Additional scan result of Farbar Recovery Scan Tool (x86) Version:02-08-2015 01 Ran by inFidel (2015-08-06 18:06:04) Running from C:\Users\inFidel\Desktop Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-4041656617-1838989228-2178339868-500 - Administrator - Disabled) Guest (S-1-5-21-4041656617-1838989228-2178339868-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-4041656617-1838989228-2178339868-1004 - Limited - Enabled) inFidel (S-1-5-21-4041656617-1838989228-2178339868-1000 - Administrator - Enabled) => C:\Users\inFidel ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) µTorrent (HKU\S-1-5-21-4041656617-1838989228-2178339868-1000\...\uTorrent) (Version: 3.4.2.34024 - BitTorrent Inc.) ABBYY FineReader 9.0 Professional Edition (HKLM\...\{F9000000-0001-0000-0000-074957833700}) (Version: 9.00.662.5581 - ABBYY) Adobe AIR (HKLM\...\Adobe AIR) (Version: 1.5.3.9120 - Adobe Systems Inc.) Adobe Community Help (HKLM\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 3.0.0.400 - Adobe Systems Incorporated) Adobe Flash Player 18 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 18.0.0.209 - Adobe Systems Incorporated) Adobe Flash Player 18 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 18.0.0.209 - Adobe Systems Incorporated) Adobe Photoshop CC (HKLM\...\{2D99B50E-431D-4AA8-85C1-172A6F8BCF09}) (Version: 14.0 - Adobe Systems Incorporated) Adobe Reader X (10.1.15) MUI (HKLM\...\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.1.15 - Adobe Systems Incorporated) Adobe Shockwave Player 11.5 (HKLM\...\Adobe Shockwave Player) (Version: 11.5.9.620 - Adobe Systems, Inc.) Apple Application Support (HKLM\...\{21ECABC3-40B2-42DF-8E21-ACF3A4D0D95A}) (Version: 3.0.5 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{941B4CE7-3F5D-443E-A8B7-56A420D2EAFD}) (Version: 7.1.2.6 - Apple Inc.) Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) ATI Catalyst Install Manager (HKLM\...\{A930C335-3FC8-A452-B8CA-F3998969CA3A}) (Version: 3.0.829.0 - ATI Technologies, Inc.) Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.) Broadcom 802.11 Wireless LAN Adapter (HKLM\...\Broadcom 802.11 Wireless LAN Adapter) (Version: 5.100.82.86 - Broadcom Corporation) Broadcom Bluetooth Software (HKLM\...\{6E7F4CA3-B2DE-413C-A7A1-43AA5BE19EA1}) (Version: 6.5.0.1600 - Broadcom Corporation) Broadcom InConcert Maestro (HKLM\...\{57DD35E9-D9BB-4089-BB05-EF933C586CB3}) (Version: 1.0.1.1600 - Broadcom Corporation) CCleaner (HKLM\...\CCleaner) (Version: 4.15 - Piriform) Cheat Engine 6.4 (HKLM\...\Cheat Engine 6.4_is1) (Version: - Cheat Engine) CyberLink YouCam (HKLM\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.5.1.4305 - CyberLink Corp.) D3DX10 (Version: 15.4.2368.0902 - Microsoft) Hidden Dropbox (HKU\S-1-5-21-4041656617-1838989228-2178339868-1000\...\Dropbox) (Version: 3.8.5 - Dropbox, Inc.) ESU for Microsoft Windows 7 SP1 (HKLM\...\{E96CAA2A-0244-4A2A-8403-0C3C9534778B}) (Version: 2.1.1 - Hewlett-Packard) FileZilla Client 3.7.3 (HKLM\...\FileZilla Client) (Version: 3.7.3 - Tim Kosse) Futuremark SystemInfo (HKLM\...\{4115C9AA-35E0-45D8-9363-47635B8750C7}) (Version: 4.29.438.0 - Futuremark) Google Chrome (HKU\S-1-5-21-4041656617-1838989228-2178339868-1000\...\Google Chrome) (Version: 44.0.2403.125 - Google Inc.) Hewlett-Packard ACLM.NET v1.2.1.1 (Version: 1.00.0000 - Hewlett-Packard Company) Hidden HP 3D DriveGuard (HKLM\...\{5601F151-A69F-4E30-8C60-37928124CD07}) (Version: 4.1.9.1 - Hewlett-Packard Company) HP CoolSense (HKLM\...\{0D8B3696-E52D-4291-B833-9F6AEB1CC4AB}) (Version: 2.1.0 - Hewlett-Packard Company) HP Deskjet 1050 J410 series Basic Device Software (HKLM\...\{226837D8-0BF8-4CBE-BAB2-8F07E2C2B4DD}) (Version: 22.50.231.0 - Hewlett-Packard Co.) HP Deskjet 1050 J410 series Help (HKLM\...\{5C90D8CF-F12A-41C6-9007-3B651A1F0D78}) (Version: 140.0.66.66 - Hewlett Packard) HP Deskjet 1050 J410 series Product Improvement Study (HKLM\...\{7414C891-720D-4E86-85E5-C3AA898DA9EC}) (Version: 22.50.231.0 - Hewlett-Packard Co.) HP On Screen Display (HKLM\...\{D7670221-BF9B-4DFF-B26B-5BE55A87329F}) (Version: 1.2.2 - Hewlett-Packard Company) HP Power Manager (HKLM\...\{872B1C80-38EC-4A31-A25C-980820593900}) (Version: 1.2.3 - Hewlett-Packard Company) HP QuickWeb (HKLM\...\{57D8E376-0E8A-4AFD-9040-DA2D33B7FF94}) (Version: 3.1.0.9791 - Hewlett-Packard Company) HP Setup (HKLM\...\{5036764A-435D-40C9-869C-31085A3D741D}) (Version: 8.7.4751.3798 - Hewlett-Packard Company) HP Setup Manager (HKLM\...\{AE856388-AFAD-4753-81DF-D96B19D0A17C}) (Version: 1.1.13476.3753 - Hewlett-Packard Company) HP Software Framework (HKLM\...\{31EEA563-3544-4EA1-8773-BCBF83F9627A}) (Version: 4.1.8.1 - Hewlett-Packard Company) HP Support Assistant (HKLM\...\{EE202411-2C26-49E8-9784-1BC1DBF7DE96}) (Version: 7.0.39.15 - Hewlett-Packard Company) HP Update (HKLM\...\{B0069CFA-5BB9-4C03-B1C6-89CE290E5AFE}) (Version: 5.002.006.003 - Hewlett-Packard) IDT Audio (HKLM\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6351.0 - IDT) Imagenomic Portraiture 2.3 Plug-in (build 2308) (HKLM\...\ImagenomicPortraiturePlugin) (Version: - ) iSkysoft Video Converter(Build 3.1.1.0) (HKLM\...\iSkysoft Video Converter_is1) (Version: - iSkysoft Software) iTunes (HKLM\...