Additional scan result of Farbar Recovery Scan Tool (x64) Version:05-03-2016 01 Ran by Scott (2016-03-09 12:34:49) Running from F:\ Windows 7 Home Premium Service Pack 1 (X64) (2013-09-26 17:44:47) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-981822129-3063170520-1044425282-500 - Administrator - Disabled) Guest (S-1-5-21-981822129-3063170520-1044425282-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-981822129-3063170520-1044425282-1007 - Limited - Enabled) Scott (S-1-5-21-981822129-3063170520-1044425282-1000 - Administrator - Enabled) => C:\Users\Scott ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Norton Security with Backup (Enabled - Up to date) {53C7D717-52E2-B95E-FA61-6F32ECC805DB} AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Norton Security with Backup (Enabled - Up to date) {E8A636F3-74D8-B6D0-C0D1-5440974F4F66} FW: Norton Security with Backup (Enabled) {6BFC5632-188D-B806-D13E-C607121B42A0} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.010.20059 - Adobe Systems Incorporated) Adobe Flash Player 13 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 13.0.0.182 - Adobe Systems Incorporated) Adobe Photoshop 7.0 (HKLM-x32\...\Adobe Photoshop 7.0) (Version: 7.0 - Adobe Systems, Inc.) Adobe Photoshop CC 2015 (HKLM-x32\...\{793C2BF7-A4FE-4608-91C9-9282C5801C21}) (Version: 16.0.1 - Adobe Systems Incorporated) AMD Catalyst Install Manager (HKLM\...\{F2A7CE36-57BF-5C86-952D-90DBF3746D82}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.) Apple Application Support (32-bit) (HKLM-x32\...\{649A1FD9-5892-46AD-8DF0-C4A43FF61CB7}) (Version: 4.1 - Apple Inc.) Apple Application Support (64-bit) (HKLM\...\{0DE0A178-AC7B-4650-806C-CF226DE03766}) (Version: 4.1 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{FD244E19-6EFE-4A2D-948A-0D45D4C168BE}) (Version: 9.0.0.26 - Apple Inc.) Apple Software Update (HKLM-x32\...\{FFD1F7F1-1AC9-4BC4-A908-0686D635ABAF}) (Version: 2.1.4.131 - Apple Inc.) ASUS PC Diagnostics (HKLM-x32\...\{D709005F-D8DC-42A8-8435-5AE880ECAF82}) (Version: 1.3.4 - ASUSTeK Computer Inc.) ASUS Product Register Program (HKLM-x32\...\{C87D79F6-F813-4812-B7A9-CCCAAB8B1188}) (Version: 1.0.020 - ASUSTek Computer Inc.) Atheros Bluetooth Suite (64) (HKLM\...\{230D1595-57DA-4933-8C4E-375797EBB7E1}) (Version: 7.4.0.170 - Atheros) AVS Video ReMaker 4.4.2.168 (HKLM-x32\...\AVS Video ReMaker_is1) (Version: 4.4.2.168 - Online Media Technologies Ltd.) Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) BlueStacks App Player (HKLM-x32\...\{D080F290-4B2A-4C67-9757-63DA0C6E8855}) (Version: 2.0.0.1011 - BlueStack Systems, Inc.) Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.) CPUID CPU-Z 1.64.0 (HKLM\...\CPUID CPU-Z_is1) (Version: - ) CPUID HWMonitor 1.27 (HKLM\...\CPUID HWMonitor_is1) (Version: - ) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Eraser 6.1.0.2946 (HKLM\...\{2901EEAA-C6CE-41B2-BC10-5DA62102A820}) (Version: 6.1.2946 - The Eraser Project) File Uploader (HKLM-x32\...\{237CD223-1B9D-47E8-A76C-E478B83CCEA2}) (Version: 1.2.5 - Nikon) Free ISO to USB version 1.0 (HKLM-x32\...\Free ISO to USB_is1) (Version: 1.0 - ) FTL version 1.5.13 (HKLM-x32\...\{20E23A40-38E5-4DD6-B738-BC8097AE66B6}_is1) (Version: 1.5.13 - Subset Games) Geeks3D FurMark 1.15.2.2 (HKLM-x32\...\{2397CAD4-2263-4CD0-96BE-E43A980B9C9A}_is1) (Version: - Geeks3D) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 48.0.2564.116 - Google Inc.) Google Earth (HKLM-x32\...\{817750FA-EC6A-485D-9901-0683AE6FFDF1}) (Version: 7.1.5.1557 - Google) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.29.5 - Google Inc.) Hidden Hearthstone (HKLM-x32\...\Hearthstone) (Version: - Blizzard Entertainment) Heroes of the Storm (HKLM-x32\...\Heroes of the Storm) (Version: - Blizzard Entertainment) iCloud (HKLM\...\{4B48E22A-2FB0-4EFA-B99E-954B1E50CD69}) (Version: 5.1.0.34 - Apple Inc.) iExplorer 3.8.5.0 (HKLM-x32\...\{7FD8B0C1-CDDA-4B4D-A577-B2E3570EA3A3}_is1) (Version: - Macroplant LLC) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.0.0.1323 - Intel Corporation) Intel(R) Network Connections 18.1.59.0 (HKLM\...\PROSetDX) (Version: 18.1.59.0 - Intel) Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.0.0.1083 - Intel Corporation) Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 2.5.0.19 - Intel Corporation) Java 8 Update 71 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218071F0}) (Version: 8.0.710.15 - Oracle Corporation) League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games) League of Legends (x32 Version: 3.0.1 - Riot Games) Hidden Logitech Gaming Software 8.75 (HKLM\...\Logitech Gaming Software) (Version: 8.75.30 - Logitech Inc.) Magical Jelly Bean KeyFinder (HKLM-x32\...\KeyFinder_is1) (Version: 2.0.10.10 - Magical Jelly Bean) Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation) Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation) Microsoft Mouse and Keyboard Center (HKLM\...