (Microsoft Corporation)
BHO: No Name -> {3706EE7C-3CAD-445D-8A43-03EBC3B75908} -> No File
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-04-23] (Google Inc.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\ssv.dll [2015-07-28] (Oracle Corporation)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-04-23] (Google Inc.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\jp2ssv.dll [2015-07-28] (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-04-23] (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-04-23] (Google Inc.)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-06-29] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-06-29] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-06-29] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-06-29] (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
FireFox:
========
FF ProfilePath: C:\Users\Wr3ckage\AppData\Roaming\Mozilla\Firefox\Profiles\mpsryc5m.default [2018-06-30]
FF user.js: detected! => C:\Users\Wr3ckage\AppData\Roaming\Mozilla\Firefox\Profiles\mpsryc5m.default\user.js [2014-08-10]
FF Homepage: Mozilla\Firefox\Profiles\mpsryc5m.default -> hxxps://us.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_fs_16_35¶m1=1¶m2=f%3D1%26b%3DFirefox%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzuyByE0DtDtB0BtB0C0Azy0ByC0Ezz0A0FtN0D0Tzu0StCyBtDyCtN1L2XzutAtFtByEtFyCtFzytN1L1Czu1BtBtN1L1G1B1V1N2Y1L1Qzu2SyDzz0EyB0C0D0FyCtGyB0F0DtAtGzyzztBzztGyB0DyC0DtGtB0A0F0EtCtCyEzyzyyE0F0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0C0EtDzzyEzyyB0AtG0DyD0EzztGyE0EyE0BtG0BtD0C0DtGyE0DtD0A0FzzyDyB0Bzy0Bzz2QtN0A0LzuyE%26cr%3D1500848655%26a%3Dwbf_fs_16_35%26os_ver%3D10.0%26os%3DWindows%2B10%2BPro
FF NewTab: Mozilla\Firefox\Profiles\mpsryc5m.default -> about:newtab
FF Extension: (Bluhell Firewall) - C:\Users\Wr3ckage\AppData\Roaming\Mozilla\Firefox\Profiles\mpsryc5m.default\Extensions\{6BB5760D-F97E-421B-AF5B-8457A90C3CED}.xpi [2018-01-13] [Legacy]
FF SearchPlugin: C:\Users\Wr3ckage\AppData\Roaming\Mozilla\Firefox\Profiles\mpsryc5m.default\searchplugins\Search Provided by Yahoo.xml [2016-03-14]
FF SearchPlugin: C:\Users\Wr3ckage\AppData\Roaming\Mozilla\Firefox\Profiles\mpsryc5m.default\searchplugins\yahoo! powered.xml [2016-09-02]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_27_0_0_187.dll [2017-11-14] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_27_0_0_187.dll [2017-11-14] ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2016-10-06] (Google)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.0.72 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-03-12] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-03-12] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.51.2 -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\dtplugin\npDeployJava1.dll [2015-07-28] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.51.2 -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\plugin2\npjp2.dll [2015-07-28] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2018-03-08] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2017-10-27] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2017-10-27] (NVIDIA Corporation)
FF Plugin-x32: @playon.tv/PlayOnToolbar -> C:\Program Files (x86)\MediaMall\toolbar\npVT.dll [2017-04-18] (MediaMall Technologies, Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-15] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-15] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2013-07-30] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2013-05-11] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2206024096-2261513051-2171788053-1000: @my.com/Games -> C:\Users\Wr3ckage\AppData\Local\MyComGames\NPMyComDetector.dll [2016-02-06] (MY.COM B.V.)
FF Plugin HKU\S-1-5-21-2206024096-2261513051-2171788053-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Wr3ckage\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-08-28] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-2206024096-2261513051-2171788053-1000: jpl.nasa.gov/NASAEyes -> C:\Users\Wr3ckage\AppData\Roaming\JPL-NASA-Caltech\NASA's Eyes\npNASAEyes.dll [2014-12-16] (Jet Propulsion Laboratory)
StartMenuInternet: FIREFOX.EXE - firefox.exe
Chrome:
=======
CHR HomePage: Default -> hxxps://us.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_mdaffmarmarie_16_09¶m1=1¶m2=f%3D1%26b%3DChrome%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzuyByE0DtDtB0BtB0C0Azy0ByC0Ezz0A0FtN0D0Tzu0StCyDtByCtN1L2XzutAtFtCzytFtCtFtDtN1L1Czu1BtBtN1L1G1B1V1N2Y1L1Qzu2StCtC0FtAzyyEzztCtGtBtAtC0BtGyEyCzy0FtGyDyEtCzytGyBtAyBtAtDtA0A0ByDtAyEyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0C0EtDzzyEzyyB0AtG0DyD0EzztGyE0EyE0BtG0BtD0C0DtGyE0DtD0A0FzzyDyB0Bzy0Bzz2QtN0A0LzuyE%26cr%3D511454156%26a%3Dwncy_mdaffmarmarie_16_09%26os_ver%3D6.1%26os%3DWindows%2B7%2BUltimate
CHR DefaultSearchURL: Default -> hxxps://us.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_mdaffmarmarie_16_09¶m1=1¶m2=f%3D4%26b%3DChrome%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzuyByE0DtDtB0BtB0C0Azy0ByC0Ezz0A0FtN0D0Tzu0StCyDtByCtN1L2XzutAtFtCzytFtCtFtDtN1L1Czu1BtBtN1L1G1B1V1N2Y1L1Qzu2StCtC0FtAzyyEzztCtGtBtAtC0BtGyEyCzy0FtGyDyEtCzytGyBtAyBtAtDtA0A0ByDtAyEyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0C0EtDzzyEzyyB0AtG0DyD0EzztGyE0EyE0BtG0BtD0C0DtGyE0DtD0A0FzzyDyB0Bzy0Bzz2QtN0A0LzuyE%26cr%3D511454156%26a%3Dwncy_mdaffmarmarie_16_09%26os_ver%3D6.1%26os%3DWindows%2B7%2BUltimate&p={searchTerms}
CHR DefaultSearchKeyword: Default -> search provided by yahoo.com
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?client=chrome&hl={language}&q={searchTerms}
CHR Profile: C:\Users\Wr3ckage\AppData\Local\Google\Chrome\User Data\Default [2018-06-30]
CHR Extension: (Google Docs Offline) - C:\Users\Wr3ckage\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-03-31]
CHR Extension: (AdBlock) - C:\Users\Wr3ckage\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2018-06-16]
CHR Extension: (TwitchAlerts Stream Labels) - C:\Users\Wr3ckage\AppData\Local\Google\Chrome\User Data\Default\Extensions\kgmggmdngboajiakmbpdknfpdelbjbcg [2016-12-07]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Wr3ckage\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-04]
CHR Extension: (Chrome Media Router) - C:\Users\Wr3ckage\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-11-16]
CHR HKLM\...\Chrome\Extension: [ajcmdlkeklfmbjffnlofgfkjcnpfckab] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-2206024096-2261513051-2171788053-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [ajcmdlkeklfmbjffnlofgfkjcnpfckab] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [ajcmdlkeklfmbjffnlofgfkjcnpfckab] - hxxps://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S2 AppApcVerifier; C:\ProgramData\AppApcVerifier\AppVerifierapc.exe [47104 2016-06-30] (AppApcVerifier) [File not signed]
S2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.01.02\atkexComSvc.exe [936728 2013-07-04] ()
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1522184 2017-06-10] ()
S2 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [409304 2014-10-08] (BlueStack Systems, Inc.)
S2 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [388824 2014-10-08] (BlueStack Systems, Inc.)
S2 BstHdUpdaterSvc; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe [782040 2014-10-08] (BlueStack Systems, Inc.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [8765104 2018-06-20] (Microsoft Corporation)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2017-05-03] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2017-05-03] (Dropbox, Inc.)
R2 DbxSvc; C:\WINDOWS\system32\DbxSvc.exe [51016 2017-12-04] (Dropbox, Inc.)
S2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15344 2013-01-31] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [731648 2013-02-13] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [820184 2013-02-13] (Intel(R) Corporation)
S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [177376 2016-08-12] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-03-12] (Intel Corporation)
R2 MediaMall Server; C:\Program Files (x86)\MediaMall\MediaMallServer.exe [8326408 2018-01-09] (MediaMall Technologies, Inc.)
S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [3758336 2015-11-29] (INCA Internet Co., Ltd.)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2078216 2015-10-08] (Electronic Arts)
R2 osrss; C:\WINDOWS\system32\osrss.dll [131288 2018-06-27] (Microsoft Corporation)
S3 PAExec; C:\WINDOWS\PAExec.exe [189112 2017-02-15] (Power Admin LLC)
S3 PrintNotify; c:\Windows\System32\spool\drivers\x64\{2C4EE6E4-1857-4293-96A1-60E4D8EC3A69}\PrintConfig.dll [2899968 2017-03-18] (Microsoft Corporation)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [3913064 2017-03-18] (Microsoft Corporation)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1806.18062-0\NisSrv.exe [3925648 2018-06-26] (Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1806.18062-0\MsMpEng.exe [100080 2018-06-26] (Microsoft Corporation)
R2 NvContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe" -s NvContainerLocalSystem -f "C:\ProgramData\NVIDIA\NvContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\LocalSystem" -r -p 30000
S3 NvContainerNetworkService; "C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe" -s NvContainerNetworkService -f "C:\ProgramData\NVIDIA\NvContainerNetworkService.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\NetworkService" -r -p 30000
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
R2 NvTelemetryContainer; "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\plugin"
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 asahci64; C:\WINDOWS\System32\drivers\asahci64.sys [47512 2013-01-10] (Asmedia Technology)
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2013-07-04] ()
R3 bcgame; C:\WINDOWS\system32\drivers\bcgame.sys [35328 2007-08-14] (Belkin Corporation)
S2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [122072 2014-10-08] (BlueStack Systems)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [130688 2016-07-22] (Samsung Electronics Co., Ltd.)
S3 ElgatoGC658Y; C:\WINDOWS\System32\Drivers\ElgatoGC658.sys [50288 2012-11-12] (UB658)
R3 ElgatoVAD; C:\WINDOWS\system32\DRIVERS\ElgatoVAD.sys [38152 2016-08-16] (Elgato Systems GmbH)
R2 ISOMount; C:\Program Files (x86)\Free ISO Mount\FIMx64.sys [33896 2014-08-10] ()
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [192216 2018-06-30] (Malwarebytes)
R1 MpKsl6e22bb12; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C11889C0-CB94-4601-BCA7-336BEE2F8551}\MpKsl6e22bb12.sys [58120 2018-06-30] (Microsoft Corporation)
R3 msvad_simple; C:\WINDOWS\system32\drivers\povrtdev.sys [28528 2015-10-29] (MediaMall Technologies, Inc.)
