Additional scan result of Farbar Recovery Scan Tool (x64) Version: 31-08-2016
Ran by home (05-09-2016 15:51:25)
Running from d:\Users\home\Desktop
Windows 7 Professional Service Pack 1 (X64) (2015-11-24 19:28:37)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-2398489320-3750471686-3902459509-500 - Administrator - Disabled)
ASPNET (S-1-5-21-2398489320-3750471686-3902459509-1004 - Limited - Enabled)
Guest (S-1-5-21-2398489320-3750471686-3902459509-501 - Limited - Enabled)
home (S-1-5-21-2398489320-3750471686-3902459509-1000 - Administrator - Enabled) => C:\Users\home
HomeGroupUser$ (S-1-5-21-2398489320-3750471686-3902459509-1002 - Limited - Enabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.017.20053 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 22.0.0.153 - Adobe Systems Incorporated)
Adobe Flash Player 22 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 22.0.0.210 - Adobe Systems Incorporated)
Apple Application Support‏ (64 סיביות) (HKLM\...\{A6B0442B-E159-444B-B49D-6B9AC531EAE3}) (Version: 4.3.2 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{2E4AF2A6-50EA-4260-9BA4-5E582D11879A}) (Version: 9.3.0.15 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.)
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
CrystalDiskInfo 7.0.3 (HKLM-x32\...\CrystalDiskInfo_is1) (Version: 7.0.3 - Crystal Dew World)
DC Universe Online (HKU\S-1-5-21-2398489320-3750471686-3902459509-1000\...\DGC-DC Universe Online) (Version: 1.0.3.192 - Daybreak Game Company)
Dragon's Prophet (EU) (HKLM\...\Steam App 259020) (Version:  - Runewaker)
Energy Management (HKLM-x32\...\{0CE226F3-EB27-4ECD-BBF5-F088716779FD}) (Version: 5.4.0.8 - Lenovo)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 52.0.2743.116 - Google Inc.)
Google Update Helper (x32 Version: 1.3.31.5 - Google Inc.) Hidden
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.14.4156 - Intel Corporation)
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 3.0.5.69 - Intel Corporation)
iTunes (HKLM\...\{955524E7-79EB-4CA9-BA4D-FD2DF587651B}) (Version: 12.4.3.1 - Apple Inc.)
Java 8 Update 101 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180101F0}) (Version: 8.0.1010.13 - Oracle Corporation)
Kingdom Rush (HKLM-x32\...\Steam App 246420) (Version:  - Ironhide Game Studio)
Kingdom Rush Frontiers (HKLM\...\Steam App 458710) (Version:  - )
League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games)
League of Legends (x32 Version: 3.0.1 - Riot Games) Hidden
Lenovo EasyCamera (HKLM-x32\...\{E399A5B3-ED53-4DEA-AF04-8011E1EB1EAC}) (Version: 6.3.9600.11076 - Realtek Semiconductor Corp.)
Lenovo Smart Fingerprint (HKLM-x32\...\{90C700B4-BC7E-4628-867C-FC8622F0DAD9}_is1) (Version: 1.0.0.28 - Lenovo)
Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Microsoft .NET Framework 1.1 (HKLM-x32\...\{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}) (Version: 1.1.4322 - Microsoft)
