


Moderátor: Moderátoři
Kód: Vybrat vše
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 19-02-2017
Ran by Safire (20-02-2017 18:03:38)
Running from C:\Users\Safire\Desktop
Windows 10 Pro Version 1607 (X64) (2016-10-15 14:30:11)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-639167727-1611962213-2014225226-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-639167727-1611962213-2014225226-503 - Limited - Disabled)
defaultuser0 (S-1-5-21-639167727-1611962213-2014225226-1000 - Limited - Disabled) => C:\Users\defaultuser0
Guest (S-1-5-21-639167727-1611962213-2014225226-501 - Limited - Disabled)
Safire (S-1-5-21-639167727-1611962213-2014225226-1001 - Administrator - Enabled) => C:\Users\Safire
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
µTorrent (HKU\S-1-5-21-639167727-1611962213-2014225226-1001\...\uTorrent) (Version: 3.4.9.43295 - BitTorrent Inc.)
1600 (x32 Version: 140.0.425.000 - Hewlett-Packard) Hidden
1600_Help (x32 Version: 82.0.242.000 - Hewlett-Packard) Hidden
1600Trb (x32 Version: 82.0.242.000 - Hewlett-Packard) Hidden
64 Bit HP CIO Components Installer (Version: 7.2.8 - Hewlett-Packard) Hidden
Adobe Acrobat Reader DC - Slovak (HKLM-x32\...\{AC76BA86-7AD7-1051-7B44-AC0F074E4100}) (Version: 15.023.20056 - Adobe Systems Incorporated)
AIO_CDB_ProductContext (x32 Version: 140.0.425.000 - Hewlett-Packard) Hidden
AIO_CDB_Software (x32 Version: 140.0.428.000 - Hewlett-Packard) Hidden
AIO_Scan (x32 Version: 130.0.421.000 - Hewlett-Packard) Hidden
AMD Software (HKLM\...\AMD Catalyst Install Manager) (Version: 9.0.000.8 - Advanced Micro Devices, Inc.)
Apple Mobile Device Support (HKLM\...\{55BB2110-FB43-49B3-93F4-945A0CFB0A6C}) (Version: 10.0.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.)
Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment)
BattleBlock Theater (HKLM\...\Steam App 238460) (Version: - The Behemoth)
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
BS.Player FREE (HKLM-x32\...\BSPlayerf) (Version: 2.70.1080 - AB Team, d.o.o.)
BufferChm (x32 Version: 140.0.298.000 - Hewlett-Packard) Hidden
Castle Crashers (HKLM\...\Steam App 204360) (Version: - The Behemoth)
Catalyst Control Center Next Localization BR (Version: 2017.0113.1201.21594 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CS (Version: 2017.0113.1201.21594 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DA (Version: 2017.0113.1201.21594 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DE (Version: 2017.0113.1201.21594 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization EL (Version: 2017.0113.1201.21594 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization ES (Version: 2017.0113.1201.21594 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FI (Version: 2017.0113.1201.21594 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FR (Version: 2017.0113.1201.21594 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization HU (Version: 2017.0113.1201.21594 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHS (Version: 2017.0113.1201.21594 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHT (Version: 2017.0113.1201.21594 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization IT (Version: 2017.0113.1201.21594 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization JA (Version: 2017.0113.1201.21594 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization KO (Version: 2017.0113.1201.21594 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NL (Version: 2017.0113.1201.21594 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NO (Version: 2017.0113.1201.21594 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization PL (Version: 2017.0113.1201.21594 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization RU (Version: 2017.0113.1201.21594 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization SV (Version: 2017.0113.1201.21594 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TH (Version: 2017.0113.1201.21594 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TR (Version: 2017.0113.1201.21594 - Advanced Micro Devices, Inc.) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 5.23 - Piriform)
Copy (x32 Version: 140.0.298.000 - Hewlett-Packard) Hidden
CrystalDiskInfo 7.0.4 (HKLM-x32\...\CrystalDiskInfo_is1) (Version: 7.0.4 - Crystal Dew World)
DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 10.4.0.0196 - Disc Soft Ltd)
DayZ (HKLM\...\Steam App 221100) (Version: - Bohemia Interactive)
Destinations (x32 Version: 140.0.253.000 - Hewlett-Packard) Hidden
DeviceDiscovery (x32 Version: 140.0.298.000 - Hewlett-Packard) Hidden
Energy Management (HKLM-x32\...\InstallShield_{D0956C11-0F60-43FE-99AD-524E833471BB}) (Version: 6.0.1.6 - Lenovo)
Energy Management (x32 Version: 6.0.1.6 - Lenovo) Hidden
f.lux (HKU\S-1-5-21-639167727-1611962213-2014225226-1001\...\Flux) (Version: - )
FastStone Image Viewer 6.0 (HKLM-x32\...\FastStone Image Viewer) (Version: 6.0 - FastStone Soft)
Fax (x32 Version: 140.0.307.000 - Hewlett-Packard) Hidden
Fraps (HKLM-x32\...\Fraps) (Version: - )
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 56.0.2924.87 - Spoločnosť Google Inc.)
