Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 07-12-2016
Ran by Henry (administrator) on HENRYS-PC (11-12-2016 13:33:08)
Running from C:\Users\Henry\Desktop
Loaded Profiles: UpdatusUser & Henry (Available Profiles: UpdatusUser & Henry)
Platform: Windows 8 (X64) Language: English (United States)
Internet Explorer Version 10 (Default browser: "C:\Program Files (x86)\Boobseed\Application\chrome.exe" "%1")
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Elex do Brasil Participações Ltda) C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc.exe
(Elex do Brasil Participações Ltda) C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc2.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(ExWzp Pvt Ltd.) C:\Program Files (x86)\WinZipper\winzipersvc.exe
(ASUS) C:\Program Files\ASUS\P4G\InsOnSrv.exe
() C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSWinService.exe
(EVANGEL TECHNOLOGY (HK) LIMITED) C:\Program Files (x86)\Uncheckit\cktSvc.exe
(Intel Corporation) C:\Windows\System32\DptfParticipantProcessorService.exe
(Intel Corporation) C:\Windows\System32\DptfPolicyConfigTDPService.exe
(Intel Corporation) C:\Windows\System32\DptfPolicyCriticalService.exe
(Intel Corporation) C:\Windows\System32\DptfPolicyLpmService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(evangel technology (hk) limited) C:\Program Files (x86)\Uncheckit\UncheckitSvc.exe
() C:\Program Files (x86)\WinSaber\WinSaber.exe
(Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe
() C:\ProgramData\Boobseed\Boobseed.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
() C:\ProgramData\Monold\protect\protect.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(ASUS) C:\Program Files\ASUS\P4G\InsOnWMI.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\Splendid\ColorUService.exe
(ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe
(EVANGEL TECHNOLOGY (HK) LIMITED) C:\Program Files (x86)\Uncheckit\UncheckitBsn.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(Elex do Brasil Participações Ltda) C:\Program Files (x86)\Elex-tech\YAC\iSafeTray.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Google Inc.) C:\Program Files (x86)\Boobseed\Application\chrome.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Google Inc.) C:\Program Files (x86)\Boobseed\Application\chrome.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Google Inc.) C:\Program Files (x86)\Boobseed\Application\chrome.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Google Inc.) C:\Program Files (x86)\Boobseed\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Boobseed\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Boobseed\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Boobseed\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Boobseed\Application\chrome.exe
(Intel Corporation) C:\Windows\System32\DptfPolicyLpmServiceHelper.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\APRP\aprp.exe
(BitTorrent Inc.) C:\Users\Henry\AppData\Roaming\uTorrent\uTorrent.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
(BitTorrent Inc.) C:\Users\Henry\AppData\Roaming\uTorrent\updates\3.4.8_42576\utorrentie.exe
(BitTorrent Inc.) C:\Users\Henry\AppData\Roaming\uTorrent\updates\3.4.8_42576\utorrentie.exe
(BitTorrent Inc.) C:\Users\Henry\AppData\Roaming\uTorrent\updates\3.4.8_42576\utorrentie.exe
(Google Inc.) C:\Program Files (x86)\Boobseed\Application\chrome.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AsusVibe\AsusVibe2.0.exe
(Google Inc.) C:\Program Files (x86)\Boobseed\Application\chrome.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.2.9200.17516_none_6276a5b950d43361\TiWorker.exe
(Google Inc.) C:\Program Files (x86)\Boobseed\Application\chrome.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
(Google Inc.) C:\Program Files (x86)\Boobseed\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe
(Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13550152 2013-05-29] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1308232 2013-05-19] (Realtek Semiconductor)
HKLM\...\Run: [DptfPolicyLpmServiceHelper] => C:\Windows\system32\DptfPolicyLpmServiceHelper.exe [79376 2013-04-21] (Intel Corporation)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [35736 2010-11-15] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [932288 2010-11-15] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [3187360 2013-05-01] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [ASUSWebStorage] => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSPanel.exe [3576784 2012-12-18] (ASUS Cloud Corporation)
HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [93296 2012-07-13] (CyberLink Corp.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3165863131-4061258348-4272814689-1002\...\Run: [uTorrent] => C:\Users\Henry\AppData\Roaming\uTorrent\updates\3.4.8_42576.exe [2139840 2016-09-09] (BitTorrent Inc.)
HKU\S-1-5-21-3165863131-4061258348-4272814689-1002\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [4177784 2016-01-15] (Disc Soft Ltd)
HKU\S-1-5-21-3165863131-4061258348-4272814689-1002\...\MountPoints2: {4b316864-d25c-11e5-be75-d850e62170d6} - "F:\autorun.exe"
AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [245872 2013-04-13] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [201576 2013-04-13] (NVIDIA Corporation)
ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
ShellIconOverlayIdentifiers: [!AsusWSShellExt_B] -> {6D4133E5-0742-4ADC-8A8C-9303440F7190} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\ASUSWSShellExt64.dll [2012-09-26] (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: [!AsusWSShellExt_O] -> {64174815-8D98-4CE6-8646-4C039977D808} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\ASUSWSShellExt64.dll [2012-09-26] (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: [!AsusWSShellExt_U] -> {1C5AB7B1-0B38-4EC4-9093-7FD277E2AF4D} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\ASUSWSShellExt64.dll [2012-09-26] (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{5EA9927B-FEFB-444B-8996-E6706E1D16D9}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{A48A1144-E592-436D-A3AB-5043E4DF76E4}: [DhcpNameServer] 192.168.0.1
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-3165863131-4061258348-4272814689-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-3165863131-4061258348-4272814689-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus13.msn.com