\{0A37EE62-9A58-420D-90CC-4E52153112EE}) (Version: 11.3.0.54 - Apple Inc.) Java 7 Update 60 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.600 - Oracle) JavaFX 2.1.1 (HKLM\...\{1111706F-666A-4037-7777-211328764D10}) (Version: 2.1.1 - Oracle Corporation) Junk Mail filter update (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Lucid Dream Preparation (HKLM\...\Lucid Dream Preparation_is1) (Version: - ) Magic ISO Maker v5.4 (build 0239) (HKLM\...\Magic ISO Maker v5.4 (build 0239)) (Version: - ) Malwarebytes Anti-Malware version 2.1.8.1057 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation) Mesh Runtime (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office 2010 (HKLM\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Enterprise 2007 (HKLM\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office File Validation Add-In (HKLM\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411 (HKLM\...\{5DA8F6CD-C70E-39D8-8430-3D9808D6BD17}) (Version: 9.0.30411 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Mozilla Firefox 33.0 (x86 en-US) (HKLM\...\Mozilla Firefox 33.0 (x86 en-US)) (Version: 33.0 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 30.0 - Mozilla) Notepad++ (HKLM\...\Notepad++) (Version: 6.6.8 - Notepad++ Team) Osmo4/GPAC (remove only) (HKLM\...\Osmo4) (Version: - ) PDF Settings CC (Version: 12.0 - Adobe Systems Incorporated) Hidden Ports Of Call Simulator 3d - Updater (HKLM\...\Ports Of Call Simulator 3d - Updater) (Version: - ) Ports Of Call Simulator 3d (HKLM\...\Ports Of Call Simulator 3d) (Version: - ) Ports Of Call XXL (HKLM\...\Ports Of Call XXL) (Version: - ) Ports Of Call XXL WEB installer (HKLM\...\Ports Of Call XXL WEB installer) (Version: 1.0.13 - MMS Dipl.-Ing. Rolf-Dieter Klein) QuickTime (HKLM\...\{B67BAFBA-4C9F-48FA-9496-933E3B255044}) (Version: 7.74.80.86 - Apple Inc.) Quintessential Player (HKLM\...\Quintessential Player) (Version: 4.51 - Quinnware) RealDownloader (Version: 1.3.3 - RealNetworks, Inc.) Hidden RealNetworks - Microsoft Visual C++ 2008 Runtime (Version: 9.0 - RealNetworks, Inc) Hidden RealNetworks - Microsoft Visual C++ 2010 Runtime (Version: 10.0 - RealNetworks, Inc) Hidden RealPlayer (HKLM\...\RealPlayer 16.0) (Version: 16.0.3 - RealNetworks) Realtek Ethernet Controller Driver (HKLM\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.46.610.2011 - Realtek) Realtek USB 2.0 Card Reader (HKLM\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30127 - Realtek Semiconductor Corp.) REALTEK Wireless LAN Driver and Utility (HKLM\...\{0DF70CB6-553A-4C57-8E6D-87635EECFB78}) (Version: 1.00.0145 - ALFA NETWORK Inc..) RealUpgrade 1.1 (Version: 1.1.0 - RealNetworks, Inc.) Hidden Recover My Files (HKLM\...\Recover My Files v5_is1) (Version: 5.1.0.1824 - GetData Pty Ltd) Recovery Manager (Version: 2.0.0 - Hewlett-Packard) Hidden Skype™ 7.0 (HKLM\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.) SpeedFan (remove only) (HKLM\...\SpeedFan) (Version: - ) Sublime Text 2.0.2 (HKLM\...\Sublime Text 2_is1) (Version: - ) Sublime Text Build 3059 (HKLM\...\Sublime Text 3_is1) (Version: - Sublime HQ Pty Ltd) Synaptics TouchPad Driver (HKLM\...\SynTPDeinstKey) (Version: 15.3.29.0 - Synaptics Incorporated) The KMPlayer (remove only) (HKLM\...\The KMPlayer) (Version: - ) Topaz InFocus (HKLM\...\Topaz InFocus) (Version: 1.0.0 - Topaz Labs) Topaz InFocus (Version: 1.0.0 - Topaz Labs) Hidden Topaz Adjust 4 (HKLM\...\Topaz Adjust 4) (Version: 4.1.0 - Topaz Labs) Topaz Adjust 4 (Version: 4.1.0 - Topaz Labs) Hidden Topaz DeNoise 5 (HKLM\...\Topaz DeNoise 5) (Version: 5.0.1 - Topaz Labs) Topaz DeNoise 5 (Version: 5.0.1 - Topaz Labs) Hidden Topaz Detail 2 (HKLM\...\Topaz Detail 2) (Version: 2.0.5 - Topaz Labs) Topaz Detail 2 (Version: 2.0.5 - Topaz Labs) Hidden Topaz ReMask 3 (HKLM\...\Topaz ReMask 3) (Version: 3.1.0 - Topaz Labs) Topaz ReMask 3 (Version: 3.1.0 - Topaz Labs) Hidden TunnelBear (HKLM\...\{24ab069f-4a6a-43db-a29a-ab0daf2e8f2e}) (Version: 2.2.25.0 - TunnelBear) TunnelBear (Version: 2.2.25.0 - TunnelBear) Hidden Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Viber (HKU\S-1-5-21-4041656617-1838989228-2178339868-1000\...\Viber) (Version: 3.0.0.134678 - Viber Media Inc) VLC media player 2.1.3 (HKLM\...\VLC media player) (Version: 2.1.3 - VideoLAN) Windows Live Essentials (HKLM\...\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation) Windows Live Mesh ActiveX Control for Remote Connections (HKLM\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation) WinHTTrack Website Copier 3.48-19 (HKLM\...\WinHTTrack Website Copier_is1) (Version: 3.48.19 - HTTrack) Winrar 3.93 (HKLM\...\Winrar 3.93) (Version: - ) WinRAR archiver (HKLM\...\WinRAR archiver) (Version: - ) YTD Video Downloader 4.8 (HKLM\...\{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}) (Version: 4.8 - GreenTree Applications SRL) <==== ATTENTION ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-4041656617-1838989228-2178339868-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\inFidel\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4041656617-1838989228-2178339868-1000_Classes\CLSID\{022105BD-948A-40C9-AB42-A3300DDF097F}\localserver32 -> C:\Users\inFidel\AppData\Local\Google\Update\GoogleUpdate.