Additional scan result of Farbar Recovery Scan Tool (x64) Version:24-06-2015 Ran by David at 2015-06-27 02:24:21 Running from C:\Users\David\Downloads Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-3209958707-3427003406-1755347824-500 - Administrator - Disabled) => C:\Users\Administrator David (S-1-5-21-3209958707-3427003406-1755347824-1001 - Administrator - Enabled) => C:\Users\David David 2 (S-1-5-21-3209958707-3427003406-1755347824-1005 - Administrator - Enabled) => C:\Users\David 2 Guest (S-1-5-21-3209958707-3427003406-1755347824-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-3209958707-3427003406-1755347824-1003 - Limited - Enabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: 360 Total Security (Enabled - Up to date) {2B66EE1E-E5C8-C2F7-648F-4E55AC68D37D} AS: 360 Total Security (Enabled - Up to date) {90070FFA-C3F2-CD79-5E3F-7527D7EF99C0} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 360 Total Security (HKLM-x32\...\360TotalSecurity) (Version: 6.6.1.1024 - 360 Security Center) Chrome (HKLM-x32\...\Google Chrome) (Version: 43.0.2357.130 - Google Inc.) CyberLink MediaStory (HKLM-x32\...\InstallShield_{55762F9A-FCE3-45d5-817B-051218658423}) (Version: 1.0.1314 - CyberLink Corp.) CyberLink PhotoDirector 3 (HKLM-x32\...\InstallShield_{39337565-330E-4ab6-A9AE-AC81E0720B10}) (Version: 3.0.1.4107 - CyberLink Corp.) CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.0.2810 - CyberLink Corp.) CyberLink PowerDirector 10 (Version: 10.0.0.2810 - CyberLink Corp.) Hidden Dolby Digital Plus Home Theater (HKLM\...\{7E3D8FA1-6092-469A-955B-68FC4A2C67CA}) (Version: 7.5.1.1 - Dolby Laboratories Inc) Dragon Assistant 3 (HKLM-x32\...\{4693847A-7139-4CF4-B274-916C046C9E50}) (Version: 3.0.236 - Nuance Communications Inc.) Dragon Assistant 3 Language Data Pack en_US (HKLM-x32\...\{532A5345-1A42-4C55-B56E-CE753D0BAA02}) (Version: 3.0.236 - Nuance Communications Inc.) Energy Manager (HKLM-x32\...\InstallShield_{AC768037-7079-4658-AC24-2897650E0ABE}) (Version: 1.5.0.20 - Lenovo) Energy Manager (x32 Version: 1.5.0.20 - Lenovo) Hidden GeForce Experience NvStream Client Components (Version: 1.6.28 - NVIDIA Corporation) Hidden Google Update Helper (x32 Version: 1.3.27.5 - Google Inc.) Hidden Intel(R) Manageability Engine Firmware Recovery Agent (HKLM-x32\...\{0EC7F9CC-4741-45AE-9F55-6E9343F726F5}) (Version: 1.1.0.36960 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.15.1730 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3540 - Intel Corporation) Intel(R) Wireless Bluetooth(R) 4.0 (HKLM-x32\...\{96C730E4-F055-4118-BDF3-6E071763853C}) (Version: 3.0.1342.02 - Intel Corporation) Intel® PROSet/Wireless Software (HKLM-x32\...\{7e493493-a430-4b7b-b8a2-48d61599e220}) (Version: 17.0.0 - Intel Corporation) KakaoTalk (HKLM-x32\...\KakaoTalk) (Version: 2.0.6.843 - Daum Kakao Corp) League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games) League of Legends (x32 Version: 3.0.1 - Riot Games) Hidden Lenovo EasyCamera (HKLM-x32\...\{E0A7ED39-8CD6-4351-93C3-69CCA00D12B4}) (Version: 6.2.9200.10260 - Realtek Semiconductor Corp.) Lenovo Experience Improvement (HKLM\...\LenovoExperienceImprovement) (Version: 1.0.19.0 - Lenovo) Lenovo Motion Control (HKLM-x32\...\InstallShield_{A60E1DE0-2AD1-4BD3-BBCC-4FBB22FB6F85}) (Version: 2.5.1.0225 - PointGrab) Lenovo Motion Control (x32 Version: 2.5.1.0225 - PointGrab) Hidden Lenovo OneKey Recovery (HKLM-x32\...\InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 8.1.0.2619 - CyberLink Corp.) Lenovo OneKey Recovery (Version: 8.1.0.2619 - CyberLink Corp.) Hidden Lenovo PhoneCompanion (HKLM-x32\...