Additional scan result of Farbar Recovery Scan Tool (x64) Version: 08-03-2017 Ran by [removed] (09-03-2017 02:01:13) Running from D:\Marko\Downloads Windows 10 Pro Version 1607 (X64) (2016-09-23 08:29:36) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-3645717828-1210496963-964261727-500 - Administrator - Disabled) => C:\Users\Administrator DefaultAccount (S-1-5-21-3645717828-1210496963-964261727-503 - Limited - Disabled) Guest (S-1-5-21-3645717828-1210496963-964261727-501 - Limited - Disabled) marko (S-1-5-21-3645717828-1210496963-964261727-1000 - Administrator - Enabled) => C:\Users\marko ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) µTorrent (HKU\S-1-5-21-3645717828-1210496963-964261727-1000\...\uTorrent) (Version: 3.4.9.43295 - BitTorrent Inc.) 2007 Microsoft Office Suite Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) 2007 Microsoft Office Suite Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden ACA & MEP 2016 Object Enabler (Version: 7.8.41.0 - Autodesk) Hidden ACA & MEP 2017 Object Enabler (Version: 7.9.45.0 - Autodesk) Hidden ACAD Private (Version: 20.1.49.0 - Autodesk) Hidden ACAD Private (Version: 21.0.52.0 - Autodesk) Hidden Ace Stream Media 3.1.2 (HKU\S-1-5-21-3645717828-1210496963-964261727-1000\...\AceStream) (Version: 3.1.2 - Ace Stream Media) <==== ATTENTION ACP Application (Version: 2016.0718.1650.38 - Advanced Micro Devices, Inc.) Hidden Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.023.20070 - Adobe Systems Incorporated) Adobe Flash Player 24 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 24.0.0.221 - Adobe Systems Incorporated) Adobe Photoshop CS6 (HKLM-x32\...\{74EB3499-8B95-4B5C-96EB-7B342F3FD0C6}) (Version: 13.0 - Adobe Systems Incorporated) Akamai NetSession Interface (HKU\S-1-5-21-3645717828-1210496963-964261727-1000\...\Akamai) (Version: - Akamai Technologies, Inc) AMD Software (HKLM\...\AMD Catalyst Install Manager) (Version: 9.0.000.8 - Advanced Micro Devices, Inc.) ArmCAD6 (A15.x64) Demo (HKLM\...\ArmCAD6 (A15.x64) Demo) (Version: - Radimpex Software) AutoCAD 2016 Language Pack - English (Version: 20.1.49.0 - Autodesk) Hidden AutoCAD 2017 - English (Version: 21.0.52.0 - Autodesk) Hidden AutoCAD 2017 (Version: 21.0.104.0 - Autodesk) Hidden AutoCAD 2017 Language Pack - English (Version: 21.0.52.0 - Autodesk) Hidden Autodesk Advance Steel 2017 (HKLM\...\Autodesk Advance Steel 2017) (Version: 21.0.0.1 - Autodesk) Autodesk Advance Steel 2017 (Version: 21.0.0.1 - Autodesk) Hidden Autodesk Advance Steel 2017 HF1 (HKLM\...\Autodesk Advance Steel 2017 HF1) (Version: 1 - Autodesk) Autodesk Advanced Material Library Image Library 2017 (HKLM-x32\...\{8ED2ED41-4455-449D-993C-751C039089B9}) (Version: 15.11.3.0 - Autodesk) Autodesk AutoCAD 2017 - English (HKLM\...\AutoCAD 2017 - English) (Version: 21.0.52.0 - Autodesk) Autodesk AutoCAD 2017 SP 1 (HKLM\...\AutoCAD 2017 SP1) (Version: 21.0.104.0 - Autodesk) Autodesk AutoCAD Performance Feedback Tool 1.2.5 (HKLM-x32\...\{8600F844-9AA5-412E-B6F2-F9C6CBCFD268}) (Version: 1.2.5.0 - Autodesk) Autodesk BIM 360 Glue AutoCAD 2017 Add-in 64 bit (HKLM\...\{276A67E0-71EB-4827-B5F7-2ACF02BC1A5B}) (Version: 4.37.6853 - Autodesk) Autodesk Featured Apps 2016-2017 (HKLM-x32\...\{27C15055-713B-4D0E-881F-19598A2DFD59}) (Version: 2.2.0 - Autodesk) Autodesk License Service (x64) - 3.1 (HKLM\...\{EB6FE58F-8576-4272-BB9C-6B47D9EDFA4D}) (Version: 3.1.26.0 - Autodesk) Autodesk Material Library 2017 (HKLM-x32\...\{8FB9F735-D64C-4991-8D91-4CDDAB1ABDEE}) (Version: 15.11.3.0 - Autodesk) Autodesk Material Library Base Resolution Image Library 2017 (HKLM-x32\...\{3FBFBC43-9882-43FA-B979-2D53896747B3}) (Version: 15.11.3.0 - Autodesk) Autodesk Robot Structural Analysis Professional 2017 - English regional settings (Version: 2017.0.0.5913 - Autodesk) Hidden Autodesk Robot Structural Analysis Professional 2017 (HKLM\...