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-4041656617-1838989228-2178339868-1000_Classes\CLSID\{035FBE31-3755-450A-A775-5E6BBD43D344}\InprocServer32 -> C:\Users\inFidel\AppData\Local\Google\Update\1.3.21.135\psuser.dll No File CustomCLSID: HKU\S-1-5-21-4041656617-1838989228-2178339868-1000_Classes\CLSID\{0A368B9B-3566-4730-B40E-EAF6858A53AF}\InprocServer32 -> C:\Users\inFidel\AppData\Local\Dropbox\Update\1.3.27.33\psuser.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4041656617-1838989228-2178339868-1000_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\inFidel\AppData\Local\Google\Update\1.3.27.5\psuser.dll No File CustomCLSID: HKU\S-1-5-21-4041656617-1838989228-2178339868-1000_Classes\CLSID\{1FD1FE74-9E3C-4C1C-AEEB-AAB592AD770F}\localserver32 -> C:\Users\inFidel\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.) CustomCLSID: HKU\S-1-5-21-4041656617-1838989228-2178339868-1000_Classes\CLSID\{219D3EAA-D5B5-9D41-67F5-C9D57885EE5A}\InprocServer32 -> C:\Windows\system32\ole32.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-4041656617-1838989228-2178339868-1000_Classes\CLSID\{22181302-A8A6-4F84-A541-E5CBFC70CC43}\localserver32 -> C:\Users\inFidel\AppData\Local\Google\Update\1.3.28.1\GoogleUpdateOnDemand.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-4041656617-1838989228-2178339868-1000_Classes\CLSID\{2F0E2680-9FF5-43C0-B76E-114A56E93598}\localserver32 -> C:\Users\inFidel\AppData\Local\Google\Update\1.3.28.1\GoogleUpdateOnDemand.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-4041656617-1838989228-2178339868-1000_Classes\CLSID\{3059C9E6-9EDC-4C89-933E-C65623F8FD60}\localserver32 -> C:\Users\inFidel\AppData\Local\Dropbox\Update\DropboxUpdate.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4041656617-1838989228-2178339868-1000_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\inFidel\AppData\Local\Google\Update\1.3.23.9\psuser.dll No File CustomCLSID: HKU\S-1-5-21-4041656617-1838989228-2178339868-1000_Classes\CLSID\{38216570-5DB1-45F8-A344-B0C4E252B14B}\InprocServer32 -> C:\Users\inFidel\AppData\Local\Google\Update\1.3.26.7\psuser.dll No File CustomCLSID: HKU\S-1-5-21-4041656617-1838989228-2178339868-1000_Classes\CLSID\{51F9E8EF-59D7-475B-A106-C7EA6F30C119}\localserver32 -> C:\Users\inFidel\AppData\Local\Google\Update\1.3.28.1\GoogleUpdateOnDemand.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-4041656617-1838989228-2178339868-1000_Classes\CLSID\{5C65F4B0-3651-4514-B207-D10CB699B14B}\localserver32 -> C:\Users\inFidel\AppData\Local\Google\Chrome\Application\44.0.2403.125\delegate_execute.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-4041656617-1838989228-2178339868-1000_Classes\CLSID\{5C8C2A98-6133-4EBA-BBCC-34D9EA01FC2E}\InprocServer32 -> C:\Users\inFidel\AppData\Local\Google\Update\1.3.28.1\psuser.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-4041656617-1838989228-2178339868-1000_Classes\CLSID\{5E71E4F3-E8C7-4906-9626-973E418762B6}\InprocServer32 -> C:\Users\inFidel\AppData\Local\Facebook\Update\1.2.205.0\goopdate.dll (Facebook Inc.) CustomCLSID: HKU\S-1-5-21-4041656617-1838989228-2178339868-1000_Classes\CLSID\{62A0D750-DED9-448C-B693-406B34BB0892}\InprocServer32 -> C:\Users\inFidel\AppData\Local\Google\Update\1.3.21.145\psuser.dll No File CustomCLSID: HKU\S-1-5-21-4041656617-1838989228-2178339868-1000_Classes\CLSID\{634059C0-D264-4B2C-AE80-F73E48D33E5B}\InprocServer32 -> C:\Users\inFidel\AppData\Local\Google\Update\1.3.21.123\psuser.dll No File CustomCLSID: HKU\S-1-5-21-4041656617-1838989228-2178339868-1000_Classes\CLSID\{6D7374DE-63AA-473C-8C02-60D9CDCD84C5}\InprocServer32 -> C:\Users\inFidel\AppData\Local\Google\Update\1.3.21.153\psuser.dll No File CustomCLSID: HKU\S-1-5-21-4041656617-1838989228-2178339868-1000_Classes\CLSID\{87DC457B-B35D-48AC-BD42-BDF35EF623CE}\localserver32 -> C:\Users\inFidel\AppData\Local\Dropbox\Update\1.3.27.33\DropboxUpdateOnDemand.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4041656617-1838989228-2178339868-1000_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\inFidel\AppData\Local\Google\Update\1.3.24.15\psuser.dll No File CustomCLSID: HKU\S-1-5-21-4041656617-1838989228-2178339868-1000_Classes\CLSID\{9FAA38ED-5635-44F7-9BE0-8CAFE29B3783}\localserver32 -> C:\Users\inFidel\AppData\Local\Dropbox\Update\1.3.27.33\DropboxUpdateOnDemand.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4041656617-1838989228-2178339868-1000_Classes\CLSID\{A45426FB-E444-42B2-AA56-419F8FBEEC61}\InprocServer32 -> C:\Users\inFidel\AppData\Local\Google\Update\1.3.22.3\psuser.dll No File CustomCLSID: HKU\S-1-5-21-4041656617-1838989228-2178339868-1000_Classes\CLSID\{A54D478D-4F70-4F72-9A74-17C9986E35AB}\InprocServer32 -> C:\Users\inFidel\AppData\Local\Google\Update\1.3.21.165\psuser.dll No File CustomCLSID: HKU\S-1-5-21-4041656617-1838989228-2178339868-1000_Classes\CLSID\{C0DD324D-A74F-4533-84AD-030F76771C77}\localserver32 -> C:\Users\inFidel\AppData\Local\Dropbox\Update\1.3.27.33\DropboxUpdateOnDemand.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4041656617-1838989228-2178339868-1000_Classes\CLSID\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}\InprocServer32 -> C:\Users\inFidel\AppData\Local\Google\Update\1.3.28.1\npGoogleUpdate3.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-4041656617-1838989228-2178339868-1000_Classes\CLSID\{C32E3EEC-3C10-426E-95F3-38C7F139FADD}\localserver32 -> C:\Users\inFidel\AppData\Local\Dropbox\Update\1.3.27.33\DropboxUpdateOnDemand.