Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version:10-09-2015 01
Ran by felix (2015-09-11 20:13:59)
Running from C:\Users\felix\Desktop
Windows 10 Pro Insider Preview (X64) (2015-09-05 19:26:25)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-3600270544-3147449856-236785905-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-3600270544-3147449856-236785905-503 - Limited - Disabled)
felix (S-1-5-21-3600270544-3147449856-236785905-1001 - Administrator - Enabled) => C:\Users\felix
Guest (S-1-5-21-3600270544-3147449856-236785905-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3600270544-3147449856-236785905-1003 - Limited - Enabled)
penguin (S-1-5-21-3600270544-3147449856-236785905-1005 - Administrator - Enabled) => C:\Users\penguin
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
µTorrent (HKU\S-1-5-21-3600270544-3147449856-236785905-1001\...\uTorrent) (Version: 3.4.5.41073 - BitTorrent Inc.)
64 Bit HP CIO Components Installer (Version: 7.2.8 - Hewlett-Packard) Hidden
7-Zip 9.38 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0938-000001000000}) (Version: 9.38.00.0 - Igor Pavlov)
Adobe Illustrator CC 2014 (HKLM-x32\...\{2B4B4082-8043-4646-8334-B0A29E641211}) (Version: 18.0 - Adobe Systems Incorporated)
Adobe Photoshop CC 2014 (HKLM-x32\...\{D7A4F897-B20A-42D0-862D-CB5F6DB7391D}) (Version: 15.0 - Adobe Systems Incorporated)
AMD OverDrive (HKLM-x32\...\{34D5220A-58D0-473C-90E4-15136C3FB0E3}) (Version: 4.3.1.0690 - Advanced Micro Devices, Inc.)
Assassin's Creed Rogue (HKLM-x32\...\Uplay Install 895) (Version: - Ubisoft)
Audacity 2.1.0 (HKLM-x32\...\Audacity_is1) (Version: 2.1.0 - Audacity Team)
Autodesk 123D Catch (HKLM-x32\...\{413A0A2B-D154-4457-833F-3299DB3183FF}) (Version: 1.0.654 - Autodesk)
Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment)
Beard and Hairstyle Set (HKLM-x32\...\Beard and Hairstyle Set_is1) (Version: 1.0.0.0 - GOG.com)
BlueStacks App Player (HKLM-x32\...\BlueStacks App Player) (Version: 0.9.30.9239 - BlueStack Systems, Inc.)
BlueStacks Notification Center (HKLM-x32\...\{79809712-A577-4B8C-A9FC-51945690C7DC}) (Version: 0.9.30.9239 - BlueStack Systems, Inc.)
Boot2Docker for Windows version 1.7.0 (HKLM\...\{05BD04E9-4AB5-46AC-891E-60EA8FD57D56}_is1) (Version: 1.7.0 - Docker Inc)
BufferChm (x32 Version: 140.0.298.000 - Hewlett-Packard) Hidden
Copy (x32 Version: 140.0.298.000 - Hewlett-Packard) Hidden
Destinations (x32 Version: 140.0.253.000 - Hewlett-Packard) Hidden
DeviceDiscovery (x32 Version: 140.0.298.000 - Hewlett-Packard) Hidden
DJ_AIO_06_F4500_SW_MIN (x32 Version: 140.0.851.000 - Hewlett-Packard) Hidden
F4500 (x32 Version: 140.0.851.000 - Hewlett-Packard) Hidden
File Repair (HKLM-x32\...\File Repair_is1) (Version: - File Repair)
Git version 1.9.5-preview20150319 (HKLM-x32\...\Git_is1) (Version: 1.9.5-preview20150319 - The Git Development Community)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 45.0.2454.85 - Google Inc.)
