Additional scan result of Farbar Recovery Scan Tool (x64) Version: 08-07-2020 01
Ran by Johnny (19-07-2020 15:57:01)
Running from C:\Users\Johnny\Desktop
Windows 7 Ultimate N Service Pack 1 (X64) (2016-10-12 17:22:51)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-2350607292-2742822079-1077346085-500 - Administrator - Disabled)
Guest (S-1-5-21-2350607292-2742822079-1077346085-501 - Limited - Disabled)
Johnny (S-1-5-21-2350607292-2742822079-1077346085-1000 - Administrator - Enabled) => C:\Users\Johnny
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Avira Antivirus (Enabled - Up to date) {8EAC8D5C-B3AA-95AA-3DF1-2845CDD09CBE}
AS: Avira Antivirus (Enabled - Up to date) {35CD6CB8-9590-9A24-0741-1337B657D603}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
7-Zip 16.03 (x64) (HKLM\...\7-Zip) (Version: 16.03 - Igor Pavlov)
Adobe Reader 9.1 (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-A91000000001}) (Version: 9.1.0 - Adobe Systems Incorporated)
Apple Application Support (HKLM-x32\...\{EE6097DD-05F4-4178-9719-D3170BF098E8}) (Version: 1.4.1 - Apple Inc.)
ARP2600 V2 2.0 (HKLM-x32\...\ARP2600 V2_is1) (Version: - Arturia)
Arturia Moog Modular V2 v1.0 (HKLM-x32\...\Arturia Moog Modular V2 v1.0) (Version: - )
Arturia Prophet V VSTi RTAS v1.2.1 (HKLM-x32\...\Arturia Prophet V VSTi RTAS_is1) (Version: - )
ASIO4ALL (HKLM-x32\...\ASIO4ALL) (Version: 2.10 - Michael Tippach)
Avira (HKLM-x32\...\{ca8bf656-4912-4f9e-904d-09fd450cf44a}) (Version: 1.2.147.35397 - Avira Operations GmbH & Co. KG)
Avira (HKLM-x32\...\{F45723FF-ED60-422B-AB16-538648BBCD02}) (Version: 1.2.147.35397 - Avira Operations GmbH & Co. KG) Hidden
Avira Antivirus (HKLM-x32\...\Avira Antivirus) (Version: 15.0.2007.1910 - Avira Operations GmbH & Co. KG)
Avira Software Updater (HKLM-x32\...\{BBD09B2A-FCDB-4CDE-8614-8C608EA68E94}) (Version: 2.0.6.34011 - Avira Operations GmbH & Co. KG)
Backup and Sync from Google (HKLM\...\{01D33BEA-673C-439C-A7C7-DE5B236DB842}) (Version: 3.50.3166.0017 - Google, Inc.)
CCleaner (HKLM\...\CCleaner) (Version: 5.02 - Piriform)
ConvertHelper 3.2 (HKLM\...\{27CC6AB1-E72B-4179-AF1A-EAE507EBAF52}}_is1) (Version: - DownloadHelper)
CPUID CPU-Z MSI 1.76 (HKLM\...\CPUID CPU-Z MSI_is1) (Version: 1.76 - CPUID, Inc.)
CS-80 V3 (HKLM\...\CS-80 V3_is1) (Version: 3.3.0.1391 - Arturia & Team V.R)
D-Fend Reloaded 1.4.4 (Odinstalovat) (HKLM-x32\...\D-Fend Reloaded) (Version: 1.4.4 - Alexander Herzog)
eLicenser Control (HKLM-x32\...\eLicenser Control) (Version: - Steinberg Media Technologies GmbH)
FL Studio 10 (HKLM-x32\...\FL Studio 10) (Version: - Image-Line)
GForce - Oddity (HKLM-x32\...\Oddity) (Version: - )
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.451 - Google LLC) Hidden
HiSuite (HKLM-x32\...\Hi Suite) (Version: 1.0 - Huawei Technologies Co.,Ltd)
HP Deskjet 3520 series Basic Device Software (HKLM\...\{E80963EC-EED7-411A-8AC0-149EC57FB0F9}) (Version: 27.0.847.0 - Hewlett-Packard Co.)