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4041656617-1838989228-2178339868-1000_Classes\CLSID\{C442AC41-9200-4770-8CC0-7CDB4F245C55}\InprocServer32 -> C:\Users\inFidel\AppData\Local\Google\Update\1.3.28.1\npGoogleUpdate3.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-4041656617-1838989228-2178339868-1000_Classes\CLSID\{C5A2122B-A05B-4FD8-AE49-91990AE10998}\InprocServer32 -> C:\Users\inFidel\AppData\Local\Google\Update\1.3.21.115\psuser.dll No File CustomCLSID: HKU\S-1-5-21-4041656617-1838989228-2178339868-1000_Classes\CLSID\{D166BD15-03AF-413A-BEFD-0679FF410B49}\InprocServer32 -> C:\Users\inFidel\AppData\Local\Dropbox\Update\1.3.27.29\psuser.dll No File CustomCLSID: HKU\S-1-5-21-4041656617-1838989228-2178339868-1000_Classes\CLSID\{E67BE843-BBBE-4484-95FB-05271AE86750}\localserver32 -> C:\Users\inFidel\AppData\Local\Google\Update\1.3.28.1\GoogleUpdateOnDemand.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-4041656617-1838989228-2178339868-1000_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\inFidel\AppData\Local\Google\Update\1.3.28.1\psuser.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-4041656617-1838989228-2178339868-1000_Classes\CLSID\{EB06378B-ABB6-4B3C-9B40-D488DD8A6E93}\InprocServer32 -> C:\Users\inFidel\AppData\Local\Google\Update\1.3.22.5\psuser.dll No File CustomCLSID: HKU\S-1-5-21-4041656617-1838989228-2178339868-1000_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\inFidel\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4041656617-1838989228-2178339868-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\inFidel\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4041656617-1838989228-2178339868-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\inFidel\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4041656617-1838989228-2178339868-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\inFidel\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4041656617-1838989228-2178339868-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\inFidel\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4041656617-1838989228-2178339868-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\inFidel\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4041656617-1838989228-2178339868-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\inFidel\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4041656617-1838989228-2178339868-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\inFidel\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4041656617-1838989228-2178339868-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\inFidel\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4041656617-1838989228-2178339868-1000_Classes\CLSID\{FB994D36-B312-46CE-A40B-CF63980641F9}\InprocServer32 -> C:\Users\inFidel\AppData\Local\Google\Update\1.3.21.111\psuser.dll No File CustomCLSID: HKU\S-1-5-21-4041656617-1838989228-2178339868-1000_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\inFidel\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-4041656617-1838989228-2178339868-1000_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\inFidel\AppData\Local\Google\Update\1.3.24.7\psuser.dll No File CustomCLSID: HKU\S-1-5-21-4041656617-1838989228-2178339868-1000_Classes\CLSID\{FE819BE5-BADF-4370-9913-6FB84ABA6FB1}\InprocServer32 -> C:\Users\inFidel\AppData\Local\Dropbox\Update\1.3.27.33\psuser.dll (Dropbox, Inc.) ==================== Restore Points ========================= 06-08-2015 17:39:43 Windows Update ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2012-04-13 19:24 - 2014-08-30 00:52 - 00000924 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 activate.adobe.com google.com serena.costa.it google.com onboardportal.serena.costa.it ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {009986E1-084C-45EA-9604-7C8FC043A1B3} - System32\Tasks\RealCreateProcessScheduledTask1255228849S-1-5-21-4041656617-1838989228-2178339868-1000 => c:\program files\real\realplayer\update\realsched.exe [2013-12-13] (RealNetworks, Inc.) Task: {103AAA73-BD59-4F3F-9257-15810F30E961} - System32\Tasks\HPCeeScheduleForinFidel => C:\Program Files\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14] (Hewlett-Packard) Task: {20E6881A-B853-4D82-82C7-F135398C8FCF} - System32\Tasks\{351260BE-BC63-47A8-966B-0729B8279AC5} => pcalua.exe -a C:\PROGRA~1\poc\pocxxl\UNWISE.EXE -c C:\PROGRA~1\poc\pocxxl\INSTAL~1.LOG Task: {2BD05BA6-988D-4BD3-A9CD-9A39F80AF524} - \Microsoft\Windows\MemoryDiagnostic\CorruptionDetector No Task File <==== ATTENTION Task: {354FB93B-2CD8-4E84-B8F4-FB347026CEF3} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-4041656617-1838989228-2178339868-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.) Task: {4885BD6E-AB34-4F93-B1BF-6F00AC56797E} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-06-24] (Piriform Ltd) Task: {492D85AB-9FD2-4716-91A7-7DC7788DC846} - \Microsoft\Windows\Windows Activation Technologies\ValidationTask No Task File <==== ATTENTION Task: {4BEFD5F4-9E85-4068-8279-BBDB61B181CB} - System32\Tasks\AdobeAAMUpdater-1.0-inFidel-1337-inFidel => C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2013-03-21] (Adobe