Additional scan result of Farbar Recovery Scan Tool (x64) Version:06-05-2016 01 Ran by SUN (2016-06-14 01:48:26) Running from G:\After Hacked\ãÄÞÊ\Downloads Windows 7 Home Basic Service Pack 1 (X64) (2016-05-24 01:20:05) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-2088086660-1261043681-1886644693-500 - Administrator - Disabled) Guest (S-1-5-21-2088086660-1261043681-1886644693-501 - Limited - Disabled) SUN (S-1-5-21-2088086660-1261043681-1886644693-1000 - Administrator - Enabled) => C:\Users\SUN ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Bitdefender Antivirus (Enabled - Up to date) {9A0813D8-CED6-F86B-072E-28D2AF25A83D} AS: Bitdefender Antispyware (Enabled - Up to date) {2169F23C-E8EC-F7E5-3D9E-13A0D4A2E280} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: Bitdefender Firewall (Enabled) {A23392FD-84B9-F933-2C71-81E751F6EF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Flash Player 10 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 10.3.183.10 - Adobe Systems Incorporated) Adobe Reader X (10.1.0) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AA1000000001}) (Version: 10.1.0 - Adobe Systems Incorporated) AMD Catalyst Install Manager (HKLM\...\{70F55D70-7E5F-6291-4924-2F7640F19BFE}) (Version: 3.0.838.0 - Advanced Micro Devices, Inc.) AuthenTec TrueAPI (Version: 1.3.0.139 - AuthenTec, Inc.) Hidden Bejeweled 3 (x32 Version: 2.2.0.97 - WildTangent) Hidden Bing Bar (HKLM-x32\...\{9FA13759-5C2B-4177-9DDC-0038F8B5BEFD}) (Version: 7.0.826.0 - Microsoft Corporation) Bitdefender Total Security (HKLM\...\Bitdefender) (Version: 17.26.0.1106 - Bitdefender) Blackhawk Striker 2 (x32 Version: 2.2.0.95 - WildTangent) Hidden Broadcom 802.11 Wireless LAN Adapter (HKLM\...\Broadcom 802.11 Wireless LAN Adapter) (Version: 5.100.82.86 - Broadcom Corporation) Broadcom Bluetooth Software (HKLM\...\{6E7F4CA3-B2DE-413C-A7A1-43AA5BE19EA1}) (Version: 6.5.0.2300 - Broadcom Corporation) Broadcom InConcert Maestro (HKLM\...\{57DD35E9-D9BB-4089-BB05-EF933C586CB3}) (Version: 1.0.5.2300 - Broadcom Corporation) Chuzzle Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden Cradle of Rome 2 (x32 Version: 2.2.0.98 - WildTangent) Hidden CyberLink PowerDVD (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.3.3222 - CyberLink Corp.) CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.5.0.4528 - CyberLink Corp.) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Dora's World Adventure (x32 Version: 2.2.0.95 - WildTangent) Hidden ESU for Microsoft Windows 7 SP1 (HKLM-x32\...\{E96CAA2A-0244-4A2A-8403-0C3C9534778B}) (Version: 2.1.1 - Hewlett-Packard) Evernote v. 4.2.3 (HKLM-x32\...\{F761359C-9CED-45AE-9A51-9D6605CD55C4}) (Version: 4.2.3.22 - Evernote Corp.) Farm Frenzy (x32 Version: 2.2.0.98 - WildTangent) Hidden Farmscapes (x32 Version: 2.2.0.98 - WildTangent) Hidden FATE (x32 Version: 2.2.0.97 - WildTangent) Hidden Final Drive Fury (x32 Version: 2.2.0.95 - WildTangent) Hidden Hewlett-Packard ACLM.NET v1.1.2.0 (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden Hoyle Card Games (x32 Version: 2.2.0.95 - WildTangent) Hidden HP Documentation (HKLM-x32\...\{3D5C7E0E-AEC0-40EB-99D3-C40469738040}) (Version: 1.1.0.0 - Hewlett-Packard) HP Games (HKLM-x32\...\WildTangent hp Master Uninstall) (Version: 1.0.2.5 - WildTangent) HP Launch Box (HKLM\...\{BF1E75D0-E7AF-4BEA-9FBC-567F0C54BDF9}) (Version: 1.0.12 - Hewlett-Packard Company) HP On Screen Display (HKLM-x32\...