Additional scan result of Farbar Recovery Scan Tool (x86) Version:16-08-2014 03 Ran by [removed] at 2014-08-17 08:13:25 Running from C:\Users\[removed]\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} FW: Online Armor Firewall (Enabled) {BD3F5FCA-866B-1E2E-0A68-58900A751EA1} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe AIR (HKLM\...\Adobe AIR) (Version: 14.0.0.110 - Adobe Systems Incorporated) Adobe AIR (Version: 14.0.0.110 - Adobe Systems Incorporated) Hidden Adobe Flash Player 14 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 14.0.0.176 - Adobe Systems Incorporated) Adobe Flash Player 14 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 14.0.0.179 - Adobe Systems Incorporated) Adobe Shockwave Player 12.1 (HKLM\...\Adobe Shockwave Player) (Version: 12.1.2.152 - Adobe Systems, Inc.) Amazon MP3 Downloader 1.0.17 (HKLM\...\Amazon MP3 Downloader) (Version: 1.0.17 - Amazon Services LLC) Apple Application Support (HKLM\...\{AAC5D43E-816D-4C2D-8E51-55FFF35BE301}) (Version: 3.0.1 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{18D47FA1-0440-48D3-A7E0-DA09537FF471}) (Version: 7.1.1.3 - Apple Inc.) avast! Free Antivirus (HKLM\...\Avast) (Version: 9.0.2021 - AVAST Software) CCleaner (HKLM\...\CCleaner) (Version: 4.15 - Piriform) Clickfree Easy Image (HKLM\...\Clickfree Easy Image) (Version: - Storage Appliance Corp.) Conexant D850 PCI V.92 Modem (HKLM\...\CNXT_MODEM_PCI_HSF) (Version: 7.80.4.0 - Conexant) Diskeeper 12 Home (HKLM\...\{6AC5A728-8DEC-4595-8895-DC312781A520}) (Version: 16.0.1017.32 - Condusiv Technologies) Ditto (HKLM\...\Ditto_is1) (Version: - Scott Brogden) DriverUpdate (HKLM\...\{1EC642B2-436B-43ED-AF56-D85A48E6E6AB}) (Version: 2.2.40266 - SlimWare Utilities, Inc.) FileHippo.com Update Checker (HKLM\...\FileHippo.com) (Version: - ) Foxit Reader (HKLM\...\Foxit Reader_is1) (Version: 6.2.2.802 - Foxit Corporation) GIMP 2.8.4 (HKLM\...\GIMP-2_is1) (Version: 2.8.4 - The GIMP Team) HP Photo Creations (HKLM\...\HP Photo Creations) (Version: 1.0.0.7702 - HP) HP Photosmart 6520 series Basic Device Software (HKLM\...\{D9B4150C-9EF6-4861-902F-5F5CB760D7ED}) (Version: 28.0.1315.0 - Hewlett-Packard Co.) HP Photosmart 6520 series Help (HKLM\...\{D3293275-1002-41F5-BC37-099B4251FF5B}) (Version: 28.0.0 - Hewlett Packard) HP Photosmart 6520 series Product Improvement Study (HKLM\...\{DF711F5A-C9E4-4241-9A83-58532C99DB28}) (Version: 28.0.1315.0 - Hewlett-Packard Co.) HP Update (HKLM\...\{6F1C00D2-25C2-4CBA-8126-AE9A6E2E9CD5}) (Version: 5.003.003.001 - Hewlett-Packard) HPDiagnosticAlert (Version: 1.00.0000 - Microsoft) Hidden IDT Audio (HKLM\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 5.10.0000.0 - IDT) Intel(R) Chipset Device Software (Version: 10.0.13 - Intel Corporation) Hidden Intel(R) Chipset Device Software (Version: 10.0.13 - Intel(R) Corporation) Hidden Intel(R) Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: 8.15.10.1930 - Intel Corporation) Intel(R) Network Connections 18.7.28.0 (HKLM\...\PROSetDX) (Version: 18.7.28.0 - Intel) Intel(R) Network Connections 18.7.28.0 (Version: 18.7.28.0 - Intel) Hidden Intel(R) Rapid Storage Technology (HKLM\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.7.0.1013 - Intel Corporation) IrfanView (remove only) (HKLM\...\IrfanView) (Version: 4.38 - Irfan Skiljan) Java 7 Update 67 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F03217067FF}) (Version: 7.0.670 - Oracle) Java Auto Updater (Version: 2.1.67.1 - Oracle, Inc.) Hidden Kingsoft Office 2012 (8.1.0.3385) (HKLM\...