Additional scan result of Farbar Recovery Scan Tool (x64) Version: 23-02-2017 Ran by Mike (23-02-2017 11:33:28) Running from C:\Users\Mike\Desktop Windows 7 Professional Service Pack 1 (X64) (2013-09-11 23:45:22) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-637814681-3575538249-3970651240-500 - Administrator - Disabled) Guest (S-1-5-21-637814681-3575538249-3970651240-501 - Limited - Enabled) HomeGroupUser$ (S-1-5-21-637814681-3575538249-3970651240-1005 - Limited - Enabled) Mike (S-1-5-21-637814681-3575538249-3970651240-1000 - Administrator - Enabled) => C:\Users\Mike ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: AVG AntiVirus Free Edition (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: AVG AntiVirus Free Edition (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) @BIOS (HKLM-x32\...\{B2DC3F08-2EB2-49A5-AA24-15DFC8B1CB83}) (Version: 2.30 - GIGABYTE) µTorrent (HKU\S-1-5-21-637814681-3575538249-3970651240-1000\...\uTorrent) (Version: 3.4.9.43295 - BitTorrent Inc.) Ad-Aware Browsing Protection (HKLM-x32\...\Ad-Aware Browsing Protection) (Version: 1.0.1.110 - Lavasoft) Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.023.20070 - Adobe Systems Incorporated) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.7.0.1530 - Adobe Systems Incorporated) Adobe Flash Player 24 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 24.0.0.221 - Adobe Systems Incorporated) Adobe Flash Player 24 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 24.0.0.221 - Adobe Systems Incorporated) Adobe Flash Player 24 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 24.0.0.221 - Adobe Systems Incorporated) Aimersoft DRM Media Converter(Build 1.5.5.0) (HKLM-x32\...\Aimersoft DRM Media Converter_is1) (Version: - Aimersoft Software) Amazon Kindle (HKU\S-1-5-21-637814681-3575538249-3970651240-1000\...\Amazon Kindle) (Version: 1.19.2.46095 - Amazon) Amazon Music (HKU\S-1-5-21-637814681-3575538249-3970651240-1000\...\Amazon Amazon Music) (Version: 5.0.4.1562 - Amazon Services LLC) Andy OS (HKLM\...\Andy OS) (Version: 0.45.5.0 - Andy OS, Inc) ASUS Wireless Router Device Discovery Utility (HKLM-x32\...\{09CDCA35-23FF-4ED6-AFDA-BBD55235CE4B}) (Version: 1.4.7.2 - ASUS) Audacity 2.0.6 (HKLM-x32\...\Audacity_is1) (Version: 2.0.6 - Audacity Team) AutoGreen B12.1220.1 (HKLM-x32\...\InstallShield_{C75FAD21-EC08-42F3-92D6-C9C0AB355345}) (Version: 1.00.0000 - GIGABYTE) AutoGreen B12.1220.1 (x32 Version: 1.00.0000 - GIGABYTE) Hidden AVG (Version: 16.141.7998 - AVG Technologies) Hidden AVG 2016 (Version: 16.0.4756 - AVG Technologies) Hidden AVG Protection (HKLM\...\AVG) (Version: 2016.141.7998 - AVG Technologies) AZ Document to PDF Converter V1.8.2 (Trial) (HKLM-x32\...\AZ Document to PDF Converter V1.8.2 (Trial)) (Version: - ) BBC iPlayer Downloads (HKLM-x32\...\{C3794B09-6C43-4B93-9CA8-F10BECCF2971}) (Version: 1.11.1 - BBC) Belarc Advisor 8.4 (HKLM-x32\...\Belarc Advisor) (Version: 8.4.0.0 - Belarc Inc.) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Boxoft Screen OCR (HKLM-x32\...\Boxoft Screen OCR_is1) (Version: - Boxoft Solution) calibre (HKLM-x32\...\{C727544A-23E0-41A8-9901-2353CE3FE62A}) (Version: 2.14.0 - Kovid Goyal) CanoScan Toolbox Ver4.5 (HKLM-x32\...\{143FB15C-0C48-41E3-9C30-F56FB69BF3D7}) (Version: - ) CCleaner (HKLM\...\CCleaner) (Version: 4.09 - Piriform) CDisplayEx 1.10.29 (HKLM\...\CDisplayEx_is1) (Version: - Progdigy Software S.A.R.L.) Common Desktop Agent (Version: 1.53.0 - OEM) Hidden Compatibility Pack for the 2007 Office system (HKLM-x32\...\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation) Dashlane (HKU\S-1-5-21-637814681-3575538249-3970651240-1000\...\Dashlane) (Version: 3.0.3.68246 - Dashlane SAS) Epson Event Manager (HKLM-x32\...\{0F13C24A-FFE2-4CD0-8E0B-DC804E0A0E0B}) (Version: 3.10.0035 - Seiko Epson Corporation) EPSON Manuals (HKLM-x32\...\{84CECC1B-21EF-41B1-9A91-3E724E5D99D3}) (Version: 1.50.0.0 - SEIKO EPSON CORPORATION) EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version: - Seiko Epson Corporation) EPSON XP-312 313 315 Series Printer Uninstall (HKLM\...\EPSON XP-312 313 315 Series) (Version: - SEIKO EPSON Corporation) Epubor Ultimate (HKLM-x32\...\Epubor Ultimate) (Version: 3.0.4.5 - Epubor Inc.) FMW 1 (Version: 1.143.3 - AVG Technologies) Hidden Free Editor (HKLM\...\{1BF14E04-85DE-480C-9A04-EB36744C66B4}_is1) (Version: 2.0.3 - Blue Labs, LLC) Free Video Joiner 5.5.8 (HKLM-x32\...\Free Video Joiner_is1) (Version: - MediaRightSoft, Inc.) Freenet version 0.7.5 build 1475 (HKU\S-1-5-21-637814681-3575538249-3970651240-1000\...\{3196C62F-9C7B-4392-88B4-05C037D05518}_is1) (Version: 0.7.5 build 1475 - freenetproject.org) GIGABYTE OC_GURU II (x32 Version: 1.65.0000 - GIGABYTE Technology Co.,Ltd.) Hidden GMail Backup (HKU\S-1-5-21-637814681-3575538249-3970651240-1000\...\{cee4baf7-dcfa-4fbc-8dc8-8e47b105b5e7}) (Version: 1.0.3.174 - UpSafe) GMail Backup (Version: 1.0.3.174 - UpSafe) Hidden Google Chrome (HKLM-x32\...\Google Chrome) (Version: 56.0.2924.87 - Google Inc.) Google Drive (HKLM-x32\...\{07A12123-B717-496B-B471-48AF6407B433}) (Version: 1.32.4066.7445 - Google, Inc.) Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.8231.2252 - Google Inc.) Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.32.7 - Google Inc.) Hidden Java 7 Update 55 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217045FF}) (Version: 7.0.550 - Oracle) JDownloader 2 (HKLM\...\jdownloader2) (Version: 2.0 - AppWork GmbH) KMP Service (HKLM-x32\...\4F6D5E84-5826-4394-9F40-3A9A19165651_is1) (Version: - KMP) <==== ATTENTION LAME v3.99.3 (for Windows) (HKLM-x32\...\LAME_is1) (Version: - ) Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes) MEGAsync (HKLM-x32\...\MEGAsync) (Version: - Mega Limited) Microsoft .NET Framework 4.6.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation) Microsoft Camera Codec Pack (HKLM\...\{D553E8CC-5C56-4B06-AC1A-A443DFF31092}) (Version: 6.3.9723.0 - Microsoft Corporation) Microsoft Office PowerPoint Viewer 2007 (English) (HKLM-x32\...\{95120000-00AF-0409-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation) Microsoft Office Professional Plus 2007 (HKLM-x32\...