Fix result of Farbar Recovery Scan Tool (x64) Version:28-06-2015 01 Ran by Karos64 at 2015-07-04 19:23:30 Run:1 Running from C:\Users\Karos64\Desktop\FRST Loaded Profiles: Karos64 (Available Profiles: Karos64) Boot Mode: Normal ============================================== fixlist content: ***************** ListPermissions: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\PlugPlay Reg: reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\PlugPlay" ***************** =================================== permissions of "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\PlugPlay": Owner: BUILTIN\Administrators DACL(AI): BUILTIN\Users ALLOW READ (I) BUILTIN\Users ALLOW READ (CI-I-OI) BUILTIN\Administrators ALLOW FULL (I) BUILTIN\Administrators ALLOW FULL (CI-I-OI) NT AUTHORITY\SYSTEM ALLOW FULL (I) NT AUTHORITY\SYSTEM ALLOW FULL (CI-I-OI) CREATOR OWNER ALLOW FULL (CI-I-OI) =================================== ========= reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\PlugPlay" ========= HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\PlugPlay DisplayName REG_SZ @%SystemRoot%\system32\umpnpmgr.dll,-100 Group REG_SZ PlugPlay ImagePath REG_EXPAND_SZ %SystemRoot%\system32\svchost.exe -k DcomLaunch Description REG_SZ @%SystemRoot%\system32\umpnpmgr.dll,-101 ObjectName REG_SZ LocalSystem ErrorControl REG_DWORD 0x1 Start REG_DWORD 0x2 Type REG_DWORD 0x20 ServiceSidType REG_DWORD 0x1 RequiredPrivileges REG_MULTI_SZ SeTcbPrivilege\0SeSecurityPrivilege\0SeAssignPrimaryTokenPrivilege\0SeTakeOwnershipPrivilege\0SeLoadDriverPrivilege\0SeBackupPrivilege\0SeRestorePrivilege\0SeImpersonatePrivilege\0SeAuditPrivilege\0SeChangeNotifyPrivilege\0SeUndockPrivilege\0SeDebugPrivilege\0SeShutdownPrivilege FailureActions REG_BINARY 00000000000000000000000003000000140000000200000060EA00000200000060EA00000200000060EA0000 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\PlugPlay\Parameters ========= End of Reg: ========= ==== End of Fixlog 19:23:30 ====