\Microsoft Mouse and Keyboard Center) (Version: 2.2.173.0 - Microsoft Corporation) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-002E-0000-0000-0000000FF1CE}_ULTIMATER_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office Ultimate 2007 (HKLM-x32\...\ULTIMATER) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden MSI Afterburner 4.1.1 (HKLM-x32\...\Afterburner) (Version: 4.1.1 - MSI Co., LTD) MSI Kombustor 3.5.1 (HKLM\...\{9598DA62-2AE8-426D-9C86-BEA96AC6721E}_is1) (Version: - MSI Co., LTD) MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) Nexon Launcher (HKLM-x32\...\Nexon Nexon Launcher) (Version: 1.2.0 - Nexon) Nikon Message Center (HKLM-x32\...\{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}) (Version: 0.92.000 - Nikon) Nikon Message Center 2 (HKLM-x32\...\{B014EE44-9197-4513-9613-71E6EB1B514E}) (Version: 2.1.0 - Nikon) Nikon Transfer (HKLM-x32\...\{E9757890-7EC5-46C8-99AB-B00F07B6525C}) (Version: 1.5.3 - Nikon) Norton Bootable Recovery Tool Wizard (HKLM-x32\...\NBRTWizard) (Version: 7.1.0.26 - Symantec Corporation) Norton Security with Backup (HKLM-x32\...\NSBU) (Version: 22.5.5.15 - Symantec Corporation) Norton Utilities 16 (HKLM-x32\...\Norton Utilities 16_is1) (Version: 16.0 - Symantec Corporation) NVIDIA 3D Vision Controller Driver 352.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 352.65 - NVIDIA Corporation) NVIDIA 3D Vision Driver 358.50 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 358.50 - NVIDIA Corporation) NVIDIA GeForce Experience 2.5.15.54 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.5.15.54 - NVIDIA Corporation) NVIDIA Graphics Driver 358.50 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 358.50 - NVIDIA Corporation) NVIDIA HD Audio Driver 1.3.34.3 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.3 - NVIDIA Corporation) NVIDIA PhysX System Software 9.15.0428 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation) Path of Exile (HKLM-x32\...\{90A4562F-D4A1-4B65-906D-41F236CF6902}) (Version: 1.0.1.29801 - Grinding Gear Games) Picture Control Utility x64 (HKLM\...\{11953C65-BB4E-4CA4-B0F0-2600A4B20040}) (Version: 1.4.14 - Nikon) PowerISO (HKLM-x32\...\PowerISO) (Version: 5.7 - Power Software Ltd) Qualcomm Atheros Client Installation Program (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 10.0 - Qualcomm Atheros) QuickTime 7 (HKLM-x32\...\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}) (Version: 7.79.80.95 - Apple Inc.) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6853 - Realtek Semiconductor Corp.) Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group) SeaTools for Windows 1.4.0.2 (HKLM-x32\...\SeaTools for Windows) (Version: 1.4.0.2 - Seagate Technology) SHIELD Streaming (Version: 4.1.500 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: 2.5.15.54 - NVIDIA Corporation) Hidden Skype™ 7.18 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.18.112 - Skype Technologies S.A.) Speccy (HKLM\...\Speccy) (Version: 1.28 - Piriform) SPORE™ (HKLM-x32\...\{9DF0196F-B6B8-4C3A-8790-DE42AA530101}) (Version: 1.00.0000 - Electronic Arts) StarCraft II (HKLM-x32\...\StarCraft II) (Version: - Blizzard Entertainment) System Requirements Lab for Intel (HKLM-x32\...\{53C63F43-B827-42D9-8886-4698D91EA33B}) (Version: 4.5.15.0 - Husdawg, LLC) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.15 - TeamSpeak Systems GmbH) The Room (HKLM-x32\...\The Room_is1) (Version: - ) To the Moon (HKLM-x32\...\To the Moon1.0) (Version: 1.0 - Foxy Games) Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-002E-0000-0000-0000000FF1CE}_ULTIMATER_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) VC_CRT_x64 (Version: 1.02.0000 - Intel Corporation) Hidden VLC media player 2.1.0 (HKLM-x32\...\VLC media player) (Version: 2.1.0 - VideoLAN) Vuze (HKLM\...\8461-7759-5462-8226) (Version: 5.1.0.0 - Azureus Software, Inc.) WALTR version 1.1.33 (HKLM\...\{20AFC2A1-9E47-4A77-96E8-89AAED7B6AEB}_is1) (Version: 1.1.33 - Softorino, Inc.) WebM Media Foundation Components (HKLM-x32\...\webmmf) (Version: 1.0.1.2 - WebM Project) WebM Project Directshow Filters (HKU\S-1-5-21-981822129-3063170520-1044425282-1000\...\webmdshow) (Version: - ) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation) WinRAR 5.00 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.00.0 - win.rar GmbH) World of Warcraft (HKLM-x32\...\World of Warcraft) (Version: - Blizzard Entertainment) Xiph.Org Open Codecs 0.85.17777 (HKLM-x32\...\Open Codecs) (Version: 0.85.17777 - Xiph.Org) Yahoo Search Set (HKLM-x32\...\Yahoo! SearchSet) (Version: - Yahoo Inc.) Zoom (HKU\S-1-5-21-981822129-3063170520-1044425282-1000\...\ZoomUMX) (Version: 3.5 - Zoom Video Communications, Inc.) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {0D38C0CC-4F0C-4E46-A3B9-BB68DAF29D0B} - System32\Tasks\Remediation\AntimalwareMigrationTask => C:\Program Files\Common Files\AV\Norton Security with Backup\Upgrade.exe [2016-01-06] (Symantec Corporation) Task: {19FF8B54-0D08-4993-A0FE-05B3A33C3788} - System32\Tasks\ASUS\ASUS Product Register Service => C:\Program Files (x86)\ASUS\APRP\aprp.exe [2013-01-25] (ASUSTek Computer Inc.) Task: {2BF5BBD1-A7C1-41FB-92A6-15149BBE6091} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2013-05-13] (Microsoft Corporation) Task: {3EA77F48-2D5D-440D-BC04-69A145943A24} - System32\Tasks\{BDCB9ECA-0AFA-4621-8680-36BCC053C768} => Iexplore.exe hxxp://ui.skype.com/ui/0/7.12.0.101/en/abandoninstall?page=tsMain Task: {47A22783-B361-4C94-90E9-943459B87EF0} - System32\Tasks\MSIAfterburner => C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe [2015-05-25] () Task: {5276731C-816B-4FFB-A291-C7E16BC1A39A} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2013-05-13] (Microsoft) Task: {556DB336-FF7A-41E3-92ED-94D6D1A66234} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2015-08-26] (Apple Inc.) Task: {610154E7-B3D5-46CF-9C63-A52B9FCFB253} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.) Task: {681B76FC-4155-4261-97E0-1F53289ACC7C} - System32\Tasks\{C075475B-4921-4A50-B171-D4808F9F0654} => Iexplore.exe hxxp://ui.skype.com/ui/0/7.2.0.103/en/abandoninstall?page=tsBing Task: {6AB42209-6AF9-47BE-B16D-E82A25041BBC} - System32\Tasks\{FA5ADD74-CBE8-4395-B305-97A8F199EC24} => pcalua.exe -a C:\Users\Scott\Desktop\RipOutOffice2007.exe -d C:\Users\Scott\Desktop Task: {814AEF5A-60E5-48FF-9764-A7FDC158C3A4} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2013-05-13] (Microsoft Corporation) Task: {9D830CE1-4355-4D49-BB19-DA72F1FC8671} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2013-05-13] (Microsoft Corporation) Task: {A2AEA95B-BF93-4215-B78A-109E490B7CFF} - System32\Tasks\Norton Security with Backup\Norton Error Analyzer => C:\Program Files (x86)\Norton Security with Backup\Engine\22.5.5.15\SymErr.exe [2015-11-05] (Symantec Corporation) Task: {A52A5B34-8B97-4211-BA33-5CB152615F5D} - System32\Tasks\{56873642-DE8E-428D-B637-D05E3D37D64B} => pcalua.exe -a "G:\thumb\New Folder\keyfinder.exe" -d "G:\thumb\New Folder" Task: {A7CD29D1-D92E-4757-B347-561D696471CE} - System32\Tasks\NUAutoUpdate => C:\Program Files (x86)\Symantec\Norton Utilities 16\SULauncher.exe [2015-11-03] (Symantec) Task: {A8C88849-3AAE-45AF-BDFC-EFCD7B80A1E3} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2013-05-13] (Microsoft Corporation) Task: {AC73CE71-3383-413C-95AE-467655A5F381} - System32\Tasks\{42F18213-B2C0-4FCC-A826-D5A96AA6DCE8} => pcalua.exe -a C:\Users\Scott\Desktop\32bit_Vista_Win7_Win8_R271.exe -d C:\Users\Scott\Desktop Task: {C1799E02-8C4A-4827-BBA9-AC6DB04FA5F0} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-12-13] (Adobe Systems Incorporated) Task: {C7E010FD-7129-43B4-9EC4-6AA4ABB8E125} - System32\Tasks\Norton Security with Backup\Norton Error Processor => C:\Program Files (x86)\Norton Security with Backup\Engine\22.5.5.15\SymErr.exe [2015-11-05] (Symantec Corporation) Task: {D4BAD6E0-5D74-4A26-B532-FC364E8AF079} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.) Task: {E2D999E4-6B60-43E7-9929-33CE5A968C3C} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton Security with Backup\Engine\22.5.5.15\WSCStub.exe [2016-01-06] (Symantec Corporation) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\NUAutoUpdate.job => C:\Program Files (x86)\Symantec\Norton Utilities 16\SULauncher.exe ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== 2015-07-29 11:23 - 2015-10-02 19:49 - 00116344 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2015-09-23 15:47 - 2015-09-23 15:47 - 00085800 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2015-10-13 04:45 - 2015-10-13 04:45 - 01328912 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2013-05-07 00:45 - 2013-05-07 00:45 - 00936728 ____N () C:\Program Files (x86)\ASUS\AXSP\1.01.02\atkexComSvc.exe 2015-07-29 11:24 - 2015-10-11 20:05 - 00709408 _____ () C:\Program Files\NVIDIA Corporation\ShadowPlay\gamecaster64.dll 2015-07-29 11:24 - 2015-10-11 20:05 - 00855328 _____ () C:\Program Files\NVIDIA Corporation\ShadowPlay\twitchsdk64.dll 2015-03-06 17:07 - 2015-03-06 17:07 - 00908568 _____ () C:\Program Files\Logitech Gaming Software\libGLESv2.dll 2015-10-14 09:35 - 2015-10-14 09:35 - 01095448 _____ () C:\Program Files\Logitech Gaming Software\platforms\qwindows.dll 2015-03-06 17:07 - 2015-03-06 17:07 - 00060184 _____ () C:\Program Files\Logitech Gaming Software\libEGL.dll 2015-10-14 09:35 - 2015-10-14 09:35 - 00240408 _____ () C:\Program Files\Logitech Gaming Software\imageformats\qjpeg.dll 2015-10-15 20:10 - 2015-10-08 15:53 - 00055744 _____ () C:\Program Files\WALTR\x86\AnimationService.exe 2014-01-02 18:32 - 2016-03-09 12:30 - 00036496 _____ () C:\Program Files (x86)\ASUS\AXSP\1.01.02\PEbiosinterface32.dll 2014-01-02 18:32 - 2013-05-07 00:45 - 00104448 ____N () C:\Program Files (x86)\ASUS\AXSP\1.01.02\ATKEX.dll 2015-07-29 11:24 - 2015-10-11 20:05 - 00013088 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll 2015-10-13 04:46 - 2015-10-13 04:46 - 01040144 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2015-09-23 15:47 - 2015-09-23 15:47 - 00073512 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2015-10-13 04:45 - 2015-10-13 04:45 - 00237328 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxslt.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\ProgramData\TEMP:792D4CF1 [264] ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-13 19:34 - 2009-06-10 14:00 - 00000824 ____N C:\Windows\system32\Drivers\etc\hosts ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-981822129-3063170520-1044425282-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Scott\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 64.59.135.147 - 64.59.128.113 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) MSCONFIG\startupreg: AthBtTray => "C:\Program Files (x86)\Bluetooth Suite\athbttray.exe" MSCONFIG\startupreg: AtherosBtStack => "C:\Program Files (x86)\Bluetooth Suite\btvstack.exe" MSCONFIG\startupreg: Overwolf => ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{C8AD31CB-F7DD-46AE-8649-E35AADDA4DEB}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{42B7619E-CCF3-469D-8737-C5157CE58191}] => (Allow) C:\Program Files\Vuze\Azureus.exe FirewallRules: [{5B74649A-DD80-498F-95ED-732EA51867E5}] => (Allow) C:\Program Files\Vuze\Azureus.exe FirewallRules: [{AA81EBE4-2A10-40C1-BB28-20E2CA9229B9}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2045\Agent.exe FirewallRules: [{EC3E3B47-410D-47FA-AA31-CD781766C7DF}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2045\Agent.exe FirewallRules: [TCP Query User{E9D7BC37-5554-42CC-9C38-57EF37AC9E7D}C:\program files (x86)\starcraft ii\versions\base26490\sc2.exe] => (Allow) C:\program files (x86)\starcraft ii\versions\base26490\sc2.exe FirewallRules: [UDP Query User{708E668A-60AC-4496-908C-31D258879402}C:\program files (x86)\starcraft ii\versions\base26490\sc2.exe] => (Allow) C:\program files (x86)\starcraft ii\versions\base26490\sc2.exe FirewallRules: [TCP Query User{A3235787-1A6C-4074-9525-52DE8F4BC24D}C:\program files\vuze\azureus.exe] => (Block) C:\program files\vuze\azureus.exe FirewallRules: [UDP Query User{5C1D9B39-64BC-4439-A899-7FD6658FDC47}C:\program files\vuze\azureus.exe] => (Block) C:\program files\vuze\azureus.exe FirewallRules: [{531D8C4D-1AFA-47D3-8B1D-20CE052311F4}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe FirewallRules: [{E801BD4F-708F-4C29-BB7A-336A7BB062B8}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe FirewallRules: [{4D62605D-8D3E-4AAF-831F-713E1785CD6F}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2380\Agent.exe FirewallRules: [{75045D14-16F9-417D-80FA-CF31032517B5}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2380\Agent.exe FirewallRules: [{E0D1D0B3-4130-4B47-AA95-B54CF62FB015}] => (Allow) LPort=2869 FirewallRules: [{68AB6842-69C8-4188-A9FD-D82866BA4E73}] => (Allow) LPort=1900 FirewallRules: [{22773045-2F87-47A3-A804-424F32DAF6E6}] => (Allow) LPort=2869 FirewallRules: [{17A195EA-7888-46A3-83E7-6C9B7AB02CB5}] => (Allow) LPort=1900 FirewallRules: [{D9202D63-3BD7-4CA7-BBD2-79A1FB82F0D4}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2380\Agent.exe FirewallRules: [{E185B53B-BC62-4EB6-B9AE-BACB657BA9FE}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2380\Agent.exe FirewallRules: [{CCD58131-1AD8-4830-AC54-EA2AECDF9327}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2581\Agent.exe FirewallRules: [{71EE82CD-FF0B-4AF3-9E90-847F790F0D1A}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2581\Agent.exe FirewallRules: [{46F01ADD-57C9-424C-A431-5886AC522E10}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe FirewallRules: [{4D3F8F0C-8F67-4B9C-A99C-9784B7B30262}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe FirewallRules: [{E974ACAB-FC6F-4306-8A85-D20E891D7000}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe FirewallRules: [{808F2A0A-E086-494F-AF8E-823392F28645}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe FirewallRules: [{B943961D-9B2B-47F6-99BA-AC4DF4673570}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2638\Agent.exe FirewallRules: [{B12A13A0-E354-422E-8603-1FDE7D255546}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2638\Agent.exe FirewallRules: [{E57B72E8-13C4-4D7E-A44E-AD9EB392CB18}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2680\Agent.exe FirewallRules: [{91134A7A-2000-41DC-BF41-9F8D9D189A77}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2680\Agent.exe FirewallRules: [{A2970F0A-7149-49C3-A5D7-7A9351A9908A}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2689\Agent.exe FirewallRules: [{B4CA9F17-4AF5-48C8-A993-6D5EB4DB7280}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2689\Agent.exe FirewallRules: [TCP Query