HKU\S-1-5-21-3165863131-4061258348-4272814689-1002\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-3165863131-4061258348-4272814689-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus13.msn.com
SearchScopes: HKU\S-1-5-21-3165863131-4061258348-4272814689-1002 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3165863131-4061258348-4272814689-1002 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-11-15] (Adobe Systems Incorporated)
FireFox:
========
FF ProfilePath: C:\Users\Henry\AppData\Roaming\Mozilla\Firefox\Profiles\wzxf6lld.default-1477887815478 [2016-10-30]
FF Extension: (Firefox Hotfix) - C:\Users\Henry\AppData\Roaming\Mozilla\Firefox\Profiles\wzxf6lld.default-1477887815478\Extensions\firefox-hotfix@mozilla.org.xpi [2016-10-30]
FF HKLM-x32\...\Firefox\Extensions: [arthurj8283@gmail.com] - C:\Users\Henry\AppData\Roaming\Mozilla\Firefox\Profiles\zxsmw4me.default\extensions\arthurj8283@gmail.com => not found
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.5.29 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-05-31] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-05-31] (Intel Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-09-12] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-30] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-30] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2012-10-12] ()
FF Plugin HKU\S-1-5-21-3165863131-4061258348-4272814689-1002: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2016-02-16] ()
Chrome:
=======
CHR HomePage: Default -> hxxp://
www.nicesearches.com?type=hp&ts=1465255371&from=d1e20606&uid=st1000lm024xhn-m101mbb_s2y4j9bd907249&z=9a504b42652b5304732c86ag3z5qew5g8t1e7w4z7m
CHR StartupUrls: Default -> "hxxp://
www.nicesearches.com?type=hp&ts=1465255371&from=d1e20606&uid=st1000lm024xhn-m101mbb_s2y4j9bd907249&z=9a504b42652b5304732c86ag3z5qew5g8t1e7w4z7m"
CHR DefaultSearchURL: Default -> hxxp://
www.nicesearches.com/search.php?type=ds&ts=1465255371&from=d1e20606&uid=st1000lm024xhn-m101mbb_s2y4j9bd907249&z=9a504b42652b5304732c86ag3z5qew5g8t1e7w4z7m&q={searchTerms}
CHR DefaultSearchKeyword: Default -> nice
CHR Profile: C:\Users\Henry\AppData\Local\Google\Chrome\User Data\Default [2016-10-30]
CHR Extension: (Google Slides) - C:\Users\Henry\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-02-13]
CHR Extension: (Google Docs) - C:\Users\Henry\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-02-13]
CHR Extension: (Google Drive) - C:\Users\Henry\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-02-13]
CHR Extension: (YouTube) - C:\Users\Henry\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-02-13]
CHR Extension: (Adblock Plus) - C:\Users\Henry\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-10-30]
CHR Extension: (Google Search) - C:\Users\Henry\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-02-13]
CHR Extension: (Google Sheets) - C:\Users\Henry\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-02-13]
CHR Extension: (Google Docs Offline) - C:\Users\Henry\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-16]
CHR Extension: (AdBlock) - C:\Users\Henry\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-10-30]
CHR Extension: (Hearthstone Linkifier) - C:\Users\Henry\AppData\Local\Google\Chrome\User Data\Default\Extensions\hgfciolhdhbagnccplcficnahgleflam [2016-10-30]
CHR Extension: (Akatsuki Clouds) - C:\Users\Henry\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgankgbmohecnigpfaimapoedpabiojf [2016-03-11]
CHR Extension: (Reddit Enhancement Suite) - C:\Users\Henry\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbmfpngjjgdllneeigpgjifpgocmfgmb [2016-10-30]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Henry\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-10]
CHR Extension: (Checker Plus for Gmail™) - C:\Users\Henry\AppData\Local\Google\Chrome\User Data\Default\Extensions\oeopbcgkkoapgobdbedcemjljbihmemj [2016-10-30]
CHR Extension: (Gmail) - C:\Users\Henry\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-02-13]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 ASUS InstantOn; C:\Program Files\ASUS\P4G\InsOnSrv.exe [277120 2013-04-29] (ASUS)
R2 Asus WebStorage Windows Service; C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSWinService.exe [72192 2012-12-18] () [File not signed]
R2 BoobseedP; C:\ProgramData\Boobseed\Boobseed.exe [450944 2016-08-02] ()
S2 BoobseedU; C:\Program Files (x86)\Boobseed\Update\BoobseedUpdate.exe [601984 2016-08-02] ()
R2 cktSvc; C:\Program Files (x86)\Uncheckit\cktSvc.exe [274152 2016-08-23] (EVANGEL TECHNOLOGY (HK) LIMITED)
R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1369464 2016-01-15] (Disc Soft Ltd)
R2 DptfParticipantProcessorService; C:\Windows\system32\DptfParticipantProcessorService.exe [83032 2013-04-21] (Intel Corporation)
R2 DptfPolicyConfigTDPService; C:\Windows\system32\DptfPolicyConfigTDPService.exe [100032 2013-04-21] (Intel Corporation)
R2 DptfPolicyCriticalService; C:\Windows\system32\DptfPolicyCriticalService.exe [84568 2013-04-21] (Intel Corporation)
R2 DptfPolicyLpmService; C:\Windows\system32\DptfPolicyLpmService.exe [92864 2013-04-21] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-11] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel(R) Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-05-31] (Intel Corporation)
R2 iSafeService; C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc.exe [118048 2016-05-22] (Elex do Brasil Participações Ltda)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-05-31] (Intel Corporation)
R2 Monold_protect; C:\ProgramData\Monold\protect\protect.exe [302976 2016-05-18] ()
S2 Monold_update; C:\Program Files (x86)\Monold\Monold\bin\Monold_server.exe [487296 2016-05-18] ()
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2016-02-16] ()
R2 UncheckitSvc; C:\Program Files (x86)\Uncheckit\UncheckitSvc.exe [247528 2016-08-23] (evangel technology (hk) limited)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16056 2015-07-06] (Microsoft Corporation)
R2 winsaber; C:\Program Files (x86)\WinSaber\WinSaber.exe [443672 2016-08-01] ()
R2 winzipersvc; C:\Program Files (x86)\WinZipper\winzipersvc.exe [1254960 2016-08-23] (ExWzp Pvt Ltd.) [File not signed] <==== ATTENTION
