OTL Extras logfile created on: 4/6/2016 4:55:20 PM - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Rafael\Desktop 64bit- Professional (Version = 6.2.9200) - Type = NTWorkstation Internet Explorer (Version = 9.11.10586.0) Locale: 00000409 | Country: Estados Unidos | Language: ENU | Date Format: M/d/yyyy 3.90 Gb Total Physical Memory | 1.78 Gb Available Physical Memory | 45.76% Memory free 5.08 Gb Paging File | 2.61 Gb Available in Paging File | 51.36% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86) Drive C: | 433.15 Gb Total Space | 347.56 Gb Free Space | 80.24% Space Free | Partition Type: NTFS Drive D: | 27.84 Gb Total Space | 27.45 Gb Free Space | 98.60% Space Free | Partition Type: NTFS Computer Name: DESKTOP-S7NN2CN | User Name: Rafael | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 90 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .html[@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation) .url[@ = InternetShortcut] -- C:\WINDOWS\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] .cpl [@ = cplfile] -- C:\WINDOWS\SysWow64\control.exe (Microsoft Corporation) .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation) [color=#E56717]========== Shell Spawning ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) htmlfile [opennew] -- Reg Error: Key error. htmlfile [print] -- "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation) Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN) Directory [Varredura de pastas ByteFence] -- "C:\Program Files\ByteFence\ByteFence.exe" /scan:"%1" Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) htmlfile [opennew] -- Reg Error: Key error. http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation) Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN) Directory [Varredura de pastas ByteFence] -- "C:\Program Files\ByteFence\ByteFence.exe" /scan:"%1" Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error. [color=#E56717]========== Security Center Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 56 9D C1 CF 7B 53 D1 01 [binary data] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade] "UpgradeTime" = [binary data] "DontEnumerateCommonFilesUpgradeExe" = 1 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade] "UpgradeTime" = Reg Error: Unknown registry data type -- File not found [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 "DoNotAllowExceptions" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 "DoNotAllowExceptions" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 "DoNotAllowExceptions" = 0 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{54844F61-7664-46EC-BE9D-3D6BCA2CD335}" = lport=5353 | protocol=17 | dir=in | app=c:\program files (x86)\google\chrome\application\chrome.exe | "{7B0D03C8-61A8-4C62-BA2C-B47692FB846D}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office15\outlook.exe | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{00634A82-3FC2-4750-8806-A3500E09A834}" = dir=in | name=@{microsoft.microsoftedge_25.10586.0.0_neutral__8wekyb3d8bbwe?ms-resource://microsoft.microsoftedge/resources/appname} | "{0280B938-1345-4EA2-B2E1-5FC6B455B4E7}" = dir=out | name=@{microsoft.3dbuilder_10.10.38.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.3dbuilder/resources/appstorename} | "{030B39E3-B53C-44CF-8370-31DCEA0C75E4}" = dir=out | name=onenote | "{03F6B051-38CC-4580-AE48-FA1792AE2A23}" = dir=in | name=sway | "{089A0F87-0229-474F-A854-B574774C6111}" = dir=in | name=@{microsoft.windowscommunicationsapps_17.6769.40721.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/hxcommintl/appmanifest_outlookdesktop_displayname} | "{0C77D08C-18E5-426B-AD22-F1089408C56A}" = protocol=6 | dir=in | app=c:\program files\kmspico\service_kms.exe | "{0C7F06F0-50F2-48DC-8D7E-A51F8DEEEFF2}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office15\ucmapi.exe | "{101D11D7-5319-4E2D-9540-16CA28F53565}" = dir=in | name=@{microsoft.aad.brokerplugin_1000.10586.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.aad.brokerplugin/resources/packagedisplayname} | "{10762108-A5A6-46AB-8500-9D5131DB1D6F}" = dir=in | app=c:\program files\newext\jsinjector.exe | "{12EFAFFA-095A-4564-920B-C046CA90A4E0}" = dir=out | name=xbox | "{136116CC-2BE3-4197-A3E3-51CDC127D5CC}" = dir=out | name=@{microsoft.accountscontrol_10.0.10586.0_neutral__cw5n1h2txyewy?ms-resource://microsoft.accountscontrol/resources/displayname} | "{17CB32A9-563A-494D-B6D1-EBDBE8BE7ADB}" = dir=in | app=c:\program files\newext\jsinjector.exe | "{1CB335C1-B752-40AB-9E05-47806F003CDD}" = dir=out | name=@{microsoft.appconnector_1.3.3.0_neutral__8wekyb3d8bbwe?ms-resource://microsoft.appconnector/resources/connectorstubtitle} | "{1DD9108B-45FB-4F26-8A28-8B7A586A0C50}" = dir=in | app=c:\program files\newext\jsinjector.exe | "{1DDB230B-C659-44BC-A0DC-4F8B6EC9BEA9}" = protocol=58 | dir=out | name=@iphlpsvc.dll,-503 | "{1F3AAB5D-2FE7-46B1-A9AD-2F1F43DE8A53}" = dir=out | name=@{microsoft.people_10.0.10500.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.people/resources/appstorename} | "{1F6B1BC7-F0B1-47FC-A68B-3EDA1A8852B4}" = dir=out | name=@{microsoft.windows.photos_16.325.12390.