Additional scan result of Farbar Recovery Scan Tool (x64) Version:05-07-2015 Ran by Rooha at 2015-07-08 16:19:47 Running from C:\Users\Rooha\Downloads\Programs Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-1071033344-2270758295-2084488698-500 - Administrator - Disabled) Guest (S-1-5-21-1071033344-2270758295-2084488698-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-1071033344-2270758295-2084488698-1004 - Limited - Enabled) Rooha (S-1-5-21-1071033344-2270758295-2084488698-1002 - Administrator - Enabled) => C:\Users\Rooha ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) µTorrent (HKU\S-1-5-21-1071033344-2270758295-2084488698-1002\...\uTorrent) (Version: 3.4.0.30596 - BitTorrent Inc.) 4 Elements II (x32 Version: 2.2.0.98 - WildTangent) Hidden Acrobat.com (HKLM-x32\...\{287ECFA4-719A-2143-A09B-D6A12DE54E40}) (Version: 1.6.65 - Adobe Systems Incorporated) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 1.5.0.7220 - Adobe Systems Inc.) Adobe Flash Player 18 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 18.0.0.194 - Adobe Systems Incorporated) Adobe Reader XI (11.0.11) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.11 - Adobe Systems Incorporated) Adobe Shockwave Player 11.6 (HKLM-x32\...\Adobe Shockwave Player) (Version: 11.6.6.636 - Adobe Systems, Inc.) Advertising Center (x32 Version: 0.0.0.1 - Nero AG) Hidden Aloha TriPeaks (x32 Version: 2.2.0.98 - WildTangent) Hidden AMD Catalyst Install Manager (HKLM\...\{3CEC10BE-CD7C-8E99-E3AC-DD31F4416C1C}) (Version: 8.0.881.0 - Advanced Micro Devices, Inc.) Apple Application Support (32-bit) (HKLM-x32\...\{AFA1153A-F547-409B-B837-3A0D6C5A3FEC}) (Version: 3.1.3 - Apple Inc.) Apple Application Support (64-bit) (HKLM\...\{D7B824DE-DA32-4772-9E5E-39C5158136A7}) (Version: 3.1.3 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{C4123106-B685-48E6-B9BD-E4F911841EB4}) (Version: 8.1.1.3 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Bejeweled 3 (x32 Version: 2.2.0.98 - WildTangent) Hidden BlackBerry Link (HKLM-x32\...\BlackBerry_10_Desktop) (Version: 1.2.3.56 - BlackBerry Ltd.) BlackBerry Link (x32 Version: 1.2.3.56 - BlackBerry Ltd.) Hidden Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Build-a-lot 4 - Power Source (x32 Version: 2.2.0.98 - WildTangent) Hidden Catalyst Control Center (HKLM-x32\...\WUCCCApp) (Version: 1.00.0000 - AMD) Cradle of Rome 2 (x32 Version: 2.2.0.98 - WildTangent) Hidden Crazy Chicken Soccer (x32 Version: 2.2.0.98 - WildTangent) Hidden CyberLink LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.2.5712 - CyberLink Corp.) CyberLink Media Suite 10 (HKLM-x32\...\InstallShield_{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}) (Version: 10.0.2.2114 - CyberLink Corp.) CyberLink PhotoDirector (HKLM-x32\...\InstallShield_{4862344A-A39C-4897-ACD4-A1BED5163C5A}) (Version: 2.0.2.3317 - CyberLink Corp.) CyberLink Power2Go 8 (HKLM-x32\...\InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}) (Version: 8.0.2.2110 - CyberLink Corp.) CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.2.2126 - CyberLink Corp.) CyberLink PowerDVD (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.6.4319 - CyberLink Corp.) CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.5.5.5811 - CyberLink Corp.) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden DAEMON Tools Pro (HKLM-x32\...\DAEMON Tools Pro) (Version: 5.2.0.0348 - DT Soft Ltd) DolbyFiles (x32 Version: 0.1 - Nero AG) Hidden Energy Star (HKLM-x32\...\{FC0ADA4D-8FA5-4452-8AFF-F0A0BAC97EF7}) (Version: 1.0.9 - Hewlett-Packard Company) Facebook Video Calling 3.1.0.521 (HKLM-x32\...\{2091F234-EB58-4B80-8C96-8EB78C808CF7}) (Version: 3.1.521 - Skype Limited) Farm Frenzy (x32 Version: 2.2.0.98 - WildTangent) Hidden Final Drive Fury (x32 Version: 2.2.0.95 - WildTangent) Hidden Free Studio version 2013 (HKLM-x32\...\Free Studio_is1) (Version: 6.1.0.320 - DVDVideoSoft Ltd.) Gardenscapes: Mansion Makeover (x32 Version: 3.0.2.32 - WildTangent) Hidden Google Chrome (HKLM-x32\...\Google Chrome) (Version: 43.0.2357.130 - Google Inc.) Google Quick Scroll (HKLM-x32\...\{AD11DADE-C597-45D9-D8C5-1D2EB0B89613}) (Version: - ) <==== ATTENTION Google Update Helper (x32 Version: 1.3.26.9 - Google Inc.) Hidden Google+ Auto Backup (HKLM-x32\...\{A50DE037-B5C0-4C8A-8049-B0C576B313D1}) (Version: 1.0.21.81 - Google) Governor of Poker 2 Premium Edition (x32 Version: 2.2.0.95 - WildTangent) Hidden Grand Theft Auto Vice City (HKLM-x32\...\{4B35F00C-E63D-40DC-9839-DF15A33EAC46}) (Version: 1.00.000 - ) GTA San Andreas (HKLM-x32\...\{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}) (Version: 1.00.00001 - Rockstar Games) GTAIII (HKLM-x32\...\{92B94569-6683-4617-8C54-EB27A1B51B30}) (Version: - ) Hewlett-Packard ACLM.NET v1.2.1.1 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden House of 1000 Doors: Family Secrets (x32 Version: 2.2.0.98 - WildTangent) Hidden Hoyle Card Games (x32 Version: 2.2.0.95 - WildTangent) Hidden HP 3D DriveGuard (HKLM\...\{54CE68A8-4F2D-4328-B1F7-D6C720405F7F}) (Version: 4.2.9.1 - Hewlett-Packard Company) HP Connected Remote (HKLM-x32\...\{F243A34B-AB7F-4065-B770-B85B767C247C}) (Version: 1.0.1218 - Hewlett-Packard) HP CoolSense (HKLM-x32\...\{11AF9A96-6D83-4C3B-8DCB-16EA2A358E3F}) (Version: 2.10.51 - Hewlett-Packard Company) HP Documentation (HKLM-x32\...\{A2E95309-79F3-41E5-94C7-6D7FD6D7BBC3}) (Version: 1.2.0.0 - Hewlett-Packard) HP Games (HKLM-x32\...\WildTangent hp Master Uninstall) (Version: 1.0.3.0 - WildTangent) HP Quick Launch (HKLM-x32\...\{E5823036-6F09-4D0A-B05C-E2BAA129288A}) (Version: 3.0.6 - Hewlett-Packard Company) HP Registration Service (HKLM\...\{C2E428EB-116E-41C0-9E84-B22DE9CCA42F}) (Version: 1.1.6232.4245 - Hewlett-Packard) HP Support Assistant (HKLM-x32\...\{EE202411-2C26-49E8-9784-1BC1DBF7DE96}) (Version: 7.0.39.15 - Hewlett-Packard Company) HP Utility Center (HKLM-x32\...\{0C57987A-A03A-4B95-A309-D23F78F406CA}) (Version: 1.0.8 - Hewlett-Packard) HP Wireless Button Driver (HKLM-x32\...\{30B2D1D8-0A07-4B71-9553-0710C5D31E35}) (Version: 1.1.2.1 - Hewlett-Packard Company) Idea Net Setter (HKLM-x32\...