\Kingsoft Office) (Version: 8.1.0.3385 - Kingsoft Corp.) Malwarebytes Anti-Malware version 2.0.2.1012 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation) Microsoft .NET Framework 1.1 (HKLM\...\Microsoft .NET Framework 1.1 (1033)) (Version: - ) Microsoft .NET Framework 1.1 (Version: 1.1.4322 - Microsoft) Hidden Microsoft .NET Framework 4.5.1 (HKLM\...\{4903D172-DCCB-392F-93A3-34CA9D47FE3D}) (Version: - ) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft VC9 runtime libraries (Version: 2.0.0 - AOL Inc.) Hidden Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Mozilla Firefox 31.0 (x86 en-US) (HKLM\...\Mozilla Firefox 31.0 (x86 en-US)) (Version: 31.0 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 31.0 - Mozilla) Notepad++ (HKLM\...\Notepad++) (Version: 6.6.7 - Notepad++ Team) Online Armor 7.0 (HKLM\...\OnlineArmor_is1) (Version: 7.0 - Emsisoft GmbH) PrintMaster Platinum 18.1 (HKLM\...\{2BB2BAFA-A689-4D7A-98F6-F09D52C19A7F}) (Version: 18.01.0000 - Broderbund Software) Quick Blackjack 3.0 (remove only) (HKLM\...\Quick Blackjack 3.0) (Version: - ) Quick Cribbage 3.5 (remove only) (HKLM\...\Quick Cribbage 3.5) (Version: - ) Quick Poker 3.3 (remove only) (HKLM\...\Quick Poker 3.3) (Version: - ) Revo Uninstaller 1.95 (HKLM\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group) RoboForm 7-9-8-5 (All Users) (HKLM\...\AI RoboForm) (Version: 7-9-8-5 - Siber Systems) Speccy (HKLM\...\Speccy) (Version: 1.26 - Piriform) Stickies 7.1e (HKLM\...\ZhornStickies) (Version: - Zhorn Software) SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 5.6.1014 - SUPERAntiSpyware.com) swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden Tweaking.com - Registry Backup (HKLM\...\Tweaking.com - Registry Backup) (Version: 1.9.0 - Tweaking.com) Unlocker 1.9.2 (HKLM\...\Unlocker) (Version: 1.9.2 - Cedrick Collomb) VC_CRT_x86 (Version: 1.02.0000 - Intel Corporation) Hidden Visual Studio 2012 x86 Redistributables (HKLM\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - ) Wise Disk Cleaner 7.93 (HKLM\...\Wise Disk Cleaner_is1) (Version: 7.93 - WiseCleaner.com, Inc.) Wise Registry Cleaner 8.21 (HKLM\...\Wise Registry Cleaner_is1) (Version: 8.21 - WiseCleaner.com, Inc.) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-3499379357-965745774-4099936827-1001_Classes\CLSID\{15ea6566-467f-42ae-85d7-0ef80306cbdc}\localserver32 -> C:\Users\Karen\AppData\Local\Temp\{8b1670c8-dc4a-4ed4-974b-81737a23826b}\IDriver.NonElevated.exe No (the data entry has 4 more characters). ==================== Restore Points ========================= 16-08-2014 01:53:39 Windows Update 16-08-2014 02:11:14 avast! antivirus system restore point 16-08-2014 02:16:17 Online Armor installation 16-08-2014 02:22:49 Revo Uninstaller's restore point - Online Armor 6.0 16-08-2014 02:31:45 Online Armor installation 17-08-2014 07:00:21 Windows Update 17-08-2014 09:20:19 Windows Update 17-08-2014 11:03:05 Malware Fix Start ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-13 22:04 - 2013-12-07 20:24 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {079645E5-86ED-42F3-8388-42351B18761A} - System32\Tasks\Run RoboForm Process => C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe [2014-08-16] (Siber Systems) Task: {07B92A85-F04E-4F61-822E-5C926E58C4AD} - System32\Tasks\{61918878-F60C-4C7D-BC55-5AB9F45F59F9} => C:\Program Files\PrintMaster Platinum 