Additional scan result of Farbar Recovery Scan Tool (x64) Version:12-09-2015 Ran by [removed] (2015-09-12 11:11:32) Running from C:\Users\[removed]\Desktop Windows 10 Pro Insider Preview (X64) (2015-08-29 08:14:26) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-3387192817-1767698883-158500957-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-3387192817-1767698883-158500957-503 - Limited - Disabled) Guest (S-1-5-21-3387192817-1767698883-158500957-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-3387192817-1767698883-158500957-1002 - Limited - Enabled) martin (S-1-5-21-3387192817-1767698883-158500957-1003 - Limited - Enabled) metodiev (S-1-5-21-3387192817-1767698883-158500957-1000 - Administrator - Enabled) => C:\Users\metodiev ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Spybot - Search and Destroy (Disabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) µTorrent (HKU\S-1-5-21-3387192817-1767698883-158500957-1000\...\uTorrent) (Version: 3.4.4.40911 - BitTorrent Inc.) 7-Zip 9.38 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0938-000001000000}) (Version: 9.38.00.0 - Igor Pavlov) Adobe Acrobat 9 Pro Extended 64-bit Add-On (HKLM\...\{AC76BA86-1033-0000-0064-0003D0000004}) (Version: 9.0.0 - Adobe Systems Incorporated) Adobe Acrobat XI Pro (HKLM-x32\...\{AC76BA86-1033-FFFF-7760-000000000006}) (Version: 11.0.09 - Adobe Systems) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.1.0.4880 - Adobe Systems Incorporated) Adobe Content Viewer (HKLM-x32\...\com.adobe.dmp.contentviewer) (Version: 1.4.0 - Adobe Systems Incorporated) Adobe Dreamweaver CS6 (HKLM-x32\...\{A4ED5E53-7AA0-11E1-BF04-B2D4D4A5360E}) (Version: 12 - Adobe Systems Incorporated) Adobe Fireworks CS6 (HKLM-x32\...\{CA7C485C-7A89-11E1-B2C8-CD54B377BC52}) (Version: 12.0.0 - Adobe Systems Incorporated) Adobe Flash Player 18 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 18.0.0.232 - Adobe Systems Incorporated) Adobe Flash Player 18 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 18.0.0.232 - Adobe Systems Incorporated) Adobe Help Manager (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 4.0.244 - Adobe Systems Incorporated) Adobe Illustrator CC (HKLM-x32\...\{F2321021-08A2-44D6-B1DF-BDB415F23EC3}) (Version: 17.0 - Adobe Systems Incorporated) Adobe Illustrator CS6 (HKLM-x32\...\{4869414E-7AEA-4C8E-BE1C-8D40977FD517}) (Version: 16.0 - Adobe Systems Incorporated) Adobe InDesign CS6 (HKLM-x32\...\{CFB770D7-8D43-1014-922B-CC2715FADE3F}) (Version: 8.0 - Adobe Systems Incorporated) Adobe Photoshop CS6 (HKLM-x32\...\{74EB3499-8B95-4B5C-96EB-7B342F3FD0C6}) (Version: 13.0 - Adobe Systems Incorporated) Adobe Widget Browser (HKLM-x32\...\com.adobe.WidgetBrowser) (Version: 2.0 Build 348 - Adobe Systems Incorporated.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Belkin USB Wireless Adapter (HKLM-x32\...\InstallShield_{549CE1BD-88E4-4C5E-BF75-B155624714CC}) (Version: 1.0.0.13 - Belkin) Belkin USB Wireless Adapter (x32 Version: 1.0.0.13 - Belkin) Hidden Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) CDBurnerXP (HKLM-x32\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.5.5666 - CDBurnerXP) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden FileZilla Client 3.13.0 (HKLM-x32\...\FileZilla Client) (Version: 3.13.0 - Tim Kosse) Git version 1.9.5-preview20150319 (HKLM-x32\...\Git_is1) (Version: 1.9.5-preview20150319 - The Git Development Community) GitHub (HKU\S-1-5-21-3387192817-1767698883-158500957-1000\...\5f7eb300e2ea4ebf) (Version: 3.0.3.1 - GitHub, Inc.) Google Apps Migration For Microsoft Outlook® 3.4.27.52 (HKLM\...\{9566573E-1092-4AF3-9805-8E86146EF578}) (Version: 3.4.27.52 - Google, Inc.) Google Apps Sync™ for Microsoft Outlook® 3.7.410.1100 (HKLM\...\{6C6A2A68-E36C-4AF4-B1A3-EF3F53FF5766}) (Version: 3.7.410.1100 - Google, Inc.) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 45.0.2454.85 - Google Inc.) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.28.13 - Google Inc.) Hidden HP Officejet 6500 E710n-z Basic Device Software (HKLM\...\{D79A5962-7305-41B9-A39E-A98AB598F372}) (Version: 28.0.1315.0 - Hewlett-Packard Co.) I.R.I.S. OCR (HKLM-x32\...\{CA6BCA2F-EDEB-408F-850B-31404BE16A61}) (Version: 12.3.4.0 - HP) Intel(R) Driver Update Utility 2.0 (x32 Version: 2.0.0.29 - Intel) Hidden Intel® Driver Update Utility (HKLM-x32\...\{8409c4f7-2340-4933-a304-5d37db4fb48b}) (Version: 2.0.0.29 - Intel) Java 8 Update 51 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418051F0}) (Version: 8.0.510 - Oracle Corporation) Java SE Development Kit 8 Update 45 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0180450}) (Version: 8.0.450.15 - Oracle Corporation) Justinmind Prototyper 6.6.1 (HKLM-x32\...\Justinmind Prototyper 6.6.1) (Version: 6.6.1 - Justinmind) MEGAsync (HKLM-x32\...\MEGAsync) (Version: - Mega Limited) Meteor (HKU\S-1-5-21-3387192817-1767698883-158500957-1000\...\{a07155a2-8337-416a-ad39-34ed7cf7a482}) (Version: 1.1.0.2 - Meteor Development Group ) Meteor (x32 Version: 1.1.0.2 - Meteor Development Group ) Hidden Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation) Microsoft Office Professional Plus 2013 (HKLM\...\Office15.PROPLUS) (Version: 15.0.4569.1506 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Mozilla Firefox 40.0.3 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 40.0.3 (x86 en-US)) (Version: 40.0.3 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 40.0.3.5716 - Mozilla) Mozilla Thunderbird 31.7.0 (x86 en-US) (HKLM-x32\...\Mozilla Thunderbird 31.7.0 (x86 en-US)) (Version: 31.7.0 - Mozilla) Node.js (HKLM-x32\...\{C2AF9137-F90A-441B-8A01-157B90879273}) (Version: 0.12.3 - Joyent, Inc. and other Node contributors) Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.8.3 - Notepad++ Team) NVIDIA 3D Vision Controller Driver 352.