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windows.photos/resources/appstorename} | "{200FD3B5-43F9-45F7-8AB4-1BF47D59649C}" = dir=out | name=@{microsoft.windows.cloudexperiencehost_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cloudexperiencehost/resources/appdescription} | "{20AD2DC1-C591-477B-9803-9D44DF3F0315}" = protocol=6 | dir=out | app=c:\users\rafael\appdata\roaming\utorrent\utorrent.exe | "{20D2C7BB-24F3-4155-BAD5-C8E446242AD1}" = dir=out | name=@{microsoft.windowsfeedback_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windowsfeedback/feedbackapp.resources/appname/text} | "{2191D4FA-EDE6-4D5C-845B-1200863D97E9}" = dir=in | app=c:\program files\newext\jsinjector.exe | "{221C15C2-E7E4-41BF-9FD2-3366CACE5AC9}" = dir=in | app=c:\program files\newext\jsinjector.exe | "{230E8868-4AB0-425D-BCE3-204B2D0A8B62}" = protocol=58 | dir=in | app=system | "{25F587BE-9852-4C60-86F0-8B6F841FCE54}" = dir=in | name=@{microsoft.aad.brokerplugin_1000.10586.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.aad.brokerplugin/resources/packagedisplayname} | "{26072619-311D-4BD2-9769-C0810CE11813}" = dir=out | name=@{microsoft.aad.brokerplugin_1000.10586.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.aad.brokerplugin/resources/packagedisplayname} | "{26BAED29-41E9-4AF3-ACFF-C444A910945A}" = dir=in | name=@{microsoft.bingsports_4.8.268.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/applicationtitlewithbranding} | "{271CA385-95F7-468A-81C3-79E74F932AC5}" = dir=in | name=@{microsoft.windows.cloudexperiencehost_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cloudexperiencehost/resources/appdescription} | "{2A036D4B-6162-4B6A-865F-94927018DD85}" = dir=out | name=@{microsoft.bingweather_4.8.277.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/applicationtitlewithbranding} | "{2BC5D3DE-32A6-4D69-BBC6-729A04F7F6E0}" = protocol=6 | dir=in | app=c:\program files\kmspico\autopico.exe | "{2ED4DEB5-A968-4DA8-9EC3-38FE7347EC16}" = dir=out | name=@{microsoft.windows.cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cortana/resources/displayname} | "{2FD0D046-6656-4683-8069-2F5577D365A4}" = dir=in | app=c:\program files\newext\jsinjector.exe | "{32ADA609-5AF1-4F7E-BFB1-14DC18CF50CE}" = protocol=17 | dir=in | app=c:\program files (x86)\popcorn time\updater.exe | "{33DAAC42-EA4A-48C6-8253-AD33711383AC}" = dir=out | name=@{microsoft.windowsmaps_4.1601.10150.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsmaps/resources/appstorename} | "{35EF86BB-8D6F-43F9-8721-6E0F9DB89602}" = dir=out | name=@{microsoft.zunemusic_3.6.15131.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/ids_manifest_music_app_name} | "{360AA18A-E99F-4DB3-A4C3-D897F49066BC}" = dir=in | name=@{microsoft.windowsstore_2016.29.13.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsstore/resources/storetitle} | "{3DCD599E-A7DD-4422-B1E9-DF3FFCE59D83}" = dir=out | name=@{microsoft.commsphone_2.15.25005.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.commsphone/resources/appstorename} | "{3E400C51-19D5-4834-9169-4859E0DCCB85}" = dir=out | name=@{microsoft.connectivitystore_1.1603.1.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.connectivitystore/mswifiresources/appstorename} | "{3F3D616C-8283-4C4F-BF63-9CA0D07391E2}" = dir=out | name=@{microsoft.xboxgamecallableui_1000.10586.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.xboxgamecallableui/resources/pkgdisplayname} | "{4290025F-84F5-47FA-8C4E-75D590D70BF5}" = dir=in | app=c:\program files\newext\jsinjector.exe | "{46427E0A-C8C3-4475-8A0F-1B34981B19A0}" = dir=out | name=@{microsoft.getstarted_3.5.11.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.getstarted/resources/appstorename} | "{47E820F9-C895-4DB6-AE48-E6181D461DAE}" = dir=out | name=@{microsoft.zunevideo_3.6.18671.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/ids_manifest_video_app_name} | "{47EF9969-4EBD-423F-AD75-309D150A30BA}" = dir=out | name=@{windows.contactsupport_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://windows.contactsupport/resources/appdisplayname} | "{48FC7F2D-65F1-4297-9109-1B6B55E5E48A}" = protocol=6 | dir=in | app=c:\program files (x86)\popcorn time\popcorntimedesktop.exe | "{4951D351-824A-494A-8AF6-FA1E5F920646}" = dir=in | name=@{microsoft.commsphone_2.15.25005.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.commsphone/resources/appstorename} | "{4D17BAFE-10FA-4166-A529-125CD594808B}" = dir=out | name=microsoft solitaire collection | "{4F536AB6-CC2A-493B-915F-5C03699EE4F2}" = dir=out | name=@{microsoft.bingfinance_4.8.268.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/applicationtitlewithbranding} | "{506389BB-15A6-4D7A-84C9-B30705611B2D}" = dir=out | name=@{microsoft.xboxgamecallableui_1000.10586.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.xboxgamecallableui/resources/pkgdisplayname} | "{5096C9FD-E234-40FE-B04F-D8F0B3992EBE}" = dir=out | name=@{microsoft.people_10.0.10811.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.people/resources/appstorename} | "{51797616-2BB1-4105-8F26-AF9A02DD8573}" = dir=in | app=c:\program files\newext\jsinjector.exe | "{53ACDC2F-DB1A-433F-9EBE-B0EBAF894E93}" = dir=out | name=@{microsoft.aad.brokerplugin_1000.10586.