18.1\PMW.exe [2010-04-07] (Broderbund Properties LLC) Task: {086E8E0B-3A02-4EA3-94CF-94F1B05178F6} - System32\Tasks\Registry Optimizer => C:\Program Files\WinZip Registry Optimizer\Winzipro.exe Task: {10316B40-4C87-4D78-AE48-11CB973DCDC8} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-06-24] (Piriform Ltd) Task: {2285D46A-3EC9-4F3E-90FE-DD816CADEA50} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup Task: {2D62DABF-97E6-4A25-A8BD-439678898CDA} - \SidebarExecute No Task File <==== ATTENTION Task: {2FB73766-BD96-426A-AEE9-D0CC3BCBAB60} - System32\Tasks\{E2813735-20E0-4C74-8AB5-6946B07409FB} => C:\Program Files\Condusiv Technologies\Diskeeper\Diskeeper12.exe [2012-07-27] (Condusiv Technologies) Task: {3FA3AA51-1313-43AC-84A6-E20FD01C5FF2} - System32\Tasks\Open URL by RoboForm => Rundll32.exe url.dll,FileProtocolHandler "http://www.roboform.com/test-pass.html?aaa=KICMLJHMMMPMNMIMJMNJCNPMNJKJJJCNLMMMKMIMCNOJHMPMLJCNOJOJLJNJNMLJLMHMLMJJJMHMJNJICMIMCNGMCNHMFMHMCNPMCNIMJMPMOMFMJMCNOMCNIMJMPMOMCNNMJNPICMOMFMEKMICNJJCKFMOMPMGMOMJNHICMMJBJKJLIMJJNBJCMFLKJJJJJJNKJCMJNNICMJNDJCMKJBJJNMJCMPMFMPMFMPMJNFICMGJLJKJBJLIGJLIGJKJMIBNKJHIKJ" Task: {48A4A98A-30F9-43FD-913B-BAE8B0DD8852} - System32\Tasks\{87AE4643-F13F-4E8E-B654-BF743C599859} => C:\Program Files\Condusiv Technologies\Diskeeper\Diskeeper12.exe [2012-07-27] (Condusiv Technologies) Task: {59F13EF7-ACB3-4E6F-A5B3-EE98501CB2E4} - System32\Tasks\WpsUpdateTask_Karen => C:\Program Files\Kingsoft\Kingsoft Office\office6\wpsupdate.exe [2013-06-05] (Kingsoft Corp. Ltd.) Task: {6ADFB7F8-767A-4720-BD86-077F7DAF8A62} - System32\Tasks\Registry Optimizer_DEFAULT => C:\Program Files\WinZip Registry Optimizer\Winzipro.exe Task: {6CEE853E-B5E1-4394-8DAD-653744385FF3} - System32\Tasks\WpsUpdateTask_Jeff => C:\Program Files\Kingsoft\Kingsoft Office\office6\wpsupdate.exe [2013-06-05] (Kingsoft Corp. Ltd.) Task: {79C5AE8C-BF60-4263-8D4B-2007D25F97B4} - System32\Tasks\DriverUpdate Daily Scan => C:\Program Files\DriverUpdate\DriverUpdate.exe [2014-08-05] (SlimWare Utilities, Inc.) Task: {7DC5212A-5EDA-40CE-ADFA-94F1804398B4} - System32\Tasks\{8DE5BDD5-FDE4-48EA-A267-E5BFAEDA33D8} => C:\Program Files\Diskeeper Corporation\Diskeeper\AppLauncher.exe Task: {844B23DA-4C19-41E1-B5B7-485359B10E44} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-08-16] (Adobe Systems Incorporated) Task: {87AEA180-9D17-4AD1-A8FC-87E03B0CE8D8} - System32\Tasks\{9BD2ED2F-6011-4C60-AEF0-E12B1AF205AA} => C:\Program Files\Winamp\winamp.exe Task: {B47F3D30-9D37-43BC-885C-06147A7930FC} - System32\Tasks\Registry Optimizer_UPDATES => C:\Program Files\WinZip Registry Optimizer\Winzipro.exe Task: {CCF1FC28-D18A-45FE-9705-2FA355A4011F} - System32\Tasks\HPCustParticipation HP Photosmart 6520 series => C:\Program Files\HP\HP Photosmart 6520 series\Bin\HPCustPartic.exe [2012-10-17] (Hewlett-Packard Co.) Task: {CF6BD976-3320-46D0-A03F-9805ACB10112} - System32\Tasks\{0EFA62F8-D658-4982-8966-737051757282} => C:\Program Files\Diskeeper Corporation\Diskeeper\AppLauncher.exe Task: {CF9FF820-D183-4BA6-8AC6-67BE2FA02F0A} - System32\Tasks\DriverUpdate Scan => C:\Program Files\DriverUpdate\DriverUpdate.exe [2014-08-05] (SlimWare Utilities, Inc.) Task: {D8766256-5929-4D50-8E03-9694FC6D67CD} - System32\Tasks\Run RoboForm TaskBar Icon => C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe [2014-08-16] (Siber Systems) Task: {DEA4C4AF-1980-40F9-B48D-3011B559687E} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-08-09] (AVAST