S2 McAPExe; "C:\Program Files\McAfee\MSC\McAPExe.exe" [X]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [65784 2013-05-28] (ASUS Corporation)
R3 DptfDevPch; C:\Windows\system32\DRIVERS\DptfDevPch.sys [57216 2013-04-21] (Intel Corporation)
R3 DptfDevProc; C:\Windows\system32\DRIVERS\DptfDevProc.sys [120256 2013-04-21] (Intel Corporation)
R3 DptfManager; C:\Windows\system32\DRIVERS\DptfManager.sys [200808 2013-04-21] (Intel Corporation)
R3 dtlitescsibus; C:\Windows\System32\drivers\dtlitescsibus.sys [30264 2016-02-14] (Disc Soft Ltd)
R3 dtliteusbbus; C:\Windows\System32\drivers\dtliteusbbus.sys [47672 2016-02-14] (Disc Soft Ltd)
R1 iSafeKrnl; C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnl.sys [262344 2016-05-22] (Elex do Brasil Participações Ltda)
S3 iSafeKrnlBoot; C:\Windows\System32\DRIVERS\iSafeKrnlBoot.sys [55056 2016-05-22] (Elex do Brasil Participações Ltda)
R1 iSafeKrnlKit; C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlKit.sys [110112 2016-05-22] (Elex do Brasil Participações Ltda)
R1 iSafeKrnlMon; C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlMon.sys [52440 2016-05-22] (Elex do Brasil Participações Ltda)
R1 iSafeKrnlR3; C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlR3.sys [103904 2016-05-22] (Elex do Brasil Participações Ltda)
R1 iSafeNetFilter; C:\Windows\System32\DRIVERS\iSafeNetFilter.sys [52392 2016-05-18] (Elex do Brasil Participações Ltda)
R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [14992 2012-08-01] ( )
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99800 2013-05-31] (Intel Corporation)
R3 RTSPER; C:\Windows\system32\DRIVERS\RtsPer.sys [460872 2013-03-08] (RTS Corporation)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44560 2015-07-06] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [281944 2015-07-06] (Microsoft Corporation)
U0 msahci; no ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-12-11 13:33 - 2016-12-11 13:33 - 00021562 _____ C:\Users\Henry\Desktop\FRST.txt
2016-12-11 13:33 - 2016-12-11 13:33 - 00000000 ____D C:\FRST
2016-12-11 13:32 - 2016-12-11 13:32 - 02420224 _____ (Farbar) C:\Users\Henry\Downloads\FRST64.exe
2016-12-11 13:32 - 2016-12-11 13:32 - 02420224 _____ (Farbar) C:\Users\Henry\Desktop\FRST64.exe
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-12-11 13:34 - 2016-02-13 11:13 - 00000000 ____D C:\Users\Henry\AppData\Roaming\uTorrent
2016-12-11 13:33 - 2013-10-17 23:31 - 00003474 _____ C:\Windows\System32\Tasks\ASUS Live Update1
2016-12-11 13:33 - 2013-10-17 23:31 - 00003464 _____ C:\Windows\System32\Tasks\ASUS Live Update2
2016-12-11 13:31 - 2016-02-28 12:11 - 00814794 _____ C:\Windows\system32\perfh00C.dat
2016-12-11 13:31 - 2016-02-28 12:11 - 00812718 _____ C:\Windows\system32\perfh00A.dat
2016-12-11 13:31 - 2016-02-28 12:11 - 00198636 _____ C:\Windows\system32\prfh0404.dat
2016-12-11 13:31 - 2016-02-28 12:11 - 00171302 _____ C:\Windows\system32\perfc00A.dat
2016-12-11 13:31 - 2016-02-28 12:11 - 00164032 _____ C:\Windows\system32\perfc00C.dat
2016-12-11 13:31 - 2016-02-28 12:11 - 00065482 _____ C:\Windows\system32\prfc0404.dat
2016-12-11 13:31 - 2012-07-26 00:12 - 00000000 ___HD C:\Program Files\WindowsApps
2016-12-11 13:31 - 2012-07-26 00:12 - 00000000 ____D C:\Windows\AUInstallAgent
2016-12-11 13:31 - 2012-07-25 23:28 - 02969750 _____ C:\Windows\system32\PerfStringBackup.INI
2016-12-11 13:31 - 2012-07-25 21:37 - 00000000 ____D C:\Windows\Inf
2016-12-11 13:30 - 2016-05-21 00:24 - 00000000 ____D C:\Program Files (x86)\Monold
2016-12-11 13:30 - 2016-02-13 06:18 - 00000062 _____ C:\Users\Henry\AppData\Roaming\sp_data.sys
2016-12-11 13:28 - 2016-09-14 15:25 - 00000000 ____D C:\Users\Henry\AppData\LocalLow\uTorrent
2016-12-11 13:27 - 2016-04-15 16:26 - 00000922 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
==================== Files in the root of some directories =======
2016-02-13 06:18 - 2016-12-11 13:30 - 0000062 _____ () C:\Users\Henry\AppData\Roaming\sp_data.sys
2013-05-01 01:34 - 2012-09-07 03:40 - 0000256 _____ () C:\ProgramData\SetStretch.cmd
2013-05-01 01:34 - 2009-07-22 02:04 - 0024576 _____ () C:\ProgramData\SetStretch.exe
2013-05-01 01:34 - 2012-09-07 03:37 - 0000103 _____ () C:\ProgramData\SetStretch.VBS
Some files in TEMP:
====================
C:\Users\Henry\AppData\Local\Temp\bitool.dll
C:\Users\Henry\AppData\Local\Temp\DefaultPack.EXE
C:\Users\Henry\AppData\Local\Temp\McCSPInstall.dll
C:\Users\Henry\AppData\Local\Temp\mccspuninstall.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-09-03 02:01
==================== End of FRST.txt ============================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 07-12-2016
Ran by Henry (11-12-2016 13:34:35)
Running from C:\Users\Henry\Desktop
Windows 8 (X64) (2016-02-13 14:17:00)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-3165863131-4061258348-4272814689-500 - Administrator - Disabled)
Guest (S-1-5-21-3165863131-4061258348-4272814689-501 - Limited - Disabled)
Henry (S-1-5-21-3165863131-4061258348-4272814689-1002 - Administrator - Enabled) => C:\Users\Henry
UpdatusUser (S-1-5-21-3165863131-4061258348-4272814689-1001 - Limited - Enabled) => C:\Users\UpdatusUser
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
µTorrent (HKU\S-1-5-21-3165863131-4061258348-4272814689-1002\...\uTorrent) (Version: 3.4.8.42576 - BitTorrent Inc.)
Adobe Reader X MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.0.0 - Adobe Systems Incorporated)
ASUS Live Update (HKLM-x32\...\{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}) (Version: 3.2.3 - ASUS)
ASUS Power4Gear Hybrid (HKLM\...\{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}) (Version: 3.0.2 - ASUS)
ASUS Screen Saver (HKLM\...\{0FBEEDF8-30FA-4FA3-B31F-C9C7E7E8DFA2}) (Version: 1.0.1 - ASUS)
ASUS Smart Gesture (HKLM-x32\...\{4D3286A6-F6AB-498A-82A4-E4F040529F3D}) (Version: 2.1.5 - ASUS)
ASUS Splendid Video Enhancement Technology (HKLM-x32\...\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 2.01.0005 - ASUS)
ASUS USB Charger Plus (HKLM-x32\...\{A859E3E5-C62F-4BFA-AF1D-2B95E03166AF}) (Version: 3.1.0 - ASUS)
ASUS WebStorage Sync Agent (HKLM-x32\...\ASUS WebStorage) (Version: 1.1.18.159 - ASUS Cloud Corporation)
ASUSDVD (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.4924.52 - CyberLink Corp.)