Systems Incorporated) Task: {53A86098-E92D-465A-9992-5B0DE052377E} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4041656617-1838989228-2178339868-1000Core => C:\Users\inFidel\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-13] (Google Inc.) Task: {55E475E8-CD21-4285-BC33-0BB31C3C0F3B} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-4041656617-1838989228-2178339868-1000Core => C:\Users\inFidel\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-01-23] (Facebook Inc.) Task: {5AD50DD1-F8CB-44BD-8037-C916B4487505} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4041656617-1838989228-2178339868-1000UA => C:\Users\inFidel\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-13] (Google Inc.) Task: {5AD99B81-4044-4598-A14C-A96AA6485E44} - System32\Tasks\RealCreateProcessScheduledTask422498102S-1-5-21-4041656617-1838989228-2178339868-1000 => c:\program files\real\realplayer\update\realsched.exe [2013-12-13] (RealNetworks, Inc.) Task: {5B184694-64C3-4633-94C5-945B3FA561D6} - \Microsoft\Windows\WindowsBackup\ConfigNotification No Task File <==== ATTENTION Task: {5E9E1543-5646-4D83-9217-C26BFFF0EB9A} - System32\Tasks\ReclaimerUpdateXML_inFidel => C:\Users\inFidel\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\11.01\agent\rnupgagent.exe [2014-06-26] (RealNetworks, Inc.) Task: {6283D386-3EE5-4D2C-9649-D392BC8BD632} - System32\Tasks\ReclaimerUpdateFiles_inFidel => C:\Users\inFidel\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\11.01\agent\rnupgagent.exe [2014-06-26] (RealNetworks, Inc.) Task: {6862C974-65DA-4679-BDFD-4822FAEBEF23} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-09-27] (Hewlett-Packard Company) Task: {70EFD96E-15A1-4F5C-9D80-C7DF43B7FE07} - System32\Tasks\RealCreateProcessScheduledTask1816915314S-1-5-21-4041656617-1838989228-2178339868-1000 => c:\program files\real\realplayer\update\realsched.exe [2013-12-13] (RealNetworks, Inc.) Task: {71E639F9-8720-44DC-BCB3-361CCF47B5E9} - System32\Tasks\RNUpgradeHelperResumePrompt_inFidel => C:\Users\inFidel\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\11.01\agent\rnupgagent.exe [2014-06-26] (RealNetworks, Inc.) Task: {7D6D93E2-73C2-4AC5-A718-42BE28FC0578} - System32\Tasks\RealCreateProcessScheduledTask252138895S-1-5-21-4041656617-1838989228-2178339868-1000 => c:\program files\real\realplayer\update\realsched.exe [2013-12-13] (RealNetworks, Inc.) Task: {7F68AF9C-4412-453D-8D6E-5416A6416BB5} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-4041656617-1838989228-2178339868-1000UA => C:\Users\inFidel\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-01-23] (Facebook Inc.) Task: {82B34A9E-CDE5-485B-AB0D-18F493C00310} - System32\Tasks\RealCreateProcessScheduledTask1575878248S-1-5-21-4041656617-1838989228-2178339868-1000 => c:\program files\real\realplayer\update\realsched.exe [2013-12-13] (RealNetworks, Inc.) Task: {860EC9CB-A3CF-4BBB-AABD-71E1A4B14DA9} - System32\Tasks\RealCreateProcessScheduledTask3427956672S-1-5-21-4041656617-1838989228-2178339868-1000 => c:\program files\real\realplayer\update\realsched.exe [2013-12-13] (RealNetworks, Inc.) Task: {8F7EB076-1391-433B-8052-A4439A675A14} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-4041656617-1838989228-2178339868-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.) Task: {98CB750C-B919-409C-8666-BCE5246A5CB8} - System32\Tasks\RealCreateProcessScheduledTask977211496S-1-5-21-4041656617-1838989228-2178339868-1000 => c:\program files\real\realplayer\update\realsched.exe [2013-12-13] (RealNetworks, Inc.) Task: {9DD41417-F1DD-4A5E-AAD3-B08331EB3424} - System32\Tasks\HPCustParticipation HP Deskjet 1050 J410 series => C:\Program Files\HP\HP Deskjet 1050 J410 series\Bin\HPCustPartic.exe [2010-11-16] (Hewlett-Packard Co.) Task: {9F54B95F-5096-4803-AE61-E9B3AC5B616D} - \Microsoft\Windows\MemoryDiagnostic\DecompressionFailureDetector No Task File <==== ATTENTION Task: {A069C56C-0897-4BA2-8D03-F6053EF86B9D} - System32\Tasks\RNUpgradeHelperLogonPrompt_inFidel => C:\Users\inFidel\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\11.01\agent\rnupgagent.exe [2014-06-26] (RealNetworks, Inc.) Task: {A5FC74E8-BD6D-4D81-9B55-F1ADB1730C4D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-09-27] (Hewlett-Packard Company) Task: {B72CD943-73BF-44B2-B595-9696646795E5} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2014-05-12] (Hewlett-Packard Company) Task: {BD56AF2E-907C-44C8-897A-40C9806F3725} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-4041656617-1838989228-2178339868-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.) Task: {BED9992B-B1C6-4AB7-B3C5-C88E6B6520D7} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-07-07] (Adobe Systems Incorporated) Task: {C2D86B3B-2BC1-431E-8AE1-473AC64CFB88} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-07-15] (Adobe Systems Incorporated) Task: {C4878030-99B3-45D1-BC5A-106549CAD895} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-4041656617-1838989228-2178339868-1000UA => C:\Users\inFidel\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-22] (Dropbox, Inc.) Task: {C93C598B-FEB8-4255-8540-FA81DA29185A} - System32\Tasks\{C4DE863C-94D5-40D1-9C25-152C05E4A3BC} => pcalua.exe -a C:\PROGRA~1\MagicISO\UNWISE.EXE -c