HP Deskjet 3520 series Help (HKLM-x32\...\{C13E1F46-84FE-4D3B-8581-0F2F624C7EEC}) (Version: 27.0.0 - Hewlett Packard)
HP Deskjet 3520 series Product Improvement Study (HKLM\...\{177F4FEE-E119-4AB7-9B32-ECF6A1D03719}) (Version: 27.0.847.0 - Hewlett-Packard Co.)
HP Deskjet 3520 series Setup Guide (HKLM-x32\...\{AEEDCEB7-00B8-4BE1-B492-AB04803D5F1E}) (Version: 27.0.0 - Hewlett Packard)
HP Update (HKLM-x32\...\{6F1C00D2-25C2-4CBA-8126-AE9A6E2E9CD5}) (Version: 5.003.003.001 - Hewlett-Packard)
IL Download Manager (HKLM-x32\...\IL Download Manager) (Version: - Image-Line)
Intel(R) Chipset Device Software (HKLM-x32\...\{c7f54569-0018-439c-809a-48046a4d4ebc}) (Version: 10.1.1.9 - Intel(R) Corporation) Hidden
Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.0.6.1194 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 21.20.16.4534 - Intel Corporation)
Intel(R) Update Manager (HKLM-x32\...\{7224B7CE-196C-4E2A-A1AE-1D7BF259FD36}) (Version: 3.4.1942 - Intel Corporation)
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 4.0.0.36 - Intel Corporation)
Jupiter-8V2 2.0 (HKLM-x32\...\Jupiter-8V2_is1) (Version: - Arturia)
M30 Reverb (HKLM-x32\...\M30 Reverb) (Version: 1.0.0.1 - TC Electronic)
McAfee True Key (HKLM\...\TrueKey) (Version: 5.3.138.1 - McAfee, LLC)
Microsoft .NET Framework 4.7 (čeština) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1029) (Version: 4.7.02053 - Microsoft Corporation)
Microsoft .NET Framework 4.7 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.02053 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM\...\Office14.PROPLUSR) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23506 (HKLM-x32\...\{3ee5e5bb-b7cc-4556-8861-a00a82977d6c}) (Version: 14.0.23506.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Mozilla Firefox 78.0.2 (x64 cs) (HKLM\...\Mozilla Firefox 78.0.2 (x64 cs)) (Version: 78.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 68.4.2 - Mozilla)
Mozilla Thunderbird 68.10.0 (x86 cs) (HKLM-x32\...\Mozilla Thunderbird 68.10.0 (x86 cs)) (Version: 68.10.0 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
N.I Pro-53 v3.0-OxYGeN (HKLM-x32\...\N.I Pro-53 v3.0-OxYGeN) (Version: - )
Native Instruments FM7 (HKLM-x32\...\Native Instruments FM7) (Version: - )
Native Instruments FM8 (HKLM-x32\...\Native Instruments FM8) (Version: - )
Native Instruments Massive v1.0.1.008 VSTi DXi RTAS (HKLM-x32\...\Native Instruments Massive v1.0.1.008 VSTi DXi RTAS) (Version: - )
Picture Control Utility (HKLM-x32\...\{87441A59-5E64-4096-A170-14EFE67200C3}) (Version: 1.2.2 - Nikon)
PSD Codec by Ardfry Imaging, LLC (32 bit) (HKLM-x32\...\{345E25C8-EC20-45D5-A088-C5891FC603D4}) (Version: 1.0.15.0 - Ardfry Imaging, LLC) Hidden
PSD Codec by Ardfry Imaging, LLC (64 bit) (HKLM\...\{AD4E43FF-20E5-4E91-9B10-5BFAB7F66EE2}) (Version: 1.0.15.0 - Ardfry Imaging, LLC) Hidden
PSD CODEC Version 1.6.1.0 (HKLM\...\Ardfry PSD CODEC_is1) (Version: 1.6.1.0 - Ardfry Imaging, LLC)
QuickTime (HKLM-x32\...\{57752979-A1C9-4C02-856B-FBB27AC4E02C}) (Version: 7.69.80.9 - Apple Inc.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.97.1001.2015 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7730 - Realtek Semiconductor Corp.)