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.aad.brokerplugin/resources/packagedisplayname} | "{54904A8D-0167-45FF-816F-86A346D0D703}" = dir=in | name=xbox | "{56DE7E2E-A8D2-4E05-BDB1-C6CCA997C770}" = dir=in | name=@{microsoft.microsoftofficehub_17.6811.23771.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.microsoftofficehub/officehubintl/appmanifest_getoffice_displayname} | "{576AF4FB-A6A9-479A-8403-7C10FB97136A}" = protocol=17 | dir=in | app=c:\program files (x86)\popcorn time\popcorntimedesktop.exe | "{57ECCED0-89D9-4AA3-85A5-429709C55E30}" = dir=in | app=c:\program files\newext\jsinjector.exe | "{581677A7-0068-45F6-B594-EC5DE2B01A8D}" = dir=out | name=@{microsoft.connectivitystore_1.1603.1.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.connectivitystore/mswifiresources/appstorename} | "{58886481-799B-4957-B30B-04BE8F7726CD}" = dir=in | name=@{microsoft.messaging_2.13.20000.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.messaging/microsoft.apps.messaging.skype/skypemessaging.resources/skype_appstorename} | "{58CFE9ED-82BF-48E1-9B2A-EFBBC6AC8A4B}" = dir=out | name=@{microsoft.lockapp_10.0.10586.0_neutral__cw5n1h2txyewy?ms-resource://microsoft.lockapp/resources/appdisplayname} | "{5992D358-AE98-4822-9093-EAB57C352048}" = dir=out | name=@{microsoft.microsoftofficehub_17.6811.23771.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.microsoftofficehub/officehubintl/appmanifest_getoffice_displayname} | "{59CA703B-9911-4B85-8BC1-3CB56472BE71}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office15\lync.exe | "{5A9AAA59-57BC-411B-A5CF-D65779BC5CA0}" = dir=out | name=@{microsoft.bingweather_4.8.277.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/applicationtitlewithbranding} | "{5B04E137-6CD3-45B6-81FD-AD47BBDF09F9}" = dir=out | name=twitter | "{5D5AD6B5-37D3-4681-B512-F56FFE2B2798}" = dir=in | app=c:\program files\newext\jsinjector.exe | "{5D5F0E37-633F-4E46-8743-ECF45B93E4BF}" = dir=in | name=xbox | "{5E8FC281-6BBF-438A-892E-4CAFBE1FF111}" = dir=out | name=@{microsoft.getstarted_3.5.11.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.getstarted/resources/appstorename} | "{61D36740-2AEA-430E-A2AB-E10BC918C5D3}" = dir=out | name=@{microsoft.appconnector_1.3.3.0_neutral__8wekyb3d8bbwe?ms-resource://microsoft.appconnector/resources/connectorstubtitle} | "{63FB687C-BAD3-4F37-A531-D9C16E8FD40E}" = protocol=17 | dir=out | app=c:\users\rafael\appdata\roaming\utorrent\utorrent.exe | "{649D77C3-6AB5-4252-9A3F-77977021B6DF}" = dir=in | app=c:\program files\newext\jsinjector.exe | "{64C792D8-F881-4A88-A87E-6E4B695C5343}" = dir=in | app=c:\program files\newext\jsinjector.exe | "{6547C1B5-4925-416F-B2A3-B7C2FCE2C5D1}" = dir=in | name=onenote | "{6AE25ABF-1C7F-4F41-AB25-7132FCE77465}" = protocol=6 | dir=in | app=c:\users\rafael\appdata\roaming\utorrent\utorrent.exe | "{6CA5899C-E9BF-442D-8008-81C06E9CFF40}" = dir=out | name=@{microsoft.windowsphone_10.1602.3010.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphone/resources/appstorename} | "{6DD674A2-1B98-4F79-A884-D71B07346BAE}" = dir=in | name=onenote | "{7001D469-7261-4EF7-A6CC-A11C643EAA1B}" = dir=in | app=c:\program files\newext\jsinjector.exe | "{71C500D2-08B1-43FE-BDA0-3908A4032351}" = protocol=17 | dir=in | app=c:\program files\kmspico\kmseldi.exe | "{775BC5D5-AD41-4440-BCD6-41FF68DFCFED}" = dir=out | name=@{microsoft.messaging_2.13.20000.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.messaging/microsoft.apps.messaging.skype/skypemessaging.resources/skype_appstorename} | "{78DAB990-6A1E-4E08-B01E-DB72B25F2473}" = dir=in | name=@{microsoft.windowsstore_2016.29.13.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsstore/resources/storetitle} | "{7914FE1A-C9E0-4301-AF25-5AC404E89917}" = dir=in | app=c:\program files\newext\jsinjector.exe | "{7AC67FE3-BB54-4A17-BE90-F649953D0E3D}" = dir=out | name=@{microsoft.3dbuilder_10.10.38.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.3dbuilder/resources/appstorename} | "{7C06801F-9ED5-4646-AEEB-333779E935E9}" = dir=in | name=microsoft solitaire collection | "{7D6A5671-4D8F-4709-8475-00A0B3386DB5}" = dir=in | name=@{microsoft.bingweather_4.8.277.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/applicationtitlewithbranding} | "{7E7EF9E0-B78B-4AB9-B76B-58CA3D2598F7}" = dir=out | name=onenote | "{7E9490AA-B206-44DB-8810-63DD70B61402}" = dir=in | name=sway | "{7FA0AB6D-EF2C-4A0F-9C19-50AA888A1144}" = protocol=17 | dir=in | app=c:\users\rafael\appdata\roaming\utorrent\utorrent.exe | "{7FE7EABD-C479-4FBB-A579-366733E1D600}" = dir=out | name=@{microsoft.bingsports_4.8.268.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/applicationtitlewithbranding} | "{80491CFD-BC61-4774-95A4-6BF4A49E6549}" = dir=in | name=@{microsoft.windowscommunicationsapps_17.6769.40721.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/hxcommintl/appmanifest_outlookdesktop_displayname} | "{81220279-D4D3-4C8F-8106-5A8A38FEC330}" = dir=out | name=@{windows.purchasedialog_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://windows.purchasedialog/resources/displayname} | "{848AB30E-548A-44D3-8216-B1859230FAA8}" = dir=in | name=@{microsoft.windows.photos_16.325.12390.