Google Update Helper (x32 Version: 1.3.32.7 - Google Inc.) Hidden
H1Z1: King of the Kill (HKLM\...\Steam App 433850) (Version: - Daybreak Game Company)
HD Tune Pro 5.50 (HKLM-x32\...\HD Tune Pro_is1) (Version: - EFD Software)
HP Imaging Device Functions 14.0 (HKLM\...\HP Imaging Device Functions) (Version: 14.0 - HP)
HP Photosmart Officejet and Deskjet All-In-One Driver Software (HKLM\...\{6F5B70F0-EA6C-4A5B-BB16-8390BD66B251}) (Version: 14.0 - HP)
HPPhotoGadget (x32 Version: 140.0.524.000 - Hewlett-Packard) Hidden
Intel(R) Chipset Device Software (x32 Version: 10.1.1.14 - Intel(R) Corporation) Hidden
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 20.19.15.4483 - Intel Corporation)
Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation)
Intel® PROSet/Wireless WiFi Software (HKLM\...\{99FDAE3B-6905-45A6-8F73-595363AAD3D1}) (Version: 15.05.1000.1411 - Intel Corporation)
iTunes (HKLM\...\{554C62C7-E6BB-40F1-892B-F0AE02D3C135}) (Version: 12.5.3.17 - Apple Inc.)
League of Legends (HKLM-x32\...\League of Legends 4.2.1) (Version: 4.2.1 - Riot Games)
League of Legends (x32 Version: 4.2.1 - Riot Games) Hidden
Life is Strange (HKLM-x32\...\Life is Strange_is1) (Version: - )
Life Is Strange™ (HKLM\...\Steam App 319630) (Version: - DONTNOD Entertainment)
Logitech Gaming Software 8.88 (HKLM\...\Logitech Gaming Software) (Version: 8.88.30 - Logitech Inc.)
Manticore Gaming Keyboard (HKLM-x32\...\{0DAEFA4F-E394-4D1F-8F1A-6A2180561290}}_is1) (Version: - )
Microsoft Flight Simulator SimConnect Client v10.0.61259.0 (HKLM-x32\...\{D61CA184-3F6D-4A50-B2CC-7A18447D6A8D}) (Version: 10.0.61259.0 - Microsoft Corporation)
Microsoft Flight Simulator SimConnect Client v10.0.62615.0 (HKLM-x32\...\{33D89314-361A-4495-A1E1-0ACBCE08F78D}) (Version: 10.0.62615.0 - Microsoft Corporation)
Microsoft Office 2016 Professional Plus - sk-sk (HKLM\...\ProplusRetail - sk-sk) (Version: 16.0.7766.2047 - Microsoft Corporation)
Microsoft Office Professional Plus 2016 - en-us (HKLM\...\ProplusRetail - en-us) (Version: 16.0.7766.2047 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24210 (HKLM-x32\...\{f144e08f-9cbe-4f09-9a8c-f2b858b7ee7f}) (Version: 14.0.24210.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24210 (HKLM-x32\...\{23658c02-145e-483d-ba6b-1eb82c580529}) (Version: 14.0.24210.0 - Microsoft Corporation)
Mp3tag v2.79 (HKLM-x32\...\Mp3tag) (Version: v2.79 - Florian Heidenreich)
MSXML 4.0 SP2 Parser and SDK (HKLM-x32\...\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation)
Network64 (Version: 140.0.306.000 - Hewlett-Packard) Hidden
NVIDIA PhysX (HKLM-x32\...\{B455E95A-B804-439F-B533-336B1635AE97}) (Version: 9.14.0702 - NVIDIA Corporation)
Office 16 Click-to-Run Extensibility Component (Version: 16.0.7766.2047 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (Version: 16.0.7766.2047 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (Version: 16.0.7766.2039 - Microsoft Corporation) Hidden
Overwatch (HKLM-x32\...\Overwatch) (Version: - Blizzard Entertainment)
Podpora Apple aplikácií (32-bit) (HKLM-x32\...\{F2871C89-C8A5-42EE-8D45-0F02506385A6}) (Version: 5.1 - Apple Inc.)
Podpora Apple aplikácií(64-bit) (HKLM\...\{9BC93467-75D1-4AA4-BD58-D9C51D88DFAB}) (Version: 5.1 - Apple Inc.)
PX Profile Update (x32 Version: 1.00.1. - AMD) Hidden
Razer Cortex (HKLM-x32\...\Razer Cortex_is1) (Version: 7.6.8.66 - Razer Inc.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.2.612.2012 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6657 - Realtek Semiconductor Corp.)
Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.8400.39029 - Realtek Semiconductor Corp.)
Realtek USB 2.0 Reader Driver (HKLM-x32\...\{62BBB2F0-E220-4821-A564-730807D2C34D}) (Version: 6.1.7600.10008 - Realtek Semiconductor Corp.)
Sapphire TRIXX (HKLM-x32\...\Sapphire TRIXX) (Version: - )
Scan (x32 Version: 140.0.253.000 - Hewlett-Packard) Hidden
Sid Meier's Civilization V (HKLM\...\Steam App 8930) (Version: - Firaxis Games)
SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version: - )
Status (x32 Version: 140.0.342.000 - Hewlett-Packard) Hidden
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Subtitle Workshop 6.0b (HKLM-x32\...\SubtitleWorkshop) (Version: - )
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 19.0.12.0 - Synaptics Incorporated)
Synaptics WBF Fingerprint Reader (HKLM\...\{B0CB33D8-1426-4D61-A4F6-BDFD7407AE92}) (Version: 4.5.307.0 - Synaptics)
TeamViewer 12 (HKLM-x32\...\TeamViewer) (Version: 12.0.72365 - TeamViewer)
TechPowerUp GPU-Z (HKLM-x32\...\TechPowerUp GPU-Z) (Version: - TechPowerUp)
The Elder Scrolls Online (HKLM-x32\...\The Elder Scrolls Online) (Version: 1.5.0.0 - Zenimax Online Studios)
The Sims 4: City Living (HKLM\...\dGhlc2ltczRjaXR5bGl2aW5n_is1) (Version: 1 - )
The Sims™ 4 (HKLM-x32\...\{48EBEBBF-B9F8-4520-A3CF-89A730721917}) (Version: 1.25.136.1020 - Electronic Arts Inc.)