\Autodesk Robot Structural Analysis Professional 2017) (Version: 2017.0.1.5933 - Autodesk, Inc.) Autodesk Robot Structural Analysis Professional 2017 (Version: 2017.0.1.5933 - Autodesk, Inc.) Hidden Catalyst Control Center Next Localization BR (Version: 2017.0125.1845.33722 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CHS (Version: 2017.0125.1845.33722 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CHT (Version: 2017.0125.1845.33722 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CS (Version: 2017.0125.1845.33722 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization DA (Version: 2017.0125.1845.33722 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization DE (Version: 2017.0125.1845.33722 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization EL (Version: 2017.0125.1845.33722 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization ES (Version: 2017.0125.1845.33722 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization FI (Version: 2017.0125.1845.33722 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization FR (Version: 2017.0125.1845.33722 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization HU (Version: 2017.0125.1845.33722 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization IT (Version: 2017.0125.1845.33722 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization JA (Version: 2017.0125.1845.33722 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization KO (Version: 2017.0125.1845.33722 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization NL (Version: 2017.0125.1845.33722 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization NO (Version: 2017.0125.1845.33722 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization PL (Version: 2017.0125.1845.33722 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization RU (Version: 2017.0125.1845.33722 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization SV (Version: 2017.0125.1845.33722 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization TH (Version: 2017.0125.1845.33722 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization TR (Version: 2017.0125.1845.33722 - Advanced Micro Devices, Inc.) Hidden CCleaner (HKLM\...\CCleaner) (Version: 5.27 - Piriform) CPUID CPU-Z 1.78 (HKLM\...\CPUID CPU-Z_is1) (Version: - ) EPSON L200 Series Printer Uninstall (HKLM\...\EPSON L200 Series) (Version: - SEIKO EPSON Corporation) EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version: - Seiko Epson Corporation) FARO LS 1.1.502.0 (64bit) (HKLM-x32\...\{66D83FE0-D798-4B38-86FE-FB48151E5AEF}) (Version: 5.2.0.35213 - FARO Scanner Production) FIFA 17 (HKLM-x32\...\{8C0DD062-B659-409C-9AB7-8EBD1D64D2EB}) (Version: 1.0.47.2427 - Electronic Arts) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 56.0.2924.87 - Google Inc.) Google Drive (HKLM-x32\...\{07A12123-B717-496B-B471-48AF6407B433}) (Version: 1.32.4066.7445 - Google, Inc.) Google Update Helper (x32 Version: 1.3.21.115 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.32.7 - Google Inc.) Hidden Grand Theft Auto V (HKLM-x32\...\{E01FA564-2094-4833-8F2F-1FFEC6AFCC46}) (Version: "1.00.0000" - Rockstar Games) HITMAN™ (HKLM\...\Steam App 236870) (Version: - Io-Interactive) HP Connectivity Kit (HKLM-x32\...\{b2fc46a7-5c75-4471-9355-547056862295}) (Version: 1.31.10637.0 - HP) HP LaserJet Professional P1100-P1560-P1600 Series (HKLM\...\HP LaserJet Professional P1100-P1560-P1600 Series) (Version: - ) HP Prime Virtual Calculator (HKLM-x32\...\{39959ae9-ec27-4f46-8adf-a7278892fc41}) (Version: 1.31.10637.0 - HP) hppLaserJetService (x32 Version: 001.001.0.0 - Hewlett-Packard) Hidden hppP1100P1560P1600SeriesLaserJetService (x32 Version: 001.001.0.0 - Hewlett-Packard) Hidden hppusgP1100P1560P1600Series (x32 Version: 1.0.0.1 - Hewlett-Packard) Hidden HPSSupply (HKLM-x32\...\{7902E313-FF0F-4493-ACB1-A8147B78DCD0}) (Version: 2.1.1.0000 - Hewlett Packard Development Company L.P.) Intel(R) Chipset Device Software (x32 Version: 10.0.26 - Intel(R) Corporation) Hidden Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 10.0.39.1003 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 20.19.15.4531 - Intel Corporation) Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes) MarketResearch (x32 Version: 130.0.374.000 - Hewlett-Packard) Hidden MATLAB R2016a (HKLM\...