Sei sulla pagina 1di 29

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 30-11-2017

Ran by Win 7 (05-12-2017 01:12:38)

Running from C:\Users\Win 7\Downloads

Windows 7 Ultimate Service Pack 1 (X64) (2017-08-05 11:22:31)

Boot Mode: Normal

==========================================================

==================== Accounts: =============================

Administrator (S-1-5-21-2737374540-661935763-2935816294-500 - Administrator - Disabled)

Guest (S-1-5-21-2737374540-661935763-2935816294-501 - Limited - Disabled)

HomeGroupUser$ (S-1-5-21-2737374540-661935763-2935816294-1002 - Limited - Enabled)

Win 7 (S-1-5-21-2737374540-661935763-2935816294-1000 - Administrator - Enabled) => C:\Users\Win


7

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Avira Antivirus (Enabled - Up to date) {B3F630BD-538D-1B4A-14FA-14B63235278F}

AS: Avira Antivirus (Enabled - Up to date) {0897D159-75B7-14C4-2E4A-2FC449B26D32}

AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================


(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware
programs should be uninstalled manually.)

Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version:


18.009.20050 - Adobe Systems Incorporated)

Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 4.3.0.256 - Adobe Systems
Incorporated)

Adobe Flash Player 26 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 26.0.0.137 - Adobe
Systems Incorporated)

Adobe Master Collection CC 2015 (HKLM-x32\...\{E8AD3069-9EB7-4BA8-8BFE-83F4E69355C3}) (Version:


9.0 - Adobe Systems Incorporated)

Adobe Scout CC (HKLM\...\{BA573BFE-83B4-11E3-93D2-D231FEB1DC81}) (Version: 1.1.3.354121 - Adobe


Systems Incorporated) Hidden

Adobe Shockwave Player 12.2 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.2.9.199 - Adobe
Systems, Inc.)

Avira (HKLM-x32\...\{37C2DE81-46FA-4EB3-83A5-F0D8F5B08F6E}) (Version: 1.2.99.31392 - Avira


Operations GmbH & Co. KG) Hidden

Avira (HKLM-x32\...\{5a024a65-9f29-41b1-b178-946c9f826e72}) (Version: 1.2.99.31392 - Avira


Operations GmbH & Co. KG)

Avira Antivirus (HKLM-x32\...\Avira Antivirus) (Version: 15.0.33.24 - Avira Operations GmbH & Co. KG)

Avira Phantom VPN (HKLM-x32\...\Avira Phantom VPN) (Version: 2.11.3.29834 - Avira Operations GmbH
& Co. KG)

Avira Safe Shopping (HKLM-x32\...\{32484ED7-3133-4E50-9882-F3DBB1ACDD25}) (Version: 1.0.37.1668 -


Avira Operations Gmbh & Co. KG)

Avira Software Updater (HKLM-x32\...\{E15B0074-D367-4A3C-8410-491F2C7E497F}) (Version:


2.0.4.17544 - Avira Operations GmbH & Co. KG)

Avira System Speedup (HKLM-x32\...\Avira System Speedup_is1) (Version: 4.4.0.6828 - Avira Operations
GmbH & Co. KG)

BitTorrent (HKU\S-1-5-21-2737374540-661935763-2935816294-1000\...\BitTorrent) (Version:


7.10.0.43917 - BitTorrent Inc.)

CCleaner (HKLM\...\CCleaner) (Version: 5.12 - Piriform)


Counter Strike Source WaRzOnE (HKLM-x32\...\{3F77C740-D6C8-4BDB-B730-49C8D8BCA9ED}) (Version:
2.0 - Warzone) Hidden

Counter Strike Source WaRzOnE (HKLM-x32\...\Counter Strike Source WaRzOnE 2.0) (Version: 2.0 -
Warzone)

Electroneum Pool Miner BETA v1.1 (HKLM-x32\...\Electroneum Pool Miner BETA v1.1) (Version: - )

Exodus (HKU\S-1-5-21-2737374540-661935763-2935816294-1000\...\exodus) (Version: 1.33.2 - Exodus


Movement Inc)

FMSE17 (HKLM\...\{11B609E0-43B4-40B2-AD17-5978F29DAC0C}) (Version: 0.7.0.0 - AppCake Limited)


Hidden

FMSE17 (HKLM-x32\...\{2cf6af2c-f243-426f-a0ca-0e57088a59de}) (Version: 0.7.0.0 - AppCake Limited)

FreeLAN 2.0.0 (HKLM\...\{3AE669E7-36C2-48DF-985B-6037F9AF69A8}_is1) (Version: 2.0.0 - Julien


Kauffmann)

Google Chrome (HKLM-x32\...\Google Chrome) (Version: 62.0.3202.94 - Google Inc.)

Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.7 -


Google Inc.) Hidden

Intel(R) PROSet/Wireless WiFi Software (HKLM\...\{1927E640-A2C6-4BA7-8F43-FFD2AE3DFCF3})


(Version: 14.0.2000 - Intel Corporation)

Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version:


11.1.0.1006 - Intel Corporation)

Java 8 Update 144 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180144F0}) (Version: 8.0.1440.1


- Oracle Corporation)

Java 8 Update 144 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180144F0}) (Version: 8.0.1440.1 -


Oracle Corporation)

LSI HDA Modem (HKLM\...\LSI Soft Modem) (Version: 2.2.101 - LSI Corporation)

Marvelous Designer 6 Enterprise Online Auth (HKLM-x32\...\Marvelous Designer 6 Enterprise Online


Auth) (Version: - CLO Virtual Fashion Inc.)

