Beruflich Dokumente
Kultur Dokumente
(Only the adware programs with "Hidden" flag could be added to the fixlist to
unhide them. The adware programs should be uninstalled manually.)
(If an entry is included in the fixlist, it will be removed from the registry. The
file will not be moved unless listed separately.)
HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-BF15-
2C2B11260CE4}-03142017095255358\...\ChromeHTML: ->
C:\Users\Hers\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017095255358_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-
C0CE100EA736}\localserver32 ->
C:\Users\Hers\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017095255358_Classes\CLSID\{0E270DAA-1BE6-48F2-AC49-
555C57710721}\InprocServer32 -> %%systemroot%%\system32\shell32.dll => No File
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017095255358_Classes\CLSID\{0F22A205-CFB0-4679-8499-
A6F44A80A208}\InprocServer32 ->
C:\Users\Hers\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017095255358_Classes\CLSID\{1423F872-3F7F-4E57-B621-
8B1A9D49B448}\InprocServer32 ->
C:\Users\Hers\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017095255358_Classes\CLSID\{355EC88A-02E2-4547-9DEE-
F87426484BD1}\InprocServer32 ->
C:\Users\Hers\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017095255358_Classes\CLSID\{590C4387-5EBD-4D46-8A84-
CD0BA2EF2856}\InprocServer32 ->
C:\Users\Hers\AppData\Local\Google\Update\1.3.30.3\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017095255358_Classes\CLSID\{59B55F04-DE14-4BB8-92FF-
C4A22EF2E5F4}\InprocServer32 ->
C:\Users\Hers\AppData\Local\Google\Update\1.3.31.5\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017095255358_Classes\CLSID\{5C8C2A98-6133-4EBA-BBCC-
34D9EA01FC2E}\InprocServer32 ->
C:\Users\Hers\AppData\Local\Google\Update\1.3.28.1\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017095255358_Classes\CLSID\{78550997-5DEF-4A8A-BAF9-
D5774E87AC98}\InprocServer32 ->
C:\Users\Hers\AppData\Local\Google\Update\1.3.28.13\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017095255358_Classes\CLSID\{793EE463-1304-471C-ADF1-
68C2FFB01247}\InprocServer32 ->
C:\Users\Hers\AppData\Local\Google\Update\1.3.29.5\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017095255358_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-
AFDC81C1B309}\InprocServer32 ->
C:\Users\Hers\AppData\Local\Citrix\GoToMeeting\5530\G2MOutlookAddin64.dll => No
File
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017095255358_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-
F332194690F8}\InprocServer32 ->
C:\Users\Hers\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017095255358_Classes\CLSID\{ABECE8A0-FF84-4efb-82AE-
9B3181CE097D}\InprocServer32 -> C:\Program Files (x86)\TextPad
5\System\shellext64.dll => No File
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017095255358_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-
41373F017C9A}\InprocServer32 ->
C:\Users\Hers\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017095255358_Classes\CLSID\{CB492AF1-2CEF-4E58-BE47-
471C77D0C8BA}\InprocServer32 ->
C:\Users\Hers\AppData\Local\Google\Update\1.3.32.7\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017095255358_Classes\CLSID\{CC182BE1-84CE-4A57-B85C-
FD4BBDF78CB2}\InprocServer32 ->
C:\Users\Hers\AppData\Local\Google\Update\1.3.29.1\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017095255358_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-
2EBAE2ECE8C9}\InprocServer32 ->
C:\Users\Hers\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017095255358_Classes\CLSID\{D1EDC4F5-7F4D-4B12-906A-
614ECF66DDAF}\InprocServer32 ->
C:\Users\Hers\AppData\Local\Google\Update\1.3.28.15\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017095255358_Classes\CLSID\{e8c77137-e224-5791-b6e9-
ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative
Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems)
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017095255358_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-
948E6CB34B9F}\InprocServer32 ->
C:\Users\Hers\AppData\Local\Google\Update\1.3.32.7\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017095255358_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-
CCAB78F7711C}\InprocServer32 ->
C:\Users\Hers\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017095255358_Classes\CLSID\{FB314ED9-A251-47B7-93E1-
CDD82E34AF8B}\InprocServer32 ->
C:\Users\Hers\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017095255358_Classes\CLSID\{FB314EDA-A251-47B7-93E1-
CDD82E34AF8B}\InprocServer32 ->
C:\Users\Hers\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017095255358_Classes\CLSID\{FB314EDB-A251-47B7-93E1-
CDD82E34AF8B}\InprocServer32 ->
C:\Users\Hers\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017095255358_Classes\CLSID\{FB314EDC-A251-47B7-93E1-