\{ED1BD69A-07E3-418C-91F1-D856582581BF}) (Version: 1.3.5 - Hewlett-Packard Company) HP Power Manager (HKLM-x32\...\{E44578C7-4667-4124-8BC2-1161BCA54978}) (Version: 1.4.4 - Hewlett-Packard Company) HP Quick Launch (HKLM-x32\...\{285F722C-0E45-47DE-B38E-5B3B10FA4A7C}) (Version: 2.5.2 - Hewlett-Packard Company) HP QuickWeb (HKLM-x32\...\{BB4FC2AD-DF12-4EE1-8AA7-2C0A26B5E2FB}) (Version: 3.1.1.10197 - Hewlett-Packard Company) HP Security Assistant (HKLM\...\{562608FE-2051-4488-BF22-8CE4C03046AC}) (Version: 1.0.12 - Hewlett-Packard) HP Setup (HKLM-x32\...\{F5E7D9AF-60F6-4A30-87E3-4EA94D322CE1}) (Version: 9.0.15076.3891 - Hewlett-Packard Company) HP SimplePass PE 2011 (HKLM-x32\...\{4741965C-AFD0-4D00-81D1-1039F96D4DC3}) (Version: 5.3.0.264 - Hewlett-Packard) HP Software Framework (HKLM-x32\...\{AF240B18-034B-4A82-B3FC-0B879C4BAE2E}) (Version: 4.5.1.1 - Hewlett-Packard Company) IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6365.0 - IDT) Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation) Intel(R) Display Audio Driver (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 6.14.00.3074 - Intel Corporation) Intel(R) Identity Protection Technology 1.1.2.0 (HKLM-x32\...\{C01A86F5-56E7-101F-9BC9-E3F1025EB779}) (Version: 1.1.2.0 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.5.0.1026 - Intel Corporation) itisaluna (HKLM-x32\...\itisaluna) (Version: 21.005.22.00.328 - Huawei Technologies Co.,Ltd) Jewel Match 3 (x32 Version: 2.2.0.98 - WildTangent) Hidden Jewel Quest Mysteries: The Seventh Gate Collector's Edition (x32 Version: 2.2.0.98 - WildTangent) Hidden John Deere Drive Green (x32 Version: 2.2.0.95 - WildTangent) Hidden Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Letters from Nowhere 2 (x32 Version: 2.2.0.97 - WildTangent) Hidden Luxor HD (x32 Version: 2.2.0.98 - WildTangent) Hidden Mah Jong Medley (x32 Version: 2.2.0.95 - WildTangent) Hidden Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Extended (HKLM\...\Microsoft .NET Framework 4 Extended) (Version: 4.0.30319 - Microsoft Corporation) Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-2088086660-1261043681-1886644693-1000\...\OneDriveSetup.exe) (Version: 17.0.4035.0328 - Microsoft Corporation) Microsoft Silverlight (HKLM-x32\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 4.0.50401.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) opensource (x32 Version: 1.0.14960.3876 - Your Company Name) Hidden Penguins! (x32 Version: 2.2.0.98 - WildTangent) Hidden Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.98 - WildTangent) Hidden Poker Superstars III (x32 Version: 2.2.0.95 - WildTangent) Hidden Polar Bowler (x32 Version: 2.2.0.97 - WildTangent) Hidden Polar Golfer (x32 Version: 2.2.0.98 - WildTangent) Hidden PX Profile Update (x32 Version: 1.00.1. - AMD) Hidden Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.48.823.2011 - Realtek) Realtek PCIE Card Reader (HKLM-x32\...\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.1.7601.85 - Realtek Semiconductor Corp.) RollerCoaster Tycoon 3: Platinum (x32 Version: 2.2.0.98 - WildTangent) Hidden Skype™ 5.5 (HKLM-x32\...\{AA59DDE4-B672-4621-A016-4C248204957A}) (Version: 5.5.117 - Skype Technologies S.A.) swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden Synaptics TouchPad Driver (HKLM\...