\InstallShield_{0F82EA83-B0C5-4AB9-9695-DFE92C5FD57B}) (Version: 1.2.0.2 - Lenovo) Lenovo PhoneCompanion (x32 Version: 1.2.0.2 - Lenovo) Hidden Lenovo Photos (HKLM-x32\...\Lenovo Photos) (Version: 4.8.5 - CEWE COLOR AG u Co. OHG) Lenovo pointing device (HKLM\...\Elantech) (Version: 11.4.39.1 - ELAN Microelectronic Corp.) Lenovo PowerDVD10 (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.5630.52 - CyberLink Corp.) Lenovo PowerDVD10 (x32 Version: 10.0.5630.52 - CyberLink Corp.) Hidden Lenovo Reach (HKLM-x32\...\{3245D8C8-7FE0-4FD4-B04B-2720A333D592}) (Version: 1.1.3.5 - Stoneware, Inc.) Lenovo Settings (HKLM-x32\...\InstallShield_{42F8AFC3-7944-46CC-9689-94FF9869D0A7}) (Version: 1.0.0.46 - Lenovo) Lenovo Settings (x32 Version: 1.0.0.46 - Lenovo) Hidden Lenovo Smart Voice (HKLM\...\Lenovo SmartVoice) (Version: 1.0.2.2 - Lenovo) Lenovo Updates (HKLM-x32\...\InstallShield_{A2E1E9F0-0B68-4166-8C7F-85B563B84DF4}) (Version: 1.1.0.61 - Lenovo) Lenovo Updates (x32 Version: 1.1.0.61 - Lenovo) Hidden Lenovo VeriFace Pro (HKLM\...\Lenovo VeriFace) (Version: 5.1.14.3211 - Lenovo) Magic Transfer (HKLM\...\{AD2B2BD1-A1D7-4798-8FDD-B2A58FD94E68}) (Version: 1.1.1.11 - ) Magic Transfer (HKLM-x32\...\InstallShield_{AD2B2BD1-A1D7-4798-8FDD-B2A58FD94E68}) (Version: 1.1.1.11 - Lenovo) Magic Transfer (x32 Version: 1.1.1.11 - Lenovo) Hidden Maxthon Cloud Browser (HKLM-x32\...\Maxthon3) (Version: 4.1.3.5000 - Maxthon International Limited) Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Nitro Pro 9 (HKLM\...\{70B831B7-A8EE-4C5F-8F34-F383D24B3A04}) (Version: 9.0.5.9 - Nitro) NVIDIA GeForce Experience 1.8.2 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 1.8.2 - NVIDIA Corporation) NVIDIA Graphics Driver 332.50 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 332.50 - NVIDIA Corporation) NVIDIA PhysX System Software 9.13.0927 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.0927 - NVIDIA Corporation) NVIDIA Virtual Audio 1.2.20 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver) (Version: 1.2.20 - NVIDIA Corporation) Onekey Theater (HKLM-x32\...\{91CC5BAE-A098-40D3-A43B-C0DC7CE263FE}) (Version: 3.0.1.2 - Lenovo) Power2Go (HKLM-x32\...\{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 5.6.0.10525 - CyberLink Corp.) Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.2.9600.21243 - Realtek Semiconductor Corp.) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.20.815.2013 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7195 - Realtek Semiconductor Corp.) SHIELD Streaming (Version: 1.7.306 - NVIDIA Corporation) Hidden Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.4.0.9058 - Microsoft Corporation) Skype™ 7.6 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.6.103 - Skype Technologies S.A.) Spotify (HKU\S-1-5-21-3209958707-3427003406-1755347824-1001\...\Spotify) (Version: 1.0.7.157.g2a6526f9 - Spotify AB) StageLight (HKLM\...\StageLight) (Version: 1.3.0.4350 - Open Labs, LLC.) User Manuals (HKLM-x32\...\InstallShield_{F07C2CF8-4C53-4EC3-8162-A6221E36EB88}) (Version: 3.0.0.3 - Lenovo) User Manuals (x32 Version: 3.0.0.3 - Lenovo) Hidden Windows Driver Package - Lenovo (ACPIVPC) System (09/24/2013 19.29.2.34) (HKLM\...\EE9B1F2037C580F36D92FA431CC02BFF04C31F15) (Version: 09/24/2013 19.29.2.34 - Lenovo) Windows Driver Package - Lenovo (WUDFRd) LenovoVhid (07/25/2013 10.30.0.288) (HKLM\...