\Idea Net Setter) (Version: 16.001.06.01.356 - Huawei Technologies Co.,Ltd) IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6425.0 - IDT) ImagXpress (x32 Version: 7.0.74.0 - Nero AG) Hidden Internet Download Manager (HKLM-x32\...\Internet Download Manager) (Version: - Tonec Inc.) iTunes (HKLM\...\{93F2A022-6C37-48B8-B241-FFABD9F60C30}) (Version: 12.1.2.27 - Apple Inc.) Jewel Match 3 (x32 Version: 2.2.0.98 - WildTangent) Hidden John Deere Drive Green (x32 Version: 2.2.0.95 - WildTangent) Hidden Letters from Nowhere 2 (x32 Version: 2.2.0.97 - WildTangent) Hidden Luxor Evolved (x32 Version: 2.2.0.98 - WildTangent) Hidden Mahjongg Dimensions Deluxe: Tiles in Time (x32 Version: 2.2.0.98 - WildTangent) Hidden McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.8.150.1 - McAfee, Inc.) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-1071033344-2270758295-2084488698-1002\...\OneDriveSetup.exe) (Version: 17.0.4041.0512 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable - x86 8.0.61001 (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 Redistributable - x86 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.) Movie Maker (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden Nero 9 Essentials (HKLM-x32\...\{8cf10404-53b1-431b-a076-d3141b078a80}) (Version: - Nero AG) Nokia Connectivity Cable Driver (HKLM-x32\...\{0906982B-A432-4C06-8F01-C01BE1143779}) (Version: 7.1.92.0 - Nokia) Nokia Suite (HKLM-x32\...\Nokia Suite) (Version: 3.6.36.0 - Nokia) Nokia Suite (x32 Version: 3.6.36.0 - Nokia) Hidden Origin (HKLM-x32\...\Origin) (Version: 8.4.1.210 - Electronic Arts, Inc.) PC Connectivity Solution (HKLM-x32\...\{BA77F9D2-CD35-41EB-9BC9-769879DFF8A6}) (Version: 12.0.48.0 - Nokia) Peggle Nights (x32 Version: 2.2.0.98 - WildTangent) Hidden Penguins! (x32 Version: 2.2.0.98 - WildTangent) Hidden Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9 - Google, Inc.) Polar Bowler (x32 Version: 2.2.0.97 - WildTangent) Hidden Polar Golfer (x32 Version: 2.2.0.98 - WildTangent) Hidden QuickTime 7 (HKLM-x32\...\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.) Ralink Bluetooth Stack64 (HKLM\...\{95DF815D-BE2D-9118-F549-39794C5869CF}) (Version: 9.0.725.0 - Ralink Corporation) Ralink RT3290 802.11bgn Wi-Fi Adapter (HKLM-x32\...\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}) (Version: 5.0.5.0 - Ralink) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.3.730.2012 - Realtek) Realtek PCIE Card Reader (HKLM-x32\...\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.2.8400.29029 - Realtek Semiconductor Corp.) Roads of Rome 3 (x32 Version: 2.2.0.98 - WildTangent) Hidden Royal Envoy 2 Collector's Edition (x32 Version: 3.0.2.32 - WildTangent) Hidden Safari (HKLM-x32\...\{C779648B-410E-4BBA-B75B-5815BCEFE71D}) (Version: 5.34.57.2 - Apple Inc.) Samsung Kies (HKLM-x32\...\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.0.0.11042_28 - Samsung Electronics Co., Ltd.) Samsung Kies (x32 Version: 2.0.0.11042_28 - Samsung Electronics Co., Ltd.) Hidden sauve nEt (HKLM-x32\...\{7DD5E91C-3864-77EC-7635-D14910C2A03E}) (Version: 4.3.0.1667 - siave net) <==== ATTENTION SeekerSystem (HKLM-x32\...\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}{fc67e7a0}) (Version: - ZPremiumLite) <==== ATTENTION Skype Click to Call (HKLM-x32\...\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 6.12.13601 - Skype Technologies S.A.) SkypeTalking 0.9.6 (HKLM-x32\...\SkypeTalking_is1) (Version: 0.9.6 - Hrvoje Katić) Skype™ 7.0 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.) Sony PC Companion 2.10.259 (HKLM-x32\...\{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}) (Version: 2.10.259 - Sony) swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 16.5.3.3 - Synaptics Incorporated) The Sims 4 (HKLM-x32\...\VGhlU2ltczQ=_is1) (Version: 1 - ) The Sims™ 3 (HKLM-x32\...\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}) (Version: 1.0.615 - Electronic Arts) The Sims™ 4 (HKLM-x32\...\{48EBEBBF-B9F8-4520-A3CF-89A730721917}) (Version: 1.0.732.20 - Electronic Arts Inc.) The Treasures of Mystery Island: The Ghost Ship (x32 Version: 2.2.0.98 - WildTangent) Hidden Trinklit Supreme (x32 Version: 2.2.0.98 - WildTangent) Hidden TuneUp Utilities 2013 (x32 Version: 13.0.3000.138 - TuneUp Software) Hidden TuneUp Utilities Language Pack (en-US) (x32 Version: 13.0.3000.138 - TuneUp Software) Hidden Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update Installer for WildTangent Games App (x32 Version: - WildTangent) Hidden VLC media player 1.1.2 (HKLM-x32\...\VLC media player) (Version: 1.1.2 - VideoLAN) Web Cake 3.00 (HKLM\...\{C4ED781C-7394-4906-AAFF-D6AB64FF7C38}) (Version: 3.00 - Web Cake LLC) WildTangent Games (HKLM-x32\...\WildTangent wildgames Master Uninstall) (Version: 1.0.3.0 - WildTangent) WildTangent Games App (x32 Version: 4.0.9.7 - WildTangent) Hidden Windows Driver Package - Nokia pccsmcfd LegacyDriver (05/31/2012 7.1.2.0) (HKLM\...\62BBD193ADFDBB228C7E1ADB56463F5732FF7F6F) (Version: 05/31/2012 7.1.2.0 - Nokia) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3503.0728 - Microsoft Corporation) WinRAR 4.01 (HKLM-x32\...\WinRAR 4.01) (Version: - ) WordWeb Pro (HKLM-x32\...