rgcAudio z3ta Plus v1.40 (HKLM-x32\...\rgcAudio z3ta Plus v1.40) (Version: - )
Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{A3364707-2F53-4C83-8F68-C9877A9080C7}) (Version: - Microsoft)
SES Driver (HKLM\...\{D8CC254C-C671-4664-9A38-FA368D1E2C97}) (Version: 1.0.0 - Western Digital)
SonicProjects OP-X PRO-II (HKLM\...\OP-X PRO-II_is1) (Version: 1.2.5 - Team V.R)
Total Commander (Remove or Repair) (HKLM-x32\...\Totalcmd) (Version: - )
TubeOhm ANTI-TRANSPIRANT/Stepper4free (HKLM-x32\...\TUBEOHM A-T and Stepper4free_is1) (Version: - )
VdhCoApp 1.3.0 (HKLM\...\weh-iss-net.downloadhelper.coapp_is1) (Version: - DownloadHelper)
ViewNX 2 (HKLM-x32\...\{DDD62492-32A7-412B-8AF1-2CF032AD42E3}) (Version: 2.1.2 - Nikon)
VLC media player (HKLM-x32\...\VLC media player) (Version: 3.0.1 - VideoLAN)
Waldorf PPG Wave 2.V v1.2 (HKLM-x32\...\Waldorf PPG Wave 2.V v1.2) (Version: - )
Windows Driver Package - Western Digital Technologies (WDC_SAM) WDC_SAM (01/19/2011 1.0.0009.0) (HKLM\...\4CA7CFBB29889F25ACB3DF6E3A42BAE29EB43B20) (Version: 01/19/2011 1.0.0009.0 - Western Digital Technologies)
Z3TA+ 2 (HKLM-x32\...\Z3TA+ 2_is1) (Version: 2.1 - Cakewalk Music Software)
Zip Motion Block Video codec (Remove Only) (HKLM-x32\...\ZMBV) (Version: - DOSBox Team)
==================== Custom CLSID (Whitelisted): ==============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
ShellExecuteHooks: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [6671064 2013-12-19] (Microsoft Corporation -> Microsoft Corporation)
ShellExecuteHooks-x32: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [4171480 2013-12-19] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files\Google\Drive\googledrivesync64.dll [2020-06-15] (Google LLC -> Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files\Google\Drive\googledrivesync64.dll [2020-06-15] (Google LLC -> Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files\Google\Drive\googledrivesync64.dll [2020-06-15] (Google LLC -> Google)
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-09-28] (Igor Pavlov) [File not signed]
ContextMenuHandlers1: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files\Google\Drive\contextmenu64.dll [2020-06-15] (Google LLC -> Google)
ContextMenuHandlers1: [Shell Extension for Malware scanning] -> {45AC2688-0253-4ED8-97DE-B5370FA7D48A} => C:\Program Files (x86)\Avira\Antivirus\shlext64.dll [2020-07-14] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-09-28] (Igor Pavlov) [File not signed]
ContextMenuHandlers4: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files\Google\Drive\contextmenu64.dll [2020-06-15] (Google LLC -> Google)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\Windows\system32\igfxDTCM.dll [2016-12-06] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-09-28] (Igor Pavlov) [File not signed]
ContextMenuHandlers6: [Shell Extension for Malware scanning] -> {45AC2688-0253-4ED8-97DE-B5370FA7D48A} => C:\Program Files (x86)\Avira\Antivirus\shlext64.dll [2020-07-14] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
==================== Codecs (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Drivers32: [VIDC.ZMBV] => C:\Windows\SysWOW64\zmbv.dll [94208 2010-04-09] () [File not signed]
HKLM\...\Drivers32: [msacm.vorbis] => C:\Windows\SysWOW64\vorbis.acm [1554944 2009-09-15] (HMS hxxp://hp.vector.co.jp/authors/VA012897/) [File not signed]
==================== Shortcuts & WMI ========================
(The entries could be listed to be restored or removed.)