\Matlab R2016a) (Version: 9.0 - MathWorks) Microsoft Mathematics (64-bit) (HKLM\...\{E57B7E0A-8BE5-42E2-BE60-C07ED680A063}) (Version: 4.0 - Microsoft Corporation) Microsoft Office Professional Plus 2007 (HKLM-x32\...\PROPLUS) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24210 (HKLM-x32\...\{f144e08f-9cbe-4f09-9a8c-f2b858b7ee7f}) (Version: 14.0.24210.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24210 (HKLM-x32\...\{23658c02-145e-483d-ba6b-1eb82c580529}) (Version: 14.0.24210.0 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.31119 - Microsoft Corporation) Mozilla Firefox 46.0.1 (x64 en-GB) (HKLM\...\Mozilla Firefox 46.0.1 (x64 en-GB)) (Version: 46.0.1 - Mozilla) Mozilla Firefox 50.0 (x86 en-GB) (HKLM-x32\...\Mozilla Firefox 50.0 (x86 en-GB)) (Version: 50.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 50.0.0.6130 - Mozilla) MusicBee 2.5 (HKLM-x32\...\MusicBee) (Version: 2.5 - Steven Mayall) Origin (HKLM-x32\...\Origin) (Version: 10.4.3.15631 - Electronic Arts, Inc.) PDF Settings CS6 (x32 Version: 11.0 - Adobe Systems Incorporated) Hidden Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9.141.259 - Google, Inc.) Raptr (HKLM-x32\...\Raptr) (Version: 5.2.7-r116720-release - Raptr, Inc) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.88.617.2014 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7541 - Realtek Semiconductor Corp.) Results Connect (HKLM\...\{E9100151-C562-4B7C-B25F-1355E9ED9387}) (Version: 2016.0.0.16045 - Autodesk, Inc.) Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.2.1.4 - Rockstar Games) SketchUp Import (HKLM-x32\...\{C403E867-FCF1-432B-BCC1-8FFD40A10A6E}) (Version: 1.2.0 - Autodesk) SketchUp Import 2016-2017 (HKLM-x32\...\{063925DB-9D8C-48E2-8F04-1B7038B6C783}) (Version: 2.2.0 - Autodesk) Skype™ 7.32 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.32.104 - Skype Technologies S.A.) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 8.52a - Ghisler Software GmbH) Tower7 Demo (HKLM-x32\...\Tower7 Demo) (Version: - Radimpex Software) Transcribe! 8.64 (HKLM-x32\...\com.seventhstring.Transcribe_is1) (Version: 8.64 - Seventh String Software) Uplay (HKLM-x32\...\Uplay) (Version: 27.0 - Ubisoft) VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.4 - VideoLAN) Vulkan Run Time Libraries 1.0.11.0 (HKLM\...\VulkanRT1.0.11.0-2) (Version: 1.0.11.0 - LunarG, Inc.) Vulkan Run Time Libraries 1.0.11.0 (Version: 1.0.11.0 - LunarG, Inc.) Hidden Vulkan Run Time Libraries 1.0.17.0 (HKLM\...\VulkanRT1.0.17.0-2) (Version: 1.0.17.0 - LunarG, Inc.) Vulkan Run Time Libraries 1.0.17.0 (Version: 1.0.17.0 - LunarG, Inc.) Hidden Vulkan Run Time Libraries 1.0.26.0 (HKLM\...\VulkanRT1.0.26.0-4) (Version: 1.0.26.0 - LunarG, Inc.) Vulkan Run Time Libraries 1.0.26.0 (Version: 1.0.26.0 - LunarG, Inc.) Hidden Vulkan Run Time Libraries 1.0.3.1 (HKLM\...\VulkanRT1.0.3.1) (Version: 1.0.3.1 - LunarG, Inc.) Vulkan Run Time Libraries 1.0.37.0 (HKLM\...\VulkanRT1.0.37.0) (Version: 1.0.37.0 - LunarG, Inc.) WinRAR 5.30 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.30.0 - win.rar GmbH) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-3645717828-1210496963-964261727-1000_Classes\CLSID\{0D327DA6-B4DF-4842-B833-2CFF84F0948F}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2017\acad.exe (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-3645717828-1210496963-964261727-1000_Classes\CLSID\{720DB9AF-D62C-4ED0-A377-429C22312852}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2017\acad.exe (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-3645717828-1210496963-964261727-1000_Classes\CLSID\{E2C40589-DE61-11ce-BAE0-0020AF6D7005}\InprocServer32 -> C:\Program Files\Autodesk\AutoCAD 2017\en-US\acadficn.dll (Autodesk, Inc.) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {044F22D9-F466-4982-9231-37C21DF7DC00} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => %SystemRoot%\ehome\ehrec.exe Task: {081B5687-1645-4903-8990-2613FD542FB6} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => %SystemRoot%\ehome\mcupdate.exe Task: {0ACEA480-28F8-4FF2-8C83-923BEA8BF607} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\Program Files\Windows Defender\\MpCmdRun.exe [2016-07-16] (Microsoft Corporation) Task: {0E67716F-F906-450A-8AF8-367155F95765} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => %SystemRoot%\ehome\ehPrivJob.exe Task: {0E67B3C8-D8D0-4DB7-AB58-36213F349A21} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => %SystemRoot%\ehome\ehPrivJob.exe Task: {0E942208-8BB8-40C4-B0B8-90563AD79A05} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => %SystemRoot%\ehome\ehrec.exe Task: {11583219-3FD9-41B9-8BDA-B6049333E483} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => %SystemRoot%\ehome\mcupdate.exe Task: {1238F1B5-DB3E-411F-BAC1-6463BB36E66E} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => %SystemRoot%\ehome\ehPrivJob.exe Task: {1658767D-A97E-46FE-A267-FFDCC82D702B} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => %SystemRoot%\ehome\ehPrivJob.exe Task: {18A9239F-33A6-4D11-A202-739414ED1C64} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2017-02-08] (Piriform Ltd) Task: {23B8824F-856C-43CC-BCB9-C918D98EAC2B} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => %SystemRoot%\ehome\mcupdate.exe Task: {27ED1BA3-A4C0-493D-BE8A-8B3B404E20A0} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-01-19] (Google Inc.) Task: {398B64D1-02A4-438D-986D-AD83E97F7D80} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => %windir%\ehome\MCUpdate.exe Task: {4CDD00C8-94BB-4567-BA66-06434F7F473D} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => %SystemRoot%\ehome\mcupdate.exe Task: {5284678B-CA2B-48A3-8A2A-B78D910AAC80} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-12-19] (Adobe Systems Incorporated) Task: {54234077-6098-46EA-A397-EA834C706C30} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => %SystemRoot%\ehome\ehPrivJob.exe Task: {58B627F0-E3B1-498F-B31B-985F9AA15FE7} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => %SystemRoot%\ehome\ehPrivJob.exe Task: {6DBBA42C-3791-4F4B-BED8-54C287953522} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\Program Files\Windows Defender\\MpCmdRun.exe [2016-07-16] (Microsoft Corporation) Task: {6EA4CF18-86FE-4950-BE57-B9B5B2C450E8} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => %SystemRoot%\ehome\ehPrivJob.exe Task: {7AAAA911-101C-4238-B0A7-7A5597F5E423} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => %SystemRoot%\ehome\mcupdate.exe Task: {820D4547-5D51-4A5A-9E41-E68229C7E1A6} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-02-16] (Adobe Systems Incorporated) Task: {856D7995-6A88-497D-BFEE-6C504D70520E} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => %SystemRoot%\ehome\ehPrivJob.exe Task: {87C8AECF-4933-4ACD-8109-4DFDDABC4E63} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe [2017-01-25] (Advanced Micro Devices, Inc.) Task: {90BC24BD-C2D7-45EF-A7FB-D95A573D926C} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => %SystemRoot%\ehome\ehPrivJob.exe Task: {99134D73-36B9-42D9-93BC-8EA314ADE77C} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => %SystemRoot%\ehome\ehPrivJob.exe Task: {9FC752BA-EA1B-41BB-A30C-1F4F301CAFB7} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => %SystemRoot%\ehome\ehPrivJob.exe Task: {AA19C57F-ADFC-432B-A82C-CE9040475663} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\Program Files\Windows Defender\\MpCmdRun.exe [2016-07-16] (Microsoft Corporation) Task: {B346FC7C-6152-4B26-BDDB-BBC3A61E89AE} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => %SystemRoot%\ehome\ehPrivJob.exe Task: {B88DF910-CA64-4F31-AEB6-346E662DD932} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => %SystemRoot%\ehome\mcupdate.exe Task: {BA7CF4B4-8CFA-4463-8C59-FA2B5EEBA814} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\Program Files\Windows Defender\\MpCmdRun.exe [2016-07-16] (Microsoft Corporation) Task: {CFACD705-1299-41CF-B4D4-08A4F0AF5252} - System32\Tasks\Ugsusvllkbhithd => C:\WINDOWS\system32\4425\SystemPropertiesComputerName.exe [2016-07-16] (Microsoft Corporation) <==== ATTENTION Task: {DA103234-2D3E-4329-ACF6-981A4C99B83D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-01-19] (Google Inc.) Task: {E9DA8B44-E0E0-411F-815E-6CD3F5FB05A0} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => %SystemRoot%\ehome\ehPrivJob.exe Task: {EC3E333C-55AC-46B0-B602-33FE5380B035} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => %SystemRoot%\ehome\mcupdate.exe Task: {FB768B1C-67F9-478F-84C3-252CEEFCB3BB} - System32\Tasks\ASUS Live Update Task Schedule => C:\Program Files (x86)\ASUS\GPU Tweak\ASUSLiveUpdate.exe (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== 2016-07-16 12:42 - 2016-07-16 12:42 - 00231424 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll 2016-12-14 04:00 - 2016-12-09 11:29 - 02681200 _____ () C:\WINDOWS\system32\CoreUIComponents.dll 2016-01-20 00:54 - 2012-08-31 15:03 - 00288768 _____ () C:\WINDOWS\System32\HP1100LM.DLL 2016-01-20 00:54 - 2012-08-31 15:02 - 00074240 _____ () C:\WINDOWS\system32\spool\PRTPROCS\x64\HP1100PP.DLL 2016-12-14 04:00 - 2016-12-09 11:29 - 02681200 _____ () C:\WINDOWS\SYSTEM32\CoreUIComponents.dll 2016-09-23 09:31 - 2016-09-23 09:31 - 00959168 _____ () C:\Users\marko\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\ClientTelemetry.dll 2016-09-23 17:50 - 2016-09-07 05:56 - 00134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll 2017-01-11 13:30 - 2016-12-21 08:09 - 00474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll 2017-01-11 13:29 - 2016-12-21 07:54 - 09760768 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2017-01-11 13:29 - 2016-12-21 07:48 - 01401856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2017-01-11 13:29 - 2016-12-21 07:48 - 00757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll 2017-01-11 13:29 - 2016-12-21 07:48 - 02424320 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll 2017-01-11 13:30 - 2016-12-21 07:53 - 04853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll 2016-08-29 17:54 - 2016-08-29 17:54 - 00014336 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick.2\qtquick2plugin.dll 2016-08-29 17:54 - 2016-08-29 17:54 - 00739840 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Controls\qtquickcontrolsplugin.dll 2016-08-29 17:54 - 2016-08-29 17:54 - 00014336 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Window.2\windowplugin.dll 2016-08-29 17:54 - 2016-08-29 17:54 - 00071168 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Layouts\qquicklayoutsplugin.dll 2016-08-29 17:54 - 2016-08-29 17:54 - 00011776 _____ () C:\Program Files\AMD\CNext\CNext\libEGL.dll 2016-08-29 17:54 - 2016-08-29 17:54 - 02013696 _____ () C:\Program Files\AMD\CNext\CNext\libGLESv2.dll 2016-08-29 17:54 - 2016-08-29 17:54 - 00191488 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Dialogs\dialogplugin.dll 2017-02-22 18:47 - 2017-02-22 18:47 - 00073728 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.110.0_x64__kzf8qxf38zg5c\SkypeHost.exe 2017-02-22 18:47 - 2017-02-22 18:47 - 00179712 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.110.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll 2017-02-22 18:47 - 2017-02-22 18:47 - 42895360 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.110.0_x64__kzf8qxf38zg5c\SkyWrap.dll 2017-02-06 11:50 - 2017-02-06 11:50 - 02215424 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.110.0_x64__kzf8qxf38zg5c\roottools.dll 2015-02-25 14:15 - 2015-02-25 14:15 - 01243936 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) HKU\S-1-5-21-3645717828-1210496963-964261727-1000\Software\Classes\.scr: AutoCADScriptFile => ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) IE trusted site: HKU\S-1-5-21-3645717828-1210496963-964261727-1000\...\hola.org -> hxxp://hola.org ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-3645717828-1210496963-964261727-1000\Control Panel\Desktop\\Wallpaper -> d:\marko\slike\fan posters\black_keys_brothers_style_desktop_wallpaper_by_wbayc-d55at43.png DNS Servers: [removed] - [removed] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == MSCONFIG\Services: MyEpson Portal Service => 2 HKLM\...\StartupApproved\Run: => "StartCN" HKLM\...\StartupApproved\Run32: => "ADSKAppManager" HKLM\...\StartupApproved\Run32: => "Raptr" HKLM\...