The Witcher 3 - Wild Hunt (HKLM-x32\...\1495134320_is1) (Version: 2.0.0.51 - GOG.com)
Toolbox (x32 Version: 140.0.596.000 - Hewlett-Packard) Hidden
TrayApp (x32 Version: 140.0.297.000 - Hewlett-Packard) Hidden
WebReg (x32 Version: 140.0.297.017 - Hewlett-Packard) Hidden
Windows 7 USB/DVD Download Tool (HKLM-x32\...\{CCF298AF-9CE1-4B26-B251-486E98A34789}) (Version: 1.0.30 - Microsoft Corporation)
Windows Driver Package - Lenovo (ACPIVPC) System (12/02/2010 6.1.0.1) (HKLM\...\EA12B1FB53CE4E387C31A85236C41EF559B5E392) (Version: 12/02/2010 6.1.0.1 - Lenovo)
WinRAR 5.30 (64-bitová verzia) (HKLM\...\WinRAR archiver) (Version: 5.30.0 - win.rar GmbH)
Wise Auto Shutdown 1.55 (HKLM-x32\...\Wise Auto Shutdown_is1) (Version: 1.55 - WiseCleaner.com, Inc.)
youndoo - Uninstall (HKLM-x32\...\{8833B02A-1A73-4450-8BB5-9B893D007D09}) (Version: - ) <==== ATTENTION
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-639167727-1611962213-2014225226-1001_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32 -> C:\Users\Safire\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\amd64\FileSyncShell64.dll => No File
CustomCLSID: HKU\S-1-5-21-639167727-1611962213-2014225226-1001_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32 -> C:\Users\Safire\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\amd64\FileSyncShell64.dll => No File
CustomCLSID: HKU\S-1-5-21-639167727-1611962213-2014225226-1001_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32 -> C:\Users\Safire\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\amd64\FileSyncShell64.dll => No File
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {071BF5D4-B51F-488A-974A-CE2E13C5A158} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-01-29] (Microsoft Corporation)
Task: {1456F6AC-8D10-49D6-A25F-1C20F7B636D7} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-12-19] (Adobe Systems Incorporated)
Task: {32DD1A3E-BEDA-4C58-81F1-F29D6F787392} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe [2017-01-13] (Advanced Micro Devices, Inc.)
Task: {3904411E-3865-43E4-A7D1-23A7E4541F20} - System32\Tasks\AMD Updater => C:\Program Files\AMD\CIM\\Bin64\RadeonInstaller.exe [2017-01-13] (Advanced Micro Devices, Inc.)
Task: {3C043F9B-C9CC-49E2-8DC3-F26B22EEAF80} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-01-29] (Microsoft Corporation)
Task: {4D4819FE-E7E7-4D98-96FA-848BBED1969C} - System32\Tasks\Kokock => "msiexec" /i hxxp://d2buh1bf1g584w.cloudfront.net/msi/rel.php?u=HITACHIXHTS545050B9A300_120129PBN406P7HLX4JEX&v=2017220 /q
Task: {539492BF-AE75-4AC2-B3B5-AE6DA1930772} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-09-28] (Piriform Ltd)
Task: {5B1468FD-4981-4134-B0AE-658D27F99FB8} - System32\Tasks\Nimasy Engine => C:\Program Files (x86)\Divosh\plejither.exe [2017-02-20] (Glarysoft Ltd)
Task: {705D5C7D-E230-4470-8A0B-FCB541EFF1ED} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-10-15] (Google Inc.)
Task: {78229A4E-016A-433B-AB30-E1D99911CC00} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.)
Task: {B175F8AF-413E-4CD2-8753-1AF37D119B6A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-10-15] (Google Inc.)
Task: {CE605C66-2429-4F08-988B-0AF815F785B3} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [2017-02-07] (Microsoft Corporation)
Task: {DE6229BD-BD60-4CB5-A2F8-EF04B922AC57} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [2017-02-07] (Microsoft Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job => C:\Windows\explorer.exe
==================== Shortcuts =============================
(The entries could be listed to be restored or removed.)