\WordWeb) (Version: 6 - WordWeb Software) Youda Jewel Shop (x32 Version: 3.0.2.32 - WildTangent) Hidden Zuma's Revenge (x32 Version: 2.2.0.98 - WildTangent) Hidden ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-1071033344-2270758295-2084488698-1002_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\Rooha\AppData\Local\Microsoft\SkyDrive\17.0.4041.0512\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1071033344-2270758295-2084488698-1002_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\Rooha\AppData\Local\Microsoft\SkyDrive\17.0.4041.0512\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1071033344-2270758295-2084488698-1002_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\Rooha\AppData\Local\Microsoft\SkyDrive\17.0.4041.0512\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1071033344-2270758295-2084488698-1002_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\Rooha\AppData\Local\Microsoft\SkyDrive\17.0.4041.0512\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1071033344-2270758295-2084488698-1002_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Rooha\AppData\Local\Microsoft\SkyDrive\17.0.4041.0512\amd64\FileSyncApi64.dll (Microsoft Corporation) ==================== Restore Points ========================= ATTENTION: System Restore is disabled 26-06-2015 15:50:11 Windows Update 29-06-2015 22:37:39 Software Removal Tool 07-07-2015 16:32:40 avast! antivirus system restore point 07-07-2015 17:43:31 avast! antivirus system restore point 07-07-2015 18:12:49 avast! antivirus system restore point 08-07-2015 10:28:44 Restore Operation ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2013-08-22 18:55 - 2013-08-22 18:55 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {02AD2BB6-1870-4C66-A01B-7F1A44EB94D8} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1071033344-2270758295-2084488698-1002UA => C:\Users\Rooha\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-10-05] (Facebook Inc.) Task: {0568C803-6E74-4882-8B5D-E60492B7A61B} - System32\Tasks\00e1002c-7029-4aa8-96af-5a4f99b861b7-3 => C:\Program Files (x86)\Torntv V9.0\00e1002c-7029-4aa8-96af-5a4f99b861b7-3.exe <==== ATTENTION Task: {08F333DE-B5DC-4770-BAA1-0E21F9B793D3} - System32\Tasks\Synaptics TouchPad Enhancements => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2014-03-26] (Synaptics Incorporated) Task: {15AD3020-80D2-4254-A037-8CDE7A4C97AB} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 => C:\Program Files (x86)\TuneUp Utilities 2013\OneClick.exe Task: {2BBF2296-1230-4470-BE08-551C98546D36} - System32\Tasks\a7982934-0630-49b5-bdb1-d23d83f53ffd-1 => C:\Program Files (x86)\Torntv V9.0\Torntv V9.0-codedownloader.exe <==== ATTENTION Task: {2F4D5AFC-06F7-429E-B3A6-EEE12A459226} - System32\Tasks\MirageAgent => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [2012-10-13] (CyberLink) Task: {2FD3507B-680A-4379-BFEB-0CDE035E6463} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-09-28] (Hewlett-Packard Company) Task: {3689CACA-DE74-4AE8-8794-9EAE18DF477D} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-06-27] (Adobe Systems Incorporated) Task: {4AD18C2F-140F-4773-AB3E-51DCC47B5284} - System32\Tasks\00e1002c-7029-4aa8-96af-5a4f99b861b7-5 => C:\Program Files (x86)\Torntv V9.0\00e1002c-7029-4aa8-96af-5a4f99b861b7-5.exe <==== ATTENTION Task: {4DCBC018-CD5E-4391-84B6-321A2F6344F8} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-09-28] (Hewlett-Packard Company) Task: {52DEAADE-D4AE-42FA-9197-B386D0C6FB9C} - System32\Tasks\CLMLSvc_P2G8 => C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [2012-06-08] (CyberLink) Task: {58611162-48EB-4A23-8947-49824DFC4048} - System32\Tasks\HPCeeScheduleForRooha => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14] (Hewlett-Packard) Task: {5A32284A-997F-4F91-8DB3-AC02A3C0FE88} - System32\Tasks\a7982934-0630-49b5-bdb1-d23d83f53ffd-7 => C:\Program Files (x86)\Torntv V9.0\Torntv V9.0-nova.exe [2014-05-19] (installdaddy) <==== ATTENTION Task: {5D3A5308-39A1-492E-9BC0-33F208E9A4B3} - System32\Tasks\a7982934-0630-49b5-bdb1-d23d83f53ffd-6 => C:\Program Files (x86)\Torntv V9.0\Torntv V9.0-novainstaller.exe <==== ATTENTION Task: {68C8BC4F-4529-4CCA-8D31-17BECCA42A92} - System32\Tasks\a7982934-0630-49b5-bdb1-d23d83f53ffd-4 => C:\Program Files (x86)\Torntv V9.0\a7982934-0630-49b5-bdb1-d23d83f53ffd-4.exe <==== ATTENTION Task: {71E68D3D-8146-4973-89D3-F4D161377E50} - System32\Tasks\{1A862BAF-4EEF-4748-BF58-0AE9C5832814} => pcalua.exe -a C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_16_0_0_257_Plugin.exe -c -maintain plugin Task: {7266C889-5E94-451E-A5D3-6619743E0C46} - System32\Tasks\kin_kon_updating_service => C:\Program Files (x86)\kin kon\kin_kon_updating_service.exe [2015-04-11] () <==== ATTENTION Task: {75AC46A1-FF17-4DFB-9BD9-C701BD26569C} - System32\Tasks\00e1002c-7029-4aa8-96af-5a4f99b861b7-1 => C:\Program Files (x86)\Torntv V9.0\Torntv V9.0-codedownloader.exe <==== ATTENTION Task: {7FCCFD59-C206-4A92-B817-E889AFA047CB} - System32\Tasks\globalUpdateUpdateTaskMachineUA => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-05-19] (globalUpdate) <==== ATTENTION Task: {85F4F4E6-F187-4761-A3F1-1931E4FD280C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-06-29] (Google Inc.) Task: {984A2477-3958-4BF7-B72A-61EA2557A8D1} - System32\Tasks\00e1002c-7029-4aa8-96af-5a4f99b861b7-2 => C:\Program Files (x86)\Torntv V9.0\00e1002c-7029-4aa8-96af-5a4f99b861b7-2.exe <==== ATTENTION Task: {9E2F918D-1BE6-4AFB-A984-FC4EF2BCFC2E} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {A5A1448A-49F7-4950-9F59-BC5D0B4D5BFA} - System32\Tasks\Express FilesUpdate => C:\Program Files (x86)\ExpressFiles\EFUpdater.exe <==== ATTENTION Task: {B0F0F4F8-7E62-445C-8F61-3B2CCC17030B} - System32\Tasks\globalUpdateUpdateTaskMachineCore => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-05-19] (globalUpdate) <==== ATTENTION Task: {BF132375-BA23-44E5-9DCA-8696F1DF42AD} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-06-12] (Adobe Systems Incorporated) Task: {C03BC193-FF4A-45CA-8191-9EB46AFBDB25} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1071033344-2270758295-2084488698-1002Core => C:\Users\Rooha\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-10-05] (Facebook Inc.) Task: {CCC3D31C-74F6-4D4D-9642-F5FC94F0CCF0} - System32\Tasks\BitGuard => Sc.exe start BitGuard <==== ATTENTION Task: {E3F75113-8956-44FE-80B1-883962C0C47B} - System32\Tasks\kin_kon_notification_service => C:\Program Files (x86)\kin kon\kin_kon_notification_service.exe [2015-04-11] (FileProperties_CompanyName) <==== ATTENTION Task: {E7094F26-2328-4D10-9289-B98A8F476615} - System32\Tasks\godzilla_shopper_helper_service => C:\Program Files (x86)\Godzilla Shopper\godzilla_shopper_helper_service.exe [2015-05-30] () Task: {F1660DD6-FB8C-4C94-A9A8-C0F414FB2DC4} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-06-29] (Google Inc.) Task: {F1DE634A-09F8-4B7D-96D7-A7B02FE8F7E8} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2014-05-12] (Hewlett-Packard Company) Task: {F61FF7BB-9190-4EAE-8D5C-7D969F71C466} - System32\Tasks\a7982934-0630-49b5-bdb1-d23d83f53ffd-5 => C:\Program Files (x86)\Torntv V9.0\a7982934-0630-49b5-bdb1-d23d83f53ffd-5.exe <==== ATTENTION Task: {F9682A30-416E-4AFD-AF8E-00F50FF079AD} - System32\Tasks\00e1002c-7029-4aa8-96af-5a4f99b861b7-4 => C:\Program Files (x86)\Torntv V9.0\00e1002c-7029-4aa8-96af-5a4f99b861b7-4.exe <==== ATTENTION Task: {F9ED8A6D-231C-484B-A511-6596333398AB} - System32\Tasks\a7982934-0630-49b5-bdb1-d23d83f53ffd-2 => C:\Program Files (x86)\Torntv V9.0\a7982934-0630-49b5-bdb1-d23d83f53ffd-2.