Additional scan result of Farbar Recovery Scan Tool (x64) Version:16-05-2016 Ran by mario (2016-05-18 09:10:07) Running from C:\Users\mario\Desktop Windows 7 Home Premium Service Pack 1 (X64) (2012-04-04 01:53:01) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-2158992580-1304642717-576862432-500 - Administrator - Disabled) Guest (S-1-5-21-2158992580-1304642717-576862432-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-2158992580-1304642717-576862432-1003 - Limited - Enabled) mario (S-1-5-21-2158992580-1304642717-576862432-1002 - Administrator - Enabled) => C:\Users\mario ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AV: AVG AntiVirus Free Edition 2015 (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413} AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: AVG AntiVirus Free Edition 2015 (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE} AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} FW: AVG Internet Security 2015 (Disabled) {757AB44A-78C2-7D1A-E37F-CA42A037B368} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Ad-Aware Web Companion (x32 Version: 2.0.1025.2130 - Lavasoft) Hidden Apple Application Support (HKLM-x32\...\{5D09C772-ECB3-442B-9CC6-B4341C78FDC2}) (Version: 2.3.4 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{2F72F540-1F60-4266-9506-952B21D6640D}) (Version: 6.1.0.13 - Apple Inc.) ATI Catalyst Install Manager (HKLM\...\{B3C4ADC9-637E-DDD9-A66C-782AE5E2E667}) (Version: 3.0.829.0 - ATI Technologies, Inc.) Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 10.3.2225 - AVAST Software) AVG 2015 (HKLM\...\AVG) (Version: 2015.0.6122 - AVG Technologies) AVG 2015 (Version: 15.0.4568 - AVG Technologies) Hidden AVG 2015 (Version: 15.0.6122 - AVG Technologies) Hidden Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Compaq Setup Manager (HKLM-x32\...\{AE856388-AFAD-4753-81DF-D96B19D0A17C}) (Version: 1.2.14901.3869 - Hewlett-Packard Company) CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.5.0.4606 - CyberLink Corp.) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden ESU for Microsoft Windows 7 SP1 (HKLM-x32\...\{E96CAA2A-0244-4A2A-8403-0C3C9534778B}) (Version: 2.1.1 - Hewlett-Packard) Facebook Video Calling 3.1.0.521 (HKLM-x32\...\{2091F234-EB58-4B80-8C96-8EB78C808CF7}) (Version: 3.1.521 - Skype Limited) Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.7619.1252 - Google Inc.) Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.30.3 - Google Inc.) Hidden Hewlett-Packard ACLM.NET v1.1.2.0 (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden HP Application Assistant (HKLM\...\{6032497A-4479-462B-ADB8-A0A372BB9A23}) (Version: 1.0.409.3882 - Hewlett-Packard) HP Documentation (HKLM-x32\...\{39FCC6B7-FFF5-4075-A5E8-B5CEBD54C331}) (Version: 1.1.0.0 - Hewlett-Packard) HP MovieStore (HKLM-x32\...\{9008D736-35CA-40DB-A2BE-5F32D954E5AA}) (Version: 2.1.21091.0 - Hewlett-Packard Company) iTunes (HKLM\...\{7FCDABCC-1A1E-4D61-909D-BA9495172774}) (Version: 11.0.3.42 - Apple Inc.) Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden LavasoftTcpService (x32 Version: 2.3.4.7 - Lavasoft) Hidden Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation) Microsoft Office 2007 Primary Interop Assemblies (HKLM-x32\...\{50120000-1105-0000-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Click-to-Run 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office Starter 2010 - English (HKLM-x32\...\{90140011-0066-0409-0000-0000000FF1CE}) (Version: 14.0.5139.5005 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.20513.