CDD82E34AF8B}\InprocServer32 ->
C:\Users\Hers\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017095255358_Classes\CLSID\{FB314EDD-A251-47B7-93E1-
CDD82E34AF8B}\InprocServer32 ->
C:\Users\Hers\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017095255358_Classes\CLSID\{FB314EDE-A251-47B7-93E1-
CDD82E34AF8B}\InprocServer32 ->
C:\Users\Hers\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017095255358_Classes\CLSID\{FB314EDF-A251-47B7-93E1-
CDD82E34AF8B}\InprocServer32 ->
C:\Users\Hers\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017095255358_Classes\CLSID\{FB314EE0-A251-47B7-93E1-
CDD82E34AF8B}\InprocServer32 ->
C:\Users\Hers\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017095255358_Classes\CLSID\{FB314EE1-A251-47B7-93E1-
CDD82E34AF8B}\InprocServer32 ->
C:\Users\Hers\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017095255358_Classes\CLSID\{FB314EE2-A251-47B7-93E1-
CDD82E34AF8B}\InprocServer32 ->
C:\Users\Hers\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017095255358_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-
C426E071637F}\InprocServer32 ->
C:\Users\Hers\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017095255358_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-
3641AAAF5E9E}\InprocServer32 ->
C:\Users\Hers\AppData\Local\Google\Update\1.3.24.7\psuser_64.dll => No File
HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-BF15-
2C2B11260CE4}-03142017102154479\...\ChromeHTML: ->
C:\Users\Hers\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017102154479_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-
C0CE100EA736}\localserver32 ->
C:\Users\Hers\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017102154479_Classes\CLSID\{0E270DAA-1BE6-48F2-AC49-
555C57710721}\InprocServer32 -> %%systemroot%%\system32\shell32.dll => No File
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017102154479_Classes\CLSID\{0F22A205-CFB0-4679-8499-
A6F44A80A208}\InprocServer32 ->
C:\Users\Hers\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017102154479_Classes\CLSID\{1423F872-3F7F-4E57-B621-
8B1A9D49B448}\InprocServer32 ->
C:\Users\Hers\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017102154479_Classes\CLSID\{355EC88A-02E2-4547-9DEE-
F87426484BD1}\InprocServer32 ->
C:\Users\Hers\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017102154479_Classes\CLSID\{590C4387-5EBD-4D46-8A84-
CD0BA2EF2856}\InprocServer32 ->
C:\Users\Hers\AppData\Local\Google\Update\1.3.30.3\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017102154479_Classes\CLSID\{59B55F04-DE14-4BB8-92FF-
C4A22EF2E5F4}\InprocServer32 ->
C:\Users\Hers\AppData\Local\Google\Update\1.3.31.5\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017102154479_Classes\CLSID\{5C8C2A98-6133-4EBA-BBCC-
34D9EA01FC2E}\InprocServer32 ->
C:\Users\Hers\AppData\Local\Google\Update\1.3.28.1\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017102154479_Classes\CLSID\{78550997-5DEF-4A8A-BAF9-
D5774E87AC98}\InprocServer32 ->
C:\Users\Hers\AppData\Local\Google\Update\1.3.28.13\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017102154479_Classes\CLSID\{793EE463-1304-471C-ADF1-
68C2FFB01247}\InprocServer32 ->
C:\Users\Hers\AppData\Local\Google\Update\1.3.29.5\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017102154479_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-
AFDC81C1B309}\InprocServer32 ->
C:\Users\Hers\AppData\Local\Citrix\GoToMeeting\5530\G2MOutlookAddin64.dll => No
File
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017102154479_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-
F332194690F8}\InprocServer32 ->
C:\Users\Hers\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017102154479_Classes\CLSID\{ABECE8A0-FF84-4efb-82AE-
9B3181CE097D}\InprocServer32 -> C:\Program Files (x86)\TextPad
5\System\shellext64.dll => No File
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017102154479_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-
41373F017C9A}\InprocServer32 ->
C:\Users\Hers\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017102154479_Classes\CLSID\{CB492AF1-2CEF-4E58-BE47-
471C77D0C8BA}\InprocServer32 ->
C:\Users\Hers\AppData\Local\Google\Update\1.3.32.7\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017102154479_Classes\CLSID\{CC182BE1-84CE-4A57-B85C-
FD4BBDF78CB2}\InprocServer32 ->
C:\Users\Hers\AppData\Local\Google\Update\1.3.29.1\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017102154479_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-
2EBAE2ECE8C9}\InprocServer32 ->
C:\Users\Hers\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017102154479_Classes\CLSID\{D1EDC4F5-7F4D-4B12-906A-
614ECF66DDAF}\InprocServer32 ->
C:\Users\Hers\AppData\Local\Google\Update\1.3.28.15\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017102154479_Classes\CLSID\{e8c77137-e224-5791-b6e9-
ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative
Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems)
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017102154479_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-
948E6CB34B9F}\InprocServer32 ->
C:\Users\Hers\AppData\Local\Google\Update\1.3.32.7\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017102154479_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-
CCAB78F7711C}\InprocServer32 ->
C:\Users\Hers\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017102154479_Classes\CLSID\{FB314ED9-A251-47B7-93E1-
CDD82E34AF8B}\InprocServer32 ->
C:\Users\Hers\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017102154479_Classes\CLSID\{FB314EDA-A251-47B7-93E1-
CDD82E34AF8B}\InprocServer32 ->
C:\Users\Hers\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017102154479_Classes\CLSID\{FB314EDB-A251-47B7-93E1-
CDD82E34AF8B}\InprocServer32 ->
C:\Users\Hers\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017102154479_Classes\CLSID\{FB314EDC-A251-47B7-93E1-
CDD82E34AF8B}\InprocServer32 ->
C:\Users\Hers\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017102154479_Classes\CLSID\{FB314EDD-A251-47B7-93E1-
CDD82E34AF8B}\InprocServer32 ->
C:\Users\Hers\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017102154479_Classes\CLSID\{FB314EDE-A251-47B7-93E1-
CDD82E34AF8B}\InprocServer32 ->
C:\Users\Hers\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017102154479_Classes\CLSID\{FB314EDF-A251-47B7-93E1-
CDD82E34AF8B}\InprocServer32 ->
C:\Users\Hers\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017102154479_Classes\CLSID\{FB314EE0-A251-47B7-93E1-
CDD82E34AF8B}\InprocServer32 ->
C:\Users\Hers\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017102154479_Classes\CLSID\{FB314EE1-A251-47B7-93E1-
CDD82E34AF8B}\InprocServer32 ->
C:\Users\Hers\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017102154479_Classes\CLSID\{FB314EE2-A251-47B7-93E1-
CDD82E34AF8B}\InprocServer32 ->
C:\Users\Hers\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017102154479_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-
C426E071637F}\InprocServer32 ->
C:\Users\Hers\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017102154479_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-
3641AAAF5E9E}\InprocServer32 ->
C:\Users\Hers\AppData\Local\Google\Update\1.3.24.7\psuser_64.dll => No File
HKU\S-1-5-21-4082831485-1773989390-755940452-1000\...\ChromeHTML: ->
C:\Users\Hers\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000_Classes\CLSID\
{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 ->
C:\Users\Hers\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000_Classes\CLSID\
{0E270DAA-1BE6-48F2-AC49-555C57710721}\InprocServer32 -> %%systemroot%
%\system32\shell32.dll => No File
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000_Classes\CLSID\
{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 ->
C:\Users\Hers\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000_Classes\CLSID\
{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 ->
C:\Users\Hers\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000_Classes\CLSID\
{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 ->
C:\Users\Hers\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000_Classes\CLSID\
{590C4387-5EBD-4D46-8A84-CD0BA2EF2856}\InprocServer32 ->
C:\Users\Hers\AppData\Local\Google\Update\1.3.30.3\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000_Classes\CLSID\
{59B55F04-DE14-4BB8-92FF-C4A22EF2E5F4}\InprocServer32 ->
C:\Users\Hers\AppData\Local\Google\Update\1.3.31.5\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000_Classes\CLSID\
{5C8C2A98-6133-4EBA-BBCC-34D9EA01FC2E}\InprocServer32 ->
C:\Users\Hers\AppData\Local\Google\Update\1.3.28.1\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000_Classes\CLSID\
{78550997-5DEF-4A8A-BAF9-D5774E87AC98}\InprocServer32 ->
C:\Users\Hers\AppData\Local\Google\Update\1.3.28.13\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000_Classes\CLSID\
{793EE463-1304-471C-ADF1-68C2FFB01247}\InprocServer32 ->
C:\Users\Hers\AppData\Local\Google\Update\1.3.29.5\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000_Classes\CLSID\
{84B5A313-CD5D-4904-8BA2-AFDC81C1B309}\InprocServer32 ->
C:\Users\Hers\AppData\Local\Citrix\GoToMeeting\5530\G2MOutlookAddin64.dll => No
File
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000_Classes\CLSID\
{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 ->
C:\Users\Hers\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000_Classes\CLSID\
{ABECE8A0-FF84-4efb-82AE-9B3181CE097D}\InprocServer32 -> C:\Program Files
(x86)\TextPad 5\System\shellext64.dll => No File
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000_Classes\CLSID\