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nv_ref_pubwu.inf_amd64_2e7fa54192fe16d0\nvlddmkm.sys [16936048 2017-11-09] (NVIDIA Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30144 2017-03-27] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [47552 2017-03-27] (NVIDIA Corporation)
R3 nvvhci; C:\WINDOWS\System32\drivers\nvvhci.sys [57792 2017-03-27] (NVIDIA Corporation)
S3 SDFRd; C:\WINDOWS\System32\drivers\SDFRd.sys [31128 2017-03-18] ()
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [164992 2016-07-22] (Samsung Electronics Co., Ltd.)
S3 taphss6; C:\WINDOWS\System32\DRIVERS\taphss6.sys [42184 2014-01-14] (Anchorfree Inc.)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [46592 2018-06-26] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [340008 2018-06-26] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [59944 2018-06-26] (Microsoft Corporation)
S3 WinRing0_1_2_0; C:\Program Files (x86)\EVGA\Precision XOC\WinRing0\WinRing0x64.sys [14536 2015-10-20] (OpenLibSys.org)
R3 XSplit_Dummy; C:\WINDOWS\system32\drivers\xspltspk.sys [26200 2015-05-26] (SplitmediaLabs Limited)
U3 idsvc; no ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-06-30 18:56 - 2018-06-30 18:56 - 000028486 _____ C:\Users\Wr3ckage\Desktop\FRST.txt
2018-06-30 18:55 - 2018-06-30 18:55 - 002412544 _____ (Farbar) C:\Users\Wr3ckage\Desktop\FRST64.exe
2018-06-30 18:47 - 2018-06-30 18:47 - 007765399 _____ C:\Users\Wr3ckage\Desktop\gsmartcontrol-1.1.1-win32.exe
2018-06-30 18:35 - 2018-06-30 18:35 - 001371677 _____ C:\Users\Wr3ckage\Desktop\Fixlog.txt
2018-06-30 18:32 - 2018-06-30 18:56 - 000000000 ____D C:\FRST
2018-06-30 18:16 - 2018-06-30 18:16 - 011262890 _____ C:\Users\Wr3ckage\Desktop\cbs.txt
2018-06-30 18:16 - 2018-06-30 18:16 - 000712022 _____ C:\Users\Wr3ckage\Desktop\cbs (3).zip
2018-06-30 18:16 - 2018-06-30 18:16 - 000712022 _____ C:\Users\Wr3ckage\Desktop\cbs (2).zip
2018-06-30 18:02 - 2018-06-30 18:02 - 006430316 _____ C:\Users\Wr3ckage\Downloads\CBS.zip
2018-06-30 18:01 - 2018-06-30 18:01 - 006430316 _____ C:\Users\Wr3ckage\Desktop\CBS.zip
2018-06-30 18:01 - 2018-06-30 18:01 - 000000000 ____D C:\Users\Wr3ckage\Desktop\CBS
2018-06-30 17:59 - 2018-06-30 17:59 - 002884096 _____ (niemiro) C:\Users\Wr3ckage\Downloads\SFCFix.exe
2018-06-30 15:20 - 2018-06-30 15:20 - 042400128 _____ (EaseUS ) C:\Users\Wr3ckage\Downloads\drw_setup.exe
2018-06-30 04:54 - 2018-06-30 04:54 - 000286158 _____ C:\Users\Wr3ckage\Desktop\SFCFix.zip
2018-06-30 04:52 - 2018-06-30 04:52 - 002884096 _____ (niemiro) C:\Users\Wr3ckage\Desktop\SFCFix.exe
2018-06-30 04:11 - 2018-06-30 04:11 - 000195346 _____ C:\Users\Wr3ckage\Downloads\wu170509.diagcab
2018-06-30 03:02 - 2018-06-30 03:02 - 000000000 ____D C:\Users\rmarc\AppData\Local\NVIDIA Corporation
2018-06-30 03:02 - 2018-06-30 03:02 - 000000000 ____D C:\Users\rmarc\AppData\Local\Comms
2018-06-30 03:01 - 2018-06-30 03:01 - 001573568 _____ C:\Users\rmarc\Downloads\SteamSetup.exe
2018-06-30 03:00 - 2018-06-30 04:05 - 000000000 ____D C:\Users\rmarc\AppData\Local\Publishers
2018-06-30 03:00 - 2018-06-30 04:05 - 000000000 ____D C:\Users\rmarc\AppData\Local\Packages
2018-06-30 03:00 - 2018-06-30 03:00 - 000002336 _____ C:\Users\rmarc\Desktop\Google Chrome.lnk
2018-06-30 03:00 - 2018-06-30 03:00 - 000000258 __RSH C:\Users\rmarc\ntuser.pol
2018-06-30 03:00 - 2018-06-30 03:00 - 000000020 ___SH C:\Users\rmarc\ntuser.ini
2018-06-30 03:00 - 2018-06-30 03:00 - 000000000 ____D C:\Users\rmarc\AppData\Roaming\Elgato
2018-06-30 03:00 - 2018-06-30 03:00 - 000000000 ____D C:\Users\rmarc\AppData\Roaming\Adobe
2018-06-30 03:00 - 2018-06-30 03:00 - 000000000 ____D C:\Users\rmarc\AppData\Local\VirtualStore
2018-06-30 03:00 - 2018-06-30 03:00 - 000000000 ____D C:\Users\rmarc\AppData\Local\TileDataLayer
2018-06-30 03:00 - 2018-06-30 03:00 - 000000000 ____D C:\Users\rmarc\AppData\Local\NVIDIA
2018-06-30 03:00 - 2018-06-30 03:00 - 000000000 ____D C:\Users\rmarc\AppData\Local\Logitech
2018-06-30 03:00 - 2018-06-30 03:00 - 000000000 ____D C:\Users\rmarc\AppData\Local\IsolatedStorage
2018-06-30 03:00 - 2018-06-30 03:00 - 000000000 ____D C:\Users\rmarc\AppData\Local\Google
2018-06-30 03:00 - 2018-06-30 03:00 - 000000000 ____D C:\Users\rmarc\AppData\Local\DBG
2018-06-30 03:00 - 2018-06-30 03:00 - 000000000 ____D C:\Users\rmarc\AppData\Local\ConnectedDevicesPlatform
2018-06-30 03:00 - 2018-06-30 03:00 - 000000000 ____D C:\Users\rmarc
2018-06-30 03:00 - 2016-10-19 21:15 - 000000000 ____D C:\Users\rmarc\AppData\Roaming\Media Center Programs
2018-06-30 03:00 - 2016-10-19 21:15 - 000000000 ____D C:\Users\rmarc\AppData\Roaming\Macromedia
2018-06-30 02:43 - 2018-06-30 02:43 - 037993920 _____ (EaseUS ) C:\Users\Wr3ckage\Downloads\epm.exe
2018-06-30 02:16 - 2018-06-30 02:21 - 000824139 _____ C:\Users\Wr3ckage\Desktop\regdll.bat
2018-06-30 02:15 - 2018-06-30 02:15 - 002301216 _____ C:\regdll.bat
2018-06-30 00:30 - 2018-06-30 00:31 - 131354336 _____ (Microsoft Corporation) C:\Users\Wr3ckage\Downloads\msert (1).exe
2018-06-29 13:38 - 2018-06-29 13:38 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools
2018-06-29 09:45 - 2018-06-29 09:45 - 000918104 _____ C:\Users\Wr3ckage\Downloads\628925049244_Mar_2018.pdf
2018-06-29 09:44 - 2018-06-29 09:44 - 000918421 _____ C:\Users\Wr3ckage\Downloads\628925049244_May_2018.pdf
2018-06-29 09:44 - 2018-06-29 09:44 - 000918421 _____ C:\Users\Wr3ckage\Downloads\628925049244_May_2018 (1).pdf
2018-06-29 09:44 - 2018-06-29 09:44 - 000918158 _____ C:\Users\Wr3ckage\Downloads\628925049244_Apr_2018.pdf
2018-06-27 04:17 - 2018-06-27 04:20 - 000000000 ___HD C:\$WINDOWS.~BT
2018-06-27 01:30 - 2018-06-27 01:30 - 000000000 ____D C:\WINDOWS\UpdateAssistant
2018-06-22 23:03 - 2018-06-22 23:03 - 000135252 _____ C:\Users\Wr3ckage\Downloads\SamanthaDym-MarcianoResume.pdf
2018-06-06 16:37 - 2018-06-06 16:37 - 000010478 _____ C:\Users\Wr3ckage\Downloads\test.odt
2018-06-06 16:36 - 2018-06-06 16:36 - 000355200 _____ C:\Users\Wr3ckage\Downloads\test.pdf
2018-06-06 16:22 - 2018-06-06 16:22 - 000078569 _____ C:\Users\Wr3ckage\Desktop\RichardMarcianoResume.PDF.pdf
2018-06-06 16:19 - 2018-06-06 16:19 - 000006664 _____ C:\Users\Wr3ckage\Desktop\test2.odt
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-06-30 18:10 - 2017-08-24 16:28 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2018-06-30 17:23 - 2017-08-24 16:34 - 000004166 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{3FDA6D8E-70CD-417D-A75A-C73BEBB6E755}
2018-06-30 15:28 - 2017-03-18 17:01 - 000000000 ____D C:\WINDOWS\INF
2018-06-30 11:29 - 2017-03-18 17:03 - 000000000 ____D C:\WINDOWS\AppReadiness
2018-06-30 04:28 - 2017-03-18 17:03 - 000000000 ____D C:\WINDOWS\system32\NDF
2018-06-30 04:23 - 2015-10-27 03:11 - 000192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2018-06-30 04:13 - 2017-05-13 01:26 - 000000000 ____D C:\ProgramData\MediaMall
2018-06-30 04:05 - 2016-07-19 16:07 - 000000000 ____D C:\Users\Wr3ckage\AppData\Local\ElevatedDiagnostics
2018-06-30 04:01 - 2017-03-18 17:03 - 000000000 ___HD C:\Program Files\WindowsApps
2018-06-30 03:54 - 2017-04-16 00:46 - 000000000 ____D C:\Users\Wr3ckage\AppData\Local\YoloMouse
2018-06-30 03:16 - 2017-03-18 17:03 - 000000000 ___RD C:\WINDOWS\PrintDialog
2018-06-30 03:16 - 2017-03-18 17:03 - 000000000 ___RD C:\WINDOWS\MiracastView
2018-06-30 03:02 - 2017-08-24 16:29 - 000000000 ____D C:\ProgramData\NVIDIA
2018-06-30 03:00 - 2016-04-27 02:42 - 000000000 __RHD C:\Users\Public\AccountPictures
2018-06-30 02:27 - 2017-08-24 16:29 - 003296422 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI
2018-06-30 02:25 - 2017-08-24 16:29 - 003295974 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2018-06-30 02:24 - 2017-08-24 16:29 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2018-06-29 13:38 - 2017-03-18 17:03 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2018-06-29 13:38 - 2016-11-03 00:59 - 000002493 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk
2018-06-29 13:38 - 2016-11-03 00:59 - 000002492 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk
2018-06-29 13:38 - 2016-11-03 00:59 - 000002456 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access.lnk
