Forums
New posts
Search forums
News
Security News
Technology News
Giveaways
Giveaways, Promotions and Contests
Discounts & Deals
Reviews
Users Reviews
Video Reviews
Support
Windows Malware Removal Help & Support
Inactive Support Threads
Mac Malware Removal Help & Support
Mobile Malware Removal Help & Support
Blog
Log in
Register
What's new
Search
Search titles only
By:
Search titles only
By:
Reply to thread
Menu
Install the app
Install
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Forums
Support
Windows Malware Removal Help & Support
Ran MWB, No Internet Connection
Message
<blockquote data-quote="BenNeedsHelp" data-source="post: 453151" data-attributes="member: 45756"><p>Additional scan result of Farbar Recovery Scan Tool (x64) Version:23-11-2015</p><p>Ran by owner (2015-11-24 19:09:55)</p><p>Running from C:\Users\owner\Desktop</p><p>Windows 8 (X64) (2015-05-20 03:04:19)</p><p>Boot Mode: Normal</p><p>==========================================================</p><p></p><p></p><p>==================== Accounts: =============================</p><p></p><p>Administrator (S-1-5-21-4053647124-3796825272-3454316862-500 - Administrator - Disabled) => C:\Users\Administrator</p><p>Guest (S-1-5-21-4053647124-3796825272-3454316862-501 - Limited - Disabled)</p><p>owner (S-1-5-21-4053647124-3796825272-3454316862-1001 - Administrator - Enabled) => C:\Users\owner</p><p></p><p>==================== Security Center ========================</p><p></p><p>(If an entry is included in the fixlist, it will be removed.)</p><p></p><p>AV: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}</p><p>AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}</p><p></p><p>==================== Installed Programs ======================</p><p></p><p>(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)</p><p></p><p>µTorrent (HKU\S-1-5-21-4053647124-3796825272-3454316862-1001\...\uTorrent) (Version: 3.4.3.40298 - BitTorrent Inc.)</p><p>Adobe Flash Player 19 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 19.0.0.245 - Adobe Systems Incorporated)</p><p>Adobe Reader X (10.1.16) MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.1.16 - Adobe Systems Incorporated)</p><p>ASUS Instant Connect (HKLM-x32\...\{89ECB85A-D933-4CEA-9116-5CBC9C2ED95B}) (Version: 1.2.8 - ASUS)</p><p>ASUS InstantOn (HKLM-x32\...\{749F674B-2674-47E8-879C-5626A06B2A91}) (Version: 3.0.4 - ASUS)</p><p>ASUS LifeFrame3 (HKLM-x32\...\{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}) (Version: 3.1.9 - ASUS)</p><p>ASUS Live Update (HKLM-x32\...\{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}) (Version: 3.1.9 - ASUS)</p><p>ASUS Power4Gear Hybrid (HKLM\...\{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}) (Version: 2.0.4 - ASUS)</p><p>ASUS Smart Gesture (HKLM-x32\...\{4D3286A6-F6AB-498A-82A4-E4F040529F3D}) (Version: 1.0.35 - ASUS)</p><p>ASUS Splendid Video Enhancement Technology (HKLM-x32\...\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 1.03.0006 - ASUS)</p><p>ASUS Tutor (HKLM-x32\...\{58172D66-2F69-4215-9AEC-ED8196023736}) (Version: 1.0.7 - ASUS)</p><p>ASUS USB Charger Plus (HKLM-x32\...\{A859E3E5-C62F-4BFA-AF1D-2B95E03166AF}) (Version: 2.1.4 - ASUS)</p><p>ASUSDVD (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.4126.52 - CyberLink Corp.)</p><p>ASUSDVD (x32 Version: 10.0.4126.52 - CyberLink Corp.) Hidden</p><p>ATK Package (HKLM-x32\...\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0025 - ASUS)</p><p>Batman Arkham Asylum - Game of the Year Edition (HKLM-x32\...\Batman Arkham Asylum - Game of the Year Edition_is1) (Version: - )</p><p>Batman: Arkham City™ GOTY (HKLM-x32\...\GFWL_{57520FA0-DF38-46A1-8046-3B1000008500}) (Version: 1.0.0000.133 - WB Games)</p><p>Batman: Arkham City™ GOTY (x32 Version: 1.0.0000.133 - WB Games) Hidden</p><p>Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment)</p><p>DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 10.0.0.0054 - Disc Soft Ltd)</p><p>Dropbox (HKLM-x32\...\Dropbox) (Version: 3.10.11 - Dropbox, Inc.)</p><p>Dropbox Update Helper (x32 Version: 1.3.27.33 - Dropbox, Inc.) Hidden</p><p>Dual-Core Optimizer (HKLM-x32\...\{9FD6F1A8-5550-46AF-8509-271DF0E768B5}) (Version: 1.1.4.0169 - AMD)</p><p>Fallout (HKLM-x32\...\GOGPACKFALLOUT_is1) (Version: 2.0.0.14 - GOG.com)</p><p>Fallout 3 (HKLM-x32\...\{974C4B12-4D02-4879-85E0-61C95CC63E9E}) (Version: 1.00.0000 - Bethesda Softworks)</p><p>Hearthstone (HKLM-x32\...\Hearthstone) (Version: - Blizzard Entertainment)</p><p>Hi-Rez Studios Authenticate and Update Service (HKLM-x32\...\{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF1FC}) (Version: 3.0.0.0 - Hi-Rez Studios)</p><p>Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1252 - Intel Corporation)</p><p>Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.2867 - Intel Corporation)</p><p>Intel(R) PROSet/Wireless for Bluetooth(R) + High Speed (HKLM\...\{E77289CF-12B9-4CAB-A49E-FEAE947F4D95}) (Version: 15.5.4.0423 - Intel Corporation)</p><p>Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (HKLM\...\{7854AA22-A2F0-4F29-A2E9-D0C5A2B685E7}) (Version: 2.5.0.0236 - Motorola Solutions, Inc)</p><p>Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation)</p><p>Intel(R) WiDi (HKLM\...\{6097158B-0184-4140-BEC3-7885794D2571}) (Version: 3.5.40.0 - Intel Corporation)</p><p>Intel® PROSet/Wireless Software (HKLM-x32\...