ASUSDVD (x32 Version: 10.0.4924.52 - CyberLink Corp.) Hidden
AsusVibe2.0 (HKLM-x32\...\Asus Vibe2.0) (Version: 2.0.12.309 - ASUSTEK)
ATK Package (HKLM-x32\...\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0029 - ASUS)
Azteca (x32 Version: 2.2.0.97 - WildTangent) Hidden
Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment)
Bejeweled 3 (x32 Version: 2.2.0.97 - WildTangent) Hidden
Cut the Rope (x32 Version: 3.0.2.38 - WildTangent) Hidden
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 10.2.0.0115 - Disc Soft Ltd)
Far Cry 3 (HKLM-x32\...\{E3B9C5A9-BD7A-4B56-B754-FAEA7DD6FA88}) (Version: 1.01 - Ubisoft)
Galería de fotos (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Galerie de photos (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 52.0.2743.116 - Google Inc.)
Google Update Helper (x32 Version: 1.3.31.5 - Google Inc.) Hidden
Intel(R) Dynamic Platform and Thermal Framework (HKLM-x32\...\FFD10ECE-F715-4a86-9BD8-F6F47DA5DA1C) (Version: 7.0.0.2023 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.10.1550 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.18.10.3186 - Intel Corporation)
Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 3.0.0.66956 - Intel Corporation)
Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4454.1510 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50428.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Movie Maker (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Mozilla Firefox 47.0.1 (x86 en-GB) (HKLM-x32\...\Mozilla Firefox 47.0.1 (x86 en-GB)) (Version: 47.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 47.0.1.6018 - Mozilla)
MyBitCast 2.0 (HKLM-x32\...\MyBitCast) (Version: 2.0 - ASUS)
NVIDIA Graphics Driver 311.54 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 311.54 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.13.0325 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.0325 - NVIDIA Corporation)
NVIDIA Update 1.11.3 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.11.3 - NVIDIA Corporation)
Peggle (x32 Version: 2.2.0.95 - WildTangent) Hidden
Penguins! (x32 Version: 2.2.0.98 - WildTangent) Hidden
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.993 - Even Balance, Inc.)
qksee (HKLM-x32\...\qksee) (Version: - Taiwan Shui Mu Chih Ching Technology Limited) <==== ATTENTION
Qualcomm Atheros Client Installation Program (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 10.0 - Qualcomm Atheros)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.16.614.2013 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6937 - Realtek Semiconductor Corp.)
Realtek PCIE Card Reader (HKLM-x32\...\{C9661090-C134-46E8-90B2-76D72355C2A6}) (Version: 6.2.9200.21224 - Realtek Semiconductor Corp.)
Shared C Run-time for x64 (HKLM\...\{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee)
Tales of Lagoona (x32 Version: 2.2.0.110 - WildTangent) Hidden
Uncheckit (HKLM-x32\...\Uncheckit) (Version: 2.2.2 - EVANGEL TECHNOLOGY (HK) LIMITED) <==== ATTENTION
Update Installer for WildTangent Games App (x32 Version: - WildTangent) Hidden
Uplay (HKLM-x32\...\Uplay) (Version: 2.0 - Ubisoft)
WildTangent Games (HKLM-x32\...\WildTangent wildgames Master Uninstall) (Version: 1.0.0.0 - WildTangent)
WildTangent Games App (x32 Version: 4.0.10.5 - WildTangent) Hidden
Windows Driver Package - ASUS (ATP) Mouse (05/09/2013 1.0.0.173) (HKLM\...\1016059FBF327ED9E3BAE758BD08CF10D3C6252D) (Version: 05/09/2013 1.0.0.173 - ASUS)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3505.0912 - Microsoft Corporation)
WinFlash (HKLM-x32\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 2.42.0 - ASUS)
WinRAR 5.31 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 5.31.0 - win.rar GmbH)
WinZip (HKLM-x32\...\WinZip) (Version: 2.2.98 - Winzipper Pvt Ltd.) <==== ATTENTION
YAC(Yet Another Cleaner!) (HKLM-x32\...\iSafe) (Version: - ELEX DO BRASIL PARTICIPAÇÕES LTDA) <==== ATTENTION
yessearches Uninstall (HKLM-x32\...\Uninstall dam) (Version: - ) <==== ATTENTION
影像中心 (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
照片库 (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {06E56DF0-D70F-4CA1-95E1-CD6E0C4FE206} - System32\Tasks\WinTaske => C:\Program Files (x86)\WinTaske\WinTaske\WinTaske.exe <==== ATTENTION
Task: {0A06E085-4523-4EF3-AB9D-93A389A2E517} - System32\Tasks\ASUS Smart Gesture Launcher => C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLauncher.exe [2013-05-28] (AsusTek)
Task: {223B3F83-503E-4444-8201-7141D03C5A7F} - System32\Tasks\UncheckitUpdateTaskC => C:\Program Files (x86)\Uncheckit\UncheckitUpdate.exe [2016-08-23] (EVANGEL TECHNOLOGY (HK) LIMITED) <==== ATTENTION
Task: {285D064D-96F0-4281-8029-DE576912A6A3} - System32\Tasks\ASUS Live Update1 => C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe [2013-05-21] (ASUSTeK Computer Inc.)
Task: {357A2A3B-D2C5-422E-9A23-391C36ACD61A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-04-15] (Google Inc.)
Task: {4950A0EC-0CFC-43C4-AD7B-2ACDBFCDE82D} - System32\Tasks\ASUS Live Update2 => C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe [2013-05-21] (ASUSTeK Computer Inc.)
Task: {599755E9-4450-4CC6-85FB-9F53C3E82544} - System32\Tasks\BoobseedUpdateTaskMachineUA => C:\Program Files (x86)\Boobseed\Update\BoobseedUpdate.exe [2016-08-02] () <==== ATTENTION
Task: {6077B886-F97D-4BA1-834A-EBD18561DE5B} - System32\Tasks\ASUS Splendid ColorU => C:\Program Files (x86)\ASUS\Splendid\ColorUService.exe [2013-02-26] (ASUSTeK Computer Inc.)