Microsoft .NET Framework 4.6.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft .NET Framework 4.6.1 ‏(עברית) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1037) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM\...\Office14.PROPLUS) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50428.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Neverwinter (HKLM\...\Steam App 109600) (Version:  - Cryptic Studios)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.3.9600.39064 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.92.115.2015 - Realtek)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{A3364707-2F53-4C83-8F68-C9877A9080C7}) (Version:  - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (Version:  - Microsoft) Hidden
Skype™ 7.25 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.25.106 - Skype Technologies S.A.)
SpyHunter 4 (HKLM-x32\...\SpyHunter) (Version: 4.23.2.4686 - Enigma Software Group, LLC)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 18.1.26.19 - Synaptics Incorporated)
Synaptics WBF DDK 5011 (HKLM\...\{4D70781C-36A9-4335-9568-565C6F61B5EB}) (Version: 4.5.268.0 - )
Synaptics WBF DDK 5011 (HKLM\...\{E62CE691-6F3D-477B-9B0C-6AF6EE320694}) (Version: 4.5.268.0 - Synaptics)
Transformice (HKLM-x32\...\Steam App 335240) (Version:  - Atelier 801)
WinRAR 4.20 (64-bit) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
חבילת התקני Windows. - Lenovo (ACPIVPC) System  (10/19/2009 5.4.0.1) (HKLM\...\0A4175B489A1B4A6E07E11B063A6263480C51D71) (Version: 10/19/2009 5.4.0.1 - Lenovo)
ערכת שפה של Microsoft Visual Studio 2010 Tools for Office Runtime (x64)‎ - ‏HEB (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - HEB) (Version: 10.0.50903 - Microsoft Corporation)
תוכנת Intel® Chipset Device  (x32 Version: 10.0.22 - Intel(R) Corporation) Hidden
תוכנת Intel® PROSet/Wireless (HKLM-x32\...\{21fed2aa-c2b4-4d9e-bd4b-072866d210b7}) (Version: 17.14.1 - Intel Corporation)
תמיכה ביישומים של Apple‏ (32 סיביות) (HKLM-x32\...\{D4B07658-F443-4445-A261-E643996E139D}) (Version: 4.3.2 - Apple Inc.)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {043260D2-91CE-4349-913D-EA2F9EBE23BB} - System32\Tasks\{A256F429-4300-4D55-A3FB-6BDA454BB8D8} => pcalua.exe -a "C:\Program Files\SQDT\SuccubusQuest短編\Setup.exe" -d "C:\Program Files\SQDT\SuccubusQuest短編"
Task: {0B5ED67E-44CB-409E-856C-DA98650457EF} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-11-24] (Google Inc.)
Task: {491B5F9E-3559-43A8-AE62-1DCD92838002} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-11-24] (Google Inc.)
Task: {4ECDAFC2-E2A7-4408-A063-BBF7F17DFB02} - System32\Tasks\Games\UpdateCheck_S-1-5-21-2398489320-3750471686-3902459509-1000
Task: {6082C735-F1C3-4B73-A40A-3397C6C55253} - System32\Tasks\{4145E1FA-EA92-4BC5-A782-F735C3C799B5} => pcalua.exe -a "E:\Worms World Party\Worms World Party - (Www.ApunKaGames.Net)\Game\RegSetup.exe" -d "E:\Worms World Party\Worms World Party - (Www.ApunKaGames.Net)\Game"
Task: {7203D319-7EAB-41DB-B1F0-323C1D77CF76} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-06-25] (Adobe Systems Incorporated)
Task: {B809A442-F07F-4039-B03D-5F6F09682462} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.)
Task: {EB02381F-D652-4B1C-894A-712498C62C51} - \Microsoft\Windows\MUI\LPRemove -> No File <==== ATTENTION
Task: {F0B2761D-68EC-4FE5-B251-3083D072FCE0} - System32\Tasks\SpyHunter4Startup => C:\Program Files\Enigma Software Group\SpyHunter\Spyhunter4.exe