\{c9967fbd-e3c3-4ed0-992a-5b33260f2944}) (Version: 16.1.5 - Intel Corporation)</p><p>League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games)</p><p>League of Legends (x32 Version: 3.0.1 - Riot Games) Hidden</p><p>LibreOffice 4.4.3.2 (HKLM-x32\...\{A651A592-2F6C-4D66-AEA8-9BFE4B61BCB3}) (Version: 4.4.3.2 - The Document Foundation)</p><p>Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)</p><p>Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}) (Version: 3.5.92.0 - Microsoft Corporation)</p><p>Microsoft Games for Windows Marketplace (HKLM-x32\...\{67F42018-F647-4D3C-BE62-F8CB4FE2FCD5}) (Version: 3.5.67.0 - Microsoft Corporation)</p><p>Microsoft Office 365 - en-us (HKLM\...\O365HomePremRetail - en-us) (Version: 15.0.4771.1004 - Microsoft Corporation)</p><p>Microsoft OneDrive (HKU\S-1-5-21-4053647124-3796825272-3454316862-1001\...\OneDriveSetup.exe) (Version: 17.3.4604.0120 - Microsoft Corporation)</p><p>Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation)</p><p>Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)</p><p>Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)</p><p>Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)</p><p>Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)</p><p>Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)</p><p>Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)</p><p>Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)</p><p>Mozilla Firefox 42.0 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 42.0 (x86 en-US)) (Version: 42.0 - Mozilla)</p><p>Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 42.0.0.5780 - Mozilla)</p><p>NVIDIA PhysX (HKLM-x32\...\{C5C1C0F0-D62F-4DBF-81D4-D7EF397C228B}) (Version: 9.09.0814 - NVIDIA Corporation)</p><p>Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4771.1004 - Microsoft Corporation) Hidden</p><p>Office 15 Click-to-Run Licensing Component (Version: 15.0.4771.1004 - Microsoft Corporation) Hidden</p><p>Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4771.1004 - Microsoft Corporation) Hidden</p><p>Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.3.730.2012 - Realtek)</p><p>Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6760 - Realtek Semiconductor Corp.)</p><p>Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.8400.30136 - Realtek Semiconductor Corp.)</p><p>Skype™ 7.13 (HKLM-x32\...\{6A0549A9-1B96-498C-ACBC-3943001FEB19}) (Version: 7.13.101 - Skype Technologies S.A.)</p><p>Smite (HKLM-x32\...\{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF017}) (Version: 2.6.2742.1 - Hi-Rez Studios)</p><p>Spotify (HKU\S-1-5-21-4053647124-3796825272-3454316862-1001\...\Spotify) (Version: 1.0.18.60.g5fe0413d - Spotify AB)</p><p>TeamSpeak 3 Client (HKLM-x32\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH)</p><p>Windows Driver Package - ASUS (ATP) Mouse (10/29/2012 1.0.0.148) (HKLM\...\C01F56FBD9B141017E63E2A1A141E59934D4DC67) (Version: 10/29/2012 1.0.0.148 - ASUS)</p><p>WinFlash (HKLM-x32\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 2.41.1 - ASUS)</p><p>WinRAR 5.21 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH)</p><p>WTFast 3.5 (HKLM-x32\...\{12B4121D-5221-4AFC-9EDC-63B0CA139856}_is1) (Version: 3.5.9.511 - Initex & AAA Internet Publishing)</p><p></p><p>==================== Custom CLSID (Whitelisted): ==========================</p><p></p><p>(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)</p><p></p><p></p><p>==================== Restore Points =========================</p><p></p><p>05-11-2015 13:08:35 Scheduled Checkpoint</p><p>13-11-2015 11:51:00 Scheduled Checkpoint</p><p>23-11-2015 18:22:33 Scheduled Checkpoint</p><p></p><p>==================== Hosts content: ===============================</p><p></p><p>(If needed Hosts: directive could be included in the fixlist to reset Hosts.)</p><p></p><p>2012-07-26 00:26 - 2012-07-26 00:26 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts</p><p></p><p></p><p>==================== Scheduled Tasks (Whitelisted) =============</p><p></p><p>(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)</p><p></p><p>Task: {26BF8079-047C-4054-8696-1ACD18FD6D8E} - System32\Tasks\{C75438B8-DAEF-435A-AAF7-111CFBF3037B} => Firefox.exe hxxp://ui.skype.com/ui/0/7.4.0.102/en/go/help.faq.installer?source=lightinstaller&amp;LastError=1618</p><p>Task: {2BA2221C-3501-4976-94E6-58362CCC9925} - System32\Tasks\ASUS Touchpad Launcher (x64) => C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLauncher.exe [2012-10-31] (AsusTek)</p><p>Task: {2E95013E-1F22-4324-BCAB-24EE7D2E8F24} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2015-10-13] (Microsoft Corporation)</p><p>Task: {404C4D0C-CFBB-41C4-B727-F2F8A71DD17F} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2015-07-10] (Dropbox, Inc.)</p><p>Task: {406A1E94-1944-4DF3-9CF3-F5B960827104} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2015-07-10] (Dropbox, Inc.)</p><p>Task: {537806BD-A5FA-409D-9C78-101512871370} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-09-14] (Adobe Systems Incorporated)</p><p>Task: {552BA50C-4FD7-4D86-8816-78597B9C1876} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2015-10-13] (Microsoft Corporation)</p><p>Task: {55E4CA9E-8125-494A-9358-40F2C257E207} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonx86\Microsoft Shared\OFFICE15\OLicenseHeartbeat.exe [2015-10-13] (Microsoft Corporation)</p><p>Task: {8E8D4B09-63FB-41D3-BA60-C54CB7523BCA} - System32\Tasks\ASUS USB Charger Plus => C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [2012-07-24] (ASUSTek Computer Inc.)