2018-06-29 13:38 - 2016-11-03 00:59 - 000002455 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk
2018-06-29 13:38 - 2016-11-03 00:59 - 000002449 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook.lnk
2018-06-29 13:38 - 2016-11-03 00:59 - 000002443 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher.lnk
2018-06-29 13:38 - 2016-11-03 00:59 - 000002435 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk
2018-06-29 13:38 - 2014-02-12 00:14 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2018-06-27 12:10 - 2018-02-14 13:29 - 000131288 _____ (Microsoft Corporation) C:\WINDOWS\system32\osrss.dll
2018-06-27 04:20 - 2018-03-09 06:08 - 000000000 ____D C:\WINDOWS\Panther
2018-06-27 04:20 - 2017-08-24 16:35 - 000001908 _____ C:\WINDOWS\diagwrn.xml
2018-06-27 04:20 - 2017-08-24 16:35 - 000001908 _____ C:\WINDOWS\diagerr.xml
2018-06-27 04:20 - 2016-07-29 20:38 - 000000000 ___HD C:\$GetCurrent
2018-06-27 04:17 - 2018-03-09 06:06 - 000000036 _____ C:\WINDOWS\progress.ini
2018-06-27 04:15 - 2017-08-24 16:36 - 000000258 __RSH C:\Users\Wr3ckage\ntuser.pol
2018-06-27 04:15 - 2017-08-24 16:30 - 000000000 ____D C:\Users\Wr3ckage
2018-06-27 04:15 - 2016-07-29 20:38 - 000000000 ____D C:\Windows10Upgrade
2018-06-27 04:15 - 2016-03-06 04:47 - 000000344 __RSH C:\ProgramData\ntuser.pol
2018-06-26 01:05 - 2018-02-21 16:03 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2018-06-19 00:39 - 2017-08-24 16:34 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2018-06-19 00:39 - 2017-08-24 16:28 - 000391736 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2018-06-16 21:19 - 2017-05-24 14:48 - 000000000 ____D C:\Program Files\Opera
2018-06-12 17:51 - 2013-08-11 21:03 - 000000000 ____D C:\WINDOWS\system32\MRT
2018-06-12 17:50 - 2017-10-11 05:09 - 133315992 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT-KB890830.exe
2018-06-12 17:50 - 2013-08-11 18:53 - 133315992 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
==================== Files in the root of some directories =======
2015-06-12 11:43 - 2015-06-15 04:33 - 004427564 _____ () C:\ProgramData\4j4BNPi59zb3hp1JI2fi3sH4ty68b.exe
2015-06-11 13:15 - 2015-06-11 13:15 - 000549820 _____ () C:\ProgramData\rmA8qT4D.exe
2015-09-24 23:11 - 2015-09-24 23:11 - 000000000 _____ () C:\Users\Wr3ckage\AppData\Roaming\REN_winlogon.exe.vir
2014-06-01 18:47 - 2015-09-24 23:07 - 000266752 _____ (BabaTools.com | Next Generation Tools. (3132333)) C:\Users\Wr3ckage\AppData\Roaming\Twitch God 2014 (VIP Edition) v7.exe
2016-03-06 05:48 - 2016-09-04 22:03 - 000000195 _____ () C:\Users\Wr3ckage\AppData\Roaming\WB.CFG
2015-09-24 23:07 - 2015-09-24 23:11 - 000000000 _____ () C:\Users\Wr3ckage\AppData\Roaming\winlogon.exe.vir
2014-12-28 21:50 - 2014-12-28 21:50 - 000000064 _____ () C:\Users\Wr3ckage\AppData\Local\dc2edefb345698374a259f7e89115294
2017-02-15 18:09 - 2017-02-15 18:11 - 001307648 _____ () C:\Users\Wr3ckage\AppData\Local\file__0.localstorage
2017-06-08 05:17 - 2017-06-08 05:17 - 000019428 _____ () C:\Users\Wr3ckage\AppData\Local\recently-used.xbel
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2018-06-26 17:02
==================== End of FRST.txt ============================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 20.06.2018
Ran by Wr3ckage (30-06-2018 18:56:57)
Running from C:\Users\Wr3ckage\Desktop
Windows 10 Pro Version 1703 15063.726 (X64) (2017-08-24 20:36:50)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-2206024096-2261513051-2171788053-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-2206024096-2261513051-2171788053-503 - Limited - Disabled)
Guest (S-1-5-21-2206024096-2261513051-2171788053-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2206024096-2261513051-2171788053-1002 - Limited - Enabled)
rmarc (S-1-5-21-2206024096-2261513051-2171788053-1004 - Administrator - Enabled) => C:\Users\rmarc
Wr3ckage (S-1-5-21-2206024096-2261513051-2171788053-1000 - Administrator - Enabled) => C:\Users\Wr3ckage
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
µTorrent (HKU\S-1-5-21-2206024096-2261513051-2171788053-1000\...\uTorrent) (Version: 3.5.0.44294 - BitTorrent Inc.)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 19.0.0.213 - Adobe Systems Incorporated)
Adobe Flash Player 27 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 27.0.0.187 - Adobe Systems Incorporated)
Adobe Flash Player 27 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 27.0.0.187 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.03) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.03 - Adobe Systems Incorporated)
Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Ascella Fullscreen Timer (HKLM-x32\...\Ascella Fullscreen Timer_is1) (Version: 1.4.2.0 - AAR Innovations)
Asmedia ASM106x SATA Host Controller Driver (HKLM-x32\...\{61942EF5-2CD8-47D4-869C-2E9A8BB085F1}) (Version: 1.3.4.001 - Asmedia Technology)
ASUS Product Register Program (HKLM-x32\...\{C87D79F6-F813-4812-B7A9-CCCAAB8B1188}) (Version: 1.0.020 - ASUSTek Computer Inc.)
Audacity 2.1.0 (HKLM-x32\...\Audacity_is1) (Version: 2.1.0 - Audacity Team)
AVG 2016 (HKLM\...\{C95CF442-7229-4025-A4F0-E970BF801432}) (Version: 16.0.4450 - AVG Technologies) Hidden
Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment)
BitTorrent (HKU\S-1-5-21-2206024096-2261513051-2171788053-1000\...\BitTorrent) (Version: 7.10.0.43917 - BitTorrent Inc.)
Blender (HKLM\...\{437221A8-91D1-42A0-9E04-0AD64B502374}) (Version: 2.78.1 - Blender Foundation)
BlueStacks App Player (HKLM-x32\...\BlueStacks App Player) (Version: 0.9.4.4079 - BlueStack Systems, Inc.)
BlueStacks Notification Center (HKLM-x32\...\{8DCCC556-265B-478A-8B32-C12DA988BA74}) (Version: 0.9.4.4079 - BlueStack Systems, Inc.)
CameraHelperMsi (HKLM-x32\...\{15634701-BACE-4449-8B25-1567DA8C9FD3}) (Version: 13.51.815.0 - Logitech) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 5.30 - Piriform)
CMUD 3.34 (HKLM-x32\...\CMUD) (Version: 3.34 - Zugg Software)
Combined Community Codec Pack 64bit 2015-10-18 (HKLM\...\Combined Community Codec Pack 64bit_is1) (Version: 2015.10.19.0 - CCCP Project)
Compatibility Pack for the 2007 Office system (HKLM-x32\...\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Core Temp 1.0 RC5 (HKLM\...\{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1) (Version: 1.0 - Alcpu)
CPUID CPU-Z 1.65.1 (HKLM\...\CPUID CPU-Z_is1) (Version: - ) <==== ATTENTION
D3DX10 (HKLM-x32\...\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden
Diablo III (HKLM-x32\...\Diablo III) (Version: - Blizzard Entertainment)
Discord (HKU\S-1-5-21-2206024096-2261513051-2171788053-1000\...\Discord) (Version: 0.0.298 - Discord Inc.)
Dropbox (HKLM-x32\...\Dropbox) (Version: 40.4.46 - Dropbox, Inc.)
Dropbox Update Helper (HKLM-x32\...\{099218A5-A723-43DC-8DB5-6173656A1E94}) (Version: 1.3.65.1 - Dropbox, Inc.) Hidden
Elgato Game Capture HD (HKLM\...\{21F4E9A1-CB52-49EC-997F-4C7F29306252}) (Version: 3.50.125.2125 - Elgato Systems GmbH)
Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
erLT (HKLM-x32\...\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}) (Version: 1.20.138.34 - Logitech, Inc.) Hidden
EVGA OC Scanner X 3.6.1.2 (64-bit) (HKLM\...\{CC520CF6-B02E-49AA-8192-C1DDC159E0AA}}_is1) (Version: - EVGA)
EVGA Precision XOC (HKLM-x32\...\{D705C0CA-D900-45AB-85A7-AD651F7055A6}) (Version: 6.0.9 - EVGA Corporation)
Fox Searchlight Digital Screeners (HKU\S-1-5-21-2206024096-2261513051-2171788053-1000\...\209253121.IIS Windows Server) (Version: - IIS Windows Server)
Free ISO Mount (HKLM-x32\...\FreeISOMount) (Version: 1.0 - Media Freeware)
Game Capture HD v1.0.0.1 (HKLM-x32\...\Software_Elgato_Game Capture HD) (Version: 1.0.0.1 - Elgato Systems)
Game Capture HD60 Pro v1.1.0.149 (HKLM-x32\...\Software_Elgato_Game Capture HD60 Pro) (Version: 1.1.0.149 - Elgato Systems)
Game Capture HD60 S v1.1.0.160 (HKLM-x32\...\Software_Elgato_Game Capture HD60 S) (Version: 1.1.0.160 - Elgato Systems)
Game Capture HD60 v2.1.1.4 (HKLM-x32\...\Software_Elgato_Game Capture HD60) (Version: 2.1.1.4 - Elgato Systems)
GIMP 2.8.20 (HKLM\...\GIMP-2_is1) (Version: 2.8.20 - The GIMP Team)
GoldWave v6.21 (HKLM\...\GoldWave v6.21) (Version: 6.21 - GoldWave Inc.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 62.0.3202.94 - Google Inc.)