Google Update Helper (x32 Version: 1.3.28.13 - Google Inc.) Hidden
GPBaseService2 (x32 Version: 140.0.297.000 - Hewlett-Packard) Hidden
HD Tune Pro 5.50 (HKLM-x32\...\HD Tune Pro_is1) (Version: - EFD Software)
HP Customer Participation Program 14.0 (HKLM\...\HPExtendedCapabilities) (Version: 14.0 - HP)
HP Deskjet F4500 All-in-One Driver Software 14.0 Rel. 6 (HKLM\...\{FD126052-310E-4364-937B-6B5564F24578}) (Version: 14.0 - HP)
HP Imaging Device Functions 14.0 (HKLM\...\HP Imaging Device Functions) (Version: 14.0 - HP)
HP Solution Center 14.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 14.0 - HP)
HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HPPhotoGadget (x32 Version: 140.0.524.000 - Hewlett-Packard) Hidden
HPProductAssistant (x32 Version: 140.0.298.000 - Hewlett-Packard) Hidden
Java 8 Update 60 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418060F0}) (Version: 8.0.600.27 - Oracle Corporation)
Java 8 Update 60 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218060F0}) (Version: 8.0.600.27 - Oracle Corporation)
Java SE Development Kit 8 Update 60 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0180600}) (Version: 8.0.600.27 - Oracle Corporation)
KMSpico v9.1.3 (HKLM\...\KMSpico_is1) (Version: 9.1.3 - )
Legoaizer v1.5 (HKLM-x32\...\Legoaizer_is1) (Version: 1.5 - APP Helmond)
Line 6 Uninstaller (HKLM-x32\...\Line 6 Uninstaller) (Version: - Line 6)
Mad Max version 1.0 (HKLM-x32\...\{0EA0C5B4-A21F-4AA8-A66C-C2C8730534D1}_is1) (Version: 1.0 - Rldgames)
Malwarebytes Anti-Malware Version 2.1.8.1057 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation)
MarketResearch (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden
Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Xbox 360 Accessories 1.2 (HKLM\...\{D9C50188-12D5-4D3E-8F00-682346C2AA5F}) (Version: 1.20.146.0 - Microsoft)
Mortal Kombat X (HKLM-x32\...\TW9ydGFsS29tYmF0WA==_is1) (Version: 1 - )
MSI Afterburner 4.1.1 (HKLM-x32\...\Afterburner) (Version: 4.1.1 - MSI Co., LTD)
NetBeans IDE 8.1 Beta (HKLM\...\nbi-nb-base-8.1.0.0.201508041349) (Version: 8.1 Beta - NetBeans.org)
Network64 (Version: 140.0.306.000 - Hewlett-Packard) Hidden
NVIDIA 3D Vision Controller-Treiber 352.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 352.65 - NVIDIA Corporation)
NVIDIA 3D Vision Treiber 355.82 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 355.82 - NVIDIA Corporation)
NVIDIA CUDA Samples 7.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_CUDASamples_7.0) (Version: 7.0 - NVIDIA Corporation)
NVIDIA CUDA Toolkit 7.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_CUDAToolkit_7.0) (Version: 7.0 - NVIDIA Corporation)
NVIDIA CUDA Visual Studio Integration 7.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_CUDAVisualStudioIntegration_7.0) (Version: 7.0 - NVIDIA Corporation)
NVIDIA GeForce Experience 2.5.13.6 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.5.13.6 - NVIDIA Corporation)
NVIDIA Grafiktreiber 355.82 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 355.82 - NVIDIA Corporation)
NVIDIA HD-Audiotreiber 1.3.34.3 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.3 - NVIDIA Corporation)
NVIDIA Nsight Visual Studio Edition 4.5.0.15036 (HKLM\...\{DA371382-CABC-44B3-9BB4-14B5081B6446}) (Version: 4.5.0.15036 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.15.0428 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation)
NVIDIA Tools Extension SDK (NVTX) - 64 bit (HKLM\...\{4D983759-07FC-4571-BB59-58C9BBADECC5}) (Version: 1.00.00.00 - NVIDIA Corporation)
OpenOffice.org 3.4.1 (HKLM-x32\...\{2303AEEA-0FA8-4AFD-80A9-8F86BA4B44D2}) (Version: 3.41.9593 - Apache Software Foundation)
OpenSSH for Windows (remove only) (HKLM-x32\...\OpenSSH) (Version: - Michael Johnson)
Oracle VM VirtualBox 4.3.28 (HKLM\...\{E8BB81BC-E67C-4750-84EE-128DA5A7ADA5}) (Version: 4.3.28 - Oracle Corporation)
PixRecovery 3.0.21083.2 Demo License (HKLM-x32\...\{D9AA12EF-3315-435A-A3E4-CD734D6D0A0B}) (Version: 3.0.21083.2 - Recoveronix)
psynetic® Gif-X 3.00 (HKLM-x32\...\psynetic® Gif-X) (Version: 3.00 - Robert Mundt)
Python 2.7.10 (Anaconda 2.3.0 64-bit) (HKU\S-1-5-21-3600270544-3147449856-236785905-1001\...\Python 2.7.10 (Anaconda 2.3.0 64-bit)) (Version: 2.3.0 - Continuum Analytics, Inc.)