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 352.65 - NVIDIA Corporation) NVIDIA 3D Vision Driver 355.82 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 355.82 - NVIDIA Corporation) NVIDIA GeForce Experience 2.5.12.11 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.5.12.11 - NVIDIA Corporation) NVIDIA Graphics Driver 355.82 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 355.82 - NVIDIA Corporation) NVIDIA HD Audio Driver 1.3.34.3 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.3 - NVIDIA Corporation) NVIDIA PhysX System Software 9.15.0428 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation) Opera Stable 31.0.1889.174 (HKLM-x32\...\Opera 31.0.1889.174) (Version: 31.0.1889.174 - Opera Software) Outils de vérification linguistique 2013 de Microsoft Office - Français (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden PDF Settings CC (x32 Version: 12.0 - Adobe Systems Incorporated) Hidden PDF Settings CS6 (x32 Version: 11.0 - Adobe Systems Incorporated) Hidden Plex Media Server (HKLM-x32\...\{ca5910de-4c30-4f28-b6bd-5dd8edff922d}) (Version: 0.9.1211 - Plex, Inc.) Plex Media Server (x32 Version: 0.9.1211 - Plex, Inc.) Hidden Robomongo (HKLM-x32\...\Robomongo) (Version: 0.8.5 - Paralect) Safari (HKLM-x32\...\{C779648B-410E-4BBA-B75B-5815BCEFE71D}) (Version: 5.34.57.2 - Apple Inc.) Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{D82063A8-7C8C-4C3B-A9BB-95138CA55D26}) (Version: - Microsoft) Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (Version: - Microsoft) Hidden Shark007 Advanced Codecs (HKLM-x32\...\{8C0CAA7A-3272-4991-A808-2C7559DE3409}) (Version: 5.2.6 - Shark007) SHIELD Streaming (Version: 4.1.3000 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: 2.5.12.11 - NVIDIA Corporation) Hidden SketchUp 2015 (HKLM\...\{350488A4-1540-4103-8F01-B27503891EB0}) (Version: 15.3.331 - Trimble Navigation Limited) Skype™ 7.8 (HKLM-x32\...\{6A0549A9-1B96-498C-ACBC-3943001FEB19}) (Version: 7.8.102 - Skype Technologies S.A.) Sublime Text Build 3065 (HKLM\...\Sublime Text 3_is1) (Version: - Sublime HQ Pty Ltd) SWAT 4 (HKLM-x32\...\InstallShield_{8E1CCF20-9E12-4824-BD59-7AD9E0486DD8}) (Version: 1.0.31763 - Sierra Entertainment, Inc.) SWAT 4 (x32 Version: 1.0.31763 - Sierra Entertainment, Inc.) Hidden The Sims 4 Deluxe Edition version 1.0.732.20 Update 5 (HKLM-x32\...\The Sims 4 Deluxe Edition_is1) (Version: 1.0.732.20 Update 5 - GMT-MAX.ORG) TightVNC (HKLM\...\{D2372F87-7DA2-47F7-A102-AF2181B8EAA2}) (Version: 2.7.10.0 - GlavSoft LLC.) TortoiseHg 3.4.1 (x64) (HKLM\...\{B157934A-8048-4B31-8A9B-81D1395A3E1F}) (Version: 3.4.1 - Steve Borho and others) TurboTax 2014 (HKLM-x32\...\TurboTax 2014) (Version: 2014.0 - Intuit, Inc) Update for Skype for Business 2015 (KB2889853) 64-Bit Edition (HKLM\...\{90150000-012B-0409-1000-0000000FF1CE}_Office15.PROPLUS_{40930C8E-A677-414C-A72F-DFDEB10738FB}) (Version: - Microsoft) Vector Magic (HKLM-x32\...\Vector Magic) (Version: 1.14 - Vector Magic, Inc.) Viber (HKU\S-1-5-21-3387192817-1767698883-158500957-1000\...\Viber) (Version: 5.2.0.2546 - Viber Media Inc) VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN) VMware Workstation (HKLM-x32\...\VMware_Workstation) (Version: 11.1.2 - VMware, Inc) VMware Workstation (Version: 11.1.2 - VMware, Inc.) Hidden VPN Chameleon 1.0.25 (HKLM\...\VPNArea Chameleon) (Version: 1.0.25 - VPNArea) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation) WinLess (HKLM-x32\...\{35C89D8D-26ED-4E2A-8176-EF0C11E4DE11}) (Version: 1.9.1 - Mark Lagendijk) x64 Components v5.2.6 (HKLM\...\Advanced x64Components_is1) (Version: 5.2.6 - Shark007) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-3387192817-1767698883-158500957-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\metodiev\AppData\Roaming\Dropbox\bin\Dropbox.exe /autoplay No File CustomCLSID: HKU\S-1-5-21-3387192817-1767698883-158500957-1000_Classes\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6}\InprocServer32 -> C:\Windows\system32\shell32.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3387192817-1767698883-158500957-1000_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32 -> C:\Users\metodiev\AppData\Local\Microsoft\OneDrive\17.3.5930.0814_2\amd64\FileSyncShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3387192817-1767698883-158500957-1000_Classes\CLSID\{5AB7172C-9C11-405C-8DD5-AF20F3606282}\InprocServer32 -> C:\Users\metodiev\AppData\Local\Microsoft\OneDrive\17.3.5930.0814_2\amd64\FileSyncShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3387192817-1767698883-158500957-1000_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32 -> C:\Users\metodiev\AppData\Local\Microsoft\OneDrive\17.3.5930.0814_2\amd64\FileSyncShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3387192817-1767698883-158500957-1000_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32 -> C:\Users\metodiev\AppData\Local\Microsoft\OneDrive\17.3.5930.0814_2\amd64\FileSyncShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3387192817-1767698883-158500957-1000_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\metodiev\AppData\Local\Microsoft\OneDrive\17.3.5930.0814_2\amd64\FileSyncShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3387192817-1767698883-158500957-1000_Classes\CLSID\{A78ED123-AB77-406B-9962-2A5D9D2F7F30}\InprocServer32 -> C:\Users\metodiev\AppData\Local\Microsoft\OneDrive\17.3.5930.0814_2\amd64\FileSyncShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3387192817-1767698883-158500957-1000_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\metodiev\AppData\Local\Microsoft\OneDrive\17.3.5930.0814_2\amd64\FileSyncShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3387192817-1767698883-158500957-1000_Classes\CLSID\{ca586c80-7c84-4b88-8537-726724df6929}\InprocServer32 -> C:\Program Files (x86)\Git\git-cheetah\git_shell_ext64.dll () CustomCLSID: HKU\S-1-5-21-3387192817-1767698883-158500957-1000_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\metodiev\AppData\Local\Microsoft\OneDrive\17.3.5930.0814_2\amd64\FileSyncShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3387192817-1767698883-158500957-1000_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\metodiev\AppData\Local\Microsoft\OneDrive\17.3.5930.0814_2\amd64\FileSyncShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-3387192817-1767698883-158500957-1000_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\metodiev\AppData\Local\Microsoft\OneDrive\17.3.5930.0814_2\amd64\FileSyncApi64.dll (Microsoft Corporation) ==================== Restore Points ========================= 05-09-2015 08:13:06 Windows Modules Installer 07-09-2015 15:59:00 SPTD setup V1.84 09-09-2015 17:16:18 Checkpoint by HitmanPro 11-09-2015 22:08:35 Plex Media Server ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-13 22:34 - 2015-01-29 10:43 - 00001805 ____A C:\WINDOWS\system32\Drivers\etc\hosts 127.0.0.1 3dns.adobe.com 3dns-1.adobe.com 3dns-2.adobe.com 3dns-3.adobe.com 3dns-4.adobe.com activate.adobe.com activate-sea.adobe.com activate-sjc0.adobe.com activate.wip.adobe.com 127.0.0.1 activate.wip1.adobe.com activate.wip2.adobe.com activate.wip3.adobe.com activate.wip4.adobe.com adobe-dns.adobe.com adobe-dns-1.adobe.com adobe-dns-2.adobe.com adobe-dns-3.adobe.com adobe-dns-4.adobe.com 127.0.0.1 adobeereg.com practivate.adobe practivate.adobe.com practivate.adobe.newoa practivate.adobe.ntp practivate.adobe.ipp ereg.adobe.com ereg.wip.adobe.com ereg.wip1.adobe.com 127.0.0.1 ereg.wip2.adobe.com ereg.wip3.adobe.com ereg.wip4.adobe.com hl2rcv.adobe.com wip.adobe.com wip1.adobe.com wip2.adobe.com wip3.adobe.com wip4.adobe.com 127.0.0.1 www.adobeereg.com wwis-dubc1-vip60.adobe.com www.wip.adobe.com www.wip1.adobe.com 127.0.0.1 www.wip2.adobe.com www.wip3.adobe.com www.wip4.adobe.com wwis-dubc1-vip60.adobe.com crl.verisign.net CRL.VERISIGN.NET ood.opsource.net ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {0AE5606C-06FB-4A3D-985F-346C5D03A417} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.) Task: {0B12449E-0DD8-4CD5-84E7-86814560FAE8} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\Windows\ehome\ehPrivJob.exe Task: {0B44C295-799F-488D-A1A7-B4E9635DB0A5} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\Windows\ehome\ehPrivJob.exe Task: {1043B158-923D-4FE8-BB18-FB3FED70E140} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION Task: {10BB2EE2-5C81-4033-9389-B17835BA0537} - System32\Tasks\Microsoft\Windows\Location\WindowsActionDialog => C:\Windows\System32\WindowsActionDialog.exe [2015-08-23] (Microsoft Corporation) Task: {149C1713-57E9-4414-AC58-710C1351AC39} - System32\Tasks\Microsoft\Windows\WindowsUpdate\sihboot => C:\Windows\System32\sihclient.exe [2015-08-23] (Microsoft Corporation) Task: {23D2653F-8C3F-4FD7-B859-0A965B26AF63} - System32\Tasks\{6BE1FF75-7526-43FD-83D4-5B18451D8571} => pcalua.exe -a "C:\Users\metodiev\Downloads\Alcohol 120% 2.0.2.5629 Final Retail Multilingual - {Cyclonoid}\Alcohol120_retail_2.0.2.5629.exe" -d "C:\Users\metodiev\Downloads\Alcohol 120% 2.0.2.5629 Final Retail Multilingual - {Cyclonoid}" Task: {240F0B0C-DB47-4AD5-A6F5-C6A052E12E1A} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_18_0_0_232_pepper.exe [2015-08-12] (Adobe Systems Incorporated) Task: {25BE29D6-17C5-425B-92A3-3C5FDF6ADB54} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\Windows\ehome\ehPrivJob.exe Task: {293D7432-58B7-48EF-8972-794E1D5D9682} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION Task: {2C694886-0E8E-40F9-AB8F-B56000DA9B72} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\Windows\ehome\MCUpdate.exe Task: {2E44B94C-1B2A-467D-A649-0608BA06B734} - System32\Tasks\Microsoft\Windows\Feedback\Siuf\DmClient => C:\Windows\system32\dmclient.exe [2015-08-23] (Microsoft Corporation) Task: {39237538-E247-4C12-8172-8AC7B0450165} - System32\Tasks\Microsoft\Windows\AppID\EDP Policy Manager Task: {4537D848-0AB6-4E4D-92F2-A85FF507B8AB} - System32\Tasks\Microsoft\Windows\ApplicationData\DsSvcCleanup => C:\Windows\system32\dstokenclean.exe [2015-08-23] (Microsoft Corporation) Task: {477D09E1-0C62-4ACB-B0CB-78F772D55177} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\Windows\ehome\ehPrivJob.exe Task: {4A6A06B4-E7B1-4FF4-B5B5-AACE69F30CA5} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\Windows\ehome\mcupdate.exe Task: {4CCF0449-1E21-479D-8EB0-24FBF3D2F62D} - System32\Tasks\Microsoft\Windows\Maps\MapsToastTask Task: {51C8EE5D-5EF8-4C79-8DC4-9F70B8E8CD21} - System32\Tasks\Microsoft\Windows\TPM\Tpm-HASCertRetr Task: {555D3256-A9AE-46C3-8658-E58EF4D829DF} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation) Task: {55D7E0D8-8915-40BB-BA73-A97BCCAD21F7} - System32\Tasks\Microsoft\Windows\Clip\License Validation => C:\Windows\system32\ClipUp.exe [2015-08-23] (Microsoft Corporation) Task: {57AFE7E1-E2CB-4B27-B72D-CB2216AE9E08} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.) Task: {5C94DBC2-678C-4539-9536-30B0D590E268} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\Windows\ehome\ehrec.exe Task: {62A7CF09-40B1-4FB2-BFA9-1B65E0A3A3E8} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\Windows\ehome\ehPrivJob.exe Task: {6AC985C2-1259-4721-9CF9-7836FEB63C68} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Device-Join => C:\Windows\System32\dsregcmd.exe [2015-08-23] (Microsoft Corporation) Task: {6B5FEC69-780A-4A7F-88AE-8E0C78974A21} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\Windows\ehome\mcupdate.exe Task: {7B232959-EA6E-468D-B51F-2253D63022E3} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\Windows\ehome\ehPrivJob.exe Task: {7E63D6F0-500B-49BA-8E6E-0D6D7FCADAE3} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {8035EAEE-8BD3-49A5-89AE-5042DF2BFBAE} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation) Task: {83F58BCF-BCD9-456E-BBAA-62719841339E} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION Task: {85AA372F-93D8-4B8B-97CA-0D9F2BBBB13C} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\Windows\ehome\ehPrivJob.exe Task: {886A6518-C162-42B4-9DA0-137635961BD7} - System32\Tasks\AdobeAAMUpdater-1.0-metodiev-PC-metodiev => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2014-02-27] (Adobe