User{8F5191E1-B12F-4B0D-A534-EA498EC107E5}C:\program files (x86)\starcraft ii\versions\base28667\sc2.exe] => (Block) C:\program files (x86)\starcraft ii\versions\base28667\sc2.exe FirewallRules: [UDP Query User{F440DC39-2D26-4132-AB7D-5C46DF837324}C:\program files (x86)\starcraft ii\versions\base28667\sc2.exe] => (Block) C:\program files (x86)\starcraft ii\versions\base28667\sc2.exe FirewallRules: [{8515D5CA-FEE4-416D-B115-C7B01D026DC7}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2717\Agent.exe FirewallRules: [{5EB4B842-2A05-4F6F-8636-FFFB8053174B}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2717\Agent.exe FirewallRules: [{60853106-473A-4E30-8A43-BC4C7098C1D6}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2737\Agent.exe FirewallRules: [{0167A682-CA46-4379-B25E-F6D6CF565054}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2737\Agent.exe FirewallRules: [{BC31A9A4-7580-4EB5-913B-4995108A64C5}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2753\Agent.exe FirewallRules: [{CB643E3A-007E-416B-BFD3-5CF34526C9FC}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2753\Agent.exe FirewallRules: [{AFD653AC-678C-4B06-A5E4-3E118D40C84C}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2787\Agent.exe FirewallRules: [{E807269F-C239-41CE-AEAF-DCC9CAC16E2D}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2787\Agent.exe FirewallRules: [{40D8895B-D12B-4437-943A-582345112CAC}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2816\Agent.exe FirewallRules: [{170DA56C-42C9-4517-AAEE-C7946136448F}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2816\Agent.exe FirewallRules: [{F1946954-6FD8-4BBF-B5CC-13DFB798CA64}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2880\Agent.exe FirewallRules: [{D1167CDF-EFEA-4B52-B1ED-B4163ED45AE0}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2880\Agent.exe FirewallRules: [{CADEF5FB-5FF3-48D7-9BFA-06DC8C15D58E}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3023\Agent.exe FirewallRules: [{1B61F2E9-0E5B-4F66-9972-382F5FA73147}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3023\Agent.exe FirewallRules: [{6211ABDD-BF95-469A-BB2A-9F329CA7D1EE}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3109\Agent.exe FirewallRules: [{D876A6F6-C9DE-4AD1-B94E-1548404D34BD}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3109\Agent.exe FirewallRules: [{AF771CF8-CFDB-4A5A-83C0-68194E1625BC}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3147\Agent.exe FirewallRules: [{273596FB-2AF3-449B-9380-D4634C712F14}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3147\Agent.exe FirewallRules: [{76BBA0E0-597F-4D5F-BECD-FF36B7BF4E82}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3182\Agent.exe FirewallRules: [{172C5488-1A0F-4C2A-A720-681999FF5FFC}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3182\Agent.exe FirewallRules: [{8B63EE37-B9F8-4A78-A748-4CD03C74142E}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3235\Agent.exe FirewallRules: [{75E158C1-DC00-464D-B0B1-098AE3C22589}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3235\Agent.exe FirewallRules: [{136E72BF-BDDC-477D-A938-C5890D61DC9F}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3286\Agent.exe FirewallRules: [{E0A630C4-75CE-42FB-B025-279DB981192D}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3286\Agent.exe FirewallRules: [{BE0D01AB-0F92-4A53-BE8D-51ECB53D1445}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3372\Agent.exe FirewallRules: [{D2304565-DC74-4A5C-ACFB-F9A0DA814B7F}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3372\Agent.exe FirewallRules: [TCP Query User{4C9E934D-553F-4C01-A518-7BBCF9774114}C:\program files (x86)\starcraft ii\versions\base32283\sc2.exe] => (Allow) C:\program files (x86)\starcraft ii\versions\base32283\sc2.exe FirewallRules: [UDP Query User{0B824854-E8E8-4809-9E02-F6C67B7440E7}C:\program files (x86)\starcraft ii\versions\base32283\sc2.exe] => (Allow) C:\program files (x86)\starcraft ii\versions\base32283\sc2.exe FirewallRules: [{F1E63090-F73E-4447-9733-E7C0E0494726}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3427\Agent.exe FirewallRules: [{1C838D7B-A6B0-4332-86BF-1DB9397A3111}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3427\Agent.exe FirewallRules: [{FEA8B012-854E-4827-8CF7-0BB1CF1CA6B2}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3454\Agent.exe FirewallRules: [{5D80DCA3-3E37-4299-9395-72FB94945AF4}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3454\Agent.exe FirewallRules: [{C008AAF0-51BC-420F-B4A7-AC154CC1A1FB}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3478\Agent.exe FirewallRules: [{F637F762-F585-4F0E-9079-16FA6C6C33EB}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3478\Agent.exe FirewallRules: [{24E05A37-9135-48D9-A6F9-36852AB1126E}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3507\Agent.exe FirewallRules: [{8A02AB62-10FC-42C2-AB5C-5B332EA34958}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3507\Agent.exe