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

ShortcutWithArgument: C:\Users\home\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\69639df789022856\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory="Profile 1"

==================== Loaded Modules (Whitelisted) ==============

2016-03-18 22:56 - 2016-03-18 22:56 - 00092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2016-07-05 15:23 - 2016-07-05 15:23 - 01354040 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2013-09-05 01:17 - 2013-09-05 01:17 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2015-11-24 19:00 - 2009-07-15 16:55 - 00054088 _____ () C:\Program Files (x86)\Lenovo\Energy Management\kbdhook.dll
2015-11-24 19:00 - 2009-07-15 16:55 - 00054088 _____ () C:\Program Files (x86)\Lenovo\Energy Management\HookLib.dll
2015-11-24 18:29 - 2015-03-06 16:59 - 00391784 _____ () C:\Windows\system32\igfxTray.exe
2014-01-21 17:54 - 2016-01-16 22:36 - 01294336 _____ () C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe
2016-08-25 12:31 - 2016-08-25 12:31 - 02409464 _____ () C:\Riot Games\League of Legends\RADS\projects\lol_launcher\releases\0.0.1.26\deploy\LoLLauncher.exe
2016-08-25 12:32 - 2016-08-25 12:32 - 04602872 _____ () C:\Riot Games\League of Legends\RADS\projects\lol_patcher\releases\0.0.0.66\deploy\LoLPatcher.exe
2016-01-16 23:06 - 2016-01-16 23:06 - 00074752 _____ () C:\Riot Games\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.214\deploy\LolClient.exe
2013-09-05 01:14 - 2013-09-05 01:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2016-08-25 12:32 - 2016-08-25 12:32 - 00449528 _____ () C:\Riot Games\League of Legends\RADS\projects\lol_patcher\releases\0.0.0.66\deploy\RiotLauncher.dll
2016-08-09 00:51 - 2016-08-03 03:24 - 01771336 _____ () C:\Program Files (x86)\Google\Chrome\Application\52.0.2743.116\libglesv2.dll
2016-08-09 00:51 - 2016-08-03 03:23 - 00094024 _____ () C:\Program Files (x86)\Google\Chrome\Application\52.0.2743.116\libegl.dll
2016-04-26 21:30 - 2016-04-26 21:30 - 04887216 _____ () C:\Riot Games\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.214\deploy\Adobe AIR\Versions\1.0\Resources\WebKit.dll
2016-04-26 21:30 - 2016-04-26 21:30 - 19397808 _____ () C:\Riot Games\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.214\deploy\Adobe AIR\Versions\1.0\Resources\NPSWF32.dll
2015-12-07 11:25 - 2016-08-09 02:27 - 00785920 _____ () C:\Program Files (x86)\Steam\SDL2.dll
2015-12-07 11:25 - 2015-07-02 01:06 - 04962816 _____ () C:\Program Files (x86)\Steam\v8.dll
2015-12-07 11:25 - 2015-07-02 01:06 - 01556992 _____ () C:\Program Files (x86)\Steam\icui18n.dll
2015-12-07 11:25 - 2015-07-02 01:06 - 01187840 _____ () C:\Program Files (x86)\Steam\icuuc.dll
2015-12-07 11:25 - 2016-08-23 22:33 - 02321184 _____ () C:\Program Files (x86)\Steam\video.dll
2015-12-07 11:25 - 2016-01-27 10:49 - 02549760 _____ () C:\Program Files (x86)\Steam\libavcodec-56.dll
2015-12-07 11:25 - 2016-01-27 10:49 - 00442880 _____ () C:\Program Files (x86)\Steam\libavutil-54.dll
2015-12-07 11:25 - 2016-01-27 10:49 - 00491008 _____ () C:\Program Files (x86)\Steam\libavformat-56.dll
2015-12-07 11:25 - 2016-01-27 10:49 - 00332800 _____ () C:\Program Files (x86)\Steam\libavresample-2.dll
2015-12-07 11:25 - 2016-01-27 10:49 - 00485888 _____ () C:\Program Files (x86)\Steam\libswscale-3.dll
2015-12-07 11:25 - 2016-08-23 22:33 - 00835360 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL
2016-04-04 21:46 - 2016-07-05 01:17 - 00266560 _____ () C:\Program Files (x86)\Steam\openvr_api.dll
2015-12-07 11:25 - 2016-08-04 23:56 - 49825056 _____ () C:\Program Files (x86)\Steam\bin\libcef.dll
2016-06-28 22:46 - 2016-08-30 13:44 - 295131171 _____ () C:\Program Files (x86)\Steam\steamapps\common\Kingdom Rush Frontiers\Kingdom Rush Frontiers.exe
2016-06-28 22:46 - 2016-07-06 23:35 - 02379776 _____ () C:\Program Files (x86)\Steam\steamapps\common\Kingdom Rush Frontiers\love.dll
2016-06-28 22:46 - 2016-07-06 23:35 - 00349184 _____ () C:\Program Files (x86)\Steam\steamapps\common\Kingdom Rush Frontiers\lua51.dll
2016-06-28 22:46 - 2016-07-06 23:35 - 00390656 _____ () C:\Program Files (x86)\Steam\steamapps\common\Kingdom Rush Frontiers\OpenAL32.dll
2016-06-28 22:46 - 2016-07-06 23:35 - 00812032 _____ () C:\Program Files (x86)\Steam\steamapps\common\Kingdom Rush Frontiers\SDL2.dll
2016-06-28 22:53 - 2016-07-06 23:35 - 00139776 _____ () C:\Program Files (x86)\Steam\steamapps\common\Kingdom Rush Frontiers\mpg123.dll

==================== Alternate Data Streams (Whitelisted) =========

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 05:34 - 2009-06-11 00:00 - 00000824 ____N C:\Windows\system32\Drivers\etc\hosts