\PROPLUS) (Version: 12.0.4518.1014 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-637814681-3575538249-3970651240-1000\...\OneDriveSetup.exe) (Version: 17.3.6743.1212 - Microsoft Corporation) Microsoft OneNote Home and Student 2016 - en-us (HKLM\...\OneNoteFreeRetail - en-us) (Version: 16.0.7571.2109 - Microsoft Corporation) Microsoft Reader (HKLM-x32\...\{B6F7DBE7-2FE2-458F-A738-B10832746036}) (Version: - ) Microsoft Report Viewer Redistributable 2005 (HKLM-x32\...\Microsoft Report Viewer Redistributable 2005) (Version: - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation) ModifyRegistry version 0.1 (HKLM-x32\...\{1D5BE6B5-7FD4-4A78-90F2-AF6B53BC8C1C}_is1) (Version: 0.1 - VIA Technologies, Inc.) Moo0 File Shredder 1.21 (HKLM-x32\...\Moo0 FileShredder) (Version: - ) Moo0 Video Cutter 1.06 (HKLM-x32\...\Moo0 VideoCutter) (Version: - ) MyEpson Portal (HKLM-x32\...\MyEpson Portal) (Version: - SEIKO EPSON Corporation) MyEpson Portal (x32 Version: 1.1.1.0 - SEIKO EPSON CORPORATION) Hidden Nero 11 InfoTool (HKLM-x32\...\{64BEF779-5053-48AF-A3D8-B70EBC1C70E7}) (Version: 11.0.00500 - Nero AG) Nero 8 Micro (HKLM-x32\...\Nero8Lite_is1) (Version: 8.3.20.0 - UpdatePack.nl) NFO Reader version 1.0 (HKLM-x32\...\{8B9BD4A4-9669-469B-9AE0-0858B72AAB4D}_is1) (Version: 1.0 - nforeader.com) NirSoft IE PassView (HKLM-x32\...\NirSoft IE PassView) (Version: - ) Nuance Cloud Connector (HKLM-x32\...\{DE7C1B86-27EF-4D02-886E-17CC3458034B}) (Version: 3.2.713 - Nuance Communications, Inc.) Nuance OmniPage 18 (HKLM-x32\...\{560C6F9C-8D5E-4EAF-B408-98850E5DF49C}) (Version: 18.1.0000 - Nuance Communications, Inc.) Nuance PDF Create 7 (HKLM\...\{CD7A262C-287E-41DD-A0F7-733856252C6B}) (Version: 7.10.2364 - Nuance Communications, Inc.) Nuance PDF Create 7 (HKLM-x32\...\{CD7A262C-287E-41DD-A0F7-733856252C6B}) (Version: 7.10.2364 - Nuance Communications, Inc.) NVIDIA 3D Vision Controller Driver 347.09 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 347.09 - NVIDIA Corporation) NVIDIA 3D Vision Driver 347.88 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 347.88 - NVIDIA Corporation) NVIDIA GeForce Experience 2.2.2 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.2.2 - NVIDIA Corporation) NVIDIA Graphics Driver 347.88 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 347.88 - NVIDIA Corporation) NVIDIA HD Audio Driver 1.3.33.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.33.0 - NVIDIA Corporation) NVIDIA PhysX System Software 9.14.0702 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.14.0702 - NVIDIA Corporation) Office 16 Click-to-Run Extensibility Component (x32 Version: 16.0.7571.2109 - Microsoft Corporation) Hidden Office 16 Click-to-Run Extensibility Component 64-bit Registration (Version: 16.0.7571.2109 - Microsoft Corporation) Hidden Office 16 Click-to-Run Licensing Component (Version: 16.0.7571.2109 - Microsoft Corporation) Hidden Office 16 Click-to-Run Localization Component (x32 Version: 16.0.7571.2109 - Microsoft Corporation) Hidden ON_OFF Charge B12.1025.1 (HKLM-x32\...\{3DECD372-76A1-4483-BF10-B547790A3261}) (Version: 1.00.0001 - GIGABYTE) paint.net (HKLM\...\{6AC1101E-7561-43C9-BEEA-4AB1D220D8FF}) (Version: 4.0.13 - dotPDN LLC) PCX Viewer (HKLM-x32\...\{64088381-C625-41E7-B3FA-A5EE3268E264}_is1) (Version: - IdeaMK) Platform (x32 Version: 1.39 - VIA Technologies, Inc.) Hidden Poser Pro 2010 (8.0.3.11414) (HKLM\...\Poser Pro 2010_is1) (Version: 8.0.0 - Smith Micro Software, Inc.) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.48.823.2011 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6767 - Realtek Semiconductor Corp.) Recuva (HKLM\...\Recuva) (Version: 1.51 - Piriform) Samsung Data Migration (HKLM-x32\...\{3B304604-0BF5-488E-AB95-F2F2E31206F3}) (Version: 3.0 - Samsung) Samsung Easy Printer Manager (HKLM-x32\...\Samsung Easy Printer Manager) (Version: 1.02.06.07 - Samsung Electronics Co., Ltd.) Samsung Magician (HKLM-x32\...\{29AE3F9F-7158-4ca7-B1ED-28A73ECDB215}_is1) (Version: 4.5.1 - Samsung Electronics) Samsung ML-2160 Series (HKLM-x32\...\Samsung ML-2160 Series) (Version: 1.08 (24/08/2012) - Samsung Electronics Co., Ltd.) Samsung Printer Diagnostics (HKLM-x32\...\Samsung Printer Diagnostics) (Version: 1.0.4.7.04 - Samsung Electronics Co., Ltd.) Samsung Printer Live Update (HKLM-x32\...\Samsung Printer Live Update) (Version: - Samsung Electronics Co., Ltd.) Scansoft PDF Create (x32 Version: - ) Hidden SHIELD Streaming (Version: 4.0.1000 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: 17.12.8 - NVIDIA Corporation) Hidden SketchUp 2014 (HKLM-x32\...\{A608A8D3-E77C-4BEE-8F2A-F8124F5F0FE2}) (Version: 14.0.4900 - Trimble Navigation Limited) Skype Click to Call (HKLM-x32\...\{873F8E7C-10E6-449F-BD7E-5FBA7C8E1C9B}) (Version: 8.5.0.9167 - Microsoft Corporation) Skype Web Plugin (HKLM-x32\...\{AC7406B6-BB3B-4CD1-AEBA-0527B9CB16FE}) (Version: 7.27.0.105 - Skype Technologies S.A.) Skype™ 7.18 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.18.112 - Skype Technologies S.A.) Smart Organizing Monitor for SP 210 Series (HKLM-x32\...\{D1EC71F7-E534-4A54-A75A-DCDCCAD77BF7}) (Version: 1.00 - RICOH) Software Updater (HKLM-x32\...\{8DBC5A0A-31C4-46C7-B252-6B593EA11A87}) (Version: 4.3.7 - SEIKO EPSON CORPORATION) SWF Opener (HKLM-x32\...\{01386D1F-ADE7-43B4-A4E9-312FC5BC726F}_is1) (Version: 1.3 - UnH Solutions) TeamViewer 9 (HKLM-x32\...\TeamViewer 9) (Version: 9.0.27339 - TeamViewer) The KMPlayer (remove only) (HKLM-x32\...\The KMPlayer) (Version: 3.7.0.107 - KMP Media co., Ltd) Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 8.01 - Ghisler Software GmbH) VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden VIA Platform Device Manager (HKLM-x32\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.39 - VIA Technologies, Inc.) Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies) Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.) VLC media player (HKLM\...\VLC media player) (Version: 2.2.4 - VideoLAN) VMware Player (Version: 6.0.7 - VMware, Inc.) Hidden VMware VIX (HKLM-x32\...\{F99FC179-EA67-4BBC-8955-BDDA0CB94B88}) (Version: 1.13.7.62285 - VMware, Inc.) WavePad Sound Editor (HKLM-x32\...\WavePad) (Version: 5.80 - NCH Software) Who Is On My Wifi version 2.1.9 (HKLM-x32\...