Google Earth Plug-in (HKLM-x32\...\{57BB4801-61C8-4E74-9672-2160728A461E}) (Version: 7.1.5.1557 - Google)
Google Earth Pro (HKLM-x32\...\{ECF2E224-42F5-4E50-B58E-94CA70E85697}) (Version: 7.3.0.3832 - Google)
Google Toolbar for Internet Explorer (HKLM-x32\...\{18455581-E099-4BA8-BC6B-F34B2F06600C}) (Version: 1.0.0 - Google Inc.) Hidden
Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.8231.2252 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.7 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden
HandBrake 0.10.5 (HKLM-x32\...\HandBrake) (Version: 0.10.5 - )
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.0.0.1323 - Intel Corporation)
Intel(R) Network Connections 18.1.59.0 (HKLM\...\PROSetDX) (Version: 18.1.59.0 - Intel)
Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.0.0.1083 - Intel Corporation)
Intel(R) Update Manager (HKLM-x32\...\{7224B7CE-196C-4E2A-A1AE-1D7BF259FD36}) (Version: 3.4.1942 - Intel Corporation)
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 2.0.0.100 - Intel Corporation)
Intel® SSD Toolbox (HKLM-x32\...\{06D085C8-1F00-11B2-96A7-8f0CE39193ED}) (Version: 3.2.0.400 - Intel Corporation)
IPVanish (HKLM\...\{37C6D801-BF83-4EA4-9859-109E92625352}) (Version: 3.1.0.0 - IPVanish) Hidden
IPVanish (HKLM-x32\...\IPVanish 3.1.0.0) (Version: 3.1.0.0 - IPVanish)
Java 8 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218051F0}) (Version: 8.0.510 - Oracle Corporation)
Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
Logitech Gaming Software 8.58 (HKLM\...\Logitech Gaming Software) (Version: 8.58.183 - Logitech Inc.)
Logitech Webcam Software (HKLM-x32\...\{D40EB009-0499-459c-A8AF-C9C110766215}) (Version: 2.51 - Logitech Inc.)
Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Office 365 - en-us (HKLM\...\O365HomePremRetail - en-us) (Version: 16.0.10228.20080 - Microsoft Corporation)
Microsoft Office Word Viewer 2003 (HKLM-x32\...\{90850409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-2206024096-2261513051-2171788053-1000\...\OneDriveSetup.exe) (Version: 17.3.7076.1026 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Xbox One Controller for Windows (HKLM\...\{DC2CB48C-FD96-48EB-A36A-7D995BB587EB}) (Version: 1.0.2 - Microsoft Corporation)
Movie Maker (HKLM-x32\...\{38F03569-A636-4CF3-BDDE-032C8C251304}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Movie Maker (HKLM-x32\...\{DD67BE4B-7E62-4215-AFA3-F123A800A389}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 56.0.0.6478 - Mozilla)
MSI Afterburner 2.3.1 (HKLM-x32\...\Afterburner) (Version: 2.3.1 - MSI Co., LTD)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
My.com Game Center (HKU\S-1-5-21-2206024096-2261513051-2171788053-1000\...\MyComGames) (Version: 3.170 - My.com B.V.)
NCSOFT Game Launcher (HKLM-x32\...\NCLauncher_NCWest) (Version: - NCSOFT)
Nostromo (HKLM-x32\...\{548C7B77-8B04-427E-ACD0-D0E6E6E59BCF}) (Version: 3.2.4 - Belkin International)
NVIDIA 3D Vision Driver 388.13 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 388.13 - NVIDIA Corporation)
NVIDIA GeForce Experience 3.5.0.70 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.5.0.70 - NVIDIA Corporation)
NVIDIA Graphics Driver 388.13 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 388.13 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.35.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.35.1 - NVIDIA Corporation)
NvNodejs (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvNodejs) (Version: 3.5.0.70 - NVIDIA Corporation) Hidden
NvTelemetry (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvTelemetry) (Version: 2.4.5.0 - NVIDIA Corporation) Hidden
NvvHci (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvvHci) (Version: 2.02.0.5 - NVIDIA Corporation) Hidden
OBS Studio (HKLM-x32\...\OBS Studio) (Version: 19.0.2 - OBS Project)
Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.10228.20080 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.10228.20080 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.10228.20080 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0409-0000-0000000FF1CE}) (Version: 16.0.10228.20080 - Microsoft Corporation) Hidden
OpenAL (HKLM-x32\...\OpenAL) (Version: - )
Opera Stable 49.0.2725.47 (HKLM-x32\...\Opera 49.0.2725.47) (Version: 49.0.2725.47 - Opera Software)
Origin (HKLM-x32\...\Origin) (Version: 9.7.2.53208 - Electronic Arts, Inc.)
PlayOn (HKLM-x32\...\{7D147000-343B-4202-88BD-7715A4EE93A7}) (Version: 4.3.9 - MediaMall Technologies, Inc.) Hidden
PlayOn (HKLM-x32\...\{9eaa2820-362d-46bd-a7ab-a9244ccd41db}) (Version: 4.3.9.18619 - MediaMall Technologies, Inc.)
PlayOn Dependencies (HKLM-x32\...\{0E100B2E-D56C-4BFB-9FD6-894FDEDC10E6}) (Version: 1.0.0.0 - MediaMall Technologies, Inc.) Hidden
QuickTime 7 (HKLM-x32\...\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}) (Version: 7.79.80.95 - Apple Inc.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6853 - Realtek Semiconductor Corp.)
RivaTuner Statistics Server 5.2.0 (HKLM-x32\...\RTSS) (Version: 5.2.0 - Unwinder)
Rosetta Stone Version 3 (HKLM-x32\...\{80F7CA44-F3A5-4853-8BA6-DDF57CD4F078}) (Version: 3.4.7.0 - Rosetta Stone Ltd.)
SHIELD Streaming (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.NvStreamSrv) (Version: 7.1.0360 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShieldWirelessController) (Version: 3.5.0.70 - NVIDIA Corporation) Hidden
Skypeâ„¢ 7.6 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.6.105 - Skype Technologies S.A.)
SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version: - )
SpeedTest (HKLM-x32\...\{E27EA56C-7123-42AA-950C-3F2A984A0B30}_is1) (Version: - )
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
System Requirements Lab for Intel (HKLM-x32\...\{53C63F43-B827-42D9-8886-4698D91EA33B}) (Version: 4.5.15.0 - Husdawg, LLC)
TeamSpeak 3 Client (HKLM-x32\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH)
TechPowerUp GPU-Z (HKLM-x32\...\TechPowerUp GPU-Z) (Version: - TechPowerUp)
Unigine Valley Benchmark version 1.0 (HKLM-x32\...\Unigine Valley Benchmark_is1) (Version: 1.0 - Unigine Corp.)
Unity Web Player (HKU\S-1-5-21-2206024096-2261513051-2171788053-1000\...\UnityWebPlayer) (Version: 5.2.0f3 - Unity Technologies ApS)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{5009B7EE-8A15-4A23-B404-15E31D02DA67}) (Version: 2.43.0.0 - Microsoft Corporation)
UpdateAssistant (HKLM\...\{A7B60FC9-A750-43C7-B7EC-892CD09147C7}) (Version: 1.18.0.0 - Microsoft Corporation) Hidden
Uplay (HKLM-x32\...\Uplay) (Version: 37.0 - Ubisoft)
VC_CRT_x64 (HKLM\...\{54F2237F-018C-483B-8884-9FC0D88840C3}) (Version: 1.02.0000 - Intel Corporation) Hidden
Ventrilo Client for Windows x64 (HKLM\...\{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}) (Version: 3.0.8.0 - Flagship Industries, Inc.)
VideoPad Video Editor (HKLM-x32\...\VideoPad) (Version: 5.03 - NCH Software)
Virtual Audio Cable 4.14 (HKLM\...\Virtual Audio Cable 4.14) (Version: - )
VirtualCloneDrive (HKLM-x32\...\VirtualCloneDrive) (Version: 5.4.7.0 - Elaborate Bytes)
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
VLC media player 2.0.8 (HKLM-x32\...\VLC media player) (Version: 2.0.8 - VideoLAN)
VSDC Free Video Editor version 5.5.0.601 (HKLM-x32\...\VSDC Free Video Editor_is1) (Version: 5.5.0.601 - Flash-Integro LLC)
Vulkan Run Time Libraries 1.0.61.0 (HKLM\...\VulkanRT1.0.61.0) (Version: 1.0.61.0 - LunarG, Inc.) Hidden
Wargaming.net Game Center (HKU\S-1-5-21-2206024096-2261513051-2171788053-1000\...\Wargaming.net Game Center) (Version: 17.9.0.6629 - Wargaming.net)
Windows 10 Update and Privacy Settings (HKLM\...\{4DFCD818-036A-4229-A67D-CF17DC461D92}) (Version: 1.0.14.0 - Microsoft Corporation)
Windows 10 Update Assistant (HKLM-x32\...\{D5C69738-B486-402E-85AC-2456D98A64E4}) (Version: 1.4.9200.22452 - Microsoft Corporation)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
Windows Setup Remediations (x64) (KB4023057) (HKLM\...\{5534e02f-0f5d-40dd-ba92-bea38d22384d}.sdb) (Version: - )
WinRAR 5.01 beta 1 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.01.1 - win.rar GmbH)
World of Warships (HKU\S-1-5-21-2206024096-2261513051-2171788053-1000\...\WOWS.NA.PRODUCTION) (Version: - Wargaming.net)
XSplit Broadcaster (HKLM-x32\...\{6459F338-FE52-4034-BCA7-74772DA0F24D}) (Version: 1.3.1403.1202 - SplitMediaLabs)
XSplit Gamecaster (HKLM-x32\...\{02297800-E109-4A50-8F82-AACD0844A051}) (Version: 2.5.1507.3024 - SplitmediaLabs)
YoloMouse (HKLM\...\{AD023FBA-862C-4342-9E9C-FBB9870412B5}) (Version: 0.8.2.0 - HaPpY)
zMUD 7.21.0.0 (HKLM-x32\...\zMUD) (Version: 7.21.0.0 - Zugg Software)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
HKU\S-1-5-21-2206024096-2261513051-2171788053-1000\...\ChromeHTML: -> <==== ATTENTION
ShellIconOverlayIdentifiers: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-12-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-12-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-12-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-12-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-12-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-12-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-12-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-12-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-12-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-12-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-12-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-12-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-12-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-12-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-12-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-12-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-12-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-12-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-12-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-12-04] (Dropbox, Inc.)