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-2398489320-3750471686-3902459509-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\home\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)


==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [{C4011843-F040-4305-943D-BC8B937594F7}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
FirewallRules: [{62D0B159-2E0E-4E94-8452-AC7BEEADF46D}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{A6620C64-FC75-49E9-A49A-8E5604B703E8}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{6892B282-0B8C-45F6-B2D0-E0C0B6D80B0F}] => (Allow) E:\ETCETC\Steam\Steam.exe
FirewallRules: [{5DC20B3C-F434-426C-88F1-29F57A28D3AA}] => (Allow) E:\ETCETC\Steam\Steam.exe
FirewallRules: [{03F667CD-58DF-4B04-B108-BEEE26583038}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{D7F7E4E7-C441-4299-8A8E-D223D9D95E54}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{DCB85239-8BAE-4C53-A740-B33F77A63F30}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Kingdom Rush\Kingdom Rush.exe
FirewallRules: [{F80D8ED9-856E-4E0A-BDFF-7A260FD82F58}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Kingdom Rush\Kingdom Rush.exe
FirewallRules: [{C9C94FA0-7A79-4A6D-9224-2EA720ED807E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Transformice\Transformice.exe
FirewallRules: [{612B3BD9-0DEA-4CEB-8C28-2FD1E81CFCC3}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Transformice\Transformice.exe
FirewallRules: [TCP Query User{7D2807C6-82D0-4804-8DA1-11267CFDBC5A}C:\program files (x86)\team17\worms armageddon\wa.exe] => (Allow) C:\program files (x86)\team17\worms armageddon\wa.exe
FirewallRules: [UDP Query User{99AF0CDE-3918-4C2D-939B-F93AC64ABC65}C:\program files (x86)\team17\worms armageddon\wa.exe] => (Allow) C:\program files (x86)\team17\worms armageddon\wa.exe
FirewallRules: [{529A739E-13F5-45DA-9D38-2662F0640E95}] => (Block) C:\program files (x86)\team17\worms armageddon\wa.exe
FirewallRules: [{75F13578-CDB3-4F90-94EE-AB99A39BE0EC}] => (Block) C:\program files (x86)\team17\worms armageddon\wa.exe
FirewallRules: [{A0614FC9-746B-42E4-9C00-78CC76BE7651}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{511B5817-8809-4CA5-ABA4-9601E1C47153}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Cryptic Studios\Neverwinter.exe
FirewallRules: [{8990CCCB-D255-431C-BA4C-29D806C9870F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Cryptic Studios\Neverwinter.exe
FirewallRules: [TCP Query User{CB02A1E2-5B26-4954-99D5-A4CFF7A241A7}C:\program files (x86)\steam\steamapps\common\dungeons and dragons online\dndclient.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\dungeons and dragons online\dndclient.exe
FirewallRules: [UDP Query User{C8C2B2C5-195D-43F1-BE81-8213C9D9A33F}C:\program files (x86)\steam\steamapps\common\dungeons and dragons online\dndclient.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\dungeons and dragons online\dndclient.exe
FirewallRules: [TCP Query User{0059F281-1D67-4B4C-9C53-09CD46F9A639}C:\program files (x86)\steam\steamapps\common\cryptic studios\neverwinter\live\gameclient.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\cryptic studios\neverwinter\live\gameclient.exe
FirewallRules: [UDP Query User{01A831ED-0A1E-4D60-8C69-4A182B5804E4}C:\program files (x86)\steam\steamapps\common\cryptic studios\neverwinter\live\gameclient.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\cryptic studios\neverwinter\live\gameclient.exe
FirewallRules: [{91264CD3-BC1E-4389-BC12-E208D256C339}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Dragon's Prophet (EU)\dplogin.exe