FirewallRules: [{A132C35B-45C0-4B53-93AF-27FB4ACAD752}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3526\Agent.exe FirewallRules: [{F8106E8D-C1CC-4F8A-8AE1-797C62ED9C6D}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3526\Agent.exe FirewallRules: [{1615A909-FB06-4354-A4A7-0DBBC3ACBD00}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3632\Agent.exe FirewallRules: [{DD3C2224-A4AE-4F3C-97A8-CC710457FF33}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3632\Agent.exe FirewallRules: [{B29DCA38-6F11-43BC-A86C-DACFBF8FC776}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3634\Agent.exe FirewallRules: [{30D1D228-183A-4F0F-968F-CC1575DC9EA8}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3634\Agent.exe FirewallRules: [{9F3588E8-489F-4FFD-989D-090FE07D025E}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3668\Agent.exe FirewallRules: [{B80476BE-DE3C-40C3-896E-C2C74A3F0CF5}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3668\Agent.exe FirewallRules: [{69D5086E-2561-4963-8314-73198CDAD0BB}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3669\Agent.exe FirewallRules: [{6E64AC4D-4D1A-4451-9B66-945B527A4AEC}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3669\Agent.exe FirewallRules: [{EFE8F950-8430-4A92-8E00-BF62D3A35360}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3688\Agent.exe FirewallRules: [{43697127-C8F5-4728-A919-2F2E27D72A7B}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3688\Agent.exe FirewallRules: [{82F44B59-61DE-4FAE-9967-5FE9DA63E75D}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3689\Agent.exe FirewallRules: [{3820F9CD-66C5-44A7-AFDE-3109088CEDC2}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3689\Agent.exe FirewallRules: [{1E06886A-A2C8-46F4-9CE8-C12CB32B7229}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3715\Agent.exe FirewallRules: [{0ED51A55-DA26-4549-BD68-752A6C1C13D8}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3715\Agent.exe FirewallRules: [TCP Query User{559AD77B-2B11-48C3-BE0E-39A20251DF60}C:\program files (x86)\heroes of the storm\versions\base34846\heroesofthestorm_x64.exe] => (Allow) C:\program files (x86)\heroes of the storm\versions\base34846\heroesofthestorm_x64.exe FirewallRules: [UDP Query User{20889D24-C082-47A0-91B6-4DF1635926EB}C:\program files (x86)\heroes of the storm\versions\base34846\heroesofthestorm_x64.exe] => (Allow) C:\program files (x86)\heroes of the storm\versions\base34846\heroesofthestorm_x64.exe FirewallRules: [TCP Query User{215377BF-9A8D-44EC-9795-0D81C8EA2A28}C:\program files (x86)\heroes of the storm\versions\base35360\heroesofthestorm_x64.exe] => (Block) C:\program files (x86)\heroes of the storm\versions\base35360\heroesofthestorm_x64.exe FirewallRules: [UDP Query User{12E55E61-8DA1-4E3C-B63E-5B7C136103D2}C:\program files (x86)\heroes of the storm\versions\base35360\heroesofthestorm_x64.exe] => (Block) C:\program files (x86)\heroes of the storm\versions\base35360\heroesofthestorm_x64.exe FirewallRules: [TCP Query User{081B6F6E-2AAE-4D5E-AA1C-473148446212}C:\program files (x86)\heroes of the storm\versions\base35360\heroesofthestorm.exe] => (Block) C:\program files (x86)\heroes of the storm\versions\base35360\heroesofthestorm.exe FirewallRules: [UDP Query User{08A6576C-0C6B-400C-99C9-7555941AC255}C:\program files (x86)\heroes of the storm\versions\base35360\heroesofthestorm.exe] => (Block) C:\program files (x86)\heroes of the storm\versions\base35360\heroesofthestorm.exe FirewallRules: [{01DCBFA4-00C3-4E1B-ABB3-855124FB0ACC}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe FirewallRules: [{B6D8E72B-5E9C-4C1F-B1A0-6582C6628852}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe FirewallRules: [{E3B90077-4C11-4DC7-B5F7-BE68BEBFD41A}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe FirewallRules: [{C583B00D-AD01-4E32-BF92-DD4141F4D1CD}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe FirewallRules: [TCP Query User{DB91FEA7-413B-4A8E-9C76-0DFD14BBFA52}C:\program files (x86)\heroes of the storm\versions\base35634\heroesofthestorm.exe] => (Allow) C:\program files (x86)\heroes of the storm\versions\base35634\heroesofthestorm.exe FirewallRules: [UDP Query User{901C2ED4-3128-491B-9009-144322441BD9}C:\program files (x86)\heroes of the storm\versions\base35634\heroesofthestorm.exe] => (Allow) C:\program files (x86)\heroes of the storm\versions\base35634\heroesofthestorm.exe FirewallRules: [{EC9CDDAD-EDFC-483D-A73F-2AE78AD5E40F}] => (Allow) C:\Program Files (x86)\ASUS\AI Suite III\Wi-Fi GO!\AssistTools\WiFi GO! Server.exe FirewallRules: [{2F7370E5-EC1B-4250-B8AD-756E5051D18C}] => (Allow) C:\Program Files (x86)\ASUS\AI Suite III\Wi-Fi GO!\AssistTools\WiFi GO! Server.exe FirewallRules: [{A8CE389B-CB62-40C3-A82A-5AF5B72E3DFD}] => (Allow) C:\Program Files (x86)\ASUS\AI Suite III\Wi-Fi GO!