</p><p>Task: {991678EA-4031-4CFE-803E-F95AEEBE9281} - System32\Tasks\YBSNKXI => C:\ProgramData\6b818a33a2964c51a9c56ff33ef8d8c7\6b818a33a2964c51a9c56ff33ef8d8c7.exe <==== ATTENTION</p><p>Task: {A6AD429C-F3A9-464E-B79B-F924E9C95D55} - System32\Tasks\ASUS P4G => C:\Program Files\ASUS\P4G\BatteryLife.exe [2012-08-24] (ASUS)</p><p>Task: {CE96EE03-7A4A-4955-B249-6D5096739190} - System32\Tasks\ASUS Splendid ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2012-10-17] (ASUS)</p><p>Task: {D5846A61-4F8D-4C03-BB3B-CA9A97D07A6B} - System32\Tasks\ASUS Live Update => C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe [2012-08-22] (ASUSTeK Computer Inc.)</p><p>Task: {EB8632DF-8257-4048-90E5-4589D0F4ECBB} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-11-11] (Adobe Systems Incorporated)</p><p></p><p>(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)</p><p></p><p>Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe</p><p>Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe</p><p>Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe</p><p></p><p>==================== Shortcuts =============================</p><p></p><p>(The entries could be listed to be restored or removed.)</p><p></p><p>==================== Loaded Modules (Whitelisted) ==============</p><p></p><p>2015-07-10 10:50 - 2015-10-13 04:34 - 00105640 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll</p><p>2012-08-24 20:26 - 2012-08-24 20:26 - 00031360 _____ () C:\Program Files\ASUS\P4G\DevMng.dll</p><p>2015-10-28 08:30 - 2015-09-01 11:04 - 08901184 _____ () C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\1033\GrooveIntlResource.dll</p><p>2012-07-26 02:58 - 2012-07-26 02:53 - 00170864 _____ () C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe\ModernShared\ErrorReporting\ErrorReporting.dll</p><p>2012-10-17 12:51 - 2012-10-17 12:51 - 00168664 _____ () C:\Program Files (x86)\ASUS\Splendid\ColorUService.exe</p><p>2012-11-13 03:30 - 2012-10-14 23:09 - 00094208 _____ () C:\Windows\system32\IccLibDll_x64.dll</p><p>2012-10-17 12:51 - 2012-10-17 12:51 - 00011776 _____ () C:\Program Files (x86)\ASUS\Splendid\GLCDdll.dll</p><p>2012-12-28 11:45 - 2012-06-24 21:41 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll</p><p></p><p>==================== Alternate Data Streams (Whitelisted) =========</p><p></p><p>(If an entry is included in the fixlist, only the ADS will be removed.)</p><p></p><p></p><p>==================== Safe Mode (Whitelisted) ===================</p><p></p><p>(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)</p><p></p><p></p><p>==================== EXE Association (Whitelisted) ===============</p><p></p><p>(If an entry is included in the fixlist, the registry item will be restored to default or removed.)</p><p></p><p></p><p>==================== Internet Explorer trusted/restricted ===============</p><p></p><p>(If an entry is included in the fixlist, it will be removed from the registry.)</p><p></p><p></p><p>==================== Other Areas ============================</p><p></p><p>(Currently there is no automatic fix for this section.)</p><p></p><p>HKU\S-1-5-21-4053647124-3796825272-3454316862-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\owner\Pictures\Protest\durrutifaiwallpaper.jpg</p><p>DNS Servers: 192.168.1.1</p><p>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)</p><p>Windows Firewall is enabled.</p><p></p><p>==================== MSCONFIG/TASK MANAGER disabled items ==</p><p></p><p>(Currently there is no automatic fix for this section.)</p><p></p><p>HKU\S-1-5-21-4053647124-3796825272-3454316862-1001\...\StartupApproved\Run: => "Skype"</p><p>HKU\S-1-5-21-4053647124-3796825272-3454316862-1001\...\StartupApproved\Run: => "Spotify"</p><p>HKU\S-1-5-21-4053647124-3796825272-3454316862-1001\...\StartupApproved\Run: => "Spotify Web Helper"</p><p></p><p>==================== FirewallRules (Whitelisted) ===============</p><p></p><p>(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)</p><p></p><p>FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139</p><p>FirewallRules: [{EA4FF0B3-8537-4EBF-9D03-A25C9F89A4C0}] => (Allow) C:\Program Files\Intel Corporation\Intel WiDi\WiDiApp.exe</p><p>FirewallRules: [{A8D22C49-A55D-4170-9E83-8A1FDD2D0A74}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD Cinema\PowerDVDCinema10.exe</p><p>FirewallRules: [{49B970C5-5095-41D0-A9A1-5C8AD8FF0D47}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD10.EXE</p><p>FirewallRules: [{0213E8B1-EC43-4D15-80C2-68389453A0A7}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe</p><p>FirewallRules: [{6703A77F-EDD0-49F8-8948-0ACC40FDC5DF}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe</p><p>FirewallRules: [TCP Query User{A2A5413E-683C-4BEC-9652-D91B9AFECB16}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe</p><p>FirewallRules: [{C19A86A6-9D9B-4957-88A6-7B348DD3221E}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe</p><p>FirewallRules: [TCP Query User{2DFC80DC-7CA4-4C24-A7B1-A5A181A0B925}C:\users\owner\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\owner\appdata\roaming\spotify\spotify.exe</p><p>FirewallRules: [UDP Query User{85CBA462-D9E4-4977-BF08-8FC82F02AAC9}C:\users\owner\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\owner\appdata\roaming\spotify\spotify.exe</p><p>FirewallRules: [{B5CA1395-3768-4172-82F2-17BD5718280A}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe</p><p>FirewallRules: [{87D572C1-9F18-4C7D-99FC-FCD709AF096A}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe</p><p>FirewallRules: [{9F9F5FFB-4D7E-40F6-BC8D-5C83984CF2E1}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe</p><p>FirewallRules: [{8D2886F6-4005-44C9-B32C-FCD4EF6235FA}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe</p><p>FirewallRules: [TCP Query User{47857BA7-107E-4C27-A80E-32C9D7D07D00}C:\program files (x86)\hi-rez studios\hirezgames\smite\binaries\win32\smite.exe] => (Allow) C:\program files (x86)\hi-rez studios\hirezgames\smite\binaries\win32\smite.exe</p><p>FirewallRules: [UDP Query User{EA044A73-679F-4A8F-A8C2-0B356933FC43}C:\program files (x86)\hi-rez studios\hirezgames\smite\binaries\win32\smite.exe] => (Allow) C:\program files (x86)\hi-rez studios\hirezgames\smite\binaries\win32\smite.exe</p><p>FirewallRules: [{66810C25-19C6-48A2-B2B6-22A8277A1C3B}] => (Allow) C:\Users\owner\AppData\Roaming\uTorrent\uTorrent.exe</p><p>FirewallRules: [{01F3C9E4-02E8-4A41-965E-17877B247B85}] => (Allow) C:\Users\owner\AppData\Roaming\uTorrent\uTorrent.exe</p><p>FirewallRules: [TCP Query User{D0B1E449-5069-4A9E-A522-C4A57588A2DC}C:\program files (x86)\rocksteady studios\batman arkham asylum - game of the year edition\binaries\shippingpc-bmgame.exe] => (Allow) C:\program files (x86)\rocksteady studios\batman arkham asylum - game of the year edition\binaries\shippingpc-bmgame.exe</p><p>FirewallRules: [UDP Query User{E5C10345-10BB-405B-A76E-7BF0ABA77015}C:\program files (x86)\rocksteady studios\batman arkham asylum - game of the year edition\binaries\shippingpc-bmgame.exe] => (Allow) C:\program files (x86)\rocksteady studios\batman arkham asylum - game of the year edition\binaries\shippingpc-bmgame.exe</p><p>FirewallRules: [{13038F5B-16C7-4B63-86EF-F83935358F33}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\outlook.exe</p><p>FirewallRules: [{F785BCB7-1DDC-4C98-B30D-0126BC9757E2}] => (Allow) C:\Users\owner\AppData\Local\Microsoft\OneDrive\OneDrive.exe</p><p>FirewallRules: [{AB0F478A-8DCA-4DE8-8C6A-A069BAF65BBA}] => (Allow) C:\Users\owner\Desktop\Games\BatmanArkhamCity\Binaries\Win32\BatmanAC.exe</p><p>FirewallRules: [TCP Query User{C57AE126-E45C-412D-9ECB-F7C9298C23A0}C:\users\owner\desktop\games\batmanarkhamcity\binaries\win32\batmanac_o.exe] => (Allow) C:\users\owner\desktop\games\batmanarkhamcity\binaries\win32\batmanac_o.exe</p><p>FirewallRules: [UDP Query User{F65286C6-AE46-44AA-9D0E-DC3B6DCE369D}C:\users\owner\desktop\games\batmanarkhamcity\binaries\win32\batmanac_o.exe] => (Allow) C:\users\owner\desktop\games\batmanarkhamcity\binaries\win32\batmanac_o.exe</p><p>FirewallRules: [{96CE8779-A30F-451D-B162-7BCDBE2BA07B}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe</p><p>FirewallRules: [{91BB544A-A87F-4222-A8BB-3F8D5C75992E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe</p><p>FirewallRules: [{C4A1FCC3-A441-4927-A906-3B81DC904353}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe</p><p></p><p>==================== Faulty Device Manager Devices =============</p><p></p><p></p><p>==================== Event log errors: =========================</p><p></p><p>Application errors:</p><p>==================</p><p>Error: (11/24/2015 06:46:38 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)</p><p>Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code.</p><p></p><p>Error: (11/24/2015 06:46:38 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)</p><p>Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.</p><p></p><p>Error: (11/24/2015 06:31:40 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)</p><p>Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code.</p><p></p><p>Error: (11/24/2015 06:31:40 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)</p><p>Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.</p><p></p><p>Error: (11/24/2015 06:19:10 PM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: )</p><p>Description: Subscription licensing service failed: -1073415161</p><p></p><p>Error: (11/24/2015 07:59:40 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)</p><p>Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code.</p><p></p><p>Error: (11/24/2015 07:59:40 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)</p><p>Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.</p><p></p><p>Error: (11/24/2015 01:20:45 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)</p><p>Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code.</p><p></p><p>Error: (11/24/2015 01:20:45 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)</p><p>Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.</p><p></p><p>Error: (11/23/2015 05:18:46 PM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: )</p><p>Description: Subscription licensing service failed: -1073415161</p><p></p><p></p><p>System errors:</p><p>=============</p><p>Error: (11/24/2015 06:39:50 PM) (Source: Service Control Manager) (EventID: 7000) (User: )</p><p>Description: The Windows Search service failed to start due to the following error:</p><p>%%1069</p><p></p><p>Error: (11/24/2015 06:39:50 PM) (Source: Service Control Manager) (EventID: 7038) (User: )</p><p>Description: The WSearch service was unable to log on as NT AUTHORITY\SYSTEM with the currently configured password due to the following error:</p><p>%%50</p><p></p><p>To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).