WMI_ActiveScriptEventConsumer_ASEC: <===== ATTENTION
ShortcutWithArgument: C:\Users\Safire\Desktop\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --load-extension="C:\Users\Safire\AppData\Local\kemgadeojglibflomicgnfeopkdfflnk" hxxp://qtipr.com/
ShortcutWithArgument: C:\Users\Safire\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --load-extension="C:\Users\Safire\AppData\Local\kemgadeojglibflomicgnfeopkdfflnk" hxxp://qtipr.com/
ShortcutWithArgument: C:\Users\Safire\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --load-extension="C:\Users\Safire\AppData\Local\kemgadeojglibflomicgnfeopkdfflnk" hxxp://qtipr.com/
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --load-extension="C:\Users\Safire\AppData\Local\kemgadeojglibflomicgnfeopkdfflnk" hxxp://qtipr.com/
==================== Loaded Modules (Whitelisted) ==============
2016-07-16 12:42 - 2016-07-16 12:42 - 00231424 _____ () C:\Windows\SYSTEM32\ism32k.dll
2016-12-14 18:19 - 2016-12-09 11:29 - 02681200 _____ () C:\Windows\system32\CoreUIComponents.dll
2017-02-20 17:21 - 2017-02-20 17:21 - 00307200 _____ () C:\Program Files (x86)\Nimasy Engine\local64spl.dll
2015-06-10 16:33 - 2015-06-10 16:33 - 00022528 _____ () C:\Windows\system32\fpCSEvtSvc.exe
2016-10-05 18:17 - 2016-10-05 18:17 - 00092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2016-10-05 18:17 - 2016-10-05 18:17 - 01353528 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2016-09-24 23:20 - 2016-09-24 23:21 - 00189264 _____ () C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
2016-12-14 18:19 - 2016-12-09 11:29 - 02681200 _____ () C:\Windows\SYSTEM32\CoreUIComponents.dll
2016-10-15 18:44 - 2016-09-07 05:56 - 00134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll
2017-01-10 19:41 - 2016-12-21 08:09 - 00474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll
2017-01-10 19:40 - 2016-12-21 07:54 - 09760768 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2017-01-10 19:40 - 2016-12-21 07:48 - 01401856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2017-01-10 19:40 - 2016-12-21 07:48 - 00757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll
2017-01-10 19:40 - 2016-12-21 07:48 - 02424320 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2017-01-10 19:40 - 2016-12-21 07:53 - 04853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2015-08-23 19:43 - 2016-08-04 22:42 - 00384496 _____ () C:\Windows\system32\igfxTray.exe
2016-09-14 02:20 - 2016-09-14 02:20 - 00014336 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick.2\qtquick2plugin.dll
2016-09-14 02:20 - 2016-09-14 02:20 - 00739840 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Controls\qtquickcontrolsplugin.dll
2016-09-14 02:20 - 2016-09-14 02:20 - 00014336 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Window.2\windowplugin.dll
2016-09-14 02:20 - 2016-09-14 02:20 - 00071168 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Layouts\qquicklayoutsplugin.dll
2016-09-14 02:20 - 2016-09-14 02:20 - 00011776 _____ () C:\Program Files\AMD\CNext\CNext\libEGL.dll
2016-09-14 02:20 - 2016-09-14 02:20 - 02013696 _____ () C:\Program Files\AMD\CNext\CNext\libGLESv2.dll
2016-09-14 02:20 - 2016-09-14 02:20 - 00191488 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Dialogs\dialogplugin.dll
2017-02-07 00:13 - 2017-02-01 10:47 - 02459992 _____ () C:\Program Files (x86)\Google\Chrome\Application\56.0.2924.87\libglesv2.dll
2017-02-07 00:13 - 2017-02-01 10:47 - 00099672 _____ () C:\Program Files (x86)\Google\Chrome\Application\56.0.2924.87\libegl.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2016-07-16 12:47 - 2017-02-20 17:30 - 00002216 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 cpm.paneladmin.pro
127.0.0.1 publisher.hmdiadmingate.xyz
127.0.0.1 distribution.hmdiadmingate.xyz
127.0.0.1 hmdicrewtracksystem.xyz
127.0.0.1 beautifllink.xyz
127.0.0.1 cpm.paneladmin.pro
127.0.0.1 publisher.hmdiadmingate.xyz
127.0.0.1 distribution.hmdiadmingate.xyz
127.0.0.1 hmdicrewtracksystem.xyz
127.0.0.1 beautifllink.xyz
127.0.0.1 cpm.paneladmin.pro
127.0.0.1 publisher.hmdiadmingate.xyz
127.0.0.1 distribution.hmdiadmingate.xyz
127.0.0.1 hmdicrewtracksystem.xyz
127.0.0.1 beautifllink.xyz
127.0.0.1 cpm.paneladmin.pro
127.0.0.1 publisher.hmdiadmingate.xyz
127.0.0.1 distribution.hmdiadmingate.xyz
127.0.0.1 hmdicrewtracksystem.xyz
127.0.0.1 beautifllink.xyz
127.0.0.1 cpm.paneladmin.pro
127.0.0.1 publisher.hmdiadmingate.xyz
127.0.0.1 distribution.hmdiadmingate.xyz
127.0.0.1 hmdicrewtracksystem.xyz
127.0.0.1 beautifllink.xyz
127.0.0.1 cpm.paneladmin.pro
127.0.0.1 publisher.hmdiadmingate.xyz
127.0.0.1 distribution.hmdiadmingate.xyz
127.0.0.1 hmdicrewtracksystem.xyz
127.0.0.1 beautifllink.xyz
There are 9 more lines.