Task: {6EECAF16-8137-416B-B11C-4DE2A492FBDA} - System32\Tasks\AsusVibeSchedule => C:\Program Files (x86)\Asus\AsusVibe\AsusVibeLauncher.exe [2013-01-04] ()
Task: {8B401A51-A87F-4754-AB4E-3DADD37DAC8F} - System32\Tasks\BoobseedUpdateTaskMachineCore => C:\Program Files (x86)\Boobseed\Update\BoobseedUpdate.exe [2016-08-02] () <==== ATTENTION
Task: {9F38C70F-107D-42B4-A80F-186DEB9E2F26} - System32\Tasks\MonoldBrowserUpdateCore => C:\Program Files (x86)\Monold\Monold\bin\Monold_server.exe [2016-05-18] () <==== ATTENTION
Task: {A095D84A-1076-4B13-94BF-7DD01AD88C34} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-04-15] (Google Inc.)
Task: {A365A610-85FC-45D3-9EDA-3045E8B15C27} - System32\Tasks\ASUS InstantOn Config => C:\Program Files\ASUS\P4G\InsOnCfg.exe
Task: {A81112D8-6B67-4A1B-B45B-ADD3FFCB32CF} - System32\Tasks\UncheckitUpdateTaskDB => C:\Program Files (x86)\Uncheckit\UncheckitUpdate.exe [2016-08-23] (EVANGEL TECHNOLOGY (HK) LIMITED) <==== ATTENTION
Task: {C272A9E2-A4BD-4804-82C2-17739E54DFEC} - System32\Tasks\ASUS USB Charger Plus => C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [2013-03-26] (ASUSTek Computer Inc.)
Task: {C992D46B-721A-4EF9-9B54-BE2560090865} - System32\Tasks\ASUS Splendid ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2012-11-28] (ASUS)
Task: {D439BFAE-8DA9-433F-BAC0-118D1C126E17} - System32\Tasks\Browser Updater Task(Core) => C:\Program Files (x86)\QQBrowser\Update\Download\F7D3B1F7CB6A32C3CB90685798204DC4\Update\BrowserUpdate.exe [2016-03-16] (Tencent) <==== ATTENTION
Task: {DA073D38-6890-41BF-B946-EEDB7D0C7A16} - System32\Tasks\ASUS P4G => C:\Program Files\ASUS\P4G\BatteryLife.exe [2013-04-29] (ASUS)
Task: {DAF748EB-53B2-45B2-AC58-B35F6E246078} - System32\Tasks\MonoldCheckTask => C:\Program Files (x86)\Monold\Monold\bin\Monold_server.exe [2016-05-18] () <==== ATTENTION
Task: {DE9E8145-B642-4593-8E51-C9890743CCEC} - System32\Tasks\Microsoft\Windows\Setup\EOSNotify => C:\Windows\system32\EOSNotify.exe [2016-06-25] (Microsoft Corporation)
Task: {E420165E-8663-4881-A774-283B7C18B28D} - System32\Tasks\MonoldBrowserUpdateUA => C:\Program Files (x86)\Monold\Monold\bin\Monold_server.exe [2016-05-18] () <==== ATTENTION
Task: {FC0ACBFD-ECFF-43AC-B6F1-2B297044E62D} - System32\Tasks\UncheckitTaskMN => C:\Program Files (x86)\Uncheckit\cktSvc.exe [2016-08-23] (EVANGEL TECHNOLOGY (HK) LIMITED) <==== ATTENTION
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Shortcuts =============================
(The entries could be listed to be restored or removed.)
Shortcut: C:\Users\Henry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk -> C:\Program Files (x86)\Boobseed\Application\chrome.exe (Google Inc.)
Shortcut: C:\Users\Henry\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Boobseed\Application\chrome.exe (Google Inc.)
Shortcut: C:\Users\Henry\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Boobseed\Application\chrome.exe (Google Inc.)
==================== Loaded Modules (Whitelisted) ==============
2012-12-18 22:10 - 2012-12-18 22:10 - 00072192 _____ () C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSWinService.exe
2016-02-16 07:08 - 2016-02-16 07:08 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2016-08-02 21:42 - 2016-08-01 18:42 - 00443672 _____ () C:\Program Files (x86)\WinSaber\WinSaber.exe
2016-08-02 21:53 - 2016-08-02 00:07 - 00450944 _____ () C:\ProgramData\Boobseed\Boobseed.exe
2016-05-21 00:28 - 2016-05-18 23:13 - 00302976 _____ () C:\ProgramData\Monold\protect\protect.exe
2013-04-29 15:03 - 2013-04-29 15:03 - 00031360 _____ () C:\Program Files\ASUS\P4G\DevMng.dll
2016-05-21 00:31 - 2016-05-22 18:37 - 00065696 _____ () C:\Program Files (x86)\Elex-tech\YAC\zlib1.dll
2016-03-24 22:33 - 2015-12-29 21:34 - 00582144 _____ () C:\Program Files (x86)\WinZipper\curlpp.dll
2016-03-24 22:33 - 2016-01-26 00:27 - 00066560 _____ () C:\Program Files (x86)\WinZipper\zlib1.dll
2016-08-02 21:42 - 2016-07-04 22:54 - 00068432 _____ () C:\Program Files (x86)\Uncheckit\zlib1.dll
2013-10-17 23:14 - 2013-05-31 12:30 - 01199576 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
2016-08-02 21:42 - 2016-05-25 02:28 - 00179200 _____ () C:\Program Files (x86)\Uncheckit\libpng.dll
2016-05-21 00:31 - 2016-05-22 18:37 - 00179200 _____ () C:\Program Files (x86)\Elex-tech\YAC\libpng.dll
2016-08-02 21:53 - 2016-08-02 00:07 - 01763200 _____ () C:\Program Files (x86)\Boobseed\Application\libglesv2.dll
2016-08-02 21:53 - 2016-08-02 00:07 - 00085888 _____ () C:\Program Files (x86)\Boobseed\Application\libegl.dll
2013-04-27 09:24 - 2013-04-27 09:24 - 00071680 _____ () C:\Program Files (x86)\ASUS\ASUS Live Update\checkmetro.dll
2016-08-02 21:53 - 2016-05-23 23:28 - 17565848 _____ () C:\Program Files (x86)\Boobseed\Application\PepperFlash\pepflashplayer.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2012-07-25 21:26 - 2016-10-30 20:35 - 00002024 ____A C:\Windows\system32\Drivers\etc\hosts
0.0.0.0 0.0.0.0 # fix for traceroute and netstat display anomaly
0.0.0.0 tracking.opencandy.com.s3.amazonaws.com
0.0.0.0 media.opencandy.com
0.0.0.0 cdn.opencandy.com
0.0.0.0 tracking.opencandy.com
0.0.0.0 api.opencandy.com
0.0.0.0 api.recommendedsw.com
0.0.0.0 installer.betterinstaller.com
0.0.0.0 installer.filebulldog.com
0.0.0.0 d3oxtn1x3b8d7i.cloudfront.net
0.0.0.0 inno.bisrv.com
0.0.0.0 nsis.bisrv.com
0.0.0.0 cdn.file2desktop.com
0.0.0.0 cdn.goateastcach.us
0.0.0.0 cdn.guttastatdk.us
0.0.0.0 cdn.inskinmedia.com
0.0.0.0 cdn.insta.oibundles2.com
0.0.0.0 cdn.insta.playbryte.com
0.0.0.0 cdn.llogetfastcach.us
0.0.0.0 cdn.montiera.com
0.0.0.0 cdn.msdwnld.com
0.0.0.0 cdn.mypcbackup.com
0.0.0.0 cdn.ppdownload.com
0.0.0.0 cdn.riceateastcach.us
0.0.0.0 cdn.shyapotato.us
0.0.0.0 cdn.solimba.com
0.0.0.0 cdn.tuto4pc.com
0.0.0.0 cdn.appround.biz
0.0.0.0 cdn.bigspeedpro.com
0.0.0.0 cdn.bispd.com
There are 4 more lines.
