Additional scan result of Farbar Recovery Scan Tool (x64) Version:30-08-2015 Ran by Atmega64 (2015-08-30 19:07:41) Running from A:\Nowy folder Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Atmega64 (S-1-5-21-1956654831-1094942765-1821975874-1001 - Administrator - Enabled) => C:\Users\Atmega64 DefaultAccount (S-1-5-21-1956654831-1094942765-1821975874-503 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-1956654831-1094942765-1821975874-1003 - Limited - Enabled) NOACCESSGUY (S-1-5-21-1956654831-1094942765-1821975874-501 - Limited - Disabled) Żupan (S-1-5-21-1956654831-1094942765-1821975874-500 - Administrator - Disabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) µTorrent (HKU\S-1-5-21-1956654831-1094942765-1821975874-1001\...\uTorrent) (Version: 3.4.3.40760 - BitTorrent Inc.) Adobe Flash Player 18 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 18.0.0.232 - Adobe Systems Incorporated) Arduino (HKLM-x32\...\Arduino) (Version: 1.6.5-r2 - Arduino LLC) Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) Broadcom CrystalHD Decoder (X64) (HKLM\...\{1F277AB1-55E5-4569-B6C2-63278A7F9840}) (Version: 3.6.9.64 - Broadcom Corporation) CodeBlocks (HKU\S-1-5-21-1956654831-1094942765-1821975874-1001\...\CodeBlocks) (Version: 13.12 - The Code::Blocks Team) EAGLE 7.1.0 (HKLM-x32\...\EAGLE 7.1.0) (Version: 7.1.0 - CadSoft Computer GmbH) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 44.0.2403.157 - Google Inc.) Google Update Helper (x32 Version: 1.3.28.1 - Google Inc.) Hidden Hearthstone (HKLM-x32\...\Hearthstone) (Version: - Blizzard Entertainment) Intel(R) Wireless Bluetooth(R)(patch version 17.1.1519.1030) (HKLM\...\{302600C1-6BDF-4FD1-1504-148929CC1385}) (Version: 17.1.1504.0518 - Intel Corporation) Intel® PROSet/Wireless Software (HKLM-x32\...\{d9e230c1-06bb-4b78-a9f1-c1ddce14e6fc}) (Version: 18.11.0 - Intel Corporation) Java 8 Update 51 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418051F0}) (Version: 8.0.510 - Oracle Corporation) Lenovo Power Management Driver (HKLM\...\Power Management Driver) (Version: 1.67.10.17 - Lenovo) Malwarebytes Anti-Malware version 2.1.8.1057 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation) MATLAB Production Server R2015a (HKLM\...\MATLAB Production Server R2015a) (Version: 2.1 - MathWorks) Microsoft Age of Empires Gold (HKLM-x32\...\Age of Empires Gold 1.0) (Version: - ) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) MSI Afterburner 4.1.1 (HKLM-x32\...\Afterburner) (Version: 4.1.1 - MSI Co., LTD) Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.8.1 - Notepad++ Team) NVIDIA Graphics Driver 341.74 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 341.74 - NVIDIA Corporation) Opera Stable 31.0.1889.174 (HKLM-x32\...\Opera 31.0.1889.174) (Version: 31.0.1889.174 - Opera Software) Samsung USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.55.0 - Samsung Electronics Co., Ltd.) Skype™ 7.8 (HKLM-x32\...\{6A0549A9-1B96-498C-ACBC-3943001FEB19}) (Version: 7.8.102 - Skype Technologies S.A.) SoundMAX (HKLM-x32\...\{F0A37341-D692-11D4-A984-009027EC0A9C}) (Version: 6.10.2.7255 - Analog Devices) Stronghold Crusader Extreme HD (HKLM-x32\...\GOGPACKSTRONGHOLDCRUSADERHD_is1) (Version: 2.0.0.6 - GOG.com) ThinkPad UltraNav Driver (HKLM\...\SynTPDeinstKey) (Version: 16.2.19.7 - ) TPFanControl v0.62 (HKLM\...\{717F5741-5C2E-4469-BDA0-B5EC2243646F}_is1) (Version: - troubadix) Windows Driver Package - FTDI CDM Driver Package - Bus/D2XX Driver (07/10/2015 2.12.06) (HKLM\...\B85E5F21D69245012A4E4C2DFAF38615FC7CF7AA) (Version: 07/10/2015 2.12.06 - FTDI) Windows Driver Package - FTDI CDM Driver Package - VCP Driver (07/10/2015 2.12.06) (HKLM\...