Systems Incorporated) Task: {8C928627-E2FF-4651-AD41-02766B389C72} - System32\Tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser => Rundll32.exe generaltel.dll,RunTelemetryW Task: {8E1874C0-9350-4FEB-B952-C18D21FA0325} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\Windows\ehome\ehPrivJob.exe Task: {8E2F9311-D32B-4BB5-8966-F9B5FFFD8275} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\Windows\ehome\mcupdate.exe Task: {8E84625F-8BC2-434E-BF08-651A317FF247} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe Task: {9A488B54-8450-44F8-A8DB-F94EE50FEA40} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\Windows\ehome\mcupdate.exe Task: {B14E8A21-0743-4FE3-9CBC-5D05CC6B1ED6} - System32\Tasks\Opera scheduled Autoupdate 1419461931 => C:\Program Files (x86)\Opera\launcher.exe [2015-08-17] (Opera Software) Task: {B47EF5A0-45B8-499D-947D-105C79FB9D60} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\Windows\ehome\ehPrivJob.exe Task: {BB5FAA2D-4FDF-48F5-8390-FEB79DE355F8} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2014-01-23] (Microsoft Corporation) Task: {BF49B66E-57D0-449C-A0D4-5ABD79D1BC9C} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\Windows\ehome\mcupdate.exe Task: {BFA78254-F4F1-4787-9CB1-717481CFDDBF} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION Task: {C5691050-83F5-4D1C-93BB-D337C386C018} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\Windows\ehome\mcupdate.exe Task: {C83C9F51-0F70-4F17-A466-402D6FC304D6} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\Windows\ehome\ehPrivJob.exe Task: {CA9676CD-4E59-4E50-BB68-20CC8CF2C7D3} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\Windows\ehome\ehPrivJob.exe Task: {CDF2D9D7-20E1-4AA0-983C-64C554EC7318} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION Task: {D0657F9E-1846-415F-9386-CB474D816148} - System32\Tasks\Microsoft\Windows\WindowsUpdate\sih => C:\Windows\System32\sihclient.exe [2015-08-23] (Microsoft Corporation) Task: {D51385BA-4B30-447D-9348-8432AEFF948B} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\Windows\ehome\ehPrivJob.exe Task: {DFF1D3DD-CCFE-4963-8084-E7B9F0802123} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION Task: {E07E8CD0-C523-4FF8-9875-C4CD3495379D} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\Windows\ehome\ehrec.exe Task: {E6197990-C5EB-4CB4-9B61-F090647320B7} - System32\Tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater => Rundll32.exe generaltel.dll,RunTelemetry -maintenance Task: {E7D9BBF1-A8C4-4224-AF5E-7F126CB1183D} - \Microsoft\Windows\File Classification Infrastructure\Property Definition Sync -> No File <==== ATTENTION Task: {E7E8F002-F2B3-4508-90C3-E6D014FBBBF8} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-12] (Adobe Systems Incorporated) Task: {EC649666-6079-4140-8308-50D64F2BF911} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\Windows\ehome\ehPrivJob.exe Task: {F97C8689-2B12-4DA8-A0A8-03BBB73D9B77} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION Task: {FAEFF711-70B7-4F60-ADFE-17AF945B95C0} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS\AutoKMS.exe [2015-02-16] () Task: {FD6822F7-1C12-4905-92F6-53A084AF434F} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\Adobe Flash Player PPAPI Notifier.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_18_0_0_232_pepper.exe Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (Whitelisted) ============== 2015-08-23 00:53 - 2015-08-23 00:53 - 00028672 _____ () C:\WINDOWS\SYSTEM32\efsext.dll 2015-08-29 03:53 - 2015-08-25 11:57 - 00116344 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2015-08-23 00:54 - 2015-08-23 00:54 - 02574840 _____ () C:\WINDOWS\system32\CoreUIComponents.dll 2015-08-23 00:54 - 2015-08-23 00:54 - 02574840 _____ () C:\WINDOWS\System32\CoreUIComponents.dll 2015-03-18 14:08 - 2015-03-18 14:08 - 08898720 _____ () C:\Program Files\Microsoft Office\Office15\1033\GrooveIntlResource.dll 2014-05-01 10:13 - 2014-05-01 10:13 - 00470016 _____ () C:\Users\metodiev\AppData\Local\MEGAsync\ShellExtX64.dll 2015-04-03 20:20 - 2015-03-19 23:33 - 00736962 _____ () C:\Program Files (x86)\Git\git-cheetah\git_shell_ext64.dll 2015-04-15 16:13 - 2015-04-15 16:13 - 00222720 _____ () C:\Program Files (x86)\Notepad++\NppShell_06.dll 2015-08-23 00:52 - 2015-08-23 00:52 - 00431104 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll 2015-08-23 00:57 - 2015-08-23 02:45 - 06369792 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2015-08-23 00:57 - 2015-08-23 02:45 - 00551424 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2015-08-23 00:57 - 2015-08-23 02:45 - 02482688 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll 2015-06-03 13:49 - 2015-06-03 13:49 - 00101128 _____ () C:\Program Files\TortoiseHg\TortoiseHgOverlayServer.exe 2014-05-03 13:14 - 2014-05-03 13:14 - 00130048 _____ () C:\Program Files\TortoiseHg\win32api.pyd 2014-05-03 13:12 - 2014-05-03 13:12 - 00137728 _____ () C:\Program Files\TortoiseHg\bin\pywintypes27.dll 2014-05-03 13:14 - 2014-05-03 13:14 - 00223744 _____ () C:\Program Files\TortoiseHg\win32gui.pyd 2014-05-03 13:13 - 2014-05-03 13:13 - 00027648 _____ () C:\Program Files\TortoiseHg\win32pipe.pyd 2014-05-03 13:13 - 2014-05-03 13:13 - 00023040 _____ () C:\Program Files\TortoiseHg\win32event.pyd 2014-05-03 13:13 - 2014-05-03 13:13 - 00149504 _____ () C:\Program Files\TortoiseHg\win32file.pyd 2014-05-03 13:13 - 2014-05-03 13:13 - 00136192 _____ () C:\Program Files\TortoiseHg\win32security.pyd 2014-12-10 13:28 - 2014-12-10 13:28 - 00112128 _____ () C:\Program Files\TortoiseHg\_ctypes.pyd 2015-06-03 13:47 - 2015-06-03 13:47 - 00010752 _____ () C:\Program Files\TortoiseHg\mercurial.osutil.pyd 2014-12-10 13:28 - 2014-12-10 13:28 - 01152000 _____ () C:\Program Files\TortoiseHg\_hashlib.pyd 2015-06-03 13:47 - 2015-06-03 13:47 - 00059392 _____ () C:\Program Files\TortoiseHg\mercurial.parsers.pyd 2014-05-03 13:13 - 2014-05-03 13:13 - 00045056 _____ () C:\Program