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-639167727-1611962213-2014225226-1001\Control Panel\Desktop\\Wallpaper ->
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
HKLM\...\StartupApproved\StartupFolder: => "HP Digital Imaging Monitor.lnk"
HKLM\...\StartupApproved\Run: => "WindowsDefender"
HKLM\...\StartupApproved\Run: => "RtsCM"
HKLM\...\StartupApproved\Run: => "EnergyUtility"
HKLM\...\StartupApproved\Run: => "Energy Management"
HKLM\...\StartupApproved\Run: => "SynTPEnh"
HKLM\...\StartupApproved\Run: => "Launch LCore"
HKLM\...\StartupApproved\Run: => "iTunesHelper"
HKLM\...\StartupApproved\Run32: => "WindowsDefender"
HKLM\...\StartupApproved\Run32: => "Manticore"
HKLM\...\StartupApproved\Run32: => "RazerCortex"
HKLM\...\StartupApproved\Run32: => "OMEWPRODUCT_2TRY3"
HKU\S-1-5-21-639167727-1611962213-2014225226-1001\...\StartupApproved\StartupFolder: => "Sapphire TRIXX.lnk"
HKU\S-1-5-21-639167727-1611962213-2014225226-1001\...\StartupApproved\StartupFolder: => "ThrottleStop - Shortcut.lnk"
HKU\S-1-5-21-639167727-1611962213-2014225226-1001\...\StartupApproved\Run: => "DAEMON Tools Lite Automount"
HKU\S-1-5-21-639167727-1611962213-2014225226-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-639167727-1611962213-2014225226-1001\...\StartupApproved\Run: => "Steam"
HKU\S-1-5-21-639167727-1611962213-2014225226-1001\...\StartupApproved\Run: => "f.lux"
HKU\S-1-5-21-639167727-1611962213-2014225226-1001\...\StartupApproved\Run: => "CCleaner Monitoring"
HKU\S-1-5-21-639167727-1611962213-2014225226-1001\...\StartupApproved\Run: => "Battle.net"
HKU\S-1-5-21-639167727-1611962213-2014225226-1001\...\StartupApproved\Run: => "Uninstall C:\Users\Safire\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_1\amd64"
HKU\S-1-5-21-639167727-1611962213-2014225226-1001\...\StartupApproved\Run: => "18c294f5-8b2b-415f-a903-553cccbe3aad"
HKU\S-1-5-21-639167727-1611962213-2014225226-1001\...\StartupApproved\Run: => "51fa5df9-73ee-4efa-96ac-853c6418a27f"
HKU\S-1-5-21-639167727-1611962213-2014225226-1001\...\StartupApproved\Run: => "b2956951-fab2-487d-ac0d-16138d77c2d2"
HKU\S-1-5-21-639167727-1611962213-2014225226-1001\...\StartupApproved\Run: => "baad9cf4-d497-405b-8736-78c7780c3422"
HKU\S-1-5-21-639167727-1611962213-2014225226-1001\...\StartupApproved\Run: => "GoogleChromeAutoLaunch_86536B082181848BA60E21454357D310"
HKU\S-1-5-21-639167727-1611962213-2014225226-1001\...\StartupApproved\Run: => "msiql"
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{A61D35F8-9B9D-4987-A918-9D04BE4BF660}] => (Allow) C:\Users\Safire\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{1E1F01A8-39FC-4B94-B88C-024567B9DE0E}] => (Allow) C:\Users\Safire\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{2C16EB4C-27BF-4798-8951-9CCCDAA04533}] => (Allow) C:\Users\Safire\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{B2EB2D83-00E1-415F-88A7-CB41FDE74943}] => (Allow) C:\Users\Safire\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{04CD9B5F-F562-483B-8A06-46D59C56ACAF}] => (Allow) C:\Users\Safire\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{4E255959-E61B-4C7D-A50D-A9E43776E53C}] => (Allow) C:\Users\Safire\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [TCP Query User{6E59B162-2174-4960-A44B-B9B55E6B581C}E:\overwatch\overwatch.exe] => (Allow) E:\overwatch\overwatch.exe
FirewallRules: [UDP Query User{D43707F3-BE37-425C-B7F8-B71F36BCF0A8}E:\overwatch\overwatch.exe] => (Allow) E:\overwatch\overwatch.exe
FirewallRules: [{1C9C000E-D5D0-440B-AEA9-7F522D8C6577}] => (Allow) E:\Steam\Steam.exe
FirewallRules: [{A843E776-FE53-4BE4-83E7-DA88D00F3BAC}] => (Allow) E:\Steam\Steam.exe
FirewallRules: [TCP Query User{F9C6D998-58C3-4197-96EA-A22540764026}E:\steam\steamapps\common\h1z1 king of the kill\h1z1.exe] => (Allow) E:\steam\steamapps\common\h1z1 king of the kill\h1z1.exe
FirewallRules: [UDP Query User{375502E7-E295-4A19-A65A-E129C3320A3F}E:\steam\steamapps\common\h1z1 king of the kill\h1z1.exe] => (Allow) E:\steam\steamapps\common\h1z1 king of the kill\h1z1.exe
FirewallRules: [TCP Query User{433DED09-EA13-41C3-84AE-42E4B53B9F34}E:\steam\steamapps\common\arma 3\arma3.exe] => (Allow) E:\steam\steamapps\common\arma 3\arma3.exe
FirewallRules: [UDP Query User{0EE41F77-F21B-4153-A14F-301FC66A1319}E:\steam\steamapps\common\arma 3\arma3.exe] => (Allow) E:\steam\steamapps\common\arma 3\arma3.exe
FirewallRules: [{620CEB3C-BEE8-4354-A21F-0F8298BA1E36}] => (Allow) E:\Steam\steamapps\common\DayZ\DayZ_BE.exe
FirewallRules: [{5C47D28C-DEB5-4AE3-B9DA-7C5BEDC2D162}] => (Allow) E:\Steam\steamapps\common\DayZ\DayZ_BE.exe
FirewallRules: [TCP Query User{5E8967C8-2395-4A99-9565-749EC62CF7A5}E:\steam\steamapps\common\dayz\dayz.exe] => (Allow) E:\steam\steamapps\common\dayz\dayz.exe