\71B7FC12B248030B4BBBCA0C57826D74F64DB010) (Version: 07/10/2015 2.12.06 - FTDI) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-1956654831-1094942765-1821975874-1001_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32 -> C:\Users\Atmega64\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64\FileSyncShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1956654831-1094942765-1821975874-1001_Classes\CLSID\{5AB7172C-9C11-405C-8DD5-AF20F3606282}\InprocServer32 -> C:\Users\Atmega64\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64\FileSyncShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1956654831-1094942765-1821975874-1001_Classes\CLSID\{5F63E8CB-8F57-490A-97FE-62BC2F2A5EA4}\InprocServer32 -> no filepath CustomCLSID: HKU\S-1-5-21-1956654831-1094942765-1821975874-1001_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32 -> C:\Users\Atmega64\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64\FileSyncShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1956654831-1094942765-1821975874-1001_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32 -> C:\Users\Atmega64\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64\FileSyncShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1956654831-1094942765-1821975874-1001_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\Atmega64\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64\FileSyncShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1956654831-1094942765-1821975874-1001_Classes\CLSID\{A78ED123-AB77-406B-9962-2A5D9D2F7F30}\InprocServer32 -> C:\Users\Atmega64\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64\FileSyncShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1956654831-1094942765-1821975874-1001_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\Atmega64\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64\FileSyncShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1956654831-1094942765-1821975874-1001_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\Atmega64\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64\FileSyncShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1956654831-1094942765-1821975874-1001_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\Atmega64\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64\FileSyncShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1956654831-1094942765-1821975874-1001_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Atmega64\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64\FileSyncApi64.dll (Microsoft Corporation) ==================== Restore Points ========================= ATTENTION: System Restore is disabled ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2015-07-10 12:04 - 2015-07-10 12:02 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {002FCA4A-CA0C-43B4-8843-5806506E6A02} - System32\Tasks\MSIAfterburner => A:\Programy\MSI Afterburner\MSIAfterburner.exe [2015-06-02] () Task: {00EEBA9C-F9EF-4272-B793-C830FBADD359} - System32\Tasks\Microsoft\Windows\ApplicationData\DsSvcCleanup => C:\Windows\system32\dstokenclean.exe [2015-07-10] (Microsoft Corporation) Task: {0CCA7916-2916-4F12-BD32-1E3BE31E1269} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Device-Join => C:\Windows\System32\dsregcmd.exe [2015-07-10] (Microsoft Corporation) Task: {19865544-CE08-40BE-8B8C-87C47681433D} - System32\Tasks\Microsoft\Windows\WindowsUpdate\sihboot => C:\Windows\System32\sihclient.exe [2015-07-10] (Microsoft Corporation) Task: {20418A80-65D7-4F7A-8A36-AB3BBA31613D} - System32\Tasks\ThrottleStop => A:\Atmega64\ThrottleStop_600\ThrottleStop.exe [2015-07-25] (uWebb Software) Task: {3F6E048D-6404-433B-8F5F-CFF4D89BF89E} - System32\Tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser => Rundll32.exe generaltel.dll,RunTelemetryW Task: {41160EA0-208B-4C3E-B4DB-805BBABC6B93} - System32\Tasks\Microsoft\Windows\Feedback\Siuf\DmClient => C:\Windows\system32\dmclient.exe [2015-07-10] (Microsoft Corporation) Task: {73551810-E5F4-433E-9494-0D00B55C855E} - System32\Tasks\Microsoft\Windows\Maps\MapsToastTask Task: {78B77FA3-9D97-441D-97B6-68CEA40B4F74} - System32\Tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater => Rundll32.exe generaltel.dll,RunTelemetry -maintenance Task: {8DF84CB3-D8E0-4307-A35B-CA74E21786DB} - System32\Tasks\Microsoft\Windows\Clip\License Validation => C:\Windows\system32\ClipUp.exe [2015-07-15] (Microsoft Corporation) Task: {A5B6CD85-1B57-49B9-BA80-5D5D65F02826} - System32\Tasks\Microsoft\Windows\AppID\EDP Policy Manager Task: {C56AFFD3-06B8-4A16-AF7E-F7A6EB3FAE9E} - System32\Tasks\Microsoft\Windows\TPM\Tpm-HASCertRetr Task: {C5EE2EA2-5312-4D1F-B9D0-41B18DF31B78} - System32\Tasks\Microsoft\Windows\WindowsUpdate\sih => C:\Windows\System32\sihclient.exe [2015-07-10] (Microsoft Corporation) Task: {C7A236B2-12E1-46DC-9501-3B1B0209CC09} - System32\Tasks\Microsoft\Windows\Location\WindowsActionDialog => C:\Windows\System32\WindowsActionDialog.exe [2015-07-10] (Microsoft Corporation) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) ==================== Loaded Modules (Whitelisted) ============== 2015-07-25 20:37 - 2015-07-15 03:04 - 00032768 _____ () C:\WINDOWS\SYSTEM32\licensemanagerapi.dll 2015-08-05 18:55 - 2015-07-30 07:05 - 02498808 _____ () C:\WINDOWS\system32\CoreUIComponents.dll 2015-08-05 18:55 - 2015-07-30 07:05 - 02498808 _____ () C:\WINDOWS\System32\CoreUIComponents.dll 2015-04-15 21:13 - 2015-04-15 21:13 - 00222720 _____ () A:\Programy\Notepad++\NppShell_06.dll 2015-07-10 11:59 - 2015-07-10 11:59 - 00429056 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll 2015-07-27 23:27 - 2015-07-24 03:44 - 00642048 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\MtcUvc.dll 2015-08-19 23:18 - 2015-08-19 15:16 - 58600568 _____ () A:\Programy\Opera\31.0.1889.174\opera.dll 2015-08-19 23:18 - 2015-08-19 15:16 - 01781368 _____ () A:\Programy\Opera\31.0.1889.174\libglesv2.dll 2015-08-19 23:18 - 2015-08-19 15:16 - 00081528 _____ () A:\Programy\Opera\31.0.1889.174\libegl.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\ProgramData\TEMP:9A870F8B AlternateDataStreams: C:\Users\Atmega64\OneDrive:ms-properties ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Ahcache.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CoreMessagingRegistrar => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\StateRepository => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TileDataModelSvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\UserManager => ""="Service" ==================== EXE Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-1956654831-1094942765-1821975874-1001\Control Panel\Desktop\\Wallpaper -> c:\windows\web\wallpaper\windows\img0.jpg DNS Servers: 194.168.4.100 - 194.168.8.100 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) mpsdrv Firewall Service is not running. MpsSvc Firewall Service is not running. ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) MSCONFIG\Services: BDESVC => 3 MSCONFIG\Services: WSearch => 2 MSCONFIG\Services: XblAuthManager => 3 MSCONFIG\Services: XblGameSave => 3 MSCONFIG\Services: XboxNetApiSvc => 3 HKLM\...\StartupApproved\Run32: => "AsioReg" HKLM\...\StartupApproved\Run32: => "NvCplDaemon" HKLM\...\StartupApproved\Run32: => "ADSKAppManager" HKLM\...\StartupApproved\Run32: => "CtxfiReg" HKLM\...\StartupApproved\Run32: => "DevconDefaultDB" HKLM\...\StartupApproved\Run32: => "Malwarebytes Anti-Malware (cleanup)" HKU\S-1-5-21-1956654831-1094942765-1821975874-1001\...\StartupApproved\Run: => "DAEMON Tools Pro Agent" HKU\S-1-5-21-1956654831-1094942765-1821975874-1001\...\StartupApproved\Run: => "Akamai NetSession Interface" HKU\S-1-5-21-1956654831-1094942765-1821975874-1001\...\StartupApproved\Run: => "DevconDefaultDB" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppextcomobj.exe FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppextcomobj.exe ==================== Faulty Device Manager Devices ============= Name: Ricoh MMC Disk Device Description: Disk drive Class Guid: {4d36e967-e325-11ce-bfc1-08002be10318} Manufacturer: (Standard disk drives) Service: disk Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Could not list Devices. Check "winmgmt" service or repair WMI. ==================== Event log errors: ========================= Application errors: ================== Error: (08/29/2015 01:14:19 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: THINKI) Description: Activation of app Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI failed with error: -2147024891 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (08/27/2015 09:43:19 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: THINKI) Description: Activation of app Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI failed with error: -2147024891 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (08/10/2015 10:56:00 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Activation context generation failed for "Microsoft.VC90.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.30729.6161"1". Dependent Assembly Microsoft.VC90.