\SynTPDeinstKey) (Version: 15.3.11.0 - Synaptics Incorporated) The Treasures of Mystery Island: The Ghost Ship (x32 Version: 2.2.0.98 - WildTangent) Hidden Torchlight (x32 Version: 2.2.0.98 - WildTangent) Hidden Update Installer for WildTangent Games App (x32 Version: - WildTangent) Hidden VIP Access SDK (1.0.1.2) (HKLM-x32\...\VIP Access SDK) (Version: 1.0.1.2 - Symantec Inc.) Virtual Villagers 4 - The Tree of Life (x32 Version: 2.2.0.98 - WildTangent) Hidden WildTangent Games App (HP Games) (x32 Version: 4.0.5.32 - WildTangent) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation) WinPcap 4.1.2 (HKLM-x32\...\WinPcapInst) (Version: 4.1.0.2001 - CACE Technologies) Zuma's Revenge (x32 Version: 2.2.0.98 - WildTangent) Hidden ÈÑíÏ Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden ãÚÑÖ ÕæÑ Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {08559613-EBC1-4437-BF7E-146AF9A13CF5} - System32\Tasks\Bitdefender Update Product Data_A17FD818A96743FAB28AC221BEB4B2C8 => C:\Program Files\Bitdefender\Bitdefender\bdproductdata.exe [2016-05-27] (Bitdefender) Task: {11599FC8-1C6D-456A-BAC9-B238AEB785BB} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2016-06-03] (Hewlett-Packard Company) Task: {1C935FF7-2DAD-41AD-BC33-FEB6B6FA2554} - System32\Tasks\MirageAgent => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [2011-09-29] (CyberLink) Task: {7505B58F-89BA-4E3A-8961-2A51268892E6} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Tuneup => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2016-06-03] (Hewlett-Packard Company) Task: {A4517201-5109-4E87-A4FE-0E2488DB9F22} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPSFMessenger\HPSFMsgr.exe [2011-09-10] (Hewlett-Packard Company) Task: {D7DDD91F-D614-4D0F-A981-1EABA9701727} - System32\Tasks\{123DC23B-D4D6-4D99-A49D-5C4CA5FD7356} => pcalua.exe -a C:\Users\SUN\Downloads\BIPCPSetup.exe -d C:\Users\SUN\Downloads Task: {E1FBDE88-2741-42B8-BE14-4BAD6DF2D457} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Ghost Resign Task => c:\program files (x86)\hewlett-packard\hp health check\activecheck\product_line\HPResignFileLoader.exe [2016-05-24] (Microsoft) Task: {FFA9A09B-F69D-47E8-8585-6E335895F53F} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater\HPSFUpdater.exe [2011-06-14] (Hewlett-Packard) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== 2016-05-27 08:37 - 2016-05-27 11:28 - 00265080 _____ () C:\Program Files\Bitdefender\Bitdefender\txmlutil.dll 2016-05-27 11:31 - 2016-05-27 11:31 - 00003072 _____ () C:\Program Files\Bitdefender\Bitdefender\UI\accessl.ui 2016-05-27 08:37 - 2011-11-14 19:17 - 00153680 _____ () C:\Program Files\Bitdefender\Bitdefender\bdfwcore.dll 2016-05-27 08:37 - 2016-05-27 11:26 - 00004608 _____ () C:\Program Files\Bitdefender\Bitdefender\UI\IMSecurityAL.ui 2016-05-27 09:56 - 2016-05-27 10:18 - 01006336 _____ () C:\Program Files\Bitdefender\Bitdefender\otengines_02251_002\ashttpbr.mdl 2016-05-27 09:56 - 2016-05-27 10:18 - 00541952 _____ () C:\Program Files\Bitdefender\Bitdefender\otengines_02251_002\ashttpdsp.mdl 2016-05-27 09:56 - 2016-05-27 10:19 - 03035488 _____ () C:\Program Files\Bitdefender\Bitdefender\otengines_02251_002\ashttpph.mdl 2016-05-27 09:56 - 2016-05-27 10:20 - 01541440 _____ () C:\Program Files\Bitdefender\Bitdefender\otengines_02251_002\ashttprbl.mdl 2011-08-09 18:44 - 2011-08-09 18:44 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2011-09-30 20:40 - 2011-09-30 20:40 - 00107320 _____ () C:\Program Files\Hewlett-Packard\HP