\ASUSDMS.exe FirewallRules: [{42DBD23D-C8A5-40D7-AEF2-1B78E7D29BD4}] => (Allow) C:\Program Files (x86)\ASUS\AI Suite III\Wi-Fi GO!\ASUSDMS.exe FirewallRules: [TCP Query User{D3485981-5F65-4009-AB42-FF93E88E1FA5}C:\program files (x86)\heroes of the storm\versions\base35702\heroesofthestorm.exe] => (Allow) C:\program files (x86)\heroes of the storm\versions\base35702\heroesofthestorm.exe FirewallRules: [UDP Query User{6AE19172-3093-4639-8A5C-A8B0BDD7920B}C:\program files (x86)\heroes of the storm\versions\base35702\heroesofthestorm.exe] => (Allow) C:\program files (x86)\heroes of the storm\versions\base35702\heroesofthestorm.exe FirewallRules: [{9177FD2B-685B-4276-A1F1-138FA231AD94}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe FirewallRules: [{5904A8D5-A38C-4207-A319-84AF95C9A393}] => (Allow) LPort=2869 FirewallRules: [{7A3516B9-4851-497C-8F08-12B50C93738F}] => (Allow) LPort=1900 FirewallRules: [TCP Query User{B2B42031-77B0-438E-B213-22E2787E4252}C:\program files (x86)\heroes of the storm\versions\base36144\heroesofthestorm.exe] => (Block) C:\program files (x86)\heroes of the storm\versions\base36144\heroesofthestorm.exe FirewallRules: [UDP Query User{BF9428F8-DA81-4582-836A-DEC0A583AE16}C:\program files (x86)\heroes of the storm\versions\base36144\heroesofthestorm.exe] => (Block) C:\program files (x86)\heroes of the storm\versions\base36144\heroesofthestorm.exe FirewallRules: [{3B1C9CE1-E707-4A48-8F6C-AEAFDA1C8C6F}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{4459D98C-3EF5-476E-B791-D1A89BB75FF7}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{84DF1F79-0018-47BC-ADE7-F3029BCB2E4B}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{5E30B0AC-A2A5-45B7-8881-DE08EF78E937}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{A03E02E8-918D-4A76-9586-F58C0FF80B25}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe FirewallRules: [{9B10E32E-3A71-4E15-9500-B533B8005857}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{8265817E-05EB-4ACF-AB86-B28E73FA4967}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{0DA12AB0-D0DE-465B-B959-0908442B6E45}] => (Allow) C:\Nexon\Library\dragonnest\appdata\DragonNest.exe FirewallRules: [{F9274449-2149-4D74-AFC8-AC7E4EF09F3D}] => (Allow) C:\Nexon\Library\dragonnest\appdata\DragonNest.exe FirewallRules: [{9B7C5319-0D5C-4C61-853B-E20B552E70F9}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{07E5AFDB-A55E-4534-A893-9D582CC1E742}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{440F4588-5182-41B7-9180-F9A498209268}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{714E9131-DD22-4AB2-AD05-8B125B801498}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [TCP Query User{D62E8FB8-CC5D-4A58-BA69-36CEA584CC14}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe FirewallRules: [UDP Query User{AD1382BA-CBB9-47F4-A6A5-A515BE61A216}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe FirewallRules: [TCP Query User{B0C43BC2-168E-4AFF-859C-D5510038E830}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe FirewallRules: [UDP Query User{DFD98516-97AB-499E-ACBC-BE06606496E5}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe FirewallRules: [{05B888D3-573A-4293-9CA1-8ED312BD996A}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Restore Points ========================= 18-02-2016 16:14:34 Scheduled Checkpoint 26-02-2016 10:15:07 Scheduled Checkpoint 05-03-2016 13:43:05 Scheduled Checkpoint 09-03-2016 10:17:10 Norton_Power_Eraser_20160309101704276 ==================== Faulty Device Manager Devices ============= Name: Qualcomm Atheros AR9462 Bluetooth 4.0 + HS Adapter Description: Qualcomm Atheros AR9462 Bluetooth 4.0 + HS Adapter Class Guid: {e0cbf06c-cd8b-4647-bb8a-263b43f0f974} Manufacturer: Atheros Communications Service: BTHUSB Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (03/09/2016 12:32:20 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/09/2016 10:23:00 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/09/2016 09:45:33 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/09/2016 07:42:58 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/09/2016 07:30:56 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/08/2016 01:45:45 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/08/2016 12:58:43 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/08/2016 07:47:24 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/08/2016 07:38:36 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 10964358 Error: (03/08/2016 07:38:36 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 10964358 System errors: ============= Error: (03/09/2016 12:31:10 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: The following boot-start or system-start driver(s) failed to load: cdrom Error: (03/09/2016 10:21:49 AM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: The following boot-start or system-start driver(s) failed to load: cdrom Error: (03/09/2016 10:16:04 AM) (Source: DCOM) (EventID: 