\{010D45A1-093D-4534-8147-4E10E80F81CC}_is1) (Version: 2.1.9 - IO3O LLC) WinDjView 2.0.2 (HKLM\...\WinDjView) (Version: 2.0.2 - Andrew Zhezherun) WinRAR 5.00 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.00.0 - win.rar GmbH) Wondershare Video Converter Ultimate(Build 7.1.0.2) (HKLM-x32\...\Wondershare Video Converter Ultimate_is1) (Version: 7.1.0.2 - Wondershare Software) Your Uninstaller! 7 (HKLM-x32\...\YU2010_is1) (Version: 7.5.2013.2 - URSoft, Inc.) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) HKU\S-1-5-21-637814681-3575538249-3970651240-1000\...\ChromeHTML: -> <==== ATTENTION CustomCLSID: HKU\S-1-5-21-637814681-3575538249-3970651240-1000_Classes\CLSID\{162C6FB5-44D3-435B-903D-E613FA093FB5}\InprocServer32 -> C:\Users\Mike\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\amd64\FileCoAuthLib64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-637814681-3575538249-3970651240-1000_Classes\CLSID\{58743271-597A-401B-AF4A-1450179151C0}\InprocServer32 -> C:\Users\Mike\AppData\Local\SkypePlugin\7.27.0.105\GatewayActiveX-x64.dll (Skype Technologies S.A.) CustomCLSID: HKU\S-1-5-21-637814681-3575538249-3970651240-1000_Classes\CLSID\{8AAE6BAC-FCFC-49E7-940C-B11668616323}\InprocServer32 -> C:\Users\Mike\AppData\Local\SkypePlugin\7.28.0.46\GatewayActiveX-x64.dll (Skype Technologies S.A.) CustomCLSID: HKU\S-1-5-21-637814681-3575538249-3970651240-1000_Classes\CLSID\{9206EDB2-DB9E-4AE0-A821-5048667D3A17}\localserver32 -> C:\Users\Mike\AppData\Local\SkypePlugin\7.28.0.46\GatewayVersion-x64.exe (Skype Technologies S.A.) CustomCLSID: HKU\S-1-5-21-637814681-3575538249-3970651240-1000_Classes\CLSID\{CBF9CD8C-2714-4F36-B76A-43E6C7547BC2}\localserver32 -> C:\Users\Mike\AppData\Local\SkypePlugin\7.28.0.46\EdgeCalling.exe (Skype Technologies S.A.) CustomCLSID: HKU\S-1-5-21-637814681-3575538249-3970651240-1000_Classes\CLSID\{D0FC4B60-C60D-4908-8365-0C64C03E0291}\localserver32 -> C:\Users\Mike\AppData\Local\SkypePlugin\7.27.0.105\GatewayVersion-x64.exe (Skype Technologies S.A.) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {020FACC6-C53C-4045-B1F9-F9D23FC71952} - System32\Tasks\EPSON XP-312 313 315 Series Invitation {8D51A5EC-C42D-4908-9F0C-4BA07589D4C6} => C:\Windows\system32\spool\DRIVERS\x64\3\E_ITSLFE.EXE [2013-02-28] (SEIKO EPSON CORPORATION) Task: {0AFEF0A4-B1FA-4F8E-BEC4-E919D920B014} - System32\Tasks\{8E7A416F-785C-4FBC-B68D-A7CC7D2265A4} => pcalua.exe -a C:\Users\Mike\Downloads\winsdk_web.exe -d C:\Users\Mike\Downloads Task: {0BFAA38A-04DC-4654-9A41-BFA25C80193A} - System32\Tasks\RunAsStdUser Task => C:\Program Files (x86)\Moo0\VideoCutter 1.06\VideoCutter.exe [2013-08-09] (Moo0) Task: {0EEBCA1A-5ED8-40E6-83F4-957134C511F3} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_24_0_0_221_pepper.exe [2017-02-14] (Adobe Systems Incorporated) Task: {1FE17DFB-F4C2-492C-948F-BB5F1320D711} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2016-12-28] (Microsoft Corporation) Task: {495A50E0-4333-438A-BD2A-09C9F54B3669} - System32\Tasks\EPSON XP-312 313 315 Series Update {8D51A5EC-C42D-4908-9F0C-4BA07589D4C6} => C:\Windows\system32\spool\DRIVERS\x64\3\E_ITSLFE.EXE [2013-02-28] (SEIKO EPSON CORPORATION) Task: {5211BC6E-BCA2-4961-A062-7782680A6200} - System32\Tasks\AVG EUpdate Task => avgsetupx.exe Task: {728EC1D1-2CCB-47F4-AC1A-917EE5F5138E} - System32\Tasks\EPSON XP-312 313 315 Series Update {43C8D45B-EE11-4ADC-B681-5BEA56874F9E} => C:\Windows\system32\spool\DRIVERS\x64\3\E_ITSLFE.EXE [2013-02-28] (SEIKO EPSON CORPORATION) Task: {72A76000-A5A9-4875-9CE7-9E6FA3268C8F} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-02-14] (Adobe Systems Incorporated) Task: {7D5EFEC5-0C52-42D3-A2E5-8290B204E013} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2016-12-28] (Microsoft Corporation) Task: {9C13A8FB-4249-4A2E-AD34-9EB4E979B670} - System32\Tasks\SamsungMagician => C:\Program Files (x86)\Samsung\Samsung Magician\Samsung Magician.exe [2014-09-28] (Samsung Electronics.) Task: {B8427D3E-7884-438F-B7AD-FD013C526B6F} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-02-22] (Google Inc.) Task: {C4CB79D6-FBD1-4354-8FD2-4E2B7B314868} - System32\Tasks\{47B256E7-FFEC-4782-AAC5-30EF86A5EA50} => pcalua.exe -a C:\Users\Mike\Downloads\madFlac-1.10\InstallFilter.exe -d C:\Users\Mike\Downloads\madFlac-1.10 -c madFlac.ax Task: {E42C6C57-E20B-4245-945C-6629411E8660} - System32\Tasks\EPSON XP-312 313 315 Series Invitation {43C8D45B-EE11-4ADC-B681-5BEA56874F9E} => C:\Windows\system32\spool\DRIVERS\x64\3\E_ITSLFE.EXE [2013-02-28] (SEIKO EPSON CORPORATION) Task: {E9B5D9AC-8FFC-4F8A-91A9-7FD638F41754} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-02-22] (Google Inc.) Task: {EDD36DDA-0654-4DE2-A012-B5245034231C} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-12-17] (Piriform Ltd) Task: {FE4DE646-AD86-447F-B84F-DC117ADB77E2} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-12-19] (Adobe Systems Incorporated) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\Adobe Flash Player PPAPI Notifier.job => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_24_0_0_221_pepper.exe Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\EPSON XP-312 313 315 Series Invitation {43C8D45B-EE11-4ADC-B681-5BEA56874F9E}.job => C:\Windows\system32\spool\DRIVERS\x64\3\E_ITSLFE.EXE Task: C:\Windows\Tasks\EPSON XP-312 313 315 Series Invitation {8D51A5EC-C42D-4908-9F0C-4BA07589D4C6}.job => C:\Windows\system32\spool\DRIVERS\x64\3\E_ITSLFE.EXE Task: C:\Windows\Tasks\EPSON XP-312 313 315 Series Update {43C8D45B-EE11-4ADC-B681-5BEA56874F9E}.job => C:\Windows\system32\spool\DRIVERS\x64\3\E_ITSLFE.EXE:/EXE:{43C8D45B-EE11-4ADC-B681-5BEA56874F9E} /F:UpdateSYSTEMĊSearches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi Task: C:\Windows\Tasks\EPSON XP-312 313 315 Series Update {8D51A5EC-C42D-4908-9F0C-4BA07589D4C6}.job => C:\Windows\system32\spool\DRIVERS\x64\3\E_ITSLFE.EXE:/EXE:{8D51A5EC-C42D-4908-9F0C-4BA07589D4C6} /F:UpdateSYSTEMĊSearches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) Shortcut: C:\Users\Mike\Favorites\NCH Software Download Site.lnk -> hxxp://www.nch.com.au/index.htm ==================== Loaded Modules (Whitelisted) ============== 2013-09-12 17:06 - 2015-03-13 16:16 - 00118472 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2015-04-08 08:59 - 2015-04-08 08:59 - 00022528 _____ () C:\Windows\System32\ssj1mlm.dll 2016-08-26 14:46 - 2016-12-28 17:03 - 08924864 _____ () C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\1033\GrooveIntlResource.dll 2014-05-15 17:26 - 2013-08-23 12:36 - 00721263 _____ () C:\Windows\SysWOW64\WSCM64.dll 2014-05-01 14:13 - 2016-08-17 23:17 - 00592384 _____ () C:\ProgramData\MEGAsync\ShellExtX64.dll 2011-07-26 09:21 - 2011-07-26 09:21 - 00222064 _____ () C:\Program Files (x86)\Nuance\Nuance Cloud Connector\WOSVSSSvr.exe 2016-01-30 11:57 - 2016-07-17 21:43 - 00499000 ____N () C:\Windows\SysWOW64\spdsvc.exe 2013-06-28 11:12 - 2015-04-08 08:59 - 01604096 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\ssj1mdu.dll 2011-07-26 09:13 - 2011-07-26 09:13 - 00292720 _____ () C:\Program Files (x86)\Nuance\Nuance Cloud Connector\sqlite3.dll 2011-07-26 09:13 - 2011-07-26 09:13 - 00079728 _____ () C:\Program Files (x86)\Nuance\Nuance Cloud Connector\zlib125.dll 2011-07-26 09:13 - 2011-07-26 09:13 - 00015216 _____ () C:\Program Files (x86)\Nuance\Nuance Cloud Connector\WOSMui.dll 2015-06-24 14:28 - 2015-06-24 14:28 - 01301720 _____ () C:\Program Files (x86)\VMware\VMware Player\libxml2.dll 2016-11-28 16:12 - 2016-11-28 16:12 - 48920064 _____ () C:\Program Files (x86)\AVG\UiDll\2623\libcef.dll 2017-02-17 13:27 - 2014-09-28 17:59 - 00019872 _____ () C:\Program Files (x86)\Samsung\Samsung Magician\SAMSUNG_SSD.dll 2014-05-01 14:15 - 2016-08-17 23:17 - 00564224 _____ () C:\ProgramData\MEGAsync\ShellExtX32.dll 2017-02-06 21:13 - 2017-02-01 09:01 - 01870168 _____ () C:\Program Files (x86)\Google\Chrome\Application\56.0.2924.87\libglesv2.dll 2017-02-06 21:13 - 2017-02-01 09:01 - 00085848 _____ () C:\Program Files (x86)\Google\Chrome\Application\56.0.2924.87\libegl.dll 2017-02-14 19:43 - 2017-02-14 19:43 - 17840216 _____ () C:\Windows\SysWOW64\Macromed\Flash\pepflashplayer32_24_0_0_221.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\ProgramData\TEMP:1CE11B51 [174] AlternateDataStreams: C:\ProgramData\TEMP:A303874F [141] AlternateDataStreams: C:\Users\Public\.DS_Store:AFP_AfpInfo [122] ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 02:34 - 2016-11-04 19:55 - 00000826 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-637814681-3575538249-3970651240-1000\Control Panel\Desktop\\Wallpaper -> DNS Servers: 192.168.1.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^GIGABYTE OC_GURU.lnk => C:\Windows\pss\GIGABYTE OC_GURU.lnk.CommonStartup MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HandyAndy.lnk => C:\Windows\pss\HandyAndy.lnk.CommonStartup MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Nuance Cloud Connector.lnk => C:\Windows\pss\Nuance Cloud Connector.lnk.CommonStartup MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Who Is On My Wifi.lnk => C:\Windows\pss\Who Is On My Wifi.lnk.CommonStartup MSCONFIG\startupfolder: C:^Users^Mike^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^MEGAsync.lnk => C:\Windows\pss\MEGAsync.lnk.Startup MSCONFIG\startupfolder: C:^Users^Mike^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Send to OneNote.lnk => C:\Windows\pss\Send to OneNote.lnk.Startup MSCONFIG\startupreg: Ad-Aware Browsing Protection => "C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe" MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" MSCONFIG\startupreg: Aimersoft Helper Compact.exe => C:\Program Files (x86)\Common Files\Aimersoft\Aimersoft Helper Compact\ASHelper.exe MSCONFIG\startupreg: Amazon Music => "C:\Users\Mike\AppData\Local\Amazon Music\Amazon Music Helper.exe" MSCONFIG\startupreg: AVG-Secure-Search-Update_0214c => C:\Users\Mike\AppData\Roaming\AVG 0214c Campaign\AVG-Secure-Search-Update-0214c.exe /PROMPT /mid=528e08c30dd047d3b8934597c659cc27-18f70e0d571fde3b8feb621bf671ce2743686407 /CMPID=0214c MSCONFIG\startupreg: AVG-Secure-Search-Update_1113a => C:\Users\Mike\AppData\Roaming\AVG 1113a Campaign\AVG-Secure-Search-Update-1113a.exe /PROMPT /mid=528e08c30dd047d3b8934597c659cc27-18f70e0d571fde3b8feb621bf671ce2743686407 /CMPID=1113a MSCONFIG\startupreg: AvgUi => "C:\Program Files (x86)\AVG\Framework\Common\avguirnx.exe" /lps=fmw MSCONFIG\startupreg: AVG_UI => "C:\Program Files (x86)\AVG\AVG2015\avgui.exe" /TRAYONLY MSCONFIG\startupreg: BrowserPlugInHelper => C:\Program Files (x86)\Wondershare\Video Converter Ultimate\BrowserPlugInHelper.exe MSCONFIG\startupreg: CDAServer => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe MSCONFIG\startupreg: chromium => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe --no-startup-window MSCONFIG\startupreg: Dashlane => "C:\Users\Mike\AppData\Roaming\Dashlane\Dashlane.exe" autoLaunchAtStartup MSCONFIG\startupreg: DivXMediaServer => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe MSCONFIG\startupreg: EaseUS Cleanup => "C:\Program Files (x86)\EaseUS\EaseUS Partition Master 11.9\bin\CleanUpUI.exe" 10 300 MSCONFIG\startupreg: EaseUS EPM tray => C:\Program Files (x86)\EaseUS\EaseUS Partition Master 11.9\bin\EpmNews.exe MSCONFIG\startupreg: EEventManager => "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe" MSCONFIG\startupreg: EPLTarget => MSCONFIG\startupreg: GoogleChromeAutoLaunch_A9A28D217F0AF6C0AE66A9006030A09A => "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window MSCONFIG\startupreg: HDAudDeck => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r MSCONFIG\startupreg: ISUSPM => "C:\ProgramData\FLEXnet\Connect\11\isuspm.exe" -scheduler MSCONFIG\startupreg: Kleptomania => C:\Program Files (x86)\Kleptomania\KMania.exe MSCONFIG\startupreg: Nuance OmniPage 18-reminder => "C:\Program Files (x86)\Nuance\OmniPage18\Ereg\Ereg.exe" -r "C:\ProgramData\ScanSoft\OmniPage 18\Ereg\Ereg.ini" MSCONFIG\startupreg: NvBackend => "C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" MSCONFIG\startupreg: Nvtmru => "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" MSCONFIG\startupreg: OCR => C:\Program Files (x86)\Screen OCR\OCR64.exe MSCONFIG\startupreg: OmniPage Preload => C:\Program Files (x86)\Nuance\OmniPage18\OmniPage18.exe /preload MSCONFIG\startupreg: OpAgent => "OpAgent.exe" /agent MSCONFIG\startupreg: PDF7 Registry Controller => C:\Program Files (x86)\Nuance\PDF Create 7\RegistryController.exe MSCONFIG\startupreg: PDFCreHook => C:\Program Files (x86)\Nuance\PDF Create 7\pdfcreate7hook.exe MSCONFIG\startupreg: ShadowPlay => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" MSCONFIG\startupreg: swg => "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" MSCONFIG\startupreg: tixati => "C:\Program Files\tixati\tixati.exe" -d1 MSCONFIG\startupreg: Viber => "C:\Users\Mike\AppData\Local\Viber\Viber.exe" MSCONFIG\startupreg: WindowsUpdate => C:\Users\Mike\AppData\Roaming\SUBEZ\FUIZB.cmd C:\Users\Mike\AppData\Roaming\SUBEZ\ZTNXU-~1 MSCONFIG\startupreg: WindowsUpdates => C:\Users\Mike\BYPLW\LUPOA-TGECU.BTYQD.vbe MSCONFIG\startupreg: Wondershare Helper Compact.exe => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe FirewallRules: [{9737F5DD-957E-498D-9748-8498D04060DE}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe FirewallRules: [{61DD9D21-46FE-4845-8DCC-CF1AF16D6564}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe FirewallRules: [{BC080EFB-A506-4904-A48B-D351E9D17B92}] => (Allow) C:\Users\Mike\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe FirewallRules: [TCP Query User{F5BFA556-E19C-4E16-9D22-75638BE4803F}C:\program files (x86)\jdownloader\jre\bin\javaw.exe] => (Allow) C:\program files (x86)\jdownloader\jre\bin\javaw.exe FirewallRules: [UDP Query User{51D807A8-F17C-48C9-B816-256703B020EF}C:\program files (x86)\jdownloader\jre\bin\javaw.exe] => (Allow) C:\program files (x86)\jdownloader\jre\bin\javaw.exe FirewallRules: [{7D1CFB3E-F027-4455-A273-5AFCDECB6801}] => (Allow) C:\Users\Mike\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{0CEAEA79-D7A9-4851-A175-8EE80E849794}] => (Allow) C:\Users\Mike\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [TCP Query User{E2835D71-BAD4-4019-A181-3FD5A34A76C3}C:\program files\smith micro\poser pro 2010\poserpro.exe] => (Block) C:\program files\smith micro\poser pro 2010\poserpro.exe FirewallRules: [UDP Query User{B2CB984C-801C-4982-838D-CE0B395B4C0B}C:\program files\smith micro\poser pro 2010\poserpro.exe] => (Block) C:\program files\smith micro\poser pro 2010\poserpro.exe FirewallRules: [TCP Query User{F0AE105A-2532-4871-9699-9240D4CEFD45}C:\program files\smith micro\poser pro 2010\poserpro.exe] => (Block) C:\program files\smith micro\poser pro 2010\poserpro.exe FirewallRules: [UDP Query User{CC305177-F8F0-43BA-8F79-70519D401D15}C:\program files\smith micro\poser pro 2010\poserpro.exe] => (Block) C:\program files\smith micro\poser pro 2010\poserpro.exe FirewallRules: [{CF2FEA8E-9216-45C8-A43B-78817E0EF9D5}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe FirewallRules: [{1EEA16B0-7170-47AD-A286-57856F04B92C}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe FirewallRules: [{29D6079D-8FCB-4689-873C-65514A1821E8}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{A6BC6260-5695-4EE7-9CEC-FA54914EA100}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{29B62130-BBD4-4A29-BB78-140B98866D2F}] => (Allow) C:\Users\Mike\AppData\Local\Viber\Viber.exe FirewallRules: [{12BF1C7A-497B-472F-B4B1-BA1A2A9D4F77}] => (Allow) C:\Program Files (x86)\PANDORA.TV\PanService\KMPProcess.exe FirewallRules: [{1ED8E032-5590-4958-89BC-5E72F3B9DF0A}] => (Allow) C:\Program Files (x86)\PANDORA.TV\PanService\KMPProcess.exe FirewallRules: [{B3E0F31F-9766-4DBE-8731-A5BF6C8040A1}] => (Allow) C:\Program Files (x86)\PANDORA.TV\PanService\KMPProcess.exe FirewallRules: [{D58B74F8-8B5A-4A83-BFE8-9DEE1594A7BD}] => (Allow) C:\Program Files (x86)\PANDORA.TV\PanService\KMPProcess.exe FirewallRules: [{539052AF-AB39-4D08-9147-C81BD626CDB1}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe FirewallRules: [{677C6AD4-052B-4FF8-8A3F-73FB648ADF2A}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe FirewallRules: [{9777375A-5CF7-4F1E-8B27-1734AAC13BD7}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{50D2C38F-6EA5-4E43-9A33-C8304F074887}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [TCP Query User{10B8CAF1-C552-49FF-8E8E-69EE2E749BA0}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe FirewallRules: [UDP Query User{B9193A07-9414-45DE-926A-C462E9639F1E}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe FirewallRules: [{CA91546D-1D5A-48A7-9512-39283C34388A}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe FirewallRules: [{8383B99B-2B62-4FF9-A6A7-03689278C688}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe FirewallRules: [{CC3E708F-FCB9-4EA4-A757-C760470DB7E5}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{0F3DBE88-44C1-4009-B89A-52816D29F1C2}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{EDC092A3-5A4F-4789-BF13-852047389093}] => (Allow) C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe FirewallRules: [{6CD6D6E2-D336-4844-9C9A-A979F2B2B40A}] => (Allow) C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe FirewallRules: [{9828CFC6-966D-4DDE-800A-B2CF352FC45A}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\IDS.Application.exe FirewallRules: [{4CCF8C81-CF5C-480A-A9C4-FB20DEC3EAD7}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\IDS.Application.exe FirewallRules: [{272AED0C-00F7-4A42-9A56-F0A4765BB4F5}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\OrderSupplies.exe FirewallRules: [{D188560D-47C0-482A-9B56-F6D1BF560178}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\OrderSupplies.exe FirewallRules: [{22D6C862-FB31-48B6-963F-3FEE30F3CB29}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\IDSAlert.exe FirewallRules: [{7887048F-0E41-4F27-A13E-2519A9DC16DD}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\IDSAlert.exe FirewallRules: [{2A964709-1AED-407C-A1F9-44CD714C0234}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\CDAS2PC\CDAS2PC.exe FirewallRules: [{E81D563E-839F-4FB5-A8EC-E58E67313239}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\CDAS2PC\CDAS2PC.exe FirewallRules: [{F81C36BA-7EA1-40C7-A8D1-0083D26D0E00}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{2D159F09-AE72-439F-B069-80577D25B479}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{0E45C5C9-6009-411C-9FFC-D20C39B61D7B}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe FirewallRules: [{D906C42D-43EE-463C-9F5F-CF2275EC1E09}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe FirewallRules: [{F1E86651-B7F5-4F93-94F1-4FF2B9D1D27B}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{E000E3A4-77AB-4736-BA8F-E7833741DC50}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [TCP Query User{C1CB5DA8-D3C2-41FA-922E-D7036B27D1AB}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre7\bin\javaw.exe FirewallRules: [UDP Query User{E91855B1-AE84-4A11-B2C2-25E850D1DE5C}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre7\bin\javaw.exe FirewallRules: [{6A50B266-D116-4E50-9980-F0EDC1A74763}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe FirewallRules: [{148EAEF3-39B3-4E29-BA25-0160911DE049}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe FirewallRules: [{BE90E2F0-EED3-4521-B5EE-7F67EF08CE0A}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe FirewallRules: [{BC8EA66D-4BE1-453E-8DE7-0F5AAAAF30B5}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe FirewallRules: [{44AFA1F3-49E5-4519-A9C5-8B2027BA21F1}] => (Allow) C:\Program Files (x86)\Nuance\OmniPage18\OmniPage18.exe FirewallRules: [{9A3C49B6-A4B2-4897-B3AC-6A8A82E2415B}] => (Allow) C:\Program Files (x86)\Nuance\OmniPage18\OmniPage18.exe FirewallRules: [{EE75939F-05A6-4EC4-BF95-4369233249C9}] => (Allow) C:\Program Files (x86)\Nuance\OmniPage18\PPMV.exe FirewallRules: [{00001A49-6240-40A3-97EC-A262671411A7}] => (Allow) C:\Program Files (x86)\Nuance\OmniPage18\PPMV.exe FirewallRules: [{D7D567F0-B881-47E9-90B4-07CB9D20D341}] => (Allow) C:\Program Files (x86)\Nuance\OmniPage18\Ereg\Ereg.exe FirewallRules: [{D14359A4-3E15-4440-9AF0-4B37206982CD}] => (Allow) C:\Program Files (x86)\Nuance\OmniPage18\Ereg\Ereg.exe FirewallRules: [{57C2D65C-BE9A-4656-A987-399C95AEFBCB}] => (Allow) C:\Program Files (x86)\Nuance\Nuance Cloud Connector\GladinetClient.exe FirewallRules: [{E945340E-772D-47E5-8A03-7C24EB780C2D}] => (Allow) C:\Program Files (x86)\Nuance\Nuance Cloud Connector\GladinetClient.exe FirewallRules: [{441E3552-A5CD-41B4-B5CA-BF5E2E0E480D}] => (Allow) C:\Program Files (x86)\Nuance\Nuance Cloud Connector\WOSVSSSvr.exe FirewallRules: [{CEE8FACF-DD10-4679-B88B-25E84FC31051}] => (Allow) C:\Program Files (x86)\Nuance\Nuance Cloud Connector\WOSVSSSvr.exe FirewallRules: [{09AFAA2A-F10E-43AF-B81D-1EA51B69312B}] => (Allow) C:\Program Files (x86)\Nuance\Nuance Cloud Connector\WOSVSSSvr2003.exe FirewallRules: [{C8E95320-CBA9-4654-A46E-7328DB78B800}] => (Allow) C:\Program Files (x86)\Nuance\Nuance Cloud Connector\WOSVSSSvr2003.exe FirewallRules: [TCP Query User{94C36B33-68BE-4837-9B72-3C710D1A8945}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => (Block) C:\program files (x86)\epson software\event manager\eeventmanager.exe FirewallRules: [UDP Query User{B55414B2-A6D8-402A-87DC-FFAD27472F53}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => (Block) C:\program files (x86)\epson software\event manager\eeventmanager.exe FirewallRules: [TCP Query User{05C1B4C3-7095-4A44-86A3-6A3AC131F015}C:\program files (x86)\wondershare\video converter ultimate\videoconverterultimate.exe] => (Allow) C:\program files (x86)\wondershare\video converter ultimate\videoconverterultimate.exe FirewallRules: [UDP Query User{E120ECEB-69F7-48D2-B748-FA445908DE2D}C:\program files (x86)\wondershare\video converter ultimate\videoconverterultimate.exe] => (Allow) C:\program files (x86)\wondershare\video converter ultimate\videoconverterultimate.exe FirewallRules: [{28B2EC34-8678-42B1-B640-8779297C88CC}] => (Allow) C:\Users\Mike\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{CA7924E2-97DD-4F1C-A846-F9E9EA9EEA8D}] => (Allow) C:\Users\Mike\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{430157EE-53FA-4561-8300-88E9553B3746}] => (Allow) C:\Program Files (x86)\AVG\AVG2014\avgmfapx.exe FirewallRules: [{96035723-00D9-4820-B0B4-D6CCB9EB7DFF}] => (Allow) C:\Program Files (x86)\AVG\AVG2014\avgmfapx.exe FirewallRules: [{CD500174-49E5-45EE-AEC7-A6E7CFBF8DF8}] => (Allow) C:\Users\Mike\AppData\Local\Temp\nslE11F.tmp\CnetInstaller-75990537.exe FirewallRules: [{FF48D77C-516A-4C49-9AF9-4C976EB447AF}] => (Allow) C:\Users\Mike\AppData\Local\Temp\nslE11F.tmp\CnetInstaller-75990537.exe FirewallRules: [{673DC000-2934-4769-A645-268331289366}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [TCP Query User{75C6CDB2-9C01-4ED8-B66D-FC24402A8EA9}C:\program files (x86)\gigabyte\@bios\gwflash.exe] => (Allow) C:\program files (x86)\gigabyte\@bios\gwflash.exe FirewallRules: [UDP Query User{5C8E0B71-0461-41BE-A973-8AC010F08447}C:\program files (x86)\gigabyte\@bios\gwflash.exe] => (Allow) C:\program files (x86)\gigabyte\@bios\gwflash.exe FirewallRules: [{5E175FF0-E555-4829-86A7-574F1E7910D2}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe FirewallRules: [{D9CD89C5-A0A2-4E80-90AB-C6593A7F026F}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe FirewallRules: [{544BF0F4-D732-458D-BE32-D4B2E04B610B}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe FirewallRules: [{D4A31B4E-A02C-4852-B172-C4078F072EC1}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe FirewallRules: [{452D5540-8EDF-4C01-A5B8-C84483D46279}] => (Allow) C:\Program Files (x86)\AVG\Av\avgnsa.exe FirewallRules: [{F77521E3-A47D-457F-BBEE-BB4C67C48673}] => (Allow) C:\Program Files (x86)\AVG\Av\avgnsa.exe FirewallRules: [{E39BB83A-72A8-49B3-B790-0124962CF02B}] => (Allow) C:\Program Files (x86)\AVG\Av\avgdiagex.exe FirewallRules: [{E556833F-4D41-4A22-987F-D107526D3DA8}] => (Allow) C:\Program Files (x86)\AVG\Av\avgdiagex.exe FirewallRules: [{2F38DE60-2FC3-4714-8B2A-F8C0A5A03E0A}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe FirewallRules: [{CAA780F1-E796-4857-A9D6-4B3AAF34C36F}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe FirewallRules: [{EFD1DEB0-BC4B-4757-BE0E-CB6D0EBD9762}] => (Allow) C:\Users\Mike\AppData\Local\Temp\Andy_45.5_x64\Setup.exe FirewallRules: [{BBB83E49-7543-4D36-A94F-B008D1831009}] => (Allow) C:\Users\Mike\AppData\Local\Temp\Andy_45.5_x64\Setup.exe FirewallRules: [{EB5561B5-E286-4247-B6C8-FBB70D110363}] => (Allow) C:\Program