Shortcut: C:\Users\Johnny\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Image-Line\FL Studio 10\Image-Line website.lnk -> hxxp://
www.image-line.com
Shortcut: C:\Users\Johnny\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Image-Line\FL Studio 10\Advanced\Diagnostic.lnk -> hxxp://
www.image-line.com/diagnosti
Shortcut: C:\Users\Johnny\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Image-Line\FL Studio 10\Additional\Download Deckadance.lnk -> hxxp://
www.deckadance.com
Shortcut: C:\Users\Johnny\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Image-Line\FL Studio 10\Additional\SynthMaker website.lnk -> hxxp://
www.synthmaker.co.uk
==================== Loaded Modules (Whitelisted) =============
2015-01-21 04:06 - 2015-01-21 04:06 - 000053248 _____ () [File not signed] C:\Program Files\CCleaner\lang\lang-1029.dll
2020-07-19 14:21 - 2020-07-19 14:21 - 000114176 _____ () [File not signed] C:\Users\Johnny\AppData\Local\Temp\_MEI12482\_ctypes.pyd
2020-07-19 14:21 - 2020-07-19 14:21 - 000172544 _____ () [File not signed] C:\Users\Johnny\AppData\Local\Temp\_MEI12482\_elementtree.pyd
2020-07-19 14:21 - 2020-07-19 14:21 - 002250240 _____ () [File not signed] C:\Users\Johnny\AppData\Local\Temp\_MEI12482\_hashlib.pyd
2020-07-19 14:21 - 2020-07-19 14:21 - 000032256 _____ () [File not signed] C:\Users\Johnny\AppData\Local\Temp\_MEI12482\_multiprocessing.pyd
2020-07-19 14:21 - 2020-07-19 14:21 - 000046080 _____ () [File not signed] C:\Users\Johnny\AppData\Local\Temp\_MEI12482\_psutil_windows.pyd
2020-07-19 14:21 - 2020-07-19 14:21 - 000047616 _____ () [File not signed] C:\Users\Johnny\AppData\Local\Temp\_MEI12482\_socket.pyd
2020-07-19 14:21 - 2020-07-19 14:21 - 002819584 _____ () [File not signed] C:\Users\Johnny\AppData\Local\Temp\_MEI12482\_ssl.pyd
2020-07-19 14:21 - 2020-07-19 14:21 - 000026112 _____ () [File not signed] C:\Users\Johnny\AppData\Local\Temp\_MEI12482\_yappi.pyd
2020-07-19 14:21 - 2020-07-19 14:21 - 000080896 _____ () [File not signed] C:\Users\Johnny\AppData\Local\Temp\_MEI12482\bz2.pyd
2020-07-19 14:21 - 2020-07-19 14:21 - 000016384 _____ () [File not signed] C:\Users\Johnny\AppData\Local\Temp\_MEI12482\common.time34.pyd
2020-07-19 14:21 - 2020-07-19 14:21 - 000007680 _____ () [File not signed] C:\Users\Johnny\AppData\Local\Temp\_MEI12482\hashobjs_ext.pyd
2020-07-19 14:21 - 2020-07-19 14:21 - 000301568 _____ () [File not signed] C:\Users\Johnny\AppData\Local\Temp\_MEI12482\PIL._imaging.pyd
2020-07-19 14:21 - 2020-07-19 14:21 - 000168448 _____ () [File not signed] C:\Users\Johnny\AppData\Local\Temp\_MEI12482\pyexpat.pyd
2020-07-19 14:21 - 2020-07-19 14:21 - 001084416 _____ () [File not signed] C:\Users\Johnny\AppData\Local\Temp\_MEI12482\pysqlite2._sqlite.pyd
2020-07-19 14:21 - 2020-07-19 14:21 - 000548864 _____ () [File not signed] C:\Users\Johnny\AppData\Local\Temp\_MEI12482\pythoncom27.dll
2020-07-19 14:21 - 2020-07-19 14:21 - 000137728 _____ () [File not signed] C:\Users\Johnny\AppData\Local\Temp\_MEI12482\pywintypes27.dll
2020-07-19 14:21 - 2020-07-19 14:21 - 000010752 _____ () [File not signed] C:\Users\Johnny\AppData\Local\Temp\_MEI12482\select.pyd
2020-07-19 14:21 - 2020-07-19 14:21 - 000020992 _____ () [File not signed] C:\Users\Johnny\AppData\Local\Temp\_MEI12482\thumbnails_ext.pyd
2020-07-19 14:21 - 2020-07-19 14:21 - 000689664 _____ () [File not signed] C:\Users\Johnny\AppData\Local\Temp\_MEI12482\unicodedata.pyd