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\00e1002c-7029-4aa8-96af-5a4f99b861b7-1.job => C:\Program Files (x86)\Torntv V9.0\Torntv V9.0-codedownloader.exeù/KNosn /ceSvSK=task /heUCr='Torntv V9.0' /PpSKBO=51390 /FqNnsylxw='001062' /asCBYCeX='0' /tdZTLM='0' /rYJRMSPK=A7D4542B86C64E07BB199650E3828318IE /GjLwxmx=777c5f7570c4f523c58da29776173d9b /vTpzEx=1_34_3_28 /eUIoWTDb=1.34.3.28 /owweQb=1398707470 /awRUFZ=http:/stats.clientdemocloud.com /dGfIRu=http:/errors.clientdemocloud.com /XdRbiHzea=http:/cr.install-daddy.com /pGPTYifb=ch /teQgT /XDdFXOUod='http:/update.clientdemocloud.com/ie_code_agent_updates/{CAMP_ID}/update.jso <==== ATTENTION Task: C:\WINDOWS\Tasks\00e1002c-7029-4aa8-96af-5a4f99b861b7-2.job => C:\Program Files (x86)\Torntv V9.0\00e1002c-7029-4aa8-96af-5a4f99b861b7-2.exeß/XoCWy /heUCr='Torntv V9.0' /PpSKBO=51390 /FqNnsylxw='001062' /asCBYCeX='0' /tdZTLM='0' /rYJRMSPK=A7D4542B86C64E07BB199650E3828318IE /GjLwxmx=777c5f7570c4f523c58da29776173d9b /vTpzEx=1_34_3_28 /owweQb=1398707470 /awRUFZ=http:/stats.clientdemocloud.com /dGfIRu=http:/errors.clientdemocloud.com /cYArD=11111111-1111-1111-1111-110511131190 /pGPTYifb=ch /teQgT /XDdFXOUod='http:/update.clientdemocloud.com/ie_enable_agent_updates/{CAMP_ID}/update.jso <==== ATTENTION Task: C:\WINDOWS\Tasks\00e1002c-7029-4aa8-96af-5a4f99b861b7-3.job => C:\Program Files (x86)\Torntv V9.0\00e1002c-7029-4aa8-96af-5a4f99b861b7-3.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\00e1002c-7029-4aa8-96af-5a4f99b861b7-4.job => C:\Program Files (x86)\Torntv V9.0\00e1002c-7029-4aa8-96af-5a4f99b861b7-4.exe®/zbLvJxp /heUCr='Torntv V9.0' /LwCYe C:\Program Files (x86)\Torntv V9.0\51390.xpi' /PpSKBO=51390 /FqNnsylxw='001062' /asCBYCeX='0' /tdZTLM='0' /rYJRMSPK=A7D4542B86C64E07BB199650E3828318IE /GjLwxmx=777c5f7570c4f523c58da29776173d9b /vTpzEx=1_34_3_28 /eUIoWTDb=1.34.3.28 /owweQb=1398707470 /awRUFZ=http:/stats.clientdemocloud.com /dGfIRu=http:/errors.clientdemocloud.com /PJmiDDcv=300 /krczaMzH=5a6bf058-b978-4b84-a2ec-6f5462cfccb2@10120365-d3c0-4ec9-8624-5fac2592d0df.com /QENJRXKAQ=0.94 /GVDAy=a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390 /LpxRXSk=https:/w9u6a2p6.ssl.hwcdn.net/plugin/ff/update/51390.rdf /nNiSqAI='Torntv V9.0' /dLGCLWsIV='The must-have App extensions for Television fans! Watch free TV channels, live sports and more' /lDyVOM='installdaddy' /pGPTYifb=ch /teQgT /zZpAkr /kHGMgPVW /XDdFXOUod='http:/update.clientdemocloud.com/ff_agent_updates/{CAMP_ID}/update.jso <==== ATTENTION Task: C:\WINDOWS\Tasks\00e1002c-7029-4aa8-96af-5a4f99b861b7-5.job => C:\Program Files (x86)\Torntv V9.0\00e1002c-7029-4aa8-96af-5a4f99b861b7-5.exe/GZvOTW /heUCr='Torntv V9.0' /PpSKBO=51390 /FqNnsylxw='001062' /asCBYCeX='0' /tdZTLM='0' /rYJRMSPK=A7D4542B86C64E07BB199650E3828318IE /GjLwxmx=777c5f7570c4f523c58da29776173d9b /vTpzEx=1_34_3_28 /owweQb=1398707470 /awRUFZ=http:/stats.clientdemocloud.com /dGfIRu=http:/errors.clientdemocloud.com /QXhcmrQ=http:/ipgeoapi.com/ /bmVVI=http:/update.clientdemocloud.com /dlzwP=2 /UMGJC=http:/logs.clientdemocloud.com /XDdFXOUod='http:/update.clientdemocloud.com/updater_agent_updates/{CAMP_ID}/update.jso <==== ATTENTION Task: C:\WINDOWS\Tasks\a7982934-0630-49b5-bdb1-d23d83f53ffd-1.job => C:\Program Files (x86)\Torntv V9.0\Torntv V9.0-codedownloader.exeø/PEkTOtrv /BEgyH=task /SBwmFc='Torntv V9.0' /BBlBcB=51390 /LpWwwgnS='001062' /WvheJND='0' /ucLho='0' /fflpXyJRs=A7D4542B86C64E07BB199650E3828318IE /gRMsA=777c5f7570c4f523c58da29776173d9b /oxPbBmKZ=1_34_05_12 /nflasGzBy=1.34.5.12 /MNGad=1400518182 /KAWIFfEy=http:/stats.clientstaticserv.com /LlrQwPe=http:/errors.clientstaticserv.com /dxMDrPipt=http:/cr.install-daddy.com /PviVuL=ch /Vzwlk /zUjti='http:/update.clientstaticserv.com/ie_code_agent_updates/{CAMP_ID}/update.jso <==== ATTENTION Task: C:\WINDOWS\Tasks\a7982934-0630-49b5-bdb1-d23d83f53ffd-2.job => C:\Program Files (x86)\Torntv V9.0\a7982934-0630-49b5-bdb1-d23d83f53ffd-2.exeß/rrjVClNe /SBwmFc='Torntv V9.0' /BBlBcB=51390 /LpWwwgnS='001062' /WvheJND='0' /ucLho='0' /fflpXyJRs=A7D4542B86C64E07BB199650E3828318IE /gRMsA=777c5f7570c4f523c58da29776173d9b /oxPbBmKZ=1_34_05_12 /MNGad=1400518182 /KAWIFfEy=http:/stats.clientstaticserv.com /LlrQwPe=http:/errors.clientstaticserv.com /PIppLG=11111111-1111-1111-1111-110511131190 /PviVuL=ch /Vzwlk /zUjti='http:/update.clientstaticserv.com/ie_enable_agent_updates/{CAMP_ID}/update.jso <==== ATTENTION Task: C:\WINDOWS\Tasks\a7982934-0630-49b5-bdb1-d23d83f53ffd-4.job => C:\Program Files (x86)\Torntv V9.0\a7982934-0630-49b5-bdb1-d23d83f53ffd-4.exe³/JkozhpUYu /SBwmFc='Torntv V9.0' /lAPnyfXfh C:\Program Files (x86)\Torntv V9.0\51390.xpi' /BBlBcB=51390 /LpWwwgnS='001062' /WvheJND='0' /ucLho='0' /fflpXyJRs=A7D4542B86C64E07BB199650E3828318IE /gRMsA=777c5f7570c4f523c58da29776173d9b /oxPbBmKZ=1_34_05_12 /nflasGzBy=1.34.5.12 /MNGad=1400518182 /KAWIFfEy=http:/stats.clientstaticserv.com /LlrQwPe=http:/errors.clientstaticserv.com /GdfOrZC=300 /jQrbw=5a6bf058-b978-4b84-a2ec-6f5462cfccb2@10120365-d3c0-4ec9-8624-5fac2592d0df.com /OBwmOGsiH=0.94 /wHxOilHE=a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390 /ExCEk=https:/w9u6a2p6.ssl.hwcdn.net/plugin/ff/update/51390.rdf /LFwkfeDs='Torntv V9.0' /cMpdDDSu='The must-have App extensions for Television fans! Watch free TV channels, live sports and more' /LMEWh='installdaddy' /PviVuL=ch /Vzwlk /vdCqigHFf /sUQQpUpj /zUjti='http:/update.clientstaticserv.com/ff_agent_updates/{CAMP_ID}/update.jso <==== ATTENTION Task: C:\WINDOWS\Tasks\a7982934-0630-49b5-bdb1-d23d83f53ffd-5.job => C:\Program Files (x86)\Torntv V9.0\a7982934-0630-49b5-bdb1-d23d83f53ffd-5.exe/JMriPzevx /SBwmFc='Torntv V9.0' /BBlBcB=51390 /LpWwwgnS='001062' /WvheJND='0' /ucLho='0' /fflpXyJRs=A7D4542B86C64E07BB199650E3828318IE /gRMsA=777c5f7570c4f523c58da29776173d9b /oxPbBmKZ=1_34_05_12 /MNGad=1400518182 /KAWIFfEy=http:/stats.clientstaticserv.com /LlrQwPe=http:/errors.clientstaticserv.com /KiMNO=http:/ipgeoapi.com/ /mRrSTLpUC=http:/update.clientstaticserv.com /mmmzpi=2 /MfNyMEV=http:/logs.clientstaticserv.com /zUjti='http:/update.clientstaticserv.com/updater_agent_updates/{CAMP_ID}/update.jso <==== ATTENTION Task: C:\WINDOWS\Tasks\a7982934-0630-49b5-bdb1-d23d83f53ffd-6.job => C:\Program Files (x86)\Torntv V9.0\Torntv V9.0-novainstaller.exeþ/bAScVrp /BEgyH=task /SBwmFc='Torntv V9.0' /BBlBcB=51390 /LpWwwgnS='001062' /WvheJND='0' /ucLho='0' /fflpXyJRs=A7D4542B86C64E07BB199650E3828318IE /gRMsA=777c5f7570c4f523c58da29776173d9b /oxPbBmKZ=1_34_05_12 /nflasGzBy=1.34.5.12 /MNGad=1400517984 /KAWIFfEy=http:/stats.clientstaticserv.com /LlrQwPe=http:/errors.clientstaticserv.com /dxMDrPipt=http:/cr.install-daddy.com /PviVuL=ch /QwjVucGTf /ZgHbvep='nova' /zUjti='http:/update.clientstaticserv.com/novacode/{CAMP_ID}/update.jso <==== ATTENTION Task: C:\WINDOWS\Tasks\a7982934-0630-49b5-bdb1-d23d83f53ffd-7.job => C:\Program Files (x86)\Torntv V9.0\Torntv V9.0-nova.exeè/SBwmFc='Torntv V9.0' /BBlBcB=51390 /LpWwwgnS='001062' /WvheJND='0' /ucLho='0' /fflpXyJRs=A7D4542B86C64E07BB199650E3828318IE /gRMsA=777c5f7570c4f523c58da29776173d9b /oxPbBmKZ=1_34_05_12 /nflasGzBy=1.34.5.12 /MNGad=1400517984 /KAWIFfEy=http:/stats.clientstaticserv.com /LlrQwPe=http:/errors.clientstaticserv.com /dxMDrPipt=http:/cr.install-daddy.com /PviVuL=ch /QwjVucGTf /ZgHbvep='nova' /zUjti='http:/update.clientstaticserv.com/novarun/{CAMP_ID}/update.jso <==== ATTENTION Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-1071033344-2270758295-2084488698-1002Core.job => C:\Users\Rooha\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-1071033344-2270758295-2084488698-1002UA.job => C:\Users\Rooha\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\WINDOWS\Tasks\globalUpdateUpdateTaskMachineCore.job => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\globalUpdateUpdateTaskMachineUA.job => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\godzilla_shopper_helper_service.job => C:\Program Files (x86)\Godzilla Shopper\godzilla_shopper_helper_service.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\HPCeeScheduleForRooha.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe Task: C:\WINDOWS\Tasks\kin_kon_notification_service.job => C:\Program Files (x86)\kin kon\kin_kon_notification_service.exeã/url='http:/cdn.selectbestopt.com/notf_sys/index.html' /crregname='kin kon' /appid='73143' /srcid='2913' /bic='cfc1cf92c617791b53a6d97e3b63a5ec' /verifier='36e5a9867e47f351c9b19d08ba952cdb' /installerversion='1.50.3.10' /statsdomain='http:/stats.buildomserv.com/data.gif?' /errorsdomain='http:/stats.buildomserv.com/data.gif?' /monetizationdomain='http:/logs.buildomserv.com/monetization.gif <==== ATTENTION Task: C:\WINDOWS\Tasks\kin_kon_updating_service.job => C:\Program Files (x86)\kin kon\kin_kon_updating_service.exe¨ /campid=2913 /verid=1 /url=http:/cdn.buildomserv.com/txt/@CAMPID@/@VER@/file.txt /appid=73143 /taskname=kin_kon_updating_service /funurl=http:/stats.buildomserv.com <==== ATTENTION Task: C:\WINDOWS\Tasks\Synaptics TouchPad Enhancements.job => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe ==================== Loaded Modules (Whitelisted) ============== 2014-07-04 21:33 - 2014-07-04 21:33 - 00127488 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.Wlan.dll 2015-02-13 04:20 - 2015-02-13 04:20 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2015-02-13 04:20 - 2015-02-13 04:20 - 01346344 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2012-09-19 18:37 - 2012-09-19 18:37 - 00017160 _____ () C:\Windows\system32\BsHelpCSps.dll 2012-09-19 18:37 - 2012-09-19 18:37 - 00029960 _____ () C:\Windows\system32\BsTrace.dll 2015-05-30 22:26 - 2015-05-30 22:26 - 00191696 _____ () C:\Program Files (x86)\Godzilla Shopper\godzilla_shopper_helper_service.exe 2013-11-27 22:31 - 2014-06-23 09:07 - 00113376 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe 2014-07-04 21:33 - 2014-07-04 21:33 - 00102400 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll 2014-06-24 09:37 - 2014-06-24 09:37 - 00661752 _____ () C:\Program Files (x86)\Common Files\Research In Motion\nginx\nginx.exe 2012-09-19 18:37 - 2012-09-19 18:37 - 00029960 _____ () C:\WINDOWS\SYSTEM32\BsTrace.dll 2012-09-19 18:37 - 2012-09-19 18:37 - 00017160 _____ () C:\Windows\SYSTEM32\BsHelpCSps.dll 2012-09-19 18:37 - 2012-09-19 18:37 - 00062216 _____ () C:\Windows\SYSTEM32\BlueSoleilCSps.dll 2012-09-24 14:27 - 2012-09-24 14:27 - 00335176 _____ () C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\Driver\USB\tl_filter.dll 2012-05-02 17:28 - 2012-05-02 17:28 - 00012800 _____ () C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\Driver\AMP\IVTAMPRL.dll 2013-07-21 13:12 - 2012-12-06 07:41 - 00107520 _____ () C:\Program Files (x86)\DAEMON Tools Pro\BRD.dll 2013-07-21 13:00 - 2011-07-13 21:06 - 00022800 ____N () C:\Program Files (x86)\WordWeb\WUCNT.dll 2013-11-27 22:31 - 2012-04-30 11:57 - 00039936 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\TMonitorAPI.dll 2013-11-27 22:31 - 2014-12-04 15:18 - 00241152 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\MExplorer.dll 2011-07-07 14:54 - 2011-07-07 14:54 - 00233984 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\Report.dll 2013-11-27 22:31 - 2013-05-20 12:58 - 00620718 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\sqlite3.dll 2013-11-27 22:31 - 2010-01-11 16:44 - 00053248 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\VObject.dll 2014-11-21 12:31 - 2014-11-21 12:31 - 00663040 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\PhoneUpdate.dll 2012-09-19 18:37 - 2012-09-19 18:37 - 00079624 _____ () C:\WINDOWS\SYSTEM32\BsProfilefunc.dll 2012-09-19 18:37 - 2012-09-19 18:37 - 00363784 _____ () C:\WINDOWS\SYSTEM32\BsExtendFunc.dll 2013-07-22 00:16 - 2012-06-08 09:04 - 00627216 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMediaLibrary.dll 2012-06-09 00:04 - 2012-06-09 00:04 - 00016400 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvcPS.dll 2012-09-19 18:37 - 2012-09-19 18:37 - 00029960 _____ () C:\Windows\SYSTEM32\BsTrace.dll 2012-04-24 20:18 - 2012-04-24 20:18 - 01242472 _____ () C:\Program Files (x86)\Safari\Apple Application Support\libxml2.dll 2012-04-24 20:18 - 2012-04-24 20:18 - 00087912 _____ () C:\Program Files (x86)\Safari\Apple Application Support\zlib1.