RAIDXpert (HKLM-x32\...\InstallShield_{8B76B8E9-F773-4B75-A08C-120079EB765E}) (Version: 3.2.1540.5 - AMD)
RAIDXpert (x32 Version: 3.2.1540.5 - AMD) Hidden
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7535 - Realtek Semiconductor Corp.)
Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.1.5.8 - Rockstar Games)
Scan (x32 Version: 140.0.253.000 - Hewlett-Packard) Hidden
SHIELD Streaming (Version: 4.1.3000 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 2.5.13.6 - NVIDIA Corporation) Hidden
SketchUp 2015 (HKLM\...\{A83795B9-570F-40FF-ACB4-710B568EBA22}) (Version: 15.3.331 - Trimble Navigation Limited)
SolutionCenter (x32 Version: 140.0.299.000 - Hewlett-Packard) Hidden
Spotify (HKU\S-1-5-21-3600270544-3147449856-236785905-1001\...\Spotify) (Version: 1.0.6.80.g2a801a53 - Spotify AB)
Status (x32 Version: 140.0.342.000 - Hewlett-Packard) Hidden
Temerian Armor Set (HKLM-x32\...\Temerian Armor Set_is1) (Version: 1.0.0.0 - GOG.com)
The Witcher 3 - Wild Hunt (HKLM-x32\...\1207664643_is1) (Version: 1.0.0.0 - GOG.com)
Toolbox (x32 Version: 140.0.596.000 - Hewlett-Packard) Hidden
TrayApp (x32 Version: 140.0.297.000 - Hewlett-Packard) Hidden
Uplay (HKLM-x32\...\Uplay) (Version: 4.9 - Ubisoft)
Vagrant (HKLM-x32\...\{40ADEFDD-ABAC-4AAE-A868-387F666C0B17}) (Version: 1.7.2 - HashiCorp)
VirtualCloneDrive (HKLM-x32\...\VirtualCloneDrive) (Version: 5.4.8.0 - Elaborate Bytes)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN)
WebReg (x32 Version: 140.0.297.017 - Hewlett-Packard) Hidden
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-3600270544-3147449856-236785905-1001_Classes\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6}\InprocServer32 -> C:\Windows\system32\shell32.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3600270544-3147449856-236785905-1001_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32 -> C:\Users\felix\AppData\Local\Microsoft\OneDrive\17.3.5930.0814_1\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3600270544-3147449856-236785905-1001_Classes\CLSID\{5AB7172C-9C11-405C-8DD5-AF20F3606282}\InprocServer32 -> C:\Users\felix\AppData\Local\Microsoft\OneDrive\17.3.5930.0814_1\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3600270544-3147449856-236785905-1001_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32 -> C:\Users\felix\AppData\Local\Microsoft\OneDrive\17.3.5930.0814_1\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3600270544-3147449856-236785905-1001_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32 -> C:\Users\felix\AppData\Local\Microsoft\OneDrive\17.3.5930.0814_1\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3600270544-3147449856-236785905-1001_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\felix\AppData\Local\Microsoft\OneDrive\17.3.5930.0814_1\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3600270544-3147449856-236785905-1001_Classes\CLSID\{A78ED123-AB77-406B-9962-2A5D9D2F7F30}\InprocServer32 -> C:\Users\felix\AppData\Local\Microsoft\OneDrive\17.3.5930.0814_1\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3600270544-3147449856-236785905-1001_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\felix\AppData\Local\Microsoft\OneDrive\17.3.5930.0814_1\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3600270544-3147449856-236785905-1001_Classes\CLSID\{ca586c80-7c84-4b88-8537-726724df6929}\InprocServer32 -> C:\Program Files (x86)\Git\git-cheetah\git_shell_ext64.dll ()
CustomCLSID: HKU\S-1-5-21-3600270544-3147449856-236785905-1001_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\felix\AppData\Local\Microsoft\OneDrive\17.3.5930.0814_1\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3600270544-3147449856-236785905-1001_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\felix\AppData\Local\Microsoft\OneDrive\17.3.5930.0814_1\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3600270544-3147449856-236785905-1001_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\felix\AppData\Local\Microsoft\OneDrive\17.3.5930.0814_1\amd64\FileSyncApi64.dll (Microsoft Corporation)