ContextMenuHandlers1: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-12-04] (Dropbox, Inc.)
ContextMenuHandlers1: [VirtualCloneDrive] -> {B7056B8E-4F99-44f8-8CBD-282390FE5428} => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\ElbyVCDShell.dll [2009-12-14] (Elaborate Bytes AG)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2013-11-27] (Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2013-11-27] (Alexander Roshal)
ContextMenuHandlers2: [VirtualCloneDrive] -> {B7056B8E-4F99-44f8-8CBD-282390FE5428} => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\ElbyVCDShell.dll [2009-12-14] (Elaborate Bytes AG)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamext.dll [2016-03-10] (Malwarebytes)
ContextMenuHandlers4: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-12-04] (Dropbox, Inc.)
ContextMenuHandlers5: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-12-04] (Dropbox, Inc.)
ContextMenuHandlers5: [Gadgets] -> {6B9228DA-9C15-419e-856C-19E768A13BDC} => -> No File
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\System32\nvshext.dll [2017-10-27] (NVIDIA Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamext.dll [2016-03-10] (Malwarebytes)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2013-11-27] (Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2013-11-27] (Alexander Roshal)
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {01B0DEF9-7F56-475D-B8C2-E6F4050B14CA} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2017-05-03] (Dropbox, Inc.)
Task: {0322CE59-05E8-4FD0-A25D-544AE9430569} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\WINDOWS\ehome\ehrec.exe
Task: {05F56212-DD7E-4DC2-9C46-DBC308315334} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-03-27] (NVIDIA Corporation)
Task: {08A0D656-BFBB-434A-AF9A-C95801E614B8} - System32\Tasks\EVGAPrecisionX => C:\Program Files (x86)\EVGA\PrecisionX 16\PrecisionX_x64.exe
Task: {10A4FFA9-C662-449B-81DD-75E3FD5A75BB} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {1172B2B2-8144-47CF-8DA2-06EEECD4AD35} - System32\Tasks\EVGAPrecision => C:\Program Files (x86)\EVGA Precision X\EVGAPrecision.exe
Task: {14ABAAC8-BB0C-46C9-B938-8C208E2D9312} - System32\Tasks\GridinSoft Anti-Malware => C:\Program Files\GridinSoft Anti-Malware\gsam.exe
Task: {1AA9D6D2-9C0E-4C2A-BAE2-F82D57351469} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {1D28F87B-7958-48E3-8D9E-BE734E2EF6A8} - System32\Tasks\{8DB225DA-401B-4324-B9D2-CAEECC6714E3} => C:\Windows\system32\pcalua.exe -a C:\Users\Wr3ckage\Downloads\Haardvuur.exe -d C:\Users\Wr3ckage\Downloads
Task: {1E27A1E5-E788-41A3-A07E-9761AF2E3788} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {21BEE89E-7A5A-46E7-A884-E9E72C370123} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-03-27] (NVIDIA Corporation)
Task: {2550273A-3A52-4D7E-8C8A-5F9AA4439B87} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime -> No File <==== ATTENTION
Task: {313A60CE-3734-4FF0-BD81-15B5735CEDF3} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-03-27] (NVIDIA Corporation)
Task: {34D121B2-4042-4D93-BF9A-14C40F0A5761} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_27_0_0_187_pepper.exe [2017-11-14] (Adobe Systems Incorporated)
Task: {3A5C1EA4-412F-4F79-8A95-D087F488B243} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2018-06-29] (Microsoft Corporation)
Task: {3DD46BF8-4E74-47FA-AD12-A858F1001799} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2018-06-20] (Microsoft Corporation)
Task: {45036761-A47B-460A-B65C-388CA89D794C} - System32\Tasks\{425B38BA-4249-4B92-972E-A9DCACA26066} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\InstallShield Installation Information\{2B41E132-07DF-4925-A3D3-F2D1765CCDFE}\setup.exe" -c -runfromtemp -l0x0009 -removeonly
Task: {4F7E9E38-C6E8-47A8-A994-0665E2B5044C} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-11-14] (Adobe Systems Incorporated)
Task: {50ADA210-8F62-4515-90BD-F9DF48DB3672} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2017-03-27] (NVIDIA Corporation)
Task: {5250DD9F-FEF9-4C70-AF21-6205EE398C8D} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1806.18062-0\MpCmdRun.exe [2018-06-26] (Microsoft Corporation)
Task: {537E0268-30A4-419A-AD05-FE3A631E08E6} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {56057729-3885-45C4-B32F-EBF0301C64DD} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {56367BD5-B69B-4904-8A5E-AF35CB6FA3A8} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {59CF72E4-4C3F-4929-B8FE-A8B1F54232B4} - \PastaQuotes -> No File <==== ATTENTION
Task: {6181CE75-6CDC-4985-B826-91139BE24F53} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2016-08-12] (Intel Corporation)
Task: {62726965-9661-4725-BA45-A6B3720E96CC} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1806.18062-0\MpCmdRun.exe [2018-06-26] (Microsoft Corporation)
Task: {64BEC3E6-B3A4-4ED4-ACCE-013834FB5233} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {6B4E5B16-B84D-4C2D-B543-C0D53FF9D7BE} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2018-06-29] (Microsoft Corporation)
Task: {762DDC4D-8645-4871-A0FC-0DF9738D1C2D} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {7AF5BB6F-7881-4A8C-B61D-71099FDEAD1D} - \Microsoft\Windows\Setup\EOONotify -> No File <==== ATTENTION
Task: {7F4CC302-F7E9-4DD9-979C-D6A352FB6DBC} - \Microsoft\Windows\Setup\gwx\rundetector -> No File <==== ATTENTION
Task: {8131BB14-7FC8-4964-A4A5-E3D89C12AC23} - \LaunchSignup -> No File <==== ATTENTION
Task: {844BC227-11FA-4E17-88A6-D6B3C6343C37} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\WINDOWS\ehome\mcupdate.exe
Task: {8467252C-E66A-4E1B-BE56-05CF87EA4EE3} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\WINDOWS\ehome\mcupdate.exe
Task: {8826475F-15C0-4A16-B4D7-B64AE15EF953} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2017-03-27] (NVIDIA Corporation)
Task: {887F0DF0-A490-46AE-97DC-B6FC9F1C36B9} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {898D3B10-6742-496E-9AB4-91109A33D79C} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {9D667347-2184-4C59-BC1F-BB07F329DD16} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {9E9388D8-1188-4CD9-A682-8551F27EEC88} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-03-27] (NVIDIA Corporation)
Task: {A2E7844B-D058-40AA-BF49-4E1494D59BAC} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {A45AFBEE-4481-4905-9A1D-06FB153EDF89} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {A906D588-606F-4319-AA82-97F62A29DF22} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\WINDOWS\ehome\MCUpdate.exe
Task: {AB978A6C-A494-4780-BCF0-5CED6850F31F} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {AF3DDA01-9A54-440D-B4CA-A739F51711BB} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {B1D9E5F1-5799-4314-9044-FDD9B0C2E7EC} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2018-06-29] (Microsoft Corporation)
Task: {B3B12495-7EA8-4381-AD14-1EEAEF621531} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {B60DAFAE-434F-4EB4-AFF8-6888E33F6C49} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {BD41F101-356F-445E-BF74-5C1E70A295DE} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1806.18062-0\MpCmdRun.exe [2018-06-26] (Microsoft Corporation)
Task: {BED1E8DC-1AAA-47B3-8627-9097B5413F9B} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\WINDOWS\ehome\ehrec.exe
Task: {C4D5822C-5219-4EAE-AC85-22FD064B82D4} - System32\Tasks\Trojan Remover => C:\Program Files\Loaris\Trojan Remover\ltr.exe
Task: {C4F1AEAD-328A-48E0-B257-2A18032AA998} - System32\Tasks\Microsoft\Office\OfficeOsfInstaller => C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\osfinstaller.exe [2018-06-29] (Microsoft Corporation)
Task: {C9EAA4EE-3A05-455F-BB8D-67ED71D8BEE2} - System32\Tasks\Opera scheduled Autoupdate 1495651710 => C:\Program Files\Opera\launcher.exe [2017-11-23] (Opera Software)
Task: {CE1C063E-8D6A-4357-AD29-EE3FF09DF4D3} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime -> No File <==== ATTENTION
Task: {D18B8EDE-1419-4A6D-802F-4C30E9029F51} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {D47FDD49-4CF3-4D5C-878B-6CE0C371C91F} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {E313CD67-A3ED-4DD8-B25D-D6DB85B3C2FD} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2017-05-19] (Piriform Ltd)
Task: {E3AC54D9-AABD-4215-BEE2-0262115F8236} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {E59E241D-BA23-4152-9793-57B7EA9A1E06} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2018-06-20] (Microsoft Corporation)
Task: {EB42E748-1606-4C3B-9025-21294AD33DFA} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {EC025D43-A002-4D7B-8618-AEA78DCB6C0B} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {EF83EAEE-4117-446D-B38B-05C274E5D354} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2017-05-03] (Dropbox, Inc.)