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-3165863131-4061258348-4272814689-1002\Control Panel\Desktop\\Wallpaper -> C:\Windows\asus\wallpapers\asus.jpg
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [vm-monitoring-nb-session] => LPort=139
FirewallRules: [{0C2C45C0-6122-4D6E-B66D-D1A6A4ACD5DB}] => C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{4C85DDCB-8F3B-459E-8894-079FA992ABC1}] => LPort=2869
FirewallRules: [{037906A0-EA0B-4353-8B10-388C0254F270}] => LPort=1900
FirewallRules: [{12223DA3-0792-46D5-8D6A-36EFF3A47494}] => C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{F2B31906-DD6A-45A3-91FF-FE0E3A77208F}] => C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{6103B7E1-47E4-48DC-BEAC-BDE37CE9FC7C}] => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{CEC9A049-11C5-4FDA-8454-772A28BA8270}] => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{F90E16CD-A972-4220-898D-BB8C78DAD58A}] => C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD Cinema\PowerDVDCinema10.exe
FirewallRules: [{3A938B08-1D81-4522-A94F-36828FAF6055}] => C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD10.EXE
FirewallRules: [{D69B37F7-32D3-4800-AFE9-476A0A2C7F0D}] => C:\Users\Henry\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{9C612A31-87EC-4D90-B0B1-386C3DA19B99}] => C:\Users\Henry\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{AED34AD9-4287-4112-B55B-1D6C4DE55907}] => C:\Users\Henry\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{4B6E3C0F-B4B9-4183-ABBA-242BFE442108}] => C:\Users\Henry\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{6C97BDE0-0E47-4EF9-A9F5-6DFDEA44D450}] => C:\Users\Henry\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{8568269E-A3C5-40D8-86EA-A0F15C705043}] => C:\Users\Henry\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{ED3DBDF2-4AA4-4142-88AF-4385684A11AC}] => C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{06F25CE0-5B82-4DE8-9E29-8843B950EB7F}] => C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{F8F36F10-5AE3-4B88-BA32-F6F6339DA4DE}] => C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{FCDF4CEB-EFCC-44F4-868F-D033D60C4527}] => C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{933C102E-ED87-425A-88DB-6DF1091C475A}] => C:\Program Files (x86)\Ubisoft\FarCry 3\bin\farcry3.exe
FirewallRules: [{9EF04E6E-3BE2-48C9-B3F0-E54252175DB9}] => C:\Program Files (x86)\Ubisoft\FarCry 3\bin\farcry3.exe
FirewallRules: [{1CF057F9-632E-4332-AF6B-90D8AB3F2BE2}] => C:\Program Files (x86)\Ubisoft\FarCry 3\bin\farcry3_d3d11.exe
FirewallRules: [{C191E264-82CD-4DE3-AB00-ABD92A033DB3}] => C:\Program Files (x86)\Ubisoft\FarCry 3\bin\farcry3_d3d11.exe
FirewallRules: [{C8410933-9E15-40F7-8926-B97454FFF941}] => C:\Program Files (x86)\Ubisoft\FarCry 3\bin\FC3Updater.exe
FirewallRules: [{C322BB00-8540-40EE-B06F-A3AC26688E64}] => C:\Program Files (x86)\Ubisoft\FarCry 3\bin\FC3Updater.exe
FirewallRules: [{0FE769FB-4ED2-4548-B725-828C2DA041FB}] => C:\Program Files (x86)\Ubisoft\FarCry 3\bin\FC3Editor.exe
FirewallRules: [{0D6CF7A4-B1D6-4E10-AF9E-7B7A27B6AB2C}] => C:\Program Files (x86)\Ubisoft\FarCry 3\bin\FC3Editor.exe
FirewallRules: [{FE1236F1-4E46-464B-A355-9590A5D9748D}] => C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [TCP Query User{A70B1952-6311-4B1A-AD85-97D9B0E877FF}C:\program files (x86)\hearthstone\hearthstone.exe] => C:\program files (x86)\hearthstone\hearthstone.exe
FirewallRules: [UDP Query User{35BA761B-0587-451D-9334-84913057E632}C:\program files (x86)\hearthstone\hearthstone.exe] => C:\program files (x86)\hearthstone\hearthstone.exe
FirewallRules: [{6EE1DFA7-66BF-4BBD-A379-2CA3C84B8C87}] => C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{FEECA456-4DC9-4A45-9C1F-88784ABCF930}] => C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{54657F99-2AC8-42CB-979D-93E5EB9E9DCE}] => C:\Program Files (x86)\Boobseed\Update\BoobseedUpdate.exe
FirewallRules: [{C4AE6192-584D-42E7-88D9-FEC8101C4CDD}] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{B7EB0D53-4FC4-45A4-91DD-30FFA4074741}] => C:\ProgramData\Monold\protect\protect.exe
FirewallRules: [{F804E634-D551-4471-A5A6-77A896D9EE2C}] => C:\Program Files (x86)\Monold\Monold\chrome.exe
FirewallRules: [{C8CC9D54-CEEB-44F0-B248-493D38F40F57}] => C:\Program Files (x86)\Monold\Monold\bin\Monold_server.exe
==================== Restore Points =========================
19-08-2016 23:54:43 Scheduled Checkpoint
27-08-2016 02:01:07 Scheduled Checkpoint
03-09-2016 02:02:07 Scheduled Checkpoint
==================== Faulty Device Manager Devices =============
Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft Teredo Tunneling Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (12/11/2016 01:31:35 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: BrowserUpdate.exe, version: 9.3.6494.400, time stamp: 0x5697910d
Faulting module name: 798204DC4\Update\chrome_elf.dll, version: 6.2.9200.17581, time stamp: 0x5644f0df
Exception code: 0xc0000135
Fault offset: 0x00078dd2
Faulting process id: 0x1a30
Faulting application start time: 0x01d253f5f0d91dc5
Faulting application path: C:\Program Files (x86)\QQBrowser\Update\Download\F7D3B1F7CB6A32C3CB90685798204DC4\Update\BrowserUpdate.exe