==================== Restore Points =========================
ATTENTION: System Restore is disabled
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {0EB24C6C-7B72-4D39-84AD-42DFBF28372D} - System32\Tasks\Microsoft\Windows\AppReadiness\TriggerTask
Task: {10BB2EE2-5C81-4033-9389-B17835BA0537} - System32\Tasks\Microsoft\Windows\Location\WindowsActionDialog => C:\Windows\System32\WindowsActionDialog.exe [2015-08-23] (Microsoft Corporation)
Task: {149C1713-57E9-4414-AC58-710C1351AC39} - System32\Tasks\Microsoft\Windows\WindowsUpdate\sihboot => C:\Windows\System32\sihclient.exe [2015-08-23] (Microsoft Corporation)
Task: {16208544-47D9-4483-B959-AE7CCE97D82D} - \Microsoft\Windows\Setup\GWXTriggers\Logon -> No File <==== ATTENTION
Task: {1D5371B3-F3CF-4683-B197-BAC151C615DA} - System32\Tasks\Microsoft\Windows\RetailDemo\CleanupOfflineContent
Task: {22C94E43-2C59-4A8C-9CAD-7FE692CFB25B} - System32\Tasks\Microsoft\Windows\WindowsUpdate\ausessionconnect => C:\Windows\System32\sihclient.exe [2015-08-23] (Microsoft Corporation)
Task: {23E8D3FA-C7C7-4F50-93DF-4668B044CBC1} - System32\Tasks\MSIAfterburner => C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe [2015-05-25] ()
Task: {297A1D22-3AA7-4F93-B779-461DE515B551} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-08-29] (Microsoft Corporation)
Task: {2E44B94C-1B2A-467D-A649-0608BA06B734} - System32\Tasks\Microsoft\Windows\Feedback\Siuf\DmClient => C:\Windows\system32\dmclient.exe [2015-08-23] (Microsoft Corporation)
Task: {339B6D68-1BEC-49B2-AA7C-BCBAD7B679E3} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-05-19] (Google Inc.)
Task: {373A4142-F09E-4F5B-858F-93DB9E4909D5} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {382A29EF-5A9E-4EDB-80B9-4929DCC57D13} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {39237538-E247-4C12-8172-8AC7B0450165} - System32\Tasks\Microsoft\Windows\AppID\EDP Policy Manager
Task: {4537D848-0AB6-4E4D-92F2-A85FF507B8AB} - System32\Tasks\Microsoft\Windows\ApplicationData\DsSvcCleanup => C:\Windows\system32\dstokenclean.exe [2015-08-23] (Microsoft Corporation)
Task: {4664D7E2-95BE-4D09-9E74-C7732B4D47E0} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle -> No File <==== ATTENTION
Task: {4CCF0449-1E21-479D-8EB0-24FBF3D2F62D} - System32\Tasks\Microsoft\Windows\Maps\MapsToastTask
Task: {51C8EE5D-5EF8-4C79-8DC4-9F70B8E8CD21} - System32\Tasks\Microsoft\Windows\TPM\Tpm-HASCertRetr
Task: {55D7E0D8-8915-40BB-BA73-A97BCCAD21F7} - System32\Tasks\Microsoft\Windows\Clip\License Validation => C:\Windows\system32\ClipUp.exe [2015-08-23] (Microsoft Corporation)
Task: {5ED05CEC-4167-4A53-8836-A3EBA591ED20} - System32\Tasks\AutoPico Daily Restart => C:\Program Files\KMSpico\AutoPico.exe [2013-12-12] ()
Task: {602AD81C-364C-4EEB-AF5F-D0270290F3A4} - System32\Tasks\Microsoft\Windows\SetupSQMTask => C:\WINDOWS\SYSTEM32\OOBE\SETUPSQM.EXE [2015-08-23] (Microsoft Corporation)
Task: {63E13754-9C1C-45B0-BBF5-BA899B799BF7} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {6AC985C2-1259-4721-9CF9-7836FEB63C68} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Device-Join => C:\Windows\System32\dsregcmd.exe [2015-08-23] (Microsoft Corporation)
Task: {82B68E5D-FE3D-468C-868E-C10A19D8DE0F} - \SpeechRuntimeTask -> No File <==== ATTENTION
Task: {8C928627-E2FF-4651-AD41-02766B389C72} - System32\Tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser => Rundll32.exe generaltel.dll,RunTelemetryW
Task: {D0657F9E-1846-415F-9386-CB474D816148} - System32\Tasks\Microsoft\Windows\WindowsUpdate\sih => C:\Windows\System32\sihclient.exe [2015-08-23] (Microsoft Corporation)
Task: {E4948109-EEE8-48B2-945F-449FF63FC5CB} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-05-19] (Google Inc.)