\StartupApproved\Run32: => "AdobeCS6ServiceManager" HKU\S-1-5-21-3645717828-1210496963-964261727-1000\...\StartupApproved\Run: => "SpybotPostWindows10UpgradeReInstall" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [MSMQ-In-TCP] => (Allow) %systemroot%\system32\mqsvc.exe FirewallRules: [MSMQ-Out-TCP] => (Allow) %systemroot%\system32\mqsvc.exe FirewallRules: [MSMQ-In-UDP] => (Allow) %systemroot%\system32\mqsvc.exe FirewallRules: [MSMQ-Out-UDP] => (Allow) %systemroot%\system32\mqsvc.exe FirewallRules: [WCF-NetTcpActivator-In-TCP-64bit] => (Allow) LPort=808 FirewallRules: [{BABAD0E2-CD64-4D48-8955-A5AA0E818D4C}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{6AAF092C-AC31-41E9-9639-943F8071188E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{E4F95795-8EC3-442A-9275-A5C62AB8E268}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [{E5D452D4-D59C-4E91-ABE1-EE75091CF148}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [UDP Query User{28427B43-915C-4EF5-A894-44B8A5836352}D:\program files\rockstar games\grand theft auto v\gta5.exe] => (Allow) D:\program files\rockstar games\grand theft auto v\gta5.exe FirewallRules: [TCP Query User{8F263985-FE83-43F4-8A12-4D339BEE592B}D:\program files\rockstar games\grand theft auto v\gta5.exe] => (Allow) D:\program files\rockstar games\grand theft auto v\gta5.exe FirewallRules: [{02442503-ADC7-4F33-B6EE-AB34F640D3A2}] => (Allow) D:\Program Files\SteamLibrary\steamapps\common\Hitman™\Launcher.exe FirewallRules: [{F4326076-5C1E-439F-8032-D7FEA77B941F}] => (Allow) D:\Program Files\SteamLibrary\steamapps\common\Hitman™\Launcher.exe FirewallRules: [UDP Query User{BC3A11F5-21F8-40FB-B3C8-344FA7B94EF5}C:\users\marko\appdata\roaming\acestream\engine\ace_engine.exe] => (Allow) C:\users\marko\appdata\roaming\acestream\engine\ace_engine.exe FirewallRules: [TCP Query User{008BA508-C264-4D38-942B-FF29ED1E2BD8}C:\users\marko\appdata\roaming\acestream\engine\ace_engine.exe] => (Allow) C:\users\marko\appdata\roaming\acestream\engine\ace_engine.exe FirewallRules: [{20E5AD50-05CC-4F81-B529-E17D6CE2DB13}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{51D57A3F-BB10-4538-8025-0A8820CD6242}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [UDP Query User{AF2E100E-A348-4D09-9C1D-EAF78FECAAAD}C:\users\marko\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\marko\appdata\roaming\utorrent\utorrent.exe FirewallRules: [TCP Query User{FD43DA00-2B76-4ABE-8714-CA65C5367AB1}C:\users\marko\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\marko\appdata\roaming\utorrent\utorrent.exe FirewallRules: [{6EA41347-F997-4D8E-BD28-88281778E5A5}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [UDP Query User{6AC681E6-7A71-41D7-9FE4-E2BEF33514FF}C:\users\marko\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\marko\appdata\local\akamai\netsession_win.exe FirewallRules: [TCP Query User{28D31C97-771A-46D4-8295-1BD45260DE59}C:\users\marko\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\marko\appdata\local\akamai\netsession_win.exe FirewallRules: [TCP Query User{F3FA2F1A-D8CD-45DF-8CF9-76B2B911372E}C:\program files (x86)\hp\hp prime virtual calculator\hpprime.exe] => (Allow) C:\program files (x86)\hp\hp prime virtual calculator\hpprime.exe FirewallRules: [UDP Query User{0A70621B-009B-4282-8CB5-CAE68F42130B}C:\program files (x86)\hp\hp prime virtual calculator\hpprime.exe] => (Allow) C:\program files (x86)\hp\hp prime virtual calculator\hpprime.exe FirewallRules: [TCP Query User{500529C6-ED3E-43EF-9F81-074CCF1D0A60}D:\program files\origin\fifa 17\fifa17.exe] => (Allow) D:\program files\origin\fifa 17\fifa17.exe FirewallRules: [UDP Query User{DC651FE8-3CB2-4EC1-8209-D6856D7532A2}D:\program files\origin\fifa 17\fifa17.exe] => (Allow) D:\program files\origin\fifa 17\fifa17.exe FirewallRules: [{EA470083-EE4B-4637-824E-7EB287C81919}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr.exe FirewallRules: [{E0A9C558-4597-4978-9F5B-7DD73D835FE0}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr.exe FirewallRules: [{EE243636-3BBB-4D18-9A4C-F7F1E19DC092}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr_im.exe FirewallRules: [{337B53DD-7D2F-46B4-919F-D92124E7D2E9}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr_im.exe FirewallRules: [{D3473546-4169-4A58-BEC6-9B2021AC35E1}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{7AA88CD0-90EF-4F09-9FC4-D50A5116E2E6}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{E0A74861-8C72-4EA8-81DB-C70C2C1253FB}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{03CA0EB9-A308-485A-A459-C1A7980C81D1}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [TCP Query User{7D5F002B-6EE4-4B0B-81C0-7546A1EA08E4}D:\program files\matlab\r2016a\bin\win64\matlab.exe] => (Allow) D:\program files\matlab\r2016a\bin\win64\matlab.exe FirewallRules: [UDP Query User{EBDC8407-84AC-418B-A466-10C9757A14DA}D:\program files\matlab\r2016a\bin\win64\matlab.exe] => (Allow) D:\program files\matlab\r2016a\bin\win64\matlab.exe FirewallRules: [{158E9247-1F5C-4924-8B93-321035E69A52}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{1FF9C790-23F6-4C1E-B0FC-2155F05FE94A}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{C7386A9A-9E93-4315-BBA2-01796C0DCA22}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{8AFC27B5-0611-458F-AC20-B791ACB0DBD1}] => (Allow) D:\Program Files\Origin\FIFA 17\FIFASetup\fifaconfig.exe FirewallRules: [{2204F378-1A6E-4203-93D6-64AA5F73D0A8}] => (Allow) D:\Program Files\Origin\FIFA 17\FIFASetup\fifaconfig.exe ==================== Restore Points ========================= ATTENTION: System Restore is disabled ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (03/09/2017 01:27:48 AM) (Source: MsiInstaller) (EventID: 11310) (User: marko-PC) Description: Product: Akamai NetSession Interface -- Error 1310. Error writing to file: C:\Users\marko\AppData\Local\Akamai\admintool.exe. System error 0. Verify that you have access to that directory. Error: (03/09/2017 01:27:34 AM) (Source: MsiInstaller) (EventID: 11310) (User: marko-PC) Description: Product: Akamai NetSession Interface -- Error 1310. Error writing to file: C:\Users\marko\AppData\Local\Akamai\admintool.exe. System error 0. Verify that you have access to that directory. Error: (03/08/2017 11:29:16 PM) (Source: Microsoft-Windows-EFS) (EventID: 4401) (User: marko-PC) Description: 7.488: EFS service failed to provision a user for EDP. Error code: 0x80070005. Error: (03/08/2017 11:27:09 PM) (Source: amdacpusrsvc) (EventID: 0) (User: ) Description: Event-ID 0 Error: (03/08/2017 11:22:34 PM) (Source: Microsoft-Windows-EFS) (EventID: 4401) (User: marko-PC) Description: 7.488: EFS service failed to provision a user for EDP. Error code: 0x80070005. Error: (03/08/2017 11:20:27 PM) (Source: amdacpusrsvc) (EventID: 0) (User: ) Description: Event-ID 0 Error: (03/08/2017 11:20:05 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: marko-PC) Description: Activation of app Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI failed with error: -2144927141 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (03/08/2017 11:20:01 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: SDUpdSvc.exe, version: 2.5.44.79, time stamp: 0x57e24e33 Faulting module name: rtl150.bpl, version: 15.0.3953.35171, time stamp: 0x4cca139f Exception code: 0xc0000005 Fault offset: 0x0000a116 Faulting process id: 0x1c80 Faulting application start time: 0x01d2985217115646 Faulting application path: C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe Faulting module path: C:\Program Files (x86)\Spybot - Search & Destroy 2\rtl150.bpl Report Id: de1d6450-7a36-4a1c-8362-97cd752fa9bd Faulting package full name: Faulting package-relative application ID: Error: (03/08/2017 10:05:09 PM) (Source: Microsoft-Windows-EFS) (EventID: 4401) (User: marko-PC) Description: 7.488: EFS service failed to provision a user for EDP. Error code: 0x80070005. Error: (03/08/2017 10:03:01 PM) (Source: amdacpusrsvc) (EventID: 0) (User: ) Description: Event-ID 0 System errors: ============= Error: (03/08/2017 11:27:14 PM) (Source: Service Control Manager) (EventID: 7024) (User: ) Description: The HitmanPro 3.7 Crusader (Boot) service terminated with the following service-specific error: The operation completed successfully. Error: (03/08/2017 