</p><p></p><p>Error: (11/24/2015 06:39:45 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)</p><p>Description: WLAN Extensibility Module has stopped unexpectedly.</p><p></p><p>Module Path: C:\WINDOWS\System32\IWMSSvc.dll</p><p></p><p>Error: (11/24/2015 06:39:45 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)</p><p>Description: WLAN Extensibility Module has stopped unexpectedly.</p><p></p><p>Module Path: C:\WINDOWS\System32\IWMSSvc.dll</p><p></p><p>Error: (11/24/2015 06:39:43 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)</p><p>Description: WLAN Extensibility Module has stopped unexpectedly.</p><p></p><p>Module Path: C:\WINDOWS\System32\IWMSSvc.dll</p><p></p><p>Error: (11/24/2015 06:39:21 PM) (Source: Service Control Manager) (EventID: 7034) (User: )</p><p>Description: The Intel(R) Management and Security Application User Notification Service service terminated unexpectedly. It has done this 1 time(s).</p><p></p><p>Error: (11/24/2015 06:39:21 PM) (Source: Service Control Manager) (EventID: 7031) (User: )</p><p>Description: The Intel(R) Centrino(R) Wireless Bluetooth(R) + High Speed Security Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service.</p><p></p><p>Error: (11/24/2015 06:39:21 PM) (Source: Service Control Manager) (EventID: 7031) (User: )</p><p>Description: The Intel® Centrino® Wireless Bluetooth® + High Speed Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.</p><p></p><p>Error: (11/24/2015 06:39:21 PM) (Source: Service Control Manager) (EventID: 7034) (User: )</p><p>Description: The Disc Soft Lite Bus Service service terminated unexpectedly. It has done this 1 time(s).</p><p></p><p>Error: (11/24/2015 06:39:21 PM) (Source: Service Control Manager) (EventID: 7034) (User: )</p><p>Description: The Bluetooth OBEX Service service terminated unexpectedly. It has done this 1 time(s).</p><p></p><p></p><p>==================== Memory info ===========================</p><p></p><p>Processor: Intel(R) Core(TM) i5-3230M CPU @ 2.60GHz</p><p>Percentage of memory in use: 33%</p><p>Total physical RAM: 6033.77 MB</p><p>Available physical RAM: 4042.12 MB</p><p>Total Virtual: 12177.77 MB</p><p>Available Virtual: 10125.1 MB</p><p></p><p>==================== Drives ================================</p><p></p><p>Drive c: (OS) (Fixed) (Total:676.99 GB) (Free:286.15 GB) NTFS ==>[system with boot components (obtained from drive)]</p><p>Drive g: (BACGOTY) (CDROM) (Total:18.16 GB) (Free:0 GB) CDFS</p><p></p><p>==================== MBR & Partition Table ==================</p><p></p><p>========================================================</p><p>Disk: 0 (Size: 698.6 GB) (Disk ID: A3362226)</p><p></p><p>Partition: GPT.</p><p></p><p>==================== End of Addition.txt ============================</p></blockquote><p></p>
[QUOTE="BenNeedsHelp, post: 453151, member: 45756"] Additional scan result of Farbar Recovery Scan Tool (x64) Version:23-11-2015 Ran by owner (2015-11-24 19:09:55) Running from C:\Users\owner\Desktop Windows 8 (X64) (2015-05-20 03:04:19) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-4053647124-3796825272-3454316862-500 - Administrator - Disabled) => C:\Users\Administrator Guest (S-1-5-21-4053647124-3796825272-3454316862-501 - Limited - Disabled) owner (S-1-5-21-4053647124-3796825272-3454316862-1001 - Administrator - Enabled) => C:\Users\owner ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) µTorrent (HKU\S-1-5-21-4053647124-3796825272-3454316862-1001\...\uTorrent) (Version: 3.4.3.40298 - BitTorrent Inc.) Adobe Flash Player 19 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 19.0.0.245 - Adobe Systems Incorporated) Adobe Reader X (10.1.16) MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.1.16 - Adobe Systems Incorporated) ASUS Instant Connect (HKLM-x32\...\{89ECB85A-D933-4CEA-9116-5CBC9C2ED95B}) (Version: 1.2.8 - ASUS) ASUS InstantOn (HKLM-x32\...\{749F674B-2674-47E8-879C-5626A06B2A91}) (Version: 3.0.4 - ASUS) ASUS LifeFrame3 (HKLM-x32\...\{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}) (Version: 3.1.9 - ASUS) ASUS Live Update (HKLM-x32\...\{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}) (Version: 3.1.9 - ASUS) ASUS Power4Gear Hybrid (HKLM\...\{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}) (Version: 2.0.4 - ASUS) ASUS Smart Gesture (HKLM-x32\...\{4D3286A6-F6AB-498A-82A4-E4F040529F3D}) (Version: 1.0.35 - ASUS) ASUS Splendid Video Enhancement Technology (HKLM-x32\...\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 1.03.0006 - ASUS) ASUS Tutor (HKLM-x32\...\{58172D66-2F69-4215-9AEC-ED8196023736}) (Version: 1.0.7 - ASUS) ASUS USB Charger Plus (HKLM-x32\...\{A859E3E5-C62F-4BFA-AF1D-2B95E03166AF}) (Version: 2.1.4 - ASUS) ASUSDVD (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.4126.52 - CyberLink Corp.) ASUSDVD (x32 Version: 10.0.4126.52 - CyberLink Corp.) Hidden ATK Package (HKLM-x32\...\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0025 - ASUS) Batman Arkham Asylum - Game of the Year Edition (HKLM-x32\...\Batman Arkham Asylum - Game of the Year Edition_is1) (Version: - ) Batman: Arkham City™ GOTY (HKLM-x32\...\GFWL_{57520FA0-DF38-46A1-8046-3B1000008500}) (Version: 1.0.0000.133 - WB Games) Batman: Arkham City™ GOTY (x32 Version: 1.0.0000.133 - WB Games) Hidden Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 10.0.0.0054 - Disc Soft Ltd) Dropbox (HKLM-x32\...