FirewallRules: [UDP Query User{4B021C3A-35CB-4655-9EEB-5488E08D50DE}E:\steam\steamapps\common\dayz\dayz.exe] => (Allow) E:\steam\steamapps\common\dayz\dayz.exe
FirewallRules: [TCP Query User{1ABF72A6-42FD-49A4-8DD2-D5918315E61E}C:\program files\logitech gaming software\lcore.exe] => (Block) C:\program files\logitech gaming software\lcore.exe
FirewallRules: [UDP Query User{14A27788-DB71-44E5-B12F-91E62795CBC0}C:\program files\logitech gaming software\lcore.exe] => (Block) C:\program files\logitech gaming software\lcore.exe
FirewallRules: [{BC5B0CB3-29FE-4558-B157-11774F5F45F6}] => (Allow) E:\Steam\steamapps\common\H1Z1 King of the Kill\LaunchPad.exe
FirewallRules: [{82227E65-7D20-4A48-A55B-C2C7457A1AEF}] => (Allow) E:\Steam\steamapps\common\H1Z1 King of the Kill\LaunchPad.exe
FirewallRules: [{3DAB3AE1-302B-445E-8CD8-EECB8C3BD286}] => (Allow) E:\Steam\steamapps\common\CastleCrashers\castle.exe
FirewallRules: [{9B510CF4-0610-4779-8BA1-F142FA6DC0B5}] => (Allow) E:\Steam\steamapps\common\CastleCrashers\castle.exe
FirewallRules: [{056123DA-F357-4EA4-86B5-88E9B3A8CAE3}] => (Allow) E:\Steam\steamapps\common\BattleBlock Theater\BattleBlockTheater.exe
FirewallRules: [{0AA11BB0-AF0D-453D-A4F4-365F3EF42D1B}] => (Allow) E:\Steam\steamapps\common\BattleBlock Theater\BattleBlockTheater.exe
FirewallRules: [{A0A4889E-8E7A-4911-A137-C320CF461752}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{964E81FB-3FF7-4996-A3B3-8F52FBE3BA33}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{3DD1B225-D796-4BF5-8D27-A633D7353DD7}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{5FF09922-5702-4441-9367-2C28DDCBB83B}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{9356DE29-9183-4C6D-911F-513363EF8828}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{2732BF25-5742-48D6-A8E8-21E388FEEF3C}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
FirewallRules: [{DA863C30-8B1A-42F0-BEF3-5A079F81EEFD}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe
FirewallRules: [{D9EC1B84-7432-44AC-8FD8-39D0A52C2291}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpofxm08.exe
FirewallRules: [{DEA09CC4-6350-408C-8C16-7F06418F46DF}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposfx08.exe
FirewallRules: [{A5067960-83D4-43F3-B88C-F8EB13451EE4}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposid01.exe
FirewallRules: [{3B7998D2-905F-45EB-B62E-014441A33CB4}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqkygrp.exe
FirewallRules: [{7DDA1281-0CE5-476D-B6FF-B24D0F2B9E8B}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcopy2.exe
FirewallRules: [{3A211694-02DA-4C30-8FB9-DF57641BA298}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpfccopy.exe
FirewallRules: [{FFE48677-E992-4CBC-BB95-9FAD57AD0152}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpzwiz01.exe
FirewallRules: [{6BD6738B-074C-4CA4-B55B-830B71F36A7A}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpoews01.exe
FirewallRules: [{1A82EDF0-FD94-47C8-BE2D-F9530117810D}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqnrs08.exe
FirewallRules: [{E09A65DC-1016-4374-B24F-C51D5C9C271D}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpiscnapp.exe
FirewallRules: [{0806696B-6DBC-4C08-8443-4599A81A5346}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpofxs08.exe
FirewallRules: [{1FAFE796-DD61-4517-A113-BD35B9623AA8}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqfxt08.exe
FirewallRules: [{A7455183-1FCB-4BEC-9573-C197593A111A}] => (Allow) E:\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{439D5886-C8F2-4AAA-80DD-07D63512DB42}] => (Allow) E:\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [TCP Query User{F8A05764-C502-4EFF-9E48-B18B5BB81DB5}E:\steam\steamapps\common\dayz\dayz_x64.exe] => (Allow) E:\steam\steamapps\common\dayz\dayz_x64.exe
FirewallRules: [UDP Query User{EDE81CFD-AA9E-456D-A2E5-901D214F5638}E:\steam\steamapps\common\dayz\dayz_x64.exe] => (Allow) E:\steam\steamapps\common\dayz\dayz_x64.exe
FirewallRules: [{FD08640E-7097-432A-9805-A43E83418113}] => (Allow) E:\Steam\steamapps\common\Life Is Strange\Binaries\Win32\LifeIsStrange.exe
FirewallRules: [{F67AFCB4-C9E1-494F-823E-7AB601FA0FEB}] => (Allow) E:\Steam\steamapps\common\Life Is Strange\Binaries\Win32\LifeIsStrange.exe
FirewallRules: [{7992ABED-9F02-48A5-A070-1F2907B8FABA}] => (Allow) C:\Users\Safire\Downloads\The.Sims.4.Deluxe.Edition.v1.20.60.1020.Incl.Dine.Out\The Sims 4\Game\Bin\TS4.exe
FirewallRules: [{C6EE9612-F696-42BB-885A-FBB1E027EEE2}] => (Allow) C:\Users\Safire\Downloads\The.Sims.4.Deluxe.Edition.v1.20.60.1020.Incl.Dine.Out\The Sims 4\Game\Bin\TS4.exe
FirewallRules: [{ECE5DF2E-09AB-4124-838F-B88D750EB930}] => (Allow) C:\Users\Safire\Downloads\The.Sims.4.Deluxe.Edition.v1.20.60.1020.Incl.Dine.Out\The Sims 4\Game\Bin\TS4_x64.exe