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual Studio 2005 Tools for Office Runtime (HKLM-x32\...\Microsoft Visual Studio 2005 Tools for Office Runtime) (Version: - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.40303 - Microsoft Corporation) Mozilla Firefox 40.0.2 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 40.0.2 (x86 en-US)) (Version: 40.0.2 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 40.0.2 - Mozilla) MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MSXML 4.0 SP2 Parser and SDK (HKLM-x32\...\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation) opensource (x32 Version: 1.0.14960.3876 - Your Company Name) Hidden Opera Stable 36.0.2130.65 (HKLM-x32\...\Opera 36.0.2130.65) (Version: 36.0.2130.65 - Opera Software) Opera Stable 37.0.2178.43 (HKLM-x32\...\Opera 37.0.2178.43) (Version: 37.0.2178.43 - Opera Software) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6461 - Realtek Semiconductor Corp.) SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.24.0 - SAMSUNG Electronics Co., Ltd.) Skype Web Plugin (HKLM-x32\...\{75BBD24C-C19A-4885-B8FD-EB15009277D3}) (Version: 7.5.0.123 - Skype Technologies S.A.) swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) USB INTERNET (HKLM-x32\...\USB INTERNET) (Version: USB INTERNET - ) VirtualDJ Home FREE (HKLM-x32\...\{5E1375CB-6792-4464-8715-CC3EC83D48FA}) (Version: 7.0.5 - Atomix Productions) Visual Studio 2008 x64 Redistributables (HKLM-x32\...\{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}) (Version: 10.0.0.2 - AVG Technologies) Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies) Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.) VLC media player 0.9.9 (HKLM-x32\...\VLC media player) (Version: 0.9.9 - VideoLAN Team) Web Companion (HKLM-x32\...\{88B10E3E-8911-4FAC-8663-CCF6E33C58B3}_WebCompanion) (Version: 2.0.1025.2130 - Lavasoft) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-2158992580-1304642717-576862432-1002_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\mario\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-2158992580-1304642717-576862432-1002_Classes\CLSID\{59CA9673-A08B-489C-8932-1C3E0CF244D8}\localserver32 -> C:\Users\mario\AppData\Local\SkypePlugin\7.5.0.123\GatewayVersion-x64.exe (Skype Technologies S.A.) CustomCLSID: HKU\S-1-5-21-2158992580-1304642717-576862432-1002_Classes\CLSID\{B982932A-124D-489C-A7B3-8BCD1FDB8DD3}\InprocServer32 -> C:\Users\mario\AppData\Local\SkypePlugin\7.5.0.123\GatewayActiveX-x64.dll (Skype Technologies S.A.) CustomCLSID: HKU\S-1-5-21-2158992580-1304642717-576862432-1002_Classes\CLSID\{CBF9CD8C-2714-4F36-B76A-43E6C7547BC2}\localserver32 -> C:\Users\mario\AppData\Local\SkypePlugin\7.5.0.123\EdgeCalling.exe (Skype Technologies S.A.) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {1444774B-0A50-45C8-A30A-4FA6EF1894BD} - System32\Tasks\Hewlett-Packard\HP Support Assistant\NetworkCheck => c:\program files (x86)\hewlett-packard\hp health check\activecheck\product_line\Detection_NetworkCheck.exe [2012-05-23] (Hewlett-Packard) Task: {14EF0EC4-77D1-4492-8B56-3F1BB51458AD} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-05-26] (Google Inc.) Task: {1BE972CB-BCC9-4C63-89F2-BDBC0118034A} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2158992580-1304642717-576862432-1002Core => C:\Users\mario\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-02-16] (Facebook Inc.) Task: {2403D813-45D4-4C81-AF97-D4A7BB315C5C} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-08-25] (AVAST