Task: {E6197990-C5EB-4CB4-9B61-F090647320B7} - System32\Tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater => Rundll32.exe generaltel.dll,RunTelemetry -maintenance
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (Whitelisted) ==============
2015-08-23 06:54 - 2015-08-23 06:54 - 02574840 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2015-08-23 06:54 - 2015-08-23 06:54 - 02574840 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2015-07-07 13:04 - 2015-03-19 23:33 - 00736962 _____ () C:\Program Files (x86)\Git\git-cheetah\git_shell_ext64.dll
2015-08-23 06:52 - 2015-08-23 06:52 - 00431104 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2015-08-23 06:52 - 2015-08-23 06:52 - 00642048 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\MtcUvc.dll
2015-08-23 06:57 - 2015-08-23 08:45 - 06369792 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2015-08-23 06:57 - 2015-08-23 08:45 - 00551424 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2015-08-23 06:57 - 2015-08-23 08:45 - 02482688 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2015-09-03 21:35 - 2015-09-03 21:35 - 00007168 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.827.16340.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
2015-09-03 21:35 - 2015-09-03 21:35 - 11606528 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.827.16340.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll
2015-08-23 08:48 - 2015-08-23 08:48 - 07897088 _____ () C:\Program Files\WindowsApps\Microsoft.NET.Native.Framework.1.0_1.0.22929.0_x64__8wekyb3d8bbwe\SharedLibrary.dll
2015-09-04 00:30 - 2015-08-28 02:17 - 01501512 _____ () C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.85\libglesv2.dll
2015-09-04 00:30 - 2015-08-28 02:17 - 00081224 _____ () C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.85\libegl.dll
2015-09-04 00:30 - 2015-08-28 02:17 - 16393032 _____ () C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.85\PepperFlash\pepflashplayer.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
AlternateDataStreams: C:\160754be85af964965a09c6e64a1b4:Win32App
AlternateDataStreams: C:\3f024bb582e8df25d26e2f65ba9805ae:Win32App
AlternateDataStreams: C:\46e152a2173a9d947650152efbe932:Win32App
AlternateDataStreams: C:\9aa07cab936acdbcd6a360:Win32App
AlternateDataStreams: C:\Program Files\Adobe:Win32App
AlternateDataStreams: C:\Program Files\Boot2Docker for Windows:Win32App
AlternateDataStreams: C:\Program Files\KMSpico:Win32App
AlternateDataStreams: C:\Program Files\Microsoft Xbox 360 Accessories:Win32App
AlternateDataStreams: C:\Program Files (x86)\Audacity:Win32App
AlternateDataStreams: C:\Program Files (x86)\Battle.net:Win32App
AlternateDataStreams: C:\Program Files (x86)\BlueStacks:Win32App
AlternateDataStreams: C:\Program Files (x86)\Git:Win32App
AlternateDataStreams: C:\Program Files (x86)\HD Tune Pro:Win32App
AlternateDataStreams: C:\Program Files (x86)\HP:Win32App
AlternateDataStreams: C:\Program Files (x86)\OpenOffice.org 3:Win32App
AlternateDataStreams: C:\ProgramData\BlueStacks:Win32App
AlternateDataStreams: C:\ProgramData\HP:Win32App
AlternateDataStreams: C:\ProgramData\HP Product Assistant:Win32App
AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxldtlfudivq`qsp`26hfm
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Ahcache.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CoreMessagingRegistrar => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SpbCx.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\StateRepository => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TileDataModelSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\UserManager => ""="Service"
==================== EXE Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-3600270544-3147449856-236785905-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\felix\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\img13.jpg