{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 ->
C:\Users\Hers\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000_Classes\CLSID\
{CB492AF1-2CEF-4E58-BE47-471C77D0C8BA}\InprocServer32 ->
C:\Users\Hers\AppData\Local\Google\Update\1.3.32.7\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000_Classes\CLSID\
{CC182BE1-84CE-4A57-B85C-FD4BBDF78CB2}\InprocServer32 ->
C:\Users\Hers\AppData\Local\Google\Update\1.3.29.1\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000_Classes\CLSID\
{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 ->
C:\Users\Hers\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000_Classes\CLSID\
{D1EDC4F5-7F4D-4B12-906A-614ECF66DDAF}\InprocServer32 ->
C:\Users\Hers\AppData\Local\Google\Update\1.3.28.15\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000_Classes\CLSID\
{e8c77137-e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files
(x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems)
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000_Classes\CLSID\
{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 ->
C:\Users\Hers\AppData\Local\Google\Update\1.3.32.7\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000_Classes\CLSID\
{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 ->
C:\Users\Hers\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000_Classes\CLSID\
{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 ->
C:\Users\Hers\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000_Classes\CLSID\
{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 ->
C:\Users\Hers\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000_Classes\CLSID\
{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 ->
C:\Users\Hers\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000_Classes\CLSID\
{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 ->
C:\Users\Hers\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000_Classes\CLSID\
{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 ->
C:\Users\Hers\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000_Classes\CLSID\
{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 ->
C:\Users\Hers\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000_Classes\CLSID\
{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 ->
C:\Users\Hers\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000_Classes\CLSID\
{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 ->
C:\Users\Hers\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000_Classes\CLSID\
{FB314EE1-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 ->
C:\Users\Hers\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000_Classes\CLSID\
{FB314EE2-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 ->
C:\Users\Hers\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000_Classes\CLSID\
{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 ->
C:\Users\Hers\AppData\Roaming\Dropbox\bin\DropboxExt64.14.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1000_Classes\CLSID\
{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 ->
C:\Users\Hers\AppData\Local\Google\Update\1.3.24.7\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1022-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017095256430_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-
CF2960B8F63E}\InprocServer32 ->
C:\Users\Champ\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\amd64\FileSyncShell6
4.dll => No File
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1022-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017095256430_Classes\CLSID\{5AB7172C-9C11-405C-8DD5-
AF20F3606282}\InprocServer32 ->
C:\Users\Champ\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\amd64\FileSyncShell6
4.dll => No File
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1022-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017095256430_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-
6C3BE50D980C}\InprocServer32 ->
C:\Users\Champ\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\amd64\FileSyncShell6
4.dll => No File
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1022-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017095256430_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-
BE4C51810A9E}\InprocServer32 ->
C:\Users\Champ\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\amd64\FileSyncShell6
4.dll => No File
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1022-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017095256430_Classes\CLSID\{9AA2F32D-362A-42D9-9328-
24A483E2CCC3}\InprocServer32 ->
C:\Users\Champ\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\amd64\FileSyncShell6
4.dll => No File
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1022-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017095256430_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-