\Dropbox) (Version: 3.10.11 - Dropbox, Inc.) Dropbox Update Helper (x32 Version: 1.3.27.33 - Dropbox, Inc.) Hidden Dual-Core Optimizer (HKLM-x32\...\{9FD6F1A8-5550-46AF-8509-271DF0E768B5}) (Version: 1.1.4.0169 - AMD) Fallout (HKLM-x32\...\GOGPACKFALLOUT_is1) (Version: 2.0.0.14 - GOG.com) Fallout 3 (HKLM-x32\...\{974C4B12-4D02-4879-85E0-61C95CC63E9E}) (Version: 1.00.0000 - Bethesda Softworks) Hearthstone (HKLM-x32\...\Hearthstone) (Version: - Blizzard Entertainment) Hi-Rez Studios Authenticate and Update Service (HKLM-x32\...\{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF1FC}) (Version: 3.0.0.0 - Hi-Rez Studios) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1252 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.2867 - Intel Corporation) Intel(R) PROSet/Wireless for Bluetooth(R) + High Speed (HKLM\...\{E77289CF-12B9-4CAB-A49E-FEAE947F4D95}) (Version: 15.5.4.0423 - Intel Corporation) Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (HKLM\...\{7854AA22-A2F0-4F29-A2E9-D0C5A2B685E7}) (Version: 2.5.0.0236 - Motorola Solutions, Inc) Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation) Intel(R) WiDi (HKLM\...\{6097158B-0184-4140-BEC3-7885794D2571}) (Version: 3.5.40.0 - Intel Corporation) Intel® PROSet/Wireless Software (HKLM-x32\...\{c9967fbd-e3c3-4ed0-992a-5b33260f2944}) (Version: 16.1.5 - Intel Corporation) League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games) League of Legends (x32 Version: 3.0.1 - Riot Games) Hidden LibreOffice 4.4.3.2 (HKLM-x32\...\{A651A592-2F6C-4D66-AEA8-9BFE4B61BCB3}) (Version: 4.4.3.2 - The Document Foundation) Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes) Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}) (Version: 3.5.92.0 - Microsoft Corporation) Microsoft Games for Windows Marketplace (HKLM-x32\...\{67F42018-F647-4D3C-BE62-F8CB4FE2FCD5}) (Version: 3.5.67.0 - Microsoft Corporation) Microsoft Office 365 - en-us (HKLM\...\O365HomePremRetail - en-us) (Version: 15.0.4771.1004 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-4053647124-3796825272-3454316862-1001\...\OneDriveSetup.exe) (Version: 17.3.4604.0120 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Mozilla Firefox 42.0 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 42.0 (x86 en-US)) (Version: 42.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 42.0.0.5780 - Mozilla) NVIDIA PhysX (HKLM-x32\...\{C5C1C0F0-D62F-4DBF-81D4-D7EF397C228B}) (Version: 9.09.0814 - NVIDIA Corporation) Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4771.1004 - Microsoft Corporation) Hidden Office 15 Click-to-Run Licensing Component (Version: 15.0.4771.1004 - Microsoft Corporation) Hidden Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4771.1004 - Microsoft Corporation) Hidden Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.3.730.2012 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6760 - Realtek Semiconductor Corp.) Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.8400.30136 - Realtek Semiconductor Corp.) Skype™ 7.13 (HKLM-x32\...\{6A0549A9-1B96-498C-ACBC-3943001FEB19}) (Version: 7.13.101 - Skype Technologies S.A.) Smite (HKLM-x32\...\{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF017}) (Version: 2.6.2742.1 - Hi-Rez Studios) Spotify (HKU\S-1-5-21-4053647124-3796825272-3454316862-1001\...\Spotify) (Version: 1.0.18.60.g5fe0413d - Spotify AB) TeamSpeak 3 Client (HKLM-x32\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH) Windows Driver Package - ASUS (ATP) Mouse (10/29/2012 1.0.0.148) (HKLM\...\C01F56FBD9B141017E63E2A1A141E59934D4DC67) (Version: 10/29/2012 1.0.0.148 - ASUS) WinFlash (HKLM-x32\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 2.41.1 - ASUS) WinRAR 5.21 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH) WTFast 3.5 (HKLM-x32\...\{12B4121D-5221-4AFC-9EDC-63B0CA139856}_is1) (Version: 3.5.9.511 - Initex & AAA Internet Publishing) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== Restore Points ========================= 05-11-2015 13:08:35 Scheduled Checkpoint 13-11-2015 11:51:00 Scheduled Checkpoint 23-11-2015 18:22:33 Scheduled Checkpoint ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2012-07-26 00:26 - 2012-07-26 00:26 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {26BF8079-047C-4054-8696-1ACD18FD6D8E} - System32\Tasks\{C75438B8-DAEF-435A-AAF7-111CFBF3037B} => Firefox.exe hxxp://ui.skype.com/ui/0/7.4.0.102/en/go/help.faq.installer?source=lightinstaller&LastError=1618 Task: {2BA2221C-3501-4976-94E6-58362CCC9925} - System32\Tasks\ASUS Touchpad Launcher (x64) => C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLauncher.exe [2012-10-31] (AsusTek) Task: {2E95013E-1F22-4324-BCAB-24EE7D2E8F24} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2015-10-13] (Microsoft Corporation) Task: {404C4D0C-CFBB-41C4-B727-F2F8A71DD17F} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2015-07-10] (Dropbox, Inc.) Task: {406A1E94-1944-4DF3-9CF3-F5B960827104} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2015-07-10] (Dropbox, Inc.) Task: {537806BD-A5FA-409D-9C78-101512871370} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-09-14] (Adobe Systems Incorporated) Task: {552BA50C-4FD7-4D86-8816-78597B9C1876} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2015-10-13] (Microsoft Corporation) Task: {55E4CA9E-8125-494A-9358-40F2C257E207} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonx86\Microsoft