Task: {F28D3CCA-DA9C-4CDD-9B82-952A59DC41AA} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1806.18062-0\MpCmdRun.exe [2018-06-26] (Microsoft Corporation)
Task: {F5384768-C412-47D1-B8F6-92443F06A89A} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {F6733661-63A1-4A55-BA18-916C5EA53F61} - System32\Tasks\ASUS\ASUS Product Register Service => C:\Program Files (x86)\ASUS\APRP\aprp.exe
Task: {F684C460-AE34-4023-A6F3-DE63CF68C901} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2016-08-12] (Intel Corporation)
Task: {FF3F3BCF-472B-4674-9A86-0D387519578F} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {FF5AF123-FE7E-4165-AA42-694A326A4217} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-03-27] (NVIDIA Corporation)
Task: {FFB45B12-5A62-437E-94BF-E2E348DD32BB} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
==================== Shortcuts & WMI ========================
(The entries could be listed to be restored or removed.)
Shortcut: C:\Users\Wr3ckage\Favorites\NCH Software Download Site.lnk -> hxxp://www.nchsoftware.com/index.htm
ShortcutWithArgument: C:\Users\Wr3ckage\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Fox Searchlight Digital Scr....lnk -> C:\Program Files (x86)\Microsoft Silverlight\sllauncher.exe (Microsoft Corporation) -> 209253121.IIS Windows Server
ShortcutWithArgument: C:\Users\Wr3ckage\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\TwitchAlerts Stream Labels.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=kgmggmdngboajiakmbpdknfpdelbjbcg
==================== Loaded Modules (Whitelisted) ==============
2017-08-24 16:29 - 2017-10-27 12:12 - 000133752 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2017-02-15 05:30 - 2017-03-27 23:32 - 001147328 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll
2017-02-08 17:14 - 2017-02-08 17:14 - 000180736 _____ () C:\Program Files\YoloMouse\Yolo64.dll
2017-03-18 16:58 - 2017-03-18 16:58 - 000138000 _____ () C:\WINDOWS\SYSTEM32\inputhost.dll
2018-05-22 15:04 - 2018-05-22 15:04 - 000086528 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.209.0_x64__kzf8qxf38zg5c\SkypeHost.exe
2018-05-22 15:04 - 2018-05-22 15:04 - 000195072 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.209.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll
2018-05-22 15:04 - 2018-05-22 15:04 - 022374400 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.209.0_x64__kzf8qxf38zg5c\SkyWrap.dll
2018-05-22 15:04 - 2018-05-22 15:04 - 002610176 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.209.0_x64__kzf8qxf38zg5c\skypert.dll
2018-05-22 15:04 - 2018-05-22 15:04 - 000654848 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.209.0_x64__kzf8qxf38zg5c\RtmMvrUap.dll
2018-05-22 15:04 - 2018-05-22 15:04 - 000146432 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.209.0_x64__kzf8qxf38zg5c\SkypeHost.Proxies.dll
2014-09-18 03:23 - 2014-09-18 03:23 - 000866584 _____ () C:\Program Files\Logitech Gaming Software\libGLESv2.dll
2015-03-12 14:23 - 2015-03-12 14:23 - 001050904 _____ () C:\Program Files\Logitech Gaming Software\platforms\qwindows.dll
2014-09-18 03:23 - 2014-09-18 03:23 - 000059160 _____ () C:\Program Files\Logitech Gaming Software\libEGL.dll
2015-03-12 14:23 - 2015-03-12 14:23 - 000242456 _____ () C:\Program Files\Logitech Gaming Software\imageformats\qjpeg.dll
2017-04-19 08:43 - 2017-04-19 08:43 - 001234944 _____ () C:\Program Files\Elgato\SoundCapture\SoundCapture.exe
2017-02-08 17:14 - 2017-02-08 17:14 - 000222208 _____ () C:\Program Files\YoloMouse\YoloMouse.exe
2017-11-14 16:13 - 2017-11-10 05:57 - 004135768 _____ () C:\Program Files (x86)\Google\Chrome\Application\62.0.3202.94\libglesv2.dll
2017-11-14 16:13 - 2017-11-10 05:57 - 000100184 _____ () C:\Program Files (x86)\Google\Chrome\Application\62.0.3202.94\libegl.dll
2018-06-08 13:27 - 2018-06-08 13:27 - 000478720 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18041.15530.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
2018-06-08 13:27 - 2018-06-08 13:27 - 067232256 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18041.15530.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll
2017-10-07 13:56 - 2017-10-07 13:56 - 002523136 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18041.15530.0_x64__8wekyb3d8bbwe\UnityEngineDelegates.dll
2018-05-30 06:18 - 2018-05-30 06:19 - 000010752 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18041.15530.0_x64__8wekyb3d8bbwe\RenderingPlugin.dll
2018-05-30 06:18 - 2018-05-30 06:19 - 004214784 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18041.15530.0_x64__8wekyb3d8bbwe\MediaEngineCSWrapper.dll
2018-05-04 09:33 - 2018-05-04 09:33 - 000009216 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18041.15530.0_x64__8wekyb3d8bbwe\ImagePipelineNative.dll
2018-05-30 06:18 - 2018-05-30 06:19 - 000035840 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18041.15530.0_x64__8wekyb3d8bbwe\WinMLWrapper.UWP.dll
2018-04-05 02:44 - 2018-04-05 02:44 - 002283008 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18041.15530.0_x64__8wekyb3d8bbwe\TrackingDLLUWP.dll
2018-06-08 13:27 - 2018-06-08 13:27 - 014851072 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18041.15530.0_x64__8wekyb3d8bbwe\PhotosApp.Windows.dll
2018-05-30 06:18 - 2018-05-30 06:19 - 004058624 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18041.15530.0_x64__8wekyb3d8bbwe\MediaEngine.dll
2018-06-08 13:27 - 2018-06-08 13:27 - 003266048 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18041.15530.0_x64__8wekyb3d8bbwe\AppCore.Windows.dll
2018-05-30 06:18 - 2018-05-30 06:19 - 001393664 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18041.15530.0_x64__8wekyb3d8bbwe\Microsoft.RichMedia.Ink.Controls.dll
2018-05-30 06:18 - 2018-05-30 06:19 - 004218080 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18041.15530.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll
2018-05-30 06:18 - 2018-05-30 06:19 - 000103424 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18041.15530.0_x64__8wekyb3d8bbwe\BendRealityNode.dll
2018-05-30 06:18 - 2018-05-30 06:19 - 000872448 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18041.15530.0_x64__8wekyb3d8bbwe\RuntimeConfiguration.dll
2018-04-05 02:44 - 2018-04-05 02:44 - 000043008 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18041.15530.0_x64__8wekyb3d8bbwe\Microsoft.Photos.Edit.Services.dll
2018-06-08 13:27 - 2018-06-08 13:27 - 000165376 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18041.15530.0_x64__8wekyb3d8bbwe\SKU.dll
2017-04-18 16:10 - 2017-04-18 16:10 - 000817152 _____ () C:\Program Files\Elgato\GameCapture\CFLite.dll
2017-04-18 16:11 - 2017-04-18 16:11 - 074678272 _____ () C:\Program Files\Elgato\GameCapture\libcef.dll
2017-03-18 16:59 - 2017-03-18 22:30 - 001731072 ____N () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2017-03-18 16:58 - 2017-03-18 16:58 - 000047616 ____N () C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUITelemetry.dll
2017-07-11 01:41 - 2017-07-11 01:41 - 002331136 ____N () C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUIViewModels.dll
2017-07-11 01:41 - 2017-07-11 01:41 - 002836480 ____N () C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUIDataModel.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
AlternateDataStreams: C:\ProgramData\TEMP:27D40D6F [390]
AlternateDataStreams: C:\ProgramData\TEMP:56E2E879 [118]
AlternateDataStreams: C:\ProgramData\TEMP:CB0AACC9 [148]
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
IE trusted site: HKU\S-1-5-21-2206024096-2261513051-2171788053-1000\...\foxtv.com -> hxxps://ftsaccess.foxtv.com
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-13 22:34 - 2017-07-06 05:16 - 000001484 _____ C:\WINDOWS\system32\Drivers\etc\hosts
161.202.84.165 gs001.pso2gs.net #PSO2Proxy Public Server Ship 01
161.202.84.165 gs016.pso2gs.net #PSO2Proxy Public Server Ship 02
161.202.84.165 gs031.pso2gs.net #PSO2Proxy Public Server Ship 03
161.202.84.165 gs046.pso2gs.net #PSO2Proxy Public Server Ship 04
161.202.84.165 gs061.pso2gs.net #PSO2Proxy Public Server Ship 05
161.202.84.165 gs076.pso2gs.net #PSO2Proxy Public Server Ship 06
161.202.84.165 gs091.pso2gs.net #PSO2Proxy Public Server Ship 07
161.202.84.165 gs106.pso2gs.net #PSO2Proxy Public Server Ship 08
161.202.84.165 gs121.pso2gs.net #PSO2Proxy Public Server Ship 09
161.202.84.165 gs136.pso2gs.net #PSO2Proxy Public Server Ship 10
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-2206024096-2261513051-2171788053-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Wr3ckage\Desktop\newvegfinal.jpg
HKU\S-1-5-21-2206024096-2261513051-2171788053-1004\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\web\wallpaper\Windows\img0.jpg
DNS Servers: 208.59.247.45 - 208.59.247.46
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Nostromo Loadout Manager.lnk => C:\Windows\pss\Nostromo Loadout Manager.lnk.CommonStartup
MSCONFIG\startupfolder: C:^Users^Wr3ckage^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^MagicDisc.lnk => C:\Windows\pss\MagicDisc.lnk.Startup
MSCONFIG\startupfolder: C:^Users^Wr3ckage^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Wr3ckage.exe => C:\Windows\pss\Wr3ckage.exe.Startup
MSCONFIG\startupreg: AvgUi => "C:\Program Files (x86)\AVG\Framework\Common\avguirnx.exe" /lps=fmw
MSCONFIG\startupreg: BitTorrent => "C:\Users\Wr3ckage\AppData\Roaming\BitTorrent\BitTorrent.exe" /MINIMIZED
MSCONFIG\startupreg: BlueStacks Agent => C:\Program Files (x86)\BlueStacks\HD-Agent.exe
MSCONFIG\startupreg: BrowserSafeguard => "C:\Program Files (x86)\Browsersafeguard\BrowserSafeguard.exe"
MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
MSCONFIG\startupreg: cpx => "C:\Program Files (x86)\cpx\cpx.exe" -starup
MSCONFIG\startupreg: Discord => C:\Users\Wr3ckage\AppData\Local\Discord\app-0.0.277\Discord.exe
MSCONFIG\startupreg: IAStorIcon => "C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe" "C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" 60