Files\TortoiseHg\win32process.pyd 2014-05-03 13:15 - 2014-05-03 13:15 - 00548864 _____ () C:\Program Files\TortoiseHg\bin\pythoncom27.dll 2014-05-03 13:17 - 2014-05-03 13:17 - 00522240 _____ () C:\Program Files\TortoiseHg\win32com.shell.shell.pyd 2015-08-19 07:59 - 2015-08-11 23:48 - 72389840 _____ () C:\Users\metodiev\AppData\Local\Viber\Viber.exe 2015-05-31 07:59 - 2015-05-31 07:59 - 01301696 _____ () C:\Program Files (x86)\VMware\VMware Workstation\libxml2.dll 2015-04-03 17:59 - 2015-07-24 00:22 - 00011920 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll 2015-08-19 07:59 - 2015-08-11 23:42 - 00089088 _____ () C:\Users\metodiev\AppData\Local\Viber\qfacebook.dll 2015-08-19 07:59 - 2015-08-11 23:42 - 00168960 _____ () C:\Users\metodiev\AppData\Local\Viber\exif.dll 2015-08-19 08:00 - 2015-07-29 01:38 - 00012288 _____ () C:\Users\metodiev\AppData\Local\Viber\QtQuick.2\qtquick2plugin.dll 2015-08-19 08:00 - 2015-07-29 01:39 - 00690176 _____ () C:\Users\metodiev\AppData\Local\Viber\QtQuick\Controls\qtquickcontrolsplugin.dll 2015-08-19 07:59 - 2015-07-29 01:39 - 00057856 _____ () C:\Users\metodiev\AppData\Local\Viber\QtQuick\Layouts\qquicklayoutsplugin.dll 2015-08-19 08:00 - 2015-07-29 01:38 - 00012288 _____ () C:\Users\metodiev\AppData\Local\Viber\QtQuick\Window.2\windowplugin.dll 2015-08-19 07:59 - 2015-07-29 01:41 - 00184320 _____ () C:\Users\metodiev\AppData\Local\Viber\QtMultimedia\declarative_multimedia.dll 2015-08-23 03:27 - 2015-08-23 03:27 - 00838792 _____ () C:\Program Files (x86)\Plex\Plex Media Server\libxml2.dll 2015-08-23 03:27 - 2015-08-23 03:27 - 00049800 _____ () C:\Program Files (x86)\Plex\Plex Media Server\soci_sqlite3-vc80-3_0.dll 2015-08-23 03:27 - 2015-08-23 03:27 - 00086664 _____ () C:\Program Files (x86)\Plex\Plex Media Server\soci_core-vc80-3_0.dll 2015-08-23 03:27 - 2015-08-23 03:27 - 02092680 _____ () C:\Program Files (x86)\Plex\Plex Media Server\opencv_core249.dll 2015-08-23 03:27 - 2015-08-23 03:27 - 01883272 _____ () C:\Program Files (x86)\Plex\Plex Media Server\opencv_imgproc249.dll 2015-08-23 03:27 - 2015-08-23 03:27 - 00502920 _____ () C:\Program Files (x86)\Plex\Plex Media Server\tag.dll 2015-08-23 03:27 - 2015-08-23 03:27 - 00072840 _____ () C:\Program Files (x86)\Plex\Plex Media Server\zlib.dll 2015-08-23 03:27 - 2015-08-23 03:27 - 00196232 _____ () C:\Program Files (x86)\Plex\Plex Media Server\libidn.dll 2015-08-23 03:27 - 2015-08-23 03:27 - 00044680 _____ () C:\Program Files (x86)\Plex\Plex Media Server\DLLs\_socket.pyd 2015-08-23 03:27 - 2015-08-23 03:27 - 00027784 _____ () C:\Program Files (x86)\Plex\Plex Media Server\DLLs\_ssl.pyd 2015-08-23 03:27 - 2015-08-23 03:27 - 00018568 _____ () C:\Program Files (x86)\Plex\Plex Media Server\DLLs\_hashlib.pyd 2015-08-23 03:27 - 2015-08-23 03:27 - 00034952 _____ () C:\Program Files (x86)\Plex\Plex Media Server\Exts\simplejson\_speedups.pyd 2015-08-23 03:27 - 2015-08-23 03:27 - 00836232 _____ () C:\Program Files (x86)\Plex\Plex Media Server\Exts\lxml\etree.pyd 2015-08-23 03:27 - 2015-08-23 03:27 - 00166024 _____ () C:\Program Files (x86)\Plex\Plex Media Server\libxslt.dll 2015-08-23 03:27 - 2015-08-23 03:27 - 00062600 _____ () C:\Program Files (x86)\Plex\Plex Media Server\libexslt.dll 2015-08-23 03:27 - 2015-08-23 03:27 - 00192136 _____ () C:\Program Files (x86)\Plex\Plex Media Server\Exts\lxml\objectify.pyd 2015-08-23 03:27 - 2015-08-23 03:27 - 00016520 _____ () C:\Program Files (x86)\Plex\Plex Media Server\DLLs\select.pyd 2015-08-23 03:27 - 2015-08-23 03:27 - 00081544 _____ () C:\Program Files (x86)\Plex\Plex Media Server\DLLs\_ctypes.pyd 2015-08-23 03:27 - 2015-08-23 03:27 - 00111240 _____ () C:\Program Files (x86)\Plex\Plex Media Server\DLLs\pyexpat.pyd 2015-08-23 03:27 - 2015-08-23 03:27 - 00689800 _____ () C:\Program Files (x86)\Plex\Plex Media Server\DLLs\unicodedata.pyd 2015-08-15 08:42 - 2015-08-15 08:42 - 00039384 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext.dll 2015-03-18 14:08 - 2015-03-18 14:08 - 08898720 _____ () C:\Program Files (x86)\Microsoft Office\Office15\1033\GrooveIntlResource.dll 2014-05-01 10:15 - 2014-05-01 10:15 - 00463360 _____ () C:\Users\metodiev\AppData\Local\MEGAsync\ShellExtX32.dll 2015-09-01 17:31 - 2015-08-27 20:17 - 01501512 _____ () C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.85\libglesv2.dll 2015-09-01 17:31 - 2015-08-27 20:17 - 00081224 _____ () C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.85\libegl.dll 2015-09-01 17:31 - 2015-08-27 20:17 - 16393032 _____ () C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.85\PepperFlash\pepflashplayer.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxldtlfudivq`qsp`26hfm AlternateDataStreams: C:\Users\metodiev\Downloads\noname (1).eml:OECustomProperty AlternateDataStreams: C:\Users\metodiev\Downloads\noname.eml:OECustomProperty ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Ahcache.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CoreMessagingRegistrar => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SpbCx.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\StateRepository => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TileDataModelSvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\UserManager => ""="Service" ==================== EXE Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-3387192817-1767698883-158500957-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\metodiev\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\1_sunnyshores_cyprus.jpg HKU\S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415\Control Panel\Desktop\\Wallpaper -> DNS Servers: 75.75.75.75 - 75.75.76.76 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppextcomobj.exe FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppextcomobj.exe FirewallRules: [MSMQ-In-TCP] => (Allow) %systemroot%\system32\mqsvc.exe FirewallRules: [MSMQ-Out-TCP] => (Allow) %systemroot%\system32\mqsvc.exe FirewallRules: [MSMQ-In-UDP] => (Allow) %systemroot%\system32\mqsvc.exe