Shared\OFFICE15\OLicenseHeartbeat.exe [2015-10-13] (Microsoft Corporation) Task: {8E8D4B09-63FB-41D3-BA60-C54CB7523BCA} - System32\Tasks\ASUS USB Charger Plus => C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [2012-07-24] (ASUSTek Computer Inc.) Task: {991678EA-4031-4CFE-803E-F95AEEBE9281} - System32\Tasks\YBSNKXI => C:\ProgramData\6b818a33a2964c51a9c56ff33ef8d8c7\6b818a33a2964c51a9c56ff33ef8d8c7.exe <==== ATTENTION Task: {A6AD429C-F3A9-464E-B79B-F924E9C95D55} - System32\Tasks\ASUS P4G => C:\Program Files\ASUS\P4G\BatteryLife.exe [2012-08-24] (ASUS) Task: {CE96EE03-7A4A-4955-B249-6D5096739190} - System32\Tasks\ASUS Splendid ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2012-10-17] (ASUS) Task: {D5846A61-4F8D-4C03-BB3B-CA9A97D07A6B} - System32\Tasks\ASUS Live Update => C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe [2012-08-22] (ASUSTeK Computer Inc.) Task: {EB8632DF-8257-4048-90E5-4589D0F4ECBB} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-11-11] (Adobe Systems Incorporated) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== 2015-07-10 10:50 - 2015-10-13 04:34 - 00105640 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll 2012-08-24 20:26 - 2012-08-24 20:26 - 00031360 _____ () C:\Program Files\ASUS\P4G\DevMng.dll 2015-10-28 08:30 - 2015-09-01 11:04 - 08901184 _____ () C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\1033\GrooveIntlResource.dll 2012-07-26 02:58 - 2012-07-26 02:53 - 00170864 _____ () C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe\ModernShared\ErrorReporting\ErrorReporting.dll 2012-10-17 12:51 - 2012-10-17 12:51 - 00168664 _____ () C:\Program Files (x86)\ASUS\Splendid\ColorUService.exe 2012-11-13 03:30 - 2012-10-14 23:09 - 00094208 _____ () C:\Windows\system32\IccLibDll_x64.dll 2012-10-17 12:51 - 2012-10-17 12:51 - 00011776 _____ () C:\Program Files (x86)\ASUS\Splendid\GLCDdll.dll 2012-12-28 11:45 - 2012-06-24 21:41 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-4053647124-3796825272-3454316862-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\owner\Pictures\Protest\durrutifaiwallpaper.jpg DNS Servers: 192.168.1.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) HKU\S-1-5-21-4053647124-3796825272-3454316862-1001\...\StartupApproved\Run: => "Skype" HKU\S-1-5-21-4053647124-3796825272-3454316862-1001\...\StartupApproved\Run: => "Spotify" HKU\S-1-5-21-4053647124-3796825272-3454316862-1001\...\StartupApproved\Run: => "Spotify Web Helper" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [{EA4FF0B3-8537-4EBF-9D03-A25C9F89A4C0}] => (Allow) C:\Program Files\Intel Corporation\Intel WiDi\WiDiApp.exe FirewallRules: [{A8D22C49-A55D-4170-9E83-8A1FDD2D0A74}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD Cinema\PowerDVDCinema10.exe FirewallRules: [{49B970C5-5095-41D0-A9A1-5C8AD8FF0D47}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD10.EXE FirewallRules: [{0213E8B1-EC43-4D15-80C2-68389453A0A7}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{6703A77F-EDD0-49F8-8948-0ACC40FDC5DF}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [TCP Query User{A2A5413E-683C-4BEC-9652-D91B9AFECB16}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe FirewallRules: [{C19A86A6-9D9B-4957-88A6-7B348DD3221E}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe FirewallRules: [TCP Query User{2DFC80DC-7CA4-4C24-A7B1-A5A181A0B925}C:\users\owner\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\owner\appdata\roaming\spotify\spotify.exe FirewallRules: [UDP Query User{85CBA462-D9E4-4977-BF08-8FC82F02AAC9}C:\users\owner\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\owner\appdata\roaming\spotify\spotify.exe FirewallRules: [{B5CA1395-3768-4172-82F2-17BD5718280A}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe FirewallRules: [{87D572C1-9F18-4C7D-99FC-FCD709AF096A}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe FirewallRules: [{9F9F5FFB-4D7E-40F6-BC8D-5C83984CF2E1}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe FirewallRules: [{8D2886F6-4005-44C9-B32C-FCD4EF6235FA}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe FirewallRules: [TCP Query User{47857BA7-107E-4C27-A80E-32C9D7D07D00}C:\program files (x86)\hi-rez studios\hirezgames\smite\binaries\win32\smite.exe] => (Allow) C:\program files (x86)\hi-rez studios\hirezgames\smite\binaries\win32\smite.exe FirewallRules: [UDP Query User{EA044A73-679F-4A8F-A8C2-0B356933FC43}C:\program files (x86)\hi-rez studios\hirezgames\smite\binaries\win32\smite.exe] => (Allow) C:\program files (x86)\hi-rez studios\hirezgames\smite\binaries\win32\smite.exe FirewallRules: [{66810C25-19C6-48A2-B2B6-22A8277A1C3B}] => (Allow) C:\Users\owner\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{01F3C9E4-02E8-4A41-965E-17877B247B85}] => (Allow) C:\Users\owner\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [TCP Query User{D0B1E449-5069-4A9E-A522-C4A57588A2DC}C:\program files (x86)\rocksteady studios\batman arkham asylum - game of the year edition\binaries\shippingpc-bmgame.exe] => (Allow) C:\program files (x86)\rocksteady studios\batman arkham asylum - game of the year edition\binaries\shippingpc-bmgame.exe FirewallRules: [UDP Query User{E5C10345-10BB-405B-A76E-7BF0ABA77015}C:\program files (x86)\rocksteady studios\batman arkham asylum - game of the year edition\binaries\shippingpc-bmgame.exe] => (Allow) C:\program files (x86)\rocksteady