LaunchBox\HPTaskBar1.exe 2011-03-14 18:27 - 2011-03-14 18:27 - 00346976 _____ () C:\ProgramData\DatacardService\HWDeviceService64.exe 2016-05-27 08:37 - 2013-03-25 15:16 - 01117920 _____ () C:\Program Files\Bitdefender\Bitdefender SafeBox\System.Data.SQLite.dll 2016-05-25 17:49 - 2016-05-25 17:49 - 00514048 _____ () C:\Program Files (x86)\itisaluna\itisaluna.exe 2016-06-13 00:43 - 2016-06-13 01:28 - 24172616 _____ () C:\Users\SUN\Downloads\RogueKillerX64.exe 2011-08-18 08:14 - 2011-08-18 08:14 - 00369152 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll 2011-09-02 20:49 - 2011-09-02 20:49 - 00016384 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll 2016-05-27 08:37 - 2016-05-27 08:41 - 00204280 _____ () C:\Program Files\Bitdefender\Bitdefender\antispam32\txmlutil.dll 2016-05-25 17:49 - 2016-05-25 17:49 - 00430592 _____ () C:\Program Files (x86)\itisaluna\core.dll 2016-05-25 17:49 - 2016-05-25 17:49 - 00264192 _____ () C:\Program Files (x86)\itisaluna\sdk.dll 2016-05-25 17:49 - 2016-05-25 17:49 - 02415104 _____ () C:\Program Files (x86)\itisaluna\QtCore4.dll 2016-05-25 17:49 - 2016-05-25 17:49 - 00011362 _____ () C:\Program Files (x86)\itisaluna\mingwm10.dll 2016-05-25 17:49 - 2016-05-25 17:49 - 00043008 _____ () C:\Program Files (x86)\itisaluna\libgcc_s_dw2-1.dll 2016-05-25 17:49 - 2016-05-25 17:49 - 09515520 _____ () C:\Program Files (x86)\itisaluna\QtGui4.dll 2016-05-25 17:49 - 2016-05-25 17:49 - 00382464 _____ () C:\Program Files (x86)\itisaluna\Proxy.DLL 2016-05-25 17:49 - 2016-05-25 17:49 - 00218112 _____ () C:\Program Files (x86)\itisaluna\Common.dll 2016-05-25 17:49 - 2016-05-25 17:49 - 00135168 _____ () C:\Program Files (x86)\itisaluna\Trace.dll 2016-05-25 17:49 - 2016-05-25 17:49 - 00545280 _____ () C:\Program Files (x86)\itisaluna\PluginContainer.dll 2016-05-25 17:49 - 2016-05-25 17:49 - 00238080 _____ () C:\Program Files (x86)\itisaluna\AtCodec.dll 2016-05-25 17:49 - 2016-05-25 17:49 - 00304128 _____ () C:\Program Files (x86)\itisaluna\DeviceSrvPlugin.dll 2016-05-25 17:49 - 2016-05-25 17:49 - 00238592 _____ () C:\Program Files (x86)\itisaluna\NetSrvPlugin.dll 2016-05-25 17:49 - 2016-05-25 17:49 - 00133120 _____ () C:\Program Files (x86)\itisaluna\OSDialup.dll 2016-05-25 17:49 - 2016-05-25 17:49 - 00161792 _____ () C:\Program Files (x86)\itisaluna\XCodec.dll 2016-05-25 17:49 - 2016-05-25 17:49 - 00157184 _____ () C:\Program Files (x86)\itisaluna\DataServicePlugin.dll 2016-05-25 17:49 - 2016-05-25 17:49 - 00176128 _____ () C:\Program Files (x86)\itisaluna\CallSrvPlugin.dll 2016-05-25 17:49 - 2016-05-25 17:49 - 00264704 _____ () C:\Program Files (x86)\itisaluna\AddrBookSrvPlugin.dll 2016-05-25 17:49 - 2016-05-25 17:49 - 00217600 _____ () C:\Program Files (x86)\itisaluna\SmsSrvPlugin.dll 2016-05-25 17:49 - 2016-05-25 17:49 - 00339968 _____ () C:\Program Files (x86)\itisaluna\DeviceAppPlugin.dll 2016-05-25 17:49 - 2016-05-25 17:49 - 00065536 _____ () C:\Program Files (x86)\itisaluna\OSPowerMgr.dll 2016-05-25 17:49 - 2016-05-25 17:49 - 00114688 _____ () C:\Program Files (x86)\itisaluna\Win7Support.dll 2016-05-25 17:49 - 2016-05-25 17:49 - 01078272 _____ () C:\Program Files (x86)\itisaluna\AddrBookPlugin.dll 2016-05-25 17:49 - 2016-05-25 17:49 - 00670720 _____ () C:\Program Files (x86)\itisaluna\SmsAppPlugin.dll 2016-05-25 17:49 - 2016-05-25 17:49 - 00182272 _____ () C:\Program Files (x86)\itisaluna\CallAppPlugin.dll 