95FFCCAEF20E}\InprocServer32 ->
C:\Users\Champ\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\amd64\FileSyncShell6
4.dll => No File
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1022-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017095256430_Classes\CLSID\{A78ED123-AB77-406B-9962-
2A5D9D2F7F30}\InprocServer32 ->
C:\Users\Champ\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\amd64\FileSyncShell6
4.dll => No File
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1022-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017095256430_Classes\CLSID\{BBACC218-34EA-4666-9D7A-
C78F2274A524}\InprocServer32 ->
C:\Users\Champ\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\amd64\FileSyncShell6
4.dll => No File
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1022-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017095256430_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-
23ED75B5106B}\InprocServer32 ->
C:\Users\Champ\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\amd64\FileSyncShell6
4.dll => No File
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1022-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017095256430_Classes\CLSID\{F241C880-6982-4CE5-8CF7-
7085BA96DA5A}\InprocServer32 ->
C:\Users\Champ\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\amd64\FileSyncShell6
4.dll => No File
CustomCLSID: HKU\S-1-5-21-4082831485-1773989390-755940452-1022-{ED1FC765-E35E-4C3D-
BF15-2C2B11260CE4}-03142017095256430_Classes\CLSID\{F8071786-1FD0-4A66-81A1-
3CBE29274458}\InprocServer32 ->
C:\Users\Champ\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\amd64\FileSyncApi64.
dll => No File
(If an entry is included in the fixlist, it will be removed from the registry. The
file will not be moved unless listed separately.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The
file which is running by the task will not be moved.)
(If an entry is included in the fixlist, only the ADS will be removed.)
(If an entry is included in the fixlist, it will be removed from the registry. The
"AlternateShell" will be restored.)
(If an entry is included in the fixlist, the registry item will be restored to
default or removed.)
(If an entry is included in the fixlist, it will be removed from the registry.)
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
10.100.0.100 elsvulnerable.com
HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-03142017095255105\Control
Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-03142017102154011\Control
Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-03142017095255195\Control
Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-03142017102154253\Control
Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
HKU\S-1-5-21-4082831485-1773989390-755940452-1000\Control Panel\Desktop\\Wallpaper
-> C:\Users\Hers\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-BF15-
2C2B11260CE4}-03142017095255358\Control Panel\Desktop\\Wallpaper ->
C:\Users\Hers\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
HKU\S-1-5-21-4082831485-1773989390-755940452-1000-{ED1FC765-E35E-4C3D-BF15-
2C2B11260CE4}-03142017102154479\Control Panel\Desktop\\Wallpaper ->
C:\Users\Hers\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
HKU\S-1-5-21-4082831485-1773989390-755940452-1003-{ED1FC765-E35E-4C3D-BF15-
2C2B11260CE4}-03142017095256227\Control Panel\Desktop\\Wallpaper ->
C:\Windows\Web\Wallpaper\Windows\img0.jpg
HKU\S-1-5-21-4082831485-1773989390-755940452-1003-{ED1FC765-E35E-4C3D-BF15-
2C2B11260CE4}-03142017102155500\Control Panel\Desktop\\Wallpaper ->
C:\Windows\Web\Wallpaper\Windows\img0.jpg
HKU\S-1-5-21-4082831485-1773989390-755940452-1022-{ED1FC765-E35E-4C3D-BF15-
2C2B11260CE4}-03142017095256430\Control Panel\Desktop\\Wallpaper ->
C:\WINDOWS\web\wallpaper\Windows\img0.jpg
HKU\S-1-5-21-4082831485-1773989390-755940452-500-{ED1FC765-E35E-4C3D-BF15-
2C2B11260CE4}-03142017095256549\Control Panel\Desktop\\Wallpaper ->
C:\Windows\web\wallpaper\dell\Dell_XPS_silverswirl.jpg
HKU\S-1-5-21-4082831485-1773989390-755940452-500-{ED1FC765-E35E-4C3D-BF15-
2C2B11260CE4}-03142017102156103\Control Panel\Desktop\\Wallpaper ->
C:\Windows\web\wallpaper\dell\Dell_XPS_silverswirl.jpg
HKU\S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415-{ED1FC765-E35E-
4C3D-BF15-2C2B11260CE4}-03142017095256702\Control Panel\Desktop\\Wallpaper ->
HKU\S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415-{ED1FC765-E35E-
4C3D-BF15-2C2B11260CE4}-03142017102157055\Control Panel\Desktop\\Wallpaper ->
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System =>
(ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
(If an entry is included in the fixlist, it will be removed from the registry. The
file will not be moved unless listed separately.)