studios\batman arkham asylum - game of the year edition\binaries\shippingpc-bmgame.exe FirewallRules: [{13038F5B-16C7-4B63-86EF-F83935358F33}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\outlook.exe FirewallRules: [{F785BCB7-1DDC-4C98-B30D-0126BC9757E2}] => (Allow) C:\Users\owner\AppData\Local\Microsoft\OneDrive\OneDrive.exe FirewallRules: [{AB0F478A-8DCA-4DE8-8C6A-A069BAF65BBA}] => (Allow) C:\Users\owner\Desktop\Games\BatmanArkhamCity\Binaries\Win32\BatmanAC.exe FirewallRules: [TCP Query User{C57AE126-E45C-412D-9ECB-F7C9298C23A0}C:\users\owner\desktop\games\batmanarkhamcity\binaries\win32\batmanac_o.exe] => (Allow) C:\users\owner\desktop\games\batmanarkhamcity\binaries\win32\batmanac_o.exe FirewallRules: [UDP Query User{F65286C6-AE46-44AA-9D0E-DC3B6DCE369D}C:\users\owner\desktop\games\batmanarkhamcity\binaries\win32\batmanac_o.exe] => (Allow) C:\users\owner\desktop\games\batmanarkhamcity\binaries\win32\batmanac_o.exe FirewallRules: [{96CE8779-A30F-451D-B162-7BCDBE2BA07B}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{91BB544A-A87F-4222-A8BB-3F8D5C75992E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{C4A1FCC3-A441-4927-A906-3B81DC904353}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (11/24/2015 06:46:38 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY) Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code. Error: (11/24/2015 06:46:38 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY) Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section. Error: (11/24/2015 06:31:40 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY) Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code. Error: (11/24/2015 06:31:40 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY) Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section. Error: (11/24/2015 06:19:10 PM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: ) Description: Subscription licensing service failed: -1073415161 Error: (11/24/2015 07:59:40 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY) Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code. Error: (11/24/2015 07:59:40 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY) Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section. Error: (11/24/2015 01:20:45 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY) Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code. Error: (11/24/2015 01:20:45 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY) Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section. Error: (11/23/2015 05:18:46 PM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: ) Description: Subscription licensing service failed: -1073415161 System errors: ============= Error: (11/24/2015 06:39:50 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The Windows Search service failed to start due to the following error: %%1069 Error: (11/24/2015 06:39:50 PM) (Source: Service Control Manager) (EventID: 7038) (User: ) Description: The WSearch service was unable to log on as NT AUTHORITY\SYSTEM with the currently configured password due to the following error: %%50 To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC). Error: (11/24/2015 06:39:45 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY) Description: WLAN Extensibility Module has stopped unexpectedly. Module Path: C:\WINDOWS\System32\IWMSSvc.dll Error: (11/24/2015 06:39:45 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY) Description: WLAN Extensibility Module has stopped unexpectedly. Module Path: C:\WINDOWS\System32\IWMSSvc.dll Error: (11/24/2015 06:39:43 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY) Description: WLAN Extensibility Module has stopped unexpectedly. Module Path: C:\WINDOWS\System32\IWMSSvc.dll Error: (11/24/2015 06:39:21 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The Intel(R) Management and Security Application User Notification Service service terminated unexpectedly. It has done this 1 time(s). Error: (11/24/2015 06:39:21 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The Intel(R) Centrino(R) Wireless Bluetooth(R) + High Speed Security Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service. Error: (11/24/2015 06:39:21 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The Intel® Centrino® Wireless Bluetooth® + High Speed Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. Error: (11/24/2015 06:39:21 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The Disc Soft Lite Bus Service service terminated unexpectedly. It has done this 1 time(s). Error: (11/24/2015 06:39:21 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The Bluetooth OBEX Service service terminated unexpectedly. It has done this 1 time(s). ==================== Memory info =========================== Processor: Intel(R) Core(TM) i5-3230M CPU @ 2.60GHz Percentage of memory in use: 33% Total physical RAM: 6033.77 MB Available physical RAM: 4042.12 MB Total Virtual: 12177.77 MB Available Virtual: 10125.1 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:676.99 GB) (Free:286.15 GB) NTFS ==>[system with boot components (obtained from drive)] Drive g: (BACGOTY) (CDROM) (Total:18.16 GB) (Free:0 GB) CDFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 698.6 GB) (Disk ID: A3362226) Partition: GPT. ==================== End of Addition.txt ============================ [/QUOTE]
Insert quotes…
Verification
Post reply
Top