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
HKLM\...\StartupApproved\StartupFolder: => "HP Digital Imaging Monitor.lnk"
HKLM\...\StartupApproved\Run: => "AdobeAAMUpdater-1.0"
HKLM\...\StartupApproved\Run: => "NvBackend"
HKLM\...\StartupApproved\Run: => "ShadowPlay"
HKLM\...\StartupApproved\Run32: => "BlueStacks Agent"
HKLM\...\StartupApproved\Run32: => "ReCycle Patch"
HKLM\...\StartupApproved\Run32: => "HP Software Update"
HKLM\...\StartupApproved\Run32: => "VirtualCloneDrive"
HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched"
HKU\S-1-5-21-3600270544-3147449856-236785905-1001\...\StartupApproved\Run: => "Spotify"
HKU\S-1-5-21-3600270544-3147449856-236785905-1001\...\StartupApproved\Run: => "Spotify Web Helper"
HKU\S-1-5-21-3600270544-3147449856-236785905-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-3600270544-3147449856-236785905-1001\...\StartupApproved\Run: => "Skype"
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppextcomobj.exe
FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppextcomobj.exe
FirewallRules: [{27C2753F-E650-4C67-882B-FAA27725C8C7}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe
FirewallRules: [{277AA9BC-04D7-4F39-AD09-3C59E14C2335}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe
FirewallRules: [TCP Query User{4BB2FD06-098B-4250-AE4F-EF2C615C9BB4}C:\program files (x86)\skype\phone\skype.exe] => (Block) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [{365314C1-023A-44A1-BB0B-126EFD7DAFE0}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe
FirewallRules: [{79E962D0-2C47-48A1-956C-9481AEE9ABD1}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe
FirewallRules: [TCP Query User{267F0F15-B345-4BD9-960C-464096AA3589}G:\program files\sc2\starcraft ii\versions\base32283\sc2.exe] => (Allow) G:\program files\sc2\starcraft ii\versions\base32283\sc2.exe
FirewallRules: [UDP Query User{1977440A-5584-4F6A-A597-8A32EEC09C79}G:\program files\sc2\starcraft ii\versions\base32283\sc2.exe] => (Allow) G:\program files\sc2\starcraft ii\versions\base32283\sc2.exe
FirewallRules: [TCP Query User{F46B167F-6CA5-49D2-9144-8771CBF5F31C}C:\users\felix\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\felix\appdata\roaming\utorrent\utorrent.exe
FirewallRules: [UDP Query User{A6F1A138-CA13-4F78-B1FC-A15EA2130A4A}C:\users\felix\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\felix\appdata\roaming\utorrent\utorrent.exe
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (09/11/2015 08:11:19 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: loff9bko.exe, Version: 2.1.19357.0, Zeitstempel: 0x52e7ea83
Name des fehlerhaften Moduls: loff9bko.exe, Version: 2.1.19357.0, Zeitstempel: 0x52e7ea83
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000011aa
ID des fehlerhaften Prozesses: 0x12e4
Startzeit der fehlerhaften Anwendung: 0xloff9bko.exe0
Pfad der fehlerhaften Anwendung: loff9bko.exe1
Pfad des fehlerhaften Moduls: loff9bko.exe2
Berichtskennung: loff9bko.exe3
Vollständiger Name des fehlerhaften Pakets: loff9bko.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: loff9bko.exe5
Error: (09/11/2015 04:39:43 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: loff9bko.exe, Version: 2.1.19357.0, Zeitstempel: 0x52e7ea83
Name des fehlerhaften Moduls: loff9bko.exe, Version: 2.1.19357.0, Zeitstempel: 0x52e7ea83
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000011aa
ID des fehlerhaften Prozesses: 0xe8
Startzeit der fehlerhaften Anwendung: 0xloff9bko.exe0
Pfad der fehlerhaften Anwendung: loff9bko.exe1
Pfad des fehlerhaften Moduls: loff9bko.exe2
Berichtskennung: loff9bko.exe3
Vollständiger Name des fehlerhaften Pakets: loff9bko.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: loff9bko.exe5
Error: (09/11/2015 04:14:49 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm onenoteim.exe, Version 16.0.6131.1003 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Systemsteuerung "Sicherheit und Wartung", um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 1248