Microsoft .NET Framework 4.7 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version:


4.7.02053 - Microsoft Corporation)

Microsoft Office Professional Plus 2010 (HKLM\...\Office14.PROPLUS) (Version: 14.0.4763.1000 -


Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 -
Microsoft Corporation)

Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d})


(Version: 8.0.56336 - Microsoft Corporation)

Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f})


(Version: 8.0.56336 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-


13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-


BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)

Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-


6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)

Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-


68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)

Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-


4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)

Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-


97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)

Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-


47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)

Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-


0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)

Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-


fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation)

Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-


3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)

Mouse Server version 1.7.7.4 (HKLM-x32\...\{7AFAA880-BB05-4E38-9279-C53EECE1B7BE}_is1) (Version:


1.7.7.4 - Necta Inc.)

Opera Stable 49.0.2725.47 (HKLM-x32\...\Opera 49.0.2725.47) (Version: 49.0.2725.47 - Opera Software)

Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9.141.259 - Google, Inc.)

Popcorn Time (HKLM-x32\...\Popcorn Time_is1) (Version: 5.6.1.0 - Popcorn Time) <==== ATTENTION
Popcorn Time Community (HKLM-x32\...\{F9BC7890-4FE5-4391-8C59-CD0C556EF115}) (Version: 0.4.0 -
yify.is) <==== ATTENTION

Qualcomm Atheros WiFi Driver Installation (HKLM-x32\...\{7D916FA5-DAE9-4A25-B089-655C70EAF607})


(Version: 9.2 - Qualcomm Atheros)

Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC})


(Version: 6.0.1.7285 - Realtek Semiconductor Corp.)

Resident Evil Revelations (HKLM-x32\...\Resident Evil Revelations_is1) (Version: - Capcom)

Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)

swMSM (HKLM-x32\...\{612C34C7-5E90-47D8-9B5C-0F717DD82726}) (Version: 12.0.0.1 - Adobe


Systems, Inc) Hidden

TAP-ProtonVPN 9.21.2 (HKLM\...\TAP-ProtonVPN) (Version: 9.21.2 - ProtonVPN AG)

TAP-Windows 9.21.2 (HKLM\...\TAP-Windows) (Version: 9.21.2 - )

TunnelBear (HKLM-x32\...\{8092fbe5-9e59-4729-a5de-5bb6a64873cc}) (Version: 3.0.37.12 - TunnelBear)

TunnelBear (HKLM-x32\...\{ABC9BE61-B890-4100-BCA4-5AC3BF1F3CB5}) (Version: 3.0.37.12 -


TunnelBear) Hidden

UserTesting (HKU\S-1-5-21-2737374540-661935763-2935816294-1000\...\UserTestingPlugin) (Version: -


UserTesting.com)

VLC media player (HKLM\...\VLC media player) (Version: 2.2.6 - VideoLAN)

WinRAR 5.21 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless
listed separately.)

CustomCLSID: HKU\S-1-5-21-2737374540-661935763-2935816294-1000_Classes\CLSID\{e8c77137-
e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative
Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems)
ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program
Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2017-09-26] ()

ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} =>


C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2017-09-26] ()

ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program


Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2017-09-26] ()

ContextMenuHandlers1: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files


(x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2017-09-26] ()

ContextMenuHandlers1: [Shell Extension for Malware scanning] -> {45AC2688-0253-4ED8-97DE-


B5370FA7D48A} => C:\Program Files (x86)\Avira\Antivirus\shlext64.dll [2017-12-01] (Avira Operations
GmbH & Co. KG)

ContextMenuHandlers1: [SystemSpeedupFilesMenu] -> {ef263503-8f0e-3e6a-ae2e-fe0b4b441d52} =>


C:\Windows\system32\mscoree.dll [2010-11-21] (Microsoft Corporation)

ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program


Files\WinRAR\rarext.dll [2015-02-15] (Alexander Roshal)

ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} =>


C:\Program Files\WinRAR\rarext32.dll [2015-02-15] (Alexander Roshal)

ContextMenuHandlers4: [SystemSpeedupFoldersMenu] -> {3d52b24d-33bb-3895-99ea-a0156f24a3f9}


=> C:\Windows\system32\mscoree.dll [2010-11-21] (Microsoft Corporation)

ContextMenuHandlers5: [SystemSpeedupDesktopMenu] -> {cefaf456-bc17-3f4b-b7d9-75070925911b}


=> C:\Windows\system32\mscoree.dll [2010-11-21] (Microsoft Corporation)

ContextMenuHandlers6: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files


(x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2017-09-26] ()

ContextMenuHandlers6: [Shell Extension for Malware scanning] -> {45AC2688-0253-4ED8-97DE-


B5370FA7D48A} => C:\Program Files (x86)\Avira\Antivirus\shlext64.dll [2017-12-01] (Avira Operations
GmbH & Co. KG)

ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program


Files\WinRAR\rarext.dll [2015-02-15] (Alexander Roshal)

ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} =>


C:\Program Files\WinRAR\rarext32.dll [2015-02-15] (Alexander Roshal)

==================== Scheduled Tasks (Whitelisted) =============


(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless
listed separately.)