FirewallRules: [{D25D5BF8-1293-46E2-A32A-4E9DBB053C46}] => (Allow) C:\Users\Safire\Downloads\The.Sims.4.Deluxe.Edition.v1.20.60.1020.Incl.Dine.Out\The Sims 4\Game\Bin\TS4_x64.exe
FirewallRules: [{D2BBD0E6-224D-41FE-BBA6-079E5530ACE0}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{A0391E87-DD20-4830-B43B-C472C710A515}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{667C9989-A868-484F-9A60-BF6C71C10CBA}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{8A2C4B36-DFFC-416A-AE7F-AAD6D3445DEA}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{ECB3E350-CC7E-45FC-93DB-9731ABA42A38}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [TCP Query User{C18F8441-5264-4C37-929E-D7E76303F286}C:\users\safire\appdata\local\temp\i1487242227\windows\resource\jre\bin\javaw.exe] => (Allow) C:\users\safire\appdata\local\temp\i1487242227\windows\resource\jre\bin\javaw.exe
FirewallRules: [UDP Query User{861B9133-66C8-43E0-946E-39465A8EDBD6}C:\users\safire\appdata\local\temp\i1487242227\windows\resource\jre\bin\javaw.exe] => (Allow) C:\users\safire\appdata\local\temp\i1487242227\windows\resource\jre\bin\javaw.exe
FirewallRules: [{E25FAF38-BD85-42F1-8592-3A2E71EEB191}] => (Allow) E:\Steam\steamapps\common\Sid Meier's Civilization V\Launcher.exe
FirewallRules: [{401FCC55-E7CE-48FE-8672-7DD4861C56F9}] => (Allow) E:\Steam\steamapps\common\Sid Meier's Civilization V\Launcher.exe
FirewallRules: [TCP Query User{17DBA1FD-F883-4880-94CC-E605E5BDC84E}C:\users\safire\appdata\local\temp\is-ld4b1.tmp\download\minithunderplatform.exe] => (Allow) C:\users\safire\appdata\local\temp\is-ld4b1.tmp\download\minithunderplatform.exe
FirewallRules: [UDP Query User{73C5010C-F107-4697-9D98-D6C9003A111F}C:\users\safire\appdata\local\temp\is-ld4b1.tmp\download\minithunderplatform.exe] => (Allow) C:\users\safire\appdata\local\temp\is-ld4b1.tmp\download\minithunderplatform.exe
FirewallRules: [{5C7318B6-85CC-4B40-A8DA-83F1A32A069D}] => (Allow) C:\Users\Safire\AppData\Local\Temp\is-LD4B1.tmp\download\MiniThunderPlatform.exe
==================== Restore Points =========================
03-02-2017 16:36:41 Scheduled Checkpoint
10-02-2017 21:56:56 Scheduled Checkpoint
18-02-2017 17:02:44 Scheduled Checkpoint
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (02/20/2017 05:47:41 PM) (Source: ATIeRecord) (EventID: 16387) (User: )
Description: ATI EEU Service event error
Error: (02/20/2017 05:47:30 PM) (Source: ATIeRecord) (EventID: 16387) (User: )
Description: ATI EEU Service event error
Error: (02/20/2017 05:30:46 PM) (Source: SideBySide) (EventID: 63) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\Razer\Razer Cortex\StreamingServicesAPI.dll.Manifest".Error in manifest or policy file "C:\Program Files (x86)\Razer\Razer Cortex\StreamingServicesAPI.dll.Manifest" on line 2.
The value "F:\joju\projects\XSplitCSDemo\RazerLauncher\Components\StreamingServicesAPI.dll" of attribute "name" in element "urn:schemas-microsoft-com:asm.v1^file" is invalid.
Error: (02/19/2017 09:03:52 PM) (Source: ATIeRecord) (EventID: 16387) (User: )
Description: ATI EEU Service event error
Error: (02/19/2017 07:00:10 PM) (Source: ATIeRecord) (EventID: 16387) (User: )
Description: ATI EEU Service event error
Error: (02/18/2017 08:17:44 PM) (Source: ATIeRecord) (EventID: 16387) (User: )
Description: ATI EEU Service event error
Error: (02/18/2017 08:17:39 PM) (Source: ATIeRecord) (EventID: 16387) (User: )
Description: ATI EEU Service event error
Error: (02/18/2017 05:03:00 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.
Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.
System Error:
Access is denied.
.
Error: (02/17/2017 08:27:26 PM) (Source: ATIeRecord) (EventID: 16387) (User: )
Description: ATI EEU Service event error
Error: (02/17/2017 08:27:21 PM) (Source: ATIeRecord) (EventID: 16387) (User: )
Description: ATI EEU Service event error
System errors:
=============
Error: (02/20/2017 05:51:13 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
and APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (02/20/2017 05:51:13 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
and APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (02/20/2017 05:51:13 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
and APPID
{F72671A9-012C-4725-9D2F-2A4D32D65169}
to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (02/20/2017 05:47:24 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (02/20/2017 05:27:10 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Windows Presentation Foundation Font Cache 3.0.0.0 service failed to start due to the following error:
The service did not respond to the start or control request in a timely fashion.