\6BCA401E9CBEED970D75F55FA5320F60D11984E9) (Version: 07/25/2013 10.30.0.288 - Lenovo) 네이트 메일로 파일 전송 (HKLM-x32\...\네이트 메일로 파일 전송) (Version: - SK Communications) 네이트온 (HKLM-x32\...\{697E41EA-AEBE-4B5F-884E-87B5CD6C70AC}) (Version: - ) 네이트온 (HKLM-x32\...\{EA77EC9A-C82F-4F80-8B7D-D32C09A9C25F}) (Version: 5.1.19.0 - SK Communications) 토크온 (HKLM-x32\...\TALKON) (Version: - ) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-3209958707-3427003406-1755347824-1001_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\WINDOWS\system32\igfxEM.exe (Intel Corporation) ==================== Restore Points ========================= 26-06-2015 11:13:20 Installed DirectX 26-06-2015 11:14:32 League of Legends 설치됨 ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2013-08-22 22:25 - 2013-08-22 22:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {0A5826CF-E755-496C-B76F-7C954D1341BD} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-06-26] (Google Inc.) Task: {29BB00BF-3A76-4380-BE94-8819CACA4A38} - System32\Tasks\PDVDServ Task => C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.EXE [2013-03-09] (CyberLink Corp.) Task: {379ED726-4983-493F-A231-2618C6B9DE53} - System32\Tasks\OFFICE2013ACT => C:\ProgramData\Office2013\OFFICEICON.vbs [2013-06-03] () Task: {5069E469-CCC9-439C-BE68-F678E5CF4258} - System32\Tasks\Lenovo Smart Voice => C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvTrayLoad.exe [2014-07-06] (Lenovo) Task: {5E08902D-AC17-4575-BD70-8E1BE919E74F} - System32\Tasks\Lenovo\Experience Improvement => C:\Program Files\Lenovo\ExperienceImprovement\LenovoExperienceImprovement.exe [2015-06-26] (Lenovo) Task: {62F12801-D1B6-435B-AE84-7C41CA8F6440} - System32\Tasks\DolbySelectorTask => C:\Program Files\Dolby Digital Plus\ddp.exe Task: {66C5433C-28FC-4D2C-98FD-8D5B3190D982} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2013-03-08] (Intel Corporation) Task: {8A96E2F7-8F32-4D5F-9519-EEC913C9817A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-06-26] (Google Inc.) Task: {CB0ECFD6-1254-466D-A571-F306959D383E} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2013-03-08] (Intel Corporation) Task: {F23214CB-E8A5-430F-AAD6-17BC4AF6F9A3} - System32\Tasks\Maxthon Update => C:\Program Files (x86)\Maxthon\Bin\mxup.exe [2013-10-14] (Maxthon International ltd.) Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (Whitelisted) ============== 2013-05-10 09:58 - 2013-05-10 09:58 - 00119808 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\updateui.exe 2014-02-26 08:42 - 2014-02-26 08:42 - 02689800 _____ () C:\Program Files (x86)\Lenovo\Motion Control\WebcamSplitterFilter.ax 2015-06-26 10:52 - 2015-05-18 19:20 - 00559224 _____ () C:\Program Files (x86)\360\Total Security\safemon\wdui2.dll 2015-06-26 09:50 - 2015-06-20 14:46 - 01281864 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.130\libglesv2.dll 2015-06-26 09:50 - 2015-06-20 14:46 - 00080712 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.130\libegl.dll 2010-12-18 04:56 - 2010-12-18 04:56 - 02603520 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtCore4.dll 2010-01-13 08:55 - 2010-01-13 08:55 - 00322048 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\log4cplus.dll 2010-12-18 04:56 - 2010-12-18 04:56 - 00382464 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtXml4.dll 2010-12-17 04:16 - 2010-12-17 04:16 - 00195584 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\libgsoap.dll 2013-03-08 04:54 - 2013-03-08 04:54 - 00071680 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\ServiceManagerStarter.dll 2010-01-18 