2020-07-19 14:21 - 2020-07-19 14:21 - 000119808 _____ () [File not signed] C:\Users\Johnny\AppData\Local\Temp\_MEI12482\usb_ext.pyd
2020-07-19 14:21 - 2020-07-19 14:21 - 000128512 _____ () [File not signed] C:\Users\Johnny\AppData\Local\Temp\_MEI12482\win32api.pyd
2020-07-19 14:21 - 2020-07-19 14:21 - 000438784 _____ () [File not signed] C:\Users\Johnny\AppData\Local\Temp\_MEI12482\win32com.shell.shell.pyd
2020-07-19 14:21 - 2020-07-19 14:21 - 000011776 _____ () [File not signed] C:\Users\Johnny\AppData\Local\Temp\_MEI12482\win32crypt.pyd
2020-07-19 14:21 - 2020-07-19 14:21 - 000023040 _____ () [File not signed] C:\Users\Johnny\AppData\Local\Temp\_MEI12482\win32event.pyd
2020-07-19 14:21 - 2020-07-19 14:21 - 000149504 _____ () [File not signed] C:\Users\Johnny\AppData\Local\Temp\_MEI12482\win32file.pyd
2020-07-19 14:21 - 2020-07-19 14:21 - 000223232 _____ () [File not signed] C:\Users\Johnny\AppData\Local\Temp\_MEI12482\win32gui.pyd
2020-07-19 14:21 - 2020-07-19 14:21 - 000048128 _____ () [File not signed] C:\Users\Johnny\AppData\Local\Temp\_MEI12482\win32inet.pyd
2020-07-19 14:21 - 2020-07-19 14:21 - 000029696 _____ () [File not signed] C:\Users\Johnny\AppData\Local\Temp\_MEI12482\win32pdh.pyd
2020-07-19 14:21 - 2020-07-19 14:21 - 000027648 _____ () [File not signed] C:\Users\Johnny\AppData\Local\Temp\_MEI12482\win32pipe.pyd
2020-07-19 14:21 - 2020-07-19 14:21 - 000044032 _____ () [File not signed] C:\Users\Johnny\AppData\Local\Temp\_MEI12482\win32process.pyd
2020-07-19 14:21 - 2020-07-19 14:21 - 000020480 _____ () [File not signed] C:\Users\Johnny\AppData\Local\Temp\_MEI12482\win32profile.pyd
2020-07-19 14:21 - 2020-07-19 14:21 - 000136192 _____ () [File not signed] C:\Users\Johnny\AppData\Local\Temp\_MEI12482\win32security.pyd
2020-07-19 14:21 - 2020-07-19 14:21 - 000026624 _____ () [File not signed] C:\Users\Johnny\AppData\Local\Temp\_MEI12482\win32ts.pyd
2020-07-19 14:21 - 2020-07-19 14:21 - 000034816 _____ () [File not signed] C:\Users\Johnny\AppData\Local\Temp\_MEI12482\windows.conditional.pyd
2020-07-19 14:21 - 2020-07-19 14:21 - 000038400 _____ () [File not signed] C:\Users\Johnny\AppData\Local\Temp\_MEI12482\windows.connectivity.pyd
2020-07-19 14:21 - 2020-07-19 14:21 - 000071680 _____ () [File not signed] C:\Users\Johnny\AppData\Local\Temp\_MEI12482\windows.device_monitor.pyd
2020-07-19 14:21 - 2020-07-19 14:21 - 000109056 _____ () [File not signed] C:\Users\Johnny\AppData\Local\Temp\_MEI12482\windows.volumes.pyd
2020-07-19 14:21 - 2020-07-19 14:21 - 000020480 _____ () [File not signed] C:\Users\Johnny\AppData\Local\Temp\_MEI12482\windows.winwrap.pyd
2020-07-19 14:21 - 2020-07-19 14:21 - 001325056 _____ () [File not signed] C:\Users\Johnny\AppData\Local\Temp\_MEI12482\wx._controls_.pyd
2020-07-19 14:21 - 2020-07-19 14:21 - 001489408 _____ () [File not signed] C:\Users\Johnny\AppData\Local\Temp\_MEI12482\wx._core_.pyd
2020-07-19 14:21 - 2020-07-19 14:21 - 001007104 _____ () [File not signed] C:\Users\Johnny\AppData\Local\Temp\_MEI12482\wx._gdi_.pyd
2020-07-19 14:21 - 2020-07-19 14:21 - 000103424 _____ () [File not signed] C:\Users\Johnny\AppData\Local\Temp\_MEI12482\wx._html2.pyd
2020-07-19 14:21 - 2020-07-19 14:21 - 000916992 _____ () [File not signed] C:\Users\Johnny\AppData\Local\Temp\_MEI12482\wx._misc_.pyd
2020-07-19 14:21 - 2020-07-19 14:21 - 001039872 _____ () [File not signed] C:\Users\Johnny\AppData\Local\Temp\_MEI12482\wx._windows_.pyd