Software) Task: {273DEADB-B800-45B3-BC78-EA8159B8AD2A} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Total Care Tune-Up => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPTuneUp.exe Task: {38C1A596-36FD-445A-B3B6-C1918BF4A43E} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Tuneup => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe Task: {3F53404A-22F1-4073-95F4-E23D5C2C0B5A} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2158992580-1304642717-576862432-1002 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe Task: {408BC5F3-0970-4704-B741-9E5610FBB453} - System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-2158992580-1304642717-576862432-1002 => C:\Program Files (x86)\RealNetworks\RealDownloader\recordingmanager.exe Task: {4825BF73-910A-43A2-9043-D2300FCA1715} - System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-2158992580-1304642717-576862432-1002 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe Task: {601E0E43-0603-4D73-ADA1-42BD3B36E6AC} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2158992580-1304642717-576862432-1002UA => C:\Users\mario\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-02-16] (Facebook Inc.) Task: {63F9D7E4-3A6F-4A45-9987-04604594DC78} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater\HPSFUpdater.exe [2011-12-15] (Hewlett-Packard) Task: {7C490BF6-9D7C-4F52-ACCE-42E40BBA6096} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Opt-in For HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF_Utils.exe Task: {91E534F1-88E1-438C-98B5-6D55C34D9F34} - System32\Tasks\Opera scheduled Autoupdate 1463007634 => C:\Program Files (x86)\Opera\launcher.exe [2016-05-09] (Opera Software) Task: {93F170BF-DC32-4BBE-8421-570B83EEFEFD} - System32\Tasks\Opera scheduled Autoupdate 1463014205 => C:\Program Files (x86)\Opera\launcher.exe [2016-05-09] (Opera Software) Task: {9448B303-4877-4DEE-9CE9-BD52EB12538E} - System32\Tasks\{C747A9AB-B9CA-4AF7-9987-13472E64406A} => pcalua.exe -a C:\Users\mario\Desktop\tremulous-1.1.0-installer.exe -d C:\Users\mario\Desktop Task: {998DDE04-A891-4E0E-9672-2FDDDC7E6B0E} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2016-05-11] (AVAST Software) Task: {A1D36339-A3D7-427E-AEB0-14FBB20B817D} - System32\Tasks\{6F0BF4F3-FA19-44DE-86D2-4DACB875220D} => pcalua.exe -a "C:\Users\mario\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EVMLH4VK\Ski_Challenge_06.exe" -d C:\Users\mario\Desktop Task: {B7CFF1B7-975D-4F21-9B75-A763E2B16AC6} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe Task: {B9B9F02B-BE4D-4E2B-9D7C-8B76FE4409B6} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-2158992580-1304642717-576862432-1002 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe Task: {C2CDB71D-1B26-41E5-BCF2-97FFF23B6662} - System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-2158992580-1304642717-576862432-1002 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe Task: {CBA5E7A9-25B7-41D6-9151-647584D37B3F} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-2158992580-1304642717-576862432-1002 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe Task: {D2754072-9FDD-4676-A55D-CD74CC904E55} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPSFMessenger\HPSFMsgr.exe Task: {EA6CBC35-F54D-4A9F-B4C4-0350446DBB12} - System32\Tasks\{18B7615F-DC82-41E3-BD9E-6DE35FC626D1} => pcalua.exe -a C:\KuaiwanGames\Games\1787\VC2010x86.exe -d C:\KuaiwanGames\Games\1787 Task: {F3816CF1-1D90-49FB-9E4E-16E9F159B1DB} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2158992580-1304642717-576862432-1002 