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.30729.6161" could not be found. Please use sxstrace.exe for detailed diagnosis. Error: (08/10/2015 10:55:53 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Activation context generation failed for "Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195"1". Dependent Assembly Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195" could not be found. Please use sxstrace.exe for detailed diagnosis. Error: (08/10/2015 08:45:33 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: THINKI) Description: Activation of app Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI failed with error: -2147024891 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (08/10/2015 08:28:48 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: THINKI) Description: Activation of app Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI failed with error: -2147024891 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (08/10/2015 06:06:45 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program left4dead2.exe version 0.0.0.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel. Process ID: 410 Start Time: 01d0d38ed36ccc7f Termination Time: 121 Application Path: A:\Atmega64\Left 4 Dead 2\left4dead2.exe Report Id: 2ca8a1da-3f82-11e5-9c04-001c251a29bc Faulting package full name: Faulting package-relative application ID: Error: (08/10/2015 03:09:58 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: THINKI) Description: Activation of app Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI failed with error: -2147024891 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (08/10/2015 03:04:52 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: SystemSettingsBroker.exe, version: 10.0.10240.16384, time stamp: 0x559f39c2 Faulting module name: KERNELBASE.dll, version: 10.0.10240.16384, time stamp: 0x559f38c3 Exception code: 0xe06d7363 Fault offset: 0x000000000002a1c8 Faulting process id: 0x16f8 Faulting application start time: 0xSystemSettingsBroker.exe0 Faulting application path: SystemSettingsBroker.exe1 Faulting module path: SystemSettingsBroker.exe2 Report Id: SystemSettingsBroker.exe3 Faulting package full name: SystemSettingsBroker.exe4 Faulting package-relative application ID: SystemSettingsBroker.exe5 Error: (08/10/2015 02:54:36 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: THINKI) Description: Activation of app Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI failed with error: -2147024891 See the Microsoft-Windows-TWinUI/Operational log for additional information. System errors: ============= Error: (08/27/2015 10:14:26 PM) (Source: DCOM) (EventID: 10005) (User: NT AUTHORITY) Description: 1068netprofmUnavailable{A47979D2-C419-11D9-A5B4-001185AD2B89} Error: (08/27/2015 10:14:26 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: %%1068 Error: (08/27/2015 10:14:26 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The Network Location Awareness service depends on the Windows Event Log service which failed to start because of the following error: %%1058 Error: (08/27/2015 10:14:23 PM) (Source: DCOM) (EventID: 10005) (User: NT AUTHORITY) Description: 1068netprofmUnavailable{A47979D2-C419-11D9-A5B4-001185AD2B89} Error: (08/27/2015 10:14:23 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: %%1068 Error: (08/27/2015 10:14:23 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The Network Location Awareness service depends on the Windows Event Log service which failed to start because of the following error: %%1058 Error: (08/27/2015 10:14:20 PM) (Source: DCOM) (EventID: 10005) (User: NT AUTHORITY) Description: 1068netprofmUnavailable{A47979D2-C419-11D9-A5B4-001185AD2B89} Error: (08/27/2015 10:14:20 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: %%1068 Error: (08/27/2015 10:14:20 PM) (Source: Service Control Manager) (EventID: 7001) (User: ) Description: The Network Location Awareness service depends on the Windows Event Log service which failed to start because of the following error: %%1058 Error: (08/27/2015 10:14:17 PM) (Source: DCOM) (EventID: 10005) (User: NT AUTHORITY) Description: 1068netprofmUnavailable{A47979D2-C419-11D9-A5B4-001185AD2B89} Microsoft Office: ========================= Error: (08/29/2015 01:14:19 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: THINKI) Description: Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI-2147024891 Error: (08/27/2015 09:43:19 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: THINKI) Description: Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI-2147024891 Error: (08/10/2015 10:56:00 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Microsoft.VC90.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.30729.6161"d:\bin\win64\vc90\VCRT_check.exe Error: (08/10/2015 10:55:53 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195"d:\bin\win64\VCRT_check.exe Error: (08/10/2015 08:45:33 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: THINKI) Description: Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI-2147024891 Error: (08/10/2015 08:28:48 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: THINKI) Description: Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI-2147024891 Error: (08/10/2015 06:06:45 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: left4dead2.exe0.0.0.041001d0d38ed36ccc7f121A:\Atmega64\Left 4 Dead 2\left4dead2.exe2ca8a1da-3f82-11e5-9c04-001c251a29bc Error: (08/10/2015 03:09:58 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: THINKI) Description: Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI-2147024891 Error: (08/10/2015 03:04:52 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: SystemSettingsBroker.exe10.0.10240.16384559f39c2KERNELBASE.dll10.0.10240.16384559f38c3e06d7363000000000002a1c816f801d0d374e1ff80c4C:\Windows\System32\SystemSettingsBroker.exeC:\WINDOWS\system32\KERNELBASE.dll45eb4075-e173-4526-bc1d-8c749cba2d30 Error: (08/10/2015 02:54:36 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: THINKI) Description: Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI-2147024891 CodeIntegrity: =================================== Date: 2015-08-06 02:49:42.721 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Scenario\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2015-08-06 02:49:41.614 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Scenario\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2015-08-06 02:49:40.569 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Scenario\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2015-08-06 02:49:39.527 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Scenario\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2015-08-06 02:49:36.298 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Scenario\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2015-08-06 02:49:35.230 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Scenario\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2015-08-06 02:49:34.186 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Scenario\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2015-08-06 02:49:33.143 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Scenario\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2015-07-25 23:08:01.525 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Programy\RMClock\RTCore64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2015-07-25 23:08:01.469 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Programy\RMClock\RTCore64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. ==================== Memory info =========================== Processor: Intel(R) Core(TM)2 Extreme CPU X9000 @ 2.80GHz Percentage of memory in use: 30% Total physical RAM: 8126.29 MB Available physical RAM: 5610.11 MB Total Virtual: 24126.29 MB Available Virtual: 21007.27 MB ==================== Drives ================================ Drive a: (SSD) (Fixed) (Total:344.03 GB) (Free:174.28 GB) NTFS Drive c: () (Fixed) (Total:85.97 GB) (Free:22.4 GB) NTFS Drive f: () (Fixed) (Total:238.36 GB) (Free:238.19 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 238.5 GB) (Disk ID: 140394ED) Partition 1: (Not Active) - (Size=238.4 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (Size: 476.9 GB) (Disk ID: B57E8D32) Partition 1: (Active) - (Size=350 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=86 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=344 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=46.6 GB) - (Type=05) ==================== End of Addition.txt ============================