2016-10-20 20:52 - 2016-09-28 10:54 - 000076800 _____ (Igor Pavlov) [File not signed] C:\Program Files\7-Zip\7-zip.dll
2017-04-21 13:24 - 2017-04-21 13:24 - 000112128 _____ (Microsoft Corporation) [File not signed] [File is in use] C:\Windows\Microsoft.Net\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
2017-04-21 13:26 - 2017-04-21 13:26 - 000126976 _____ (Microsoft Corporation) [File not signed] [File is in use] C:\Windows\Microsoft.Net\assembly\GAC_64\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
2020-07-19 14:21 - 2020-07-19 14:21 - 003043328 _____ (Python Software Foundation) [File not signed] C:\Users\Johnny\AppData\Local\Temp\_MEI12482\python27.dll
2020-07-19 14:21 - 2020-07-19 14:21 - 000202240 _____ (wxWidgets development team) [File not signed] C:\Users\Johnny\AppData\Local\Temp\_MEI12482\wxbase30u_net_vc90_x64.dll
2020-07-19 14:21 - 2020-07-19 14:21 - 002831872 _____ (wxWidgets development team) [File not signed] C:\Users\Johnny\AppData\Local\Temp\_MEI12482\wxbase30u_vc90_x64.dll
2020-07-19 14:21 - 2020-07-19 14:21 - 001654784 _____ (wxWidgets development team) [File not signed] C:\Users\Johnny\AppData\Local\Temp\_MEI12482\wxmsw30u_adv_vc90_x64.dll
2020-07-19 14:21 - 2020-07-19 14:21 - 006542336 _____ (wxWidgets development team) [File not signed] C:\Users\Johnny\AppData\Local\Temp\_MEI12482\wxmsw30u_core_vc90_x64.dll
2020-07-19 14:21 - 2020-07-19 14:21 - 000773632 _____ (wxWidgets development team) [File not signed] C:\Users\Johnny\AppData\Local\Temp\_MEI12482\wxmsw30u_html_vc90_x64.dll
2020-07-19 14:21 - 2020-07-19 14:21 - 000137216 _____ (wxWidgets development team) [File not signed] C:\Users\Johnny\AppData\Local\Temp\_MEI12482\wxmsw30u_webview_vc90_x64.dll
==================== Alternate Data Streams (Whitelisted) ========
==================== Safe Mode (Whitelisted) ==================
==================== Association (Whitelisted) =================
==================== Internet Explorer trusted/restricted ==========
==================== Hosts content: =========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 04:34 - 2009-06-10 23:00 - 000000824 _____ C:\Windows\system32\drivers\etc\hosts
==================== Other Areas ===========================
(Currently there is no automatic fix for this section.)
HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Intel\iCLS Client\;C:\Program Files\Intel\iCLS Client\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files (x86)\QuickTime\QTSystem\
HKU\S-1-5-21-2350607292-2742822079-1077346085-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Johnny\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
==================== FirewallRules (Whitelisted) ================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [TCP Query User{14D8EF69-CCD2-4E89-BE3C-03D3F1B60F43}C:\windows\kmsemulator.exe] => (Allow) C:\windows\kmsemulator.exe () [File not signed]
FirewallRules: [UDP Query User{6FD7B68E-E7BC-4E96-97BF-11FFFC3DAA1B}C:\windows\kmsemulator.exe] => (Allow) C:\windows\kmsemulator.exe () [File not signed]
FirewallRules: [{A1D1EC1C-F397-4C20-9D6A-906045B067EA}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{822E070F-E42B-4087-B2F3-5B57E7DD1138}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{36B2F014-A755-4AA3-9C36-F8EEC4BE1BC4}] => (Allow) C:\Program Files\HP\HP Deskjet 3520 series\Bin\DeviceSetup.exe (Hewlett Packard -> Hewlett-Packard Co.)