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windows.photos/resources/appstorename} | "{874BF3F5-E28F-438F-9CA6-9BF14A925F0F}" = dir=out | name=@{microsoft.windowsstore_2016.29.13.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsstore/resources/storetitle} | "{887C0E90-CA5B-4FDD-A6E0-95C01B470793}" = dir=out | name=windows_ie_ac_001 | "{89A837C4-4562-40A8-9F64-059DA205BF12}" = dir=out | name=@{microsoft.xboxidentityprovider_1000.10586.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.xboxidentityprovider/resources/pkgdisplayname} | "{89EF4974-553C-4F0B-B368-B69DE571FA06}" = dir=in | name=@{microsoft.commsphone_2.15.25005.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.commsphone/resources/appstorename} | "{8D731A6E-E00B-4D09-BFC3-951843A398B5}" = dir=in | name=@{microsoft.microsoftedge_25.10586.0.0_neutral__8wekyb3d8bbwe?ms-resource://microsoft.microsoftedge/resources/appname} | "{8F420C76-A896-49B2-A053-F96CBA1BE66A}" = dir=out | name=sway | "{8F8BA4EF-608D-4199-B08B-642EF3368FD8}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office15\ucmapi.exe | "{915D82F1-D1B2-4827-873B-A49B8A40E837}" = dir=out | name=@{microsoft.xboxidentityprovider_1000.10586.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.xboxidentityprovider/resources/pkgdisplayname} | "{939461CB-612A-451A-99EE-18AAF2019549}" = dir=out | name=@{microsoft.microsoftofficehub_17.6811.23771.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.microsoftofficehub/officehubintl/appmanifest_getoffice_displayname} | "{9593D5B5-5AC0-4454-8B42-224470A60EBC}" = dir=out | name=@{microsoft.accountscontrol_10.0.10586.0_neutral__cw5n1h2txyewy?ms-resource://microsoft.accountscontrol/resources/displayname} | "{95C8EB90-B2AF-45CE-B047-BB48B3374D4C}" = dir=in | name=@{microsoft.windows.photos_16.325.12390.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windows.photos/resources/appstorename} | "{96091FB0-9319-4B72-9E3C-B1BE85293856}" = dir=in | app=c:\program files\newext\jsinjector.exe | "{964B28E6-0B1A-47C6-B40B-3F76032AE7DD}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office15\lync.exe | "{968CA423-9549-461C-946E-665E6733E89A}" = dir=in | app=c:\program files\newext\jsinjector.exe | "{976E112E-01B4-404B-BBB3-85E199B86003}" = dir=out | name=@{microsoft.windows.parentalcontrols_1000.10586.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.parentalcontrols/resources/displayname} | "{9872958A-70C6-4D13-85C5-83866A6B1B07}" = dir=out | name=@{microsoft.windows.cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cortana/resources/displayname} | "{9960CF85-BB7E-4F60-A0B0-9F59F4E5AEE9}" = dir=in | app=c:\program files\newext\jsinjector.exe | "{9A960DA3-8E48-4CCA-9E62-81AA072D0591}" = dir=in | app=c:\program files\newext\jsinjector.exe | "{A216A297-EA7F-4D50-AC35-EB0231328200}" = dir=out | name=@{microsoft.bingfinance_4.8.268.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/applicationtitlewithbranding} | "{A24D1701-C30C-4418-A8C8-0841AC96FADD}" = dir=in | app=c:\program files\newext\jsinjector.exe | "{A3D6920A-FB53-4449-A725-FC1CD823C1A6}" = dir=in | app=c:\program files\newext\jsinjector.exe | "{A7476257-7958-4775-B896-D1FB68559A49}" = dir=in | name=@{microsoft.bingweather_4.8.277.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/applicationtitlewithbranding} | "{A93E4E26-12EE-4B4E-B501-CF2E7C603B58}" = protocol=6 | dir=in | app=c:\program files (x86)\popcorn time\updater.exe | "{A9803D18-EB98-4498-BEE8-81DC05C60210}" = dir=in | name=@{microsoft.windows.cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cortana/resources/displayname} | "{AC5D8D12-90C5-4F13-A93A-841F8508D3C1}" = dir=in | name=@{microsoft.bingnews_4.8.268.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/applicationtitlewithbranding} | "{ACC98BA9-DDEE-431C-A0A8-2E5FCDD2DA89}" = dir=out | name=@{microsoft.zunemusic_3.6.15131.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/ids_manifest_music_app_name} | "{AD8D403C-A30E-4CA7-8555-6FA0ED9556B6}" = dir=out | name=@{microsoft.windows.photos_16.325.12390.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windows.photos/resources/appstorename} | "{AEFAAE31-E447-4612-863D-6E0AE4C61C3F}" = protocol=6 | dir=in | app=c:\program files\kmspico\kmseldi.exe | "{B2895A5A-493E-46EA-A8AA-E96D2F49D4DB}" = dir=in | app=c:\program files\newext\jsinjector.exe | "{B2AA64A2-BAD1-48CB-B0C0-3040D202237C}" = dir=out | name=@{microsoft.windowsfeedback_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windowsfeedback/feedbackapp.resources/appname/text} | "{B2CF3934-FD74-4A3D-B857-7F94D735F0A1}" = dir=out | name=@{microsoft.windowsphone_10.1602.3010.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphone/resources/appstorename} | "{B3B6048E-D34F-4153-80EC-2F760CFF793A}" = dir=in | name=@{microsoft.bingnews_4.8.268.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/applicationtitlewithbranding} | "{B710F843-31C2-4A03-951A-A9DF1CD33066}" = dir=in | name=@{windows.contactsupport_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://windows.contactsupport/resources/appdisplayname} | "{B763E4C7-5757-44EC-94FF-D1E5C278B4B5}" = dir=out | name=microsoft solitaire collection | "{B82BE70C-23C5-4EBF-AF4A-816C5CD64A63}" = dir=out | name=candy crush soda saga | "{BA200478-FBD9-47CA-9670-6D777E028528}" = dir=in | name=@{microsoft.windows.cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cortana/resources/displayname} | "{BD1F0C7E-F631-4AF4-84BD-1B8E38152445}" = dir=in | name=@{microsoft.bingfinance_4.8.268.