Faulting module path: 798204DC4\Update\chrome_elf.dll
Report Id: 3082334c-bfe9-11e6-be89-d850e62170d6
Faulting package full name:
Faulting package-relative application ID:
Error: (10/30/2016 08:17:52 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: BrowserUpdate.exe, version: 9.3.6494.400, time stamp: 0x5697910d
Faulting module name: 798204DC4\Update\chrome_elf.dll, version: 6.2.9200.17581, time stamp: 0x5644f0df
Exception code: 0xc0000135
Fault offset: 0x00078dd2
Faulting process id: 0x185c
Faulting application start time: 0x01d2332dba7bc90e
Faulting application path: C:\Program Files (x86)\QQBrowser\Update\Download\F7D3B1F7CB6A32C3CB90685798204DC4\Update\BrowserUpdate.exe
Faulting module path: 798204DC4\Update\chrome_elf.dll
Report Id: fd142acf-9f20-11e6-be88-a4db303fe2ab
Faulting package full name:
Faulting package-relative application ID:
Error: (09/14/2016 03:24:49 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: A problem prevented Customer Experience Improvement Program data from being sent to Microsoft, (Error 80070005).
Error: (09/09/2016 11:15:36 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: BrowserUpdate.exe, version: 9.3.6494.400, time stamp: 0x5697910d
Faulting module name: 798204DC4\Update\chrome_elf.dll, version: 6.2.9200.17581, time stamp: 0x5644f0df
Exception code: 0xc0000135
Fault offset: 0x00078dd2
Faulting process id: 0x17a8
Faulting application start time: 0x01d20b3320349f87
Faulting application path: C:\Program Files (x86)\QQBrowser\Update\Download\F7D3B1F7CB6A32C3CB90685798204DC4\Update\BrowserUpdate.exe
Faulting module path: 798204DC4\Update\chrome_elf.dll
Report Id: 5e5b2dfd-7726-11e6-be88-a4db303fe2ab
Faulting package full name:
Faulting package-relative application ID:
Error: (09/09/2016 10:11:43 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: BrowserUpdate.exe, version: 9.3.6494.400, time stamp: 0x5697910d
Faulting module name: 798204DC4\Update\chrome_elf.dll, version: 6.2.9200.17581, time stamp: 0x5644f0df
Exception code: 0xc0000135
Fault offset: 0x00078dd2
Faulting process id: 0x2408
Faulting application start time: 0x01d20b2a33cad48a
Faulting application path: C:\Program Files (x86)\QQBrowser\Update\Download\F7D3B1F7CB6A32C3CB90685798204DC4\Update\BrowserUpdate.exe
Faulting module path: 798204DC4\Update\chrome_elf.dll
Report Id: 71d15681-771d-11e6-be87-d850e62170d6
Faulting package full name:
Faulting package-relative application ID:
Error: (09/09/2016 09:11:44 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: BrowserUpdate.exe, version: 9.3.6494.400, time stamp: 0x5697910d
Faulting module name: 798204DC4\Update\chrome_elf.dll, version: 6.2.9200.17581, time stamp: 0x5644f0df
Exception code: 0xc0000135
Fault offset: 0x00078dd2
Faulting process id: 0x24ec
Faulting application start time: 0x01d20b21d270bbc6
Faulting application path: C:\Program Files (x86)\QQBrowser\Update\Download\F7D3B1F7CB6A32C3CB90685798204DC4\Update\BrowserUpdate.exe
Faulting module path: 798204DC4\Update\chrome_elf.dll
Report Id: 10722962-7715-11e6-be87-d850e62170d6
Faulting package full name:
Faulting package-relative application ID:
Error: (09/09/2016 08:11:43 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: BrowserUpdate.exe, version: 9.3.6494.400, time stamp: 0x5697910d
Faulting module name: 798204DC4\Update\chrome_elf.dll, version: 6.2.9200.17581, time stamp: 0x5644f0df
Exception code: 0xc0000135
Fault offset: 0x00078dd2
Faulting process id: 0x2494
Faulting application start time: 0x01d20b19704d1df8
Faulting application path: C:\Program Files (x86)\QQBrowser\Update\Download\F7D3B1F7CB6A32C3CB90685798204DC4\Update\BrowserUpdate.exe
Faulting module path: 798204DC4\Update\chrome_elf.dll
Report Id: ae0a5a4f-770c-11e6-be87-d850e62170d6
Faulting package full name:
Faulting package-relative application ID:
Error: (09/09/2016 07:11:44 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: BrowserUpdate.exe, version: 9.3.6494.400, time stamp: 0x5697910d
Faulting module name: 798204DC4\Update\chrome_elf.dll, version: 6.2.9200.17581, time stamp: 0x5644f0df
Exception code: 0xc0000135
Fault offset: 0x00078dd2
Faulting process id: 0x1a68
Faulting application start time: 0x01d20b110ee58d4e
Faulting application path: C:\Program Files (x86)\QQBrowser\Update\Download\F7D3B1F7CB6A32C3CB90685798204DC4\Update\BrowserUpdate.exe
Faulting module path: 798204DC4\Update\chrome_elf.dll
Report Id: 4ca2c7cb-7704-11e6-be87-d850e62170d6
Faulting package full name:
Faulting package-relative application ID:
Error: (09/09/2016 06:11:44 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: BrowserUpdate.exe, version: 9.3.6494.400, time stamp: 0x5697910d
Faulting module name: 798204DC4\Update\chrome_elf.dll, version: 6.2.9200.17581, time stamp: 0x5644f0df
Exception code: 0xc0000135
Fault offset: 0x00078dd2
Faulting process id: 0x1254
Faulting application start time: 0x01d20b08ad30b154
Faulting application path: C:\Program Files (x86)\QQBrowser\Update\Download\F7D3B1F7CB6A32C3CB90685798204DC4\Update\BrowserUpdate.exe
Faulting module path: 798204DC4\Update\chrome_elf.dll