Application errors:
==================
Error: (03/14/2017 11:24:30 AM) (Source: Microsoft-Windows-Immersive-Shell)
(EventID: 2484) (User: BEAUTY)
Description: Package Microsoft.Windows.Photos_17.214.10010.0_x64__8wekyb3d8bbwe+App
was terminated because it took too long to suspend.
Error: (03/13/2017 03:01:15 PM) (Source: Microsoft Office 16) (EventID: 2000)
(User: )
Description: Microsoft Word: Accepted Safe Mode action : Word couldn't start last
time. Safe mode could help you troubleshoot the problem, but some features might
not be available in this mode.
Error: (03/13/2017 09:21:55 AM) (Source: Windows Search Service) (EventID: 3104)
(User: )
Description: Enumerating user sessions to generate filter pools failed.
Details:
(HRESULT : 0x80040210) (0x80040210)
Error: (03/13/2017 09:21:55 AM) (Source: Windows Search Service) (EventID: 3104)
(User: )
Description: Enumerating user sessions to generate filter pools failed.
Details:
(HRESULT : 0x80040210) (0x80040210)
Error: (03/13/2017 09:21:55 AM) (Source: Windows Search Service) (EventID: 3104)
(User: )
Description: Enumerating user sessions to generate filter pools failed.
Details:
(HRESULT : 0x80040210) (0x80040210)
Error: (03/13/2017 09:21:55 AM) (Source: Windows Search Service) (EventID: 3104)
(User: )
Description: Enumerating user sessions to generate filter pools failed.
Details:
(HRESULT : 0x80040210) (0x80040210)
Error: (03/13/2017 09:21:55 AM) (Source: Windows Search Service) (EventID: 3104)
(User: )
Description: Enumerating user sessions to generate filter pools failed.
Details:
(HRESULT : 0x80040210) (0x80040210)
System errors:
=============
Error: (03/14/2017 11:39:45 AM) (Source: Service Control Manager) (EventID: 7034)
(User: )
Description: The Malwarebytes Service service terminated unexpectedly. It has done
this 1 time(s).
Error: (03/11/2017 05:45:47 PM) (Source: Service Control Manager) (EventID: 7000)
(User: )
Description: The NetPipeActivator service failed to start due to the following
error:
The service did not respond to the start or control request in a timely fashion.
Error: (03/11/2017 05:45:47 PM) (Source: Service Control Manager) (EventID: 7009)
(User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the
NetPipeActivator service to connect.
Error: (03/11/2017 05:45:31 PM) (Source: Service Control Manager) (EventID: 7000)
(User: )
Description: The ClickToRunSvc service failed to start due to the following error:
The service did not respond to the start or control request in a timely fashion.
CodeIntegrity:
===================================
Date: 2017-03-03 15:56:23.691
Description: Code Integrity determined that a process
(\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe)
attempted to load
\Device\HarddiskVolume3\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f
7f11d50a3a\Microsoft.StdFormat.dll that did not meet the Microsoft signing level
requirements.