FirewallRules: [MSMQ-Out-UDP] => (Allow) %systemroot%\system32\mqsvc.exe FirewallRules: [WCF-NetTcpActivator-In-TCP-64bit] => (Allow) LPort=808 FirewallRules: [{E9504597-6B62-4E97-B588-A0CC495FE14F}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe FirewallRules: [{61EC3EBE-E132-401C-9C4C-F3A5E3753F17}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe FirewallRules: [{1EAA94A0-17FC-4973-BFE5-AA37FAD43B1E}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe FirewallRules: [{4717B7C4-6CFE-463C-BC43-F5715DDDAE11}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe FirewallRules: [UDP Query User{BDEA4734-EBE9-4CAC-A7D6-8783F2BAB4DD}C:\program files\java\jdk1.8.0_45\bin\jmc.exe] => (Allow) C:\program files\java\jdk1.8.0_45\bin\jmc.exe FirewallRules: [TCP Query User{E194DAC8-5696-4506-8BE0-43C238DE6BE7}C:\program files\java\jdk1.8.0_45\bin\jmc.exe] => (Allow) C:\program files\java\jdk1.8.0_45\bin\jmc.exe FirewallRules: [{37087C49-6F2B-4BB8-B8CB-1CAA177C45DB}] => (Allow) C:\Program Files\HP\HP Officejet 6500 E710n-z\Bin\HPNetworkCommunicatorCom.exe FirewallRules: [{ED726BD7-91FF-4E52-B81F-DF9527E2CA72}] => (Allow) C:\Program Files\HP\HP Officejet 6500 E710n-z\Bin\HPNetworkCommunicator.exe FirewallRules: [{7CDBD5BB-CC75-417C-8766-1EB349C50362}] => (Allow) C:\Program Files\HP\HP Officejet 6500 E710n-z\Bin\DeviceSetup.exe FirewallRules: [{B51DA6EC-C1A7-47FB-9B7F-C5194D46320C}] => (Allow) C:\Program Files\HP\HP Officejet 6500 E710n-z\bin\SendAFax.exe FirewallRules: [{D7030ECC-EFB5-4490-BC18-F4B66708488D}] => (Allow) C:\Program Files\HP\HP Officejet 6500 E710n-z\bin\DigitalWizards.exe FirewallRules: [{4870B65A-6A26-4BAC-8E0B-1156A3BCDD8B}] => (Allow) C:\Program Files\HP\HP Officejet 6500 E710n-z\bin\FaxApplications.exe FirewallRules: [{90BC2ED1-E4FF-4464-B683-DE60E033ADF4}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{D11D8203-B3C8-4035-B31F-85CE38CE759F}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{DAD5039A-C0C0-4883-AD25-71EE578962C5}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{32B91BE8-1549-40FA-BDFB-B94B56BEF4B9}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{8E0E6AE9-3495-45A5-94F7-0AFACE485687}] => (Allow) LPort=1900 FirewallRules: [{D7EFDF85-9E0B-4D3E-BC40-0AD7C9F32219}] => (Allow) LPort=2869 FirewallRules: [{B32961E5-41C4-4D95-A74C-49011E4A6997}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe FirewallRules: [{C4FE5EB2-DFD6-4974-966F-0EF32B2D5405}] => (Allow) C:\Program Files\TightVNC\tvnserver.exe FirewallRules: [{35E2DB0B-DC81-4BFD-9210-6666DEBF5E19}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe FirewallRules: [{52156235-B27F-4011-8F8B-341CE31C1BEA}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe FirewallRules: [{D57ADA24-9BDC-4B28-911B-D4396B6F524E}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe FirewallRules: [{976A4723-C03F-415C-B88F-1316B964D496}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe FirewallRules: [{7C0B791E-98A8-4953-BCF2-B55A3189466D}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe FirewallRules: [{609E8141-C782-446B-93A2-72B1499BF435}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdater.exe FirewallRules: [{D831AE5D-000C-4A41-85DF-78865099A60C}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{5FA08201-7FCE-42EB-ACF6-E9FD1EA94F82}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{3319098A-047D-4346-82A4-534542EB01EB}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [UDP Query User{A2862CB6-E777-4021-B97F-24C2B25083EB}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe FirewallRules: [TCP Query User{C4966A1E-A11A-4F17-89D3-7D9028BE2DF5}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe FirewallRules: [UDP Query User{A457134F-C3A9-4D9B-AC65-3141E7B33B19}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe FirewallRules: [TCP Query User{B5A8F794-9998-428C-9DB1-124D11D18E54}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe FirewallRules: [UDP Query User{A8AB0791-7B8B-4520-B755-FCA034115E2E}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe FirewallRules: [TCP Query User{145D1AC6-18C4-4C58-9227-B0234B6A9D8F}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe FirewallRules: [{70B4514A-DCFB-480D-94D3-BA1FEF9FA879}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{13967590-A72F-4F37-A87B-311B7DF80A9C}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{9B17D14A-2B66-416E-97FE-37C981CEF3D4}] => (Allow) LPort=5558 FirewallRules: [{BFDBAC4E-CAE4-4695-BA99-73EFE44BC1D7}] => (Allow) LPort=5556 FirewallRules: [{BA2D25D0-C017-4F6D-B554-10BF8558BC3B}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{00D18569-B74D-449C-BB87-A687983AD2C3}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{0B26E2D4-A958-4036-B0E8-A52CB021379D}] => (Allow) C:\Users\metodiev\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{B9AC01D3-DD99-4A4D-89BE-ED06A74E80F6}] => (Allow) C:\Users\metodiev\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{B63E062F-8987-415D-B6D3-33CF9C20DD66}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe FirewallRules: [{101C6C11-2DFA-4ED5-A1D4-9DBD9233432C}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe FirewallRules: [{33FACED2-B4D4-477C-A656-0347E8E19D11}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe FirewallRules: [{CBEEFA65-CE4D-4F02-B386-AB28ACA21B72}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe FirewallRules: [TCP Query User{1DF79C5A-AF87-4972-94F8-6C4D9D1E9373}C:\users\metodiev\appdata\local\.meteor\packages\meteor-tool\1.1.3\mt-os.windows.x86_32\dev_bundle\bin\node.exe] => (Allow) C:\users\metodiev\appdata\local\.meteor\packages\meteor-tool\1.1.3\mt-os.windows.x86_32\dev_bundle\bin\node.exe FirewallRules: [UDP Query User{2DFDFAE4-4C4D-44E3-92AC-B0C80491B067}C:\users\metodiev\appdata\local\.meteor\packages\meteor-tool\1.1.3\mt-os.windows.x86_32\dev_bundle\bin\node.exe] => (Allow) C:\users\metodiev\appdata\local\.meteor\packages\meteor-tool\1.1.3\mt-os.windows.x86_32\dev_bundle\bin\node.exe