15:34 - 2010-01-18 15:34 - 00062464 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\zlib1.dll 2010-12-18 04:56 - 2010-12-18 04:56 - 01006592 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtNetwork4.dll 2013-03-08 04:53 - 2013-03-08 04:53 - 00015872 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\featureController.dll 2010-01-13 08:55 - 2010-01-13 08:55 - 00400384 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\sqlite3.dll 2013-03-08 04:55 - 2013-03-08 04:55 - 00472576 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\DeviceProfile.dll 2013-03-08 04:58 - 2013-03-08 04:58 - 00499488 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\plugin\PServerPlugin.dll 2013-03-08 04:54 - 2013-03-08 04:54 - 00013824 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\eventsSender.dll 2010-12-18 04:56 - 2010-12-18 04:56 - 14978048 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtWebKit4.dll 2010-12-18 04:56 - 2010-12-18 04:56 - 09224704 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtGui4.dll 2010-12-18 04:56 - 2010-12-18 04:56 - 00317952 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\phonon4.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\Users\David\Desktop\9ecn37ww.exe:BDU AlternateDataStreams: C:\Users\David\Downloads\SystemExplorerSetup_642.exe:BDU ==================== Safe Mode (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""="" ==================== EXE Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-3209958707-3427003406-1755347824-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\David\Pictures\1970797.jpg DNS Servers: 210.220.163.82 - 219.250.36.130 ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [{AF016E9B-2889-4056-9EB3-66D6A6FAA5F8}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{39462F27-0F50-45DA-9588-1AFF4CC2CD8D}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{61DE654E-3FB6-4C13-AB61-8D1268C8D94E}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe FirewallRules: [{6012703D-0DFC-454B-A2CF-FA1559DEF491}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe FirewallRules: [{AA69348F-DFBE-4C58-AA94-0D4BBF5A490E}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{AE721D8D-1413-45E1-9212-749389912752}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{BC94223C-0810-420B-BA0B-CC1C845BA765}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe FirewallRules: [{053EEA42-D080-4E6D-947C-A9FD4A4EE86C}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe FirewallRules: [{625D6096-A737-4525-B0ED-EAE82FFC8EEF}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe FirewallRules: [{CC1E2F31-AD68-43D2-9EF2-6C9F78AE06F3}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\MxUp.exe FirewallRules: [{EC476E6E-1B48-485C-90C4-7D2AA35A706C}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\MxUp.exe FirewallRules: [{43898D75-AE1C-4BFA-9D80-3DA0B780A95F}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe FirewallRules: [{A4CAF0C3-8F17-4997-8A1E-27021D6EB502}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe FirewallRules: [{DD4678B9-500D-4AEF-B7FC-0535333C1C54}] => (Allow) C:\Program Files\CyberLink\PowerDirector10\PDR10.EXE FirewallRules: [{A888B8C7-0D3A-43EE-841A-460C07DDE07E}] => (Allow) C:\Program Files (x86)\Lenovo\PowerDVD10\PowerDVD Cinema\PowerDVDCinema10.exe FirewallRules: [{ED2D2445-5472-4BE7-B838-121DB32935BE}] => (Allow) C:\Program Files (x86)\Lenovo\PowerDVD10\PowerDVD10.EXE FirewallRules: [{5E174FA9-53BD-4C51-83EE-A652A4EB4D9A}] => (Allow) C:\Users\David\AppData\Roaming\RIOTGames\rgDownload\rgDownload.exe