Software) Task: {E2F09E24-BAE2-4420-9758-7B2A39A7525F} - System32\Tasks\{9861A06D-54E4-4C80-AD65-D49D75836F94} => C:\Program Files\Winamp\winamp.exe Task: {EE47759A-7F71-4852-86B3-3F683EB41C64} - System32\Tasks\{25401860-0C17-48BE-9943-1AEB1AFB7791} => C:\Program Files\PrintMaster Platinum 18.1\PMW.exe [2010-04-07] (Broderbund Properties LLC) Task: {EFDFB7FF-639B-41E3-AAE3-F3DE15ECE6D6} - System32\Tasks\{DABF1F30-E559-452F-935A-A66F399C1B55} => C:\Program Files\Condusiv Technologies\Diskeeper\Diskeeper12.exe [2012-07-27] (Condusiv Technologies) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\DriverUpdate Daily Scan.job => C:\Program Files\DriverUpdate\DriverUpdate.exe Task: C:\Windows\Tasks\DriverUpdate Scan.job => C:\Program Files\DriverUpdate\DriverUpdate.exe Task: C:\Windows\Tasks\Registry Optimizer_DEFAULT.job => C:\Program Files\WinZip Registry Optimizer\Winzipro.exe Task: C:\Windows\Tasks\Registry Optimizer_UPDATES.job => C:\Program Files\WinZip Registry Optimizer\Winzipro.exe Task: C:\Windows\Tasks\WpsUpdateTask_Jeff.job => C:\Program Files\Kingsoft\Kingsoft Office\office6\wpsupdate.exe Task: C:\Windows\Tasks\WpsUpdateTask_Karen.job => C:\Program Files\Kingsoft\Kingsoft Office\office6\wpsupdate.exe ==================== Loaded Modules (whitelisted) ============= 2014-08-09 21:11 - 2014-08-09 21:11 - 00301152 _____ () C:\Program Files\AVAST Software\Avast\aswProperty.dll 2014-08-17 04:45 - 2014-08-17 04:45 - 02797568 _____ () C:\Program Files\AVAST Software\Avast\defs\14081700\algo.dll 2014-02-12 20:58 - 2014-02-12 20:58 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2014-02-12 20:58 - 2014-02-12 20:58 - 01044808 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2013-02-17 14:51 - 2013-11-28 11:34 - 00235848 ____R () C:\programdata\Clickfree\FullImagingBackup\FullImagingService.exe 2013-02-17 14:51 - 2013-11-28 11:34 - 00133960 ____R () C:\programdata\Clickfree\FullImagingBackup\VssClientDll.dll 2010-07-04 17:32 - 2010-07-04 17:32 - 00010752 _____ () C:\Program Files\Unlocker\UnlockerCOM.dll 2014-05-12 05:49 - 2014-05-12 05:49 - 00260608 _____ () C:\Program Files\Notepad++\NppShell_06.dll 2014-08-09 21:11 - 2014-08-09 21:11 - 19329904 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2013-12-07 19:48 - 2012-11-08 21:17 - 01433200 _____ () C:\Program Files\Ditto\Ditto.exe 2013-08-25 11:31 - 2013-08-25 11:31 - 00049152 _____ () C:\Program Files\Stickies\shook70.dll 2014-08-15 22:58 - 2014-08-15 22:58 - 00017920 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\PSIClient\e0cca00b42165c0b882a7ef23368c6ac\PSIClient.ni.dll 2014-08-07 11:27 - 2014-07-17 01:42 - 03800688 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) MSCONFIG\Services: AdobeFlashPlayerUpdateSvc => 3 MSCONFIG\Services: Diskeeper => 2 MSCONFIG\Services: MBAMScheduler => 2 MSCONFIG\Services: MBAMService => 2 MSCONFIG\Services: OAcat => 2 MSCONFIG\Services: SvcOnlineArmor => 2 MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Event Reminder.lnk => C:\Windows\pss\Event Reminder.lnk.CommonStartup MSCONFIG\startupreg: @OnlineArmor GUI => "C:\Program Files\Online Armor\oaui.exe" MSCONFIG\startupreg: HP Software Update => C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe MSCONFIG\startupreg: SUPERAntiSpyware => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe MSCONFIG\startupreg: UnlockerAssistant => "C:\Program Files\Unlocker\UnlockerAssistant.exe" ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (08/17/2014 08:03:34 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/17/2014 05:28:35 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/17/2014 04:51:41 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/17/2014 04:45:17 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/17/2014 00:59:00 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Activation context generation failed for "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1". Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found. Please use sxstrace.exe for detailed diagnosis. Error: (08/16/2014 08:11:50 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/16/2014 07:57:52 PM) (Source: ESENT) (EventID: 215) (User: ) Description: WinMail (5040) WindowsMail0: The backup has been stopped because it was halted by the client or the connection with the client failed. Error: (08/16/2014 03:57:12 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Activation context generation failed for "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1". Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found. Please use sxstrace.exe for detailed diagnosis. Error: (08/16/2014 00:30:56 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Activation context generation failed for "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1". Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found. Please use sxstrace.exe for detailed diagnosis. Error: (08/15/2014 10:38:58 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (08/17/2014 08:05:44 AM) (Source: WMPNetworkSvc) (EventID: 14338) (User: ) Description: 0x80070422 Error: (08/17/2014 08:05:44 AM) (Source: WMPNetworkSvc) (EventID: 14338) (User: ) Description: 0x80070422 Error: (08/17/2014 05:30:00 AM) (Source: WMPNetworkSvc) (EventID: 14338) (User: ) Description: 0x80070422 Error: (08/17/2014 05:30:00 AM) (Source: WMPNetworkSvc) (EventID: 14338) (User: ) Description: 0x80070422 Error: (08/17/2014 04:53:40 AM) (Source: WMPNetworkSvc) (EventID: 14338) (User: ) Description: 0x80070422 Error: (08/17/2014 04:53:40 AM) (Source: WMPNetworkSvc) (EventID: 14338) (User: ) Description: 0x80070422 Error: (08/17/2014 04:52:33 AM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: The Windows Modules Installer service terminated with the following error: %%16405 Error: (08/17/2014 04:47:22 AM) (Source: WMPNetworkSvc) (EventID: 14338) (User: ) Description: 0x80070422 Error: (08/17/2014 04:47:22 AM) (Source: WMPNetworkSvc) (EventID: 14338) (User: ) Description: 0x80070422 Error: (08/16/2014 08:12:43 PM) (Source: WMPNetworkSvc) (EventID: 14338) (User: ) Description: 0x80070422 Microsoft Office Sessions: ========================= Error: (08/17/2014 08:03:34 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/17/2014 05:28:35 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/17/2014 04:51:41 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/17/2014 04:45:17 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/17/2014 00:59:00 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"C:\Program Files\HP\HP Photosmart 6520 series\DriverStore\Pipeline\amd64\hpinkinsAF11.exe Error: (08/16/2014 08:11:50 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/16/2014 07:57:52 PM) (Source: ESENT) (EventID: 215) (User: ) Description: WinMail5040WindowsMail0: Error: (08/16/2014 03:57:12 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"C:\Program