Task: {053BCB64-532D-45E9-B3B0-AD1C1B4CEDE1} - System32\Tasks\AutoKMS =>


C:\Windows\AutoKMS\AutoKMS.exe [2017-08-06] ()

Task: {1A690525-007B-4F9C-8E93-6F57E12665B9} - System32\Tasks\Avira Safe Shopping Updater =>


C:\Program Files (x86)\Avira\Safe Shopping\\Updater\Updater.exe [2017-10-30] (Avira Operations Gmbh
& Co. KG)

Task: {205A5881-5C7B-4E9B-962A-013ACCF2D046} - System32\Tasks\AviraSystemSpeedupUpdate =>


C:\ProgramData\Avira\SystemSpeedup\Update\avira_speedup_setup_update.exe [2017-12-04] (Avira
Operations GmbH & Co. KG )

Task: {2CBD5703-5A12-4642-8AC5-5E28850EC49D} - System32\Tasks\Opera scheduled Autoupdate


1508256773 => C:\Program Files\Opera\launcher.exe [2017-11-23] (Opera Software)

Task: {4039D29A-10FB-48AA-89BD-9A35A7951F1B} - System32\Tasks\CCleanerSkipUAC => C:\Program


Files\CCleaner\CCleaner.exe [2015-11-16] (Piriform Ltd)

Task: {45787601-4088-40D4-AA97-F5E2213467EF} - System32\Tasks\Adobe Acrobat Update Task =>


C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-09-27] (Adobe Systems
Incorporated)

Task: {4C99E48A-ACB9-4F7D-B259-D8391A3B9F7C} - System32\Tasks\GoogleUpdateTaskMachineUA =>


C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-08-06] (Google Inc.)

Task: {4ECEFEA2-28D6-4EC4-8C3A-0AEC356DAAAB} - System32\Tasks\AdobeAAMUpdater-1.0-Win7-PC-


Win 7 => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe
[2016-07-01] (Adobe Systems Incorporated)

Task: {4F433F0F-8DC0-4B75-822D-947FA6F95938} - System32\Tasks\klcp_update => C:\Program Files


(x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [2017-08-03] ()

Task: {6AB0B956-EE63-4509-B521-642E040AD220} - System32\Tasks\Avira\System


Speedup\TestScheduler => C:\Program Files (x86)\Avira\System
Speedup\Avira.SystemSpeedup.Core.Common.Starter.exe [2017-12-04] (Avira Operations GmbH & Co.
KG)

Task: {7BC4C9FC-58A8-48B9-8D6C-E653F727476F} - System32\Tasks\GoogleUpdateTaskMachineCore =>


C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-08-06] (Google Inc.)
Task: {CA521486-D71D-44D9-8015-7775DB4800C6} - System32\Tasks\Avira SystrayStartTrigger =>
Avira.SystrayStartTrigger.exe

Task: {FBE327B6-1257-4433-81C5-CB83EC42FE9E} - System32\Tasks\Avira\System


Speedup\SpeedupSysTray => C:\Program Files (x86)\Avira\System
Speedup\Avira.SystemSpeedup.UI.Systray.exe [2017-12-04] (Avira Operations GmbH & Co. KG)

Task: {FD7B3EF7-4DEE-46A1-9AFA-0D751473587B} - System32\Tasks\Avira_Antivirus_Systray =>


C:\Program Files (x86)\Avira\Antivirus\avgnt.exe [2017-12-01] (Avira Operations GmbH & Co. KG)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task
will not be moved.)

Task: C:\Windows\Tasks\AutoKMS.job => C:\Windows\AutoKMS\AutoKMS.exe

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)

==================== Loaded Modules (Whitelisted) ==============

2011-01-05 11:53 - 2011-01-05 11:53 - 001501696 _____ () C:\Program Files\Common


Files\Intel\WirelessCommon\Libeay32.dll

2017-10-18 20:47 - 2015-05-07 20:36 - 003486720 _____ () C:\Program Files\FreeLAN\bin\freelan.exe

2017-09-06 15:48 - 2017-09-06 15:48 - 000037248 _____ () C:\Program Files


(x86)\TunnelBear\TunnelBear.Maintenance.exe

2017-09-26 01:52 - 2017-09-26 01:52 - 000491600 _____ () C:\Program Files (x86)\Common


Files\Adobe\CoreSyncExtension\CoreSync_x64.dll

2015-11-16 17:55 - 2015-11-16 17:55 - 000057344 _____ () C:\Program Files\CCleaner\lang\lang-


2074.dll
2017-09-26 01:52 - 2017-09-26 01:52 - 034879568 _____ () C:\Program Files (x86)\Adobe\Adobe
Sync\Coresync\Coresync.exe

2017-11-13 21:25 - 2017-11-10 10:57 - 004135768 _____ () C:\Program Files


(x86)\Google\Chrome\Application\62.0.3202.94\libglesv2.dll

2017-11-13 21:25 - 2017-11-10 10:57 - 000100184 _____ () C:\Program Files


(x86)\Google\Chrome\Application\62.0.3202.94\libegl.dll

2017-08-05 13:03 - 2017-08-05 13:03 - 000172032 _____ ()


C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\67f2d87ba056e1075fce76a8c50bb57e
\IsdiInterop.ni.dll

2017-08-05 13:03 - 2012-02-01 15:25 - 000059904 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid
Storage Technology\IsdiInterop.dll

2017-10-03 22:39 - 2017-09-09 20:25 - 000688416 _____ () C:\Users\Win 7\Desktop\Steam\SDL2.dll

2017-10-03 22:39 - 2016-09-01 02:02 - 004969248 _____ () C:\Users\Win 7\Desktop\Steam\v8.dll

2017-10-03 22:39 - 2016-09-01 02:02 - 001563936 _____ () C:\Users\Win 7\Desktop\Steam\icui18n.dll

2017-10-03 22:39 - 2016-09-01 02:02 - 001195296 _____ () C:\Users\Win 7\Desktop\Steam\icuuc.dll

2017-10-03 22:39 - 2017-10-31 04:22 - 002546976 _____ () C:\Users\Win 7\Desktop\Steam\video.dll

2017-10-03 22:39 - 2016-01-27 08:49 - 002549760 _____ () C:\Users\Win 7\Desktop\Steam\libavcodec-