FirewallRules: [{74FCA96D-E52C-40B7-815E-6387045B9B3F}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{E40E0FE2-7428-45DA-9FCE-CF9B4EC44BF5}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{7DDC39F8-C213-4A25-9F0F-28602491EA2E}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe FirewallRules: [{76DDF140-01C2-40A0-A5DE-AFD8AE69D372}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{05232199-823E-448E-B556-A4D1DB19538E}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{3C4D091F-A905-4A01-8702-1F4B11BD13C9}] => (Block) LPort=19302 FirewallRules: [{E3FAD746-F12E-450E-BD5E-54E9ED4D3748}] => (Block) LPort=19302 FirewallRules: [TCP Query User{03D252B3-FB7F-4572-8FFD-45AACA2C7A58}C:\users\metodiev\appdata\local\.meteor\packages\meteor-tool\1.1.4\mt-os.windows.x86_32\dev_bundle\bin\node.exe] => (Allow) C:\users\metodiev\appdata\local\.meteor\packages\meteor-tool\1.1.4\mt-os.windows.x86_32\dev_bundle\bin\node.exe FirewallRules: [UDP Query User{708FEB3B-7B12-410A-B90B-1F8DBC36F167}C:\users\metodiev\appdata\local\.meteor\packages\meteor-tool\1.1.4\mt-os.windows.x86_32\dev_bundle\bin\node.exe] => (Allow) C:\users\metodiev\appdata\local\.meteor\packages\meteor-tool\1.1.4\mt-os.windows.x86_32\dev_bundle\bin\node.exe FirewallRules: [{3F8B6588-38B9-4B25-8B1B-70B1C1D2D98B}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{10967C52-4099-4A74-A77E-AAA66EF28EE1}] => (Allow) C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe FirewallRules: [{9B1EAF71-1D4F-48E2-9E85-96AAE7F1BDA2}] => (Allow) C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe FirewallRules: [{5646328D-1EFE-4E49-B427-5B609A6BAB52}] => (Allow) C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe FirewallRules: [{3A394669-2662-4B54-BAF8-FFCF8247D602}] => (Allow) C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe FirewallRules: [{7A8AFC46-157A-4F58-9A99-A9378108A81F}] => (Allow) C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe FirewallRules: [{77B159B4-84DE-498A-B1E5-B1A80222B65B}] => (Allow) C:\Program Files (x86)\Plex\Plex Media Server\PlexScriptHost.exe FirewallRules: [{3F54CF99-538F-44FD-9FE2-5C808AB8723A}] => (Allow) C:\Program Files (x86)\Plex\Plex Media Server\PlexDlnaServer.exe FirewallRules: [{73852D00-B544-4C20-A443-0C1884AE3EAB}] => (Allow) C:\Windows\AutoKMS\AutoKMS.exe FirewallRules: [{885408E8-7A43-4EDB-B867-A4F046599F98}] => (Allow) C:\Windows\AutoKMS\AutoKMS.exe ==================== Faulty Device Manager Devices ============= Name: TAP-Windows Adapter V9 #5 Description: TAP-Windows Adapter V9 Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: TAP-Windows Provider V9 Service: tap0901 Problem: : Windows has stopped this device because it has reported problems. (Code 43) Resolution: One of the drivers controlling the device notified the operating system that the device failed in some manner. For more information about how to diagnose the problem, see the hardware documentation. ==================== Event log errors: ========================= Application errors: ================== Error: (09/12/2015 11:03:05 AM) (Source: Chrome) (EventID: 1) (User: NT AUTHORITY) Description: Chrome has encountered a fatal error. ver=45.0.2454.85;lang=;guid=5A17AA893FC04D3BB1BEC619F6B0991F;is_machine=1;oop=1;upload=1;minidump=C:\Program Files (x86)\Google\CrashReports\92863f8f-7aaf-4cbf-b2c7-716dcdc864c3.dmp Error: (09/12/2015 10:16:59 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: AutoKMS.exe, version: 2.5.0.0, time stamp: 0x52aef33f Faulting module name: KERNELBASE.dll, version: 10.0.10532.0, time stamp: 0x55d90461 Exception code: 0xe0434352 Fault offset: 0x000000000000d1a8 Faulting process id: 0x59c Faulting application start time: 0xAutoKMS.exe0 Faulting application path: AutoKMS.exe1 Faulting module path: AutoKMS.exe2 Report Id: AutoKMS.exe3 Faulting package full name: AutoKMS.exe4 Faulting package-relative application ID: AutoKMS.exe5 Error: (09/12/2015 10:16:54 AM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Application: AutoKMS.exe Framework Version: v4.0.30319 Description: The process was terminated due to an unhandled exception. Exception Info: System.ApplicationException Stack: at ..() at ..(., System.String, Boolean, System.String, Int32, System.String, Boolean, Boolean, Boolean, Boolean, Boolean, Boolean, System.String, System.String) at ..(System.String, Boolean, Boolean, System.String, Boolean, Boolean, System.String, ., Boolean, Int32, System.String, Boolean, Boolean) at ..(.) at ..() Error: (09/11/2015 10:08:48 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol. System Error: Access is denied. . Error: (09/11/2015 08:30:42 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Local Hostname metodiev-PC.local already in use; will try metodiev-PC-2.local instead Error: (09/11/2015 08:30:42 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: mDNSCoreReceiveResponse: ProbeCount 2; will deregister 4 metodiev-PC.local. Addr 10.0.0.8 Error: (09/11/2015 08:30:42 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: mDNSCoreReceiveResponse: Received from 10.0.0.8:5353 16 metodiev-PC.local. AAAA 2601:06C5:8002:6F40:B675:0EFF:FE7A:07A9 Error: (09/11/2015 07:05:41 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: NvStreamNetworkService.exe, version: 4.1.1977.6980, time stamp: 0x55a97f26 Faulting module name: ntdll.dll, version: 10.0.10532.0, time stamp: 0x55d903f2 Exception code: 0xc0000005 Fault offset: 0x000000000001b6fd Faulting process id: 0x1a8 Faulting application start time: 0xNvStreamNetworkService.exe0 Faulting application path: NvStreamNetworkService.exe1 Faulting module path: NvStreamNetworkService.exe2 Report Id: NvStreamNetworkService.exe3 Faulting package full name: NvStreamNetworkService.exe4 Faulting package-relative application ID: NvStreamNetworkService.exe5 Error: (09/11/2015 05:37:41 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 3797 Error: (09/11/2015 05:37:41 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 3797 