2016-05-25 17:49 - 2016-05-25 17:49 - 00547840 _____ () C:\Program Files (x86)\itisaluna\CallLogSrvPlugin.dll 2016-05-25 17:49 - 2016-05-25 17:49 - 00158720 _____ () C:\Program Files (x86)\itisaluna\NetConnectSrvPlugin.dll 2016-05-25 17:49 - 2016-05-25 17:49 - 00211968 _____ () C:\Program Files (x86)\itisaluna\DialUpPlugin.dll 2016-05-25 17:49 - 2016-05-25 17:49 - 00102400 _____ () C:\Program Files (x86)\itisaluna\OSAdapt.dll 2016-05-25 17:49 - 2016-05-25 17:49 - 00180736 _____ () C:\Program Files (x86)\itisaluna\NDISPlugin.dll 2016-05-25 17:49 - 2016-05-25 17:49 - 00131072 _____ () C:\Program Files (x86)\itisaluna\OSNDIS.dll 2016-05-25 17:49 - 2016-05-25 17:49 - 01101824 _____ () C:\Program Files (x86)\itisaluna\NDISAPI.dll 2016-05-25 17:49 - 2016-05-25 17:49 - 00278528 _____ () C:\Program Files (x86)\itisaluna\NetInfoSrvPlugin.dll 2016-05-25 17:49 - 2016-05-25 17:49 - 00062976 _____ () C:\Program Files (x86)\itisaluna\OSCall.dll 2016-05-25 17:49 - 2016-05-25 17:49 - 00538624 _____ () C:\Program Files (x86)\itisaluna\DeviceMgrUIPlugin.dll 2016-05-25 17:49 - 2016-05-25 17:49 - 00398336 _____ () C:\Program Files (x86)\itisaluna\QtXml4.dll 2016-05-25 17:49 - 2016-05-25 17:49 - 00123392 _____ () C:\Program Files (x86)\itisaluna\ATR2SMgr.dll 2016-05-25 17:49 - 2016-05-25 17:49 - 00184832 _____ () C:\Program Files (x86)\itisaluna\XFramePlugin.dll 2016-05-25 17:49 - 2016-05-25 17:49 - 00646144 _____ () C:\Program Files (x86)\itisaluna\CallUIPlugin.dll 2016-05-25 17:49 - 2016-05-25 17:49 - 00093184 _____ () C:\Program Files (x86)\itisaluna\NotifyServicePlugin.dll 2016-05-25 17:49 - 2016-05-25 17:49 - 00309760 _____ () C:\Program Files (x86)\itisaluna\StatusBarMgrPlugin.dll 2016-05-25 17:49 - 2016-05-25 17:49 - 00117760 _____ () C:\Program Files (x86)\itisaluna\LayoutPlugin.dll 2016-05-25 17:49 - 2016-05-25 17:49 - 00447488 _____ () C:\Program Files (x86)\itisaluna\DialupUIPlugin.dll 2016-05-25 17:49 - 2016-05-25 17:49 - 00343552 _____ () C:\Program Files (x86)\itisaluna\NetConnectPlugin.dll 2016-05-25 17:49 - 2016-05-25 17:49 - 00297472 _____ () C:\Program Files (x86)\itisaluna\MenuMgrPlugin.dll 2016-05-25 17:49 - 2016-05-25 17:49 - 00486400 _____ () C:\Program Files (x86)\itisaluna\NetInfoUIExPlugin.dll 2016-05-25 17:49 - 2016-05-25 17:49 - 00827392 _____ () C:\Program Files (x86)\itisaluna\SMSUIPlugin.dll 2016-05-25 17:49 - 2016-05-25 17:49 - 00771584 _____ () C:\Program Files (x86)\itisaluna\AddrBookUIPlugin.dll 2016-05-25 17:49 - 2016-05-25 17:49 - 00406016 _____ () C:\Program Files (x86)\itisaluna\CallLogUIPlugin.dll 2016-05-25 17:49 - 2016-05-25 17:49 - 00212480 _____ () C:\Program Files (x86)\itisaluna\ToolBarMgrPlugin.dll 2016-05-25 17:49 - 2016-05-25 17:49 - 00693760 _____ () C:\Program Files (x86)\itisaluna\LiveUpdateInterface.DLL 2016-05-25 17:49 - 2016-05-25 17:49 - 01148416 _____ () C:\Program Files (x86)\itisaluna\QtNetwork4.dll 2016-05-25 17:49 - 2016-05-25 17:49 - 00082944 _____ () C:\Program Files (x86)\itisaluna\plugins\imageformats\qgif4.dll 2016-05-25 17:49 - 2016-05-25 17:49 - 00081920 _____ () C:\Program Files (x86)\itisaluna\plugins\imageformats\qico4.dll 2016-05-24 10:21 - 2016-05-24 10:21 - 00172544 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\84842098d2f03a96f67a190bd3de8940\IsdiInterop.ni.dll 2016-05-24 10:21 - 2011-04-30 10:28 - 00059904 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\Users\SUN\Downloads\AntiNetCut3-Win7.exe:BDU [0] AlternateDataStreams: C:\Users\SUN\Downloads\FRST64 (1).exe:BDU [0] AlternateDataStreams: C:\Users\SUN\Downloads\FRST64 (2).exe:BDU [0] AlternateDataStreams: C:\Users\SUN\Downloads\FRST64.exe:BDU [0] AlternateDataStreams: C:\Users\SUN\Downloads\HSS-5.4.3-install-plain-773-plain.exe:BDU [0] AlternateDataStreams: C:\Users\SUN\Downloads\RogueKiller.exe:BDU [0] AlternateDataStreams: C:\Users\SUN\Downloads\RogueKillerX64.exe:BDU [0] ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 05:34 - 2009-06-11 00:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-2088086660-1261043681-1886644693-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\SUN\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: Media is not connected to internet. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is disabled. ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{B1B56981-2599-4BE2-960B-940A912B5F08}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{588FFDC2-6DEC-434C-970B-83BDFFB79A58}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe FirewallRules: [{E9A6E351-C72E-44B1-942B-C5A800F503B4}] => (Allow) C:\Windows\system32\ezSharedSvcHost.exe FirewallRules: [{5531E6AE-E735-45A6-9FEC-CDBC096395E2}] => (Allow) C:\Program Files (x86)\EasyBits For Kids\ezDesktop.exe FirewallRules: [{ACDD4297-5E21-4249-AAFF-A2E578A411AE}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD Cinema\PowerDVDCinema10.exe FirewallRules: [{35EF8DD2-B2AF-466E-B37A-387B61CB3A91}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD10.EXE FirewallRules: [{3B6F636A-7197-40AA-B115-97E3A7B9C35E}] => (Allow) C:\Users\SUN\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe FirewallRules: [{A042A361-2619-4240-8D67-3F0326A0F467}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe FirewallRules: [{65E4394D-ECF9-4714-B576-F76C12A6C88D}] => (Allow) LPort=2869 FirewallRules: [{CDB4E954-BC8A-4158-9DC4-1ECAFEA3DEE6}] => (Allow) LPort=1900 ==================== Restore Points ========================= 29-05-2016 17:03:51 Installed Anti NetCut 3 Service Loader 29-05-2016 17:07:40 Installed AntiNetCut3 30-05-2016 21:33:14 Removed Anti NetCut 3 Service Loader 30-05-2016 21:46:28 Removed AntiNetCut3 31-05-2016 08:00:02 Device Driver Package Install: Anchorfree HSS VPN Adapter Network adapters 31-05-2016 16:38:21 Windows Live Essentials 31-05-2016 17:22:18 Installed DirectX 31-05-2016 17:22:53 Installed DirectX 31-05-2016 17:23:10 Installed DirectX 31-05-2016 17:24:01 WLSetup 31-05-2016 17:55:49 Windows Live Essentials 31-05-2016 17:56:44 Installed DirectX 31-05-2016 17:57:19 Installed DirectX 31-05-2016 17:57:35 Installed DirectX 31-05-2016 17:57:57 WLSetup 31-05-2016 19:22:29 Windows Update 02-06-2016 06:45:44 Windows Update 07-06-2016 00:26:47 Windows Update 12-06-2016 00:13:11 Windows Update ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (06/14/2016 12:30:16 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/13/2016 12:37:55 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/12/2016 12:18:33 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/11/2016 12:46:22 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/10/2016 01:31:44 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/08/2016 08:39:03 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/07/2016 01:36:58 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/05/2016 05:33:04 