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe Task: {F3EB7473-B674-4CCC-A3EB-D591BA572D29} - System32\Tasks\{C89D7978-EC39-4822-8376-C899F17D1053} => Iexplore.exe hxxp://www.skype.com/go/downloading?source=lightinstaller&ver=6.5.0.158&LastError=12002 Task: {FA480C65-E0D5-45D6-BA83-930D61D56CB7} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-05-26] (Google Inc.) Task: {FD97AD78-936F-4B99-B628-1126B20E786D} - System32\Tasks\MirageAgent => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [2011-10-06] (CyberLink) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2158992580-1304642717-576862432-1002Core.job => C:\Users\mario\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2158992580-1304642717-576862432-1002UA.job => C:\Users\mario\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== 2012-04-02 11:46 - 2012-04-02 11:46 - 00329544 _____ () C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe 2010-11-16 06:38 - 2010-11-16 06:38 - 00339456 _____ () C:\ProgramData\DatacardService\HWDeviceService64.exe 2013-08-16 20:21 - 2012-05-11 02:52 - 00059904 ____R () C:\Program Files (x86)\Ubee\UbeeStick\UbeeStick64.exe 2012-05-11 02:52 - 2012-05-11 02:52 - 00066560 ____R () C:\Program Files (x86)\Ubee\UbeeStick\UbeeStickHandler64.dll 2015-08-25 08:44 - 2015-08-25 08:44 - 00102864 _____ () C:\Program Files\AVAST Software\Avast\log.dll 2015-08-25 08:44 - 2015-08-25 08:44 - 00123976 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll 2016-05-18 07:12 - 2016-05-18 07:12 - 02909696 _____ () C:\Program Files\AVAST Software\Avast\defs\16051800\algo.dll 2013-01-28 13:08 - 2013-01-28 13:08 - 00087952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2013-01-28 13:08 - 2013-01-28 13:08 - 01242512 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2015-08-25 08:44 - 2015-08-25 08:44 - 40540672 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\ProgramData\Temp:0B4227B4 [127] ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) IE trusted site: HKU\S-1-5-21-2158992580-1304642717-576862432-1002\...\localhost -> localhost IE trusted site: HKU\S-1-5-21-2158992580-1304642717-576862432-1002\...\webcompanion.com -> hxxp://webcompanion.com ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-13 19:34 - 2009-06-10 14:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-2158992580-1304642717-576862432-1002\Control Panel\Desktop\\Wallpaper -> C:\Users\mario\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.15.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{DC3047AD-4FA9-4816-B7E8-507428985733}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\MediaSmart\RoxioNow\RNow.exe FirewallRules: [{48E34E3F-A1CB-4688-9A5D-7C4F23372ADA}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\MediaSmart\RoxioNow\RNow.exe FirewallRules: [{52E41CA0-41DE-41DA-9741-7EE294092218}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\MediaSmart\RoxioNow\IndivDRM.exe FirewallRules: [{E7A3AAA3-EE63-48BA-BF19-5A054E1458DF}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\MediaSmart\RoxioNow\IndivDRM.exe FirewallRules: [{27E2AD31-D824-4E29-B7BE-68DF7061803B}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe FirewallRules: [{D3875090-2DAA-4664-8BEB-190AA8CDCBDE}] => (Allow) LPort=2869 FirewallRules: [{12485372-E6AD-4BE5-8C0C-4155A1E56ABA}] => (Allow) LPort=1900 FirewallRules: [{4771D0A0-D5B7-467F-9E06-AA22CAACDD67}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe FirewallRules: [{6462E1DF-58F6-4B3B-8B95-C8B4B10EA285}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe FirewallRules: [{601E7696-2CDC-4EFF-BCC2-96D842878A57}] => (Allow) C:\Program Files (x86)\AVG\AVG2012\avgmfapx.exe FirewallRules: [{33E1EFEE-3A3D-4C4D-BFEA-AB7A0AA6741C}] => (Allow) C:\Program Files (x86)\AVG\AVG2012\avgmfapx.exe FirewallRules: [{50396280-B290-4E1C-90C1-D23563313594}] => (Allow) C:\Windows\SysWOW64\msiexec.exe FirewallRules: [{736D46CD-58D7-43F7-84FB-24AF87C22C27}] => (Allow) C:\Windows\SysWOW64\msiexec.exe FirewallRules: [{22C9336B-88FE-457C-8EC1-477785C0F4D2}] => (Allow) C:\ProgramData\NexonEU\NGM\NGM.exe FirewallRules: [{9F2C493D-F2B8-4DFB-936A-7B473F7AA677}] => (Allow) C:\ProgramData\NexonEU\NGM\NGM.exe FirewallRules: [{33096A06-E2A1-4329-B4DF-A0245E2177AD}] => (Allow) C:\ProgramData\NexonUS\NGM\NGM.exe FirewallRules: [{6DCEFEA4-A9CA-4763-96F7-ACDE79EF949B}] => (Allow) C:\ProgramData\NexonUS\NGM\NGM.exe FirewallRules: [{BE7D18BF-954B-4CC7-8A22-95B274F7B109}] => (Allow) C:\Program Files (x86)\GoforFiles\goforfilesdl.exe FirewallRules: [{D456ACAC-1A4D-44E1-B588-8F7E014A7F7E}] => (Allow) C:\Program Files (x86)\GoforFiles\goforfilesdl.exe FirewallRules: [{8F635A73-52F2-4818-874F-E78E04D0C4A3}] => (Allow) C:\Program Files (x86)\GoforFiles\GoforFiles.exe FirewallRules: [{7A6D3444-B31F-48B6-A926-49E5577514BE}] => (Allow) C:\Program Files (x86)\GoforFiles\GoforFiles.exe FirewallRules: [{03DC2763-EB69-4FC1-9CAC-8C14C3EC07FF}] => (Allow) C:\Users\mario\AppData\Local\Facebook\Video\Skype\FacebookVideoCalling.exe FirewallRules: [{90612E45-9E88-4EC7-A8D4-1EBF66DCB3FC}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe FirewallRules: [{56FB259F-F1F8-4CD8-9CD2-4A3746447A74}] => (Allow) C:\Program Files (x86)\MaxTV\MaxTV4\maxtv.exe FirewallRules: [{C0FB6897-9EAF-479B-B5E5-760B8A2041F2}] => (Allow) C:\Program Files (x86)\MaxTV\MaxTV4\maxtv.exe FirewallRules: [{C8D8CC41-0AB3-4A90-8F9A-3ADBE9BFC9B5}] => (Allow) C:\Program Files (x86)\MaxTV\MaxTV4\core\maxtv_xul.exe FirewallRules: [{C9EEA969-C62A-4752-B60B-92746456B9C2}] => (Allow) C:\Program Files (x86)\MaxTV\MaxTV4\core\maxtv_xul.exe FirewallRules: [{232FA98A-5273-4687-885C-857E73CE9F58}] => (Allow) C:\Program Files (x86)\MaxTV\MaxTV4\recorder.exe FirewallRules: [{48A683B4-BDE8-43FA-BF67-EAE8014F9F8D}] => (Allow) C:\Program Files (x86)\MaxTV\MaxTV4\recorder.exe FirewallRules: [{6BA33255-BE53-42C5-998D-F2613803C098}] => (Allow) C:\Program Files (x86)\MaxTV\MaxTV4\task_scheduler.exe FirewallRules: [{0F64F78E-7F80-40FD-AD1F-376201645F13}] => (Allow) C:\Program Files (x86)\MaxTV\MaxTV4\task_scheduler.exe FirewallRules: [{A7F9E51D-4709-4638-8756-332D413629AA}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{3EF7C956-16FE-4A7A-AC1E-9EB90D6C6725}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{F9638825-0E93-42F8-872D-8F4B733ABC5E}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{B1BD77EF-0563-4670-9E32-6F4CF696AF00}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{FA6CB8C4-59A1-4EB1-9E8A-6971B5C81747}] => (Allow) C:\Program Files (x86)\iTunes\iTunes.exe FirewallRules: [{0B0A366B-8274-4C72-8544-B2DD7031EF74}] => (Allow) C:\Program Files (x86)\FreeCall.com\FreeCall\FreeCall.exe FirewallRules: [{13EEAE27-0D75-476B-81F3-000096798BE9}] => (Allow) C:\Program Files (x86)\FreeCall.com\FreeCall\FreeCall.exe FirewallRules: [{24BA080D-1A6C-46D1-A562-397D9BEC2451}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe FirewallRules: [{C5420FDC-9ED4-4D43-901D-9978E4709395}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe FirewallRules: [TCP Query