56.dll

2017-10-03 22:39 - 2016-01-27 08:49 - 000442880 _____ () C:\Users\Win 7\Desktop\Steam\libavutil-


54.dll

2017-10-03 22:39 - 2016-01-27 08:49 - 000491008 _____ () C:\Users\Win 7\Desktop\Steam\libavformat-


56.dll

2017-10-03 22:39 - 2016-01-27 08:49 - 000332800 _____ () C:\Users\Win


7\Desktop\Steam\libavresample-2.dll

2017-10-03 22:39 - 2016-01-27 08:49 - 000485888 _____ () C:\Users\Win 7\Desktop\Steam\libswscale-


3.dll

2017-10-03 22:39 - 2017-10-31 04:22 - 000901408 _____ () C:\Users\Win


7\Desktop\Steam\bin\chromehtml.DLL

2017-10-03 22:41 - 2017-08-16 23:28 - 073130272 _____ () C:\Users\Win


7\Desktop\Steam\bin\cef\cef.win7\libcef.dll
2017-10-03 22:41 - 2017-09-07 03:04 - 000678400 _____ () C:\Users\Win
7\Desktop\Steam\bin\cef\cef.win7\SDL2.dll

2017-10-03 22:39 - 2015-09-25 00:52 - 000119208 _____ () C:\Users\Win 7\Desktop\Steam\winh264.dll

2017-09-06 17:11 - 2017-09-06 17:11 - 000118272 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe


Creative Cloud\CCXProcess\js\node_modules\fs-ext\build\Release\fs-ext.node

2017-09-06 17:11 - 2017-09-06 17:11 - 000214528 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe


Creative Cloud\CCXProcess\js\node_modules\node-vulcanjs\build\Release\VulcanJS.node

2017-09-06 17:11 - 2017-09-06 17:11 - 000117248 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe


Creative Cloud\CCXProcess\js\node_modules\ref\build\Release\binding.node

2017-09-06 17:11 - 2017-09-06 17:11 - 000125952 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe


Creative Cloud\CCXProcess\js\node_modules\ffi\build\Release\ffi_bindings.node

2017-09-20 02:04 - 2017-09-20 02:04 - 000110688 _____ () C:\Program Files (x86)\Adobe\Adobe


Creative Cloud\CCXProcess\js\node_modules\node-ProxyResolver\build\Release\ProxyResolverWin7.dll

2017-09-06 17:11 - 2017-09-06 17:11 - 000086528 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe


Creative Cloud\CCXProcess\js\node_modules\idle-gc\build\Release\idle-gc.node

2017-09-12 19:11 - 2017-09-12 19:11 - 000118272 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe


Creative Cloud\CCLibrary\js\node_modules\fs-ext\build\Release\fs-ext.node

2017-09-12 19:10 - 2017-09-12 19:10 - 000117760 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe


Creative Cloud\CCLibrary\js\node_modules\ref\build\Release\binding.node

2017-09-12 19:11 - 2017-09-12 19:11 - 000125440 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe


Creative Cloud\CCLibrary\js\node_modules\ffi\build\Release\ffi_bindings.node

2017-09-12 19:11 - 2017-09-12 19:11 - 000214528 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe


Creative Cloud\CCLibrary\js\node_modules\node-vulcanjs\build\Release\VulcanJS.node

2017-09-20 01:59 - 2017-09-20 01:59 - 000110688 _____ () C:\Program Files (x86)\Adobe\Adobe


Creative Cloud\CCLibrary\js\node_modules\node-ProxyResolver\build\Release\ProxyResolverWin7.dll

2017-09-12 19:11 - 2017-09-12 19:11 - 000098816 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe


Creative Cloud\CCLibrary\js\node_modules\bufferutil\build\Release\bufferutil.node

2017-09-12 19:11 - 2017-09-12 19:11 - 000086528 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe


Creative Cloud\CCLibrary\js\node_modules\idle-gc\build\Release\idle-gc.node

==================== Alternate Data Streams (Whitelisted) =========


(If an entry is included in the fixlist, only the ADS will be removed.)

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be
restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 03:34 - 2009-06-10 22:00 - 000000824 _____ C:\Windows\system32\Drivers\etc\hosts

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-2737374540-661935763-2935816294-1000\Control Panel\Desktop\\Wallpaper ->


C:\Users\Win 7\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg

DNS Servers: 192.168.0.1

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System =>
(ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 0)

Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless
listed separately.)

FirewallRules: [{98584452-BDB5-4662-B0D3-A322F37CC855}] => (Allow) C:\Program


Files\Intel\WiFi\bin\PanDhcpDns.exe

FirewallRules: [TCP Query User{94D498CD-2494-4DBD-A482-


044BBA154276}C:\windows\kmsemulator.exe] => (Block) C:\windows\kmsemulator.exe

FirewallRules: [UDP Query User{9BE6B934-A031-4DB1-BB83-


0BBB6276BB9A}C:\windows\kmsemulator.exe] => (Block) C:\windows\kmsemulator.exe
FirewallRules: [{9F36BE82-B47E-467F-92F8-9BE49F9CB280}] => (Allow) C:\Users\Win
7\AppData\Roaming\BitTorrent\BitTorrent.exe

FirewallRules: [{B9C74CAA-B770-4998-A0C1-A02D92241E7E}] => (Allow) C:\Users\Win


7\AppData\Roaming\BitTorrent\BitTorrent.exe

FirewallRules: [TCP Query User{77E67E85-218F-41FE-9D0C-8C7F797E1370}C:\warzone\counter strike


source warzone\hl2.exe] => (Allow) C:\warzone\counter strike source warzone\hl2.exe