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/applicationtitlewithbranding} | "{BF4C7354-46F6-493B-B939-4FE4E087780D}" = dir=out | name=@{microsoft.windowsstore_2016.29.13.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsstore/resources/storetitle} | "{C0D7D2EE-9659-41F6-B877-F3F7D96A5AE6}" = dir=in | app=c:\program files\newext\jsinjector.exe | "{C163618A-8BAA-4431-ABC2-DAE312103F2B}" = dir=in | app=c:\program files\newext\jsinjector.exe | "{C26E8BD2-F0FE-4B3E-BEED-B87E56E6263F}" = dir=in | app=c:\program files\newext\jsinjector.exe | "{C34E47A3-C2A2-4021-B1A4-E9A5A9B1F6C0}" = dir=out | name=@{windows.purchasedialog_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://windows.purchasedialog/resources/displayname} | "{C41BBBBD-1E92-4FED-9CF9-90B5B0DD0BBA}" = dir=out | name=@{microsoft.bingnews_4.8.268.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/applicationtitlewithbranding} | "{C4AD824F-51DE-48D9-81CD-B49014F16253}" = protocol=17 | dir=in | app=c:\program files\kmspico\service_kms.exe | "{CA47CEB5-6806-4973-B26D-202A311C36DB}" = dir=out | name=@{microsoft.microsoftedge_25.10586.0.0_neutral__8wekyb3d8bbwe?ms-resource://microsoft.microsoftedge/resources/appname} | "{CE8B1A55-48D2-4C29-9F87-115142D60F40}" = dir=out | name=@{microsoft.microsoftedge_25.10586.0.0_neutral__8wekyb3d8bbwe?ms-resource://microsoft.microsoftedge/resources/appname} | "{CEFD3459-649B-4E2F-8A53-4A9CB6E21206}" = dir=out | name=@{microsoft.messaging_2.13.20000.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.messaging/microsoft.apps.messaging.skype/skypemessaging.resources/skype_appstorename} | "{CF82DB8D-8A0F-4166-BE43-D3CC419849D7}" = dir=out | name=@{microsoft.windows.cloudexperiencehost_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cloudexperiencehost/resources/appdescription} | "{CFBBBBCA-D239-4152-8803-568E5E52F10D}" = dir=in | app=c:\program files\newext\jsinjector.exe | "{D07EA864-7594-43ED-9A1F-19C2E581AEA3}" = dir=in | app=c:\program files\newext\jsinjector.exe | "{D1E45A2B-E4E0-42A7-A8A8-4FF89BBAD231}" = dir=out | name=@{microsoft.lockapp_10.0.10586.0_neutral__cw5n1h2txyewy?ms-resource://microsoft.lockapp/resources/appdisplayname} | "{D42CC827-254F-49D4-B9AA-71DE69704639}" = dir=out | name=@{microsoft.windowscommunicationsapps_17.6769.40721.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/hxcommintl/appmanifest_outlookdesktop_displayname} | "{D5BDFF2D-BA2E-42BC-A662-B32DE03F150A}" = protocol=17 | dir=in | app=c:\program files\kmspico\autopico.exe | "{DBB5B7A0-90AE-4E28-AC70-B9B3FFBB3561}" = dir=in | app=c:\program files\newext\jsinjector.exe | "{DBE2D306-F88B-49C9-81B0-26BD94A878D4}" = dir=out | name=@{microsoft.windows.contentdeliverymanager_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.contentdeliverymanager/resources/appdisplayname} | "{DE375AC0-AB00-49B0-B9C7-5DA1419805E1}" = dir=in | app=c:\program files\newext\jsinjector.exe | "{DFCB67DB-8CE2-4479-A832-545E747C5A67}" = dir=out | name=@{microsoft.commsphone_2.15.25005.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.commsphone/resources/appstorename} | "{E0578A07-6D30-4904-BFD1-1447300D1E27}" = dir=in | name=microsoft solitaire collection | "{E1E562C2-EEB0-4E01-813D-DBD745A91F08}" = dir=in | name=@{microsoft.zunevideo_3.6.18671.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/ids_manifest_video_app_name} | "{E2AF0AFE-7944-4CB8-BF43-D914F43E0A4B}" = dir=out | name=sway | "{E3EC3610-A26D-41CB-9FF3-448CB61C2721}" = dir=in | name=@{windows.contactsupport_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://windows.contactsupport/resources/appdisplayname} | "{E52B2718-AF24-4982-B92B-991B2C82BF95}" = dir=out | name=xbox | "{E58D6031-D14B-486A-8E75-163123E29F6A}" = dir=in | app=c:\program files\newext\jsinjector.exe | "{E60D12CE-6EAE-4A72-81C0-248A872F2A8D}" = dir=out | name=@{microsoft.windows.contentdeliverymanager_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.contentdeliverymanager/resources/appdisplayname} | "{E64B5ECD-1733-4813-9713-8B2DC03709BB}" = dir=in | app=c:\program files\newext\jsinjector.exe | "{E6DCF91F-9D6C-4190-985D-02861539E79E}" = dir=out | name=@{microsoft.windowscommunicationsapps_17.6769.40721.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/hxcommintl/appmanifest_outlookdesktop_displayname} | "{E7D749CE-6814-4886-AF16-9A702D83E231}" = dir=out | name=@{microsoft.windowsmaps_4.1601.10150.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsmaps/resources/appstorename} | "{E95E998C-9D74-45EC-BB9B-C1C46ED0ED03}" = protocol=6 | dir=in | app=c:\users\rafael\appdata\roaming\utorrent\utorrent.exe | "{EB1DA0E1-7A30-4CAB-8CDC-DA424EFA5BC3}" = dir=out | name=@{microsoft.windows.parentalcontrols_1000.10586.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.parentalcontrols/resources/displayname} | "{EDE73E5B-4151-49AB-B411-952B8266B6BB}" = dir=out | name=@{windows.contactsupport_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://windows.contactsupport/resources/appdisplayname} | "{EE4390B2-A09E-498C-91FC-2CD8CA2839CE}" = dir=in | name=@{microsoft.windows.cloudexperiencehost_10.0.10586.