System errors: ============= Error: (09/12/2015 10:20:13 AM) (Source: Service Control Manager) (EventID: 7024) (User: ) Description: The Xbox Live Auth Manager service terminated with the following service-specific error: %%0 Error: (09/12/2015 10:16:35 AM) (Source: Microsoft-Windows-NDIS) (EventID: 10317) (User: NT AUTHORITY) Description: Miniport TAP-Windows Adapter V9 #5, {59DBF6DC-B21E-4FF9-A29B-B8B6C062E66D}, had event 76 Error: (09/12/2015 10:15:28 AM) (Source: DCOM) (EventID: 10016) (User: METODIEV-PC) Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}metodiev-PCmetodievS-1-5-21-3387192817-1767698883-158500957-1000LocalHost (Using LRPC)Microsoft.Windows.FeatureOnDemand.InsiderHub_10.0.10532.0_neutral_neutral_cw5n1h2txyewyS-1-15-2-4016783169-893401051-2237370320-274899566-412088533-2398988950-2155762795 Error: (09/12/2015 10:06:38 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: application-specificLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYLOCAL SERVICES-1-5-19LocalHost (Using LRPC)UnavailableUnavailable Error: (09/12/2015 10:06:38 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: application-specificLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYLOCAL SERVICES-1-5-19LocalHost (Using LRPC)UnavailableUnavailable Error: (09/12/2015 10:06:38 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: application-specificLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYLOCAL SERVICES-1-5-19LocalHost (Using LRPC)UnavailableUnavailable Error: (09/12/2015 12:38:36 AM) (Source: DCOM) (EventID: 10010) (User: METODIEV-PC) Description: {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} Error: (09/12/2015 12:38:36 AM) (Source: DCOM) (EventID: 10010) (User: METODIEV-PC) Description: {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} Error: (09/12/2015 12:38:36 AM) (Source: DCOM) (EventID: 10010) (User: METODIEV-PC) Description: {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} Error: (09/12/2015 12:38:36 AM) (Source: DCOM) (EventID: 10010) (User: METODIEV-PC) Description: {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} Microsoft Office: ========================= Error: (09/12/2015 11:03:05 AM) (Source: Chrome) (EventID: 1) (User: NT AUTHORITY) Description: Chrome has encountered a fatal error. ver=45.0.2454.85;lang=;guid=5A17AA893FC04D3BB1BEC619F6B0991F;is_machine=1;oop=1;upload=1;minidump=C:\Program Files (x86)\Google\CrashReports\92863f8f-7aaf-4cbf-b2c7-716dcdc864c3.dmp Error: (09/12/2015 10:16:59 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: AutoKMS.exe2.5.0.052aef33fKERNELBASE.dll10.0.10532.055d90461e0434352000000000000d1a859c01d0ed640ebb9df9C:\Windows\AutoKMS\AutoKMS.exeC:\WINDOWS\system32\KERNELBASE.dlle3ac86be-a846-4640-b467-ffb4740dc5fa Error: (09/12/2015 10:16:54 AM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Application: AutoKMS.exe Framework Version: v4.0.30319 Description: The process was terminated due to an unhandled exception. Exception Info: System.ApplicationException Stack: at ..() at ..(., System.String, Boolean, System.String, Int32, System.String, Boolean, Boolean, Boolean, Boolean, Boolean, Boolean, System.String, System.String) at ..(System.String, Boolean, Boolean, System.String, Boolean, Boolean, System.String, ., Boolean, Int32, System.String, Boolean, Boolean) at ..(.) at ..() Error: (09/11/2015 10:08:48 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol. System Error: Access is denied. Error: (09/11/2015 08:30:42 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Local Hostname metodiev-PC.local already in use; will try metodiev-PC-2.local instead Error: (09/11/2015 08:30:42 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: mDNSCoreReceiveResponse: ProbeCount 2; will deregister 4 metodiev-PC.local. Addr 10.0.0.8 Error: (09/11/2015 08:30:42 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: mDNSCoreReceiveResponse: Received from 10.0.0.8:5353 16 metodiev-PC.local. AAAA 2601:06C5:8002:6F40:B675:0EFF:FE7A:07A9 Error: (09/11/2015 07:05:41 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: NvStreamNetworkService.exe4.1.1977.698055a97f26ntdll.dll10.0.10532.055d903f2c0000005000000000001b6fd1a801d0ece65b97e7dbC:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exeC:\WINDOWS\SYSTEM32\ntdll.dll02fc4993-fad6-45ae-b140-83e043ab6c83 Error: (09/11/2015 05:37:41 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 3797 Error: (09/11/2015 05:37:41 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 3797 CodeIntegrity: =================================== Date: 2015-09-12 11:04:43.381 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-09-12 11:04:43.371 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-09-12 11:04:15.085 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-09-12 11:04:15.073 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-09-11 04:28:40.847 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-09-10 17:18:24.254 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-09-10 17:18:24.247 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-09-10 16:57:09.796 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-09-10 16:57:09.761 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2015-09-10 09:18:51.848 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. ==================== Memory info =========================== Processor: Intel(R) Core(TM)2 Duo CPU E8400 @ 3.00GHz Percentage of memory in use: 49% Total physical RAM: 8061.61 MB Available physical RAM: 4071.45 MB Total Virtual: 16253.61 MB Available Virtual: 11528.01 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:278.92 GB) (Free:102.47 GB) NTFS Drive d: (RECOVERY) (Fixed) (Total:9.59 GB) (Free:4.89 GB) NTFS ==>[system with boot components (obtained from reading drive)] Drive e: (kon4e) (Fixed) (Total:288.39 GB) (Free:36.46 GB) NTFS ==================== MBR & Partition Table ================== ==================== End of Addition.txt ============================