Startzeit: 01d0ec9bd9369348
Beendigungszeit: 4294967295
Anwendungspfad: C:\Program Files\WindowsApps\Microsoft.Office.OneNote_17.6131.10031.0_x64__8wekyb3d8bbwe\onenoteim.exe
Berichts-ID: 6a2f4e29-588f-11e5-8284-000cf6fde5dc
Vollständiger Name des fehlerhaften Pakets: Microsoft.Office.OneNote_17.6131.10031.0_x64__8wekyb3d8bbwe
Auf das fehlerhafte Paket bezogene Anwendungs-ID: microsoft.onenoteim
Error: (09/11/2015 04:14:29 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: ZARA)
Description: Das Paket „Microsoft.Office.OneNote_17.6131.10031.0_x64__8wekyb3d8bbwe+microsoft.onenoteim“ wurde beendet, da das Anhalten zu lange dauerte.
Error: (09/10/2015 04:53:35 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: ZARA)
Description: Bei der Aktivierung der App „microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1“ ist folgender Fehler aufgetreten: -2144927142. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.
Error: (09/10/2015 04:53:30 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: ZARA)
Description: Bei der Aktivierung der App „Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe!Microsoft.MicrosoftOfficeHub“ ist folgender Fehler aufgetreten: -2144927142. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.
Error: (09/10/2015 04:53:30 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: ZARA)
Description: Bei der Aktivierung der App „microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1“ ist folgender Fehler aufgetreten: -2144927142. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.
Error: (09/10/2015 04:53:30 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: ZARA)
Description: Bei der Aktivierung der App „microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1“ ist folgender Fehler aufgetreten: -2144927142. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.
Error: (09/10/2015 04:53:30 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: ZARA)
Description: Bei der Aktivierung der App „microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1“ ist folgender Fehler aufgetreten: -2144927142. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.
Error: (09/10/2015 04:48:53 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: cygrunsrv.exe, Version: 0.0.0.0, Zeitstempel: 0x40826252
Name des fehlerhaften Moduls: ntdll.dll, Version: 10.0.10532.0, Zeitstempel: 0x55d9082b
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0004714e
ID des fehlerhaften Prozesses: 0xb84
Startzeit der fehlerhaften Anwendung: 0xcygrunsrv.exe0
Pfad der fehlerhaften Anwendung: cygrunsrv.exe1
Pfad des fehlerhaften Moduls: cygrunsrv.exe2
Berichtskennung: cygrunsrv.exe3
Vollständiger Name des fehlerhaften Pakets: cygrunsrv.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: cygrunsrv.exe5
System errors:
=============
Error: (09/11/2015 04:52:59 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "NVIDIA Network Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (09/11/2015 04:52:58 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "NVIDIA Streamer Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (09/11/2015 04:52:58 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "NVIDIA GeForce Experience Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (09/11/2015 04:52:58 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "AMD RAIDXpert" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (09/11/2015 04:52:58 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "NVIDIA Stereoscopic 3D Driver Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (09/11/2015 04:52:58 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "NVIDIA Display Driver Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (09/10/2015 05:01:06 PM) (Source: DCOM) (EventID: 10010) (User: ZARA)
Description: microsoft.windowslive.calendar.AppXwkn9j84yh1kvnt49k5r8h6y1ecsv09hs.mca