Files\Andy\andy.exe FirewallRules: [{B4A36DA3-9DDE-4F17-B0A4-C93F15446003}] => (Allow) C:\Program Files\Andy\andy.exe FirewallRules: [{2C33B7A9-4F52-4880-B528-4A38AC26AC3B}] => (Allow) C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe FirewallRules: [{A85627DA-C26D-4C42-93D5-E62082A7DE26}] => (Allow) C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe FirewallRules: [{A6ACD22C-01F4-41CD-9AA6-75B6271BB9A9}] => (Allow) C:\Program Files\Andy\HandyAndy.exe FirewallRules: [{1CEFC419-0143-44CA-A3DD-2E724C3C9000}] => (Allow) C:\Program Files\Andy\HandyAndy.exe FirewallRules: [TCP Query User{E010F08C-B68E-4751-8BA7-393CB37F7E96}C:\program files\tixati\tixati.exe] => (Allow) C:\program files\tixati\tixati.exe FirewallRules: [UDP Query User{025883E0-9404-476E-BC1C-E67006F23433}C:\program files\tixati\tixati.exe] => (Allow) C:\program files\tixati\tixati.exe FirewallRules: [{A58E9C3B-B5DC-47A5-B61A-F5D6F5625951}] => (Allow) C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe FirewallRules: [{2596A291-70B7-4DAF-A530-DB48D6C32AB5}] => (Allow) C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe FirewallRules: [{92C93613-7E43-4583-9DF2-D350B2AD7E02}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\IDS.Application.exe FirewallRules: [{3B6EB0DB-9F9A-4384-8AA5-346FF302FE63}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\IDS.Application.exe FirewallRules: [{959C5F3B-9901-4E93-BFEF-CF51EAED67C3}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\OrderSupplies.exe FirewallRules: [{DC3B3A0D-0B6F-4904-9E12-B4D4EBE643D1}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\OrderSupplies.exe FirewallRules: [{ADE63989-18EC-45D9-ACCE-AD22C038112D}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\IDSAlert.exe FirewallRules: [{B723722F-41F5-4278-B7AE-2ED7537B765A}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\IDSAlert.exe FirewallRules: [{93CA2ABA-3319-4E71-B109-DD845377FF1A}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\CDAS2PC\CDAS2PC.exe FirewallRules: [{3D17633D-4BBA-40FC-841A-231749B9881C}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\CDAS2PC\CDAS2PC.exe FirewallRules: [{9E916DE4-1713-43B3-8BB5-C725ACC77C95}] => (Allow) C:\Program Files (x86)\Samsung\Samsung Printer Diagnostics\SEInstall\SPD\ESM.exe FirewallRules: [{92253F77-95F7-488A-97B9-65BE22CE6968}] => (Allow) C:\Program Files (x86)\Samsung\Samsung Printer Diagnostics\SEInstall\SPD\ESM.exe FirewallRules: [{B3DF73F8-7751-499F-9FA1-AEA23B2CB08C}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{7258ACAA-549C-456F-BC77-2F4BAE25A29D}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{3A2DD7AE-3906-4BE5-A784-4C88E5381BD1}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{86D88A58-2F29-4CD7-BDC9-C417D0893764}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [TCP Query User{ADAD581B-F89F-4BCD-8917-423134DCA8AC}C:\program files (x86)\dearmob\5kplayer\5kplayer.exe] => (Allow) C:\program files (x86)\dearmob\5kplayer\5kplayer.exe FirewallRules: [UDP Query User{57767FAE-A9D7-45F6-A35A-94EDFE4106C5}C:\program files (x86)\dearmob\5kplayer\5kplayer.exe] => (Allow) C:\program files (x86)\dearmob\5kplayer\5kplayer.exe FirewallRules: [{9FF83D6E-5649-4E93-94CD-BF6AAA1E8C38}] => (Block) C:\program files (x86)\dearmob\5kplayer\5kplayer.exe FirewallRules: [{51631C84-CBAC-4296-8CF3-87AF24869069}] => (Block) C:\program files (x86)\dearmob\5kplayer\5kplayer.exe FirewallRules: [TCP Query User{FFECB1D4-ED34-4227-BBE1-73E6755F504A}C:\users\mike\appdata\roaming\utorrent\updates\3.4.9_42606.exe] => (Allow) C:\users\mike\appdata\roaming\utorrent\updates\3.4.9_42606.exe FirewallRules: [UDP Query User{3B4A3387-0E55-4271-A0CC-B3D25A387CDC}C:\users\mike\appdata\roaming\utorrent\updates\3.4.9_42606.exe] => (Allow) C:\users\mike\appdata\roaming\utorrent\updates\3.4.9_42606.exe FirewallRules: [{A52B891E-2C7F-43C1-8809-E560B24EE9BD}] => (Block) C:\users\mike\appdata\roaming\utorrent\updates\3.4.9_42606.exe FirewallRules: [{824B76CC-76A7-4312-96CA-7EAE230FFA15}] => (Block) C:\users\mike\appdata\roaming\utorrent\updates\3.4.9_42606.exe FirewallRules: [TCP Query User{7FD5C5CF-0490-4DEF-8327-F89AC65BD0CC}C:\users\mike\appdata\local\skypeplugin\7.2.0.422\pluginhost.exe] => (Allow) C:\users\mike\appdata\local\skypeplugin\7.2.0.422\pluginhost.exe FirewallRules: [UDP Query User{4C3DA0C8-3827-4C33-987C-EE5D6ACD64F4}C:\users\mike\appdata\local\skypeplugin\7.2.0.422\pluginhost.exe] => (Allow) C:\users\mike\appdata\local\skypeplugin\7.2.0.422\pluginhost.exe FirewallRules: [{D853FC83-4976-476B-9EA0-AD9BFD72DEAC}] => (Block) C:\users\mike\appdata\local\skypeplugin\7.2.0.422\pluginhost.exe FirewallRules: [{141B2E92-F7A6-4146-9142-C9DC54C53004}] => (Block) C:\users\mike\appdata\local\skypeplugin\7.2.0.422\pluginhost.exe FirewallRules: [TCP Query User{55513122-5312-4324-9702-427291174558}C:\users\mike\appdata\local\skypeplugin\pluginhost.exe] => (Allow) C:\users\mike\appdata\local\skypeplugin\pluginhost.exe FirewallRules: [UDP Query User{51E85BE9-90CC-4A0E-A212-9368FA97F5D8}C:\users\mike\appdata\local\skypeplugin\pluginhost.exe] => (Allow) C:\users\mike\appdata\local\skypeplugin\pluginhost.exe FirewallRules: [{18DFFC13-DB14-42A1-93BF-75EB2AA30CB7}] => (Block) C:\users\mike\appdata\local\skypeplugin\pluginhost.exe FirewallRules: [{9C2BE15B-EA32-48D1-A049-541B099144FD}] => (Block) C:\users\mike\appdata\local\skypeplugin\pluginhost.exe FirewallRules: [TCP Query User{68676FAF-6D6E-42D0-A584-FED801F9A3A0}C:\users\mike\appdata\local\amazon music\amazon music helper.exe] => (Allow) C:\users\mike\appdata\local\amazon music\amazon music helper.exe FirewallRules: [UDP Query User{41DB7CA4-8B99-4BEA-B8C9-740FB03E5C19}C:\users\mike\appdata\local\amazon music\amazon music helper.exe] => (Allow) C:\users\mike\appdata\local\amazon music\amazon music helper.exe FirewallRules: [{9C876940-A9F9-489C-B9D8-F8E29EC39F2E}] => (Block) C:\users\mike\appdata\local\amazon music\amazon music helper.exe FirewallRules: [{2DA07B87-08B6-4FD9-AC47-1912300B5313}] => (Block) C:\users\mike\appdata\local\amazon music\amazon music helper.exe FirewallRules: [{24796F11-AB35-418D-8327-66B247F205B2}] => (Allow) C:\Program Files (x86)\ASUS\Wireless