User{F3C2A580-A436-42DC-8829-07A483296920}C:\users\mario\appdata\local\google\chrome\application\chrome.exe] => (Allow) C:\users\mario\appdata\local\google\chrome\application\chrome.exe FirewallRules: [UDP Query User{23114BF0-24FF-441E-BCCA-4A5B691E2CFB}C:\users\mario\appdata\local\google\chrome\application\chrome.exe] => (Allow) C:\users\mario\appdata\local\google\chrome\application\chrome.exe FirewallRules: [{C0A207FA-974F-441E-9A48-5C3618C85CAF}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe FirewallRules: [{13941B16-0235-4EDC-9BB5-79FE7A229F0F}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe FirewallRules: [{5B6684F1-D73C-4FEA-9E3B-9D0B2483015E}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe FirewallRules: [{2A04D8FE-C95D-49CA-94B3-174BB5B419CC}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe FirewallRules: [{CBAD67B9-0329-4B73-BCC4-017459585A42}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe FirewallRules: [{F1FE0AFD-C425-4B92-883F-4BCA01CE6BBD}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe FirewallRules: [{8EEBB6B1-9764-4972-A309-CEB0E5873C5D}] => (Allow) C:\Program Files (x86)\Apowersoft\Video Download Capture\Video Download Capture.exe FirewallRules: [{F90AB3C1-F436-4FFD-A169-69587BD6956F}] => (Allow) C:\Program Files (x86)\Apowersoft\Video Download Capture\Video Download Capture.exe FirewallRules: [{8120EA44-810D-4BC0-A9A5-FCA074F9DE02}] => (Allow) C:\Program Files (x86)\Apowersoft\Video Download Capture\ApowersoftSrv.dll FirewallRules: [{2CB184E4-0741-4345-8731-6229DF13195C}] => (Allow) C:\Program Files (x86)\Apowersoft\Video Download Capture\ApowersoftSrv.dll FirewallRules: [{1EF32EA1-A591-4D57-B6F3-CE02626136B6}] => (Allow) C:\Program Files (x86)\Apowersoft\Video Download Capture\ApowersoftDump.dll FirewallRules: [{B18EB22C-EC93-43AF-879B-BB8154C932A1}] => (Allow) C:\Program Files (x86)\Apowersoft\Video Download Capture\ApowersoftDump.dll FirewallRules: [{BEADBB89-01D2-44C8-AC19-6F5C85B51040}] => (Allow) C:\Program Files (x86)\Apowersoft\Video Download Capture\ApowersoftAC.dll FirewallRules: [{EF343B48-FEE0-41EC-ABA6-9EF17E3F8509}] => (Allow) C:\Program Files (x86)\Apowersoft\Video Download Capture\ApowersoftAC.dll FirewallRules: [{79A7554B-77E3-4FBA-86C6-B02E72DA7EC2}] => (Allow) C:\Program Files (x86)\Apowersoft\Video Download Capture\ApowersoftPlayer.dll FirewallRules: [{3663893B-E343-43ED-B745-B30CBB7E02E4}] => (Allow) C:\Program Files (x86)\Apowersoft\Video Download Capture\ApowersoftPlayer.dll FirewallRules: [{5037D750-3A99-4D75-AD29-ACA27C3E0B86}] => (Allow) C:\Program Files (x86)\Apowersoft\Video Download Capture\ApowersoftDownloaderHelp.dll FirewallRules: [{41A990AF-EF17-4F9B-829F-8D388A03F74D}] => (Allow) C:\Program Files (x86)\Apowersoft\Video Download Capture\ApowersoftDownloaderHelp.dll FirewallRules: [{50588D65-0780-4135-A60B-E5FFE7F14B21}] => (Allow) C:\Program Files (x86)\Apowersoft\Video Download Capture\ApowersoftHDSDump.dll FirewallRules: [{10589DB3-06D3-4452-BFA4-1BFCE3A4ACD4}] => (Allow) C:\Program Files (x86)\Apowersoft\Video Download Capture\ApowersoftHDSDump.dll FirewallRules: [{B01B9403-DB8F-4666-8067-597ED34B37A7}] => (Allow) C:\Program Files (x86)\Apowersoft\Apowersoft Screen Capture Pro\Apowersoft Screen Capture Pro.exe FirewallRules: [{4587E0D3-41A2-48E0-8C4F-32326D2B8930}] => (Allow) C:\Program Files (x86)\Apowersoft\Apowersoft Screen Capture Pro\Apowersoft Screen Capture Pro.exe FirewallRules: [{C4B5A738-51EC-4FE3-B6C8-FAD491DCBA71}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{5690D58B-5DC2-4CD4-81F7-CFC7A710B88A}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [TCP