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\Users\Rooha\OneDrive:ms-properties ==================== Safe Mode (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-1071033344-2270758295-2084488698-1002\Control Panel\Desktop\\Wallpaper -> C:\Users\Rooha\Pictures\sasuke_and_itachi_by_kujaex.jpg DNS Servers: 192.168.1.1 ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) MSCONFIG\Services: AMD External Events Utility => 2 MSCONFIG\Services: AMD FUEL Service => 2 MSCONFIG\Services: BlueSoleilCS => 2 MSCONFIG\Services: Bonjour Service => 2 MSCONFIG\Services: BsHelpCS => 3 MSCONFIG\Services: GamesAppIntegrationService => 2 MSCONFIG\Services: GamesAppService => 3 MSCONFIG\Services: globalUpdate => 2 MSCONFIG\Services: globalUpdatem => 3 MSCONFIG\Services: gupdate => 2 MSCONFIG\Services: gupdatem => 3 MSCONFIG\Services: gusvc => 3 MSCONFIG\Services: HP Support Assistant Service => 2 MSCONFIG\Services: HPConnectedRemote => 2 MSCONFIG\Services: hpqwmiex => 3 MSCONFIG\Services: hpsrv => 2 MSCONFIG\Services: HPWMISVC => 2 MSCONFIG\Services: IconMan_R => 2 MSCONFIG\Services: Nero BackItUp Scheduler 4.0 => 2 MSCONFIG\Services: ServiceLayer => 3 MSCONFIG\Services: Skype C2C Service => 2 MSCONFIG\Services: SkypeUpdate => 2 MSCONFIG\Services: Sony PC Companion => 3 MSCONFIG\Services: STacSV => 2 HKLM\...\StartupApproved\StartupFolder: => "McAfee Security Scan Plus.lnk" HKLM\...\StartupApproved\Run32: => "Adobe Reader Speed Launcher" HKLM\...\StartupApproved\Run32: => "GrooveMonitor" HKLM\...\StartupApproved\Run32: => "Adobe ARM" HKU\S-1-5-21-1071033344-2270758295-2084488698-1002\...\StartupApproved\Run: => "NokiaSuite.exe" HKU\S-1-5-21-1071033344-2270758295-2084488698-1002\...\StartupApproved\Run: => "KiesHelper" HKU\S-1-5-21-1071033344-2270758295-2084488698-1002\...\StartupApproved\Run: => "KiesTrayAgent" HKU\S-1-5-21-1071033344-2270758295-2084488698-1002\...\StartupApproved\Run: => "KiesPDLR" HKU\S-1-5-21-1071033344-2270758295-2084488698-1002\...\StartupApproved\Run: => "WebCake Desktop" HKU\S-1-5-21-1071033344-2270758295-2084488698-1002\...\StartupApproved\Run: => "SkyDrive" HKU\S-1-5-21-1071033344-2270758295-2084488698-1002\...\StartupApproved\Run: => "Skype" HKU\S-1-5-21-1071033344-2270758295-2084488698-1002\...\StartupApproved\Run: => "Pbxsxh" HKU\S-1-5-21-1071033344-2270758295-2084488698-1002\...\StartupApproved\Run: => "Adobe System Incorporated" HKU\S-1-5-21-1071033344-2270758295-2084488698-1002\...\StartupApproved\Run: => "Torntv Downloader" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [{1CBFC03C-D14D-4B5C-94CE-016A2320A811}] => (Allow) C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BlueSoleilCS.exe FirewallRules: [{FCE61627-0341-4255-84B3-B8C3DDEE1DC9}] => (Allow) C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BlueSoleilCS.exe FirewallRules: [UDP Query User{45D035DD-82A7-4101-8B9C-F47C71984488}C:\program files (x86)\r.g. mechanics\outlast\binaries\win64\olgame.exe] => (Allow) C:\program files (x86)\r.g. mechanics\outlast\binaries\win64\olgame.exe FirewallRules: [TCP Query User{BD84C5D3-0380-450C-B624-1A8FBBD2ED2E}C:\program files (x86)\r.g. mechanics\outlast\binaries\win64\olgame.exe] => (Allow) C:\program files (x86)\r.g. mechanics\outlast\binaries\win64\olgame.exe FirewallRules: [{77CFE4EE-2CC0-4149-8351-1961ACCD5D38}] => (Allow) C:\Users\Rooha\AppData\Local\Facebook\Video\Skype\FacebookVideoCalling.exe FirewallRules: [{51E75F42-2B9B-417C-9697-1AEF291044CF}] => (Allow) LPort=52000 FirewallRules: [{F91CEF9A-988D-4ED3-B911-81D5486A7B3D}] => (Allow) LPort=53000 FirewallRules: [UDP Query User{3EEDFEE2-13DC-40DF-8CE5-A41DC75AF928}C:\program files (x86)\torntv.com\torntv downloader.exe] => (Allow) C:\program files (x86)\torntv.com\torntv downloader.exe FirewallRules: [TCP Query User{1FDA1AB8-08BB-4DED-ADE6-2A2ECBDCACCE}C:\program files (x86)\torntv.com\torntv downloader.exe] => (Allow) C:\program files (x86)\torntv.com\torntv downloader.exe FirewallRules: [UDP Query User{8F7D1CDB-E1C8-472B-A0C6-3966A3989F67}C:\program files (x86)\torntv.com\torntv downloader.exe] => (Allow) C:\program files (x86)\torntv.com\torntv downloader.exe FirewallRules: [TCP Query User{3D95EC16-02CD-44B7-89F7-BB27E93D43FD}C:\program files (x86)\torntv.com\torntv downloader.exe] => (Allow) C:\program files (x86)\torntv.com\torntv downloader.exe FirewallRules: [UDP Query User{39F51D08-B21A-43F3-A44C-33FC66BF9DC9}C:\users\rooha\downloads\programs\utorrent.exe] => (Block) C:\users\rooha\downloads\programs\utorrent.exe FirewallRules: [TCP Query User{9A10910D-A88C-4055-9760-306AB7D744B4}C:\users\rooha\downloads\programs\utorrent.exe] => (Block) C:\users\rooha\downloads\programs\utorrent.exe FirewallRules: [{CB9A3EEE-FD8B-4F06-BAA8-407919B3680B}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD10.EXE FirewallRules: [UDP Query User{0BBAF316-F154-4482-A4F0-716327487279}C:\users\rooha\downloads\programs\utorrent.exe] => (Block) C:\users\rooha\downloads\programs\utorrent.exe FirewallRules: [TCP Query User{BD1BEA32-82E8-4B4B-93EA-B32BA8BBE443}C:\users\rooha\downloads\programs\utorrent.exe] => (Block) C:\users\rooha\downloads\programs\utorrent.exe FirewallRules: [{04F14D0E-B968-4D45-B6BB-A6C9061388E6}] => (Allow) C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BlueSoleilCS.exe FirewallRules: [{1EAEFA0D-AB94-4720-80BF-64FEFEC92980}] => (Allow) C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BlueSoleilCS.exe FirewallRules: [UDP Query User{BDC037BF-BBCF-420D-8350-A53FBAAA3590}C:\users\rooha\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\rooha\appdata\roaming\utorrent\utorrent.exe FirewallRules: [TCP Query User{B4C32DCF-0D71-4D5B-84A0-538DEA6C1D81}C:\users\rooha\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\rooha\appdata\roaming\utorrent\utorrent.exe FirewallRules: [{127DE025-A80E-4750-9A1D-F51C6AC24E9A}] => (Block) C:\program files (x86)\electronic arts\eadm\core.exe FirewallRules: [{C9EB3554-CA63-43A5-BB61-02FE2FEBBE3F}] => (Block) C:\program files (x86)\electronic arts\eadm\core.exe FirewallRules: [UDP Query User{FFCACE2D-7043-4EFE-949B-850F1DF9108E}C:\program files (x86)\electronic arts\eadm\core.exe] => (Allow) C:\program files (x86)\electronic arts\eadm\core.exe FirewallRules: [TCP Query User{6B4EB7D7-2015-4C69-8A52-51098EA5A2E2}C:\program files (x86)\electronic arts\eadm\core.exe] => (Allow) C:\program files (x86)\electronic arts\eadm\core.exe FirewallRules: [UDP Query User{33853B7D-8637-4845-A8F1-8C7EED87C871}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe FirewallRules: [TCP Query User{D9610EA2-48DC-4EA8-A31E-59A9689BA900}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe FirewallRules: [UDP Query User{5FF21810-E90F-438B-99FD-34CF9B71596F}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe FirewallRules: [TCP Query User{EDABF1AC-2466-4F31-B870-4F7660AC2C9E}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe FirewallRules: [{D8EC283A-4187-483E-9893-707FA8053B75}] => (Allow) C:\ProgramData\eSafe\eGdpSvc.exe FirewallRules: [{72A5521F-7971-43F5-B71F-3E8F8B22DC11}] => (Allow) C:\Windows\SysWOW64\muzapp.exe FirewallRules: [{72FFD9D5-84DC-42F5-BE1B-C6FD433729AD}] => (Allow) C:\Windows\SysWOW64\muzapp.exe FirewallRules: [{BDFF08A8-C3C3-4AC1-9E4E-1A07ACCB4B9F}] => (Allow) C:\Program Files (x86)\nokia\nokia suite\nokiasuite.exe FirewallRules: [{94CE92B6-8DAD-40F7-9DCB-BABF7170CAE9}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDirector10\PDR10.EXE FirewallRules: [{E1D098E1-8421-41E8-87DA-19DA9F54560A}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{33513171-C20B-4009-9D7D-FE5AB79F00DD}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{4E471BA6-D1B1-48AB-BAF7-33D9334602DB}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{CEF65F31-D852-453D-A5CA-508F9527663F}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{AAA0149F-039E-4879-817A-7C4BA4BEE466}] => (Allow) LPort=1900 FirewallRules: [{8830760E-A9CD-4307-8671-64645A191381}] => (Allow) LPort=2869 FirewallRules: [{302D2D2E-579F-43BD-9158-738DA670E4BF}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe FirewallRules: [{74AE8CB3-ACDF-4ECE-827E-04E1E4845E14}] => (Allow) C:\Program Files\iTunes\iTunes.exe FirewallRules: [{71170E0B-B191-4069-B2C8-17C4454B1679}] => (Allow) C:\Program Files (x86)\Common Files\Research In Motion\Tunnel Manager\tunmgr.exe FirewallRules: [{2BF60F5A-5057-4873-A536-2C699C17BDD0}] => (Allow) C:\Program Files (x86)\Common Files\Research In Motion\Tunnel Manager\tunmgr.exe FirewallRules: [{900F5336-5C3A-45C3-972F-BC535BB4BDE5}] => (Allow) C:\Program Files (x86)\Common Files\Research In Motion\Tunnel Manager\mDNSResponder.exe FirewallRules: [{71BC3059-7717-4EFC-A46C-FAAEAB8BC811}] => (Allow) C:\Program Files (x86)\Common Files\Research In Motion\Tunnel Manager\mDNSResponder.exe FirewallRules: [{2A5B9833-55F1-49D8-BDDD-C8A36274AE82}] => (Allow) C:\Program Files (x86)\Common Files\Research In Motion\nginx\nginx.exe FirewallRules: [{6E90766E-9C1B-4111-AE80-E79C8D35BC62}] => (Allow) C:\Program Files (x86)\Common Files\Research In Motion\Tunnel Manager\PeerManager.exe FirewallRules: [{C881B36B-284F-4A36-B2F6-F0E96B2857D8}] => (Allow) C:\Program Files (x86)\The Sims 4\Game\Bin\TS4.exe FirewallRules: [{851E3F66-71F9-43D8-9250-707279529902}] => (Allow) C:\Program Files (x86)\The Sims 4\Game\Bin\TS4.exe FirewallRules: [{02BD142F-06AD-492A-B44E-2030A3D10388}] => (Allow) C:\Program Files (x86)\The Sims 4\Game\Bin\TS4.exe FirewallRules: [{970B421D-917A-4034-85A3-A5BC07F68F85}] => (Allow) C:\Program Files (x86)\The Sims 4\Game\Bin\TS4.exe FirewallRules: [{8172EAE0-BC22-4A00-B6EE-941CA38ABF0C}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (07/08/2015 04:09:33 PM) (Source: RIM MDNS) (EventID: 100) (User: ) Description: 608: ERROR: read_msg errno 0 (The operation completed successfully.) Error: (07/08/2015 04:09:33 PM) (Source: RIM MDNS) (EventID: 100) (User: ) Description: ERROR: mDNSPlatformReadTCP - recv: 10053 Error: (07/08/2015 00:40:45 PM) (Source: ESENT) (EventID: 455) (User: ) Description: svchost (1512) SRUJet: Error -1811 (0xfffff8ed) occurred while opening logfile C:\WINDOWS\system32\SRU\SRU00622.log. Error: (07/08/2015 00:00:56 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Activation context generation failed for "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest1".Error in manifest or policy file "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest2" on line C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest3. A component version required by the application conflicts with another component version already active. Conflicting components are:. Component 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_6240b9c7ecbd0bda.manifest. Component 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17810_none_a9edf09f013934e0.manifest. Error: (07/08/2015 10:28:58 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image of binary avast! VM Monitor. System Error: The system cannot find the file specified. . Error: (07/08/2015 10:28:58 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image of binary aswSP. System Error: The system cannot find the file specified. . Error: (07/08/2015 10:28:58 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image of binary aswMonFlt. System Error: The system cannot find the file specified. . Error: (07/08/2015 10:28:58 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image