Router\Device Discovery\Discovery.exe FirewallRules: [{58B40DBB-3309-4108-8935-6C3A4FC391DE}] => (Allow) C:\Program Files (x86)\ASUS\Wireless Router\Device Discovery\Discovery.exe FirewallRules: [{D4E40764-1B8B-42F6-8DC0-0EA6BEE82611}] => (Allow) C:\Program Files (x86)\AVG\Av\avgnsa.exe FirewallRules: [{0CECA175-C948-4800-BB8D-7D74E26CD06C}] => (Allow) C:\Program Files (x86)\AVG\Av\avgnsa.exe FirewallRules: [{990FA90A-9C48-4993-9CA1-38A48D1863E3}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe FirewallRules: [{E052F2A0-D8A4-4052-A8EF-EBD1BE1CCA35}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe FirewallRules: [TCP Query User{05AD633E-BC55-448E-A7F1-86C97661A9F6}C:\program files (x86)\java\jre7\bin\java.exe] => (Allow) C:\program files (x86)\java\jre7\bin\java.exe FirewallRules: [UDP Query User{7B6BFF0F-85E5-4006-927D-F16530D473E7}C:\program files (x86)\java\jre7\bin\java.exe] => (Allow) C:\program files (x86)\java\jre7\bin\java.exe FirewallRules: [{519A6EA3-B622-4435-9651-0597E281E16B}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Restore Points ========================= ==================== Faulty Device Manager Devices ============= Name: HUAWEI Mobile Connect - Bus Enumerate Device Description: HUAWEI Mobile Connect - Bus Enumerate Device Class Guid: Manufacturer: Service: Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (02/23/2017 11:26:35 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Error: (02/23/2017 11:24:56 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: mepService.exe, version: 1.1.2.0, time stamp: 0x541f882f Faulting module name: mepService.exe, version: 1.1.2.0, time stamp: 0x541f882f Exception code: 0xc000000d Fault offset: 0x0006c33b Faulting process id: 0xc04 Faulting application start time: 0x01d28dc7733ee71a Faulting application path: C:\Program Files (x86)\EPSON\MyEpson Portal\mepService.exe Faulting module path: C:\Program Files (x86)\EPSON\MyEpson Portal\mepService.exe Report Id: b3cd5c8f-f9ba-11e6-aeb7-005056c00008 Error: (02/23/2017 11:24:55 AM) (Source: NvStreamSvc) (EventID: 2001) (User: ) Description: Event-ID 2001 Error: (02/23/2017 11:24:55 AM) (Source: NvStreamSvc) (EventID: 2001) (User: ) Description: Event-ID 2001 Error: (02/23/2017 11:24:55 AM) (Source: NvStreamSvc) (EventID: 2001) (User: ) Description: Event-ID 2001 Error: (02/23/2017 11:17:36 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Error: (02/23/2017 11:15:59 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: mepService.exe, version: 1.1.2.0, time stamp: 0x541f882f Faulting module name: mepService.exe, version: 1.1.2.0, time stamp: 0x541f882f Exception code: 0xc000000d Fault offset: 0x0006c33b Faulting process id: 0xc8c Faulting application start time: 0x01d28dc6326786e7 Faulting application path: C:\Program Files (x86)\EPSON\MyEpson Portal\mepService.exe Faulting module path: C:\Program Files (x86)\EPSON\MyEpson Portal\mepService.exe Report Id: 73b49944-f9b9-11e6-a52b-005056c00008 Error: (02/23/2017 11:15:57 AM) (Source: NvStreamSvc) (EventID: 2001) (User: ) Description: Event-ID 2001 Error: (02/23/2017 11:15:57 AM) (Source: NvStreamSvc) (EventID: 2001) (User: ) Description: Event-ID 2001 Error: (02/23/2017 11:15:57 AM) (Source: NvStreamSvc) (EventID: 2001) (User: ) Description: Event-ID 2001 System errors: ============= Error: (02/23/2017 11:24:57 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The MyEpson Portal Service service terminated unexpectedly. It has done this 1 time(s). Error: (02/23/2017 11:24:51 AM) (Source: Service Control Manager) (EventID: 7006) (User: ) Description: The ScRegSetValueExW call failed for FailureActions with the following error: Access is denied. Error: (02/23/2017 11:24:51 AM) (Source: Service Control Manager) (EventID: 7006) (User: ) Description: The ScRegSetValueExW call failed for FailureActions with the following error: Access is denied. Error: (02/23/2017 11:24:13 AM) (Source: Service Control Manager) (EventID: 7006) (User: ) Description: The ScRegSetValueExW call failed for FailureActions with the following error: Access is denied. Error: (02/23/2017 11:23:13 AM) (Source: Service Control Manager) (EventID: 7032) (User: ) Description: The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Search service, but this action failed with the following error: An instance of the service is already running. Error: (02/23/2017 11:22:43 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The Windows Modules Installer service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service. Error: (02/23/2017 11:22:43 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The Windows Media Player Network Sharing Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service. Error: (02/23/2017 11:22:43 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The Software Protection service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service. Error: (02/23/2017 11:22:43 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The Windows Search service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service. Error: (02/23/2017 11:22:43 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The VMware Authorization Service service terminated unexpectedly. It has done this 1 time(s). ==================== Memory info =========================== Processor: AMD FX(tm)-6300 Six-Core Processor Percentage of memory in use: 56% Total physical RAM: 8173.55 MB Available physical RAM: 3557.32 MB Total Virtual: 16345.29 MB Available Virtual: 12083.21 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:465.66 GB) (Free:292.5 GB) NTFS Drive d: (SAMSUNG SSD) (CDROM) (Total:0.05 GB) (Free:0 GB) UDF Drive e: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS ==>[system with boot components (obtained from drive)] Drive f: () (Fixed) (Total:931.41 GB) (Free:755.33 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 465.8 GB) (Disk ID: FB915E4C) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=465.7 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 19608239) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=931.4 GB) - (Type=07 NTFS) ==================== End of Addition.txt ============================