FirewallRules: [{533EAB03-AF98-48F4-B0B3-EF82074594CC}] => (Allow) C:\Users\David\AppData\Roaming\RIOTGames\rgDownload\rgDownload.exe FirewallRules: [{7C35FCF1-8A0E-40F5-B91E-10B2A936726C}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{22A258FB-97AD-4C2B-B4A8-9E0EC180B892}] => (Allow) C:\Riot Games Korea\League of Legends\lol.launcher.admin.exe FirewallRules: [{EC23F9E7-CCDA-411E-98B6-6C6CCA12CD63}] => (Allow) C:\Riot Games Korea\League of Legends\lol.launcher.admin.exe FirewallRules: [{2B5904DB-1950-4F09-A8FC-08AC77277CB3}] => (Allow) C:\Riot Games Korea\League of Legends\lol.launcher.admin.exe FirewallRules: [{1BD2E54A-CC0B-4559-82CF-6B544515E6BD}] => (Allow) C:\Riot Games Korea\League of Legends\lol.launcher.admin.exe FirewallRules: [TCP Query User{FDA08A76-AB39-45D5-BB67-9A342BB92699}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe FirewallRules: [UDP Query User{14FCEEAF-AA6C-4C95-9530-AE16474AC825}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe FirewallRules: [{1DABA7A8-0271-4948-82E5-10EBEB51C830}] => (Allow) C:\Users\David\Downloads\360TS_Setup_Mini.exe FirewallRules: [{26ADE936-3EBE-4A4F-903E-6A72CD1DF1FB}] => (Allow) C:\Users\David\Downloads\360TS_Setup_Mini.exe FirewallRules: [TCP Query User{A72E6CA6-8F45-45D9-A747-2C5B9AD150DF}C:\users\david\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\david\appdata\roaming\spotify\spotify.exe FirewallRules: [UDP Query User{3DD287D2-A572-44BD-8B79-026CAB5D5A82}C:\users\david\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\david\appdata\roaming\spotify\spotify.exe FirewallRules: [{23C49149-85CC-4967-AFA8-7C45FE0ACBCA}] => (Allow) C:\Program Files (x86)\SK Communications\NATEON\BIN\NateOnMain.exe FirewallRules: [{3C630E2C-2069-42DD-AAFC-9AF234D3EDAC}] => (Allow) C:\Program Files (x86)\SK Communications\NATEON\BIN\NateOnMain.exe FirewallRules: [{C2A58CFD-9AF7-41AD-AA28-A41DB2F51000}] => (Allow) C:\Program Files (x86)\TALKON\TalkOnMain.exe FirewallRules: [{75EA7C70-080C-4D87-9077-06EDA2D80F63}] => (Allow) C:\Program Files (x86)\TALKON\TalkOnMain.exe FirewallRules: [{2AEFE6F2-126B-44DA-9BED-32A8819D4800}] => (Allow) C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe FirewallRules: [{979DA934-2044-4C33-9D76-7E6D50F010D9}] => (Allow) C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe FirewallRules: [{C0919627-0F80-4877-B438-7B33F14C2ACD}] => (Allow) C:\Program Files (x86)\360\Total Security\LiveUpdate360.exe FirewallRules: [{3B234027-57A5-4A97-AB47-A81679AEF941}] => (Allow) C:\Program Files (x86)\360\Total Security\LiveUpdate360.exe ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (06/27/2015 01:52:31 AM) (Source: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe) (EventID: 1) (User: ) Description: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exeCan't get user token [1008] Error: (06/27/2015 01:27:13 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: League of Legends.exe, version: 5.12.0.341, time stamp: 0x5584922e Faulting module name: League of Legends.exe, version: 5.12.0.341, time stamp: 0x5584922e Exception code: 0xc0000005 Fault offset: 0x00546220 Faulting process id: 0xf20 Faulting application start time: 0xLeague of Legends.exe0 Faulting application path: League of Legends.exe1 Faulting module path: League of Legends.exe2 Report Id: League of Legends.exe3 Faulting package full name: League of Legends.exe4 Faulting package-relative application ID: League of Legends.exe5 Error: (06/27/2015 