FirewallRules: [{AE18B73B-7C69-4C9D-A7A6-2F3A70E08508}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Dragon's Prophet (EU)\dplogin.exe
FirewallRules: [{BF054CA5-3442-4CB8-A5DF-163A4387F712}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Dragon's Prophet (EU)\dp_x64.exe
FirewallRules: [{8ABDA87C-BD30-44D9-91C1-4B1A989B61ED}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Dragon's Prophet (EU)\launcher.exe
FirewallRules: [{BB67EA3B-0919-4361-83ED-496A31D28238}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Dragon's Prophet (EU)\dp_x64.exe
FirewallRules: [{4DBD9AA3-F9DD-4FBC-B82B-6124E48F1886}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Dragon's Prophet (EU)\launcher.exe
FirewallRules: [{725B23E3-4165-4DB2-8279-E2FA8248DE0E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Dragon's Prophet (EU)\dp_x86.exe
FirewallRules: [{7B4B2F82-F3F6-43FC-9BFC-FEA93D0ECC93}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Dragon's Prophet (EU)\dp_x86.exe
FirewallRules: [TCP Query User{B078804F-DEB0-4FB7-B671-15F9FA54EC7E}E:\star trek online_en\star trek online\live\gameclient.exe] => (Allow) E:\star trek online_en\star trek online\live\gameclient.exe
FirewallRules: [UDP Query User{449D1417-78F2-4F2B-9B5D-58EC885BE77C}E:\star trek online_en\star trek online\live\gameclient.exe] => (Allow) E:\star trek online_en\star trek online\live\gameclient.exe
FirewallRules: [{A7F492AA-896B-4E7C-8CDC-36F58AB53974}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{2673A0B7-E8B9-4883-9CEF-426C8EBC92D5}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{51811F99-02BF-40DF-A142-F41A7CB3E578}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{EA6881EA-F6EE-42EF-AE0E-FAA18333B64D}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{ADBD6178-E518-44B1-9749-3EDC0A36CF5F}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{66D2B16B-ADA9-4CF7-A211-E95196639ABB}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Kingdom Rush Frontiers\Kingdom Rush Frontiers.exe
FirewallRules: [{008085DE-1370-41B4-A4A0-5298570A9B20}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Kingdom Rush Frontiers\Kingdom Rush Frontiers.exe
FirewallRules: [{AADF6B29-8F49-4B9C-89F7-85104F05A345}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{93D565CC-3179-4B6F-8DC8-6083480E16EE}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{F828C3EF-7C8C-4F4C-B94C-B7535D50BA70}] => (Allow) C:\Program Files (x86)\Popcorn Time\Updater.exe
FirewallRules: [{2E146BAB-68B8-46CB-80B4-B051430F9519}] => (Allow) C:\Program Files (x86)\Popcorn Time\Updater.exe
FirewallRules: [{D1B10D45-0824-49C5-8D04-10E3B5DACA97}] => (Allow) C:\Program Files (x86)\Popcorn Time\PopcornTimeDesktop.exe
FirewallRules: [{DCFEEC00-9690-4962-A11B-9104C3C951EC}] => (Allow) C:\Program Files (x86)\Popcorn Time\PopcornTimeDesktop.exe
FirewallRules: [{42047439-E593-48D3-B3B1-000B3001173C}] => (Allow) C:\Program Files (x86)\Popcorn Time\chromecast\node.exe
FirewallRules: [{03EFD8EB-EAD7-4F2C-86C0-09D79808420E}] => (Allow) C:\Program Files (x86)\Popcorn Time\chromecast\node.exe
FirewallRules: [{4F287AF2-CB7C-4016-8AAA-436F0E5AC33B}] => (Allow) C:\Program Files\Vuze\Azureus.exe
FirewallRules: [{7165731B-548C-4BE2-99A5-B52F3B3D938A}] => (Allow) C:\Program Files\Vuze\Azureus.exe
FirewallRules: [TCP Query User{B2426BBD-9F2A-4A78-A255-C70A9BC72AAD}C:\program files\vuze\azureus.exe] => (Block) C:\program files\vuze\azureus.exe
FirewallRules: [UDP Query User{78E682C8-88A7-4404-81E1-7FDDBF1C2312}C:\program files\vuze\azureus.exe] => (Block) C:\program files\vuze\azureus.exe