FirewallRules: [{BA947712-39F6-4059-8FD6-32C297759E69}] => (Allow) C:\Program Files\HP\HP Deskjet 3520 series\Bin\HPNetworkCommunicator.exe (Hewlett Packard -> Hewlett-Packard Co.)
FirewallRules: [TCP Query User{3DE8CCDA-4CD4-4A06-9F64-EE2901A439EF}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [UDP Query User{64EF5EE1-5889-4090-9468-A86778719B3F}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{3689E3A2-02A1-4D67-9686-6763A253491D}] => (Block) C:\Program Files (x86)\Avira\SoftwareUpdater\avirasoftwareupdatertoastnotificationsbridge.exe (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
FirewallRules: [{5E2C014C-7DDC-4B07-96DA-237725B9CC47}] => (Allow) C:\Program Files (x86)\Avira\SoftwareUpdater\avirasoftwareupdatertoastnotificationsbridge.exe (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
FirewallRules: [{34A90519-6A68-4D05-9C0D-786DB1F676A2}] => (Allow) C:\Program Files (x86)\Avira\SoftwareUpdater\avirasoftwareupdatertoastnotificationsbridge.exe (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
==================== Restore Points =========================
14-06-2020 19:00:11 Windows Backup
22-06-2020 11:13:40 Windows Backup
28-06-2020 19:00:10 Windows Backup
05-07-2020 19:36:03 Windows Backup
12-07-2020 19:11:21 Windows Backup
==================== Faulty Device Manager Devices ============
Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
==================== Event log errors: ========================
Application errors:
==================
Error: (07/14/2020 06:08:59 PM) (Source: Software Protection Platform Service) (EventID: 8208) (User: )
Description: Acquisition of genuine ticket failed (hr=0x80072EE7) for template Id 66c92734-d682-4d71-983e-d6ec3f16059f
Error: (07/14/2020 06:08:59 PM) (Source: Software Protection Platform Service) (EventID: 8200) (User: )
Description: License acquisition failure details.
hr=0x80072EE7
Error: (06/22/2020 11:02:06 AM) (Source: TrueKey) (EventID: 0) (User: )
Description: Failed to process session change. System.ArgumentNullException: Value cannot be null.
at System.Threading.Monitor.Enter(Object obj)
at McAfee.YAP.Service.Common.UsersManager.GetWindowsUsers(Boolean async)
at McAfee.YAP.Service.Service.OnSessionChange(SessionChangeDescription changeDescription)
at System.ServiceProcess.ServiceBase.DeferredSessionChange(Int32 eventType, Int32 sessionId)
Error: (06/04/2020 10:18:25 AM) (Source: TrueKey) (EventID: 0) (User: )
Description: Failed to process session change. System.ArgumentNullException: Value cannot be null.
at System.Threading.Monitor.Enter(Object obj)
at McAfee.YAP.Service.Common.UsersManager.GetWindowsUsers(Boolean async)
at McAfee.YAP.Service.Service.OnSessionChange(SessionChangeDescription changeDescription)
at System.ServiceProcess.ServiceBase.DeferredSessionChange(Int32 eventType, Int32 sessionId)
Error: (06/02/2020 03:48:39 PM) (Source: TrueKey) (EventID: 0) (User: )
Description: Failed to process session change. System.ArgumentNullException: Value cannot be null.
at System.Threading.Monitor.Enter(Object obj)
at McAfee.YAP.Service.Common.UsersManager.GetWindowsUsers(Boolean async)
at McAfee.YAP.Service.Service.OnSessionChange(SessionChangeDescription changeDescription)
at System.ServiceProcess.ServiceBase.DeferredSessionChange(Int32 eventType, Int32 sessionId)
Error: (06/02/2020 02:36:11 PM) (Source: TrueKey) (EventID: 0) (User: )
Description: Failed to process session change. System.ArgumentNullException: Value cannot be null.
at System.Threading.Monitor.Enter(Object obj)
at McAfee.YAP.Service.Common.UsersManager.GetWindowsUsers(Boolean async)
at McAfee.YAP.Service.Service.OnSessionChange(SessionChangeDescription changeDescription)
at System.ServiceProcess.ServiceBase.DeferredSessionChange(Int32 eventType, Int32 sessionId)
Error: (05/24/2020 02:45:43 PM) (Source: TrueKey) (EventID: 0) (User: )
Description: Failed to process session change. System.ArgumentNullException: Value cannot be null.