C:\PROGRA~1\MagicISO\INSTALL.LOG Task: {CC2282AC-B4DA-4915-BB90-D9CB1E511BEE} - System32\Tasks\RealCreateProcessScheduledTask3586971720S-1-5-21-4041656617-1838989228-2178339868-1000 => c:\program files\real\realplayer\update\realsched.exe [2013-12-13] (RealNetworks, Inc.) Task: {CFF52379-353C-4C55-9ACF-0752840AB3FE} - System32\Tasks\RealCreateProcessScheduledTask3278052768S-1-5-21-4041656617-1838989228-2178339868-1000 => c:\program files\real\realplayer\update\realsched.exe [2013-12-13] (RealNetworks, Inc.) Task: {D05CC1AE-6F8F-46AA-B059-78292F4FA782} - \Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline No Task File <==== ATTENTION Task: {D21F6024-191F-4454-BBBC-09A650DA2549} - \Microsoft\Windows\Application Experience\AitAgent No Task File <==== ATTENTION Task: {D44DD388-5750-4948-BAAE-C734BB0EADE8} - System32\Tasks\MirageAgent => C:\Program Files\CyberLink\YouCam\YCMMirage.exe [2011-07-07] (CyberLink) Task: {DC16CBDE-AA9E-4210-A986-8D68EA498A7D} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-4041656617-1838989228-2178339868-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.) Task: {E0BA284D-66A1-45B7-81C3-26863D50B281} - System32\Tasks\RealCreateProcessScheduledTask3543218697S-1-5-21-4041656617-1838989228-2178339868-1000 => c:\program files\real\realplayer\update\realsched.exe [2013-12-13] (RealNetworks, Inc.) Task: {E7973815-D42D-4EDC-9FCF-88D6231943D2} - System32\Tasks\RealCreateProcessScheduledTask460272418S-1-5-21-4041656617-1838989228-2178339868-1000 => c:\program files\real\realplayer\update\realsched.exe [2013-12-13] (RealNetworks, Inc.) Task: {EDA8FD07-340F-4073-8D95-DB2FBBF08B12} - System32\Tasks\RealCreateProcessScheduledTask1257031909S-1-5-21-4041656617-1838989228-2178339868-1000 => c:\program files\real\realplayer\update\realsched.exe [2013-12-13] (RealNetworks, Inc.) Task: {FA930F2A-9ECB-4043-836C-6C803C2FB6D6} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-4041656617-1838989228-2178339868-1000Core => C:\Users\inFidel\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-22] (Dropbox, Inc.) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-4041656617-1838989228-2178339868-1000Core.job => C:\Users\inFidel\AppData\Local\Dropbox\Update\DropboxUpdate.exe Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-4041656617-1838989228-2178339868-1000UA.job => C:\Users\inFidel\AppData\Local\Dropbox\Update\DropboxUpdate.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4041656617-1838989228-2178339868-1000Core.job => C:\Users\inFidel\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4041656617-1838989228-2178339868-1000UA.job => C:\Users\inFidel\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4041656617-1838989228-2178339868-1000Core.job => C:\Users\inFidel\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4041656617-1838989228-2178339868-1000UA.job => C:\Users\inFidel\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\HPCeeScheduleForinFidel.job => C:\Program Files\Hewlett-Packard\HP Ceement\HPCEE.exe Task: C:\Windows\Tasks\ReclaimerUpdateFiles_inFidel.job => C:\Users\inFidel\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\11.01\agent\rnupgagent.exe Task: C:\Windows\Tasks\ReclaimerUpdateXML_inFidel.job => C:\Users\inFidel\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\11.01\agent\rnupgagent.exe Task: C:\Windows\Tasks\RNUpgradeHelperLogonPrompt_inFidel.job => C:\Users\inFidel\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\11.01\agent\rnupgagent.exe ==================== Loaded Modules (Whitelisted) ============== 2013-08-07 21:25 - 2013-08-07 21:25 - 00093696 _____ () C:\Program Files\FileZilla FTP Client\fzshellext.dll 2010-03-15 11:28 - 2010-03-15 11:28 - 00141824 _____ () C:\Program Files\WinRAR\rarext.dll 2014-05-12 11:49 - 2014-05-12 11:49 - 00260608 _____ () C:\Program Files\Notepad++\NppShell_06.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\ProgramData\Temp:56E2E879 AlternateDataStreams: C:\Users\inFidel\Desktop\NEW-LOGO-2014.png:com.dropbox.attributes ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.) ==================== EXE Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-4041656617-1838989228-2178339868-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\inFidel\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.1.254 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 0) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) MSCONFIG\Services: ABBYY.Licensing.FineReader.Professional.9.0 => 2 MSCONFIG\Services: AdobeARMservice => 2 MSCONFIG\Services: AdobeFlashPlayerUpdateSvc => 3 MSCONFIG\Services: AESTFilters => 2 MSCONFIG\Services: AMD External Events Utility => 2 MSCONFIG\Services: Apple Mobile Device => 2 MSCONFIG\Services: Bonjour Service => 2 MSCONFIG\Services: btwdins => 2 MSCONFIG\Services: CodeMeter.exe => 2 MSCONFIG\Services: ezSharedSvc => 2 MSCONFIG\Services: Futuremark SystemInfo Service => 3 MSCONFIG\Services: HP Support Assistant Service => 2 MSCONFIG\Services: HPClientSvc => 2 MSCONFIG\Services: HPDrvMntSvc.exe => 2 MSCONFIG\Services: hpqwmiex => 3 MSCONFIG\Services: hpsrv => 2 MSCONFIG\Services: iPod Service => 3 MSCONFIG\Services: MBAMScheduler => 2 MSCONFIG\Services: MBAMService => 2 MSCONFIG\Services: MozillaMaintenance => 3 MSCONFIG\Services: RealNetworks