==================== Restore Points =========================

30-08-2016 17:56:10 Removed Minecraft
31-08-2016 19:11:32 Windows Update
01-09-2016 08:54:59 Windows Update
04-09-2016 11:01:00 Removed Breeding Season
04-09-2016 23:58:08 Windows Update
05-09-2016 15:40:15 Removed Avira Browser Safety
05-09-2016 15:42:12 Removed Avira Software Updater

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (09/05/2016 03:41:56 PM) (Source: MsiInstaller) (EventID: 11722) (User: home-PC)
Description: Product: Avira Browser Safety -- Error 1722. There is a problem with this Windows Installer package. A program run as part of the setup did not finish as expected. Contact your support personnel or package vendor.  Action TrackMSIFailed, location: C:\Windows\Installer\MSID7EF.tmp, command: "MSI Failed"

Error: (09/05/2016 03:41:53 PM) (Source: MsiInstaller) (EventID: 11722) (User: home-PC)
Description: Product: Avira Browser Safety -- Error 1722. There is a problem with this Windows Installer package. A program run as part of the setup did not finish as expected. Contact your support personnel or package vendor.  Action TrackMSIUninstalled, location: C:\Windows\Installer\MSIAD27.tmp, command: "MSI Uninstalled"

Error: (09/05/2016 03:16:58 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 10468

Error: (09/05/2016 03:16:58 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 10468

Error: (09/05/2016 03:16:58 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (09/05/2016 11:18:53 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Error: (09/04/2016 11:29:25 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: rads_user_kernel.exe, version: 0.0.0.0, time stamp: 0x4e65c1ac
Faulting module name: rads_user_kernel.exe, version: 0.0.0.0, time stamp: 0x4e65c1ac
Exception code: 0xc0000005
Fault offset: 0x000b8554
Faulting process id: 0xc40
Faulting application start time: 0x01d206eb052b05f2
Faulting application path: C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe
Faulting module path: C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe
Report Id: 44ba3453-72de-11e6-9baa-b46d83f882f6

Error: (09/04/2016 11:29:01 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Error: (09/04/2016 10:51:52 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Error: (09/04/2016 08:53:11 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.


System errors:
=============
Error: (09/05/2016 03:39:30 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Windows Modules Installer service terminated with the following error: 
Access is denied.

Error: (09/05/2016 11:21:15 AM) (Source: Microsoft-Windows-WHEA-Logger) (EventID: 18) (User: NT AUTHORITY)
Description: A fatal hardware error has occurred.

Reported by component: Processor Core
Error Source: 3
Error Type: 9
Processor ID: 0

The details view of this entry contains further information.

Error: (09/05/2016 11:20:36 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Windows Presentation Foundation Font Cache 3.0.0.0 service failed to start due to the following error: 
The service did not respond to the start or control request in a timely fashion.

Error: (09/05/2016 11:20:36 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Windows Presentation Foundation Font Cache 3.0.0.0 service to connect.

Error: (09/05/2016 11:20:01 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load: 
cdrom

Error: (09/04/2016 11:29:27 AM) (Source: Microsoft-Windows-WHEA-Logger) (EventID: 18) (User: NT AUTHORITY)
Description: A fatal hardware error has occurred.

Reported by component: Processor Core
Error Source: 3
Error Type: 9
Processor ID: 0

The details view of this entry contains further information.

Error: (09/04/2016 11:29:21 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load: 
cdrom

Error: (09/04/2016 11:27:43 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has stopped unexpectedly.

Module Path: C:\Windows\System32\IWMSSvc.dll

Error: (09/04/2016 11:27:43 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has stopped unexpectedly.

Module Path: C:\Windows\System32\IWMSSvc.dll

Error: (09/04/2016 11:27:43 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has stopped unexpectedly.

Module Path: C:\Windows\System32\IWMSSvc.dll


CodeIntegrity:
===================================
  Date: 2015-11-24 19:28:32.282
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.

  Date: 2015-11-24 19:23:36.693
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.

  Date: 2015-11-24 19:14:39.241
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.

  Date: 2015-11-24 19:06:37.616
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.

  Date: 2015-11-24 17:56:49.107
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.

  Date: 2015-11-24 17:27:15.691
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.

  Date: 2015-11-24 17:08:54.144
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.


==================== Memory info =========================== 

Processor: Intel(R) Core(TM) i3-4030U CPU @ 1.90GHz
Percentage of memory in use: 69%
Total physical RAM: 4020.94 MB
Available physical RAM: 1236.82 MB
Total Virtual: 8040.07 MB
Available Virtual: 4736.73 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:156.25 GB) (Free:73.07 GB) NTFS
Drive d: (אמצעי אחסון חדש) (Fixed) (Total:308.53 GB) (Free:306.43 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: D9FA2484)
Partition 1: (Active) - (Size=1000 MB) - (Type=0B)
Partition 2: (Not Active) - (Size=156.3 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=308.5 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================