at System.Threading.Monitor.Enter(Object obj)
at McAfee.YAP.Service.Common.UsersManager.GetWindowsUsers(Boolean async)
at McAfee.YAP.Service.Service.OnSessionChange(SessionChangeDescription changeDescription)
at System.ServiceProcess.ServiceBase.DeferredSessionChange(Int32 eventType, Int32 sessionId)
Error: (05/16/2020 07:52:55 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: FL.exe, version: 0.0.0.0, time stamp: 0x4d3574e7
Faulting module name: ntdll.dll, version: 6.1.7601.23915, time stamp: 0x59b94a16
Exception code: 0xc0000374
Fault offset: 0x000ce85b
Faulting process id: 0x1688
Faulting application start time: 0x01d62b45ace503e1
Faulting application path: C:\Program Files (x86)\Image-Line\FL Studio 10\FL.exe
Faulting module path: C:\Windows\SysWOW64\ntdll.dll
Report Id: 7c9ee6a1-9739-11ea-89ec-4ccc6a4b57c8
System errors:
=============
Error: (07/18/2020 08:18:48 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: The server {995C996E-D918-4A8C-A302-45719A6F4EA7} did not register with DCOM within the required timeout.
Error: (07/13/2020 06:45:42 PM) (Source: Microsoft-Windows-HAL) (EventID: 12) (User: )
Description: The platform firmware has corrupted memory across the previous system power transition. Please check for updated firmware for your system.
Error: (07/08/2020 02:56:41 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: The server {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39} did not register with DCOM within the required timeout.
Error: (07/05/2020 11:52:23 AM) (Source: Microsoft-Windows-HAL) (EventID: 12) (User: )
Description: The platform firmware has corrupted memory across the previous system power transition. Please check for updated firmware for your system.
Error: (07/03/2020 03:08:34 PM) (Source: Microsoft-Windows-HAL) (EventID: 12) (User: )
Description: The platform firmware has corrupted memory across the previous system power transition. Please check for updated firmware for your system.
Error: (07/02/2020 04:31:04 PM) (Source: Microsoft-Windows-HAL) (EventID: 12) (User: )
Description: The platform firmware has corrupted memory across the previous system power transition. Please check for updated firmware for your system.
Error: (06/30/2020 06:32:38 PM) (Source: Microsoft-Windows-HAL) (EventID: 12) (User: )
Description: The platform firmware has corrupted memory across the previous system power transition. Please check for updated firmware for your system.
Error: (06/29/2020 07:55:58 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: The server {995C996E-D918-4A8C-A302-45719A6F4EA7} did not register with DCOM within the required timeout.
CodeIntegrity:
===================================
Date: 2016-12-01 12:56:40.510
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\wdcsam64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2016-12-01 12:56:40.510
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\wdcsam64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2016-11-23 22:22:24.070
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\wdcsam64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2016-11-23 22:22:24.070
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\wdcsam64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2016-11-14 22:43:43.026
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\wdcsam64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2016-11-14 22:43:43.026
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\wdcsam64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2016-11-14 20:18:23.425
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\wdcsam64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2016-11-14 20:18:23.425
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\wdcsam64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
==================== Memory info ===========================
BIOS: American Megatrends Inc. C.60 07/22/2016
Motherboard: MSI B150M MORTAR (MS-7972)
Processor: Intel(R) Core(TM) i5-6500 CPU @ 3.20GHz
Percentage of memory in use: 31%
Total physical RAM: 16258.88 MB
Available physical RAM: 11171.88 MB
Total Virtual: 32515.93 MB
Available Virtual: 27457.71 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:223.35 GB) (Free:101.64 GB) NTFS
Drive d: () (Fixed) (Total:1863.01 GB) (Free:372.98 GB) NTFS
==================== MBR & Partition Table ====================
==========================================================
Disk: 0 (Protective MBR) (Size: 223.6 GB) (Disk ID: 00000000)
Partition: GPT.
==========================================================
Disk: 1 (MBR Code: Windows 7/8/10) (Size: 1863 GB) (Disk ID: 346FBCB4)
Partition 1: (Not Active) - (Size=1863 GB) - (Type=07 NTFS)
==================== End of Addition.txt =======================