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/03/2016 03:51:19 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: wmplayer.exe, version: 12.0.7601.17514, time stamp: 0x4ce7a485 Faulting module name: CLFLVSplitter.ax, version: 1.0.0.2027, time stamp: 0x4c77640c Exception code: 0xc0000094 Fault offset: 0x0001bbdb Faulting process id: 0x179c Faulting application start time: 0xwmplayer.exe0 Faulting application path: wmplayer.exe1 Faulting module path: wmplayer.exe2 Report Id: wmplayer.exe3 Error: (06/03/2016 03:48:45 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: wmplayer.exe, version: 12.0.7601.17514, time stamp: 0x4ce7a485 Faulting module name: CLFLVSplitter.ax, version: 1.0.0.2027, time stamp: 0x4c77640c Exception code: 0xc0000094 Fault offset: 0x0001bbdb Faulting process id: 0xd24 Faulting application start time: 0xwmplayer.exe0 Faulting application path: wmplayer.exe1 Faulting module path: wmplayer.exe2 Report Id: wmplayer.exe3 System errors: ============= Error: (06/14/2016 12:30:23 AM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the HPWMISVC service. Error: (06/14/2016 12:29:54 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The itisaluna. OUC service failed to start due to the following error: %%1053 Error: (06/14/2016 12:29:54 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: A timeout was reached (30000 milliseconds) while waiting for the itisaluna. OUC service to connect. Error: (06/14/2016 12:29:12 AM) (Source: Service Control Manager) (EventID: 7022) (User: ) Description: The Bitdefender Virus Shield service hung on starting. Error: (06/14/2016 12:29:14 AM) (Source: EventLog) (EventID: 6008) (User: ) Description: The previous system shutdown at 02:18:19 Õ on þ08/þ09/þ37 was unexpected. Error: (06/13/2016 02:10:01 AM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the HP Support Assistant Service service. Error: (06/13/2016 12:56:17 AM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The UPnP Device Host service depends on the SSDP Discovery service which failed to start because of the following error: %%1058 Error: (06/13/2016 12:56:17 AM) (Source: DCOM) (EventID: 10005) (User: ) Description: 1068upnphost{204810B9-73B2-11D4-BF42-00B0D0118B56} Error: (06/13/2016 12:37:36 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The itisaluna. OUC service failed to start due to the following error: %%1053 Error: (06/13/2016 12:37:36 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: A timeout was reached (30000 milliseconds) while waiting for the itisaluna. OUC service to connect. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i5-2450M CPU @ 2.50GHz Percentage of memory in use: 79% Total physical RAM: 4043.86 MB Available physical RAM: 837.64 MB Total Virtual: 8085.91 MB Available Virtual: 3022.36 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:440.76 GB) (Free:392.38 GB) NTFS ==>[system with boot components (obtained from drive)] Drive d: (Recovery) (Fixed) (Total:20.83 GB) (Free:2.19 GB) NTFS ==>[system with boot components (obtained from drive)] Drive e: (HP_TOOLS) (Fixed) (Total:3.96 GB) (Free:1.08 GB) FAT32 Drive g: (ÇáÎÇÑÌí) (Fixed) (Total:465.76 GB) (Free:375.71 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 1 (Size: 465.8 GB) (Disk ID: 4D3832B8) Partition 1: (Not Active) - (Size=465.8 GB) - (Type=07 NTFS) ==================== End of Addition.txt ============================