of binary aswRdr. System Error: The system cannot find the file specified. . Error: (07/08/2015 10:28:58 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image of binary aswSnx. System Error: The system cannot find the file specified. . Error: (07/08/2015 10:25:11 AM) (Source: globalUpdate Update) (EventID: 1) (User: NT AUTHORITY) Description: globalUpdate Update has encountered a fatal error. ver=1.3.25.0.private;lang=en;id=;is_machine=1;upload=0;minidump=C:\Program Files (x86)\globalUpdate\CrashReports\8d30e5e3-0e31-4ee1-b2a9-e81b4fdbfeb2.dmp System errors: ============= Error: (07/08/2015 04:15:26 PM) (Source: NetBT) (EventID: 4321) (User: ) Description: The name "WORKGROUP :1d" could not be registered on the interface with IP address 169.254.128.196. The computer with the IP address 169.254.245.88 did not allow the name to be claimed by this computer. Error: (07/08/2015 04:09:42 PM) (Source: Schannel) (EventID: 4102) (User: NT AUTHORITY) Description: A fatal error occurred when attempting to access the SSL client credential private key. The error code returned from the cryptographic module is 0x8009030d. The internal error state is 10003. Error: (07/08/2015 04:09:42 PM) (Source: Schannel) (EventID: 4102) (User: NT AUTHORITY) Description: A fatal error occurred when attempting to access the SSL client credential private key. The error code returned from the cryptographic module is 0x8009030d. The internal error state is 10003. Error: (07/08/2015 04:09:40 PM) (Source: Schannel) (EventID: 4102) (User: NT AUTHORITY) Description: A fatal error occurred when attempting to access the SSL client credential private key. The error code returned from the cryptographic module is 0x8009030d. The internal error state is 10003. Error: (07/08/2015 00:03:06 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The Windows Defender Service service terminated unexpectedly. It has done this 5 time(s). Error: (07/08/2015 00:03:03 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The Windows Defender Service service terminated unexpectedly. It has done this 4 time(s). Error: (07/08/2015 00:00:53 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The Windows Defender Service service terminated unexpectedly. It has done this 3 time(s). Error: (07/08/2015 11:59:06 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The Windows Defender Service service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 100 milliseconds: Run the configured recovery program. Error: (07/08/2015 11:59:03 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The Windows Defender Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 100 milliseconds: Restart the service. Error: (07/08/2015 11:56:25 AM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY) Description: {752073A1-23F2-4396-85F0-8FDB879ED0ED} Microsoft Office: ========================= Error: (03/31/2015 05:49:40 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6718.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 116544 seconds with 4740 seconds of active time. This session ended with a crash. Error: (01/01/2015 05:26:06 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6713.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 1790 seconds with 0 seconds of active time. This session ended with a crash. Error: (09/24/2014 06:24:46 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6695.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 287091 seconds with 6120 seconds of active time. This session ended with a crash. Error: (05/30/2014 08:43:09 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6695.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 99 seconds with 0 seconds of active time. This session ended with a crash. Error: (05/09/2014 00:45:18 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6695.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 7277 seconds with 0 seconds of active time. This session ended with a crash. Error: (05/08/2014 02:58:03 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6695.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 234475 seconds with 3420 seconds of active time. This session ended with a crash. Error: (08/10/2013 09:42:08 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 3, Application Name: Microsoft Office PowerPoint, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 590 seconds with 540 seconds of active time. This session ended with a crash. CodeIntegrity Errors: =================================== Date: 2015-06-23 10:17:28.531 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-05-21 12:50:44.264 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-05-17 19:08:57.348 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-05-10 11:28:50.517 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-05-02 18:27:49.013 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-04-19 17:58:24.737 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-03-31 18:33:49.693 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-03-30 18:01:56.823 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-03-28 09:03:25.515 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-03-15 13:51:14.068 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. ==================== Memory info =========================== Processor: AMD A8-4500M APU with Radeon(tm) HD Graphics Percentage of memory in use: 40% Total physical RAM: 3554.26 MB Available physical RAM: 2097.23 MB Total Virtual: 7138.26 MB Available Virtual: 5488.84 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:290.5 GB) (Free:184.95 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive d: (RECOVERY) (Fixed) (Total:24.05 GB) (Free:2.91 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive e: (pAt!O oF fRol!C) (Fixed) (Total:150 GB) (Free:30.25 GB) NTFS Drive h: (The Sims 4) (CDROM) (Total:8.8 GB) (Free:0 GB) CDFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 465.8 GB) (Disk ID: D7477615) Partition: GPT Partition Type. ==================== End of log ============================