Query User{615CF0F3-BF20-46DD-B39B-4AC3E2D418B8}G:\kuaiwan\kuaiwansvc.exe] => (Allow) G:\kuaiwan\kuaiwansvc.exe FirewallRules: [UDP Query User{E8FFAE81-2985-49D4-A685-4779690E3063}G:\kuaiwan\kuaiwansvc.exe] => (Allow) G:\kuaiwan\kuaiwansvc.exe FirewallRules: [TCP Query User{1BD278F6-8F5B-4FF0-AF29-A33380F49474}C:\users\mario\desktop\kuaiwan\kuaiwansvc.exe] => (Allow) C:\users\mario\desktop\kuaiwan\kuaiwansvc.exe FirewallRules: [UDP Query User{EE5FB42C-6950-43F2-A1F4-9FA3777A0E64}C:\users\mario\desktop\kuaiwan\kuaiwansvc.exe] => (Allow) C:\users\mario\desktop\kuaiwan\kuaiwansvc.exe FirewallRules: [TCP Query User{CC174804-5A45-4FA7-9F6C-2CF577E7F0EB}C:\kuaiwangames\games\1787\对战平台.exe] => (Allow) C:\kuaiwangames\games\1787\对战平台.exe FirewallRules: [UDP Query User{346CE877-24E7-40F7-8CF6-DDC32377CD39}C:\kuaiwangames\games\1787\对战平台.exe] => (Allow) C:\kuaiwangames\games\1787\对战平台.exe FirewallRules: [TCP Query User{862AD205-934D-45B1-A8B8-506CBCCF1893}C:\kuaiwangames\games\1787\hurtworldv.0.3.1.8\hurtworld.exe] => (Allow) C:\kuaiwangames\games\1787\hurtworldv.0.3.1.8\hurtworld.exe FirewallRules: [UDP Query User{F38250F6-36F6-4F7E-8DC9-F987F10D9E50}C:\kuaiwangames\games\1787\hurtworldv.0.3.1.8\hurtworld.exe] => (Allow) C:\kuaiwangames\games\1787\hurtworldv.0.3.1.8\hurtworld.exe ==================== Restore Points ========================= 12-05-2016 04:57:06 Scheduled Checkpoint 14-05-2016 03:47:15 Device Driver Package Install: libusbx.org 15-05-2016 17:07:31 Removed Hi-Rez Studios Games 18-05-2016 08:32:52 Windows Update ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (05/18/2016 09:02:03 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/18/2016 08:47:23 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/18/2016 08:35:08 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: firefox.exe, version: 40.0.2.5702, time stamp: 0x55cbf192 Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000 Exception code: 0xc000041d Fault offset: 0x77be11f1 Faulting process id: 0xc48 Faulting application start time: 0xfirefox.exe0 Faulting application path: firefox.exe1 Faulting module path: firefox.exe2 Report Id: firefox.exe3 Error: (05/18/2016 08:34:02 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: opera.exe, version: 37.0.2178.43, time stamp: 0x572d58fc Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000 Exception code: 0xc000041d Fault offset: 0x77be11f1 Faulting process id: 0x1674 Faulting application start time: 0xopera.exe0 Faulting application path: opera.exe1 Faulting module path: opera.exe2 Report Id: opera.exe3 Error: (05/18/2016 08:34:02 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: opera.exe, version: 37.0.2178.43, time stamp: 0x572d58fc Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000 Exception code: 0xc000041d Fault offset: 0x77be11f1 Faulting process id: 0x8d4 Faulting application start time: 0xopera.exe0 Faulting application path: opera.exe1 Faulting module path: opera.exe2 Report Id: opera.exe3 Error: (05/18/2016 08:29:07 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/18/2016 08:23:43 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: opera.exe, version: 37.0.2178.43, time stamp: 0x572d58fc Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000 Exception code: 0xc000041d Fault offset: 0x77b311f1 Faulting process id: 0x16c0 Faulting application start time: 0xopera.exe0 Faulting application path: opera.exe1 Faulting module path: opera.exe2 Report