MSCONFIG\startupreg: msrtn32 => "C:\Program Files (x86)\msrtn32\msrtn32.exe" -startup=smartcpx -check=60
MSCONFIG\startupreg: MyComGames => "C:\Users\Wr3ckage\AppData\Local\MyComGames\MyComGames.exe" -autostart
MSCONFIG\startupreg: Nvtmru => "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe"
MSCONFIG\startupreg: Overwolf => C:\Program Files (x86)\Overwolf\Overwolf.exe -silent
MSCONFIG\startupreg: ShadowPlay => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
MSCONFIG\startupreg: Steam => "C:\Program Files (x86)\Steam\Steam.exe" -silent
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
MSCONFIG\startupreg: TrojanScanner => C:\Program Files (x86)\Trojan Remover\Trjscan.exe /boot
MSCONFIG\startupreg: tsiVideo => C:\Windows\SysWOW64\rundll32.exe C:\Users\Wr3ckage\AppData\Local\Temp\mdi064.dll,quardin
MSCONFIG\startupreg: UserCheck => C:\ProgramData\UserCheck.exe
MSCONFIG\startupreg: VirtualCloneDrive => "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
MSCONFIG\startupreg: Winlogon => C:\Users\Wr3ckage\AppData\Roaming\winlogon.exe
HKLM\...\StartupApproved\Run: => "WindowsDefender"
HKLM\...\StartupApproved\Run32: => "Adobe ARM"
HKLM\...\StartupApproved\Run32: => "Dropbox"
HKLM\...\StartupApproved\Run32: => "APSDaemon"
HKU\S-1-5-21-2206024096-2261513051-2171788053-1000\...\StartupApproved\Run: => "BitTorrent"
HKU\S-1-5-21-2206024096-2261513051-2171788053-1000\...\StartupApproved\Run: => "Chromium"
HKU\S-1-5-21-2206024096-2261513051-2171788053-1000\...\StartupApproved\Run: => "Discord"
HKU\S-1-5-21-2206024096-2261513051-2171788053-1000\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-2206024096-2261513051-2171788053-1000\...\StartupApproved\Run: => "uTorrent"
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{E206A2EC-AE47-4943-81BF-8839B44ABD6D}] => (Allow) C:\Users\Wr3ckage\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{544E391F-0661-4463-8F80-5F3B883E377C}] => (Allow) C:\Users\Wr3ckage\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{608F7ED1-FBB7-429D-8750-B3F8DEA73B7D}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe
FirewallRules: [{E47C765C-6FDC-4EF8-AA99-41362CFC4F71}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Project Highrise\Game.exe
FirewallRules: [{1876ECFF-8541-4DBD-8AFB-19097D81871F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Project Highrise\Game.exe
FirewallRules: [{FF510C99-2CB1-41B2-8EA9-394CF74DCD6E}] => (Allow) C:\Program Files (x86)\MediaMall\Surfer.exe
FirewallRules: [{3677F5AA-463C-4884-A349-85D516697DC6}] => (Allow) C:\Program Files (x86)\MediaMall\PlayMark.exe
FirewallRules: [{CDAD1FB1-E628-4934-B3B4-FB8AD6D587DF}] => (Allow) C:\Program Files (x86)\MediaMall\PlayOn.exe
FirewallRules: [{F176C550-43C8-432E-8B09-A76524832AE6}] => (Allow) C:\Program Files (x86)\MediaMall\SettingsManager.exe
FirewallRules: [{93CECC06-64E3-4915-B533-AD65BC96FFBD}] => (Allow) C:\Program Files (x86)\MediaMall\MediaMallServerLauncher.exe
FirewallRules: [{095151F2-4383-43B1-8E86-AEB68A98643A}] => (Allow) C:\Program Files (x86)\MediaMall\MediaMallServer.exe
FirewallRules: [{94428C46-FD11-485A-AF0A-2A344ED45D66}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{A709DD6E-E5AB-4591-8137-1D729A922F65}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{E9124850-004C-4B29-B3A7-D074BE9435E5}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
FirewallRules: [{25CB5D37-C122-4BA8-AE91-D4243B8E1BA1}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [{A909610D-74F4-4857-819B-0985A56ED49F}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [{F744D64B-B0D7-41FB-8BE8-6CF819E95520}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{3E6466AA-A9EF-41D0-9937-EBE1421D89A5}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [UDP Query User{D6D51F59-1CEF-47BD-8F83-B4C50F7DAFFE}C:\program files (x86)\diablo iii\x64\diablo iii64.exe] => (Allow) C:\program files (x86)\diablo iii\x64\diablo iii64.exe
FirewallRules: [TCP Query User{92BDBB9C-7892-4F29-A8A8-0C68B44CE40C}C:\program files (x86)\diablo iii\x64\diablo iii64.exe] => (Allow) C:\program files (x86)\diablo iii\x64\diablo iii64.exe
FirewallRules: [{93233250-AEF5-4266-A744-8640BF0351AE}] => (Allow) C:\Program Files (x86)\FlashIntegro\VideoEditor\Updater.exe
FirewallRules: [{02D7516E-3CA7-44BD-83B9-A85E505472D7}] => (Allow) C:\Program Files (x86)\FlashIntegro\VideoEditor\Updater.exe
FirewallRules: [{69E66EA3-CCBA-4DAF-87F9-3994443A286A}] => (Allow) C:\Program Files (x86)\FlashIntegro\VideoEditor\Activation.exe
FirewallRules: [{801CC622-9815-4EB3-BB3F-594009D0BDB6}] => (Allow) C:\Program Files (x86)\FlashIntegro\VideoEditor\Activation.exe
FirewallRules: [{FC9F100D-74E2-4EA9-97EE-133DB21B2472}] => (Allow) C:\Program Files (x86)\FlashIntegro\VideoEditor\VideoEditor.exe
FirewallRules: [{09294686-B832-476F-91FD-FA09B37971A4}] => (Allow) C:\Program Files (x86)\FlashIntegro\VideoEditor\VideoEditor.exe
FirewallRules: [{A6BD5E16-140C-4F35-8622-37CB9B88F5F1}] => (Allow) LPort=1900
FirewallRules: [{29CB68C6-CBB1-405A-99D2-9BD08006ADC9}] => (Allow) LPort=2869
FirewallRules: [{5945C811-53F7-45FD-9AAB-AFB2C4DCD181}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [UDP Query User{2FC6A050-9F37-4FED-B964-40A9B469B103}C:\users\wr3ckage\appdata\local\mycomgames\mycomgames.exe] => (Allow) C:\users\wr3ckage\appdata\local\mycomgames\mycomgames.exe
FirewallRules: [TCP Query User{81987451-11DC-46DA-9F21-1D69133B471B}C:\users\wr3ckage\appdata\local\mycomgames\mycomgames.exe] => (Allow) C:\users\wr3ckage\appdata\local\mycomgames\mycomgames.exe
FirewallRules: [{73C0FAC1-2D61-4891-9FC8-810042CB0600}] => (Allow) C:\Users\Wr3ckage\AppData\Local\MyComGames\MyComGames.exe
FirewallRules: [{468D7AD5-53C5-4053-9B14-764CE07127B8}] => (Allow) C:\Users\Wr3ckage\AppData\Local\MyComGames\MyComGames.exe
FirewallRules: [{38D02012-249B-4B8F-A949-75D085AB55E2}] => (Allow) C:\Program Files\Logitech Gaming Software\LCore.exe
FirewallRules: [{57686B6D-D79B-4408-B226-3B0205AD057D}] => (Allow) C:\Program Files\Logitech Gaming Software\LCore.exe
FirewallRules: [{AFBB460D-3037-4F1C-9DB1-57CB8D580236}] => (Allow) C:\Program Files (x86)\Rosetta Stone\Rosetta Stone Version 3\support\bin\win\RosettaStoneLtdServices.exe
FirewallRules: [{8A6CA56C-1974-4D20-BA0C-631DC2EE4097}] => (Allow) C:\Program Files (x86)\Rosetta Stone\Rosetta Stone Version 3\support\bin\win\RosettaStoneLtdServices.exe
FirewallRules: [{6143A5D2-7B5F-4936-AEE3-E1FEB35704BF}] => (Allow) C:\Program Files (x86)\Rosetta Stone\Rosetta Stone Version 3\RosettaStoneVersion3.exe
FirewallRules: [{4B0506F3-01B7-4CBC-8DD9-7EEC02CC84DF}] => (Allow) C:\Program Files (x86)\Rosetta Stone\Rosetta Stone Version 3\RosettaStoneVersion3.exe
FirewallRules: [{7E6BAA8C-5DC1-4B0A-90F3-46044189F012}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2753\Agent.exe
FirewallRules: [{AE50D218-4A65-4640-AC11-7951CB521C7C}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2753\Agent.exe
FirewallRules: [{0B2F61CF-8BEF-43B0-BE51-14A0EC005FFE}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2737\Agent.exe
FirewallRules: [{A3FDC6A8-F669-4E01-B5BE-11461622E68C}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2737\Agent.exe
FirewallRules: [{9A273C0E-4276-4BF0-8458-FCC3384FE846}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{E33E2A17-67EB-4F89-AC40-6554914DF53F}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{EE5E8C22-ADBD-46DA-8381-8672BC56B4CE}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{78333F96-3E6A-46A2-A858-1AA2E8CFF5F9}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{1042FB8A-8DFA-4D87-9E19-3928EE8174CE}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{1E75FD1F-580B-4931-83A9-3A11CAC06105}] => (Allow) C:\Program Files\Ventrilo\Ventrilo.exe
FirewallRules: [{362736EE-1791-4AFC-A949-4AE5D8958285}] => (Allow) C:\Program Files\Ventrilo\Ventrilo.exe
FirewallRules: [{B1854FBA-2A0B-41D8-B496-96FBC2A177A7}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{D2D93F62-44FD-46EC-9805-12838C5799A9}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{770D9BCF-483F-4248-8B52-EFED5DB023A8}] => (Allow) C:\Users\Wr3ckage\AppData\Roaming\BitTorrent\BitTorrent.exe
FirewallRules: [{C2597128-FFA5-4C5A-9820-D81898D9E790}] => (Allow) C:\Users\Wr3ckage\AppData\Roaming\BitTorrent\BitTorrent.exe
FirewallRules: [{23C60FE2-6631-434E-B02D-9FD5DE5D06B1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\South Park The Fractured But Whole\SouthPark_TFBW.exe
FirewallRules: [{25E4EACE-5D44-487E-9156-9DB008597F49}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\South Park The Fractured But Whole\SouthPark_TFBW.exe
FirewallRules: [{2E953464-BB92-415D-A0CD-D68DD876421B}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{3693DC32-587F-4B31-8FA7-1219C3A00E61}] => (Allow) C:\Program Files\Opera\49.0.2725.39\opera.exe
FirewallRules: [{48117B84-206C-42DF-8A80-0CCAF0E564ED}] => (Allow) C:\Program Files\Opera\49.0.2725.47\opera.exe
FirewallRules: [{F99718CF-DEE3-499B-B426-B5FA517D9DEC}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
FirewallRules: [TCP Query User{FEA40C4B-B121-46E1-BDB5-BC3AA20C139D}C:\programdata\wargaming.net\gamecenter\wgc.exe] => (Allow) C:\programdata\wargaming.net\gamecenter\wgc.exe
FirewallRules: [UDP Query User{11ED596C-3CAA-412C-973F-398FB8290B8A}C:\programdata\wargaming.net\gamecenter\wgc.exe] => (Allow) C:\programdata\wargaming.net\gamecenter\wgc.exe
FirewallRules: [{212DA6DE-42C0-4EC9-AF8E-75844ECD740E}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe
==================== Restore Points =========================
19-06-2018 20:17:21 Scheduled Checkpoint
27-06-2018 01:30:22 Windows Update
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (06/30/2018 06:47:24 PM) (Source: SideBySide) (EventID: 59) (User: )
Description: Activation context generation failed for "C:\Users\Wr3ckage\Downloads\SFCFix.exe".Error in manifest or policy file "C:\WINDOWS\WinSxS\manifests\x86_policy.8.0.microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.9307_none_5168dae10f4d982d.manifest" on line 0.