00:49:02 AM) (Source: Perflib) (EventID: 1023) (User: ) Description: rdyboost4 Error: (06/26/2015 07:07:01 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: AUDIODG.EXE, version: 6.3.9600.17041, time stamp: 0x531816b3 Faulting module name: ntdll.dll, version: 6.3.9600.17031, time stamp: 0x530895af Exception code: 0xc0000005 Fault offset: 0x0000000000065e8e Faulting process id: 0x1b28 Faulting application start time: 0xAUDIODG.EXE0 Faulting application path: AUDIODG.EXE1 Faulting module path: AUDIODG.EXE2 Report Id: AUDIODG.EXE3 Faulting package full name: AUDIODG.EXE4 Faulting package-relative application ID: AUDIODG.EXE5 Error: (06/26/2015 06:01:43 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: League of Legends.exe, version: 5.12.0.341, time stamp: 0x5584922e Faulting module name: ntdll.dll, version: 6.3.9600.17031, time stamp: 0x5308893d Exception code: 0xc000000d Fault offset: 0x000ef24c Faulting process id: 0x12f0 Faulting application start time: 0xLeague of Legends.exe0 Faulting application path: League of Legends.exe1 Faulting module path: League of Legends.exe2 Report Id: League of Legends.exe3 Faulting package full name: League of Legends.exe4 Faulting package-relative application ID: League of Legends.exe5 Error: (06/26/2015 05:22:52 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: AUDIODG.EXE, version: 6.3.9600.17041, time stamp: 0x531816b3 Faulting module name: FMAPO64.dll, version: 50.6.5.66, time stamp: 0x53017fec Exception code: 0xc0000005 Fault offset: 0x000000000009a006 Faulting process id: 0xb7c Faulting application start time: 0xAUDIODG.EXE0 Faulting application path: AUDIODG.EXE1 Faulting module path: AUDIODG.EXE2 Report Id: AUDIODG.EXE3 Faulting package full name: AUDIODG.EXE4 Faulting package-relative application ID: AUDIODG.EXE5 Error: (06/26/2015 09:51:42 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: AUDIODG.EXE, version: 6.3.9600.17041, time stamp: 0x531816b3 Faulting module name: ntdll.dll, version: 6.3.9600.17031, time stamp: 0x530895af Exception code: 0xc0000005 Fault offset: 0x0000000000065e8e Faulting process id: 0x11b8 Faulting application start time: 0xAUDIODG.EXE0 Faulting application path: AUDIODG.EXE1 Faulting module path: AUDIODG.EXE2 Report Id: AUDIODG.EXE3 Faulting package full name: AUDIODG.EXE4 Faulting package-relative application ID: AUDIODG.EXE5 System errors: ============= Error: (06/27/2015 02:04:11 AM) (Source: Service Control Manager) (EventID: 7032) (User: ) Description: The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Modules Installer service, but this action failed with the following error: %%1056 Error: (06/27/2015 02:02:11 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The Windows Modules Installer service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service. Error: (06/27/2015 02:02:09 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The Windows Presentation Foundation Font Cache 3.0.0.0 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. Error: (06/27/2015 02:02:09 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The Intel(R) PROSet/Wireless Zero Configuration Service service terminated unexpectedly. It has done this 1 time(s). Error: (06/27/2015 02:02:09 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The VeriFaceSrv service terminated unexpectedly. It has done this 1 time(s). Error: (06/27/2015 02:02:09 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The Cyberlink RichVideo64 Service(CRVS) service terminated unexpectedly. It