Error: (02/20/2017 05:27:10 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the FontCache3.0.0.0 service to connect.
Error: (02/20/2017 05:26:45 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
and APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (02/20/2017 05:26:45 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
and APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (02/20/2017 05:26:43 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
and APPID
{F72671A9-012C-4725-9D2F-2A4D32D65169}
to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (02/20/2017 05:25:42 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Razer Game Scanner Service service failed to start due to the following error:
The service did not respond to the start or control request in a timely fashion.
CodeIntegrity:
===================================
Date: 2017-02-11 19:27:23.764
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\amdhdl64.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-01-26 15:16:13.885
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\DriverStore\FileRepository\c0310456.inf_amd64_54a99fe241bea5ba\amdhdl64.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-01-12 16:14:57.569
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\amdhdl64.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-01-11 17:13:31.550
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\amdhdl64.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2016-12-28 20:15:57.883
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\amdhdl64.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2016-12-27 15:54:14.650
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\amdhdl64.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2016-12-26 16:57:03.820
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\amdhdl64.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2016-12-25 19:02:57.494
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\DriverStore\FileRepository\c0309792.inf_amd64_16fba8c07200efae\amdhdl64.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2016-12-17 16:29:23.037
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\amdhdl64.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2016-12-15 17:01:48.900
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\amdhdl64.dll that did not meet the Custom 3 / Antimalware signing level requirements.
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i7-4702MQ CPU @ 2.20GHz
Percentage of memory in use: 26%
Total physical RAM: 8073.11 MB
Available physical RAM: 5963.34 MB
Total Virtual: 9353.11 MB
Available Virtual: 7275.27 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:283.2 GB) (Free:81.76 GB) NTFS
Drive e: (New Volume) (Fixed) (Total:182.36 GB) (Free:93.54 GB) NTFS
Drive i: (SAMSUNG) (Fixed) (Total:698.64 GB) (Free:129.35 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 4056EB82)
Partition 1: (Active) - (Size=200 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=283.2 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=182.4 GB) - (Type=07 NTFS)
========================================================
Disk: 1 (Size: 698.6 GB) (Disk ID: 66BE3048)
Partition 1: (Active) - (Size=698.6 GB) - (Type=07 NTFS)
==================== End of Addition.txt ============================
Stáhněte AdwCleaner https://toolslib.net/downloads/viewdown ... dwcleaner/
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan<(hledání) a pak na >Clean< (mazání).
Proběhne skenováni a pak se objeví log, který sem vložte.
Uložte na plochu jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.Start
HKU\S-1-5-21-639167727-1611962213-2014225226-1001\...\Run: [51fa5df9-73ee-4efa-96ac-853c6418a27f] => C:\Program Files\8VG3U2BWP7\8VG3U2BWP.exe [370176 2017-02-20] (IAS33000000000000)
HKU\S-1-5-21-639167727-1611962213-2014225226-1001\...\Run: [b2956951-fab2-487d-ac0d-16138d77c2d2] => C:\Program Files\40SGV55LUE\SWICAKXEY.exe [370176 2017-02-20] (IAS33000000000000)
HKU\S-1-5-21-639167727-1611962213-2014225226-1001\...\Run: [baad9cf4-d497-405b-8736-78c7780c3422] => C:\Program Files\L9H6Y29HWJ\L9H6Y29HW.exe [370176 2017-02-20] (IAS33000000000000)
HKU\S-1-5-21-639167727-1611962213-2014225226-1001\...\Run: [18c294f5-8b2b-415f-a903-553cccbe3aad] => C:\Program Files\4IDBK0B7IX\732D05FC5.exe [370176 2017-02-20] (IAS33000000000000)
C:\Program Files\8VG3U2BWP7
C:\Program Files\40SGV55LUE
C:\Program Files\L9H6Y29HWJ
C:\Program Files\4IDBK0B7IX
HKU\S-1-5-21-639167727-1611962213-2014225226-1001\...\MountPoints2: {b4011332-93a8-11e6-a064-c5b9bf7a5324} - "H:\setup.exe"
HKU\S-1-5-21-639167727-1611962213-2014225226-1001\...\MountPoints2: {b60a08b8-9cff-11e6-a08a-a4db30d8d363} - "F:\LaunchU3.exe" -a
IFEO\SppExtComObj.exe: [Debugger] SppExtComObjPatcher.exe
GroupPolicy: Restriction - Chrome <======= ATTENTION
CHR StartupUrls: ChromeDefaultData2 -> "hxxp://www.youndoo.com/?z=46817d47ee5f418369f8 ... EX&type=hp"
CHR Profile: C:\Users\Safire\AppData\Local\Google\Chrome\User Data\ChromeDefaultData2 [2017-02-21] <==== ATTENTION
S1 ljkhoawh; C:\Windows\system32\drivers\ljkhoawh.sys [55168 2017-02-21] (Microsoft Corporation)
C:\Program Files\Y6T6BFBSH9
C:\Program Files (x86)\PubHotspot
C:\Users\Safire\AppData\Local\Temp
EmptyTemp:
End
autoclean;
resethosts;
emptyclsid;
IEdefaults;
FFdefaults;
CHRdefaults;
emptyIEcache;
emptyFFcache;
emptyCHRcache;
emptyalltemp;
emptyflash;
emptyjava;
emptyrecycle.bin;