Id: opera.exe3 Error: (05/18/2016 08:21:42 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/18/2016 08:06:56 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/18/2016 08:01:33 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: opera.exe, version: 37.0.2178.43, time stamp: 0x572d58fc Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000 Exception code: 0xc000041d Fault offset: 0x772b11f1 Faulting process id: 0x160c Faulting application start time: 0xopera.exe0 Faulting application path: opera.exe1 Faulting module path: opera.exe2 Report Id: opera.exe3 System errors: ============= Error: (05/18/2016 09:04:18 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The HP Support Assistant Service service failed to start due to the following error: %%2 Error: (05/18/2016 08:59:44 AM) (Source: DCOM) (EventID: 10010) (User: ) Description: {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} Error: (05/18/2016 08:59:32 AM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The Computer Browser service depends on the Server service which failed to start because of the following error: %%1068 Error: (05/18/2016 08:59:32 AM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The Computer Browser service depends on the Server service which failed to start because of the following error: %%1068 Error: (05/18/2016 08:59:32 AM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The Computer Browser service depends on the Server service which failed to start because of the following error: %%1068 Error: (05/18/2016 08:57:46 AM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The Computer Browser service depends on the Server service which failed to start because of the following error: %%1068 Error: (05/18/2016 08:57:46 AM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The Computer Browser service depends on the Server service which failed to start because of the following error: %%1068 Error: (05/18/2016 08:57:46 AM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The Computer Browser service depends on the Server service which failed to start because of the following error: %%1068 Error: (05/18/2016 08:57:45 AM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The HomeGroup Provider service depends on the Function Discovery Provider Host service which failed to start because of the following error: %%1068 Error: (05/18/2016 08:56:16 AM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The Computer Browser service depends on the Server service which failed to start because of the following error: %%1068 ==================== Memory info =========================== Processor: AMD E-300 APU with Radeon(tm) HD Graphics Percentage of memory in use: 74% Total physical RAM: 1642.91 MB Available physical RAM: 413.04 MB Total Virtual: 3285.81 MB Available Virtual: 1864.3 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:209.33 GB) (Free:123.38 GB) NTFS ==>[system with boot components (obtained from drive)] Drive d: (Recovery) (Fixed) (Total:19.39 GB) (Free:2.1 GB) NTFS ==>[system with boot components (obtained from drive)] Drive e: (HP_TOOLS) (Fixed) (Total:3.96 GB) (Free:3.95 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 232.9 GB) (Disk ID: 27F7617E) Partition 1: (Active) - (Size=199 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=209.3 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=19.4 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=4 GB) - (Type=0C) ==================== End of Addition.txt ============================