Report Id: eb6aeace-76fb-11e6-be87-d850e62170d6
Faulting package full name:
Faulting package-relative application ID:
Error: (09/09/2016 05:11:43 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: BrowserUpdate.exe, version: 9.3.6494.400, time stamp: 0x5697910d
Faulting module name: 798204DC4\Update\chrome_elf.dll, version: 6.2.9200.17581, time stamp: 0x5644f0df
Exception code: 0xc0000135
Fault offset: 0x00078dd2
Faulting process id: 0x11c8
Faulting application start time: 0x01d20b004aeb3195
Faulting application path: C:\Program Files (x86)\QQBrowser\Update\Download\F7D3B1F7CB6A32C3CB90685798204DC4\Update\BrowserUpdate.exe
Faulting module path: 798204DC4\Update\chrome_elf.dll
Report Id: 88c79366-76f3-11e6-be87-d850e62170d6
Faulting package full name:
Faulting package-relative application ID:
System errors:
=============
Error: (12/11/2016 01:31:44 PM) (Source: DCOM) (EventID: 10016) (User: HENRYS-PC)
Description: The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID
{9BA05972-F6A8-11CF-A442-00A0C90A8F39}
and APPID
{9BA05972-F6A8-11CF-A442-00A0C90A8F39}
to the user Henrys-PC\Henry SID (S-1-5-21-3165863131-4061258348-4272814689-1002) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (12/11/2016 01:31:43 PM) (Source: DCOM) (EventID: 10016) (User: HENRYS-PC)
Description: The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID
{9BA05972-F6A8-11CF-A442-00A0C90A8F39}
and APPID
{9BA05972-F6A8-11CF-A442-00A0C90A8F39}
to the user Henrys-PC\Henry SID (S-1-5-21-3165863131-4061258348-4272814689-1002) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (12/11/2016 01:31:35 PM) (Source: DCOM) (EventID: 10016) (User: HENRYS-PC)
Description: The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID
{9BA05972-F6A8-11CF-A442-00A0C90A8F39}
and APPID
{9BA05972-F6A8-11CF-A442-00A0C90A8F39}
to the user Henrys-PC\Henry SID (S-1-5-21-3165863131-4061258348-4272814689-1002) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (12/11/2016 01:31:35 PM) (Source: DCOM) (EventID: 10016) (User: HENRYS-PC)
Description: The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID
{9BA05972-F6A8-11CF-A442-00A0C90A8F39}
and APPID
{9BA05972-F6A8-11CF-A442-00A0C90A8F39}
to the user Henrys-PC\Henry SID (S-1-5-21-3165863131-4061258348-4272814689-1002) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (12/11/2016 01:31:21 PM) (Source: DCOM) (EventID: 10016) (User: HENRYS-PC)
Description: The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID
{9BA05972-F6A8-11CF-A442-00A0C90A8F39}
and APPID
{9BA05972-F6A8-11CF-A442-00A0C90A8F39}
to the user Henrys-PC\Henry SID (S-1-5-21-3165863131-4061258348-4272814689-1002) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (12/11/2016 01:31:21 PM) (Source: DCOM) (EventID: 10016) (User: HENRYS-PC)
Description: The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID
{9BA05972-F6A8-11CF-A442-00A0C90A8F39}
and APPID
{9BA05972-F6A8-11CF-A442-00A0C90A8F39}
to the user Henrys-PC\Henry SID (S-1-5-21-3165863131-4061258348-4272814689-1002) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (12/11/2016 01:31:13 PM) (Source: DCOM) (EventID: 10016) (User: HENRYS-PC)
Description: The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID
{9BA05972-F6A8-11CF-A442-00A0C90A8F39}
and APPID
{9BA05972-F6A8-11CF-A442-00A0C90A8F39}
to the user Henrys-PC\Henry SID (S-1-5-21-3165863131-4061258348-4272814689-1002) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (12/11/2016 01:31:13 PM) (Source: DCOM) (EventID: 10016) (User: HENRYS-PC)
Description: The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID
{9BA05972-F6A8-11CF-A442-00A0C90A8F39}
and APPID
{9BA05972-F6A8-11CF-A442-00A0C90A8F39}
to the user Henrys-PC\Henry SID (S-1-5-21-3165863131-4061258348-4272814689-1002) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (12/11/2016 01:31:04 PM) (Source: DCOM) (EventID: 10016) (User: HENRYS-PC)
Description: The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID
{9BA05972-F6A8-11CF-A442-00A0C90A8F39}
and APPID
{9BA05972-F6A8-11CF-A442-00A0C90A8F39}
to the user Henrys-PC\Henry SID (S-1-5-21-3165863131-4061258348-4272814689-1002) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (12/11/2016 01:31:04 PM) (Source: DCOM) (EventID: 10016) (User: HENRYS-PC)
Description: The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID
{9BA05972-F6A8-11CF-A442-00A0C90A8F39}
and APPID
{9BA05972-F6A8-11CF-A442-00A0C90A8F39}
to the user Henrys-PC\Henry SID (S-1-5-21-3165863131-4061258348-4272814689-1002) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i7-4500U CPU @ 1.80GHz
Percentage of memory in use: 31%
Total physical RAM: 8075.48 MB
Available physical RAM: 5544.13 MB
Total Virtual: 9483.48 MB
Available Virtual: 6681.05 MB
==================== Drives ================================
Drive c: (OS) (Fixed) (Total:372.6 GB) (Free:255.03 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive d: (DATA) (Fixed) (Total:537.8 GB) (Free:537.64 GB) NTFS
Drive f: (Far Cry 3) (CDROM) (Total:1.94 GB) (Free:0 GB) CDFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: 568814A2)
Partition: GPT.
==================== End of Addition.txt ============================