Files\HP\HP Photosmart 6520 series\DriverStore\Pipeline\amd64\hpinkinsAF11.exe Error: (08/16/2014 00:30:56 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"C:\Program Files\HP\HP Photosmart 6520 series\DriverStore\Pipeline\amd64\hpinkinsAF11.exe Error: (08/15/2014 10:38:58 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 CodeIntegrity Errors: =================================== Date: 2013-09-14 06:46:25.301 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll because the set of per-page image hashes could not be found on the system. Date: 2013-09-14 06:20:52.059 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll because the set of per-page image hashes could not be found on the system. Date: 2013-09-14 06:14:37.855 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll because the set of per-page image hashes could not be found on the system. Date: 2013-09-14 05:31:50.612 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll because the set of per-page image hashes could not be found on the system. Date: 2013-09-14 05:15:25.918 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll because the set of per-page image hashes could not be found on the system. Date: 2013-09-14 00:15:06.263 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll because the set of per-page image hashes could not be found on the system. Date: 2013-09-14 00:03:09.112 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll because the set of per-page image hashes could not be found on the system. Date: 2013-09-13 23:58:06.848 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll because the set of per-page image hashes could not be found on the system. Date: 2013-09-13 23:49:35.156 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll because the set of per-page image hashes could not be found on the system. Date: 2013-09-13 23:40:27.927 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll because the set of per-page image hashes could not be found on the system. ==================== Memory info =========================== Processor: Intel(R) Core(TM)2 CPU 4300 @ 1.80GHz Percentage of memory in use: 46% Total physical RAM: 3061.91 MB Available physical RAM: 1639.88 MB Total Pagefile: 6122.12 MB Available Pagefile: 4308.97 MB Total Virtual: 2047.88 MB Available Virtual: 1889.74 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:222.79 GB) (Free:189.39 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive f: () (Fixed) (Total:10.04 GB) (Free:9.66 GB) NTFS Drive g: (Clickfree) (CDROM) (Total:0.13 GB) (Free:0 GB) CDFS Drive h: (CF_Storage) (Removable) (Total:465.35 GB) (Free:396.83 GB) NTFS Drive j: () (Removable) (Total:14.92 GB) (Free:13.95 GB) FAT32 Drive k: (KINGSTON) (Removable) (Total:15.01 GB) (Free:11.29 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 232.8 GB) (Disk ID: D8000000) Partition 1: (Not Active) - (Size=10 GB) - (Type=07 NTFS) Partition 2: (Active) - (Size=222.8 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (Size: 15 GB) (Disk ID: 04030201) Partition 1: (Not Active) - (Size=15 GB) - (Type=0B) ======================================================== Disk: 2 (MBR Code: Windows XP) (Size: 14.9 GB) (Disk ID: C3072E18) Partition 1: (Active) - (Size=14.9 GB) - (Type=0C) ======================================================== Disk: 3 (Size: 465.6 GB) (Disk ID: 00000000) Partition: GPT Partition Type. ==================== End Of Log ============================