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cloudexperiencehost/resources/appdescription} | "{EF8F829D-7645-4D8B-938F-2D023F92AB7C}" = dir=out | name=@{microsoft.zunevideo_3.6.18671.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/ids_manifest_video_app_name} | "{F3CA038C-DA83-42D7-8CE2-204517BE072F}" = protocol=17 | dir=in | app=c:\users\rafael\appdata\roaming\utorrent\utorrent.exe | "{F513F663-4D2C-413C-BD87-71A70184BB21}" = dir=in | name=@{microsoft.microsoftofficehub_17.6811.23771.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.microsoftofficehub/officehubintl/appmanifest_getoffice_displayname} | "{F51C6EC2-76CE-4A8E-B750-0AEB6C333497}" = dir=in | app=c:\program files\newext\jsinjector.exe | "{F55BC395-2BFF-4961-A5ED-957F9929706D}" = dir=in | name=@{microsoft.bingfinance_4.8.268.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/applicationtitlewithbranding} | "{F5F24A4B-1710-44E7-8BCE-C830E4EFA3A1}" = dir=in | name=@{microsoft.messaging_2.13.20000.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.messaging/microsoft.apps.messaging.skype/skypemessaging.resources/skype_appstorename} | "{F66AB886-A676-44E7-9551-7FA176342094}" = dir=in | app=c:\program files\newext\jsinjector.exe | "{FB126940-D793-4B57-B5D0-41EA1686BB49}" = dir=out | name=@{microsoft.bingnews_4.8.268.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/applicationtitlewithbranding} | "{FB56F307-5836-45A1-A62D-C646C9C26799}" = dir=in | app=c:\program files\newext\jsinjector.exe | "{FC47F27B-9B39-4846-A069-3BAAB6D06E9A}" = dir=in | name=@{microsoft.bingsports_4.8.268.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/applicationtitlewithbranding} | "{FD2A0530-5826-4B18-ADDC-E2CC003E082C}" = dir=out | name=@{microsoft.bingsports_4.8.268.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/applicationtitlewithbranding} | "{FD2A5D0D-CD5A-4011-9D3D-46EFF8FD8DC8}" = dir=in | name=@{microsoft.zunevideo_3.6.18671.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/ids_manifest_video_app_name} | "TCP Query User{CC6FB258-9831-4DD8-95F6-20C193DDFFF8}C:\users\rafael\appdata\roaming\spotify\spotify.exe" = protocol=6 | dir=in | app=c:\users\rafael\appdata\roaming\spotify\spotify.exe | "UDP Query User{99AFDC46-55E3-4FF1-B422-5555AC109AD5}C:\users\rafael\appdata\roaming\spotify\spotify.exe" = protocol=17 | dir=in | app=c:\users\rafael\appdata\roaming\spotify\spotify.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 "{26A24AE4-039D-4CA4-87B4-2F06417065FF}" = Java 7 Update 65 (64-bit) "{5CBE79CC-5F78-4AC2-AEB0-62F939D869CC}" = Windows Phone 8.1 SDK - x64 "{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}" = Microsoft Visual C++ 2005 Redistributable (x64) "{90150000-0011-0000-1000-0000000FF1CE}" = Microsoft Office Professional Plus 2013 "{90150000-0015-0416-1000-0000000FF1CE}" = Microsoft Access MUI (Portuguese (Brazil)) 2013 "{90150000-0016-0416-1000-0000000FF1CE}" = Microsoft Excel MUI (Portuguese (Brazil)) 2013 "{90150000-0018-0416-1000-0000000FF1CE}" = Microsoft PowerPoint MUI (Portuguese (Brazil)) 2013 "{90150000-0019-0416-1000-0000000FF1CE}" = Microsoft Publisher MUI (Portuguese (Brazil)) 2013 "{90150000-001A-0416-1000-0000000FF1CE}" = Microsoft Outlook MUI (Portuguese (Brazil)) 2013 "{90150000-001B-0416-1000-0000000FF1CE}" = Microsoft Word MUI (Portuguese (Brazil)) 2013 "{90150000-001F-0409-1000-0000000FF1CE}" = Microsoft Office Proofing Tools 2013 - English "{90150000-001F-0416-1000-0000000FF1CE}" = Revisores de Texto do Microsoft Office 2013 – Português do Brasil "{90150000-001F-0C0A-1000-0000000FF1CE}" = Microsoft Office Proofing Tools 2013 - Español "{90150000-002C-0416-1000-0000000FF1CE}" = Microsoft Office Proofing (Portuguese (Brazil)) 2013 "{90150000-0044-0416-1000-0000000FF1CE}" = Microsoft InfoPath MUI (Portuguese (Brazil)) 2013 "{90150000-006E-0416-1000-0000000FF1CE}" = Microsoft Office Shared MUI (Portuguese (Brazil)) 2013 "{90150000-0090-0416-1000-0000000FF1CE}" = Microsoft DCF MUI (Portuguese (Brazil)) 2013 "{90150000-00A1-0416-1000-0000000FF1CE}" = Microsoft OneNote MUI (Portuguese (Brazil)) 2013 "{90150000-00BA-0416-1000-0000000FF1CE}" = Microsoft Groove MUI (Portuguese (Brazil)) 2013 "{90150000-00C1-0000-1000-0000000FF1CE}" = Microsoft Office 32-bit Components 2013 "{90150000-00C1-0416-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (Portuguese (Brazil)) 2013 "{90150000-00E1-0416-1000-0000000FF1CE}" = Microsoft Office OSM MUI (Portuguese (Brazil)) 2013 "{90150000-00E2-0416-1000-0000000FF1CE}" = Microsoft Office OSM UX MUI (Portuguese (Brazil)) 2013 "{90150000-012B-0416-1000-0000000FF1CE}" = Microsoft Lync MUI (Portuguese (Brazil)) 2013 "CCleaner" = CCleaner "KMSpico_is1" = KMSpico v9.1.3 "Office15.PROPLUS" = Microsoft Office Professional Plus 2013 "TeamSpeak 3 Client" = TeamSpeak 3 Client [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{009476EE-71CA-4629-9823-FBB0616E4C9C}_is1" = Key Generate 2020 version 2016 "{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}" = Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 "{2B22F6A1-5E8E-49D6-B754-84FF69354314}" = Windows