10016) (User: Scott-PC) Description: application-specificLocalActivation{EA022610-0748-4C24-B229-6C507EBDFDBB}{EA022610-0748-4C24-B229-6C507EBDFDBB}Scott-PCScottS-1-5-21-981822129-3063170520-1044425282-1000LocalHost (Using LRPC) Error: (03/09/2016 10:16:04 AM) (Source: DCOM) (EventID: 10016) (User: Scott-PC) Description: application-specificLocalActivation{EA022610-0748-4C24-B229-6C507EBDFDBB}{EA022610-0748-4C24-B229-6C507EBDFDBB}Scott-PCScottS-1-5-21-981822129-3063170520-1044425282-1000LocalHost (Using LRPC) Error: (03/09/2016 10:16:04 AM) (Source: DCOM) (EventID: 10016) (User: Scott-PC) Description: application-specificLocalActivation{EA022610-0748-4C24-B229-6C507EBDFDBB}{EA022610-0748-4C24-B229-6C507EBDFDBB}Scott-PCScottS-1-5-21-981822129-3063170520-1044425282-1000LocalHost (Using LRPC) Error: (03/09/2016 10:16:04 AM) (Source: DCOM) (EventID: 10016) (User: Scott-PC) Description: application-specificLocalActivation{EA022610-0748-4C24-B229-6C507EBDFDBB}{EA022610-0748-4C24-B229-6C507EBDFDBB}Scott-PCScottS-1-5-21-981822129-3063170520-1044425282-1000LocalHost (Using LRPC) Error: (03/09/2016 10:16:04 AM) (Source: DCOM) (EventID: 10016) (User: Scott-PC) Description: application-specificLocalActivation{EA022610-0748-4C24-B229-6C507EBDFDBB}{EA022610-0748-4C24-B229-6C507EBDFDBB}Scott-PCScottS-1-5-21-981822129-3063170520-1044425282-1000LocalHost (Using LRPC) Error: (03/09/2016 10:16:04 AM) (Source: DCOM) (EventID: 10016) (User: Scott-PC) Description: application-specificLocalActivation{EA022610-0748-4C24-B229-6C507EBDFDBB}{EA022610-0748-4C24-B229-6C507EBDFDBB}Scott-PCScottS-1-5-21-981822129-3063170520-1044425282-1000LocalHost (Using LRPC) Error: (03/09/2016 09:56:16 AM) (Source: DCOM) (EventID: 10016) (User: Scott-PC) Description: application-specificLocalActivation{EA022610-0748-4C24-B229-6C507EBDFDBB}{EA022610-0748-4C24-B229-6C507EBDFDBB}Scott-PCScottS-1-5-21-981822129-3063170520-1044425282-1000LocalHost (Using LRPC) Error: (03/09/2016 09:56:16 AM) (Source: DCOM) (EventID: 10016) (User: Scott-PC) Description: application-specificLocalActivation{EA022610-0748-4C24-B229-6C507EBDFDBB}{EA022610-0748-4C24-B229-6C507EBDFDBB}Scott-PCScottS-1-5-21-981822129-3063170520-1044425282-1000LocalHost (Using LRPC) CodeIntegrity: =================================== Date: 2016-03-09 12:32:36.407 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\sxs.dll because the set of per-page image hashes could not be found on the system. Date: 2016-03-09 10:22:35.296 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\sxs.dll because the set of per-page image hashes could not be found on the system. Date: 2016-03-09 10:20:05.174 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\sxs.dll because the set of per-page image hashes could not be found on the system. Date: 2016-03-09 09:46:11.717 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\sxs.dll because the set of per-page image hashes could not be found on the system. Date: 2016-03-09 07:30:20.165 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\sxs.dll because the set of per-page image hashes could not be found on the system. Date: 2016-03-08 14:39:43.824 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\sxs.dll because the set of per-page image hashes could not be found on the system. Date: 2016-03-08 14:33:46.794 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\sxs.dll because the set of per-page image hashes could not be found on the system. Date: 2016-03-08 14:15:26.384 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\sxs.dll because the set of per-page image hashes could not be found on the system. Date: 2016-03-08 14:08:37.206 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\sxs.dll because the set of per-page image hashes could not be found on the system. Date: 2016-03-08 14:00:52.959 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\sxs.dll because the set of per-page image hashes could not be found on the system. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i7-4770 CPU @ 3.40GHz Percentage of memory in use: 26% Total physical RAM: 8129.66 MB Available physical RAM: 5963.71 MB Total Virtual: 16257.53 MB Available Virtual: 13901.9 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:931.41 GB) (Free:232.85 GB) NTFS Drive d: () (Fixed) (Total:465.75 GB) (Free:174.18 GB) NTFS ==>[system with boot components (obtained from drive)] Drive f: (THUMB) (Removable) (Total:1.96 GB) (Free:1.96 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: CE32E1F5) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=931.4 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 31433143) Partition 1: (Active) - (Size=465.8 GB) - (Type=07 NTFS) ======================================================== Disk: 2 (MBR Code: Windows 7 or 8) (Size: 2 GB) (Disk ID: 00000000) Partition: GPT. ==================== End of Addition.txt ============================