11:27:13 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {8D8F4F83-3594-4F07-8369-FC3C3CAE4919} and APPID {F72671A9-012C-4725-9D2F-2A4D32D65169} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (03/08/2017 11:27:09 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The NetTcpActivator service depends on the NetTcpPortSharing service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Error: (03/08/2017 11:20:31 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {8D8F4F83-3594-4F07-8369-FC3C3CAE4919} and APPID {F72671A9-012C-4725-9D2F-2A4D32D65169} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (03/08/2017 11:20:27 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The NetTcpActivator service depends on the NetTcpPortSharing service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Error: (03/08/2017 11:20:05 PM) (Source: DCOM) (EventID: 10010) (User: marko-PC) Description: The server CortanaUI.AppXtpp90jhw9p0njjb85kvhxpppgrqfp117.mca did not register with DCOM within the required timeout. Error: (03/08/2017 10:03:05 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {8D8F4F83-3594-4F07-8369-FC3C3CAE4919} and APPID {F72671A9-012C-4725-9D2F-2A4D32D65169} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (03/08/2017 10:03:01 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The NetTcpActivator service depends on the NetTcpPortSharing service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Error: (03/08/2017 06:08:35 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {8D8F4F83-3594-4F07-8369-FC3C3CAE4919} and APPID {F72671A9-012C-4725-9D2F-2A4D32D65169} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (03/08/2017 06:08:31 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The NetTcpActivator service depends on the NetTcpPortSharing service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. CodeIntegrity: =================================== Date: 2017-03-09 00:30:03.474 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-03-08 21:41:21.086 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\SET6C89.tmp because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2017-03-08 21:41:21.081 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\SET6C89.tmp because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2017-03-08 21:41:21.077 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\SET6C89.tmp because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2017-03-08 21:18:49.437 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-03-08 21:05:26.601 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\SET6C89.tmp because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2017-03-08 21:05:26.595 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\SET6C89.tmp because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2017-03-08 21:05:26.591 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\SET6C89.tmp because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2017-03-08 18:21:05.273 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\SET6C89.tmp because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2017-03-08 18:21:05.268 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\SET6C89.tmp because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i5-4460 CPU @ 3.20GHz Percentage of memory in use: 24% Total physical RAM: 8063.92 MB Available physical RAM: 6101.67 MB Total Virtual: 24447.92 MB Available Virtual: 22278.18 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:111.25 GB) (Free:32.85 GB) NTFS Drive d: () (Fixed) (Total:439.45 GB) (Free:123.59 GB) NTFS Drive e: () (Fixed) (Total:492.06 GB) (Free:455.06 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 111.8 GB) (Disk ID: C801CFA4) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=111.3 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=450 MB) - (Type=27) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: C801CFB5) Partition 1: (Not Active) - (Size=439.5 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=492.1 GB) - (Type=07 NTFS) ==================== End of Addition.txt ============================