Downloader Resolver Service => 2 MSCONFIG\Services: Realtek87B => 2 MSCONFIG\Services: SkypeUpdate => 3 MSCONFIG\Services: STacSV => 2 MSCONFIG\Services: TunnelBearMaintenance => 3 MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk => C:\Windows\pss\Bluetooth.lnk.CommonStartup MSCONFIG\startupfolder: C:^Users^inFidel^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk => C:\Windows\pss\Dropbox.lnk.Startup MSCONFIG\startupreg: Adobe Reader Speed Launcher => "C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe" MSCONFIG\startupreg: AdobeAAMUpdater-1.0 => "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" MSCONFIG\startupreg: AdobeCEPServiceManager => "C:\Program Files\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe" -launchedbylogin MSCONFIG\startupreg: APSDaemon => "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" MSCONFIG\startupreg: Dropbox Update => "C:\Users\inFidel\AppData\Local\Dropbox\Update\DropboxUpdate.exe" /c MSCONFIG\startupreg: Facebook Update => "C:\Users\inFidel\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver MSCONFIG\startupreg: Google Update => "C:\Users\inFidel\AppData\Local\Google\Update\GoogleUpdate.exe" /c MSCONFIG\startupreg: GrooveMonitor => "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" MSCONFIG\startupreg: HP CoolSense => C:\Program Files\Hewlett-Packard\HP CoolSense\CoolSense.exe -byrunkey MSCONFIG\startupreg: HP Software Update => C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe MSCONFIG\startupreg: HPOSD => C:\Program Files\Hewlett-Packard\HP On Screen Display\HPOSD.exe MSCONFIG\startupreg: HPQuickWebProxy => "C:\Program Files\Hewlett-Packard\HP QuickWeb\hpqwutils.exe" MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe" MSCONFIG\startupreg: NCPluginUpdater => "C:\Program Files\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe" Update MSCONFIG\startupreg: QuickTime Task => "C:\Program Files\QuickTime\QTTask.exe" -atboottime MSCONFIG\startupreg: Skype => "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun MSCONFIG\startupreg: StartCCC => "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files\Common Files\Java\Java Update\jusched.exe" MSCONFIG\startupreg: SysTrayApp => C:\Program Files\IDT\WDM\sttray.exe MSCONFIG\startupreg: TkBellExe => "c:\program files\real\realplayer\update\realsched.exe" -osboot ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{13150711-637C-4B7B-B015-927C8AFD0B34}] => (Allow) C:\Program Files\Windows Live\Contacts\wlcomm.exe FirewallRules: [{8A11AF01-A2E1-42FE-A548-E27057A37A69}] => (Allow) LPort=2869 FirewallRules: [{8FC51FDF-9204-4114-B98C-FDE066FE7A42}] => (Allow) LPort=1900 FirewallRules: [{D7B0BF1F-5AC7-4BDE-95EA-48353153D9B2}] => (Allow) C:\Program Files\Windows Live\Messenger\msnmsgr.exe FirewallRules: [{6B1C6C39-989E-45C0-85C8-30E9EE046446}] => (Allow) C:\Program Files\Windows Live\Mesh\MOE.exe FirewallRules: [{EA72AEC1-BC41-41FC-8C9B-F2CC50E56246}] => (Allow) C:\Windows\system32\ezSharedSvcHost.exe FirewallRules: [{503748D5-04FD-4FC0-BBEF-613EACE3B0B4}] => (Allow) C:\Program Files\EasyBits For Kids\ezDesktop.exe FirewallRules: [{25C05E15-0F88-43CA-BF88-A6699555192D}] => (Allow) C:\Program Files\uTorrent\uTorrent.exe FirewallRules: [{CDEB5FDC-6FE5-427D-970A-078496B66720}] => (Allow) C:\Program Files\uTorrent\uTorrent.exe FirewallRules: [{4ABDBE74-524E-4004-A29E-964F100DDD72}] => (Allow) C:\Program Files\Skype\Phone\Skype.exe FirewallRules: [{596B2558-52B5-43EA-9382-68F871A3FE16}] => (Allow) C:\Users\inFidel\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [{20EDB504-9744-4606-A198-B9171F7071F8}] => (Allow) C:\Users\inFidel\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [{29A5756D-6F75-4441-AEC2-96EAE6476ED7}] => (Allow) C:\Program Files\Realtek\RTL8187 Wireless LAN Utility\RtWLan.exe FirewallRules: [{D7EC3FAC-2050-402C-A6B3-BCDC169A855D}] => (Allow) C:\Program Files\Realtek\RTL8187 Wireless LAN Utility\RtWLan.exe FirewallRules: [{BA03B495-55E6-4CE0-B8A0-5EED5450DD01}] => (Allow) LPort=1542 FirewallRules: [{9CD2D101-7391-45AF-94F1-2E464E048363}] => (Allow) LPort=1542 FirewallRules: [{1A48C6AB-4E1D-413C-9378-D793A3DAA5EB}] => (Allow) LPort=53 FirewallRules: [TCP Query User{5036818C-8EB0-4344-9929-64EF17FD885E}C:\users\infidel\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\infidel\appdata\roaming\dropbox\bin\dropbox.exe FirewallRules: [UDP Query User{60E77581-9FF8-4C73-A6F6-31EA5EDD5B70}C:\users\infidel\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\infidel\appdata\roaming\dropbox\bin\dropbox.exe FirewallRules: [{AEC02BD7-A6E1-421E-ADFC-D1F45C07C0FC}] => (Allow) C:\Program Files\HP\HP Deskjet 1050 J410 series\Bin\USBSetup.exe FirewallRules: [{65367420-F09D-46F0-A7A8-8E3AFF5E2386}] => (Allow) C:\Program Files\HP\HP Deskjet 1050 J410 series\Bin\USBSetup.exe FirewallRules: [TCP Query User{B74A1F15-39F3-4CE2-8A7C-5F2E46B37A39}C:\program files\poc\pocxxl\bin\pocxxl.exe] => (Allow) C:\program files\poc\pocxxl\bin\pocxxl.exe FirewallRules: [UDP Query User{272B80D2-3BCE-42F7-B2C0-CDD78C884450}C:\program files\poc\pocxxl\bin\pocxxl.exe] => (Allow) C:\program files\poc\pocxxl\bin\pocxxl.exe FirewallRules: [{C16841EF-920F-4323-99D5-3D3993DCD3F9}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe FirewallRules: [{9CAFFCC9-9E0A-4911-809B-CA1C52D63A48}] => (Allow) C:\Program Files\CodeMeter\Runtime\bin\CodeMeter.exe FirewallRules: [{C4998E5E-82F4-44DB-A08C-94E5ABAFADD8}] => (Allow) C:\Program Files\CodeMeter\Runtime\bin\CodeMeter.exe FirewallRules: [{A2B7E03B-E010-4968-A99A-C82E2107E370}] => (Allow) C:\Program Files\CodeMeter\Runtime\bin\CodeMeter.exe FirewallRules: [{8C81D482-2533-4D4C-938F-E257F60AF7F2}] => (Allow) C:\Program Files\CodeMeter\Runtime\bin\CodeMeter.exe FirewallRules: [{18AB7373-127E-42E2-AA72-B9FBC9C3951E}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{C421BD34-A57C-4D92-9AA3-E92DAA163EB3}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{F8762FD3-57FF-4E15-8A90-90F2C5B5FE14}] => (Allow) C:\Program Files\iTunes\iTunes.exe FirewallRules: [{795010D6-440A-4A01-803D-57EA1877225B}] => (Allow) C:\Users\inFidel\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{F38BFF15-E50E-4187-8426-369D6AABDF6D}] => (Allow) C:\Users\inFidel\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{FFEA7936-A8B5-4B08-98AA-B3EB0A451214}] => (Allow) C:\Users\inFidel\AppData\Local\Google\Chrome\Application\chrome.exe ==================== Faulty Device Manager Devices ============= Name: Bluetooth Peripheral Device Description: Bluetooth Peripheral Device Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (08/06/2015 05:57:19 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/06/2015 05:37:06 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/29/2015 06:13:02 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: wuauclt.exe, version: 7.6.7601.18917, time stamp: 0x559eab0c Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000 Exception code: 0xc0000005 Fault offset: 0x69770073 Faulting process id: 0x1718 Faulting application start time: 0xwuauclt.exe0 Faulting application path: wuauclt.exe1 Faulting module path: wuauclt.exe2 Report Id: wuauclt.exe3 Error: (07/28/2015 08:15:35 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/27/2015 08:50:00 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: Dropbox.exe, version: 3.6.9.0, time stamp: 0x550a7723 Faulting module name: ole32.dll, version: 6.1.7601.18915, time stamp: 0x55981b9e Exception code: 0xc0000005 Fault offset: 0x0002d7e1 Faulting process id: 0xcd4 Faulting application start time: 0xDropbox.exe0 Faulting application path: Dropbox.exe1 Faulting module path: Dropbox.exe2 Report Id: Dropbox.exe3 Error: (07/27/2015 08:47:46 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/25/2015 05:30:58 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/23/2015 11:02:58 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/23/2015 10:59:28 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 15819 Error: (07/23/2015 10:59:28 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 15819 System errors: ============= Error: (08/06/2015 05:55:52 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: The following boot-start or system-start driver(s) failed to load: cdrom Error: (08/06/2015 05:54:48 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: {E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E} Error: (08/06/2015 05:36:10 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: The following boot-start or system-start driver(s) failed to load: cdrom Error: (08/06/2015 05:35:10 PM) (Source: volmgr) (EventID: 46) (User: ) Description: Crash dump initialization failed! Error: (07/29/2015 06:19:31 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: {E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E} Error: (07/29/2015 12:21:06 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Wlansvc service. Error: (07/29/2015 02:17:49 AM) (Source: DCOM) (EventID: 10010) (User: ) Description: {995C996E-D918-4A8C-A302-45719A6F4EA7} Error: (07/28/2015 08:14:20 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: The following boot-start or system-start driver(s) failed to load: cdrom Error: (07/28/2015 08:12:21 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: {E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E} Error: (07/27/2015 08:47:27 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: The following boot-start or system-start driver(s) failed to load: cdrom Microsoft Office: ========================= ==================== Memory info =========================== Processor: AMD E-450 APU with Radeon(tm) HD Graphics Percentage of memory in use: 46% Total physical RAM: 3578.91 MB Available physical RAM: 1901.23 MB Total Virtual: 7156.13 MB Available Virtual: 5402.82 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:100 GB) (Free:50.18 GB) NTFS ==>[system with boot components (obtained from reading drive)] Drive d: (Recovery) (Fixed) (Total:15.73 GB) (Free:1.73 GB) NTFS ==>[system with boot components (obtained from reading drive)] Drive e: (HP_TOOLS) (Fixed) (Total:3.96 GB) (Free:1.1 GB) FAT32 Drive f: (Data) (Fixed) (Total:345.86 GB) (Free:152.21 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 6500A13B) Partition 1: (Active) - (Size=199 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=100 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=15.7 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=365.6 GB) - (Type=OF Extended) ==================== End of log ============================