Error: (09/10/2015 04:59:05 PM) (Source: DCOM) (EventID: 10010) (User: ZARA)
Description: microsoft.windowslive.calendar.AppXwkn9j84yh1kvnt49k5r8h6y1ecsv09hs.mca
Error: (09/10/2015 04:56:36 PM) (Source: DCOM) (EventID: 10010) (User: ZARA)
Description: microsoft.windowslive.calendar.AppXwkn9j84yh1kvnt49k5r8h6y1ecsv09hs.mca
Error: (09/10/2015 04:56:35 PM) (Source: DCOM) (EventID: 10010) (User: ZARA)
Description: Microsoft.MicrosoftOfficeHub.AppXrqs94aemecwbtd1veqtvyn34m9ks80g7.mca
Microsoft Office:
=========================
Error: (09/11/2015 08:11:19 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: loff9bko.exe2.1.19357.052e7ea83loff9bko.exe2.1.19357.052e7ea83c0000005000011aa12e401d0ecbd391469fdC:\Users\felix\Desktop\loff9bko.exeC:\Users\felix\Desktop\loff9bko.exe73bbca72-7059-49d6-acda-e4aceb81b93a
Error: (09/11/2015 04:39:43 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: loff9bko.exe2.1.19357.052e7ea83loff9bko.exe2.1.19357.052e7ea83c0000005000011aae801d0ec9fab36f224C:\Users\felix\Desktop\loff9bko.exeC:\Users\felix\Desktop\loff9bko.exe3df38e92-289d-4def-ad24-d9eacd37da72
Error: (09/11/2015 04:14:49 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: onenoteim.exe16.0.6131.1003124801d0ec9bd93693484294967295C:\Program Files\WindowsApps\Microsoft.Office.OneNote_17.6131.10031.0_x64__8wekyb3d8bbwe\onenoteim.exe6a2f4e29-588f-11e5-8284-000cf6fde5dcMicrosoft.Office.OneNote_17.6131.10031.0_x64__8wekyb3d8bbwemicrosoft.onenoteim
Error: (09/11/2015 04:14:29 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: ZARA)
Description: Microsoft.Office.OneNote_17.6131.10031.0_x64__8wekyb3d8bbwe+microsoft.onenoteim
Error: (09/10/2015 04:53:35 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: ZARA)
Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1-2144927142
Error: (09/10/2015 04:53:30 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: ZARA)
Description: Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe!Microsoft.MicrosoftOfficeHub-2144927142
Error: (09/10/2015 04:53:30 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: ZARA)
Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1-2144927142
Error: (09/10/2015 04:53:30 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: ZARA)
Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1-2144927142
Error: (09/10/2015 04:53:30 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: ZARA)
Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1-2144927142
Error: (09/10/2015 04:48:53 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: cygrunsrv.exe0.0.0.040826252ntdll.dll10.0.10532.055d9082bc00000050004714eb8401d0ebd7ccccf5a2C:\Program Files (x86)\OpenSSH\bin\cygrunsrv.exeC:\WINDOWS\SYSTEM32\ntdll.dll67ce7a14-034b-42f2-a298-422d0d4a7945
==================== Memory info ===========================
Processor: AMD Phenom(tm) II X4 965 Processor
Percentage of memory in use: 60%
Total physical RAM: 4094.49 MB
Available physical RAM: 1614.52 MB
Total Virtual: 9982.49 MB
Available Virtual: 6574.23 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:100.01 GB) (Free:6.61 GB) NTFS
Drive d: (Windows8) (Fixed) (Total:48.83 GB) (Free:24.28 GB) NTFS ==>[system with boot components (obtained from reading drive)]
Drive e: (WIndows8.1) (Fixed) (Total:146.21 GB) (Free:76.93 GB) NTFS ==>[system with boot components (obtained from reading drive)]
Drive f: (Auslagerungsdatei) (Fixed) (Total:48.82 GB) (Free:14.66 GB) NTFS
Drive g: (Daten) (Fixed) (Total:733.85 GB) (Free:2.07 GB) NTFS
Drive h: (WindowsXP) (Fixed) (Total:68.81 GB) (Free:40.71 GB) NTFS ==>[system with boot components (obtained from reading drive)]
Drive i: (Fotos) (Fixed) (Total:17.58 GB) (Free:2.1 GB) NTFS
Drive j: (Daten) (Fixed) (Total:146.49 GB) (Free:33.85 GB) NTFS
Drive k: (Mortal Kombat X) (CDROM) (Total:31.23 GB) (Free:0 GB) UDF
==================== MBR & Partition Table ==================
==================== End of Addition.txt ============================ |