Phone 8.1 SDK - x86 "{2C828520-3C22-3BBE-B3F5-40A27C4C5D18}" = Windows Phone 8.0 仿真程序图像 - chs "{37464E70-B0B9-9DFF-649A-CBE169BAD657}" = Windows Software Development Kit for Windows Store Apps "{491D1B4D-F605-3C92-A313-5B9A05681E23}" = Windows Phone SDK 8.0 Assemblies "{495D0BE3-CA66-4768-9D3E-7CDCA0C2B9F7}" = TypeScript Power Tool "{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}" = Google Update Helper "{61C35890-79E1-4DC4-84CD-422649085B0F}" = Windows Phone 8.1 Tools for Visual Studio 2013 "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{7515082B-0B97-331C-9725-9D42EF0DE501}" = Windows Phone 8.0 Emulation Images "{AC76BA86-0804-1033-1959-001824166751}" = Adobe Refresh Manager "{AC76BA86-7AD7-1046-7B44-AC0F074E4100}" = Adobe Acrobat Reader DC - Português "{AC948AD4-DFDD-4ED8-AAFE-318C31EF1DD4}" = APKtoW10M "{BCCDE721-9F4D-4396-9592-92DD865D965E}" = League of Legends "{C3F383C1-D050-4A40-843F-8171A6A02C3A}" = Blade & Soul "{C7EE26EC-477D-37D0-87B4-ED146C5A9CD2}" = Windows Phone SDK 8.0 Assemblies "{D21B5F75-8042-3B39-80A1-F1D56D6DB4AB}" = Windows Phone 8.0 Managed SDK Profiler (X86) "{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}" = GTA San Andreas "{D5C2528F-DD1C-48F7-B283-AB1053F32CAE}" = Aplicativo Projetar minha tela "{D6DEA3AD-637E-368A-BD00-501D443F5E86}" = Windows Phone 8.0 Managed SDK Profiler (ARM) "{DB9620B6-CBBE-433C-A769-5617C40862A8}" = Windows Phone 8.1 SDK - ARM "{DE51DC25-FC28-4B33-BFD5-7D8D2F3F6A0E}" = SnapDo "{E10DB5DA-E576-40EA-A7FC-1CB2A7B283A6}" = NVIDIA PhysX "{E7C8E5D3-9EDC-4430-8AEF-FD590937F55F}" = Windows Phone IP Over USB "{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Processor Graphics "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F58FA66E-86F8-4BEA-9E6D-FAE8E0FB86BA}" = Windows Phone 8.1 SDK - Desktop "{f65db027-aff3-4070-886a-0d87064aabb1}" = Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 "{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}" = Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 "Anki" = Anki "Audacity®_is1" = Audacity 2.1.2 "Avira Antivirus" = Avira Antivirus "Google Chrome" = Google Chrome "InstallShield_{C3F383C1-D050-4A40-843F-8171A6A02C3A}" = Blade & Soul "League of Legends 3.0.1" = League of Legends "NCLauncher_NCWest" = NCSOFT Game Launcher "Popcorn Time_is1" = Popcorn Time "Rainmeter" = Rainmeter "VLC media player" = VLC media player "WinRAR archiver" = WinRAR 5.30 (32-bit) [color=#E56717]========== HKEY_CURRENT_USER Uninstall List ==========[/color] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "APKtoW10M 1.0.2" = APKtoW10M "Spotify" = Spotify "StartIsBack" = StartIsBack++ "uTorrent" = µTorrent [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 4/6/2016 3:39:54 PM | Computer Name = DESKTOP-S7NN2CN | Source = Application Error | ID = 1000 Description = Faulting application name: svchost.exe_DiagTrack, version: 10.0.10586.0, time stamp: 0x5632d7ba Faulting module name: SafeGuard64.dll_unloaded, version: 2.2.0.40, time stamp: 0x5683828f Exception code: 0xc0000005 Fault offset: 0x000000000005827b Faulting process id: 0x3e4 Faulting application start time: 0x01d1903bb9c68261 Faulting application path: C:\WINDOWS\System32\svchost.exe Faulting module path: SafeGuard64.dll Report Id: 39ec8b7a-ec74-4443-985a-775add7558c2 Faulting package full name: Faulting package-relative application ID: Error - 4/6/2016 3:40:43 PM | Computer Name = DESKTOP-S7NN2CN | Source = Software Protection Platform Service | ID = 8198 Description = License Activation (slui.exe) failed with the following error code: hr=0xC004F074 Command-line arguments: RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=NetworkAvailable Error - 4/6/2016 3:40:57 PM | Computer Name = DESKTOP-S7NN2CN | Source = Software Protection Platform Service | ID = 8198 Description = License Activation (slui.exe) failed with the following error code: hr=0xC004F074 Command-line arguments: RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=UserLogon;SessionId=1 Error - 4/6/2016 3:41:03 PM | Computer Name = DESKTOP-S7NN2CN | Source = Software Protection Platform Service | ID = 8198 Description = License Activation (slui.exe) failed with the following error code: hr=0xC004F074 Command-line arguments: RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=NetworkAvailable Error - 4/6/2016 3:41:51 PM | Computer Name = DESKTOP-S7NN2CN | Source = Application Error | ID = 1000 Description = Faulting application name: svchost.exe_DiagTrack, version: 10.0.10586.0, time stamp: 0x5632d7ba Faulting module name: SafeGuard64.dll_unloaded, version: 2.2.0.40, time stamp: 0x5683828f Exception code: 0xc0000005 Fault offset: 0x000000000005827b Faulting process id: 0x1b7c Faulting application start time: 0x01d1903c2a87c981 Faulting application path: C:\WINDOWS\System32\svchost.exe Faulting module path: SafeGuard64.dll Report Id: 432c7a7c-2608-42ae-aefe-5ffd5423170d Faulting package full name: Faulting package-relative application ID: Error - 4/6/2016 3:44:12 PM | Computer Name = DESKTOP-S7NN2CN | Source = Application Error | ID = 1000 Description = Faulting application name: svchost.exe_DiagTrack, version: 10.0.10586.0, time stamp: 0x5632d7ba Faulting module name: SafeGuard64.dll_unloaded, version: 2.2.0.40, time stamp: 0x5683828f Exception code: 0xc0000005 Fault offset: 0x000000000005827b Faulting process id: 0x22ac Faulting application start time: 0x01d1903c6f904a42 Faulting application path: C:\WINDOWS\System32\svchost.exe Faulting module path: SafeGuard64.dll Report Id: e3282423-86c3-443e-9b30-7af3810d3ed7 Faulting package full name: Faulting package-relative application ID: Error - 4/6/2016 3:45:39 PM | Computer Name = DESKTOP-S7NN2CN | Source = Application Error | ID = 1000 Description = Faulting application name: avscan.exe, version: 15.0.15.122, time stamp: 0x564b4fa3 Faulting module name: SafeGuard32.dll_unloaded, version: 2.2.0.40, time stamp: 0x568382a8 Exception code: 0xc00001a5 Fault offset: 0x001442c3 Faulting process id: 0x20c8 Faulting application start time: 0x01d1903ce21e270b Faulting application path: c:\program files (x86)\avira\antivirus\avscan.exe Faulting module path: SafeGuard32.dll Report Id: eebc4844-82ad-46b9-92ef-d0d6e23520c5 Faulting package full name: Faulting package-relative application ID: Error - 4/6/2016 3:46:29 PM | Computer Name = DESKTOP-S7NN2CN | Source = Application Error | ID = 1000 Description = Faulting application name: avscan.exe, version: 15.0.15.122, time stamp: 0x564b4fa3 Faulting module name: SafeGuard32.dll_unloaded, version: 2.2.0.40, time stamp: 0x568382a8 Exception code: 0xc00001a5 Fault offset: 0x001442c3 Faulting process id: 0x1980 Faulting application start time: 0x01d1903d0080406a Faulting application path: c:\program files (x86)\avira\antivirus\avscan.exe Faulting module path: SafeGuard32.dll Report Id: 714a4fbd-2f0e-4412-81eb-4c8c10682b6e Faulting package full name: Faulting package-relative application ID: Error - 4/6/2016 3:46:55 PM | Computer Name = DESKTOP-S7NN2CN | Source = Application Error | ID = 1000 Description = Faulting application name: avscan.exe, version: 15.0.15.122, time stamp: 0x564b4fa3 Faulting module name: SafeGuard32.dll_unloaded, version: 2.2.0.40, time stamp: 0x568382a8 Exception code: 0xc00001a5 Fault offset: 0x001442c3 Faulting process id: 0x1e94 Faulting application start time: 0x01d1903d0f583685 Faulting application path: c:\program files (x86)\avira\antivirus\avscan.exe Faulting module path: SafeGuard32.dll Report Id: c0f4c124-69ba-483f-b561-8f842e930e7b Faulting package full name: Faulting package-relative application ID: Error - 4/6/2016 4:00:13 PM | Computer Name = DESKTOP-S7NN2CN | Source = Application Error | ID = 1000 Description = Faulting application name: avscan.exe, version: 15.0.15.122, time stamp: 0x564b4fa3 Faulting module name: SafeGuard32.dll_unloaded, version: 2.2.0.40, time stamp: 0x568382a8 Exception code: 0xc00001a5 Fault offset: 0x001442c3 Faulting process id: 0x1d44 Faulting application start time: 0x01d1903eeb01d8a1 Faulting application path: c:\program files (x86)\avira\antivirus\avscan.exe Faulting module path: SafeGuard32.dll Report Id: 8616141b-4276-4c33-b0d5-33d20af903af Faulting package full name: Faulting package-relative application ID: [ System Events ] Error - 4/6/2016 12:46:23 PM | Computer Name = DESKTOP-S7NN2CN | Source = Service Control Manager | ID = 7009 Description = A timeout was reached (30000 milliseconds) while waiting for the gupdate service to connect. Error - 4/6/2016 12:46:23 PM | Computer Name = DESKTOP-S7NN2CN | Source = Service Control Manager | ID = 7000 Description = The Serviço do Google Update (gupdate) service failed to start due to the following error: %%1053 Error - 4/6/2016 12:46:48 PM | Computer Name = DESKTOP-S7NN2CN | Source = Service Control Manager | ID = 7032 Description = The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Network Store Interface Service service, but this action failed with the following error: %%1056 Error - 4/6/2016 12:48:20 PM | Computer Name = DESKTOP-S7NN2CN | Source = Service Control Manager | ID = 7031 Description = The Connected User Experiences and Telemetry service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service. Error - 4/6/2016 12:57:48 PM | Computer Name = DESKTOP-S7NN2CN | Source = Service Control Manager | ID = 7034 Description = The COM+ Live Service service terminated unexpectedly. It has done this 1 time(s). Error - 4/6/2016 1:45:30 PM | Computer Name = DESKTOP-S7NN2CN | Source = DCOM | ID = 10016 Description = Error - 4/6/2016 1:45:30 PM | Computer Name = DESKTOP-S7NN2CN | Source = Service Control Manager | ID = 7031 Description = The Sync Host_14db8b service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service. Error - 4/6/2016 1:45:30 PM | Computer Name = DESKTOP-S7NN2CN | Source = Service Control Manager | ID = 7031 Description = The Contact Data_14db8b service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service. Error - 4/6/2016 1:45:30 PM | Computer Name = DESKTOP-S7NN2CN | Source = Service Control Manager | ID = 7031 Description = The User Data Storage_14db8b service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service. Error - 4/6/2016 1:45:30 PM | Computer Name = DESKTOP-S7NN2CN | Source = Service Control Manager | ID = 7031 Description = The User Data Access_14db8b service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service. < End of report >