has done this 1 time(s). Error: (06/27/2015 02:02:09 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The Intel(R) PROSet/Wireless Registry Service service terminated unexpectedly. It has done this 1 time(s). Error: (06/27/2015 02:02:09 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The Lenovo PhoneCompanionPusher Service service terminated unexpectedly. It has done this 1 time(s). Error: (06/27/2015 02:02:09 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The PGService service terminated unexpectedly. It has done this 1 time(s). Error: (06/27/2015 02:02:09 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The PG_Service_Launcher service terminated unexpectedly. It has done this 1 time(s). Microsoft Office: ========================= Error: (06/27/2015 01:52:31 AM) (Source: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe) (EventID: 1) (User: ) Description: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exeCan't get user token [1008] Error: (06/27/2015 01:27:13 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: League of Legends.exe5.12.0.3415584922eLeague of Legends.exe5.12.0.3415584922ec000000500546220f2001d0b027b1cb12dbC:\Riot Games KR\League of Legends\RADS\solutions\lol_game_client_sln\releases\0.0.0.167\deploy\League of Legends.exeC:\Riot Games KR\League of Legends\RADS\solutions\lol_game_client_sln\releases\0.0.0.167\deploy\League of Legends.exe3345df1a-1c20-11e5-825b-e82aeab5863b Error: (06/27/2015 00:49:02 AM) (Source: Perflib) (EventID: 1023) (User: ) Description: rdyboost4 Error: (06/26/2015 07:07:01 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: AUDIODG.EXE6.3.9600.17041531816b3ntdll.dll6.3.9600.17031530895afc00000050000000000065e8e1b2801d0afe96075d65dC:\WINDOWS\system32\AUDIODG.EXEC:\WINDOWS\SYSTEM32\ntdll.dll1603c00f-1beb-11e5-825b-e82aeab5863b Error: (06/26/2015 06:01:43 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: League of Legends.exe5.12.0.3415584922entdll.dll6.3.9600.170315308893dc000000d000ef24c12f001d0afee8bce4a28C:\Riot Games KR\League of Legends\RADS\solutions\lol_game_client_sln\releases\0.0.0.167\deploy\League of Legends.exeC:\WINDOWS\SYSTEM32\ntdll.dllf697e49f-1be1-11e5-825b-e82aeab5863b Error: (06/26/2015 05:22:52 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: AUDIODG.EXE6.3.9600.17041531816b3FMAPO64.dll50.6.5.6653017fecc0000005000000000009a006b7c01d0afb479bc1392C:\WINDOWS\system32\AUDIODG.EXEC:\windows\system32\FMAPO64.dll8963186c-1bdc-11e5-825b-e82aeab5863b Error: (06/26/2015 09:51:42 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: AUDIODG.EXE6.3.9600.17041531816b3ntdll.dll6.3.9600.17031530895afc00000050000000000065e8e11b801d0afa92d6c2eecC:\WINDOWS\system32\AUDIODG.EXEC:\WINDOWS\SYSTEM32\ntdll.dll8248bb86-1b9d-11e5-825a-e82aeab5863b ==================== Memory info =========================== Processor: Intel(R) Core(TM) i7-4700HQ CPU @ 2.40GHz Percentage of memory in use: 19% Total physical RAM: 16296.27 MB Available physical RAM: 13173.91 MB Total Pagefile: 19240.27 MB Available Pagefile: 15868.29 MB Total Virtual: 131072 MB Available Virtual: 131071.84 MB ==================== Drives ================================ Drive c: (Windows8_OS) (Fixed) (Total:887.88 GB) (Free:714.14 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive d: (LENOVO) (Fixed) (Total:25 GB) (Free:22.13 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 931.5 GB) (Disk ID: 3C8F16BF) Partition: GPT Partition Type. ==================== End of log ============================