FirewallRules: [UDP Query User{DEFDA539-4226-41F2-8BCE-56130DA392DD}C:\warzone\counter strike


source warzone\hl2.exe] => (Allow) C:\warzone\counter strike source warzone\hl2.exe

FirewallRules: [{56A15B5F-D320-45D4-AF69-851E60291BC0}] => (Allow) C:\Users\Win


7\Desktop\Steam\Steam.exe

FirewallRules: [{11C7F73E-BF41-42E3-BA43-18A1C998B8F0}] => (Allow) C:\Users\Win


7\Desktop\Steam\Steam.exe

FirewallRules: [{0D0A4122-2809-4D0E-AB69-55E8102709D3}] => (Allow) C:\Users\Win


7\Desktop\Steam\bin\cef\cef.win7\steamwebhelper.exe

FirewallRules: [{C9DD4A2D-D914-4BB5-BA24-944458C6ABBB}] => (Allow) C:\Users\Win


7\Desktop\Steam\bin\cef\cef.win7\steamwebhelper.exe

FirewallRules: [{8224DE93-2D33-49C7-BB40-59895B01F54B}] => (Allow)


C:\Windows\system32\hasplms.exe

FirewallRules: [{52BB210F-89D5-49D6-90C5-E6130CE4D136}] => (Block) %ProgramFiles%\Marvelous


Designer 6 Enterprise Online Auth\MarvelousDesigner6_Enterprise_OnlineAuth_x64.exe

FirewallRules: [TCP Query User{CAC99D42-C70C-41F2-9786-E728286BB463}C:\users\win


7\appdata\local\popcorn time community\nw.exe] => (Allow) C:\users\win 7\appdata\local\popcorn
time community\nw.exe

FirewallRules: [UDP Query User{A82D89C7-1C38-4FF0-A598-68831B6FC933}C:\users\win


7\appdata\local\popcorn time community\nw.exe] => (Allow) C:\users\win 7\appdata\local\popcorn
time community\nw.exe

FirewallRules: [TCP Query User{06DF2E7D-D2E9-4B2E-820C-77A452D6C8C3}C:\users\win


7\appdata\local\popcorn time community\nw.exe] => (Block) C:\users\win 7\appdata\local\popcorn
time community\nw.exe

FirewallRules: [UDP Query User{48B8CD79-8184-4CEE-8617-8F41D65ADACC}C:\users\win


7\appdata\local\popcorn time community\nw.exe] => (Block) C:\users\win 7\appdata\local\popcorn
time community\nw.exe
FirewallRules: [TCP Query User{3CBAB5BE-8990-4122-9420-05641BEBF92B}C:\program files
(x86)\mouse server\mouseserver.exe] => (Allow) C:\program files (x86)\mouse server\mouseserver.exe

FirewallRules: [UDP Query User{B20B27B2-D7D9-41D5-B836-AD3A9DEF113C}C:\program files


(x86)\mouse server\mouseserver.exe] => (Allow) C:\program files (x86)\mouse server\mouseserver.exe

FirewallRules: [{939E11C6-B548-4C9D-8BAC-2D4845105351}] => (Block) C:\program files (x86)\mouse


server\mouseserver.exe

FirewallRules: [{71CDD9D1-D2C0-4661-A80B-83659D94944A}] => (Block) C:\program files (x86)\mouse


server\mouseserver.exe

FirewallRules: [{C3919431-92F6-4412-866C-6B82FA10E967}] => (Allow) C:\Program Files (x86)\Popcorn


Time\Updater.exe

FirewallRules: [{5DA1C98F-4EA6-4FB0-B017-3106FB96FA5B}] => (Allow) C:\Program Files (x86)\Popcorn


Time\Updater.exe

FirewallRules: [{D76884E2-34D3-45B3-ADA8-1593A200DDB3}] => (Allow) C:\Program Files


(x86)\Popcorn Time\Updater.exe

FirewallRules: [{4A5E01D0-F1DA-45E2-92CF-22C075498C55}] => (Allow) C:\Program Files (x86)\Popcorn


Time\Updater.exe

FirewallRules: [{89131770-7FF6-473C-9701-296664D2A37C}] => (Allow) C:\Program Files (x86)\Popcorn


Time\PopcornTimeDesktop.exe

FirewallRules: [{433B4053-9DE6-4994-B0D4-B395A3038069}] => (Allow) C:\Program Files (x86)\Popcorn


Time\PopcornTimeDesktop.exe

FirewallRules: [{88C5488A-0FB8-45DB-8BAA-E827007D9D2D}] => (Allow) C:\Program Files (x86)\Popcorn


Time\PopcornTimeDesktop.exe

FirewallRules: [{A6E818DD-EACA-4610-B467-D5A0F93C75FD}] => (Allow) C:\Program Files (x86)\Popcorn


Time\PopcornTimeDesktop.exe

FirewallRules: [{A7128AE9-50CB-46E8-AC7F-1C6C2F6BF152}] => (Allow) C:\Program Files (x86)\Popcorn


Time\chromecast\node.exe

FirewallRules: [{720FCE30-F062-4151-A0F4-F82BCFD1D6CA}] => (Allow) C:\Program Files (x86)\Popcorn


Time\chromecast\node.exe

FirewallRules: [TCP Query User{2E3CF2E7-2204-4675-B317-68FBF30DDD03}C:\program files


(x86)\popcorn time\chromecast\node.exe] => (Allow) C:\program files (x86)\popcorn
time\chromecast\node.exe
FirewallRules: [UDP Query User{1FC3B807-4501-4AA4-AD84-E1F6E24D4665}C:\program files
(x86)\popcorn time\chromecast\node.exe] => (Allow) C:\program files (x86)\popcorn
time\chromecast\node.exe

FirewallRules: [{21D5332F-E72E-491E-B3AB-45C7F9D2CCC9}] => (Allow) C:\Program Files


(x86)\Google\Chrome\Application\chrome.exe

FirewallRules: [{2996D05B-81A3-4AF6-89EE-ED10EC2CE105}] => (Allow) C:\Program


Files\Opera\49.0.2725.39\opera.exe

FirewallRules: [{A29178E3-BFCC-4C74-9548-200A2BDA7489}] => (Allow) C:\Program


Files\Opera\49.0.2725.47\opera.exe

==================== Restore Points =========================

==================== Faulty Device Manager Devices =============

Name: TunnelBear Adapter V9

Description: TunnelBear Adapter V9

Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}

Manufacturer: TunnelBear Provider V9

Service: tap-tb-0901

Problem: : This device is disabled. (Code 22)

Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable
Device wizard. Follow the instructions.

Name: TAP-Windows Adapter V9 #2

Description: TAP-Windows Adapter V9

Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}

Manufacturer: TAP-Windows Provider V9


Service: tap0901

Problem: : This device is disabled. (Code 22)

Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable
Device wizard. Follow the instructions.

==================== Event log errors: =========================

Application errors:

==================

Error: (12/05/2017 01:02:49 AM) (Source: Application Error) (EventID: 1005) (User: )

Description: Windows cannot access the file for one of the following reasons:

there is a problem with the network connection, the disk that the file is stored on, or the storage

drivers installed on this computer; or the disk is missing.

Windows closed the program minerd.exe because of this error.

Program: minerd.exe

File:

The error value is listed in the Additional Data section.

User Action

1. Open the file again.

This situation might be a temporary problem that corrects itself when the program runs again.

2.

If the file still cannot be accessed and

- It is on the network,
your network administrator should verify that there is not a problem with the network and that the
server can be contacted.

- It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the disk is fully
inserted into the computer.

3. Check and repair the file system by running CHKDSK. To run CHKDSK, click Start, click Run, type CMD,
and then click OK. At the command prompt, type CHKDSK /F, and then press ENTER.

4. If the problem persists, restore the file from a backup copy.

5. Determine whether other files on the same disk can be opened. If not, the disk might be damaged. If
it is a hard disk, contact your administrator or computer hardware vendor for

further assistance.

Additional Data

Error value: 00000000

Disk type: 0

Error: (12/05/2017 01:02:49 AM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application name: minerd.exe, version: 0.0.0.0, time stamp: 0x000e6bfc

Faulting module name: minerd.exe, version: 0.0.0.0, time stamp: 0x000e6bfc

Exception code: 0xc000001d

Fault offset: 0x000000000005c0a8

Faulting process id: 0x1fc8

Faulting application start time: 0x01d36d5c63572b9f

Faulting application path: C:\Users\Win 7\AppData\Roaming\Electroneum\cpuminer-multi-wolf-


AES\minerd.exe

Faulting module path: C:\Users\Win 7\AppData\Roaming\Electroneum\cpuminer-multi-wolf-


AES\minerd.exe

Report Id: a1087940-d94f-11e7-be74-4061861f71d2


Error: (12/05/2017 01:02:44 AM) (Source: Application Error) (EventID: 1005) (User: )

Description: Windows cannot access the file for one of the following reasons:

there is a problem with the network connection, the disk that the file is stored on, or the storage

drivers installed on this computer; or the disk is missing.

Windows closed the program minerd.exe because of this error.

Program: minerd.exe

File:

The error value is listed in the Additional Data section.

User Action

1. Open the file again.

This situation might be a temporary problem that corrects itself when the program runs again.

2.

If the file still cannot be accessed and

- It is on the network,

your network administrator should verify that there is not a problem with the network and that the
server can be contacted.

- It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the disk is fully
inserted into the computer.

3. Check and repair the file system by running CHKDSK. To run CHKDSK, click Start, click Run, type CMD,
and then click OK. At the command prompt, type CHKDSK /F, and then press ENTER.

4. If the problem persists, restore the file from a backup copy.

5. Determine whether other files on the same disk can be opened. If not, the disk might be damaged. If
it is a hard disk, contact your administrator or computer hardware vendor for

further assistance.
Additional Data

Error value: 00000000

Disk type: 0

Error: (12/05/2017 01:02:44 AM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application name: minerd.exe, version: 0.0.0.0, time stamp: 0x000e6bfc

Faulting module name: minerd.exe, version: 0.0.0.0, time stamp: 0x000e6bfc

Exception code: 0xc000001d

Fault offset: 0x000000000005c0a8

Faulting process id: 0xe58

Faulting application start time: 0x01d36d5c609849c3

Faulting application path: C:\Users\Win 7\AppData\Roaming\Electroneum\cpuminer-multi-wolf-


AES\minerd.exe

Faulting module path: C:\Users\Win 7\AppData\Roaming\Electroneum\cpuminer-multi-wolf-


AES\minerd.exe

Report Id: 9e4bf8c4-d94f-11e7-be74-4061861f71d2

Error: (12/05/2017 01:02:12 AM) (Source: Application Error) (EventID: 1005) (User: )

Description: Windows cannot access the file for one of the following reasons:

there is a problem with the network connection, the disk that the file is stored on, or the storage

drivers installed on this computer; or the disk is missing.

Windows closed the program minerd.exe because of this error.

Program: minerd.exe

File:
The error value is listed in the Additional Data section.

User Action

1. Open the file again.

This situation might be a temporary problem that corrects itself when the program runs again.

2.

If the file still cannot be accessed and

- It is on the network,

your network administrator should verify that there is not a problem with the network and that the
server can be contacted.

- It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the disk is fully
inserted into the computer.

3. Check and repair the file system by running CHKDSK. To run CHKDSK, click Start, click Run, type CMD,
and then click OK. At the command prompt, type CHKDSK /F, and then press ENTER.

4. If the problem persists, restore the file from a backup copy.

5. Determine whether other files on the same disk can be opened. If not, the disk might be damaged. If
it is a hard disk, contact your administrator or computer hardware vendor for

further assistance.

Additional Data

Error value: 00000000

Disk type: 0

Error: (12/05/2017 01:02:12 AM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application name: minerd.exe, version: 0.0.0.0, time stamp: 0x000e6bfc

Faulting module name: minerd.exe, version: 0.0.0.0, time stamp: 0x000e6bfc

Exception code: 0xc000001d

Fault offset: 0x000000000005c0a8


Faulting process id: 0x1dc4

Faulting application start time: 0x01d36d5c4d1fc406

Faulting application path: C:\Users\Win 7\AppData\Roaming\Electroneum\cpuminer-multi-wolf-


AES\minerd.exe

Faulting module path: C:\Users\Win 7\AppData\Roaming\Electroneum\cpuminer-multi-wolf-


AES\minerd.exe

Report Id: 8b3e90f3-d94f-11e7-be74-4061861f71d2

Error: (12/05/2017 12:59:41 AM) (Source: Application Error) (EventID: 1005) (User: )

Description: Windows cannot access the file for one of the following reasons:

there is a problem with the network connection, the disk that the file is stored on, or the storage

drivers installed on this computer; or the disk is missing.

Windows closed the program minerd.exe because of this error.

Program: minerd.exe

File:

The error value is listed in the Additional Data section.

User Action

1. Open the file again.

This situation might be a temporary problem that corrects itself when the program runs again.

2.

If the file still cannot be accessed and

- It is on the network,

your network administrator should verify that there is not a problem with the network and that the
server can be contacted.
- It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the disk is fully
inserted into the computer.

3. Check and repair the file system by running CHKDSK. To run CHKDSK, click Start, click Run, type CMD,
and then click OK. At the command prompt, type CHKDSK /F, and then press ENTER.

4. If the problem persists, restore the file from a backup copy.

5. Determine whether other files on the same disk can be opened. If not, the disk might be damaged. If
it is a hard disk, contact your administrator or computer hardware vendor for

further assistance.

Additional Data

Error value: 00000000

Disk type: 0

Error: (12/05/2017 12:59:41 AM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application name: minerd.exe, version: 0.0.0.0, time stamp: 0x000e6bfc

Faulting module name: minerd.exe, version: 0.0.0.0, time stamp: 0x000e6bfc

Exception code: 0xc000001d

Fault offset: 0x000000000005c0a8

Faulting process id: 0x1e38

Faulting application start time: 0x01d36d5bf32b4406

Faulting application path: C:\Users\Win 7\AppData\Roaming\Electroneum\cpuminer-multi-wolf-


AES\minerd.exe

Faulting module path: C:\Users\Win 7\AppData\Roaming\Electroneum\cpuminer-multi-wolf-


AES\minerd.exe

Report Id: 30db12eb-d94f-11e7-be74-4061861f71d2

Error: (12/05/2017 12:59:19 AM) (Source: Application Error) (EventID: 1005) (User: )
Description: Windows cannot access the file for one of the following reasons:

there is a problem with the network connection, the disk that the file is stored on, or the storage

drivers installed on this computer; or the disk is missing.

Windows closed the program minerd.exe because of this error.

Program: minerd.exe

File:

The error value is listed in the Additional Data section.

User Action

1. Open the file again.

This situation might be a temporary problem that corrects itself when the program runs again.

2.

If the file still cannot be accessed and

- It is on the network,

your network administrator should verify that there is not a problem with the network and that the
server can be contacted.

- It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the disk is fully
inserted into the computer.

3. Check and repair the file system by running CHKDSK. To run CHKDSK, click Start, click Run, type CMD,
and then click OK. At the command prompt, type CHKDSK /F, and then press ENTER.

4. If the problem persists, restore the file from a backup copy.

5. Determine whether other files on the same disk can be opened. If not, the disk might be damaged. If
it is a hard disk, contact your administrator or computer hardware vendor for

further assistance.

Additional Data
Error value: 00000000

Disk type: 0

Error: (12/05/2017 12:59:19 AM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application name: minerd.exe, version: 0.0.0.0, time stamp: 0x000e6bfc

Faulting module name: minerd.exe, version: 0.0.0.0, time stamp: 0x000e6bfc

Exception code: 0xc000001d

Fault offset: 0x000000000005c0a8

Faulting process id: 0x11f0

Faulting application start time: 0x01d36d5be654cad7

Faulting application path: C:\Users\Win 7\AppData\Roaming\Electroneum\cpuminer-multi-wolf-


AES\minerd.exe

Faulting module path: C:\Users\Win 7\AppData\Roaming\Electroneum\cpuminer-multi-wolf-


AES\minerd.exe

Report Id: 24062061-d94f-11e7-be74-4061861f71d2

System errors:

=============

Error: (12/04/2017 04:39:00 AM) (Source: Service Control Manager) (EventID: 7031) (User: )

Description: The Avira Real-Time Protection service terminated unexpectedly. It has done this 1 time(s).
The following corrective action will be taken in 0 milliseconds: Restart the service.

Error: (12/03/2017 09:49:02 PM) (Source: Service Control Manager) (EventID: 7034) (User: )

Description: The Update service service terminated unexpectedly. It has done this 1 time(s).

Error: (12/01/2017 09:12:13 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Avira Real-Time Protection service terminated unexpectedly. It has done this 1 time(s).
The following corrective action will be taken in 0 milliseconds: Restart the service.

Error: (11/18/2017 02:40:46 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003)


(User: NT AUTHORITY)

Description: WLAN Extensibility Module has stopped unexpectedly.

Module Path: C:\Windows\System32\IWMSSvc.dll

Error: (11/18/2017 02:40:46 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003)


(User: NT AUTHORITY)

Description: WLAN Extensibility Module has stopped unexpectedly.

Module Path: C:\Windows\System32\IWMSSvc.dll

Error: (11/18/2017 02:40:31 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003)


(User: NT AUTHORITY)

Description: WLAN Extensibility Module has stopped unexpectedly.

Module Path: C:\Windows\System32\IWMSSvc.dll

Error: (11/17/2017 11:31:17 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003)


(User: NT AUTHORITY)

Description: WLAN Extensibility Module has stopped unexpectedly.

Module Path: C:\Windows\System32\IWMSSvc.dll


Error: (11/16/2017 02:54:55 AM) (Source: DCOM) (EventID: 10010) (User: )

Description: The server {53362C64-A296-4F2D-A2F8-FD984D08340B} did not register with DCOM within
the required timeout.

Error: (11/14/2017 07:42:19 PM) (Source: EventLog) (EventID: 6008) (User: )

Description: The previous system shutdown at 7:40:35 PM on 11/14/2017 was unexpected.

Error: (11/14/2017 02:12:23 AM) (Source: DCOM) (EventID: 10010) (User: )

Description: The server {53362C64-A296-4F2D-A2F8-FD984D08340B} did not register with DCOM within
the required timeout.

CodeIntegrity:

===================================

Date: 2017-12-04 16:36:04.847

Description: Windows is unable to verify the image integrity of the file


\Device\HarddiskVolume2\Windows\System32\drivers\tapprotonvpn.sys because file hash could not be
found on the system. A recent hardware or software change might have installed a file that is signed
incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2017-12-04 16:36:04.816

Description: Windows is unable to verify the image integrity of the file


\Device\HarddiskVolume2\Windows\System32\drivers\tapprotonvpn.sys because file hash could not be
found on the system. A recent hardware or software change might have installed a file that is signed
incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2017-12-03 21:45:15.613

Description: Windows is unable to verify the image integrity of the file


\Device\HarddiskVolume2\Windows\System32\drivers\tapprotonvpn.sys because file hash could not be
found on the system. A recent hardware or software change might have installed a file that is signed
incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2017-12-03 21:45:15.550

Description: Windows is unable to verify the image integrity of the file


\Device\HarddiskVolume2\Windows\System32\drivers\tapprotonvpn.sys because file hash could not be
found on the system. A recent hardware or software change might have installed a file that is signed
incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2017-12-03 15:54:56.486

Description: Windows is unable to verify the image integrity of the file


\Device\HarddiskVolume2\Windows\System32\drivers\tapprotonvpn.sys because file hash could not be
found on the system. A recent hardware or software change might have installed a file that is signed
incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2017-12-03 15:54:56.440

Description: Windows is unable to verify the image integrity of the file


\Device\HarddiskVolume2\Windows\System32\drivers\tapprotonvpn.sys because file hash could not be
found on the system. A recent hardware or software change might have installed a file that is signed
incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2017-12-01 19:01:23.925

Description: Windows is unable to verify the image integrity of the file


\Device\HarddiskVolume2\Windows\System32\drivers\tapprotonvpn.sys because file hash could not be
found on the system. A recent hardware or software change might have installed a file that is signed
incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2017-12-01 19:01:23.878

Description: Windows is unable to verify the image integrity of the file


\Device\HarddiskVolume2\Windows\System32\drivers\tapprotonvpn.sys because file hash could not be
found on the system. A recent hardware or software change might have installed a file that is signed
incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2017-11-21 00:04:38.549

Description: Windows is unable to verify the image integrity of the file


\Device\HarddiskVolume2\Windows\System32\drivers\tapprotonvpn.sys because file hash could not be
found on the system. A recent hardware or software change might have installed a file that is signed
incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2017-11-21 00:04:38.518

Description: Windows is unable to verify the image integrity of the file


\Device\HarddiskVolume2\Windows\System32\drivers\tapprotonvpn.sys because file hash could not be
found on the system. A recent hardware or software change might have installed a file that is signed
incorrectly or damaged, or that might be malicious software from an unknown source.

==================== Memory info ===========================

Processor: Intel(R) Core(TM) i5 CPU M 430 @ 2.27GHz

Percentage of memory in use: 58%

Total physical RAM: 3949.59 MB

Available physical RAM: 1624.62 MB

Total Virtual: 7897.37 MB

Available Virtual: 3878.7 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:195.21 GB) (Free:56.72 GB) NTFS

Drive d: () (Fixed) (Total:270.45 GB) (Free:254.53 GB) NTFS

Drive f: (New Volume) (Fixed) (Total:465.76 GB) (Free:465.66 GB) NTFS


==================== MBR & Partition Table ==================

========================================================

Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 0001DB15)

Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)

Partition 2: (Not Active) - (Size=195.2 GB) - (Type=07 NTFS)

Partition 3: (Not Active) - (Size=270.4 GB) - (Type=07 NTFS)

========================================================

Disk: 1 (Size: 465.8 GB) (Disk ID: 85AEF0D6)

Partition 1: (Not Active) - (Size=465.8 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================

Potrebbero piacerti anche