Invalid Xml syntax.
Error: (06/30/2018 06:00:08 PM) (Source: SideBySide) (EventID: 59) (User: )
Description: Activation context generation failed for "C:\Users\Wr3ckage\Downloads\SFCFix.exe".Error in manifest or policy file "C:\WINDOWS\WinSxS\manifests\x86_policy.8.0.microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.9307_none_5168dae10f4d982d.manifest" on line 0.
Invalid Xml syntax.
Error: (06/30/2018 06:00:01 PM) (Source: SideBySide) (EventID: 59) (User: )
Description: Activation context generation failed for "C:\Users\Wr3ckage\Downloads\SFCFix.exe".Error in manifest or policy file "C:\WINDOWS\WinSxS\manifests\x86_policy.8.0.microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.9307_none_5168dae10f4d982d.manifest" on line 0.
Invalid Xml syntax.
Error: (06/30/2018 05:59:44 PM) (Source: SideBySide) (EventID: 59) (User: )
Description: Activation context generation failed for "C:\Users\Wr3ckage\Desktop\SFCFix.exe".Error in manifest or policy file "C:\WINDOWS\WinSxS\manifests\x86_policy.8.0.microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.9307_none_5168dae10f4d982d.manifest" on line 0.
Invalid Xml syntax.
Error: (06/30/2018 05:26:45 PM) (Source: SideBySide) (EventID: 59) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\Intel\Intel(R) SSD Toolbox\Intel SSD Toolbox.exe".Error in manifest or policy file "C:\WINDOWS\WinSxS\manifests\x86_policy.9.0.microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9279_none_f4810f46f6546fca.manifest" on line 0.
Invalid Xml syntax.
Error: (06/30/2018 05:26:45 PM) (Source: SideBySide) (EventID: 59) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\Intel\Intel(R) SSD Toolbox\Intel SSD Toolbox.exe".Error in manifest or policy file "C:\WINDOWS\WinSxS\manifests\x86_policy.9.0.microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9279_none_f4810f46f6546fca.manifest" on line 0.
Invalid Xml syntax.
Error: (06/30/2018 05:26:44 PM) (Source: SideBySide) (EventID: 59) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe".Error in manifest or policy file "C:\WINDOWS\WinSxS\manifests\x86_policy.9.0.microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9279_none_f4810f46f6546fca.manifest" on line 0.
Invalid Xml syntax.
Error: (06/30/2018 04:33:41 PM) (Source: SideBySide) (EventID: 59) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe".Error in manifest or policy file "C:\WINDOWS\WinSxS\manifests\x86_policy.9.0.microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9279_none_f4810f46f6546fca.manifest" on line 0.
Invalid Xml syntax.
System errors:
=============
Error: (06/30/2018 03:28:01 PM) (Source: DCOM) (EventID: 10010) (User: Wr3ckage-PC)
Description: The server Microsoft.MicrosoftEdge_40.15063.674.0_neutral__8wekyb3d8bbwe!ContentProcess did not register with DCOM within the required timeout.
Error: (06/30/2018 03:16:19 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID
{C2F03A33-21F5-47FA-B4BB-156362A2F239}
and APPID
{316CDED5-E4AE-4B15-9113-7055D84DCC97}
to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (06/30/2018 03:16:19 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
and APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (06/30/2018 03:16:19 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID
{C2F03A33-21F5-47FA-B4BB-156362A2F239}
and APPID
{316CDED5-E4AE-4B15-9113-7055D84DCC97}
to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (06/30/2018 03:16:19 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
and APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (06/30/2018 03:16:19 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID
{C2F03A33-21F5-47FA-B4BB-156362A2F239}
and APPID
{316CDED5-E4AE-4B15-9113-7055D84DCC97}
to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (06/30/2018 03:16:19 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
and APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (06/30/2018 03:16:19 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID
{C2F03A33-21F5-47FA-B4BB-156362A2F239}
and APPID
{316CDED5-E4AE-4B15-9113-7055D84DCC97}
to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Windows Defender:
===================================
Date: 2018-06-30 15:35:09.296
Description:
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {56EC89F5-33D7-4F8F-9243-44A952D2808E}
Scan Type: Antimalware
Scan Parameters: Full Scan
Date: 2018-06-30 01:03:42.800
Description:
Windows Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?li...n32/Bitrep.B&threatid=2147723143&enterprise=0
Name: Trojan:Win32/Bitrep.B
ID: 2147723143
Severity: Severe
Category: Trojan
Path: file:_C:\Users\Wr3ckage\Downloads\Rosetta Stone JP1-3+App\Rosetta Stone V3.2\Rosetta Stone v3.2 - Patch.exe
Detection Origin: Local machine
Detection Type: FastPath
Detection Source: System
Process Name: Unknown
Signature Version: AV: 1.271.213.0, AS: 1.271.213.0, NIS: 1.271.213.0
Engine Version: AM: 1.1.15000.2, NIS: 1.1.15000.2
Date: 2018-06-30 01:03:24.001
Description:
Windows Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?li...n32/Bitrep.B&threatid=2147723143&enterprise=0
Name: Trojan:Win32/Bitrep.B
ID: 2147723143
Severity: Severe
Category: Trojan
Path: file:_C:\Users\Wr3ckage\Downloads\Rosetta Stone JP1-3+App\Rosetta Stone V3.2\Rosetta Stone v3.2 - Patch.exe
Detection Origin: Local machine
Detection Type: FastPath
Detection Source: System
Process Name: Unknown
Signature Version: AV: 1.271.213.0, AS: 1.271.213.0, NIS: 1.271.213.0
Engine Version: AM: 1.1.15000.2, NIS: 1.1.15000.2
Date: 2018-06-30 00:49:47.827
Description:
Windows Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?li...n32/Bitrep.B&threatid=2147723143&enterprise=0
Name: Trojan:Win32/Bitrep.B
ID: 2147723143
Severity: Severe
Category: Trojan
Path: file:_C:\Users\Wr3ckage\Downloads\Rosetta Stone JP1-3+App\Rosetta Stone V3.2\Rosetta Stone v3.2 - Patch.exe
Detection Origin: Local machine
Detection Type: FastPath
Detection Source: System
Process Name: Unknown
Signature Version: AV: 1.271.213.0, AS: 1.271.213.0, NIS: 1.271.213.0
Engine Version: AM: 1.1.15000.2, NIS: 1.1.15000.2
Date: 2018-06-26 01:39:12.541
Description:
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {C4807C59-8460-4E65-99E0-4A836B31BD1F}
Scan Type: Antimalware
Scan Parameters: Quick Scan
CodeIntegrity:
===================================
Date: 2018-06-26 01:26:50.891
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\ProgramData\Microsoft\Windows Defender\Platform\4.18.1806.18062-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2018-06-26 01:05:11.653
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ProgramData\Microsoft\Windows Defender\Platform\4.18.1806.18062-0\Drivers\WdBoot.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2018-06-26 01:05:11.652
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ProgramData\Microsoft\Windows Defender\Platform\4.18.1806.18062-0\Drivers\WdBoot.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2018-06-19 00:50:14.580
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\ProgramData\Microsoft\Windows Defender\Platform\4.16.17656.18052-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2018-06-16 21:26:45.941
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\ProgramData\Microsoft\Windows Defender\Platform\4.16.17656.18052-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2018-05-30 19:37:08.321
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\ProgramData\Microsoft\Windows Defender\Platform\4.16.17656.18052-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2018-05-30 18:39:44.515
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ProgramData\Microsoft\Windows Defender\Platform\4.16.17656.18052-0\Drivers\WdBoot.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2018-05-30 18:39:44.513
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ProgramData\Microsoft\Windows Defender\Platform\4.16.17656.18052-0\Drivers\WdBoot.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i7-4770K CPU @ 3.50GHz
Percentage of memory in use: 47%
Total physical RAM: 16321.32 MB
Available physical RAM: 8625.3 MB
Total Virtual: 32705.32 MB
Available Virtual: 19990.32 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:222.63 GB) (Free:7.67 GB) NTFS
\\?\Volume{58414428-01dc-11e3-8dc2-806e6f6e6963}\ (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS
\\?\Volume{45cae16c-0000-0000-0000-f0ae37000000}\ () (Fixed) (Total:0.84 GB) (Free:0.34 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 223.6 GB) (Disk ID: 45CAE16C)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=222.6 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=856 MB) - (Type=27)
==================== End of Addition.txt ============================
Attachments
Last edited by a moderator: